More recently, I tried AVZ again. Immediately it says something including this:
Function NtEnumerateKey (47) - machine code modification Method of JmpTo. jmp F833960AXyj42.sys
Function NtOpenKey (77) - machine code modification Method of JmpTo. jmp F8339376AXyj42.sys
\FileSystem\ntfs[IRP_MJ_DIRECTORY_CONTROL] = F8334EE7 -> Xyj42.sys
I investigated that a bit then there was an Awola fake malware scan popping up repeatedly, annoyingly, so I decided to nevermind AVZ for the moment and instead read a guide on bleepingcomputer that suggested Smitfraudfix in safe mode to clean up Awola. Rebooted in safe mode. Used SmitFraudFix as described in the guide. Rebooted, still Awola. Rebooted again in safe mode. Terminated Awola's process then went and deleted awola's files manually.
Before restarting I decided to try a regular file search in safemode for that Xyj42.sys from AVZ. It was found in c:\windows\system32 ...I then renamed it xyj42.sy. Restarted in normal mode. No Awola stuff!
Scanned again with AVZ. Enabled malware removal mode and in the search parameters turned the rootkit blocking options on and enabled avzguard. Here's what I saved from its window afterwards:
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YHITCL4Z\myraz32[1].exe >>> suspicion for AdvWare.Win32.SuperJuan.tfd ( 0B7200EB 0249C70B 00282CED 00248B31 97280)
File quarantined succesfully (C:\System Volume Information\_restore{EE28ED23-5B67-4E4A-960A-1AA37372AA6D}\RP0\A0000001.dll)
C:\System Volume Information\_restore{EE28ED23-5B67-4E4A-960A-1AA37372AA6D}\RP0\A0000001.dll >>
File quarantined succesfully (C:\System Volume Information\_restore{EE28ED23-5B67-4E4A-960A-1AA37372AA6D}\RP1\A0000450.exe)
File quarantined succesfully (C:\System Volume Information\_restore{EE28ED23-5B67-4E4A-960A-1AA37372AA6D}\RP1\A0000451.exe)
C:\System Volume Information\_restore{EE28ED23-5B67-4E4A-960A-1AA37372AA6D}\RP1\A0000451.exe >>>>> Constructor.VBS.SSIWG.10 deleted successfully
File quarantined succesfully (C:\System Volume Information\_restore{EE28ED23-5B67-4E4A-960A-1AA37372AA6D}\RP1\A0000452.exe)
C:\System Volume Information\_restore{EE28ED23-5B67-4E4A-960A-1AA37372AA6D}\RP1\A0000452.exe
C:\System Volume Information\_restore{EE28ED23-5B67-4E4A-960A-1AA37372AA6D}\RP1\A0000453.COM >>>>> HackTool.DOS.Eudpass deleted successfully
File quarantined succesfully (C:\System Volume Information\_restore{EE28ED23-5B67-4E4A-960A-1AA37372AA6D}\RP1\A0000454.exe)
C:\System Volume Information\_restore{EE28ED23-5B67-4E4A-960A-1AA37372AA6D}\RP1\A0000454.exe >>>>> HackTool.Win32.TrHunter.15 deleted successfully
C:\wintcid.exe >>> suspicion for Trojan-Downloader.Win32.Hilldoor.b ( 0AE3D85F 04DFABCF 0024CDB5 00217095 14336)
C:\winysgd.exe >>> suspicion for Trojan-Downloader.Win32.Hilldoor.b ( 0AE0AA26 04D95439 0024CDB5 00217095 14336)
Removing traces of deleted files...
4. Checking Winsock Layered Service Provider (SPI/LSP)
LSP settings checked. No errors detected
5. Searching for keyboard/mouse/windows events hooks (Keyloggers, Trojan DLLs)
6. Searching for opened TCP/UDP ports used by malicious software
Checking - disabled by user
7. Heuristic system check
Checking - complete
8. Searching for vulnerabilities
>> Services: potentially dangerous service allowed: RemoteRegistry (Remote Registry)
>> Services: potentially dangerous service allowed: TermService (Terminal Services)
>> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery Service)
>> Services: potentially dangerous service allowed: TlntSvr (Telnet)
>> Services: potentially dangerous service allowed: Schedule (Task Scheduler)
>> Services: potentially dangerous service allowed: mnmsrvc (NetMeeting Remote Desktop Sharing)
>> Services: potentially dangerous service allowed: RDSessMgr (Remote Desktop Help Session Manager)
> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
>> Security: disk drives' autorun is enabled
>> Security: administrative shares (C$, D$ ...) are enabled
>> Security: anonymous user access is enabled
>> Security: sending Remote Assistant queries is enabled
Checking - complete
Files scanned: 40580, extracted from archives: 20845, malicious software found 9, suspicions - 10
---
Restarted again after. Ran a Spybot S&D scan. It found many things, including Win32.Small.azi, Virtumonde, Smitfraud-C. Awola Anti Spyware. Had it try to fix that stuff. Restarted.
Tinkered with Spybot's System Internals section at some point I seem to recall. Discovered printing worked again! I printed important business things immediately. Later scanned with Hijackthis. There were like 100 bizarre O4 - HKCU\..\Run entries with random names, questionmarks in the filenames, and odd paths. I'm baffled! Help me please!
Here is the OTL scan log:
OTL logfile created on: 6/4/2011 7:49:31 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Program Files\mIRC\download
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
510.48 Mb Total Physical Memory | 264.51 Mb Available Physical Memory | 51.82% Memory free
1.22 Gb Paging File | 1.03 Gb Available in Paging File | 84.29% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 23.86 Gb Free Space | 32.01% Space Free | Partition Type: NTFS
Drive E: | 123.00 Mb Total Space | 68.60 Mb Free Space | 55.77% Space Free | Partition Type: FAT32
Computer Name: PERFUNDO | User Name: kathy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/06/04 19:07:58 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Program Files\mIRC\download\OTLgtg.exe
PRC - [2011/06/04 12:39:01 | 000,068,608 | RHS- | M] () -- C:\WINDOWS\Τаsks\regedit.exe
PRC - [2011/04/14 11:25:41 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2006/11/23 10:45:34 | 002,076,672 | ---- | M] (mIRC Co. Ltd.) -- C:\Program Files\mIRC\mirc.exe
PRC - [2006/07/16 05:01:43 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2001/08/17 22:36:54 | 000,086,016 | ---- | M] (PCtel, Inc.) -- C:\WINDOWS\system32\pctspk.exe
========== Modules (SafeList) ==========
MOD - [2011/06/04 19:07:58 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Program Files\mIRC\download\OTLgtg.exe
MOD - [2006/07/16 05:02:56 | 001,053,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2649_x-ww_aac16c8b\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2010/07/26 16:01:00 | 000,066,112 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) getPlus®
SRV - [2001/08/17 22:36:54 | 000,086,016 | ---- | M] (PCtel, Inc.) [Auto | Running] -- C:\WINDOWS\system32\pctspk.exe -- (Pctspk)
========== Driver Services (SafeList) ==========
DRV - [2007/05/10 15:02:19 | 000,639,224 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2006/07/16 05:09:03 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2002/10/15 01:00:00 | 000,101,431 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\IdeChnDr.sys -- (IdeChnDr) Intel®
DRV - [2002/10/15 01:00:00 | 000,013,891 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\IdeBusDr.sys -- (IdeBusDr)
DRV - [2002/07/23 10:01:38 | 000,161,020 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x)
DRV - [2002/07/23 10:01:34 | 000,011,935 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV11NT.sys -- (iAimFP8)
DRV - [2002/07/23 10:01:32 | 000,011,871 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV09NT.sys -- (iAimFP7)
DRV - [2002/07/23 10:01:32 | 000,011,807 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV07nt.sys -- (iAimFP5)
DRV - [2002/07/23 10:01:32 | 000,011,295 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV08NT.sys -- (iAimFP6)
DRV - [2002/07/23 10:01:30 | 000,012,127 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV02NT.sys -- (iAimFP1)
DRV - [2002/07/23 10:01:30 | 000,011,775 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV05NT.sys -- (iAimFP2)
DRV - [2002/07/23 10:01:28 | 000,019,455 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wVchNTxx.sys -- (iAimFP4)
DRV - [2002/07/23 10:01:28 | 000,012,415 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV01nt.sys -- (iAimFP0)
DRV - [2002/07/23 10:01:28 | 000,012,063 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wSiINTxx.sys -- (iAimFP3)
DRV - [2002/07/23 10:01:26 | 000,025,471 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV10nt.sys -- (iAimTV5)
DRV - [2002/07/23 10:01:26 | 000,022,271 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV06nt.sys -- (iAimTV6)
DRV - [2002/07/23 10:01:24 | 000,033,599 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV04nt.sys -- (iAimTV3)
DRV - [2002/07/23 10:01:22 | 000,029,311 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV01nt.sys -- (iAimTV0)
DRV - [2002/07/23 10:01:22 | 000,019,551 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV02NT.sys -- (iAimTV1)
DRV - [2002/07/23 10:01:20 | 000,023,615 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wCh7xxNT.sys -- (iAimTV4)
DRV - [2001/08/17 13:28:16 | 000,397,502 | ---- | M] (PCtel, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\vpctcom.sys -- (Vpctcom)
DRV - [2001/08/17 13:28:16 | 000,064,605 | ---- | M] (PCtel, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\vvoice.sys -- (Vvoice)
DRV - [2001/08/17 13:28:14 | 000,604,253 | ---- | M] (PCTEL, INC.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\vmodem.sys -- (Vmodem)
DRV - [2001/08/17 13:28:12 | 000,128,286 | ---- | M] (PCTEL, INC.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptserli.sys -- (Ptserli)
DRV - [2001/08/17 12:12:24 | 000,070,730 | ---- | M] (Linksys Group, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lne100tx.sys -- (lne100tx)
DRV - [2001/08/17 09:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default = ED 18 0C 03 60 D0 7F 49 BE AE C9 BE 6E 33 9E F7 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "http://www.google.co...m/webhp?rls=ig"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {AB196CF2-BF33-4E98-AD19-67A3CD5A4AA0}:1.9.1
FF - HKLM\software\mozilla\Firefox\extensions\\{AB196CF2-BF33-4E98-AD19-67A3CD5A4AA0}: C:\Documents and Settings\kathy\Local Settings\Application Data\{AB196CF2-BF33-4E98-AD19-67A3CD5A4AA0} [2011/06/03 18:48:55 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox 4.0 Beta 8\components [2011/04/03 16:16:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox 4.0 Beta 8\plugins
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/22 18:31:01 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/22 18:30:59 | 000,000,000 | ---D | M]
[2011/03/12 17:24:25 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\kathy\Application Data\Mozilla\Extensions
[2011/05/11 10:46:48 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\kathy\Application Data\Mozilla\Firefox\Profiles\hng3qhcl.default\extensions
[2011/05/22 18:31:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
[2011/06/03 18:48:55 | 000,000,000 | ---D | M] (XULRunner) -- C:\DOCUMENTS AND SETTINGS\KATHY\LOCAL SETTINGS\APPLICATION DATA\{AB196CF2-BF33-4E98-AD19-67A3CD5A4AA0}
[2009/05/08 20:35:36 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/04/14 11:26:02 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 03:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/06/03 20:53:22 | 000,000,000 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O2 - BHO: (no name) - {18D69F3C-27AA-2D5C-8E38-58C02C5385E8} - File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (BndShell3 BHO Class) - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - File not found
O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - Reg Error: Value error. File not found
O2 - BHO: (no name) - {EAF1AF45-6130-4CC5-8051-6A58BB253F93} - File not found
O4 - HKLM..\Run: [F9FBFAF6FBFCFCF] File not found
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [Apntuzze] File not found
O4 - HKCU..\Run: [Asue] C:\WINDOWS\Τаsks\regedit.exe ()
O4 - HKCU..\Run: [Bwctcex] File not found
O4 - HKCU..\Run: [Cheq] File not found
O4 - HKCU..\Run: [Csxavqi] File not found
O4 - HKCU..\Run: [Czssnsq] C:\WINDOWS\system32\аѕsembly\іexplore.exe ()
O4 - HKCU..\Run: [Damyknqj] File not found
O4 - HKCU..\Run: [Dide] File not found
O4 - HKCU..\Run: [Dnwgbsmq] File not found
O4 - HKCU..\Run: [Efoh] File not found
O4 - HKCU..\Run: [Egfha] File not found
O4 - HKCU..\Run: [Fkvo] File not found
O4 - HKCU..\Run: [Glevip] C:\WINDOWS\wroetmol.dll ()
O4 - HKCU..\Run: [Hcuabct] File not found
O4 - HKCU..\Run: [Hgxzps] File not found
O4 - HKCU..\Run: [Hubfsuh] File not found
O4 - HKCU..\Run: [Hzs] File not found
O4 - HKCU..\Run: [Idt] File not found
O4 - HKCU..\Run: [Iytmywy] File not found
O4 - HKCU..\Run: [Jhs] File not found
O4 - HKCU..\Run: [Jksmmmk] File not found
O4 - HKCU..\Run: [Jtyzvdd] File not found
O4 - HKCU..\Run: [Kdtkwriw] File not found
O4 - HKCU..\Run: [Ktkufd] File not found
O4 - HKCU..\Run: [Kvhiq] File not found
O4 - HKCU..\Run: [Lwwdespp] File not found
O4 - HKCU..\Run: [Nalk] File not found
O4 - HKCU..\Run: [Nhkmmt] File not found
O4 - HKCU..\Run: [Nht] File not found
O4 - HKCU..\Run: [Ntgsjcj] File not found
O4 - HKCU..\Run: [Odtw] C:\Program Files\Common Files\ѕystem32\scanregw.exe ()
O4 - HKCU..\Run: [oroi] File not found
O4 - HKCU..\Run: [Pvkikko] File not found
O4 - HKCU..\Run: [QdrModule10] File not found
O4 - HKCU..\Run: [QdrPack11] File not found
O4 - HKCU..\Run: [Qmrccvw] File not found
O4 - HKCU..\Run: [Qptlgcdl] File not found
O4 - HKCU..\Run: [Qqqqf] File not found
O4 - HKCU..\Run: [Sfqywb] File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Torqsabx] File not found
O4 - HKCU..\Run: [Ukfhmk] File not found
O4 - HKCU..\Run: [Umafi] File not found
O4 - HKCU..\Run: [Wjil] File not found
O4 - HKCU..\Run: [Wlw] File not found
O4 - HKCU..\Run: [Wuwn] File not found
O4 - HKCU..\Run: [xInsIDE] File not found
O4 - HKCU..\Run: [Ykocki] File not found
O4 - HKCU..\Run: [Yngyje] File not found
O4 - HKCU..\Run: [Yshmjo] File not found
O4 - HKCU..\Run: [Zmpod] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com...ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {3334504D-9980-0010-8000-00AA00389B71} http://download.micr...C4D/mp43dmo.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.micr...922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {50BD5CDA-4BA8-4048-8FAA-763F222E41D8} ms-its:mhtml:file://c:\\nores.mht!http://adxrnet.net/c...::/xpreload.ocx (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\fccabba: DllName - fccabba.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\kathy\Local Settings\Application Data\Microsoft\Wallpaper2.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\kathy\Local Settings\Application Data\Microsoft\Wallpaper2.bmp
O28 - HKLM ShellExecuteHooks: {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - Reg Error: Value error. File not found
O30 - LSA: Authentication Packages - (C:\WINDOWS\System32\pmkhh.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/12/28 11:50:47 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/06/04 17:53:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kathy\Desktop\backups
[2011/06/04 12:38:26 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\kathy\IETldCache
[2011/06/04 12:01:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2011/06/04 11:59:45 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
[2011/06/04 11:59:45 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2011/06/04 11:59:43 | 001,985,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
[2011/06/04 11:59:38 | 011,076,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
[2011/06/04 11:59:38 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2011/06/04 11:58:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2011/06/04 11:55:31 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2011/06/04 11:55:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US
[2011/06/04 11:54:54 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MpEngineStore
[2011/06/03 21:37:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot_bak
[2011/06/03 20:47:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kathy\Desktop\SmitfraudFix
[2011/06/03 20:44:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\KB905474
[2011/06/03 20:44:03 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/06/03 20:43:50 | 000,000,000 | ---D | C] -- C:\e366ee99452b59ded35c06bd
[2011/06/03 20:43:27 | 000,000,000 | ---D | C] -- C:\996e4d00c27fa4c99c8a
[2011/06/03 20:43:15 | 000,000,000 | ---D | C] -- C:\ff4c7b36ff72458a78cb5f056b126059
[2011/06/03 20:39:47 | 000,000,000 | ---D | C] -- C:\9d58ec02821eb6fecc8321d7c035
[2011/06/03 20:37:12 | 000,000,000 | ---D | C] -- C:\183a80f4440e33293f
[2011/06/03 20:32:51 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 6.0
[2011/06/03 20:17:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2011/06/03 20:13:34 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2011/06/03 19:32:39 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msyuv.dll
[2011/06/03 19:30:32 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tsbyuv.dll
[2011/06/03 19:30:30 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iyuv_32.dll
[2011/06/03 19:25:59 | 000,272,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthport.sys
[2011/06/03 19:23:49 | 000,457,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2011/06/03 19:18:05 | 002,143,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2011/06/03 19:17:57 | 002,186,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2011/06/03 19:17:47 | 002,021,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2011/06/03 19:17:39 | 002,063,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2011/06/03 18:55:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2011/06/03 18:52:42 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winzm.ime
[2011/06/03 18:52:41 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winsp.ime
[2011/06/03 18:52:40 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winpy.ime
[2011/06/03 18:52:39 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winime.ime
[2011/06/03 18:52:38 | 000,079,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winar30.ime
[2011/06/03 18:52:38 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wingb.ime
[2011/06/03 18:52:36 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\weitekp9.sys
[2011/06/03 18:52:35 | 000,041,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\weitekp9.dll
[2011/06/03 18:52:33 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wamreg51.dll
[2011/06/03 18:52:32 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wamps51.dll
[2011/06/03 18:52:31 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wam51.dll
[2011/06/03 18:52:29 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w3svapi.dll
[2011/06/03 18:52:28 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w3ext.dll
[2011/06/03 18:52:28 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w3ctrs51.dll
[2011/06/03 18:52:27 | 000,048,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w32.dll
[2011/06/03 18:52:26 | 000,086,073 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\voicesub.dll
[2011/06/03 18:52:26 | 000,026,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spupdsvc.exe
[2011/06/03 18:52:26 | 000,016,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll
[2011/06/03 18:52:25 | 000,426,041 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\voicepad.dll
[2011/06/03 18:52:25 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$
[2011/06/03 18:52:19 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\uniime.dll
[2011/06/03 18:52:18 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\unicdime.ime
[2011/06/03 18:52:17 | 000,103,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\uihelper.dll
[2011/06/03 18:52:16 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tsprof.exe
[2011/06/03 18:52:13 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tools.dll
[2011/06/03 18:52:12 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tmigrate.dll
[2011/06/03 18:52:11 | 000,455,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tintsetp.exe
[2011/06/03 18:52:11 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tintlphr.exe
[2011/06/03 18:52:10 | 000,571,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tintlgnt.ime
[2011/06/03 18:52:09 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\thawbrkr.dll
[2011/06/03 18:52:08 | 000,019,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdspx.sys
[2011/06/03 18:52:07 | 000,021,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdipx.sys
[2011/06/03 18:52:07 | 000,013,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdasync.sys
[2011/06/03 18:52:03 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\svcext51.dll
[2011/06/03 18:52:01 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\status.dll
[2011/06/03 18:52:00 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sspifilt.dll
[2011/06/03 18:51:58 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srusbusd.dll
[2011/06/03 18:51:54 | 000,143,422 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\softkey.dll
[2011/06/03 18:51:52 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmptrap.exe
[2011/06/03 18:51:52 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_snprfdll.dll
[2011/06/03 18:51:51 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpthrd.dll
[2011/06/03 18:51:51 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpstup.dll
[2011/06/03 18:51:50 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpmib.dll
[2011/06/03 18:51:48 | 000,259,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpcl.dll
[2011/06/03 18:51:46 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_smtpctrs.dll
[2011/06/03 18:51:45 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smimsgif.dll
[2011/06/03 18:51:45 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smierrsy.dll
[2011/06/03 18:51:44 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smierrsm.dll
[2011/06/03 18:51:43 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smb6w.dll
[2011/06/03 18:51:42 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm9aw.dll
[2011/06/03 18:51:42 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sma3w.dll
[2011/06/03 18:51:42 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm93w.dll
[2011/06/03 18:51:41 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm92w.dll
[2011/06/03 18:51:41 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm90w.dll
[2011/06/03 18:51:40 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm8cw.dll
[2011/06/03 18:51:40 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm8dw.dll
[2011/06/03 18:51:40 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm8aw.dll
[2011/06/03 18:51:39 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm87w.dll
[2011/06/03 18:51:39 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm89w.dll
[2011/06/03 18:51:38 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm81w.dll
[2011/06/03 18:51:38 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm59w.dll
[2011/06/03 18:51:37 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\simptcp.dll
[2011/06/03 18:51:30 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_seos.dll
[2011/06/03 18:51:28 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_scripto.dll
[2011/06/03 18:51:26 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2011/06/03 18:51:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kathy\Application Data\Awol
[2011/06/03 18:51:25 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2011/06/03 18:51:25 | 000,026,624 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll
[2011/06/03 18:51:24 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rw001ext.dll
[2011/06/03 18:51:22 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rpcref.dll
[2011/06/03 18:51:21 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\romanime.ime
[2011/06/03 18:51:19 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_regtrace.exe
[2011/06/03 18:51:18 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\register.exe
[2011/06/03 18:51:15 | 000,020,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ramdisk.sys
[2011/06/03 18:51:14 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\quick.ime
[2011/06/03 18:51:14 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\quser.exe
[2011/06/03 18:51:13 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\query.exe
[2011/06/03 18:51:11 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pwsdata.dll
[2011/06/03 18:51:07 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pmxviceo.dll
[2011/06/03 18:51:07 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pmxmcro.dll
[2011/06/03 18:51:07 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pmxgl.dll
[2011/06/03 18:51:06 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pmigrate.dll
[2011/06/03 18:51:05 | 000,070,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pintlphr.exe
[2011/06/03 18:51:04 | 000,482,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pintlgnt.ime
[2011/06/03 18:51:03 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pintlcsd.dll
[2011/06/03 18:51:02 | 000,079,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\phon.ime
[2011/06/03 18:51:01 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\permchk.dll
[2011/06/03 18:50:59 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pagecnt.dll
[2011/06/03 18:50:59 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\padrs804.dll
[2011/06/03 18:50:58 | 000,036,927 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\padrs411.dll
[2011/06/03 18:50:58 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\padrs412.dll
[2011/06/03 18:50:57 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\padrs404.dll
[2011/06/03 18:50:51 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_ntfsdrv.dll
[2011/06/03 18:50:50 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nsepm.dll
[2011/06/03 18:50:47 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nextlink.dll
[2011/06/03 18:50:42 | 000,229,439 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\multibox.dll
[2011/06/03 18:50:30 | 001,875,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msir3jp.lex
[2011/06/03 18:50:29 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msir3jp.dll
[2011/06/03 18:50:11 | 000,092,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mga.sys
[2011/06/03 18:50:11 | 000,092,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mga.dll
[2011/06/03 18:50:10 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\metada51.dll
[2011/06/03 18:50:10 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mdsync.dll
[2011/06/03 18:50:07 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_mailmsg.dll
[2011/06/03 18:50:06 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lprmon.dll
[2011/06/03 18:50:05 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lpdsvc.dll
[2011/06/03 18:50:05 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lonsint.dll
[2011/06/03 18:50:04 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\logscrpt.dll
[2011/06/03 18:50:03 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lmmib2.dll
[2011/06/03 18:49:57 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\korwbrkr.dll
[2011/06/03 18:49:55 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdvntc.dll
[2011/06/03 18:49:55 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdusa.dll
[2011/06/03 18:49:54 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdth3.dll
[2011/06/03 18:49:54 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdurdu.dll
[2011/06/03 18:49:53 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdth2.dll
[2011/06/03 18:49:53 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdth1.dll
[2011/06/03 18:49:53 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdth0.dll
[2011/06/03 18:49:52 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdsyr2.dll
[2011/06/03 18:49:52 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdsyr1.dll
[2011/06/03 18:49:51 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdnecnt.dll
[2011/06/03 18:49:50 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdnecat.dll
[2011/06/03 18:49:50 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdnec95.dll
[2011/06/03 18:49:49 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlk41a.dll
[2011/06/03 18:49:49 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlk41j.dll
[2011/06/03 18:49:48 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdinpun.dll
[2011/06/03 18:49:48 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdintel.dll
[2011/06/03 18:49:48 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdintam.dll
[2011/06/03 18:49:47 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdinmar.dll
[2011/06/03 18:49:47 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdinkan.dll
[2011/06/03 18:49:47 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdinhin.dll
[2011/06/03 18:49:46 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdinguj.dll
[2011/06/03 18:49:46 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdindev.dll
[2011/06/03 18:49:45 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdibm02.dll
[2011/06/03 18:49:45 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdheb.dll
[2011/06/03 18:49:44 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdfa.dll
[2011/06/03 18:49:44 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdgeo.dll
[2011/06/03 18:49:43 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbddiv2.dll
[2011/06/03 18:49:43 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbddiv1.dll
[2011/06/03 18:49:42 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdax2.dll
[2011/06/03 18:49:42 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdarmw.dll
[2011/06/03 18:49:41 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbda3.dll
[2011/06/03 18:49:41 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbda2.dll
[2011/06/03 18:49:41 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdarme.dll
[2011/06/03 18:49:40 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd106n.dll
[2011/06/03 18:49:40 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbda1.dll
[2011/06/03 18:49:39 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jupiw.dll
[2011/06/03 18:49:39 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd101a.dll
[2011/06/03 18:49:39 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd101.dll
[2011/06/03 18:49:38 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iwrps.dll
[2011/06/03 18:49:37 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iscomlog.dll
[2011/06/03 18:49:36 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\isapips.dll
[2011/06/03 18:49:35 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iprip.dll
[2011/06/03 18:49:33 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\infoctrs.dll
[2011/06/03 18:49:32 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetin51.exe
[2011/06/03 18:49:30 | 000,315,452 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imskf.dll
[2011/06/03 18:49:29 | 000,471,102 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imskdic.dll
[2011/06/03 18:49:28 | 000,102,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imlang.dll
[2011/06/03 18:49:28 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imkrinst.exe
[2011/06/03 18:49:27 | 000,274,489 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjputyc.dll
[2011/06/03 18:49:27 | 000,262,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjputy.exe
[2011/06/03 18:49:26 | 000,233,527 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjprw.exe
[2011/06/03 18:49:26 | 000,045,109 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpuex.exe
[2011/06/03 18:49:25 | 000,208,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpmig.exe
[2011/06/03 18:49:24 | 000,155,705 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpdsvr.exe
[2011/06/03 18:49:23 | 000,307,257 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpdct.exe
[2011/06/03 18:49:23 | 000,081,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpdct.dll
[2011/06/03 18:49:22 | 000,716,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpcus.dll
[2011/06/03 18:49:22 | 000,057,398 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpdadm.exe
[2011/06/03 18:49:20 | 000,368,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpcic.dll
[2011/06/03 18:49:19 | 000,811,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjp81k.dll
[2011/06/03 18:49:19 | 000,340,023 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjp81.ime
[2011/06/03 18:49:18 | 000,311,359 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imepadsv.exe
[2011/06/03 18:49:18 | 000,102,463 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imepadsm.dll
[2011/06/03 18:49:17 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imekrmbx.dll
[2011/06/03 18:49:17 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imekrmig.exe
[2011/06/03 18:49:16 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imekrcic.dll
[2011/06/03 18:49:16 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imekr61.ime
[2011/06/03 18:49:14 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iissync.exe
[2011/06/03 18:49:13 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisfecnv.dll
[2011/06/03 18:49:12 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iische51.dll
[2011/06/03 18:49:12 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iiscrmap.dll
[2011/06/03 18:49:11 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisadmin.dll
[2011/06/03 18:48:56 | 010,129,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hwxkor.dll
[2011/06/03 18:48:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kathy\Local Settings\Application Data\{AB196CF2-BF33-4E98-AD19-67A3CD5A4AA0}
[2011/06/03 18:48:28 | 010,096,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hwxcht.dll
[2011/06/03 18:48:27 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\httpmb51.dll
[2011/06/03 18:48:24 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hostmib.dll
[2011/06/03 18:48:22 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hanjadic.dll
[2011/06/03 18:48:20 | 000,032,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\gzip.dll
[2011/06/03 18:48:17 | 000,400,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsxp32.dll
[2011/06/03 18:48:17 | 000,192,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxswzrd.dll
[2011/06/03 18:48:16 | 000,397,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxstiff.dll
[2011/06/03 18:48:16 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxst30.dll
[2011/06/03 18:48:16 | 000,154,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsui.dll
[2011/06/03 18:48:15 | 000,562,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsst.dll
[2011/06/03 18:48:15 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxssvc.exe
[2011/06/03 18:48:14 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsroute.dll
[2011/06/03 18:48:14 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxssend.exe
[2011/06/03 18:48:14 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsres.dll
[2011/06/03 18:48:13 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsmon.dll
[2011/06/03 18:48:13 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsperf.dll
[2011/06/03 18:48:12 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsevent.dll
[2011/06/03 18:48:12 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsdrv.dll
[2011/06/03 18:48:12 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsext32.dll
[2011/06/03 18:48:11 | 000,285,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxscomex.dll
[2011/06/03 18:48:11 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxscover.exe
[2011/06/03 18:48:10 | 000,143,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsclnt.exe
[2011/06/03 18:48:10 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsclntr.dll
[2011/06/03 18:48:10 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxscom.dll
[2011/06/03 18:48:09 | 000,452,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsapi.dll
[2011/06/03 18:48:09 | 000,111,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxscfgwz.dll
[2011/06/03 18:48:08 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftpsv251.dll
[2011/06/03 18:48:08 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftpmib.dll
[2011/06/03 18:48:07 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftpctrs2.dll
[2011/06/03 18:48:07 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftlx041e.dll
[2011/06/03 18:48:05 | 000,020,541 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpadmdll.dll
[2011/06/03 18:48:04 | 000,024,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpadmcgi.exe
[2011/06/03 18:48:02 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\flattemp.exe
[2011/06/03 18:48:01 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_fcachdll.dll
[2011/06/03 18:48:00 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\f3ahvoas.dll
[2011/06/03 18:47:58 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\evntwin.exe
[2011/06/03 18:47:58 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\evntcmd.exe
[2011/06/03 18:47:57 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\evntagnt.dll
[2011/06/03 18:47:57 | 000,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\et4000.sys
[2011/06/03 18:47:56 | 000,057,856 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuimgd.dll
[2011/06/03 18:47:56 | 000,045,056 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esunid.dll
[2011/06/03 18:47:55 | 000,031,744 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esucmd.dll
[2011/06/03 18:47:43 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dayi.ime
[2011/06/03 18:47:42 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\davcdata.exe
[2011/06/03 18:47:39 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cprofile.exe
[2011/06/03 18:47:38 | 000,057,399 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cplexe.exe
[2011/06/03 18:47:37 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\counters.dll
[2011/06/03 18:47:36 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\convlog.exe
[2011/06/03 18:47:36 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\controt.dll
[2011/06/03 18:47:33 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\compfilt.dll
[2011/06/03 18:47:30 | 000,480,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cintsetp.exe
[2011/06/03 18:47:29 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cintime.dll
[2011/06/03 18:47:29 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cintlgnt.ime
[2011/06/03 18:47:27 | 000,097,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chtmbx.dll
[2011/06/03 18:47:27 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chtskdic.dll
[2011/06/03 18:47:26 | 000,838,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chtbrkr.dll
[2011/06/03 18:47:23 | 001,677,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chsbrkr.dll
[2011/06/03 18:47:21 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chgport.exe
[2011/06/03 18:47:21 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chgusr.exe
[2011/06/03 18:47:21 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chglogon.exe
[2011/06/03 18:47:20 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chajei.ime
[2011/06/03 18:47:20 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\change.exe
[2011/06/03 18:47:15 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2011/06/03 18:47:15 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\c_iscii.dll
[2011/06/03 18:47:14 | 000,218,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\c_g18030.dll
[2011/06/03 18:47:14 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\c_is2022.dll
[2011/06/03 18:46:46 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\browscap.dll
[2011/06/03 18:46:42 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\authfilt.dll
[2011/06/03 18:46:40 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\asptxn.dll
[2011/06/03 18:46:40 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aspperf.dll
[2011/06/03 18:46:38 | 000,331,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aqueue.dll
[2011/06/03 18:46:36 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_aqadmin.dll
[2011/06/03 18:46:35 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\appconf.dll
[2011/06/03 18:46:34 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt0804.dll
[2011/06/03 18:46:34 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt0412.dll
[2011/06/03 18:46:33 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt0411.dll
[2011/06/03 18:46:33 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt040d.dll
[2011/06/03 18:46:32 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt0404.dll
[2011/06/03 18:46:32 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt0401.dll
[2011/06/03 18:46:30 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_adsiisex.dll
[2011/06/03 18:46:29 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\adrot.dll
[2011/06/03 18:46:28 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admexs.dll
[2011/06/03 18:46:28 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admxprox.dll
[2011/06/03 18:46:17 | 000,032,827 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcptest.exe
[2011/06/03 18:46:17 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcptsat.dll
[2011/06/03 18:46:15 | 002,134,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smtpsnap.dll
[2011/06/03 18:46:13 | 000,020,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shtml.dll
[2011/06/03 18:46:13 | 000,016,437 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shtml.exe
[2011/06/03 18:46:02 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetmgr.exe
[2011/06/03 18:46:01 | 000,829,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetmgr.dll
[2011/06/03 18:46:00 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisrstas.exe
[2011/06/03 18:45:59 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisreset.exe
[2011/06/03 18:45:59 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisrstap.dll
[2011/06/03 18:45:58 | 000,020,538 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpremadm.exe
[2011/06/03 18:45:58 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftpsapi2.dll
[2011/06/03 18:45:56 | 000,598,071 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpmmc.dll
[2011/06/03 18:45:56 | 000,208,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpmmcsat.dll
[2011/06/03 18:45:55 | 000,188,494 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpcount.exe
[2011/06/03 18:45:55 | 000,020,541 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpexedll.dll
[2011/06/03 18:45:54 | 000,109,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp98swin.exe
[2011/06/03 18:45:53 | 000,876,653 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4awel.dll
[2011/06/03 18:45:53 | 000,014,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp98sadm.exe
[2011/06/03 18:45:52 | 000,049,212 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4awebs.dll
[2011/06/03 18:45:52 | 000,032,826 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4avss.dll
[2011/06/03 18:45:51 | 000,102,509 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4atxt.dll
[2011/06/03 18:45:51 | 000,041,020 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4avnb.dll
[2011/06/03 18:45:50 | 000,147,513 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4apws.dll
[2011/06/03 18:45:50 | 000,049,210 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4areg.dll
[2011/06/03 18:45:49 | 000,184,435 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4amsft.dll
[2011/06/03 18:45:49 | 000,082,035 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4anscp.dll
[2011/06/03 18:45:47 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cnfgprts.ocx
[2011/06/03 18:45:46 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\certwiz.ocx
[2011/06/03 18:45:46 | 000,188,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cfgwiz.exe
[2011/06/03 18:45:45 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\certmap.ocx
[2011/06/03 18:45:44 | 000,020,540 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\author.dll
[2011/06/03 18:45:44 | 000,016,439 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\author.exe
[2011/06/03 18:45:42 | 000,016,439 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admin.exe
[2011/06/03 18:45:39 | 000,020,540 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admin.dll
[2011/06/03 18:39:54 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\isignup.exe
[2011/06/03 18:39:40 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmpns.dll
[2011/06/03 18:39:36 | 000,327,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wucltui.dll
[2011/06/03 18:39:36 | 000,173,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuweb.dll
[2011/06/03 18:39:36 | 000,127,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wucltui.dll
[2011/06/03 18:39:35 | 000,194,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuaueng1.dll
[2011/06/03 18:39:35 | 000,194,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuaueng1.dll
[2011/06/03 18:39:34 | 000,174,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuaucpl.cpl
[2011/06/03 18:39:34 | 000,172,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuauclt1.exe
[2011/06/03 18:39:34 | 000,172,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuauclt1.exe
[2011/06/03 18:39:34 | 000,035,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wups.dll
[2011/06/03 18:39:34 | 000,035,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wups.dll
[2011/06/03 18:39:33 | 000,575,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll
[2011/06/03 18:39:33 | 000,465,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuapi.dll
[2011/06/03 18:39:33 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bitsprx2.dll
[2011/06/03 18:39:33 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx2.dll
[2011/06/03 18:39:33 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bitsprx3.dll
[2011/06/03 18:39:33 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx3.dll
[2011/06/03 18:39:29 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmm2res2.dll
[2011/06/03 18:39:29 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmm2eres.dll
[2011/06/03 18:39:28 | 004,256,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmm2res.dll
[2011/06/03 18:39:28 | 000,502,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmm2fxa.dll
[2011/06/03 18:39:28 | 000,325,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmm2fxb.dll
[2011/06/03 18:39:27 | 000,402,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmm2filt.dll
[2011/06/03 18:39:27 | 000,167,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmm2ae.dll
[2011/06/03 18:39:27 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmm2ext.dll
[2011/06/03 18:39:08 | 000,124,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fltmgr.sys
[2011/06/03 18:39:08 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fltMc.exe
[2011/06/03 18:39:08 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fltmc.exe
[2011/06/03 18:39:08 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fltlib.dll
[2011/06/03 18:38:43 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msado27.tlb
[2011/06/03 18:38:37 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedw.exe
[2011/06/03 18:35:58 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisui.dll
[2011/06/03 18:35:58 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisclex4.dll
[2011/06/03 18:35:58 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wamregps.dll
[2011/06/03 18:35:58 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wamregps.dll
[2011/06/03 18:35:57 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetsloc.dll
[2011/06/03 18:35:57 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetsloc.dll
[2011/06/03 18:35:57 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\iismui.dll
[2011/06/03 18:35:57 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iismui.dll
[2011/06/03 18:35:34 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\migregdb.exe
[2011/06/03 18:35:32 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\staxmem.dll
[2011/06/03 18:35:32 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\staxmem.dll
[2011/06/03 18:35:31 | 000,221,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\seo.dll
[2011/06/03 18:35:31 | 000,189,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smtpadm.dll
[2011/06/03 18:35:31 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\smtpapi.dll
[2011/06/03 18:35:31 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smtpapi.dll
[2011/06/03 18:35:31 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rwnh.dll
[2011/06/03 18:35:31 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rwnh.dll
[2011/06/03 18:35:30 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\logui.ocx
[2011/06/03 18:35:30 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\isatq.dll
[2011/06/03 18:35:30 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisext51.dll
[2011/06/03 18:35:30 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\iisext.dll
[2011/06/03 18:35:29 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\iismap.dll
[2011/06/03 18:35:29 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iismap.dll
[2011/06/03 18:35:29 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admwprox.dll
[2011/06/03 18:35:29 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\admwprox.dll
[2011/06/03 18:35:29 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\exstrace.dll
[2011/06/03 18:35:29 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\exstrace.dll
[2011/06/03 18:35:29 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\infoadmn.dll
[2011/06/03 18:35:29 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\infoadmn.dll
[2011/06/03 18:35:28 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\iisRtl.dll
[2011/06/03 18:35:28 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisrtl.dll
[2011/06/03 18:31:57 | 000,070,730 | ---- | C] (Linksys Group, Inc.) -- C:\WINDOWS\System32\drivers\lne100tx.sys
[2011/06/03 18:26:04 | 000,024,661 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\spxcoins.dll
[2011/06/03 18:26:04 | 000,024,661 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\dllcache\spxcoins.dll
[2011/06/03 18:26:04 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\irclass.dll
[2011/06/03 18:26:04 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irclass.dll
[2011/06/03 18:24:51 | 000,021,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\PANSON24.DRV
[2011/06/03 18:00:21 | 000,577,536 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxres.dll
[2011/06/03 17:58:08 | 000,274,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
[2011/06/03 17:58:08 | 000,016,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui
[2011/06/03 17:58:01 | 000,021,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wucltui.dll.mui
[2011/06/03 17:58:01 | 000,015,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll.mui
[2011/06/03 17:58:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2011/06/03 14:23:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\setup.pss
[2011/06/03 09:27:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2011/06/03 09:27:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\Provisioning
[2011/06/03 09:27:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2011/06/03 09:27:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\PeerNet
[2011/06/03 09:27:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\Network Diagnostic
[2011/06/03 09:27:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en
[2011/06/03 09:27:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\ehome
[2011/06/03 02:43:54 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\msmq
[2011/06/03 02:43:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Logfiles
[2011/06/03 02:05:30 | 000,363,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w3svc.dll
[2011/06/03 02:04:38 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ssinc51.dll
[2011/06/03 02:04:25 | 000,358,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpincl.dll
[2011/06/03 02:04:25 | 000,188,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpsmir.dll
[2011/06/03 02:04:24 | 000,456,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smtpsvc.dll
[2011/06/03 02:04:21 | 000,236,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smi2smir.exe
[2011/06/03 02:01:53 | 000,037,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\md5filt.dll
[2011/06/03 02:01:03 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\infocomm.dll
[2011/06/03 02:00:53 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iislog51.dll
[2011/06/03 02:00:24 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\httpod51.dll
[2011/06/03 02:00:23 | 000,268,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\httpext.dll
[2011/06/03 01:57:24 | 000,369,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\asp51.dll
[2011/06/03 01:56:16 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\coadmin.dll
[2011/06/03 01:56:13 | 000,290,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\adsiis51.dll
[2011/06/03 01:56:13 | 000,290,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\adsiis.dll
[2011/06/02 20:39:14 | 000,000,000 | ---D | C] -- C:\New Folder
[2011/05/28 01:03:47 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/05/28 01:01:11 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/05/28 01:01:11 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/05/28 01:01:11 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/05/28 01:01:11 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/05/28 01:01:03 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011/05/28 00:59:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/05/28 00:59:02 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/05/27 21:24:48 | 000,021,024 | ---- | C] (Microsoft Corporation) -- C:\PANSON24.DRV
[2011/05/27 21:23:02 | 000,021,024 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\kathy\Desktop\PANSON24.DRV
[2011/05/27 20:50:06 | 000,218,112 | ---- | C] (Soeperman Enterprises Ltd.) -- C:\Documents and Settings\kathy\Desktop\HijackThis.exe
[2011/05/25 13:29:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kathy\Application Data\ImgBurn
[2011/05/25 06:50:13 | 000,000,000 | ---D | C] -- C:\Program Files\ImgBurn
[2011/05/25 06:50:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ImgBurn
[2011/05/25 00:00:12 | 000,000,000 | ---D | C] -- C:\NEW PANA
[2011/05/24 23:59:33 | 000,000,000 | ---D | C] -- C:\new panasonic drivers
[2011/05/24 20:09:47 | 000,881,664 | ---- | C] (BitDefender) -- C:\Documents and Settings\All Users\Application Data\defender.e
[2011/05/24 19:31:24 | 000,880,640 | ---- | C] (BitDefender) -- C:\Documents and Settings\All Users\Application Data\defender.ex
[2011/05/11 01:22:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kathy\Desktop\New Folder
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2045/02/03 01:00:00 | 000,188,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\WINGDE.DLL
[2045/02/03 01:00:00 | 000,092,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\WING.DLL
[2045/02/03 01:00:00 | 000,092,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System\WING.DLL
[2045/02/03 01:00:00 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\WAVMIX16.DLL
[2045/02/03 01:00:00 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System\WAVMIX16.DLL
[2045/02/03 01:00:00 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\WING32.DLL
[2045/02/03 01:00:00 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System\WING32.DLL
[2045/02/03 01:00:00 | 000,006,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\WINGDIB.DRV
[2045/02/03 01:00:00 | 000,005,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\WINGPAL.WND
[2045/02/03 01:00:00 | 000,002,554 | ---- | M] () -- C:\WINDOWS\WAVEMIX.INI
[2045/02/03 01:00:00 | 000,001,966 | ---- | M] () -- C:\WINDOWS\System32\DVA.386
[2011/06/04 12:59:35 | 000,000,214 | ---- | M] () -- C:\Documents and Settings\kathy\Desktop\Internet Security Suite.url
[2011/06/04 12:42:52 | 000,000,258 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2011/06/04 12:38:09 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/06/04 11:59:33 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/06/04 03:37:44 | 000,107,808 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/06/04 02:40:10 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Wgecewatebicogic.dat
[2011/06/04 02:40:10 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Yrapalanahif.bin
[2011/06/04 02:22:07 | 000,006,218 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2011/06/03 20:53:29 | 000,001,378 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg
[2011/06/03 20:38:17 | 001,872,472 | ---- | M] () -- C:\Documents and Settings\kathy\Desktop\SmitfraudFix.exe
[2011/06/03 18:53:50 | 000,018,039 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2011/06/03 18:44:36 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2011/06/03 18:44:31 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/06/03 18:44:31 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/06/03 18:44:20 | 000,000,194 | -HS- | M] () -- C:\boot.ini
[2011/06/03 18:44:12 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2011/06/03 18:26:21 | 000,311,934 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/06/03 18:26:21 | 000,040,196 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/06/03 17:58:26 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/06/02 05:48:13 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malware Protection.lnk
[2011/05/27 23:48:02 | 000,000,020 | ---- | M] () -- C:\Documents and Settings\kathy\defogger_reenable
[2011/05/27 22:22:20 | 612,499,456 | ---- | M] () -- C:\WXPVOL_EN.ISO
[2011/05/25 06:50:13 | 000,001,582 | ---- | M] () -- C:\Documents and Settings\kathy\Application Data\Microsoft\Internet Explorer\Quick Launch\ImgBurn.lnk
[2011/05/25 06:50:13 | 000,001,564 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
[2011/05/24 21:27:11 | 000,013,312 | ---- | M] () -- C:\WINDOWS\System32\drivers\vdi3ndu1.sys
[2011/05/24 20:09:47 | 000,881,664 | ---- | M] (BitDefender) -- C:\Documents and Settings\All Users\Application Data\defender.e
[2011/05/24 19:59:06 | 000,000,240 | ---- | M] () -- C:\WINDOWS\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2011/05/24 19:31:25 | 000,880,640 | ---- | M] (BitDefender) -- C:\Documents and Settings\All Users\Application Data\defender.ex
[2011/05/23 13:06:59 | 000,002,350 | ---- | M] () -- C:\Documents and Settings\kathy\My Documents\Fell On Black Days.rtf
[2011/05/22 18:31:04 | 000,000,778 | ---- | M] () -- C:\Documents and Settings\kathy\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/22 18:31:03 | 000,000,760 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/05/20 08:58:39 | 000,000,754 | ---- | M] () -- C:\WINDOWS\WORDPAD.INI
[2011/05/19 22:45:49 | 000,002,694 | ---- | M] () -- C:\Documents and Settings\kathy\My Documents\Don't Let It Bring You Down.rtf
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/04 12:59:35 | 000,000,214 | ---- | C] () -- C:\Documents and Settings\kathy\Desktop\Internet Security Suite.url
[2011/06/03 20:53:28 | 000,001,378 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg
[2011/06/03 20:44:24 | 000,000,258 | ---- | C] () -- C:\WINDOWS\tasks\WGASetup.job
[2011/06/03 20:37:54 | 001,872,472 | ---- | C] () -- C:\Documents and Settings\kathy\Desktop\SmitfraudFix.exe
[2011/06/03 18:51:03 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2011/06/03 18:49:57 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2011/06/03 18:49:29 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2011/06/03 18:49:24 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2011/06/03 18:49:15 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2011/06/03 18:48:41 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2011/06/03 18:48:21 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2011/06/03 18:48:05 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2011/06/03 18:47:28 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2011/06/03 18:41:52 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2011/06/03 18:24:10 | 000,141,702 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat
[2011/06/03 18:24:10 | 000,110,116 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat
[2011/06/03 18:24:10 | 000,031,965 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat
[2011/06/03 18:24:10 | 000,024,209 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn7.cat
[2011/06/03 18:24:10 | 000,011,651 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn9.cat
[2011/06/03 18:24:10 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2011/06/03 18:24:10 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2011/06/03 18:24:10 | 000,007,245 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2011/06/03 18:24:09 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2011/06/03 18:24:09 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2011/06/03 18:24:09 | 000,031,281 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2011/06/03 18:24:09 | 000,013,753 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2011/06/03 18:24:09 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2011/06/03 18:24:09 | 000,009,581 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2011/06/03 18:24:09 | 000,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
[2011/06/03 18:24:08 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2011/06/03 18:24:06 | 001,042,903 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP2.CAT
[2011/06/03 18:24:04 | 002,012,670 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2011/06/03 18:24:04 | 000,502,724 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2011/05/28 01:03:48 | 000,245,920 | RHS- | C] () -- C:\cmldr
[2011/05/28 01:01:11 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/05/28 01:01:11 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/05/28 01:01:11 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/05/28 01:01:11 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/05/28 01:01:11 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/05/27 23:47:53 | 000,000,020 | ---- | C] () -- C:\Documents and Settings\kathy\defogger_reenable
[2011/05/27 23:32:10 | 612,499,456 | ---- | C] () -- C:\WXPVOL_EN.ISO
[2011/05/25 06:50:13 | 000,001,582 | ---- | C] () -- C:\Documents and Settings\kathy\Application Data\Microsoft\Internet Explorer\Quick Launch\ImgBurn.lnk
[2011/05/25 06:50:13 | 000,001,564 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ImgBurn.lnk
[2011/05/24 21:27:11 | 000,013,312 | ---- | C] () -- C:\WINDOWS\System32\drivers\vdi3ndu1.sys
[2011/05/24 19:59:06 | 000,000,240 | ---- | C] () -- C:\WINDOWS\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2011/05/24 19:31:26 | 000,000,815 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malware Protection.lnk
[2011/05/23 13:06:23 | 000,002,350 | ---- | C] () -- C:\Documents and Settings\kathy\My Documents\Fell On Black Days.rtf
[2011/05/22 18:31:03 | 000,000,766 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/05/19 21:52:21 | 000,002,694 | ---- | C] () -- C:\Documents and Settings\kathy\My Documents\Don't Let It Bring You Down.rtf
[2011/03/25 04:26:02 | 000,024,623 | -HS- | C] () -- C:\WINDOWS\System32\hhkmp.ini2
[2011/03/25 03:04:34 | 000,016,094 | -HS- | C] () -- C:\Documents and Settings\kathy\Local Settings\Application Data\6o1fpxf5dlxq47de5jb1600yp8m4cy5xnp3yiv
[2011/03/25 03:04:34 | 000,016,094 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\6o1fpxf5dlxq47de5jb1600yp8m4cy5xnp3yi
[2011/03/14 12:27:13 | 000,024,623 | -HS- | C] () -- C:\WINDOWS\System32\hhkmp.ini
[2011/01/06 05:48:22 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Wgecewatebicogic.dat
[2011/01/06 05:48:22 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Yrapalanahif.bin
[2010/09/23 18:11:32 | 000,006,218 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/10/05 19:45:04 | 000,013,824 | ---- | C] () -- C:\Documents and Settings\kathy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/06 04:34:51 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009/03/27 21:47:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NSREX.INI
[2008/10/19 13:59:44 | 000,016,332 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2008/10/02 14:05:26 | 001,040,303 | -HS- | C] () -- C:\WINDOWS\System32\lsmmwxti.ini
[2008/09/23 19:16:05 | 000,898,638 | -HS- | C] () -- C:\WINDOWS\System32\krheffkn.ini
[2008/09/20 23:23:00 | 001,001,677 | -HS- | C] () -- C:\WINDOWS\System32\fsvyjvkl.ini
[2008/09/14 23:47:16 | 001,071,071 | -HS- | C] () -- C:\WINDOWS\System32\mkhmhyfu.ini
[2008/09/14 08:49:02 | 001,078,208 | -HS- | C] () -- C:\WINDOWS\System32\kaialjnj.ini
[2008/09/13 00:22:24 | 001,078,208 | -HS- | C] () -- C:\WINDOWS\System32\xvvroeie.ini
[2008/09/12 00:24:31 | 001,180,778 | -HS- | C] () -- C:\WINDOWS\System32\gpwktclo.ini
[2008/09/12 00:18:21 | 000,000,022 | ---- | C] () -- C:\WINDOWS\pskt.ini
[2008/09/11 23:14:53 | 000,001,536 | ---- | C] () -- C:\WINDOWS\System32\TrueSoft.dat
[2008/09/11 23:14:46 | 000,000,456 | ---- | C] () -- C:\WINDOWS\System32\pthsp.dat
[2008/02/07 19:57:32 | 000,000,000 | -HS- | C] () -- C:\Documents and Settings\kathy\Application Data\0047ab9674cb9a941c4a359502ec95b0ef22087b9f0ba1e2bc.dat
[2008/02/07 18:00:49 | 001,219,783 | -HS- | C] () -- C:\WINDOWS\System32\wkijcjlh.ini
[2008/01/21 09:25:38 | 001,086,203 | -HS- | C] () -- C:\WINDOWS\System32\mdqgphut.ini
[2008/01/20 07:02:02 | 000,000,953 | ---- | C] () -- C:\WINDOWS\cookies.ini
[2008/01/19 19:18:14 | 001,073,319 | -HS- | C] () -- C:\WINDOWS\System32\arslrudn.ini
[2008/01/19 15:34:28 | 000,000,000 | ---- | C] () -- C:\WINDOWS\netscape.INI
[2008/01/19 15:14:32 | 000,635,243 | ---- | C] () -- C:\WINDOWS\ld32408.exe
[2008/01/18 19:15:21 | 001,073,352 | -HS- | C] () -- C:\WINDOWS\System32\yuavlxbo.ini
[2008/01/17 18:34:23 | 000,001,158 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2008/01/17 18:32:41 | 000,030,998 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/01/17 17:20:42 | 001,075,882 | -HS- | C] () -- C:\WINDOWS\System32\todykilb.ini
[2008/01/15 09:53:30 | 001,075,822 | -HS- | C] () -- C:\WINDOWS\System32\fstjrjib.ini
[2008/01/15 09:51:24 | 001,056,916 | -HS- | C] () -- C:\WINDOWS\System32\iuggqneb.ini
[2008/01/04 23:23:01 | 001,018,922 | -HS- | C] () -- C:\WINDOWS\System32\eftifpvt.ini
[2007/12/25 19:39:00 | 001,044,100 | -HS- | C] () -- C:\WINDOWS\System32\svlgcbsq.ini
[2007/12/22 01:37:02 | 000,991,542 | -HS- | C] () -- C:\WINDOWS\System32\kshpldbf.ini
[2007/12/16 03:16:31 | 000,000,002 | ---- | C] () -- C:\WINDOWS\System32\wapiitr.exe
[2007/05/14 17:07:03 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2007/05/10 14:12:19 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2007/05/10 14:09:34 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2007/05/10 14:09:34 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2007/05/10 14:09:34 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2007/05/10 14:08:42 | 000,000,037 | ---- | C] () -- C:\WINDOWS\sierra.ini
[2007/04/22 19:15:29 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/04/22 19:01:47 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/03/18 22:38:31 | 000,002,554 | ---- | C] () -- C:\WINDOWS\WAVEMIX.INI
[2007/03/18 22:38:30 | 000,000,169 | ---- | C] () -- C:\WINDOWS\SimTower.ini
[2007/03/16 01:50:31 | 000,000,444 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2007/01/03 16:16:16 | 000,258,048 | ---- | C] () -- C:\WINDOWS\System32\shpshftr.dll
[2007/01/03 16:16:03 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\igfxdgps.dll
[2007/01/03 16:16:02 | 000,012,351 | ---- | C] () -- C:\WINDOWS\System32\i81xcoin.dll
[2006/12/28 11:56:21 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/12/28 11:45:02 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/12/28 06:23:48 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/12/28 06:21:50 | 000,107,808 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2006/07/16 05:03:01 | 000,012,800 | ---- | C] () -- C:\WINDOWS\System32\WgaTray.exe
[2006/07/16 05:03:01 | 000,003,584 | ---- | C] () -- C:\WINDOWS\System32\WgaLogon.dll
[2005/03/25 18:42:50 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2004/08/03 18:07:22 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004/08/02 07:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2002/08/28 22:41:18 | 000,090,112 | ---- | C] () -- C:\WINDOWS\wroetmol.dll
[2001/08/23 07:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 07:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 07:00:00 | 000,311,934 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 07:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 07:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 07:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 07:00:00 | 000,040,196 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 07:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 07:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 07:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== Files - Unicode (All) ==========
[2011/06/03 18:46:39 | 000,000,000 | ---D | M](C:\WINDOWS\??sks) -- C:\WINDOWS\Τаsks
[2010/10/22 08:10:38 | 000,000,000 | ---D | M](C:\WINDOWS\System32\??sembly) -- C:\WINDOWS\System32\аѕsembly
[2010/10/22 08:10:38 | 000,000,000 | ---D | M](C:\Program Files\??stem32) -- C:\Program Files\ѕуstem32
[2010/10/22 08:10:38 | 000,000,000 | ---D | M](C:\Program Files\??stem32) -- C:\Program Files\ѕуstem32
[2010/10/17 06:30:12 | 000,000,000 | ---D | M](C:\Program Files\Common Files\F?nts) -- C:\Program Files\Common Files\Fоnts
[2010/10/17 06:30:12 | 000,000,000 | ---D | M](C:\Program Files\Common Files\F?nts) -- C:\Program Files\Common Files\Fоnts
[2010/10/15 04:40:39 | 000,000,000 | ---D | M](C:\WINDOWS\System32\M?crosoft) -- C:\WINDOWS\System32\Mіcrosoft
[2010/10/15 04:40:39 | 000,000,000 | ---D | C](C:\WINDOWS\System32\M?crosoft) -- C:\WINDOWS\System32\Mіcrosoft
[2010/09/22 16:03:25 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\??mbols) -- C:\Documents and Settings\kathy\Application Data\ѕуmbols
[2010/09/22 16:03:25 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\??mbols) -- C:\Documents and Settings\kathy\Application Data\ѕуmbols
[2010/09/21 16:08:37 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\??crosoft) -- C:\Documents and Settings\kathy\Application Data\Міcrosoft
[2010/09/21 16:08:37 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\??crosoft) -- C:\Documents and Settings\kathy\Application Data\Міcrosoft
[2010/09/20 17:02:19 | 000,000,000 | ---D | M](C:\WINDOWS\?asks) -- C:\WINDOWS\Τasks
[2010/09/20 17:02:19 | 000,000,000 | ---D | C](C:\WINDOWS\?asks) -- C:\WINDOWS\Τasks
[2010/09/16 11:48:31 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\My Documents\?ecurity) -- C:\Documents and Settings\kathy\My Documents\ѕecurity
[2010/09/16 11:48:31 | 000,000,000 | ---D | C](C:\Documents and Settings\kathy\My Documents\?ecurity) -- C:\Documents and Settings\kathy\My Documents\ѕecurity
[2010/09/08 08:41:18 | 000,000,000 | ---D | M](C:\Program Files\Common Files\a?sembly) -- C:\Program Files\Common Files\aѕsembly
[2010/09/08 08:41:18 | 000,000,000 | ---D | M](C:\Program Files\Common Files\a?sembly) -- C:\Program Files\Common Files\aѕsembly
[2010/09/07 07:31:37 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?ppPatch) -- C:\Program Files\Common Files\ΑppPatch
[2010/09/07 07:31:37 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?ppPatch) -- C:\Program Files\Common Files\ΑppPatch
[2010/09/06 07:17:32 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\??mantec) -- C:\Documents and Settings\kathy\Application Data\Ѕуmantec
[2010/09/06 07:17:32 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\??mantec) -- C:\Documents and Settings\kathy\Application Data\Ѕуmantec
[2010/09/05 07:04:57 | 000,000,000 | ---D | M](C:\Program Files\Common Files\??pPatch) -- C:\Program Files\Common Files\ΑрpPatch
[2010/09/05 07:04:57 | 000,000,000 | ---D | M](C:\Program Files\Common Files\??pPatch) -- C:\Program Files\Common Files\ΑрpPatch
[2010/09/03 07:25:13 | 000,000,000 | ---D | M](C:\Program Files\?racle) -- C:\Program Files\Οracle
[2010/09/03 07:25:13 | 000,000,000 | ---D | M](C:\Program Files\?racle) -- C:\Program Files\Οracle
[2010/09/01 06:57:38 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?racle) -- C:\Documents and Settings\kathy\Application Data\Οracle
[2010/09/01 06:57:38 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?racle) -- C:\Documents and Settings\kathy\Application Data\Οracle
[2010/08/30 05:46:13 | 000,000,000 | ---D | M](C:\WINDOWS\System32\??pPatch) -- C:\WINDOWS\System32\АрpPatch
[2010/08/30 05:46:13 | 000,000,000 | ---D | C](C:\WINDOWS\System32\??pPatch) -- C:\WINDOWS\System32\АрpPatch
[2010/08/29 05:58:15 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\My Documents\?icrosoft) -- C:\Documents and Settings\kathy\My Documents\Μicrosoft
[2010/08/29 05:58:15 | 000,000,000 | ---D | C](C:\Documents and Settings\kathy\My Documents\?icrosoft) -- C:\Documents and Settings\kathy\My Documents\Μicrosoft
[2010/08/28 06:46:27 | 000,000,000 | ---D | M](C:\WINDOWS\System32\??crosoft.NET) -- C:\WINDOWS\System32\Μіcrosoft.NET
[2010/08/28 06:46:27 | 000,000,000 | ---D | C](C:\WINDOWS\System32\??crosoft.NET) -- C:\WINDOWS\System32\Μіcrosoft.NET
[2010/07/03 05:05:52 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\My Documents\?ymbols) -- C:\Documents and Settings\kathy\My Documents\ѕymbols
[2010/06/29 18:01:49 | 000,000,000 | ---D | M](C:\Program Files\M?crosoft.NET) -- C:\Program Files\Mіcrosoft.NET
[2010/06/29 18:01:49 | 000,000,000 | ---D | M](C:\Program Files\M?crosoft.NET) -- C:\Program Files\Mіcrosoft.NET
[2010/06/23 15:48:55 | 000,000,000 | ---D | M](C:\WINDOWS\System32\??sks) -- C:\WINDOWS\System32\Τаsks
[2010/06/23 15:48:55 | 000,000,000 | ---D | C](C:\WINDOWS\System32\??sks) -- C:\WINDOWS\System32\Τаsks
[2010/06/23 15:48:08 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?dobe) -- C:\Documents and Settings\kathy\Application Data\Αdobe
[2010/06/23 15:48:08 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?dobe) -- C:\Documents and Settings\kathy\Application Data\Αdobe
[2010/06/13 07:47:47 | 000,000,000 | ---D | M](C:\WINDOWS\??sembly) -- C:\WINDOWS\аѕsembly
[2010/06/13 07:47:47 | 000,000,000 | ---D | C](C:\WINDOWS\??sembly) -- C:\WINDOWS\аѕsembly
[2010/06/05 02:24:47 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\My Documents\??curity) -- C:\Documents and Settings\kathy\My Documents\ѕеcurity
[2010/06/05 02:24:47 | 000,000,000 | ---D | C](C:\Documents and Settings\kathy\My Documents\??curity) -- C:\Documents and Settings\kathy\My Documents\ѕеcurity
[2010/05/18 23:35:13 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?ecurity) -- C:\Documents and Settings\kathy\Application Data\ѕecurity
[2010/05/18 23:35:13 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?ecurity) -- C:\Documents and Settings\kathy\Application Data\ѕecurity
[2010/05/18 23:33:55 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?icrosoft.NET) -- C:\Documents and Settings\kathy\Application Data\Мicrosoft.NET
[2010/05/18 23:33:55 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?icrosoft.NET) -- C:\Documents and Settings\kathy\Application Data\Мicrosoft.NET
[2010/05/18 02:32:56 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\M?crosoft) -- C:\Documents and Settings\kathy\Application Data\Mіcrosoft
[2010/05/18 02:32:56 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\M?crosoft) -- C:\Documents and Settings\kathy\Application Data\Mіcrosoft
[2010/05/16 00:57:07 | 000,000,000 | ---D | M](C:\WINDOWS\?racle) -- C:\WINDOWS\Οracle
[2010/05/16 00:57:07 | 000,000,000 | ---D | C](C:\WINDOWS\?racle) -- C:\WINDOWS\Οracle
[2010/05/14 00:42:07 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?ecurity) -- C:\Program Files\Common Files\ѕecurity
[2010/05/14 00:42:07 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?ecurity) -- C:\Program Files\Common Files\ѕecurity
[2010/05/10 23:42:03 | 000,000,000 | ---D | M](C:\Program Files\Common Files\s?stem) -- C:\Program Files\Common Files\sуstem
[2010/05/10 23:42:03 | 000,000,000 | ---D | M](C:\Program Files\Common Files\s?stem) -- C:\Program Files\Common Files\sуstem
[2010/05/10 00:43:08 | 000,000,000 | ---D | M](C:\Program Files\??mbols) -- C:\Program Files\ѕуmbols
[2010/05/10 00:43:08 | 000,000,000 | ---D | M](C:\Program Files\??mbols) -- C:\Program Files\ѕуmbols
[2010/05/09 00:26:32 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?ystem) -- C:\Documents and Settings\kathy\Application Data\ѕystem
[2010/05/09 00:26:32 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?ystem) -- C:\Documents and Settings\kathy\Application Data\ѕystem
[2010/05/08 00:08:45 | 000,000,000 | ---D | M](C:\WINDOWS\?ystem) -- C:\WINDOWS\ѕystem
[2010/05/08 00:08:45 | 000,000,000 | ---D | C](C:\WINDOWS\?ystem) -- C:\WINDOWS\ѕystem
[2010/05/06 01:15:35 | 000,000,000 | ---D | M](C:\Program Files\Common Files\??sembly) -- C:\Program Files\Common Files\аѕsembly
[2010/05/06 01:15:35 | 000,000,000 | ---D | M](C:\Program Files\Common Files\??sembly) -- C:\Program Files\Common Files\аѕsembly
[2010/05/05 01:56:44 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\F?nts) -- C:\Documents and Settings\kathy\Application Data\Fοnts
[2010/05/05 01:56:44 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\F?nts) -- C:\Documents and Settings\kathy\Application Data\Fοnts
[2010/05/04 00:58:52 | 000,000,000 | ---D | M](C:\Program Files\?icrosoft.NET) -- C:\Program Files\Μicrosoft.NET
[2010/05/04 00:58:52 | 000,000,000 | ---D | M](C:\Program Files\?icrosoft.NET) -- C:\Program Files\Μicrosoft.NET
[2010/05/02 20:18:14 | 000,000,000 | ---D | M](C:\WINDOWS\??crosoft) -- C:\WINDOWS\Μіcrosoft
[2010/05/02 20:18:14 | 000,000,000 | ---D | C](C:\WINDOWS\??crosoft) -- C:\WINDOWS\Μіcrosoft
[2010/04/30 20:09:01 | 000,000,000 | ---D | M](C:\WINDOWS\System32\??stem) -- C:\WINDOWS\System32\ѕуstem
[2010/04/30 20:09:01 | 000,000,000 | ---D | C](C:\WINDOWS\System32\??stem) -- C:\WINDOWS\System32\ѕуstem
[2010/04/17 18:55:05 | 000,000,000 | ---D | M](C:\Program Files\??pPatch) -- C:\Program Files\ΑрpPatch
[2010/04/17 18:55:05 | 000,000,000 | ---D | M](C:\Program Files\??pPatch) -- C:\Program Files\ΑрpPatch
[2010/02/26 09:10:14 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?asks) -- C:\Documents and Settings\kathy\Application Data\Τasks
[2010/02/26 09:10:14 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?asks) -- C:\Documents and Settings\kathy\Application Data\Τasks
[2010/02/24 08:35:19 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?ppPatch) -- C:\WINDOWS\System32\АppPatch
[2010/02/24 08:35:19 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?ppPatch) -- C:\WINDOWS\System32\АppPatch
[2010/02/23 08:39:26 | 000,000,000 | ---D | M](C:\Program Files\T?sks) -- C:\Program Files\Tаsks
[2010/02/23 08:39:26 | 000,000,000 | ---D | M](C:\Program Files\T?sks) -- C:\Program Files\Tаsks
[2010/02/21 06:50:41 | 000,000,000 | ---D | M](C:\Program Files\Common Files\s?curity) -- C:\Program Files\Common Files\sеcurity
[2010/02/21 06:50:41 | 000,000,000 | ---D | M](C:\Program Files\Common Files\s?curity) -- C:\Program Files\Common Files\sеcurity
[2010/02/20 06:32:01 | 000,000,000 | ---D | M](C:\WINDOWS\F?nts) -- C:\WINDOWS\Fοnts
[2010/02/20 06:32:01 | 000,000,000 | ---D | C](C:\WINDOWS\F?nts) -- C:\WINDOWS\Fοnts
[2010/02/19 05:32:13 | 000,000,000 | ---D | M](C:\WINDOWS\?dobe) -- C:\WINDOWS\Αdobe
[2010/02/19 05:32:13 | 000,000,000 | ---D | C](C:\WINDOWS\?dobe) -- C:\WINDOWS\Αdobe
[2010/02/17 05:43:00 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\s?stem32) -- C:\Documents and Settings\kathy\Application Data\sуstem32
[2010/02/17 05:43:00 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\s?stem32) -- C:\Documents and Settings\kathy\Application Data\sуstem32
[2010/02/16 06:26:06 | 000,000,000 | ---D | M](C:\WINDOWS\A?pPatch) -- C:\WINDOWS\AрpPatch
[2010/02/16 06:26:06 | 000,000,000 | ---D | C](C:\WINDOWS\A?pPatch) -- C:\WINDOWS\AрpPatch
[2010/01/17 11:15:45 | 000,000,000 | ---D | M](C:\WINDOWS\s?mbols) -- C:\WINDOWS\sуmbols
[2010/01/17 11:15:45 | 000,000,000 | ---D | C](C:\WINDOWS\s?mbols) -- C:\WINDOWS\sуmbols
[2010/01/16 11:53:38 | 000,000,000 | ---D | M](C:\WINDOWS\System32\s?curity) -- C:\WINDOWS\System32\sеcurity
[2010/01/16 11:53:38 | 000,000,000 | ---D | C](C:\WINDOWS\System32\s?curity) -- C:\WINDOWS\System32\sеcurity
[2010/01/15 10:58:51 | 000,000,000 | ---D | M](C:\Program Files\?dobe) -- C:\Program Files\Αdobe
[2010/01/15 10:58:51 | 000,000,000 | ---D | M](C:\Program Files\?dobe) -- C:\Program Files\Αdobe
[2010/01/14 10:43:30 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?dobe) -- C:\WINDOWS\System32\Αdobe
[2010/01/14 10:43:30 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?dobe) -- C:\WINDOWS\System32\Αdobe
[2010/01/13 09:49:57 | 000,000,000 | ---D | M](C:\Program Files\Common Files\W?nSxS) -- C:\Program Files\Common Files\WіnSxS
[2010/01/13 09:49:57 | 000,000,000 | ---D | M](C:\Program Files\Common Files\W?nSxS) -- C:\Program Files\Common Files\WіnSxS
[2010/01/10 10:38:00 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?racle) -- C:\Documents and Settings\kathy\Application Data\Оracle
[2010/01/10 10:38:00 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?racle) -- C:\Documents and Settings\kathy\Application Data\Оracle
[2010/01/09 10:58:35 | 000,000,000 | ---D | M](C:\Program Files\Common Files\??stem32) -- C:\Program Files\Common Files\ѕуstem32
[2010/01/09 10:58:35 | 000,000,000 | ---D | M](C:\Program Files\Common Files\??stem32) -- C:\Program Files\Common Files\ѕуstem32
[2010/01/08 11:27:09 | 000,000,000 | ---D | M](C:\Program Files\??pPatch) -- C:\Program Files\АрpPatch
[2010/01/08 11:27:09 | 000,000,000 | ---D | M](C:\Program Files\??pPatch) -- C:\Program Files\АрpPatch
[2010/01/05 12:20:04 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?asks) -- C:\WINDOWS\System32\Тasks
[2010/01/05 12:20:04 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?asks) -- C:\WINDOWS\System32\Тasks
[2010/01/02 10:50:16 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\??stem32) -- C:\Documents and Settings\kathy\Application Data\ѕуstem32
[2010/01/02 10:50:16 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\??stem32) -- C:\Documents and Settings\kathy\Application Data\ѕуstem32
[2009/12/31 10:33:48 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\My Documents\??pPatch) -- C:\Documents and Settings\kathy\My Documents\ΑрpPatch
[2009/12/31 10:33:48 | 000,000,000 | ---D | C](C:\Documents and Settings\kathy\My Documents\??pPatch) -- C:\Documents and Settings\kathy\My Documents\ΑрpPatch
[2009/12/30 09:46:11 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\My Documents\F?nts) -- C:\Documents and Settings\kathy\My Documents\Fоnts
[2009/12/30 09:46:11 | 000,000,000 | ---D | C](C:\Documents and Settings\kathy\My Documents\F?nts) -- C:\Documents and Settings\kathy\My Documents\Fоnts
[2009/12/28 10:27:46 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?icrosoft) -- C:\Documents and Settings\kathy\Application Data\Μicrosoft
[2009/12/28 10:27:46 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?icrosoft) -- C:\Documents and Settings\kathy\Application Data\Μicrosoft
[2009/12/24 08:02:41 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\s?mbols) -- C:\Documents and Settings\kathy\Application Data\sуmbols
[2009/12/24 08:02:41 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\s?mbols) -- C:\Documents and Settings\kathy\Application Data\sуmbols
[2009/12/23 07:13:11 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?dobe) -- C:\Documents and Settings\kathy\Application Data\Аdobe
[2009/12/23 07:13:11 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?dobe) -- C:\Documents and Settings\kathy\Application Data\Аdobe
[2009/12/22 06:29:09 | 000,000,000 | ---D | M](C:\WINDOWS\??mbols) -- C:\WINDOWS\ѕуmbols
[2009/12/22 06:29:09 | 000,000,000 | ---D | C](C:\WINDOWS\??mbols) -- C:\WINDOWS\ѕуmbols
[2009/12/18 06:22:22 | 000,000,000 | ---D | M](C:\Program Files\??crosoft.NET) -- C:\Program Files\Міcrosoft.NET
[2009/12/18 06:22:22 | 000,000,000 | ---D | M](C:\Program Files\??crosoft.NET) -- C:\Program Files\Міcrosoft.NET
[2009/12/17 05:57:41 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?ymantec) -- C:\Documents and Settings\kathy\Application Data\Ѕymantec
[2009/12/17 05:57:41 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?ymantec) -- C:\Documents and Settings\kathy\Application Data\Ѕymantec
[2009/11/28 05:06:16 | 000,000,000 | ---D | M](C:\Program Files\M?crosoft) -- C:\Program Files\Mіcrosoft
[2009/11/28 05:06:16 | 000,000,000 | ---D | M](C:\Program Files\M?crosoft) -- C:\Program Files\Mіcrosoft
[2009/11/27 04:27:26 | 000,000,000 | ---D | M](C:\Program Files\?asks) -- C:\Program Files\Тasks
[2009/11/27 04:27:26 | 000,000,000 | ---D | M](C:\Program Files\?asks) -- C:\Program Files\Тasks
[2009/11/20 19:42:56 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\My Documents\S?mantec) -- C:\Documents and Settings\kathy\My Documents\Sуmantec
[2009/11/20 19:42:56 | 000,000,000 | ---D | C](C:\Documents and Settings\kathy\My Documents\S?mantec) -- C:\Documents and Settings\kathy\My Documents\Sуmantec
[2009/11/12 20:23:33 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?racle) -- C:\Program Files\Common Files\Οracle
[2009/11/12 20:23:33 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?racle) -- C:\Program Files\Common Files\Οracle
[2009/10/24 13:36:50 | 000,000,000 | ---D | M](C:\Program Files\Common Files\F?nts) -- C:\Program Files\Common Files\Fοnts
[2009/10/24 13:36:50 | 000,000,000 | ---D | M](C:\Program Files\Common Files\F?nts) -- C:\Program Files\Common Files\Fοnts
[2009/09/28 06:45:09 | 000,000,000 | ---D | M](C:\Program Files\??stem) -- C:\Program Files\ѕуstem
[2009/09/28 06:45:09 | 000,000,000 | ---D | M](C:\Program Files\??stem) -- C:\Program Files\ѕуstem
[2009/09/26 01:38:29 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\s?curity) -- C:\Documents and Settings\kathy\Application Data\sеcurity
[2009/09/26 01:38:29 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\s?curity) -- C:\Documents and Settings\kathy\Application Data\sеcurity
[2009/09/24 02:29:40 | 000,000,000 | ---D | C](C:\WINDOWS\??sks) -- C:\WINDOWS\Τаsks
[2009/09/20 12:55:25 | 000,000,000 | ---D | M](C:\WINDOWS\M?crosoft) -- C:\WINDOWS\Mіcrosoft
[2009/09/20 12:55:25 | 000,000,000 | ---D | C](C:\WINDOWS\M?crosoft) -- C:\WINDOWS\Mіcrosoft
[2009/09/20 12:33:08 | 000,000,000 | ---D | M](C:\Program Files\??mantec) -- C:\Program Files\Ѕуmantec
[2009/09/20 12:33:08 | 000,000,000 | ---D | M](C:\Program Files\??mantec) -- C:\Program Files\Ѕуmantec
[2009/09/06 00:32:19 | 000,000,000 | ---D | M](C:\Program Files\s?curity) -- C:\Program Files\sеcurity
[2009/09/06 00:32:19 | 000,000,000 | ---D | M](C:\Program Files\s?curity) -- C:\Program Files\sеcurity
[2009/09/04 13:22:47 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?ymbols) -- C:\Documents and Settings\kathy\Application Data\ѕymbols
[2009/09/04 13:22:47 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\?ymbols) -- C:\Documents and Settings\kathy\Application Data\ѕymbols
[2009/08/24 16:41:52 | 000,000,000 | ---D | M](C:\WINDOWS\??crosoft) -- C:\WINDOWS\Міcrosoft
[2009/08/24 16:41:52 | 000,000,000 | ---D | C](C:\WINDOWS\??crosoft) -- C:\WINDOWS\Міcrosoft
[2009/08/15 07:16:01 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?ystem) -- C:\WINDOWS\System32\ѕystem
[2009/08/15 07:16:01 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?ystem) -- C:\WINDOWS\System32\ѕystem
[2009/08/08 15:45:39 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?dobe) -- C:\WINDOWS\System32\Аdobe
[2009/08/08 15:45:39 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?dobe) -- C:\WINDOWS\System32\Аdobe
[2009/08/07 16:12:36 | 000,000,000 | ---D | C](C:\WINDOWS\System32\??sembly) -- C:\WINDOWS\System32\аѕsembly
[2009/08/06 08:19:28 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\My Documents\?ystem) -- C:\Documents and Settings\kathy\My Documents\ѕystem
[2009/08/06 08:19:28 | 000,000,000 | ---D | C](C:\Documents and Settings\kathy\My Documents\?ystem) -- C:\Documents and Settings\kathy\My Documents\ѕystem
[2009/07/25 11:14:51 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\My Documents\T?sks) -- C:\Documents and Settings\kathy\My Documents\Tаsks
[2009/07/25 11:14:51 | 000,000,000 | ---D | C](C:\Documents and Settings\kathy\My Documents\T?sks) -- C:\Documents and Settings\kathy\My Documents\Tаsks
[2009/07/20 22:31:08 | 000,000,000 | ---D | M](C:\Program Files\F?nts) -- C:\Program Files\Fоnts
[2009/07/20 22:31:08 | 000,000,000 | ---D | M](C:\Program Files\F?nts) -- C:\Program Files\Fоnts
[2009/07/14 00:15:26 | 000,000,000 | ---D | M](C:\WINDOWS\System32\??crosoft.NET) -- C:\WINDOWS\System32\Міcrosoft.NET
[2009/07/14 00:15:26 | 000,000,000 | ---D | C](C:\WINDOWS\System32\??crosoft.NET) -- C:\WINDOWS\System32\Міcrosoft.NET
[2009/07/09 22:24:04 | 000,000,000 | ---D | M](C:\WINDOWS\System32\s?mbols) -- C:\WINDOWS\System32\sуmbols
[2009/07/09 22:24:04 | 000,000,000 | ---D | C](C:\WINDOWS\System32\s?mbols) -- C:\WINDOWS\System32\sуmbols
[2009/07/07 12:40:35 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?ymantec) -- C:\Program Files\Common Files\Ѕymantec
[2009/07/07 12:40:35 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?ymantec) -- C:\Program Files\Common Files\Ѕymantec
[2009/06/30 17:37:15 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\??sembly) -- C:\Documents and Settings\kathy\Application Data\аѕsembly
[2009/06/30 17:37:15 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\??sembly) -- C:\Documents and Settings\kathy\Application Data\аѕsembly
[2009/06/29 03:11:58 | 000,000,000 | ---D | M](C:\Program Files\??crosoft.NET) -- C:\Program Files\Μіcrosoft.NET
[2009/06/29 03:11:58 | 000,000,000 | ---D | M](C:\Program Files\??crosoft.NET) -- C:\Program Files\Μіcrosoft.NET
[2009/06/15 21:36:18 | 000,000,000 | ---D | M](C:\Program Files\Common Files\??pPatch) -- C:\Program Files\Common Files\АрpPatch
[2009/06/15 21:36:18 | 000,000,000 | ---D | M](C:\Program Files\Common Files\??pPatch) -- C:\Program Files\Common Files\АрpPatch
[2009/06/05 18:39:00 | 000,000,000 | ---D | M](C:\Program Files\?icrosoft) -- C:\Program Files\Мicrosoft
[2009/06/05 18:39:00 | 000,000,000 | ---D | M](C:\Program Files\?icrosoft) -- C:\Program Files\Мicrosoft
[2009/05/31 14:40:25 | 000,000,000 | ---D | M](C:\Program Files\?ppPatch) -- C:\Program Files\ΑppPatch
[2009/05/31 14:40:25 | 000,000,000 | ---D | M](C:\Program Files\?ppPatch) -- C:\Program Files\ΑppPatch
[2009/05/16 01:03:29 | 000,000,000 | ---D | M](C:\Program Files\Common Files\??crosoft.NET) -- C:\Program Files\Common Files\Міcrosoft.NET
[2009/05/16 01:03:29 | 000,000,000 | ---D | M](C:\Program Files\Common Files\??crosoft.NET) -- C:\Program Files\Common Files\Міcrosoft.NET
[2009/05/04 11:44:27 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?ystem) -- C:\Program Files\Common Files\ѕystem
[2009/05/04 11:44:27 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?ystem) -- C:\Program Files\Common Files\ѕystem
[2009/04/25 10:50:40 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\??crosoft.NET) -- C:\Documents and Settings\kathy\Application Data\Міcrosoft.NET
[2009/04/25 10:50:40 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\??crosoft.NET) -- C:\Documents and Settings\kathy\Application Data\Міcrosoft.NET
[2009/04/19 17:54:28 | 000,000,000 | ---D | M](C:\Program Files\Common Files\??stem) -- C:\Program Files\Common Files\ѕуstem
[2009/04/19 17:54:28 | 000,000,000 | ---D | M](C:\Program Files\Common Files\??stem) -- C:\Program Files\Common Files\ѕуstem
[2009/03/28 21:02:03 | 000,000,000 | ---D | M](C:\WINDOWS\System32\??mantec) -- C:\WINDOWS\System32\Ѕуmantec
[2009/03/28 21:02:03 | 000,000,000 | ---D | C](C:\WINDOWS\System32\??mantec) -- C:\WINDOWS\System32\Ѕуmantec
[2009/03/25 11:44:32 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?racle) -- C:\WINDOWS\System32\Оracle
[2009/03/24 18:28:47 | 000,000,000 | ---D | M](C:\Program Files\Common Files\??mantec) -- C:\Program Files\Common Files\Ѕуmantec
[2009/03/24 18:28:47 | 000,000,000 | ---D | M](C:\Program Files\Common Files\??mantec) -- C:\Program Files\Common Files\Ѕуmantec
[2009/03/23 18:22:06 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?racle) -- C:\WINDOWS\System32\Оracle
[2009/03/23 18:21:17 | 000,000,000 | ---D | M](C:\Program Files\Common Files\M?crosoft.NET) -- C:\Program Files\Common Files\Mіcrosoft.NET
[2009/03/23 18:21:17 | 000,000,000 | ---D | M](C:\Program Files\Common Files\M?crosoft.NET) -- C:\Program Files\Common Files\Mіcrosoft.NET
[2009/03/22 15:10:26 | 000,000,000 | ---D | M](C:\Program Files\??crosoft) -- C:\Program Files\Μіcrosoft
[2009/03/22 15:10:26 | 000,000,000 | ---D | M](C:\Program Files\??crosoft) -- C:\Program Files\Μіcrosoft
[2009/03/15 18:12:06 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\My Documents\?dobe) -- C:\Documents and Settings\kathy\My Documents\Αdobe
[2009/03/14 01:28:58 | 000,000,000 | ---D | M](C:\WINDOWS\System32\F?nts) -- C:\WINDOWS\System32\Fοnts
[2009/03/14 01:28:58 | 000,000,000 | ---D | C](C:\WINDOWS\System32\F?nts) -- C:\WINDOWS\System32\Fοnts
[2009/03/07 17:03:11 | 000,000,000 | ---D | M](C:\Program Files\?dobe) -- C:\Program Files\Аdobe
[2009/03/07 17:03:11 | 000,000,000 | ---D | M](C:\Program Files\?dobe) -- C:\Program Files\Аdobe
[2009/02/28 20:10:14 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?ppPatch) -- C:\Program Files\Common Files\АppPatch
[2009/02/28 20:10:14 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?ppPatch) -- C:\Program Files\Common Files\АppPatch
[2009/02/28 18:37:21 | 000,000,000 | ---D | C](C:\Documents and Settings\kathy\My Documents\?dobe) -- C:\Documents and Settings\kathy\My Documents\Αdobe
[2009/02/14 18:49:42 | 000,000,000 | ---D | M](C:\Program Files\Common Files\s?mbols) -- C:\Program Files\Common Files\sуmbols
[2009/02/14 18:49:42 | 000,000,000 | ---D | M](C:\Program Files\Common Files\s?mbols) -- C:\Program Files\Common Files\sуmbols
[2009/02/09 21:13:41 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?dobe) -- C:\Program Files\Common Files\Αdobe
[2009/02/09 21:13:41 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?dobe) -- C:\Program Files\Common Files\Αdobe
[2009/02/08 21:27:01 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?ymbols) -- C:\Program Files\Common Files\ѕymbols
[2009/02/08 21:27:01 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?ymbols) -- C:\Program Files\Common Files\ѕymbols
[2009/02/02 21:35:51 | 000,000,000 | ---D | M](C:\WINDOWS\s?curity) -- C:\WINDOWS\sеcurity
[2009/01/25 20:33:16 | 000,000,000 | ---D | C](C:\WINDOWS\s?curity) -- C:\WINDOWS\sеcurity
[2009/01/22 01:15:18 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?racle) -- C:\Program Files\Common Files\Оracle
[2009/01/22 01:15:18 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?racle) -- C:\Program Files\Common Files\Оracle
[2009/01/21 21:35:48 | 000,000,000 | ---D | M](C:\Program Files\F?nts) -- C:\Program Files\Fοnts
[2009/01/21 21:35:48 | 000,000,000 | ---D | M](C:\Program Files\F?nts) -- C:\Program Files\Fοnts
[2009/01/19 07:36:16 | 000,000,000 | ---D | M](C:\WINDOWS\?ppPatch) -- C:\WINDOWS\ΑppPatch
[2009/01/18 18:35:22 | 000,000,000 | ---D | M](C:\Program Files\A?pPatch) -- C:\Program Files\AрpPatch
[2009/01/18 18:35:22 | 000,000,000 | ---D | M](C:\Program Files\A?pPatch) -- C:\Program Files\AрpPatch
[2009/01/17 11:40:47 | 000,000,000 | ---D | C](C:\WINDOWS\?ppPatch) -- C:\WINDOWS\ΑppPatch
[2009/01/17 11:39:59 | 000,000,000 | ---D | M](C:\WINDOWS\System32\W?nSxS) -- C:\WINDOWS\System32\WіnSxS
[2009/01/11 18:30:51 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?ystem32) -- C:\WINDOWS\System32\ѕystem32
[2009/01/10 21:41:35 | 000,000,000 | ---D | C](C:\WINDOWS\System32\W?nSxS) -- C:\WINDOWS\System32\WіnSxS
[2009/01/08 05:36:16 | 000,000,000 | ---D | M](C:\WINDOWS\??curity) -- C:\WINDOWS\ѕеcurity
[2009/01/05 18:19:29 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?ystem32) -- C:\WINDOWS\System32\ѕystem32
[2009/01/05 16:36:00 | 000,000,000 | ---D | M](C:\Program Files\Common Files\??curity) -- C:\Program Files\Common Files\ѕеcurity
[2009/01/05 16:36:00 | 000,000,000 | ---D | M](C:\Program Files\Common Files\??curity) -- C:\Program Files\Common Files\ѕеcurity
[2009/01/04 17:13:27 | 000,000,000 | ---D | C](C:\WINDOWS\??curity) -- C:\WINDOWS\ѕеcurity
[2009/01/03 01:33:29 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\My Documents\?racle) -- C:\Documents and Settings\kathy\My Documents\Οracle
[2008/12/31 20:59:08 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\F?nts) -- C:\Documents and Settings\kathy\Application Data\Fоnts
[2008/12/31 20:59:08 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\F?nts) -- C:\Documents and Settings\kathy\Application Data\Fоnts
[2008/12/25 13:09:31 | 000,000,000 | ---D | M](C:\Program Files\?ystem) -- C:\Program Files\ѕystem
[2008/12/25 13:09:31 | 000,000,000 | ---D | M](C:\Program Files\?ystem) -- C:\Program Files\ѕystem
[2008/12/22 02:51:36 | 000,000,000 | ---D | M](C:\Program Files\?ystem32) -- C:\Program Files\ѕystem32
[2008/12/22 02:51:36 | 000,000,000 | ---D | M](C:\Program Files\?ystem32) -- C:\Program Files\ѕystem32
[2008/12/22 02:50:38 | 000,000,000 | ---D | M](C:\WINDOWS\?icrosoft.NET) -- C:\WINDOWS\Μicrosoft.NET
[2008/12/17 12:41:16 | 000,000,000 | ---D | M](C:\Program Files\s?stem32) -- C:\Program Files\sуstem32
[2008/12/17 12:41:16 | 000,000,000 | ---D | M](C:\Program Files\s?stem32) -- C:\Program Files\sуstem32
[2008/12/16 12:12:11 | 000,000,000 | ---D | C](C:\WINDOWS\?icrosoft.NET) -- C:\WINDOWS\Μicrosoft.NET
[2008/12/16 12:11:09 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\??crosoft) -- C:\Documents and Settings\kathy\Application Data\Μіcrosoft
[2008/12/16 12:11:09 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\??crosoft) -- C:\Documents and Settings\kathy\Application Data\Μіcrosoft
[2008/12/11 22:23:52 | 000,000,000 | ---D | M](C:\WINDOWS\?ymbols) -- C:\WINDOWS\ѕymbols
[2008/12/11 22:23:52 | 000,000,000 | ---D | C](C:\WINDOWS\?ymbols) -- C:\WINDOWS\ѕymbols
[2008/12/11 21:42:45 | 000,000,000 | ---D | M](C:\Program Files\?ymbols) -- C:\Program Files\ѕymbols
[2008/12/11 21:42:45 | 000,000,000 | ---D | M](C:\Program Files\?ymbols) -- C:\Program Files\ѕymbols
[2008/12/06 00:26:23 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?icrosoft) -- C:\WINDOWS\System32\Мicrosoft
[2008/12/05 11:54:06 | 000,000,000 | ---D | M](C:\WINDOWS\??pPatch) -- C:\WINDOWS\АрpPatch
[2008/12/05 11:54:06 | 000,000,000 | ---D | C](C:\WINDOWS\??pPatch) -- C:\WINDOWS\АрpPatch
[2008/11/30 21:16:37 | 000,000,000 | ---D | M](C:\Program Files\?ymantec) -- C:\Program Files\Ѕymantec
[2008/11/30 21:16:37 | 000,000,000 | ---D | M](C:\Program Files\?ymantec) -- C:\Program Files\Ѕymantec
[2008/11/29 18:57:52 | 000,000,000 | ---D | M](C:\Program Files\S?mantec) -- C:\Program Files\Sуmantec
[2008/11/29 18:57:52 | 000,000,000 | ---D | M](C:\Program Files\S?mantec) -- C:\Program Files\Sуmantec
[2008/11/27 21:17:23 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\A?pPatch) -- C:\Documents and Settings\kathy\Application Data\AрpPatch
[2008/11/27 21:17:23 | 000,000,000 | ---D | M](C:\Documents and Settings\kathy\Application Data\A?pPatch) -- C:\Documents and Settings\kathy\Application Data\AрpPatch
[2008/11/26 21:05:29 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?icrosoft) -- C:\WINDOWS\System32\Мicrosoft
[2008/11/24 21:11:47 | 000,000,000 | ---D | M](C:\Program Files\?ecurity) -- C:\Program Files\ѕecurity
[2008/11/24 21:11:47 | 000,000,000 | ---D | M](C:\Program Files\?ecurity) -- C:\Program Files\ѕecurity
[2008/11/17 21:17:25 | 000,000,000 | ---D | M](C:\WINDOWS\W?nSxS) -- C:\WINDOWS\WіnSxS
[2008/11/17 21:17:25 | 000,000,000 | ---D | C](C:\WINDOWS\W?nSxS) -- C:\WINDOWS\WіnSxS
[2008/11/16 15:17:06 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?asks) -- C:\WINDOWS\System32\Τasks
[2008/11/16 15:17:06 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?asks) -- C:\WINDOWS\System32\Τasks
[2008/11/15 14:56:23 | 000,000,000 | ---D | C](C:\Documents and Settings\kathy\My Documents\?racle) -- C:\Documents and Settings\kathy\My Documents\Οracle
[2008/11/13 17:15:51 | 000,000,000 | ---D | M](C:\WINDOWS\?asks) -- C:\WINDOWS\Тasks
[2008/02/07 18:00:02 | 000,000,000 | ---D | M](C:\WINDOWS\System32\??curity) -- C:\WINDOWS\System32\ѕеcurity
[2008/02/07 18:00:02 | 000,000,000 | ---D | C](C:\WINDOWS\System32\??curity) -- C:\WINDOWS\System32\ѕеcurity
[2008/01/20 00:08:13 | 000,000,000 | ---D | C](C:\WINDOWS\?asks) -- C:\WINDOWS\Тasks
[2008/01/20 00:08:02 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?ystem32) -- C:\Program Files\Common Files\ѕystem32
[2008/01/20 00:08:02 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?ystem32) -- C:\Program Files\Common Files\ѕystem32
[2008/01/17 18:52:11 | 000,000,000 | ---D | M](C:\WINDOWS\System32\??stem32) -- C:\WINDOWS\System32\ѕуstem32
[2008/01/17 17:50:32 | 000,000,000 | ---D | C](C:\WINDOWS\System32\??stem32) -- C:\WINDOWS\System32\ѕуstem32
[2008/01/11 23:07:39 | 000,000,000 | ---D | M](C:\Program Files\?racle) -- C:\Program Files\Оracle
[2008/01/11 23:07:39 | 000,000,000 | ---D | M](C:\Program Files\?racle) -- C:\Program Files\Оracle
[2008/01/05 03:14:46 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?ssembly) -- C:\Program Files\Common Files\аssembly
[2008/01/05 03:14:46 | 000,000,000 | ---D | M](C:\Program Files\Common Files\?ssembly) -- C:\Program Files\Common Files\аssembly
[2007/12/16 03:16:29 | 000,000,000 | ---D | C](C:\Documents and Settings\kathy\My Documents\?ymbols) -- C:\Documents and Settings\kathy\My Documents\ѕymbols
(C:\Program Files\T?sks) -- C:\Program Files\Tаsks
(C:\Program Files\s?stem32) -- C:\Program Files\sуstem32
(C:\Program Files\S?mantec) -- C:\Program Files\Sуmantec
(C:\Program Files\s?curity) -- C:\Program Files\sеcurity
(C:\Program Files\M?crosoft.NET) -- C:\Program Files\Mіcrosoft.NET
(C:\Program Files\M?crosoft) -- C:\Program Files\Mіcrosoft
(C:\Program Files\F?nts) -- C:\Program Files\Fоnts
(C:\Program Files\F?nts) -- C:\Program Files\Fοnts
(C:\Program Files\Common Files\W?nSxS) -- C:\Program Files\Common Files\WіnSxS
(C:\Program Files\Common Files\s?stem) -- C:\Program Files\Common Files\sуstem
(C:\Program Files\Common Files\s?mbols) -- C:\Program Files\Common Files\sуmbols
(C:\Program Files\Common Files\s?curity) -- C:\Program Files\Common Files\sеcurity
(C:\Program Files\Common Files\M?crosoft.NET) -- C:\Program Files\Common Files\Mіcrosoft.NET
(C:\Program Files\Common Files\F?nts) -- C:\Program Files\Common Files\Fоnts
(C:\Program Files\Common Files\F?nts) -- C:\Program Files\Common Files\Fοnts
(C:\Program Files\Common Files\a?sembly) -- C:\Program Files\Common Files\aѕsembly
(C:\Program Files\Common Files\?ystem32) -- C:\Program Files\Common Files\ѕystem32
(C:\Program Files\Common Files\?ystem) -- C:\Program Files\Common Files\ѕystem
(C:\Program Files\Common Files\?ymbols) -- C:\Program Files\Common Files\ѕymbols
(C:\Program Files\Common Files\?ymantec) -- C:\Program Files\Common Files\Ѕymantec
(C:\Program Files\Common Files\?ssembly) -- C:\Program Files\Common Files\аssembly
(C:\Program Files\Common Files\?racle) -- C:\Program Files\Common Files\Оracle
(C:\Program Files\Common Files\?racle) -- C:\Program Files\Common Files\Οracle
(C:\Program Files\Common Files\?ppPatch) -- C:\Program Files\Common Files\АppPatch
(C:\Program Files\Common Files\?ppPatch) -- C:\Program Files\Common Files\ΑppPatch
(C:\Program Files\Common Files\?ecurity) -- C:\Program Files\Common Files\ѕecurity
(C:\Program Files\Common Files\?dobe) -- C:\Program Files\Common Files\Αdobe
(C:\Program Files\Common Files\??stem32) -- C:\Program Files\Common Files\ѕуstem32
(C:\Program Files\Common Files\??stem) -- C:\Program Files\Common Files\ѕуstem
(C:\Program Files\Common Files\??sembly) -- C:\Program Files\Common Files\аѕsembly
(C:\Program Files\Common Files\??pPatch) -- C:\Program Files\Common Files\АрpPatch
(C:\Program Files\Common Files\??pPatch) -- C:\Program Files\Common Files\ΑрpPatch
(C:\Program Files\Common Files\??mantec) -- C:\Program Files\Common Files\Ѕуmantec
(C:\Program Files\Common Files\??curity) -- C:\Program Files\Common Files\ѕеcurity
(C:\Program Files\Common Files\??crosoft.NET) -- C:\Program Files\Common Files\Міcrosoft.NET
(C:\Program Files\A?pPatch) -- C:\Program Files\AрpPatch
(C:\Program Files\?ystem32) -- C:\Program Files\ѕystem32
(C:\Program Files\?ystem) -- C:\Program Files\ѕystem
(C:\Program Files\?ymbols) -- C:\Program Files\ѕymbols
(C:\Program Files\?ymantec) -- C:\Program Files\Ѕymantec
(C:\Program Files\?racle) -- C:\Program Files\Оracle
(C:\Program Files\?racle) -- C:\Program Files\Οracle
(C:\Program Files\?ppPatch) -- C:\Program Files\ΑppPatch
(C:\Program Files\?icrosoft.NET) -- C:\Program Files\Μicrosoft.NET
(C:\Program Files\?icrosoft) -- C:\Program Files\Мicrosoft
(C:\Program Files\?ecurity) -- C:\Program Files\ѕecurity
(C:\Program Files\?dobe) -- C:\Program Files\Аdobe
(C:\Program Files\?dobe) -- C:\Program Files\Αdobe
(C:\Program Files\?asks) -- C:\Program Files\Тasks
(C:\Program Files\??stem32) -- C:\Program Files\ѕуstem32
(C:\Program Files\??stem) -- C:\Program Files\ѕуstem
(C:\Program Files\??pPatch) -- C:\Program Files\АрpPatch
(C:\Program Files\??pPatch) -- C:\Program Files\ΑрpPatch
(C:\Program Files\??mbols) -- C:\Program Files\ѕуmbols
(C:\Program Files\??mantec) -- C:\Program Files\Ѕуmantec
(C:\Program Files\??crosoft.NET) -- C:\Program Files\Міcrosoft.NET
(C:\Program Files\??crosoft.NET) -- C:\Program Files\Μіcrosoft.NET
(C:\Program Files\??crosoft) -- C:\Program Files\Μіcrosoft
(C:\Documents and Settings\kathy\Application Data\s?stem32) -- C:\Documents and Settings\kathy\Application Data\sуstem32
(C:\Documents and Settings\kathy\Application Data\s?mbols) -- C:\Documents and Settings\kathy\Application Data\sуmbols
(C:\Documents and Settings\kathy\Application Data\s?curity) -- C:\Documents and Settings\kathy\Application Data\sеcurity
(C:\Documents and Settings\kathy\Application Data\M?crosoft) -- C:\Documents and Settings\kathy\Application Data\Mіcrosoft
(C:\Documents and Settings\kathy\Application Data\F?nts) -- C:\Documents and Settings\kathy\Application Data\Fоnts
(C:\Documents and Settings\kathy\Application Data\F?nts) -- C:\Documents and Settings\kathy\Application Data\Fοnts
(C:\Documents and Settings\kathy\Application Data\A?pPatch) -- C:\Documents and Settings\kathy\Application Data\AрpPatch
(C:\Documents and Settings\kathy\Application Data\?ystem) -- C:\Documents and Settings\kathy\Application Data\ѕystem
(C:\Documents and Settings\kathy\Application Data\?ymbols) -- C:\Documents and Settings\kathy\Application Data\ѕymbols
(C:\Documents and Settings\kathy\Application Data\?ymantec) -- C:\Documents and Settings\kathy\Application Data\Ѕymantec
(C:\Documents and Settings\kathy\Application Data\?racle) -- C:\Documents and Settings\kathy\Application Data\Оracle
(C:\Documents and Settings\kathy\Application Data\?racle) -- C:\Documents and Settings\kathy\Application Data\Οracle
(C:\Documents and Settings\kathy\Application Data\?icrosoft.NET) -- C:\Documents and Settings\kathy\Application Data\Мicrosoft.NET
(C:\Documents and Settings\kathy\Application Data\?icrosoft) -- C:\Documents and Settings\kathy\Application Data\Μicrosoft
(C:\Documents and Settings\kathy\Application Data\?ecurity) -- C:\Documents and Settings\kathy\Application Data\ѕecurity
(C:\Documents and Settings\kathy\Application Data\?dobe) -- C:\Documents and Settings\kathy\Application Data\Аdobe
(C:\Documents and Settings\kathy\Application Data\?dobe) -- C:\Documents and Settings\kathy\Application Data\Αdobe
(C:\Documents and Settings\kathy\Application Data\?asks) -- C:\Documents and Settings\kathy\Application Data\Τasks
(C:\Documents and Settings\kathy\Application Data\??stem32) -- C:\Documents and Settings\kathy\Application Data\ѕуstem32
(C:\Documents and Settings\kathy\Application Data\??sembly) -- C:\Documents and Settings\kathy\Application Data\аѕsembly
(C:\Documents and Settings\kathy\Application Data\??mbols) -- C:\Documents and Settings\kathy\Application Data\ѕуmbols
(C:\Documents and Settings\kathy\Application Data\??mantec) -- C:\Documents and Settings\kathy\Application Data\Ѕуmantec
(C:\Documents and Settings\kathy\Application Data\??crosoft.NET) -- C:\Documents and Settings\kathy\Application Data\Міcrosoft.NET
(C:\Documents and Settings\kathy\Application Data\??crosoft) -- C:\Documents and Settings\kathy\Application Data\Міcrosoft
(C:\Documents and Settings\kathy\Application Data\??crosoft) -- C:\Documents and Settings\kathy\Application Data\Μіcrosoft
< End of report >