Dear Tigger93
Thanks for your effort in helping me
HERE is the CF log
ComboFix 08-04-11.8 - Administrator 2008-04-12 17:25:36.4 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.219 [GMT 2:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CCEVTMGR
-------\Service_ccEvtMgr
((((((((((((((((((((((((( Files Created from 2005-09-28 to 2005-10-31 )))))))))))))))))))))))))))))))
.
2005-10-14 08:37 . 2005-10-14 08:37 118,916 --a------ C:\WINDOWS\system32\nidnt_s1.nfw
2005-10-14 06:18 . 2005-10-14 06:18 69 --a------ C:\WINDOWS\nicancfg.ini
2005-10-13 13:38 . 2005-10-13 13:38 1,074,984 --a------ C:\WINDOWS\system32\nids.dll
2005-10-13 10:24 . 2005-10-13 10:24 32,768 --a------ C:\WINDOWS\system32\nidaqcfg.exe
2005-10-13 10:24 . 2005-10-13 10:24 28,672 --a------ C:\WINDOWS\system32\nidqcfgc.dll
2005-10-13 10:24 . 2005-10-13 10:24 20,480 --a------ C:\WINDOWS\system32\nitpan32.exe
2005-10-13 10:18 . 2005-10-13 10:18 50,688 --a------ C:\WINDOWS\system32\drivers\nidmmk.dll
2005-10-13 10:17 . 2005-10-13 10:17 674,304 --a------ C:\WINDOWS\system32\drivers\nidaq32k.sys
2005-10-13 10:14 . 2005-10-13 10:14 88,576 --a------ C:\WINDOWS\system32\drivers\nipsbfw.sys
2005-10-13 10:14 . 2005-10-13 10:14 54,272 --a------ C:\WINDOWS\system32\drivers\nidaqusb.sys
2005-10-13 10:12 . 2005-10-13 10:12 102,400 --a------ C:\WINDOWS\system32\niddvctl.dll
2005-10-13 10:11 . 2005-10-13 10:11 151,552 --a------ C:\WINDOWS\system32\nidqsrvr.exe
2005-10-13 10:11 . 2005-10-13 10:11 8,704 --a------ C:\WINDOWS\system32\niidaqlv.dll
2005-10-13 10:10 . 2005-10-13 10:10 2,867,200 --a------ C:\WINDOWS\system32\niidaq32.dll
2005-10-13 09:58 . 2005-10-13 09:58 59,392 --a------ C:\WINDOWS\system32\cfswitch.dll
2005-10-13 09:55 . 2005-10-13 09:55 73,216 --a------ C:\WINDOWS\system32\CfgEng32.dll
2005-10-13 09:51 . 2005-10-13 09:51 700,416 --a------ C:\WINDOWS\system32\nidaqk.dll
2005-10-13 09:48 . 2005-10-13 09:48 57,344 --a------ C:\WINDOWS\system32\nivdaq32.exe
2005-10-13 09:48 . 2005-10-13 09:48 49,152 --a------ C:\WINDOWS\system32\nihdlc32.exe
2005-10-13 09:48 . 2005-10-13 09:48 18,944 --a------ C:\WINDOWS\system32\nicfqsvr.dll
2005-10-13 09:33 . 2005-10-13 09:33 5,081 --a------ C:\WINDOWS\system32\ni7030.dat
2005-10-13 09:30 . 2005-10-13 09:30 598,016 --a------ C:\WINDOWS\system32\NIScale.dll
2005-10-13 09:30 . 2005-10-13 09:30 122,880 --a------ C:\WINDOWS\system32\niSTCp.dll
2005-10-13 09:30 . 2005-10-13 09:30 111,616 --a------ C:\WINDOWS\system32\drivers\niSTCk.dll
2005-10-13 09:30 . 2005-10-13 09:30 53,248 --a------ C:\WINDOWS\system32\nimdsu.dll
2005-10-13 09:30 . 2005-10-13 09:30 45,056 --a------ C:\WINDOWS\system32\nimdsP.dll
2005-10-13 09:30 . 2005-10-13 09:30 30,208 --a------ C:\WINDOWS\system32\drivers\nimdsk.dll
2005-10-13 09:30 . 2005-10-13 09:30 28,672 --a------ C:\WINDOWS\system32\niSTCu.dll
2005-10-13 09:30 . 2005-10-13 09:30 15,360 --a------ C:\WINDOWS\system32\nimxprxu.dll
2005-10-13 09:29 . 2005-10-13 09:29 40,960 --a------ C:\WINDOWS\system32\nibffru.dll
2005-10-13 09:29 . 2005-10-13 09:29 37,376 --a------ C:\WINDOWS\system32\drivers\niarbk.dll
2005-10-13 09:29 . 2005-10-13 09:29 32,768 --a------ C:\WINDOWS\system32\nibffrp.dll
2005-10-13 09:29 . 2005-10-13 09:29 21,504 --a------ C:\WINDOWS\system32\drivers\nibffrk.dll
2005-10-13 09:28 . 2005-10-13 09:28 4,540,740 --a------ C:\WINDOWS\nihwdb.psm
2005-10-13 09:28 . 2005-10-13 09:28 28,672 --a------ C:\WINDOWS\system32\NIAutoConfig.exe
2005-10-13 09:28 . 2005-10-13 09:28 28,672 --a------ C:\WINDOWS\system32\NIAutoCfgRda.exe
2005-10-13 07:27 . 2005-10-13 07:27 166,912 --a------ C:\WINDOWS\system32\drivers\nidmxfk.dll
2005-10-12 17:13 . 2005-10-12 17:13 8,704 --a------ C:\WINDOWS\system32\drivers\NiViFWK.sys
2005-10-12 17:07 . 2005-10-12 17:07 38,912 --a------ C:\WINDOWS\system32\drivers\NiViUsbK.sys
2005-10-12 17:07 . 2005-10-12 17:07 38,400 --a------ C:\WINDOWS\system32\drivers\NiUsbTmc.sys
2005-10-12 17:04 . 2005-10-12 17:04 37,376 --a------ C:\WINDOWS\system32\drivers\NiViPciK.sys
2005-10-12 17:04 . 2005-10-12 17:04 10,752 --a------ C:\WINDOWS\system32\drivers\NiViPxiK.sys
2005-10-12 16:59 . 2005-10-12 16:59 160,768 --a------ C:\WINDOWS\system32\visa32.dll
2005-10-12 16:59 . 2005-10-12 16:59 56,320 --a------ C:\WINDOWS\system32\NiViSv32.dll
2005-10-12 13:39 . 2005-10-12 13:39 40,960 --a-s---- C:\WINDOWS\system32\NiSpyLog.dll
2005-10-12 12:21 . 2005-10-12 12:21 73,728 --a------ C:\WINDOWS\system32\iviconfig.dll
2005-10-12 12:21 . 2005-10-12 12:21 73,216 --a------ C:\WINDOWS\system32\IviConfig_CalExec.dll
2005-10-12 12:21 . 2005-10-12 12:21 37,888 --a------ C:\WINDOWS\system32\iviconfig_lv.dll
2005-10-12 12:21 . 2005-10-12 12:21 35,840 --a------ C:\WINDOWS\system32\iviconfig_visa.dll
2005-10-12 12:19 . 2005-10-12 12:19 238,592 --a------ C:\WINDOWS\system32\Ivi.dll
2005-10-12 12:14 . 2005-10-12 12:14 68,608 --a------ C:\WINDOWS\system32\ivi_support_c.dll
2005-10-12 12:14 . 2005-10-12 12:14 5,632 --a------ C:\WINDOWS\system32\ivi_support_cs.dll
2005-10-12 12:12 . 2005-10-12 12:12 42,496 --a------ C:\WINDOWS\system32\ivi_support_f.dll
2005-10-11 15:00 . 2005-10-11 15:00 286,720 --a------ C:\WINDOWS\system32\ninetbrw.ocx
2005-10-11 00:16 . 2005-10-11 00:16 523,264 --a------ C:\WINDOWS\system32\niScopeDMF2u.dll
2005-10-11 00:16 . 2005-10-11 00:16 410,624 --a------ C:\WINDOWS\system32\niScopeDAQ2u.dll
2005-10-11 00:07 . 2005-10-11 00:07 552,960 --a------ C:\WINDOWS\system32\ni407xCalAnlys.dll
2005-10-11 00:04 . 2005-10-11 00:04 97,792 --a------ C:\WINDOWS\system32\nihwsu.dll
2005-10-10 20:07 . 2005-10-10 20:07 820,224 --a------ C:\WINDOWS\system32\nitioxu.dll
2005-10-10 20:07 . 2005-10-10 20:07 247,296 --a------ C:\WINDOWS\system32\nistcxu.dll
2005-10-10 20:07 . 2005-10-10 20:07 172,544 --a------ C:\WINDOWS\system32\nitioru.dll
2005-10-10 20:07 . 2005-10-10 20:07 110,080 --a------ C:\WINDOWS\system32\drivers\nistcrk.dll
2005-10-10 20:07 . 2005-10-10 20:07 31,232 --a------ C:\WINDOWS\system32\nistcru.dll
2005-10-10 20:02 . 2005-10-10 20:02 216,064 --a------ C:\WINDOWS\system32\nidmfpan.exe
2005-10-10 20:02 . 2005-10-10 20:02 139,776 --a------ C:\WINDOWS\system32\nimmgluu.dll
2005-10-10 20:02 . 2005-10-10 20:02 7,680 --a------ C:\WINDOWS\system32\niviobsu.dll
2005-10-10 20:01 . 2005-10-10 20:01 555 --a------ C:\WINDOWS\system32\nidmfpan.exe.manifest
2005-10-08 01:08 . 2005-10-08 01:08 598,528 --a------ C:\WINDOWS\system32\niswdu.dll
2005-10-08 01:08 . 2005-10-08 01:08 476,160 --a------ C:\WINDOWS\system32\drivers\niswdk.dll
2005-10-08 01:08 . 2005-10-08 01:08 238,080 --a------ C:\WINDOWS\system32\nisweu.dll
2005-10-08 01:03 . 2005-10-08 01:03 708,608 --a------ C:\WINDOWS\system32\nisceu.dll
2005-10-08 01:03 . 2005-10-08 01:03 393,216 --a------ C:\WINDOWS\system32\niscdu.dll
2005-10-08 01:03 . 2005-10-08 01:03 40,960 --a------ C:\WINDOWS\system32\nispdu.dll
2005-10-08 01:00 . 2005-10-08 01:00 148,480 --a------ C:\WINDOWS\system32\nicdxu.dll
2005-10-08 01:00 . 2005-10-08 01:00 133,120 --a------ C:\WINDOWS\system32\nicdru.dll
2005-10-08 00:22 . 2005-10-08 00:22 326,144 --a------ C:\WINDOWS\system32\nisftu.dll
2005-10-07 00:54 . 2005-10-07 00:54 692,736 --a------ C:\WINDOWS\system32\drivers\nitiork.dll
2005-10-07 00:20 . 2005-10-07 00:20 1,058,304 --a------ C:\WINDOWS\system32\drivers\nissrk.dll
2005-10-07 00:20 . 2005-10-07 00:20 926,720 --a------ C:\WINDOWS\system32\drivers\nixsrk.dll
2005-10-07 00:20 . 2005-10-07 00:20 422,400 --a------ C:\WINDOWS\system32\drivers\niwfrk.dll
2005-10-07 00:19 . 2005-10-07 00:19 489,984 --a------ C:\WINDOWS\system32\drivers\niesrk.dll
2005-10-07 00:19 . 2005-10-07 00:19 346,624 --a------ C:\WINDOWS\system32\drivers\niemrk.dll
2005-10-07 00:06 . 2005-10-07 00:06 233,472 --a------ C:\WINDOWS\system32\drivers\nisdigk.dll
2005-10-07 00:06 . 2005-10-07 00:06 163,963 --a------ C:\WINDOWS\system32\drivers\usb9162k.sys
2005-10-07 00:06 . 2005-10-07 00:06 19,968 --a------ C:\WINDOWS\system32\drivers\usb6xxxk.dll
2005-10-07 00:06 . 2005-10-07 00:06 10,665 --a------ C:\WINDOWS\system32\drivers\NIUSB717A0200.bin
2005-10-07 00:06 . 2005-10-07 00:06 10,664 --a------ C:\WINDOWS\system32\drivers\NIUSB717B0200.bin
2005-10-07 00:06 . 2005-10-07 00:06 9,381 --a------ C:\WINDOWS\system32\drivers\NIUSB717B0100.bin
2005-10-07 00:06 . 2005-10-07 00:06 9,146 --a------ C:\WINDOWS\system32\drivers\NIUSB717A0100.bin
2005-10-07 00:06 . 2005-10-07 00:06 8,091 --a------ C:\WINDOWS\system32\drivers\NIUSB718A0100.bin
2005-10-07 00:06 . 2005-10-07 00:06 7,310 --a------ C:\WINDOWS\system32\drivers\NIUSB718A0200.bin
2005-10-06 18:11 . 2005-10-06 18:11 24,705 --a------ C:\WINDOWS\system32\nimcdbu.dll
2005-10-06 18:09 . 2005-10-06 18:09 43,141 --a------ C:\WINDOWS\system32\nimcrpcsu.dll
2005-10-06 17:59 . 2005-10-06 17:59 169,092 --a------ C:\WINDOWS\system32\NIMCInit.dll
2005-10-06 16:23 . 2005-10-06 16:23 72,192 --a------ C:\WINDOWS\system32\niorbu.dll
2005-10-06 16:22 . 2005-10-06 16:22 38,912 --a------ C:\WINDOWS\system32\drivers\niorbk.dll
2005-10-06 12:32 . 2005-10-06 12:32 18,944 --a------ C:\WINDOWS\system32\nimxpu.dll
2005-10-06 12:31 . 2005-10-06 12:31 19,456 --a------ C:\WINDOWS\system32\drivers\nimxpk.dll
2005-10-06 12:27 . 2005-10-06 12:27 494,776 --a------ C:\WINDOWS\system32\nidaqmx.tlb
2005-10-06 12:25 . 2005-10-06 12:25 51,200 --a------ C:\WINDOWS\system32\drivers\nimstsk.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-28 17:46 --------- d-----w C:\Program Files\Common Files\Scanner
2008-03-28 17:43 --------- d-----w C:\Program Files\CA Yahoo! Anti-Spy
2008-03-18 16:59 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ieSpell
2008-03-18 16:58 --------- d-----w C:\Program Files\ieSpell
2008-03-12 11:39 --------- d-----w C:\Documents and Settings\Administrator\Application Data\IDM
2008-03-12 11:39 --------- d-----w C:\Documents and Settings\Administrator\Application Data\DMCache
2008-03-08 13:01 --------- d-----w C:\Documents and Settings\me\Application Data\FileOpen
2008-03-08 13:01 --------- d-----w C:\Documents and Settings\me\Application Data\AdobeUM
2008-03-08 11:48 --------- d--h--r C:\Documents and Settings\me\Application Data\yahoo!
2008-03-08 11:26 --------- d-----w C:\Documents and Settings\me\Application Data\Avant Profiles
2008-03-08 11:25 --------- d-----w C:\Documents and Settings\me\Application Data\PC Suite
2008-03-06 19:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-06 19:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-06 19:32 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-03-04 19:43 --------- d-----w C:\Program Files\UnH Solutions
2008-03-04 16:07 --------- d-----w C:\Program Files\Trend Micro
2008-03-04 08:11 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-03-04 08:11 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-03-04 08:11 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-25 10:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\AWR
2008-02-25 10:30 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AWR
2008-02-25 10:29 --------- d-----w C:\Program Files\AWR
2008-02-24 11:14 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Avant Profiles
2008-02-24 11:13 --------- d-----w C:\Program Files\Avant Browser
2008-02-23 11:03 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ATTNaturalVoices
2008-02-23 11:00 --------- d-----w C:\Documents and Settings\Administrator\Application Data\BellCraft.com
2008-02-23 10:57 --------- d-----w C:\Program Files\BellCraft.com
2008-02-23 10:47 --------- d-----w C:\Program Files\ATTNaturalVoices
2008-02-11 11:25 --------- d-----w C:\Program Files\FileOpen
2008-02-11 11:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\FileOpen
2008-02-11 11:25 --------- d-----w C:\Documents and Settings\Administrator\Application Data\FileOpen
2007-12-28 11:15 --------- d-----w C:\Program Files\Kaspersky Lab
2007-12-28 11:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-27 18:11 --------- d-----w C:\Program Files\kav
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-12-09 12:20 --------- d-----w C:\Documents and Settings\Administrator\Application Data\U3
2007-12-02 07:33 --------- d-----w C:\Program Files\Athan
2007-12-01 09:29 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AdobeUM
2007-12-01 07:48 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Skype
2007-11-30 21:57 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-11-30 21:57 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-11-30 21:57 279,088 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-11-30 21:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-11-30 21:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-11-30 21:57 10,545 ----a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-11-30 21:57 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-11-30 21:57 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-11-30 21:57 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-30 14:57 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Yahoo!
2007-11-30 13:48 --------- d-----w C:\Documents and Settings\Administrator\Application Data\MathWorks
2007-11-29 18:18 --------- d-----w C:\Documents and Settings\Administrator\Application Data\PC Suite
2007-11-20 10:56 --------- d-----w C:\Program Files\Nokia
2007-11-20 10:56 --------- d-----w C:\Program Files\Common Files\PCSuite
2007-11-20 10:56 --------- d-----w C:\Program Files\Common Files\Nokia
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-10 06:49 --------- d-----w C:\Program Files\MSXML 4.0
2007-11-07 15:20 --------- d-----w C:\Program Files\Common Files\National Instruments Shared
2007-11-07 15:18 --------- d-----w C:\Program Files\cameralink
2007-11-07 15:01 --------- d-----w C:\Program Files\IVI
2007-11-07 14:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\MGS
2007-11-03 10:02 --------- d-----w C:\Program Files\DNA
2007-10-30 17:55 39,856 ----a-w C:\WINDOWS\system32\drivers\symids.sys
2007-10-30 17:55 37,936 ----a-w C:\WINDOWS\system32\drivers\symndisv.sys
2007-10-30 17:55 35,120 ----a-w C:\WINDOWS\system32\drivers\symndis.sys
2007-10-30 17:55 27,696 ----a-w C:\WINDOWS\system32\drivers\symredrv.sys
2007-10-30 17:55 191,536 ----a-w C:\WINDOWS\system32\drivers\symtdi.sys
2007-10-30 17:55 145,968 ----a-w C:\WINDOWS\system32\drivers\symfw.sys
2007-10-30 17:55 12,848 ----a-w C:\WINDOWS\system32\drivers\symdns.sys
2007-10-30 17:24 12,963 ----a-w C:\WINDOWS\system32\drivers\SymRedir.cat
2007-10-30 17:24 1,358 ----a-w C:\WINDOWS\system32\drivers\SymRedir.inf
2007-10-30 17:20 360,064 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2007-09-05 11:34 --------- d-----w C:\Program Files\ZD Soft
2007-08-28 08:15 --------- d-----w C:\Program Files\Skype
2007-08-28 08:15 --------- d-----w C:\Program Files\Common Files\Skype
2007-08-28 08:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-08-20 09:32 --------- d-----w C:\Program Files\Java
2007-08-20 09:28 --------- d-----w C:\Program Files\Common Files\Java
2007-07-06 10:05 72,960 ----a-w C:\WINDOWS\system32\drivers\mqac.sys
2007-07-05 16:34 --------- d-----w C:\Program Files\D-Link
2007-06-30 10:06 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-06-19 11:01 --------- d-----w C:\Documents and Settings\me\Application Data\Share-to-Web Upload Folder
2007-06-19 11:01 --------- d-----w C:\Documents and Settings\LogMeInRemoteUser\Application Data\Share-to-Web Upload Folder
2007-06-19 11:01 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Share-to-Web Upload Folder
2007-06-18 11:02 --------- d-----w C:\Program Files\Internet Download Manager
2007-06-18 10:35 --------- d-----w C:\Program Files\Common Files\Bcgsoft
2007-06-18 10:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\National Instruments
2007-06-18 10:22 --------- d-----w C:\Program Files\Common Files\Merge Modules
2007-05-13 07:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-05-10 16:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-05-10 12:47 --------- d-----w C:\Program Files\TechSmith
2007-05-10 12:36 --------- d-----w C:\Program Files\Google
2007-05-10 12:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2007-05-10 10:45 --------- d-----w C:\Program Files\Yahoo!
2007-05-02 15:40 --------- d-----w C:\Program Files\MSECache
2007-04-23 11:32 364,160 ----a-w C:\WINDOWS\system32\drivers\update.sys
2007-04-10 10:13 --------- d-----w C:\Program Files\ZEMAX
2007-04-04 13:29 --------- d-----w C:\Program Files\PIC Simulator IDE
2007-04-03 14:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
2007-03-18 08:55 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\MathWorks
2007-03-17 07:57 --------- d-----w C:\Program Files\National Instruments
2006-01-23 08:32 131,072 ----a-w C:\Program Files\internet explorer\plugins\LV80ActiveXControl.dll
2006-06-07 12:40 132,848 ----a-w C:\Program Files\internet explorer\plugins\LV82ActiveXControl.dll
2003-05-01 07:36 114,688 ----a-w C:\Program Files\internet explorer\plugins\LV7ActiveXControl.dll
2004-03-15 15:51 114,688 ----a-w C:\Program Files\internet explorer\plugins\LV71ActiveXControl.dll
.
((((((((((((((((((((((((((((( snapshot@2008-03-31_15.46.11.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-03-19 09:40:28 1,845,888 ------w C:\WINDOWS\$hf_mig$\KB941693\SP2QFE\win32k.sys
+ 2007-03-06 01:22:36 14,048 ------w C:\WINDOWS\$hf_mig$\KB941693\spmsg.dll
+ 2007-03-06 01:22:42 213,216 ------w C:\WINDOWS\$hf_mig$\KB941693\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ------w C:\WINDOWS\$hf_mig$\KB941693\update\spcustom.dll
+ 2007-03-06 01:23:00 716,000 ------w C:\WINDOWS\$hf_mig$\KB941693\update\update.exe
+ 2007-03-06 01:23:52 371,424 ------w C:\WINDOWS\$hf_mig$\KB941693\update\updspapi.dll
+ 2008-02-20 05:19:36 147,968 ------w C:\WINDOWS\$hf_mig$\KB945553\SP2QFE\dnsapi.dll
+ 2008-02-20 18:49:36 45,568 ------w C:\WINDOWS\$hf_mig$\KB945553\SP2QFE\dnsrslvr.dll
+ 2007-03-06 01:22:36 14,048 ------w C:\WINDOWS\$hf_mig$\KB945553\spmsg.dll
+ 2007-03-06 01:22:42 213,216 ------w C:\WINDOWS\$hf_mig$\KB945553\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ------w C:\WINDOWS\$hf_mig$\KB945553\update\spcustom.dll
+ 2007-03-06 01:23:00 716,000 ------w C:\WINDOWS\$hf_mig$\KB945553\update\update.exe
+ 2007-03-06 01:23:52 371,424 ------w C:\WINDOWS\$hf_mig$\KB945553\update\updspapi.dll
+ 2008-03-01 13:03:00 124,928 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\advpack.dll
+ 2008-03-01 13:03:00 347,136 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\dxtmsft.dll
+ 2008-03-01 13:03:00 214,528 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\dxtrans.dll
+ 2008-03-01 13:03:00 132,608 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\extmgr.dll
+ 2008-03-01 13:03:00 63,488 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\icardie.dll
+ 2008-02-22 09:39:56 70,656 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ie4uinit.exe
+ 2008-03-01 13:03:00 153,088 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieakeng.dll
+ 2008-03-01 13:03:00 230,400 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieaksie.dll
+ 2008-02-15 05:44:26 161,792 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieapfltr.dat
+ 2008-03-01 13:03:00 383,488 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieapfltr.dll
+ 2008-03-01 13:03:00 388,608 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iedkcs32.dll
+ 2008-03-01 13:03:02 6,067,712 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieframe.dll
+ 2008-03-01 13:03:02 44,544 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iernonce.dll
+ 2008-03-01 13:03:02 267,776 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iertutil.dll
+ 2008-02-22 09:39:56 13,824 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieudinit.exe
+ 2008-02-22 09:40:22 625,664 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
+ 2008-03-01 13:03:02 27,648 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\jsproxy.dll
+ 2008-03-01 13:03:02 459,264 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msfeeds.dll
+ 2008-03-01 13:03:02 52,224 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msfeedsbs.dll
+ 2008-03-01 13:03:02 3,593,216 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mshtml.dll
+ 2008-03-01 13:03:02 478,208 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mshtmled.dll
+ 2008-03-01 13:03:02 193,024 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msrating.dll
+ 2008-03-01 13:03:02 671,232 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mstime.dll
+ 2008-03-01 13:03:02 102,912 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\occache.dll
+ 2008-03-01 13:03:02 44,544 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\pngfilt.dll
+ 2008-03-01 13:03:02 105,984 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\url.dll
+ 2008-03-01 13:03:02 1,162,752 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\urlmon.dll
+ 2008-03-01 13:03:02 233,472 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\webcheck.dll
+ 2008-03-01 13:03:02 827,392 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:34 14,048 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\spmsg.dll
+ 2007-03-06 01:22:40 213,216 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\spuninst.exe
+ 2007-03-06 01:22:32 22,752 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\spcustom.dll
+ 2007-03-06 01:22:56 716,000 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\update.exe
+ 2007-03-06 01:23:52 371,424 ------w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\updspapi.dll
+ 2008-02-20 06:52:44 282,624 ------w C:\WINDOWS\$hf_mig$\KB948590\SP2QFE\gdi32.dll
+ 2007-03-06 01:22:36 14,048 ------w C:\WINDOWS\$hf_mig$\KB948590\spmsg.dll
+ 2007-03-06 01:22:42 213,216 ------w C:\WINDOWS\$hf_mig$\KB948590\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ------w C:\WINDOWS\$hf_mig$\KB948590\update\spcustom.dll
+ 2007-03-06 01:23:00 716,000 ------w C:\WINDOWS\$hf_mig$\KB948590\update\update.exe
+ 2007-03-06 01:23:52 371,424 ------w C:\WINDOWS\$hf_mig$\KB948590\update\updspapi.dll
+ 2007-03-06 01:22:34 14,048 ------w C:\WINDOWS\$hf_mig$\KB948881\spmsg.dll
+ 2007-03-06 01:22:40 213,216 ------w C:\WINDOWS\$hf_mig$\KB948881\spuninst.exe
+ 2007-03-06 01:22:32 22,752 ------w C:\WINDOWS\$hf_mig$\KB948881\update\spcustom.dll
+ 2007-03-06 01:22:56 716,000 ------w C:\WINDOWS\$hf_mig$\KB948881\update\update.exe
+ 2007-03-06 01:23:48 371,424 ------w C:\WINDOWS\$hf_mig$\KB948881\update\updspapi.dll
+ 2007-03-06 01:22:42 213,216 ------w C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe
+ 2007-03-06 01:23:52 371,424 ------w C:\WINDOWS\$NtUninstallKB941693$\spuninst\updspapi.dll
+ 2007-03-08 13:47:48 1,843,584 ------w C:\WINDOWS\$NtUninstallKB941693$\win32k.sys
+ 2006-06-26 17:37:10 148,480 ------w C:\WINDOWS\$NtUninstallKB945553$\dnsapi.dll
+ 2004-08-03 20:56:44 45,568 ------w C:\WINDOWS\$NtUninstallKB945553$\dnsrslvr.dll
+ 2007-03-06 01:22:42 213,216 ------w C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe
+ 2007-03-06 01:23:52 371,424 ------w C:\WINDOWS\$NtUninstallKB945553$\spuninst\updspapi.dll
+ 2007-06-19 14:31:20 282,112 ------w C:\WINDOWS\$NtUninstallKB948590$\gdi32.dll
+ 2007-03-06 01:22:42 213,216 ------w C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe
+ 2007-03-06 01:23:52 371,424 ------w C:\WINDOWS\$NtUninstallKB948590$\spuninst\updspapi.dll
+ 2007-03-06 01:22:40 213,216 ------w C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe
+ 2007-03-06 01:23:48 371,424 ------w C:\WINDOWS\$NtUninstallKB948881$\spuninst\updspapi.dll
- 2000-08-31 06:00:00 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
- 2000-08-31 06:00:00 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2000-08-31 06:00:00 73,728 ----a-w C:\WINDOWS\fdsv.exe
+ 2000-08-31 06:00:00 80,412 ----a-w C:\WINDOWS\grep.exe
+ 2007-12-07 02:21:46 124,928 ------w C:\WINDOWS\ie7updates\KB947864-IE7\advpack.dll
+ 2007-12-19 23:01:06 347,136 ------w C:\WINDOWS\ie7updates\KB947864-IE7\dxtmsft.dll
+ 2007-12-07 02:21:46 214,528 ------w C:\WINDOWS\ie7updates\KB947864-IE7\dxtrans.dll
+ 2007-12-07 02:21:46 133,120 ------w C:\WINDOWS\ie7updates\KB947864-IE7\extmgr.dll
+ 2007-12-07 02:21:46 63,488 ------w C:\WINDOWS\ie7updates\KB947864-IE7\icardie.dll
+ 2007-12-06 11:00:58 70,656 ------w C:\WINDOWS\ie7updates\KB947864-IE7\ie4uinit.exe
+ 2007-12-07 02:21:46 153,088 ------w C:\WINDOWS\ie7updates\KB947864-IE7\ieakeng.dll
+ 2007-12-07 02:21:46 230,400 ------w C:\WINDOWS\ie7updates\KB947864-IE7\ieaksie.dll
+ 2007-12-06 04:59:52 161,792 ------w C:\WINDOWS\ie7updates\KB947864-IE7\ieakui.dll
+ 2007-12-07 02:21:46 383,488 ------w C:\WINDOWS\ie7updates\KB947864-IE7\ieapfltr.dll
+ 2007-12-07 02:21:46 384,512 ------w C:\WINDOWS\ie7updates\KB947864-IE7\iedkcs32.dll
+ 2007-12-07 02:21:46 6,066,176 ------w C:\WINDOWS\ie7updates\KB947864-IE7\ieframe.dll
+ 2007-12-07 02:21:46 44,544 ------w C:\WINDOWS\ie7updates\KB947864-IE7\iernonce.dll
+ 2007-12-07 02:21:46 267,776 ------w C:\WINDOWS\ie7updates\KB947864-IE7\iertutil.dll
+ 2007-12-06 11:00:58 13,824 ------w C:\WINDOWS\ie7updates\KB947864-IE7\ieudinit.exe
+ 2007-12-06 11:01:26 625,664 ------w C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
+ 2007-12-07 02:21:48 27,648 ------w C:\WINDOWS\ie7updates\KB947864-IE7\jsproxy.dll
+ 2007-12-07 02:21:48 459,264 ------w C:\WINDOWS\ie7updates\KB947864-IE7\msfeeds.dll
+ 2007-12-07 02:21:48 52,224 ------w C:\WINDOWS\ie7updates\KB947864-IE7\msfeedsbs.dll
+ 2007-12-08 05:21:48 3,592,192 ------w C:\WINDOWS\ie7updates\KB947864-IE7\mshtml.dll
+ 2007-12-07 02:21:48 478,208 ------w C:\WINDOWS\ie7updates\KB947864-IE7\mshtmled.dll
+ 2007-12-07 02:21:48 193,024 ------w C:\WINDOWS\ie7updates\KB947864-IE7\msrating.dll
+ 2007-12-07 02:21:48 671,232 ------w C:\WINDOWS\ie7updates\KB947864-IE7\mstime.dll
+ 2007-12-07 02:21:48 102,912 ------w C:\WINDOWS\ie7updates\KB947864-IE7\occache.dll
+ 2008-01-11 05:53:32 44,544 ------w C:\WINDOWS\ie7updates\KB947864-IE7\pngfilt.dll
+ 2007-03-06 01:22:40 213,216 ------w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:52 371,424 ------w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\updspapi.dll
+ 2007-12-07 02:21:48 105,984 ------w C:\WINDOWS\ie7updates\KB947864-IE7\url.dll
+ 2007-12-07 02:21:48 1,159,680 ------w C:\WINDOWS\ie7updates\KB947864-IE7\urlmon.dll
+ 2007-12-07 02:21:48 233,472 ------w C:\WINDOWS\ie7updates\KB947864-IE7\webcheck.dll
+ 2007-12-07 02:21:48 824,832 ------w C:\WINDOWS\ie7updates\KB947864-IE7\wininet.dll
+ 2000-08-31 06:00:00 98,816 ----a-w C:\WINDOWS\sed.exe
+ 2000-08-31 06:00:00 161,792 ----a-w C:\WINDOWS\swreg.exe
+ 2000-08-31 06:00:00 136,704 ----a-w C:\WINDOWS\swsc.exe
+ 2000-08-31 06:00:00 212,480 ----a-w C:\WINDOWS\swxcacls.exe
- 2007-12-07 02:21:46 124,928 ----a-w C:\WINDOWS\system32\advpack.dll
+ 2008-03-01 13:06:20 124,928 ----a-w C:\WINDOWS\system32\advpack.dll
- 2007-12-07 02:21:46 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
+ 2008-03-01 13:06:20 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
- 2006-06-26 17:37:10 148,480 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
+ 2008-02-20 05:32:44 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
- 2004-08-03 20:56:44 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
+ 2008-02-20 05:32:44 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
- 2007-12-19 23:01:06 347,136 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-03-01 13:06:22 347,136 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2007-12-07 02:21:46 214,528 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-03-01 13:06:22 214,528 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
- 2007-12-07 02:21:46 133,120 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-03-01 13:06:22 133,120 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
- 2007-06-19 14:31:20 282,112 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
+ 2008-02-20 06:51:06 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
- 2007-12-07 02:21:46 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
+ 2008-03-01 13:06:22 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
- 2007-12-06 11:00:58 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
+ 2008-02-29 08:55:24 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
- 2007-12-07 02:21:46 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2008-03-01 13:06:22 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
- 2007-12-07 02:21:46 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
+ 2008-03-01 13:06:22 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
- 2007-12-06 04:59:52 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
+ 2008-02-15 05:44:26 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
- 2007-12-07 02:21:46 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
+ 2008-03-01 13:06:22 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
- 2007-12-07 02:21:46 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2008-03-01 13:06:22 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
- 2007-12-07 02:21:46 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
+ 2008-03-01 13:06:24 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
- 2007-12-07 02:21:46 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
+ 2008-03-01 13:06:24 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
- 2007-12-07 02:21:46 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
+ 2008-03-01 13:06:26 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
- 2007-12-06 11:00:58 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
+ 2008-02-22 10:00:52 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
- 2007-12-06 11:01:26 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
+ 2008-02-29 08:55:46 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
- 2007-12-07 02:21:48 27,648 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-03-01 13:06:26 27,648 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
- 2007-12-07 02:21:48 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
+ 2008-03-01 13:06:26 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
- 2007-12-07 02:21:48 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
+ 2008-03-01 13:06:26 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
- 2007-12-08 05:21:48 3,592,192 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-03-01 16:36:30 3,591,680 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
- 2007-12-07 02:21:48 478,208 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-03-01 13:06:28 478,208 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2007-12-07 02:21:48 193,024 ------w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-03-01 13:06:28 193,024 ------w C:\WINDOWS\system32\dllcache\msrating.dll
- 2007-12-07 02:21:48 671,232 ------w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-03-01 13:06:30 671,232 ------w C:\WINDOWS\system32\dllcache\mstime.dll
- 2007-12-07 02:21:48 102,912 ------w C:\WINDOWS\system32\dllcache\occache.dll
+ 2008-03-01 13:06:30 102,912 ------w C:\WINDOWS\system32\dllcache\occache.dll
- 2008-01-11 05:53:32 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-03-01 13:06:30 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
- 2007-12-07 02:21:48 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
+ 2008-03-01 13:06:30 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
- 2007-12-07 02:21:48 1,159,680 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-03-01 13:06:30 1,159,680 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
- 2007-12-07 02:21:48 233,472 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2008-03-01 13:06:30 233,472 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
- 2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
+ 2008-03-19 09:47:00 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
- 2007-12-07 02:21:48 824,832 ------w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-03-01 13:06:32 826,368 ------w C:\WINDOWS\system32\dllcache\wininet.dll
- 2006-06-26 17:37:10 148,480 ----a-w C:\WINDOWS\system32\dnsapi.dll
+ 2008-02-20 05:32:44 148,992 ----a-w C:\WINDOWS\system32\dnsapi.dll
- 2004-08-03 20:56:44 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
+ 2008-02-20 05:32:44 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
- 2007-12-19 23:01:06 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2008-03-01 13:06:22 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2007-12-07 02:21:46 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
+ 2008-03-01 13:06:22 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
- 2007-12-07 02:21:46 133,120 ------w C:\WINDOWS\system32\extmgr.dll
+ 2008-03-01 13:06:22 133,120 ------w C:\WINDOWS\system32\extmgr.dll
- 2007-09-29 06:31:04 321,928 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-04-10 07:23:38 321,928 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2007-06-19 14:31:20 282,112 ----a-w C:\WINDOWS\system32\gdi32.dll
+ 2008-02-20 06:51:06 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
- 2007-12-07 02:21:46 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
+ 2008-03-01 13:06:22 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
- 2007-12-06 11:00:58 70,656 ------w C:\WINDOWS\system32\ie4uinit.exe
+ 2008-02-29 08:55:24 70,656 ------w C:\WINDOWS\system32\ie4uinit.exe
- 2007-12-07 02:21:46 153,088 ------w C:\WINDOWS\system32\ieakeng.dll
+ 2008-03-01 13:06:22 153,088 ------w C:\WINDOWS\system32\ieakeng.dll
- 2007-12-07 02:21:46 230,400 ------w C:\WINDOWS\system32\ieaksie.dll
+ 2008-03-01 13:06:22 230,400 ------w C:\WINDOWS\system32\ieaksie.dll
- 2007-12-06 04:59:52 161,792 ------w C:\WINDOWS\system32\ieakui.dll
+ 2008-02-15 05:44:26 161,792 ------w C:\WINDOWS\system32\ieakui.dll
- 2007-12-07 02:21:46 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
+ 2008-03-01 13:06:22 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
- 2007-12-07 02:21:46 384,512 ------w C:\WINDOWS\system32\iedkcs32.dll
+ 2008-03-01 13:06:22 384,512 ------w C:\WINDOWS\system32\iedkcs32.dll
- 2007-12-07 02:21:46 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll
+ 2008-03-01 13:06:24 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll
- 2007-12-07 02:21:46 44,544 ------w C:\WINDOWS\system32\iernonce.dll
+ 2008-03-01 13:06:24 44,544 ------w C:\WINDOWS\system32\iernonce.dll
- 2007-12-07 02:21:46 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
+ 2008-03-01 13:06:26 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
- 2007-12-06 11:00:58 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
+ 2008-02-22 10:00:52 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
- 2007-12-07 02:21:48 27,648 ------w C:\WINDOWS\system32\jsproxy.dll
+ 2008-03-01 13:06:26 27,648 ------w C:\WINDOWS\system32\jsproxy.dll
- 2008-03-05 16:30:54 19,148,408 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-04-06 05:56:20 19,836,024 ----a-w C:\WINDOWS\system32\MRT.exe
- 2007-12-07 02:21:48 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
+ 2008-03-01 13:06:26 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
- 2007-12-07 02:21:48 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
+ 2008-03-01 13:06:26 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
- 2007-12-08 05:21:48 3,592,192 ----a-w C:\WINDOWS\system32\mshtml.dll
+ 2008-03-01 16:36:30 3,591,680 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2007-12-07 02:21:48 478,208 ------w C:\WINDOWS\system32\mshtmled.dll
+ 2008-03-01 13:06:28 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2007-12-07 02:21:48 193,024 ------w C:\WINDOWS\system32\msrating.dll
+ 2008-03-01 13:06:28 193,024 ------w C:\WINDOWS\system32\msrating.dll
- 2007-12-07 02:21:48 671,232 ------w C:\WINDOWS\system32\mstime.dll
+ 2008-03-01 13:06:30 671,232 ------w C:\WINDOWS\system32\mstime.dll
- 2007-12-07 02:21:48 102,912 ------w C:\WINDOWS\system32\occache.dll
+ 2008-03-01 13:06:30 102,912 ------w C:\WINDOWS\system32\occache.dll
- 2008-01-11 05:53:32 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-03-01 13:06:30 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-01-28 07:52:30 357,888 --sh--w C:\WINDOWS\system32\ShuiNiu.exe
- 2007-12-07 02:21:48 105,984 ----a-w C:\WINDOWS\system32\url.dll
+ 2008-03-01 13:06:30 105,984 ----a-w C:\WINDOWS\system32\url.dll
- 2007-12-07 02:21:48 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2008-03-01 13:06:30 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
- 2007-12-07 02:21:48 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll
+ 2008-03-01 13:06:30 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll
- 2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys
+ 2008-03-19 09:47:00 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
- 2007-12-07 02:21:48 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
+ 2008-03-01 13:06:32 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
+ 2000-08-31 06:00:00 49,152 ----a-w C:\WINDOWS\VFind.exe
+ 2000-08-31 06:00:00 68,096 ----a-w C:\WINDOWS\zip.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 22:56 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-05 10:45 68856]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-08-17 03:45 23120680]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2005-10-24 16:53 307200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2003-01-07 12:09 46592 C:\WINDOWS\SOUNDMAN.EXE]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 20:52 483328]
"Easy-PrintToolBox"="C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.exe" [2004-01-14 04:10 409600]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"niDevMon"="C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe" [2005-10-06 11:49 263168]
"DataLayer"="C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-06-07 11:31 819712]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-06-29 15:29 176128]
"Athan"="C:\Program Files\Athan\Athan.exe" [2007-09-06 21:25 1003520]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 16:24 86016]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 07:59 115816]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-01-14 09:11 771704]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
"antinetcut2"="C:\Program Files\Anti Netcut\Anti NetCut.exe" [ ]
"DsNiu"="C:\WINDOWS\system32\ShuiNiu.exe" [2008-01-28 09:52 357888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 22:56 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2007-03-11 15:36:33 25214]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\National Instruments\\LabVIEW 8.0\\LabVIEW.exe"=
"C:\\Program Files\\National Instruments\\Shared\\Example Finder\\1.0\\bin\\NIExampleFinder.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Avant Browser\\avant.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 NIPALK;NIPALK;C:\WINDOWS\system32\drivers\nipalk.sys [2005-09-22 21:12]
R0 PCIIMAQ;National Instruments IMAQ Driver;C:\WINDOWS\system32\drivers\PCIIMAQ.sys [2005-08-30 10:38]
R2 cvintdrv;cvintdrv;C:\WINDOWS\system32\drivers\cvintdrv.sys [2006-07-27 10:00]
R2 gpib420;GPIB Analyzer;C:\WINDOWS\system32\drivers\gpib420.sys [2005-07-18 01:45]
R2 GpibPrtK;Gpib Port;C:\WINDOWS\system32\drivers\gpibprtk.sys [2005-07-18 01:25]
R2 lvalarmk;lvalarmk;C:\WINDOWS\system32\drivers\lvalarmk.dll [2005-07-27 08:58]
R2 mxssvr;NI Configuration Manager;"C:\Program Files\National Instruments\MAX\nimxs.exe" [2005-10-03 22:52]
R2 niarbk;niarbk;C:\WINDOWS\system32\drivers\niarbk.dll [2005-10-13 09:29]
R2 nibffrk;nibffrk;C:\WINDOWS\system32\drivers\nibffrk.dll [2005-10-13 09:29]
R2 nicanpk;nicanpk;C:\WINDOWS\system32\DRIVERS\nicanpk.dll [2005-10-14 06:02]
R2 Nidaq32k;Nidaq32k;C:\WINDOWS\system32\drivers\Nidaq32k.sys [2005-10-13 10:17]
R2 nidimk;nidimk;C:\WINDOWS\system32\drivers\nidimk.dll [2005-09-28 21:14]
R2 nidmmk;NI DMM and Data Logger Kernel Driver;C:\WINDOWS\system32\drivers\nidmmk.dll [2005-10-13 10:18]
R2 nidmxfk;nidmxfk;C:\WINDOWS\system32\drivers\nidmxfk.dll [2005-10-13 07:27]
R2 nidwgk;nidwgk;C:\WINDOWS\system32\drivers\nidwgk.dll [2005-09-20 20:48]
R2 niembrtk;niembrtk;C:\WINDOWS\system32\drivers\niembrtk.sys [2004-07-08 10:24]
R2 niemrk;niemrk;C:\WINDOWS\system32\drivers\niemrk.dll [2005-10-07 00:19]
R2 nifslk;nifslk;C:\WINDOWS\system32\drivers\nifslk.dll [2005-10-06 11:32]
R2 nigplk;nigplk;C:\WINDOWS\system32\drivers\nigplk.dll [2005-09-20 18:17]
R2 nihsdrk;nihsdrk;C:\WINDOWS\system32\drivers\nihsdrk.dll [2005-09-20 20:45]
R2 niimaqk;niimaqk;C:\WINDOWS\system32\drivers\niimaqk.dll [2005-09-21 15:41]
R2 nimdsk;nimdsk;C:\WINDOWS\system32\drivers\nimdsk.dll [2005-10-13 09:30]
R2 nimxpk;nimxpk;C:\WINDOWS\system32\drivers\nimxpk.dll [2005-10-06 12:31]
R2 nipxirmk;nipxirmk;C:\WINDOWS\system32\drivers\nipxirmk.dll [2005-09-21 11:30]
R2 niRTProxy;niRTProxy;C:\WINDOWS\system32\RTProxy.exe C:\WINDOWS\system32\RTProxy.exe []
R2 nisldk;nisldk;C:\WINDOWS\system32\drivers\nisldk.dll [2005-09-20 20:32]
R2 nisrcdk;nisrcdk;C:\WINDOWS\system32\drivers\nisrcdk.dll [2005-09-20 20:04]
R2 nistck;nistck;C:\WINDOWS\system32\drivers\nistck.dll [2005-10-13 09:30]
R2 niswdk;niswdk;C:\WINDOWS\system32\drivers\niswdk.dll [2005-10-08 01:08]
R2 NITaggerService;National Instruments Variable Engine;"C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe" [2005-10-11 15:13]
R2 usb6xxxk;usb6xxxk;C:\WINDOWS\system32\drivers\usb6xxxk.dll [2005-10-07 00:06]
R3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys [2004-08-03 22:29]
R3 nicdrk;nicdrk;C:\WINDOWS\system32\drivers\nicdrk.dll [2005-10-06 11:56]
R3 nimdbgk;nimdbgk;C:\WINDOWS\system32\drivers\nimdbgk.dll [2005-09-28 20:07]
R3 nimru2k;nimru2k;C:\WINDOWS\system32\drivers\nimru2k.dll [2005-09-28 21:54]
R3 nimsdrk;nimsdrk;C:\WINDOWS\system32\drivers\nimsdrk.dll [2005-10-06 12:19]
R3 nimstsk;nimstsk;C:\WINDOWS\system32\drivers\nimstsk.dll [2005-10-06 12:25]
R3 nimxdfk;nimxdfk;C:\WINDOWS\system32\drivers\nimxdfk.dll [2005-09-28 20:52]
R3 niorbk;niorbk;C:\WINDOWS\system32\drivers\niorbk.dll [2005-10-06 16:22]
R3 niscdk;niscdk;C:\WINDOWS\system32\drivers\niscdk.dll [2005-10-06 12:07]
S3 m4cxw2k3;NDIS5.1 Miniport Driver for D-Link PCI Express Ethernet Controller;C:\WINDOWS\system32\DRIVERS\m4cxw2k3.sys [2005-03-10 07:42]
S3 nidsark;nidsark;C:\WINDOWS\system32\drivers\nidsark.dll [2005-10-06 12:14]
S3 niesrk;niesrk;C:\WINDOWS\system32\drivers\niesrk.dll [2005-10-07 00:19]
S3 nimcdfxk;nimcdfxk;C:\WINDOWS\system32\drivers\nimcdfxk.dll [2005-09-14 10:45]
S3 nimcdlbk;nimcdlbk;C:\WINDOWS\system32\drivers\nimcdlbk.dll [2005-09-14 10:29]
S3 nimslk;nimslk;C:\WINDOWS\system32\drivers\nimslk.dll [2005-10-06 01:00]
S3 nimsrlk;nimsrlk;C:\WINDOWS\system32\drivers\nimsrlk.dll [2005-10-06 01:00]
S3 nipalusb;NI-PAL USB Driver;C:\WINDOWS\system32\DRIVERS\nipalusb.sys [2005-09-22 21:13]
S3 nisdigk;nisdigk;C:\WINDOWS\system32\drivers\nisdigk.dll [2005-10-07 00:06]
S3 nisftk;nisftk;C:\WINDOWS\system32\drivers\nisftk.dll [2005-10-06 11:48]
S3 nispdk;nispdk;C:\WINDOWS\system32\drivers\nispdk.dll [2005-10-06 12:07]
S3 nissrk;nissrk;C:\WINDOWS\system32\drivers\nissrk.dll [2005-10-07 00:20]
S3 nistc2k;nistc2k;C:\WINDOWS\system32\drivers\nistc2k.dll [2005-10-06 12:03]
S3 nistcrk;nistcrk;C:\WINDOWS\system32\drivers\nistcrk.dll [2005-10-10 20:07]
S3 nitiork;nitiork;C:\WINDOWS\system32\drivers\nitiork.dll [2005-10-07 00:54]
S3 NiViFWK;NI-VISA FireWire Driver;C:\WINDOWS\system32\drivers\NiViFWK.sys [2005-10-12 17:13]
S3 NiViPciK;NI-VISA PCI Driver;C:\WINDOWS\system32\drivers\NiViPciK.sys [2005-10-12 17:04]
S3 NiViPxiK;NI-VISA PXI Driver;C:\WINDOWS\system32\drivers\NiViPxiK.sys [2005-10-12 17:04]
S3 niwdk;niwdk;C:\WINDOWS\system32\drivers\niwdk.sys [2005-10-05 17:34]
S3 niwfrk;niwfrk;C:\WINDOWS\system32\drivers\niwfrk.dll [2005-10-07 00:20]
S3 nixsrk;nixsrk;C:\WINDOWS\system32\drivers\nixsrk.dll [2005-10-07 00:20]
S3 PORTMON;PORTMON;C:\DOCUME~1\user05\LOCALS~1\Temp\Rar$EX00.937\PORTMSYS.SYS []
S3 scrcap;scrcap;C:\WINDOWS\system32\DRIVERS\scrcap.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0bec3367-dc4a-11db-a60a-00104bb0c20c}]
\Shell\AutoRun\command - I:\
\Shell\explore\Command - WScript.exe .\__.vbs
\Shell\open\Command - WScript.exe .\__.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{116c5b46-7d53-11dc-9a30-00104bb0c20c}]
\Shell\AutoRun\command - I:\ShuiNiu.exe
\Shell\Explore\Command - I:\ShuiNiu.exe
\Shell\Open\Command - I:\ShuiNiu.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61631e1e-a896-11dc-9a83-00104bb0c20c}]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{83e29194-847a-11dc-9a3e-00104bb0c20c}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb594348-f26d-11dc-9b18-00104bb0c20c}]
\Shell\AutoRun\command - ShuiNiu.exe
\Shell\Explore\Command - ShuiNiu.exe
\Shell\Open\Command - ShuiNiu.exe
*Newly Created Service* - COMHOST
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2005-10-31 14:03:56
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSVCHST.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\APPCORE\APPSVC32.EXE
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\ALUSCHEDULERSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSVCHST.EXE
C:\WINDOWS\SYSTEM32\LKCITDL.EXE
C:\WINDOWS\SYSTEM32\LKADS.EXE
C:\WINDOWS\SYSTEM32\LKTSRV.EXE
C:\MATLAB6P5\WEBSERVER\BIN\WIN32\MATLABSERVER.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\MATLAB6P5\BIN\WIN32\MATLAB.EXE
C:\PROGRAM FILES\NATIONAL INSTRUMENTS\SHARED\SECURITY\NIDMSRV.EXE
C:\PROGRAM FILES\COMMON FILES\PCSUITE\SERVICES\SERVIC~1.EXE
C:\WINDOWS\SYSTEM32\NISVCLOC.EXE
C:\WINDOWS\SYSTEM32\NIPALSM.EXE
C:\WINDOWS\