![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Jul 2009
Posts: 14
OS: xp
|
Recurring Vundo Trojan
Hi, I'm using an xp machine, have McAfee and Malwarebytes. I use firefox as my browser. My problem is that when I run a search with either of the above programs I find 4 infected files, both scans claim to have deleted and removed them however upon rescanning they are still there. Malwarebytes labels all of these files as 'Trojan.Vundo.H'. The virus appears to be preventing windows from updating, as well as preventing updates on some of my other programs. Any help would be appreciated. Thanks.
DDS (Ver_09-06-26.01) - NTFSx86 Run by User at 13:02:08.64 on 03/07/2009 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_11 Microsoft Windows XP Home Edition 5.1.2600.2.1252.44.1033.18.447.215 [GMT 1:00] AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE svchost.exe C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\System32\PAStiSvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\Explorer.EXE C:\Program Files\QuickTime\qttask.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\WINDOWS\system32\atwtusb.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Multimedia Combo Set\MouseDrv.exe C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Electronic Arts\EADM\Core.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\Program Files\WiFiConnector\NintendoWFCReg.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Documents and Settings\User\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://www.google.com uWindow Title = Tiscali Internet Access uSearch Bar = hxxp://www.google.com/ie mDefault_Page_URL = hxxp://www.meshcomputers.com mDefault_Search_URL = hxxp://www.google.com/ie mWindow Title = Tiscali Internet Access uInternet Settings,ProxyServer = http=localhost:7171 uInternet Settings,ProxyOverride = *.local;<local> uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: : {e3b4ffe6-4204-4cc4-915d-3bd09c95175c} - c:\windows\system32\sllstwo.dll TB: FlashGet Bar: {e0e899ab-f487-11d5-8d29-0050ba6940e3} - c:\progra~1\flashget\fgiebar.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe mRun: [atwtusb] atwtusb.exe beta mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [WireLessMouse ] c:\program files\multimedia combo set\MouseDrv.exe mRun: [WireLessKeyboard ] c:\program files\multimedia combo set\PS2USBKbdDrv.exe mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\UdaterUI.exe" /StartedFromRunKey mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [<NO NAME>] dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE dRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe dRun: [dll32] dll32 StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\runnin~1.lnk - c:\program files\wificonnector\NintendoWFCReg.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE IE: Download All by FlashGet - c:\progra~1\flashget\jc_all.htm IE: Download using FlashGet - c:\progra~1\flashget\jc_link.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\progra~1\flashget\flashget.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - hxxp://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab32846.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} - hxxp://chat.msn.com/controls/msnchat45.cab DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab TCP: {51AE91DF-5F11-4628-9904-A77489B7A8CF} = 192.168.0.1 Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll Notify: ajhdivzd - sllstwo.dll AppInit_DLLs: c:\windows\system32\hibopiro.dll c:\windows\system32\dazeneho.dll c:\windows\system32\rokesoza.dll c:\windows\system32\rofazito.dll LSA: Notification Packages = scecli c:\windows\system32\hibopiro.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\dnmkxgqc.default\ FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\real\realone player\netscape6\nppl3260.dll FF - plugin: c:\program files\real\realone player\netscape6\nprjplug.dll FF - plugin: c:\program files\real\realone player\netscape6\nprpjplug.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} ---- FIREFOX POLICIES ---- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== R0 ypdsgotl;ypdsgotl;c:\windows\system32\drivers\ypdsgotl.sys [2005-9-9 23424] R1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2006-11-30 31944] R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-4-4 55152] R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2007-9-22 104000] R2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2006-11-30 144960] R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2006-11-30 54872] R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-1-14 226656] R3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2007-9-22 72264] R3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2007-9-22 34152] R3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2007-9-22 168776] R3 TNET1130;802.11 WLAN;c:\windows\system32\drivers\tnet1130.sys [2006-1-10 385536] S1 aiptektp;HyperPen;c:\windows\system32\drivers\aiptektp.sys [2006-1-10 22272] S3 cpuz;cpuz;\??\e:\cpuz.sys --> e:\cpuz.sys [?] S3 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2009-2-6 533360] S3 PAC207;SoC PC-Camer@;c:\windows\system32\drivers\PFC027.sys [2005-2-24 162176] S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [2006-11-16 87824] S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [2006-11-16 85696] S4 m5287;m5287;c:\windows\system32\drivers\m5287.sys [2005-11-25 85888] S4 m5289;m5289;c:\windows\system32\drivers\m5289.sys [2005-11-25 51840] =============== Created Last 30 ================ 2009-06-30 23:20 <DIR> --d----- c:\docume~1\user\applic~1\Malwarebytes 2009-06-30 23:20 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-30 23:20 19,096 a------- c:\windows\system32\drivers\mbam.sys 2009-06-30 23:20 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-06-30 23:20 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware 2009-06-30 00:12 131 a------- c:\windows\wininit.ini 2009-06-29 23:17 1 a------- c:\windows\934fdfg34fgjf23 ==================== Find3M ==================== 2009-07-03 13:02 109,308 a------- c:\windows\system32\drivers\8d89dc49.sys 2009-06-30 11:38 103,424 a------- c:\windows\system32\sllstwo.dll 2009-04-29 17:04 2,098 ---sh--- c:\windows\system32\besegopa.exe 2007-09-22 18:03 3,099,663 a------- c:\program files\uos-security-check_0015f2013aa2_1190480531.exe ============= FINISH: 13:03:21.07 =============== |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Registered User
Join Date: Jul 2009
Posts: 14
OS: xp
|
Re: Recurring Vundo Trojan
Right well, I'm going to be going away for the weekend so I wont be able to act on any advice I get until I get back on Sunday at 8 o clock (GMT). However I'd be grateful if somebody could look over my problem and give me the first step so I can do it as soon as I get back.
|
|
|
|
|
#3 (permalink) |
|
Moderator, Analyst, Security Team
Join Date: Oct 2006
Location: Důn Čideann,Scotland.
Posts: 5,093
OS: XP
|
Re: Recurring Vundo Trojan
Hello and welcome to TSF
Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe. ======== Please follow all instructions and in which order they come, if you have any questions, please ask before proceeding. Its important that you follow this through until i give you the all clear. Please DO NOT Attach logs to your posts unless you are advised to do so. ========= Download ComboFix from one of these locations: Link 1 Link 2 Link 3 * IMPORTANT !!! Place combofix.exe on your Desktop Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix. Double click on combofix.exe & follow the prompts. As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. ![]() The Windows recovery console will allow you to boot up into a special recovery mode that allows us to help you in the case that your computer has a problem after an attempted removal of malware. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement. ComboFix will now automatically install the Microsoft Windows Recovery Console onto your computer, which will show up as a new option when booting up your computer. Do not select the Microsoft Windows Recovery Console option when you start your computer unless requested to by a helper. Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see a message that says: The Recovery Console was successfully installed. ![]() Click on Yes, to continue scanning for malware. Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal. When finished, it shall produce a log for you. Post that log in your next reply Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall. Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed. |
|
|
|
|
#4 (permalink) |
|
Registered User
Join Date: Jul 2009
Posts: 14
OS: xp
|
Re: Recurring Vundo Trojan
I have completed the scan, the log file is as follows.
ComboFix 09-07-04.09 - User 05/07/2009 19:43.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.44.1033.18.447.223 [GMT 1:00] Running from: c:\documents and settings\User\Desktop\ComboFix.exe AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0} * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\-1333272000 c:\recycler\S-1-5-21-3290155749-1650567868-3821821243-1003 c:\windows\Installer\WinRMSrv.msi c:\windows\system32\drivers\kjcfdgdu.sys c:\windows\system32\drivers\ypdsgotl.sys c:\windows\system32\kaksldwx.dll c:\windows\system32\liwoduki.exe c:\windows\system32\qekyfdu.dll c:\windows\system32\sllstwo.dll c:\windows\Tasks\At1.job c:\windows\system32\drivers\8d89dc49.sys . . . . failed to delete . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_ypdsgotl -------\Service_ypdsgotl -------\Service_8d89dc49 ((((((((((((((((((((((((( Files Created from 2009-06-05 to 2009-07-05 ))))))))))))))))))))))))))))))) . 2009-06-30 22:20 . 2009-06-30 22:20 -------- d-----w- c:\documents and settings\User\Application Data\Malwarebytes 2009-06-30 22:20 . 2009-06-17 10:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-30 22:20 . 2009-06-30 22:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-06-30 22:20 . 2009-06-17 10:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-30 22:20 . 2009-06-30 22:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-29 22:58 . 2009-06-29 23:01 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-05 18:56 . 2009-04-28 22:02 109308 ----a-w- c:\windows\system32\drivers\8d89dc49.sys 2009-07-05 18:06 . 2008-08-10 19:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2009-07-02 22:05 . 2006-01-10 19:54 -------- d-----w- c:\program files\Guild Wars 2009-07-02 22:03 . 2005-11-25 09:17 -------- d-----w- c:\program files\CyberLink 2009-07-02 22:03 . 2005-11-25 09:17 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-07-02 19:44 . 2006-07-19 19:45 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-07-02 19:41 . 2006-07-19 19:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-07-01 18:56 . 2006-11-16 18:47 -------- d-----w- c:\program files\Common Files\Teleca Shared 2009-06-29 23:01 . 2006-07-19 19:44 -------- d-----w- c:\program files\SpywareBlaster 2009-05-14 22:37 . 2006-01-10 19:28 38552 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-04-29 16:04 . 2009-04-29 16:04 2098 --sh--w- c:\windows\system32\besegopa.exe 2007-09-22 17:03 . 2007-09-22 17:03 3099663 ----a-w- c:\program files\uos-security-check_0015f2013aa2_1190480531.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-22 68856] "EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-04-29 3338240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-11-25 98304] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-10-10 7286784] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-10-10 86016] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-13 136600] "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-02-03 180269] "WireLessMouse "="c:\program files\Multimedia Combo Set\MouseDrv.exe" [2004-06-27 503808] "WireLessKeyboard "="c:\program files\Multimedia Combo Set\PS2USBKbdDrv.exe" [2004-07-01 80896] "McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768] "ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 112216] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "Ptipbmf"="ptipbmf.dll" - c:\windows\system32\ptipbmf.dll [2003-06-20 118784] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-10-10 1519616] "High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2004-10-27 61952] "atwtusb"="atwtusb.exe" - c:\windows\system32\atwtusb.exe [2005-03-09 290816] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "dll32"="dll32" [X] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-22 68856] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588] Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2007-12-12 1073152] WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2006-1-12 118784] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\CyberLink\\PowerCinema\\PowerCinema.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaw.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\THQ\\Dawn Of War\\W40kWA.exe"= "c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"= "c:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"= "c:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"= "c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"= "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"= "c:\\Program Files\\Wizards of the Coast\\Magic Online III\\Renamer.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "6112:UDP"= 6112:UDP:dow6112 "6500:UDP"= 6500:UDP:dow6500 "27900:UDP"= 27900:UDP:dow27900 "27901:UDP"= 27901:UDP:dow27901 "28910:TCP"= 28910:TCP:dow28910 "29900:TCP"= 29900:TCP:dow29900 "29901:TCP"= 29901:TCP:dow29901 "29910:UDP"= 29910:UDP:dow29910 "29920:TCP"= 29920:TCP:dow29920 R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [04/04/2009 00:44 55152] R3 TNET1130;802.11 WLAN;c:\windows\system32\drivers\tnet1130.sys [10/01/2006 20:03 385536] S1 aiptektp;HyperPen;c:\windows\system32\drivers\aiptektp.sys [10/01/2006 19:44 22272] S3 cpuz;cpuz;\??\e:\cpuz.sys --> e:\cpuz.sys [?] S3 PAC207;SoC PC-Camer@;c:\windows\system32\drivers\PFC027.sys [24/02/2005 13:29 162176] S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [16/11/2006 19:54 87824] S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [16/11/2006 19:54 85696] S4 m5287;m5287;c:\windows\system32\drivers\m5287.sys [25/11/2005 17:44 85888] S4 m5289;m5289;c:\windows\system32\drivers\m5289.sys [25/11/2005 17:44 51840] --- Other Services/Drivers In Memory --- *NewlyCreated* - YPDSGOTL *Deregistered* - ypdsgotl HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs lyxulsbp . Contents of the 'Scheduled Tasks' folder 2009-07-05 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-14 22:43] . - - - - ORPHANS REMOVED - - - - HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Search_URL = hxxp://www.google.com/ie mWindow Title = Tiscali Internet Access uInternet Settings,ProxyServer = http=localhost:7171 uInternet Settings,ProxyOverride = *.local;<local> uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie IE: Download All by FlashGet - c:\progra~1\FlashGet\jc_all.htm IE: Download using FlashGet - c:\progra~1\FlashGet\jc_link.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 TCP: {51AE91DF-5F11-4628-9904-A77489B7A8CF} = 192.168.0.1 DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\dnmkxgqc.default\ FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} ---- FIREFOX POLICIES ---- FF - user.js: yahoo.homepage.dontask - true. ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-05 19:52 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\8d89dc49] "ImagePath"="\SystemRoot\System32\drivers\8d89dc49.sys" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\s-1-5-21-732552938-1092693543-720440500-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:ec,16,b4,c0,b6,ee,4e,2e,4a,e0,68,14,b3,dd,c0,e0,ec,21,a9,95,36,83,65, 76,16,1a,00,03,f2,cb,96,c1,53,18,44,16,41,eb,a0,99,e6,62,15,59,1d,5d,a9,7b,\ "??"=hex:3f,eb,b2,a8,d5,51,4b,c2,1b,01,ec,08,0f,18,11,95 [HKEY_USERS\s-1-5-21-732552938-1092693543-720440500-1006\Software\SecuROM\License information*] "datasecu"=hex:9a,d5,f3,33,92,e0,11,05,3f,cd,36,e6,a1,82,37,fa,06,63,c9,77,aa, cd,24,dc,44,2f,cb,5b,a5,ad,6c,e2,94,e7,24,0f,c9,c8,fd,2b,6d,8f,06,b7,56,ee,\ "rkeysecu"=hex:e2,26,6d,94,9c,ba,ad,1d,64,79,70,1b,d8,19,de,23 . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\LEXBCES.EXE c:\windows\system32\LEXPPS.EXE c:\program files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe c:\program files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\McAfee\Common Framework\FrameworkService.exe c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe c:\windows\system32\nvsvc32.exe c:\program files\McAfee\Common Framework\naPrdMgr.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\windows\system32\PAStiSvc.exe c:\windows\system32\wdfmgr.exe c:\program files\McAfee\Common Framework\Mctray.exe c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe . ************************************************************************** . Completion time: 2009-07-05 20:02 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-05 19:02 Pre-Run: 130,620,329,984 bytes free Post-Run: 131,146,383,360 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4 217 --- E O F --- 2009-04-20 02:10 I dont know if it matters seen as the log file was created anyway, but after combofix restarted my computer when the window was displaying that a log file was being generated and instructed me not to run any programs, a number of programs that load on startup such as McAfee (which I'd disabled before the scan/restart) loaded themselves, I just wanted to be sure that this couldn't influence the results. Thanks for your time. |
|
|
|
|
#5 (permalink) | |
|
Moderator, Analyst, Security Team
Join Date: Oct 2006
Location: Důn Čideann,Scotland.
Posts: 5,093
OS: XP
|
Re: Recurring Vundo Trojan
Hello again
Please follow all instructions and in which order they come, if you have any questions, please ask before proceeding. Its important that you follow this through until i give you the all clear. ======== Quote:
======= P2P P2P - I see you have P2P software (Azureus) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information. Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares and their infections. References for the risk of these programs are Here, Here and Here. ======== Open notepad and copy/paste the text in the quotebox below into it: Code:
http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/391391-recurring-vundo-trojan.html Collect:: c:\windows\system32\besegopa.exe File:: c:\windows\system32\drivers\8d89dc49.sys FileLook:: c:\program files\uos-security-check_0015f2013aa2_1190480531.exe NetSvc:: lyxulsbp DDS:: uInternet Settings,ProxyServer = http=localhost:7171 uInternet Settings,ProxyOverride = *.local;<local> Registry:: [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\8d89dc49] AtJob:: ![]() Refering to the picture above, drag CFscript into ComboFix.exe Follow the prompts, and post the resulting log, C:\ComboFix.txt Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system. Warning: Do not mouseclick combofix's window whilst it's running. That may cause it to stall When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture a file to submit for analysis. Ensure you are connected to the internet and click OK. A browser will open. Simply follow the instructions to copy/paste/send the requested file(s). ======= JAVA OUTDATED Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
======== Download ATF-Cleaner by Atribune to your desktop. Double-click ATF Cleaner.exe to open it Under Main choose: Windows Temp Current User Temp All Users Temp Cookies Temporary Internet Files Prefetch Java Cache *The other boxes are optional* Then click the Empty Selected button. If you have Firefox installed: Click Firefox at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click NO at the prompt. If you have Opera installed: Click Opera at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click NO at the prompt. Click Exit on the Main menu to close the program. ========= Establish an internet connection & perform an online scan with Internet Explorer at Kaspersky Online Scanner Click Accept, when prompted to download and install the program files and database of malware definitions.
This animation will guide you through the process: ![]() To optimize scanning time and produce a more sensible report for review:
========= Logs Required C:\Combofix.txt Kaspersky Scan Report An update on how your system is running. |
|
|
|
|
|
#6 (permalink) |
|
Registered User
Join Date: Jul 2009
Posts: 14
OS: xp
|
Re: Recurring Vundo Trojan
Hello again, just got finished doing those things you asked me to, also deleted Azureus for good measure considering I hadn't used it in an age anyway. As for how my machine is running in general, it seems a fair bit faster, the windows automatic update system is prompting me to update again and I am able to download said updates, and the other programs which couldn't update are not able to. Anyway, here are the logs you asked for.
The combofix log is as follows: ComboFix 09-07-05.01 - User 05/07/2009 22:09.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.44.1033.18.447.210 [GMT 1:00] Running from: c:\documents and settings\User\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\User\Desktop\CFscript.txt AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0} FILE :: "c:\windows\system32\drivers\8d89dc49.sys" file zipped: c:\windows\system32\besegopa.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\besegopa.exe c:\windows\system32\drivers\8d89dc49.sys . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_8d89dc49 ((((((((((((((((((((((((( Files Created from 2009-06-05 to 2009-07-05 ))))))))))))))))))))))))))))))) . 2009-06-30 22:20 . 2009-06-30 22:20 -------- d-----w- c:\documents and settings\User\Application Data\Malwarebytes 2009-06-30 22:20 . 2009-06-17 10:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-30 22:20 . 2009-06-30 22:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-06-30 22:20 . 2009-06-17 10:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-30 22:20 . 2009-06-30 22:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-29 22:58 . 2009-06-29 23:01 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-05 21:01 . 2005-11-25 09:17 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-07-05 21:01 . 2005-11-25 09:17 -------- d-----w- c:\program files\CyberLink 2009-07-05 20:59 . 2006-01-12 20:16 -------- d-----w- c:\program files\Azureus 2009-07-05 18:06 . 2008-08-10 19:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2009-07-02 22:05 . 2006-01-10 19:54 -------- d-----w- c:\program files\Guild Wars 2009-07-02 19:44 . 2006-07-19 19:45 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-07-02 19:41 . 2006-07-19 19:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-07-01 18:56 . 2006-11-16 18:47 -------- d-----w- c:\program files\Common Files\Teleca Shared 2009-06-29 23:01 . 2006-07-19 19:44 -------- d-----w- c:\program files\SpywareBlaster 2009-05-14 22:37 . 2006-01-10 19:28 38552 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2007-09-22 17:03 . 2007-09-22 17:03 3099663 ----a-w- c:\program files\uos-security-check_0015f2013aa2_1190480531.exe . (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . --- c:\program files\uos-security-check_0015f2013aa2_1190480531.exe --- Company: File Description: File Version: Product Name: Copyright: Original Filename: File size: 3099663 Created time: 2007-09-22 17:03 Modified time: 2007-09-22 17:03 MD5: C79A9D2001E09E32D822B5537D79484B SHA1: 569B8739863F6EFCDD1E3BAE60C727DFF0AB87F9 ((((((((((((((((((((((((((((( SnapShot@2009-07-05_18.54.32 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-05 21:18 . 2009-07-05 21:18 16384 c:\windows\Temp\Perflib_Perfdata_20c.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-22 68856] "EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-04-29 3338240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-11-25 98304] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-10-10 7286784] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-10-10 86016] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-13 136600] "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-02-03 180269] "WireLessMouse "="c:\program files\Multimedia Combo Set\MouseDrv.exe" [2004-06-27 503808] "WireLessKeyboard "="c:\program files\Multimedia Combo Set\PS2USBKbdDrv.exe" [2004-07-01 80896] "McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768] "ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 112216] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "Ptipbmf"="ptipbmf.dll" - c:\windows\system32\ptipbmf.dll [2003-06-20 118784] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-10-10 1519616] "High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2004-10-27 61952] "atwtusb"="atwtusb.exe" - c:\windows\system32\atwtusb.exe [2005-03-09 290816] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "dll32"="dll32" [X] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-22 68856] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588] Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2007-12-12 1073152] WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2006-1-12 118784] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\CyberLink\\PowerCinema\\PowerCinema.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaw.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\THQ\\Dawn Of War\\W40kWA.exe"= "c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"= "c:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"= "c:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"= "c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"= "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"= "c:\\Program Files\\Wizards of the Coast\\Magic Online III\\Renamer.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "6112:UDP"= 6112:UDP:dow6112 "6500:UDP"= 6500:UDP:dow6500 "27900:UDP"= 27900:UDP:dow27900 "27901:UDP"= 27901:UDP:dow27901 "28910:TCP"= 28910:TCP:dow28910 "29900:TCP"= 29900:TCP:dow29900 "29901:TCP"= 29901:TCP:dow29901 "29910:UDP"= 29910:UDP:dow29910 "29920:TCP"= 29920:TCP:dow29920 R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [04/04/2009 00:44 55152] R3 TNET1130;802.11 WLAN;c:\windows\system32\drivers\tnet1130.sys [10/01/2006 20:03 385536] S1 aiptektp;HyperPen;c:\windows\system32\drivers\aiptektp.sys [10/01/2006 19:44 22272] S3 cpuz;cpuz;\??\e:\cpuz.sys --> e:\cpuz.sys [?] S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 18:08 533360] S3 PAC207;SoC PC-Camer@;c:\windows\system32\drivers\PFC027.sys [24/02/2005 13:29 162176] S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [16/11/2006 19:54 87824] S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [16/11/2006 19:54 85696] S4 m5287;m5287;c:\windows\system32\drivers\m5287.sys [25/11/2005 17:44 85888] S4 m5289;m5289;c:\windows\system32\drivers\m5289.sys [25/11/2005 17:44 51840] . Contents of the 'Scheduled Tasks' folder 2009-07-05 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-14 22:43] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Search_URL = hxxp://www.google.com/ie mWindow Title = Tiscali Internet Access uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie IE: Download All by FlashGet - c:\progra~1\FlashGet\jc_all.htm IE: Download using FlashGet - c:\progra~1\FlashGet\jc_link.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 TCP: {51AE91DF-5F11-4628-9904-A77489B7A8CF} = 192.168.0.1 DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\dnmkxgqc.default\ FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} ---- FIREFOX POLICIES ---- FF - user.js: yahoo.homepage.dontask - true. ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-05 22:20 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-732552938-1092693543-720440500-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:ec,16,b4,c0,b6,ee,4e,2e,4a,e0,68,14,b3,dd,c0,e0,ec,21,a9,95,36,83,65, 76,16,1a,00,03,f2,cb,96,c1,53,18,44,16,41,eb,a0,99,e6,62,15,59,1d,5d,a9,7b,\ "??"=hex:3f,eb,b2,a8,d5,51,4b,c2,1b,01,ec,08,0f,18,11,95 [HKEY_USERS\S-1-5-21-732552938-1092693543-720440500-1006\Software\SecuROM\License information*] "datasecu"=hex:9a,d5,f3,33,92,e0,11,05,3f,cd,36,e6,a1,82,37,fa,06,63,c9,77,aa, cd,24,dc,44,2f,cb,5b,a5,ad,6c,e2,94,e7,24,0f,c9,c8,fd,2b,6d,8f,06,b7,56,ee,\ "rkeysecu"=hex:e2,26,6d,94,9c,ba,ad,1d,64,79,70,1b,d8,19,de,23 . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\LEXBCES.EXE c:\windows\system32\LEXPPS.EXE c:\program files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe c:\program files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\McAfee\Common Framework\FrameworkService.exe c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe c:\windows\system32\nvsvc32.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\windows\system32\PAStiSvc.exe c:\windows\system32\wdfmgr.exe c:\program files\McAfee\Common Framework\naPrdMgr.exe c:\program files\McAfee\Common Framework\Mctray.exe c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe . ************************************************************************** . Completion time: 2009-07-05 22:32 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-05 21:32 ComboFix2.txt 2009-07-05 19:02 Pre-Run: 131,342,946,304 bytes free Post-Run: 131,356,233,728 bytes free Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4 209 --- E O F --- 2009-04-20 02:10 The Kaspersky scan log is as follows: -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0 REPORT Monday, July 6, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Sunday, July 05, 2009 21:12:41 Records in database: 2430157 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Files scanned: 80018 Threat name: 4 Infected objects: 14 Suspicious objects: 0 Duration of the scan: 02:08:52 File name / Threat name / Threats count C:\Program Files\Common Files\Real\Toolbar\RealBar.dll Infected: not-a-virus:AdWare.Win32.MegaSearch.s 1 C:\Program Files\RealVNC\VNC4\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1 C:\Program Files\RealVNC\VNC4\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1 C:\Program Files\RealVNC\VNC4\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1 C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\8d89dc49.sys.vir Infected: Backdoor.Win32.NewRest.z 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_8d89dc49_.sys.zip Infected: Backdoor.Win32.NewRest.z 6 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_ypdsgotl_.sys.zip Infected: Trojan.Win32.BHO.ext 1 C:\System Volume Information\_restore{54C7A4C0-672A-400F-89D3-264781F4E928}\RP20\A0008285.sys Infected: Backdoor.Win32.NewRest.z 1 The selected area was scanned. |
|
|
|
|
#7 (permalink) |
|
Moderator, Analyst, Security Team
Join Date: Oct 2006
Location: Důn Čideann,Scotland.
Posts: 5,093
OS: XP
|
Re: Recurring Vundo Trojan
Hello again
When Combofix was finished it should have requested you to uploaded a file. Since that file was not uploaded automatically, we`ll uploaded it manually. Please go to this website: http://www.bleepingcomputer.com/subm....php?channel=4 Locate this file: C:\QooBox\Quarantine\[4]-Submit_2009-xx-xx@xx.xx.zip Included this link into your submission: http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/391391-recurring-vundo-trojan.html Let me know once this has been completed. |
|
|
|
|
#9 (permalink) |
|
Moderator, Analyst, Security Team
Join Date: Oct 2006
Location: Důn Čideann,Scotland.
Posts: 5,093
OS: XP
|
Re: Recurring Vundo Trojan
Hello again
File uploaded successfully, thanks. Kaspersky found infected files in Combofix`s quarantine folder and System Volume Information folder, both of these folders will be removed before we have concluded. However, Kaspersky detected RealVNC which is a legitmate application, i believe from your logs that you no longer have this installed. I shall remove the RealVNC folder during this fix, if on the other hand you still have RealVNC installed, please let me know before you carry on, i can edit out that folder if need be. ========= Open notepad and copy/paste the text in the quotebox below into it: Code:
Folder:: c:\program files\Azureus c:\Program Files\Java\jre1.5.0_06 C:\Program Files\RealVNC File:: c:\program files\uos-security-check_0015f2013aa2_1190480531.exe C:\Program Files\Common Files\Real\Toolbar\RealBar.dll Registry:: [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "dll32"=- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaw.exe"=- ![]() Refering to the picture above, drag CFscript into ComboFix.exe Follow the prompts, and post the resulting log, C:\ComboFix.txt Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system. Warning: Do not mouseclick combofix's window whilst it's running. That may cause it to stall ======== You don't seem to have a firewall program installed. Using a firewall will allow you to give/deny access for applications that want to go online. Select one of these, or another of your choice: ======== Log Required C:\Combofix.txt |
|
|
|
|
#10 (permalink) |
|
Registered User
Join Date: Jul 2009
Posts: 14
OS: xp
|
Re: Recurring Vundo Trojan
Hello, I've done that step, here's the log, it was suprisingly huge. So I'm going to have to post it in a series of chunks. Sorry for any inconvenience.
EDIT- upon closer inspection of what its given me, it appears one of the windows updates the system did when it regained its ability to do so was a service pack, and the mass of this log is just combofix reporting what the service pack changed. ComboFix 09-07-05.04 - User 06/07/2009 13:28.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.447.192 [GMT 1:00] Running from: c:\documents and settings\User\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\User\Desktop\CFscript.txt AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0} FW: PC Tools Firewall Plus *enabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52} * Resident AV is active FILE :: "c:\program files\Common Files\Real\Toolbar\RealBar.dll" "c:\program files\uos-security-check_0015f2013aa2_1190480531.exe" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\Azureus c:\program files\Azureus\plugins\azplugins\azplugins_1.8.8.jar c:\program files\Azureus\plugins\azupdater\azupdater_1.8.3.zip c:\program files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.3.jar c:\program files\Azureus\plugins\azupdater\Azureus2_2.3.0.6_P2.pax c:\program files\Azureus\plugins\azupdater\plugin.properties_1.8.3 c:\program files\Azureus\plugins\azupdater\Updater.jar.bak c:\program files\Azureus\Uninstall.exe c:\program files\Common Files\Real\Toolbar\RealBar.dll c:\program files\RealVNC c:\program files\RealVNC\VNC4\logmessages.dll c:\program files\RealVNC\VNC4\unins000.dat c:\program files\RealVNC\VNC4\unins000.exe c:\program files\RealVNC\VNC4\vncconfig.exe c:\program files\RealVNC\VNC4\vncviewer.exe c:\program files\RealVNC\VNC4\winvnc4.exe c:\program files\RealVNC\VNC4\wm_hooks.dll c:\program files\uos-security-check_0015f2013aa2_1190480531.exe . ((((((((((((((((((((((((( Files Created from 2009-06-06 to 2009-07-06 ))))))))))))))))))))))))))))))) . 2009-07-06 12:22 . 2009-03-06 15:45 130424 ----a-w- c:\windows\system32\drivers\PCTCore.sys 2009-07-06 12:22 . 2008-12-18 11:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys 2009-07-06 12:22 . 2008-12-11 07:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys 2009-07-06 12:20 . 2009-07-06 12:20 -------- d-----w- c:\windows\LastGood 2009-07-06 12:19 . 2009-07-06 12:22 -------- d-----w- c:\program files\Common Files\PC Tools 2009-07-06 12:19 . 2008-09-22 10:29 97408 ----a-w- c:\windows\system32\drivers\pctfw.sys 2009-07-06 12:19 . 2009-01-21 08:38 95640 ----a-w- c:\windows\system32\drivers\pctplfw.sys 2009-07-06 12:19 . 2009-07-06 12:22 -------- d-----w- c:\program files\PC Tools Firewall Plus 2009-07-06 01:34 . 2009-07-06 01:34 -------- d-----w- c:\windows\LastGood.Tmp 2009-07-06 01:30 . 2009-07-06 01:30 -------- d-----w- c:\windows\system32\scripting 2009-07-06 01:30 . 2009-07-06 01:30 -------- d-----w- c:\windows\l2schemas 2009-07-06 01:30 . 2009-07-06 01:30 -------- d-----w- c:\windows\system32\en 2009-07-06 01:30 . 2009-07-06 01:30 -------- d-----w- c:\windows\system32\bits 2009-07-06 01:26 . 2009-07-06 01:30 -------- d-----w- c:\windows\ServicePackFiles 2009-07-05 21:59 . 2009-07-05 21:59 -------- d-----w- c:\program files\Java 2009-06-30 22:20 . 2009-06-30 22:20 -------- d-----w- c:\documents and settings\User\Application Data\Malwarebytes 2009-06-30 22:20 . 2009-06-17 10:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-30 22:20 . 2009-06-30 22:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-06-30 22:20 . 2009-06-17 10:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-30 22:20 . 2009-06-30 22:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-29 22:58 . 2009-07-06 12:22 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-06 02:05 . 2006-06-28 10:31 96384 ----a-w- c:\windows\system32\drivers\sptd8093.sys 2009-07-06 01:33 . 2005-11-25 09:00 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-07-05 22:00 . 2009-03-13 22:38 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-07-05 21:01 . 2005-11-25 09:17 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-07-05 21:01 . 2005-11-25 09:17 -------- d-----w- c:\program files\CyberLink 2009-07-05 18:06 . 2008-08-10 19:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2009-07-02 22:05 . 2006-01-10 19:54 -------- d-----w- c:\program files\Guild Wars 2009-07-02 19:44 . 2006-07-19 19:45 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-07-02 19:41 . 2006-07-19 19:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-07-01 18:56 . 2006-11-16 18:47 -------- d-----w- c:\program files\Common Files\Teleca Shared 2009-06-29 23:01 . 2006-07-19 19:44 -------- d-----w- c:\program files\SpywareBlaster 2009-05-14 22:37 . 2006-01-10 19:28 38552 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-07 15:32 . 2005-09-09 22:03 345600 ----a-w- c:\windows\system32\localspl.dll 2009-04-29 04:46 . 2005-09-09 22:03 666624 ----a-w- c:\windows\system32\wininet.dll 2009-04-29 04:46 . 2005-09-09 22:03 81920 ----a-w- c:\windows\system32\ieencode.dll 2009-04-17 12:26 . 2005-09-09 22:03 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:51 . 2005-09-09 22:03 585216 ----a-w- c:\windows\system32\rpcrt4.dll . ((((((((((((((((((((((((((((( SnapShot@2009-07-05_18.54.32 ))))))))))))))))))))))))))))))))))))))))) . + 2008-09-08 22:51 . 2008-04-14 00:12 57344 c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcirt.dll - 2007-02-18 19:15 . 2007-01-19 20:15 74802 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll + 2008-09-08 22:51 . 2008-04-14 00:12 74802 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll - 2005-09-09 22:03 . 2004-08-04 12:00 50688 c:\windows\twain_32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 50688 c:\windows\twain_32.dll + 2009-07-06 02:07 . 2009-07-06 02:07 16384 c:\windows\Temp\Perflib_Perfdata_2b0.dat - 2005-11-25 08:58 . 2006-03-01 19:42 11776 c:\windows\system32\xolehlp.dll + 2005-11-25 08:58 . 2008-04-14 00:12 11776 c:\windows\system32\xolehlp.dll - 2005-09-09 22:03 . 2004-08-04 12:00 50176 c:\windows\system32\xmlprovi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 50176 c:\windows\system32\xmlprovi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 30720 c:\windows\system32\xcopy.exe - 2005-09-09 22:03 . 2004-08-04 12:00 30720 c:\windows\system32\xcopy.exe - 2005-09-09 22:03 . 2004-08-04 12:00 91648 c:\windows\system32\xactsrv.dll + 2005-09-09 22:03 . 2008-04-14 00:12 91648 c:\windows\system32\xactsrv.dll + 2004-08-04 00:56 . 2008-04-14 00:12 52736 c:\windows\system32\wzcsapi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 18432 c:\windows\system32\wtsapi32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 18432 c:\windows\system32\wtsapi32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 50688 c:\windows\system32\wstdecod.dll + 2005-09-09 22:03 . 2008-04-14 00:12 50688 c:\windows\system32\wstdecod.dll + 2005-09-09 22:03 . 2008-04-14 00:12 22528 c:\windows\system32\wsock32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 22528 c:\windows\system32\wsock32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 41984 c:\windows\system32\wsnmp32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 19456 c:\windows\system32\wshtcpip.dll + 2005-09-09 22:03 . 2008-04-14 00:12 11264 c:\windows\system32\wshrm.dll + 2005-09-09 22:03 . 2008-04-14 00:12 14336 c:\windows\system32\wship6.dll - 2005-09-09 22:03 . 2004-08-04 12:00 14336 c:\windows\system32\wship6.dll + 2005-09-09 22:03 . 2008-04-14 00:12 90112 c:\windows\system32\wshext.dll + 2005-09-09 22:03 . 2008-04-14 00:12 36864 c:\windows\system32\wshcon.dll + 2005-09-09 22:03 . 2008-04-14 00:12 80896 c:\windows\system32\wscsvc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 13824 c:\windows\system32\wscntfy.exe - 2005-09-09 22:03 . 2004-08-04 12:00 13824 c:\windows\system32\wscntfy.exe - 2005-09-09 22:03 . 2004-08-04 12:00 19968 c:\windows\system32\ws2help.dll + 2005-09-09 22:03 . 2008-04-14 00:12 19968 c:\windows\system32\ws2help.dll + 2005-09-09 22:03 . 2008-04-14 00:12 82432 c:\windows\system32\ws2_32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 11264 c:\windows\system32\wpnpinst.exe + 2005-09-09 22:03 . 2008-04-14 00:12 32256 c:\windows\system32\wpabaln.exe - 2005-09-09 22:03 . 2004-08-04 12:00 32256 c:\windows\system32\wpabaln.exe + 2005-09-09 22:03 . 2008-04-14 00:12 92672 c:\windows\system32\wlnotify.dll - 2005-09-09 22:03 . 2004-08-04 12:00 92672 c:\windows\system32\wlnotify.dll + 2008-09-08 22:54 . 2008-04-14 00:12 69120 c:\windows\system32\wlanapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 53760 c:\windows\system32\winsta.dll + 2005-09-09 22:03 . 2008-04-14 00:12 53760 c:\windows\system32\winsta.dll - 2005-09-09 22:03 . 2004-08-04 12:00 17408 c:\windows\system32\winshfhc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 17408 c:\windows\system32\winshfhc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 99328 c:\windows\system32\winscard.dll + 2005-09-09 22:03 . 2008-04-14 00:12 99328 c:\windows\system32\winscard.dll - 2005-09-09 22:03 . 2004-08-04 12:00 16896 c:\windows\system32\winrnr.dll + 2005-09-09 22:03 . 2008-04-14 00:12 16896 c:\windows\system32\winrnr.dll + 2005-09-09 22:03 . 2008-04-14 00:12 32256 c:\windows\system32\winipsec.dll + 2005-09-09 22:03 . 2008-04-14 00:12 75776 c:\windows\system32\wiascr.dll - 2005-09-09 22:03 . 2004-08-04 12:00 75776 c:\windows\system32\wiascr.dll + 2005-09-09 22:03 . 2008-04-14 00:12 65024 c:\windows\system32\wextract.exe - 2005-09-09 22:03 . 2006-01-04 03:35 68096 c:\windows\system32\webclnt.dll + 2005-09-09 22:03 . 2008-04-14 00:12 68096 c:\windows\system32\webclnt.dll + 2004-08-04 00:56 . 2008-04-14 00:12 23552 c:\windows\system32\wdmaud.drv - 2004-08-04 00:56 . 2004-08-04 12:00 23552 c:\windows\system32\wdmaud.drv - 2005-09-09 22:03 . 2004-08-04 12:00 49152 c:\windows\system32\wdigest.dll + 2005-09-09 22:03 . 2008-04-14 00:12 49152 c:\windows\system32\wdigest.dll + 2005-11-25 08:58 . 2008-04-14 00:12 95232 c:\windows\system32\wbem\wmiutils.dll - 2005-11-25 08:58 . 2004-08-04 12:00 95232 c:\windows\system32\wbem\wmiutils.dll - 2005-11-25 08:58 . 2004-08-04 12:00 41472 c:\windows\system32\wbem\wmipsess.dll + 2005-11-25 08:58 . 2008-04-14 00:12 41472 c:\windows\system32\wbem\wmipsess.dll + 2005-11-25 08:58 . 2008-04-14 00:12 62464 c:\windows\system32\wbem\wmipjobj.dll + 2005-11-25 08:58 . 2008-04-14 00:12 61952 c:\windows\system32\wbem\wmipiprt.dll + 2005-11-25 08:58 . 2008-04-14 00:12 60928 c:\windows\system32\wbem\wmicookr.dll - 2005-11-25 08:58 . 2004-08-04 12:00 60928 c:\windows\system32\wbem\wmicookr.dll + 2005-11-25 08:58 . 2008-04-14 00:12 88576 c:\windows\system32\wbem\wmiaprpl.dll + 2005-11-25 08:58 . 2008-04-14 00:12 43520 c:\windows\system32\wbem\wbemsvc.dll - 2005-11-25 08:58 . 2004-08-04 12:00 43520 c:\windows\system32\wbem\wbemsvc.dll - 2005-11-25 08:58 . 2004-08-04 12:00 18944 c:\windows\system32\wbem\wbemprox.dll + 2005-11-25 08:58 . 2008-04-14 00:12 18944 c:\windows\system32\wbem\wbemprox.dll + 2005-09-09 22:03 . 2008-04-14 00:12 43008 c:\windows\system32\wbem\wbemperf.dll - 2005-09-09 22:03 . 2004-08-04 12:00 43008 c:\windows\system32\wbem\wbemperf.dll + 2005-11-25 08:58 . 2008-04-14 00:12 71680 c:\windows\system32\wbem\wbemcons.dll - 2005-11-25 08:58 . 2004-08-04 12:00 71680 c:\windows\system32\wbem\wbemcons.dll + 2005-11-25 08:58 . 2008-04-14 00:12 86528 c:\windows\system32\wbem\stdprov.dll - 2005-11-25 08:58 . 2004-08-04 12:00 86528 c:\windows\system32\wbem\stdprov.dll + 2005-11-25 08:58 . 2008-04-14 00:12 36352 c:\windows\system32\wbem\scrcons.exe + 2005-11-25 08:58 . 2008-04-14 00:12 47104 c:\windows\system32\wbem\ncprov.dll - 2005-11-25 08:58 . 2004-08-04 12:00 47104 c:\windows\system32\wbem\ncprov.dll + 2005-11-25 08:58 . 2008-04-14 00:12 16384 c:\windows\system32\wbem\mofcomp.exe - 2005-11-25 08:58 . 2004-08-04 12:00 16384 c:\windows\system32\wbem\mofcomp.exe - 2005-11-25 08:58 . 2004-08-04 12:00 24576 c:\windows\system32\wbem\krnlprov.dll + 2005-11-25 08:58 . 2008-04-14 00:11 24576 c:\windows\system32\wbem\krnlprov.dll + 2005-09-09 22:03 . 2008-04-14 00:11 21504 c:\windows\system32\wbem\evntrprv.dll - 2005-09-09 22:03 . 2004-08-04 12:00 17664 c:\windows\system32\watchdog.sys + 2005-09-09 22:03 . 2008-04-13 18:44 17664 c:\windows\system32\watchdog.sys + 2005-09-09 22:03 . 2008-04-14 00:12 15872 c:\windows\system32\w3ssl.dll - 2005-09-09 22:03 . 2004-08-04 12:00 15872 c:\windows\system32\w3ssl.dll + 2007-01-01 19:25 . 2008-04-14 00:12 53760 c:\windows\system32\vfwwdm32.dll - 2007-01-01 19:25 . 2004-08-04 00:56 53760 c:\windows\system32\vfwwdm32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 18944 c:\windows\system32\version.dll + 2005-09-09 22:03 . 2008-04-14 00:12 18944 c:\windows\system32\version.dll + 2005-09-09 22:03 . 2008-04-14 00:12 26624 c:\windows\system32\verifier.dll + 2006-03-17 00:38 . 2008-04-14 00:12 28672 c:\windows\system32\verclsid.exe - 2006-03-17 00:38 . 2006-03-17 00:38 28672 c:\windows\system32\verclsid.exe - 2005-09-09 22:03 . 2004-08-04 12:00 51712 c:\windows\system32\vdmredir.dll + 2005-09-09 22:03 . 2008-04-14 00:12 51712 c:\windows\system32\vdmredir.dll + 2005-09-09 22:03 . 2008-04-14 00:12 26112 c:\windows\system32\vdmdbg.dll - 2005-09-09 22:03 . 2004-08-04 12:00 26112 c:\windows\system32\vdmdbg.dll - 2005-09-09 22:03 . 2004-08-04 12:00 30749 c:\windows\system32\vbajet32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 30749 c:\windows\system32\vbajet32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 50176 c:\windows\system32\utilman.exe - 2005-09-09 22:03 . 2004-08-04 12:00 50176 c:\windows\system32\utilman.exe - 2005-09-09 22:03 . 2005-04-28 19:16 19968 c:\windows\system32\usmt\log.dll + 2005-09-09 22:03 . 2008-04-14 00:11 19968 c:\windows\system32\usmt\log.dll + 2005-11-25 16:41 . 2008-04-13 16:44 17920 c:\windows\system32\usmt\cobramsg.dll - 2005-11-25 16:41 . 2005-04-27 23:15 17920 c:\windows\system32\usmt\cobramsg.dll + 2005-09-09 22:03 . 2008-04-14 00:12 26112 c:\windows\system32\userinit.exe - 2006-01-06 17:18 . 2004-08-04 00:56 74240 c:\windows\system32\usbui.dll + 2006-01-06 17:18 . 2008-04-14 00:12 74240 c:\windows\system32\usbui.dll + 2005-09-09 22:03 . 2008-04-14 00:12 16896 c:\windows\system32\usbmon.dll - 2005-09-09 22:03 . 2004-08-04 12:00 16896 c:\windows\system32\usbmon.dll - 2005-09-09 22:03 . 2004-08-04 12:00 37888 c:\windows\system32\url.dll + 2005-09-09 22:03 . 2008-04-14 00:12 37888 c:\windows\system32\url.dll - 2005-09-09 22:03 . 2004-08-04 12:00 18432 c:\windows\system32\ups.exe + 2005-09-09 22:03 . 2008-04-14 00:12 18432 c:\windows\system32\ups.exe - 2005-09-09 22:03 . 2004-08-04 12:00 16896 c:\windows\system32\upnpcont.exe + 2005-09-09 22:03 . 2008-04-14 00:12 16896 c:\windows\system32\upnpcont.exe - 2005-09-09 22:03 . 2004-08-04 12:00 13824 c:\windows\system32\uniplat.dll + 2005-09-09 22:03 . 2008-04-14 00:12 13824 c:\windows\system32\uniplat.dll + 2005-09-09 22:03 . 2008-04-14 00:12 74240 c:\windows\system32\unimdmat.dll - 2005-09-09 22:03 . 2004-08-04 12:00 74240 c:\windows\system32\unimdmat.dll - 2005-09-09 22:03 . 2004-08-04 12:00 35840 c:\windows\system32\umandlg.dll + 2005-09-09 22:03 . 2008-04-14 00:12 35840 c:\windows\system32\umandlg.dll + 2005-09-09 22:03 . 2008-04-14 00:12 26624 c:\windows\system32\udhisapi.dll + 2007-01-29 08:58 . 2008-04-14 00:12 60416 c:\windows\system32\tzchange.exe + 2005-09-09 22:03 . 2008-04-14 00:12 57856 c:\windows\system32\twext.dll + 2008-09-08 22:53 . 2008-04-14 00:12 50688 c:\windows\system32\tspkg.dll + 2008-09-08 22:53 . 2008-04-14 00:12 53248 c:\windows\system32\tsgqec.dll + 2005-09-09 22:03 . 2008-04-14 00:13 12168 c:\windows\system32\tsddd.dll - 2005-09-09 22:03 . 2004-08-04 12:00 12168 c:\windows\system32\tsddd.dll - 2005-11-25 08:58 . 2004-08-04 12:00 93696 c:\windows\system32\tscfgwmi.dll + 2005-11-25 08:58 . 2008-04-14 00:12 93696 c:\windows\system32\tscfgwmi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 90112 c:\windows\system32\trkwks.dll + 2005-09-09 22:03 . 2008-04-14 00:12 12800 c:\windows\system32\tree.com + 2005-09-09 22:03 . 2008-04-14 00:12 12288 c:\windows\system32\tracert.exe - 2005-09-09 22:03 . 2004-08-04 12:00 12288 c:\windows\system32\tracert.exe - 2005-09-09 22:03 . 2005-05-10 23:45 75776 c:\windows\system32\telnet.exe + 2005-09-09 22:03 . 2008-04-14 00:12 75776 c:\windows\system32\telnet.exe - 2005-09-09 22:03 . 2004-08-04 12:00 45568 c:\windows\system32\tcpmonui.dll + 2005-09-09 22:03 . 2008-04-14 00:12 45568 c:\windows\system32\tcpmonui.dll - 2005-09-09 22:03 . 2004-08-04 12:00 45568 c:\windows\system32\tcpmon.dll + 2005-09-09 22:03 . 2008-04-14 00:12 45568 c:\windows\system32\tcpmon.dll + 2005-09-09 22:03 . 2008-04-14 00:12 14848 c:\windows\system32\tcpmib.dll - 2005-09-09 22:03 . 2004-08-04 12:00 14848 c:\windows\system32\tcpmib.dll - 2005-09-09 22:03 . 2004-08-04 12:00 57856 c:\windows\system32\synceng.dll + 2005-09-09 22:03 . 2008-04-14 00:12 57856 c:\windows\system32\synceng.dll + 2005-09-09 22:03 . 2008-04-14 00:12 14336 c:\windows\system32\svchost.exe - 2005-09-09 22:03 . 2004-08-04 12:00 14336 c:\windows\system32\svchost.exe - 2005-09-09 22:03 . 2004-08-04 12:00 75776 c:\windows\system32\strmfilt.dll + 2005-09-09 22:03 . 2008-04-14 00:12 75776 c:\windows\system32\strmfilt.dll + 2005-11-25 08:54 . 2008-04-14 00:12 74752 c:\windows\system32\storprop.dll - 2005-11-25 08:54 . 2004-08-04 00:56 74752 c:\windows\system32\storprop.dll - 2005-09-09 22:03 . 2004-08-04 12:00 14848 c:\windows\system32\stimon.exe + 2005-09-09 22:03 . 2008-04-14 00:12 14848 c:\windows\system32\stimon.exe + 2005-09-09 22:03 . 2008-04-14 00:12 68096 c:\windows\system32\sti.dll + 2005-11-25 08:58 . 2008-04-14 00:12 59392 c:\windows\system32\stclient.dll - 2005-09-09 22:03 . 2004-08-04 12:00 14336 c:\windows\system32\ssstars.scr + 2005-09-09 22:03 . 2008-04-14 00:12 14336 c:\windows\system32\ssstars.scr - 2005-09-09 22:03 . 2004-08-04 12:00 18944 c:\windows\system32\ssmyst.scr + 2005-09-09 22:03 . 2008-04-14 00:12 18944 c:\windows\system32\ssmyst.scr + 2005-09-09 22:03 . 2008-04-14 00:12 47104 c:\windows\system32\ssmypics.scr - 2005-09-09 22:03 . 2004-08-04 12:00 47104 c:\windows\system32\ssmypics.scr + 2005-09-09 22:03 . 2008-04-14 00:12 20992 c:\windows\system32\ssmarque.scr - 2005-09-09 22:03 . 2004-08-04 12:00 20992 c:\windows\system32\ssmarque.scr + 2005-09-09 22:03 . 2008-04-14 00:12 71680 c:\windows\system32\ssdpsrv.dll - 2005-09-09 22:03 . 2004-08-04 12:00 71680 c:\windows\system32\ssdpsrv.dll + 2005-09-09 22:03 . 2008-04-14 00:12 34816 c:\windows\system32\ssdpapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 34816 c:\windows\system32\ssdpapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 19968 c:\windows\system32\ssbezier.scr + 2005-09-09 22:03 . 2008-04-14 00:12 19968 c:\windows\system32\ssbezier.scr - 2005-09-09 22:03 . 2004-12-07 19:32 96768 c:\windows\system32\srvsvc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 96768 c:\windows\system32\srvsvc.dll - 2005-11-25 08:59 . 2004-08-04 12:00 67584 c:\windows\system32\srclient.dll + 2005-11-25 08:59 . 2008-04-14 00:12 67584 c:\windows\system32\srclient.dll + 2007-09-22 16:26 . 2008-04-14 00:12 20992 c:\windows\system32\spupdwxp.exe + 2005-11-25 09:30 . 2007-08-10 19:46 26488 c:\windows\system32\spupdsvc.exe - 2005-11-25 09:30 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe + 2005-09-09 22:03 . 2008-04-14 00:12 57856 c:\windows\system32\spoolsv.exe - 2005-09-09 22:03 . 2005-06-10 23:53 57856 c:\windows\system32\spoolsv.exe + 2005-09-09 22:03 . 2008-04-14 00:12 75264 c:\windows\system32\spoolss.dll + 2005-11-25 09:03 . 2008-04-14 00:11 26624 c:\windows\system32\spool\drivers\w32x86\3\fxsdrv.dll + 2005-09-09 22:03 . 2008-04-14 04:42 11264 c:\windows\system32\spnpinst.exe + 2006-01-12 23:40 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll - 2006-01-12 23:40 . 2007-11-30 11:18 17272 c:\windows\system32\spmsg.dll + 2005-09-09 22:03 . 2008-04-14 00:12 24576 c:\windows\system32\sort.exe + 2005-09-09 22:03 . 2008-04-14 00:12 18944 c:\windows\system32\snmpapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 18944 c:\windows\system32\snmpapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 50688 c:\windows\system32\smss.exe + 2005-09-09 22:03 . 2008-04-14 00:12 50688 c:\windows\system32\smss.exe - 2005-09-09 22:03 . 2004-08-04 12:00 89600 c:\windows\system32\smlogsvc.exe + 2005-09-09 22:03 . 2008-04-14 00:12 89600 c:\windows\system32\smlogsvc.exe - 2007-09-22 16:26 . 2004-08-03 23:56 73796 c:\windows\system32\slserv.exe + 2007-09-22 16:26 . 2008-04-14 00:12 73796 c:\windows\system32\slserv.exe + 2007-09-22 16:26 . 2008-04-14 00:12 32866 c:\windows\system32\slrundll.exe - 2007-09-22 16:26 . 2004-08-03 23:56 32866 c:\windows\system32\slrundll.exe + 2007-09-22 16:26 . 2008-04-14 00:12 73832 c:\windows\system32\slcoinst.dll - 2007-09-22 16:26 . 2004-08-03 23:56 73832 c:\windows\system32\slcoinst.dll - 2005-09-09 22:03 . 2004-08-04 12:00 98304 c:\windows\system32\slbiop.dll + 2005-09-09 22:03 . 2008-04-14 00:12 98304 c:\windows\system32\slbiop.dll + 2005-09-09 22:03 . 2008-04-14 00:12 25088 c:\windows\system32\slayerxp.dll - 2005-09-09 22:03 . 2004-08-04 12:00 25088 c:\windows\system32\slayerxp.dll + 2005-09-09 22:03 . 2008-04-14 00:12 26112 c:\windows\system32\skeys.exe - 2005-09-09 22:03 . 2004-08-04 12:00 26112 c:\windows\system32\skeys.exe - 2005-09-09 22:03 . 2004-08-04 12:00 70144 c:\windows\system32\sigverif.exe + 2005-09-09 22:03 . 2008-04-14 00:12 70144 c:\windows\system32\sigverif.exe - 2005-09-09 22:03 . 2004-08-04 12:00 13312 c:\windows\system32\sigtab.dll + 2005-09-09 22:03 . 2008-04-14 00:12 13312 c:\windows\system32\sigtab.dll - 2005-09-09 22:03 . 2004-08-04 12:00 19456 c:\windows\system32\shutdown.exe + 2005-09-09 22:03 . 2008-04-14 00:12 19456 c:\windows\system32\shutdown.exe + 2005-09-09 22:03 . 2008-04-14 00:12 27648 c:\windows\system32\shscrap.dll - 2005-09-09 22:03 . 2004-08-04 12:00 27648 c:\windows\system32\shscrap.dll + 2005-09-09 22:03 . 2008-04-14 00:12 77824 c:\windows\system32\shrpubw.exe - 2005-09-09 22:03 . 2004-08-04 12:00 77824 c:\windows\system32\shrpubw.exe + 2005-09-09 22:03 . 2008-04-14 00:12 45056 c:\windows\system32\shmgrate.exe + 2005-09-09 22:03 . 2008-04-14 00:12 65024 c:\windows\system32\shimeng.dll + 2005-09-09 22:03 . 2008-04-14 00:12 68096 c:\windows\system32\shgina.dll - 2005-09-09 22:03 . 2004-08-04 12:00 68096 c:\windows\system32\shgina.dll + 2005-09-09 22:03 . 2008-04-14 00:12 25088 c:\windows\system32\shfolder.dll - 2005-09-09 22:03 . 2004-08-04 12:00 25088 c:\windows\system32\shfolder.dll + 2008-09-08 22:53 . 2008-04-14 00:12 32768 c:\windows\system32\setupn.exe + 2005-09-09 22:03 . 2008-04-14 00:12 26624 c:\windows\system32\Setup\startoc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 17408 c:\windows\system32\Setup\ocmsn.dll - 2005-09-09 22:03 . 2004-08-04 12:00 17408 c:\windows\system32\Setup\ocmsn.dll + 2005-09-09 22:03 . 2008-04-14 00:12 15360 c:\windows\system32\Setup\ocgen.dll - 2005-09-09 22:03 . 2004-08-04 12:00 62976 c:\windows\system32\Setup\ntoc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 62976 c:\windows\system32\Setup\ntoc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 77312 c:\windows\system32\Setup\netoc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 77312 c:\windows\system32\Setup\netoc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 15360 c:\windows\system32\Setup\msgrocm.dll + 2005-09-09 22:03 . 2008-04-14 00:11 15360 c:\windows\system32\Setup\msgrocm.dll + 2005-09-09 22:03 . 2008-04-14 00:11 90112 c:\windows\system32\Setup\msdtcstp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 32828 c:\windows\system32\Setup\fp40ext.dll - 2005-09-09 22:03 . 2004-08-04 12:00 32828 c:\windows\system32\Setup\fp40ext.dll - 2005-09-09 22:03 . 2004-08-04 12:00 23040 c:\windows\system32\setup.exe + 2005-09-09 22:03 . 2008-04-14 00:12 23040 c:\windows\system32\setup.exe + 2005-09-09 22:03 . 2008-04-14 00:12 31232 c:\windows\system32\sethc.exe - 2005-09-09 22:03 . 2004-08-04 12:00 31232 c:\windows\system32\sethc.exe - 2005-11-25 08:58 . 2004-08-04 12:00 56320 c:\windows\system32\servdeps.dll + 2005-11-25 08:58 . 2008-04-14 00:12 56320 c:\windows\system32\servdeps.dll + 2005-09-09 22:03 . 2008-04-14 00:12 39424 c:\windows\system32\sens.dll + 2005-09-09 22:03 . 2008-04-14 00:12 54784 c:\windows\system32\sendmail.dll - 2005-09-09 22:03 . 2004-08-04 12:00 29184 c:\windows\system32\sendcmsg.dll + 2005-09-09 22:03 . 2008-04-14 00:12 29184 c:\windows\system32\sendcmsg.dll + 2005-09-09 22:03 . 2009-02-03 19:59 56832 c:\windows\system32\secur32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 18944 c:\windows\system32\seclogon.dll + 2005-09-09 22:03 . 2008-04-14 00:12 18944 c:\windows\system32\seclogon.dll + 2004-08-04 00:56 . 2008-04-14 00:12 29184 c:\windows\system32\sdhcinst.dll - 2004-08-04 00:56 . 2004-08-04 12:00 29184 c:\windows\system32\sdhcinst.dll + 2005-09-09 22:03 . 2008-04-14 00:12 77312 c:\windows\system32\sdbinst.exe - 2005-09-09 22:03 . 2004-08-04 12:00 77312 c:\windows\system32\sdbinst.exe + 2005-09-09 22:03 . 2008-04-14 00:12 20480 c:\windows\system32\sclgntfy.dll + 2005-09-09 22:03 . 2008-04-14 00:12 95744 c:\windows\system32\scardsvr.exe - 2005-09-09 22:03 . 2004-08-04 12:00 95744 c:\windows\system32\scardsvr.exe + 2005-09-09 22:03 . 2008-04-14 00:12 69632 c:\windows\system32\scarddlg.dll - 2005-09-09 22:03 . 2004-08-04 12:00 69632 c:\windows\system32\scarddlg.dll + 2005-09-09 22:03 . 2009-02-06 10:39 35328 c:\windows\system32\sc.exe - 2005-09-09 22:03 . 2009-02-06 16:54 35328 c:\windows\system32\sc.exe - 2005-09-09 22:03 . 2004-08-04 12:00 13312 c:\windows\system32\savedump.exe + 2005-09-09 22:03 . 2008-04-14 00:12 13312 c:\windows\system32\savedump.exe + 2005-09-09 22:03 . 2008-04-14 00:12 64000 c:\windows\system32\samlib.dll - 2005-09-09 22:03 . 2004-08-04 12:00 64000 c:\windows\system32\samlib.dll - 2005-11-25 08:59 . 2004-08-04 12:00 45568 c:\windows\system32\safrslv.dll + 2005-11-25 08:59 . 2008-04-14 00:12 45568 c:\windows\system32\safrslv.dll - 2005-11-25 08:59 . 2004-08-04 12:00 29696 c:\windows\system32\safrdm.dll + 2005-11-25 08:59 . 2008-04-14 00:12 29696 c:\windows\system32\safrdm.dll + 2005-11-25 08:59 . 2008-04-14 00:12 43520 c:\windows\system32\safrcdlg.dll - 2005-11-25 08:59 . 2004-08-04 12:00 43520 c:\windows\system32\safrcdlg.dll + 2005-09-09 22:03 . 2008-04-14 00:12 14336 c:\windows\system32\runonce.exe - 2005-09-09 22:03 . 2004-08-04 12:00 14336 c:\windows\system32\runonce.exe + 2005-09-09 22:03 . 2008-04-14 00:12 33280 c:\windows\system32\rundll32.exe - 2005-09-09 22:03 . 2004-08-04 12:00 33280 c:\windows\system32\rundll32.exe - 2005-09-09 22:03 . 2004-08-04 12:00 44032 c:\windows\system32\rtutils.dll + 2005-09-09 22:03 . 2008-04-14 00:12 44032 c:\windows\system32\rtutils.dll - 2005-09-09 22:03 . 2004-08-04 12:00 31744 c:\windows\system32\rtipxmib.dll + 2005-09-09 22:03 . 2008-04-14 00:12 31744 c:\windows\system32\rtipxmib.dll + 2005-09-09 22:03 . 2008-04-14 00:12 77312 c:\windows\system32\rtcshare.exe - 2005-09-09 22:03 . 2004-08-04 12:00 77312 c:\windows\system32\rtcshare.exe + 2005-09-09 22:03 . 2008-04-14 00:12 92672 c:\windows\system32\rsvpsp.dll + 2005-09-09 22:03 . 2008-04-14 00:12 18944 c:\windows\system32\rsmps.dll - 2005-09-09 22:03 . 2004-08-04 12:00 18944 c:\windows\system32\rsmps.dll + 2005-09-09 22:03 . 2008-04-14 00:12 39936 c:\windows\system32\rshx32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 39936 c:\windows\system32\rshx32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 14848 c:\windows\system32\rsh.exe - 2005-09-09 22:03 . 2004-08-04 12:00 14848 c:\windows\system32\rsh.exe + 2005-09-09 22:03 . 2008-04-14 00:12 13824 c:\windows\system32\rexec.exe - 2005-09-09 22:03 . 2004-08-04 12:00 13824 c:\windows\system32\rexec.exe - 2005-09-09 22:03 . 2004-08-04 12:00 58880 c:\windows\system32\resutils.dll + 2005-09-09 22:03 . 2008-04-14 00:12 58880 c:\windows\system32\resutils.dll - 2005-11-25 08:58 . 2004-08-04 12:00 60416 c:\windows\system32\remotepg.dll + 2005-11-25 08:58 . 2008-04-14 00:12 60416 c:\windows\system32\remotepg.dll - 2005-09-09 22:03 . 2004-08-04 12:00 11776 c:\windows\system32\regsvr32.exe + 2005-09-09 22:03 . 2008-04-14 00:12 11776 c:\windows\system32\regsvr32.exe - 2005-09-09 22:03 . 2004-08-04 12:00 59904 c:\windows\system32\regsvc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 59904 c:\windows\system32\regsvc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 49664 c:\windows\system32\regapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 49664 c:\windows\system32\regapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 50176 c:\windows\system32\reg.exe + 2005-09-09 22:03 . 2008-04-14 00:12 50176 c:\windows\system32\reg.exe + 2005-11-25 08:58 . 2008-04-14 00:12 67072 c:\windows\system32\rdshost.exe - 2005-11-25 08:58 . 2004-08-04 12:00 67072 c:\windows\system32\rdshost.exe + 2005-11-25 08:58 . 2008-04-14 00:12 13824 c:\windows\system32\rdsaddin.exe - 2005-11-25 08:58 . 2004-08-04 12:00 13824 c:\windows\system32\rdsaddin.exe + 2005-11-25 08:58 . 2008-04-14 00:13 87176 c:\windows\system32\rdpwsx.dll - 2005-11-25 08:58 . 2004-08-04 12:00 87176 c:\windows\system32\rdpwsx.dll - 2005-11-25 08:58 . 2004-08-04 12:00 19968 c:\windows\system32\rdpsnd.dll + 2005-11-25 08:58 . 2008-04-14 00:12 19968 c:\windows\system32\rdpsnd.dll + 2005-09-09 22:03 . 2008-04-14 00:13 92424 c:\windows\system32\rdpdd.dll + 2005-11-25 08:58 . 2008-04-14 00:12 62976 c:\windows\system32\rdpclip.exe - 2005-09-09 22:03 . 2004-08-04 12:00 21504 c:\windows\system32\rcp.exe + 2005-09-09 22:03 . 2008-04-14 00:12 21504 c:\windows\system32\rcp.exe - 2005-09-09 22:03 . 2004-08-04 12:00 35840 c:\windows\system32\rcimlby.exe + 2005-09-09 22:03 . 2008-04-14 00:12 35840 c:\windows\system32\rcimlby.exe + 2005-09-09 22:03 . 2008-04-14 00:12 58368 c:\windows\system32\rastapi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 16384 c:\windows\system32\rassapi.dll + 2008-09-08 22:53 . 2008-04-14 00:12 61952 c:\windows\system32\rasqec.dll + 2005-09-09 22:03 . 2008-04-14 00:12 56832 c:\windows\system32\rasphone.exe - 2005-09-09 22:03 . 2004-08-04 12:00 56832 c:\windows\system32\rasphone.exe - 2005-09-09 22:03 . 2004-08-04 12:00 61440 c:\windows\system32\rasman.dll + 2005-09-09 22:03 . 2008-04-14 00:12 61440 c:\windows\system32\rasman.dll + 2005-09-09 22:03 . 2008-04-14 00:12 79872 c:\windows\system32\raschap.dll + 2005-09-09 22:03 . 2008-04-14 00:12 88576 c:\windows\system32\rasauto.dll - 2005-11-25 08:59 . 2004-08-04 12:00 43520 c:\windows\system32\racpldlg.dll + 2005-11-25 08:59 . 2008-04-14 00:12 43520 c:\windows\system32\racpldlg.dll + 2008-09-08 22:53 . 2008-04-14 00:12 76800 c:\windows\system32\qutil.dll + 2005-11-25 08:58 . 2008-04-14 00:12 19968 c:\windows\system32\qprocess.exe - 2005-11-25 08:59 . 2004-08-04 12:00 18944 c:\windows\system32\qmgrprxy.dll + 2005-11-25 08:59 . 2008-04-14 00:12 18944 c:\windows\system32\qmgrprxy.dll + 2008-09-08 22:53 . 2008-04-14 00:12 62464 c:\windows\system32\qcliprov.dll - 2005-09-09 22:03 . 2004-08-04 12:00 34304 c:\windows\system32\pstorsvc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 34304 c:\windows\system32\pstorsvc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 43520 c:\windows\system32\pstorec.dll - 2005-09-09 22:03 . 2004-08-04 12:00 43520 c:\windows\system32\pstorec.dll + 2005-09-09 22:03 . 2008-04-14 00:12 96768 c:\windows\system32\psbase.dll - 2005-09-09 22:03 . 2004-08-04 12:00 96768 c:\windows\system32\psbase.dll - 2005-09-09 22:03 . 2004-08-04 12:00 23040 c:\windows\system32\psapi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 23040 c:\windows\system32\psapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 50176 c:\windows\system32\proquota.exe + 2005-09-09 22:03 . 2008-04-14 00:12 50176 c:\windows\system32\proquota.exe - 2005-09-09 22:03 . 2004-08-04 12:00 27648 c:\windows\system32\profmap.dll + 2005-09-09 22:03 . 2008-04-14 00:12 27648 c:\windows\system32\profmap.dll + 2005-09-09 22:03 . 2008-04-14 00:12 17408 c:\windows\system32\powrprof.dll - 2005-09-09 22:03 . 2004-08-04 12:00 17408 c:\windows\system32\powrprof.dll + 2005-09-09 22:03 . 2008-04-14 00:12 49152 c:\windows\system32\powercfg.exe - 2005-09-09 22:03 . 2004-08-04 12:00 49152 c:\windows\system32\powercfg.exe + 2005-09-09 22:03 . 2008-04-14 00:12 58880 c:\windows\system32\pnrpnsp.dll - 2005-09-09 22:03 . 2009-02-20 08:14 39424 c:\windows\system32\pngfilt.dll + 2005-09-09 22:03 . 2008-04-14 00:12 39424 c:\windows\system32\pngfilt.dll + 2004-08-04 00:56 . 2008-04-14 00:12 15360 c:\windows\system32\pjlmon.dll - 2004-08-04 00:56 . 2004-08-04 12:00 15360 c:\windows\system32\pjlmon.dll + 2005-09-09 22:03 . 2008-04-14 00:12 17920 c:\windows\system32\ping.exe - 2005-09-09 22:03 . 2004-08-04 12:00 17920 c:\windows\system32\ping.exe + 2005-09-09 22:03 . 2008-04-13 18:35 24064 c:\windows\system32\pidgen.dll - 2005-09-09 22:03 . 2004-08-04 12:00 24064 c:\windows\system32\pidgen.dll + 2004-08-04 00:56 . 2008-04-14 00:12 35328 c:\windows\system32\pid.dll - 2004-08-04 00:56 . 2004-08-04 12:00 35328 c:\windows\system32\pid.dll + 2005-09-09 22:03 . 2008-04-14 00:12 34816 c:\windows\system32\perfproc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 34816 c:\windows\system32\perfproc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 25088 c:\windows\system32\perfos.dll - 2005-09-09 22:03 . 2004-08-04 12:00 25088 c:\windows\system32\perfos.dll + 2005-09-09 22:03 . 2008-04-14 00:12 17920 c:\windows\system32\perfnet.dll - 2005-09-09 22:03 . 2004-08-04 12:00 15872 c:\windows\system32\perfmon.exe + 2005-09-09 22:03 . 2008-04-14 00:12 15872 c:\windows\system32\perfmon.exe + 2005-09-09 22:03 . 2008-04-14 00:12 26624 c:\windows\system32\perfdisk.dll - 2005-09-09 22:03 . 2004-08-04 12:00 26624 c:\windows\system32\perfdisk.dll - 2005-09-09 22:03 . 2004-08-04 12:00 39936 c:\windows\system32\perfctrs.dll + 2005-09-09 22:03 . 2008-04-14 00:12 39936 c:\windows\system32\perfctrs.dll - 2005-09-09 22:03 . 2009-04-20 09:36 65260 c:\windows\system32\perfc009.dat + 2005-09-09 22:03 . 2009-07-06 02:10 65260 c:\windows\system32\perfc009.dat + 2005-09-09 22:03 . 2008-04-14 00:12 67584 c:\windows\system32\pautoenr.dll - 2005-09-09 22:03 . 2004-08-04 12:00 58368 c:\windows\system32\packager.exe + 2005-09-09 22:03 . 2008-04-14 00:12 58368 c:\windows\system32\packager.exe - 2005-09-09 22:03 . 2004-08-04 12:00 67584 c:\windows\system32\osuninst.dll + 2005-09-09 22:03 . 2008-04-14 00:12 67584 c:\windows\system32\osuninst.dll + 2005-11-25 08:59 . 2008-04-14 00:12 51200 c:\windows\system32\oobe\oobebaln.exe - 2005-11-25 08:59 . 2004-08-04 12:00 51200 c:\windows\system32\oobe\oobebaln.exe + 2005-11-25 08:59 . 2008-04-14 00:12 29184 c:\windows\system32\oobe\msoobe.exe + 2005-11-25 08:59 . 2008-04-14 00:12 19456 c:\windows\system32\oobe\msobweb.dll + 2005-11-25 08:59 . 2008-04-14 00:12 30720 c:\windows\system32\oobe\msobshel.dll - 2005-11-25 08:59 . 2004-08-04 12:00 30720 c:\windows\system32\oobe\msobshel.dll - 2005-11-25 08:59 . 2004-08-04 12:00 16384 c:\windows\system32\oobe\msobdl.dll + 2005-11-25 08:59 . 2008-04-14 00:12 16384 c:\windows\system32\oobe\msobdl.dll + 2005-09-09 22:03 . 2008-04-14 00:12 84992 c:\windows\system32\olepro32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 37376 c:\windows\system32\olecnv32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 74752 c:\windows\system32\olecli32.dll - 2005-09-09 22:03 . 2005-07-26 04:39 74752 c:\windows\system32\olecli32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 20511 c:\windows\system32\odtext32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 20511 c:\windows\system32\odtext32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 20510 c:\windows\system32\odpdx32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 20510 c:\windows\system32\odpdx32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 20510 c:\windows\system32\odfox32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 20510 c:\windows\system32\odfox32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 20510 c:\windows\system32\odexl32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 20510 c:\windows\system32\odexl32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 20511 c:\windows\system32\oddbse32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 20511 c:\windows\system32\oddbse32.dll + 2005-09-09 22:03 . 2008-04-13 17:26 12288 c:\windows\system32\odbcp32r.dll - 2005-09-09 22:03 . 2004-08-04 12:00 12288 c:\windows\system32\odbcp32r.dll + 2005-09-09 22:03 . 2008-04-14 00:10 53279 c:\windows\system32\odbcji32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 53279 c:\windows\system32\odbcji32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 94208 c:\windows\system32\odbcint.dll + 2005-09-09 22:03 . 2008-04-13 17:26 94208 c:\windows\system32\odbcint.dll - 2005-09-09 22:03 . 2004-08-04 12:00 65536 c:\windows\system32\odbccu32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 65536 c:\windows\system32\odbccu32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 65536 c:\windows\system32\odbccr32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 65536 c:\windows\system32\odbccr32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 69632 c:\windows\system32\odbcconf.exe + 2005-09-09 22:03 . 2008-04-14 00:12 69632 c:\windows\system32\odbcconf.exe - 2005-09-09 22:03 . 2004-08-04 12:00 24576 c:\windows\system32\odbcbcp.dll + 2005-09-09 22:03 . 2008-04-14 00:12 24576 c:\windows\system32\odbcbcp.dll + 2005-09-09 22:03 . 2008-04-14 00:12 32768 c:\windows\system32\odbcad32.exe - 2005-09-09 22:03 . 2004-08-04 12:00 32768 c:\windows\system32\odbcad32.exe - 2005-09-09 22:03 . 2004-08-04 12:00 16384 c:\windows\system32\odbc32gt.dll + 2005-09-09 22:03 . 2008-04-14 00:12 16384 c:\windows\system32\odbc32gt.dll + 2005-09-09 22:03 . 2008-04-14 00:12 67584 c:\windows\system32\ocmanage.dll + 2005-09-09 22:03 . 2008-04-14 00:12 96256 c:\windows\system32\occache.dll - 2005-09-09 22:03 . 2004-08-04 12:00 96256 c:\windows\system32\occache.dll + 2005-09-09 22:03 . 2008-04-14 00:12 15360 c:\windows\system32\ntvdmd.dll - 2005-09-09 22:03 . 2004-08-04 12:00 91136 c:\windows\system32\ntprint.dll + 2005-09-09 22:03 . 2008-04-14 00:12 91136 c:\windows\system32\ntprint.dll - 2005-09-09 22:03 . 2004-08-04 12:00 40960 c:\windows\system32\ntmsapi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 40960 c:\windows\system32\ntmsapi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 44032 c:\windows\system32\ntlanman.dll - 2005-09-09 22:03 . 2004-08-04 12:00 67072 c:\windows\system32\ntdsapi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 67072 c:\windows\system32\ntdsapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 76800 c:\windows\system32\nslookup.exe + 2005-09-09 22:03 . 2008-04-14 00:12 76800 c:\windows\system32\nslookup.exe + 2005-09-09 22:03 . 2008-04-14 00:12 54784 c:\windows\system32\npptools.dll - 2005-09-09 22:03 . 2004-08-04 12:00 54784 c:\windows\system32\npptools.dll - 2005-09-09 22:03 . 2004-08-04 12:00 15360 c:\windows\system32\npp\nppagent.exe + 2005-09-09 22:03 . 2008-04-14 00:12 15360 c:\windows\system32\npp\nppagent.exe - 2005-09-09 22:03 . 2004-08-04 12:00 57344 c:\windows\system32\npp\ndisnpp.dll + 2005-09-09 22:03 . 2008-04-14 00:12 57344 c:\windows\system32\npp\ndisnpp.dll + 2005-09-09 22:03 . 2008-04-14 00:12 69120 c:\windows\system32\notepad.exe - 2005-09-09 22:03 . 2004-08-04 12:00 69120 c:\windows\system32\notepad.exe - 2005-11-25 08:59 . 2004-08-04 12:00 28672 c:\windows\system32\nmmkcert.dll + 2005-11-25 08:59 . 2008-04-14 00:12 28672 c:\windows\system32\nmmkcert.dll + 2005-09-09 22:03 . 2008-04-14 00:12 98304 c:\windows\system32\nlhtml.dll - 2005-09-09 22:03 . 2004-08-04 12:00 80896 c:\windows\system32\netui0.dll + 2005-09-09 22:03 . 2008-04-14 00:12 80896 c:\windows\system32\netui0.dll + 2005-09-09 22:03 . 2008-04-14 00:12 36864 c:\windows\system32\netstat.exe - 2005-09-09 22:03 . 2004-08-04 12:00 36864 c:\windows\system32\netstat.exe - 2005-09-09 22:03 . 2004-08-04 12:00 86016 c:\windows\system32\netsh.exe + 2005-09-09 22:03 . 2008-04-14 00:12 86016 c:\windows\system32\netsh.exe + 2005-09-09 22:03 . 2008-04-14 00:12 11776 c:\windows\system32\netrap.dll + 2005-09-09 22:03 . 2008-04-14 00:12 42496 c:\windows\system32\net.exe - 2005-09-09 22:03 . 2004-08-04 12:00 42496 c:\windows\system32\net.exe + 2005-09-09 22:03 . 2008-04-14 00:12 18944 c:\windows\system32\nddenb32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 18944 c:\windows\system32\nddenb32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 17920 c:\windows\system32\nddeapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 17920 c:\windows\system32\nddeapi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 36352 c:\windows\system32\ncobjapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 36352 c:\windows\system32\ncobjapi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 53760 c:\windows\system32\narrator.exe - 2005-09-09 22:03 . 2004-08-04 12:00 53760 c:\windows\system32\narrator.exe + 2008-09-08 22:53 . 2008-04-14 00:12 30208 c:\windows\system32\napipsec.dll + 2005-09-09 22:03 . 2008-04-14 00:12 90624 c:\windows\system32\mydocs.dll - 2005-09-09 22:03 . 2004-08-04 12:00 90624 c:\windows\system32\mydocs.dll - 2005-11-25 08:58 . 2008-06-12 14:16 91648 c:\windows\system32\mtxoci.dll + 2005-11-25 08:58 . 2008-06-12 14:23 91648 c:\windows\system32\mtxoci.dll + 2005-11-25 08:58 . 2008-04-14 00:12 34304 c:\windows\system32\mtxlegih.dll + 2005-11-25 08:58 . 2008-04-14 00:12 30720 c:\windows\system32\mtxdm.dll - 2005-09-09 22:03 . 2008-06-12 14:16 66560 c:\windows\system32\mtxclu.dll + 2005-09-09 22:03 . 2008-06-12 14:23 66560 c:\windows\system32\mtxclu.dll + 2004-08-04 00:56 . 2008-04-14 00:12 16896 c:\windows\system32\msyuv.dll + 2008-09-08 22:53 . 2008-04-13 17:27 79872 c:\windows\system32\msxml6r.dll + 2005-09-09 22:03 . 2008-04-14 00:12 72704 c:\windows\system32\msw3prt.dll - 2005-09-09 22:03 . 2004-08-04 12:00 72704 c:\windows\system32\msw3prt.dll + 2005-09-09 22:03 . 2008-04-13 18:30 61440 c:\windows\system32\msvcrt40.dll - 2005-09-09 22:03 . 2004-08-04 12:00 61440 c:\windows\system32\msvcrt40.dll + 2005-09-09 22:03 . 2008-04-14 00:12 57344 c:\windows\system32\msvcirt.dll - 2005-11-25 08:59 . 2004-08-04 12:00 12288 c:\windows\system32\mstinit.exe + 2005-11-25 08:59 . 2008-04-14 00:12 12288 c:\windows\system32\mstinit.exe + 2008-09-08 22:53 . 2008-04-13 18:14 76800 c:\windows\system32\msshavmsg.dll + 2005-09-09 22:03 . 2008-04-14 00:12 11264 c:\windows\system32\msrle32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 11264 c:\windows\system32\msrle32.dll + 2005-09-09 22:03 . 2008-04-13 16:23 48128 c:\windows\system32\msprivs.dll - 2005-09-09 22:03 . 2004-08-04 12:00 48128 c:\windows\system32\msprivs.dll + 2005-09-09 22:03 . 2008-04-14 00:12 29696 c:\windows\system32\mspatcha.dll - 2005-09-09 22:03 . 2004-08-04 12:00 20480 c:\windows\system32\msorc32r.dll + 2005-09-09 22:03 . 2008-04-13 17:24 20480 c:\windows\system32\msorc32r.dll + 2005-09-09 22:03 . 2008-04-14 00:12 25088 c:\windows\system32\mslbui.dll - 2005-09-09 22:03 . 2004-08-04 12:00 25088 c:\windows\system32\mslbui.dll + 2005-09-09 22:03 . 2008-04-14 00:11 15360 c:\windows\system32\msisip.dll - 2005-09-09 22:03 . 2005-05-04 14:45 15360 c:\windows\system32\msisip.dll - 2005-09-09 22:03 . 2005-05-04 14:45 78848 c:\windows\system32\msiexec.exe + 2005-09-09 22:03 . 2008-04-14 00:12 78848 c:\windows\system32\msiexec.exe - 2005-09-09 22:03 . 2004-08-04 12:00 51712 c:\windows\system32\msident.dll + 2005-09-09 22:03 . 2008-04-14 00:11 51712 c:\windows\system32\msident.dll + 2005-09-09 22:03 . 2008-04-13 16:26 56832 c:\windows\system32\mshtmler.dll Last edited by Kirashio; 07-06-2009 at 07:01 AM. |
|
|
|
|
#11 (permalink) |
|
Registered User
Join Date: Jul 2009
Posts: 14
OS: xp
|
Re: Recurring Vundo Trojan
- 2005-09-09 22:03 . 2004-08-04 12:00 56832 c:\windows\system32\mshtmler.dll
+ 2005-09-09 22:03 . 2008-04-14 00:12 29184 c:\windows\system32\mshta.exe - 2005-09-09 22:03 . 2004-08-04 12:00 29184 c:\windows\system32\mshta.exe - 2005-09-09 22:03 . 2004-08-04 12:00 33792 c:\windows\system32\msgsvc.dll + 2005-09-09 22:03 . 2008-04-14 00:11 33792 c:\windows\system32\msgsvc.dll - 2005-11-25 08:58 . 2008-06-12 14:16 58880 c:\windows\system32\msdtclog.dll + 2005-11-25 08:58 . 2008-06-12 14:23 58880 c:\windows\system32\msdtclog.dll + 2005-09-09 22:03 . 2008-04-14 00:11 14336 c:\windows\system32\msdmo.dll - 2005-09-09 22:03 . 2004-08-04 12:00 14336 c:\windows\system32\msdmo.dll + 2005-09-09 22:03 . 2008-04-14 00:11 68608 c:\windows\system32\msctfp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 36864 c:\windows\system32\mscpxl32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 36864 c:\windows\system32\mscpxl32.dLL + 2005-09-09 22:03 . 2008-04-13 17:26 12288 c:\windows\system32\mscpx32r.dll - 2005-09-09 22:03 . 2004-08-04 12:00 12288 c:\windows\system32\mscpx32r.dLL - 2005-11-25 08:59 . 2004-08-04 12:00 69632 c:\windows\system32\msconf.dll + 2005-11-25 08:59 . 2008-04-14 00:11 69632 c:\windows\system32\msconf.dll + 2005-09-09 22:03 . 2008-06-24 16:43 74240 c:\windows\system32\mscms.dll - 2005-09-09 22:03 . 2008-06-24 16:23 74240 c:\windows\system32\mscms.dll + 2005-09-09 22:03 . 2008-04-14 00:11 57344 c:\windows\system32\msasn1.dll - 2005-09-09 22:03 . 2004-08-04 12:00 57344 c:\windows\system32\msasn1.dll - 2005-09-09 22:03 . 2004-08-04 12:00 86016 c:\windows\system32\msapsspc.dll + 2005-09-09 22:03 . 2008-04-14 00:11 86016 c:\windows\system32\msapsspc.dll + 2005-09-09 22:03 . 2008-04-14 00:11 71680 c:\windows\system32\msacm32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 71680 c:\windows\system32\msacm32.dll + 2005-09-09 22:03 . 2008-04-14 00:11 53248 c:\windows\system32\mprdim.dll + 2005-09-09 22:03 . 2008-04-14 00:11 87040 c:\windows\system32\mprapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 87040 c:\windows\system32\mprapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 59904 c:\windows\system32\mpr.dll + 2005-09-09 22:03 . 2008-04-14 00:11 59904 c:\windows\system32\mpr.dll + 2005-09-09 22:03 . 2008-04-14 00:12 16896 c:\windows\system32\more.com - 2005-11-25 08:59 . 2004-08-04 12:00 32768 c:\windows\system32\mnmsrvc.exe + 2005-11-25 08:59 . 2008-04-14 00:12 32768 c:\windows\system32\mnmsrvc.exe + 2005-11-25 08:59 . 2008-04-14 00:11 34560 c:\windows\system32\mnmdd.dll - 2005-11-25 08:59 . 2004-08-04 12:00 34560 c:\windows\system32\mnmdd.dll + 2005-11-25 08:58 . 2008-04-14 00:11 17408 c:\windows\system32\mmfutil.dll - 2005-11-25 08:58 . 2004-08-04 12:00 17408 c:\windows\system32\mmfutil.dll + 2005-09-09 22:03 . 2008-04-14 00:11 61440 c:\windows\system32\mmcshext.dll + 2008-09-08 22:52 . 2008-04-14 00:12 33792 c:\windows\system32\mmcperf.exe + 2005-09-09 22:03 . 2008-04-14 00:11 29696 c:\windows\system32\mimefilt.dll + 2005-09-09 22:03 . 2008-04-14 00:11 60928 c:\windows\system32\miglibnt.dll - 2005-09-09 22:03 . 2004-08-04 12:00 60928 c:\windows\system32\miglibnt.dll - 2005-09-09 22:03 . 2004-08-04 12:00 18944 c:\windows\system32\midimap.dll + 2005-09-09 22:03 . 2008-04-14 00:11 18944 c:\windows\system32\midimap.dll + 2005-09-09 22:03 . 2008-04-14 00:11 14848 c:\windows\system32\mgmtapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 14848 c:\windows\system32\mgmtapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 22528 c:\windows\system32\mfcsubs.dll + 2005-09-09 22:03 . 2008-04-14 00:11 22528 c:\windows\system32\mfcsubs.dll + 2005-09-09 22:03 . 2008-04-14 00:11 40960 c:\windows\system32\mf3216.dll - 2005-09-09 22:03 . 2007-03-08 15:36 40960 c:\windows\system32\mf3216.dll + 2007-09-22 16:26 . 2008-04-14 00:11 86016 c:\windows\system32\mdmxsdk.dll - 2007-09-22 16:26 . 2004-08-03 23:56 86016 c:\windows\system32\mdmxsdk.dll + 2005-09-09 22:03 . 2008-04-14 00:11 23552 c:\windows\system32\mciwave.dll - 2005-09-09 22:03 . 2004-08-04 12:00 23552 c:\windows\system32\mciwave.dll + 2005-09-09 22:03 . 2008-04-14 00:11 23040 c:\windows\system32\mciseq.dll - 2005-09-09 22:03 . 2004-08-04 12:00 23040 c:\windows\system32\mciseq.dll + 2005-09-09 22:03 . 2008-04-14 00:11 35328 c:\windows\system32\mciqtz32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 35328 c:\windows\system32\mciqtz32.dll + 2005-09-09 22:03 . 2008-04-14 00:11 84480 c:\windows\system32\mciavi32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 84480 c:\windows\system32\mciavi32.dll + 2005-09-09 22:03 . 2008-04-14 00:11 14336 c:\windows\system32\mcastmib.dll + 2005-09-09 22:03 . 2008-04-14 00:12 57344 c:\windows\system32\makecab.exe + 2005-09-09 22:03 . 2008-04-14 00:12 72704 c:\windows\system32\magnify.exe - 2005-09-09 22:03 . 2004-08-04 12:00 72704 c:\windows\system32\magnify.exe - 2005-09-09 22:03 . 2004-08-04 12:00 13312 c:\windows\system32\lsass.exe + 2005-09-09 22:03 . 2008-04-14 00:12 13312 c:\windows\system32\lsass.exe + 2005-09-09 22:03 . 2008-04-14 00:11 10240 c:\windows\system32\lprhelp.dll - 2005-09-09 22:03 . 2004-08-04 12:00 10240 c:\windows\system32\lprhelp.dll - 2005-09-09 22:03 . 2004-08-04 12:00 22016 c:\windows\system32\lpk.dll + 2005-09-09 22:03 . 2008-04-14 00:11 22016 c:\windows\system32\lpk.dll - 2005-09-09 22:03 . 2004-08-04 12:00 59392 c:\windows\system32\logman.exe + 2005-09-09 22:03 . 2008-04-14 00:12 59392 c:\windows\system32\logman.exe + 2005-09-09 22:03 . 2008-04-14 00:12 75264 c:\windows\system32\locator.exe - 2005-09-09 22:03 . 2004-08-04 12:00 75264 c:\windows\system32\locator.exe - 2005-09-09 22:03 . 2004-08-04 12:00 11776 c:\windows\system32\localui.dll + 2005-09-09 22:03 . 2008-04-14 00:11 11776 c:\windows\system32\localui.dll - 2005-09-09 22:03 . 2004-08-04 12:00 97280 c:\windows\system32\loadperf.dll + 2005-09-09 22:03 . 2008-04-14 00:11 97280 c:\windows\system32\loadperf.dll - 2005-09-09 22:03 . 2004-08-04 12:00 13824 c:\windows\system32\lmhsvc.dll + 2005-09-09 22:03 . 2008-04-14 00:11 13824 c:\windows\system32\lmhsvc.dll + 2005-09-09 22:03 . 2008-04-14 00:11 19968 c:\windows\system32\linkinfo.dll - 2005-09-09 22:03 . 2005-09-01 01:41 19968 c:\windows\system32\linkinfo.dll - 2005-11-25 08:58 . 2004-08-04 12:00 58880 c:\windows\system32\licwmi.dll + 2005-11-25 08:58 . 2008-04-14 00:11 58880 c:\windows\system32\licwmi.dll + 2005-09-09 22:03 . 2008-04-14 00:11 22016 c:\windows\system32\licmgr10.dll - 2005-09-09 22:03 . 2004-08-04 12:00 22016 c:\windows\system32\licmgr10.dll + 2008-09-08 22:52 . 2008-04-14 00:11 37376 c:\windows\system32\l2gpstore.dll + 2008-09-08 22:52 . 2008-04-14 00:11 61440 c:\windows\system32\kmsvc.dll + 2005-09-09 22:03 . 2008-04-14 00:11 15872 c:\windows\system32\jsproxy.dll + 2005-09-09 22:03 . 2008-04-14 00:11 27648 c:\windows\system32\jgpl400.dll - 2005-09-09 22:03 . 2006-06-01 18:47 27648 c:\windows\system32\jgpl400.dll + 2004-08-04 00:56 . 2008-04-14 00:11 47616 c:\windows\system32\iyuv_32.dll - 2004-08-04 00:56 . 2004-08-04 12:00 47616 c:\windows\system32\iyuv_32.dll + 2005-09-09 22:03 . 2008-04-14 00:11 54272 c:\windows\system32\ixsso.dll - 2005-09-09 22:03 . 2004-08-04 12:00 54272 c:\windows\system32\ixsso.dll - 2005-11-25 08:59 . 2004-08-04 12:00 32768 c:\windows\system32\isrdbg32.dll + 2005-11-25 08:59 . 2008-04-14 00:11 32768 c:\windows\system32\isrdbg32.dll - 2005-11-25 08:59 . 2004-08-04 12:00 81920 c:\windows\system32\isign32.dll + 2005-11-25 08:59 . 2008-04-14 00:11 81920 c:\windows\system32\isign32.dll + 2005-09-09 22:03 . 2008-04-14 00:11 22016 c:\windows\system32\ipxwan.dll - 2005-09-09 22:03 . 2004-08-04 12:00 23552 c:\windows\system32\ipxroute.exe + 2005-09-09 22:03 . 2008-04-14 00:12 23552 c:\windows\system32\ipxroute.exe + 2005-09-09 22:03 . 2008-04-14 00:11 59904 c:\windows\system32\ipv6mon.dll - 2005-09-09 22:03 . 2004-08-04 12:00 59904 c:\windows\system32\ipv6mon.dll + 2005-09-09 22:03 . 2008-04-14 00:12 53248 c:\windows\system32\ipv6.exe - 2005-09-09 22:03 . 2004-08-04 12:00 53248 c:\windows\system32\ipv6.exe - 2005-09-09 22:03 . 2006-05-19 12:59 94720 c:\windows\system32\iphlpapi.dll + 2005-09-09 22:03 . 2008-04-14 00:11 94720 c:\windows\system32\iphlpapi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 55808 c:\windows\system32\ipconfig.exe - 2005-09-09 22:03 . 2004-08-04 12:00 55808 c:\windows\system32\ipconfig.exe + 2005-09-09 22:03 . 2008-04-14 00:11 96256 c:\windows\system32\inseng.dll - 2005-09-09 22:03 . 2009-02-20 08:14 96256 c:\windows\system32\inseng.dll - 2005-11-25 08:59 . 2004-08-04 12:00 48128 c:\windows\system32\inetres.dll + 2005-11-25 08:59 . 2008-04-13 16:22 48128 c:\windows\system32\inetres.dll + 2005-09-09 22:03 . 2008-04-14 00:11 15872 c:\windows\system32\inetppui.dll - 2005-09-09 22:03 . 2004-08-04 12:00 15872 c:\windows\system32\inetppui.dll - 2005-09-09 22:03 . 2004-08-04 12:00 75264 c:\windows\system32\inetpp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 75264 c:\windows\system32\inetpp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 32768 c:\windows\system32\inetmib1.dll + 2005-09-09 22:03 . 2008-04-14 00:11 35840 c:\windows\system32\imgutil.dll - 2005-09-09 22:03 . 2004-08-04 12:00 35840 c:\windows\system32\imgutil.dll - 2005-09-09 22:03 . 2004-08-04 12:00 36921 c:\windows\system32\imeshare.dll + 2005-09-09 22:03 . 2008-04-14 00:11 36921 c:\windows\system32\imeshare.dll + 2005-11-25 08:59 . 2008-04-14 00:11 81920 c:\windows\system32\ils.dll - 2005-11-25 08:59 . 2004-08-04 12:00 81920 c:\windows\system32\ils.dll + 2005-09-09 22:03 . 2008-04-14 00:11 62976 c:\windows\system32\iesetup.dll - 2005-09-09 22:03 . 2004-08-04 12:00 62976 c:\windows\system32\iesetup.dll + 2005-09-09 22:03 . 2008-04-14 00:11 48640 c:\windows\system32\iernonce.dll - 2005-09-09 22:03 . 2004-08-04 12:00 48640 c:\windows\system32\iernonce.dll + 2005-09-09 22:03 . 2008-04-14 00:12 34304 c:\windows\system32\ie4uinit.exe - 2005-09-09 22:03 . 2004-08-04 12:00 34304 c:\windows\system32\ie4uinit.exe + 2005-11-25 08:59 . 2008-04-14 00:11 65536 c:\windows\system32\icwphbk.dll - 2005-11-25 08:59 . 2004-08-04 12:00 65536 c:\windows\system32\icwphbk.dll - 2005-11-25 08:59 . 2004-08-04 12:00 73728 c:\windows\system32\icwdial.dll + 2005-11-25 08:59 . 2008-04-14 00:11 73728 c:\windows\system32\icwdial.dll - 2005-09-09 22:03 . 2004-08-04 12:00 80384 c:\windows\system32\iccvid.dll + 2005-09-09 22:03 . 2008-04-14 00:11 80384 c:\windows\system32\iccvid.dll - 2005-11-25 08:58 . 2004-08-04 12:00 11264 c:\windows\system32\icaapi.dll + 2005-11-25 08:58 . 2008-04-14 00:11 11264 c:\windows\system32\icaapi.dll + 2005-09-09 22:03 . 2008-04-14 00:11 41984 c:\windows\system32\htui.dll - 2005-09-09 22:03 . 2004-08-04 12:00 41984 c:\windows\system32\htui.dll - 2005-09-09 22:03 . 2004-08-04 12:00 24576 c:\windows\system32\httpapi.dll + 2005-09-09 22:03 . 2008-04-14 00:11 24576 c:\windows\system32\httpapi.dll - 2007-09-22 16:26 . 2004-08-03 23:56 32285 c:\windows\system32\hsfcisp2.dll + 2007-09-22 16:26 . 2008-04-14 00:11 32285 c:\windows\system32\hsfcisp2.dll - 2005-09-09 22:03 . 2006-07-21 08:24 72704 c:\windows\system32\hlink.dll + 2005-09-09 22:03 . 2008-04-14 00:11 72704 c:\windows\system32\hlink.dll - 2006-12-28 14:45 . 2004-08-04 00:56 21504 c:\windows\system32\hidserv.dll + 2006-12-28 14:45 . 2008-04-14 00:11 21504 c:\windows\system32\hidserv.dll - 2004-08-04 00:56 . 2004-08-04 12:00 20992 c:\windows\system32\hid.dll + 2004-08-04 00:56 . 2008-04-14 00:11 20992 c:\windows\system32\hid.dll + 2005-09-09 22:03 . 2008-04-14 00:11 41472 c:\windows\system32\hhsetup.dll - 2005-09-09 22:03 . 2005-05-27 02:04 41472 c:\windows\system32\hhsetup.dll + 2005-09-09 22:03 . 2008-04-14 00:12 15872 c:\windows\system32\help.exe - 2005-09-09 22:03 . 2004-08-04 12:00 39424 c:\windows\system32\grpconv.exe + 2005-09-09 22:03 . 2008-04-14 00:12 39424 c:\windows\system32\grpconv.exe + 2005-11-25 09:03 . 2008-04-14 00:11 23552 c:\windows\system32\fxsmon.dll - 2005-11-25 09:03 . 2004-08-04 12:00 23552 c:\windows\system32\fxsmon.dll + 2005-11-25 09:03 . 2008-04-14 00:11 23552 c:\windows\system32\fxsext32.dll - 2005-11-25 09:03 . 2004-08-04 12:00 23552 c:\windows\system32\fxsext32.dll - 2005-11-25 09:03 . 2004-08-04 12:00 55296 c:\windows\system32\fxsevent.dll + 2005-11-25 09:03 . 2008-04-14 00:11 55296 c:\windows\system32\fxsevent.dll + 2005-11-25 09:03 . 2008-04-14 00:11 26624 c:\windows\system32\fxsdrv.dll - 2005-11-25 09:03 . 2004-08-04 12:00 72192 c:\windows\system32\fxscom.dll + 2005-11-25 09:03 . 2008-04-14 00:11 72192 c:\windows\system32\fxscom.dll + 2005-09-09 22:03 . 2008-04-14 00:11 60416 c:\windows\system32\fwcfg.dll - 2005-09-09 22:03 . 2004-08-04 12:00 60416 c:\windows\system32\fwcfg.dll - 2005-09-09 22:03 . 2004-08-04 12:00 42496 c:\windows\system32\ftp.exe + 2005-09-09 22:03 . 2008-04-14 00:12 42496 c:\windows\system32\ftp.exe + 2005-09-09 22:03 . 2008-04-14 00:12 29696 c:\windows\system32\format.com - 2005-09-09 22:03 . 2004-08-04 12:00 20992 c:\windows\system32\fontview.exe + 2005-09-09 22:03 . 2008-04-14 00:12 20992 c:\windows\system32\fontview.exe + 2005-09-09 22:03 . 2008-04-14 00:11 80896 c:\windows\system32\fontsub.dll - 2005-09-09 22:03 . 2005-10-17 21:14 80896 c:\windows\system32\fontsub.dll + 2005-11-25 08:59 . 2008-04-14 00:12 23040 c:\windows\system32\fltmc.exe - 2005-11-25 08:59 . 2006-08-21 09:14 23040 c:\windows\system32\fltmc.exe - 2005-11-25 08:59 . 2006-08-21 12:21 16896 c:\windows\system32\fltlib.dll + 2005-11-25 08:59 . 2008-04-14 00:11 16896 c:\windows\system32\fltlib.dll - 2005-09-09 22:03 . 2004-08-04 12:00 87552 c:\windows\system32\fldrclnr.dll + 2005-09-09 22:03 . 2008-04-14 00:11 87552 c:\windows\system32\fldrclnr.dll + 2005-09-09 22:03 . 2008-04-14 00:12 27136 c:\windows\system32\findstr.exe - 2005-09-09 22:03 . 2004-08-04 12:00 27136 c:\windows\system32\findstr.exe + 2005-09-09 22:03 . 2008-04-14 00:11 21504 c:\windows\system32\feclient.dll - 2005-09-09 22:03 . 2004-08-04 12:00 21504 c:\windows\system32\feclient.dll + 2007-09-22 16:26 . 2008-04-14 00:12 20992 c:\windows\system32\faxpatch.exe - 2007-09-22 16:26 . 2004-08-03 23:56 20992 c:\windows\system32\faxpatch.exe - 2005-09-09 22:03 . 2004-08-04 12:00 80384 c:\windows\system32\faultrep.dll + 2005-09-09 22:03 . 2008-04-14 00:11 80384 c:\windows\system32\faultrep.dll + 2005-09-09 22:03 . 2008-04-14 00:12 24064 c:\windows\system32\extrac32.exe - 2005-09-09 22:03 . 2009-02-20 08:14 55808 c:\windows\system32\extmgr.dll + 2005-09-09 22:03 . 2008-04-14 00:11 55808 c:\windows\system32\extmgr.dll + 2005-09-09 22:03 . 2008-04-14 00:11 56320 c:\windows\system32\eventlog.dll + 2005-09-09 22:03 . 2008-04-14 00:11 23040 c:\windows\system32\ersvc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 23040 c:\windows\system32\ersvc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 20480 c:\windows\system32\encapi.dll + 2005-09-09 22:03 . 2008-04-14 00:11 20480 c:\windows\system32\encapi.dll + 2008-09-08 22:52 . 2008-04-14 00:11 40960 c:\windows\system32\en\mmcex.resources.dll + 2008-09-08 22:52 . 2008-04-14 00:11 28672 c:\windows\system32\en\microsoft.managementconsole.resources.dll + 2008-09-08 22:52 . 2008-04-14 00:11 33792 c:\windows\system32\eapsvc.dll + 2008-09-08 22:52 . 2008-04-14 00:11 59392 c:\windows\system32\eapqec.dll + 2008-09-08 22:52 . 2008-04-14 00:11 40960 c:\windows\system32\eappprxy.dll + 2008-09-08 22:52 . 2008-04-14 00:11 94208 c:\windows\system32\eappgnui.dll + 2008-09-08 22:52 . 2008-04-14 00:11 30720 c:\windows\system32\eapolqec.dll + 2005-09-09 22:03 . 2008-04-14 00:12 17920 c:\windows\system32\dvdupgrd.exe - 2005-09-09 22:03 . 2004-08-04 12:00 17920 c:\windows\system32\dvdupgrd.exe - 2005-09-09 22:03 . 2004-08-04 12:00 10752 c:\windows\system32\dumprep.exe + 2005-09-09 22:03 . 2008-04-14 00:12 10752 c:\windows\system32\dumprep.exe - 2005-09-09 22:03 . 2004-08-04 12:00 19456 c:\windows\system32\dswave.dll + 2005-09-09 22:03 . 2008-04-14 00:11 19456 c:\windows\system32\dswave.dll - 2005-09-09 22:03 . 2004-08-04 12:00 51200 c:\windows\system32\dssec.dll + 2005-09-09 22:03 . 2008-04-14 00:11 51200 c:\windows\system32\dssec.dll - 2005-09-09 22:03 . 2004-08-04 12:00 92672 c:\windows\system32\dskquota.dll + 2005-09-09 22:03 . 2008-04-14 00:11 92672 c:\windows\system32\dskquota.dll + 2005-09-09 22:03 . 2008-04-14 00:11 71680 c:\windows\system32\dsdmoprp.dll - 2005-09-09 22:03 . 2004-08-04 12:00 71680 c:\windows\system32\dsdmoprp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 16384 c:\windows\system32\ds32gt.dll - 2005-09-09 22:03 . 2004-08-04 12:00 16384 c:\windows\system32\ds32gt.dll + 2005-09-09 22:03 . 2008-04-14 00:11 14336 c:\windows\system32\drprov.dll - 2005-09-09 22:03 . 2004-08-04 12:00 14336 c:\windows\system32\drprov.dll + 2007-01-01 19:25 . 2008-04-13 18:46 19200 c:\windows\system32\drivers\wstcodec.sys + 2006-01-06 17:24 . 2008-04-13 19:17 83072 c:\windows\system32\drivers\wdmaud.sys - 2005-09-09 22:03 . 2004-08-04 12:00 34560 c:\windows\system32\drivers\wanarp.sys + 2005-09-09 22:03 . 2008-04-13 18:57 34560 c:\windows\system32\drivers\wanarp.sys + 2007-09-22 16:26 . 2008-04-13 18:43 14208 c:\windows\system32\drivers\wacompen.sys + 2005-09-09 22:03 . 2008-04-13 18:41 52352 c:\windows\system32\drivers\volsnap.sys - 2005-09-09 22:03 . 2004-08-04 12:00 52352 c:\windows\system32\drivers\volsnap.sys + 2005-09-09 22:03 . 2008-04-13 18:44 81664 c:\windows\system32\drivers\videoprt.sys + 2005-11-25 09:49 . 2008-04-13 18:36 42240 c:\windows\system32\drivers\viaagp.sys - 2005-11-25 09:49 . 2004-08-03 23:07 42240 c:\windows\system32\drivers\VIAAGP.SYS - 2005-09-09 22:03 . 2004-08-04 12:00 20992 c:\windows\system32\drivers\vga.sys + 2005-09-09 22:03 . 2008-04-13 18:44 20992 c:\windows\system32\drivers\vga.sys - 2007-09-22 16:26 . 2004-08-03 23:56 11325 c:\windows\system32\drivers\vchnt5.dll + 2007-09-22 16:26 . 2008-04-14 00:12 11325 c:\windows\system32\drivers\vchnt5.dll + 2006-01-06 17:40 . 2008-04-13 18:45 26368 c:\windows\system32\drivers\usbstor.sys - 2006-01-10 18:47 . 2004-08-03 23:01 25856 c:\windows\system32\drivers\usbprint.sys + 2006-01-10 18:47 . 2008-04-13 18:47 25856 c:\windows\system32\drivers\usbprint.sys + 2006-01-06 17:18 . 2008-04-13 18:45 17152 c:\windows\system32\drivers\usbohci.sys + 2004-08-03 23:08 . 2008-04-13 18:45 15872 c:\windows\system32\drivers\usbintel.sys + 2006-01-06 17:18 . 2008-04-13 18:45 59520 c:\windows\system32\drivers\usbhub.sys + 2006-01-06 17:18 . 2008-04-13 18:45 30208 c:\windows\system32\drivers\usbehci.sys + 2006-12-07 07:27 . 2008-04-13 18:45 32128 c:\windows\system32\drivers\usbccgp.sys + 2001-08-17 14:03 . 2008-04-13 18:45 25728 c:\windows\system32\drivers\usbcamd2.sys + 2001-08-17 14:03 . 2008-04-13 18:45 25600 c:\windows\system32\drivers\usbcamd.sys + 2007-09-22 16:26 . 2008-04-13 18:56 12800 c:\windows\system32\drivers\usb8023x.sys + 2005-09-09 22:03 . 2008-04-13 18:56 12800 c:\windows\system32\drivers\usb8023.sys + 2005-09-09 22:03 . 2008-04-13 18:32 66048 c:\windows\system32\drivers\udfs.sys - 2007-09-22 16:26 . 2004-08-03 22:07 44672 c:\windows\system32\drivers\uagp35.sys + 2007-09-22 16:26 . 2008-04-13 18:36 44672 c:\windows\system32\drivers\uagp35.sys + 2004-08-03 23:03 . 2008-04-13 18:56 12288 c:\windows\system32\drivers\tunmp.sys + 2005-11-25 08:58 . 2008-04-14 00:13 40840 c:\windows\system32\drivers\termdd.sys - 2005-11-25 08:58 . 2004-08-04 01:01 40840 c:\windows\system32\drivers\termdd.sys + 2005-11-25 08:58 . 2008-04-14 00:13 21896 c:\windows\system32\drivers\tdtcp.sys - 2005-11-25 08:58 . 2004-08-04 12:00 21896 c:\windows\system32\drivers\tdtcp.sys + 2005-11-25 08:58 . 2008-04-14 00:13 12040 c:\windows\system32\drivers\tdpipe.sys - 2005-11-25 08:58 . 2004-08-04 12:00 12040 c:\windows\system32\drivers\tdpipe.sys + 2005-09-09 22:03 . 2008-04-13 19:00 19072 c:\windows\system32\drivers\tdi.sys + 2005-09-09 22:03 . 2008-04-13 18:40 14976 c:\windows\system32\drivers\tape.sys - 2005-09-09 22:03 . 2004-08-04 12:00 14976 c:\windows\system32\drivers\tape.sys - 2006-01-06 17:24 . 2004-08-03 23:15 60800 c:\windows\system32\drivers\sysaudio.sys + 2006-01-06 17:24 . 2008-04-13 19:15 60800 c:\windows\system32\drivers\sysaudio.sys + 2006-01-06 17:24 . 2008-04-13 18:45 56576 c:\windows\system32\drivers\swmidi.sys + 2007-01-01 19:25 . 2008-04-13 18:46 15232 c:\windows\system32\drivers\streamip.sys + 2004-08-03 23:08 . 2008-04-13 18:45 49408 c:\windows\system32\drivers\stream.sys + 2005-11-25 08:59 . 2008-04-13 18:36 73472 c:\windows\system32\drivers\sr.sys - 2005-11-25 08:59 . 2004-08-04 12:00 73472 c:\windows\system32\drivers\sr.sys + 2004-08-03 23:09 . 2008-04-13 18:46 25344 c:\windows\system32\drivers\sonydcam.sys - 2007-01-01 19:25 . 2004-08-03 23:10 11136 c:\windows\system32\drivers\SLIP.sys + 2007-01-01 19:25 . 2008-04-13 18:46 11136 c:\windows\system32\drivers\slip.sys + 2005-11-25 09:48 . 2008-04-13 18:36 40960 c:\windows\system32\drivers\sisagp.sys - 2004-08-03 22:59 . 2004-08-04 12:00 11392 c:\windows\system32\drivers\sfloppy.sys + 2004-08-03 22:59 . 2008-04-13 18:40 11392 c:\windows\system32\drivers\sfloppy.sys + 2004-08-03 22:59 . 2008-04-13 18:40 11008 c:\windows\system32\drivers\sffp_sd.sys + 2008-09-08 22:53 . 2008-04-13 18:40 10240 c:\windows\system32\drivers\sffp_mmc.sys + 2004-08-03 22:59 . 2008-04-13 18:40 11904 c:\windows\system32\drivers\sffdisk.sys + 2004-08-03 23:15 . 2008-04-13 19:15 64512 c:\windows\system32\drivers\serial.sys + 2004-08-03 22:59 . 2008-04-13 18:40 15744 c:\windows\system32\drivers\serenum.sys + 2004-08-03 23:07 . 2008-04-13 18:36 79232 c:\windows\system32\drivers\sdbus.sys + 2004-08-03 22:59 . 2008-04-13 18:40 96384 c:\windows\system32\drivers\scsiport.sys + 2007-09-22 16:26 . 2008-04-13 18:56 30592 c:\windows\system32\drivers\rndismpx.sys + 2005-09-09 22:03 . 2008-04-13 18:56 30592 c:\windows\system32\drivers\rndismp.sys + 2007-09-22 16:26 . 2008-04-13 18:46 59136 c:\windows\system32\drivers\rfcomm.sys + 2006-01-06 17:17 . 2008-04-13 18:40 57600 c:\windows\system32\drivers\redbook.sys + 2005-09-09 22:03 . 2008-04-13 19:19 48384 c:\windows\system32\drivers\raspptp.sys - 2005-09-09 22:03 . 2004-08-04 12:00 48384 c:\windows\system32\drivers\raspptp.sys + 2005-09-09 22:03 . 2008-04-13 18:57 41472 c:\windows\system32\drivers\raspppoe.sys - 2005-09-09 22:03 . 2004-08-04 12:00 41472 c:\windows\system32\drivers\raspppoe.sys + 2005-09-09 22:03 . 2008-04-13 19:19 51328 c:\windows\system32\drivers\rasl2tp.sys - 2005-09-09 22:03 . 2004-08-04 12:00 51328 c:\windows\system32\drivers\rasl2tp.sys + 2005-09-09 22:03 . 2008-04-13 18:56 69120 c:\windows\system32\drivers\psched.sys - 2005-09-09 22:03 . 2004-08-04 12:00 69120 c:\windows\system32\drivers\psched.sys + 2004-08-03 22:59 . 2008-04-13 18:31 35840 c:\windows\system32\drivers\processr.sys + 2004-08-03 22:59 . 2008-04-13 18:40 24960 c:\windows\system32\drivers\pciidex.sys - 2004-08-03 23:07 . 2004-08-03 23:07 68224 c:\windows\system32\drivers\pci.sys + 2004-08-03 23:07 . 2008-04-13 18:36 68224 c:\windows\system32\drivers\pci.sys + 2005-09-09 22:03 . 2008-04-13 18:40 19712 c:\windows\system32\drivers\partmgr.sys + 2004-08-03 22:59 . 2008-04-13 18:40 80128 c:\windows\system32\drivers\parport.sys - 2004-08-03 22:59 . 2004-08-04 12:00 80128 c:\windows\system32\drivers\parport.sys + 2004-08-03 22:59 . 2008-04-13 18:31 42752 c:\windows\system32\drivers\p3.sys + 2005-09-09 22:03 . 2008-04-13 18:56 88320 c:\windows\system32\drivers\nwlnkipx.sys - 2005-09-09 22:03 . 2004-08-04 12:00 30848 c:\windows\system32\drivers\npfs.sys + 2005-09-09 22:03 . 2008-04-13 18:32 30848 c:\windows\system32\drivers\npfs.sys + 2005-09-09 22:03 . 2008-04-13 18:53 40320 c:\windows\system32\drivers\nmnt.sys - 2005-09-09 22:03 . 2004-08-04 12:00 40320 c:\windows\system32\drivers\nmnt.sys + 2004-08-03 22:58 . 2008-04-13 18:51 61824 c:\windows\system32\drivers\nic1394.sys - 2004-08-03 22:58 . 2004-08-04 12:00 61824 c:\windows\system32\drivers\nic1394.sys + 2005-09-09 22:03 . 2008-04-13 18:56 34688 c:\windows\system32\drivers\netbios.sys + 2005-09-09 22:03 . 2008-04-13 18:57 40576 c:\windows\system32\drivers\ndproxy.sys + 2005-09-09 22:03 . 2008-04-13 19:20 91520 c:\windows\system32\drivers\ndiswan.sys + 2004-08-03 23:03 . 2008-04-13 18:55 14592 c:\windows\system32\drivers\ndisuio.sys + 2005-09-09 22:03 . 2008-04-13 18:57 10112 c:\windows\system32\drivers\ndistapi.sys + 2007-01-01 19:25 . 2008-04-13 18:46 10880 c:\windows\system32\drivers\ndisip.sys - 2007-01-01 19:25 . 2004-08-03 23:10 10880 c:\windows\system32\drivers\NdisIP.sys + 2007-01-01 19:25 . 2008-04-13 18:46 85248 c:\windows\system32\drivers\nabtsfec.sys - 2007-09-22 16:26 . 2004-08-03 22:04 12672 c:\windows\system32\drivers\mutohpen.sys + 2007-09-22 16:26 . 2008-04-13 18:43 12672 c:\windows\system32\drivers\mutohpen.sys - 2004-08-03 23:07 . 2004-08-03 23:07 15488 c:\windows\system32\drivers\mssmbios.sys + 2004-08-03 23:07 . 2008-04-13 18:36 15488 c:\windows\system32\drivers\mssmbios.sys - 2005-09-09 22:03 . 2004-08-04 12:00 35072 c:\windows\system32\drivers\msgpc.sys + 2005-09-09 22:03 . 2008-04-13 18:56 35072 c:\windows\system32\drivers\msgpc.sys - 2005-09-09 22:03 . 2004-08-04 12:00 19072 c:\windows\system32\drivers\msfs.sys + 2005-09-09 22:03 . 2008-04-13 18:32 19072 c:\windows\system32\drivers\msfs.sys + 2005-09-09 22:03 . 2008-04-13 18:39 42368 c:\windows\system32\drivers\mountmgr.sys + 2004-08-03 22:58 . 2008-04-13 18:39 23040 c:\windows\system32\drivers\mouclass.sys - 2004-08-03 22:58 . 2004-08-03 22:58 23040 c:\windows\system32\drivers\mouclass.sys + 2004-08-03 23:08 . 2008-04-13 19:00 30080 c:\windows\system32\drivers\modem.sys - 2004-08-03 23:08 . 2004-08-04 12:00 30080 c:\windows\system32\drivers\modem.sys + 2004-08-03 23:07 . 2008-04-13 18:36 63744 c:\windows\system32\drivers\mf.sys - 2004-08-03 23:07 . 2004-08-04 12:00 63744 c:\windows\system32\drivers\mf.sys + 2005-09-09 22:03 . 2008-04-13 18:31 92288 c:\windows\system32\drivers\ksecdd.sys + 2006-12-28 14:44 . 2008-04-13 18:39 14592 c:\windows\system32\drivers\kbdhid.sys + 2004-08-03 22:58 . 2008-04-13 18:39 24576 c:\windows\system32\drivers\kbdclass.sys - 2004-08-03 22:58 . 2004-08-03 22:58 24576 c:\windows\system32\drivers\kbdclass.sys + 2001-08-17 13:58 . 2008-04-13 18:36 37248 c:\windows\system32\drivers\isapnp.sys - 2005-11-25 08:54 . 2004-08-04 12:00 11264 c:\windows\system32\drivers\irenum.sys + 2005-11-25 08:54 . 2008-04-13 18:54 11264 c:\windows\system32\drivers\irenum.sys + 2005-09-09 22:03 . 2008-04-13 19:19 75264 c:\windows\system32\drivers\ipsec.sys + 2005-09-09 22:03 . 2008-04-13 18:57 20864 c:\windows\system32\drivers\ipinip.sys + 2005-09-09 22:03 . 2008-04-13 18:53 36608 c:\windows\system32\drivers\ip6fw.sys + 2004-08-03 22:59 . 2008-04-13 18:31 36352 c:\windows\system32\drivers\intelppm.sys + 2004-08-03 23:00 . 2008-04-13 18:40 42112 c:\windows\system32\drivers\imapi.sys + 2004-08-03 23:14 . 2008-04-13 19:18 52480 c:\windows\system32\drivers\i8042prt.sys - 2005-11-25 09:55 . 2004-08-03 23:00 18560 c:\windows\system32\drivers\i2omp.sys + 2005-11-25 09:55 . 2008-04-13 18:41 18560 c:\windows\system32\drivers\i2omp.sys + 2006-01-06 17:18 . 2008-04-13 18:45 10368 c:\windows\system32\drivers\hidusb.sys + 2006-01-06 17:18 . 2008-04-13 18:45 24960 c:\windows\system32\drivers\hidparse.sys - 2006-01-06 17:18 . 2004-08-03 23:08 24960 c:\windows\system32\drivers\hidparse.sys + 2007-09-22 16:26 . 2008-04-13 18:45 19200 c:\windows\system32\drivers\hidir.sys + 2006-01-06 17:18 . 2008-04-13 18:45 36864 c:\windows\system32\drivers\hidclass.sys + 2007-09-22 16:26 . 2008-04-13 18:46 25600 c:\windows\system32\drivers\hidbth.sys - 2007-09-22 16:26 . 2004-08-03 22:10 25600 c:\windows\system32\drivers\hidbth.sys - 2007-09-22 16:26 . 2004-08-03 22:07 46464 c:\windows\system32\drivers\gagp30kx.sys + 2007-09-22 16:26 . 2008-04-13 18:36 46464 c:\windows\system32\drivers\gagp30kx.sys + 2004-08-03 22:59 . 2008-04-13 18:40 20480 c:\windows\system32\drivers\flpydisk.sys - 2004-08-03 22:59 . 2004-08-04 12:00 20480 c:\windows\system32\drivers\flpydisk.sys + 2005-09-09 22:03 . 2008-04-13 18:33 44544 c:\windows\system32\drivers\fips.sys - 2004-08-03 22:59 . 2004-08-04 12:00 27392 c:\windows\system32\drivers\fdc.sys + 2004-08-03 22:59 . 2008-04-13 18:40 27392 c:\windows\system32\drivers\fdc.sys + 2004-08-03 23:00 . 2008-04-13 18:38 71168 c:\windows\system32\drivers\dxg.sys + 2006-01-06 17:24 . 2008-04-13 18:45 60160 c:\windows\system32\drivers\drmk.sys - 2006-01-06 17:24 . 2004-08-03 23:07 52864 c:\windows\system32\drivers\DMusic.sys + 2006-01-06 17:24 . 2008-04-13 18:45 52864 c:\windows\system32\drivers\dmusic.sys - 2005-09-09 22:03 . 2004-08-04 12:00 14208 c:\windows\system32\drivers\diskdump.sys + 2005-09-09 22:03 . 2008-04-13 18:40 14208 c:\windows\system32\drivers\diskdump.sys - 2004-08-03 22:59 . 2004-08-04 12:00 36352 c:\windows\system32\drivers\disk.sys + 2004-08-03 22:59 . 2008-04-13 18:40 36352 c:\windows\system32\drivers\disk.sys + 2004-08-03 22:59 . 2008-04-13 18:31 36736 c:\windows\system32\drivers\crusoe.sys + 2005-09-09 22:03 . 2008-04-13 19:16 49536 c:\windows\system32\drivers\classpnp.sys - 2007-09-22 16:26 . 2004-08-03 23:56 15423 c:\windows\system32\drivers\ch7xxnt5.dll + 2007-09-22 16:26 . 2008-04-14 00:11 15423 c:\windows\system32\drivers\ch7xxnt5.dll + 2004-08-03 22:59 . 2008-04-13 18:40 62976 c:\windows\system32\drivers\cdrom.sys + 2005-09-09 22:03 . 2008-04-13 19:14 63744 c:\windows\system32\drivers\cdfs.sys - 2005-09-09 22:03 . 2004-08-04 12:00 63744 c:\windows\system32\drivers\cdfs.sys + 2007-01-01 19:25 . 2008-04-13 18:46 17024 c:\windows\system32\drivers\ccdecode.sys - 2007-01-01 19:25 . 2004-08-03 23:10 17024 c:\windows\system32\drivers\CCDECODE.sys + 2007-09-22 16:26 . 2008-04-13 18:46 18944 c:\windows\system32\drivers\bthusb.sys - 2007-09-22 16:26 . 2004-08-03 22:10 18944 c:\windows\system32\drivers\bthusb.sys + 2007-09-22 16:26 . 2008-04-13 18:46 36480 c:\windows\system32\drivers\bthprint.sys + 2007-09-22 16:26 . 2008-04-13 18:46 37888 c:\windows\system32\drivers\bthmodem.sys + 2007-09-22 16:26 . 2008-04-13 18:46 17024 c:\windows\system32\drivers\bthenum.sys - 2007-09-22 16:26 . 2004-08-03 22:10 17024 c:\windows\system32\drivers\bthenum.sys + 2005-09-09 22:03 . 2008-04-13 18:53 71552 c:\windows\system32\drivers\bridge.sys - 2005-09-09 22:03 . 2004-08-04 12:00 71552 c:\windows\system32\drivers\bridge.sys + 2007-09-22 16:26 . 2008-04-14 00:11 17279 c:\windows\system32\drivers\atv10nt5.dll - 2007-09-22 16:26 . 2004-08-03 23:56 17279 c:\windows\system32\drivers\atv10nt5.dll + 2007-09-22 16:26 . 2008-04-14 00:11 14143 c:\windows\system32\drivers\atv06nt5.dll - 2007-09-22 16:26 . 2004-08-03 23:56 14143 c:\windows\system32\drivers\atv06nt5.dll - 2007-09-22 16:26 . 2004-08-03 23:56 25471 c:\windows\system32\drivers\atv04nt5.dll + 2007-09-22 16:26 . 2008-04-14 00:11 25471 c:\windows\system32\drivers\atv04nt5.dll - 2007-09-22 16:26 . 2004-08-03 23:56 11359 c:\windows\system32\drivers\atv02nt5.dll + 2007-09-22 16:26 . 2008-04-14 00:11 11359 c:\windows\system32\drivers\atv02nt5.dll + 2007-09-22 16:26 . 2008-04-14 00:11 21183 c:\windows\system32\drivers\atv01nt5.dll - 2007-09-22 16:26 . 2004-08-03 23:56 21183 c:\windows\system32\drivers\atv01nt5.dll + 2005-09-09 22:03 . 2008-04-13 18:51 55808 c:\windows\system32\drivers\atmlane.sys - 2005-09-09 22:03 . 2004-08-04 12:00 59904 c:\windows\system32\drivers\atmarpc.sys + 2005-09-09 22:03 . 2008-04-13 18:51 59904 c:\windows\system32\drivers\atmarpc.sys + 2004-08-03 22:59 . 2008-04-13 18:40 96512 c:\windows\system32\drivers\atapi.sys + 2005-09-09 22:03 . 2008-04-13 18:57 14336 c:\windows\system32\drivers\asyncmac.sys - 2005-09-09 22:03 . 2004-08-04 12:00 14336 c:\windows\system32\drivers\asyncmac.sys + 2004-08-03 22:58 . 2008-04-13 18:51 60800 c:\windows\system32\drivers\arp1394.sys - 2004-08-03 22:58 . 2004-08-04 12:00 60800 c:\windows\system32\drivers\arp1394.sys + 2004-08-03 22:59 . 2008-04-13 18:31 37760 c:\windows\system32\drivers\amdk7.sys + 2004-08-03 22:59 . 2008-04-13 18:31 37376 c:\windows\system32\drivers\amdk6.sys - 2005-11-25 09:42 . 2004-08-03 23:07 43008 c:\windows\system32\drivers\AMDAGP.SYS + 2005-11-25 09:42 . 2008-04-13 18:36 43008 c:\windows\system32\drivers\amdagp.sys + 2005-11-25 09:42 . 2008-04-13 18:36 42752 c:\windows\system32\drivers\alim1541.sys - 2005-11-25 09:42 . 2004-08-03 23:07 42752 c:\windows\system32\drivers\ALIM1541.SYS - 2005-11-25 09:48 . 2004-08-03 23:07 44928 c:\windows\system32\drivers\AGPCPQ.SYS + 2005-11-25 09:48 . 2008-04-13 18:36 44928 c:\windows\system32\drivers\agpcpq.sys - 2005-11-25 09:44 . 2004-08-03 23:07 42368 c:\windows\system32\drivers\AGP440.SYS + 2005-11-25 09:44 . 2008-04-13 18:36 42368 c:\windows\system32\drivers\agp440.sys - 2005-09-09 22:03 . 2004-08-04 12:00 57344 c:\windows\system32\dpwsockx.dll + 2005-09-09 22:03 . 2008-04-14 00:11 57344 c:\windows\system32\dpwsockx.dll - 2005-09-09 22:03 . 2004-08-04 12:00 83456 c:\windows\system32\dpvsetup.exe + 2005-09-09 22:03 . 2008-04-14 00:12 83456 c:\windows\system32\dpvsetup.exe + 2005-09-09 22:03 . 2008-04-14 00:11 21504 c:\windows\system32\dpvacm.dll - 2005-09-09 22:03 . 2004-08-04 12:00 21504 c:\windows\system32\dpvacm.dll + 2005-09-09 22:03 . 2008-04-14 00:12 17920 c:\windows\system32\dpnsvr.exe - 2005-09-09 22:03 . 2004-08-04 12:00 60928 c:\windows\system32\dpnhupnp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 60928 c:\windows\system32\dpnhupnp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 35328 c:\windows\system32\dpnhpast.dll - 2005-09-09 22:03 . 2004-08-04 12:00 35328 c:\windows\system32\dpnhpast.dll - 2005-09-09 22:03 . 2004-08-04 12:00 23552 c:\windows\system32\dpmodemx.dll + 2005-09-09 22:03 . 2008-04-14 00:11 23552 c:\windows\system32\dpmodemx.dll + 2005-09-09 22:03 . 2008-04-14 00:12 29696 c:\windows\system32\dplaysvr.exe + 2008-09-08 22:52 . 2008-04-14 00:11 56320 c:\windows\system32\dot3msm.dll + 2008-09-08 22:52 . 2008-04-14 00:11 39936 c:\windows\system32\dot3gpclnt.dll + 2008-09-08 22:52 . 2008-04-14 00:11 57856 c:\windows\system32\dot3cfg.dll + 2008-09-08 22:52 . 2008-04-14 00:11 26112 c:\windows\system32\dot3api.dll - 2005-09-09 22:03 . 2004-08-04 12:00 48128 c:\windows\system32\docprop2.dll + 2005-09-09 22:03 . 2008-04-14 00:11 48128 c:\windows\system32\docprop2.dll - 2005-09-09 22:03 . 2008-02-20 05:32 45568 c:\windows\system32\dnsrslvr.dll + 2005-09-09 22:03 . 2008-04-14 00:11 45568 c:\windows\system32\dnsrslvr.dll - 2004-08-04 00:56 . 2004-08-04 12:00 52224 c:\windows\system32\dmutil.dll + 2004-08-04 00:56 . 2008-04-14 00:11 52224 c:\windows\system32\dmutil.dll - 2005-09-09 22:03 . 2004-08-04 12:00 23552 c:\windows\system32\dmserver.dll + 2005-09-09 22:03 . 2008-04-14 00:11 23552 c:\windows\system32\dmserver.dll - 2005-09-09 22:03 . 2004-08-04 12:00 82432 c:\windows\system32\dmscript.dll + 2005-09-09 22:03 . 2008-04-14 00:11 82432 c:\windows\system32\dmscript.dll + 2005-09-09 22:03 . 2008-04-14 00:12 15872 c:\windows\system32\dmremote.exe - 2005-09-09 22:03 . 2004-08-04 12:00 15872 c:\windows\system32\dmremote.exe - 2005-09-09 22:03 . 2004-08-04 12:00 35840 c:\windows\system32\dmloader.dll + 2005-09-09 22:03 . 2008-04-14 00:11 35840 c:\windows\system32\dmloader.dll - 2005-09-09 22:03 . 2004-08-04 12:00 61440 c:\windows\system32\dmcompos.dll + 2005-09-09 22:03 . 2008-04-14 00:11 61440 c:\windows\system32\dmcompos.dll - 2005-09-09 22:03 . 2004-08-04 12:00 28672 c:\windows\system32\dmband.dll + 2005-09-09 22:03 . 2008-04-14 00:11 28672 c:\windows\system32\dmband.dll + 2009-02-03 19:59 . 2009-02-03 19:59 56832 c:\windows\system32\dllcache\secur32.dll - 2005-09-09 22:03 . 2009-02-06 16:54 35328 c:\windows\system32\dllcache\sc.exe + 2005-09-09 22:03 . 2009-02-06 10:39 35328 c:\windows\system32\dllcache\sc.exe - 2005-11-25 08:59 . 2004-08-04 12:00 10240 c:\windows\system32\dllcache\npwmsdrm.dll + 2005-11-25 08:59 . 2008-04-14 00:12 10240 c:\windows\system32\dllcache\npwmsdrm.dll - 2005-11-25 08:58 . 2008-06-12 14:16 91648 c:\windows\system32\dllcache\mtxoci.dll + 2008-06-12 14:23 . 2008-06-12 14:23 91648 c:\windows\system32\dllcache\mtxoci.dll - 2005-09-09 22:03 . 2008-06-12 14:16 66560 c:\windows\system32\dllcache\mtxclu.dll + 2008-06-12 14:23 . 2008-06-12 14:23 66560 c:\windows\system32\dllcache\mtxclu.dll + 2008-09-08 22:53 . 2008-04-13 17:27 79872 c:\windows\system32\dllcache\msxml6r.dll - 2005-11-25 08:58 . 2008-06-12 14:16 58880 c:\windows\system32\dllcache\msdtclog.dll + 2008-06-12 14:23 . 2008-06-12 14:23 58880 c:\windows\system32\dllcache\msdtclog.dll - 2005-09-09 22:03 . 2008-06-24 16:23 74240 c:\windows\system32\dllcache\mscms.dll + 2008-06-24 16:43 . 2008-06-24 16:43 74240 c:\windows\system32\dllcache\mscms.dll + 2009-02-20 08:10 . 2009-04-29 04:46 81920 c:\windows\system32\dllcache\ieencode.dll - 2005-09-09 22:03 . 2009-02-20 08:14 81920 c:\windows\system32\dllcache\ieencode.dll + 2005-09-09 22:03 . 2008-04-14 00:11 32768 c:\windows\system32\dispex.dll + 2008-09-08 22:52 . 2008-04-14 00:11 39936 c:\windows\system32\dimsroam.dll + 2008-09-08 22:52 . 2008-04-14 00:11 19456 c:\windows\system32\dimsntfy.dll + 2005-09-09 22:03 . 2008-04-14 00:11 68608 c:\windows\system32\digest.dll - 2005-09-09 22:03 . 2004-08-04 12:00 68608 c:\windows\system32\digest.dll + 2005-09-09 22:03 . 2008-04-14 00:12 87040 c:\windows\system32\diantz.exe + 2008-09-08 22:52 . 2008-04-14 00:11 48640 c:\windows\system32\dhcpqec.dll - 2005-09-09 22:03 . 2004-08-04 12:00 28672 c:\windows\system32\dfsshlex.dll + 2005-09-09 22:03 . 2008-04-14 00:11 28672 c:\windows\system32\dfsshlex.dll + 2005-09-09 22:03 . 2008-04-14 00:11 39424 c:\windows\system32\dfrgsnap.dll + 2005-09-09 22:03 . 2008-04-14 00:12 82944 c:\windows\system32\dfrgfat.exe - 2005-09-09 22:03 . 2004-08-04 12:00 59904 c:\windows\system32\devenum.dll + 2005-09-09 22:03 . 2008-04-14 00:11 59904 c:\windows\system32\devenum.dll - 2005-09-09 22:03 . 2004-08-04 12:00 25088 c:\windows\system32\defrag.exe + 2005-09-09 22:03 . 2008-04-14 00:12 25088 c:\windows\system32\defrag.exe - 2005-09-09 22:03 . 2004-08-04 12:00 27136 c:\windows\system32\ddrawex.dll + 2005-09-09 22:03 . 2008-04-14 00:11 27136 c:\windows\system32\ddrawex.dll - 2005-09-09 22:03 . 2004-08-04 12:00 30208 c:\windows\system32\ddeshare.exe + 2005-09-09 22:03 . 2008-04-14 00:12 30208 c:\windows\system32\ddeshare.exe - 2005-09-09 22:03 . 2004-08-04 12:00 28672 c:\windows\system32\dbnmpntw.dll + 2005-09-09 22:03 . 2008-04-14 00:11 28672 c:\windows\system32\dbnmpntw.dll + 2005-09-09 22:03 . 2008-04-14 00:11 24576 c:\windows\system32\dbmsrpcn.dll - 2005-09-09 22:03 . 2004-08-04 12:00 24576 c:\windows\system32\dbmsrpcn.dll + 2005-09-09 22:03 . 2008-04-14 00:11 25088 c:\windows\system32\davclnt.dll - 2005-09-09 22:03 . 2004-08-04 12:00 54272 c:\windows\system32\dataclen.dll + 2005-09-09 22:03 . 2008-04-14 00:11 54272 c:\windows\system32\dataclen.dll - 2005-09-09 22:03 . 2004-08-04 12:00 15360 c:\windows\system32\ctfmon.exe + 2005-09-09 22:03 . 2008-04-14 00:12 15360 c:\windows\system32\ctfmon.exe + 2005-09-09 22:03 . 2008-04-14 00:11 32256 c:\windows\system32\csrsrv.dll + 2005-09-09 22:03 . 2008-04-14 00:11 62464 c:\windows\system32\cryptsvc.dll + 2005-09-09 22:03 . 2008-04-14 00:11 64512 c:\windows\system32\cryptnet.dll - 2005-09-09 22:03 . 2004-08-04 12:00 53760 c:\windows\system32\cryptext.dll + 2005-09-09 22:03 . 2008-04-14 00:11 53760 c:\windows\system32\cryptext.dll + 2005-09-09 22:03 . 2008-04-14 00:11 33280 c:\windows\system32\cryptdll.dll - 2005-09-09 22:03 . 2004-08-04 12:00 33280 c:\windows\system32\cryptdll.dll - 2005-09-09 22:03 . 2004-08-04 12:00 74752 c:\windows\system32\cryptdlg.dll + 2005-09-09 22:03 . 2008-04-14 00:11 74752 c:\windows\system32\cryptdlg.dll + 2008-09-08 22:52 . 2008-04-14 00:11 12800 c:\windows\system32\credssp.dll - 2005-09-09 22:03 . 2004-08-04 12:00 35328 c:\windows\system32\corpol.dll + 2005-09-09 22:03 . 2008-04-14 00:11 35328 c:\windows\system32\corpol.dll + 2005-09-09 22:03 . 2008-04-14 00:12 27648 c:\windows\system32\conime.exe - 2005-09-09 22:03 . 2004-08-04 12:00 27648 c:\windows\system32\conime.exe - 2005-11-25 09:01 . 2009-06-29 21:52 49152 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat + 2005-11-25 09:01 . 2009-07-06 02:07 49152 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat + 2009-07-06 02:07 . 2009-07-06 02:07 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009070620090707\index.dat - 2005-11-25 09:01 . 2009-06-29 21:52 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat + 2005-11-25 09:01 . 2009-07-06 02:07 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat - 2005-11-25 09:01 . 2009-06-29 21:52 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat + 2005-11-25 09:01 . 2009-07-06 02:07 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat + 2005-11-25 08:58 . 2008-04-14 00:11 97792 c:\windows\system32\comrepl.dll - 2005-11-25 08:58 . 2005-07-26 04:39 97792 c:\windows\system32\comrepl.dll + 2005-11-25 08:58 . 2008-04-14 00:11 28160 c:\windows\system32\comaddin.dll - 2005-11-25 08:58 . 2005-07-26 04:39 60416 c:\windows\system32\colbact.dll + 2005-11-25 08:58 . 2008-04-14 00:11 60416 c:\windows\system32\colbact.dll + 2004-08-04 00:56 . 2008-04-14 00:11 47104 c:\windows\system32\cnbjmon.dll - 2004-08-04 00:56 . 2004-08-04 12:00 47104 c:\windows\system32\cnbjmon.dll + 2005-09-09 22:03 . 2008-04-14 00:11 39424 c:\windows\system32\cmutil.dll - 2005-09-09 22:03 . 2004-08-04 12:00 63488 c:\windows\system32\cmstp.exe + 2005-09-09 22:03 . 2008-04-14 00:12 63488 c:\windows\system32\cmstp.exe + 2005-09-09 22:03 . 2008-04-14 00:11 13312 c:\windows\system32\cmsetacl.dll - 2005-09-09 22:03 . 2004-08-04 12:00 39936 c:\windows\system32\cmmon32.exe + 2005-09-09 22:03 . 2008-04-14 00:12 39936 c:\windows\system32\cmmon32.exe + 2005-09-09 22:03 . 2008-04-14 00:12 25600 c:\windows\system32\cmdl32.exe + 2005-09-09 22:03 . 2008-04-14 00:11 15872 c:\windows\system32\cmcfg32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 15872 c:\windows\system32\cmcfg32.dll + 2005-09-09 22:03 . 2008-04-14 00:11 58368 c:\windows\system32\clusapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 33280 c:\windows\system32\clipsrv.exe + 2005-09-09 22:03 . 2008-04-14 00:12 33280 c:\windows\system32\clipsrv.exe + 2005-09-09 22:03 . 2008-04-14 00:12 20480 c:\windows\system32\cliconfg.exe - 2005-09-09 22:03 . 2004-08-04 12:00 20480 c:\windows\system32\cliconfg.exe - 2005-09-09 22:03 . 2004-08-04 12:00 77824 c:\windows\system32\cliconfg.dll + 2005-09-09 22:03 . 2008-04-14 00:11 77824 c:\windows\system32\cliconfg.dll + 2005-09-09 22:03 . 2008-04-14 00:12 64000 c:\windows\system32\cleanmgr.exe - 2005-09-09 22:03 . 2004-08-04 12:00 64000 c:\windows\system32\cleanmgr.exe - 2005-09-09 22:03 . 2006-06-22 05:06 69120 c:\windows\system32\ciodm.dll + 2005-09-09 22:03 . 2008-04-14 00:11 69120 c:\windows\system32\ciodm.dll - 2005-09-09 22:03 . 2004-08-04 12:00 16896 c:\windows\system32\cfgmgr32.dll + 2005-09-09 22:03 . 2008-04-14 00:09 16896 c:\windows\system32\cfgmgr32.dll + 2005-11-25 08:58 . 2008-04-14 00:11 38912 c:\windows\system32\cfgbkend.dll - 2005-11-25 08:58 . 2004-08-04 12:00 38912 c:\windows\system32\cfgbkend.dll - 2005-11-25 08:58 . 2004-08-04 12:00 85504 c:\windows\system32\catsrvps.dll + 2005-11-25 08:58 . 2008-04-14 00:11 85504 c:\windows\system32\catsrvps.dll + 2005-09-09 22:03 . 2008-04-14 00:11 50688 c:\windows\system32\camocx.dll - 2005-09-09 22:03 . 2004-08-04 12:00 50688 c:\windows\system32\camocx.dll + 2005-09-09 22:03 . 2008-04-14 00:12 19968 c:\windows\system32\cacls.exe - 2005-09-09 22:03 . 2004-08-04 12:00 84480 c:\windows\system32\cabview.dll + 2005-09-09 22:03 . 2008-04-14 00:11 84480 c:\windows\system32\cabview.dll + 2005-09-09 22:03 . 2008-04-14 00:11 60416 c:\windows\system32\cabinet.dll - 2005-09-09 22:03 . 2004-08-04 12:00 50688 c:\windows\system32\btpanui.dll + 2005-09-09 22:03 . 2008-04-14 00:11 50688 c:\windows\system32\btpanui.dll - 2004-08-04 00:56 . 2004-08-04 12:00 30208 c:\windows\system32\bthserv.dll + 2004-08-04 00:56 . 2008-04-14 00:11 30208 c:\windows\system32\bthserv.dll - 2004-08-04 00:56 . 2004-08-04 12:00 20992 c:\windows\system32\bthci.dll + 2004-08-04 00:56 . 2008-04-14 00:11 20992 c:\windows\system32\bthci.dll - 2005-09-09 22:03 . 2004-08-04 12:00 78336 c:\windows\system32\browsewm.dll + 2005-09-09 22:03 . 2008-04-14 00:11 78336 c:\windows\system32\browsewm.dll + 2005-09-09 22:03 . 2008-04-14 00:11 77824 c:\windows\system32\browser.dll + 2005-09-09 22:03 . 2008-04-13 17:03 63488 c:\windows\system32\browselc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 63488 c:\windows\system32\browselc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 71680 c:\windows\system32\blastcln.exe - 2005-09-09 22:03 . 2004-08-04 12:00 71680 c:\windows\system32\blastcln.exe - 2005-09-09 22:03 . 2004-08-04 12:00 17408 c:\windows\system32\bidispl.dll + 2005-09-09 22:03 . 2008-04-14 00:11 17408 c:\windows\system32\bidispl.dll + 2005-09-09 22:03 . 2008-04-14 00:11 29184 c:\windows\system32\batmeter.dll - 2005-09-09 22:03 . 2004-08-04 12:00 52736 c:\windows\system32\basesrv.dll + 2005-09-09 22:03 . 2008-04-14 00:11 52736 c:\windows\system32\basesrv.dll + 2005-09-09 22:03 . 2008-04-14 00:11 84992 c:\windows\system32\avifil32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 84992 c:\windows\system32\avifil32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 11264 c:\windows\system32\autolfn.exe - 2005-09-09 22:03 . 2004-08-04 12:00 11264 c:\windows\system32\autolfn.exe + 2005-09-09 22:03 . 2008-04-14 00:11 62464 c:\windows\system32\authz.dll + 2005-09-09 22:03 . 2008-04-14 00:12 14336 c:\windows\system32\auditusr.exe - 2005-09-09 22:03 . 2004-08-04 12:00 14336 c:\windows\system32\auditusr.exe + 2005-09-09 22:03 . 2008-04-14 00:11 42496 c:\windows\system32\audiosrv.dll - 2005-09-09 22:03 . 2004-08-04 12:00 42496 c:\windows\system32\audiosrv.dll + 2005-09-09 22:03 . 2008-04-14 00:12 12288 c:\windows\system32\attrib.exe - 2005-09-09 22:03 . 2004-08-04 12:00 30208 c:\windows\system32\atmlib.dll + 2005-09-09 22:03 . 2008-04-14 00:11 30208 c:\windows\system32\atmlib.dll + 2005-09-09 22:03 . 2008-04-14 00:12 11264 c:\windows\system32\atmadm.exe - 2005-09-09 22:03 . 2004-08-04 12:00 11264 c:\windows\system32\atmadm.exe + 2005-09-09 22:03 . 2008-04-14 00:11 58880 c:\windows\system32\atl.dll - 2005-09-09 22:03 . 2004-08-04 12:00 58880 c:\windows\system32\atl.dll + 2007-09-22 16:26 . 2008-04-14 00:11 32768 c:\windows\system32\ativtmxx.dll - 2007-09-22 16:26 . 2004-08-03 23:56 32768 c:\windows\system32\ativtmxx.dll + 2005-09-09 22:03 . 2008-04-14 00:12 25088 c:\windows\system32\at.exe - 2005-09-09 22:03 . 2004-08-04 12:00 25088 c:\windows\system32\at.exe - 2005-09-09 22:03 . 2004-08-04 12:00 65024 c:\windows\system32\asycfilt.dll + 2005-09-09 22:03 . 2008-04-14 00:11 65024 c:\windows\system32\asycfilt.dll + 2005-09-09 22:03 . 2008-04-14 00:11 70656 c:\windows\system32\amstream.dll - 2005-09-09 22:03 . 2004-08-04 12:00 70656 c:\windows\system32\amstream.dll + 2005-09-09 22:03 . 2008-04-14 00:11 17408 c:\windows\system32\alrsvc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 17408 c:\windows\system32\alrsvc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 44544 c:\windows\system32\alg.exe + 2005-09-09 22:03 . 2008-04-14 00:12 44544 c:\windows\system32\alg.exe + 2005-09-09 22:03 . 2008-04-14 00:12 98304 c:\windows\system32\ahui.exe - 2005-09-09 22:03 . 2004-08-04 12:00 98304 c:\windows\system32\ahui.exe + 2005-09-09 22:03 . 2008-04-14 00:11 99840 c:\windows\system32\advpack.dll - 2005-09-09 22:03 . 2004-08-04 12:00 99840 c:\windows\system32\advpack.dll - 2005-09-09 22:03 . 2004-08-04 12:00 68096 c:\windows\system32\adsmsext.dll + 2005-09-09 22:03 . 2008-04-14 00:11 68096 c:\windows\system32\adsmsext.dll + 2005-09-09 22:03 . 2008-04-14 00:11 61440 c:\windows\system32\admparse.dll - 2005-09-09 22:03 . 2004-08-04 12:00 61440 c:\windows\system32\admparse.dll + 2005-09-09 22:03 . 2008-04-14 00:11 98304 c:\windows\system32\actxprxy.dll + 2005-11-25 08:59 . 2008-04-14 00:12 58434 c:\windows\srchasst\srchctls.dll - 2005-11-25 08:59 . 2004-08-04 12:00 58434 c:\windows\srchasst\srchctls.dll + 2007-09-22 16:26 . 2008-04-14 00:12 32866 c:\windows\slrundll.exe - 2007-09-22 16:26 . 2004-08-03 23:56 32866 c:\windows\slrundll.exe + 2008-09-08 22:53 . 2008-04-14 00:11 82944 c:\windows\ServicePackFiles\ServicePackCache\i386\msgsc.dll + 2008-09-08 22:52 . 2008-04-14 00:11 33792 c:\windows\ServicePackFiles\ServicePackCache\i386\custsat.dll + 2008-09-08 22:54 . 2008-04-14 00:12 18944 c:\windows\ServicePackFiles\i386\xrxscnui.dll + 2008-09-08 22:54 . 2008-04-14 00:12 11776 c:\windows\ServicePackFiles\i386\xolehlp.dll + 2008-09-08 22:54 . 2008-04-14 00:12 50176 c:\windows\ServicePackFiles\i386\xmlprovi.dll + 2008-09-08 22:54 . 2008-04-14 00:12 30720 c:\windows\ServicePackFiles\i386\xcopy.exe + 2008-09-08 22:54 . 2008-04-14 00:12 91648 c:\windows\ServicePackFiles\i386\xactsrv.dll + 2008-09-08 22:54 . 2008-04-14 00:12 52736 c:\windows\ServicePackFiles\i386\wzcsapi.dll + 2008-09-08 22:54 . 2004-08-03 21:29 19455 c:\windows\ServicePackFiles\i386\wvchntxx.sys + 2008-09-08 22:54 . 2008-04-14 00:12 32256 c:\windows\ServicePackFiles\i386\wups.dll + 2008-09-08 22:54 . 2008-04-14 00:12 18432 c:\windows\ServicePackFiles\i386\wtsapi32.dll + 2008-09-08 22:54 . 2008-04-14 00:12 50688 c:\windows\ServicePackFiles\i386\wstdecod.dll + 2008-09-08 22:54 . 2008-04-13 18:46 19200 c:\windows\ServicePackFiles\i386\wstcodec.sys + 2008-09-08 22:54 . 2008-04-14 00:12 22528 c:\windows\ServicePackFiles\i386\wsock32.dll + 2008-09-08 22:54 . 2008-04-14 00:12 41984 c:\windows\ServicePackFiles\i386\wsnmp32.dll + 2008-09-08 22:54 . 2004-08-03 21:29 12063 c:\windows\ServicePackFiles\i386\wsiintxx.sys + 2008-09-08 22:54 . 2008-04-14 00:12 19456 c:\windows\ServicePackFiles\i386\wshtcpip.dll + 2008-09-08 22:54 . 2008-04-14 00:12 11264 c:\windows\ServicePackFiles\i386\wshrm.dll + 2008-09-08 22:54 . 2008-04-14 00:12 14336 c:\windows\ServicePackFiles\i386\wship6.dll + 2008-09-08 22:54 . 2008-04-14 00:12 90112 c:\windows\ServicePackFiles\i386\wshext.dll + 2008-09-08 22:54 . 2008-04-14 00:12 36864 c:\windows\ServicePackFiles\i386\wshcon.dll + 2008-09-08 22:54 . 2008-04-14 00:12 80896 c:\windows\ServicePackFiles\i386\wscsvc.dll + 2008-09-08 22:54 . 2008-04-14 00:12 13824 c:\windows\ServicePackFiles\i386\wscntfy.exe + 2008-09-08 22:54 . 2008-04-14 00:12 19968 c:\windows\ServicePackFiles\i386\ws2help.dll + 2008-09-08 22:54 . 2008-04-14 00:12 82432 c:\windows\ServicePackFiles\i386\ws2_32.dll + 2008-09-08 22:54 . 2008-04-14 00:12 11264 c:\windows\ServicePackFiles\i386\wpnpinst.exe + 2008-09-08 22:54 . 2008-04-14 00:12 32256 c:\windows\ServicePackFiles\i386\wpabaln.exe + 2008-09-08 22:54 . 2008-04-14 00:12 95232 c:\windows\ServicePackFiles\i386\wmiutils.dll + 2008-09-08 22:54 . 2008-04-14 00:12 41472 c:\windows\ServicePackFiles\i386\wmipsess.dll + 2008-09-08 22:54 . 2008-04-14 00:12 62464 c:\windows\ServicePackFiles\i386\wmipjobj.dll + 2008-09-08 22:54 . 2008-04-14 00:12 61952 c:\windows\ServicePackFiles\i386\wmipiprt.dll + 2008-09-08 22:54 . 2008-04-14 00:12 60928 c:\windows\ServicePackFiles\i386\wmicookr.dll + 2008-09-08 22:54 . 2008-04-14 00:12 88576 c:\windows\ServicePackFiles\i386\wmiaprpl.dll + 2008-09-08 22:54 . 2008-04-14 00:12 92672 c:\windows\ServicePackFiles\i386\wlnotify.dll + 2008-09-08 22:54 . 2008-04-14 00:12 69120 c:\windows\ServicePackFiles\i386\wlanapi.dll + 2008-09-08 22:54 . 2008-04-14 00:12 53760 c:\windows\ServicePackFiles\i386\winsta.dll + 2008-09-08 22:54 . 2008-04-14 00:12 17408 c:\windows\ServicePackFiles\i386\winshfhc.dll + 2008-09-08 22:54 . 2008-04-14 00:12 99328 c:\windows\ServicePackFiles\i386\winscard.dll + 2008-09-08 22:54 . 2008-04-14 00:12 16896 c:\windows\ServicePackFiles\i386\winrnr.dll + 2008-09-08 22:54 . 2008-04-14 00:12 32256 c:\windows\ServicePackFiles\i386\winipsec.dll + 2008-09-08 22:54 . 2008-04-14 00:12 75776 c:\windows\ServicePackFiles\i386\wiascr.dll + 2008-09-08 22:54 . 2008-04-14 00:12 65024 c:\windows\ServicePackFiles\i386\wextract.exe + 2008-09-08 22:54 . 2008-04-14 00:12 68096 c:\windows\ServicePackFiles\i386\webclnt.dll + 2008-09-08 22:54 . 2008-04-13 19:17 83072 c:\windows\ServicePackFiles\i386\wdmaud.sys + 2008-09-08 22:54 . 2008-04-14 00:12 23552 c:\windows\ServicePackFiles\i386\wdmaud.drv + 2008-09-08 22:54 . 2008-04-14 00:12 49152 c:\windows\ServicePackFiles\i386\wdigest.dll + 2008-09-08 22:54 . 2004-08-03 21:29 23615 c:\windows\ServicePackFiles\i386\wch7xxnt.sys + 2008-09-08 22:54 . 2008-04-13 18:45 31744 c:\windows\ServicePackFiles\i386\wceusbsh.sys + 2008-09-08 22:54 . 2008-04-14 00:12 43520 c:\windows\ServicePackFiles\i386\wbemsvc.dll + 2008-09-08 22:54 . 2008-04-14 00:12 18944 c:\windows\ServicePackFiles\i386\wbemprox.dll + 2008-09-08 22:54 . 2008-04-14 00:12 43008 c:\windows\ServicePackFiles\i386\wbemperf.dll + 2008-09-08 22:54 . 2008-04-14 00:12 71680 c:\windows\ServicePackFiles\i386\wbemcons.dll + 2008-09-08 22:54 . 2004-08-03 21:29 25471 c:\windows\ServicePackFiles\i386\watv10nt.sys + 2008-09-08 22:54 . 2004-08-03 21:29 22271 c:\windows\ServicePackFiles\i386\watv06nt.sys + 2008-09-08 22:54 . 2004-08-03 21:29 33599 c:\windows\ServicePackFiles\i386\watv04nt.sys + 2008-09-08 22:54 . 2004-08-03 21:29 19551 c:\windows\ServicePackFiles\i386\watv02nt.sys + 2008-09-08 22:54 . 2004-08-03 21:29 29311 c:\windows\ServicePackFiles\i386\watv01nt.sys + 2008-09-08 22:54 . 2008-04-13 18:44 17664 c:\windows\ServicePackFiles\i386\watchdog.sys + 2008-09-08 22:54 . 2008-04-13 18:57 34560 c:\windows\ServicePackFiles\i386\wanarp.sys + 2008-09-08 22:54 . 2004-08-03 21:29 11935 c:\windows\ServicePackFiles\i386\wadv11nt.sys + 2008-09-08 22:54 . 2004-08-03 21:29 11871 c:\windows\ServicePackFiles\i386\wadv09nt.sys + 2008-09-08 22:54 . 2004-08-03 21:29 11295 c:\windows\ServicePackFiles\i386\wadv08nt.sys + 2008-09-08 22:54 . 2004-08-03 21:29 11807 c:\windows\ServicePackFiles\i386\wadv07nt.sys + 2008-09-08 22:54 . 2004-08-03 21:29 11775 c:\windows\ServicePackFiles\i386\wadv05nt.sys + 2008-09-08 22:54 . 2004-08-03 21:29 12127 c:\windows\ServicePackFiles\i386\wadv02nt.sys + 2008-09-08 22:54 . 2004-08-03 21:29 12415 c:\windows\ServicePackFiles\i386\wadv01nt.sys + 2008-09-08 22:54 . 2008-04-13 18:43 14208 c:\windows\ServicePackFiles\i386\wacompen.sys + 2008-09-08 22:54 . 2008-04-14 00:12 30208 c:\windows\ServicePackFiles\i386\wabmig.exe + 2008-09-08 22:54 . 2008-04-14 00:12 85504 c:\windows\ServicePackFiles\i386\wabimp.dll + 2008-09-08 22:54 . 2008-04-14 00:12 32768 c:\windows\ServicePackFiles\i386\wabfind.dll + 2008-09-08 22:54 . 2008-04-14 00:12 46080 c:\windows\ServicePackFiles\i386\wab.exe + 2008-09-08 22:54 . 2008-04-14 00:12 15872 c:\windows\ServicePackFiles\i386\w3ssl.dll + 2008-09-08 22:54 . 2008-04-13 18:41 52352 c:\windows\ServicePackFiles\i386\volsnap.sys + 2008-09-08 22:54 . 2008-04-13 18:44 81664 c:\windows\ServicePackFiles\i386\videoprt.sys + 2008-09-08 22:53 . 2008-04-13 18:36 42240 c:\windows\ServicePackFiles\i386\viaagp.sys + 2008-09-08 22:53 . 2008-04-13 18:44 20992 c:\windows\ServicePackFiles\i386\vga.sys + 2008-09-08 22:53 . 2008-04-14 00:12 53760 c:\windows\ServicePackFiles\i386\vfwwdm32.dll + 2008-09-08 22:53 . 2008-04-14 00:12 18944 c:\windows\ServicePackFiles\i386\version.dll + 2008-09-08 22:53 . 2008-04-14 00:12 26624 c:\windows\ServicePackFiles\i386\verifier.dll + 2008-09-08 22:53 . 2008-04-14 00:12 28672 c:\windows\ServicePackFiles\i386\verclsid.exe + 2008-09-08 22:53 . 2008-04-14 00:12 51712 c:\windows\ServicePackFiles\i386\vdmredir.dll + 2008-09-08 22:53 . 2008-04-14 00:12 26112 c:\windows\ServicePackFiles\i386\vdmdbg.dll + 2008-09-08 22:53 . 2008-04-14 00:12 11325 c:\windows\ServicePackFiles\i386\vchnt5.dll + 2008-09-08 22:53 . 2008-04-14 00:12 30749 c:\windows\ServicePackFiles\i386\vbajet32.dll + 2008-09-08 22:53 . 2008-04-14 00:12 50176 c:\windows\ServicePackFiles\i386\utilman.exe + 2008-09-08 22:53 . 2008-04-14 00:12 26112 c:\windows\ServicePackFiles\i386\userinit.exe + 2008-09-08 22:53 . 2008-04-14 00:12 74240 c:\windows\ServicePackFiles\i386\usbui.dll + 2008-09-08 22:53 . 2008-04-13 18:45 20608 c:\windows\ServicePackFiles\i386\usbuhci.sys + 2008-09-08 22:53 . 2008-04-13 18:45 26368 c:\windows\ServicePackFiles\i386\usbstor.sys + 2008-09-08 22:53 . 2008-04-13 18:45 26112 c:\windows\ServicePackFiles\i386\usbser.sys + 2008-09-08 22:53 . 2008-04-13 18:45 15104 c:\windows\ServicePackFiles\i386\usbscan.sys + 2008-09-08 22:53 . 2008-04-13 18:47 25856 c:\windows\ServicePackFiles\i386\usbprint.sys + 2008-09-08 22:53 . 2008-04-13 18:45 17152 c:\windows\ServicePackFiles\i386\usbohci.sys + 2008-09-08 22:53 . 2008-04-14 00:12 16896 c:\windows\ServicePackFiles\i386\usbmon.dll + 2008-09-08 22:53 . 2008-04-13 18:45 15872 c:\windows\ServicePackFiles\i386\usbintel.sys + 2008-09-08 22:53 . 2008-04-13 18:45 59520 c:\windows\ServicePackFiles\i386\usbhub.sys + 2008-09-08 22:53 . 2008-04-13 18:45 30208 c:\windows\ServicePackFiles\i386\usbehci.sys + 2008-09-08 22:53 . 2008-04-13 18:45 32128 c:\windows\ServicePackFiles\i386\usbccgp.sys + 2008-09-08 22:53 . 2008-04-13 18:45 25728 c:\windows\ServicePackFiles\i386\usbcamd2.sys + 2008-09-08 22:53 . 2008-04-13 18:45 25600 c:\windows\ServicePackFiles\i386\usbcamd.sys + 2008-09-08 22:53 . 2008-04-13 18:45 60032 c:\windows\ServicePackFiles\i386\usbaudio.sys + 2008-09-08 22:53 . 2008-04-13 18:56 12800 c:\windows\ServicePackFiles\i386\usb8023x.sys + 2008-09-08 22:53 . 2008-04-13 18:56 12800 c:\windows\ServicePackFiles\i386\usb8023.sys + 2008-09-08 22:53 . 2004-08-03 21:31 32384 c:\windows\ServicePackFiles\i386\usb101et.sys + 2008-09-08 22:53 . 2008-04-14 00:12 37888 c:\windows\ServicePackFiles\i386\url.dll + 2008-09-08 22:53 . 2008-04-14 00:12 18432 c:\windows\ServicePackFiles\i386\ups.exe + 2008-09-08 22:53 . 2008-04-14 00:12 16896 c:\windows\ServicePackFiles\i386\upnpcont.exe + 2008-09-08 22:53 . 2008-04-14 00:12 13824 c:\windows\ServicePackFiles\i386\uniplat.dll + 2008-09-08 22:53 . 2008-04-14 00:12 74240 c:\windows\ServicePackFiles\i386\unimdmat.dll + 2008-09-08 22:53 . 2008-04-14 00:12 35840 c:\windows\ServicePackFiles\i386\umandlg.dll + 2008-09-08 22:53 . 2008-04-14 00:12 26624 c:\windows\ServicePackFiles\i386\udhisapi.dll + 2008-09-08 22:53 . 2008-04-13 18:32 66048 c:\windows\ServicePackFiles\i386\udfs.sys + 2008-09-08 22:53 . 2008-04-13 18:36 44672 c:\windows\ServicePackFiles\i386\uagp35.sys + 2008-09-08 22:53 . 2008-04-14 00:12 60416 c:\windows\ServicePackFiles\i386\tzchange.exe + 2008-09-08 22:53 . 2008-04-14 00:12 57856 c:\windows\ServicePackFiles\i386\twext.dll + 2008-09-08 22:53 . 2008-04-14 00:12 50688 c:\windows\ServicePackFiles\i386\twain_32.dll + 2008-09-08 22:53 . 2008-04-13 18:56 12288 c:\windows\ServicePackFiles\i386\tunmp.sys + 2008-09-08 22:53 . 2008-04-14 00:12 16384 c:\windows\ServicePackFiles\i386\ttyui.dll + 2008-09-08 22:53 . 2007-04-02 15:31 39936 c:\windows\ServicePackFiles\i386\ttyres.dll + 2008-09-08 22:53 . 2008-04-14 00:12 50688 c:\windows\ServicePackFiles\i386\tspkg.dll + 2008-09-08 22:53 . 2008-04-14 00:12 53248 c:\windows\ServicePackFiles\i386\tsgqec.dll + 2008-09-08 22:53 . 2008-04-14 00:13 12168 c:\windows\ServicePackFiles\i386\tsddd.dll + 2008-09-08 22:53 . 2008-04-14 00:11 25600 c:\windows\ServicePackFiles\i386\tscupdc.dll + 2008-09-08 22:53 . 2007-10-30 10:06 13801 c:\windows\ServicePackFiles\i386\tscuinst.vbs + 2008-09-08 22:53 . 2007-12-12 10:33 18917 c:\windows\ServicePackFiles\i386\tscinst.vbs + 2008-09-08 22:53 . 2008-04-14 00:12 93696 c:\windows\ServicePackFiles\i386\tscfgwmi.dll + 2008-09-08 22:53 . 2008-04-14 00:12 90112 c:\windows\ServicePackFiles\i386\trkwks.dll + 2008-09-08 22:53 . 2008-04-14 00:12 12800 c:\windows\ServicePackFiles\i386\tree.com + 2008-09-08 22:53 . 2008-04-14 00:12 12288 c:\windows\ServicePackFiles\i386\tracert.exe + 2008-09-08 22:53 . 2008-04-14 00:12 82944 c:\windows\ServicePackFiles\i386\tp4mon.exe + 2008-09-08 22:53 . 2008-04-14 00:13 40840 c:\windows\ServicePackFiles\i386\termdd.sys + 2008-09-08 22:53 . 2008-04-14 00:12 75776 c:\windows\ServicePackFiles\i386\telnet.exe + 2008-09-08 22:53 . 2008-04-14 00:13 21896 c:\windows\ServicePackFiles\i386\tdtcp.sys + 2008-09-08 22:53 . 2008-04-14 00:13 12040 c:\windows\ServicePackFiles\i386\tdpipe.sys + 2008-09-08 22:53 . 2008-04-13 19:00 19072 c:\windows\ServicePackFiles\i386\tdi.sys + 2008-09-08 22:53 . 2007-04-02 16:36 16384 c:\windows\ServicePackFiles\i386\tcptsat.dll + 2008-09-08 22:53 . 2008-04-14 00:12 32827 c:\windows\ServicePackFiles\i386\tcptest.exe + 2008-09-08 22:53 . 2008-04-14 00:12 45568 c:\windows\ServicePackFiles\i386\tcpmonui.dll + 2008-09-08 22:53 . 2008-04-14 00:12 45568 c:\windows\ServicePackFiles\i386\tcpmon.dll + 2008-09-08 22:53 . 2008-04-14 00:12 14848 c:\windows\ServicePackFiles\i386\tcpmib.dll + 2008-09-08 22:53 . 2008-04-13 18:40 14976 c:\windows\ServicePackFiles\i386\tape.sys + 2008-09-08 22:53 . 2008-04-13 19:15 60800 c:\windows\ServicePackFiles\i386\sysaudio.sys + 2008-09-08 22:53 . 2008-04-14 00:12 57856 c:\windows\ServicePackFiles\i386\synceng.dll + 2008-09-08 22:53 . 2008-04-13 18:45 56576 c:\windows\ServicePackFiles\i386\swmidi.sys + 2008-09-08 22:53 . 2008-04-14 00:12 14336 c:\windows\ServicePackFiles\i386\svchost.exe + 2008-09-08 22:53 . 2008-04-14 00:12 65601 c:\windows\ServicePackFiles\i386\stub_fpsrvwin.exe + 2008-04-14 00:12 . 2008-04-14 00:12 16449 c:\windows\ServicePackFiles\i386\stub_fpsrvadm.exe + 2008-09-08 22:53 . 2008-04-14 00:12 75776 c:\windows\ServicePackFiles\i386\strmfilt.dll + 2008-09-08 22:53 . 2008-04-13 18:46 15232 c:\windows\ServicePackFiles\i386\streamip.sys + 2008-09-08 22:53 . 2008-04-13 18:45 49408 c:\windows\ServicePackFiles\i386\stream.sys + 2008-09-08 22:53 . 2008-04-14 00:12 74752 c:\windows\ServicePackFiles\i386\storprop.dll + 2008-09-08 22:53 . 2008-04-14 00:12 14848 c:\windows\ServicePackFiles\i386\stimon.exe + 2008-09-08 22:53 . 2008-04-14 00:12 68096 c:\windows\ServicePackFiles\i386\sti.dll + 2008-09-08 22:53 . 2008-04-14 00:12 86528 c:\windows\ServicePackFiles\i386\stdprov.dll + 2008-09-08 22:53 . 2008-04-14 00:12 59392 c:\windows\ServicePackFiles\i386\stclient.dll + 2008-09-08 22:52 . 2008-04-14 00:12 26624 c:\windows\ServicePackFiles\i386\startoc.dll + 2008-09-08 22:53 . 2008-04-14 00:12 33280 c:\windows\ServicePackFiles\i386\sstub.dll + 2008-09-08 22:53 . 2008-04-14 00:12 14336 c:\windows\ServicePackFiles\i386\ssstars.scr + 2008-09-08 22:53 . 2008-04-14 00:12 18944 c:\windows\ServicePackFiles\i386\ssmyst.scr + 2008-09-08 22:53 . 2008-04-14 00:12 47104 c:\windows\ServicePackFiles\i386\ssmypics.scr + 2008-09-08 22:53 . 2008-04-14 00:12 20992 c:\windows\ServicePackFiles\i386\ssmarque.scr + 2008-09-08 22:53 . 2008-04-14 00:12 71680 c:\windows\ServicePackFiles\i386\ssdpsrv.dll + 2008-09-08 22:53 . 2008-04-14 00:12 34816 c:\windows\ServicePackFiles\i386\ssdpapi.dll + 2008-09-08 22:53 . 2008-04-14 00:12 19968 c:\windows\ServicePackFiles\i386\ssbezier.scr + 2008-09-08 22:53 . 2008-04-14 00:12 96768 c:\windows\ServicePackFiles\i386\srvsvc.dll + 2008-09-08 22:53 . 2008-04-14 00:12 67584 c:\windows\ServicePackFiles\i386\srclient.dll + 2008-09-08 22:53 . 2008-04-14 00:12 58434 c:\windows\ServicePackFiles\i386\srchctls.dll + 2008-09-08 22:53 . 2008-04-13 18:36 73472 c:\windows\ServicePackFiles\i386\sr.sys + 2008-09-08 22:53 . 2008-04-14 00:12 20992 c:\windows\ServicePackFiles\i386\spupdwxp.exe + 2008-09-08 22:53 . 2008-04-14 00:12 57856 c:\windows\ServicePackFiles\i386\spoolsv.exe + 2008-09-08 22:53 . 2008-04-14 00:12 75264 c:\windows\ServicePackFiles\i386\spoolss.dll + 2008-09-08 22:53 . 2008-04-14 04:42 11264 c:\windows\ServicePackFiles\i386\spnpinst.exe + 2008-09-08 22:53 . 2008-04-13 16:43 62976 c:\windows\ServicePackFiles\i386\spgrmr.dll + 2008-09-08 22:53 . 2008-04-14 00:12 24576 c:\windows\ServicePackFiles\i386\sort.exe + 2008-09-08 22:53 . 2008-04-13 18:46 25344 c:\windows\ServicePackFiles\i386\sonydcam.sys + 2008-09-08 22:53 . 2008-04-14 00:12 39936 c:\windows\ServicePackFiles\i386\snmpthrd.dll + 2008-09-08 22:53 . 2008-04-14 00:12 18944 c:\windows\ServicePackFiles\i386\snmpapi.dll + 2008-09-08 22:53 . 2008-04-14 00:12 33280 c:\windows\ServicePackFiles\i386\snmp.exe + 2008-09-08 22:53 . 2008-04-14 00:12 34816 c:\windows\ServicePackFiles\i386\sniffpol.dll + 2008-09-08 22:53 . 2008-04-14 00:12 50688 c:\windows\ServicePackFiles\i386\smss.exe + 2008-09-08 22:53 . 2008-04-14 00:12 89600 c:\windows\ServicePackFiles\i386\smlogsvc.exe + 2008-09-08 22:53 . 2008-04-13 18:36 16000 c:\windows\ServicePackFiles\i386\smbbatt.sys + 2008-09-08 22:53 . 2004-08-03 21:41 13240 c:\windows\ServicePackFiles\i386\slwdmsup.sys + 2008-09-08 22:53 . 2008-04-14 00:12 73796 c:\windows\ServicePackFiles\i386\slserv.exe + 2008-09-08 22:53 . 2008-04-14 00:12 32866 c:\windows\ServicePackFiles\i386\slrundll.exe + 2008-09-08 22:53 . 2004-08-03 21:41 95424 c:\windows\ServicePackFiles\i386\slnthal.sys + 2008-09-08 22:53 . 2008-04-13 18:46 11136 c:\windows\ServicePackFiles\i386\slip.sys + 2008-09-08 22:53 . 2008-04-14 00:12 73832 c:\windows\ServicePackFiles\i386\slcoinst.dll + 2008-09-08 22:53 . 2008-04-14 00:12 98304 c:\windows\ServicePackFiles\i386\slbiop.dll + 2008-09-08 22:53 . 2008-04-14 00:12 25088 c:\windows\ServicePackFiles\i386\slayerxp.dll + 2008-09-08 22:53 . 2004-08-03 21:31 63547 c:\windows\ServicePackFiles\i386\sla30nd5.sys + 2008-09-08 22:53 . 2008-04-14 00:12 26112 c:\windows\ServicePackFiles\i386\skeys.exe + 2008-09-08 22:53 . 2004-08-03 21:31 32768 c:\windows\ServicePackFiles\i386\sisnic.sys + 2008-09-08 22:53 . 2008-04-13 18:36 40960 c:\windows\ServicePackFiles\i386\sisagp.sys + 2008-09-08 22:53 . 2008-04-14 00:12 70144 c:\windows\ServicePackFiles\i386\sigverif.exe + 2008-09-08 22:53 . 2008-04-14 00:12 13312 c:\windows\ServicePackFiles\i386\sigtab.dll + 2008-09-08 22:53 . 2008-04-14 00:12 19456 c:\windows\ServicePackFiles\i386\shutdown.exe + 2008-04-14 00:12 . 2008-04-14 00:12 16437 c:\windows\ServicePackFiles\i386\shtml.exe + 2008-09-08 22:53 . 2008-04-14 00:12 20536 c:\windows\ServicePackFiles\i386\shtml.dll + 2008-09-08 22:53 . 2008-04-14 00:12 27648 c:\windows\ServicePackFiles\i386\shscrap.dll + 2008-09-08 22:53 . 2008-04-14 00:12 77824 c:\windows\ServicePackFiles\i386\shrpubw.exe + 2008-09-08 22:53 . 2008-04-14 00:12 45056 c:\windows\ServicePackFiles\i386\shmgrate.exe + 2008-09-08 22:53 . 2008-04-14 00:12 65024 c:\windows\ServicePackFiles\i386\shimeng.dll + 2008-09-08 22:53 . 2008-04-14 00:12 68096 c:\windows\ServicePackFiles\i386\shgina.dll + 2008-09-08 22:53 . 2008-04-14 00:12 25088 c:\windows\ServicePackFiles\i386\shfolder.dll + 2008-09-08 22:53 . 2008-04-13 18:40 11392 c:\windows\ServicePackFiles\i386\sfloppy.sys + 2008-09-08 22:53 . 2008-04-13 18:40 11008 c:\windows\ServicePackFiles\i386\sffp_sd.sys + 2008-09-08 22:53 . 2008-04-13 18:40 10240 c:\windows\ServicePackFiles\i386\sffp_mmc.sys + 2008-09-08 22:53 . 2008-04-13 18:40 11904 c:\windows\ServicePackFiles\i386\sffdisk.sys + 2008-09-08 22:53 . 2008-04-14 00:12 32768 c:\windows\ServicePackFiles\i386\setupn.exe + 2008-09-08 22:53 . 2008-04-14 00:12 73216 c:\windows\ServicePackFiles\i386\setup50.exe + 2008-09-08 22:53 . 2008-04-14 00:12 23040 c:\windows\ServicePackFiles\i386\setup.exe + 2008-09-08 22:53 . 2008-04-14 00:12 31232 c:\windows\ServicePackFiles\i386\sethc.exe + 2008-09-08 22:53 . 2008-04-14 00:12 56320 c:\windows\ServicePackFiles\i386\servdeps.dll + 2008-09-08 22:53 . 2008-04-13 19:15 64512 c:\windows\ServicePackFiles\i386\serial.sys + 2008-09-08 22:53 . 2008-04-13 18:40 15744 c:\windows\ServicePackFiles\i386\serenum.sys + 2008-09-08 22:53 . 2008-04-14 00:12 39424 c:\windows\ServicePackFiles\i386\sens.dll + 2008-09-08 22:53 . 2008-04-14 00:12 54784 c:\windows\ServicePackFiles\i386\sendmail.dll + 2008-09-08 22:53 . 2008-04-14 00:12 29184 c:\windows\ServicePackFiles\i386\sendcmsg.dll + 2008-09-08 22:53 . 2008-04-14 00:12 56320 c:\windows\ServicePackFiles\i386\secur32.dll + 2008-09-08 22:53 . 2008-04-14 00:12 18944 c:\windows\ServicePackFiles\i386\seclogon.dll + 2008-09-08 22:53 . 2007-11-13 10:25 20480 c:\windows\ServicePackFiles\i386\secdrv.sys + 2008-09-08 22:53 . 2008-04-14 00:12 29184 c:\windows\ServicePackFiles\i386\sdhcinst.dll + 2008-09-08 22:53 . 2008-04-13 18:36 79232 c:\windows\ServicePackFiles\i386\sdbus.sys + 2008-09-08 22:53 . 2008-04-14 00:12 77312 c:\windows\ServicePackFiles\i386\sdbinst.exe + 2008-09-08 22:53 . 2008-04-13 18:45 11520 c:\windows\ServicePackFiles\i386\scsiscan.sys + 2008-09-08 22:53 . 2008-04-13 18:40 96384 c:\windows\ServicePackFiles\i386\scsiport.sys + 2008-09-08 22:53 . 2008-04-14 00:12 36352 c:\windows\ServicePackFiles\i386\scrcons.exe + 2008-09-08 22:53 . 2008-04-14 00:12 20480 c:\windows\ServicePackFiles\i386\sclgntfy.dll + 2008-09-08 22:53 . 2008-04-14 00:12 95744 c:\windows\ServicePackFiles\i386\scardsvr.exe + 2008-09-08 22:53 . 2008-04-14 00:12 69632 c:\windows\ServicePackFiles\i386\scarddlg.dll + 2008-09-08 22:53 . 2008-04-13 18:40 43904 c:\windows\ServicePackFiles\i386\sbp2port.sys + 2008-09-08 22:53 . 2008-04-14 00:12 13312 c:\windows\ServicePackFiles\i386\savedump.exe + 2008-09-08 22:53 . 2008-04-14 00:12 64000 c:\windows\ServicePackFiles\i386\samlib.dll + 2008-09-08 22:53 . 2008-04-14 00:12 45568 c:\windows\ServicePackFiles\i386\safrslv.dll + 2008-09-08 22:53 . 2008-04-14 00:12 29696 c:\windows\ServicePackFiles\i386\safrdm.dll + 2008-09-08 22:53 . 2008-04-14 00:12 43520 c:\windows\ServicePackFiles\i386\safrcdlg.dll + 2008-09-08 22:53 . 2008-04-14 00:12 29696 c:\windows\ServicePackFiles\i386\rw450ext.dll + 2008-09-08 22:53 . 2008-04-14 00:12 27648 c:\windows\ServicePackFiles\i386\rw430ext.dll + 2008-09-08 22:53 . 2008-04-14 00:12 29184 c:\windows\ServicePackFiles\i386\rw330ext.dll + 2008-09-08 22:53 . 2008-04-14 00:12 27648 c:\windows\ServicePackFiles\i386\rw001ext.dll + 2008-09-08 22:53 . 2008-04-14 00:12 14336 c:\windows\ServicePackFiles\i386\runonce.exe + 2008-09-08 22:53 . 2008-04-14 00:12 33280 c:\windows\ServicePackFiles\i386\rundll32.exe + 2008-09-08 22:53 . 2008-04-14 00:12 44032 c:\windows\ServicePackFiles\i386\rtutils.dll + 2008-09-08 22:53 . 2004-08-03 21:31 20992 c:\windows\ServicePackFiles\i386\rtl8139.sys + 2008-09-08 22:53 . 2008-04-14 00:12 31744 c:\windows\ServicePackFiles\i386\rtipxmib.dll + 2008-09-08 22:53 . 2008-04-14 00:12 77312 c:\windows\ServicePackFiles\i386\rtcshare.exe + 2008-09-08 22:53 . 2008-04-14 00:12 92672 c:\windows\ServicePackFiles\i386\rsvpsp.dll + 2008-09-08 22:53 . 2008-04-14 00:12 18944 c:\windows\ServicePackFiles\i386\rsmps.dll + 2008-09-08 22:53 . 2008-04-14 00:12 39936 c:\windows\ServicePackFiles\i386\rshx32.dll + 2008-09-08 22:53 . 2008-04-14 00:12 14848 c:\windows\ServicePackFiles\i386\rsh.exe + 2008-09-08 22:53 . 2008-04-14 00:12 61440 c:\windows\ServicePackFiles\i386\rrcm.dll + 2008-09-08 22:53 . 2008-04-13 18:40 79104 c:\windows\ServicePackFiles\i386\rocket.sys + 2008-09-08 22:53 . 2008-04-13 18:56 30592 c:\windows\ServicePackFiles\i386\rndismpx.sys + 2008-09-08 22:53 . 2008-04-13 18:56 30592 c:\windows\ServicePackFiles\i386\rndismp.sys + 2008-09-08 22:53 . 2008-04-14 00:12 11776 c:\windows\ServicePackFiles\i386\riafui2.dll + 2008-09-08 22:53 . 2008-04-14 00:12 11776 c:\windows\ServicePackFiles\i386\riafui1.dll + 2008-09-08 22:53 . 2008-04-13 18:46 59136 c:\windows\ServicePackFiles\i386\rfcomm.sys + 2008-09-08 22:53 . 2008-04-14 00:12 13824 c:\windows\ServicePackFiles\i386\rexec.exe + 2008-09-08 22:53 . 2008-04-14 00:12 58880 c:\windows\ServicePackFiles\i386\resutils.dll + 2008-09-08 22:53 . 2008-04-14 00:12 60416 c:\windows\ServicePackFiles\i386\remotepg.dll + 2008-09-08 22:53 . 2008-04-14 00:12 11776 c:\windows\ServicePackFiles\i386\regsvr32.exe + 2008-09-08 22:53 . 2008-04-14 00:12 59904 c:\windows\ServicePackFiles\i386\regsvc.dll + 2008-09-08 22:53 . 2008-04-14 00:12 49664 c:\windows\ServicePackFiles\i386\regapi.dll + 2008-09-08 22:53 . 2008-04-14 00:12 50176 c:\windows\ServicePackFiles\i386\reg.exe + 2008-09-08 22:53 . 2008-04-13 18:40 57600 c:\windows\ServicePackFiles\i386\redbook.sys + 2008-09-08 22:53 . 2004-08-03 21:41 13776 c:\windows\ServicePackFiles\i386\recagent.sys + 2008-09-08 22:53 . 2008-04-14 00:12 67072 c:\windows\ServicePackFiles\i386\rdshost.exe + 2008-09-08 22:53 . 2008-04-14 00:12 13824 c:\windows\ServicePackFiles\i386\rdsaddin.exe + 2008-09-08 22:53 . 2008-04-14 00:13 87176 c:\windows\ServicePackFiles\i386\rdpwsx.dll + 2008-09-08 22:53 . 2008-04-14 00:12 19968 c:\windows\ServicePackFiles\i386\rdpsnd.dll + 2008-09-08 22:53 . 2008-04-14 00:13 92424 c:\windows\ServicePackFiles\i386\rdpdd.dll + 2008-09-08 22:53 . 2008-04-14 00:12 62976 c:\windows\ServicePackFiles\i386\rdpclip.exe + 2008-09-08 22:53 . 2008-04-14 00:12 21504 c:\windows\ServicePackFiles\i386\rcp.exe + 2008-09-08 22:53 . 2008-04-14 00:12 35840 c:\windows\ServicePackFiles\i386\rcimlby.exe + 2008-09-08 22:53 . 2008-04-14 00:12 58368 c:\windows\ServicePackFiles\i386\rastapi.dll + 2008-09-08 22:53 . 2008-04-14 00:12 16384 c:\windows\ServicePackFiles\i386\rassapi.dll + 2008-09-08 22:53 . 2008-04-14 00:12 61952 c:\windows\ServicePackFiles\i386\rasqec.dll + 2008-09-08 22:53 . 2008-04-13 19:19 48384 c:\windows\ServicePackFiles\i386\raspptp.sys + 2008-09-08 22:53 . 2008-04-13 18:57 41472 c:\windows\ServicePackFiles\i386\raspppoe.sys + 2008-09-08 22:53 . 2008-04-14 00:12 56832 c:\windows\ServicePackFiles\i386\rasphone.exe + 2008-09-08 22:53 . 2008-04-14 00:12 61440 c:\windows\ServicePackFiles\i386\rasman.dll + 2008-09-08 22:53 . 2008-04-13 19:19 51328 c:\windows\ServicePackFiles\i386\rasl2tp.sys + 2008-09-08 22:53 . 2008-04-14 00:12 79872 c:\windows\ServicePackFiles\i386\raschap.dll + 2008-09-08 22:53 . 2008-04-14 00:12 88576 c:\windows\ServicePackFiles\i386\rasauto.dll + 2008-09-08 22:53 . 2008-04-13 18:41 20736 c:\windows\ServicePackFiles\i386\ramdisk.sys + 2008-09-08 22:53 . 2008-04-14 00:12 43520 c:\windows\ServicePackFiles\i386\racpldlg.dll + 2008-09-08 22:53 . 2008-04-14 00:12 76800 c:\windows\ServicePackFiles\i386\qutil.dll + 2008-09-08 22:53 . 2008-04-14 00:12 19968 c:\windows\ServicePackFiles\i386\qprocess.exe + 2008-09-08 22:53 . 2008-04-14 00:12 18944 c:\windows\ServicePackFiles\i386\qmgrprxy.dll + 2008-09-08 22:53 . 2008-04-14 00:12 62464 c:\windows\ServicePackFiles\i386\qcliprov.dll + 2008-09-08 22:53 . 2008-04-14 00:12 34304 c:\windows\ServicePackFiles\i386\pstorsvc.dll + 2008-09-08 22:53 . 2008-04-14 00:12 43520 c:\windows\ServicePackFiles\i386\pstorec.dll + 2008-09-08 22:53 . 2008-04-13 18:56 69120 c:\windows\ServicePackFiles\i386\psched.sys + 2008-09-08 22:53 . 2008-04-14 00:12 96768 c:\windows\ServicePackFiles\i386\psbase.dll + 2008-09-08 22:53 . 2008-04-14 00:12 23040 c:\windows\ServicePackFiles\i386\psapi.dll + 2008-09-08 22:53 . 2008-04-14 00:12 50176 c:\windows\ServicePackFiles\i386\proquota.exe + 2008-09-08 22:53 . 2008-04-14 00:12 27648 c:\windows\ServicePackFiles\i386\profmap.dll + 2008-09-08 22:53 . 2008-04-13 18:31 35840 c:\windows\ServicePackFiles\i386\processr.sys + 2008-09-08 22:53 . 2008-04-13 18:41 17664 c:\windows\ServicePackFiles\i386\ppa3.sys + 2008-09-08 22:53 . 2008-04-14 00:12 17408 c:\windows\ServicePackFiles\i386\powrprof.dll + 2008-09-08 22:53 . 2008-04-14 00:12 49152 c:\windows\ServicePackFiles\i386\powercfg.exe + 2008-09-08 22:53 . 2008-04-14 00:12 58880 c:\windows\ServicePackFiles\i386\pnrpnsp.dll + 2008-09-08 22:53 . 2008-04-14 00:12 39424 c:\windows\ServicePackFiles\i386\pngfilt.dll + 2008-09-08 22:53 . 2008-04-14 00:12 52736 c:\windows\ServicePackFiles\i386\plotui.dll + 2008-09-08 22:53 . 2008-04-14 00:12 44544 c:\windows\ServicePackFiles\i386\plotter.dll + 2008-09-08 22:53 . 2008-04-14 00:12 15360 c:\windows\ServicePackFiles\i386\pjlmon.dll + 2008-09-08 22:53 . 2008-04-14 00:12 17920 c:\windows\ServicePackFiles\i386\ping.exe + 2008-09-08 22:52 . 2008-04-13 18:35 24064 c:\windows\ServicePackFiles\i386\pidgen.dll + 2008-09-08 22:53 . 2008-04-14 00:12 35328 c:\windows\ServicePackFiles\i386\pid.dll + 2008-09-08 22:53 . 2008-04-13 18:44 28032 c:\windows\ServicePackFiles\i386\perm3.sys + 2008-09-08 22:53 . 2008-04-13 18:44 27904 c:\windows\ServicePackFiles\i386\perm2.sys + 2008-09-08 22:53 . 2008-04-14 00:12 34816 c:\windows\ServicePackFiles\i386\perfproc.dll + 2008-09-08 22:53 . 2008-04-14 00:12 25088 c:\windows\ServicePackFiles\i386\perfos.dll + 2008-09-08 22:53 . 2008-04-14 00:12 17920 c:\windows\ServicePackFiles\i386\perfnet.dll + 2008-09-08 22:53 . 2008-04-14 00:12 15872 c:\windows\ServicePackFiles\i386\perfmon.exe + 2008-09-08 22:53 . 2008-04-14 00:12 26624 c:\windows\ServicePackFiles\i386\perfdisk.dll + 2008-09-08 22:53 . 2008-04-14 00:12 39936 c:\windows\ServicePackFiles\i386\perfctrs.dll + 2008-09-08 22:53 . 2008-04-13 18:40 24960 c:\windows\ServicePackFiles\i386\pciidex.sys + 2008-09-08 22:53 . 2008-04-13 18:36 68224 c:\windows\ServicePackFiles\i386\pci.sys + 2008-09-08 22:53 . 2008-04-14 00:12 38400 c:\windows\ServicePackFiles\i386\pchsvc.dll + 2008-09-08 22:53 . 2004-08-03 21:31 29502 c:\windows\ServicePackFiles\i386\pca200e.sys + 2008-09-08 22:53 . 2008-04-14 00:12 67584 c:\windows\ServicePackFiles\i386\pautoenr.dll + 2008-09-08 22:53 . 2008-04-13 18:40 19712 c:\windows\ServicePackFiles\i386\partmgr.sys + 2008-09-08 22:53 . 2008-04-13 18:40 80128 c:\windows\ServicePackFiles\i386\parport.sys + 2008-09-08 22:53 . 2008-04-14 00:12 58368 c:\windows\ServicePackFiles\i386\packager.exe + 2008-09-08 22:53 . 2008-04-13 18:31 42752 c:\windows\ServicePackFiles\i386\p3.sys + 2008-09-08 22:53 . 2008-04-14 00:12 67584 c:\windows\ServicePackFiles\i386\osuninst.dll + 2008-09-08 22:53 . 2008-04-14 00:12 51200 c:\windows\ServicePackFiles\i386\oobebaln.exe + 2008-09-08 22:53 . 2008-04-14 00:12 84992 c:\windows\ServicePackFiles\i386\olepro32.dll + 2008-09-08 22:53 . 2008-04-14 00:12 65536 c:\windows\ServicePackFiles\i386\oledb32r.dll + 2008-09-08 22:53 . 2008-04-14 00:12 37376 c:\windows\ServicePackFiles\i386\olecnv32.dll + 2008-09-08 22:53 . 2008-04-14 00:12 74752 c:\windows\ServicePackFiles\i386\olecli32.dll + 2008-09-08 22:53 . 2008-04-13 18:46 61696 c:\windows\ServicePackFiles\i386\ohci1394.sys + 2008-09-08 22:53 . 2008-04-14 00:12 35328 c:\windows\ServicePackFiles\i386\oemiglib.dll + 2008-09-08 22:53 . 2008-04-14 00:12 60416 c:\windows\ServicePackFiles\i386\oemig50.exe + 2008-09-08 22:53 . 2008-04-14 00:12 20511 c:\windows\ServicePackFiles\i386\odtext32.dll + 2008-09-08 22:53 . 2008-04-14 00:12 20510 c:\windows\ServicePackFiles\i386\odpdx32.dll + 2008-09-08 22:53 . 2008-04-14 00:12 20510 c:\windows\ServicePackFiles\i386\odfox32.dll + 2008-09-08 22:53 . 2008-04-14 00:12 20510 c:\windows\ServicePackFiles\i386\odexl32.dll + 2008-09-08 22:53 . 2008-04-14 00:12 20511 c:\windows\ServicePackFiles\i386\oddbse32.dll + 2008-09-08 22:53 . 2008-04-13 17:26 12288 c:\windows\ServicePackFiles\i386\odbcp32r.dll + 2008-09-08 22:53 . 2008-04-14 00:10 53279 c:\windows\ServicePackFiles\i386\odbcji32.dll + 2008-09-08 22:53 . 2008-04-13 17:26 94208 c:\windows\ServicePackFiles\i386\odbcint.dll + 2008-09-08 22:53 . 2008-04-14 00:12 65536 c:\windows\ServicePackFiles\i386\odbccu32.dll + 2008-09-08 22:53 . 2008-04-14 00:12 65536 c:\windows\ServicePackFiles\i386\odbccr32.dll + 2008-09-08 22:53 . 2008-04-14 00:12 69632 c:\windows\ServicePackFiles\i386\odbcconf.exe + 2008-09-08 22:53 . 2008-04-14 00:12 24576 c:\windows\ServicePackFiles\i386\odbcbcp.dll + 2008-09-08 22:53 . 2008-04-14 00:12 32768 c:\windows\ServicePackFiles\i386\odbcad32.exe + 2008-09-08 22:53 . 2008-04-14 00:12 16384 c:\windows\ServicePackFiles\i386\odbc32gt.dll + 2008-09-08 22:53 . 2004-08-04 12:00 26224 c:\windows\ServicePackFiles\i386\odbc16gt.dll + 2008-09-08 22:53 . 2008-04-14 00:12 17408 c:\windows\ServicePackFiles\i386\ocmsn.dll + 2008-09-08 22:53 . 2008-04-14 00:12 67584 c:\windows\ServicePackFiles\i386\ocmanage.dll + 2008-09-08 22:53 . 2008-04-14 00:12 15360 c:\windows\ServicePackFiles\i386\ocgen.dll + 2008-09-08 22:53 . 2008-04-14 00:12 96256 c:\windows\ServicePackFiles\i386\occache.dll + 2008-09-08 22:53 . 2008-04-14 00:10 86016 c:\windows\ServicePackFiles\i386\obepopc.dll + 2008-09-08 22:53 . 2007-04-02 18:44 77824 c:\windows\ServicePackFiles\i386\obemtllc.dll + 2008-09-08 22:53 . 2008-04-13 18:56 88320 c:\windows\ServicePackFiles\i386\nwlnkipx.sys + 2008-09-08 22:53 . 2008-04-14 00:12 15360 c:\windows\ServicePackFiles\i386\ntvdmd.dll + 2008-09-08 22:53 . 2008-04-14 00:12 91136 c:\windows\ServicePackFiles\i386\ntprint.dll + 2008-09-08 22:53 . 2008-04-14 00:12 62976 c:\windows\ServicePackFiles\i386\ntoc.dll + 2008-09-08 22:53 . 2008-04-14 00:12 40960 c:\windows\ServicePackFiles\i386\ntmsapi.dll + 2008-09-08 22:53 . 2008-04-14 00:12 44032 c:\windows\ServicePackFiles\i386\ntlanman.dll + 2008-09-08 22:53 . 2004-08-04 12:00 34560 c:\windows\ServicePackFiles\i386\ntio804.sys + 2008-09-08 22:53 . 2004-08-04 12:00 35424 c:\windows\ServicePackFiles\i386\ntio412.sys + 2008-09-08 22:53 . 2004-08-04 12:00 35648 c:\windows\ServicePackFiles\i386\ntio411.sys + 2008-09-08 22:53 . 2004-08-04 12:00 34560 c:\windows\ServicePackFiles\i386\ntio404.sys + 2008-09-08 22:53 . 2004-08-04 12:00 33840 c:\windows\ServicePackFiles\i386\ntio.sys + 2008-09-08 22:53 . 2008-04-14 00:12 67072 c:\windows\ServicePackFiles\i386\ntdsapi.dll + 2008-09-08 22:53 . 2004-08-04 12:00 47564 c:\windows\ServicePackFiles\i386\ntdetect.com + 2008-09-08 22:53 . 2008-04-14 00:12 76800 c:\windows\ServicePackFiles\i386\nslookup.exe + 2008-09-08 22:53 . 2008-04-13 18:54 28672 c:\windows\ServicePackFiles\i386\nscirda.sys + 2008-09-08 22:53 . 2008-04-14 00:12 54784 c:\windows\ServicePackFiles\i386\npptools.dll + 2008-09-08 22:53 . 2008-04-14 00:12 15360 c:\windows\ServicePackFiles\i386\nppagent.exe + 2008-09-08 22:53 . 2008-04-13 18:32 30848 c:\windows\ServicePackFiles\i386\npfs.sys + 2008-09-08 22:53 . 2008-04-14 00:12 69120 c:\windows\ServicePackFiles\i386\notepad.exe + 2008-09-08 22:53 . 2008-04-13 18:53 40320 c:\windows\ServicePackFiles\i386\nmnt.sys + 2008-09-08 22:53 . 2008-04-14 00:12 28672 c:\windows\ServicePackFiles\i386\nmmkcert.dll + 2008-09-08 22:53 . 2008-04-14 00:12 77824 c:\windows\ServicePackFiles\i386\nmcom.dll + 2008-09-08 22:53 . 2008-04-14 00:12 81920 c:\windows\ServicePackFiles\i386\nmchat.dll + 2008-09-08 22:53 . 2008-04-14 00:12 28672 c:\windows\ServicePackFiles\i386\nmasnt.dll + 2008-09-08 22:53 . 2008-04-14 00:12 98304 c:\windows\ServicePackFiles\i386\nlhtml.dll + 2008-09-08 22:53 . 2008-04-13 18:51 61824 c:\windows\ServicePackFiles\i386\nic1394.sys + 2008-09-08 22:53 . 2008-04-14 00:12 80896 c:\windows\ServicePackFiles\i386\netui0.dll + 2008-09-08 22:53 . 2008-04-14 00:12 36864 c:\windows\ServicePackFiles\i386\netstat.exe + 2008-09-08 22:53 . 2008-04-14 00:12 86016 c:\windows\ServicePackFiles\i386\netsh.exe + 2008-09-08 22:53 . 2008-04-14 00:12 11776 c:\windows\ServicePackFiles\i386\netrap.dll + 2008-09-08 22:53 . 2008-04-14 00:12 77312 c:\windows\ServicePackFiles\i386\netoc.dll + 2008-09-08 22:53 . 2008-04-13 18:56 34688 c:\windows\ServicePackFiles\i386\netbios.sys + 2008-09-08 22:53 . 2008-04-14 00:12 42496 c:\windows\ServicePackFiles\i386\net.exe + 2008-09-08 22:53 . 2008-04-13 18:57 40576 c:\windows\ServicePackFiles\i386\ndproxy.sys + 2008-09-08 22:53 . 2008-04-13 19:20 91520 c:\windows\ServicePackFiles\i386\ndiswan.sys + 2008-09-08 22:53 . 2008-04-13 18:55 14592 c:\windows\ServicePackFiles\i386\ndisuio.sys + 2008-09-08 22:53 . 2008-04-13 18:57 10112 c:\windows\ServicePackFiles\i386\ndistapi.sys + 2008-09-08 22:53 . 2008-04-14 00:12 57344 c:\windows\ServicePackFiles\i386\ndisnpp.dll + 2008-09-08 22:53 . 2008-04-13 18:46 10880 c:\windows\ServicePackFiles\i386\ndisip.sys + 2008-09-08 22:53 . 2008-04-14 00:12 18944 c:\windows\ServicePackFiles\i386\nddenb32.dll + 2008-09-08 22:53 . 2008-04-14 00:12 17920 c:\windows\ServicePackFiles\i386\nddeapi.dll + 2008-09-08 22:53 . 2008-04-14 00:12 47104 c:\windows\ServicePackFiles\i386\ncprov.dll + 2008-09-08 22:53 . 2008-04-14 00:12 36352 c:\windows\ServicePackFiles\i386\ncobjapi.dll + 2008-09-08 22:53 . 2008-04-14 00:12 53760 c:\windows\ServicePackFiles\i386\narrator.exe + 2008-09-08 22:53 . 2008-04-14 00:12 30208 c:\windows\ServicePackFiles\i386\napipsec.dll + 2008-09-08 22:53 . 2008-04-13 18:46 85248 c:\windows\ServicePackFiles\i386\nabtsfec.sys + 2008-09-08 22:53 . 2008-04-14 00:12 90624 c:\windows\ServicePackFiles\i386\mydocs.dll + 2008-09-08 22:53 . 2008-04-13 18:43 12672 c:\windows\ServicePackFiles\i386\mutohpen.sys + 2008-09-08 22:53 . 2008-04-14 00:12 90624 c:\windows\ServicePackFiles\i386\muisetup.exe + 2008-09-08 22:53 . 2008-04-14 00:12 91648 c:\windows\ServicePackFiles\i386\mtxoci.dll + 2008-09-08 22:53 . 2008-04-14 00:12 34304 c:\windows\ServicePackFiles\i386\mtxlegih.dll + 2008-09-08 22:53 . 2008-04-14 00:12 30720 c:\windows\ServicePackFiles\i386\mtxdm.dll + 2008-09-08 22:53 . 2008-04-14 00:12 66560 c:\windows\ServicePackFiles\i386\mtxclu.dll + 2008-09-08 22:53 . 2008-04-14 00:12 16896 c:\windows\ServicePackFiles\i386\msyuv.dll + 2008-09-08 22:53 . 2008-04-14 00:12 24576 c:\windows\ServicePackFiles\i386\msxactps.dll + 2008-09-08 22:53 . 2008-04-14 00:12 72704 c:\windows\ServicePackFiles\i386\msw3prt.dll + 2008-09-08 22:53 . 2008-04-13 18:30 61440 c:\windows\ServicePackFiles\i386\msvcrt40.dll + 2008-09-08 22:53 . 2008-04-14 00:12 57344 c:\windows\ServicePackFiles\i386\msvcirt.dll + 2008-09-08 22:53 . 2008-04-14 00:12 12288 c:\windows\ServicePackFiles\i386\mstinit.exe + 2008-09-08 22:53 . 2008-04-13 18:46 49024 c:\windows\ServicePackFiles\i386\mstape.sys |
|
|
|
|
#12 (permalink) |
|
Registered User
Join Date: Jul 2009
Posts: 14
OS: xp
|
Re: Recurring Vundo Trojan
+ 2008-09-08 22:53 . 2008-04-14 00:12 57344 c:\windows\ServicePackFiles\i386\mst123.dll
+ 2008-09-08 22:53 . 2008-04-13 18:36 15488 c:\windows\ServicePackFiles\i386\mssmbios.sys + 2008-09-08 22:53 . 2008-04-13 18:14 76800 c:\windows\ServicePackFiles\i386\msshamsg.dll + 2008-09-08 22:53 . 2008-04-14 00:12 11264 c:\windows\ServicePackFiles\i386\msrle32.dll + 2008-09-08 22:53 . 2008-04-13 16:23 48128 c:\windows\ServicePackFiles\i386\msprivs.dll + 2008-09-08 22:53 . 2008-04-14 00:12 29696 c:\windows\ServicePackFiles\i386\mspatcha.dll + 2008-09-08 22:53 . 2008-04-13 17:24 20480 c:\windows\ServicePackFiles\i386\msorc32r.dll + 2008-09-08 22:53 . 2008-04-14 00:12 29184 c:\windows\ServicePackFiles\i386\msoobe.exe + 2008-09-08 22:53 . 2008-04-14 00:12 19456 c:\windows\ServicePackFiles\i386\msobweb.dll + 2008-09-08 22:53 . 2008-04-14 00:12 30720 c:\windows\ServicePackFiles\i386\msobshel.dll + 2008-09-08 22:53 . 2008-04-14 00:12 16384 c:\windows\ServicePackFiles\i386\msobdl.dll + 2008-09-08 22:53 . 2008-04-14 00:12 39936 c:\windows\ServicePackFiles\i386\mslwvtts.dll + 2008-09-08 22:53 . 2008-04-14 00:12 25088 c:\windows\ServicePackFiles\i386\mslbui.dll + 2008-09-08 22:53 . 2008-03-25 04:50 60192 c:\windows\ServicePackFiles\i386\msjter40.dll + 2008-09-08 22:53 . 2008-04-14 00:11 15360 c:\windows\ServicePackFiles\i386\msisip.dll + 2008-09-08 22:53 . 2008-04-14 00:12 40960 c:\windows\ServicePackFiles\i386\msiregmv.exe + 2008-09-08 22:53 . 2008-04-13 18:54 22016 c:\windows\ServicePackFiles\i386\msircomm.sys + 2008-09-08 22:53 . 2008-04-14 00:12 60416 c:\windows\ServicePackFiles\i386\msimn.exe + 2008-09-08 22:53 . 2008-04-14 00:12 78848 c:\windows\ServicePackFiles\i386\msiexec.exe + 2008-09-08 22:53 . 2008-04-14 00:11 51712 c:\windows\ServicePackFiles\i386\msident.dll + 2008-09-08 22:53 . 2008-04-13 16:26 56832 c:\windows\ServicePackFiles\i386\mshtmler.dll + 2008-09-08 22:53 . 2008-04-14 00:12 29184 c:\windows\ServicePackFiles\i386\mshta.exe + 2008-09-08 22:53 . 2008-04-14 00:11 33792 c:\windows\ServicePackFiles\i386\msgsvc.dll + 2008-09-08 22:53 . 2008-04-14 00:11 82944 c:\windows\ServicePackFiles\i386\msgsc.dll + 2008-09-08 22:53 . 2008-04-14 00:11 15360 c:\windows\ServicePackFiles\i386\msgrocm.dll + 2008-09-08 22:53 . 2008-04-13 18:56 35072 c:\windows\ServicePackFiles\i386\msgpc.sys + 2008-09-08 22:53 . 2008-04-13 18:32 19072 c:\windows\ServicePackFiles\i386\msfs.sys + 2008-09-08 22:53 . 2008-04-13 18:46 51200 c:\windows\ServicePackFiles\i386\msdv.sys + 2008-09-08 22:52 . 2008-04-14 00:11 90112 c:\windows\ServicePackFiles\i386\msdtcstp.dll + 2008-09-08 22:52 . 2008-04-14 00:11 58880 c:\windows\ServicePackFiles\i386\msdtclog.dll + 2008-09-08 22:52 . 2008-04-14 00:11 14336 c:\windows\ServicePackFiles\i386\msdmo.dll + 2008-09-08 22:52 . 2008-04-14 00:11 36864 c:\windows\ServicePackFiles\i386\msdfmap.dll + 2008-09-08 22:52 . 2008-04-14 00:11 20480 c:\windows\ServicePackFiles\i386\msdatt.dll + 2008-09-08 22:52 . 2008-04-14 00:11 94208 c:\windows\ServicePackFiles\i386\msdatl3.dll + 2008-09-08 22:52 . 2008-04-13 17:26 16384 c:\windows\ServicePackFiles\i386\msdasqlr.dll + 2008-09-08 22:52 . 2008-04-13 17:25 16384 c:\windows\ServicePackFiles\i386\msdaremr.dll + 2008-09-08 22:52 . 2008-04-13 17:25 16384 c:\windows\ServicePackFiles\i386\msdaprsr.dll + 2008-09-08 22:52 . 2008-04-14 00:11 77824 c:\windows\ServicePackFiles\i386\msdaosp.dll + 2008-09-08 22:52 . 2008-04-13 17:24 16384 c:\windows\ServicePackFiles\i386\msdaorar.dll + 2008-09-08 22:52 . 2008-04-14 00:11 68608 c:\windows\ServicePackFiles\i386\msctfp.dll + 2008-09-08 22:52 . 2008-04-14 00:11 36864 c:\windows\ServicePackFiles\i386\mscpxl32.dll + 2008-09-08 22:52 . 2008-04-13 17:26 12288 c:\windows\ServicePackFiles\i386\mscpx32r.dll + 2008-09-08 22:52 . 2008-04-14 00:11 69632 c:\windows\ServicePackFiles\i386\msconf.dll + 2008-09-08 22:52 . 2008-04-14 00:11 73728 c:\windows\ServicePackFiles\i386\mscms.dll + 2008-09-08 22:52 . 2008-04-14 00:11 57344 c:\windows\ServicePackFiles\i386\msasn1.dll + 2008-09-08 22:52 . 2008-04-14 00:11 86016 c:\windows\ServicePackFiles\i386\msapsspc.dll + 2008-09-08 22:52 . 2008-04-14 00:11 57344 c:\windows\ServicePackFiles\i386\msadrh15.dll + 2008-09-08 22:52 . 2008-04-14 00:11 57344 c:\windows\ServicePackFiles\i386\msador15.dll + 2008-09-08 22:52 . 2008-04-13 17:26 24576 c:\windows\ServicePackFiles\i386\msader15.dll + 2008-09-08 22:52 . 2008-04-13 17:25 24576 c:\windows\ServicePackFiles\i386\msaddsr.dll + 2008-09-08 22:52 . 2008-04-14 00:11 53248 c:\windows\ServicePackFiles\i386\msadcs.dll + 2008-09-08 22:52 . 2008-04-13 17:25 16384 c:\windows\ServicePackFiles\i386\msadcor.dll + 2008-09-08 22:52 . 2008-04-13 17:25 16384 c:\windows\ServicePackFiles\i386\msadcfr.dll + 2008-09-08 22:52 . 2008-04-14 00:11 61440 c:\windows\ServicePackFiles\i386\msadcf.dll + 2008-09-08 22:52 . 2008-04-13 17:25 20480 c:\windows\ServicePackFiles\i386\msadcer.dll + 2008-09-08 22:52 . 2008-04-14 00:11 71680 c:\windows\ServicePackFiles\i386\msacm32.dll + 2008-09-08 22:52 . 2008-04-14 00:11 53248 c:\windows\ServicePackFiles\i386\mprdim.dll + 2008-09-08 22:52 . 2008-04-14 00:11 87040 c:\windows\ServicePackFiles\i386\mprapi.dll + 2008-09-08 22:52 . 2008-04-14 00:11 59904 c:\windows\ServicePackFiles\i386\mpr.dll + 2008-09-08 22:52 . 2008-04-13 18:46 15232 c:\windows\ServicePackFiles\i386\mpe.sys + 2008-09-08 22:52 . 2008-04-13 18:39 42368 c:\windows\ServicePackFiles\i386\mountmgr.sys + 2008-09-08 22:52 . 2008-04-13 18:39 23040 c:\windows\ServicePackFiles\i386\mouclass.sys + 2008-09-08 22:52 . 2008-04-14 00:12 16896 c:\windows\ServicePackFiles\i386\more.com + 2008-09-08 22:52 . 2008-04-14 00:12 16384 c:\windows\ServicePackFiles\i386\mofcomp.exe + 2008-09-08 22:52 . 2008-04-13 19:00 30080 c:\windows\ServicePackFiles\i386\modem.sys + 2008-09-08 22:52 . 2008-04-14 00:12 32768 c:\windows\ServicePackFiles\i386\mnmsrvc.exe + 2008-09-08 22:52 . 2008-04-14 00:11 34560 c:\windows\ServicePackFiles\i386\mnmdd.dll + 2008-09-08 22:52 . 2004-08-04 12:00 68768 c:\windows\ServicePackFiles\i386\mmsystem.dll + 2008-09-08 22:52 . 2008-04-14 00:11 17408 c:\windows\ServicePackFiles\i386\mmfutil.dll + 2008-09-08 22:52 . 2008-04-14 00:11 61440 c:\windows\ServicePackFiles\i386\mmcshext.dll + 2008-09-08 22:52 . 2008-04-14 00:12 33792 c:\windows\ServicePackFiles\i386\mmcperf.exe + 2008-09-08 22:52 . 2008-04-14 00:11 40960 c:\windows\ServicePackFiles\i386\mmcexr.dll + 2008-09-08 22:52 . 2008-04-14 00:11 28672 c:\windows\ServicePackFiles\i386\mmc30r.dll + 2008-09-08 22:52 . 2008-04-14 00:11 29696 c:\windows\ServicePackFiles\i386\mimefilt.dll + 2008-09-08 22:52 . 2008-04-14 00:11 60928 c:\windows\ServicePackFiles\i386\miglibnt.dll + 2008-09-08 22:52 . 2008-04-14 00:11 18944 c:\windows\ServicePackFiles\i386\midimap.dll + 2008-09-08 22:52 . 2008-04-14 00:11 14848 c:\windows\ServicePackFiles\i386\mgmtapi.dll + 2008-09-08 22:52 . 2008-04-14 00:11 22528 c:\windows\ServicePackFiles\i386\mfcsubs.dll + 2008-09-08 22:52 . 2008-04-14 00:11 40960 c:\windows\ServicePackFiles\i386\mf3216.dll + 2008-09-08 22:52 . 2008-04-13 18:36 63744 c:\windows\ServicePackFiles\i386\mf.sys + 2008-09-08 22:52 . 2008-04-13 18:41 26112 c:\windows\ServicePackFiles\i386\memstpci.sys + 2008-09-08 22:52 . 2004-08-03 21:41 11868 c:\windows\ServicePackFiles\i386\mdmxsdk.sys + 2008-09-08 22:52 . 2008-04-14 00:11 86016 c:\windows\ServicePackFiles\i386\mdmxsdk.dll + 2008-09-08 22:52 . 2008-04-14 00:11 23552 c:\windows\ServicePackFiles\i386\mciwave.dll + 2008-09-08 22:52 . 2008-04-14 00:11 23040 c:\windows\ServicePackFiles\i386\mciseq.dll + 2008-09-08 22:52 . 2008-04-14 00:11 35328 c:\windows\ServicePackFiles\i386\mciqtz32.dll + 2008-09-08 22:52 . 2008-04-14 00:11 84480 c:\windows\ServicePackFiles\i386\mciavi32.dll + 2008-09-08 22:52 . 2008-04-14 00:11 14336 c:\windows\ServicePackFiles\i386\mcastmib.dll + 2008-09-08 22:52 . 2008-04-14 00:12 57344 c:\windows\ServicePackFiles\i386\makecab.exe + 2008-09-08 22:52 . 2008-04-14 00:12 72704 c:\windows\ServicePackFiles\i386\magnify.exe + 2008-09-08 22:52 . 2004-08-03 21:39 20864 c:\windows\ServicePackFiles\i386\lwadihid.sys + 2008-09-08 22:52 . 2008-04-14 00:12 13312 c:\windows\ServicePackFiles\i386\lsass.exe + 2008-09-08 22:52 . 2008-04-14 00:11 18944 c:\windows\ServicePackFiles\i386\lprmon.dll + 2008-09-08 22:52 . 2008-04-14 00:11 10240 c:\windows\ServicePackFiles\i386\lprhelp.dll + 2008-09-08 22:52 . 2008-04-14 00:11 22016 c:\windows\ServicePackFiles\i386\lpk.dll + 2008-09-08 22:52 . 2008-04-14 00:11 22528 c:\windows\ServicePackFiles\i386\lpdsvc.dll + 2008-09-08 22:52 . 2008-04-14 00:12 59392 c:\windows\ServicePackFiles\i386\logman.exe + 2008-09-08 22:52 . 2008-04-14 00:11 19968 c:\windows\ServicePackFiles\i386\log.dll + 2008-09-08 22:52 . 2008-04-14 00:12 75264 c:\windows\ServicePackFiles\i386\locator.exe + 2008-09-08 22:52 . 2008-04-14 00:11 11776 c:\windows\ServicePackFiles\i386\localui.dll + 2008-09-08 22:52 . 2008-04-14 00:11 97280 c:\windows\ServicePackFiles\i386\loadperf.dll + 2008-09-08 22:52 . 2008-04-14 00:11 33792 c:\windows\ServicePackFiles\i386\lmmib2.dll + 2008-09-08 22:52 . 2008-04-14 00:11 13824 c:\windows\ServicePackFiles\i386\lmhsvc.dll + 2008-09-08 22:52 . 2008-04-14 00:11 19968 c:\windows\ServicePackFiles\i386\linkinfo.dll + 2008-09-08 22:52 . 2008-04-14 00:11 58880 c:\windows\ServicePackFiles\i386\licwmi.dll + 2008-09-08 22:52 . 2008-04-14 00:11 22016 c:\windows\ServicePackFiles\i386\licmgr10.dll + 2008-09-08 22:52 . 2008-04-13 18:40 34688 c:\windows\ServicePackFiles\i386\lbrtfdc.sys + 2008-09-08 22:52 . 2008-04-14 00:11 86073 c:\windows\ServicePackFiles\i386\lang\voicesub.dll + 2008-09-08 22:52 . 2008-04-14 00:11 76288 c:\windows\ServicePackFiles\i386\lang\uniime.dll + 2008-09-08 22:52 . 2008-04-14 00:10 10240 c:\windows\ServicePackFiles\i386\lang\tmigrate.dll + 2008-09-08 22:52 . 2008-04-13 16:43 44032 c:\windows\ServicePackFiles\i386\lang\tintlphr.exe + 2008-09-08 22:52 . 2008-04-14 00:10 67584 c:\windows\ServicePackFiles\i386\lang\pmigrate.dll + 2008-09-08 22:52 . 2008-04-13 16:43 70144 c:\windows\ServicePackFiles\i386\lang\pintlphr.exe + 2008-09-08 22:52 . 2008-04-14 00:10 53760 c:\windows\ServicePackFiles\i386\lang\pintlcsd.dll + 2008-09-08 22:52 . 2008-04-14 00:10 15360 c:\windows\ServicePackFiles\i386\lang\padrs804.dll + 2008-09-08 22:52 . 2008-04-14 00:10 15872 c:\windows\ServicePackFiles\i386\lang\padrs404.dll + 2008-09-08 22:52 . 2008-04-13 16:43 59392 c:\windows\ServicePackFiles\i386\lang\imscinst.exe + 2008-09-08 22:52 . 2008-04-14 00:09 81976 c:\windows\ServicePackFiles\i386\lang\imjpdct.dll + 2008-09-08 22:52 . 2008-04-14 00:09 86016 c:\windows\ServicePackFiles\i386\lang\imekrmbx.dll + 2008-09-08 22:52 . 2008-04-13 16:43 57399 c:\windows\ServicePackFiles\i386\lang\cplexe.exe + 2008-09-08 22:52 . 2008-04-14 00:09 56320 c:\windows\ServicePackFiles\i386\lang\chtskdic.dll + 2008-09-08 22:52 . 2008-04-14 00:09 97792 c:\windows\ServicePackFiles\i386\lang\chtmbx.dll + 2008-09-08 22:52 . 2008-04-14 00:11 37376 c:\windows\ServicePackFiles\i386\l2store.dll + 2008-09-08 22:52 . 2008-04-13 18:31 92288 c:\windows\ServicePackFiles\i386\ksecdd.sys + 2008-09-08 22:52 . 2008-04-14 00:11 24576 c:\windows\ServicePackFiles\i386\krnlprov.dll + 2008-09-08 22:52 . 2004-08-04 12:00 92224 c:\windows\ServicePackFiles\i386\krnl386.exe + 2008-09-08 22:52 . 2008-04-14 00:09 24576 c:\windows\ServicePackFiles\i386\kpropid.dll + 2008-09-08 22:52 . 2008-04-14 00:09 24064 c:\windows\ServicePackFiles\i386\kperpid.dll + 2008-09-08 22:52 . 2008-04-14 00:09 24576 c:\windows\ServicePackFiles\i386\knpropid.dll + 2008-09-08 22:52 . 2008-04-14 00:09 24064 c:\windows\ServicePackFiles\i386\knperpid.dll + 2008-09-08 22:52 . 2008-04-14 00:11 61440 c:\windows\ServicePackFiles\i386\kmsvc.dll + 2008-09-08 22:52 . 2004-08-04 12:00 42537 c:\windows\ServicePackFiles\i386\keyboard.sys + 2008-09-08 22:52 . 2008-04-14 00:11 48640 c:\windows\ServicePackFiles\i386\kdsui.dll + 2008-09-08 22:52 . 2008-04-13 18:39 14592 c:\windows\ServicePackFiles\i386\kbdhid.sys + 2008-09-08 22:52 . 2008-04-13 18:39 24576 c:\windows\ServicePackFiles\i386\kbdclass.sys + 2008-09-08 22:52 . 2008-04-14 00:11 15872 c:\windows\ServicePackFiles\i386\jsproxy.dll + 2008-09-08 22:52 . 2008-04-14 00:11 27648 c:\windows\ServicePackFiles\i386\jgpl400.dll + 2008-09-08 22:52 . 2008-04-14 00:11 47616 c:\windows\ServicePackFiles\i386\iyuv_32.dll + 2008-09-08 22:52 . 2008-04-14 00:11 54272 c:\windows\ServicePackFiles\i386\ixsso.dll + 2008-09-08 22:52 . 2008-04-14 00:11 32768 c:\windows\ServicePackFiles\i386\isrdbg32.dll + 2008-09-08 22:52 . 2008-04-14 00:10 24064 c:\windows\ServicePackFiles\i386\ispid.dll + 2008-09-08 22:52 . 2008-04-14 00:11 81920 c:\windows\ServicePackFiles\i386\isign32.dll + 2008-09-08 22:52 . 2008-04-14 00:10 24064 c:\windows\ServicePackFiles\i386\isenpid.dll + 2008-09-08 22:52 . 2008-04-13 18:36 37248 c:\windows\ServicePackFiles\i386\isapnp.sys + 2008-09-08 22:52 . 2008-04-14 00:11 28160 c:\windows\ServicePackFiles\i386\irmon.dll + 2008-09-08 22:52 . 2008-04-13 18:54 11264 c:\windows\ServicePackFiles\i386\irenum.sys + 2008-09-08 22:52 . 2008-04-13 18:54 88192 c:\windows\ServicePackFiles\i386\irda.sys + 2008-09-08 22:52 . 2008-04-14 00:11 22016 c:\windows\ServicePackFiles\i386\ipxwan.dll + 2008-09-08 22:52 . 2008-04-14 00:12 23552 c:\windows\ServicePackFiles\i386\ipxroute.exe + 2008-09-08 22:52 . 2008-04-14 00:11 59904 c:\windows\ServicePackFiles\i386\ipv6mon.dll + 2008-09-08 22:52 . 2008-04-14 00:12 53248 c:\windows\ServicePackFiles\i386\ipv6.exe + 2008-09-08 22:52 . 2008-04-14 00:09 24064 c:\windows\ServicePackFiles\i386\ipselpid.dll + 2008-09-08 22:52 . 2008-04-13 19:19 75264 c:\windows\ServicePackFiles\i386\ipsec.sys + 2008-09-08 22:52 . 2008-04-14 00:11 35328 c:\windows\ServicePackFiles\i386\iprip.dll + 2008-09-08 22:52 . 2008-04-13 18:57 20864 c:\windows\ServicePackFiles\i386\ipinip.sys + 2008-09-08 22:52 . 2008-04-14 00:11 94720 c:\windows\ServicePackFiles\i386\iphlpapi.dll + 2008-09-08 22:52 . 2008-04-14 00:09 24064 c:\windows\ServicePackFiles\i386\ipevlpid.dll + 2008-09-08 22:52 . 2008-04-14 00:12 55808 c:\windows\ServicePackFiles\i386\ipconfig.exe + 2008-09-08 22:52 . 2008-04-13 18:53 36608 c:\windows\ServicePackFiles\i386\ip6fw.sys + 2008-09-08 22:52 . 2008-04-13 18:31 36352 c:\windows\ServicePackFiles\i386\intelppm.sys + 2008-09-08 22:52 . 2008-04-14 00:11 96256 c:\windows\ServicePackFiles\i386\inseng.dll + 2008-09-08 22:52 . 2008-04-14 00:12 20480 c:\windows\ServicePackFiles\i386\inetwiz.exe + 2008-09-08 22:52 . 2008-04-13 16:22 48128 c:\windows\ServicePackFiles\i386\inetres.dll + 2008-09-08 22:52 . 2008-04-14 00:11 15872 c:\windows\ServicePackFiles\i386\inetppui.dll + 2008-09-08 22:52 . 2008-04-14 00:11 75264 c:\windows\ServicePackFiles\i386\inetpp.dll + 2008-09-08 22:52 . 2008-04-14 00:11 32768 c:\windows\ServicePackFiles\i386\inetmib1.dll + 2008-09-08 22:52 . 2008-04-14 00:11 35840 c:\windows\ServicePackFiles\i386\imgutil.dll + 2008-09-08 22:52 . 2008-04-14 00:11 36921 c:\windows\ServicePackFiles\i386\imeshare.dll + 2008-09-08 22:52 . 2008-04-13 18:40 42112 c:\windows\ServicePackFiles\i386\imapi.sys + 2008-09-08 22:52 . 2008-04-14 00:11 81920 c:\windows\ServicePackFiles\i386\ils.dll + 2008-09-08 22:52 . 2008-04-14 00:12 93184 c:\windows\ServicePackFiles\i386\iexplore.exe + 2008-09-08 22:52 . 2008-04-14 00:11 62976 c:\windows\ServicePackFiles\i386\iesetup.dll + 2008-09-08 22:52 . 2008-04-14 00:11 48640 c:\windows\ServicePackFiles\i386\iernonce.dll + 2008-09-08 22:52 . 2008-04-14 00:11 81920 c:\windows\ServicePackFiles\i386\ieencode.dll + 2008-09-08 22:52 . 2008-04-14 00:12 18432 c:\windows\ServicePackFiles\i386\iedw.exe + 2008-09-08 22:52 . 2008-04-14 00:12 34304 c:\windows\ServicePackFiles\i386\ie4uinit.exe + 2008-09-08 22:52 . 2008-04-14 00:11 49152 c:\windows\ServicePackFiles\i386\icwutil.dll + 2008-09-08 22:52 . 2008-04-14 00:12 24576 c:\windows\ServicePackFiles\i386\icwrmind.exe + 2008-09-08 22:52 . 2008-04-14 00:11 65536 c:\windows\ServicePackFiles\i386\icwphbk.dll + 2008-09-08 22:52 . 2008-04-14 00:11 32768 c:\windows\ServicePackFiles\i386\icwdl.dll + 2008-09-08 22:52 . 2008-04-14 00:11 73728 c:\windows\ServicePackFiles\i386\icwdial.dll + 2008-09-08 22:52 . 2008-04-14 00:12 86016 c:\windows\ServicePackFiles\i386\icwconn2.exe + 2008-09-08 22:52 . 2008-04-14 00:11 61440 c:\windows\ServicePackFiles\i386\icwconn.dll + 2008-09-08 22:52 . 2008-04-14 00:11 80384 c:\windows\ServicePackFiles\i386\iccvid.dll + 2008-09-08 22:52 . 2008-04-14 00:11 11264 c:\windows\ServicePackFiles\i386\icaapi.dll + 2008-09-08 22:52 . 2008-04-13 19:18 52480 c:\windows\ServicePackFiles\i386\i8042prt.sys + 2008-09-08 22:52 . 2008-04-13 18:41 18560 c:\windows\ServicePackFiles\i386\i2omp.sys + 2008-09-08 22:52 . 2008-04-14 00:11 41984 c:\windows\ServicePackFiles\i386\htui.dll + 2008-09-08 22:52 . 2008-04-14 00:11 24576 c:\windows\ServicePackFiles\i386\httpapi.dll + 2008-09-08 22:52 . 2008-04-14 00:11 32285 c:\windows\ServicePackFiles\i386\hsfcisp2.dll + 2008-09-08 22:52 . 2008-04-14 00:12 18432 c:\windows\ServicePackFiles\i386\hscupd.exe + 2008-09-08 22:52 . 2008-04-14 00:11 87552 c:\windows\ServicePackFiles\i386\hpfud50.dll + 2008-09-08 22:52 . 2008-04-14 00:11 10240 c:\windows\ServicePackFiles\i386\hpcjrrps.dll + 2008-09-08 22:52 . 2008-04-14 00:11 10752 c:\windows\ServicePackFiles\i386\hpcjrr.dll + 2008-09-08 22:52 . 2008-04-14 00:11 39936 c:\windows\ServicePackFiles\i386\hostmib.dll + 2008-09-08 22:52 . 2008-04-14 00:11 38912 c:\windows\ServicePackFiles\i386\hmmapi.dll + 2008-09-08 22:52 . 2008-04-14 00:11 72704 c:\windows\ServicePackFiles\i386\hlink.dll + 2008-09-08 22:52 . 2008-04-13 18:45 10368 c:\windows\ServicePackFiles\i386\hidusb.sys + 2008-09-08 22:52 . 2008-04-14 00:11 21504 c:\windows\ServicePackFiles\i386\hidserv.dll + 2008-09-08 22:52 . 2008-04-13 18:45 24960 c:\windows\ServicePackFiles\i386\hidparse.sys + 2008-09-08 22:52 . 2008-04-13 18:45 19200 c:\windows\ServicePackFiles\i386\hidir.sys + 2008-09-08 22:52 . 2008-04-13 18:45 36864 c:\windows\ServicePackFiles\i386\hidclass.sys + 2008-09-08 22:52 . 2008-04-13 18:46 25600 c:\windows\ServicePackFiles\i386\hidbth.sys + 2008-09-08 22:52 . 2008-04-13 18:36 20352 c:\windows\ServicePackFiles\i386\hidbatt.sys + 2008-09-08 22:52 . 2008-04-14 00:11 20992 c:\windows\ServicePackFiles\i386\hid.dll + 2008-09-08 22:52 . 2008-04-14 00:11 41472 c:\windows\ServicePackFiles\i386\hhsetup.dll + 2008-09-08 22:52 . 2008-04-14 00:12 10752 c:\windows\ServicePackFiles\i386\hh.exe + 2008-09-08 22:52 . 2008-04-14 00:12 15872 c:\windows\ServicePackFiles\i386\help.exe + 2008-09-08 22:52 . 2008-04-13 18:31 77696 c:\windows\ServicePackFiles\i386\halsp.dll + 2008-09-08 22:52 . 2008-04-13 18:31 81152 c:\windows\ServicePackFiles\i386\halacpi.dll + 2008-09-08 22:52 . 2008-04-14 00:11 57344 c:\windows\ServicePackFiles\i386\h323cc.dll + 2008-09-08 22:52 . 2008-04-13 18:40 28288 c:\windows\ServicePackFiles\i386\grserial.sys + 2008-09-08 22:52 . 2008-04-14 00:12 39424 c:\windows\ServicePackFiles\i386\grpconv.exe + 2008-09-08 22:52 . 2008-04-13 18:45 59136 c:\windows\ServicePackFiles\i386\gckernel.sys + 2008-09-08 22:52 . 2008-04-13 18:45 10624 c:\windows\ServicePackFiles\i386\gameenum.sys + 2008-09-08 22:52 . 2008-04-13 18:36 46464 c:\windows\ServicePackFiles\i386\gagp30kx.sys + 2008-09-08 22:52 . 2008-04-14 00:11 23552 c:\windows\ServicePackFiles\i386\fxsmon.dll + 2008-09-08 22:52 . 2008-04-14 00:11 23552 c:\windows\ServicePackFiles\i386\fxsext32.dll + 2008-09-08 22:52 . 2008-04-14 00:11 55296 c:\windows\ServicePackFiles\i386\fxsevent.dll + 2008-09-08 22:52 . 2008-04-14 00:11 26624 c:\windows\ServicePackFiles\i386\fxsdrv.dll + 2008-09-08 22:52 . 2008-04-14 00:11 72192 c:\windows\ServicePackFiles\i386\fxscom.dll + 2008-09-08 22:52 . 2008-04-14 00:11 60416 c:\windows\ServicePackFiles\i386\fwcfg.dll + 2008-09-08 22:52 . 2008-04-14 00:12 42496 c:\windows\ServicePackFiles\i386\ftp.exe + 2008-09-08 22:52 . 2008-04-14 00:12 28728 c:\windows\ServicePackFiles\i386\fpsrvadm.exe + 2008-04-14 00:12 . 2008-04-14 00:12 20538 c:\windows\ServicePackFiles\i386\fpremadm.exe + 2008-09-08 22:52 . 2008-04-14 00:11 20541 c:\windows\ServicePackFiles\i386\fpexedll.dll + 2008-09-08 22:52 . 2008-04-14 00:11 94208 c:\windows\ServicePackFiles\i386\fpencode.dll + 2008-09-08 22:52 . 2008-04-14 00:11 20541 c:\windows\ServicePackFiles\i386\fpadmdll.dll + 2008-09-08 22:52 . 2008-04-14 00:12 24632 c:\windows\ServicePackFiles\i386\fpadmcgi.exe + 2008-09-08 22:52 . 2008-04-14 00:12 15120 c:\windows\ServicePackFiles\i386\fp98sadm.exe + 2008-09-08 22:52 . 2008-04-14 00:11 49212 c:\windows\ServicePackFiles\i386\fp4awebs.dll + 2008-09-08 22:52 . 2008-04-14 00:11 32826 c:\windows\ServicePackFiles\i386\fp4avss.dll + 2008-09-08 22:52 . 2008-04-14 00:11 41020 c:\windows\ServicePackFiles\i386\fp4avnb.dll + 2008-09-08 22:52 . 2008-04-14 00:11 49210 c:\windows\ServicePackFiles\i386\fp4areg.dll + 2008-09-08 22:52 . 2008-04-14 00:11 82035 c:\windows\ServicePackFiles\i386\fp4anscp.dll + 2008-09-08 22:52 . 2008-04-14 00:11 32828 c:\windows\ServicePackFiles\i386\fp40ext.dll + 2008-09-08 22:52 . 2008-04-14 00:12 29696 c:\windows\ServicePackFiles\i386\format.com + 2008-09-08 22:52 . 2004-08-03 21:31 34173 c:\windows\ServicePackFiles\i386\forehe.sys + 2008-09-08 22:52 . 2008-04-14 00:12 20992 c:\windows\ServicePackFiles\i386\fontview.exe + 2008-09-08 22:52 . 2008-04-14 00:11 80896 c:\windows\ServicePackFiles\i386\fontsub.dll + 2008-09-08 22:52 . 2008-04-14 00:12 23040 c:\windows\ServicePackFiles\i386\fltmc.exe + 2008-09-08 22:52 . 2008-04-14 00:11 16896 c:\windows\ServicePackFiles\i386\fltlib.dll + 2008-09-08 22:52 . 2008-04-13 18:40 20480 c:\windows\ServicePackFiles\i386\flpydisk.sys + 2008-09-08 22:52 . 2008-04-14 00:11 87552 c:\windows\ServicePackFiles\i386\fldrclnr.dll + 2008-09-08 22:52 . 2008-04-13 18:33 44544 c:\windows\ServicePackFiles\i386\fips.sys + 2008-09-08 22:52 . 2008-04-14 00:12 27136 c:\windows\ServicePackFiles\i386\findstr.exe + 2008-09-08 22:52 . 2008-04-14 00:11 21504 c:\windows\ServicePackFiles\i386\feclient.dll + 2008-09-08 22:52 . 2008-04-13 18:40 27392 c:\windows\ServicePackFiles\i386\fdc.sys + 2008-09-08 22:52 . 2008-04-14 00:12 20992 c:\windows\ServicePackFiles\i386\faxpatch.exe + 2008-09-08 22:52 . 2008-04-14 00:11 80384 c:\windows\ServicePackFiles\i386\faultrep.dll + 2008-09-08 22:52 . 2008-04-14 00:12 24064 c:\windows\ServicePackFiles\i386\extrac32.exe + 2008-09-08 22:52 . 2008-04-14 00:11 55808 c:\windows\ServicePackFiles\i386\extmgr.dll + 2008-09-08 22:52 . 2008-04-14 00:12 92160 c:\windows\ServicePackFiles\i386\evntwin.exe + 2008-09-08 22:52 . 2008-04-14 00:11 21504 c:\windows\ServicePackFiles\i386\evntrprv.dll + 2008-09-08 22:52 . 2008-04-14 00:12 24064 c:\windows\ServicePackFiles\i386\evntcmd.exe + 2008-09-08 22:52 . 2008-04-14 00:11 56320 c:\windows\ServicePackFiles\i386\eventlog.dll + 2008-09-08 22:52 . 2008-04-14 00:11 23040 c:\windows\ServicePackFiles\i386\ersvc.dll + 2008-09-08 22:52 . 2008-04-13 16:26 40960 c:\windows\ServicePackFiles\i386\ep9res.dll + 2008-09-08 22:52 . 2008-04-14 00:11 20480 c:\windows\ServicePackFiles\i386\encapi.dll + 2008-09-08 22:52 . 2008-04-14 00:11 33792 c:\windows\ServicePackFiles\i386\eapsvc.dll + 2008-09-08 22:52 . 2008-04-14 00:11 59392 c:\windows\ServicePackFiles\i386\eapqec.dll + 2008-09-08 22:52 . 2008-04-14 00:11 40960 c:\windows\ServicePackFiles\i386\eappprxy.dll + 2008-09-08 22:52 . 2008-04-14 00:11 94208 c:\windows\ServicePackFiles\i386\eappgnui.dll + 2008-09-08 22:52 . 2008-04-14 00:11 30720 c:\windows\ServicePackFiles\i386\eapolqec.dll + 2008-09-08 22:52 . 2008-04-13 18:38 71168 c:\windows\ServicePackFiles\i386\dxg.sys + 2008-09-08 22:52 . 2008-04-14 00:12 17920 c:\windows\ServicePackFiles\i386\dvdupgrd.exe + 2008-09-08 22:52 . 2008-04-14 00:12 10752 c:\windows\ServicePackFiles\i386\dumprep.exe + 2008-09-08 22:52 . 2008-04-14 00:11 19456 c:\windows\ServicePackFiles\i386\dswave.dll + 2008-09-08 22:52 . 2008-04-14 00:11 51200 c:\windows\ServicePackFiles\i386\dssec.dll + 2008-09-08 22:52 . 2008-04-14 00:11 92672 c:\windows\ServicePackFiles\i386\dskquota.dll + 2008-09-08 22:52 . 2008-04-14 00:11 71680 c:\windows\ServicePackFiles\i386\dsdmoprp.dll + 2008-09-08 22:52 . 2008-04-14 00:11 16384 c:\windows\ServicePackFiles\i386\ds32gt.dll + 2008-09-08 22:52 . 2008-04-14 00:11 14336 c:\windows\ServicePackFiles\i386\drprov.dll + 2008-09-08 22:52 . 2008-04-13 18:45 60160 c:\windows\ServicePackFiles\i386\drmk.sys + 2008-09-08 22:52 . 2008-04-14 00:11 57344 c:\windows\ServicePackFiles\i386\dpwsockx.dll + 2008-09-08 22:52 . 2008-04-14 00:12 83456 c:\windows\ServicePackFiles\i386\dpvsetup.exe + 2008-09-08 22:52 . 2008-04-14 00:11 21504 c:\windows\ServicePackFiles\i386\dpvacm.dll + 2008-09-08 22:52 . 2008-04-14 00:12 17920 c:\windows\ServicePackFiles\i386\dpnsvr.exe + 2008-09-08 22:52 . 2008-04-14 00:11 60928 c:\windows\ServicePackFiles\i386\dpnhupnp.dll + 2008-09-08 22:52 . 2008-04-14 00:11 35328 c:\windows\ServicePackFiles\i386\dpnhpast.dll + 2008-09-08 22:52 . 2008-04-14 00:11 23552 c:\windows\ServicePackFiles\i386\dpmodemx.dll + 2008-09-08 22:52 . 2008-04-14 00:12 29696 c:\windows\ServicePackFiles\i386\dplaysvr.exe + 2008-09-08 22:52 . 2008-04-14 00:11 56320 c:\windows\ServicePackFiles\i386\dot3msm.dll + 2008-09-08 22:52 . 2008-04-14 00:11 39936 c:\windows\ServicePackFiles\i386\dot3clnt.dll + 2008-09-08 22:52 . 2008-04-14 00:11 57856 c:\windows\ServicePackFiles\i386\dot3cfg.dll + 2008-09-08 22:52 . 2008-04-14 00:11 26112 c:\windows\ServicePackFiles\i386\dot3api.dll + 2008-09-08 22:52 . 2004-08-04 12:00 53840 c:\windows\ServicePackFiles\i386\dosx.exe + 2008-09-08 22:52 . 2008-04-14 00:11 48128 c:\windows\ServicePackFiles\i386\docprop2.dll + 2008-09-08 22:52 . 2008-04-14 00:11 45568 c:\windows\ServicePackFiles\i386\dnsrslvr.dll + 2008-09-08 22:52 . 2008-04-14 00:11 52224 c:\windows\ServicePackFiles\i386\dmutil.dll |
|
|
|
|
#13 (permalink) |
|
Registered User
Join Date: Jul 2009
Posts: 14
OS: xp
|
Re: Recurring Vundo Trojan
+ 2008-09-08 22:52 . 2008-04-13 18:45 52864 c:\windows\ServicePackFiles\i386\dmusic.sys
+ 2008-09-08 22:52 . 2008-04-14 00:11 23552 c:\windows\ServicePackFiles\i386\dmserver.dll + 2008-09-08 22:52 . 2008-04-14 00:11 82432 c:\windows\ServicePackFiles\i386\dmscript.dll + 2008-09-08 22:52 . 2008-04-14 00:12 15872 c:\windows\ServicePackFiles\i386\dmremote.exe + 2008-09-08 22:52 . 2008-04-14 00:11 35840 c:\windows\ServicePackFiles\i386\dmloader.dll + 2008-09-08 22:52 . 2008-04-14 00:11 61440 c:\windows\ServicePackFiles\i386\dmcompos.dll + 2008-09-08 22:52 . 2008-04-14 00:11 28672 c:\windows\ServicePackFiles\i386\dmband.dll + 2008-09-08 22:52 . 2008-04-14 00:11 32768 c:\windows\ServicePackFiles\i386\dispex.dll + 2008-09-08 22:52 . 2008-04-13 18:40 14208 c:\windows\ServicePackFiles\i386\diskdump.sys + 2008-09-08 22:52 . 2008-04-13 18:40 36352 c:\windows\ServicePackFiles\i386\disk.sys + 2008-09-08 22:52 . 2008-04-14 00:11 86528 c:\windows\ServicePackFiles\i386\directdb.dll + 2008-09-08 22:52 . 2008-04-14 00:11 39936 c:\windows\ServicePackFiles\i386\dimsroam.dll + 2008-09-08 22:52 . 2008-04-14 00:11 19456 c:\windows\ServicePackFiles\i386\dimsntfy.dll + 2008-09-08 22:52 . 2008-04-14 00:11 68608 c:\windows\ServicePackFiles\i386\digest.dll + 2008-09-08 22:52 . 2008-04-14 00:12 87040 c:\windows\ServicePackFiles\i386\diantz.exe + 2008-09-08 22:52 . 2008-04-14 00:11 48640 c:\windows\ServicePackFiles\i386\dhcpqec.dll + 2008-09-08 22:52 . 2008-04-14 00:11 28672 c:\windows\ServicePackFiles\i386\dfsshlex.dll + 2008-09-08 22:52 . 2008-04-14 00:11 39424 c:\windows\ServicePackFiles\i386\dfrgsnap.dll + 2008-09-08 22:52 . 2008-04-14 00:12 82944 c:\windows\ServicePackFiles\i386\dfrgfat.exe + 2008-09-08 22:52 . 2008-04-14 00:11 59904 c:\windows\ServicePackFiles\i386\devenum.dll + 2008-09-08 22:52 . 2008-04-14 00:12 25088 c:\windows\ServicePackFiles\i386\defrag.exe + 2008-09-08 22:52 . 2008-04-14 00:11 27136 c:\windows\ServicePackFiles\i386\ddrawex.dll + 2008-09-08 22:52 . 2008-04-14 00:12 30208 c:\windows\ServicePackFiles\i386\ddeshare.exe + 2008-09-08 22:52 . 2008-04-14 00:11 40960 c:\windows\ServicePackFiles\i386\dcap32.dll + 2008-09-08 22:52 . 2008-04-14 00:11 28672 c:\windows\ServicePackFiles\i386\dbnmpntw.dll + 2008-09-08 22:52 . 2008-04-14 00:11 24576 c:\windows\ServicePackFiles\i386\dbmsrpcn.dll + 2008-09-08 22:52 . 2008-04-14 00:11 25088 c:\windows\ServicePackFiles\i386\davclnt.dll + 2008-09-08 22:52 . 2008-04-14 00:11 54272 c:\windows\ServicePackFiles\i386\dataclen.dll + 2008-09-08 22:52 . 2004-08-03 21:32 48640 c:\windows\ServicePackFiles\i386\cwrwdm.sys + 2008-09-08 22:52 . 2008-04-14 00:11 33792 c:\windows\ServicePackFiles\i386\custsat.dll + 2008-09-08 22:52 . 2008-04-14 00:12 15360 c:\windows\ServicePackFiles\i386\ctfmon.exe + 2008-09-08 22:52 . 2008-04-14 00:11 32256 c:\windows\ServicePackFiles\i386\csrsrv.dll + 2008-09-08 22:52 . 2008-04-14 00:11 62464 c:\windows\ServicePackFiles\i386\cryptsvc.dll + 2008-09-08 22:52 . 2008-04-14 00:11 64512 c:\windows\ServicePackFiles\i386\cryptnet.dll + 2008-09-08 22:52 . 2008-04-14 00:11 53760 c:\windows\ServicePackFiles\i386\cryptext.dll + 2008-09-08 22:52 . 2008-04-14 00:11 33280 c:\windows\ServicePackFiles\i386\cryptdll.dll + 2008-09-08 22:52 . 2008-04-14 00:11 74752 c:\windows\ServicePackFiles\i386\cryptdlg.dll + 2008-09-08 22:52 . 2008-04-13 18:31 36736 c:\windows\ServicePackFiles\i386\crusoe.sys + 2008-09-08 22:52 . 2008-04-14 00:11 12800 c:\windows\ServicePackFiles\i386\credssp.dll + 2008-09-08 22:52 . 2008-04-14 00:11 35328 c:\windows\ServicePackFiles\i386\corpol.dll + 2008-09-08 22:52 . 2008-04-14 00:12 27648 c:\windows\ServicePackFiles\i386\conime.exe + 2008-09-08 22:52 . 2008-04-14 00:11 45056 c:\windows\ServicePackFiles\i386\confmrsl.dll + 2008-09-08 22:52 . 2008-04-14 00:11 97792 c:\windows\ServicePackFiles\i386\comrepl.dll + 2008-09-08 22:52 . 2008-04-13 18:36 10240 c:\windows\ServicePackFiles\i386\compbatt.sys + 2008-09-08 22:52 . 2008-04-14 00:11 28160 c:\windows\ServicePackFiles\i386\comaddin.dll + 2008-09-08 22:52 . 2008-04-14 00:11 60416 c:\windows\ServicePackFiles\i386\colbact.dll + 2008-09-08 22:52 . 2008-04-13 16:44 17920 c:\windows\ServicePackFiles\i386\cobramsg.dll + 2008-09-08 22:52 . 2008-04-14 00:11 79360 c:\windows\ServicePackFiles\i386\cnbjmon2.dll + 2008-09-08 22:52 . 2008-04-14 00:11 47104 c:\windows\ServicePackFiles\i386\cnbjmon.dll + 2008-09-08 22:52 . 2008-04-14 00:11 39424 c:\windows\ServicePackFiles\i386\cmutil.dll + 2008-09-08 22:52 . 2008-04-14 00:12 63488 c:\windows\ServicePackFiles\i386\cmstp.exe + 2008-09-08 22:52 . 2008-04-14 00:11 13312 c:\windows\ServicePackFiles\i386\cmsetacl.dll + 2008-09-08 22:52 . 2008-04-14 00:12 39936 c:\windows\ServicePackFiles\i386\cmmon32.exe + 2008-09-08 22:52 . 2008-04-14 00:12 25600 c:\windows\ServicePackFiles\i386\cmdl32.exe + 2008-09-08 22:52 . 2008-04-14 00:11 15872 c:\windows\ServicePackFiles\i386\cmcfg32.dll + 2008-09-08 22:52 . 2008-04-13 18:36 13952 c:\windows\ServicePackFiles\i386\cmbatt.sys + 2008-09-08 22:52 . 2008-04-14 00:11 58368 c:\windows\ServicePackFiles\i386\clusapi.dll + 2008-09-08 22:52 . 2008-04-14 00:12 33280 c:\windows\ServicePackFiles\i386\clipsrv.exe + 2008-09-08 22:52 . 2008-04-14 00:12 20480 c:\windows\ServicePackFiles\i386\cliconfg.exe + 2008-09-08 22:52 . 2008-04-14 00:11 77824 c:\windows\ServicePackFiles\i386\cliconfg.dll + 2008-09-08 22:52 . 2008-04-14 00:12 64000 c:\windows\ServicePackFiles\i386\cleanmgr.exe + 2008-09-08 22:52 . 2008-04-13 19:16 49536 c:\windows\ServicePackFiles\i386\classpnp.sys + 2008-09-08 22:52 . 2008-04-14 00:11 69120 c:\windows\ServicePackFiles\i386\ciodm.dll + 2008-09-08 22:52 . 2008-04-14 00:11 15423 c:\windows\ServicePackFiles\i386\ch7xxnt5.dll + 2008-09-08 22:52 . 2008-04-14 00:09 16896 c:\windows\ServicePackFiles\i386\cfgmgr32.dll + 2008-09-08 22:52 . 2008-04-14 00:11 38912 c:\windows\ServicePackFiles\i386\cfgbkend.dll + 2008-09-08 22:52 . 2008-04-13 18:40 62976 c:\windows\ServicePackFiles\i386\cdrom.sys + 2008-09-08 22:52 . 2008-04-14 00:11 66560 c:\windows\ServicePackFiles\i386\cdm.dll + 2008-09-08 22:52 . 2008-04-13 19:14 63744 c:\windows\ServicePackFiles\i386\cdfs.sys + 2008-09-08 22:52 . 2008-04-13 18:46 17024 c:\windows\ServicePackFiles\i386\ccdecode.sys + 2008-09-08 22:52 . 2008-04-14 00:11 85504 c:\windows\ServicePackFiles\i386\catsrvps.dll + 2008-09-08 22:52 . 2008-04-14 00:11 50688 c:\windows\ServicePackFiles\i386\camocx.dll + 2008-09-08 22:52 . 2008-04-14 00:12 19968 c:\windows\ServicePackFiles\i386\cacls.exe + 2008-09-08 22:52 . 2008-04-14 00:11 84480 c:\windows\ServicePackFiles\i386\cabview.dll + 2008-09-08 22:52 . 2008-04-14 00:11 60416 c:\windows\ServicePackFiles\i386\cabinet.dll + 2008-09-08 22:52 . 2008-04-14 00:11 50688 c:\windows\ServicePackFiles\i386\btpanui.dll + 2008-09-08 22:52 . 2008-04-13 18:46 18944 c:\windows\ServicePackFiles\i386\bthusb.sys + 2008-09-08 22:52 . 2008-04-14 00:11 30208 c:\windows\ServicePackFiles\i386\bthserv.dll + 2008-09-08 22:52 . 2008-04-13 18:46 36480 c:\windows\ServicePackFiles\i386\bthprint.sys + 2008-09-08 22:52 . 2008-04-13 18:46 37888 c:\windows\ServicePackFiles\i386\bthmodem.sys + 2008-09-08 22:52 . 2008-04-13 18:46 17024 c:\windows\ServicePackFiles\i386\bthenum.sys + 2008-09-08 22:52 . 2008-04-14 00:11 20992 c:\windows\ServicePackFiles\i386\bthci.dll + 2008-09-08 22:52 . 2008-04-14 00:11 78336 c:\windows\ServicePackFiles\i386\browsewm.dll + 2008-09-08 22:52 . 2008-04-14 00:11 77824 c:\windows\ServicePackFiles\i386\browser.dll + 2008-09-08 22:52 . 2008-04-13 17:03 63488 c:\windows\ServicePackFiles\i386\browselc.dll + 2008-09-08 22:51 . 2008-04-13 18:53 71552 c:\windows\ServicePackFiles\i386\bridge.sys + 2008-09-08 22:51 . 2008-04-14 00:12 71680 c:\windows\ServicePackFiles\i386\blastcln.exe + 2008-09-08 22:51 . 2008-04-14 00:11 17408 c:\windows\ServicePackFiles\i386\bidispl.dll + 2008-09-08 22:51 . 2008-04-13 18:46 11776 c:\windows\ServicePackFiles\i386\bdasup.sys + 2008-09-08 22:51 . 2008-04-13 18:36 14208 c:\windows\ServicePackFiles\i386\battc.sys + 2008-09-08 22:51 . 2008-04-14 00:11 29184 c:\windows\ServicePackFiles\i386\batmeter.dll + 2008-09-08 22:51 . 2008-04-14 00:11 52736 c:\windows\ServicePackFiles\i386\basesrv.dll + 2008-09-08 22:51 . 2008-04-14 00:11 84992 c:\windows\ServicePackFiles\i386\avifil32.dll + 2008-09-08 22:51 . 2008-04-13 18:46 13696 c:\windows\ServicePackFiles\i386\avcstrm.sys + 2008-09-08 22:51 . 2008-04-13 18:46 38912 c:\windows\ServicePackFiles\i386\avc.sys + 2008-09-08 22:51 . 2008-04-14 00:12 11264 c:\windows\ServicePackFiles\i386\autolfn.exe + 2008-09-08 22:51 . 2008-04-14 00:11 62464 c:\windows\ServicePackFiles\i386\authz.dll + 2008-09-08 22:51 . 2008-04-14 00:12 16439 c:\windows\ServicePackFiles\i386\author.exe + 2008-09-08 22:51 . 2008-04-14 00:11 20540 c:\windows\ServicePackFiles\i386\author.dll + 2008-09-08 22:51 . 2008-04-14 00:12 14336 c:\windows\ServicePackFiles\i386\auditusr.exe + 2008-09-08 22:51 . 2008-04-14 00:11 42496 c:\windows\ServicePackFiles\i386\audiosrv.dll + 2008-09-08 22:51 . 2008-04-14 00:11 17279 c:\windows\ServicePackFiles\i386\atv10nt5.dll + 2008-09-08 22:51 . 2008-04-14 00:11 14143 c:\windows\ServicePackFiles\i386\atv06nt5.dll + 2008-09-08 22:51 . 2008-04-14 00:11 25471 c:\windows\ServicePackFiles\i386\atv04nt5.dll + 2008-09-08 22:51 . 2008-04-14 00:11 11359 c:\windows\ServicePackFiles\i386\atv02nt5.dll + 2008-09-08 22:51 . 2008-04-14 00:11 21183 c:\windows\ServicePackFiles\i386\atv01nt5.dll + 2008-09-08 22:51 . 2008-04-14 00:12 12288 c:\windows\ServicePackFiles\i386\attrib.exe + 2008-09-08 22:51 . 2008-04-14 00:11 30208 c:\windows\ServicePackFiles\i386\atmlib.dll + 2008-09-08 22:51 . 2008-04-13 18:51 55808 c:\windows\ServicePackFiles\i386\atmlane.sys + 2008-09-08 22:51 . 2008-04-13 18:51 59904 c:\windows\ServicePackFiles\i386\atmarpc.sys + 2008-09-08 22:51 . 2008-04-14 00:12 11264 c:\windows\ServicePackFiles\i386\atmadm.exe + 2008-09-08 22:51 . 2008-04-14 00:11 58880 c:\windows\ServicePackFiles\i386\atl.dll + 2008-09-08 22:51 . 2008-04-14 00:11 32768 c:\windows\ServicePackFiles\i386\ativtmxx.dll + 2008-09-08 22:51 . 2004-08-03 21:29 63488 c:\windows\ServicePackFiles\i386\atinxsxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 31744 c:\windows\ServicePackFiles\i386\atinxbxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 73216 c:\windows\ServicePackFiles\i386\atintuxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 13824 c:\windows\ServicePackFiles\i386\atinttxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 28672 c:\windows\ServicePackFiles\i386\atinsnxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 52224 c:\windows\ServicePackFiles\i386\atinraxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 14336 c:\windows\ServicePackFiles\i386\atinpdxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 13824 c:\windows\ServicePackFiles\i386\atinmdxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 57856 c:\windows\ServicePackFiles\i386\atinbtxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 34735 c:\windows\ServicePackFiles\i386\ati1xsxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 29455 c:\windows\ServicePackFiles\i386\ati1xbxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 36463 c:\windows\ServicePackFiles\i386\ati1tuxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 21343 c:\windows\ServicePackFiles\i386\ati1ttxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 26367 c:\windows\ServicePackFiles\i386\ati1snxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 63663 c:\windows\ServicePackFiles\i386\ati1rvxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 30671 c:\windows\ServicePackFiles\i386\ati1raxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 12047 c:\windows\ServicePackFiles\i386\ati1pdxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 11615 c:\windows\ServicePackFiles\i386\ati1mdxx.sys + 2008-09-08 22:51 . 2004-08-03 21:29 56623 c:\windows\ServicePackFiles\i386\ati1btxx.sys + 2008-09-08 22:51 . 2008-04-13 18:40 96512 c:\windows\ServicePackFiles\i386\atapi.sys + 2008-09-08 22:51 . 2008-04-14 00:12 25088 c:\windows\ServicePackFiles\i386\at.exe + 2008-09-08 22:51 . 2008-04-13 18:57 14336 c:\windows\ServicePackFiles\i386\asyncmac.sys + 2008-09-08 22:51 . 2008-04-14 00:11 65024 c:\windows\ServicePackFiles\i386\asycfilt.dll + 2008-09-08 22:51 . 2008-04-13 18:51 60800 c:\windows\ServicePackFiles\i386\arp1394.sys + 2008-09-08 22:51 . 2004-08-03 21:31 36224 c:\windows\ServicePackFiles\i386\an983.sys + 2008-09-08 22:51 . 2008-04-14 00:11 70656 c:\windows\ServicePackFiles\i386\amstream.dll + 2008-09-08 22:51 . 2008-04-13 18:31 37760 c:\windows\ServicePackFiles\i386\amdk7.sys + 2008-09-08 22:51 . 2008-04-13 18:31 37376 c:\windows\ServicePackFiles\i386\amdk6.sys + 2008-09-08 22:51 . 2008-04-13 18:36 43008 c:\windows\ServicePackFiles\i386\amdagp.sys + 2008-09-08 22:51 . 2008-04-14 00:11 17408 c:\windows\ServicePackFiles\i386\alrsvc.dll + 2008-09-08 22:51 . 2008-04-13 18:36 42752 c:\windows\ServicePackFiles\i386\alim1541.sys + 2008-09-08 22:51 . 2008-04-14 00:12 44544 c:\windows\ServicePackFiles\i386\alg.exe + 2008-09-08 22:51 . 2008-04-14 00:12 98304 c:\windows\ServicePackFiles\i386\ahui.exe + 2008-09-08 22:51 . 2008-04-14 00:11 24064 c:\windows\ServicePackFiles\i386\agtintl.dll + 2008-09-08 22:51 . 2007-04-02 18:26 20480 c:\windows\ServicePackFiles\i386\agt0c0a.dll + 2008-09-08 22:51 . 2007-04-02 18:26 20992 c:\windows\ServicePackFiles\i386\agt0816.dll + 2008-09-08 22:51 . 2007-04-02 18:26 19456 c:\windows\ServicePackFiles\i386\agt0804.dll + 2008-09-08 22:51 . 2007-04-02 18:26 19456 c:\windows\ServicePackFiles\i386\agt041f.dll + 2008-09-08 22:51 . 2007-04-02 18:26 19456 c:\windows\ServicePackFiles\i386\agt041d.dll + 2008-09-08 22:51 . 2007-04-02 18:26 19456 c:\windows\ServicePackFiles\i386\agt0419.dll + 2008-09-08 22:51 . 2007-04-02 18:26 20480 c:\windows\ServicePackFiles\i386\agt0416.dll + 2008-09-08 22:51 . 2007-04-02 18:26 19456 c:\windows\ServicePackFiles\i386\agt0415.dll + 2008-09-08 22:51 . 2007-04-02 18:26 19456 c:\windows\ServicePackFiles\i386\agt0414.dll + 2008-09-08 22:51 . 2007-04-02 18:26 20992 c:\windows\ServicePackFiles\i386\agt0413.dll + 2008-09-08 22:51 . 2007-04-02 18:26 19456 c:\windows\ServicePackFiles\i386\agt0412.dll + 2008-09-08 22:51 . 2007-04-02 18:26 19456 c:\windows\ServicePackFiles\i386\agt0411.dll + 2008-09-08 22:51 . 2007-04-02 18:26 20992 c:\windows\ServicePackFiles\i386\agt0410.dll + 2008-09-08 22:51 . 2007-04-02 18:26 19968 c:\windows\ServicePackFiles\i386\agt040e.dll + 2008-09-08 22:51 . 2007-04-02 18:26 19456 c:\windows\ServicePackFiles\i386\agt040d.dll + 2008-09-08 22:51 . 2007-04-02 18:26 21504 c:\windows\ServicePackFiles\i386\agt040c.dll + 2008-09-08 22:51 . 2007-04-02 18:26 19456 c:\windows\ServicePackFiles\i386\agt040b.dll + 2008-09-08 22:51 . 2008-04-13 17:32 19968 c:\windows\ServicePackFiles\i386\agt0409.dll + 2008-09-08 22:51 . 2007-04-02 18:26 22016 c:\windows\ServicePackFiles\i386\agt0408.dll + 2008-09-08 22:51 . 2007-04-02 18:26 21504 c:\windows\ServicePackFiles\i386\agt0407.dll + 2008-09-08 22:51 . 2007-04-02 18:25 19456 c:\windows\ServicePackFiles\i386\agt0406.dll + 2008-09-08 22:51 . 2007-04-02 18:25 19456 c:\windows\ServicePackFiles\i386\agt0405.dll + 2008-09-08 22:51 . 2007-04-02 18:25 19456 c:\windows\ServicePackFiles\i386\agt0404.dll + 2008-09-08 22:51 . 2007-04-02 18:25 19456 c:\windows\ServicePackFiles\i386\agt0401.dll + 2008-09-08 22:51 . 2008-04-13 18:36 44928 c:\windows\ServicePackFiles\i386\agpcpq.sys + 2008-09-08 22:51 . 2008-04-13 18:36 42368 c:\windows\ServicePackFiles\i386\agp440.sys + 2008-09-08 22:51 . 2008-04-14 00:11 44032 c:\windows\ServicePackFiles\i386\agentsr.dll + 2008-09-08 22:51 . 2008-04-14 00:11 24064 c:\windows\ServicePackFiles\i386\agentpsh.dll + 2008-09-08 22:51 . 2008-04-14 00:11 49152 c:\windows\ServicePackFiles\i386\agentmpx.dll + 2008-09-08 22:51 . 2008-04-14 00:11 57344 c:\windows\ServicePackFiles\i386\agentdpv.dll + 2008-09-08 22:51 . 2008-04-14 00:11 42496 c:\windows\ServicePackFiles\i386\agentdp2.dll + 2008-09-08 22:51 . 2008-04-14 00:11 24064 c:\windows\ServicePackFiles\i386\agentanm.dll + 2008-09-08 22:51 . 2008-04-14 00:11 99840 c:\windows\ServicePackFiles\i386\advpack.dll + 2008-09-08 22:51 . 2008-04-14 00:11 68096 c:\windows\ServicePackFiles\i386\adsmsext.dll + 2008-09-08 22:51 . 2008-04-14 00:11 61440 c:\windows\ServicePackFiles\i386\admparse.dll + 2008-09-08 22:51 . 2004-08-03 21:32 10880 c:\windows\ServicePackFiles\i386\admjoy.sys + 2008-04-14 00:12 . 2008-04-14 00:12 16439 c:\windows\ServicePackFiles\i386\admin.exe + 2008-09-08 22:51 . 2008-04-14 00:11 20540 c:\windows\ServicePackFiles\i386\admin.dll + 2008-09-08 22:51 . 2008-04-14 00:11 98304 c:\windows\ServicePackFiles\i386\actxprxy.dll + 2008-09-08 22:51 . 2008-04-14 00:11 39424 c:\windows\ServicePackFiles\i386\acadproc.dll + 2008-09-08 22:51 . 2004-08-03 21:32 84480 c:\windows\ServicePackFiles\i386\ac97via.sys + 2008-09-08 22:51 . 2008-04-13 18:46 48128 c:\windows\ServicePackFiles\i386\61883.sys + 2008-09-08 22:51 . 2008-04-13 18:40 12288 c:\windows\ServicePackFiles\i386\4mmdat.sys + 2008-09-08 22:51 . 2008-04-13 18:46 53376 c:\windows\ServicePackFiles\i386\1394bus.sys + 2005-11-25 08:59 . 2008-04-14 00:12 38400 c:\windows\pchealth\helpctr\binaries\pchsvc.dll + 2005-11-25 08:59 . 2008-04-14 00:12 18432 c:\windows\pchealth\helpctr\binaries\hscupd.exe + 2005-11-25 08:54 . 2008-04-14 00:12 69120 c:\windows\notepad.exe - 2005-11-25 08:54 . 2004-08-04 12:00 69120 c:\windows\NOTEPAD.EXE + 2008-09-08 22:52 . 2008-04-14 00:11 33792 c:\windows\network diagnostic\custsat.dll - 2005-09-09 22:03 . 2004-08-04 12:00 39936 c:\windows\msagent\mslwvtts.dll + 2005-09-09 22:03 . 2008-04-14 00:12 39936 c:\windows\msagent\mslwvtts.dll - 2005-09-09 22:03 . 2004-08-04 12:00 20480 c:\windows\msagent\intl\agt0c0a.dll + 2005-09-09 22:03 . 2007-04-02 18:26 20480 c:\windows\msagent\intl\agt0c0a.dll - 2005-09-09 22:03 . 2004-08-04 12:00 20992 c:\windows\msagent\intl\agt0816.dll + 2005-09-09 22:03 . 2007-04-02 18:26 20992 c:\windows\msagent\intl\agt0816.dll + 2005-11-25 08:54 . 2007-04-02 18:26 19456 c:\windows\msagent\intl\agt041f.dll - 2005-11-25 08:54 . 2004-08-04 12:00 19456 c:\windows\msagent\intl\agt041f.dll + 2005-09-09 22:03 . 2007-04-02 18:26 19456 c:\windows\msagent\intl\agt041d.dll - 2005-09-09 22:03 . 2004-08-04 12:00 19456 c:\windows\msagent\intl\agt041d.dll + 2005-11-25 08:54 . 2007-04-02 18:26 19456 c:\windows\msagent\intl\agt0419.dll - 2005-11-25 08:54 . 2004-08-04 12:00 19456 c:\windows\msagent\intl\agt0419.dll - 2005-09-09 22:03 . 2004-08-04 12:00 20480 c:\windows\msagent\intl\agt0416.dll + 2005-09-09 22:03 . 2007-04-02 18:26 20480 c:\windows\msagent\intl\agt0416.dll - 2005-11-25 08:54 . 2004-08-04 12:00 19456 c:\windows\msagent\intl\agt0415.dll + 2005-11-25 08:54 . 2007-04-02 18:26 19456 c:\windows\msagent\intl\agt0415.dll - 2005-09-09 22:03 . 2004-08-04 12:00 19456 c:\windows\msagent\intl\agt0414.dll + 2005-09-09 22:03 . 2007-04-02 18:26 19456 c:\windows\msagent\intl\agt0414.dll + 2005-09-09 22:03 . 2007-04-02 18:26 20992 c:\windows\msagent\intl\agt0413.dll - 2005-09-09 22:03 . 2004-08-04 12:00 20992 c:\windows\msagent\intl\agt0413.dll + 2005-09-09 22:03 . 2007-04-02 18:26 20992 c:\windows\msagent\intl\agt0410.dll - 2005-09-09 22:03 . 2004-08-04 12:00 20992 c:\windows\msagent\intl\agt0410.dll + 2005-11-25 08:54 . 2007-04-02 18:26 19968 c:\windows\msagent\intl\agt040e.dll - 2005-11-25 08:54 . 2004-08-04 12:00 19968 c:\windows\msagent\intl\agt040e.dll + 2005-09-09 22:03 . 2007-04-02 18:26 21504 c:\windows\msagent\intl\agt040c.dll - 2005-09-09 22:03 . 2004-08-04 12:00 21504 c:\windows\msagent\intl\agt040c.dll - 2005-09-09 22:03 . 2004-08-04 12:00 19456 c:\windows\msagent\intl\agt040b.dll + 2005-09-09 22:03 . 2007-04-02 18:26 19456 c:\windows\msagent\intl\agt040b.dll + 2005-09-09 22:03 . 2008-04-13 17:32 19968 c:\windows\msagent\intl\agt0409.dll + 2005-11-25 08:54 . 2007-04-02 18:26 22016 c:\windows\msagent\intl\agt0408.dll - 2005-11-25 08:54 . 2004-08-04 12:00 22016 c:\windows\msagent\intl\agt0408.dll + 2005-09-09 22:03 . 2007-04-02 18:26 21504 c:\windows\msagent\intl\agt0407.dll - 2005-09-09 22:03 . 2004-08-04 12:00 21504 c:\windows\msagent\intl\agt0407.dll - 2005-09-09 22:03 . 2004-08-04 12:00 19456 c:\windows\msagent\intl\agt0406.dll + 2005-09-09 22:03 . 2007-04-02 18:25 19456 c:\windows\msagent\intl\agt0406.dll + 2005-11-25 08:54 . 2007-04-02 18:25 19456 c:\windows\msagent\intl\agt0405.dll - 2005-11-25 08:54 . 2004-08-04 12:00 19456 c:\windows\msagent\intl\agt0405.dll - 2005-09-09 22:03 . 2004-08-04 12:00 24064 c:\windows\msagent\agtintl.dll + 2005-09-09 22:03 . 2008-04-14 00:11 24064 c:\windows\msagent\agtintl.dll - 2005-09-09 22:03 . 2004-08-04 12:00 44032 c:\windows\msagent\agentsr.dll + 2005-09-09 22:03 . 2008-04-14 00:11 44032 c:\windows\msagent\agentsr.dll - 2005-09-09 22:03 . 2004-08-04 12:00 24064 c:\windows\msagent\agentpsh.dll + 2005-09-09 22:03 . 2008-04-14 00:11 24064 c:\windows\msagent\agentpsh.dll + 2005-09-09 22:03 . 2008-04-14 00:11 49152 c:\windows\msagent\agentmpx.dll - 2005-09-09 22:03 . 2004-08-04 12:00 49152 c:\windows\msagent\agentmpx.dll + 2005-09-09 22:03 . 2008-04-14 00:11 57344 c:\windows\msagent\agentdpv.dll - 2005-09-09 22:03 . 2007-03-09 13:58 57344 c:\windows\msagent\agentdpv.dll - 2005-09-09 22:03 . 2006-10-12 13:54 42496 c:\windows\msagent\agentdp2.dll + 2005-09-09 22:03 . 2008-04-14 00:11 42496 c:\windows\msagent\agentdp2.dll + 2005-09-09 22:03 . 2008-04-14 00:11 24064 c:\windows\msagent\agentanm.dll - 2005-09-09 22:03 . 2004-08-04 12:00 24064 c:\windows\msagent\agentanm.dll + 2008-09-08 22:53 . 2008-04-14 00:11 25600 c:\windows\Installer\tsclientmsitrans\tscupdc.dll + 2008-09-08 22:53 . 2007-10-30 10:06 13801 c:\windows\Installer\tsclientmsitrans\tscuinst.vbs + 2008-09-08 22:53 . 2007-12-12 10:33 18917 c:\windows\Installer\tsclientmsitrans\tscinst.vbs - 2005-11-25 09:16 . 2009-04-20 02:04 23040 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe + 2005-11-25 09:16 . 2009-07-06 01:02 23040 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe - 2005-11-25 09:16 . 2009-04-20 02:04 27136 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe + 2005-11-25 09:16 . 2009-07-06 01:02 27136 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe - 2005-11-25 09:16 . 2009-04-20 02:04 11264 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe + 2005-11-25 09:16 . 2009-07-06 01:02 11264 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe - 2005-11-25 09:16 . 2009-04-20 02:04 12288 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe + 2005-11-25 09:16 . 2009-07-06 01:02 12288 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe + 2007-03-22 18:05 . 2007-03-22 18:05 97632 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\PP7X32.DLL + 2005-09-09 22:03 . 2008-04-13 16:43 62976 c:\windows\ime\spgrmr.dll - 2005-09-09 22:03 . 2004-08-04 12:00 62976 c:\windows\ime\SPGRMR.dll + 2005-09-09 22:03 . 2008-04-14 00:12 10752 c:\windows\hh.exe - 2005-09-09 22:03 . 2005-05-26 23:22 10752 c:\windows\hh.exe + 2005-09-09 22:03 . 2008-04-14 00:12 33280 c:\windows\Help\sstub.dll - 2005-09-09 22:03 . 2004-08-04 12:00 33280 c:\windows\Help\sstub.dll + 2005-09-09 22:03 . 2008-04-14 00:12 34816 c:\windows\Help\sniffpol.dll - 2005-09-09 22:03 . 2004-08-04 12:00 34816 c:\windows\Help\sniffpol.dll + 2008-09-08 22:51 . 2008-04-14 00:11 39424 c:\windows\AppPatch\acadproc.dll + 2009-04-20 02:02 . 2008-10-16 10:20 39424 c:\windows\$NtUninstallKB963027_0$\pngfilt.dll + 2009-04-20 02:02 . 2008-10-16 10:20 16384 c:\windows\$NtUninstallKB963027_0$\jsproxy.dll + 2009-04-20 02:02 . 2008-10-16 10:20 96256 c:\windows\$NtUninstallKB963027_0$\inseng.dll + 2009-04-20 02:02 . 2004-08-04 12:00 81920 c:\windows\$NtUninstallKB963027_0$\ieencode.dll + 2009-04-20 02:02 . 2008-10-15 14:18 18432 c:\windows\$NtUninstallKB963027_0$\iedw.exe + 2009-04-20 02:02 . 2008-10-16 10:20 55808 c:\windows\$NtUninstallKB963027_0$\extmgr.dll - 2009-04-20 02:02 . 2004-08-04 12:00 81920 c:\windows\$NtUninstallKB963027$\ieencode.dll + 2009-04-20 02:10 . 2004-08-04 12:00 55808 c:\windows\$NtUninstallKB959426_0$\secur32.dll + 2008-12-10 00:32 . 2008-08-20 05:33 39424 c:\windows\$NtUninstallKB958215_0$\pngfilt.dll + 2008-12-10 00:32 . 2008-08-20 05:33 16384 c:\windows\$NtUninstallKB958215_0$\jsproxy.dll + 2008-12-10 00:32 . 2008-08-20 05:33 96256 c:\windows\$NtUninstallKB958215_0$\inseng.dll + 2008-12-10 00:32 . 2008-08-19 09:38 18432 c:\windows\$NtUninstallKB958215_0$\iedw.exe + 2008-12-10 00:32 . 2008-08-20 05:33 55808 c:\windows\$NtUninstallKB958215_0$\extmgr.dll + 2009-04-20 02:05 . 2004-08-04 12:00 31232 c:\windows\$NtUninstallKB956572_0$\sc.exe + 2008-10-18 01:11 . 2008-06-23 16:12 39424 c:\windows\$NtUninstallKB956390_0$\pngfilt.dll + 2008-10-18 01:11 . 2008-06-23 16:11 16384 c:\windows\$NtUninstallKB956390_0$\jsproxy.dll + 2008-10-18 01:11 . 2008-06-23 16:11 96256 c:\windows\$NtUninstallKB956390_0$\inseng.dll + 2008-10-18 01:11 . 2008-06-23 09:53 18432 c:\windows\$NtUninstallKB956390_0$\iedw.exe + 2008-10-18 01:11 . 2008-06-23 16:11 55808 c:\windows\$NtUninstallKB956390_0$\extmgr.dll + 2008-08-13 23:53 . 2008-04-21 06:56 39424 c:\windows\$NtUninstallKB953838_0$\pngfilt.dll + 2008-08-13 23:53 . 2008-04-21 06:56 16384 c:\windows\$NtUninstallKB953838_0$\jsproxy.dll + 2008-08-13 23:53 . 2008-04-21 06:56 96256 c:\windows\$NtUninstallKB953838_0$\inseng.dll + 2008-08-13 23:53 . 2008-04-17 10:46 18432 c:\windows\$NtUninstallKB953838_0$\iedw.exe + 2008-08-13 23:53 . 2008-04-21 06:56 55808 c:\windows\$NtUninstallKB953838_0$\extmgr.dll + 2008-08-13 23:54 . 2005-06-29 01:46 74240 c:\windows\$NtUninstallKB952954_0$\mscms.dll + 2009-04-20 02:05 . 2006-03-01 19:42 91136 c:\windows\$NtUninstallKB952004_0$\mtxoci.dll + 2009-04-20 02:05 . 2006-03-01 19:42 66560 c:\windows\$NtUninstallKB952004_0$\mtxclu.dll + 2009-04-20 02:05 . 2004-08-04 12:00 58880 c:\windows\$NtUninstallKB952004_0$\msdtclog.dll - 2009-04-20 02:05 . 2006-03-01 19:42 66560 c:\windows\$NtUninstallKB952004$\mtxclu.dll - 2009-04-20 02:05 . 2004-08-04 12:00 58880 c:\windows\$NtUninstallKB952004$\msdtclog.dll + 2008-06-13 01:10 . 2008-02-16 09:32 39424 c:\windows\$NtUninstallKB950759_0$\pngfilt.dll + 2008-06-13 01:10 . 2008-02-16 09:32 16384 c:\windows\$NtUninstallKB950759_0$\jsproxy.dll + 2008-06-13 01:10 . 2008-02-16 09:32 96256 c:\windows\$NtUninstallKB950759_0$\inseng.dll + 2008-06-13 01:10 . 2008-02-15 09:07 18432 c:\windows\$NtUninstallKB950759_0$\iedw.exe + 2008-06-13 01:10 . 2008-02-16 09:32 55808 c:\windows\$NtUninstallKB950759_0$\extmgr.dll + 2008-08-13 23:54 . 2004-08-04 01:06 82944 c:\windows\$NtUninstallKB946648_0$\msgsc.dll - 2008-08-13 23:54 . 2004-08-04 01:06 82944 c:\windows\$NtUninstallKB946648$\msgsc.dll + 2009-04-19 19:11 . 2008-05-03 11:55 2560 c:\windows\system32\xpsp4res.dll + 2005-11-25 08:59 . 2008-04-14 00:12 6656 c:\windows\system32\wuauserv.dll - 2005-11-25 08:59 . 2004-08-04 12:00 6656 c:\windows\system32\wuauserv.dll + 2005-09-09 22:03 . 2008-04-14 00:11 5632 c:\windows\system32\wmi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 5632 c:\windows\system32\wmi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 5632 c:\windows\system32\winver.exe + 2005-09-09 22:03 . 2008-04-14 00:12 5632 c:\windows\system32\winver.exe + 2005-11-25 08:58 . 2008-04-13 17:10 6656 c:\windows\system32\wbem\wmiapres.dll - 2005-11-25 08:58 . 2004-08-04 12:00 6656 c:\windows\system32\wbem\wmiapres.dll - 2005-09-09 22:03 . 2005-04-27 23:15 2560 c:\windows\system32\usmt\iconlib.dll + 2005-09-09 22:03 . 2008-04-13 16:44 2560 c:\windows\system32\usmt\iconlib.dll - 2005-11-25 09:03 . 2004-08-04 12:00 6656 c:\windows\system32\spool\drivers\w32x86\3\FXSRES.DLL + 2005-11-25 09:03 . 2008-04-14 00:09 6656 c:\windows\system32\spool\drivers\w32x86\3\fxsres.dll + 2007-09-22 16:25 . 2008-04-14 00:12 7680 c:\windows\system32\spdwnwxp.exe - 2005-09-09 22:03 . 2004-08-04 12:00 8192 c:\windows\system32\smbinst.exe + 2005-09-09 22:03 . 2008-04-14 00:12 8192 c:\windows\system32\smbinst.exe |
|
|
|
|
#14 (permalink) |
|
Registered User
Join Date: Jul 2009
Posts: 14
OS: xp
|
Re: Recurring Vundo Trojan
- 2005-09-09 22:03 . 2004-08-04 12:00 5120 c:\windows\system32\sfc.dll
+ 2005-09-09 22:03 . 2008-04-14 00:12 5120 c:\windows\system32\sfc.dll + 2008-09-08 22:52 . 2008-04-14 00:11 8192 c:\windows\system32\Setup\koc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 7168 c:\windows\system32\sensapi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 5632 c:\windows\system32\security.dll - 2005-09-09 22:03 . 2004-08-04 12:00 5632 c:\windows\system32\security.dll - 2005-09-09 22:03 . 2004-08-04 12:00 9216 c:\windows\system32\scrnsave.scr + 2005-09-09 22:03 . 2008-04-14 00:12 9216 c:\windows\system32\scrnsave.scr + 2005-09-09 22:03 . 2008-04-14 00:12 7680 c:\windows\system32\rasadhlp.dll - 2005-09-09 22:03 . 2004-08-04 12:00 9216 c:\windows\system32\proxycfg.exe + 2005-09-09 22:03 . 2008-04-14 00:12 9216 c:\windows\system32\proxycfg.exe - 2005-09-09 22:03 . 2004-08-04 12:00 8192 c:\windows\system32\ntlsapi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 8192 c:\windows\system32\ntlsapi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 4096 c:\windows\system32\nddeapir.exe - 2005-09-09 22:03 . 2004-08-04 12:00 4096 c:\windows\system32\nddeapir.exe + 2005-11-25 08:58 . 2008-04-14 00:12 4096 c:\windows\system32\mtxex.dll - 2005-11-25 08:58 . 2004-08-04 12:00 4096 c:\windows\system32\mtxex.dll + 2005-09-09 22:03 . 2008-04-14 00:11 4608 c:\windows\system32\msimg32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 4608 c:\windows\system32\msimg32.dll + 2005-09-09 22:03 . 2008-04-14 00:11 6656 c:\windows\system32\msidle.dll - 2005-09-09 22:03 . 2004-08-04 12:00 6656 c:\windows\system32\msidle.dll + 2005-09-09 22:03 . 2008-04-14 00:10 4126 c:\windows\system32\msdxmlc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 4126 c:\windows\system32\msdxmlc.dll - 2005-11-25 08:58 . 2004-08-04 12:00 6144 c:\windows\system32\msdtc.exe + 2005-11-25 08:58 . 2008-04-14 00:12 6144 c:\windows\system32\msdtc.exe + 2005-09-09 22:03 . 2008-04-14 00:10 3584 c:\windows\system32\msafd.dll - 2005-09-09 22:03 . 2004-08-04 12:00 3584 c:\windows\system32\msafd.dll + 2006-01-06 17:24 . 2008-04-14 00:11 4096 c:\windows\system32\ksuser.dll - 2006-01-06 17:24 . 2004-08-04 00:56 4096 c:\windows\system32\ksuser.dll + 2005-09-09 22:03 . 2008-04-13 18:31 7424 c:\windows\system32\kd1394.dll - 2005-09-09 22:03 . 2004-08-04 12:00 7424 c:\windows\system32\kd1394.dll - 2005-09-09 22:03 . 2004-08-04 12:00 7168 c:\windows\system32\kbdukx.dll + 2005-09-09 22:03 . 2008-04-14 00:09 7168 c:\windows\system32\kbdukx.dll - 2005-09-09 22:03 . 2004-08-04 12:00 7680 c:\windows\system32\kbdsmsno.dll + 2005-09-09 22:03 . 2008-04-14 00:09 7680 c:\windows\system32\kbdsmsno.dll + 2005-09-09 22:03 . 2008-04-14 00:09 7680 c:\windows\system32\kbdsmsfi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 7680 c:\windows\system32\kbdsmsfi.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\system32\kbdpash.dll + 2005-09-09 22:03 . 2008-04-14 00:09 7168 c:\windows\system32\kbdno1.dll - 2005-09-09 22:03 . 2004-08-04 12:00 7168 c:\windows\system32\kbdno1.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\system32\kbdnepr.dll - 2005-09-09 22:03 . 2004-08-04 12:00 7168 c:\windows\system32\kbdnec.dll + 2005-09-09 22:03 . 2008-04-14 00:09 7168 c:\windows\system32\kbdnec.dll - 2005-09-09 22:03 . 2004-08-04 12:00 6144 c:\windows\system32\kbdmlt48.dll + 2005-09-09 22:03 . 2008-04-14 00:09 6144 c:\windows\system32\kbdmlt48.dll + 2005-09-09 22:03 . 2008-04-14 00:09 6144 c:\windows\system32\kbdmlt47.dll - 2005-09-09 22:03 . 2004-08-04 12:00 6144 c:\windows\system32\kbdmlt47.dll - 2005-09-09 22:03 . 2004-08-04 12:00 5632 c:\windows\system32\kbdmaori.dll + 2005-09-09 22:03 . 2008-04-14 00:09 5632 c:\windows\system32\kbdmaori.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\system32\kbdiultn.dll + 2005-09-09 22:03 . 2008-04-14 00:09 6656 c:\windows\system32\kbdinmal.dll - 2005-09-09 22:03 . 2004-08-04 12:00 6656 c:\windows\system32\kbdinmal.dll + 2005-09-09 22:03 . 2008-04-14 00:09 6144 c:\windows\system32\kbdinben.dll - 2005-09-09 22:03 . 2004-08-04 12:00 6144 c:\windows\system32\kbdinbe1.dll + 2005-09-09 22:03 . 2008-04-14 00:09 6144 c:\windows\system32\kbdinbe1.dll - 2005-09-09 22:03 . 2004-08-04 12:00 7168 c:\windows\system32\kbdfi1.dll + 2005-09-09 22:03 . 2008-04-14 00:09 7168 c:\windows\system32\kbdfi1.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\system32\kbdbhc.dll + 2006-02-24 16:17 . 2008-04-14 00:09 6144 c:\windows\system32\kbd106.dll - 2006-02-24 16:17 . 2001-08-17 14:55 6144 c:\windows\system32\kbd106.dll + 2005-09-09 22:03 . 2008-04-14 00:11 8192 c:\windows\system32\igmpagnt.dll - 2005-09-09 22:03 . 2004-08-04 12:00 8192 c:\windows\system32\igmpagnt.dll - 2005-09-09 22:03 . 2004-08-04 12:00 3584 c:\windows\system32\icmp.dll + 2005-09-09 22:03 . 2008-04-14 00:09 3584 c:\windows\system32\icmp.dll - 2006-01-06 17:18 . 2004-08-04 00:56 7168 c:\windows\system32\hccoin.dll + 2006-01-06 17:18 . 2008-04-14 00:11 7168 c:\windows\system32\hccoin.dll - 2005-09-09 22:03 . 2004-08-04 12:00 9728 c:\windows\system32\gpkrsrc.dll + 2005-09-09 22:03 . 2006-12-31 01:26 9728 c:\windows\system32\gpkrsrc.dll - 2005-11-25 09:03 . 2004-08-04 12:00 6656 c:\windows\system32\fxsres.dll + 2005-11-25 09:03 . 2008-04-14 00:09 6656 c:\windows\system32\fxsres.dll - 2005-11-25 09:03 . 2004-08-04 12:00 8704 c:\windows\system32\fxsperf.dll + 2005-11-25 09:03 . 2008-04-14 00:11 8704 c:\windows\system32\fxsperf.dll - 2005-09-09 22:03 . 2004-08-04 12:00 9344 c:\windows\system32\framebuf.dll + 2005-09-09 22:03 . 2008-04-14 00:09 9344 c:\windows\system32\framebuf.dll + 2005-09-09 22:03 . 2008-04-14 00:12 7680 c:\windows\system32\forcedos.exe + 2008-09-08 22:52 . 2008-04-14 00:11 6656 c:\windows\system32\en\mmcfxcommon.resources.dll - 2005-09-09 22:03 . 2004-08-04 12:00 4096 c:\windows\system32\dsprpres.dll + 2005-09-09 22:03 . 2008-04-13 17:09 4096 c:\windows\system32\dsprpres.dll + 2005-11-25 10:00 . 2008-04-13 18:40 5376 c:\windows\system32\drivers\viaide.sys - 2005-11-25 10:00 . 2004-08-03 22:59 5376 c:\windows\system32\drivers\viaide.sys - 2004-08-03 22:58 . 2004-08-03 22:58 4352 c:\windows\system32\drivers\swenum.sys + 2004-08-03 22:58 . 2008-04-13 18:39 4352 c:\windows\system32\drivers\swenum.sys + 2006-01-06 17:24 . 2008-04-13 18:45 6272 c:\windows\system32\drivers\splitter.sys + 2007-09-22 16:26 . 2008-04-13 18:36 5888 c:\windows\system32\drivers\smbali.sys - 2007-09-22 16:26 . 2004-08-03 23:56 3901 c:\windows\system32\drivers\siint5.dll + 2007-09-22 16:26 . 2008-04-14 00:12 3901 c:\windows\system32\drivers\siint5.dll + 2007-01-01 19:25 . 2008-04-13 18:39 5504 c:\windows\system32\drivers\mstee.sys - 2007-01-01 19:25 . 2004-08-03 22:58 5504 c:\windows\system32\drivers\MSTEE.sys + 2006-01-06 17:24 . 2008-04-13 18:39 4992 c:\windows\system32\drivers\mspqm.sys - 2006-01-06 17:24 . 2004-08-03 22:58 4992 c:\windows\system32\drivers\MSPQM.sys - 2006-01-06 17:24 . 2004-08-03 22:58 5376 c:\windows\system32\drivers\MSPCLOCK.sys + 2006-01-06 17:24 . 2008-04-13 18:39 5376 c:\windows\system32\drivers\mspclock.sys - 2006-01-06 17:24 . 2004-08-03 22:58 7552 c:\windows\system32\drivers\MSKSSRV.sys + 2006-01-06 17:24 . 2008-04-13 18:39 7552 c:\windows\system32\drivers\mskssrv.sys - 2005-11-25 09:59 . 2004-08-03 22:59 5504 c:\windows\system32\drivers\intelide.sys + 2005-11-25 09:59 . 2008-04-13 18:40 5504 c:\windows\system32\drivers\intelide.sys + 2005-11-25 09:55 . 2008-04-13 18:41 8576 c:\windows\system32\drivers\i2omgmt.sys - 2006-01-06 17:24 . 2004-08-03 23:07 2944 c:\windows\system32\drivers\drmkaud.sys + 2006-01-06 17:24 . 2008-04-13 18:45 2944 c:\windows\system32\drivers\drmkaud.sys - 2007-09-22 16:26 . 2004-08-03 23:56 3775 c:\windows\system32\drivers\adv11nt5.dll + 2007-09-22 16:26 . 2008-04-14 00:11 3775 c:\windows\system32\drivers\adv11nt5.dll + 2007-09-22 16:26 . 2008-04-14 00:11 3711 c:\windows\system32\drivers\adv09nt5.dll - 2007-09-22 16:26 . 2004-08-03 23:56 3711 c:\windows\system32\drivers\adv09nt5.dll - 2007-09-22 16:26 . 2004-08-03 23:56 3135 c:\windows\system32\drivers\adv08nt5.dll + 2007-09-22 16:26 . 2008-04-14 00:11 3135 c:\windows\system32\drivers\adv08nt5.dll - 2007-09-22 16:26 . 2004-08-03 23:56 3647 c:\windows\system32\drivers\adv07nt5.dll + 2007-09-22 16:26 . 2008-04-14 00:11 3647 c:\windows\system32\drivers\adv07nt5.dll - 2007-09-22 16:26 . 2004-08-03 23:56 3615 c:\windows\system32\drivers\adv05nt5.dll + 2007-09-22 16:26 . 2008-04-14 00:11 3615 c:\windows\system32\drivers\adv05nt5.dll + 2007-09-22 16:26 . 2008-04-14 00:11 3967 c:\windows\system32\drivers\adv02nt5.dll - 2007-09-22 16:26 . 2004-08-03 23:56 3967 c:\windows\system32\drivers\adv02nt5.dll - 2007-09-22 16:26 . 2004-08-03 23:56 4255 c:\windows\system32\drivers\adv01nt5.dll + 2007-09-22 16:26 . 2008-04-14 00:11 4255 c:\windows\system32\drivers\adv01nt5.dll + 2005-09-09 22:03 . 2008-04-14 00:09 3072 c:\windows\system32\dpnlobby.dll + 2005-09-09 22:03 . 2008-04-14 00:09 3072 c:\windows\system32\dpnaddr.dll + 2008-09-08 22:52 . 2008-04-14 00:11 9216 c:\windows\system32\dot3dlg.dll + 2005-09-09 22:03 . 2008-04-14 00:12 5120 c:\windows\system32\dllhost.exe - 2005-09-09 22:03 . 2004-08-04 12:00 5120 c:\windows\system32\dllhost.exe - 2005-09-09 22:03 . 2004-08-04 12:00 4126 c:\windows\system32\dllcache\msdxmlc.dll + 2005-09-09 22:03 . 2008-04-14 00:10 4126 c:\windows\system32\dllcache\msdxmlc.dll - 2005-11-25 08:59 . 2004-08-04 12:00 4639 c:\windows\system32\dllcache\mplayer2.exe + 2005-11-25 08:59 . 2008-04-14 00:12 4639 c:\windows\system32\dllcache\mplayer2.exe + 2005-11-25 08:58 . 2008-04-14 00:12 6144 c:\windows\system32\dcomcnfg.exe + 2005-09-09 22:03 . 2008-04-14 00:11 8704 c:\windows\system32\dciman32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 8704 c:\windows\system32\dciman32.dll + 2005-09-09 22:03 . 2008-04-14 00:25 1804 c:\windows\system32\dcache.bin + 2005-09-09 22:03 . 2008-04-14 00:11 8192 c:\windows\system32\d3d8thk.dll - 2005-09-09 22:03 . 2004-08-04 12:00 8192 c:\windows\system32\d3d8thk.dll + 2005-09-09 22:03 . 2008-04-14 00:12 6144 c:\windows\system32\csrss.exe - 2005-09-09 22:03 . 2004-08-04 12:00 6144 c:\windows\system32\csrss.exe + 2005-11-25 08:58 . 2008-04-14 00:12 6144 c:\windows\system32\Com\comrereg.exe + 2005-11-25 08:58 . 2008-04-14 00:12 9728 c:\windows\system32\Com\comrepl.exe - 2005-11-25 08:58 . 2004-08-04 12:00 9728 c:\windows\system32\Com\comrepl.exe - 2005-09-09 22:03 . 2004-08-04 12:00 5632 c:\windows\system32\cisvc.exe + 2005-09-09 22:03 . 2008-04-14 00:12 5632 c:\windows\system32\cisvc.exe + 2008-09-08 22:51 . 2008-04-14 00:11 7168 c:\windows\system32\bitsprx4.dll - 2005-11-25 08:59 . 2004-08-04 12:00 7168 c:\windows\system32\bitsprx3.dll + 2005-11-25 08:59 . 2008-04-14 00:11 7168 c:\windows\system32\bitsprx3.dll - 2005-11-25 08:59 . 2004-08-04 12:00 8192 c:\windows\system32\bitsprx2.dll + 2005-11-25 08:59 . 2008-04-14 00:11 8192 c:\windows\system32\bitsprx2.dll - 2005-11-25 08:54 . 2004-08-04 12:00 8704 c:\windows\system32\batt.dll + 2005-11-25 08:54 . 2008-04-14 00:11 8704 c:\windows\system32\batt.dll + 2005-09-09 22:03 . 2008-04-14 00:12 4096 c:\windows\system32\actmovie.exe - 2005-09-09 22:03 . 2004-08-04 12:00 4096 c:\windows\system32\actmovie.exe + 2008-09-08 22:54 . 2008-04-14 00:12 6656 c:\windows\ServicePackFiles\i386\wuauserv.dll + 2008-09-08 22:54 . 2008-04-14 00:12 8192 c:\windows\ServicePackFiles\i386\wshirda.dll + 2008-09-08 22:54 . 2008-04-14 00:12 5632 c:\windows\ServicePackFiles\i386\wmm2res2.dll + 2008-09-08 22:54 . 2008-04-14 00:12 7680 c:\windows\ServicePackFiles\i386\wmm2ext.dll + 2008-09-08 22:54 . 2008-04-14 00:12 4096 c:\windows\ServicePackFiles\i386\wmm2eres.dll + 2008-09-08 22:54 . 2008-04-13 17:10 6656 c:\windows\ServicePackFiles\i386\wmiapres.dll + 2008-09-08 22:54 . 2008-04-13 18:36 8832 c:\windows\ServicePackFiles\i386\wmiacpi.sys + 2008-09-08 22:54 . 2008-04-14 00:11 5632 c:\windows\ServicePackFiles\i386\wmi.dll + 2008-09-08 22:54 . 2008-04-14 00:12 5632 c:\windows\ServicePackFiles\i386\winver.exe + 2008-09-08 22:54 . 2004-08-04 12:00 5120 c:\windows\ServicePackFiles\i386\winnls.dll + 2008-09-08 22:53 . 2008-04-13 18:40 5376 c:\windows\ServicePackFiles\i386\viaide.sys + 2008-09-08 22:53 . 2008-04-14 00:12 8704 c:\windows\ServicePackFiles\i386\tty.dll + 2008-09-08 22:53 . 2008-01-18 15:13 2247 c:\windows\ServicePackFiles\i386\tscdsbl.bat + 2008-09-08 22:53 . 2008-04-13 18:39 4352 c:\windows\ServicePackFiles\i386\swenum.sys + 2008-09-08 22:53 . 2008-04-13 18:45 6272 c:\windows\ServicePackFiles\i386\splitter.sys + 2008-09-08 22:53 . 2008-04-14 00:12 7680 c:\windows\ServicePackFiles\i386\spdwnwxp.exe + 2008-09-08 22:53 . 2008-04-13 18:40 7552 c:\windows\ServicePackFiles\i386\sonyait.sys + 2008-09-08 22:53 . 2008-04-14 00:12 8704 c:\windows\ServicePackFiles\i386\snmptrap.exe + 2008-09-08 22:53 . 2008-04-14 00:12 6144 c:\windows\ServicePackFiles\i386\snmpmib.dll + 2008-09-08 22:53 . 2008-04-14 00:12 8192 c:\windows\ServicePackFiles\i386\smbinst.exe + 2008-09-08 22:53 . 2008-04-13 18:36 6912 c:\windows\ServicePackFiles\i386\smbclass.sys + 2008-09-08 22:53 . 2008-04-13 18:36 5888 c:\windows\ServicePackFiles\i386\smbali.sys + 2008-09-08 22:53 . 2008-04-14 00:12 3901 c:\windows\ServicePackFiles\i386\siint5.dll + 2008-09-08 22:53 . 2008-04-14 00:12 5120 c:\windows\ServicePackFiles\i386\sfc.dll + 2008-09-08 22:53 . 2008-04-14 00:12 7168 c:\windows\ServicePackFiles\i386\sensapi.dll + 2008-09-08 22:53 . 2008-04-14 00:12 5632 c:\windows\ServicePackFiles\i386\security.dll + 2008-09-08 22:53 . 2006-12-31 06:57 4569 c:\windows\ServicePackFiles\i386\secupd.dat + 2008-09-08 22:53 . 2008-04-14 00:12 9216 c:\windows\ServicePackFiles\i386\scrnsave.scr + 2008-09-08 22:53 . 2004-08-04 12:00 3338 c:\windows\ServicePackFiles\i386\redir.exe + 2008-09-08 22:53 . 2008-04-14 00:12 7680 c:\windows\ServicePackFiles\i386\rasadhlp.dll + 2008-09-08 22:53 . 2008-04-13 18:40 6016 c:\windows\ServicePackFiles\i386\qic157.sys + 2008-09-08 22:53 . 2008-04-14 00:12 9216 c:\windows\ServicePackFiles\i386\proxycfg.exe + 2008-09-08 22:53 . 2008-04-13 18:40 8832 c:\windows\ServicePackFiles\i386\powerfil.sys + 2008-09-08 22:53 . 2008-04-14 00:12 8192 c:\windows\ServicePackFiles\i386\ntlsapi.dll + 2008-09-08 22:53 . 2008-04-14 00:12 4096 c:\windows\ServicePackFiles\i386\nddeapir.exe + 2008-09-08 22:53 . 2008-04-14 00:12 9728 c:\windows\ServicePackFiles\i386\ncpsres.dll + 2008-09-08 22:53 . 2008-04-14 00:12 4096 c:\windows\ServicePackFiles\i386\mtxex.dll + 2008-09-08 22:53 . 2008-04-13 18:39 5504 c:\windows\ServicePackFiles\i386\mstee.sys + 2008-09-08 22:53 . 2008-04-13 18:39 4992 c:\windows\ServicePackFiles\i386\mspqm.sys + 2008-09-08 22:53 . 2008-04-13 18:39 5376 c:\windows\ServicePackFiles\i386\mspclock.sys + 2008-09-08 22:53 . 2008-04-13 18:39 7552 c:\windows\ServicePackFiles\i386\mskssrv.sys + 2008-09-08 22:53 . 2008-04-14 00:11 4608 c:\windows\ServicePackFiles\i386\msimg32.dll + 2008-09-08 22:53 . 2008-04-14 00:11 6656 c:\windows\ServicePackFiles\i386\msidle.dll + 2008-09-08 22:52 . 2008-04-14 00:12 6144 c:\windows\ServicePackFiles\i386\msdtc.exe + 2008-09-08 22:52 . 2008-04-14 00:11 4096 c:\windows\ServicePackFiles\i386\msdaurl.dll + 2008-09-08 22:52 . 2008-04-14 00:11 4096 c:\windows\ServicePackFiles\i386\msdasc.dll + 2008-09-08 22:52 . 2008-04-14 00:11 4096 c:\windows\ServicePackFiles\i386\msdaer.dll + 2008-09-08 22:52 . 2008-04-14 00:11 4096 c:\windows\ServicePackFiles\i386\msdaenum.dll + 2008-09-08 22:52 . 2008-04-14 00:11 4096 c:\windows\ServicePackFiles\i386\msdadc.dll + 2008-09-08 22:52 . 2008-04-14 00:10 3584 c:\windows\ServicePackFiles\i386\msafd.dll + 2008-09-08 22:52 . 2008-04-14 00:11 6656 c:\windows\ServicePackFiles\i386\mmcfxcr.dll + 2008-09-08 22:52 . 2008-04-14 00:12 7680 c:\windows\ServicePackFiles\i386\migregdb.exe + 2008-09-08 22:52 . 2008-04-13 18:40 7040 c:\windows\ServicePackFiles\i386\ltotape.sys + 2008-09-08 22:52 . 2008-04-14 00:11 4096 c:\windows\ServicePackFiles\i386\ksuser.dll + 2008-09-08 22:52 . 2008-04-14 00:11 8192 c:\windows\ServicePackFiles\i386\koc.dll + 2008-09-08 22:52 . 2008-04-13 18:31 7424 c:\windows\ServicePackFiles\i386\kd1394.dll + 2008-09-08 22:52 . 2008-04-14 00:09 7168 c:\windows\ServicePackFiles\i386\kbdukx.dll + 2008-09-08 22:52 . 2008-04-14 00:09 7680 c:\windows\ServicePackFiles\i386\kbdsmsno.dll + 2008-09-08 22:52 . 2008-04-14 00:09 7680 c:\windows\ServicePackFiles\i386\kbdsmsfi.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\ServicePackFiles\i386\kbdpash.dll + 2008-09-08 22:52 . 2008-04-14 00:09 7168 c:\windows\ServicePackFiles\i386\kbdno1.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\ServicePackFiles\i386\kbdnepr.dll + 2008-09-08 22:52 . 2008-04-14 00:09 7168 c:\windows\ServicePackFiles\i386\kbdnec.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\ServicePackFiles\i386\kbdmlt48.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\ServicePackFiles\i386\kbdmlt47.dll + 2008-09-08 22:52 . 2008-04-14 00:09 5632 c:\windows\ServicePackFiles\i386\kbdmaori.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\ServicePackFiles\i386\kbdlk41j.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6656 c:\windows\ServicePackFiles\i386\kbdlk41a.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\ServicePackFiles\i386\kbdiultn.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6656 c:\windows\ServicePackFiles\i386\kbdinmal.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\ServicePackFiles\i386\kbdinben.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\ServicePackFiles\i386\kbdinbe1.dll + 2008-09-08 22:52 . 2008-04-14 00:09 7168 c:\windows\ServicePackFiles\i386\kbdibm02.dll + 2008-09-08 22:52 . 2008-04-14 00:09 7168 c:\windows\ServicePackFiles\i386\kbdfi1.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\ServicePackFiles\i386\kbdbhc.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\ServicePackFiles\i386\kbdax2.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\ServicePackFiles\i386\kbd106n.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\ServicePackFiles\i386\kbd106.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6144 c:\windows\ServicePackFiles\i386\kbd101.dll + 2008-09-08 22:52 . 2008-04-13 18:40 5504 c:\windows\ServicePackFiles\i386\intelide.sys + 2008-09-08 22:52 . 2008-04-14 00:11 8192 c:\windows\ServicePackFiles\i386\igmpagnt.dll + 2008-09-08 22:52 . 2008-04-13 16:44 2560 c:\windows\ServicePackFiles\i386\iconlib.dll + 2008-09-08 22:52 . 2008-04-14 00:09 3584 c:\windows\ServicePackFiles\i386\icmp.dll + 2008-09-08 22:52 . 2008-04-13 18:41 8576 c:\windows\ServicePackFiles\i386\i2omgmt.sys + 2008-09-08 22:52 . 2008-04-14 00:11 7168 c:\windows\ServicePackFiles\i386\hccoin.dll + 2008-09-08 22:52 . 2006-12-31 01:26 9728 c:\windows\ServicePackFiles\i386\gpkrsrc.dll + 2008-09-08 22:52 . 2008-04-14 00:09 6656 c:\windows\ServicePackFiles\i386\fxsres.dll + 2008-09-08 22:52 . 2008-04-14 00:11 8704 c:\windows\ServicePackFiles\i386\fxsperf.dll + 2008-09-08 22:52 . 2008-04-14 00:09 9344 c:\windows\ServicePackFiles\i386\framebuf.dll + 2008-09-08 22:52 . 2008-04-14 00:12 7680 c:\windows\ServicePackFiles\i386\forcedos.exe + 2008-09-08 22:52 . 2008-04-14 00:09 7168 c:\windows\ServicePackFiles\i386\f3ahvoas.dll + 2008-09-08 22:52 . 2008-04-13 17:09 4096 c:\windows\ServicePackFiles\i386\dsprpres.dll + 2008-09-08 22:52 . 2004-08-04 12:00 4656 c:\windows\ServicePackFiles\i386\ds16gt.dll + 2008-09-08 22:52 . 2008-04-13 18:45 2944 c:\windows\ServicePackFiles\i386\drmkaud.sys + 2008-09-08 22:52 . 2008-04-14 00:09 3072 c:\windows\ServicePackFiles\i386\dpnlobby.dll + 2008-09-08 22:52 . 2008-04-14 00:09 3072 c:\windows\ServicePackFiles\i386\dpnaddr.dll + 2008-09-08 22:52 . 2008-04-14 00:11 9216 c:\windows\ServicePackFiles\i386\dot3dlg.dll + 2008-09-08 22:52 . 2008-04-13 18:40 8320 c:\windows\ServicePackFiles\i386\dlttape.sys + 2008-09-08 22:52 . 2008-04-14 00:12 5120 c:\windows\ServicePackFiles\i386\dllhost.exe + 2008-09-08 22:52 . 2008-04-14 00:12 6144 c:\windows\ServicePackFiles\i386\dcomcnfg.exe + 2008-09-08 22:52 . 2008-04-14 00:11 8704 c:\windows\ServicePackFiles\i386\dciman32.dll + 2008-09-08 22:52 . 2008-04-14 00:25 1804 c:\windows\ServicePackFiles\i386\dcache.bin + 2008-09-08 22:52 . 2008-04-14 00:11 8192 c:\windows\ServicePackFiles\i386\d3d8thk.dll + 2008-09-08 22:52 . 2008-04-14 00:12 6144 c:\windows\ServicePackFiles\i386\csrss.exe + 2008-09-08 22:52 . 2008-04-14 00:12 6144 c:\windows\ServicePackFiles\i386\comrereg.exe + 2008-09-08 22:52 . 2008-04-14 00:12 9728 c:\windows\ServicePackFiles\i386\comrepl.exe + 2008-09-08 22:52 . 2008-04-14 00:12 5632 c:\windows\ServicePackFiles\i386\cisvc.exe + 2008-09-08 22:52 . 2008-04-13 18:40 8192 c:\windows\ServicePackFiles\i386\changer.sys + 2008-09-08 22:51 . 2008-04-14 00:11 7168 c:\windows\ServicePackFiles\i386\bitsprx4.dll + 2008-09-08 22:51 . 2008-04-14 00:11 7168 c:\windows\ServicePackFiles\i386\bitsprx3.dll + 2008-09-08 22:51 . 2008-04-14 00:11 8192 c:\windows\ServicePackFiles\i386\bitsprx2.dll + 2008-09-08 22:51 . 2008-04-14 00:11 8704 c:\windows\ServicePackFiles\i386\batt.dll + 2008-09-08 22:51 . 2008-04-14 00:11 3775 c:\windows\ServicePackFiles\i386\adv11nt5.dll + 2008-09-08 22:51 . 2008-04-14 00:11 3711 c:\windows\ServicePackFiles\i386\adv09nt5.dll + 2008-09-08 22:51 . 2008-04-14 00:11 3135 c:\windows\ServicePackFiles\i386\adv08nt5.dll + 2008-09-08 22:51 . 2008-04-14 00:11 3647 c:\windows\ServicePackFiles\i386\adv07nt5.dll + 2008-09-08 22:51 . 2008-04-14 00:11 3615 c:\windows\ServicePackFiles\i386\adv05nt5.dll + 2008-09-08 22:51 . 2008-04-14 00:11 3967 c:\windows\ServicePackFiles\i386\adv02nt5.dll + 2008-09-08 22:51 . 2008-04-14 00:11 4255 c:\windows\ServicePackFiles\i386\adv01nt5.dll + 2008-09-08 22:51 . 2008-04-14 00:12 4096 c:\windows\ServicePackFiles\i386\actmovie.exe + 2005-11-25 09:00 . 2009-07-06 01:33 3042 c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin + 2008-09-08 22:53 . 2008-01-18 15:13 2247 c:\windows\Installer\tsclientmsitrans\tscdsbl.bat + 2005-11-25 09:16 . 2009-07-06 01:02 4096 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe - 2005-11-25 09:16 . 2009-04-20 02:04 4096 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe + 2008-09-08 22:51 . 2008-04-13 18:26 132096 c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0\rtcres.dll - 2005-11-25 08:54 . 2004-08-03 23:55 132096 c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0\rtcres.dll + 2008-09-08 22:51 . 2008-04-14 00:12 991232 c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll - 2005-11-25 08:54 . 2004-08-03 23:57 991232 c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll - 2005-11-25 08:54 . 2004-08-03 23:57 853504 c:\windows\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll + 2008-09-08 22:51 . 2008-04-14 00:12 853504 c:\windows\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll + 2008-09-08 22:51 . 2008-04-14 00:12 343040 c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcrt.dll + 2008-09-08 22:51 . 2008-04-14 00:12 401462 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll - 2007-02-18 19:15 . 2007-01-19 20:15 401462 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll - 2007-02-18 19:15 . 2007-01-19 20:15 995383 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll + 2008-09-08 22:51 . 2008-04-14 00:12 995383 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll - 2005-09-09 22:03 . 2004-08-04 12:00 283648 c:\windows\winhlp32.exe + 2005-09-09 22:03 . 2008-04-14 00:12 283648 c:\windows\winhlp32.exe + 2005-09-09 22:03 . 2008-04-14 00:12 338432 c:\windows\system32\zipfldr.dll + 2005-11-25 16:41 . 2008-04-13 17:39 689152 c:\windows\system32\xpsp3res.dll + 2005-09-09 22:03 . 2008-04-13 17:39 187392 c:\windows\system32\xpsp1res.dll - 2005-09-09 22:03 . 2004-08-04 12:00 187392 c:\windows\system32\xpsp1res.dll - 2005-09-09 22:03 . 2004-08-04 12:00 438784 c:\windows\system32\xpob2res.dll + 2005-09-09 22:03 . 2008-04-13 17:39 438784 c:\windows\system32\xpob2res.dll + 2005-09-09 22:03 . 2008-04-14 00:12 129024 c:\windows\system32\xmlprov.dll + 2008-09-08 22:54 . 2008-04-14 00:12 121856 c:\windows\system32\xmllite.dll + 2004-08-04 00:56 . 2008-04-14 00:12 483840 c:\windows\system32\wzcsvc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 383488 c:\windows\system32\wzcdlg.dll + 2004-08-04 00:56 . 2008-04-14 00:12 108032 c:\windows\system32\wshbth.dll - 2004-08-04 00:56 . 2004-08-04 12:00 108032 c:\windows\system32\wshbth.dll + 2005-09-09 22:03 . 2008-04-14 00:12 155648 c:\windows\system32\wscript.exe + 2005-09-09 22:03 . 2008-04-14 00:12 264192 c:\windows\system32\wow32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 264192 c:\windows\system32\wow32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 303616 c:\windows\system32\wmstream.dll - 2005-09-09 22:03 . 2004-08-04 12:00 303616 c:\windows\system32\wmstream.dll + 2005-09-09 22:03 . 2008-04-14 00:12 115200 c:\windows\system32\wmsdmoe.dll - 2005-09-09 22:03 . 2004-08-04 12:00 115200 c:\windows\system32\wmsdmoe.dll - 2006-10-24 11:30 . 2006-10-24 11:30 276992 c:\windows\system32\WMPhoto.dll + 2006-10-24 11:30 . 2008-04-14 00:12 276992 c:\windows\system32\wmphoto.dll + 2005-09-09 22:03 . 2008-04-14 00:12 172032 c:\windows\system32\wldap32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 172032 c:\windows\system32\wldap32.dll - 2005-09-09 22:03 . 2006-08-17 12:28 132096 c:\windows\system32\wkssvc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 132096 c:\windows\system32\wkssvc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 176640 c:\windows\system32\wintrust.dll - 2005-09-09 22:03 . 2004-08-04 12:00 176640 c:\windows\system32\wintrust.dll + 2005-09-09 22:03 . 2008-04-14 00:12 293376 c:\windows\system32\winsrv.dll + 2005-09-09 22:03 . 2008-04-14 00:12 146432 c:\windows\system32\winspool.drv - 2005-09-09 22:03 . 2004-08-04 12:00 146432 c:\windows\system32\winspool.drv + 2005-09-09 22:03 . 2008-04-14 00:11 756224 c:\windows\system32\winntbbu.dll + 2005-09-09 22:03 . 2008-04-14 00:12 176128 c:\windows\system32\winmm.dll - 2005-09-09 22:03 . 2004-08-04 12:00 176128 c:\windows\system32\winmm.dll + 2005-09-09 22:03 . 2008-04-14 00:12 507904 c:\windows\system32\winlogon.exe + 2005-09-09 22:03 . 2008-12-16 12:30 354304 c:\windows\system32\winhttp.dll + 2005-09-09 22:03 . 2008-04-14 00:12 102400 c:\windows\system32\win32spl.dll + 2005-09-09 22:03 . 2008-04-14 00:12 111104 c:\windows\system32\wiavideo.dll - 2005-09-09 22:03 . 2004-08-04 12:00 111104 c:\windows\system32\wiavideo.dll - 2005-09-09 22:03 . 2004-08-04 12:00 589312 c:\windows\system32\wiashext.dll + 2005-09-09 22:03 . 2008-04-14 00:12 589312 c:\windows\system32\wiashext.dll - 2005-09-09 22:03 . 2006-12-19 18:16 333824 c:\windows\system32\wiaservc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 333824 c:\windows\system32\wiaservc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 124416 c:\windows\system32\wiadss.dll + 2005-09-09 22:03 . 2008-04-14 00:12 124416 c:\windows\system32\wiadss.dll - 2005-09-09 22:03 . 2004-08-04 12:00 463360 c:\windows\system32\wiadefui.dll + 2005-09-09 22:03 . 2008-04-14 00:12 463360 c:\windows\system32\wiadefui.dll - 2005-09-09 22:03 . 2004-08-04 12:00 433664 c:\windows\system32\wiaacmgr.exe + 2005-09-09 22:03 . 2008-04-14 00:12 433664 c:\windows\system32\wiaacmgr.exe - 2005-09-09 22:03 . 2004-08-04 12:00 135680 c:\windows\system32\webvw.dll + 2005-09-09 22:03 . 2008-04-14 00:12 135680 c:\windows\system32\webvw.dll - 2005-09-09 22:03 . 2004-08-04 12:00 276480 c:\windows\system32\webcheck.dll + 2005-09-09 22:03 . 2008-04-14 00:12 276480 c:\windows\system32\webcheck.dll + 2005-11-25 08:58 . 2008-04-14 00:12 144896 c:\windows\system32\wbem\wmisvc.dll - 2005-11-25 08:58 . 2004-08-04 12:00 144896 c:\windows\system32\wbem\wmisvc.dll - 2005-11-25 08:58 . 2009-02-06 16:39 227840 c:\windows\system32\wbem\wmiprvse.exe + 2005-11-25 08:58 . 2009-02-06 10:10 227840 c:\windows\system32\wbem\wmiprvse.exe + 2005-11-25 08:58 . 2009-02-09 12:10 453120 c:\windows\system32\wbem\wmiprvsd.dll - 2005-11-25 08:58 . 2009-02-09 10:20 453120 c:\windows\system32\wbem\wmiprvsd.dll + 2005-11-25 08:58 . 2008-04-14 00:12 144896 c:\windows\system32\wbem\wmiprov.dll - 2005-11-25 08:58 . 2004-08-04 12:00 144896 c:\windows\system32\wbem\wmiprov.dll + 2005-11-25 08:58 . 2008-04-14 00:12 132096 c:\windows\system32\wbem\wmipdskq.dll - 2005-11-25 08:58 . 2004-08-04 12:00 132096 c:\windows\system32\wbem\wmipdskq.dll + 2005-11-25 08:58 . 2008-04-14 00:12 156672 c:\windows\system32\wbem\wmipcima.dll - 2005-11-25 08:58 . 2004-08-04 12:00 156672 c:\windows\system32\wbem\wmipcima.dll - 2005-11-25 08:58 . 2004-08-04 12:00 140800 c:\windows\system32\wbem\wmidcprv.dll + 2005-11-25 08:58 . 2008-04-14 00:12 140800 c:\windows\system32\wbem\wmidcprv.dll + 2005-11-25 08:58 . 2008-04-14 00:12 126464 c:\windows\system32\wbem\wmiapsrv.exe - 2005-11-25 08:58 . 2004-08-04 12:00 126464 c:\windows\system32\wbem\wmiapsrv.exe - 2005-11-25 08:58 . 2004-08-04 12:00 196608 c:\windows\system32\wbem\wmiadap.exe + 2005-11-25 08:58 . 2008-04-14 00:12 196608 c:\windows\system32\wbem\wmiadap.exe + 2005-11-25 08:58 . 2008-04-14 00:12 197120 c:\windows\system32\wbem\wbemupgd.dll - 2005-11-25 08:58 . 2004-08-04 12:00 197120 c:\windows\system32\wbem\wbemupgd.dll + 2005-11-25 08:58 . 2008-04-14 00:12 116224 c:\windows\system32\wbem\wbemtest.exe - 2005-11-25 08:58 . 2004-08-04 12:00 116224 c:\windows\system32\wbem\wbemtest.exe + 2005-11-25 08:58 . 2008-04-14 00:12 273920 c:\windows\system32\wbem\wbemess.dll - 2005-11-25 08:58 . 2004-08-04 12:00 273920 c:\windows\system32\wbem\wbemess.dll - 2005-11-25 08:58 . 2004-08-04 12:00 178176 c:\windows\system32\wbem\wbemdisp.dll + 2005-11-25 08:58 . 2008-04-14 00:12 178176 c:\windows\system32\wbem\wbemdisp.dll + 2005-11-25 08:58 . 2008-04-14 00:12 531456 c:\windows\system32\wbem\wbemcore.dll - 2005-11-25 08:58 . 2004-08-04 12:00 214528 c:\windows\system32\wbem\wbemcomn.dll + 2005-11-25 08:58 . 2008-04-14 00:12 214528 c:\windows\system32\wbem\wbemcomn.dll - 2005-11-25 08:58 . 2004-08-04 12:00 196608 c:\windows\system32\wbem\wbemcntl.dll + 2005-11-25 08:58 . 2008-04-14 00:12 196608 c:\windows\system32\wbem\wbemcntl.dll - 2005-11-25 08:58 . 2004-08-04 12:00 131584 c:\windows\system32\wbem\viewprov.dll + 2005-11-25 08:58 . 2008-04-14 00:12 131584 c:\windows\system32\wbem\viewprov.dll + 2005-11-25 08:58 . 2008-04-14 00:12 178176 c:\windows\system32\wbem\repdrvfs.dll + 2005-11-25 08:58 . 2008-04-14 00:12 237056 c:\windows\system32\wbem\provthrd.dll - 2005-11-25 08:58 . 2004-08-04 12:00 237056 c:\windows\system32\wbem\provthrd.dll - 2005-11-25 08:58 . 2004-08-04 12:00 212992 c:\windows\system32\wbem\ntevt.dll + 2005-11-25 08:58 . 2008-04-14 00:12 212992 c:\windows\system32\wbem\ntevt.dll - 2005-11-25 08:58 . 2004-08-04 12:00 123904 c:\windows\system32\wbem\mofd.dll + 2005-11-25 08:58 . 2008-04-14 00:11 123904 c:\windows\system32\wbem\mofd.dll + 2005-11-25 08:58 . 2008-04-14 00:11 185344 c:\windows\system32\wbem\framedyn.dll + 2005-11-25 08:58 . 2009-02-09 12:10 473600 c:\windows\system32\wbem\fastprox.dll + 2005-11-25 08:58 . 2008-04-14 00:11 247808 c:\windows\system32\wbem\esscli.dll - 2005-11-25 08:58 . 2004-08-04 12:00 247808 c:\windows\system32\wbem\esscli.dll + 2005-09-09 22:03 . 2008-04-14 00:12 215552 c:\windows\system32\wavemsp.dll + 2005-09-09 22:03 . 2008-04-14 00:12 175104 c:\windows\system32\w32time.dll + 2005-09-09 22:03 . 2008-04-14 00:12 289792 c:\windows\system32\vssvc.exe - 2005-09-09 22:03 . 2004-08-04 12:00 289792 c:\windows\system32\vssvc.exe + 2005-09-09 22:03 . 2008-04-14 00:12 430592 c:\windows\system32\vssapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 430592 c:\windows\system32\vssapi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 434176 c:\windows\system32\vbscript.dll - 2005-09-09 22:03 . 2004-08-04 12:00 218624 c:\windows\system32\uxtheme.dll + 2005-09-09 22:03 . 2008-04-14 00:12 218624 c:\windows\system32\uxtheme.dll + 2005-09-09 22:03 . 2008-04-14 00:12 406016 c:\windows\system32\usp10.dll + 2005-11-25 16:41 . 2008-04-14 00:12 173568 c:\windows\system32\usmt\sysmoda.dll - 2005-11-25 16:41 . 2005-04-28 19:16 173568 c:\windows\system32\usmt\sysmoda.dll + 2005-09-09 22:03 . 2008-04-14 00:12 193024 c:\windows\system32\usmt\sysmod.dll - 2005-09-09 22:03 . 2005-04-28 19:16 193024 c:\windows\system32\usmt\sysmod.dll + 2005-11-25 16:41 . 2008-04-14 00:12 199680 c:\windows\system32\usmt\scripta.dll - 2005-11-25 16:41 . 2005-04-28 19:16 199680 c:\windows\system32\usmt\scripta.dll - 2005-09-09 22:03 . 2005-04-28 19:16 215552 c:\windows\system32\usmt\script.dll + 2005-09-09 22:03 . 2008-04-14 00:12 215552 c:\windows\system32\usmt\script.dll - 2005-11-25 16:41 . 2005-04-28 00:12 241152 c:\windows\system32\usmt\migwiza.exe + 2005-11-25 16:41 . 2008-04-14 00:12 241152 c:\windows\system32\usmt\migwiza.exe - 2005-09-09 22:03 . 2005-04-28 00:12 245248 c:\windows\system32\usmt\migwiz.exe + 2005-09-09 22:03 . 2008-04-14 00:12 245248 c:\windows\system32\usmt\migwiz.exe + 2005-09-09 22:03 . 2008-04-14 00:12 103936 c:\windows\system32\usmt\migload.exe + 2005-11-25 16:41 . 2008-04-14 00:11 261120 c:\windows\system32\usmt\migisma.dll - 2005-11-25 16:41 . 2005-04-28 12:16 261120 c:\windows\system32\usmt\migisma.dll - 2005-09-09 22:03 . 2005-04-28 19:16 274432 c:\windows\system32\usmt\migism.dll + 2005-09-09 22:03 . 2008-04-14 00:11 274432 c:\windows\system32\usmt\migism.dll - 2005-11-25 16:41 . 2005-04-28 19:16 115200 c:\windows\system32\usmt\guitrna.dll + 2005-11-25 16:41 . 2008-04-14 00:11 115200 c:\windows\system32\usmt\guitrna.dll + 2005-09-09 22:03 . 2008-04-14 00:11 133120 c:\windows\system32\usmt\guitrn.dll - 2005-09-09 22:03 . 2005-04-28 19:16 133120 c:\windows\system32\usmt\guitrn.dll + 2005-09-09 22:03 . 2008-04-14 00:12 727040 c:\windows\system32\userenv.dll |
|
|
|
|
#15 (permalink) |
|
Registered User
Join Date: Jul 2009
Posts: 14
OS: xp
|
Re: Recurring Vundo Trojan
+ 2005-09-09 22:03 . 2008-04-14 00:12 578560 c:\windows\system32\user32.dll
+ 2005-09-09 22:03 . 2009-04-29 04:46 620032 c:\windows\system32\urlmon.dll - 2005-09-09 22:03 . 2004-08-04 12:00 239616 c:\windows\system32\upnpui.dll + 2005-09-09 22:03 . 2008-04-14 00:12 239616 c:\windows\system32\upnpui.dll + 2005-09-09 22:03 . 2008-04-14 00:12 185856 c:\windows\system32\upnphost.dll + 2005-09-09 22:03 . 2008-04-14 00:12 133632 c:\windows\system32\upnp.dll + 2005-09-09 22:03 . 2008-04-14 00:12 316416 c:\windows\system32\untfs.dll - 2005-09-09 22:03 . 2004-08-04 12:00 316416 c:\windows\system32\untfs.dll - 2005-09-09 22:03 . 2005-08-23 03:35 123392 c:\windows\system32\umpnpmgr.dll + 2005-09-09 22:03 . 2008-04-14 00:12 123392 c:\windows\system32\umpnpmgr.dll - 2005-09-09 22:03 . 2004-08-04 12:00 275456 c:\windows\system32\ulib.dll + 2005-09-09 22:03 . 2008-04-14 00:12 275456 c:\windows\system32\ulib.dll - 2005-09-09 22:03 . 2005-07-26 04:39 101376 c:\windows\system32\txflog.dll + 2005-09-09 22:03 . 2008-04-14 00:12 101376 c:\windows\system32\txflog.dll + 2005-09-09 22:03 . 2008-04-14 00:12 347136 c:\windows\system32\tourstart.exe - 2005-09-09 22:03 . 2004-08-04 12:00 347136 c:\windows\system32\tourstart.exe - 2005-09-09 22:03 . 2004-08-04 12:00 385536 c:\windows\system32\themeui.dll + 2005-09-09 22:03 . 2008-04-14 00:12 385536 c:\windows\system32\themeui.dll - 2005-11-25 08:58 . 2004-08-04 12:00 295424 c:\windows\system32\termsrv.dll + 2005-11-25 08:58 . 2008-04-14 00:12 295424 c:\windows\system32\termsrv.dll - 2005-09-09 22:03 . 2004-08-04 12:00 358400 c:\windows\system32\termmgr.dll + 2005-09-09 22:03 . 2008-04-14 00:12 358400 c:\windows\system32\termmgr.dll + 2005-09-09 22:03 . 2008-04-14 00:12 135680 c:\windows\system32\taskmgr.exe - 2005-09-09 22:03 . 2004-08-04 12:00 135680 c:\windows\system32\taskmgr.exe + 2005-09-09 22:03 . 2008-04-14 00:12 249856 c:\windows\system32\tapisrv.dll - 2005-09-09 22:03 . 2004-08-04 12:00 181760 c:\windows\system32\tapi32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 181760 c:\windows\system32\tapi32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 858624 c:\windows\system32\tapi3.dll + 2005-09-09 22:03 . 2008-04-14 00:12 858624 c:\windows\system32\tapi3.dll + 2005-09-09 22:03 . 2008-04-14 00:12 117760 c:\windows\system32\t2embed.dll + 2005-09-09 22:03 . 2008-04-14 00:12 990208 c:\windows\system32\syssetup.dll + 2005-09-09 22:03 . 2008-04-14 00:12 106496 c:\windows\system32\sysocmgr.exe + 2005-09-09 22:03 . 2008-04-14 00:12 191488 c:\windows\system32\syncui.dll - 2005-09-09 22:03 . 2004-08-04 12:00 191488 c:\windows\system32\syncui.dll + 2005-09-09 22:03 . 2008-04-14 00:12 713216 c:\windows\system32\sxs.dll - 2005-09-09 22:03 . 2006-10-19 13:56 713216 c:\windows\system32\sxs.dll + 2005-09-09 22:03 . 2008-10-03 10:02 247326 c:\windows\system32\strmdll.dll - 2005-09-09 22:03 . 2008-10-03 10:15 247326 c:\windows\system32\strmdll.dll + 2005-09-09 22:03 . 2008-04-14 00:12 121856 c:\windows\system32\stobject.dll - 2005-09-09 22:03 . 2004-08-04 12:00 121856 c:\windows\system32\stobject.dll + 2005-09-09 22:03 . 2008-04-14 00:12 136704 c:\windows\system32\sti_ci.dll - 2005-09-09 22:03 . 2004-08-04 12:00 136704 c:\windows\system32\sti_ci.dll - 2005-09-09 22:03 . 2004-08-04 12:00 679936 c:\windows\system32\sstext3d.scr + 2005-09-09 22:03 . 2008-04-14 00:12 679936 c:\windows\system32\sstext3d.scr + 2005-09-09 22:03 . 2008-04-14 00:12 610304 c:\windows\system32\sspipes.scr - 2005-09-09 22:03 . 2004-08-04 12:00 610304 c:\windows\system32\sspipes.scr - 2005-09-09 22:03 . 2004-08-04 12:00 393216 c:\windows\system32\ssflwbox.scr + 2005-09-09 22:03 . 2008-04-14 00:12 393216 c:\windows\system32\ssflwbox.scr + 2005-09-09 22:03 . 2008-04-14 00:12 704512 c:\windows\system32\ss3dfo.scr - 2005-09-09 22:03 . 2004-08-04 12:00 704512 c:\windows\system32\ss3dfo.scr + 2005-11-25 08:59 . 2008-04-14 00:12 171008 c:\windows\system32\srsvc.dll + 2005-11-25 08:59 . 2008-04-14 00:12 239104 c:\windows\system32\srrstr.dll - 2005-11-25 08:59 . 2004-08-04 12:00 239104 c:\windows\system32\srrstr.dll + 2005-09-09 22:03 . 2008-04-14 00:12 180800 c:\windows\system32\sqlunirl.dll - 2005-09-09 22:03 . 2004-08-04 12:00 180800 c:\windows\system32\sqlunirl.dll - 2005-09-09 22:03 . 2004-08-04 12:00 442368 c:\windows\system32\sqlsrv32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 442368 c:\windows\system32\sqlsrv32.dll + 2006-01-06 17:39 . 2007-05-15 08:08 761344 c:\windows\system32\spool\drivers\w32x86\3\unires.dll + 2006-01-06 17:39 . 2008-04-14 00:12 744448 c:\windows\system32\spool\drivers\w32x86\3\unidrvui.dll + 2006-01-06 17:39 . 2008-04-14 00:12 373248 c:\windows\system32\spool\drivers\w32x86\3\unidrv.dll + 2005-11-25 09:03 . 2008-04-14 00:11 192512 c:\windows\system32\spool\drivers\w32x86\3\fxswzrd.dll - 2005-11-25 09:03 . 2004-08-04 12:00 192512 c:\windows\system32\spool\drivers\w32x86\3\FXSWZRD.DLL + 2005-11-25 09:03 . 2008-04-14 00:11 154112 c:\windows\system32\spool\drivers\w32x86\3\fxsui.dll - 2005-11-25 09:03 . 2004-08-04 12:00 154112 c:\windows\system32\spool\drivers\w32x86\3\FXSUI.DLL + 2005-11-25 09:03 . 2008-04-14 00:11 397312 c:\windows\system32\spool\drivers\w32x86\3\fxstiff.dll - 2005-11-25 09:03 . 2004-08-04 12:00 397312 c:\windows\system32\spool\drivers\w32x86\3\FXSTIFF.DLL + 2005-11-25 09:03 . 2008-04-14 00:11 451584 c:\windows\system32\spool\drivers\w32x86\3\fxsapi.dll + 2005-11-25 08:58 . 2008-04-14 00:12 538624 c:\windows\system32\spider.exe - 2005-11-25 08:58 . 2004-08-04 12:00 538624 c:\windows\system32\spider.exe - 2005-09-09 22:03 . 2004-08-04 12:00 182272 c:\windows\system32\snmpsnap.dll + 2005-09-09 22:03 . 2008-04-14 00:12 182272 c:\windows\system32\snmpsnap.dll + 2005-11-25 08:58 . 2008-04-14 00:12 131584 c:\windows\system32\sndrec32.exe - 2005-11-25 08:58 . 2004-08-04 12:00 131584 c:\windows\system32\sndrec32.exe + 2005-09-09 22:03 . 2008-04-14 00:12 362496 c:\windows\system32\smlogcfg.dll - 2007-09-22 16:26 . 2004-08-03 23:56 188508 c:\windows\system32\slgen.dll + 2007-09-22 16:26 . 2008-04-14 00:12 188508 c:\windows\system32\slgen.dll - 2007-09-22 16:26 . 2004-08-03 23:56 286792 c:\windows\system32\slextspk.dll + 2007-09-22 16:26 . 2008-04-14 00:12 286792 c:\windows\system32\slextspk.dll + 2005-09-09 22:03 . 2008-04-14 00:12 135168 c:\windows\system32\shsvcs.dll + 2005-09-09 22:03 . 2008-04-14 00:12 152064 c:\windows\system32\shmedia.dll + 2005-09-09 22:03 . 2008-04-14 00:12 474112 c:\windows\system32\shlwapi.dll - 2005-09-09 22:03 . 2009-02-20 08:14 474112 c:\windows\system32\shlwapi.dll - 2005-09-09 22:03 . 2004-08-04 12:00 438272 c:\windows\system32\shimgvw.dll + 2005-09-09 22:03 . 2008-04-14 00:12 438272 c:\windows\system32\shimgvw.dll + 2005-09-09 22:03 . 2008-04-13 17:03 549376 c:\windows\system32\shdoclc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 549376 c:\windows\system32\shdoclc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 140288 c:\windows\system32\sfc_os.dll - 2005-09-09 22:03 . 2004-08-04 12:00 140288 c:\windows\system32\sfc_os.dll + 2005-09-09 22:03 . 2008-04-14 04:42 985088 c:\windows\system32\setupapi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 130048 c:\windows\system32\Setup\tsoc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 101376 c:\windows\system32\Setup\setupqry.dll - 2005-09-09 22:03 . 2004-08-04 12:00 101376 c:\windows\system32\Setup\setupqry.dll + 2005-09-09 22:03 . 2008-04-14 00:11 123392 c:\windows\system32\Setup\imsinsnt.dll - 2005-09-09 22:03 . 2004-08-04 12:00 505344 c:\windows\system32\Setup\iis.dll + 2005-09-09 22:03 . 2008-04-14 00:11 505344 c:\windows\system32\Setup\iis.dll + 2005-09-09 22:03 . 2008-04-14 00:11 132608 c:\windows\system32\Setup\fxsocm.dll - 2005-09-09 22:03 . 2004-08-04 12:00 132608 c:\windows\system32\Setup\fxsocm.dll + 2005-09-09 22:03 . 2008-04-14 00:11 274944 c:\windows\system32\Setup\comsetup.dll + 2005-11-25 08:58 . 2008-04-14 00:12 141312 c:\windows\system32\sessmgr.exe + 2005-09-09 22:03 . 2009-02-06 11:11 110592 c:\windows\system32\services.exe - 2005-09-09 22:03 . 2009-02-06 17:14 110592 c:\windows\system32\services.exe + 2005-09-09 22:03 . 2008-04-14 00:12 172032 c:\windows\system32\scrrun.dll + 2005-09-09 22:03 . 2008-04-14 00:12 180224 c:\windows\system32\scrobj.dll + 2005-11-25 08:59 . 2008-04-14 00:12 192512 c:\windows\system32\schedsvc.dll + 2005-09-09 22:03 . 2008-12-05 06:54 144896 c:\windows\system32\schannel.dll - 2005-09-09 22:03 . 2008-12-05 07:12 144896 c:\windows\system32\schannel.dll + 2005-09-09 22:03 . 2008-04-14 00:12 314880 c:\windows\system32\scesrv.dll + 2005-09-09 22:03 . 2008-04-14 00:12 181248 c:\windows\system32\scecli.dll + 2005-09-09 22:03 . 2008-04-14 00:12 171008 c:\windows\system32\sccsccp.dll - 2005-09-09 22:03 . 2004-08-04 12:00 171008 c:\windows\system32\sccsccp.dll - 2005-09-09 22:03 . 2004-08-04 12:00 159232 c:\windows\system32\sbeio.dll + 2005-09-09 22:03 . 2008-04-14 00:12 159232 c:\windows\system32\sbeio.dll - 2005-09-09 22:03 . 2004-08-04 12:00 270848 c:\windows\system32\sbe.dll + 2005-09-09 22:03 . 2008-04-14 00:12 270848 c:\windows\system32\sbe.dll + 2005-09-09 22:03 . 2008-04-14 00:12 415744 c:\windows\system32\samsrv.dll - 2005-09-09 22:03 . 2004-08-04 12:00 415744 c:\windows\system32\samsrv.dll + 2007-09-22 16:26 . 2008-04-14 00:12 397056 c:\windows\system32\s3gnb.dll - 2007-09-22 16:26 . 2004-08-03 23:56 397056 c:\windows\system32\s3gnb.dll + 2005-09-09 22:03 . 2008-04-13 17:37 208384 c:\windows\system32\rsaenh.dll + 2005-09-09 22:03 . 2009-02-09 12:10 401408 c:\windows\system32\rpcss.dll + 2005-09-09 22:03 . 2008-04-14 00:12 433664 c:\windows\system32\riched20.dll + 2008-09-08 22:53 . 2008-04-14 00:12 290304 c:\windows\system32\rhttpaa.dll - 2005-11-25 08:59 . 2004-08-04 12:00 380416 c:\windows\system32\Restore\rstrui.exe + 2005-11-25 08:59 . 2008-04-14 00:12 380416 c:\windows\system32\Restore\rstrui.exe + 2009-07-06 01:21 . 2004-10-27 15:21 138240 c:\windows\system32\ReinstallBackups\0009\DriverFiles\hdaudbus.sys + 2005-09-09 22:03 . 2008-04-14 00:12 397824 c:\windows\system32\regwizc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 397824 c:\windows\system32\regwizc.dll - 2005-11-25 08:58 . 2004-08-04 12:00 147968 c:\windows\system32\rdchost.dll + 2005-11-25 08:58 . 2008-04-14 00:12 147968 c:\windows\system32\rdchost.dll - 2005-09-09 22:03 . 2004-08-04 12:00 102400 c:\windows\system32\rcbdyctl.dll + 2005-09-09 22:03 . 2008-04-14 00:12 102400 c:\windows\system32\rcbdyctl.dll + 2005-09-09 22:03 . 2008-04-14 00:12 150016 c:\windows\system32\rastls.dll + 2005-09-09 22:03 . 2008-04-14 00:12 210944 c:\windows\system32\rasppp.dll + 2005-09-09 22:03 . 2008-04-14 00:12 186368 c:\windows\system32\rasmans.dll + 2005-09-09 22:03 . 2008-04-14 00:12 658432 c:\windows\system32\rasdlg.dll + 2005-09-09 22:03 . 2008-04-14 00:12 237056 c:\windows\system32\rasapi32.dll + 2005-11-25 08:59 . 2008-04-14 00:12 409088 c:\windows\system32\qmgr.dll + 2005-09-09 22:03 . 2008-04-13 17:21 733696 c:\windows\system32\qedwipes.dll - 2005-09-09 22:03 . 2004-08-04 12:00 733696 c:\windows\system32\qedwipes.dll + 2005-09-09 22:03 . 2008-04-14 00:12 562176 c:\windows\system32\qedit.dll - 2005-09-09 22:03 . 2004-08-04 12:00 562176 c:\windows\system32\qedit.dll + 2005-09-09 22:03 . 2008-04-14 00:12 386048 c:\windows\system32\qdvd.dll + 2005-09-09 22:03 . 2008-04-14 00:12 279040 c:\windows\system32\qdv.dll - 2005-09-09 22:03 . 2004-08-04 12:00 279040 c:\windows\system32\qdv.dll + 2005-09-09 22:03 . 2008-04-14 00:12 192512 c:\windows\system32\qcap.dll - 2005-09-09 22:03 . 2004-08-04 12:00 192512 c:\windows\system32\qcap.dll + 2008-09-08 22:53 . 2008-04-14 00:12 291328 c:\windows\system32\qagentrt.dll + 2008-09-08 22:53 . 2008-04-14 00:12 150528 c:\windows\system32\qagent.dll + 2005-09-09 22:03 . 2008-04-14 00:12 109568 c:\windows\system32\progman.exe - 2005-09-09 22:03 . 2004-08-04 12:00 109568 c:\windows\system32\progman.exe - 2005-09-09 22:03 . 2004-08-04 12:00 560640 c:\windows\system32\printui.dll + 2005-09-09 22:03 . 2008-04-14 00:12 560640 c:\windows\system32\printui.dll - 2005-09-09 22:03 . 2004-08-04 12:00 105472 c:\windows\system32\polstore.dll + 2005-09-09 22:03 . 2008-04-14 00:12 105472 c:\windows\system32\polstore.dll + 2005-09-09 22:03 . 2008-04-14 00:12 176128 c:\windows\system32\photowiz.dll - 2005-09-09 22:03 . 2004-08-04 12:00 176128 c:\windows\system32\photowiz.dll - 2006-10-24 11:30 . 2006-10-24 11:30 412160 c:\windows\system32\photometadatahandler.dll + 2006-10-24 11:30 . 2008-04-14 00:12 412160 c:\windows\system32\photometadatahandler.dll - 2005-09-09 22:03 . 2009-04-20 09:36 408650 c:\windows\system32\perfh009.dat + 2005-09-09 22:03 . 2009-07-06 02:10 408650 c:\windows\system32\perfh009.dat + 2005-09-09 22:03 . 2009-03-06 14:22 284160 c:\windows\system32\pdh.dll + 2005-09-09 22:03 . 2008-04-14 00:12 554496 c:\windows\system32\p2psvc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 115712 c:\windows\system32\p2pnetsh.dll + 2005-09-09 22:03 . 2008-04-14 00:12 313856 c:\windows\system32\p2pgraph.dll + 2005-09-09 22:03 . 2008-04-14 00:12 105472 c:\windows\system32\p2pgasvc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 153600 c:\windows\system32\p2p.dll - 2005-09-09 22:03 . 2004-08-04 12:00 215552 c:\windows\system32\osk.exe + 2005-09-09 22:03 . 2008-04-14 00:12 215552 c:\windows\system32\osk.exe - 2005-09-09 22:03 . 2004-08-04 12:00 713728 c:\windows\system32\opengl32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 713728 c:\windows\system32\opengl32.dll + 2005-11-25 08:59 . 2008-04-14 00:12 565248 c:\windows\system32\oobe\msobmain.dll + 2005-11-25 08:59 . 2008-04-14 00:12 122368 c:\windows\system32\oobe\msobcomm.dll - 2005-11-25 08:59 . 2004-08-04 12:00 122368 c:\windows\system32\oobe\msobcomm.dll + 2008-09-08 22:53 . 2008-04-14 00:12 144384 c:\windows\system32\onex.dll - 2005-09-09 22:03 . 2004-08-04 12:00 107008 c:\windows\system32\oleprn.dll + 2005-09-09 22:03 . 2008-04-14 00:12 107008 c:\windows\system32\oleprn.dll + 2005-09-09 22:03 . 2008-04-14 00:12 122880 c:\windows\system32\oledlg.dll - 2005-09-09 22:03 . 2006-10-16 16:15 122880 c:\windows\system32\oledlg.dll + 2005-09-09 22:03 . 2008-04-14 00:12 551936 c:\windows\system32\oleaut32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 192000 c:\windows\system32\offfilt.dll + 2005-09-09 22:03 . 2008-04-14 00:12 147456 c:\windows\system32\odbctrac.dll - 2005-09-09 22:03 . 2004-08-04 12:00 147456 c:\windows\system32\odbctrac.dll - 2005-09-09 22:03 . 2004-08-04 12:00 278559 c:\windows\system32\odbcjt32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 278559 c:\windows\system32\odbcjt32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 106496 c:\windows\system32\odbccp32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 106496 c:\windows\system32\odbccp32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 135168 c:\windows\system32\odbcconf.dll - 2005-09-09 22:03 . 2004-08-04 12:00 135168 c:\windows\system32\odbcconf.dll + 2005-09-09 22:03 . 2008-04-14 00:12 249856 c:\windows\system32\odbc32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 249856 c:\windows\system32\odbc32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 286208 c:\windows\system32\objsel.dll + 2005-09-09 22:03 . 2008-04-14 00:12 270336 c:\windows\system32\oakley.dll - 2005-09-09 22:03 . 2006-10-13 12:35 142336 c:\windows\system32\nwprovau.dll + 2005-09-09 22:03 . 2008-04-14 00:12 142336 c:\windows\system32\nwprovau.dll + 2005-09-09 22:03 . 2008-04-14 00:12 420864 c:\windows\system32\ntvdm.exe + 2005-09-09 22:03 . 2008-04-14 00:12 143360 c:\windows\system32\ntshrui.dll - 2005-09-09 22:03 . 2004-08-04 12:00 435200 c:\windows\system32\ntmssvc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 435200 c:\windows\system32\ntmssvc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 488448 c:\windows\system32\ntmsmgr.dll + 2005-09-09 22:03 . 2008-04-14 00:12 488448 c:\windows\system32\ntmsmgr.dll + 2005-09-09 22:03 . 2008-04-14 00:12 179200 c:\windows\system32\ntmsdba.dll - 2005-09-09 22:03 . 2004-08-04 12:00 118784 c:\windows\system32\ntmarta.dll + 2005-09-09 22:03 . 2008-04-14 00:12 118784 c:\windows\system32\ntmarta.dll + 2005-09-09 22:03 . 2009-02-09 12:10 714752 c:\windows\system32\ntdll.dll - 2005-09-09 22:03 . 2009-02-09 10:20 714752 c:\windows\system32\ntdll.dll + 2005-09-09 22:03 . 2008-04-14 00:12 247808 c:\windows\system32\newdev.dll + 2005-09-09 22:03 . 2008-04-14 00:12 245760 c:\windows\system32\netui1.dll - 2005-09-09 22:03 . 2004-08-04 12:00 245760 c:\windows\system32\netui1.dll - 2005-09-09 22:03 . 2004-08-04 12:00 329728 c:\windows\system32\netsetup.exe + 2005-09-09 22:03 . 2008-04-14 00:16 329728 c:\windows\system32\netsetup.exe + 2005-09-09 22:03 . 2008-04-14 00:12 875008 c:\windows\system32\netplwiz.dll - 2005-09-09 22:03 . 2004-08-04 12:00 875008 c:\windows\system32\netplwiz.dll + 2005-09-09 22:03 . 2008-04-14 00:12 198144 c:\windows\system32\netman.dll + 2005-09-09 22:03 . 2008-04-14 00:12 407040 c:\windows\system32\netlogon.dll - 2005-09-09 22:03 . 2004-08-04 12:00 407040 c:\windows\system32\netlogon.dll - 2005-09-09 22:03 . 2004-08-04 12:00 139264 c:\windows\system32\netid.dll + 2005-09-09 22:03 . 2008-04-14 00:12 139264 c:\windows\system32\netid.dll - 2005-09-09 22:03 . 2004-08-04 12:00 111104 c:\windows\system32\netdde.exe + 2005-09-09 22:03 . 2008-04-14 00:12 111104 c:\windows\system32\netdde.exe + 2005-09-09 22:03 . 2008-04-14 00:12 622592 c:\windows\system32\netcfgx.dll + 2005-09-09 22:03 . 2008-10-15 16:34 337408 c:\windows\system32\netapi32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 124928 c:\windows\system32\net1.exe - 2005-09-09 22:03 . 2004-08-04 12:00 124928 c:\windows\system32\net1.exe + 2008-09-08 22:53 . 2008-04-14 00:12 176640 c:\windows\system32\napstat.exe + 2008-09-08 22:53 . 2008-04-14 00:12 193024 c:\windows\system32\napmontr.dll + 2008-09-08 22:53 . 2008-04-13 18:40 576512 c:\windows\system32\mui\0424\xpsp3res.dll - 2005-09-09 22:03 . 2004-08-04 12:00 732160 c:\windows\system32\mui\0424\xpsp2res.dll + 2005-09-09 22:03 . 2008-04-13 18:38 732160 c:\windows\system32\mui\0424\xpsp2res.dll - 2005-09-09 22:03 . 2004-08-04 12:00 192512 c:\windows\system32\mui\0424\xpsp1res.dll + 2005-09-09 22:03 . 2008-04-13 18:35 192512 c:\windows\system32\mui\0424\xpsp1res.dll + 2005-09-09 22:03 . 2008-04-13 18:40 408576 c:\windows\system32\mui\0424\xpob2res.dll - 2005-09-09 22:03 . 2004-08-04 12:00 408576 c:\windows\system32\mui\0424\xpob2res.dll - 2007-09-22 16:26 . 2004-08-03 23:56 187392 c:\windows\system32\mui\041e\xpsp1res.dll + 2007-09-22 16:26 . 2008-04-13 17:39 187392 c:\windows\system32\mui\041e\xpsp1res.dll + 2008-09-08 22:53 . 2008-04-13 18:40 577536 c:\windows\system32\mui\041b\xpsp3res.dll - 2005-09-09 22:03 . 2004-08-04 12:00 757248 c:\windows\system32\mui\041b\xpsp2res.dll + 2005-09-09 22:03 . 2008-04-13 18:38 757248 c:\windows\system32\mui\041b\xpsp2res.dll + 2005-09-09 22:03 . 2008-04-13 18:35 192512 c:\windows\system32\mui\041b\xpsp1res.dll + 2005-09-09 22:03 . 2008-04-13 18:40 405504 c:\windows\system32\mui\041b\xpob2res.dll - 2005-09-09 22:03 . 2004-08-04 12:00 405504 c:\windows\system32\mui\041b\xpob2res.dll - 2005-09-09 22:03 . 2004-08-04 12:00 701440 c:\windows\system32\msxml2.dll + 2005-09-09 22:03 . 2008-04-14 00:12 701440 c:\windows\system32\msxml2.dll - 2005-09-09 22:03 . 2004-08-04 12:00 506368 c:\windows\system32\msxml.dll + 2005-09-09 22:03 . 2008-04-14 00:12 506368 c:\windows\system32\msxml.dll + 2005-09-09 22:03 . 2008-06-20 17:46 245248 c:\windows\system32\mswsock.dll - 2005-09-09 22:03 . 2008-06-20 17:41 245248 c:\windows\system32\mswsock.dll + 2005-09-09 22:03 . 2008-04-14 00:12 203776 c:\windows\system32\mswebdvd.dll + 2005-09-09 22:03 . 2008-04-14 00:12 121344 c:\windows\system32\msvfw32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 343040 c:\windows\system32\msvcrt.dll - 2005-09-09 22:03 . 2004-08-04 12:00 343040 c:\windows\system32\msvcrt.dll - 2005-09-09 22:03 . 2004-08-04 12:00 413696 c:\windows\system32\msvcp60.dll + 2005-09-09 22:03 . 2008-04-14 00:12 413696 c:\windows\system32\msvcp60.dll + 2005-09-09 22:03 . 2008-04-14 00:12 132608 c:\windows\system32\msv1_0.dll + 2005-09-09 22:03 . 2008-04-14 00:12 195072 c:\windows\system32\msutb.dll - 2005-09-09 22:03 . 2004-08-04 12:00 195072 c:\windows\system32\msutb.dll + 2005-11-25 08:58 . 2008-04-14 00:12 677888 c:\windows\system32\mstsc.exe + 2005-09-09 22:03 . 2008-04-14 00:12 116224 c:\windows\system32\mstlsapi.dll + 2005-09-09 22:03 . 2008-04-14 00:12 532480 c:\windows\system32\mstime.dll - 2005-09-09 22:03 . 2009-02-20 08:14 532480 c:\windows\system32\mstime.dll - 2005-11-25 08:59 . 2004-08-04 12:00 274944 c:\windows\system32\mstask.dll + 2005-11-25 08:59 . 2008-04-14 00:12 274944 c:\windows\system32\mstask.dll + 2008-09-08 22:53 . 2008-04-14 00:12 155136 c:\windows\system32\mssha.dll + 2005-09-09 22:03 . 2008-04-14 00:12 134656 c:\windows\system32\mssap.dll - 2005-09-09 22:03 . 2004-08-04 12:00 134656 c:\windows\system32\mssap.dll - 2005-09-09 22:03 . 2009-02-20 08:14 146432 c:\windows\system32\msrating.dll + 2005-09-09 22:03 . 2008-04-14 00:12 146432 c:\windows\system32\msrating.dll - 2005-11-25 08:58 . 2004-08-04 12:00 343040 c:\windows\system32\mspaint.exe + 2005-11-25 08:58 . 2008-04-14 00:12 343040 c:\windows\system32\mspaint.exe - 2005-09-09 22:03 . 2004-08-04 12:00 143360 c:\windows\system32\msorcl32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 143360 c:\windows\system32\msorcl32.dll - 2005-11-25 08:59 . 2004-08-04 12:00 105984 c:\windows\system32\msoert2.dll + 2005-11-25 08:59 . 2008-04-14 00:12 105984 c:\windows\system32\msoert2.dll - 2005-11-25 08:59 . 2004-08-04 12:00 252928 c:\windows\system32\msoeacct.dll + 2005-11-25 08:59 . 2008-04-14 00:12 252928 c:\windows\system32\msoeacct.dll - 2005-09-09 22:03 . 2004-08-04 12:00 290816 c:\windows\system32\msnsspc.dll + 2005-09-09 22:03 . 2008-04-14 00:12 290816 c:\windows\system32\msnsspc.dll - 2005-09-09 22:03 . 2008-03-27 08:12 151583 c:\windows\system32\msjint40.dll + 2005-09-09 22:03 . 2008-04-14 00:12 151583 c:\windows\system32\msjint40.dll + 2005-09-09 22:03 . 2008-04-14 00:11 159232 c:\windows\system32\msimtf.dll - 2005-09-09 22:03 . 2004-08-04 12:00 159232 c:\windows\system32\MSIMTF.dll + 2005-09-09 22:03 . 2008-04-13 15:39 884736 c:\windows\system32\msimsg.dll - 2005-09-09 22:03 . 2005-05-04 14:45 884736 c:\windows\system32\msimsg.dll - 2005-09-09 22:03 . 2005-05-04 14:45 271360 c:\windows\system32\msihnd.dll + 2005-09-09 22:03 . 2008-04-14 00:11 271360 c:\windows\system32\msihnd.dll - 2005-09-09 22:03 . 2004-08-04 12:00 248832 c:\windows\system32\msieftp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 248832 c:\windows\system32\msieftp.dll - 2005-09-09 22:03 . 2009-02-20 08:14 449024 c:\windows\system32\mshtmled.dll + 2005-09-09 22:03 . 2008-04-14 00:11 449024 c:\windows\system32\mshtmled.dll + 2004-08-04 00:56 . 2008-04-14 00:12 294912 c:\windows\system32\msh263.drv - 2004-08-04 00:56 . 2004-08-04 12:00 294912 c:\windows\system32\msh263.drv + 2005-11-25 08:59 . 2008-04-14 00:12 188416 c:\windows\system32\msh261.drv - 2005-11-25 08:59 . 2004-08-04 12:00 188416 c:\windows\system32\msh261.drv + 2005-09-09 22:03 . 2008-04-14 00:11 997376 c:\windows\system32\msgina.dll - 2005-09-09 22:03 . 2006-11-27 14:54 539136 c:\windows\system32\msftedit.dll + 2005-09-09 22:03 . 2008-04-14 00:11 539136 c:\windows\system32\msftedit.dll - 2005-11-25 08:58 . 2008-06-12 14:16 161792 c:\windows\system32\msdtcuiu.dll + 2005-11-25 08:58 . 2008-06-12 14:23 161792 c:\windows\system32\msdtcuiu.dll + 2005-11-25 08:58 . 2008-06-12 14:23 956928 c:\windows\system32\msdtctm.dll - 2005-11-25 08:58 . 2008-06-12 14:16 956928 c:\windows\system32\msdtctm.dll + 2005-11-25 08:58 . 2008-06-12 14:23 428032 c:\windows\system32\msdtcprx.dll - 2005-11-25 08:58 . 2008-06-12 14:16 428032 c:\windows\system32\msdtcprx.dll + 2005-09-09 22:03 . 2008-04-14 00:11 151552 c:\windows\system32\msdart.dll - 2005-09-09 22:03 . 2004-08-04 12:00 151552 c:\windows\system32\msdart.dll - 2005-09-09 22:03 . 2004-08-04 12:00 118784 c:\windows\system32\msdadiag.dll + 2005-09-09 22:03 . 2008-04-14 00:11 118784 c:\windows\system32\msdadiag.dll + 2005-09-09 22:03 . 2008-04-14 00:11 297984 c:\windows\system32\msctf.dll - 2005-11-25 08:58 . 2004-08-04 12:00 123392 c:\windows\system32\mplay32.exe + 2005-11-25 08:58 . 2008-04-14 00:12 123392 c:\windows\system32\mplay32.exe - 2005-09-09 22:03 . 2004-08-04 12:00 240640 c:\windows\system32\mpg4dmod.dll + 2005-09-09 22:03 . 2008-04-14 00:11 240640 c:\windows\system32\mpg4dmod.dll - 2005-09-09 22:03 . 2004-08-04 12:00 216064 c:\windows\system32\moricons.dll + 2005-09-09 22:03 . 2008-04-13 16:45 216064 c:\windows\system32\moricons.dll + 2005-09-09 22:03 . 2008-04-14 00:11 153600 c:\windows\system32\modemui.dll - 2005-09-09 22:03 . 2004-08-04 12:00 153600 c:\windows\system32\modemui.dll + 2005-09-09 22:03 . 2008-04-14 00:12 143360 c:\windows\system32\mobsync.exe - 2005-09-09 22:03 . 2004-08-04 12:00 143360 c:\windows\system32\mobsync.exe - 2005-09-09 22:03 . 2004-08-04 12:00 207360 c:\windows\system32\mobsync.dll + 2005-09-09 22:03 . 2008-04-14 00:11 207360 c:\windows\system32\mobsync.dll + 2008-09-08 22:52 . 2008-04-14 00:11 106496 c:\windows\system32\mmcfxcommon.dll + 2008-09-08 22:52 . 2008-04-14 00:11 397312 c:\windows\system32\mmcex.dll + 2005-09-09 22:03 . 2008-04-14 00:11 163328 c:\windows\system32\mmcbase.dll + 2005-09-09 22:03 . 2008-04-14 00:11 586240 c:\windows\system32\mlang.dll - 2005-09-09 22:03 . 2004-08-04 12:00 586240 c:\windows\system32\mlang.dll + 2008-09-08 22:52 . 2008-04-14 00:11 184320 c:\windows\system32\microsoft.managementconsole.dll - 2005-09-09 22:03 . 2006-11-01 19:17 927504 c:\windows\system32\mfc40u.dll + 2005-09-09 22:03 . 2008-04-14 00:11 927504 c:\windows\system32\mfc40u.dll + 2005-09-09 22:03 . 2008-04-14 00:11 118272 c:\windows\system32\mdminst.dll - 2005-09-09 22:03 . 2004-08-04 12:00 118272 c:\windows\system32\mdminst.dll + 2005-09-09 22:03 . 2009-02-09 12:10 729088 c:\windows\system32\lsasrv.dll - 2005-09-09 22:03 . 2004-08-04 12:00 514560 c:\windows\system32\logonui.exe + 2005-09-09 22:03 . 2008-04-14 00:12 514560 c:\windows\system32\logonui.exe - 2005-09-09 22:03 . 2004-08-04 12:00 220672 c:\windows\system32\logon.scr + 2005-09-09 22:03 . 2008-04-14 00:12 220672 c:\windows\system32\logon.scr + 2005-09-09 22:03 . 2008-04-14 00:11 221696 c:\windows\system32\localsec.dll - 2005-09-09 22:03 . 2004-08-04 12:00 221696 c:\windows\system32\localsec.dll - 2005-09-09 22:03 . 2004-08-04 12:00 399872 c:\windows\system32\lmrt.dll + 2005-09-09 22:03 . 2008-04-14 00:11 399872 c:\windows\system32\lmrt.dll + 2005-09-09 22:03 . 2008-04-14 04:41 423936 c:\windows\system32\licdll.dll - 2005-09-09 22:03 . 2004-08-04 12:00 423936 c:\windows\system32\licdll.dll + 2005-09-09 22:03 . 2008-04-14 00:11 150528 c:\windows\system32\keymgr.dll - 2005-09-09 22:03 . 2004-08-04 12:00 150528 c:\windows\system32\keymgr.dll + 2005-09-09 22:03 . 2009-03-21 14:06 989696 c:\windows\system32\kernel32.dll + 2005-09-09 22:03 . 2008-04-14 00:11 299520 c:\windows\system32\kerberos.dll + 2005-09-09 22:03 . 2008-04-14 00:11 512000 c:\windows\system32\jscript.dll - 2005-09-09 22:03 . 2006-06-01 18:47 163840 c:\windows\system32\jgdw400.dll + 2005-09-09 22:03 . 2008-04-14 00:11 163840 c:\windows\system32\jgdw400.dll - 2009-03-13 22:38 . 2009-03-13 22:37 148888 c:\windows\system32\javaws.exe + 2009-07-05 22:01 . 2009-07-05 22:00 148888 c:\windows\system32\javaws.exe - 2009-03-13 22:38 . 2009-03-13 22:37 144792 c:\windows\system32\javaw.exe + 2009-07-05 22:01 . 2009-07-05 22:00 144792 c:\windows\system32\javaw.exe - 2009-03-13 22:38 . 2009-03-13 22:37 144792 c:\windows\system32\java.exe + 2009-07-05 22:01 . 2009-07-05 22:00 144792 c:\windows\system32\java.exe + 2005-09-09 22:03 . 2008-04-14 00:11 138240 c:\windows\system32\itss.dll + 2005-09-09 22:03 . 2008-04-14 00:11 155136 c:\windows\system32\itircl.dll - 2005-09-09 22:03 . 2005-05-27 02:04 155136 c:\windows\system32\itircl.dll - 2005-09-09 22:03 . 2004-08-04 12:00 183808 c:\windows\system32\ir50_qcx.dll + 2005-09-09 22:03 . 2008-04-14 00:11 183808 c:\windows\system32\ir50_qcx.dll + 2005-09-09 22:03 . 2008-04-14 00:11 200192 c:\windows\system32\ir50_qc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 200192 c:\windows\system32\ir50_qc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 755200 c:\windows\system32\ir50_32.dll + 2005-09-09 22:03 . 2008-04-14 00:11 755200 c:\windows\system32\ir50_32.dll + 2005-09-09 22:03 . 2008-04-14 00:11 338432 c:\windows\system32\ir41_qcx.dll - 2005-09-09 22:03 . 2004-08-04 12:00 338432 c:\windows\system32\ir41_qcx.dll - 2005-09-09 22:03 . 2004-08-04 12:00 120320 c:\windows\system32\ir41_qc.dll + 2005-09-09 22:03 . 2008-04-14 00:11 120320 c:\windows\system32\ir41_qc.dll + 2005-09-09 22:03 . 2008-04-14 00:11 384000 c:\windows\system32\ipsmsnap.dll - 2005-09-09 22:03 . 2004-08-04 12:00 384000 c:\windows\system32\ipsmsnap.dll + 2005-09-09 22:03 . 2008-04-14 00:11 183808 c:\windows\system32\ipsecsvc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 349696 c:\windows\system32\ipsecsnp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 349696 c:\windows\system32\ipsecsnp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 177152 c:\windows\system32\iprtrmgr.dll + 2005-09-09 22:03 . 2008-04-14 00:11 330752 c:\windows\system32\ippromon.dll - 2005-09-09 22:03 . 2004-08-04 12:00 330752 c:\windows\system32\ippromon.dll - 2005-09-09 22:03 . 2004-08-04 12:00 331264 c:\windows\system32\ipnathlp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 331264 c:\windows\system32\ipnathlp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 161280 c:\windows\system32\ipmontr.dll - 2005-09-09 22:03 . 2004-08-04 12:00 123392 c:\windows\system32\input.dll + 2005-09-09 22:03 . 2008-04-14 00:11 123392 c:\windows\system32\input.dll + 2005-09-09 22:03 . 2008-04-14 00:11 147456 c:\windows\system32\initpki.dll - 2005-09-09 22:03 . 2004-08-04 12:00 147456 c:\windows\system32\initpki.dll + 2005-11-25 08:59 . 2008-04-11 19:04 691712 c:\windows\system32\inetcomm.dll + 2005-11-25 08:59 . 2008-04-14 00:11 274432 c:\windows\system32\inetcfg.dll - 2005-11-25 08:59 . 2004-08-04 12:00 274432 c:\windows\system32\inetcfg.dll - 2005-09-09 22:03 . 2004-08-04 12:00 110080 c:\windows\system32\imm32.dll + 2005-09-09 22:03 . 2008-04-14 00:11 110080 c:\windows\system32\imm32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 150528 c:\windows\system32\imapi.exe + 2005-09-09 22:03 . 2008-04-14 00:11 144384 c:\windows\system32\imagehlp.dll - 2005-09-09 22:03 . 2004-08-04 12:00 144384 c:\windows\system32\imagehlp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 135680 c:\windows\system32\ifmon.dll - 2005-09-09 22:03 . 2004-08-04 12:00 135680 c:\windows\system32\ifmon.dll - 2005-09-09 22:03 . 2004-08-04 12:00 114688 c:\windows\system32\iexpress.exe + 2005-09-09 22:03 . 2008-04-14 00:12 114688 c:\windows\system32\iexpress.exe - 2005-09-09 22:03 . 2009-02-20 08:14 251904 c:\windows\system32\iepeers.dll + 2005-09-09 22:03 . 2008-04-14 00:11 251904 c:\windows\system32\iepeers.dll - 2005-09-09 22:03 . 2004-08-04 12:00 323584 c:\windows\system32\iedkcs32.dll + 2005-09-09 22:03 . 2008-04-14 00:11 323584 c:\windows\system32\iedkcs32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 216576 c:\windows\system32\ieaksie.dll + 2005-09-09 22:03 . 2008-04-14 00:11 216576 c:\windows\system32\ieaksie.dll + 2005-09-09 22:03 . 2008-04-14 00:11 143360 c:\windows\system32\ieakeng.dll + 2005-09-09 22:03 . 2008-04-14 00:11 120832 c:\windows\system32\idq.dll - 2005-09-09 22:03 . 2004-08-04 12:00 120832 c:\windows\system32\idq.dll + 2005-09-09 22:03 . 2008-04-14 00:11 254976 c:\windows\system32\icm32.dll - 2005-09-09 22:03 . 2005-06-29 01:46 254976 c:\windows\system32\icm32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 119808 c:\windows\system32\iasrad.dll + 2005-09-09 22:03 . 2008-04-14 00:11 119808 c:\windows\system32\iasrad.dll - 2005-11-25 08:58 . 2004-11-17 17:41 347136 c:\windows\system32\hypertrm.dll + 2005-11-25 08:58 . 2008-04-14 00:11 347136 c:\windows\system32\hypertrm.dll + 2005-09-09 22:03 . 2008-04-14 00:11 144896 c:\windows\system32\hotplug.dll - 2005-09-09 22:03 . 2004-08-04 12:00 144896 c:\windows\system32\hotplug.dll - 2005-09-09 22:03 . 2004-08-04 12:00 330752 c:\windows\system32\hnetwiz.dll + 2005-09-09 22:03 . 2008-04-14 00:11 330752 c:\windows\system32\hnetwiz.dll - 2005-09-09 22:03 . 2004-08-04 12:00 344064 c:\windows\system32\hnetcfg.dll + 2005-09-09 22:03 . 2008-04-14 00:11 344064 c:\windows\system32\hnetcfg.dll - 2004-08-03 22:59 . 2004-08-04 12:00 134400 c:\windows\system32\hal.dll + 2004-08-03 22:59 . 2008-04-13 18:31 134400 c:\windows\system32\HAL.DLL - 2005-09-09 22:03 . 2004-08-04 12:00 614912 c:\windows\system32\h323msp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 614912 c:\windows\system32\h323msp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 122880 c:\windows\system32\glu32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 122880 c:\windows\system32\glu32.dll + 2005-09-09 22:03 . 2008-10-23 12:36 286720 c:\windows\system32\gdi32.dll - 2005-11-25 09:03 . 2004-08-04 12:00 400384 c:\windows\system32\fxsxp32.dll + 2005-11-25 09:03 . 2008-04-14 00:11 400384 c:\windows\system32\fxsxp32.dll + 2005-11-25 09:03 . 2008-04-14 00:11 192512 c:\windows\system32\fxswzrd.dll - 2005-11-25 09:03 . 2004-08-04 12:00 192512 c:\windows\system32\fxswzrd.dll - 2005-11-25 09:03 . 2004-08-04 12:00 154112 c:\windows\system32\fxsui.dll + 2005-11-25 09:03 . 2008-04-14 00:11 154112 c:\windows\system32\fxsui.dll - 2005-11-25 09:03 . 2004-08-04 12:00 397312 c:\windows\system32\fxstiff.dll + 2005-11-25 09:03 . 2008-04-14 00:11 397312 c:\windows\system32\fxstiff.dll + 2005-11-25 09:03 . 2008-04-14 00:11 246272 c:\windows\system32\fxst30.dll - 2005-11-25 09:03 . 2004-08-04 12:00 246272 c:\windows\system32\fxst30.dll + 2005-11-25 09:03 . 2008-04-14 00:12 267776 c:\windows\system32\fxssvc.exe - 2005-11-25 09:03 . 2004-08-04 12:00 267776 c:\windows\system32\fxssvc.exe + 2005-11-25 09:03 . 2008-04-14 00:11 562176 c:\windows\system32\fxsst.dll - 2005-11-25 09:03 . 2004-08-04 12:00 562176 c:\windows\system32\fxsst.dll - 2005-11-25 09:03 . 2004-08-04 12:00 229376 c:\windows\system32\fxscover.exe + 2005-11-25 09:03 . 2008-04-14 00:12 229376 c:\windows\system32\fxscover.exe - 2005-11-25 09:03 . 2004-08-04 12:00 285184 c:\windows\system32\fxscomex.dll + 2005-11-25 09:03 . 2008-04-14 00:11 285184 c:\windows\system32\fxscomex.dll + 2005-11-25 09:03 . 2008-04-14 00:12 142848 c:\windows\system32\fxsclnt.exe + 2005-11-25 09:03 . 2008-04-14 00:11 451584 c:\windows\system32\fxsapi.dll + 2004-08-04 00:56 . 2008-04-14 00:12 193024 c:\windows\system32\fsquirt.exe - 2004-08-04 00:56 . 2004-08-04 12:00 193024 c:\windows\system32\fsquirt.exe + 2005-09-09 22:03 . 2008-04-14 00:11 382976 c:\windows\system32\fontext.dll - 2005-09-09 22:03 . 2004-08-04 12:00 382976 c:\windows\system32\fontext.dll + 2005-11-25 08:54 . 2009-07-06 02:06 172280 c:\windows\system32\FNTCACHE.DAT - 2005-11-25 08:54 . 2009-04-23 11:33 172280 c:\windows\system32\FNTCACHE.DAT + 2005-09-09 22:03 . 2008-04-14 00:11 337920 c:\windows\system32\filemgmt.dll - 2005-09-09 22:03 . 2004-08-04 12:00 337920 c:\windows\system32\filemgmt.dll + 2005-09-09 22:03 . 2008-04-14 00:11 125952 c:\windows\system32\exts.dll + 2005-09-09 22:03 . 2008-04-14 00:11 380445 c:\windows\system32\expsrv.dll + 2005-09-09 22:03 . 2008-04-14 00:12 193024 c:\windows\system32\eudcedit.exe - 2005-09-09 22:03 . 2004-08-04 12:00 193024 c:\windows\system32\eudcedit.exe + 2005-09-09 22:03 . 2008-07-07 20:26 253952 c:\windows\system32\es.dll - 2005-09-09 22:03 . 2008-07-07 20:32 253952 c:\windows\system32\es.dll + 2005-09-09 22:03 . 2008-04-14 00:11 186880 c:\windows\system32\encdec.dll - 2005-09-09 22:03 . 2004-08-04 12:00 183296 c:\windows\system32\els.dll + 2005-09-09 22:03 . 2008-04-14 00:11 183296 c:\windows\system32\els.dll + 2008-09-08 22:52 . 2008-04-14 00:11 180224 c:\windows\system32\eapphost.dll + 2008-09-08 22:52 . 2008-04-14 00:11 126976 c:\windows\system32\eappcfg.dll + 2008-09-08 22:52 . 2008-04-14 00:11 184832 c:\windows\system32\eapp3hst.dll + 2005-09-09 22:03 . 2008-04-14 00:11 205312 c:\windows\system32\dxtrans.dll - 2005-09-09 22:03 . 2009-02-20 08:14 205312 c:\windows\system32\dxtrans.dll + 2005-09-09 22:03 . 2008-04-14 00:11 357888 c:\windows\system32\dxtmsft.dll - 2005-09-09 22:03 . 2009-02-20 08:14 357888 c:\windows\system32\dxtmsft.dll - 2005-09-09 22:03 . 2006-08-22 04:05 498742 c:\windows\system32\dxmasf.dll + 2005-09-09 22:03 . 2008-04-14 00:11 498742 c:\windows\system32\dxmasf.dll - 2005-09-09 22:03 . 2004-08-04 12:00 619008 c:\windows\system32\dx7vb.dll + 2005-09-09 22:03 . 2008-04-14 00:11 619008 c:\windows\system32\dx7vb.dll - 2005-09-09 22:03 . 2004-08-04 12:00 180224 c:\windows\system32\dwwin.exe + 2005-09-09 22:03 . 2008-04-14 00:12 180224 c:\windows\system32\dwwin.exe + 2005-09-09 22:03 . 2008-04-14 00:11 304128 c:\windows\system32\duser.dll - 2005-09-09 22:03 . 2004-08-04 12:00 304128 c:\windows\system32\duser.dll - 2005-09-09 22:03 . 2004-08-04 12:00 113152 c:\windows\system32\dsuiext.dll + 2005-09-09 22:03 . 2008-04-14 00:11 113152 c:\windows\system32\dsuiext.dll + 2005-09-09 22:03 . 2008-04-13 17:37 138752 c:\windows\system32\dssenh.dll - 2005-09-09 22:03 . 2004-08-04 12:00 239104 c:\windows\system32\dsquery.dll + 2005-09-09 22:03 . 2008-04-14 00:11 239104 c:\windows\system32\dsquery.dll + 2005-09-09 22:03 . 2008-04-14 00:11 142848 c:\windows\system32\dsprop.dll - 2005-09-09 22:03 . 2004-08-04 12:00 367616 c:\windows\system32\dsound.dll + 2005-09-09 22:03 . 2008-04-14 00:11 367616 c:\windows\system32\dsound.dll + 2005-09-09 22:03 . 2008-04-14 00:11 155648 c:\windows\system32\dskquoui.dll + 2005-09-09 22:03 . 2008-04-14 00:11 181248 c:\windows\system32\dsdmo.dll + 2007-09-22 16:26 . 2008-04-13 18:46 121984 c:\windows\system32\drivers\usbvideo.sys + 2006-01-06 17:18 . 2008-04-13 18:45 143872 c:\windows\system32\drivers\usbport.sys + 2005-09-09 22:03 . 2008-04-13 18:39 384768 c:\windows\system32\drivers\update.sys + 2005-09-09 22:03 . 2008-06-20 11:08 225856 c:\windows\system32\drivers\tcpip6.sys + 2005-09-09 22:03 . 2008-06-20 11:51 361600 c:\windows\system32\drivers\tcpip.sys + 2005-09-09 22:03 . 2008-12-11 10:57 333952 c:\windows\system32\drivers\srv.sys + 2005-09-09 22:03 . 2008-05-08 14:02 203136 c:\windows\system32\drivers\rmcast.sys + 2005-11-25 08:58 . 2008-04-14 00:13 139656 c:\windows\system32\drivers\rdpwd.sys + 2005-11-25 08:58 . 2008-04-13 18:32 196224 c:\windows\system32\drivers\rdpdr.sys + 2005-09-09 22:03 . 2008-04-13 19:28 175744 c:\windows\system32\drivers\rdbss.sys + 2006-01-06 17:24 . 2008-04-13 19:19 146048 c:\windows\system32\drivers\portcls.sys + 2004-08-03 23:07 . 2008-04-13 18:36 120192 c:\windows\system32\drivers\pcmcia.sys + 2005-09-09 22:03 . 2008-04-13 19:15 574976 c:\windows\system32\drivers\ntfs.sys - 2005-09-09 22:03 . 2004-08-04 12:00 162816 c:\windows\system32\drivers\netbt.sys + 2005-09-09 22:03 . 2008-04-13 19:21 162816 c:\windows\system32\drivers\netbt.sys + 2005-09-09 22:03 . 2008-04-13 19:20 182656 c:\windows\system32\drivers\ndis.sys + 2005-09-09 22:03 . 2008-04-13 19:17 105344 c:\windows\system32\drivers\mup.sys + 2005-09-09 22:03 . 2008-10-24 11:21 455296 c:\windows\system32\drivers\mrxsmb.sys + 2005-09-09 22:03 . 2008-04-13 18:32 180608 c:\windows\system32\drivers\mrxdav.sys + 2004-08-03 23:15 . 2008-04-13 19:16 141056 c:\windows\system32\drivers\ks.sys + 2006-01-06 17:24 . 2008-04-13 18:45 172416 c:\windows\system32\drivers\kmixer.sys - 2006-01-06 17:24 . 2006-06-14 08:47 172416 c:\windows\system32\drivers\kmixer.sys + 2005-09-09 22:03 . 2008-04-13 18:57 152832 c:\windows\system32\drivers\ipnat.sys + 2004-08-03 23:00 . 2008-04-13 18:53 264832 c:\windows\system32\drivers\http.sys + 2004-10-27 15:21 . 2008-04-13 16:36 144384 c:\windows\system32\drivers\hdaudbus.sys + 2005-11-25 08:59 . 2008-04-13 18:32 129792 c:\windows\system32\drivers\fltmgr.sys + 2005-09-09 22:03 . 2008-04-13 19:14 143744 c:\windows\system32\drivers\fastfat.sys + 2005-09-09 22:03 . 2008-04-13 18:44 153344 c:\windows\system32\drivers\dmio.sys - 2005-09-09 22:03 . 2004-08-04 12:00 153344 c:\windows\system32\drivers\dmio.sys - 2005-09-09 22:03 . 2004-08-04 12:00 799744 c:\windows\system32\drivers\dmboot.sys + 2005-09-09 22:03 . 2008-04-13 18:44 799744 c:\windows\system32\drivers\dmboot.sys + 2007-09-22 16:26 . 2008-06-13 11:05 272128 c:\windows\system32\drivers\bthport.sys - 2007-09-22 16:26 . 2008-06-13 13:10 272128 c:\windows\system32\drivers\bthport.sys + 2007-09-22 16:26 . 2008-04-13 18:51 101120 c:\windows\system32\drivers\bthpan.sys + 2005-09-09 22:03 . 2008-08-14 10:04 138496 c:\windows\system32\drivers\afd.sys + 2006-01-06 17:24 . 2008-04-13 16:39 142592 c:\windows\system32\drivers\aec.sys + 2004-08-03 23:07 . 2008-04-13 18:36 187776 c:\windows\system32\drivers\acpi.sys - 2004-08-03 23:07 . 2004-08-04 12:00 187776 c:\windows\system32\drivers\acpi.sys + 2005-09-09 22:03 . 2008-04-14 00:11 116736 c:\windows\system32\dpvvox.dll - 2005-09-09 22:03 . 2004-08-04 12:00 116736 c:\windows\system32\dpvvox.dll - 2005-09-09 22:03 . 2004-08-04 12:00 212480 c:\windows\system32\dpvoice.dll + 2005-09-09 22:03 . 2008-04-14 00:11 212480 c:\windows\system32\dpvoice.dll - 2005-09-09 22:03 . 2004-08-04 12:00 375296 c:\windows\system32\dpnet.dll + 2005-09-09 22:03 . 2008-04-14 00:11 375296 c:\windows\system32\dpnet.dll - 2005-09-09 22:03 . 2004-08-04 12:00 229888 c:\windows\system32\dplayx.dll + 2005-09-09 22:03 . 2008-04-14 00:11 229888 c:\windows\system32\dplayx.dll + 2005-09-09 22:03 . 2008-04-13 21:00 103424 c:\windows\system32\dpcdll.dll + 2008-09-08 22:52 . 2008-04-14 00:11 650752 c:\windows\system32\dot3ui.dll + 2008-09-08 22:52 . 2008-04-14 00:11 132096 c:\windows\system32\dot3svc.dll + 2005-09-09 22:03 . 2008-06-20 17:46 147968 c:\windows\system32\dnsapi.dll + 2005-09-09 22:03 . 2008-04-14 00:11 104448 c:\windows\system32\dmusic.dll - 2005-09-09 22:03 . 2004-08-04 12:00 104448 c:\windows\system32\dmusic.dll - 2005-09-09 22:03 . 2004-08-04 12:00 103424 c:\windows\system32\dmsynth.dll + 2005-09-09 22:03 . 2008-04-14 00:11 103424 c:\windows\system32\dmsynth.dll - 2005-09-09 22:03 . 2004-08-04 12:00 105984 c:\windows\system32\dmstyle.dll + 2005-09-09 22:03 . 2008-04-14 00:11 105984 c:\windows\system32\dmstyle.dll + 2005-09-09 22:03 . 2008-04-14 00:11 181248 c:\windows\system32\dmime.dll |
|
|
|
|
#16 (permalink) |
|
Registered User
Join Date: Jul 2009
Posts: 14
OS: xp
|
Re: Recurring Vundo Trojan
- 2005-09-09 22:03 . 2004-08-04 12:00 181248 c:\windows\system32\dmime.dll - 2005-09-09 22:03 . 2004-08-04 12:00 200704 c:\windows\system32\dmdskmgr.dll + 2005-09-09 22:03 . 2008-04-14 00:11 200704 c:\windows\system32\dmdskmgr.dll + 2005-09-09 22:03 . 2008-04-14 00:11 285184 c:\windows\system32\dmdlgs.dll + 2005-09-09 22:03 . 2008-04-14 00:12 224768 c:\windows\system32\dmadmin.exe - 2005-09-09 22:03 . 2004-08-04 12:00 224768 c:\windows\system32\dmadmin.exe + 2009-04-19 19:11 . 2008-04-21 12:08 215552 c:\windows\system32\dllcache\wordpad.exe - 2005-11-25 08:58 . 2008-04-21 10:02 215552 c:\windows\system32\dllcache\wordpad.exe + 2005-09-09 22:03 . 2008-04-14 00:12 303616 c:\windows\system32\dllcache\wmstream.dll - 2005-09-09 22:03 . 2004-08-04 12:00 303616 c:\windows\system32\dllcache\wmstream.dll + 2005-09-09 22:03 . 2008-04-14 00:12 115200 c:\windows\system32\dllcache\wmsdmoe.dll - 2005-09-09 22:03 . 2004-08-04 12:00 115200 c:\windows\system32\dllcache\wmsdmoe.dll + 2009-04-19 19:13 . 2009-02-06 10:10 227840 c:\windows\system32\dllcache\wmiprvse.exe - 2005-11-25 08:58 . 2009-02-06 16:39 227840 c:\windows\system32\dllcache\wmiprvse.exe + 2009-04-19 19:13 . 2009-02-09 12:10 453120 c:\windows\system32\dllcache\wmiprvsd.dll - 2005-11-25 08:58 . 2009-02-09 10:20 453120 c:\windows\system32\dllcache\wmiprvsd.dll + 2008-04-21 06:44 . 2009-04-29 04:46 666624 c:\windows\system32\dllcache\wininet.dll + 2008-12-16 12:30 . 2008-12-16 12:30 354304 c:\windows\system32\dllcache\winhttp.dll + 2008-06-26 08:15 . 2009-04-29 04:46 620032 c:\windows\system32\dllcache\urlmon.dll + 2008-06-20 11:08 . 2008-06-20 11:08 225856 c:\windows\system32\dllcache\tcpip6.sys + 2008-06-20 11:51 . 2008-06-20 11:51 361600 c:\windows\system32\dllcache\tcpip.sys - 2005-09-09 22:03 . 2008-10-03 10:15 247326 c:\windows\system32\dllcache\strmdll.dll + 2005-09-09 22:03 . 2008-10-03 10:02 247326 c:\windows\system32\dllcache\strmdll.dll + 2008-10-17 17:51 . 2008-12-11 10:57 333952 c:\windows\system32\dllcache\srv.sys + 2005-09-09 22:03 . 2008-04-14 00:12 152064 c:\windows\system32\dllcache\shmedia.dll - 2005-09-09 22:03 . 2009-02-06 17:14 110592 c:\windows\system32\dllcache\services.exe + 2009-04-19 19:13 . 2009-02-06 11:11 110592 c:\windows\system32\dllcache\services.exe + 2008-12-05 06:54 . 2008-12-05 06:54 144896 c:\windows\system32\dllcache\schannel.dll - 2005-09-09 22:03 . 2008-12-05 07:12 144896 c:\windows\system32\dllcache\schannel.dll + 2009-04-19 19:13 . 2009-02-09 12:10 401408 c:\windows\system32\dllcache\rpcss.dll + 2009-04-15 14:51 . 2009-04-15 14:51 585216 c:\windows\system32\dllcache\rpcrt4.dll + 2008-06-12 18:56 . 2008-05-08 14:02 203136 c:\windows\system32\dllcache\rmcast.sys + 2009-04-19 19:13 . 2009-03-06 14:22 284160 c:\windows\system32\dllcache\pdh.dll - 2005-09-09 22:03 . 2009-02-09 10:20 714752 c:\windows\system32\dllcache\ntdll.dll + 2009-04-19 19:13 . 2009-02-09 12:10 714752 c:\windows\system32\dllcache\ntdll.dll + 2005-11-25 08:59 . 2008-04-14 00:12 364544 c:\windows\system32\dllcache\npdsplay.dll - 2005-11-25 08:59 . 2005-11-29 16:27 364544 c:\windows\system32\dllcache\npdsplay.dll - 2005-11-25 08:59 . 2004-08-04 12:00 226816 c:\windows\system32\dllcache\npdrmv2.dll + 2005-11-25 08:59 . 2008-04-14 00:12 226816 c:\windows\system32\dllcache\npdrmv2.dll + 2008-10-24 22:04 . 2008-10-15 16:34 337408 c:\windows\system32\dllcache\netapi32.dll - 2005-09-09 22:03 . 2008-06-20 17:41 245248 c:\windows\system32\dllcache\mswsock.dll + 2008-06-20 17:46 . 2008-06-20 17:46 245248 c:\windows\system32\dllcache\mswsock.dll - 2005-11-25 08:58 . 2008-06-12 14:16 161792 c:\windows\system32\dllcache\msdtcuiu.dll + 2008-06-12 14:23 . 2008-06-12 14:23 161792 c:\windows\system32\dllcache\msdtcuiu.dll - 2005-11-25 08:58 . 2008-06-12 14:16 956928 c:\windows\system32\dllcache\msdtctm.dll + 2008-06-12 14:23 . 2008-06-12 14:23 956928 c:\windows\system32\dllcache\msdtctm.dll + 2008-06-12 14:23 . 2008-06-12 14:23 428032 c:\windows\system32\dllcache\msdtcprx.dll - 2005-11-25 08:58 . 2008-06-12 14:16 428032 c:\windows\system32\dllcache\msdtcprx.dll - 2005-11-25 08:59 . 2008-05-01 14:30 331776 c:\windows\system32\dllcache\msadce.dll + 2005-11-25 08:59 . 2008-05-01 14:33 331776 c:\windows\system32\dllcache\msadce.dll + 2008-11-12 17:35 . 2008-10-24 11:21 455296 c:\windows\system32\dllcache\mrxsmb.sys + 2005-11-25 08:58 . 2008-04-14 00:12 123392 c:\windows\system32\dllcache\mplay32.exe - 2005-11-25 08:58 . 2004-08-04 12:00 123392 c:\windows\system32\dllcache\mplay32.exe - 2005-09-09 22:03 . 2004-08-04 12:00 240640 c:\windows\system32\dllcache\mpg4dmod.dll + 2005-09-09 22:03 . 2008-04-14 00:11 240640 c:\windows\system32\dllcache\mpg4dmod.dll + 2009-04-19 19:13 . 2009-02-09 12:10 729088 c:\windows\system32\dllcache\lsasrv.dll + 2009-05-07 15:32 . 2009-05-07 15:32 345600 c:\windows\system32\dllcache\localspl.dll + 2009-03-21 14:06 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\kernel32.dll + 2008-08-13 23:28 . 2008-04-11 19:04 691712 c:\windows\system32\dllcache\inetcomm.dll + 2008-10-23 12:36 . 2008-10-23 12:36 286720 c:\windows\system32\dllcache\gdi32.dll + 2009-04-19 19:13 . 2009-02-09 12:10 473600 c:\windows\system32\dllcache\fastprox.dll - 2005-09-09 22:03 . 2008-07-07 20:32 253952 c:\windows\system32\dllcache\es.dll + 2008-07-07 20:26 . 2008-07-07 20:26 253952 c:\windows\system32\dllcache\es.dll + 2005-09-09 22:03 . 2008-04-14 00:11 498742 c:\windows\system32\dllcache\dxmasf.dll - 2005-09-09 22:03 . 2006-08-22 04:05 498742 c:\windows\system32\dllcache\dxmasf.dll + 2008-06-20 17:46 . 2008-06-20 17:46 147968 c:\windows\system32\dllcache\dnsapi.dll - 2007-09-22 16:26 . 2008-06-13 13:10 272128 c:\windows\system32\dllcache\bthport.sys + 2008-06-12 18:56 . 2008-06-13 11:05 272128 c:\windows\system32\dllcache\bthport.sys + 2008-06-20 11:40 . 2008-08-14 10:04 138496 c:\windows\system32\dllcache\afd.sys + 2009-04-19 19:13 . 2009-02-09 12:10 617472 c:\windows\system32\dllcache\advapi32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 163840 c:\windows\system32\diskpart.exe + 2005-09-09 22:03 . 2008-04-14 00:12 163840 c:\windows\system32\diskpart.exe + 2005-09-09 22:03 . 2008-04-14 00:11 181760 c:\windows\system32\dinput8.dll - 2005-09-09 22:03 . 2004-08-04 12:00 181760 c:\windows\system32\dinput8.dll + 2005-09-09 22:03 . 2008-04-14 00:11 158720 c:\windows\system32\dinput.dll + 2005-09-09 22:03 . 2008-04-14 00:11 379904 c:\windows\system32\dhcpmon.dll + 2005-09-09 22:03 . 2008-04-14 00:11 126976 c:\windows\system32\dhcpcsvc.dll + 2005-09-09 22:03 . 2008-04-14 00:11 111104 c:\windows\system32\dgnet.dll - 2005-09-09 22:03 . 2004-08-04 12:00 111104 c:\windows\system32\dgnet.dll + 2005-09-09 22:03 . 2008-04-14 00:11 124416 c:\windows\system32\dfrgui.dll + 2005-09-09 22:03 . 2008-04-14 00:12 105472 c:\windows\system32\dfrgntfs.exe - 2005-09-09 22:03 . 2004-08-04 12:00 282624 c:\windows\system32\devmgr.dll + 2005-09-09 22:03 . 2008-04-14 00:11 282624 c:\windows\system32\devmgr.dll + 2005-09-09 22:03 . 2008-04-14 00:11 279552 c:\windows\system32\ddraw.dll - 2005-09-09 22:03 . 2004-08-04 12:00 110592 c:\windows\system32\dbnetlib.dll + 2005-09-09 22:03 . 2008-04-14 00:11 110592 c:\windows\system32\dbnetlib.dll + 2005-09-09 22:03 . 2008-04-14 00:11 640000 c:\windows\system32\dbghelp.dll - 2005-09-09 22:03 . 2004-08-04 12:00 640000 c:\windows\system32\dbghelp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 165376 c:\windows\system32\datime.dll + 2005-09-09 22:03 . 2008-04-14 00:11 824320 c:\windows\system32\d3dim700.dll - 2005-09-09 22:03 . 2004-08-04 12:00 326656 c:\windows\system32\cscui.dll + 2005-09-09 22:03 . 2008-04-14 00:11 326656 c:\windows\system32\cscui.dll + 2005-09-09 22:03 . 2008-04-14 00:12 139264 c:\windows\system32\cscript.exe + 2005-09-09 22:03 . 2008-04-14 00:11 101888 c:\windows\system32\cscdll.dll - 2005-09-09 22:03 . 2004-08-04 12:00 101888 c:\windows\system32\cscdll.dll + 2005-09-09 22:03 . 2008-04-14 00:11 512512 c:\windows\system32\cryptui.dll - 2005-09-09 22:03 . 2004-08-04 12:00 512512 c:\windows\system32\cryptui.dll + 2005-09-09 22:03 . 2008-04-14 00:11 599040 c:\windows\system32\crypt32.dll + 2005-09-09 22:03 . 2008-04-14 00:11 163840 c:\windows\system32\credui.dll - 2005-09-09 22:03 . 2004-08-04 12:00 163840 c:\windows\system32\credui.dll + 2005-09-09 22:03 . 2008-04-14 00:11 357888 c:\windows\system32\confmsp.dll + 2005-11-25 08:58 . 2008-04-14 00:11 539648 c:\windows\system32\comuid.dll + 2005-11-25 08:58 . 2008-04-14 00:11 167424 c:\windows\system32\comsnap.dll - 2005-09-09 22:03 . 2004-08-04 12:00 792064 c:\windows\system32\comres.dll + 2005-09-09 22:03 . 2008-04-14 00:11 792064 c:\windows\system32\comres.dll - 2005-09-09 22:03 . 2004-08-04 12:00 229376 c:\windows\system32\compstui.dll + 2005-09-09 22:03 . 2008-04-14 00:11 229376 c:\windows\system32\compstui.dll + 2005-09-09 22:03 . 2008-04-14 00:11 252928 c:\windows\system32\compatui.dll - 2005-09-09 22:03 . 2004-08-04 12:00 252928 c:\windows\system32\compatUI.dll - 2005-09-09 22:03 . 2004-08-04 12:00 276992 c:\windows\system32\comdlg32.dll + 2005-09-09 22:03 . 2008-04-14 00:11 276992 c:\windows\system32\comdlg32.dll + 2005-09-09 22:03 . 2008-04-14 00:11 617472 c:\windows\system32\comctl32.dll - 2005-09-09 22:03 . 2006-08-25 15:45 617472 c:\windows\system32\comctl32.dll - 2005-11-25 08:58 . 2005-07-26 04:39 195072 c:\windows\system32\Com\comadmin.dll + 2005-11-25 08:58 . 2008-04-14 00:11 195072 c:\windows\system32\Com\comadmin.dll - 2005-11-25 08:58 . 2004-08-04 12:00 185344 c:\windows\system32\cmprops.dll + 2005-11-25 08:58 . 2008-04-14 00:11 185344 c:\windows\system32\cmprops.dll + 2005-09-09 22:03 . 2008-04-14 00:11 344064 c:\windows\system32\cmdial32.dll + 2005-09-09 22:03 . 2008-04-14 00:12 389120 c:\windows\system32\cmd.exe - 2005-11-25 08:58 . 2004-08-04 12:00 102912 c:\windows\system32\clipbrd.exe + 2005-11-25 08:58 . 2008-04-14 00:12 102912 c:\windows\system32\clipbrd.exe - 2005-11-25 08:58 . 2005-07-26 04:39 498688 c:\windows\system32\clbcatq.dll + 2005-11-25 08:58 . 2008-04-14 00:11 498688 c:\windows\system32\clbcatq.dll + 2005-11-25 08:58 . 2008-04-14 00:11 110592 c:\windows\system32\clbcatex.dll + 2005-09-09 22:03 . 2008-04-14 00:11 148480 c:\windows\system32\cic.dll + 2005-09-09 22:03 . 2008-04-14 00:11 457728 c:\windows\system32\certmgr.dll - 2005-09-09 22:03 . 2004-08-04 12:00 457728 c:\windows\system32\certmgr.dll - 2005-09-09 22:03 . 2004-08-04 12:00 194560 c:\windows\system32\certcli.dll + 2005-09-09 22:03 . 2008-04-14 00:11 194560 c:\windows\system32\certcli.dll - 2005-09-09 22:03 . 2009-02-20 08:14 151040 c:\windows\system32\cdfview.dll + 2005-09-09 22:03 . 2008-04-14 00:11 151040 c:\windows\system32\cdfview.dll + 2005-11-25 08:58 . 2008-04-14 00:11 625664 c:\windows\system32\catsrvut.dll + 2005-11-25 08:58 . 2008-04-14 00:11 226304 c:\windows\system32\catsrv.dll + 2005-09-09 22:03 . 2008-04-14 00:11 150016 c:\windows\system32\capesnpn.dll + 2008-09-08 22:53 . 2008-04-14 00:12 409088 c:\windows\system32\bits\qmgr.dll + 2008-09-08 22:51 . 2008-04-14 00:11 233472 c:\windows\system32\azroles.dll + 2005-09-09 22:03 . 2008-04-14 00:12 580608 c:\windows\system32\autofmt.exe - 2005-09-09 22:03 . 2004-08-04 12:00 580608 c:\windows\system32\autofmt.exe + 2005-09-09 22:03 . 2008-04-14 00:12 602624 c:\windows\system32\autoconv.exe - 2005-09-09 22:03 . 2004-08-04 12:00 602624 c:\windows\system32\autoconv.exe + 2005-09-09 22:03 . 2008-04-14 00:12 588800 c:\windows\system32\autochk.exe - 2005-09-09 22:03 . 2004-08-04 12:00 588800 c:\windows\system32\autochk.exe + 2005-09-09 22:03 . 2008-04-14 00:09 285696 c:\windows\system32\atmfd.dll - 2005-09-09 22:03 . 2004-08-04 12:00 285696 c:\windows\system32\atmfd.dll + 2007-09-22 16:26 . 2008-04-14 00:11 516768 c:\windows\system32\ativvaxx.dll - 2007-09-22 16:26 . 2004-08-03 23:56 516768 c:\windows\system32\ativvaxx.dll - 2007-09-22 16:26 . 2004-08-03 23:56 870784 c:\windows\system32\ati3d1ag.dll + 2007-09-22 16:26 . 2008-04-14 00:11 870784 c:\windows\system32\ati3d1ag.dll + 2007-09-22 16:26 . 2008-04-14 00:11 201728 c:\windows\system32\ati2dvag.dll - 2007-09-22 16:26 . 2004-08-03 23:56 201728 c:\windows\system32\ati2dvag.dll - 2007-09-22 16:26 . 2004-08-03 23:56 377984 c:\windows\system32\ati2dvaa.dll + 2007-09-22 16:26 . 2008-04-14 00:11 377984 c:\windows\system32\ati2dvaa.dll + 2007-09-22 16:26 . 2008-04-14 00:11 229376 c:\windows\system32\ati2cqag.dll - 2007-09-22 16:26 . 2004-08-03 23:56 229376 c:\windows\system32\ati2cqag.dll + 2005-09-09 22:03 . 2008-04-14 00:11 125952 c:\windows\system32\apphelp.dll + 2005-09-09 22:03 . 2009-02-09 12:10 617472 c:\windows\system32\advapi32.dll - 2005-09-09 22:03 . 2004-08-04 12:00 263680 c:\windows\system32\adsnt.dll + 2005-09-09 22:03 . 2008-04-14 00:11 263680 c:\windows\system32\adsnt.dll + 2005-09-09 22:03 . 2008-04-14 00:11 143360 c:\windows\system32\adsldpc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 143360 c:\windows\system32\adsldpc.dll - 2005-09-09 22:03 . 2004-08-04 12:00 175616 c:\windows\system32\adsldp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 175616 c:\windows\system32\adsldp.dll + 2005-09-09 22:03 . 2008-04-14 00:11 193536 c:\windows\system32\activeds.dll + 2005-09-09 22:03 . 2008-04-14 00:11 115712 c:\windows\system32\aclui.dll + 2005-11-25 08:58 . 2008-04-14 00:12 184320 c:\windows\system32\accwiz.exe + 2008-09-08 22:51 . 2008-04-14 00:11 136192 c:\windows\system32\aaclient.dll - 2005-09-09 22:03 . 2006-08-16 11:58 100352 c:\windows\system32\6to4svc.dll + 2005-09-09 22:03 . 2008-04-14 00:11 100352 c:\windows\system32\6to4svc.dll - 2005-11-25 08:54 . 2004-08-04 12:00 146432 c:\windows\system\WINSPOOL.DRV + 2005-11-25 08:54 . 2008-04-14 00:12 146432 c:\windows\system\winspool.drv + 2005-11-25 08:59 . 2008-04-14 00:12 726078 c:\windows\srchasst\srchui.dll + 2008-09-08 22:53 . 2008-04-13 17:30 180224 c:\windows\ServicePackFiles\ServicePackCache\i386\msgslang.dll + 2008-09-08 22:54 . 2008-04-14 00:12 338432 c:\windows\ServicePackFiles\i386\zipfldr.dll + 2008-09-08 22:54 . 2008-04-14 00:12 116224 c:\windows\ServicePackFiles\i386\xrxwiadr.dll + 2008-09-08 22:54 . 2008-04-13 17:39 689152 c:\windows\ServicePackFiles\i386\xpsp3res.dll + 2008-09-08 22:54 . 2008-04-13 17:39 187392 c:\windows\ServicePackFiles\i386\xpsp1res.dll + 2008-09-08 22:54 . 2008-04-13 17:39 438784 c:\windows\ServicePackFiles\i386\xpob2res.dll + 2008-09-08 22:54 . 2008-04-13 18:53 558080 c:\windows\ServicePackFiles\i386\xpnetdg.exe + 2008-09-08 22:54 . 2008-04-14 00:12 129024 c:\windows\ServicePackFiles\i386\xmlprov.dll + 2008-09-08 22:54 . 2008-04-14 00:12 121856 c:\windows\ServicePackFiles\i386\xmllite.dll + 2008-09-08 22:54 . 2004-08-04 12:00 174200 c:\windows\ServicePackFiles\i386\xenroll.dll + 2008-09-08 22:54 . 2008-04-14 00:12 483840 c:\windows\ServicePackFiles\i386\wzcsvc.dll + 2008-09-08 22:54 . 2008-04-14 00:12 383488 c:\windows\ServicePackFiles\i386\wzcdlg.dll + 2008-09-08 22:54 . 2008-04-14 00:12 120320 c:\windows\ServicePackFiles\i386\wuweb.dll + 2008-09-08 22:54 . 2008-04-14 00:12 112640 c:\windows\ServicePackFiles\i386\wucltui.dll + 2008-09-08 22:54 . 2008-04-14 00:12 183296 c:\windows\ServicePackFiles\i386\wuaueng1.dll + 2008-09-08 22:54 . 2008-04-14 00:12 165888 c:\windows\ServicePackFiles\i386\wuauclt1.exe + 2008-09-08 22:54 . 2008-04-14 00:12 111104 c:\windows\ServicePackFiles\i386\wuauclt.exe + 2008-09-08 22:54 . 2008-04-14 00:12 430592 c:\windows\ServicePackFiles\i386\wuapi.dll + 2008-09-08 22:54 . 2008-04-14 00:12 108032 c:\windows\ServicePackFiles\i386\wshbth.dll + 2008-09-08 22:54 . 2008-04-14 00:12 155648 c:\windows\ServicePackFiles\i386\wscript.exe + 2008-09-08 22:54 . 2008-04-14 00:12 264192 c:\windows\ServicePackFiles\i386\wow32.dll + 2008-09-08 22:54 . 2008-04-14 00:12 214528 c:\windows\ServicePackFiles\i386\wordpad.exe + 2008-09-08 22:54 . 2008-04-14 00:12 276992 c:\windows\ServicePackFiles\i386\wmphoto.dll + 2008-09-08 22:54 . 2008-04-14 00:12 325632 c:\windows\ServicePackFiles\i386\wmm2fxb.dll + 2008-09-08 22:54 . 2008-04-14 00:12 502272 c:\windows\ServicePackFiles\i386\wmm2fxa.dll + 2008-09-08 22:54 . 2008-04-14 00:12 402432 c:\windows\ServicePackFiles\i386\wmm2filt.dll + 2008-09-08 22:54 . 2008-04-14 00:12 167936 c:\windows\ServicePackFiles\i386\wmm2ae.dll + 2008-09-08 22:54 . 2008-04-14 00:12 144896 c:\windows\ServicePackFiles\i386\wmisvc.dll + 2008-09-08 22:54 . 2008-04-14 00:12 218112 c:\windows\ServicePackFiles\i386\wmiprvse.exe + 2008-09-08 22:54 . 2008-04-14 00:12 437248 c:\windows\ServicePackFiles\i386\wmiprvsd.dll + 2008-09-08 22:54 . 2008-04-14 00:12 144896 c:\windows\ServicePackFiles\i386\wmiprov.dll + 2008-09-08 22:54 . 2008-04-14 00:12 132096 c:\windows\ServicePackFiles\i386\wmipdskq.dll + 2008-09-08 22:54 . 2008-04-14 00:12 156672 c:\windows\ServicePackFiles\i386\wmipcima.dll + 2008-09-08 22:54 . 2008-04-14 00:12 140800 c:\windows\ServicePackFiles\i386\wmidcprv.dll + 2008-09-08 22:54 . 2008-04-14 00:12 126464 c:\windows\ServicePackFiles\i386\wmiapsrv.exe + 2008-09-08 22:54 . 2008-04-14 00:12 196608 c:\windows\ServicePackFiles\i386\wmiadap.exe + 2008-09-08 22:54 . 2004-08-03 21:31 154624 c:\windows\ServicePackFiles\i386\wlluc48.sys + 2008-09-08 22:54 . 2008-04-14 00:12 172032 c:\windows\ServicePackFiles\i386\wldap32.dll + 2008-09-08 22:54 . 2008-04-14 00:12 132096 c:\windows\ServicePackFiles\i386\wkssvc.dll + 2008-09-08 22:54 . 2008-04-14 00:12 176640 c:\windows\ServicePackFiles\i386\wintrust.dll + 2008-09-08 22:54 . 2008-04-14 00:12 293376 c:\windows\ServicePackFiles\i386\winsrv.dll + 2008-09-08 22:54 . 2008-04-14 00:12 146432 c:\windows\ServicePackFiles\i386\winspool.drv + 2008-09-08 22:54 . 2008-04-14 00:11 756224 c:\windows\ServicePackFiles\i386\winntbbu.dll + 2008-09-08 22:54 . 2008-04-14 00:12 176128 c:\windows\ServicePackFiles\i386\winmm.dll + 2008-09-08 22:54 . 2008-04-14 00:12 507904 c:\windows\ServicePackFiles\i386\winlogon.exe + 2008-09-08 22:54 . 2008-04-14 00:12 666112 c:\windows\ServicePackFiles\i386\wininet.dll + 2008-09-08 22:54 . 2008-04-14 00:12 354304 c:\windows\ServicePackFiles\i386\winhttp.dll + 2008-09-08 22:54 . 2008-04-14 00:12 283648 c:\windows\ServicePackFiles\i386\winhlp32.exe + 2008-09-08 22:54 . 2008-04-14 00:12 102400 c:\windows\ServicePackFiles\i386\win32spl.dll + 2008-09-08 22:54 . 2008-04-14 00:12 346112 c:\windows\ServicePackFiles\i386\wicext.dll + 2008-09-08 22:54 . 2008-04-14 00:12 712704 c:\windows\ServicePackFiles\i386\wic.dll + 2008-09-08 22:54 . 2008-04-14 00:12 111104 c:\windows\ServicePackFiles\i386\wiavideo.dll + 2008-09-08 22:54 . 2008-04-14 00:12 589312 c:\windows\ServicePackFiles\i386\wiashext.dll + 2008-09-08 22:54 . 2008-04-14 00:12 333824 c:\windows\ServicePackFiles\i386\wiaservc.dll + 2008-09-08 22:54 . 2008-04-14 00:12 124416 c:\windows\ServicePackFiles\i386\wiadss.dll + 2008-09-08 22:54 . 2008-04-14 00:12 463360 c:\windows\ServicePackFiles\i386\wiadefui.dll + 2008-09-08 22:54 . 2008-04-14 00:12 433664 c:\windows\ServicePackFiles\i386\wiaacmgr.exe + 2008-09-08 22:54 . 2008-04-14 00:12 135680 c:\windows\ServicePackFiles\i386\webvw.dll + 2008-09-08 22:54 . 2008-04-14 00:12 276480 c:\windows\ServicePackFiles\i386\webcheck.dll + 2008-09-08 22:54 . 2008-04-14 00:12 197120 c:\windows\ServicePackFiles\i386\wbemupgd.dll + 2008-09-08 22:54 . 2008-04-14 00:12 116224 c:\windows\ServicePackFiles\i386\wbemtest.exe + 2008-09-08 22:54 . 2008-04-14 00:12 273920 c:\windows\ServicePackFiles\i386\wbemess.dll + 2008-09-08 22:54 . 2008-04-14 00:12 178176 c:\windows\ServicePackFiles\i386\wbemdisp.dll + 2008-09-08 22:54 . 2008-04-14 00:12 531456 c:\windows\ServicePackFiles\i386\wbemcore.dll + 2008-09-08 22:54 . 2008-04-14 00:12 214528 c:\windows\ServicePackFiles\i386\wbemcomn.dll + 2008-09-08 22:54 . 2008-04-14 00:12 196608 c:\windows\ServicePackFiles\i386\wbemcntl.dll + 2008-09-08 22:54 . 2008-04-14 00:12 215552 c:\windows\ServicePackFiles\i386\wavemsp.dll + 2008-09-08 22:54 . 2008-04-13 16:21 249856 c:\windows\ServicePackFiles\i386\wab32res.dll + 2008-09-08 22:54 . 2008-04-14 00:12 510976 c:\windows\ServicePackFiles\i386\wab32.dll + 2008-09-08 22:54 . 2008-04-14 00:12 483840 c:\windows\ServicePackFiles\i386\w95upgnt.dll + 2008-09-08 22:54 . 2008-04-14 00:12 175104 c:\windows\ServicePackFiles\i386\w32time.dll + 2008-09-08 22:54 . 2008-04-14 00:12 289792 c:\windows\ServicePackFiles\i386\vssvc.exe + 2008-09-08 22:54 . 2008-04-14 00:12 430592 c:\windows\ServicePackFiles\i386\vssapi.dll + 2008-09-08 22:54 . 2008-04-14 00:12 131584 c:\windows\ServicePackFiles\i386\viewprov.dll + 2008-09-08 22:53 . 2008-04-14 00:12 851968 c:\windows\ServicePackFiles\i386\vgx.dll + 2008-09-08 22:53 . 2008-04-14 00:12 434176 c:\windows\ServicePackFiles\i386\vbscript.dll + 2008-09-08 22:53 . 2008-04-14 00:12 218624 c:\windows\ServicePackFiles\i386\uxtheme.dll + 2008-09-08 22:53 . 2008-04-14 00:12 406016 c:\windows\ServicePackFiles\i386\usp10.dll + 2008-09-08 22:53 . 2008-04-14 00:12 727040 c:\windows\ServicePackFiles\i386\userenv.dll + 2008-09-08 22:53 . 2008-04-14 00:12 578560 c:\windows\ServicePackFiles\i386\user32.dll + 2008-09-08 22:53 . 2008-04-13 18:46 121984 c:\windows\ServicePackFiles\i386\usbvideo.sys + 2008-09-08 22:53 . 2008-04-13 18:45 143872 c:\windows\ServicePackFiles\i386\usbport.sys + 2008-09-08 22:53 . 2008-04-14 00:12 619520 c:\windows\ServicePackFiles\i386\urlmon.dll + 2008-09-08 22:53 . 2008-04-14 00:12 239616 c:\windows\ServicePackFiles\i386\upnpui.dll |