Part Three

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/s...irector/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01...l/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/03/27 08:40:39 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

Drivers32: aux - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.I420 - lvcodec2.dll File not found
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.IYUV - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: VIDC.MP42 - C:\WINDOWS\System32\mpg4c32.dll (Microsoft Corporation)
Drivers32: VIDC.MPG4 - C:\WINDOWS\System32\mpg4c32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YUY2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.YVU9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)
Unable to start service RpcSs!

========== Files/Folders - Created Within 90 Days ==========

[2102/01/04 03:07:13 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
[2102/01/04 02:10:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2102/01/03 14:32:43 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2102/01/02 02:39:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Malwarebytes
[2102/01/02 02:33:46 | 000,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2102/01/02 02:33:45 | 000,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2102/01/02 02:33:45 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2102/01/02 02:33:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2102/01/01 15:44:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2102/01/01 15:40:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com
[2102/01/01 15:40:15 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2102/01/01 15:39:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2010/08/02 17:29:14 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe
[2010/07/25 11:44:05 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/07/19 15:05:14 | 003,374,640 | ---- | C] (Macromedia, Inc.) -- C:\WINDOWS\System32\dllcache\tourP.exe
[2010/07/19 15:05:05 | 000,019,072 | ---- | C] (Adaptec, Inc.) -- C:\WINDOWS\System32\drivers\sparrow.sys
[2010/07/19 15:05:05 | 000,019,072 | ---- | C] (Adaptec, Inc.) -- C:\WINDOWS\System32\dllcache\sparrow.sys
[2010/07/19 15:04:52 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2010/07/19 15:04:52 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2010/07/19 15:04:52 | 000,026,624 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll
[2010/07/19 15:04:45 | 000,272,896 | ---- | C] (Cinematronics) -- C:\WINDOWS\System32\dllcache\pinball.exe
[2010/07/19 15:04:02 | 000,017,280 | ---- | C] (American Megatrends Inc.) -- C:\WINDOWS\System32\drivers\mraid35x.sys
[2010/07/19 15:04:02 | 000,017,280 | ---- | C] (American Megatrends Inc.) -- C:\WINDOWS\System32\dllcache\mraid35x.sys
[2010/07/19 15:01:54 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2010/07/19 15:01:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\I386
[2010/07/19 15:01:27 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Pictures
[2010/07/19 13:29:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Desktop\Unused Desktop Shortcuts
[2010/07/18 15:06:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/07/18 15:06:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/06/28 10:02:44 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\User\Recent
[2010/06/25 17:21:59 | 000,000,000 | ---D | C] -- C:\Program Files\Gran Diccionario Oxford
[2010/06/24 18:11:40 | 000,000,000 | ---D | C] -- C:\Program Files\Atomic Alarm Clock
[2010/06/19 11:25:02 | 000,000,000 | ---D | C] -- C:\Program Files\WorldUnlock Codes Calculator
[2010/06/03 06:53:36 | 000,453,164 | ---- | C] ( ) -- C:\Documents and Settings\User\Desktop\btv.exe
[2010/05/22 17:16:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2010/05/22 11:56:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\Logs
[2010/05/22 11:56:16 | 000,000,000 | ---D | C] -- C:\Program Files\Winamp Detect
[2006/12/12 11:59:08 | 000,184,320 | ---- | C] ( ) -- C:\WINDOWS\System32\Interop.MSXML2.dll
[1 C:\Documents and Settings\User\*.tmp files -> C:\Documents and Settings\User\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/08/02 17:33:48 | 000,000,302 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Shortcut to New Text Document.lnk
[2010/08/02 17:29:14 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe
[2010/08/02 17:26:44 | 000,000,757 | ---- | M] () -- C:\Documents and Settings\User\Application Data\AtomicAlarmClock.ini
[2010/08/02 17:23:13 | 000,029,204 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/08/02 17:21:43 | 008,126,464 | -H-- | M] () -- C:\Documents and Settings\User\ntuser.dat
[2010/08/02 17:19:22 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/08/02 17:19:16 | 1341,706,240 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/02 13:39:32 | 000,000,180 | -HS- | M] () -- C:\Documents and Settings\User\ntuser.ini
[2010/08/02 12:54:41 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/08/02 12:54:32 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/08/02 12:48:09 | 000,000,000 | -H-- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\IconCache.db
[2010/07/30 14:35:11 | 000,001,230 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/07/27 04:45:35 | 000,294,072 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/07/25 14:13:13 | 000,089,261 | ---- | M] () -- C:\ComboFix.zip
[2010/07/25 11:44:10 | 000,000,264 | RHS- | M] () -- C:\boot.ini
[2010/07/25 08:40:05 | 000,000,267 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Shortcut to ComboFix.zip.lnk
[2010/07/19 16:12:51 | 000,000,018 | ---- | M] () -- C:\SYSREST
[2010/07/19 06:38:34 | 001,474,832 | ---- | M] () -- C:\WINDOWS\System32\drivers\sfi.dat
[2010/07/17 18:58:10 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/07/13 03:34:26 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\FOXIT_PDF
[2010/07/12 18:37:23 | 000,044,780 | ---- | M] () -- C:\Documents and Settings\User\Application Data\wklnhst.dat
[2010/07/06 19:50:11 | 000,353,396 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\Scooter Insurance.xps
[2010/07/05 15:19:05 | 000,000,104 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Shortcut to Internet.lnk
[2010/06/24 21:38:18 | 000,017,659 | ---- | M] (TopLang Software) -- C:\WINDOWS\System32\drivers\InetLock.sys
[2010/06/24 18:33:53 | 000,000,163 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2010/06/22 18:26:00 | 002,801,748 | ---- | M] () -- C:\Documents and Settings\User\Desktop\British TV.exe
[2010/05/31 15:35:36 | 000,153,600 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/25 07:13:07 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/05/15 11:20:38 | 000,075,088 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/05/09 02:05:25 | 000,095,172 | ---- | M] () -- C:\Documents and Settings\User\Desktop\_=Demonoid.com=_-TV_UFO_Series_(1970)_1348087.9036.torrent
[1 C:\Documents and Settings\User\*.tmp files -> C:\Documents and Settings\User\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/02 17:33:48 | 000,000,302 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Shortcut to New Text Document.lnk
[2010/07/26 18:02:11 | 1341,706,240 | -HS- | C] () -- C:\hiberfil.sys
[2010/07/25 14:13:13 | 000,089,261 | ---- | C] () -- C:\ComboFix.zip
[2010/07/25 11:44:10 | 000,000,193 | ---- | C] () -- C:\Boot.bak
[2010/07/25 11:44:07 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/07/25 08:40:05 | 000,000,267 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Shortcut to ComboFix.zip.lnk
[2010/07/19 16:12:51 | 000,000,018 | ---- | C] () -- C:\SYSREST
[2010/07/19 15:05:46 | 000,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp
[2010/07/19 15:05:46 | 000,000,707 | ---- | C] () -- C:\WINDOWS\_default.pif
[2010/07/19 15:05:44 | 000,021,281 | ---- | C] () -- C:\WINDOWS\System32\dllcache\XMLDSOC.CAT
[2010/07/19 15:05:39 | 000,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc
[2010/07/19 15:05:35 | 000,032,674 | ---- | C] () -- C:\WINDOWS\System32\winhelp.hlp
[2010/07/19 15:05:35 | 000,013,312 | ---- | C] () -- C:\WINDOWS\System32\dllcache\win87em.dll
[2010/07/19 15:05:33 | 000,390,168 | ---- | C] () -- C:\WINDOWS\System32\dllcache\WFC.CAT
[2010/07/19 15:05:32 | 001,325,568 | ---- | C] () -- C:\WINDOWS\System32\webfldrs.msi
[2010/07/19 15:05:32 | 000,004,096 | ---- | C] () -- C:\WINDOWS\System32\wdl.trm
[2010/07/19 15:05:31 | 001,095,680 | ---- | C] () -- C:\WINDOWS\System32\wbdbase.nld
[2010/07/19 15:05:31 | 000,937,984 | ---- | C] () -- C:\WINDOWS\System32\wbdbase.sve
[2010/07/19 15:05:31 | 000,867,840 | ---- | C] () -- C:\WINDOWS\System32\wbdbase.ita
[2010/07/19 15:05:31 | 000,786,944 | ---- | C] () -- C:\WINDOWS\System32\wbdbase.fra
[2010/07/19 15:05:30 | 001,309,184 | ---- | C] () -- C:\WINDOWS\System32\wbdbase.deu
[2010/07/19 15:05:30 | 000,957,440 | ---- | C] () -- C:\WINDOWS\System32\wbdbase.enu
[2010/07/19 15:05:30 | 000,750,080 | ---- | C] () -- C:\WINDOWS\System32\wbdbase.esn
[2010/07/19 15:05:30 | 000,065,489 | ---- | C] () -- C:\WINDOWS\System32\wbcache.sve
[2010/07/19 15:05:30 | 000,065,489 | ---- | C] () -- C:\WINDOWS\System32\wbcache.nld
[2010/07/19 15:05:30 | 000,065,489 | ---- | C] () -- C:\WINDOWS\System32\wbcache.ita
[2010/07/19 15:05:30 | 000,065,489 | ---- | C] () -- C:\WINDOWS\System32\wbcache.fra
[2010/07/19 15:05:30 | 000,065,489 | ---- | C] () -- C:\WINDOWS\System32\wbcache.esn
[2010/07/19 15:05:30 | 000,065,489 | ---- | C] () -- C:\WINDOWS\System32\wbcache.enu
[2010/07/19 15:05:30 | 000,065,489 | ---- | C] () -- C:\WINDOWS\System32\wbcache.deu
[2010/07/19 15:05:20 | 000,018,832 | ---- | C] () -- C:\WINDOWS\System32\v7vga.rom
[2010/07/19 15:05:20 | 000,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
[2010/07/19 15:05:18 | 000,089,588 | ---- | C] () -- C:\WINDOWS\System32\unicode.nls
[2010/07/19 15:05:16 | 000,262,656 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tshoot.dll
[2010/07/19 15:05:16 | 000,015,360 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tsd32.dll
[2010/07/19 15:05:11 | 000,352,020 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tahomabd.ttf
[2010/07/19 15:05:11 | 000,022,151 | ---- | C] () -- C:\WINDOWS\System32\dllcache\TCLASSES.CAT
[2010/07/19 15:05:10 | 000,379,588 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tahoma.ttf
[2010/07/19 15:05:10 | 000,003,577 | ---- | C] () -- C:\WINDOWS\System32\sysprtj.sep
[2010/07/19 15:05:10 | 000,003,214 | ---- | C] () -- C:\WINDOWS\System32\sysprint.sep
[2010/07/19 15:05:08 | 000,093,702 | ---- | C] () -- C:\WINDOWS\System32\subrange.uce
[2010/07/19 15:05:08 | 000,030,720 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sstub.dll
[2010/07/19 15:05:07 | 000,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf
[2010/07/19 15:05:06 | 000,046,133 | ---- | C] () -- C:\WINDOWS\System32\sqlsodbc.chm
[2010/07/19 15:05:00 | 000,262,148 | ---- | C] () -- C:\WINDOWS\System32\sortkey.nls
[2010/07/19 15:05:00 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sniffpol.dll
[2010/07/19 15:05:00 | 000,021,116 | ---- | C] () -- C:\WINDOWS\System32\sorttbls.nls
[2010/07/19 15:04:58 | 000,016,740 | ---- | C] () -- C:\WINDOWS\System32\shiftjis.uce
[2010/07/19 15:04:56 | 000,011,753 | ---- | C] () -- C:\WINDOWS\System32\setver.exe
[2010/07/19 15:04:56 | 000,000,882 | ---- | C] () -- C:\WINDOWS\System32\share.exe
[2010/07/19 15:04:56 | 000,000,882 | ---- | C] () -- C:\WINDOWS\System32\dllcache\share.exe
[2010/07/19 15:04:55 | 000,033,464 | ---- | C] () -- C:\WINDOWS\System32\services.msc
[2010/07/19 15:04:55 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2010/07/19 15:04:54 | 000,218,112 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sbe.dll
[2010/07/19 15:04:52 | 001,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd
[2010/07/19 15:04:52 | 000,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf
[2010/07/19 15:04:51 | 000,003,167 | ---- | C] () -- C:\WINDOWS\System32\rsaci.rat
[2010/07/19 15:04:49 | 000,003,338 | ---- | C] () -- C:\WINDOWS\System32\redir.exe