Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

NEED HELP WITH RED Desktop {BIOHAZARD} - TROYAN and WORM

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

NEED HELP WITH RED Desktop {BIOHAZARD} - TROYAN and WORM

Unread postby bobcat61 » July 26th, 2008, 8:19 am

hello, i am glad that i found website like this. i need real help, i ve got red desktop with biohazard sign on. i would like to ask for help, my ESET software found 13 files putted in karanteen, i dont know what to do next. i made hjt log file. please, write me what to do next. 1000xTHANKS

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:14: VIRUS ALERT!, on 26. 7. 2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Lenovo\System Update\SUService.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\qttask.exe
C:\program files\microcom\adsl deskporte usb\CnxDslTb.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
E:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wm ... Ojg5&lid=2
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: QXK Olive - {7DED6C43-C9A7-4EAE-A6C0-692B27D44EA9} - C:\WINDOWS\nfavxwdblwf.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: fdkowvbp - {CC62551A-9113-48E1-936F-27ABC255A8B4} - C:\WINDOWS\fdkowvbp.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [frymxins] "C:\Program Files\ATI Technologies\Fire GL 3D Studio Max\atiimxgl"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CnxDslTaskBar] "c:\program files\microcom\adsl deskporte usb\CnxDslTb.exe" "Microcom\ADSL DeskPorte USB"
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\IBM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{0CFD20D2-4E26-4DAC-91FF-7C35EACEED91}: NameServer = 195.146.132.58 195.146.128.60
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: ljJYRLDS - C:\WINDOWS\SYSTEM32\ljJYRLDS.dll
O20 - Winlogon Notify: WinCtrl32 - C:\WINDOWS\SYSTEM32\WinCtrl32.dll
O21 - SSODL: wnslvxtf - {CEEBC533-D0D3-4FE9-A267-331CA5645955} - C:\WINDOWS\wnslvxtf.dll
O21 - SSODL: eqvwamkl - {332603FE-0853-4FEB-A952-07F146C5C611} - C:\WINDOWS\eqvwamkl.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

--
End of file - 9718 bytes
bobcat61
Active Member
 
Posts: 9
Joined: July 26th, 2008, 8:13 am
Advertisement
Register to Remove

Re: NEED HELP WITH RED Desktop {BIOHAZARD} - TROYAN and WORM

Unread postby random/random » July 26th, 2008, 9:32 am

Please download SmitfraudFix (by S!Ri)

Double-click SmitfraudFix.exe.
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

**If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc...processutil.htm

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log, and the smitfraudfix log.
User avatar
random/random
Developer
Developer
 
Posts: 7733
Joined: December 18th, 2005, 3:30 pm

Re: NEED HELP WITH RED Desktop {BIOHAZARD} - TROYAN and WORM

Unread postby bobcat61 » July 26th, 2008, 10:14 am

Hello Mr. Teacher,
so....i downloaded the SmitFraudFix file and a did it like you wrote: 1 and ENTER...
now i can see this report:




SmitFraudFix v2.331

Scan done at 16:09:29,02, so 26. 07. 2008
Run from C:\Documents and Settings\Cermak\Plocha\SmitfraudFix
OS: Microsoft Windows XP [Verze 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Lenovo\System Update\SUService.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\qttask.exe
C:\program files\microcom\adsl deskporte usb\CnxDslTb.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

C:\WINDOWS\privacy_danger FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Cermak


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Cermak\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Cermak\OBLBEN~1

C:\DOCUME~1\Cermak\OBLBEN~1\Error Cleaner.url FOUND !
C:\DOCUME~1\Cermak\OBLBEN~1\Privacy Protector.url FOUND !
C:\DOCUME~1\Cermak\OBLBEN~1\Spyware?Malware Protection.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop

C:\DOCUME~1\Cermak\Plocha\Error Cleaner.url FOUND !
C:\DOCUME~1\Cermak\Plocha\Privacy Protector.url FOUND !
C:\DOCUME~1\Cermak\Plocha\Spyware?Malware Protection.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="file:///C:\\WINDOWS\\privacy_danger\\index.htm"
"SubscribedURL"=""
"FriendlyName"="Privacy Protection"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Aktu lnˇ domovsk str nka"

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, following keys are not inevitably infected!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
+--------------------------------------------------+
[!] Suspicious: nfavxwdblwf.dll
BHO: QXK Olive - {7DED6C43-C9A7-4EAE-A6C0-692B27D44EA9}
TypeLib: {6CE95B96-2A25-4493-A109-FE067851D101}
Interface: {14BA7348-6C90-4EA0-A97A-5F83924856BD}
Interface: {28D41E1D-6DAC-4391-B002-B3DB2B4C18CF}

[!] Suspicious: fdkowvbp.dll
Toolbar: fdkowvbp - {CC62551A-9113-48E1-936F-27ABC255A8B4}
TypeLib: {B0AC3074-B52F-419B-A03B-4AF60D27CF58}
Interface: {2F5BA4B7-B0DE-4B66-84D0-32EF2D9941B0}
Classe: fdkowvbp.btmn
Classe: fdkowvbp.ToolBar.1

[!] Suspicious: wnslvxtf.dll
SSODL: wnslvxtf - {CEEBC533-D0D3-4FE9-A267-331CA5645955}

[!] Suspicious: eqvwamkl.dll
SSODL: eqvwamkl - {332603FE-0853-4FEB-A952-07F146C5C611}


»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, following keys are not inevitably infected!!!

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: WAN (PPP/SLIP) Interface
DNS Server Search Order: 195.146.132.58
DNS Server Search Order: 195.146.128.60

HKLM\SYSTEM\CCS\Services\Tcpip\..\{0CFD20D2-4E26-4DAC-91FF-7C35EACEED91}: NameServer=195.146.132.58 195.146.128.60
HKLM\SYSTEM\CS1\Services\Tcpip\..\{0CFD20D2-4E26-4DAC-91FF-7C35EACEED91}: NameServer=195.146.132.58 195.146.128.60


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
bobcat61
Active Member
 
Posts: 9
Joined: July 26th, 2008, 8:13 am

Re: NEED HELP WITH RED Desktop {BIOHAZARD} - TROYAN and WORM

Unread postby bobcat61 » July 26th, 2008, 11:42 am

hi...so, i did it like you wrote. thanks, the red desktop gone away, but I am not sure if it is finish.
the files are still in karanteen. here is new log file from HJT: what are the next steps ???? is it finish??? if yes, thank you very much for help !!!!!!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:40:22, on 26. 7. 2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Lenovo\System Update\SUService.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\qttask.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\program files\microcom\adsl deskporte usb\CnxDslTb.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Winamp\winamp.exe
E:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [frymxins] "C:\Program Files\ATI Technologies\Fire GL 3D Studio Max\atiimxgl"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CnxDslTaskBar] "c:\program files\microcom\adsl deskporte usb\CnxDslTb.exe" "Microcom\ADSL DeskPorte USB"
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SDFix] E:\SDFix\SDFix\RunThis.bat /second
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\IBM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{0CFD20D2-4E26-4DAC-91FF-7C35EACEED91}: NameServer = 195.146.132.58 195.146.128.60
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

--
End of file - 8772 bytes
bobcat61
Active Member
 
Posts: 9
Joined: July 26th, 2008, 8:13 am

Re: NEED HELP WITH RED Desktop {BIOHAZARD} - TROYAN and WORM

Unread postby bobcat61 » July 26th, 2008, 11:45 am

SmitFraudFix v2.331

Scan done at 17:26:46,49, so 26. 07. 2008
Run from C:\Documents and Settings\Cermak\Plocha\SmitfraudFix
OS: Microsoft Windows XP [Verze 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» VACFix

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\privacy_danger\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» 404Fix

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: WAN (PPP/SLIP) Interface
DNS Server Search Order: 195.146.128.62
DNS Server Search Order: 195.146.132.59

HKLM\SYSTEM\CCS\Services\Tcpip\..\{0CFD20D2-4E26-4DAC-91FF-7C35EACEED91}: NameServer=195.146.128.62 195.146.132.59
HKLM\SYSTEM\CS1\Services\Tcpip\..\{0CFD20D2-4E26-4DAC-91FF-7C35EACEED91}: NameServer=195.146.128.62 195.146.132.59


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
bobcat61
Active Member
 
Posts: 9
Joined: July 26th, 2008, 8:13 am

Re: NEED HELP WITH RED Desktop {BIOHAZARD} - TROYAN and WORM

Unread postby random/random » July 26th, 2008, 12:05 pm

Please post the SDFix log (C:\SDFix\report.txt)
User avatar
random/random
Developer
Developer
 
Posts: 7733
Joined: December 18th, 2005, 3:30 pm

Re: NEED HELP WITH RED Desktop {BIOHAZARD} - TROYAN and WORM

Unread postby bobcat61 » July 26th, 2008, 8:00 pm

hi Teacher...i can send you this, sorry for long time and thank you for the time as well. i did this control and i think is too long. propably my mistake. please,anser me what to do...thanks!!!!!!!!!!!!!!!!!!!!!!!!!!!!



System Report
*************

Run on ne 27. 07. 2008 at 01:51

Microsoft Windows XP [Verze 5.1.2600]

Current user is an administrator

Running Processes:

\SystemRoot\System32\smss.exe [912]
\??\C:\WINDOWS\system32\csrss.exe [1008]
\??\C:\WINDOWS\system32\winlogon.exe [1032]
C:\WINDOWS\system32\services.exe [1076]
C:\WINDOWS\system32\lsass.exe [1088]
C:\WINDOWS\system32\ibmpmsvc.exe [1236]
C:\WINDOWS\system32\Ati2evxx.exe [1264]
C:\WINDOWS\system32\svchost.exe [1276]
C:\WINDOWS\system32\svchost.exe [1352]
C:\WINDOWS\System32\svchost.exe [1392]
C:\WINDOWS\system32\S24EvMon.exe [1432]
C:\WINDOWS\system32\svchost.exe [1580]
C:\WINDOWS\system32\svchost.exe [1692]
C:\WINDOWS\system32\Ati2evxx.exe [1860]
C:\WINDOWS\Explorer.EXE [1964]
C:\WINDOWS\system32\spoolsv.exe [336]
C:\WINDOWS\system32\svchost.exe [456]
C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe [468]
C:\Program Files\ESET\ESET Smart Security\ekrn.exe [496]
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [548]
C:\WINDOWS\system32\RegSrvc.exe [640]
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [688]
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe [716]
C:\WINDOWS\System32\TPHDEXLG.exe [728]
C:\WINDOWS\system32\TpKmpSVC.exe [748]
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe [808]
C:\WINDOWS\system32\wdfmgr.exe [828]
C:\Program Files\Lenovo\System Update\SUService.exe [944]
C:\WINDOWS\System32\alg.exe [1880]
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe [2152]
C:\WINDOWS\system32\rundll32.exe [2224]
C:\WINDOWS\system32\RunDll32.exe [2232]
C:\WINDOWS\system32\rundll32.exe [2252]
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe [2288]
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe [2308]
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2348]
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe [2360]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2368]
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe [2388]
C:\Program Files\ESET\ESET Smart Security\egui.exe [2396]
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2452]
C:\WINDOWS\system32\qttask.exe [2504]
C:\program files\microcom\adsl deskporte usb\CnxDslTb.exe [2528]
C:\WINDOWS\system32\TpShocks.exe [2540]
C:\Program Files\Winamp\winampa.exe [2584]
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2844]
C:\WINDOWS\system32\ctfmon.exe [2860]
C:\Program Files\Digital Line Detect\DLG.exe [2896]
C:\Program Files\uTorrent\uTorrent.exe [3608]
C:\Program Files\Winamp\winamp.exe [3040]
C:\Program Files\Mozilla Firefox\firefox.exe [928]


Drivers - Running:

ACPI
ACPIEC
aeaudio
AegisP
AFD
agp440
atapi
ati2mtag
audstub
Beep
BthEnum
BthPan
BTHUSB
BTKRNL
Cdfs
Cdrom
CmBatt
CnxEtP
CnxEtU
CnxTgNP
Compbatt
Disk
E1000
eamon
easdrv
epfw
Epfwndis
epfwtdi
Fips
FltMgr
Ftdisk
Gpc
HidUsb
HSFHWICH
HSF_DPV
i8042prt
IBMPMDRV
Imapi
IntelIde
intelppm
IpNat
IPSec
irda
IRENUM
isapnp
Kbdclass
kmixer
KSecDD
mdmxsdk
mnmdd
Modem
Mouclass
mouhid
MountMgr
MRxDAV
MRxSmb
Msfs
mssmbios
Mup
NDIS
NdisTapi
Ndisuio
NdisWan
NDProxy
NetBIOS
NetBT
Npfs
NSCIRDA
Ntfs
Null
Parport
PartMgr
ParVdm
PCI
PCIIde
Pcmcia
PptpMiniport
psadd
PSched
Ptilink
PxHelp20
RasAcd
Rasirda
Rasl2tp
RasPppoe
Raspti
Rdbss
RDPCDD
rdpdr
redbook
RFCOMM
s24trans
serenum
Serial
Shockprf
Smapint
smwdm
sr
Srv
swenum
SynTP
sysaudio
Tcpip
TDSMAPI
TermDD
TPDIGIMN
TPHKDRV
TPPWR
Update
usbehci
usbhub
usbuhci
VgaSave
VolSnap
Wanarp
wdmaud
winachsf


Drivers - Stopped:

Abiosdsk
abp480n5
adpu160m
aec
Aha154x
aic78u2
aic78xx
AliIde
amsint
asc
asc3350p
asc3550
AsyncMac
Atdisk
Atmarpc
BTHPORT
catchme
cbidf2k
cd20xrnt
Cdaudio
Changer
CmdIde
Cpqarray
dac960nt
dmboot
dmio
dmload
DMusic
dpti2o
drmkaud
Fastfat
Fdc
Flpydisk
hpn
HTTP
i2omgmt
i2omp
ini910u
Ip6Fw
IpFilterDriver
IpInIp
lbrtfdc
mraid35x
MSKSSRV
MSPCLOCK
MSPQM
NwlnkFlt
NwlnkFwd
PCIDump
PDCOMP
PDFRAME
PDRELI
PDRFRAME
perc2
perc2hib
ql1080
Ql10wnt
ql12160
ql1240
ql1280
RDPWD
Secdrv
Sfloppy
Simbad
Sparrow
splitter
swmidi
symc810
symc8xx
sym_hi
sym_u3
TDPIPE
TDTCP
TosIde
Udfs
UIUSys
ultra
USBSTOR
ViaIde
w70n51
WDICA
Winhn30
Winpw28


Services - Running:

ALG
Ati
AudioSrv
BITS
Browser
BthServ
btwdins
CryptSvc
DcomLaunch
Dhcp
Dnscache
ekrn
ERSvc
Eventlog
EventSystem
FastUserSwitchingCompatibility
helpsvc
IBMPMSVC
Irmon
lanmanserver
lanmanworkstation
LmHosts
MDM
Netman
Nla
PlugPlay
PolicyAgent
ProtectedStorage
RasMan
RegSrvc
RemoteRegistry
RpcSs
S24EventMonitor
SamSs
Schedule
seclogon
SENS
SharedAccess
ShellHWDetection
SoundMAX
Spooler
srservice
SUService
TapiSrv
TermService
Themes
ThinkVantage
TPHDEXLGSVC
TpKmpSVC
TrkWks
TVT
UMWdf
UxTuneUp
W32Time
WebClient
winmgmt
wscsvc
wuauserv
WZCSVC


Services - Stopped:

Alerter
AppMgmt
aspnet_state
CiSvc
ClipSrv
clr_optimization_v2.0.50727_32
COMSysApp
dmadmin
dmserver
EhttpSrv
HidServ
HTTPFilter
IDriverT
ImapiService
Messenger
mnmsrvc
MSDTC
MSIServer
NetDDE
NetDDEdsdm
Netlogon
NtLmSsp
NtmsSvc
ose
RasAuto
RDSessMgr
RemoteAccess
RpcLocator
RSVP
SCardSvr
SSDPSRV
stisvc
SwPrv
SysmonLog
TlntSvr
TuneUp.Defrag
upnphost
UPS
VSS
WmdmPmSN
Wmi
WmiApSrv
xmlprov


Files Created/Modified - 60 Days:


C:\

13 Jun 2008 11.20.18 0 A.... "C:\AUTOEXEC.BAT"
13 Jun 2008 11.14.38 211 ..SH. "C:\boot.ini"
13 Jun 2008 11.20.18 0 A.... "C:\CONFIG.SYS"
13 Jun 2008 11.20.18 0 A.SHR "C:\IO.SYS"
13 Jun 2008 11.20.18 0 A.SHR "C:\MSDOS.SYS"
27 Jul 2008 0.14.24 2 145 386 496 A.SH. "C:\pagefile.sys"
26 Jul 2008 17.28.34 1 755 A.... "C:\rapport.txt"


C:\WINDOWS\

27 Jul 2008 0.14.30 0 A.... "C:\WINDOWS\0.log"
27 Jul 2008 0.14.28 2 048 A.S.. "C:\WINDOWS\bootstat.dat"
13 Jun 2008 11.20.18 0 A.... "C:\WINDOWS\control.ini"
22 Jul 2008 22.21.04 116 A.... "C:\WINDOWS\NeroDigital.ini"
13 Jun 2008 14.35.20 0 A.... "C:\WINDOWS\nsreg.dat"
26 Jul 2008 17.17.38 82 166 A.... "C:\WINDOWS\ntbtlog.txt"
13 Jun 2008 14.28.34 390 A.... "C:\WINDOWS\ODBC.INI"
13 Jun 2008 11.20.00 4 249 A.... "C:\WINDOWS\ODBCINST.INI"
27 Jun 2008 6.42.48 1 409 A.... "C:\WINDOWS\QTFont.for"
27 Jun 2008 6.42.48 54 156 A..H. "C:\WINDOWS\QTFont.qfn"
13 Jun 2008 11.23.38 8 192 A.... "C:\WINDOWS\REGLOCS.OLD"
26 Jul 2008 18.51.58 13 364 A.... "C:\WINDOWS\SchedLgU.Txt"
26 Jul 2008 17.27.58 180 A.... "C:\WINDOWS\setupact.log"
26 Jul 2008 17.27.16 0 A.... "C:\WINDOWS\setuperr.log"
13 Jun 2008 14.50.38 9 419 A.... "C:\WINDOWS\system.ini"
13 Jun 2008 11.16.42 36 A.... "C:\WINDOWS\vb.ini"
13 Jun 2008 11.16.42 37 A.... "C:\WINDOWS\vbaddin.ini"
13 Jun 2008 14.28.18 573 A.... "C:\WINDOWS\win.ini"
20 Jul 2008 15.49.28 1 061 A.... "C:\WINDOWS\wincmd.ini"
27 Jul 2008 0.16.12 1 343 141 A.... "C:\WINDOWS\WindowsUpdate.log"
13 Jun 2008 11.19.04 749 A..HR "C:\WINDOWS\WindowsShell.Manifest"
13 Jun 2008 14.44.04 316 640 A.... "C:\WINDOWS\WMSysPr9.prx"
13 Jun 2008 17.22.16 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00013"
13 Jun 2008 17.22.16 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00014"
13 Jun 2008 17.22.16 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00015"
13 Jun 2008 17.22.16 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00016"
13 Jun 2008 17.22.16 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00017"
13 Jun 2008 17.22.16 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00018"
13 Jun 2008 17.22.16 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00019"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00020"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00021"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00022"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00023"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00024"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00025"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00026"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00027"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00028"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00029"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00030"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00031"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00032"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00033"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00034"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00035"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00036"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00037"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00038"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00039"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00040"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00041"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00042"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00043"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00044"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00045"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00046"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00047"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00048"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00051"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00052"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00053"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00054"
13 Jun 2008 17.22.18 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00055"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00056"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00057"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00058"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00059"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00060"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00061"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00062"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00063"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00064"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00065"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00066"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00067"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00068"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00069"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00070"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00071"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00072"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00073"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00074"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00075"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00076"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00077"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00078"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00079"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00080"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00081"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00082"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00083"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00084"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00085"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00086"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00087"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00088"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00089"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00090"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00091"
13 Jun 2008 17.22.20 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00092"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00093"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00094"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00095"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00096"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00097"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00098"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00099"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00100"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00101"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00102"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00103"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00104"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00105"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00106"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00107"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00108"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00109"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00110"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00111"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00112"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00113"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00114"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00115"
13 Jun 2008 17.22.22 8 192 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00116"
13 Jun 2008 18.36.44 28 672 A.... "C:\WINDOWS\$NtUninstallKB950760$\reg00001"
13 Jun 2008 18.42.16 8 192 A.... "C:\WINDOWS\$NtUninstallKB924496$\reg00001"
13 Jun 2008 18.42.16 8 192 A.... "C:\WINDOWS\$NtUninstallKB924496$\reg00002"
13 Jun 2008 18.42.16 8 192 A.... "C:\WINDOWS\$NtUninstallKB924496$\reg00003"
13 Jun 2008 18.42.16 8 192 A.... "C:\WINDOWS\$NtUninstallKB924496$\reg00004"
13 Jun 2008 18.42.18 8 192 A.... "C:\WINDOWS\$NtUninstallKB924496$\reg00005"
13 Jun 2008 18.42.18 8 192 A.... "C:\WINDOWS\$NtUninstallKB924496$\reg00006"
13 Jun 2008 18.39.32 8 192 A.... "C:\WINDOWS\$NtUninstallKB890046$\reg00001"
13 Jun 2008 18.41.36 8 192 A.... "C:\WINDOWS\$NtUninstallKB896358$\reg00001"
13 Jun 2008 18.41.36 8 192 A.... "C:\WINDOWS\$NtUninstallKB896358$\reg00002"
13 Jun 2008 18.41.36 8 192 A.... "C:\WINDOWS\$NtUninstallKB896358$\reg00003"
13 Jun 2008 18.41.36 8 192 A.... "C:\WINDOWS\$NtUninstallKB896358$\reg00004"
13 Jun 2008 18.37.56 8 192 A.... "C:\WINDOWS\$NtUninstallKB950759$\reg00003"
13 Jun 2008 18.37.56 8 192 A.... "C:\WINDOWS\$NtUninstallKB950759$\reg00004"
13 Jun 2008 18.37.56 8 192 A.... "C:\WINDOWS\$NtUninstallKB950759$\reg00006"
13 Jun 2008 18.37.56 8 192 A.... "C:\WINDOWS\$NtUninstallKB950759$\reg00007"
13 Jun 2008 18.37.56 8 192 A.... "C:\WINDOWS\$NtUninstallKB950759$\reg00010"
13 Jun 2008 18.37.56 8 192 A.... "C:\WINDOWS\$NtUninstallKB950759$\reg00011"
13 Jun 2008 18.37.56 8 192 A.... "C:\WINDOWS\$NtUninstallKB950759$\reg00012"
13 Jun 2008 18.37.58 8 192 A.... "C:\WINDOWS\$NtUninstallKB950759$\reg00013"
13 Jun 2008 18.37.58 8 192 A.... "C:\WINDOWS\$NtUninstallKB950759$\reg00014"
13 Jun 2008 18.37.58 8 192 A.... "C:\WINDOWS\$NtUninstallKB950759$\reg00015"
13 Jun 2008 18.37.58 8 192 A.... "C:\WINDOWS\$NtUninstallKB950759$\reg00016"
13 Jun 2008 18.37.58 8 192 A.... "C:\WINDOWS\$NtUninstallKB950759$\reg00017"
13 Jun 2008 18.37.58 8 192 A.... "C:\WINDOWS\$NtUninstallKB950759$\reg00018"
13 Jun 2008 18.37.58 8 192 A.... "C:\WINDOWS\$NtUninstallKB950759$\reg00019"
13 Jun 2008 18.37.58 32 768 A.... "C:\WINDOWS\$NtUninstallKB950759$\reg00022"
13 Jun 2008 18.43.40 32 768 A.... "C:\WINDOWS\$NtUninstallKB933729$\reg00001"
13 Jun 2008 18.33.34 8 192 A.... "C:\WINDOWS\$NtUninstallKB928843$\reg00001"
13 Jun 2008 18.33.34 8 192 A.... "C:\WINDOWS\$NtUninstallKB928843$\reg00002"
26 Jul 2008 17.12.36 64 A.S.. "C:\WINDOWS\CSC\00000001"
26 Jul 2008 17.12.36 64 A.S.. "C:\WINDOWS\CSC\00000002"
27 Jul 2008 0.14.28 0 A.... "C:\WINDOWS\Debug\PASSWD.LOG"
13 Jun 2008 11.19.10 65 ...H. "C:\WINDOWS\Downloaded Program Files\desktop.ini"
13 Jun 2008 11.19.48 67 A.SH. "C:\WINDOWS\Fonts\desktop.ini"
13 Jun 2008 11.33.32 17 152 A.... "C:\WINDOWS\inf\1394.PNF"
13 Jun 2008 11.33.32 5 668 A.... "C:\WINDOWS\inf\1394vdbg.PNF"
13 Jun 2008 11.33.32 28 852 A.... "C:\WINDOWS\inf\3dfxvs2k.PNF"
13 Jun 2008 11.33.32 7 256 A.... "C:\WINDOWS\inf\61883.PNF"
13 Jun 2008 11.42.10 5 664 A.... "C:\WINDOWS\inf\855.PNF"
13 Jun 2008 11.33.32 48 740 A.... "C:\WINDOWS\inf\accessor.PNF"
13 Jun 2008 11.33.32 10 300 A.... "C:\WINDOWS\inf\acerscan.PNF"
13 Jun 2008 11.33.32 12 512 A.... "C:\WINDOWS\inf\acpi.PNF"
13 Jun 2008 11.33.32 8 240 A.... "C:\WINDOWS\inf\adm_mult.PNF"
13 Jun 2008 11.33.32 6 492 A.... "C:\WINDOWS\inf\adm_port.PNF"
13 Jun 2008 14.20.22 13 778 A.... "C:\WINDOWS\inf\AegisP.inf"
13 Jun 2008 14.20.22 9 968 A.... "C:\WINDOWS\inf\AegisP.PNF"
13 Jun 2008 11.33.32 10 800 A.... "C:\WINDOWS\inf\agp.PNF"
13 Jun 2008 11.33.32 17 232 A.... "C:\WINDOWS\inf\agtinst.PNF"
13 Jun 2008 11.33.32 8 428 A.... "C:\WINDOWS\inf\apcompat.PNF"
13 Jun 2008 11.33.32 2 856 A.... "C:\WINDOWS\inf\appmig.PNF"
13 Jun 2008 11.33.32 109 260 A.... "C:\WINDOWS\inf\apps.PNF"
13 Jun 2008 11.33.34 3 236 A.... "C:\WINDOWS\inf\asroc.PNF"
13 Jun 2008 11.33.34 13 628 A.... "C:\WINDOWS\inf\asynceqn.PNF"
13 Jun 2008 11.33.34 43 280 A.... "C:\WINDOWS\inf\ati1xwdm.PNF"
13 Jun 2008 11.33.34 29 012 A.... "C:\WINDOWS\inf\atiixpaa.PNF"
13 Jun 2008 11.33.34 94 532 A.... "C:\WINDOWS\inf\atiixpag.PNF"
13 Jun 2008 11.33.34 29 332 A.... "C:\WINDOWS\inf\atim128.PNF"
13 Jun 2008 11.33.34 38 660 A.... "C:\WINDOWS\inf\atimpab.PNF"
13 Jun 2008 11.33.34 9 428 A.... "C:\WINDOWS\inf\atirage3.PNF"
13 Jun 2008 11.33.34 41 732 A.... "C:\WINDOWS\inf\atividin.PNF"
13 Jun 2008 11.33.34 45 784 A.... "C:\WINDOWS\inf\atixpwdm.PNF"
13 Jun 2008 11.33.34 14 788 A.... "C:\WINDOWS\inf\au.PNF"
13 Jun 2008 11.33.34 9 596 A.... "C:\WINDOWS\inf\avc.PNF"
13 Jun 2008 11.33.34 33 304 A.... "C:\WINDOWS\inf\avmisdn.PNF"
13 Jun 2008 11.33.36 4 428 A.... "C:\WINDOWS\inf\axant5.PNF"
13 Jun 2008 11.33.36 9 908 A.... "C:\WINDOWS\inf\banshee.PNF"
13 Jun 2008 11.33.36 13 416 A.... "C:\WINDOWS\inf\battery.PNF"
13 Jun 2008 11.33.36 20 252 A.... "C:\WINDOWS\inf\bda.PNF"
13 Jun 2008 11.33.36 69 256 A.... "C:\WINDOWS\inf\biosinfo.PNF"
20 Jun 2008 19.57.22 926 ..... "C:\WINDOWS\inf\branches.inf"
18 Jul 2008 19.25.12 4 676 A.... "C:\WINDOWS\inf\branches.PNF"
13 Jun 2008 11.33.36 47 528 A.... "C:\WINDOWS\inf\brmfcmdm.PNF"
13 Jun 2008 11.33.36 66 240 A.... "C:\WINDOWS\inf\brmfcmf.PNF"
13 Jun 2008 11.33.36 8 924 A.... "C:\WINDOWS\inf\brmfcsto.PNF"
13 Jun 2008 11.33.36 8 656 A.... "C:\WINDOWS\inf\brmfcumd.PNF"
13 Jun 2008 11.33.36 37 384 A.... "C:\WINDOWS\inf\brmfcwia.PNF"
13 Jun 2008 11.33.36 15 312 A.... "C:\WINDOWS\inf\brmfport.PNF"
13 Jun 2008 11.33.36 25 924 A.... "C:\WINDOWS\inf\bth.PNF"
13 Jun 2008 11.33.36 8 032 A.... "C:\WINDOWS\inf\bthpan.PNF"
13 Jun 2008 11.33.36 6 256 A.... "C:\WINDOWS\inf\bthprint.PNF"
13 Jun 2008 11.33.36 6 060 A.... "C:\WINDOWS\inf\bthspp.PNF"
13 Jun 2008 11.33.36 11 180 A.... "C:\WINDOWS\inf\camdsh20.PNF"
13 Jun 2008 11.33.36 17 268 A.... "C:\WINDOWS\inf\camvid20.PNF"
13 Jun 2008 11.33.36 16 020 A.... "C:\WINDOWS\inf\camvid30.PNF"
13 Jun 2008 11.33.36 9 668 A.... "C:\WINDOWS\inf\ccdecode.PNF"
13 Jun 2008 11.33.36 56 772 A.... "C:\WINDOWS\inf\cdrom.PNF"
13 Jun 2008 11.33.26 7 800 A.... "C:\WINDOWS\inf\certclas.PNF"
13 Jun 2008 14.43.48 13 082 A.... "C:\WINDOWS\inf\codecs10.PNF"
13 Jun 2008 11.33.36 17 524 A.... "C:\WINDOWS\inf\communic.PNF"
13 Jun 2008 11.33.38 135 668 A.... "C:\WINDOWS\inf\comnt5.PNF"
13 Jun 2008 11.33.38 31 012 A.... "C:\WINDOWS\inf\corelist.PNF"
13 Jun 2008 11.33.38 16 972 A.... "C:\WINDOWS\inf\cpu.PNF"
13 Jun 2008 11.33.38 21 512 A.... "C:\WINDOWS\inf\ctmaport.PNF"
13 Jun 2008 11.33.38 6 732 A.... "C:\WINDOWS\inf\cyclad-z.PNF"
13 Jun 2008 11.33.38 6 872 A.... "C:\WINDOWS\inf\cyclom-y.PNF"
13 Jun 2008 11.33.38 13 352 A.... "C:\WINDOWS\inf\cyyport.PNF"
13 Jun 2008 11.33.38 21 792 A.... "C:\WINDOWS\inf\cyzport.PNF"
13 Jun 2008 11.33.38 322 880 A.... "C:\WINDOWS\inf\defltwk.PNF"
13 Jun 2008 11.33.38 39 644 A.... "C:\WINDOWS\inf\devxprop.PNF"
13 Jun 2008 11.33.38 6 636 A.... "C:\WINDOWS\inf\dfrg.PNF"
13 Jun 2008 11.33.40 41 668 A.... "C:\WINDOWS\inf\dgaport.PNF"
13 Jun 2008 11.33.40 21 904 A.... "C:\WINDOWS\inf\dgasync.PNF"
13 Jun 2008 11.33.40 6 424 A.... "C:\WINDOWS\inf\digiasyn.PNF"
13 Jun 2008 11.33.40 8 416 A.... "C:\WINDOWS\inf\digiisdn.PNF"
13 Jun 2008 11.33.40 16 384 A.... "C:\WINDOWS\inf\digimps.PNF"
13 Jun 2008 11.33.40 7 996 A.... "C:\WINDOWS\inf\digirp.PNF"
13 Jun 2008 11.33.40 8 168 A.... "C:\WINDOWS\inf\digirprt.PNF"
13 Jun 2008 14.34.56 7 620 A.... "C:\WINDOWS\inf\Digita.usbscan.PNF"
13 Jun 2008 11.33.40 27 876 A.... "C:\WINDOWS\inf\dimaps.PNF"
13 Jun 2008 11.33.40 12 240 A.... "C:\WINDOWS\inf\disk.PNF"
13 Jun 2008 11.33.40 54 260 A.... "C:\WINDOWS\inf\display.PNF"
13 Jun 2008 11.33.40 33 636 A.... "C:\WINDOWS\inf\divac.PNF"
13 Jun 2008 11.33.40 23 804 A.... "C:\WINDOWS\inf\divasrv.PNF"
13 Jun 2008 11.33.40 67 912 A.... "C:\WINDOWS\inf\dot4.PNF"
13 Jun 2008 11.33.40 6 476 A.... "C:\WINDOWS\inf\dot4prt.PNF"
13 Jun 2008 11.33.40 4 084 A.... "C:\WINDOWS\inf\drm.PNF"
13 Jun 2008 14.43.42 6 770 A.... "C:\WINDOWS\inf\DRM10.PNF"
13 Jun 2008 14.17.40 222 180 A.... "C:\WINDOWS\inf\drvindex.PNF"
13 Jun 2008 11.33.42 8 760 A.... "C:\WINDOWS\inf\dshowext.PNF"
13 Jun 2008 11.33.42 10 168 A.... "C:\WINDOWS\inf\dtcnt5.PNF"
13 Jun 2008 11.33.42 26 660 A.... "C:\WINDOWS\inf\dvd.PNF"
13 Jun 2008 11.33.42 330 524 A.... "C:\WINDOWS\inf\dwup.PNF"
13 Jun 2008 11.33.42 6 092 A.... "C:\WINDOWS\inf\enum1394.PNF"
13 Jun 2008 11.33.42 5 888 A.... "C:\WINDOWS\inf\epcfw2k.PNF"
13 Jun 2008 11.33.42 11 416 A.... "C:\WINDOWS\inf\epsnmfp.PNF"
13 Jun 2008 11.33.42 45 672 A.... "C:\WINDOWS\inf\epsnscan.PNF"
13 Jun 2008 11.33.42 5 864 A.... "C:\WINDOWS\inf\epstw2k.PNF"
13 Jun 2008 11.33.42 6 584 A.... "C:\WINDOWS\inf\eqnport.PNF"
13 Jun 2008 11.33.42 8 116 A.... "C:\WINDOWS\inf\fdc.PNF"
13 Jun 2008 11.33.42 23 988 A.... "C:\WINDOWS\inf\fjtscan.PNF"
13 Jun 2008 11.33.42 11 420 A.... "C:\WINDOWS\inf\flash.PNF"
13 Jun 2008 11.33.42 8 616 A.... "C:\WINDOWS\inf\flpydisk.PNF"
13 Jun 2008 11.33.42 5 020 A.... "C:\WINDOWS\inf\fltmgr.PNF"
13 Jun 2008 11.26.42 62 380 A.... "C:\WINDOWS\inf\font.PNF"
13 Jun 2008 11.26.16 17 704 A.... "C:\WINDOWS\inf\fp40ext.PNF"
13 Jun 2008 11.33.42 8 708 A.... "C:\WINDOWS\inf\fsvga.PNF"
13 Jun 2008 11.33.42 2 648 A.... "C:\WINDOWS\inf\fsvgaadd.PNF"
13 Jun 2008 11.33.42 2 648 A.... "C:\WINDOWS\inf\fsvgadel.PNF"
13 Jun 2008 11.33.42 56 640 A.... "C:\WINDOWS\inf\fxsocm.PNF"
13 Jun 2008 11.33.44 11 868 A.... "C:\WINDOWS\inf\g200.PNF"
13 Jun 2008 11.33.44 12 836 A.... "C:\WINDOWS\inf\g400.PNF"
13 Jun 2008 11.33.44 14 232 A.... "C:\WINDOWS\inf\gameport.PNF"
13 Jun 2008 11.33.44 15 156 A.... "C:\WINDOWS\inf\games.PNF"
13 Jun 2008 11.33.44 5 844 A.... "C:\WINDOWS\inf\genprint.PNF"
13 Jun 2008 11.33.44 11 836 A.... "C:\WINDOWS\inf\hal.PNF"
13 Jun 2008 11.33.44 7 788 A.... "C:\WINDOWS\inf\hidbth.PNF"
13 Jun 2008 11.33.44 9 476 A.... "C:\WINDOWS\inf\HidDigi.PNF"
13 Jun 2008 11.33.44 13 576 A.... "C:\WINDOWS\inf\hidserv.PNF"
13 Jun 2008 11.33.44 7 080 A.... "C:\WINDOWS\inf\hpdigwia.PNF"
13 Jun 2008 11.33.44 23 060 A.... "C:\WINDOWS\inf\hpojscan.PNF"
13 Jun 2008 11.33.44 41 164 A.... "C:\WINDOWS\inf\hpscan.PNF"
13 Jun 2008 11.33.44 8 996 A.... "C:\WINDOWS\inf\i740nt5.PNF"
13 Jun 2008 11.33.44 18 084 A.... "C:\WINDOWS\inf\i81xnt5.PNF"
13 Jun 2008 11.33.44 8 072 A.... "C:\WINDOWS\inf\ibmvcap.PNF"
13 Jun 2008 11.33.44 13 148 A.... "C:\WINDOWS\inf\icam3.PNF"
13 Jun 2008 11.33.44 17 876 A.... "C:\WINDOWS\inf\icam4usb.PNF"
13 Jun 2008 11.33.44 13 708 A.... "C:\WINDOWS\inf\icam5usb.PNF"
13 Jun 2008 11.42.06 6 648 A.... "C:\WINDOWS\inf\ich4core.PNF"
13 Jun 2008 11.42.04 5 680 A.... "C:\WINDOWS\inf\ich4ide.PNF"
13 Jun 2008 11.42.00 5 544 A.... "C:\WINDOWS\inf\ich4usb.PNF"
13 Jun 2008 11.33.44 3 260 A.... "C:\WINDOWS\inf\icminst.PNF"
13 Jun 2008 11.33.44 15 512 A.... "C:\WINDOWS\inf\icwnt5.PNF"
13 Jun 2008 11.33.44 84 144 A.... "C:\WINDOWS\inf\ie.PNF"
13 Jun 2008 11.33.46 4 480 A.... "C:\WINDOWS\inf\ieaccess.PNF"
13 Jun 2008 11.33.46 5 752 A.... "C:\WINDOWS\inf\iereset.PNF"
13 Jun 2008 11.33.46 13 292 A.... "C:\WINDOWS\inf\igames.PNF"
13 Jun 2008 11.33.46 977 820 A.... "C:\WINDOWS\inf\iis.PNF"
13 Jun 2008 11.33.46 22 908 A.... "C:\WINDOWS\inf\image.PNF"
13 Jun 2008 11.33.46 105 472 A.... "C:\WINDOWS\inf\ims.PNF"
13 Jun 2008 17.04.48 1 391 480 A.... "C:\WINDOWS\inf\INFCACHE.1"
13 Jun 2008 11.33.46 103 188 A.... "C:\WINDOWS\inf\input.PNF"
13 Jun 2008 11.33.46 456 272 A.... "C:\WINDOWS\inf\intl.PNF"
13 Jun 2008 11.33.46 18 872 A.... "C:\WINDOWS\inf\irbus.PNF"
13 Jun 2008 11.33.46 8 948 A.... "C:\WINDOWS\inf\irdaalif.PNF"
13 Jun 2008 11.33.46 15 608 A.... "C:\WINDOWS\inf\irdasmc.PNF"
13 Jun 2008 11.33.46 8 988 A.... "C:\WINDOWS\inf\irmk7w2k.PNF"
13 Jun 2008 11.33.46 26 988 A.... "C:\WINDOWS\inf\irnsc.PNF"
13 Jun 2008 11.33.48 9 172 A.... "C:\WINDOWS\inf\irstusb.PNF"
13 Jun 2008 11.33.48 11 892 A.... "C:\WINDOWS\inf\irtos4mo.PNF"
13 Jun 2008 11.33.48 22 640 A.... "C:\WINDOWS\inf\kdk2x0.PNF"
13 Jun 2008 11.33.48 10 808 A.... "C:\WINDOWS\inf\kdkscan.PNF"
13 Jun 2008 11.33.48 59 092 A.... "C:\WINDOWS\inf\keyboard.PNF"
13 Jun 2008 11.33.48 10 268 A.... "C:\WINDOWS\inf\kodak.PNF"
13 Jun 2008 11.33.28 93 340 A.... "C:\WINDOWS\inf\ks.PNF"
13 Jun 2008 11.33.48 43 628 A.... "C:\WINDOWS\inf\kscaptur.PNF"
13 Jun 2008 11.33.48 24 696 A.... "C:\WINDOWS\inf\ksfilter.PNF"
13 Jun 2008 11.26.06 1 041 744 A.... "C:\WINDOWS\inf\LAYOUT.PNF"
13 Jun 2008 11.33.48 3 972 A.... "C:\WINDOWS\inf\legcydrv.PNF"
13 Jun 2008 11.33.48 13 944 A.... "C:\WINDOWS\inf\lwngmadi.PNF"
13 Jun 2008 11.33.48 18 680 A.... "C:\WINDOWS\inf\lwusbhid.PNF"
13 Jun 2008 11.33.48 196 940 A.... "C:\WINDOWS\inf\machine.PNF"
13 Jun 2008 11.33.48 30 264 A.... "C:\WINDOWS\inf\mchgr.PNF"
13 Jun 2008 11.33.48 17 572 A.... "C:\WINDOWS\inf\mdac.PNF"
13 Jun 2008 11.33.48 97 624 A.... "C:\WINDOWS\inf\mdm3com.PNF"
13 Jun 2008 11.33.48 49 072 A.... "C:\WINDOWS\inf\mdm3cpcm.PNF"
13 Jun 2008 11.33.48 99 404 A.... "C:\WINDOWS\inf\mdm3mini.PNF"
13 Jun 2008 11.33.50 43 708 A.... "C:\WINDOWS\inf\mdm5674a.PNF"
13 Jun 2008 11.33.50 56 852 A.... "C:\WINDOWS\inf\mdm656n5.PNF"
13 Jun 2008 11.33.50 15 036 A.... "C:\WINDOWS\inf\mdmadc.PNF"
13 Jun 2008 11.33.50 8 824 A.... "C:\WINDOWS\inf\mdmairte.PNF"
13 Jun 2008 11.33.50 23 988 A.... "C:\WINDOWS\inf\mdmaiwa.PNF"
13 Jun 2008 11.33.50 18 488 A.... "C:\WINDOWS\inf\mdmaiwa3.PNF"
13 Jun 2008 11.33.50 105 104 A.... "C:\WINDOWS\inf\mdmaiwa4.PNF"
13 Jun 2008 11.33.50 26 676 A.... "C:\WINDOWS\inf\mdmaiwa5.PNF"
13 Jun 2008 11.33.50 10 968 A.... "C:\WINDOWS\inf\mdmaiwat.PNF"
13 Jun 2008 11.33.50 15 528 A.... "C:\WINDOWS\inf\mdmar1.PNF"
13 Jun 2008 11.33.50 43 228 A.... "C:\WINDOWS\inf\mdmarch.PNF"
13 Jun 2008 11.33.50 16 420 A.... "C:\WINDOWS\inf\mdmarn.PNF"
13 Jun 2008 11.33.50 77 752 A.... "C:\WINDOWS\inf\mdmati.PNF"
13 Jun 2008 11.33.50 19 568 A.... "C:\WINDOWS\inf\mdmatm2k.PNF"
13 Jun 2008 11.33.52 34 212 A.... "C:\WINDOWS\inf\mdmatt.PNF"
13 Jun 2008 11.33.52 21 376 A.... "C:\WINDOWS\inf\mdmaus.PNF"
13 Jun 2008 11.33.52 81 048 A.... "C:\WINDOWS\inf\mdmbcmsm.PNF"
13 Jun 2008 11.33.52 64 292 A.... "C:\WINDOWS\inf\mdmboca.PNF"
13 Jun 2008 11.33.52 23 888 A.... "C:\WINDOWS\inf\mdmbsb.PNF"
13 Jun 2008 11.33.52 40 720 A.... "C:\WINDOWS\inf\mdmbtmdm.PNF"
13 Jun 2008 11.33.52 10 516 A.... "C:\WINDOWS\inf\mdmbug3.PNF"
13 Jun 2008 11.33.52 26 316 A.... "C:\WINDOWS\inf\mdmbw561.PNF"
13 Jun 2008 11.33.52 22 428 A.... "C:\WINDOWS\inf\mdmc26a.PNF"
13 Jun 2008 11.33.52 12 544 A.... "C:\WINDOWS\inf\mdmcdp.PNF"
13 Jun 2008 11.33.52 2 312 A.... "C:\WINDOWS\inf\mdmchipv.PNF"
13 Jun 2008 11.33.54 91 508 A.... "C:\WINDOWS\inf\mdmcm28.PNF"
13 Jun 2008 11.33.54 24 468 A.... "C:\WINDOWS\inf\mdmcodex.PNF"
13 Jun 2008 11.33.54 43 240 A.... "C:\WINDOWS\inf\mdmcom1.PNF"
13 Jun 2008 11.33.54 10 456 A.... "C:\WINDOWS\inf\mdmcommu.PNF"
13 Jun 2008 11.33.54 12 528 A.... "C:\WINDOWS\inf\mdmcomp.PNF"
13 Jun 2008 11.33.54 136 128 A.... "C:\WINDOWS\inf\mdmcpq.PNF"
13 Jun 2008 11.33.56 47 576 A.... "C:\WINDOWS\inf\mdmcpq2.PNF"
13 Jun 2008 11.33.56 13 828 A.... "C:\WINDOWS\inf\mdmcpv.PNF"
13 Jun 2008 11.33.56 21 372 A.... "C:\WINDOWS\inf\mdmcrtix.PNF"
13 Jun 2008 11.33.56 68 340 A.... "C:\WINDOWS\inf\mdmcxsf2.PNF"
13 Jun 2008 11.33.56 628 064 ..... "C:\WINDOWS\inf\MDMCXSFT.PNF"
13 Jun 2008 11.33.56 77 992 A.... "C:\WINDOWS\inf\mdmdcm5.PNF"
13 Jun 2008 11.33.56 34 084 A.... "C:\WINDOWS\inf\mdmdcm6.PNF"
13 Jun 2008 11.33.56 24 624 A.... "C:\WINDOWS\inf\mdmdf56F.PNF"
13 Jun 2008 11.33.56 20 368 A.... "C:\WINDOWS\inf\mdmdgden.PNF"
13 Jun 2008 11.33.58 20 052 A.... "C:\WINDOWS\inf\mdmdgitn.PNF"
13 Jun 2008 11.33.58 31 784 A.... "C:\WINDOWS\inf\mdmdigi.PNF"
13 Jun 2008 11.33.58 17 500 A.... "C:\WINDOWS\inf\mdmdp2.PNF"
13 Jun 2008 11.33.58 169 544 A.... "C:\WINDOWS\inf\mdmdsi.PNF"
13 Jun 2008 11.33.58 57 164 A.... "C:\WINDOWS\inf\mdmdyna.PNF"
13 Jun 2008 11.33.58 30 596 A.... "C:\WINDOWS\inf\mdmeiger.PNF"
13 Jun 2008 11.33.58 115 112 A.... "C:\WINDOWS\inf\mdmelsa.PNF"
13 Jun 2008 11.33.58 20 192 A.... "C:\WINDOWS\inf\mdmeric.PNF"
13 Jun 2008 11.33.58 26 872 A.... "C:\WINDOWS\inf\mdmeric2.PNF"
13 Jun 2008 11.33.58 49 228 A.... "C:\WINDOWS\inf\mdmess.PNF"
13 Jun 2008 11.33.58 62 708 A.... "C:\WINDOWS\inf\mdmetech.PNF"
13 Jun 2008 11.33.58 47 316 A.... "C:\WINDOWS\inf\mdmexp.PNF"
13 Jun 2008 11.33.58 21 124 A.... "C:\WINDOWS\inf\mdmfj2.PNF"
13 Jun 2008 11.34.00 69 540 A.... "C:\WINDOWS\inf\mdmgatew.PNF"
13 Jun 2008 11.34.00 42 676 A.... "C:\WINDOWS\inf\mdmgcs.PNF"
13 Jun 2008 11.34.00 72 408 ..... "C:\WINDOWS\inf\MDMGEN.PNF"
13 Jun 2008 11.34.00 77 228 A.... "C:\WINDOWS\inf\mdmgl001.PNF"
13 Jun 2008 11.34.00 89 852 A.... "C:\WINDOWS\inf\mdmgl002.PNF"
13 Jun 2008 11.34.00 59 372 A.... "C:\WINDOWS\inf\mdmgl003.PNF"
13 Jun 2008 11.34.02 1 597 336 A.... "C:\WINDOWS\inf\mdmgl004.PNF"
13 Jun 2008 11.34.02 82 384 A.... "C:\WINDOWS\inf\mdmgl005.PNF"
13 Jun 2008 11.34.02 96 712 A.... "C:\WINDOWS\inf\mdmgl006.PNF"
13 Jun 2008 11.34.02 151 716 A.... "C:\WINDOWS\inf\mdmgl007.PNF"
13 Jun 2008 11.34.02 57 572 A.... "C:\WINDOWS\inf\mdmgl008.PNF"
13 Jun 2008 11.34.02 157 264 A.... "C:\WINDOWS\inf\mdmgl009.PNF"
13 Jun 2008 11.34.02 93 596 A.... "C:\WINDOWS\inf\mdmgl010.PNF"
13 Jun 2008 11.34.02 29 512 A.... "C:\WINDOWS\inf\mdmgsm.PNF"
13 Jun 2008 11.34.02 8 560 A.... "C:\WINDOWS\inf\mdmhaeu.PNF"
13 Jun 2008 11.34.04 152 828 A.... "C:\WINDOWS\inf\mdmhamrw.PNF"
13 Jun 2008 11.34.04 59 556 A.... "C:\WINDOWS\inf\mdmhandy.PNF"
13 Jun 2008 11.34.04 69 848 A.... "C:\WINDOWS\inf\mdmhay2.PNF"
13 Jun 2008 11.34.04 102 112 A.... "C:\WINDOWS\inf\mdmhayes.PNF"
13 Jun 2008 11.34.04 28 908 A.... "C:\WINDOWS\inf\mdminfot.PNF"
13 Jun 2008 11.34.04 27 208 A.... "C:\WINDOWS\inf\mdmintel.PNF"
13 Jun 2008 11.34.04 30 748 A.... "C:\WINDOWS\inf\mdmiodat.PNF"
13 Jun 2008 11.34.04 107 872 A.... "C:\WINDOWS\inf\mdmirmdm.PNF"
13 Jun 2008 11.34.04 58 752 A.... "C:\WINDOWS\inf\mdmisdn.PNF"
13 Jun 2008 11.34.04 25 996 A.... "C:\WINDOWS\inf\MDMJF56E.PNF"
13 Jun 2008 11.34.04 11 892 A.... "C:\WINDOWS\inf\mdmke.PNF"
13 Jun 2008 11.34.06 12 644 A.... "C:\WINDOWS\inf\mdmkortx.PNF"
13 Jun 2008 11.34.06 20 868 A.... "C:\WINDOWS\inf\mdmlasat.PNF"
13 Jun 2008 11.34.06 42 660 A.... "C:\WINDOWS\inf\mdmlasno.PNF"
13 Jun 2008 11.34.06 96 400 A.... "C:\WINDOWS\inf\mdmlt3.PNF"
13 Jun 2008 11.34.06 76 292 A.... "C:\WINDOWS\inf\mdmltleo.PNF"
13 Jun 2008 11.34.06 77 168 A.... "C:\WINDOWS\inf\mdmltsft.PNF"
13 Jun 2008 11.34.06 36 404 A.... "C:\WINDOWS\inf\mdmlucnt.PNF"
13 Jun 2008 11.34.06 16 504 A.... "C:\WINDOWS\inf\mdmmc288.PNF"
13 Jun 2008 11.34.06 11 504 A.... "C:\WINDOWS\inf\mdmmcd.PNF"
13 Jun 2008 11.34.06 64 544 A.... "C:\WINDOWS\inf\mdmmcom.PNF"
13 Jun 2008 11.34.06 63 176 A.... "C:\WINDOWS\inf\mdmmct.PNF"
13 Jun 2008 11.34.06 17 416 A.... "C:\WINDOWS\inf\mdmmega.PNF"
13 Jun 2008 11.34.06 110 412 A.... "C:\WINDOWS\inf\mdmmetri.PNF"
13 Jun 2008 11.34.08 74 120 A.... "C:\WINDOWS\inf\mdmmhrtz.PNF"
13 Jun 2008 11.34.08 92 092 A.... "C:\WINDOWS\inf\mdmmhza.PNF"
13 Jun 2008 11.34.08 199 760 A.... "C:\WINDOWS\inf\mdmmhzel.PNF"
13 Jun 2008 11.34.08 89 996 A.... "C:\WINDOWS\inf\mdmmhzk1.PNF"
13 Jun 2008 11.34.08 11 696 A.... "C:\WINDOWS\inf\mdmminij.PNF"
13 Jun 2008 11.34.08 18 540 A.... "C:\WINDOWS\inf\mdmmod.PNF"
13 Jun 2008 11.34.08 72 136 A.... "C:\WINDOWS\inf\mdmmoto.PNF"
13 Jun 2008 11.34.08 20 132 A.... "C:\WINDOWS\inf\mdmmoto1.PNF"
13 Jun 2008 11.34.08 8 864 A.... "C:\WINDOWS\inf\mdmmotou.PNF"
13 Jun 2008 11.34.08 81 760 A.... "C:\WINDOWS\inf\mdmmts.PNF"
13 Jun 2008 11.34.08 20 328 A.... "C:\WINDOWS\inf\mdmneuhs.PNF"
13 Jun 2008 11.34.08 11 268 A.... "C:\WINDOWS\inf\Mdmnis1u.PNF"
13 Jun 2008 11.34.10 11 340 A.... "C:\WINDOWS\inf\Mdmnis2u.PNF"
13 Jun 2008 11.34.10 10 364 A.... "C:\WINDOWS\inf\Mdmnis3t.PNF"
13 Jun 2008 11.34.10 10 340 A.... "C:\WINDOWS\inf\Mdmnis5t.PNF"
13 Jun 2008 11.34.10 13 244 A.... "C:\WINDOWS\inf\mdmnokia.PNF"
13 Jun 2008 11.34.10 20 216 A.... "C:\WINDOWS\inf\mdmnova.PNF"
13 Jun 2008 11.34.10 46 132 A.... "C:\WINDOWS\inf\mdmntstm.PNF"
13 Jun 2008 11.34.10 13 800 A.... "C:\WINDOWS\inf\mdmntt1.PNF"
13 Jun 2008 11.34.10 21 996 A.... "C:\WINDOWS\inf\mdmnttd2.PNF"
13 Jun 2008 11.34.10 22 004 A.... "C:\WINDOWS\inf\mdmnttd6.PNF"
13 Jun 2008 11.34.10 11 516 A.... "C:\WINDOWS\inf\mdmnttme.PNF"
13 Jun 2008 11.34.10 16 196 A.... "C:\WINDOWS\inf\mdmnttp.PNF"
13 Jun 2008 11.34.10 17 460 A.... "C:\WINDOWS\inf\mdmnttp2.PNF"
13 Jun 2008 11.34.10 10 572 A.... "C:\WINDOWS\inf\mdmnttte.PNF"
13 Jun 2008 11.34.10 19 048 A.... "C:\WINDOWS\inf\mdmolic.PNF"
13 Jun 2008 11.34.12 126 152 A.... "C:\WINDOWS\inf\mdmomrn3.PNF"
13 Jun 2008 11.34.12 11 480 A.... "C:\WINDOWS\inf\mdmoptn.PNF"
13 Jun 2008 11.34.12 49 096 A.... "C:\WINDOWS\inf\mdmosi.PNF"
13 Jun 2008 11.34.12 39 416 A.... "C:\WINDOWS\inf\mdmosice.PNF"
13 Jun 2008 11.34.12 27 860 A.... "C:\WINDOWS\inf\mdmpace.PNF"
13 Jun 2008 11.34.12 8 372 A.... "C:\WINDOWS\inf\mdmpbit.PNF"
13 Jun 2008 11.34.12 68 664 A.... "C:\WINDOWS\inf\mdmpctel.PNF"
13 Jun 2008 11.34.12 79 716 A.... "C:\WINDOWS\inf\mdmpenr.PNF"
13 Jun 2008 11.34.12 19 268 A.... "C:\WINDOWS\inf\mdmpin.PNF"
13 Jun 2008 11.34.12 10 424 A.... "C:\WINDOWS\inf\mdmpn1.PNF"
13 Jun 2008 11.34.12 57 224 A.... "C:\WINDOWS\inf\mdmpp.PNF"
13 Jun 2008 11.34.12 15 840 A.... "C:\WINDOWS\inf\mdmpsion.PNF"
13 Jun 2008 11.34.14 80 624 A.... "C:\WINDOWS\inf\mdmracal.PNF"
13 Jun 2008 11.34.14 6 776 A.... "C:\WINDOWS\inf\mdmrisa.PNF"
13 Jun 2008 11.34.14 23 712 A.... "C:\WINDOWS\inf\mdmrock.PNF"
13 Jun 2008 11.34.14 50 624 A.... "C:\WINDOWS\inf\mdmrock3.PNF"
13 Jun 2008 11.34.14 71 236 A.... "C:\WINDOWS\inf\mdmrock4.PNF"
13 Jun 2008 11.34.14 125 636 A.... "C:\WINDOWS\inf\mdmrock5.PNF"
13 Jun 2008 11.34.14 306 060 ..... "C:\WINDOWS\inf\MDMRPCI.PNF"
13 Jun 2008 11.34.16 1 536 452 ..... "C:\WINDOWS\inf\MDMRPCIW.PNF"
13 Jun 2008 11.34.16 4 000 A.... "C:\WINDOWS\inf\mdmsetup.PNF"
13 Jun 2008 11.34.16 6 076 A.... "C:\WINDOWS\inf\mdmsgsml.PNF"
13 Jun 2008 11.34.16 23 000 A.... "C:\WINDOWS\inf\mdmsgsmu.PNF"
13 Jun 2008 11.34.16 44 876 A.... "C:\WINDOWS\inf\mdmsier.PNF"
13 Jun 2008 11.34.16 23 408 A.... "C:\WINDOWS\inf\mdmsii64.PNF"
13 Jun 2008 11.34.16 23 608 A.... "C:\WINDOWS\inf\mdmsiil6.PNF"
13 Jun 2008 11.34.16 14 536 A.... "C:\WINDOWS\inf\mdmsmart.PNF"
13 Jun 2008 11.34.16 90 232 A.... "C:\WINDOWS\inf\mdmsonyu.PNF"
13 Jun 2008 11.34.16 76 068 A.... "C:\WINDOWS\inf\mdmspq28.PNF"
13 Jun 2008 11.34.18 11 292 A.... "C:\WINDOWS\inf\mdmsun1.PNF"
13 Jun 2008 11.34.18 34 272 A.... "C:\WINDOWS\inf\mdmsun2.PNF"
13 Jun 2008 11.34.18 45 896 A.... "C:\WINDOWS\inf\mdmsupr3.PNF"
13 Jun 2008 11.34.18 134 308 A.... "C:\WINDOWS\inf\mdmsupra.PNF"
13 Jun 2008 11.34.18 40 676 A.... "C:\WINDOWS\inf\mdmsuprv.PNF"
13 Jun 2008 11.34.18 65 804 A.... "C:\WINDOWS\inf\mdmtdk.PNF"
13 Jun 2008 11.34.18 27 016 A.... "C:\WINDOWS\inf\mdmtdkj2.PNF"
13 Jun 2008 11.34.18 26 716 A.... "C:\WINDOWS\inf\mdmtdkj3.PNF"
13 Jun 2008 11.34.18 24 516 A.... "C:\WINDOWS\inf\mdmtdkj4.PNF"
13 Jun 2008 11.34.18 29 708 A.... "C:\WINDOWS\inf\mdmtdkj5.PNF"
13 Jun 2008 11.34.18 17 320 A.... "C:\WINDOWS\inf\mdmtdkj6.PNF"
13 Jun 2008 11.34.18 20 260 A.... "C:\WINDOWS\inf\mdmtdkj7.PNF"
13 Jun 2008 11.34.18 16 332 A.... "C:\WINDOWS\inf\mdmtexas.PNF"
13 Jun 2008 11.34.18 53 880 A.... "C:\WINDOWS\inf\mdmti.PNF"
13 Jun 2008 11.34.20 53 128 A.... "C:\WINDOWS\inf\mdmtosh.PNF"
13 Jun 2008 11.34.20 23 188 A.... "C:\WINDOWS\inf\mdmtron.PNF"
13 Jun 2008 11.34.20 9 332 A.... "C:\WINDOWS\inf\mdmusrf.PNF"
13 Jun 2008 11.34.20 23 852 A.... "C:\WINDOWS\inf\mdmusrg.PNF"
13 Jun 2008 11.34.20 75 336 A.... "C:\WINDOWS\inf\mdmusrgl.PNF"
13 Jun 2008 11.34.20 74 520 A.... "C:\WINDOWS\inf\mdmusrk1.PNF"
13 Jun 2008 11.34.20 10 424 A.... "C:\WINDOWS\inf\mdmusrsp.PNF"
13 Jun 2008 11.34.20 8 224 A.... "C:\WINDOWS\inf\mdmvdot.PNF"
13 Jun 2008 11.34.20 26 836 A.... "C:\WINDOWS\inf\mdmvv.PNF"
13 Jun 2008 11.34.20 168 904 A.... "C:\WINDOWS\inf\mdmwhql0.PNF"
13 Jun 2008 11.34.20 71 144 A.... "C:\WINDOWS\inf\mdmx5560.PNF"
13 Jun 2008 11.34.20 76 812 A.... "C:\WINDOWS\inf\mdmxircc.PNF"
13 Jun 2008 11.34.22 74 036 A.... "C:\WINDOWS\inf\mdmxirmp.PNF"
13 Jun 2008 11.34.22 129 992 A.... "C:\WINDOWS\inf\mdmzoom.PNF"
13 Jun 2008 11.34.22 80 924 A.... "C:\WINDOWS\inf\mdmzyp.PNF"
13 Jun 2008 11.34.22 122 052 A.... "C:\WINDOWS\inf\mdmzyxel.PNF"
13 Jun 2008 11.34.22 134 964 A.... "C:\WINDOWS\inf\mdmzyxlg.PNF"
13 Jun 2008 11.34.22 106 528 A.... "C:\WINDOWS\inf\medctroc.PNF"
13 Jun 2008 11.34.22 17 300 A.... "C:\WINDOWS\inf\memcard.PNF"
13 Jun 2008 11.34.22 8 916 A.... "C:\WINDOWS\inf\memstpci.PNF"
13 Jun 2008 11.34.22 5 584 A.... "C:\WINDOWS\inf\mf.PNF"
13 Jun 2008 11.34.22 7 668 A.... "C:\WINDOWS\inf\mfcem28.PNF"
13 Jun 2008 11.34.22 7 396 A.... "C:\WINDOWS\inf\mfcem33.PNF"
13 Jun 2008 11.34.22 19 024 A.... "C:\WINDOWS\inf\mfcem56.PNF"
13 Jun 2008 11.34.24 9 704 A.... "C:\WINDOWS\inf\mff56n5.PNF"
13 Jun 2008 11.34.24 9 296 A.... "C:\WINDOWS\inf\mflm.PNF"
13 Jun 2008 11.34.24 9 712 A.... "C:\WINDOWS\inf\mflm56.PNF"
13 Jun 2008 11.34.24 11 076 A.... "C:\WINDOWS\inf\mfmhzn5.PNF"
13 Jun 2008 11.34.24 12 292 A.... "C:\WINDOWS\inf\mfosi5.PNF"
13 Jun 2008 11.34.24 9 604 A.... "C:\WINDOWS\inf\mfsocket.PNF"
13 Jun 2008 11.34.24 6 636 A.... "C:\WINDOWS\inf\mfsupra.PNF"
13 Jun 2008 11.34.24 9 460 A.... "C:\WINDOWS\inf\mfx56nf.PNF"
13 Jun 2008 11.34.24 10 004 A.... "C:\WINDOWS\inf\mgau.PNF"
13 Jun 2008 11.34.24 3 788 A.... "C:\WINDOWS\inf\minioc.PNF"
13 Jun 2008 11.34.24 42 740 A.... "C:\WINDOWS\inf\mmopt.PNF"
13 Jun 2008 11.34.24 11 836 A.... "C:\WINDOWS\inf\modemcsa.PNF"
13 Jun 2008 11.34.24 108 468 A.... "C:\WINDOWS\inf\monitor.PNF"
13 Jun 2008 11.34.24 101 148 A.... "C:\WINDOWS\inf\monitor2.PNF"
13 Jun 2008 11.34.24 89 384 A.... "C:\WINDOWS\inf\monitor3.PNF"
13 Jun 2008 11.34.26 86 844 A.... "C:\WINDOWS\inf\monitor4.PNF"
13 Jun 2008 11.34.26 120 616 A.... "C:\WINDOWS\inf\monitor5.PNF"
13 Jun 2008 11.34.26 94 420 A.... "C:\WINDOWS\inf\monitor6.PNF"
13 Jun 2008 11.34.26 88 208 A.... "C:\WINDOWS\inf\monitor7.PNF"
13 Jun 2008 11.34.26 112 360 A.... "C:\WINDOWS\inf\monitor8.PNF"
13 Jun 2008 11.34.26 15 196 A.... "C:\WINDOWS\inf\moviemk.PNF"
13 Jun 2008 14.44.48 5 322 A.... "C:\WINDOWS\inf\MPCD10.PNF"
13 Jun 2008 11.34.26 8 276 A.... "C:\WINDOWS\inf\mpe.PNF"
13 Jun 2008 11.34.26 30 924 A.... "C:\WINDOWS\inf\mplayer2.PNF"
13 Jun 2008 14.43.36 6 178 A.... "C:\WINDOWS\inf\MPPRE10.PNF"
13 Jun 2008 11.34.26 15 924 A.... "C:\WINDOWS\inf\mpsstln.PNF"
13 Jun 2008 14.44.50 5 346 A.... "C:\WINDOWS\inf\MPSTUB10.PNF"
13 Jun 2008 11.34.26 2 808 A.... "C:\WINDOWS\inf\mqsysoc.PNF"
13 Jun 2008 11.34.26 6 688 A.... "C:\WINDOWS\inf\mscpqpa1.PNF"
13 Jun 2008 11.34.26 39 292 A.... "C:\WINDOWS\inf\msdv.PNF"
13 Jun 2008 11.34.26 51 828 A.... "C:\WINDOWS\inf\mshdc.PNF"
13 Jun 2008 11.34.26 9 968 A.... "C:\WINDOWS\inf\msinfo32.PNF"
13 Jun 2008 11.34.26 63 560 A.... "C:\WINDOWS\inf\msmouse.PNF"
13 Jun 2008 11.34.28 13 688 A.... "C:\WINDOWS\inf\msmqocm.PNF"
13 Jun 2008 11.34.28 29 196 A.... "C:\WINDOWS\inf\msmscsi.PNF"
13 Jun 2008 11.26.08 87 736 A.... "C:\WINDOWS\inf\msmsgs.PNF"
13 Jun 2008 11.34.28 15 340 A.... "C:\WINDOWS\inf\msmusb.PNF"
13 Jun 2008 11.34.28 61 308 A.... "C:\WINDOWS\inf\msnetmtg.PNF"
13 Jun 2008 11.34.28 6 808 A.... "C:\WINDOWS\inf\msnike.PNF"
13 Jun 2008 11.34.28 7 548 A.... "C:\WINDOWS\inf\msnmsn.PNF"
13 Jun 2008 11.26.08 36 124 A.... "C:\WINDOWS\inf\msoe50.PNF"
13 Jun 2008 11.34.28 30 232 A.... "C:\WINDOWS\inf\msports.PNF"
13 Jun 2008 11.34.28 7 012 A.... "C:\WINDOWS\inf\msrio.PNF"
13 Jun 2008 11.34.28 6 928 A.... "C:\WINDOWS\inf\msrio8.PNF"
13 Jun 2008 11.34.28 24 088 A.... "C:\WINDOWS\inf\mstape.PNF"
13 Jun 2008 11.34.28 14 032 A.... "C:\WINDOWS\inf\mstask.PNF"
13 Jun 2008 11.34.28 8 720 A.... "C:\WINDOWS\inf\mtxvideo.PNF"
13 Jun 2008 11.34.28 12 288 A.... "C:\WINDOWS\inf\multimed.PNF"
13 Jun 2008 11.34.28 5 844 A.... "C:\WINDOWS\inf\multiprt.PNF"
13 Jun 2008 11.34.30 38 224 A.... "C:\WINDOWS\inf\mwavmdm1.PNF"
13 Jun 2008 11.34.30 8 508 A.... "C:\WINDOWS\inf\mwmbatam.PNF"
13 Jun 2008 11.34.30 16 924 A.... "C:\WINDOWS\inf\mwremove.PNF"
13 Jun 2008 11.34.30 54 832 A.... "C:\WINDOWS\inf\mwtpdsp.PNF"
13 Jun 2008 11.34.30 9 960 A.... "C:\WINDOWS\inf\mxboard.PNF"
13 Jun 2008 11.34.30 12 224 A.... "C:\WINDOWS\inf\mxport.PNF"
13 Jun 2008 11.34.30 7 848 A.... "C:\WINDOWS\inf\mymusic.PNF"
13 Jun 2008 11.34.30 9 652 A.... "C:\WINDOWS\inf\nabtsfec.PNF"
13 Jun 2008 11.34.30 9 088 A.... "C:\WINDOWS\inf\ndisip.PNF"
13 Jun 2008 11.34.30 5 864 A.... "C:\WINDOWS\inf\ndisuio.PNF"
13 Jun 2008 11.34.30 8 020 A.... "C:\WINDOWS\inf\neo20xx.PNF"
13 Jun 2008 11.34.30 6 236 A.... "C:\WINDOWS\inf\net10.PNF"
13 Jun 2008 11.34.30 6 356 A.... "C:\WINDOWS\inf\net1394.PNF"
13 Jun 2008 11.34.30 26 792 A.... "C:\WINDOWS\inf\net21x4.PNF"
13 Jun 2008 11.34.30 8 900 A.... "C:\WINDOWS\inf\net3c556.PNF"
13 Jun 2008 11.34.30 11 664 A.... "C:\WINDOWS\inf\net3c589.PNF"
13 Jun 2008 11.34.30 14 512 A.... "C:\WINDOWS\inf\net3c985.PNF"
13 Jun 2008 11.34.32 6 916 A.... "C:\WINDOWS\inf\net3sr.PNF"
13 Jun 2008 11.34.32 8 580 A.... "C:\WINDOWS\inf\net5515n.PNF"
13 Jun 2008 11.34.32 83 816 A.... "C:\WINDOWS\inf\net557.PNF"
13 Jun 2008 11.34.32 8 524 A.... "C:\WINDOWS\inf\net559ib.PNF"
13 Jun 2008 11.34.32 10 684 A.... "C:\WINDOWS\inf\net575nt.PNF"
13 Jun 2008 11.34.32 8 012 A.... "C:\WINDOWS\inf\net650d.PNF"
13 Jun 2008 11.34.32 9 244 A.... "C:\WINDOWS\inf\net656c5.PNF"
13 Jun 2008 11.34.32 10 924 A.... "C:\WINDOWS\inf\net656n5.PNF"
13 Jun 2008 11.34.32 8 620 A.... "C:\WINDOWS\inf\net713.PNF"
13 Jun 2008 11.34.32 16 204 A.... "C:\WINDOWS\inf\net83820.PNF"
13 Jun 2008 11.34.32 25 844 A.... "C:\WINDOWS\inf\net8511.PNF"
13 Jun 2008 11.34.32 7 748 A.... "C:\WINDOWS\inf\netali.PNF"
13 Jun 2008 11.34.32 6 568 A.... "C:\WINDOWS\inf\netambi.PNF"
13 Jun 2008 11.34.32 9 852 A.... "C:\WINDOWS\inf\netamd.PNF"
13 Jun 2008 11.34.32 18 088 A.... "C:\WINDOWS\inf\netamd2.PNF"
13 Jun 2008 11.34.32 10 488 A.... "C:\WINDOWS\inf\netamdhl.PNF"
13 Jun 2008 11.34.34 16 472 A.... "C:\WINDOWS\inf\netan983.PNF"
13 Jun 2008 11.34.34 12 252 A.... "C:\WINDOWS\inf\netana.PNF"
13 Jun 2008 11.34.34 12 056 A.... "C:\WINDOWS\inf\netasp2k.PNF"
13 Jun 2008 11.34.34 6 656 A.... "C:\WINDOWS\inf\netauni.PNF"
13 Jun 2008 11.34.34 35 248 A.... "C:\WINDOWS\inf\netb57xp.PNF"
13 Jun 2008 11.34.34 8 884 A.... "C:\WINDOWS\inf\netbcm4e.PNF"
13 Jun 2008 11.34.34 9 440 A.... "C:\WINDOWS\inf\netbcm4p.PNF"
13 Jun 2008 11.34.34 8 824 A.... "C:\WINDOWS\inf\netbcm4u.PNF"
13 Jun 2008 11.34.34 3 652 A.... "C:\WINDOWS\inf\netbeac.PNF"
13 Jun 2008 11.34.34 5 896 A.... "C:\WINDOWS\inf\netbrdgm.PNF"
13 Jun 2008 11.34.34 5 484 A.... "C:\WINDOWS\inf\netbrdgs.PNF"
13 Jun 2008 11.34.34 12 612 A.... "C:\WINDOWS\inf\netbrzw.PNF"
13 Jun 2008 11.34.34 8 892 A.... "C:\WINDOWS\inf\netcb102.PNF"
13 Jun 2008 11.34.34 14 996 A.... "C:\WINDOWS\inf\netcb325.PNF"
13 Jun 2008 11.34.34 16 708 A.... "C:\WINDOWS\inf\netcbe.PNF"
13 Jun 2008 11.34.36 10 152 A.... "C:\WINDOWS\inf\netce2.PNF"
13 Jun 2008 11.34.36 14 776 A.... "C:\WINDOWS\inf\netce3.PNF"
13 Jun 2008 11.34.36 9 244 A.... "C:\WINDOWS\inf\netcem28.PNF"
13 Jun 2008 11.34.36 9 220 A.... "C:\WINDOWS\inf\netcem33.PNF"
13 Jun 2008 11.34.36 14 572 A.... "C:\WINDOWS\inf\netcem56.PNF"
13 Jun 2008 11.34.36 15 124 A.... "C:\WINDOWS\inf\netcicap.PNF"
13 Jun 2008 11.34.36 4 416 A.... "C:\WINDOWS\inf\netcis.PNF"
13 Jun 2008 11.34.36 3 696 A.... "C:\WINDOWS\inf\netclass.PNF"
13 Jun 2008 11.34.36 12 912 A.... "C:\WINDOWS\inf\netcpqc.PNF"
13 Jun 2008 11.34.36 17 576 A.... "C:\WINDOWS\inf\netcpqg.PNF"
13 Jun 2008 11.34.36 17 940 A.... "C:\WINDOWS\inf\netcpqi.PNF"
13 Jun 2008 11.34.36 10 520 A.... "C:\WINDOWS\inf\netcpqmt.PNF"
13 Jun 2008 11.34.36 10 468 A.... "C:\WINDOWS\inf\netctmrk.PNF"
13 Jun 2008 11.34.36 10 536 A.... "C:\WINDOWS\inf\netdav.PNF"
13 Jun 2008 11.34.36 9 380 A.... "C:\WINDOWS\inf\netdefxa.PNF"
13 Jun 2008 11.34.36 8 552 A.... "C:\WINDOWS\inf\netdf650.PNF"
13 Jun 2008 11.34.36 57 556 A.... "C:\WINDOWS\inf\netdgdxb.PNF"
13 Jun 2008 11.34.36 12 264 A.... "C:\WINDOWS\inf\netdlh5x.PNF"
13 Jun 2008 11.34.38 10 688 A.... "C:\WINDOWS\inf\netdm.PNF"
13 Jun 2008 11.34.38 30 100 A.... "C:\WINDOWS\inf\nete1000.PNF"
13 Jun 2008 11.34.38 11 700 A.... "C:\WINDOWS\inf\nete100i.PNF"
13 Jun 2008 11.34.38 8 412 A.... "C:\WINDOWS\inf\netejxmp.PNF"
13 Jun 2008 11.34.38 7 560 A.... "C:\WINDOWS\inf\netel515.PNF"
13 Jun 2008 11.34.38 11 212 A.... "C:\WINDOWS\inf\netel574.PNF"
13 Jun 2008 11.34.38 7 320 A.... "C:\WINDOWS\inf\netel5x9.PNF"
13 Jun 2008 11.34.38 12 000 A.... "C:\WINDOWS\inf\netel90a.PNF"
13 Jun 2008 11.34.38 19 568 A.... "C:\WINDOWS\inf\netel90b.PNF"
13 Jun 2008 11.34.38 12 780 A.... "C:\WINDOWS\inf\netel980.PNF"
13 Jun 2008 11.34.38 17 500 A.... "C:\WINDOWS\inf\netel99x.PNF"
13 Jun 2008 11.34.38 10 944 A.... "C:\WINDOWS\inf\netepicn.PNF"
13 Jun 2008 11.34.38 8 288 A.... "C:\WINDOWS\inf\netepro.PNF"
13 Jun 2008 11.34.38 7 016 A.... "C:\WINDOWS\inf\netepvcm.PNF"
13 Jun 2008 11.34.38 6 484 A.... "C:\WINDOWS\inf\netepvcp.PNF"
13 Jun 2008 11.34.38 7 124 A.... "C:\WINDOWS\inf\netex10.PNF"
13 Jun 2008 11.34.40 9 864 A.... "C:\WINDOWS\inf\netf56n5.PNF"
13 Jun 2008 11.34.40 9 988 A.... "C:\WINDOWS\inf\netfa312.PNF"
13 Jun 2008 11.34.40 7 996 A.... "C:\WINDOWS\inf\netfa410.PNF"
13 Jun 2008 11.34.40 7 264 A.... "C:\WINDOWS\inf\netfjvi.PNF"
13 Jun 2008 11.34.40 7 296 A.... "C:\WINDOWS\inf\netfjvj.PNF"
13 Jun 2008 11.34.40 7 656 A.... "C:\WINDOWS\inf\netfore.PNF"
13 Jun 2008 11.34.40 7 632 A.... "C:\WINDOWS\inf\netforeh.PNF"
13 Jun 2008 11.34.40 3 704 A.... "C:\WINDOWS\inf\netfw.PNF"
13 Jun 2008 11.34.40 174 876 A.... "C:\WINDOWS\inf\netfxocm.PNF"
13 Jun 2008 11.34.40 5 340 A.... "C:\WINDOWS\inf\netgpc.PNF"
13 Jun 2008 11.34.40 9 804 A.... "C:\WINDOWS\inf\netias.PNF"
13 Jun 2008 11.34.40 17 952 A.... "C:\WINDOWS\inf\netibm.PNF"
13 Jun 2008 11.34.40 14 988 A.... "C:\WINDOWS\inf\netibm2.PNF"
13 Jun 2008 11.34.40 13 124 A.... "C:\WINDOWS\inf\netip6.PNF"
13 Jun 2008 11.34.42 6 264 A.... "C:\WINDOWS\inf\netiprip.PNF"
13 Jun 2008 11.34.42 9 676 A.... "C:\WINDOWS\inf\netirda.PNF"
13 Jun 2008 11.34.42 24 720 A.... "C:\WINDOWS\inf\netirsir.PNF"
13 Jun 2008 11.34.42 18 912 A.... "C:\WINDOWS\inf\netklsi.PNF"
13 Jun 2008 11.34.42 8 664 A.... "C:\WINDOWS\inf\netktc.PNF"
13 Jun 2008 11.34.42 5 428 A.... "C:\WINDOWS\inf\netlanem.PNF"
13 Jun 2008 11.34.42 6 324 A.... "C:\WINDOWS\inf\netlanep.PNF"
13 Jun 2008 11.34.42 7 484 A.... "C:\WINDOWS\inf\netlm.PNF"
13 Jun 2008 11.34.42 7 368 A.... "C:\WINDOWS\inf\netlm56.PNF"
13 Jun 2008 11.34.42 8 228 A.... "C:\WINDOWS\inf\netlnev2.PNF"
13 Jun 2008 11.34.42 7 456 A.... "C:\WINDOWS\inf\netloop.PNF"
13 Jun 2008 11.34.42 10 524 A.... "C:\WINDOWS\inf\netlpd.PNF"
13 Jun 2008 11.34.42 27 932 A.... "C:\WINDOWS\inf\netmadge.PNF"
13 Jun 2008 11.34.42 11 220 A.... "C:\WINDOWS\inf\netmhzn5.PNF"
13 Jun 2008 11.34.44 20 664 A.... "C:\WINDOWS\inf\netmscli.PNF"
13 Jun 2008 11.34.44 6 056 A.... "C:\WINDOWS\inf\netnb.PNF"
13 Jun 2008 11.34.44 22 176 A.... "C:\WINDOWS\inf\netnf3.PNF"
13 Jun 2008 11.34.44 10 956 A.... "C:\WINDOWS\inf\netngr.PNF"
13 Jun 2008 11.34.44 14 800 A.... "C:\WINDOWS\inf\netnm.PNF"
13 Jun 2008 11.34.44 14 668 A.... "C:\WINDOWS\inf\netnovel.PNF"
13 Jun 2008 11.34.44 10 856 A.... "C:\WINDOWS\inf\netnwcli.PNF"
13 Jun 2008 11.34.44 16 260 A.... "C:\WINDOWS\inf\netnwlnk.PNF"
13 Jun 2008 11.34.44 16 944 A.... "C:\WINDOWS\inf\netoc.PNF"
13 Jun 2008 11.34.44 14 928 A.... "C:\WINDOWS\inf\netosi2c.PNF"
13 Jun 2008 11.34.44 13 124 A.... "C:\WINDOWS\inf\netosi5.PNF"
13 Jun 2008 11.34.44 8 452 A.... "C:\WINDOWS\inf\netpc100.PNF"
13 Jun 2008 11.34.44 10 268 A.... "C:\WINDOWS\inf\netpnic.PNF"
13 Jun 2008 11.34.44 5 796 A.... "C:\WINDOWS\inf\netpsa.PNF"
13 Jun 2008 11.34.44 6 248 A.... "C:\WINDOWS\inf\netpschd.PNF"
13 Jun 2008 11.34.44 11 428 A.... "C:\WINDOWS\inf\netpwr2.PNF"
13 Jun 2008 11.34.44 24 080 A.... "C:\WINDOWS\inf\netrasa.PNF"
13 Jun 2008 11.34.44 45 612 A.... "C:\WINDOWS\inf\netrass.PNF"
13 Jun 2008 11.34.44 12 184 A.... "C:\WINDOWS\inf\netrast.PNF"
13 Jun 2008 11.34.46 7 568 A.... "C:\WINDOWS\inf\netrlw2k.PNF"
13 Jun 2008 11.34.46 6 800 A.... "C:\WINDOWS\inf\netrndis.PNF"
13 Jun 2008 11.34.46 8 392 A.... "C:\WINDOWS\inf\netrsvp.PNF"
13 Jun 2008 11.34.46 10 708 A.... "C:\WINDOWS\inf\netrtpnt.PNF"
13 Jun 2008 11.34.46 19 972 A.... "C:\WINDOWS\inf\netrtsnt.PNF"
13 Jun 2008 11.34.46 8 484 A.... "C:\WINDOWS\inf\netrwan.PNF"
13 Jun 2008 11.34.46 7 572 A.... "C:\WINDOWS\inf\netsap.PNF"
13 Jun 2008 11.34.46 8 684 A.... "C:\WINDOWS\inf\netserv.PNF"
13 Jun 2008 11.34.46 21 728 A.... "C:\WINDOWS\inf\netsis.PNF"
13 Jun 2008 11.34.46 14 912 A.... "C:\WINDOWS\inf\netsk98.PNF"
13 Jun 2008 11.34.46 23 584 A.... "C:\WINDOWS\inf\netsk_fp.PNF"
13 Jun 2008 11.34.46 7 612 A.... "C:\WINDOWS\inf\netsla30.PNF"
13 Jun 2008 11.34.46 6 412 A.... "C:\WINDOWS\inf\netsmc.PNF"
13 Jun 2008 11.34.46 10 372 A.... "C:\WINDOWS\inf\netsnip.PNF"
13 Jun 2008 11.34.48 20 116 A.... "C:\WINDOWS\inf\netsnmp.PNF"
13 Jun 2008 11.34.48 9 388 A.... "C:\WINDOWS\inf\nettb155.PNF"
13 Jun 2008 11.34.48 38 440 A.... "C:\WINDOWS\inf\nettcpip.PNF"
13 Jun 2008 11.34.48 8 196 A.... "C:\WINDOWS\inf\nettdkb.PNF"
13 Jun 2008 11.34.48 11 312 A.... "C:\WINDOWS\inf\nettiger.PNF"
13 Jun 2008 11.34.48 7 480 A.... "C:\WINDOWS\inf\nettpro.PNF"
13 Jun 2008 11.34.48 10 780 A.... "C:\WINDOWS\inf\nettpsmp.PNF"
13 Jun 2008 11.34.48 6 348 A.... "C:\WINDOWS\inf\nettun.PNF"
13 Jun 2008 11.34.48 4 004 A.... "C:\WINDOWS\inf\netupnp.PNF"
13 Jun 2008 11.34.48 8 972 A.... "C:\WINDOWS\inf\netupnph.PNF"
13 Jun 2008 11.34.48 14 964 A.... "C:\WINDOWS\inf\netvt86.PNF"
13 Jun 2008 11.34.48 9 948 A.... "C:\WINDOWS\inf\netw840.PNF"
13 Jun 2008 11.34.50 7 176 A.... "C:\WINDOWS\inf\netw926.PNF"
13 Jun 2008 11.34.50 6 660 A.... "C:\WINDOWS\inf\netw940.PNF"
13 Jun 2008 11.34.50 28 024 A.... "C:\WINDOWS\inf\netwlan.PNF"
13 Jun 2008 11.34.50 15 172 A.... "C:\WINDOWS\inf\netwlan2.PNF"
13 Jun 2008 11.34.50 19 536 A.... "C:\WINDOWS\inf\netwv48.PNF"
13 Jun 2008 11.34.50 7 084 A.... "C:\WINDOWS\inf\netwzc.PNF"
13 Jun 2008 11.34.50 19 464 A.... "C:\WINDOWS\inf\netx500.PNF"
13 Jun 2008 11.34.50 11 096 A.... "C:\WINDOWS\inf\netx56n5.PNF"
13 Jun 2008 11.34.50 9 992 A.... "C:\WINDOWS\inf\netxcpq.PNF"
13 Jun 2008 11.26.20 7 336 A.... "C:\WINDOWS\inf\nlite.PNF"
13 Jun 2008 11.34.50 6 708 A.... "C:\WINDOWS\inf\ntapm.PNF"
13 Jun 2008 11.34.50 7 104 A.... "C:\WINDOWS\inf\ntgrip.PNF"
13 Jun 2008 11.34.50 1 317 460 A.... "C:\WINDOWS\inf\ntprint.PNF"
13 Jun 2008 11.34.50 9 668 A.... "C:\WINDOWS\inf\nv3.PNF"
13 Jun 2008 11.34.52 53 292 A.... "C:\WINDOWS\inf\nv4_disp.PNF"
13 Jun 2008 11.34.52 22 148 A.... "C:\WINDOWS\inf\nvct.PNF"
13 Jun 2008 11.34.52 34 060 A.... "C:\WINDOWS\inf\nvdm.PNF"
13 Jun 2008 11.34.52 22 196 A.... "C:\WINDOWS\inf\nvts.PNF"
13 Jun 2008 11.34.52 4 400 A.... "C:\WINDOWS\inf\oeaccess.PNF"
13 Jun 2008 11.33.30 49 754 A.... "C:\WINDOWS\inf\oem0.PNF"
13 Jun 2008 11.36.46 27 638 A.... "C:\WINDOWS\inf\oem1.PNF"
13 Jun 2008 14.17.42 298 092 A.... "C:\WINDOWS\inf\oem10.PNF"
13 Jun 2008 14.18.18 104 880 A.... "C:\WINDOWS\inf\oem11.PNF"
13 Jun 2008 14.19.26 9 806 A.... "C:\WINDOWS\inf\oem12.PNF"
13 Jun 2008 14.19.26 55 072 A.... "C:\WINDOWS\inf\oem13.PNF"
13 Jun 2008 14.20.02 36 104 A.... "C:\WINDOWS\inf\oem14.PNF"
13 Jun 2008 14.34.54 7 362 A.... "C:\WINDOWS\inf\oem15.PNF"
13 Jun 2008 14.34.54 5 306 A.... "C:\WINDOWS\inf\oem16.PNF"
13 Jun 2008 17.04.32 21 282 A.... "C:\WINDOWS\inf\oem17.PNF"
13 Jun 2008 17.04.32 21 314 A.... "C:\WINDOWS\inf\oem18.PNF"
13 Jun 2008 17.04.34 14 754 A.... "C:\WINDOWS\inf\oem19.PNF"
13 Jun 2008 11.36.46 6 400 A.... "C:\WINDOWS\inf\oem2.PNF"
13 Jun 2008 17.04.40 38 680 A.... "C:\WINDOWS\inf\oem20.PNF"
13 Jun 2008 17.07.58 0 ...H. "C:\WINDOWS\inf\oem21.inf"
13 Jun 2008 11.43.18 57 644 A.... "C:\WINDOWS\inf\oem3.PNF"
13 Jun 2008 11.55.56 237 976 A.... "C:\WINDOWS\inf\oem4.PNF"
13 Jun 2008 12.01.46 14 200 A.... "C:\WINDOWS\inf\oem5.PNF"
13 Jun 2008 12.19.32 18 096 A.... "C:\WINDOWS\inf\oem6.PNF"
13 Jun 2008 12.19.32 48 104 A.... "C:\WINDOWS\inf\oem7.PNF"
13 Jun 2008 14.02.18 7 412 A.... "C:\WINDOWS\inf\oem8.PNF"
13 Jun 2008 14.16.52 14 456 A.... "C:\WINDOWS\inf\oem9.PNF"
13 Jun 2008 11.34.52 17 240 A.... "C:\WINDOWS\inf\oobe.PNF"
13 Jun 2008 11.34.52 21 776 A.... "C:\WINDOWS\inf\optional.PNF"
13 Jun 2008 11.34.52 24 764 A.... "C:\WINDOWS\inf\ovcam.PNF"
13 Jun 2008 11.34.52 5 868 A.... "C:\WINDOWS\inf\ovcomp.PNF"
13 Jun 2008 11.34.52 12 420 A.... "C:\WINDOWS\inf\ovsound.PNF"
13 Jun 2008 11.34.52 14 408 A.... "C:\WINDOWS\inf\p2p.PNF"
13 Jun 2008 11.34.52 35 832 A.... "C:\WINDOWS\inf\parhmse.PNF"
13 Jun 2008 11.34.54 12 992 A.... "C:\WINDOWS\inf\pchealth.PNF"
13 Jun 2008 11.34.54 47 228 A.... "C:\WINDOWS\inf\pcmcia.PNF"
13 Jun 2008 11.34.54 12 556 A.... "C:\WINDOWS\inf\perm2.PNF"
13 Jun 2008 11.34.54 9 004 A.... "C:\WINDOWS\inf\perm3.PNF"
13 Jun 2008 11.34.54 12 604 A.... "C:\WINDOWS\inf\phdsext.PNF"
13 Jun 2008 11.34.54 10 484 A.... "C:\WINDOWS\inf\phil1vid.PNF"
13 Jun 2008 11.34.54 13 828 A.... "C:\WINDOWS\inf\phil2vid.PNF"
13 Jun 2008 11.34.54 13 228 A.... "C:\WINDOWS\inf\phildec.PNF"
13 Jun 2008 11.34.54 13 292 A.... "C:\WINDOWS\inf\philtune.PNF"
13 Jun 2008 11.34.54 12 408 A.... "C:\WINDOWS\inf\pinball.PNF"
13 Jun 2008 11.34.54 17 008 A.... "C:\WINDOWS\inf\pmxmcro.PNF"
13 Jun 2008 11.34.54 107 240 A.... "C:\WINDOWS\inf\pnpscsi.PNF"
13 Jun 2008 11.34.54 6 900 A.... "C:\WINDOWS\inf\ppa.PNF"
13 Jun 2008 11.34.54 6 940 A.... "C:\WINDOWS\inf\ppa3.PNF"
13 Jun 2008 11.34.56 44 964 A.... "C:\WINDOWS\inf\printupg.PNF"
13 Jun 2008 11.34.56 146 476 A.... "C:\WINDOWS\inf\prtupg9x.PNF"
13 Jun 2008 11.34.56 9 380 A.... "C:\WINDOWS\inf\ps5333.PNF"
13 Jun 2008 11.34.56 10 788 A.... "C:\WINDOWS\inf\ptpusb.PNF"
13 Jun 2008 11.34.56 11 512 A.... "C:\WINDOWS\inf\qmgr.PNF"
13 Jun 2008 11.34.56 7 180 A.... "C:\WINDOWS\inf\ramdisk.PNF"
13 Jun 2008 11.34.56 18 492 A.... "C:\WINDOWS\inf\ricoh.PNF"
13 Jun 2008 11.34.56 3 964 A.... "C:\WINDOWS\inf\rootau.PNF"
13 Jun 2008 14.20.20 9 148 A.... "C:\WINDOWS\inf\S24Trans.PNF"
13 Jun 2008 11.34.56 8 484 A.... "C:\WINDOWS\inf\s3sav3d.PNF"
13 Jun 2008 11.34.56 8 644 A.... "C:\WINDOWS\inf\s3sav4.PNF"
13 Jun 2008 11.34.56 8 676 A.... "C:\WINDOWS\inf\s3savmx.PNF"
13 Jun 2008 11.34.56 6 740 A.... "C:\WINDOWS\inf\s3trio3d.PNF"
13 Jun 2008 11.34.56 139 136 A.... "C:\WINDOWS\inf\sapi5.PNF"
13 Jun 2008 11.34.56 6 808 A.... "C:\WINDOWS\inf\sbp2.PNF"
13 Jun 2008 11.34.58 39 880 A.... "C:\WINDOWS\inf\sceregvl.PNF"
13 Jun 2008 11.34.58 22 424 A.... "C:\WINDOWS\inf\scsi.PNF"
13 Jun 2008 11.34.58 37 824 A.... "C:\WINDOWS\inf\scsidev.PNF"
13 Jun 2008 11.34.58 10 864 A.... "C:\WINDOWS\inf\sdbus.PNF"
13 Jun 2008 11.34.58 37 520 A.... "C:\WINDOWS\inf\sdwndr2k.PNF"
13 Jun 2008 11.34.58 4 096 A.... "C:\WINDOWS\inf\secdrv.PNF"
13 Jun 2008 11.34.58 26 328 A.... "C:\WINDOWS\inf\secrecs.PNF"
13 Jun 2008 11.34.58 41 588 A.... "C:\WINDOWS\inf\setupqry.PNF"
13 Jun 2008 11.34.58 7 936 A.... "C:\WINDOWS\inf\sffdisk.PNF"
13 Jun 2008 11.34.58 8 572 A.... "C:\WINDOWS\inf\sgiu.PNF"
13 Jun 2008 11.34.58 38 508 A.... "C:\WINDOWS\inf\shell.PNF"
13 Jun 2008 11.34.58 16 128 A.... "C:\WINDOWS\inf\shl_img.PNF"
13 Jun 2008 11.34.58 9 068 A.... "C:\WINDOWS\inf\sis300i.PNF"
13 Jun 2008 11.34.58 7 988 A.... "C:\WINDOWS\inf\sis6306.PNF"
13 Jun 2008 11.34.58 11 252 A.... "C:\WINDOWS\inf\sisgr.PNF"
13 Jun 2008 11.35.00 7 716 A.... "C:\WINDOWS\inf\sisv6326.PNF"
13 Jun 2008 15.39.16 6 348 A.... "C:\WINDOWS\inf\skins.PNF"
13 Jun 2008 11.35.00 9 188 A.... "C:\WINDOWS\inf\slip.PNF"
13 Jun 2008 11.35.00 36 444 A.... "C:\WINDOWS\inf\smartcrd.PNF"
13 Jun 2008 11.35.00 7 300 A.... "C:\WINDOWS\inf\smi.PNF"
13 Jun 2008 11.35.00 6 200 A.... "C:\WINDOWS\inf\sonypvu1.PNF"
13 Jun 2008 11.35.00 20 252 A.... "C:\WINDOWS\inf\spx.PNF"
13 Jun 2008 11.35.00 12 188 A.... "C:\WINDOWS\inf\spxports.PNF"
13 Jun 2008 11.35.00 12 064 A.... "C:\WINDOWS\inf\sr.PNF"
13 Jun 2008 11.35.00 5 988 A.... "C:\WINDOWS\inf\srchasst.PNF"
13 Jun 2008 11.35.00 11 724 A.... "C:\WINDOWS\inf\srusbusd.PNF"
13 Jun 2008 11.35.00 8 004 A.... "C:\WINDOWS\inf\stalport.PNF"
13 Jun 2008 11.35.00 27 968 A.... "C:\WINDOWS\inf\sti.PNF"
13 Jun 2008 11.35.00 87 424 A.... "C:\WINDOWS\inf\stillcam.PNF"
13 Jun 2008 11.35.02 11 956 A.... "C:\WINDOWS\inf\streamip.PNF"
13 Jun 2008 11.35.02 2 608 A.... "C:\WINDOWS\inf\SVCPACK.PNF"
13 Jun 2008 15.39.16 8 368 A.... "C:\WINDOWS\inf\swflash.PNF"
13 Jun 2008 11.35.02 57 444 A.... "C:\WINDOWS\inf\swnt.PNF"
13 Jun 2008 11.35.02 3 204 A.... "C:\WINDOWS\inf\syscomp.PNF"
13 Jun 2008 11.35.02 7 372 A.... "C:\WINDOWS\inf\SYSOC.PNF"
13 Jun 2008 11.26.14 101 892 A.... "C:\WINDOWS\inf\syssetup.PNF"
13 Jun 2008 11.35.02 523 716 A.... "C:\WINDOWS\inf\tabletpc.PNF"
13 Jun 2008 11.35.02 59 884 A.... "C:\WINDOWS\inf\tape.PNF"
13 Jun 2008 11.35.02 9 440 A.... "C:\WINDOWS\inf\tdibth.PNF"
13 Jun 2008 11.35.02 8 804 A.... "C:\WINDOWS\inf\tgiu.PNF"
13 Jun 2008 11.35.04 9 916 A.... "C:\WINDOWS\inf\trid3d.PNF"
13 Jun 2008 11.35.04 9 716 A.... "C:\WINDOWS\inf\tridkb.PNF"
13 Jun 2008 11.35.04 8 628 A.... "C:\WINDOWS\inf\tridxp.PNF"
13 Jun 2008 11.35.04 9 916 A.... "C:\WINDOWS\inf\tsbvcap.PNF"
13 Jun 2008 11.35.04 9 776 A.... "C:\WINDOWS\inf\tshoot.PNF"
13 Jun 2008 11.35.04 122 800 A.... "C:\WINDOWS\inf\tsoc.PNF"
13 Jun 2008 11.35.04 68 420 A.... "C:\WINDOWS\inf\umax.PNF"
13 Jun 2008 11.35.04 11 032 A.... "C:\WINDOWS\inf\umaxpp.PNF"
13 Jun 2008 11.35.04 4 896 A.... "C:\WINDOWS\inf\unknown.PNF"
13 Jun 2008 11.35.04 44 864 A.... "C:\WINDOWS\inf\usb.PNF"
13 Jun 2008 11.35.04 54 656 A.... "C:\WINDOWS\inf\usbport.PNF"
13 Jun 2008 11.35.04 5 492 A.... "C:\WINDOWS\inf\usbprint.PNF"
13 Jun 2008 11.35.04 38 104 A.... "C:\WINDOWS\inf\usbstor.PNF"
13 Jun 2008 11.35.04 25 000 A.... "C:\WINDOWS\inf\usbvideo.PNF"
13 Jun 2008 11.35.04 4 376 A.... "C:\WINDOWS\inf\vgx.PNF"
13 Jun 2008 11.35.04 9 716 A.... "C:\WINDOWS\inf\viafir2k.PNF"
13 Jun 2008 11.35.06 4 972 A.... "C:\WINDOWS\inf\volsnap.PNF"
13 Jun 2008 11.35.06 4 808 A.... "C:\WINDOWS\inf\volume.PNF"
13 Jun 2008 11.26.10 21 368 A.... "C:\WINDOWS\inf\wab50.PNF"
13 Jun 2008 11.35.06 10 812 A.... "C:\WINDOWS\inf\wave.PNF"
13 Jun 2008 11.35.06 14 024 A.... "C:\WINDOWS\inf\wbemoc.PNF"
13 Jun 2008 11.35.06 7 016 A.... "C:\WINDOWS\inf\wbemsnmp.PNF"
13 Jun 2008 11.35.06 10 668 A.... "C:\WINDOWS\inf\wbfirdma.PNF"
13 Jun 2008 11.35.06 11 928 A.... "C:\WINDOWS\inf\wceusbsh.PNF"
13 Jun 2008 11.35.06 303 720 A.... "C:\WINDOWS\inf\wdma10k1.PNF"
13 Jun 2008 11.33.28 45 016 A.... "C:\WINDOWS\inf\wdmaudio.PNF"
13 Jun 2008 11.35.06 75 032 A.... "C:\WINDOWS\inf\wdma_ali.PNF"
13 Jun 2008 11.35.06 96 888 A.... "C:\WINDOWS\inf\wdma_aur.PNF"
13 Jun 2008 11.35.06 18 312 A.... "C:\WINDOWS\inf\wdma_avc.PNF"
13 Jun 2008 11.35.06 35 772 A.... "C:\WINDOWS\inf\wdma_azt.PNF"
13 Jun 2008 11.35.06 41 964 A.... "C:\WINDOWS\inf\wdma_csc.PNF"
13 Jun 2008 11.35.06 45 872 A.... "C:\WINDOWS\inf\wdma_csf.PNF"
13 Jun 2008 11.35.06 64 008 A.... "C:\WINDOWS\inf\wdma_ctl.PNF"
13 Jun 2008 11.35.06 32 044 A.... "C:\WINDOWS\inf\wdma_cwr.PNF"
13 Jun 2008 11.35.08 36 640 A.... "C:\WINDOWS\inf\wdma_ens.PNF"
13 Jun 2008 11.35.08 102 540 A.... "C:\WINDOWS\inf\wdma_es2.PNF"
13 Jun 2008 11.35.08 123 868 A.... "C:\WINDOWS\inf\wdma_es3.PNF"
13 Jun 2008 11.35.08 42 240 A.... "C:\WINDOWS\inf\wdma_ess.PNF"
13 Jun 2008 11.35.08 45 748 A.... "C:\WINDOWS\inf\wdma_int.PNF"
13 Jun 2008 11.35.08 43 920 A.... "C:\WINDOWS\inf\wdma_m2e.PNF"
13 Jun 2008 11.35.08 18 920 A.... "C:\WINDOWS\inf\wdma_ne2.PNF"
13 Jun 2008 11.35.08 25 112 A.... "C:\WINDOWS\inf\wdma_neo.PNF"
13 Jun 2008 11.35.08 26 200 A.... "C:\WINDOWS\inf\wdma_rip.PNF"
13 Jun 2008 11.35.08 44 356 A.... "C:\WINDOWS\inf\wdma_sis.PNF"
13 Jun 2008 11.35.08 74 620 A.... "C:\WINDOWS\inf\wdma_usb.PNF"
13 Jun 2008 11.35.08 33 804 A.... "C:\WINDOWS\inf\wdma_via.PNF"
13 Jun 2008 11.35.08 30 420 A.... "C:\WINDOWS\inf\wdma_ym2.PNF"
13 Jun 2008 11.35.08 17 488 A.... "C:\WINDOWS\inf\wdma_ymh.PNF"
13 Jun 2008 11.35.08 19 976 A.... "C:\WINDOWS\inf\wdmjoy.PNF"
13 Jun 2008 11.35.08 8 884 A.... "C:\WINDOWS\inf\wfp0.PNF"
13 Jun 2008 11.35.08 8 884 A.... "C:\WINDOWS\inf\wfp1.PNF"
13 Jun 2008 11.35.10 8 884 A.... "C:\WINDOWS\inf\wfp2.PNF"
13 Jun 2008 11.35.10 8 884 A.... "C:\WINDOWS\inf\wfp3.PNF"
13 Jun 2008 11.35.10 8 876 A.... "C:\WINDOWS\inf\wfp4.PNF"
13 Jun 2008 11.35.10 8 884 A.... "C:\WINDOWS\inf\wfp5.PNF"
13 Jun 2008 11.35.10 8 884 A.... "C:\WINDOWS\inf\wfp6.PNF"
13 Jun 2008 11.35.10 8 884 A.... "C:\WINDOWS\inf\wfp7.PNF"
13 Jun 2008 11.35.10 8 884 A.... "C:\WINDOWS\inf\wfp8.PNF"
13 Jun 2008 11.35.10 4 064 A.... "C:\WINDOWS\inf\wmaccess.PNF"
13 Jun 2008 11.35.10 21 768 A.... "C:\WINDOWS\inf\wmdm.PNF"
13 Jun 2008 14.44.04 22 154 A.... "C:\WINDOWS\inf\WMDM10.PNF"
13 Jun 2008 11.35.10 15 908 A.... "C:\WINDOWS\inf\wmfsdk.PNF"
13 Jun 2008 14.43.52 10 744 A.... "C:\WINDOWS\inf\WMFSDK10.PNF"
13 Jun 2008 11.26.10 57 340 A.... "C:\WINDOWS\inf\wmp.PNF"
13 Jun 2008 14.44.22 65 996 A.... "C:\WINDOWS\inf\WMP10.PNF"
13 Jun 2008 11.35.10 4 440 A.... "C:\WINDOWS\inf\wmpocm.PNF"
13 Jun 2008 14.44.52 5 242 A.... "C:\WINDOWS\inf\WMSET10.PNF"
13 Jun 2008 15.39.16 3 988 A.... "C:\WINDOWS\inf\wmsetsdk.PNF"
13 Jun 2008 11.35.10 6 644 A.... "C:\WINDOWS\inf\wmtour.PNF"
13 Jun 2008 11.26.04 16 784 A.... "C:\WINDOWS\inf\wordpad.PNF"
13 Jun 2008 14.44.12 10 684 A.... "C:\WINDOWS\inf\WPD10.PNF"
13 Jun 2008 15.39.18 10 516 A.... "C:\WINDOWS\inf\wpdmtp.PNF"
13 Jun 2008 11.35.12 15 932 A.... "C:\WINDOWS\inf\wsh.PNF"
13 Jun 2008 11.35.12 9 256 A.... "C:\WINDOWS\inf\wstcodec.PNF"
13 Jun 2008 11.35.12 8 892 A.... "C:\WINDOWS\inf\wtv0.PNF"
13 Jun 2008 11.35.12 8 892 A.... "C:\WINDOWS\inf\wtv1.PNF"
13 Jun 2008 11.35.12 8 892 A.... "C:\WINDOWS\inf\wtv2.PNF"
13 Jun 2008 11.35.12 8 892 A.... "C:\WINDOWS\inf\wtv3.PNF"
13 Jun 2008 11.35.12 8 892 A.... "C:\WINDOWS\inf\wtv4.PNF"
13 Jun 2008 11.35.12 8 892 A.... "C:\WINDOWS\inf\wtv5.PNF"
13 Jun 2008 11.35.12 9 960 A.... "C:\WINDOWS\inf\xscan_xp.PNF"
13 Jun 2008 11.19.10 65 ...H. "C:\WINDOWS\Offline Web Pages\desktop.ini"
13 Jun 2008 11.16.44 52 A.... "C:\WINDOWS\Registration\R000000000001.clb"
13 Jun 2008 11.16.56 21 812 A.... "C:\WINDOWS\Registration\R000000000003.clb"
13 Jun 2008 11.19.56 22 708 A.... "C:\WINDOWS\Registration\R000000000006.clb"
13 Jun 2008 11.19.56 22 708 A.... "C:\WINDOWS\Registration\R000000000007.clb"
13 Jun 2008 11.20.22 1 048 576 A.... "C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{21281BAC-6349-4033-B417-4117A6AAB7C4}.crmlog"
13 Jun 2008 11.20.18 2 504 A.... "C:\WINDOWS\repair\config.nt"
13 Jun 2008 11.22.40 229 376 A.... "C:\WINDOWS\repair\default"
13 Jun 2008 11.20.24 229 376 A..H. "C:\WINDOWS\repair\ntuser.dat"
13 Jun 2008 11.22.40 24 576 A.... "C:\WINDOWS\repair\sam"
13 Jun 2008 11.20.36 823 628 A.... "C:\WINDOWS\repair\secsetup.inf"
13 Jun 2008 11.22.40 32 768 A.... "C:\WINDOWS\repair\security"
13 Jun 2008 11.18.48 223 684 A.... "C:\WINDOWS\repair\setup.log"
13 Jun 2008 11.22.38 8 581 120 A.... "C:\WINDOWS\repair\software"
13 Jun 2008 11.22.36 1 060 864 A.... "C:\WINDOWS\repair\system"
13 Jun 2008 14.50.54 8 192 A.... "C:\WINDOWS\security\edb.chk"
13 Jun 2008 14.50.54 1 048 576 A.... "C:\WINDOWS\security\edb.log"
13 Jun 2008 11.20.34 1 048 576 A.... "C:\WINDOWS\security\edb00002.log"
13 Jun 2008 13.11.16 1 048 576 A.... "C:\WINDOWS\security\res1.log"
13 Jun 2008 13.11.16 1 048 576 A.... "C:\WINDOWS\security\res2.log"
13 Jun 2008 11.22.44 934 A.... "C:\WINDOWS\system32\$winnt$.inf"
13 Jun 2008 14.44.44 16 832 A.... "C:\WINDOWS\system32\amcompat.tlb"
13 Jun 2008 11.19.04 749 A..HR "C:\WINDOWS\system32\cdplayer.exe.manifest"
13 Jun 2008 11.20.18 2 504 A.... "C:\WINDOWS\system32\CONFIG.NT"
20 Jun 2008 19.42.16 148 992 A.... "C:\WINDOWS\system32\dnsapi.dll"
13 Jun 2008 11.16.56 21 812 A.... "C:\WINDOWS\system32\emptyregdb.dat"
18 Jun 2008 23.07.24 56 A..H. "C:\WINDOWS\system32\ezsidmv.dat"
14 Jun 2008 8.41.06 243 128 A.... "C:\WINDOWS\system32\FNTCACHE.DAT"
13 Jun 2008 13.14.38 0 A.... "C:\WINDOWS\system32\h323log.txt"
2 Jul 2008 13.33.46 82 432 A.... "C:\WINDOWS\system32\IEDFix.C.exe"
10 Jun 2008 1.21.02 135 168 A.... "C:\WINDOWS\system32\java.exe"
10 Jun 2008 2.32.34 73 728 A.... "C:\WINDOWS\system32\javacpl.cpl"
10 Jun 2008 1.21.04 135 168 A.... "C:\WINDOWS\system32\javaw.exe"
10 Jun 2008 2.32.34 139 264 A.... "C:\WINDOWS\system32\javaws.exe"
26 Jul 2008 18.19.00 6 587 A.... "C:\WINDOWS\system32\jupdate-1.6.0_07-b06.log"
13 Jun 2008 11.19.10 488 A..HR "C:\WINDOWS\system32\logonui.exe.manifest"
25 Jun 2008 18.15.46 17 972 344 A.... "C:\WINDOWS\system32\MRT.exe"
20 Jun 2008 19.42.16 247 296 A.... "C:\WINDOWS\system32\mswsock.dll"
13 Jun 2008 11.19.04 749 A..HR "C:\WINDOWS\system32\ncpa.cpl.manifest"
13 Jun 2008 14.44.44 23 392 A.... "C:\WINDOWS\system32\nscompat.tlb"
13 Jun 2008 11.19.04 749 A..HR "C:\WINDOWS\system32\nwc.cpl.manifest"
24 Jun 2008 21.00.16 70 264 A.... "C:\WINDOWS\system32\perfc005.dat"
24 Jun 2008 21.00.16 59 774 A.... "C:\WINDOWS\system32\perfc009.dat"
24 Jun 2008 21.00.16 393 232 A.... "C:\WINDOWS\system32\perfh005.dat"
24 Jun 2008 21.00.16 395 534 A.... "C:\WINDOWS\system32\perfh009.dat"
24 Jun 2008 21.00.16 929 478 A.... "C:\WINDOWS\system32\PerfStringBackup.INI"
13 Jun 2008 14.50.32 98 304 A.... "C:\WINDOWS\system32\qttask.exe"
13 Jun 2008 14.20.26 308 A.... "C:\WINDOWS\system32\results.txt"
13 Jun 2008 11.19.04 749 A..HR "C:\WINDOWS\system32\sapi.cpl.manifest"
26 Jul 2008 17.26.54 4 274 A.... "C:\WINDOWS\system32\tmp.reg"
26 Jul 2008 17.26.54 0 A.... "C:\WINDOWS\system32\tmp.txt"
27 Jul 2008 1.12.14 13 056 A.... "C:\WINDOWS\system32\TPAPSLOG.LOG"
27 Jul 2008 1.14.32 13 952 A.... "C:\WINDOWS\system32\TPHDLOG0.LOG"
26 Jul 2008 12.39.56 354 560 A.... "C:\WINDOWS\system32\TuneUpDefragService.exe"
13 Jun 2008 18.40.48 138 634 A.... "C:\WINDOWS\system32\TZLog.log"
29 May 2008 9.35.36 86 528 A.... "C:\WINDOWS\system32\VACFix.exe"
13 Jun 2008 11.19.10 488 A..HR "C:\WINDOWS\system32\WindowsLogon.manifest"
27 Jul 2008 0.14.36 2 206 A.... "C:\WINDOWS\system32\wpa.dbl"
13 Jun 2008 11.19.04 749 A..HR "C:\WINDOWS\system32\wuaucpl.cpl.manifest"
26 Jul 2008 12.36.08 312 A.... "C:\WINDOWS\Tasks\1-Click Maintenance.job"
13 Jun 2008 14.39.20 284 A.... "C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
13 Jun 2008 11.38.46 300 A.... "C:\WINDOWS\Tasks\BMMTask.job"
27 Jul 2008 0.14.30 6 A..H. "C:\WINDOWS\Tasks\SA.DAT"
27 Jul 2008 1.51.42 14 210 A.... "C:\WINDOWS\Temp\scs21F.tmp"
27 Jul 2008 0.14.30 255 A.... "C:\WINDOWS\Temp\WGAErrLog.txt"
27 Jul 2008 0.14.42 409 A.... "C:\WINDOWS\Temp\WGANotify.settings"
13 Jun 2008 17.22.28 13 838 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.inf"
13 Jun 2008 17.22.22 967 A.... "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.txt"
21 Jun 2008 20.22.16 11 057 A.... "C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.inf"
21 Jun 2008 20.22.10 607 A.... "C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.txt"
13 Jun 2008 18.42.30 8 416 A.... "C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.inf"
13 Jun 2008 18.42.28 370 A.... "C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.txt"
13 Jun 2008 18.43.18 8 806 A.... "C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.inf"
13 Jun 2008 18.43.14 365 A.... "C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.txt"
13 Jun 2008 18.37.18 620 A.... "C:\WINDOWS\$NtUninstallKB923191$\spuninst\KB923191.asms"
13 Jun 2008 18.37.20 6 339 A.... "C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.inf"
13 Jun 2008 18.37.18 313 A.... "C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.txt"
13 Jun 2008 18.39.44 12 342 A.... "C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.inf"
13 Jun 2008 18.39.38 2 893 A.... "C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.txt"
13 Jun 2008 18.43.12 8 779 A.... "C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.inf"
13 Jun 2008 18.43.08 360 A.... "C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.txt"
13 Jun 2008 18.42.36 9 072 A.... "C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.inf"
13 Jun 2008 18.42.34 663 A.... "C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.txt"
13 Jun 2008 18.35.12 7 065 A.... "C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.inf"
13 Jun 2008 18.35.08 1 580 A.... "C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.txt"
13 Jun 2008 18.37.06 6 528 A.... "C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.inf"
13 Jun 2008 18.37.04 370 A.... "C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.txt"
13 Jun 2008 18.36.12 5 990 A.... "C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.inf"
13 Jun 2008 18.36.10 370 A.... "C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.txt"
13 Jun 2008 18.43.06 8 851 A.... "C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.inf"
13 Jun 2008 18.43.04 383 A.... "C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.txt"
13 Jun 2008 18.40.06 8 984 A.... "C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.inf"
13 Jun 2008 18.40.04 1 186 A.... "C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.txt"
13 Jun 2008 18.34.50 5 809 A.... "C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.inf"
13 Jun 2008 18.34.46 740 A.... "C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.txt"
13 Jun 2008 18.36.40 6 235 A.... "C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.inf"
13 Jun 2008 18.36.38 355 A.... "C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.txt"
13 Jun 2008 18.36.18 7 033 A.... "C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.inf"
13 Jun 2008 18.36.14 961 A.... "C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.txt"
13 Jun 2008 18.35.26 6 807 A.... "C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.inf"
13 Jun 2008 18.35.20 520 A.... "C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.txt"
13 Jun 2008 18.40.00 7 508 A.... "C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.inf"
13 Jun 2008 18.39.58 355 A.... "C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.txt"
13 Jun 2008 18.45.00 10 788 A.... "C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.inf"
13 Jun 2008 18.44.52 426 A.... "C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.txt"
13 Jun 2008 18.36.46 5 527 A.... "C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.inf"
13 Jun 2008 18.36.44 122 A.... "C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.txt"
14 Jun 2008 9.12.20 9 845 A.... "C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.inf"
14 Jun 2008 9.12.12 347 A.... "C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.txt"
13 Jun 2008 18.44.30 9 499 A.... "C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.inf"
13 Jun 2008 18.44.28 353 A.... "C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.txt"
13 Jun 2008 18.40.46 7 722 A.... "C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.inf"
13 Jun 2008 18.40.44 331 A.... "C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.txt"
13 Jun 2008 18.34.54 5 291 A.... "C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.inf"
13 Jun 2008 18.34.52 370 A.... "C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.txt"
13 Jun 2008 18.39.24 8 400 A.... "C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.inf"
13 Jun 2008 18.39.20 1 016 A.... "C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.txt"
13 Jun 2008 18.44.16 10 779 A.... "C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.inf"
13 Jun 2008 18.44.12 664 A.... "C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.txt"
13 Jun 2008 18.37.14 7 415 A.... "C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.inf"
13 Jun 2008 18.37.12 839 A.... "C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.txt"
13 Jun 2008 18.43.48 8 704 A.... "C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.inf"
13 Jun 2008 18.43.44 187 A.... "C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.txt"
13 Jun 2008 18.38.16 6 619 A.... "C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.inf"
13 Jun 2008 18.38.12 358 A.... "C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.txt"
13 Jun 2008 18.45.06 9 736 A.... "C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.inf"
13 Jun 2008 18.45.02 370 A.... "C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.txt"
13 Jun 2008 18.38.32 6 495 A.... "C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.inf"
13 Jun 2008 18.38.30 183 A.... "C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.txt"
13 Jun 2008 18.36.02 6 199 A.... "C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.inf"
13 Jun 2008 18.36.00 612 A.... "C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.txt"
13 Jun 2008 18.43.24 10 220 A.... "C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.inf"
13 Jun 2008 18.43.20 1 087 A.... "C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.txt"
13 Jun 2008 18.36.50 5 696 A.... "C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.inf"
13 Jun 2008 18.36.48 183 A.... "C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.txt"
13 Jun 2008 18.38.28 7 596 A.... "C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.inf"
13 Jun 2008 18.38.24 478 A.... "C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.txt"
13 Jun 2008 18.34.38 5 427 A.... "C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.inf"
13 Jun 2008 18.34.36 608 A.... "C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.txt"
13 Jun 2008 18.36.56 6 384 A.... "C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.inf"
13 Jun 2008 18.36.52 345 A.... "C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.txt"
13 Jun 2008 18.39.56 6 972 A.... "C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.inf"
13 Jun 2008 18.39.52 222 A.... "C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.txt"
13 Jun 2008 18.41.50 7 090 A.... "C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.inf"
13 Jun 2008 18.41.46 94 A.... "C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.txt"
13 Jun 2008 18.44.24 12 106 A.... "C:\WINDOWS\$NtUninstallKB937894$\spuninst\spuninst.inf"
13 Jun 2008 18.44.20 2 232 A.... "C:\WINDOWS\$NtUninstallKB937894$\spuninst\spuninst.txt"
13 Jun 2008 18.40.12 8 578 A.... "C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.inf"
13 Jun 2008 18.40.10 894 A.... "C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.txt"
13 Jun 2008 18.42.14 8 299 A.... "C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.inf"
13 Jun 2008 18.42.12 363 A.... "C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.txt"
13 Jun 2008 18.44.08 10 712 A.... "C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.inf"
13 Jun 2008 18.44.04 1 132 A.... "C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.txt"
13 Jun 2008 18.42.48 8 102 A.... "C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.inf"
13 Jun 2008 18.42.46 187 A.... "C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.txt"
13 Jun 2008 18.35.56 5 167 A.... "C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.inf"
13 Jun 2008 18.35.54 187 A.... "C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.txt"
13 Jun 2008 18.41.44 8 038 A.... "C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.inf"
13 Jun 2008 18.41.42 368 A.... "C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.txt"
13 Jun 2008 18.37.02 6 804 A.... "C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.inf"
13 Jun 2008 18.36.58 618 A.... "C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.txt"
13 Jun 2008 18.34.28 4 743 A.... "C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.inf"
13 Jun 2008 18.34.26 272 A.... "C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.txt"
13 Jun 2008 18.40.52 9 070 A.... "C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.inf"
13 Jun 2008 18.40.50 334 A.... "C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.txt"
13 Jun 2008 18.42.20 8 155 A.... "C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.inf"
13 Jun 2008 18.42.18 178 A.... "C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.txt"
13 Jun 2008 18.43.54 8 827 A.... "C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.inf"
13 Jun 2008 18.43.50 183 A.... "C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.txt"
13 Jun 2008 18.35.40 6 596 A.... "C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.inf"
13 Jun 2008 18.35.38 534 A.... "C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.txt"
13 Jun 2008 18.41.56 8 106 A.... "C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.inf"
13 Jun 2008 18.41.54 360 A.... "C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.txt"
13 Jun 2008 18.36.08 5 921 A.... "C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.inf"
13 Jun 2008 18.36.04 360 A.... "C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.txt"
13 Jun 2008 18.39.34 6 499 A.... "C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.inf"
13 Jun 2008 18.39.32 0 A.... "C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.txt"
13 Jun 2008 18.36.36 6 669 A.... "C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.inf"
13 Jun 2008 18.36.32 565 A.... "C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.txt"
13 Jun 2008 18.39.28 7 235 A.... "C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.inf"
13 Jun 2008 18.39.26 360 A.... "C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.txt"
13 Jun 2008 18.36.28 6 270 A.... "C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.inf"
13 Jun 2008 18.36.26 376 A.... "C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.txt"
13 Jun 2008 18.43.36 9 304 A.... "C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.inf"
13 Jun 2008 18.43.32 588 A.... "C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.txt"
13 Jun 2008 18.42.44 8 844 A.... "C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.inf"
13 Jun 2008 18.42.40 398 A.... "C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.txt"
13 Jun 2008 18.35.52 5 709 A.... "C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.inf"
13 Jun 2008 18.35.50 312 A.... "C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.txt"
13 Jun 2008 18.40.58 7 756 A.... "C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.inf"
13 Jun 2008 18.40.56 355 A.... "C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.txt"
13 Jun 2008 18.36.24 6 405 A.... "C:\WINDOWS\$NtUninstallKB944338$\spuninst\spuninst.inf"
13 Jun 2008 18.36.20 613 A.... "C:\WINDOWS\$NtUninstallKB944338$\spuninst\spuninst.txt"
13 Jun 2008 18.38.20 6 966 A.... "C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.inf"
13 Jun 2008 18.38.18 426 A.... "C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.txt"
13 Jun 2008 18.39.16 7 165 A.... "C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.inf"
13 Jun 2008 18.39.14 364 A.... "C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.txt"
13 Jun 2008 18.42.52 672 A.... "C:\WINDOWS\$NtUninstallKB924667$\spuninst\KB924667.asms"
13 Jun 2008 18.42.54 8 528 A.... "C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.inf"
13 Jun 2008 18.42.50 488 A.... "C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.txt"
13 Jun 2008 18.42.08 8 300 A.... "C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.inf"
13 Jun 2008 18.42.04 368 A.... "C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.txt"
13 Jun 2008 18.38.38 7 641 A.... "C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.inf"
13 Jun 2008 18.38.36 673 A.... "C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.txt"
13 Jun 2008 18.34.34 5 867 A.... "C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.inf"
13 Jun 2008 18.34.30 609 A.... "C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.txt"
13 Jun 2008 18.43.58 9 229 A.... "C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.inf"
13 Jun 2008 18.43.56 365 A.... "C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.txt"
9 Jul 2008 18.46.54 13 197 A.... "C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.inf"
9 Jul 2008 18.46.42 1 921 A.... "C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.txt"
13 Jun 2008 18.35.16 5 025 A.... "C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.inf"
13 Jun 2008 18.35.14 191 A.... "C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.txt"
13 Jun 2008 18.39.10 6 755 A.... "C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.inf"
13 Jun 2008 18.39.10 301 A.... "C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.txt"
13 Jun 2008 18.35.06 4 901 A.... "C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.inf"
13 Jun 2008 18.35.04 183 A.... "C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.txt"
13 Jun 2008 18.35.46 5 715 A.... "C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.inf"
13 Jun 2008 18.35.44 358 A.... "C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.txt"
13 Jun 2008 18.34.44 5 484 A.... "C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.inf"
13 Jun 2008 18.34.42 608 A.... "C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.txt"
13 Jun 2008 18.39.50 7 692 A.... "C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.inf"
13 Jun 2008 18.39.48 510 A.... "C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.txt"
13 Jun 2008 18.44.42 8 484 A.... "C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.inf"
13 Jun 2008 18.44.38 0 A.... "C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.txt"
13 Jun 2008 18.44.36 8 634 A.... "C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.inf"
13 Jun 2008 18.44.32 107 A.... "C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.txt"
13 Jun 2008 18.37.52 6 367 A.... "C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.inf"
13 Jun 2008 18.37.50 309 A.... "C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.txt"
13 Jun 2008 18.42.02 8 763 A.... "C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.inf"
13 Jun 2008 18.42.00 470 A.... "C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.txt"
13 Jun 2008 18.41.38 8 875 A.... "C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.inf"
13 Jun 2008 18.41.36 703 A.... "C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.txt"
13 Jun 2008 18.43.00 8 605 A.... "C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.inf"
13 Jun 2008 18.42.56 361 A.... "C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.txt"
13 Jun 2008 18.42.24 7 375 A.... "C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.inf"
13 Jun 2008 18.42.22 91 A.... "C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.txt"
13 Jun 2008 18.43.30 8 792 A.... "C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.inf"
13 Jun 2008 18.43.26 378 A.... "C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.txt"
13 Jun 2008 18.45.18 9 382 A.... "C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.inf"
13 Jun 2008 18.45.16 191 A.... "C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.txt"
13 Jun 2008 18.45.12 10 944 A.... "C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.inf"
13 Jun 2008 18.45.08 1 163 A.... "C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.txt"
13 Jun 2008 18.38.10 16 315 A.... "C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.inf"
13 Jun 2008 18.37.58 5 280 A.... "C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.txt"
13 Jun 2008 18.43.42 9 267 A.... "C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.inf"
13 Jun 2008 18.43.40 417 A.... "C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.txt"
13 Jun 2008 18.35.00 5 348 A.... "C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.inf"
13 Jun 2008 18.34.58 370 A.... "C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.txt"
13 Jun 2008 18.44.48 10 171 A.... "C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.inf"
13 Jun 2008 18.44.46 611 A.... "C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.txt"
13 Jun 2008 18.35.36 12 037 A.... "C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.inf"
13 Jun 2008 18.35.28 4 362 A.... "C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.txt"
13 Jun 2008 18.41.32 7 965 A.... "C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.inf"
13 Jun 2008 18.41.30 528 A.... "C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.txt"
13 Jun 2008 17.16.14 5 251 A.... "C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.inf"
13 Jun 2008 17.16.08 463 A.... "C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.txt"
13 Jun 2008 18.33.38 5 125 A.... "C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.inf"
13 Jun 2008 18.33.34 360 A.... "C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.txt"
13 Jun 2008 18.34.14 4 801 A.... "C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.inf"
13 Jun 2008 18.34.10 317 A.... "C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.txt"
13 Jun 2008 18.34.22 6 720 A.... "C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.inf"
13 Jun 2008 18.34.16 1 110 A.... "C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.txt"
27 Jul 2008 0.14.30 9 096 A.... "C:\WINDOWS\Debug\UserMode\userenv.log"
13 Jun 2008 14.44.20 0 A.... "C:\WINDOWS\Debug\WPD\wpdtrace.log"
13 Jun 2008 14.30.38 12 506 904 A.... "C:\WINDOWS\Downloaded Installations\{4F2720AC-0516-495E-AA54-793C39767899}\ACDSee 5.0 PowerPack.msi"
14 Jun 2008 20.00.16 272 128 ..... "C:\WINDOWS\Driver Cache\i386\bthport.sys"
26 Jul 2008 17.54.40 258 048 A.... "C:\WINDOWS\ERDNT\dss\default"
26 Jul 2008 17.54.04 220 A.... "C:\WINDOWS\ERDNT\dss\README.txt"
26 Jul 2008 17.54.06 24 576 A.... "C:\WINDOWS\ERDNT\dss\sam"
26 Jul 2008 17.54.40 22 208 512 A.... "C:\WINDOWS\ERDNT\dss\software"
26 Jul 2008 17.54.40 3 723 264 A.... "C:\WINDOWS\ERDNT\dss\system"
13 Jun 2008 13.12.02 13 948 A.... "C:\WINDOWS\NLDRV\001\iaahci.PNF"
13 Jun 2008 13.12.02 13 084 A.... "C:\WINDOWS\NLDRV\001\iastor.PNF"
13 Jun 2008 13.12.02 5 512 A.... "C:\WINDOWS\NLDRV\001\INFCACHE.1"
13 Jun 2008 14.44.54 3 153 920 A.... "C:\WINDOWS\security\Database\secedit.sdb"
13 Jun 2008 11.20.36 823 628 A.... "C:\WINDOWS\security\templates\setup security.inf"
27 Jul 2008 0.14.32 5 132 A.... "C:\WINDOWS\system32\(null)\tvtsched.log"
20 Jun 2008 12.44.38 138 368 A.... "C:\WINDOWS\system32\dllcache\afd.sys"
14 Jun 2008 20.00.16 272 128 A.... "C:\WINDOWS\system32\dllcache\bthport.sys"
20 Jun 2008 19.42.16 148 992 A.... "C:\WINDOWS\system32\dllcache\dnsapi.dll"
20 Jun 2008 19.42.16 247 296 A.... "C:\WINDOWS\system32\dllcache\mswsock.dll"
20 Jun 2008 12.45.14 360 320 A.... "C:\WINDOWS\system32\dllcache\tcpip.sys"
20 Jun 2008 11.52.06 225 920 A.... "C:\WINDOWS\system32\dllcache\tcpip6.sys"
13 Jun 2008 14.20.22 17 801 A.... "C:\WINDOWS\system32\drivers\AegisP.sys"
20 Jun 2008 12.44.38 138 368 A.... "C:\WINDOWS\system32\drivers\afd.sys"
14 Jun 2008 20.00.16 272 128 A.... "C:\WINDOWS\system32\drivers\bthport.sys"
13 Jun 2008 14.17.46 0 A..HR "C:\WINDOWS\system32\drivers\IBM_2373_HTG_TP.MRK"
23 Jul 2008 20.09.38 17 144 A.... "C:\WINDOWS\system32\drivers\mbam.sys"
23 Jul 2008 20.09.44 38 472 A.... "C:\WINDOWS\system32\drivers\mbamswissarmy.sys"
20 Jun 2008 12.45.14 360 320 A.... "C:\WINDOWS\system32\drivers\tcpip.sys"
20 Jun 2008 11.52.06 225 920 A.... "C:\WINDOWS\system32\drivers\tcpip6.sys"
13 Jun 2008 11.16.36 4 194 304 ..... "C:\WINDOWS\system32\MsDtc\MSDTC.LOG"
16 Jun 2008 18.49.50 78 A.... "C:\WINDOWS\system32\Restore\MachineGuid.txt"
18 Jun 2008 23.23.02 3 243 A.... "C:\WINDOWS\system32\wbem\Outlook_01c8d1897cee4750.mof"
13 Jun 2008 11.19.12 1 440 054 A.... "C:\WINDOWS\Web\Wallpaper\Nebe.bmp"
13 Jun 2008 13.10.10 1 862 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest"
13 Jun 2008 13.10.14 1 819 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7.Manifest"
13 Jun 2008 13.10.16 500 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_b2505ed9.Manifest"
13 Jun 2008 13.10.14 443 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries.Resources_6595b64144ccf1df_6.0.0.0_cs-CZ_8b83fff2.Manifest"
13 Jun 2008 13.10.16 494 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a.Manifest"
13 Jun 2008 13.10.02 1 237 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.2600.2000_x-ww_bcc9a281.Manifest"
13 Jun 2008 13.10.02 397 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82.Manifest"
13 Jun 2008 13.10.04 391 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.0.0_x-ww_8d353f13.Manifest"
13 Jun 2008 13.10.06 640 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.0.0_x-ww_fc342b0b.Manifest"
13 Jun 2008 12.07.10 8 173 A.... "C:\WINDOWS\WinSxS\Manifests\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790.manifest"
13 Jun 2008 13.10.14 1 784 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest"
13 Jun 2008 18.42.52 1 822 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a.Manifest"
13 Jun 2008 13.10.06 1 877 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7.Manifest"
13 Jun 2008 13.10.08 1 177 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95.Manifest"
13 Jun 2008 13.10.08 460 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_cs_d92a54f9.Manifest"
13 Jun 2008 18.37.18 1 862 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03.Manifest"
13 Jun 2008 12.07.10 258 048 A.... "C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll"
13 Jun 2008 12.07.10 114 176 A.... "C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll"
14 Jun 2008 20.05.50 272 128 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\SP2QFE\bthport.sys"
14 Jun 2008 19.35.32 272 128 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\SP3GDR\bthport.sys"
14 Jun 2008 19.40.30 272 128 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\SP3QFE\bthport.sys"
16 Jun 2008 19.23.00 926 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\update\branches.inf"
16 Jun 2008 20.15.36 12 431 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\update\KB951376-v2.CAT"
16 Jun 2008 22.25.46 390 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\update\update.ver"
16 Jun 2008 19.23.00 681 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\update\updatebr.inf"
16 Jun 2008 20.00.46 23 667 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\update\update_SP2QFE.inf"
16 Jun 2008 20.21.58 26 035 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\update\update_SP3GDR.inf"
16 Jun 2008 19.59.46 26 035 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\update\update_SP3QFE.inf"
20 Jun 2008 12.44.08 138 368 A.... "C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\afd.sys"
20 Jun 2008 19.37.40 147 968 A.... "C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\dnsapi.dll"
20 Jun 2008 19.37.40 247 296 A.... "C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\mswsock.dll"
20 Jun 2008 12.44.42 360 960 A.... "C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys"
20 Jun 2008 11.32.40 225 920 A.... "C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip6.sys"
20 Jun 2008 13.40.08 138 496 A.... "C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\afd.sys"
20 Jun 2008 19.49.26 147 968 A.... "C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\dnsapi.dll"
20 Jun 2008 19.49.26 247 296 A.... "C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\mswsock.dll"
20 Jun 2008 13.51.12 361 600 A.... "C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys"
20 Jun 2008 13.08.28 225 856 A.... "C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip6.sys"
20 Jun 2008 13.48.04 138 496 A.... "C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\afd.sys"
20 Jun 2008 19.44.40 147 968 A.... "C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\dnsapi.dll"
20 Jun 2008 19.44.40 247 296 A.... "C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\mswsock.dll"
20 Jun 2008 13.59.02 361 600 A.... "C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys"
20 Jun 2008 13.16.44 225 856 A.... "C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip6.sys"
20 Jun 2008 19.57.22 926 A.... "C:\WINDOWS\$hf_mig$\KB951748\update\branches.inf"
21 Jun 2008 12.36.20 18 785 A.... "C:\WINDOWS\$hf_mig$\KB951748\update\KB951748.CAT"
21 Jun 2008 13.01.58 2 032 A.... "C:\WINDOWS\$hf_mig$\KB951748\update\update.ver"
18 Jun 2008 21.15.00 678 A.... "C:\WINDOWS\$hf_mig$\KB951748\update\updatebr.inf"
21 Jun 2008 12.42.30 24 029 A.... "C:\WINDOWS\$hf_mig$\KB951748\update\update_SP2QFE.inf"
21 Jun 2008 12.59.58 26 293 A.... "C:\WINDOWS\$hf_mig$\KB951748\update\update_SP3GDR.inf"
21 Jun 2008 12.41.56 26 293 A.... "C:\WINDOWS\$hf_mig$\KB951748\update\update_SP3QFE.inf"
13 Jun 2008 12.08.34 28 200 A.... "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen.log"
13 Jun 2008 12.12.32 89 982 A.... "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen_service.log"
18 Jun 2008 19.12.24 15 736 832 A.... "C:\WINDOWS\pchealth\helpctr\Database\HCdata.edb"
18 Jun 2008 19.11.44 3 005 230 A.... "C:\WINDOWS\pchealth\helpctr\Indices\merged.hhk"
18 Jun 2008 19.11.46 13 290 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_2.hhk"
18 Jun 2008 19.11.46 16 888 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_3.hhk"
18 Jun 2008 19.11.46 35 165 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_4.hhk"
18 Jun 2008 19.11.46 19 308 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_5.hhk"
18 Jun 2008 19.11.46 15 893 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_6.hhk"
18 Jun 2008 19.11.46 103 459 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_7.hhk"
18 Jun 2008 19.11.46 215 664 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_8.hhk"
18 Jun 2008 19.11.46 50 803 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_9.hhk"
18 Jun 2008 19.12.00 425 833 A.... "C:\WINDOWS\pchealth\helpctr\Logs\hcupdate.log"
18 Jun 2008 19.12.00 86 327 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat"
18 Jun 2008 19.12.00 4 A.... "C:\WINDOWS\pchealth\helpctr\PackageStore\CRC_Disk"
13 Jun 2008 11.19.30 783 ..SHR "C:\WINDOWS\pchealth\helpctr\PackageStore\package_1.cab"
13 Jun 2008 11.19.30 20 362 ..SHR "C:\WINDOWS\pchealth\helpctr\PackageStore\package_2.cab"
13 Jun 2008 11.19.30 246 649 ..SHR "C:\WINDOWS\pchealth\helpctr\PackageStore\package_3.cab"
18 Jun 2008 19.12.00 2 426 A.... "C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin"
13 Jun 2008 11.19.30 6 162 A.... "C:\WINDOWS\pchealth\helpctr\System\Headlines.htm"
13 Jun 2008 11.19.30 5 812 A.... "C:\WINDOWS\pchealth\helpctr\System\HelpCtr.mmf"
13 Jun 2008 11.19.30 7 811 A.... "C:\WINDOWS\pchealth\helpctr\System\HomePage__DESKTOP.htm"
13 Jun 2008 11.19.30 7 500 A.... "C:\WINDOWS\pchealth\helpctr\System\HomePage__SERVER.htm"
13 Jun 2008 14.43.36 578 A.... "C:\WINDOWS\RegisteredPackages\{077ACEC7-979C-40AB-9835-435BA1511E0D}$BACKUP$\System\$BackupData$"
13 Jun 2008 14.44.06 578 A.... "C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\$BackupData$"
13 Jun 2008 14.44.52 578 A.... "C:\WINDOWS\RegisteredPackages\{3FDF25EE-E592-4495-8391-6E9C504DAC2B}$BACKUP$\System\$BackupData$"
13 Jun 2008 14.44.50 578 A.... "C:\WINDOWS\RegisteredPackages\{60204BB3-7078-4F70-8F69-68297621941C}$BACKUP$\System\$BackupData$"
13 Jun 2008 14.44.12 578 A.... "C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}$BACKUP$\System\$BackupData$"
13 Jun 2008 14.43.48 578 A.... "C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\$BackupData$"
13 Jun 2008 14.43.52 578 A.... "C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\$BackupData$"
13 Jun 2008 14.43.42 578 A.... "C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\$BackupData$"
13 Jun 2008 14.44.48 578 A.... "C:\WINDOWS\RegisteredPackages\{CFB4B314-0328-45E1-94AF-45A3F5F48E0B}$BACKUP$\System\$BackupData$"
13 Jun 2008 14.44.24 578 A.... "C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\$BackupData$"
13 Jun 2008 13.10.24 8 A.... "C:\WINDOWS\system32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\TimeStamp"
16 Jun 2008 20.15.36 12 431 ..S.. "C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB951376-v2.cat"
21 Jun 2008 12.36.20 18 785 ..S.. "C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB951748.cat"
9 Jul 2008 18.46.54 8 A.... "C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\TimeStamp"
26 Jul 2008 17.26.52 686 A.... "C:\WINDOWS\system32\drivers\etc\HOSTS"
15 Jun 2008 23.23.32 11 931 A.... "C:\WINDOWS\system32\Macromed\Flash\install.log"
15 Jun 2008 23.22.46 70 264 A.... "C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe"
13 Jun 2008 11.22.48 24 576 A.... "C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log"
13 Jun 2008 11.17.08 33 396 A.... "C:\WINDOWS\system32\wbem\AutoRecover\02E78424AB18BDBFA706C08B7D7B9F1D.mof"
13 Jun 2008 11.17.08 23 798 A.... "C:\WINDOWS\system32\wbem\AutoRecover\092389D621F5A8834203DAAC74CCA279.mof"
13 Jun 2008 11.17.06 130 456 A.... "C:\WINDOWS\system32\wbem\AutoRecover\0A9DBC92D554324656F61F9862679F27.mof"
13 Jun 2008 11.17.10 7 694 A.... "C:\WINDOWS\system32\wbem\AutoRecover\1E97A05DE566CF6EEAE29D0634E27392.mof"
13 Jun 2008 12.07.22 68 372 A.... "C:\WINDOWS\system32\wbem\AutoRecover\1EBE968EB7AF815A32641E6185350A9E.mof"
13 Jun 2008 11.17.08 3 352 A.... "C:\WINDOWS\system32\wbem\AutoRecover\20D2C3B8CE10B96CE6B8A3C241EF4416.mof"
13 Jun 2008 11.17.04 2 774 334 A.... "C:\WINDOWS\system32\wbem\AutoRecover\26C097A9392F8C541AD42E89B7909073.mof"
13 Jun 2008 11.17.10 10 452 A.... "C:\WINDOWS\system32\wbem\AutoRecover\26D6C4EB696DD0C83F5D5BF2235000A7.mof"
13 Jun 2008 11.17.08 16 768 A.... "C:\WINDOWS\system32\wbem\AutoRecover\2A61A823DC2C1C838EE71C4351BED0B4.mof"
13 Jun 2008 11.17.06 41 508 A.... "C:\WINDOWS\system32\wbem\AutoRecover\2AA23BB86A5EBD8BC2D820944E55B233.mof"
13 Jun 2008 11.17.08 13 448 A.... "C:\WINDOWS\system32\wbem\AutoRecover\2C142C4C15E3B8D139B98154CD083071.mof"
13 Jun 2008 11.17.08 44 084 A.... "C:\WINDOWS\system32\wbem\AutoRecover\2CE64FBD51953C097BB5470043A6DAF9.mof"
13 Jun 2008 11.17.08 12 256 A.... "C:\WINDOWS\system32\wbem\AutoRecover\2CFB5B149FA396D1AEA5F89B1C5A8D81.mof"
13 Jun 2008 11.17.10 3 182 A.... "C:\WINDOWS\system32\wbem\AutoRecover\2DA80135BA8EC175C9B1C1598F659434.mof"
13 Jun 2008 11.17.06 29 862 A.... "C:\WINDOWS\system32\wbem\AutoRecover\37134956F76D3C30C9BE0C12571CAF43.mof"
13 Jun 2008 11.17.06 1 987 264 A.... "C:\WINDOWS\system32\wbem\AutoRecover\3EC317800FF508210BB945C81C0EACE7.mof"
13 Jun 2008 11.17.08 13 986 A.... "C:\WINDOWS\system32\wbem\AutoRecover\42355E8E232EF8CADD187D531DEC55DD.mof"
13 Jun 2008 11.17.10 16 914 A.... "C:\WINDOWS\system32\wbem\AutoRecover\42C894EEACAD83A4E41154685841B3E1.mof"
13 Jun 2008 11.17.10 19 372 A.... "C:\WINDOWS\system32\wbem\AutoRecover\608B41C6A2CD9460C2263E6CD80C335A.mof"
13 Jun 2008 11.17.08 5 110 A.... "C:\WINDOWS\system32\wbem\AutoRecover\60A06765DDFE47EF7240BD9C1EB29EFE.mof"
13 Jun 2008 11.17.08 107 982 A.... "C:\WINDOWS\system32\wbem\AutoRecover\6B38F33147D0369D5038BBB61C7A31C8.mof"
13 Jun 2008 11.19.50 8 820 A.... "C:\WINDOWS\system32\wbem\AutoRecover\6FFF7467A5B40765D5740A413CA8BB8A.mof"
13 Jun 2008 11.17.08 58 940 A.... "C:\WINDOWS\system32\wbem\AutoRecover\701B705ED7DF100F88D5BC4A595E938D.mof"
13 Jun 2008 11.17.08 127 988 A.... "C:\WINDOWS\system32\wbem\AutoRecover\72F867EF62976CE9F70993FF3E68A4EB.mof"
13 Jun 2008 11.17.10 43 182 A.... "C:\WINDOWS\system32\wbem\AutoRecover\731AE1FC8C795979F40FAD645FFBAEB1.mof"
13 Jun 2008 11.17.10 15 688 A.... "C:\WINDOWS\system32\wbem\AutoRecover\79E817BC978E2D450EB9E3794DFDA6CF.mof"
13 Jun 2008 11.17.08 4 594 A.... "C:\WINDOWS\system32\wbem\AutoRecover\7A62FA52E22CE751514BC93BE067BC80.mof"
13 Jun 2008 11.17.08 4 120 A.... "C:\WINDOWS\system32\wbem\AutoRecover\852ECCDBABE77624586E4417FE66F857.mof"
13 Jun 2008 11.17.08 12 818 A.... "C:\WINDOWS\system32\wbem\AutoRecover\8636DC7F9479DACE6778109CB4FB4B01.mof"
13 Jun 2008 11.17.08 29 386 A.... "C:\WINDOWS\system32\wbem\AutoRecover\88744D2A29102FC88ECF505DD2E984FC.mof"
13 Jun 2008 14.28.10 149 050 A.... "C:\WINDOWS\system32\wbem\AutoRecover\8A94AF24F162D580E3D9889344A3A317.mof"
13 Jun 2008 11.17.08 11 468 A.... "C:\WINDOWS\system32\wbem\AutoRecover\958A50DFF8A9DF5FAEA042AC9F60815F.mof"
13 Jun 2008 11.20.00 2 566 A.... "C:\WINDOWS\system32\wbem\AutoRecover\9AD3182A2F39A3E091E15109132EC6CC.mof"
13 Jun 2008 11.17.06 46 478 A.... "C:\WINDOWS\system32\wbem\AutoRecover\A7575F8DE31A912FFE91A7A41B1E382A.mof"
13 Jun 2008 11.17.08 14 390 A.... "C:\WINDOWS\system32\wbem\AutoRecover\A99860BB696AE92ED001E48B014365CE.mof"
13 Jun 2008 11.17.08 8 664 A.... "C:\WINDOWS\system32\wbem\AutoRecover\ABB70D53B97FC8002205F77E02C97304.mof"
13 Jun 2008 11.17.08 19 462 A.... "C:\WINDOWS\system32\wbem\AutoRecover\AE7023598F41510BF261111652046301.mof"
13 Jun 2008 11.17.08 9 110 A.... "C:\WINDOWS\system32\wbem\AutoRecover\AEA50E449C23761CA4D9B7F9ED0D9C89.mof"
13 Jun 2008 11.17.08 32 772 A.... "C:\WINDOWS\system32\wbem\AutoRecover\BE81B2C0741907C1FC1C42B6223E59AD.mof"
13 Jun 2008 11.19.50 88 742 A.... "C:\WINDOWS\system32\wbem\AutoRecover\C3A0BE17B37ACE48BE78B31580231AE9.mof"
13 Jun 2008 11.17.08 99 856 A.... "C:\WINDOWS\system32\wbem\AutoRecover\C6300BFE37ADE6B52EC023F66124985F.mof"
13 Jun 2008 11.17.08 18 500 A.... "C:\WINDOWS\system32\wbem\AutoRecover\C81ACF420917AA0F87487BC4D958BEB4.mof"
13 Jun 2008 11.17.06 28 022 A.... "C:\WINDOWS\system32\wbem\AutoRecover\C92641594A6F2DA8A55FE4738AFDA539.mof"
13 Jun 2008 11.17.06 38 840 A.... "C:\WINDOWS\system32\wbem\AutoRecover\CA0106054EB09C302ED3E0669F99D021.mof"
13 Jun 2008 11.17.08 4 496 A.... "C:\WINDOWS\system32\wbem\AutoRecover\CFC35B349D24A8495FD2CEAB15C32D88.mof"
13 Jun 2008 11.19.50 294 288 A.... "C:\WINDOWS\system32\wbem\AutoRecover\D724DF13E0B0DF051EB5D403DD8EF2FC.mof"
13 Jun 2008 11.17.10 4 092 A.... "C:\WINDOWS\system32\wbem\AutoRecover\D92470B796B6B18F9EE52301857F0567.mof"
13 Jun 2008 11.17.08 8 560 A.... "C:\WINDOWS\system32\wbem\AutoRecover\DBD781C2C031C708BCB490F228E7BEF9.mof"
13 Jun 2008 11.17.08 165 526 A.... "C:\WINDOWS\system32\wbem\AutoRecover\DC999686F8B85B326CEDFA199DD07F72.mof"
13 Jun 2008 11.17.08 21 220 A.... "C:\WINDOWS\system32\wbem\AutoRecover\DFD614E4D613EF4506AC8F525F5F514B.mof"
13 Jun 2008 11.17.08 10 784 A.... "C:\WINDOWS\system32\wbem\AutoRecover\E04DE4CDFEC284A342159BB920976701.mof"
13 Jun 2008 11.17.10 10 848 A.... "C:\WINDOWS\system32\wbem\AutoRecover\E441354B9FE5F63362A481C9B9195A73.mof"
13 Jun 2008 11.17.08 58 852 A.... "C:\WINDOWS\system32\wbem\AutoRecover\E737DE61441445E1FDFCA45EF5E7D987.mof"
13 Jun 2008 11.17.08 6 600 A.... "C:\WINDOWS\system32\wbem\AutoRecover\EDBF963FB003D0670AA9C2219BD091FB.mof"
13 Jun 2008 11.17.08 61 314 A.... "C:\WINDOWS\system32\wbem\AutoRecover\FAAD7D567E76CAB10704AFD7C0488F23.mof"
13 Jun 2008 13.10.12 621 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2180.Policy"
13 Jun 2008 18.37.18 621 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2982.Policy"
13 Jun 2008 13.10.16 623 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.7.0.Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_x-ww_a317e4b3\7.0.2600.2180.Policy"
13 Jun 2008 13.10.10 641 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.5.2.Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_x-ww_362e60dd\5.2.2.3.Policy"
13 Jun 2008 13.10.04 605 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.1.0.Microsoft.Windows.GdiPlus_6595b64144ccf1df_x-ww_4e8510ac\1.0.2600.2180.Policy"
13 Jun 2008 13.10.10 641 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.5.2.Microsoft.Windows.Networking.Rtcdll_6595b64144ccf1df_x-ww_c7b7206f\5.2.2.3.Policy"
13 Jun 2008 18.42.52 644 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_x-ww_527a1c68\6.0.9792.0.Policy"
13 Jun 2008 13.10.06 623 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.5.1.Microsoft.Windows.SystemCompatible_6595b64144ccf1df_x-ww_a0111510\5.1.2600.2000.Policy"
18 Jun 2008 19.11.46 62 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000000.query"
18 Jun 2008 19.11.46 752 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000001.query"
18 Jun 2008 19.11.46 752 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000002.query"
18 Jun 2008 19.11.46 194 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000004.query"
18 Jun 2008 19.11.50 258 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000100.query"
18 Jun 2008 19.11.50 2 950 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000102.query"
18 Jun 2008 19.11.50 2 950 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000103.query"
18 Jun 2008 19.11.50 242 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000104.query"
18 Jun 2008 19.11.56 288 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000200.query"
18 Jun 2008 19.11.56 6 044 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000202.query"
18 Jun 2008 19.11.56 6 044 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000203.query"
18 Jun 2008 19.11.56 214 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000204.query"
18 Jun 2008 19.11.46 1 712 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000006.query"
18 Jun 2008 19.11.50 7 850 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000106.query"
18 Jun 2008 19.11.56 2 408 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000206.query"
18 Jun 2008 19.11.46 1 712 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000005.query"
18 Jun 2008 19.11.50 7 850 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000107.query"
18 Jun 2008 19.11.48 2 430 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000086.query"
18 Jun 2008 19.11.52 5 352 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000186.query"
18 Jun 2008 19.11.58 914 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000286.query"
18 Jun 2008 19.11.48 386 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000084.query"
18 Jun 2008 19.11.58 3 876 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000283.query"
18 Jun 2008 19.11.52 254 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000184.query"
18 Jun 2008 19.11.48 2 430 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000085.query"
18 Jun 2008 19.11.58 130 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000284.query"
18 Jun 2008 19.11.52 6 428 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000183.query"
18 Jun 2008 19.11.48 8 700 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000082.query"
18 Jun 2008 19.11.52 6 428 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000182.query"
18 Jun 2008 19.11.48 8 700 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000083.query"
18 Jun 2008 19.11.58 3 876 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000282.query"
18 Jun 2008 19.11.48 210 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000080.query"
18 Jun 2008 19.11.52 310 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000180.query"
18 Jun 2008 19.11.58 172 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000280.query"
18 Jun 2008 19.11.52 5 352 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000187.query"
18 Jun 2008 19.11.46 2 676 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000016.query"
18 Jun 2008 19.11.50 506 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000116.query"
18 Jun 2008 19.11.46 2 676 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000017.query"
18 Jun 2008 19.11.56 354 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000216.query"
18 Jun 2008 19.11.50 506 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000115.query"
18 Jun 2008 19.11.46 314 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000014.query"
18 Jun 2008 19.11.56 5 068 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000213.query"
18 Jun 2008 19.11.50 362 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000114.query"
18 Jun 2008 19.11.56 196 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000214.query"
18 Jun 2008 19.11.50 2 050 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000113.query"
18 Jun 2008 19.11.46 680 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000012.query"
18 Jun 2008 19.11.56 368 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000211.query"
18 Jun 2008 19.11.50 2 050 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000112.query"
18 Jun 2008 19.11.46 680 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000013.query"
18 Jun 2008 19.11.56 5 428 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000212.query"
18 Jun 2008 19.11.46 236 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000010.query"
18 Jun 2008 19.11.50 188 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000110.query"
18 Jun 2008 19.11.56 164 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000210.query"
18 Jun 2008 19.11.48 1 922 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000096.query"
18 Jun 2008 19.12.00 984 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000295.query"
18 Jun 2008 19.11.54 6 728 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000196.query"
18 Jun 2008 19.12.00 984 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000296.query"
18 Jun 2008 19.11.48 296 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000094.query"
18 Jun 2008 19.12.00 2 764 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000293.query"
18 Jun 2008 19.11.54 294 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000194.query"
18 Jun 2008 19.11.48 1 922 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000095.query"
18 Jun 2008 19.12.00 206 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000294.query"
18 Jun 2008 19.11.54 4 206 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000193.query"
18 Jun 2008 19.11.48 7 348 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000092.query"
18 Jun 2008 19.11.54 4 206 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000192.query"
18 Jun 2008 19.11.48 7 348 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000093.query"
18 Jun 2008 19.12.00 2 764 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000292.query"
18 Jun 2008 19.11.48 218 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000090.query"
18 Jun 2008 19.11.54 278 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000190.query"
18 Jun 2008 19.12.00 206 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000290.query"
18 Jun 2008 19.11.54 6 728 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000197.query"
18 Jun 2008 19.11.50 1 836 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000a6.query"
18 Jun 2008 19.11.54 3 638 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001a7.query"
18 Jun 2008 19.11.50 1 836 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000a7.query"
18 Jun 2008 19.12.00 4 932 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002a6.query"
18 Jun 2008 19.11.54 160 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001a4.query"
18 Jun 2008 19.11.50 280 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000a4.query"
18 Jun 2008 19.12.00 260 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002a3.query"
18 Jun 2008 19.12.00 126 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002a4.query"
18 Jun 2008 19.11.54 4 006 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001a2.query"
18 Jun 2008 19.11.48 3 422 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000a2.query"
18 Jun 2008 19.11.54 4 006 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001a3.query"
18 Jun 2008 19.11.48 3 422 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000a3.query"
18 Jun 2008 19.12.00 260 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002a2.query"
18 Jun 2008 19.11.54 182 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001a0.query"
18 Jun 2008 19.11.48 240 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000a0.query"
18 Jun 2008 19.12.00 132 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002a0.query"
18 Jun 2008 19.11.54 3 638 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001a6.query"
18 Jun 2008 19.11.48 1 660 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000026.query"
18 Jun 2008 19.11.56 1 938 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000225.query"
18 Jun 2008 19.11.52 6 414 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000126.query"
18 Jun 2008 19.11.56 1 938 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000226.query"
18 Jun 2008 19.11.48 418 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000024.query"
18 Jun 2008 19.11.56 1 360 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000223.query"
18 Jun 2008 19.11.52 252 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000124.query"
18 Jun 2008 19.11.48 1 660 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000025.query"
18 Jun 2008 19.11.56 88 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000224.query"
18 Jun 2008 19.11.52 3 574 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000123.query"
18 Jun 2008 19.11.48 776 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000022.query"
18 Jun 2008 19.11.52 3 574 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000122.query"
18 Jun 2008 19.11.48 776 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000023.query"
18 Jun 2008 19.11.56 1 360 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000222.query"
18 Jun 2008 19.11.48 288 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000020.query"
18 Jun 2008 19.11.52 256 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000120.query"
18 Jun 2008 19.11.56 100 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000220.query"
18 Jun 2008 19.11.52 6 414 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000127.query"
18 Jun 2008 19.11.50 2 594 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000b6.query"
18 Jun 2008 19.11.54 3 148 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001b7.query"
18 Jun 2008 19.12.00 1 914 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002b6.query"
18 Jun 2008 19.11.54 242 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001b4.query"
18 Jun 2008 19.11.50 442 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000b4.query"
18 Jun 2008 19.12.00 1 910 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002b3.query"
18 Jun 2008 19.11.50 2 594 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000b5.query"
18 Jun 2008 19.12.00 206 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002b4.query"
18 Jun 2008 19.11.54 3 288 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001b2.query"
18 Jun 2008 19.11.50 1 642 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000b2.query"
18 Jun 2008 19.11.54 3 288 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001b3.query"
18 Jun 2008 19.11.50 1 642 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000b3.query"
18 Jun 2008 19.12.00 1 910 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002b2.query"
18 Jun 2008 19.11.54 148 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001b0.query"
18 Jun 2008 19.11.50 184 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000b0.query"
18 Jun 2008 19.12.00 348 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002b0.query"
18 Jun 2008 19.11.54 3 148 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001b6.query"
18 Jun 2008 19.11.48 970 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000036.query"
18 Jun 2008 19.11.52 4 414 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000136.query"
18 Jun 2008 19.11.56 2 148 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000236.query"
18 Jun 2008 19.11.48 536 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000034.query"
18 Jun 2008 19.11.52 292 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000134.query"
18 Jun 2008 19.11.48 970 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000035.query"
18 Jun 2008 19.11.56 194 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000234.query"
18 Jun 2008 19.11.48 558 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000032.query"
18 Jun 2008 19.11.56 2 644 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000231.query"
18 Jun 2008 19.11.52 2 174 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000132.query"
18 Jun 2008 19.11.56 2 644 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000232.query"
18 Jun 2008 19.11.52 2 174 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000131.query"
18 Jun 2008 19.11.48 390 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000030.query"
18 Jun 2008 19.11.52 428 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000130.query"
18 Jun 2008 19.11.48 558 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000031.query"
18 Jun 2008 19.11.56 288 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000230.query"
18 Jun 2008 19.11.52 4 414 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000137.query"
18 Jun 2008 19.11.50 2 982 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000c6.query"
18 Jun 2008 19.11.54 298 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001c7.query"
18 Jun 2008 19.11.50 2 982 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000c7.query"
18 Jun 2008 19.12.00 3 494 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002c6.query"
18 Jun 2008 19.11.54 246 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001c4.query"
18 Jun 2008 19.11.50 252 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000c4.query"
18 Jun 2008 19.12.00 3 502 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002c3.query"
18 Jun 2008 19.11.54 560 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001c5.query"
18 Jun 2008 19.12.00 220 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002c4.query"
18 Jun 2008 19.11.54 540 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001c2.query"
18 Jun 2008 19.11.50 6 650 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000c2.query"
18 Jun 2008 19.11.50 6 650 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000c3.query"
18 Jun 2008 19.12.00 3 502 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002c2.query"
18 Jun 2008 19.11.54 290 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001c0.query"
18 Jun 2008 19.11.50 206 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000c0.query"
18 Jun 2008 19.11.54 540 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001c1.query"
18 Jun 2008 19.12.00 256 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002c0.query"
18 Jun 2008 19.11.54 850 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001c6.query"
18 Jun 2008 19.11.48 4 060 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000046.query"
18 Jun 2008 19.11.52 1 394 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000146.query"
18 Jun 2008 19.11.48 4 060 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000047.query"
18 Jun 2008 19.11.58 5 344 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000246.query"
18 Jun 2008 19.11.48 192 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000044.query"
18 Jun 2008 19.11.52 250 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000144.query"
18 Jun 2008 19.11.58 194 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000244.query"
18 Jun 2008 19.11.52 6 054 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000143.query"
18 Jun 2008 19.11.48 4 164 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000042.query"
18 Jun 2008 19.11.58 3 102 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000241.query"
18 Jun 2008 19.11.52 6 054 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000142.query"
18 Jun 2008 19.11.48 4 164 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000043.query"
18 Jun 2008 19.11.58 3 102 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000242.query"
18 Jun 2008 19.11.48 196 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000040.query"
18 Jun 2008 19.11.52 288 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000140.query"
18 Jun 2008 19.11.58 196 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000240.query"
18 Jun 2008 19.11.52 1 394 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000147.query"
18 Jun 2008 19.11.50 2 204 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000d6.query"
18 Jun 2008 19.11.54 9 774 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001d7.query"
18 Jun 2008 19.11.50 2 204 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000d7.query"
18 Jun 2008 19.11.54 196 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001d4.query"
18 Jun 2008 19.11.50 212 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000d4.query"
18 Jun 2008 19.11.54 2 296 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001d2.query"
18 Jun 2008 19.11.50 10 100 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000d2.query"
18 Jun 2008 19.11.54 2 296 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001d3.query"
18 Jun 2008 19.11.50 10 100 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000d3.query"
18 Jun 2008 19.11.54 198 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001d0.query"
18 Jun 2008 19.11.50 202 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000d0.query"
18 Jun 2008 19.11.54 9 774 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001d6.query"
18 Jun 2008 19.11.48 2 504 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000056.query"
18 Jun 2008 19.11.52 914 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000156.query"
18 Jun 2008 19.11.48 2 504 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000057.query"
18 Jun 2008 19.11.58 1 658 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000256.query"
18 Jun 2008 19.11.52 914 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000155.query"
18 Jun 2008 19.11.48 248 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000054.query"
18 Jun 2008 19.11.52 430 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000154.query"
18 Jun 2008 19.11.58 198 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000254.query"
18 Jun 2008 19.11.48 1 364 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000052.query"
18 Jun 2008 19.11.58 1 436 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000251.query"
18 Jun 2008 19.11.52 2 116 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000152.query"
18 Jun 2008 19.11.58 1 436 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000252.query"
18 Jun 2008 19.11.52 2 116 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000151.query"
18 Jun 2008 19.11.48 408 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000050.query"
18 Jun 2008 19.11.52 194 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000150.query"
18 Jun 2008 19.11.48 1 364 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000051.query"
18 Jun 2008 19.11.58 148 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000250.query"
18 Jun 2008 19.11.50 2 562 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000e6.query"
18 Jun 2008 19.11.56 3 836 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001e7.query"
18 Jun 2008 19.11.50 2 562 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000e7.query"
18 Jun 2008 19.11.54 242 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001e4.query"
18 Jun 2008 19.11.50 236 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000e4.query"
18 Jun 2008 19.11.54 3 190 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001e2.query"
18 Jun 2008 19.11.50 5 908 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000e2.query"
18 Jun 2008 19.11.54 3 190 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001e3.query"
18 Jun 2008 19.11.50 5 908 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000e3.query"
18 Jun 2008 19.11.54 244 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001e0.query"
18 Jun 2008 19.11.50 186 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000e0.query"
18 Jun 2008 19.11.56 3 836 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001e6.query"
18 Jun 2008 19.11.48 1 968 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000066.query"
18 Jun 2008 19.11.58 2 350 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000265.query"
18 Jun 2008 19.11.52 278 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000166.query"
18 Jun 2008 19.11.48 1 968 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000067.query"
18 Jun 2008 19.11.58 2 350 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000266.query"
18 Jun 2008 19.11.48 198 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000064.query"
18 Jun 2008 19.11.58 3 316 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000263.query"
18 Jun 2008 19.11.52 150 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000164.query"
18 Jun 2008 19.11.58 242 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000264.query"
18 Jun 2008 19.11.52 4 236 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000163.query"
18 Jun 2008 19.11.48 2 444 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000062.query"
18 Jun 2008 19.11.52 4 236 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000162.query"
18 Jun 2008 19.11.48 2 444 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000063.query"
18 Jun 2008 19.11.58 3 316 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000262.query"
18 Jun 2008 19.11.48 160 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000060.query"
18 Jun 2008 19.11.52 220 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000160.query"
18 Jun 2008 19.11.58 264 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000260.query"
18 Jun 2008 19.11.52 278 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000167.query"
18 Jun 2008 19.11.50 1 460 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000f6.query"
18 Jun 2008 19.11.56 5 794 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001f7.query"
18 Jun 2008 19.11.50 1 460 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000f7.query"
18 Jun 2008 19.11.56 240 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001f4.query"
18 Jun 2008 19.11.50 214 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000f4.query"
18 Jun 2008 19.11.56 3 602 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001f2.query"
18 Jun 2008 19.11.50 4 572 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000f2.query"
18 Jun 2008 19.11.56 3 602 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001f3.query"
18 Jun 2008 19.11.50 4 572 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000f3.query"
18 Jun 2008 19.11.56 184 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001f0.query"
18 Jun 2008 19.11.50 186 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000f0.query"
18 Jun 2008 19.11.56 5 794 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001f6.query"
18 Jun 2008 19.11.48 2 728 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000076.query"
18 Jun 2008 19.11.58 1 034 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000275.query"
18 Jun 2008 19.11.52 4 282 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000176.query"
18 Jun 2008 19.11.58 1 034 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000276.query"
18 Jun 2008 19.11.48 416 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000074.query"
18 Jun 2008 19.11.58 3 508 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000273.query"
18 Jun 2008 19.11.52 244 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000174.query"
18 Jun 2008 19.11.48 2 728 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000075.query"
18 Jun 2008 19.11.58 320 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000274.query"
18 Jun 2008 19.11.52 3 592 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000173.query"
18 Jun 2008 19.11.48 1 828 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000072.query"
18 Jun 2008 19.11.52 3 592 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000172.query"
18 Jun 2008 19.11.58 3 508 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000272.query"
18 Jun 2008 19.11.48 428 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000070.query"
18 Jun 2008 19.11.52 270 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000170.query"
18 Jun 2008 19.11.48 1 828 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000071.query"
18 Jun 2008 19.11.58 210 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000270.query"
18 Jun 2008 19.11.52 4 282 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000177.query"
18 Jun 2008 19.11.46 516 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000008.query"
18 Jun 2008 19.11.56 2 408 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000207.query"
18 Jun 2008 19.11.50 202 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000108.query"
18 Jun 2008 19.11.46 1 624 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000009.query"
18 Jun 2008 19.11.56 562 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000208.query"
18 Jun 2008 19.11.48 264 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000088.query"
18 Jun 2008 19.11.58 914 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000287.query"
18 Jun 2008 19.11.54 198 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000188.query"
18 Jun 2008 19.12.00 216 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000288.query"
18 Jun 2008 19.11.50 346 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000119.query"
18 Jun 2008 19.11.48 240 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000018.query"
18 Jun 2008 19.11.56 354 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000217.query"
18 Jun 2008 19.11.50 230 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000118.query"
18 Jun 2008 19.11.56 180 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000218.query"
18 Jun 2008 19.12.00 300 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000299.query"
18 Jun 2008 19.11.54 2 890 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000199.query"
18 Jun 2008 19.11.48 176 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000098.query"
18 Jun 2008 19.11.54 384 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000198.query"
18 Jun 2008 19.12.00 240 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000298.query"
18 Jun 2008 19.12.00 1 934 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002a9.query"
18 Jun 2008 19.11.54 124 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001a8.query"
18 Jun 2008 19.11.50 260 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000a8.query"
18 Jun 2008 19.12.00 4 932 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002a7.query"
18 Jun 2008 19.12.00 316 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002a8.query"
18 Jun 2008 19.11.56 2 214 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000229.query"
18 Jun 2008 19.11.48 490 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000028.query"
18 Jun 2008 19.11.52 262 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000128.query"
18 Jun 2008 19.11.48 2 018 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000029.query"
18 Jun 2008 19.11.56 224 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000228.query"
18 Jun 2008 19.11.54 248 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001b8.query"
18 Jun 2008 19.11.50 270 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000b8.query"
18 Jun 2008 19.12.00 1 914 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002b7.query"
18 Jun 2008 19.12.00 248 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002b8.query"
18 Jun 2008 19.11.56 322 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000239.query"
18 Jun 2008 19.11.48 394 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000038.query"
18 Jun 2008 19.11.56 2 148 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000237.query"
18 Jun 2008 19.11.52 320 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000138.query"
18 Jun 2008 19.11.48 1 092 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000039.query"
18 Jun 2008 19.11.56 248 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000238.query"
18 Jun 2008 19.11.54 202 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001c8.query"
18 Jun 2008 19.11.50 248 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000c8.query"
18 Jun 2008 19.12.00 3 494 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002c7.query"
18 Jun 2008 19.12.00 190 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002c8.query"
18 Jun 2008 19.11.58 1 378 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000249.query"
18 Jun 2008 19.11.48 210 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000048.query"
18 Jun 2008 19.11.58 5 344 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000247.query"
18 Jun 2008 19.11.52 352 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000148.query"
18 Jun 2008 19.11.58 270 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000248.query"
18 Jun 2008 19.11.54 342 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001d8.query"
18 Jun 2008 19.11.50 200 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000d8.query"
18 Jun 2008 19.11.54 2 518 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001d9.query"
18 Jun 2008 19.11.52 1 932 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000159.query"
18 Jun 2008 19.11.48 252 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000058.query"
18 Jun 2008 19.11.58 1 658 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000257.query"
18 Jun 2008 19.11.52 256 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000158.query"
18 Jun 2008 19.11.58 200 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000258.query"
18 Jun 2008 19.11.56 266 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001e8.query"
18 Jun 2008 19.11.50 194 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000e8.query"
18 Jun 2008 19.11.50 944 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000e9.query"
18 Jun 2008 19.11.52 2 740 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000169.query"
18 Jun 2008 19.11.48 180 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000068.query"
18 Jun 2008 19.11.52 430 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000168.query"
18 Jun 2008 19.11.58 152 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000268.query"
18 Jun 2008 19.11.56 282 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001f8.query"
18 Jun 2008 19.11.50 190 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000f8.query"
18 Jun 2008 19.11.58 1 544 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000279.query"
18 Jun 2008 19.11.48 286 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000078.query"
18 Jun 2008 19.11.52 226 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000178.query"
18 Jun 2008 19.11.48 3 112 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000079.query"
18 Jun 2008 19.11.58 188 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\00000278.query"
18 Jun 2008 19.11.46 4 292 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000000f.query"
18 Jun 2008 19.11.56 484 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000020e.query"
18 Jun 2008 19.11.50 3 126 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000010f.query"
18 Jun 2008 19.11.50 3 126 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000010e.query"
18 Jun 2008 19.11.56 82 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000020c.query"
18 Jun 2008 19.11.46 4 292 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000000e.query"
18 Jun 2008 19.11.56 484 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000020d.query"
18 Jun 2008 19.11.50 194 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000010c.query"
18 Jun 2008 19.11.50 3 862 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000010b.query"
18 Jun 2008 19.11.46 190 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000000c.query"
18 Jun 2008 19.11.50 3 862 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000010a.query"
18 Jun 2008 19.11.46 1 624 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000000a.query"
18 Jun 2008 19.12.00 1 874 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000028e.query"
18 Jun 2008 19.11.54 2 562 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000018f.query"
18 Jun 2008 19.11.54 2 562 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000018e.query"
18 Jun 2008 19.11.48 1 978 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000008d.query"
18 Jun 2008 19.12.00 286 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000028c.query"
18 Jun 2008 19.11.48 1 978 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000008e.query"
18 Jun 2008 19.12.00 1 874 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000028d.query"
18 Jun 2008 19.11.54 236 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000018c.query"
18 Jun 2008 19.11.48 4 772 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000008b.query"
18 Jun 2008 19.12.00 986 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000028a.query"
18 Jun 2008 19.11.54 5 900 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000018b.query"
18 Jun 2008 19.11.48 578 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000008c.query"
18 Jun 2008 19.12.00 986 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000028b.query"
18 Jun 2008 19.11.54 5 900 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000018a.query"
18 Jun 2008 19.11.48 4 772 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000008a.query"
18 Jun 2008 19.11.52 1 278 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000011e.query"
18 Jun 2008 19.11.48 1 564 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000001d.query"
18 Jun 2008 19.11.56 236 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000021c.query"
18 Jun 2008 19.11.50 1 278 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000011d.query"
18 Jun 2008 19.11.48 1 564 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000001e.query"
18 Jun 2008 19.11.50 440 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000011c.query"
18 Jun 2008 19.11.48 3 454 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000001b.query"
18 Jun 2008 19.11.56 336 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000021a.query"
18 Jun 2008 19.11.50 3 762 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000011b.query"
18 Jun 2008 19.11.48 396 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000001c.query"
18 Jun 2008 19.11.56 336 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000021b.query"
18 Jun 2008 19.11.50 4 100 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000011a.query"
18 Jun 2008 19.11.48 3 454 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000001a.query"
18 Jun 2008 19.11.48 3 552 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000009f.query"
18 Jun 2008 19.12.00 896 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000029e.query"
18 Jun 2008 19.11.54 5 660 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000019f.query"
18 Jun 2008 19.11.54 5 660 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000019e.query"
18 Jun 2008 19.12.00 176 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000029c.query"
18 Jun 2008 19.11.48 3 552 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000009e.query"
18 Jun 2008 19.12.00 896 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000029d.query"
18 Jun 2008 19.11.54 234 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000019c.query"
18 Jun 2008 19.11.48 2 426 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000009b.query"
18 Jun 2008 19.12.00 300 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000029a.query"
18 Jun 2008 19.11.48 176 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000009c.query"
18 Jun 2008 19.11.54 2 890 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000019a.query"
18 Jun 2008 19.11.48 2 426 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000009a.query"
18 Jun 2008 19.11.50 1 942 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000af.query"
18 Jun 2008 19.12.00 1 800 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002ae.query"
18 Jun 2008 19.12.00 1 800 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002af.query"
18 Jun 2008 19.11.54 178 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001ad.query"
18 Jun 2008 19.12.00 298 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002ac.query"
18 Jun 2008 19.11.54 1 758 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001ae.query"
18 Jun 2008 19.11.50 1 942 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000ae.query"
18 Jun 2008 19.11.54 2 272 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001ab.query"
18 Jun 2008 19.11.50 2 682 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000ab.query"
18 Jun 2008 19.12.00 1 934 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002aa.query"
18 Jun 2008 19.11.54 132 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001ac.query"
18 Jun 2008 19.11.50 212 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000ac.query"
18 Jun 2008 19.11.54 2 272 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001aa.query"
18 Jun 2008 19.11.50 2 682 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000aa.query"
18 Jun 2008 19.11.54 1 588 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001af.query"
18 Jun 2008 19.11.56 1 582 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000022e.query"
18 Jun 2008 19.11.48 500 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000002d.query"
18 Jun 2008 19.11.56 166 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000022c.query"
18 Jun 2008 19.11.48 500 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000002e.query"
18 Jun 2008 19.11.56 1 582 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000022d.query"
18 Jun 2008 19.11.52 384 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000012c.query"
18 Jun 2008 19.11.56 2 214 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000022a.query"
18 Jun 2008 19.11.52 2 658 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000012b.query"
18 Jun 2008 19.11.48 268 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000002c.query"
18 Jun 2008 19.11.52 2 658 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000012a.query"
18 Jun 2008 19.11.48 2 018 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000002a.query"
18 Jun 2008 19.11.50 8 452 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000bf.query"
18 Jun 2008 19.12.00 1 640 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002be.query"
18 Jun 2008 19.12.00 1 026 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002bf.query"
18 Jun 2008 19.12.00 224 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002bc.query"
18 Jun 2008 19.11.54 2 778 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001be.query"
18 Jun 2008 19.11.50 8 452 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000be.query"
18 Jun 2008 19.12.00 622 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002bd.query"
18 Jun 2008 19.11.54 4 152 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001bb.query"
18 Jun 2008 19.11.50 9 028 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000bb.query"
18 Jun 2008 19.12.00 2 628 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002ba.query"
18 Jun 2008 19.11.54 196 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001bc.query"
18 Jun 2008 19.11.50 240 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000bc.query"
18 Jun 2008 19.12.00 2 628 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002bb.query"
18 Jun 2008 19.11.54 4 152 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001ba.query"
18 Jun 2008 19.11.50 9 028 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000ba.query"
18 Jun 2008 19.11.54 2 778 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001bf.query"
18 Jun 2008 19.11.58 1 764 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000023e.query"
18 Jun 2008 19.11.52 3 394 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000013f.query"
18 Jun 2008 19.11.52 3 888 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000013e.query"
18 Jun 2008 19.11.48 1 394 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000003d.query"
18 Jun 2008 19.11.58 176 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000023c.query"
18 Jun 2008 19.11.52 502 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000013d.query"
18 Jun 2008 19.11.48 1 394 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000003e.query"
18 Jun 2008 19.11.58 1 764 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000023d.query"
18 Jun 2008 19.11.52 308 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000013c.query"
18 Jun 2008 19.11.56 4 222 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000023a.query"
18 Jun 2008 19.11.52 2 892 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000013b.query"
18 Jun 2008 19.11.48 326 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000003c.query"
18 Jun 2008 19.11.58 3 908 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000023b.query"
18 Jun 2008 19.11.52 2 892 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000013a.query"
18 Jun 2008 19.11.48 1 092 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000003a.query"
18 Jun 2008 19.11.50 2 050 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000cf.query"
18 Jun 2008 19.11.54 4 900 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001ce.query"
18 Jun 2008 19.11.50 2 050 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000ce.query"
18 Jun 2008 19.11.54 1 460 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001cb.query"
18 Jun 2008 19.11.50 9 646 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000cb.query"
18 Jun 2008 19.12.00 2 402 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002ca.query"
18 Jun 2008 19.11.54 204 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001cc.query"
18 Jun 2008 19.11.50 192 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000cc.query"
18 Jun 2008 19.12.00 2 402 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000002cb.query"
18 Jun 2008 19.11.54 1 460 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001ca.query"
18 Jun 2008 19.11.50 9 646 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000ca.query"
18 Jun 2008 19.11.54 4 900 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001cf.query"
18 Jun 2008 19.11.48 4 370 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000004f.query"
18 Jun 2008 19.11.58 2 290 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000024e.query"
18 Jun 2008 19.11.52 890 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000014e.query"
18 Jun 2008 19.11.58 406 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000024c.query"
18 Jun 2008 19.11.52 890 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000014d.query"
18 Jun 2008 19.11.48 4 370 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000004e.query"
18 Jun 2008 19.11.58 2 290 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000024d.query"
18 Jun 2008 19.11.52 412 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000014c.query"
18 Jun 2008 19.11.48 2 380 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000004b.query"
18 Jun 2008 19.11.58 1 378 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000024a.query"
18 Jun 2008 19.11.48 200 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000004c.query"
18 Jun 2008 19.11.48 2 380 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000004a.query"
18 Jun 2008 19.11.50 2 804 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000df.query"
18 Jun 2008 19.11.54 8 746 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001de.query"
18 Jun 2008 19.11.50 2 804 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000de.query"
18 Jun 2008 19.11.50 2 448 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000db.query"
18 Jun 2008 19.11.54 172 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001dc.query"
18 Jun 2008 19.11.50 238 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000dc.query"
18 Jun 2008 19.11.54 2 518 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001da.query"
18 Jun 2008 19.11.50 2 448 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000da.query"
18 Jun 2008 19.11.54 8 746 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001df.query"
18 Jun 2008 19.11.48 5 636 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000005f.query"
18 Jun 2008 19.11.58 3 192 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000025e.query"
18 Jun 2008 19.11.58 3 192 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000025f.query"
18 Jun 2008 19.11.52 756 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000015e.query"
18 Jun 2008 19.11.58 192 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000025c.query"
18 Jun 2008 19.11.52 756 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000015d.query"
18 Jun 2008 19.11.48 5 636 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000005e.query"
18 Jun 2008 19.11.52 312 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000015c.query"
18 Jun 2008 19.11.48 2 240 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000005b.query"
18 Jun 2008 19.11.58 1 902 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000025a.query"
18 Jun 2008 19.11.48 366 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000005c.query"
18 Jun 2008 19.11.58 1 902 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000025b.query"
18 Jun 2008 19.11.52 1 932 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000015a.query"
18 Jun 2008 19.11.48 2 240 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000005a.query"
18 Jun 2008 19.11.50 3 946 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000ed.query"
18 Jun 2008 19.11.56 4 596 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001ee.query"
18 Jun 2008 19.11.50 3 946 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000ee.query"
18 Jun 2008 19.11.56 2 082 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001eb.query"
18 Jun 2008 19.11.56 230 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001ec.query"
18 Jun 2008 19.11.50 524 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000ec.query"
18 Jun 2008 19.11.56 2 082 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001ea.query"
18 Jun 2008 19.11.50 944 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000ea.query"
18 Jun 2008 19.11.56 4 596 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001ef.query"
18 Jun 2008 19.11.58 632 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000026e.query"
18 Jun 2008 19.11.52 3 406 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000016f.query"
18 Jun 2008 19.11.58 632 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000026f.query"
18 Jun 2008 19.11.52 3 406 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000016e.query"
18 Jun 2008 19.11.48 1 432 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000006d.query"
18 Jun 2008 19.11.58 196 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000026c.query"
18 Jun 2008 19.11.48 1 432 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000006e.query"
18 Jun 2008 19.11.52 206 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000016c.query"
18 Jun 2008 19.11.48 1 632 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000006b.query"
18 Jun 2008 19.11.58 3 042 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000026a.query"
18 Jun 2008 19.11.48 194 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000006c.query"
18 Jun 2008 19.11.58 3 042 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000026b.query"
18 Jun 2008 19.11.52 2 740 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000016a.query"
18 Jun 2008 19.11.48 1 632 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000006a.query"
18 Jun 2008 19.11.50 3 622 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000ff.query"
18 Jun 2008 19.11.56 3 256 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001fe.query"
18 Jun 2008 19.11.50 3 622 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000fe.query"
18 Jun 2008 19.11.56 5 460 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001fb.query"
18 Jun 2008 19.11.50 1 892 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000fb.query"
18 Jun 2008 19.11.56 236 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001fc.query"
18 Jun 2008 19.11.50 206 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000fc.query"
18 Jun 2008 19.11.56 5 460 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001fa.query"
18 Jun 2008 19.11.50 1 892 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000000fa.query"
18 Jun 2008 19.11.56 3 256 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\000001ff.query"
18 Jun 2008 19.11.48 8 800 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000007f.query"
18 Jun 2008 19.11.58 2 558 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000027e.query"
18 Jun 2008 19.11.58 2 558 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000027f.query"
18 Jun 2008 19.11.52 364 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000017e.query"
18 Jun 2008 19.11.58 156 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000027c.query"
18 Jun 2008 19.11.52 364 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000017d.query"
18 Jun 2008 19.11.48 8 800 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000007e.query"
18 Jun 2008 19.11.52 304 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000017c.query"
18 Jun 2008 19.11.58 1 544 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000027a.query"
18 Jun 2008 19.11.52 4 456 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000017b.query"
18 Jun 2008 19.11.48 306 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000007c.query"
18 Jun 2008 19.11.52 4 456 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000017a.query"
18 Jun 2008 19.11.48 3 112 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0405\0000007a.query"
13 Jun 2008 11.19.30 2 441 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\about_support.htm"
13 Jun 2008 11.19.30 1 501 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\Favorites.htm"
13 Jun 2008 11.19.30 1 801 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\ftshelp.htm"
13 Jun 2008 11.19.30 1 394 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\History.htm"
13 Jun 2008 11.19.30 1 483 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\Index.htm"
13 Jun 2008 11.19.30 3 930 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\isupport.htm"
13 Jun 2008 11.19.30 1 779 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\keywordhelp.htm"
13 Jun 2008 11.19.30 1 736 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\options.htm"
13 Jun 2008 11.19.30 1 792 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\searchblurb.htm"
13 Jun 2008 11.19.30 10 480 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\searchtips.htm"
13 Jun 2008 11.19.30 1 410 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\tools.htm"
13 Jun 2008 11.19.30 360 054 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\watermark_300x.bmp"
13 Jun 2008 11.19.30 2 475 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\windows_newsgroups.htm"
13 Jun 2008 11.19.30 3 263 A.... "C:\WINDOWS\pchealth\helpctr\System\CompatCtr\AboutCompat.htm"
18 Jun 2008 19.11.00 76 463 A.... "C:\WINDOWS\pchealth\helpctr\System\CompatCtr\CompatMode.htm"
13 Jun 2008 11.19.30 1 355 A.... "C:\WINDOWS\pchealth\helpctr\System\CompatCtr\CompatOffline.htm"
13 Jun 2008 11.19.30 2 706 A.... "C:\WINDOWS\pchealth\helpctr\System\CompatCtr\LearnCompat.htm"
13 Jun 2008 11.19.30 1 175 A.... "C:\WINDOWS\pchealth\helpctr\System\css\Behaviors.css"
13 Jun 2008 11.19.30 492 A.... "C:\WINDOWS\pchealth\helpctr\System\css\Layout.css"
13 Jun 2008 11.19.30 851 A.... "C:\WINDOWS\pchealth\helpctr\System\dialogs\DlgLib.js"
13 Jun 2008 11.19.30 7 532 A.... "C:\WINDOWS\pchealth\helpctr\System\dialogs\Print.dlg"
13 Jun 2008 11.19.30 1 733 A.... "C:\WINDOWS\pchealth\helpctr\System\DVDUpgrd\dvdupgrd.htm"
18 Jun 2008 19.11.00 1 206 A.... "C:\WINDOWS\pchealth\helpctr\System\DVDUpgrd\dvdupgrd.js"
13 Jun 2008 11.19.30 9 264 A.... "C:\WINDOWS\pchealth\helpctr\System\DVDUpgrd\stripe.jpg"
13 Jun 2008 11.19.30 894 A.... "C:\WINDOWS\pchealth\helpctr\System\ErrMsg\ErrorMessagesOffline.htm"
13 Jun 2008 11.19.30 1 662 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\badurl.htm"
18 Jun 2008 19.11.00 18 996 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\connection.htm"
13 Jun 2008 11.19.30 1 688 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\indexfirstlevel.htm"
13 Jun 2008 11.19.30 2 026 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\notfound.htm"
13 Jun 2008 11.19.30 775 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\offline.htm"
13 Jun 2008 11.19.30 1 721 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\redirect.htm"
13 Jun 2008 11.19.30 1 689 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\unreachable.htm"
13 Jun 2008 11.19.30 1 557 A.... "C:\WINDOWS\pchealth\helpctr\System\images\error.gif"
13 Jun 2008 11.19.30 895 A.... "C:\WINDOWS\pchealth\helpctr\System\images\feedback.gif"
13 Jun 2008 11.19.30 70 A.... "C:\WINDOWS\pchealth\helpctr\System\images\flyout_arrow.gif"
13 Jun 2008 11.19.30 1 383 A.... "C:\WINDOWS\pchealth\helpctr\System\images\get_conn.gif"
13 Jun 2008 11.19.30 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_articles_12x.bmp"
13 Jun 2008 11.19.30 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_blank_12x.bmp"
13 Jun 2008 11.19.30 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_newwindow_12x.bmp"
13 Jun 2008 11.19.30 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_onlineinline_12x.bmp"
13 Jun 2008 11.19.30 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_tours_12x.bmp"
13 Jun 2008 11.19.30 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_tutorials_12x.bmp"
13 Jun 2008 11.19.30 1 521 A.... "C:\WINDOWS\pchealth\helpctr\System\images\info.gif"
13 Jun 2008 11.19.30 2 801 A.... "C:\WINDOWS\pchealth\helpctr\System\images\progbar.gif"
13 Jun 2008 11.19.30 1 466 A.... "C:\WINDOWS\pchealth\helpctr\System\images\warning.gif"
13 Jun 2008 11.19.30 76 A.... "C:\WINDOWS\pchealth\helpctr\System\images\wrapperhelp.gif"
13 Jun 2008 11.19.30 55 518 A.... "C:\WINDOWS\pchealth\helpctr\System\NetDiag\dglogs.htm"
13 Jun 2008 11.19.30 2 591 A.... "C:\WINDOWS\pchealth\helpctr\System\NetDiag\dglogshelp.htm"
18 Jun 2008 19.11.00 19 581 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\AdvSearch.htm"
13 Jun 2008 11.19.30 608 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\blank.htm"
13 Jun 2008 11.19.30 9 184 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\Context.htm"
13 Jun 2008 11.19.30 714 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\firstpage.htm"
13 Jun 2008 11.19.30 713 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\HHWrapper.htm"
13 Jun 2008 11.19.30 4 802 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\MiniNavBar.htm"
13 Jun 2008 11.19.30 2 031 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\MiniNavBar.xml"
13 Jun 2008 11.19.30 20 902 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\NavBar.htm"
13 Jun 2008 11.19.30 2 622 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\NavBar.xml"
13 Jun 2008 11.19.30 4 472 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\Options.htm"
13 Jun 2008 11.19.30 43 288 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\RemoteHelp.htm"
13 Jun 2008 11.19.30 4 624 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\ShareHelp.htm"
13 Jun 2008 11.19.30 5 525 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\Topics.htm"
13 Jun 2008 11.19.30 2 440 A.... "C:\WINDOWS\pchealth\helpctr\System\rc\rcRequest.htm"
13 Jun 2008 11.19.40 80 856 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\ding.wav"
13 Jun 2008 11.19.40 3 901 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\helpeeaccept.htm"
18 Jun 2008 19.11.00 538 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\RAClientLayout.xml"
18 Jun 2008 19.11.00 664 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\RAHelpeeAcceptLayout.xml"
18 Jun 2008 19.11.00 587 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\RAIMLayout.xml"
13 Jun 2008 11.19.40 3 494 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\RAStartPage.htm"
18 Jun 2008 19.11.00 569 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\RAURA.xml"
13 Jun 2008 11.19.40 6 083 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\rcBuddy.htm"
18 Jun 2008 19.11.00 3 159 A.... "C:\WINDOWS\pchealth\helpctr\System\scripts\Common.js"
13 Jun 2008 11.19.30 4 631 A.... "C:\WINDOWS\pchealth\helpctr\System\scripts\HomePage__SHARED.js"
13 Jun 2008 11.19.30 3 445 A.... "C:\WINDOWS\pchealth\helpctr\System\scripts\HomePage__DESKTOP.js"
13 Jun 2008 11.19.30 8 844 A.... "C:\WINDOWS\pchealth\helpctr\System\scripts\HomePage__SERVER.js"
13 Jun 2008 11.19.30 2 954 A.... "C:\WINDOWS\pchealth\helpctr\System\scripts\wrapperparam.js"
18 Jun 2008 19.11.00 32 141 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\commonFunc.js"
13 Jun 2008 11.19.30 26 322 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\loc_strings.xml"
13 Jun 2008 11.19.30 2 492 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\msinfo.htm"
13 Jun 2008 11.19.30 374 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\msinfo.xml"
13 Jun 2008 11.19.30 582 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\msinfohss.css"
13 Jun 2008 11.19.30 56 618 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\RSoP.htm"
13 Jun 2008 11.19.30 57 125 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\RSoP.js"
18 Jun 2008 19.11.00 25 129 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysComponentInfo.htm"
18 Jun 2008 19.11.00 27 910 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysComponentInfo.js"
13 Jun 2008 11.19.30 1 402 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysConfigLaunch.htm"
13 Jun 2008 11.19.30 2 616 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysDiskTS.htm"
13 Jun 2008 11.19.30 10 399 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysEvtLogInfo.htm"
13 Jun 2008 11.19.30 13 633 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysHealthInfo.htm"
13 Jun 2008 11.19.30 20 083 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysHealthInfo.js"
13 Jun 2008 11.19.30 4 210 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysInfoLaunch.htm"
13 Jun 2008 11.19.30 4 229 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysinfomain.htm"
18 Jun 2008 19.11.00 16 175 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysinfosum.htm"
13 Jun 2008 11.19.30 1 945 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysRemoteInfo.htm"
13 Jun 2008 11.19.30 10 212 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysServicesInfo.htm"
18 Jun 2008 19.11.00 7 919 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysSoftwareInfo.htm"
13 Jun 2008 11.19.30 9 506 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysSoftwareInfo.js"
18 Jun 2008 19.11.00 14 129 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\wmi_data.js"
13 Jun 2008 11.19.30 4 093 A.... "C:\WINDOWS\pchealth\helpctr\System\UpdateCtr\AboutWU.htm"
13 Jun 2008 11.19.30 2 123 A.... "C:\WINDOWS\pchealth\helpctr\System\UpdateCtr\Learn.htm"
13 Jun 2008 11.19.30 2 576 A.... "C:\WINDOWS\pchealth\helpctr\System\UpdateCtr\LearnInternet.htm"
13 Jun 2008 11.19.30 2 554 A.... "C:\WINDOWS\pchealth\helpctr\System\UpdateCtr\learnWU.htm"
13 Jun 2008 11.19.30 1 106 A.... "C:\WINDOWS\pchealth\helpctr\System\UpdateCtr\updatecenter.htm"
13 Jun 2008 11.19.42 716 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Connection.htm"
13 Jun 2008 11.19.42 682 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\GArrow.gif"
13 Jun 2008 11.19.42 311 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\GRect.gif"
13 Jun 2008 11.19.42 213 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Info_Icon.gif"
13 Jun 2008 11.19.42 2 859 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\OfflineOptions.htm"
13 Jun 2008 11.19.42 13 107 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\OfflineDC.htm"
13 Jun 2008 11.19.42 781 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\PSS.css"
13 Jun 2008 11.19.42 10 912 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\pssmachinesnapshot.xml"
13 Jun 2008 11.19.42 7 098 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\pssmachinesnapshot-less.xml"
13 Jun 2008 11.19.42 10 755 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\pssmachinesnapshot-wo-com.xml"
13 Jun 2008 11.19.42 30 494 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\pss_getting_worldwide_help.htm"
13 Jun 2008 11.19.42 114 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r1_c1.gif"
13 Jun 2008 11.19.42 107 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r1_c2.gif"
13 Jun 2008 11.19.42 106 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r1_c3.gif"
13 Jun 2008 11.19.42 107 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r3_c2.gif"
13 Jun 2008 11.19.42 43 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\spacer.gif"
13 Jun 2008 11.19.42 232 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\status_ok.gif"
13 Jun 2008 11.33.48 196 940 A.... "C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\machine.PNF"
13 Jun 2008 11.35.04 54 656 A.... "C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\usbport.PNF"
13 Jun 2008 11.33.48 196 940 A.... "C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\machine.PNF"
13 Jun 2008 11.35.04 54 656 A.... "C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\usbport.PNF"
13 Jun 2008 11.35.04 54 656 A.... "C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\usbport.PNF"
13 Jun 2008 11.34.26 51 828 A.... "C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\mshdc.PNF"
13 Jun 2008 11.33.48 196 940 A.... "C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\machine.PNF"
13 Jun 2008 11.33.48 196 940 A.... "C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\machine.PNF"
13 Jun 2008 11.33.48 196 940 A.... "C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\machine.PNF"
13 Jun 2008 12.01.46 14 200 A.... "C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\ibmpmdrv.PNF"
13 Jun 2008 11.55.56 237 976 A.... "C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\e1000325.PNF"
13 Jun 2008 11.34.26 63 560 A.... "C:\WINDOWS\system32\ReinstallBackups\0011\DriverFiles\msmouse.PNF"
13 Jun 2008 11.19.30 2 358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\arrow_blue_normal_shadow.bmp"
13 Jun 2008 11.19.30 2 358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\arrow_green_normal_shadow.bmp"
13 Jun 2008 11.19.30 1 078 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\compat.bmp"
13 Jun 2008 11.19.30 1 078 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\errmsg.bmp"
13 Jun 2008 11.19.30 1 078 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\support.bmp"
13 Jun 2008 11.19.30 1 078 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\tools.bmp"
13 Jun 2008 11.19.30 1 078 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\update.bmp"
13 Jun 2008 11.19.30 600 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\warning.gif"
13 Jun 2008 11.19.30 2 358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\24x24\arrow_green_mousedown.bmp"
13 Jun 2008 11.19.30 2 358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\24x24\arrow_green_mouseover.bmp"
13 Jun 2008 11.19.30 2 358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\24x24\arrow_green_normal.bmp"
13 Jun 2008 11.19.30 2 358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\32x32\logo.bmp"
13 Jun 2008 11.19.30 9 270 A.... "C:\WINDOWS\pchealth\helpctr\System\images\48x48\desktop_icon_generic.bmp"
13 Jun 2008 11.19.30 9 270 A.... "C:\WINDOWS\pchealth\helpctr\System\images\48x48\desktop_icon_01.bmp"
13 Jun 2008 11.19.30 9 270 A.... "C:\WINDOWS\pchealth\helpctr\System\images\48x48\desktop_icon_02.bmp"
13 Jun 2008 11.19.30 9 270 A.... "C:\WINDOWS\pchealth\helpctr\System\images\48x48\desktop_icon_03.bmp"
13 Jun 2008 11.19.30 9 270 A.... "C:\WINDOWS\pchealth\helpctr\System\images\48x48\desktop_icon_04.bmp"
13 Jun 2008 11.19.30 674 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Centers\blue_arrow.gif"
13 Jun 2008 11.19.30 1 383 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Centers\Connect.gif"
13 Jun 2008 11.19.30 1 839 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Centers\IULogo.gif"
13 Jun 2008 11.19.30 1 525 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Centers\Uabrand.gif"
13 Jun 2008 11.19.30 139 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Expando\collapsed.gif"
13 Jun 2008 11.19.30 136 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Expando\endnode.gif"
13 Jun 2008 11.19.30 135 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Expando\expanded.gif"
13 Jun 2008 11.19.30 207 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Expando\helpdoc.gif"
13 Jun 2008 11.19.30 8 547 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Channels.htm"
13 Jun 2008 11.19.30 8 548 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Favorites.htm"
13 Jun 2008 11.19.30 5 371 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\History.htm"
13 Jun 2008 11.19.30 2 914 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Index.htm"
13 Jun 2008 11.19.30 3 482 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Options.htm"
18 Jun 2008 19.11.00 37 487 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Search.htm"
13 Jun 2008 11.19.30 6 520 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Subsite.htm"
18 Jun 2008 19.11.00 5 267 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\common.js"
13 Jun 2008 11.19.40 5 451 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\ConnIssue.htm"
13 Jun 2008 11.19.40 2 070 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\constants.js"
13 Jun 2008 11.19.40 234 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\icon_information_32x.gif"
13 Jun 2008 11.19.40 219 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\icon_warning_32x.gif"
13 Jun 2008 11.19.40 1 752 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\LearnInternet.htm"
13 Jun 2008 11.19.40 2 318 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\RAHelp.htm"
13 Jun 2008 11.19.40 3 012 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\RCMoreInfo.htm"
13 Jun 2008 11.19.40 1 369 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Css\RAChat.css"
13 Jun 2008 11.19.40 2 442 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Css\rc.css"
13 Jun 2008 11.19.40 1 308 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Css\rcbuddy.css"
13 Jun 2008 11.19.30 118 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\alert.gif"
13 Jun 2008 11.19.30 674 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\BArrow.gif"
13 Jun 2008 11.19.30 162 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\card.gif"
13 Jun 2008 11.19.30 257 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\cd.gif"
13 Jun 2008 11.19.30 145 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\check.gif"
13 Jun 2008 11.19.30 102 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\chip.gif"
13 Jun 2008 11.19.30 1 498 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\down.bmp"
13 Jun 2008 11.19.30 139 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\drive.gif"
13 Jun 2008 11.19.30 107 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\error.gif"
13 Jun 2008 11.19.30 159 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\floppy.gif"
13 Jun 2008 11.19.30 682 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\GArrow.gif"
13 Jun 2008 11.19.30 135 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\gears.gif"
13 Jun 2008 11.19.30 677 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\greendot.jpg"
13 Jun 2008 11.19.30 99 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\info.gif"
13 Jun 2008 11.19.30 129 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\monitor.gif"
13 Jun 2008 11.19.30 181 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\personalizing.gif"
13 Jun 2008 11.19.30 1 135 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\PieChart.gif"
13 Jun 2008 11.19.30 67 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\PieGrey.gif"
13 Jun 2008 11.19.30 67 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\PieWhite.gif"
13 Jun 2008 11.19.30 136 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\printer.gif"
13 Jun 2008 11.19.30 114 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\r1_c1.gif"
13 Jun 2008 11.19.30 107 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\r1_c2.gif"
13 Jun 2008 11.19.30 106 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\r1_c3.gif"
13 Jun 2008 11.19.30 107 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\r3_c2.gif"
13 Jun 2008 11.19.30 43 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\spacer.gif"
13 Jun 2008 11.19.30 404 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\system.gif"
13 Jun 2008 11.19.30 1 135 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\Untitled.gif"
13 Jun 2008 11.19.30 1 498 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\up.bmp"
13 Jun 2008 11.19.30 262 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\usb.gif"
13 Jun 2008 11.19.30 569 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\windows.gif"
13 Jun 2008 11.19.40 2 860 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\confirm.htm"
18 Jun 2008 19.11.00 16 254 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\rcstatus.htm"
13 Jun 2008 11.19.40 4 756 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\Animation.gif"
13 Jun 2008 11.19.40 59 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\combobox_line.gif"
13 Jun 2008 11.19.40 1 094 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\connected.gif"
13 Jun 2008 11.19.40 1 024 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\DividerBar.gif"
13 Jun 2008 11.19.40 345 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\DividerBar.htm"
13 Jun 2008 11.19.40 838 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\DownArrow.gif"
13 Jun 2008 11.19.40 9 000 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAChatClient.htm"
18 Jun 2008 19.11.00 45 189 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAClient.htm"
18 Jun 2008 19.11.00 11 037 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAClient.js"
13 Jun 2008 11.19.40 7 174 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAStatusBar.htm"
18 Jun 2008 19.11.00 11 179 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAToolBar.htm"
13 Jun 2008 11.19.40 3 257 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAToolBar.xml"
13 Jun 2008 11.19.40 1 290 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\rcscreen6_head.htm"
18 Jun 2008 19.11.00 2 495 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\rctoolScreen1.htm"
13 Jun 2008 11.19.40 6 569 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\setting.htm"
13 Jun 2008 11.19.40 3 898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\TakeControl.bmp"
13 Jun 2008 11.19.40 861 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\TakeControl.gif"
13 Jun 2008 11.19.40 834 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\UpArrow.gif"
18 Jun 2008 19.11.02 690 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\attentioninteraction.gif"
13 Jun 2008 11.19.40 2 085 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\ErrorMsgs.htm"
13 Jun 2008 11.19.40 3 898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\HelpCenter.bmp"
13 Jun 2008 11.19.40 845 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\HelpCenter.gif"
13 Jun 2008 11.19.40 379 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\hide-chat.gif"
13 Jun 2008 11.19.40 227 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\info.gif"
13 Jun 2008 11.19.40 3 898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Options.bmp"
13 Jun 2008 11.19.40 713 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Options.gif"
13 Jun 2008 11.19.40 3 898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Quit.bmp"
13 Jun 2008 11.19.40 750 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Quit.gif"
18 Jun 2008 19.11.00 15 699 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\RAControl.js"
18 Jun 2008 19.11.00 30 791 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\RCFileXfer.htm"
13 Jun 2008 11.19.40 1 041 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendChat.gif"
13 Jun 2008 11.19.40 3 898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendFile.bmp"
13 Jun 2008 11.19.40 694 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendFile.gif"
13 Jun 2008 11.19.40 3 898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendVoice.bmp"
13 Jun 2008 11.19.40 692 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendVoice.gif"
13 Jun 2008 11.19.40 994 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendVoiceOn.gif"
13 Jun 2008 11.19.40 380 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\show-chat.gif"
18 Jun 2008 19.11.02 3 237 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\voicefirewallmsg.htm"
13 Jun 2008 11.19.40 2 331 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\VOIPMsgs.htm"
13 Jun 2008 11.19.40 340 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\DividerBar1.htm"
13 Jun 2008 11.19.40 352 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\DividerBar2.htm"
13 Jun 2008 11.19.40 2 818 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\ESC_key.gif"
13 Jun 2008 11.19.40 75 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\Helpee_line.gif"
13 Jun 2008 11.19.40 8 120 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\RAChatServer.htm"
18 Jun 2008 19.11.00 21 054 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\RAServer.htm"
18 Jun 2008 19.11.00 5 174 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\RAServer.js"
18 Jun 2008 19.11.00 14 586 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\RAServerToolBar.htm"
13 Jun 2008 11.19.40 4 810 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\SettingServer.htm"
13 Jun 2008 11.19.40 3 898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\StopControl.bmp"
13 Jun 2008 11.19.40 640 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\StopControl.gif"
13 Jun 2008 11.19.40 3 191 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\TakeControlMsgs.htm"
13 Jun 2008 11.19.30 734 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\0_chart.gif"
13 Jun 2008 11.19.30 741 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\100_chart.gif"
13 Jun 2008 11.19.30 784 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\10_chart.gif"
13 Jun 2008 11.19.30 778 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\15_chart.gif"
13 Jun 2008 11.19.30 775 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\20_chart.gif"
13 Jun 2008 11.19.30 781 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\25_chart.gif"
13 Jun 2008 11.19.30 782 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\30_chart.gif"
13 Jun 2008 11.19.30 793 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\35_chart.gif"
13 Jun 2008 11.19.30 789 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\40_chart.gif"
13 Jun 2008 11.19.30 785 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\45_chart.gif"
13 Jun 2008 11.19.30 762 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\50_chart.gif"
13 Jun 2008 11.19.30 777 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\55_chart.gif"
13 Jun 2008 11.19.30 773 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\5_chart.gif"
13 Jun 2008 11.19.30 789 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\60_chart.gif"
13 Jun 2008 11.19.30 1 199 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\65_chart.gif"
13 Jun 2008 11.19.30 1 190 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\70_chart.gif"
13 Jun 2008 11.19.30 1 194 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\75_chart.gif"
13 Jun 2008 11.19.30 1 196 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\80_chart.gif"
13 Jun 2008 11.19.30 1 190 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\85_chart.gif"
13 Jun 2008 11.19.30 1 196 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\90_chart.gif"
13 Jun 2008 11.19.30 1 207 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\95_chart.gif"
13 Jun 2008 11.19.30 1 345 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\0_chart.gif"
13 Jun 2008 11.19.30 1 358 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\100_chart.gif"
13 Jun 2008 11.19.30 1 443 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\10_chart.gif"
13 Jun 2008 11.19.30 1 435 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\15_chart.gif"
13 Jun 2008 11.19.30 1 421 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\20_chart.gif"
13 Jun 2008 11.19.30 1 423 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\25_chart.gif"
13 Jun 2008 11.19.30 1 428 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\30_chart.gif"
13 Jun 2008 11.19.30 1 441 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\35_chart.gif"
13 Jun 2008 11.19.30 1 446 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\40_chart.gif"
13 Jun 2008 11.19.30 1 446 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\45_chart.gif"
13 Jun 2008 11.19.30 1 412 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\50_chart.gif"
13 Jun 2008 11.19.30 1 430 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\55_chart.gif"
13 Jun 2008 11.19.30 1 413 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\5_chart.gif"
13 Jun 2008 11.19.30 1 446 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\60_chart.gif"
13 Jun 2008 11.19.30 1 445 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\65_chart.gif"
13 Jun 2008 11.19.30 1 435 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\70_chart.gif"
13 Jun 2008 11.19.30 1 442 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\75_chart.gif"
13 Jun 2008 11.19.30 1 447 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\80_chart.gif"
13 Jun 2008 11.19.30 1 426 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\85_chart.gif"
13 Jun 2008 11.19.30 1 442 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\90_chart.gif"
13 Jun 2008 11.19.30 1 445 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\95_chart.gif"
18 Jun 2008 19.11.00 5 267 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\common.js"
18 Jun 2008 19.11.00 5 451 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\ConnIssue.htm"
13 Jun 2008 11.19.40 2 070 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\constants.js"
13 Jun 2008 11.19.40 234 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\icon_information_32x.gif"
13 Jun 2008 11.19.40 219 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\icon_warning_32x.gif"
13 Jun 2008 11.19.40 1 752 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\LearnInternet.htm"
13 Jun 2008 11.19.40 2 318 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\RAHelp.htm"
18 Jun 2008 19.11.00 3 012 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\RCMoreInfo.htm"
13 Jun 2008 11.19.40 1 369 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Css\RAChat.css"
13 Jun 2008 11.19.40 2 442 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Css\rc.css"
13 Jun 2008 11.19.40 1 308 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Css\rcbuddy.css"
13 Jun 2008 11.19.40 102 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\address_book.gif"
13 Jun 2008 11.19.40 1 074 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\arrow.gif"
13 Jun 2008 11.19.40 690 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\attention.gif"
13 Jun 2008 11.19.40 384 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_offline.gif"
13 Jun 2008 11.19.40 387 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy.gif"
13 Jun 2008 11.19.40 608 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_attention.gif"
13 Jun 2008 11.19.40 382 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_away.gif"
13 Jun 2008 11.19.40 373 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_busy.gif"
13 Jun 2008 11.19.40 910 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_none.gif"
13 Jun 2008 11.19.40 111 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\Envelope.gif"
13 Jun 2008 11.19.40 159 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\floppy.gif"
13 Jun 2008 11.19.40 1 047 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\generic_mail.gif"
13 Jun 2008 11.19.40 321 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\icon_extweb.gif"
13 Jun 2008 11.19.40 139 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\IM_icon.gif"
13 Jun 2008 11.19.40 227 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\info.gif"
13 Jun 2008 11.19.40 3 169 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\logon_anim.gif"
13 Jun 2008 11.19.40 1 473 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\messenger_big.gif"
13 Jun 2008 11.19.40 7 066 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\monitor_left.gif"
13 Jun 2008 11.19.40 8 509 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\monitor_right.gif"
13 Jun 2008 11.19.40 180 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\outlook.gif"
13 Jun 2008 11.19.40 410 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\outlook_express.gif"
13 Jun 2008 11.19.40 3 360 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\rcConnection.htm"
13 Jun 2008 11.19.40 2 630 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\rcscreen1.htm"
13 Jun 2008 11.19.40 4 465 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\rcscreen2.htm"
13 Jun 2008 11.19.40 321 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\rcscreen3.htm"
13 Jun 2008 11.19.40 53 542 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\Remote_Assistance_Graphic.png"
13 Jun 2008 11.19.40 51 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\square_bullet.gif"
13 Jun 2008 11.19.40 137 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\check.gif"
18 Jun 2008 19.11.02 3 513 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\escalationhelp.htm"
13 Jun 2008 11.19.40 254 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\help.gif"
13 Jun 2008 11.19.40 4 799 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcDetails.htm"
18 Jun 2008 19.11.00 8 025 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen7.htm"
13 Jun 2008 11.19.40 7 679 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen8.htm"
13 Jun 2008 11.19.40 8 435 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen9.htm"
13 Jun 2008 11.19.40 5 209 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcInviteStatus.htm"
13 Jun 2008 11.19.40 14 603 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreenshot3.gif"
13 Jun 2008 11.19.40 4 359 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen4.htm"
13 Jun 2008 11.19.40 14 804 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen5.htm"
18 Jun 2008 19.11.00 30 522 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen6.htm"
13 Jun 2008 11.19.40 1 290 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen6_head.htm"
18 Jun 2008 19.11.00 3 283 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\ShieldsUpMsg.htm"
13 Jun 2008 11.19.40 13 426 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Unsolicited\UnSolicitedRCUI.htm"


C:\Program Files\

13 Jun 2008 14.50.16 207 555 A.... "C:\Program Files\ACE Mega CoDecS Pack\unins000.dat"
13 Jun 2008 14.45.28 632 963 A.... "C:\Program Files\ACE Mega CoDecS Pack\unins000.exe"
26 Jul 2008 11.55.16 13 952 A.... "C:\Program Files\Mozilla Firefox\AccessibleMarshal.dll"
26 Jul 2008 11.55.24 7 667 312 A.... "C:\Program Files\Mozilla Firefox\firefox.exe"
26 Jul 2008 11.55.24 200 829 A.... "C:\Program Files\Mozilla Firefox\freebl3.dll"
26 Jul 2008 11.55.26 458 856 A.... "C:\Program Files\Mozilla Firefox\js3250.dll"
26 Jul 2008 11.55.26 161 392 A.... "C:\Program Files\Mozilla Firefox\nspr4.dll"
26 Jul 2008 11.55.26 382 568 A.... "C:\Program Files\Mozilla Firefox\nss3.dll"
26 Jul 2008 11.55.26 276 080 A.... "C:\Program Files\Mozilla Firefox\nssckbi.dll"
26 Jul 2008 11.55.26 34 424 A.... "C:\Program Files\Mozilla Firefox\plc4.dll"
26 Jul 2008 11.55.20 30 320 A.... "C:\Program Files\Mozilla Firefox\plds4.dll"
26 Jul 2008 11.55.20 112 232 A.... "C:\Program Files\Mozilla Firefox\smime3.dll"
26 Jul 2008 11.55.20 254 060 A.... "C:\Program Files\Mozilla Firefox\softokn3.dll"
26 Jul 2008 11.55.20 136 808 A.... "C:\Program Files\Mozilla Firefox\ssl3.dll"
26 Jul 2008 11.55.22 132 232 A.... "C:\Program Files\Mozilla Firefox\updater.exe"
26 Jul 2008 11.55.22 13 416 A.... "C:\Program Files\Mozilla Firefox\xpcom.dll"
26 Jul 2008 11.55.22 73 848 A.... "C:\Program Files\Mozilla Firefox\xpcom_compat.dll"
26 Jul 2008 11.55.22 422 000 A.... "C:\Program Files\Mozilla Firefox\xpcom_core.dll"
26 Jul 2008 11.55.22 73 336 A.... "C:\Program Files\Mozilla Firefox\xpicleanup.exe"
26 Jul 2008 11.55.22 12 400 A.... "C:\Program Files\Mozilla Firefox\xpistub.dll"
14 Jun 2008 18.02.00 681 081 A.... "C:\Program Files\PCDR5\uninst.exe"
18 Jun 2008 18.24.26 219 952 A.... "C:\Program Files\uTorrent\uTorrent.exe"
3 Jul 2008 18.55.42 145 518 A.... "C:\Program Files\Winamp\UninstWA.exe"
3 Jul 2008 7.37.34 64 577 A.... "C:\Program Files\Winamp Toolbar\uninstall.exe"
13 Jun 2008 14.44.48 20 A.... "C:\Program Files\WinRAR\rarnew.dat"
13 Jun 2008 14.44.48 22 A.... "C:\Program Files\WinRAR\zipnew.dat"
30 May 2008 15.54.14 1 942 864 A...R "C:\Program Files\Common Files\Skype\Skype4COM.dll"
13 Jun 2008 14.37.24 49 503 A.... "C:\Program Files\ESET\ESET Smart Security\em000_32.dat"
26 Jul 2008 11.59.32 310 568 A.... "C:\Program Files\ESET\ESET Smart Security\em001_32.dat"
26 Jul 2008 11.59.38 9 796 567 A.... "C:\Program Files\ESET\ESET Smart Security\em002_32.dat"
26 Jul 2008 11.59.38 220 390 A.... "C:\Program Files\ESET\ESET Smart Security\em003_32.dat"
13 Jun 2008 14.37.32 431 515 A.... "C:\Program Files\ESET\ESET Smart Security\em004_32.dat"
26 Jul 2008 11.59.38 43 291 A.... "C:\Program Files\ESET\ESET Smart Security\em005_32.dat"
26 Jul 2008 11.59.38 10 393 A.... "C:\Program Files\ESET\ESET Smart Security\em006_32.dat"
13 Jun 2008 14.37.32 158 036 A.... "C:\Program Files\ESET\ESET Smart Security\em008_32.dat"
22 Jul 2008 18.05.38 672 077 A.... "C:\Program Files\ESET\ESET Smart Security\em010_32.dat"
27 Jul 2008 1.15.40 195 A.... "C:\Program Files\ESET\ESET Smart Security\mod_comp.dat"
13 Jun 2008 14.37.50 492 032 ..... "C:\Program Files\InstallShield Installation Information\{60DE4033-9503-48D1-A483-7846BD217CA9}\ISSetup.dll"
13 Jun 2008 14.37.50 455 600 A.... "C:\Program Files\InstallShield Installation Information\{60DE4033-9503-48D1-A483-7846BD217CA9}\setup.exe"
13 Jun 2008 14.37.50 164 784 A.... "C:\Program Files\InstallShield Installation Information\{60DE4033-9503-48D1-A483-7846BD217CA9}\_Setup.dll"
13 Jun 2008 11.33.10 380 928 A.... "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\_setup.dll"
13 Jun 2008 14.39.50 131 072 A.... "C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll"
13 Jun 2008 14.39.50 131 072 A.... "C:\Program Files\Internet Explorer\PLUGINS\npqtplugin6.dll"
13 Jun 2008 14.39.50 131 072 A.... "C:\Program Files\Internet Explorer\PLUGINS\npqtplugin7.dll"
13 Jun 2008 14.39.50 131 072 A.... "C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll"
13 Jun 2008 14.39.50 131 072 A.... "C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll"
13 Jun 2008 14.39.50 131 072 A.... "C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll"
13 Jun 2008 14.39.50 131 072 A.... "C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll"
10 Jun 2008 2.10.36 994 ....R "C:\Program Files\Java\jre1.6.0_07\Welcome.html"
26 Jul 2008 11.55.20 67 696 A.... "C:\Program Files\Mozilla Firefox\components\jar50.dll"
26 Jul 2008 11.55.20 54 376 A.... "C:\Program Files\Mozilla Firefox\components\jsd3250.dll"
26 Jul 2008 11.55.20 34 952 A.... "C:\Program Files\Mozilla Firefox\components\myspell.dll"
26 Jul 2008 11.55.20 46 720 A.... "C:\Program Files\Mozilla Firefox\components\spellchk.dll"
26 Jul 2008 11.55.20 172 144 A.... "C:\Program Files\Mozilla Firefox\components\xpinstal.dll"
13 Jun 2008 14.39.50 131 072 A.... "C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll"
13 Jun 2008 14.39.50 131 072 A.... "C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll"
13 Jun 2008 14.39.50 131 072 A.... "C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll"
26 Jul 2008 11.55.20 22 664 A.... "C:\Program Files\Mozilla Firefox\plugins\npnul32.dll"
13 Jun 2008 14.39.50 131 072 A.... "C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll"
13 Jun 2008 14.39.50 131 072 A.... "C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll"
13 Jun 2008 14.39.50 131 072 A.... "C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll"
13 Jun 2008 14.39.50 131 072 A.... "C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll"
18 Jun 2008 23.24.48 117 A.... "C:\Program Files\Mozilla Firefox\res\hiddenWindow.html"
26 Jul 2008 11.55.22 451 600 A.... "C:\Program Files\Mozilla Firefox\uninstall\helper.exe"
30 May 2008 15.54.14 21 718 312 A...R "C:\Program Files\Skype\Phone\Skype.exe"
30 May 2008 15.54.16 3 279 816 A...R "C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll"
30 May 2008 15.54.16 76 744 A...R "C:\Program Files\Skype\Plugin Manager\skypePM.exe"
30 May 2008 15.54.16 17 864 A...R "C:\Program Files\Skype\Plugin Manager\spmServices.dll"
10 Jun 2008 4.27.14 1 060 864 A.... "C:\Program Files\Java\jre1.6.0_07\bin\awt.dll"
10 Jun 2008 4.27.14 114 688 A.... "C:\Program Files\Java\jre1.6.0_07\bin\axbridge.dll"
10 Jun 2008 4.27.14 192 512 A.... "C:\Program Files\Java\jre1.6.0_07\bin\cmm.dll"
10 Jun 2008 4.27.14 143 360 A.... "C:\Program Files\Java\jre1.6.0_07\bin\dcpr.dll"
10 Jun 2008 4.27.14 69 632 A.... "C:\Program Files\Java\jre1.6.0_07\bin\deploy.dll"
10 Jun 2008 4.27.14 16 896 A.... "C:\Program Files\Java\jre1.6.0_07\bin\dt_shmem.dll"
10 Jun 2008 4.27.14 13 312 A.... "C:\Program Files\Java\jre1.6.0_07\bin\dt_socket.dll"
10 Jun 2008 4.27.14 335 872 A.... "C:\Program Files\Java\jre1.6.0_07\bin\fontmanager.dll"
10 Jun 2008 4.27.14 15 872 A.... "C:\Program Files\Java\jre1.6.0_07\bin\hpi.dll"
10 Jun 2008 4.27.14 139 264 A.... "C:\Program Files\Java\jre1.6.0_07\bin\hprof.dll"
10 Jun 2008 4.27.14 98 304 A.... "C:\Program Files\Java\jre1.6.0_07\bin\instrument.dll"
10 Jun 2008 4.27.14 12 800 A.... "C:\Program Files\Java\jre1.6.0_07\bin\ioser12.dll"
10 Jun 2008 4.27.14 7 680 A.... "C:\Program Files\Java\jre1.6.0_07\bin\j2pcsc.dll"
10 Jun 2008 4.27.14 37 376 A.... "C:\Program Files\Java\jre1.6.0_07\bin\j2pkcs11.dll"
10 Jun 2008 4.27.14 10 240 A.... "C:\Program Files\Java\jre1.6.0_07\bin\jaas_nt.dll"
10 Jun 2008 1.47.38 25 088 A.... "C:\Program Files\Java\jre1.6.0_07\bin\java-rmi.exe"
10 Jun 2008 4.27.14 126 976 A.... "C:\Program Files\Java\jre1.6.0_07\bin\java.dll"
10 Jun 2008 1.21.02 135 168 A.... "C:\Program Files\Java\jre1.6.0_07\bin\java.exe"
10 Jun 2008 2.32.34 49 152 A.... "C:\Program Files\Java\jre1.6.0_07\bin\javacpl.exe"
10 Jun 2008 1.21.04 135 168 A.... "C:\Program Files\Java\jre1.6.0_07\bin\javaw.exe"
10 Jun 2008 2.32.34 139 264 A.... "C:\Program Files\Java\jre1.6.0_07\bin\javaws.exe"
10 Jun 2008 4.27.14 14 336 A.... "C:\Program Files\Java\jre1.6.0_07\bin\java_crw_demo.dll"
10 Jun 2008 4.27.14 5 120 A.... "C:\Program Files\Java\jre1.6.0_07\bin\jawt.dll"
10 Jun 2008 4.27.14 36 352 A.... "C:\Program Files\Java\jre1.6.0_07\bin\JdbcOdbc.dll"
10 Jun 2008 4.27.14 167 936 A.... "C:\Program Files\Java\jre1.6.0_07\bin\jdwp.dll"
10 Jun 2008 4.27.14 77 824 A.... "C:\Program Files\Java\jre1.6.0_07\bin\jli.dll"
10 Jun 2008 4.27.14 147 456 A.... "C:\Program Files\Java\jre1.6.0_07\bin\jpeg.dll"
10 Jun 2008 4.27.14 98 304 A.... "C:\Program Files\Java\jre1.6.0_07\bin\jpicom.dll"
10 Jun 2008 4.27.14 110 592 A.... "C:\Program Files\Java\jre1.6.0_07\bin\jpiexp.dll"
10 Jun 2008 4.27.14 98 304 A.... "C:\Program Files\Java\jre1.6.0_07\bin\jpinscp.dll"
10 Jun 2008 4.27.14 65 536 A.... "C:\Program Files\Java\jre1.6.0_07\bin\jpioji.dll"
10 Jun 2008 4.27.14 126 976 A.... "C:\Program Files\Java\jre1.6.0_07\bin\jpishare.dll"
10 Jun 2008 4.27.14 147 456 A.... "C:\Program Files\Java\jre1.6.0_07\bin\jsound.dll"
10 Jun 2008 4.27.14 18 432 A.... "C:\Program Files\Java\jre1.6.0_07\bin\jsoundds.dll"
10 Jun 2008 4.27.04 329 104 A.... "C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe"
10 Jun 2008 4.27.04 54 672 A.... "C:\Program Files\Java\jre1.6.0_07\bin\jureg.exe"
10 Jun 2008 4.27.04 144 784 A.... "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
10 Jun 2008 1.35.16 25 600 A.... "C:\Program Files\Java\jre1.6.0_07\bin\keytool.exe"
10 Jun 2008 1.36.04 25 600 A.... "C:\Program Files\Java\jre1.6.0_07\bin\kinit.exe"
10 Jun 2008 1.36.08 25 600 A.... "C:\Program Files\Java\jre1.6.0_07\bin\klist.exe"
10 Jun 2008 1.36.10 25 600 A.... "C:\Program Files\Java\jre1.6.0_07\bin\ktab.exe"
10 Jun 2008 4.27.14 18 432 A.... "C:\Program Files\Java\jre1.6.0_07\bin\management.dll"
10 Jun 2008 4.27.14 602 112 A.... "C:\Program Files\Java\jre1.6.0_07\bin\mlib_image.dll"
10 Jun 2008 4.44.26 348 160 A.... "C:\Program Files\Java\jre1.6.0_07\bin\msvcr71.dll"
10 Jun 2008 4.27.14 77 824 A.... "C:\Program Files\Java\jre1.6.0_07\bin\net.dll"
10 Jun 2008 4.27.14 20 480 A.... "C:\Program Files\Java\jre1.6.0_07\bin\nio.dll"
10 Jun 2008 4.27.14 126 976 A.... "C:\Program Files\Java\jre1.6.0_07\bin\npjava11.dll"
10 Jun 2008 4.27.14 126 976 A.... "C:\Program Files\Java\jre1.6.0_07\bin\npjava12.dll"
10 Jun 2008 4.27.14 126 976 A.... "C:\Program Files\Java\jre1.6.0_07\bin\npjava13.dll"
10 Jun 2008 4.27.14 126 976 A.... "C:\Program Files\Java\jre1.6.0_07\bin\npjava14.dll"
10 Jun 2008 4.27.14 126 976 A.... "C:\Program Files\Java\jre1.6.0_07\bin\npjava32.dll"
10 Jun 2008 4.27.02 132 496 A.... "C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll"
10 Jun 2008 4.27.14 126 976 A.... "C:\Program Files\Java\jre1.6.0_07\bin\npoji610.dll"
10 Jun 2008 4.27.14 8 192 A.... "C:\Program Files\Java\jre1.6.0_07\bin\npt.dll"
10 Jun 2008 1.56.06 25 600 A.... "C:\Program Files\Java\jre1.6.0_07\bin\orbd.exe"
10 Jun 2008 1.56.52 25 600 A.... "C:\Program Files\Java\jre1.6.0_07\bin\pack200.exe"
10 Jun 2008 1.36.00 25 600 A.... "C:\Program Files\Java\jre1.6.0_07\bin\policytool.exe"
10 Jun 2008 4.44.26 237 568 A.... "C:\Program Files\Java\jre1.6.0_07\bin\regutils.dll"
10 Jun 2008 4.27.16 5 120 A.... "C:\Program Files\Java\jre1.6.0_07\bin\rmi.dll"
10 Jun 2008 1.47.30 25 600 A.... "C:\Program Files\Java\jre1.6.0_07\bin\rmid.exe"
10 Jun 2008 1.47.20 25 600 A.... "C:\Program Files\Java\jre1.6.0_07\bin\rmiregistry.exe"
10 Jun 2008 1.56.10 25 600 A.... "C:\Program Files\Java\jre1.6.0_07\bin\servertool.exe"
10 Jun 2008 4.27.16 131 072 A.... "C:\Program Files\Java\jre1.6.0_07\bin\splashscreen.dll"
10 Jun 2008 4.27.02 509 328 A.... "C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll"
10 Jun 2008 2.32.34 7 168 A.... "C:\Program Files\Java\jre1.6.0_07\bin\ssvagent.exe"
10 Jun 2008 4.27.16 16 384 A.... "C:\Program Files\Java\jre1.6.0_07\bin\sunmscapi.dll"
10 Jun 2008 1.55.54 26 112 A.... "C:\Program Files\Java\jre1.6.0_07\bin\tnameserv.exe"
10 Jun 2008 4.27.16 61 440 A.... "C:\Program Files\Java\jre1.6.0_07\bin\unpack.dll"
10 Jun 2008 1.56.48 122 880 A.... "C:\Program Files\Java\jre1.6.0_07\bin\unpack200.exe"
10 Jun 2008 4.27.16 31 744 A.... "C:\Program Files\Java\jre1.6.0_07\bin\verify.dll"
10 Jun 2008 4.27.16 24 701 A.... "C:\Program Files\Java\jre1.6.0_07\bin\w2k_lsa_auth.dll"
10 Jun 2008 4.27.16 110 592 A.... "C:\Program Files\Java\jre1.6.0_07\bin\wsdetect.dll"
10 Jun 2008 4.27.16 47 104 A.... "C:\Program Files\Java\jre1.6.0_07\bin\zip.dll"
18 Jun 2008 23.24.38 7 135 A.... "C:\Program Files\Mozilla Firefox\defaults\profile\bookmarks.html"
30 May 2008 15.54.16 1 475 880 A.... "C:\Program Files\Skype\Toolbars\Shared\SPhoneParser.dll"
13 Jun 2008 14.15.48 6 989 888 ..... "C:\Program Files\Synaptics\SynTP\Media\7igu03ww.exe"
10 Jun 2008 4.27.16 2 334 720 A.... "C:\Program Files\Java\jre1.6.0_07\bin\client\jvm.dll"
10 Jun 2008 2.32.34 16 801 A.... "C:\Program Files\Java\jre1.6.0_07\lib\deploy\ffjcext.zip"
13 Jun 2008 14.12.00 32 886 648 A.... "C:\Program Files\Lenovo\System Update\session\1rd637ww\1rd637ww.exe"
13 Jun 2008 14.12.12 1 458 904 A.... "C:\Program Files\Lenovo\System Update\session\1ruj37us\1ruj37us.exe"
13 Jun 2008 14.16.30 6 541 200 A.... "C:\Program Files\Lenovo\System Update\session\1rwc89ww\1rwc89ww.exe"
13 Jun 2008 14.06.56 4 565 544 A.... "C:\Program Files\Lenovo\System Update\session\7avu43ww\7avu43ww.exe"
13 Jun 2008 14.15.48 6 989 888 A.... "C:\Program Files\Lenovo\System Update\session\7igu03ww\7igu03ww.exe"
13 Jun 2008 14.08.12 11 663 064 A.... "C:\Program Files\Lenovo\System Update\session\7ira09ww_mt1e\7ira09ww.exe"
13 Jun 2008 14.15.08 28 908 576 A.... "C:\Program Files\Lenovo\System Update\session\7ju501aw\7ju501aw.exe"
14 Jun 2008 17.48.28 8 596 960 A.... "C:\Program Files\Lenovo\System Update\session\7ksa14ww\7ksa14ww.exe"
13 Jun 2008 14.04.34 36 352 A.... "C:\Program Files\Lenovo\System Update\session\7ksa14ww\dm.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\7ksa14ww\multirc_run.exe"
13 Jun 2008 14.04.34 22 704 A.... "C:\Program Files\Lenovo\System Update\session\7ksa14ww\swi32.sys"
13 Jun 2008 14.04.36 24 368 A.... "C:\Program Files\Lenovo\System Update\session\7ksa14ww\swix64.sys"
13 Jun 2008 14.04.34 10 240 A.... "C:\Program Files\Lenovo\System Update\session\7ksa14ww\tpisysid3.exe"
13 Jun 2008 14.06.24 1 333 976 A.... "C:\Program Files\Lenovo\System Update\session\7tku03ww\7tku03ww.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613nl\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613nl\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613pl\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613pl\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613en\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613en\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613no\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613no\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613po\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613po\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613sp\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613sp\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613jp\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613jp\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613hb\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613hb\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613tr\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613tr\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613fr\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613fr\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613gr\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613gr\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613kr\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613kr\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613sc\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613sc\trueoslang.exe"
13 Jun 2008 14.04.16 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613tc\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613tc\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613it\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613it\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613ar\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613ar\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613br\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613br\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613cz\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613cz\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613dk\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613dk\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613ru\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613ru\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613hu\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613hu\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613sv\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613sv\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613fi\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613fi\trueoslang.exe"
13 Jun 2008 14.04.14 36 864 A.... "C:\Program Files\Lenovo\System Update\session\kb896613gk\multirc_run.exe"
13 Jun 2008 14.04.14 20 480 A.... "C:\Program Files\Lenovo\System Update\session\kb896613gk\trueoslang.exe"
13 Jun 2008 14.04.16 36 864 A.... "C:\Program Files\Lenovo\System Update\session\osx516jp\multirc_run.exe"
13 Jun 2008 14.04.34 20 480 A.... "C:\Program Files\Lenovo\System Update\session\osx516jp\trueoslang.exe"
13 Jun 2008 14.04.16 36 864 A.... "C:\Program Files\Lenovo\System Update\session\osx516us\multirc_run.exe"
13 Jun 2008 14.04.34 20 480 A.... "C:\Program Files\Lenovo\System Update\session\osx516us\trueoslang.exe"
13 Jun 2008 14.04.14 147 456 A.... "C:\Program Files\Lenovo\System Update\session\pae90_cdl_patch\dirpermission.exe"
13 Jun 2008 14.04.20 679 936 A.... "C:\Program Files\Lenovo\System Update\session\pbd0e_systemupdate\300$client.dll"
13 Jun 2008 14.04.24 221 184 A.... "C:\Program Files\Lenovo\System Update\session\pbd0e_systemupdate\300$common.dll"
13 Jun 2008 14.04.30 947 512 A.... "C:\Program Files\Lenovo\System Update\session\pbd0e_systemupdate\315$client.dll"
13 Jun 2008 14.04.32 247 096 A.... "C:\Program Files\Lenovo\System Update\session\pbd0e_systemupdate\315$common.dll"
13 Jun 2008 14.04.20 147 456 A.... "C:\Program Files\Lenovo\System Update\session\pbd0e_systemupdate\dirpermission.exe"
13 Jun 2008 14.04.24 24 576 A.... "C:\Program Files\Lenovo\System Update\session\pbd0e_systemupdate\patchinstall20071208.exe"
14 Jun 2008 18.00.24 53 323 215 A.... "C:\Program Files\Lenovo\System Update\session\pcd5setup_475511\pcd5setup_475511.exe"
13 Jun 2008 14.04.36 20 480 A.... "C:\Program Files\Lenovo\System Update\session\randomscheduler\detectschedulersetting.exe"
13 Jun 2008 14.04.38 20 480 A.... "C:\Program Files\Lenovo\System Update\session\rnr3guipatch\filedate2.exe"
26 Jul 2008 11.55.20 99 840 A.... "C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\BrandRes.dll"
26 Jul 2008 11.55.20 156 544 A.... "C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\fullsoft.dll"
26 Jul 2008 11.55.22 14 456 A.... "C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll"
26 Jul 2008 11.55.22 407 040 A.... "C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\talkback.exe"
30 May 2008 15.54.16 102 400 A.... "C:\Program Files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll"
30 May 2008 15.54.16 210 216 A.... "C:\Program Files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\PNRComponent.dll"
10 Jun 2008 4.44.20 9 685 797 A.... "C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core1.zip"
10 Jun 2008 4.44.22 10 238 372 A.... "C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core2.zip"
10 Jun 2008 4.44.24 4 868 848 A.... "C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core3.zip"
10 Jun 2008 4.44.26 3 584 A.... "C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_07.b06\launcher.exe"
10 Jun 2008 4.44.26 348 160 A.... "C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_07.b06\msvcr71.dll"
10 Jun 2008 4.44.26 5 690 728 A.... "C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_07.b06\patchjre.exe"
10 Jun 2008 4.44.26 237 568 A.... "C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_07.b06\regutils.dll"
10 Jun 2008 4.44.18 20 480 A.... "C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_07.b06\zipper.exe"
13 Jun 2008 14.39.12 10 498 A.... "C:\Program Files\ICQ6\services\icqatlasXtraz\ver1\theme\atlas_film\film.zip"
13 Jun 2008 14.39.12 10 599 A.... "C:\Program Files\ICQ6\services\icqatlasXtraz\ver1\theme\atlas_news\news.zip"
17 Jul 2008 18.56.08 833 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\content\coreg\index.html"
17 Jul 2008 18.56.08 444 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\content\coreg\preload.html"
13 Jun 2008 14.39.12 4 611 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\avatar\avatar.zip"
13 Jun 2008 14.39.12 5 704 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\backgammon\backgammon.zip"
13 Jun 2008 14.39.12 5 865 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\checkers\checkers.zip"
13 Jun 2008 14.39.12 5 170 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\comming_up\comming_up.zip"
13 Jun 2008 14.39.12 4 137 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\coreg\flower.zip"
13 Jun 2008 14.39.12 4 137 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\icq5_notification\flower.zip"
13 Jun 2008 14.39.12 3 219 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\icq_dialer\icq_dialer.zip"
13 Jun 2008 14.39.12 4 137 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\icq_welcome\flower.zip"
13 Jun 2008 14.39.12 15 722 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\mini_game_center\games_center.zip"
13 Jun 2008 14.39.14 53 189 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\mini_game_center\images.zip"
13 Jun 2008 14.39.12 4 539 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\odd_cast_vhost\oddcast.zip"
13 Jun 2008 14.39.12 2 364 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\p7_billing\p7_billing.zip"
13 Jun 2008 14.39.12 4 830 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\pccw_billing\pccw_billing.zip"
13 Jun 2008 14.39.12 5 647 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\pccw_pay_gmib\pccw_pay_gmib.zip"
13 Jun 2008 14.39.12 5 145 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\photo_cropper\photo.zip"
13 Jun 2008 14.39.12 6 187 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\pool\pool.zip"
13 Jun 2008 14.39.12 5 389 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\rps\rps.zip"
13 Jun 2008 14.39.14 4 984 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\slide-a-lama\slide-a-lama.zip"
13 Jun 2008 14.39.14 5 357 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\sms_activation\sms_activation.zip"
13 Jun 2008 14.39.14 4 706 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\warsheep\warsheep.zip"
13 Jun 2008 14.39.14 9 696 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\xicq_admirer_matchx\admirer.zip"
13 Jun 2008 14.39.14 9 696 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\xicq_admirer_top5x\admirer.zip"
13 Jun 2008 14.39.14 9 696 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\xicq_admirerx\admirer.zip"
13 Jun 2008 14.39.14 4 922 A.... "C:\Program Files\ICQ6\services\icqXtraz\ver1\theme\zoopaloola\zoopaloola.zip"
13 Jun 2008 11.33.10 180 356 A.... "C:\Program Files\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\iGdi.dll"
13 Jun 2008 11.33.10 303 236 A.... "C:\Program Files\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\setup.dll"


Files with hidden attributes:

Sat 26 Jul 2008 65,536 ..SH. --- "C:\Documents and Settings\Cermak\MediaTubeCodec_ver1.1463.0.exe"
Thu 17 Jul 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\eb0bafef2d63e64c417e80e803ff8747\BIT20.tmp"
Sat 14 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f7db876e78b88fd8276fd7d29cb7e4eb\BIT1.tmp"


Program Folders:

C:\Program Files\

ACD Systems
ACE Mega CoDecS Pack
Adobe
Ahead
Analog Devices
Apple Software Update
ATI Technologies
Common Files
ComPlus Applications
CONEXANT
CyberLink
Digital Line Detect
ESET
IBM
ICQ6
InstallShield Installation Information
Intel
Internet Explorer
Java
Lenovo
Messenger
Microcom
microsoft frontpage
Microsoft Office
Microsoft Visual Studio
Microsoft Works
Microsoft.NET
Movie Maker
Mozilla Firefox
MSN Gaming Zone
NetMeeting
NetWaiting
Online Services
Outlook Express
PCDR5
QuickTime
Skype
Sun
Synaptics
ThinkPad
Uninstall Information
uTorrent
Winamp
Winamp Toolbar
Windows Media Player
Windows NT
WindowsUpdate
WinRAR
xerox
Yahoo!

C:\Program Files\Common Files\

ACD Systems
Adobe
Ahead
DESIGNER
InstallShield
Java
Lenovo
Microsoft Shared
MSSoap
ODBC
Services
Skype
SpeechEngines
System
Wise Installation Wizard


Add/Remove Programs:

Adobe Flash Player Plugin
ATI - Software Uninstall Utility
ATI Display Driver
CCleaner (remove only)
ThinkPad Integrated 56K Modem
Conexant AccessRunner ADSL
HijackThis 2.0.2
Oprava Hotfix systému Windows XP číslo KB873339
Oprava Hotfix systému Windows XP číslo KB885835
Oprava Hotfix systému Windows XP číslo KB885836
Oprava Hotfix systému Windows XP číslo KB886185
Oprava Hotfix systému Windows XP číslo KB887472
Oprava Hotfix systému Windows XP číslo KB888302
Aktualizace zabezpečení systému Windows XP (KB890046)
Oprava Hotfix systému Windows XP číslo KB890859
Oprava Hotfix systému Windows XP číslo KB891781
Aktualizace zabezpečení systému Windows XP (KB893756)
Windows Installer 3.1 (KB893803)
Aktualizace systému Windows XP (KB894391)
Aktualizace zabezpečení systému Windows XP (KB896358)
Aktualizace zabezpečení systému Windows XP (KB896423)
Aktualizace zabezpečení systému Windows XP (KB896428)
Aktualizace systému Windows XP (KB898461)
Aktualizace zabezpečení systému Windows XP (KB899587)
Aktualizace zabezpečení systému Windows XP (KB899591)
Aktualizace systému Windows XP (KB900485)
Aktualizace zabezpečení systému Windows XP (KB900725)
Aktualizace zabezpečení systému Windows XP (KB901017)
Aktualizace zabezpečení systému Windows XP (KB901214)
Aktualizace zabezpečení systému Windows XP (KB902400)
Aktualizace zabezpečení systému Windows XP (KB905414)
Aktualizace zabezpečení systému Windows XP (KB905749)
Aktualizace zabezpečení systému Windows XP (KB908519)
Aktualizace systému Windows XP (KB908531)
Aktualizace systému Windows XP (KB910437)
Aktualizace systému Windows XP (KB911280)
Aktualizace zabezpečení systému Windows XP (KB911562)
Aktualizace zabezpečení aplikace Windows Media Player (KB911564)
Aktualizace zabezpečení systému Windows XP (KB911927)
Aktualizace zabezpečení systému Windows XP (KB913580)
Aktualizace zabezpečení systému Windows XP (KB914388)
Aktualizace zabezpečení systému Windows XP (KB914389)
Aktualizace systému Windows XP (KB916595)
Aktualizace zabezpečení systému Windows XP (KB918118)
Aktualizace zabezpečení systému Windows XP (KB918439)
Aktualizace zabezpečení systému Windows XP (KB920213)
Aktualizace zabezpečení systému Windows XP (KB920670)
Aktualizace zabezpečení systému Windows XP (KB920683)
Aktualizace zabezpečení systému Windows XP (KB920685)
Aktualizace systému Windows XP (KB920872)
Aktualizace systému Windows XP (KB922582)
Aktualizace zabezpečení systému Windows XP (KB922819)
Aktualizace zabezpečení systému Windows XP (KB923191)
Aktualizace zabezpečení systému Windows XP (KB923414)
Aktualizace zabezpečení produktu Windows XP (KB923689)
Aktualizace zabezpečení systému Windows XP (KB923980)
Aktualizace zabezpečení systému Windows XP (KB924270)
Aktualizace zabezpečení systému Windows XP (KB924496)
Aktualizace zabezpečení systému Windows XP (KB924667)
Aktualizace zabezpečení aplikace Windows Media Player 6.4 (KB925398)
Aktualizace zabezpečení systému Windows XP (KB925902)
Aktualizace zabezpečení systému Windows XP (KB926255)
Aktualizace zabezpečení systému Windows XP (KB926436)
Aktualizace zabezpečení systému Windows XP (KB927779)
Aktualizace zabezpečení systému Windows XP (KB927802)
Aktualizace systému Windows XP (KB927891)
Aktualizace zabezpečení systému Windows XP (KB928255)
Aktualizace zabezpečení systému Windows XP (KB928843)
Aktualizace zabezpečení systému Windows XP (KB929123)
Aktualizace zabezpečení systému Windows XP (KB930178)
Aktualizace systému Windows XP (KB930916)
Aktualizace zabezpečení systému Windows XP (KB931261)
Aktualizace zabezpečení systému Windows XP (KB931784)
Aktualizace zabezpečení systému Windows XP (KB932168)
Aktualizace zabezpečení systému Windows XP (KB933729)
Aktualizace zabezpečení systému Windows XP (KB935839)
Aktualizace zabezpečení systému Windows XP (KB935840)
Aktualizace zabezpečení systému Windows XP (KB936021)
Aktualizace systému Windows XP (KB936357)
Aktualizace zabezpečení aplikace Windows Media Player 10 (KB936782)
Aktualizace zabezpečení systému Windows XP (KB937894)
Aktualizace zabezpečení systému Windows XP (KB938127)
Aktualizace systému Windows XP (KB938828)
Aktualizace zabezpečení systému Windows XP (KB941202)
Aktualizace zabezpečení produktu Windows XP (KB941569)
Aktualizace zabezpečení systému Windows XP (KB941644)
Aktualizace zabezpečení systému Windows XP (KB941693)
Aktualizace systému Windows XP (KB942763)
Aktualizace zabezpečení systému Windows XP (KB943055)
Aktualizace zabezpečení systému Windows XP (KB943460)
Aktualizace zabezpečení systému Windows XP (KB943485)
Aktualizace zabezpečení systému Windows XP (KB944338)
Aktualizace zabezpečení systému Windows XP (KB944653)
Aktualizace zabezpečení systému Windows XP (KB945553)
Aktualizace zabezpečení systému Windows XP (KB946026)
Aktualizace zabezpečení systému Windows XP (KB948590)
Aktualizace zabezpečení systému Windows XP (KB950749)
Aktualizace zabezpečení systému Windows XP (KB950759)
Aktualizace zabezpečení systému Windows XP (KB950760)
Aktualizace zabezpečení systému Windows XP (KB950762)
Aktualizace zabezpečení systému Windows XP (KB951376)
Aktualizace zabezpečení systému Windows XP (KB951376-v2)
Aktualizace zabezpečení systému Windows XP (KB951698)
Aktualizace zabezpečení systému Windows XP (KB951748)
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0
Mozilla Firefox (2.0.0.16)
Nero 6 Ultra Edition
PC-Doctor 5 for Windows
IBM ThinkPad Battery MaxiMiser and Power Management Features
ThinkPad Power Management Driver
Intel(R) PRO Network Connections Drivers
Adobe Flash Player 9 ActiveX
ThinkPad UltraNav Driver
ThinkPad FullScreen Magnifier
Total Commander (Remove or Repair)
Winamp
Winamp Toolbar for Internet Explorer
Winamp Toolbar for Firefox
Windows Media Format Runtime
Windows Media Player 10
WinRAR archivátor
Yahoo! Toolbar
Yahoo! Install Manager
ATI Control Panel
OpenOffice.org Installer 1.0
ThinkPad Keyboard Customizer Utility
Java(TM) 6 Update 7
ThinkVantage Active Protection System
ACDSee 5.0 PowerPack
TuneUp Utilities 2008
Skype™ 3.8
QuickTime
ICQ6
Intel(R) Sebring API
PowerDVD
Microsoft .NET Framework 2.0
System Update
Microsoft Office Professional Edition 2003
Apple Software Update
Adobe Reader 7.0.5 - Czech
ESET Smart Security
FIRE GL driver for 3D Studio MAX/VIZ
IBM Integrated Bluetooth II Software
SoundMAX
ThinkPad Configuration
ACE Mega CoDecS Pack
µTorrent


Run Values:

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\SoundMAX\\SMax4PNP.exe"
"SoundMAX"="C:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe /tray"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"BMMGAG"="RunDll32 C:\\PROGRA~1\\ThinkPad\\UTILIT~1\\pwrmonit.dll,StartPwrMonitor"
"BMMLREF"="C:\\Program Files\\ThinkPad\\Utilities\\BMMLREF.EXE"
"BMMMONWND"="rundll32.exe C:\\PROGRA~1\\ThinkPad\\UTILIT~1\\BatInfEx.dll,BMMAutonomicMonitor"
"BLOG"="rundll32.exe C:\\PROGRA~1\\ThinkPad\\UTILIT~1\\BatLogEx.DLL,StartBattLog"
"TPKMAPHELPER"="C:\\Program Files\\ThinkPad\\Utilities\\TpKmapAp.exe -helper"
"TVT Scheduler Proxy"="C:\\Program Files\\Common Files\\Lenovo\\Scheduler\\scheduler_proxy.exe"
"TPHOTKEY"="C:\\PROGRA~1\\Lenovo\\PkgMgr\\HOTKEY\\TPHKMGR.exe"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"frymxins"="\"C:\\Program Files\\ATI Technologies\\Fire GL 3D Studio Max\\atiimxgl\""
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"egui"="\"C:\\Program Files\\ESET\\ESET Smart Security\\egui.exe\" /hide /waitservice"
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"QuickTime Task"="\"C:\\WINDOWS\\system32\\qttask.exe\" -atboottime"
"CnxDslTaskBar"="\"c:\\program files\\microcom\\adsl deskporte usb\\CnxDslTb.exe\" \"Microcom\\ADSL DeskPorte USB\""
"TpShocks"="TpShocks.exe"
"WinampAgent"="\"C:\\Program Files\\Winamp\\winampa.exe\""
"SDFix"="E:\\SDFix\\SDFix\\RunThis.bat /second"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"


Bot Check:

SERVICE_NAME: wscsvc
DISPLAY_NAME : Centrum zabezpe
START_TYPE : 2 AUTO_START

SERVICE_NAME: sharedaccess
DISPLAY_NAME : Brána Firewall / Sdílení p
START_TYPE : 2 AUTO_START

SERVICE_NAME: wuauserv
DISPLAY_NAME : Automatické aktualizace
START_TYPE : 2 AUTO_START

SERVICE_NAME: srservice
DISPLAY_NAME : Slu
START_TYPE : 2 AUTO_START

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole]
"EnableDCOM"="Y"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"restrictanonymous"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update]
"AUOptions"=dword:00000004

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify"=dword:00000000
"FirewallDisableNotify"=dword:00000000
"UpdatesDisableNotify"=dword:00000000
"AntiVirusOverride"=dword:00000000
"FirewallOverride"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"WaitToKillServiceTimeout"="20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"SFCDisable"=dword:00000000
"Shell"="Explorer.exe"
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shell extensions]
@=""

@=""


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters]
"TransportBindName"="\\Device\\"


ShellExecuteHooks:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""



Environment:


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\environment
ComSpec REG_EXPAND_SZ %SystemRoot%\system32\cmd.exe
Path REG_EXPAND_SZ C:\Program Files\ThinkPad\Utilities;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Lenovo;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\ATI Technologies\Fire GL 3D Studio Max;C:\Program Files\QuickTime\QTSystem\
windir REG_EXPAND_SZ %SystemRoot%
OS REG_SZ Windows_NT
PATHEXT REG_SZ .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
TEMP REG_EXPAND_SZ %SystemRoot%\TEMP
TMP REG_EXPAND_SZ %SystemRoot%\TEMP
TVT REG_SZ C:\Program Files\Lenovo
CLASSPATH REG_SZ .;C:\Program Files\QuickTime\QTSystem\QTJava.zip
QTJAVA REG_SZ C:\Program Files\QuickTime\QTSystem\QTJava.zip

SecurityProviders:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders
SecurityProviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,


Authentication Packages:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0


Subsystem Startup:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems]
"Windows"="%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16"


Midi Drivers:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midi"="wdmaud.drv"


Non-Default IFEO Debugger:


Non-Default Installed Components:


Non-Default Safeboot Minimal:


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\winhn30.sys
<NO NAME> REG_SZ Driver


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\winpw28.sys
<NO NAME> REG_SZ Driver


File Associations:


[HKEY_CLASSES_ROOT\batfile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\cmdfile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\comfile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\htafile\shell\open\command]
@="C:\\WINDOWS\\system32\\mshta.exe \"%1\" %*"

[HKEY_CLASSES_ROOT\http\shell\open\command]
@="C:\\PROGRA~1\\MOZILL~1\\FIREFOX.EXE -requestPending -osint -url \"%1\""

[HKEY_CLASSES_ROOT\htmlfile\shell\open\command]
@="\"C:\\Program Files\\Internet Explorer\\iexplore.exe\" -nohome"

[HKEY_CLASSES_ROOT\regedit\shell\open\command]
@="regedit.exe %1"

[HKEY_CLASSES_ROOT\regfile\shell\open\command]
@="regedit.exe \"%1\" %*"

[HKEY_CLASSES_ROOT\scrfile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\txtfile\shell\open\command]
@="%SystemRoot%\system32\NOTEPAD.EXE %1"


Finished!
bobcat61
Active Member
 
Posts: 9
Joined: July 26th, 2008, 8:13 am

Re: NEED HELP WITH RED Desktop {BIOHAZARD} - TROYAN and WORM

Unread postby random/random » July 27th, 2008, 6:43 am

You appear to have run SDFix in normal mode. It needs to be run in safe mode. Please follow the instructions exactly and then post the log.
User avatar
random/random
Developer
Developer
 
Posts: 7733
Joined: December 18th, 2005, 3:30 pm

Re: NEED HELP WITH RED Desktop {BIOHAZARD} - TROYAN and WORM

Unread postby bobcat61 » July 27th, 2008, 8:14 am

i did it again. sorry, i was wrong. hope it is ok now. here are log files:

SDFix: Version 1.208
Run by Cermak on ne 27. 07. 2008 at 14:07

Microsoft Windows XP [Verze 5.1.2600]
Running From: C:\DOCUME~1\Cermak\Plocha\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-27 14:10:23
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0020e07e9724]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0020e07e9724]

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes]
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?"="C:\WINDOWS\cursors\arrow_r.cur,C:\WINDOWS\cursors\help_r.cur,C:\WINDOWS\cursors\wait_r.cur,C:\WINDOWS\cursors\busy_r.cur,C:\WINDOWS\cursors\cross_r.cur,C:\WINDOWS\cursors\beam_r.cur,C:\WINDOWS\cursors\pen_r.cur,C:\WINDOWS\cursors\no_r.cur,C:\WINDOWS\cursors\size4_r.cur,C:\WINDOWS\cursors\size3_r.cur,C:\WINDOWS\cursors\size2_r.cur,C:\WINDOWS\cursors\size1_r.cur,C:\WINDOWS\cursors\move_r.cur,C:\WINDOWS\cursors\up_r.cur"
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?(?v?e?l?k?é?)?"="C:\WINDOWS\cursors\arrow_rm.cur,C:\WINDOWS\cursors\help_rm.cur,C:\WINDOWS\cursors\wait_rm.cur,C:\WINDOWS\cursors\busy_rm.cur,C:\WINDOWS\cursors\cross_rm.cur,C:\WINDOWS\cursors\beam_rm.cur,C:\WINDOWS\cursors\pen_rm.cur,C:\WINDOWS\cursors\no_rm.cur,C:\WINDOWS\cursors\size4_rm.cur,C:\WINDOWS\cursors\size3_rm.cur,C:\WINDOWS\cursors\size2_rm.cur,C:\WINDOWS\cursors\size1_rm.cur,C:\WINDOWS\cursors\move_rm.cur,C:\WINDOWS\cursors\up_rm.cur"
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?(?n?e?j?v?\e\1t?a\1í?)?"="C:\WINDOWS\cursors\arrow_rl.cur,C:\WINDOWS\cursors\help_rl.cur,C:\WINDOWS\cursors\wait_rl.cur,C:\WINDOWS\cursors\busy_rl.cur,C:\WINDOWS\cursors\cross_rl.cur,C:\WINDOWS\cursors\beam_rl.cur,C:\WINDOWS\cursors\pen_rl.cur,C:\WINDOWS\cursors\no_rl.cur,C:\WINDOWS\cursors\size4_rl.cur,C:\WINDOWS\cursors\size3_rl.cur,C:\WINDOWS\cursors\size2_rl.cur,C:\WINDOWS\cursors\size1_rl.cur,C:\WINDOWS\cursors\move_rl.cur,C:\WINDOWS\cursors\up_rl.cur"

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\ICQ6\\ICQ.exe"="C:\\Program Files\\ICQ6\\ICQ.exe:*:Enabled:ICQ6"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:uTorrent"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Mozilla Firefox"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files :



Files with Hidden Attributes :

Sat 26 Jul 2008 65,536 ..SH. --- "C:\Documents and Settings\Cermak\MediaTubeCodec_ver1.1463.0.exe"
Thu 17 Jul 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\eb0bafef2d63e64c417e80e803ff8747\BIT20.tmp"
Sat 14 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f7db876e78b88fd8276fd7d29cb7e4eb\BIT1.tmp"

Finished!








...and log file from HJT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:12:14, on 27. 7. 2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Lenovo\System Update\SUService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\qttask.exe
C:\program files\microcom\adsl deskporte usb\CnxDslTb.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
E:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [frymxins] "C:\Program Files\ATI Technologies\Fire GL 3D Studio Max\atiimxgl"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CnxDslTaskBar] "c:\program files\microcom\adsl deskporte usb\CnxDslTb.exe" "Microcom\ADSL DeskPorte USB"
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\IBM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

--
End of file - 9141 bytes


thank you very mauch for patient.

roman
bobcat61
Active Member
 
Posts: 9
Joined: July 26th, 2008, 8:13 am

Re: NEED HELP WITH RED Desktop {BIOHAZARD} - TROYAN and WORM

Unread postby random/random » July 27th, 2008, 3:00 pm

I had a quick look at the first SDFix report you posted, and I saw a couple of worrying registry keys there, so I'd like to run another tool to check further.

We'll continue with ComboFix. Please visit this webpage for download links, and instructions for running the tool:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Post the combofix log and a new HijackThis log as a reply to this topic.
User avatar
random/random
Developer
Developer
 
Posts: 7733
Joined: December 18th, 2005, 3:30 pm

Re: NEED HELP WITH RED Desktop {BIOHAZARD} - TROYAN and WORM

Unread postby bobcat61 » July 27th, 2008, 3:32 pm

hi, i just did it. thank you for helping once again.

ComboFix 08-07-27.2 - Cermak 2008-07-27 21:26:29.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.1609 [GMT 2:00]
Running from: C:\Documents and Settings\Cermak\Plocha\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-06-27 to 2008-07-27 )))))))))))))))))))))))))))))))
.

2008-07-26 18:20 . 2008-07-26 18:20 <DIR> d-------- C:\WINDOWS\Sun
2008-07-26 18:19 . 2008-07-26 18:19 <DIR> d-------- C:\Program Files\Sun
2008-07-26 18:18 . 2008-07-26 18:18 <DIR> d-------- C:\Program Files\Java
2008-07-26 18:18 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-26 18:17 . 2008-07-26 18:17 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-26 17:53 . 2008-07-26 17:53 <DIR> d-------- C:\Deckard
2008-07-26 17:47 . 2008-07-26 17:47 <DIR> d-------- C:\Documents and Settings\Cermak\Data aplikací\Malwarebytes
2008-07-26 17:47 . 2008-07-26 17:47 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2008-07-26 17:47 . 2008-07-23 20:09 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-26 17:47 . 2008-07-23 20:09 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-26 17:26 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-07-26 17:26 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-07-26 17:26 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-07-26 17:26 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-07-26 17:26 . 2008-07-02 13:33 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-07-26 17:26 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
2008-07-26 17:26 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-07-26 17:26 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-07-26 17:26 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-07-26 17:16 . 2008-07-26 17:16 <DIR> d-------- C:\WINDOWS\ERUNT
2008-07-26 16:09 . 2008-07-26 17:26 4,274 --a------ C:\WINDOWS\system32\tmp.reg
2008-07-26 13:31 . 2008-07-26 13:31 <DIR> d-------- C:\Program Files\Yahoo!
2008-07-26 13:31 . 2008-07-26 13:31 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Yahoo! Companion
2008-07-26 12:39 . 2008-07-26 12:39 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-07-26 12:39 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-07-26 12:33 . 2008-07-26 12:33 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-26 12:11 . 2001-10-25 14:00 4,224 --a------ C:\WINDOWS\system32\beep.sys
2008-07-26 12:10 . 2008-07-26 12:10 65,536 ---hs---- C:\Documents and Settings\Cermak\MediaTubeCodec_ver1.1463.0.exe
2008-07-07 20:28 . 2008-07-07 20:28 <DIR> d-------- C:\Documents and Settings\Cermak\Data aplikací\AdobeUM
2008-07-03 07:37 . 2008-07-03 07:37 <DIR> d-------- C:\Program Files\Winamp Toolbar
2008-07-03 07:37 . 2008-07-06 20:08 <DIR> d-------- C:\Program Files\Winamp
2008-07-03 07:37 . 2008-07-03 07:41 <DIR> d-------- C:\Documents and Settings\Cermak\Data aplikací\Winamp
2008-07-03 07:37 . 2008-07-03 07:37 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Winamp Toolbar
2008-06-27 06:42 . 2008-06-27 06:42 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-27 06:42 . 2008-06-27 06:42 1,409 --a------ C:\WINDOWS\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-27 19:25 --------- d-----w C:\Documents and Settings\Cermak\Data aplikací\uTorrent
2008-07-22 17:07 --------- d-----w C:\Documents and Settings\Cermak\Data aplikací\Skype
2008-07-22 16:50 --------- d-----w C:\Documents and Settings\Cermak\Data aplikací\skypePM
2008-07-17 16:54 --------- d-----w C:\Documents and Settings\Cermak\Data aplikací\ICQ
2008-07-17 16:53 --------- d-----w C:\Program Files\ICQ6
2008-06-20 17:42 247,296 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-18 21:02 --------- d-----w C:\Program Files\Skype
2008-06-18 21:02 --------- d-----w C:\Program Files\Common Files\Skype
2008-06-18 21:02 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Skype
2008-06-18 16:24 --------- d-----w C:\Program Files\uTorrent
2008-06-16 16:53 --------- d-----w C:\Documents and Settings\Cermak\Data aplikací\ACD Systems
2008-06-14 18:00 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-14 16:01 --------- d-----w C:\Program Files\PCDR5
2008-06-14 16:01 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\PC-Doctor
2008-06-13 16:05 --------- d-----w C:\Documents and Settings\Cermak\Data aplikací\TuneUp Software
2008-06-13 16:05 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2008-06-13 15:03 --------- d-----w C:\Program Files\Microcom
2008-06-13 12:50 98,304 ----a-w C:\WINDOWS\system32\qttask.exe
2008-06-13 12:50 --------- d-----w C:\Program Files\QuickTime
2008-06-13 12:49 --------- d-----w C:\Program Files\Ahead
2008-06-13 12:49 --------- d-----w C:\Program Files\ACE Mega CoDecS Pack
2008-06-13 12:48 --------- d-----w C:\Program Files\Common Files\Ahead
2008-06-13 12:46 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-13 12:41 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\CyberLink
2008-06-13 12:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-13 12:40 --------- d-----w C:\Program Files\CyberLink
2008-06-13 12:39 --------- d-----w C:\Program Files\Apple Software Update
2008-06-13 12:39 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2008-06-13 12:37 --------- d-----w C:\Documents and Settings\Cermak\Data aplikací\InstallShield
2008-06-13 12:35 --------- d-----w C:\Documents and Settings\Cermak\Data aplikací\ESET
2008-06-13 12:34 --------- d-----w C:\Program Files\ESET
2008-06-13 12:34 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\ESET
2008-06-13 12:32 --------- d-----w C:\Program Files\ACD Systems
2008-06-13 12:31 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-06-13 12:31 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\ACD Systems
2008-06-13 12:27 --------- d-----w C:\Program Files\Microsoft Works
2008-06-13 12:25 --------- d-----w C:\Program Files\Microsoft.NET
2008-06-13 12:20 17,801 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-06-13 12:19 --------- d-----w C:\Program Files\Synaptics
2008-06-13 12:18 --------- d-----w C:\Program Files\ATI Technologies
2008-06-13 12:17 0 ---ha-r C:\WINDOWS\system32\drivers\IBM_2373_HTG_TP.MRK
2008-06-13 12:17 --------- d-----w C:\Program Files\Lenovo
2008-06-13 12:02 --------- d-----w C:\Program Files\Common Files\Lenovo
2008-06-13 10:16 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-13 09:43 --------- d-----w C:\Program Files\NetWaiting
2008-06-13 09:43 --------- d-----w C:\Program Files\Digital Line Detect
2008-06-13 09:43 --------- d-----w C:\Program Files\CONEXANT
2008-06-13 09:42 --------- d-----w C:\Program Files\Intel
2008-06-13 09:38 --------- d-----w C:\Program Files\ThinkPad
2008-06-13 09:36 --------- d-----w C:\Program Files\IBM
2008-06-13 09:33 --------- d-----w C:\Program Files\Analog Devices
2008-06-13 09:20 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-16 08:36 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-05-16 08:36 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-05-16 08:36 1,047,552 ----a-w C:\WINDOWS\system32\MFC71u.dll
2008-05-07 05:16 1,290,240 ----a-w C:\WINDOWS\system32\quartz.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2008-03-20 00:36 1267040]

[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"frymxins"="C:\Program Files\ATI Technologies\Fire GL 3D Studio Max\atiimxgl" [X]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 09:11 1388544]
"BMMGAG"="C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2005-04-20 01:38 110592]
"BMMLREF"="C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE" [2005-04-20 01:38 20480]
"BMMMONWND"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2005-04-20 01:38 396288]
"BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-04-20 01:38 208896]
"TPKMAPHELPER"="C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" [2006-06-02 22:00 856064]
"TVT Scheduler Proxy"="C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 10:34 487424]
"TPHOTKEY"="C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-10-02 10:19 94208]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2007-02-06 21:00 344064]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2007-12-05 16:14 122880]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-05 16:14 524288]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2007-10-25 09:26 1410304]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24 32768]
"QuickTime Task"="C:\WINDOWS\system32\qttask.exe" [2008-06-13 14:50 98304]
"CnxDslTaskBar"="c:\program files\microcom\adsl deskporte usb\CnxDslTb.exe" [2004-06-16 07:55 233472]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-03-27 08:35 36352]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-17 15:49 110592 C:\WINDOWS\system32\bthprops.cpl]
"TpShocks"="TpShocks.exe" [2007-11-22 15:09 181536 C:\WINDOWS\system32\TpShocks.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 15:49 15360]

C:\Documents and Settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 07:05:26 29696]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-06-13 11:43:58 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-05 23:45 28672 C:\WINDOWS\system32\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-11-30 20:16 24576 C:\WINDOWS\system32\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.iac2"= C:\PROGRA~1\ACEMEG~1\SystemS\Intel\iac25_32.ax
"msacm.sl_anet"= C:\PROGRA~1\ACEMEG~1\SystemS\sl_anet.acm
"vidc.yv12"= C:\PROGRA~1\ACEMEG~1\SystemS\ATI\atiyuv12.DLL
"vidc.divx"= C:\PROGRA~1\ACEMEG~1\SystemS\DivX\DivX520.dll
"vidc.iyuv"= C:\PROGRA~1\ACEMEG~1\SystemS\Intel\iyuv_32.dll
"vidc.yvu9"= C:\PROGRA~1\ACEMEG~1\SystemS\Intel\Iyvu9_32.dll
"vidc.uyvy"= C:\PROGRA~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"vidc.yuy2"= C:\PROGRA~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"vidc.yvyu"= C:\PROGRA~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"msacm.msaudio1"= C:\PROGRA~1\ACEMEG~1\SystemS\MICROS~1\msaud32.acm

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winhn30.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winpw28.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 Shockprf;Shockprf;C:\WINDOWS\system32\DRIVERS\Apsx86.sys [2007-10-16 18:33]
R0 TPDIGIMN;TPDIGIMN;C:\WINDOWS\system32\DRIVERS\ApsHM86.sys [2007-10-16 18:32]
R1 easdrv;easdrv;C:\WINDOWS\system32\DRIVERS\easdrv.sys [2007-10-25 09:25]
R1 epfwtdi;epfwtdi;C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2007-10-25 09:27]
R1 Smapint;Smapint;C:\WINDOWS\system32\drivers\Smapint.sys [2006-10-02 01:55]
R1 TDSMAPI;TDSMAPI;C:\WINDOWS\system32\drivers\TDSMAPI.SYS [2006-10-02 01:55]
R1 TPHKDRV;TPHKDRV;C:\WINDOWS\system32\drivers\TPHKDRV.sys [2005-07-05 14:57]
R1 TPPWR;TPPWR;C:\WINDOWS\system32\drivers\Tppwr.sys [2005-04-20 01:38]
R2 BthServ;Bluetooth Support Service;C:\WINDOWS\system32\svchost.exe [2004-08-17 15:49]
R2 eamon;EAMON;C:\WINDOWS\system32\DRIVERS\eamon.sys [2007-10-25 09:25]
R2 ekrn;Eset Service;C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-10-25 09:26]
R2 epfw;epfw;C:\WINDOWS\system32\DRIVERS\epfw.sys [2007-10-25 09:27]
R2 IBMPMSVC;ThinkPad PM Service;C:\WINDOWS\system32\ibmpmsvc.exe [2007-11-02 15:51]
R2 irda;Protokol IrDA;C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-04 01:00]
R2 Irmon;Sledování infračerveného přenosu;C:\WINDOWS\system32\svchost.exe [2004-08-17 15:49]
R2 RegSrvc;RegSrvc;C:\WINDOWS\system32\RegSrvc.exe [2006-06-16 15:55]
R2 s24trans;WLAN Transport;C:\WINDOWS\system32\DRIVERS\s24trans.sys [2006-06-16 15:50]
R2 SUService;System Update;C:\Program Files\Lenovo\System Update\SUService.exe [2008-05-16 10:52]
R2 ThinkVantage Registry Monitor Service;ThinkVantage Registry Monitor Service;C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe [2007-09-26 17:34]
R2 TpKmpSVC;IBM KCU Service;C:\WINDOWS\system32\TpKmpSVC.exe [2005-06-06 21:26]
R2 TVT Scheduler;TVT Scheduler;C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe [2008-03-04 10:34]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-17 15:49]
R3 aeaudio;aeaudio;C:\WINDOWS\system32\drivers\aeaudio.sys [2005-03-04 20:53]
R3 BthEnum;Ovladač pro Bluetooth Request Block;C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2004-08-03 23:10]
R3 BthPan;Bluetooth Device (Personal Area Network);C:\WINDOWS\system32\DRIVERS\bthpan.sys [2004-08-03 22:58]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth;C:\WINDOWS\system32\Drivers\BTHUSB.sys [2004-08-03 23:10]
R3 CnxEtP;Conexant AccessRunner USB ADSL Adapter Filter Driver;C:\WINDOWS\system32\DRIVERS\CnxEtP.sys [2004-06-16 07:51]
R3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;C:\WINDOWS\system32\DRIVERS\CnxEtU.sys [2004-06-16 07:51]
R3 CnxTgNP;Conexant AccessRunner ADSL WAN PPPoE Adapter Driver;C:\WINDOWS\system32\DRIVERS\CnxTgNP.sys [2004-06-16 07:51]
R3 Epfwndis;Eset Personal Firewall;C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2007-10-25 09:27]
R3 HSF_DPV;HSF_DPV;C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-10-18 17:53]
R3 HSFHWICH;HSFHWICH;C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys [2005-10-18 17:52]
R3 IBMPMDRV;IBMPMDRV;C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2007-11-02 15:50]
R3 NSCIRDA;NSC Infrared Device Driver;C:\WINDOWS\system32\DRIVERS\nscirda.sys [2004-08-04 01:00]
R3 psadd;Lenovo Parties Service Access Device Driver;C:\WINDOWS\system32\DRIVERS\psadd.sys [2007-02-19 07:56]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
R3 Rasirda;WAN Miniport (IrDA);C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 23:51]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI);C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2004-08-03 23:10]
R3 smwdm;smwdm;C:\WINDOWS\system32\drivers\smwdm.sys [2005-03-28 09:19]
R3 SynTP;Synaptics TouchPad Driver;C:\WINDOWS\system32\DRIVERS\SynTP.sys [2007-12-05 16:11]
S0 Winhn30;Winhn30;C:\WINDOWS\system32\Drivers\Winhn30.sys []
S0 Winpw28;Winpw28;C:\WINDOWS\system32\Drivers\Winpw28.sys []
S3 BTHPORT;Ovladač portu Bluetooth;C:\WINDOWS\system32\Drivers\BTHport.sys [2008-06-14 20:00]
S3 EhttpSrv;Eset HTTP Server;C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2007-10-25 09:27]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-07-26 12:39]
S3 UIUSys;Conexant Setup API;C:\WINDOWS\system32\drivers\UIUSys.sys []
S3 w70n51;Intel(R) PRO/Wireless 7100 Adapter Driver for Windows XP;C:\WINDOWS\system32\DRIVERS\w70n51.sys [2006-07-13 12:33]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-07-26 C:\WINDOWS\Tasks\1-Click Maintenance.job - E:\tu\OneClick.exe [2008-04-16 09:59]
2008-06-13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]
2008-06-13 C:\WINDOWS\Tasks\BMMTask.job - C:\PROGRA~1\ThinkPad\UTILIT~1\BMMTASK.EXE [2005-04-20 01:38]
.
.
------- Supplementary Scan -------
.
O8 -: &Winamp Search - C:\Documents and Settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 -: E&xportovat do aplikace Microsoft Office Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: Send To &Bluetooth - C:\Program Files\IBM\Bluetooth Software\btsendto_ie_ctx.htm


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-27 21:27:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\tphklock.dll
.
Completion time: 2008-07-27 21:28:11
ComboFix-quarantined-files.txt 2008-07-27 19:28:07

Pre-Run: 8,431,710,208
Post-Run: 8,420,802,560

254 --- E O F --- 2008-07-16 22:37:36








HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:30:49, on 27. 7. 2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Lenovo\System Update\SUService.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\qttask.exe
C:\program files\microcom\adsl deskporte usb\CnxDslTb.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
E:\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [frymxins] "C:\Program Files\ATI Technologies\Fire GL 3D Studio Max\atiimxgl"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CnxDslTaskBar] "c:\program files\microcom\adsl deskporte usb\CnxDslTb.exe" "Microcom\ADSL DeskPorte USB"
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\IBM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{0CFD20D2-4E26-4DAC-91FF-7C35EACEED91}: NameServer = 195.146.132.58 195.146.128.60
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

--
End of file - 9482 bytes
bobcat61
Active Member
 
Posts: 9
Joined: July 26th, 2008, 8:13 am

Re: NEED HELP WITH RED Desktop {BIOHAZARD} - TROYAN and WORM

Unread postby random/random » July 28th, 2008, 9:05 am

  • Open a new notepad window (Start>All programs>accessories>notepad)
  • Highlight the contents of the below codebox and then press ctrl+c to copy it to the clipboard
    Code: Select all
    Driver::
    Winhn30
    Winpw28
    File::
    C:\WINDOWS\system32\Drivers\Winhn30.sys
    C:\WINDOWS\system32\Drivers\Winpw28.sys
    Registry::
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winhn30.sys]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winpw28.sys]
    
  • Paste the contents of the clipboard into the notepad window by pressing ctrl+v or edit>paste
  • Save it to the desktop as CFscript.txt
  • Now drag and drop CFscript.txt onto combofix.exe as in the picture below and follow the prompts:
    Image
  • When finished, it shall produce a log for you. Post that log and a HijackThis log in your next reply
    Note: Do not mouseclick combofix's window while its running. That may cause it to stall
User avatar
random/random
Developer
Developer
 
Posts: 7733
Joined: December 18th, 2005, 3:30 pm

Re: NEED HELP WITH RED Desktop {BIOHAZARD} - TROYAN and WORM

Unread postby bobcat61 » July 28th, 2008, 9:36 am

hello,
i did it as you wrote. here are new log files.

ComboFix 08-07-27.2 - Cermak 2008-07-28 15:25:37.2 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.1631 [GMT 2:00]
Running from: C:\Documents and Settings\Cermak\Plocha\ComboFix.exe
Command switches used :: C:\Documents and Settings\Cermak\Plocha\CFscript.txt
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\Drivers\Winhn30.sys
C:\WINDOWS\system32\Drivers\Winpw28.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_Winhn30
-------\Service_Winpw28


((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-28 )))))))))))))))))))))))))))))))
.

2008-07-26 18:20 . 2008-07-26 18:20 <DIR> d-------- C:\WINDOWS\Sun
2008-07-26 18:19 . 2008-07-26 18:19 <DIR> d-------- C:\Program Files\Sun
2008-07-26 18:18 . 2008-07-26 18:18 <DIR> d-------- C:\Program Files\Java
2008-07-26 18:18 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-26 18:17 . 2008-07-26 18:17 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-26 17:53 . 2008-07-26 17:53 <DIR> d-------- C:\Deckard
2008-07-26 17:47 . 2008-07-23 20:09 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-26 17:47 . 2008-07-23 20:09 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-26 17:26 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-07-26 17:26 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-07-26 17:26 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-07-26 17:26 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-07-26 17:26 . 2008-07-02 13:33 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-07-26 17:26 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
2008-07-26 17:26 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-07-26 17:26 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-07-26 17:26 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-07-26 17:16 . 2008-07-26 17:16 <DIR> d-------- C:\WINDOWS\ERUNT
2008-07-26 16:09 . 2008-07-26 17:26 4,274 --a------ C:\WINDOWS\system32\tmp.reg
2008-07-26 13:31 . 2008-07-26 13:31 <DIR> d-------- C:\Program Files\Yahoo!
2008-07-26 12:39 . 2008-07-26 12:39 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-07-26 12:39 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-07-26 12:33 . 2008-07-26 12:33 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-26 12:11 . 2001-10-25 14:00 4,224 --a------ C:\WINDOWS\system32\beep.sys
2008-07-26 12:10 . 2008-07-26 12:10 65,536 ---hs---- C:\Documents and Settings\Cermak\MediaTubeCodec_ver1.1463.0.exe
2008-07-03 07:37 . 2008-07-03 07:37 <DIR> d-------- C:\Program Files\Winamp Toolbar
2008-07-03 07:37 . 2008-07-06 20:08 <DIR> d-------- C:\Program Files\Winamp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-17 16:53 --------- d-----w C:\Program Files\ICQ6
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-18 21:02 --------- d-----w C:\Program Files\Skype
2008-06-18 21:02 --------- d-----w C:\Program Files\Common Files\Skype
2008-06-18 16:24 --------- d-----w C:\Program Files\uTorrent
2008-06-14 18:00 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-14 16:01 --------- d-----w C:\Program Files\PCDR5
2008-06-13 15:03 --------- d-----w C:\Program Files\Microcom
2008-06-13 12:50 --------- d-----w C:\Program Files\QuickTime
2008-06-13 12:49 --------- d-----w C:\Program Files\Ahead
2008-06-13 12:49 --------- d-----w C:\Program Files\ACE Mega CoDecS Pack
2008-06-13 12:48 --------- d-----w C:\Program Files\Common Files\Ahead
2008-06-13 12:46 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-13 12:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-13 12:40 --------- d-----w C:\Program Files\CyberLink
2008-06-13 12:39 --------- d-----w C:\Program Files\Apple Software Update
2008-06-13 12:34 --------- d-----w C:\Program Files\ESET
2008-06-13 12:32 --------- d-----w C:\Program Files\ACD Systems
2008-06-13 12:31 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-06-13 12:27 --------- d-----w C:\Program Files\Microsoft Works
2008-06-13 12:25 --------- d-----w C:\Program Files\Microsoft.NET
2008-06-13 12:20 17,801 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-06-13 12:19 --------- d-----w C:\Program Files\Synaptics
2008-06-13 12:18 --------- d-----w C:\Program Files\ATI Technologies
2008-06-13 12:17 0 ---ha-r C:\WINDOWS\system32\drivers\IBM_2373_HTG_TP.MRK
2008-06-13 12:17 --------- d-----w C:\Program Files\Lenovo
2008-06-13 12:02 --------- d-----w C:\Program Files\Common Files\Lenovo
2008-06-13 10:16 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-13 09:43 --------- d-----w C:\Program Files\NetWaiting
2008-06-13 09:43 --------- d-----w C:\Program Files\Digital Line Detect
2008-06-13 09:43 --------- d-----w C:\Program Files\CONEXANT
2008-06-13 09:42 --------- d-----w C:\Program Files\Intel
2008-06-13 09:38 --------- d-----w C:\Program Files\ThinkPad
2008-06-13 09:36 --------- d-----w C:\Program Files\IBM
2008-06-13 09:33 --------- d-----w C:\Program Files\Analog Devices
2008-06-13 09:20 --------- d-----w C:\Program Files\microsoft frontpage
.

((((((((((((((((((((((((((((( snapshot@2008-07-27_21.27.59.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\ERDNT\subs\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2008-03-20 00:36 1267040]

[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"frymxins"="C:\Program Files\ATI Technologies\Fire GL 3D Studio Max\atiimxgl" [X]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 09:11 1388544]
"BMMGAG"="C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2005-04-20 01:38 110592]
"BMMLREF"="C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE" [2005-04-20 01:38 20480]
"BMMMONWND"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2005-04-20 01:38 396288]
"BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-04-20 01:38 208896]
"TPKMAPHELPER"="C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" [2006-06-02 22:00 856064]
"TVT Scheduler Proxy"="C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 10:34 487424]
"TPHOTKEY"="C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-10-02 10:19 94208]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2007-02-06 21:00 344064]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2007-12-05 16:14 122880]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-05 16:14 524288]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2007-10-25 09:26 1410304]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24 32768]
"QuickTime Task"="C:\WINDOWS\system32\qttask.exe" [2008-06-13 14:50 98304]
"CnxDslTaskBar"="c:\program files\microcom\adsl deskporte usb\CnxDslTb.exe" [2004-06-16 07:55 233472]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-03-27 08:35 36352]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-17 15:49 110592 C:\WINDOWS\system32\bthprops.cpl]
"TpShocks"="TpShocks.exe" [2007-11-22 15:09 181536 C:\WINDOWS\system32\TpShocks.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 15:49 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-05 23:45 28672 C:\WINDOWS\system32\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-11-30 20:16 24576 C:\WINDOWS\system32\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.iac2"= C:\PROGRA~1\ACEMEG~1\SystemS\Intel\iac25_32.ax
"msacm.sl_anet"= C:\PROGRA~1\ACEMEG~1\SystemS\sl_anet.acm
"vidc.yv12"= C:\PROGRA~1\ACEMEG~1\SystemS\ATI\atiyuv12.DLL
"vidc.divx"= C:\PROGRA~1\ACEMEG~1\SystemS\DivX\DivX520.dll
"vidc.iyuv"= C:\PROGRA~1\ACEMEG~1\SystemS\Intel\iyuv_32.dll
"vidc.yvu9"= C:\PROGRA~1\ACEMEG~1\SystemS\Intel\Iyvu9_32.dll
"vidc.uyvy"= C:\PROGRA~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"vidc.yuy2"= C:\PROGRA~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"vidc.yvyu"= C:\PROGRA~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"msacm.msaudio1"= C:\PROGRA~1\ACEMEG~1\SystemS\MICROS~1\msaud32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 Shockprf;Shockprf;C:\WINDOWS\system32\DRIVERS\Apsx86.sys [2007-10-16 18:33]
R0 TPDIGIMN;TPDIGIMN;C:\WINDOWS\system32\DRIVERS\ApsHM86.sys [2007-10-16 18:32]
R1 TPPWR;TPPWR;C:\WINDOWS\system32\drivers\Tppwr.sys [2005-04-20 01:38]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-17 15:49]
R3 CnxEtP;Conexant AccessRunner USB ADSL Adapter Filter Driver;C:\WINDOWS\system32\DRIVERS\CnxEtP.sys [2004-06-16 07:51]
R3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;C:\WINDOWS\system32\DRIVERS\CnxEtU.sys [2004-06-16 07:51]
R3 CnxTgNP;Conexant AccessRunner ADSL WAN PPPoE Adapter Driver;C:\WINDOWS\system32\DRIVERS\CnxTgNP.sys [2004-06-16 07:51]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-07-26 12:39]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2008-07-26 C:\WINDOWS\Tasks\1-Click Maintenance.job - E:\tu\OneClick.exe [2008-04-16 09:59]
2008-06-13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]
2008-06-13 C:\WINDOWS\Tasks\BMMTask.job - C:\PROGRA~1\ThinkPad\UTILIT~1\BMMTASK.EXE [2005-04-20 01:38]
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-28 15:28:19
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\tphklock.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\system32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSvc.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Lenovo\System Update\SUService.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
.
**************************************************************************
.
Completion time: 2008-07-28 15:29:26 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-28 13:29:22
ComboFix2.txt 2008-07-27 19:28:12

Pre-Run: 8,384,786,432
Post-Run: 8,361,689,088

216 --- E O F --- 2008-07-16 22:37:36



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:33:42, on 28. 7. 2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Lenovo\System Update\SUService.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\qttask.exe
C:\program files\microcom\adsl deskporte usb\CnxDslTb.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
E:\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [frymxins] "C:\Program Files\ATI Technologies\Fire GL 3D Studio Max\atiimxgl"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CnxDslTaskBar] "c:\program files\microcom\adsl deskporte usb\CnxDslTb.exe" "Microcom\ADSL DeskPorte USB"
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\IBM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

--
End of file - 9345 bytes



thank you for helping. i couldnt do this operations alone. realy thanks a lot.
roman
bobcat61
Active Member
 
Posts: 9
Joined: July 26th, 2008, 8:13 am

Re: NEED HELP WITH RED Desktop {BIOHAZARD} - TROYAN and WORM

Unread postby random/random » July 28th, 2008, 10:24 am

Please do a scan with Kaspersky Online Scanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post, along with a new HijackThis log and a description of any remaining problems.
User avatar
random/random
Developer
Developer
 
Posts: 7733
Joined: December 18th, 2005, 3:30 pm

Re: NEED HELP WITH RED Desktop {BIOHAZARD} - TROYAN and WORM

Unread postby bobcat61 » July 28th, 2008, 5:58 pm

hello MRU Teacher,

i did Kaspersky scan. here are the logs:

KASPERSKY ONLINE SCANNER 7 REPORT
Monday, July 28, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, July 28, 2008 18:39:04
Records in database: 1021993
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\

Scan statistics:
Files scanned: 48993
Threat name: 2
Infected objects: 5
Suspicious objects: 0
Duration of the scan: 03:00:17


File name / Threat name / Threats count
C:\Documents and Settings\Cermak\Plocha\SmitfraudFix.exe Infected: Hoax.Win32.Renos.vaoz 2
C:\Documents and Settings\Cermak\Plocha\SmitfraudFix.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\WINDOWS\system32\IEDFix.C.exe Infected: Hoax.Win32.Renos.vaoz 1
C:\WINDOWS\system32\IEDFix.exe Infected: Hoax.Win32.Renos.vaoz 1

The selected area was scanned.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:57:16, on 28. 7. 2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINDOWS\system32\qttask.exe
C:\program files\microcom\adsl deskporte usb\CnxDslTb.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Lenovo\System Update\SUService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
E:\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [frymxins] "C:\Program Files\ATI Technologies\Fire GL 3D Studio Max\atiimxgl"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CnxDslTaskBar] "c:\program files\microcom\adsl deskporte usb\CnxDslTb.exe" "Microcom\ADSL DeskPorte USB"
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\IBM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

--
End of file - 9358 bytes


thank you. it looks it is infected. what do you think is good to do now?? thank you again.
roman
bobcat61
Active Member
 
Posts: 9
Joined: July 26th, 2008, 8:13 am
Advertisement
Register to Remove

Next

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 118 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware