+ 2006-10-19 02:03:58 100,864 ----a-w I:\WINDOWS\system32\logagent.exe
+ 2004-11-19 03:13:02 36,864 ----a-w I:\WINDOWS\system32\MCMM___Q.DLL
+ 2006-10-19 03:47:14 212,992 ------w I:\WINDOWS\system32\MFPLAT.dll
+ 2004-11-19 03:13:02 23,552 ----a-w I:\WINDOWS\system32\MGDI32_Q.DLL
+ 2004-11-19 03:13:02 9,728 ----a-w I:\WINDOWS\system32\MICM___Q.DLL
+ 2004-11-19 03:13:02 13,824 ----a-w I:\WINDOWS\system32\MIMF32_Q.DLL
+ 2004-11-19 03:13:02 49,152 ----a-w I:\WINDOWS\system32\MINFIN_Q.EXE
+ 2004-12-06 08:57:38 77,824 ----a-w I:\WINDOWS\system32\MLMON__Q.DLL
+ 2004-11-19 03:13:02 18,848 ----a-w I:\WINDOWS\system32\MLPTDR_Q.SYS
+ 2006-10-19 03:47:14 259,072 ------w I:\WINDOWS\system32\MP43DECD.dll
- 2004-08-04 12:00:00 310,272 ----a-w I:\WINDOWS\system32\mp43dmod.dll
+ 2006-10-19 03:47:14 4,096 ----a-w I:\WINDOWS\system32\MP43DMOD.dll
+ 2006-10-19 03:47:14 317,440 ------w I:\WINDOWS\system32\MP4SDECD.dll
- 2004-08-04 12:00:00 384,512 ----a-w I:\WINDOWS\system32\mp4sdmod.dll
+ 2006-10-19 03:47:14 4,096 ----a-w I:\WINDOWS\system32\MP4SDMOD.dll
+ 2006-10-19 03:47:14 259,072 ------w I:\WINDOWS\system32\MPG4DECD.dll
- 2004-08-04 12:00:00 240,640 ----a-w I:\WINDOWS\system32\mpg4dmod.dll
+ 2006-10-19 03:47:14 4,096 ----a-w I:\WINDOWS\system32\MPG4DMOD.dll
+ 2006-10-02 21:28:42 312,128 ------w I:\WINDOWS\system32\msdelta.dll
- 2004-08-04 12:00:00 259,072 ----a-w I:\WINDOWS\system32\msnetobj.dll
+ 2006-10-19 03:47:16 179,712 ----a-w I:\WINDOWS\system32\msnetobj.dll
- 2004-08-04 12:00:00 52,224 ----a-w I:\WINDOWS\system32\mspmsnsv.dll
+ 2006-10-19 03:47:16 27,136 ----a-w I:\WINDOWS\system32\mspmsnsv.dll
- 2004-08-04 12:00:00 201,728 ----a-w I:\WINDOWS\system32\mspmsp.dll
+ 2006-10-19 03:47:16 175,616 ----a-w I:\WINDOWS\system32\mspmsp.dll
+ 2004-11-19 03:13:02 51,200 ----a-w I:\WINDOWS\system32\MSPOOL_Q.DLL
- 2004-08-04 12:00:00 356,352 ----a-w I:\WINDOWS\system32\msscp.dll
+ 2006-10-19 03:47:16 414,208 ----a-w I:\WINDOWS\system32\msscp.dll
+ 2004-11-19 03:13:04 1,490,944 ----a-w I:\WINDOWS\system32\MSTMON_Q.DLL
+ 2004-11-22 03:42:38 163,840 ----a-w I:\WINDOWS\system32\MSTMON_Q.EXE
- 2004-08-04 12:00:00 245,760 ----a-w I:\WINDOWS\system32\mswmdm.dll
+ 2006-10-19 03:47:16 321,536 ----a-w I:\WINDOWS\system32\mswmdm.dll
+ 2000-10-20 06:05:42 25,088 ----a-w I:\WINDOWS\system32\msxml3a.dll
+ 2004-11-19 03:13:06 19,456 ----a-w I:\WINDOWS\system32\MTAG32_Q.DLL
+ 2004-11-19 03:13:06 147,456 ----a-w I:\WINDOWS\system32\MUINST_Q.EXE
- 2007-08-30 22:32:00 62,344 ----a-w I:\WINDOWS\system32\perfc009.dat
+ 2007-11-28 22:26:18 62,344 ----a-w I:\WINDOWS\system32\perfc009.dat
- 2007-08-30 22:32:00 401,064 ----a-w I:\WINDOWS\system32\perfh009.dat
+ 2007-11-28 22:26:18 401,064 ----a-w I:\WINDOWS\system32\perfh009.dat
+ 2006-10-19 03:47:18 284,160 ------w I:\WINDOWS\system32\PortableDeviceApi.dll
+ 2006-10-19 03:47:18 101,888 ------w I:\WINDOWS\system32\PortableDeviceClassExtension.dll
+ 2006-10-19 03:47:18 166,912 ------w I:\WINDOWS\system32\PortableDeviceTypes.dll
+ 2006-10-19 03:47:18 132,096 ------w I:\WINDOWS\system32\PortableDeviceWiaCompat.dll
+ 2006-10-19 03:47:18 199,168 ------w I:\WINDOWS\system32\PortableDeviceWMDRM.dll
- 2004-08-04 12:00:00 237,568 ----a-w I:\WINDOWS\system32\qasf.dll
+ 2006-10-19 03:47:18 211,456 ----a-w I:\WINDOWS\system32\qasf.dll
+ 2007-11-27 04:27:11 49,056 ----a-w I:\WINDOWS\system32\Restore\rstrlog.dat
- 2006-12-10 20:10:02 14,640 ------w I:\WINDOWS\system32\spmsg.dll
+ 2006-09-25 23:58:48 14,640 ------w I:\WINDOWS\system32\spmsg.dll
+ 2004-11-19 03:13:02 36,864 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MCMM___Q.DLL
+ 2004-11-19 03:13:02 65,536 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MDDM32_Q.DLL
+ 2004-11-19 03:13:02 118,784 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MDDMUI_Q.DLL
+ 2004-11-19 03:13:02 23,552 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MGDI32_Q.DLL
+ 2004-11-19 03:13:02 9,728 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MICM___Q.DLL
+ 2004-11-19 03:13:02 13,824 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MIMF32_Q.DLL
+ 2004-11-19 03:13:02 34,816 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MIMFN5_Q.DLL
+ 2004-11-19 03:13:02 10,240 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MIMFPR_Q.DLL
+ 2004-11-19 03:13:02 126,976 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MLTSRV_Q.DLL
+ 2004-11-19 03:13:02 28,672 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MNT5UI_Q.DLL
+ 2004-11-19 03:13:02 40,960 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MQDPRT_Q.DLL
+ 2004-11-19 03:13:02 77,824 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MSD32__Q.DLL
+ 2004-11-19 03:13:02 32,768 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MSDIMF_Q.DLL
+ 2004-11-22 03:43:04 151,552 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MSDMLT_Q.DLL
+ 2004-11-19 03:13:02 40,960 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MSPL32_Q.EXE
+ 2004-11-19 03:13:02 51,200 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MSPOOL_Q.DLL
+ 2004-11-19 03:13:02 131,072 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MSR32__Q.DLL
+ 2004-11-19 03:13:06 696,320 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MSUMLT_Q.DLL
+ 2004-11-19 03:13:06 19,456 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MTAG32_Q.DLL
+ 2004-11-19 03:13:06 147,456 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\3\MUINST_Q.EXE
+ 2004-11-19 03:13:02 36,864 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MCMM___Q.DLL
+ 2004-11-19 03:13:02 65,536 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MDDM32_Q.DLL
+ 2004-11-19 03:13:02 118,784 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MDDMUI_Q.DLL
+ 2004-11-19 03:13:02 23,552 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MGDI32_Q.DLL
+ 2004-11-19 03:13:02 9,728 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MICM___Q.DLL
+ 2004-11-19 03:13:02 13,824 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MIMF32_Q.DLL
+ 2004-11-19 03:13:02 34,816 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MIMFN5_Q.DLL
+ 2004-11-19 03:13:02 10,240 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MIMFPR_Q.DLL
+ 2004-11-19 03:13:02 126,976 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MLTSRV_Q.DLL
+ 2004-11-19 03:13:02 28,672 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MNT5UI_Q.DLL
+ 2004-11-19 03:13:02 40,960 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MQDPRT_Q.DLL
+ 2004-11-19 03:13:02 77,824 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MSD32__Q.DLL
+ 2004-11-19 03:13:02 32,768 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MSDIMF_Q.DLL
+ 2004-11-22 03:43:04 151,552 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MSDMLT_Q.DLL
+ 2004-11-19 03:13:02 40,960 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MSPL32_Q.EXE
+ 2004-11-19 03:13:02 51,200 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MSPOOL_Q.DLL
+ 2004-11-19 03:13:02 131,072 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MSR32__Q.DLL
+ 2004-11-19 03:13:06 696,320 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MSUMLT_Q.DLL
+ 2004-11-19 03:13:06 19,456 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MTAG32_Q.DLL
+ 2004-11-19 03:13:06 147,456 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\konica_minoltapp13508e8c\MUINST_Q.EXE
+ 2004-11-19 03:13:02 36,864 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MCMM___Q.DLL
+ 2004-11-19 03:13:02 65,536 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MDDM32_Q.DLL
+ 2004-11-19 03:13:02 118,784 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MDDMUI_Q.DLL
+ 2004-11-19 03:13:02 23,552 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MGDI32_Q.DLL
+ 2004-11-19 03:13:02 9,728 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MICM___Q.DLL
+ 2004-11-19 03:13:02 13,824 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MIMF32_Q.DLL
+ 2004-11-19 03:13:02 34,816 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MIMFN5_Q.DLL
+ 2004-11-19 03:13:02 10,240 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MIMFPR_Q.DLL
+ 2004-11-19 03:13:02 126,976 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MLTSRV_Q.DLL
+ 2004-11-19 03:13:02 28,672 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MNT5UI_Q.DLL
+ 2004-11-19 03:13:02 40,960 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MQDPRT_Q.DLL
+ 2004-11-19 03:13:02 77,824 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MSD32__Q.DLL
+ 2004-11-19 03:13:02 32,768 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MSDIMF_Q.DLL
+ 2004-11-22 03:43:04 151,552 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MSDMLT_Q.DLL
+ 2004-11-19 03:13:02 51,200 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MSPOOL_Q.DLL
+ 2004-11-19 03:13:02 131,072 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MSR32__Q.DLL
+ 2004-11-19 03:13:06 696,320 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MSUMLT_Q.DLL
+ 2004-11-19 03:13:06 19,456 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MTAG32_Q.DLL
+ 2004-11-19 03:13:06 147,456 ----a-w I:\WINDOWS\system32\spool\drivers\w32x86\MUINST_Q.EXE
+ 2004-11-19 03:13:02 10,240 ----a-w I:\WINDOWS\system32\spool\prtprocs\w32x86\MIMFPR_Q.DLL
- 2005-06-28 15:21:34 22,752 ----a-w I:\WINDOWS\system32\spupdsvc.exe
+ 2006-09-25 23:58:48 23,856 ----a-w I:\WINDOWS\system32\spupdsvc.exe
+ 2006-04-27 22:49:30 288,417 ----a-w I:\WINDOWS\system32\SrchSTS.exe
- 2007-07-22 23:39:27 279,552 ----a-w I:\WINDOWS\system32\swreg.exe
+ 2007-07-23 00:39:27 279,552 ----a-w I:\WINDOWS\system32\swreg.exe
+ 2006-10-19 03:58:00 8,704 ----a-w I:\WINDOWS\system32\uwdf.exe
+ 2007-09-06 05:22:24 289,144 ----a-w I:\WINDOWS\system32\VCCLSID.exe
+ 2006-10-19 03:47:18 4,096 ----a-w I:\WINDOWS\system32\wdfapi.dll
+ 2006-10-19 03:58:00 8,704 ----a-w I:\WINDOWS\system32\wdfmgr.exe
- 2004-08-04 12:00:00 408,064 ----a-w I:\WINDOWS\system32\wmadmod.dll
+ 2006-10-19 03:47:18 757,248 ----a-w I:\WINDOWS\system32\WMADMOD.dll
- 2004-08-04 12:00:00 670,720 ----a-w I:\WINDOWS\system32\wmadmoe.dll
+ 2006-10-19 03:47:18 1,117,696 ----a-w I:\WINDOWS\system32\WMADMOE.dll
- 2004-08-04 12:00:00 230,400 ----a-w I:\WINDOWS\system32\wmasf.dll
+ 2006-10-19 03:47:18 222,208 ----a-w I:\WINDOWS\system32\WMASF.dll
- 2004-08-04 12:00:00 27,136 ----a-w I:\WINDOWS\system32\wmdmlog.dll
+ 2006-10-19 03:47:18 33,792 ----a-w I:\WINDOWS\system32\wmdmlog.dll
- 2004-08-04 12:00:00 23,552 ----a-w I:\WINDOWS\system32\wmdmps.dll
+ 2006-10-19 03:47:18 37,376 ----a-w I:\WINDOWS\system32\wmdmps.dll
+ 2006-10-19 03:47:18 429,056 ----a-w I:\WINDOWS\system32\wmdrmdev.dll
+ 2006-10-19 03:47:20 348,672 ----a-w I:\WINDOWS\system32\wmdrmnet.dll
+ 2006-10-19 03:47:20 535,040 ------w I:\WINDOWS\system32\wmdrmsdk.dll
- 2004-08-04 12:00:00 168,448 ----a-w I:\WINDOWS\system32\wmerror.dll
+ 2006-10-19 03:47:20 227,328 ----a-w I:\WINDOWS\system32\wmerror.dll
- 2004-08-04 12:00:00 151,552 ----a-w I:\WINDOWS\system32\wmidx.dll
+ 2006-10-19 03:47:20 157,184 ----a-w I:\WINDOWS\system32\wmidx.dll
- 2004-08-04 12:00:00 1,050,624 ----a-w I:\WINDOWS\system32\wmnetmgr.dll
+ 2006-10-19 03:47:20 937,984 ----a-w I:\WINDOWS\system32\WMNetMgr.dll
- 2007-04-30 07:22:16 4,734,976 ----a-w I:\WINDOWS\system32\wmp.dll
+ 2006-10-19 03:47:20 10,834,432 ----a-w I:\WINDOWS\system32\wmp.dll
- 2004-08-04 12:00:00 114,688 ----a-w I:\WINDOWS\system32\wmpasf.dll
+ 2006-10-19 03:47:20 242,688 ----a-w I:\WINDOWS\system32\wmpasf.dll
- 2004-08-04 12:00:00 233,472 ----a-w I:\WINDOWS\system32\wmpdxm.dll
+ 2006-10-19 03:47:20 314,880 ----a-w I:\WINDOWS\system32\wmpdxm.dll
+ 2006-10-19 03:47:20 295,936 ------w I:\WINDOWS\system32\wmpeffects.dll
+ 2006-10-19 03:47:20 1,661,440 ------w I:\WINDOWS\system32\wmpencen.dll
- 2004-08-04 12:00:00 2,940,928 ----a-w I:\WINDOWS\system32\wmploc.dll
+ 2006-10-19 03:47:20 8,231,936 ----a-w I:\WINDOWS\system32\wmploc.dll
+ 2006-10-19 03:47:20 613,376 ------w I:\WINDOWS\system32\wmpmde.dll
+ 2006-10-19 03:47:20 130,048 ------w I:\WINDOWS\system32\wmpps.dll
- 2004-08-04 12:00:00 102,400 ----a-w I:\WINDOWS\system32\wmpshell.dll
+ 2006-10-19 03:47:20 99,840 ----a-w I:\WINDOWS\system32\wmpshell.dll
+ 2006-10-19 03:47:20 204,288 ------w I:\WINDOWS\system32\wmpsrcwp.dll
- 2004-08-04 12:00:00 759,296 ----a-w I:\WINDOWS\system32\wmsdmod.dll
+ 2006-10-19 03:47:22 4,096 ----a-w I:\WINDOWS\system32\wmsdmod.dll
- 2004-08-04 12:00:00 1,119,744 ----a-w I:\WINDOWS\system32\wmsdmoe2.dll
+ 2006-10-19 03:47:22 4,096 ----a-w I:\WINDOWS\system32\wmsdmoe2.dll
- 2004-08-04 12:00:00 484,864 ----a-w I:\WINDOWS\system32\wmspdmod.dll
+ 2006-10-19 03:47:22 603,648 ----a-w I:\WINDOWS\system32\WMSPDMOD.dll
- 2004-08-04 12:00:00 896,512 ----a-w I:\WINDOWS\system32\wmspdmoe.dll
+ 2006-10-19 03:47:22 1,329,152 ----a-w I:\WINDOWS\system32\WMSPDMOE.dll
+ 2006-10-19 03:47:22 4,096 ----a-w I:\WINDOWS\system32\WMVADVD.dll
+ 2006-10-19 03:47:22 4,096 ----a-w I:\WINDOWS\system32\WMVADVE.DLL
- 2006-12-07 23:02:24 2,174,976 ----a-w I:\WINDOWS\system32\wmvcore.dll
+ 2006-10-19 03:47:22 2,450,944 ----a-w I:\WINDOWS\system32\wmvcore.dll
+ 2006-10-19 03:47:22 1,543,680 ------w I:\WINDOWS\system32\WMVDECOD.dll
- 2004-08-04 12:00:00 809,984 ----a-w I:\WINDOWS\system32\wmvdmod.dll
+ 2006-10-19 03:47:22 4,096 ----a-w I:\WINDOWS\system32\wmvdmod.dll
- 2004-08-04 12:00:00 1,001,472 ----a-w I:\WINDOWS\system32\wmvdmoe2.dll
+ 2006-10-19 03:47:22 4,096 ----a-w I:\WINDOWS\system32\wmvdmoe2.dll
+ 2006-10-19 03:47:22 1,574,912 ------w I:\WINDOWS\system32\WMVENCOD.dll
+ 2006-10-19 03:47:22 1,382,912 ------w I:\WINDOWS\system32\WMVSDECD.dll
+ 2006-10-19 03:47:22 767,488 ------w I:\WINDOWS\system32\WMVSENCD.dll
+ 2006-10-19 03:47:22 656,896 ------w I:\WINDOWS\system32\WMVXENCD.dll
+ 2006-10-19 03:47:22 629,760 ----a-w I:\WINDOWS\system32\wpd_ci.dll
+ 2006-10-19 03:47:22 35,840 ----a-w I:\WINDOWS\system32\wpdconns.dll
+ 2006-10-19 03:47:22 154,624 ----a-w I:\WINDOWS\system32\wpdmtp.dll
+ 2004-10-11 16:20:38 331,776 ----a-w I:\WINDOWS\system32\wpdmtpdr.dll
+ 2006-10-19 03:47:22 63,488 ----a-w I:\WINDOWS\system32\wpdmtpus.dll
+ 2006-10-19 03:47:22 2,603,008 ------w I:\WINDOWS\system32\WpdShext.dll
+ 2006-10-19 02:00:14 17,408 ------w I:\WINDOWS\system32\wpdshextautoplay.exe
+ 2006-10-19 03:47:22 38,400 ------w I:\WINDOWS\system32\wpdshextres.dll
+ 2006-10-19 03:47:22 133,632 ------w I:\WINDOWS\system32\WPDShServiceObj.dll
+ 2006-10-19 03:47:22 356,352 ----a-w I:\WINDOWS\system32\wpdsp.dll
+ 2004-10-11 16:20:38 10,752 ----a-w I:\WINDOWS\system32\wpdtrace.dll
+ 2007-10-04 05:36:46 25,600 ----a-w I:\WINDOWS\system32\WS2Fix.exe
+ 2006-09-29 02:13:26 95,344 ------w I:\WINDOWS\system32\WUDFCoinstaller.dll
+ 2006-09-29 00:56:38 146,432 ------w I:\WINDOWS\system32\WudfHost.exe
+ 2006-09-29 00:56:16 165,376 ------w I:\WINDOWS\system32\WudfPlatform.dll
+ 2006-09-29 00:56:14 55,808 ------w I:\WINDOWS\system32\WudfSvc.dll
+ 2006-09-29 00:56:38 316,416 ------w I:\WINDOWS\system32\WUDFx.dll
+ 2007-11-27 00:52:12 34,304 ----a-w I:\WINDOWS\system32\wvutqqq.dll
+ 2005-09-23 04:49:12 95,744 ----a-w I:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7722642D-C56A-55E4-6E7E-07D5462CC3EE}]
2007-11-26 18:52 110592 --a------ I:\Program Files\Zubslwjj\etlcyqkc.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="I:\Program Files\QuickTime\qttask.exe" [2007-02-16 09:54]
"Steam"="I:\Program Files\Steam\Steam.exe" [2007-11-20 16:29]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"P17Helper"="Rundll32 P17.dll" []
"UpdReg"="I:\WINDOWS\UpdReg.EXE" [2000-05-11 00:00]
"BootSkin Startup Jobs"="I:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" [2004-04-26 15:21]
"LogonStudio"="I:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" [2002-09-03 17:38]
"QuickTime Task"="I:\Program Files\QuickTime\qttask.exe" [2007-02-16 09:54]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-12-10 11:45 I:\WINDOWS\KHALMNPR.Exe]
"SpySweeper"="I:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2006-08-03 19:02]
"KONICA MINOLTA PagePro 1350WStatusDisplay"="I:\WINDOWS\system32\MSTMON_Q.EXE" [2004-11-21 21:42]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="I:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-27 15:30]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= I:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="LogonUI.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
I:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 I:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
I:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll 2005-01-31 14:13 49152 I:\PROGRA~1\COMMON~1\Stardock\MCPStub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winghy32]
winghy32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvutqqq]
wvutqqq.dll 2007-11-26 18:52 34304 I:\WINDOWS\system32\wvutqqq.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\I:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=I:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=I:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\I:^Documents and Settings^G^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=I:\Documents and Settings\G\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=I:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\I:^Documents and Settings^G^Start Menu^Programs^Startup^D-Odometer.lnk]
path=I:\Documents and Settings\G\Start Menu\Programs\Startup\D-Odometer.lnk
backup=I:\WINDOWS\pss\D-Odometer.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
I:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe]
2006-09-13 10:00 700416 --------- I:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IpWins]
I:\Program Files\Ipwindows\ipwins.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
I:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
I:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler]
I:\Program Files\Logitech\Profiler\lwemon.exe /noui
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-03-14 02:43 83608 --a------ I:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2007-05-23 09:12 1314816 --a------ I:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WUSB54Gv2]
2004-04-19 09:19 24576 --a------ I:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\InvokeSvc3.exe
R1 ATITool;ATITool Overclocking Utility;I:\WINDOWS\system32\DRIVERS\ATITool.sys
R2 MLPTDR_Q;MLPTDR_Q;\??\I:\WINDOWS\system32\MLPTDR_Q.SYS
R2 OneStep Search Service;OneStep Search Service;"I:\Program Files\OneStepSearch\onestep.exe" "I:\Program Files\OneStepSearch\onestep.dll" Service
R3 P17;Sound Blaster Audigy;I:\WINDOWS\system32\drivers\P17.sys
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;I:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;I:\WINDOWS\system32\drivers\WmXlCore.sys
S3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;I:\WINDOWS\system32\DRIVERS\AN983.sys
S3 WmFilter;Logitech Gaming HID Filter Driver;I:\WINDOWS\system32\drivers\WmFilter.sys
S3 WmHidLo;Logitech Gaming USB Filter Driver;I:\WINDOWS\system32\drivers\WmHidLo.sys
S3 WmVirHid;Logitech Virtual Hid Device Driver;I:\WINDOWS\system32\drivers\WmVirHid.sys
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-29 16:42:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-29 16:44:26 - machine was rebooted
I:\ComboFix-quarantined-files.txt ... 2007-09-21 15:04
I:\ComboFix2.txt ... 2007-09-21 15:04
.
--- E O F ---