DDS (Ver_10-03-17.01) - NTFSX64 Run by ShakyLuigi at 1:45:48,43 on 02.05.2010 Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18 Microsoft Windows 7 Professional 6.1.7600.0.1252.47.1033.18.6143.4687 [GMT 2:00] SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Program Files\WTouch\WTouchService.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\SysWOW64\PnkBstrA.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\Pen_Tablet.exe C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\WTouch\WTouchUser.exe C:\Windows\WindowsMobile\wmdc.exe C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Program Files (x86)\Winamp\winampa.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Windows\SysWOW64\rundll32.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Windows\system32\WTablet\Pen_TabletUser.exe C:\Windows\system32\Pen_Tablet.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe C:\Program Files (x86)\Internet Explorer\IELowutil.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\ShakyLuigi\Desktop\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== mLocal Page = c:\windows\syswow64\blank.htm uInternet Settings,ProxyOverride = uInternet Settings,ProxyServer = http=127.0.0.1:5555 BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files (x86)\spybot - search & destroy\SDHelper.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll uRun: [DS3 Tool] c:\program files\motioninjoy\ds3\DS3_Tool.exe -mini uRun: [SpybotSD TeaTimer] c:\program files (x86)\spybot - search & destroy\TeaTimer.exe uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun mRun: [WinampAgent] "c:\program files (x86)\winamp\winampa.exe" mRun: [avgnt] "c:\program files (x86)\avira\antivir desktop\avgnt.exe" /min mRun: [Acrobat Assistant 8.0] "c:\program files (x86)\adobe\acrobat 8.0\acrobat\Acrotray.exe" mRun: [] mRun: [SunJavaUpdateSched] "c:\program files (x86)\common files\java\java update\jusched.exe" mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SPIRunE] Rundll32 SPIRunE.dll,RunDLLEntry mRun: [StartCCC] "c:\program files (x86)\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun StartupFolder: c:\users\shakyl~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files (x86)\microsoft office\office12\ONENOTEM.EXE mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Append to existing PDF - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files (x86)\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&ksporter til Microsoft Excel - c:\progra~2\micros~2\office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~2\micros~2\office12\ONBttnIE.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files (x86)\spybot - search & destroy\SDHelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15111/CTPID.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~2\common~1\skype\SKYPE4~1.DLL BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll TB-X64: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File mRun-x64: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe ================= FIREFOX =================== FF - ProfilePath - c:\users\shakyl~1\appdata\roaming\mozilla\firefox\profiles\0mium2aq.default\ FF - plugin: c:\program files (x86)\opera\program\plugins\np_gp.dll FF - plugin: c:\program files (x86)\tabletplugins\npwacom.dll FF - plugin: c:\program files (x86)\unity\webplayer\loader\npUnity3D32.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} ---- FIREFOX POLICIES ---- c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true); c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files (x86)\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no"); ============= SERVICES / DRIVERS =============== R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-3-3 202752] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\avira\antivir desktop\sched.exe [2009-9-16 108289] R2 AntiVirService;Avira AntiVir Guard;c:\program files (x86)\avira\antivir desktop\avguard.exe [2009-9-16 185089] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-9-16 74880] R2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\spybot - search & destroy\SDWinSec.exe [2009-12-21 1153368] R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2010-4-29 5556520] R2 TeamViewer5;TeamViewer 5;c:\program files (x86)\teamviewer\version5\TeamViewer_Service.exe [2009-12-17 185640] R2 WTouchService;WTouch Service;c:\program files\wtouch\WTouchService.exe [2010-4-29 127784] R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atipmdag.sys [2010-3-3 6402560] R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-3-3 188928] R3 t3;Sound Blaster X-Fi Xtreme Audio;c:\windows\system32\drivers\t3.sys [2010-3-20 639512] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x64.sys [2009-6-10 389120] S3 CamDrL64;Logitech QuickCam Pro 3000(PID_08B0);c:\windows\system32\drivers\CamDrL64.sys [2007-2-3 955680] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\common files\creative labs shared\service\CTAELicensing.exe [2010-3-20 79360] S3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\drivers\LVUSBS64.sys [2007-2-3 58528] S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\drivers\MijXfilt.sys [2010-1-10 53248] S3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys [2008-5-2 18432] S3 SaiHFF0C;SaiHFF0C;c:\windows\system32\drivers\SaiHFF0C.sys [2007-5-1 171144] S3 SaiUFF0C;SaiUFF0C;c:\windows\system32\drivers\SaiUFF0C.sys [2007-5-1 34304] S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136] S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2010-4-29 18216] =============== Created Last 30 ================ 2010-05-01 21:42:26 0 d-----w- c:\program files (x86)\AutoREALM 2010-04-29 18:23:54 0 d-----w- c:\users\shakyl~1\appdata\roaming\WTablet 2010-04-29 18:23:50 0 d-----w- c:\users\shakyl~1\appdata\roaming\WTouch 2010-04-29 18:23:49 290088 ----a-w- c:\windows\system32\Touch_Tablet.dll 2010-04-29 18:23:49 245032 ----a-w- c:\windows\syswow64\Touch_Tablet.dll 2010-04-29 18:23:48 0 d-----w- c:\program files\WTouch 2010-04-29 18:23:45 7543592 ----a-w- c:\windows\system32\PenTablet.cpl 2010-04-29 18:23:45 1595175 ----a-w- c:\windows\system32\PenTablet.znc 2010-04-29 18:23:37 18216 ----a-w- c:\windows\system32\drivers\wacmoumonitor.sys 2010-04-29 18:23:37 0 d-----w- c:\windows\system32\WTablet 2010-04-29 18:23:34 5556520 ----a-w- c:\windows\system32\Pen_Tablet.exe 2010-04-29 18:23:34 490280 ----a-w- c:\windows\system32\Pen_Tablet.dll 2010-04-29 18:23:34 349184 ----a-w- c:\windows\system32\Wintab32.dll 2010-04-18 16:11:11 0 d-----w- c:\program files\common files\Logitech 2010-04-18 13:28:57 0 d-----w- c:\programdata\ATI 2010-04-18 13:22:51 0 d-----w- c:\program files (x86)\common files\ATI Technologies 2010-04-18 13:22:49 0 d-----w- c:\program files (x86)\ATI 2010-04-14 22:24:34 0 d-----w- C:\Fraps 2010-04-14 15:34:35 0 d-----w- c:\users\shakyl~1\appdata\roaming\XMind 2010-04-14 15:34:31 0 d-----w- c:\program files (x86)\XMind 2010-04-07 18:04:43 74000 ----a-w- c:\windows\syswow64\msrclr40.dll 2010-04-07 18:04:43 7348 ----a-w- c:\windows\syswow64\Odbcjet.cnt 2010-04-07 18:04:43 171967 ----a-w- c:\windows\syswow64\Odbcjet.hlp 2010-04-07 18:04:42 28944 ----a-w- c:\windows\syswow64\msrecr40.dll 2010-04-03 15:43:44 3360 ----a-w- c:\windows\system32\SaiDFF0C.pr0 2010-04-02 17:52:16 0 d-----w- c:\users\shakyl~1\appdata\roaming\Ascaron Entertainment 2010-04-02 13:49:46 306688 ----a-w- c:\windows\IsUn0414.exe ==================== Find3M ==================== 2010-05-01 19:59:28 218808 ----a-w- c:\windows\syswow64\PnkBstrB.exe 2010-05-01 19:57:30 56 ---ha-w- c:\programdata\ezsidmv.dat 2010-04-29 13:39:28 24664 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-03-31 06:00:46 86016 ----a-w- c:\windows\syswow64\frapsvid.dll 2010-03-31 06:00:44 84992 ----a-w- c:\windows\system32\frapsv64.dll 2010-03-19 18:43:51 75064 ----a-w- c:\windows\syswow64\PnkBstrA.exe 2010-03-19 18:43:51 2434856 ----a-w- c:\windows\syswow64\pbsvc_bc2.exe 2010-03-03 04:23:10 6402560 ----a-w- c:\windows\system32\drivers\atipmdag.sys 2010-03-03 04:23:10 6402560 ----a-w- c:\windows\system32\drivers\atikmdag.sys 2010-03-03 04:16:38 143360 ----a-w- c:\windows\system32\atiapfxx.exe 2010-03-03 04:16:26 446464 ----a-w- c:\windows\syswow64\aticfx32.dll 2010-03-03 04:15:30 497152 ----a-w- c:\windows\system32\aticfx64.dll 2010-03-03 04:13:04 446464 ----a-w- c:\windows\system32\ATIDEMGX.dll 2010-03-03 04:12:52 450560 ----a-w- c:\windows\system32\atieclxx.exe 2010-03-03 04:12:12 202752 ----a-w- c:\windows\system32\atiesrxx.exe 2010-03-03 04:10:34 120320 ----a-w- c:\windows\system32\atitmm64.dll 2010-03-03 04:10:12 420864 ----a-w- c:\windows\system32\atipdl64.dll 2010-03-03 04:10:04 356352 ----a-w- c:\windows\syswow64\atipdlxx.dll 2010-03-03 04:09:48 274432 ----a-w- c:\windows\syswow64\Oemdspif.dll 2010-03-03 04:09:40 12288 ----a-w- c:\windows\system32\atimuixx.dll 2010-03-03 04:09:34 59392 ----a-w- c:\windows\system32\atiedu64.dll 2010-03-03 04:09:28 43520 ----a-w- c:\windows\syswow64\ati2edxx.dll 2010-03-03 04:06:18 3131392 ----a-w- c:\windows\syswow64\atidxx32.dll 2010-03-03 04:04:46 18798080 ----a-w- c:\windows\system32\atio6axx.dll 2010-03-03 03:57:00 3800576 ----a-w- c:\windows\system32\atidxx64.dll 2010-03-03 03:46:42 3703808 ----a-w- c:\windows\syswow64\atiumdag.dll 2010-03-03 03:45:02 14226944 ----a-w- c:\windows\syswow64\atioglxx.dll 2010-03-03 03:39:46 4801536 ----a-w- c:\windows\system32\atiumd64.dll 2010-03-03 03:32:06 2716160 ----a-w- c:\windows\system32\atiumd6a.dll 2010-03-03 03:24:24 2993152 ----a-w- c:\windows\syswow64\atiumdva.dll 2010-03-03 03:23:52 55296 ----a-w- c:\windows\system32\coinst.dll 2010-03-03 03:20:22 43008 ----a-w- c:\windows\system32\aticalrt64.dll 2010-03-03 03:20:20 53248 ----a-w- c:\windows\syswow64\aticalrt.dll 2010-03-03 03:20:10 39936 ----a-w- c:\windows\system32\aticalcl64.dll 2010-03-03 03:20:08 53248 ----a-w- c:\windows\syswow64\aticalcl.dll 2010-03-03 03:19:56 4781568 ----a-w- c:\windows\system32\aticaldd64.dll 2010-03-03 03:18:56 3657728 ----a-w- c:\windows\syswow64\aticaldd.dll 2010-03-03 03:08:50 53248 ----a-w- c:\windows\system32\atimpc64.dll 2010-03-03 03:08:50 53248 ----a-w- c:\windows\system32\amdpcom64.dll 2010-03-03 03:08:44 52224 ----a-w- c:\windows\syswow64\atimpc32.dll 2010-03-03 03:08:44 52224 ----a-w- c:\windows\syswow64\amdpcom32.dll 2010-03-03 03:08:14 330752 ----a-w- c:\windows\system32\atiadlxx.dll 2010-03-03 03:08:06 237568 ----a-w- c:\windows\syswow64\atiadlxy.dll 2010-03-03 03:07:54 14848 ----a-w- c:\windows\system32\atig6pxx.dll 2010-03-03 03:07:48 12800 ----a-w- c:\windows\syswow64\atiglpxx.dll 2010-03-03 03:07:48 12800 ----a-w- c:\windows\system32\atiglpxx.dll 2010-03-03 03:07:44 16896 ----a-w- c:\windows\system32\atig6txx.dll 2010-03-03 03:07:38 15360 ----a-w- c:\windows\syswow64\atigktxx.dll 2010-03-03 03:07:32 188928 ----a-w- c:\windows\system32\drivers\atikmpag.sys 2010-03-03 03:06:50 36352 ----a-w- c:\windows\system32\atiuxp64.dll 2010-03-03 03:06:42 27648 ----a-w- c:\windows\syswow64\atiuxpag.dll 2010-03-03 03:06:34 28160 ----a-w- c:\windows\system32\atiu9p64.dll 2010-03-03 03:06:26 20480 ----a-w- c:\windows\syswow64\atiu9pag.dll 2010-03-03 03:05:42 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll 2010-02-25 19:55:46 201875 ----a-w- c:\windows\system32\atiicdxx.dat 2010-02-24 17:09:40 466456 ----a-w- c:\windows\system32\wrap_oal.dll 2010-02-24 17:09:40 444952 ----a-w- c:\windows\syswow64\wrap_oal.dll 2010-02-24 17:09:40 122904 ----a-w- c:\windows\system32\OpenAL32.dll 2010-02-24 17:09:40 109080 ----a-w- c:\windows\syswow64\OpenAL32.dll 2010-02-24 08:16:06 212864 ------w- c:\windows\system32\MpSigStub.exe 2010-02-10 22:17:47 455680 ----a-w- c:\windows\system32\deploytk.dll 2010-02-02 08:36:47 2048 ----a-w- c:\windows\system32\tzres.dll 2010-02-02 07:45:54 2048 ----a-w- c:\windows\syswow64\tzres.dll 2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat 2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat 2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat 2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat 2009-07-14 04:54:24 174 --sha-w- c:\program files\desktop.ini 2009-07-14 04:54:24 174 --sha-w- c:\program files (x86)\desktop.ini 2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat 2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat 2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat 2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat 2009-06-10 20:44:08 9633792 --sha-r- c:\windows\fonts\StaticCache.dat 2010-01-23 13:09:22 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat 2009-07-14 01:39:53 398848 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe 2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe ============= FINISH: 1:46:21,04 ===============