Fri Jul 01 2011 08:50:11 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/23/AB3DEF1FC49CB32F0E8E93E988EBA.jpg cache stored in: UPQVMROL/AB3DEF1FC49CB32F0E8E93E988EBA[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "16b5a88f638cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 3159 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 09:14:07 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://tap2-cdn.rubiconproject.com/partner/scripts/rubicon/emily.html?pc=8142/13187 cache stored in: UPQVMROL/emily[1].htm - HTTP/1.1 200 OK - Content-Length: 6621 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 09:57:36 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/F4/8E1CE8BD265B47CBBE321FF47E2A1.jpg cache stored in: UPQVMROL/8E1CE8BD265B47CBBE321FF47E2A1[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "ab269faf38cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 4095 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 09:57:47 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://s0.2mdn.net/1361550/PID_1666481_K2335_NAS_OM_728x90.jpg cache stored in: UPQVMROL/PID_1666481_K2335_NAS_OM_728x90[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Content-Type-Options: nosniff - Content-Length: 30061 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 10:08:08 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/ie6-fixes.css?r=38841 cache stored in: SLK18LSF/ie6-fixes[2].css - HTTP/1.1 200 OK - Content-Length: 1604 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/js/tpl_channels.js?r=38841 cache stored in: YZCXGNW1/tpl_channels[2].js - HTTP/1.1 200 OK - Content-Length: 7834 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/js/tpl_comments.js?r=38841 cache stored in: UPQVMROL/tpl_comments[2].js - HTTP/1.1 200 OK - Content-Length: 3493 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/js/tpl_directory.js?r=38841 cache stored in: YZCXGNW1/tpl_directory[1].js - HTTP/1.1 200 OK - Content-Length: 3164 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/js/tpl_htdocs.js?r=38841 cache stored in: UPQVMROL/tpl_htdocs[1].js - HTTP/1.1 200 OK - Content-Length: 78342 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/js/tpl_player.js?r=38841 cache stored in: YZCXGNW1/tpl_player[2].js - HTTP/1.1 200 OK - Content-Length: 20356 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/js/tpl_shows.js?r=38841 cache stored in: SLK18LSF/tpl_shows[2].js - HTTP/1.1 200 OK - Content-Length: 65677 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 10:08:18 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/js/combined/index.js?r=38841 cache stored in: UPQVMROL/index[2].js - HTTP/1.1 200 OK - Content-Length: 157999 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 10:08:29 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/js/combined/showPage.js?r=38841 cache stored in: QJM5KT6J/showPage[2].js - HTTP/1.1 200 OK - Content-Length: 98741 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 10:08:41 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/combined/channels.css?r=38841 cache stored in: QJM5KT6J/channels[1].css - HTTP/1.1 200 OK - Content-Length: 18839 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 10:08:42 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/combined/directory.css?r=38841 cache stored in: SLK18LSF/directory[2].css - HTTP/1.1 200 OK - Content-Length: 1954 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 10:08:43 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/combined/index.css?r=38841 cache stored in: QJM5KT6J/index[1].css - HTTP/1.1 200 OK - Content-Length: 26185 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 10:08:50 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/combined/shows.css?r=38841 cache stored in: UPQVMROL/shows[2].css - HTTP/1.1 200 OK - Content-Length: 33316 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 11:33:45 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/D8/5BDA7261AAEAD28A63201DFFAC2A4B.jpg cache stored in: YZCXGNW1/5BDA7261AAEAD28A63201DFFAC2A4B[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "0e15f691d38cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 4078 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 11:37:53 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/500/21e/50021ee7fded0de4baf2235b2b688d3ec4d239cc.jpg?url=http://origin.psstatic.podshow.com/images/shows/21849/episodes/286858/large/presspause-us-e.jpg?r=1309545471&width=200&height=112&scheme=1 cache stored in: SLK18LSF/50021ee7fded0de4baf2235b2b688d3ec4d239cc[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 14652 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 11:38:22 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stc.s-msn.com/br/sc/css/2e/9f5897c9639ef97fa228d2ecc7575e.css cache stored in: UPQVMROL/9f5897c9639ef97fa228d2ecc7575e[1].css - HTTP/1.1 200 OK - Content-Length: 3520 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stc.s-msn.com/br/sc/css/37/b862c6c3329c726208dab3c6f742b8_blue.css cache stored in: UPQVMROL/b862c6c3329c726208dab3c6f742b8_blue[1].css - HTTP/1.1 200 OK - Content-Length: 112836 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stc.s-msn.com/br/sc/css/66/40bebb8ac371d6f92b3720e62f3017.css cache stored in: SLK18LSF/40bebb8ac371d6f92b3720e62f3017[1].css - HTTP/1.1 200 OK - Content-Length: 4690 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 11:38:25 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stj.s-msn.com/br/sc/js/50/e2815c7504541e30998dd35159edbb.js cache stored in: QJM5KT6J/e2815c7504541e30998dd35159edbb[1].js - HTTP/1.1 200 OK - Content-Length: 133114 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 12:07:30 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/60/C40C5665D2C06F965D1A6A40B84.jpg cache stored in: QJM5KT6J/C40C5665D2C06F965D1A6A40B84[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "0c5c51f2238cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 15098 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 12:56:41 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/TimeZoneInformation 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0A08/2&daba3ff&0/LogConf 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0C01/2&daba3ff&0/LogConf 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_2660&SUBSYS_00000000&REV_03/3&b1bfb68&0&E0/LogConf 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/TimeZoneInformation 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0A08/2&daba3ff&0/LogConf 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0C01/2&daba3ff&0/LogConf 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_2660&SUBSYS_00000000&REV_03/3&b1bfb68&0&E0/LogConf Fri Jul 01 2011 12:56:48 131072 .acb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/15_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:56:52 131072 .acb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:56:55 0 ma.. r/rr-xr-xr-x 0 0 3657-128-13 /WINDOWS/Debug/PASSWD.LOG Fri Jul 01 2011 12:56:56 62 mac. r/rr-xr-xr-x 0 0 10656-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000131.ini 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) EventLog/6005_Info_ (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) EventLog/6009_Info_5.01. - 2600 - Service Pack 3 - Uniprocessor Free (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:56:57 0 m... 0 0 0 0 REG_System_SECURITYSECURITY/Policy/Secrets/L${6B3E6424-AF3E-4bff-ACB6-DA535F0DDC0A}/CupdTime 0 m... 0 0 0 0 REG_System_SECURITYSECURITY/Policy/Secrets/L${6B3E6424-AF3E-4bff-ACB6-DA535F0DDC0A}/CurrVal 0 m... 0 0 0 0 REG_System_SECURITYSECURITY/Policy/Secrets/L${6B3E6424-AF3E-4bff-ACB6-DA535F0DDC0A}/OldVal 0 m... 0 0 0 0 REG_System_SECURITYSECURITY/Policy/Secrets/L${6B3E6424-AF3E-4bff-ACB6-DA535F0DDC0A}/OupdTime 0 ma.. r/rr-xr-xr-x 0 0 10402-128-12 /WINDOWS/0.log 62 mac. r/rr-xr-xr-x 0 0 10662-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000132.ini Fri Jul 01 2011 12:57:09 131072 .acb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:57:11 131072 .acb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 .acb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:57:18 131072 m... 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 m... 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 m... 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/15_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 m... 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:58:12 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Dhcp/1007_Warn_001558286148 - 169.254.125.21 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:58:27 20 m.c. r/rrwxrwxrwx 0 0 11486-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/$WinMgmt.CFG 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/17_Error_time.windows.com-0x1 - A socket operation was attempted to an unreachable host. (0x80072751) - 15 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/29_Error_14 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:58:30 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_ALG/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_NLA/0000 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) SecurityCenter/1800_Info_ (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Service Control Manager/7036_Info_Network Location Awareness (NLA) - running (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 S-1-5-18 0 3663 [Event Log] (Time generated/Time written) User: S-1-5-18 Service Control Manager/7035_Info_Network Location Awareness (NLA) - start (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/17_Error_time.windows.com-0x1 - A socket operation was attempted to an unreachable host. (0x80072751) - 15 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/29_Error_14 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:58:31 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Service Control Manager/7036_Info_Application Layer Gateway Service - running (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Service Control Manager/7036_Info_Computer Browser - stopped (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 S-1-5-18 0 3663 [Event Log] (Time generated/Time written) User: S-1-5-18 Service Control Manager/7035_Info_Application Layer Gateway Service - start (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:58:58 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Print Fri Jul 01 2011 12:59:15 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) ESENT/100_Info_wuauclt - 528 - - 5 - 01 - 2600 - 5512 (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) ESENT/102_Info_wuaueng.dll - 528 - SUS20ClientDataStore: - 0 (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) Fri Jul 01 2011 12:59:16 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:59:20 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/9_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:59:21 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:59:24 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:59:35 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:59:38 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:59:43 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_FASTUSERSWITCHINGCOMPATIBILITY/0000 0 macb 0 0 0 10413 [XP Prefetch] (Last run) EXPLORER.EXE-082F38A9.pf - [EXPLORER.EXE] was executed - run count [3]- full path: [C:/WINDOWS/EXPLORER.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/BROWSEUI.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/SHDOCVW.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/CRYPTUI.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/WININET.DLL - WINDOWS/SYSTEM32/WINTRUST.DLL - WINDOWS/SYSTEM32/IMAGEHLP.DLL - WINDOWS/SYSTEM32/WLDAP32.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/RICHED20.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/RPCSS.DLL - WINDOWS/SYSTEM32/APPHELP.DLL - WINDOWS/SYSTEM32/CLBCATQ.DLL - WINDOWS/SYSTEM32/COMRES.DLL - WINDOWS/SYSTEM32/CSCUI.DLL - WINDOWS/SYSTEM32/CSCDLL.DLL - WINDOWS/SYSTEM32/THEMEUI.DLL - WINDOWS/SYSTEM32/MSIMG32.DLL - WINDOWS/SYSTEM32/XPSP2RES.DLL - WINDOWS/SYSTEM32/ACTXPRXY.DLL - WINDOWS/SYSTEM32/SAMLIB.DLL - WINDOWS/SYSTEM32/SETUPAPI.DLL - WINDOWS/SYSTEM32/MYDOCS.DLL - WINDOWS/SYSTEM32/NETSHELL.DLL - WINDOWS/SYSTEM32/ATL.DLL - WINDOWS/SYSTEM32/CREDUI.DLL - WINDOWS/SYSTEM32/DOT3API.DLL - WINDOWS/SYSTEM32/RTUTILS.DLL - WINDOWS/SYSTEM32/DOT3DLG.DLL - WINDOWS/SYSTEM32/ONEX.DLL - WINDOWS/SYSTEM32/WTSAPI32.DLL - WINDOWS/SYSTEM32/WINSTA.DLL - WINDOWS/SYSTEM32/EAPPCFG.DLL - WINDOWS/SYSTEM32/MSVCP60.DLL - WINDOWS/SYSTEM32/EAPPPRXY.DLL - WINDOWS/SYSTEM32/IPHLPAPI.DLL - WINDOWS/SYSTEM32/WS2_32.DLL - WINDOWS/SYSTEM32/WS2HELP.DLL - WINDOWS/SYSTEM32/MORICONS.DLL - WINDOWS/SYSTEM32/URLMON.DLL - WINDOWS/SYSTEM32/WINSRV.DLL - WINDOWS/SYSTEM32/SHDOCLC.DLL} (file: /media/sdb1/WINDOWS/Prefetch/EXPLORER.EXE-082F38A9.pf) 0 macb 0 0 0 10413 [XP Prefetch] (Last run) USERINIT.EXE-30B18140.pf - [USERINIT.EXE] was executed - run count [2]- full path: [C:/WINDOWS/SYSTEM32/USERINIT.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/WLDAP32.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/APPHELP.DLL - WINDOWS/SYSTEM32/SETUPAPI.DLL} (file: /media/sdb1/WINDOWS/Prefetch/USERINIT.EXE-30B18140.pf) 84 .a.. r/rr-xr-xr-x 0 0 10507-128-3 /Documents and Settings/malware/Start Menu/Programs/Accessories/Entertainment/desktop.ini 348 .a.. r/rr-xr-xr-x 0 0 10517-128-3 /Documents and Settings/malware/Start Menu/Programs/Accessories/Accessibility/desktop.ini 90 .a.. r/rr-xr-xr-x 0 0 10758-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000071.ini 448 .a.. r/rr-xr-xr-x 0 0 10778-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000073.ini 146 .a.. r/rr-xr-xr-x 0 0 10811-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000080.ini 757 .a.. r/rr-xr-xr-x 0 0 10834-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000088.ini 62 mac. r/rr-xr-xr-x 0 0 11164-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000133.ini 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Service Control Manager/7036_Info_Fast User Switching Compatibility - running (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 S-1-5-18 0 3663 [Event Log] (Time generated/Time written) User: S-1-5-18 Service Control Manager/7035_Info_Fast User Switching Compatibility - start (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 448 .a.. r/rr-xr-xr-x 0 0 4855-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Communications/desktop.ini 757 .a.. r/rr-xr-xr-x 0 0 5514-128-3 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/System Tools/desktop.ini 146 .a.. r/rr-xr-xr-x 0 0 5519-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Entertainment/desktop.ini 90 .a.. r/rr-xr-xr-x 0 0 5523-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Accessibility/desktop.ini Fri Jul 01 2011 12:59:44 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_SSDPSRV/0000 0 ma.. r/rr-xr-xr-x 0 0 11452-128-3 /ok.txt 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Service Control Manager/7036_Info_SSDP Discovery Service - running (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 S-1-5-18 0 3663 [Event Log] (Time generated/Time written) User: S-1-5-18 Service Control Manager/7035_Info_SSDP Discovery Service - start (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:59:45 0 macb 0 0 0 10413 [XP Prefetch] (Last run) FC.EXE-1B9F0926.pf - [FC.EXE] was executed - run count [1]- full path: [C:/WINDOWS/SYSTEM32/FC.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/ULIB.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL} (file: /media/sdb1/WINDOWS/Prefetch/FC.EXE-1B9F0926.pf) 0 macb 0 0 0 10413 [XP Prefetch] (Last run) FIND.EXE-0EC32F1E.pf - [FIND.EXE] was executed - run count [1]- full path: [C:/WINDOWS/SYSTEM32/FIND.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/ULIB.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL} (file: /media/sdb1/WINDOWS/Prefetch/FIND.EXE-0EC32F1E.pf) 0 macb 0 0 0 10413 [XP Prefetch] (Last run) WGET.EXE-37D5C025.pf - [WGET.EXE] was executed - run count [2]- full path: [C:/WINDOWS/SYSTEM32/WGET.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/WSOCK32.DLL - WINDOWS/SYSTEM32/WS2_32.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/WS2HELP.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/RSAENH.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSWSOCK.DLL - WINDOWS/SYSTEM32/HNETCFG.DLL - WINDOWS/SYSTEM32/WSHTCPIP.DLL - WINDOWS/SYSTEM32/RASADHLP.DLL} (file: /media/sdb1/WINDOWS/Prefetch/WGET.EXE-37D5C025.pf) 0 ma.. r/rr-xr-xr-x 0 0 11165-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000134.exe 0 m... r/rr-xr-xr-x 0 0 11453-128-3 /WINDOWS/system32/sandnet.exe 10124 macb r/rrwxrwxrwx 0 0 11460-128-4 /WINDOWS/Prefetch/WGET.EXE-37D5C025.pf 10944 macb r/rrwxrwxrwx 0 0 11462-128-4 /WINDOWS/Prefetch/FC.EXE-1B9F0926.pf 10888 macb r/rrwxrwxrwx 0 0 11463-128-4 /WINDOWS/Prefetch/FIND.EXE-0EC32F1E.pf Fri Jul 01 2011 12:59:49 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_IMAPISERVICE/0000 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/CD Burning 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/Desktop/CleanupWiz 0 macb 0 0 0 10413 [XP Prefetch] (Last run) IMAPI.EXE-0BF740A4.pf - [IMAPI.EXE] was executed - run count [3]- full path: [C:/WINDOWS/SYSTEM32/IMAPI.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/SETUPAPI.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/RPCSS.DLL - WINDOWS/SYSTEM32/XPSP2RES.DLL - WINDOWS/SYSTEM32/CLBCATQ.DLL - WINDOWS/SYSTEM32/COMRES.DLL - WINDOWS/SYSTEM32/ACTXPRXY.DLL - WINDOWS/SYSTEM32/RSAENH.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/WINTRUST.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/IMAGEHLP.DLL} (file: /media/sdb1/WINDOWS/Prefetch/IMAPI.EXE-0BF740A4.pf) 0 macb 0 0 0 10413 [XP Prefetch] (Last run) RUNDLL32.EXE-1BC69D2D.pf - [RUNDLL32.EXE] was executed - run count [1]- full path: [C:/WINDOWS/SYSTEM32/RUNDLL32.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/IMAGEHLP.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/FLDRCLNR.DLL - WINDOWS/SYSTEM32/RPCSS.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/APPHELP.DLL - WINDOWS/SYSTEM32/CLBCATQ.DLL - WINDOWS/SYSTEM32/COMRES.DLL - WINDOWS/SYSTEM32/SHDOCVW.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/CRYPTUI.DLL - WINDOWS/SYSTEM32/WININET.DLL - WINDOWS/SYSTEM32/WINTRUST.DLL - WINDOWS/SYSTEM32/WLDAP32.DLL - WINDOWS/SYSTEM32/RICHED20.DLL - WINDOWS/SYSTEM32/SETUPAPI.DLL - WINDOWS/SYSTEM32/LINKINFO.DLL - WINDOWS/SYSTEM32/NTSHRUI.DLL - WINDOWS/SYSTEM32/ATL.DLL} (file: /media/sdb1/WINDOWS/Prefetch/RUNDLL32.EXE-1BC69D2D.pf) 18922 macb r/rrwxrwxrwx 0 0 11464-128-4 /WINDOWS/Prefetch/RUNDLL32.EXE-1BC69D2D.pf 87552 .a.. r/rr-xr-xr-x 0 0 2484-128-3 /WINDOWS/system32/fldrclnr.dll 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Service Control Manager/7036_Info_IMAPI CD-Burning COM Service - running (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 S-1-5-18 0 3663 [Event Log] (Time generated/Time written) User: S-1-5-18 Service Control Manager/7035_Info_IMAPI CD-Burning COM Service - start (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:59:51 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 12:59:53 13814 mac. r/rrwxrwxrwx 0 0 10586-128-4 /WINDOWS/Prefetch/USERINIT.EXE-30B18140.pf 55850 mac. r/rrwxrwxrwx 0 0 10587-128-4 /WINDOWS/Prefetch/EXPLORER.EXE-082F38A9.pf Fri Jul 01 2011 12:59:55 18480 mac. r/rrwxrwxrwx 0 0 10639-128-4 /WINDOWS/Prefetch/IMAPI.EXE-0BF740A4.pf 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Service Control Manager/7036_Info_IMAPI CD-Burning COM Service - stopped (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:00:09 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Print/Providers Fri Jul 01 2011 13:00:44 0 macb 0 0 0 10413 [XP Prefetch] (Last run) WMIADAP.EXE-2DF425B2.pf - [WMIADAP.EXE] was executed - run count [3]- full path: [C:/WINDOWS/SYSTEM32/WBEM/WMIADAP.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/MSVCP60.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/WBEM/WBEMCOMN.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/LOADPERF.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/RPCSS.DLL - WINDOWS/SYSTEM32/XPSP2RES.DLL - WINDOWS/SYSTEM32/PSAPI.DLL - WINDOWS/SYSTEM32/NTMARTA.DLL - WINDOWS/SYSTEM32/SAMLIB.DLL - WINDOWS/SYSTEM32/WLDAP32.DLL - WINDOWS/SYSTEM32/CLBCATQ.DLL - WINDOWS/SYSTEM32/COMRES.DLL - WINDOWS/SYSTEM32/WBEM/WBEMPROX.DLL - WINDOWS/SYSTEM32/WS2_32.DLL - WINDOWS/SYSTEM32/WS2HELP.DLL - WINDOWS/SYSTEM32/WBEM/WBEMSVC.DLL - WINDOWS/SYSTEM32/WBEM/FASTPROX.DLL - WINDOWS/SYSTEM32/NTDSAPI.DLL - WINDOWS/SYSTEM32/DNSAPI.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL} (file: /media/sdb1/WINDOWS/Prefetch/WMIADAP.EXE-2DF425B2.pf) 97280 .a.. r/rr-xr-xr-x 0 0 2147-128-3 /WINDOWS/system32/loadperf.dll 196608 .a.. r/rr-xr-xr-x 0 0 4899-128-3 /WINDOWS/system32/wbem/wmiadap.exe Fri Jul 01 2011 13:00:45 144896 .a.. r/rr-xr-xr-x 0 0 4910-128-3 /WINDOWS/system32/wbem/wmiprov.dll 0 macb 0 0 0 5544 [WMIprov Log file] (Time Written) Entry in log file: WDM call returned error: 4200 (file: /media/sdb1/WINDOWS/system32/wbem/Logs/wmiprov.log) Fri Jul 01 2011 13:00:46 123904 .a.. r/rr-xr-xr-x 0 0 4877-128-3 /WINDOWS/system32/wbem/mofd.dll Fri Jul 01 2011 13:00:48 187776 .a.. r/rr-xr-xr-x 0 0 3621-128-3 /WINDOWS/system32/drivers/acpi.sys 14208 .a.. r/rr-xr-xr-x 0 0 4838-128-3 /WINDOWS/system32/drivers/battc.sys Fri Jul 01 2011 13:00:49 738 m... r/rr-xr-xr-x 0 0 11465-128-4 /WINDOWS/system32/wbem/Performance/WmiApRpl.h 3160 m.c. r/rrwxrwxrwx 0 0 11491-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/FS/MAPPING1.MAP Fri Jul 01 2011 13:00:51 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/WmiApRpl/Performance 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/WmiApRpl/Performance 3824 ma.. r/rr-xr-xr-x 0 0 10652-128-4 /WINDOWS/system32/wbem/Performance/WmiApRpl.ini 738 .a.. r/rr-xr-xr-x 0 0 11465-128-4 /WINDOWS/system32/wbem/Performance/WmiApRpl.h 40394 ma.. r/rr-xr-xr-x 0 0 246-128-3 /WINDOWS/system32/perfc009.dat 312172 ma.. r/rr-xr-xr-x 0 0 247-128-3 /WINDOWS/system32/perfh009.dat 56 m... d/dr-xr-xr-x 0 0 29-144-7 /WINDOWS/system32 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) LoadPerf/1000_Info_WmiApRpl - WmiApRpl (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) LoadPerf/1001_Info_WmiApRpl - WmiApRpl (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) 356120 ma.. r/rr-xr-xr-x 0 0 4149-128-4 /WINDOWS/system32/PerfStringBackup.INI 264 m... d/dr-xr-xr-x 0 0 5539-144-1 /WINDOWS/system32/wbem/Performance Fri Jul 01 2011 13:00:52 26610 mac. r/rrwxrwxrwx 0 0 10653-128-4 /WINDOWS/Prefetch/WMIADAP.EXE-2DF425B2.pf Fri Jul 01 2011 13:00:57 999424 m.c. r/rrwxrwxrwx 0 0 11488-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/FS/INDEX.BTR 524 m.c. r/rrwxrwxrwx 0 0 11489-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/FS/INDEX.MAP 5300224 m.c. r/rrwxrwxrwx 0 0 11493-128-4 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/FS/OBJECTS.DATA 2636 m.c. r/rrwxrwxrwx 0 0 11494-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/FS/OBJECTS.MAP Fri Jul 01 2011 13:00:58 4 m.c. r/rrwxrwxrwx 0 0 11490-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/FS/MAPPING.VER 3160 m.c. r/rrwxrwxrwx 0 0 11492-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/FS/MAPPING2.MAP 3160 m... r/rr-xr-xr-x 0 0 5549-128-3 /WINDOWS/system32/wbem/Repository/FS/MAPPING2.MAP Fri Jul 01 2011 13:02:09 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:02:13 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/9_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:02:16 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:02:30 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 0 macb 0 0 0 5544 [WMIprov Log file] (Time Written) Entry in log file: WDM call returned error: 4200 (file: /media/sdb1/WINDOWS/system32/wbem/Logs/wmiprov.log) Fri Jul 01 2011 13:02:33 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:02:44 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:02:47 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:03:33 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:03:37 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/9_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:03:40 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:03:51 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:03:54 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:04:05 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:04:07 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:04:16 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) ESENT/101_Info_wuauclt - 528 (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) ESENT/103_Info_wuaueng.dll - 528 - SUS20ClientDataStore: - 0 (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) Fri Jul 01 2011 13:06:29 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:06:36 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/9_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:06:39 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:06:41 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/9_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:06:42 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:06:44 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:06:58 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:07:01 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:07:12 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:07:14 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:07:19 0 macb 0 0 0 5544 [WMIprov Log file] (Time Written) Entry in log file: Impersonation failed - Access denied (file: /media/sdb1/WINDOWS/system32/wbem/Logs/wmiprov.log) Fri Jul 01 2011 13:08:02 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:08:04 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/9_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:08:05 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:08:08 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:08:15 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:08:18 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:08:30 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:08:32 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:09:35 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:09:38 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:09:40 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:09:49 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:09:52 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:10:03 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:10:06 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:11:29 15360 .a.. r/rr-xr-xr-x 0 0 2747-128-3 /WINDOWS/system32/msisip.dll 90112 .a.. r/rr-xr-xr-x 0 0 3185-128-3 /WINDOWS/system32/wshext.dll Fri Jul 01 2011 13:11:43 383488 .a.. r/rr-xr-xr-x 0 0 3196-128-3 /WINDOWS/system32/wzcdlg.dll 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/17_Error_time.windows.com-0x1 - A socket operation was attempted to an unreachable host. (0x80072751) - 15 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/29_Error_14 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:17:08 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:17:10 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/9_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:17:11 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:17:13 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Dhcp/1003_Warn_001558286148 - %23 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:17:22 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:17:24 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Dhcp/1003_Warn_001558286148 - %23 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:17:55 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Tcpip/Parameters 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Tcpip/Parameters 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Dhcp/1003_Warn_001558286148 - %1 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:17:58 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Dhcp/1007_Warn_001558286148 - 169.254.125.21 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/17_Error_time.windows.com-0x1 - A socket operation was attempted to an unreachable host. (0x80072751) - 15 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/29_Error_14 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:19:21 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:19:28 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:19:29 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4202_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:19:30 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/9_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:19:31 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:19:33 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:19:34 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:20:13 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:20:16 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:20:27 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:20:29 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:21:31 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Dhcp/Parameters 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Dhcp/Parameters Fri Jul 01 2011 13:21:34 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Dhcp/1007_Warn_001558286148 - 169.254.125.21 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/17_Error_time.windows.com-0x1 - A socket operation was attempted to an unreachable host. (0x80072751) - 15 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/29_Error_15 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:21:40 0 macb 0 0 0 10413 [XP Prefetch] (Last run) LOGON.SCR-151EFAEA.pf - [LOGON.SCR] was executed - run count [11]- full path: [] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL} (file: /media/sdb1/WINDOWS/Prefetch/LOGON.SCR-151EFAEA.pf) 220672 .a.. r/rr-xr-xr-x 0 0 2163-128-3 /WINDOWS/system32/logon.scr Fri Jul 01 2011 13:21:50 5910 mac. r/rrwxrwxrwx 0 0 11122-128-4 /WINDOWS/Prefetch/LOGON.SCR-151EFAEA.pf Fri Jul 01 2011 13:22:02 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:22:07 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/9_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:22:09 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/9_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:22:12 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:23:04 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:23:07 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:23:18 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:23:20 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:24:29 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:24:31 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/9_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:24:32 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:24:35 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/11_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:26:44 0 macb 0 0 0 10413 [XP Prefetch] (Last run) DEFRAG.EXE-273F131E.pf - [DEFRAG.EXE] was executed - run count [4]- full path: [C:/WINDOWS/SYSTEM32/DEFRAG.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/RPCSS.DLL - WINDOWS/SYSTEM32/DFRGRES.DLL - WINDOWS/SYSTEM32/NTMARTA.DLL - WINDOWS/SYSTEM32/SAMLIB.DLL - WINDOWS/SYSTEM32/WLDAP32.DLL - WINDOWS/SYSTEM32/CLBCATQ.DLL - WINDOWS/SYSTEM32/COMRES.DLL - WINDOWS/SYSTEM32/XPSP2RES.DLL - WINDOWS/SYSTEM32/WINSTA.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL} (file: /media/sdb1/WINDOWS/Prefetch/DEFRAG.EXE-273F131E.pf) 110178 mac. r/rrwxrwxrwx 0 0 11123-128-3 /WINDOWS/Prefetch/Layout.ini 25088 .a.. r/rr-xr-xr-x 0 0 2158-128-3 /WINDOWS/system32/defrag.exe Fri Jul 01 2011 13:26:45 0 macb 0 0 0 10413 [XP Prefetch] (Last run) DFRGNTFS.EXE-269967DF.pf - [DFRGNTFS.EXE] was executed - run count [4]- full path: [C:/WINDOWS/SYSTEM32/DFRGNTFS.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/VSSAPI.DLL - WINDOWS/SYSTEM32/ATL.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/RPCSS.DLL - WINDOWS/SYSTEM32/DFRGRES.DLL - WINDOWS/SYSTEM32/CLBCATQ.DLL - WINDOWS/SYSTEM32/COMRES.DLL - WINDOWS/SYSTEM32/XPSP2RES.DLL - WINDOWS/SYSTEM32/WINSTA.DLL} (file: /media/sdb1/WINDOWS/Prefetch/DFRGNTFS.EXE-269967DF.pf) 105472 .a.. r/rr-xr-xr-x 0 0 2161-128-3 /WINDOWS/system32/dfrgntfs.exe 51200 .a.. r/rr-xr-xr-x 0 0 244-128-3 /WINDOWS/system32/dfrgres.dll Fri Jul 01 2011 13:26:51 14988 mac. r/rrwxrwxrwx 0 0 11124-128-4 /WINDOWS/Prefetch/DEFRAG.EXE-273F131E.pf 36214 mac. r/rrwxrwxrwx 0 0 11125-128-4 /WINDOWS/Prefetch/DFRGNTFS.EXE-269967DF.pf Fri Jul 01 2011 13:27:22 416 ...b d/drwxrwxrwx 0 0 11458-144-5 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12 536 ...b r/rrwxrwxrwx 0 0 11466-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/rp.log 56 ...b d/drwxrwxrwx 0 0 11468-144-5 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot 245760 macb r/rrwxrwxrwx 0 0 11469-128-4 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/_REGISTRY_USER_NTUSER_S-1-5-18 237568 macb r/rrwxrwxrwx 0 0 11470-128-4 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/_REGISTRY_USER_NTUSER_S-1-5-19 8192 macb r/rrwxrwxrwx 0 0 11471-128-4 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/_REGISTRY_USER_USRCLASS_S-1-5-19 237568 macb r/rrwxrwxrwx 0 0 11472-128-4 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/_REGISTRY_USER_NTUSER_S-1-5-20 8192 macb r/rrwxrwxrwx 0 0 11473-128-4 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/_REGISTRY_USER_USRCLASS_S-1-5-20 606208 macb r/rrwxrwxrwx 0 0 11474-128-4 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/_REGISTRY_USER_NTUSER_S-1-5-21-1390067357-343818398-1801674531-1003 8192 macb r/rrwxrwxrwx 0 0 11475-128-4 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/_REGISTRY_USER_USRCLASS_S-1-5-21-1390067357-343818398-1801674531-1003 245760 macb r/rrwxrwxrwx 0 0 11476-128-4 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/_REGISTRY_USER_.DEFAULT 22528 .a.. r/rr-xr-xr-x 0 0 2679-128-3 /WINDOWS/system32/mfcsubs.dll 226304 .a.. r/rr-xr-xr-x 0 0 4930-128-3 /WINDOWS/system32/catsrv.dll 625664 .a.. r/rr-xr-xr-x 0 0 4931-128-3 /WINDOWS/system32/catsrvut.dll Fri Jul 01 2011 13:27:23 40960 macb r/rrwxrwxrwx 0 0 11477-128-4 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/_REGISTRY_MACHINE_SECURITY 9314304 macb r/rrwxrwxrwx 0 0 11478-128-6 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/_REGISTRY_MACHINE_SOFTWARE 3346432 ...b r/rrwxrwxrwx 0 0 11480-128-4 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/_REGISTRY_MACHINE_SYSTEM Fri Jul 01 2011 13:27:24 16384 macb 16895 0 0 10383 [Restore Point] (Created) Restore point RP12 created - System Checkpoint (file: /media/sdb1/System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}) 23256 m.c. r/rrwxrwxrwx 0 0 10426-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/_filelst.cfg 536 m.c. r/rrwxrwxrwx 0 0 11466-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/rp.log 56 mac. d/drwxrwxrwx 0 0 11468-144-5 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot 3346432 mac. r/rrwxrwxrwx 0 0 11480-128-4 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/_REGISTRY_MACHINE_SYSTEM 28672 macb r/rrwxrwxrwx 0 0 11481-128-4 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/_REGISTRY_MACHINE_SAM 22512 .a.b r/rrwxrwxrwx 0 0 11482-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/ComDb.Dat 56 macb r/rrwxrwxrwx 0 0 11483-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/domain.txt 248 macb d/drwxrwxrwx 0 0 11485-144-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository 20 .a.b r/rrwxrwxrwx 0 0 11486-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/$WinMgmt.CFG 56 macb d/drwxrwxrwx 0 0 11487-144-5 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/FS 999424 .a.b r/rrwxrwxrwx 0 0 11488-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/FS/INDEX.BTR 524 .a.b r/rrwxrwxrwx 0 0 11489-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/FS/INDEX.MAP 4 .a.b r/rrwxrwxrwx 0 0 11490-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/FS/MAPPING.VER 3160 .a.b r/rrwxrwxrwx 0 0 11491-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/FS/MAPPING1.MAP 3160 .a.b r/rrwxrwxrwx 0 0 11492-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/FS/MAPPING2.MAP 5300224 .a.b r/rrwxrwxrwx 0 0 11493-128-4 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/FS/OBJECTS.DATA 2636 .a.b r/rrwxrwxrwx 0 0 11494-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/snapshot/Repository/FS/OBJECTS.MAP 8 macb r/rrwxrwxrwx 0 0 11495-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/RestorePointSize 19569 .ac. r/r--x--x--x 0 0 5762-128-3 /WINDOWS/system32/Restore/filelist.xml Fri Jul 01 2011 13:27:54 0 macb 0 0 0 10413 [XP Prefetch] (Last run) HELPSVC.EXE-2878DDA2.pf - [HELPSVC.EXE] was executed - run count [11]- full path: [C:/WINDOWS/PCHEALTH/HELPCTR/BINARIES/HELPSVC.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/RPCSS.DLL - WINDOWS/SYSTEM32/XPSP2RES.DLL - WINDOWS/PCHEALTH/HELPCTR/BINARIES/HCAPPRES.DLL - WINDOWS/SYSTEM32/CLBCATQ.DLL - WINDOWS/SYSTEM32/COMRES.DLL - WINDOWS/SYSTEM32/SXS.DLL - WINDOWS/SYSTEM32/MSXML3.DLL - WINDOWS/SYSTEM32/MSXML3R.DLL - WINDOWS/SYSTEM32/URLMON.DLL - WINDOWS/SYSTEM32/MLANG.DLL - WINDOWS/SYSTEM32/WBEM/FASTPROX.DLL - WINDOWS/SYSTEM32/MSVCP60.DLL - WINDOWS/SYSTEM32/WBEM/WBEMCOMN.DLL - WINDOWS/SYSTEM32/NTDSAPI.DLL - WINDOWS/SYSTEM32/DNSAPI.DLL - WINDOWS/SYSTEM32/WS2_32.DLL - WINDOWS/SYSTEM32/WS2HELP.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/WLDAP32.DLL - WINDOWS/SYSTEM32/WBEM/WBEMPROX.DLL - WINDOWS/SYSTEM32/WBEM/WBEMSVC.DLL - WINDOWS/SYSTEM32/WBEM/XML/WMI2XML.DLL} (file: /media/sdb1/WINDOWS/Prefetch/HELPSVC.EXE-2878DDA2.pf) 4 .a.. r/rr-xr-xr-x 0 0 11085-128-1 /WINDOWS/pchealth/helpctr/PackageStore/CRC_Disk 3476 .a.. r/rr-xr-xr-x 0 0 11096-128-4 /WINDOWS/pchealth/helpctr/PackageStore/SkuStore.bin 2036 .a.. r/rr-xr-xr-x 0 0 11364-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_237.xml 744448 .a.. r/rr-xr-xr-x 0 0 5771-128-3 /WINDOWS/pchealth/helpctr/binaries/HelpSvc.exe 6656 .a.. r/rr-xr-xr-x 0 0 6261-128-3 /WINDOWS/pchealth/helpctr/binaries/HCAppRes.dll 2435 .a.. r/rr-xr-xr-x 0 0 6575-128-3 /WINDOWS/pchealth/helpctr/Config/dataspec.xml 8738 .a.. r/rr-xr-xr-x 0 0 7515-128-5 /WINDOWS/pchealth/helpctr/Config/Cntstore.bin Fri Jul 01 2011 13:27:55 25600 .a.. r/rr-xr-xr-x 0 0 1015-128-3 /WINDOWS/system32/msvidc32.dll 0 macb 0 0 0 10413 [XP Prefetch] (Last run) WMIPRVSE.EXE-28F301A9.pf - [WMIPRVSE.EXE] was executed - run count [12]- full path: [C:/WINDOWS/SYSTEM32/WBEM/WMIPRVSE.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/WBEM/WBEMCOMN.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/WBEM/FASTPROX.DLL - WINDOWS/SYSTEM32/MSVCP60.DLL - WINDOWS/SYSTEM32/NTDSAPI.DLL - WINDOWS/SYSTEM32/DNSAPI.DLL - WINDOWS/SYSTEM32/WS2_32.DLL - WINDOWS/SYSTEM32/WS2HELP.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/WLDAP32.DLL - WINDOWS/SYSTEM32/NCOBJAPI.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/RPCSS.DLL - WINDOWS/SYSTEM32/XPSP2RES.DLL - WINDOWS/SYSTEM32/CLBCATQ.DLL - WINDOWS/SYSTEM32/COMRES.DLL - WINDOWS/SYSTEM32/WBEM/WBEMPROX.DLL - WINDOWS/SYSTEM32/WBEM/WBEMSVC.DLL - WINDOWS/SYSTEM32/WBEM/WMIUTILS.DLL - WINDOWS/SYSTEM32/WBEM/CIMWIN32.DLL - WINDOWS/SYSTEM32/WBEM/FRAMEDYN.DLL - WINDOWS/SYSTEM32/SETUPAPI.DLL - WINDOWS/SYSTEM32/PSAPI.DLL - WINDOWS/SYSTEM32/ICCVID.DLL - WINDOWS/SYSTEM32/IR32_32.DLL - WINDOWS/SYSTEM32/IYUV_32.DLL - WINDOWS/SYSTEM32/MSRLE32.DLL - WINDOWS/SYSTEM32/MSVIDC32.DLL - WINDOWS/SYSTEM32/MSYUV.DLL - WINDOWS/SYSTEM32/TSBYUV.DLL - WINDOWS/SYSTEM32/IR50_32.DLL - WINDOWS/SYSTEM32/WTSAPI32.DLL - WINDOWS/SYSTEM32/WINSTA.DLL - WINDOWS/SYSTEM32/CFGMGR32.DLL - WINDOWS/SYSTEM32/WMI.DLL - WINDOWS/SYSTEM32/DSKQUOTA.DLL - WINDOWS/SYSTEM32/TRAFFIC.DLL - WINDOWS/SYSTEM32/IPHLPAPI.DLL - WINDOWS/SYSTEM32/SECURITY.DLL - WINDOWS/SYSTEM32/SCHANNEL.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/WBEM/WMIPROV.DLL - WINDOWS/SYSTEM32/WBEM/MOFD.DLL} (file: /media/sdb1/WINDOWS/Prefetch/WMIPRVSE.EXE-28F301A9.pf) 2036 .a.. r/rr-xr-xr-x 0 0 11176-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_27.xml 5424 .a.. r/rr-xr-xr-x 0 0 11177-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_37.xml 2036 .a.. r/rr-xr-xr-x 0 0 11178-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_57.xml 2036 .a.. r/rr-xr-xr-x 0 0 11239-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_87.xml 2036 .a.. r/rr-xr-xr-x 0 0 11240-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_117.xml 2036 .a.. r/rr-xr-xr-x 0 0 11271-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_147.xml 2036 .a.. r/rr-xr-xr-x 0 0 11302-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_177.xml 2036 .a.. r/rr-xr-xr-x 0 0 11333-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_207.xml 8192 .a.. r/rr-xr-xr-x 0 0 1411-128-3 /WINDOWS/system32/tsbyuv.dll 8192 .a.. r/rr-xr-xr-x 0 0 1414-128-3 /WINDOWS/system32/tssoft32.acm 16896 .a.. r/rr-xr-xr-x 0 0 2041-128-3 /WINDOWS/system32/cfgmgr32.dll 92672 .a.. r/rr-xr-xr-x 0 0 2421-128-3 /WINDOWS/system32/dskquota.dll 80384 .a.. r/rr-xr-xr-x 0 0 2534-128-3 /WINDOWS/system32/iccvid.dll 16384 .a.. r/rr-xr-xr-x 0 0 2552-128-3 /WINDOWS/system32/imaadp32.acm 14848 .a.. r/rr-xr-xr-x 0 0 2727-128-3 /WINDOWS/system32/msadp32.acm 11264 .a.. r/rr-xr-xr-x 0 0 2765-128-3 /WINDOWS/system32/msrle32.dll 16896 .a.. r/rr-xr-xr-x 0 0 2787-128-3 /WINDOWS/system32/msyuv.dll 199680 .a.. r/rr-xr-xr-x 0 0 3415-128-3 /WINDOWS/system32/iac25_32.ax 848384 .a.. r/rr-xr-xr-x 0 0 3417-128-3 /WINDOWS/system32/ir41_32.ax 755200 .a.. r/rr-xr-xr-x 0 0 3420-128-3 /WINDOWS/system32/ir50_32.dll 47616 .a.. r/rr-xr-xr-x 0 0 3424-128-3 /WINDOWS/system32/iyuv_32.dll 294912 .a.. r/rr-xr-xr-x 0 0 3447-128-3 /WINDOWS/system32/msh263.drv 290816 .a.. r/rr-xr-xr-x 0 0 3558-128-3 /WINDOWS/system32/l3codeca.acm 294912 .a.. r/rr-xr-xr-x 0 0 3566-128-3 /WINDOWS/system32/msaud32.acm 86016 .a.. r/rr-xr-xr-x 0 0 3578-128-3 /WINDOWS/system32/sl_anet.acm 211 .a.. r/rr-xr-xr-x 0 0 3646-128-3 /boot.ini 1358848 .a.. r/rr-xr-xr-x 0 0 4867-128-3 /WINDOWS/system32/wbem/cimwin32.dll 185344 .a.. r/rr-xr-xr-x 0 0 4871-128-3 /WINDOWS/system32/wbem/framedyn.dll 218112 .a.. r/rr-xr-xr-x 0 0 4912-128-3 /WINDOWS/system32/wbem/wmiprvse.exe 188416 .a.. r/rr-xr-xr-x 0 0 5750-128-3 /WINDOWS/system32/msh261.drv 118784 .a.. r/rr-xr-xr-x 0 0 6191-128-3 /WINDOWS/system32/msg723.acm 199168 .a.. r/rr-xr-xr-x 0 0 671-128-3 /WINDOWS/system32/ir32_32.dll 9216 .a.. r/rr-xr-xr-x 0 0 988-128-3 /WINDOWS/system32/msg711.acm 19968 .a.. r/rr-xr-xr-x 0 0 989-128-3 /WINDOWS/system32/msgsm32.acm Fri Jul 01 2011 13:27:56 42980 m..b r/rr-xr-xr-x 0 0 11496-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_256.xml 31232 .a.. r/rr-xr-xr-x 0 0 1407-128-3 /WINDOWS/system32/traffic.dll 5632 .a.. r/rr-xr-xr-x 0 0 2996-128-3 /WINDOWS/system32/security.dll 231750 .a.. r/rr-xr-xr-x 0 0 3632-128-3 /WINDOWS/repair/setup.log 45568 .a.. r/rr-xr-xr-x 0 0 5099-128-3 /WINDOWS/system32/wbem/xml/wmi2xml.dll Fri Jul 01 2011 13:27:57 600484 m..b r/rr-xr-xr-x 0 0 11126-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_274.xml 1896 ma.b r/rr-xr-xr-x 0 0 11138-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_266.xml 18844 ma.b r/rr-xr-xr-x 0 0 11140-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_270.xml 2054 ma.b r/rr-xr-xr-x 0 0 11145-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_272.xml 1592 ma.b r/rr-xr-xr-x 0 0 11238-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_268.xml 20218 ma.b r/rr-xr-xr-x 0 0 11270-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_264.xml 3652 ma.b r/rr-xr-xr-x 0 0 11301-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_262.xml 50176 ma.b r/rr-xr-xr-x 0 0 11332-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_260.xml 1492 ma.b r/rr-xr-xr-x 0 0 11363-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_258.xml 42980 .a.. r/rr-xr-xr-x 0 0 11496-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_256.xml 2036 ma.b r/rr-xr-xr-x 0 0 11497-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_267.xml Fri Jul 01 2011 13:27:58 600484 .a.. r/rr-xr-xr-x 0 0 11126-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_274.xml 157092 ma.b r/rr-xr-xr-x 0 0 11127-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_276.xml 87390 ma.b r/rr-xr-xr-x 0 0 11128-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_278.xml 316 ma.b r/rr-xr-xr-x 0 0 11129-128-1 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_280.xml 44442 ma.b r/rr-xr-xr-x 0 0 11130-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_282.xml 10374 ma.b r/rr-xr-xr-x 0 0 11131-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_284.xml 9486 ma.. r/rr-xr-xr-x 0 0 11141-128-4 /WINDOWS/pchealth/helpctr/DataColl/history_db.xml 3684 ma.b r/rr-xr-xr-x 0 0 11498-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_277.xml 312 m... d/dr-xr-xr-x 0 0 5769-144-5 /WINDOWS/pchealth/helpctr/DataColl Fri Jul 01 2011 13:28:04 73948 mac. r/rrwxrwxrwx 0 0 7555-128-4 /WINDOWS/Prefetch/HELPSVC.EXE-2878DDA2.pf Fri Jul 01 2011 13:28:05 37104 mac. r/rrwxrwxrwx 0 0 10674-128-4 /WINDOWS/Prefetch/WMIPRVSE.EXE-28F301A9.pf Fri Jul 01 2011 13:36:34 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/17_Error_time.windows.com-0x1 - A socket operation was attempted to an unreachable host. (0x80072751) - 30 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/29_Error_30 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 13:44:34 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/65/7815B21D9A578DAD6365D443B0D6B6.jpg cache stored in: SLK18LSF/7815B21D9A578DAD6365D443B0D6B6[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "206730af2f38cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 9167 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 14:01:58 56 mac. d/dr-xr-xr-x 0 0 10383-144-6 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA} 497 macb r/rrwxrwxrwx 0 0 3759-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/fifo.log Fri Jul 01 2011 14:06:34 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/17_Error_time.windows.com-0x1 - A socket operation was attempted to an unreachable host. (0x80072751) - 60 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/29_Error_60 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 14:09:59 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/4_Warn_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 14:10:01 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Tcpip/4201_Info_ - Broadcom...Ethernet - Packet Scheduler Miniport (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/9_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 14:14:33 650752 .a.. r/rr-xr-xr-x 0 0 2399-128-3 /WINDOWS/system32/dot3ui.dll Fri Jul 01 2011 14:16:24 7168 .a.. r/rr-xr-xr-x 0 0 1535-128-3 /WINDOWS/system32/wshnetbs.dll 56 m... d/dr-xr-xr-x 0 0 3753-144-5 /WINDOWS/system32/CatRoot2 Fri Jul 01 2011 14:16:44 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Tcpip/Parameters/Interfaces/{D668E008-1573-470A-9346-7741E6261C75} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/{D668E008-1573-470A-9346-7741E6261C75}/Parameters/Tcpip 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Tcpip/Parameters/Interfaces/{D668E008-1573-470A-9346-7741E6261C75} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/{D668E008-1573-470A-9346-7741E6261C75}/Parameters/Tcpip Fri Jul 01 2011 14:16:46 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Network 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Network/{4D36E972-E325-11CE-BFC1-08002BE10318}/{D668E008-1573-470A-9346-7741E6261C75}/Connection 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Network 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Network/{4D36E972-E325-11CE-BFC1-08002BE10318}/{D668E008-1573-470A-9346-7741E6261C75}/Connection 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/SharedAccess/Epoch Fri Jul 01 2011 14:17:01 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/17_Error_time.windows.com-0x1 - A socket operation was attempted to an unreachable host. (0x80072751) - 15 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/29_Error_14 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 14:20:11 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/F7/7E527F040B5694B10F6F9B92DE95.jpg cache stored in: QJM5KT6J/7E527F040B5694B10F6F9B92DE95[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "08e7ea93438cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 7832 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://variantov.com/pusk.exe cache stored in: UPQVMROL/pusk[1].exe - HTTP/1.1 200 OK - Content-Type: application/octet-stream - Content-Length: 452608 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 14:32:01 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/17_Error_time.windows.com-0x1 - A socket operation was attempted to an unreachable host. (0x80072751) - 30 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) W32Time/29_Error_29 (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 14:38:35 1527 .a.. r/rr-xr-xr-x 0 0 10498-128-4 /Documents and Settings/malware/Start Menu/Programs/Accessories/Tour Windows XP.lnk 347136 .a.. r/rr-xr-xr-x 0 0 3479-128-3 /WINDOWS/system32/tourstart.exe Fri Jul 01 2011 14:38:36 208896 .a.. r/rr-xr-xr-x 0 0 3398-128-3 /WINDOWS/inf/unregmp2.exe Fri Jul 01 2011 14:38:43 67 .a.. r/rr-xr-xr-x 0 0 10520-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/desktop.ini 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://home.microsoft.com (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 0 .acb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:microsoft.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 122 .a.. r/rr-xr-xr-x 0 0 10592-128-1 /Documents and Settings/malware/Favorites/Desktop.ini 108 ma.b r/rr-xr-xr-x 0 0 5540-128-1 /Documents and Settings/malware/Cookies/malware@microsoft[1].txt Fri Jul 01 2011 14:38:44 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stc.s-msn.com/br/sc/css/2e/9f5897c9639ef97fa228d2ecc7575e.css cache stored in: UPQVMROL/9f5897c9639ef97fa228d2ecc7575e[1].css - HTTP/1.1 200 OK - Content-Length: 3520 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stc.s-msn.com/br/sc/css/37/b862c6c3329c726208dab3c6f742b8_blue.css cache stored in: UPQVMROL/b862c6c3329c726208dab3c6f742b8_blue[1].css - HTTP/1.1 200 OK - Content-Length: 112836 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stc.s-msn.com/br/sc/css/66/40bebb8ac371d6f92b3720e62f3017.css cache stored in: SLK18LSF/40bebb8ac371d6f92b3720e62f3017[1].css - HTTP/1.1 200 OK - Content-Length: 4690 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stj.s-msn.com/br/sc/js/jquery/jquery-1.4.2.min.js cache stored in: YZCXGNW1/jquery-1.4.2.min[2].js - HTTP/1.1 200 OK - Content-Length: 72182 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 72182 .a.. r/rr-xr-xr-x 0 0 10770-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/jquery-1.4.2.min[2].js 112836 ma.b r/rr-xr-xr-x 0 0 6828-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/b862c6c3329c726208dab3c6f742b8_blue[1].css 3520 ma.b r/rr-xr-xr-x 0 0 6829-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/9f5897c9639ef97fa228d2ecc7575e[1].css 4690 ma.b r/rr-xr-xr-x 0 0 6830-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/40bebb8ac371d6f92b3720e62f3017[1].css Fri Jul 01 2011 14:38:45 4842 ma.b r/rr-xr-xr-x 0 0 10356-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/1db850e671ac9a39751a1482909ea6[1].jpg 7322 ma.b r/rr-xr-xr-x 0 0 10438-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/4378db7471b44dea1c183f006ee3d0[1].gif 9167 ma.b r/rr-xr-xr-x 0 0 10439-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/7815B21D9A578DAD6365D443B0D6B6[1].jpg 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ads1.msn.com/library/dapmsn.js cache stored in: YZCXGNW1/dapmsn[1].js - HTTP/1.1 200 OK - Content-Length: 3877 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://analytics.live.com/Analytics/wlanalytics.js cache stored in: UPQVMROL/wlanalytics[1].js - HTTP/1.1 200 OK - Content-Length: 9288 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://blst.msn.com/as/wea3/i/en-us/law/32.gif cache stored in: SLK18LSF/32[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - ETag: "083df89b6bac81:0"- - X-Powered-By: ASP.NET - S: BLUMPPSTCA01 - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 895 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/18/41EA2BB896C1D269F946D98D1E31A.jpg cache stored in: QJM5KT6J/41EA2BB896C1D269F946D98D1E31A[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "80fc42806537cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 3775 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/54/76EF7E2C6994B1A2C79DDB1DF450.jpg cache stored in: SLK18LSF/76EF7E2C6994B1A2C79DDB1DF450[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "56ffa123431cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 4830 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/60/C40C5665D2C06F965D1A6A40B84.jpg cache stored in: QJM5KT6J/C40C5665D2C06F965D1A6A40B84[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "0c5c51f2238cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 15098 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/65/7815B21D9A578DAD6365D443B0D6B6.jpg cache stored in: SLK18LSF/7815B21D9A578DAD6365D443B0D6B6[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "206730af2f38cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 9167 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/A1/D72D7743BB3018A939743976971.jpg cache stored in: YZCXGNW1/D72D7743BB3018A939743976971[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "6a999136637cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 2661 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/A3/6ECB5F9A4119F2F7D7B4AF62EC5A.jpg cache stored in: QJM5KT6J/6ECB5F9A4119F2F7D7B4AF62EC5A[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "80c558286637cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 3996 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/B7/EB75D45B8948F72EE451223E95A96.gif cache stored in: QJM5KT6J/EB75D45B8948F72EE451223E95A96[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - ETag: "80a1bae029c0ca1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 2477 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/E2/37BA92E210D341BFDBF4126422A3D2.gif cache stored in: UPQVMROL/37BA92E210D341BFDBF4126422A3D2[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - ETag: "ac1668bfc52ca1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 657 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/F7/7E527F040B5694B10F6F9B92DE95.jpg cache stored in: QJM5KT6J/7E527F040B5694B10F6F9B92DE95[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "08e7ea93438cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 7832 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stc.s-msn.com/br/sc/i/07/617475cf39bf6f5c0bd6ecb985335c.gif cache stored in: UPQVMROL/617475cf39bf6f5c0bd6ecb985335c[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - ETag: "0f9486d2298cb1:0"- - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 48 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stc.s-msn.com/br/sc/i/2d/1db850e671ac9a39751a1482909ea6.jpg cache stored in: UPQVMROL/1db850e671ac9a39751a1482909ea6[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "0d2e990026cc1:0"- - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 4842 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stc.s-msn.com/br/sc/i/f8/614595fba50d96389708a4135776e4.gif cache stored in: YZCXGNW1/614595fba50d96389708a4135776e4[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - ETag: "8053ca1db891cb1:0"- - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 43 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stc.s-msn.com/br/sc/i/ff/adchoices_gif2.gif cache stored in: UPQVMROL/adchoices_gif2[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - ETag: "096b38d19cc1:0"- - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 417 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stc.s-msn.com/br/sc/i/icons/BING_websearch_2.jpg cache stored in: SLK18LSF/BING_websearch_2[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "0e49dbec5aecb1:0"- - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 4082 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stj.s-msn.com/br/sc/js/50/e2815c7504541e30998dd35159edbb.js cache stored in: QJM5KT6J/e2815c7504541e30998dd35159edbb[1].js - HTTP/1.1 200 OK - Content-Length: 133114 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.bing.com/partner/primedns.gif cache stored in: UPQVMROL/primedns[2].gif - HTTP/1.1 200 OK - Content-Length: 43 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:exp.www.msn.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 m... 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:live.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 4830 ma.b r/rr-xr-xr-x 0 0 10556-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/76EF7E2C6994B1A2C79DDB1DF450[1].jpg 417 ma.b r/rr-xr-xr-x 0 0 10558-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/adchoices_gif2[1].gif 3996 ma.b r/rr-xr-xr-x 0 0 10577-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/6ECB5F9A4119F2F7D7B4AF62EC5A[1].jpg 3775 ma.b r/rr-xr-xr-x 0 0 10580-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/41EA2BB896C1D269F946D98D1E31A[1].jpg 43 .a.. r/rr-xr-xr-x 0 0 10764-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/primedns[2].gif 137 .a.. r/rr-xr-xr-x 0 0 10772-128-1 /Documents and Settings/malware/Cookies/malware@exp.www.msn[1].txt 4082 .a.. r/rr-xr-xr-x 0 0 10773-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/BING_websearch_2[1].jpg 9288 .a.. r/rr-xr-xr-x 0 0 10777-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/wlanalytics[1].js 2477 .a.. r/rr-xr-xr-x 0 0 10782-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/EB75D45B8948F72EE451223E95A96[1].gif 48 .a.. r/rr-xr-xr-x 0 0 10783-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/617475cf39bf6f5c0bd6ecb985335c[1].gif 657 .a.. r/rr-xr-xr-x 0 0 10787-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/37BA92E210D341BFDBF4126422A3D2[1].gif 43 .a.. r/rr-xr-xr-x 0 0 10791-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/614595fba50d96389708a4135776e4[1].gif 94 .a.. r/rr-xr-xr-x 0 0 10805-128-1 /Documents and Settings/malware/Cookies/malware@live[1].txt 133114 ma.b r/rr-xr-xr-x 0 0 6827-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/e2815c7504541e30998dd35159edbb[1].js 2661 ma.b r/rr-xr-xr-x 0 0 6831-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/D72D7743BB3018A939743976971[1].jpg 3877 ma.b r/rr-xr-xr-x 0 0 6832-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/dapmsn[1].js 895 ma.b r/rr-xr-xr-x 0 0 6833-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/32[1].gif 7832 ma.b r/rr-xr-xr-x 0 0 6835-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/7E527F040B5694B10F6F9B92DE95[1].jpg 15098 ma.b r/rr-xr-xr-x 0 0 8483-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/C40C5665D2C06F965D1A6A40B84[1].jpg Fri Jul 01 2011 14:38:46 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1828.1214.tk.100x25/805306726 cache stored in: YZCXGNW1/805306726[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Powered-By: PHP/5.1.6 - P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" - Content-Length: 42 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ads2.msads.net/CIS/43/000/000/000/017/544.jpg cache stored in: UPQVMROL/544[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-AspNet-Version: 4.0.30319 - X-Powered-By: ASP.NET - Content-Length: 16533 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ads2.msads.net/CIS/61/000/000/000/017/003.png cache stored in: QJM5KT6J/003[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-AspNet-Version: 4.0.30319 - X-Powered-By: ASP.NET - Content-Length: 4330 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/23/AB3DEF1FC49CB32F0E8E93E988EBA.jpg cache stored in: UPQVMROL/AB3DEF1FC49CB32F0E8E93E988EBA[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "16b5a88f638cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 3159 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/D8/5BDA7261AAEAD28A63201DFFAC2A4B.jpg cache stored in: YZCXGNW1/5BDA7261AAEAD28A63201DFFAC2A4B[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "0e15f691d38cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 4078 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/F4/8E1CE8BD265B47CBBE321FF47E2A1.jpg cache stored in: UPQVMROL/8E1CE8BD265B47CBBE321FF47E2A1[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "ab269faf38cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 4095 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stc.s-msn.com/br/sc/i/0c/c57bc2a7d38843d7c4aa8028fc9f82.gif cache stored in: SLK18LSF/c57bc2a7d38843d7c4aa8028fc9f82[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - ETag: "066dd3aa6bdcb1:0"- - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 1142 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://rad.msn.com/ADSAdClient31.dll?GetSAd=&DPJS=4&PN=MSFT&ID=0A9F82A7055868E13BAD83DD015868BB&MUID=0A9F82A7055868E13BAD83DD015868BB&PG=MSNHQ2&AP=1402 cache stored in: YZCXGNW1/ADSAdClient31[1].htm - HTTP/1.1 200 OK - Content-Length: 1046 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://rad.msn.com/ADSAdClient31.dll?GetSAd=&DPJS=4&PN=MSFT&ID=0A9F82A7055868E13BAD83DD015868BB&MUID=0A9F82A7055868E13BAD83DD015868BB&PG=MSNIF1&AP=1455 cache stored in: SLK18LSF/ADSAdClient31[1].htm - HTTP/1.1 200 OK - Content-Length: 978 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:ad.wsod.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:c.msn.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 .acb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:msn.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 68 ma.b r/rr-xr-xr-x 0 0 10574-128-1 /Documents and Settings/malware/Cookies/malware@c.msn[2].txt 42 ma.b r/rr-xr-xr-x 0 0 10582-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/805306726[1].gif 583 ma.. r/rr-xr-xr-x 0 0 10588-128-1 /Documents and Settings/malware/Cookies/malware@msn[1].txt 3159 ma.b r/rr-xr-xr-x 0 0 10603-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/AB3DEF1FC49CB32F0E8E93E988EBA[1].jpg 4078 ma.b r/rr-xr-xr-x 0 0 10604-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/5BDA7261AAEAD28A63201DFFAC2A4B[1].jpg 1046 ma.b r/rr-xr-xr-x 0 0 10605-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/ADSAdClient31[1].htm 1142 ma.b r/rr-xr-xr-x 0 0 10618-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/c57bc2a7d38843d7c4aa8028fc9f82[1].gif 4095 ma.b r/rr-xr-xr-x 0 0 10619-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/8E1CE8BD265B47CBBE321FF47E2A1[1].jpg 978 ma.b r/rr-xr-xr-x 0 0 10620-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/ADSAdClient31[1].htm 4330 ma.b r/rr-xr-xr-x 0 0 10621-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/003[1].png 16533 ma.b r/rr-xr-xr-x 0 0 10622-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/544[1].jpg 176 ma.b r/rr-xr-xr-x 0 0 10625-128-1 /Documents and Settings/malware/Cookies/malware@ad.wsod[2].txt 42 m..b r/rr-xr-xr-x 0 0 10626-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/pixel[1].gif Fri Jul 01 2011 14:38:47 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.rad.msn.com/ADSAdClient31.dll?GetSAd=&DPJS=4&PN=MSFT&ID=0A9F82A7055868E13BAD83DD015868BB&MUID=0A9F82A7055868E13BAD83DD015868BB&PG=MSNREC&AP=1089 cache stored in: QJM5KT6J/ADSAdClient31[1].htm - HTTP/1.1 200 OK - Content-Length: 5200 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://api.bing.com/qsonhs.aspx?form=MSN005&q= cache stored in: YZCXGNW1/qsonhs[1].aspx - HTTP/1.1 200 OK - Content-Length: 35 - Content-Type: application/json_ charset=utf-8 - X-Akamai-TestID: 6ef8e433668e41d8bb73e8fca6cd23d2 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stb.s-msn.com/i/86/9934D0635AD244E5FA684B7B8CBD0.gif cache stored in: QJM5KT6J/9934D0635AD244E5FA684B7B8CBD0[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - ETag: "67c14931217cc1:0"- "" - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 7582 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stj.s-msn.com/br/sc/js/1c/4a0253de6eac448d8f2c39c53f8926.js cache stored in: SLK18LSF/4a0253de6eac448d8f2c39c53f8926[2].js - HTTP/1.1 200 OK - Content-Length: 554 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stj.s-msn.com/br/sc/js/1c/899538en_msn.js cache stored in: UPQVMROL/899538en_msn[1].js - HTTP/1.1 200 OK - Content-Length: 14512 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:www.bing.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:www.msn.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 5200 ma.b r/rr-xr-xr-x 0 0 10627-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/ADSAdClient31[1].htm 14512 ma.b r/rr-xr-xr-x 0 0 10629-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/899538en_msn[1].js 35 ma.b r/rr-xr-xr-x 0 0 10630-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/qsonhs[1].aspx 110 ma.b r/rr-xr-xr-x 0 0 10631-128-1 /Documents and Settings/malware/Cookies/malware@www.bing[1].txt 190 ...b r/rr-xr-xr-x 0 0 10634-128-1 /Documents and Settings/malware/Cookies/malware@bing[1].txt 188 ma.. r/rr-xr-xr-x 0 0 10635-128-1 /Documents and Settings/malware/Cookies/malware@www.msn[1].txt 7582 ma.b r/rr-xr-xr-x 0 0 10636-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/9934D0635AD244E5FA684B7B8CBD0[1].gif 554 ma.b r/rr-xr-xr-x 0 0 10637-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/4a0253de6eac448d8f2c39c53f8926[2].js 19882 ...b r/rr-xr-xr-x 0 0 5542-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/894[1].jpg Fri Jul 01 2011 14:38:48 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Internet Settings/5.0/Cache/Extensible Cache 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Internet Settings/5.0/Cache/Extensible Cache/MSHist012011070120110702 496 m... d/drwxrwxrwx 0 0 10463-144-1 /Documents and Settings/malware/Local Settings/History/History.IE5 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.ads2.msads.net/CIS/48/000/000/000/016/894.jpg cache stored in: UPQVMROL/894[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-AspNet-Version: 4.0.30319 - X-Powered-By: ASP.NET - Content-Length: 19882 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://analytics.live.com/Sync.html?V=3525&AQNT=1 cache stored in: YZCXGNW1/Sync[1].htm - HTTP/1.1 200 OK - Content-Length: 607 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://analytics.msn.com/Include.html cache stored in: YZCXGNW1/Include[1].htm - HTTP/1.1 200 OK - Content-Length: 464 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://col.stc.s-msn.com/br/sc/i/76/4378db7471b44dea1c183f006ee3d0.gif cache stored in: YZCXGNW1/4378db7471b44dea1c183f006ee3d0[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - ETag: "052428bbd36cc1:0"- - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 7322 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://www.msn.com (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:bing.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 113 .a.. r/rr-xr-xr-x 0 0 10568-128-1 /Documents and Settings/malware/Local Settings/History/desktop.ini 152 m..b d/drwxrwxrwx 0 0 10632-144-1 /Documents and Settings/malware/Local Settings/History/History.IE5/MSHist012011070120110702 190 ma.. r/rr-xr-xr-x 0 0 10634-128-1 /Documents and Settings/malware/Cookies/malware@bing[1].txt 0 macb 0 0 0 10638 [Internet Explorer] (Last Access) User: malware URL::Host: www.msn.com (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/MSHist012011070120110702/index.dat) 0 macb 0 0 0 10638 [Internet Explorer] (Last Access) User: malware URL:http://www.msn.com (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/MSHist012011070120110702/index.dat) 32768 .a.b r/rr-xr-xr-x 0 0 10638-128-3 /Documents and Settings/malware/Local Settings/History/History.IE5/MSHist012011070120110702/index.dat 607 ma.. r/rr-xr-xr-x 0 0 10641-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/Sync[1].htm 1988 m..b r/rr-xr-xr-x 0 0 10642-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/wlHelper[1].js 1340 m..b r/rr-xr-xr-x 0 0 10644-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/wlHelper[3].js 19882 ma.. r/rr-xr-xr-x 0 0 5542-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/894[1].jpg Fri Jul 01 2011 14:38:51 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://analytics.atdmt.com/Scripts/wlHelper.js?i=MUID cache stored in: QJM5KT6J/wlHelper[3].js - HTTP/1.1 200 OK - Content-Length: 1340 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://analytics.live.com/Scripts/wlHelper.js?i=ANID cache stored in: SLK18LSF/wlHelper[1].js - HTTP/1.1 200 OK - Content-Type: application/x-javascript_ charset=utf-8 - X-AspNet-Version: 2.0.50727 - X-Powered-By: ASP.NET - P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo" - Content-Length: 1988 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 1988 .a.. r/rr-xr-xr-x 0 0 10642-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/wlHelper[1].js 1340 .a.. r/rr-xr-xr-x 0 0 10644-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/wlHelper[3].js 464 .a.. r/rr-xr-xr-x 0 0 10809-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/Include[1].htm Fri Jul 01 2011 14:38:54 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/UserAssist/{5E6AB780-7743-11CF-A12B-00AA004AE837}/Count Fri Jul 01 2011 14:39:00 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/UsbFlags 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/UsbFlags/13fe1d200100 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USB 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USB/Vid_13fe&Pid_1d20 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USB/Vid_13fe&Pid_1d20/077403946E3A/LogConf 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/UsbFlags 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/UsbFlags/13fe1d200100 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USB 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USB/Vid_13fe&Pid_1d20 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USB/Vid_13fe&Pid_1d20/077403946E3A/LogConf 0 macb 0 0 0 10413 [XP Prefetch] (Last run) RUNDLL32.EXE-1B220F9A.pf - [RUNDLL32.EXE] was executed - run count [1]- full path: [C:/WINDOWS/SYSTEM32/RUNDLL32.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/IMAGEHLP.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/NEWDEV.DLL - WINDOWS/SYSTEM32/SETUPAPI.DLL - WINDOWS/SYSTEM32/WININET.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/CREDUI.DLL} (file: /media/sdb1/WINDOWS/Prefetch/RUNDLL32.EXE-1B220F9A.pf) 247808 .a.. r/rr-xr-xr-x 0 0 2825-128-3 /WINDOWS/system32/newdev.dll Fri Jul 01 2011 14:39:02 8 .a.. r/rr-xr-xr-x 0 0 3771-128-1 /WINDOWS/system32/CatRoot2/{F750E6C3-38EE-11D1-85E5-00C04FC295EE}/TimeStamp 8 .a.. r/rr-xr-xr-x 0 0 3772-128-1 /WINDOWS/system32/CatRoot/{F750E6C3-38EE-11D1-85E5-00C04FC295EE}/TimeStamp Fri Jul 01 2011 14:39:03 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Class/{36FC9E60-C465-11CF-8056-444553540000} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Class/{36FC9E60-C465-11CF-8056-444553540000}/0012 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{a5dcbf10-6530-11d2-901f-00c04fb951ed} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{a5dcbf10-6530-11d2-901f-00c04fb951ed}/##?#USB#Vid_13fe&Pid_1d20#077403946E3A#{a5dcbf10-6530-11d2-901f-00c04fb951ed} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{a5dcbf10-6530-11d2-901f-00c04fb951ed}/##?#USB#Vid_13fe&Pid_1d20#077403946E3A#{a5dcbf10-6530-11d2-901f-00c04fb951ed}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USB/Vid_13fe&Pid_1d20/077403946E3A 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/USBSTOR 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Class/{36FC9E60-C465-11CF-8056-444553540000} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Class/{36FC9E60-C465-11CF-8056-444553540000}/0012 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{a5dcbf10-6530-11d2-901f-00c04fb951ed} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{a5dcbf10-6530-11d2-901f-00c04fb951ed}/##?#USB#Vid_13fe&Pid_1d20#077403946E3A#{a5dcbf10-6530-11d2-901f-00c04fb951ed} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{a5dcbf10-6530-11d2-901f-00c04fb951ed}/##?#USB#Vid_13fe&Pid_1d20#077403946E3A#{a5dcbf10-6530-11d2-901f-00c04fb951ed}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USB/Vid_13fe&Pid_1d20/077403946E3A 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/USBSTOR 26368 .a.. r/rr-xr-xr-x 0 0 10678-128-3 /WINDOWS/system32/drivers/USBSTOR.SYS Fri Jul 01 2011 14:39:05 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f56307-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f56307-b6bf-11d0-94f2-00a0c91efb8b}/##?#USBSTOR#Disk&Ven_&Prod_Secure_Guard&Rev_PMAP#077403946E3A&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f56307-b6bf-11d0-94f2-00a0c91efb8b}/##?#USBSTOR#Disk&Ven_&Prod_Secure_Guard&Rev_PMAP#077403946E3A&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f5630a-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f5630a-b6bf-11d0-94f2-00a0c91efb8b}/##?#STORAGE#RemovableMedia#7&311e3236&0&RM#{53f5630a-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f5630a-b6bf-11d0-94f2-00a0c91efb8b}/##?#STORAGE#RemovableMedia#7&311e3236&0&RM#{53f5630a-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/STORAGE/RemovableMedia 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/STORAGE/RemovableMedia/7&311e3236&0&RM/LogConf 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USB/Vid_13fe&Pid_1d20/077403946E3A/Device Parameters 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USBSTOR 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USBSTOR/Disk&Ven_&Prod_Secure_Guard&Rev_PMAP 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USBSTOR/Disk&Ven_&Prod_Secure_Guard&Rev_PMAP/077403946E3A&0/Device Parameters/MediaChangeNotification 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USBSTOR/Disk&Ven_&Prod_Secure_Guard&Rev_PMAP/077403946E3A&0/LogConf 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USBSTOR/SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USBSTOR/SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP/077403946E3A&1/LogConf 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f56307-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f56307-b6bf-11d0-94f2-00a0c91efb8b}/##?#USBSTOR#Disk&Ven_&Prod_Secure_Guard&Rev_PMAP#077403946E3A&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f56307-b6bf-11d0-94f2-00a0c91efb8b}/##?#USBSTOR#Disk&Ven_&Prod_Secure_Guard&Rev_PMAP#077403946E3A&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f5630a-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f5630a-b6bf-11d0-94f2-00a0c91efb8b}/##?#STORAGE#RemovableMedia#7&311e3236&0&RM#{53f5630a-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f5630a-b6bf-11d0-94f2-00a0c91efb8b}/##?#STORAGE#RemovableMedia#7&311e3236&0&RM#{53f5630a-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/STORAGE/RemovableMedia 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/STORAGE/RemovableMedia/7&311e3236&0&RM/LogConf 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USB/Vid_13fe&Pid_1d20/077403946E3A/Device Parameters 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USBSTOR 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USBSTOR/Disk&Ven_&Prod_Secure_Guard&Rev_PMAP 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USBSTOR/Disk&Ven_&Prod_Secure_Guard&Rev_PMAP/077403946E3A&0/Device Parameters/MediaChangeNotification 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USBSTOR/Disk&Ven_&Prod_Secure_Guard&Rev_PMAP/077403946E3A&0/LogConf 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USBSTOR/SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USBSTOR/SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP/077403946E3A&1/LogConf Fri Jul 01 2011 14:39:06 74752 .a.. r/rr-xr-xr-x 0 0 3906-128-3 /WINDOWS/system32/storprop.dll Fri Jul 01 2011 14:39:08 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Class/{4D36E967-E325-11CE-BFC1-08002BE10318} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Class/{4D36E967-E325-11CE-BFC1-08002BE10318}/0003 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_FASTFAT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USBSTOR/Disk&Ven_&Prod_Secure_Guard&Rev_PMAP/077403946E3A&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USBSTOR/Disk&Ven_&Prod_Secure_Guard&Rev_PMAP/077403946E3A&0/Device Parameters 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Class/{4D36E967-E325-11CE-BFC1-08002BE10318} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Class/{4D36E967-E325-11CE-BFC1-08002BE10318}/0003 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_FASTFAT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USBSTOR/Disk&Ven_&Prod_Secure_Guard&Rev_PMAP/077403946E3A&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USBSTOR/Disk&Ven_&Prod_Secure_Guard&Rev_PMAP/077403946E3A&0/Device Parameters 143744 .a.. r/rr-xr-xr-x 0 0 1934-128-3 /WINDOWS/system32/drivers/fastfat.sys Fri Jul 01 2011 14:39:09 1048520 ...b r/rrwxrwxrwx 0 0 10633-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/change.log.1 1048472 ...b r/rrwxrwxrwx 0 0 10648-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/change.log.3 109652 ...b r/rrwxrwxrwx 0 0 11162-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/change.log.2 83990 ...b r/rrwxrwxrwx 0 0 11179-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/change.log 8480 ma.. r/rr-xr-xr-x 0 0 3871-128-3 /WINDOWS/inf/flpydisk.PNF Fri Jul 01 2011 14:39:10 13216 macb r/rrwxrwxrwx 0 0 10645-128-4 /WINDOWS/Prefetch/RUNDLL32.EXE-1B220F9A.pf Fri Jul 01 2011 14:39:11 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Class/{4D36E980-E325-11CE-BFC1-08002BE10318} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Class/{4D36E980-E325-11CE-BFC1-08002BE10318} Fri Jul 01 2011 14:39:12 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Class/{4D36E980-E325-11CE-BFC1-08002BE10318}/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/##?#USBSTOR#SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP#077403946E3A&1#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/##?#USBSTOR#SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP#077403946E3A&1#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f56311-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f56311-b6bf-11d0-94f2-00a0c91efb8b}/##?#USBSTOR#SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP#077403946E3A&1#{53f56311-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f56311-b6bf-11d0-94f2-00a0c91efb8b}/##?#USBSTOR#SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP#077403946E3A&1#{53f56311-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USBSTOR/SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP/077403946E3A&1 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USBSTOR/SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP/077403946E3A&1/Device Parameters 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USBSTOR/SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP/077403946E3A&1/Device Parameters/MediaChangeNotification 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Sfloppy 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Class/{4D36E980-E325-11CE-BFC1-08002BE10318}/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/##?#USBSTOR#SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP#077403946E3A&1#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/##?#USBSTOR#SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP#077403946E3A&1#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f56311-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f56311-b6bf-11d0-94f2-00a0c91efb8b}/##?#USBSTOR#SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP#077403946E3A&1#{53f56311-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f56311-b6bf-11d0-94f2-00a0c91efb8b}/##?#USBSTOR#SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP#077403946E3A&1#{53f56311-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USBSTOR/SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP/077403946E3A&1 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USBSTOR/SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP/077403946E3A&1/Device Parameters 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USBSTOR/SFloppy&Ven_&Prod_Secure_Guard&Rev_PMAP/077403946E3A&1/Device Parameters/MediaChangeNotification 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Sfloppy 0 m... 0 0 0 0 REG_System_system/MountedDevices 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/MountPoints2/{8adc8c6b-a42a-11e0-9a12-001558286148} 11392 .a.. r/rr-xr-xr-x 0 0 1923-128-3 /WINDOWS/system32/drivers/sfloppy.sys Fri Jul 01 2011 14:39:14 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Class/{71A27CDD-812A-11D0-BEC7-08002BE2092F} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Class/{71A27CDD-812A-11D0-BEC7-08002BE2092F}/0003 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/STORAGE/RemovableMedia/7&311e3236&0&RM 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Class/{71A27CDD-812A-11D0-BEC7-08002BE2092F} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Class/{71A27CDD-812A-11D0-BEC7-08002BE2092F}/0003 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/STORAGE/RemovableMedia/7&311e3236&0&RM 990208 .a.. r/rr-xr-xr-x 0 0 2125-128-3 /WINDOWS/system32/syssetup.dll Fri Jul 01 2011 14:39:15 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/##?#STORAGE#RemovableMedia#7&311e3236&0&RM#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/##?#STORAGE#RemovableMedia#7&311e3236&0&RM#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/##?#STORAGE#RemovableMedia#7&311e3236&0&RM#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/##?#STORAGE#RemovableMedia#7&311e3236&0&RM#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/# 271475 ma.. r/rr-xr-xr-x 0 0 3735-128-3 /WINDOWS/setupapi.log Fri Jul 01 2011 14:39:17 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/MountPoints2/{8adc8c6a-a42a-11e0-9a12-001558286148}/shell 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/MountPoints2/{8adc8c6a-a42a-11e0-9a12-001558286148}/shell/Autoplay 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/MountPoints2/{8adc8c6a-a42a-11e0-9a12-001558286148}/shell/Autoplay/DropTarget 0 macb 0 0 0 10413 [XP Prefetch] (Last run) RUNDLL32.EXE-451FC2C0.pf - [RUNDLL32.EXE] was executed - run count [6]- full path: [C:/WINDOWS/SYSTEM32/RUNDLL32.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/IMAGEHLP.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL} (file: /media/sdb1/WINDOWS/Prefetch/RUNDLL32.EXE-451FC2C0.pf) 10952 mac. r/rrwxrwxrwx 0 0 10682-128-4 /WINDOWS/Prefetch/RUNDLL32.EXE-451FC2C0.pf 33280 .a.. r/rr-xr-xr-x 0 0 2123-128-3 /WINDOWS/system32/rundll32.exe Fri Jul 01 2011 14:39:21 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/MountPoints2/{8adc8c6a-a42a-11e0-9a12-001558286148} Fri Jul 01 2011 14:39:29 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/Streams/1 Fri Jul 01 2011 14:39:34 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/StreamMRU 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/Streams 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/Streams/6 Fri Jul 01 2011 14:39:35 338432 .a.. r/rr-xr-xr-x 0 0 3254-128-3 /WINDOWS/system32/zipfldr.dll Fri Jul 01 2011 14:39:53 56 .a.. d/dr-xr-xr-x 0 0 10360-144-6 /Documents and Settings/LocalService 0 macb 0 0 0 10413 [XP Prefetch] (Last run) DOCUMENT.EXE-1502F88B.pf - [DOCUMENT.EXE] was executed - run count [1]- full path: [] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/WININET.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/APPHELP.DLL - WINDOWS/SYSTEM32/VERSION.DLL} (file: /media/sdb1/WINDOWS/Prefetch/DOCUMENT.EXE-1502F88B.pf) 0 macb 0 0 0 10413 [XP Prefetch] (Last run) SVCHOST.EXE-3530F672.pf - [SVCHOST.EXE] was executed - run count [3]- full path: [C:/WINDOWS/SYSTEM32/SVCHOST.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/WININET.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/WSOCK32.DLL - WINDOWS/SYSTEM32/WS2_32.DLL - WINDOWS/SYSTEM32/WS2HELP.DLL - WINDOWS/SYSTEM32/RASAPI32.DLL - WINDOWS/SYSTEM32/RASMAN.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/TAPI32.DLL - WINDOWS/SYSTEM32/RTUTILS.DLL - WINDOWS/SYSTEM32/SENSAPI.DLL - WINDOWS/SYSTEM32/URLMON.DLL - WINDOWS/SYSTEM32/MSWSOCK.DLL - WINDOWS/SYSTEM32/DNSAPI.DLL - WINDOWS/SYSTEM32/WEBCLNT.DLL - WINDOWS/SYSTEM32/REGSVC.DLL - WINDOWS/SYSTEM32/SCHEDSVC.DLL - WINDOWS/SYSTEM32/WKSSVC.DLL - WINDOWS/SYSTEM32/CRYPTSVC.DLL - WINDOWS/SYSTEM32/CERTCLI.DLL - WINDOWS/SYSTEM32/WUAUSERV.DLL - WINDOWS/SYSTEM32/WBEM/WMISVC.DLL - WINDOWS/SYSTEM32/DSSENH.DLL - WINDOWS/SYSTEM32/VSSAPI.DLL - WINDOWS/SYSTEM32/WUAUENG.DLL - WINDOWS/SYSTEM32/ADVPACK.DLL - WINDOWS/SYSTEM32/CABINET.DLL - WINDOWS/SYSTEM32/MSPATCHA.DLL - WINDOWS/SYSTEM32/SFC.DLL - WINDOWS/SYSTEM32/SFC_OS.DLL - WINDOWS/SYSTEM32/SHFOLDER.DLL - WINDOWS/SYSTEM32/WINHTTP.DLL - WINDOWS/SYSTEM32/W32TIME.DLL - WINDOWS/SYSTEM32/TRKWKS.DLL - WINDOWS/SYSTEM32/ES.DLL - WINDOWS/SYSTEM32/SRSVC.DLL - WINDOWS/SYSTEM32/POWRPROF.DLL - WINDOWS/SYSTEM32/SETUPAPI.DLL - WINDOWS/SYSTEM32/NTMARTA.DLL - WINDOWS/SYSTEM32/SECLOGON.DLL - WINDOWS/SYSTEM32/NETMAN.DLL - WINDOWS/SYSTEM32/NETSHELL.DLL - WINDOWS/SYSTEM32/CREDUI.DLL - WINDOWS/SYSTEM32/DOT3DLG.DLL - WINDOWS/SYSTEM32/ONEX.DLL - WINDOWS/SYSTEM32/EAPPCFG.DLL - WINDOWS/SYSTEM32/EAPPPRXY.DLL - WINDOWS/SYSTEM32/WZCSAPI.DLL - WINDOWS/SYSTEM32/IPHLPAPI.DLL - WINDOWS/SYSTEM32/HNETCFG.DLL - WINDOWS/SYSTEM32/WSHTCPIP.DLL - WINDOWS/SYSTEM32/SRVSVC.DLL - WINDOWS/SYSTEM32/NETMSG.DLL - WINDOWS/PCHEALTH/HELPCTR/BINARIES/PCHSVC.DLL - WINDOWS/SYSTEM32/MSXML3.DLL - WINDOWS/SYSTEM32/MSXML3R.DLL - WINDOWS/SYSTEM32/ERSVC.DLL - WINDOWS/SYSTEM32/WSCSVC.DLL - WINDOWS/SYSTEM32/MSI.DLL - WINDOWS/SYSTEM32/IPNATHLP.DLL - WINDOWS/SYSTEM32/AUTHZ.DLL - WINDOWS/SYSTEM32/SENS.DLL - WINDOWS/SYSTEM32/WBEM/WBEMPROX.DLL - WINDOWS/SYSTEM32/WBEM/WBEMCOMN.DLL - WINDOWS/SYSTEM32/BROWSER.DLL - WINDOWS/SYSTEM32/WBEM/WBEMCORE.DLL - WINDOWS/SYSTEM32/WBEM/ESSCLI.DLL - WINDOWS/SYSTEM32/WBEM/FASTPROX.DLL - WINDOWS/SYSTEM32/SENSCFG.DLL - WINDOWS/SYSTEM32/XPSP2RES.DLL - WINDOWS/SYSTEM32/WBEM/WBEMSVC.DLL - WINDOWS/SYSTEM32/SXS.DLL - WINDOWS/SYSTEM32/COMSVCS.DLL - WINDOWS/SYSTEM32/COLBACT.DLL - WINDOWS/SYSTEM32/MTXCLU.DLL - WINDOWS/SYSTEM32/CLUSAPI.DLL - WINDOWS/SYSTEM32/RESUTILS.DLL} (file: /media/sdb1/WINDOWS/Prefetch/SVCHOST.EXE-3530F672.pf) 10468 macb r/rrwxrwxrwx 0 0 10647-128-4 /WINDOWS/Prefetch/DOCUMENT.EXE-1502F88B.pf Fri Jul 01 2011 14:39:58 452608 ...b r/rr-xr-xr-x 0 0 10646-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/pusk[1].exe Fri Jul 01 2011 14:40:03 48206 mac. r/rrwxrwxrwx 0 0 10428-128-4 /WINDOWS/Prefetch/SVCHOST.EXE-3530F672.pf Fri Jul 01 2011 14:41:02 3153920 ma.. r/rr-xr-xr-x 0 0 3768-128-3 /WINDOWS/system32/CatRoot2/{F750E6C3-38EE-11D1-85E5-00C04FC295EE}/catdb Fri Jul 01 2011 14:42:26 78 .a.. r/rr-xr-xr-x 0 0 10548-128-1 /Documents and Settings/malware/My Documents/desktop.ini Fri Jul 01 2011 14:42:29 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/ShellNoRoam/BagMRU/3 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/ShellNoRoam/Bags 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/ShellNoRoam/Bags/1/Shell 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/ShellNoRoam/Bags/11 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/ShellNoRoam/DUIBags/ShellFolders 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/ShellNoRoam/DUIBags/ShellFolders/{450D8FBA-AD25-11D0-98A8-0800361B1103} 185 .a.. r/rr-xr-xr-x 0 0 10550-128-1 /Documents and Settings/malware/My Documents/My Pictures/Desktop.ini 183 .a.. r/rr-xr-xr-x 0 0 10553-128-1 /Documents and Settings/malware/My Documents/My Music/Desktop.ini Fri Jul 01 2011 14:42:32 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/ShellNoRoam/Bags/11/Shell Fri Jul 01 2011 14:42:44 555 .a.. r/rr-xr-xr-x 0 0 11075-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Windows Resource Kit Tools/Command Shell.lnk 555 .a.. r/rrwxrwxrwx 0 0 11151-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000122.lnk Fri Jul 01 2011 14:42:48 84 .a.. r/rr-xr-xr-x 0 0 10495-128-3 /Documents and Settings/malware/Start Menu/Programs/Startup/desktop.ini 1599 .a.. r/rr-xr-xr-x 0 0 10496-128-4 /Documents and Settings/malware/Start Menu/Programs/Remote Assistance.lnk 376 .a.. r/rr-xr-xr-x 0 0 10499-128-3 /Documents and Settings/malware/Start Menu/Programs/Messenger Center.lnk 382 .a.. r/rr-xr-xr-x 0 0 10500-128-3 /Documents and Settings/malware/Start Menu/Programs/Media Player Center.lnk 234 .a.. r/rr-xr-xr-x 0 0 10501-128-3 /Documents and Settings/malware/Start Menu/Programs/desktop.ini 792 .a.. r/rr-xr-xr-x 0 0 10505-128-4 /Documents and Settings/malware/Start Menu/Programs/Windows Media Player.lnk 542 .a.. r/rr-xr-xr-x 0 0 10508-128-3 /Documents and Settings/malware/Start Menu/Programs/Accessories/desktop.ini 767 .a.. r/rr-xr-xr-x 0 0 10565-128-4 /Documents and Settings/malware/Start Menu/Programs/Internet Explorer.lnk 738 .a.. r/rr-xr-xr-x 0 0 10576-128-4 /Documents and Settings/malware/Start Menu/Programs/Outlook Express.lnk 294 .a.. r/rr-xr-xr-x 0 0 10683-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000069.ini 265 .a.. r/rr-xr-xr-x 0 0 10808-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000079.ini 545 .a.. r/rr-xr-xr-x 0 0 10847-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000100.ini 150 .a.. r/rr-xr-xr-x 0 0 10853-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000105.ini 798 .a.. r/rr-xr-xr-x 0 0 10855-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000106.ini 1986 .a.. r/rrwxrwxrwx 0 0 11139-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000118.lnk 84 .a.. r/rr-xr-xr-x 0 0 11147-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000119.ini 609 .a.. r/rrwxrwxrwx 0 0 11148-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000120.lnk 786 .a.. r/rrwxrwxrwx 0 0 11149-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000121.lnk 1607 .a.. r/rrwxrwxrwx 0 0 11154-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000125.lnk 398 .a.. r/rrwxrwxrwx 0 0 11155-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000126.lnk 1507 .a.. r/rrwxrwxrwx 0 0 11156-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000127.lnk 294 .a.. r/rr-xr-xr-x 0 0 3844-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/desktop.ini 150 .a.. r/rr-xr-xr-x 0 0 3846-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/desktop.ini 84 .a.. r/rr-xr-xr-x 0 0 3848-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Startup/desktop.ini 265 .a.. r/rr-xr-xr-x 0 0 5488-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/desktop.ini 1986 .a.. r/rr-xr-xr-x 0 0 5494-128-3 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/MSN.lnk 545 .a.. r/rr-xr-xr-x 0 0 5502-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Administrative Tools/desktop.ini 798 .a.. r/rr-xr-xr-x 0 0 5526-128-3 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Games/desktop.ini 609 .a.. r/rr-xr-xr-x 0 0 5537-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Windows Messenger.lnk 786 .a.. r/rr-xr-xr-x 0 0 6549-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Windows Movie Maker.lnk 1507 .a.. r/rr-xr-xr-x 0 0 7591-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Windows Update.lnk 398 .a.. r/rr-xr-xr-x 0 0 7592-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Windows Catalog.lnk 1607 .a.. r/rr-xr-xr-x 0 0 7594-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Set Program Access and Defaults.lnk Fri Jul 01 2011 14:44:11 0 macb 0 0 0 10413 [XP Prefetch] (Last run) TASKMGR.EXE-20256C55.pf - [TASKMGR.EXE] was executed - run count [1]- full path: [] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/IPHLPAPI.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/WS2_32.DLL - WINDOWS/SYSTEM32/WS2HELP.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/VDMDBG.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/SYSTEM32/WINSTA.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/UTILDLL.DLL - WINDOWS/SYSTEM32/TAPI32.DLL - WINDOWS/SYSTEM32/RTUTILS.DLL - WINDOWS/SYSTEM32/SETUPAPI.DLL - WINDOWS/SYSTEM32/WTSAPI32.DLL} (file: /media/sdb1/WINDOWS/Prefetch/TASKMGR.EXE-20256C55.pf) 25600 .a.. r/rr-xr-xr-x 0 0 1433-128-3 /WINDOWS/system32/utildll.dll 26112 .a.. r/rr-xr-xr-x 0 0 3144-128-3 /WINDOWS/system32/vdmdbg.dll Fri Jul 01 2011 14:44:21 15094 macb r/rrwxrwxrwx 0 0 10649-128-4 /WINDOWS/Prefetch/TASKMGR.EXE-20256C55.pf Fri Jul 01 2011 14:44:25 135680 .a.. r/rr-xr-xr-x 0 0 3086-128-3 /WINDOWS/system32/taskmgr.exe Fri Jul 01 2011 14:45:18 0 macb 0 0 0 10413 [XP Prefetch] (Last run) PUSK.EXE-0C3E2A63.pf - [PUSK.EXE] was executed - run count [1]- full path: [] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/IMAGEHLP.DLL - WINDOWS/SYSTEM32/MSVCP60.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/WININET.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/OLE32.DLL} (file: /media/sdb1/WINDOWS/Prefetch/PUSK.EXE-0C3E2A63.pf) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://variantov.com/pusk.exe cache stored in: UPQVMROL/pusk[1].exe - HTTP/1.1 200 OK - Content-Type: application/octet-stream - Content-Length: 452608 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 452608 ma.. r/rr-xr-xr-x 0 0 10646-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/pusk[1].exe 452608 m... r/rr-xr-xr-x 0 0 10650-128-4 /Documents and Settings/All Users/Application Data/VDPLtsHLVdsd.exe 62 .a.. r/rr-xr-xr-x 0 0 3853-128-1 /Documents and Settings/All Users/Documents/desktop.ini Fri Jul 01 2011 14:45:22 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Policies/System 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Run 0 macb 0 0 0 10413 [XP Prefetch] (Last run) VDPLTSHLVDSD.EXE-134109E4.pf - [VDPLTSHLVDSD.EXE] was executed - run count [1]- full path: [] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/IMAGEHLP.DLL - WINDOWS/SYSTEM32/MSVCP60.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/WININET.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/OLE32.DLL} (file: /media/sdb1/WINDOWS/Prefetch/VDPLTSHLVDSD.EXE-134109E4.pf) 452608 ...b r/rr-xr-xr-x 0 0 10650-128-4 /Documents and Settings/All Users/Application Data/VDPLtsHLVdsd.exe Fri Jul 01 2011 14:45:23 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Internet Explorer/Download 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Policies/Associations 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Policies/Attachments 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://findlate.org/404.php?type=stats&affid=531&subid=01&awok cache stored in: YZCXGNW1/404[1].htm - HTTP/1.1 200 OK - Content-Type: text/html - Transfer-Encoding: chunked - X-Powered-By: PHP/5.2.10 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 ma.b r/rr-xr-xr-x 0 0 10651-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/404[1].htm Fri Jul 01 2011 14:45:24 299008 ...b r/rr-xr-xr-x 0 0 10654-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/531-direct[1] Fri Jul 01 2011 14:45:28 12538 macb r/rrwxrwxrwx 0 0 10658-128-4 /WINDOWS/Prefetch/PUSK.EXE-0C3E2A63.pf Fri Jul 01 2011 14:45:32 11364 macb r/rrwxrwxrwx 0 0 10660-128-4 /WINDOWS/Prefetch/VDPLTSHLVDSD.EXE-134109E4.pf Fri Jul 01 2011 14:45:40 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://finddelicate.org/pica1/531-direct cache stored in: SLK18LSF/531-direct[1] - HTTP/1.1 200 OK - Content-Type: application/octet-stream - Content-Length: 299008 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 299008 ma.. r/rr-xr-xr-x 0 0 10654-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/531-direct[1] Fri Jul 01 2011 14:45:41 0 macb 0 0 0 10413 [XP Prefetch] (Last run) ADOBE_FLASH_PLAYER.EXE-22950765.pf - [ADOBE_FLASH_PLAYER.EXE] was executed - run count [1]- full path: [] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/RPCSS.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/SETUPAPI.DLL - WINDOWS/SYSTEM32/CLBCATQ.DLL - WINDOWS/SYSTEM32/COMRES.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/URLMON.DLL - WINDOWS/SYSTEM32/APPHELP.DLL} (file: /media/sdb1/WINDOWS/Prefetch/ADOBE_FLASH_PLAYER.EXE-22950765.pf) 0 macb 0 0 0 10413 [XP Prefetch] (Last run) JAVAW.EXE-2B5AE019.pf - [JAVAW.EXE] was executed - run count [1]- full path: [] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL} (file: /media/sdb1/WINDOWS/Prefetch/JAVAW.EXE-2B5AE019.pf) 16250 macb r/rrwxrwxrwx 0 0 10663-128-4 /WINDOWS/Prefetch/ADOBE_FLASH_PLAYER.EXE-22950765.pf Fri Jul 01 2011 14:45:51 7730 macb r/rrwxrwxrwx 0 0 10675-128-4 /WINDOWS/Prefetch/JAVAW.EXE-2B5AE019.pf Fri Jul 01 2011 14:47:07 64281 ma.. r/rr-xr-xr-x 0 0 5556-128-3 /WINDOWS/system32/wbem/Logs/wbemcore.log Fri Jul 01 2011 14:48:27 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/Advanced 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/User Shell Folders 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/User Shell Folders/New 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Policies 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Policies/ActiveDesktop 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Policies/Explorer 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Shell Extensions/Cached 0 macb 0 0 0 10413 [XP Prefetch] (Last run) VERCLSID.EXE-3667BD89.pf - [VERCLSID.EXE] was executed - run count [18]- full path: [C:/WINDOWS/SYSTEM32/VERCLSID.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/RPCSS.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/SYSTEM32/CLBCATQ.DLL - WINDOWS/SYSTEM32/COMRES.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/SHDOCVW.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/CRYPTUI.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/WININET.DLL - WINDOWS/SYSTEM32/WINTRUST.DLL - WINDOWS/SYSTEM32/IMAGEHLP.DLL - WINDOWS/SYSTEM32/WLDAP32.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/RICHED20.DLL - WINDOWS/SYSTEM32/APPHELP.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/ZIPFLDR.DLL - WINDOWS/SYSTEM32/NETSHELL.DLL - WINDOWS/SYSTEM32/ATL.DLL - WINDOWS/SYSTEM32/CREDUI.DLL - WINDOWS/SYSTEM32/DOT3API.DLL - WINDOWS/SYSTEM32/RTUTILS.DLL - WINDOWS/SYSTEM32/DOT3DLG.DLL - WINDOWS/SYSTEM32/ONEX.DLL - WINDOWS/SYSTEM32/WTSAPI32.DLL - WINDOWS/SYSTEM32/WINSTA.DLL - WINDOWS/SYSTEM32/EAPPCFG.DLL - WINDOWS/SYSTEM32/MSVCP60.DLL - WINDOWS/SYSTEM32/EAPPPRXY.DLL - WINDOWS/SYSTEM32/IPHLPAPI.DLL - WINDOWS/SYSTEM32/WS2_32.DLL - WINDOWS/SYSTEM32/WS2HELP.DLL} (file: /media/sdb1/WINDOWS/Prefetch/VERCLSID.EXE-3667BD89.pf) 150 .ac. r/rr-xr-xr-x 0 0 10591-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000068.ini 17802 mac. r/rrwxrwxrwx 0 0 10615-128-4 /WINDOWS/Prefetch/VERCLSID.EXE-3667BD89.pf 150 m..b r/rr-xr-xr-x 0 0 10676-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000135.ini 312 ...b d/dr-xr-xr-x 0 0 10679-144-1 /Documents and Settings/malware/Local Settings/Temp/smtmp 56 ...b d/dr-xr-xr-x 0 0 10681-144-5 /Documents and Settings/malware/Local Settings/Temp/smtmp/1 56 ...b d/dr-xr-xr-x 0 0 10686-144-5 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs 56 ...b d/dr-xr-xr-x 0 0 10754-144-6 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories 400 m..b d/dr-xr-xr-x 0 0 10756-144-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Accessibility 56 ...b d/dr-xr-xr-x 0 0 10765-144-6 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Communications 294 ..c. r/rr-xr-xr-x 0 0 3844-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/desktop.ini 448 ..c. r/rr-xr-xr-x 0 0 4855-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Communications/desktop.ini 48 m... d/d--x--x--x 0 0 5521-144-1 /Documents and Settings/All Users/Start Menu/Programs/Accessories/Accessibility 90 ..c. r/rr-xr-xr-x 0 0 5523-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Accessibility/desktop.ini Fri Jul 01 2011 14:48:28 56 m... d/dr-xr-xr-x 0 0 10754-144-6 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories 56 m... d/dr-xr-xr-x 0 0 10765-144-6 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Communications 56 m..b d/dr-xr-xr-x 0 0 10810-144-6 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Entertainment 56 m..b d/dr-xr-xr-x 0 0 10830-144-6 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/System Tools 56 ...b d/dr-xr-xr-x 0 0 10843-144-6 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Administrative Tools 56 m... d/d--x--x--x 0 0 4852-144-6 /Documents and Settings/All Users/Start Menu/Programs/Accessories 48 m... d/d--x--x--x 0 0 4853-144-6 /Documents and Settings/All Users/Start Menu/Programs/Accessories/Communications 265 ..c. r/rr-xr-xr-x 0 0 5488-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/desktop.ini 545 ..c. r/rr-xr-xr-x 0 0 5502-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Administrative Tools/desktop.ini 48 m... d/d--x--x--x 0 0 5512-144-6 /Documents and Settings/All Users/Start Menu/Programs/Accessories/System Tools 757 ..c. r/rr-xr-xr-x 0 0 5514-128-3 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/System Tools/desktop.ini 48 m... d/d--x--x--x 0 0 5517-144-6 /Documents and Settings/All Users/Start Menu/Programs/Accessories/Entertainment 146 ..c. r/rr-xr-xr-x 0 0 5519-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Entertainment/desktop.ini Fri Jul 01 2011 14:48:29 48 m... d/d--x--x--x 0 0 10562-144-6 /Documents and Settings/malware/Application Data/Microsoft/Internet Explorer/Quick Launch 119 ..c. r/rr-xr-xr-x 0 0 10564-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/2/desktop.ini 312 m... d/dr-xr-xr-x 0 0 10679-144-1 /Documents and Settings/malware/Local Settings/Temp/smtmp 56 m... d/dr-xr-xr-x 0 0 10681-144-5 /Documents and Settings/malware/Local Settings/Temp/smtmp/1 56 m... d/dr-xr-xr-x 0 0 10686-144-5 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs 56 m... d/dr-xr-xr-x 0 0 10843-144-6 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Administrative Tools 56 m..b d/dr-xr-xr-x 0 0 10854-144-5 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Games 48 m... d/dr-xr-xr-x 0 0 11072-144-6 /Documents and Settings/All Users/Start Menu/Programs/Windows Resource Kit Tools 152 m..b d/dr-xr-xr-x 0 0 11146-144-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Startup 56 m..b d/dr-xr-xr-x 0 0 11150-144-6 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Windows Resource Kit Tools 48 m..b d/dr-xr-xr-x 0 0 11157-144-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/4 656 m..b d/dr-xr-xr-x 0 0 11158-144-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/2 56 m... d/d--x--x--x 0 0 3843-144-6 /Documents and Settings/All Users/Start Menu 56 m... d/d--x--x--x 0 0 3845-144-5 /Documents and Settings/All Users/Start Menu/Programs 150 ..c. r/rr-xr-xr-x 0 0 3846-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/desktop.ini 48 m... d/d--x--x--x 0 0 3847-144-1 /Documents and Settings/All Users/Start Menu/Programs/Startup 84 ..c. r/rr-xr-xr-x 0 0 3848-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Startup/desktop.ini 48 m... d/d--x--x--x 0 0 5500-144-6 /Documents and Settings/All Users/Start Menu/Programs/Administrative Tools 48 m... d/d--x--x--x 0 0 5524-144-5 /Documents and Settings/All Users/Start Menu/Programs/Games 798 ..c. r/rr-xr-xr-x 0 0 5526-128-3 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Games/desktop.ini Fri Jul 01 2011 14:48:30 56 .a.. d/drwxrwxrwx 0 0 10306-144-6 /Documents and Settings/NetworkService/Application Data/Microsoft 56 .a.. d/drwxrwxrwx 0 0 10373-144-6 /Documents and Settings/LocalService/Application Data/Microsoft 22984 ...b r/rrwxrwxrwx 0 0 11161-128-4 /WINDOWS/Prefetch/ATTRIB.EXE-39EAFB02.pf 56 .a.. d/dr-xr-xr-x 0 0 3633-144-6 /Documents and Settings/NetworkService 56 .a.. d/drwxrwxrwx 0 0 3745-144-6 /Documents and Settings/Default User/Application Data/Microsoft Fri Jul 01 2011 14:48:32 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/MenuOrder/Start Menu2/Programs 62 .a.. r/rr-xr-xr-x 0 0 10514-128-3 /Documents and Settings/malware/Start Menu/desktop.ini Fri Jul 01 2011 14:48:33 56 .a.. d/d-wx-wx-wx 0 0 47-144-6 /WINDOWS/Fonts Fri Jul 01 2011 14:48:39 56 .a.. d/dr-xr-xr-x 0 0 4147-144-6 /WINDOWS/Installer Fri Jul 01 2011 14:48:41 56 .a.. d/drwxrwxrwx 0 0 10223-144-6 /WINDOWS/system32/config/systemprofile/Application Data/Microsoft Fri Jul 01 2011 14:48:42 56 .a.. d/d--x--x--x 0 0 71-144-7 /WINDOWS/system32/dllcache Fri Jul 01 2011 14:48:50 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows NT/CurrentVersion 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows NT/CurrentVersion/TaskManager Fri Jul 01 2011 14:48:53 144 .a.. d/drwxrwxrwx 0 0 10405-144-1 /WINDOWS/system32/Microsoft 152 .a.. d/drwxrwxrwx 0 0 10406-144-1 /WINDOWS/system32/Microsoft/Protect 144 .a.. d/drwxrwxrwx 0 0 10407-144-1 /WINDOWS/system32/Microsoft/Protect/S-1-5-18 56 .a.. d/drwxrwxrwx 0 0 10408-144-5 /WINDOWS/system32/Microsoft/Protect/S-1-5-18/User Fri Jul 01 2011 14:49:00 1048520 mac. r/rrwxrwxrwx 0 0 10633-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/change.log.1 0 ..c. r/rr-xr-xr-x 0 0 11165-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000134.exe Fri Jul 01 2011 14:49:02 248 .a.. d/drwxrwxrwx 0 0 6135-144-1 /WINDOWS/Tasks Fri Jul 01 2011 14:50:09 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/StartPage 20480 .a.. r/rr-xr-xr-x 0 0 2176-128-3 /WINDOWS/system32/sclgntfy.dll Fri Jul 01 2011 14:50:10 109652 ma.. r/rrwxrwxrwx 0 0 11162-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/change.log.2 178 ..c. r/rr-xr-xr-x 0 0 11163-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000130.ini 178 ma.. r/rr-xr-xr-x 0 0 12072-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000136.ini Fri Jul 01 2011 14:50:11 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Session Manager/AppCompatibility 20480 .a.. r/rr-xr-xr-x 0 0 10368-128-4 /System Volume Information/tracking.log 8192 ma.. r/rr-xr-xr-x 0 0 3760-128-3 /WINDOWS/system32/CatRoot2/edb.chk Fri Jul 01 2011 14:50:12 24 mac. r/rr-xr-xr-x 0 0 10410-128-1 /WINDOWS/system32/Microsoft/Protect/S-1-5-18/User/Preferred 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) EventLog/6006_Info_ (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 ma.. r/rr-xr-xr-x 0 0 3779-128-3 /WINDOWS/system32/CatRoot2/edb.log 388 macb r/rr-xr-xr-x 0 0 4824-128-1 /WINDOWS/system32/Microsoft/Protect/S-1-5-18/User/317d6b3f-8ca3-4e12-a89f-4e263595d5f1 Fri Jul 01 2011 14:50:14 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Watchdog/Display 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Windows Fri Jul 01 2011 14:50:28 0 m... 0 0 0 0 REG_System_system 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{4afa3d51-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#ThermalZone#THM0#{4afa3d51-74a7-11d0-be5e-00a0c9062857} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{4afa3d51-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#ThermalZone#THM0#{4afa3d51-74a7-11d0-be5e-00a0c9062857}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{4afa3d53-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#FixedButton#2&daba3ff&0#{4afa3d53-74a7-11d0-be5e-00a0c9062857} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{4afa3d53-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#FixedButton#2&daba3ff&0#{4afa3d53-74a7-11d0-be5e-00a0c9062857}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{4afa3d53-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#PNP0C0D#2&daba3ff&0#{4afa3d53-74a7-11d0-be5e-00a0c9062857} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{4afa3d53-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#PNP0C0D#2&daba3ff&0#{4afa3d53-74a7-11d0-be5e-00a0c9062857}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{4afa3d53-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#PNP0C0E#2&daba3ff&0#{4afa3d53-74a7-11d0-be5e-00a0c9062857} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{4afa3d53-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#PNP0C0E#2&daba3ff&0#{4afa3d53-74a7-11d0-be5e-00a0c9062857}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/IDConfigDB 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/FixedButton/2&daba3ff&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/GenuineIntel_-_x86_Family_6_Model_13/_0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/IBM0057/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/IBM0071/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/NSC1100/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0000/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0100/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0200/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0303/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0400/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0501/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0700/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0800/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0A08/2&daba3ff&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0A08/2&daba3ff&0/Device Parameters 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0B00/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0C01/2&daba3ff&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0C02/0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0C04/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0C09/0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0C0D/2&daba3ff&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0C0E/2&daba3ff&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/ThermalZone/THM0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI_HAL/PNP0C08/0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/HTREE/ROOT/0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ISAPNP/ReadDataPort/0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_1002&DEV_5460&SUBSYS_056E1014&REV_00/4&266c3fa7&0&0008 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_1180&DEV_0476&SUBSYS_056C1014&REV_8D/4&ad1b67f&0&00F0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_14E4&DEV_167D&SUBSYS_05771014&REV_11/4&111a1fd8&0&00E0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_2448&SUBSYS_00000000&REV_D3/3&b1bfb68&0&F0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_2448&SUBSYS_00000000&REV_D3/3&b1bfb68&0&F0/Device Parameters 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_2590&SUBSYS_00000000&REV_03/3&b1bfb68&0&00 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_2591&SUBSYS_00000000&REV_03/3&b1bfb68&0&08 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_2591&SUBSYS_00000000&REV_03/3&b1bfb68&0&08/Device Parameters 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_2641&SUBSYS_00000000&REV_03/3&b1bfb68&0&F8 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_2653&SUBSYS_056A1014&REV_03/3&b1bfb68&0&FA 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_2658&SUBSYS_05651014&REV_03/3&b1bfb68&0&E8 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_2659&SUBSYS_05651014&REV_03/3&b1bfb68&0&E9 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_265A&SUBSYS_05651014&REV_03/3&b1bfb68&0&EA 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_265B&SUBSYS_05651014&REV_03/3&b1bfb68&0&EB 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_265C&SUBSYS_05661014&REV_03/3&b1bfb68&0&EF 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_2660&SUBSYS_00000000&REV_03/3&b1bfb68&0&E0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_2660&SUBSYS_00000000&REV_03/3&b1bfb68&0&E0/Device Parameters 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_2664&SUBSYS_00000000&REV_03/3&b1bfb68&0&E2 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_266A&SUBSYS_056B1014&REV_03/3&b1bfb68&0&FB 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_266D&SUBSYS_05761014&REV_03/3&b1bfb68&0&F3 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_266E&SUBSYS_05671014&REV_03/3&b1bfb68&0&F2 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCI/VEN_8086&DEV_4224&SUBSYS_10108086&REV_05/4&ad1b67f&0&10F0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/ACPI_HAL/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/COMPOSITE_BATTERY/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_AFD/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_BEEP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_DMBOOT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_DMLOAD/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_FIPS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_GPC/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_HTTP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_IPNAT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_IPSEC/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_IRDA/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_KSECDD/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_MNMDD/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_MOUNTMGR/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_NDIS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_NDISTAPI/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_NDISUIO/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_NDPROXY/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_NETBT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_NULL/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_PARTMGR/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_PARVDM/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_PCIIDE/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_RASACD/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_RDPCDD/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_TCPIP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_VGASAVE/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_VOLSNAP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_WANARP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/MEDIA/MS_MMACM 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/MEDIA/MS_MMDRV 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/MEDIA/MS_MMMCI 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/MEDIA/MS_MMVCD 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/MEDIA/MS_MMVID 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/MS_IRDAMINIPORT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/MS_L2TPMINIPORT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/MS_NDISWANIP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/MS_PPPOEMINIPORT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/MS_PPTPMINIPORT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/MS_PSCHEDMP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/MS_PSCHEDMP/0001 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/MS_PTIMINIPORT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/RDPDR/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/RDP_KBD/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/RDP_MOU/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/SYSTEM/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/SYSTEM/0001 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/SYSTEM/0002 0 m... 0 0 0 0 REG_System_system/ControlSet001/Hardware Profiles 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/ACPI 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/ACPIEC 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/AFD 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/ALG 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/AudioSrv 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Beep 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Browser 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/COMSysApp 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Cdfs 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Compbatt 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/CryptSvc 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/DcomLaunch 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Dhcp 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Dnscache 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/ERSvc 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/EventSystem 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/FastUserSwitchingCompatibility 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Fastfat 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Fdc 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Fips 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/FltMgr 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Fs_Rec 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Ftdisk 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Gpc 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/HTTP 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/IPSec 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/IRENUM 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/ImapiService 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/IntelIde 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/IpNat 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Irmon 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/KSecDD 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Kbdclass 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/LanmanServer 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/LmHosts 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/MRxDAV 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/MRxSmb 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/MSDTC 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/MSIServer 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Mouclass 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/MountMgr 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Msfs 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Mup 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/NDIS 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/NDProxy 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/NSCIRDA 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/NdisTapi 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/NdisWan 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Ndisuio 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/NetBIOS 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/NetBT 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Netman 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Nla 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Npfs 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Ntfs 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Null 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/PCI 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/PCIIde 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/PSched 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/ParVdm 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/PartMgr 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Pcmcia 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/PolicyAgent 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/PptpMiniport 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/ProtectedStorage 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Ptilink 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/RDPCDD 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/RDPNP 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/RasAcd 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/RasMan 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/RasPppoe 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Rasirda 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Rasl2tp 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Raspti 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Rdbss 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/RemoteRegistry 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/RpcSs 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/SENS 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/SSDPSRV 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/SamSs 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Schedule 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Serial 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/SharedAccess 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/ShellHWDetection 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Spooler 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Srv 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/TapiSrv 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Tcpip 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/TermDD 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/TermService 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Themes 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/TrkWks 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Update 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/VgaSave 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/VolSnap 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/W32Time 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/WZCSVC 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Wanarp 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/WebClient 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/audstub 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/b57w2k 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/dmboot 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/dmload 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/helpsvc 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/i8042prt 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/intelppm 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/irda 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/isapnp 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/lanmanworkstation 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/mnmdd 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/rdpdr 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/seclogon 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/serenum 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/sr 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/srservice 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/stisvc 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/swenum 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/usbehci 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/usbuhci 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/winmgmt 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/wscsvc 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/wuauserv 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{4afa3d51-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#ThermalZone#THM0#{4afa3d51-74a7-11d0-be5e-00a0c9062857} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{4afa3d51-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#ThermalZone#THM0#{4afa3d51-74a7-11d0-be5e-00a0c9062857}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{4afa3d53-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#FixedButton#2&daba3ff&0#{4afa3d53-74a7-11d0-be5e-00a0c9062857} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{4afa3d53-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#FixedButton#2&daba3ff&0#{4afa3d53-74a7-11d0-be5e-00a0c9062857}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{4afa3d53-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#PNP0C0D#2&daba3ff&0#{4afa3d53-74a7-11d0-be5e-00a0c9062857} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{4afa3d53-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#PNP0C0D#2&daba3ff&0#{4afa3d53-74a7-11d0-be5e-00a0c9062857}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{4afa3d53-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#PNP0C0E#2&daba3ff&0#{4afa3d53-74a7-11d0-be5e-00a0c9062857} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{4afa3d53-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#PNP0C0E#2&daba3ff&0#{4afa3d53-74a7-11d0-be5e-00a0c9062857}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/IDConfigDB 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/FixedButton/2&daba3ff&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/GenuineIntel_-_x86_Family_6_Model_13/_0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/IBM0057/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/IBM0071/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/NSC1100/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0000/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0100/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0200/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0303/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0400/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0501/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0700/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0800/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0A08/2&daba3ff&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0A08/2&daba3ff&0/Device Parameters 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0B00/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0C01/2&daba3ff&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0C02/0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0C04/4&3863886d&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0C09/0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0C0D/2&daba3ff&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0C0E/2&daba3ff&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/ThermalZone/THM0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI_HAL/PNP0C08/0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/HTREE/ROOT/0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ISAPNP/ReadDataPort/0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_1002&DEV_5460&SUBSYS_056E1014&REV_00/4&266c3fa7&0&0008 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_1180&DEV_0476&SUBSYS_056C1014&REV_8D/4&ad1b67f&0&00F0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_14E4&DEV_167D&SUBSYS_05771014&REV_11/4&111a1fd8&0&00E0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_2448&SUBSYS_00000000&REV_D3/3&b1bfb68&0&F0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_2448&SUBSYS_00000000&REV_D3/3&b1bfb68&0&F0/Device Parameters 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_2590&SUBSYS_00000000&REV_03/3&b1bfb68&0&00 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_2591&SUBSYS_00000000&REV_03/3&b1bfb68&0&08 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_2591&SUBSYS_00000000&REV_03/3&b1bfb68&0&08/Device Parameters 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_2641&SUBSYS_00000000&REV_03/3&b1bfb68&0&F8 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_2653&SUBSYS_056A1014&REV_03/3&b1bfb68&0&FA 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_2658&SUBSYS_05651014&REV_03/3&b1bfb68&0&E8 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_2659&SUBSYS_05651014&REV_03/3&b1bfb68&0&E9 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_265A&SUBSYS_05651014&REV_03/3&b1bfb68&0&EA 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_265B&SUBSYS_05651014&REV_03/3&b1bfb68&0&EB 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_265C&SUBSYS_05661014&REV_03/3&b1bfb68&0&EF 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_2660&SUBSYS_00000000&REV_03/3&b1bfb68&0&E0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_2660&SUBSYS_00000000&REV_03/3&b1bfb68&0&E0/Device Parameters 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_2664&SUBSYS_00000000&REV_03/3&b1bfb68&0&E2 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_266A&SUBSYS_056B1014&REV_03/3&b1bfb68&0&FB 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_266D&SUBSYS_05761014&REV_03/3&b1bfb68&0&F3 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_266E&SUBSYS_05671014&REV_03/3&b1bfb68&0&F2 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCI/VEN_8086&DEV_4224&SUBSYS_10108086&REV_05/4&ad1b67f&0&10F0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/ACPI_HAL/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/COMPOSITE_BATTERY/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_AFD/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_BEEP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_DMBOOT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_DMLOAD/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_FIPS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_GPC/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_HTTP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_IPNAT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_IPSEC/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_IRDA/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_KSECDD/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_MNMDD/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_MOUNTMGR/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_NDIS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_NDISTAPI/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_NDISUIO/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_NDPROXY/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_NETBT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_NULL/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_PARTMGR/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_PARVDM/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_PCIIDE/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_RASACD/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_RDPCDD/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_TCPIP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_VGASAVE/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_VOLSNAP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_WANARP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/MEDIA/MS_MMACM 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/MEDIA/MS_MMDRV 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/MEDIA/MS_MMMCI 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/MEDIA/MS_MMVCD 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/MEDIA/MS_MMVID 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/MS_IRDAMINIPORT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/MS_L2TPMINIPORT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/MS_NDISWANIP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/MS_PPPOEMINIPORT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/MS_PPTPMINIPORT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/MS_PSCHEDMP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/MS_PSCHEDMP/0001 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/MS_PTIMINIPORT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/RDPDR/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/RDP_KBD/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/RDP_MOU/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/SYSTEM/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/SYSTEM/0001 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/SYSTEM/0002 0 m... 0 0 0 0 REG_System_system/ControlSet002/Hardware Profiles 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/ACPI 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/ACPIEC 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/AFD 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/ALG 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/AudioSrv 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Beep 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Browser 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/COMSysApp 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Cdfs 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Compbatt 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/CryptSvc 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/DcomLaunch 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Dhcp 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Dnscache 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/ERSvc 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/EventSystem 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/FastUserSwitchingCompatibility 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Fastfat 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Fdc 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Fips 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/FltMgr 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Fs_Rec 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Ftdisk 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Gpc 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/HTTP 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/IPSec 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/IRENUM 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/ImapiService 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/IntelIde 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/IpNat 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Irmon 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/KSecDD 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Kbdclass 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/LanmanServer 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/LmHosts 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/MRxDAV 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/MRxSmb 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/MSDTC 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/MSIServer 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Mouclass 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/MountMgr 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Msfs 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Mup 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/NDIS 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/NDProxy 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/NSCIRDA 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/NdisTapi 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/NdisWan 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Ndisuio 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/NetBIOS 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/NetBT 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Netman 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Nla 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Npfs 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Ntfs 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Null 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/PCI 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/PCIIde 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/PSched 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/ParVdm 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/PartMgr 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Pcmcia 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/PolicyAgent 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/PptpMiniport 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/ProtectedStorage 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Ptilink 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/RDPCDD 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/RDPNP 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/RasAcd 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/RasMan 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/RasPppoe 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Rasirda 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Rasl2tp 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Raspti 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Rdbss 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/RemoteRegistry 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/RpcSs 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/SENS 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/SSDPSRV 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/SamSs 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Schedule 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Serial 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/SharedAccess 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/ShellHWDetection 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Spooler 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Srv 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/TapiSrv 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Tcpip 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/TermDD 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/TermService 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Themes 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/TrkWks 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Update 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/VgaSave 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/VolSnap 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/W32Time 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/WZCSVC 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Wanarp 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/WebClient 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/audstub 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/b57w2k 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/dmboot 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/dmload 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/helpsvc 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/i8042prt 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/intelppm 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/irda 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/isapnp 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/lanmanworkstation 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/mnmdd 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/rdpdr 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/seclogon 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/serenum 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/sr 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/srservice 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/stisvc 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/swenum 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/usbehci 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/usbuhci 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/winmgmt 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/wscsvc 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/wuauserv Fri Jul 01 2011 14:50:29 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Class/{4D36E96A-E325-11CE-BFC1-08002BE10318}/0001 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Class/{4D36E96A-E325-11CE-BFC1-08002BE10318}/0002 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f5630e-b6bf-11d0-94f2-00a0c91efb8b}/##?#Root#ftdisk#0000#{53f5630e-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f5630e-b6bf-11d0-94f2-00a0c91efb8b}/##?#Root#ftdisk#0000#{53f5630e-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/ACPI0003/0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/IBM0068/5&2890d699&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/ACPI/PNP0C0A/0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/IDE/DiskHTS541060G9AT00_________________________MB3IA60A/5&2c06044&0&0.0.0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCIIDE/IDEChannel/4&345649fa&0&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/PCIIDE/IDEChannel/4&345649fa&0&1 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/ftdisk/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/CmBatt 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Disk 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/atapi 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Class/{4D36E96A-E325-11CE-BFC1-08002BE10318}/0001 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Class/{4D36E96A-E325-11CE-BFC1-08002BE10318}/0002 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f5630e-b6bf-11d0-94f2-00a0c91efb8b}/##?#Root#ftdisk#0000#{53f5630e-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f5630e-b6bf-11d0-94f2-00a0c91efb8b}/##?#Root#ftdisk#0000#{53f5630e-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/ACPI0003/0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/IBM0068/5&2890d699&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/ACPI/PNP0C0A/0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/IDE/DiskHTS541060G9AT00_________________________MB3IA60A/5&2c06044&0&0.0.0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCIIDE/IDEChannel/4&345649fa&0&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/PCIIDE/IDEChannel/4&345649fa&0&1 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/ftdisk/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/CmBatt 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Disk 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/atapi Fri Jul 01 2011 14:50:30 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f56307-b6bf-11d0-94f2-00a0c91efb8b}/##?#IDE#DiskHTS541060G9AT00_________________________MB3IA60A#5&2c06044&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f56307-b6bf-11d0-94f2-00a0c91efb8b}/##?#IDE#DiskHTS541060G9AT00_________________________MB3IA60A#5&2c06044&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/##?#STORAGE#Volume#1&30a96598&0&Signature56DF56DFOffset7E00Length18E356200#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/##?#STORAGE#Volume#1&30a96598&0&Signature56DF56DFOffset7E00Length18E356200#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/IDE/CdRomHL-DT-ST_RW/DVD_GCC-4242N_______________0J05____/5&2ba179a6&0&0.0.0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_FLTMGR/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_MUP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_NTFS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_SR/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/STORAGE/Volume/1&30a96598&0&Signature56DF56DFOffset7E00Length18E356200 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Cdrom 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Imapi 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/redbook 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f56307-b6bf-11d0-94f2-00a0c91efb8b}/##?#IDE#DiskHTS541060G9AT00_________________________MB3IA60A#5&2c06044&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f56307-b6bf-11d0-94f2-00a0c91efb8b}/##?#IDE#DiskHTS541060G9AT00_________________________MB3IA60A#5&2c06044&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/##?#STORAGE#Volume#1&30a96598&0&Signature56DF56DFOffset7E00Length18E356200#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/##?#STORAGE#Volume#1&30a96598&0&Signature56DF56DFOffset7E00Length18E356200#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/IDE/CdRomHL-DT-ST_RW/DVD_GCC-4242N_______________0J05____/5&2ba179a6&0&0.0.0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_FLTMGR/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_MUP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_NTFS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_SR/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/STORAGE/Volume/1&30a96598&0&Signature56DF56DFOffset7E00Length18E356200 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Cdrom 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Imapi 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/redbook Fri Jul 01 2011 14:50:31 256 .a.. d/drwxrwxrwx 0 0 10363-144-1 /Documents and Settings/LocalService/Local Settings/Temporary Internet Files 56 .a.. d/drwxrwxrwx 0 0 10364-144-5 /Documents and Settings/LocalService/Local Settings/Temporary Internet Files/Content.IE5 256 .a.. d/drwxrwxrwx 0 0 10369-144-1 /Documents and Settings/LocalService/Local Settings/History 256 .a.. d/drwxrwxrwx 0 0 10370-144-1 /Documents and Settings/LocalService/Local Settings/History/History.IE5 152 .a.. d/drwxrwxrwx 0 0 10371-144-1 /Documents and Settings/LocalService/Cookies 0 macb 0 0 0 10413 [XP Prefetch] (Last run) NTOSBOOT-B00DFAAD.pf - [NTOSBOOT] was executed - run count [9]- full path: [] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/SFCFILES.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/COMDLG32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/IMAGEHLP.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/LZ32.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/OLECLI32.DLL - WINDOWS/SYSTEM32/OLECNV32.DLL - WINDOWS/SYSTEM32/OLESVR32.DLL - WINDOWS/SYSTEM32/OLETHK32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/URL.DLL - WINDOWS/SYSTEM32/URLMON.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/WININET.DLL - WINDOWS/SYSTEM32/WLDAP32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/MPR.DLL - WINDOWS/SYSTEM32/WOW32.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/SHDOCVW.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/APPHELP.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/CRYPTUI.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/WINTRUST.DLL - WINDOWS/SYSTEM32/CSRSRV.DLL - WINDOWS/SYSTEM32/BASESRV.DLL - WINDOWS/SYSTEM32/WINSRV.DLL - WINDOWS/SYSTEM32/VGA.DLL - WINDOWS/SYSTEM32/FRAMEBUF.DLL - WINDOWS/SYSTEM32/VGA256.DLL - WINDOWS/SYSTEM32/VGA64K.DLL - WINDOWS/SYSTEM32/AUTHZ.DLL - WINDOWS/SYSTEM32/NDDEAPI.DLL - WINDOWS/SYSTEM32/PROFMAP.DLL - WINDOWS/SYSTEM32/PSAPI.DLL - WINDOWS/SYSTEM32/REGAPI.DLL - WINDOWS/SYSTEM32/SETUPAPI.DLL - WINDOWS/SYSTEM32/WINSTA.DLL - WINDOWS/SYSTEM32/WS2_32.DLL - WINDOWS/SYSTEM32/WS2HELP.DLL - WINDOWS/SYSTEM32/KBDUS.DLL - WINDOWS/SYSTEM32/MSGINA.DLL - WINDOWS/SYSTEM32/ODBC32.DLL - WINDOWS/SYSTEM32/SXS.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/ODBCINT.DLL - WINDOWS/SYSTEM32/SHSVCS.DLL - WINDOWS/SYSTEM32/SFC.DLL - WINDOWS/SYSTEM32/SFC_OS.DLL - WINDOWS/SYSTEM32/NCOBJAPI.DLL - WINDOWS/SYSTEM32/MSVCP60.DLL - WINDOWS/SYSTEM32/SCESRV.DLL - WINDOWS/SYSTEM32/UMPNPMGR.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACADPROC.DLL - WINDOWS/SYSTEM32/LSASRV.DLL - WINDOWS/SYSTEM32/NTDSAPI.DLL - WINDOWS/SYSTEM32/DNSAPI.DLL - WINDOWS/SYSTEM32/SAMLIB.DLL - WINDOWS/SYSTEM32/SAMSRV.DLL - WINDOWS/SYSTEM32/CRYPTDLL.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/SYSTEM32/SCHANNEL.DLL - WINDOWS/SYSTEM32/MSPRIVS.DLL - WINDOWS/SYSTEM32/KERBEROS.DLL - WINDOWS/SYSTEM32/MSV1_0.DLL - WINDOWS/SYSTEM32/IPHLPAPI.DLL - WINDOWS/SYSTEM32/NETLOGON.DLL - WINDOWS/SYSTEM32/W32TIME.DLL - WINDOWS/SYSTEM32/WDIGEST.DLL - WINDOWS/SYSTEM32/RSAENH.DLL - WINDOWS/SYSTEM32/WINSCARD.DLL - WINDOWS/SYSTEM32/WTSAPI32.DLL - WINDOWS/SYSTEM32/SCECLI.DLL - WINDOWS/SYSTEM32/NTMARTA.DLL - WINDOWS/SYSTEM32/RPCSS.DLL - WINDOWS/SYSTEM32/XPSP2RES.DLL - WINDOWS/SYSTEM32/EVENTLOG.DLL - WINDOWS/SYSTEM32/NETEVENT.DLL - WINDOWS/SYSTEM32/MSWSOCK.DLL - WINDOWS/SYSTEM32/HNETCFG.DLL - WINDOWS/SYSTEM32/WSHTCPIP.DLL - WINDOWS/SYSTEM32/WINRNR.DLL - WINDOWS/SYSTEM32/RASADHLP.DLL - WINDOWS/SYSTEM32/DHCPCSVC.DLL - WINDOWS/SYSTEM32/DNSRSLVR.DLL - WINDOWS/SYSTEM32/DUSER.DLL - WINDOWS/SYSTEM32/MSIMG32.DLL - WINDOWS/SYSTEM32/OLEACC.DLL - WINDOWS/SYSTEM32/OLEACCRC.DLL - WINDOWS/SYSTEM32/CSCDLL.DLL - WINDOWS/SYSTEM32/DIMSNTFY.DLL - WINDOWS/SYSTEM32/WLNOTIFY.DLL - WINDOWS/SYSTEM32/CLBCATQ.DLL - WINDOWS/SYSTEM32/COMRES.DLL - WINDOWS/SYSTEM32/SHGINA.DLL - WINDOWS/SYSTEM32/LMHSVC.DLL - WINDOWS/SYSTEM32/TERMSRV.DLL - WINDOWS/SYSTEM32/ICAAPI.DLL - WINDOWS/SYSTEM32/MSTLSAPI.DLL - WINDOWS/SYSTEM32/ACTIVEDS.DLL - WINDOWS/SYSTEM32/ADSLDPC.DLL - WINDOWS/SYSTEM32/ATL.DLL - WINDOWS/SYSTEM32/WZCSVC.DLL - WINDOWS/SYSTEM32/RTUTILS.DLL - WINDOWS/SYSTEM32/WMI.DLL - WINDOWS/SYSTEM32/EAPOLQEC.DLL - WINDOWS/SYSTEM32/QUTIL.DLL - WINDOWS/SYSTEM32/DOT3API.DLL - WINDOWS/SYSTEM32/ESENT.DLL - WINDOWS/SYSTEM32/IRMON.DLL - WINDOWS/SYSTEM32/RASTLS.DLL - WINDOWS/SYSTEM32/MPRAPI.DLL - WINDOWS/SYSTEM32/RASAPI32.DLL - WINDOWS/SYSTEM32/RASMAN.DLL - WINDOWS/SYSTEM32/TAPI32.DLL - WINDOWS/SYSTEM32/RICHED20.DLL - WINDOWS/SYSTEM32/RASCHAP.DLL - WINDOWS/SYSTEM32/WSHIRDA.DLL - WINDOWS/SYSTEM32/SCHEDSVC.DLL - WINDOWS/SYSTEM32/MSIDLE.DLL - WINDOWS/SYSTEM32/AUDIOSRV.DLL - WINDOWS/SYSTEM32/WKSSVC.DLL - WINDOWS/SYSTEM32/WEBCLNT.DLL - WINDOWS/SYSTEM32/WSOCK32.DLL - WINDOWS/SYSTEM32/CRYPTSVC.DLL - WINDOWS/SYSTEM32/CERTCLI.DLL - WINDOWS/SYSTEM32/ERSVC.DLL - WINDOWS/SYSTEM32/ES.DLL - WINDOWS/PCHEALTH/HELPCTR/BINARIES/PCHSVC.DLL - WINDOWS/SYSTEM32/SRVSVC.DLL - WINDOWS/SYSTEM32/NETMSG.DLL - WINDOWS/SYSTEM32/IPSECSVC.DLL - WINDOWS/SYSTEM32/OAKLEY.DLL - WINDOWS/SYSTEM32/WINIPSEC.DLL - WINDOWS/SYSTEM32/PSTORSVC.DLL - WINDOWS/SYSTEM32/PSBASE.DLL - WINDOWS/SYSTEM32/NETMAN.DLL - WINDOWS/SYSTEM32/NETSHELL.DLL - WINDOWS/SYSTEM32/CREDUI.DLL - WINDOWS/SYSTEM32/DOT3DLG.DLL - WINDOWS/SYSTEM32/ONEX.DLL - WINDOWS/SYSTEM32/EAPPCFG.DLL - WINDOWS/SYSTEM32/EAPPPRXY.DLL - WINDOWS/SYSTEM32/WZCSAPI.DLL - WINDOWS/SYSTEM32/REGSVC.DLL - WINDOWS/SYSTEM32/SENS.DLL - WINDOWS/SYSTEM32/SECLOGON.DLL - WINDOWS/SYSTEM32/SRSVC.DLL - WINDOWS/SYSTEM32/POWRPROF.DLL - WINDOWS/SYSTEM32/TRKWKS.DLL - WINDOWS/SYSTEM32/WBEM/WMISVC.DLL - WINDOWS/SYSTEM32/VSSAPI.DLL - WINDOWS/SYSTEM32/WUAUSERV.DLL - WINDOWS/SYSTEM32/WUAUENG.DLL - WINDOWS/SYSTEM32/ADVPACK.DLL - WINDOWS/SYSTEM32/CABINET.DLL - WINDOWS/SYSTEM32/MSPATCHA.DLL - WINDOWS/SYSTEM32/SHFOLDER.DLL - WINDOWS/SYSTEM32/WINHTTP.DLL - WINDOWS/SYSTEM32/WSCSVC.DLL - WINDOWS/SYSTEM32/MSI.DLL - WINDOWS/SYSTEM32/BROWSER.DLL - WINDOWS/SYSTEM32/DSSENH.DLL - WINDOWS/SYSTEM32/WBEM/WBEMPROX.DLL - WINDOWS/SYSTEM32/WBEM/WBEMCOMN.DLL - WINDOWS/SYSTEM32/CSCUI.DLL - WINDOWS/SYSTEM32/DPCDLL.DLL - WINDOWS/SYSTEM32/WBEM/WBEMCORE.DLL - WINDOWS/SYSTEM32/WBEM/ESSCLI.DLL - WINDOWS/SYSTEM32/WBEM/FASTPROX.DLL - WINDOWS/SYSTEM32/WBEM/WBEMSVC.DLL - WINDOWS/SYSTEM32/MSXML3.DLL - WINDOWS/SYSTEM32/MSXML3R.DLL - WINDOWS/SYSTEM32/COMSVCS.DLL - WINDOWS/SYSTEM32/COLBACT.DLL - WINDOWS/SYSTEM32/MTXCLU.DLL - WINDOWS/SYSTEM32/CLUSAPI.DLL - WINDOWS/SYSTEM32/RESUTILS.DLL - WINDOWS/SYSTEM32/WBEM/WMIUTILS.DLL - WINDOWS/SYSTEM32/WBEM/REPDRVFS.DLL - WINDOWS/SYSTEM32/WBEM/WMIPRVSD.DLL - WINDOWS/SYSTEM32/WBEM/WBEMESS.DLL - WINDOWS/SYSTEM32/IPNATHLP.DLL - WINDOWS/SYSTEM32/WUAPI.DLL - WINDOWS/SYSTEM32/WBEM/NCPROV.DLL - WINDOWS/SYSTEM32/WBEM/WBEMCONS.DLL - WINDOWS/SYSTEM32/BROWSEUI.DLL - WINDOWS/SYSTEM32/NETCFGX.DLL - WINDOWS/SYSTEM32/THEMEUI.DLL - WINDOWS/SYSTEM32/ACTXPRXY.DLL - WINDOWS/SYSTEM32/MYDOCS.DLL - WINDOWS/SYSTEM32/MORICONS.DLL - WINDOWS/SYSTEM32/UPNP.DLL - WINDOWS/SYSTEM32/SSDPAPI.DLL - WINDOWS/SYSTEM32/SSDPSRV.DLL - WINDOWS/SYSTEM32/ULIB.DLL - WINDOWS/SYSTEM32/WEBCHECK.DLL - WINDOWS/SYSTEM32/STOBJECT.DLL - WINDOWS/SYSTEM32/BATMETER.DLL - WINDOWS/SYSTEM32/RASDLG.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.GDIPLUS_6595B64144CCF1DF_1.0.2600.5512_X-WW_DFB54E0C/GDIPLUS.DLL - WINDOWS/SYSTEM32/MFC42U.DLL - WINDOWS/SYSTEM32/LINKINFO.DLL - WINDOWS/SYSTEM32/NTSHRUI.DLL - WINDOWS/SYSTEM32/SENSAPI.DLL - WINDOWS/SYSTEM32/DCIMAN32.DLL - WINDOWS/SYSTEM32/SPOOLSS.DLL - WINDOWS/SYSTEM32/LOCALSPL.DLL - WINDOWS/SYSTEM32/CNBJMON.DLL - WINDOWS/SYSTEM32/PJLMON.DLL - WINDOWS/SYSTEM32/TCPMON.DLL - WINDOWS/SYSTEM32/USBMON.DLL - WINDOWS/SYSTEM32/WIN32SPL.DLL - WINDOWS/SYSTEM32/NETRAP.DLL - WINDOWS/SYSTEM32/INETPP.DLL - WINDOWS/SYSTEM32/WUPS.DLL - WINDOWS/SYSTEM32/NEWDEV.DLL - WINDOWS/SYSTEM32/MDMINST.DLL - WINDOWS/SYSTEM32/SYSSETUP.DLL - WINDOWS/SYSTEM32/STI_CI.DLL - WINDOWS/SYSTEM32/BATT.DLL - WINDOWS/SYSTEM32/SDHCINST.DLL - WINDOWS/SYSTEM32/BTHCI.DLL - WINDOWS/SYSTEM32/FLDRCLNR.DLL} (file: /media/sdb1/WINDOWS/Prefetch/NTOSBOOT-B00DFAAD.pf) 36352 .a.. r/rr-xr-xr-x 0 0 2570-128-3 /WINDOWS/system32/drivers/intelppm.sys 56 .a.. d/dr-xr-xr-x 0 0 3652-144-6 /System Volume Information Fri Jul 01 2011 14:50:32 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{4d36e978-e325-11ce-bfc1-08002be10318}/##?#ACPI#PNP0501#4&3863886d&0#{4d36e978-e325-11ce-bfc1-08002be10318} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{4d36e978-e325-11ce-bfc1-08002be10318}/##?#ACPI#PNP0501#4&3863886d&0#{4d36e978-e325-11ce-bfc1-08002be10318}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{72631e54-78a4-11d0-bcf7-00aa00b7b32a}/##?#ACPI#PNP0C0A#0#{72631e54-78a4-11d0-bcf7-00aa00b7b32a} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{72631e54-78a4-11d0-bcf7-00aa00b7b32a}/##?#ACPI#PNP0C0A#0#{72631e54-78a4-11d0-bcf7-00aa00b7b32a}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{4d36e978-e325-11ce-bfc1-08002be10318}/##?#ACPI#PNP0501#4&3863886d&0#{4d36e978-e325-11ce-bfc1-08002be10318} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{4d36e978-e325-11ce-bfc1-08002be10318}/##?#ACPI#PNP0501#4&3863886d&0#{4d36e978-e325-11ce-bfc1-08002be10318}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{72631e54-78a4-11d0-bcf7-00aa00b7b32a}/##?#ACPI#PNP0C0A#0#{72631e54-78a4-11d0-bcf7-00aa00b7b32a} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{72631e54-78a4-11d0-bcf7-00aa00b7b32a}/##?#ACPI#PNP0C0A#0#{72631e54-78a4-11d0-bcf7-00aa00b7b32a}/# 161792 .a.. r/rr-xr-xr-x 0 0 10752-128-3 /WINDOWS/system32/drivers/b57xp32.sys 19072 .a.. r/rr-xr-xr-x 0 0 1894-128-3 /WINDOWS/system32/drivers/tdi.sys 141056 .a.. r/rr-xr-xr-x 0 0 1906-128-3 /WINDOWS/system32/drivers/ks.sys 27392 .a.. r/rr-xr-xr-x 0 0 1908-128-3 /WINDOWS/system32/drivers/fdc.sys 64512 .a.. r/rr-xr-xr-x 0 0 1909-128-3 /WINDOWS/system32/drivers/serial.sys 15744 .a.. r/rr-xr-xr-x 0 0 1910-128-3 /WINDOWS/system32/drivers/serenum.sys 80128 .a.. r/rr-xr-xr-x 0 0 1911-128-3 /WINDOWS/system32/drivers/parport.sys 62976 .a.. r/rr-xr-xr-x 0 0 1912-128-3 /WINDOWS/system32/drivers/cdrom.sys 51328 .a.. r/rr-xr-xr-x 0 0 1913-128-3 /WINDOWS/system32/drivers/rasl2tp.sys 10112 .a.. r/rr-xr-xr-x 0 0 1914-128-3 /WINDOWS/system32/drivers/ndistapi.sys 91520 .a.. r/rr-xr-xr-x 0 0 1915-128-3 /WINDOWS/system32/drivers/ndiswan.sys 41472 .a.. r/rr-xr-xr-x 0 0 1916-128-3 /WINDOWS/system32/drivers/raspppoe.sys 48384 .a.. r/rr-xr-xr-x 0 0 1917-128-3 /WINDOWS/system32/drivers/raspptp.sys 69120 .a.. r/rr-xr-xr-x 0 0 1918-128-3 /WINDOWS/system32/drivers/psched.sys 35072 .a.. r/rr-xr-xr-x 0 0 1919-128-3 /WINDOWS/system32/drivers/msgpc.sys 42112 .a.. r/rr-xr-xr-x 0 0 1929-128-3 /WINDOWS/system32/drivers/imapi.sys 52480 .a.. r/rr-xr-xr-x 0 0 3619-128-3 /WINDOWS/system32/drivers/i8042prt.sys 143872 .a.. r/rr-xr-xr-x 0 0 3626-128-3 /WINDOWS/system32/drivers/usbport.sys 20608 .a.. r/rr-xr-xr-x 0 0 3627-128-3 /WINDOWS/system32/drivers/usbuhci.sys 30208 .a.. r/rr-xr-xr-x 0 0 3629-128-3 /WINDOWS/system32/drivers/usbehci.sys 23040 .a.. r/rr-xr-xr-x 0 0 3630-128-3 /WINDOWS/system32/drivers/mouclass.sys 24576 .a.. r/rr-xr-xr-x 0 0 3631-128-3 /WINDOWS/system32/drivers/kbdclass.sys 11264 .a.. r/rr-xr-xr-x 0 0 3910-128-3 /WINDOWS/system32/drivers/irenum.sys 28672 .a.. r/rr-xr-xr-x 0 0 4828-128-3 /WINDOWS/system32/drivers/nscirda.sys 19584 .a.. r/rr-xr-xr-x 0 0 4836-128-3 /WINDOWS/system32/drivers/rasirda.sys 13952 .a.. r/rr-xr-xr-x 0 0 4837-128-3 /WINDOWS/system32/drivers/CmBatt.sys 57600 .a.. r/rr-xr-xr-x 0 0 4840-128-3 /WINDOWS/system32/drivers/redbook.sys 3072 .a.. r/rr-xr-xr-x 0 0 4845-128-3 /WINDOWS/system32/drivers/audstub.sys Fri Jul 01 2011 14:50:33 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{4747b320-62ce-11cf-a5d6-28db04c10000}/##?#Root#SYSTEM#0000#{4747b320-62ce-11cf-a5d6-28db04c10000} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{4747b320-62ce-11cf-a5d6-28db04c10000}/##?#Root#SYSTEM#0000#{4747b320-62ce-11cf-a5d6-28db04c10000}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{97fadb10-4e33-40ae-359c-8bef029dbdd0}/##?#ACPI#GenuineIntel_-_x86_Family_6_Model_13#_0#{97fadb10-4e33-40ae-359c-8bef029dbdd0} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{97fadb10-4e33-40ae-359c-8bef029dbdd0}/##?#ACPI#GenuineIntel_-_x86_Family_6_Model_13#_0#{97fadb10-4e33-40ae-359c-8bef029dbdd0}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{eeab7790-c514-11d1-b42b-00805fc1270e}&asyncmac 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/mssmbios 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{4747b320-62ce-11cf-a5d6-28db04c10000}/##?#Root#SYSTEM#0000#{4747b320-62ce-11cf-a5d6-28db04c10000} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{4747b320-62ce-11cf-a5d6-28db04c10000}/##?#Root#SYSTEM#0000#{4747b320-62ce-11cf-a5d6-28db04c10000}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{97fadb10-4e33-40ae-359c-8bef029dbdd0}/##?#ACPI#GenuineIntel_-_x86_Family_6_Model_13#_0#{97fadb10-4e33-40ae-359c-8bef029dbdd0} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{97fadb10-4e33-40ae-359c-8bef029dbdd0}/##?#ACPI#GenuineIntel_-_x86_Family_6_Model_13#_0#{97fadb10-4e33-40ae-359c-8bef029dbdd0}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{eeab7790-c514-11d1-b42b-00805fc1270e}&asyncmac 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/mssmbios 17792 .a.. r/rr-xr-xr-x 0 0 191-128-3 /WINDOWS/system32/drivers/ptilink.sys 16512 .a.. r/rr-xr-xr-x 0 0 192-128-3 /WINDOWS/system32/drivers/raspti.sys 4352 .a.. r/rr-xr-xr-x 0 0 1920-128-3 /WINDOWS/system32/drivers/swenum.sys 15488 .a.. r/rr-xr-xr-x 0 0 2771-128-3 /WINDOWS/system32/drivers/mssmbios.sys 384768 .a.. r/rr-xr-xr-x 0 0 3391-128-3 /WINDOWS/system32/drivers/update.sys 40840 .a.. r/rr-xr-xr-x 0 0 4862-128-3 /WINDOWS/system32/drivers/termdd.sys 196224 .a.. r/rr-xr-xr-x 0 0 4863-128-3 /WINDOWS/system32/drivers/rdpdr.sys Fri Jul 01 2011 14:50:34 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{1186654d-47b8-48b9-beb9-7df113ae3c67}/##?#IDE#CdRomHL-DT-ST_RW#DVD_GCC-4242N_______________0J05____#5&2ba179a6&0&0.0.0#{1186654d-47b8-48b9-beb9-7df113ae3c67} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{1186654d-47b8-48b9-beb9-7df113ae3c67}/##?#IDE#CdRomHL-DT-ST_RW#DVD_GCC-4242N_______________0J05____#5&2ba179a6&0&0.0.0#{1186654d-47b8-48b9-beb9-7df113ae3c67}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f56308-b6bf-11d0-94f2-00a0c91efb8b}/##?#IDE#CdRomHL-DT-ST_RW#DVD_GCC-4242N_______________0J05____#5&2ba179a6&0&0.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f56308-b6bf-11d0-94f2-00a0c91efb8b}/##?#IDE#CdRomHL-DT-ST_RW#DVD_GCC-4242N_______________0J05____#5&2ba179a6&0&0.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/##?#IDE#CdRomHL-DT-ST_RW#DVD_GCC-4242N_______________0J05____#5&2ba179a6&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/##?#IDE#CdRomHL-DT-ST_RW#DVD_GCC-4242N_______________0J05____#5&2ba179a6&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_IRDAMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_IRDAMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{CCF3C231-86A7-4A76-91ED-5DB1B34426E5} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{E037727E-458A-432B-B328-F49A39D3C157} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{82F044D2-E75B-4BDB-B526-3A4305E354DC} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{34FDEE64-BCC1-4E03-867C-5775AC1F07FD} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{1186654d-47b8-48b9-beb9-7df113ae3c67}/##?#IDE#CdRomHL-DT-ST_RW#DVD_GCC-4242N_______________0J05____#5&2ba179a6&0&0.0.0#{1186654d-47b8-48b9-beb9-7df113ae3c67} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{1186654d-47b8-48b9-beb9-7df113ae3c67}/##?#IDE#CdRomHL-DT-ST_RW#DVD_GCC-4242N_______________0J05____#5&2ba179a6&0&0.0.0#{1186654d-47b8-48b9-beb9-7df113ae3c67}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f56308-b6bf-11d0-94f2-00a0c91efb8b}/##?#IDE#CdRomHL-DT-ST_RW#DVD_GCC-4242N_______________0J05____#5&2ba179a6&0&0.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f56308-b6bf-11d0-94f2-00a0c91efb8b}/##?#IDE#CdRomHL-DT-ST_RW#DVD_GCC-4242N_______________0J05____#5&2ba179a6&0&0.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/##?#IDE#CdRomHL-DT-ST_RW#DVD_GCC-4242N_______________0J05____#5&2ba179a6&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/##?#IDE#CdRomHL-DT-ST_RW#DVD_GCC-4242N_______________0J05____#5&2ba179a6&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_IRDAMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_IRDAMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{CCF3C231-86A7-4A76-91ED-5DB1B34426E5} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{E037727E-458A-432B-B328-F49A39D3C157} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{82F044D2-E75B-4BDB-B526-3A4305E354DC} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{34FDEE64-BCC1-4E03-867C-5775AC1F07FD} 40576 .a.. r/rr-xr-xr-x 0 0 1921-128-3 /WINDOWS/system32/drivers/ndproxy.sys 131072 .acb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/15_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 14:50:35 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{378de44c-56ef-11d1-bc8c-00a0c91405dd}/##?#Root#RDP_MOU#0000#{378de44c-56ef-11d1-bc8c-00a0c91405dd} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{378de44c-56ef-11d1-bc8c-00a0c91405dd}/##?#Root#RDP_MOU#0000#{378de44c-56ef-11d1-bc8c-00a0c91405dd}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_2658&SUBSYS_05651014&REV_03#3&b1bfb68&0&E8#{3abf6f2d-71c4-462a-8a92-1e6861e6af27} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_2658&SUBSYS_05651014&REV_03#3&b1bfb68&0&E8#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{884b96c3-56ef-11d1-bc8c-00a0c91405dd}/##?#Root#RDP_KBD#0000#{884b96c3-56ef-11d1-bc8c-00a0c91405dd} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{884b96c3-56ef-11d1-bc8c-00a0c91405dd}/##?#Root#RDP_KBD#0000#{884b96c3-56ef-11d1-bc8c-00a0c91405dd}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#PCI#VEN_14E4&DEV_167D&SUBSYS_05771014&REV_11#4&111a1fd8&0&00E0#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#PCI#VEN_14E4&DEV_167D&SUBSYS_05771014&REV_11#4&111a1fd8&0&00E0#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{D668E008-1573-470A-9346-7741E6261C75} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#NDISWANIP 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PSCHEDMP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PSCHEDMP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{0A512159-DACE-4B87-A40C-67B8A358DEE7} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PSCHEDMP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PSCHEDMP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{E9E11213-1FEC-4A82-A89F-EDF59351EE8D} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PTIMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PTIMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{9FACBF16-E737-45C2-9529-1F8336812DDB} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB#4&1b50c3be&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB#4&1b50c3be&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USB/ROOT_HUB/4&1b50c3be&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/usbhub 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{378de44c-56ef-11d1-bc8c-00a0c91405dd}/##?#Root#RDP_MOU#0000#{378de44c-56ef-11d1-bc8c-00a0c91405dd} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{378de44c-56ef-11d1-bc8c-00a0c91405dd}/##?#Root#RDP_MOU#0000#{378de44c-56ef-11d1-bc8c-00a0c91405dd}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_2658&SUBSYS_05651014&REV_03#3&b1bfb68&0&E8#{3abf6f2d-71c4-462a-8a92-1e6861e6af27} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_2658&SUBSYS_05651014&REV_03#3&b1bfb68&0&E8#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{884b96c3-56ef-11d1-bc8c-00a0c91405dd}/##?#Root#RDP_KBD#0000#{884b96c3-56ef-11d1-bc8c-00a0c91405dd} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{884b96c3-56ef-11d1-bc8c-00a0c91405dd}/##?#Root#RDP_KBD#0000#{884b96c3-56ef-11d1-bc8c-00a0c91405dd}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#PCI#VEN_14E4&DEV_167D&SUBSYS_05771014&REV_11#4&111a1fd8&0&00E0#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#PCI#VEN_14E4&DEV_167D&SUBSYS_05771014&REV_11#4&111a1fd8&0&00E0#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{D668E008-1573-470A-9346-7741E6261C75} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#NDISWANIP 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PSCHEDMP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PSCHEDMP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{0A512159-DACE-4B87-A40C-67B8A358DEE7} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PSCHEDMP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PSCHEDMP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{E9E11213-1FEC-4A82-A89F-EDF59351EE8D} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PTIMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ROOT#MS_PTIMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{9FACBF16-E737-45C2-9529-1F8336812DDB} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB#4&1b50c3be&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB#4&1b50c3be&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USB/ROOT_HUB/4&1b50c3be&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/usbhub 4736 .a.. r/rr-xr-xr-x 0 0 1885-128-3 /WINDOWS/system32/drivers/usbd.sys 28672 .a.. r/rr-xr-xr-x 0 0 3146-128-3 /WINDOWS/system32/verclsid.exe 59520 .a.. r/rr-xr-xr-x 0 0 3623-128-3 /WINDOWS/system32/drivers/usbhub.sys 131072 .acb 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/9_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 14:50:36 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_2659&SUBSYS_05651014&REV_03#3&b1bfb68&0&E9#{3abf6f2d-71c4-462a-8a92-1e6861e6af27} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_2659&SUBSYS_05651014&REV_03#3&b1bfb68&0&E9#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_265A&SUBSYS_05651014&REV_03#3&b1bfb68&0&EA#{3abf6f2d-71c4-462a-8a92-1e6861e6af27} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_265A&SUBSYS_05651014&REV_03#3&b1bfb68&0&EA#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_265B&SUBSYS_05651014&REV_03#3&b1bfb68&0&EB#{3abf6f2d-71c4-462a-8a92-1e6861e6af27} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_265B&SUBSYS_05651014&REV_03#3&b1bfb68&0&EB#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_265C&SUBSYS_05661014&REV_03#3&b1bfb68&0&EF#{3abf6f2d-71c4-462a-8a92-1e6861e6af27} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_265C&SUBSYS_05661014&REV_03#3&b1bfb68&0&EF#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{4afa3d53-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#PNP0303#4&3863886d&0#{4afa3d53-74a7-11d0-be5e-00a0c9062857} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{4afa3d53-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#PNP0303#4&3863886d&0#{4afa3d53-74a7-11d0-be5e-00a0c9062857}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{884b96c3-56ef-11d1-bc8c-00a0c91405dd}/##?#ACPI#PNP0303#4&3863886d&0#{884b96c3-56ef-11d1-bc8c-00a0c91405dd} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{884b96c3-56ef-11d1-bc8c-00a0c91405dd}/##?#ACPI#PNP0303#4&3863886d&0#{884b96c3-56ef-11d1-bc8c-00a0c91405dd}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB#4&236de289&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB#4&236de289&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB#4&34f80b40&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB#4&34f80b40&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB#4&9c69b07&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB#4&9c69b07&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB20#4&1aa45922&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB20#4&1aa45922&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USB/ROOT_HUB/4&236de289&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USB/ROOT_HUB/4&34f80b40&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USB/ROOT_HUB/4&9c69b07&0 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USB/ROOT_HUB20/4&1aa45922&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_2659&SUBSYS_05651014&REV_03#3&b1bfb68&0&E9#{3abf6f2d-71c4-462a-8a92-1e6861e6af27} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_2659&SUBSYS_05651014&REV_03#3&b1bfb68&0&E9#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_265A&SUBSYS_05651014&REV_03#3&b1bfb68&0&EA#{3abf6f2d-71c4-462a-8a92-1e6861e6af27} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_265A&SUBSYS_05651014&REV_03#3&b1bfb68&0&EA#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_265B&SUBSYS_05651014&REV_03#3&b1bfb68&0&EB#{3abf6f2d-71c4-462a-8a92-1e6861e6af27} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_265B&SUBSYS_05651014&REV_03#3&b1bfb68&0&EB#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_265C&SUBSYS_05661014&REV_03#3&b1bfb68&0&EF#{3abf6f2d-71c4-462a-8a92-1e6861e6af27} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/##?#PCI#VEN_8086&DEV_265C&SUBSYS_05661014&REV_03#3&b1bfb68&0&EF#{3abf6f2d-71c4-462a-8a92-1e6861e6af27}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{4afa3d53-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#PNP0303#4&3863886d&0#{4afa3d53-74a7-11d0-be5e-00a0c9062857} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{4afa3d53-74a7-11d0-be5e-00a0c9062857}/##?#ACPI#PNP0303#4&3863886d&0#{4afa3d53-74a7-11d0-be5e-00a0c9062857}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{884b96c3-56ef-11d1-bc8c-00a0c91405dd}/##?#ACPI#PNP0303#4&3863886d&0#{884b96c3-56ef-11d1-bc8c-00a0c91405dd} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{884b96c3-56ef-11d1-bc8c-00a0c91405dd}/##?#ACPI#PNP0303#4&3863886d&0#{884b96c3-56ef-11d1-bc8c-00a0c91405dd}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB#4&236de289&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB#4&236de289&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB#4&34f80b40&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB#4&34f80b40&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB#4&9c69b07&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB#4&9c69b07&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB20#4&1aa45922&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{f18a0e88-c30c-11d0-8815-00a0c906bed8}/##?#USB#ROOT_HUB20#4&1aa45922&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USB/ROOT_HUB/4&236de289&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USB/ROOT_HUB/4&34f80b40&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USB/ROOT_HUB/4&9c69b07&0 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USB/ROOT_HUB20/4&1aa45922&0 Fri Jul 01 2011 14:50:37 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{378de44c-56ef-11d1-bc8c-00a0c91405dd}/##?#ACPI#IBM0057#4&3863886d&0#{378de44c-56ef-11d1-bc8c-00a0c91405dd} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{378de44c-56ef-11d1-bc8c-00a0c91405dd}/##?#ACPI#IBM0057#4&3863886d&0#{378de44c-56ef-11d1-bc8c-00a0c91405dd}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{811fc6a5-f728-11d0-a537-0000f8753ed1}/##?#LPTENUM#MicrosoftRawPort#5&be86656&0&LPT1#{811fc6a5-f728-11d0-a537-0000f8753ed1} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{811fc6a5-f728-11d0-a537-0000f8753ed1}/##?#LPTENUM#MicrosoftRawPort#5&be86656&0&LPT1#{811fc6a5-f728-11d0-a537-0000f8753ed1}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{86e0d1e0-8089-11d0-9ce4-08003e301f73}/##?#ACPI#PNP0501#4&3863886d&0#{86e0d1e0-8089-11d0-9ce4-08003e301f73} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{86e0d1e0-8089-11d0-9ce4-08003e301f73}/##?#ACPI#PNP0501#4&3863886d&0#{86e0d1e0-8089-11d0-9ce4-08003e301f73}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{97f76ef0-f883-11d0-af1f-0000f800845c}/##?#ACPI#PNP0400#4&3863886d&0#{97f76ef0-f883-11d0-af1f-0000f800845c} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{97f76ef0-f883-11d0-af1f-0000f800845c}/##?#ACPI#PNP0400#4&3863886d&0#{97f76ef0-f883-11d0-af1f-0000f800845c}/# 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ACPI#IBM0071#4&3863886d&0#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ACPI#IBM0071#4&3863886d&0#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{97EC1D9E-62DB-4516-A68D-06DA05EB2694} 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Session Manager 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/LPTENUM/MicrosoftRawPort/5&be86656&0&LPT1 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_FS_REC/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_MRXSMB/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_MSFS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_NETBIOS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_NPFS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_RDBSS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Cdaudio 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Flpydisk 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Parport 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{378de44c-56ef-11d1-bc8c-00a0c91405dd}/##?#ACPI#IBM0057#4&3863886d&0#{378de44c-56ef-11d1-bc8c-00a0c91405dd} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{378de44c-56ef-11d1-bc8c-00a0c91405dd}/##?#ACPI#IBM0057#4&3863886d&0#{378de44c-56ef-11d1-bc8c-00a0c91405dd}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{811fc6a5-f728-11d0-a537-0000f8753ed1}/##?#LPTENUM#MicrosoftRawPort#5&be86656&0&LPT1#{811fc6a5-f728-11d0-a537-0000f8753ed1} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{811fc6a5-f728-11d0-a537-0000f8753ed1}/##?#LPTENUM#MicrosoftRawPort#5&be86656&0&LPT1#{811fc6a5-f728-11d0-a537-0000f8753ed1}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{86e0d1e0-8089-11d0-9ce4-08003e301f73}/##?#ACPI#PNP0501#4&3863886d&0#{86e0d1e0-8089-11d0-9ce4-08003e301f73} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{86e0d1e0-8089-11d0-9ce4-08003e301f73}/##?#ACPI#PNP0501#4&3863886d&0#{86e0d1e0-8089-11d0-9ce4-08003e301f73}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{97f76ef0-f883-11d0-af1f-0000f800845c}/##?#ACPI#PNP0400#4&3863886d&0#{97f76ef0-f883-11d0-af1f-0000f800845c} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{97f76ef0-f883-11d0-af1f-0000f800845c}/##?#ACPI#PNP0400#4&3863886d&0#{97f76ef0-f883-11d0-af1f-0000f800845c}/# 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ACPI#IBM0071#4&3863886d&0#{ad498944-762f-11d0-8dcb-00c04fc3358c} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/DeviceClasses/{ad498944-762f-11d0-8dcb-00c04fc3358c}/##?#ACPI#IBM0071#4&3863886d&0#{ad498944-762f-11d0-8dcb-00c04fc3358c}/#{97EC1D9E-62DB-4516-A68D-06DA05EB2694} 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Session Manager 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/LPTENUM/MicrosoftRawPort/5&be86656&0&LPT1 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_FS_REC/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_MRXSMB/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_MSFS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_NETBIOS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_NPFS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_RDBSS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Cdaudio 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Flpydisk 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Parport 23256 .a.. r/rrwxrwxrwx 0 0 10426-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/_filelst.cfg 4224 .a.. r/rr-xr-xr-x 0 0 1552-128-3 /WINDOWS/system32/drivers/mnmdd.sys 456576 .a.. r/rr-xr-xr-x 0 0 1896-128-3 /WINDOWS/system32/drivers/mrxsmb.sys 175744 .a.. r/rr-xr-xr-x 0 0 1897-128-3 /WINDOWS/system32/drivers/rdbss.sys 19072 .a.. r/rr-xr-xr-x 0 0 1898-128-3 /WINDOWS/system32/drivers/msfs.sys 34688 .a.. r/rr-xr-xr-x 0 0 1900-128-3 /WINDOWS/system32/drivers/netbios.sys 30848 .a.. r/rr-xr-xr-x 0 0 1901-128-3 /WINDOWS/system32/drivers/npfs.sys 81664 .a.. r/rr-xr-xr-x 0 0 1905-128-3 /WINDOWS/system32/drivers/videoprt.sys 20480 .a.. r/rr-xr-xr-x 0 0 1922-128-3 /WINDOWS/system32/drivers/flpydisk.sys 20992 .a.. r/rr-xr-xr-x 0 0 1924-128-3 /WINDOWS/system32/drivers/vga.sys 75264 .a.. r/rr-xr-xr-x 0 0 1925-128-3 /WINDOWS/system32/drivers/ipsec.sys 361344 .a.. r/rr-xr-xr-x 0 0 1926-128-3 /WINDOWS/system32/drivers/tcpip.sys 162816 .a.. r/rr-xr-xr-x 0 0 1927-128-3 /WINDOWS/system32/drivers/netbt.sys 34560 .a.. r/rr-xr-xr-x 0 0 1928-128-3 /WINDOWS/system32/drivers/wanarp.sys 18688 .a.. r/rr-xr-xr-x 0 0 193-128-3 /WINDOWS/system32/drivers/cdaudio.sys 44544 .a.. r/rr-xr-xr-x 0 0 1930-128-3 /WINDOWS/system32/drivers/fips.sys 50688 .a.. r/rr-xr-xr-x 0 0 1932-128-3 /WINDOWS/system32/smss.exe 588800 .a.. r/rr-xr-xr-x 0 0 1933-128-3 /WINDOWS/system32/autochk.exe 7936 .a.. r/rr-xr-xr-x 0 0 194-128-3 /WINDOWS/system32/drivers/fs_rec.sys 2944 .a.. r/rr-xr-xr-x 0 0 195-128-3 /WINDOWS/system32/drivers/null.sys 4224 .a.. r/rr-xr-xr-x 0 0 196-128-3 /WINDOWS/system32/drivers/beep.sys 4224 .a.. r/rr-xr-xr-x 0 0 197-128-3 /WINDOWS/system32/drivers/rdpcdd.sys 8832 .a.. r/rr-xr-xr-x 0 0 198-128-3 /WINDOWS/system32/drivers/rasacd.sys 138112 .a.. r/rr-xr-xr-x 0 0 2022-128-3 /WINDOWS/system32/drivers/afd.sys 152832 .a.. r/rr-xr-xr-x 0 0 2577-128-3 /WINDOWS/system32/drivers/ipnat.sys Fri Jul 01 2011 14:50:38 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_CDFS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/USB/Vid_0483&Pid_2016/5&1227f778&0&2 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_CDFS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/USB/Vid_0483&Pid_2016/5&1227f778&0&2 4352 .a.. r/rr-xr-xr-x 0 0 188-128-3 /WINDOWS/system32/drivers/wmilib.sys 96512 .a.. r/rr-xr-xr-x 0 0 1886-128-3 /WINDOWS/system32/drivers/atapi.sys 74752 .a.. r/rr-xr-xr-x 0 0 1943-128-3 /WINDOWS/system32/olecli32.dll 37376 .a.. r/rr-xr-xr-x 0 0 1944-128-3 /WINDOWS/system32/olecnv32.dll 37888 .a.. r/rr-xr-xr-x 0 0 1947-128-3 /WINDOWS/system32/url.dll 420864 .a.. r/rr-xr-xr-x 0 0 1957-128-3 /WINDOWS/system32/ntvdm.exe 264192 .a.. r/rr-xr-xr-x 0 0 1958-128-3 /WINDOWS/system32/wow32.dll 2560 .a.. r/rr-xr-xr-x 0 0 199-128-3 /WINDOWS/system32/lz32.dll 22016 .a.. r/rr-xr-xr-x 0 0 200-128-3 /WINDOWS/system32/olesvr32.dll 69120 .a.. r/rr-xr-xr-x 0 0 201-128-3 /WINDOWS/system32/olethk32.dll 63744 .a.. r/rr-xr-xr-x 0 0 2297-128-3 /WINDOWS/system32/drivers/cdfs.sys 1610612736 mac. r/rr-xr-xr-x 0 0 27-128-1 /pagefile.sys Fri Jul 01 2011 14:50:39 0 m... 0 0 0 0 REG_System_SECURITYSECURITY 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/ComputerName 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Lsa 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Lsa/SspiCache 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Session Manager/Memory Management/PrefetchParameters 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Session Manager/SubSystems 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/ComputerName 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Lsa 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Lsa/SspiCache 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Session Manager/Memory Management/PrefetchParameters 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Session Manager/SubSystems 221676 .a.. r/rr-xr-xr-x 0 0 1367-128-3 /WINDOWS/Fonts/sylfaen.ttf 18880 .a.. r/rr-xr-xr-x 0 0 1536-128-3 /WINDOWS/Fonts/wst_czec.fon 18880 .a.. r/rr-xr-xr-x 0 0 1537-128-3 /WINDOWS/Fonts/wst_engl.fon 18880 .a.. r/rr-xr-xr-x 0 0 1538-128-3 /WINDOWS/Fonts/wst_fren.fon 18880 .a.. r/rr-xr-xr-x 0 0 1539-128-3 /WINDOWS/Fonts/wst_germ.fon 18880 .a.. r/rr-xr-xr-x 0 0 1540-128-3 /WINDOWS/Fonts/wst_ital.fon 18880 .a.. r/rr-xr-xr-x 0 0 1541-128-3 /WINDOWS/Fonts/wst_span.fon 18880 .a.. r/rr-xr-xr-x 0 0 1542-128-3 /WINDOWS/Fonts/wst_swed.fon 51456 .a.. r/rr-xr-xr-x 0 0 1880-128-3 /WINDOWS/system32/vga256.dll 18176 .a.. r/rr-xr-xr-x 0 0 1881-128-3 /WINDOWS/system32/vga64k.dll 17664 .a.. r/rr-xr-xr-x 0 0 1963-128-3 /WINDOWS/system32/watchdog.sys 6144 .a.. r/rr-xr-xr-x 0 0 1964-128-3 /WINDOWS/system32/csrss.exe 32256 .a.. r/rr-xr-xr-x 0 0 1965-128-3 /WINDOWS/system32/csrsrv.dll 52736 .a.. r/rr-xr-xr-x 0 0 1966-128-3 /WINDOWS/system32/basesrv.dll 71168 .a.. r/rr-xr-xr-x 0 0 1970-128-3 /WINDOWS/system32/drivers/dxg.sys 17920 .a.. r/rr-xr-xr-x 0 0 1972-128-3 /WINDOWS/system32/nddeapi.dll 27648 .a.. r/rr-xr-xr-x 0 0 1975-128-3 /WINDOWS/system32/profmap.dll 355680 .a.. r/rr-xr-xr-x 0 0 1981-128-3 /WINDOWS/Fonts/tahomabd.ttf 383804 .a.. r/rr-xr-xr-x 0 0 1982-128-3 /WINDOWS/Fonts/tahoma.ttf 108544 .a.. r/rr-xr-xr-x 0 0 1994-128-3 /WINDOWS/system32/services.exe 13312 .a.. r/rr-xr-xr-x 0 0 1995-128-3 /WINDOWS/system32/lsass.exe 314880 .a.. r/rr-xr-xr-x 0 0 1996-128-3 /WINDOWS/system32/scesrv.dll 123392 .a.. r/rr-xr-xr-x 0 0 1997-128-3 /WINDOWS/system32/umpnpmgr.dll 728064 .a.. r/rr-xr-xr-x 0 0 1998-128-3 /WINDOWS/system32/lsasrv.dll 33280 .a.. r/rr-xr-xr-x 0 0 1999-128-3 /WINDOWS/system32/cryptdll.dll 415744 .a.. r/rr-xr-xr-x 0 0 2001-128-3 /WINDOWS/system32/samsrv.dll 48128 .a.. r/rr-xr-xr-x 0 0 2007-128-3 /WINDOWS/system32/msprivs.dll 299520 .a.. r/rr-xr-xr-x 0 0 2008-128-3 /WINDOWS/system32/kerberos.dll 407040 .a.. r/rr-xr-xr-x 0 0 2012-128-3 /WINDOWS/system32/netlogon.dll 49152 .a.. r/rr-xr-xr-x 0 0 2013-128-3 /WINDOWS/system32/wdigest.dll 148624 .a.. r/rr-xr-xr-x 0 0 2028-128-3 /WINDOWS/Fonts/tunga.ttf 3328 .a.. r/rr-xr-xr-x 0 0 203-128-3 /WINDOWS/system32/drivers/dxgthk.sys 5360 .a.. r/rr-xr-xr-x 0 0 205-128-3 /WINDOWS/Fonts/vgafix.fon 9344 .a.. r/rr-xr-xr-x 0 0 206-128-3 /WINDOWS/system32/vga.dll 231 .a.. r/rr-xr-xr-x 0 0 207-128-1 /WINDOWS/system.ini 5312 .a.. r/rr-xr-xr-x 0 0 209-128-3 /WINDOWS/Fonts/ega80woa.fon 13312 .a.. r/rr-xr-xr-x 0 0 215-128-3 /WINDOWS/Fonts/roman.fon 12288 .a.. r/rr-xr-xr-x 0 0 216-128-3 /WINDOWS/Fonts/script.fon 8704 .a.. r/rr-xr-xr-x 0 0 217-128-3 /WINDOWS/Fonts/modern.fon 134108 .a.. r/rr-xr-xr-x 0 0 2170-128-3 /WINDOWS/Fonts/trebuc.ttf 26112 .a.. r/rr-xr-xr-x 0 0 218-128-3 /WINDOWS/Fonts/smalle.fon 118832 .a.. r/rr-xr-xr-x 0 0 2180-128-3 /WINDOWS/Fonts/ariblk.ttf 127596 .a.. r/rr-xr-xr-x 0 0 2182-128-3 /WINDOWS/Fonts/comic.ttf 155068 .a.. r/rr-xr-xr-x 0 0 2184-128-3 /WINDOWS/Fonts/georgia.ttf 137448 .a.. r/rr-xr-xr-x 0 0 2185-128-3 /WINDOWS/Fonts/impact.ttf 56336 .a.. r/rr-xr-xr-x 0 0 219-128-3 /WINDOWS/Fonts/symbole.fon 39424 .a.. r/rr-xr-xr-x 0 0 2194-128-3 /WINDOWS/AppPatch/AcAdProc.dll 23408 .a.. r/rr-xr-xr-x 0 0 220-128-3 /WINDOWS/Fonts/coure.fon 57936 .a.. r/rr-xr-xr-x 0 0 222-128-3 /WINDOWS/Fonts/serife.fon 24124 .a.. r/rr-xr-xr-x 0 0 223-128-3 /WINDOWS/Fonts/marlett.ttf 79744 .a.. r/rr-xr-xr-x 0 0 226-128-3 /WINDOWS/Fonts/estre.ttf 285696 .a.. r/rr-xr-xr-x 0 0 2264-128-3 /WINDOWS/system32/atmfd.dll 214936 .a.. r/rr-xr-xr-x 0 0 227-128-3 /WINDOWS/Fonts/gautami.ttf 73292 .a.. r/rr-xr-xr-x 0 0 228-128-3 /WINDOWS/Fonts/latha.ttf 143864 .a.. r/rr-xr-xr-x 0 0 229-128-3 /WINDOWS/Fonts/mangal.ttf 40500 .a.. r/rr-xr-xr-x 0 0 230-128-3 /WINDOWS/Fonts/mvboli.ttf 57348 .a.. r/rr-xr-xr-x 0 0 231-128-3 /WINDOWS/Fonts/raavi.ttf 234280 .a.. r/rr-xr-xr-x 0 0 232-128-3 /WINDOWS/Fonts/shruti.ttf 123096 .a.. r/rr-xr-xr-x 0 0 249-128-3 /WINDOWS/Fonts/trebucbd.ttf 9344 .a.. r/rr-xr-xr-x 0 0 2493-128-3 /WINDOWS/system32/framebuf.dll 207808 .a.. r/rr-xr-xr-x 0 0 251-128-3 /WINDOWS/Fonts/ariali.ttf 111476 .a.. r/rr-xr-xr-x 0 0 252-128-3 /WINDOWS/Fonts/comicbd.ttf 303296 .a.. r/rr-xr-xr-x 0 0 253-128-3 /WINDOWS/Fonts/cour.ttf 312920 .a.. r/rr-xr-xr-x 0 0 254-128-3 /WINDOWS/Fonts/courbd.ttf 236148 .a.. r/rr-xr-xr-x 0 0 255-128-3 /WINDOWS/Fonts/courbi.ttf 245032 .a.. r/rr-xr-xr-x 0 0 256-128-3 /WINDOWS/Fonts/couri.ttf 141032 .a.. r/rr-xr-xr-x 0 0 257-128-3 /WINDOWS/Fonts/georgiab.ttf 157388 .a.. r/rr-xr-xr-x 0 0 258-128-3 /WINDOWS/Fonts/georgiai.ttf 159736 .a.. r/rr-xr-xr-x 0 0 259-128-3 /WINDOWS/Fonts/georgiaz.ttf 48 .a.. r/rr-xr-xr-x 0 0 26-144-2 /$Extend/$Reparse:$R 323980 .a.. r/rr-xr-xr-x 0 0 260-128-3 /WINDOWS/Fonts/l_10646.ttf 115068 .a.. r/rr-xr-xr-x 0 0 261-128-3 /WINDOWS/Fonts/lucon.ttf 489884 .a.. r/rr-xr-xr-x 0 0 262-128-3 /WINDOWS/Fonts/pala.ttf 434004 .a.. r/rr-xr-xr-x 0 0 263-128-3 /WINDOWS/Fonts/palab.ttf 344288 .a.. r/rr-xr-xr-x 0 0 264-128-3 /WINDOWS/Fonts/palabi.ttf 430800 .a.. r/rr-xr-xr-x 0 0 265-128-3 /WINDOWS/Fonts/palai.ttf 69464 .a.. r/rr-xr-xr-x 0 0 266-128-3 /WINDOWS/Fonts/symbol.ttf 239692 .a.. r/rr-xr-xr-x 0 0 267-128-3 /WINDOWS/Fonts/timesbi.ttf 248368 .a.. r/rr-xr-xr-x 0 0 268-128-3 /WINDOWS/Fonts/timesi.ttf 131188 .a.. r/rr-xr-xr-x 0 0 269-128-3 /WINDOWS/Fonts/trebucbi.ttf 139288 .a.. r/rr-xr-xr-x 0 0 270-128-3 /WINDOWS/Fonts/trebucit.ttf 155076 .a.. r/rr-xr-xr-x 0 0 271-128-3 /WINDOWS/Fonts/verdanai.ttf 154800 .a.. r/rr-xr-xr-x 0 0 272-128-3 /WINDOWS/Fonts/verdanaz.ttf 118752 .a.. r/rr-xr-xr-x 0 0 273-128-3 /WINDOWS/Fonts/webdings.ttf 261 .a.. r/rr-xr-xr-x 0 0 3641-128-3 /WINDOWS/system32/$winnt$.inf 90296 .a.. r/rr-xr-xr-x 0 0 3651-128-3 /WINDOWS/system32/FNTCACHE.DAT 625 .a.. r/rr-xr-xr-x 0 0 3683-128-4 /WINDOWS/WinSxS/Policies/x86_policy.5.1.Microsoft.Windows.SystemCompatible_6595b64144ccf1df_x-ww_a0111510/5.1.2600.2000.Policy 10496 .a.. r/rr-xr-xr-x 0 0 515-128-3 /WINDOWS/system32/drivers/dxapi.sys 488 .a.. r/r--x--x--x 0 0 6563-128-1 /WINDOWS/system32/WindowsLogon.manifest Fri Jul 01 2011 14:50:40 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_DCOMLAUNCH/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_DHCP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_DNSCACHE/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_RPCSS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_SAMSS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_THEMES/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_DCOMLAUNCH/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_DHCP/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_DNSCACHE/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_RPCSS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_SAMSS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_THEMES/0000 20 ..c. r/rr-xr-xr-x 0 0 10328-128-1 /Documents and Settings/NetworkService/ntuser.ini 62 mac. r/rr-xr-xr-x 0 0 10329-128-1 /Documents and Settings/NetworkService/Local Settings/desktop.ini 20 ..c. r/rr-xr-xr-x 0 0 10395-128-1 /Documents and Settings/LocalService/ntuser.ini 109652 ..c. r/rrwxrwxrwx 0 0 11162-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/change.log.2 1614848 .a.. r/rr-xr-xr-x 0 0 1935-128-3 /WINDOWS/system32/sfcfiles.dll 135168 .a.. r/rr-xr-xr-x 0 0 1987-128-3 /WINDOWS/system32/shsvcs.dll 56320 .a.. r/rr-xr-xr-x 0 0 2016-128-3 /WINDOWS/system32/eventlog.dll 181248 .a.. r/rr-xr-xr-x 0 0 2017-128-3 /WINDOWS/system32/scecli.dll 45568 .a.. r/rr-xr-xr-x 0 0 2033-128-3 /WINDOWS/system32/dnsrslvr.dll 14592 .a.. r/rr-xr-xr-x 0 0 2150-128-3 /WINDOWS/system32/drivers/ndisuio.sys 2188928 .a.. r/rr-xr-xr-x 0 0 3615-128-3 /WINDOWS/system32/ntoskrnl.exe 2065792 .a.. r/rr-xr-xr-x 0 0 3616-128-3 /WINDOWS/system32/ntkrnlpa.exe 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) EventLog/6005_Info_ (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) EventLog/6009_Info_5.01. - 2600 - Service Pack 3 - Uniprocessor Free (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 88192 .a.. r/rr-xr-xr-x 0 0 4831-128-3 /WINDOWS/system32/drivers/irda.sys Fri Jul 01 2011 14:50:41 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_IRMON/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_LMHOSTS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_TERMSERVICE/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_WZCSVC/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_IRMON/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_LMHOSTS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_TERMSERVICE/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_WZCSVC/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/Eventlog/Application/ESENT 16384 m... r/rr-xr-xr-x 0 0 10296-128-3 /Documents and Settings/NetworkService/Cookies/index.dat 16384 m... r/rr-xr-xr-x 0 0 10298-128-3 /Documents and Settings/NetworkService/Local Settings/History/History.IE5/index.dat 62 mac. r/rr-xr-xr-x 0 0 10396-128-1 /Documents and Settings/LocalService/Local Settings/desktop.ini 163328 .a.. r/rr-xr-xr-x 0 0 1144-128-3 /WINDOWS/system32/oleacc.dll 49664 .a.. r/rr-xr-xr-x 0 0 1977-128-3 /WINDOWS/system32/regapi.dll 14336 .a.. r/rr-xr-xr-x 0 0 2018-128-3 /WINDOWS/system32/svchost.exe 13824 .a.. r/rr-xr-xr-x 0 0 2034-128-3 /WINDOWS/system32/lmhsvc.dll 92672 .a.. r/rr-xr-xr-x 0 0 2084-128-3 /WINDOWS/system32/wlnotify.dll 116224 .a.. r/rr-xr-xr-x 0 0 2092-128-3 /WINDOWS/system32/mstlsapi.dll 514560 .a.. r/rr-xr-xr-x 0 0 2174-128-3 /WINDOWS/system32/logonui.exe 19456 .a.. r/rr-xr-xr-x 0 0 2367-128-3 /WINDOWS/system32/dimsntfy.dll 28160 .a.. r/rr-xr-xr-x 0 0 4832-128-3 /WINDOWS/system32/irmon.dll 11264 .a.. r/rr-xr-xr-x 0 0 4959-128-3 /WINDOWS/system32/icaapi.dll 295424 .a.. r/rr-xr-xr-x 0 0 4964-128-3 /WINDOWS/system32/termsrv.dll 488 .a.. r/r--x--x--x 0 0 6562-128-1 /WINDOWS/system32/logonui.exe.manifest Fri Jul 01 2011 14:50:42 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_AUDIOSRV/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_LANMANWORKSTATION/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_SCHEDULE/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_SHELLHWDETECTION/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_SPOOLER/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_AUDIOSRV/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_LANMANWORKSTATION/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_SCHEDULE/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_SHELLHWDETECTION/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_SPOOLER/0000 99328 .a.. r/rr-xr-xr-x 0 0 2015-128-3 /WINDOWS/system32/winscard.dll 6656 .a.. r/rr-xr-xr-x 0 0 2035-128-3 /WINDOWS/system32/msidle.dll 57856 .a.. r/rr-xr-xr-x 0 0 2036-128-3 /WINDOWS/system32/spoolsv.exe 132096 .a.. r/rr-xr-xr-x 0 0 2038-128-3 /WINDOWS/system32/wkssvc.dll 42496 .a.. r/rr-xr-xr-x 0 0 2040-128-3 /WINDOWS/system32/audiosrv.dll 150016 .a.. r/rr-xr-xr-x 0 0 2151-128-3 /WINDOWS/system32/rastls.dll 79872 .a.. r/rr-xr-xr-x 0 0 2152-128-3 /WINDOWS/system32/raschap.dll 192512 .a.. r/rr-xr-xr-x 0 0 5708-128-3 /WINDOWS/system32/schedsvc.dll Fri Jul 01 2011 14:50:48 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_BROWSER/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_CRYPTSVC/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_ERSVC/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_EVENTSYSTEM/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_HELPSVC/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_LANMANSERVER/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_MRXDAV/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_NETMAN/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_POLICYAGENT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_PROTECTEDSTORAGE/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_REMOTEREGISTRY/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_SECLOGON/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_SENS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_SRSERVICE/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_SRV/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_TRKWKS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_W32TIME/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_WEBCLIENT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_WINMGMT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_WSCSVC/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_WUAUSERV/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/LanmanServer/Parameters 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_BROWSER/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_CRYPTSVC/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_ERSVC/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_EVENTSYSTEM/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_HELPSVC/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_LANMANSERVER/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_MRXDAV/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_NETMAN/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_POLICYAGENT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_PROTECTEDSTORAGE/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_REMOTEREGISTRY/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_SECLOGON/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_SENS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_SRSERVICE/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_SRV/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_TRKWKS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_W32TIME/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_WEBCLIENT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_WINMGMT/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_WSCSVC/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_WUAUSERV/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Services/LanmanServer/Parameters 256 ..c. d/drwxrwxrwx 0 0 10363-144-1 /Documents and Settings/LocalService/Local Settings/Temporary Internet Files 56 ..c. d/drwxrwxrwx 0 0 10364-144-5 /Documents and Settings/LocalService/Local Settings/Temporary Internet Files/Content.IE5 16384 m... r/rr-xr-xr-x 0 0 10365-128-3 /Documents and Settings/LocalService/Cookies/index.dat 16384 m... r/rr-xr-xr-x 0 0 10366-128-3 /Documents and Settings/LocalService/Local Settings/History/History.IE5/index.dat 256 ..c. d/drwxrwxrwx 0 0 10369-144-1 /Documents and Settings/LocalService/Local Settings/History 256 ..c. d/drwxrwxrwx 0 0 10370-144-1 /Documents and Settings/LocalService/Local Settings/History/History.IE5 152 ..c. d/drwxrwxrwx 0 0 10371-144-1 /Documents and Settings/LocalService/Cookies 32768 m... r/rr-xr-xr-x 0 0 10414-128-3 /Documents and Settings/LocalService/Local Settings/Temporary Internet Files/Content.IE5/index.dat 536 .a.. r/rrwxrwxrwx 0 0 11466-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/rp.log 180608 .a.. r/rr-xr-xr-x 0 0 1893-128-3 /WINDOWS/system32/drivers/mrxdav.sys 183808 .a.. r/rr-xr-xr-x 0 0 2044-128-3 /WINDOWS/system32/ipsecsvc.dll 270336 .a.. r/rr-xr-xr-x 0 0 2046-128-3 /WINDOWS/system32/oakley.dll 59904 .a.. r/rr-xr-xr-x 0 0 2047-128-3 /WINDOWS/system32/regsvc.dll 32256 .a.. r/rr-xr-xr-x 0 0 2048-128-3 /WINDOWS/system32/winipsec.dll 68096 .a.. r/rr-xr-xr-x 0 0 2050-128-3 /WINDOWS/system32/webclnt.dll 62464 .a.. r/rr-xr-xr-x 0 0 2051-128-3 /WINDOWS/system32/cryptsvc.dll 194560 .a.. r/rr-xr-xr-x 0 0 2052-128-3 /WINDOWS/system32/certcli.dll 34304 .a.. r/rr-xr-xr-x 0 0 2055-128-3 /WINDOWS/system32/pstorsvc.dll 96768 .a.. r/rr-xr-xr-x 0 0 2057-128-3 /WINDOWS/system32/psbase.dll 175104 .a.. r/rr-xr-xr-x 0 0 2061-128-3 /WINDOWS/system32/w32time.dll 90112 .a.. r/rr-xr-xr-x 0 0 2071-128-3 /WINDOWS/system32/trkwks.dll 18944 .a.. r/rr-xr-xr-x 0 0 2072-128-3 /WINDOWS/system32/seclogon.dll 96768 .a.. r/rr-xr-xr-x 0 0 2073-128-3 /WINDOWS/system32/srvsvc.dll 334848 .a.. r/rr-xr-xr-x 0 0 2075-128-3 /WINDOWS/system32/drivers/srv.sys 77824 .a.. r/rr-xr-xr-x 0 0 2077-128-3 /WINDOWS/system32/browser.dll 2843136 .a.. r/rr-xr-xr-x 0 0 2108-128-3 /WINDOWS/system32/msi.dll 430592 .a.. r/rr-xr-xr-x 0 0 2160-128-3 /WINDOWS/system32/vssapi.dll 734 .a.. r/rr-xr-xr-x 0 0 233-128-3 /WINDOWS/system32/drivers/etc/hosts 6784 .a.. r/rr-xr-xr-x 0 0 235-128-3 /WINDOWS/system32/drivers/parvdm.sys 171008 .a.. r/rr-xr-xr-x 0 0 236-128-3 /WINDOWS/system32/netmsg.dll 23040 .a.. r/rr-xr-xr-x 0 0 2464-128-3 /WINDOWS/system32/ersvc.dll 80896 .a.. r/rr-xr-xr-x 0 0 3180-128-3 /WINDOWS/system32/wscsvc.dll 144896 .a.. r/rr-xr-xr-x 0 0 4914-128-3 /WINDOWS/system32/wbem/wmisvc.dll 171008 .a.. r/rr-xr-xr-x 0 0 5759-128-3 /WINDOWS/system32/srsvc.dll 38400 .a.. r/rr-xr-xr-x 0 0 5777-128-3 /WINDOWS/pchealth/helpctr/binaries/pchsvc.dll 6656 .a.. r/rr-xr-xr-x 0 0 6058-128-3 /WINDOWS/system32/wuauserv.dll Fri Jul 01 2011 14:50:50 62 mac. r/rr-xr-xr-x 0 0 10530-128-3 /Documents and Settings/malware/Local Settings/desktop.ini 5632 .a.. r/rr-xr-xr-x 0 0 214-128-3 /WINDOWS/system32/kbdus.dll 1024 ma.. r/rr-xr-xr-x 0 0 3650-128-3 /WINDOWS/system32/config/SAM.LOG Fri Jul 01 2011 14:50:51 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Session Manager/Power 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_SHAREDACCESS/0000 0 m... 0 0 0 0 REG_System_system/ControlSet002/Control/Session Manager/Power 0 m... 0 0 0 0 REG_System_system/ControlSet002/Enum/Root/LEGACY_SHAREDACCESS/0000 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Group Policy 36352 .a.. r/rr-xr-xr-x 0 0 2000-128-3 /WINDOWS/system32/ncobjapi.dll 58368 .a.. r/rr-xr-xr-x 0 0 2313-128-3 /WINDOWS/system32/clusapi.dll 66560 .a.. r/rr-xr-xr-x 0 0 2789-128-3 /WINDOWS/system32/mtxclu.dll 58880 .a.. r/rr-xr-xr-x 0 0 2954-128-3 /WINDOWS/system32/resutils.dll 70888 ma.. r/rr-xr-xr-x 0 0 3743-128-3 /WINDOWS/Debug/UserMode/userenv.log 247808 .a.. r/rr-xr-xr-x 0 0 4869-128-3 /WINDOWS/system32/wbem/esscli.dll 472064 .a.. r/rr-xr-xr-x 0 0 4870-128-3 /WINDOWS/system32/wbem/fastprox.dll 178176 .a.. r/rr-xr-xr-x 0 0 4883-128-3 /WINDOWS/system32/wbem/repdrvfs.dll 214528 .a.. r/rr-xr-xr-x 0 0 4890-128-3 /WINDOWS/system32/wbem/wbemcomn.dll 531456 .a.. r/rr-xr-xr-x 0 0 4892-128-3 /WINDOWS/system32/wbem/wbemcore.dll 273920 .a.. r/rr-xr-xr-x 0 0 4894-128-3 /WINDOWS/system32/wbem/wbemess.dll 18944 .a.. r/rr-xr-xr-x 0 0 4895-128-3 /WINDOWS/system32/wbem/wbemprox.dll 43520 .a.. r/rr-xr-xr-x 0 0 4896-128-3 /WINDOWS/system32/wbem/wbemsvc.dll 437248 .a.. r/rr-xr-xr-x 0 0 4911-128-3 /WINDOWS/system32/wbem/wmiprvsd.dll 95232 .a.. r/rr-xr-xr-x 0 0 4915-128-3 /WINDOWS/system32/wbem/wmiutils.dll 1267200 .a.. r/rr-xr-xr-x 0 0 4929-128-3 /WINDOWS/system32/comsvcs.dll 60416 .a.. r/rr-xr-xr-x 0 0 4937-128-3 /WINDOWS/system32/colbact.dll 20 m... r/rr-xr-xr-x 0 0 5547-128-1 /WINDOWS/system32/wbem/Repository/$WinMgmt.CFG Fri Jul 01 2011 14:50:52 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_ALG/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_FASTUSERSWITCHINGCOMPATIBILITY/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_NLA/0000 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/SharedAccess/Epoch 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Internet Explorer/Desktop/Components/0 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/MountPoints2 118784 .a.. r/rr-xr-xr-x 0 0 2037-128-3 /WINDOWS/system32/ntmarta.dll 102912 .a.. r/rr-xr-xr-x 0 0 2089-128-3 /WINDOWS/system32/dpcdll.dll 26112 .a.. r/rr-xr-xr-x 0 0 2090-128-3 /WINDOWS/system32/userinit.exe 135168 .a.. r/rr-xr-xr-x 0 0 2105-128-3 /WINDOWS/system32/desk.cpl 385536 .a.. r/rr-xr-xr-x 0 0 2106-128-3 /WINDOWS/system32/themeui.dll 44544 .a.. r/rr-xr-xr-x 0 0 2242-128-3 /WINDOWS/system32/alg.exe 13646 ma.. r/rr-xr-xr-x 0 0 237-128-3 /WINDOWS/system32/wpa.dbl 331264 .a.. r/rr-xr-xr-x 0 0 2578-128-3 /WINDOWS/system32/ipnathlp.dll 4190352 .a.. r/rr-xr-xr-x 0 0 2654-128-3 /WINDOWS/Resources/Themes/Luna/luna.msstyles 34816 .a.. r/rr-xr-xr-x 0 0 3048-128-3 /WINDOWS/system32/ssdpapi.dll 13824 .a.. r/rr-xr-xr-x 0 0 3177-128-3 /WINDOWS/system32/wscntfy.exe 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) SecurityCenter/1800_Info_ (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Service Control Manager/7036_Info_Application Layer Gateway Service - running (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Service Control Manager/7036_Info_Computer Browser - stopped (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Service Control Manager/7036_Info_Fast User Switching Compatibility - running (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Service Control Manager/7036_Info_Network Location Awareness (NLA) - running (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 S-1-5-18 0 3663 [Event Log] (Time generated/Time written) User: S-1-5-18 Service Control Manager/7035_Info_Application Layer Gateway Service - start (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 S-1-5-18 0 3663 [Event Log] (Time generated/Time written) User: S-1-5-18 Service Control Manager/7035_Info_Fast User Switching Compatibility - start (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 S-1-5-18 0 3663 [Event Log] (Time generated/Time written) User: S-1-5-18 Service Control Manager/7035_Info_Network Location Awareness (NLA) - start (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 1237 .a.. r/rr-xr-xr-x 0 0 3668-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.2600.2000_x-ww_bcc9a281.Manifest 397 .a.. r/rr-xr-xr-x 0 0 3672-128-1 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c.Manifest 605 .a.. r/rr-xr-xr-x 0 0 3676-128-4 /WINDOWS/WinSxS/Policies/x86_policy.1.0.Microsoft.Windows.GdiPlus_6595b64144ccf1df_x-ww_4e8510ac/1.0.2600.5512.Policy 1883 .a.. r/rr-xr-xr-x 0 0 3689-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7.Manifest 1187 .a.. r/rr-xr-xr-x 0 0 3693-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95.Manifest 460 .a.. r/rr-xr-xr-x 0 0 3697-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0.Manifest 641 .a.. r/rr-xr-xr-x 0 0 3700-128-4 /WINDOWS/WinSxS/Policies/x86_policy.5.2.Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_x-ww_362e60dd/5.2.2.3.Policy 641 .a.. r/rr-xr-xr-x 0 0 3703-128-4 /WINDOWS/WinSxS/Policies/x86_policy.5.2.Microsoft.Windows.Networking.Rtcdll_6595b64144ccf1df_x-ww_c7b7206f/5.2.2.3.Policy 47104 .a.. r/rr-xr-xr-x 0 0 4878-128-3 /WINDOWS/system32/wbem/ncprov.dll 71680 .a.. r/rr-xr-xr-x 0 0 4891-128-3 /WINDOWS/system32/wbem/wbemcons.dll 430592 .a.. r/rr-xr-xr-x 0 0 6051-128-3 /WINDOWS/system32/wuapi.dll Fri Jul 01 2011 14:50:53 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_SSDPSRV/0000 0 m... 0 0 0 0 REG_User_malware 452608 .a.. r/rr-xr-xr-x 0 0 10650-128-4 /Documents and Settings/All Users/Application Data/VDPLtsHLVdsd.exe 36656 .a.. r/rr-xr-xr-x 0 0 208-128-3 /WINDOWS/Fonts/dosapp.fon 8368 .a.. r/rr-xr-xr-x 0 0 210-128-3 /WINDOWS/Fonts/ega40woa.fon 4304 .a.. r/rr-xr-xr-x 0 0 211-128-3 /WINDOWS/Fonts/cga80woa.fon 6336 .a.. r/rr-xr-xr-x 0 0 212-128-3 /WINDOWS/Fonts/cga40woa.fon 264832 .a.. r/rr-xr-xr-x 0 0 2530-128-3 /WINDOWS/system32/drivers/http.sys 71680 .a.. r/rr-xr-xr-x 0 0 3049-128-3 /WINDOWS/system32/ssdpsrv.dll 133632 .a.. r/rr-xr-xr-x 0 0 3126-128-3 /WINDOWS/system32/upnp.dll 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Service Control Manager/7036_Info_SSDP Discovery Service - running (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 S-1-5-18 0 3663 [Event Log] (Time generated/Time written) User: S-1-5-18 Service Control Manager/7035_Info_SSDP Discovery Service - start (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 14:50:54 308736 .a.. r/rr-xr-xr-x 0 0 11114-128-3 /WINDOWS/system32/wget.exe Fri Jul 01 2011 14:50:55 14848 .a.. r/rr-xr-xr-x 0 0 545-128-3 /WINDOWS/system32/fc.exe 9216 .a.. r/rr-xr-xr-x 0 0 551-128-3 /WINDOWS/system32/find.exe Fri Jul 01 2011 14:50:57 0 m... 0 0 0 0 REG_User_malware/Control Panel/Desktop 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Internet Explorer/Desktop/Components 62 .a.. r/rr-xr-xr-x 0 0 10537-128-3 /Documents and Settings/malware/Application Data/desktop.ini 2128 mac. r/rr-xr-xr-x 0 0 10570-128-3 /Documents and Settings/malware/Application Data/Microsoft/Internet Explorer/Desktop.htt 899 .a.. r/rr-xr-xr-x 0 0 11116-128-3 /get.bat 0 .a.. r/rr-xr-xr-x 0 0 11453-128-3 /WINDOWS/system32/sandnet.exe 17408 .a.. r/rr-xr-xr-x 0 0 2087-128-3 /WINDOWS/system32/powrprof.dll 276480 .a.. r/rr-xr-xr-x 0 0 2134-128-3 /WINDOWS/system32/webcheck.dll 121856 .a.. r/rr-xr-xr-x 0 0 2154-128-3 /WINDOWS/system32/stobject.dll 29184 .a.. r/rr-xr-xr-x 0 0 2155-128-3 /WINDOWS/system32/batmeter.dll 830 .a.. r/rr-xr-xr-x 0 0 6225-128-3 /WINDOWS/Web/deskmovr.htt Fri Jul 01 2011 14:50:58 0 m... 0 0 0 0 REG_System_system/ControlSet001/Enum/Root/LEGACY_IMAPISERVICE/0000 0 m... 0 0 0 0 REG_User_malware/Software 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/Discardable/PostSetup/Component Categories/{00021493-0000-0000-C000-000000000046}/Enum 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/Discardable/PostSetup/Component Categories/{00021494-0000-0000-C000-000000000046}/Enum 150 .ac. r/rr-xr-xr-x 0 0 10676-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000135.ini 372736 m..b r/rr-xr-xr-x 0 0 11166-128-3 /Documents and Settings/All Users/Application Data/14147364.exe 827 .acb 0 0 0 11170 [Shortcut LNK] (Modified/Access/Created) C:/Documents and Settings/All Users/Application Data/14147364.exe <-/media/sdb1/Documents and Settings/malware/Start Menu/Programs/Windows XP Repair/Windows XP Repair.lnk- which is stored on a local vol type - Fixed- SN 0xcac117b - Desc: Windows XP Repair Rel path: ../../../../All Users/Application Data/14147364.exe [a rel. path str-a descr. str-SI ID exists-points to a file or dir] - mod since last backup-hidden (file: /media/sdb1/Documents and Settings/malware/Start Menu/Programs/Windows XP Repair/Windows XP Repair.lnk) 899 .acb 0 0 0 11171 [Shortcut LNK] (Modified/Access/Created) C:/Documents and Settings/All Users/Application Data/14147364.exe <-/media/sdb1/Documents and Settings/malware/Start Menu/Programs/Windows XP Repair/Uninstall Windows XP Repair.lnk- which is stored on a local vol type - Fixed- SN 0xcac117b - Desc: Windows XP Repair Rel path: ../../../../All Users/Application Data/14147364.exe CMD arg: 1 [a rel. path str-cmd line args-a descr. str-SI ID exists-custom icon-points to a file or dir] - mod since last backup-hidden (file: /media/sdb1/Documents and Settings/malware/Start Menu/Programs/Windows XP Repair/Uninstall Windows XP Repair.lnk) 815 .acb 0 0 0 11172 [Shortcut LNK] (Modified/Access/Created) C:/Documents and Settings/All Users/Application Data/14147364.exe <-/media/sdb1/Documents and Settings/malware/Desktop/Windows XP Repair.lnk- which is stored on a local vol type - Fixed- SN 0xcac117b - Desc: Windows XP Repair Rel path: ../../All Users/Application Data/14147364.exe [a rel. path str-a descr. str-SI ID exists-points to a file or dir] - mod since last backup-hidden (file: /media/sdb1/Documents and Settings/malware/Desktop/Windows XP Repair.lnk) 98304 .a.. r/rr-xr-xr-x 0 0 2113-128-3 /WINDOWS/system32/actxprxy.dll 150528 .a.. r/rr-xr-xr-x 0 0 2126-128-3 /WINDOWS/system32/imapi.exe 90624 .a.. r/rr-xr-xr-x 0 0 2187-128-3 /WINDOWS/system32/mydocs.dll 658432 .a.. r/rr-xr-xr-x 0 0 2937-128-3 /WINDOWS/system32/rasdlg.dll 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Service Control Manager/7036_Info_IMAPI CD-Burning COM Service - running (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 macb 0 S-1-5-18 0 3663 [Event Log] (Time generated/Time written) User: S-1-5-18 Service Control Manager/7035_Info_IMAPI CD-Burning COM Service - start (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 48 m... d/dr-xr-xr-x 0 0 72-144-6 /WINDOWS/Temp Fri Jul 01 2011 14:51:00 256 .a.. d/drwxrwxrwx 0 0 10302-144-1 /Documents and Settings/NetworkService/Local Settings/History 256 .a.. d/drwxrwxrwx 0 0 3664-144-1 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files Fri Jul 01 2011 14:51:04 1024 ma.. r/rr-xr-xr-x 0 0 10541-128-4 /Documents and Settings/malware/Local Settings/Application Data/Microsoft/Windows/UsrClass.dat.LOG 336 m..b r/rr-xr-xr-x 0 0 11168-128-1 /Documents and Settings/All Users/Application Data/14147364 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Service Control Manager/7036_Info_IMAPI CD-Burning COM Service - stopped (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 m... 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/15_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 m... 0 0 0 3663 [Event Log] (Time generated/Time written) b57w2k/9_Info_ - Broadcom NetXtreme Gigabit Ethernet (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 14:51:05 1024 ma.. r/rr-xr-xr-x 0 0 10394-128-4 /Documents and Settings/LocalService/Local Settings/Application Data/Microsoft/Windows/UsrClass.dat.LOG 64000 .a.. r/rr-xr-xr-x 0 0 2308-128-3 /WINDOWS/system32/cleanmgr.exe Fri Jul 01 2011 14:51:06 1024 ma.. r/rr-xr-xr-x 0 0 10327-128-4 /Documents and Settings/NetworkService/Local Settings/Application Data/Microsoft/Windows/UsrClass.dat.LOG Fri Jul 01 2011 14:51:07 1033728 .a.. r/rr-xr-xr-x 0 0 2093-128-3 /WINDOWS/explorer.exe 176640 .a.. r/rr-xr-xr-x 0 0 2796-128-3 /WINDOWS/system32/napstat.exe Fri Jul 01 2011 14:51:08 827 m... 0 0 0 11170 [Shortcut LNK] (Modified/Access/Created) C:/Documents and Settings/All Users/Application Data/14147364.exe <-/media/sdb1/Documents and Settings/malware/Start Menu/Programs/Windows XP Repair/Windows XP Repair.lnk- which is stored on a local vol type - Fixed- SN 0xcac117b - Desc: Windows XP Repair Rel path: ../../../../All Users/Application Data/14147364.exe [a rel. path str-a descr. str-SI ID exists-points to a file or dir] - mod since last backup-hidden (file: /media/sdb1/Documents and Settings/malware/Start Menu/Programs/Windows XP Repair/Windows XP Repair.lnk) 899 m... 0 0 0 11171 [Shortcut LNK] (Modified/Access/Created) C:/Documents and Settings/All Users/Application Data/14147364.exe <-/media/sdb1/Documents and Settings/malware/Start Menu/Programs/Windows XP Repair/Uninstall Windows XP Repair.lnk- which is stored on a local vol type - Fixed- SN 0xcac117b - Desc: Windows XP Repair Rel path: ../../../../All Users/Application Data/14147364.exe CMD arg: 1 [a rel. path str-cmd line args-a descr. str-SI ID exists-custom icon-points to a file or dir] - mod since last backup-hidden (file: /media/sdb1/Documents and Settings/malware/Start Menu/Programs/Windows XP Repair/Uninstall Windows XP Repair.lnk) 815 m... 0 0 0 11172 [Shortcut LNK] (Modified/Access/Created) C:/Documents and Settings/All Users/Application Data/14147364.exe <-/media/sdb1/Documents and Settings/malware/Desktop/Windows XP Repair.lnk- which is stored on a local vol type - Fixed- SN 0xcac117b - Desc: Windows XP Repair Rel path: ../../All Users/Application Data/14147364.exe [a rel. path str-a descr. str-SI ID exists-points to a file or dir] - mod since last backup-hidden (file: /media/sdb1/Documents and Settings/malware/Desktop/Windows XP Repair.lnk) Fri Jul 01 2011 14:51:10 56 m... d/d--x--x--x 0 0 10444-144-5 /Documents and Settings/malware/Start Menu/Programs 288 m... d/dr-xr-xr-x 0 0 10471-144-1 /Documents and Settings/malware/Desktop 544 m..b d/dr-xr-xr-x 0 0 11169-144-1 /Documents and Settings/malware/Start Menu/Programs/Windows XP Repair 827 ma.b r/rr-xr-xr-x 0 0 11170-128-4 /Documents and Settings/malware/Start Menu/Programs/Windows XP Repair/Windows XP Repair.lnk 899 ma.b r/rr-xr-xr-x 0 0 11171-128-4 /Documents and Settings/malware/Start Menu/Programs/Windows XP Repair/Uninstall Windows XP Repair.lnk 815 m..b r/rr-xr-xr-x 0 0 11172-128-4 /Documents and Settings/malware/Desktop/Windows XP Repair.lnk 39424 .a.. r/rr-xr-xr-x 0 0 2074-128-3 /WINDOWS/system32/sens.dll 62 .a.. r/rr-xr-xr-x 0 0 3849-128-1 /Documents and Settings/All Users/Application Data/desktop.ini 151 .a.. r/rr-xr-xr-x 0 0 4860-128-1 /Documents and Settings/All Users/Documents/My Videos/Desktop.ini 151 .a.. r/rr-xr-xr-x 0 0 5491-128-1 /Documents and Settings/All Users/Documents/My Music/Desktop.ini 150 .a.. r/rr-xr-xr-x 0 0 5613-128-1 /Documents and Settings/All Users/Documents/My Pictures/Desktop.ini Fri Jul 01 2011 14:51:11 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/WinTrust/Trust Providers/Software Publishing 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/ShellNoRoam/MUICache 815 .a.. r/rr-xr-xr-x 0 0 11172-128-4 /Documents and Settings/malware/Desktop/Windows XP Repair.lnk 232 ...b r/rr-xr-xr-x 0 0 11173-128-4 /Documents and Settings/All Users/Application Data/~14147364 168 ma.b r/rr-xr-xr-x 0 0 11174-128-1 /Documents and Settings/All Users/Application Data/~14147364r 19968 .a.. r/rr-xr-xr-x 0 0 2117-128-3 /WINDOWS/system32/linkinfo.dll 143360 .a.. r/rr-xr-xr-x 0 0 2118-128-3 /WINDOWS/system32/ntshrui.dll 56 m... d/d--x--x--x 0 0 3736-144-6 /Documents and Settings/All Users/Application Data Fri Jul 01 2011 14:51:12 232 ma.. r/rr-xr-xr-x 0 0 11173-128-4 /Documents and Settings/All Users/Application Data/~14147364 Fri Jul 01 2011 14:51:18 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Print 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Print/Providers 75264 .a.. r/rr-xr-xr-x 0 0 2091-128-3 /WINDOWS/system32/spoolss.dll 343040 .a.. r/rr-xr-xr-x 0 0 2095-128-3 /WINDOWS/system32/localspl.dll 47104 .a.. r/rr-xr-xr-x 0 0 2097-128-3 /WINDOWS/system32/cnbjmon.dll 8192 .a.. r/rr-xr-xr-x 0 0 4829-128-3 /WINDOWS/system32/wshirda.dll Fri Jul 01 2011 14:51:19 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows NT/CurrentVersion/Devices 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows NT/CurrentVersion/PrinterPorts 67072 .a.. r/rr-xr-xr-x 0 0 2004-128-3 /WINDOWS/system32/ntdsapi.dll 15360 .a.. r/rr-xr-xr-x 0 0 2098-128-3 /WINDOWS/system32/pjlmon.dll 45568 .a.. r/rr-xr-xr-x 0 0 2099-128-3 /WINDOWS/system32/tcpmon.dll 16896 .a.. r/rr-xr-xr-x 0 0 2100-128-3 /WINDOWS/system32/usbmon.dll 102400 .a.. r/rr-xr-xr-x 0 0 2103-128-3 /WINDOWS/system32/win32spl.dll 75264 .a.. r/rr-xr-xr-x 0 0 2104-128-3 /WINDOWS/system32/inetpp.dll Fri Jul 01 2011 14:51:24 1024 .a.. r/rr-xr-xr-x 0 0 10389-128-4 /Documents and Settings/LocalService/ntuser.dat.LOG Fri Jul 01 2011 14:51:25 1024 m... r/rr-xr-xr-x 0 0 10389-128-4 /Documents and Settings/LocalService/ntuser.dat.LOG Fri Jul 01 2011 14:51:36 0 m... 0 0 0 0 REG_System_system/ControlSet001/Services/Eventlog/Application/ESENT Fri Jul 01 2011 14:51:37 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) ESENT/100_Info_wuauclt - 484 - - 5 - 01 - 2600 - 5512 (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) ESENT/102_Info_wuaueng.dll - 484 - SUS20ClientDataStore: - 0 (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) Fri Jul 01 2011 14:51:39 1048472 mac. r/rrwxrwxrwx 0 0 10648-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/change.log.3 416 m.c. d/drwxrwxrwx 0 0 11458-144-5 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12 Fri Jul 01 2011 14:51:51 20 .a.. r/rr-xr-xr-x 0 0 5547-128-1 /WINDOWS/system32/wbem/Repository/$WinMgmt.CFG 5300224 ma.. r/rr-xr-xr-x 0 0 5553-128-4 /WINDOWS/system32/wbem/Repository/FS/OBJECTS.DATA 999424 ma.. r/rr-xr-xr-x 0 0 5554-128-3 /WINDOWS/system32/wbem/Repository/FS/INDEX.BTR Fri Jul 01 2011 14:51:52 0 macb 0 0 0 10413 [XP Prefetch] (Last run) WUAUCLT.EXE-399A8E72.pf - [WUAUCLT.EXE] was executed - run count [14]- full path: [C:/WINDOWS/SYSTEM32/WUAUCLT.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/ATL.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/SHFOLDER.DLL - WINDOWS/SYSTEM32/WUAUENG.DLL - WINDOWS/SYSTEM32/ADVPACK.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/CABINET.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/ESENT.DLL - WINDOWS/SYSTEM32/MSPATCHA.DLL - WINDOWS/SYSTEM32/SETUPAPI.DLL - WINDOWS/SYSTEM32/SFC.DLL - WINDOWS/SYSTEM32/SFC_OS.DLL - WINDOWS/SYSTEM32/WINTRUST.DLL - WINDOWS/SYSTEM32/IMAGEHLP.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/WINHTTP.DLL - WINDOWS/SYSTEM32/WINSTA.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/WS2_32.DLL - WINDOWS/SYSTEM32/WS2HELP.DLL - WINDOWS/SYSTEM32/WTSAPI32.DLL - WINDOWS/SYSTEM32/MSIMG32.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/SYSTEM32/RPCSS.DLL - WINDOWS/SYSTEM32/CLBCATQ.DLL - WINDOWS/SYSTEM32/COMRES.DLL - WINDOWS/SYSTEM32/XPSP2RES.DLL - WINDOWS/SYSTEM32/WUPS.DLL} (file: /media/sdb1/WINDOWS/Prefetch/WUAUCLT.EXE-399A8E72.pf) 5120 .a.. r/rr-xr-xr-x 0 0 1989-128-3 /WINDOWS/system32/sfc.dll 14336 .a.. r/rr-xr-xr-x 0 0 2056-128-3 /WINDOWS/system32/drprov.dll 44032 .a.. r/rr-xr-xr-x 0 0 2058-128-3 /WINDOWS/system32/ntlanman.dll 80896 .a.. r/rr-xr-xr-x 0 0 2059-128-3 /WINDOWS/system32/netui0.dll 245760 .a.. r/rr-xr-xr-x 0 0 2060-128-3 /WINDOWS/system32/netui1.dll 11776 .a.. r/rr-xr-xr-x 0 0 2062-128-3 /WINDOWS/system32/netrap.dll 25088 .a.. r/rr-xr-xr-x 0 0 2064-128-3 /WINDOWS/system32/davclnt.dll 25088 .a.. r/rr-xr-xr-x 0 0 2076-128-3 /WINDOWS/system32/shfolder.dll 4608 .a.. r/rr-xr-xr-x 0 0 2107-128-3 /WINDOWS/system32/msimg32.dll 99840 .a.. r/rr-xr-xr-x 0 0 2115-128-3 /WINDOWS/system32/advpack.dll 29696 .a.. r/rr-xr-xr-x 0 0 2760-128-3 /WINDOWS/system32/mspatcha.dll 140288 .a.. r/rr-xr-xr-x 0 0 3005-128-3 /WINDOWS/system32/sfc_os.dll 3160 ma.. r/rr-xr-xr-x 0 0 5548-128-3 /WINDOWS/system32/wbem/Repository/FS/MAPPING1.MAP 4 ma.. r/rr-xr-xr-x 0 0 5550-128-1 /WINDOWS/system32/wbem/Repository/FS/MAPPING.VER 524 ma.. r/rr-xr-xr-x 0 0 5551-128-1 /WINDOWS/system32/wbem/Repository/FS/INDEX.MAP 2636 ma.. r/rr-xr-xr-x 0 0 5552-128-3 /WINDOWS/system32/wbem/Repository/FS/OBJECTS.MAP 32256 .a.. r/rr-xr-xr-x 0 0 6055-128-3 /WINDOWS/system32/wups.dll 1135616 .a.. r/rr-xr-xr-x 0 0 6056-128-3 /WINDOWS/system32/wuaueng.dll Fri Jul 01 2011 14:52:13 278154 mac. r/rrwxrwxrwx 0 0 10814-128-4 /WINDOWS/Prefetch/NTOSBOOT-B00DFAAD.pf 20948 mac. r/rrwxrwxrwx 0 0 3797-128-4 /WINDOWS/Prefetch/WUAUCLT.EXE-399A8E72.pf Fri Jul 01 2011 14:52:16 16384 .a.b r/rr-xr-xr-x 0 0 10296-128-3 /Documents and Settings/NetworkService/Cookies/index.dat 16384 .a.b r/rr-xr-xr-x 0 0 10298-128-3 /Documents and Settings/NetworkService/Local Settings/History/History.IE5/index.dat 256 ..c. d/drwxrwxrwx 0 0 10302-144-1 /Documents and Settings/NetworkService/Local Settings/History 256 mac. d/drwxrwxrwx 0 0 10303-144-1 /Documents and Settings/NetworkService/Local Settings/History/History.IE5 152 mac. d/drwxrwxrwx 0 0 10304-144-1 /Documents and Settings/NetworkService/Cookies 32768 ma.b r/rr-xr-xr-x 0 0 11180-128-3 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files/Content.IE5/index.dat 152 m.cb d/drwxrwxrwx 0 0 11181-144-1 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files/Content.IE5/GDEJ4DMF 67 macb r/rr-xr-xr-x 0 0 11182-128-1 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files/Content.IE5/GDEJ4DMF/desktop.ini 152 m.cb d/drwxrwxrwx 0 0 11183-144-1 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files/Content.IE5/W5M30XMF 67 macb r/rr-xr-xr-x 0 0 11184-128-1 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files/Content.IE5/W5M30XMF/desktop.ini 152 m.cb d/drwxrwxrwx 0 0 11185-144-1 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files/Content.IE5/4D63S16F 67 macb r/rr-xr-xr-x 0 0 11186-128-1 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files/Content.IE5/4D63S16F/desktop.ini 152 m.cb d/drwxrwxrwx 0 0 11187-144-1 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files/Content.IE5/8HYZ4L6Z 67 macb r/rr-xr-xr-x 0 0 11188-128-1 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files/Content.IE5/8HYZ4L6Z/desktop.ini 256 ..c. d/drwxrwxrwx 0 0 3664-144-1 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files 56 mac. d/drwxrwxrwx 0 0 4843-144-5 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files/Content.IE5 Fri Jul 01 2011 14:52:21 1024 ma.. r/rr-xr-xr-x 0 0 10322-128-4 /Documents and Settings/NetworkService/ntuser.dat.LOG Fri Jul 01 2011 14:52:52 246272 .a.. r/rr-xr-xr-x 0 0 2042-128-3 /WINDOWS/system32/es.dll Fri Jul 01 2011 14:53:58 416 .a.. d/drwxrwxrwx 0 0 11458-144-5 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12 Fri Jul 01 2011 14:53:59 152 .a.. d/drwxrwxrwx 0 0 11181-144-1 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files/Content.IE5/GDEJ4DMF 152 .a.. d/drwxrwxrwx 0 0 11183-144-1 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files/Content.IE5/W5M30XMF 152 .a.. d/drwxrwxrwx 0 0 11185-144-1 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files/Content.IE5/4D63S16F 152 .a.. d/drwxrwxrwx 0 0 11187-144-1 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files/Content.IE5/8HYZ4L6Z Fri Jul 01 2011 14:54:07 0 m... 0 0 0 0 REG_User_malware/AppEvents/Schemes/Apps/Explorer/Navigating/.Current 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Internet Explorer 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Internet Explorer/InformationBar 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Internet Explorer/PhishingFilter 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Internet Explorer/Recovery 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 0 m... 0 0 0 0 REG_User_malware/Software/Policies/Microsoft 0 m... 0 0 0 0 REG_User_malware/Software/Policies/Microsoft/Internet Explorer 0 m... 0 0 0 0 REG_User_malware/Software/Policies/Microsoft/Internet Explorer/Recovery 0 macb 0 0 0 10413 [XP Prefetch] (Last run) REGEDIT.EXE-1B606482.pf - [REGEDIT.EXE] was executed - run count [2]- full path: [C:/WINDOWS/REGEDIT.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/COMDLG32.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/AUTHZ.DLL - WINDOWS/SYSTEM32/ACLUI.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/ULIB.DLL - WINDOWS/SYSTEM32/CLB.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL} (file: /media/sdb1/WINDOWS/Prefetch/REGEDIT.EXE-1B606482.pf) 146432 .a.. r/rr-xr-xr-x 0 0 2109-128-3 /WINDOWS/regedit.exe 62464 .a.. r/rr-xr-xr-x 0 0 2110-128-3 /WINDOWS/system32/authz.dll 115712 .a.. r/rr-xr-xr-x 0 0 2111-128-3 /WINDOWS/system32/aclui.dll 10752 .a.. r/rr-xr-xr-x 0 0 238-128-3 /WINDOWS/system32/clb.dll Fri Jul 01 2011 14:54:08 12186 mac. r/rrwxrwxrwx 0 0 11119-128-4 /WINDOWS/Prefetch/REGEDIT.EXE-1B606482.pf Fri Jul 01 2011 14:54:11 59904 .a.. r/rr-xr-xr-x 0 0 1956-128-3 /WINDOWS/system32/mpr.dll 132608 .a.. r/rr-xr-xr-x 0 0 2011-128-3 /WINDOWS/system32/msv1_0.dll 146432 .a.. r/rr-xr-xr-x 0 0 2085-128-3 /WINDOWS/system32/winspool.drv 251904 .a.. r/rr-xr-xr-x 0 0 2542-128-3 /WINDOWS/system32/iepeers.dll 274432 .a.. r/rr-xr-xr-x 0 0 5699-128-3 /WINDOWS/system32/inetcfg.dll 16384 .a.. r/rr-xr-xr-x 0 0 6134-128-3 /WINDOWS/system32/icfgnt5.dll Fri Jul 01 2011 14:54:12 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/MenuOrder/Favorites/Links 7280 .a.. r/rr-xr-xr-x 0 0 204-128-3 /WINDOWS/Fonts/vgasys.fon Fri Jul 01 2011 14:54:27 997376 .a.. r/rr-xr-xr-x 0 0 1983-128-3 /WINDOWS/system32/msgina.dll 249856 .a.. r/rr-xr-xr-x 0 0 1984-128-3 /WINDOWS/system32/odbc32.dll 94208 .a.. r/rr-xr-xr-x 0 0 1986-128-3 /WINDOWS/system32/odbcint.dll 68096 .a.. r/rr-xr-xr-x 0 0 2177-128-3 /WINDOWS/system32/shgina.dll 304128 .a.. r/rr-xr-xr-x 0 0 2189-128-3 /WINDOWS/system32/duser.dll Fri Jul 01 2011 14:54:31 100 m..b r/rr-xr-xr-x 0 0 10317-128-1 /Documents and Settings/malware/Cookies/malware@64.111.211[1].txt 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://www.findfertile.org/go.php?userip=198.176.229.10&referer=http://www.findfertile.org/search.php?q=penguin&aid=531&sid=direc20&curl=http://64.111.211.158/c.php?s=eNolVNkOqkgQ_SAS6W627of7ACggArIo28uEVdlkERSJHz_emVRqSVUqdR7qnPqLGBbCL2bx17qYqxG4Q9b5tVmLf75gBwDH_Z_4LwIQAuEXBI5hyDdT_SVm_CG9_fnzJbjAkECcpgLHEZjkPCoBEQRSJCBNcvhPVrJlwhf8b5kTMjZBggAwk7HprySIkC_6WWH11uZ3SQZ6UbREf4hfzv01B77pZAfXLUrdqYbhpo80_UKZxBn49WYo_DpFSbnhDcfKldJoS17udJYLNKuwe55K1SZ6ej250pCJbDF8hi-eXNbbQ6OL-uRSQ6jT1So1z6kyXBFZ3EYqRb4bQ_vDotoGZdHKnjsu5iVsu_GEoZzJkXmXFM-F-FGv98fktGW0jG-BVzZnRi-37cXgUDqWW63IyK8mWVPNad76inUAuUtlMlN8e97mz3OalWDYO-u5M3W5r4hs16Jsf_QTe3t2XAVyOoEdh1627iiPHK75UkvnOzqpEb91lK2BZxmFERaPKHiH3o301K22x9HQfdA53N15SSnXeQgk7TPsqZGj3fcwHo4UnGcNlPeeKiTVDVDq8kquySY7pXvtrDTkqsBtmOfIPR_pYmLMghYmsXv4LRdk46K50nQ5G_Py1nVMVlOLUY_wklgIeBdfhvpDok-VEz2UjRueLf44pUmN_QmHr3IjvN0wriPmxV68r6oSzWFV-cD5lM8petjckb-6sRs1_HVSh4esDtEejJtsyPV9L9Pg2h_00umIROnU-IHauVSOCzg85uJ2qfRsPpTdYApth27oUxnJWZm0Uv59iKACaXy8ATXOH3o-GkeeJogXlnlg5L3_Wd1TGN-84vI2P4EprIL09Nbr0WLWbClB3TVuc6GuRu1GnoLqceHtOnflRArvh7BQANXCvtuU2Q6uABs8Lb454O2FJHoO5Cok3Msp8dVz1Mh5TOcWFB3l5ts1lvDyzhi4zRYKgJdn1kHDNQjPXWRM_Abj24iTB-t3j07lwwksoUb4J2f2b-U9qYexmVx813Joyx9V9KauyT8jSTyN0Q-j8uhX9ZP1LE1m2Z5B3dzGwPPt82S7XMAf93bntJYv7SHVzuVLHt_xwaJTe6kt3xNGyc9RO6hnScz946atZijTK_pR4pXPT8FOfROnxLshgRMV-clQSVDJWgs3qfRMwvZ5ihr6hyDcDNorzEG3YsE5VHs9WitCM7LUCK9TSebK1pfRtp0TdzJYeA1JP6VX9bU4xz6u5uORefP4aDUlazd26zXvn9RAgndQ4HcIkR0E3y_E7A5yP-eZHSTs928LfmOkzHFoMXGgbHGwgrzi5iSMh_TD1SkCP237z77MN2dyxuh-k87t4lAHSbC2Rkc-8d9jAhQYXPIpk6ZYIHnxYxJhScJkKWbLArLfFDA5LgWCQSGQjMs4gUnzIuG4pEAlEfJ_AdDxvDA&aid=531&sid=direc20 (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 0 .acb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:64.111.211.158/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 367112 .a.. r/rr-xr-xr-x 0 0 2169-128-3 /WINDOWS/Fonts/arial.ttf 352224 .a.. r/rr-xr-xr-x 0 0 2179-128-3 /WINDOWS/Fonts/arialbd.ttf Fri Jul 01 2011 14:54:32 5325 ma.b r/rr-xr-xr-x 0 0 10450-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CAG1AJ41.htm 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://search.happythat.com/results/?partnerid=113320&appid=150752&subid=23411&ip=198.176.229.10&cid=263890&entry=penguin&qs=JQwDFAMXaSFTVkVLSUVaSRpYUURuW0sTAwFFeFpUS0tCQF1fSFNAVTZUXV5cVBRzW0UWC01ER19fEhARdQofTVxLEHRdUkJfHhZUX0AREBBkW0scBQEdclZRR0tEQE8LAUxASD1UBQQYFQV2D0ZAH1VGDwgPTERSJAwMAwkJVDNADhsPGRtHDAFMBBM1TxwFCRdZeFoGQhxERQxdXxQRQDZcD0APU0Z1V1YRXwEAVF5dERgUZl5fQVRDSzJTER0XVhcCGFMHU0Q1VEsCAg4ddEgXAQoEFQ4GChwTFGNbVEheXAYiCwwGGBcdDVJcFBQUYk8YAgBYSDEaE1dKEVFbCUsTR0YyBAgDGwBBNgsPBg9eGQwZB04PQjwESEIKQBMjGxcfJhMVBB8PSEZPdloJQFRdQSAMPEdOQk1YXDETFxJrUF0vXVQTdlxTLUhFRF5aXH4TEmdYXFVeU1UxAzwBFgUGCgpLEkURa1EMFQ4GBXdYFgYULxkMCwdUTARgDV1IVARFJw== cache stored in: UPQVMROL/CAG1AJ41.htm - HTTP/1.1 200 OK - Content-Type: text/html_charset=ISO-8859-1 - Content-Length: 5325 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 361472 .a.. r/rr-xr-xr-x 0 0 321-128-3 /WINDOWS/Resources/Themes/Luna/Shell/NormalColor/shellstyle.dll Fri Jul 01 2011 14:54:33 92 ma.b r/rr-xr-xr-x 0 0 10316-128-1 /Documents and Settings/malware/Cookies/malware@search.happythat[1].txt 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://click.mygeek.com/presults.jsp?partnerid=113320&appid=150752&subid=23411&ip=198.176.229.10&cid=263890&entry=penguin&qs=JQwDFAMXaSFTVkVLSUVaSRpYUURuW0sTAwFFeFpUS0tCQF1fSFNAVTZUXV5cVBRzW0UWC01ER19fEhARdQofTVxLEHRdUkJfHhZUX0AREBBkW0scBQEdclZRR0tEQE8LAUxASD1UBQQYFQV2D0ZAH1VGDwgPTERSJAwMAwkJVDNADhsPGRtHDAFMBBM1TxwFCRdZeFoGQhxERQxdXxQRQDZcD0APU0Z1V1YRXwEAVF5dERgUZl5fQVRDSzJTER0XVhcCGFMHU0Q1VEsCAg4ddEgXAQoEFQ4GChwTFGNbVEheXAYiCwwGGBcdDVJcFBQUYk8YAgBYSDEaE1dKEVFbCUsTR0YyBAgDGwBBNgsPBg9eGQwZB04PQjwESEIKQBMjGxcfJhMVBB8PSEZPdloJQFRdQSAMPEdOQk1YXDETFxJrUF0vXVQTdlxTLUhFRF5aXH4TEmdYXFVeU1UxAzwBFgUGCgpLEkURa1EMFQ4GBXdYFgYULxkMCwdUTARgDV1IVARFJw==&REFERER=http://www.findfertile.org/ac3.php?q=penguin&aid=531&sid=direc20&POS=70x203&VIEWPORT=571x257&IFRAME=N&COOKIES=Y&RES=800x600 (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:search.happythat.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 337 ...b r/rr-xr-xr-x 0 0 11274-128-1 /Documents and Settings/malware/Cookies/malware@gamesweaseltv.mevio[1].txt Fri Jul 01 2011 14:54:34 0 .acb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:crux.mevio.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 95 m..b r/rr-xr-xr-x 0 0 11190-128-1 /Documents and Settings/malware/Cookies/malware@crux.mevio[1].txt 157999 m..b r/rr-xr-xr-x 0 0 11194-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/index[2].js 1604 m..b r/rr-xr-xr-x 0 0 11195-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/ie6-fixes[2].css 26185 m..b r/rr-xr-xr-x 0 0 11196-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/index[1].css 27240 m..b r/rr-xr-xr-x 0 0 11197-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/ga[2].js 33316 m..b r/rr-xr-xr-x 0 0 11199-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/shows[2].css 98741 m..b r/rr-xr-xr-x 0 0 11200-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/showPage[2].js Fri Jul 01 2011 14:54:35 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/0d2/554/0d255467a252a80c4e44f87bf228b2b2cad29ad9.jpg?url=http://origin.psstatic.podshow.com/images/shows/15992/episodes/279595/large/gamesweaseltv-us-e.jpg?r=1304703565&width=200&height=112&scheme=1 cache stored in: QJM5KT6J/0d255467a252a80c4e44f87bf228b2b2cad29ad9[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 7359 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/117/3f0/1173f0fb86d4e0fa2148c92cb6c7898b68e2f916.jpg?url=http://origin.psstatic.podshow.com/images/shows/15992/episodes/285148/large/gamesweaseltv-us-e.jpg?r=1308320145&width=200&height=112&scheme=1 cache stored in: YZCXGNW1/1173f0fb86d4e0fa2148c92cb6c7898b68e2f916[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 14531 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/28e/548/28e5489a6f7966d376209edd2e82a806c2abede1.jpg?url=http://origin.psstatic.podshow.com/images/shows/15992/episodes/269414/large/gamesweaseltv-us-e.jpg?r=1297964744&width=200&height=112&scheme=1 cache stored in: SLK18LSF/28e5489a6f7966d376209edd2e82a806c2abede1[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 7633 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/508/349/508349bb8d62027f2ec24c38724f2a1d940e3ac7.jpg?url=http://origin.psstatic.podshow.com/images/shows/15992/episodes/283402/large/gamesweaseltv-us-e.jpg?r=1307648820&width=200&height=112&scheme=1 cache stored in: SLK18LSF/508349bb8d62027f2ec24c38724f2a1d940e3ac7[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 6794 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/665/e57/665e57985dc43681a574bfcaee3a040978cd2d70.jpg?url=http://origin.psstatic.podshow.com/images/shows/15992/episodes/281481/large/gamesweaseltv-us-e.jpg?r=1306127545&width=200&height=112&scheme=1 cache stored in: SLK18LSF/665e57985dc43681a574bfcaee3a040978cd2d70[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 6370 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/9eb/89a/9eb89aef14a82357f61e8401668b2852b67e396c.jpg?url=http://origin.psstatic.podshow.com/images/shows/15992/episodes/276808/large/gamesweaseltv-us-e.jpg?r=1302889247&width=200&height=112&scheme=1 cache stored in: QJM5KT6J/9eb89aef14a82357f61e8401668b2852b67e396c[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 7751 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/abe/506/abe506872146a572ec53fc224421b675ec50c012.jpg?url=http://origin.psstatic.podshow.com/images/shows/15992/episodes/266842/large/gamesweaseltv-us-e.jpg?r=1297792699&width=200&height=112&scheme=1 cache stored in: QJM5KT6J/abe506872146a572ec53fc224421b675ec50c012[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 5851 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/b39/4b4/b394b4b644845918dfc3e6ea48d027c5553da117.jpg?url=http://origin.psstatic.podshow.com/images/shows/15992/episodes/271549/large/gamesweaseltv-us-e.jpg?r=1299259763&width=200&height=112&scheme=1 cache stored in: SLK18LSF/b394b4b644845918dfc3e6ea48d027c5553da117[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 7338 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/b6b/075/b6b07589d76c009b1371fbf5d33c8bca2ff4b0dd.jpg?url=http://origin.psstatic.podshow.com/images/shows/15992/episodes/273494/large/gamesweaseltv-us-e.jpg?r=1300725657&width=200&height=112&scheme=1 cache stored in: UPQVMROL/b6b07589d76c009b1371fbf5d33c8bca2ff4b0dd[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 6229 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/c5f/e9f/c5fe9f22653f73f12988a9604d85a763cfa6eef3.jpg?url=http://origin.psstatic.podshow.com/images/shows/15992/episodes/286643/large/gamesweaseltv-us-e.jpg?r=1309448670&width=200&height=112&scheme=1 cache stored in: YZCXGNW1/c5fe9f22653f73f12988a9604d85a763cfa6eef3[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 13932 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/eba/76b/eba76b89c2f2775d6f84bc382cb194af7e4e8fbc.jpg?url=http://origin.psstatic.podshow.com/images/shows/15992/episodes/275124/large/gamesweaseltv-us-e.jpg?r=1301936223&width=200&height=112&scheme=1 cache stored in: UPQVMROL/eba76b89c2f2775d6f84bc382cb194af7e4e8fbc[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 6019 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/442489/gallery/thumbs/218903.jpg cache stored in: UPQVMROL/218903[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3426 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/5825/gallery/thumbs/5028.jpg cache stored in: SLK18LSF/5028[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2856 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/7334/gallery/thumbs/4724.jpg cache stored in: UPQVMROL/4724[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3017 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 2132 m..b r/rr-xr-xr-x 0 0 11198-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/small-icons[1].png 999 m..b r/rr-xr-xr-x 0 0 11202-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/box-shadows[1].png 2680 m..b r/rr-xr-xr-x 0 0 11203-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/box-heading[1].png 11097 m..b r/rr-xr-xr-x 0 0 11204-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/logo-and-footer[1].jpg 610 m..b r/rr-xr-xr-x 0 0 11206-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/now-playing-bg[1].jpg 58767 m..b r/rr-xr-xr-x 0 0 11207-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/PromoRollV4[1].jpg 14531 ma.b r/rr-xr-xr-x 0 0 11208-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/1173f0fb86d4e0fa2148c92cb6c7898b68e2f916[1].jpg 13932 ma.b r/rr-xr-xr-x 0 0 11209-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/c5fe9f22653f73f12988a9604d85a763cfa6eef3[1].jpg 6370 ma.b r/rr-xr-xr-x 0 0 11210-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/665e57985dc43681a574bfcaee3a040978cd2d70[1].jpg 6794 ma.b r/rr-xr-xr-x 0 0 11211-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/508349bb8d62027f2ec24c38724f2a1d940e3ac7[1].jpg 7751 ma.b r/rr-xr-xr-x 0 0 11212-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/9eb89aef14a82357f61e8401668b2852b67e396c[1].jpg 7359 ma.b r/rr-xr-xr-x 0 0 11213-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/0d255467a252a80c4e44f87bf228b2b2cad29ad9[1].jpg 6019 ma.b r/rr-xr-xr-x 0 0 11215-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/eba76b89c2f2775d6f84bc382cb194af7e4e8fbc[1].jpg 6229 ma.b r/rr-xr-xr-x 0 0 11216-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/b6b07589d76c009b1371fbf5d33c8bca2ff4b0dd[1].jpg 7338 ma.b r/rr-xr-xr-x 0 0 11217-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/b394b4b644845918dfc3e6ea48d027c5553da117[1].jpg 7633 ma.b r/rr-xr-xr-x 0 0 11218-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/28e5489a6f7966d376209edd2e82a806c2abede1[1].jpg 5851 ma.b r/rr-xr-xr-x 0 0 11219-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/abe506872146a572ec53fc224421b675ec50c012[1].jpg 1222 m..b r/rr-xr-xr-x 0 0 11220-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/default[1].jpg 5130 m..b r/rr-xr-xr-x 0 0 11221-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/showicons[1].png 3017 ma.b r/rr-xr-xr-x 0 0 11222-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/4724[1].jpg 3426 ma.b r/rr-xr-xr-x 0 0 11223-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/218903[1].jpg 2705 m..b r/rr-xr-xr-x 0 0 11224-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/42861[1].jpg 2856 ma.b r/rr-xr-xr-x 0 0 11225-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/5028[1].jpg Fri Jul 01 2011 14:54:36 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://farm6.static.flickr.com/5152/5841633479_acf151e7f0_s.jpg cache stored in: QJM5KT6J/5841633479_acf151e7f0_s[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - Content-Length: 5397 - X-Cache: HIT from photocache603.flickr.gq1.yahoo.com - X-Cache-Lookup: HIT from photocache603.flickr.gq1.yahoo.com:83 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://farm6.static.flickr.com/5277/5883593413_6d272d0b28_s.jpg cache stored in: SLK18LSF/5883593413_6d272d0b28_s[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - Content-Length: 4461 - X-Cache: HIT from photocache609.flickr.gq1.yahoo.com - X-Cache-Lookup: HIT from photocache609.flickr.gq1.yahoo.com:83 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://farm6.static.flickr.com/5318/5887355857_5541eb46b6_m.jpg cache stored in: SLK18LSF/5887355857_5541eb46b6_m[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - Content-Length: 22492 - X-Cache: HIT from photocache602.flickr.gq1.yahoo.com - X-Cache-Lookup: HIT from photocache602.flickr.gq1.yahoo.com:83 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://farm7.static.flickr.com/6019/5887923130_547f50e74f_s.jpg cache stored in: QJM5KT6J/5887923130_547f50e74f_s[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - Content-Length: 19084 - X-Cache: HIT from photocache710.flickr.ne1.yahoo.com - X-Cache-Lookup: HIT from photocache710.flickr.ne1.yahoo.com:83 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://farm7.static.flickr.com/6051/5884517406_700a6f2e88_s.jpg cache stored in: QJM5KT6J/5884517406_700a6f2e88_s[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - Content-Length: 4084 - X-Cache: HIT from photocache701.flickr.ne1.yahoo.com - X-Cache-Lookup: HIT from photocache701.flickr.ne1.yahoo.com:83 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://gamesweasel.com/wp-content/themes/gamesweasel-10/images/Eastbay.png cache stored in: SLK18LSF/Eastbay[1].png - HTTP/1.1 200 OK - Content-Type: image/png - Content-Length: 20753 - X-Varnish: 1033994539 1033958766 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://gamesweasel.com/wp-content/themes/gamesweasel-10/images/Facebook.png cache stored in: QJM5KT6J/Facebook[1].png - HTTP/1.1 200 OK - Content-Type: image/png - Content-Length: 2303 - X-Varnish: 1033994574 1033959989 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://gamesweasel.com/wp-content/themes/gamesweasel-10/images/Footlocker.png cache stored in: UPQVMROL/Footlocker[1].png - HTTP/1.1 200 OK - Content-Type: image/png - Content-Length: 18385 - X-Varnish: 1033994559 1033959021 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://gamesweasel.com/wp-content/themes/gamesweasel-10/images/Twitter.png cache stored in: UPQVMROL/Twitter[1].png - HTTP/1.1 200 OK - Content-Type: image/png - Content-Length: 1906 - X-Varnish: 1033994580 1033959521 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://gamesweasel.com/wp-content/themes/gamesweasel-10/images/YouTube.png cache stored in: YZCXGNW1/YouTube[1].png - HTTP/1.1 200 OK - Content-Type: image/png - Content-Length: 2677 - X-Varnish: 1033994582 1033961743 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://gamesweasel.com/wp-content/themes/gamesweasel-10/images/Zazzle.png cache stored in: YZCXGNW1/Zazzle[1].png - HTTP/1.1 200 OK - Content-Type: image/png - Content-Length: 7165 - X-Varnish: 1033994550 1033959325 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://gamesweasel.com/wp-content/themes/gamesweasel-10/images/iTunes.png cache stored in: QJM5KT6J/iTunes[1].png - HTTP/1.1 200 OK - Content-Type: image/png - Content-Length: 4195 - X-Varnish: 1033994597 1033961726 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://gamesweasel.com/wp-content/themes/gamesweasel-10/images/rss.png cache stored in: SLK18LSF/rss[1].png - HTTP/1.1 200 OK - Content-Type: image/png - Content-Length: 2928 - X-Varnish: 1033994572 1033963195 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://gamesweasel.com/wp-content/themes/gamesweasel-10/images/showpage/About.png cache stored in: YZCXGNW1/About[1].png - HTTP/1.1 200 OK - Content-Type: image/png - Content-Length: 669 - X-Varnish: 1033994567 1033962366 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://gamesweasel.com/wp-content/themes/gamesweasel-10/images/showpage/Buy_Now.gif cache stored in: UPQVMROL/Buy_Now[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - Content-Length: 1704 - X-Varnish: 1033994521 1033954574 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://gamesweasel.com/wp-content/themes/gamesweasel-10/images/showpage/Latest_Reviews.png cache stored in: UPQVMROL/Latest_Reviews[1].png - HTTP/1.1 200 OK - Content-Type: image/png - Content-Length: 1042 - X-Varnish: 1033994503 1033966649 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://gamesweasel.com/wp-content/themes/gamesweasel-10/images/showpage/Matt_Cuttle.png cache stored in: QJM5KT6J/Matt_Cuttle[1].png - HTTP/1.1 200 OK - Content-Type: image/png - Content-Length: 70578 - X-Varnish: 1033994594 1033963225 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://gamesweasel.com/wp-content/themes/gamesweasel-10/images/showpage/News.png cache stored in: YZCXGNW1/News[1].png - HTTP/1.1 200 OK - Content-Type: image/png - Content-Length: 1477 - X-Varnish: 1033994560 1033963171 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://gamesweasel.com/wp-content/themes/gamesweasel-10/images/showpage/Offers.png cache stored in: UPQVMROL/Offers[1].png - HTTP/1.1 200 OK - Content-Type: image/png - Content-Length: 646 - X-Varnish: 1033994526 1033955930 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://gamesweasel.com/wp-content/themes/gamesweasel-10/images/showpage/s.png cache stored in: YZCXGNW1/s[1].png - HTTP/1.1 200 OK - Content-Type: image/png - Content-Length: 96 - X-Varnish: 1033994504 1033963203 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/15992/shows/thumbs/gamesweaseltv.jpg?r=1281038478 cache stored in: UPQVMROL/gamesweaseltv[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 4138 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/1016/gallery/thumbs/94614.jpg cache stored in: YZCXGNW1/94614[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3384 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/15071/gallery/thumbs/9433.jpg cache stored in: SLK18LSF/9433[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2301 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/159/gallery/thumbs/343.jpg cache stored in: UPQVMROL/343[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2737 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/1845/gallery/thumbs/3277.jpg cache stored in: SLK18LSF/3277[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2588 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/29968/gallery/thumbs/18465.jpg cache stored in: QJM5KT6J/18465[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3108 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/39460/gallery/med/29096.jpg cache stored in: QJM5KT6J/29096[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 17704 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/6058/gallery/thumbs/4176.jpg cache stored in: QJM5KT6J/4176[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2793 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/97/gallery/thumbs/34526.jpg cache stored in: QJM5KT6J/34526[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3598 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 3108 ma.b r/rr-xr-xr-x 0 0 11205-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/18465[1].jpg 2903 ma.b r/rr-xr-xr-x 0 0 11214-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/2510[1].jpg 2901 m..b r/rr-xr-xr-x 0 0 11226-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/4197dfa1f28d2d77f56f6f8e1eb334e36a0bd5a6[1].jpg 3471 m..b r/rr-xr-xr-x 0 0 11227-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/12129[1].jpg 2793 ma.b r/rr-xr-xr-x 0 0 11228-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/4176[1].jpg 1042 ma.b r/rr-xr-xr-x 0 0 11229-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/Latest_Reviews[1].png 2900 ma.b r/rr-xr-xr-x 0 0 11230-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/147123[1].jpg 96 ma.b r/rr-xr-xr-x 0 0 11231-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/s[1].png 4461 ma.b r/rr-xr-xr-x 0 0 11232-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/5883593413_6d272d0b28_s[1].jpg 22492 ma.b r/rr-xr-xr-x 0 0 11233-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/5887355857_5541eb46b6_m[1].jpg 2301 ma.b r/rr-xr-xr-x 0 0 11234-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/9433[1].jpg 4084 ma.b r/rr-xr-xr-x 0 0 11235-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/5884517406_700a6f2e88_s[1].jpg 19084 ma.b r/rr-xr-xr-x 0 0 11236-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/5887923130_547f50e74f_s[1].jpg 3598 ma.b r/rr-xr-xr-x 0 0 11237-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/34526[1].jpg 2737 ma.b r/rr-xr-xr-x 0 0 11241-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/343[1].jpg 5397 ma.b r/rr-xr-xr-x 0 0 11242-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/5841633479_acf151e7f0_s[1].jpg 3637 m..b r/rr-xr-xr-x 0 0 11243-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/277295[1].jpg 1704 ma.b r/rr-xr-xr-x 0 0 11244-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/Buy_Now[1].gif 2931 m..b r/rr-xr-xr-x 0 0 11245-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/2372[1].jpg 3384 ma.b r/rr-xr-xr-x 0 0 11246-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/94614[1].jpg 646 ma.b r/rr-xr-xr-x 0 0 11247-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/Offers[1].png 9295 m..b r/rr-xr-xr-x 0 0 11248-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/3831[1].png 20753 ma.b r/rr-xr-xr-x 0 0 11249-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/Eastbay[1].png 4138 ma.b r/rr-xr-xr-x 0 0 11250-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/gamesweaseltv[1].jpg 7165 ma.b r/rr-xr-xr-x 0 0 11251-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/Zazzle[1].png 17704 ma.b r/rr-xr-xr-x 0 0 11252-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/29096[1].jpg 18385 ma.b r/rr-xr-xr-x 0 0 11254-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/Footlocker[1].png 7011 m..b r/rr-xr-xr-x 0 0 11255-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/hotoff-us-e[1].jpg 1477 ma.b r/rr-xr-xr-x 0 0 11256-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/News[1].png 794 m..b r/rr-xr-xr-x 0 0 11257-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/joinNow25high[1].gif 669 ma.b r/rr-xr-xr-x 0 0 11259-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/About[1].png 2928 ma.b r/rr-xr-xr-x 0 0 11261-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/rss[1].png 2303 ma.b r/rr-xr-xr-x 0 0 11262-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/Facebook[1].png 1906 ma.b r/rr-xr-xr-x 0 0 11263-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/Twitter[1].png 2677 ma.b r/rr-xr-xr-x 0 0 11264-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/YouTube[1].png 2588 ma.b r/rr-xr-xr-x 0 0 11265-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/3277[1].jpg 70578 ma.b r/rr-xr-xr-x 0 0 11266-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/Matt_Cuttle[1].png 4195 ma.b r/rr-xr-xr-x 0 0 11267-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/iTunes[1].png 78342 m..b r/rr-xr-xr-x 0 0 11268-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tpl_htdocs[1].js Fri Jul 01 2011 14:54:38 3447 m..b r/rr-xr-xr-x 0 0 11253-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/beacon[2].js 20356 m..b r/rr-xr-xr-x 0 0 11258-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/tpl_player[2].js 3493 m..b r/rr-xr-xr-x 0 0 11260-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tpl_comments[2].js 65677 m..b r/rr-xr-xr-x 0 0 11269-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/tpl_shows[2].js Fri Jul 01 2011 14:54:39 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:gamesweaseltv.mevio.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 950 m..b r/rr-xr-xr-x 0 0 11272-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/dropdown-arrows[2].png 337 ma.. r/rr-xr-xr-x 0 0 11274-128-1 /Documents and Settings/malware/Cookies/malware@gamesweaseltv.mevio[1].txt 295610 ...b r/rr-xr-xr-x 0 0 11275-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/MevioBPFX[1].swf 3320 m..b r/rr-xr-xr-x 0 0 6834-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/mevio-m-neverback-24x24[1].gif Fri Jul 01 2011 14:54:40 665 m..b r/rr-xr-xr-x 0 0 11192-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/client_restserver[1].htm 295610 ma.. r/rr-xr-xr-x 0 0 11275-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/MevioBPFX[1].swf 3681 m..b r/rr-xr-xr-x 0 0 11279-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/player-icons[2].png Fri Jul 01 2011 14:54:41 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.facebook.com/extern/login_status.php?api_key=c99345b4de38e993c64ef4654ac9164b&extern=0&channel=http://gamesweaseltv.mevio.com/rest/facebook/xd_receiver.php&locale=en_US cache stored in: UPQVMROL/login_status[1].htm - HTTP/1.1 200 OK - Content-Length: 1207 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 1207 ma.b r/rr-xr-xr-x 0 0 11280-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/login_status[1].htm Fri Jul 01 2011 14:54:42 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://gamesweaseltv.mevio.com/rest/facebook/xd_receiver.php cache stored in: YZCXGNW1/xd_receiver[1].htm - HTTP/1.1 200 OK - Content-Length: 591 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 591 ma.b r/rr-xr-xr-x 0 0 11284-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/xd_receiver[1].htm 3386 m..b r/rr-xr-xr-x 0 0 11286-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/XdCommReceiver[2].js Fri Jul 01 2011 14:54:43 0 .acb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:quantserve.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 4575 ma.b r/rr-xr-xr-x 0 0 11287-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26270-2[1].js 92 m..b r/rr-xr-xr-x 0 0 11289-128-1 /Documents and Settings/malware/Cookies/malware@quantserve[1].txt Fri Jul 01 2011 14:54:44 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adi/N5271.159469.AOD-INVITE/B5501350.4_sz=728x90_pc=[TPAS_ID]_click=http://g.ca.bid.invitemedia.com/pixel?returnType=redirect&key=Click&message=eJwVjDsOxCAQQ68STR0khvlBbrOEUEXbpYr27msqvyfZfkmEjq3V4rJvJAXiql4ZxhDqXsXnPNMZ0pJmk_SJPtK8Rumah1W5aE1XuYVwLFs_DWlI7AKowO9z30AHspVs_PsDBqUbsQ--&redirectURL=_ord=b6836ffc-c739-4053-a7bd-fed2b40d583e? cache stored in: YZCXGNW1/pixel[1].htm - HTTP/1.1 200 OK - Content-Length: 6857 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://g-pixel.invitemedia.com/gmatcher?id=E0 cache stored in: QJM5KT6J/gmatcher[1].gif - HTTP/1.0 200 OK - P3P: policyref="/w3c/p3p.xml"- CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC" - Content-Type: image/gif - Pragma: no-cache - Content-Length: 43 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://r.nexac.com/e/getdata.xgi?dt=fi&fn=adrider&pkey=tubw72p3ncbzv&repequal=-&reppipe=&code= cache stored in: YZCXGNW1/getdata[1].xgi - HTTP/1.1 200 OK - Transfer-Encoding: chunked - Pragma: no-cache - P3P: policyref="http://www.nextaction.net/P3P/PolicyReferences.xml"- CP="NOI DSP COR NID CURa ADMa DEVa TAIo PSAo PSDo HISa OUR DELa SAMo UNRo OTRo BUS UNI PUR COM NAV INT DEM STA PRE" - X-Powered-By: Jigawatts - Content-type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 .acb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:tap2-cdn.rubiconproject.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 43 ma.b r/rr-xr-xr-x 0 0 11290-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/gmatcher[1].gif 6621 m..b r/rr-xr-xr-x 0 0 11297-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/emily[1].htm 6857 ma.b r/rr-xr-xr-x 0 0 11298-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/pixel[1].htm 297 m..b r/rr-xr-xr-x 0 0 11303-128-1 /Documents and Settings/malware/Cookies/malware@tap2-cdn.rubiconproject[1].txt 801 m..b r/rr-xr-xr-x 0 0 11304-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/flashwrite_1_2[2].js 12 ma.b r/rr-xr-xr-x 0 0 11310-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/getdata[1].xgi Fri Jul 01 2011 14:54:45 2205 ma.b r/rr-xr-xr-x 0 0 11306-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/26271-15[1].js 2310 m..b r/rr-xr-xr-x 0 0 11314-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/26271-2[1].js 15168 m..b r/rr-xr-xr-x 0 0 11315-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/aceUAC[1].js Fri Jul 01 2011 14:54:46 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.turn.com/server/bid/fan.bid?pub=10063193&cch=10063206&l=728x90&requestId=C1Bf9Po4Ws7K.b2Bf9Po4Ws7K&ref=http://fan-ugc-foxaudiencenetwork.com&rand=1309557286359 cache stored in: YZCXGNW1/fan[1].bid - HTTP/1.1 200 OK - Content-Type: application/json - Content-Length: 1060 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:yahoo.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 2234 m..b r/rr-xr-xr-x 0 0 11293-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26270-2[2].js 2008 m..b r/rr-xr-xr-x 0 0 11294-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-15[1].js 2008 m..b r/rr-xr-xr-x 0 0 11308-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-2[1].js 2310 .a.. r/rr-xr-xr-x 0 0 11314-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/26271-2[1].js 7951 ma.b r/rr-xr-xr-x 0 0 11316-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/adopt[1].htm 83 ma.b r/rr-xr-xr-x 0 0 11318-128-1 /Documents and Settings/malware/Cookies/malware@yahoo[1].txt 688 ma.b r/rr-xr-xr-x 0 0 11320-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/imp[1] 1060 ma.b r/rr-xr-xr-x 0 0 11323-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/fan[1].bid 9359 ...b r/rrwxrwxrwx 0 0 11990-128-4 /Documents and Settings/malware/Cookies/malware@adnxs[1].txt Fri Jul 01 2011 14:54:47 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/N5914.126262.AOLPERFORMANCENETWO/B5640868.3_sz=728x90_click=http://r1-ads.ace.advertising.com/click/site=0000795578/mnum=0001040606/cstr=26399007=_4e0e4204-8870257073-795578^1040606^1183^0-1_/xsxdata=$xsxdata/bnum=26399007/optn=64?trg=_ord=8870257073? cache stored in: QJM5KT6J/optn=64[2] - HTTP/1.1 200 OK - Content-Length: 6190 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://s0.2mdn.net/2660564/CNTL11-578_Q2_DRAboutYou_FreeActivation_728x90.jpg cache stored in: UPQVMROL/CNTL11-578_Q2_DRAboutYou_FreeActivation_728x90[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Content-Type-Options: nosniff - Content-Length: 39725 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) User: http://network.realmedia.com/RealMedia/ads/adstream_jx.ads/mevio/ros/728x90/jx/ss/a/1879480817 URL:Top1 cache stored in: YZCXGNW1/1879480817@Top1[1] - HTTP/1.1 200 OK - P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA"-policyref="/w3c/p3p.xml" - Content-Length: 687 - Keep-Alive: timeout=60 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 2234 .a.. r/rr-xr-xr-x 0 0 11293-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26270-2[2].js 2008 .a.. r/rr-xr-xr-x 0 0 11294-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-15[1].js 2008 .a.. r/rr-xr-xr-x 0 0 11308-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-2[1].js 684 ma.b r/rr-xr-xr-x 0 0 11317-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/imp[1] 39725 ma.b r/rr-xr-xr-x 0 0 11319-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CNTL11-578_Q2_DRAboutYou_FreeActivation_728x90[1].jpg 6190 ma.b r/rr-xr-xr-x 0 0 11322-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/optn=64[2] 607 ma.b r/rr-xr-xr-x 0 0 11325-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/dref=http%3A%2F%2Fgamesweasel[2].com%2F%3Futm_campaign%3D088aeb_572913_263890_113320_150752_23411%26utm_source%3D088aebc%26utm_medium%3D088aeb 687 ma.b r/rr-xr-xr-x 0 0 11330-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/1879480817@Top1[1] 2030 ma.b r/rr-xr-xr-x 0 0 11336-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/dk[1].js 12576 m..b r/rr-xr-xr-x 0 0 11339-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/tags[2].js 60 m..b r/rr-xr-xr-x 0 0 11342-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/displayAd[2].js 166 ...b r/rr-xr-xr-x 0 0 11505-128-1 /Documents and Settings/malware/Cookies/malware@realmedia[1].txt 434176 .a.. r/rr-xr-xr-x 0 0 3142-128-3 /WINDOWS/system32/vbscript.dll Fri Jul 01 2011 14:54:48 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://adadvisor.net/adscores/g.js?sid=9239766368 cache stored in: QJM5KT6J/g[1].js - HTTP/1.1 200 OK - P3P: policyref="http://www.adadvisor.net/w3c/p3p.xml"-CP="NOI NID" - Content-Length: 271 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cdn5.tribalfusion.com/media/2516896//frm.html cache stored in: YZCXGNW1/frm[1].htm - HTTP/1.1 200 OK - Content-Length: 1378 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://tags.expo9.exponential.com/tags/Targus/ROS/tags.js cache stored in: UPQVMROL/tags[2].js - HTTP/1.1 200 OK - Content-Length: 12575 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://tf.nexac.com/media/1809966/na.html cache stored in: QJM5KT6J/na[1].htm - HTTP/1.1 200 OK - P3P: CP="NOI DEVo TAIa OUR BUS" - X-Function: 301 - Content-Type: text/html - Content-Length: 762 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:imrworldwide.com/cgi-bin (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 ma.b r/rr-xr-xr-x 0 0 11296-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CAIFOHQD.ad 1332 ma.b r/rr-xr-xr-x 0 0 11345-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/CAO3Q5OT.ad 1378 ma.b r/rr-xr-xr-x 0 0 11350-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/frm[1].htm 762 ma.b r/rr-xr-xr-x 0 0 11351-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/na[1].htm 45 ma.b r/rr-xr-xr-x 0 0 11353-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/rd[1] 271 ma.b r/rr-xr-xr-x 0 0 11354-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/g[1].js 12575 ma.b r/rr-xr-xr-x 0 0 11355-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tags[2].js 2572 ma.b r/rr-xr-xr-x 0 0 11356-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CAFJPXKE.htm 214 ma.b r/rr-xr-xr-x 0 0 11357-128-1 /Documents and Settings/malware/Cookies/malware@cgi-bin[2].txt 32284 m..b r/rr-xr-xr-x 0 0 11359-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/118ed178-986a-4c57-9d20-0870639fdad0[1].jpg 24385 m..b r/rr-xr-xr-x 0 0 11360-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/StdBanner[2].js 7905 m..b r/rr-xr-xr-x 0 0 11365-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tracking_only[2].js Fri Jul 01 2011 14:54:49 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cheetah.vizu.com/a.gif?cid=2073_adid=728x90_siteid=tribalfusion_adtype=1_stype=0_siteurl=a.tribalfusion.com_wc=_cust1=_cust2=_cust3=_cust4=_cust5=_ver=v5_o=winxp_ua=msie_uv=6.0_lan=en-us_fv=null_id=1309557288828_t=1309557288843 cache stored in: SLK18LSF/a[1].gif - HTTP/1.1 200 OK - X-Px: ht lax-am6-n10.panthercdn.com - ETag: "3c04c-2b-edb95b80" - Content-Length: 43 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cheetah.vizu.com/f.gif?cd=4_cid=2073_adid=728x90_siteid=tribalfusion_adtype=1_stype=0_siteurl=a.tribalfusion.com_wc=_cust1=_cust2=_cust3=_cust4=_cust5=_ver=v5_o=winxp_ua=msie_uv=6.0_lan=en-us_fv=null_id=1309557288828_t=1309557288843f.gif?cid=2073_adid=728x90_siteid=tribalfusion_adtype=1_stype=0_siteurl=a.tribalfusion.com_wc=_cust1=_cust2=_cust3=_cust4=_cust5=_ver=v5_o=winxp_ua=msie_uv=6.0_lan=en-us_fv=null_id=1309557288828_t=1309557288843 cache stored in: YZCXGNW1/CAS5SJW3.gif - HTTP/1.1 200 OK - X-Px: ht lax-am6-n10.panthercdn.com - ETag: "3c050-2b-edb95b80" - Content-Length: 43 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cheetah.vizu.com/i.gif?cid=2073_adid=728x90_siteid=tribalfusion_adtype=1_stype=0_siteurl=a.tribalfusion.com_wc=_cust1=_cust2=_cust3=_cust4=_cust5=_ver=v5_o=winxp_ua=msie_uv=6.0_lan=en-us_fv=null_id=1309557288828_t=1309557288843 cache stored in: QJM5KT6J/i[1].gif - HTTP/1.1 200 OK - X-Px: ht lax-am6-n10.panthercdn.com - ETag: "3c051-2b-775728c0" - Content-Length: 43 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) User: http://b3.mookie1.com/2/B3DM/DLX/1 URL:x71 cache stored in: QJM5KT6J/1@x71[1].htm - HTTP/1.1 200 OK - P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA"-policyref="/w3c/p3p.xml" - Content-Length: 1423 - Keep-Alive: timeout=60 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) User: http://b3.mookie1.com/2/TribalFusionB3/Motorola/2011Q2_Atrix/CN/728/11217442856 URL:x90 cache stored in: YZCXGNW1/11217442856@x90[1].htm - HTTP/1.1 200 OK - P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA"-policyref="/w3c/p3p.xml" - Content-Length: 519 - Keep-Alive: timeout=60 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) User: http://dm.de.mookie1.com/2/B3DM/2010DM/1730591662 URL:x23?USNetwork/Moto_2011Q2_Atrix_TF_CN_728 cache stored in: SLK18LSF/1730591662@x23[1].htm - HTTP/1.1 200 OK - P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA"-policyref="/w3c/p3p.xml" - Content-Length: 2421 - Keep-Alive: timeout=60 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) User: http://mig.nexac.com/2/B3DM/DLX/1 URL:x96 cache stored in: UPQVMROL/1@x96[1].htm - HTTP/1.1 200 OK - P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA"-policyref="/w3c/p3p.xml" - Content-Length: 1391 - Keep-Alive: timeout=60 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 .acb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:nexac.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 1391 ma.b r/rr-xr-xr-x 0 0 11309-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/1@x96[1].htm 43 ma.b r/rr-xr-xr-x 0 0 11362-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CAS5SJW3.gif 43 ma.b r/rr-xr-xr-x 0 0 11366-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/a[1].gif 43 ma.b r/rr-xr-xr-x 0 0 11367-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/i[1].gif 519 ma.b r/rr-xr-xr-x 0 0 11368-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/11217442856@x90[1].htm 2421 ma.b r/rr-xr-xr-x 0 0 11370-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/1730591662@x23[1].htm 1423 ma.b r/rr-xr-xr-x 0 0 11371-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/1@x71[1].htm 144 ma.b r/rr-xr-xr-x 0 0 11372-128-1 /Documents and Settings/malware/Cookies/malware@nexac[2].txt Fri Jul 01 2011 14:54:50 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://su.addthis.com/red/usync?pid=2&puid=422217505559544-xrDlCk4OQgUADp2C cache stored in: QJM5KT6J/usync[1].png - HTTP/1.1 200 OK - P3P: policyref="/w3c/p3p.xml"- CP="NON ADM OUR DEV IND COM STA" - Content-Type: image/png - Content-Length: 67 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) User: http://dm.de.mookie1.com/2/B3DM/DLX/ URL:x94 cache stored in: YZCXGNW1/@x94[1].htm - HTTP/1.1 200 OK - P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA"-policyref="/w3c/p3p.xml" - Content-Length: 666 - Keep-Alive: timeout=60 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) User: http://premium.mookie1.com/2/PAM_DM/2011Generic URL:Bottom3 cache stored in: SLK18LSF/2011Generic@Bottom3[1].htm - HTTP/1.1 200 OK - P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA"-policyref="/w3c/p3p.xml" - Content-Length: 77 - Keep-Alive: timeout=60 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:addthis.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 666 ma.b r/rr-xr-xr-x 0 0 11373-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/@x94[1].htm 77 ma.b r/rr-xr-xr-x 0 0 11374-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/2011Generic@Bottom3[1].htm 122 ma.b r/rr-xr-xr-x 0 0 11375-128-1 /Documents and Settings/malware/Cookies/malware@addthis[1].txt 67 ma.b r/rr-xr-xr-x 0 0 11376-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/usync[1].png 177 ...b r/rr-xr-xr-x 0 0 11378-128-1 /Documents and Settings/malware/Cookies/malware@contextweb[2].txt Fri Jul 01 2011 14:54:51 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:contextweb.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 177 ma.. r/rr-xr-xr-x 0 0 11378-128-1 /Documents and Settings/malware/Cookies/malware@contextweb[2].txt 0 macb 0 0 0 5544 [WMIprov Log file] (Time Written) Entry in log file: WDM call returned error: 4200 (file: /media/sdb1/WINDOWS/system32/wbem/Logs/wmiprov.log) 1004 ma.. r/rr-xr-xr-x 0 0 5544-128-3 /WINDOWS/system32/wbem/Logs/wmiprov.log Fri Jul 01 2011 14:55:15 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/262/fa4/262fa4472ddaa4727cbc48ac93bd48d4800bf0ed.jpg?url=http://origin.psstatic.podshow.com/images/shows/21273/episodes/285822/large/itcouldbeworse-us-e.jpg?r=1308841571&width=200&height=112&scheme=1 cache stored in: SLK18LSF/262fa4472ddaa4727cbc48ac93bd48d4800bf0ed[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 26741 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/47a/c16/47ac163b368a40b309220a8ae16626c1874f24e6.jpg?url=http://origin.psstatic.podshow.com/images/shows/19008/episodes/237946/large/okinsider-us-e.jpg?r=1279595181&width=200&height=112&scheme=1 cache stored in: UPQVMROL/47ac163b368a40b309220a8ae16626c1874f24e6[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 10803 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/bcf/8b2/bcf8b2846ded8223ba1a5e2b0b3867956aa61201.jpg?url=http://origin.psstatic.podshow.com/images/shows/26298/episodes/248763/large/pop17-us-e.jpg?r=1284498840&width=200&height=112&scheme=1 cache stored in: SLK18LSF/bcf8b2846ded8223ba1a5e2b0b3867956aa61201[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 10772 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/bed/f96/bedf96242983dac037168b9a38c6c2710ff91108.jpg?url=http://origin.psstatic.podshow.com/images/shows/23974/episodes/286738/large/reformschool-us-e.jpg?r=1309473395&width=200&height=112&scheme=1 cache stored in: YZCXGNW1/bedf96242983dac037168b9a38c6c2710ff91108[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 12452 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/869922/channels/small/890024.jpg?r=38841 cache stored in: UPQVMROL/890024[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 7811 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/869922/gallery/thumbs/279738.jpg?r=38841 cache stored in: UPQVMROL/279738[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 1560 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://www.mevio.com/channels/?cId=890024 (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 18839 ma.b r/rr-xr-xr-x 0 0 11191-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/channels[1].css 10803 ma.b r/rr-xr-xr-x 0 0 11283-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/47ac163b368a40b309220a8ae16626c1874f24e6[1].jpg 307 ...b r/rr-xr-xr-x 0 0 11285-128-1 /Documents and Settings/malware/Cookies/malware@www.mevio[1].txt 7811 ma.b r/rr-xr-xr-x 0 0 11292-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/890024[1].jpg 1560 ma.b r/rr-xr-xr-x 0 0 11312-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/279738[1].jpg 26741 ma.b r/rr-xr-xr-x 0 0 11338-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/262fa4472ddaa4727cbc48ac93bd48d4800bf0ed[1].jpg 10772 ma.b r/rr-xr-xr-x 0 0 11346-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/bcf8b2846ded8223ba1a5e2b0b3867956aa61201[1].jpg 2132 ma.b r/rr-xr-xr-x 0 0 11347-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/actionBar[1].png 435 ma.b r/rr-xr-xr-x 0 0 11348-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/play-trans[1].png 23216 ma.b r/rr-xr-xr-x 0 0 11349-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/default[2].jpg 12452 ma.b r/rr-xr-xr-x 0 0 11379-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/bedf96242983dac037168b9a38c6c2710ff91108[1].jpg 11533 ...b r/rr-xr-xr-x 0 0 11382-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/8ef336c6e2b72b5c3a6bf5fc573ca5f798cb4e98[1].jpg 7834 ma.b r/rr-xr-xr-x 0 0 11384-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/tpl_channels[2].js 40014 ...b r/rr-xr-xr-x 0 0 11385-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/a4b6dbea7c7d1ad5affc22280b968759abac5fe8[1].png Fri Jul 01 2011 14:55:16 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/380/686/380686a9e245b6c9588ee47a4374fa8c6aeaf28d.jpg?url=http://origin.thumbs.mevio.com/media/23473/episodes/246022/thumbnail.jpg&width=200&height=112&scheme=1 cache stored in: QJM5KT6J/380686a9e245b6c9588ee47a4374fa8c6aeaf28d[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 4649 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/576/17b/57617b115751f9587dfd6e7c97e652757d9a158f.png?url=http://origin.psstatic.podshow.com/images/shows/21754/episodes/233419/large/hairbangersball-us-e.png?r=1274996283&width=200&height=112&scheme=1 cache stored in: UPQVMROL/57617b115751f9587dfd6e7c97e652757d9a158f[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 43391 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/5ab/272/5ab27290d55e31c8cdf1ccd41a1df4466760db63.jpg?url=http://origin.psstatic.podshow.com/images/shows/23436/episodes/234509/large/theradreport-us-e.jpg?r=1275681955&width=200&height=112&scheme=1 cache stored in: UPQVMROL/5ab27290d55e31c8cdf1ccd41a1df4466760db63[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 7424 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/8ef/336/8ef336c6e2b72b5c3a6bf5fc573ca5f798cb4e98.jpg?url=http://origin.psstatic.podshow.com/images/shows/26453/episodes/252363/large/alist-us-e.jpg?r=1286490665&width=200&height=112&scheme=1 cache stored in: QJM5KT6J/8ef336c6e2b72b5c3a6bf5fc573ca5f798cb4e98[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 11533 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/a4b/6db/a4b6dbea7c7d1ad5affc22280b968759abac5fe8.png?url=http://origin.psstatic.podshow.com/images/shows/22243/episodes/198494/large/emogirltv-us-e.png?r=1258745063&width=200&height=112&scheme=1 cache stored in: QJM5KT6J/a4b6dbea7c7d1ad5affc22280b968759abac5fe8[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 40014 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 .acb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:www.mevio.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 7424 ma.b r/rr-xr-xr-x 0 0 11277-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/5ab27290d55e31c8cdf1ccd41a1df4466760db63[1].jpg 307 ma.. r/rr-xr-xr-x 0 0 11285-128-1 /Documents and Settings/malware/Cookies/malware@www.mevio[1].txt 11533 ma.. r/rr-xr-xr-x 0 0 11382-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/8ef336c6e2b72b5c3a6bf5fc573ca5f798cb4e98[1].jpg 4649 ma.b r/rr-xr-xr-x 0 0 11383-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/380686a9e245b6c9588ee47a4374fa8c6aeaf28d[1].jpg 40014 ma.. r/rr-xr-xr-x 0 0 11385-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/a4b6dbea7c7d1ad5affc22280b968759abac5fe8[1].png 43391 ma.b r/rr-xr-xr-x 0 0 11386-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/57617b115751f9587dfd6e7c97e652757d9a158f[1].png Fri Jul 01 2011 14:55:17 1107 ...b r/rrwxrwxrwx 0 0 11324-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/login_status[1].htm 1023 ma.b r/rr-xr-xr-x 0 0 11389-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/ctrl-vert-scroll[1].png Fri Jul 01 2011 14:55:22 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) User: http://network.realmedia.com/RealMedia/ads/adstream_jx.ads/mevio/ros/728x90/jx/ss/a/1240890821 URL:Top1 cache stored in: SLK18LSF/1240890821@Top1[1] - HTTP/1.1 200 OK - P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA"-policyref="/w3c/p3p.xml" - Content-Length: 687 - Keep-Alive: timeout=60 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 687 m..b r/rr-xr-xr-x 0 0 11329-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/1240890821@Top1[1] 2234 ma.b r/rr-xr-xr-x 0 0 11393-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26317-2[1].js Fri Jul 01 2011 14:55:23 1201 ma.b r/rr-xr-xr-x 0 0 11313-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/adopt[1].htm 687 .a.. r/rr-xr-xr-x 0 0 11329-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/1240890821@Top1[1] 430 ...b r/rr-xr-xr-x 0 0 11337-128-1 /Documents and Settings/malware/Cookies/malware@serving-sys[1].txt 2322 ma.b r/rr-xr-xr-x 0 0 11344-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/26318-2[1].js 2952 ma.b r/rr-xr-xr-x 0 0 11352-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/CASPE981.htm 2030 ma.b r/rr-xr-xr-x 0 0 11395-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/dk[1].js 684 ma.b r/rr-xr-xr-x 0 0 11398-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/imp[1] 688 ma.b r/rr-xr-xr-x 0 0 11399-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/imp[1] 4348 m..b r/rr-xr-xr-x 0 0 11402-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/fp[1].js Fri Jul 01 2011 14:55:24 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://log30.doubleverify.com/visitor.aspx?query=agnc=796803&cmp=947466&crt=&crtname=&adnet=&dvtagver=3.3.1346.2176&adsrv=6&plc=2895815&advid=796804&sid=Fox%20Audience%20Network&adid=&&num=201&srcurl=http://www.mevio.com/channels/?cId=890024&random=0.5607829497620708 cache stored in: QJM5KT6J/CAA2739W.jpg - HTTP/1.1 200 OK - Content-Length: 0 - Content-Type: image/jpeg - X-AspNet-Version: 2.0.50727 - X-Powered-By: ASP.NET (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 38604 m..b r/rr-xr-xr-x 0 0 11397-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/785e48fd-311d-4f0e-be8f-e511ecfdeeb9[1].jpg 24385 m..b r/rr-xr-xr-x 0 0 11404-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/StdBanner[2].js 2914 m..b r/rr-xr-xr-x 0 0 11405-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/script201[2].js 0 ma.b r/rr-xr-xr-x 0 0 11406-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/CAA2739W.jpg Fri Jul 01 2011 14:56:26 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://www.mevio.com/episode/237946/lilo-rocks-up-10-hours-late-okinsiderepisode74 (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) Fri Jul 01 2011 14:56:27 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/11/shows/thumbs/lifespring.jpg?r=1138742130 cache stored in: YZCXGNW1/lifespring[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 4578 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/1530/shows/thumbs/atc.jpg?r=1156305678 cache stored in: UPQVMROL/atc[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 1964 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/4561/shows/thumbs/scrapcast.jpg?r=1165957395 cache stored in: QJM5KT6J/scrapcast[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3616 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 1964 ma.b r/rr-xr-xr-x 0 0 11380-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/atc[1].jpg 4578 ma.b r/rr-xr-xr-x 0 0 11381-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/lifespring[1].jpg 1039 ma.b r/rr-xr-xr-x 0 0 11388-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/success-checkmark[1].png 3616 ma.b r/rr-xr-xr-x 0 0 11410-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/scrapcast[1].jpg 398372 .a.. r/rr-xr-xr-x 0 0 2188-128-3 /WINDOWS/Fonts/timesbd.ttf Fri Jul 01 2011 14:56:28 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://www.findfertile.org/go.php?userip=198.176.229.10&referer=http://www.findfertile.org/search.php?q=book&aid=531&sid=direc20&curl=http://64.111.211.158/c.php?s=eNollMeuq0gQhh_I0oHuJjSLuwBzyNFg0mZEzmBjGxvEw4_vjH5VUNW_KZX0dQdEFAAHpvBh-ebHCC-3fAw6s-P_HOQPSdL0_4U5IAkAyX4TS9MIH_HIren7z5-DTmmGRQzJsBiyAJI5Zqi8RHRWpDmqKvqfAqIUMxmCJAZZSqUMk9IVB6via8dpjg_4VWnNVt-V3kzyPC8Rv8ZD22W3c2I1cHTjnUyCeF4rCrK6t9SQQVk1oRNYgw0T5DsitmX95BNDphV1o4kzONkpHSUvRctN8eFMcpuullVdxCtB6GNtNNIHZNpbnLKSXeG2A1qJ1HOQDdewLTqgVPdFoLFcFoaYJi_AmSed19Bp38LE04mnGwzSJ3IFeGGfO8y7Uve89fEbJ451W-LCWLP59fxsvhGvMrRFKs6RLu0F985r19Xju8AoiSDw4CaLdxkrzElkHB2Tly7qC29SiTYQowfSelHPoLVwoU0-gUgX9rCcxQhenFwuuTctMzanoW2pmBAO9MI4fMwjpK_qrMl3W6DHN05kdRRWOux0z6w7Vbb892SH-hhAZhS-D63b0tPdc8h57rmr-A7K4ENdNGYkncpeplrLrvNHODtL5KiJ_1peamraF8qJAm_wqlEoGX-I5Xv16bkhoyWhvLIwfzLm8yaXMOvhb_9RwGWk8FosJ-uKXuC5PazfZw6DM6HrYcdcf_eXH5UXVeXdKxdBNHMm1MqLU1_OtiLgbYHtqhlTda7DFLK3aXshSNgOTSgAjYPPozksb_rTivdcljixem-yv5HFqVbjnG66bPcUM1JPxEy6_PByejuezCiZA8pdlHK5tsONKNwlOBmUYZvOEmR3L7vyxB03DWrr5mT60-_Tb2YXciHvVk7bqDwPukJ6OCG73AXBBHwdVtZ5Bnrfk8pnH42HlKrBHr_hQ2iC9om968wodq2I_Pse75dANnRVpDopAJC4MrRjpQ83vpIUim6WocaZR62kdHeh4j27KMJD0NtZ3puq61kS6S8tyjLyMfVu3W5UHL87bgzvwSN0iWKs1NiIxspupF3K55yH_FsFYTrTZwvLrB-f5jhQxpGZkNU6JNffWdzgqDoZcbjUWuGbdyvhIFueVNg16OIOvOFrOwuCyfHV8uFiwk_7thnNoCmenSf4UUoykRTJ0d6uv2pr80vXNynbVNU8kiIq6daRRoJzX--rS9zuYTwNyqgXfdJnex2Pj-bm7qCgejN5kdRYBmrzvXU-cR-spb-YPwCHfwDL_EDI_QDyOACmfgD9DQb9AI46_o7AkY1Bk48fupCb4dujfKOfSZTcso3uMkh-WfafDnQUqEDG-N2MlzGJNDINP4Mxclvyl2UsYBGuvqzKMsxyRQnJlKO4FOUZpqoSUMeXdZjimCwHRYEZnP3FHEQYYTpl2RLhfwEYHbRi&aid=531&sid=direc20 (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) Fri Jul 01 2011 14:56:29 5325 ma.b r/rr-xr-xr-x 0 0 10318-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CA6RCHER.htm 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://search.chillcow.com/results/?partnerid=113320&appid=150752&subid=23411&ip=198.176.229.10&cid=264123&entry=book&qs=JQwDFAMXaSFTVkVLSUVaSRpYUURuW0sTAwFFeFpUS05EQFpcSFNAVTZUXV5cVBRzW0UWC01ER19fEhARdQofTVxLEHRdUkJfHhZUX0AREBBkW0scBQEdclZRR0xCR08LAUxASD1UBQQYFQV2D0ZAH1VGDwELQFNNKh0FFQIAVzZADhcPGRtHDAFMBBM1TxwFCRdZeFoGQhxERlxWX0BCQDZcD0APU0Z1CAUXXwEAVF5dERgUZl5eQ1tDSzJTER0XVhcCGFMHU0Q1VEsCAg4ddEgXAQoEFQ4GChwTFGNbVEheXAYiCwwGGBcdDVJcFBQUYk8YAgBYSDEaE1dKEVFbCUsTR082CB8cFRFIIAAGBQpeGQwZB04PQjwESEIKQBMjGxcfJhMVBB8PSEZPdloJQg1WEXMMPEdOQk1YXDETFxViW14vXVQTdlxTLUhFRF5aXH4TEmdYXFVeU1UxAzwBFgUGCgpLEkUTMlpcRg5AEnMbFx8mHRENBhtMBBI3WwxDXVNC cache stored in: UPQVMROL/CA6RCHER.htm - HTTP/1.1 200 OK - Content-Type: text/html_charset=ISO-8859-1 - Content-Length: 5325 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:bidsystem.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 97 ma.b r/rr-xr-xr-x 0 0 11403-128-1 /Documents and Settings/malware/Cookies/malware@bidsystem[2].txt Fri Jul 01 2011 14:56:30 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://click.mygeek.com/presults.jsp?partnerid=113320&appid=150752&subid=23411&ip=198.176.229.10&cid=264123&entry=book&qs=JQwDFAMXaSFTVkVLSUVaSRpYUURuW0sTAwFFeFpUS05EQFpcSFNAVTZUXV5cVBRzW0UWC01ER19fEhARdQofTVxLEHRdUkJfHhZUX0AREBBkW0scBQEdclZRR0xCR08LAUxASD1UBQQYFQV2D0ZAH1VGDwELQFNNKh0FFQIAVzZADhcPGRtHDAFMBBM1TxwFCRdZeFoGQhxERlxWX0BCQDZcD0APU0Z1CAUXXwEAVF5dERgUZl5eQ1tDSzJTER0XVhcCGFMHU0Q1VEsCAg4ddEgXAQoEFQ4GChwTFGNbVEheXAYiCwwGGBcdDVJcFBQUYk8YAgBYSDEaE1dKEVFbCUsTR082CB8cFRFIIAAGBQpeGQwZB04PQjwESEIKQBMjGxcfJhMVBB8PSEZPdloJQg1WEXMMPEdOQk1YXDETFxViW14vXVQTdlxTLUhFRF5aXH4TEmdYXFVeU1UxAzwBFgUGCgpLEkUTMlpcRg5AEnMbFx8mHRENBhtMBBI3WwxDXVNC&REFERER=http://www.findfertile.org/ac3.php?q=book&aid=531&sid=direc20&POS=99x232&VIEWPORT=571x257&IFRAME=N&COOKIES=Y&RES=800x600 (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:search.chillcow.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 591 ...b r/rrwxrwxrwx 0 0 11390-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/xd_receiver[1].htm 91 ma.b r/rr-xr-xr-x 0 0 11407-128-1 /Documents and Settings/malware/Cookies/malware@search.chillcow[1].txt 338 ...b r/rr-xr-xr-x 0 0 11413-128-1 /Documents and Settings/malware/Cookies/malware@nearlythenews.mevio[1].txt Fri Jul 01 2011 14:56:32 6032 ma.b r/rr-xr-xr-x 0 0 11167-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/86da2433b2d7e89bb87cbdcc717e6542abb5c1a5[1].jpg 5809 ma.b r/rr-xr-xr-x 0 0 11415-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/b0942feb76caea4b6a8c2ffc50ab58f850ca2752[1].jpg 5938 ma.b r/rr-xr-xr-x 0 0 11416-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/7fa9503afac135886b3d295e77e3f699db2f088f[1].jpg 5844 ma.b r/rr-xr-xr-x 0 0 11417-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/8d367ca2c0dcb81af9870cc8e0bf2c0b56939bb5[1].jpg 5896 ma.b r/rr-xr-xr-x 0 0 11418-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/b76f4ae429bac02e5b95d4afd5dc2c1c5847b385[1].jpg 5119 ma.b r/rr-xr-xr-x 0 0 11419-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/4644591fb077b95a495d2a1e2dbf4da947677a5e[1].jpg 5175 ma.b r/rr-xr-xr-x 0 0 11420-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/08e4f12711259da87a650a1d16e6c2292ca0d974[1].jpg 5409 ma.b r/rr-xr-xr-x 0 0 11421-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/9c4d6af299cc5b76bc81135f01e5eeb8ce626fe4[1].jpg 5748 ma.b r/rr-xr-xr-x 0 0 11422-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/ad3a99d40cfdbfe6e897921568dd671a78a625dd[1].jpg 3416 m..b r/rr-xr-xr-x 0 0 11423-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/156954[1].gif 2229 m..b r/rr-xr-xr-x 0 0 11424-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/5521[1].jpg 2441 m..b r/rr-xr-xr-x 0 0 11425-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/2661[1].jpg 5500 m..b r/rr-xr-xr-x 0 0 11426-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/3184c21120c91ede3333550f5d45b4c65cfb834b[1].jpg 5766 m..b r/rr-xr-xr-x 0 0 11427-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/fe428692e79c6adf1b2850d38470a7c7dc8616a3[1].jpg 2833 m..b r/rr-xr-xr-x 0 0 11428-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/1667[1].jpg 2973 m..b r/rr-xr-xr-x 0 0 11429-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/3860[1].jpg 2472 m..b r/rr-xr-xr-x 0 0 11430-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/5842[1].jpg 2887 m..b r/rr-xr-xr-x 0 0 11431-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/261456[1].jpg 7467 m..b r/rr-xr-xr-x 0 0 11432-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/5205[1].png 3482 m..b r/rr-xr-xr-x 0 0 11433-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/1781[1].jpg 3539 m..b r/rr-xr-xr-x 0 0 11434-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/35930[1].jpg 2754 m..b r/rr-xr-xr-x 0 0 11435-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/29096[1].jpg 2513 m..b r/rr-xr-xr-x 0 0 11436-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/7620[1].jpg 2589 m..b r/rr-xr-xr-x 0 0 11437-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/16566[1].jpg 4140 m..b r/rr-xr-xr-x 0 0 11438-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/7601[1].jpg 2537 m..b r/rr-xr-xr-x 0 0 11439-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/4091[1].jpg 17283 m..b r/rr-xr-xr-x 0 0 11441-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/280455[1].jpg 4106 m..b r/rr-xr-xr-x 0 0 11443-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/nearlythenews[1].jpg Fri Jul 01 2011 14:56:34 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:nearlythenews.mevio.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 338 ma.. r/rr-xr-xr-x 0 0 11413-128-1 /Documents and Settings/malware/Cookies/malware@nearlythenews.mevio[1].txt Fri Jul 01 2011 14:56:35 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/N3340.247realmedia.com/B5564961.8_sz=728x90_pc=[TPAS_ID]_click0=http://network.realmedia.com/RealMedia/ads/click_lx.ads/mevio/ros/728x90/jx/ss/a/L24/1010486149/Top1/USNetwork/BCN2011060146_002_Nissan/nissan_may25_728.html/7872446c436b344f51675141422f2b71?_ord=1010486149? cache stored in: YZCXGNW1/7872446c436b344f51675141422f2b71[1] - HTTP/1.1 200 OK - Content-Length: 38282 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) User: http://network.realmedia.com/RealMedia/ads/adstream_jx.ads/mevio/ros/728x90/jx/ss/a/1522405056 URL:Top1 cache stored in: YZCXGNW1/1522405056@Top1[1] - HTTP/1.1 200 OK - P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA"-policyref="/w3c/p3p.xml" - Content-Length: 1062 - Keep-Alive: timeout=60 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 2197 m..b r/rr-xr-xr-x 0 0 11343-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-2[2].js 1062 ma.b r/rr-xr-xr-x 0 0 11396-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/1522405056@Top1[1] 2234 ma.b r/rr-xr-xr-x 0 0 11440-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26270-2[3].js 688 ma.b r/rr-xr-xr-x 0 0 11448-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/imp[2] 38282 ma.b r/rr-xr-xr-x 0 0 11455-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/7872446c436b344f51675141422f2b71[1] 49 ...b r/rr-xr-xr-x 0 0 11691-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/tap[2].gif Fri Jul 01 2011 14:56:36 30061 ma.b r/rr-xr-xr-x 0 0 11189-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/PID_1666481_K2335_NAS_OM_728x90[1].jpg 2197 .a.. r/rr-xr-xr-x 0 0 11343-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-2[2].js 688 ...b r/rr-xr-xr-x 0 0 11414-128-4 /Documents and Settings/malware/Cookies/malware@insightexpressai[2].txt 3067866 ...b r/rr-xr-xr-x 0 0 11447-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/swflash[1].cab 2008 m..b r/rr-xr-xr-x 0 0 11456-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26271-15[1].js 10 m..b r/rr-xr-xr-x 0 0 11461-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/adServerESI[1].aspx Fri Jul 01 2011 14:56:37 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pixel.rubiconproject.com/tap.php?v=7249&nid=2146&put=e1psppomnjrpttd68kf4fbae6jh7bppq&expires=30 cache stored in: QJM5KT6J/tap[2].gif - HTTP/1.1 200 OK - X-Powered-By: PHP/5.1.6 - P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" - Content-Length: 49 - Keep-Alive: timeout=45- max=441 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:tag.admeld.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 688 ma.b r/rr-xr-xr-x 0 0 11331-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/imp[3] 49 ma.b r/rr-xr-xr-x 0 0 11445-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/tap[2].gif 591 ...b r/rr-xr-xr-x 0 0 11450-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/xd_receiver[2].htm 2008 .a.. r/rr-xr-xr-x 0 0 11456-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26271-15[1].js 10 .a.. r/rr-xr-xr-x 0 0 11461-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/adServerESI[1].aspx 2793 m..b r/rr-xr-xr-x 0 0 11500-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/aceUACping[1].htm 109 ma.b r/rr-xr-xr-x 0 0 11502-128-1 /Documents and Settings/malware/Cookies/malware@tag.admeld[1].txt Fri Jul 01 2011 14:56:38 448 m... d/dr-xr-xr-x 0 0 10337-144-1 /WINDOWS/SoftwareDistribution/DataStore/Logs 131072 ma.. r/rr-xr-xr-x 0 0 10355-128-3 /WINDOWS/SoftwareDistribution/DataStore/Logs/edb.log 8192 ma.. r/rr-xr-xr-x 0 0 10468-128-3 /WINDOWS/SoftwareDistribution/DataStore/Logs/edb.chk 1056768 ma.. r/rr-xr-xr-x 0 0 10502-128-4 /WINDOWS/SoftwareDistribution/DataStore/DataStore.edb 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:yieldmanager.net/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 96 ma.b r/rr-xr-xr-x 0 0 11503-128-1 /Documents and Settings/malware/Cookies/malware@yieldmanager[1].txt 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) ESENT/101_Info_wuauclt - 484 (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) ESENT/103_Info_wuaueng.dll - 484 - SUS20ClientDataStore: - 0 (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) Fri Jul 01 2011 14:56:40 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/N3340.247realmedia.com/B5564961.8_sz=728x90_pc=[TPAS_ID]_click0=http://network.realmedia.com/RealMedia/ads/click_lx.ads/mevio/ros/728x90/jx/ss/a/L24/1203465651/Top1/USNetwork/BCN2011060146_002_Nissan/nissan_may25_728.html/7872446c436b344f51675141422f2b71?_ord=1203465651? cache stored in: YZCXGNW1/7872446c436b344f51675141422f2b71[3] - HTTP/1.1 200 OK - Content-Length: 38282 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://s0.2mdn.net/1361550/PID_1666481_K2335_NAS_OM_728x90.jpg cache stored in: UPQVMROL/PID_1666481_K2335_NAS_OM_728x90[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Content-Type-Options: nosniff - Content-Length: 30061 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) User: http://network.realmedia.com/RealMedia/ads/adstream_jx.ads/mevio/ros/728x90/jx/ss/a/1898557958 URL:Top1 cache stored in: SLK18LSF/1898557958@Top1[1] - HTTP/1.1 200 OK - P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA"-policyref="/w3c/p3p.xml" - Content-Length: 1062 - Keep-Alive: timeout=60 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:insightexpressai.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:realmedia.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 8 ma.b r/rr-xr-xr-x 0 0 11326-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/adServerESI[1].aspx 1062 ma.b r/rr-xr-xr-x 0 0 11328-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/1898557958@Top1[1] 688 ma.. r/rr-xr-xr-x 0 0 11414-128-4 /Documents and Settings/malware/Cookies/malware@insightexpressai[2].txt 2234 ma.b r/rr-xr-xr-x 0 0 11504-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26270-2[4].js 166 ma.. r/rr-xr-xr-x 0 0 11505-128-1 /Documents and Settings/malware/Cookies/malware@realmedia[1].txt 688 ma.b r/rr-xr-xr-x 0 0 11506-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/imp[2] 38282 ma.b r/rr-xr-xr-x 0 0 11509-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/7872446c436b344f51675141422f2b71[3] Fri Jul 01 2011 14:56:41 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/N5552.159462.AOL.COM/B5330190.12_sz=728x90_click=http://r1-ads.ace.advertising.com/click/site=0000788695/mnum=0001039554/cstr=69825578=_4e0e4276-6276807620-788695^1039554^82^0-1_/xsxdata=$xsxdata/bnum=69825578/optn=64?trg=_ord=6276807620? cache stored in: YZCXGNW1/optn=64[2] - HTTP/1.1 200 OK - Content-Length: 6962 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://s0.2mdn.net/2784032/MoreMore_Game_728x90_BW.jpg cache stored in: YZCXGNW1/MoreMore_Game_728x90_BW[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Content-Type-Options: nosniff - Content-Length: 11280 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 .acb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:simpli.fi/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 2008 ma.b r/rr-xr-xr-x 0 0 11451-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/26271-15[1].js 684 ma.b r/rr-xr-xr-x 0 0 11484-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/imp[3] 594 ma.b r/rr-xr-xr-x 0 0 11501-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/dref=http%3A%2F%2Fnearlythenew[1].com%2F%3Futm_campaign%3D2a316b_572913_264123_113320_150752_23411%26utm_source%3D2a316b%26utm_medium%3D2a316b 11280 ma.b r/rr-xr-xr-x 0 0 11510-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/MoreMore_Game_728x90_BW[1].jpg 2034 ma.b r/rr-xr-xr-x 0 0 11514-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/26270-2[1].js 2197 ma.b r/rr-xr-xr-x 0 0 11515-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-2[3].js 90 ma.b r/rr-xr-xr-x 0 0 11517-128-1 /Documents and Settings/malware/Cookies/malware@simpli[1].txt 6962 ma.b r/rr-xr-xr-x 0 0 11520-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/optn=64[2] Fri Jul 01 2011 14:56:42 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/N3671.AOL/B5229711.9_sz=728x90_pc=[TPAS_ID]_click=http://r1-ads.ace.advertising.com/click/site=0000788695/mnum=0000973883/cstr=22439947=_4e0e4277-7818048843-788695^973883^82^0-1_/xsxdata=$xsxdata/bnum=22439947/optn=64?trg=_ord=7818048843? cache stored in: QJM5KT6J/optn=64[3] - HTTP/1.1 200 OK - Content-Length: 6666 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cdn.doubleverify.com/script152.js?agnc=563308&cmp=5229711&crt=&crtname=&adnet=&dvtagver=3.3.1346.2176&adsrv=1&plc=59781785&advid=998766&sid=320821&adid= cache stored in: UPQVMROL/script152[2].js - HTTP/1.1 200 OK - Content-Length: 2914 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cdn.doubleverify.com/script201.js?agnc=796803&cmp=947466&crt=&crtname=&adnet=&dvtagver=3.3.1346.2176&adsrv=6&plc=2895816&advid=796804&sid=Fox Audience Network&adid= cache stored in: QJM5KT6J/script201[2].js - HTTP/1.1 200 OK - Content-Length: 2914 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ds.serving-sys.com/BurstingCachedScripts//SBTemplates_2_3_2/StdBanner.js?ai=5823481 cache stored in: SLK18LSF/StdBanner[3].js - HTTP/1.1 200 OK - Content-Length: 24385 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ds.serving-sys.com/BurstingRes///Site-15895/Type-0/acc3c2fa-4748-40de-b9ea-57356529ba23.jpg cache stored in: UPQVMROL/acc3c2fa-4748-40de-b9ea-57356529ba23[1].jpg - HTTP/1.1 200 OK - Content-Length: 39662 - Content-Type: image/jpeg (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://log50.doubleverify.com/visitor.aspx?query=agnc=563308&cmp=5229711&crt=&crtname=&adnet=&dvtagver=3.3.1346.2176&adsrv=1&plc=59781785&advid=998766&sid=320821&adid=&&num=152&srcurl=http://nearlythenews.mevio.com/?utm_campaign=2a316b_572913_264123_113320_150752_23411&utm_source=2a316b&utm_medium=2a316b&random=0.9287394558228015 cache stored in: YZCXGNW1/CAB99BDB.jpg - HTTP/1.1 200 OK - Content-Length: 0 - Content-Type: image/jpeg - X-AspNet-Version: 2.0.50727 - X-Powered-By: ASP.NET (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://s0.2mdn.net/998766/1061_728x90_Promo_FreePhone_Smartphone_Static.jpg cache stored in: UPQVMROL/1061_728x90_Promo_FreePhone_Smartphone_Static[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Content-Type-Options: nosniff - Content-Length: 23346 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:demr.opt.fimserve.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 2325 ma.b r/rr-xr-xr-x 0 0 11175-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-15[2].js 594 ma.b r/rr-xr-xr-x 0 0 11341-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/dref=http%3A%2F%2Fnearlythenew[2].com%2F%3Futm_campaign%3D2a316b_572913_264123_113320_150752_23411%26utm_source%3D2a316b%26utm_medium%3D2a316b 115 ma.b r/rr-xr-xr-x 0 0 11400-128-1 /Documents and Settings/malware/Cookies/malware@demr.opt.fimserve[1].txt 2197 ma.b r/rr-xr-xr-x 0 0 11516-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26271-2[1].js 39662 ma.b r/rr-xr-xr-x 0 0 11523-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/acc3c2fa-4748-40de-b9ea-57356529ba23[1].jpg 23346 ma.b r/rr-xr-xr-x 0 0 11528-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/1061_728x90_Promo_FreePhone_Smartphone_Static[1].jpg 6666 ma.b r/rr-xr-xr-x 0 0 11529-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/optn=64[3] 2914 ma.b r/rr-xr-xr-x 0 0 11531-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/script152[2].js 1020 ma.b r/rr-xr-xr-x 0 0 11532-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/adopt[2].htm 2958 ma.b r/rr-xr-xr-x 0 0 11533-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CACRDZIA.htm 0 ma.b r/rr-xr-xr-x 0 0 11534-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CAB99BDB.jpg 24385 ma.b r/rr-xr-xr-x 0 0 11536-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/StdBanner[3].js 2914 ma.b r/rr-xr-xr-x 0 0 11537-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/script201[2].js Fri Jul 01 2011 14:56:43 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://log30.doubleverify.com/visitor.aspx?query=agnc=796803&cmp=947466&crt=&crtname=&adnet=&dvtagver=3.3.1346.2176&adsrv=6&plc=2895816&advid=796804&sid=Fox%20Audience%20Network&adid=&&num=201&srcurl=http://nearlythenews.mevio.com/?utm_campaign=2a316b_572913_264123_113320_150752_23411&utm_source=2a316b&utm_medium=2a316b&random=0.9039394999754498 cache stored in: QJM5KT6J/CA9UNXPU.jpg - HTTP/1.1 200 OK - Content-Length: 0 - Content-Type: image/jpeg - X-AspNet-Version: 2.0.50727 - X-Powered-By: ASP.NET (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 ma.b r/rr-xr-xr-x 0 0 11512-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/CA9UNXPU.jpg Fri Jul 01 2011 14:56:58 5168 .a.. r/rr-xr-xr-x 0 0 187-128-3 /WINDOWS/Fonts/vgaoem.fon Fri Jul 01 2011 14:57:14 44032 .a.. r/rr-xr-xr-x 0 0 1018-128-3 /WINDOWS/system32/msxml3r.dll 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://nearlythenews.mevio.com/?utm_campaign=2a316b_572913_264123_113320_150752_23411&utm_source=2a316b&utm_medium=2a316b (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 9432 ...b r/rr-xr-xr-x 0 0 11408-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/nearlythenews.mevio[1].htm Fri Jul 01 2011 14:57:16 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/ShellNoRoam/Bags/8/Shell Fri Jul 01 2011 14:57:17 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://nearlythenews.mevio.com/?format=show-episodes cache stored in: UPQVMROL/nearlythenews.mevio[1].htm - HTTP/1.1 200 OK - Content-Length: 9432 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 9432 ma.. r/rr-xr-xr-x 0 0 11408-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/nearlythenews.mevio[1].htm Fri Jul 01 2011 14:57:19 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Internet Settings Fri Jul 01 2011 14:57:21 2034 ma.b r/rr-xr-xr-x 0 0 11511-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/26270-2[1].js Fri Jul 01 2011 14:57:22 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Ext/Stats 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{D27CDB6E-AE6D-11CF-96B8-444553540000} 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/cm.appnexus/wireless_ron_sz=300x250_app=wireless_ron_click0=http://ib.adnxs.com/click?VC9thbH28D-rsBngguztPwAAAAAAAPg_FM_ZAkKr9T_FILByaJH4P3yXNNM_ozxHomJy4l6FLVGfQg5OAAAAAEG7BwDLAQAANwEAAAIAAABtLwcAzwkBAAEAAABVU0QAVVNEACwB-gCkIJ8DvgwBAQUCAQQAAAAAvyMXyQAAAAA./cnd=!4gRBKAi9gQYQ7d4cGM-TBCAA/referrer=http://nearlythenews.mevio.com/?utm_campaign=2a316b_572913_264123_113320_150752_23411&utm_source=2a316b&utm_medium=2a316b/clickenc=_ord=1309557407? cache stored in: QJM5KT6J/CA31HNIE. - HTTP/1.1 200 OK - Content-Length: 10453 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://data.aggregateknowledge.com/pixel!t=650!?che=556622&camid=5629905&plaid=65638121&creid=42724427&adgid=242743000 cache stored in: YZCXGNW1/pixel!t=650![1].gif - HTTP/1.1 200 OK - P3P: CP="NOI DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" - ETag: W/"43-1308732886000" - Content-Type: image/gif - Content-Language: en-US - Content-Length: 43 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://log50.doubleverify.com/visitor.aspx?query=agnc=2981993&cmp=5629905&crt=42724427&crtname=&adnet=&dvtagver=3.3.1346.2176&adsrv=1&plc=65638121&advid=2981993&sid=457626&adid=242743000&&srcurl=http://qydjuk.com/fw-nonplayer-banner.php?w=300&h=250&fwcsid=home&btf=1&is_ex=clean&btype=1&zone=shows&num=7&random=0.9811074200216594 cache stored in: SLK18LSF/CA69WXAV.jpg - HTTP/1.1 200 OK - Content-Length: 0 - Content-Type: image/jpeg - X-AspNet-Version: 2.0.50727 - X-Powered-By: ASP.NET (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 2197 ma.b r/rr-xr-xr-x 0 0 11526-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-2[4].js 0 ma.b r/rr-xr-xr-x 0 0 11535-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/CA69WXAV.jpg 2515 ma.b r/rr-xr-xr-x 0 0 11542-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26271-15[2].js 803 ma.b r/rr-xr-xr-x 0 0 11543-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/CAQV4XUR 10453 ma.b r/rr-xr-xr-x 0 0 11547-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/CA31HNIE 30302 ma.b r/rr-xr-xr-x 0 0 11549-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/300x250_062011_NATL_PROMO_INCREDIBLE2_v2[1].swf 40021 ma.b r/rr-xr-xr-x 0 0 11550-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/script7[2].js 43 ma.b r/rr-xr-xr-x 0 0 11552-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/pixel!t=650![1].gif 350 ...b r/rrwxrwxrwx 0 0 11774-128-1 /Documents and Settings/malware/Cookies/malware@aggregateknowledge[2].txt Fri Jul 01 2011 14:57:23 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://spe.atdmt.com/images/pixel.gif cache stored in: SLK18LSF/pixel[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - Content-Length: 42 - Allow: GET (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 .acb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:atdmt.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 42 .a.. r/rr-xr-xr-x 0 0 10626-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/pixel[1].gif 180 ma.b r/rr-xr-xr-x 0 0 11449-128-1 /Documents and Settings/malware/Cookies/malware@atdmt[2].txt Fri Jul 01 2011 14:57:38 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/N4300.AOL/B5501146.4_sz=728x90_pc=[TPAS_ID]_click=http://r1-ads.ace.advertising.com/click/site=0000788695/mnum=0001034404/cstr=63918538=_4e0e42af-6202258152-788695^1034404^82^0-1_/xsxdata=$xsxdata/bnum=63918538/optn=64?trg=_ord=6202258152? cache stored in: SLK18LSF/optn=64[2] - HTTP/1.1 200 OK - Content-Length: 6439 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://s0.2mdn.net/1326154/Hyatt_Leisure_National_728x90 Concept 1.gif cache stored in: QJM5KT6J/Hyatt_Leisure_National_728x90 Concept 1[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Content-Type-Options: nosniff - Content-Length: 8147 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 136 ...b r/rr-xr-xr-x 0 0 11288-128-1 /Documents and Settings/malware/Cookies/malware@r1-ads.ace.advertising[1].txt 801 .a.. r/rr-xr-xr-x 0 0 11304-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/flashwrite_1_2[2].js 8147 ma.b r/rr-xr-xr-x 0 0 11541-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/Hyatt_Leisure_National_728x90 Concept 1[1].gif 6439 ma.b r/rr-xr-xr-x 0 0 11555-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/optn=64[2] Fri Jul 01 2011 14:57:48 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/1308/shows/thumbs/otrcomedypodshowcom.jpg?r=1154989918 cache stored in: YZCXGNW1/otrcomedypodshowcom[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 4327 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/14391/shows/thumbs/striptaculous1.jpg?r=1283618372 cache stored in: YZCXGNW1/striptaculous1[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 4375 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/16840/shows/thumbs/centurymediapodcast.jpg?r=1206661968 cache stored in: SLK18LSF/centurymediapodcast[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2748 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/20235/shows/thumbs/masterinthemix.jpg?r=1283149266 cache stored in: SLK18LSF/masterinthemix[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 1595 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/20980/shows/thumbs/curtisandtarashow.jpg?r=1258141571 cache stored in: YZCXGNW1/curtisandtarashow[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 4249 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/21570/shows/thumbs/mymhmaudio.png?r=1243481220 cache stored in: SLK18LSF/mymhmaudio[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 4822 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/21749/shows/thumbs/newbrew.png?r=1278034223 cache stored in: UPQVMROL/newbrew[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 9312 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/23028/shows/thumbs/staticradioshow.jpg?r=1251935290 cache stored in: SLK18LSF/staticradioshow[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 4324 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/23436/shows/thumbs/theradreport.png?r=1282075428 cache stored in: QJM5KT6J/theradreport[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 3501 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/24182/shows/thumbs/thesmellcast.jpg?r=1263072074 cache stored in: QJM5KT6J/thesmellcast[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3510 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/24236/shows/thumbs/artsidercast1.jpg?r=1262969425 cache stored in: UPQVMROL/artsidercast1[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2258 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/24890/shows/thumbs/btpcast.jpg?r=1302321229 cache stored in: YZCXGNW1/btpcast[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3715 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/25598/shows/thumbs/podmdm.jpg?r=1276651611 cache stored in: QJM5KT6J/podmdm[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3053 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/26478/shows/thumbs/tripdspodcast.png?r=1285819529 cache stored in: UPQVMROL/tripdspodcast[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 11719 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/27109/shows/thumbs/hotoff.jpg?r=1303772318 cache stored in: QJM5KT6J/hotoff[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3002 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/27187/shows/thumbs/telekidsforever.png?r=1299877060 cache stored in: QJM5KT6J/telekidsforever[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 13332 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/27371/shows/thumbs/hotoffuk.png?r=1305045586 cache stored in: UPQVMROL/hotoffuk[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 3375 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/6207/shows/thumbs/wwwscraptimeca.jpg?r=1203985872 cache stored in: UPQVMROL/wwwscraptimeca[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2830 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/6589/shows/thumbs/theultimate.jpg?r=1176130123 cache stored in: SLK18LSF/theultimate[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3838 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/7/shows/thumbs/mostpeoplearedjs.jpg?r=1157480139 cache stored in: QJM5KT6J/mostpeoplearedjs[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3274 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/8270/shows/thumbs/michebelzhollywood.jpg?r=1290208813 cache stored in: YZCXGNW1/michebelzhollywood[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3884 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/combined/directory.css?r=38841 cache stored in: SLK18LSF/directory[2].css - HTTP/1.1 200 OK - Content-Length: 1954 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/js/tpl_directory.js?r=38841 cache stored in: YZCXGNW1/tpl_directory[1].js - HTTP/1.1 200 OK - Content-Length: 3164 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://www.mevio.com/directory (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 3053 ma.b r/rr-xr-xr-x 0 0 11327-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/podmdm[1].jpg 1954 ma.b r/rr-xr-xr-x 0 0 11391-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/directory[2].css 3274 ma.b r/rr-xr-xr-x 0 0 11392-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/mostpeoplearedjs[1].jpg 18913 m..b r/rr-xr-xr-x 0 0 11409-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/default[1].jpg 1595 ma.b r/rr-xr-xr-x 0 0 11442-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/masterinthemix[1].jpg 4324 ma.b r/rr-xr-xr-x 0 0 11467-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/staticradioshow[1].jpg 2748 ma.b r/rr-xr-xr-x 0 0 11499-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/centurymediapodcast[1].jpg 3715 ma.b r/rr-xr-xr-x 0 0 11553-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/btpcast[1].jpg 13332 ma.b r/rr-xr-xr-x 0 0 11556-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/telekidsforever[1].png 2258 ma.b r/rr-xr-xr-x 0 0 11557-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/artsidercast1[1].jpg 3375 ma.b r/rr-xr-xr-x 0 0 11558-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/hotoffuk[1].png 239 ma.b r/rr-xr-xr-x 0 0 11559-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/bg-pager[1].png 4327 ma.b r/rr-xr-xr-x 0 0 11560-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/otrcomedypodshowcom[1].jpg 3164 ma.b r/rr-xr-xr-x 0 0 11561-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/tpl_directory[1].js 261 ma.b r/rr-xr-xr-x 0 0 11562-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/action-img-map[1].png 9312 ma.b r/rr-xr-xr-x 0 0 11563-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/newbrew[1].png 2027 m..b r/rr-xr-xr-x 0 0 11564-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/26317-15[1].js 3884 ma.b r/rr-xr-xr-x 0 0 11565-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/michebelzhollywood[1].jpg 3501 ma.b r/rr-xr-xr-x 0 0 11566-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/theradreport[1].png 2830 ma.b r/rr-xr-xr-x 0 0 11567-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/wwwscraptimeca[1].jpg 3002 ma.b r/rr-xr-xr-x 0 0 11568-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/hotoff[1].jpg 11719 ma.b r/rr-xr-xr-x 0 0 11569-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tripdspodcast[1].png 3510 ma.b r/rr-xr-xr-x 0 0 11570-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/thesmellcast[1].jpg 4375 ma.b r/rr-xr-xr-x 0 0 11571-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/striptaculous1[1].jpg 4249 ma.b r/rr-xr-xr-x 0 0 11572-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/curtisandtarashow[1].jpg 4822 ma.b r/rr-xr-xr-x 0 0 11575-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/mymhmaudio[1].png 3838 ma.b r/rr-xr-xr-x 0 0 11576-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/theultimate[1].jpg Fri Jul 01 2011 14:57:49 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/1238/shows/thumbs/compcon.jpg?r=1155081665 cache stored in: YZCXGNW1/compcon[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2778 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/13817/shows/thumbs/twotimesvideo.jpg?r=1195843321 cache stored in: UPQVMROL/twotimesvideo[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2550 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/17716/shows/thumbs/themagicnewswire.png?r=1212507337 cache stored in: SLK18LSF/themagicnewswire[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 11713 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/19817/shows/thumbs/ayultp.png?r=1226416368 cache stored in: QJM5KT6J/ayultp[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 2658 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/201/shows/thumbs/themusicianscooler.jpg?r=1145333607 cache stored in: SLK18LSF/themusicianscooler[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3714 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/22248/shows/thumbs/icmusic.png?r=1246554450 cache stored in: SLK18LSF/icmusic[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 6475 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/22496/shows/thumbs/themalthursdayshow.jpg?r=1298584598 cache stored in: QJM5KT6J/themalthursdayshow[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 4000 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/23018/shows/thumbs/authorsrevealed.jpg?r=1269276961 cache stored in: QJM5KT6J/authorsrevealed[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2681 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/24372/shows/thumbs/riptheknobsoff.jpg?r=1263852026 cache stored in: UPQVMROL/riptheknobsoff[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 1993 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/25609/shows/thumbs/scottsigler.jpg?r=1276550854 cache stored in: QJM5KT6J/scottsigler[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3625 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/25801/shows/thumbs/coffeecoffeecoffee.jpg?r=1278725601 cache stored in: YZCXGNW1/coffeecoffeecoffee[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2409 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/26727/shows/thumbs/dearprudence.jpg?r=1288889631 cache stored in: UPQVMROL/dearprudence[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 4090 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/26834/shows/thumbs/podcastpipocaenanquim.jpg?r=1289918241 cache stored in: YZCXGNW1/podcastpipocaenanquim[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 4370 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/2700/shows/thumbs/broadway.jpg?r=1161182084 cache stored in: QJM5KT6J/broadway[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3461 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/27408/shows/thumbs/tuishow.png?r=1306208405 cache stored in: YZCXGNW1/tuishow[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 4607 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/27412/shows/thumbs/expertdrinking.png?r=1306306165 cache stored in: UPQVMROL/expertdrinking[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 8888 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/27423/shows/thumbs/forkthis.jpg?r=1306491544 cache stored in: UPQVMROL/forkthis[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3063 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/27472/shows/thumbs/thestevesanchezshowmeviocom.jpg?r=1307659790 cache stored in: SLK18LSF/thestevesanchezshowmeviocom[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 1940 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/27479/shows/thumbs/beatlesaramatv.jpg?r=1307920636 cache stored in: UPQVMROL/beatlesaramatv[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 4138 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/27480/shows/thumbs/erkfmmetalmonday.jpg?r=1307955572 cache stored in: UPQVMROL/erkfmmetalmonday[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3089 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/27486/shows/thumbs/creativecastpodcast.png?r=1308060668 cache stored in: YZCXGNW1/creativecastpodcast[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 1968 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/5717/shows/thumbs/gemmasplayhouse.jpg?r=1168831208 cache stored in: YZCXGNW1/gemmasplayhouse[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2596 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/723/shows/thumbs/musicalworldpodshow.jpg?r=1249957809 cache stored in: QJM5KT6J/musicalworldpodshow[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3178 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/9683/shows/thumbs/nation.jpg?r=1176143423 cache stored in: YZCXGNW1/nation[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3030 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 2681 ma.b r/rr-xr-xr-x 0 0 11358-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/authorsrevealed[1].jpg 4090 ma.b r/rr-xr-xr-x 0 0 11508-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/dearprudence[1].jpg 2778 ma.b r/rr-xr-xr-x 0 0 11522-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/compcon[1].jpg 2027 .a.. r/rr-xr-xr-x 0 0 11564-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/26317-15[1].js 4138 ma.b r/rr-xr-xr-x 0 0 11577-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/beatlesaramatv[1].jpg 2550 ma.b r/rr-xr-xr-x 0 0 11578-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/twotimesvideo[1].jpg 2409 ma.b r/rr-xr-xr-x 0 0 11580-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/coffeecoffeecoffee[1].jpg 1968 ma.b r/rr-xr-xr-x 0 0 11581-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/creativecastpodcast[1].png 3625 ma.b r/rr-xr-xr-x 0 0 11582-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/scottsigler[1].jpg 1993 ma.b r/rr-xr-xr-x 0 0 11583-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/riptheknobsoff[1].jpg 11713 ma.b r/rr-xr-xr-x 0 0 11584-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/themagicnewswire[1].png 3178 ma.b r/rr-xr-xr-x 0 0 11586-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/musicalworldpodshow[1].jpg 4370 ma.b r/rr-xr-xr-x 0 0 11588-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/podcastpipocaenanquim[1].jpg 1940 ma.b r/rr-xr-xr-x 0 0 11589-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/thestevesanchezshowmeviocom[1].jpg 2658 ma.b r/rr-xr-xr-x 0 0 11590-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/ayultp[1].png 3089 ma.b r/rr-xr-xr-x 0 0 11591-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/erkfmmetalmonday[1].jpg 3030 ma.b r/rr-xr-xr-x 0 0 11592-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/nation[1].jpg 3714 ma.b r/rr-xr-xr-x 0 0 11593-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/themusicianscooler[1].jpg 3461 ma.b r/rr-xr-xr-x 0 0 11594-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/broadway[1].jpg 4000 ma.b r/rr-xr-xr-x 0 0 11595-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/themalthursdayshow[1].jpg 3063 ma.b r/rr-xr-xr-x 0 0 11596-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/forkthis[1].jpg 2596 ma.b r/rr-xr-xr-x 0 0 11597-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/gemmasplayhouse[1].jpg 6475 ma.b r/rr-xr-xr-x 0 0 11598-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/icmusic[1].png 8888 ma.b r/rr-xr-xr-x 0 0 11599-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/expertdrinking[1].png 4607 ma.b r/rr-xr-xr-x 0 0 11600-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/tuishow[1].png Fri Jul 01 2011 14:57:50 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/images/action-img-map.png?r=38841 cache stored in: SLK18LSF/action-img-map[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 261 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/images/bg-pager.png?r=38841 cache stored in: YZCXGNW1/bg-pager[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 239 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 14:57:55 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://bannerfarm.ace.advertising.com/bannerfarm/174467/7CSG_JJF_IGO_20110315_fillForm_728x90.swf?clickTag=http://r1-ads.ace.advertising.com/click/site=0000805400/mnum=0001036330/cstr=42339116=_4e0e42c1-0815660348-805400^1036330^1183^0-1_/xsxdata=$xsxdata/bnum=42339116/optn=64?trg=&siteValue=0000805400 cache stored in: YZCXGNW1/7CSG_JJF_IGO_20110315_fillForm_728x90[1].swf - HTTP/1.1 200 OK - ETag: "4b5bdc-86b6-4a20013c1a480" - Content-Length: 34486 - Content-Type: application/x-shockwave-flash (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://bannerfarm.ace.advertising.com/bannerfarm/84352/siteIDs.txt cache stored in: QJM5KT6J/siteIDs[1].txt - HTTP/1.1 200 OK - ETag: "b333e-49f4-4a4196d326700" - Content-Length: 18932 - Content-Type: text/plain_ charset=UTF-8 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 .acb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:r1-ads.ace.advertising.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 136 m... r/rr-xr-xr-x 0 0 11288-128-1 /Documents and Settings/malware/Cookies/malware@r1-ads.ace.advertising[1].txt 18932 ma.b r/rr-xr-xr-x 0 0 11311-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/siteIDs[1].txt 34486 ma.b r/rr-xr-xr-x 0 0 11585-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/7CSG_JJF_IGO_20110315_fillForm_728x90[1].swf 2034 ma.b r/rr-xr-xr-x 0 0 11587-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26317-2[1].js 2197 ma.b r/rr-xr-xr-x 0 0 11604-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26318-2[1].js 1621 ma.b r/rr-xr-xr-x 0 0 11608-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/dref=http%3A%2F%2Fwww.mevio[2].com%2Fdirectory%2F Fri Jul 01 2011 14:58:25 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://www.mevio.com/episode/286404/lebron-james-talks-to-god-and-sarah (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) Fri Jul 01 2011 14:58:26 18453 m..b r/rr-xr-xr-x 0 0 11401-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/connect[2].php Fri Jul 01 2011 14:58:32 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://trgj.opt.fimserve.com/fp.js cache stored in: SLK18LSF/fp[1].js - HTTP/1.1 200 OK - Content-Type: application/x-javascript - Content-Length: 4348 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 1201 ma.b r/rr-xr-xr-x 0 0 11334-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/adopt[3].htm 4348 .a.. r/rr-xr-xr-x 0 0 11402-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/fp[1].js 2034 ma.b r/rr-xr-xr-x 0 0 11519-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26270-2[1].js 5627 ma.b r/rr-xr-xr-x 0 0 11548-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/view[1].htm 2199 ma.b r/rr-xr-xr-x 0 0 11579-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/26271-15[2].js 2322 ma.b r/rr-xr-xr-x 0 0 11603-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-2[5].js 608 ma.b r/rr-xr-xr-x 0 0 11607-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/dref=http%3A%2F%2Fwww.mevio[1].com%2Fepisode%2F286404%2Flebron-james-talks-to-god-and-sarah 680 ma.b r/rr-xr-xr-x 0 0 11613-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/imp[4] 313 ...b r/rrwxrwxrwx 0 0 11618-128-1 /Documents and Settings/malware/Cookies/malware@by.adshuffle[2].txt Fri Jul 01 2011 14:58:33 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ds.serving-sys.com/BurstingCachedScripts//SBTemplates_2_3_2/StdBanner.js?ai=5823403 cache stored in: UPQVMROL/StdBanner[2].js - HTTP/1.1 200 OK - Content-Length: 24385 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ds.serving-sys.com/BurstingRes///Site-15895/Type-0/785e48fd-311d-4f0e-be8f-e511ecfdeeb9.jpg cache stored in: SLK18LSF/785e48fd-311d-4f0e-be8f-e511ecfdeeb9[1].jpg - HTTP/1.1 200 OK - Content-Length: 38604 - Content-Type: image/jpeg (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://log30.doubleverify.com/visitor.aspx?query=agnc=796803&cmp=947466&crt=&crtname=&adnet=&dvtagver=3.3.1346.2176&adsrv=6&plc=2895815&advid=796804&sid=Fox%20Audience%20Network&adid=&&num=201&srcurl=http://www.mevio.com/episode/286404/lebron-james-talks-to-god-and-sarah&random=0.8429479316712722 cache stored in: UPQVMROL/CA49WFL9.jpg - HTTP/1.1 200 OK - Content-Length: 0 - Content-Type: image/jpeg - X-AspNet-Version: 2.0.50727 - X-Powered-By: ASP.NET (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://media2.adshuffle.com/images/unknown/792ba3334fd24139982578813025e0a7.gif cache stored in: UPQVMROL/792ba3334fd24139982578813025e0a7[1].gif - HTTP/1.1 200 OK - X-Px: ht lax-am6-n1.panthercdn.com - ETag: "b6a2555d1ef6cb1:2aa9" - P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTR STP IND DEM" - Content-Length: 39607 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 38604 .a.. r/rr-xr-xr-x 0 0 11397-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/785e48fd-311d-4f0e-be8f-e511ecfdeeb9[1].jpg 24385 .a.. r/rr-xr-xr-x 0 0 11404-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/StdBanner[2].js 2951 ma.b r/rr-xr-xr-x 0 0 11521-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CAGLQNGB.htm 39607 ma.b r/rr-xr-xr-x 0 0 11540-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/792ba3334fd24139982578813025e0a7[1].gif 0 ma.b r/rr-xr-xr-x 0 0 11544-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CA49WFL9.jpg 1748 ma.b r/rr-xr-xr-x 0 0 11574-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/asSwfObj13[2].js Fri Jul 01 2011 14:59:45 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/08e/4f1/08e4f12711259da87a650a1d16e6c2292ca0d974.jpg?url=http://origin.thumbs.mevio.com/media/27056/episodes/283276/thumbnail.jpg&width=200&height=112&scheme=1 cache stored in: UPQVMROL/08e4f12711259da87a650a1d16e6c2292ca0d974[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 5175 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/318/4c2/3184c21120c91ede3333550f5d45b4c65cfb834b.jpg?url=http://origin.thumbs.mevio.com/media/27056/episodes/280891/thumbnail.jpg&width=200&height=112&scheme=1 cache stored in: QJM5KT6J/3184c21120c91ede3333550f5d45b4c65cfb834b[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 5500 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/464/459/4644591fb077b95a495d2a1e2dbf4da947677a5e.jpg?url=http://origin.thumbs.mevio.com/media/27056/episodes/284281/thumbnail.jpg&width=200&height=112&scheme=1 cache stored in: QJM5KT6J/4644591fb077b95a495d2a1e2dbf4da947677a5e[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 5119 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/7fa/950/7fa9503afac135886b3d295e77e3f699db2f088f.jpg?url=http://origin.thumbs.mevio.com/media/27056/episodes/286076/thumbnail.jpg&width=200&height=112&scheme=1 cache stored in: SLK18LSF/7fa9503afac135886b3d295e77e3f699db2f088f[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 5938 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/86d/a24/86da2433b2d7e89bb87cbdcc717e6542abb5c1a5.jpg?url=http://origin.thumbs.mevio.com/media/27056/episodes/283290/thumbnail.jpg&width=200&height=112&scheme=1 cache stored in: UPQVMROL/86da2433b2d7e89bb87cbdcc717e6542abb5c1a5[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 6032 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/8d3/67c/8d367ca2c0dcb81af9870cc8e0bf2c0b56939bb5.jpg?url=http://origin.thumbs.mevio.com/media/27056/episodes/284694/thumbnail.jpg&width=200&height=112&scheme=1 cache stored in: SLK18LSF/8d367ca2c0dcb81af9870cc8e0bf2c0b56939bb5[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 5844 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/9c4/d6a/9c4d6af299cc5b76bc81135f01e5eeb8ce626fe4.jpg?url=http://origin.thumbs.mevio.com/media/27056/episodes/283270/thumbnail.jpg&width=200&height=112&scheme=1 cache stored in: YZCXGNW1/9c4d6af299cc5b76bc81135f01e5eeb8ce626fe4[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 5409 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/ad3/a99/ad3a99d40cfdbfe6e897921568dd671a78a625dd.jpg?url=http://origin.thumbs.mevio.com/media/27056/episodes/281215/thumbnail.jpg&width=200&height=112&scheme=1 cache stored in: YZCXGNW1/ad3a99d40cfdbfe6e897921568dd671a78a625dd[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 5748 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/b09/42f/b0942feb76caea4b6a8c2ffc50ab58f850ca2752.jpg?url=http://origin.thumbs.mevio.com/media/27056/episodes/286404/thumbnail.jpg&width=200&height=112&scheme=1 cache stored in: YZCXGNW1/b0942feb76caea4b6a8c2ffc50ab58f850ca2752[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 5809 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/b76/f4a/b76f4ae429bac02e5b95d4afd5dc2c1c5847b385.jpg?url=http://origin.thumbs.mevio.com/media/27056/episodes/284351/thumbnail.jpg&width=200&height=112&scheme=1 cache stored in: QJM5KT6J/b76f4ae429bac02e5b95d4afd5dc2c1c5847b385[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 5896 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/fe4/286/fe428692e79c6adf1b2850d38470a7c7dc8616a3.jpg?url=http://origin.thumbs.mevio.com/media/27056/episodes/281211/thumbnail.jpg&width=200&height=112&scheme=1 cache stored in: QJM5KT6J/fe428692e79c6adf1b2850d38470a7c7dc8616a3[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 5766 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/27056/shows/thumbs/nearlythenews.jpg?r=1298320684 cache stored in: QJM5KT6J/nearlythenews[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 4106 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/12737/gallery/thumbs/7620.jpg cache stored in: YZCXGNW1/7620[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2513 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/19430/gallery/thumbs/261456.jpg cache stored in: SLK18LSF/261456[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2887 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/2271/gallery/thumbs/277295.jpg cache stored in: QJM5KT6J/277295[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3637 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/2756/gallery/thumbs/1781.jpg cache stored in: UPQVMROL/1781[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3482 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/3075/gallery/thumbs/5521.jpg cache stored in: YZCXGNW1/5521[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2229 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/3125/gallery/thumbs/16566.jpg cache stored in: UPQVMROL/16566[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2589 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/3743/gallery/thumbs/2661.jpg cache stored in: SLK18LSF/2661[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2441 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/39460/gallery/thumbs/29096.jpg cache stored in: SLK18LSF/29096[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2754 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/530/gallery/med/280455.jpg cache stored in: QJM5KT6J/280455[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 17283 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/5703/gallery/thumbs/3831.png cache stored in: SLK18LSF/3831[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 9295 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/5894/gallery/thumbs/3860.jpg cache stored in: QJM5KT6J/3860[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2973 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/5985/gallery/thumbs/4091.jpg cache stored in: SLK18LSF/4091[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2537 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/761/gallery/thumbs/156954.gif cache stored in: YZCXGNW1/156954[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Cache: HIT - Content-Length: 3416 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/7796/gallery/thumbs/35930.jpg cache stored in: SLK18LSF/35930[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3539 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/9692/gallery/thumbs/5842.jpg cache stored in: UPQVMROL/5842[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2472 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://nearlythenews.mevio.com (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 3637 .a.. r/rr-xr-xr-x 0 0 11243-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/277295[1].jpg 9295 .a.. r/rr-xr-xr-x 0 0 11248-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/3831[1].png 3416 .a.. r/rr-xr-xr-x 0 0 11423-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/156954[1].gif 2229 .a.. r/rr-xr-xr-x 0 0 11424-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/5521[1].jpg 2441 .a.. r/rr-xr-xr-x 0 0 11425-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/2661[1].jpg 5500 .a.. r/rr-xr-xr-x 0 0 11426-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/3184c21120c91ede3333550f5d45b4c65cfb834b[1].jpg 5766 .a.. r/rr-xr-xr-x 0 0 11427-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/fe428692e79c6adf1b2850d38470a7c7dc8616a3[1].jpg 2833 .a.. r/rr-xr-xr-x 0 0 11428-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/1667[1].jpg 2973 .a.. r/rr-xr-xr-x 0 0 11429-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/3860[1].jpg 2472 .a.. r/rr-xr-xr-x 0 0 11430-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/5842[1].jpg 2887 .a.. r/rr-xr-xr-x 0 0 11431-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/261456[1].jpg 3482 .a.. r/rr-xr-xr-x 0 0 11433-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/1781[1].jpg 3539 .a.. r/rr-xr-xr-x 0 0 11434-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/35930[1].jpg 2754 .a.. r/rr-xr-xr-x 0 0 11435-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/29096[1].jpg 2513 .a.. r/rr-xr-xr-x 0 0 11436-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/7620[1].jpg 2589 .a.. r/rr-xr-xr-x 0 0 11437-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/16566[1].jpg 2537 .a.. r/rr-xr-xr-x 0 0 11439-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/4091[1].jpg 17283 .a.. r/rr-xr-xr-x 0 0 11441-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/280455[1].jpg 4106 .a.. r/rr-xr-xr-x 0 0 11443-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/nearlythenews[1].jpg Fri Jul 01 2011 14:59:46 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.facebook.com/extern/login_status.php?api_key=c99345b4de38e993c64ef4654ac9164b&extern=2&channel=http://nearlythenews.mevio.com/rest/facebook/xd_receiver.php&locale=en_US cache stored in: QJM5KT6J/login_status[1].htm - HTTP/1.1 200 OK - Content-Length: 1117 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 1117 ma.b r/rr-xr-xr-x 0 0 11387-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/login_status[1].htm Fri Jul 01 2011 14:59:47 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://nearlythenews.mevio.com/rest/facebook/xd_receiver.php cache stored in: QJM5KT6J/xd_receiver[2].htm - HTTP/1.1 200 OK - Content-Length: 591 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 591 ma.. r/rr-xr-xr-x 0 0 11450-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/xd_receiver[2].htm Fri Jul 01 2011 14:59:52 2034 ma.b r/rr-xr-xr-x 0 0 11459-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/26270-2[2].js 3129 ma.b r/rr-xr-xr-x 0 0 11621-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-15[3].js 2197 ma.b r/rr-xr-xr-x 0 0 11622-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-2[6].js Fri Jul 01 2011 14:59:53 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://18rockets.com/js/popup.js cache stored in: QJM5KT6J/popup[1].js - HTTP/1.1 200 OK - ETag: "6609907-17f-49f5377737580" - Content-Length: 383 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://acuityplatform.com:8080/Adserver/banner?Project=215&SizeID=3&CampaignID=3&SiteID=10013187&Bid=1.18&Position=3&Price=E0A7B0C432216639&ReqId=f6a1e59a37b591851d0f45077b91678df01450d8&GeoCode=1&ExID=2&AgentCode=20&Test=0&ts=130e7b68edb&Xc=0-0&UrlTopic=1&BannerID=468&Term1=[20701-26437-Free+Online+Printable+Coupons-1.22143-7.0]&Term2=[20701-26426-Free+Coupons-1.5551-7.0]&Term3=[20588-25607-Bf+Goodrich+Tire+Promotions-1.36-7.0]&Term4=[20701-26431-Online+Coupons-1.28571-7.0]&Term5=[20588-25613-Buy+Bf+Goodrich+Tires+Online-1.36-7.0]&Term6=[20588-25619-Best+Tires-1.36-7.0]&ip=c6b0e50a&jk= cache stored in: YZCXGNW1/CAGBEHGB.0]&ip=c6b0e50a&jk= - HTTP/1.1 200 OK - P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA" - Content-Length: 6192 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pixel.rubiconproject.com/tap.php?v=5672&nid=2082&put=1-0&expires=3652 cache stored in: SLK18LSF/tap[1].gif - HTTP/1.1 200 OK - X-Powered-By: PHP/5.1.6 - P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" - Content-Length: 49 - Keep-Alive: timeout=45- max=491 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:acuityplatform.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 383 ma.b r/rr-xr-xr-x 0 0 11335-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/popup[1].js 6192 ma.b r/rr-xr-xr-x 0 0 11554-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CAGBEHGB.0]&ip=c6b0e50a&jk= 49 ma.b r/rr-xr-xr-x 0 0 11614-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/tap[1].gif 78 ma.b r/rr-xr-xr-x 0 0 11626-128-1 /Documents and Settings/malware/Cookies/malware@acuityplatform[1].txt Fri Jul 01 2011 15:00:42 0 m... 0 0 0 0 REG_System_SECURITYSECURITY/Policy/Secrets/SAC /CupdTime 0 m... 0 0 0 0 REG_System_SECURITYSECURITY/Policy/Secrets/SAC /CurrVal 0 m... 0 0 0 0 REG_System_SECURITYSECURITY/Policy/Secrets/SAC /OldVal 0 m... 0 0 0 0 REG_System_SECURITYSECURITY/Policy/Secrets/SAC /OupdTime 0 m... 0 0 0 0 REG_System_SECURITYSECURITY/Policy/Secrets/SAI /CupdTime 0 m... 0 0 0 0 REG_System_SECURITYSECURITY/Policy/Secrets/SAI /CurrVal 0 m... 0 0 0 0 REG_System_SECURITYSECURITY/Policy/Secrets/SAI /OldVal 0 m... 0 0 0 0 REG_System_SECURITYSECURITY/Policy/Secrets/SAI /OupdTime 0 m... 0 0 0 0 REG_System_SECURITYSECURITY/RXACT Fri Jul 01 2011 15:00:47 1024 .a.. r/rr-xr-xr-x 0 0 3649-128-3 /WINDOWS/system32/config/SECURITY.LOG Fri Jul 01 2011 15:00:48 1024 m... r/rr-xr-xr-x 0 0 3649-128-3 /WINDOWS/system32/config/SECURITY.LOG Fri Jul 01 2011 15:02:21 135984 .a.. r/rr-xr-xr-x 0 0 563-128-3 /WINDOWS/Fonts/framd.ttf 152844 .a.. r/rr-xr-xr-x 0 0 564-128-3 /WINDOWS/Fonts/framdit.ttf Fri Jul 01 2011 15:02:32 0 macb 0 0 0 10413 [XP Prefetch] (Last run) IPCONFIG.EXE-2395F30B.pf - [IPCONFIG.EXE] was executed - run count [11]- full path: [C:/WINDOWS/SYSTEM32/IPCONFIG.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/NETMAN.DLL - WINDOWS/SYSTEM32/IPHLPAPI.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/WS2_32.DLL - WINDOWS/SYSTEM32/WS2HELP.DLL - WINDOWS/SYSTEM32/MPRAPI.DLL - WINDOWS/SYSTEM32/ACTIVEDS.DLL - WINDOWS/SYSTEM32/ADSLDPC.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/WLDAP32.DLL - WINDOWS/SYSTEM32/ATL.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/RTUTILS.DLL - WINDOWS/SYSTEM32/SAMLIB.DLL - WINDOWS/SYSTEM32/SETUPAPI.DLL - WINDOWS/SYSTEM32/NETSHELL.DLL - WINDOWS/SYSTEM32/CREDUI.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/DOT3API.DLL - WINDOWS/SYSTEM32/DOT3DLG.DLL - WINDOWS/SYSTEM32/ONEX.DLL - WINDOWS/SYSTEM32/WTSAPI32.DLL - WINDOWS/SYSTEM32/WINSTA.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/EAPPCFG.DLL - WINDOWS/SYSTEM32/MSVCP60.DLL - WINDOWS/SYSTEM32/EAPPPRXY.DLL - WINDOWS/SYSTEM32/RASAPI32.DLL - WINDOWS/SYSTEM32/RASMAN.DLL - WINDOWS/SYSTEM32/TAPI32.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/WININET.DLL - WINDOWS/SYSTEM32/WZCSAPI.DLL - WINDOWS/SYSTEM32/WZCSVC.DLL - WINDOWS/SYSTEM32/WMI.DLL - WINDOWS/SYSTEM32/DHCPCSVC.DLL - WINDOWS/SYSTEM32/DNSAPI.DLL - WINDOWS/SYSTEM32/EAPOLQEC.DLL - WINDOWS/SYSTEM32/QUTIL.DLL - WINDOWS/SYSTEM32/ESENT.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/WINTRUST.DLL - WINDOWS/SYSTEM32/IMAGEHLP.DLL} (file: /media/sdb1/WINDOWS/Prefetch/IPCONFIG.EXE-2395F30B.pf) 53760 .a.. r/rr-xr-xr-x 0 0 1974-128-3 /WINDOWS/system32/winsta.dll 64000 .a.. r/rr-xr-xr-x 0 0 2003-128-3 /WINDOWS/system32/samlib.dll 126976 .a.. r/rr-xr-xr-x 0 0 2024-128-3 /WINDOWS/system32/dhcpcsvc.dll 18432 .a.. r/rr-xr-xr-x 0 0 2031-128-3 /WINDOWS/system32/wtsapi32.dll 1082368 .a.. r/rr-xr-xr-x 0 0 2054-128-3 /WINDOWS/system32/esent.dll 87040 .a.. r/rr-xr-xr-x 0 0 2068-128-3 /WINDOWS/system32/mprapi.dll 193536 .a.. r/rr-xr-xr-x 0 0 2069-128-3 /WINDOWS/system32/activeds.dll 143360 .a.. r/rr-xr-xr-x 0 0 2070-128-3 /WINDOWS/system32/adsldpc.dll 55808 .a.. r/rr-xr-xr-x 0 0 2127-128-3 /WINDOWS/system32/ipconfig.exe 198144 .a.. r/rr-xr-xr-x 0 0 2128-128-3 /WINDOWS/system32/netman.dll 5632 .a.. r/rr-xr-xr-x 0 0 2148-128-3 /WINDOWS/system32/wmi.dll 1703936 .a.. r/rr-xr-xr-x 0 0 2149-128-3 /WINDOWS/system32/netshell.dll 163840 .a.. r/rr-xr-xr-x 0 0 2157-128-3 /WINDOWS/system32/credui.dll 26112 .a.. r/rr-xr-xr-x 0 0 2393-128-3 /WINDOWS/system32/dot3api.dll 9216 .a.. r/rr-xr-xr-x 0 0 2395-128-3 /WINDOWS/system32/dot3dlg.dll 30720 .a.. r/rr-xr-xr-x 0 0 2452-128-3 /WINDOWS/system32/eapolqec.dll 126976 .a.. r/rr-xr-xr-x 0 0 2456-128-3 /WINDOWS/system32/eappcfg.dll 40960 .a.. r/rr-xr-xr-x 0 0 2458-128-3 /WINDOWS/system32/eappprxy.dll 144384 .a.. r/rr-xr-xr-x 0 0 2883-128-3 /WINDOWS/system32/onex.dll 76800 .a.. r/rr-xr-xr-x 0 0 2934-128-3 /WINDOWS/system32/qutil.dll 52736 .a.. r/rr-xr-xr-x 0 0 3197-128-3 /WINDOWS/system32/wzcsapi.dll 483840 .a.. r/rr-xr-xr-x 0 0 3198-128-3 /WINDOWS/system32/wzcsvc.dll Fri Jul 01 2011 15:02:33 22116 mac. r/rrwxrwxrwx 0 0 11121-128-4 /WINDOWS/Prefetch/IPCONFIG.EXE-2395F30B.pf Fri Jul 01 2011 15:02:43 622592 .a.. r/rr-xr-xr-x 0 0 2805-128-3 /WINDOWS/system32/netcfgx.dll Fri Jul 01 2011 15:03:11 64656 .a.. r/rr-xr-xr-x 0 0 221-128-3 /WINDOWS/Fonts/sserife.fon Fri Jul 01 2011 15:03:27 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:https://secure.paymentsadd.com/defragmenter?product_sku=DEFRAG_WIN_BASIC-DEFRAG_WIN_PREMIUM&default_sku=1&view_eds=1&check_eds=1&affiliate_id=531&affiliate_sid=01&guid=333484643333922833342332 (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 144384 .a.. r/rr-xr-xr-x 0 0 2005-128-3 /WINDOWS/system32/schannel.dll Fri Jul 01 2011 15:03:29 56 m.c. d/drwxrwxrwx 0 0 10474-144-6 /Documents and Settings/malware/Application Data/Microsoft 248 m.cb d/drwxrwxrwx 0 0 11627-144-1 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache 56 ...b d/drwxrwxrwx 0 0 11628-144-5 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/MetaData 56 ...b d/drwxrwxrwx 0 0 11629-144-5 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/Content 216 macb r/rrwxrwxrwx 0 0 11630-128-1 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/MetaData/2BF68F4714092295550497DD56F57004 18 macb r/rrwxrwxrwx 0 0 11631-128-1 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/Content/2BF68F4714092295550497DD56F57004 216 macb r/rrwxrwxrwx 0 0 11632-128-1 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/MetaData/94308059B57B3142E455B38A6EB92015 45039 macb r/rrwxrwxrwx 0 0 11633-128-4 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/Content/94308059B57B3142E455B38A6EB92015 138752 .a.. r/rr-xr-xr-x 0 0 2065-128-3 /WINDOWS/system32/dssenh.dll 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) crypt32/1_Info_CN=GeoTrust Global CA- O=GeoTrust Inc.- C=US - DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212 (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) crypt32/2_Info_http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) crypt32/4_Info_http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212.crt (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) crypt32/7_Info_http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) Fri Jul 01 2011 15:03:30 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js cache stored in: SLK18LSF/jquery.min[1].js - HTTP/1.1 200 OK - Content-Length: 72174 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://secure.paymentsadd.com/sale/index/affiliate_id/531/affiliate_sid/01/product_sku/DEFRAG_WIN_BASIC,DEFRAG_WIN_PREMIUM/default_sku/1/guid/333484643333922833342332/view_eds/1/check_eds/1 cache stored in: YZCXGNW1/1[1].htm - HTTP/1.1 200 OK - Content-Length: 35539 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://secure.paymentsadd.com/scripts/jquery.bgiframe.js cache stored in: UPQVMROL/jquery.bgiframe[1].js - HTTP/1.1 200 OK - Content-Type: application/x-javascript - Content-Length: 1728 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://secure.paymentsadd.com/styles/layout.css cache stored in: QJM5KT6J/layout[1].css - HTTP/1.1 200 OK - Content-Type: text/css - Content-Length: 23392 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://clicknaperville.org/customers/buy.php?pid=DEFRAG_WIN_BASIC&id=531&subid=01&guid=333484643333922833342332 (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 35539 ma.b r/rr-xr-xr-x 0 0 11634-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/1[1].htm 72174 ma.b r/rr-xr-xr-x 0 0 11635-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/jquery.min[1].js 23392 ma.b r/rr-xr-xr-x 0 0 11636-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/layout[1].css 1728 ma.b r/rr-xr-xr-x 0 0 11637-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/jquery.bgiframe[1].js Fri Jul 01 2011 15:03:31 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://secure.paymentsadd.com/hit.php?id=531&sid=01 cache stored in: UPQVMROL/hit[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - Transfer-Encoding: chunked (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://secure.paymentsadd.com/images/30days.jpg cache stored in: YZCXGNW1/30days[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - Content-Length: 3164 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://secure.paymentsadd.com/images/bg.jpg cache stored in: QJM5KT6J/bg[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - Content-Length: 11596 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://secure.paymentsadd.com/images/header.jpg cache stored in: QJM5KT6J/header[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - Content-Length: 22488 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://secure.paymentsadd.com/images/lock.jpg cache stored in: SLK18LSF/lock[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - Content-Length: 12002 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://secure.paymentsadd.com/images/titile_1.jpg cache stored in: YZCXGNW1/titile_1[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - Content-Length: 16905 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://secure.paymentsadd.com/images/titile_2.jpg cache stored in: UPQVMROL/titile_2[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - Content-Length: 14697 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://secure.paymentsadd.com/images/visacvv.gif cache stored in: YZCXGNW1/visacvv[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - Content-Length: 10292 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://secure.paymentsadd.com/images/wait.gif cache stored in: SLK18LSF/wait[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - Content-Length: 1924 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:secure.paymentsadd.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 10292 ma.b r/rr-xr-xr-x 0 0 11638-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/visacvv[1].gif 1924 ma.b r/rr-xr-xr-x 0 0 11639-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/wait[1].gif 22488 ma.b r/rr-xr-xr-x 0 0 11640-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/header[1].jpg 11596 ma.b r/rr-xr-xr-x 0 0 11641-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/bg[1].jpg 14697 ma.b r/rr-xr-xr-x 0 0 11642-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/titile_2[1].jpg 16905 ma.b r/rr-xr-xr-x 0 0 11643-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/titile_1[1].jpg 12002 ma.b r/rr-xr-xr-x 0 0 11644-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/lock[1].jpg 81 ma.b r/rr-xr-xr-x 0 0 11645-128-1 /Documents and Settings/malware/Cookies/malware@secure.paymentsadd[1].txt 0 ma.b r/rr-xr-xr-x 0 0 11646-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/hit[1].gif 3164 ma.b r/rr-xr-xr-x 0 0 11647-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/30days[1].jpg 226748 .a.. r/rr-xr-xr-x 0 0 250-128-3 /WINDOWS/Fonts/arialbi.ttf Fri Jul 01 2011 15:03:32 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://secure.paymentsadd.com/images/safe.jpg cache stored in: QJM5KT6J/safe[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - Content-Length: 20744 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://secure.paymentsadd.com/images/weaccept.jpg cache stored in: SLK18LSF/weaccept[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - Content-Length: 12878 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:https://secure.paymentsadd.com/sale/index/affiliate_id/531/affiliate_sid/01/product_sku/DEFRAG_WIN_BASIC,DEFRAG_WIN_PREMIUM/default_sku/1/guid/333484643333922833342332/view_eds/1/check_eds/1 (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 0 macb 0 0 0 10638 [Internet Explorer] (Last Access) User: malware URL::Host: secure.paymentsadd.com (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/MSHist012011070120110702/index.dat) 0 macb 0 0 0 10638 [Internet Explorer] (Last Access) User: malware URL:https://secure.paymentsadd.com/sale/index/affiliate_id/531/affiliate_sid/01/product_sku/DEFRAG_WIN_BASIC,DEFRAG_WIN_PREMIUM/default_sku/1/guid/333484643333922833342332/view_eds/1/check_eds/1 (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/MSHist012011070120110702/index.dat) 12878 ma.b r/rr-xr-xr-x 0 0 11648-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/weaccept[1].jpg 20744 ma.b r/rr-xr-xr-x 0 0 11649-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/safe[1].jpg Fri Jul 01 2011 15:03:36 1024 ma.. r/rr-xr-xr-x 0 0 3639-128-3 /WINDOWS/system32/config/default.LOG Fri Jul 01 2011 15:04:48 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/UserAssist/{75048700-EF1F-11D0-9888-006097DEACF9}/Count 0 macb 0 0 0 10413 [XP Prefetch] (Last run) CMD.EXE-087B4001.pf - [CMD.EXE] was executed - run count [8]- full path: [C:/WINDOWS/SYSTEM32/CMD.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/APPHELP.DLL - WINDOWS/SYSTEM32/RPCSS.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/SETUPAPI.DLL - WINDOWS/SYSTEM32/CLBCATQ.DLL - WINDOWS/SYSTEM32/COMRES.DLL - WINDOWS/SYSTEM32/URLMON.DLL} (file: /media/sdb1/WINDOWS/Prefetch/CMD.EXE-087B4001.pf) 293376 .a.. r/rr-xr-xr-x 0 0 1967-128-3 /WINDOWS/system32/winsrv.dll 389120 .a.. r/rr-xr-xr-x 0 0 2116-128-3 /WINDOWS/system32/cmd.exe Fri Jul 01 2011 15:04:53 0 macb 0 0 0 10413 [XP Prefetch] (Last run) PING.EXE-31216D26.pf - [PING.EXE] was executed - run count [16]- full path: [C:/WINDOWS/SYSTEM32/PING.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/IPHLPAPI.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/WS2_32.DLL - WINDOWS/SYSTEM32/WS2HELP.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/MSWSOCK.DLL - WINDOWS/SYSTEM32/DNSAPI.DLL - WINDOWS/SYSTEM32/RASADHLP.DLL - WINDOWS/SYSTEM32/HNETCFG.DLL - WINDOWS/SYSTEM32/WSHTCPIP.DLL} (file: /media/sdb1/WINDOWS/Prefetch/PING.EXE-31216D26.pf) 17920 .a.. r/rr-xr-xr-x 0 0 2912-128-3 /WINDOWS/system32/ping.exe Fri Jul 01 2011 15:04:58 17368 mac. r/rrwxrwxrwx 0 0 10993-128-4 /WINDOWS/Prefetch/CMD.EXE-087B4001.pf 13022 mac. r/rrwxrwxrwx 0 0 11394-128-4 /WINDOWS/Prefetch/PING.EXE-31216D26.pf Fri Jul 01 2011 15:05:30 111104 .a.. r/rr-xr-xr-x 0 0 6052-128-3 /WINDOWS/system32/wuauclt.exe Fri Jul 01 2011 15:05:34 162304 .a.. r/rr-xr-xr-x 0 0 6054-128-3 /WINDOWS/system32/wuaucpl.cpl Fri Jul 01 2011 15:05:39 0 macb 0 0 0 10413 [XP Prefetch] (Last run) 14147364.EXE-0E2D1000.pf - [14147364.EXE] was executed - run count [1]- full path: [] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.GDIPLUS_6595B64144CCF1DF_1.0.2600.5512_X-WW_DFB54E0C/GDIPLUS.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/MFC42U.DLL - WINDOWS/SYSTEM32/MSVCP60.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/URLMON.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/SYSTEM32/WININET.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSASN1.DLL} (file: /media/sdb1/WINDOWS/Prefetch/14147364.EXE-0E2D1000.pf) 372736 .a.. r/rr-xr-xr-x 0 0 11166-128-3 /Documents and Settings/All Users/Application Data/14147364.exe 413696 .a.. r/rr-xr-xr-x 0 0 2063-128-3 /WINDOWS/system32/msvcp60.dll 981760 .a.. r/rr-xr-xr-x 0 0 2678-128-3 /WINDOWS/system32/mfc42u.dll 1724416 .a.. r/rr-xr-xr-x 0 0 3670-128-3 /WINDOWS/WinSxS/x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c/GdiPlus.dll Fri Jul 01 2011 15:05:43 336 .a.. r/rr-xr-xr-x 0 0 11168-128-1 /Documents and Settings/All Users/Application Data/14147364 Fri Jul 01 2011 15:05:44 56 m... d/dr-xr-xr-x 0 0 10413-144-6 /WINDOWS/Prefetch 13196 macb r/rrwxrwxrwx 0 0 11444-128-4 /WINDOWS/Prefetch/14147364.EXE-0E2D1000.pf Fri Jul 01 2011 15:05:58 56 .a.. d/drwxrwxrwx 0 0 10474-144-6 /Documents and Settings/malware/Application Data/Microsoft 248 .a.. d/drwxrwxrwx 0 0 11627-144-1 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache Fri Jul 01 2011 15:07:03 1104896 .a.. r/rr-xr-xr-x 0 0 2784-128-3 /WINDOWS/system32/msxml3.dll Fri Jul 01 2011 15:07:06 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/ShellNoRoam/BagMRU 0 macb 0 0 0 10413 [XP Prefetch] (Last run) IEXPLORE.EXE-27122324.pf - [IEXPLORE.EXE] was executed - run count [4]- full path: [C:/PROGRAM FILES/INTERNET EXPLORER/IEXPLORE.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/SHDOCVW.DLL - WINDOWS/SYSTEM32/CRYPT32.DLL - WINDOWS/SYSTEM32/MSASN1.DLL - WINDOWS/SYSTEM32/CRYPTUI.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/WININET.DLL - WINDOWS/SYSTEM32/WINTRUST.DLL - WINDOWS/SYSTEM32/IMAGEHLP.DLL - WINDOWS/SYSTEM32/WLDAP32.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/RICHED20.DLL - WINDOWS/SYSTEM32/WS2_32.DLL - WINDOWS/SYSTEM32/WS2HELP.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/RPCSS.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/SYSTEM32/BROWSEUI.DLL - WINDOWS/SYSTEM32/BROWSELC.DLL - WINDOWS/SYSTEM32/APPHELP.DLL - WINDOWS/SYSTEM32/CLBCATQ.DLL - WINDOWS/SYSTEM32/COMRES.DLL - WINDOWS/SYSTEM32/CSCUI.DLL - WINDOWS/SYSTEM32/CSCDLL.DLL - WINDOWS/SYSTEM32/SETUPAPI.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/XPSP2RES.DLL - WINDOWS/SYSTEM32/SXS.DLL - WINDOWS/SYSTEM32/URLMON.DLL - WINDOWS/SYSTEM32/SHDOCLC.DLL - WINDOWS/SYSTEM32/MLANG.DLL - WINDOWS/SYSTEM32/WSOCK32.DLL - WINDOWS/SYSTEM32/MSWSOCK.DLL - WINDOWS/SYSTEM32/HNETCFG.DLL - WINDOWS/SYSTEM32/WSHTCPIP.DLL - WINDOWS/SYSTEM32/RASAPI32.DLL - WINDOWS/SYSTEM32/RASMAN.DLL - WINDOWS/SYSTEM32/TAPI32.DLL - WINDOWS/SYSTEM32/RTUTILS.DLL - WINDOWS/SYSTEM32/SENSAPI.DLL - WINDOWS/SYSTEM32/DNSAPI.DLL - WINDOWS/SYSTEM32/RASADHLP.DLL - WINDOWS/SYSTEM32/MSHTML.DLL - WINDOWS/SYSTEM32/MSLS31.DLL - WINDOWS/SYSTEM32/PSAPI.DLL - WINDOWS/SYSTEM32/MSIMTF.DLL - WINDOWS/SYSTEM32/MSCTF.DLL - WINDOWS/SYSTEM32/IMM32.DLL - WINDOWS/SYSTEM32/URL.DLL - WINDOWS/SYSTEM32/JSCRIPT.DLL - WINDOWS/SYSTEM32/WINRNR.DLL - WINDOWS/SYSTEM32/IPHLPAPI.DLL - WINDOWS/SYSTEM32/IEPEERS.DLL - WINDOWS/SYSTEM32/COMDLG32.DLL - WINDOWS/SYSTEM32/IMGUTIL.DLL - WINDOWS/SYSTEM32/PNGFILT.DLL - WINDOWS/SYSTEM32/MSHTMLED.DLL - WINDOWS/SYSTEM32/INETCFG.DLL - WINDOWS/SYSTEM32/MPR.DLL - WINDOWS/SYSTEM32/ICFGNT5.DLL - WINDOWS/SYSTEM32/MSV1_0.DLL - WINDOWS/SYSTEM32/SCHANNEL.DLL} (file: /media/sdb1/WINDOWS/Prefetch/IEXPLORE.EXE-27122324.pf) 256 .ac. d/drwxrwxrwx 0 0 10455-144-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files 672 .ac. d/drwxrwxrwx 0 0 10456-144-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5 256 .ac. d/drwxrwxrwx 0 0 10462-144-1 /Documents and Settings/malware/Local Settings/History 496 .ac. d/drwxrwxrwx 0 0 10463-144-1 /Documents and Settings/malware/Local Settings/History/History.IE5 49152 m... r/rr-xr-xr-x 0 0 10534-128-4 /Documents and Settings/malware/Cookies/index.dat 276992 .a.. r/rr-xr-xr-x 0 0 1937-128-3 /WINDOWS/system32/comdlg32.dll 144384 .a.. r/rr-xr-xr-x 0 0 1939-128-3 /WINDOWS/system32/imagehlp.dll 619520 .a.. r/rr-xr-xr-x 0 0 1948-128-3 /WINDOWS/system32/urlmon.dll 666112 .a.. r/rr-xr-xr-x 0 0 1951-128-3 /WINDOWS/system32/wininet.dll 172032 .a.. r/rr-xr-xr-x 0 0 1952-128-3 /WINDOWS/system32/wldap32.dll 599040 .a.. r/rr-xr-xr-x 0 0 1959-128-3 /WINDOWS/system32/crypt32.dll 57344 .a.. r/rr-xr-xr-x 0 0 1961-128-3 /WINDOWS/system32/msasn1.dll 1845632 .a.. r/rr-xr-xr-x 0 0 1962-128-3 /WINDOWS/system32/win32k.sys 507904 .a.. r/rr-xr-xr-x 0 0 1971-128-3 /WINDOWS/system32/winlogon.exe 337408 .a.. r/rr-xr-xr-x 0 0 1976-128-3 /WINDOWS/system32/netapi32.dll 82432 .a.. r/rr-xr-xr-x 0 0 1978-128-3 /WINDOWS/system32/ws2_32.dll 19968 .a.. r/rr-xr-xr-x 0 0 1979-128-3 /WINDOWS/system32/ws2help.dll 713216 .a.. r/rr-xr-xr-x 0 0 1985-128-3 /WINDOWS/system32/sxs.dll 985088 .a.. r/rr-xr-xr-x 0 0 1988-128-3 /WINDOWS/system32/setupapi.dll 176640 .a.. r/rr-xr-xr-x 0 0 1990-128-3 /WINDOWS/system32/wintrust.dll 125952 .a.. r/rr-xr-xr-x 0 0 1992-128-3 /WINDOWS/system32/apphelp.dll 147968 .a.. r/rr-xr-xr-x 0 0 2002-128-3 /WINDOWS/system32/dnsapi.dll 399360 .a.. r/rr-xr-xr-x 0 0 2019-128-3 /WINDOWS/system32/rpcss.dll 245248 .a.. r/rr-xr-xr-x 0 0 2020-128-3 /WINDOWS/system32/mswsock.dll 19456 .a.. r/rr-xr-xr-x 0 0 2021-128-3 /WINDOWS/system32/wshtcpip.dll 94720 .a.. r/rr-xr-xr-x 0 0 2023-128-3 /WINDOWS/system32/iphlpapi.dll 16896 .a.. r/rr-xr-xr-x 0 0 2025-128-3 /WINDOWS/system32/winrnr.dll 7680 .a.. r/rr-xr-xr-x 0 0 2026-128-3 /WINDOWS/system32/rasadhlp.dll 44032 .a.. r/rr-xr-xr-x 0 0 2029-128-3 /WINDOWS/system32/rtutils.dll 22528 .a.. r/rr-xr-xr-x 0 0 2066-128-3 /WINDOWS/system32/wsock32.dll 237056 .a.. r/rr-xr-xr-x 0 0 2079-128-3 /WINDOWS/system32/rasapi32.dll 61440 .a.. r/rr-xr-xr-x 0 0 2080-128-3 /WINDOWS/system32/rasman.dll 181760 .a.. r/rr-xr-xr-x 0 0 2081-128-3 /WINDOWS/system32/tapi32.dll 7168 .a.. r/rr-xr-xr-x 0 0 2082-128-3 /WINDOWS/system32/sensapi.dll 101888 .a.. r/rr-xr-xr-x 0 0 2083-128-3 /WINDOWS/system32/cscdll.dll 326656 .a.. r/rr-xr-xr-x 0 0 2086-128-3 /WINDOWS/system32/cscui.dll 1025024 .a.. r/rr-xr-xr-x 0 0 2094-128-3 /WINDOWS/system32/browseui.dll 1499136 .a.. r/rr-xr-xr-x 0 0 2096-128-3 /WINDOWS/system32/shdocvw.dll 512512 .a.. r/rr-xr-xr-x 0 0 2143-128-3 /WINDOWS/system32/cryptui.dll 433664 .a.. r/rr-xr-xr-x 0 0 2144-128-3 /WINDOWS/system32/riched20.dll 344064 .a.. r/rr-xr-xr-x 0 0 2153-128-3 /WINDOWS/system32/hnetcfg.dll 63488 .a.. r/rr-xr-xr-x 0 0 2181-128-3 /WINDOWS/system32/browselc.dll 792064 .a.. r/rr-xr-xr-x 0 0 2324-128-3 /WINDOWS/system32/comres.dll 586240 .a.. r/rr-xr-xr-x 0 0 2685-128-3 /WINDOWS/system32/mlang.dll 549376 .a.. r/rr-xr-xr-x 0 0 3010-128-3 /WINDOWS/system32/shdoclc.dll 2897920 .a.. r/rr-xr-xr-x 0 0 3313-128-3 /WINDOWS/system32/xpsp2res.dll 498688 .a.. r/rr-xr-xr-x 0 0 4926-128-3 /WINDOWS/system32/clbcatq.dll 22512 .a.. r/rr-xr-xr-x 0 0 7539-128-4 /WINDOWS/Registration/R000000000007.clb Fri Jul 01 2011 15:07:07 105 ...b r/rrwxrwxrwx 0 0 10315-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/ac3[1].htm 110080 .a.. r/rr-xr-xr-x 0 0 2009-128-3 /WINDOWS/system32/imm32.dll 23040 .a.. r/rr-xr-xr-x 0 0 2146-128-3 /WINDOWS/system32/psapi.dll 3066880 .a.. r/rr-xr-xr-x 0 0 2186-128-3 /WINDOWS/system32/mshtml.dll 512000 .a.. r/rr-xr-xr-x 0 0 2608-128-3 /WINDOWS/system32/jscript.dll 297984 .a.. r/rr-xr-xr-x 0 0 3263-128-3 /WINDOWS/system32/MSCTF.dll 159232 .a.. r/rr-xr-xr-x 0 0 3269-128-3 /WINDOWS/system32/MSIMTF.dll 1695232 .a.. r/rr-xr-xr-x 0 0 5485-128-3 /Program Files/Messenger/msmsgs.exe 146432 .a.. r/rr-xr-xr-x 0 0 993-128-3 /WINDOWS/system32/msls31.dll Fri Jul 01 2011 15:07:09 409280 .a.. r/rr-xr-xr-x 0 0 2190-128-3 /WINDOWS/Fonts/times.ttf Fri Jul 01 2011 15:07:16 62692 mac. r/rrwxrwxrwx 0 0 10760-128-4 /WINDOWS/Prefetch/IEXPLORE.EXE-27122324.pf Fri Jul 01 2011 15:07:25 100 .a.. r/rr-xr-xr-x 0 0 10317-128-1 /Documents and Settings/malware/Cookies/malware@64.111.211[1].txt 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://www.findfertile.org/go.php?userip=198.176.229.10&referer=http://www.findfertile.org/search.php?q=exotic+cars&aid=531&sid=direc20&curl=http://64.111.211.158/c.php?s=eNodk0uzgjgUhH-QVZKQAMniLhAExIBeEHlspggPEcELgigWP36cWZxedH29Ot31IiIJKIuMyeKenDcLvS5rz7VTqz8LWAMg_6-KtIgAQqB8hQAZ4SWJqik3m3pnulV2d34WhaQFlzIEeJHTLyFxpYQIpDglsAAF-UekHOdIoTSlJSYSFTGChOcU50WRQywvlCx4Kdw_FxjF_HdTVdVRTzh2Kt1UzrBKL_tdfRO2B28T3_X9wQIrrPwKmY1X0_Hz-mzv12d-ZHrlXY7Ifs6JQOWyc0v0IIrQFWd7KD98w5qrPcgq-3sGjsb_sGucNL-wyJwEZ3fs4D52YG2E_WXyG-mq5oXWUm5r90CAkv1-HA613VR9KMfGZ589zH2OprhJ5J6AqXn-UaMXoiAag_b6YOMmHOD4KroquG3CLSA1rvy9PRUVreANtaBmImMAZ7oMy2Ab5bj1B8mhefYiiq57WRfsRff0ttWOeYr86FDGMrlgxVF9wt3v5fp-V6hJnyU8YPX6K2pm7OvsPf6V4kEUVj5pj5Gx2kSdzwaOqjEdjOH7Ydu4rjwnuvQfFk710Q8U8H7dfEti4WjOriMYRhvXw0eT-q-dS-Yd94mV5tb4Snqw0l-CdiW55W0ueJOdpszsJdNyNXO4bjdO1cSuM16EAxoEfo4nO4zex_sUdhbxdqLuHJ_dr1LSSE9qX2RbcT7zzZ7xCk5MPW75ePsNLdevys8jedH7qsKuCLVSLLms8905U9zGthRDY7EEzLnm6DLZ3_D9JQFRlyTZLPpPp39Crek7IZW3SfdAu-YoDelWgQ_fDww2yZP_ov1-lif-LSad7qLHBvsFz41c3NJtY9zeBEWwuBz1XIvgibZo28bQsAmk_ZPlby-xr9lk28CYHvvAt-QZDtSWLEH14grS4GeBlKyhIq9Fka4hWBZI8BpK35PRGlK8_GfBhYdnMQ3pmEduF6OkS8zzlM3SmERJx2ep5iL4FnuHDydndi4_P4uEEVn-C6MlRzli7ZdrvTaJbJCG74a1dE5eX06BCiKlzBHnRKF5IYKUYpqijBNcFhAvaQlSSDNKMcxLjEqaQgnIhUK--y4AIP8Chj9Mpg&aid=531&sid=direc20 (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 0 m... 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:64.111.211.158/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:64.188.52.125/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 99 ma.b r/rr-xr-xr-x 0 0 11412-128-1 /Documents and Settings/malware/Cookies/malware@64.188.52[1].txt Fri Jul 01 2011 15:07:26 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://fraud-screening.com/mtest.php?r=bjo0OntmOjE6InAiO2Y6OTk6InVnZ2M6Ly96cml2YnpoZnZwaXZxcmJmLnpyaXZiLnBiei8_aGd6X2ZiaGVwcj00MTc4cDMmaGd6X3BuemNudnRhPTQxNzhwM18yMTctMjM1MDctMSZoZ3pfenJxdmh6PXBjcCI7ZjoxOiJnIjtmOjQ6IjJfcTEiO2Y6MjoidnEiO3Y6MTY2Mjc5MDtmOjE6Im8iO3Y6NDA7fQ cache stored in: QJM5KT6J/mtest[1].htm - HTTP/1.1 200 OK - Content-Type: text/html - Transfer-Encoding: chunked (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 3181 ma.b r/rr-xr-xr-x 0 0 11446-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/mtest[1].htm Fri Jul 01 2011 15:08:08 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://fraud-screening.com/mred.php?r=bjo0OntmOjE6InAiO2Y6OTk6InVnZ2M6Ly96cml2YnpoZnZwaXZxcmJmLnpyaXZiLnBiei8_aGd6X2ZiaGVwcj00MTc4cDMmaGd6X3BuemNudnRhPTQxNzhwM18yMTctMjM1MDctMSZoZ3pfenJxdmh6PXBjcCI7ZjoxOiJnIjtmOjQ6IjJfcTEiO2Y6MjoidnEiO3Y6MTY2Mjc5MDtmOjE6Im8iO3Y6NDA7fQ&x=-1&y=-1&f=-1&i=-1&s=0 (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 1351168 .a.. r/rr-xr-xr-x 0 0 2740-128-3 /WINDOWS/system32/mshtml.tlb 832872 .a.. r/rr-xr-xr-x 0 0 6093-128-3 /WINDOWS/system32/Macromed/Flash/flash.ocx Fri Jul 01 2011 15:08:09 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://fraud-screening.com/test.swf cache stored in: UPQVMROL/test[1].swf - HTTP/1.1 200 OK - Content-Type: application/x-shockwave-flash - Content-Length: 169 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://fraud-screening.com/mred.php?r=bjo0OntmOjE6InAiO2Y6OTk6InVnZ2M6Ly96cml2YnpoZnZwaXZxcmJmLnpyaXZiLnBiei8_aGd6X2ZiaGVwcj00MTc4cDMmaGd6X3BuemNudnRhPTQxNzhwM18yMTctMjM1MDctMSZoZ3pfenJxdmh6PXBjcCI7ZjoxOiJnIjtmOjQ6IjJfcTEiO2Y6MjoidnEiO3Y6MTY2Mjc5MDtmOjE6Im8iO3Y6NDA7fQ&x=588&y=257&f=1&i=0&s=1 (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 0 m... 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:crux.mevio.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 95 .a.. r/rr-xr-xr-x 0 0 11190-128-1 /Documents and Settings/malware/Cookies/malware@crux.mevio[1].txt 157999 .a.. r/rr-xr-xr-x 0 0 11194-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/index[2].js 1604 .a.. r/rr-xr-xr-x 0 0 11195-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/ie6-fixes[2].css 26185 .a.. r/rr-xr-xr-x 0 0 11196-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/index[1].css 27240 .a.. r/rr-xr-xr-x 0 0 11197-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/ga[2].js 2132 .a.. r/rr-xr-xr-x 0 0 11198-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/small-icons[1].png 33316 .a.. r/rr-xr-xr-x 0 0 11199-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/shows[2].css 98741 .a.. r/rr-xr-xr-x 0 0 11200-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/showPage[2].js 999 .a.. r/rr-xr-xr-x 0 0 11202-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/box-shadows[1].png 2680 .a.. r/rr-xr-xr-x 0 0 11203-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/box-heading[1].png 11097 .a.. r/rr-xr-xr-x 0 0 11204-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/logo-and-footer[1].jpg 610 .a.. r/rr-xr-xr-x 0 0 11206-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/now-playing-bg[1].jpg 169 ma.b r/rr-xr-xr-x 0 0 11282-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/test[1].swf 346 ...b r/rr-xr-xr-x 0 0 11513-128-1 /Documents and Settings/malware/Cookies/malware@meviomusicvideos.mevio[1].txt 72704 .a.. r/rr-xr-xr-x 0 0 2522-128-3 /WINDOWS/system32/hlink.dll 35840 .a.. r/rr-xr-xr-x 0 0 2554-128-3 /WINDOWS/system32/imgutil.dll 449024 .a.. r/rr-xr-xr-x 0 0 2741-128-3 /WINDOWS/system32/mshtmled.dll 39424 .a.. r/rr-xr-xr-x 0 0 2913-128-3 /WINDOWS/system32/pngfilt.dll Fri Jul 01 2011 15:08:10 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/38a/445/38a4455f2ab8b48ae8b7989684b9fefbe86a74c4.jpg?url=http://origin.psstatic.podshow.com/images/shows/19560/episodes/286382/large/meviomusicvideos-us-e.jpg?r=1309284353&width=200&height=112&scheme=1 cache stored in: UPQVMROL/38a4455f2ab8b48ae8b7989684b9fefbe86a74c4[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 10750 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/576/402/576402c013369ada43b03805b1ee8f85efe6bab2.jpg?url=http://origin.psstatic.podshow.com/images/shows/19560/episodes/285203/large/meviomusicvideos-us-e.jpg?r=1308348460&width=200&height=112&scheme=1 cache stored in: UPQVMROL/576402c013369ada43b03805b1ee8f85efe6bab2[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 9401 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/5a4/580/5a458020a8c95e20363153d191a0748701307b5a.jpg?url=http://origin.psstatic.podshow.com/images/shows/19560/episodes/286410/large/meviomusicvideos-us-e.jpg?r=1309297607&width=200&height=112&scheme=1 cache stored in: UPQVMROL/5a458020a8c95e20363153d191a0748701307b5a[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 11756 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/5be/046/5be046bbf1571cbc0992bf977c4aeb36fe0bbfe2.jpg?url=http://origin.psstatic.podshow.com/images/shows/19560/episodes/285204/large/meviomusicvideos-us-e.jpg?r=1308349122&width=200&height=112&scheme=1 cache stored in: YZCXGNW1/5be046bbf1571cbc0992bf977c4aeb36fe0bbfe2[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 11857 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/6e6/a01/6e6a0112e4c93ee32e29655c48de42b3f0d7b310.jpg?url=http://origin.psstatic.podshow.com/images/shows/19560/episodes/286375/large/meviomusicvideos-us-e.jpg?r=1309281211&width=200&height=112&scheme=1 cache stored in: SLK18LSF/6e6a0112e4c93ee32e29655c48de42b3f0d7b310[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 11391 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/70c/4ea/70c4ea8c569d118f0d0058b9beea05a469166b2a.jpg?url=http://origin.psstatic.podshow.com/images/shows/19560/episodes/286216/large/meviomusicvideos-us-e.jpg?r=1309194443&width=200&height=112&scheme=1 cache stored in: SLK18LSF/70c4ea8c569d118f0d0058b9beea05a469166b2a[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 8028 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/9cc/492/9cc4923ca535dba1931fa11b1f6bd84dcc7e6dc9.jpg?url=http://origin.psstatic.podshow.com/images/shows/19560/episodes/286018/large/meviomusicvideos-us-e.jpg?r=1308962688&width=200&height=112&scheme=1 cache stored in: UPQVMROL/9cc4923ca535dba1931fa11b1f6bd84dcc7e6dc9[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 10036 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/a80/ca0/a80ca036690e47436bec21d0d63ccfc3c17d4552.png?url=http://origin.psstatic.podshow.com/images/shows/19560/episodes/285198/large/meviomusicvideos-us-e.png?r=1308758741&width=200&height=112&scheme=1 cache stored in: QJM5KT6J/a80ca036690e47436bec21d0d63ccfc3c17d4552[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 35293 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/ad5/164/ad51643e2a4d3bc8ed990def3267b92603dbd754.jpg?url=http://origin.psstatic.podshow.com/images/shows/19560/episodes/286203/large/meviomusicvideos-us-e.jpg?r=1309184585&width=200&height=112&scheme=1 cache stored in: YZCXGNW1/ad51643e2a4d3bc8ed990def3267b92603dbd754[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 10893 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/cec/453/cec453d28b67092f80601ab4e425a38c43ef51b2.jpg?url=http://origin.psstatic.podshow.com/images/shows/19560/episodes/285663/large/meviomusicvideos-us-e.jpg?r=1308703343&width=200&height=112&scheme=1 cache stored in: YZCXGNW1/cec453d28b67092f80601ab4e425a38c43ef51b2[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 10030 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/fb1/df8/fb1df8b71f80b980a70d8f0f7b7e19a553978da8.jpg?url=http://origin.psstatic.podshow.com/images/shows/19560/episodes/286218/large/meviomusicvideos-us-e.jpg?r=1309195367&width=200&height=112&scheme=1 cache stored in: QJM5KT6J/fb1df8b71f80b980a70d8f0f7b7e19a553978da8[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 10998 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/1799/shows/thumbs/fullerecords.jpg?r=1160926022 cache stored in: YZCXGNW1/fullerecords[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2278 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/19560/shows/thumbs/meviomusicvideos.png?r=1241165388 cache stored in: QJM5KT6J/meviomusicvideos[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 7135 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/22047/shows/thumbs/cattitude.jpg?r=1282942633 cache stored in: UPQVMROL/cattitude[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3170 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/10014/gallery/thumbs/6024.jpg cache stored in: YZCXGNW1/6024[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3723 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/1097/gallery/thumbs/avatar.png cache stored in: SLK18LSF/avatar[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 9948 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/1217/gallery/thumbs/274367.jpg cache stored in: UPQVMROL/274367[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3697 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/12733/gallery/thumbs/7601.jpg cache stored in: YZCXGNW1/7601[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 4140 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/13460/gallery/thumbs/21042.jpg cache stored in: QJM5KT6J/21042[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2720 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/17251/gallery/thumbs/12129.jpg cache stored in: SLK18LSF/12129[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3471 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/194/gallery/thumbs/avatar.png cache stored in: QJM5KT6J/avatar[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 11896 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/201/gallery/thumbs/407.jpg cache stored in: SLK18LSF/407[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3060 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/2098/gallery/thumbs/avatar.png cache stored in: YZCXGNW1/avatar[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 8731 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/300/gallery/thumbs/8683.jpg cache stored in: SLK18LSF/8683[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2595 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/3434/gallery/thumbs/2372.jpg cache stored in: YZCXGNW1/2372[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2931 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/3458/gallery/thumbs/183998.jpg cache stored in: UPQVMROL/183998[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3284 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/357975/gallery/med/169203.jpg cache stored in: QJM5KT6J/169203[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 21303 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/554/gallery/thumbs/646.jpg cache stored in: QJM5KT6J/646[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2364 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/68834/gallery/thumbs/42861.jpg cache stored in: YZCXGNW1/42861[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2705 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/8292/gallery/thumbs/5205.png cache stored in: UPQVMROL/5205[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 7467 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://static.podshow.com/profiles/BackgroundFiles/MEVIOmusic.jpg cache stored in: SLK18LSF/MEVIOmusic[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 137195 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/us/images/defaults/shows/thumbs/default.jpg cache stored in: QJM5KT6J/default[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 18913 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 58767 .a.. r/rr-xr-xr-x 0 0 11207-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/PromoRollV4[1].jpg 1222 .a.. r/rr-xr-xr-x 0 0 11220-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/default[1].jpg 5130 .a.. r/rr-xr-xr-x 0 0 11221-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/showicons[1].png 2705 .a.. r/rr-xr-xr-x 0 0 11224-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/42861[1].jpg 2901 .a.. r/rr-xr-xr-x 0 0 11226-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/4197dfa1f28d2d77f56f6f8e1eb334e36a0bd5a6[1].jpg 3471 .a.. r/rr-xr-xr-x 0 0 11227-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/12129[1].jpg 2931 .a.. r/rr-xr-xr-x 0 0 11245-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/2372[1].jpg 7011 .a.. r/rr-xr-xr-x 0 0 11255-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/hotoff-us-e[1].jpg 794 .a.. r/rr-xr-xr-x 0 0 11257-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/joinNow25high[1].gif 20356 .a.. r/rr-xr-xr-x 0 0 11258-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/tpl_player[2].js 3493 .a.. r/rr-xr-xr-x 0 0 11260-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tpl_comments[2].js 78342 .a.. r/rr-xr-xr-x 0 0 11268-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tpl_htdocs[1].js 65677 .a.. r/rr-xr-xr-x 0 0 11269-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/tpl_shows[2].js 18913 .a.. r/rr-xr-xr-x 0 0 11409-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/default[1].jpg 7467 .a.. r/rr-xr-xr-x 0 0 11432-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/5205[1].png 4140 .a.. r/rr-xr-xr-x 0 0 11438-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/7601[1].jpg 10998 ma.b r/rr-xr-xr-x 0 0 11573-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/fb1df8b71f80b980a70d8f0f7b7e19a553978da8[1].jpg 11756 ma.b r/rr-xr-xr-x 0 0 11602-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/5a458020a8c95e20363153d191a0748701307b5a[1].jpg 10750 ma.b r/rr-xr-xr-x 0 0 11605-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/38a4455f2ab8b48ae8b7989684b9fefbe86a74c4[1].jpg 137195 ma.b r/rr-xr-xr-x 0 0 11609-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/MEVIOmusic[1].jpg 11391 ma.b r/rr-xr-xr-x 0 0 11610-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/6e6a0112e4c93ee32e29655c48de42b3f0d7b310[1].jpg 9948 ma.b r/rr-xr-xr-x 0 0 11619-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/avatar[1].png 8028 ma.b r/rr-xr-xr-x 0 0 11620-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/70c4ea8c569d118f0d0058b9beea05a469166b2a[1].jpg 3060 ma.b r/rr-xr-xr-x 0 0 11650-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/407[1].jpg 2734 ma.b r/rr-xr-xr-x 0 0 11652-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/photo_default[1].jpg 8731 ma.b r/rr-xr-xr-x 0 0 11653-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/avatar[1].png 10893 ma.b r/rr-xr-xr-x 0 0 11654-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/ad51643e2a4d3bc8ed990def3267b92603dbd754[1].jpg 10036 ma.b r/rr-xr-xr-x 0 0 11655-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/9cc4923ca535dba1931fa11b1f6bd84dcc7e6dc9[1].jpg 5012 ma.b r/rr-xr-xr-x 0 0 11657-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/mevio-megahit[1].jpg 2720 ma.b r/rr-xr-xr-x 0 0 11658-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/21042[1].jpg 3284 ma.b r/rr-xr-xr-x 0 0 11659-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/183998[1].jpg 11896 ma.b r/rr-xr-xr-x 0 0 11660-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/avatar[1].png 10030 ma.b r/rr-xr-xr-x 0 0 11661-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/cec453d28b67092f80601ab4e425a38c43ef51b2[1].jpg 11857 ma.b r/rr-xr-xr-x 0 0 11662-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/5be046bbf1571cbc0992bf977c4aeb36fe0bbfe2[1].jpg 3723 ma.b r/rr-xr-xr-x 0 0 11663-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/6024[1].jpg 9401 ma.b r/rr-xr-xr-x 0 0 11664-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/576402c013369ada43b03805b1ee8f85efe6bab2[1].jpg 3697 ma.b r/rr-xr-xr-x 0 0 11665-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/274367[1].jpg 35293 ma.b r/rr-xr-xr-x 0 0 11666-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/a80ca036690e47436bec21d0d63ccfc3c17d4552[1].png 2364 ma.b r/rr-xr-xr-x 0 0 11667-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/646[1].jpg 2595 ma.b r/rr-xr-xr-x 0 0 11668-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/8683[1].jpg 7135 ma.b r/rr-xr-xr-x 0 0 11669-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/meviomusicvideos[1].png 21303 ma.b r/rr-xr-xr-x 0 0 11670-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/169203[1].jpg 3170 ma.b r/rr-xr-xr-x 0 0 11671-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/cattitude[1].jpg 2278 ma.b r/rr-xr-xr-x 0 0 11672-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/fullerecords[1].jpg 58880 .a.. r/rr-xr-xr-x 0 0 2053-128-3 /WINDOWS/system32/atl.dll 477 .a.. r/rr-xr-xr-x 0 0 224-128-1 /WINDOWS/win.ini 8704 .a.. r/rr-xr-xr-x 0 0 2351-128-3 /WINDOWS/system32/dciman32.dll 279552 .a.. r/rr-xr-xr-x 0 0 2353-128-3 /WINDOWS/system32/ddraw.dll 27136 .a.. r/rr-xr-xr-x 0 0 2354-128-3 /WINDOWS/system32/ddrawex.dll 357888 .a.. r/rr-xr-xr-x 0 0 2441-128-3 /WINDOWS/system32/dxtmsft.dll 205312 .a.. r/rr-xr-xr-x 0 0 2442-128-3 /WINDOWS/system32/dxtrans.dll 81000 .a.. r/rr-xr-xr-x 0 0 274-128-3 /WINDOWS/Fonts/wingding.ttf 689152 .a.. r/rr-xr-xr-x 0 0 3339-128-3 /WINDOWS/system32/xpsp3res.dll 93184 .a.. r/rr-xr-xr-x 0 0 5615-128-3 /Program Files/Internet Explorer/IEXPLORE.EXE Fri Jul 01 2011 15:08:11 950 .a.. r/rr-xr-xr-x 0 0 11272-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/dropdown-arrows[2].png 3681 .a.. r/rr-xr-xr-x 0 0 11279-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/player-icons[2].png 3320 .a.. r/rr-xr-xr-x 0 0 6834-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/mevio-m-neverback-24x24[1].gif Fri Jul 01 2011 15:08:12 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://meviomusicvideos.mevio.com/rest/facebook/xd_receiver.php cache stored in: YZCXGNW1/xd_receiver[2].htm - HTTP/1.1 200 OK - Content-Length: 591 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.facebook.com/extern/login_status.php?api_key=c99345b4de38e993c64ef4654ac9164b&extern=2&channel=http://meviomusicvideos.mevio.com/rest/facebook/xd_receiver.php&locale=en_US cache stored in: YZCXGNW1/login_status[2].htm - HTTP/1.1 200 OK - Content-Length: 1188 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:meviomusicvideos.mevio.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 665 .a.. r/rr-xr-xr-x 0 0 11192-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/client_restserver[1].htm 18453 ma.b r/rr-xr-xr-x 0 0 11273-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/en_US[1] 14288 ma.b r/rr-xr-xr-x 0 0 11278-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/connect-css[1].css 3386 .a.. r/rr-xr-xr-x 0 0 11286-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/XdCommReceiver[2].js 18453 .a.. r/rr-xr-xr-x 0 0 11401-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/connect[2].php 346 ma.. r/rr-xr-xr-x 0 0 11513-128-1 /Documents and Settings/malware/Cookies/malware@meviomusicvideos.mevio[1].txt 591 ma.b r/rr-xr-xr-x 0 0 11611-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/xd_receiver[2].htm 211318 ma.b r/rr-xr-xr-x 0 0 11651-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/XFBML[2] 1188 ma.b r/rr-xr-xr-x 0 0 11673-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/login_status[2].htm Fri Jul 01 2011 15:08:16 0 m... 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:quantserve.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 m... 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:tap2-cdn.rubiconproject.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 92 .a.. r/rr-xr-xr-x 0 0 11289-128-1 /Documents and Settings/malware/Cookies/malware@quantserve[1].txt 297 .a.. r/rr-xr-xr-x 0 0 11303-128-1 /Documents and Settings/malware/Cookies/malware@tap2-cdn.rubiconproject[1].txt 12576 .a.. r/rr-xr-xr-x 0 0 11339-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/tags[2].js 60 .a.. r/rr-xr-xr-x 0 0 11342-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/displayAd[2].js 2034 ma.b r/rr-xr-xr-x 0 0 11546-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/26270-2[3].js 423 ma.b r/rr-xr-xr-x 0 0 11677-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CAAV0DMX.ad 171792 .a.. r/rr-xr-xr-x 0 0 2171-128-3 /WINDOWS/Fonts/verdana.ttf 137616 .a.. r/rr-xr-xr-x 0 0 275-128-3 /WINDOWS/Fonts/verdanab.ttf Fri Jul 01 2011 15:08:17 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cheetah.vizu.com/a.gif?cid=2073_adid=728x90_siteid=tribalfusion_adtype=1_stype=0_siteurl=a.tribalfusion.com_wc=_cust1=_cust2=_cust3=_cust4=_cust5=_ver=v5_o=winxp_ua=msie_uv=6.0_lan=en-us_fv=null_id=1309558097515_t=1309558097531 cache stored in: YZCXGNW1/a[1].gif - HTTP/1.1 200 OK - X-Px: ht lax-am6-n17.panthercdn.com - ETag: "3c04c-2b-edb95b80" - Content-Length: 43 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cheetah.vizu.com/f.gif?cd=4_cid=2073_adid=728x90_siteid=tribalfusion_adtype=1_stype=0_siteurl=a.tribalfusion.com_wc=_cust1=_cust2=_cust3=_cust4=_cust5=_ver=v5_o=winxp_ua=msie_uv=6.0_lan=en-us_fv=null_id=1309558097515_t=1309558097531f.gif?cid=2073_adid=728x90_siteid=tribalfusion_adtype=1_stype=0_siteurl=a.tribalfusion.com_wc=_cust1=_cust2=_cust3=_cust4=_cust5=_ver=v5_o=winxp_ua=msie_uv=6.0_lan=en-us_fv=null_id=1309558097515_t=1309558097531 cache stored in: YZCXGNW1/CA7ULCDX.gif - HTTP/1.1 200 OK - X-Px: ht lax-am6-n17.panthercdn.com - ETag: "3c050-2b-edb95b80" - Content-Length: 43 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cheetah.vizu.com/i.gif?cid=2073_adid=728x90_siteid=tribalfusion_adtype=1_stype=0_siteurl=a.tribalfusion.com_wc=_cust1=_cust2=_cust3=_cust4=_cust5=_ver=v5_o=winxp_ua=msie_uv=6.0_lan=en-us_fv=null_id=1309558097515_t=1309558097531 cache stored in: UPQVMROL/i[1].gif - HTTP/1.1 200 OK - X-Px: ht lax-am6-n17.panthercdn.com - ETag: "3c051-2b-775728c0" - Content-Length: 43 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ds.serving-sys.com/BurstingCachedScripts//SBTemplates_2_3_2/StdBanner.js?ai=5627997 cache stored in: SLK18LSF/StdBanner[2].js - HTTP/1.1 200 OK - Content-Length: 24385 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ds.serving-sys.com/BurstingRes///Site-7247/Type-0/118ed178-986a-4c57-9d20-0870639fdad0.jpg cache stored in: YZCXGNW1/118ed178-986a-4c57-9d20-0870639fdad0[1].jpg - HTTP/1.1 200 OK - Content-Length: 32284 - Content-Type: image/jpeg (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://puma.vizu.com/cdn/00/00/20/73/tracking_only.js?adid=728x90_siteid=tribalfusion_ord=[RANDOM] cache stored in: UPQVMROL/tracking_only[2].js - HTTP/1.1 200 OK - Content-Length: 7905 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) User: http://b3.mookie1.com/2/TribalFusionB3/Motorola/2011Q2_Atrix/CN/728/11226746971 URL:x90 cache stored in: SLK18LSF/11226746971@x90[1].htm - HTTP/1.1 200 OK - P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA"-policyref="/w3c/p3p.xml" - Content-Length: 520 - Keep-Alive: timeout=60 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:mookie1.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 m... 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:r1-ads.ace.advertising.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 3447 .a.. r/rr-xr-xr-x 0 0 11253-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/beacon[2].js 136 .a.. r/rr-xr-xr-x 0 0 11288-128-1 /Documents and Settings/malware/Cookies/malware@r1-ads.ace.advertising[1].txt 6621 .a.. r/rr-xr-xr-x 0 0 11297-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/emily[1].htm 15168 .a.. r/rr-xr-xr-x 0 0 11315-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/aceUAC[1].js 32284 .a.. r/rr-xr-xr-x 0 0 11359-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/118ed178-986a-4c57-9d20-0870639fdad0[1].jpg 24385 .a.. r/rr-xr-xr-x 0 0 11360-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/StdBanner[2].js 688 m..b r/rr-xr-xr-x 0 0 11361-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/imp[5] 7905 .a.. r/rr-xr-xr-x 0 0 11365-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tracking_only[2].js 2199 ma.b r/rr-xr-xr-x 0 0 11680-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26271-15[3].js 2571 ma.b r/rr-xr-xr-x 0 0 11682-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CASLYJYZ.htm 2322 ma.b r/rr-xr-xr-x 0 0 11683-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26271-2[2].js 43 ma.b r/rr-xr-xr-x 0 0 11684-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/a[1].gif 43 ma.b r/rr-xr-xr-x 0 0 11685-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/i[1].gif 467 ma.b r/rr-xr-xr-x 0 0 11686-128-1 /Documents and Settings/malware/Cookies/malware@mookie1[2].txt 43 ma.b r/rr-xr-xr-x 0 0 11687-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CA7ULCDX.gif 520 ma.b r/rr-xr-xr-x 0 0 11688-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/11226746971@x90[1].htm Fri Jul 01 2011 15:08:18 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cdn.doubleverify.com/script201.js?agnc=796803&cmp=947466&crt=&crtname=&adnet=&dvtagver=3.3.1346.2176&adsrv=6&plc=2895815&advid=796804&sid=Fox Audience Network&adid= cache stored in: YZCXGNW1/script201[2].js - HTTP/1.1 200 OK - Content-Length: 2914 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ds.serving-sys.com/BurstingCachedScripts//SBTemplates_2_3_2/StdBanner.js?ai=5823404 cache stored in: UPQVMROL/StdBanner[3].js - HTTP/1.1 200 OK - Content-Length: 24385 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ds.serving-sys.com/BurstingRes///Site-15895/Type-0/e9d2c6f5-3580-49dd-bdc0-2e403a7d2856.jpg cache stored in: QJM5KT6J/e9d2c6f5-3580-49dd-bdc0-2e403a7d2856[1].jpg - HTTP/1.1 200 OK - Content-Length: 38232 - Content-Type: image/jpeg (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://log30.doubleverify.com/visitor.aspx?query=agnc=796803&cmp=947466&crt=&crtname=&adnet=&dvtagver=3.3.1346.2176&adsrv=6&plc=2895815&advid=796804&sid=Fox%20Audience%20Network&adid=&&num=201&srcurl=http://meviomusicvideos.mevio.com/?utm_source=4178c3&utm_campaign=4178c3_217-23507-1&utm_medium=cpc&random=0.94710254720234 cache stored in: YZCXGNW1/CAQR0LMZ.jpg - HTTP/1.1 200 OK - Content-Length: 0 - Content-Type: image/jpeg - X-AspNet-Version: 2.0.50727 - X-Powered-By: ASP.NET (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pixel.rubiconproject.com/tap.php?v=6073&nid=2100&expires=30&put=usr3fe2dc1c4a07ca8b cache stored in: SLK18LSF/tap[2].gif - HTTP/1.1 200 OK - X-Powered-By: PHP/5.1.6 - P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" - Content-Length: 49 - Keep-Alive: timeout=45- max=324 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) User: http://dm.de.mookie1.com/2/B3DM/2010DM/11243369564 URL:x23?USNetwork/Moto_2011Q2_Atrix_TF_CN_728 cache stored in: YZCXGNW1/11243369564@x23[1].htm - HTTP/1.1 200 OK - P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA"-policyref="/w3c/p3p.xml" - Content-Length: 2421 - Keep-Alive: timeout=60 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:b3.mookie1.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:delb.opt.fimserve.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:netseer.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:opt.fimserve.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:serving-sys.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 430 ma.. r/rr-xr-xr-x 0 0 11337-128-1 /Documents and Settings/malware/Cookies/malware@serving-sys[1].txt 688 .a.. r/rr-xr-xr-x 0 0 11361-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/imp[5] 138 ma.b r/rr-xr-xr-x 0 0 11369-128-1 /Documents and Settings/malware/Cookies/malware@netseer[1].txt 2914 .a.. r/rr-xr-xr-x 0 0 11405-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/script201[2].js 2793 .a.. r/rr-xr-xr-x 0 0 11500-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/aceUACping[1].htm 87 ma.b r/rr-xr-xr-x 0 0 11527-128-1 /Documents and Settings/malware/Cookies/malware@b3.mookie1[2].txt 1016 ma.b r/rr-xr-xr-x 0 0 11530-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/adopt[4].htm 38232 ma.b r/rr-xr-xr-x 0 0 11538-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/e9d2c6f5-3580-49dd-bdc0-2e403a7d2856[1].jpg 479 ma.b r/rr-xr-xr-x 0 0 11606-128-1 /Documents and Settings/malware/Cookies/malware@opt.fimserve[2].txt 2951 ma.b r/rr-xr-xr-x 0 0 11612-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CA2FG5QT.htm 115 ma.b r/rr-xr-xr-x 0 0 11616-128-1 /Documents and Settings/malware/Cookies/malware@delb.opt.fimserve[2].txt 49 ma.. r/rr-xr-xr-x 0 0 11691-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/tap[2].gif 2421 ma.b r/rr-xr-xr-x 0 0 11693-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/11243369564@x23[1].htm 24385 ma.b r/rr-xr-xr-x 0 0 11695-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/StdBanner[3].js 0 ma.b r/rr-xr-xr-x 0 0 11696-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CAQR0LMZ.jpg Fri Jul 01 2011 15:08:40 3067866 ma.. r/rr-xr-xr-x 0 0 11447-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/swflash[1].cab 208384 .a.. r/rr-xr-xr-x 0 0 2014-128-3 /WINDOWS/system32/rsaenh.dll Fri Jul 01 2011 15:08:41 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/SystemCertificates 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/SystemCertificates/TrustedPublisher 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/SystemCertificates/TrustedPublisher/CRLs 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/SystemCertificates/TrustedPublisher/CTLs 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/SystemCertificates/TrustedPublisher/Certificates 0 m... 0 0 0 0 REG_User_malware/Software/Policies/Microsoft/SystemCertificates 0 m... 0 0 0 0 REG_User_malware/Software/Policies/Microsoft/SystemCertificates/TrustedPublisher 0 m... 0 0 0 0 REG_User_malware/Software/Policies/Microsoft/SystemCertificates/TrustedPublisher/CRLs 0 m... 0 0 0 0 REG_User_malware/Software/Policies/Microsoft/SystemCertificates/TrustedPublisher/CTLs 0 m... 0 0 0 0 REG_User_malware/Software/Policies/Microsoft/SystemCertificates/TrustedPublisher/Certificates 56 m... d/dr-xr-xr-x 0 0 10461-144-6 /Documents and Settings/malware/Local Settings/Temp 60416 .a.. r/rr-xr-xr-x 0 0 2006-128-3 /WINDOWS/system32/cabinet.dll 461672 .a.. r/rr-xr-xr-x 0 0 2027-128-3 /WINDOWS/Fonts/micross.ttf 64512 .a.. r/rr-xr-xr-x 0 0 2145-128-3 /WINDOWS/system32/cryptnet.dll 35328 .a.. r/rr-xr-xr-x 0 0 2330-128-3 /WINDOWS/system32/corpol.dll 354304 .a.. r/rr-xr-xr-x 0 0 3169-128-3 /WINDOWS/system32/winhttp.dll 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) crypt32/1_Info_CN=VeriSign Class 3 Public Primary Certification Authority - G5- OU="(c) 2006 VeriSign- Inc. - For authorized use only"- OU=VeriSign Trust Network- O="VeriSign- Inc."- C=US - 4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5 (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) 65536 macb 0 0 0 3659 [Event Log] (Time generated/Time written) crypt32/4_Info_http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5.crt (file: /media/sdb1/WINDOWS/system32/config/AppEvent.Evt) Fri Jul 01 2011 15:08:55 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://edge.quantserve.com/quant.js cache stored in: QJM5KT6J/quant[1].js - HTTP/1.1 200 OK - Content-Length: 5265 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) Fri Jul 01 2011 15:08:56 16896 .a.. r/rr-xr-xr-x 0 0 2078-128-3 /WINDOWS/system32/stdole2.tlb 43520 .a.. r/rr-xr-xr-x 0 0 5780-128-3 /WINDOWS/system32/racpldlg.dll Fri Jul 01 2011 15:08:58 152 m..b d/d--x--x--x 0 0 10300-144-1 /Documents and Settings/malware/Recent 150 macb r/rr-xr-xr-x 0 0 10301-128-1 /Documents and Settings/malware/Recent/Desktop.ini 376 .a.. d/drwxrwxrwx 0 0 10404-144-1 /Documents and Settings/All Users/Application Data/Microsoft/Crypto/RSA/S-1-5-18 0 macb 0 0 0 10413 [XP Prefetch] (Last run) ATTRIB.EXE-39EAFB02.pf - [ATTRIB.EXE] was executed - run count [21]- full path: [] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/ULIB.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/COMCTL32.DLL} (file: /media/sdb1/WINDOWS/Prefetch/ATTRIB.EXE-39EAFB02.pf) 56 m... d/dr-xr-xr-x 0 0 10436-144-5 /Documents and Settings/malware 6976 ..c. r/rr-xr-xr-x 0 0 10617-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/malware.bmp 452608 ..c. r/rr-xr-xr-x 0 0 10650-128-4 /Documents and Settings/All Users/Application Data/VDPLtsHLVdsd.exe 6976 ..c. r/rr-xr-xr-x 0 0 11142-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/user1.bmp 6976 ..c. r/rr-xr-xr-x 0 0 11143-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/user2.bmp 6976 ..c. r/rr-xr-xr-x 0 0 11144-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/user3.bmp 372736 ..c. r/rr-xr-xr-x 0 0 11166-128-3 /Documents and Settings/All Users/Application Data/14147364.exe 336 ..c. r/rr-xr-xr-x 0 0 11168-128-1 /Documents and Settings/All Users/Application Data/14147364 232 ..c. r/rr-xr-xr-x 0 0 11173-128-4 /Documents and Settings/All Users/Application Data/~14147364 168 ..c. r/rr-xr-xr-x 0 0 11174-128-1 /Documents and Settings/All Users/Application Data/~14147364r 706048 .a.. r/rr-xr-xr-x 0 0 1931-128-3 /WINDOWS/system32/ntdll.dll 617472 .a.. r/rr-xr-xr-x 0 0 1936-128-3 /WINDOWS/system32/advapi32.dll 285184 .a.. r/rr-xr-xr-x 0 0 1938-128-3 /WINDOWS/system32/gdi32.dll 989696 .a.. r/rr-xr-xr-x 0 0 1940-128-3 /WINDOWS/system32/kernel32.dll 1287168 .a.. r/rr-xr-xr-x 0 0 1941-128-3 /WINDOWS/system32/ole32.dll 551936 .a.. r/rr-xr-xr-x 0 0 1942-128-3 /WINDOWS/system32/oleaut32.dll 584704 .a.. r/rr-xr-xr-x 0 0 1945-128-3 /WINDOWS/system32/rpcrt4.dll 8461312 .a.. r/rr-xr-xr-x 0 0 1946-128-3 /WINDOWS/system32/shell32.dll 578560 .a.. r/rr-xr-xr-x 0 0 1949-128-3 /WINDOWS/system32/user32.dll 18944 .a.. r/rr-xr-xr-x 0 0 1950-128-3 /WINDOWS/system32/version.dll 474112 .a.. r/rr-xr-xr-x 0 0 1953-128-3 /WINDOWS/system32/shlwapi.dll 617472 .a.. r/rr-xr-xr-x 0 0 1954-128-3 /WINDOWS/system32/comctl32.dll 343040 .a.. r/rr-xr-xr-x 0 0 1955-128-3 /WINDOWS/system32/msvcrt.dll 727040 .a.. r/rr-xr-xr-x 0 0 1960-128-3 /WINDOWS/system32/userenv.dll 56320 .a.. r/rr-xr-xr-x 0 0 1973-128-3 /WINDOWS/system32/secur32.dll 176128 .a.. r/rr-xr-xr-x 0 0 2010-128-3 /WINDOWS/system32/winmm.dll 218624 .a.. r/rr-xr-xr-x 0 0 2030-128-3 /WINDOWS/system32/uxtheme.dll 71680 .a.. r/rr-xr-xr-x 0 0 2039-128-3 /WINDOWS/system32/msacm32.dll 275456 .a.. r/rr-xr-xr-x 0 0 2112-128-3 /WINDOWS/system32/ulib.dll 1852928 .a.. r/rr-xr-xr-x 0 0 2193-128-3 /WINDOWS/AppPatch/AcGenral.dll 12288 .a.. r/rr-xr-xr-x 0 0 2267-128-3 /WINDOWS/system32/attrib.exe 65024 .a.. r/rr-xr-xr-x 0 0 3012-128-3 /WINDOWS/system32/shimeng.dll 1054208 .a.. r/rr-xr-xr-x 0 0 3705-128-3 /WINDOWS/WinSxS/x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83/comctl32.dll 1862 .a.. r/rr-xr-xr-x 0 0 3707-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83.Manifest 621 .a.. r/rr-xr-xr-x 0 0 3710-128-4 /WINDOWS/WinSxS/Policies/x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775/6.0.2600.5512.Policy 56 .a.. d/d--x--x--x 0 0 3736-144-6 /Documents and Settings/All Users/Application Data 224 .a.. d/drwxrwxrwx 0 0 3738-144-1 /Documents and Settings/All Users/Application Data/Microsoft/Crypto 360 .a.. d/drwxrwxrwx 0 0 3739-144-1 /Documents and Settings/All Users/Application Data/Microsoft/Crypto/RSA 48 .a.. d/drwxrwxrwx 0 0 3740-144-1 /Documents and Settings/All Users/Application Data/Microsoft/Crypto/RSA/MachineKeys 256 .a.. d/drwxrwxrwx 0 0 3741-144-1 /Documents and Settings/All Users/Application Data/Microsoft/Crypto/DSS 48 .a.. d/drwxrwxrwx 0 0 3742-144-1 /Documents and Settings/All Users/Application Data/Microsoft/Crypto/DSS/MachineKeys 256 .ac. d/dr-xr-xr-x 0 0 4211-144-1 /Documents and Settings/All Users/Application Data/Microsoft/Network 224 .ac. d/dr-xr-xr-x 0 0 4846-144-1 /Documents and Settings/All Users/Application Data/Microsoft/Network/Connections 280 .ac. d/dr-xr-xr-x 0 0 4847-144-1 /Documents and Settings/All Users/Application Data/Microsoft/Network/Connections/Pbk 853 ..c. r/rr-xr-xr-x 0 0 4849-128-3 /Documents and Settings/All Users/Application Data/Microsoft/Network/Connections/Pbk/sharedaccess.ini 48 .ac. d/dr-xr-xr-x 0 0 4858-144-1 /Documents and Settings/All Users/Application Data/Microsoft/Network/Connections/Cm 789 ..c. r/rr-xr-xr-x 0 0 6084-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA/Plylst11.wpl 1451 ..c. r/rr-xr-xr-x 0 0 6085-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA/Plylst12.wpl 783 ..c. r/rr-xr-xr-x 0 0 6086-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA/Plylst13.wpl 775 ..c. r/rr-xr-xr-x 0 0 6087-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA/Plylst14.wpl 56 .ac. d/dr-xr-xr-x 0 0 6199-144-6 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures 56 .ac. d/dr-xr-xr-x 0 0 6200-144-6 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures 6968 ..c. r/rr-xr-xr-x 0 0 6201-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/airplane.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6202-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/astronaut.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6203-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/ball.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6204-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/butterfly.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6205-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/cat.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6206-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/fish.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6207-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/pink flower.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6208-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/guitar.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6209-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/snowflake.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6210-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/beach.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6211-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/car.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6212-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/chess.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6213-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/dirt bike.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6214-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/dog.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6215-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/drip.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6216-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/duck.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6217-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/frog.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6218-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/horses.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6219-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/kick.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6220-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/lift-off.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6221-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/palm tree.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6222-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/red flower.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6223-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/Default Pictures/skater.bmp 6968 ..c. r/rr-xr-xr-x 0 0 6224-128-3 /Documents and Settings/All Users/Application Data/Microsoft/User Account Pictures/guest.bmp 56 .a.. d/d--x--x--x 0 0 6258-144-6 /Documents and Settings/All Users/Documents/My Music/Sample Music 613638 ..c. r/rr-xr-xr-x 0 0 6259-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Music/Beethoven's Symphony No. 9 (Scherzo).wma 760748 ..c. r/rr-xr-xr-x 0 0 6260-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Music/New Stories (Highway Blues).wma 749 .a.. r/r--x--x--x 0 0 6559-128-4 /WINDOWS/WindowsShell.Manifest 787 ..c. r/rr-xr-xr-x 0 0 7552-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA/Plylst10.wpl 48 .ac. d/dr-xr-xr-x 0 0 7556-144-1 /Documents and Settings/All Users/Application Data/Microsoft/Media Index 56 .a.. d/dr-xr-xr-x 0 0 7557-144-5 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA 1250 ..c. r/rr-xr-xr-x 0 0 7558-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA/Plylst1.wpl 536 .ac. d/dr-xr-xr-x 0 0 7559-144-1 /Documents and Settings/All Users/Application Data/Microsoft/Media Player 48 .a.. d/dr-xr-xr-x 0 0 7562-144-1 /Documents and Settings/All Users/Documents/My Music/My Playlists 720896 ..c. r/r--x--x--x 0 0 7563-128-4 /Documents and Settings/All Users/Application Data/Microsoft/Media Player/DefaultStore_59R.bin 720896 ..c. r/r--x--x--x 0 0 7564-128-4 /Documents and Settings/All Users/Application Data/Microsoft/Media Player/UserMigratedStore_59R.bin 48 .ac. d/dr-xr-xr-x 0 0 7604-144-1 /Documents and Settings/All Users/Application Data/Microsoft/HTML Help Fri Jul 01 2011 15:08:59 402432 ..c. r/rr-xr-xr-x 0 0 10000-128-1 /WINDOWS/system32/dllcache/wmm2filt.dll 502272 ..c. r/rr-xr-xr-x 0 0 10001-128-1 /WINDOWS/system32/dllcache/wmm2fxa.dll 325632 ..c. r/rr-xr-xr-x 0 0 10002-128-1 /WINDOWS/system32/dllcache/wmm2fxb.dll 4256768 ..c. r/rr-xr-xr-x 0 0 10003-128-1 /WINDOWS/system32/dllcache/wmm2res.dll 5632 ..c. r/rr-xr-xr-x 0 0 10004-128-1 /WINDOWS/system32/dllcache/wmm2res2.dll 1053184 ..c. r/rr-xr-xr-x 0 0 10005-128-1 /WINDOWS/system32/dllcache/wmnetmgr.dll 4874240 ..c. r/rr-xr-xr-x 0 0 10006-128-1 /WINDOWS/system32/dllcache/wmp.dll 20480 ..c. r/rr-xr-xr-x 0 0 10007-128-1 /WINDOWS/system32/dllcache/wmp.ocx 114688 ..c. r/rr-xr-xr-x 0 0 10008-128-1 /WINDOWS/system32/dllcache/wmpasf.dll 98304 ..c. r/rr-xr-xr-x 0 0 10009-128-1 /WINDOWS/system32/dllcache/wmpband.dll 15245 ..c. r/rr-xr-xr-x 0 0 1001-128-3 /WINDOWS/Help/msorcl32.chm 20480 ..c. r/rr-xr-xr-x 0 0 10010-128-1 /WINDOWS/system32/dllcache/wmpcd.dll 20480 ..c. r/rr-xr-xr-x 0 0 10011-128-1 /WINDOWS/system32/dllcache/wmpcore.dll 233472 ..c. r/rr-xr-xr-x 0 0 10012-128-1 /WINDOWS/system32/dllcache/wmpdxm.dll 73728 ..c. r/rr-xr-xr-x 0 0 10013-128-1 /WINDOWS/system32/dllcache/wmplayer.exe 2940928 ..c. r/rr-xr-xr-x 0 0 10014-128-1 /WINDOWS/system32/dllcache/wmploc.dll 221184 ..c. r/rr-xr-xr-x 0 0 10015-128-1 /WINDOWS/system32/dllcache/wmpns.dll 102400 ..c. r/rr-xr-xr-x 0 0 10016-128-1 /WINDOWS/system32/dllcache/wmpshell.dll 20480 ..c. r/rr-xr-xr-x 0 0 10017-128-1 /WINDOWS/system32/dllcache/wmpui.dll 759296 ..c. r/rr-xr-xr-x 0 0 10018-128-1 /WINDOWS/system32/dllcache/wmsdmod.dll 115200 ..c. r/rr-xr-xr-x 0 0 10019-128-1 /WINDOWS/system32/dllcache/wmsdmoe.dll 1119744 ..c. r/rr-xr-xr-x 0 0 10020-128-1 /WINDOWS/system32/dllcache/wmsdmoe2.dll 485376 ..c. r/rr-xr-xr-x 0 0 10021-128-1 /WINDOWS/system32/dllcache/wmspdmod.dll 897024 ..c. r/rr-xr-xr-x 0 0 10022-128-1 /WINDOWS/system32/dllcache/wmspdmoe.dll 303616 ..c. r/rr-xr-xr-x 0 0 10023-128-1 /WINDOWS/system32/dllcache/wmstream.dll 278559 ..c. r/rr-xr-xr-x 0 0 10024-128-1 /WINDOWS/system32/dllcache/wmv8ds32.ax 2109440 ..c. r/rr-xr-xr-x 0 0 10025-128-1 /WINDOWS/system32/dllcache/wmvcore.dll 809984 ..c. r/rr-xr-xr-x 0 0 10026-128-1 /WINDOWS/system32/dllcache/wmvdmod.dll 1001472 ..c. r/rr-xr-xr-x 0 0 10027-128-1 /WINDOWS/system32/dllcache/wmvdmoe2.dll 258048 ..c. r/rr-xr-xr-x 0 0 10028-128-1 /WINDOWS/system32/dllcache/wmvds32.ax 214528 ..c. r/rr-xr-xr-x 0 0 10029-128-1 /WINDOWS/system32/dllcache/wordpad.exe 19255 ..c. r/rr-xr-xr-x 0 0 1003-128-3 /WINDOWS/inf/msports.inf 264192 ..c. r/rr-xr-xr-x 0 0 10030-128-1 /WINDOWS/system32/dllcache/wow32.dll 2736 ..c. r/rr-xr-xr-x 0 0 10031-128-1 /WINDOWS/system32/dllcache/wowdeb.exe 10368 ..c. r/rr-xr-xr-x 0 0 10032-128-1 /WINDOWS/system32/dllcache/wowexec.exe 32256 ..c. r/rr-xr-xr-x 0 0 10033-128-1 /WINDOWS/system32/dllcache/wpabaln.exe 11264 ..c. r/rr-xr-xr-x 0 0 10034-128-1 /WINDOWS/system32/dllcache/wpnpinst.exe 5632 ..c. r/rr-xr-xr-x 0 0 10035-128-1 /WINDOWS/system32/dllcache/write.exe 82432 ..c. r/rr-xr-xr-x 0 0 10036-128-1 /WINDOWS/system32/dllcache/ws2_32.dll 19968 ..c. r/rr-xr-xr-x 0 0 10037-128-1 /WINDOWS/system32/dllcache/ws2help.dll 12032 ..c. r/rr-xr-xr-x 0 0 10038-128-1 /WINDOWS/system32/dllcache/ws2ifsl.sys 13824 ..c. r/rr-xr-xr-x 0 0 10039-128-1 /WINDOWS/system32/dllcache/wscntfy.exe 155648 ..c. r/rr-xr-xr-x 0 0 10040-128-1 /WINDOWS/system32/dllcache/wscript.exe 80896 ..c. r/rr-xr-xr-x 0 0 10041-128-1 /WINDOWS/system32/dllcache/wscsvc.dll 148480 ..c. r/rr-xr-xr-x 0 0 10042-128-1 /WINDOWS/system32/dllcache/wscui.cpl 604160 ..c. r/rr-xr-xr-x 0 0 10043-128-1 /WINDOWS/system32/dllcache/wsecedit.dll 9216 ..c. r/rr-xr-xr-x 0 0 10044-128-1 /WINDOWS/system32/dllcache/wshatm.dll 36864 ..c. r/rr-xr-xr-x 0 0 10045-128-1 /WINDOWS/system32/dllcache/wshcon.dll 90112 ..c. r/rr-xr-xr-x 0 0 10046-128-1 /WINDOWS/system32/dllcache/wshext.dll 14336 ..c. r/rr-xr-xr-x 0 0 10047-128-1 /WINDOWS/system32/dllcache/wship6.dll 11776 ..c. r/rr-xr-xr-x 0 0 10048-128-1 /WINDOWS/system32/dllcache/wshisn.dll 7168 ..c. r/rr-xr-xr-x 0 0 10049-128-1 /WINDOWS/system32/dllcache/wshnetbs.dll 1925 ..c. r/rr-xr-xr-x 0 0 1005-128-3 /WINDOWS/inf/msrio8.inf 135168 ..c. r/rr-xr-xr-x 0 0 10050-128-1 /WINDOWS/system32/dllcache/wshom.ocx 11264 ..c. r/rr-xr-xr-x 0 0 10051-128-1 /WINDOWS/system32/dllcache/wshrm.dll 19456 ..c. r/rr-xr-xr-x 0 0 10052-128-1 /WINDOWS/system32/dllcache/wshtcpip.dll 41984 ..c. r/rr-xr-xr-x 0 0 10053-128-1 /WINDOWS/system32/dllcache/wsnmp32.dll 22528 ..c. r/rr-xr-xr-x 0 0 10054-128-1 /WINDOWS/system32/dllcache/wsock32.dll 50688 ..c. r/rr-xr-xr-x 0 0 10055-128-1 /WINDOWS/system32/dllcache/wstdecod.dll 164352 ..c. r/rr-xr-xr-x 0 0 10056-128-1 /WINDOWS/system32/dllcache/wstpager.ax 239616 ..c. r/rr-xr-xr-x 0 0 10057-128-1 /WINDOWS/system32/dllcache/wstrendr.ax 18432 ..c. r/rr-xr-xr-x 0 0 10058-128-1 /WINDOWS/system32/dllcache/wtsapi32.dll 430592 ..c. r/rr-xr-xr-x 0 0 10059-128-1 /WINDOWS/system32/dllcache/wuapi.dll 1928 ..c. r/rr-xr-xr-x 0 0 1006-128-3 /WINDOWS/inf/msrio.inf 111104 ..c. r/rr-xr-xr-x 0 0 10060-128-1 /WINDOWS/system32/dllcache/wuauclt.exe 165888 ..c. r/rr-xr-xr-x 0 0 10061-128-1 /WINDOWS/system32/dllcache/wuauclt1.exe 162304 ..c. r/rr-xr-xr-x 0 0 10062-128-1 /WINDOWS/system32/dllcache/wuaucpl.cpl 1135616 ..c. r/rr-xr-xr-x 0 0 10063-128-1 /WINDOWS/system32/dllcache/wuaueng.dll 183296 ..c. r/rr-xr-xr-x 0 0 10064-128-1 /WINDOWS/system32/dllcache/wuaueng1.dll 6656 ..c. r/rr-xr-xr-x 0 0 10065-128-1 /WINDOWS/system32/dllcache/wuauserv.dll 112640 ..c. r/rr-xr-xr-x 0 0 10066-128-1 /WINDOWS/system32/dllcache/wucltui.dll 32256 ..c. r/rr-xr-xr-x 0 0 10067-128-1 /WINDOWS/system32/dllcache/wupdmgr.exe 32256 ..c. r/rr-xr-xr-x 0 0 10068-128-1 /WINDOWS/system32/dllcache/wups.dll 120320 ..c. r/rr-xr-xr-x 0 0 10069-128-1 /WINDOWS/system32/dllcache/wuweb.dll 383488 ..c. r/rr-xr-xr-x 0 0 10070-128-1 /WINDOWS/system32/dllcache/wzcdlg.dll 91648 ..c. r/rr-xr-xr-x 0 0 10071-128-1 /WINDOWS/system32/dllcache/xactsrv.dll 30720 ..c. r/rr-xr-xr-x 0 0 10072-128-1 /WINDOWS/system32/dllcache/xcopy.exe 174200 ..c. r/rr-xr-xr-x 0 0 10073-128-1 /WINDOWS/system32/dllcache/xenroll.dll 28288 ..c. r/rr-xr-xr-x 0 0 10074-128-3 /WINDOWS/system32/dllcache/xjis.nls 129024 ..c. r/rr-xr-xr-x 0 0 10075-128-1 /WINDOWS/system32/dllcache/xmlprov.dll 50176 ..c. r/rr-xr-xr-x 0 0 10076-128-1 /WINDOWS/system32/dllcache/xmlprovi.dll 11776 ..c. r/rr-xr-xr-x 0 0 10077-128-1 /WINDOWS/system32/dllcache/xolehlp.dll 393728 ..c. r/rr-xr-xr-x 0 0 10078-128-1 /WINDOWS/system32/dllcache/obrb0401.dll 212480 ..c. r/rr-xr-xr-x 0 0 10079-128-1 /WINDOWS/system32/dllcache/obrb0404.dll 428032 ..c. r/rr-xr-xr-x 0 0 10080-128-1 /WINDOWS/system32/dllcache/obrb0405.dll 418816 ..c. r/rr-xr-xr-x 0 0 10081-128-1 /WINDOWS/system32/dllcache/obrb0406.dll 403456 ..c. r/rr-xr-xr-x 0 0 10082-128-1 /WINDOWS/system32/dllcache/obrb0407.dll 419328 ..c. r/rr-xr-xr-x 0 0 10083-128-1 /WINDOWS/system32/dllcache/obrb0408.dll 405504 ..c. r/rr-xr-xr-x 0 0 10084-128-1 /WINDOWS/system32/dllcache/obrb040b.dll 410624 ..c. r/rr-xr-xr-x 0 0 10085-128-1 /WINDOWS/system32/dllcache/obrb040C.dll 384000 ..c. r/rr-xr-xr-x 0 0 10086-128-1 /WINDOWS/system32/dllcache/obrb040D.dll 434176 ..c. r/rr-xr-xr-x 0 0 10087-128-1 /WINDOWS/system32/dllcache/obrb040e.dll 413696 ..c. r/rr-xr-xr-x 0 0 10088-128-1 /WINDOWS/system32/dllcache/obrb0410.dll 275456 ..c. r/rr-xr-xr-x 0 0 10089-128-1 /WINDOWS/system32/dllcache/obrb0411.dll 306688 ..c. r/rr-xr-xr-x 0 0 10090-128-1 /WINDOWS/system32/dllcache/obrb0412.dll 401920 ..c. r/rr-xr-xr-x 0 0 10091-128-1 /WINDOWS/system32/dllcache/obrb0413.dll 353792 ..c. r/rr-xr-xr-x 0 0 10092-128-1 /WINDOWS/system32/dllcache/obrb0414.dll 391680 ..c. r/rr-xr-xr-x 0 0 10093-128-1 /WINDOWS/system32/dllcache/obrb0415.dll 409600 ..c. r/rr-xr-xr-x 0 0 10094-128-1 /WINDOWS/system32/dllcache/obrb0416.dll 427008 ..c. r/rr-xr-xr-x 0 0 10095-128-1 /WINDOWS/system32/dllcache/obrb0419.dll 405504 ..c. r/rr-xr-xr-x 0 0 10096-128-1 /WINDOWS/system32/dllcache/obrb041b.dll 363008 ..c. r/rr-xr-xr-x 0 0 10097-128-1 /WINDOWS/system32/dllcache/obrb041D.dll 390144 ..c. r/rr-xr-xr-x 0 0 10098-128-1 /WINDOWS/system32/dllcache/obrb041f.dll 408576 ..c. r/rr-xr-xr-x 0 0 10099-128-1 /WINDOWS/system32/dllcache/obrb0424.dll 270336 ..c. r/rr-xr-xr-x 0 0 10100-128-1 /WINDOWS/system32/dllcache/obrb0804.dll 435200 ..c. r/rr-xr-xr-x 0 0 10101-128-1 /WINDOWS/system32/dllcache/obrb0816.dll 446464 ..c. r/rr-xr-xr-x 0 0 10102-128-1 /WINDOWS/system32/dllcache/obrb0C0A.dll 438784 ..c. r/rr-xr-xr-x 0 0 10103-128-1 /WINDOWS/system32/dllcache/xpob2res.dll 186880 ..c. r/rr-xr-xr-x 0 0 10104-128-1 /WINDOWS/system32/dllcache/spra0401.dll 189440 ..c. r/rr-xr-xr-x 0 0 10105-128-1 /WINDOWS/system32/dllcache/spra0402.dll 161280 ..c. r/rr-xr-xr-x 0 0 10106-128-1 /WINDOWS/system32/dllcache/spra0404.dll 188928 ..c. r/rr-xr-xr-x 0 0 10107-128-1 /WINDOWS/system32/dllcache/spra0405.dll 192000 ..c. r/rr-xr-xr-x 0 0 10108-128-1 /WINDOWS/system32/dllcache/spra0406.dll 199680 ..c. r/rr-xr-xr-x 0 0 10109-128-1 /WINDOWS/system32/dllcache/spra0407.dll 28371 ..c. r/rr-xr-xr-x 0 0 1011-128-3 /WINDOWS/Help/mstask.hlp 197632 ..c. r/rr-xr-xr-x 0 0 10110-128-1 /WINDOWS/system32/dllcache/spra0408.dll 186368 ..c. r/rr-xr-xr-x 0 0 10111-128-1 /WINDOWS/system32/dllcache/spra040b.dll 197632 ..c. r/rr-xr-xr-x 0 0 10112-128-1 /WINDOWS/system32/dllcache/spra040C.dll 181760 ..c. r/rr-xr-xr-x 0 0 10113-128-1 /WINDOWS/system32/dllcache/spra040D.dll 195584 ..c. r/rr-xr-xr-x 0 0 10114-128-1 /WINDOWS/system32/dllcache/spra040e.dll 195072 ..c. r/rr-xr-xr-x 0 0 10115-128-1 /WINDOWS/system32/dllcache/spra0410.dll 171008 ..c. r/rr-xr-xr-x 0 0 10116-128-1 /WINDOWS/system32/dllcache/spra0411.dll 167936 ..c. r/rr-xr-xr-x 0 0 10117-128-1 /WINDOWS/system32/dllcache/spra0412.dll 196096 ..c. r/rr-xr-xr-x 0 0 10118-128-1 /WINDOWS/system32/dllcache/spra0413.dll 189440 ..c. r/rr-xr-xr-x 0 0 10119-128-1 /WINDOWS/system32/dllcache/spra0414.dll 6464 ..c. r/rr-xr-xr-x 0 0 1012-128-3 /WINDOWS/inf/mstask.inf 194560 ..c. r/rr-xr-xr-x 0 0 10120-128-1 /WINDOWS/system32/dllcache/spra0415.dll 192512 ..c. r/rr-xr-xr-x 0 0 10121-128-1 /WINDOWS/system32/dllcache/spra0416.dll 190464 ..c. r/rr-xr-xr-x 0 0 10122-128-1 /WINDOWS/system32/dllcache/spra0418.dll 192512 ..c. r/rr-xr-xr-x 0 0 10123-128-1 /WINDOWS/system32/dllcache/spra0419.dll 188928 ..c. r/rr-xr-xr-x 0 0 10124-128-1 /WINDOWS/system32/dllcache/spra041a.dll 192512 ..c. r/rr-xr-xr-x 0 0 10125-128-1 /WINDOWS/system32/dllcache/spra041b.dll 188928 ..c. r/rr-xr-xr-x 0 0 10126-128-1 /WINDOWS/system32/dllcache/spra041D.dll 188416 ..c. r/rr-xr-xr-x 0 0 10127-128-1 /WINDOWS/system32/dllcache/spra041e.dll 188928 ..c. r/rr-xr-xr-x 0 0 10128-128-1 /WINDOWS/system32/dllcache/spra041f.dll 192512 ..c. r/rr-xr-xr-x 0 0 10129-128-1 /WINDOWS/system32/dllcache/spra0424.dll 186880 ..c. r/rr-xr-xr-x 0 0 10130-128-1 /WINDOWS/system32/dllcache/spra0425.dll 188928 ..c. r/rr-xr-xr-x 0 0 10131-128-1 /WINDOWS/system32/dllcache/spra0426.dll 189952 ..c. r/rr-xr-xr-x 0 0 10132-128-1 /WINDOWS/system32/dllcache/spra0427.dll 161280 ..c. r/rr-xr-xr-x 0 0 10133-128-1 /WINDOWS/system32/dllcache/spra0804.dll 194560 ..c. r/rr-xr-xr-x 0 0 10134-128-1 /WINDOWS/system32/dllcache/spra0816.dll 196096 ..c. r/rr-xr-xr-x 0 0 10135-128-1 /WINDOWS/system32/dllcache/spra0C0A.dll 187392 ..c. r/rr-xr-xr-x 0 0 10136-128-1 /WINDOWS/system32/dllcache/xpsp1res.dll 2869248 ..c. r/rr-xr-xr-x 0 0 10137-128-1 /WINDOWS/system32/dllcache/sprb0401.dll 477696 ..c. r/rr-xr-xr-x 0 0 10138-128-1 /WINDOWS/system32/dllcache/sprb0404.dll 734720 ..c. r/rr-xr-xr-x 0 0 10139-128-1 /WINDOWS/system32/dllcache/sprb0405.dll 742912 ..c. r/rr-xr-xr-x 0 0 10140-128-1 /WINDOWS/system32/dllcache/sprb0406.dll 788480 ..c. r/rr-xr-xr-x 0 0 10141-128-1 /WINDOWS/system32/dllcache/sprb0407.dll 801280 ..c. r/rr-xr-xr-x 0 0 10142-128-1 /WINDOWS/system32/dllcache/sprb0408.dll 729088 ..c. r/rr-xr-xr-x 0 0 10143-128-1 /WINDOWS/system32/dllcache/sprb040b.dll 793088 ..c. r/rr-xr-xr-x 0 0 10144-128-1 /WINDOWS/system32/dllcache/sprb040C.dll 2842112 ..c. r/rr-xr-xr-x 0 0 10145-128-1 /WINDOWS/system32/dllcache/sprb040D.dll 769536 ..c. r/rr-xr-xr-x 0 0 10146-128-1 /WINDOWS/system32/dllcache/sprb040e.dll 769536 ..c. r/rr-xr-xr-x 0 0 10147-128-1 /WINDOWS/system32/dllcache/sprb0410.dll 562688 ..c. r/rr-xr-xr-x 0 0 10148-128-1 /WINDOWS/system32/dllcache/sprb0411.dll 543744 ..c. r/rr-xr-xr-x 0 0 10149-128-1 /WINDOWS/system32/dllcache/sprb0412.dll 769024 ..c. r/rr-xr-xr-x 0 0 10150-128-1 /WINDOWS/system32/dllcache/sprb0413.dll 716288 ..c. r/rr-xr-xr-x 0 0 10151-128-1 /WINDOWS/system32/dllcache/sprb0414.dll 759808 ..c. r/rr-xr-xr-x 0 0 10152-128-1 /WINDOWS/system32/dllcache/sprb0415.dll 752128 ..c. r/rr-xr-xr-x 0 0 10153-128-1 /WINDOWS/system32/dllcache/sprb0416.dll 736768 ..c. r/rr-xr-xr-x 0 0 10154-128-1 /WINDOWS/system32/dllcache/sprb0419.dll 757248 ..c. r/rr-xr-xr-x 0 0 10155-128-1 /WINDOWS/system32/dllcache/sprb041b.dll 724480 ..c. r/rr-xr-xr-x 0 0 10156-128-1 /WINDOWS/system32/dllcache/sprb041D.dll 724480 ..c. r/rr-xr-xr-x 0 0 10157-128-1 /WINDOWS/system32/dllcache/sprb041f.dll 732160 ..c. r/rr-xr-xr-x 0 0 10158-128-1 /WINDOWS/system32/dllcache/sprb0424.dll 470016 ..c. r/rr-xr-xr-x 0 0 10159-128-1 /WINDOWS/system32/dllcache/sprb0804.dll 751616 ..c. r/rr-xr-xr-x 0 0 10160-128-1 /WINDOWS/system32/dllcache/sprb0816.dll 773632 ..c. r/rr-xr-xr-x 0 0 10161-128-1 /WINDOWS/system32/dllcache/sprb0C0A.dll 2897920 ..c. r/rr-xr-xr-x 0 0 10162-128-1 /WINDOWS/system32/dllcache/xpsp2res.dll 656896 ..c. r/rr-xr-xr-x 0 0 10163-128-1 /WINDOWS/system32/dllcache/sprc0401.dll 327680 ..c. r/rr-xr-xr-x 0 0 10164-128-1 /WINDOWS/system32/dllcache/sprc0404.dll 601088 ..c. r/rr-xr-xr-x 0 0 10165-128-1 /WINDOWS/system32/dllcache/sprc0405.dll 605696 ..c. r/rr-xr-xr-x 0 0 10166-128-1 /WINDOWS/system32/dllcache/sprc0406.dll 663552 ..c. r/rr-xr-xr-x 0 0 10167-128-1 /WINDOWS/system32/dllcache/sprc0407.dll 679936 ..c. r/rr-xr-xr-x 0 0 10168-128-1 /WINDOWS/system32/dllcache/sprc0408.dll 604672 ..c. r/rr-xr-xr-x 0 0 10169-128-1 /WINDOWS/system32/dllcache/sprc040b.dll 663040 ..c. r/rr-xr-xr-x 0 0 10170-128-1 /WINDOWS/system32/dllcache/sprc040C.dll 620544 ..c. r/rr-xr-xr-x 0 0 10171-128-1 /WINDOWS/system32/dllcache/sprc040D.dll 645120 ..c. r/rr-xr-xr-x 0 0 10172-128-1 /WINDOWS/system32/dllcache/sprc040e.dll 658432 ..c. r/rr-xr-xr-x 0 0 10173-128-1 /WINDOWS/system32/dllcache/sprc0410.dll 412672 ..c. r/rr-xr-xr-x 0 0 10174-128-1 /WINDOWS/system32/dllcache/sprc0411.dll 392704 ..c. r/rr-xr-xr-x 0 0 10175-128-1 /WINDOWS/system32/dllcache/sprc0412.dll 645120 ..c. r/rr-xr-xr-x 0 0 10176-128-1 /WINDOWS/system32/dllcache/sprc0413.dll 591872 ..c. r/rr-xr-xr-x 0 0 10177-128-1 /WINDOWS/system32/dllcache/sprc0414.dll 641024 ..c. r/rr-xr-xr-x 0 0 10178-128-1 /WINDOWS/system32/dllcache/sprc0415.dll 620032 ..c. r/rr-xr-xr-x 0 0 10179-128-1 /WINDOWS/system32/dllcache/sprc0416.dll 627200 ..c. r/rr-xr-xr-x 0 0 10180-128-1 /WINDOWS/system32/dllcache/sprc0419.dll 577536 ..c. r/rr-xr-xr-x 0 0 10181-128-1 /WINDOWS/system32/dllcache/sprc041b.dll 590848 ..c. r/rr-xr-xr-x 0 0 10182-128-1 /WINDOWS/system32/dllcache/sprc041D.dll 592896 ..c. r/rr-xr-xr-x 0 0 10183-128-1 /WINDOWS/system32/dllcache/sprc041f.dll 576512 ..c. r/rr-xr-xr-x 0 0 10184-128-1 /WINDOWS/system32/dllcache/sprc0424.dll 322560 ..c. r/rr-xr-xr-x 0 0 10185-128-1 /WINDOWS/system32/dllcache/sprc0804.dll 639488 ..c. r/rr-xr-xr-x 0 0 10186-128-1 /WINDOWS/system32/dllcache/sprc0816.dll 648704 ..c. r/rr-xr-xr-x 0 0 10187-128-1 /WINDOWS/system32/dllcache/sprc0C0A.dll 689152 ..c. r/rr-xr-xr-x 0 0 10188-128-1 /WINDOWS/system32/dllcache/xpsp3res.dll 36937 ..c. r/rr-xr-xr-x 0 0 10189-128-1 /WINDOWS/system32/dllcache/zclientm.exe 3085 ..c. r/rr-xr-xr-x 0 0 1019-128-3 /WINDOWS/inf/mtxvideo.inf 41029 ..c. r/rr-xr-xr-x 0 0 10190-128-1 /WINDOWS/system32/dllcache/zcorem.dll 4677 ..c. r/rr-xr-xr-x 0 0 10191-128-1 /WINDOWS/system32/dllcache/zeeverm.dll 338432 ..c. r/rr-xr-xr-x 0 0 10192-128-1 /WINDOWS/system32/dllcache/zipfldr.dll 29760 ..c. r/rr-xr-xr-x 0 0 10193-128-1 /WINDOWS/system32/dllcache/znetm.dll 113222 ..c. r/rr-xr-xr-x 0 0 10194-128-1 /WINDOWS/system32/dllcache/zoneclim.dll 13894 ..c. r/rr-xr-xr-x 0 0 10195-128-1 /WINDOWS/system32/dllcache/zonelibm.dll 8261 ..c. r/rr-xr-xr-x 0 0 10196-128-1 /WINDOWS/system32/dllcache/zoneoc.dll 56 .ac. d/dr-xr-xr-x 0 0 10197-144-6 /WINDOWS/system32/config/systemprofile 56 .ac. d/dr-xr-xr-x 0 0 10198-144-6 /WINDOWS/system32/config/systemprofile/Templates 256 .ac. d/d--x--x--x 0 0 10199-144-1 /WINDOWS/system32/config/systemprofile/Start Menu 2391 ..c. r/rr-xr-xr-x 0 0 1020-128-3 /WINDOWS/inf/multiprt.inf 56 .ac. d/d--x--x--x 0 0 10200-144-5 /WINDOWS/system32/config/systemprofile/Start Menu/Programs 152 .ac. d/d--x--x--x 0 0 10201-144-1 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Startup 56 .ac. d/d--x--x--x 0 0 10202-144-6 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Accessories 400 .ac. d/d--x--x--x 0 0 10203-144-1 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Accessories/Entertainment 56 .ac. d/d--x--x--x 0 0 10204-144-6 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Accessories/Accessibility 56 .ac. d/d--x--x--x 0 0 10205-144-5 /WINDOWS/system32/config/systemprofile/SendTo 48 .ac. d/dr-xr-xr-x 0 0 10206-144-1 /WINDOWS/system32/config/systemprofile/Recent 48 .ac. d/dr-xr-xr-x 0 0 10207-144-1 /WINDOWS/system32/config/systemprofile/PrintHood 48 .ac. d/dr-xr-xr-x 0 0 10208-144-1 /WINDOWS/system32/config/systemprofile/NetHood 48 .ac. d/dr-xr-xr-x 0 0 10209-144-1 /WINDOWS/system32/config/systemprofile/My Documents 56 .ac. d/d--x--x--x 0 0 10210-144-6 /WINDOWS/system32/config/systemprofile/Local Settings 256 .a.. d/drwxrwxrwx 0 0 10211-144-1 /WINDOWS/system32/config/systemprofile/Local Settings/Temporary Internet Files 48 .ac. d/dr-xr-xr-x 0 0 10212-144-1 /WINDOWS/system32/config/systemprofile/Local Settings/Temp 256 .a.. d/drwxrwxrwx 0 0 10213-144-1 /WINDOWS/system32/config/systemprofile/Local Settings/History 256 .ac. d/dr-xr-xr-x 0 0 10214-144-1 /WINDOWS/system32/config/systemprofile/Local Settings/Application Data 480 .ac. d/dr-xr-xr-x 0 0 10215-144-1 /WINDOWS/system32/config/systemprofile/Local Settings/Application Data/Microsoft 136 .ac. d/dr-xr-xr-x 0 0 10216-144-1 /WINDOWS/system32/config/systemprofile/Local Settings/Application Data/Microsoft/Windows Media 368 .ac. d/dr-xr-xr-x 0 0 10217-144-1 /WINDOWS/system32/config/systemprofile/Local Settings/Application Data/Microsoft/Windows Media/9.0 296 .ac. d/dr-xr-xr-x 0 0 10218-144-1 /WINDOWS/system32/config/systemprofile/Local Settings/Application Data/Microsoft/Media Player 48 .ac. d/dr-xr-xr-x 0 0 10219-144-1 /WINDOWS/system32/config/systemprofile/Favorites 48 .ac. d/dr-xr-xr-x 0 0 10220-144-1 /WINDOWS/system32/config/systemprofile/Desktop 152 .a.. d/drwxrwxrwx 0 0 10221-144-1 /WINDOWS/system32/config/systemprofile/Cookies 360 .ac. d/d--x--x--x 0 0 10222-144-1 /WINDOWS/system32/config/systemprofile/Application Data 136 .a.. d/drwxrwxrwx 0 0 10224-144-1 /WINDOWS/system32/config/systemprofile/Application Data/Microsoft/SystemCertificates 456 .a.. d/drwxrwxrwx 0 0 10225-144-1 /WINDOWS/system32/config/systemprofile/Application Data/Microsoft/SystemCertificates/My 48 .a.. d/drwxrwxrwx 0 0 10226-144-1 /WINDOWS/system32/config/systemprofile/Application Data/Microsoft/SystemCertificates/My/CTLs 48 .a.. d/drwxrwxrwx 0 0 10227-144-1 /WINDOWS/system32/config/systemprofile/Application Data/Microsoft/SystemCertificates/My/CRLs 48 .a.. d/drwxrwxrwx 0 0 10228-144-1 /WINDOWS/system32/config/systemprofile/Application Data/Microsoft/SystemCertificates/My/Certificates 48 .ac. d/dr-xr-xr-x 0 0 10229-144-1 /WINDOWS/system32/config/systemprofile/Application Data/Microsoft/Media Player 256 .ac. d/dr-xr-xr-x 0 0 10230-144-1 /WINDOWS/system32/config/systemprofile/Application Data/Microsoft/Internet Explorer 57 ..c. r/r--x--x--x 0 0 10231-128-3 /WINDOWS/system32/config/systemprofile/Templates/wordpfct.wpg 1769 ..c. r/rr-xr-xr-x 0 0 10232-128-4 /WINDOWS/system32/config/systemprofile/Templates/winword2.doc 461 ..c. r/rr-xr-xr-x 0 0 10233-128-3 /WINDOWS/system32/config/systemprofile/Templates/presenta.shw 12288 ..c. r/rr-xr-xr-x 0 0 10234-128-4 /WINDOWS/system32/config/systemprofile/Templates/powerpnt.ppt 4017 ..c. r/rr-xr-xr-x 0 0 10235-128-4 /WINDOWS/system32/config/systemprofile/Templates/quattro.wb2 58 ..c. r/rr-xr-xr-x 0 0 10236-128-3 /WINDOWS/system32/config/systemprofile/Templates/sndrec.wav 4608 ..c. r/rr-xr-xr-x 0 0 10237-128-4 /WINDOWS/system32/config/systemprofile/Templates/winword.doc 30 ..c. r/r--x--x--x 0 0 10238-128-3 /WINDOWS/system32/config/systemprofile/Templates/wordpfct.wpd 1518 ..c. r/rr-xr-xr-x 0 0 10239-128-4 /WINDOWS/system32/config/systemprofile/Templates/excel4.xls 4570 ..c. r/rr-xr-xr-x 0 0 10240-128-4 /WINDOWS/system32/config/systemprofile/Templates/amipro.sam 5632 ..c. r/rr-xr-xr-x 0 0 10241-128-4 /WINDOWS/system32/config/systemprofile/Templates/excel.xls 792 ..c. r/rr-xr-xr-x 0 0 10242-128-4 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Windows Media Player.lnk 2448 ..c. r/rr-xr-xr-x 0 0 10243-128-4 /WINDOWS/system32/config/systemprofile/Templates/lotus.wk4 376 ..c. r/rr-xr-xr-x 0 0 10245-128-3 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Messenger Center.lnk 382 ..c. r/rr-xr-xr-x 0 0 10246-128-3 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Media Player Center.lnk 1487 ..c. r/rr-xr-xr-x 0 0 10248-128-4 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Accessories/Windows Explorer.lnk 1599 ..c. r/rr-xr-xr-x 0 0 10249-128-4 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Remote Assistance.lnk 1519 ..c. r/rr-xr-xr-x 0 0 10250-128-4 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Accessories/Synchronize.lnk 804 ..c. r/rr-xr-xr-x 0 0 10251-128-4 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Accessories/Entertainment/Windows Media Player.lnk 386 ..c. r/rr-xr-xr-x 0 0 10252-128-3 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Accessories/Program Compatibility Wizard.lnk 1527 ..c. r/rr-xr-xr-x 0 0 10254-128-4 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Accessories/Tour Windows XP.lnk 1519 ..c. r/rr-xr-xr-x 0 0 10255-128-4 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Accessories/Notepad.lnk 1539 ..c. r/rr-xr-xr-x 0 0 10257-128-4 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Accessories/Accessibility/Utility Manager.lnk 1555 ..c. r/rr-xr-xr-x 0 0 10258-128-4 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Accessories/Command Prompt.lnk 1501 ..c. r/rr-xr-xr-x 0 0 10259-128-4 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Accessories/Accessibility/On-Screen Keyboard.lnk 2447 ..c. r/rr-xr-xr-x 0 0 1026-128-3 /WINDOWS/inf/ndisuio.inf 1525 ..c. r/rr-xr-xr-x 0 0 10260-128-4 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Accessories/Accessibility/Magnifier.lnk 0 ..c. r/rr-xr-xr-x 0 0 10262-128-3 /WINDOWS/system32/config/systemprofile/SendTo/Mail Recipient.MAPIMail 0 ..c. r/rr-xr-xr-x 0 0 10264-128-3 /WINDOWS/system32/config/systemprofile/SendTo/Desktop (create shortcut).DeskLink 1532 ..c. r/rr-xr-xr-x 0 0 10265-128-4 /WINDOWS/system32/config/systemprofile/Start Menu/Programs/Accessories/Accessibility/Narrator.lnk 0 ..c. r/rr-xr-xr-x 0 0 10266-128-3 /WINDOWS/system32/config/systemprofile/SendTo/Compressed (zipped) Folder.ZFSendToTarget 12787 ..c. r/rr-xr-xr-x 0 0 10268-128-4 /WINDOWS/system32/config/systemprofile/Local Settings/Application Data/Microsoft/Windows Media/9.0/WMSDKNS.XML 2300 ..c. r/rr-xr-xr-x 0 0 1027-128-3 /WINDOWS/inf/net1394.inf 720896 ..c. r/rr-xr-xr-x 0 0 10270-128-4 /WINDOWS/system32/config/systemprofile/Local Settings/Application Data/Microsoft/Media Player/CurrentDatabase_59R.wmdb 498 ..c. r/rr-xr-xr-x 0 0 10271-128-3 /WINDOWS/system32/config/systemprofile/Local Settings/Application Data/Microsoft/Windows Media/9.0/WMSDKNS.DTD 141 ..c. r/rr-xr-xr-x 0 0 10272-128-3 /WINDOWS/system32/config/systemprofile/Application Data/Microsoft/Internet Explorer/brndlog.txt 113 ..c. r/rr-xr-xr-x 0 0 10274-128-3 /WINDOWS/system32/config/systemprofile/Application Data/Microsoft/Internet Explorer/brndlog.bak 1490944 ..c. r/rr-xr-xr-x 0 0 10275-128-3 /WINDOWS/repair/system 9011200 ..c. r/rr-xr-xr-x 0 0 10276-128-3 /WINDOWS/repair/software 237568 ..c. r/rr-xr-xr-x 0 0 10277-128-3 /WINDOWS/repair/default 32768 ..c. r/rr-xr-xr-x 0 0 10278-128-3 /WINDOWS/repair/security 24576 ..c. r/rr-xr-xr-x 0 0 10279-128-3 /WINDOWS/repair/sam 22398 ..c. r/rr-xr-xr-x 0 0 1028-128-3 /WINDOWS/inf/net21x4.inf 237568 ..c. r/rr-xr-xr-x 0 0 10280-128-3 /WINDOWS/repair/ntuser.dat 1688 ..c. r/rr-xr-xr-x 0 0 10281-128-3 /WINDOWS/repair/autoexec.nt 2577 ..c. r/rr-xr-xr-x 0 0 10282-128-3 /WINDOWS/repair/config.nt 152 .a.. d/drwxrwxrwx 0 0 10284-144-1 /Documents and Settings/Default User/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF 152 .a.. d/drwxrwxrwx 0 0 10286-144-1 /Documents and Settings/Default User/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J 152 .a.. d/drwxrwxrwx 0 0 10288-144-1 /Documents and Settings/Default User/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL 3570 ..c. r/rr-xr-xr-x 0 0 1029-128-3 /WINDOWS/inf/net5515n.inf 16384 ..c. r/rr-xr-xr-x 0 0 10290-128-3 /Documents and Settings/Default User/Cookies/index.dat 256 .a.. d/drwxrwxrwx 0 0 10291-144-1 /Documents and Settings/Default User/Local Settings/History/History.IE5 16384 ..c. r/rr-xr-xr-x 0 0 10292-128-3 /Documents and Settings/Default User/Local Settings/History/History.IE5/index.dat 3407872 ..c. r/rr-xr-xr-x 0 0 10295-128-3 /WINDOWS/system32/config/system 16384 ..c. r/rr-xr-xr-x 0 0 10296-128-3 /Documents and Settings/NetworkService/Cookies/index.dat 9437184 ..c. r/rr-xr-xr-x 0 0 10297-128-3 /WINDOWS/system32/config/software 16384 ..c. r/rr-xr-xr-x 0 0 10298-128-3 /Documents and Settings/NetworkService/Local Settings/History/History.IE5/index.dat 262144 ..c. r/rr-xr-xr-x 0 0 10299-128-3 /WINDOWS/system32/config/default 7142 ..c. r/rr-xr-xr-x 0 0 1030-128-3 /WINDOWS/inf/netana.inf 152 .ac. d/d--x--x--x 0 0 10300-144-1 /Documents and Settings/malware/Recent 256 .ac. d/dr-xr-xr-x 0 0 10305-144-1 /Documents and Settings/NetworkService/Application Data 136 .a.. d/drwxrwxrwx 0 0 10307-144-1 /Documents and Settings/NetworkService/Application Data/Microsoft/SystemCertificates 456 .a.. d/drwxrwxrwx 0 0 10308-144-1 /Documents and Settings/NetworkService/Application Data/Microsoft/SystemCertificates/My 48 .a.. d/drwxrwxrwx 0 0 10309-144-1 /Documents and Settings/NetworkService/Application Data/Microsoft/SystemCertificates/My/CTLs 48 .a.. d/drwxrwxrwx 0 0 10310-144-1 /Documents and Settings/NetworkService/Application Data/Microsoft/SystemCertificates/My/CRLs 48 .a.. d/drwxrwxrwx 0 0 10311-144-1 /Documents and Settings/NetworkService/Application Data/Microsoft/SystemCertificates/My/Certificates 48 .ac. d/dr-xr-xr-x 0 0 10312-144-1 /Documents and Settings/NetworkService/Application Data/Microsoft/Media Player 48 .ac. d/dr-xr-xr-x 0 0 10313-144-1 /Documents and Settings/NetworkService/Application Data/Microsoft/Internet Explorer 92 ..c. r/rr-xr-xr-x 0 0 10316-128-1 /Documents and Settings/malware/Cookies/malware@search.happythat[1].txt 100 ..c. r/rr-xr-xr-x 0 0 10317-128-1 /Documents and Settings/malware/Cookies/malware@64.111.211[1].txt 5325 ..c. r/rr-xr-xr-x 0 0 10318-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CA6RCHER.htm 1737 ..c. r/rr-xr-xr-x 0 0 1032-128-3 /WINDOWS/inf/netauni.inf 1024 ..c. r/rr-xr-xr-x 0 0 10322-128-4 /Documents and Settings/NetworkService/ntuser.dat.LOG 256 .ac. d/dr-xr-xr-x 0 0 10323-144-1 /Documents and Settings/NetworkService/Local Settings/Application Data 352 .ac. d/dr-xr-xr-x 0 0 10324-144-1 /Documents and Settings/NetworkService/Local Settings/Application Data/Microsoft 392 .ac. d/dr-xr-xr-x 0 0 10325-144-1 /Documents and Settings/NetworkService/Local Settings/Application Data/Microsoft/Windows 262144 ..c. r/rr-xr-xr-x 0 0 10326-128-3 /Documents and Settings/NetworkService/Local Settings/Application Data/Microsoft/Windows/UsrClass.dat 1024 ..c. r/rr-xr-xr-x 0 0 10327-128-4 /Documents and Settings/NetworkService/Local Settings/Application Data/Microsoft/Windows/UsrClass.dat.LOG 1322 ..c. r/rr-xr-xr-x 0 0 1033-128-3 /WINDOWS/inf/netbrdgm.inf 48 .ac. d/dr-xr-xr-x 0 0 10330-144-1 /Documents and Settings/NetworkService/Local Settings/Temp 152 .a.. d/drwxrwxrwx 0 0 10331-144-1 /Documents and Settings/NetworkService/Local Settings/Application Data/Microsoft/Credentials 48 .a.. d/drwxrwxrwx 0 0 10332-144-1 /Documents and Settings/NetworkService/Local Settings/Application Data/Microsoft/Credentials/S-1-5-20 152 .a.. d/drwxrwxrwx 0 0 10333-144-1 /Documents and Settings/NetworkService/Application Data/Microsoft/Credentials 48 .a.. d/drwxrwxrwx 0 0 10334-144-1 /Documents and Settings/NetworkService/Application Data/Microsoft/Credentials/S-1-5-20 368 .ac. d/dr-xr-xr-x 0 0 10336-144-1 /WINDOWS/SoftwareDistribution/DataStore 448 .ac. d/dr-xr-xr-x 0 0 10337-144-1 /WINDOWS/SoftwareDistribution/DataStore/Logs 1096 ..c. r/rr-xr-xr-x 0 0 1034-128-3 /WINDOWS/inf/netbrdgs.inf 672 .a.. d/drwxrwxrwx 0 0 10340-144-1 /WINDOWS/system32/config/systemprofile/Local Settings/Temporary Internet Files/Content.IE5 32768 ..c. r/rr-xr-xr-x 0 0 10341-128-3 /WINDOWS/system32/config/systemprofile/Local Settings/Temporary Internet Files/Content.IE5/index.dat 152 .a.. d/drwxrwxrwx 0 0 10343-144-1 /WINDOWS/system32/config/systemprofile/Local Settings/Temporary Internet Files/Content.IE5/Q9I9G56T 152 .a.. d/drwxrwxrwx 0 0 10345-144-1 /WINDOWS/system32/config/systemprofile/Local Settings/Temporary Internet Files/Content.IE5/MT2HI5QT 152 .a.. d/drwxrwxrwx 0 0 10347-144-1 /WINDOWS/system32/config/systemprofile/Local Settings/Temporary Internet Files/Content.IE5/MFOLOPYZ 152 .a.. d/drwxrwxrwx 0 0 10349-144-1 /WINDOWS/system32/config/systemprofile/Local Settings/Temporary Internet Files/Content.IE5/MHQDI1IB 281595 ..c. r/rr-xr-xr-x 0 0 1035-128-3 /WINDOWS/Help/netcfg.hlp 16384 ..c. r/rr-xr-xr-x 0 0 10351-128-3 /WINDOWS/system32/config/systemprofile/Cookies/index.dat 496 .a.. d/drwxrwxrwx 0 0 10352-144-1 /WINDOWS/system32/config/systemprofile/Local Settings/History/History.IE5 32768 ..c. r/rr-xr-xr-x 0 0 10353-128-3 /WINDOWS/system32/config/systemprofile/Local Settings/History/History.IE5/index.dat 131072 ..c. r/rr-xr-xr-x 0 0 10355-128-3 /WINDOWS/SoftwareDistribution/DataStore/Logs/edb.log 4842 ..c. r/rr-xr-xr-x 0 0 10356-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/1db850e671ac9a39751a1482909ea6[1].jpg 53 ..c. r/rr-xr-xr-x 0 0 10357-128-1 /WINDOWS/system32/config/systemprofile/Local Settings/Application Data/Microsoft/Windows Media/9.0/WMSDKNSD.XML 152 .a.. d/drwxrwxrwx 0 0 10358-144-1 /WINDOWS/system32/config/systemprofile/Local Settings/History/History.IE5/MSHist012011011420110115 32768 ..c. r/rr-xr-xr-x 0 0 10359-128-3 /WINDOWS/system32/config/systemprofile/Local Settings/History/History.IE5/MSHist012011011420110115/index.dat 1064 ..c. r/rr-xr-xr-x 0 0 1036-128-3 /WINDOWS/inf/netcis.inf 237568 ..c. r/rr-xr-xr-x 0 0 10361-128-4 /Documents and Settings/LocalService/NTUSER.DAT 56 .ac. d/dr-xr-xr-x 0 0 10362-144-6 /Documents and Settings/LocalService/Local Settings 16384 ..c. r/rr-xr-xr-x 0 0 10365-128-3 /Documents and Settings/LocalService/Cookies/index.dat 16384 ..c. r/rr-xr-xr-x 0 0 10366-128-3 /Documents and Settings/LocalService/Local Settings/History/History.IE5/index.dat 56 .a.. d/dr-xr-xr-x 0 0 10367-144-6 /WINDOWS/SoftwareDistribution 1283 ..c. r/rr-xr-xr-x 0 0 1037-128-3 /WINDOWS/inf/netclass.inf 256 .ac. d/dr-xr-xr-x 0 0 10372-144-1 /Documents and Settings/LocalService/Application Data 136 .a.. d/drwxrwxrwx 0 0 10374-144-1 /Documents and Settings/LocalService/Application Data/Microsoft/SystemCertificates 456 .a.. d/drwxrwxrwx 0 0 10375-144-1 /Documents and Settings/LocalService/Application Data/Microsoft/SystemCertificates/My 48 .a.. d/drwxrwxrwx 0 0 10376-144-1 /Documents and Settings/LocalService/Application Data/Microsoft/SystemCertificates/My/CTLs 48 .a.. d/drwxrwxrwx 0 0 10377-144-1 /Documents and Settings/LocalService/Application Data/Microsoft/SystemCertificates/My/CRLs 48 .a.. d/drwxrwxrwx 0 0 10378-144-1 /Documents and Settings/LocalService/Application Data/Microsoft/SystemCertificates/My/Certificates 48 .ac. d/dr-xr-xr-x 0 0 10379-144-1 /Documents and Settings/LocalService/Application Data/Microsoft/Media Player 3808 ..c. r/rr-xr-xr-x 0 0 1038-128-3 /WINDOWS/inf/netdav.inf 48 .ac. d/dr-xr-xr-x 0 0 10380-144-1 /Documents and Settings/LocalService/Application Data/Microsoft/Internet Explorer 2 ..c. r/rr-xr-xr-x 0 0 10382-128-1 /WINDOWS/SoftwareDistribution/ReportingEvents.log 48 .ac. d/dr-xr-xr-x 0 0 10384-144-1 /WINDOWS/SoftwareDistribution/EventCache 1024 ..c. r/rr-xr-xr-x 0 0 10389-128-4 /Documents and Settings/LocalService/ntuser.dat.LOG 4722 ..c. r/rr-xr-xr-x 0 0 1039-128-3 /WINDOWS/inf/netdefxa.inf 256 .ac. d/dr-xr-xr-x 0 0 10390-144-1 /Documents and Settings/LocalService/Local Settings/Application Data 352 .ac. d/dr-xr-xr-x 0 0 10391-144-1 /Documents and Settings/LocalService/Local Settings/Application Data/Microsoft 392 .ac. d/dr-xr-xr-x 0 0 10392-144-1 /Documents and Settings/LocalService/Local Settings/Application Data/Microsoft/Windows 262144 ..c. r/rr-xr-xr-x 0 0 10393-128-3 /Documents and Settings/LocalService/Local Settings/Application Data/Microsoft/Windows/UsrClass.dat 1024 ..c. r/rr-xr-xr-x 0 0 10394-128-4 /Documents and Settings/LocalService/Local Settings/Application Data/Microsoft/Windows/UsrClass.dat.LOG 48 .ac. d/dr-xr-xr-x 0 0 10397-144-1 /Documents and Settings/LocalService/Local Settings/Temp 152 .a.. d/drwxrwxrwx 0 0 10398-144-1 /Documents and Settings/LocalService/Local Settings/Application Data/Microsoft/Credentials 48 .a.. d/drwxrwxrwx 0 0 10399-144-1 /Documents and Settings/LocalService/Local Settings/Application Data/Microsoft/Credentials/S-1-5-19 58073 ..c. r/rr-xr-xr-x 0 0 1040-128-3 /WINDOWS/inf/netdgdxb.inf 152 .a.. d/drwxrwxrwx 0 0 10400-144-1 /Documents and Settings/LocalService/Application Data/Microsoft/Credentials 48 .a.. d/drwxrwxrwx 0 0 10401-144-1 /Documents and Settings/LocalService/Application Data/Microsoft/Credentials/S-1-5-19 7072 ..c. r/rr-xr-xr-x 0 0 1041-128-3 /WINDOWS/inf/netel90a.inf 56 .a.. d/dr-xr-xr-x 0 0 10413-144-6 /WINDOWS/Prefetch 32768 ..c. r/rr-xr-xr-x 0 0 10414-128-3 /Documents and Settings/LocalService/Local Settings/Temporary Internet Files/Content.IE5/index.dat 152 .a.. d/drwxrwxrwx 0 0 10415-144-1 /Documents and Settings/LocalService/Local Settings/Temporary Internet Files/Content.IE5/45MNODEJ 152 .a.. d/drwxrwxrwx 0 0 10417-144-1 /Documents and Settings/LocalService/Local Settings/Temporary Internet Files/Content.IE5/4H6VGPMJ 152 .a.. d/drwxrwxrwx 0 0 10419-144-1 /Documents and Settings/LocalService/Local Settings/Temporary Internet Files/Content.IE5/GDEF8DQ3 12847 ..c. r/rr-xr-xr-x 0 0 1042-128-3 /WINDOWS/inf/netel90b.inf 152 .a.. d/drwxrwxrwx 0 0 10421-144-1 /Documents and Settings/LocalService/Local Settings/Temporary Internet Files/Content.IE5/G1QN01MR 48 .ac. d/dr-xr-xr-x 0 0 10424-144-1 /WINDOWS/SoftwareDistribution/Download 48 .ac. d/dr-xr-xr-x 0 0 10425-144-1 /WINDOWS/SoftwareDistribution/SelfUpdate 2597 ..c. r/rr-xr-xr-x 0 0 1043-128-3 /WINDOWS/inf/netepvcm.inf 131072 ..c. r/rr-xr-xr-x 0 0 10434-128-3 /WINDOWS/SoftwareDistribution/DataStore/Logs/res2.log 131072 ..c. r/rr-xr-xr-x 0 0 10435-128-3 /WINDOWS/SoftwareDistribution/DataStore/Logs/res1.log 56 .ac. d/dr-xr-xr-x 0 0 10436-144-5 /Documents and Settings/malware 48 .ac. d/dr-xr-xr-x 0 0 10437-144-1 /Documents and Settings/malware/Application Data/Microsoft/MMC 7322 ..c. r/rr-xr-xr-x 0 0 10438-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/4378db7471b44dea1c183f006ee3d0[1].gif 9167 ..c. r/rr-xr-xr-x 0 0 10439-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/7815B21D9A578DAD6365D443B0D6B6[1].jpg 2134 ..c. r/rr-xr-xr-x 0 0 1044-128-3 /WINDOWS/inf/netepvcp.inf 786432 ..c. r/rr-xr-xr-x 0 0 10441-128-4 /Documents and Settings/malware/NTUSER.DAT 56 .ac. d/dr-xr-xr-x 0 0 10442-144-6 /Documents and Settings/malware/Templates 256 .ac. d/d--x--x--x 0 0 10443-144-1 /Documents and Settings/malware/Start Menu 56 .ac. d/d--x--x--x 0 0 10444-144-5 /Documents and Settings/malware/Start Menu/Programs 152 .ac. d/d--x--x--x 0 0 10445-144-1 /Documents and Settings/malware/Start Menu/Programs/Startup 56 .ac. d/d--x--x--x 0 0 10446-144-6 /Documents and Settings/malware/Start Menu/Programs/Accessories 400 .ac. d/d--x--x--x 0 0 10447-144-1 /Documents and Settings/malware/Start Menu/Programs/Accessories/Entertainment 56 .ac. d/d--x--x--x 0 0 10448-144-6 /Documents and Settings/malware/Start Menu/Programs/Accessories/Accessibility 56 .ac. d/d--x--x--x 0 0 10449-144-5 /Documents and Settings/malware/SendTo 3111 ..c. r/rr-xr-xr-x 0 0 1045-128-3 /WINDOWS/inf/netfore.inf 5325 ..c. r/rr-xr-xr-x 0 0 10450-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CAG1AJ41.htm 48 .ac. d/dr-xr-xr-x 0 0 10451-144-1 /Documents and Settings/malware/PrintHood 48 ..c. d/dr-xr-xr-x 0 0 10452-144-1 /Documents and Settings/malware/NetHood 56 .ac. d/d--x--x--x 0 0 10453-144-6 /Documents and Settings/malware/My Documents 56 .ac. d/dr-xr-xr-x 0 0 10454-144-6 /Documents and Settings/malware/Local Settings 1104 ..c. r/rr-xr-xr-x 0 0 1046-128-3 /WINDOWS/inf/netgpc.inf 56 .ac. d/dr-xr-xr-x 0 0 10461-144-6 /Documents and Settings/malware/Local Settings/Temp 56 .ac. d/dr-xr-xr-x 0 0 10464-144-6 /Documents and Settings/malware/Local Settings/Application Data 56 .ac. d/dr-xr-xr-x 0 0 10465-144-6 /Documents and Settings/malware/Local Settings/Application Data/Microsoft 136 .ac. d/dr-xr-xr-x 0 0 10466-144-1 /Documents and Settings/malware/Local Settings/Application Data/Microsoft/Windows Media 56 .ac. d/dr-xr-xr-x 0 0 10467-144-5 /Documents and Settings/malware/Local Settings/Application Data/Microsoft/Windows Media/9.0 8192 ..c. r/rr-xr-xr-x 0 0 10468-128-3 /WINDOWS/SoftwareDistribution/DataStore/Logs/edb.chk 296 .ac. d/dr-xr-xr-x 0 0 10469-144-1 /Documents and Settings/malware/Local Settings/Application Data/Microsoft/Media Player 56 .ac. d/d--x--x--x 0 0 10470-144-6 /Documents and Settings/malware/Favorites 288 .ac. d/dr-xr-xr-x 0 0 10471-144-1 /Documents and Settings/malware/Desktop 568 .ac. d/d--x--x--x 0 0 10473-144-1 /Documents and Settings/malware/Application Data 136 .a.. d/drwxrwxrwx 0 0 10475-144-1 /Documents and Settings/malware/Application Data/Microsoft/SystemCertificates 456 .a.. d/drwxrwxrwx 0 0 10476-144-1 /Documents and Settings/malware/Application Data/Microsoft/SystemCertificates/My 3537 ..c. r/rr-xr-xr-x 0 0 1048-128-3 /WINDOWS/inf/netias.inf 48 .ac. d/dr-xr-xr-x 0 0 10480-144-1 /Documents and Settings/malware/Application Data/Microsoft/Media Player 576 .ac. d/dr-xr-xr-x 0 0 10481-144-1 /Documents and Settings/malware/Application Data/Microsoft/Internet Explorer 57 ..c. r/r--x--x--x 0 0 10482-128-3 /Documents and Settings/malware/Templates/wordpfct.wpg 30 ..c. r/r--x--x--x 0 0 10483-128-3 /Documents and Settings/malware/Templates/wordpfct.wpd 1769 ..c. r/rr-xr-xr-x 0 0 10484-128-4 /Documents and Settings/malware/Templates/winword2.doc 4608 ..c. r/rr-xr-xr-x 0 0 10485-128-4 /Documents and Settings/malware/Templates/winword.doc 58 ..c. r/rr-xr-xr-x 0 0 10486-128-3 /Documents and Settings/malware/Templates/sndrec.wav 4017 ..c. r/rr-xr-xr-x 0 0 10487-128-4 /Documents and Settings/malware/Templates/quattro.wb2 461 ..c. r/rr-xr-xr-x 0 0 10488-128-3 /Documents and Settings/malware/Templates/presenta.shw 12288 ..c. r/rr-xr-xr-x 0 0 10489-128-4 /Documents and Settings/malware/Templates/powerpnt.ppt 1862 ..c. r/rr-xr-xr-x 0 0 1049-128-3 /WINDOWS/inf/netiprip.inf 2448 ..c. r/rr-xr-xr-x 0 0 10490-128-4 /Documents and Settings/malware/Templates/lotus.wk4 1518 ..c. r/rr-xr-xr-x 0 0 10491-128-4 /Documents and Settings/malware/Templates/excel4.xls 5632 ..c. r/rr-xr-xr-x 0 0 10492-128-4 /Documents and Settings/malware/Templates/excel.xls 4570 ..c. r/rr-xr-xr-x 0 0 10493-128-4 /Documents and Settings/malware/Templates/amipro.sam 804 ..c. r/rr-xr-xr-x 0 0 10494-128-4 /Documents and Settings/malware/Start Menu/Programs/Accessories/Entertainment/Windows Media Player.lnk 1599 ..c. r/rr-xr-xr-x 0 0 10496-128-4 /Documents and Settings/malware/Start Menu/Programs/Remote Assistance.lnk 1487 ..c. r/rr-xr-xr-x 0 0 10497-128-4 /Documents and Settings/malware/Start Menu/Programs/Accessories/Windows Explorer.lnk 1527 ..c. r/rr-xr-xr-x 0 0 10498-128-4 /Documents and Settings/malware/Start Menu/Programs/Accessories/Tour Windows XP.lnk 376 ..c. r/rr-xr-xr-x 0 0 10499-128-3 /Documents and Settings/malware/Start Menu/Programs/Messenger Center.lnk 4456 ..c. r/rr-xr-xr-x 0 0 1050-128-3 /WINDOWS/inf/netirda.inf 382 ..c. r/rr-xr-xr-x 0 0 10500-128-3 /Documents and Settings/malware/Start Menu/Programs/Media Player Center.lnk 1056768 ..c. r/rr-xr-xr-x 0 0 10502-128-4 /WINDOWS/SoftwareDistribution/DataStore/DataStore.edb 1519 ..c. r/rr-xr-xr-x 0 0 10503-128-4 /Documents and Settings/malware/Start Menu/Programs/Accessories/Synchronize.lnk 386 ..c. r/rr-xr-xr-x 0 0 10504-128-3 /Documents and Settings/malware/Start Menu/Programs/Accessories/Program Compatibility Wizard.lnk 792 ..c. r/rr-xr-xr-x 0 0 10505-128-4 /Documents and Settings/malware/Start Menu/Programs/Windows Media Player.lnk 1519 ..c. r/rr-xr-xr-x 0 0 10506-128-4 /Documents and Settings/malware/Start Menu/Programs/Accessories/Notepad.lnk 1555 ..c. r/rr-xr-xr-x 0 0 10509-128-4 /Documents and Settings/malware/Start Menu/Programs/Accessories/Command Prompt.lnk 15219 ..c. r/rr-xr-xr-x 0 0 1051-128-3 /WINDOWS/inf/netirsir.inf 1539 ..c. r/rr-xr-xr-x 0 0 10510-128-4 /Documents and Settings/malware/Start Menu/Programs/Accessories/Accessibility/Utility Manager.lnk 1501 ..c. r/rr-xr-xr-x 0 0 10511-128-4 /Documents and Settings/malware/Start Menu/Programs/Accessories/Accessibility/On-Screen Keyboard.lnk 0 ..c. r/rr-xr-xr-x 0 0 10512-128-3 /Documents and Settings/malware/SendTo/Mail Recipient.MAPIMail 1532 ..c. r/rr-xr-xr-x 0 0 10513-128-4 /Documents and Settings/malware/Start Menu/Programs/Accessories/Accessibility/Narrator.lnk 1525 ..c. r/rr-xr-xr-x 0 0 10515-128-4 /Documents and Settings/malware/Start Menu/Programs/Accessories/Accessibility/Magnifier.lnk 0 ..c. r/rr-xr-xr-x 0 0 10518-128-3 /Documents and Settings/malware/SendTo/Desktop (create shortcut).DeskLink 0 ..c. r/rr-xr-xr-x 0 0 10519-128-3 /Documents and Settings/malware/SendTo/Compressed (zipped) Folder.ZFSendToTarget 1190 ..c. r/rr-xr-xr-x 0 0 1052-128-3 /WINDOWS/inf/netlanem.inf 0 .acb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.findfertile.org/ac3.php?aid=531&sid=direc20 cache stored in: SLK18LSF/ac3[1].htm - HTTP/1.1 200 OK - Content-Length: 105 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 56 .ac. d/dr-xr-xr-x 0 0 10529-144-5 /Documents and Settings/malware/Favorites/Links 1823 ..c. r/rr-xr-xr-x 0 0 1053-128-3 /WINDOWS/inf/netlanep.inf 12787 ..c. r/rr-xr-xr-x 0 0 10531-128-4 /Documents and Settings/malware/Local Settings/Application Data/Microsoft/Windows Media/9.0/WMSDKNS.XML 720896 ..c. r/rr-xr-xr-x 0 0 10532-128-4 /Documents and Settings/malware/Local Settings/Application Data/Microsoft/Media Player/CurrentDatabase_59R.wmdb 498 ..c. r/rr-xr-xr-x 0 0 10533-128-3 /Documents and Settings/malware/Local Settings/Application Data/Microsoft/Windows Media/9.0/WMSDKNS.DTD 49152 ..c. r/rr-xr-xr-x 0 0 10534-128-4 /Documents and Settings/malware/Cookies/index.dat 10383 ..c. r/rr-xr-xr-x 0 0 10535-128-6 /Documents and Settings/malware/Application Data/Microsoft/Internet Explorer/brndlog.txt 141 ..c. r/rr-xr-xr-x 0 0 10536-128-5 /Documents and Settings/malware/Application Data/Microsoft/Internet Explorer/brndlog.bak 392 .ac. d/dr-xr-xr-x 0 0 10539-144-1 /Documents and Settings/malware/Local Settings/Application Data/Microsoft/Windows 3001 ..c. r/rr-xr-xr-x 0 0 1054-128-3 /WINDOWS/inf/netloop.inf 262144 ..c. r/rr-xr-xr-x 0 0 10540-128-3 /Documents and Settings/malware/Local Settings/Application Data/Microsoft/Windows/UsrClass.dat 1024 ..c. r/rr-xr-xr-x 0 0 10541-128-4 /Documents and Settings/malware/Local Settings/Application Data/Microsoft/Windows/UsrClass.dat.LOG 328 .a.. d/drwxrwxrwx 0 0 10543-144-1 /Documents and Settings/malware/Local Settings/Application Data/Microsoft/Credentials 48 .a.. d/drwxrwxrwx 0 0 10544-144-1 /Documents and Settings/malware/Local Settings/Application Data/Microsoft/Credentials/S-1-5-21-1390067357-343818398-1801674531-1003 328 .a.. d/drwxrwxrwx 0 0 10545-144-1 /Documents and Settings/malware/Application Data/Microsoft/Credentials 48 .a.. d/drwxrwxrwx 0 0 10546-144-1 /Documents and Settings/malware/Application Data/Microsoft/Credentials/S-1-5-21-1390067357-343818398-1801674531-1003 384 .ac. d/d--x--x--x 0 0 10549-144-1 /Documents and Settings/malware/My Documents/My Pictures 3894 ..c. r/rr-xr-xr-x 0 0 1055-128-3 /WINDOWS/inf/netlpd.inf 668 ..c. r/rr-xr-xr-x 0 0 10551-128-4 /Documents and Settings/malware/My Documents/My Pictures/Sample Pictures.lnk 384 .ac. d/d--x--x--x 0 0 10552-144-1 /Documents and Settings/malware/My Documents/My Music 638 ..c. r/rr-xr-xr-x 0 0 10554-128-4 /Documents and Settings/malware/My Documents/My Music/Sample Music.lnk 0 ..c. r/rr-xr-xr-x 0 0 10555-128-1 /Documents and Settings/malware/SendTo/My Documents.mydocs 4830 ..c. r/rr-xr-xr-x 0 0 10556-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/76EF7E2C6994B1A2C79DDB1DF450[1].jpg 417 ..c. r/rr-xr-xr-x 0 0 10558-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/adchoices_gif2[1].gif 21999 ..c. r/rr-xr-xr-x 0 0 1056-128-3 /WINDOWS/inf/netmadge.inf 48 .ac. d/d--x--x--x 0 0 10562-144-6 /Documents and Settings/malware/Application Data/Microsoft/Internet Explorer/Quick Launch 48 .ac. d/dr-xr-xr-x 0 0 10563-144-1 /Program Files/Uninstall Information 767 ..c. r/rr-xr-xr-x 0 0 10565-128-4 /Documents and Settings/malware/Start Menu/Programs/Internet Explorer.lnk 779 ..c. r/rr-xr-xr-x 0 0 10566-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/2/Launch Internet Explorer Browser.lnk 1955 ..c. r/rr-xr-xr-x 0 0 1057-128-3 /WINDOWS/inf/netnb.inf 312 .ac. d/dr-xr-xr-x 0 0 10572-144-1 /Documents and Settings/malware/Application Data/Identities 48 .ac. d/dr-xr-xr-x 0 0 10573-144-1 /Documents and Settings/malware/Application Data/Identities/{F9D4997F-940A-4BD4-8675-DCAE73996185} 68 ..c. r/rr-xr-xr-x 0 0 10574-128-1 /Documents and Settings/malware/Cookies/malware@c.msn[2].txt 738 ..c. r/rr-xr-xr-x 0 0 10576-128-4 /Documents and Settings/malware/Start Menu/Programs/Outlook Express.lnk 3996 ..c. r/rr-xr-xr-x 0 0 10577-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/6ECB5F9A4119F2F7D7B4AF62EC5A[1].jpg 169 ..c. r/rr-xr-xr-x 0 0 10578-128-1 /Documents and Settings/malware/Favorites/Links/Windows Marketplace.url 6659 ..c. r/rr-xr-xr-x 0 0 1058-128-3 /WINDOWS/inf/netnovel.inf 3775 ..c. r/rr-xr-xr-x 0 0 10580-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/41EA2BB896C1D269F946D98D1E31A[1].jpg 42 ..c. r/rr-xr-xr-x 0 0 10582-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/805306726[1].gif 583 ..c. r/rr-xr-xr-x 0 0 10588-128-1 /Documents and Settings/malware/Cookies/malware@msn[1].txt 774 ..c. r/rr-xr-xr-x 0 0 10589-128-4 /Documents and Settings/malware/Start Menu/Programs/Accessories/Address Book.lnk 4410 ..c. r/rr-xr-xr-x 0 0 1059-128-3 /WINDOWS/inf/netnwcli.inf 79 ..c. r/rr-xr-xr-x 0 0 10590-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/2/Show Desktop.scf 119 ..c. r/rr-xr-xr-x 0 0 10593-128-1 /Documents and Settings/malware/Favorites/MSN.com.url 197 ..c. r/rr-xr-xr-x 0 0 10594-128-1 /Documents and Settings/malware/Favorites/Radio Station Guide.url 450669 ..c. r/rr-xr-xr-x 0 0 10595-128-3 /Program Files/Common Files/Microsoft Shared/web server extensions/40/bin/FP4AWEC.DLL 78706 ..c. r/rr-xr-xr-x 0 0 10596-128-3 /Program Files/Common Files/Microsoft Shared/web server extensions/40/bin/1033/FPEXT.MSG 532480 ..c. r/rr-xr-xr-x 0 0 10597-128-3 /Program Files/Common Files/System/Ole DB/MSDAIPP.DLL 155648 ..c. r/rr-xr-xr-x 0 0 10598-128-3 /Program Files/Common Files/System/Ole DB/MSDAPML.DLL 384 .ac. d/dr-xr-xr-x 0 0 10599-144-1 /Program Files/Common Files/Microsoft Shared/Web Folders 272 .ac. d/dr-xr-xr-x 0 0 106-144-1 /WINDOWS/Resources/Themes/Luna/Shell/Metallic 13273 ..c. r/rr-xr-xr-x 0 0 1060-128-3 /WINDOWS/inf/netnwlnk.inf 561209 ..c. r/rr-xr-xr-x 0 0 10600-128-3 /Program Files/Common Files/Microsoft Shared/Web Folders/MSONSEXT.DLL 122937 ..c. r/rr-xr-xr-x 0 0 10601-128-3 /Program Files/Common Files/Microsoft Shared/Web Folders/MSOWS409.DLL 8206 ..c. r/rr-xr-xr-x 0 0 10602-128-3 /Program Files/Common Files/Microsoft Shared/Web Folders/PUBPLACE.HTT 3159 ..c. r/rr-xr-xr-x 0 0 10603-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/AB3DEF1FC49CB32F0E8E93E988EBA[1].jpg 4078 ..c. r/rr-xr-xr-x 0 0 10604-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/5BDA7261AAEAD28A63201DFFAC2A4B[1].jpg 1046 ..c. r/rr-xr-xr-x 0 0 10605-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/ADSAdClient31[1].htm 618605 ..c. r/rr-xr-xr-x 0 0 10606-128-3 /Program Files/Common Files/Microsoft Shared/web server extensions/40/bin/fp4autl.dll 264704 ..c. r/rr-xr-xr-x 0 0 10607-128-3 /WINDOWS/Installer/5db67.msi 152 .ac. d/dr-xr-xr-x 0 0 10608-144-1 /WINDOWS/Installer/{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227} 166912 ..c. r/r--x--x--x 0 0 10609-128-3 /WINDOWS/Installer/{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}/places.exe 1323 ..c. r/rr-xr-xr-x 0 0 1061-128-3 /WINDOWS/inf/netpsa.inf 119 ..c. r/rr-xr-xr-x 0 0 10610-128-1 /Documents and Settings/malware/Favorites/Links/Customize Links.url 113 ..c. r/rr-xr-xr-x 0 0 10611-128-1 /Documents and Settings/malware/Favorites/Links/Free Hotmail.url 113 ..c. r/rr-xr-xr-x 0 0 10612-128-1 /Documents and Settings/malware/Favorites/Links/Windows.url 118 ..c. r/rr-xr-xr-x 0 0 10613-128-1 /Documents and Settings/malware/Favorites/Links/Windows Media.url 48 .ac. d/dr-xr-xr-x 0 0 10616-144-1 /Documents and Settings/malware/Local Settings/Application Data/Microsoft/CD Burning 1142 ..c. r/rr-xr-xr-x 0 0 10618-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/c57bc2a7d38843d7c4aa8028fc9f82[1].gif 4095 ..c. r/rr-xr-xr-x 0 0 10619-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/8E1CE8BD265B47CBBE321FF47E2A1[1].jpg 1870 ..c. r/rr-xr-xr-x 0 0 1062-128-3 /WINDOWS/inf/netpschd.inf 978 ..c. r/rr-xr-xr-x 0 0 10620-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/ADSAdClient31[1].htm 4330 ..c. r/rr-xr-xr-x 0 0 10621-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/003[1].png 16533 ..c. r/rr-xr-xr-x 0 0 10622-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/544[1].jpg 618605 ..c. r/rr-xr-xr-x 0 0 10623-128-1 /WINDOWS/system32/dllcache/fp4autl.dll 176 ..c. r/rr-xr-xr-x 0 0 10625-128-1 /Documents and Settings/malware/Cookies/malware@ad.wsod[2].txt 42 ..c. r/rr-xr-xr-x 0 0 10626-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/pixel[1].gif 5200 ..c. r/rr-xr-xr-x 0 0 10627-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/ADSAdClient31[1].htm 14512 ..c. r/rr-xr-xr-x 0 0 10629-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/899538en_msn[1].js 17594 ..c. r/rr-xr-xr-x 0 0 1063-128-3 /WINDOWS/inf/netrasa.inf 35 ..c. r/rr-xr-xr-x 0 0 10630-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/qsonhs[1].aspx 110 ..c. r/rr-xr-xr-x 0 0 10631-128-1 /Documents and Settings/malware/Cookies/malware@www.bing[1].txt 152 .a.. d/drwxrwxrwx 0 0 10632-144-1 /Documents and Settings/malware/Local Settings/History/History.IE5/MSHist012011070120110702 190 ..c. r/rr-xr-xr-x 0 0 10634-128-1 /Documents and Settings/malware/Cookies/malware@bing[1].txt 188 ..c. r/rr-xr-xr-x 0 0 10635-128-1 /Documents and Settings/malware/Cookies/malware@www.msn[1].txt 7582 ..c. r/rr-xr-xr-x 0 0 10636-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/9934D0635AD244E5FA684B7B8CBD0[1].gif 554 ..c. r/rr-xr-xr-x 0 0 10637-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/4a0253de6eac448d8f2c39c53f8926[2].js 5892 ..c. r/rr-xr-xr-x 0 0 1064-128-3 /WINDOWS/inf/netrast.inf 607 ..c. r/rr-xr-xr-x 0 0 10641-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/Sync[1].htm 1988 ..c. r/rr-xr-xr-x 0 0 10642-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/wlHelper[1].js 1340 ..c. r/rr-xr-xr-x 0 0 10644-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/wlHelper[3].js 452608 ..c. r/rr-xr-xr-x 0 0 10646-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/pusk[1].exe 3228 ..c. r/rr-xr-xr-x 0 0 1065-128-3 /WINDOWS/inf/netrsvp.inf 0 ..c. r/rr-xr-xr-x 0 0 10651-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/404[1].htm 299008 ..c. r/rr-xr-xr-x 0 0 10654-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/531-direct[1] 144130 ..c. r/rr-xr-xr-x 0 0 10657-128-4 /WINDOWS/inf/oem0.inf 1401520 ..c. r/rr-xr-xr-x 0 0 10659-128-3 /WINDOWS/inf/INFCACHE.1 2515 ..c. r/rr-xr-xr-x 0 0 1066-128-3 /WINDOWS/inf/netrwan.inf 160 .ac. d/dr-xr-xr-x 0 0 10664-144-1 /Documents and Settings/malware/Local Settings/Application Data/Microsoft/Internet Explorer 16384 ..c. r/rr-xr-xr-x 0 0 10665-128-3 /Documents and Settings/malware/Local Settings/Application Data/Microsoft/Internet Explorer/MSIMGSIZ.DAT 12328 ..c. r/rr-xr-xr-x 0 0 10666-128-4 /Documents and Settings/malware/Local Settings/Application Data/GDIPFONTCACHEV1.DAT 2429 ..c. r/rr-xr-xr-x 0 0 1067-128-3 /WINDOWS/inf/netsap.inf 26368 ..c. r/rr-xr-xr-x 0 0 10678-128-3 /WINDOWS/system32/drivers/USBSTOR.SYS 312 .ac. d/dr-xr-xr-x 0 0 10679-144-1 /Documents and Settings/malware/Local Settings/Temp/smtmp 3359 ..c. r/rr-xr-xr-x 0 0 1068-128-3 /WINDOWS/inf/netserv.inf 26368 ..c. r/rr-xr-xr-x 0 0 10680-128-1 /WINDOWS/system32/dllcache/usbstor.sys 56 .ac. d/dr-xr-xr-x 0 0 10681-144-5 /Documents and Settings/malware/Local Settings/Temp/smtmp/1 56 .ac. d/dr-xr-xr-x 0 0 10686-144-5 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs 136 .a.. d/dr-xr-xr-x 0 0 10687-144-1 /DRIVERS 152 .ac. d/dr-xr-xr-x 0 0 10688-144-1 /DRIVERS/WIN 624 .ac. d/dr-xr-xr-x 0 0 10689-144-1 /DRIVERS/WIN/ETHERNET 11674 ..c. r/rr-xr-xr-x 0 0 1069-128-3 /WINDOWS/inf/netsnmp.inf 127946 ..c. r/rr-xr-xr-x 0 0 10691-128-3 /WINDOWS/inf/oem0.PNF 480 .ac. d/dr-xr-xr-x 0 0 10693-144-1 /DRIVERS/WIN/ETHERNET/WINNT 157294 ..c. r/rr-xr-xr-x 0 0 10694-128-3 /DRIVERS/WIN/ETHERNET/WINNT/B57NT4.SYS 85325 ..c. r/rr-xr-xr-x 0 0 10695-128-3 /DRIVERS/WIN/ETHERNET/WINNT/OEMSETUP.INF 6928 ..c. r/rr-xr-xr-x 0 0 10696-128-3 /DRIVERS/WIN/ETHERNET/WINNT/B57DTECT.DLL 13483 ..c. r/rr-xr-xr-x 0 0 10697-128-3 /DRIVERS/WIN/ETHERNET/WINNT/B57NT4.HLP 144 .ac. d/dr-xr-xr-x 0 0 10698-144-1 /DRIVERS/WIN/ETHERNET/WINXP 376 .ac. d/dr-xr-xr-x 0 0 10699-144-1 /DRIVERS/WIN/ETHERNET/WINXP/IA32 272 .ac. d/dr-xr-xr-x 0 0 107-144-1 /WINDOWS/Resources/Themes/Luna/Shell/Homestead 4749 ..c. r/rr-xr-xr-x 0 0 1070-128-3 /WINDOWS/inf/nettpsmp.inf 43637 ..c. r/rr-xr-xr-x 0 0 10700-128-3 /DRIVERS/WIN/ETHERNET/WINXP/IA32/B57WIN32.CAT 144130 ..c. r/rr-xr-xr-x 0 0 10701-128-3 /DRIVERS/WIN/ETHERNET/WINXP/IA32/B57WIN32.INF 161792 ..c. r/rr-xr-xr-x 0 0 10702-128-3 /DRIVERS/WIN/ETHERNET/WINXP/IA32/B57XP32.SYS 4581 ..c. r/rr-xr-xr-x 0 0 10703-128-3 /DRIVERS/WIN/ETHERNET/SWI.XML 144 .ac. d/dr-xr-xr-x 0 0 10704-144-1 /DRIVERS/WIN/ETHERNET/BACS 264 .ac. d/dr-xr-xr-x 0 0 10705-144-1 /DRIVERS/WIN/ETHERNET/BACS/IA32 15451176 ..c. r/rr-xr-xr-x 0 0 10706-128-3 /DRIVERS/WIN/ETHERNET/BACS/IA32/SETUP.EXE 1291 ..c. r/rr-xr-xr-x 0 0 10707-128-3 /DRIVERS/WIN/ETHERNET/BACS/IA32/SILENTBA.TXT 344 .ac. d/dr-xr-xr-x 0 0 10708-144-1 /DRIVERS/WIN/ETHERNET/TOOLS 144 .ac. d/dr-xr-xr-x 0 0 10709-144-1 /DRIVERS/WIN/ETHERNET/TOOLS/UPDATE 839 ..c. r/rr-xr-xr-x 0 0 1071-128-3 /WINDOWS/inf/netupnp.inf 384 .ac. d/dr-xr-xr-x 0 0 10710-144-1 /DRIVERS/WIN/ETHERNET/TOOLS/UPDATE/WINNT 2957 ..c. r/rr-xr-xr-x 0 0 10711-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/UPDATE/WINNT/B57NT4UD.TXT 40960 ..c. r/rr-xr-xr-x 0 0 10712-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/UPDATE/WINNT/B57NT4UD.EXE 13188 ..c. r/rr-xr-xr-x 0 0 10713-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/UPDATE/WINNT/B57NT4UD.INF 144 .ac. d/dr-xr-xr-x 0 0 10714-144-1 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST 56 .ac. d/dr-xr-xr-x 0 0 10715-144-5 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32 51712 ..c. r/rr-xr-xr-x 0 0 10716-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/1034.MST 48128 ..c. r/rr-xr-xr-x 0 0 10717-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/1035.MST 53760 ..c. r/rr-xr-xr-x 0 0 10718-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/1036.MST 53760 ..c. r/rr-xr-xr-x 0 0 10719-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/1040.MST 51712 ..c. r/rr-xr-xr-x 0 0 10720-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/1041.MST 46592 ..c. r/rr-xr-xr-x 0 0 10721-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/1042.MST 52224 ..c. r/rr-xr-xr-x 0 0 10722-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/1043.MST 48128 ..c. r/rr-xr-xr-x 0 0 10723-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/1044.MST 50176 ..c. r/rr-xr-xr-x 0 0 10724-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/1046.MST 47104 ..c. r/rr-xr-xr-x 0 0 10725-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/1053.MST 46080 ..c. r/rr-xr-xr-x 0 0 10726-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/1054.MST 37376 ..c. r/rr-xr-xr-x 0 0 10727-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/2052.MST 1521664 ..c. r/rr-xr-xr-x 0 0 10728-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/BDRVINST.MSI 173239 ..c. r/rr-xr-xr-x 0 0 10729-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/FILES6~1.CAB 407 ..c. r/rr-xr-xr-x 0 0 1073-128-1 /WINDOWS/system32/drivers/etc/networks 227221 ..c. r/rr-xr-xr-x 0 0 10730-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/FILES_~1.CAB 3940232 ..c. r/rr-xr-xr-x 0 0 10731-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/SETUP.EXE 1087 ..c. r/rr-xr-xr-x 0 0 10732-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/SILENT.TXT 36352 ..c. r/rr-xr-xr-x 0 0 10733-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/1028.MST 48128 ..c. r/rr-xr-xr-x 0 0 10734-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/1030.MST 54272 ..c. r/rr-xr-xr-x 0 0 10735-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/1031.MST 3584 ..c. r/rr-xr-xr-x 0 0 10736-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/DRVINST/IA32/1033.MST 448 .ac. d/dr-xr-xr-x 0 0 10737-144-1 /DRIVERS/WIN/ETHERNET/TOOLS/UNATTEND 10982 ..c. r/rr-xr-xr-x 0 0 10738-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/UNATTEND/BDRVCOPY.BAT 272 .ac. d/dr-xr-xr-x 0 0 10739-144-1 /DRIVERS/WIN/ETHERNET/TOOLS/UNATTEND/WINNT 25517 ..c. r/rr-xr-xr-x 0 0 1074-128-3 /WINDOWS/Help/newfeat1.chm 2056 ..c. r/rr-xr-xr-x 0 0 10740-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/UNATTEND/WINNT/BDRVCOPY.TXT 1305 ..c. r/rr-xr-xr-x 0 0 10741-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/UNATTEND/WINNT/UNATTEND.TXT 272 .ac. d/dr-xr-xr-x 0 0 10742-144-1 /DRIVERS/WIN/ETHERNET/TOOLS/UNATTEND/WIN2K 2329 ..c. r/rr-xr-xr-x 0 0 10743-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/UNATTEND/WIN2K/BDRVCOPY.TXT 1287 ..c. r/rr-xr-xr-x 0 0 10744-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/UNATTEND/WIN2K/UNATTEND.TXT 272 .ac. d/dr-xr-xr-x 0 0 10745-144-1 /DRIVERS/WIN/ETHERNET/TOOLS/UNATTEND/IA32 2324 ..c. r/rr-xr-xr-x 0 0 10746-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/UNATTEND/IA32/BDRVCOPY.TXT 1425 ..c. r/rr-xr-xr-x 0 0 10747-128-3 /DRIVERS/WIN/ETHERNET/TOOLS/UNATTEND/IA32/UNATTEND.TXT 376 .ac. d/dr-xr-xr-x 0 0 10748-144-1 /DRIVERS/WIN/ETHERNET/WIN2000 157456 ..c. r/rr-xr-xr-x 0 0 10749-128-3 /DRIVERS/WIN/ETHERNET/WIN2000/B57W2K.SYS 16162 ..c. r/rr-xr-xr-x 0 0 1075-128-3 /WINDOWS/Help/newfeat1.hlp 43637 ..c. r/rr-xr-xr-x 0 0 10750-128-3 /DRIVERS/WIN/ETHERNET/WIN2000/B57WIN32.CAT 144130 ..c. r/rr-xr-xr-x 0 0 10751-128-3 /DRIVERS/WIN/ETHERNET/WIN2000/B57WIN32.INF 161792 ..c. r/rr-xr-xr-x 0 0 10752-128-3 /WINDOWS/system32/drivers/b57xp32.sys 56 .ac. d/dr-xr-xr-x 0 0 10754-144-6 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories 161792 ..c. r/rr-xr-xr-x 0 0 10755-128-1 /WINDOWS/system32/dllcache/b57xp32.sys 400 .ac. d/dr-xr-xr-x 0 0 10756-144-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Accessibility 11047 ..c. r/rr-xr-xr-x 0 0 1076-128-3 /WINDOWS/Help/newfeat2.chm 11671 ..c. r/rr-xr-xr-x 0 0 10761-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/AuthenticationForm[1].htm 861 ..c. r/rr-xr-xr-x 0 0 10762-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/AuthenticationServlet2745323f[1].htm 210 ..c. r/rr-xr-xr-x 0 0 10763-128-1 /Documents and Settings/malware/Cookies/malware@AuthenticationServer[2].txt 43 ..c. r/rr-xr-xr-x 0 0 10764-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/primedns[2].gif 56 .ac. d/dr-xr-xr-x 0 0 10765-144-6 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Communications 2123 ..c. r/rr-xr-xr-x 0 0 10766-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/37055364ab006eb95ebbd60846447a[2].css 93256 ..c. r/rr-xr-xr-x 0 0 10767-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/c8d8548fff61b10f6f95b987c13eeg_header[2].css 5585 ..c. r/rr-xr-xr-x 0 0 10768-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/4C5D1CE4F9A4087C4EB51205AF447[1].jpg 3047 ..c. r/rr-xr-xr-x 0 0 10769-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/B496798D315B46845DC9DC6A1CAE8[1].jpg 4536 ..c. r/rr-xr-xr-x 0 0 1077-128-3 /WINDOWS/Help/newfeat2.hlp 72182 ..c. r/rr-xr-xr-x 0 0 10770-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/jquery-1.4.2.min[2].js 4429 ..c. r/rr-xr-xr-x 0 0 10771-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/ce21c8d14e6fd893c6c2cde5c0319d[2].css 137 ..c. r/rr-xr-xr-x 0 0 10772-128-1 /Documents and Settings/malware/Cookies/malware@exp.www.msn[1].txt 4082 ..c. r/rr-xr-xr-x 0 0 10773-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/BING_websearch_2[1].jpg 91435 ..c. r/rr-xr-xr-x 0 0 10774-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/ae030ac3f559d4b1e167097964e115[2].js 3737 ..c. r/rr-xr-xr-x 0 0 10775-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/dapbeta[1].js 12823 ..c. r/rr-xr-xr-x 0 0 10776-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/8b0fe9bcd1399077fdc9374e5f314d[1].png 9288 ..c. r/rr-xr-xr-x 0 0 10777-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/wlanalytics[1].js 7210 ..c. r/rr-xr-xr-x 0 0 10779-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/7980776cb684844c20339b839ac35e[1].gif 11047 ..c. r/rr-xr-xr-x 0 0 1078-128-3 /WINDOWS/Help/newfeat3.chm 776 ..c. r/rr-xr-xr-x 0 0 10780-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/11[1].gif 6726 ..c. r/rr-xr-xr-x 0 0 10781-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/CFFF237B674B87B219E8D9DE7866E2[1].jpg 2477 ..c. r/rr-xr-xr-x 0 0 10782-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/EB75D45B8948F72EE451223E95A96[1].gif 48 ..c. r/rr-xr-xr-x 0 0 10783-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/617475cf39bf6f5c0bd6ecb985335c[1].gif 7079 ..c. r/rr-xr-xr-x 0 0 10784-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/ADF825F54B93DD9717F8D5B9042[1].jpg 7334 ..c. r/rr-xr-xr-x 0 0 10785-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/C8E4CD4E96D43D83BEA03FDE2776D[1].jpg 21739 ..c. r/rr-xr-xr-x 0 0 10786-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/481C3AA95082408E63C2954E247383[1].jpg 657 ..c. r/rr-xr-xr-x 0 0 10787-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/37BA92E210D341BFDBF4126422A3D2[1].gif 6111 ..c. r/rr-xr-xr-x 0 0 10788-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/D26637BD322F8183C19B9F69F5B6B[1].jpg 3573 ..c. r/rr-xr-xr-x 0 0 10789-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/71912B7D969E821317CDE11393A271[1].jpg 4536 ..c. r/rr-xr-xr-x 0 0 1079-128-3 /WINDOWS/Help/newfeat3.hlp 5603 ..c. r/rr-xr-xr-x 0 0 10790-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/DDCC1D859DAB8B53D96D6F48A91[1].jpg 43 ..c. r/rr-xr-xr-x 0 0 10791-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/614595fba50d96389708a4135776e4[1].gif 554 ..c. r/rr-xr-xr-x 0 0 10792-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/adchoices_gif[1].gif 3211 ..c. r/rr-xr-xr-x 0 0 10793-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/8029BE41DF23A9E2D713B24DD15B5[1].gif 4921 ..c. r/rr-xr-xr-x 0 0 10794-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/1FBB87D91FC9133FE2DDE8A69D26F4[1].jpg 2761 ..c. r/rr-xr-xr-x 0 0 10795-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/5278AA767DE4E1D28B266BDC6AEE97[1].jpg 21028 ..c. r/rr-xr-xr-x 0 0 10796-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/157[1].gif 6096 ..c. r/rr-xr-xr-x 0 0 10797-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/BING_web_search[1].jpg 3069 ..c. r/rr-xr-xr-x 0 0 10798-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/7B05620FD5E4ABCB6EDC2F046198C[1].jpg 56 .ac. d/dr-xr-xr-x 0 0 108-144-5 /WINDOWS/Help/Tours/mmTour 11047 ..c. r/rr-xr-xr-x 0 0 1080-128-3 /WINDOWS/Help/newfeat4.chm 10485 ..c. r/rr-xr-xr-x 0 0 10802-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/AutoSuggest_min[2].js 94 ..c. r/rr-xr-xr-x 0 0 10805-128-1 /Documents and Settings/malware/Cookies/malware@live[1].txt 10368 ..c. r/rr-xr-xr-x 0 0 10807-128-3 /WINDOWS/system32/drivers/hidusb.sys 464 ..c. r/rr-xr-xr-x 0 0 10809-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/Include[1].htm 4536 ..c. r/rr-xr-xr-x 0 0 1081-128-3 /WINDOWS/Help/newfeat4.hlp 56 .ac. d/dr-xr-xr-x 0 0 10810-144-6 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Entertainment 13068 ..c. r/rr-xr-xr-x 0 0 10812-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/41A6EA1EFC5688B1A57FE8B773D1[1].jpg 12160 ..c. r/rr-xr-xr-x 0 0 10813-128-1 /WINDOWS/system32/dllcache/mouhid.sys 10368 ..c. r/rr-xr-xr-x 0 0 10816-128-1 /WINDOWS/system32/dllcache/hidusb.sys 12160 ..c. r/rr-xr-xr-x 0 0 10817-128-3 /WINDOWS/system32/drivers/mouhid.sys 11047 ..c. r/rr-xr-xr-x 0 0 1082-128-3 /WINDOWS/Help/newfeat5.chm 4536 ..c. r/rr-xr-xr-x 0 0 1083-128-3 /WINDOWS/Help/newfeat5.hlp 56 .ac. d/dr-xr-xr-x 0 0 10830-144-6 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/System Tools 12032 ..c. r/rr-xr-xr-x 0 0 1084-128-3 /WINDOWS/system32/drivers/nikedrv.sys 56 .ac. d/dr-xr-xr-x 0 0 10843-144-6 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Administrative Tools 232 ..c. r/rr-xr-xr-x 0 0 10849-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/status_ok.gif 56 .ac. d/dr-xr-xr-x 0 0 10854-144-5 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Games 781 ..c. r/rr-xr-xr-x 0 0 10857-128-3 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/PSS.css 84 ..c. r/rr-xr-xr-x 0 0 1086-128-1 /WINDOWS/Help/nocontnt.cnt 272 .ac. d/dr-xr-xr-x 0 0 10861-144-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US 464 .ac. d/dr-xr-xr-x 0 0 10862-144-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US/Remote Assistance 144 .ac. d/dr-xr-xr-x 0 0 10863-144-1 /Program Files/Windows Resource Kits 56 .ac. d/dr-xr-xr-x 0 0 10864-144-6 /Program Files/Windows Resource Kits/Tools 16384 ..c. r/rr-xr-xr-x 0 0 10865-128-3 /Program Files/Windows Resource Kits/Tools/atmarp.exe 13312 ..c. r/rr-xr-xr-x 0 0 10866-128-3 /Program Files/Windows Resource Kits/Tools/atmlane.exe 13824 ..c. r/rr-xr-xr-x 0 0 10867-128-3 /Program Files/Windows Resource Kits/Tools/cdburn.exe 155360 ..c. r/rr-xr-xr-x 0 0 10868-128-3 /Program Files/Windows Resource Kits/Tools/cepsetup.exe 364032 ..c. r/rr-xr-xr-x 0 0 10869-128-3 /Program Files/Windows Resource Kits/Tools/chklnks.exe 11562 ..c. r/rr-xr-xr-x 0 0 1087-128-3 /WINDOWS/Help/nofts.chm 6340 ..c. r/rr-xr-xr-x 0 0 10870-128-4 /Program Files/Windows Resource Kits/Tools/checkrepl.vbs 9728 ..c. r/rr-xr-xr-x 0 0 10871-128-3 /Program Files/Windows Resource Kits/Tools/clearmem.exe 1849856 ..c. r/rr-xr-xr-x 0 0 10872-128-3 /Program Files/Windows Resource Kits/Tools/clusdiag.msi 248705 ..c. r/rr-xr-xr-x 0 0 10873-128-4 /Program Files/Windows Resource Kits/Tools/clusterrecovery.chm 155648 ..c. r/rr-xr-xr-x 0 0 10874-128-4 /Program Files/Windows Resource Kits/Tools/clusterrecovery.exe 40448 ..c. r/rr-xr-xr-x 0 0 10875-128-3 /Program Files/Windows Resource Kits/Tools/confdisk.exe 5632 ..c. r/rr-xr-xr-x 0 0 10876-128-3 /Program Files/Windows Resource Kits/Tools/creatfil.exe 7168 ..c. r/rr-xr-xr-x 0 0 10877-128-4 /Program Files/Windows Resource Kits/Tools/crutredir.dll 54784 ..c. r/rr-xr-xr-x 0 0 10878-128-3 /Program Files/Windows Resource Kits/Tools/delprof.exe 1766911 ..c. r/rr-xr-xr-x 0 0 10879-128-3 /Program Files/Windows Resource Kits/Tools/deploy.cab 64000 ..c. r/rr-xr-xr-x 0 0 10880-128-3 /Program Files/Windows Resource Kits/Tools/dh.exe 367 ..c. r/rr-xr-xr-x 0 0 10882-128-1 /Program Files/Windows Resource Kits/Tools/dumpfsmos.cmd 15360 ..c. r/rr-xr-xr-x 0 0 10883-128-3 /Program Files/Windows Resource Kits/Tools/dvdburn.exe 37948 ..c. r/rr-xr-xr-x 0 0 10884-128-4 /Program Files/Windows Resource Kits/Tools/eventcombmt.chm 115712 ..c. r/rr-xr-xr-x 0 0 10885-128-4 /Program Files/Windows Resource Kits/Tools/eventcombmt.exe 204288 ..c. r/rr-xr-xr-x 0 0 10886-128-3 /Program Files/Windows Resource Kits/Tools/fcsetup.exe 275436 ..c. r/rr-xr-xr-x 0 0 10887-128-4 /Program Files/Windows Resource Kits/Tools/samplereasons.reg 3547 ..c. r/rr-xr-xr-x 0 0 10888-128-3 /Program Files/Windows Resource Kits/Tools/inetesc.adm 52736 ..c. r/rr-xr-xr-x 0 0 10889-128-3 /Program Files/Windows Resource Kits/Tools/ifilttst.exe 3054 ..c. r/rr-xr-xr-x 0 0 10890-128-3 /Program Files/Windows Resource Kits/Tools/srvmgr.cnt 1119232 ..c. r/rr-xr-xr-x 0 0 10891-128-4 /Program Files/Windows Resource Kits/Tools/gpmonitor.exe 76288 ..c. r/rr-xr-xr-x 0 0 10892-128-4 /Program Files/Windows Resource Kits/Tools/rcontrolad.exe 135680 ..c. r/rr-xr-xr-x 0 0 10893-128-3 /Program Files/Windows Resource Kits/Tools/iviewers.dll 39936 ..c. r/rr-xr-xr-x 0 0 10894-128-3 /Program Files/Windows Resource Kits/Tools/kerbtray.exe 29184 ..c. r/rr-xr-xr-x 0 0 10895-128-3 /Program Files/Windows Resource Kits/Tools/klist.exe 3674 ..c. r/rr-xr-xr-x 0 0 10897-128-3 /Program Files/Windows Resource Kits/Tools/lbridge.cmd 11264 ..c. r/rr-xr-xr-x 0 0 10898-128-3 /Program Files/Windows Resource Kits/Tools/linkd.exe 35840 ..c. r/rr-xr-xr-x 0 0 10899-128-4 /Program Files/Windows Resource Kits/Tools/linkspeed.exe 56 .ac. d/dr-xr-xr-x 0 0 109-144-6 /WINDOWS/Help/Tours/htmlTour 4608 ..c. r/rr-xr-xr-x 0 0 10900-128-3 /Program Files/Windows Resource Kits/Tools/logtime.exe 12800 ..c. r/rr-xr-xr-x 0 0 10901-128-3 /Program Files/Windows Resource Kits/Tools/lsreport.exe 113664 ..c. r/rr-xr-xr-x 0 0 10902-128-3 /Program Files/Windows Resource Kits/Tools/lsview.exe 9728 ..c. r/rr-xr-xr-x 0 0 10903-128-3 /Program Files/Windows Resource Kits/Tools/mcast.exe 174080 ..c. r/rr-xr-xr-x 0 0 10904-128-3 /Program Files/Windows Resource Kits/Tools/mibcc.exe 8192 ..c. r/rr-xr-xr-x 0 0 10905-128-3 /Program Files/Windows Resource Kits/Tools/moveuser.exe 107008 ..c. r/rr-xr-xr-x 0 0 10906-128-3 /Program Files/Windows Resource Kits/Tools/mstlsapi.dll 32256 ..c. r/rr-xr-xr-x 0 0 10907-128-3 /Program Files/Windows Resource Kits/Tools/now.exe 202752 ..c. r/rr-xr-xr-x 0 0 10908-128-3 /Program Files/Windows Resource Kits/Tools/kernrate.doc 32256 ..c. r/rr-xr-xr-x 0 0 10909-128-3 /Program Files/Windows Resource Kits/Tools/ntrights.exe 25088 ..c. r/rr-xr-xr-x 0 0 10910-128-3 /Program Files/Windows Resource Kits/Tools/oh.exe 146432 ..c. r/rr-xr-xr-x 0 0 10911-128-3 /Program Files/Windows Resource Kits/Tools/oleview.exe 85989 ..c. r/rr-xr-xr-x 0 0 10912-128-3 /Program Files/Windows Resource Kits/Tools/pooltag.txt 2104 ..c. r/rr-xr-xr-x 0 0 10913-128-4 /Program Files/Windows Resource Kits/Tools/rqs_setup.bat 14336 ..c. r/rr-xr-xr-x 0 0 10914-128-3 /Program Files/Windows Resource Kits/Tools/pfmon.exe 16896 ..c. r/rr-xr-xr-x 0 0 10917-128-3 /Program Files/Windows Resource Kits/Tools/qgrep.exe 6856 ..c. r/rr-xr-xr-x 0 0 10918-128-3 /Program Files/Windows Resource Kits/Tools/queryad.vbs 348160 ..c. r/rr-xr-xr-x 0 0 10919-128-3 /Program Files/Windows Resource Kits/Tools/remapkey.exe 79872 ..c. r/rr-xr-xr-x 0 0 10920-128-3 /Program Files/Windows Resource Kits/Tools/robocopy.exe 253440 ..c. r/rr-xr-xr-x 0 0 10921-128-3 /Program Files/Windows Resource Kits/Tools/robocopy.doc 14336 ..c. r/rr-xr-xr-x 0 0 10922-128-3 /Program Files/Windows Resource Kits/Tools/rpcdump.exe 20480 ..c. r/rr-xr-xr-x 0 0 10923-128-3 /Program Files/Windows Resource Kits/Tools/showperf.exe 32768 ..c. r/rr-xr-xr-x 0 0 10924-128-3 /Program Files/Windows Resource Kits/Tools/showpriv.exe 5120 ..c. r/rr-xr-xr-x 0 0 10925-128-3 /Program Files/Windows Resource Kits/Tools/sleep.exe 248320 ..c. r/rr-xr-xr-x 0 0 10926-128-3 /Program Files/Windows Resource Kits/Tools/subinacl.exe 6656 ..c. r/rr-xr-xr-x 0 0 10927-128-3 /Program Files/Windows Resource Kits/Tools/tail.exe 9216 ..c. r/rr-xr-xr-x 0 0 10928-128-3 /Program Files/Windows Resource Kits/Tools/timezone.exe 10202 ..c. r/rr-xr-xr-x 0 0 10929-128-4 /Program Files/Windows Resource Kits/Tools/clusfileport_win2000.inf 23040 ..c. r/rr-xr-xr-x 0 0 10930-128-3 /Program Files/Windows Resource Kits/Tools/vadump.exe 528440 ..c. r/rr-xr-xr-x 0 0 10931-128-3 /Program Files/Windows Resource Kits/Tools/vfi.exe 124416 ..c. r/rr-xr-xr-x 0 0 10932-128-3 /Program Files/Windows Resource Kits/Tools/adlb.exe 7168 ..c. r/rr-xr-xr-x 0 0 10933-128-3 /Program Files/Windows Resource Kits/Tools/autoexnt.exe 1080 ..c. r/rr-xr-xr-x 0 0 10934-128-3 /Program Files/Windows Resource Kits/Tools/cmdhere.inf 28160 ..c. r/rr-xr-xr-x 0 0 10935-128-3 /Program Files/Windows Resource Kits/Tools/cmgetcer.dll 3232 ..c. r/rr-xr-xr-x 0 0 10936-128-3 /Program Files/Windows Resource Kits/Tools/cmgetcer.txt 9728 ..c. r/rr-xr-xr-x 0 0 10937-128-3 /Program Files/Windows Resource Kits/Tools/consume.exe 45568 ..c. r/rr-xr-xr-x 0 0 10938-128-3 /Program Files/Windows Resource Kits/Tools/csccmd.exe 38912 ..c. r/rr-xr-xr-x 0 0 10939-128-3 /Program Files/Windows Resource Kits/Tools/list.exe 33792 ..c. r/rr-xr-xr-x 0 0 10940-128-3 /Program Files/Windows Resource Kits/Tools/ntimer.exe 6656 ..c. r/rr-xr-xr-x 0 0 10941-128-3 /Program Files/Windows Resource Kits/Tools/pathman.exe 3064 ..c. r/rr-xr-xr-x 0 0 10942-128-3 /Program Files/Windows Resource Kits/Tools/usrmgr.cnt 15360 ..c. r/rr-xr-xr-x 0 0 10943-128-3 /Program Files/Windows Resource Kits/Tools/perms.exe 10752 ..c. r/rr-xr-xr-x 0 0 10944-128-3 /Program Files/Windows Resource Kits/Tools/pmon.exe 36864 ..c. r/rr-xr-xr-x 0 0 10945-128-3 /Program Files/Windows Resource Kits/Tools/regini.exe 8192 ..c. r/rr-xr-xr-x 0 0 10946-128-3 /Program Files/Windows Resource Kits/Tools/srvany.exe 14336 ..c. r/rr-xr-xr-x 0 0 10947-128-4 /Program Files/Windows Resource Kits/Tools/memmonitor.exe 168016 ..c. r/rr-xr-xr-x 0 0 10948-128-3 /Program Files/Windows Resource Kits/Tools/tcmon.exe 30152 ..c. r/rr-xr-xr-x 0 0 10949-128-3 /Program Files/Windows Resource Kits/Tools/wins.dll 4608 ..c. r/rr-xr-xr-x 0 0 10950-128-3 /Program Files/Windows Resource Kits/Tools/permcopy.exe 39936 ..c. r/rr-xr-xr-x 0 0 10951-128-3 /Program Files/Windows Resource Kits/Tools/srvinfo.exe 14336 ..c. r/rr-xr-xr-x 0 0 10952-128-3 /Program Files/Windows Resource Kits/Tools/getcm.exe 2719 ..c. r/rr-xr-xr-x 0 0 10953-128-3 /Program Files/Windows Resource Kits/Tools/getcm.txt 8704 ..c. r/rr-xr-xr-x 0 0 10954-128-3 /Program Files/Windows Resource Kits/Tools/instcm.exe 1023 ..c. r/rr-xr-xr-x 0 0 10955-128-3 /Program Files/Windows Resource Kits/Tools/instcm.txt 20992 ..c. r/rr-xr-xr-x 0 0 10956-128-3 /Program Files/Windows Resource Kits/Tools/rqs.exe 8192 ..c. r/rr-xr-xr-x 0 0 10957-128-3 /Program Files/Windows Resource Kits/Tools/rqc.exe 6144 ..c. r/rr-xr-xr-x 0 0 10958-128-3 /Program Files/Windows Resource Kits/Tools/rqsmsg.dll 34585 ..c. r/rr-xr-xr-x 0 0 10959-128-4 /Program Files/Windows Resource Kits/Tools/winpolicies.chm 5657 ..c. r/rr-xr-xr-x 0 0 10960-128-3 /Program Files/Windows Resource Kits/Tools/frsflags.vbs 29696 ..c. r/rr-xr-xr-x 0 0 10961-128-3 /Program Files/Windows Resource Kits/Tools/rpings.exe 40448 ..c. r/rr-xr-xr-x 0 0 10962-128-3 /Program Files/Windows Resource Kits/Tools/rpingc.exe 15872 ..c. r/rr-xr-xr-x 0 0 10963-128-3 /Program Files/Windows Resource Kits/Tools/showacls.exe 46592 ..c. r/rr-xr-xr-x 0 0 10964-128-3 /Program Files/Windows Resource Kits/Tools/rpccfg.exe 40960 ..c. r/rr-xr-xr-x 0 0 10965-128-3 /Program Files/Windows Resource Kits/Tools/qtcp.exe 81408 ..c. r/rr-xr-xr-x 0 0 10966-128-4 /Program Files/Windows Resource Kits/Tools/rassrvmon.exe 27699 ..c. r/rr-xr-xr-x 0 0 10967-128-3 /Program Files/Windows Resource Kits/Tools/wlbs_hb.dll 16896 ..c. r/rr-xr-xr-x 0 0 10968-128-3 /Program Files/Windows Resource Kits/Tools/diskuse.exe 31232 ..c. r/rr-xr-xr-x 0 0 10969-128-3 /Program Files/Windows Resource Kits/Tools/mqcast.exe 25236 ..c. r/rr-xr-xr-x 0 0 1097-128-3 /WINDOWS/Help/notepad.chm 34816 ..c. r/rr-xr-xr-x 0 0 10970-128-3 /Program Files/Windows Resource Kits/Tools/mqcatch.exe 41984 ..c. r/rr-xr-xr-x 0 0 10971-128-3 /Program Files/Windows Resource Kits/Tools/mqcast.doc 200192 ..c. r/rr-xr-xr-x 0 0 10972-128-3 /Program Files/Windows Resource Kits/Tools/diskraid.exe 9728 ..c. r/rr-xr-xr-x 0 0 10973-128-3 /Program Files/Windows Resource Kits/Tools/empty.exe 5632 ..c. r/rr-xr-xr-x 0 0 10974-128-3 /Program Files/Windows Resource Kits/Tools/ifmember.exe 104960 ..c. r/rr-xr-xr-x 0 0 10975-128-3 /Program Files/Windows Resource Kits/Tools/kernrate.exe 12800 ..c. r/rr-xr-xr-x 0 0 10976-128-3 /Program Files/Windows Resource Kits/Tools/winexit.scr 31744 ..c. r/rr-xr-xr-x 0 0 10977-128-3 /Program Files/Windows Resource Kits/Tools/regview.exe 18944 ..c. r/rr-xr-xr-x 0 0 10978-128-3 /Program Files/Windows Resource Kits/Tools/vrfydsk.exe 98304 ..c. r/rr-xr-xr-x 0 0 10979-128-4 /Program Files/Windows Resource Kits/Tools/uddiconfig.exe 12521 ..c. r/rr-xr-xr-x 0 0 1098-128-3 /WINDOWS/Help/notepad.hlp 356352 ..c. r/rr-xr-xr-x 0 0 10980-128-4 /Program Files/Windows Resource Kits/Tools/uddicatschemeeditor.exe 23552 ..c. r/rr-xr-xr-x 0 0 10981-128-3 /Program Files/Windows Resource Kits/Tools/tsctst.exe 89088 ..c. r/rr-xr-xr-x 0 0 10982-128-4 /Program Files/Windows Resource Kits/Tools/ssdformat.exe 144 .ac. d/dr-xr-xr-x 0 0 10983-144-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation 16896 ..c. r/rr-xr-xr-x 0 0 10984-128-3 /Program Files/Windows Resource Kits/Tools/splinfo.exe 40960 ..c. r/rr-xr-xr-x 0 0 10985-128-4 /Program Files/Windows Resource Kits/Tools/setprinter.exe 168851 ..c. r/rr-xr-xr-x 0 0 10986-128-3 /Program Files/Windows Resource Kits/Tools/srvmgr.hlp 33280 ..c. r/rr-xr-xr-x 0 0 10987-128-3 /Program Files/Windows Resource Kits/Tools/rpcping.exe 147456 ..c. r/rr-xr-xr-x 0 0 10988-128-3 /Program Files/Windows Resource Kits/Tools/sonar.exe 1191 ..c. r/rr-xr-xr-x 0 0 10989-128-4 /Program Files/Windows Resource Kits/Tools/traffic control monitor.lnk 1227075 ..c. r/rr-xr-xr-x 0 0 1099-128-3 /WINDOWS/Help/ntart.chm 14848 ..c. r/rr-xr-xr-x 0 0 10990-128-4 /Program Files/Windows Resource Kits/Tools/winhttpcertcfg.exe 25088 ..c. r/rr-xr-xr-x 0 0 10991-128-4 /Program Files/Windows Resource Kits/Tools/winhttptracecfg.exe 97280 ..c. r/rr-xr-xr-x 0 0 10992-128-3 /Program Files/Windows Resource Kits/Tools/prnadmin.dll 573440 ..c. r/rr-xr-xr-x 0 0 10994-128-4 /Program Files/Windows Resource Kits/Tools/uddidataexport.exe 16384 ..c. r/rr-xr-xr-x 0 0 10995-128-3 /Program Files/Windows Resource Kits/Tools/iniman.exe 58368 ..c. r/rr-xr-xr-x 0 0 10996-128-3 /Program Files/Windows Resource Kits/Tools/volrest.exe 7680 ..c. r/rr-xr-xr-x 0 0 10997-128-3 /Program Files/Windows Resource Kits/Tools/volperf.dll 37376 ..c. r/rr-xr-xr-x 0 0 10998-128-3 /Program Files/Windows Resource Kits/Tools/volperf.exe 20992 ..c. r/rr-xr-xr-x 0 0 10999-128-3 /Program Files/Windows Resource Kits/Tools/nlsinfo.exe 144 .a.. d/dr-xr-xr-x 0 0 110-144-1 /WINDOWS/Provisioning 58276 ..c. r/rr-xr-xr-x 0 0 1100-128-3 /WINDOWS/Help/ntbackup.hlp 52224 ..c. r/rr-xr-xr-x 0 0 11000-128-4 /Program Files/Windows Resource Kits/Tools/lockoutstatus.exe 39424 ..c. r/rr-xr-xr-x 0 0 11001-128-3 /Program Files/Windows Resource Kits/Tools/acctinfo.dll 95744 ..c. r/rr-xr-xr-x 0 0 11002-128-3 /Program Files/Windows Resource Kits/Tools/admx.msi 28672 ..c. r/rr-xr-xr-x 0 0 11003-128-3 /Program Files/Windows Resource Kits/Tools/chknic.exe 93696 ..c. r/rr-xr-xr-x 0 0 11004-128-3 /Program Files/Windows Resource Kits/Tools/cleanspl.exe 180736 ..c. r/rr-xr-xr-x 0 0 11005-128-3 /Program Files/Windows Resource Kits/Tools/gpotool.exe 30981 ..c. r/rr-xr-xr-x 0 0 11006-128-3 /Program Files/Windows Resource Kits/Tools/winexit.hlp 39936 ..c. r/rr-xr-xr-x 0 0 11007-128-3 /Program Files/Windows Resource Kits/Tools/compress.exe 19456 ..c. r/rr-xr-xr-x 0 0 11008-128-4 /Program Files/Windows Resource Kits/Tools/clusfileport.dll 1112 ..c. r/rr-xr-xr-x 0 0 11009-128-4 /Program Files/Windows Resource Kits/Tools/clusfileport.inf 75796 ..c. r/rr-xr-xr-x 0 0 1101-128-3 /WINDOWS/Help/ntbackup.chm 89088 ..c. r/rr-xr-xr-x 0 0 11010-128-4 /Program Files/Windows Resource Kits/Tools/printdriverinfo.exe 27648 ..c. r/rr-xr-xr-x 0 0 11011-128-3 /Program Files/Windows Resource Kits/Tools/instexnt.exe 2560 ..c. r/rr-xr-xr-x 0 0 11012-128-3 /Program Files/Windows Resource Kits/Tools/servmess.dll 32256 ..c. r/rr-xr-xr-x 0 0 11013-128-3 /Program Files/Windows Resource Kits/Tools/instsrv.exe 16597 ..c. r/rr-xr-xr-x 0 0 11014-128-3 /Program Files/Windows Resource Kits/Tools/clean.vbs 79837 ..c. r/rr-xr-xr-x 0 0 11015-128-3 /Program Files/Windows Resource Kits/Tools/clone.vbs 6968 ..c. r/rr-xr-xr-x 0 0 11016-128-3 /Program Files/Windows Resource Kits/Tools/conall.vbs 6580 ..c. r/rr-xr-xr-x 0 0 11017-128-3 /Program Files/Windows Resource Kits/Tools/defprn.vbs 44544 ..c. r/rr-xr-xr-x 0 0 11018-128-3 /Program Files/Windows Resource Kits/Tools/dnsdiag.exe 16827 ..c. r/rr-xr-xr-x 0 0 11019-128-3 /Program Files/Windows Resource Kits/Tools/drvmgr.vbs 781911 ..c. r/rr-xr-xr-x 0 0 1102-128-3 /WINDOWS/Help/ntcmds.chm 15117 ..c. r/rr-xr-xr-x 0 0 11020-128-3 /Program Files/Windows Resource Kits/Tools/forms.vbs 9563 ..c. r/rr-xr-xr-x 0 0 11021-128-3 /Program Files/Windows Resource Kits/Tools/persist.vbs 14110 ..c. r/rr-xr-xr-x 0 0 11022-128-3 /Program Files/Windows Resource Kits/Tools/portconv.vbs 19475 ..c. r/rr-xr-xr-x 0 0 11023-128-3 /Program Files/Windows Resource Kits/Tools/portmgr.vbs 20269 ..c. r/rr-xr-xr-x 0 0 11024-128-3 /Program Files/Windows Resource Kits/Tools/prncfg.vbs 8576 ..c. r/rr-xr-xr-x 0 0 11025-128-3 /Program Files/Windows Resource Kits/Tools/prnctrl.vbs 13174 ..c. r/rr-xr-xr-x 0 0 11026-128-3 /Program Files/Windows Resource Kits/Tools/prndata.vbs 17915 ..c. r/rr-xr-xr-x 0 0 11027-128-3 /Program Files/Windows Resource Kits/Tools/prnmgr.vbs 458752 ..c. r/rr-xr-xr-x 0 0 11028-128-3 /Program Files/Windows Resource Kits/Tools/prnadmin.doc 13312 ..c. r/rr-xr-xr-x 0 0 11029-128-3 /Program Files/Windows Resource Kits/Tools/timeit.exe 1409024 ..c. r/rr-xr-xr-x 0 0 11030-128-3 /Program Files/Windows Resource Kits/Tools/msvbvm60.dll 28087 ..c. r/rr-xr-xr-x 0 0 11031-128-3 /Program Files/Windows Resource Kits/Tools/wlbs_rc.dll 56 .ac. d/dr-xr-xr-x 0 0 11032-144-5 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email 3282 ..c. r/rr-xr-xr-x 0 0 11033-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/ShieldsUpMsg.htm 496 .ac. d/dr-xr-xr-x 0 0 11034-144-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US/Remote Assistance/Common 5403 ..c. r/rr-xr-xr-x 0 0 11035-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US/Remote Assistance/Common/ConnIssue.htm 5930 ..c. r/rr-xr-xr-x 0 0 11036-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US/Remote Assistance/Common/rcmoreinfo.htm 16167 ..c. r/rr-xr-xr-x 0 0 11037-128-3 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US/Remote Assistance/rcstatus.htm 8096 ..c. r/rr-xr-xr-x 0 0 11038-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/rcscreen7.htm 30915 ..c. r/rr-xr-xr-x 0 0 11039-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/rcscreen6.htm 3425 ..c. r/rr-xr-xr-x 0 0 11040-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/escalationhelp.htm 1598 ..c. r/rr-xr-xr-x 0 0 11041-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002ca.query 609584 ..c. r/rr-xr-xr-x 0 0 11042-128-3 /Program Files/Windows Resource Kits/Tools/comctl32.ocx 1237777 ..c. r/rr-xr-xr-x 0 0 11043-128-3 /WINDOWS/Help/rktools.chm 752 ..c. r/rr-xr-xr-x 0 0 11044-128-3 /WINDOWS/Help/rktools.xml 32326 ..c. r/rr-xr-xr-x 0 0 11045-128-3 /Program Files/Windows Resource Kits/Tools/tcmon.inf 83968 ..c. r/rr-xr-xr-x 0 0 11046-128-3 /Program Files/Windows Resource Kits/Tools/tccom.exe 2974155 ..c. r/rr-xr-xr-x 0 0 11047-128-3 /WINDOWS/pchealth/helpctr/Indices/merged.hhk 82 ..c. r/rr-xr-xr-x 0 0 11048-128-1 /Program Files/Windows Resource Kits/Tools/tcmon.bat 13328 ..c. r/rr-xr-xr-x 0 0 11049-128-3 /WINDOWS/pchealth/helpctr/Indices/scoped_2.hhk 304128 ..c. r/rr-xr-xr-x 0 0 11050-128-4 /Program Files/Windows Resource Kits/Tools/tsscalling.exe 5120 ..c. r/rr-xr-xr-x 0 0 11051-128-3 /Program Files/Windows Resource Kits/Tools/srvcheck.exe 22528 ..c. r/rr-xr-xr-x 0 0 11052-128-3 /Program Files/Windows Resource Kits/Tools/hlscan.exe 29184 ..c. r/rr-xr-xr-x 0 0 11053-128-4 /Program Files/Windows Resource Kits/Tools/custreasonedit.exe 179200 ..c. r/rr-xr-xr-x 0 0 11054-128-3 /Program Files/Windows Resource Kits/Tools/srvmgr.exe 304128 ..c. r/rr-xr-xr-x 0 0 11055-128-3 /Program Files/Windows Resource Kits/Tools/usrmgr.exe 35328 ..c. r/rr-xr-xr-x 0 0 11056-128-3 /Program Files/Windows Resource Kits/Tools/intfiltr.exe 330 ..c. r/rr-xr-xr-x 0 0 11057-128-1 /Program Files/Windows Resource Kits/Tools/intfiltr.reg 5632 ..c. r/rr-xr-xr-x 0 0 11058-128-3 /Program Files/Windows Resource Kits/Tools/intfiltr.sys 68608 ..c. r/rr-xr-xr-x 0 0 11059-128-4 /Program Files/Windows Resource Kits/Tools/memtriage.exe 290816 ..c. r/rr-xr-xr-x 0 0 11060-128-3 /Program Files/Windows Resource Kits/Tools/msdis130.dll 487424 ..c. r/rr-xr-xr-x 0 0 11061-128-3 /Program Files/Windows Resource Kits/Tools/msvcp70.dll 344064 ..c. r/rr-xr-xr-x 0 0 11062-128-3 /Program Files/Windows Resource Kits/Tools/msvcr70.dll 1627 ..c. r/rr-xr-xr-x 0 0 11063-128-4 /Program Files/Windows Resource Kits/Tools/memtriage.ini 102912 ..c. r/rr-xr-xr-x 0 0 11064-128-4 /Program Files/Windows Resource Kits/Tools/winpolicies.exe 53930 ..c. r/rr-xr-xr-x 0 0 11065-128-3 /Program Files/Windows Resource Kits/Tools/readme.htm 44544 ..c. r/rr-xr-xr-x 0 0 11066-128-4 /Program Files/Windows Resource Kits/Tools/reportgen.exe 177 ..c. r/rr-xr-xr-x 0 0 11067-128-1 /Program Files/Windows Resource Kits/Tools/uddicatschemeeditor.exe.config 177 ..c. r/rr-xr-xr-x 0 0 11068-128-1 /Program Files/Windows Resource Kits/Tools/uddiconfig.exe.config 177 ..c. r/rr-xr-xr-x 0 0 11069-128-1 /Program Files/Windows Resource Kits/Tools/uddidataexport.exe.config 181739 ..c. r/rr-xr-xr-x 0 0 11070-128-3 /Program Files/Windows Resource Kits/Tools/usrmgr.hlp 27064 ..c. r/rr-xr-xr-x 0 0 11071-128-4 /Program Files/Windows Resource Kits/Tools/sss_1.1.xsl 48 .ac. d/dr-xr-xr-x 0 0 11072-144-6 /Documents and Settings/All Users/Start Menu/Programs/Windows Resource Kit Tools 747 ..c. r/rr-xr-xr-x 0 0 11073-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Windows Resource Kit Tools/Windows Resource Kit Tools Read Me.lnk 755 ..c. r/rr-xr-xr-x 0 0 11074-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Windows Resource Kit Tools/Windows Resource Kit Tools Help.lnk 555 ..c. r/rr-xr-xr-x 0 0 11075-128-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Windows Resource Kit Tools/Command Shell.lnk 249856 ..c. r/rr-xr-xr-x 0 0 11076-128-3 /WINDOWS/Installer/445c3.msi 16703 ..c. r/rr-xr-xr-x 0 0 11077-128-3 /WINDOWS/pchealth/helpctr/Indices/scoped_3.hhk 51061 ..c. r/rr-xr-xr-x 0 0 11078-128-3 /WINDOWS/pchealth/helpctr/Indices/scoped_9.hhk 209095 ..c. r/rr-xr-xr-x 0 0 11079-128-3 /WINDOWS/pchealth/helpctr/Indices/scoped_8.hhk 102895 ..c. r/rr-xr-xr-x 0 0 11080-128-3 /WINDOWS/pchealth/helpctr/Indices/scoped_7.hhk 20016 ..c. r/rr-xr-xr-x 0 0 11081-128-3 /WINDOWS/pchealth/helpctr/Indices/scoped_5.hhk 15646 ..c. r/rr-xr-xr-x 0 0 11082-128-3 /WINDOWS/pchealth/helpctr/Indices/scoped_6.hhk 35565 ..c. r/rr-xr-xr-x 0 0 11083-128-3 /WINDOWS/pchealth/helpctr/Indices/scoped_4.hhk 291 ..c. r/rr-xr-xr-x 0 0 11084-128-1 /WINDOWS/pchealth/helpctr/Indices/scoped_10.hhk 4 ..c. r/rr-xr-xr-x 0 0 11085-128-1 /WINDOWS/pchealth/helpctr/PackageStore/CRC_Disk 998 ..c. r/rr-xr-xr-x 0 0 11086-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002cb.query 254 ..c. r/rr-xr-xr-x 0 0 11087-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002cc.query 3514 ..c. r/rr-xr-xr-x 0 0 11088-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002ce.query 3514 ..c. r/rr-xr-xr-x 0 0 11089-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002cf.query 2317 ..c. r/rr-xr-xr-x 0 0 1109-128-3 /WINDOWS/inf/ntgrip.inf 214 ..c. r/rr-xr-xr-x 0 0 11090-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002d0.query 3322 ..c. r/rr-xr-xr-x 0 0 11091-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002d2.query 3322 ..c. r/rr-xr-xr-x 0 0 11092-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002d3.query 202 ..c. r/rr-xr-xr-x 0 0 11093-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002d4.query 2410 ..c. r/rr-xr-xr-x 0 0 11094-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002d6.query 2410 ..c. r/rr-xr-xr-x 0 0 11095-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002d7.query 3476 ..c. r/rr-xr-xr-x 0 0 11096-128-4 /WINDOWS/pchealth/helpctr/PackageStore/SkuStore.bin 320 .ac. d/dr-xr-xr-x 0 0 111-144-5 /WINDOWS/Provisioning/Schemas 20427 ..c. r/rr-xr-xr-x 0 0 1110-128-3 /WINDOWS/Help/nthelp.chm 600484 ..c. r/rr-xr-xr-x 0 0 11126-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_274.xml 157092 ..c. r/rr-xr-xr-x 0 0 11127-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_276.xml 87390 ..c. r/rr-xr-xr-x 0 0 11128-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_278.xml 316 ..c. r/rr-xr-xr-x 0 0 11129-128-1 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_280.xml 44442 ..c. r/rr-xr-xr-x 0 0 11130-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_282.xml 10374 ..c. r/rr-xr-xr-x 0 0 11131-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_284.xml 1896 ..c. r/rr-xr-xr-x 0 0 11138-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_266.xml 18844 ..c. r/rr-xr-xr-x 0 0 11140-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_270.xml 9486 ..c. r/rr-xr-xr-x 0 0 11141-128-4 /WINDOWS/pchealth/helpctr/DataColl/history_db.xml 2054 ..c. r/rr-xr-xr-x 0 0 11145-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_272.xml 152 .ac. d/dr-xr-xr-x 0 0 11146-144-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Startup 56 .ac. d/dr-xr-xr-x 0 0 11150-144-6 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Windows Resource Kit Tools 48 .ac. d/dr-xr-xr-x 0 0 11157-144-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/4 656 .ac. d/dr-xr-xr-x 0 0 11158-144-1 /Documents and Settings/malware/Local Settings/Temp/smtmp/2 6032 ..c. r/rr-xr-xr-x 0 0 11167-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/86da2433b2d7e89bb87cbdcc717e6542abb5c1a5[1].jpg 544 .ac. d/dr-xr-xr-x 0 0 11169-144-1 /Documents and Settings/malware/Start Menu/Programs/Windows XP Repair 827 ..c. r/rr-xr-xr-x 0 0 11170-128-4 /Documents and Settings/malware/Start Menu/Programs/Windows XP Repair/Windows XP Repair.lnk 899 ..c. r/rr-xr-xr-x 0 0 11171-128-4 /Documents and Settings/malware/Start Menu/Programs/Windows XP Repair/Uninstall Windows XP Repair.lnk 815 ..c. r/rr-xr-xr-x 0 0 11172-128-4 /Documents and Settings/malware/Desktop/Windows XP Repair.lnk 2325 ..c. r/rr-xr-xr-x 0 0 11175-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-15[2].js 2036 ..c. r/rr-xr-xr-x 0 0 11176-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_27.xml 5424 ..c. r/rr-xr-xr-x 0 0 11177-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_37.xml 2036 ..c. r/rr-xr-xr-x 0 0 11178-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_57.xml 32768 ..c. r/rr-xr-xr-x 0 0 11180-128-3 /Documents and Settings/NetworkService/Local Settings/Temporary Internet Files/Content.IE5/index.dat 30061 ..c. r/rr-xr-xr-x 0 0 11189-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/PID_1666481_K2335_NAS_OM_728x90[1].jpg 306870 ..c. r/rr-xr-xr-x 0 0 1119-128-3 /WINDOWS/Help/ntshared.chm 95 ..c. r/rr-xr-xr-x 0 0 11190-128-1 /Documents and Settings/malware/Cookies/malware@crux.mevio[1].txt 18839 ..c. r/rr-xr-xr-x 0 0 11191-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/channels[1].css 665 ..c. r/rr-xr-xr-x 0 0 11192-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/client_restserver[1].htm 157999 ..c. r/rr-xr-xr-x 0 0 11194-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/index[2].js 1604 ..c. r/rr-xr-xr-x 0 0 11195-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/ie6-fixes[2].css 26185 ..c. r/rr-xr-xr-x 0 0 11196-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/index[1].css 27240 ..c. r/rr-xr-xr-x 0 0 11197-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/ga[2].js 2132 ..c. r/rr-xr-xr-x 0 0 11198-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/small-icons[1].png 33316 ..c. r/rr-xr-xr-x 0 0 11199-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/shows[2].css 48 .a.. d/dr-xr-xr-x 0 0 112-144-1 /WINDOWS/system32/1025 12760 ..c. r/rr-xr-xr-x 0 0 1120-128-3 /WINDOWS/Help/ntshrui.hlp 98741 ..c. r/rr-xr-xr-x 0 0 11200-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/showPage[2].js 999 ..c. r/rr-xr-xr-x 0 0 11202-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/box-shadows[1].png 2680 ..c. r/rr-xr-xr-x 0 0 11203-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/box-heading[1].png 11097 ..c. r/rr-xr-xr-x 0 0 11204-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/logo-and-footer[1].jpg 3108 ..c. r/rr-xr-xr-x 0 0 11205-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/18465[1].jpg 610 ..c. r/rr-xr-xr-x 0 0 11206-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/now-playing-bg[1].jpg 58767 ..c. r/rr-xr-xr-x 0 0 11207-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/PromoRollV4[1].jpg 14531 ..c. r/rr-xr-xr-x 0 0 11208-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/1173f0fb86d4e0fa2148c92cb6c7898b68e2f916[1].jpg 13932 ..c. r/rr-xr-xr-x 0 0 11209-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/c5fe9f22653f73f12988a9604d85a763cfa6eef3[1].jpg 6370 ..c. r/rr-xr-xr-x 0 0 11210-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/665e57985dc43681a574bfcaee3a040978cd2d70[1].jpg 6794 ..c. r/rr-xr-xr-x 0 0 11211-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/508349bb8d62027f2ec24c38724f2a1d940e3ac7[1].jpg 7751 ..c. r/rr-xr-xr-x 0 0 11212-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/9eb89aef14a82357f61e8401668b2852b67e396c[1].jpg 7359 ..c. r/rr-xr-xr-x 0 0 11213-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/0d255467a252a80c4e44f87bf228b2b2cad29ad9[1].jpg 2903 ..c. r/rr-xr-xr-x 0 0 11214-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/2510[1].jpg 6019 ..c. r/rr-xr-xr-x 0 0 11215-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/eba76b89c2f2775d6f84bc382cb194af7e4e8fbc[1].jpg 6229 ..c. r/rr-xr-xr-x 0 0 11216-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/b6b07589d76c009b1371fbf5d33c8bca2ff4b0dd[1].jpg 7338 ..c. r/rr-xr-xr-x 0 0 11217-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/b394b4b644845918dfc3e6ea48d027c5553da117[1].jpg 7633 ..c. r/rr-xr-xr-x 0 0 11218-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/28e5489a6f7966d376209edd2e82a806c2abede1[1].jpg 5851 ..c. r/rr-xr-xr-x 0 0 11219-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/abe506872146a572ec53fc224421b675ec50c012[1].jpg 1222 ..c. r/rr-xr-xr-x 0 0 11220-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/default[1].jpg 5130 ..c. r/rr-xr-xr-x 0 0 11221-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/showicons[1].png 3017 ..c. r/rr-xr-xr-x 0 0 11222-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/4724[1].jpg 3426 ..c. r/rr-xr-xr-x 0 0 11223-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/218903[1].jpg 2705 ..c. r/rr-xr-xr-x 0 0 11224-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/42861[1].jpg 2856 ..c. r/rr-xr-xr-x 0 0 11225-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/5028[1].jpg 2901 ..c. r/rr-xr-xr-x 0 0 11226-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/4197dfa1f28d2d77f56f6f8e1eb334e36a0bd5a6[1].jpg 3471 ..c. r/rr-xr-xr-x 0 0 11227-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/12129[1].jpg 2793 ..c. r/rr-xr-xr-x 0 0 11228-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/4176[1].jpg 1042 ..c. r/rr-xr-xr-x 0 0 11229-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/Latest_Reviews[1].png 2900 ..c. r/rr-xr-xr-x 0 0 11230-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/147123[1].jpg 96 ..c. r/rr-xr-xr-x 0 0 11231-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/s[1].png 4461 ..c. r/rr-xr-xr-x 0 0 11232-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/5883593413_6d272d0b28_s[1].jpg 22492 ..c. r/rr-xr-xr-x 0 0 11233-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/5887355857_5541eb46b6_m[1].jpg 2301 ..c. r/rr-xr-xr-x 0 0 11234-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/9433[1].jpg 4084 ..c. r/rr-xr-xr-x 0 0 11235-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/5884517406_700a6f2e88_s[1].jpg 19084 ..c. r/rr-xr-xr-x 0 0 11236-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/5887923130_547f50e74f_s[1].jpg 3598 ..c. r/rr-xr-xr-x 0 0 11237-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/34526[1].jpg 1592 ..c. r/rr-xr-xr-x 0 0 11238-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_268.xml 2036 ..c. r/rr-xr-xr-x 0 0 11239-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_87.xml 2036 ..c. r/rr-xr-xr-x 0 0 11240-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_117.xml 2737 ..c. r/rr-xr-xr-x 0 0 11241-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/343[1].jpg 5397 ..c. r/rr-xr-xr-x 0 0 11242-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/5841633479_acf151e7f0_s[1].jpg 3637 ..c. r/rr-xr-xr-x 0 0 11243-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/277295[1].jpg 1704 ..c. r/rr-xr-xr-x 0 0 11244-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/Buy_Now[1].gif 2931 ..c. r/rr-xr-xr-x 0 0 11245-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/2372[1].jpg 3384 ..c. r/rr-xr-xr-x 0 0 11246-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/94614[1].jpg 646 ..c. r/rr-xr-xr-x 0 0 11247-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/Offers[1].png 9295 ..c. r/rr-xr-xr-x 0 0 11248-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/3831[1].png 20753 ..c. r/rr-xr-xr-x 0 0 11249-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/Eastbay[1].png 35062 ..c. r/rr-xr-xr-x 0 0 1125-128-3 /WINDOWS/Help/nwdoc.chm 4138 ..c. r/rr-xr-xr-x 0 0 11250-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/gamesweaseltv[1].jpg 7165 ..c. r/rr-xr-xr-x 0 0 11251-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/Zazzle[1].png 17704 ..c. r/rr-xr-xr-x 0 0 11252-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/29096[1].jpg 3447 ..c. r/rr-xr-xr-x 0 0 11253-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/beacon[2].js 18385 ..c. r/rr-xr-xr-x 0 0 11254-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/Footlocker[1].png 7011 ..c. r/rr-xr-xr-x 0 0 11255-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/hotoff-us-e[1].jpg 1477 ..c. r/rr-xr-xr-x 0 0 11256-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/News[1].png 794 ..c. r/rr-xr-xr-x 0 0 11257-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/joinNow25high[1].gif 20356 ..c. r/rr-xr-xr-x 0 0 11258-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/tpl_player[2].js 669 ..c. r/rr-xr-xr-x 0 0 11259-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/About[1].png 16718 ..c. r/rr-xr-xr-x 0 0 1126-128-3 /WINDOWS/Help/nwdoc.hlp 3493 ..c. r/rr-xr-xr-x 0 0 11260-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tpl_comments[2].js 2928 ..c. r/rr-xr-xr-x 0 0 11261-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/rss[1].png 2303 ..c. r/rr-xr-xr-x 0 0 11262-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/Facebook[1].png 1906 ..c. r/rr-xr-xr-x 0 0 11263-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/Twitter[1].png 2677 ..c. r/rr-xr-xr-x 0 0 11264-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/YouTube[1].png 2588 ..c. r/rr-xr-xr-x 0 0 11265-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/3277[1].jpg 70578 ..c. r/rr-xr-xr-x 0 0 11266-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/Matt_Cuttle[1].png 4195 ..c. r/rr-xr-xr-x 0 0 11267-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/iTunes[1].png 78342 ..c. r/rr-xr-xr-x 0 0 11268-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tpl_htdocs[1].js 65677 ..c. r/rr-xr-xr-x 0 0 11269-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/tpl_shows[2].js 20218 ..c. r/rr-xr-xr-x 0 0 11270-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_264.xml 2036 ..c. r/rr-xr-xr-x 0 0 11271-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_147.xml 950 ..c. r/rr-xr-xr-x 0 0 11272-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/dropdown-arrows[2].png 18453 ..c. r/rr-xr-xr-x 0 0 11273-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/en_US[1] 337 ..c. r/rr-xr-xr-x 0 0 11274-128-1 /Documents and Settings/malware/Cookies/malware@gamesweaseltv.mevio[1].txt 295610 ..c. r/rr-xr-xr-x 0 0 11275-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/MevioBPFX[1].swf 7424 ..c. r/rr-xr-xr-x 0 0 11277-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/5ab27290d55e31c8cdf1ccd41a1df4466760db63[1].jpg 14288 ..c. r/rr-xr-xr-x 0 0 11278-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/connect-css[1].css 3681 ..c. r/rr-xr-xr-x 0 0 11279-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/player-icons[2].png 12416 ..c. r/rr-xr-xr-x 0 0 1128-128-3 /WINDOWS/system32/drivers/nwlnkflt.sys 1207 ..c. r/rr-xr-xr-x 0 0 11280-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/login_status[1].htm 169 ..c. r/rr-xr-xr-x 0 0 11282-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/test[1].swf 10803 ..c. r/rr-xr-xr-x 0 0 11283-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/47ac163b368a40b309220a8ae16626c1874f24e6[1].jpg 591 ..c. r/rr-xr-xr-x 0 0 11284-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/xd_receiver[1].htm 307 ..c. r/rr-xr-xr-x 0 0 11285-128-1 /Documents and Settings/malware/Cookies/malware@www.mevio[1].txt 3386 ..c. r/rr-xr-xr-x 0 0 11286-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/XdCommReceiver[2].js 4575 ..c. r/rr-xr-xr-x 0 0 11287-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26270-2[1].js 136 ..c. r/rr-xr-xr-x 0 0 11288-128-1 /Documents and Settings/malware/Cookies/malware@r1-ads.ace.advertising[1].txt 92 ..c. r/rr-xr-xr-x 0 0 11289-128-1 /Documents and Settings/malware/Cookies/malware@quantserve[1].txt 32512 ..c. r/rr-xr-xr-x 0 0 1129-128-3 /WINDOWS/system32/drivers/nwlnkfwd.sys 43 ..c. r/rr-xr-xr-x 0 0 11290-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/gmatcher[1].gif 7811 ..c. r/rr-xr-xr-x 0 0 11292-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/890024[1].jpg 2234 ..c. r/rr-xr-xr-x 0 0 11293-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26270-2[2].js 2008 ..c. r/rr-xr-xr-x 0 0 11294-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-15[1].js 0 ..c. r/rr-xr-xr-x 0 0 11296-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CAIFOHQD.ad 6621 ..c. r/rr-xr-xr-x 0 0 11297-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/emily[1].htm 6857 ..c. r/rr-xr-xr-x 0 0 11298-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/pixel[1].htm 48 .a.. d/dr-xr-xr-x 0 0 113-144-1 /WINDOWS/system32/1028 63232 ..c. r/rr-xr-xr-x 0 0 1130-128-3 /WINDOWS/system32/drivers/nwlnknb.sys 3652 ..c. r/rr-xr-xr-x 0 0 11301-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_262.xml 2036 ..c. r/rr-xr-xr-x 0 0 11302-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_177.xml 297 ..c. r/rr-xr-xr-x 0 0 11303-128-1 /Documents and Settings/malware/Cookies/malware@tap2-cdn.rubiconproject[1].txt 801 ..c. r/rr-xr-xr-x 0 0 11304-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/flashwrite_1_2[2].js 2205 ..c. r/rr-xr-xr-x 0 0 11306-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/26271-15[1].js 2008 ..c. r/rr-xr-xr-x 0 0 11308-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-2[1].js 1391 ..c. r/rr-xr-xr-x 0 0 11309-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/1@x96[1].htm 55936 ..c. r/rr-xr-xr-x 0 0 1131-128-3 /WINDOWS/system32/drivers/nwlnkspx.sys 12 ..c. r/rr-xr-xr-x 0 0 11310-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/getdata[1].xgi 18932 ..c. r/rr-xr-xr-x 0 0 11311-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/siteIDs[1].txt 1560 ..c. r/rr-xr-xr-x 0 0 11312-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/279738[1].jpg 1201 ..c. r/rr-xr-xr-x 0 0 11313-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/adopt[1].htm 2310 ..c. r/rr-xr-xr-x 0 0 11314-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/26271-2[1].js 15168 ..c. r/rr-xr-xr-x 0 0 11315-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/aceUAC[1].js 7951 ..c. r/rr-xr-xr-x 0 0 11316-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/adopt[1].htm 684 ..c. r/rr-xr-xr-x 0 0 11317-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/imp[1] 83 ..c. r/rr-xr-xr-x 0 0 11318-128-1 /Documents and Settings/malware/Cookies/malware@yahoo[1].txt 39725 ..c. r/rr-xr-xr-x 0 0 11319-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CNTL11-578_Q2_DRAboutYou_FreeActivation_728x90[1].jpg 688 ..c. r/rr-xr-xr-x 0 0 11320-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/imp[1] 6190 ..c. r/rr-xr-xr-x 0 0 11322-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/optn=64[2] 1060 ..c. r/rr-xr-xr-x 0 0 11323-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/fan[1].bid 607 ..c. r/rr-xr-xr-x 0 0 11325-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/dref=http%3A%2F%2Fgamesweasel[2].com%2F%3Futm_campaign%3D088aeb_572913_263890_113320_150752_23411%26utm_source%3D088aebc%26utm_medium%3D088aeb 8 ..c. r/rr-xr-xr-x 0 0 11326-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/adServerESI[1].aspx 3053 ..c. r/rr-xr-xr-x 0 0 11327-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/podmdm[1].jpg 1062 ..c. r/rr-xr-xr-x 0 0 11328-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/1898557958@Top1[1] 687 ..c. r/rr-xr-xr-x 0 0 11329-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/1240890821@Top1[1] 26845 ..c. r/rr-xr-xr-x 0 0 1133-128-3 /WINDOWS/Help/objsel.hlp 687 ..c. r/rr-xr-xr-x 0 0 11330-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/1879480817@Top1[1] 688 ..c. r/rr-xr-xr-x 0 0 11331-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/imp[3] 50176 ..c. r/rr-xr-xr-x 0 0 11332-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_260.xml 2036 ..c. r/rr-xr-xr-x 0 0 11333-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_207.xml 1201 ..c. r/rr-xr-xr-x 0 0 11334-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/adopt[3].htm 383 ..c. r/rr-xr-xr-x 0 0 11335-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/popup[1].js 2030 ..c. r/rr-xr-xr-x 0 0 11336-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/dk[1].js 430 ..c. r/rr-xr-xr-x 0 0 11337-128-1 /Documents and Settings/malware/Cookies/malware@serving-sys[1].txt 26741 ..c. r/rr-xr-xr-x 0 0 11338-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/262fa4472ddaa4727cbc48ac93bd48d4800bf0ed[1].jpg 12576 ..c. r/rr-xr-xr-x 0 0 11339-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/tags[2].js 16119 ..c. r/rr-xr-xr-x 0 0 1134-128-3 /WINDOWS/Help/odbcinst.chm 594 ..c. r/rr-xr-xr-x 0 0 11341-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/dref=http%3A%2F%2Fnearlythenew[2].com%2F%3Futm_campaign%3D2a316b_572913_264123_113320_150752_23411%26utm_source%3D2a316b%26utm_medium%3D2a316b 60 ..c. r/rr-xr-xr-x 0 0 11342-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/displayAd[2].js 2197 ..c. r/rr-xr-xr-x 0 0 11343-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-2[2].js 2322 ..c. r/rr-xr-xr-x 0 0 11344-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/26318-2[1].js 1332 ..c. r/rr-xr-xr-x 0 0 11345-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/CAO3Q5OT.ad 10772 ..c. r/rr-xr-xr-x 0 0 11346-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/bcf8b2846ded8223ba1a5e2b0b3867956aa61201[1].jpg 2132 ..c. r/rr-xr-xr-x 0 0 11347-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/actionBar[1].png 435 ..c. r/rr-xr-xr-x 0 0 11348-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/play-trans[1].png 23216 ..c. r/rr-xr-xr-x 0 0 11349-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/default[2].jpg 34381 ..c. r/rr-xr-xr-x 0 0 1135-128-3 /WINDOWS/Help/odbcjet.chm 1378 ..c. r/rr-xr-xr-x 0 0 11350-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/frm[1].htm 762 ..c. r/rr-xr-xr-x 0 0 11351-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/na[1].htm 2952 ..c. r/rr-xr-xr-x 0 0 11352-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/CASPE981.htm 45 ..c. r/rr-xr-xr-x 0 0 11353-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/rd[1] 271 ..c. r/rr-xr-xr-x 0 0 11354-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/g[1].js 12575 ..c. r/rr-xr-xr-x 0 0 11355-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tags[2].js 2572 ..c. r/rr-xr-xr-x 0 0 11356-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CAFJPXKE.htm 214 ..c. r/rr-xr-xr-x 0 0 11357-128-1 /Documents and Settings/malware/Cookies/malware@cgi-bin[2].txt 2681 ..c. r/rr-xr-xr-x 0 0 11358-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/authorsrevealed[1].jpg 32284 ..c. r/rr-xr-xr-x 0 0 11359-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/118ed178-986a-4c57-9d20-0870639fdad0[1].jpg 28305 ..c. r/rr-xr-xr-x 0 0 1136-128-3 /WINDOWS/Help/oe_msgr.chm 24385 ..c. r/rr-xr-xr-x 0 0 11360-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/StdBanner[2].js 688 ..c. r/rr-xr-xr-x 0 0 11361-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/imp[5] 43 ..c. r/rr-xr-xr-x 0 0 11362-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CAS5SJW3.gif 1492 ..c. r/rr-xr-xr-x 0 0 11363-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_258.xml 2036 ..c. r/rr-xr-xr-x 0 0 11364-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_237.xml 7905 ..c. r/rr-xr-xr-x 0 0 11365-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tracking_only[2].js 43 ..c. r/rr-xr-xr-x 0 0 11366-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/a[1].gif 43 ..c. r/rr-xr-xr-x 0 0 11367-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/i[1].gif 519 ..c. r/rr-xr-xr-x 0 0 11368-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/11217442856@x90[1].htm 138 ..c. r/rr-xr-xr-x 0 0 11369-128-1 /Documents and Settings/malware/Cookies/malware@netseer[1].txt 2421 ..c. r/rr-xr-xr-x 0 0 11370-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/1730591662@x23[1].htm 1423 ..c. r/rr-xr-xr-x 0 0 11371-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/1@x71[1].htm 144 ..c. r/rr-xr-xr-x 0 0 11372-128-1 /Documents and Settings/malware/Cookies/malware@nexac[2].txt 666 ..c. r/rr-xr-xr-x 0 0 11373-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/@x94[1].htm 77 ..c. r/rr-xr-xr-x 0 0 11374-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/2011Generic@Bottom3[1].htm 122 ..c. r/rr-xr-xr-x 0 0 11375-128-1 /Documents and Settings/malware/Cookies/malware@addthis[1].txt 67 ..c. r/rr-xr-xr-x 0 0 11376-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/usync[1].png 177 ..c. r/rr-xr-xr-x 0 0 11378-128-1 /Documents and Settings/malware/Cookies/malware@contextweb[2].txt 12452 ..c. r/rr-xr-xr-x 0 0 11379-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/bedf96242983dac037168b9a38c6c2710ff91108[1].jpg 1964 ..c. r/rr-xr-xr-x 0 0 11380-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/atc[1].jpg 4578 ..c. r/rr-xr-xr-x 0 0 11381-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/lifespring[1].jpg 11533 ..c. r/rr-xr-xr-x 0 0 11382-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/8ef336c6e2b72b5c3a6bf5fc573ca5f798cb4e98[1].jpg 4649 ..c. r/rr-xr-xr-x 0 0 11383-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/380686a9e245b6c9588ee47a4374fa8c6aeaf28d[1].jpg 7834 ..c. r/rr-xr-xr-x 0 0 11384-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/tpl_channels[2].js 40014 ..c. r/rr-xr-xr-x 0 0 11385-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/a4b6dbea7c7d1ad5affc22280b968759abac5fe8[1].png 43391 ..c. r/rr-xr-xr-x 0 0 11386-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/57617b115751f9587dfd6e7c97e652757d9a158f[1].png 1117 ..c. r/rr-xr-xr-x 0 0 11387-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/login_status[1].htm 1039 ..c. r/rr-xr-xr-x 0 0 11388-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/success-checkmark[1].png 1023 ..c. r/rr-xr-xr-x 0 0 11389-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/ctrl-vert-scroll[1].png 1954 ..c. r/rr-xr-xr-x 0 0 11391-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/directory[2].css 3274 ..c. r/rr-xr-xr-x 0 0 11392-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/mostpeoplearedjs[1].jpg 2234 ..c. r/rr-xr-xr-x 0 0 11393-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26317-2[1].js 2030 ..c. r/rr-xr-xr-x 0 0 11395-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/dk[1].js 1062 ..c. r/rr-xr-xr-x 0 0 11396-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/1522405056@Top1[1] 38604 ..c. r/rr-xr-xr-x 0 0 11397-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/785e48fd-311d-4f0e-be8f-e511ecfdeeb9[1].jpg 684 ..c. r/rr-xr-xr-x 0 0 11398-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/imp[1] 688 ..c. r/rr-xr-xr-x 0 0 11399-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/imp[1] 48 .a.. d/dr-xr-xr-x 0 0 114-144-1 /WINDOWS/system32/1031 26177 ..c. r/rr-xr-xr-x 0 0 1140-128-3 /WINDOWS/Help/offlinefolders.chm 115 ..c. r/rr-xr-xr-x 0 0 11400-128-1 /Documents and Settings/malware/Cookies/malware@demr.opt.fimserve[1].txt 18453 ..c. r/rr-xr-xr-x 0 0 11401-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/connect[2].php 4348 ..c. r/rr-xr-xr-x 0 0 11402-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/fp[1].js 97 ..c. r/rr-xr-xr-x 0 0 11403-128-1 /Documents and Settings/malware/Cookies/malware@bidsystem[2].txt 24385 ..c. r/rr-xr-xr-x 0 0 11404-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/StdBanner[2].js 2914 ..c. r/rr-xr-xr-x 0 0 11405-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/script201[2].js 0 ..c. r/rr-xr-xr-x 0 0 11406-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/CAA2739W.jpg 91 ..c. r/rr-xr-xr-x 0 0 11407-128-1 /Documents and Settings/malware/Cookies/malware@search.chillcow[1].txt 9432 ..c. r/rr-xr-xr-x 0 0 11408-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/nearlythenews.mevio[1].htm 18913 ..c. r/rr-xr-xr-x 0 0 11409-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/default[1].jpg 3616 ..c. r/rr-xr-xr-x 0 0 11410-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/scrapcast[1].jpg 99 ..c. r/rr-xr-xr-x 0 0 11412-128-1 /Documents and Settings/malware/Cookies/malware@64.188.52[1].txt 338 ..c. r/rr-xr-xr-x 0 0 11413-128-1 /Documents and Settings/malware/Cookies/malware@nearlythenews.mevio[1].txt 688 ..c. r/rr-xr-xr-x 0 0 11414-128-4 /Documents and Settings/malware/Cookies/malware@insightexpressai[2].txt 5809 ..c. r/rr-xr-xr-x 0 0 11415-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/b0942feb76caea4b6a8c2ffc50ab58f850ca2752[1].jpg 5938 ..c. r/rr-xr-xr-x 0 0 11416-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/7fa9503afac135886b3d295e77e3f699db2f088f[1].jpg 5844 ..c. r/rr-xr-xr-x 0 0 11417-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/8d367ca2c0dcb81af9870cc8e0bf2c0b56939bb5[1].jpg 5896 ..c. r/rr-xr-xr-x 0 0 11418-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/b76f4ae429bac02e5b95d4afd5dc2c1c5847b385[1].jpg 5119 ..c. r/rr-xr-xr-x 0 0 11419-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/4644591fb077b95a495d2a1e2dbf4da947677a5e[1].jpg 5175 ..c. r/rr-xr-xr-x 0 0 11420-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/08e4f12711259da87a650a1d16e6c2292ca0d974[1].jpg 5409 ..c. r/rr-xr-xr-x 0 0 11421-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/9c4d6af299cc5b76bc81135f01e5eeb8ce626fe4[1].jpg 5748 ..c. r/rr-xr-xr-x 0 0 11422-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/ad3a99d40cfdbfe6e897921568dd671a78a625dd[1].jpg 3416 ..c. r/rr-xr-xr-x 0 0 11423-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/156954[1].gif 2229 ..c. r/rr-xr-xr-x 0 0 11424-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/5521[1].jpg 2441 ..c. r/rr-xr-xr-x 0 0 11425-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/2661[1].jpg 5500 ..c. r/rr-xr-xr-x 0 0 11426-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/3184c21120c91ede3333550f5d45b4c65cfb834b[1].jpg 5766 ..c. r/rr-xr-xr-x 0 0 11427-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/fe428692e79c6adf1b2850d38470a7c7dc8616a3[1].jpg 2833 ..c. r/rr-xr-xr-x 0 0 11428-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/1667[1].jpg 2973 ..c. r/rr-xr-xr-x 0 0 11429-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/3860[1].jpg 2472 ..c. r/rr-xr-xr-x 0 0 11430-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/5842[1].jpg 2887 ..c. r/rr-xr-xr-x 0 0 11431-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/261456[1].jpg 7467 ..c. r/rr-xr-xr-x 0 0 11432-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/5205[1].png 3482 ..c. r/rr-xr-xr-x 0 0 11433-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/1781[1].jpg 3539 ..c. r/rr-xr-xr-x 0 0 11434-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/35930[1].jpg 2754 ..c. r/rr-xr-xr-x 0 0 11435-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/29096[1].jpg 2513 ..c. r/rr-xr-xr-x 0 0 11436-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/7620[1].jpg 2589 ..c. r/rr-xr-xr-x 0 0 11437-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/16566[1].jpg 4140 ..c. r/rr-xr-xr-x 0 0 11438-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/7601[1].jpg 2537 ..c. r/rr-xr-xr-x 0 0 11439-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/4091[1].jpg 2234 ..c. r/rr-xr-xr-x 0 0 11440-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26270-2[3].js 17283 ..c. r/rr-xr-xr-x 0 0 11441-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/280455[1].jpg 1595 ..c. r/rr-xr-xr-x 0 0 11442-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/masterinthemix[1].jpg 4106 ..c. r/rr-xr-xr-x 0 0 11443-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/nearlythenews[1].jpg 49 ..c. r/rr-xr-xr-x 0 0 11445-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/tap[2].gif 3181 ..c. r/rr-xr-xr-x 0 0 11446-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/mtest[1].htm 3067866 ..c. r/rr-xr-xr-x 0 0 11447-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/swflash[1].cab 688 ..c. r/rr-xr-xr-x 0 0 11448-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/imp[2] 180 ..c. r/rr-xr-xr-x 0 0 11449-128-1 /Documents and Settings/malware/Cookies/malware@atdmt[2].txt 591 ..c. r/rr-xr-xr-x 0 0 11450-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/xd_receiver[2].htm 2008 ..c. r/rr-xr-xr-x 0 0 11451-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/26271-15[1].js 38282 ..c. r/rr-xr-xr-x 0 0 11455-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/7872446c436b344f51675141422f2b71[1] 2008 ..c. r/rr-xr-xr-x 0 0 11456-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26271-15[1].js 2034 ..c. r/rr-xr-xr-x 0 0 11459-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/26270-2[2].js 10 ..c. r/rr-xr-xr-x 0 0 11461-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/adServerESI[1].aspx 4324 ..c. r/rr-xr-xr-x 0 0 11467-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/staticradioshow[1].jpg 28344 ..c. r/rr-xr-xr-x 0 0 1148-128-3 /WINDOWS/Help/omc.chm 684 ..c. r/rr-xr-xr-x 0 0 11484-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/imp[3] 40075 ..c. r/rr-xr-xr-x 0 0 1149-128-3 /WINDOWS/Media/onestop.mid 42980 ..c. r/rr-xr-xr-x 0 0 11496-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_256.xml 2036 ..c. r/rr-xr-xr-x 0 0 11497-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_267.xml 3684 ..c. r/rr-xr-xr-x 0 0 11498-128-4 /WINDOWS/pchealth/helpctr/DataColl/CollectedData_277.xml 2748 ..c. r/rr-xr-xr-x 0 0 11499-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/centurymediapodcast[1].jpg 152 .a.. d/dr-xr-xr-x 0 0 115-144-1 /WINDOWS/system32/1033 7316 ..c. r/rr-xr-xr-x 0 0 1150-128-3 /WINDOWS/inf/optional.inf 2793 ..c. r/rr-xr-xr-x 0 0 11500-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/aceUACping[1].htm 594 ..c. r/rr-xr-xr-x 0 0 11501-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/dref=http%3A%2F%2Fnearlythenew[1].com%2F%3Futm_campaign%3D2a316b_572913_264123_113320_150752_23411%26utm_source%3D2a316b%26utm_medium%3D2a316b 109 ..c. r/rr-xr-xr-x 0 0 11502-128-1 /Documents and Settings/malware/Cookies/malware@tag.admeld[1].txt 96 ..c. r/rr-xr-xr-x 0 0 11503-128-1 /Documents and Settings/malware/Cookies/malware@yieldmanager[1].txt 2234 ..c. r/rr-xr-xr-x 0 0 11504-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26270-2[4].js 166 ..c. r/rr-xr-xr-x 0 0 11505-128-1 /Documents and Settings/malware/Cookies/malware@realmedia[1].txt 688 ..c. r/rr-xr-xr-x 0 0 11506-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/imp[2] 4090 ..c. r/rr-xr-xr-x 0 0 11508-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/dearprudence[1].jpg 38282 ..c. r/rr-xr-xr-x 0 0 11509-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/7872446c436b344f51675141422f2b71[3] 766 ..c. r/rr-xr-xr-x 0 0 1151-128-3 /WINDOWS/system32/icsxml/osinfo.xml 11280 ..c. r/rr-xr-xr-x 0 0 11510-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/MoreMore_Game_728x90_BW[1].jpg 2034 ..c. r/rr-xr-xr-x 0 0 11511-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/26270-2[1].js 0 ..c. r/rr-xr-xr-x 0 0 11512-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/CA9UNXPU.jpg 346 ..c. r/rr-xr-xr-x 0 0 11513-128-1 /Documents and Settings/malware/Cookies/malware@meviomusicvideos.mevio[1].txt 2034 ..c. r/rr-xr-xr-x 0 0 11514-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/26270-2[1].js 2197 ..c. r/rr-xr-xr-x 0 0 11515-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-2[3].js 2197 ..c. r/rr-xr-xr-x 0 0 11516-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26271-2[1].js 90 ..c. r/rr-xr-xr-x 0 0 11517-128-1 /Documents and Settings/malware/Cookies/malware@simpli[1].txt 2034 ..c. r/rr-xr-xr-x 0 0 11519-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26270-2[1].js 19605 ..c. r/rr-xr-xr-x 0 0 1152-128-3 /WINDOWS/Help/osk.chm 6962 ..c. r/rr-xr-xr-x 0 0 11520-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/optn=64[2] 2951 ..c. r/rr-xr-xr-x 0 0 11521-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CAGLQNGB.htm 2778 ..c. r/rr-xr-xr-x 0 0 11522-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/compcon[1].jpg 39662 ..c. r/rr-xr-xr-x 0 0 11523-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/acc3c2fa-4748-40de-b9ea-57356529ba23[1].jpg 2197 ..c. r/rr-xr-xr-x 0 0 11526-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-2[4].js 87 ..c. r/rr-xr-xr-x 0 0 11527-128-1 /Documents and Settings/malware/Cookies/malware@b3.mookie1[2].txt 23346 ..c. r/rr-xr-xr-x 0 0 11528-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/1061_728x90_Promo_FreePhone_Smartphone_Static[1].jpg 6666 ..c. r/rr-xr-xr-x 0 0 11529-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/optn=64[3] 12387 ..c. r/rr-xr-xr-x 0 0 1153-128-3 /WINDOWS/Help/osk.hlp 1016 ..c. r/rr-xr-xr-x 0 0 11530-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/adopt[4].htm 2914 ..c. r/rr-xr-xr-x 0 0 11531-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/script152[2].js 1020 ..c. r/rr-xr-xr-x 0 0 11532-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/adopt[2].htm 2958 ..c. r/rr-xr-xr-x 0 0 11533-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CACRDZIA.htm 0 ..c. r/rr-xr-xr-x 0 0 11534-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CAB99BDB.jpg 0 ..c. r/rr-xr-xr-x 0 0 11535-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/CA69WXAV.jpg 24385 ..c. r/rr-xr-xr-x 0 0 11536-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/StdBanner[3].js 2914 ..c. r/rr-xr-xr-x 0 0 11537-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/script201[2].js 38232 ..c. r/rr-xr-xr-x 0 0 11538-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/e9d2c6f5-3580-49dd-bdc0-2e403a7d2856[1].jpg 14809 ..c. r/rr-xr-xr-x 0 0 1154-128-3 /WINDOWS/inf/ovcam.inf 39607 ..c. r/rr-xr-xr-x 0 0 11540-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/792ba3334fd24139982578813025e0a7[1].gif 8147 ..c. r/rr-xr-xr-x 0 0 11541-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/Hyatt_Leisure_National_728x90 Concept 1[1].gif 2515 ..c. r/rr-xr-xr-x 0 0 11542-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26271-15[2].js 803 ..c. r/rr-xr-xr-x 0 0 11543-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/CAQV4XUR 0 ..c. r/rr-xr-xr-x 0 0 11544-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CA49WFL9.jpg 2034 ..c. r/rr-xr-xr-x 0 0 11546-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/26270-2[3].js 10453 ..c. r/rr-xr-xr-x 0 0 11547-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/CA31HNIE 5627 ..c. r/rr-xr-xr-x 0 0 11548-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/view[1].htm 30302 ..c. r/rr-xr-xr-x 0 0 11549-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/300x250_062011_NATL_PROMO_INCREDIBLE2_v2[1].swf 1737 ..c. r/rr-xr-xr-x 0 0 1155-128-3 /WINDOWS/inf/ovcomp.inf 40021 ..c. r/rr-xr-xr-x 0 0 11550-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/script7[2].js 43 ..c. r/rr-xr-xr-x 0 0 11552-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/pixel!t=650![1].gif 3715 ..c. r/rr-xr-xr-x 0 0 11553-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/btpcast[1].jpg 6192 ..c. r/rr-xr-xr-x 0 0 11554-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CAGBEHGB.0]&ip=c6b0e50a&jk= 6439 ..c. r/rr-xr-xr-x 0 0 11555-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/optn=64[2] 13332 ..c. r/rr-xr-xr-x 0 0 11556-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/telekidsforever[1].png 2258 ..c. r/rr-xr-xr-x 0 0 11557-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/artsidercast1[1].jpg 3375 ..c. r/rr-xr-xr-x 0 0 11558-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/hotoffuk[1].png 239 ..c. r/rr-xr-xr-x 0 0 11559-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/bg-pager[1].png 5762 ..c. r/rr-xr-xr-x 0 0 1156-128-3 /WINDOWS/inf/ovsound.inf 4327 ..c. r/rr-xr-xr-x 0 0 11560-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/otrcomedypodshowcom[1].jpg 3164 ..c. r/rr-xr-xr-x 0 0 11561-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/tpl_directory[1].js 261 ..c. r/rr-xr-xr-x 0 0 11562-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/action-img-map[1].png 9312 ..c. r/rr-xr-xr-x 0 0 11563-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/newbrew[1].png 2027 ..c. r/rr-xr-xr-x 0 0 11564-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/26317-15[1].js 3884 ..c. r/rr-xr-xr-x 0 0 11565-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/michebelzhollywood[1].jpg 3501 ..c. r/rr-xr-xr-x 0 0 11566-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/theradreport[1].png 2830 ..c. r/rr-xr-xr-x 0 0 11567-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/wwwscraptimeca[1].jpg 3002 ..c. r/rr-xr-xr-x 0 0 11568-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/hotoff[1].jpg 11719 ..c. r/rr-xr-xr-x 0 0 11569-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tripdspodcast[1].png 20067 ..c. r/rr-xr-xr-x 0 0 1157-128-3 /WINDOWS/Help/packager.chm 3510 ..c. r/rr-xr-xr-x 0 0 11570-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/thesmellcast[1].jpg 4375 ..c. r/rr-xr-xr-x 0 0 11571-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/striptaculous1[1].jpg 4249 ..c. r/rr-xr-xr-x 0 0 11572-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/curtisandtarashow[1].jpg 10998 ..c. r/rr-xr-xr-x 0 0 11573-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/fb1df8b71f80b980a70d8f0f7b7e19a553978da8[1].jpg 1748 ..c. r/rr-xr-xr-x 0 0 11574-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/asSwfObj13[2].js 4822 ..c. r/rr-xr-xr-x 0 0 11575-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/mymhmaudio[1].png 3838 ..c. r/rr-xr-xr-x 0 0 11576-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/theultimate[1].jpg 4138 ..c. r/rr-xr-xr-x 0 0 11577-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/beatlesaramatv[1].jpg 2550 ..c. r/rr-xr-xr-x 0 0 11578-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/twotimesvideo[1].jpg 2199 ..c. r/rr-xr-xr-x 0 0 11579-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/26271-15[2].js 2409 ..c. r/rr-xr-xr-x 0 0 11580-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/coffeecoffeecoffee[1].jpg 1968 ..c. r/rr-xr-xr-x 0 0 11581-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/creativecastpodcast[1].png 3625 ..c. r/rr-xr-xr-x 0 0 11582-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/scottsigler[1].jpg 1993 ..c. r/rr-xr-xr-x 0 0 11583-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/riptheknobsoff[1].jpg 11713 ..c. r/rr-xr-xr-x 0 0 11584-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/themagicnewswire[1].png 34486 ..c. r/rr-xr-xr-x 0 0 11585-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/7CSG_JJF_IGO_20110315_fillForm_728x90[1].swf 3178 ..c. r/rr-xr-xr-x 0 0 11586-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/musicalworldpodshow[1].jpg 2034 ..c. r/rr-xr-xr-x 0 0 11587-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26317-2[1].js 4370 ..c. r/rr-xr-xr-x 0 0 11588-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/podcastpipocaenanquim[1].jpg 1940 ..c. r/rr-xr-xr-x 0 0 11589-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/thestevesanchezshowmeviocom[1].jpg 2658 ..c. r/rr-xr-xr-x 0 0 11590-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/ayultp[1].png 3089 ..c. r/rr-xr-xr-x 0 0 11591-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/erkfmmetalmonday[1].jpg 3030 ..c. r/rr-xr-xr-x 0 0 11592-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/nation[1].jpg 3714 ..c. r/rr-xr-xr-x 0 0 11593-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/themusicianscooler[1].jpg 3461 ..c. r/rr-xr-xr-x 0 0 11594-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/broadway[1].jpg 4000 ..c. r/rr-xr-xr-x 0 0 11595-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/themalthursdayshow[1].jpg 3063 ..c. r/rr-xr-xr-x 0 0 11596-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/forkthis[1].jpg 2596 ..c. r/rr-xr-xr-x 0 0 11597-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/gemmasplayhouse[1].jpg 6475 ..c. r/rr-xr-xr-x 0 0 11598-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/icmusic[1].png 8888 ..c. r/rr-xr-xr-x 0 0 11599-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/expertdrinking[1].png 48 .a.. d/dr-xr-xr-x 0 0 116-144-1 /WINDOWS/system32/1037 4607 ..c. r/rr-xr-xr-x 0 0 11600-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/tuishow[1].png 11756 ..c. r/rr-xr-xr-x 0 0 11602-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/5a458020a8c95e20363153d191a0748701307b5a[1].jpg 2322 ..c. r/rr-xr-xr-x 0 0 11603-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-2[5].js 2197 ..c. r/rr-xr-xr-x 0 0 11604-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26318-2[1].js 10750 ..c. r/rr-xr-xr-x 0 0 11605-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/38a4455f2ab8b48ae8b7989684b9fefbe86a74c4[1].jpg 479 ..c. r/rr-xr-xr-x 0 0 11606-128-1 /Documents and Settings/malware/Cookies/malware@opt.fimserve[2].txt 608 ..c. r/rr-xr-xr-x 0 0 11607-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/dref=http%3A%2F%2Fwww.mevio[1].com%2Fepisode%2F286404%2Flebron-james-talks-to-god-and-sarah 1621 ..c. r/rr-xr-xr-x 0 0 11608-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/dref=http%3A%2F%2Fwww.mevio[2].com%2Fdirectory%2F 137195 ..c. r/rr-xr-xr-x 0 0 11609-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/MEVIOmusic[1].jpg 11391 ..c. r/rr-xr-xr-x 0 0 11610-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/6e6a0112e4c93ee32e29655c48de42b3f0d7b310[1].jpg 591 ..c. r/rr-xr-xr-x 0 0 11611-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/xd_receiver[2].htm 2951 ..c. r/rr-xr-xr-x 0 0 11612-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CA2FG5QT.htm 680 ..c. r/rr-xr-xr-x 0 0 11613-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/imp[4] 49 ..c. r/rr-xr-xr-x 0 0 11614-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/tap[1].gif 115 ..c. r/rr-xr-xr-x 0 0 11616-128-1 /Documents and Settings/malware/Cookies/malware@delb.opt.fimserve[2].txt 9948 ..c. r/rr-xr-xr-x 0 0 11619-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/avatar[1].png 8028 ..c. r/rr-xr-xr-x 0 0 11620-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/70c4ea8c569d118f0d0058b9beea05a469166b2a[1].jpg 3129 ..c. r/rr-xr-xr-x 0 0 11621-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-15[3].js 2197 ..c. r/rr-xr-xr-x 0 0 11622-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-2[6].js 78 ..c. r/rr-xr-xr-x 0 0 11626-128-1 /Documents and Settings/malware/Cookies/malware@acuityplatform[1].txt 20351 ..c. r/rr-xr-xr-x 0 0 1163-128-3 /WINDOWS/inf/pcmcia.inf 35539 ..c. r/rr-xr-xr-x 0 0 11634-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/1[1].htm 72174 ..c. r/rr-xr-xr-x 0 0 11635-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/jquery.min[1].js 23392 ..c. r/rr-xr-xr-x 0 0 11636-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/layout[1].css 1728 ..c. r/rr-xr-xr-x 0 0 11637-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/jquery.bgiframe[1].js 10292 ..c. r/rr-xr-xr-x 0 0 11638-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/visacvv[1].gif 1924 ..c. r/rr-xr-xr-x 0 0 11639-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/wait[1].gif 22488 ..c. r/rr-xr-xr-x 0 0 11640-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/header[1].jpg 11596 ..c. r/rr-xr-xr-x 0 0 11641-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/bg[1].jpg 14697 ..c. r/rr-xr-xr-x 0 0 11642-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/titile_2[1].jpg 16905 ..c. r/rr-xr-xr-x 0 0 11643-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/titile_1[1].jpg 12002 ..c. r/rr-xr-xr-x 0 0 11644-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/lock[1].jpg 81 ..c. r/rr-xr-xr-x 0 0 11645-128-1 /Documents and Settings/malware/Cookies/malware@secure.paymentsadd[1].txt 0 ..c. r/rr-xr-xr-x 0 0 11646-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/hit[1].gif 3164 ..c. r/rr-xr-xr-x 0 0 11647-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/30days[1].jpg 12878 ..c. r/rr-xr-xr-x 0 0 11648-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/weaccept[1].jpg 20744 ..c. r/rr-xr-xr-x 0 0 11649-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/safe[1].jpg 3060 ..c. r/rr-xr-xr-x 0 0 11650-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/407[1].jpg 211318 ..c. r/rr-xr-xr-x 0 0 11651-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/XFBML[2] 2734 ..c. r/rr-xr-xr-x 0 0 11652-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/photo_default[1].jpg 8731 ..c. r/rr-xr-xr-x 0 0 11653-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/avatar[1].png 10893 ..c. r/rr-xr-xr-x 0 0 11654-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/ad51643e2a4d3bc8ed990def3267b92603dbd754[1].jpg 10036 ..c. r/rr-xr-xr-x 0 0 11655-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/9cc4923ca535dba1931fa11b1f6bd84dcc7e6dc9[1].jpg 5012 ..c. r/rr-xr-xr-x 0 0 11657-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/mevio-megahit[1].jpg 2720 ..c. r/rr-xr-xr-x 0 0 11658-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/21042[1].jpg 3284 ..c. r/rr-xr-xr-x 0 0 11659-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/183998[1].jpg 11896 ..c. r/rr-xr-xr-x 0 0 11660-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/avatar[1].png 10030 ..c. r/rr-xr-xr-x 0 0 11661-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/cec453d28b67092f80601ab4e425a38c43ef51b2[1].jpg 11857 ..c. r/rr-xr-xr-x 0 0 11662-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/5be046bbf1571cbc0992bf977c4aeb36fe0bbfe2[1].jpg 3723 ..c. r/rr-xr-xr-x 0 0 11663-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/6024[1].jpg 9401 ..c. r/rr-xr-xr-x 0 0 11664-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/576402c013369ada43b03805b1ee8f85efe6bab2[1].jpg 3697 ..c. r/rr-xr-xr-x 0 0 11665-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/274367[1].jpg 35293 ..c. r/rr-xr-xr-x 0 0 11666-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/a80ca036690e47436bec21d0d63ccfc3c17d4552[1].png 2364 ..c. r/rr-xr-xr-x 0 0 11667-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/646[1].jpg 2595 ..c. r/rr-xr-xr-x 0 0 11668-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/8683[1].jpg 7135 ..c. r/rr-xr-xr-x 0 0 11669-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/meviomusicvideos[1].png 21303 ..c. r/rr-xr-xr-x 0 0 11670-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/169203[1].jpg 3170 ..c. r/rr-xr-xr-x 0 0 11671-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/cattitude[1].jpg 2278 ..c. r/rr-xr-xr-x 0 0 11672-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/fullerecords[1].jpg 1188 ..c. r/rr-xr-xr-x 0 0 11673-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/login_status[2].htm 423 ..c. r/rr-xr-xr-x 0 0 11677-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CAAV0DMX.ad 2199 ..c. r/rr-xr-xr-x 0 0 11680-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26271-15[3].js 2571 ..c. r/rr-xr-xr-x 0 0 11682-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CASLYJYZ.htm 2322 ..c. r/rr-xr-xr-x 0 0 11683-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26271-2[2].js 43 ..c. r/rr-xr-xr-x 0 0 11684-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/a[1].gif 43 ..c. r/rr-xr-xr-x 0 0 11685-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/i[1].gif 467 ..c. r/rr-xr-xr-x 0 0 11686-128-1 /Documents and Settings/malware/Cookies/malware@mookie1[2].txt 43 ..c. r/rr-xr-xr-x 0 0 11687-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CA7ULCDX.gif 520 ..c. r/rr-xr-xr-x 0 0 11688-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/11226746971@x90[1].htm 49 ..c. r/rr-xr-xr-x 0 0 11691-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/tap[2].gif 2421 ..c. r/rr-xr-xr-x 0 0 11693-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/11243369564@x23[1].htm 24385 ..c. r/rr-xr-xr-x 0 0 11695-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/StdBanner[3].js 0 ..c. r/rr-xr-xr-x 0 0 11696-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CAQR0LMZ.jpg 48 .a.. d/dr-xr-xr-x 0 0 117-144-1 /WINDOWS/system32/1041 6131 ..c. r/rr-xr-xr-x 0 0 1175-128-3 /WINDOWS/inf/perm2.inf 4422 ..c. r/rr-xr-xr-x 0 0 1176-128-3 /WINDOWS/inf/perm3.inf 10836 ..c. r/rr-xr-xr-x 0 0 1177-128-3 /WINDOWS/inf/phdsext.inf 4152 ..c. r/rr-xr-xr-x 0 0 1178-128-3 /WINDOWS/inf/phil1vid.inf 8426 ..c. r/rr-xr-xr-x 0 0 1179-128-3 /WINDOWS/inf/phil2vid.inf 48 .a.. d/dr-xr-xr-x 0 0 118-144-1 /WINDOWS/system32/1042 11003 ..c. r/rr-xr-xr-x 0 0 1180-128-3 /WINDOWS/inf/phildec.inf 6903 ..c. r/rr-xr-xr-x 0 0 1181-128-3 /WINDOWS/inf/philtune.inf 17269 ..c. r/rr-xr-xr-x 0 0 1182-128-3 /WINDOWS/Help/phowto.chm 3551 ..c. r/rr-xr-xr-x 0 0 1184-128-3 /WINDOWS/inf/pinball.inf 11157 ..c. r/rr-xr-xr-x 0 0 1188-128-3 /WINDOWS/inf/pmxmcro.inf 2598 ..c. r/rr-xr-xr-x 0 0 1189-128-3 /WINDOWS/system32/icsxml/potscfg.xml 48 .a.. d/dr-xr-xr-x 0 0 119-144-1 /WINDOWS/system32/1054 14420 ..c. r/rr-xr-xr-x 0 0 1190-128-3 /WINDOWS/system32/icsxml/pppcfg.xml 19599 ..c. r/rr-xr-xr-x 0 0 1194-128-3 /WINDOWS/Help/printfnd.chm 18680 ..c. r/rr-xr-xr-x 0 0 1195-128-3 /WINDOWS/inf/printupg.inf 48 .a.. d/dr-xr-xr-x 0 0 120-144-1 /WINDOWS/system32/2052 695 ..c. r/rr-xr-xr-x 0 0 1203-128-1 /WINDOWS/Help/progman.cnt 25771 ..c. r/rr-xr-xr-x 0 0 1204-128-3 /WINDOWS/Help/progman.hlp 799 ..c. r/rr-xr-xr-x 0 0 1205-128-3 /WINDOWS/system32/drivers/etc/protocol 68786 ..c. r/rr-xr-xr-x 0 0 1206-128-3 /WINDOWS/inf/prtupg9x.inf 48 .a.. d/dr-xr-xr-x 0 0 121-144-1 /WINDOWS/system32/3076 3596 ..c. r/rr-xr-xr-x 0 0 1213-128-3 /WINDOWS/inf/ptpusb.inf 31641 ..c. r/rr-xr-xr-x 0 0 1215-128-3 /WINDOWS/Help/pwrmn.chm 44213 ..c. r/rr-xr-xr-x 0 0 1216-128-3 /WINDOWS/Help/pwrmn.hlp 12752 ..c. r/rr-xr-xr-x 0 0 1217-128-3 /WINDOWS/Help/qosconcepts.chm 19598 ..c. r/rr-xr-xr-x 0 0 1228-128-3 /WINDOWS/Help/ratings.chm 294 ..c. r/rr-xr-xr-x 0 0 1229-128-1 /WINDOWS/Help/ratings.cnt 27225 ..c. r/rr-xr-xr-x 0 0 1230-128-3 /WINDOWS/Help/ratings.hlp 34432 ..c. r/rr-xr-xr-x 0 0 1231-128-3 /WINDOWS/system32/drivers/rawwan.sys 22853 ..c. r/rr-xr-xr-x 0 0 1232-128-3 /WINDOWS/Help/reader.chm 11953 ..c. r/rr-xr-xr-x 0 0 1233-128-3 /WINDOWS/Help/reader.hlp 19107 ..c. r/rr-xr-xr-x 0 0 1235-128-3 /WINDOWS/Help/recycle.chm 12886 ..c. r/rr-xr-xr-x 0 0 1237-128-3 /WINDOWS/Help/regedit.hlp 46684 ..c. r/rr-xr-xr-x 0 0 1238-128-3 /WINDOWS/Help/regedit.chm 48 .a.. d/dr-xr-xr-x 0 0 124-144-1 /WINDOWS/system32/inetsrv 14077 ..c. r/rr-xr-xr-x 0 0 1244-128-3 /WINDOWS/Help/reskit.chm 10414 ..c. r/rr-xr-xr-x 0 0 1246-128-3 /WINDOWS/inf/ricoh.inf 12032 ..c. r/rr-xr-xr-x 0 0 1247-128-3 /WINDOWS/system32/drivers/rio8drv.sys 12032 ..c. r/rr-xr-xr-x 0 0 1248-128-3 /WINDOWS/system32/drivers/riodrv.sys 13243 ..c. r/rr-xr-xr-x 0 0 1249-128-3 /WINDOWS/Help/rktoolsold.chm 160 .a.. d/dr-xr-xr-x 0 0 125-144-1 /WINDOWS/mui 859 ..c. r/rr-xr-xr-x 0 0 1251-128-3 /WINDOWS/inf/rootau.inf 5888 ..c. r/rr-xr-xr-x 0 0 1252-128-3 /WINDOWS/system32/drivers/rootmdm.sys 690 ..c. r/rr-xr-xr-x 0 0 1253-128-1 /WINDOWS/security/templates/rootsec.inf 32167 ..c. r/rr-xr-xr-x 0 0 1258-128-3 /WINDOWS/Help/rrc.chm 35699 ..c. r/rr-xr-xr-x 0 0 1262-128-3 /WINDOWS/Help/rsm.hlp 56352 ..c. r/rr-xr-xr-x 0 0 1263-128-3 /WINDOWS/Help/rsmconcepts.chm 14678 ..c. r/rr-xr-xr-x 0 0 1264-128-3 /WINDOWS/Help/rsm.chm 13779 ..c. r/rr-xr-xr-x 0 0 1267-128-3 /WINDOWS/Help/rsopsnp.chm 12977 ..c. r/rr-xr-xr-x 0 0 1278-128-3 /WINDOWS/Help/safer.chm 36011 ..c. r/rr-xr-xr-x 0 0 1279-128-3 /WINDOWS/Help/saferconcepts.chm 175444 ..c. r/rr-xr-xr-x 0 0 1280-128-3 /WINDOWS/inf/sapi5.inf 10111 ..c. r/rr-xr-xr-x 0 0 1281-128-3 /WINDOWS/Help/sapicpl.hlp 1801 ..c. r/rr-xr-xr-x 0 0 1282-128-3 /WINDOWS/inf/sbp2.inf 17571 ..c. r/rr-xr-xr-x 0 0 1284-128-3 /WINDOWS/Help/sc.chm 13955 ..c. r/rr-xr-xr-x 0 0 1285-128-3 /WINDOWS/Help/scarddlg.hlp 27570 ..c. r/rr-xr-xr-x 0 0 1287-128-3 /WINDOWS/Help/sce.chm 87926 ..c. r/rr-xr-xr-x 0 0 1288-128-3 /WINDOWS/Help/sceconcepts.chm 56 .a.. d/dr-xr-xr-x 0 0 129-144-5 /WINDOWS/ime 27414 ..c. r/rr-xr-xr-x 0 0 1290-128-3 /WINDOWS/Help/scm.chm 48025 ..c. r/rr-xr-xr-x 0 0 1291-128-3 /WINDOWS/Help/scmconcepts.chm 22618 ..c. r/rr-xr-xr-x 0 0 1294-128-3 /WINDOWS/inf/scsidev.inf 24146 ..c. r/rr-xr-xr-x 0 0 1296-128-3 /WINDOWS/inf/sdwndr2k.inf 38163 ..c. r/rr-xr-xr-x 0 0 1297-128-3 /WINDOWS/Help/secauth.hlp 734 ..c. r/rr-xr-xr-x 0 0 1298-128-3 /WINDOWS/inf/secdrv.inf 13521 ..c. r/rr-xr-xr-x 0 0 1299-128-3 /WINDOWS/Help/secedit.chm 144 .ac. d/dr-xr-xr-x 0 0 130-144-1 /WINDOWS/ime/imejp 38094 ..c. r/rr-xr-xr-x 0 0 1300-128-3 /WINDOWS/Help/secsetconcepts.chm 26944 ..c. r/rr-xr-xr-x 0 0 1301-128-3 /WINDOWS/Help/secsettings.chm 7789 ..c. r/rr-xr-xr-x 0 0 1303-128-3 /WINDOWS/security/templates/securedc.inf 7713 ..c. r/rr-xr-xr-x 0 0 1304-128-3 /WINDOWS/security/templates/securews.inf 11941 ..c. r/rr-xr-xr-x 0 0 1305-128-3 /WINDOWS/Help/sendcmsg.hlp 81728 ..c. r/rr-xr-xr-x 0 0 1308-128-3 /WINDOWS/Fonts/seriff.fon 7116 ..c. r/rr-xr-xr-x 0 0 1309-128-3 /WINDOWS/system32/drivers/etc/services 360 .a.. d/dr-xr-xr-x 0 0 131-144-1 /WINDOWS/system32/IME 59167 ..c. r/rr-xr-xr-x 0 0 1313-128-3 /WINDOWS/system/setup.inf 15957 ..c. r/rr-xr-xr-x 0 0 1318-128-3 /WINDOWS/Help/sfmmgr.hlp 48 .ac. d/dr-xr-xr-x 0 0 132-144-1 /WINDOWS/system32/IME/PINTLGNT 21787 ..c. r/rr-xr-xr-x 0 0 1321-128-3 /WINDOWS/Help/shell.hlp 12249 ..c. r/rr-xr-xr-x 0 0 1322-128-3 /WINDOWS/Help/sigverif.hlp 18992 ..c. r/rr-xr-xr-x 0 0 1326-128-3 /WINDOWS/Help/smlogcfg.chm 14592 ..c. r/rr-xr-xr-x 0 0 1329-128-3 /WINDOWS/system32/drivers/smclib.sys 48 .ac. d/dr-xr-xr-x 0 0 133-144-1 /WINDOWS/system32/IME/CINTLGNT 42000 ..c. r/rr-xr-xr-x 0 0 1330-128-3 /WINDOWS/Help/snmpconcepts.chm 16043 ..c. r/rr-xr-xr-x 0 0 1331-128-3 /WINDOWS/Help/snmpsnap.hlp 1490 ..c. r/rr-xr-xr-x 0 0 1333-128-3 /WINDOWS/inf/sonypvu1.inf 34041 ..c. r/rr-xr-xr-x 0 0 1335-128-3 /WINDOWS/Help/soundrec.chm 20246 ..c. r/rr-xr-xr-x 0 0 1336-128-3 /WINDOWS/Help/soundrec.hlp 20163 ..c. r/rr-xr-xr-x 0 0 1337-128-3 /WINDOWS/Help/sounds.chm 42687 ..c. r/rr-xr-xr-x 0 0 1338-128-3 /WINDOWS/Help/speech.chm 11594 ..c. r/rr-xr-xr-x 0 0 1339-128-3 /WINDOWS/Help/spider.hlp 48 .ac. d/dr-xr-xr-x 0 0 134-144-1 /WINDOWS/system32/IME/TINTLGNT 12492 ..c. r/rr-xr-xr-x 0 0 1340-128-3 /WINDOWS/Help/splash.chm 5038 ..c. r/rr-xr-xr-x 0 0 1348-128-3 /WINDOWS/inf/sr.inf 144 .ac. d/dr-xr-xr-x 0 0 135-144-1 /WINDOWS/ime/CHTIME 1747 ..c. r/rr-xr-xr-x 0 0 1350-128-3 /WINDOWS/inf/srchasst.inf 5215 ..c. r/rr-xr-xr-x 0 0 1352-128-3 /WINDOWS/inf/srusbusd.inf 89856 ..c. r/rr-xr-xr-x 0 0 1353-128-3 /WINDOWS/Fonts/sseriff.fon 1192 ..c. r/rr-xr-xr-x 0 0 1354-128-3 /WINDOWS/Media/start.wav 5532 ..c. r/rr-xr-xr-x 0 0 1355-128-3 /WINDOWS/system/stdole.tlb 17418 ..c. r/rr-xr-xr-x 0 0 1356-128-3 /WINDOWS/inf/sti.inf 57234 ..c. r/rr-xr-xr-x 0 0 1357-128-3 /WINDOWS/inf/stillcam.inf 48 .ac. d/dr-xr-xr-x 0 0 136-144-1 /WINDOWS/ime/CHTIME/Applets 26241 ..c. r/rr-xr-xr-x 0 0 1361-128-3 /WINDOWS/Help/supp_ed.chm 14807 ..c. r/rr-xr-xr-x 0 0 1362-128-3 /WINDOWS/Help/suptools.chm 137 ..c. r/rr-xr-xr-x 0 0 1364-128-1 /WINDOWS/inf/svcpack.inf 221676 ..c. r/rr-xr-xr-x 0 0 1367-128-3 /WINDOWS/Fonts/sylfaen.ttf 33152 ..c. r/rr-xr-xr-x 0 0 1369-128-3 /WINDOWS/Help/sysprop.chm 48 .ac. d/dr-xr-xr-x 0 0 137-144-1 /WINDOWS/ime/imejp98 410 ..c. r/rr-xr-xr-x 0 0 1370-128-1 /WINDOWS/inf/syscomp.inf 44938 ..c. r/rr-xr-xr-x 0 0 1371-128-3 /WINDOWS/Help/sysdm.chm 75448 ..c. r/rr-xr-xr-x 0 0 1372-128-3 /WINDOWS/Help/sysdm.hlp 62118 ..c. r/rr-xr-xr-x 0 0 1376-128-3 /WINDOWS/Help/sysmon.hlp 17766 ..c. r/rr-xr-xr-x 0 0 1377-128-3 /WINDOWS/Help/sysmon.chm 48 .ac. d/dr-xr-xr-x 0 0 138-144-1 /WINDOWS/ime/imejp/applets 11603 ..c. r/rr-xr-xr-x 0 0 1380-128-3 /WINDOWS/Help/sysrestore.hlp 20688 ..c. r/rr-xr-xr-x 0 0 1384-128-3 /WINDOWS/Help/tapi.hlp 35334 ..c. r/rr-xr-xr-x 0 0 1385-128-3 /WINDOWS/Help/tapi.chm 34461 ..c. r/rr-xr-xr-x 0 0 1388-128-3 /WINDOWS/Help/taskbar.chm 248 .a.. d/dr-xr-xr-x 0 0 139-144-1 /WINDOWS/pchealth 33525 ..c. r/rr-xr-xr-x 0 0 1390-128-3 /WINDOWS/Help/taskmgr.chm 13228 ..c. r/rr-xr-xr-x 0 0 1391-128-3 /WINDOWS/Help/taskmgr.hlp 50586 ..c. r/rr-xr-xr-x 0 0 1393-128-3 /WINDOWS/Help/tcpip.chm 12693 ..c. r/rr-xr-xr-x 0 0 1394-128-3 /WINDOWS/Help/tcpmon.hlp 14698 ..c. r/rr-xr-xr-x 0 0 1397-128-3 /WINDOWS/Help/telnet.hlp 30107 ..c. r/rr-xr-xr-x 0 0 1398-128-3 /WINDOWS/Help/telnet.chm 56 .ac. d/dr-xr-xr-x 0 0 140-144-5 /WINDOWS/pchealth/helpctr 19459 ..c. r/rr-xr-xr-x 0 0 1401-128-3 /WINDOWS/Help/timesrv.chm 51712 ..c. r/rr-xr-xr-x 0 0 1404-128-3 /WINDOWS/system32/drivers/tosdvd.sys 22097 ..c. r/rr-xr-xr-x 0 0 1405-128-3 /WINDOWS/Media/town.mid 3864 ..c. r/rr-xr-xr-x 0 0 1409-128-3 /WINDOWS/inf/tsbvcap.inf 56 .ac. d/dr-xr-xr-x 0 0 141-144-5 /WINDOWS/pchealth/helpctr/binaries 21376 ..c. r/rr-xr-xr-x 0 0 1410-128-3 /WINDOWS/system32/drivers/tsbvcap.sys 14340 ..c. r/rr-xr-xr-x 0 0 1413-128-3 /WINDOWS/inf/tshoot.inf 48 .a.. d/dr-xr-xr-x 0 0 142-144-1 /WINDOWS/system32/3com_dmi 94336 ..c. r/rr-xr-xr-x 0 0 1421-128-3 /WINDOWS/inf/umax.inf 4432 ..c. r/rr-xr-xr-x 0 0 1422-128-3 /WINDOWS/inf/umaxpp.inf 1394 ..c. r/rr-xr-xr-x 0 0 1424-128-3 /WINDOWS/inf/unknown.inf 193 ..c. r/rr-xr-xr-x 0 0 1426-128-1 /WINDOWS/Help/update.cnt 20623 ..c. r/rr-xr-xr-x 0 0 1428-128-3 /WINDOWS/inf/usb.inf 1670 ..c. r/rr-xr-xr-x 0 0 1429-128-3 /WINDOWS/inf/usbprint.inf 360 .a.. d/dr-xr-xr-x 0 0 143-144-1 /WINDOWS/PeerNet 14578 ..c. r/rr-xr-xr-x 0 0 1430-128-3 /WINDOWS/inf/usbstor.inf 13051 ..c. r/rr-xr-xr-x 0 0 1432-128-3 /WINDOWS/Help/users.hlp 16660 ..c. r/rr-xr-xr-x 0 0 1434-128-3 /WINDOWS/Help/utilmgr.chm 12244 ..c. r/rr-xr-xr-x 0 0 1435-128-3 /WINDOWS/Help/utilmgr.hlp 58112 ..c. r/rr-xr-xr-x 0 0 1438-128-3 /WINDOWS/system32/drivers/vdmindvd.sys 14384 ..c. r/rr-xr-xr-x 0 0 1441-128-3 /WINDOWS/Help/verifier.hlp 5232 ..c. r/rr-xr-xr-x 0 0 1444-128-3 /WINDOWS/Fonts/vga850.fon 1302 ..c. r/rr-xr-xr-x 0 0 1445-128-3 /WINDOWS/inf/vgx.inf 1095 ..c. r/rr-xr-xr-x 0 0 1447-128-3 /WINDOWS/inf/volsnap.inf 1018 ..c. r/rr-xr-xr-x 0 0 1448-128-3 /WINDOWS/inf/volume.inf 152 .a.. d/dr-xr-xr-x 0 0 145-144-1 /WINDOWS/ehome 10895 ..c. r/rr-xr-xr-x 0 0 1455-128-3 /WINDOWS/inf/wab50.inf 3581 ..c. r/rr-xr-xr-x 0 0 1456-128-3 /WINDOWS/inf/wave.inf 56 .a.. d/dr-xr-xr-x 0 0 146-144-6 /WINDOWS/Network Diagnostic 216 .a.. d/dr-xr-xr-x 0 0 147-144-6 /WINDOWS/L2Schemas 2592 ..c. r/rr-xr-xr-x 0 0 1471-128-3 /WINDOWS/inf/wbemsnmp.inf 44441 ..c. r/rr-xr-xr-x 0 0 1472-128-3 /WINDOWS/Help/wbemtest.chm 11437 ..c. r/rr-xr-xr-x 0 0 1474-128-3 /WINDOWS/inf/wdma_avc.inf 16408 ..c. r/rr-xr-xr-x 0 0 1475-128-3 /WINDOWS/inf/wdma_azt.inf 22273 ..c. r/rr-xr-xr-x 0 0 1476-128-3 /WINDOWS/inf/wdma_csc.inf 25634 ..c. r/rr-xr-xr-x 0 0 1477-128-3 /WINDOWS/inf/wdma_csf.inf 40466 ..c. r/rr-xr-xr-x 0 0 1478-128-3 /WINDOWS/inf/wdma_ctl.inf 15975 ..c. r/rr-xr-xr-x 0 0 1479-128-3 /WINDOWS/inf/wdma_cwr.inf 496 .a.. d/dr-xr-xr-x 0 0 148-144-1 /WINDOWS/system32/mui/0401 76070 ..c. r/rr-xr-xr-x 0 0 1480-128-3 /WINDOWS/inf/wdma_es2.inf 121790 ..c. r/rr-xr-xr-x 0 0 1481-128-3 /WINDOWS/inf/wdma_es3.inf 25815 ..c. r/rr-xr-xr-x 0 0 1482-128-3 /WINDOWS/inf/wdma_ens.inf 27623 ..c. r/rr-xr-xr-x 0 0 1483-128-3 /WINDOWS/inf/wdma_ess.inf 30835 ..c. r/rr-xr-xr-x 0 0 1484-128-3 /WINDOWS/inf/wdma_m2e.inf 12389 ..c. r/rr-xr-xr-x 0 0 1485-128-3 /WINDOWS/inf/wdma_neo.inf 8296 ..c. r/rr-xr-xr-x 0 0 1486-128-3 /WINDOWS/inf/wdma_ne2.inf 14690 ..c. r/rr-xr-xr-x 0 0 1487-128-3 /WINDOWS/inf/wdma_rip.inf 23848 ..c. r/rr-xr-xr-x 0 0 1488-128-3 /WINDOWS/inf/wdma_sis.inf 57297 ..c. r/rr-xr-xr-x 0 0 1489-128-3 /WINDOWS/inf/wdma_usb.inf 496 .a.. d/dr-xr-xr-x 0 0 149-144-1 /WINDOWS/system32/mui/0404 19024 ..c. r/rr-xr-xr-x 0 0 1490-128-3 /WINDOWS/inf/wdma_ym2.inf 8467 ..c. r/rr-xr-xr-x 0 0 1491-128-3 /WINDOWS/inf/wdma_ymh.inf 23685 ..c. r/rr-xr-xr-x 0 0 1492-128-3 /WINDOWS/inf/wdmaudio.inf 7624 ..c. r/rr-xr-xr-x 0 0 1493-128-3 /WINDOWS/inf/wdmjoy.inf 496 .a.. d/dr-xr-xr-x 0 0 150-144-1 /WINDOWS/system32/mui/0405 21286 ..c. r/rr-xr-xr-x 0 0 1503-128-3 /WINDOWS/Help/win_dos.chm 64 ..c. r/rr-xr-xr-x 0 0 1504-128-1 /WINDOWS/Help/windows.cnt 300163 ..c. r/rr-xr-xr-x 0 0 1505-128-3 /WINDOWS/Help/windows.hlp 69 ..c. r/rr-xr-xr-x 0 0 1509-128-1 /WINDOWS/Help/winhlp32.cnt 496 .a.. d/dr-xr-xr-x 0 0 151-144-1 /WINDOWS/system32/mui/0406 21111 ..c. r/rr-xr-xr-x 0 0 1510-128-3 /WINDOWS/Help/winhlp32.hlp 56661 ..c. r/rr-xr-xr-x 0 0 1512-128-3 /WINDOWS/Help/wininstl.chm 48008 ..c. r/rr-xr-xr-x 0 0 1518-128-3 /WINDOWS/Help/wmic.chm 12305 ..c. r/rr-xr-xr-x 0 0 1519-128-3 /WINDOWS/Help/wmifltr.chm 496 .a.. d/dr-xr-xr-x 0 0 152-144-1 /WINDOWS/system32/mui/0407 25093 ..c. r/rr-xr-xr-x 0 0 1526-128-3 /WINDOWS/Help/wpa.chm 12032 ..c. r/rr-xr-xr-x 0 0 1527-128-3 /WINDOWS/system32/drivers/ws2ifsl.sys 25712 ..c. r/rr-xr-xr-x 0 0 1528-128-3 /WINDOWS/Help/wscript.chm 12377 ..c. r/rr-xr-xr-x 0 0 1529-128-3 /WINDOWS/Help/wscript.hlp 496 .a.. d/dr-xr-xr-x 0 0 153-144-1 /WINDOWS/system32/mui/0408 58126 ..c. r/rr-xr-xr-x 0 0 1530-128-3 /WINDOWS/Help/wsecedit.hlp 8277 ..c. r/rr-xr-xr-x 0 0 1531-128-3 /WINDOWS/inf/wsh.inf 13307 ..c. r/rr-xr-xr-x 0 0 1533-128-3 /WINDOWS/Help/wshconcepts.chm 18880 ..c. r/rr-xr-xr-x 0 0 1536-128-3 /WINDOWS/Fonts/wst_czec.fon 18880 ..c. r/rr-xr-xr-x 0 0 1537-128-3 /WINDOWS/Fonts/wst_engl.fon 18880 ..c. r/rr-xr-xr-x 0 0 1538-128-3 /WINDOWS/Fonts/wst_fren.fon 18880 ..c. r/rr-xr-xr-x 0 0 1539-128-3 /WINDOWS/Fonts/wst_germ.fon 496 .a.. d/dr-xr-xr-x 0 0 154-144-1 /WINDOWS/system32/mui/040b 18880 ..c. r/rr-xr-xr-x 0 0 1540-128-3 /WINDOWS/Fonts/wst_ital.fon 18880 ..c. r/rr-xr-xr-x 0 0 1541-128-3 /WINDOWS/Fonts/wst_span.fon 18880 ..c. r/rr-xr-xr-x 0 0 1542-128-3 /WINDOWS/Fonts/wst_swed.fon 8953 ..c. r/rr-xr-xr-x 0 0 1548-128-3 /WINDOWS/Help/signin.hlp 496 .a.. d/dr-xr-xr-x 0 0 155-144-1 /WINDOWS/system32/mui/040C 4224 ..c. r/rr-xr-xr-x 0 0 1552-128-3 /WINDOWS/system32/drivers/mnmdd.sys 17675 ..c. r/rr-xr-xr-x 0 0 1553-128-3 /WINDOWS/inf/3dfxvs2k.inf 2620 ..c. r/rr-xr-xr-x 0 0 1554-128-3 /WINDOWS/inf/adm_mult.inf 1641 ..c. r/rr-xr-xr-x 0 0 1555-128-3 /WINDOWS/inf/adm_port.inf 2698341 ..c. r/rr-xr-xr-x 0 0 1556-128-3 /WINDOWS/Help/article.chm 7450 ..c. r/rr-xr-xr-x 0 0 1557-128-3 /WINDOWS/inf/asynceqn.inf 25633 ..c. r/rr-xr-xr-x 0 0 1558-128-3 /WINDOWS/inf/atim128.inf 32342 ..c. r/rr-xr-xr-x 0 0 1559-128-3 /WINDOWS/inf/atimpab.inf 3046 ..c. r/rr-xr-xr-x 0 0 1560-128-3 /WINDOWS/inf/atirage3.inf 28113 ..c. r/rr-xr-xr-x 0 0 1561-128-3 /WINDOWS/inf/avmisdn.inf 3149 ..c. r/rr-xr-xr-x 0 0 1562-128-3 /WINDOWS/inf/banshee.inf 17080 ..c. r/rr-xr-xr-x 0 0 1564-128-3 /WINDOWS/Help/compfldr.chm 7159 ..c. r/rr-xr-xr-x 0 0 1566-128-3 /WINDOWS/inf/ctmaport.inf 21964 ..c. r/rr-xr-xr-x 0 0 1568-128-3 /WINDOWS/inf/divac.inf 22554 ..c. r/rr-xr-xr-x 0 0 1569-128-3 /WINDOWS/inf/divasrv.inf 3816 ..c. r/rr-xr-xr-x 0 0 1570-128-3 /WINDOWS/inf/dshowext.inf 3207 ..c. r/rr-xr-xr-x 0 0 1572-128-3 /WINDOWS/inf/eqnport.inf 3651 ..c. r/rr-xr-xr-x 0 0 1574-128-3 /WINDOWS/inf/fsvga.inf 12160 ..c. r/rr-xr-xr-x 0 0 1575-128-3 /WINDOWS/system32/drivers/fsvga.sys 313 ..c. r/rr-xr-xr-x 0 0 1576-128-1 /WINDOWS/inf/fsvgaadd.inf 314 ..c. r/rr-xr-xr-x 0 0 1577-128-1 /WINDOWS/inf/fsvgadel.inf 3874 ..c. r/rr-xr-xr-x 0 0 1578-128-3 /WINDOWS/inf/g200.inf 2773 ..c. r/rr-xr-xr-x 0 0 1579-128-3 /WINDOWS/inf/i740nt5.inf 4228 ..c. r/rr-xr-xr-x 0 0 1580-128-3 /WINDOWS/inf/irdaalif.inf 10619 ..c. r/rr-xr-xr-x 0 0 1581-128-3 /WINDOWS/inf/irtos4mo.inf 25938 ..c. r/rr-xr-xr-x 0 0 1583-128-3 /WINDOWS/inf/mdm3cpcm.inf 55764 ..c. r/rr-xr-xr-x 0 0 1584-128-3 /WINDOWS/inf/mdm3mini.inf 30934 ..c. r/rr-xr-xr-x 0 0 1585-128-3 /WINDOWS/inf/mdm656n5.inf 48170 ..c. r/rr-xr-xr-x 0 0 1586-128-3 /WINDOWS/inf/mdmbcmsm.inf 620730 ..c. r/rr-xr-xr-x 0 0 1587-128-3 /WINDOWS/inf/mdmcxsft.inf 19125 ..c. r/rr-xr-xr-x 0 0 1588-128-3 /WINDOWS/inf/mdmdigi.inf 43975 ..c. r/rr-xr-xr-x 0 0 1589-128-3 /WINDOWS/inf/mdmess.inf 48980 ..c. r/rr-xr-xr-x 0 0 1590-128-3 /WINDOWS/inf/mdmltleo.inf 49556 ..c. r/rr-xr-xr-x 0 0 1591-128-3 /WINDOWS/inf/mdmltsft.inf 29028 ..c. r/rr-xr-xr-x 0 0 1592-128-3 /WINDOWS/inf/mdmosice.inf 38179 ..c. r/rr-xr-xr-x 0 0 1593-128-3 /WINDOWS/inf/mdmpctel.inf 2020 ..c. r/rr-xr-xr-x 0 0 1594-128-3 /WINDOWS/inf/mdmrisa.inf 1544841 ..c. r/rr-xr-xr-x 0 0 1595-128-3 /WINDOWS/inf/mdmrpciw.inf 1802 ..c. r/rr-xr-xr-x 0 0 1596-128-3 /WINDOWS/inf/mdmsgsml.inf 13982 ..c. r/rr-xr-xr-x 0 0 1597-128-3 /WINDOWS/inf/mdmsgsmu.inf 48940 ..c. r/rr-xr-xr-x 0 0 1598-128-3 /WINDOWS/inf/mdmxircc.inf 46837 ..c. r/rr-xr-xr-x 0 0 1599-128-3 /WINDOWS/inf/mdmxirmp.inf 2224 ..c. r/rr-xr-xr-x 0 0 1600-128-3 /WINDOWS/inf/mfcem28.inf 2073 ..c. r/rr-xr-xr-x 0 0 1601-128-3 /WINDOWS/inf/mfcem33.inf 10508 ..c. r/rr-xr-xr-x 0 0 1602-128-3 /WINDOWS/inf/mfcem56.inf 3936 ..c. r/rr-xr-xr-x 0 0 1603-128-3 /WINDOWS/inf/mff56n5.inf 6433 ..c. r/rr-xr-xr-x 0 0 1604-128-3 /WINDOWS/inf/mfmhzn5.inf 4750 ..c. r/rr-xr-xr-x 0 0 1605-128-3 /WINDOWS/inf/mflm.inf 4753 ..c. r/rr-xr-xr-x 0 0 1606-128-3 /WINDOWS/inf/mflm56.inf 6337 ..c. r/rr-xr-xr-x 0 0 1607-128-3 /WINDOWS/inf/mfosi5.inf 3512 ..c. r/rr-xr-xr-x 0 0 1608-128-3 /WINDOWS/inf/mfx56nf.inf 3322 ..c. r/rr-xr-xr-x 0 0 1609-128-3 /WINDOWS/inf/mgau.inf 7611 ..c. r/rr-xr-xr-x 0 0 1613-128-3 /WINDOWS/inf/mpsstln.inf 173 ..c. r/rr-xr-xr-x 0 0 1614-128-1 /WINDOWS/Help/msnauth.cnt 10556 ..c. r/rr-xr-xr-x 0 0 1615-128-3 /WINDOWS/Help/msnauth.hlp 24853 ..c. r/rr-xr-xr-x 0 0 1621-128-3 /WINDOWS/inf/mwavmdm1.inf 5089 ..c. r/rr-xr-xr-x 0 0 1622-128-3 /WINDOWS/inf/mwmbatam.inf 8627 ..c. r/rr-xr-xr-x 0 0 1623-128-3 /WINDOWS/inf/mwremove.inf 56891 ..c. r/rr-xr-xr-x 0 0 1624-128-3 /WINDOWS/inf/mwtpdsp.inf 4664 ..c. r/rr-xr-xr-x 0 0 1625-128-3 /WINDOWS/inf/mxboard.inf 4222 ..c. r/rr-xr-xr-x 0 0 1626-128-3 /WINDOWS/inf/mxport.inf 11209 ..c. r/rr-xr-xr-x 0 0 1627-128-3 /WINDOWS/inf/neo20xx.inf 1616 ..c. r/rr-xr-xr-x 0 0 1628-128-3 /WINDOWS/inf/net10.inf 3200 ..c. r/rr-xr-xr-x 0 0 1629-128-3 /WINDOWS/inf/net3c556.inf 5798 ..c. r/rr-xr-xr-x 0 0 1630-128-3 /WINDOWS/inf/net3c589.inf 8967 ..c. r/rr-xr-xr-x 0 0 1631-128-3 /WINDOWS/inf/net3c985.inf 1739 ..c. r/rr-xr-xr-x 0 0 1632-128-3 /WINDOWS/inf/net3sr.inf 65589 ..c. r/rr-xr-xr-x 0 0 1633-128-3 /WINDOWS/inf/net557.inf 4082 ..c. r/rr-xr-xr-x 0 0 1634-128-3 /WINDOWS/inf/net559ib.inf 4929 ..c. r/rr-xr-xr-x 0 0 1635-128-3 /WINDOWS/inf/net575nt.inf 4370 ..c. r/rr-xr-xr-x 0 0 1636-128-3 /WINDOWS/inf/net656n5.inf 3302 ..c. r/rr-xr-xr-x 0 0 1637-128-3 /WINDOWS/inf/net656c5.inf 3606 ..c. r/rr-xr-xr-x 0 0 1638-128-3 /WINDOWS/inf/net713.inf 7315 ..c. r/rr-xr-xr-x 0 0 1639-128-3 /WINDOWS/inf/net83820.inf 18333 ..c. r/rr-xr-xr-x 0 0 1640-128-3 /WINDOWS/inf/net8511.inf 2519 ..c. r/rr-xr-xr-x 0 0 1641-128-3 /WINDOWS/inf/netali.inf 7020 ..c. r/rr-xr-xr-x 0 0 1642-128-3 /WINDOWS/inf/netan983.inf 5417 ..c. r/rr-xr-xr-x 0 0 1643-128-3 /WINDOWS/inf/netamd.inf 15158 ..c. r/rr-xr-xr-x 0 0 1644-128-3 /WINDOWS/inf/netamd2.inf 2129 ..c. r/rr-xr-xr-x 0 0 1645-128-3 /WINDOWS/inf/netambi.inf 4861 ..c. r/rr-xr-xr-x 0 0 1646-128-3 /WINDOWS/inf/netamdhl.inf 6215 ..c. r/rr-xr-xr-x 0 0 1647-128-3 /WINDOWS/inf/netasp2k.inf 26729 ..c. r/rr-xr-xr-x 0 0 1648-128-3 /WINDOWS/inf/netb57xp.inf 2758 ..c. r/rr-xr-xr-x 0 0 1649-128-3 /WINDOWS/inf/netbcm4p.inf 2539 ..c. r/rr-xr-xr-x 0 0 1650-128-3 /WINDOWS/inf/netbcm4u.inf 3038 ..c. r/rr-xr-xr-x 0 0 1651-128-3 /WINDOWS/inf/netbcm4e.inf 6612 ..c. r/rr-xr-xr-x 0 0 1652-128-3 /WINDOWS/inf/netbrzw.inf 7513 ..c. r/rr-xr-xr-x 0 0 1653-128-3 /WINDOWS/inf/netcicap.inf 11177 ..c. r/rr-xr-xr-x 0 0 1654-128-3 /WINDOWS/inf/netcb325.inf 8599 ..c. r/rr-xr-xr-x 0 0 1655-128-3 /WINDOWS/inf/netcbe.inf 2961 ..c. r/rr-xr-xr-x 0 0 1656-128-3 /WINDOWS/inf/netcb102.inf 5462 ..c. r/rr-xr-xr-x 0 0 1657-128-3 /WINDOWS/inf/netce2.inf 8181 ..c. r/rr-xr-xr-x 0 0 1658-128-3 /WINDOWS/inf/netce3.inf 4274 ..c. r/rr-xr-xr-x 0 0 1659-128-3 /WINDOWS/inf/netcem28.inf 4260 ..c. r/rr-xr-xr-x 0 0 1660-128-3 /WINDOWS/inf/netcem33.inf 8329 ..c. r/rr-xr-xr-x 0 0 1661-128-3 /WINDOWS/inf/netcem56.inf 6268 ..c. r/rr-xr-xr-x 0 0 1662-128-3 /WINDOWS/inf/netcpqc.inf 13080 ..c. r/rr-xr-xr-x 0 0 1663-128-3 /WINDOWS/inf/netcpqg.inf 12085 ..c. r/rr-xr-xr-x 0 0 1664-128-3 /WINDOWS/inf/netcpqi.inf 6030 ..c. r/rr-xr-xr-x 0 0 1665-128-3 /WINDOWS/inf/netcpqmt.inf 5095 ..c. r/rr-xr-xr-x 0 0 1666-128-3 /WINDOWS/inf/netctmrk.inf 8138 ..c. r/rr-xr-xr-x 0 0 1667-128-3 /WINDOWS/inf/netdlh5x.inf 3257 ..c. r/rr-xr-xr-x 0 0 1668-128-3 /WINDOWS/inf/netdf650.inf 4443 ..c. r/rr-xr-xr-x 0 0 1669-128-3 /WINDOWS/inf/netdm.inf 2950 ..c. r/rr-xr-xr-x 0 0 1670-128-3 /WINDOWS/inf/net650d.inf 22319 ..c. r/rr-xr-xr-x 0 0 1671-128-3 /WINDOWS/inf/nete1000.inf 5822 ..c. r/rr-xr-xr-x 0 0 1672-128-3 /WINDOWS/inf/nete100i.inf 3467 ..c. r/rr-xr-xr-x 0 0 1673-128-3 /WINDOWS/inf/netejxmp.inf 3027 ..c. r/rr-xr-xr-x 0 0 1674-128-3 /WINDOWS/inf/netel515.inf 5552 ..c. r/rr-xr-xr-x 0 0 1675-128-3 /WINDOWS/inf/netel574.inf 3045 ..c. r/rr-xr-xr-x 0 0 1676-128-3 /WINDOWS/inf/netel5x9.inf 7072 ..c. r/rr-xr-xr-x 0 0 1677-128-3 /WINDOWS/inf/netel980.inf 11262 ..c. r/rr-xr-xr-x 0 0 1678-128-3 /WINDOWS/inf/netel99x.inf 4897 ..c. r/rr-xr-xr-x 0 0 1679-128-3 /WINDOWS/inf/netepicn.inf 4040 ..c. r/rr-xr-xr-x 0 0 1680-128-3 /WINDOWS/inf/netepro.inf 2478 ..c. r/rr-xr-xr-x 0 0 1681-128-3 /WINDOWS/inf/netex10.inf 3687 ..c. r/rr-xr-xr-x 0 0 1682-128-3 /WINDOWS/inf/netf56n5.inf 4475 ..c. r/rr-xr-xr-x 0 0 1683-128-3 /WINDOWS/inf/netfa312.inf 3031 ..c. r/rr-xr-xr-x 0 0 1684-128-3 /WINDOWS/inf/netfa410.inf 2998 ..c. r/rr-xr-xr-x 0 0 1685-128-3 /WINDOWS/inf/netfjvi.inf 2883 ..c. r/rr-xr-xr-x 0 0 1686-128-3 /WINDOWS/inf/netfjvj.inf 3092 ..c. r/rr-xr-xr-x 0 0 1687-128-3 /WINDOWS/inf/netforeh.inf 12602 ..c. r/rr-xr-xr-x 0 0 1688-128-3 /WINDOWS/inf/netibm.inf 8339 ..c. r/rr-xr-xr-x 0 0 1689-128-3 /WINDOWS/inf/netibm2.inf 2849 ..c. r/rr-xr-xr-x 0 0 1690-128-3 /WINDOWS/inf/netktc.inf 2398 ..c. r/rr-xr-xr-x 0 0 1691-128-3 /WINDOWS/inf/netlm.inf 2320 ..c. r/rr-xr-xr-x 0 0 1692-128-3 /WINDOWS/inf/netlm56.inf 2694 ..c. r/rr-xr-xr-x 0 0 1693-128-3 /WINDOWS/inf/netlnev2.inf 4507 ..c. r/rr-xr-xr-x 0 0 1694-128-3 /WINDOWS/inf/netmhzn5.inf 24491 ..c. r/rr-xr-xr-x 0 0 1695-128-3 /WINDOWS/inf/netnf3.inf 5037 ..c. r/rr-xr-xr-x 0 0 1696-128-3 /WINDOWS/inf/netngr.inf 10008 ..c. r/rr-xr-xr-x 0 0 1697-128-3 /WINDOWS/inf/netosi2c.inf 7919 ..c. r/rr-xr-xr-x 0 0 1698-128-3 /WINDOWS/inf/netosi5.inf 3204 ..c. r/rr-xr-xr-x 0 0 1699-128-3 /WINDOWS/inf/netpc100.inf 4945 ..c. r/rr-xr-xr-x 0 0 1700-128-3 /WINDOWS/inf/netpnic.inf 6308 ..c. r/rr-xr-xr-x 0 0 1701-128-3 /WINDOWS/inf/netpwr2.inf 3208 ..c. r/rr-xr-xr-x 0 0 1702-128-3 /WINDOWS/inf/netrlw2k.inf 4645 ..c. r/rr-xr-xr-x 0 0 1703-128-3 /WINDOWS/inf/netrtpnt.inf 14374 ..c. r/rr-xr-xr-x 0 0 1704-128-3 /WINDOWS/inf/netsis.inf 17766 ..c. r/rr-xr-xr-x 0 0 1705-128-3 /WINDOWS/inf/netsk_fp.inf 7790 ..c. r/rr-xr-xr-x 0 0 1706-128-3 /WINDOWS/inf/netsk98.inf 2158 ..c. r/rr-xr-xr-x 0 0 1707-128-3 /WINDOWS/inf/netsla30.inf 2038 ..c. r/rr-xr-xr-x 0 0 1708-128-3 /WINDOWS/inf/netsmc.inf 3474 ..c. r/rr-xr-xr-x 0 0 1709-128-3 /WINDOWS/inf/netsnip.inf 160 .a.. d/dr-xr-xr-x 0 0 171-144-1 /WINDOWS/system32/mui/0402 4637 ..c. r/rr-xr-xr-x 0 0 1710-128-3 /WINDOWS/inf/nettb155.inf 2999 ..c. r/rr-xr-xr-x 0 0 1711-128-3 /WINDOWS/inf/nettdkb.inf 6520 ..c. r/rr-xr-xr-x 0 0 1712-128-3 /WINDOWS/inf/nettiger.inf 2879 ..c. r/rr-xr-xr-x 0 0 1713-128-3 /WINDOWS/inf/nettpro.inf 8415 ..c. r/rr-xr-xr-x 0 0 1714-128-3 /WINDOWS/inf/netvt86.inf 4980 ..c. r/rr-xr-xr-x 0 0 1715-128-3 /WINDOWS/inf/netw840.inf 2293 ..c. r/rr-xr-xr-x 0 0 1716-128-3 /WINDOWS/inf/netw926.inf 2175 ..c. r/rr-xr-xr-x 0 0 1717-128-3 /WINDOWS/inf/netw940.inf 12323 ..c. r/rr-xr-xr-x 0 0 1718-128-3 /WINDOWS/inf/netx500.inf 4538 ..c. r/rr-xr-xr-x 0 0 1719-128-3 /WINDOWS/inf/netx56n5.inf 4612 ..c. r/rr-xr-xr-x 0 0 1720-128-3 /WINDOWS/inf/netxcpq.inf 1761 ..c. r/rr-xr-xr-x 0 0 1721-128-3 /WINDOWS/inf/ntapm.inf 4177 ..c. r/rr-xr-xr-x 0 0 1722-128-3 /WINDOWS/inf/nv3.inf 2048 ..c. r/rr-xr-xr-x 0 0 1725-128-3 /WINDOWS/inf/ppa.inf 2076 ..c. r/rr-xr-xr-x 0 0 1726-128-3 /WINDOWS/inf/ppa3.inf 757717 ..c. r/rr-xr-xr-x 0 0 1727-128-3 /WINDOWS/Help/Tours/mmTour/intro.swf 807 ..c. r/rr-xr-xr-x 0 0 1728-128-3 /WINDOWS/Help/Tours/mmTour/intro.txt 175759 ..c. r/rr-xr-xr-x 0 0 1729-128-3 /WINDOWS/Help/Tours/mmTour/nav.swf 407 ..c. r/rr-xr-xr-x 0 0 1730-128-1 /WINDOWS/Help/Tours/mmTour/nav.txt 2103945 ..c. r/rr-xr-xr-x 0 0 1731-128-3 /WINDOWS/Help/Tours/mmTour/segment1.swf 747 ..c. r/rr-xr-xr-x 0 0 1732-128-3 /WINDOWS/Help/Tours/mmTour/segment1.txt 1637375 ..c. r/rr-xr-xr-x 0 0 1733-128-3 /WINDOWS/Help/Tours/mmTour/segment2.swf 772 ..c. r/rr-xr-xr-x 0 0 1734-128-3 /WINDOWS/Help/Tours/mmTour/segment2.txt 1635503 ..c. r/rr-xr-xr-x 0 0 1735-128-3 /WINDOWS/Help/Tours/mmTour/segment3.swf 717 ..c. r/rr-xr-xr-x 0 0 1736-128-1 /WINDOWS/Help/Tours/mmTour/segment3.txt 2794421 ..c. r/rr-xr-xr-x 0 0 1737-128-3 /WINDOWS/Help/Tours/mmTour/segment4.swf 633 ..c. r/rr-xr-xr-x 0 0 1738-128-1 /WINDOWS/Help/Tours/mmTour/segment4.txt 7679963 ..c. r/rr-xr-xr-x 0 0 1739-128-3 /WINDOWS/Help/Tours/mmTour/segment5.swf 799 ..c. r/rr-xr-xr-x 0 0 1740-128-3 /WINDOWS/Help/Tours/mmTour/segment5.txt 3167 ..c. r/rr-xr-xr-x 0 0 1741-128-3 /WINDOWS/inf/s3sav3d.inf 3246 ..c. r/rr-xr-xr-x 0 0 1742-128-3 /WINDOWS/inf/s3sav4.inf 3258 ..c. r/rr-xr-xr-x 0 0 1743-128-3 /WINDOWS/inf/s3savmx.inf 2219 ..c. r/rr-xr-xr-x 0 0 1744-128-3 /WINDOWS/inf/s3trio3d.inf 2883 ..c. r/rr-xr-xr-x 0 0 1745-128-3 /WINDOWS/inf/sgiu.inf 3788 ..c. r/rr-xr-xr-x 0 0 1746-128-3 /WINDOWS/inf/sis300i.inf 3166 ..c. r/rr-xr-xr-x 0 0 1747-128-3 /WINDOWS/inf/sis6306.inf 5445 ..c. r/rr-xr-xr-x 0 0 1748-128-3 /WINDOWS/inf/sisgr.inf 3102 ..c. r/rr-xr-xr-x 0 0 1749-128-3 /WINDOWS/inf/sisv6326.inf 9197 ..c. r/rr-xr-xr-x 0 0 1750-128-3 /WINDOWS/inf/smi.inf 14782 ..c. r/rr-xr-xr-x 0 0 1751-128-3 /WINDOWS/inf/spx.inf 9856 ..c. r/rr-xr-xr-x 0 0 1752-128-3 /WINDOWS/inf/spxports.inf 2565 ..c. r/rr-xr-xr-x 0 0 1753-128-3 /WINDOWS/inf/stalport.inf 29998 ..c. r/rr-xr-xr-x 0 0 1754-128-3 /WINDOWS/inf/swnt.inf 2812 ..c. r/rr-xr-xr-x 0 0 1755-128-3 /WINDOWS/inf/tgiu.inf 3374640 ..c. r/rr-xr-xr-x 0 0 1756-128-3 /WINDOWS/Help/Tours/mmTour/tour.exe 3609 ..c. r/rr-xr-xr-x 0 0 1757-128-3 /WINDOWS/inf/trid3d.inf 4044 ..c. r/rr-xr-xr-x 0 0 1758-128-3 /WINDOWS/inf/tridkb.inf 3121 ..c. r/rr-xr-xr-x 0 0 1759-128-3 /WINDOWS/inf/tridxp.inf 4898 ..c. r/rr-xr-xr-x 0 0 1777-128-3 /WINDOWS/inf/viafir2k.inf 4100 ..c. r/rr-xr-xr-x 0 0 1779-128-3 /WINDOWS/inf/wbfirdma.inf 4726 ..c. r/rr-xr-xr-x 0 0 1780-128-3 /WINDOWS/inf/wceusbsh.inf 267903 ..c. r/rr-xr-xr-x 0 0 1781-128-3 /WINDOWS/inf/wdma10k1.inf 86985 ..c. r/rr-xr-xr-x 0 0 1782-128-3 /WINDOWS/inf/wdma_aur.inf 872679 ..c. r/rr-xr-xr-x 0 0 1783-128-3 /WINDOWS/Help/windows.chm 166 ..c. r/rr-xr-xr-x 0 0 1785-128-1 /WINDOWS/Help/Tours/htmlTour/bluearrow.gif 53 ..c. r/rr-xr-xr-x 0 0 1786-128-1 /WINDOWS/Help/Tours/htmlTour/bot_bar.gif 6222 ..c. r/rr-xr-xr-x 0 0 1787-128-3 /WINDOWS/Help/Tours/htmlTour/connected_data.jpg 14433 ..c. r/rr-xr-xr-x 0 0 1788-128-3 /WINDOWS/Help/Tours/htmlTour/connected_data_big.jpg 4967 ..c. r/rr-xr-xr-x 0 0 1789-128-3 /WINDOWS/Help/Tours/htmlTour/connected_data_ghost.jpg 7192 ..c. r/rr-xr-xr-x 0 0 1790-128-3 /WINDOWS/Help/Tours/htmlTour/connected_multiple.jpg 17059 ..c. r/rr-xr-xr-x 0 0 1791-128-3 /WINDOWS/Help/Tours/htmlTour/connected_multiple_big.jpg 5683 ..c. r/rr-xr-xr-x 0 0 1792-128-3 /WINDOWS/Help/Tours/htmlTour/connected_multiple_ghost.jpg 7236 ..c. r/rr-xr-xr-x 0 0 1793-128-3 /WINDOWS/Help/Tours/htmlTour/connected_networks.jpg 18137 ..c. r/rr-xr-xr-x 0 0 1794-128-3 /WINDOWS/Help/Tours/htmlTour/connected_networks_big.jpg 5628 ..c. r/rr-xr-xr-x 0 0 1795-128-3 /WINDOWS/Help/Tours/htmlTour/connected_networks_ghost.jpg 6778 ..c. r/rr-xr-xr-x 0 0 1796-128-3 /WINDOWS/Help/Tours/htmlTour/connected_wizard.jpg 17214 ..c. r/rr-xr-xr-x 0 0 1797-128-3 /WINDOWS/Help/Tours/htmlTour/connected_wizard_big.jpg 5314 ..c. r/rr-xr-xr-x 0 0 1798-128-3 /WINDOWS/Help/Tours/htmlTour/connected_wizard_ghost.jpg 4407 ..c. r/rr-xr-xr-x 0 0 1799-128-3 /WINDOWS/Help/Tours/htmlTour/control_up.jpg 56 .a.. d/dr-xr-xr-x 0 0 180-144-5 /WINDOWS/system32/en 22890 ..c. r/rr-xr-xr-x 0 0 1800-128-3 /WINDOWS/Help/Tours/htmlTour/desktop_screen_shot.jpg 4232 ..c. r/rr-xr-xr-x 0 0 1801-128-3 /WINDOWS/Help/Tours/htmlTour/desktop_up.jpg 4399 ..c. r/rr-xr-xr-x 0 0 1802-128-3 /WINDOWS/Help/Tours/htmlTour/end_up.jpg 4326 ..c. r/rr-xr-xr-x 0 0 1803-128-3 /WINDOWS/Help/Tours/htmlTour/folder_up.jpg 644 ..c. r/rr-xr-xr-x 0 0 1804-128-1 /WINDOWS/Help/Tours/htmlTour/gradient.jpg 4322 ..c. r/rr-xr-xr-x 0 0 1805-128-3 /WINDOWS/Help/Tours/htmlTour/icon_up.jpg 63270 ..c. r/rr-xr-xr-x 0 0 1806-128-3 /WINDOWS/Help/Tours/htmlTour/img004b.jpg 8639 ..c. r/rr-xr-xr-x 0 0 1807-128-3 /WINDOWS/Help/Tours/htmlTour/img014.jpg 66232 ..c. r/rr-xr-xr-x 0 0 1808-128-3 /WINDOWS/Help/Tours/htmlTour/img033.jpg 67797 ..c. r/rr-xr-xr-x 0 0 1809-128-3 /WINDOWS/Help/Tours/htmlTour/img033a.jpg 31079 ..c. r/rr-xr-xr-x 0 0 1810-128-3 /WINDOWS/Help/Tours/htmlTour/img034.jpg 37207 ..c. r/rr-xr-xr-x 0 0 1811-128-3 /WINDOWS/Help/Tours/htmlTour/img040.jpg 44618 ..c. r/rr-xr-xr-x 0 0 1812-128-3 /WINDOWS/Help/Tours/htmlTour/img060.jpg 24137 ..c. r/rr-xr-xr-x 0 0 1813-128-3 /WINDOWS/Help/Tours/htmlTour/img068.jpg 41453 ..c. r/rr-xr-xr-x 0 0 1814-128-3 /WINDOWS/Help/Tours/htmlTour/img072.jpg 87264 ..c. r/rr-xr-xr-x 0 0 1815-128-3 /WINDOWS/Help/Tours/htmlTour/img089.jpg 43292 ..c. r/rr-xr-xr-x 0 0 1816-128-3 /WINDOWS/Help/Tours/htmlTour/img100.jpg 43667 ..c. r/rr-xr-xr-x 0 0 1817-128-3 /WINDOWS/Help/Tours/htmlTour/img109.jpg 16257 ..c. r/rr-xr-xr-x 0 0 1818-128-3 /WINDOWS/Help/Tours/htmlTour/img110.jpg 21987 ..c. r/rr-xr-xr-x 0 0 1819-128-3 /WINDOWS/Help/Tours/htmlTour/img116.jpg 31637 ..c. r/rr-xr-xr-x 0 0 1820-128-3 /WINDOWS/Help/Tours/htmlTour/img121.jpg 20762 ..c. r/rr-xr-xr-x 0 0 1821-128-3 /WINDOWS/Help/Tours/htmlTour/img123.jpg 18782 ..c. r/rr-xr-xr-x 0 0 1822-128-3 /WINDOWS/Help/Tours/htmlTour/img126.jpg 77688 ..c. r/rr-xr-xr-x 0 0 1823-128-3 /WINDOWS/Help/Tours/htmlTour/img136.jpg 100686 ..c. r/rr-xr-xr-x 0 0 1824-128-3 /WINDOWS/Help/Tours/htmlTour/img149.jpg 25420 ..c. r/rr-xr-xr-x 0 0 1825-128-3 /WINDOWS/Help/Tours/htmlTour/intro_logo.jpg 4651 ..c. r/rr-xr-xr-x 0 0 1826-128-3 /WINDOWS/Help/Tours/htmlTour/logo.jpg 855 ..c. r/rr-xr-xr-x 0 0 1827-128-3 /WINDOWS/Help/Tours/htmlTour/nav_blank.gif 1221 ..c. r/rr-xr-xr-x 0 0 1828-128-3 /WINDOWS/Help/Tours/htmlTour/nav_best.gif 1161 ..c. r/rr-xr-xr-x 0 0 1829-128-3 /WINDOWS/Help/Tours/htmlTour/nav_best_down.gif 1211 ..c. r/rr-xr-xr-x 0 0 1830-128-3 /WINDOWS/Help/Tours/htmlTour/nav_connected.gif 1179 ..c. r/rr-xr-xr-x 0 0 1831-128-3 /WINDOWS/Help/Tours/htmlTour/nav_connected_down.gif 1496 ..c. r/rr-xr-xr-x 0 0 1832-128-3 /WINDOWS/Help/Tours/htmlTour/nav_gray.gif 1237 ..c. r/rr-xr-xr-x 0 0 1833-128-3 /WINDOWS/Help/Tours/htmlTour/nav_safe_easy.gif 1176 ..c. r/rr-xr-xr-x 0 0 1834-128-3 /WINDOWS/Help/Tours/htmlTour/nav_safe_easy_down.gif 1130 ..c. r/rr-xr-xr-x 0 0 1835-128-3 /WINDOWS/Help/Tours/htmlTour/nav_start_here.gif 761 ..c. r/rr-xr-xr-x 0 0 1836-128-3 /WINDOWS/Help/Tours/htmlTour/nav_start_here_down.gif 1237 ..c. r/rr-xr-xr-x 0 0 1837-128-3 /WINDOWS/Help/Tours/htmlTour/nav_unlock.gif 1131 ..c. r/rr-xr-xr-x 0 0 1838-128-3 /WINDOWS/Help/Tours/htmlTour/nav_unlock_down.gif 2580 ..c. r/rr-xr-xr-x 0 0 1839-128-3 /WINDOWS/Help/Tours/htmlTour/pen_icon.jpg 2626 ..c. r/rr-xr-xr-x 0 0 1840-128-3 /WINDOWS/Help/Tours/htmlTour/question_icon.jpg 1535 ..c. r/rr-xr-xr-x 0 0 1841-128-3 /WINDOWS/Help/Tours/htmlTour/read_icon.jpg 6416 ..c. r/rr-xr-xr-x 0 0 1842-128-3 /WINDOWS/Help/Tours/htmlTour/safe_easy_better.jpg 13378 ..c. r/rr-xr-xr-x 0 0 1843-128-3 /WINDOWS/Help/Tours/htmlTour/safe_easy_better_big.jpg 5159 ..c. r/rr-xr-xr-x 0 0 1844-128-3 /WINDOWS/Help/Tours/htmlTour/safe_easy_better_ghost.jpg 6293 ..c. r/rr-xr-xr-x 0 0 1845-128-3 /WINDOWS/Help/Tours/htmlTour/safe_easy_easier.jpg 15707 ..c. r/rr-xr-xr-x 0 0 1846-128-3 /WINDOWS/Help/Tours/htmlTour/safe_easy_easier_big.jpg 5040 ..c. r/rr-xr-xr-x 0 0 1847-128-3 /WINDOWS/Help/Tours/htmlTour/safe_easy_easier_ghost.jpg 6782 ..c. r/rr-xr-xr-x 0 0 1848-128-3 /WINDOWS/Help/Tours/htmlTour/safe_easy_faster.jpg 18151 ..c. r/rr-xr-xr-x 0 0 1849-128-3 /WINDOWS/Help/Tours/htmlTour/safe_easy_faster_big.jpg 5330 ..c. r/rr-xr-xr-x 0 0 1850-128-3 /WINDOWS/Help/Tours/htmlTour/safe_easy_faster_ghost.jpg 43 ..c. r/rr-xr-xr-x 0 0 1851-128-1 /WINDOWS/Help/Tours/htmlTour/spacer.gif 4337 ..c. r/rr-xr-xr-x 0 0 1852-128-3 /WINDOWS/Help/Tours/htmlTour/start_up.jpg 4222 ..c. r/rr-xr-xr-x 0 0 1853-128-3 /WINDOWS/Help/Tours/htmlTour/taskbar_up.jpg 6566 ..c. r/rr-xr-xr-x 0 0 1854-128-3 /WINDOWS/Help/Tours/htmlTour/ul_logo.jpg 6514 ..c. r/rr-xr-xr-x 0 0 1855-128-3 /WINDOWS/Help/Tours/htmlTour/unlock_built.jpg 14770 ..c. r/rr-xr-xr-x 0 0 1856-128-3 /WINDOWS/Help/Tours/htmlTour/unlock_built_big.jpg 5063 ..c. r/rr-xr-xr-x 0 0 1857-128-3 /WINDOWS/Help/Tours/htmlTour/unlock_built_ghost.jpg 6290 ..c. r/rr-xr-xr-x 0 0 1858-128-3 /WINDOWS/Help/Tours/htmlTour/unlock_optimized.jpg 14093 ..c. r/rr-xr-xr-x 0 0 1859-128-3 /WINDOWS/Help/Tours/htmlTour/unlock_optimized_big.jpg 5135 ..c. r/rr-xr-xr-x 0 0 1860-128-3 /WINDOWS/Help/Tours/htmlTour/unlock_optimized_ghost.jpg 4366 ..c. r/rr-xr-xr-x 0 0 1861-128-3 /WINDOWS/Help/Tours/htmlTour/window_up.jpg 7951 ..c. r/rr-xr-xr-x 0 0 1862-128-3 /WINDOWS/Help/Tours/htmlTour/best_road.jpg 21352 ..c. r/rr-xr-xr-x 0 0 1863-128-3 /WINDOWS/Help/Tours/htmlTour/best_road_big.jpg 6253 ..c. r/rr-xr-xr-x 0 0 1864-128-3 /WINDOWS/Help/Tours/htmlTour/best_road_ghost.jpg 6452 ..c. r/rr-xr-xr-x 0 0 1865-128-3 /WINDOWS/Help/Tours/htmlTour/best_robust.jpg 13667 ..c. r/rr-xr-xr-x 0 0 1866-128-3 /WINDOWS/Help/Tours/htmlTour/best_robust_big.jpg 5065 ..c. r/rr-xr-xr-x 0 0 1867-128-3 /WINDOWS/Help/Tours/htmlTour/best_robust_ghost.jpg 6645 ..c. r/rr-xr-xr-x 0 0 1868-128-3 /WINDOWS/Help/Tours/htmlTour/best_secure.jpg 17777 ..c. r/rr-xr-xr-x 0 0 1869-128-3 /WINDOWS/Help/Tours/htmlTour/best_secure_big.jpg 5168 ..c. r/rr-xr-xr-x 0 0 187-128-3 /WINDOWS/Fonts/vgaoem.fon 5249 ..c. r/rr-xr-xr-x 0 0 1870-128-3 /WINDOWS/Help/Tours/htmlTour/best_secure_ghost.jpg 42914 ..c. r/rr-xr-xr-x 0 0 1871-128-3 /WINDOWS/Help/Tours/htmlTour/img074a.jpg 1135 ..c. r/rr-xr-xr-x 0 0 1872-128-3 /WINDOWS/Help/Tours/htmlTour/scripts.js 2595 ..c. r/rr-xr-xr-x 0 0 1873-128-3 /WINDOWS/Help/Tours/htmlTour/style.css 3212 ..c. r/rr-xr-xr-x 0 0 1874-128-3 /WINDOWS/inf/xscan_xp.inf 1481 ..c. r/rr-xr-xr-x 0 0 1875-128-3 /WINDOWS/inf/wmtour.inf 1885 ..c. r/rr-xr-xr-x 0 0 1878-128-3 /WINDOWS/Help/mplayer2.cnt 97117 ..c. r/rr-xr-xr-x 0 0 1879-128-3 /WINDOWS/Help/mplayer2.hlp 4352 ..c. r/rr-xr-xr-x 0 0 188-128-3 /WINDOWS/system32/drivers/wmilib.sys 11648 ..c. r/rr-xr-xr-x 0 0 1882-128-3 /WINDOWS/system32/drivers/acpiec.sys 3456 ..c. r/rr-xr-xr-x 0 0 1883-128-3 /WINDOWS/system32/drivers/oprghdlr.sys 3328 ..c. r/rr-xr-xr-x 0 0 1884-128-3 /WINDOWS/system32/drivers/pciide.sys 4736 ..c. r/rr-xr-xr-x 0 0 1885-128-3 /WINDOWS/system32/drivers/usbd.sys 96512 ..c. r/rr-xr-xr-x 0 0 1886-128-3 /WINDOWS/system32/drivers/atapi.sys 36352 ..c. r/rr-xr-xr-x 0 0 1887-128-3 /WINDOWS/system32/drivers/disk.sys 49536 ..c. r/rr-xr-xr-x 0 0 1888-128-3 /WINDOWS/system32/drivers/classpnp.sys 153344 ..c. r/rr-xr-xr-x 0 0 1889-128-3 /WINDOWS/system32/drivers/dmio.sys 5888 ..c. r/rr-xr-xr-x 0 0 189-128-3 /WINDOWS/system32/drivers/dmload.sys 24960 ..c. r/rr-xr-xr-x 0 0 1890-128-3 /WINDOWS/system32/drivers/pciidex.sys 92288 ..c. r/rr-xr-xr-x 0 0 1891-128-3 /WINDOWS/system32/drivers/ksecdd.sys 42368 ..c. r/rr-xr-xr-x 0 0 1892-128-3 /WINDOWS/system32/drivers/mountmgr.sys 180608 ..c. r/rr-xr-xr-x 0 0 1893-128-3 /WINDOWS/system32/drivers/mrxdav.sys 19072 ..c. r/rr-xr-xr-x 0 0 1894-128-3 /WINDOWS/system32/drivers/tdi.sys 182656 ..c. r/rr-xr-xr-x 0 0 1895-128-3 /WINDOWS/system32/drivers/ndis.sys 456576 ..c. r/rr-xr-xr-x 0 0 1896-128-3 /WINDOWS/system32/drivers/mrxsmb.sys 175744 ..c. r/rr-xr-xr-x 0 0 1897-128-3 /WINDOWS/system32/drivers/rdbss.sys 19072 ..c. r/rr-xr-xr-x 0 0 1898-128-3 /WINDOWS/system32/drivers/msfs.sys 105344 ..c. r/rr-xr-xr-x 0 0 1899-128-3 /WINDOWS/system32/drivers/mup.sys 125056 ..c. r/rr-xr-xr-x 0 0 190-128-3 /WINDOWS/system32/drivers/ftdisk.sys 34688 ..c. r/rr-xr-xr-x 0 0 1900-128-3 /WINDOWS/system32/drivers/netbios.sys 30848 ..c. r/rr-xr-xr-x 0 0 1901-128-3 /WINDOWS/system32/drivers/npfs.sys 19712 ..c. r/rr-xr-xr-x 0 0 1902-128-3 /WINDOWS/system32/drivers/partmgr.sys 52352 ..c. r/rr-xr-xr-x 0 0 1903-128-3 /WINDOWS/system32/drivers/volsnap.sys 42752 ..c. r/rr-xr-xr-x 0 0 1904-128-3 /WINDOWS/system32/drivers/p3.sys 81664 ..c. r/rr-xr-xr-x 0 0 1905-128-3 /WINDOWS/system32/drivers/videoprt.sys 141056 ..c. r/rr-xr-xr-x 0 0 1906-128-3 /WINDOWS/system32/drivers/ks.sys 30080 ..c. r/rr-xr-xr-x 0 0 1907-128-3 /WINDOWS/system32/drivers/modem.sys 27392 ..c. r/rr-xr-xr-x 0 0 1908-128-3 /WINDOWS/system32/drivers/fdc.sys 64512 ..c. r/rr-xr-xr-x 0 0 1909-128-3 /WINDOWS/system32/drivers/serial.sys 17792 ..c. r/rr-xr-xr-x 0 0 191-128-3 /WINDOWS/system32/drivers/ptilink.sys 15744 ..c. r/rr-xr-xr-x 0 0 1910-128-3 /WINDOWS/system32/drivers/serenum.sys 80128 ..c. r/rr-xr-xr-x 0 0 1911-128-3 /WINDOWS/system32/drivers/parport.sys 62976 ..c. r/rr-xr-xr-x 0 0 1912-128-3 /WINDOWS/system32/drivers/cdrom.sys 51328 ..c. r/rr-xr-xr-x 0 0 1913-128-3 /WINDOWS/system32/drivers/rasl2tp.sys 10112 ..c. r/rr-xr-xr-x 0 0 1914-128-3 /WINDOWS/system32/drivers/ndistapi.sys 91520 ..c. r/rr-xr-xr-x 0 0 1915-128-3 /WINDOWS/system32/drivers/ndiswan.sys 41472 ..c. r/rr-xr-xr-x 0 0 1916-128-3 /WINDOWS/system32/drivers/raspppoe.sys 48384 ..c. r/rr-xr-xr-x 0 0 1917-128-3 /WINDOWS/system32/drivers/raspptp.sys 69120 ..c. r/rr-xr-xr-x 0 0 1918-128-3 /WINDOWS/system32/drivers/psched.sys 35072 ..c. r/rr-xr-xr-x 0 0 1919-128-3 /WINDOWS/system32/drivers/msgpc.sys 16512 ..c. r/rr-xr-xr-x 0 0 192-128-3 /WINDOWS/system32/drivers/raspti.sys 4352 ..c. r/rr-xr-xr-x 0 0 1920-128-3 /WINDOWS/system32/drivers/swenum.sys 40576 ..c. r/rr-xr-xr-x 0 0 1921-128-3 /WINDOWS/system32/drivers/ndproxy.sys 20480 ..c. r/rr-xr-xr-x 0 0 1922-128-3 /WINDOWS/system32/drivers/flpydisk.sys 11392 ..c. r/rr-xr-xr-x 0 0 1923-128-3 /WINDOWS/system32/drivers/sfloppy.sys 20992 ..c. r/rr-xr-xr-x 0 0 1924-128-3 /WINDOWS/system32/drivers/vga.sys 75264 ..c. r/rr-xr-xr-x 0 0 1925-128-3 /WINDOWS/system32/drivers/ipsec.sys 361344 ..c. r/rr-xr-xr-x 0 0 1926-128-3 /WINDOWS/system32/drivers/tcpip.sys 162816 ..c. r/rr-xr-xr-x 0 0 1927-128-3 /WINDOWS/system32/drivers/netbt.sys 34560 ..c. r/rr-xr-xr-x 0 0 1928-128-3 /WINDOWS/system32/drivers/wanarp.sys 42112 ..c. r/rr-xr-xr-x 0 0 1929-128-3 /WINDOWS/system32/drivers/imapi.sys 18688 ..c. r/rr-xr-xr-x 0 0 193-128-3 /WINDOWS/system32/drivers/cdaudio.sys 44544 ..c. r/rr-xr-xr-x 0 0 1930-128-3 /WINDOWS/system32/drivers/fips.sys 143744 ..c. r/rr-xr-xr-x 0 0 1934-128-3 /WINDOWS/system32/drivers/fastfat.sys 7936 ..c. r/rr-xr-xr-x 0 0 194-128-3 /WINDOWS/system32/drivers/fs_rec.sys 2944 ..c. r/rr-xr-xr-x 0 0 195-128-3 /WINDOWS/system32/drivers/null.sys 4224 ..c. r/rr-xr-xr-x 0 0 196-128-3 /WINDOWS/system32/drivers/beep.sys 4224 ..c. r/rr-xr-xr-x 0 0 197-128-3 /WINDOWS/system32/drivers/rdpcdd.sys 71168 ..c. r/rr-xr-xr-x 0 0 1970-128-3 /WINDOWS/system32/drivers/dxg.sys 8832 ..c. r/rr-xr-xr-x 0 0 198-128-3 /WINDOWS/system32/drivers/rasacd.sys 355680 ..c. r/rr-xr-xr-x 0 0 1981-128-3 /WINDOWS/Fonts/tahomabd.ttf 383804 ..c. r/rr-xr-xr-x 0 0 1982-128-3 /WINDOWS/Fonts/tahoma.ttf 138112 ..c. r/rr-xr-xr-x 0 0 2022-128-3 /WINDOWS/system32/drivers/afd.sys 461672 ..c. r/rr-xr-xr-x 0 0 2027-128-3 /WINDOWS/Fonts/micross.ttf 148624 ..c. r/rr-xr-xr-x 0 0 2028-128-3 /WINDOWS/Fonts/tunga.ttf 3328 ..c. r/rr-xr-xr-x 0 0 203-128-3 /WINDOWS/system32/drivers/dxgthk.sys 7280 ..c. r/rr-xr-xr-x 0 0 204-128-3 /WINDOWS/Fonts/vgasys.fon 5360 ..c. r/rr-xr-xr-x 0 0 205-128-3 /WINDOWS/Fonts/vgafix.fon 334848 ..c. r/rr-xr-xr-x 0 0 2075-128-3 /WINDOWS/system32/drivers/srv.sys 36656 ..c. r/rr-xr-xr-x 0 0 208-128-3 /WINDOWS/Fonts/dosapp.fon 5312 ..c. r/rr-xr-xr-x 0 0 209-128-3 /WINDOWS/Fonts/ega80woa.fon 8368 ..c. r/rr-xr-xr-x 0 0 210-128-3 /WINDOWS/Fonts/ega40woa.fon 4304 ..c. r/rr-xr-xr-x 0 0 211-128-3 /WINDOWS/Fonts/cga80woa.fon 6336 ..c. r/rr-xr-xr-x 0 0 212-128-3 /WINDOWS/Fonts/cga40woa.fon 13312 ..c. r/rr-xr-xr-x 0 0 215-128-3 /WINDOWS/Fonts/roman.fon 14592 ..c. r/rr-xr-xr-x 0 0 2150-128-3 /WINDOWS/system32/drivers/ndisuio.sys 97016 ..c. r/rr-xr-xr-x 0 0 2156-128-3 /WINDOWS/Media/chord.wav 12288 ..c. r/rr-xr-xr-x 0 0 216-128-3 /WINDOWS/Fonts/script.fon 367112 ..c. r/rr-xr-xr-x 0 0 2169-128-3 /WINDOWS/Fonts/arial.ttf 8704 ..c. r/rr-xr-xr-x 0 0 217-128-3 /WINDOWS/Fonts/modern.fon 134108 ..c. r/rr-xr-xr-x 0 0 2170-128-3 /WINDOWS/Fonts/trebuc.ttf 171792 ..c. r/rr-xr-xr-x 0 0 2171-128-3 /WINDOWS/Fonts/verdana.ttf 14208 ..c. r/rr-xr-xr-x 0 0 2172-128-3 /WINDOWS/system32/drivers/diskdump.sys 35840 ..c. r/rr-xr-xr-x 0 0 2173-128-3 /WINDOWS/system32/drivers/processr.sys 352224 ..c. r/rr-xr-xr-x 0 0 2179-128-3 /WINDOWS/Fonts/arialbd.ttf 26112 ..c. r/rr-xr-xr-x 0 0 218-128-3 /WINDOWS/Fonts/smalle.fon 118832 ..c. r/rr-xr-xr-x 0 0 2180-128-3 /WINDOWS/Fonts/ariblk.ttf 127596 ..c. r/rr-xr-xr-x 0 0 2182-128-3 /WINDOWS/Fonts/comic.ttf 155068 ..c. r/rr-xr-xr-x 0 0 2184-128-3 /WINDOWS/Fonts/georgia.ttf 137448 ..c. r/rr-xr-xr-x 0 0 2185-128-3 /WINDOWS/Fonts/impact.ttf 398372 ..c. r/rr-xr-xr-x 0 0 2188-128-3 /WINDOWS/Fonts/timesbd.ttf 56336 ..c. r/rr-xr-xr-x 0 0 219-128-3 /WINDOWS/Fonts/symbole.fon 409280 ..c. r/rr-xr-xr-x 0 0 2190-128-3 /WINDOWS/Fonts/times.ttf 25815 ..c. r/rr-xr-xr-x 0 0 2192-128-3 /WINDOWS/inf/accessor.inf 1852928 ..c. r/rr-xr-xr-x 0 0 2193-128-3 /WINDOWS/AppPatch/AcGenral.dll 39424 ..c. r/rr-xr-xr-x 0 0 2194-128-3 /WINDOWS/AppPatch/AcAdProc.dll 451072 ..c. r/rr-xr-xr-x 0 0 2195-128-3 /WINDOWS/AppPatch/AcLayers.dll 141312 ..c. r/rr-xr-xr-x 0 0 2196-128-3 /WINDOWS/AppPatch/AcLua.dll 4727 ..c. r/rr-xr-xr-x 0 0 2197-128-3 /WINDOWS/inf/acpi.inf 245248 ..c. r/rr-xr-xr-x 0 0 2198-128-3 /WINDOWS/AppPatch/AcSpecfc.dll 23408 ..c. r/rr-xr-xr-x 0 0 220-128-3 /WINDOWS/Fonts/coure.fon 116224 ..c. r/rr-xr-xr-x 0 0 2200-128-3 /WINDOWS/AppPatch/AcXtrnal.dll 24064 ..c. r/rr-xr-xr-x 0 0 2206-128-3 /WINDOWS/msagent/agentanm.dll 214016 ..c. r/rr-xr-xr-x 0 0 2207-128-3 /WINDOWS/msagent/agentctl.dll 42496 ..c. r/rr-xr-xr-x 0 0 2208-128-3 /WINDOWS/msagent/agentdp2.dll 57344 ..c. r/rr-xr-xr-x 0 0 2209-128-3 /WINDOWS/msagent/agentdpv.dll 64656 ..c. r/rr-xr-xr-x 0 0 221-128-3 /WINDOWS/Fonts/sserife.fon 49152 ..c. r/rr-xr-xr-x 0 0 2210-128-3 /WINDOWS/msagent/agentmpx.dll 24064 ..c. r/rr-xr-xr-x 0 0 2211-128-3 /WINDOWS/msagent/agentpsh.dll 44032 ..c. r/rr-xr-xr-x 0 0 2212-128-3 /WINDOWS/msagent/agentsr.dll 256512 ..c. r/rr-xr-xr-x 0 0 2213-128-3 /WINDOWS/msagent/agentsvr.exe 3976 ..c. r/rr-xr-xr-x 0 0 2214-128-3 /WINDOWS/inf/agp.inf 19456 ..c. r/rr-xr-xr-x 0 0 2215-128-3 /WINDOWS/msagent/intl/agt0406.dll 8783 ..c. r/rr-xr-xr-x 0 0 2216-128-3 /WINDOWS/Help/agt0406.hlp 21504 ..c. r/rr-xr-xr-x 0 0 2217-128-3 /WINDOWS/msagent/intl/agt0407.dll 8856 ..c. r/rr-xr-xr-x 0 0 2218-128-3 /WINDOWS/Help/agt0407.hlp 19968 ..c. r/rr-xr-xr-x 0 0 2219-128-3 /WINDOWS/msagent/intl/agt0409.dll 57936 ..c. r/rr-xr-xr-x 0 0 222-128-3 /WINDOWS/Fonts/serife.fon 8648 ..c. r/rr-xr-xr-x 0 0 2220-128-3 /WINDOWS/Help/agt0409.hlp 19456 ..c. r/rr-xr-xr-x 0 0 2221-128-3 /WINDOWS/msagent/intl/agt040b.dll 8662 ..c. r/rr-xr-xr-x 0 0 2222-128-3 /WINDOWS/Help/agt040b.hlp 21504 ..c. r/rr-xr-xr-x 0 0 2223-128-3 /WINDOWS/msagent/intl/agt040c.dll 8882 ..c. r/rr-xr-xr-x 0 0 2224-128-3 /WINDOWS/Help/agt040c.hlp 20992 ..c. r/rr-xr-xr-x 0 0 2225-128-3 /WINDOWS/msagent/intl/agt0410.dll 8746 ..c. r/rr-xr-xr-x 0 0 2226-128-3 /WINDOWS/Help/agt0410.hlp 20992 ..c. r/rr-xr-xr-x 0 0 2227-128-3 /WINDOWS/msagent/intl/agt0413.dll 9309 ..c. r/rr-xr-xr-x 0 0 2228-128-3 /WINDOWS/Help/agt0413.hlp 19456 ..c. r/rr-xr-xr-x 0 0 2229-128-3 /WINDOWS/msagent/intl/agt0414.dll 24124 ..c. r/rr-xr-xr-x 0 0 223-128-3 /WINDOWS/Fonts/marlett.ttf 8654 ..c. r/rr-xr-xr-x 0 0 2230-128-3 /WINDOWS/Help/agt0414.hlp 20480 ..c. r/rr-xr-xr-x 0 0 2231-128-3 /WINDOWS/msagent/intl/agt0416.dll 8758 ..c. r/rr-xr-xr-x 0 0 2232-128-3 /WINDOWS/Help/agt0416.hlp 19456 ..c. r/rr-xr-xr-x 0 0 2233-128-3 /WINDOWS/msagent/intl/agt041d.dll 9251 ..c. r/rr-xr-xr-x 0 0 2234-128-3 /WINDOWS/Help/agt041d.hlp 20992 ..c. r/rr-xr-xr-x 0 0 2235-128-3 /WINDOWS/msagent/intl/agt0816.dll 8799 ..c. r/rr-xr-xr-x 0 0 2236-128-3 /WINDOWS/Help/agt0816.hlp 20480 ..c. r/rr-xr-xr-x 0 0 2237-128-3 /WINDOWS/msagent/intl/agt0c0a.dll 8830 ..c. r/rr-xr-xr-x 0 0 2238-128-3 /WINDOWS/Help/agt0c0a.hlp 18432 ..c. r/rr-xr-xr-x 0 0 2239-128-3 /WINDOWS/msagent/agtctl15.tlb 7766 ..c. r/rr-xr-xr-x 0 0 2240-128-3 /WINDOWS/inf/agtinst.inf 24064 ..c. r/rr-xr-xr-x 0 0 2241-128-3 /WINDOWS/msagent/agtintl.dll 37376 ..c. r/rr-xr-xr-x 0 0 2244-128-3 /WINDOWS/system32/drivers/amdk6.sys 37760 ..c. r/rr-xr-xr-x 0 0 2245-128-3 /WINDOWS/system32/drivers/amdk7.sys 785972 ..c. r/rr-xr-xr-x 0 0 2247-128-3 /WINDOWS/AppPatch/apph_sp.sdb 218134 ..c. r/rr-xr-xr-x 0 0 2248-128-3 /WINDOWS/AppPatch/apphelp.sdb 80546 ..c. r/rr-xr-xr-x 0 0 2251-128-3 /WINDOWS/Help/apps.chm 306716 ..c. r/rr-xr-xr-x 0 0 2252-128-3 /WINDOWS/Help/apps_sp.chm 60800 ..c. r/rr-xr-xr-x 0 0 2253-128-3 /WINDOWS/system32/drivers/arp1394.sys 14336 ..c. r/rr-xr-xr-x 0 0 2258-128-3 /WINDOWS/system32/drivers/asyncmac.sys 79744 ..c. r/rr-xr-xr-x 0 0 226-128-3 /WINDOWS/Fonts/estre.ttf 29632 ..c. r/rr-xr-xr-x 0 0 2260-128-3 /WINDOWS/inf/ati1xwdm.inf 22219 ..c. r/rr-xr-xr-x 0 0 2261-128-3 /WINDOWS/Help/atm.chm 59904 ..c. r/rr-xr-xr-x 0 0 2263-128-3 /WINDOWS/system32/drivers/atmarpc.sys 55808 ..c. r/rr-xr-xr-x 0 0 2265-128-3 /WINDOWS/system32/drivers/atmlane.sys 214936 ..c. r/rr-xr-xr-x 0 0 227-128-3 /WINDOWS/Fonts/gautami.ttf 612 ..c. r/rr-xr-xr-x 0 0 2273-128-4 /WINDOWS/Provisioning/Schemas/baseeapmethodconfig.xsd 648 ..c. r/rr-xr-xr-x 0 0 2274-128-4 /WINDOWS/Provisioning/Schemas/baseeapmethodusercredentials.xsd 1066 ..c. r/rr-xr-xr-x 0 0 2275-128-3 /WINDOWS/Provisioning/Schemas/baseeapconnectionpropertiesv1.xsd 1116 ..c. r/rr-xr-xr-x 0 0 2276-128-3 /WINDOWS/Provisioning/Schemas/baseeapuserpropertiesv1.xsd 5442 ..c. r/rr-xr-xr-x 0 0 2277-128-3 /WINDOWS/inf/battery.inf 9921 ..c. r/rr-xr-xr-x 0 0 2278-128-3 /WINDOWS/inf/bda.inf 73292 ..c. r/rr-xr-xr-x 0 0 228-128-3 /WINDOWS/Fonts/latha.ttf 50059 ..c. r/rr-xr-xr-x 0 0 2280-128-3 /WINDOWS/Help/blutooth.chm 71552 ..c. r/rr-xr-xr-x 0 0 2282-128-3 /WINDOWS/system32/drivers/bridge.sys 11681 ..c. r/rr-xr-xr-x 0 0 2284-128-3 /WINDOWS/inf/bth.inf 1997 ..c. r/rr-xr-xr-x 0 0 2286-128-3 /WINDOWS/inf/bthprint.inf 1943 ..c. r/rr-xr-xr-x 0 0 2289-128-3 /WINDOWS/inf/bthspp.inf 143864 ..c. r/rr-xr-xr-x 0 0 229-128-3 /WINDOWS/Fonts/mangal.ttf 2563 ..c. r/rr-xr-xr-x 0 0 2290-128-3 /WINDOWS/inf/bthpan.inf 3776 ..c. r/rr-xr-xr-x 0 0 2296-128-3 /WINDOWS/inf/ccdecode.inf 63744 ..c. r/rr-xr-xr-x 0 0 2297-128-3 /WINDOWS/system32/drivers/cdfs.sys 40500 ..c. r/rr-xr-xr-x 0 0 230-128-3 /WINDOWS/Fonts/mvboli.ttf 35450 ..c. r/rr-xr-xr-x 0 0 2301-128-3 /WINDOWS/inf/cdrom.inf 55776 ..c. r/rr-xr-xr-x 0 0 2303-128-3 /WINDOWS/Media/chimes.wav 57348 ..c. r/rr-xr-xr-x 0 0 231-128-3 /WINDOWS/Fonts/raavi.ttf 234280 ..c. r/rr-xr-xr-x 0 0 232-128-3 /WINDOWS/Fonts/shruti.ttf 81776 ..c. r/rr-xr-xr-x 0 0 2321-128-3 /WINDOWS/inf/comnt5.inf 40282 ..c. r/rr-xr-xr-x 0 0 2326-128-3 /WINDOWS/inf/conf.adm 22555 ..c. r/rr-xr-xr-x 0 0 2327-128-3 /WINDOWS/Help/conf1.chm 734 ..c. r/rr-xr-xr-x 0 0 233-128-3 /WINDOWS/system32/drivers/etc/hosts 8134 ..c. r/rr-xr-xr-x 0 0 2331-128-3 /WINDOWS/inf/cpu.inf 36736 ..c. r/rr-xr-xr-x 0 0 2333-128-3 /WINDOWS/system32/drivers/crusoe.sys 33792 ..c. r/rr-xr-xr-x 0 0 2338-128-3 /WINDOWS/Network Diagnostic/custsat.dll 18855 ..c. r/rr-xr-xr-x 0 0 2344-128-3 /WINDOWS/Help/datetime.chm 6784 ..c. r/rr-xr-xr-x 0 0 235-128-3 /WINDOWS/system32/drivers/parvdm.sys 300422 ..c. r/rr-xr-xr-x 0 0 2355-128-3 /WINDOWS/inf/defltwk.inf 39513 ..c. r/rr-xr-xr-x 0 0 2358-128-3 /WINDOWS/inf/devxprop.inf 80856 ..c. r/rr-xr-xr-x 0 0 2369-128-3 /WINDOWS/Media/ding.wav 5327 ..c. r/rr-xr-xr-x 0 0 2372-128-3 /WINDOWS/inf/disk.inf 799744 ..c. r/rr-xr-xr-x 0 0 2379-128-3 /WINDOWS/system32/drivers/dmboot.sys 67899 ..c. r/rr-xr-xr-x 0 0 2414-128-3 /WINDOWS/inf/drvindex.inf 9424 ..c. r/rr-xr-xr-x 0 0 2415-128-3 /WINDOWS/AppPatch/drvmain.sdb 54004 ..c. r/rr-xr-xr-x 0 0 2423-128-3 /WINDOWS/Help/dskquoui.chm 3285 ..c. r/rr-xr-xr-x 0 0 2432-128-3 /WINDOWS/inf/dtcnt5.inf 320562 ..c. r/rr-xr-xr-x 0 0 2435-128-3 /WINDOWS/inf/dwup.inf 24759 ..c. r/rr-xr-xr-x 0 0 2440-128-3 /WINDOWS/Help/dxdiag.chm 752 ..c. r/rr-xr-xr-x 0 0 2444-128-3 /WINDOWS/Provisioning/Schemas/eapcommon.xsd 1120 ..c. r/rr-xr-xr-x 0 0 2445-128-3 /WINDOWS/Provisioning/Schemas/eapgenericusercredentials.xsd 1275 ..c. r/rr-xr-xr-x 0 0 2446-128-3 /WINDOWS/Provisioning/Schemas/eaphostconfig.xsd 1353 ..c. r/rr-xr-xr-x 0 0 2447-128-3 /WINDOWS/Provisioning/Schemas/eaphostusercredentials.xsd 1159 ..c. r/rr-xr-xr-x 0 0 2448-128-3 /WINDOWS/Provisioning/Schemas/eapconnectionpropertiesv1.xsd 789 ..c. r/rr-xr-xr-x 0 0 2449-128-3 /WINDOWS/Provisioning/Schemas/eapuserpropertiesv1.xsd 3192 ..c. r/rr-xr-xr-x 0 0 2450-128-3 /WINDOWS/Provisioning/Schemas/eaptlsconnectionpropertiesv1.xsd 1329 ..c. r/rr-xr-xr-x 0 0 2451-128-3 /WINDOWS/Provisioning/Schemas/eaptlsuserpropertiesv1.xsd 64768 ..c. r/rr-xr-xr-x 0 0 2467-128-3 /WINDOWS/Help/evconcepts.chm 48494 ..c. r/rr-xr-xr-x 0 0 2480-128-3 /WINDOWS/Help/file_srv.chm 77945 ..c. r/rr-xr-xr-x 0 0 2481-128-3 /WINDOWS/Help/filefold.chm 1224 ..c. r/rr-xr-xr-x 0 0 2485-128-3 /WINDOWS/inf/fltmgr.inf 123096 ..c. r/rr-xr-xr-x 0 0 249-128-3 /WINDOWS/Fonts/trebucbd.ttf 7946 ..c. r/rr-xr-xr-x 0 0 2492-128-3 /WINDOWS/inf/fp40ext.inf 50680 ..c. r/rr-xr-xr-x 0 0 2498-128-3 /WINDOWS/inf/fxsocm.inf 226748 ..c. r/rr-xr-xr-x 0 0 250-128-3 /WINDOWS/Fonts/arialbi.ttf 32171 ..c. r/rr-xr-xr-x 0 0 2509-128-3 /WINDOWS/Help/hardware.chm 207808 ..c. r/rr-xr-xr-x 0 0 251-128-3 /WINDOWS/Fonts/ariali.ttf 15071 ..c. r/rr-xr-xr-x 0 0 2510-128-3 /WINDOWS/Help/hardware.hlp 2464 ..c. r/rr-xr-xr-x 0 0 2511-128-3 /WINDOWS/inf/hdaudbus.inf 144384 ..c. r/rr-xr-xr-x 0 0 2512-128-3 /WINDOWS/system32/drivers/hdaudbus.sys 1995 ..c. r/rr-xr-xr-x 0 0 2519-128-3 /WINDOWS/inf/hidbth.inf 111476 ..c. r/rr-xr-xr-x 0 0 252-128-3 /WINDOWS/Fonts/comicbd.ttf 4433 ..c. r/rr-xr-xr-x 0 0 2521-128-3 /WINDOWS/inf/hidserv.inf 48179 ..c. r/rr-xr-xr-x 0 0 2527-128-3 /WINDOWS/Help/howto.chm 33427 ..c. r/rr-xr-xr-x 0 0 2528-128-3 /WINDOWS/Help/hschelp.chm 303296 ..c. r/rr-xr-xr-x 0 0 253-128-3 /WINDOWS/Fonts/cour.ttf 264832 ..c. r/rr-xr-xr-x 0 0 2530-128-3 /WINDOWS/system32/drivers/http.sys 54131 ..c. r/rr-xr-xr-x 0 0 2537-128-3 /WINDOWS/inf/ie.inf 815 ..c. r/rr-xr-xr-x 0 0 2538-128-3 /WINDOWS/inf/ieaccess.inf 312920 ..c. r/rr-xr-xr-x 0 0 254-128-3 /WINDOWS/Fonts/courbd.ttf 204810 ..c. r/rr-xr-xr-x 0 0 2545-128-3 /WINDOWS/Help/iexplore.chm 236148 ..c. r/rr-xr-xr-x 0 0 255-128-3 /WINDOWS/Fonts/courbi.ttf 836490 ..c. r/rr-xr-xr-x 0 0 2550-128-3 /WINDOWS/inf/iis.inf 38132 ..c. r/rr-xr-xr-x 0 0 2551-128-3 /WINDOWS/Help/iis.chm 48885 ..c. r/rr-xr-xr-x 0 0 2555-128-3 /WINDOWS/inf/ims.inf 245032 ..c. r/rr-xr-xr-x 0 0 256-128-3 /WINDOWS/Fonts/couri.ttf 1719224 ..c. r/rr-xr-xr-x 0 0 2560-128-3 /WINDOWS/inf/inetres.adm 165024 ..c. r/rr-xr-xr-x 0 0 2561-128-3 /WINDOWS/Help/inetres.chm 18516 ..c. r/rr-xr-xr-x 0 0 2562-128-3 /WINDOWS/inf/inetset.adm 81568 ..c. r/rr-xr-xr-x 0 0 2563-128-3 /WINDOWS/Help/infrared.chm 69990 ..c. r/rr-xr-xr-x 0 0 2565-128-3 /WINDOWS/inf/input.inf 34703 ..c. r/rr-xr-xr-x 0 0 2566-128-3 /WINDOWS/Help/input.chm 24285 ..c. r/rr-xr-xr-x 0 0 2567-128-3 /WINDOWS/Help/input.hlp 141032 ..c. r/rr-xr-xr-x 0 0 257-128-3 /WINDOWS/Fonts/georgiab.ttf 36352 ..c. r/rr-xr-xr-x 0 0 2570-128-3 /WINDOWS/system32/drivers/intelppm.sys 868116 ..c. r/rr-xr-xr-x 0 0 2572-128-3 /WINDOWS/inf/intl.inf 36608 ..c. r/rr-xr-xr-x 0 0 2573-128-3 /WINDOWS/system32/drivers/ip6fw.sys 20864 ..c. r/rr-xr-xr-x 0 0 2575-128-3 /WINDOWS/system32/drivers/ipinip.sys 152832 ..c. r/rr-xr-xr-x 0 0 2577-128-3 /WINDOWS/system32/drivers/ipnat.sys 157388 ..c. r/rr-xr-xr-x 0 0 258-128-3 /WINDOWS/Fonts/georgiai.ttf 159736 ..c. r/rr-xr-xr-x 0 0 259-128-3 /WINDOWS/Fonts/georgiaz.ttf 219609 ..c. r/rr-xr-xr-x 0 0 2592-128-3 /WINDOWS/Help/ipsecconcepts.chm 154065 ..c. r/rr-xr-xr-x 0 0 2594-128-3 /WINDOWS/Help/Ipv6.chm 27483 ..c. r/rr-xr-xr-x 0 0 2599-128-3 /WINDOWS/inf/irbus.inf 323980 ..c. r/rr-xr-xr-x 0 0 260-128-3 /WINDOWS/Fonts/l_10646.ttf 115068 ..c. r/rr-xr-xr-x 0 0 261-128-3 /WINDOWS/Fonts/lucon.ttf 489884 ..c. r/rr-xr-xr-x 0 0 262-128-3 /WINDOWS/Fonts/pala.ttf 43203 ..c. r/rr-xr-xr-x 0 0 2623-128-3 /WINDOWS/inf/keyboard.inf 278 ..c. r/rr-xr-xr-x 0 0 2628-128-1 /WINDOWS/inf/koc.inf 36992 ..c. r/rr-xr-xr-x 0 0 2629-128-3 /WINDOWS/inf/ks.inf 434004 ..c. r/rr-xr-xr-x 0 0 263-128-3 /WINDOWS/Fonts/palab.ttf 23978 ..c. r/rr-xr-xr-x 0 0 2630-128-3 /WINDOWS/inf/kscaptur.inf 9904 ..c. r/rr-xr-xr-x 0 0 2631-128-3 /WINDOWS/inf/ksfilter.inf 2687 ..c. r/rr-xr-xr-x 0 0 2633-128-3 /WINDOWS/L2Schemas/lan_policy_v1.xsd 2241 ..c. r/rr-xr-xr-x 0 0 2634-128-3 /WINDOWS/L2Schemas/lan_profile_v1.xsd 78519 ..c. r/rr-xr-xr-x 0 0 2635-128-3 /WINDOWS/Help/langbar.chm 417419 ..c. r/rr-xr-xr-x 0 0 2636-128-3 /WINDOWS/inf/layout.inf 101723 ..c. r/rr-xr-xr-x 0 0 2637-128-3 /WINDOWS/Help/mstsc.chm 31785 ..c. r/rr-xr-xr-x 0 0 2638-128-3 /WINDOWS/Help/rdesktop.chm 32564 ..c. r/rr-xr-xr-x 0 0 2639-128-3 /WINDOWS/Help/license.chm 344288 ..c. r/rr-xr-xr-x 0 0 264-128-3 /WINDOWS/Fonts/palabi.ttf 58740 ..c. r/rr-xr-xr-x 0 0 2649-128-3 /WINDOWS/Fonts/lsans.ttf 430800 ..c. r/rr-xr-xr-x 0 0 265-128-3 /WINDOWS/Fonts/palai.ttf 54320 ..c. r/rr-xr-xr-x 0 0 2650-128-3 /WINDOWS/Fonts/lsansd.ttf 60664 ..c. r/rr-xr-xr-x 0 0 2651-128-3 /WINDOWS/Fonts/lsansdi.ttf 59636 ..c. r/rr-xr-xr-x 0 0 2652-128-3 /WINDOWS/Fonts/lsansi.ttf 4190352 ..c. r/rr-xr-xr-x 0 0 2654-128-3 /WINDOWS/Resources/Themes/Luna/luna.msstyles 85547 ..c. r/rr-xr-xr-x 0 0 2655-128-3 /WINDOWS/inf/machine.inf 16322 ..c. r/rr-xr-xr-x 0 0 2659-128-3 /WINDOWS/inf/mchgr.inf 69464 ..c. r/rr-xr-xr-x 0 0 266-128-3 /WINDOWS/Fonts/symbol.ttf 11790 ..c. r/rr-xr-xr-x 0 0 2664-128-3 /WINDOWS/inf/mdac.inf 26756 ..c. r/rr-xr-xr-x 0 0 2665-128-3 /WINDOWS/inf/mdmbtmdm.inf 41011 ..c. r/rr-xr-xr-x 0 0 2666-128-3 /WINDOWS/inf/mdmetech.inf 49296 ..c. r/rr-xr-xr-x 0 0 2667-128-3 /WINDOWS/inf/mdmgen.inf 80087 ..c. r/rr-xr-xr-x 0 0 2669-128-3 /WINDOWS/inf/mdmirmdm.inf 239692 ..c. r/rr-xr-xr-x 0 0 267-128-3 /WINDOWS/Fonts/timesbi.ttf 27971 ..c. r/rr-xr-xr-x 0 0 2670-128-3 /WINDOWS/inf/mdmsuprv.inf 49661 ..c. r/rr-xr-xr-x 0 0 2671-128-3 /WINDOWS/inf/mdmusrk1.inf 15527 ..c. r/rr-xr-xr-x 0 0 2672-128-3 /WINDOWS/inf/mdmvv.inf 2180663 ..c. r/rr-xr-xr-x 0 0 2673-128-3 /WINDOWS/msagent/chars/merlin.acs 63744 ..c. r/rr-xr-xr-x 0 0 2674-128-3 /WINDOWS/system32/drivers/mf.sys 248368 ..c. r/rr-xr-xr-x 0 0 268-128-3 /WINDOWS/Fonts/timesi.ttf 79196 ..c. r/rr-xr-xr-x 0 0 2684-128-3 /WINDOWS/Help/misc.chm 28672 ..c. r/rr-xr-xr-x 0 0 2688-128-3 /WINDOWS/system32/en/microsoft.managementconsole.resources.dll 131188 ..c. r/rr-xr-xr-x 0 0 269-128-3 /WINDOWS/Fonts/trebucbi.ttf 40960 ..c. r/rr-xr-xr-x 0 0 2690-128-3 /WINDOWS/system32/en/mmcex.resources.dll 6656 ..c. r/rr-xr-xr-x 0 0 2692-128-3 /WINDOWS/system32/en/mmcfxcommon.resources.dll 143747 ..c. r/rr-xr-xr-x 0 0 2695-128-3 /WINDOWS/Help/mmc.chm 20776 ..c. r/rr-xr-xr-x 0 0 2698-128-3 /WINDOWS/inf/mmopt.inf 139288 ..c. r/rr-xr-xr-x 0 0 270-128-3 /WINDOWS/Fonts/trebucit.ttf 56768 ..c. r/rr-xr-xr-x 0 0 2702-128-3 /WINDOWS/Help/mode.chm 7379 ..c. r/rr-xr-xr-x 0 0 2705-128-3 /WINDOWS/inf/moviemk.inf 3353 ..c. r/rr-xr-xr-x 0 0 2706-128-3 /WINDOWS/inf/mpe.inf 155076 ..c. r/rr-xr-xr-x 0 0 271-128-3 /WINDOWS/Fonts/verdanai.ttf 92544 ..c. r/rr-xr-xr-x 0 0 2710-128-3 /WINDOWS/system32/drivers/mqac.sys 154800 ..c. r/rr-xr-xr-x 0 0 272-128-3 /WINDOWS/Fonts/verdanaz.ttf 118752 ..c. r/rr-xr-xr-x 0 0 273-128-3 /WINDOWS/Fonts/webdings.ttf 1271 ..c. r/rr-xr-xr-x 0 0 2730-128-3 /WINDOWS/Provisioning/Schemas/mschapv2connectionpropertiesv1.xsd 1410 ..c. r/rr-xr-xr-x 0 0 2731-128-3 /WINDOWS/Provisioning/Schemas/mschapv2userpropertiesv1.xsd 27604 ..c. r/rr-xr-xr-x 0 0 2738-128-3 /WINDOWS/inf/mshdc.inf 81000 ..c. r/rr-xr-xr-x 0 0 274-128-3 /WINDOWS/Fonts/wingding.ttf 204396 ..c. r/rr-xr-xr-x 0 0 2745-128-3 /WINDOWS/AppPatch/msimain.sdb 44271 ..c. r/rr-xr-xr-x 0 0 2746-128-3 /WINDOWS/Help/msinfo32.chm 137616 ..c. r/rr-xr-xr-x 0 0 275-128-3 /WINDOWS/Fonts/verdanab.ttf 39936 ..c. r/rr-xr-xr-x 0 0 2753-128-3 /WINDOWS/msagent/mslwvtts.dll 488023 ..c. r/rr-xr-xr-x 0 0 2754-128-3 /WINDOWS/Help/msmqconcepts.chm 18400 ..c. r/rr-xr-xr-x 0 0 2757-128-3 /WINDOWS/inf/msoe50.inf 2843 ..c. r/rr-xr-xr-x 0 0 2761-128-3 /WINDOWS/Provisioning/Schemas/mspeapconnectionpropertiesv1.xsd 1484 ..c. r/rr-xr-xr-x 0 0 2762-128-3 /WINDOWS/Provisioning/Schemas/mspeapuserpropertiesv1.xsd 15488 ..c. r/rr-xr-xr-x 0 0 2771-128-3 /WINDOWS/system32/drivers/mssmbios.sys 16957 ..c. r/rr-xr-xr-x 0 0 2772-128-3 /WINDOWS/inf/mstape.inf 37318 ..c. r/rr-xr-xr-x 0 0 2773-128-3 /WINDOWS/Help/mstask.chm 879 ..c. r/rr-xr-xr-x 0 0 2788-128-3 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/WordPad.lnk 7895 ..c. r/rr-xr-xr-x 0 0 279-128-3 /WINDOWS/inf/1394.inf 5748 ..c. r/rr-xr-xr-x 0 0 2790-128-3 /WINDOWS/inf/multimed.inf 4097 ..c. r/rr-xr-xr-x 0 0 2791-128-3 /WINDOWS/inf/nabtsfec.inf 1352 ..c. r/rr-xr-xr-x 0 0 280-128-3 /WINDOWS/inf/1394vdbg.inf 6742 ..c. r/rr-xr-xr-x 0 0 2801-128-3 /WINDOWS/inf/ndisip.inf 787 ..c. r/rr-xr-xr-x 0 0 2803-128-3 /WINDOWS/inf/netbeac.inf 535789 ..c. r/rr-xr-xr-x 0 0 2804-128-3 /WINDOWS/Help/netcfg.chm 111115 ..c. r/rr-xr-xr-x 0 0 2808-128-3 /WINDOWS/inf/netfxocm.inf 696 ..c. r/rr-xr-xr-x 0 0 2809-128-1 /WINDOWS/inf/netfw.inf 2505 ..c. r/rr-xr-xr-x 0 0 281-128-3 /WINDOWS/inf/61883.inf 6151 ..c. r/rr-xr-xr-x 0 0 2811-128-3 /WINDOWS/inf/netip6.inf 11747 ..c. r/rr-xr-xr-x 0 0 2812-128-3 /WINDOWS/inf/netmscli.inf 8847 ..c. r/rr-xr-xr-x 0 0 2813-128-3 /WINDOWS/inf/netnm.inf 9074 ..c. r/rr-xr-xr-x 0 0 2815-128-3 /WINDOWS/inf/netoc.inf 39025 ..c. r/rr-xr-xr-x 0 0 2817-128-3 /WINDOWS/inf/netrass.inf 2938 ..c. r/rr-xr-xr-x 0 0 2818-128-3 /WINDOWS/inf/netrndis.inf 24362 ..c. r/rr-xr-xr-x 0 0 2822-128-3 /WINDOWS/inf/nettcpip.inf 1997 ..c. r/rr-xr-xr-x 0 0 2823-128-3 /WINDOWS/inf/nettun.inf 3243 ..c. r/rr-xr-xr-x 0 0 2824-128-3 /WINDOWS/inf/netupnph.inf 3998 ..c. r/rr-xr-xr-x 0 0 2826-128-3 /WINDOWS/inf/netwzc.inf 61824 ..c. r/rr-xr-xr-x 0 0 2827-128-3 /WINDOWS/system32/drivers/nic1394.sys 40320 ..c. r/rr-xr-xr-x 0 0 2829-128-3 /WINDOWS/system32/drivers/nmnt.sys 20832 ..c. r/rr-xr-xr-x 0 0 283-128-3 /WINDOWS/Help/acc_dis.chm 119384 ..c. r/rr-xr-xr-x 0 0 2830-128-3 /WINDOWS/Media/notify.wav 20257 ..c. r/rr-xr-xr-x 0 0 2835-128-3 /WINDOWS/Help/ntchowto.chm 574976 ..c. r/rr-xr-xr-x 0 0 2837-128-3 /WINDOWS/system32/drivers/ntfs.sys 35919 ..c. r/rr-xr-xr-x 0 0 284-128-3 /WINDOWS/Help/access.chm 21138 ..c. r/rr-xr-xr-x 0 0 285-128-3 /WINDOWS/Help/accessib.chm 1498946 ..c. r/rr-xr-xr-x 0 0 2850-128-3 /WINDOWS/inf/ntprint.inf 271333 ..c. r/rr-xr-xr-x 0 0 2853-128-3 /WINDOWS/Help/nusrmgr.chm 88320 ..c. r/rr-xr-xr-x 0 0 2855-128-3 /WINDOWS/system32/drivers/nwlnkipx.sys 163584 ..c. r/rr-xr-xr-x 0 0 2857-128-3 /WINDOWS/system32/drivers/nwrdr.sys 3237 ..c. r/rr-xr-xr-x 0 0 286-128-3 /WINDOWS/inf/acerscan.inf 771 ..c. r/rr-xr-xr-x 0 0 2878-128-3 /WINDOWS/inf/oeaccess.inf 51552 ..c. r/rr-xr-xr-x 0 0 288-128-3 /WINDOWS/Help/aclui.chm 15263 ..c. r/rr-xr-xr-x 0 0 2884-128-3 /WINDOWS/L2Schemas/WLAN_profile_v1.xsd 6786 ..c. r/rr-xr-xr-x 0 0 2889-128-3 /WINDOWS/inf/p2p.inf 17277 ..c. r/rr-xr-xr-x 0 0 289-128-3 /WINDOWS/Help/aclui.hlp 13358 ..c. r/rr-xr-xr-x 0 0 2896-128-3 /WINDOWS/inf/parhmse.inf 21891 ..c. r/rr-xr-xr-x 0 0 2897-128-3 /WINDOWS/Help/password.chm 5089 ..c. r/rr-xr-xr-x 0 0 2898-128-3 /WINDOWS/inf/pchealth.inf 120192 ..c. r/rr-xr-xr-x 0 0 2899-128-3 /WINDOWS/system32/drivers/pcmcia.sys 284160 ..c. r/rr-xr-xr-x 0 0 2900-128-1 /WINDOWS/system32/dllcache/pdh.dll 15481 ..c. r/rr-xr-xr-x 0 0 291-128-3 /WINDOWS/Help/addremov.chm 53259 ..c. r/rr-xr-xr-x 0 0 2914-128-3 /WINDOWS/inf/pnpscsi.inf 98833 ..c. r/rr-xr-xr-x 0 0 2919-128-3 /WINDOWS/Help/printing.chm 27532 ..c. r/rr-xr-xr-x 0 0 292-128-3 /WINDOWS/Help/ade.hlp 35422 ..c. r/rr-xr-xr-x 0 0 293-128-3 /WINDOWS/Help/admtools.chm 6547 ..c. r/rr-xr-xr-x 0 0 2932-128-3 /WINDOWS/inf/qmgr.inf 1894 ..c. r/rr-xr-xr-x 0 0 2935-128-3 /WINDOWS/inf/ramdisk.inf 105608 ..c. r/rr-xr-xr-x 0 0 294-128-3 /WINDOWS/Help/adprop.hlp 25434 ..c. r/rr-xr-xr-x 0 0 2947-128-3 /WINDOWS/Media/recycle.wav 24567 ..c. r/rr-xr-xr-x 0 0 2950-128-3 /WINDOWS/Help/regopt.chm 20126 ..c. r/rr-xr-xr-x 0 0 2952-128-3 /WINDOWS/Help/remasst.chm 10026 ..c. r/rr-xr-xr-x 0 0 2957-128-3 /WINDOWS/Media/ringin.wav 5212 ..c. r/rr-xr-xr-x 0 0 2958-128-3 /WINDOWS/Media/ringout.wav 202624 ..c. r/rr-xr-xr-x 0 0 2959-128-3 /WINDOWS/system32/drivers/RMCast.sys 30592 ..c. r/rr-xr-xr-x 0 0 2960-128-3 /WINDOWS/system32/drivers/rndismp.sys 45830 ..c. r/rr-xr-xr-x 0 0 2965-128-3 /WINDOWS/Help/rsop.chm 17708 ..c. r/rr-xr-xr-x 0 0 2978-128-3 /WINDOWS/inf/sceregvl.inf 3843 ..c. r/rr-xr-xr-x 0 0 298-128-3 /WINDOWS/inf/apcompat.inf 10822 ..c. r/rr-xr-xr-x 0 0 2984-128-3 /WINDOWS/inf/scsi.inf 96384 ..c. r/rr-xr-xr-x 0 0 2985-128-3 /WINDOWS/system32/drivers/scsiport.sys 3669 ..c. r/rr-xr-xr-x 0 0 2988-128-3 /WINDOWS/inf/sdbus.inf 79232 ..c. r/rr-xr-xr-x 0 0 2989-128-3 /WINDOWS/system32/drivers/sdbus.sys 20480 ..c. r/rr-xr-xr-x 0 0 2991-128-3 /WINDOWS/system32/drivers/secdrv.sys 8339 ..c. r/rr-xr-xr-x 0 0 2993-128-3 /WINDOWS/inf/secrecs.inf 18379 ..c. r/rr-xr-xr-x 0 0 2998-128-3 /WINDOWS/Help/sendcmsg.chm 56 .a.. d/dr-xr-xr-x 0 0 30-144-5 /WINDOWS/system32/config 43229 ..c. r/rr-xr-xr-x 0 0 3004-128-3 /WINDOWS/inf/setupqry.inf 4433 ..c. r/rr-xr-xr-x 0 0 3006-128-3 /WINDOWS/inf/sffdisk.inf 11904 ..c. r/rr-xr-xr-x 0 0 3007-128-3 /WINDOWS/system32/drivers/sffdisk.sys 11008 ..c. r/rr-xr-xr-x 0 0 3008-128-3 /WINDOWS/system32/drivers/sffp_sd.sys 10240 ..c. r/rr-xr-xr-x 0 0 3009-128-3 /WINDOWS/system32/drivers/sffp_mmc.sys 404 ..c. r/rr-xr-xr-x 0 0 301-128-1 /WINDOWS/inf/appmig.inf 26411 ..c. r/rr-xr-xr-x 0 0 3011-128-3 /WINDOWS/inf/shell.inf 6540 ..c. r/rr-xr-xr-x 0 0 3014-128-3 /WINDOWS/inf/shl_img.inf 62517 ..c. r/rr-xr-xr-x 0 0 302-128-3 /WINDOWS/inf/apps.inf 3599 ..c. r/rr-xr-xr-x 0 0 3026-128-3 /WINDOWS/inf/slip.inf 23714 ..c. r/rr-xr-xr-x 0 0 3027-128-3 /WINDOWS/inf/smartcrd.inf 34816 ..c. r/rr-xr-xr-x 0 0 3030-128-3 /WINDOWS/Help/sniffpol.dll 25344 ..c. r/rr-xr-xr-x 0 0 3033-128-3 /WINDOWS/system32/drivers/sonydcam.sys 20056462 ..c. r/rr-xr-xr-x 0 0 3034-128-3 /WINDOWS/Driver Cache/i386/sp3.cab 20233 ..c. r/rr-xr-xr-x 0 0 3035-128-3 /WINDOWS/Help/spad.chm 202413 ..c. r/rr-xr-xr-x 0 0 3036-128-3 /WINDOWS/Help/spconcepts.chm 119885 ..c. r/rr-xr-xr-x 0 0 3038-128-3 /WINDOWS/Help/spolsconcepts.chm 151552 ..c. r/rr-xr-xr-x 0 0 3039-128-3 /WINDOWS/PeerNet/sqldb20.dll 462848 ..c. r/rr-xr-xr-x 0 0 3040-128-3 /WINDOWS/PeerNet/sqlqp20.dll 110592 ..c. r/rr-xr-xr-x 0 0 3041-128-3 /WINDOWS/PeerNet/sqlse20.dll 17304 ..c. r/rr-xr-xr-x 0 0 3045-128-3 /WINDOWS/Help/sr_ui.chm 392 ..c. r/rr-xr-xr-x 0 0 305-128-1 /WINDOWS/inf/asroc.inf 33280 ..c. r/rr-xr-xr-x 0 0 3057-128-3 /WINDOWS/Help/sstub.dll 29798 ..c. r/rr-xr-xr-x 0 0 306-128-3 /WINDOWS/inf/atividin.inf 49408 ..c. r/rr-xr-xr-x 0 0 3062-128-3 /WINDOWS/system32/drivers/stream.sys 5884 ..c. r/rr-xr-xr-x 0 0 3063-128-3 /WINDOWS/inf/streamip.inf 1863 ..c. r/rr-xr-xr-x 0 0 3065-128-3 /WINDOWS/inf/swflash.inf 32400 ..c. r/rr-xr-xr-x 0 0 3068-128-3 /WINDOWS/Help/sys_srv.chm 1896 ..c. r/rr-xr-xr-x 0 0 3072-128-3 /WINDOWS/inf/sysoc.inf 35403 ..c. r/rr-xr-xr-x 0 0 3074-128-3 /WINDOWS/Help/sysrestore.chm 35862 ..c. r/rr-xr-xr-x 0 0 3075-128-3 /WINDOWS/inf/syssetup.inf 1745720 ..c. r/rr-xr-xr-x 0 0 3076-128-3 /WINDOWS/inf/system.adm 462338 ..c. r/rr-xr-xr-x 0 0 3077-128-3 /WINDOWS/Help/system.chm 171100 ..c. r/rr-xr-xr-x 0 0 3079-128-3 /WINDOWS/Media/tada.wav 31360 ..c. r/rr-xr-xr-x 0 0 308-128-3 /WINDOWS/system32/drivers/atmepvc.sys 33550 ..c. r/rr-xr-xr-x 0 0 3080-128-3 /WINDOWS/inf/tape.inf 14976 ..c. r/rr-xr-xr-x 0 0 3081-128-3 /WINDOWS/system32/drivers/tape.sys 225664 ..c. r/rr-xr-xr-x 0 0 3087-128-3 /WINDOWS/system32/drivers/tcpip6.sys 4473 ..c. r/rr-xr-xr-x 0 0 3092-128-3 /WINDOWS/inf/tdibth.inf 56 .a.. d/dr-xr-xr-x 0 0 31-144-6 /WINDOWS/system32/drivers 352256 ..c. r/rr-xr-xr-x 0 0 310-128-3 /WINDOWS/system32/drivers/atmuni.sys 313676 ..c. r/rr-xr-xr-x 0 0 3106-128-3 /WINDOWS/Help/tshoot.chm 279040 ..c. r/rr-xr-xr-x 0 0 3107-128-3 /WINDOWS/Help/tshoot.dll 119855 ..c. r/rr-xr-xr-x 0 0 3109-128-3 /WINDOWS/inf/tsoc.inf 11445 ..c. r/rr-xr-xr-x 0 0 311-128-3 /WINDOWS/Help/audiocdc.hlp 12288 ..c. r/rr-xr-xr-x 0 0 3110-128-3 /WINDOWS/system32/drivers/tunmp.sys 45068 ..c. r/rr-xr-xr-x 0 0 3112-128-3 /WINDOWS/Help/twclient.chm 12488 ..c. r/rr-xr-xr-x 0 0 3113-128-3 /WINDOWS/Help/twclient.hlp 66048 ..c. r/rr-xr-xr-x 0 0 3117-128-3 /WINDOWS/system32/drivers/udfs.sys 32750 ..c. r/rr-xr-xr-x 0 0 312-128-3 /WINDOWS/Help/audit.chm 61279 ..c. r/rr-xr-xr-x 0 0 3125-128-3 /WINDOWS/Help/update1.chm 12800 ..c. r/rr-xr-xr-x 0 0 3131-128-3 /WINDOWS/system32/drivers/usb8023.sys 25600 ..c. r/rr-xr-xr-x 0 0 3132-128-3 /WINDOWS/system32/drivers/usbcamd.sys 25728 ..c. r/rr-xr-xr-x 0 0 3133-128-3 /WINDOWS/system32/drivers/usbcamd2.sys 23708 ..c. r/rr-xr-xr-x 0 0 3134-128-3 /WINDOWS/inf/usbport.inf 9026 ..c. r/rr-xr-xr-x 0 0 3135-128-3 /WINDOWS/inf/usbvideo.inf 30284 ..c. r/rr-xr-xr-x 0 0 3136-128-3 /WINDOWS/Help/usercpl.chm 4269 ..c. r/rr-xr-xr-x 0 0 314-128-3 /WINDOWS/inf/avc.inf 5955 ..c. r/rr-xr-xr-x 0 0 3150-128-3 /WINDOWS/inf/wbemoc.inf 63292 ..c. r/rr-xr-xr-x 0 0 3152-128-3 /WINDOWS/inf/wdma_ali.inf 18734 ..c. r/rr-xr-xr-x 0 0 3153-128-3 /WINDOWS/inf/wdma_via.inf 16643 ..c. r/rr-xr-xr-x 0 0 3154-128-3 /WINDOWS/Help/webpub.chm 46008 ..c. r/rr-xr-xr-x 0 0 3157-128-3 /WINDOWS/Help/whatsnew.chm 8047 ..c. r/rr-xr-xr-x 0 0 3173-128-3 /WINDOWS/inf/wordpad.inf 1633 ..c. r/rr-xr-xr-x 0 0 318-128-3 /WINDOWS/inf/axant5.inf 3612 ..c. r/rr-xr-xr-x 0 0 3192-128-3 /WINDOWS/inf/wstcodec.inf 6091 ..c. r/rr-xr-xr-x 0 0 3199-128-3 /WINDOWS/inf/au.inf 56 .a.. d/dr-xr-xr-x 0 0 32-144-5 /WINDOWS/system 40856 ..c. r/rr-xr-xr-x 0 0 3200-128-3 /WINDOWS/inf/wuau.adm 20170 ..c. r/rr-xr-xr-x 0 0 3201-128-3 /WINDOWS/Help/wuau.chm 73873 ..c. r/rr-xr-xr-x 0 0 3202-128-3 /WINDOWS/Help/wuauhelp.chm 520 ..c. r/rr-xr-xr-x 0 0 3206-128-1 /WINDOWS/Provisioning/Schemas/baseeapconnectionpropertiesv1.xdr 580 ..c. r/rr-xr-xr-x 0 0 3207-128-4 /WINDOWS/Provisioning/Schemas/baseeapuserpropertiesv1.xdr 1426 ..c. r/rr-xr-xr-x 0 0 3208-128-3 /WINDOWS/Provisioning/Schemas/branding.xdr 689 ..c. r/rr-xr-xr-x 0 0 3209-128-3 /WINDOWS/Provisioning/Schemas/eapconnectionpropertiesv1.xdr 361472 ..c. r/rr-xr-xr-x 0 0 321-128-3 /WINDOWS/Resources/Themes/Luna/Shell/NormalColor/shellstyle.dll 378 ..c. r/rr-xr-xr-x 0 0 3210-128-1 /WINDOWS/Provisioning/Schemas/eapuserpropertiesv1.xdr 9924 ..c. r/rr-xr-xr-x 0 0 3211-128-3 /WINDOWS/Provisioning/Schemas/flashconfigdevice.xdr 4089 ..c. r/rr-xr-xr-x 0 0 3212-128-3 /WINDOWS/Provisioning/Schemas/flashconfig.xdr 732 ..c. r/rr-xr-xr-x 0 0 3213-128-3 /WINDOWS/Provisioning/Schemas/help.xdr 1721 ..c. r/rr-xr-xr-x 0 0 3214-128-3 /WINDOWS/Provisioning/Schemas/locations.xdr 2459 ..c. r/rr-xr-xr-x 0 0 3215-128-3 /WINDOWS/Provisioning/Schemas/masterfile.xdr 395 ..c. r/rr-xr-xr-x 0 0 3216-128-1 /WINDOWS/Provisioning/Schemas/mschapv2connectionpropertiesv1.xdr 861 ..c. r/rr-xr-xr-x 0 0 3217-128-3 /WINDOWS/Provisioning/Schemas/mschapv2userpropertiesv1.xdr 1911 ..c. r/rr-xr-xr-x 0 0 3218-128-3 /WINDOWS/Provisioning/Schemas/mspeapconnectionpropertiesv1.xdr 698 ..c. r/rr-xr-xr-x 0 0 3219-128-3 /WINDOWS/Provisioning/Schemas/mspeapuserpropertiesv1.xdr 19007 ..c. r/rr-xr-xr-x 0 0 322-128-3 /WINDOWS/Help/blurbs.chm 1032 ..c. r/rr-xr-xr-x 0 0 3220-128-3 /WINDOWS/Provisioning/Schemas/register.xdr 1673 ..c. r/rr-xr-xr-x 0 0 3221-128-3 /WINDOWS/Provisioning/Schemas/ssid.xdr 22405 ..c. r/rr-xr-xr-x 0 0 3222-128-3 /WINDOWS/Provisioning/Schemas/wizard.xdr 2036 ..c. r/rr-xr-xr-x 0 0 3223-128-3 /WINDOWS/Provisioning/Schemas/wirelessprofile.xdr 6400 ..c. r/rr-xr-xr-x 0 0 3226-128-3 /WINDOWS/Media/Windows XP Balloon.wav 36910 ..c. r/rr-xr-xr-x 0 0 3227-128-3 /WINDOWS/Media/Windows XP Battery Critical.wav 53864 ..c. r/rr-xr-xr-x 0 0 3228-128-3 /WINDOWS/Media/Windows XP Battery Low.wav 29444 ..c. r/rr-xr-xr-x 0 0 3229-128-3 /WINDOWS/Media/Windows XP Pop-up Blocked.wav 152576 ..c. r/rr-xr-xr-x 0 0 323-128-3 /WINDOWS/Help/bnts.dll 39382 ..c. r/rr-xr-xr-x 0 0 3230-128-3 /WINDOWS/Media/Windows XP Critical Stop.wav 24530 ..c. r/rr-xr-xr-x 0 0 3231-128-3 /WINDOWS/Media/Windows XP Default.wav 17132 ..c. r/rr-xr-xr-x 0 0 3232-128-3 /WINDOWS/Media/Windows XP Ding.wav 44136 ..c. r/rr-xr-xr-x 0 0 3233-128-3 /WINDOWS/Media/Windows XP Error.wav 42576 ..c. r/rr-xr-xr-x 0 0 3234-128-3 /WINDOWS/Media/Windows XP Exclamation.wav 36614 ..c. r/rr-xr-xr-x 0 0 3235-128-3 /WINDOWS/Media/Windows XP Hardware Fail.wav 36636 ..c. r/rr-xr-xr-x 0 0 3236-128-3 /WINDOWS/Media/Windows XP Hardware Insert.wav 36538 ..c. r/rr-xr-xr-x 0 0 3237-128-3 /WINDOWS/Media/Windows XP Hardware Remove.wav 20336 ..c. r/rr-xr-xr-x 0 0 3238-128-3 /WINDOWS/Media/Windows XP Information Bar.wav 179704 ..c. r/rr-xr-xr-x 0 0 3239-128-3 /WINDOWS/Media/Windows XP Logoff Sound.wav 39622 ..c. r/rr-xr-xr-x 0 0 324-128-3 /WINDOWS/Help/bootcons.chm 190208 ..c. r/rr-xr-xr-x 0 0 3240-128-3 /WINDOWS/Media/Windows XP Logon Sound.wav 1404 ..c. r/rr-xr-xr-x 0 0 3241-128-3 /WINDOWS/Media/Windows XP Menu Command.wav 22580 ..c. r/rr-xr-xr-x 0 0 3242-128-3 /WINDOWS/Media/Windows XP Minimize.wav 558080 ..c. r/rr-xr-xr-x 0 0 3243-128-3 /WINDOWS/Network Diagnostic/xpnetdiag.exe 1692 ..c. r/rr-xr-xr-x 0 0 3244-128-3 /WINDOWS/Network Diagnostic/xpnetdiag.xsl 48988 ..c. r/rr-xr-xr-x 0 0 3245-128-3 /WINDOWS/Media/Windows XP Notify.wav 43762 ..c. r/rr-xr-xr-x 0 0 3246-128-3 /WINDOWS/Media/Windows XP Print complete.wav 22816 ..c. r/rr-xr-xr-x 0 0 3247-128-3 /WINDOWS/Media/Windows XP Recycle.wav 19458 ..c. r/rr-xr-xr-x 0 0 3248-128-3 /WINDOWS/Media/Windows XP Restore.wav 38930 ..c. r/rr-xr-xr-x 0 0 3249-128-3 /WINDOWS/Media/Windows XP Ringin.wav 22070 ..c. r/rr-xr-xr-x 0 0 3250-128-3 /WINDOWS/Media/Windows XP Ringout.wav 282608 ..c. r/rr-xr-xr-x 0 0 3251-128-3 /WINDOWS/Media/Windows XP Shutdown.wav 2202 ..c. r/rr-xr-xr-x 0 0 3252-128-3 /WINDOWS/Media/Windows XP Start.wav 424644 ..c. r/rr-xr-xr-x 0 0 3253-128-3 /WINDOWS/Media/Windows XP Startup.wav 6344 ..c. r/rr-xr-xr-x 0 0 3255-128-3 /WINDOWS/inf/oobe.inf 121452 ..c. r/rr-xr-xr-x 0 0 3256-128-3 /WINDOWS/Fonts/kartika.ttf 252820 ..c. r/rr-xr-xr-x 0 0 3262-128-3 /WINDOWS/Fonts/vrinda.ttf 250368 ..c. r/rr-xr-xr-x 0 0 3266-128-3 /WINDOWS/ime/SPTIP.dll 62976 ..c. r/rr-xr-xr-x 0 0 3267-128-3 /WINDOWS/ime/SPGRMR.dll 18991 ..c. r/rr-xr-xr-x 0 0 327-128-3 /WINDOWS/Help/brief.chm 220160 ..c. r/rr-xr-xr-x 0 0 3270-128-3 /WINDOWS/ime/mscandui.dll 130048 ..c. r/rr-xr-xr-x 0 0 3271-128-3 /WINDOWS/ime/SOFTKBD.DLL 401259 ..c. r/rr-xr-xr-x 0 0 3275-128-3 /WINDOWS/inf/tabletpc.inf 95597 ..c. r/rr-xr-xr-x 0 0 3277-128-3 /WINDOWS/inf/medctroc.inf 33792 ..c. r/rr-xr-xr-x 0 0 3278-128-3 /WINDOWS/ehome/custsat.dll 90624 ..c. r/rr-xr-xr-x 0 0 3279-128-3 /WINDOWS/mui/muisetup.exe 28644 ..c. r/rr-xr-xr-x 0 0 328-128-3 /WINDOWS/inf/brmfcmdm.inf 186880 ..c. r/rr-xr-xr-x 0 0 3281-128-3 /WINDOWS/system32/mui/0401/xpsp1res.dll 161280 ..c. r/rr-xr-xr-x 0 0 3282-128-3 /WINDOWS/system32/mui/0404/xpsp1res.dll 188928 ..c. r/rr-xr-xr-x 0 0 3283-128-3 /WINDOWS/system32/mui/0405/xpsp1res.dll 192000 ..c. r/rr-xr-xr-x 0 0 3284-128-3 /WINDOWS/system32/mui/0406/xpsp1res.dll 199680 ..c. r/rr-xr-xr-x 0 0 3285-128-3 /WINDOWS/system32/mui/0407/xpsp1res.dll 197632 ..c. r/rr-xr-xr-x 0 0 3286-128-3 /WINDOWS/system32/mui/0408/xpsp1res.dll 186368 ..c. r/rr-xr-xr-x 0 0 3287-128-3 /WINDOWS/system32/mui/040b/xpsp1res.dll 48055 ..c. r/rr-xr-xr-x 0 0 329-128-3 /WINDOWS/inf/brmfcmf.inf 3029 ..c. r/rr-xr-xr-x 0 0 330-128-3 /WINDOWS/inf/brmfcsto.inf 189440 ..c. r/rr-xr-xr-x 0 0 3304-128-3 /WINDOWS/system32/mui/0402/xpsp1res.dll 2556 ..c. r/rr-xr-xr-x 0 0 331-128-3 /WINDOWS/inf/brmfcumd.inf 2869248 ..c. r/rr-xr-xr-x 0 0 3314-128-3 /WINDOWS/system32/mui/0401/xpsp2res.dll 477696 ..c. r/rr-xr-xr-x 0 0 3315-128-3 /WINDOWS/system32/mui/0404/xpsp2res.dll 734720 ..c. r/rr-xr-xr-x 0 0 3316-128-3 /WINDOWS/system32/mui/0405/xpsp2res.dll 742912 ..c. r/rr-xr-xr-x 0 0 3317-128-3 /WINDOWS/system32/mui/0406/xpsp2res.dll 788480 ..c. r/rr-xr-xr-x 0 0 3318-128-3 /WINDOWS/system32/mui/0407/xpsp2res.dll 801280 ..c. r/rr-xr-xr-x 0 0 3319-128-3 /WINDOWS/system32/mui/0408/xpsp2res.dll 23444 ..c. r/rr-xr-xr-x 0 0 332-128-3 /WINDOWS/inf/brmfcwia.inf 729088 ..c. r/rr-xr-xr-x 0 0 3320-128-3 /WINDOWS/system32/mui/040b/xpsp2res.dll 5295 ..c. r/rr-xr-xr-x 0 0 333-128-3 /WINDOWS/inf/brmfport.inf 656896 ..c. r/rr-xr-xr-x 0 0 3340-128-3 /WINDOWS/system32/mui/0401/xpsp3res.dll 327680 ..c. r/rr-xr-xr-x 0 0 3341-128-3 /WINDOWS/system32/mui/0404/xpsp3res.dll 601088 ..c. r/rr-xr-xr-x 0 0 3342-128-3 /WINDOWS/system32/mui/0405/xpsp3res.dll 605696 ..c. r/rr-xr-xr-x 0 0 3343-128-3 /WINDOWS/system32/mui/0406/xpsp3res.dll 663552 ..c. r/rr-xr-xr-x 0 0 3344-128-3 /WINDOWS/system32/mui/0407/xpsp3res.dll 679936 ..c. r/rr-xr-xr-x 0 0 3345-128-3 /WINDOWS/system32/mui/0408/xpsp3res.dll 604672 ..c. r/rr-xr-xr-x 0 0 3346-128-3 /WINDOWS/system32/mui/040b/xpsp3res.dll 393728 ..c. r/rr-xr-xr-x 0 0 3366-128-3 /WINDOWS/system32/mui/0401/xpob2res.dll 212480 ..c. r/rr-xr-xr-x 0 0 3367-128-3 /WINDOWS/system32/mui/0404/xpob2res.dll 428032 ..c. r/rr-xr-xr-x 0 0 3368-128-3 /WINDOWS/system32/mui/0405/xpob2res.dll 418816 ..c. r/rr-xr-xr-x 0 0 3369-128-3 /WINDOWS/system32/mui/0406/xpob2res.dll 403456 ..c. r/rr-xr-xr-x 0 0 3370-128-3 /WINDOWS/system32/mui/0407/xpob2res.dll 419328 ..c. r/rr-xr-xr-x 0 0 3371-128-3 /WINDOWS/system32/mui/0408/xpob2res.dll 405504 ..c. r/rr-xr-xr-x 0 0 3372-128-3 /WINDOWS/system32/mui/040b/xpob2res.dll 410624 ..c. r/rr-xr-xr-x 0 0 3373-128-3 /WINDOWS/system32/mui/040C/xpob2res.dll 384768 ..c. r/rr-xr-xr-x 0 0 3391-128-3 /WINDOWS/system32/drivers/update.sys 1202774 ..c. r/rr-xr-xr-x 0 0 3392-128-3 /WINDOWS/AppPatch/sysmain.sdb 208896 ..c. r/rr-xr-xr-x 0 0 3398-128-3 /WINDOWS/inf/unregmp2.exe 18286 ..c. r/rr-xr-xr-x 0 0 3402-128-3 /WINDOWS/inf/mplayer2.inf 14455 ..c. r/rr-xr-xr-x 0 0 3404-128-3 /WINDOWS/inf/atiixpaa.inf 60304 ..c. r/rr-xr-xr-x 0 0 3405-128-3 /WINDOWS/inf/atiixpag.inf 30548 ..c. r/rr-xr-xr-x 0 0 3406-128-3 /WINDOWS/inf/atixpwdm.inf 48044 ..c. r/rr-xr-xr-x 0 0 3407-128-3 /WINDOWS/inf/biosinfo.inf 376086 ..c. r/rr-xr-xr-x 0 0 3409-128-3 /WINDOWS/Help/cpanel.chq 5199 ..c. r/rr-xr-xr-x 0 0 3410-128-3 /WINDOWS/inf/g400.inf 3751 ..c. r/rr-xr-xr-x 0 0 3413-128-3 /WINDOWS/inf/HidDigi.inf 11718 ..c. r/rr-xr-xr-x 0 0 3414-128-3 /WINDOWS/inf/i81xnt5.inf 50067 ..c. r/rr-xr-xr-x 0 0 3427-128-3 /WINDOWS/inf/mdmcxsf2.inf 85069 ..c. r/rr-xr-xr-x 0 0 3428-128-3 /WINDOWS/inf/mdmhamrw.inf 28128 ..c. r/rr-xr-xr-x 0 0 3429-128-3 /WINDOWS/inf/mdmntstm.inf 60733 ..c. r/rr-xr-xr-x 0 0 3430-128-3 /WINDOWS/inf/mdmlt3.inf 299444 ..c. r/rr-xr-xr-x 0 0 3431-128-3 /WINDOWS/inf/mdmrpci.inf 2575 ..c. r/rr-xr-xr-x 0 0 3441-128-3 /WINDOWS/Help/migwiz.htm 1644 ..c. r/rr-xr-xr-x 0 0 3442-128-3 /WINDOWS/Help/migwiz2.htm 46281 ..c. r/rr-xr-xr-x 0 0 3449-128-3 /WINDOWS/inf/msnetmtg.inf 8810 ..c. r/rr-xr-xr-x 0 0 3455-128-3 /WINDOWS/inf/netklsi.inf 9022 ..c. r/rr-xr-xr-x 0 0 3456-128-3 /WINDOWS/inf/netrtsnt.inf 17503 ..c. r/rr-xr-xr-x 0 0 3457-128-3 /WINDOWS/inf/netwlan.inf 9030 ..c. r/rr-xr-xr-x 0 0 3458-128-3 /WINDOWS/inf/netwlan2.inf 111575 ..c. r/rr-xr-xr-x 0 0 3459-128-3 /WINDOWS/Help/network.chm 10068 ..c. r/rr-xr-xr-x 0 0 3460-128-3 /WINDOWS/inf/netwv48.inf 81426 ..c. r/rr-xr-xr-x 0 0 3461-128-3 /WINDOWS/Help/ntdef.chm 21295 ..c. r/rr-xr-xr-x 0 0 3462-128-3 /WINDOWS/inf/nv4_disp.inf 11494 ..c. r/rr-xr-xr-x 0 0 3463-128-3 /WINDOWS/inf/nvct.inf 19214 ..c. r/rr-xr-xr-x 0 0 3464-128-3 /WINDOWS/inf/nvdm.inf 10865 ..c. r/rr-xr-xr-x 0 0 3465-128-3 /WINDOWS/inf/nvts.inf 3464 ..c. r/rr-xr-xr-x 0 0 3472-128-3 /WINDOWS/inf/ps5333.inf 15872 ..c. r/rr-xr-xr-x 0 0 3481-128-3 /WINDOWS/system32/drivers/usbintel.sys 672 .a.. d/drwxrwxrwx 0 0 3483-144-1 /Documents and Settings/Default User/Local Settings/Temporary Internet Files/Content.IE5 24371 ..c. r/rr-xr-xr-x 0 0 3484-128-3 /WINDOWS/inf/wdma_int.inf 1104994 ..c. r/rr-xr-xr-x 0 0 3485-128-3 /WINDOWS/Help/windows.chq 3455 ..c. r/rr-xr-xr-x 0 0 3486-128-3 /WINDOWS/inf/wfp0.inf 3454 ..c. r/rr-xr-xr-x 0 0 3487-128-3 /WINDOWS/inf/wfp1.inf 3453 ..c. r/rr-xr-xr-x 0 0 3488-128-3 /WINDOWS/inf/wfp2.inf 3455 ..c. r/rr-xr-xr-x 0 0 3489-128-3 /WINDOWS/inf/wfp3.inf 3455 ..c. r/rr-xr-xr-x 0 0 3490-128-3 /WINDOWS/inf/wfp4.inf 3459 ..c. r/rr-xr-xr-x 0 0 3491-128-3 /WINDOWS/inf/wfp5.inf 3458 ..c. r/rr-xr-xr-x 0 0 3492-128-3 /WINDOWS/inf/wfp6.inf 3458 ..c. r/rr-xr-xr-x 0 0 3493-128-3 /WINDOWS/inf/wfp7.inf 3460 ..c. r/rr-xr-xr-x 0 0 3494-128-3 /WINDOWS/inf/wfp8.inf 3459 ..c. r/rr-xr-xr-x 0 0 3495-128-3 /WINDOWS/inf/wtv0.inf 3462 ..c. r/rr-xr-xr-x 0 0 3496-128-3 /WINDOWS/inf/wtv1.inf 3462 ..c. r/rr-xr-xr-x 0 0 3497-128-3 /WINDOWS/inf/wtv2.inf 3456 ..c. r/rr-xr-xr-x 0 0 3498-128-3 /WINDOWS/inf/wtv3.inf 3457 ..c. r/rr-xr-xr-x 0 0 3499-128-3 /WINDOWS/inf/wtv4.inf 3455 ..c. r/rr-xr-xr-x 0 0 3500-128-3 /WINDOWS/inf/wtv5.inf 32768 ..c. r/rr-xr-xr-x 0 0 3501-128-3 /Documents and Settings/Default User/Local Settings/Temporary Internet Files/Content.IE5/index.dat 1066 ..c. r/rr-xr-xr-x 0 0 3502-128-3 /WINDOWS/L2Schemas/baseeapconnectionpropertiesv1.xsd 1116 ..c. r/rr-xr-xr-x 0 0 3503-128-3 /WINDOWS/L2Schemas/baseeapuserpropertiesv1.xsd 612 ..c. r/rr-xr-xr-x 0 0 3504-128-4 /WINDOWS/L2Schemas/BaseEapMethodConfig.xsd 648 ..c. r/rr-xr-xr-x 0 0 3505-128-4 /WINDOWS/L2Schemas/BaseEapMethodUserCredentials.xsd 752 ..c. r/rr-xr-xr-x 0 0 3506-128-3 /WINDOWS/L2Schemas/EapCommon.xsd 1159 ..c. r/rr-xr-xr-x 0 0 3507-128-3 /WINDOWS/L2Schemas/eapconnectionpropertiesv1.xsd 789 ..c. r/rr-xr-xr-x 0 0 3508-128-3 /WINDOWS/L2Schemas/eapuserpropertiesv1.xsd 1115 ..c. r/rr-xr-xr-x 0 0 3509-128-3 /WINDOWS/L2Schemas/EapHostConfig.xsd 1193 ..c. r/rr-xr-xr-x 0 0 3510-128-3 /WINDOWS/L2Schemas/EapHostUserCredentials.xsd 3192 ..c. r/rr-xr-xr-x 0 0 3511-128-3 /WINDOWS/L2Schemas/EapTlsConnectionPropertiesV1.xsd 1329 ..c. r/rr-xr-xr-x 0 0 3512-128-3 /WINDOWS/L2Schemas/EapTlsUserPropertiesV1.xsd 1271 ..c. r/rr-xr-xr-x 0 0 3513-128-3 /WINDOWS/L2Schemas/mschapv2connectionpropertiesv1.xsd 1410 ..c. r/rr-xr-xr-x 0 0 3514-128-3 /WINDOWS/L2Schemas/mschapv2userpropertiesv1.xsd 2843 ..c. r/rr-xr-xr-x 0 0 3515-128-3 /WINDOWS/L2Schemas/mspeapconnectionpropertiesv1.xsd 1484 ..c. r/rr-xr-xr-x 0 0 3516-128-3 /WINDOWS/L2Schemas/mspeapuserpropertiesv1.xsd 5957 ..c. r/rr-xr-xr-x 0 0 3517-128-3 /WINDOWS/L2Schemas/OneX_v1.xsd 46130 ..c. r/rr-xr-xr-x 0 0 3519-128-3 /WINDOWS/Help/wschelp.chm 108111 ..c. r/rr-xr-xr-x 0 0 3521-128-3 /WINDOWS/Help/Tours/htmlTour/img046.jpg 384 ..c. r/rr-xr-xr-x 0 0 3522-128-1 /WINDOWS/Help/Tours/htmlTour/best_fr.htm 8359 ..c. r/rr-xr-xr-x 0 0 3523-128-3 /WINDOWS/Help/Tours/htmlTour/best_road.htm 8350 ..c. r/rr-xr-xr-x 0 0 3524-128-3 /WINDOWS/Help/Tours/htmlTour/best_robust.htm 8362 ..c. r/rr-xr-xr-x 0 0 3525-128-3 /WINDOWS/Help/Tours/htmlTour/best_secure.htm 7969 ..c. r/rr-xr-xr-x 0 0 3526-128-3 /WINDOWS/Help/Tours/htmlTour/connected_data.htm 401 ..c. r/rr-xr-xr-x 0 0 3527-128-1 /WINDOWS/Help/Tours/htmlTour/connected_fr.htm 9211 ..c. r/rr-xr-xr-x 0 0 3528-128-3 /WINDOWS/Help/Tours/htmlTour/connected_multiple.htm 9151 ..c. r/rr-xr-xr-x 0 0 3529-128-3 /WINDOWS/Help/Tours/htmlTour/connected_networks.htm 8796 ..c. r/rr-xr-xr-x 0 0 3530-128-3 /WINDOWS/Help/Tours/htmlTour/connected_wizard.htm 4423 ..c. r/rr-xr-xr-x 0 0 3531-128-3 /WINDOWS/Help/Tours/htmlTour/default.htm 1777 ..c. r/rr-xr-xr-x 0 0 3532-128-3 /WINDOWS/Help/Tours/htmlTour/footer.htm 8223 ..c. r/rr-xr-xr-x 0 0 3533-128-3 /WINDOWS/Help/Tours/htmlTour/safe_better.htm 7690 ..c. r/rr-xr-xr-x 0 0 3534-128-3 /WINDOWS/Help/Tours/htmlTour/safe_easier.htm 7568 ..c. r/rr-xr-xr-x 0 0 3535-128-3 /WINDOWS/Help/Tours/htmlTour/safe_faster.htm 399 ..c. r/rr-xr-xr-x 0 0 3536-128-1 /WINDOWS/Help/Tours/htmlTour/safe_fr.htm 9372 ..c. r/rr-xr-xr-x 0 0 3537-128-3 /WINDOWS/Help/Tours/htmlTour/start_control.htm 8506 ..c. r/rr-xr-xr-x 0 0 3538-128-3 /WINDOWS/Help/Tours/htmlTour/start_desktop.htm 8760 ..c. r/rr-xr-xr-x 0 0 3539-128-3 /WINDOWS/Help/Tours/htmlTour/start_ending.htm 8612 ..c. r/rr-xr-xr-x 0 0 3540-128-3 /WINDOWS/Help/Tours/htmlTour/start_files.htm 396 ..c. r/rr-xr-xr-x 0 0 3541-128-1 /WINDOWS/Help/Tours/htmlTour/start_fr.htm 9220 ..c. r/rr-xr-xr-x 0 0 3542-128-3 /WINDOWS/Help/Tours/htmlTour/start_icons.htm 9230 ..c. r/rr-xr-xr-x 0 0 3543-128-3 /WINDOWS/Help/Tours/htmlTour/start_menu.htm 9099 ..c. r/rr-xr-xr-x 0 0 3544-128-3 /WINDOWS/Help/Tours/htmlTour/start_taskbar.htm 9921 ..c. r/rr-xr-xr-x 0 0 3545-128-3 /WINDOWS/Help/Tours/htmlTour/start_windows.htm 7233 ..c. r/rr-xr-xr-x 0 0 3546-128-3 /WINDOWS/Help/Tours/htmlTour/unlock_built.htm 399 ..c. r/rr-xr-xr-x 0 0 3547-128-1 /WINDOWS/Help/Tours/htmlTour/unlock_fr.htm 7041 ..c. r/rr-xr-xr-x 0 0 3548-128-3 /WINDOWS/Help/Tours/htmlTour/unlock_optimized.htm 3928 ..c. r/rr-xr-xr-x 0 0 3549-128-3 /WINDOWS/inf/msnmsn.inf 750 ..c. r/rr-xr-xr-x 0 0 3551-128-3 /WINDOWS/inf/drm.inf 3637 ..c. r/rr-xr-xr-x 0 0 3574-128-3 /WINDOWS/inf/mymusic.inf 77307 ..c. r/rr-xr-xr-x 0 0 3575-128-3 /WINDOWS/Help/plyr_err.chm 908 ..c. r/rr-xr-xr-x 0 0 3577-128-3 /WINDOWS/inf/skins.inf 17272 ..c. r/rr-xr-xr-x 0 0 3582-128-3 /WINDOWS/inf/wmdm.inf 6769 ..c. r/rr-xr-xr-x 0 0 3586-128-3 /WINDOWS/inf/wmfsdk.inf 29070 ..c. r/rr-xr-xr-x 0 0 3589-128-3 /WINDOWS/inf/wmp.inf 613334 ..c. r/rr-xr-xr-x 0 0 3591-128-3 /WINDOWS/Help/wmplayer.chm 67374 ..c. r/rr-xr-xr-x 0 0 3595-128-3 /WINDOWS/inf/wmplayer.adm 23195 ..c. r/rr-xr-xr-x 0 0 3596-128-3 /WINDOWS/Help/wmplay.chm 855 ..c. r/rr-xr-xr-x 0 0 3597-128-3 /WINDOWS/inf/wmpocm.inf 51427 ..c. r/rr-xr-xr-x 0 0 3610-128-3 /WINDOWS/inf/msmsgs.inf 586 ..c. r/rr-xr-xr-x 0 0 3611-128-1 /WINDOWS/inf/wmaccess.inf 52480 ..c. r/rr-xr-xr-x 0 0 3619-128-3 /WINDOWS/system32/drivers/i8042prt.sys 37248 ..c. r/rr-xr-xr-x 0 0 3620-128-3 /WINDOWS/system32/drivers/isapnp.sys 187776 ..c. r/rr-xr-xr-x 0 0 3621-128-3 /WINDOWS/system32/drivers/acpi.sys 68224 ..c. r/rr-xr-xr-x 0 0 3622-128-3 /WINDOWS/system32/drivers/pci.sys 59520 ..c. r/rr-xr-xr-x 0 0 3623-128-3 /WINDOWS/system32/drivers/usbhub.sys 36864 ..c. r/rr-xr-xr-x 0 0 3624-128-3 /WINDOWS/system32/drivers/hidclass.sys 24960 ..c. r/rr-xr-xr-x 0 0 3625-128-3 /WINDOWS/system32/drivers/hidparse.sys 143872 ..c. r/rr-xr-xr-x 0 0 3626-128-3 /WINDOWS/system32/drivers/usbport.sys 20608 ..c. r/rr-xr-xr-x 0 0 3627-128-3 /WINDOWS/system32/drivers/usbuhci.sys 30208 ..c. r/rr-xr-xr-x 0 0 3629-128-3 /WINDOWS/system32/drivers/usbehci.sys 23040 ..c. r/rr-xr-xr-x 0 0 3630-128-3 /WINDOWS/system32/drivers/mouclass.sys 24576 ..c. r/rr-xr-xr-x 0 0 3631-128-3 /WINDOWS/system32/drivers/kbdclass.sys 231750 ..c. r/rr-xr-xr-x 0 0 3632-128-3 /WINDOWS/repair/setup.log 237568 ..c. r/rr-xr-xr-x 0 0 3634-128-4 /Documents and Settings/NetworkService/NTUSER.DAT 56 .ac. d/dr-xr-xr-x 0 0 3635-144-6 /Documents and Settings/NetworkService/Local Settings 262144 ..c. r/rr-xr-xr-x 0 0 3636-128-3 /WINDOWS/system32/config/userdiff 1024 ..c. r/rr-xr-xr-x 0 0 3639-128-3 /WINDOWS/system32/config/default.LOG 1024 ..c. r/rr-xr-xr-x 0 0 3640-128-3 /WINDOWS/system32/config/userdiff.LOG 913408 ..c. r/rr-xr-xr-x 0 0 3642-128-3 /WINDOWS/system32/config/system.sav 1024 ..c. r/rr-xr-xr-x 0 0 3643-128-3 /WINDOWS/system32/config/TempKey.LOG 1089536 ..c. r/rr-xr-xr-x 0 0 3644-128-3 /WINDOWS/system32/config/software.sav 94208 ..c. r/rr-xr-xr-x 0 0 3645-128-3 /WINDOWS/system32/config/default.sav 262144 ..c. r/rr-xr-xr-x 0 0 3647-128-3 /WINDOWS/system32/config/SECURITY 262144 ..c. r/rr-xr-xr-x 0 0 3648-128-3 /WINDOWS/system32/config/SAM 1024 ..c. r/rr-xr-xr-x 0 0 3649-128-3 /WINDOWS/system32/config/SECURITY.LOG 1024 ..c. r/rr-xr-xr-x 0 0 3650-128-3 /WINDOWS/system32/config/SAM.LOG 56 .ac. d/dr-xr-xr-x 0 0 3655-144-7 /Documents and Settings/Default User 56 .ac. d/dr-xr-xr-x 0 0 3656-144-6 /Documents and Settings/All Users 0 ..c. r/rr-xr-xr-x 0 0 3657-128-13 /WINDOWS/Debug/PASSWD.LOG 65536 ..c. r/rr-xr-xr-x 0 0 3660-128-1 /WINDOWS/system32/config/SecEvent.Evt 101836 ..c. r/rr-xr-xr-x 0 0 3665-128-3 /WINDOWS/inf/syssetup.PNF 1068864 ..c. r/rr-xr-xr-x 0 0 3666-128-3 /WINDOWS/inf/LAYOUT.PNF 8026 ..c. r/rr-xr-xr-x 0 0 367-128-3 /WINDOWS/inf/camdsh20.inf 21924 ..c. r/rr-xr-xr-x 0 0 368-128-3 /WINDOWS/Help/camera.chm 31178 ..c. r/rr-xr-xr-x 0 0 369-128-3 /WINDOWS/Help/camera.hlp 9785 ..c. r/rr-xr-xr-x 0 0 370-128-3 /WINDOWS/inf/camvid20.inf 6782 ..c. r/rr-xr-xr-x 0 0 371-128-3 /WINDOWS/inf/camvid30.inf 13952 ..c. r/rr-xr-xr-x 0 0 373-128-3 /WINDOWS/system32/drivers/cbidf2k.sys 56 ..c. d/d--x--x--x 0 0 3736-144-6 /Documents and Settings/All Users/Application Data 70888 ..c. r/rr-xr-xr-x 0 0 3743-128-3 /WINDOWS/Debug/UserMode/userenv.log 360 .ac. d/d--x--x--x 0 0 3744-144-1 /Documents and Settings/Default User/Application Data 136 .a.. d/drwxrwxrwx 0 0 3746-144-1 /Documents and Settings/Default User/Application Data/Microsoft/SystemCertificates 456 .a.. d/drwxrwxrwx 0 0 3747-144-1 /Documents and Settings/Default User/Application Data/Microsoft/SystemCertificates/My 48 .a.. d/drwxrwxrwx 0 0 3748-144-1 /Documents and Settings/Default User/Application Data/Microsoft/SystemCertificates/My/Certificates 48 .a.. d/drwxrwxrwx 0 0 3749-144-1 /Documents and Settings/Default User/Application Data/Microsoft/SystemCertificates/My/CRLs 20544 ..c. r/rr-xr-xr-x 0 0 375-128-3 /WINDOWS/Help/cdmedia.chm 48 .a.. d/drwxrwxrwx 0 0 3750-144-1 /Documents and Settings/Default User/Application Data/Microsoft/SystemCertificates/My/CTLs 576 .a.. d/dr-xr-xr-x 0 0 3751-144-1 /WINDOWS/system32/CatRoot 256 .ac. d/dr-xr-xr-x 0 0 3752-144-1 /WINDOWS/system32/CatRoot/{127D0A1D-4EF2-11D1-8608-00C04FC295EE} 56 .a.. d/dr-xr-xr-x 0 0 3753-144-5 /WINDOWS/system32/CatRoot2 352 .ac. d/dr-xr-xr-x 0 0 3754-144-1 /WINDOWS/system32/CatRoot2/{127D0A1D-4EF2-11D1-8608-00C04FC295EE} 131072 ..c. r/rr-xr-xr-x 0 0 3757-128-3 /WINDOWS/system32/CatRoot2/res2.log 131072 ..c. r/rr-xr-xr-x 0 0 3758-128-3 /WINDOWS/system32/CatRoot2/res1.log 11627 ..c. r/rr-xr-xr-x 0 0 376-128-3 /WINDOWS/Help/cdmedia.hlp 8192 ..c. r/rr-xr-xr-x 0 0 3760-128-3 /WINDOWS/system32/CatRoot2/edb.chk 1056768 ..c. r/rr-xr-xr-x 0 0 3761-128-3 /WINDOWS/system32/CatRoot2/{127D0A1D-4EF2-11D1-8608-00C04FC295EE}/catdb 8 ..c. r/rr-xr-xr-x 0 0 3762-128-1 /WINDOWS/system32/CatRoot/{127D0A1D-4EF2-11D1-8608-00C04FC295EE}/TimeStamp 8 ..c. r/rr-xr-xr-x 0 0 3763-128-1 /WINDOWS/system32/CatRoot2/{127D0A1D-4EF2-11D1-8608-00C04FC295EE}/TimeStamp 56 .ac. d/dr-xr-xr-x 0 0 3764-144-6 /WINDOWS/system32/CatRoot/{F750E6C3-38EE-11D1-85E5-00C04FC295EE} 352 .ac. d/dr-xr-xr-x 0 0 3765-144-1 /WINDOWS/system32/CatRoot2/{F750E6C3-38EE-11D1-85E5-00C04FC295EE} 2899 ..c. r/rr-xr-xr-x 0 0 3767-128-3 /WINDOWS/system32/CatRoot2/dberr.txt 3153920 ..c. r/rr-xr-xr-x 0 0 3768-128-3 /WINDOWS/system32/CatRoot2/{F750E6C3-38EE-11D1-85E5-00C04FC295EE}/catdb 2186 ..c. r/rr-xr-xr-x 0 0 377-128-3 /WINDOWS/inf/certclas.inf 8 ..c. r/rr-xr-xr-x 0 0 3771-128-1 /WINDOWS/system32/CatRoot2/{F750E6C3-38EE-11D1-85E5-00C04FC295EE}/TimeStamp 8 ..c. r/rr-xr-xr-x 0 0 3772-128-1 /WINDOWS/system32/CatRoot/{F750E6C3-38EE-11D1-85E5-00C04FC295EE}/TimeStamp 445594 ..c. r/rr-xr-xr-x 0 0 3773-128-3 /WINDOWS/system32/dllcache/NT5INF.CAT 131072 ..c. r/rr-xr-xr-x 0 0 3779-128-3 /WINDOWS/system32/CatRoot2/edb.log 26345 ..c. r/rr-xr-xr-x 0 0 378-128-3 /WINDOWS/Help/certmgr.hlp 131072 ..c. r/rr-xr-xr-x 0 0 3782-128-3 /WINDOWS/system32/CatRoot2/edb00013.log 131072 ..c. r/rr-xr-xr-x 0 0 3783-128-3 /WINDOWS/system32/CatRoot2/edb00014.log 131072 ..c. r/rr-xr-xr-x 0 0 3786-128-3 /WINDOWS/system32/CatRoot2/edb00015.log 131072 ..c. r/rr-xr-xr-x 0 0 3787-128-3 /WINDOWS/system32/CatRoot2/edb00016.log 131072 ..c. r/rr-xr-xr-x 0 0 3788-128-3 /WINDOWS/system32/CatRoot2/edb00017.log 131072 ..c. r/rr-xr-xr-x 0 0 3790-128-3 /WINDOWS/system32/CatRoot2/edb00018.log 15255 ..c. r/rr-xr-xr-x 0 0 380-128-3 /WINDOWS/Help/certmgr.chm 2144487 ..c. r/rr-xr-xr-x 0 0 3800-128-3 /WINDOWS/system32/dllcache/NT5.CAT 1296669 ..c. r/rr-xr-xr-x 0 0 3801-128-3 /WINDOWS/system32/dllcache/SP3.CAT 1088840 ..c. r/rr-xr-xr-x 0 0 3802-128-3 /WINDOWS/system32/dllcache/NTPRINT.CAT 797189 ..c. r/rr-xr-xr-x 0 0 3803-128-3 /WINDOWS/system32/dllcache/NT5IIS.CAT 399645 ..c. r/rr-xr-xr-x 0 0 3804-128-3 /WINDOWS/system32/dllcache/MAPIMIG.CAT 34063 ..c. r/rr-xr-xr-x 0 0 3805-128-3 /WINDOWS/system32/dllcache/FP4.CAT 16535 ..c. r/rr-xr-xr-x 0 0 3806-128-3 /WINDOWS/system32/dllcache/IMS.CAT 12363 ..c. r/rr-xr-xr-x 0 0 3807-128-3 /WINDOWS/system32/dllcache/MSMSGS.CAT 13472 ..c. r/rr-xr-xr-x 0 0 3808-128-3 /WINDOWS/system32/dllcache/HPCRDP.CAT 37484 ..c. r/rr-xr-xr-x 0 0 3809-128-3 /WINDOWS/system32/dllcache/MW770.CAT 6352 ..c. r/rr-xr-xr-x 0 0 381-128-3 /WINDOWS/Fonts/cga40850.fon 7334 ..c. r/rr-xr-xr-x 0 0 3810-128-3 /WINDOWS/system32/dllcache/wmerrenu.cat 8574 ..c. r/rr-xr-xr-x 0 0 3811-128-3 /WINDOWS/system32/dllcache/IASNT4.CAT 10027 ..c. r/rr-xr-xr-x 0 0 3812-128-3 /WINDOWS/system32/dllcache/MSTSWEB.CAT 7382 ..c. r/rr-xr-xr-x 0 0 3813-128-3 /WINDOWS/system32/dllcache/OEMBIOS.CAT 112918 ..c. r/rr-xr-xr-x 0 0 3814-128-3 /WINDOWS/system32/dllcache/tabletpc.cat 34747 ..c. r/rr-xr-xr-x 0 0 3815-128-3 /WINDOWS/system32/dllcache/mediactr.cat 26991 ..c. r/rr-xr-xr-x 0 0 3816-128-3 /WINDOWS/system32/dllcache/msn7.cat 14433 ..c. r/rr-xr-xr-x 0 0 3817-128-3 /WINDOWS/system32/dllcache/msn9.cat 144484 ..c. r/rr-xr-xr-x 0 0 3818-128-3 /WINDOWS/system32/dllcache/netfx.cat 2608 ..c. r/rr-xr-xr-x 0 0 3819-128-3 /WINDOWS/inf/SVCPACK.PNF 4320 ..c. r/rr-xr-xr-x 0 0 382-128-3 /WINDOWS/Fonts/cga80850.fon 152 .a.. d/drwxrwxrwx 0 0 3821-144-1 /Documents and Settings/Default User/Cookies 48 .ac. d/dr-xr-xr-x 0 0 3822-144-1 /Documents and Settings/Default User/Desktop 48 .ac. d/dr-xr-xr-x 0 0 3823-144-1 /Documents and Settings/Default User/Favorites 48 .ac. d/dr-xr-xr-x 0 0 3824-144-1 /Documents and Settings/Default User/NetHood 48 .ac. d/dr-xr-xr-x 0 0 3825-144-1 /Documents and Settings/Default User/My Documents 48 .ac. d/dr-xr-xr-x 0 0 3826-144-1 /Documents and Settings/Default User/PrintHood 48 .ac. d/dr-xr-xr-x 0 0 3827-144-1 /Documents and Settings/Default User/Recent 56 .ac. d/d--x--x--x 0 0 3828-144-5 /Documents and Settings/Default User/SendTo 256 .ac. d/d--x--x--x 0 0 3829-144-1 /Documents and Settings/Default User/Start Menu 56 .ac. d/dr-xr-xr-x 0 0 3831-144-6 /Documents and Settings/Default User/Templates 56 .ac. d/d--x--x--x 0 0 3832-144-5 /Documents and Settings/Default User/Start Menu/Programs 152 .ac. d/d--x--x--x 0 0 3834-144-1 /Documents and Settings/Default User/Start Menu/Programs/Startup 56 .ac. d/d--x--x--x 0 0 3836-144-6 /Documents and Settings/Default User/Local Settings 256 .ac. d/dr-xr-xr-x 0 0 3838-144-1 /Documents and Settings/Default User/Local Settings/Application Data 256 .a.. d/drwxrwxrwx 0 0 3839-144-1 /Documents and Settings/Default User/Local Settings/Temporary Internet Files 256 .a.. d/drwxrwxrwx 0 0 3840-144-1 /Documents and Settings/Default User/Local Settings/History 48 .ac. d/dr-xr-xr-x 0 0 3841-144-1 /Documents and Settings/Default User/Local Settings/Temp 48 ..c. d/dr-xr-xr-x 0 0 3842-144-1 /Documents and Settings/All Users/Desktop 56 .ac. d/d--x--x--x 0 0 3843-144-6 /Documents and Settings/All Users/Start Menu 56 .ac. d/d--x--x--x 0 0 3845-144-5 /Documents and Settings/All Users/Start Menu/Programs 48 .ac. d/d--x--x--x 0 0 3847-144-1 /Documents and Settings/All Users/Start Menu/Programs/Startup 48 .ac. d/dr-xr-xr-x 0 0 3850-144-1 /Documents and Settings/All Users/Templates 48 .ac. d/dr-xr-xr-x 0 0 3851-144-1 /Documents and Settings/All Users/Favorites 56 .ac. d/d--x--x--x 0 0 3852-144-6 /Documents and Settings/All Users/Documents 222468 ..c. r/rr-xr-xr-x 0 0 3854-128-3 /WINDOWS/inf/drvindex.PNF 16576 ..c. r/rr-xr-xr-x 0 0 3855-128-3 /WINDOWS/inf/1394.PNF 7800 ..c. r/rr-xr-xr-x 0 0 3856-128-3 /WINDOWS/inf/certclas.PNF 5596 ..c. r/rr-xr-xr-x 0 0 3857-128-3 /WINDOWS/inf/1394vdbg.PNF 7256 ..c. r/rr-xr-xr-x 0 0 3858-128-3 /WINDOWS/inf/61883.PNF 9548 ..c. r/rr-xr-xr-x 0 0 3859-128-3 /WINDOWS/inf/avc.PNF 13312 ..c. r/rr-xr-xr-x 0 0 3860-128-3 /WINDOWS/inf/battery.PNF 25780 ..c. r/rr-xr-xr-x 0 0 3861-128-3 /WINDOWS/inf/bth.PNF 56516 ..c. r/rr-xr-xr-x 0 0 3862-128-3 /WINDOWS/inf/cdrom.PNF 16972 ..c. r/rr-xr-xr-x 0 0 3863-128-3 /WINDOWS/inf/cpu.PNF 6092 ..c. r/rr-xr-xr-x 0 0 3864-128-3 /WINDOWS/inf/enum1394.PNF 11404 ..c. r/rr-xr-xr-x 0 0 3865-128-3 /WINDOWS/inf/flash.PNF 12136 ..c. r/rr-xr-xr-x 0 0 3866-128-3 /WINDOWS/inf/disk.PNF 53980 ..c. r/rr-xr-xr-x 0 0 3867-128-3 /WINDOWS/inf/display.PNF 68016 ..c. r/rr-xr-xr-x 0 0 3868-128-3 /WINDOWS/inf/dot4.PNF 6460 ..c. r/rr-xr-xr-x 0 0 3869-128-3 /WINDOWS/inf/dot4prt.PNF 11797 ..c. r/rr-xr-xr-x 0 0 387-128-3 /WINDOWS/Help/chnscsvr.hlp 7940 ..c. r/rr-xr-xr-x 0 0 3870-128-3 /WINDOWS/inf/fdc.PNF 8480 ..c. r/rr-xr-xr-x 0 0 3871-128-3 /WINDOWS/inf/flpydisk.PNF 5844 ..c. r/rr-xr-xr-x 0 0 3872-128-3 /WINDOWS/inf/genprint.PNF 11468 ..c. r/rr-xr-xr-x 0 0 3873-128-3 /WINDOWS/inf/hal.PNF 108916 ..c. r/rr-xr-xr-x 0 0 3874-128-3 /WINDOWS/inf/input.PNF 67708 ..c. r/rr-xr-xr-x 0 0 3875-128-3 /WINDOWS/inf/keyboard.PNF 3924 ..c. r/rr-xr-xr-x 0 0 3876-128-3 /WINDOWS/inf/legcydrv.PNF 187380 ..c. r/rr-xr-xr-x 0 0 3877-128-3 /WINDOWS/inf/machine.PNF 30564 ..c. r/rr-xr-xr-x 0 0 3878-128-3 /WINDOWS/inf/mchgr.PNF 4000 ..c. r/rr-xr-xr-x 0 0 3879-128-3 /WINDOWS/inf/mdmsetup.PNF 11288 ..c. r/rr-xr-xr-x 0 0 388-128-3 /WINDOWS/Help/chooser.hlp 5592 ..c. r/rr-xr-xr-x 0 0 3880-128-3 /WINDOWS/inf/mf.PNF 108188 ..c. r/rr-xr-xr-x 0 0 3881-128-3 /WINDOWS/inf/monitor.PNF 49540 ..c. r/rr-xr-xr-x 0 0 3882-128-3 /WINDOWS/inf/mshdc.PNF 63112 ..c. r/rr-xr-xr-x 0 0 3883-128-3 /WINDOWS/inf/msmouse.PNF 30232 ..c. r/rr-xr-xr-x 0 0 3884-128-3 /WINDOWS/inf/msports.PNF 5836 ..c. r/rr-xr-xr-x 0 0 3885-128-3 /WINDOWS/inf/multiprt.PNF 6660 ..c. r/rr-xr-xr-x 0 0 3886-128-3 /WINDOWS/inf/ntapm.PNF 3696 ..c. r/rr-xr-xr-x 0 0 3887-128-3 /WINDOWS/inf/netclass.PNF 24424 ..c. r/rr-xr-xr-x 0 0 3888-128-3 /WINDOWS/inf/netirsir.PNF 1317388 ..c. r/rr-xr-xr-x 0 0 3889-128-3 /WINDOWS/inf/ntprint.PNF 45772 ..c. r/rr-xr-xr-x 0 0 3890-128-3 /WINDOWS/inf/pcmcia.PNF 105552 ..c. r/rr-xr-xr-x 0 0 3891-128-3 /WINDOWS/inf/pnpscsi.PNF 6464 ..c. r/rr-xr-xr-x 0 0 3892-128-3 /WINDOWS/inf/sbp2.PNF 21944 ..c. r/rr-xr-xr-x 0 0 3893-128-3 /WINDOWS/inf/scsi.PNF 10732 ..c. r/rr-xr-xr-x 0 0 3894-128-3 /WINDOWS/inf/sdbus.PNF 36372 ..c. r/rr-xr-xr-x 0 0 3895-128-3 /WINDOWS/inf/smartcrd.PNF 27832 ..c. r/rr-xr-xr-x 0 0 3896-128-3 /WINDOWS/inf/sti.PNF 59804 ..c. r/rr-xr-xr-x 0 0 3897-128-3 /WINDOWS/inf/tape.PNF 44496 ..c. r/rr-xr-xr-x 0 0 3898-128-3 /WINDOWS/inf/usb.PNF 44896 ..c. r/rr-xr-xr-x 0 0 3899-128-3 /WINDOWS/inf/wdmaudio.PNF 315 ..c. r/rr-xr-xr-x 0 0 390-128-1 /WINDOWS/Help/ciadmin.htm 4816 ..c. r/rr-xr-xr-x 0 0 3900-128-3 /WINDOWS/inf/volume.PNF 4964 ..c. r/rr-xr-xr-x 0 0 3901-128-3 /WINDOWS/inf/volsnap.PNF 11944 ..c. r/rr-xr-xr-x 0 0 3902-128-3 /WINDOWS/inf/wceusbsh.PNF 8932 ..c. r/rr-xr-xr-x 0 0 3903-128-3 /WINDOWS/inf/memstpci.PNF 54832 ..c. r/rr-xr-xr-x 0 0 3904-128-3 /WINDOWS/inf/mwtpdsp.PNF 68768 ..c. r/rr-xr-xr-x 0 0 3907-128-3 /WINDOWS/system/MMSYSTEM.DLL 146432 ..c. r/rr-xr-xr-x 0 0 3908-128-3 /WINDOWS/system/WINSPOOL.DRV 11264 ..c. r/rr-xr-xr-x 0 0 3910-128-3 /WINDOWS/system32/drivers/irenum.sys 69584 ..c. r/rr-xr-xr-x 0 0 3914-128-3 /WINDOWS/system/AVICAP.DLL 109456 ..c. r/rr-xr-xr-x 0 0 3915-128-3 /WINDOWS/system/AVIFILE.DLL 32816 ..c. r/rr-xr-xr-x 0 0 3916-128-3 /WINDOWS/system/COMMDLG.DLL 9936 ..c. r/rr-xr-xr-x 0 0 3917-128-3 /WINDOWS/system/LZEXPAND.DLL 2000 ..c. r/rr-xr-xr-x 0 0 3918-128-3 /WINDOWS/system/KEYBOARD.DRV 73376 ..c. r/rr-xr-xr-x 0 0 3919-128-3 /WINDOWS/system/MCIAVI.DRV 25264 ..c. r/rr-xr-xr-x 0 0 3920-128-3 /WINDOWS/system/MCISEQ.DRV 28160 ..c. r/rr-xr-xr-x 0 0 3921-128-3 /WINDOWS/system/MCIWAVE.DRV 1152 ..c. r/rr-xr-xr-x 0 0 3922-128-3 /WINDOWS/system/MMTASK.TSK 2032 ..c. r/rr-xr-xr-x 0 0 3923-128-3 /WINDOWS/system/MOUSE.DRV 126912 ..c. r/rr-xr-xr-x 0 0 3924-128-3 /WINDOWS/system/MSVIDEO.DLL 82944 ..c. r/rr-xr-xr-x 0 0 3925-128-3 /WINDOWS/system/OLECLI.DLL 24064 ..c. r/rr-xr-xr-x 0 0 3926-128-3 /WINDOWS/system/OLESVR.DLL 5120 ..c. r/rr-xr-xr-x 0 0 3927-128-3 /WINDOWS/system/SHELL.DLL 1744 ..c. r/rr-xr-xr-x 0 0 3928-128-3 /WINDOWS/system/SOUND.DRV 3360 ..c. r/rr-xr-xr-x 0 0 3929-128-3 /WINDOWS/system/SYSTEM.DRV 262528 ..c. r/rr-xr-xr-x 0 0 393-128-3 /WINDOWS/system32/drivers/cinemst2.sys 19200 ..c. r/rr-xr-xr-x 0 0 3930-128-3 /WINDOWS/system/TAPI.DLL 4048 ..c. r/rr-xr-xr-x 0 0 3931-128-3 /WINDOWS/system/TIMER.DRV 9008 ..c. r/rr-xr-xr-x 0 0 3932-128-3 /WINDOWS/system/VER.DLL 2176 ..c. r/rr-xr-xr-x 0 0 3933-128-3 /WINDOWS/system/VGA.DRV 13600 ..c. r/rr-xr-xr-x 0 0 3934-128-3 /WINDOWS/system/WFWNET.DRV 21352 ..c. r/rr-xr-xr-x 0 0 394-128-3 /WINDOWS/Help/ciquery.htm 432252 ..c. r/rr-xr-xr-x 0 0 3940-128-3 /WINDOWS/inf/intl.PNF 10976 ..c. r/rr-xr-xr-x 0 0 3942-128-3 /WINDOWS/Fonts/8514fix.fon 12288 ..c. r/rr-xr-xr-x 0 0 3943-128-3 /WINDOWS/Fonts/8514oem.fon 9280 ..c. r/rr-xr-xr-x 0 0 3944-128-3 /WINDOWS/Fonts/8514sys.fon 36672 ..c. r/rr-xr-xr-x 0 0 3945-128-3 /WINDOWS/Fonts/app850.fon 21504 ..c. r/rr-xr-xr-x 0 0 3946-128-3 /WINDOWS/Fonts/smallf.fon 5184 ..c. r/rr-xr-xr-x 0 0 3947-128-3 /WINDOWS/Fonts/vga860.fon 5200 ..c. r/rr-xr-xr-x 0 0 3948-128-3 /WINDOWS/Fonts/vga863.fon 5184 ..c. r/rr-xr-xr-x 0 0 3949-128-3 /WINDOWS/Fonts/vga865.fon 62236 ..c. r/rr-xr-xr-x 0 0 3950-128-3 /WINDOWS/inf/font.PNF 10976 ..c. r/rr-xr-xr-x 0 0 3969-128-3 /WINDOWS/Fonts/8514fixe.fon 3025 ..c. r/rr-xr-xr-x 0 0 397-128-3 /WINDOWS/Resources/Themes/Windows Classic.theme 13248 ..c. r/rr-xr-xr-x 0 0 3970-128-3 /WINDOWS/Fonts/8514oeme.fon 9504 ..c. r/rr-xr-xr-x 0 0 3971-128-3 /WINDOWS/Fonts/8514syse.fon 36656 ..c. r/rr-xr-xr-x 0 0 3972-128-3 /WINDOWS/Fonts/app852.fon 6672 ..c. r/rr-xr-xr-x 0 0 3973-128-3 /WINDOWS/Fonts/cga40852.fon 5200 ..c. r/rr-xr-xr-x 0 0 3974-128-3 /WINDOWS/Fonts/cga80852.fon 23440 ..c. r/rr-xr-xr-x 0 0 3975-128-3 /WINDOWS/Fonts/couree.fon 31776 ..c. r/rr-xr-xr-x 0 0 3976-128-3 /WINDOWS/Fonts/courfe.fon 8368 ..c. r/rr-xr-xr-x 0 0 3977-128-3 /WINDOWS/Fonts/ega40852.fon 5344 ..c. r/rr-xr-xr-x 0 0 3978-128-3 /WINDOWS/Fonts/ega80852.fon 59952 ..c. r/rr-xr-xr-x 0 0 3979-128-3 /WINDOWS/Fonts/serifee.fon 85360 ..c. r/rr-xr-xr-x 0 0 3980-128-3 /WINDOWS/Fonts/seriffe.fon 24784 ..c. r/rr-xr-xr-x 0 0 3981-128-3 /WINDOWS/Fonts/smallee.fon 19600 ..c. r/rr-xr-xr-x 0 0 3982-128-3 /WINDOWS/Fonts/smallfe.fon 66464 ..c. r/rr-xr-xr-x 0 0 3983-128-3 /WINDOWS/Fonts/sserifee.fon 92032 ..c. r/rr-xr-xr-x 0 0 3984-128-3 /WINDOWS/Fonts/sseriffe.fon 6160 ..c. r/rr-xr-xr-x 0 0 3985-128-3 /WINDOWS/Fonts/vga852.fon 5376 ..c. r/rr-xr-xr-x 0 0 3986-128-3 /WINDOWS/Fonts/vgafixe.fon 6608 ..c. r/rr-xr-xr-x 0 0 3987-128-3 /WINDOWS/Fonts/vgasyse.fon 12304 ..c. r/rr-xr-xr-x 0 0 3996-128-3 /WINDOWS/Fonts/85775.fon 10976 ..c. r/rr-xr-xr-x 0 0 3997-128-3 /WINDOWS/Fonts/85f1257.fon 9472 ..c. r/rr-xr-xr-x 0 0 3998-128-3 /WINDOWS/Fonts/85s1257.fon 35808 ..c. r/rr-xr-xr-x 0 0 3999-128-3 /WINDOWS/Fonts/app775.fon 25129 ..c. r/rr-xr-xr-x 0 0 400-128-3 /WINDOWS/Help/clipbrd.chm 23440 ..c. r/rr-xr-xr-x 0 0 4000-128-3 /WINDOWS/Fonts/coue1257.fon 31760 ..c. r/rr-xr-xr-x 0 0 4001-128-3 /WINDOWS/Fonts/couf1257.fon 59024 ..c. r/rr-xr-xr-x 0 0 4002-128-3 /WINDOWS/Fonts/sere1257.fon 84080 ..c. r/rr-xr-xr-x 0 0 4003-128-3 /WINDOWS/Fonts/serf1257.fon 24672 ..c. r/rr-xr-xr-x 0 0 4004-128-3 /WINDOWS/Fonts/smae1257.fon 19904 ..c. r/rr-xr-xr-x 0 0 4005-128-3 /WINDOWS/Fonts/smaf1257.fon 65456 ..c. r/rr-xr-xr-x 0 0 4006-128-3 /WINDOWS/Fonts/ssee1257.fon 90336 ..c. r/rr-xr-xr-x 0 0 4007-128-3 /WINDOWS/Fonts/ssef1257.fon 5168 ..c. r/rr-xr-xr-x 0 0 4008-128-3 /WINDOWS/Fonts/vga775.fon 5376 ..c. r/rr-xr-xr-x 0 0 4009-128-3 /WINDOWS/Fonts/vgaf1257.fon 45445 ..c. r/rr-xr-xr-x 0 0 401-128-3 /WINDOWS/Help/clipbrd.hlp 6656 ..c. r/rr-xr-xr-x 0 0 4010-128-3 /WINDOWS/Fonts/vgas1257.fon 96877 ..c. r/rr-xr-xr-x 0 0 402-128-3 /WINDOWS/Help/cmconcepts.chm 11520 ..c. r/rr-xr-xr-x 0 0 4023-128-3 /WINDOWS/Fonts/8514fixg.fon 12800 ..c. r/rr-xr-xr-x 0 0 4024-128-3 /WINDOWS/Fonts/8514oemg.fon 9856 ..c. r/rr-xr-xr-x 0 0 4025-128-3 /WINDOWS/Fonts/8514sysg.fon 7216 ..c. r/rr-xr-xr-x 0 0 4026-128-3 /WINDOWS/Fonts/cga40737.fon 7216 ..c. r/rr-xr-xr-x 0 0 4027-128-3 /WINDOWS/Fonts/cga40869.fon 5168 ..c. r/rr-xr-xr-x 0 0 4028-128-3 /WINDOWS/Fonts/cga80737.fon 5168 ..c. r/rr-xr-xr-x 0 0 4029-128-3 /WINDOWS/Fonts/cga80869.fon 25024 ..c. r/rr-xr-xr-x 0 0 4030-128-3 /WINDOWS/Fonts/coureg.fon 33344 ..c. r/rr-xr-xr-x 0 0 4031-128-3 /WINDOWS/Fonts/courfg.fon 36336 ..c. r/rr-xr-xr-x 0 0 4032-128-3 /WINDOWS/Fonts/dos737.fon 9248 ..c. r/rr-xr-xr-x 0 0 4033-128-3 /WINDOWS/Fonts/ega40737.fon 9248 ..c. r/rr-xr-xr-x 0 0 4034-128-3 /WINDOWS/Fonts/ega40869.fon 6192 ..c. r/rr-xr-xr-x 0 0 4035-128-3 /WINDOWS/Fonts/ega80737.fon 6192 ..c. r/rr-xr-xr-x 0 0 4036-128-3 /WINDOWS/Fonts/ega80869.fon 60752 ..c. r/rr-xr-xr-x 0 0 4037-128-3 /WINDOWS/Fonts/serifeg.fon 86256 ..c. r/rr-xr-xr-x 0 0 4038-128-3 /WINDOWS/Fonts/seriffg.fon 28912 ..c. r/rr-xr-xr-x 0 0 4039-128-3 /WINDOWS/Fonts/smalleg.fon 23120 ..c. r/rr-xr-xr-x 0 0 4040-128-3 /WINDOWS/Fonts/smallfg.fon 65328 ..c. r/rr-xr-xr-x 0 0 4041-128-3 /WINDOWS/Fonts/sserifeg.fon 90288 ..c. r/rr-xr-xr-x 0 0 4042-128-3 /WINDOWS/Fonts/sseriffg.fon 5168 ..c. r/rr-xr-xr-x 0 0 4043-128-3 /WINDOWS/Fonts/vga737.fon 5184 ..c. r/rr-xr-xr-x 0 0 4044-128-3 /WINDOWS/Fonts/vga869.fon 6112 ..c. r/rr-xr-xr-x 0 0 4045-128-3 /WINDOWS/Fonts/vgafixg.fon 7008 ..c. r/rr-xr-xr-x 0 0 4046-128-3 /WINDOWS/Fonts/vgasysg.fon 10976 ..c. r/rr-xr-xr-x 0 0 4062-128-3 /WINDOWS/Fonts/8514fixr.fon 13200 ..c. r/rr-xr-xr-x 0 0 4063-128-3 /WINDOWS/Fonts/8514oemr.fon 10064 ..c. r/rr-xr-xr-x 0 0 4064-128-3 /WINDOWS/Fonts/8514sysr.fon 12256 ..c. r/rr-xr-xr-x 0 0 4065-128-3 /WINDOWS/Fonts/85855.fon 37296 ..c. r/rr-xr-xr-x 0 0 4066-128-3 /WINDOWS/Fonts/app855.fon 37472 ..c. r/rr-xr-xr-x 0 0 4067-128-3 /WINDOWS/Fonts/app866.fon 7232 ..c. r/rr-xr-xr-x 0 0 4068-128-3 /WINDOWS/Fonts/cga40866.fon 5168 ..c. r/rr-xr-xr-x 0 0 4069-128-3 /WINDOWS/Fonts/cga80866.fon 5854 ..c. r/rr-xr-xr-x 0 0 407-128-3 /WINDOWS/system32/icsxml/cmnicfg.xml 23440 ..c. r/rr-xr-xr-x 0 0 4070-128-3 /WINDOWS/Fonts/courer.fon 31808 ..c. r/rr-xr-xr-x 0 0 4071-128-3 /WINDOWS/Fonts/courfr.fon 9232 ..c. r/rr-xr-xr-x 0 0 4072-128-3 /WINDOWS/Fonts/ega40866.fon 5280 ..c. r/rr-xr-xr-x 0 0 4073-128-3 /WINDOWS/Fonts/ega80866.fon 63296 ..c. r/rr-xr-xr-x 0 0 4074-128-3 /WINDOWS/Fonts/serifer.fon 90736 ..c. r/rr-xr-xr-x 0 0 4075-128-3 /WINDOWS/Fonts/seriffr.fon 24832 ..c. r/rr-xr-xr-x 0 0 4076-128-3 /WINDOWS/Fonts/smaller.fon 19760 ..c. r/rr-xr-xr-x 0 0 4077-128-3 /WINDOWS/Fonts/smallfr.fon 68848 ..c. r/rr-xr-xr-x 0 0 4078-128-3 /WINDOWS/Fonts/sserifer.fon 98256 ..c. r/rr-xr-xr-x 0 0 4079-128-3 /WINDOWS/Fonts/sseriffr.fon 5120 ..c. r/rr-xr-xr-x 0 0 4080-128-3 /WINDOWS/Fonts/vga855.fon 6128 ..c. r/rr-xr-xr-x 0 0 4081-128-3 /WINDOWS/Fonts/vga866.fon 5600 ..c. r/rr-xr-xr-x 0 0 4082-128-3 /WINDOWS/Fonts/vgafixr.fon 6912 ..c. r/rr-xr-xr-x 0 0 4083-128-3 /WINDOWS/Fonts/vgasysr.fon 11488 ..c. r/rr-xr-xr-x 0 0 4090-128-3 /WINDOWS/Fonts/8514fixt.fon 12720 ..c. r/rr-xr-xr-x 0 0 4091-128-3 /WINDOWS/Fonts/8514oemt.fon 9792 ..c. r/rr-xr-xr-x 0 0 4092-128-3 /WINDOWS/Fonts/8514syst.fon 36672 ..c. r/rr-xr-xr-x 0 0 4093-128-3 /WINDOWS/Fonts/app857.fon 6672 ..c. r/rr-xr-xr-x 0 0 4094-128-3 /WINDOWS/Fonts/cga40857.fon 4640 ..c. r/rr-xr-xr-x 0 0 4095-128-3 /WINDOWS/Fonts/cga80857.fon 25024 ..c. r/rr-xr-xr-x 0 0 4096-128-3 /WINDOWS/Fonts/couret.fon 33360 ..c. r/rr-xr-xr-x 0 0 4097-128-3 /WINDOWS/Fonts/courft.fon 8704 ..c. r/rr-xr-xr-x 0 0 4098-128-3 /WINDOWS/Fonts/ega40857.fon 5648 ..c. r/rr-xr-xr-x 0 0 4099-128-3 /WINDOWS/Fonts/ega80857.fon 48 .a.. d/dr-xr-xr-x 0 0 41-144-1 /WINDOWS/system32/dhcp 20549 ..c. r/rr-xr-xr-x 0 0 410-128-3 /WINDOWS/Help/colormgt.chm 61024 ..c. r/rr-xr-xr-x 0 0 4100-128-3 /WINDOWS/Fonts/serifet.fon 84848 ..c. r/rr-xr-xr-x 0 0 4101-128-3 /WINDOWS/Fonts/serifft.fon 29200 ..c. r/rr-xr-xr-x 0 0 4102-128-3 /WINDOWS/Fonts/smallet.fon 23008 ..c. r/rr-xr-xr-x 0 0 4103-128-3 /WINDOWS/Fonts/smallft.fon 64400 ..c. r/rr-xr-xr-x 0 0 4104-128-3 /WINDOWS/Fonts/sserifet.fon 89456 ..c. r/rr-xr-xr-x 0 0 4105-128-3 /WINDOWS/Fonts/sserifft.fon 5552 ..c. r/rr-xr-xr-x 0 0 4106-128-3 /WINDOWS/Fonts/vga857.fon 6112 ..c. r/rr-xr-xr-x 0 0 4107-128-3 /WINDOWS/Fonts/vgafixt.fon 6912 ..c. r/rr-xr-xr-x 0 0 4108-128-3 /WINDOWS/Fonts/vgasyst.fon 19456 ..c. r/rr-xr-xr-x 0 0 4109-128-3 /WINDOWS/msagent/intl/agt0405.dll 19968 ..c. r/rr-xr-xr-x 0 0 4110-128-3 /WINDOWS/msagent/intl/agt040e.dll 19456 ..c. r/rr-xr-xr-x 0 0 4111-128-3 /WINDOWS/msagent/intl/agt0415.dll 8975 ..c. r/rr-xr-xr-x 0 0 4112-128-3 /WINDOWS/Help/agt0405.hlp 8987 ..c. r/rr-xr-xr-x 0 0 4113-128-3 /WINDOWS/Help/agt040e.hlp 8917 ..c. r/rr-xr-xr-x 0 0 4114-128-3 /WINDOWS/Help/agt0415.hlp 22016 ..c. r/rr-xr-xr-x 0 0 4116-128-3 /WINDOWS/msagent/intl/agt0408.dll 9001 ..c. r/rr-xr-xr-x 0 0 4117-128-3 /WINDOWS/Help/agt0408.hlp 19456 ..c. r/rr-xr-xr-x 0 0 4118-128-3 /WINDOWS/msagent/intl/agt0419.dll 8799 ..c. r/rr-xr-xr-x 0 0 4119-128-3 /WINDOWS/Help/agt0419.hlp 19456 ..c. r/rr-xr-xr-x 0 0 4120-128-3 /WINDOWS/msagent/intl/agt041f.dll 9041 ..c. r/rr-xr-xr-x 0 0 4121-128-3 /WINDOWS/Help/agt041f.hlp 139136 ..c. r/rr-xr-xr-x 0 0 4122-128-3 /WINDOWS/inf/sapi5.PNF 56 .a.. d/d--x--x--x 0 0 4123-144-6 /Program Files 56 .ac. d/dr-xr-xr-x 0 0 4124-144-6 /Program Files/Common Files 56 .ac. d/dr-xr-xr-x 0 0 4125-144-6 /Program Files/Common Files/Microsoft Shared 456 .ac. d/dr-xr-xr-x 0 0 4126-144-1 /Program Files/Common Files/Microsoft Shared/Speech 741376 ..c. r/rr-xr-xr-x 0 0 4127-128-3 /Program Files/Common Files/Microsoft Shared/Speech/sapi.dll 155648 ..c. r/rr-xr-xr-x 0 0 4128-128-3 /Program Files/Common Files/Microsoft Shared/Speech/sapi.cpl 36864 ..c. r/rr-xr-xr-x 0 0 4129-128-3 /Program Files/Common Files/Microsoft Shared/Speech/sapisvr.exe 256 .ac. d/dr-xr-xr-x 0 0 4130-144-1 /Program Files/Common Files/SpeechEngines 344 .ac. d/dr-xr-xr-x 0 0 4131-144-1 /Program Files/Common Files/SpeechEngines/Microsoft 144 .ac. d/dr-xr-xr-x 0 0 4132-144-1 /Program Files/Common Files/SpeechEngines/Microsoft/Lexicon 272 .ac. d/dr-xr-xr-x 0 0 4133-144-1 /Program Files/Common Files/SpeechEngines/Microsoft/Lexicon/1033 643717 ..c. r/rr-xr-xr-x 0 0 4134-128-3 /Program Files/Common Files/SpeechEngines/Microsoft/Lexicon/1033/ltts1033.lxa 605050 ..c. r/rr-xr-xr-x 0 0 4135-128-3 /Program Files/Common Files/SpeechEngines/Microsoft/Lexicon/1033/r1033tts.lxa 144 .ac. d/dr-xr-xr-x 0 0 4136-144-1 /Program Files/Common Files/SpeechEngines/Microsoft/TTS 352 .ac. d/dr-xr-xr-x 0 0 4137-144-1 /Program Files/Common Files/SpeechEngines/Microsoft/TTS/1033 774144 ..c. r/rr-xr-xr-x 0 0 4138-128-3 /Program Files/Common Files/SpeechEngines/Microsoft/TTS/1033/spttseng.dll 888 ..c. r/rr-xr-xr-x 0 0 4139-128-3 /Program Files/Common Files/SpeechEngines/Microsoft/TTS/1033/sam.sdf 1685606 ..c. r/rr-xr-xr-x 0 0 4140-128-3 /Program Files/Common Files/SpeechEngines/Microsoft/TTS/1033/sam.spd 77824 ..c. r/rr-xr-xr-x 0 0 4141-128-3 /Program Files/Common Files/SpeechEngines/Microsoft/spcommon.dll 152 .ac. d/dr-xr-xr-x 0 0 4142-144-1 /Program Files/Common Files/Microsoft Shared/Speech/1033 61440 ..c. r/rr-xr-xr-x 0 0 4143-128-3 /Program Files/Common Files/Microsoft Shared/Speech/1033/spcplui.dll 264 .ac. d/dr-xr-xr-x 0 0 4144-144-1 /Program Files/Common Files/ODBC 48 .ac. d/dr-xr-xr-x 0 0 4145-144-1 /Program Files/Common Files/ODBC/Data Sources 7356 ..c. r/rr-xr-xr-x 0 0 4148-128-3 /WINDOWS/inf/SYSOC.PNF 17081 ..c. r/rr-xr-xr-x 0 0 415-128-3 /WINDOWS/Help/common.chm 2916 ..c. r/rr-xr-xr-x 0 0 4150-128-3 /WINDOWS/inf/koc.PNF 14228 ..c. r/rr-xr-xr-x 0 0 4151-128-3 /WINDOWS/inf/wbemoc.PNF 55728 ..c. r/rr-xr-xr-x 0 0 4153-128-3 /WINDOWS/inf/fxsocm.PNF 16448 ..c. r/rr-xr-xr-x 0 0 4155-128-3 /WINDOWS/inf/netoc.PNF 971036 ..c. r/rr-xr-xr-x 0 0 4156-128-3 /WINDOWS/inf/iis.PNF 134788 ..c. r/rr-xr-xr-x 0 0 4158-128-3 /WINDOWS/inf/comnt5.PNF 8842 ..c. r/rr-xr-xr-x 0 0 416-128-3 /WINDOWS/inf/communic.inf 10240 ..c. r/rr-xr-xr-x 0 0 4160-128-3 /WINDOWS/inf/dtcnt5.PNF 41164 ..c. r/rr-xr-xr-x 0 0 4162-128-3 /WINDOWS/inf/setupqry.PNF 131204 ..c. r/rr-xr-xr-x 0 0 4163-128-3 /WINDOWS/inf/tsoc.PNF 13592 ..c. r/rr-xr-xr-x 0 0 4165-128-3 /WINDOWS/inf/msmqocm.PNF 105208 ..c. r/rr-xr-xr-x 0 0 4167-128-3 /WINDOWS/inf/ims.PNF 17568 ..c. r/rr-xr-xr-x 0 0 4169-128-3 /WINDOWS/inf/fp40ext.PNF 87456 ..c. r/rr-xr-xr-x 0 0 4170-128-3 /WINDOWS/inf/msmsgs.PNF 4056 ..c. r/rr-xr-xr-x 0 0 4172-128-3 /WINDOWS/inf/wmaccess.PNF 3932 ..c. r/rr-xr-xr-x 0 0 4173-128-3 /WINDOWS/inf/rootau.PNF 4464 ..c. r/rr-xr-xr-x 0 0 4174-128-3 /WINDOWS/inf/ieaccess.PNF 4384 ..c. r/rr-xr-xr-x 0 0 4175-128-3 /WINDOWS/inf/oeaccess.PNF 4408 ..c. r/rr-xr-xr-x 0 0 4176-128-3 /WINDOWS/inf/wmpocm.PNF 15092 ..c. r/rr-xr-xr-x 0 0 4177-128-3 /WINDOWS/inf/games.PNF 48316 ..c. r/rr-xr-xr-x 0 0 4178-128-3 /WINDOWS/inf/accessor.PNF 17476 ..c. r/rr-xr-xr-x 0 0 4179-128-3 /WINDOWS/inf/communic.PNF 11984 ..c. r/rr-xr-xr-x 0 0 4180-128-3 /WINDOWS/inf/multimed.PNF 21688 ..c. r/rr-xr-xr-x 0 0 4181-128-3 /WINDOWS/inf/optional.PNF 12368 ..c. r/rr-xr-xr-x 0 0 4182-128-3 /WINDOWS/inf/pinball.PNF 16656 ..c. r/rr-xr-xr-x 0 0 4183-128-3 /WINDOWS/inf/wordpad.PNF 13260 ..c. r/rr-xr-xr-x 0 0 4184-128-3 /WINDOWS/inf/igames.PNF 558428 ..c. r/rr-xr-xr-x 0 0 4185-128-3 /WINDOWS/inf/tabletpc.PNF 106528 ..c. r/rr-xr-xr-x 0 0 4187-128-3 /WINDOWS/inf/medctroc.PNF 174876 ..c. r/rr-xr-xr-x 0 0 4189-128-3 /WINDOWS/inf/netfxocm.PNF 67884 ..c. r/rr-xr-xr-x 0 0 419-128-3 /WINDOWS/security/templates/compatws.inf 9492 ..c. r/rr-xr-xr-x 0 0 4191-128-3 /WINDOWS/inf/msnmsn.PNF 20116 ..c. r/rr-xr-xr-x 0 0 4193-128-3 /WINDOWS/inf/netsnmp.PNF 6928 ..c. r/rr-xr-xr-x 0 0 4194-128-3 /WINDOWS/inf/wbemsnmp.PNF 10732 ..c. r/rr-xr-xr-x 0 0 4195-128-3 /WINDOWS/inf/nettpsmp.PNF 4004 ..c. r/rr-xr-xr-x 0 0 4196-128-3 /WINDOWS/inf/netupnp.PNF 3652 ..c. r/rr-xr-xr-x 0 0 4197-128-3 /WINDOWS/inf/netbeac.PNF 6216 ..c. r/rr-xr-xr-x 0 0 4198-128-3 /WINDOWS/inf/netiprip.PNF 14492 ..c. r/rr-xr-xr-x 0 0 4199-128-3 /WINDOWS/inf/p2p.PNF 56 .a.. d/dr-xr-xr-x 0 0 42-144-5 /WINDOWS/repair 10412 ..c. r/rr-xr-xr-x 0 0 4200-128-3 /WINDOWS/inf/netlpd.PNF 326568 ..c. r/rr-xr-xr-x 0 0 4201-128-3 /WINDOWS/inf/defltwk.PNF 1048576 ..c. r/rr-xr-xr-x 0 0 4202-128-3 /WINDOWS/security/edb.log 1048576 ..c. r/rr-xr-xr-x 0 0 4203-128-3 /WINDOWS/security/edb00002.log 1048576 ..c. r/rr-xr-xr-x 0 0 4204-128-3 /WINDOWS/security/res2.log 1048576 ..c. r/rr-xr-xr-x 0 0 4205-128-3 /WINDOWS/security/res1.log 8192 ..c. r/rr-xr-xr-x 0 0 4207-128-3 /WINDOWS/security/edb.chk 423518 ..c. r/rr-xr-xr-x 0 0 4208-128-3 /WINDOWS/security/logs/scesetup.log 152 .ac. d/dr-xr-xr-x 0 0 4209-144-1 /WINDOWS/security/Database 19921 ..c. r/rr-xr-xr-x 0 0 421-128-3 /WINDOWS/Help/compmgmt.chm 3153920 ..c. r/rr-xr-xr-x 0 0 4210-128-3 /WINDOWS/security/Database/secedit.sdb 833624 ..c. r/rr-xr-xr-x 0 0 4212-128-5 /WINDOWS/security/templates/setup security.inf 588 ..c. r/rr-xr-xr-x 0 0 4213-128-1 /WINDOWS/security/logs/SceRoot.log 9936 ..c. r/rr-xr-xr-x 0 0 4214-128-3 /WINDOWS/inf/xscan_xp.PNF 8892 ..c. r/rr-xr-xr-x 0 0 4215-128-3 /WINDOWS/inf/wtv5.PNF 8892 ..c. r/rr-xr-xr-x 0 0 4216-128-3 /WINDOWS/inf/wtv4.PNF 8892 ..c. r/rr-xr-xr-x 0 0 4217-128-3 /WINDOWS/inf/wtv3.PNF 8892 ..c. r/rr-xr-xr-x 0 0 4218-128-3 /WINDOWS/inf/wtv2.PNF 8892 ..c. r/rr-xr-xr-x 0 0 4219-128-3 /WINDOWS/inf/wtv1.PNF 8892 ..c. r/rr-xr-xr-x 0 0 4220-128-3 /WINDOWS/inf/wtv0.PNF 9200 ..c. r/rr-xr-xr-x 0 0 4221-128-3 /WINDOWS/inf/wstcodec.PNF 15620 ..c. r/rr-xr-xr-x 0 0 4222-128-3 /WINDOWS/inf/wsh.PNF 6644 ..c. r/rr-xr-xr-x 0 0 4223-128-3 /WINDOWS/inf/wmtour.PNF 57172 ..c. r/rr-xr-xr-x 0 0 4224-128-3 /WINDOWS/inf/wmp.PNF 15908 ..c. r/rr-xr-xr-x 0 0 4225-128-3 /WINDOWS/inf/wmfsdk.PNF 21768 ..c. r/rr-xr-xr-x 0 0 4226-128-3 /WINDOWS/inf/wmdm.PNF 8884 ..c. r/rr-xr-xr-x 0 0 4228-128-3 /WINDOWS/inf/wfp8.PNF 8884 ..c. r/rr-xr-xr-x 0 0 4229-128-3 /WINDOWS/inf/wfp7.PNF 18134 ..c. r/rr-xr-xr-x 0 0 423-128-3 /WINDOWS/Help/compstui.hlp 8884 ..c. r/rr-xr-xr-x 0 0 4230-128-3 /WINDOWS/inf/wfp6.PNF 8884 ..c. r/rr-xr-xr-x 0 0 4231-128-3 /WINDOWS/inf/wfp5.PNF 8876 ..c. r/rr-xr-xr-x 0 0 4232-128-3 /WINDOWS/inf/wfp4.PNF 8884 ..c. r/rr-xr-xr-x 0 0 4233-128-3 /WINDOWS/inf/wfp3.PNF 8884 ..c. r/rr-xr-xr-x 0 0 4234-128-3 /WINDOWS/inf/wfp2.PNF 8884 ..c. r/rr-xr-xr-x 0 0 4235-128-3 /WINDOWS/inf/wfp1.PNF 8884 ..c. r/rr-xr-xr-x 0 0 4236-128-3 /WINDOWS/inf/wfp0.PNF 18112 ..c. r/rr-xr-xr-x 0 0 4237-128-3 /WINDOWS/inf/wdmjoy.PNF 17416 ..c. r/rr-xr-xr-x 0 0 4238-128-3 /WINDOWS/inf/wdma_ymh.PNF 30252 ..c. r/rr-xr-xr-x 0 0 4239-128-3 /WINDOWS/inf/wdma_ym2.PNF 33508 ..c. r/rr-xr-xr-x 0 0 4240-128-3 /WINDOWS/inf/wdma_via.PNF 74356 ..c. r/rr-xr-xr-x 0 0 4241-128-3 /WINDOWS/inf/wdma_usb.PNF 43508 ..c. r/rr-xr-xr-x 0 0 4242-128-3 /WINDOWS/inf/wdma_sis.PNF 25888 ..c. r/rr-xr-xr-x 0 0 4243-128-3 /WINDOWS/inf/wdma_rip.PNF 24792 ..c. r/rr-xr-xr-x 0 0 4244-128-3 /WINDOWS/inf/wdma_neo.PNF 18672 ..c. r/rr-xr-xr-x 0 0 4245-128-3 /WINDOWS/inf/wdma_ne2.PNF 43672 ..c. r/rr-xr-xr-x 0 0 4246-128-3 /WINDOWS/inf/wdma_m2e.PNF 44908 ..c. r/rr-xr-xr-x 0 0 4247-128-3 /WINDOWS/inf/wdma_int.PNF 42088 ..c. r/rr-xr-xr-x 0 0 4248-128-3 /WINDOWS/inf/wdma_ess.PNF 123012 ..c. r/rr-xr-xr-x 0 0 4249-128-3 /WINDOWS/inf/wdma_es3.PNF 101404 ..c. r/rr-xr-xr-x 0 0 4250-128-3 /WINDOWS/inf/wdma_es2.PNF 36624 ..c. r/rr-xr-xr-x 0 0 4251-128-3 /WINDOWS/inf/wdma_ens.PNF 31812 ..c. r/rr-xr-xr-x 0 0 4252-128-3 /WINDOWS/inf/wdma_cwr.PNF 63168 ..c. r/rr-xr-xr-x 0 0 4253-128-3 /WINDOWS/inf/wdma_ctl.PNF 45648 ..c. r/rr-xr-xr-x 0 0 4254-128-3 /WINDOWS/inf/wdma_csf.PNF 41660 ..c. r/rr-xr-xr-x 0 0 4255-128-3 /WINDOWS/inf/wdma_csc.PNF 35276 ..c. r/rr-xr-xr-x 0 0 4256-128-3 /WINDOWS/inf/wdma_azt.PNF 18216 ..c. r/rr-xr-xr-x 0 0 4257-128-3 /WINDOWS/inf/wdma_avc.PNF 95848 ..c. r/rr-xr-xr-x 0 0 4258-128-3 /WINDOWS/inf/wdma_aur.PNF 74520 ..c. r/rr-xr-xr-x 0 0 4259-128-3 /WINDOWS/inf/wdma_ali.PNF 8463 ..c. r/rr-xr-xr-x 0 0 426-128-3 /WINDOWS/inf/corelist.inf 301312 ..c. r/rr-xr-xr-x 0 0 4260-128-3 /WINDOWS/inf/wdma10k1.PNF 10644 ..c. r/rr-xr-xr-x 0 0 4261-128-3 /WINDOWS/inf/wbfirdma.PNF 10580 ..c. r/rr-xr-xr-x 0 0 4262-128-3 /WINDOWS/inf/wave.PNF 21352 ..c. r/rr-xr-xr-x 0 0 4263-128-3 /WINDOWS/inf/wab50.PNF 9684 ..c. r/rr-xr-xr-x 0 0 4264-128-3 /WINDOWS/inf/viafir2k.PNF 4368 ..c. r/rr-xr-xr-x 0 0 4265-128-3 /WINDOWS/inf/vgx.PNF 152 .a.. d/drwxrwxrwx 0 0 4266-144-1 /Documents and Settings/Default User/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1 20324 ..c. r/rr-xr-xr-x 0 0 4267-128-3 /WINDOWS/inf/usbvideo.PNF 37024 ..c. r/rr-xr-xr-x 0 0 4268-128-3 /WINDOWS/inf/usbstor.PNF 5476 ..c. r/rr-xr-xr-x 0 0 4269-128-3 /WINDOWS/inf/usbprint.PNF 51448 ..c. r/rr-xr-xr-x 0 0 4270-128-3 /WINDOWS/inf/usbport.PNF 4792 ..c. r/rr-xr-xr-x 0 0 4271-128-3 /WINDOWS/inf/unknown.PNF 10992 ..c. r/rr-xr-xr-x 0 0 4272-128-3 /WINDOWS/inf/umaxpp.PNF 68364 ..c. r/rr-xr-xr-x 0 0 4273-128-3 /WINDOWS/inf/umax.PNF 9776 ..c. r/rr-xr-xr-x 0 0 4274-128-3 /WINDOWS/inf/tshoot.PNF 9900 ..c. r/rr-xr-xr-x 0 0 4275-128-3 /WINDOWS/inf/tsbvcap.PNF 8628 ..c. r/rr-xr-xr-x 0 0 4276-128-3 /WINDOWS/inf/tridxp.PNF 9716 ..c. r/rr-xr-xr-x 0 0 4277-128-3 /WINDOWS/inf/tridkb.PNF 9916 ..c. r/rr-xr-xr-x 0 0 4278-128-3 /WINDOWS/inf/trid3d.PNF 8812 ..c. r/rr-xr-xr-x 0 0 4279-128-3 /WINDOWS/inf/tgiu.PNF 31712 ..c. r/rr-xr-xr-x 0 0 428-128-3 /WINDOWS/Fonts/courf.fon 9424 ..c. r/rr-xr-xr-x 0 0 4280-128-3 /WINDOWS/inf/tdibth.PNF 3164 ..c. r/rr-xr-xr-x 0 0 4281-128-3 /WINDOWS/inf/syscomp.PNF 57548 ..c. r/rr-xr-xr-x 0 0 4282-128-3 /WINDOWS/inf/swnt.PNF 5724 ..c. r/rr-xr-xr-x 0 0 4283-128-3 /WINDOWS/inf/swflash.PNF 11956 ..c. r/rr-xr-xr-x 0 0 4284-128-3 /WINDOWS/inf/streamip.PNF 87168 ..c. r/rr-xr-xr-x 0 0 4285-128-3 /WINDOWS/inf/stillcam.PNF 8004 ..c. r/rr-xr-xr-x 0 0 4286-128-3 /WINDOWS/inf/stalport.PNF 11660 ..c. r/rr-xr-xr-x 0 0 4287-128-3 /WINDOWS/inf/srusbusd.PNF 5988 ..c. r/rr-xr-xr-x 0 0 4288-128-3 /WINDOWS/inf/srchasst.PNF 12064 ..c. r/rr-xr-xr-x 0 0 4289-128-3 /WINDOWS/inf/sr.PNF 19735 ..c. r/rr-xr-xr-x 0 0 429-128-3 /WINDOWS/Help/cpanel.chm 12388 ..c. r/rr-xr-xr-x 0 0 4290-128-3 /WINDOWS/inf/spxports.PNF 20228 ..c. r/rr-xr-xr-x 0 0 4291-128-3 /WINDOWS/inf/spx.PNF 6192 ..c. r/rr-xr-xr-x 0 0 4292-128-3 /WINDOWS/inf/sonypvu1.PNF 7300 ..c. r/rr-xr-xr-x 0 0 4293-128-3 /WINDOWS/inf/smi.PNF 9196 ..c. r/rr-xr-xr-x 0 0 4294-128-3 /WINDOWS/inf/slip.PNF 4444 ..c. r/rr-xr-xr-x 0 0 4295-128-3 /WINDOWS/inf/skins.PNF 7716 ..c. r/rr-xr-xr-x 0 0 4296-128-3 /WINDOWS/inf/sisv6326.PNF 11252 ..c. r/rr-xr-xr-x 0 0 4297-128-3 /WINDOWS/inf/sisgr.PNF 7988 ..c. r/rr-xr-xr-x 0 0 4298-128-3 /WINDOWS/inf/sis6306.PNF 9068 ..c. r/rr-xr-xr-x 0 0 4299-128-3 /WINDOWS/inf/sis300i.PNF 560 .ac. d/dr-xr-xr-x 0 0 43-144-1 /WINDOWS/system32/drivers/etc 11776 ..c. r/rr-xr-xr-x 0 0 430-128-3 /WINDOWS/system32/drivers/cpqdap01.sys 15720 ..c. r/rr-xr-xr-x 0 0 4300-128-3 /WINDOWS/inf/shl_img.PNF 38476 ..c. r/rr-xr-xr-x 0 0 4301-128-3 /WINDOWS/inf/shell.PNF 8572 ..c. r/rr-xr-xr-x 0 0 4302-128-3 /WINDOWS/inf/sgiu.PNF 10036 ..c. r/rr-xr-xr-x 0 0 4303-128-3 /WINDOWS/inf/sffdisk.PNF 26712 ..c. r/rr-xr-xr-x 0 0 4304-128-3 /WINDOWS/inf/secrecs.PNF 4096 ..c. r/rr-xr-xr-x 0 0 4305-128-3 /WINDOWS/inf/secdrv.PNF 37312 ..c. r/rr-xr-xr-x 0 0 4306-128-3 /WINDOWS/inf/sdwndr2k.PNF 37528 ..c. r/rr-xr-xr-x 0 0 4307-128-3 /WINDOWS/inf/scsidev.PNF 39428 ..c. r/rr-xr-xr-x 0 0 4308-128-3 /WINDOWS/inf/sceregvl.PNF 6740 ..c. r/rr-xr-xr-x 0 0 4309-128-3 /WINDOWS/inf/s3trio3d.PNF 14504 ..c. r/rr-xr-xr-x 0 0 431-128-3 /WINDOWS/Help/cscui.hlp 8676 ..c. r/rr-xr-xr-x 0 0 4310-128-3 /WINDOWS/inf/s3savmx.PNF 8644 ..c. r/rr-xr-xr-x 0 0 4311-128-3 /WINDOWS/inf/s3sav4.PNF 8484 ..c. r/rr-xr-xr-x 0 0 4312-128-3 /WINDOWS/inf/s3sav3d.PNF 18476 ..c. r/rr-xr-xr-x 0 0 4313-128-3 /WINDOWS/inf/ricoh.PNF 7172 ..c. r/rr-xr-xr-x 0 0 4314-128-3 /WINDOWS/inf/ramdisk.PNF 11920 ..c. r/rr-xr-xr-x 0 0 4315-128-3 /WINDOWS/inf/qmgr.PNF 10620 ..c. r/rr-xr-xr-x 0 0 4316-128-3 /WINDOWS/inf/ptpusb.PNF 9380 ..c. r/rr-xr-xr-x 0 0 4317-128-3 /WINDOWS/inf/ps5333.PNF 146476 ..c. r/rr-xr-xr-x 0 0 4318-128-3 /WINDOWS/inf/prtupg9x.PNF 44964 ..c. r/rr-xr-xr-x 0 0 4319-128-3 /WINDOWS/inf/printupg.PNF 6916 ..c. r/rr-xr-xr-x 0 0 4320-128-3 /WINDOWS/inf/ppa3.PNF 6868 ..c. r/rr-xr-xr-x 0 0 4321-128-3 /WINDOWS/inf/ppa.PNF 16952 ..c. r/rr-xr-xr-x 0 0 4322-128-3 /WINDOWS/inf/pmxmcro.PNF 13300 ..c. r/rr-xr-xr-x 0 0 4323-128-3 /WINDOWS/inf/philtune.PNF 13172 ..c. r/rr-xr-xr-x 0 0 4324-128-3 /WINDOWS/inf/phildec.PNF 13828 ..c. r/rr-xr-xr-x 0 0 4325-128-3 /WINDOWS/inf/phil2vid.PNF 10484 ..c. r/rr-xr-xr-x 0 0 4326-128-3 /WINDOWS/inf/phil1vid.PNF 12596 ..c. r/rr-xr-xr-x 0 0 4327-128-3 /WINDOWS/inf/phdsext.PNF 8940 ..c. r/rr-xr-xr-x 0 0 4328-128-3 /WINDOWS/inf/perm3.PNF 12556 ..c. r/rr-xr-xr-x 0 0 4329-128-3 /WINDOWS/inf/perm2.PNF 13292 ..c. r/rr-xr-xr-x 0 0 4330-128-3 /WINDOWS/inf/pchealth.PNF 35832 ..c. r/rr-xr-xr-x 0 0 4331-128-3 /WINDOWS/inf/parhmse.PNF 12380 ..c. r/rr-xr-xr-x 0 0 4332-128-3 /WINDOWS/inf/ovsound.PNF 5860 ..c. r/rr-xr-xr-x 0 0 4333-128-3 /WINDOWS/inf/ovcomp.PNF 24812 ..c. r/rr-xr-xr-x 0 0 4334-128-3 /WINDOWS/inf/ovcam.PNF 17240 ..c. r/rr-xr-xr-x 0 0 4335-128-3 /WINDOWS/inf/oobe.PNF 22196 ..c. r/rr-xr-xr-x 0 0 4336-128-3 /WINDOWS/inf/nvts.PNF 34060 ..c. r/rr-xr-xr-x 0 0 4337-128-3 /WINDOWS/inf/nvdm.PNF 22148 ..c. r/rr-xr-xr-x 0 0 4338-128-3 /WINDOWS/inf/nvct.PNF 53292 ..c. r/rr-xr-xr-x 0 0 4339-128-3 /WINDOWS/inf/nv4_disp.PNF 2418 ..c. r/rr-xr-xr-x 0 0 434-128-3 /WINDOWS/inf/cyclad-z.inf 9668 ..c. r/rr-xr-xr-x 0 0 4340-128-3 /WINDOWS/inf/nv3.PNF 7096 ..c. r/rr-xr-xr-x 0 0 4341-128-3 /WINDOWS/inf/ntgrip.PNF 9848 ..c. r/rr-xr-xr-x 0 0 4342-128-3 /WINDOWS/inf/netxcpq.PNF 11016 ..c. r/rr-xr-xr-x 0 0 4343-128-3 /WINDOWS/inf/netx56n5.PNF 19344 ..c. r/rr-xr-xr-x 0 0 4344-128-3 /WINDOWS/inf/netx500.PNF 7028 ..c. r/rr-xr-xr-x 0 0 4345-128-3 /WINDOWS/inf/netwzc.PNF 19408 ..c. r/rr-xr-xr-x 0 0 4346-128-3 /WINDOWS/inf/netwv48.PNF 14740 ..c. r/rr-xr-xr-x 0 0 4347-128-3 /WINDOWS/inf/netwlan2.PNF 27880 ..c. r/rr-xr-xr-x 0 0 4348-128-3 /WINDOWS/inf/netwlan.PNF 6668 ..c. r/rr-xr-xr-x 0 0 4349-128-3 /WINDOWS/inf/netw940.PNF 2589 ..c. r/rr-xr-xr-x 0 0 435-128-3 /WINDOWS/inf/cyclom-y.inf 7176 ..c. r/rr-xr-xr-x 0 0 4350-128-3 /WINDOWS/inf/netw926.PNF 9868 ..c. r/rr-xr-xr-x 0 0 4351-128-3 /WINDOWS/inf/netw840.PNF 14892 ..c. r/rr-xr-xr-x 0 0 4352-128-3 /WINDOWS/inf/netvt86.PNF 8932 ..c. r/rr-xr-xr-x 0 0 4353-128-3 /WINDOWS/inf/netupnph.PNF 6348 ..c. r/rr-xr-xr-x 0 0 4354-128-3 /WINDOWS/inf/nettun.PNF 7472 ..c. r/rr-xr-xr-x 0 0 4355-128-3 /WINDOWS/inf/nettpro.PNF 11312 ..c. r/rr-xr-xr-x 0 0 4356-128-3 /WINDOWS/inf/nettiger.PNF 8172 ..c. r/rr-xr-xr-x 0 0 4357-128-3 /WINDOWS/inf/nettdkb.PNF 39216 ..c. r/rr-xr-xr-x 0 0 4358-128-3 /WINDOWS/inf/nettcpip.PNF 9204 ..c. r/rr-xr-xr-x 0 0 4359-128-3 /WINDOWS/inf/nettb155.PNF 10483 ..c. r/rr-xr-xr-x 0 0 436-128-3 /WINDOWS/Help/cyycoins.chm 10316 ..c. r/rr-xr-xr-x 0 0 4360-128-3 /WINDOWS/inf/netsnip.PNF 6412 ..c. r/rr-xr-xr-x 0 0 4361-128-3 /WINDOWS/inf/netsmc.PNF 7668 ..c. r/rr-xr-xr-x 0 0 4362-128-3 /WINDOWS/inf/netsla30.PNF 23448 ..c. r/rr-xr-xr-x 0 0 4363-128-3 /WINDOWS/inf/netsk_fp.PNF 14720 ..c. r/rr-xr-xr-x 0 0 4364-128-3 /WINDOWS/inf/netsk98.PNF 21736 ..c. r/rr-xr-xr-x 0 0 4365-128-3 /WINDOWS/inf/netsis.PNF 8700 ..c. r/rr-xr-xr-x 0 0 4366-128-3 /WINDOWS/inf/netserv.PNF 7540 ..c. r/rr-xr-xr-x 0 0 4367-128-3 /WINDOWS/inf/netsap.PNF 8428 ..c. r/rr-xr-xr-x 0 0 4368-128-3 /WINDOWS/inf/netrwan.PNF 19836 ..c. r/rr-xr-xr-x 0 0 4369-128-3 /WINDOWS/inf/netrtsnt.PNF 4627 ..c. r/rr-xr-xr-x 0 0 437-128-3 /WINDOWS/inf/cyyport.inf 10700 ..c. r/rr-xr-xr-x 0 0 4370-128-3 /WINDOWS/inf/netrtpnt.PNF 8408 ..c. r/rr-xr-xr-x 0 0 4371-128-3 /WINDOWS/inf/netrsvp.PNF 6800 ..c. r/rr-xr-xr-x 0 0 4372-128-3 /WINDOWS/inf/netrndis.PNF 7528 ..c. r/rr-xr-xr-x 0 0 4373-128-3 /WINDOWS/inf/netrlw2k.PNF 12104 ..c. r/rr-xr-xr-x 0 0 4374-128-3 /WINDOWS/inf/netrast.PNF 45180 ..c. r/rr-xr-xr-x 0 0 4375-128-3 /WINDOWS/inf/netrass.PNF 23504 ..c. r/rr-xr-xr-x 0 0 4376-128-3 /WINDOWS/inf/netrasa.PNF 11388 ..c. r/rr-xr-xr-x 0 0 4377-128-3 /WINDOWS/inf/netpwr2.PNF 6208 ..c. r/rr-xr-xr-x 0 0 4378-128-3 /WINDOWS/inf/netpschd.PNF 5772 ..c. r/rr-xr-xr-x 0 0 4379-128-3 /WINDOWS/inf/netpsa.PNF 10743 ..c. r/rr-xr-xr-x 0 0 438-128-3 /WINDOWS/Help/cyzcoins.chm 10220 ..c. r/rr-xr-xr-x 0 0 4380-128-3 /WINDOWS/inf/netpnic.PNF 8412 ..c. r/rr-xr-xr-x 0 0 4381-128-3 /WINDOWS/inf/netpc100.PNF 12940 ..c. r/rr-xr-xr-x 0 0 4382-128-3 /WINDOWS/inf/netosi5.PNF 14696 ..c. r/rr-xr-xr-x 0 0 4383-128-3 /WINDOWS/inf/netosi2c.PNF 16156 ..c. r/rr-xr-xr-x 0 0 4384-128-3 /WINDOWS/inf/netnwlnk.PNF 10824 ..c. r/rr-xr-xr-x 0 0 4385-128-3 /WINDOWS/inf/netnwcli.PNF 14684 ..c. r/rr-xr-xr-x 0 0 4386-128-3 /WINDOWS/inf/netnovel.PNF 14768 ..c. r/rr-xr-xr-x 0 0 4387-128-3 /WINDOWS/inf/netnm.PNF 10884 ..c. r/rr-xr-xr-x 0 0 4388-128-3 /WINDOWS/inf/netngr.PNF 22000 ..c. r/rr-xr-xr-x 0 0 4389-128-3 /WINDOWS/inf/netnf3.PNF 7813 ..c. r/rr-xr-xr-x 0 0 439-128-3 /WINDOWS/inf/cyzport.inf 6056 ..c. r/rr-xr-xr-x 0 0 4390-128-3 /WINDOWS/inf/netnb.PNF 20344 ..c. r/rr-xr-xr-x 0 0 4391-128-3 /WINDOWS/inf/netmscli.PNF 11180 ..c. r/rr-xr-xr-x 0 0 4392-128-3 /WINDOWS/inf/netmhzn5.PNF 27740 ..c. r/rr-xr-xr-x 0 0 4393-128-3 /WINDOWS/inf/netmadge.PNF 7440 ..c. r/rr-xr-xr-x 0 0 4394-128-3 /WINDOWS/inf/netloop.PNF 8180 ..c. r/rr-xr-xr-x 0 0 4395-128-3 /WINDOWS/inf/netlnev2.PNF 7344 ..c. r/rr-xr-xr-x 0 0 4396-128-3 /WINDOWS/inf/netlm56.PNF 7452 ..c. r/rr-xr-xr-x 0 0 4397-128-3 /WINDOWS/inf/netlm.PNF 6260 ..c. r/rr-xr-xr-x 0 0 4398-128-3 /WINDOWS/inf/netlanep.PNF 5340 ..c. r/rr-xr-xr-x 0 0 4399-128-3 /WINDOWS/inf/netlanem.PNF 48 .ac. d/dr-xr-xr-x 0 0 44-144-1 /WINDOWS/system32/drivers/disdn 8616 ..c. r/rr-xr-xr-x 0 0 4400-128-3 /WINDOWS/inf/netktc.PNF 18624 ..c. r/rr-xr-xr-x 0 0 4401-128-3 /WINDOWS/inf/netklsi.PNF 9556 ..c. r/rr-xr-xr-x 0 0 4402-128-3 /WINDOWS/inf/netirda.PNF 13020 ..c. r/rr-xr-xr-x 0 0 4403-128-3 /WINDOWS/inf/netip6.PNF 14620 ..c. r/rr-xr-xr-x 0 0 4404-128-3 /WINDOWS/inf/netibm2.PNF 17712 ..c. r/rr-xr-xr-x 0 0 4405-128-3 /WINDOWS/inf/netibm.PNF 9732 ..c. r/rr-xr-xr-x 0 0 4406-128-3 /WINDOWS/inf/netias.PNF 5356 ..c. r/rr-xr-xr-x 0 0 4407-128-3 /WINDOWS/inf/netgpc.PNF 3704 ..c. r/rr-xr-xr-x 0 0 4408-128-3 /WINDOWS/inf/netfw.PNF 7584 ..c. r/rr-xr-xr-x 0 0 4409-128-3 /WINDOWS/inf/netforeh.PNF 7616 ..c. r/rr-xr-xr-x 0 0 4410-128-3 /WINDOWS/inf/netfore.PNF 7288 ..c. r/rr-xr-xr-x 0 0 4411-128-3 /WINDOWS/inf/netfjvj.PNF 7272 ..c. r/rr-xr-xr-x 0 0 4412-128-3 /WINDOWS/inf/netfjvi.PNF 7972 ..c. r/rr-xr-xr-x 0 0 4413-128-3 /WINDOWS/inf/netfa410.PNF 9940 ..c. r/rr-xr-xr-x 0 0 4414-128-3 /WINDOWS/inf/netfa312.PNF 9864 ..c. r/rr-xr-xr-x 0 0 4415-128-3 /WINDOWS/inf/netf56n5.PNF 7132 ..c. r/rr-xr-xr-x 0 0 4416-128-3 /WINDOWS/inf/netex10.PNF 6484 ..c. r/rr-xr-xr-x 0 0 4417-128-3 /WINDOWS/inf/netepvcp.PNF 7032 ..c. r/rr-xr-xr-x 0 0 4418-128-3 /WINDOWS/inf/netepvcm.PNF 8232 ..c. r/rr-xr-xr-x 0 0 4419-128-3 /WINDOWS/inf/netepro.PNF 10896 ..c. r/rr-xr-xr-x 0 0 4420-128-3 /WINDOWS/inf/netepicn.PNF 17332 ..c. r/rr-xr-xr-x 0 0 4421-128-3 /WINDOWS/inf/netel99x.PNF 12612 ..c. r/rr-xr-xr-x 0 0 4422-128-3 /WINDOWS/inf/netel980.PNF 19480 ..c. r/rr-xr-xr-x 0 0 4423-128-3 /WINDOWS/inf/netel90b.PNF 11984 ..c. r/rr-xr-xr-x 0 0 4424-128-3 /WINDOWS/inf/netel90a.PNF 7304 ..c. r/rr-xr-xr-x 0 0 4425-128-3 /WINDOWS/inf/netel5x9.PNF 11132 ..c. r/rr-xr-xr-x 0 0 4426-128-3 /WINDOWS/inf/netel574.PNF 7560 ..c. r/rr-xr-xr-x 0 0 4427-128-3 /WINDOWS/inf/netel515.PNF 8324 ..c. r/rr-xr-xr-x 0 0 4428-128-3 /WINDOWS/inf/netejxmp.PNF 11532 ..c. r/rr-xr-xr-x 0 0 4429-128-3 /WINDOWS/inf/nete100i.PNF 29420 ..c. r/rr-xr-xr-x 0 0 4430-128-3 /WINDOWS/inf/nete1000.PNF 10608 ..c. r/rr-xr-xr-x 0 0 4431-128-3 /WINDOWS/inf/netdm.PNF 12096 ..c. r/rr-xr-xr-x 0 0 4432-128-3 /WINDOWS/inf/netdlh5x.PNF 57460 ..c. r/rr-xr-xr-x 0 0 4433-128-3 /WINDOWS/inf/netdgdxb.PNF 8512 ..c. r/rr-xr-xr-x 0 0 4434-128-3 /WINDOWS/inf/netdf650.PNF 9244 ..c. r/rr-xr-xr-x 0 0 4435-128-3 /WINDOWS/inf/netdefxa.PNF 10448 ..c. r/rr-xr-xr-x 0 0 4436-128-3 /WINDOWS/inf/netdav.PNF 10460 ..c. r/rr-xr-xr-x 0 0 4437-128-3 /WINDOWS/inf/netctmrk.PNF 10328 ..c. r/rr-xr-xr-x 0 0 4438-128-3 /WINDOWS/inf/netcpqmt.PNF 17772 ..c. r/rr-xr-xr-x 0 0 4439-128-3 /WINDOWS/inf/netcpqi.PNF 17392 ..c. r/rr-xr-xr-x 0 0 4440-128-3 /WINDOWS/inf/netcpqg.PNF 12656 ..c. r/rr-xr-xr-x 0 0 4441-128-3 /WINDOWS/inf/netcpqc.PNF 4416 ..c. r/rr-xr-xr-x 0 0 4442-128-3 /WINDOWS/inf/netcis.PNF 15124 ..c. r/rr-xr-xr-x 0 0 4443-128-3 /WINDOWS/inf/netcicap.PNF 14388 ..c. r/rr-xr-xr-x 0 0 4444-128-3 /WINDOWS/inf/netcem56.PNF 9044 ..c. r/rr-xr-xr-x 0 0 4445-128-3 /WINDOWS/inf/netcem33.PNF 9068 ..c. r/rr-xr-xr-x 0 0 4446-128-3 /WINDOWS/inf/netcem28.PNF 14128 ..c. r/rr-xr-xr-x 0 0 4447-128-3 /WINDOWS/inf/netce3.PNF 10080 ..c. r/rr-xr-xr-x 0 0 4448-128-3 /WINDOWS/inf/netce2.PNF 16524 ..c. r/rr-xr-xr-x 0 0 4449-128-3 /WINDOWS/inf/netcbe.PNF 14812 ..c. r/rr-xr-xr-x 0 0 4450-128-3 /WINDOWS/inf/netcb325.PNF 8868 ..c. r/rr-xr-xr-x 0 0 4451-128-3 /WINDOWS/inf/netcb102.PNF 12604 ..c. r/rr-xr-xr-x 0 0 4452-128-3 /WINDOWS/inf/netbrzw.PNF 5492 ..c. r/rr-xr-xr-x 0 0 4453-128-3 /WINDOWS/inf/netbrdgs.PNF 5896 ..c. r/rr-xr-xr-x 0 0 4454-128-3 /WINDOWS/inf/netbrdgm.PNF 8776 ..c. r/rr-xr-xr-x 0 0 4455-128-3 /WINDOWS/inf/netbcm4u.PNF 9368 ..c. r/rr-xr-xr-x 0 0 4456-128-3 /WINDOWS/inf/netbcm4p.PNF 8724 ..c. r/rr-xr-xr-x 0 0 4457-128-3 /WINDOWS/inf/netbcm4e.PNF 34904 ..c. r/rr-xr-xr-x 0 0 4458-128-3 /WINDOWS/inf/netb57xp.PNF 6648 ..c. r/rr-xr-xr-x 0 0 4459-128-3 /WINDOWS/inf/netauni.PNF 18629 ..c. r/rr-xr-xr-x 0 0 446-128-3 /WINDOWS/Help/ddeshare.chm 11912 ..c. r/rr-xr-xr-x 0 0 4460-128-3 /WINDOWS/inf/netasp2k.PNF 12188 ..c. r/rr-xr-xr-x 0 0 4461-128-3 /WINDOWS/inf/netana.PNF 16416 ..c. r/rr-xr-xr-x 0 0 4462-128-3 /WINDOWS/inf/netan983.PNF 10360 ..c. r/rr-xr-xr-x 0 0 4463-128-3 /WINDOWS/inf/netamdhl.PNF 17936 ..c. r/rr-xr-xr-x 0 0 4464-128-3 /WINDOWS/inf/netamd2.PNF 9740 ..c. r/rr-xr-xr-x 0 0 4465-128-3 /WINDOWS/inf/netamd.PNF 6568 ..c. r/rr-xr-xr-x 0 0 4466-128-3 /WINDOWS/inf/netambi.PNF 7748 ..c. r/rr-xr-xr-x 0 0 4467-128-3 /WINDOWS/inf/netali.PNF 25484 ..c. r/rr-xr-xr-x 0 0 4468-128-3 /WINDOWS/inf/net8511.PNF 15748 ..c. r/rr-xr-xr-x 0 0 4469-128-3 /WINDOWS/inf/net83820.PNF 33495 ..c. r/rr-xr-xr-x 0 0 447-128-3 /WINDOWS/Help/ddeshare.hlp 8604 ..c. r/rr-xr-xr-x 0 0 4470-128-3 /WINDOWS/inf/net713.PNF 10820 ..c. r/rr-xr-xr-x 0 0 4471-128-3 /WINDOWS/inf/net656n5.PNF 9172 ..c. r/rr-xr-xr-x 0 0 4472-128-3 /WINDOWS/inf/net656c5.PNF 7980 ..c. r/rr-xr-xr-x 0 0 4473-128-3 /WINDOWS/inf/net650d.PNF 10588 ..c. r/rr-xr-xr-x 0 0 4474-128-3 /WINDOWS/inf/net575nt.PNF 8452 ..c. r/rr-xr-xr-x 0 0 4475-128-3 /WINDOWS/inf/net559ib.PNF 83384 ..c. r/rr-xr-xr-x 0 0 4476-128-3 /WINDOWS/inf/net557.PNF 8532 ..c. r/rr-xr-xr-x 0 0 4477-128-3 /WINDOWS/inf/net5515n.PNF 6916 ..c. r/rr-xr-xr-x 0 0 4478-128-3 /WINDOWS/inf/net3sr.PNF 14352 ..c. r/rr-xr-xr-x 0 0 4479-128-3 /WINDOWS/inf/net3c985.PNF 11552 ..c. r/rr-xr-xr-x 0 0 4480-128-3 /WINDOWS/inf/net3c589.PNF 8812 ..c. r/rr-xr-xr-x 0 0 4481-128-3 /WINDOWS/inf/net3c556.PNF 26576 ..c. r/rr-xr-xr-x 0 0 4482-128-3 /WINDOWS/inf/net21x4.PNF 6356 ..c. r/rr-xr-xr-x 0 0 4483-128-3 /WINDOWS/inf/net1394.PNF 6236 ..c. r/rr-xr-xr-x 0 0 4484-128-3 /WINDOWS/inf/net10.PNF 8020 ..c. r/rr-xr-xr-x 0 0 4485-128-3 /WINDOWS/inf/neo20xx.PNF 5792 ..c. r/rr-xr-xr-x 0 0 4486-128-3 /WINDOWS/inf/ndisuio.PNF 9096 ..c. r/rr-xr-xr-x 0 0 4487-128-3 /WINDOWS/inf/ndisip.PNF 9636 ..c. r/rr-xr-xr-x 0 0 4488-128-3 /WINDOWS/inf/nabtsfec.PNF 7856 ..c. r/rr-xr-xr-x 0 0 4489-128-3 /WINDOWS/inf/mymusic.PNF 12550 ..c. r/rr-xr-xr-x 0 0 449-128-3 /WINDOWS/Help/defrag.hlp 12224 ..c. r/rr-xr-xr-x 0 0 4490-128-3 /WINDOWS/inf/mxport.PNF 9960 ..c. r/rr-xr-xr-x 0 0 4491-128-3 /WINDOWS/inf/mxboard.PNF 16924 ..c. r/rr-xr-xr-x 0 0 4492-128-3 /WINDOWS/inf/mwremove.PNF 8508 ..c. r/rr-xr-xr-x 0 0 4493-128-3 /WINDOWS/inf/mwmbatam.PNF 38224 ..c. r/rr-xr-xr-x 0 0 4494-128-3 /WINDOWS/inf/mwavmdm1.PNF 8720 ..c. r/rr-xr-xr-x 0 0 4495-128-3 /WINDOWS/inf/mtxvideo.PNF 13960 ..c. r/rr-xr-xr-x 0 0 4496-128-3 /WINDOWS/inf/mstask.PNF 23816 ..c. r/rr-xr-xr-x 0 0 4497-128-3 /WINDOWS/inf/mstape.PNF 6920 ..c. r/rr-xr-xr-x 0 0 4498-128-3 /WINDOWS/inf/msrio8.PNF 7012 ..c. r/rr-xr-xr-x 0 0 4499-128-3 /WINDOWS/inf/msrio.PNF 168 .a.. d/dr-xr-xr-x 0 0 45-144-6 /WINDOWS/inf 13041 ..c. r/rr-xr-xr-x 0 0 450-128-3 /WINDOWS/Help/defrag.chm 35964 ..c. r/rr-xr-xr-x 0 0 4500-128-3 /WINDOWS/inf/msoe50.PNF 6768 ..c. r/rr-xr-xr-x 0 0 4501-128-3 /WINDOWS/inf/msnike.PNF 60940 ..c. r/rr-xr-xr-x 0 0 4502-128-3 /WINDOWS/inf/msnetmtg.PNF 15364 ..c. r/rr-xr-xr-x 0 0 4503-128-3 /WINDOWS/inf/msmusb.PNF 29140 ..c. r/rr-xr-xr-x 0 0 4504-128-3 /WINDOWS/inf/msmscsi.PNF 9952 ..c. r/rr-xr-xr-x 0 0 4505-128-3 /WINDOWS/inf/msinfo32.PNF 39084 ..c. r/rr-xr-xr-x 0 0 4506-128-3 /WINDOWS/inf/msdv.PNF 6688 ..c. r/rr-xr-xr-x 0 0 4507-128-3 /WINDOWS/inf/mscpqpa1.PNF 2824 ..c. r/rr-xr-xr-x 0 0 4508-128-3 /WINDOWS/inf/mqsysoc.PNF 15924 ..c. r/rr-xr-xr-x 0 0 4509-128-3 /WINDOWS/inf/mpsstln.PNF 30644 ..c. r/rr-xr-xr-x 0 0 4510-128-3 /WINDOWS/inf/mplayer2.PNF 8284 ..c. r/rr-xr-xr-x 0 0 4511-128-3 /WINDOWS/inf/mpe.PNF 15196 ..c. r/rr-xr-xr-x 0 0 4512-128-3 /WINDOWS/inf/moviemk.PNF 112360 ..c. r/rr-xr-xr-x 0 0 4513-128-3 /WINDOWS/inf/monitor8.PNF 88208 ..c. r/rr-xr-xr-x 0 0 4514-128-3 /WINDOWS/inf/monitor7.PNF 94204 ..c. r/rr-xr-xr-x 0 0 4515-128-3 /WINDOWS/inf/monitor6.PNF 120720 ..c. r/rr-xr-xr-x 0 0 4516-128-3 /WINDOWS/inf/monitor5.PNF 86836 ..c. r/rr-xr-xr-x 0 0 4517-128-3 /WINDOWS/inf/monitor4.PNF 89128 ..c. r/rr-xr-xr-x 0 0 4518-128-3 /WINDOWS/inf/monitor3.PNF 101148 ..c. r/rr-xr-xr-x 0 0 4519-128-3 /WINDOWS/inf/monitor2.PNF 11764 ..c. r/rr-xr-xr-x 0 0 4520-128-3 /WINDOWS/inf/modemcsa.PNF 41332 ..c. r/rr-xr-xr-x 0 0 4521-128-3 /WINDOWS/inf/mmopt.PNF 3764 ..c. r/rr-xr-xr-x 0 0 4522-128-3 /WINDOWS/inf/minioc.PNF 10004 ..c. r/rr-xr-xr-x 0 0 4523-128-3 /WINDOWS/inf/mgau.PNF 9460 ..c. r/rr-xr-xr-x 0 0 4524-128-3 /WINDOWS/inf/mfx56nf.PNF 6636 ..c. r/rr-xr-xr-x 0 0 4525-128-3 /WINDOWS/inf/mfsupra.PNF 9596 ..c. r/rr-xr-xr-x 0 0 4526-128-3 /WINDOWS/inf/mfsocket.PNF 12292 ..c. r/rr-xr-xr-x 0 0 4527-128-3 /WINDOWS/inf/mfosi5.PNF 11068 ..c. r/rr-xr-xr-x 0 0 4528-128-3 /WINDOWS/inf/mfmhzn5.PNF 9712 ..c. r/rr-xr-xr-x 0 0 4529-128-3 /WINDOWS/inf/mflm56.PNF 9288 ..c. r/rr-xr-xr-x 0 0 4530-128-3 /WINDOWS/inf/mflm.PNF 9704 ..c. r/rr-xr-xr-x 0 0 4531-128-3 /WINDOWS/inf/mff56n5.PNF 18984 ..c. r/rr-xr-xr-x 0 0 4532-128-3 /WINDOWS/inf/mfcem56.PNF 7388 ..c. r/rr-xr-xr-x 0 0 4533-128-3 /WINDOWS/inf/mfcem33.PNF 7668 ..c. r/rr-xr-xr-x 0 0 4534-128-3 /WINDOWS/inf/mfcem28.PNF 17180 ..c. r/rr-xr-xr-x 0 0 4535-128-3 /WINDOWS/inf/memcard.PNF 134964 ..c. r/rr-xr-xr-x 0 0 4536-128-3 /WINDOWS/inf/mdmzyxlg.PNF 122052 ..c. r/rr-xr-xr-x 0 0 4537-128-3 /WINDOWS/inf/mdmzyxel.PNF 80924 ..c. r/rr-xr-xr-x 0 0 4538-128-3 /WINDOWS/inf/mdmzyp.PNF 129992 ..c. r/rr-xr-xr-x 0 0 4539-128-3 /WINDOWS/inf/mdmzoom.PNF 74036 ..c. r/rr-xr-xr-x 0 0 4540-128-3 /WINDOWS/inf/mdmxirmp.PNF 76812 ..c. r/rr-xr-xr-x 0 0 4541-128-3 /WINDOWS/inf/mdmxircc.PNF 71144 ..c. r/rr-xr-xr-x 0 0 4542-128-3 /WINDOWS/inf/mdmx5560.PNF 168904 ..c. r/rr-xr-xr-x 0 0 4543-128-3 /WINDOWS/inf/mdmwhql0.PNF 26724 ..c. r/rr-xr-xr-x 0 0 4544-128-3 /WINDOWS/inf/mdmvv.PNF 8224 ..c. r/rr-xr-xr-x 0 0 4545-128-3 /WINDOWS/inf/mdmvdot.PNF 10424 ..c. r/rr-xr-xr-x 0 0 4546-128-3 /WINDOWS/inf/mdmusrsp.PNF 74344 ..c. r/rr-xr-xr-x 0 0 4547-128-3 /WINDOWS/inf/mdmusrk1.PNF 75336 ..c. r/rr-xr-xr-x 0 0 4548-128-3 /WINDOWS/inf/mdmusrgl.PNF 23852 ..c. r/rr-xr-xr-x 0 0 4549-128-3 /WINDOWS/inf/mdmusrg.PNF 9332 ..c. r/rr-xr-xr-x 0 0 4550-128-3 /WINDOWS/inf/mdmusrf.PNF 23188 ..c. r/rr-xr-xr-x 0 0 4551-128-3 /WINDOWS/inf/mdmtron.PNF 53128 ..c. r/rr-xr-xr-x 0 0 4552-128-3 /WINDOWS/inf/mdmtosh.PNF 53880 ..c. r/rr-xr-xr-x 0 0 4553-128-3 /WINDOWS/inf/mdmti.PNF 16332 ..c. r/rr-xr-xr-x 0 0 4554-128-3 /WINDOWS/inf/mdmtexas.PNF 20260 ..c. r/rr-xr-xr-x 0 0 4555-128-3 /WINDOWS/inf/mdmtdkj7.PNF 17320 ..c. r/rr-xr-xr-x 0 0 4556-128-3 /WINDOWS/inf/mdmtdkj6.PNF 29708 ..c. r/rr-xr-xr-x 0 0 4557-128-3 /WINDOWS/inf/mdmtdkj5.PNF 24516 ..c. r/rr-xr-xr-x 0 0 4558-128-3 /WINDOWS/inf/mdmtdkj4.PNF 26716 ..c. r/rr-xr-xr-x 0 0 4559-128-3 /WINDOWS/inf/mdmtdkj3.PNF 63440 ..c. r/rr-xr-xr-x 0 0 456-128-3 /WINDOWS/Help/devmgr.hlp 27016 ..c. r/rr-xr-xr-x 0 0 4560-128-3 /WINDOWS/inf/mdmtdkj2.PNF 65804 ..c. r/rr-xr-xr-x 0 0 4561-128-3 /WINDOWS/inf/mdmtdk.PNF 40676 ..c. r/rr-xr-xr-x 0 0 4562-128-3 /WINDOWS/inf/mdmsuprv.PNF 134308 ..c. r/rr-xr-xr-x 0 0 4563-128-3 /WINDOWS/inf/mdmsupra.PNF 45896 ..c. r/rr-xr-xr-x 0 0 4564-128-3 /WINDOWS/inf/mdmsupr3.PNF 34272 ..c. r/rr-xr-xr-x 0 0 4565-128-3 /WINDOWS/inf/mdmsun2.PNF 11292 ..c. r/rr-xr-xr-x 0 0 4566-128-3 /WINDOWS/inf/mdmsun1.PNF 76068 ..c. r/rr-xr-xr-x 0 0 4567-128-3 /WINDOWS/inf/mdmspq28.PNF 90232 ..c. r/rr-xr-xr-x 0 0 4568-128-3 /WINDOWS/inf/mdmsonyu.PNF 14536 ..c. r/rr-xr-xr-x 0 0 4569-128-3 /WINDOWS/inf/mdmsmart.PNF 53709 ..c. r/rr-xr-xr-x 0 0 457-128-3 /WINDOWS/Help/devmgr.chm 23608 ..c. r/rr-xr-xr-x 0 0 4570-128-3 /WINDOWS/inf/mdmsiil6.PNF 23408 ..c. r/rr-xr-xr-x 0 0 4571-128-3 /WINDOWS/inf/mdmsii64.PNF 44876 ..c. r/rr-xr-xr-x 0 0 4572-128-3 /WINDOWS/inf/mdmsier.PNF 23000 ..c. r/rr-xr-xr-x 0 0 4573-128-3 /WINDOWS/inf/mdmsgsmu.PNF 6076 ..c. r/rr-xr-xr-x 0 0 4574-128-3 /WINDOWS/inf/mdmsgsml.PNF 1536452 ..c. r/rr-xr-xr-x 0 0 4575-128-3 /WINDOWS/inf/mdmrpciw.PNF 306060 ..c. r/rr-xr-xr-x 0 0 4576-128-3 /WINDOWS/inf/mdmrpci.PNF 125636 ..c. r/rr-xr-xr-x 0 0 4577-128-3 /WINDOWS/inf/mdmrock5.PNF 71236 ..c. r/rr-xr-xr-x 0 0 4578-128-3 /WINDOWS/inf/mdmrock4.PNF 50624 ..c. r/rr-xr-xr-x 0 0 4579-128-3 /WINDOWS/inf/mdmrock3.PNF 29366 ..c. r/rr-xr-xr-x 0 0 458-128-3 /WINDOWS/Help/dfs.hlp 23712 ..c. r/rr-xr-xr-x 0 0 4580-128-3 /WINDOWS/inf/mdmrock.PNF 6776 ..c. r/rr-xr-xr-x 0 0 4581-128-3 /WINDOWS/inf/mdmrisa.PNF 80624 ..c. r/rr-xr-xr-x 0 0 4582-128-3 /WINDOWS/inf/mdmracal.PNF 15840 ..c. r/rr-xr-xr-x 0 0 4583-128-3 /WINDOWS/inf/mdmpsion.PNF 57224 ..c. r/rr-xr-xr-x 0 0 4584-128-3 /WINDOWS/inf/mdmpp.PNF 10424 ..c. r/rr-xr-xr-x 0 0 4585-128-3 /WINDOWS/inf/mdmpn1.PNF 19268 ..c. r/rr-xr-xr-x 0 0 4586-128-3 /WINDOWS/inf/mdmpin.PNF 79716 ..c. r/rr-xr-xr-x 0 0 4587-128-3 /WINDOWS/inf/mdmpenr.PNF 68664 ..c. r/rr-xr-xr-x 0 0 4588-128-3 /WINDOWS/inf/mdmpctel.PNF 8372 ..c. r/rr-xr-xr-x 0 0 4589-128-3 /WINDOWS/inf/mdmpbit.PNF 2139 ..c. r/rr-xr-xr-x 0 0 459-128-3 /WINDOWS/inf/dfrg.inf 27860 ..c. r/rr-xr-xr-x 0 0 4590-128-3 /WINDOWS/inf/mdmpace.PNF 39416 ..c. r/rr-xr-xr-x 0 0 4591-128-3 /WINDOWS/inf/mdmosice.PNF 49096 ..c. r/rr-xr-xr-x 0 0 4592-128-3 /WINDOWS/inf/mdmosi.PNF 11480 ..c. r/rr-xr-xr-x 0 0 4593-128-3 /WINDOWS/inf/mdmoptn.PNF 126152 ..c. r/rr-xr-xr-x 0 0 4594-128-3 /WINDOWS/inf/mdmomrn3.PNF 19048 ..c. r/rr-xr-xr-x 0 0 4595-128-3 /WINDOWS/inf/mdmolic.PNF 10572 ..c. r/rr-xr-xr-x 0 0 4596-128-3 /WINDOWS/inf/mdmnttte.PNF 17460 ..c. r/rr-xr-xr-x 0 0 4597-128-3 /WINDOWS/inf/mdmnttp2.PNF 16196 ..c. r/rr-xr-xr-x 0 0 4598-128-3 /WINDOWS/inf/mdmnttp.PNF 11516 ..c. r/rr-xr-xr-x 0 0 4599-128-3 /WINDOWS/inf/mdmnttme.PNF 56 .a.. d/dr-xr-xr-x 0 0 46-144-6 /WINDOWS/Help 22004 ..c. r/rr-xr-xr-x 0 0 4600-128-3 /WINDOWS/inf/mdmnttd6.PNF 21996 ..c. r/rr-xr-xr-x 0 0 4601-128-3 /WINDOWS/inf/mdmnttd2.PNF 13800 ..c. r/rr-xr-xr-x 0 0 4602-128-3 /WINDOWS/inf/mdmntt1.PNF 46132 ..c. r/rr-xr-xr-x 0 0 4603-128-3 /WINDOWS/inf/mdmntstm.PNF 20216 ..c. r/rr-xr-xr-x 0 0 4604-128-3 /WINDOWS/inf/mdmnova.PNF 13244 ..c. r/rr-xr-xr-x 0 0 4605-128-3 /WINDOWS/inf/mdmnokia.PNF 10340 ..c. r/rr-xr-xr-x 0 0 4606-128-3 /WINDOWS/inf/Mdmnis5t.PNF 10364 ..c. r/rr-xr-xr-x 0 0 4607-128-3 /WINDOWS/inf/Mdmnis3t.PNF 11340 ..c. r/rr-xr-xr-x 0 0 4608-128-3 /WINDOWS/inf/Mdmnis2u.PNF 11268 ..c. r/rr-xr-xr-x 0 0 4609-128-3 /WINDOWS/inf/Mdmnis1u.PNF 14952 ..c. r/rr-xr-xr-x 0 0 461-128-3 /WINDOWS/inf/dgaport.inf 20328 ..c. r/rr-xr-xr-x 0 0 4610-128-3 /WINDOWS/inf/mdmneuhs.PNF 81760 ..c. r/rr-xr-xr-x 0 0 4611-128-3 /WINDOWS/inf/mdmmts.PNF 8864 ..c. r/rr-xr-xr-x 0 0 4612-128-3 /WINDOWS/inf/mdmmotou.PNF 20132 ..c. r/rr-xr-xr-x 0 0 4613-128-3 /WINDOWS/inf/mdmmoto1.PNF 72136 ..c. r/rr-xr-xr-x 0 0 4614-128-3 /WINDOWS/inf/mdmmoto.PNF 18540 ..c. r/rr-xr-xr-x 0 0 4615-128-3 /WINDOWS/inf/mdmmod.PNF 11696 ..c. r/rr-xr-xr-x 0 0 4616-128-3 /WINDOWS/inf/mdmminij.PNF 89996 ..c. r/rr-xr-xr-x 0 0 4617-128-3 /WINDOWS/inf/mdmmhzk1.PNF 199760 ..c. r/rr-xr-xr-x 0 0 4618-128-3 /WINDOWS/inf/mdmmhzel.PNF 92092 ..c. r/rr-xr-xr-x 0 0 4619-128-3 /WINDOWS/inf/mdmmhza.PNF 14981 ..c. r/rr-xr-xr-x 0 0 462-128-3 /WINDOWS/inf/dgasync.inf 74120 ..c. r/rr-xr-xr-x 0 0 4620-128-3 /WINDOWS/inf/mdmmhrtz.PNF 110412 ..c. r/rr-xr-xr-x 0 0 4621-128-3 /WINDOWS/inf/mdmmetri.PNF 17416 ..c. r/rr-xr-xr-x 0 0 4622-128-3 /WINDOWS/inf/mdmmega.PNF 63176 ..c. r/rr-xr-xr-x 0 0 4623-128-3 /WINDOWS/inf/mdmmct.PNF 64544 ..c. r/rr-xr-xr-x 0 0 4624-128-3 /WINDOWS/inf/mdmmcom.PNF 11504 ..c. r/rr-xr-xr-x 0 0 4625-128-3 /WINDOWS/inf/mdmmcd.PNF 16504 ..c. r/rr-xr-xr-x 0 0 4626-128-3 /WINDOWS/inf/mdmmc288.PNF 36404 ..c. r/rr-xr-xr-x 0 0 4627-128-3 /WINDOWS/inf/mdmlucnt.PNF 77168 ..c. r/rr-xr-xr-x 0 0 4628-128-3 /WINDOWS/inf/mdmltsft.PNF 76292 ..c. r/rr-xr-xr-x 0 0 4629-128-3 /WINDOWS/inf/mdmltleo.PNF 96400 ..c. r/rr-xr-xr-x 0 0 4630-128-3 /WINDOWS/inf/mdmlt3.PNF 42660 ..c. r/rr-xr-xr-x 0 0 4631-128-3 /WINDOWS/inf/mdmlasno.PNF 20868 ..c. r/rr-xr-xr-x 0 0 4632-128-3 /WINDOWS/inf/mdmlasat.PNF 12644 ..c. r/rr-xr-xr-x 0 0 4633-128-3 /WINDOWS/inf/mdmkortx.PNF 11892 ..c. r/rr-xr-xr-x 0 0 4634-128-3 /WINDOWS/inf/mdmke.PNF 25996 ..c. r/rr-xr-xr-x 0 0 4635-128-3 /WINDOWS/inf/MDMJF56E.PNF 58752 ..c. r/rr-xr-xr-x 0 0 4636-128-3 /WINDOWS/inf/mdmisdn.PNF 108224 ..c. r/rr-xr-xr-x 0 0 4637-128-3 /WINDOWS/inf/mdmirmdm.PNF 30748 ..c. r/rr-xr-xr-x 0 0 4638-128-3 /WINDOWS/inf/mdmiodat.PNF 27208 ..c. r/rr-xr-xr-x 0 0 4639-128-3 /WINDOWS/inf/mdmintel.PNF 28908 ..c. r/rr-xr-xr-x 0 0 4640-128-3 /WINDOWS/inf/mdminfot.PNF 102152 ..c. r/rr-xr-xr-x 0 0 4641-128-3 /WINDOWS/inf/mdmhayes.PNF 69848 ..c. r/rr-xr-xr-x 0 0 4642-128-3 /WINDOWS/inf/mdmhay2.PNF 59556 ..c. r/rr-xr-xr-x 0 0 4643-128-3 /WINDOWS/inf/mdmhandy.PNF 152828 ..c. r/rr-xr-xr-x 0 0 4644-128-3 /WINDOWS/inf/mdmhamrw.PNF 8560 ..c. r/rr-xr-xr-x 0 0 4645-128-3 /WINDOWS/inf/mdmhaeu.PNF 29512 ..c. r/rr-xr-xr-x 0 0 4646-128-3 /WINDOWS/inf/mdmgsm.PNF 93596 ..c. r/rr-xr-xr-x 0 0 4647-128-3 /WINDOWS/inf/mdmgl010.PNF 157264 ..c. r/rr-xr-xr-x 0 0 4648-128-3 /WINDOWS/inf/mdmgl009.PNF 57572 ..c. r/rr-xr-xr-x 0 0 4649-128-3 /WINDOWS/inf/mdmgl008.PNF 151716 ..c. r/rr-xr-xr-x 0 0 4650-128-3 /WINDOWS/inf/mdmgl007.PNF 96712 ..c. r/rr-xr-xr-x 0 0 4651-128-3 /WINDOWS/inf/mdmgl006.PNF 82384 ..c. r/rr-xr-xr-x 0 0 4652-128-3 /WINDOWS/inf/mdmgl005.PNF 1597336 ..c. r/rr-xr-xr-x 0 0 4653-128-3 /WINDOWS/inf/mdmgl004.PNF 59372 ..c. r/rr-xr-xr-x 0 0 4654-128-3 /WINDOWS/inf/mdmgl003.PNF 89852 ..c. r/rr-xr-xr-x 0 0 4655-128-3 /WINDOWS/inf/mdmgl002.PNF 77228 ..c. r/rr-xr-xr-x 0 0 4656-128-3 /WINDOWS/inf/mdmgl001.PNF 72016 ..c. r/rr-xr-xr-x 0 0 4657-128-3 /WINDOWS/inf/mdmgen.PNF 42676 ..c. r/rr-xr-xr-x 0 0 4658-128-3 /WINDOWS/inf/mdmgcs.PNF 69540 ..c. r/rr-xr-xr-x 0 0 4659-128-3 /WINDOWS/inf/mdmgatew.PNF 29762 ..c. r/rr-xr-xr-x 0 0 466-128-3 /WINDOWS/Help/diagboot.chm 21124 ..c. r/rr-xr-xr-x 0 0 4660-128-3 /WINDOWS/inf/mdmfj2.PNF 47316 ..c. r/rr-xr-xr-x 0 0 4661-128-3 /WINDOWS/inf/mdmexp.PNF 62708 ..c. r/rr-xr-xr-x 0 0 4662-128-3 /WINDOWS/inf/mdmetech.PNF 49228 ..c. r/rr-xr-xr-x 0 0 4663-128-3 /WINDOWS/inf/mdmess.PNF 26872 ..c. r/rr-xr-xr-x 0 0 4664-128-3 /WINDOWS/inf/mdmeric2.PNF 20192 ..c. r/rr-xr-xr-x 0 0 4665-128-3 /WINDOWS/inf/mdmeric.PNF 115112 ..c. r/rr-xr-xr-x 0 0 4666-128-3 /WINDOWS/inf/mdmelsa.PNF 30596 ..c. r/rr-xr-xr-x 0 0 4667-128-3 /WINDOWS/inf/mdmeiger.PNF 57164 ..c. r/rr-xr-xr-x 0 0 4668-128-3 /WINDOWS/inf/mdmdyna.PNF 169544 ..c. r/rr-xr-xr-x 0 0 4669-128-3 /WINDOWS/inf/mdmdsi.PNF 2016 ..c. r/rr-xr-xr-x 0 0 467-128-3 /WINDOWS/inf/digiasyn.inf 17500 ..c. r/rr-xr-xr-x 0 0 4670-128-3 /WINDOWS/inf/mdmdp2.PNF 31784 ..c. r/rr-xr-xr-x 0 0 4671-128-3 /WINDOWS/inf/mdmdigi.PNF 20052 ..c. r/rr-xr-xr-x 0 0 4672-128-3 /WINDOWS/inf/mdmdgitn.PNF 20368 ..c. r/rr-xr-xr-x 0 0 4673-128-3 /WINDOWS/inf/mdmdgden.PNF 24624 ..c. r/rr-xr-xr-x 0 0 4674-128-3 /WINDOWS/inf/mdmdf56F.PNF 34084 ..c. r/rr-xr-xr-x 0 0 4675-128-3 /WINDOWS/inf/mdmdcm6.PNF 77992 ..c. r/rr-xr-xr-x 0 0 4676-128-3 /WINDOWS/inf/mdmdcm5.PNF 628064 ..c. r/rr-xr-xr-x 0 0 4677-128-3 /WINDOWS/inf/mdmcxsft.PNF 68340 ..c. r/rr-xr-xr-x 0 0 4678-128-3 /WINDOWS/inf/mdmcxsf2.PNF 21372 ..c. r/rr-xr-xr-x 0 0 4679-128-3 /WINDOWS/inf/mdmcrtix.PNF 3146 ..c. r/rr-xr-xr-x 0 0 468-128-3 /WINDOWS/inf/digiisdn.inf 13828 ..c. r/rr-xr-xr-x 0 0 4680-128-3 /WINDOWS/inf/mdmcpv.PNF 47576 ..c. r/rr-xr-xr-x 0 0 4681-128-3 /WINDOWS/inf/mdmcpq2.PNF 136128 ..c. r/rr-xr-xr-x 0 0 4682-128-3 /WINDOWS/inf/mdmcpq.PNF 12528 ..c. r/rr-xr-xr-x 0 0 4683-128-3 /WINDOWS/inf/mdmcomp.PNF 10456 ..c. r/rr-xr-xr-x 0 0 4684-128-3 /WINDOWS/inf/mdmcommu.PNF 43240 ..c. r/rr-xr-xr-x 0 0 4685-128-3 /WINDOWS/inf/mdmcom1.PNF 24468 ..c. r/rr-xr-xr-x 0 0 4686-128-3 /WINDOWS/inf/mdmcodex.PNF 91508 ..c. r/rr-xr-xr-x 0 0 4687-128-3 /WINDOWS/inf/mdmcm28.PNF 12544 ..c. r/rr-xr-xr-x 0 0 4688-128-3 /WINDOWS/inf/mdmcdp.PNF 22428 ..c. r/rr-xr-xr-x 0 0 4689-128-3 /WINDOWS/inf/mdmc26a.PNF 12299 ..c. r/rr-xr-xr-x 0 0 469-128-3 /WINDOWS/inf/digimps.inf 26316 ..c. r/rr-xr-xr-x 0 0 4690-128-3 /WINDOWS/inf/mdmbw561.PNF 10516 ..c. r/rr-xr-xr-x 0 0 4691-128-3 /WINDOWS/inf/mdmbug3.PNF 40560 ..c. r/rr-xr-xr-x 0 0 4692-128-3 /WINDOWS/inf/mdmbtmdm.PNF 23888 ..c. r/rr-xr-xr-x 0 0 4693-128-3 /WINDOWS/inf/mdmbsb.PNF 64292 ..c. r/rr-xr-xr-x 0 0 4694-128-3 /WINDOWS/inf/mdmboca.PNF 81048 ..c. r/rr-xr-xr-x 0 0 4695-128-3 /WINDOWS/inf/mdmbcmsm.PNF 21376 ..c. r/rr-xr-xr-x 0 0 4696-128-3 /WINDOWS/inf/mdmaus.PNF 34212 ..c. r/rr-xr-xr-x 0 0 4697-128-3 /WINDOWS/inf/mdmatt.PNF 19568 ..c. r/rr-xr-xr-x 0 0 4698-128-3 /WINDOWS/inf/mdmatm2k.PNF 77752 ..c. r/rr-xr-xr-x 0 0 4699-128-3 /WINDOWS/inf/mdmati.PNF 73882 ..c. r/rr-xr-xr-x 0 0 470-128-3 /WINDOWS/Help/digiras.chm 16420 ..c. r/rr-xr-xr-x 0 0 4700-128-3 /WINDOWS/inf/mdmarn.PNF 43228 ..c. r/rr-xr-xr-x 0 0 4701-128-3 /WINDOWS/inf/mdmarch.PNF 15528 ..c. r/rr-xr-xr-x 0 0 4702-128-3 /WINDOWS/inf/mdmar1.PNF 10968 ..c. r/rr-xr-xr-x 0 0 4703-128-3 /WINDOWS/inf/mdmaiwat.PNF 26676 ..c. r/rr-xr-xr-x 0 0 4704-128-3 /WINDOWS/inf/mdmaiwa5.PNF 105104 ..c. r/rr-xr-xr-x 0 0 4705-128-3 /WINDOWS/inf/mdmaiwa4.PNF 18488 ..c. r/rr-xr-xr-x 0 0 4706-128-3 /WINDOWS/inf/mdmaiwa3.PNF 23988 ..c. r/rr-xr-xr-x 0 0 4707-128-3 /WINDOWS/inf/mdmaiwa.PNF 8824 ..c. r/rr-xr-xr-x 0 0 4708-128-3 /WINDOWS/inf/mdmairte.PNF 15036 ..c. r/rr-xr-xr-x 0 0 4709-128-3 /WINDOWS/inf/mdmadc.PNF 4671 ..c. r/rr-xr-xr-x 0 0 471-128-3 /WINDOWS/inf/digirp.inf 56852 ..c. r/rr-xr-xr-x 0 0 4710-128-3 /WINDOWS/inf/mdm656n5.PNF 43708 ..c. r/rr-xr-xr-x 0 0 4711-128-3 /WINDOWS/inf/mdm5674a.PNF 99404 ..c. r/rr-xr-xr-x 0 0 4712-128-3 /WINDOWS/inf/mdm3mini.PNF 49072 ..c. r/rr-xr-xr-x 0 0 4713-128-3 /WINDOWS/inf/mdm3cpcm.PNF 97624 ..c. r/rr-xr-xr-x 0 0 4714-128-3 /WINDOWS/inf/mdm3com.PNF 17572 ..c. r/rr-xr-xr-x 0 0 4715-128-3 /WINDOWS/inf/mdac.PNF 18592 ..c. r/rr-xr-xr-x 0 0 4716-128-3 /WINDOWS/inf/lwusbhid.PNF 13944 ..c. r/rr-xr-xr-x 0 0 4717-128-3 /WINDOWS/inf/lwngmadi.PNF 24640 ..c. r/rr-xr-xr-x 0 0 4718-128-3 /WINDOWS/inf/ksfilter.PNF 43500 ..c. r/rr-xr-xr-x 0 0 4719-128-3 /WINDOWS/inf/kscaptur.PNF 3999 ..c. r/rr-xr-xr-x 0 0 472-128-3 /WINDOWS/inf/digirprt.inf 91444 ..c. r/rr-xr-xr-x 0 0 4720-128-3 /WINDOWS/inf/ks.PNF 10212 ..c. r/rr-xr-xr-x 0 0 4721-128-3 /WINDOWS/inf/kodak.PNF 10712 ..c. r/rr-xr-xr-x 0 0 4722-128-3 /WINDOWS/inf/kdkscan.PNF 22040 ..c. r/rr-xr-xr-x 0 0 4723-128-3 /WINDOWS/inf/kdk2x0.PNF 11884 ..c. r/rr-xr-xr-x 0 0 4724-128-3 /WINDOWS/inf/irtos4mo.PNF 9148 ..c. r/rr-xr-xr-x 0 0 4725-128-3 /WINDOWS/inf/irstusb.PNF 26132 ..c. r/rr-xr-xr-x 0 0 4726-128-3 /WINDOWS/inf/irnsc.PNF 8948 ..c. r/rr-xr-xr-x 0 0 4727-128-3 /WINDOWS/inf/irmk7w2k.PNF 15440 ..c. r/rr-xr-xr-x 0 0 4728-128-3 /WINDOWS/inf/irdasmc.PNF 8884 ..c. r/rr-xr-xr-x 0 0 4729-128-3 /WINDOWS/inf/irdaalif.PNF 20460 ..c. r/rr-xr-xr-x 0 0 473-128-3 /WINDOWS/Help/dijoy.hlp 28188 ..c. r/rr-xr-xr-x 0 0 4730-128-3 /WINDOWS/inf/irbus.PNF 22804 ..c. r/rr-xr-xr-x 0 0 4731-128-3 /WINDOWS/inf/image.PNF 5752 ..c. r/rr-xr-xr-x 0 0 4732-128-3 /WINDOWS/inf/iereset.PNF 83728 ..c. r/rr-xr-xr-x 0 0 4733-128-3 /WINDOWS/inf/ie.PNF 15408 ..c. r/rr-xr-xr-x 0 0 4734-128-3 /WINDOWS/inf/icwnt5.PNF 3260 ..c. r/rr-xr-xr-x 0 0 4735-128-3 /WINDOWS/inf/icminst.PNF 13708 ..c. r/rr-xr-xr-x 0 0 4736-128-3 /WINDOWS/inf/icam5usb.PNF 17876 ..c. r/rr-xr-xr-x 0 0 4737-128-3 /WINDOWS/inf/icam4usb.PNF 13148 ..c. r/rr-xr-xr-x 0 0 4738-128-3 /WINDOWS/inf/icam3.PNF 7984 ..c. r/rr-xr-xr-x 0 0 4739-128-3 /WINDOWS/inf/ibmvcap.PNF 18084 ..c. r/rr-xr-xr-x 0 0 4740-128-3 /WINDOWS/inf/i81xnt5.PNF 8996 ..c. r/rr-xr-xr-x 0 0 4741-128-3 /WINDOWS/inf/i740nt5.PNF 41068 ..c. r/rr-xr-xr-x 0 0 4742-128-3 /WINDOWS/inf/hpscan.PNF 23052 ..c. r/rr-xr-xr-x 0 0 4743-128-3 /WINDOWS/inf/hpojscan.PNF 7024 ..c. r/rr-xr-xr-x 0 0 4744-128-3 /WINDOWS/inf/hpdigwia.PNF 12720 ..c. r/rr-xr-xr-x 0 0 4745-128-3 /WINDOWS/inf/hidserv.PNF 9476 ..c. r/rr-xr-xr-x 0 0 4746-128-3 /WINDOWS/inf/HidDigi.PNF 7780 ..c. r/rr-xr-xr-x 0 0 4747-128-3 /WINDOWS/inf/hidbth.PNF 6796 ..c. r/rr-xr-xr-x 0 0 4748-128-3 /WINDOWS/inf/hdaudbus.PNF 14192 ..c. r/rr-xr-xr-x 0 0 4749-128-3 /WINDOWS/inf/gameport.PNF 11373 ..c. r/rr-xr-xr-x 0 0 475-128-3 /WINDOWS/inf/dimaps.inf 12836 ..c. r/rr-xr-xr-x 0 0 4750-128-3 /WINDOWS/inf/g400.PNF 11868 ..c. r/rr-xr-xr-x 0 0 4751-128-3 /WINDOWS/inf/g200.PNF 2648 ..c. r/rr-xr-xr-x 0 0 4752-128-3 /WINDOWS/inf/fsvgadel.PNF 2648 ..c. r/rr-xr-xr-x 0 0 4753-128-3 /WINDOWS/inf/fsvgaadd.PNF 8580 ..c. r/rr-xr-xr-x 0 0 4754-128-3 /WINDOWS/inf/fsvga.PNF 5004 ..c. r/rr-xr-xr-x 0 0 4755-128-3 /WINDOWS/inf/fltmgr.PNF 23876 ..c. r/rr-xr-xr-x 0 0 4756-128-3 /WINDOWS/inf/fjtscan.PNF 6584 ..c. r/rr-xr-xr-x 0 0 4757-128-3 /WINDOWS/inf/eqnport.PNF 5856 ..c. r/rr-xr-xr-x 0 0 4758-128-3 /WINDOWS/inf/epstw2k.PNF 45632 ..c. r/rr-xr-xr-x 0 0 4759-128-3 /WINDOWS/inf/epsnscan.PNF 11416 ..c. r/rr-xr-xr-x 0 0 4760-128-3 /WINDOWS/inf/epsnmfp.PNF 5872 ..c. r/rr-xr-xr-x 0 0 4761-128-3 /WINDOWS/inf/epcfw2k.PNF 334564 ..c. r/rr-xr-xr-x 0 0 4762-128-3 /WINDOWS/inf/dwup.PNF 26564 ..c. r/rr-xr-xr-x 0 0 4763-128-3 /WINDOWS/inf/dvd.PNF 8664 ..c. r/rr-xr-xr-x 0 0 4764-128-3 /WINDOWS/inf/dshowext.PNF 4084 ..c. r/rr-xr-xr-x 0 0 4765-128-3 /WINDOWS/inf/drm.PNF 23804 ..c. r/rr-xr-xr-x 0 0 4766-128-3 /WINDOWS/inf/divasrv.PNF 33636 ..c. r/rr-xr-xr-x 0 0 4767-128-3 /WINDOWS/inf/divac.PNF 27876 ..c. r/rr-xr-xr-x 0 0 4768-128-3 /WINDOWS/inf/dimaps.PNF 8168 ..c. r/rr-xr-xr-x 0 0 4769-128-3 /WINDOWS/inf/digirprt.PNF 7964 ..c. r/rr-xr-xr-x 0 0 4770-128-3 /WINDOWS/inf/digirp.PNF 16384 ..c. r/rr-xr-xr-x 0 0 4771-128-3 /WINDOWS/inf/digimps.PNF 8384 ..c. r/rr-xr-xr-x 0 0 4772-128-3 /WINDOWS/inf/digiisdn.PNF 6424 ..c. r/rr-xr-xr-x 0 0 4773-128-3 /WINDOWS/inf/digiasyn.PNF 21904 ..c. r/rr-xr-xr-x 0 0 4774-128-3 /WINDOWS/inf/dgasync.PNF 41668 ..c. r/rr-xr-xr-x 0 0 4775-128-3 /WINDOWS/inf/dgaport.PNF 6604 ..c. r/rr-xr-xr-x 0 0 4776-128-3 /WINDOWS/inf/dfrg.PNF 39396 ..c. r/rr-xr-xr-x 0 0 4777-128-3 /WINDOWS/inf/devxprop.PNF 21792 ..c. r/rr-xr-xr-x 0 0 4778-128-3 /WINDOWS/inf/cyzport.PNF 13352 ..c. r/rr-xr-xr-x 0 0 4779-128-3 /WINDOWS/inf/cyyport.PNF 30063 ..c. r/rr-xr-xr-x 0 0 478-128-3 /WINDOWS/Help/diskmgmt.hlp 6864 ..c. r/rr-xr-xr-x 0 0 4780-128-3 /WINDOWS/inf/cyclom-y.PNF 6732 ..c. r/rr-xr-xr-x 0 0 4781-128-3 /WINDOWS/inf/cyclad-z.PNF 21512 ..c. r/rr-xr-xr-x 0 0 4782-128-3 /WINDOWS/inf/ctmaport.PNF 31012 ..c. r/rr-xr-xr-x 0 0 4783-128-3 /WINDOWS/inf/corelist.PNF 9644 ..c. r/rr-xr-xr-x 0 0 4784-128-3 /WINDOWS/inf/ccdecode.PNF 16020 ..c. r/rr-xr-xr-x 0 0 4785-128-3 /WINDOWS/inf/camvid30.PNF 17268 ..c. r/rr-xr-xr-x 0 0 4786-128-3 /WINDOWS/inf/camvid20.PNF 11180 ..c. r/rr-xr-xr-x 0 0 4787-128-3 /WINDOWS/inf/camdsh20.PNF 5972 ..c. r/rr-xr-xr-x 0 0 4788-128-3 /WINDOWS/inf/bthspp.PNF 6224 ..c. r/rr-xr-xr-x 0 0 4789-128-3 /WINDOWS/inf/bthprint.PNF 152138 ..c. r/rr-xr-xr-x 0 0 479-128-3 /WINDOWS/Help/diskmgmt.chm 8032 ..c. r/rr-xr-xr-x 0 0 4790-128-3 /WINDOWS/inf/bthpan.PNF 15312 ..c. r/rr-xr-xr-x 0 0 4791-128-3 /WINDOWS/inf/brmfport.PNF 37336 ..c. r/rr-xr-xr-x 0 0 4792-128-3 /WINDOWS/inf/brmfcwia.PNF 8648 ..c. r/rr-xr-xr-x 0 0 4793-128-3 /WINDOWS/inf/brmfcumd.PNF 8924 ..c. r/rr-xr-xr-x 0 0 4794-128-3 /WINDOWS/inf/brmfcsto.PNF 66232 ..c. r/rr-xr-xr-x 0 0 4795-128-3 /WINDOWS/inf/brmfcmf.PNF 47528 ..c. r/rr-xr-xr-x 0 0 4796-128-3 /WINDOWS/inf/brmfcmdm.PNF 69256 ..c. r/rr-xr-xr-x 0 0 4797-128-3 /WINDOWS/inf/biosinfo.PNF 20236 ..c. r/rr-xr-xr-x 0 0 4798-128-3 /WINDOWS/inf/bda.PNF 9908 ..c. r/rr-xr-xr-x 0 0 4799-128-3 /WINDOWS/inf/banshee.PNF 48 .a.. d/dr-xr-xr-x 0 0 48-144-1 /WINDOWS/Config 4428 ..c. r/rr-xr-xr-x 0 0 4800-128-3 /WINDOWS/inf/axant5.PNF 33304 ..c. r/rr-xr-xr-x 0 0 4801-128-3 /WINDOWS/inf/avmisdn.PNF 14772 ..c. r/rr-xr-xr-x 0 0 4802-128-3 /WINDOWS/inf/au.PNF 45784 ..c. r/rr-xr-xr-x 0 0 4803-128-3 /WINDOWS/inf/atixpwdm.PNF 41732 ..c. r/rr-xr-xr-x 0 0 4804-128-3 /WINDOWS/inf/atividin.PNF 9420 ..c. r/rr-xr-xr-x 0 0 4805-128-3 /WINDOWS/inf/atirage3.PNF 38636 ..c. r/rr-xr-xr-x 0 0 4806-128-3 /WINDOWS/inf/atimpab.PNF 29316 ..c. r/rr-xr-xr-x 0 0 4807-128-3 /WINDOWS/inf/atim128.PNF 94532 ..c. r/rr-xr-xr-x 0 0 4808-128-3 /WINDOWS/inf/atiixpag.PNF 29012 ..c. r/rr-xr-xr-x 0 0 4809-128-3 /WINDOWS/inf/atiixpaa.PNF 43280 ..c. r/rr-xr-xr-x 0 0 4810-128-3 /WINDOWS/inf/ati1xwdm.PNF 13628 ..c. r/rr-xr-xr-x 0 0 4811-128-3 /WINDOWS/inf/asynceqn.PNF 3188 ..c. r/rr-xr-xr-x 0 0 4812-128-3 /WINDOWS/inf/asroc.PNF 109404 ..c. r/rr-xr-xr-x 0 0 4813-128-3 /WINDOWS/inf/apps.PNF 2856 ..c. r/rr-xr-xr-x 0 0 4814-128-3 /WINDOWS/inf/appmig.PNF 8428 ..c. r/rr-xr-xr-x 0 0 4815-128-3 /WINDOWS/inf/apcompat.PNF 17232 ..c. r/rr-xr-xr-x 0 0 4816-128-3 /WINDOWS/inf/agtinst.PNF 10768 ..c. r/rr-xr-xr-x 0 0 4817-128-3 /WINDOWS/inf/agp.PNF 6452 ..c. r/rr-xr-xr-x 0 0 4818-128-3 /WINDOWS/inf/adm_port.PNF 8248 ..c. r/rr-xr-xr-x 0 0 4819-128-3 /WINDOWS/inf/adm_mult.PNF 46969 ..c. r/rr-xr-xr-x 0 0 482-128-3 /WINDOWS/Help/display.chm 12512 ..c. r/rr-xr-xr-x 0 0 4820-128-3 /WINDOWS/inf/acpi.PNF 10284 ..c. r/rr-xr-xr-x 0 0 4821-128-3 /WINDOWS/inf/acerscan.PNF 28828 ..c. r/rr-xr-xr-x 0 0 4822-128-3 /WINDOWS/inf/3dfxvs2k.PNF 2312 ..c. r/rr-xr-xr-x 0 0 4823-128-3 /WINDOWS/inf/mdmchipv.PNF 5504 ..c. r/rr-xr-xr-x 0 0 4827-128-3 /WINDOWS/system32/drivers/intelide.sys 28672 ..c. r/rr-xr-xr-x 0 0 4828-128-3 /WINDOWS/system32/drivers/nscirda.sys 51408 ..c. r/rr-xr-xr-x 0 0 483-128-3 /WINDOWS/Help/display.hlp 88192 ..c. r/rr-xr-xr-x 0 0 4831-128-3 /WINDOWS/system32/drivers/irda.sys 15906 ..c. r/rr-xr-xr-x 0 0 4833-128-3 /WINDOWS/Media/Ir_begin.wav 42728 ..c. r/rr-xr-xr-x 0 0 4834-128-3 /WINDOWS/Media/ir_end.wav 75508 ..c. r/rr-xr-xr-x 0 0 4835-128-3 /WINDOWS/Media/ir_inter.wav 19584 ..c. r/rr-xr-xr-x 0 0 4836-128-3 /WINDOWS/system32/drivers/rasirda.sys 13952 ..c. r/rr-xr-xr-x 0 0 4837-128-3 /WINDOWS/system32/drivers/CmBatt.sys 14208 ..c. r/rr-xr-xr-x 0 0 4838-128-3 /WINDOWS/system32/drivers/battc.sys 10240 ..c. r/rr-xr-xr-x 0 0 4839-128-3 /WINDOWS/system32/drivers/compbatt.sys 33702 ..c. r/rr-xr-xr-x 0 0 484-128-3 /WINDOWS/inf/display.inf 57600 ..c. r/rr-xr-xr-x 0 0 4840-128-3 /WINDOWS/system32/drivers/redbook.sys 3072 ..c. r/rr-xr-xr-x 0 0 4845-128-3 /WINDOWS/system32/drivers/audstub.sys 2557 ..c. r/rr-xr-xr-x 0 0 4848-128-3 /WINDOWS/Debug/NetSetup.LOG 34296 ..c. r/rr-xr-xr-x 0 0 485-128-3 /WINDOWS/Help/dkconcepts.chm 1056768 ..c. r/rr-xr-xr-x 0 0 4850-128-3 /WINDOWS/security/tmp.edb 56 .ac. d/d--x--x--x 0 0 4852-144-6 /Documents and Settings/All Users/Start Menu/Programs/Accessories 48 .ac. d/d--x--x--x 0 0 4853-144-6 /Documents and Settings/All Users/Start Menu/Programs/Accessories/Communications 1757 ..c. r/rr-xr-xr-x 0 0 4854-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Communications/Network Connections.lnk 1646 ..c. r/rr-xr-xr-x 0 0 4856-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Communications/New Connection Wizard.lnk 152 .ac. d/d--x--x--x 0 0 4859-144-1 /Documents and Settings/All Users/Documents/My Videos 40840 ..c. r/rr-xr-xr-x 0 0 4862-128-3 /WINDOWS/system32/drivers/termdd.sys 196224 ..c. r/rr-xr-xr-x 0 0 4863-128-3 /WINDOWS/system32/drivers/rdpdr.sys 56 .a.. d/dr-xr-xr-x 0 0 49-144-5 /WINDOWS/msagent 294912 ..c. r/rr-xr-xr-x 0 0 492-128-3 /WINDOWS/system32/ias/dnary.mdb 56 .a.. d/dr-xr-xr-x 0 0 4938-144-5 /WINDOWS/system32/Com 195072 ..c. r/rr-xr-xr-x 0 0 4939-128-3 /WINDOWS/system32/Com/comadmin.dll 9728 ..c. r/rr-xr-xr-x 0 0 4944-128-3 /WINDOWS/system32/Com/comrepl.exe 6144 ..c. r/rr-xr-xr-x 0 0 4945-128-3 /WINDOWS/system32/Com/comrereg.exe 1498 ..c. r/rr-xr-xr-x 0 0 4946-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Calculator.lnk 269916 ..c. r/rr-xr-xr-x 0 0 4947-128-3 /WINDOWS/Help/comexp.chm 42416 ..c. r/rr-xr-xr-x 0 0 495-128-3 /WINDOWS/inf/dot4.inf 248 .a.. d/dr-xr-xr-x 0 0 4955-144-1 /WINDOWS/system32/MsDtc 376 .ac. d/dr-xr-xr-x 0 0 4956-144-1 /WINDOWS/system32/MsDtc/Trace 27818 ..c. r/rr-xr-xr-x 0 0 4957-128-3 /WINDOWS/system32/MsDtc/Trace/msdtctr.mof 2243 ..c. r/rr-xr-xr-x 0 0 496-128-3 /WINDOWS/inf/dot4prt.inf 139656 ..c. r/rr-xr-xr-x 0 0 4976-128-3 /WINDOWS/system32/drivers/rdpwd.sys 12040 ..c. r/rr-xr-xr-x 0 0 4977-128-3 /WINDOWS/system32/drivers/tdpipe.sys 21896 ..c. r/rr-xr-xr-x 0 0 4978-128-3 /WINDOWS/system32/drivers/tdtcp.sys 728 .a.. d/dr-xr-xr-x 0 0 4981-144-1 /WINDOWS/system32/en-US 49152 ..c. r/r--x--x--x 0 0 4982-128-3 /WINDOWS/system32/en-US/mstsc.exe.mui 86016 ..c. r/rr-xr-xr-x 0 0 4983-128-3 /WINDOWS/system32/en-US/mstscax.dll.mui 4096 ..c. r/rr-xr-xr-x 0 0 4984-128-3 /WINDOWS/system32/en-US/aaclient.dll.mui 45590 ..c. r/rr-xr-xr-x 0 0 4988-128-3 /WINDOWS/Help/mspaint.chm 19181 ..c. r/rr-xr-xr-x 0 0 4989-128-3 /WINDOWS/Help/mspaint.hlp 56 .ac. d/dr-xr-xr-x 0 0 4990-144-6 /Program Files/Windows NT 539136 ..c. r/rr-xr-xr-x 0 0 4991-128-3 /Program Files/Windows NT/dialer.exe 280 .ac. d/dr-xr-xr-x 0 0 4997-144-5 /Program Files/Windows NT/Pinball 281088 ..c. r/rr-xr-xr-x 0 0 4998-128-3 /Program Files/Windows NT/Pinball/PINBALL.EXE 464 .ac. d/dr-xr-xr-x 0 0 4999-144-1 /Program Files/Windows NT/Accessories 56 .ac. d/dr-xr-xr-x 0 0 50-144-5 /WINDOWS/msagent/intl 214528 ..c. r/rr-xr-xr-x 0 0 5000-128-3 /Program Files/Windows NT/Accessories/wordpad.exe 186880 ..c. r/rr-xr-xr-x 0 0 5001-128-3 /Program Files/Windows NT/Accessories/mswrd6.wpc 279552 ..c. r/rr-xr-xr-x 0 0 5002-128-3 /Program Files/Windows NT/Accessories/mswrd8.wpc 89088 ..c. r/rr-xr-xr-x 0 0 5003-128-3 /Program Files/Windows NT/Accessories/write.wpc 264 .ac. d/dr-xr-xr-x 0 0 5004-144-1 /Program Files/MSN 240 .ac. d/dr-xr-xr-x 0 0 5005-144-1 /Program Files/MSN/MSNCoreFiles 680 .ac. d/dr-xr-xr-x 0 0 5006-144-1 /Program Files/MSN/MSNCoreFiles/Install 19322 ..c. r/rr-xr-xr-x 0 0 5007-128-3 /Program Files/MSN/MSNCoreFiles/Install/cinfo.xml 1327320 ..c. r/rr-xr-xr-x 0 0 5008-128-3 /Program Files/MSN/MSNCoreFiles/Install/msnsusii.exe 25214 ..c. r/rr-xr-xr-x 0 0 5009-128-3 /Program Files/MSN/MSNCoreFiles/Install/msnms.ico 496 ..c. r/rr-xr-xr-x 0 0 5010-128-1 /Program Files/MSN/MSNCoreFiles/Install/xfp.xml 576 .ac. d/dr-xr-xr-x 0 0 5011-144-1 /Program Files/MSN/MSNCoreFiles/Install/MSN9Components 11053008 ..c. r/rr-xr-xr-x 0 0 5012-128-3 /Program Files/MSN/MSNCoreFiles/Install/MSN9Components/Msncli.exe 884712 ..c. r/rr-xr-xr-x 0 0 5013-128-3 /Program Files/MSN/MSNCoreFiles/Install/MSN9Components/Digcore.exe 863232 ..c. r/rr-xr-xr-x 0 0 5014-128-3 /Program Files/MSN/MSNCoreFiles/Install/MSN9Components/digopt.msi 366080 ..c. r/rr-xr-xr-x 0 0 5015-128-3 /Program Files/MSN/MSNCoreFiles/Install/MSN9Components/digreqEx.msi 5080576 ..c. r/rr-xr-xr-x 0 0 5016-128-3 /Program Files/MSN/MSNCoreFiles/Install/MSN9Components/msnmsgs.msi 688 .ac. d/dr-xr-xr-x 0 0 5017-144-1 /Program Files/MSN/MSNCoreFiles/OOBE 185922 ..c. r/rr-xr-xr-x 0 0 5018-128-3 /Program Files/MSN/MSNCoreFiles/OOBE/market.mar 229376 ..c. r/rr-xr-xr-x 0 0 5019-128-3 /Program Files/MSN/MSNCoreFiles/OOBE/obelog.dll 62720038 ..c. r/rr-xr-xr-x 0 0 502-128-3 /WINDOWS/Driver Cache/i386/driver.cab 966656 ..c. r/rr-xr-xr-x 0 0 5020-128-3 /Program Files/MSN/MSNCoreFiles/OOBE/obemetal.dll 77824 ..c. r/rr-xr-xr-x 0 0 5021-128-3 /Program Files/MSN/MSNCoreFiles/OOBE/obemtllc.dll 86016 ..c. r/rr-xr-xr-x 0 0 5022-128-3 /Program Files/MSN/MSNCoreFiles/OOBE/obepopc.dll 466954 ..c. r/rr-xr-xr-x 0 0 5023-128-3 /Program Files/MSN/MSNCoreFiles/OOBE/signup.mar 12817 ..c. r/rr-xr-xr-x 0 0 503-128-3 /WINDOWS/Help/drvvfp.chm 20406 ..c. r/rr-xr-xr-x 0 0 505-128-3 /WINDOWS/Help/drwtsn32.chm 14161 ..c. r/rr-xr-xr-x 0 0 507-128-3 /WINDOWS/Help/drwtsn32.hlp 20220 ..c. r/rr-xr-xr-x 0 0 509-128-3 /WINDOWS/Help/dsclient.hlp 56 .a.. d/dr-xr-xr-x 0 0 51-144-6 /WINDOWS/Cursors 17396 ..c. r/rr-xr-xr-x 0 0 510-128-3 /WINDOWS/Help/dskquoui.hlp 78048 ..c. r/rr-xr-xr-x 0 0 5100-128-3 /WINDOWS/system32/Com/comexp.msc 61440 ..c. r/rr-xr-xr-x 0 0 5101-128-3 /WINDOWS/system32/Com/comempty.dat 19456 ..c. r/rr-xr-xr-x 0 0 5102-128-3 /WINDOWS/system32/Com/mtsadmin.tlb 47768 ..c. r/rr-xr-xr-x 0 0 5103-128-3 /WINDOWS/Help/comexp.hlp 19429 ..c. r/rr-xr-xr-x 0 0 5106-128-3 /WINDOWS/system32/MsDtc/Trace/msdtcvtr.bat 15803 ..c. r/rr-xr-xr-x 0 0 5125-128-3 /WINDOWS/Help/freecell.chm 12457 ..c. r/rr-xr-xr-x 0 0 5126-128-3 /WINDOWS/Help/freecell.hlp 15051 ..c. r/rr-xr-xr-x 0 0 5128-128-3 /WINDOWS/Help/mshearts.chm 16592 ..c. r/rr-xr-xr-x 0 0 513-128-3 /WINDOWS/inf/dvd.inf 15071 ..c. r/rr-xr-xr-x 0 0 5130-128-3 /WINDOWS/Help/winmine.chm 11476 ..c. r/rr-xr-xr-x 0 0 5131-128-3 /WINDOWS/Help/winmine.hlp 16962 ..c. r/rr-xr-xr-x 0 0 5133-128-3 /WINDOWS/Help/sol.chm 13517 ..c. r/rr-xr-xr-x 0 0 5134-128-3 /WINDOWS/Help/sol.hlp 15961 ..c. r/rr-xr-xr-x 0 0 5135-128-3 /WINDOWS/Help/spider.chm 24551 ..c. r/rr-xr-xr-x 0 0 5137-128-3 /WINDOWS/Help/calc.chm 32195 ..c. r/rr-xr-xr-x 0 0 5138-128-3 /WINDOWS/Help/calc.hlp 21704 ..c. r/rr-xr-xr-x 0 0 5149-128-3 /WINDOWS/Help/charmap.chm 10496 ..c. r/rr-xr-xr-x 0 0 515-128-3 /WINDOWS/system32/drivers/dxapi.sys 12961 ..c. r/rr-xr-xr-x 0 0 5150-128-3 /WINDOWS/Help/charmap.hlp 55632 ..c. r/rr-xr-xr-x 0 0 516-128-3 /WINDOWS/system32/1033/dwintl.dll 7962 ..c. r/rr-xr-xr-x 0 0 5162-128-3 /WINDOWS/Cursors/appstar2.ani 7856 ..c. r/rr-xr-xr-x 0 0 5163-128-3 /WINDOWS/Cursors/appstar3.ani 7954 ..c. r/rr-xr-xr-x 0 0 5164-128-3 /WINDOWS/Cursors/appstart.ani 11904 ..c. r/rr-xr-xr-x 0 0 5165-128-3 /WINDOWS/Cursors/banana.ani 8660 ..c. r/rr-xr-xr-x 0 0 5166-128-3 /WINDOWS/Cursors/barber.ani 7114 ..c. r/rr-xr-xr-x 0 0 5167-128-3 /WINDOWS/Cursors/coin.ani 6832 ..c. r/rr-xr-xr-x 0 0 5168-128-3 /WINDOWS/Cursors/counter.ani 4804 ..c. r/rr-xr-xr-x 0 0 5169-128-3 /WINDOWS/Cursors/dinosau2.ani 4804 ..c. r/rr-xr-xr-x 0 0 5170-128-3 /WINDOWS/Cursors/dinosaur.ani 3240 ..c. r/rr-xr-xr-x 0 0 5171-128-3 /WINDOWS/Cursors/drum.ani 14936 ..c. r/rr-xr-xr-x 0 0 5172-128-3 /WINDOWS/Cursors/fillitup.ani 3292 ..c. r/rr-xr-xr-x 0 0 5173-128-3 /WINDOWS/Cursors/hand.ani 6356 ..c. r/rr-xr-xr-x 0 0 5174-128-3 /WINDOWS/Cursors/handapst.ani 1700 ..c. r/rr-xr-xr-x 0 0 5175-128-3 /WINDOWS/Cursors/handnesw.ani 4066 ..c. r/rr-xr-xr-x 0 0 5176-128-3 /WINDOWS/Cursors/handno.ani 1698 ..c. r/rr-xr-xr-x 0 0 5177-128-3 /WINDOWS/Cursors/handns.ani 1700 ..c. r/rr-xr-xr-x 0 0 5178-128-3 /WINDOWS/Cursors/handnwse.ani 7530 ..c. r/rr-xr-xr-x 0 0 5179-128-3 /WINDOWS/Cursors/handwait.ani 8384 ..c. r/rr-xr-xr-x 0 0 518-128-3 /WINDOWS/Fonts/ega40850.fon 1698 ..c. r/rr-xr-xr-x 0 0 5180-128-3 /WINDOWS/Cursors/handwe.ani 18722 ..c. r/rr-xr-xr-x 0 0 5181-128-3 /WINDOWS/Cursors/horse.ani 11832 ..c. r/rr-xr-xr-x 0 0 5182-128-3 /WINDOWS/Cursors/hourgla2.ani 11830 ..c. r/rr-xr-xr-x 0 0 5183-128-3 /WINDOWS/Cursors/hourgla3.ani 11824 ..c. r/rr-xr-xr-x 0 0 5184-128-3 /WINDOWS/Cursors/hourglas.ani 5674 ..c. r/rr-xr-xr-x 0 0 5185-128-3 /WINDOWS/Cursors/metronom.ani 4100 ..c. r/rr-xr-xr-x 0 0 5186-128-3 /WINDOWS/Cursors/piano.ani 9824 ..c. r/rr-xr-xr-x 0 0 5187-128-3 /WINDOWS/Cursors/rainbow.ani 4826 ..c. r/rr-xr-xr-x 0 0 5188-128-3 /WINDOWS/Cursors/raindrop.ani 818 ..c. r/rr-xr-xr-x 0 0 5189-128-3 /WINDOWS/Cursors/sizenesw.ani 5328 ..c. r/rr-xr-xr-x 0 0 519-128-3 /WINDOWS/Fonts/ega80850.fon 818 ..c. r/rr-xr-xr-x 0 0 5190-128-3 /WINDOWS/Cursors/sizens.ani 818 ..c. r/rr-xr-xr-x 0 0 5191-128-3 /WINDOWS/Cursors/sizenwse.ani 818 ..c. r/rr-xr-xr-x 0 0 5192-128-3 /WINDOWS/Cursors/sizewe.ani 6712 ..c. r/rr-xr-xr-x 0 0 5193-128-3 /WINDOWS/Cursors/stopwtch.ani 1894 ..c. r/rr-xr-xr-x 0 0 5194-128-3 /WINDOWS/Cursors/vanisher.ani 2548 ..c. r/rr-xr-xr-x 0 0 5195-128-3 /WINDOWS/Cursors/wagtail.ani 766 ..c. r/rr-xr-xr-x 0 0 5196-128-3 /WINDOWS/Cursors/3dgarro.cur 766 ..c. r/rr-xr-xr-x 0 0 5197-128-3 /WINDOWS/Cursors/3dgmove.cur 766 ..c. r/rr-xr-xr-x 0 0 5198-128-3 /WINDOWS/Cursors/3dgnesw.cur 766 ..c. r/rr-xr-xr-x 0 0 5199-128-3 /WINDOWS/Cursors/3dgno.cur 320 .a.. d/dr-xr-xr-x 0 0 52-144-5 /WINDOWS/Media 37251 ..c. r/rr-xr-xr-x 0 0 520-128-3 /WINDOWS/Help/els.hlp 766 ..c. r/rr-xr-xr-x 0 0 5200-128-3 /WINDOWS/Cursors/3dgns.cur 766 ..c. r/rr-xr-xr-x 0 0 5201-128-3 /WINDOWS/Cursors/3dgnwse.cur 766 ..c. r/rr-xr-xr-x 0 0 5202-128-3 /WINDOWS/Cursors/3dgwe.cur 766 ..c. r/rr-xr-xr-x 0 0 5203-128-3 /WINDOWS/Cursors/3dsmove.cur 766 ..c. r/rr-xr-xr-x 0 0 5204-128-3 /WINDOWS/Cursors/3dsns.cur 766 ..c. r/rr-xr-xr-x 0 0 5205-128-3 /WINDOWS/Cursors/3dsnwse.cur 766 ..c. r/rr-xr-xr-x 0 0 5206-128-3 /WINDOWS/Cursors/3dwarro.cur 766 ..c. r/rr-xr-xr-x 0 0 5207-128-3 /WINDOWS/Cursors/3dwmove.cur 766 ..c. r/rr-xr-xr-x 0 0 5208-128-3 /WINDOWS/Cursors/3dwnesw.cur 766 ..c. r/rr-xr-xr-x 0 0 5209-128-3 /WINDOWS/Cursors/3dwno.cur 14805 ..c. r/rr-xr-xr-x 0 0 521-128-3 /WINDOWS/Help/els.chm 766 ..c. r/rr-xr-xr-x 0 0 5210-128-3 /WINDOWS/Cursors/3dwns.cur 766 ..c. r/rr-xr-xr-x 0 0 5211-128-3 /WINDOWS/Cursors/3dwnwse.cur 766 ..c. r/rr-xr-xr-x 0 0 5212-128-3 /WINDOWS/Cursors/3dwwe.cur 766 ..c. r/rr-xr-xr-x 0 0 5213-128-3 /WINDOWS/Cursors/cross.cur 766 ..c. r/rr-xr-xr-x 0 0 5214-128-3 /WINDOWS/Cursors/harrow.cur 766 ..c. r/rr-xr-xr-x 0 0 5215-128-3 /WINDOWS/Cursors/hcross.cur 766 ..c. r/rr-xr-xr-x 0 0 5216-128-3 /WINDOWS/Cursors/hibeam.cur 766 ..c. r/rr-xr-xr-x 0 0 5217-128-3 /WINDOWS/Cursors/hmove.cur 766 ..c. r/rr-xr-xr-x 0 0 5218-128-3 /WINDOWS/Cursors/hnesw.cur 766 ..c. r/rr-xr-xr-x 0 0 5219-128-3 /WINDOWS/Cursors/hnodrop.cur 56065 ..c. r/rr-xr-xr-x 0 0 522-128-3 /WINDOWS/Help/encrypt.chm 766 ..c. r/rr-xr-xr-x 0 0 5220-128-3 /WINDOWS/Cursors/hns.cur 766 ..c. r/rr-xr-xr-x 0 0 5221-128-3 /WINDOWS/Cursors/hnwse.cur 766 ..c. r/rr-xr-xr-x 0 0 5222-128-3 /WINDOWS/Cursors/hwe.cur 766 ..c. r/rr-xr-xr-x 0 0 5223-128-3 /WINDOWS/Cursors/lappstrt.cur 766 ..c. r/rr-xr-xr-x 0 0 5224-128-3 /WINDOWS/Cursors/larrow.cur 766 ..c. r/rr-xr-xr-x 0 0 5225-128-3 /WINDOWS/Cursors/lcross.cur 766 ..c. r/rr-xr-xr-x 0 0 5226-128-3 /WINDOWS/Cursors/libeam.cur 766 ..c. r/rr-xr-xr-x 0 0 5227-128-3 /WINDOWS/Cursors/lmove.cur 766 ..c. r/rr-xr-xr-x 0 0 5228-128-3 /WINDOWS/Cursors/lnesw.cur 766 ..c. r/rr-xr-xr-x 0 0 5229-128-3 /WINDOWS/Cursors/lnodrop.cur 1535 ..c. r/rr-xr-xr-x 0 0 523-128-3 /WINDOWS/inf/enum1394.inf 766 ..c. r/rr-xr-xr-x 0 0 5230-128-3 /WINDOWS/Cursors/lns.cur 766 ..c. r/rr-xr-xr-x 0 0 5231-128-3 /WINDOWS/Cursors/lnwse.cur 766 ..c. r/rr-xr-xr-x 0 0 5232-128-3 /WINDOWS/Cursors/lwait.cur 766 ..c. r/rr-xr-xr-x 0 0 5233-128-3 /WINDOWS/Cursors/lwe.cur 4570 ..c. r/rr-xr-xr-x 0 0 5234-128-3 /Documents and Settings/Default User/Templates/amipro.sam 5632 ..c. r/rr-xr-xr-x 0 0 5235-128-3 /Documents and Settings/Default User/Templates/excel.xls 1518 ..c. r/rr-xr-xr-x 0 0 5236-128-3 /Documents and Settings/Default User/Templates/excel4.xls 2448 ..c. r/rr-xr-xr-x 0 0 5237-128-3 /Documents and Settings/Default User/Templates/lotus.wk4 12288 ..c. r/rr-xr-xr-x 0 0 5238-128-3 /Documents and Settings/Default User/Templates/powerpnt.ppt 461 ..c. r/rr-xr-xr-x 0 0 5239-128-1 /Documents and Settings/Default User/Templates/presenta.shw 1533 ..c. r/rr-xr-xr-x 0 0 524-128-3 /WINDOWS/inf/epcfw2k.inf 4017 ..c. r/rr-xr-xr-x 0 0 5240-128-3 /Documents and Settings/Default User/Templates/quattro.wb2 58 ..c. r/rr-xr-xr-x 0 0 5241-128-1 /Documents and Settings/Default User/Templates/sndrec.wav 4608 ..c. r/rr-xr-xr-x 0 0 5242-128-3 /Documents and Settings/Default User/Templates/winword.doc 1769 ..c. r/rr-xr-xr-x 0 0 5243-128-3 /Documents and Settings/Default User/Templates/winword2.doc 30 ..c. r/r--x--x--x 0 0 5244-128-1 /Documents and Settings/Default User/Templates/wordpfct.wpd 57 ..c. r/r--x--x--x 0 0 5245-128-1 /Documents and Settings/Default User/Templates/wordpfct.wpg 17782 ..c. r/rr-xr-xr-x 0 0 5247-128-3 /WINDOWS/Help/winchat.chm 12377 ..c. r/rr-xr-xr-x 0 0 5248-128-3 /WINDOWS/Help/winchat.hlp 39969 ..c. r/rr-xr-xr-x 0 0 5249-128-3 /WINDOWS/Help/dialer.chm 32707 ..c. r/rr-xr-xr-x 0 0 525-128-3 /WINDOWS/inf/epsnscan.inf 30693 ..c. r/rr-xr-xr-x 0 0 5250-128-3 /WINDOWS/Help/dialer.hlp 28160 ..c. r/rr-xr-xr-x 0 0 5254-128-3 /Program Files/Windows NT/hypertrm.exe 13312 ..c. r/rr-xr-xr-x 0 0 5255-128-3 /Program Files/Windows NT/htrn_jis.dll 16645 ..c. r/rr-xr-xr-x 0 0 5258-128-3 /WINDOWS/Help/sndvol32.chm 11290 ..c. r/rr-xr-xr-x 0 0 5259-128-3 /WINDOWS/Help/sndvol32.hlp 4985 ..c. r/rr-xr-xr-x 0 0 526-128-3 /WINDOWS/inf/epsnmfp.inf 34032 ..c. r/rr-xr-xr-x 0 0 5260-128-3 /WINDOWS/Help/access.hlp 326 ..c. r/rr-xr-xr-x 0 0 5261-128-1 /WINDOWS/Cursors/arrow_r.cur 766 ..c. r/rr-xr-xr-x 0 0 5262-128-3 /WINDOWS/Cursors/arrow_rl.cur 766 ..c. r/rr-xr-xr-x 0 0 5263-128-3 /WINDOWS/Cursors/arrow_rm.cur 326 ..c. r/rr-xr-xr-x 0 0 5264-128-1 /WINDOWS/Cursors/beam_r.cur 766 ..c. r/rr-xr-xr-x 0 0 5265-128-3 /WINDOWS/Cursors/beam_rl.cur 766 ..c. r/rr-xr-xr-x 0 0 5266-128-3 /WINDOWS/Cursors/beam_rm.cur 326 ..c. r/rr-xr-xr-x 0 0 5267-128-1 /WINDOWS/Cursors/busy_r.cur 766 ..c. r/rr-xr-xr-x 0 0 5268-128-3 /WINDOWS/Cursors/busy_rl.cur 766 ..c. r/rr-xr-xr-x 0 0 5269-128-3 /WINDOWS/Cursors/busy_rm.cur 1417 ..c. r/rr-xr-xr-x 0 0 527-128-3 /WINDOWS/inf/epstw2k.inf 326 ..c. r/rr-xr-xr-x 0 0 5270-128-1 /WINDOWS/Cursors/cross_r.cur 766 ..c. r/rr-xr-xr-x 0 0 5271-128-3 /WINDOWS/Cursors/cross_rl.cur 766 ..c. r/rr-xr-xr-x 0 0 5272-128-3 /WINDOWS/Cursors/cross_rm.cur 326 ..c. r/rr-xr-xr-x 0 0 5273-128-1 /WINDOWS/Cursors/help_r.cur 766 ..c. r/rr-xr-xr-x 0 0 5274-128-3 /WINDOWS/Cursors/help_rl.cur 766 ..c. r/rr-xr-xr-x 0 0 5275-128-3 /WINDOWS/Cursors/help_rm.cur 326 ..c. r/rr-xr-xr-x 0 0 5276-128-1 /WINDOWS/Cursors/move_r.cur 766 ..c. r/rr-xr-xr-x 0 0 5277-128-3 /WINDOWS/Cursors/move_rl.cur 766 ..c. r/rr-xr-xr-x 0 0 5278-128-3 /WINDOWS/Cursors/move_rm.cur 326 ..c. r/rr-xr-xr-x 0 0 5279-128-1 /WINDOWS/Cursors/no_r.cur 766 ..c. r/rr-xr-xr-x 0 0 5280-128-3 /WINDOWS/Cursors/no_rl.cur 766 ..c. r/rr-xr-xr-x 0 0 5281-128-3 /WINDOWS/Cursors/no_rm.cur 326 ..c. r/rr-xr-xr-x 0 0 5282-128-1 /WINDOWS/Cursors/pen_r.cur 766 ..c. r/rr-xr-xr-x 0 0 5283-128-3 /WINDOWS/Cursors/pen_rl.cur 766 ..c. r/rr-xr-xr-x 0 0 5284-128-3 /WINDOWS/Cursors/pen_rm.cur 326 ..c. r/rr-xr-xr-x 0 0 5285-128-1 /WINDOWS/Cursors/size1_r.cur 766 ..c. r/rr-xr-xr-x 0 0 5286-128-3 /WINDOWS/Cursors/size1_rl.cur 766 ..c. r/rr-xr-xr-x 0 0 5287-128-3 /WINDOWS/Cursors/size1_rm.cur 326 ..c. r/rr-xr-xr-x 0 0 5288-128-1 /WINDOWS/Cursors/size2_r.cur 766 ..c. r/rr-xr-xr-x 0 0 5289-128-3 /WINDOWS/Cursors/size2_rl.cur 766 ..c. r/rr-xr-xr-x 0 0 5290-128-3 /WINDOWS/Cursors/size2_rm.cur 326 ..c. r/rr-xr-xr-x 0 0 5291-128-1 /WINDOWS/Cursors/size3_r.cur 766 ..c. r/rr-xr-xr-x 0 0 5292-128-3 /WINDOWS/Cursors/size3_rl.cur 766 ..c. r/rr-xr-xr-x 0 0 5293-128-3 /WINDOWS/Cursors/size3_rm.cur 326 ..c. r/rr-xr-xr-x 0 0 5294-128-1 /WINDOWS/Cursors/size4_r.cur 766 ..c. r/rr-xr-xr-x 0 0 5295-128-3 /WINDOWS/Cursors/size4_rl.cur 766 ..c. r/rr-xr-xr-x 0 0 5296-128-3 /WINDOWS/Cursors/size4_rm.cur 326 ..c. r/rr-xr-xr-x 0 0 5297-128-1 /WINDOWS/Cursors/up_r.cur 326 ..c. r/rr-xr-xr-x 0 0 5298-128-1 /WINDOWS/Cursors/up_rl.cur 326 ..c. r/rr-xr-xr-x 0 0 5299-128-1 /WINDOWS/Cursors/up_rm.cur 248 .a.. d/dr-xr-xr-x 0 0 53-144-1 /WINDOWS/java 326 ..c. r/rr-xr-xr-x 0 0 5300-128-1 /WINDOWS/Cursors/wait_r.cur 766 ..c. r/rr-xr-xr-x 0 0 5301-128-3 /WINDOWS/Cursors/wait_rl.cur 766 ..c. r/rr-xr-xr-x 0 0 5302-128-3 /WINDOWS/Cursors/wait_rm.cur 326 ..c. r/rr-xr-xr-x 0 0 5303-128-1 /WINDOWS/Cursors/arrow_i.cur 766 ..c. r/rr-xr-xr-x 0 0 5304-128-3 /WINDOWS/Cursors/arrow_il.cur 766 ..c. r/rr-xr-xr-x 0 0 5305-128-3 /WINDOWS/Cursors/arrow_im.cur 326 ..c. r/rr-xr-xr-x 0 0 5306-128-1 /WINDOWS/Cursors/beam_i.cur 766 ..c. r/rr-xr-xr-x 0 0 5307-128-3 /WINDOWS/Cursors/beam_il.cur 766 ..c. r/rr-xr-xr-x 0 0 5308-128-3 /WINDOWS/Cursors/beam_im.cur 326 ..c. r/rr-xr-xr-x 0 0 5309-128-1 /WINDOWS/Cursors/busy_i.cur 766 ..c. r/rr-xr-xr-x 0 0 5310-128-3 /WINDOWS/Cursors/busy_il.cur 766 ..c. r/rr-xr-xr-x 0 0 5311-128-3 /WINDOWS/Cursors/busy_im.cur 326 ..c. r/rr-xr-xr-x 0 0 5312-128-1 /WINDOWS/Cursors/cross_i.cur 766 ..c. r/rr-xr-xr-x 0 0 5313-128-3 /WINDOWS/Cursors/cross_il.cur 766 ..c. r/rr-xr-xr-x 0 0 5314-128-3 /WINDOWS/Cursors/cross_im.cur 326 ..c. r/rr-xr-xr-x 0 0 5315-128-1 /WINDOWS/Cursors/help_i.cur 766 ..c. r/rr-xr-xr-x 0 0 5316-128-3 /WINDOWS/Cursors/help_il.cur 766 ..c. r/rr-xr-xr-x 0 0 5317-128-3 /WINDOWS/Cursors/help_im.cur 326 ..c. r/rr-xr-xr-x 0 0 5318-128-1 /WINDOWS/Cursors/move_i.cur 766 ..c. r/rr-xr-xr-x 0 0 5319-128-3 /WINDOWS/Cursors/move_il.cur 766 ..c. r/rr-xr-xr-x 0 0 5320-128-3 /WINDOWS/Cursors/move_im.cur 326 ..c. r/rr-xr-xr-x 0 0 5321-128-1 /WINDOWS/Cursors/no_i.cur 766 ..c. r/rr-xr-xr-x 0 0 5322-128-3 /WINDOWS/Cursors/no_il.cur 766 ..c. r/rr-xr-xr-x 0 0 5323-128-3 /WINDOWS/Cursors/no_im.cur 326 ..c. r/rr-xr-xr-x 0 0 5324-128-1 /WINDOWS/Cursors/pen_i.cur 766 ..c. r/rr-xr-xr-x 0 0 5325-128-3 /WINDOWS/Cursors/pen_il.cur 766 ..c. r/rr-xr-xr-x 0 0 5326-128-3 /WINDOWS/Cursors/pen_im.cur 326 ..c. r/rr-xr-xr-x 0 0 5327-128-1 /WINDOWS/Cursors/size1_i.cur 766 ..c. r/rr-xr-xr-x 0 0 5328-128-3 /WINDOWS/Cursors/size1_il.cur 766 ..c. r/rr-xr-xr-x 0 0 5329-128-3 /WINDOWS/Cursors/size1_im.cur 23754 ..c. r/rr-xr-xr-x 0 0 533-128-3 /WINDOWS/Help/eudcedit.chm 326 ..c. r/rr-xr-xr-x 0 0 5330-128-1 /WINDOWS/Cursors/size2_i.cur 766 ..c. r/rr-xr-xr-x 0 0 5331-128-3 /WINDOWS/Cursors/size2_il.cur 766 ..c. r/rr-xr-xr-x 0 0 5332-128-3 /WINDOWS/Cursors/size2_im.cur 326 ..c. r/rr-xr-xr-x 0 0 5333-128-1 /WINDOWS/Cursors/size3_i.cur 766 ..c. r/rr-xr-xr-x 0 0 5334-128-3 /WINDOWS/Cursors/size3_il.cur 766 ..c. r/rr-xr-xr-x 0 0 5335-128-3 /WINDOWS/Cursors/size3_im.cur 326 ..c. r/rr-xr-xr-x 0 0 5336-128-1 /WINDOWS/Cursors/size4_i.cur 766 ..c. r/rr-xr-xr-x 0 0 5337-128-3 /WINDOWS/Cursors/size4_il.cur 766 ..c. r/rr-xr-xr-x 0 0 5338-128-3 /WINDOWS/Cursors/size4_im.cur 326 ..c. r/rr-xr-xr-x 0 0 5339-128-1 /WINDOWS/Cursors/up_i.cur 18509 ..c. r/rr-xr-xr-x 0 0 534-128-3 /WINDOWS/Help/eudcedit.hlp 326 ..c. r/rr-xr-xr-x 0 0 5340-128-1 /WINDOWS/Cursors/up_il.cur 326 ..c. r/rr-xr-xr-x 0 0 5341-128-1 /WINDOWS/Cursors/up_im.cur 326 ..c. r/rr-xr-xr-x 0 0 5342-128-1 /WINDOWS/Cursors/wait_i.cur 766 ..c. r/rr-xr-xr-x 0 0 5343-128-3 /WINDOWS/Cursors/wait_il.cur 766 ..c. r/rr-xr-xr-x 0 0 5344-128-3 /WINDOWS/Cursors/wait_im.cur 766 ..c. r/rr-xr-xr-x 0 0 5345-128-3 /WINDOWS/Cursors/arrow_l.cur 766 ..c. r/rr-xr-xr-x 0 0 5346-128-3 /WINDOWS/Cursors/arrow_m.cur 766 ..c. r/rr-xr-xr-x 0 0 5347-128-3 /WINDOWS/Cursors/beam_l.cur 766 ..c. r/rr-xr-xr-x 0 0 5348-128-3 /WINDOWS/Cursors/beam_m.cur 766 ..c. r/rr-xr-xr-x 0 0 5349-128-3 /WINDOWS/Cursors/busy_l.cur 766 ..c. r/rr-xr-xr-x 0 0 5350-128-3 /WINDOWS/Cursors/busy_m.cur 766 ..c. r/rr-xr-xr-x 0 0 5351-128-3 /WINDOWS/Cursors/cross_l.cur 766 ..c. r/rr-xr-xr-x 0 0 5352-128-3 /WINDOWS/Cursors/cross_m.cur 766 ..c. r/rr-xr-xr-x 0 0 5353-128-3 /WINDOWS/Cursors/help_l.cur 766 ..c. r/rr-xr-xr-x 0 0 5354-128-3 /WINDOWS/Cursors/help_m.cur 766 ..c. r/rr-xr-xr-x 0 0 5355-128-3 /WINDOWS/Cursors/move_l.cur 766 ..c. r/rr-xr-xr-x 0 0 5356-128-3 /WINDOWS/Cursors/move_m.cur 766 ..c. r/rr-xr-xr-x 0 0 5357-128-3 /WINDOWS/Cursors/no_l.cur 766 ..c. r/rr-xr-xr-x 0 0 5358-128-3 /WINDOWS/Cursors/no_m.cur 766 ..c. r/rr-xr-xr-x 0 0 5359-128-3 /WINDOWS/Cursors/pen_l.cur 766 ..c. r/rr-xr-xr-x 0 0 5360-128-3 /WINDOWS/Cursors/pen_m.cur 766 ..c. r/rr-xr-xr-x 0 0 5361-128-3 /WINDOWS/Cursors/size1_l.cur 766 ..c. r/rr-xr-xr-x 0 0 5362-128-3 /WINDOWS/Cursors/size1_m.cur 766 ..c. r/rr-xr-xr-x 0 0 5363-128-3 /WINDOWS/Cursors/size2_l.cur 766 ..c. r/rr-xr-xr-x 0 0 5364-128-3 /WINDOWS/Cursors/size2_m.cur 766 ..c. r/rr-xr-xr-x 0 0 5365-128-3 /WINDOWS/Cursors/size3_l.cur 766 ..c. r/rr-xr-xr-x 0 0 5366-128-3 /WINDOWS/Cursors/size3_m.cur 766 ..c. r/rr-xr-xr-x 0 0 5367-128-3 /WINDOWS/Cursors/size4_l.cur 766 ..c. r/rr-xr-xr-x 0 0 5368-128-3 /WINDOWS/Cursors/size4_m.cur 766 ..c. r/rr-xr-xr-x 0 0 5369-128-3 /WINDOWS/Cursors/up_l.cur 766 ..c. r/rr-xr-xr-x 0 0 5370-128-3 /WINDOWS/Cursors/up_m.cur 766 ..c. r/rr-xr-xr-x 0 0 5371-128-3 /WINDOWS/Cursors/wait_l.cur 766 ..c. r/rr-xr-xr-x 0 0 5372-128-3 /WINDOWS/Cursors/wait_m.cur 3947 ..c. r/rr-xr-xr-x 0 0 5373-128-3 /Program Files/Windows NT/Pinball/FONT.DAT 928700 ..c. r/rr-xr-xr-x 0 0 5374-128-3 /Program Files/Windows NT/Pinball/PINBALL.DAT 108607 ..c. r/rr-xr-xr-x 0 0 5375-128-3 /Program Files/Windows NT/Pinball/PINBALL.MID 28888 ..c. r/rr-xr-xr-x 0 0 5376-128-3 /Program Files/Windows NT/Pinball/PINBALL2.MID 55490 ..c. r/rr-xr-xr-x 0 0 5377-128-3 /Program Files/Windows NT/Pinball/SOUND1.WAV 1226 ..c. r/rr-xr-xr-x 0 0 5378-128-3 /Program Files/Windows NT/Pinball/SOUND104.WAV 1968 ..c. r/rr-xr-xr-x 0 0 5379-128-3 /Program Files/Windows NT/Pinball/SOUND105.WAV 7754 ..c. r/rr-xr-xr-x 0 0 5380-128-3 /Program Files/Windows NT/Pinball/SOUND108.WAV 890 ..c. r/rr-xr-xr-x 0 0 5381-128-3 /Program Files/Windows NT/Pinball/SOUND111.WAV 824 ..c. r/rr-xr-xr-x 0 0 5382-128-3 /Program Files/Windows NT/Pinball/SOUND112.WAV 4296 ..c. r/rr-xr-xr-x 0 0 5383-128-3 /Program Files/Windows NT/Pinball/SOUND12.WAV 8034 ..c. r/rr-xr-xr-x 0 0 5384-128-3 /Program Files/Windows NT/Pinball/SOUND13.WAV 1290 ..c. r/rr-xr-xr-x 0 0 5385-128-3 /Program Files/Windows NT/Pinball/SOUND131.WAV 19282 ..c. r/rr-xr-xr-x 0 0 5386-128-3 /Program Files/Windows NT/Pinball/SOUND136.WAV 3002 ..c. r/rr-xr-xr-x 0 0 5387-128-3 /Program Files/Windows NT/Pinball/SOUND14.WAV 1046 ..c. r/rr-xr-xr-x 0 0 5388-128-3 /Program Files/Windows NT/Pinball/SOUND16.WAV 2090 ..c. r/rr-xr-xr-x 0 0 5389-128-3 /Program Files/Windows NT/Pinball/SOUND17.WAV 22988 ..c. r/rr-xr-xr-x 0 0 539-128-3 /WINDOWS/Help/evntwin.hlp 3986 ..c. r/rr-xr-xr-x 0 0 5390-128-3 /Program Files/Windows NT/Pinball/SOUND18.WAV 27472 ..c. r/rr-xr-xr-x 0 0 5391-128-3 /Program Files/Windows NT/Pinball/SOUND181.WAV 5230 ..c. r/rr-xr-xr-x 0 0 5392-128-3 /Program Files/Windows NT/Pinball/SOUND19.WAV 8650 ..c. r/rr-xr-xr-x 0 0 5393-128-3 /Program Files/Windows NT/Pinball/SOUND20.WAV 9194 ..c. r/rr-xr-xr-x 0 0 5394-128-3 /Program Files/Windows NT/Pinball/SOUND21.WAV 7376 ..c. r/rr-xr-xr-x 0 0 5395-128-3 /Program Files/Windows NT/Pinball/SOUND22.WAV 12106 ..c. r/rr-xr-xr-x 0 0 5396-128-3 /Program Files/Windows NT/Pinball/SOUND24.WAV 14600 ..c. r/rr-xr-xr-x 0 0 5397-128-3 /Program Files/Windows NT/Pinball/SOUND240.WAV 20712 ..c. r/rr-xr-xr-x 0 0 5398-128-3 /Program Files/Windows NT/Pinball/SOUND243.WAV 25704 ..c. r/rr-xr-xr-x 0 0 5399-128-3 /Program Files/Windows NT/Pinball/SOUND25.WAV 48 .ac. d/dr-xr-xr-x 0 0 54-144-1 /WINDOWS/java/classes 7306 ..c. r/rr-xr-xr-x 0 0 5400-128-3 /Program Files/Windows NT/Pinball/SOUND26.WAV 20242 ..c. r/rr-xr-xr-x 0 0 5401-128-3 /Program Files/Windows NT/Pinball/SOUND27.WAV 8650 ..c. r/rr-xr-xr-x 0 0 5402-128-3 /Program Files/Windows NT/Pinball/SOUND28.WAV 10364 ..c. r/rr-xr-xr-x 0 0 5403-128-3 /Program Files/Windows NT/Pinball/SOUND29.WAV 22858 ..c. r/rr-xr-xr-x 0 0 5404-128-3 /Program Files/Windows NT/Pinball/SOUND3.WAV 22570 ..c. r/rr-xr-xr-x 0 0 5405-128-3 /Program Files/Windows NT/Pinball/SOUND30.WAV 1520 ..c. r/rr-xr-xr-x 0 0 5406-128-3 /Program Files/Windows NT/Pinball/SOUND34.WAV 19498 ..c. r/rr-xr-xr-x 0 0 5407-128-3 /Program Files/Windows NT/Pinball/SOUND35.WAV 33848 ..c. r/rr-xr-xr-x 0 0 5408-128-3 /Program Files/Windows NT/Pinball/SOUND36.WAV 13024 ..c. r/rr-xr-xr-x 0 0 5409-128-3 /Program Files/Windows NT/Pinball/SOUND38.WAV 28282 ..c. r/rr-xr-xr-x 0 0 5410-128-3 /Program Files/Windows NT/Pinball/SOUND39.WAV 16626 ..c. r/rr-xr-xr-x 0 0 5411-128-3 /Program Files/Windows NT/Pinball/SOUND4.WAV 29140 ..c. r/rr-xr-xr-x 0 0 5412-128-3 /Program Files/Windows NT/Pinball/SOUND42.WAV 22796 ..c. r/rr-xr-xr-x 0 0 5413-128-3 /Program Files/Windows NT/Pinball/SOUND43.WAV 9770 ..c. r/rr-xr-xr-x 0 0 5414-128-3 /Program Files/Windows NT/Pinball/SOUND45.WAV 1876 ..c. r/rr-xr-xr-x 0 0 5415-128-3 /Program Files/Windows NT/Pinball/SOUND49.WAV 3330 ..c. r/rr-xr-xr-x 0 0 5416-128-3 /Program Files/Windows NT/Pinball/SOUND49D.WAV 3180 ..c. r/rr-xr-xr-x 0 0 5417-128-3 /Program Files/Windows NT/Pinball/SOUND5.WAV 12074 ..c. r/rr-xr-xr-x 0 0 5418-128-3 /Program Files/Windows NT/Pinball/SOUND50.WAV 8932 ..c. r/rr-xr-xr-x 0 0 5419-128-3 /Program Files/Windows NT/Pinball/SOUND528.WAV 9022 ..c. r/rr-xr-xr-x 0 0 5420-128-3 /Program Files/Windows NT/Pinball/SOUND53.WAV 18250 ..c. r/rr-xr-xr-x 0 0 5421-128-3 /Program Files/Windows NT/Pinball/SOUND54.WAV 21890 ..c. r/rr-xr-xr-x 0 0 5422-128-3 /Program Files/Windows NT/Pinball/SOUND55.WAV 29004 ..c. r/rr-xr-xr-x 0 0 5423-128-3 /Program Files/Windows NT/Pinball/SOUND560.WAV 24192 ..c. r/rr-xr-xr-x 0 0 5424-128-3 /Program Files/Windows NT/Pinball/SOUND563.WAV 30502 ..c. r/rr-xr-xr-x 0 0 5425-128-3 /Program Files/Windows NT/Pinball/SOUND57.WAV 3408 ..c. r/rr-xr-xr-x 0 0 5426-128-3 /Program Files/Windows NT/Pinball/SOUND58.WAV 4376 ..c. r/rr-xr-xr-x 0 0 5427-128-3 /Program Files/Windows NT/Pinball/SOUND6.WAV 17676 ..c. r/rr-xr-xr-x 0 0 5428-128-3 /Program Files/Windows NT/Pinball/SOUND65.WAV 32402 ..c. r/rr-xr-xr-x 0 0 5429-128-3 /Program Files/Windows NT/Pinball/SOUND68.WAV 26442 ..c. r/rr-xr-xr-x 0 0 5430-128-3 /Program Files/Windows NT/Pinball/SOUND7.WAV 14592 ..c. r/rr-xr-xr-x 0 0 5431-128-3 /Program Files/Windows NT/Pinball/SOUND713.WAV 27268 ..c. r/rr-xr-xr-x 0 0 5432-128-3 /Program Files/Windows NT/Pinball/SOUND735.WAV 2102 ..c. r/rr-xr-xr-x 0 0 5433-128-3 /Program Files/Windows NT/Pinball/SOUND8.WAV 47230 ..c. r/rr-xr-xr-x 0 0 5434-128-3 /Program Files/Windows NT/Pinball/SOUND827.WAV 20098 ..c. r/rr-xr-xr-x 0 0 5435-128-3 /Program Files/Windows NT/Pinball/SOUND9.WAV 6742 ..c. r/rr-xr-xr-x 0 0 5436-128-3 /Program Files/Windows NT/Pinball/SOUND999.WAV 339178 ..c. r/rr-xr-xr-x 0 0 5437-128-3 /Program Files/Windows NT/Pinball/table.bmp 2687 ..c. r/r--x--x--x 0 0 5438-128-3 /Program Files/Windows NT/Pinball/wavemix.inf 39590 ..c. r/rr-xr-xr-x 0 0 5439-128-3 /WINDOWS/Help/pinball.chm 22398 ..c. r/rr-xr-xr-x 0 0 5440-128-3 /WINDOWS/Help/pinball.hlp 32887 ..c. r/rr-xr-xr-x 0 0 5441-128-3 /WINDOWS/Help/wordpad.chm 19706 ..c. r/rr-xr-xr-x 0 0 5442-128-3 /WINDOWS/Help/wordpad.hlp 144 .ac. d/dr-xr-xr-x 0 0 5444-144-1 /Program Files/MSN Gaming Zone 56 .ac. d/dr-xr-xr-x 0 0 5445-144-5 /Program Files/MSN Gaming Zone/Windows 36937 ..c. r/rr-xr-xr-x 0 0 5446-128-3 /Program Files/MSN Gaming Zone/Windows/zClientm.exe 29760 ..c. r/rr-xr-xr-x 0 0 5447-128-3 /Program Files/MSN Gaming Zone/Windows/ZNetM.dll 217160 ..c. r/rr-xr-xr-x 0 0 5448-128-3 /Program Files/MSN Gaming Zone/Windows/Cmnclim.dll 113222 ..c. r/rr-xr-xr-x 0 0 5449-128-3 /Program Files/MSN Gaming Zone/Windows/zoneclim.dll 1039955 ..c. r/rr-xr-xr-x 0 0 5450-128-3 /Program Files/MSN Gaming Zone/Windows/Cmnresm.dll 41029 ..c. r/rr-xr-xr-x 0 0 5451-128-3 /Program Files/MSN Gaming Zone/Windows/ZCorem.dll 13894 ..c. r/rr-xr-xr-x 0 0 5452-128-3 /Program Files/MSN Gaming Zone/Windows/zonelibM.dll 32339 ..c. r/rr-xr-xr-x 0 0 5453-128-3 /Program Files/MSN Gaming Zone/Windows/UniAnsi.dll 4677 ..c. r/rr-xr-xr-x 0 0 5454-128-3 /Program Files/MSN Gaming Zone/Windows/zeeverm.dll 57409 ..c. r/rr-xr-xr-x 0 0 5455-128-3 /Program Files/MSN Gaming Zone/Windows/hrtz.dll 1175635 ..c. r/rr-xr-xr-x 0 0 5456-128-3 /Program Files/MSN Gaming Zone/Windows/Hrtzres.dll 42573 ..c. r/rr-xr-xr-x 0 0 5457-128-3 /Program Files/MSN Gaming Zone/Windows/hrtzzm.exe 66113 ..c. r/rr-xr-xr-x 0 0 5458-128-3 /Program Files/MSN Gaming Zone/Windows/shvl.dll 2178131 ..c. r/rr-xr-xr-x 0 0 5459-128-3 /Program Files/MSN Gaming Zone/Windows/Shvlres.dll 2402 ..c. r/rr-xr-xr-x 0 0 546-128-3 /WINDOWS/inf/fdc.inf 42573 ..c. r/rr-xr-xr-x 0 0 5460-128-3 /Program Files/MSN Gaming Zone/Windows/shvlzm.exe 40515 ..c. r/rr-xr-xr-x 0 0 5461-128-3 /Program Files/MSN Gaming Zone/Windows/chkr.dll 780885 ..c. r/rr-xr-xr-x 0 0 5462-128-3 /Program Files/MSN Gaming Zone/Windows/chkrres.dll 42575 ..c. r/rr-xr-xr-x 0 0 5463-128-3 /Program Files/MSN Gaming Zone/Windows/chkrzm.exe 48706 ..c. r/rr-xr-xr-x 0 0 5464-128-3 /Program Files/MSN Gaming Zone/Windows/rvse.dll 753236 ..c. r/rr-xr-xr-x 0 0 5465-128-3 /Program Files/MSN Gaming Zone/Windows/Rvseres.dll 42574 ..c. r/rr-xr-xr-x 0 0 5466-128-3 /Program Files/MSN Gaming Zone/Windows/Rvsezm.exe 82501 ..c. r/rr-xr-xr-x 0 0 5467-128-3 /Program Files/MSN Gaming Zone/Windows/bckg.dll 1817687 ..c. r/rr-xr-xr-x 0 0 5468-128-3 /Program Files/MSN Gaming Zone/Windows/bckgres.dll 42577 ..c. r/rr-xr-xr-x 0 0 5469-128-3 /Program Files/MSN Gaming Zone/Windows/bckgzm.exe 16275 ..c. r/rr-xr-xr-x 0 0 547-128-3 /WINDOWS/Help/fde.hlp 35135 ..c. r/rr-xr-xr-x 0 0 5470-128-3 /WINDOWS/Help/bckg.chm 27978 ..c. r/rr-xr-xr-x 0 0 5471-128-3 /WINDOWS/Help/chkr.chm 25815 ..c. r/rr-xr-xr-x 0 0 5472-128-3 /WINDOWS/Help/rvse.chm 32162 ..c. r/rr-xr-xr-x 0 0 5473-128-3 /WINDOWS/Help/shvl.chm 30260 ..c. r/rr-xr-xr-x 0 0 5474-128-3 /WINDOWS/Help/hrtz.chm 56 .ac. d/dr-xr-xr-x 0 0 5475-144-6 /Program Files/Messenger 33792 ..c. r/rr-xr-xr-x 0 0 5476-128-3 /Program Files/Messenger/custsat.dll 9306 ..c. r/rr-xr-xr-x 0 0 5477-128-3 /Program Files/Messenger/online.wav 18052 ..c. r/rr-xr-xr-x 0 0 5478-128-3 /Program Files/Messenger/newemail.wav 9306 ..c. r/rr-xr-xr-x 0 0 5479-128-3 /Program Files/Messenger/newalert.wav 24479 ..c. r/rr-xr-xr-x 0 0 548-128-3 /WINDOWS/Help/filefold.hlp 4821 ..c. r/r--x--x--x 0 0 5480-128-3 /Program Files/Messenger/logowin.gif 1585 ..c. r/rr-xr-xr-x 0 0 5481-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Remote Desktop Connection.lnk 7047 ..c. r/rr-xr-xr-x 0 0 5482-128-3 /Program Files/Messenger/lvback.gif 82944 ..c. r/rr-xr-xr-x 0 0 5483-128-3 /Program Files/Messenger/msgsc.dll 180224 ..c. r/rr-xr-xr-x 0 0 5484-128-3 /Program Files/Messenger/msgslang.dll 1695232 ..c. r/rr-xr-xr-x 0 0 5485-128-3 /Program Files/Messenger/msmsgs.exe 4454 ..c. r/rr-xr-xr-x 0 0 5486-128-3 /Program Files/Messenger/type.wav 115981 ..c. r/rr-xr-xr-x 0 0 5487-128-3 /Program Files/Messenger/xpmsgr.chm 56 .ac. d/dr-xr-xr-x 0 0 5489-144-6 /Program Files/Windows Media Player 32107 ..c. r/rr-xr-xr-x 0 0 549-128-3 /WINDOWS/Help/filemgmt.hlp 56 .ac. d/d--x--x--x 0 0 5490-144-6 /Documents and Settings/All Users/Documents/My Music 56 .ac. d/dr-xr-xr-x 0 0 5492-144-6 /Documents and Settings/All Users/Documents/My Music/Sample Playlists 1986 ..c. r/rr-xr-xr-x 0 0 5494-128-3 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/MSN.lnk 56 .ac. d/dr-xr-xr-x 0 0 5495-144-6 /Program Files/Online Services 1798 ..c. r/rr-xr-xr-x 0 0 5496-128-4 /Program Files/Online Services/Use MSN Explorer to sign up for Internet Access (US only).lnk 4194304 ..c. r/rr-xr-xr-x 0 0 5498-128-3 /WINDOWS/system32/MsDtc/MSDTC.LOG 24576 ..c. r/rr-xr-xr-x 0 0 5499-128-3 /WINDOWS/system32/MsDtc/Trace/dtctrace.log 48 .ac. d/dr-xr-xr-x 0 0 55-144-1 /WINDOWS/java/trustlib 29654 ..c. r/rr-xr-xr-x 0 0 550-128-3 /WINDOWS/Help/find.chm 48 .ac. d/d--x--x--x 0 0 5500-144-6 /Documents and Settings/All Users/Start Menu/Programs/Administrative Tools 1582 ..c. r/rr-xr-xr-x 0 0 5501-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Administrative Tools/Component Services.lnk 56 .a.. d/dr-xr-xr-x 0 0 5503-144-6 /WINDOWS/Registration 48 .ac. d/dr-xr-xr-x 0 0 5504-144-1 /WINDOWS/Registration/CRMLog 48 .ac. d/dr-xr-xr-x 0 0 5507-144-1 /Program Files/ComPlus Applications 1555 ..c. r/rr-xr-xr-x 0 0 5508-128-4 /Documents and Settings/Default User/Start Menu/Programs/Accessories/Command Prompt.lnk 1519 ..c. r/rr-xr-xr-x 0 0 5509-128-3 /Documents and Settings/Default User/Start Menu/Programs/Accessories/Notepad.lnk 1519 ..c. r/rr-xr-xr-x 0 0 5510-128-4 /Documents and Settings/Default User/Start Menu/Programs/Accessories/Synchronize.lnk 48 .ac. d/d--x--x--x 0 0 5512-144-6 /Documents and Settings/All Users/Start Menu/Programs/Accessories/System Tools 1521 ..c. r/rr-xr-xr-x 0 0 5513-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/System Tools/Character Map.lnk 1515 ..c. r/rr-xr-xr-x 0 0 5515-128-3 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Paint.lnk 786 ..c. r/rr-xr-xr-x 0 0 5516-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Communications/HyperTerminal.lnk 48 .ac. d/d--x--x--x 0 0 5517-144-6 /Documents and Settings/All Users/Start Menu/Programs/Accessories/Entertainment 1528 ..c. r/rr-xr-xr-x 0 0 5518-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Entertainment/Sound Recorder.lnk 1528 ..c. r/rr-xr-xr-x 0 0 5520-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Entertainment/Volume Control.lnk 48 .ac. d/d--x--x--x 0 0 5521-144-1 /Documents and Settings/All Users/Start Menu/Programs/Accessories/Accessibility 1520 ..c. r/rr-xr-xr-x 0 0 5522-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Accessibility/Accessibility Wizard.lnk 48 .ac. d/d--x--x--x 0 0 5524-144-5 /Documents and Settings/All Users/Start Menu/Programs/Games 885 ..c. r/rr-xr-xr-x 0 0 5525-128-3 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Games/Pinball.lnk 1522 ..c. r/rr-xr-xr-x 0 0 5527-128-3 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Games/Freecell.lnk 1520 ..c. r/rr-xr-xr-x 0 0 5528-128-3 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Games/Hearts.lnk 1515 ..c. r/rr-xr-xr-x 0 0 5529-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Games/Minesweeper.lnk 1491 ..c. r/rr-xr-xr-x 0 0 5530-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Games/Solitaire.lnk 1502 ..c. r/rr-xr-xr-x 0 0 5531-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Games/Spider Solitaire.lnk 913 ..c. r/rr-xr-xr-x 0 0 5532-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Games/Internet Hearts.lnk 913 ..c. r/rr-xr-xr-x 0 0 5533-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Games/Internet Spades.lnk 913 ..c. r/rr-xr-xr-x 0 0 5534-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Games/Internet Checkers.lnk 913 ..c. r/rr-xr-xr-x 0 0 5535-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Games/Internet Reversi.lnk 913 ..c. r/rr-xr-xr-x 0 0 5536-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Games/Internet Backgammon.lnk 609 ..c. r/rr-xr-xr-x 0 0 5537-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Windows Messenger.lnk 12398 ..c. r/rr-xr-xr-x 0 0 554-128-3 /WINDOWS/inf/fjtscan.inf 108 ..c. r/rr-xr-xr-x 0 0 5540-128-1 /Documents and Settings/malware/Cookies/malware@microsoft[1].txt 19882 ..c. r/rr-xr-xr-x 0 0 5542-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/894[1].jpg 6351 ..c. r/rr-xr-xr-x 0 0 555-128-3 /WINDOWS/inf/flash.inf 24253 ..c. r/rr-xr-xr-x 0 0 556-128-3 /WINDOWS/Media/flourish.mid 3049 ..c. r/rr-xr-xr-x 0 0 557-128-3 /WINDOWS/inf/flpydisk.inf 26022 ..c. r/rr-xr-xr-x 0 0 559-128-3 /WINDOWS/Help/folderop.chm 70683 ..c. r/rr-xr-xr-x 0 0 560-128-3 /WINDOWS/inf/font.inf 17250 ..c. r/rr-xr-xr-x 0 0 561-128-3 /WINDOWS/Help/fonts.chm 368 .ac. d/d--x--x--x 0 0 5612-144-1 /Documents and Settings/All Users/Documents/My Pictures 56 .ac. d/dr-xr-xr-x 0 0 5614-144-6 /Program Files/Internet Explorer 93184 ..c. r/rr-xr-xr-x 0 0 5615-128-3 /Program Files/Internet Explorer/IEXPLORE.EXE 18432 ..c. r/rr-xr-xr-x 0 0 5616-128-3 /Program Files/Internet Explorer/iedw.exe 38912 ..c. r/rr-xr-xr-x 0 0 5617-128-3 /Program Files/Internet Explorer/HMMAPI.DLL 592 .ac. d/dr-xr-xr-x 0 0 5618-144-1 /Program Files/Common Files/Microsoft Shared/TextConv 311864 ..c. r/rr-xr-xr-x 0 0 5619-128-3 /Program Files/Common Files/Microsoft Shared/TextConv/html32.cnv 18931 ..c. r/rr-xr-xr-x 0 0 562-128-3 /WINDOWS/Help/fonts.hlp 116288 ..c. r/rr-xr-xr-x 0 0 5620-128-3 /Program Files/Common Files/Microsoft Shared/TextConv/msconv97.dll 256 .ac. d/dr-xr-xr-x 0 0 5621-144-1 /Program Files/Common Files/Microsoft Shared/Triedit 128512 ..c. r/rr-xr-xr-x 0 0 5622-128-3 /Program Files/Common Files/Microsoft Shared/Triedit/DHTMLED.OCX 153088 ..c. r/rr-xr-xr-x 0 0 5623-128-3 /Program Files/Common Files/Microsoft Shared/Triedit/TRIEDIT.DLL 56 .ac. d/dr-xr-xr-x 0 0 5624-144-5 /Program Files/Common Files/System 56 .ac. d/dr-xr-xr-x 0 0 5625-144-5 /Program Files/Common Files/System/msadc 629 ..c. r/rr-xr-xr-x 0 0 5626-128-1 /Program Files/Common Files/System/msadc/adcjavas.inc 622 ..c. r/rr-xr-xr-x 0 0 5627-128-1 /Program Files/Common Files/System/msadc/adcvbs.inc 331776 ..c. r/rr-xr-xr-x 0 0 5628-128-3 /Program Files/Common Files/System/msadc/msadce.dll 20480 ..c. r/rr-xr-xr-x 0 0 5629-128-3 /Program Files/Common Files/System/msadc/msadcer.dll 135984 ..c. r/rr-xr-xr-x 0 0 563-128-3 /WINDOWS/Fonts/framd.ttf 61440 ..c. r/rr-xr-xr-x 0 0 5630-128-3 /Program Files/Common Files/System/msadc/msadcf.dll 16384 ..c. r/rr-xr-xr-x 0 0 5631-128-3 /Program Files/Common Files/System/msadc/msadcfr.dll 143360 ..c. r/rr-xr-xr-x 0 0 5632-128-3 /Program Files/Common Files/System/msadc/msadco.dll 16384 ..c. r/rr-xr-xr-x 0 0 5633-128-3 /Program Files/Common Files/System/msadc/msadcor.dll 53248 ..c. r/rr-xr-xr-x 0 0 5634-128-3 /Program Files/Common Files/System/msadc/msadcs.dll 155648 ..c. r/rr-xr-xr-x 0 0 5635-128-3 /Program Files/Common Files/System/msadc/msadds.dll 24576 ..c. r/rr-xr-xr-x 0 0 5636-128-3 /Program Files/Common Files/System/msadc/msaddsr.dll 16384 ..c. r/rr-xr-xr-x 0 0 5637-128-3 /Program Files/Common Files/System/msadc/msdaprsr.dll 200704 ..c. r/rr-xr-xr-x 0 0 5638-128-3 /Program Files/Common Files/System/msadc/msdaprst.dll 36864 ..c. r/rr-xr-xr-x 0 0 5639-128-3 /Program Files/Common Files/System/msadc/msdfmap.dll 152844 ..c. r/rr-xr-xr-x 0 0 564-128-3 /WINDOWS/Fonts/framdit.ttf 16384 ..c. r/rr-xr-xr-x 0 0 5640-128-3 /Program Files/Common Files/System/msadc/msdaremr.dll 118784 ..c. r/rr-xr-xr-x 0 0 5641-128-3 /Program Files/Common Files/System/msadc/msdarem.dll 56 .ac. d/dr-xr-xr-x 0 0 5642-144-5 /Program Files/Common Files/System/ado 14610 ..c. r/rr-xr-xr-x 0 0 5643-128-3 /Program Files/Common Files/System/ado/adojavas.inc 14951 ..c. r/rr-xr-xr-x 0 0 5644-128-3 /Program Files/Common Files/System/ado/adovbs.inc 24576 ..c. r/rr-xr-xr-x 0 0 5645-128-3 /Program Files/Common Files/System/ado/msader15.dll 536576 ..c. r/rr-xr-xr-x 0 0 5646-128-3 /Program Files/Common Files/System/ado/msado15.dll 61440 ..c. r/rr-xr-xr-x 0 0 5647-128-3 /Program Files/Common Files/System/ado/msado20.tlb 61440 ..c. r/rr-xr-xr-x 0 0 5648-128-3 /Program Files/Common Files/System/ado/msado21.tlb 81920 ..c. r/rr-xr-xr-x 0 0 5649-128-3 /Program Files/Common Files/System/ado/msado25.tlb 81920 ..c. r/rr-xr-xr-x 0 0 5650-128-3 /Program Files/Common Files/System/ado/msado26.tlb 81920 ..c. r/rr-xr-xr-x 0 0 5651-128-3 /Program Files/Common Files/System/ado/msado27.tlb 180224 ..c. r/rr-xr-xr-x 0 0 5652-128-3 /Program Files/Common Files/System/ado/msadomd.dll 57344 ..c. r/rr-xr-xr-x 0 0 5653-128-3 /Program Files/Common Files/System/ado/msador15.dll 200704 ..c. r/rr-xr-xr-x 0 0 5654-128-3 /Program Files/Common Files/System/ado/msadox.dll 57344 ..c. r/rr-xr-xr-x 0 0 5655-128-3 /Program Files/Common Files/System/ado/msadrh15.dll 102400 ..c. r/rr-xr-xr-x 0 0 5656-128-3 /Program Files/Common Files/System/ado/msjro.dll 56 .ac. d/dr-xr-xr-x 0 0 5657-144-6 /Program Files/Common Files/System/Ole DB 4096 ..c. r/rr-xr-xr-x 0 0 5658-128-3 /Program Files/Common Files/System/Ole DB/msdadc.dll 4096 ..c. r/rr-xr-xr-x 0 0 5659-128-3 /Program Files/Common Files/System/Ole DB/msdaenum.dll 4096 ..c. r/rr-xr-xr-x 0 0 5660-128-3 /Program Files/Common Files/System/Ole DB/msdaer.dll 233472 ..c. r/rr-xr-xr-x 0 0 5661-128-3 /Program Files/Common Files/System/Ole DB/msdaora.dll 16384 ..c. r/rr-xr-xr-x 0 0 5662-128-3 /Program Files/Common Files/System/Ole DB/msdaorar.dll 4096 ..c. r/rr-xr-xr-x 0 0 5663-128-3 /Program Files/Common Files/System/Ole DB/msdasc.dll 315392 ..c. r/rr-xr-xr-x 0 0 5664-128-3 /Program Files/Common Files/System/Ole DB/msdasql.dll 16384 ..c. r/rr-xr-xr-x 0 0 5665-128-3 /Program Files/Common Files/System/Ole DB/msdasqlr.dll 20480 ..c. r/rr-xr-xr-x 0 0 5666-128-3 /Program Files/Common Files/System/Ole DB/msdatt.dll 4096 ..c. r/rr-xr-xr-x 0 0 5667-128-3 /Program Files/Common Files/System/Ole DB/msdaurl.dll 24576 ..c. r/rr-xr-xr-x 0 0 5668-128-3 /Program Files/Common Files/System/Ole DB/msxactps.dll 204800 ..c. r/rr-xr-xr-x 0 0 5669-128-3 /Program Files/Common Files/System/Ole DB/msdaps.dll 77824 ..c. r/rr-xr-xr-x 0 0 5670-128-3 /Program Files/Common Files/System/Ole DB/msdaosp.dll 94208 ..c. r/rr-xr-xr-x 0 0 5671-128-3 /Program Files/Common Files/System/Ole DB/msdatl3.dll 487424 ..c. r/rr-xr-xr-x 0 0 5672-128-3 /Program Files/Common Files/System/Ole DB/oledb32.dll 65536 ..c. r/rr-xr-xr-x 0 0 5673-128-3 /Program Files/Common Files/System/Ole DB/oledb32r.dll 528384 ..c. r/rr-xr-xr-x 0 0 5674-128-3 /Program Files/Common Files/System/Ole DB/sqloledb.dll 61440 ..c. r/rr-xr-xr-x 0 0 5675-128-3 /Program Files/Common Files/System/Ole DB/sqloledb.rll 217088 ..c. r/rr-xr-xr-x 0 0 5676-128-3 /Program Files/Common Files/System/Ole DB/sqlxmlx.dll 28672 ..c. r/rr-xr-xr-x 0 0 5677-128-3 /Program Files/Common Files/System/Ole DB/sqlxmlx.rll 152 .ac. d/dr-xr-xr-x 0 0 5678-144-1 /Program Files/Common Files/Microsoft Shared/DAO 554008 ..c. r/rr-xr-xr-x 0 0 5679-128-3 /Program Files/Common Files/Microsoft Shared/DAO/dao360.dll 56 .ac. d/dr-xr-xr-x 0 0 5680-144-6 /Program Files/Internet Explorer/Connection Wizard 214528 ..c. r/rr-xr-xr-x 0 0 5681-128-3 /Program Files/Internet Explorer/Connection Wizard/icwconn1.exe 86016 ..c. r/rr-xr-xr-x 0 0 5682-128-3 /Program Files/Internet Explorer/Connection Wizard/icwconn2.exe 20480 ..c. r/rr-xr-xr-x 0 0 5683-128-3 /Program Files/Internet Explorer/Connection Wizard/inetwiz.exe 172032 ..c. r/rr-xr-xr-x 0 0 5684-128-3 /Program Files/Internet Explorer/Connection Wizard/icwhelp.dll 61440 ..c. r/rr-xr-xr-x 0 0 5685-128-3 /Program Files/Internet Explorer/Connection Wizard/icwconn.dll 49152 ..c. r/rr-xr-xr-x 0 0 5686-128-3 /Program Files/Internet Explorer/Connection Wizard/icwutil.dll 24576 ..c. r/rr-xr-xr-x 0 0 5687-128-3 /Program Files/Internet Explorer/Connection Wizard/icwrmind.exe 32768 ..c. r/rr-xr-xr-x 0 0 5688-128-3 /Program Files/Internet Explorer/Connection Wizard/icwdl.dll 566 ..c. r/rr-xr-xr-x 0 0 5689-128-1 /Program Files/Internet Explorer/Connection Wizard/icwx25a.dun 139118 ..c. r/rr-xr-xr-x 0 0 569-128-3 /WINDOWS/Help/fxsclnt.chm 617 ..c. r/rr-xr-xr-x 0 0 5690-128-1 /Program Files/Internet Explorer/Connection Wizard/icwx25b.dun 566 ..c. r/rr-xr-xr-x 0 0 5691-128-1 /Program Files/Internet Explorer/Connection Wizard/icwx25c.dun 352 ..c. r/rr-xr-xr-x 0 0 5692-128-1 /Program Files/Internet Explorer/Connection Wizard/icwip.dun 2921 ..c. r/rr-xr-xr-x 0 0 5693-128-3 /Program Files/Internet Explorer/Connection Wizard/phone.icw 19 ..c. r/rr-xr-xr-x 0 0 5694-128-1 /Program Files/Internet Explorer/Connection Wizard/phone.ver 851 ..c. r/rr-xr-xr-x 0 0 5695-128-3 /Program Files/Internet Explorer/Connection Wizard/state.icw 158 ..c. r/rr-xr-xr-x 0 0 5696-128-1 /Program Files/Internet Explorer/Connection Wizard/msicw.isp 197 ..c. r/rr-xr-xr-x 0 0 5697-128-1 /Program Files/Internet Explorer/Connection Wizard/msn.isp 132 ..c. r/rr-xr-xr-x 0 0 5698-128-1 /Program Files/Internet Explorer/Connection Wizard/support.icw 27091 ..c. r/rr-xr-xr-x 0 0 570-128-3 /WINDOWS/Help/fxsclnt.hlp 57305 ..c. r/rr-xr-xr-x 0 0 5703-128-3 /WINDOWS/Help/connect.hlp 129 ..c. r/rr-xr-xr-x 0 0 5704-128-1 /WINDOWS/Help/connect.cnt 29876 ..c. r/rr-xr-xr-x 0 0 5705-128-3 /WINDOWS/Help/icwdial.chm 56 .ac. d/dr-xr-xr-x 0 0 5709-144-6 /Program Files/Outlook Express 27066 ..c. r/rr-xr-xr-x 0 0 571-128-3 /WINDOWS/Help/fxscover.chm 73216 ..c. r/rr-xr-xr-x 0 0 5710-128-3 /Program Files/Outlook Express/setup50.exe 60416 ..c. r/rr-xr-xr-x 0 0 5711-128-3 /Program Files/Outlook Express/oemig50.exe 35328 ..c. r/rr-xr-xr-x 0 0 5712-128-3 /Program Files/Outlook Express/oemiglib.dll 253201 ..c. r/rr-xr-xr-x 0 0 5713-128-3 /WINDOWS/Help/msoe.chm 2479616 ..c. r/rr-xr-xr-x 0 0 5714-128-3 /Program Files/Outlook Express/msoeres.dll 1314816 ..c. r/rr-xr-xr-x 0 0 5715-128-3 /Program Files/Outlook Express/msoe.dll 104448 ..c. r/rr-xr-xr-x 0 0 5716-128-3 /Program Files/Outlook Express/oeimport.dll 60416 ..c. r/rr-xr-xr-x 0 0 5717-128-3 /Program Files/Outlook Express/msimn.exe 32657 ..c. r/rr-xr-xr-x 0 0 572-128-3 /WINDOWS/Help/fxsshare.chm 86528 ..c. r/rr-xr-xr-x 0 0 5720-128-3 /Program Files/Common Files/System/directdb.dll 249856 ..c. r/rr-xr-xr-x 0 0 5721-128-3 /Program Files/Common Files/System/wab32res.dll 510976 ..c. r/rr-xr-xr-x 0 0 5722-128-3 /Program Files/Common Files/System/wab32.dll 85504 ..c. r/rr-xr-xr-x 0 0 5723-128-3 /Program Files/Outlook Express/wabimp.dll 32768 ..c. r/rr-xr-xr-x 0 0 5724-128-3 /Program Files/Outlook Express/wabfind.dll 30208 ..c. r/rr-xr-xr-x 0 0 5725-128-3 /Program Files/Outlook Express/wabmig.exe 46080 ..c. r/rr-xr-xr-x 0 0 5726-128-3 /Program Files/Outlook Express/wab.exe 56 .ac. d/dr-xr-xr-x 0 0 5729-144-6 /Program Files/NetMeeting 1032192 ..c. r/rr-xr-xr-x 0 0 5730-128-3 /Program Files/NetMeeting/conf.exe 172032 ..c. r/rr-xr-xr-x 0 0 5731-128-3 /Program Files/NetMeeting/nmoldwb.dll 151552 ..c. r/rr-xr-xr-x 0 0 5732-128-3 /Program Files/NetMeeting/nmft.dll 188416 ..c. r/rr-xr-xr-x 0 0 5733-128-3 /Program Files/NetMeeting/nmwb.dll 81920 ..c. r/rr-xr-xr-x 0 0 5734-128-3 /Program Files/NetMeeting/nmchat.dll 29117 ..c. r/rr-xr-xr-x 0 0 5735-128-3 /Program Files/NetMeeting/netmeet.htm 274432 ..c. r/rr-xr-xr-x 0 0 5736-128-3 /Program Files/NetMeeting/MST120.DLL 57344 ..c. r/rr-xr-xr-x 0 0 5737-128-3 /Program Files/NetMeeting/MST123.DLL 77824 ..c. r/rr-xr-xr-x 0 0 5738-128-3 /Program Files/NetMeeting/nmcom.dll 45056 ..c. r/rr-xr-xr-x 0 0 5739-128-3 /Program Files/NetMeeting/confmrsl.dll 6314 ..c. r/rr-xr-xr-x 0 0 574-128-3 /WINDOWS/inf/gameport.inf 221184 ..c. r/rr-xr-xr-x 0 0 5740-128-3 /Program Files/NetMeeting/nac.dll 57344 ..c. r/rr-xr-xr-x 0 0 5741-128-3 /Program Files/NetMeeting/h323cc.dll 61440 ..c. r/rr-xr-xr-x 0 0 5742-128-3 /Program Files/NetMeeting/rrcm.dll 385024 ..c. r/rr-xr-xr-x 0 0 5743-128-3 /Program Files/NetMeeting/callcont.dll 28672 ..c. r/rr-xr-xr-x 0 0 5744-128-3 /Program Files/NetMeeting/nmasnt.dll 229376 ..c. r/rr-xr-xr-x 0 0 5745-128-3 /Program Files/NetMeeting/nmas.dll 40960 ..c. r/rr-xr-xr-x 0 0 5746-128-3 /Program Files/NetMeeting/dcap32.dll 8860 ..c. r/rr-xr-xr-x 0 0 575-128-3 /WINDOWS/inf/games.inf 30848 ..c. r/rr-xr-xr-x 0 0 5754-128-3 /WINDOWS/Help/conf.hlp 91007 ..c. r/rr-xr-xr-x 0 0 5755-128-3 /WINDOWS/Help/conf.chm 22553 ..c. r/rr-xr-xr-x 0 0 5756-128-3 /WINDOWS/Help/nmwhiteb.chm 73472 ..c. r/rr-xr-xr-x 0 0 5757-128-3 /WINDOWS/system32/drivers/sr.sys 129792 ..c. r/rr-xr-xr-x 0 0 5764-128-3 /WINDOWS/system32/drivers/fltMgr.sys 56 .ac. d/dr-xr-xr-x 0 0 5768-144-5 /WINDOWS/pchealth/helpctr/Config 312 .ac. d/dr-xr-xr-x 0 0 5769-144-5 /WINDOWS/pchealth/helpctr/DataColl 769024 ..c. r/rr-xr-xr-x 0 0 5770-128-3 /WINDOWS/pchealth/helpctr/binaries/HelpCtr.exe 744448 ..c. r/rr-xr-xr-x 0 0 5771-128-3 /WINDOWS/pchealth/helpctr/binaries/HelpSvc.exe 18432 ..c. r/rr-xr-xr-x 0 0 5772-128-3 /WINDOWS/pchealth/helpctr/binaries/HscUpd.exe 169984 ..c. r/rr-xr-xr-x 0 0 5773-128-3 /WINDOWS/pchealth/helpctr/binaries/msconfig.exe 376832 ..c. r/rr-xr-xr-x 0 0 5774-128-3 /WINDOWS/pchealth/helpctr/binaries/msinfo.dll 2711956 ..c. r/rr-xr-xr-x 0 0 5775-128-3 /WINDOWS/pchealth/helpctr/binaries/pchdt_w3.cab 102912 ..c. r/rr-xr-xr-x 0 0 5776-128-3 /WINDOWS/pchealth/helpctr/binaries/pchshell.dll 38400 ..c. r/rr-xr-xr-x 0 0 5777-128-3 /WINDOWS/pchealth/helpctr/binaries/pchsvc.dll 309519 ..c. r/rr-xr-xr-x 0 0 5778-128-3 /WINDOWS/pchealth/helpctr/binaries/hscsp_w3.cab 68704 ..c. r/rr-xr-xr-x 0 0 5779-128-3 /WINDOWS/pchealth/helpctr/binaries/hscmui.cab 17520 ..c. r/rr-xr-xr-x 0 0 578-128-3 /WINDOWS/Help/gen.chm 248 .ac. d/dr-xr-xr-x 0 0 5784-144-1 /WINDOWS/pchealth/UploadLB 152 .ac. d/dr-xr-xr-x 0 0 5785-144-1 /WINDOWS/pchealth/UploadLB/Binaries 150528 ..c. r/rr-xr-xr-x 0 0 5786-128-3 /WINDOWS/pchealth/UploadLB/Binaries/UploadM.exe 1402 ..c. r/rr-xr-xr-x 0 0 579-128-3 /WINDOWS/inf/genprint.inf 251289 ..c. r/rr-xr-xr-x 0 0 582-128-3 /WINDOWS/Help/Glossary.chm 3440660 ..c. r/rr-xr-xr-x 0 0 583-128-3 /WINDOWS/system32/drivers/gm.dls 646 ..c. r/rr-xr-xr-x 0 0 584-128-1 /WINDOWS/system32/drivers/gmreadme.txt 26824 ..c. r/rr-xr-xr-x 0 0 585-128-3 /WINDOWS/Help/gpedit.hlp 21160 ..c. r/rr-xr-xr-x 0 0 586-128-3 /WINDOWS/Help/gpedit.chm 14604 ..c. r/rr-xr-xr-x 0 0 588-128-3 /WINDOWS/Help/gptext.hlp 6053 ..c. r/rr-xr-xr-x 0 0 592-128-3 /WINDOWS/inf/hal.inf 25153 ..c. r/rr-xr-xr-x 0 0 593-128-3 /WINDOWS/Help/halftone.hlp 87552 ..c. r/rr-xr-xr-x 0 0 594-128-3 /WINDOWS/system32/mui/0009/hhctrlui.dll 8015 ..c. r/rr-xr-xr-x 0 0 596-128-3 /WINDOWS/security/templates/hisecws.inf 7784 ..c. r/rr-xr-xr-x 0 0 597-128-3 /WINDOWS/security/templates/hisecdc.inf 362496 ..c. r/rr-xr-xr-x 0 0 600-128-3 /WINDOWS/Resources/Themes/Luna/Shell/Homestead/shellstyle.dll 1946 ..c. r/rr-xr-xr-x 0 0 602-128-3 /WINDOWS/inf/hpdigwia.inf 56 .ac. d/dr-xr-xr-x 0 0 6024-144-6 /Program Files/Movie Maker 3558912 ..c. r/rr-xr-xr-x 0 0 6025-128-3 /Program Files/Movie Maker/moviemk.exe 167936 ..c. r/rr-xr-xr-x 0 0 6026-128-3 /Program Files/Movie Maker/WMM2AE.dll 7680 ..c. r/rr-xr-xr-x 0 0 6027-128-3 /Program Files/Movie Maker/WMM2EXT.dll 402432 ..c. r/rr-xr-xr-x 0 0 6028-128-3 /Program Files/Movie Maker/WMM2FILT.dll 502272 ..c. r/rr-xr-xr-x 0 0 6029-128-3 /Program Files/Movie Maker/WMM2FXA.dll 8945 ..c. r/rr-xr-xr-x 0 0 603-128-3 /WINDOWS/inf/hpojscan.inf 325632 ..c. r/rr-xr-xr-x 0 0 6030-128-3 /Program Files/Movie Maker/WMM2FXB.dll 4256768 ..c. r/rr-xr-xr-x 0 0 6031-128-3 /Program Files/Movie Maker/WMM2RES.dll 4096 ..c. r/rr-xr-xr-x 0 0 6032-128-3 /Program Files/Movie Maker/WMM2ERES.dll 5632 ..c. r/rr-xr-xr-x 0 0 6033-128-3 /Program Files/Movie Maker/WMM2RES2.dll 56 .ac. d/dr-xr-xr-x 0 0 6034-144-5 /Program Files/Movie Maker/Shared 18 ..c. r/rr-xr-xr-x 0 0 6035-128-1 /Program Files/Movie Maker/Shared/Empty.txt 7591 ..c. r/rr-xr-xr-x 0 0 6036-128-3 /Program Files/Movie Maker/Shared/Filters.xml 138660 ..c. r/rr-xr-xr-x 0 0 6037-128-3 /Program Files/Movie Maker/Shared/news.png 67213 ..c. r/rr-xr-xr-x 0 0 6038-128-3 /Program Files/Movie Maker/Shared/paint.png 62732 ..c. r/rr-xr-xr-x 0 0 6039-128-3 /Program Files/Movie Maker/Shared/Sample1.jpg 28714 ..c. r/rr-xr-xr-x 0 0 604-128-3 /WINDOWS/inf/hpscan.inf 46822 ..c. r/rr-xr-xr-x 0 0 6040-128-3 /Program Files/Movie Maker/Shared/Sample2.jpg 152 .ac. d/dr-xr-xr-x 0 0 6041-144-1 /Program Files/Movie Maker/Shared/Profiles 21 ..c. r/rr-xr-xr-x 0 0 6042-128-1 /Program Files/Movie Maker/Shared/Profiles/Blank.txt 144 .ac. d/dr-xr-xr-x 0 0 6043-144-1 /Program Files/Movie Maker/MUI 152 .ac. d/dr-xr-xr-x 0 0 6044-144-1 /Program Files/Movie Maker/MUI/0409 731275 ..c. r/rr-xr-xr-x 0 0 6045-128-3 /Program Files/Movie Maker/MUI/0409/moviemk.chm 20077 ..c. r/rr-xr-xr-x 0 0 605-128-3 /WINDOWS/Help/hs.chm 35983 ..c. r/rr-xr-xr-x 0 0 606-128-3 /WINDOWS/Help/hypertrm.chm 256 .ac. d/dr-xr-xr-x 0 0 6061-144-1 /Program Files/Windows Media Player/Skins 184959 ..c. r/rr-xr-xr-x 0 0 6062-128-3 /Program Files/Windows Media Player/Skins/compact.wmz 66725 ..c. r/rr-xr-xr-x 0 0 6063-128-3 /Program Files/Windows Media Player/Skins/Revert.wmz 4639 ..c. r/rr-xr-xr-x 0 0 6064-128-3 /Program Files/Windows Media Player/mplayer2.exe 364544 ..c. r/rr-xr-xr-x 0 0 6065-128-3 /Program Files/Windows Media Player/npdsplay.dll 10240 ..c. r/rr-xr-xr-x 0 0 6066-128-3 /Program Files/Windows Media Player/npwmsdrm.dll 226816 ..c. r/rr-xr-xr-x 0 0 6067-128-3 /Program Files/Windows Media Player/npdrmv2.dll 73728 ..c. r/rr-xr-xr-x 0 0 6068-128-3 /Program Files/Windows Media Player/wmplayer.exe 786432 ..c. r/rr-xr-xr-x 0 0 6069-128-3 /Program Files/Windows Media Player/migrate.exe 25153 ..c. r/rr-xr-xr-x 0 0 607-128-3 /WINDOWS/Help/hypertrm.hlp 33792 ..c. r/rr-xr-xr-x 0 0 6070-128-3 /Program Files/Windows Media Player/custsat.dll 221184 ..c. r/rr-xr-xr-x 0 0 6071-128-3 /Program Files/Windows Media Player/wmpns.dll 368640 ..c. r/rr-xr-xr-x 0 0 6072-128-3 /Program Files/Windows Media Player/mpvis.dll 774144 ..c. r/rr-xr-xr-x 0 0 6073-128-3 /Program Files/Windows Media Player/setup_wm.exe 98304 ..c. r/rr-xr-xr-x 0 0 6074-128-3 /Program Files/Windows Media Player/wmpband.dll 48 .ac. d/dr-xr-xr-x 0 0 6075-144-6 /Program Files/Windows Media Player/Sample Playlists 1474 ..c. r/rr-xr-xr-x 0 0 6076-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA/Plylst3.wpl 1448 ..c. r/rr-xr-xr-x 0 0 6077-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA/Plylst4.wpl 1477 ..c. r/rr-xr-xr-x 0 0 6078-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA/Plylst5.wpl 1477 ..c. r/rr-xr-xr-x 0 0 6079-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA/Plylst6.wpl 256 .ac. d/dr-xr-xr-x 0 0 608-144-1 /Documents and Settings/Default User/Application Data/Microsoft/Internet Explorer 1046 ..c. r/rr-xr-xr-x 0 0 6080-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA/Plylst7.wpl 1036 ..c. r/rr-xr-xr-x 0 0 6081-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA/Plylst8.wpl 784 ..c. r/rr-xr-xr-x 0 0 6082-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA/Plylst9.wpl 296 .ac. d/dr-xr-xr-x 0 0 6083-144-1 /Documents and Settings/Default User/Local Settings/Application Data/Microsoft/Media Player 733 ..c. r/rr-xr-xr-x 0 0 6088-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA/Plylst15.wpl 1049 ..c. r/rr-xr-xr-x 0 0 6089-128-3 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA/Plylst2.wpl 144 .a.. d/dr-xr-xr-x 0 0 6091-144-1 /WINDOWS/system32/Macromed 152 .ac. d/dr-xr-xr-x 0 0 6092-144-1 /WINDOWS/system32/Macromed/Flash 832872 ..c. r/rr-xr-xr-x 0 0 6093-128-3 /WINDOWS/system32/Macromed/Flash/flash.ocx 144 .ac. d/dr-xr-xr-x 0 0 6094-144-1 /Program Files/Common Files/Microsoft Shared/VGX 851968 ..c. r/rr-xr-xr-x 0 0 6095-128-3 /Program Files/Common Files/Microsoft Shared/VGX/vgx.dll 664 .a.. d/dr-xr-xr-x 0 0 6096-144-1 /WINDOWS/srchasst 3166208 ..c. r/rr-xr-xr-x 0 0 6097-128-3 /WINDOWS/srchasst/msgr3en.dll 58434 ..c. r/rr-xr-xr-x 0 0 6098-128-3 /WINDOWS/srchasst/srchctls.dll 726078 ..c. r/rr-xr-xr-x 0 0 6099-128-3 /WINDOWS/srchasst/srchui.dll 368 .ac. d/dr-xr-xr-x 0 0 6100-144-1 /WINDOWS/srchasst/chars 816535 ..c. r/rr-xr-xr-x 0 0 6101-128-3 /WINDOWS/srchasst/chars/courtney.acs 1472718 ..c. r/rr-xr-xr-x 0 0 6102-128-3 /WINDOWS/srchasst/chars/earl.acs 144 .ac. d/dr-xr-xr-x 0 0 6103-144-1 /WINDOWS/srchasst/mui 56 .ac. d/dr-xr-xr-x 0 0 6104-144-5 /WINDOWS/srchasst/mui/0409 2822 ..c. r/rr-xr-xr-x 0 0 6105-128-3 /WINDOWS/srchasst/mui/0409/inetpref.xml 5544 ..c. r/rr-xr-xr-x 0 0 6106-128-3 /WINDOWS/srchasst/mui/0409/lcladvd.xml 2518 ..c. r/rr-xr-xr-x 0 0 6107-128-3 /WINDOWS/srchasst/mui/0409/lcldocs.xml 2343 ..c. r/rr-xr-xr-x 0 0 6108-128-3 /WINDOWS/srchasst/mui/0409/lclmm.xml 213066 ..c. r/rr-xr-xr-x 0 0 6109-128-3 /Program Files/Common Files/Microsoft Shared/TextConv/mswrd632.wpc 278602 ..c. r/rr-xr-xr-x 0 0 6110-128-3 /Program Files/Common Files/Microsoft Shared/TextConv/mswrd832.cnv 110665 ..c. r/rr-xr-xr-x 0 0 6111-128-3 /Program Files/Common Files/Microsoft Shared/TextConv/write32.wpc 152 .ac. d/dr-xr-xr-x 0 0 6112-144-1 /Program Files/Internet Explorer/SIGNUP 1363 ..c. r/rr-xr-xr-x 0 0 6113-128-3 /Program Files/Internet Explorer/SIGNUP/INSTALL.INS 376 .ac. d/dr-xr-xr-x 0 0 6114-144-1 /Program Files/Common Files/Microsoft Shared/MSInfo 93184 ..c. r/rr-xr-xr-x 0 0 6115-128-3 /Program Files/Common Files/Microsoft Shared/MSInfo/IEINFO5.OCX 617 ..c. r/rr-xr-xr-x 0 0 6116-128-1 /Program Files/Common Files/Microsoft Shared/MSInfo/IEFILES5.INF 518 ..c. r/rr-xr-xr-x 0 0 6117-128-1 /Program Files/Common Files/System/msadc/handler.reg 588 ..c. r/rr-xr-xr-x 0 0 6118-128-1 /Program Files/Common Files/System/msadc/handsafe.reg 543 ..c. r/rr-xr-xr-x 0 0 6119-128-1 /Program Files/Common Files/System/ado/MDACReadme.htm 9804 ..c. r/rr-xr-xr-x 0 0 6120-128-3 /Program Files/Common Files/System/Ole DB/oledbjvs.inc 9975 ..c. r/rr-xr-xr-x 0 0 6121-128-3 /Program Files/Common Files/System/Ole DB/oledbvbs.inc 35631 ..c. r/rr-xr-xr-x 0 0 6122-128-3 /Program Files/Common Files/System/Ole DB/sqlsoldb.chm 152 .ac. d/dr-xr-xr-x 0 0 6123-144-1 /Program Files/Common Files/MSSoap 464 .ac. d/dr-xr-xr-x 0 0 6124-144-1 /Program Files/Common Files/MSSoap/Binaries 235520 ..c. r/rr-xr-xr-x 0 0 6125-128-3 /Program Files/Common Files/MSSoap/Binaries/mssoap1.dll 25088 ..c. r/rr-xr-xr-x 0 0 6126-128-3 /Program Files/Common Files/MSSoap/Binaries/wisc10.dll 144 .ac. d/dr-xr-xr-x 0 0 6127-144-1 /Program Files/Common Files/MSSoap/Binaries/Resources 152 .ac. d/dr-xr-xr-x 0 0 6128-144-1 /Program Files/Common Files/MSSoap/Binaries/Resources/1033 23552 ..c. r/rr-xr-xr-x 0 0 6129-128-3 /Program Files/Common Files/MSSoap/Binaries/Resources/1033/mssoapr.dll 16384 ..c. r/rr-xr-xr-x 0 0 6130-128-3 /Program Files/Internet Explorer/Connection Wizard/isignup.exe 73728 ..c. r/rr-xr-xr-x 0 0 6131-128-3 /Program Files/Internet Explorer/Connection Wizard/icwtutor.exe 61440 ..c. r/rr-xr-xr-x 0 0 6132-128-3 /Program Files/Internet Explorer/Connection Wizard/icwres.dll 40960 ..c. r/rr-xr-xr-x 0 0 6133-128-3 /Program Files/Internet Explorer/Connection Wizard/trialoc.dll 117006 ..c. r/rr-xr-xr-x 0 0 6137-128-3 /WINDOWS/Help/msoe.hlp 133 ..c. r/rr-xr-xr-x 0 0 6138-128-1 /Program Files/Outlook Express/msoe.txt 304 .ac. d/dr-xr-xr-x 0 0 6139-144-6 /Program Files/Common Files/Microsoft Shared/Stationery 7830 ..c. r/rr-xr-xr-x 0 0 6140-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/aleabanr.gif 2184 ..c. r/rr-xr-xr-x 0 0 6141-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/amaizrul.gif 15492 ..c. r/rr-xr-xr-x 0 0 6142-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/anabnr2.gif 2086 ..c. r/rr-xr-xr-x 0 0 6143-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/aswrule.gif 412 ..c. r/rr-xr-xr-x 0 0 6144-128-1 /Program Files/Common Files/Microsoft Shared/Stationery/Blank.htm 145 ..c. r/rr-xr-xr-x 0 0 6145-128-1 /Program Files/Common Files/Microsoft Shared/Stationery/Blank Bkgrd.gif 978 ..c. r/rr-xr-xr-x 0 0 6146-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/Btzhsepa.gif 11959 ..c. r/rr-xr-xr-x 0 0 6147-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/citbannA.gif 2454 ..c. r/rr-xr-xr-x 0 0 6148-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/Citrus Punch Bkgrd.gif 403 ..c. r/rr-xr-xr-x 0 0 6149-128-1 /Program Files/Common Files/Microsoft Shared/Stationery/Citrus Punch.htm 276 ..c. r/rr-xr-xr-x 0 0 6150-128-1 /Program Files/Common Files/Microsoft Shared/Stationery/Clear Day.htm 5675 ..c. r/rr-xr-xr-x 0 0 6151-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/Clear Day Bkgrd.jpg 1325 ..c. r/rr-xr-xr-x 0 0 6152-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/fieruled.gif 319 ..c. r/rr-xr-xr-x 0 0 6153-128-1 /Program Files/Common Files/Microsoft Shared/Stationery/Fiesta.htm 5048 ..c. r/rr-xr-xr-x 0 0 6154-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/Fiesta Bkgrd.jpg 272 ..c. r/rr-xr-xr-x 0 0 6155-128-1 /Program Files/Common Files/Microsoft Shared/Stationery/Glacier.htm 2743 ..c. r/rr-xr-xr-x 0 0 6156-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/Glacier Bkgrd.jpg 5665 ..c. r/rr-xr-xr-x 0 0 6157-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/Ivy.gif 367 ..c. r/rr-xr-xr-x 0 0 6158-128-1 /Program Files/Common Files/Microsoft Shared/Stationery/Ivy.htm 368 ..c. r/rr-xr-xr-x 0 0 6159-128-1 /Program Files/Common Files/Microsoft Shared/Stationery/Leaves.htm 4389 ..c. r/rr-xr-xr-x 0 0 6160-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/Leaves Bkgrd.jpg 366 ..c. r/rr-xr-xr-x 0 0 6161-128-1 /Program Files/Common Files/Microsoft Shared/Stationery/Maize.htm 11748 ..c. r/rr-xr-xr-x 0 0 6162-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/Maize Bkgrd.jpg 398 ..c. r/rr-xr-xr-x 0 0 6163-128-1 /Program Files/Common Files/Microsoft Shared/Stationery/Nature.htm 3781 ..c. r/rr-xr-xr-x 0 0 6164-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/Nature Bkgrd.jpg 407 ..c. r/rr-xr-xr-x 0 0 6165-128-1 /Program Files/Common Files/Microsoft Shared/Stationery/Network Blitz.htm 5314 ..c. r/rr-xr-xr-x 0 0 6166-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/Network Blitz Bkgrd.gif 2371 ..c. r/rr-xr-xr-x 0 0 6167-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/Pie Charts Bkgrd.jpg 290 ..c. r/rr-xr-xr-x 0 0 6168-128-1 /Program Files/Common Files/Microsoft Shared/Stationery/Pie Charts.htm 9749 ..c. r/rr-xr-xr-x 0 0 6169-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/sunbannA.gif 17147 ..c. r/rr-xr-xr-x 0 0 6170-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/Sunflower Bkgrd.jpg 402 ..c. r/rr-xr-xr-x 0 0 6171-128-1 /Program Files/Common Files/Microsoft Shared/Stationery/Sunflower.htm 361 ..c. r/rr-xr-xr-x 0 0 6172-128-1 /Program Files/Common Files/Microsoft Shared/Stationery/Sweets.htm 917 ..c. r/rr-xr-xr-x 0 0 6173-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/Sweets Bkgrd.gif 862 ..c. r/rr-xr-xr-x 0 0 6174-128-3 /Program Files/Common Files/Microsoft Shared/Stationery/tech.gif 411 ..c. r/rr-xr-xr-x 0 0 6175-128-1 /Program Files/Common Files/Microsoft Shared/Stationery/Technical.htm 59142 ..c. r/rr-xr-xr-x 0 0 6176-128-3 /WINDOWS/Help/wab.hlp 74905 ..c. r/rr-xr-xr-x 0 0 6177-128-3 /WINDOWS/Help/wab.chm 35240 ..c. r/rr-xr-xr-x 0 0 6178-128-3 /WINDOWS/Help/msoeacct.hlp 376 .ac. d/dr-xr-xr-x 0 0 6179-144-1 /Program Files/Common Files/Services 2805 ..c. r/rr-xr-xr-x 0 0 618-128-3 /WINDOWS/inf/ibmvcap.inf 2702 ..c. r/rr-xr-xr-x 0 0 6180-128-3 /Program Files/Common Files/Services/verisign.bmp 2702 ..c. r/rr-xr-xr-x 0 0 6181-128-3 /Program Files/Common Files/Services/bigfoot.bmp 2702 ..c. r/rr-xr-xr-x 0 0 6182-128-3 /Program Files/Common Files/Services/whowhere.bmp 48 .ac. d/dr-xr-xr-x 0 0 6184-144-1 /WINDOWS/pchealth/helpctr/BATCH 56 .ac. d/dr-xr-xr-x 0 0 6185-144-6 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US 39936 ..c. r/rr-xr-xr-x 0 0 6186-128-3 /Program Files/Common Files/Microsoft Shared/MSInfo/msinfo32.exe 12288 ..c. r/rr-xr-xr-x 0 0 6187-128-3 /Program Files/NetMeeting/cb32.exe 12288 ..c. r/rr-xr-xr-x 0 0 6188-128-3 /Program Files/NetMeeting/wb32.exe 79002 ..c. r/rr-xr-xr-x 0 0 6189-128-3 /Program Files/NetMeeting/TestSnd.wav 7655 ..c. r/rr-xr-xr-x 0 0 619-128-3 /WINDOWS/inf/icam3.inf 21260 ..c. r/rr-xr-xr-x 0 0 6190-128-3 /Program Files/NetMeeting/Blip.wav 106 ..c. r/rr-xr-xr-x 0 0 6193-128-1 /WINDOWS/Help/conf.cnt 11563 ..c. r/rr-xr-xr-x 0 0 6194-128-3 /WINDOWS/Help/nmchat.chm 22060 ..c. r/rr-xr-xr-x 0 0 6195-128-3 /Program Files/Windows Media Player/npds.zip 403 ..c. r/rr-xr-xr-x 0 0 6196-128-1 /Program Files/Windows Media Player/npdrmv2.zip 11141 ..c. r/rr-xr-xr-x 0 0 620-128-3 /WINDOWS/inf/icam4usb.inf 8049 ..c. r/rr-xr-xr-x 0 0 621-128-3 /WINDOWS/inf/icam5usb.inf 624 ..c. r/rr-xr-xr-x 0 0 622-128-1 /WINDOWS/inf/icminst.inf 8167 ..c. r/rr-xr-xr-x 0 0 624-128-3 /WINDOWS/inf/icwnt5.inf 256 .a.. d/dr-xr-xr-x 0 0 6247-144-1 /Documents and Settings/All Users/DRM 12701 ..c. r/rr-xr-xr-x 0 0 625-128-3 /WINDOWS/Help/ident.hlp 56 .ac. d/d--x--x--x 0 0 6253-144-6 /Documents and Settings/All Users/Documents/My Pictures/Sample Pictures 28521 ..c. r/rr-xr-xr-x 0 0 6254-128-3 /Documents and Settings/All Users/Documents/My Pictures/Sample Pictures/Blue hills.jpg 71189 ..c. r/rr-xr-xr-x 0 0 6255-128-3 /Documents and Settings/All Users/Documents/My Pictures/Sample Pictures/Sunset.jpg 83794 ..c. r/rr-xr-xr-x 0 0 6256-128-3 /Documents and Settings/All Users/Documents/My Pictures/Sample Pictures/Water lilies.jpg 105542 ..c. r/rr-xr-xr-x 0 0 6257-128-3 /Documents and Settings/All Users/Documents/My Pictures/Sample Pictures/Winter.jpg 56 ..c. d/d--x--x--x 0 0 6258-144-6 /Documents and Settings/All Users/Documents/My Music/Sample Music 12761 ..c. r/rr-xr-xr-x 0 0 626-128-3 /WINDOWS/Help/ieeula.chm 6656 ..c. r/rr-xr-xr-x 0 0 6261-128-3 /WINDOWS/pchealth/helpctr/binaries/HCAppRes.dll 99840 ..c. r/rr-xr-xr-x 0 0 6262-128-3 /WINDOWS/pchealth/helpctr/binaries/HelpHost.exe 21504 ..c. r/rr-xr-xr-x 0 0 6263-128-3 /WINDOWS/pchealth/helpctr/binaries/brpinfo.dll 35328 ..c. r/rr-xr-xr-x 0 0 6264-128-3 /WINDOWS/pchealth/helpctr/binaries/notiflag.exe 56 .ac. d/dr-xr-xr-x 0 0 6266-144-6 /WINDOWS/Help/Tours/WindowsMediaPlayer 10457 ..c. r/rr-xr-xr-x 0 0 6267-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/wmptour.hta 232 .ac. d/dr-xr-xr-x 0 0 6268-144-1 /WINDOWS/Help/Tours/WindowsMediaPlayer/Audio 1148 ..c. r/rr-xr-xr-x 0 0 6269-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Audio/snd.htm 56 .ac. d/dr-xr-xr-x 0 0 6270-144-5 /WINDOWS/Help/Tours/WindowsMediaPlayer/Audio/Wav 354468 ..c. r/rr-xr-xr-x 0 0 6271-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Audio/Wav/wmpaud1.wav 86180 ..c. r/rr-xr-xr-x 0 0 6272-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Audio/Wav/wmpaud2.wav 172196 ..c. r/rr-xr-xr-x 0 0 6273-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Audio/Wav/wmpaud3.wav 86180 ..c. r/rr-xr-xr-x 0 0 6274-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Audio/Wav/wmpaud4.wav 86196 ..c. r/rr-xr-xr-x 0 0 6275-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Audio/Wav/wmpaud5.wav 343204 ..c. r/rr-xr-xr-x 0 0 6276-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Audio/Wav/wmpaud6.wav 343204 ..c. r/rr-xr-xr-x 0 0 6277-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Audio/Wav/wmpaud7.wav 172196 ..c. r/rr-xr-xr-x 0 0 6278-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Audio/Wav/wmpaud8.wav 172196 ..c. r/rr-xr-xr-x 0 0 6279-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Audio/Wav/wmpaud9.wav 118460 ..c. r/rr-xr-xr-x 0 0 628-128-3 /WINDOWS/Help/ieakmmc.chm 264 .ac. d/dr-xr-xr-x 0 0 6280-144-1 /WINDOWS/Help/Tours/WindowsMediaPlayer/Cnt 8298 ..c. r/rr-xr-xr-x 0 0 6281-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Cnt/contents.htm 420 ..c. r/rr-xr-xr-x 0 0 6282-128-1 /WINDOWS/Help/Tours/WindowsMediaPlayer/Cnt/wmploc.js 264 .ac. d/dr-xr-xr-x 0 0 6283-144-1 /WINDOWS/Help/Tours/WindowsMediaPlayer/Css 9585 ..c. r/rr-xr-xr-x 0 0 6284-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Css/controls.css 1771 ..c. r/rr-xr-xr-x 0 0 6285-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Css/wmptour.css 56 .ac. d/dr-xr-xr-x 0 0 6286-144-5 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img 2545 ..c. r/rr-xr-xr-x 0 0 6287-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/mplogo.gif 2778 ..c. r/rr-xr-xr-x 0 0 6288-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/mplogoh.gif 23829 ..c. r/rr-xr-xr-x 0 0 6289-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/tourbg.gif 17489 ..c. r/rr-xr-xr-x 0 0 6290-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/videobg.gif 5290 ..c. r/rr-xr-xr-x 0 0 6291-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/vidsamp.gif 56 .ac. d/dr-xr-xr-x 0 0 6292-144-5 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/Btn 1005 ..c. r/rr-xr-xr-x 0 0 6293-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/Btn/bktr.gif 999 ..c. r/rr-xr-xr-x 0 0 6294-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/Btn/bktrh.gif 717 ..c. r/rr-xr-xr-x 0 0 6295-128-1 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/Btn/cloapp.gif 760 ..c. r/rr-xr-xr-x 0 0 6296-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/Btn/cloapph.gif 773 ..c. r/rr-xr-xr-x 0 0 6297-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/Btn/cnt.gif 772 ..c. r/rr-xr-xr-x 0 0 6298-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/Btn/cntd.gif 773 ..c. r/rr-xr-xr-x 0 0 6299-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/Btn/cnth.gif 48 .a.. d/dr-xr-xr-x 0 0 63-144-1 /WINDOWS/addins 12013 ..c. r/rr-xr-xr-x 0 0 630-128-3 /WINDOWS/Help/ieos.chm 1380 ..c. r/rr-xr-xr-x 0 0 6300-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/Btn/taoff.gif 1367 ..c. r/rr-xr-xr-x 0 0 6301-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/Btn/taoffh.gif 1398 ..c. r/rr-xr-xr-x 0 0 6302-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/Btn/taon.gif 1380 ..c. r/rr-xr-xr-x 0 0 6303-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/Btn/taonh.gif 2450 ..c. r/rr-xr-xr-x 0 0 6304-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/Btn/tpause.gif 2371 ..c. r/rr-xr-xr-x 0 0 6305-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/Btn/tpauseh.gif 2469 ..c. r/rr-xr-xr-x 0 0 6306-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/Btn/tplay.gif 2375 ..c. r/rr-xr-xr-x 0 0 6307-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/Btn/tplayh.gif 56 .ac. d/dr-xr-xr-x 0 0 6308-144-5 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/WMarks 5789 ..c. r/rr-xr-xr-x 0 0 6309-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/WMarks/wm1.gif 2762 ..c. r/rr-xr-xr-x 0 0 631-128-3 /WINDOWS/inf/iereset.inf 7636 ..c. r/rr-xr-xr-x 0 0 6310-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/WMarks/wm2.gif 6241 ..c. r/rr-xr-xr-x 0 0 6311-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/WMarks/wm3.gif 7369 ..c. r/rr-xr-xr-x 0 0 6312-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/WMarks/wm4.gif 2477 ..c. r/rr-xr-xr-x 0 0 6313-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/WMarks/wm5.gif 6060 ..c. r/rr-xr-xr-x 0 0 6314-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/WMarks/wm6.gif 8677 ..c. r/rr-xr-xr-x 0 0 6315-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/WMarks/wm7.gif 4193 ..c. r/rr-xr-xr-x 0 0 6316-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/WMarks/wm8.gif 7892 ..c. r/rr-xr-xr-x 0 0 6317-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Img/WMarks/wm9.gif 352 .ac. d/dr-xr-xr-x 0 0 6318-144-1 /WINDOWS/Help/Tours/WindowsMediaPlayer/Scr 6878 ..c. r/rr-xr-xr-x 0 0 6319-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Scr/controls.js 35774 ..c. r/rr-xr-xr-x 0 0 632-128-3 /WINDOWS/Help/ieshared.chm 5971 ..c. r/rr-xr-xr-x 0 0 6320-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Scr/events.js 3187 ..c. r/rr-xr-xr-x 0 0 6321-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Scr/tour.js 560 .ac. d/dr-xr-xr-x 0 0 6322-144-1 /WINDOWS/Help/Tours/WindowsMediaPlayer/Video 381425 ..c. r/rr-xr-xr-x 0 0 6323-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Video/copycd.wmv 457607 ..c. r/rr-xr-xr-x 0 0 6324-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Video/mdlib.wmv 375519 ..c. r/rr-xr-xr-x 0 0 6325-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Video/nuskin.wmv 572557 ..c. r/rr-xr-xr-x 0 0 6326-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Video/rtuner.wmv 300969 ..c. r/rr-xr-xr-x 0 0 6327-128-3 /WINDOWS/Help/Tours/WindowsMediaPlayer/Video/viz.wmv 144 .a.. d/dr-xr-xr-x 0 0 6328-144-1 /WINDOWS/system32/DirectX 56 .ac. d/dr-xr-xr-x 0 0 6329-144-6 /WINDOWS/system32/DirectX/Dinput 30148 ..c. r/rr-xr-xr-x 0 0 633-128-3 /WINDOWS/Help/iesupp.chm 13804 ..c. r/rr-xr-xr-x 0 0 6330-128-3 /WINDOWS/system32/DirectX/Dinput/glmda.ini 74585 ..c. r/rr-xr-xr-x 0 0 6331-128-3 /WINDOWS/system32/DirectX/Dinput/glmda.png 11886 ..c. r/rr-xr-xr-x 0 0 6332-128-3 /WINDOWS/system32/DirectX/Dinput/glmdiggp.ini 73786 ..c. r/rr-xr-xr-x 0 0 6333-128-3 /WINDOWS/system32/DirectX/Dinput/glmdiggp.png 18594 ..c. r/rr-xr-xr-x 0 0 6334-128-3 /WINDOWS/system32/DirectX/Dinput/hammer.ini 52876 ..c. r/rr-xr-xr-x 0 0 6335-128-3 /WINDOWS/system32/DirectX/Dinput/SV-262e1.png 53104 ..c. r/rr-xr-xr-x 0 0 6336-128-3 /WINDOWS/system32/DirectX/Dinput/SV-262e3.png 92178 ..c. r/rr-xr-xr-x 0 0 6337-128-3 /WINDOWS/system32/DirectX/Dinput/SV-262e4.png 24142 ..c. r/rr-xr-xr-x 0 0 6338-128-3 /WINDOWS/system32/DirectX/Dinput/raiderpd.ini 42674 ..c. r/rr-xr-xr-x 0 0 6339-128-3 /WINDOWS/system32/DirectX/Dinput/sv2511.png 12108 ..c. r/rr-xr-xr-x 0 0 634-128-3 /WINDOWS/Help/iewebhlp.chm 90339 ..c. r/rr-xr-xr-x 0 0 6340-128-3 /WINDOWS/system32/DirectX/Dinput/sv2512.png 11865 ..c. r/rr-xr-xr-x 0 0 6341-128-3 /WINDOWS/system32/DirectX/Dinput/ia3002.ini 59005 ..c. r/rr-xr-xr-x 0 0 6342-128-3 /WINDOWS/system32/DirectX/Dinput/ia3002_1.png 51179 ..c. r/rr-xr-xr-x 0 0 6343-128-3 /WINDOWS/system32/DirectX/Dinput/ia3002_2.png 5809 ..c. r/rr-xr-xr-x 0 0 6344-128-3 /WINDOWS/system32/DirectX/Dinput/lgc202.ini 31539 ..c. r/rr-xr-xr-x 0 0 6345-128-3 /WINDOWS/system32/DirectX/Dinput/lgc202.png 13610 ..c. r/rr-xr-xr-x 0 0 6346-128-3 /WINDOWS/system32/DirectX/Dinput/lgc207.ini 36408 ..c. r/rr-xr-xr-x 0 0 6347-128-3 /WINDOWS/system32/DirectX/Dinput/lgc207.png 3971 ..c. r/rr-xr-xr-x 0 0 6348-128-3 /WINDOWS/system32/DirectX/Dinput/lgc209.ini 38899 ..c. r/rr-xr-xr-x 0 0 6349-128-3 /WINDOWS/system32/DirectX/Dinput/lgc209.png 180335 ..c. r/rr-xr-xr-x 0 0 635-128-3 /WINDOWS/Help/iexplore.hlp 6735 ..c. r/rr-xr-xr-x 0 0 6350-128-3 /WINDOWS/system32/DirectX/Dinput/lgc20a.ini 39453 ..c. r/rr-xr-xr-x 0 0 6351-128-3 /WINDOWS/system32/DirectX/Dinput/lgc20a.png 2409 ..c. r/rr-xr-xr-x 0 0 6352-128-3 /WINDOWS/system32/DirectX/Dinput/lgc291.ini 29503 ..c. r/rr-xr-xr-x 0 0 6353-128-3 /WINDOWS/system32/DirectX/Dinput/lgc291.png 6761 ..c. r/rr-xr-xr-x 0 0 6354-128-3 /WINDOWS/system32/DirectX/Dinput/ms34.ini 58085 ..c. r/rr-xr-xr-x 0 0 6355-128-3 /WINDOWS/system32/DirectX/Dinput/ms34.png 5085 ..c. r/rr-xr-xr-x 0 0 6356-128-3 /WINDOWS/system32/DirectX/Dinput/ms34_01.png 3382 ..c. r/rr-xr-xr-x 0 0 6357-128-3 /WINDOWS/system32/DirectX/Dinput/ms34_02.png 595 ..c. r/rr-xr-xr-x 0 0 6358-128-1 /WINDOWS/system32/DirectX/Dinput/ms34_03.png 1006 ..c. r/rr-xr-xr-x 0 0 6359-128-3 /WINDOWS/system32/DirectX/Dinput/ms34_04.png 1152 ..c. r/rr-xr-xr-x 0 0 6360-128-3 /WINDOWS/system32/DirectX/Dinput/ms34_05.png 575 ..c. r/rr-xr-xr-x 0 0 6361-128-1 /WINDOWS/system32/DirectX/Dinput/ms34_06.png 592 ..c. r/rr-xr-xr-x 0 0 6362-128-1 /WINDOWS/system32/DirectX/Dinput/ms34_07.png 585 ..c. r/rr-xr-xr-x 0 0 6363-128-1 /WINDOWS/system32/DirectX/Dinput/ms34_08.png 14450 ..c. r/rr-xr-xr-x 0 0 6364-128-3 /WINDOWS/system32/DirectX/Dinput/ms1b.ini 50325 ..c. r/rr-xr-xr-x 0 0 6365-128-3 /WINDOWS/system32/DirectX/Dinput/ms1b.png 2018 ..c. r/rr-xr-xr-x 0 0 6366-128-3 /WINDOWS/system32/DirectX/Dinput/ms1b_01.png 739 ..c. r/rr-xr-xr-x 0 0 6367-128-3 /WINDOWS/system32/DirectX/Dinput/ms1b_02.png 581 ..c. r/rr-xr-xr-x 0 0 6368-128-1 /WINDOWS/system32/DirectX/Dinput/ms1b_03.png 788 ..c. r/rr-xr-xr-x 0 0 6369-128-3 /WINDOWS/system32/DirectX/Dinput/ms1b_04.png 6324 ..c. r/rr-xr-xr-x 0 0 637-128-3 /WINDOWS/inf/igames.inf 380 ..c. r/rr-xr-xr-x 0 0 6370-128-1 /WINDOWS/system32/DirectX/Dinput/ms1b_05.png 406 ..c. r/rr-xr-xr-x 0 0 6371-128-1 /WINDOWS/system32/DirectX/Dinput/ms1b_06.png 575 ..c. r/rr-xr-xr-x 0 0 6372-128-1 /WINDOWS/system32/DirectX/Dinput/ms1b_07.png 576 ..c. r/rr-xr-xr-x 0 0 6373-128-1 /WINDOWS/system32/DirectX/Dinput/ms1b_08.png 645 ..c. r/rr-xr-xr-x 0 0 6374-128-1 /WINDOWS/system32/DirectX/Dinput/ms1b_09.png 641 ..c. r/rr-xr-xr-x 0 0 6375-128-1 /WINDOWS/system32/DirectX/Dinput/ms1b_10.png 8389 ..c. r/rr-xr-xr-x 0 0 6376-128-3 /WINDOWS/system32/DirectX/Dinput/ms26.ini 66085 ..c. r/rr-xr-xr-x 0 0 6377-128-3 /WINDOWS/system32/DirectX/Dinput/ms26.png 3084 ..c. r/rr-xr-xr-x 0 0 6378-128-3 /WINDOWS/system32/DirectX/Dinput/ms26_01.png 1535 ..c. r/rr-xr-xr-x 0 0 6379-128-3 /WINDOWS/system32/DirectX/Dinput/ms26_02.png 11549 ..c. r/rr-xr-xr-x 0 0 638-128-3 /WINDOWS/Help/iismmc.chm 1216 ..c. r/rr-xr-xr-x 0 0 6380-128-3 /WINDOWS/system32/DirectX/Dinput/ms26_03.png 1150 ..c. r/rr-xr-xr-x 0 0 6381-128-3 /WINDOWS/system32/DirectX/Dinput/ms26_04.png 1132 ..c. r/rr-xr-xr-x 0 0 6382-128-3 /WINDOWS/system32/DirectX/Dinput/ms26_05.png 1099 ..c. r/rr-xr-xr-x 0 0 6383-128-3 /WINDOWS/system32/DirectX/Dinput/ms26_06.png 962 ..c. r/rr-xr-xr-x 0 0 6384-128-3 /WINDOWS/system32/DirectX/Dinput/ms26_07.png 910 ..c. r/rr-xr-xr-x 0 0 6385-128-3 /WINDOWS/system32/DirectX/Dinput/ms26_08.png 6085 ..c. r/rr-xr-xr-x 0 0 6386-128-3 /WINDOWS/system32/DirectX/Dinput/mse_g.ini 4543 ..c. r/rr-xr-xr-x 0 0 6387-128-3 /WINDOWS/system32/DirectX/Dinput/mse.ini 69437 ..c. r/rr-xr-xr-x 0 0 6388-128-3 /WINDOWS/system32/DirectX/Dinput/mse.png 3973 ..c. r/rr-xr-xr-x 0 0 6389-128-3 /WINDOWS/system32/DirectX/Dinput/mse_1.png 1204 ..c. r/rr-xr-xr-x 0 0 6390-128-3 /WINDOWS/system32/DirectX/Dinput/mse_2.png 1294 ..c. r/rr-xr-xr-x 0 0 6391-128-3 /WINDOWS/system32/DirectX/Dinput/mse_3.png 1154 ..c. r/rr-xr-xr-x 0 0 6392-128-3 /WINDOWS/system32/DirectX/Dinput/mse_4.png 1322 ..c. r/rr-xr-xr-x 0 0 6393-128-3 /WINDOWS/system32/DirectX/Dinput/mse_5.png 1241 ..c. r/rr-xr-xr-x 0 0 6394-128-3 /WINDOWS/system32/DirectX/Dinput/mse_6.png 1277 ..c. r/rr-xr-xr-x 0 0 6395-128-3 /WINDOWS/system32/DirectX/Dinput/mse_7.png 892 ..c. r/rr-xr-xr-x 0 0 6396-128-3 /WINDOWS/system32/DirectX/Dinput/mse_8.png 1721 ..c. r/rr-xr-xr-x 0 0 6397-128-3 /WINDOWS/system32/DirectX/Dinput/mse_9.png 1113 ..c. r/rr-xr-xr-x 0 0 6398-128-3 /WINDOWS/system32/DirectX/Dinput/mse_10.png 6073 ..c. r/rr-xr-xr-x 0 0 6399-128-3 /WINDOWS/system32/DirectX/Dinput/ms8.ini 48 .a.. d/dr-xr-xr-x 0 0 64-144-1 /WINDOWS/Connection Wizard 19224 ..c. r/rr-xr-xr-x 0 0 640-128-3 /WINDOWS/inf/image.inf 5832 ..c. r/rr-xr-xr-x 0 0 6400-128-3 /WINDOWS/system32/DirectX/Dinput/ms8_g.ini 55905 ..c. r/rr-xr-xr-x 0 0 6401-128-3 /WINDOWS/system32/DirectX/Dinput/ms8.png 2355 ..c. r/rr-xr-xr-x 0 0 6402-128-3 /WINDOWS/system32/DirectX/Dinput/ms8_1.png 681 ..c. r/rr-xr-xr-x 0 0 6403-128-1 /WINDOWS/system32/DirectX/Dinput/ms8_2.png 1091 ..c. r/rr-xr-xr-x 0 0 6404-128-3 /WINDOWS/system32/DirectX/Dinput/ms8_3.png 450 ..c. r/rr-xr-xr-x 0 0 6405-128-1 /WINDOWS/system32/DirectX/Dinput/ms8_4.png 495 ..c. r/rr-xr-xr-x 0 0 6406-128-1 /WINDOWS/system32/DirectX/Dinput/ms8_5.png 715 ..c. r/rr-xr-xr-x 0 0 6407-128-1 /WINDOWS/system32/DirectX/Dinput/ms8_6.png 748 ..c. r/rr-xr-xr-x 0 0 6408-128-3 /WINDOWS/system32/DirectX/Dinput/ms8_7.png 769 ..c. r/rr-xr-xr-x 0 0 6409-128-3 /WINDOWS/system32/DirectX/Dinput/ms8_8.png 30369 ..c. r/rr-xr-xr-x 0 0 641-128-3 /WINDOWS/Help/imgprev.chm 769 ..c. r/rr-xr-xr-x 0 0 6410-128-3 /WINDOWS/system32/DirectX/Dinput/ms8_9.png 1518 ..c. r/rr-xr-xr-x 0 0 6411-128-3 /WINDOWS/system32/DirectX/Dinput/ms8_10.png 3106 ..c. r/rr-xr-xr-x 0 0 6412-128-3 /WINDOWS/system32/DirectX/Dinput/ms7.ini 3068 ..c. r/rr-xr-xr-x 0 0 6413-128-3 /WINDOWS/system32/DirectX/Dinput/ms7_g.ini 65985 ..c. r/rr-xr-xr-x 0 0 6414-128-3 /WINDOWS/system32/DirectX/Dinput/ms7.png 4412 ..c. r/rr-xr-xr-x 0 0 6415-128-3 /WINDOWS/system32/DirectX/Dinput/ms7_1.png 1254 ..c. r/rr-xr-xr-x 0 0 6416-128-3 /WINDOWS/system32/DirectX/Dinput/ms7_2.png 1278 ..c. r/rr-xr-xr-x 0 0 6417-128-3 /WINDOWS/system32/DirectX/Dinput/ms7_3.png 1301 ..c. r/rr-xr-xr-x 0 0 6418-128-3 /WINDOWS/system32/DirectX/Dinput/ms7_4.png 963 ..c. r/rr-xr-xr-x 0 0 6419-128-3 /WINDOWS/system32/DirectX/Dinput/ms7_5.png 6823 ..c. r/rr-xr-xr-x 0 0 642-128-3 /WINDOWS/inf/inetcorp.adm 982 ..c. r/rr-xr-xr-x 0 0 6420-128-3 /WINDOWS/system32/DirectX/Dinput/ms7_6.png 1071 ..c. r/rr-xr-xr-x 0 0 6421-128-3 /WINDOWS/system32/DirectX/Dinput/ms7_7.png 829 ..c. r/rr-xr-xr-x 0 0 6422-128-3 /WINDOWS/system32/DirectX/Dinput/ms7_8.png 1207 ..c. r/rr-xr-xr-x 0 0 6423-128-3 /WINDOWS/system32/DirectX/Dinput/ms7_9.png 5171 ..c. r/rr-xr-xr-x 0 0 6424-128-3 /WINDOWS/system32/DirectX/Dinput/ms6.ini 58484 ..c. r/rr-xr-xr-x 0 0 6425-128-3 /WINDOWS/system32/DirectX/Dinput/ms6.png 1130 ..c. r/rr-xr-xr-x 0 0 6426-128-3 /WINDOWS/system32/DirectX/Dinput/ms6_1.png 681 ..c. r/rr-xr-xr-x 0 0 6427-128-1 /WINDOWS/system32/DirectX/Dinput/ms6_2.png 510 ..c. r/rr-xr-xr-x 0 0 6428-128-1 /WINDOWS/system32/DirectX/Dinput/ms6_3.png 511 ..c. r/rr-xr-xr-x 0 0 6429-128-1 /WINDOWS/system32/DirectX/Dinput/ms6_4.png 792 ..c. r/rr-xr-xr-x 0 0 6430-128-3 /WINDOWS/system32/DirectX/Dinput/ms6_5.png 753 ..c. r/rr-xr-xr-x 0 0 6431-128-3 /WINDOWS/system32/DirectX/Dinput/ms6_6.png 774 ..c. r/rr-xr-xr-x 0 0 6432-128-3 /WINDOWS/system32/DirectX/Dinput/ms6_7.png 757 ..c. r/rr-xr-xr-x 0 0 6433-128-3 /WINDOWS/system32/DirectX/Dinput/ms6_8.png 2436 ..c. r/rr-xr-xr-x 0 0 6434-128-3 /WINDOWS/system32/DirectX/Dinput/ms6_9.png 1414 ..c. r/rr-xr-xr-x 0 0 6435-128-3 /WINDOWS/system32/DirectX/Dinput/ms6_10.png 5915 ..c. r/rr-xr-xr-x 0 0 6436-128-3 /WINDOWS/system32/DirectX/Dinput/msf1f.ini 60612 ..c. r/rr-xr-xr-x 0 0 6437-128-3 /WINDOWS/system32/DirectX/Dinput/msf1f.png 1293 ..c. r/rr-xr-xr-x 0 0 6438-128-3 /WINDOWS/system32/DirectX/Dinput/msf1f_1.png 1125 ..c. r/rr-xr-xr-x 0 0 6439-128-3 /WINDOWS/system32/DirectX/Dinput/msf1f_2.png 891 ..c. r/rr-xr-xr-x 0 0 6440-128-3 /WINDOWS/system32/DirectX/Dinput/msf1f_3.png 639 ..c. r/rr-xr-xr-x 0 0 6441-128-1 /WINDOWS/system32/DirectX/Dinput/msf1f_4.png 646 ..c. r/rr-xr-xr-x 0 0 6442-128-1 /WINDOWS/system32/DirectX/Dinput/msf1f_5.png 947 ..c. r/rr-xr-xr-x 0 0 6443-128-3 /WINDOWS/system32/DirectX/Dinput/msf1f_6.png 850 ..c. r/rr-xr-xr-x 0 0 6444-128-3 /WINDOWS/system32/DirectX/Dinput/msf1f_7.png 870 ..c. r/rr-xr-xr-x 0 0 6445-128-3 /WINDOWS/system32/DirectX/Dinput/msf1f_8.png 765 ..c. r/rr-xr-xr-x 0 0 6446-128-3 /WINDOWS/system32/DirectX/Dinput/msf1f_9.png 832 ..c. r/rr-xr-xr-x 0 0 6447-128-3 /WINDOWS/system32/DirectX/Dinput/msf1f_10.png 5848 ..c. r/rr-xr-xr-x 0 0 6448-128-3 /WINDOWS/system32/DirectX/Dinput/ms56.ini 59623 ..c. r/rr-xr-xr-x 0 0 6449-128-3 /WINDOWS/system32/DirectX/Dinput/ms56.png 13943 ..c. r/rr-xr-xr-x 0 0 645-128-3 /WINDOWS/Help/infrared.hlp 2796 ..c. r/rr-xr-xr-x 0 0 6450-128-3 /WINDOWS/system32/DirectX/Dinput/ms56_1.png 862 ..c. r/rr-xr-xr-x 0 0 6451-128-3 /WINDOWS/system32/DirectX/Dinput/ms56_2.png 990 ..c. r/rr-xr-xr-x 0 0 6452-128-3 /WINDOWS/system32/DirectX/Dinput/ms56_3.png 937 ..c. r/rr-xr-xr-x 0 0 6453-128-3 /WINDOWS/system32/DirectX/Dinput/ms56_4.png 523 ..c. r/rr-xr-xr-x 0 0 6454-128-1 /WINDOWS/system32/DirectX/Dinput/ms56_5.png 496 ..c. r/rr-xr-xr-x 0 0 6455-128-1 /WINDOWS/system32/DirectX/Dinput/ms56_6.png 846 ..c. r/rr-xr-xr-x 0 0 6456-128-3 /WINDOWS/system32/DirectX/Dinput/ms56_7.png 743 ..c. r/rr-xr-xr-x 0 0 6457-128-3 /WINDOWS/system32/DirectX/Dinput/ms56_8.png 864 ..c. r/rr-xr-xr-x 0 0 6458-128-3 /WINDOWS/system32/DirectX/Dinput/ms56_9.png 885 ..c. r/rr-xr-xr-x 0 0 6459-128-3 /WINDOWS/system32/DirectX/Dinput/ms56_10.png 17944 ..c. r/rr-xr-xr-x 0 0 646-128-3 /WINDOWS/Help/intellimirror.chm 3951 ..c. r/rr-xr-xr-x 0 0 6460-128-3 /WINDOWS/system32/DirectX/Dinput/msprw.ini 51544 ..c. r/rr-xr-xr-x 0 0 6461-128-3 /WINDOWS/system32/DirectX/Dinput/msprw.png 4040 ..c. r/rr-xr-xr-x 0 0 6462-128-3 /WINDOWS/system32/DirectX/Dinput/msprw_1.png 6043 ..c. r/rr-xr-xr-x 0 0 6463-128-3 /WINDOWS/system32/DirectX/Dinput/msprw_2.png 1444 ..c. r/rr-xr-xr-x 0 0 6464-128-3 /WINDOWS/system32/DirectX/Dinput/msprw_3.png 1365 ..c. r/rr-xr-xr-x 0 0 6465-128-3 /WINDOWS/system32/DirectX/Dinput/msprw_4.png 1423 ..c. r/rr-xr-xr-x 0 0 6466-128-3 /WINDOWS/system32/DirectX/Dinput/msprw_5.png 1380 ..c. r/rr-xr-xr-x 0 0 6467-128-3 /WINDOWS/system32/DirectX/Dinput/msprw_6.png 1697 ..c. r/rr-xr-xr-x 0 0 6468-128-3 /WINDOWS/system32/DirectX/Dinput/msprw_7.png 1476 ..c. r/rr-xr-xr-x 0 0 6469-128-3 /WINDOWS/system32/DirectX/Dinput/msprw_8.png 3203 ..c. r/rr-xr-xr-x 0 0 6470-128-3 /WINDOWS/system32/DirectX/Dinput/ms28.ini 4372 ..c. r/rr-xr-xr-x 0 0 6471-128-3 /WINDOWS/system32/DirectX/Dinput/ms28_8.png 68342 ..c. r/rr-xr-xr-x 0 0 6472-128-3 /WINDOWS/system32/DirectX/Dinput/ms28.png 790 ..c. r/rr-xr-xr-x 0 0 6473-128-3 /WINDOWS/system32/DirectX/Dinput/ms28_1.png 932 ..c. r/rr-xr-xr-x 0 0 6474-128-3 /WINDOWS/system32/DirectX/Dinput/ms28_2.png 883 ..c. r/rr-xr-xr-x 0 0 6475-128-3 /WINDOWS/system32/DirectX/Dinput/ms28_3.png 1014 ..c. r/rr-xr-xr-x 0 0 6476-128-3 /WINDOWS/system32/DirectX/Dinput/ms28_4.png 1073 ..c. r/rr-xr-xr-x 0 0 6477-128-3 /WINDOWS/system32/DirectX/Dinput/ms28_5.png 1135 ..c. r/rr-xr-xr-x 0 0 6478-128-3 /WINDOWS/system32/DirectX/Dinput/ms28_6.png 1228 ..c. r/rr-xr-xr-x 0 0 6479-128-3 /WINDOWS/system32/DirectX/Dinput/ms28_7.png 13437 ..c. r/rr-xr-xr-x 0 0 648-128-3 /WINDOWS/system32/icsxml/ipcfg.xml 63020 ..c. r/rr-xr-xr-x 0 0 6480-128-3 /WINDOWS/system32/DirectX/Dinput/ms27.png 4510 ..c. r/rr-xr-xr-x 0 0 6481-128-3 /WINDOWS/system32/DirectX/Dinput/ms27.ini 3396 ..c. r/rr-xr-xr-x 0 0 6482-128-3 /WINDOWS/system32/DirectX/Dinput/ms27_1.png 1389 ..c. r/rr-xr-xr-x 0 0 6483-128-3 /WINDOWS/system32/DirectX/Dinput/ms27_2.png 1334 ..c. r/rr-xr-xr-x 0 0 6484-128-3 /WINDOWS/system32/DirectX/Dinput/ms27_3.png 1136 ..c. r/rr-xr-xr-x 0 0 6485-128-3 /WINDOWS/system32/DirectX/Dinput/ms27_4.png 1111 ..c. r/rr-xr-xr-x 0 0 6486-128-3 /WINDOWS/system32/DirectX/Dinput/ms27_5.png 43640 ..c. r/rr-xr-xr-x 0 0 6487-128-3 /WINDOWS/system32/DirectX/Dinput/ms3b.png 2078 ..c. r/rr-xr-xr-x 0 0 6488-128-3 /WINDOWS/system32/DirectX/Dinput/ms3b.ini 3109 ..c. r/rr-xr-xr-x 0 0 6489-128-3 /WINDOWS/system32/DirectX/Dinput/ms3b_1.png 32896 ..c. r/rr-xr-xr-x 0 0 649-128-3 /WINDOWS/system32/drivers/ipfltdrv.sys 2534 ..c. r/rr-xr-xr-x 0 0 6490-128-3 /WINDOWS/system32/DirectX/Dinput/ms3b_2.png 2313 ..c. r/rr-xr-xr-x 0 0 6491-128-3 /WINDOWS/system32/DirectX/Dinput/ms3b_3.png 2387 ..c. r/rr-xr-xr-x 0 0 6492-128-3 /WINDOWS/system32/DirectX/Dinput/ms3b_4.png 4381 ..c. r/rr-xr-xr-x 0 0 6493-128-3 /WINDOWS/system32/DirectX/Dinput/ms3b_a.png 7794 ..c. r/rr-xr-xr-x 0 0 6494-128-3 /WINDOWS/system32/DirectX/Dinput/ms3b_c.png 3431 ..c. r/rr-xr-xr-x 0 0 6495-128-3 /WINDOWS/system32/DirectX/Dinput/ms3b_m.png 3638 ..c. r/rr-xr-xr-x 0 0 6496-128-3 /WINDOWS/system32/DirectX/Dinput/ms3b_t.png 3529 ..c. r/rr-xr-xr-x 0 0 6497-128-3 /WINDOWS/system32/DirectX/Dinput/gr4003.ini 30100 ..c. r/rr-xr-xr-x 0 0 6498-128-3 /WINDOWS/system32/DirectX/Dinput/gr4003.png 5013 ..c. r/rr-xr-xr-x 0 0 6499-128-3 /WINDOWS/system32/DirectX/Dinput/gr3001.ini 144 .a.. d/dr-xr-xr-x 0 0 65-144-1 /WINDOWS/Driver Cache 37743 ..c. r/rr-xr-xr-x 0 0 6500-128-3 /WINDOWS/system32/DirectX/Dinput/gr3001.png 3865 ..c. r/rr-xr-xr-x 0 0 6501-128-3 /WINDOWS/system32/DirectX/Dinput/gr3001_g.ini 2142 ..c. r/rr-xr-xr-x 0 0 6502-128-3 /WINDOWS/system32/DirectX/Dinput/gr4005.ini 34022 ..c. r/rr-xr-xr-x 0 0 6503-128-3 /WINDOWS/system32/DirectX/Dinput/gr4005.png 16226 ..c. r/rr-xr-xr-x 0 0 6504-128-3 /WINDOWS/system32/DirectX/Dinput/gr4001.ini 31621 ..c. r/rr-xr-xr-x 0 0 6505-128-3 /WINDOWS/system32/DirectX/Dinput/gr4001.png 14416 ..c. r/rr-xr-xr-x 0 0 6506-128-3 /WINDOWS/system32/DirectX/Dinput/gr4001_g.ini 27459 ..c. r/rr-xr-xr-x 0 0 6507-128-3 /WINDOWS/system32/DirectX/Dinput/gr4001_g.png 96731 ..c. r/rr-xr-xr-x 0 0 6508-128-3 /WINDOWS/system32/DirectX/Dinput/act_rs.png 4069 ..c. r/rr-xr-xr-x 0 0 6509-128-3 /WINDOWS/system32/DirectX/Dinput/actc094.ini 4399505 ..c. r/rr-xr-xr-x 0 0 6510-128-3 /WINDOWS/srchasst/nls302en.lex 1861820 ..c. r/rr-xr-xr-x 0 0 6511-128-3 /WINDOWS/srchasst/chars/rover.acs 34671 ..c. r/rr-xr-xr-x 0 0 6512-128-3 /WINDOWS/srchasst/mui/0409/balloon.xsl 34643 ..c. r/rr-xr-xr-x 0 0 6513-128-3 /WINDOWS/srchasst/mui/0409/bar.xsl 242 ..c. r/rr-xr-xr-x 0 0 6514-128-1 /WINDOWS/srchasst/mui/0409/charchsr.xml 530 ..c. r/rr-xr-xr-x 0 0 6515-128-1 /WINDOWS/srchasst/mui/0409/charctxt.xml 105 ..c. r/rr-xr-xr-x 0 0 6516-128-1 /WINDOWS/srchasst/mui/0409/error.xml 1070 ..c. r/rr-xr-xr-x 0 0 6517-128-3 /WINDOWS/srchasst/mui/0409/finish.xml 1397 ..c. r/rr-xr-xr-x 0 0 6518-128-3 /WINDOWS/srchasst/mui/0409/indxsvc.xml 799 ..c. r/rr-xr-xr-x 0 0 6519-128-3 /WINDOWS/srchasst/mui/0409/inetfind.xml 1542 ..c. r/rr-xr-xr-x 0 0 6520-128-3 /WINDOWS/srchasst/mui/0409/inetopts.xml 1192 ..c. r/rr-xr-xr-x 0 0 6521-128-3 /WINDOWS/srchasst/mui/0409/inetsrch.xml 612 ..c. r/rr-xr-xr-x 0 0 6522-128-1 /WINDOWS/srchasst/mui/0409/intents.xml 563 ..c. r/rr-xr-xr-x 0 0 6523-128-1 /WINDOWS/srchasst/mui/0409/intro.xml 6228 ..c. r/rr-xr-xr-x 0 0 6524-128-3 /WINDOWS/srchasst/mui/0409/lcladv.xml 6574 ..c. r/rr-xr-xr-x 0 0 6525-128-3 /WINDOWS/srchasst/mui/0409/lcladvdf.xml 7354 ..c. r/rr-xr-xr-x 0 0 6526-128-3 /WINDOWS/srchasst/mui/0409/lcladvmm.xml 794 ..c. r/rr-xr-xr-x 0 0 6527-128-3 /WINDOWS/srchasst/mui/0409/lclcomp.xml 2114 ..c. r/rr-xr-xr-x 0 0 6528-128-3 /WINDOWS/srchasst/mui/0409/lcldate.xml 462 ..c. r/rr-xr-xr-x 0 0 6529-128-1 /WINDOWS/srchasst/mui/0409/lclkwrds.xml 381 ..c. r/rr-xr-xr-x 0 0 6530-128-1 /WINDOWS/srchasst/mui/0409/lcllook.xml 545 ..c. r/rr-xr-xr-x 0 0 6531-128-1 /WINDOWS/srchasst/mui/0409/lclmode.xml 732 ..c. r/rr-xr-xr-x 0 0 6532-128-3 /WINDOWS/srchasst/mui/0409/lclother.xml 2140 ..c. r/rr-xr-xr-x 0 0 6533-128-3 /WINDOWS/srchasst/mui/0409/lclprog.xml 6551 ..c. r/rr-xr-xr-x 0 0 6534-128-3 /WINDOWS/srchasst/mui/0409/lclrfine.xml 1622 ..c. r/rr-xr-xr-x 0 0 6535-128-3 /WINDOWS/srchasst/mui/0409/lclsize.xml 1324 ..c. r/rr-xr-xr-x 0 0 6536-128-3 /WINDOWS/srchasst/mui/0409/lclsrch.xml 656 ..c. r/rr-xr-xr-x 0 0 6537-128-1 /WINDOWS/srchasst/mui/0409/lcltechy.xml 1640 ..c. r/rr-xr-xr-x 0 0 6539-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Communications/Network Setup Wizard.lnk 1572 ..c. r/rr-xr-xr-x 0 0 6540-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/System Tools/Disk Defragmenter.lnk 1070 ..c. r/rr-xr-xr-x 0 0 6541-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/System Tools/System Information.lnk 1616 ..c. r/rr-xr-xr-x 0 0 6542-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/System Tools/System Restore.lnk 56 .ac. d/d--x--x--x 0 0 6543-144-6 /Documents and Settings/Default User/Start Menu/Programs/Accessories 1487 ..c. r/rr-xr-xr-x 0 0 6544-128-4 /Documents and Settings/Default User/Start Menu/Programs/Accessories/Windows Explorer.lnk 1532 ..c. r/rr-xr-xr-x 0 0 6546-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/System Tools/Disk Cleanup.lnk 1753 ..c. r/rr-xr-xr-x 0 0 6547-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/System Tools/Scheduled Tasks.lnk 1007 ..c. r/rr-xr-xr-x 0 0 6548-128-4 /Program Files/Online Services/Refer me to more Internet Service Providers.lnk 786 ..c. r/rr-xr-xr-x 0 0 6549-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Windows Movie Maker.lnk 48 .ac. d/dr-xr-xr-x 0 0 6550-144-1 /Program Files/WindowsUpdate 0 ..c. r/rr-xr-xr-x 0 0 6551-128-1 /Documents and Settings/Default User/SendTo/Mail Recipient.MAPIMail 0 ..c. r/rr-xr-xr-x 0 0 6561-128-1 /Documents and Settings/Default User/SendTo/Desktop (create shortcut).DeskLink 152 .a.. d/drwxrwxrwx 0 0 6564-144-1 /WINDOWS/Downloaded Program Files 65 ..c. r/rr-xr-xr-x 0 0 6565-128-1 /WINDOWS/Downloaded Program Files/desktop.ini 152 .a.. d/d--x--x--x 0 0 6566-144-1 /WINDOWS/Offline Web Pages 65 ..c. r/rr-xr-xr-x 0 0 6567-128-1 /WINDOWS/Offline Web Pages/desktop.ini 0 ..c. r/rr-xr-xr-x 0 0 6568-128-1 /Documents and Settings/Default User/SendTo/Compressed (zipped) Folder.ZFSendToTarget 160 .ac. d/dr-xr-xr-x 0 0 6570-144-1 /WINDOWS/pchealth/helpctr/Logs 48 .ac. d/dr-xr-xr-x 0 0 6571-144-1 /WINDOWS/pchealth/helpctr/Temp 56 .ac. d/dr-xr-xr-x 0 0 6572-144-6 /WINDOWS/pchealth/helpctr/OfflineCache 48 .ac. d/dr-xr-xr-x 0 0 6573-144-1 /WINDOWS/pchealth/helpctr/InstalledSKUs 56 .ac. d/dr-xr-xr-x 0 0 6574-144-6 /WINDOWS/pchealth/helpctr/PackageStore 2435 ..c. r/rr-xr-xr-x 0 0 6575-128-3 /WINDOWS/pchealth/helpctr/Config/dataspec.xml 152 .ac. d/dr-xr-xr-x 0 0 6577-144-1 /WINDOWS/pchealth/UploadLB/Config 466 ..c. r/rr-xr-xr-x 0 0 6578-128-1 /WINDOWS/pchealth/UploadLB/Config/config.xml 152 .ac. d/dr-xr-xr-x 0 0 6580-144-1 /WINDOWS/pchealth/helpctr/Database 56 .ac. d/dr-xr-xr-x 0 0 6582-144-5 /WINDOWS/pchealth/helpctr/Indices 56 .ac. d/dr-xr-xr-x 0 0 6583-144-5 /WINDOWS/pchealth/helpctr/System 48 .ac. d/dr-xr-xr-x 0 0 6584-144-1 /WINDOWS/pchealth/helpctr/System_OEM 672 .ac. d/dr-xr-xr-x 0 0 6585-144-1 /WINDOWS/pchealth/helpctr/Vendors 48 .ac. d/dr-xr-xr-x 0 0 6586-144-1 /WINDOWS/pchealth/helpctr/HelpFiles 1206 ..c. r/rr-xr-xr-x 0 0 6587-128-3 /WINDOWS/pchealth/helpctr/System/DVDUpgrd/dvdupgrd.js 6150 ..c. r/rr-xr-xr-x 0 0 6588-128-4 /WINDOWS/pchealth/helpctr/System/Headlines.htm 7737 ..c. r/rr-xr-xr-x 0 0 6589-128-4 /WINDOWS/pchealth/helpctr/System/HomePage__DESKTOP.htm 7355 ..c. r/rr-xr-xr-x 0 0 6590-128-4 /WINDOWS/pchealth/helpctr/System/HomePage__SERVER.htm 376 .ac. d/dr-xr-xr-x 0 0 6591-144-1 /WINDOWS/pchealth/helpctr/System/NetDiag 2654 ..c. r/rr-xr-xr-x 0 0 6592-128-4 /WINDOWS/pchealth/helpctr/System/NetDiag/dglogshelp.htm 176 .ac. d/dr-xr-xr-x 0 0 6593-144-5 /WINDOWS/pchealth/helpctr/System/sysinfo 56777 ..c. r/rr-xr-xr-x 0 0 6594-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/RSoP.js 32141 ..c. r/rr-xr-xr-x 0 0 6595-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/commonFunc.js 26520 ..c. r/rr-xr-xr-x 0 0 6596-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/loc_strings.xml 582 ..c. r/rr-xr-xr-x 0 0 6597-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/msinfohss.css 25050 ..c. r/rr-xr-xr-x 0 0 6598-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/sysComponentInfo.htm 27910 ..c. r/rr-xr-xr-x 0 0 6599-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/sysComponentInfo.js 248 .ac. d/dr-xr-xr-x 0 0 66-144-1 /WINDOWS/Driver Cache/i386 1323 ..c. r/rr-xr-xr-x 0 0 6600-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/sysConfigLaunch.htm 2537 ..c. r/rr-xr-xr-x 0 0 6601-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/sysDiskTS.htm 10312 ..c. r/rr-xr-xr-x 0 0 6602-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/sysEvtLogInfo.htm 13556 ..c. r/rr-xr-xr-x 0 0 6603-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/sysHealthInfo.htm 20083 ..c. r/rr-xr-xr-x 0 0 6604-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/sysHealthInfo.js 4132 ..c. r/rr-xr-xr-x 0 0 6605-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/sysInfoLaunch.htm 1864 ..c. r/rr-xr-xr-x 0 0 6606-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/sysRemoteInfo.htm 10136 ..c. r/rr-xr-xr-x 0 0 6607-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/sysServicesInfo.htm 7840 ..c. r/rr-xr-xr-x 0 0 6608-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/sysSoftwareInfo.htm 9506 ..c. r/rr-xr-xr-x 0 0 6609-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/sysSoftwareInfo.js 4150 ..c. r/rr-xr-xr-x 0 0 6610-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/sysinfomain.htm 16097 ..c. r/rr-xr-xr-x 0 0 6611-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/sysinfosum.htm 14129 ..c. r/rr-xr-xr-x 0 0 6612-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/wmi_data.js 56 .ac. d/dr-xr-xr-x 0 0 6613-144-5 /WINDOWS/pchealth/helpctr/System/blurbs 1386 ..c. r/rr-xr-xr-x 0 0 6614-128-3 /WINDOWS/pchealth/helpctr/System/blurbs/History.htm 1477 ..c. r/rr-xr-xr-x 0 0 6615-128-3 /WINDOWS/pchealth/helpctr/System/blurbs/Index.htm 2352 ..c. r/rr-xr-xr-x 0 0 6616-128-4 /WINDOWS/pchealth/helpctr/System/blurbs/about_support.htm 1740 ..c. r/rr-xr-xr-x 0 0 6617-128-3 /WINDOWS/pchealth/helpctr/System/blurbs/ftshelp.htm 3873 ..c. r/rr-xr-xr-x 0 0 6618-128-3 /WINDOWS/pchealth/helpctr/System/blurbs/isupport.htm 1816 ..c. r/rr-xr-xr-x 0 0 6619-128-4 /WINDOWS/pchealth/helpctr/System/blurbs/keywordhelp.htm 1679 ..c. r/rr-xr-xr-x 0 0 6620-128-3 /WINDOWS/pchealth/helpctr/System/blurbs/options.htm 1763 ..c. r/rr-xr-xr-x 0 0 6621-128-4 /WINDOWS/pchealth/helpctr/System/blurbs/searchblurb.htm 10376 ..c. r/rr-xr-xr-x 0 0 6622-128-4 /WINDOWS/pchealth/helpctr/System/blurbs/searchtips.htm 1411 ..c. r/rr-xr-xr-x 0 0 6623-128-3 /WINDOWS/pchealth/helpctr/System/blurbs/tools.htm 2368 ..c. r/rr-xr-xr-x 0 0 6624-128-4 /WINDOWS/pchealth/helpctr/System/blurbs/windows_newsgroups.htm 56 .ac. d/dr-xr-xr-x 0 0 6625-144-6 /WINDOWS/pchealth/helpctr/System/CompatCtr 77245 ..c. r/rr-xr-xr-x 0 0 6626-128-4 /WINDOWS/pchealth/helpctr/System/CompatCtr/CompatMode.htm 1340 ..c. r/rr-xr-xr-x 0 0 6627-128-4 /WINDOWS/pchealth/helpctr/System/CompatCtr/CompatOffline.htm 2588 ..c. r/rr-xr-xr-x 0 0 6628-128-4 /WINDOWS/pchealth/helpctr/System/CompatCtr/LearnCompat.htm 376 .ac. d/dr-xr-xr-x 0 0 6629-144-1 /WINDOWS/pchealth/helpctr/System/css 56 .ac. d/dr-xr-xr-x 0 0 6630-144-5 /WINDOWS/pchealth/helpctr/System/DFS 32982 ..c. r/rr-xr-xr-x 0 0 6631-128-4 /WINDOWS/pchealth/helpctr/System/DFS/uplddrvinfo.htm 275 ..c. r/rr-xr-xr-x 0 0 6632-128-1 /WINDOWS/pchealth/helpctr/System/DFS/viewmode.xml 967 ..c. r/rr-xr-xr-x 0 0 6633-128-4 /WINDOWS/pchealth/helpctr/System/DFS/xmldialog.htm 11750 ..c. r/rr-xr-xr-x 0 0 6634-128-4 /WINDOWS/pchealth/helpctr/System/DFS/xmldisplay.xsl 256 .ac. d/dr-xr-xr-x 0 0 6635-144-1 /WINDOWS/pchealth/helpctr/System/dialogs 7523 ..c. r/rr-xr-xr-x 0 0 6636-128-3 /WINDOWS/pchealth/helpctr/System/dialogs/Print.dlg 296 .ac. d/dr-xr-xr-x 0 0 6637-144-1 /WINDOWS/pchealth/helpctr/System/ErrMsg 56 .ac. d/dr-xr-xr-x 0 0 6638-144-5 /WINDOWS/pchealth/helpctr/System/errors 18852 ..c. r/rr-xr-xr-x 0 0 6639-128-4 /WINDOWS/pchealth/helpctr/System/errors/connection.htm 84292 ..c. r/rr-xr-xr-x 0 0 664-128-3 /WINDOWS/Help/ipsecsnp.hlp 1655 ..c. r/rr-xr-xr-x 0 0 6640-128-4 /WINDOWS/pchealth/helpctr/System/errors/indexfirstlevel.htm 2028 ..c. r/rr-xr-xr-x 0 0 6641-128-3 /WINDOWS/pchealth/helpctr/System/errors/notfound.htm 775 ..c. r/rr-xr-xr-x 0 0 6642-128-3 /WINDOWS/pchealth/helpctr/System/errors/offline.htm 1728 ..c. r/rr-xr-xr-x 0 0 6643-128-3 /WINDOWS/pchealth/helpctr/System/errors/redirect.htm 1689 ..c. r/rr-xr-xr-x 0 0 6644-128-4 /WINDOWS/pchealth/helpctr/System/errors/unreachable.htm 56 .ac. d/dr-xr-xr-x 0 0 6645-144-5 /WINDOWS/pchealth/helpctr/System/panels 9174 ..c. r/rr-xr-xr-x 0 0 6646-128-3 /WINDOWS/pchealth/helpctr/System/panels/Context.htm 713 ..c. r/rr-xr-xr-x 0 0 6647-128-4 /WINDOWS/pchealth/helpctr/System/panels/HHWrapper.htm 4764 ..c. r/rr-xr-xr-x 0 0 6648-128-4 /WINDOWS/pchealth/helpctr/System/panels/MiniNavBar.htm 1990 ..c. r/rr-xr-xr-x 0 0 6649-128-4 /WINDOWS/pchealth/helpctr/System/panels/MiniNavBar.xml 18800 ..c. r/rr-xr-xr-x 0 0 665-128-3 /WINDOWS/Help/ipsecsnp.chm 20832 ..c. r/rr-xr-xr-x 0 0 6650-128-3 /WINDOWS/pchealth/helpctr/System/panels/NavBar.htm 2513 ..c. r/rr-xr-xr-x 0 0 6651-128-3 /WINDOWS/pchealth/helpctr/System/panels/NavBar.xml 4418 ..c. r/rr-xr-xr-x 0 0 6652-128-3 /WINDOWS/pchealth/helpctr/System/panels/Options.htm 43111 ..c. r/rr-xr-xr-x 0 0 6653-128-4 /WINDOWS/pchealth/helpctr/System/panels/RemoteHelp.htm 4553 ..c. r/rr-xr-xr-x 0 0 6654-128-4 /WINDOWS/pchealth/helpctr/System/panels/ShareHelp.htm 5547 ..c. r/rr-xr-xr-x 0 0 6655-128-3 /WINDOWS/pchealth/helpctr/System/panels/Topics.htm 608 ..c. r/rr-xr-xr-x 0 0 6656-128-1 /WINDOWS/pchealth/helpctr/System/panels/blank.htm 714 ..c. r/rr-xr-xr-x 0 0 6657-128-4 /WINDOWS/pchealth/helpctr/System/panels/firstpage.htm 56 .ac. d/dr-xr-xr-x 0 0 6658-144-6 /WINDOWS/pchealth/helpctr/System/panels/subpanels 8522 ..c. r/rr-xr-xr-x 0 0 6659-128-4 /WINDOWS/pchealth/helpctr/System/panels/subpanels/Favorites.htm 5369 ..c. r/rr-xr-xr-x 0 0 6660-128-3 /WINDOWS/pchealth/helpctr/System/panels/subpanels/History.htm 2911 ..c. r/rr-xr-xr-x 0 0 6661-128-3 /WINDOWS/pchealth/helpctr/System/panels/subpanels/Index.htm 3465 ..c. r/rr-xr-xr-x 0 0 6662-128-3 /WINDOWS/pchealth/helpctr/System/panels/subpanels/Options.htm 37469 ..c. r/rr-xr-xr-x 0 0 6663-128-3 /WINDOWS/pchealth/helpctr/System/panels/subpanels/Search.htm 6520 ..c. r/rr-xr-xr-x 0 0 6664-128-3 /WINDOWS/pchealth/helpctr/System/panels/subpanels/Subsite.htm 272 .ac. d/dr-xr-xr-x 0 0 6665-144-1 /WINDOWS/pchealth/helpctr/System/rc 56 .ac. d/dr-xr-xr-x 0 0 6666-144-5 /WINDOWS/pchealth/helpctr/System/scripts 56 .ac. d/dr-xr-xr-x 0 0 6667-144-6 /WINDOWS/pchealth/helpctr/System/UpdateCtr 2059 ..c. r/rr-xr-xr-x 0 0 6668-128-3 /WINDOWS/pchealth/helpctr/System/UpdateCtr/Learn.htm 2500 ..c. r/rr-xr-xr-x 0 0 6669-128-4 /WINDOWS/pchealth/helpctr/System/UpdateCtr/LearnInternet.htm 2518 ..c. r/rr-xr-xr-x 0 0 6670-128-3 /WINDOWS/pchealth/helpctr/System/UpdateCtr/learnWU.htm 1132 ..c. r/rr-xr-xr-x 0 0 6671-128-4 /WINDOWS/pchealth/helpctr/System/UpdateCtr/updatecenter.htm 2501 ..c. r/rr-xr-xr-x 0 0 6672-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/msinfo.htm 371 ..c. r/rr-xr-xr-x 0 0 6673-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/msinfo.xml 9264 ..c. r/rr-xr-xr-x 0 0 6674-128-3 /WINDOWS/pchealth/helpctr/System/DVDUpgrd/stripe.jpg 5812 ..c. r/rr-xr-xr-x 0 0 6675-128-3 /WINDOWS/pchealth/helpctr/System/HelpCtr.mmf 56 .ac. d/dr-xr-xr-x 0 0 6676-144-5 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics 741 ..c. r/rr-xr-xr-x 0 0 6677-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/100_chart.gif 784 ..c. r/rr-xr-xr-x 0 0 6678-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/10_chart.gif 778 ..c. r/rr-xr-xr-x 0 0 6679-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/15_chart.gif 775 ..c. r/rr-xr-xr-x 0 0 6680-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/20_chart.gif 781 ..c. r/rr-xr-xr-x 0 0 6681-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/25_chart.gif 782 ..c. r/rr-xr-xr-x 0 0 6682-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/30_chart.gif 793 ..c. r/rr-xr-xr-x 0 0 6683-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/35_chart.gif 789 ..c. r/rr-xr-xr-x 0 0 6684-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/40_chart.gif 785 ..c. r/rr-xr-xr-x 0 0 6685-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/45_chart.gif 762 ..c. r/rr-xr-xr-x 0 0 6686-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/50_chart.gif 777 ..c. r/rr-xr-xr-x 0 0 6687-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/55_chart.gif 773 ..c. r/rr-xr-xr-x 0 0 6688-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/5_chart.gif 789 ..c. r/rr-xr-xr-x 0 0 6689-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/60_chart.gif 1199 ..c. r/rr-xr-xr-x 0 0 6690-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/65_chart.gif 1190 ..c. r/rr-xr-xr-x 0 0 6691-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/70_chart.gif 1194 ..c. r/rr-xr-xr-x 0 0 6692-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/75_chart.gif 1196 ..c. r/rr-xr-xr-x 0 0 6693-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/80_chart.gif 1190 ..c. r/rr-xr-xr-x 0 0 6694-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/85_chart.gif 1196 ..c. r/rr-xr-xr-x 0 0 6695-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/90_chart.gif 1207 ..c. r/rr-xr-xr-x 0 0 6696-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/95_chart.gif 56 .ac. d/dr-xr-xr-x 0 0 6697-144-5 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie 1358 ..c. r/rr-xr-xr-x 0 0 6698-128-4 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/100_chart.gif 1443 ..c. r/rr-xr-xr-x 0 0 6699-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/10_chart.gif 56 .a.. d/dr-xr-xr-x 0 0 67-144-5 /WINDOWS/security 1435 ..c. r/rr-xr-xr-x 0 0 6700-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/15_chart.gif 1421 ..c. r/rr-xr-xr-x 0 0 6701-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/20_chart.gif 1423 ..c. r/rr-xr-xr-x 0 0 6702-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/25_chart.gif 1428 ..c. r/rr-xr-xr-x 0 0 6703-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/30_chart.gif 1441 ..c. r/rr-xr-xr-x 0 0 6704-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/35_chart.gif 1446 ..c. r/rr-xr-xr-x 0 0 6705-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/40_chart.gif 1446 ..c. r/rr-xr-xr-x 0 0 6706-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/45_chart.gif 1412 ..c. r/rr-xr-xr-x 0 0 6707-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/50_chart.gif 1430 ..c. r/rr-xr-xr-x 0 0 6708-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/55_chart.gif 1413 ..c. r/rr-xr-xr-x 0 0 6709-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/5_chart.gif 1446 ..c. r/rr-xr-xr-x 0 0 6710-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/60_chart.gif 1445 ..c. r/rr-xr-xr-x 0 0 6711-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/65_chart.gif 1435 ..c. r/rr-xr-xr-x 0 0 6712-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/70_chart.gif 1442 ..c. r/rr-xr-xr-x 0 0 6713-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/75_chart.gif 1447 ..c. r/rr-xr-xr-x 0 0 6714-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/80_chart.gif 1426 ..c. r/rr-xr-xr-x 0 0 6715-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/85_chart.gif 1442 ..c. r/rr-xr-xr-x 0 0 6716-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/90_chart.gif 1445 ..c. r/rr-xr-xr-x 0 0 6717-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/95_chart.gif 674 ..c. r/rr-xr-xr-x 0 0 6718-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/BArrow.gif 682 ..c. r/rr-xr-xr-x 0 0 6719-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/GArrow.gif 11927 ..c. r/rr-xr-xr-x 0 0 672-128-3 /WINDOWS/inf/irdasmc.inf 1135 ..c. r/rr-xr-xr-x 0 0 6720-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/PieChart.gif 67 ..c. r/rr-xr-xr-x 0 0 6721-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/PieGrey.gif 67 ..c. r/rr-xr-xr-x 0 0 6722-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/PieWhite.gif 1135 ..c. r/rr-xr-xr-x 0 0 6723-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/Untitled.gif 118 ..c. r/rr-xr-xr-x 0 0 6724-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/alert.gif 162 ..c. r/rr-xr-xr-x 0 0 6725-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/card.gif 257 ..c. r/rr-xr-xr-x 0 0 6726-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/cd.gif 145 ..c. r/rr-xr-xr-x 0 0 6727-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/check.gif 102 ..c. r/rr-xr-xr-x 0 0 6728-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/chip.gif 1498 ..c. r/rr-xr-xr-x 0 0 6729-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/down.bmp 23078 ..c. r/rr-xr-xr-x 0 0 673-128-3 /WINDOWS/inf/irnsc.inf 139 ..c. r/rr-xr-xr-x 0 0 6730-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/drive.gif 107 ..c. r/rr-xr-xr-x 0 0 6731-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/error.gif 159 ..c. r/rr-xr-xr-x 0 0 6732-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/floppy.gif 135 ..c. r/rr-xr-xr-x 0 0 6733-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/gears.gif 677 ..c. r/rr-xr-xr-x 0 0 6734-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/greendot.jpg 99 ..c. r/rr-xr-xr-x 0 0 6735-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/info.gif 129 ..c. r/rr-xr-xr-x 0 0 6736-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/monitor.gif 181 ..c. r/rr-xr-xr-x 0 0 6737-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/personalizing.gif 136 ..c. r/rr-xr-xr-x 0 0 6738-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/printer.gif 114 ..c. r/rr-xr-xr-x 0 0 6739-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/r1_c1.gif 4701 ..c. r/rr-xr-xr-x 0 0 674-128-3 /WINDOWS/inf/irmk7w2k.inf 107 ..c. r/rr-xr-xr-x 0 0 6740-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/r1_c2.gif 106 ..c. r/rr-xr-xr-x 0 0 6741-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/r1_c3.gif 107 ..c. r/rr-xr-xr-x 0 0 6742-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/r3_c2.gif 43 ..c. r/rr-xr-xr-x 0 0 6743-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/spacer.gif 404 ..c. r/rr-xr-xr-x 0 0 6744-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/system.gif 1498 ..c. r/rr-xr-xr-x 0 0 6745-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/up.bmp 262 ..c. r/rr-xr-xr-x 0 0 6746-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/usb.gif 569 ..c. r/rr-xr-xr-x 0 0 6747-128-1 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/windows.gif 360054 ..c. r/rr-xr-xr-x 0 0 6748-128-4 /WINDOWS/pchealth/helpctr/System/blurbs/watermark_300x.bmp 1175 ..c. r/rr-xr-xr-x 0 0 6749-128-4 /WINDOWS/pchealth/helpctr/System/css/Behaviors.css 3711 ..c. r/rr-xr-xr-x 0 0 675-128-3 /WINDOWS/inf/irstusb.inf 56 .ac. d/dr-xr-xr-x 0 0 6750-144-5 /WINDOWS/pchealth/helpctr/System/images 2358 ..c. r/rr-xr-xr-x 0 0 6751-128-4 /WINDOWS/pchealth/helpctr/System/images/16x16/arrow_green_normal_shadow.bmp 1078 ..c. r/rr-xr-xr-x 0 0 6752-128-3 /WINDOWS/pchealth/helpctr/System/images/16x16/compat.bmp 1078 ..c. r/rr-xr-xr-x 0 0 6753-128-3 /WINDOWS/pchealth/helpctr/System/images/16x16/errmsg.bmp 1078 ..c. r/rr-xr-xr-x 0 0 6754-128-3 /WINDOWS/pchealth/helpctr/System/images/16x16/support.bmp 1078 ..c. r/rr-xr-xr-x 0 0 6755-128-3 /WINDOWS/pchealth/helpctr/System/images/16x16/tools.bmp 1078 ..c. r/rr-xr-xr-x 0 0 6756-128-3 /WINDOWS/pchealth/helpctr/System/images/16x16/update.bmp 600 ..c. r/rr-xr-xr-x 0 0 6757-128-1 /WINDOWS/pchealth/helpctr/System/images/16x16/warning.gif 56 .ac. d/dr-xr-xr-x 0 0 6758-144-5 /WINDOWS/pchealth/helpctr/System/images/24x24 2358 ..c. r/rr-xr-xr-x 0 0 6759-128-4 /WINDOWS/pchealth/helpctr/System/images/24x24/arrow_green_mouseover.bmp 15432 ..c. r/rr-xr-xr-x 0 0 676-128-3 /WINDOWS/Help/is.chm 2358 ..c. r/rr-xr-xr-x 0 0 6760-128-4 /WINDOWS/pchealth/helpctr/System/images/24x24/arrow_green_normal.bmp 152 .ac. d/dr-xr-xr-x 0 0 6761-144-1 /WINDOWS/pchealth/helpctr/System/images/32x32 56 .ac. d/dr-xr-xr-x 0 0 6762-144-5 /WINDOWS/pchealth/helpctr/System/images/48x48 9270 ..c. r/rr-xr-xr-x 0 0 6763-128-4 /WINDOWS/pchealth/helpctr/System/images/48x48/desktop_icon_02.bmp 9270 ..c. r/rr-xr-xr-x 0 0 6764-128-4 /WINDOWS/pchealth/helpctr/System/images/48x48/desktop_icon_03.bmp 9270 ..c. r/rr-xr-xr-x 0 0 6765-128-4 /WINDOWS/pchealth/helpctr/System/images/48x48/desktop_icon_04.bmp 9270 ..c. r/rr-xr-xr-x 0 0 6766-128-4 /WINDOWS/pchealth/helpctr/System/images/48x48/desktop_icon_generic.bmp 584 .ac. d/dr-xr-xr-x 0 0 6767-144-1 /WINDOWS/pchealth/helpctr/System/images/Centers 1839 ..c. r/rr-xr-xr-x 0 0 6768-128-3 /WINDOWS/pchealth/helpctr/System/images/Centers/IULogo.gif 1525 ..c. r/rr-xr-xr-x 0 0 6769-128-3 /WINDOWS/pchealth/helpctr/System/images/Centers/Uabrand.gif 109258 ..c. r/rr-xr-xr-x 0 0 677-128-3 /WINDOWS/Help/isconcepts.chm 674 ..c. r/rr-xr-xr-x 0 0 6770-128-4 /WINDOWS/pchealth/helpctr/System/images/Centers/blue_arrow.gif 592 .ac. d/dr-xr-xr-x 0 0 6771-144-1 /WINDOWS/pchealth/helpctr/System/images/Expando 136 ..c. r/rr-xr-xr-x 0 0 6772-128-1 /WINDOWS/pchealth/helpctr/System/images/Expando/endnode.gif 135 ..c. r/rr-xr-xr-x 0 0 6773-128-1 /WINDOWS/pchealth/helpctr/System/images/Expando/expanded.gif 207 ..c. r/rr-xr-xr-x 0 0 6774-128-1 /WINDOWS/pchealth/helpctr/System/images/Expando/helpdoc.gif 1557 ..c. r/rr-xr-xr-x 0 0 6775-128-3 /WINDOWS/pchealth/helpctr/System/images/error.gif 895 ..c. r/rr-xr-xr-x 0 0 6776-128-3 /WINDOWS/pchealth/helpctr/System/images/feedback.gif 70 ..c. r/rr-xr-xr-x 0 0 6777-128-1 /WINDOWS/pchealth/helpctr/System/images/flyout_arrow.gif 1383 ..c. r/rr-xr-xr-x 0 0 6778-128-3 /WINDOWS/pchealth/helpctr/System/images/get_conn.gif 630 ..c. r/rr-xr-xr-x 0 0 6779-128-4 /WINDOWS/pchealth/helpctr/System/images/icon_articles_12x.bmp 16062 ..c. r/rr-xr-xr-x 0 0 678-128-3 /WINDOWS/Help/ixhelp.hlp 630 ..c. r/rr-xr-xr-x 0 0 6780-128-4 /WINDOWS/pchealth/helpctr/System/images/icon_blank_12x.bmp 630 ..c. r/rr-xr-xr-x 0 0 6781-128-4 /WINDOWS/pchealth/helpctr/System/images/icon_newwindow_12x.bmp 630 ..c. r/rr-xr-xr-x 0 0 6782-128-4 /WINDOWS/pchealth/helpctr/System/images/icon_onlineinline_12x.bmp 630 ..c. r/rr-xr-xr-x 0 0 6783-128-4 /WINDOWS/pchealth/helpctr/System/images/icon_tours_12x.bmp 630 ..c. r/rr-xr-xr-x 0 0 6784-128-4 /WINDOWS/pchealth/helpctr/System/images/icon_tutorials_12x.bmp 1521 ..c. r/rr-xr-xr-x 0 0 6785-128-3 /WINDOWS/pchealth/helpctr/System/images/info.gif 2801 ..c. r/rr-xr-xr-x 0 0 6786-128-3 /WINDOWS/pchealth/helpctr/System/images/progbar.gif 1466 ..c. r/rr-xr-xr-x 0 0 6787-128-3 /WINDOWS/pchealth/helpctr/System/images/warning.gif 76 ..c. r/rr-xr-xr-x 0 0 6788-128-1 /WINDOWS/pchealth/helpctr/System/images/wrapperhelp.gif 3159 ..c. r/rr-xr-xr-x 0 0 6789-128-3 /WINDOWS/pchealth/helpctr/System/scripts/Common.js 2323 ..c. r/rr-xr-xr-x 0 0 679-128-3 /WINDOWS/Help/ixqlang.htm 3445 ..c. r/rr-xr-xr-x 0 0 6790-128-4 /WINDOWS/pchealth/helpctr/System/scripts/HomePage__DESKTOP.js 8844 ..c. r/rr-xr-xr-x 0 0 6791-128-4 /WINDOWS/pchealth/helpctr/System/scripts/HomePage__SERVER.js 2954 ..c. r/rr-xr-xr-x 0 0 6792-128-4 /WINDOWS/pchealth/helpctr/System/scripts/wrapperparam.js 304 .ac. d/dr-xr-xr-x 0 0 6793-144-1 /WINDOWS/pchealth/helpctr/Config/Cache 48 .ac. d/dr-xr-xr-x 0 0 6794-144-1 /WINDOWS/pchealth/helpctr/Config/CheckPoint 87643 ..c. r/rr-xr-xr-x 0 0 6795-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/index.dat 14688256 ..c. r/rr-xr-xr-x 0 0 6796-128-3 /WINDOWS/pchealth/helpctr/Database/HCdata.edb 368 .ac. d/dr-xr-xr-x 0 0 6799-144-1 /WINDOWS/pchealth/helpctr/System/DVDUpgrd 56 .ac. d/dr-xr-xr-x 0 0 68-144-6 /WINDOWS/security/templates 1656 ..c. r/rr-xr-xr-x 0 0 6800-128-3 /WINDOWS/pchealth/helpctr/System/DVDUpgrd/dvdupgrd.htm 55709 ..c. r/rr-xr-xr-x 0 0 6801-128-3 /WINDOWS/pchealth/helpctr/System/NetDiag/dglogs.htm 56540 ..c. r/rr-xr-xr-x 0 0 6802-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/RSoP.htm 1453 ..c. r/rr-xr-xr-x 0 0 6803-128-4 /WINDOWS/pchealth/helpctr/System/blurbs/Favorites.htm 3155 ..c. r/rr-xr-xr-x 0 0 6804-128-4 /WINDOWS/pchealth/helpctr/System/CompatCtr/AboutCompat.htm 492 ..c. r/rr-xr-xr-x 0 0 6805-128-1 /WINDOWS/pchealth/helpctr/System/css/Layout.css 3047 ..c. r/rr-xr-xr-x 0 0 6806-128-3 /WINDOWS/pchealth/helpctr/System/DFS/privacy.htm 850 ..c. r/rr-xr-xr-x 0 0 6807-128-3 /WINDOWS/pchealth/helpctr/System/dialogs/DlgLib.js 880 ..c. r/rr-xr-xr-x 0 0 6808-128-4 /WINDOWS/pchealth/helpctr/System/ErrMsg/ErrorMessagesOffline.htm 1663 ..c. r/rr-xr-xr-x 0 0 6809-128-3 /WINDOWS/pchealth/helpctr/System/errors/badurl.htm 19520 ..c. r/rr-xr-xr-x 0 0 6810-128-4 /WINDOWS/pchealth/helpctr/System/panels/AdvSearch.htm 8494 ..c. r/rr-xr-xr-x 0 0 6811-128-3 /WINDOWS/pchealth/helpctr/System/panels/subpanels/Channels.htm 2367 ..c. r/rr-xr-xr-x 0 0 6812-128-4 /WINDOWS/pchealth/helpctr/System/rc/rcRequest.htm 4609 ..c. r/rr-xr-xr-x 0 0 6813-128-4 /WINDOWS/pchealth/helpctr/System/scripts/HomePage__SHARED.js 4113 ..c. r/rr-xr-xr-x 0 0 6814-128-3 /WINDOWS/pchealth/helpctr/System/UpdateCtr/AboutWU.htm 56 .ac. d/dr-xr-xr-x 0 0 6815-144-5 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie 734 ..c. r/rr-xr-xr-x 0 0 6816-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/33x16pie/0_chart.gif 1345 ..c. r/rr-xr-xr-x 0 0 6817-128-3 /WINDOWS/pchealth/helpctr/System/sysinfo/graphics/47x24pie/0_chart.gif 56 .ac. d/dr-xr-xr-x 0 0 6818-144-5 /WINDOWS/pchealth/helpctr/System/images/16x16 2358 ..c. r/rr-xr-xr-x 0 0 6819-128-4 /WINDOWS/pchealth/helpctr/System/images/16x16/arrow_blue_normal_shadow.bmp 2358 ..c. r/rr-xr-xr-x 0 0 6820-128-4 /WINDOWS/pchealth/helpctr/System/images/24x24/arrow_green_mousedown.bmp 2358 ..c. r/rr-xr-xr-x 0 0 6821-128-3 /WINDOWS/pchealth/helpctr/System/images/32x32/logo.bmp 9270 ..c. r/rr-xr-xr-x 0 0 6822-128-4 /WINDOWS/pchealth/helpctr/System/images/48x48/desktop_icon_01.bmp 1383 ..c. r/rr-xr-xr-x 0 0 6823-128-3 /WINDOWS/pchealth/helpctr/System/images/Centers/Connect.gif 320925 ..c. r/rr-xr-xr-x 0 0 6824-128-3 /WINDOWS/pchealth/helpctr/Logs/hcupdate.log 233472 ..c. r/rr-xr-xr-x 0 0 6826-128-3 /WINDOWS/system32/ias/ias.mdb 133114 ..c. r/rr-xr-xr-x 0 0 6827-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/e2815c7504541e30998dd35159edbb[1].js 112836 ..c. r/rr-xr-xr-x 0 0 6828-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/b862c6c3329c726208dab3c6f742b8_blue[1].css 3520 ..c. r/rr-xr-xr-x 0 0 6829-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/9f5897c9639ef97fa228d2ecc7575e[1].css 4690 ..c. r/rr-xr-xr-x 0 0 6830-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/40bebb8ac371d6f92b3720e62f3017[1].css 2661 ..c. r/rr-xr-xr-x 0 0 6831-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/D72D7743BB3018A939743976971[1].jpg 3877 ..c. r/rr-xr-xr-x 0 0 6832-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/dapmsn[1].js 895 ..c. r/rr-xr-xr-x 0 0 6833-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/32[1].gif 3320 ..c. r/rr-xr-xr-x 0 0 6834-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/mevio-m-neverback-24x24[1].gif 7832 ..c. r/rr-xr-xr-x 0 0 6835-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/7E527F040B5694B10F6F9B92DE95[1].jpg 139 ..c. r/rr-xr-xr-x 0 0 6836-128-1 /WINDOWS/pchealth/helpctr/System/images/Expando/collapsed.gif 179978 ..c. r/rr-xr-xr-x 0 0 6837-128-4 /WINDOWS/pchealth/helpctr/Config/Cache/Professional_32_1033.dat.bak 176 .ac. d/dr-xr-xr-x 0 0 6838-144-9 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409 62 ..c. r/rr-xr-xr-x 0 0 6839-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000000.query 908 ..c. r/rr-xr-xr-x 0 0 6840-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000001.query 908 ..c. r/rr-xr-xr-x 0 0 6841-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000002.query 194 ..c. r/rr-xr-xr-x 0 0 6842-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000004.query 1614 ..c. r/rr-xr-xr-x 0 0 6843-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000005.query 1614 ..c. r/rr-xr-xr-x 0 0 6844-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000006.query 500 ..c. r/rr-xr-xr-x 0 0 6845-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000008.query 1594 ..c. r/rr-xr-xr-x 0 0 6846-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000009.query 1594 ..c. r/rr-xr-xr-x 0 0 6847-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000000a.query 186 ..c. r/rr-xr-xr-x 0 0 6848-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000000c.query 4128 ..c. r/rr-xr-xr-x 0 0 6849-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000000e.query 4128 ..c. r/rr-xr-xr-x 0 0 6850-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000000f.query 232 ..c. r/rr-xr-xr-x 0 0 6851-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000010.query 306 ..c. r/rr-xr-xr-x 0 0 6852-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000012.query 306 ..c. r/rr-xr-xr-x 0 0 6853-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000013.query 314 ..c. r/rr-xr-xr-x 0 0 6854-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000014.query 2180 ..c. r/rr-xr-xr-x 0 0 6855-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000016.query 2180 ..c. r/rr-xr-xr-x 0 0 6856-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000017.query 254 ..c. r/rr-xr-xr-x 0 0 6857-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000018.query 3352 ..c. r/rr-xr-xr-x 0 0 6858-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000001a.query 3352 ..c. r/rr-xr-xr-x 0 0 6859-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000001b.query 18949 ..c. r/rr-xr-xr-x 0 0 686-128-3 /WINDOWS/Help/joy.chm 384 ..c. r/rr-xr-xr-x 0 0 6860-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000001c.query 1570 ..c. r/rr-xr-xr-x 0 0 6861-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000001d.query 1570 ..c. r/rr-xr-xr-x 0 0 6862-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000001e.query 264 ..c. r/rr-xr-xr-x 0 0 6863-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000020.query 786 ..c. r/rr-xr-xr-x 0 0 6864-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000022.query 786 ..c. r/rr-xr-xr-x 0 0 6865-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000023.query 438 ..c. r/rr-xr-xr-x 0 0 6866-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000024.query 1572 ..c. r/rr-xr-xr-x 0 0 6867-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000025.query 1572 ..c. r/rr-xr-xr-x 0 0 6868-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000026.query 446 ..c. r/rr-xr-xr-x 0 0 6869-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000028.query 1622 ..c. r/rr-xr-xr-x 0 0 6870-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000029.query 1622 ..c. r/rr-xr-xr-x 0 0 6871-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000002a.query 268 ..c. r/rr-xr-xr-x 0 0 6872-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000002c.query 500 ..c. r/rr-xr-xr-x 0 0 6873-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000002d.query 500 ..c. r/rr-xr-xr-x 0 0 6874-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000002e.query 378 ..c. r/rr-xr-xr-x 0 0 6875-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000030.query 564 ..c. r/rr-xr-xr-x 0 0 6876-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000031.query 564 ..c. r/rr-xr-xr-x 0 0 6877-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000032.query 504 ..c. r/rr-xr-xr-x 0 0 6878-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000034.query 1000 ..c. r/rr-xr-xr-x 0 0 6879-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000035.query 1000 ..c. r/rr-xr-xr-x 0 0 6880-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000036.query 302 ..c. r/rr-xr-xr-x 0 0 6881-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000038.query 1078 ..c. r/rr-xr-xr-x 0 0 6882-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000039.query 1078 ..c. r/rr-xr-xr-x 0 0 6883-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000003a.query 298 ..c. r/rr-xr-xr-x 0 0 6884-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000003c.query 1414 ..c. r/rr-xr-xr-x 0 0 6885-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000003d.query 1414 ..c. r/rr-xr-xr-x 0 0 6886-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000003e.query 212 ..c. r/rr-xr-xr-x 0 0 6887-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000040.query 4186 ..c. r/rr-xr-xr-x 0 0 6888-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000042.query 4186 ..c. r/rr-xr-xr-x 0 0 6889-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000043.query 208 ..c. r/rr-xr-xr-x 0 0 6890-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000044.query 4096 ..c. r/rr-xr-xr-x 0 0 6891-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000046.query 4096 ..c. r/rr-xr-xr-x 0 0 6892-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000047.query 204 ..c. r/rr-xr-xr-x 0 0 6893-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000048.query 2306 ..c. r/rr-xr-xr-x 0 0 6894-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000004a.query 2306 ..c. r/rr-xr-xr-x 0 0 6895-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000004b.query 188 ..c. r/rr-xr-xr-x 0 0 6896-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000004c.query 4174 ..c. r/rr-xr-xr-x 0 0 6897-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000004e.query 4174 ..c. r/rr-xr-xr-x 0 0 6898-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000004f.query 398 ..c. r/rr-xr-xr-x 0 0 6899-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000050.query 1392 ..c. r/rr-xr-xr-x 0 0 6900-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000051.query 1392 ..c. r/rr-xr-xr-x 0 0 6901-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000052.query 246 ..c. r/rr-xr-xr-x 0 0 6902-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000054.query 2390 ..c. r/rr-xr-xr-x 0 0 6903-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000056.query 2390 ..c. r/rr-xr-xr-x 0 0 6904-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000057.query 240 ..c. r/rr-xr-xr-x 0 0 6905-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000058.query 2204 ..c. r/rr-xr-xr-x 0 0 6906-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000005a.query 2204 ..c. r/rr-xr-xr-x 0 0 6907-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000005b.query 360 ..c. r/rr-xr-xr-x 0 0 6908-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000005c.query 5500 ..c. r/rr-xr-xr-x 0 0 6909-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000005e.query 5500 ..c. r/rr-xr-xr-x 0 0 6910-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000005f.query 180 ..c. r/rr-xr-xr-x 0 0 6911-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000060.query 2410 ..c. r/rr-xr-xr-x 0 0 6912-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000062.query 2410 ..c. r/rr-xr-xr-x 0 0 6913-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000063.query 204 ..c. r/rr-xr-xr-x 0 0 6914-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000064.query 2000 ..c. r/rr-xr-xr-x 0 0 6915-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000066.query 2000 ..c. r/rr-xr-xr-x 0 0 6916-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000067.query 202 ..c. r/rr-xr-xr-x 0 0 6917-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000068.query 1686 ..c. r/rr-xr-xr-x 0 0 6918-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000006a.query 1686 ..c. r/rr-xr-xr-x 0 0 6919-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000006b.query 194 ..c. r/rr-xr-xr-x 0 0 6920-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000006c.query 1426 ..c. r/rr-xr-xr-x 0 0 6921-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000006d.query 1426 ..c. r/rr-xr-xr-x 0 0 6922-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000006e.query 454 ..c. r/rr-xr-xr-x 0 0 6923-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000070.query 1808 ..c. r/rr-xr-xr-x 0 0 6924-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000071.query 1808 ..c. r/rr-xr-xr-x 0 0 6925-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000072.query 398 ..c. r/rr-xr-xr-x 0 0 6926-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000074.query 2680 ..c. r/rr-xr-xr-x 0 0 6927-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000075.query 2680 ..c. r/rr-xr-xr-x 0 0 6928-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000076.query 282 ..c. r/rr-xr-xr-x 0 0 6929-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000078.query 3096 ..c. r/rr-xr-xr-x 0 0 6930-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000079.query 3096 ..c. r/rr-xr-xr-x 0 0 6931-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000007a.query 304 ..c. r/rr-xr-xr-x 0 0 6932-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000007c.query 8746 ..c. r/rr-xr-xr-x 0 0 6933-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000007e.query 8746 ..c. r/rr-xr-xr-x 0 0 6934-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000007f.query 216 ..c. r/rr-xr-xr-x 0 0 6935-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000080.query 8558 ..c. r/rr-xr-xr-x 0 0 6936-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000082.query 8558 ..c. r/rr-xr-xr-x 0 0 6937-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000083.query 386 ..c. r/rr-xr-xr-x 0 0 6938-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000084.query 2452 ..c. r/rr-xr-xr-x 0 0 6939-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000085.query 2452 ..c. r/rr-xr-xr-x 0 0 6940-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000086.query 262 ..c. r/rr-xr-xr-x 0 0 6941-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000088.query 4514 ..c. r/rr-xr-xr-x 0 0 6942-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000008a.query 4514 ..c. r/rr-xr-xr-x 0 0 6943-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000008b.query 516 ..c. r/rr-xr-xr-x 0 0 6944-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000008c.query 1894 ..c. r/rr-xr-xr-x 0 0 6945-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000008d.query 1894 ..c. r/rr-xr-xr-x 0 0 6946-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000008e.query 228 ..c. r/rr-xr-xr-x 0 0 6947-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000090.query 7226 ..c. r/rr-xr-xr-x 0 0 6948-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000092.query 7226 ..c. r/rr-xr-xr-x 0 0 6949-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000093.query 294 ..c. r/rr-xr-xr-x 0 0 6950-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000094.query 1892 ..c. r/rr-xr-xr-x 0 0 6951-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000095.query 1892 ..c. r/rr-xr-xr-x 0 0 6952-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000096.query 154 ..c. r/rr-xr-xr-x 0 0 6953-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000098.query 2362 ..c. r/rr-xr-xr-x 0 0 6954-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000009a.query 2362 ..c. r/rr-xr-xr-x 0 0 6955-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000009b.query 168 ..c. r/rr-xr-xr-x 0 0 6956-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000009c.query 3604 ..c. r/rr-xr-xr-x 0 0 6957-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000009e.query 3604 ..c. r/rr-xr-xr-x 0 0 6958-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000009f.query 216 ..c. r/rr-xr-xr-x 0 0 6959-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000a0.query 3342 ..c. r/rr-xr-xr-x 0 0 6960-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000a2.query 3342 ..c. r/rr-xr-xr-x 0 0 6961-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000a3.query 258 ..c. r/rr-xr-xr-x 0 0 6962-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000a4.query 1782 ..c. r/rr-xr-xr-x 0 0 6963-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000a6.query 1782 ..c. r/rr-xr-xr-x 0 0 6964-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000a7.query 256 ..c. r/rr-xr-xr-x 0 0 6965-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000a8.query 2660 ..c. r/rr-xr-xr-x 0 0 6966-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000aa.query 2660 ..c. r/rr-xr-xr-x 0 0 6967-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000ab.query 200 ..c. r/rr-xr-xr-x 0 0 6968-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000ac.query 1874 ..c. r/rr-xr-xr-x 0 0 6969-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000ae.query 1874 ..c. r/rr-xr-xr-x 0 0 6970-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000af.query 184 ..c. r/rr-xr-xr-x 0 0 6971-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000b0.query 1614 ..c. r/rr-xr-xr-x 0 0 6972-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000b2.query 1614 ..c. r/rr-xr-xr-x 0 0 6973-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000b3.query 472 ..c. r/rr-xr-xr-x 0 0 6974-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000b4.query 2596 ..c. r/rr-xr-xr-x 0 0 6975-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000b5.query 2596 ..c. r/rr-xr-xr-x 0 0 6976-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000b6.query 270 ..c. r/rr-xr-xr-x 0 0 6977-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000b8.query 8814 ..c. r/rr-xr-xr-x 0 0 6978-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000ba.query 8814 ..c. r/rr-xr-xr-x 0 0 6979-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000bb.query 246 ..c. r/rr-xr-xr-x 0 0 6980-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000bc.query 8350 ..c. r/rr-xr-xr-x 0 0 6981-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000be.query 8350 ..c. r/rr-xr-xr-x 0 0 6982-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000bf.query 214 ..c. r/rr-xr-xr-x 0 0 6983-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000c0.query 6424 ..c. r/rr-xr-xr-x 0 0 6984-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000c2.query 6424 ..c. r/rr-xr-xr-x 0 0 6985-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000c3.query 242 ..c. r/rr-xr-xr-x 0 0 6986-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000c4.query 2816 ..c. r/rr-xr-xr-x 0 0 6987-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000c6.query 2816 ..c. r/rr-xr-xr-x 0 0 6988-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000c7.query 250 ..c. r/rr-xr-xr-x 0 0 6989-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000c8.query 9064 ..c. r/rr-xr-xr-x 0 0 6990-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000ca.query 9064 ..c. r/rr-xr-xr-x 0 0 6991-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000cb.query 198 ..c. r/rr-xr-xr-x 0 0 6992-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000cc.query 2020 ..c. r/rr-xr-xr-x 0 0 6993-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000ce.query 2020 ..c. r/rr-xr-xr-x 0 0 6994-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000cf.query 198 ..c. r/rr-xr-xr-x 0 0 6995-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000d0.query 9864 ..c. r/rr-xr-xr-x 0 0 6996-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000d2.query 9864 ..c. r/rr-xr-xr-x 0 0 6997-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000d3.query 206 ..c. r/rr-xr-xr-x 0 0 6998-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000d4.query 2102 ..c. r/rr-xr-xr-x 0 0 6999-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000d6.query 248 .a.. d/dr-xr-xr-x 0 0 70-144-1 /WINDOWS/system32/ias 2102 ..c. r/rr-xr-xr-x 0 0 7000-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000d7.query 206 ..c. r/rr-xr-xr-x 0 0 7001-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000d8.query 2396 ..c. r/rr-xr-xr-x 0 0 7002-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000da.query 2396 ..c. r/rr-xr-xr-x 0 0 7003-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000db.query 240 ..c. r/rr-xr-xr-x 0 0 7004-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000dc.query 2740 ..c. r/rr-xr-xr-x 0 0 7005-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000de.query 2740 ..c. r/rr-xr-xr-x 0 0 7006-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000df.query 184 ..c. r/rr-xr-xr-x 0 0 7007-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000e0.query 5838 ..c. r/rr-xr-xr-x 0 0 7008-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000e2.query 5838 ..c. r/rr-xr-xr-x 0 0 7009-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000e3.query 230 ..c. r/rr-xr-xr-x 0 0 7010-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000e4.query 2488 ..c. r/rr-xr-xr-x 0 0 7011-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000e6.query 2488 ..c. r/rr-xr-xr-x 0 0 7012-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000e7.query 194 ..c. r/rr-xr-xr-x 0 0 7013-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000e8.query 962 ..c. r/rr-xr-xr-x 0 0 7014-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000e9.query 962 ..c. r/rr-xr-xr-x 0 0 7015-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000ea.query 486 ..c. r/rr-xr-xr-x 0 0 7016-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000ec.query 3932 ..c. r/rr-xr-xr-x 0 0 7017-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000ed.query 3932 ..c. r/rr-xr-xr-x 0 0 7018-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000ee.query 182 ..c. r/rr-xr-xr-x 0 0 7019-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000f0.query 4534 ..c. r/rr-xr-xr-x 0 0 7020-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000f2.query 4534 ..c. r/rr-xr-xr-x 0 0 7021-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000f3.query 206 ..c. r/rr-xr-xr-x 0 0 7022-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000f4.query 1438 ..c. r/rr-xr-xr-x 0 0 7023-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000f6.query 1438 ..c. r/rr-xr-xr-x 0 0 7024-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000f7.query 194 ..c. r/rr-xr-xr-x 0 0 7025-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000f8.query 1864 ..c. r/rr-xr-xr-x 0 0 7026-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000fa.query 1864 ..c. r/rr-xr-xr-x 0 0 7027-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000fb.query 218 ..c. r/rr-xr-xr-x 0 0 7028-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000fc.query 3646 ..c. r/rr-xr-xr-x 0 0 7029-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000fe.query 3646 ..c. r/rr-xr-xr-x 0 0 7030-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000000ff.query 266 ..c. r/rr-xr-xr-x 0 0 7031-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000100.query 2990 ..c. r/rr-xr-xr-x 0 0 7032-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000102.query 2990 ..c. r/rr-xr-xr-x 0 0 7033-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000103.query 246 ..c. r/rr-xr-xr-x 0 0 7034-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000104.query 7626 ..c. r/rr-xr-xr-x 0 0 7035-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000106.query 7626 ..c. r/rr-xr-xr-x 0 0 7036-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000107.query 206 ..c. r/rr-xr-xr-x 0 0 7037-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000108.query 3822 ..c. r/rr-xr-xr-x 0 0 7038-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000010a.query 3822 ..c. r/rr-xr-xr-x 0 0 7039-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000010b.query 202 ..c. r/rr-xr-xr-x 0 0 7040-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000010c.query 3106 ..c. r/rr-xr-xr-x 0 0 7041-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000010e.query 3106 ..c. r/rr-xr-xr-x 0 0 7042-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000010f.query 190 ..c. r/rr-xr-xr-x 0 0 7043-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000110.query 2056 ..c. r/rr-xr-xr-x 0 0 7044-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000112.query 2056 ..c. r/rr-xr-xr-x 0 0 7045-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000113.query 374 ..c. r/rr-xr-xr-x 0 0 7046-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000114.query 520 ..c. r/rr-xr-xr-x 0 0 7047-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000115.query 520 ..c. r/rr-xr-xr-x 0 0 7048-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000116.query 230 ..c. r/rr-xr-xr-x 0 0 7049-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000118.query 324 ..c. r/rr-xr-xr-x 0 0 7050-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000119.query 4020 ..c. r/rr-xr-xr-x 0 0 7051-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000011a.query 3704 ..c. r/rr-xr-xr-x 0 0 7052-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000011b.query 420 ..c. r/rr-xr-xr-x 0 0 7053-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000011c.query 1208 ..c. r/rr-xr-xr-x 0 0 7054-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000011d.query 1208 ..c. r/rr-xr-xr-x 0 0 7055-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000011e.query 246 ..c. r/rr-xr-xr-x 0 0 7056-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000120.query 3554 ..c. r/rr-xr-xr-x 0 0 7057-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000122.query 3554 ..c. r/rr-xr-xr-x 0 0 7058-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000123.query 262 ..c. r/rr-xr-xr-x 0 0 7059-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000124.query 6412 ..c. r/rr-xr-xr-x 0 0 7060-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000126.query 6412 ..c. r/rr-xr-xr-x 0 0 7061-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000127.query 242 ..c. r/rr-xr-xr-x 0 0 7062-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000128.query 2628 ..c. r/rr-xr-xr-x 0 0 7063-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000012a.query 2628 ..c. r/rr-xr-xr-x 0 0 7064-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000012b.query 368 ..c. r/rr-xr-xr-x 0 0 7065-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000012c.query 484 ..c. r/rr-xr-xr-x 0 0 7066-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000130.query 2194 ..c. r/rr-xr-xr-x 0 0 7067-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000131.query 2194 ..c. r/rr-xr-xr-x 0 0 7068-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000132.query 298 ..c. r/rr-xr-xr-x 0 0 7069-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000134.query 4738 ..c. r/rr-xr-xr-x 0 0 7070-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000136.query 4738 ..c. r/rr-xr-xr-x 0 0 7071-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000137.query 314 ..c. r/rr-xr-xr-x 0 0 7072-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000138.query 2804 ..c. r/rr-xr-xr-x 0 0 7073-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000013a.query 2804 ..c. r/rr-xr-xr-x 0 0 7074-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000013b.query 338 ..c. r/rr-xr-xr-x 0 0 7075-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000013c.query 512 ..c. r/rr-xr-xr-x 0 0 7076-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000013d.query 3900 ..c. r/rr-xr-xr-x 0 0 7077-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000013e.query 3396 ..c. r/rr-xr-xr-x 0 0 7078-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000013f.query 310 ..c. r/rr-xr-xr-x 0 0 7079-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000140.query 5806 ..c. r/rr-xr-xr-x 0 0 7080-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000142.query 5806 ..c. r/rr-xr-xr-x 0 0 7081-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000143.query 250 ..c. r/rr-xr-xr-x 0 0 7082-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000144.query 1374 ..c. r/rr-xr-xr-x 0 0 7083-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000146.query 1374 ..c. r/rr-xr-xr-x 0 0 7084-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000147.query 336 ..c. r/rr-xr-xr-x 0 0 7085-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000148.query 396 ..c. r/rr-xr-xr-x 0 0 7086-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000014c.query 850 ..c. r/rr-xr-xr-x 0 0 7087-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000014d.query 850 ..c. r/rr-xr-xr-x 0 0 7088-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000014e.query 194 ..c. r/rr-xr-xr-x 0 0 7089-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000150.query 2020 ..c. r/rr-xr-xr-x 0 0 7090-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000151.query 2020 ..c. r/rr-xr-xr-x 0 0 7091-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000152.query 432 ..c. r/rr-xr-xr-x 0 0 7092-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000154.query 940 ..c. r/rr-xr-xr-x 0 0 7093-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000155.query 940 ..c. r/rr-xr-xr-x 0 0 7094-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000156.query 264 ..c. r/rr-xr-xr-x 0 0 7095-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000158.query 1946 ..c. r/rr-xr-xr-x 0 0 7096-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000159.query 1946 ..c. r/rr-xr-xr-x 0 0 7097-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000015a.query 332 ..c. r/rr-xr-xr-x 0 0 7098-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000015c.query 764 ..c. r/rr-xr-xr-x 0 0 7099-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000015d.query 764 ..c. r/rr-xr-xr-x 0 0 7100-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000015e.query 222 ..c. r/rr-xr-xr-x 0 0 7101-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000160.query 4174 ..c. r/rr-xr-xr-x 0 0 7102-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000162.query 4174 ..c. r/rr-xr-xr-x 0 0 7103-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000163.query 146 ..c. r/rr-xr-xr-x 0 0 7104-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000164.query 260 ..c. r/rr-xr-xr-x 0 0 7105-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000166.query 260 ..c. r/rr-xr-xr-x 0 0 7106-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000167.query 428 ..c. r/rr-xr-xr-x 0 0 7107-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000168.query 2776 ..c. r/rr-xr-xr-x 0 0 7108-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000169.query 2776 ..c. r/rr-xr-xr-x 0 0 7109-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000016a.query 226 ..c. r/rr-xr-xr-x 0 0 7110-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000016c.query 3460 ..c. r/rr-xr-xr-x 0 0 7111-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000016e.query 3460 ..c. r/rr-xr-xr-x 0 0 7112-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000016f.query 298 ..c. r/rr-xr-xr-x 0 0 7113-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000170.query 3616 ..c. r/rr-xr-xr-x 0 0 7114-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000172.query 3616 ..c. r/rr-xr-xr-x 0 0 7115-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000173.query 234 ..c. r/rr-xr-xr-x 0 0 7116-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000174.query 4296 ..c. r/rr-xr-xr-x 0 0 7117-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000176.query 4296 ..c. r/rr-xr-xr-x 0 0 7118-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000177.query 222 ..c. r/rr-xr-xr-x 0 0 7119-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000178.query 4312 ..c. r/rr-xr-xr-x 0 0 7120-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000017a.query 4312 ..c. r/rr-xr-xr-x 0 0 7121-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000017b.query 316 ..c. r/rr-xr-xr-x 0 0 7122-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000017c.query 356 ..c. r/rr-xr-xr-x 0 0 7123-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000017d.query 356 ..c. r/rr-xr-xr-x 0 0 7124-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000017e.query 282 ..c. r/rr-xr-xr-x 0 0 7125-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000180.query 6114 ..c. r/rr-xr-xr-x 0 0 7126-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000182.query 6114 ..c. r/rr-xr-xr-x 0 0 7127-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000183.query 270 ..c. r/rr-xr-xr-x 0 0 7128-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000184.query 5186 ..c. r/rr-xr-xr-x 0 0 7129-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000186.query 5186 ..c. r/rr-xr-xr-x 0 0 7130-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000187.query 202 ..c. r/rr-xr-xr-x 0 0 7131-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000188.query 5718 ..c. r/rr-xr-xr-x 0 0 7132-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000018a.query 5718 ..c. r/rr-xr-xr-x 0 0 7133-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000018b.query 230 ..c. r/rr-xr-xr-x 0 0 7134-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000018c.query 2488 ..c. r/rr-xr-xr-x 0 0 7135-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000018e.query 2488 ..c. r/rr-xr-xr-x 0 0 7136-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000018f.query 266 ..c. r/rr-xr-xr-x 0 0 7137-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000190.query 4088 ..c. r/rr-xr-xr-x 0 0 7138-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000192.query 4088 ..c. r/rr-xr-xr-x 0 0 7139-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000193.query 310 ..c. r/rr-xr-xr-x 0 0 7140-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000194.query 6540 ..c. r/rr-xr-xr-x 0 0 7141-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000196.query 6540 ..c. r/rr-xr-xr-x 0 0 7142-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000197.query 354 ..c. r/rr-xr-xr-x 0 0 7143-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000198.query 2812 ..c. r/rr-xr-xr-x 0 0 7144-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000199.query 2812 ..c. r/rr-xr-xr-x 0 0 7145-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000019a.query 240 ..c. r/rr-xr-xr-x 0 0 7146-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000019c.query 5394 ..c. r/rr-xr-xr-x 0 0 7147-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000019e.query 5394 ..c. r/rr-xr-xr-x 0 0 7148-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000019f.query 180 ..c. r/rr-xr-xr-x 0 0 7149-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001a0.query 3924 ..c. r/rr-xr-xr-x 0 0 7150-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001a2.query 3924 ..c. r/rr-xr-xr-x 0 0 7151-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001a3.query 164 ..c. r/rr-xr-xr-x 0 0 7152-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001a4.query 3572 ..c. r/rr-xr-xr-x 0 0 7153-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001a6.query 3572 ..c. r/rr-xr-xr-x 0 0 7154-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001a7.query 124 ..c. r/rr-xr-xr-x 0 0 7155-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001a8.query 2194 ..c. r/rr-xr-xr-x 0 0 7156-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001aa.query 2194 ..c. r/rr-xr-xr-x 0 0 7157-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001ab.query 132 ..c. r/rr-xr-xr-x 0 0 7158-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001ac.query 186 ..c. r/rr-xr-xr-x 0 0 7159-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001ad.query 1838 ..c. r/rr-xr-xr-x 0 0 7160-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001ae.query 1660 ..c. r/rr-xr-xr-x 0 0 7161-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001af.query 128 ..c. r/rr-xr-xr-x 0 0 7162-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001b0.query 3206 ..c. r/rr-xr-xr-x 0 0 7163-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001b2.query 3206 ..c. r/rr-xr-xr-x 0 0 7164-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001b3.query 216 ..c. r/rr-xr-xr-x 0 0 7165-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001b4.query 3030 ..c. r/rr-xr-xr-x 0 0 7166-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001b6.query 3030 ..c. r/rr-xr-xr-x 0 0 7167-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001b7.query 248 ..c. r/rr-xr-xr-x 0 0 7168-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001b8.query 4132 ..c. r/rr-xr-xr-x 0 0 7169-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001ba.query 4132 ..c. r/rr-xr-xr-x 0 0 7170-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001bb.query 196 ..c. r/rr-xr-xr-x 0 0 7171-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001bc.query 2660 ..c. r/rr-xr-xr-x 0 0 7172-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001be.query 2660 ..c. r/rr-xr-xr-x 0 0 7173-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001bf.query 276 ..c. r/rr-xr-xr-x 0 0 7174-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001c0.query 500 ..c. r/rr-xr-xr-x 0 0 7175-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001c1.query 500 ..c. r/rr-xr-xr-x 0 0 7176-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001c2.query 246 ..c. r/rr-xr-xr-x 0 0 7177-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001c4.query 568 ..c. r/rr-xr-xr-x 0 0 7178-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001c5.query 860 ..c. r/rr-xr-xr-x 0 0 7179-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001c6.query 300 ..c. r/rr-xr-xr-x 0 0 7180-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001c7.query 192 ..c. r/rr-xr-xr-x 0 0 7181-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001c8.query 1404 ..c. r/rr-xr-xr-x 0 0 7182-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001ca.query 1404 ..c. r/rr-xr-xr-x 0 0 7183-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001cb.query 200 ..c. r/rr-xr-xr-x 0 0 7184-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001cc.query 4716 ..c. r/rr-xr-xr-x 0 0 7185-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001ce.query 4716 ..c. r/rr-xr-xr-x 0 0 7186-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001cf.query 192 ..c. r/rr-xr-xr-x 0 0 7187-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001d0.query 2222 ..c. r/rr-xr-xr-x 0 0 7188-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001d2.query 2222 ..c. r/rr-xr-xr-x 0 0 7189-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001d3.query 190 ..c. r/rr-xr-xr-x 0 0 7190-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001d4.query 9334 ..c. r/rr-xr-xr-x 0 0 7191-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001d6.query 9334 ..c. r/rr-xr-xr-x 0 0 7192-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001d7.query 348 ..c. r/rr-xr-xr-x 0 0 7193-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001d8.query 2486 ..c. r/rr-xr-xr-x 0 0 7194-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001d9.query 2486 ..c. r/rr-xr-xr-x 0 0 7195-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001da.query 194 ..c. r/rr-xr-xr-x 0 0 7196-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001dc.query 8348 ..c. r/rr-xr-xr-x 0 0 7197-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001de.query 8348 ..c. r/rr-xr-xr-x 0 0 7198-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001df.query 248 ..c. r/rr-xr-xr-x 0 0 7199-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001e0.query 10700 ..c. r/rr-xr-xr-x 0 0 720-128-3 /WINDOWS/inf/kdk2x0.inf 3048 ..c. r/rr-xr-xr-x 0 0 7200-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001e2.query 3048 ..c. r/rr-xr-xr-x 0 0 7201-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001e3.query 244 ..c. r/rr-xr-xr-x 0 0 7202-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001e4.query 3710 ..c. r/rr-xr-xr-x 0 0 7203-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001e6.query 3710 ..c. r/rr-xr-xr-x 0 0 7204-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001e7.query 250 ..c. r/rr-xr-xr-x 0 0 7205-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001e8.query 1960 ..c. r/rr-xr-xr-x 0 0 7206-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001ea.query 1960 ..c. r/rr-xr-xr-x 0 0 7207-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001eb.query 226 ..c. r/rr-xr-xr-x 0 0 7208-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001ec.query 4368 ..c. r/rr-xr-xr-x 0 0 7209-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001ee.query 4761 ..c. r/rr-xr-xr-x 0 0 721-128-3 /WINDOWS/inf/kdkscan.inf 4368 ..c. r/rr-xr-xr-x 0 0 7210-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001ef.query 184 ..c. r/rr-xr-xr-x 0 0 7211-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001f0.query 3552 ..c. r/rr-xr-xr-x 0 0 7212-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001f2.query 3552 ..c. r/rr-xr-xr-x 0 0 7213-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001f3.query 260 ..c. r/rr-xr-xr-x 0 0 7214-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001f4.query 5578 ..c. r/rr-xr-xr-x 0 0 7215-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001f6.query 5578 ..c. r/rr-xr-xr-x 0 0 7216-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001f7.query 256 ..c. r/rr-xr-xr-x 0 0 7217-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001f8.query 5264 ..c. r/rr-xr-xr-x 0 0 7218-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001fa.query 5264 ..c. r/rr-xr-xr-x 0 0 7219-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001fb.query 236 ..c. r/rr-xr-xr-x 0 0 7220-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001fc.query 3086 ..c. r/rr-xr-xr-x 0 0 7221-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001fe.query 3086 ..c. r/rr-xr-xr-x 0 0 7222-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000001ff.query 260 ..c. r/rr-xr-xr-x 0 0 7223-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000200.query 5784 ..c. r/rr-xr-xr-x 0 0 7224-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000202.query 5784 ..c. r/rr-xr-xr-x 0 0 7225-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000203.query 208 ..c. r/rr-xr-xr-x 0 0 7226-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000204.query 2334 ..c. r/rr-xr-xr-x 0 0 7227-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000206.query 2334 ..c. r/rr-xr-xr-x 0 0 7228-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000207.query 490 ..c. r/rr-xr-xr-x 0 0 7229-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000208.query 25168 ..c. r/rr-xr-xr-x 0 0 723-128-3 /WINDOWS/Help/key.chm 164 ..c. r/rr-xr-xr-x 0 0 7230-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000020c.query 218 ..c. r/rr-xr-xr-x 0 0 7231-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000020d.query 218 ..c. r/rr-xr-xr-x 0 0 7232-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000020e.query 218 ..c. r/rr-xr-xr-x 0 0 7233-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000210.query 366 ..c. r/rr-xr-xr-x 0 0 7234-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000211.query 366 ..c. r/rr-xr-xr-x 0 0 7235-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000212.query 366 ..c. r/rr-xr-xr-x 0 0 7236-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000214.query 1130 ..c. r/rr-xr-xr-x 0 0 7237-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000215.query 1448 ..c. r/rr-xr-xr-x 0 0 7238-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000216.query 326 ..c. r/rr-xr-xr-x 0 0 7239-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000217.query 16494 ..c. r/rr-xr-xr-x 0 0 724-128-3 /WINDOWS/Help/keyb.chm 82 ..c. r/rr-xr-xr-x 0 0 7240-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000218.query 448 ..c. r/rr-xr-xr-x 0 0 7241-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000219.query 448 ..c. r/rr-xr-xr-x 0 0 7242-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000021a.query 158 ..c. r/rr-xr-xr-x 0 0 7243-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000021c.query 462 ..c. r/rr-xr-xr-x 0 0 7244-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000021d.query 5506 ..c. r/rr-xr-xr-x 0 0 7245-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000021e.query 5052 ..c. r/rr-xr-xr-x 0 0 7246-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000021f.query 160 ..c. r/rr-xr-xr-x 0 0 7247-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000220.query 306 ..c. r/rr-xr-xr-x 0 0 7248-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000222.query 306 ..c. r/rr-xr-xr-x 0 0 7249-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000223.query 310 ..c. r/rr-xr-xr-x 0 0 7250-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000224.query 962 ..c. r/rr-xr-xr-x 0 0 7251-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000225.query 1224 ..c. r/rr-xr-xr-x 0 0 7252-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000226.query 270 ..c. r/rr-xr-xr-x 0 0 7253-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000227.query 208 ..c. r/rr-xr-xr-x 0 0 7254-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000228.query 98 ..c. r/rr-xr-xr-x 0 0 7255-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000022c.query 1220 ..c. r/rr-xr-xr-x 0 0 7256-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000022e.query 1220 ..c. r/rr-xr-xr-x 0 0 7257-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000022f.query 82 ..c. r/rr-xr-xr-x 0 0 7258-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000230.query 1970 ..c. r/rr-xr-xr-x 0 0 7259-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000231.query 17762 ..c. r/rr-xr-xr-x 0 0 726-128-3 /WINDOWS/Help/keyshort.chm 1970 ..c. r/rr-xr-xr-x 0 0 7260-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000232.query 222 ..c. r/rr-xr-xr-x 0 0 7261-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000234.query 2222 ..c. r/rr-xr-xr-x 0 0 7262-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000235.query 2222 ..c. r/rr-xr-xr-x 0 0 7263-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000236.query 178 ..c. r/rr-xr-xr-x 0 0 7264-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000238.query 1600 ..c. r/rr-xr-xr-x 0 0 7265-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000239.query 1600 ..c. r/rr-xr-xr-x 0 0 7266-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000023a.query 292 ..c. r/rr-xr-xr-x 0 0 7267-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000023c.query 2618 ..c. r/rr-xr-xr-x 0 0 7268-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000023d.query 2618 ..c. r/rr-xr-xr-x 0 0 7269-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000023e.query 3154 ..c. r/rr-xr-xr-x 0 0 727-128-3 /WINDOWS/inf/kodak.inf 182 ..c. r/rr-xr-xr-x 0 0 7270-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000240.query 2074 ..c. r/rr-xr-xr-x 0 0 7271-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000242.query 2074 ..c. r/rr-xr-xr-x 0 0 7272-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000243.query 222 ..c. r/rr-xr-xr-x 0 0 7273-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000244.query 300 ..c. r/rr-xr-xr-x 0 0 7274-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000245.query 4104 ..c. r/rr-xr-xr-x 0 0 7275-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000246.query 3812 ..c. r/rr-xr-xr-x 0 0 7276-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000247.query 202 ..c. r/rr-xr-xr-x 0 0 7277-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000248.query 1842 ..c. r/rr-xr-xr-x 0 0 7278-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000249.query 1842 ..c. r/rr-xr-xr-x 0 0 7279-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000024a.query 202 ..c. r/rr-xr-xr-x 0 0 7280-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000024c.query 3050 ..c. r/rr-xr-xr-x 0 0 7281-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000024d.query 3050 ..c. r/rr-xr-xr-x 0 0 7282-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000024e.query 200 ..c. r/rr-xr-xr-x 0 0 7283-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000250.query 5242 ..c. r/rr-xr-xr-x 0 0 7284-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000252.query 5242 ..c. r/rr-xr-xr-x 0 0 7285-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000253.query 258 ..c. r/rr-xr-xr-x 0 0 7286-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000254.query 1362 ..c. r/rr-xr-xr-x 0 0 7287-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000255.query 1362 ..c. r/rr-xr-xr-x 0 0 7288-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000256.query 418 ..c. r/rr-xr-xr-x 0 0 7289-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000258.query 2278 ..c. r/rr-xr-xr-x 0 0 7290-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000259.query 2278 ..c. r/rr-xr-xr-x 0 0 7291-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000025a.query 140 ..c. r/rr-xr-xr-x 0 0 7292-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000025c.query 1464 ..c. r/rr-xr-xr-x 0 0 7293-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000025d.query 1464 ..c. r/rr-xr-xr-x 0 0 7294-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000025e.query 214 ..c. r/rr-xr-xr-x 0 0 7295-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000260.query 1718 ..c. r/rr-xr-xr-x 0 0 7296-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000262.query 1718 ..c. r/rr-xr-xr-x 0 0 7297-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000263.query 204 ..c. r/rr-xr-xr-x 0 0 7298-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000264.query 1918 ..c. r/rr-xr-xr-x 0 0 7299-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000266.query 1918 ..c. r/rr-xr-xr-x 0 0 7300-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000267.query 192 ..c. r/rr-xr-xr-x 0 0 7301-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000268.query 3222 ..c. r/rr-xr-xr-x 0 0 7302-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000026a.query 3222 ..c. r/rr-xr-xr-x 0 0 7303-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000026b.query 262 ..c. r/rr-xr-xr-x 0 0 7304-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000026c.query 3234 ..c. r/rr-xr-xr-x 0 0 7305-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000026e.query 3234 ..c. r/rr-xr-xr-x 0 0 7306-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000026f.query 248 ..c. r/rr-xr-xr-x 0 0 7307-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000270.query 2298 ..c. r/rr-xr-xr-x 0 0 7308-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000271.query 2298 ..c. r/rr-xr-xr-x 0 0 7309-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000272.query 20585 ..c. r/rr-xr-xr-x 0 0 731-128-3 /WINDOWS/Help/lang.chm 166 ..c. r/rr-xr-xr-x 0 0 7310-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000274.query 3040 ..c. r/rr-xr-xr-x 0 0 7311-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000276.query 3040 ..c. r/rr-xr-xr-x 0 0 7312-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000277.query 194 ..c. r/rr-xr-xr-x 0 0 7313-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000278.query 618 ..c. r/rr-xr-xr-x 0 0 7314-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000027a.query 618 ..c. r/rr-xr-xr-x 0 0 7315-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000027b.query 206 ..c. r/rr-xr-xr-x 0 0 7316-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000027c.query 3374 ..c. r/rr-xr-xr-x 0 0 7317-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000027e.query 3374 ..c. r/rr-xr-xr-x 0 0 7318-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000027f.query 258 ..c. r/rr-xr-xr-x 0 0 7319-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000280.query 1052 ..c. r/rr-xr-xr-x 0 0 7320-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000281.query 1052 ..c. r/rr-xr-xr-x 0 0 7321-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000282.query 186 ..c. r/rr-xr-xr-x 0 0 7322-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000284.query 1546 ..c. r/rr-xr-xr-x 0 0 7323-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000285.query 1546 ..c. r/rr-xr-xr-x 0 0 7324-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000286.query 162 ..c. r/rr-xr-xr-x 0 0 7325-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000288.query 2554 ..c. r/rr-xr-xr-x 0 0 7326-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000028a.query 2554 ..c. r/rr-xr-xr-x 0 0 7327-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000028b.query 178 ..c. r/rr-xr-xr-x 0 0 7328-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000028c.query 3868 ..c. r/rr-xr-xr-x 0 0 7329-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000028e.query 3868 ..c. r/rr-xr-xr-x 0 0 7330-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000028f.query 130 ..c. r/rr-xr-xr-x 0 0 7331-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000290.query 858 ..c. r/rr-xr-xr-x 0 0 7332-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000292.query 858 ..c. r/rr-xr-xr-x 0 0 7333-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000293.query 214 ..c. r/rr-xr-xr-x 0 0 7334-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000294.query 998 ..c. r/rr-xr-xr-x 0 0 7335-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000296.query 998 ..c. r/rr-xr-xr-x 0 0 7336-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000297.query 284 ..c. r/rr-xr-xr-x 0 0 7337-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000298.query 1830 ..c. r/rr-xr-xr-x 0 0 7338-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/00000299.query 1830 ..c. r/rr-xr-xr-x 0 0 7339-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000029a.query 829 ..c. r/rr-xr-xr-x 0 0 734-128-3 /WINDOWS/inf/legcydrv.inf 214 ..c. r/rr-xr-xr-x 0 0 7340-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000029c.query 2602 ..c. r/rr-xr-xr-x 0 0 7341-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000029e.query 2602 ..c. r/rr-xr-xr-x 0 0 7342-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/0000029f.query 194 ..c. r/rr-xr-xr-x 0 0 7343-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002a0.query 966 ..c. r/rr-xr-xr-x 0 0 7344-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002a1.query 966 ..c. r/rr-xr-xr-x 0 0 7345-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002a2.query 246 ..c. r/rr-xr-xr-x 0 0 7346-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002a4.query 308 ..c. r/rr-xr-xr-x 0 0 7347-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002a5.query 308 ..c. r/rr-xr-xr-x 0 0 7348-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002a6.query 188 ..c. r/rr-xr-xr-x 0 0 7349-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002a8.query 926 ..c. r/rr-xr-xr-x 0 0 7350-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002a9.query 926 ..c. r/rr-xr-xr-x 0 0 7351-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002aa.query 128 ..c. r/rr-xr-xr-x 0 0 7352-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002ac.query 242 ..c. r/rr-xr-xr-x 0 0 7353-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002ae.query 242 ..c. r/rr-xr-xr-x 0 0 7354-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002af.query 130 ..c. r/rr-xr-xr-x 0 0 7355-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002b0.query 4752 ..c. r/rr-xr-xr-x 0 0 7356-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002b2.query 4752 ..c. r/rr-xr-xr-x 0 0 7357-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002b3.query 316 ..c. r/rr-xr-xr-x 0 0 7358-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002b4.query 1956 ..c. r/rr-xr-xr-x 0 0 7359-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002b5.query 3683 ..c. r/rr-xr-xr-x 0 0 736-128-3 /WINDOWS/system32/drivers/etc/lmhosts.sam 1956 ..c. r/rr-xr-xr-x 0 0 7360-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002b6.query 302 ..c. r/rr-xr-xr-x 0 0 7361-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002b8.query 1816 ..c. r/rr-xr-xr-x 0 0 7362-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002ba.query 1816 ..c. r/rr-xr-xr-x 0 0 7363-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002bb.query 326 ..c. r/rr-xr-xr-x 0 0 7364-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002bc.query 1914 ..c. r/rr-xr-xr-x 0 0 7365-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002be.query 1914 ..c. r/rr-xr-xr-x 0 0 7366-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002bf.query 218 ..c. r/rr-xr-xr-x 0 0 7367-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002c0.query 1910 ..c. r/rr-xr-xr-x 0 0 7368-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002c2.query 1910 ..c. r/rr-xr-xr-x 0 0 7369-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002c3.query 262 ..c. r/rr-xr-xr-x 0 0 7370-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002c4.query 2638 ..c. r/rr-xr-xr-x 0 0 7371-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002c6.query 2638 ..c. r/rr-xr-xr-x 0 0 7372-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002c7.query 234 ..c. r/rr-xr-xr-x 0 0 7373-128-1 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002c8.query 608 ..c. r/rr-xr-xr-x 0 0 7374-128-4 /WINDOWS/pchealth/helpctr/OfflineCache/Professional_32#0409/000002c9.query 9270 ..c. r/rr-xr-xr-x 0 0 7376-128-4 /WINDOWS/pchealth/helpctr/System/images/48x48/icon_reskit_48x.bmp 2670 ..c. r/rr-xr-xr-x 0 0 7377-128-4 /WINDOWS/pchealth/helpctr/Config/SAFStore.xml 56 .ac. d/dr-xr-xr-x 0 0 7378-144-6 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance 2843 ..c. r/rr-xr-xr-x 0 0 7379-128-3 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/confirm.htm 45311 ..c. r/rr-xr-xr-x 0 0 738-128-3 /WINDOWS/Help/localsec.chm 16167 ..c. r/rr-xr-xr-x 0 0 7380-128-3 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/rcstatus.htm 448 .ac. d/dr-xr-xr-x 0 0 7381-144-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation 176 .ac. d/dr-xr-xr-x 0 0 7382-144-5 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common 2630 ..c. r/rr-xr-xr-x 0 0 7383-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/rcscreen1.htm 4437 ..c. r/rr-xr-xr-x 0 0 7384-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/rcscreen2.htm 321 ..c. r/rr-xr-xr-x 0 0 7385-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/rcscreen3.htm 3332 ..c. r/rr-xr-xr-x 0 0 7386-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/rcConnection.htm 53542 ..c. r/rr-xr-xr-x 0 0 7387-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/Remote_Assistance_Graphic.png 7066 ..c. r/rr-xr-xr-x 0 0 7388-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/monitor_left.gif 8509 ..c. r/rr-xr-xr-x 0 0 7389-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/monitor_right.gif 23811 ..c. r/rr-xr-xr-x 0 0 739-128-3 /WINDOWS/Help/localsec.hlp 102 ..c. r/rr-xr-xr-x 0 0 7390-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/address_book.gif 690 ..c. r/rr-xr-xr-x 0 0 7391-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/attention.gif 1074 ..c. r/rr-xr-xr-x 0 0 7392-128-3 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/arrow.gif 387 ..c. r/rr-xr-xr-x 0 0 7393-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/buddy.gif 608 ..c. r/rr-xr-xr-x 0 0 7394-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/buddy_attention.gif 3169 ..c. r/rr-xr-xr-x 0 0 7395-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/logon_anim.gif 382 ..c. r/rr-xr-xr-x 0 0 7396-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/buddy_away.gif 373 ..c. r/rr-xr-xr-x 0 0 7397-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/buddy_busy.gif 910 ..c. r/rr-xr-xr-x 0 0 7398-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/buddy_none.gif 384 ..c. r/rr-xr-xr-x 0 0 7399-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/buddy_offline.gif 48 .a.. d/dr-xr-xr-x 0 0 74-144-1 /WINDOWS/system32/export 1047 ..c. r/rr-xr-xr-x 0 0 7400-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/generic_mail.gif 227 ..c. r/rr-xr-xr-x 0 0 7401-128-3 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/info.gif 1473 ..c. r/rr-xr-xr-x 0 0 7402-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/messenger_big.gif 51 ..c. r/rr-xr-xr-x 0 0 7403-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/square_bullet.gif 180 ..c. r/rr-xr-xr-x 0 0 7404-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/outlook.gif 410 ..c. r/rr-xr-xr-x 0 0 7405-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/outlook_express.gif 111 ..c. r/rr-xr-xr-x 0 0 7406-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/Envelope.gif 159 ..c. r/rr-xr-xr-x 0 0 7407-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/floppy.gif 139 ..c. r/rr-xr-xr-x 0 0 7408-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/IM_icon.gif 321 ..c. r/rr-xr-xr-x 0 0 7409-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Common/icon_extweb.gif 56 .ac. d/dr-xr-xr-x 0 0 7410-144-5 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email 4374 ..c. r/rr-xr-xr-x 0 0 7411-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/rcscreen4.htm 14765 ..c. r/rr-xr-xr-x 0 0 7412-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/rcscreen5.htm 30915 ..c. r/rr-xr-xr-x 0 0 7413-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/rcscreen6.htm 3282 ..c. r/rr-xr-xr-x 0 0 7414-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/ShieldsUpMsg.htm 1290 ..c. r/rr-xr-xr-x 0 0 7415-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/rcscreen6_head.htm 5207 ..c. r/rr-xr-xr-x 0 0 7416-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/rcInviteStatus.htm 8096 ..c. r/rr-xr-xr-x 0 0 7417-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/rcscreen7.htm 7662 ..c. r/rr-xr-xr-x 0 0 7418-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/rcscreen8.htm 8445 ..c. r/rr-xr-xr-x 0 0 7419-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/rcscreen9.htm 25130 ..c. r/rr-xr-xr-x 0 0 742-128-3 /WINDOWS/Help/lpe.chm 4805 ..c. r/rr-xr-xr-x 0 0 7420-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/rcDetails.htm 137 ..c. r/rr-xr-xr-x 0 0 7421-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/check.gif 254 ..c. r/rr-xr-xr-x 0 0 7422-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/help.gif 14603 ..c. r/rr-xr-xr-x 0 0 7423-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/rcscreenshot3.gif 3425 ..c. r/rr-xr-xr-x 0 0 7424-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Email/escalationhelp.htm 280 .ac. d/dr-xr-xr-x 0 0 7425-144-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Unsolicited 13433 ..c. r/rr-xr-xr-x 0 0 7426-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Escalation/Unsolicited/UnSolicitedRCUI.htm 352 .ac. d/dr-xr-xr-x 0 0 7427-144-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Css 1308 ..c. r/rr-xr-xr-x 0 0 7428-128-3 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Css/rcbuddy.css 2442 ..c. r/rr-xr-xr-x 0 0 7429-128-3 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Css/rc.css 34698 ..c. r/rr-xr-xr-x 0 0 743-128-3 /WINDOWS/Help/lpeconcepts.chm 1369 ..c. r/rr-xr-xr-x 0 0 7430-128-3 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Css/RAChat.css 56 .ac. d/dr-xr-xr-x 0 0 7431-144-5 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Common 5231 ..c. r/rr-xr-xr-x 0 0 7432-128-3 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Common/common.js 2151 ..c. r/rr-xr-xr-x 0 0 7433-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Common/constants.js 2317 ..c. r/rr-xr-xr-x 0 0 7434-128-3 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Common/RAHelp.htm 2981 ..c. r/rr-xr-xr-x 0 0 7435-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Common/RCMoreInfo.htm 5403 ..c. r/rr-xr-xr-x 0 0 7436-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Common/ConnIssue.htm 1633 ..c. r/rr-xr-xr-x 0 0 7437-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Common/LearnInternet.htm 219 ..c. r/rr-xr-xr-x 0 0 7438-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Common/icon_warning_32x.gif 234 ..c. r/rr-xr-xr-x 0 0 7439-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Remote Assistance/Common/icon_information_32x.gif 56 .ac. d/dr-xr-xr-x 0 0 7440-144-6 /WINDOWS/pchealth/helpctr/System/Remote Assistance 540 ..c. r/rr-xr-xr-x 0 0 7441-128-1 /WINDOWS/pchealth/helpctr/System/Remote Assistance/RAClientLayout.xml 569 ..c. r/rr-xr-xr-x 0 0 7442-128-1 /WINDOWS/pchealth/helpctr/System/Remote Assistance/RAURA.xml 587 ..c. r/rr-xr-xr-x 0 0 7443-128-1 /WINDOWS/pchealth/helpctr/System/Remote Assistance/RAIMLayout.xml 666 ..c. r/rr-xr-xr-x 0 0 7444-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/RAHelpeeAcceptLayout.xml 5980 ..c. r/rr-xr-xr-x 0 0 7445-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/rcBuddy.htm 3493 ..c. r/rr-xr-xr-x 0 0 7446-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/RAStartPage.htm 80856 ..c. r/rr-xr-xr-x 0 0 7447-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/ding.wav 3907 ..c. r/rr-xr-xr-x 0 0 7448-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/helpeeaccept.htm 336 .ac. d/dr-xr-xr-x 0 0 7449-144-1 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction 56 .ac. d/dr-xr-xr-x 0 0 7450-144-5 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client 2496 ..c. r/rr-xr-xr-x 0 0 7451-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/rctoolScreen1.htm 1290 ..c. r/rr-xr-xr-x 0 0 7452-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/rcscreen6_head.htm 45530 ..c. r/rr-xr-xr-x 0 0 7453-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/RAClient.htm 6552 ..c. r/rr-xr-xr-x 0 0 7454-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/setting.htm 11187 ..c. r/rr-xr-xr-x 0 0 7455-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/RAToolBar.htm 3172 ..c. r/rr-xr-xr-x 0 0 7456-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/RAToolBar.xml 7140 ..c. r/rr-xr-xr-x 0 0 7457-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/RAStatusBar.htm 8969 ..c. r/rr-xr-xr-x 0 0 7458-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/RAChatClient.htm 346 ..c. r/rr-xr-xr-x 0 0 7459-128-1 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/DividerBar.htm 11165 ..c. r/rr-xr-xr-x 0 0 7460-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/RAClient.js 838 ..c. r/rr-xr-xr-x 0 0 7461-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/DownArrow.gif 834 ..c. r/rr-xr-xr-x 0 0 7462-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/UpArrow.gif 861 ..c. r/rr-xr-xr-x 0 0 7463-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/TakeControl.gif 3898 ..c. r/rr-xr-xr-x 0 0 7464-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/TakeControl.bmp 4756 ..c. r/rr-xr-xr-x 0 0 7465-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/Animation.gif 1094 ..c. r/rr-xr-xr-x 0 0 7466-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/connected.gif 59 ..c. r/rr-xr-xr-x 0 0 7467-128-1 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/combobox_line.gif 1024 ..c. r/rr-xr-xr-x 0 0 7468-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Client/DividerBar.gif 56 .ac. d/dr-xr-xr-x 0 0 7469-144-5 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Server 1222 ..c. r/rr-xr-xr-x 0 0 747-128-3 /WINDOWS/Resources/Themes/Luna.theme 21049 ..c. r/rr-xr-xr-x 0 0 7470-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Server/RAServer.htm 8095 ..c. r/rr-xr-xr-x 0 0 7471-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Server/RAChatServer.htm 14557 ..c. r/rr-xr-xr-x 0 0 7472-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Server/RAServerToolBar.htm 341 ..c. r/rr-xr-xr-x 0 0 7473-128-1 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Server/DividerBar1.htm 353 ..c. r/rr-xr-xr-x 0 0 7474-128-1 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Server/DividerBar2.htm 4797 ..c. r/rr-xr-xr-x 0 0 7475-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Server/SettingServer.htm 3210 ..c. r/rr-xr-xr-x 0 0 7476-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Server/TakeControlMsgs.htm 5158 ..c. r/rr-xr-xr-x 0 0 7477-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Server/RAServer.js 640 ..c. r/rr-xr-xr-x 0 0 7478-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Server/StopControl.gif 3898 ..c. r/rr-xr-xr-x 0 0 7479-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Server/StopControl.bmp 75 ..c. r/rr-xr-xr-x 0 0 7480-128-1 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Server/Helpee_line.gif 2818 ..c. r/rr-xr-xr-x 0 0 7481-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Server/ESC_key.gif 56 .ac. d/dr-xr-xr-x 0 0 7482-144-5 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common 30717 ..c. r/rr-xr-xr-x 0 0 7483-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/RCFileXfer.htm 15709 ..c. r/rr-xr-xr-x 0 0 7484-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/RAControl.js 2086 ..c. r/rr-xr-xr-x 0 0 7485-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/ErrorMsgs.htm 2333 ..c. r/rr-xr-xr-x 0 0 7486-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/VOIPMsgs.htm 379 ..c. r/rr-xr-xr-x 0 0 7487-128-1 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/hide-chat.gif 380 ..c. r/rr-xr-xr-x 0 0 7488-128-1 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/show-chat.gif 713 ..c. r/rr-xr-xr-x 0 0 7489-128-1 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/Options.gif 7004 ..c. r/rr-xr-xr-x 0 0 749-128-3 /WINDOWS/inf/lwngmadi.inf 3898 ..c. r/rr-xr-xr-x 0 0 7490-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/Options.bmp 750 ..c. r/rr-xr-xr-x 0 0 7491-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/Quit.gif 3898 ..c. r/rr-xr-xr-x 0 0 7492-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/Quit.bmp 1041 ..c. r/rr-xr-xr-x 0 0 7493-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/SendChat.gif 694 ..c. r/rr-xr-xr-x 0 0 7494-128-1 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/SendFile.gif 3898 ..c. r/rr-xr-xr-x 0 0 7495-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/SendFile.bmp 692 ..c. r/rr-xr-xr-x 0 0 7496-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/SendVoice.gif 3898 ..c. r/rr-xr-xr-x 0 0 7497-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/SendVoice.bmp 994 ..c. r/rr-xr-xr-x 0 0 7498-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/SendVoiceOn.gif 845 ..c. r/rr-xr-xr-x 0 0 7499-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/HelpCenter.gif 8728 ..c. r/rr-xr-xr-x 0 0 750-128-3 /WINDOWS/inf/lwusbhid.inf 3898 ..c. r/rr-xr-xr-x 0 0 7500-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/HelpCenter.bmp 352 .ac. d/dr-xr-xr-x 0 0 7501-144-1 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Css 1308 ..c. r/rr-xr-xr-x 0 0 7502-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Css/rcbuddy.css 2442 ..c. r/rr-xr-xr-x 0 0 7503-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Css/rc.css 1369 ..c. r/rr-xr-xr-x 0 0 7504-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Css/RAChat.css 56 .ac. d/dr-xr-xr-x 0 0 7505-144-5 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Common 5231 ..c. r/rr-xr-xr-x 0 0 7506-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Common/common.js 2151 ..c. r/rr-xr-xr-x 0 0 7507-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Common/constants.js 2317 ..c. r/rr-xr-xr-x 0 0 7508-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Common/RAHelp.htm 2981 ..c. r/rr-xr-xr-x 0 0 7509-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Common/RCMoreInfo.htm 5403 ..c. r/rr-xr-xr-x 0 0 7510-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Common/ConnIssue.htm 1633 ..c. r/rr-xr-xr-x 0 0 7511-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Common/LearnInternet.htm 3226 ..c. r/rr-xr-xr-x 0 0 7512-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/voicefirewallmsg.htm 219 ..c. r/rr-xr-xr-x 0 0 7513-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Common/icon_warning_32x.gif 234 ..c. r/rr-xr-xr-x 0 0 7514-128-4 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Common/icon_information_32x.gif 8738 ..c. r/rr-xr-xr-x 0 0 7515-128-5 /WINDOWS/pchealth/helpctr/Config/Cntstore.bin 141 ..c. r/rr-xr-xr-x 0 0 7516-128-3 /Documents and Settings/Default User/Application Data/Microsoft/Internet Explorer/brndlog.txt 227 ..c. r/rr-xr-xr-x 0 0 7517-128-3 /WINDOWS/pchealth/helpctr/System/Remote Assistance/Interaction/Common/info.gif 16498 ..c. r/rr-xr-xr-x 0 0 7518-128-4 /WINDOWS/pchealth/helpctr/Config/sereg.xml 10912 ..c. r/rr-xr-xr-x 0 0 7519-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/pssmachinesnapshot.xml 7098 ..c. r/rr-xr-xr-x 0 0 7520-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/pssmachinesnapshot-less.xml 10755 ..c. r/rr-xr-xr-x 0 0 7521-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/pssmachinesnapshot-wo-com.xml 2722 ..c. r/rr-xr-xr-x 0 0 7522-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/OfflineOptions.htm 13050 ..c. r/rr-xr-xr-x 0 0 7523-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/OfflineDC.htm 627 ..c. r/rr-xr-xr-x 0 0 7524-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Connection.htm 30494 ..c. r/rr-xr-xr-x 0 0 7525-128-4 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/pss_getting_worldwide_help.htm 43 ..c. r/rr-xr-xr-x 0 0 7526-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/spacer.gif 107 ..c. r/rr-xr-xr-x 0 0 7527-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/r3_c2.gif 106 ..c. r/rr-xr-xr-x 0 0 7528-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/r1_c3.gif 107 ..c. r/rr-xr-xr-x 0 0 7529-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/r1_c2.gif 19677 ..c. r/rr-xr-xr-x 0 0 753-128-3 /WINDOWS/Help/magnify.chm 114 ..c. r/rr-xr-xr-x 0 0 7530-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/r1_c1.gif 213 ..c. r/rr-xr-xr-x 0 0 7531-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/Info_Icon.gif 311 ..c. r/rr-xr-xr-x 0 0 7532-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/GRect.gif 682 ..c. r/rr-xr-xr-x 0 0 7533-128-1 /WINDOWS/pchealth/helpctr/Vendors/CN=Microsoft Corporation,L=Redmond,S=Washington,C=US/GArrow.gif 84992 ..c. r/rr-xr-xr-x 0 0 7534-128-3 /Program Files/Windows Resource Kits/Tools/krt.exe 1048576 ..c. r/rr-xr-xr-x 0 0 7535-128-4 /WINDOWS/Registration/{02D4B3F1-FD88-11D1-960D-00805FC79235}.{A57F0ADC-DEF4-41D6-8287-CCA5DB9E1D71}.crmlog 1527 ..c. r/rr-xr-xr-x 0 0 7537-128-4 /Documents and Settings/Default User/Start Menu/Programs/Accessories/Tour Windows XP.lnk 22512 ..c. r/rr-xr-xr-x 0 0 7538-128-4 /WINDOWS/Registration/R000000000006.clb 22512 ..c. r/rr-xr-xr-x 0 0 7539-128-4 /WINDOWS/Registration/R000000000007.clb 12115 ..c. r/rr-xr-xr-x 0 0 754-128-3 /WINDOWS/Help/magnify.hlp 286 ..c. r/rr-xr-xr-x 0 0 7540-128-1 /WINDOWS/Debug/blastcln.log 113 ..c. r/rr-xr-xr-x 0 0 7541-128-1 /Documents and Settings/Default User/Application Data/Microsoft/Internet Explorer/brndlog.bak 480 .ac. d/dr-xr-xr-x 0 0 7546-144-1 /Documents and Settings/Default User/Local Settings/Application Data/Microsoft 136 .ac. d/dr-xr-xr-x 0 0 7547-144-1 /Documents and Settings/Default User/Local Settings/Application Data/Microsoft/Windows Media 256 .ac. d/dr-xr-xr-x 0 0 7548-144-1 /Documents and Settings/Default User/Local Settings/Application Data/Microsoft/Windows Media/9.0 12784 ..c. r/rr-xr-xr-x 0 0 7549-128-3 /Documents and Settings/Default User/Local Settings/Application Data/Microsoft/Windows Media/9.0/WMSDKNS.XML 121327 ..c. r/rr-xr-xr-x 0 0 755-128-3 /WINDOWS/Help/mail.chm 498 ..c. r/rr-xr-xr-x 0 0 7550-128-1 /Documents and Settings/Default User/Local Settings/Application Data/Microsoft/Windows Media/9.0/WMSDKNS.DTD 56 ..c. d/dr-xr-xr-x 0 0 7557-144-5 /Documents and Settings/All Users/Documents/My Music/Sample Playlists/000EF7AA 48 .ac. d/dr-xr-xr-x 0 0 7560-144-1 /Documents and Settings/Default User/Application Data/Microsoft/Media Player 720896 ..c. r/rr-xr-xr-x 0 0 7561-128-4 /Documents and Settings/Default User/Local Settings/Application Data/Microsoft/Media Player/CurrentDatabase_59R.wmdb 48 ..c. d/dr-xr-xr-x 0 0 7562-144-1 /Documents and Settings/All Users/Documents/My Music/My Playlists 48 .ac. d/dr-xr-xr-x 0 0 7565-144-1 /Program Files/Windows Media Player/Visualizations 48 .ac. d/dr-xr-xr-x 0 0 7566-144-1 /Program Files/Windows Media Player/Icons 400 .ac. d/d--x--x--x 0 0 7567-144-1 /Documents and Settings/Default User/Start Menu/Programs/Accessories/Entertainment 804 ..c. r/rr-xr-xr-x 0 0 7568-128-4 /Documents and Settings/Default User/Start Menu/Programs/Accessories/Entertainment/Windows Media Player.lnk 792 ..c. r/rr-xr-xr-x 0 0 7569-128-4 /Documents and Settings/Default User/Start Menu/Programs/Windows Media Player.lnk 2714 ..c. r/rr-xr-xr-x 0 0 7576-128-3 /WINDOWS/security/logs/backup.log 386 ..c. r/rr-xr-xr-x 0 0 7577-128-4 /Documents and Settings/Default User/Start Menu/Programs/Accessories/Program Compatibility Wizard.lnk 56 .ac. d/d--x--x--x 0 0 7578-144-6 /Documents and Settings/Default User/Start Menu/Programs/Accessories/Accessibility 7680 ..c. r/rr-xr-xr-x 0 0 758-128-3 /WINDOWS/system32/drivers/mcd.sys 1525 ..c. r/rr-xr-xr-x 0 0 7580-128-4 /Documents and Settings/Default User/Start Menu/Programs/Accessories/Accessibility/Magnifier.lnk 1532 ..c. r/rr-xr-xr-x 0 0 7581-128-3 /Documents and Settings/Default User/Start Menu/Programs/Accessories/Accessibility/Narrator.lnk 1501 ..c. r/rr-xr-xr-x 0 0 7582-128-4 /Documents and Settings/Default User/Start Menu/Programs/Accessories/Accessibility/On-Screen Keyboard.lnk 1539 ..c. r/rr-xr-xr-x 0 0 7583-128-4 /Documents and Settings/Default User/Start Menu/Programs/Accessories/Accessibility/Utility Manager.lnk 1602 ..c. r/rr-xr-xr-x 0 0 7584-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Administrative Tools/Computer Management.lnk 1592 ..c. r/rr-xr-xr-x 0 0 7585-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Administrative Tools/Event Viewer.lnk 1591 ..c. r/rr-xr-xr-x 0 0 7586-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Administrative Tools/Performance.lnk 1596 ..c. r/rr-xr-xr-x 0 0 7587-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Administrative Tools/Data Sources (ODBC).lnk 1590 ..c. r/rr-xr-xr-x 0 0 7588-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Administrative Tools/Local Security Policy.lnk 1602 ..c. r/rr-xr-xr-x 0 0 7589-128-3 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Administrative Tools/Services.lnk 1507 ..c. r/rr-xr-xr-x 0 0 7591-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Windows Update.lnk 398 ..c. r/rr-xr-xr-x 0 0 7592-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Windows Catalog.lnk 1607 ..c. r/rr-xr-xr-x 0 0 7594-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Set Program Access and Defaults.lnk 1532 ..c. r/rr-xr-xr-x 0 0 7595-128-3 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/System Tools/Backup.lnk 1599 ..c. r/rr-xr-xr-x 0 0 7596-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/System Tools/Activate Windows.lnk 1591 ..c. r/rr-xr-xr-x 0 0 7597-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/System Tools/Files and Settings Transfer Wizard.lnk 1583 ..c. r/rr-xr-xr-x 0 0 7598-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/System Tools/Security Center.lnk 1700 ..c. r/rr-xr-xr-x 0 0 7599-128-4 /Documents and Settings/malware/Local Settings/Temp/smtmp/1/Programs/Accessories/Communications/Wireless Network Setup Wizard.lnk 1599 ..c. r/rr-xr-xr-x 0 0 7600-128-4 /Documents and Settings/Default User/Start Menu/Programs/Remote Assistance.lnk 382 ..c. r/rr-xr-xr-x 0 0 7601-128-1 /Documents and Settings/Default User/Start Menu/Programs/Media Player Center.lnk 376 ..c. r/rr-xr-xr-x 0 0 7602-128-1 /Documents and Settings/Default User/Start Menu/Programs/Messenger Center.lnk 237568 ..c. r/rr-xr-xr-x 0 0 7603-128-3 /Documents and Settings/Default User/NTUSER.DAT 1048576 ..c. r/rr-xr-xr-x 0 0 7605-128-3 /WINDOWS/security/edbtmp.log 833624 ..c. r/rr-xr-xr-x 0 0 7606-128-3 /WINDOWS/repair/secsetup.inf 136 .ac. d/dr-xr-xr-x 0 0 7607-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions 736 .ac. d/dr-xr-xr-x 0 0 7608-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions/40 256 .ac. d/dr-xr-xr-x 0 0 7609-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions/40/isapi 48 .ac. d/dr-xr-xr-x 0 0 7610-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions/40/isapi/_vti_adm 256 .ac. d/dr-xr-xr-x 0 0 7611-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions/40/_vti_bin 48 .ac. d/dr-xr-xr-x 0 0 7612-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions/40/_vti_bin/_vti_adm 48 .ac. d/dr-xr-xr-x 0 0 7613-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions/40/isapi/_vti_aut 48 .ac. d/dr-xr-xr-x 0 0 7614-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions/40/_vti_bin/_vti_aut 352 .ac. d/dr-xr-xr-x 0 0 7615-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions/40/bin 48 .ac. d/dr-xr-xr-x 0 0 7616-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions/40/servsupp 152 .ac. d/dr-xr-xr-x 0 0 7617-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions/40/bots 48 .ac. d/dr-xr-xr-x 0 0 7618-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions/40/bots/vinavbar 152 .ac. d/dr-xr-xr-x 0 0 7619-144-1 /Program Files/microsoft frontpage 136 .ac. d/dr-xr-xr-x 0 0 7620-144-1 /Program Files/microsoft frontpage/version3.0 48 .ac. d/dr-xr-xr-x 0 0 7621-144-1 /Program Files/microsoft frontpage/version3.0/bin 152 .ac. d/dr-xr-xr-x 0 0 7622-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions/40/bin/1033 144 .ac. d/dr-xr-xr-x 0 0 7623-144-1 /WINDOWS/ime/imjp8_1 144 .ac. d/dr-xr-xr-x 0 0 7624-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions/40/admcgi 48 .ac. d/dr-xr-xr-x 0 0 7625-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions/40/admcgi/scripts 144 .ac. d/dr-xr-xr-x 0 0 7626-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions/40/admisapi 48 .ac. d/dr-xr-xr-x 0 0 7627-144-1 /Program Files/Common Files/Microsoft Shared/web server extensions/40/admisapi/scripts 240 .ac. d/dr-xr-xr-x 0 0 7628-144-1 /WINDOWS/ime/imkr6_1 48 .ac. d/dr-xr-xr-x 0 0 7629-144-1 /WINDOWS/ime/imkr6_1/dicts 48 .ac. d/dr-xr-xr-x 0 0 7630-144-1 /WINDOWS/ime/imjp8_1/applets 48 .ac. d/dr-xr-xr-x 0 0 7631-144-1 /WINDOWS/ime/imkr6_1/applets 136 .ac. d/dr-xr-xr-x 0 0 7633-144-1 /WINDOWS/ime/shared 48 .ac. d/dr-xr-xr-x 0 0 7634-144-1 /WINDOWS/ime/shared/res 144 .ac. d/dr-xr-xr-x 0 0 7635-144-1 /WINDOWS/ime/chsime 48 .ac. d/dr-xr-xr-x 0 0 7636-144-1 /WINDOWS/ime/chsime/applets 144 .ac. d/dr-xr-xr-x 0 0 7638-144-1 /Program Files/xerox 48 .ac. d/dr-xr-xr-x 0 0 7639-144-1 /Program Files/xerox/nwwia 136192 ..c. r/rr-xr-xr-x 0 0 7640-128-1 /WINDOWS/system32/dllcache/aaclient.dll 1852928 ..c. r/rr-xr-xr-x 0 0 7641-128-1 /WINDOWS/system32/dllcache/acgenral.dll 451072 ..c. r/rr-xr-xr-x 0 0 7642-128-1 /WINDOWS/system32/dllcache/aclayers.dll 245248 ..c. r/rr-xr-xr-x 0 0 7643-128-1 /WINDOWS/system32/dllcache/acspecfc.dll 116224 ..c. r/rr-xr-xr-x 0 0 7644-128-1 /WINDOWS/system32/dllcache/acxtrnal.dll 43520 ..c. r/rr-xr-xr-x 0 0 7645-128-3 /WINDOWS/system32/dllcache/admwprox.dll 20540 ..c. r/rr-xr-xr-x 0 0 7646-128-3 /WINDOWS/system32/dllcache/admin.dll 16439 ..c. r/rr-xr-xr-x 0 0 7647-128-3 /WINDOWS/system32/dllcache/admin.exe 290816 ..c. r/rr-xr-xr-x 0 0 7648-128-3 /WINDOWS/system32/dllcache/adsiis51.dll 98304 ..c. r/rr-xr-xr-x 0 0 7649-128-1 /WINDOWS/system32/dllcache/ahui.exe 785972 ..c. r/rr-xr-xr-x 0 0 7650-128-1 /WINDOWS/system32/dllcache/apph_sp.sdb 125952 ..c. r/rr-xr-xr-x 0 0 7651-128-1 /WINDOWS/system32/dllcache/apphelp.dll 218134 ..c. r/rr-xr-xr-x 0 0 7652-128-1 /WINDOWS/system32/dllcache/apphelp.sdb 80546 ..c. r/rr-xr-xr-x 0 0 7653-128-1 /WINDOWS/system32/dllcache/apps.chm 65024 ..c. r/rr-xr-xr-x 0 0 7654-128-1 /WINDOWS/system32/dllcache/asycfilt.dll 30208 ..c. r/rr-xr-xr-x 0 0 7655-128-1 /WINDOWS/system32/dllcache/atmlib.dll 233472 ..c. r/rr-xr-xr-x 0 0 7656-128-1 /WINDOWS/system32/dllcache/azroles.dll 20540 ..c. r/rr-xr-xr-x 0 0 7657-128-3 /WINDOWS/system32/dllcache/author.dll 16439 ..c. r/rr-xr-xr-x 0 0 7658-128-3 /WINDOWS/system32/dllcache/author.exe 7168 ..c. r/rr-xr-xr-x 0 0 7659-128-1 /WINDOWS/system32/dllcache/bitsprx4.dll 94720 ..c. r/rr-xr-xr-x 0 0 7660-128-3 /WINDOWS/system32/dllcache/certmap.ocx 275968 ..c. r/rr-xr-xr-x 0 0 7661-128-3 /WINDOWS/system32/dllcache/certwiz.ocx 16896 ..c. r/rr-xr-xr-x 0 0 7662-128-1 /WINDOWS/system32/dllcache/cfgmgr32.dll 76288 ..c. r/rr-xr-xr-x 0 0 7663-128-3 /WINDOWS/system32/dllcache/cnfgprts.ocx 188480 ..c. r/rr-xr-xr-x 0 0 7664-128-3 /WINDOWS/system32/dllcache/cfgwiz.exe 46592 ..c. r/rr-xr-xr-x 0 0 7665-128-3 /WINDOWS/system32/dllcache/coadmin.dll 617472 ..c. r/rr-xr-xr-x 0 0 7666-128-1 /WINDOWS/system32/dllcache/comctl32.dll 276992 ..c. r/rr-xr-xr-x 0 0 7667-128-1 /WINDOWS/system32/dllcache/comdlg32.dll 252928 ..c. r/rr-xr-xr-x 0 0 7668-128-1 /WINDOWS/system32/dllcache/compatui.dll 599040 ..c. r/rr-xr-xr-x 0 0 7669-128-1 /WINDOWS/system32/dllcache/crypt32.dll 74752 ..c. r/rr-xr-xr-x 0 0 7670-128-1 /WINDOWS/system32/dllcache/cryptdlg.dll 33280 ..c. r/rr-xr-xr-x 0 0 7671-128-1 /WINDOWS/system32/dllcache/cryptdll.dll 53760 ..c. r/rr-xr-xr-x 0 0 7672-128-1 /WINDOWS/system32/dllcache/cryptext.dll 64512 ..c. r/rr-xr-xr-x 0 0 7673-128-1 /WINDOWS/system32/dllcache/cryptnet.dll 62464 ..c. r/rr-xr-xr-x 0 0 7674-128-1 /WINDOWS/system32/dllcache/cryptsvc.dll 512512 ..c. r/rr-xr-xr-x 0 0 7675-128-1 /WINDOWS/system32/dllcache/cryptui.dll 27136 ..c. r/rr-xr-xr-x 0 0 7676-128-1 /WINDOWS/system32/dllcache/ctl3d32.dll 19456 ..c. r/rr-xr-xr-x 0 0 7677-128-1 /WINDOWS/system32/dllcache/dimsntfy.dll 39936 ..c. r/rr-xr-xr-x 0 0 7678-128-1 /WINDOWS/system32/dllcache/dimsroam.dll 32768 ..c. r/rr-xr-xr-x 0 0 7679-128-1 /WINDOWS/system32/dllcache/dispex.dll 36656 ..c. r/rr-xr-xr-x 0 0 7680-128-1 /WINDOWS/system32/dllcache/dosapp.fon 9424 ..c. r/rr-xr-xr-x 0 0 7681-128-1 /WINDOWS/system32/dllcache/drvmain.sdb 138752 ..c. r/rr-xr-xr-x 0 0 7682-128-1 /WINDOWS/system32/dllcache/dssenh.dll 143744 ..c. r/rr-xr-xr-x 0 0 7683-128-1 /WINDOWS/system32/dllcache/fastfat.sys 135984 ..c. r/rr-xr-xr-x 0 0 7684-128-1 /WINDOWS/system32/dllcache/framd.ttf 184435 ..c. r/rr-xr-xr-x 0 0 7685-128-3 /WINDOWS/system32/dllcache/fp4amsft.dll 82035 ..c. r/rr-xr-xr-x 0 0 7686-128-3 /WINDOWS/system32/dllcache/fp4anscp.dll 147513 ..c. r/rr-xr-xr-x 0 0 7687-128-3 /WINDOWS/system32/dllcache/fp4apws.dll 49210 ..c. r/rr-xr-xr-x 0 0 7688-128-3 /WINDOWS/system32/dllcache/fp4areg.dll 102509 ..c. r/rr-xr-xr-x 0 0 7689-128-3 /WINDOWS/system32/dllcache/fp4atxt.dll 53234 ..c. r/rr-xr-xr-x 0 0 769-128-3 /WINDOWS/inf/mdm3com.inf 41020 ..c. r/rr-xr-xr-x 0 0 7690-128-3 /WINDOWS/system32/dllcache/fp4avnb.dll 32826 ..c. r/rr-xr-xr-x 0 0 7691-128-3 /WINDOWS/system32/dllcache/fp4avss.dll 49212 ..c. r/rr-xr-xr-x 0 0 7692-128-3 /WINDOWS/system32/dllcache/fp4awebs.dll 876653 ..c. r/rr-xr-xr-x 0 0 7693-128-3 /WINDOWS/system32/dllcache/fp4awel.dll 14608 ..c. r/rr-xr-xr-x 0 0 7694-128-3 /WINDOWS/system32/dllcache/fp98sadm.exe 109328 ..c. r/rr-xr-xr-x 0 0 7695-128-3 /WINDOWS/system32/dllcache/fp98swin.exe 188494 ..c. r/rr-xr-xr-x 0 0 7696-128-3 /WINDOWS/system32/dllcache/fpcount.exe 20541 ..c. r/rr-xr-xr-x 0 0 7697-128-3 /WINDOWS/system32/dllcache/fpexedll.dll 598071 ..c. r/rr-xr-xr-x 0 0 7698-128-3 /WINDOWS/system32/dllcache/fpmmc.dll 208896 ..c. r/rr-xr-xr-x 0 0 7699-128-3 /WINDOWS/system32/dllcache/fpmmcsat.dll 32807 ..c. r/rr-xr-xr-x 0 0 770-128-3 /WINDOWS/inf/mdm5674a.inf 20538 ..c. r/rr-xr-xr-x 0 0 7700-128-3 /WINDOWS/system32/dllcache/fpremadm.exe 152844 ..c. r/rr-xr-xr-x 0 0 7701-128-1 /WINDOWS/system32/dllcache/framdit.ttf 6144 ..c. r/rr-xr-xr-x 0 0 7702-128-3 /WINDOWS/system32/dllcache/ftpsapi2.dll 68608 ..c. r/rr-xr-xr-x 0 0 7703-128-3 /WINDOWS/system32/dllcache/iisext51.dll 64512 ..c. r/rr-xr-xr-x 0 0 7704-128-3 /WINDOWS/system32/dllcache/iismap.dll 14336 ..c. r/rr-xr-xr-x 0 0 7705-128-3 /WINDOWS/system32/dllcache/iisreset.exe 5632 ..c. r/rr-xr-xr-x 0 0 7706-128-3 /WINDOWS/system32/dllcache/iisrstap.dll 30720 ..c. r/rr-xr-xr-x 0 0 7707-128-3 /WINDOWS/system32/dllcache/iisrstas.exe 133632 ..c. r/rr-xr-xr-x 0 0 7708-128-3 /WINDOWS/system32/dllcache/iisrtl.dll 169984 ..c. r/rr-xr-xr-x 0 0 7709-128-3 /WINDOWS/system32/dllcache/iisui.dll 6532 ..c. r/rr-xr-xr-x 0 0 771-128-3 /WINDOWS/inf/mdmadc.inf 36921 ..c. r/rr-xr-xr-x 0 0 7710-128-1 /WINDOWS/system32/dllcache/imeshare.dll 829440 ..c. r/rr-xr-xr-x 0 0 7711-128-3 /WINDOWS/system32/dllcache/inetmgr.dll 7680 ..c. r/rr-xr-xr-x 0 0 7712-128-3 /WINDOWS/system32/dllcache/inetmgr.exe 19968 ..c. r/rr-xr-xr-x 0 0 7713-128-3 /WINDOWS/system32/dllcache/inetsloc.dll 13312 ..c. r/rr-xr-xr-x 0 0 7714-128-3 /WINDOWS/system32/dllcache/infoadmn.dll 75264 ..c. r/rr-xr-xr-x 0 0 7715-128-1 /WINDOWS/system32/dllcache/ipsec.sys 68608 ..c. r/rr-xr-xr-x 0 0 7716-128-3 /WINDOWS/system32/dllcache/isatq.dll 155136 ..c. r/rr-xr-xr-x 0 0 7717-128-1 /WINDOWS/system32/dllcache/itircl.dll 138240 ..c. r/rr-xr-xr-x 0 0 7718-128-1 /WINDOWS/system32/dllcache/itss.dll 512000 ..c. r/rr-xr-xr-x 0 0 7719-128-1 /WINDOWS/system32/dllcache/jscript.dll 2861 ..c. r/rr-xr-xr-x 0 0 772-128-3 /WINDOWS/inf/mdmairte.inf 15872 ..c. r/rr-xr-xr-x 0 0 7720-128-1 /WINDOWS/system32/dllcache/jsproxy.dll 989696 ..c. r/rr-xr-xr-x 0 0 7721-128-1 /WINDOWS/system32/dllcache/kernel32.dll 6144 ..c. r/rr-xr-xr-x 0 0 7722-128-1 /WINDOWS/system32/dllcache/kbdbhc.dll 6144 ..c. r/rr-xr-xr-x 0 0 7723-128-1 /WINDOWS/system32/dllcache/kbdiultn.dll 6144 ..c. r/rr-xr-xr-x 0 0 7724-128-1 /WINDOWS/system32/dllcache/kbdnepr.dll 6144 ..c. r/rr-xr-xr-x 0 0 7725-128-1 /WINDOWS/system32/dllcache/kbdpash.dll 76800 ..c. r/rr-xr-xr-x 0 0 7726-128-3 /WINDOWS/system32/dllcache/logui.ocx 728064 ..c. r/rr-xr-xr-x 0 0 7727-128-1 /WINDOWS/system32/dllcache/lsasrv.dll 24124 ..c. r/rr-xr-xr-x 0 0 7728-128-1 /WINDOWS/system32/dllcache/marlett.ttf 924432 ..c. r/rr-xr-xr-x 0 0 7729-128-1 /WINDOWS/system32/dllcache/mfc40.dll 13380 ..c. r/rr-xr-xr-x 0 0 773-128-3 /WINDOWS/inf/mdmaiwa.inf 927504 ..c. r/rr-xr-xr-x 0 0 7730-128-1 /WINDOWS/system32/dllcache/mfc40u.dll 1028096 ..c. r/rr-xr-xr-x 0 0 7731-128-1 /WINDOWS/system32/dllcache/mfc42.dll 981760 ..c. r/rr-xr-xr-x 0 0 7732-128-1 /WINDOWS/system32/dllcache/mfc42u.dll 22528 ..c. r/rr-xr-xr-x 0 0 7733-128-1 /WINDOWS/system32/dllcache/mfcsubs.dll 461672 ..c. r/rr-xr-xr-x 0 0 7734-128-1 /WINDOWS/system32/dllcache/micross.ttf 8704 ..c. r/rr-xr-xr-x 0 0 7735-128-1 /WINDOWS/system32/dllcache/modern.fon 204396 ..c. r/rr-xr-xr-x 0 0 7736-128-1 /WINDOWS/system32/dllcache/msimain.sdb 4608 ..c. r/rr-xr-xr-x 0 0 7737-128-1 /WINDOWS/system32/dllcache/mssip32.dll 343040 ..c. r/rr-xr-xr-x 0 0 7738-128-1 /WINDOWS/system32/dllcache/msvcrt.dll 61440 ..c. r/rr-xr-xr-x 0 0 7739-128-1 /WINDOWS/system32/dllcache/msvcrt40.dll 9614 ..c. r/rr-xr-xr-x 0 0 774-128-3 /WINDOWS/inf/mdmaiwa3.inf 91520 ..c. r/rr-xr-xr-x 0 0 7740-128-1 /WINDOWS/system32/dllcache/ndiswan.sys 337408 ..c. r/rr-xr-xr-x 0 0 7741-128-1 /WINDOWS/system32/dllcache/netapi32.dll 706048 ..c. r/rr-xr-xr-x 0 0 7742-128-1 /WINDOWS/system32/dllcache/ntdll.dll 574976 ..c. r/rr-xr-xr-x 0 0 7743-128-1 /WINDOWS/system32/dllcache/ntfs.sys 17408 ..c. r/rr-xr-xr-x 0 0 7744-128-1 /WINDOWS/system32/dllcache/nwapi16.dll 64000 ..c. r/rr-xr-xr-x 0 0 7745-128-1 /WINDOWS/system32/dllcache/nwapi32.dll 36864 ..c. r/rr-xr-xr-x 0 0 7746-128-1 /WINDOWS/system32/dllcache/nwc.cpl 67584 ..c. r/rr-xr-xr-x 0 0 7747-128-1 /WINDOWS/system32/dllcache/ocmanage.dll 106496 ..c. r/rr-xr-xr-x 0 0 7748-128-1 /WINDOWS/system32/dllcache/odbccp32.dll 20511 ..c. r/rr-xr-xr-x 0 0 7749-128-1 /WINDOWS/system32/dllcache/odtext32.dll 59725 ..c. r/rr-xr-xr-x 0 0 775-128-3 /WINDOWS/inf/mdmaiwa4.inf 13107200 ..c. r/rr-xr-xr-x 0 0 7750-128-1 /WINDOWS/system32/dllcache/oembios.bin 4461 ..c. r/rr-xr-xr-x 0 0 7751-128-1 /WINDOWS/system32/dllcache/oembios.dat 6761 ..c. r/rr-xr-xr-x 0 0 7752-128-1 /WINDOWS/system32/dllcache/oembios.sig 1287168 ..c. r/rr-xr-xr-x 0 0 7753-128-1 /WINDOWS/system32/dllcache/ole32.dll 551936 ..c. r/rr-xr-xr-x 0 0 7754-128-1 /WINDOWS/system32/dllcache/oleaut32.dll 84992 ..c. r/rr-xr-xr-x 0 0 7755-128-1 /WINDOWS/system32/dllcache/olepro32.dll 433664 ..c. r/rr-xr-xr-x 0 0 7756-128-1 /WINDOWS/system32/dllcache/riched20.dll 3584 ..c. r/rr-xr-xr-x 0 0 7757-128-1 /WINDOWS/system32/dllcache/riched32.dll 208384 ..c. r/rr-xr-xr-x 0 0 7758-128-1 /WINDOWS/system32/dllcache/rsaenh.dll 64000 ..c. r/rr-xr-xr-x 0 0 7759-128-1 /WINDOWS/system32/dllcache/samlib.dll 14428 ..c. r/rr-xr-xr-x 0 0 776-128-3 /WINDOWS/inf/mdmaiwa5.inf 415744 ..c. r/rr-xr-xr-x 0 0 7760-128-1 /WINDOWS/system32/dllcache/samsrv.dll 144384 ..c. r/rr-xr-xr-x 0 0 7761-128-1 /WINDOWS/system32/dllcache/schannel.dll 12288 ..c. r/rr-xr-xr-x 0 0 7762-128-1 /WINDOWS/system32/dllcache/script.fon 180224 ..c. r/rr-xr-xr-x 0 0 7763-128-1 /WINDOWS/system32/dllcache/scrobj.dll 172032 ..c. r/rr-xr-xr-x 0 0 7764-128-1 /WINDOWS/system32/dllcache/scrrun.dll 77312 ..c. r/rr-xr-xr-x 0 0 7765-128-1 /WINDOWS/system32/dllcache/sdbinst.exe 4569 ..c. r/rr-xr-xr-x 0 0 7766-128-1 /WINDOWS/system32/dllcache/secupd.dat 7208 ..c. r/rr-xr-xr-x 0 0 7767-128-1 /WINDOWS/system32/dllcache/secupd.sig 985088 ..c. r/rr-xr-xr-x 0 0 7768-128-1 /WINDOWS/system32/dllcache/setupapi.dll 5120 ..c. r/rr-xr-xr-x 0 0 7769-128-1 /WINDOWS/system32/dllcache/sfc.dll 4317 ..c. r/rr-xr-xr-x 0 0 777-128-3 /WINDOWS/inf/mdmaiwat.inf 9728 ..c. r/rr-xr-xr-x 0 0 7770-128-1 /WINDOWS/system32/dllcache/sfc.exe 1614848 ..c. r/rr-xr-xr-x 0 0 7771-128-1 /WINDOWS/system32/dllcache/sfcfiles.dll 65024 ..c. r/rr-xr-xr-x 0 0 7772-128-1 /WINDOWS/system32/dllcache/shimeng.dll 25088 ..c. r/rr-xr-xr-x 0 0 7773-128-1 /WINDOWS/system32/dllcache/slayerxp.dll 20536 ..c. r/rr-xr-xr-x 0 0 7774-128-3 /WINDOWS/system32/dllcache/shtml.dll 16437 ..c. r/rr-xr-xr-x 0 0 7775-128-3 /WINDOWS/system32/dllcache/shtml.exe 189440 ..c. r/rr-xr-xr-x 0 0 7776-128-3 /WINDOWS/system32/dllcache/smtpadm.dll 2134528 ..c. r/rr-xr-xr-x 0 0 7777-128-3 /WINDOWS/system32/dllcache/smtpsnap.dll 8192 ..c. r/rr-xr-xr-x 0 0 7778-128-3 /WINDOWS/system32/dllcache/staxmem.dll 16896 ..c. r/rr-xr-xr-x 0 0 7779-128-1 /WINDOWS/system32/dllcache/stdole2.tlb 7761 ..c. r/rr-xr-xr-x 0 0 778-128-3 /WINDOWS/inf/mdmar1.inf 1202774 ..c. r/rr-xr-xr-x 0 0 7780-128-1 /WINDOWS/system32/dllcache/sysmain.sdb 106496 ..c. r/rr-xr-xr-x 0 0 7781-128-1 /WINDOWS/system32/dllcache/sysocmgr.exe 383804 ..c. r/rr-xr-xr-x 0 0 7782-128-1 /WINDOWS/system32/dllcache/tahoma.ttf 355680 ..c. r/rr-xr-xr-x 0 0 7783-128-1 /WINDOWS/system32/dllcache/tahomabd.ttf 49680 ..c. r/rr-xr-xr-x 0 0 7784-128-1 /WINDOWS/system32/dllcache/twunk_16.exe 32827 ..c. r/rr-xr-xr-x 0 0 7785-128-3 /WINDOWS/system32/dllcache/tcptest.exe 16384 ..c. r/rr-xr-xr-x 0 0 7786-128-3 /WINDOWS/system32/dllcache/tcptsat.dll 25600 ..c. r/rr-xr-xr-x 0 0 7787-128-1 /WINDOWS/system32/dllcache/twunk_32.exe 177856 ..c. r/rr-xr-xr-x 0 0 7788-128-1 /WINDOWS/system32/dllcache/typelib.dll 123392 ..c. r/rr-xr-xr-x 0 0 7789-128-1 /WINDOWS/system32/dllcache/umpnpmgr.dll 25073 ..c. r/rr-xr-xr-x 0 0 779-128-3 /WINDOWS/inf/mdmarch.inf 37888 ..c. r/rr-xr-xr-x 0 0 7790-128-1 /WINDOWS/system32/dllcache/url.dll 619520 ..c. r/rr-xr-xr-x 0 0 7791-128-1 /WINDOWS/system32/dllcache/urlmon.dll 434176 ..c. r/rr-xr-xr-x 0 0 7792-128-1 /WINDOWS/system32/dllcache/vbscript.dll 5168 ..c. r/rr-xr-xr-x 0 0 7793-128-1 /WINDOWS/system32/dllcache/vgaoem.fon 7168 ..c. r/rr-xr-xr-x 0 0 7794-128-3 /WINDOWS/system32/dllcache/wamregps.dll 666112 ..c. r/rr-xr-xr-x 0 0 7795-128-1 /WINDOWS/system32/dllcache/wininet.dll 507904 ..c. r/rr-xr-xr-x 0 0 7796-128-1 /WINDOWS/system32/dllcache/winlogon.exe 176640 ..c. r/rr-xr-xr-x 0 0 7797-128-1 /WINDOWS/system32/dllcache/wintrust.dll 554008 ..c. r/rr-xr-xr-x 0 0 7798-128-1 /WINDOWS/system32/dllcache/dao360.dll 299520 ..c. r/rr-xr-xr-x 0 0 7799-128-1 /WINDOWS/system32/dllcache/drmclien.dll 7232 ..c. r/rr-xr-xr-x 0 0 780-128-3 /WINDOWS/inf/mdmarn.inf 87040 ..c. r/rr-xr-xr-x 0 0 7800-128-1 /WINDOWS/system32/dllcache/drmstor.dll 16384 ..c. r/rr-xr-xr-x 0 0 7801-128-1 /WINDOWS/system32/dllcache/ds32gt.dll 498742 ..c. r/rr-xr-xr-x 0 0 7802-128-1 /WINDOWS/system32/dllcache/dxmasf.dll 380445 ..c. r/rr-xr-xr-x 0 0 7803-128-1 /WINDOWS/system32/dllcache/expsrv.dll 6656 ..c. r/rr-xr-xr-x 0 0 7804-128-1 /WINDOWS/system32/dllcache/laprxy.dll 103936 ..c. r/rr-xr-xr-x 0 0 7805-128-1 /WINDOWS/system32/dllcache/logagent.exe 262144 ..c. r/rr-xr-xr-x 0 0 7806-128-1 /WINDOWS/system32/dllcache/mpg4ds32.ax 4639 ..c. r/rr-xr-xr-x 0 0 7807-128-1 /WINDOWS/system32/dllcache/mplayer2.exe 331776 ..c. r/rr-xr-xr-x 0 0 7808-128-1 /WINDOWS/system32/dllcache/msadce.dll 20480 ..c. r/rr-xr-xr-x 0 0 7809-128-1 /WINDOWS/system32/dllcache/msadcer.dll 52695 ..c. r/rr-xr-xr-x 0 0 781-128-3 /WINDOWS/inf/mdmati.inf 61440 ..c. r/rr-xr-xr-x 0 0 7810-128-1 /WINDOWS/system32/dllcache/msadcf.dll 16384 ..c. r/rr-xr-xr-x 0 0 7811-128-1 /WINDOWS/system32/dllcache/msadcfr.dll 143360 ..c. r/rr-xr-xr-x 0 0 7812-128-1 /WINDOWS/system32/dllcache/msadco.dll 16384 ..c. r/rr-xr-xr-x 0 0 7813-128-1 /WINDOWS/system32/dllcache/msadcor.dll 53248 ..c. r/rr-xr-xr-x 0 0 7814-128-1 /WINDOWS/system32/dllcache/msadcs.dll 155648 ..c. r/rr-xr-xr-x 0 0 7815-128-1 /WINDOWS/system32/dllcache/msadds.dll 221184 ..c. r/rr-xr-xr-x 0 0 7816-128-1 /WINDOWS/system32/dllcache/msadds32.ax 24576 ..c. r/rr-xr-xr-x 0 0 7817-128-1 /WINDOWS/system32/dllcache/msaddsr.dll 24576 ..c. r/rr-xr-xr-x 0 0 7818-128-1 /WINDOWS/system32/dllcache/msader15.dll 536576 ..c. r/rr-xr-xr-x 0 0 7819-128-1 /WINDOWS/system32/dllcache/msado15.dll 10083 ..c. r/rr-xr-xr-x 0 0 782-128-3 /WINDOWS/inf/mdmatm2k.inf 61440 ..c. r/rr-xr-xr-x 0 0 7820-128-1 /WINDOWS/system32/dllcache/msado20.tlb 61440 ..c. r/rr-xr-xr-x 0 0 7821-128-1 /WINDOWS/system32/dllcache/msado21.tlb 180224 ..c. r/rr-xr-xr-x 0 0 7822-128-1 /WINDOWS/system32/dllcache/msadomd.dll 57344 ..c. r/rr-xr-xr-x 0 0 7823-128-1 /WINDOWS/system32/dllcache/msador15.dll 200704 ..c. r/rr-xr-xr-x 0 0 7824-128-1 /WINDOWS/system32/dllcache/msadox.dll 57344 ..c. r/rr-xr-xr-x 0 0 7825-128-1 /WINDOWS/system32/dllcache/msadrh15.dll 36864 ..c. r/rr-xr-xr-x 0 0 7826-128-1 /WINDOWS/system32/dllcache/mscpxl32.dll 4096 ..c. r/rr-xr-xr-x 0 0 7827-128-1 /WINDOWS/system32/dllcache/msdadc.dll 4096 ..c. r/rr-xr-xr-x 0 0 7828-128-1 /WINDOWS/system32/dllcache/msdaenum.dll 4096 ..c. r/rr-xr-xr-x 0 0 7829-128-1 /WINDOWS/system32/dllcache/msdaer.dll 22012 ..c. r/rr-xr-xr-x 0 0 783-128-3 /WINDOWS/inf/mdmatt.inf 233472 ..c. r/rr-xr-xr-x 0 0 7830-128-1 /WINDOWS/system32/dllcache/msdaora.dll 77824 ..c. r/rr-xr-xr-x 0 0 7831-128-1 /WINDOWS/system32/dllcache/msdaosp.dll 16384 ..c. r/rr-xr-xr-x 0 0 7832-128-1 /WINDOWS/system32/dllcache/msdaprsr.dll 200704 ..c. r/rr-xr-xr-x 0 0 7833-128-1 /WINDOWS/system32/dllcache/msdaprst.dll 204800 ..c. r/rr-xr-xr-x 0 0 7834-128-1 /WINDOWS/system32/dllcache/msdaps.dll 118784 ..c. r/rr-xr-xr-x 0 0 7835-128-1 /WINDOWS/system32/dllcache/msdarem.dll 16384 ..c. r/rr-xr-xr-x 0 0 7836-128-1 /WINDOWS/system32/dllcache/msdaremr.dll 4096 ..c. r/rr-xr-xr-x 0 0 7837-128-1 /WINDOWS/system32/dllcache/msdasc.dll 315392 ..c. r/rr-xr-xr-x 0 0 7838-128-1 /WINDOWS/system32/dllcache/msdasql.dll 16384 ..c. r/rr-xr-xr-x 0 0 7839-128-1 /WINDOWS/system32/dllcache/msdasqlr.dll 12883 ..c. r/rr-xr-xr-x 0 0 784-128-3 /WINDOWS/inf/mdmaus.inf 12288 ..c. r/rr-xr-xr-x 0 0 7840-128-1 /WINDOWS/system32/dllcache/msdatsrc.tlb 20480 ..c. r/rr-xr-xr-x 0 0 7841-128-1 /WINDOWS/system32/dllcache/msdatt.dll 4096 ..c. r/rr-xr-xr-x 0 0 7842-128-1 /WINDOWS/system32/dllcache/msdaurl.dll 36864 ..c. r/rr-xr-xr-x 0 0 7843-128-1 /WINDOWS/system32/dllcache/msdfmap.dll 844314 ..c. r/rr-xr-xr-x 0 0 7844-128-1 /WINDOWS/system32/dllcache/msdxm.ocx 4126 ..c. r/rr-xr-xr-x 0 0 7845-128-1 /WINDOWS/system32/dllcache/msdxmlc.dll 518944 ..c. r/rr-xr-xr-x 0 0 7846-128-1 /WINDOWS/system32/dllcache/msexch40.dll 326432 ..c. r/rr-xr-xr-x 0 0 7847-128-1 /WINDOWS/system32/dllcache/msexcl40.dll 1516568 ..c. r/rr-xr-xr-x 0 0 7848-128-1 /WINDOWS/system32/dllcache/msjet40.dll 151583 ..c. r/rr-xr-xr-x 0 0 7849-128-1 /WINDOWS/system32/dllcache/msjint40.dll 44439 ..c. r/rr-xr-xr-x 0 0 785-128-3 /WINDOWS/inf/mdmboca.inf 102400 ..c. r/rr-xr-xr-x 0 0 7850-128-1 /WINDOWS/system32/dllcache/msjro.dll 60192 ..c. r/rr-xr-xr-x 0 0 7851-128-1 /WINDOWS/system32/dllcache/msjter40.dll 248608 ..c. r/rr-xr-xr-x 0 0 7852-128-1 /WINDOWS/system32/dllcache/msjtes40.dll 219936 ..c. r/rr-xr-xr-x 0 0 7853-128-1 /WINDOWS/system32/dllcache/msltus40.dll 143360 ..c. r/rr-xr-xr-x 0 0 7854-128-1 /WINDOWS/system32/dllcache/msorcl32.dll 355104 ..c. r/rr-xr-xr-x 0 0 7855-128-1 /WINDOWS/system32/dllcache/mspbde40.dll 432928 ..c. r/rr-xr-xr-x 0 0 7856-128-1 /WINDOWS/system32/dllcache/msrd2x40.dll 322336 ..c. r/rr-xr-xr-x 0 0 7857-128-1 /WINDOWS/system32/dllcache/msrd3x40.dll 559904 ..c. r/rr-xr-xr-x 0 0 7858-128-1 /WINDOWS/system32/dllcache/msrepl40.dll 264992 ..c. r/rr-xr-xr-x 0 0 7859-128-1 /WINDOWS/system32/dllcache/mstext40.dll 12357 ..c. r/rr-xr-xr-x 0 0 786-128-3 /WINDOWS/inf/mdmbsb.inf 838432 ..c. r/rr-xr-xr-x 0 0 7860-128-1 /WINDOWS/system32/dllcache/mswdat10.dll 621344 ..c. r/rr-xr-xr-x 0 0 7861-128-1 /WINDOWS/system32/dllcache/mswstr10.dll 24576 ..c. r/rr-xr-xr-x 0 0 7862-128-1 /WINDOWS/system32/dllcache/msxactps.dll 355104 ..c. r/rr-xr-xr-x 0 0 7863-128-1 /WINDOWS/system32/dllcache/msxbde40.dll 364544 ..c. r/rr-xr-xr-x 0 0 7864-128-1 /WINDOWS/system32/dllcache/npdsplay.dll 10240 ..c. r/rr-xr-xr-x 0 0 7865-128-1 /WINDOWS/system32/dllcache/npwmsdrm.dll 249856 ..c. r/rr-xr-xr-x 0 0 7866-128-1 /WINDOWS/system32/dllcache/odbc32.dll 16384 ..c. r/rr-xr-xr-x 0 0 7867-128-1 /WINDOWS/system32/dllcache/odbc32gt.dll 32768 ..c. r/rr-xr-xr-x 0 0 7868-128-1 /WINDOWS/system32/dllcache/odbcad32.exe 135168 ..c. r/rr-xr-xr-x 0 0 7869-128-1 /WINDOWS/system32/dllcache/odbcconf.dll 4206 ..c. r/rr-xr-xr-x 0 0 787-128-3 /WINDOWS/inf/mdmbug3.inf 69632 ..c. r/rr-xr-xr-x 0 0 7870-128-1 /WINDOWS/system32/dllcache/odbcconf.exe 4310 ..c. r/rr-xr-xr-x 0 0 7871-128-1 /WINDOWS/system32/dllcache/odbcconf.rsp 32768 ..c. r/rr-xr-xr-x 0 0 7872-128-1 /WINDOWS/system32/dllcache/odbccp32.cpl 65536 ..c. r/rr-xr-xr-x 0 0 7873-128-1 /WINDOWS/system32/dllcache/odbccr32.dll 65536 ..c. r/rr-xr-xr-x 0 0 7874-128-1 /WINDOWS/system32/dllcache/odbccu32.dll 94208 ..c. r/rr-xr-xr-x 0 0 7875-128-1 /WINDOWS/system32/dllcache/odbcint.dll 53279 ..c. r/rr-xr-xr-x 0 0 7876-128-1 /WINDOWS/system32/dllcache/odbcji32.dll 278559 ..c. r/rr-xr-xr-x 0 0 7877-128-1 /WINDOWS/system32/dllcache/odbcjt32.dll 147456 ..c. r/rr-xr-xr-x 0 0 7878-128-1 /WINDOWS/system32/dllcache/odbctrac.dll 20511 ..c. r/rr-xr-xr-x 0 0 7879-128-1 /WINDOWS/system32/dllcache/oddbse32.dll 14675 ..c. r/rr-xr-xr-x 0 0 788-128-3 /WINDOWS/inf/mdmbw561.INF 20510 ..c. r/rr-xr-xr-x 0 0 7880-128-1 /WINDOWS/system32/dllcache/odexl32.dll 20510 ..c. r/rr-xr-xr-x 0 0 7881-128-1 /WINDOWS/system32/dllcache/odfox32.dll 20510 ..c. r/rr-xr-xr-x 0 0 7882-128-1 /WINDOWS/system32/dllcache/odpdx32.dll 487424 ..c. r/rr-xr-xr-x 0 0 7883-128-1 /WINDOWS/system32/dllcache/oledb32.dll 65536 ..c. r/rr-xr-xr-x 0 0 7884-128-1 /WINDOWS/system32/dllcache/oledb32r.dll 246814 ..c. r/rr-xr-xr-x 0 0 7885-128-1 /WINDOWS/system32/dllcache/strmdll.dll 208896 ..c. r/rr-xr-xr-x 0 0 7886-128-1 /WINDOWS/system32/dllcache/unregmp2.exe 30749 ..c. r/rr-xr-xr-x 0 0 7887-128-1 /WINDOWS/system32/dllcache/vbajet32.dll 2151 ..c. r/rr-xr-xr-x 0 0 7888-128-1 /WINDOWS/system32/dllcache/12520437.cpx 2233 ..c. r/rr-xr-xr-x 0 0 7889-128-1 /WINDOWS/system32/dllcache/12520850.cpx 12899 ..c. r/rr-xr-xr-x 0 0 789-128-3 /WINDOWS/inf/mdmc26a.INF 100352 ..c. r/rr-xr-xr-x 0 0 7890-128-1 /WINDOWS/system32/dllcache/6to4svc.dll 25600 ..c. r/rr-xr-xr-x 0 0 7891-128-1 /WINDOWS/system32/dllcache/aaaamon.dll 68608 ..c. r/rr-xr-xr-x 0 0 7892-128-1 /WINDOWS/system32/dllcache/access.cpl 64512 ..c. r/rr-xr-xr-x 0 0 7893-128-1 /WINDOWS/system32/dllcache/acctres.dll 184320 ..c. r/rr-xr-xr-x 0 0 7894-128-1 /WINDOWS/system32/dllcache/accwiz.exe 129536 ..c. r/rr-xr-xr-x 0 0 7895-128-1 /WINDOWS/system32/dllcache/acledit.dll 141312 ..c. r/rr-xr-xr-x 0 0 7896-128-1 /WINDOWS/system32/dllcache/aclua.dll 115712 ..c. r/rr-xr-xr-x 0 0 7897-128-1 /WINDOWS/system32/dllcache/aclui.dll 193536 ..c. r/rr-xr-xr-x 0 0 7898-128-1 /WINDOWS/system32/dllcache/activeds.dll 111104 ..c. r/rr-xr-xr-x 0 0 7899-128-1 /WINDOWS/system32/dllcache/activeds.tlb 144 .a.. d/dr-xr-xr-x 0 0 79-144-1 /WINDOWS/msapps 6045 ..c. r/rr-xr-xr-x 0 0 790-128-3 /WINDOWS/inf/mdmcdp.inf 4096 ..c. r/rr-xr-xr-x 0 0 7900-128-1 /WINDOWS/system32/dllcache/actmovie.exe 98304 ..c. r/rr-xr-xr-x 0 0 7901-128-1 /WINDOWS/system32/dllcache/actxprxy.dll 29696 ..c. r/rr-xr-xr-x 0 0 7902-128-3 /WINDOWS/system32/dllcache/admexs.dll 61440 ..c. r/rr-xr-xr-x 0 0 7903-128-1 /WINDOWS/system32/dllcache/admparse.dll 6144 ..c. r/rr-xr-xr-x 0 0 7904-128-3 /WINDOWS/system32/dllcache/admxprox.dll 26112 ..c. r/rr-xr-xr-x 0 0 7905-128-1 /WINDOWS/system32/dllcache/adptif.dll 49664 ..c. r/rr-xr-xr-x 0 0 7906-128-3 /WINDOWS/system32/dllcache/adrot.dll 175616 ..c. r/rr-xr-xr-x 0 0 7907-128-1 /WINDOWS/system32/dllcache/adsldp.dll 5632 ..c. r/rr-xr-xr-x 0 0 7908-128-3 /WINDOWS/system32/dllcache/EXCH_adsiisex.dll 143360 ..c. r/rr-xr-xr-x 0 0 7909-128-1 /WINDOWS/system32/dllcache/adsldpc.dll 77 ..c. r/rr-xr-xr-x 0 0 791-128-1 /WINDOWS/inf/mdmchipv.inf 68096 ..c. r/rr-xr-xr-x 0 0 7910-128-1 /WINDOWS/system32/dllcache/adsmsext.dll 161792 ..c. r/rr-xr-xr-x 0 0 7911-128-1 /WINDOWS/system32/dllcache/adsnds.dll 263680 ..c. r/rr-xr-xr-x 0 0 7912-128-1 /WINDOWS/system32/dllcache/adsnt.dll 123392 ..c. r/rr-xr-xr-x 0 0 7913-128-1 /WINDOWS/system32/dllcache/adsnw.dll 617472 ..c. r/rr-xr-xr-x 0 0 7914-128-1 /WINDOWS/system32/dllcache/advapi32.dll 99840 ..c. r/rr-xr-xr-x 0 0 7915-128-1 /WINDOWS/system32/dllcache/advpack.dll 138112 ..c. r/rr-xr-xr-x 0 0 7916-128-1 /WINDOWS/system32/dllcache/afd.sys 24064 ..c. r/rr-xr-xr-x 0 0 7917-128-1 /WINDOWS/system32/dllcache/agentanm.dll 214016 ..c. r/rr-xr-xr-x 0 0 7918-128-1 /WINDOWS/system32/dllcache/agentctl.dll 42496 ..c. r/rr-xr-xr-x 0 0 7919-128-1 /WINDOWS/system32/dllcache/agentdp2.dll 69701 ..c. r/rr-xr-xr-x 0 0 792-128-3 /WINDOWS/inf/mdmcm28.inf 57344 ..c. r/rr-xr-xr-x 0 0 7920-128-1 /WINDOWS/system32/dllcache/agentdpv.dll 49152 ..c. r/rr-xr-xr-x 0 0 7921-128-1 /WINDOWS/system32/dllcache/agentmpx.dll 24064 ..c. r/rr-xr-xr-x 0 0 7922-128-1 /WINDOWS/system32/dllcache/agentpsh.dll 44032 ..c. r/rr-xr-xr-x 0 0 7923-128-1 /WINDOWS/system32/dllcache/agentsr.dll 256512 ..c. r/rr-xr-xr-x 0 0 7924-128-1 /WINDOWS/system32/dllcache/agentsvr.exe 19456 ..c. r/rr-xr-xr-x 0 0 7925-128-3 /WINDOWS/system32/dllcache/agt0401.dll 19456 ..c. r/rr-xr-xr-x 0 0 7926-128-3 /WINDOWS/system32/dllcache/agt0404.dll 19456 ..c. r/rr-xr-xr-x 0 0 7927-128-1 /WINDOWS/system32/dllcache/agt0405.dll 19456 ..c. r/rr-xr-xr-x 0 0 7928-128-1 /WINDOWS/system32/dllcache/agt0406.dll 21504 ..c. r/rr-xr-xr-x 0 0 7929-128-1 /WINDOWS/system32/dllcache/agt0407.dll 13035 ..c. r/rr-xr-xr-x 0 0 793-128-3 /WINDOWS/inf/mdmcodex.inf 22016 ..c. r/rr-xr-xr-x 0 0 7930-128-1 /WINDOWS/system32/dllcache/agt0408.dll 19968 ..c. r/rr-xr-xr-x 0 0 7931-128-1 /WINDOWS/system32/dllcache/agt0409.dll 19456 ..c. r/rr-xr-xr-x 0 0 7932-128-1 /WINDOWS/system32/dllcache/agt040b.dll 21504 ..c. r/rr-xr-xr-x 0 0 7933-128-1 /WINDOWS/system32/dllcache/agt040c.dll 19456 ..c. r/rr-xr-xr-x 0 0 7934-128-3 /WINDOWS/system32/dllcache/agt040d.dll 19968 ..c. r/rr-xr-xr-x 0 0 7935-128-1 /WINDOWS/system32/dllcache/agt040e.dll 20992 ..c. r/rr-xr-xr-x 0 0 7936-128-1 /WINDOWS/system32/dllcache/agt0410.dll 19456 ..c. r/rr-xr-xr-x 0 0 7937-128-3 /WINDOWS/system32/dllcache/agt0411.dll 19456 ..c. r/rr-xr-xr-x 0 0 7938-128-3 /WINDOWS/system32/dllcache/agt0412.dll 20992 ..c. r/rr-xr-xr-x 0 0 7939-128-1 /WINDOWS/system32/dllcache/agt0413.dll 28499 ..c. r/rr-xr-xr-x 0 0 794-128-3 /WINDOWS/inf/mdmcom1.inf 19456 ..c. r/rr-xr-xr-x 0 0 7940-128-1 /WINDOWS/system32/dllcache/agt0414.dll 19456 ..c. r/rr-xr-xr-x 0 0 7941-128-1 /WINDOWS/system32/dllcache/agt0415.dll 20480 ..c. r/rr-xr-xr-x 0 0 7942-128-1 /WINDOWS/system32/dllcache/agt0416.dll 19456 ..c. r/rr-xr-xr-x 0 0 7943-128-1 /WINDOWS/system32/dllcache/agt0419.dll 19456 ..c. r/rr-xr-xr-x 0 0 7944-128-1 /WINDOWS/system32/dllcache/agt041d.dll 19456 ..c. r/rr-xr-xr-x 0 0 7945-128-1 /WINDOWS/system32/dllcache/agt041f.dll 19456 ..c. r/rr-xr-xr-x 0 0 7946-128-3 /WINDOWS/system32/dllcache/agt0804.dll 20992 ..c. r/rr-xr-xr-x 0 0 7947-128-1 /WINDOWS/system32/dllcache/agt0816.dll 20480 ..c. r/rr-xr-xr-x 0 0 7948-128-1 /WINDOWS/system32/dllcache/agt0c0a.dll 18432 ..c. r/rr-xr-xr-x 0 0 7949-128-1 /WINDOWS/system32/dllcache/agtctl15.tlb 3761 ..c. r/rr-xr-xr-x 0 0 795-128-3 /WINDOWS/inf/mdmcommu.inf 24064 ..c. r/rr-xr-xr-x 0 0 7950-128-1 /WINDOWS/system32/dllcache/agtintl.dll 44544 ..c. r/rr-xr-xr-x 0 0 7951-128-1 /WINDOWS/system32/dllcache/alg.exe 17408 ..c. r/rr-xr-xr-x 0 0 7952-128-1 /WINDOWS/system32/dllcache/alrsvc.dll 70656 ..c. r/rr-xr-xr-x 0 0 7953-128-1 /WINDOWS/system32/dllcache/amstream.dll 9029 ..c. r/rr-xr-xr-x 0 0 7954-128-1 /WINDOWS/system32/dllcache/ansi.sys 102912 ..c. r/rr-xr-xr-x 0 0 7955-128-1 /WINDOWS/system32/dllcache/apcups.dll 108544 ..c. r/rr-xr-xr-x 0 0 7956-128-3 /WINDOWS/system32/dllcache/appconf.dll 12498 ..c. r/rr-xr-xr-x 0 0 7957-128-1 /WINDOWS/system32/dllcache/append.exe 167936 ..c. r/rr-xr-xr-x 0 0 7958-128-1 /WINDOWS/system32/dllcache/appmgmts.dll 295936 ..c. r/rr-xr-xr-x 0 0 7959-128-1 /WINDOWS/system32/dllcache/appmgr.dll 6027 ..c. r/rr-xr-xr-x 0 0 796-128-3 /WINDOWS/inf/mdmcomp.inf 549888 ..c. r/rr-xr-xr-x 0 0 7960-128-1 /WINDOWS/system32/dllcache/appwiz.cpl 331264 ..c. r/rr-xr-xr-x 0 0 7961-128-3 /WINDOWS/system32/dllcache/aqueue.dll 45056 ..c. r/rr-xr-xr-x 0 0 7962-128-3 /WINDOWS/system32/dllcache/EXCH_aqadmin.dll 19456 ..c. r/rr-xr-xr-x 0 0 7963-128-1 /WINDOWS/system32/dllcache/arp.exe 114688 ..c. r/rr-xr-xr-x 0 0 7964-128-1 /WINDOWS/system32/dllcache/asctrls.ocx 8192 ..c. r/rr-xr-xr-x 0 0 7965-128-1 /WINDOWS/system32/dllcache/asferror.dll 369664 ..c. r/rr-xr-xr-x 0 0 7966-128-3 /WINDOWS/system32/dllcache/asp51.dll 10240 ..c. r/rr-xr-xr-x 0 0 7967-128-3 /WINDOWS/system32/dllcache/aspperf.dll 29184 ..c. r/rr-xr-xr-x 0 0 7968-128-3 /WINDOWS/system32/dllcache/asptxn.dll 30208 ..c. r/rr-xr-xr-x 0 0 7969-128-1 /WINDOWS/system32/dllcache/asr_fmt.exe 104156 ..c. r/rr-xr-xr-x 0 0 797-128-3 /WINDOWS/inf/mdmcpq.inf 32256 ..c. r/rr-xr-xr-x 0 0 7970-128-1 /WINDOWS/system32/dllcache/asr_ldm.exe 32768 ..c. r/rr-xr-xr-x 0 0 7971-128-1 /WINDOWS/system32/dllcache/asr_pfu.exe 14336 ..c. r/rr-xr-xr-x 0 0 7972-128-1 /WINDOWS/system32/dllcache/asyncmac.sys 25088 ..c. r/rr-xr-xr-x 0 0 7973-128-1 /WINDOWS/system32/dllcache/at.exe 13312 ..c. r/rr-xr-xr-x 0 0 7974-128-1 /WINDOWS/system32/dllcache/atkctrs.dll 58880 ..c. r/rr-xr-xr-x 0 0 7975-128-1 /WINDOWS/system32/dllcache/atl.dll 11264 ..c. r/rr-xr-xr-x 0 0 7976-128-1 /WINDOWS/system32/dllcache/atmadm.exe 59904 ..c. r/rr-xr-xr-x 0 0 7977-128-1 /WINDOWS/system32/dllcache/atmarpc.sys 31360 ..c. r/rr-xr-xr-x 0 0 7978-128-1 /WINDOWS/system32/dllcache/atmepvc.sys 285696 ..c. r/rr-xr-xr-x 0 0 7979-128-1 /WINDOWS/system32/dllcache/atmfd.dll 28376 ..c. r/rr-xr-xr-x 0 0 798-128-3 /WINDOWS/inf/mdmcpq2.inf 55808 ..c. r/rr-xr-xr-x 0 0 7980-128-1 /WINDOWS/system32/dllcache/atmlane.sys 34816 ..c. r/rr-xr-xr-x 0 0 7981-128-1 /WINDOWS/system32/dllcache/atmpvcno.dll 352256 ..c. r/rr-xr-xr-x 0 0 7982-128-1 /WINDOWS/system32/dllcache/atmuni.sys 11264 ..c. r/rr-xr-xr-x 0 0 7983-128-1 /WINDOWS/system32/dllcache/atrace.dll 12288 ..c. r/rr-xr-xr-x 0 0 7984-128-1 /WINDOWS/system32/dllcache/attrib.exe 42496 ..c. r/rr-xr-xr-x 0 0 7985-128-1 /WINDOWS/system32/dllcache/audiosrv.dll 14336 ..c. r/rr-xr-xr-x 0 0 7986-128-1 /WINDOWS/system32/dllcache/auditusr.exe 9216 ..c. r/rr-xr-xr-x 0 0 7987-128-3 /WINDOWS/system32/dllcache/authfilt.dll 62464 ..c. r/rr-xr-xr-x 0 0 7988-128-1 /WINDOWS/system32/dllcache/authz.dll 588800 ..c. r/rr-xr-xr-x 0 0 7989-128-1 /WINDOWS/system32/dllcache/autochk.exe 5689 ..c. r/rr-xr-xr-x 0 0 799-128-3 /WINDOWS/inf/mdmcpv.inf 602624 ..c. r/rr-xr-xr-x 0 0 7990-128-1 /WINDOWS/system32/dllcache/autoconv.exe 80384 ..c. r/rr-xr-xr-x 0 0 7991-128-1 /WINDOWS/system32/dllcache/autodisc.dll 580608 ..c. r/rr-xr-xr-x 0 0 7992-128-1 /WINDOWS/system32/dllcache/autofmt.exe 11264 ..c. r/rr-xr-xr-x 0 0 7993-128-1 /WINDOWS/system32/dllcache/autolfn.exe 64000 ..c. r/rr-xr-xr-x 0 0 7994-128-1 /WINDOWS/system32/dllcache/avicap32.dll 69584 ..c. r/rr-xr-xr-x 0 0 7995-128-1 /WINDOWS/system32/dllcache/avicap.dll 84992 ..c. r/rr-xr-xr-x 0 0 7996-128-1 /WINDOWS/system32/dllcache/avifil32.dll 16384 ..c. r/rr-xr-xr-x 0 0 7997-128-1 /WINDOWS/system32/dllcache/avmeter.dll 109456 ..c. r/rr-xr-xr-x 0 0 7998-128-1 /WINDOWS/system32/dllcache/avifile.dll 227840 ..c. r/rr-xr-xr-x 0 0 7999-128-1 /WINDOWS/system32/dllcache/avtapi.dll 48 .ac. d/dr-xr-xr-x 0 0 80-144-1 /WINDOWS/msapps/msinfo 11972 ..c. r/rr-xr-xr-x 0 0 800-128-3 /WINDOWS/inf/mdmcrtix.inf 73216 ..c. r/rr-xr-xr-x 0 0 8000-128-1 /WINDOWS/system32/dllcache/avwav.dll 52736 ..c. r/rr-xr-xr-x 0 0 8001-128-1 /WINDOWS/system32/dllcache/basesrv.dll 29184 ..c. r/rr-xr-xr-x 0 0 8002-128-1 /WINDOWS/system32/dllcache/batmeter.dll 8704 ..c. r/rr-xr-xr-x 0 0 8003-128-1 /WINDOWS/system32/dllcache/batt.dll 82501 ..c. r/rr-xr-xr-x 0 0 8004-128-1 /WINDOWS/system32/dllcache/bckg.dll 1817687 ..c. r/rr-xr-xr-x 0 0 8005-128-1 /WINDOWS/system32/dllcache/bckgres.dll 42577 ..c. r/rr-xr-xr-x 0 0 8006-128-1 /WINDOWS/system32/dllcache/bckgzm.exe 4224 ..c. r/rr-xr-xr-x 0 0 8007-128-1 /WINDOWS/system32/dllcache/beep.sys 17408 ..c. r/rr-xr-xr-x 0 0 8008-128-1 /WINDOWS/system32/dllcache/bidispl.dll 66728 ..c. r/rr-xr-xr-x 0 0 8009-128-3 /WINDOWS/system32/dllcache/big5.nls 53570 ..c. r/rr-xr-xr-x 0 0 801-128-3 /WINDOWS/inf/mdmdcm5.inf 8192 ..c. r/rr-xr-xr-x 0 0 8010-128-1 /WINDOWS/system32/dllcache/bitsprx2.dll 7168 ..c. r/rr-xr-xr-x 0 0 8011-128-1 /WINDOWS/system32/dllcache/bitsprx3.dll 286720 ..c. r/rr-xr-xr-x 0 0 8012-128-1 /WINDOWS/system32/dllcache/blackbox.dll 71680 ..c. r/rr-xr-xr-x 0 0 8013-128-1 /WINDOWS/system32/dllcache/blastcln.exe 152576 ..c. r/rr-xr-xr-x 0 0 8014-128-1 /WINDOWS/system32/dllcache/bnts.dll 142848 ..c. r/rr-xr-xr-x 0 0 8015-128-1 /WINDOWS/system32/dllcache/bootcfg.exe 4608 ..c. r/rr-xr-xr-x 0 0 8016-128-1 /WINDOWS/system32/dllcache/bootok.exe 12288 ..c. r/rr-xr-xr-x 0 0 8017-128-1 /WINDOWS/system32/dllcache/bootvid.dll 5120 ..c. r/rr-xr-xr-x 0 0 8018-128-1 /WINDOWS/system32/dllcache/bootvrfy.exe 82172 ..c. r/rr-xr-xr-x 0 0 8019-128-3 /WINDOWS/system32/dllcache/bopomofo.nls 22776 ..c. r/rr-xr-xr-x 0 0 802-128-3 /WINDOWS/inf/mdmdcm6.inf 71552 ..c. r/rr-xr-xr-x 0 0 8020-128-1 /WINDOWS/system32/dllcache/bridge.sys 45568 ..c. r/rr-xr-xr-x 0 0 8021-128-3 /WINDOWS/system32/dllcache/browscap.dll 63488 ..c. r/rr-xr-xr-x 0 0 8022-128-1 /WINDOWS/system32/dllcache/browselc.dll 77824 ..c. r/rr-xr-xr-x 0 0 8023-128-1 /WINDOWS/system32/dllcache/browser.dll 1025024 ..c. r/rr-xr-xr-x 0 0 8024-128-1 /WINDOWS/system32/dllcache/browseui.dll 78336 ..c. r/rr-xr-xr-x 0 0 8025-128-1 /WINDOWS/system32/dllcache/browsewm.dll 21504 ..c. r/rr-xr-xr-x 0 0 8026-128-1 /WINDOWS/system32/dllcache/brpinfo.dll 50688 ..c. r/rr-xr-xr-x 0 0 8027-128-1 /WINDOWS/system32/dllcache/btpanui.dll 66082 ..c. r/rr-xr-xr-x 0 0 8028-128-1 /WINDOWS/system32/dllcache/c_037.nls 66082 ..c. r/rr-xr-xr-x 0 0 8029-128-1 /WINDOWS/system32/dllcache/c_10000.nls 13275 ..c. r/rr-xr-xr-x 0 0 803-128-3 /WINDOWS/inf/mdmdf56F.inf 162850 ..c. r/rr-xr-xr-x 0 0 8030-128-3 /WINDOWS/system32/dllcache/c_10001.nls 195618 ..c. r/rr-xr-xr-x 0 0 8031-128-3 /WINDOWS/system32/dllcache/c_10002.nls 177698 ..c. r/rr-xr-xr-x 0 0 8032-128-3 /WINDOWS/system32/dllcache/c_10003.nls 66082 ..c. r/rr-xr-xr-x 0 0 8033-128-3 /WINDOWS/system32/dllcache/c_10004.nls 66082 ..c. r/rr-xr-xr-x 0 0 8034-128-3 /WINDOWS/system32/dllcache/c_10005.nls 66082 ..c. r/rr-xr-xr-x 0 0 8035-128-1 /WINDOWS/system32/dllcache/c_10006.nls 66082 ..c. r/rr-xr-xr-x 0 0 8036-128-1 /WINDOWS/system32/dllcache/c_10007.nls 173602 ..c. r/rr-xr-xr-x 0 0 8037-128-3 /WINDOWS/system32/dllcache/c_10008.nls 66082 ..c. r/rr-xr-xr-x 0 0 8038-128-1 /WINDOWS/system32/dllcache/c_10010.nls 66082 ..c. r/rr-xr-xr-x 0 0 8039-128-1 /WINDOWS/system32/dllcache/c_10017.nls 9736 ..c. r/rr-xr-xr-x 0 0 804-128-3 /WINDOWS/inf/mdmdgitn.inf 66082 ..c. r/rr-xr-xr-x 0 0 8040-128-3 /WINDOWS/system32/dllcache/c_10021.nls 66082 ..c. r/rr-xr-xr-x 0 0 8041-128-1 /WINDOWS/system32/dllcache/c_10029.nls 66082 ..c. r/rr-xr-xr-x 0 0 8042-128-1 /WINDOWS/system32/dllcache/c_10079.nls 66082 ..c. r/rr-xr-xr-x 0 0 8043-128-1 /WINDOWS/system32/dllcache/c_10081.nls 66082 ..c. r/rr-xr-xr-x 0 0 8044-128-1 /WINDOWS/system32/dllcache/c_10082.nls 66082 ..c. r/rr-xr-xr-x 0 0 8045-128-1 /WINDOWS/system32/dllcache/c_1026.nls 66082 ..c. r/rr-xr-xr-x 0 0 8046-128-3 /WINDOWS/system32/dllcache/c_1047.nls 66082 ..c. r/rr-xr-xr-x 0 0 8047-128-3 /WINDOWS/system32/dllcache/c_1140.nls 66082 ..c. r/rr-xr-xr-x 0 0 8048-128-3 /WINDOWS/system32/dllcache/c_1141.nls 66082 ..c. r/rr-xr-xr-x 0 0 8049-128-3 /WINDOWS/system32/dllcache/c_1142.nls 11407 ..c. r/rr-xr-xr-x 0 0 805-128-3 /WINDOWS/inf/mdmdgden.inf 66082 ..c. r/rr-xr-xr-x 0 0 8050-128-3 /WINDOWS/system32/dllcache/c_1143.nls 66082 ..c. r/rr-xr-xr-x 0 0 8051-128-3 /WINDOWS/system32/dllcache/c_1144.nls 66082 ..c. r/rr-xr-xr-x 0 0 8052-128-3 /WINDOWS/system32/dllcache/c_1145.nls 66082 ..c. r/rr-xr-xr-x 0 0 8053-128-3 /WINDOWS/system32/dllcache/c_1146.nls 66082 ..c. r/rr-xr-xr-x 0 0 8054-128-3 /WINDOWS/system32/dllcache/c_1147.nls 66082 ..c. r/rr-xr-xr-x 0 0 8055-128-3 /WINDOWS/system32/dllcache/c_1148.nls 66082 ..c. r/rr-xr-xr-x 0 0 8056-128-3 /WINDOWS/system32/dllcache/c_1149.nls 66082 ..c. r/rr-xr-xr-x 0 0 8057-128-1 /WINDOWS/system32/dllcache/c_1250.nls 66082 ..c. r/rr-xr-xr-x 0 0 8058-128-1 /WINDOWS/system32/dllcache/c_1251.nls 66082 ..c. r/rr-xr-xr-x 0 0 8059-128-1 /WINDOWS/system32/dllcache/c_1252.nls 9288 ..c. r/rr-xr-xr-x 0 0 806-128-3 /WINDOWS/inf/mdmdp2.inf 66082 ..c. r/rr-xr-xr-x 0 0 8060-128-1 /WINDOWS/system32/dllcache/c_1253.nls 66082 ..c. r/rr-xr-xr-x 0 0 8061-128-1 /WINDOWS/system32/dllcache/c_1254.nls 66082 ..c. r/rr-xr-xr-x 0 0 8062-128-1 /WINDOWS/system32/dllcache/c_1255.nls 66082 ..c. r/rr-xr-xr-x 0 0 8063-128-1 /WINDOWS/system32/dllcache/c_1256.nls 66082 ..c. r/rr-xr-xr-x 0 0 8064-128-1 /WINDOWS/system32/dllcache/c_1257.nls 66082 ..c. r/rr-xr-xr-x 0 0 8065-128-1 /WINDOWS/system32/dllcache/c_1258.nls 189986 ..c. r/rr-xr-xr-x 0 0 8066-128-3 /WINDOWS/system32/dllcache/c_1361.nls 180258 ..c. r/rr-xr-xr-x 0 0 8067-128-3 /WINDOWS/system32/dllcache/c_20000.nls 186402 ..c. r/rr-xr-xr-x 0 0 8068-128-3 /WINDOWS/system32/dllcache/c_20001.nls 173602 ..c. r/rr-xr-xr-x 0 0 8069-128-3 /WINDOWS/system32/dllcache/c_20002.nls 133512 ..c. r/rr-xr-xr-x 0 0 807-128-3 /WINDOWS/inf/mdmdsi.inf 185378 ..c. r/rr-xr-xr-x 0 0 8070-128-3 /WINDOWS/system32/dllcache/c_20003.nls 180258 ..c. r/rr-xr-xr-x 0 0 8071-128-3 /WINDOWS/system32/dllcache/c_20004.nls 187938 ..c. r/rr-xr-xr-x 0 0 8072-128-3 /WINDOWS/system32/dllcache/c_20005.nls 66082 ..c. r/rr-xr-xr-x 0 0 8073-128-3 /WINDOWS/system32/dllcache/c_20105.nls 66082 ..c. r/rr-xr-xr-x 0 0 8074-128-3 /WINDOWS/system32/dllcache/c_20106.nls 66082 ..c. r/rr-xr-xr-x 0 0 8075-128-3 /WINDOWS/system32/dllcache/c_20107.nls 66082 ..c. r/rr-xr-xr-x 0 0 8076-128-3 /WINDOWS/system32/dllcache/c_20108.nls 66082 ..c. r/rr-xr-xr-x 0 0 8077-128-1 /WINDOWS/system32/dllcache/c_20127.nls 139810 ..c. r/rr-xr-xr-x 0 0 8078-128-1 /WINDOWS/system32/dllcache/c_20261.nls 66082 ..c. r/rr-xr-xr-x 0 0 8079-128-3 /WINDOWS/system32/dllcache/c_20269.nls 38304 ..c. r/rr-xr-xr-x 0 0 808-128-3 /WINDOWS/inf/mdmdyna.inf 66082 ..c. r/rr-xr-xr-x 0 0 8080-128-3 /WINDOWS/system32/dllcache/c_20273.nls 66082 ..c. r/rr-xr-xr-x 0 0 8081-128-3 /WINDOWS/system32/dllcache/c_20277.nls 66082 ..c. r/rr-xr-xr-x 0 0 8082-128-3 /WINDOWS/system32/dllcache/c_20278.nls 66082 ..c. r/rr-xr-xr-x 0 0 8083-128-3 /WINDOWS/system32/dllcache/c_20280.nls 66082 ..c. r/rr-xr-xr-x 0 0 8084-128-3 /WINDOWS/system32/dllcache/c_20284.nls 66082 ..c. r/rr-xr-xr-x 0 0 8085-128-3 /WINDOWS/system32/dllcache/c_20285.nls 66082 ..c. r/rr-xr-xr-x 0 0 8086-128-3 /WINDOWS/system32/dllcache/c_20290.nls 66082 ..c. r/rr-xr-xr-x 0 0 8087-128-3 /WINDOWS/system32/dllcache/c_20297.nls 66082 ..c. r/rr-xr-xr-x 0 0 8088-128-3 /WINDOWS/system32/dllcache/c_20420.nls 66082 ..c. r/rr-xr-xr-x 0 0 8089-128-3 /WINDOWS/system32/dllcache/c_20423.nls 17939 ..c. r/rr-xr-xr-x 0 0 809-128-3 /WINDOWS/inf/mdmeiger.inf 66082 ..c. r/rr-xr-xr-x 0 0 8090-128-3 /WINDOWS/system32/dllcache/c_20424.nls 66082 ..c. r/rr-xr-xr-x 0 0 8091-128-3 /WINDOWS/system32/dllcache/c_20833.nls 66082 ..c. r/rr-xr-xr-x 0 0 8092-128-3 /WINDOWS/system32/dllcache/c_20838.nls 66082 ..c. r/rr-xr-xr-x 0 0 8093-128-1 /WINDOWS/system32/dllcache/c_20866.nls 66082 ..c. r/rr-xr-xr-x 0 0 8094-128-3 /WINDOWS/system32/dllcache/c_20871.nls 66082 ..c. r/rr-xr-xr-x 0 0 8095-128-3 /WINDOWS/system32/dllcache/c_20880.nls 66082 ..c. r/rr-xr-xr-x 0 0 8096-128-1 /WINDOWS/system32/dllcache/c_20905.nls 66082 ..c. r/rr-xr-xr-x 0 0 8097-128-3 /WINDOWS/system32/dllcache/c_20924.nls 180770 ..c. r/rr-xr-xr-x 0 0 8098-128-3 /WINDOWS/system32/dllcache/c_20932.nls 173602 ..c. r/rr-xr-xr-x 0 0 8099-128-3 /WINDOWS/system32/dllcache/c_20936.nls 152 .ac. d/dr-xr-xr-x 0 0 81-144-1 /WINDOWS/msagent/chars 76481 ..c. r/rr-xr-xr-x 0 0 810-128-3 /WINDOWS/inf/mdmelsa.inf 177698 ..c. r/rr-xr-xr-x 0 0 8100-128-3 /WINDOWS/system32/dllcache/c_20949.nls 66082 ..c. r/rr-xr-xr-x 0 0 8101-128-3 /WINDOWS/system32/dllcache/c_21025.nls 66082 ..c. r/rr-xr-xr-x 0 0 8102-128-3 /WINDOWS/system32/dllcache/c_21027.nls 66082 ..c. r/rr-xr-xr-x 0 0 8103-128-1 /WINDOWS/system32/dllcache/c_21866.nls 66082 ..c. r/rr-xr-xr-x 0 0 8104-128-1 /WINDOWS/system32/dllcache/c_28591.nls 66082 ..c. r/rr-xr-xr-x 0 0 8105-128-1 /WINDOWS/system32/dllcache/c_28592.nls 66082 ..c. r/rr-xr-xr-x 0 0 8106-128-1 /WINDOWS/system32/dllcache/c_28593.nls 66082 ..c. r/rr-xr-xr-x 0 0 8107-128-1 /WINDOWS/system32/dllcache/c_28594.nls 66082 ..c. r/rr-xr-xr-x 0 0 8108-128-1 /WINDOWS/system32/dllcache/c_28595.nls 66082 ..c. r/rr-xr-xr-x 0 0 8109-128-3 /WINDOWS/system32/dllcache/c_28596.nls 9972 ..c. r/rr-xr-xr-x 0 0 811-128-3 /WINDOWS/inf/mdmeric.inf 66082 ..c. r/rr-xr-xr-x 0 0 8110-128-1 /WINDOWS/system32/dllcache/c_28597.nls 66082 ..c. r/rr-xr-xr-x 0 0 8111-128-1 /WINDOWS/system32/dllcache/c_28598.nls 66082 ..c. r/rr-xr-xr-x 0 0 8112-128-1 /WINDOWS/system32/dllcache/c_28599.nls 66082 ..c. r/rr-xr-xr-x 0 0 8113-128-1 /WINDOWS/system32/dllcache/c_28603.nls 66082 ..c. r/rr-xr-xr-x 0 0 8114-128-1 /WINDOWS/system32/dllcache/c_28605.nls 66594 ..c. r/rr-xr-xr-x 0 0 8115-128-1 /WINDOWS/system32/dllcache/c_437.nls 66082 ..c. r/rr-xr-xr-x 0 0 8116-128-1 /WINDOWS/system32/dllcache/c_500.nls 66082 ..c. r/rr-xr-xr-x 0 0 8117-128-3 /WINDOWS/system32/dllcache/c_708.nls 66594 ..c. r/rr-xr-xr-x 0 0 8118-128-3 /WINDOWS/system32/dllcache/c_720.nls 66594 ..c. r/rr-xr-xr-x 0 0 8119-128-1 /WINDOWS/system32/dllcache/c_737.nls 15523 ..c. r/rr-xr-xr-x 0 0 812-128-3 /WINDOWS/inf/mdmeric2.inf 66594 ..c. r/rr-xr-xr-x 0 0 8120-128-1 /WINDOWS/system32/dllcache/c_775.nls 66594 ..c. r/rr-xr-xr-x 0 0 8121-128-1 /WINDOWS/system32/dllcache/c_850.nls 66594 ..c. r/rr-xr-xr-x 0 0 8122-128-1 /WINDOWS/system32/dllcache/c_852.nls 66594 ..c. r/rr-xr-xr-x 0 0 8123-128-1 /WINDOWS/system32/dllcache/c_855.nls 66594 ..c. r/rr-xr-xr-x 0 0 8124-128-1 /WINDOWS/system32/dllcache/c_857.nls 66594 ..c. r/rr-xr-xr-x 0 0 8125-128-3 /WINDOWS/system32/dllcache/c_858.nls 66594 ..c. r/rr-xr-xr-x 0 0 8126-128-1 /WINDOWS/system32/dllcache/c_860.nls 66594 ..c. r/rr-xr-xr-x 0 0 8127-128-1 /WINDOWS/system32/dllcache/c_861.nls 66594 ..c. r/rr-xr-xr-x 0 0 8128-128-3 /WINDOWS/system32/dllcache/c_862.nls 66594 ..c. r/rr-xr-xr-x 0 0 8129-128-1 /WINDOWS/system32/dllcache/c_863.nls 31321 ..c. r/rr-xr-xr-x 0 0 813-128-3 /WINDOWS/inf/mdmexp.inf 66594 ..c. r/rr-xr-xr-x 0 0 8130-128-3 /WINDOWS/system32/dllcache/c_864.nls 66594 ..c. r/rr-xr-xr-x 0 0 8131-128-1 /WINDOWS/system32/dllcache/c_865.nls 66594 ..c. r/rr-xr-xr-x 0 0 8132-128-1 /WINDOWS/system32/dllcache/c_866.nls 66594 ..c. r/rr-xr-xr-x 0 0 8133-128-1 /WINDOWS/system32/dllcache/c_869.nls 66082 ..c. r/rr-xr-xr-x 0 0 8134-128-3 /WINDOWS/system32/dllcache/c_870.nls 66594 ..c. r/rr-xr-xr-x 0 0 8135-128-1 /WINDOWS/system32/dllcache/c_874.nls 66082 ..c. r/rr-xr-xr-x 0 0 8136-128-1 /WINDOWS/system32/dllcache/c_875.nls 162850 ..c. r/rr-xr-xr-x 0 0 8137-128-1 /WINDOWS/system32/dllcache/c_932.nls 196642 ..c. r/rr-xr-xr-x 0 0 8138-128-1 /WINDOWS/system32/dllcache/c_936.nls 196642 ..c. r/rr-xr-xr-x 0 0 8139-128-1 /WINDOWS/system32/dllcache/c_949.nls 11037 ..c. r/rr-xr-xr-x 0 0 814-128-3 /WINDOWS/inf/mdmfj2.inf 196642 ..c. r/rr-xr-xr-x 0 0 8140-128-1 /WINDOWS/system32/dllcache/c_950.nls 218112 ..c. r/rr-xr-xr-x 0 0 8141-128-3 /WINDOWS/system32/dllcache/c_g18030.dll 6656 ..c. r/rr-xr-xr-x 0 0 8142-128-3 /WINDOWS/system32/dllcache/c_is2022.dll 10752 ..c. r/rr-xr-xr-x 0 0 8143-128-3 /WINDOWS/system32/dllcache/c_iscii.dll 60416 ..c. r/rr-xr-xr-x 0 0 8144-128-1 /WINDOWS/system32/dllcache/cabinet.dll 84480 ..c. r/rr-xr-xr-x 0 0 8145-128-1 /WINDOWS/system32/dllcache/cabview.dll 19968 ..c. r/rr-xr-xr-x 0 0 8146-128-1 /WINDOWS/system32/dllcache/cacls.exe 114688 ..c. r/rr-xr-xr-x 0 0 8147-128-1 /WINDOWS/system32/dllcache/calc.exe 385024 ..c. r/rr-xr-xr-x 0 0 8148-128-1 /WINDOWS/system32/dllcache/callcont.dll 50688 ..c. r/rr-xr-xr-x 0 0 8149-128-1 /WINDOWS/system32/dllcache/camocx.dll 46281 ..c. r/rr-xr-xr-x 0 0 815-128-3 /WINDOWS/inf/mdmgatew.inf 54528 ..c. r/rr-xr-xr-x 0 0 8150-128-3 /WINDOWS/system32/dllcache/cap7146.sys 150016 ..c. r/rr-xr-xr-x 0 0 8151-128-1 /WINDOWS/system32/dllcache/capesnpn.dll 359936 ..c. r/rr-xr-xr-x 0 0 8152-128-1 /WINDOWS/system32/dllcache/cards.dll 226304 ..c. r/rr-xr-xr-x 0 0 8153-128-1 /WINDOWS/system32/dllcache/catsrv.dll 85504 ..c. r/rr-xr-xr-x 0 0 8154-128-1 /WINDOWS/system32/dllcache/catsrvps.dll 625664 ..c. r/rr-xr-xr-x 0 0 8155-128-1 /WINDOWS/system32/dllcache/catsrvut.dll 12288 ..c. r/rr-xr-xr-x 0 0 8156-128-1 /WINDOWS/system32/dllcache/cb32.exe 27648 ..c. r/rr-xr-xr-x 0 0 8157-128-1 /WINDOWS/system32/dllcache/ccfgnt.dll 63744 ..c. r/rr-xr-xr-x 0 0 8158-128-1 /WINDOWS/system32/dllcache/cdfs.sys 151040 ..c. r/rr-xr-xr-x 0 0 8159-128-1 /WINDOWS/system32/dllcache/cdfview.dll 23576 ..c. r/rr-xr-xr-x 0 0 816-128-3 /WINDOWS/inf/mdmgcs.inf 66560 ..c. r/rr-xr-xr-x 0 0 8160-128-1 /WINDOWS/system32/dllcache/cdm.dll 15872 ..c. r/rr-xr-xr-x 0 0 8161-128-1 /WINDOWS/system32/dllcache/cdmodem.dll 2091520 ..c. r/rr-xr-xr-x 0 0 8162-128-1 /WINDOWS/system32/dllcache/cdosys.dll 194560 ..c. r/rr-xr-xr-x 0 0 8163-128-1 /WINDOWS/system32/dllcache/certcli.dll 457728 ..c. r/rr-xr-xr-x 0 0 8164-128-1 /WINDOWS/system32/dllcache/certmgr.dll 159232 ..c. r/rr-xr-xr-x 0 0 8165-128-1 /WINDOWS/system32/dllcache/cewmdm.dll 38912 ..c. r/rr-xr-xr-x 0 0 8166-128-1 /WINDOWS/system32/dllcache/cfgbkend.dll 78336 ..c. r/rr-xr-xr-x 0 0 8167-128-3 /WINDOWS/system32/dllcache/chajei.ime 9728 ..c. r/rr-xr-xr-x 0 0 8168-128-3 /WINDOWS/system32/dllcache/change.exe 80384 ..c. r/rr-xr-xr-x 0 0 8169-128-1 /WINDOWS/system32/dllcache/charmap.exe 44714 ..c. r/rr-xr-xr-x 0 0 817-128-3 /WINDOWS/inf/mdmgl001.inf 13312 ..c. r/rr-xr-xr-x 0 0 8170-128-3 /WINDOWS/system32/dllcache/chglogon.exe 15872 ..c. r/rr-xr-xr-x 0 0 8171-128-3 /WINDOWS/system32/dllcache/chgport.exe 14336 ..c. r/rr-xr-xr-x 0 0 8172-128-3 /WINDOWS/system32/dllcache/chgusr.exe 11776 ..c. r/rr-xr-xr-x 0 0 8173-128-1 /WINDOWS/system32/dllcache/chkdsk.exe 11264 ..c. r/rr-xr-xr-x 0 0 8174-128-1 /WINDOWS/system32/dllcache/chkntfs.exe 40515 ..c. r/rr-xr-xr-x 0 0 8175-128-1 /WINDOWS/system32/dllcache/chkr.dll 780885 ..c. r/rr-xr-xr-x 0 0 8176-128-1 /WINDOWS/system32/dllcache/chkrres.dll 42575 ..c. r/rr-xr-xr-x 0 0 8177-128-1 /WINDOWS/system32/dllcache/chkrzm.exe 1677824 ..c. r/rr-xr-xr-x 0 0 8178-128-3 /WINDOWS/system32/dllcache/chsbrkr.dll 838144 ..c. r/rr-xr-xr-x 0 0 8179-128-3 /WINDOWS/system32/dllcache/chtbrkr.dll 49397 ..c. r/rr-xr-xr-x 0 0 818-128-3 /WINDOWS/inf/mdmgl002.inf 97792 ..c. r/rr-xr-xr-x 0 0 8180-128-3 /WINDOWS/system32/dllcache/chtmbx.dll 56320 ..c. r/rr-xr-xr-x 0 0 8181-128-3 /WINDOWS/system32/dllcache/chtskdic.dll 173568 ..c. r/rr-xr-xr-x 0 0 8182-128-3 /WINDOWS/system32/dllcache/chtskf.dll 163328 ..c. r/rr-xr-xr-x 0 0 8183-128-1 /WINDOWS/system32/dllcache/ciadmin.dll 148480 ..c. r/rr-xr-xr-x 0 0 8184-128-1 /WINDOWS/system32/dllcache/cic.dll 8192 ..c. r/rr-xr-xr-x 0 0 8185-128-1 /WINDOWS/system32/dllcache/cidaemon.exe 1358848 ..c. r/rr-xr-xr-x 0 0 8186-128-1 /WINDOWS/system32/dllcache/cimwin32.dll 198656 ..c. r/rr-xr-xr-x 0 0 8187-128-3 /WINDOWS/system32/dllcache/cintime.dll 21504 ..c. r/rr-xr-xr-x 0 0 8188-128-3 /WINDOWS/system32/dllcache/cintlgnt.ime 480256 ..c. r/rr-xr-xr-x 0 0 8189-128-3 /WINDOWS/system32/dllcache/cintsetp.exe 52138 ..c. r/rr-xr-xr-x 0 0 819-128-3 /WINDOWS/inf/mdmgl003.inf 69120 ..c. r/rr-xr-xr-x 0 0 8190-128-1 /WINDOWS/system32/dllcache/ciodm.dll 56832 ..c. r/rr-xr-xr-x 0 0 8191-128-1 /WINDOWS/system32/dllcache/cipher.exe 5632 ..c. r/rr-xr-xr-x 0 0 8192-128-1 /WINDOWS/system32/dllcache/cisvc.exe 7680 ..c. r/rr-xr-xr-x 0 0 8193-128-1 /WINDOWS/system32/dllcache/ckcnv.exe 49536 ..c. r/rr-xr-xr-x 0 0 8194-128-1 /WINDOWS/system32/dllcache/classpnp.sys 10752 ..c. r/rr-xr-xr-x 0 0 8195-128-1 /WINDOWS/system32/dllcache/clb.dll 110592 ..c. r/rr-xr-xr-x 0 0 8196-128-1 /WINDOWS/system32/dllcache/clbcatex.dll 498688 ..c. r/rr-xr-xr-x 0 0 8197-128-1 /WINDOWS/system32/dllcache/clbcatq.dll 64000 ..c. r/rr-xr-xr-x 0 0 8198-128-1 /WINDOWS/system32/dllcache/cleanmgr.exe 102912 ..c. r/rr-xr-xr-x 0 0 8199-128-1 /WINDOWS/system32/dllcache/clipbrd.exe 368 .ac. d/dr-xr-xr-x 0 0 82-144-1 /WINDOWS/security/logs 1571002 ..c. r/rr-xr-xr-x 0 0 820-128-3 /WINDOWS/inf/mdmgl004.inf 33280 ..c. r/rr-xr-xr-x 0 0 8200-128-1 /WINDOWS/system32/dllcache/clipsrv.exe 58368 ..c. r/rr-xr-xr-x 0 0 8201-128-1 /WINDOWS/system32/dllcache/clusapi.dll 15872 ..c. r/rr-xr-xr-x 0 0 8202-128-1 /WINDOWS/system32/dllcache/cmcfg32.dll 389120 ..c. r/rr-xr-xr-x 0 0 8203-128-1 /WINDOWS/system32/dllcache/cmd.exe 45056 ..c. r/rr-xr-xr-x 0 0 8204-128-1 /WINDOWS/system32/dllcache/evtgprov.dll 344064 ..c. r/rr-xr-xr-x 0 0 8205-128-1 /WINDOWS/system32/dllcache/cmdial32.dll 25600 ..c. r/rr-xr-xr-x 0 0 8206-128-1 /WINDOWS/system32/dllcache/cmdl32.exe 39936 ..c. r/rr-xr-xr-x 0 0 8207-128-1 /WINDOWS/system32/dllcache/cmmon32.exe 217160 ..c. r/rr-xr-xr-x 0 0 8208-128-1 /WINDOWS/system32/dllcache/cmnclim.dll 1039955 ..c. r/rr-xr-xr-x 0 0 8209-128-1 /WINDOWS/system32/dllcache/cmnresm.dll 47026 ..c. r/rr-xr-xr-x 0 0 821-128-3 /WINDOWS/inf/mdmgl005.inf 14336 ..c. r/rr-xr-xr-x 0 0 8210-128-1 /WINDOWS/system32/dllcache/cmpbk32.dll 185344 ..c. r/rr-xr-xr-x 0 0 8211-128-1 /WINDOWS/system32/dllcache/cmprops.dll 13312 ..c. r/rr-xr-xr-x 0 0 8212-128-1 /WINDOWS/system32/dllcache/cmsetacl.dll 63488 ..c. r/rr-xr-xr-x 0 0 8213-128-1 /WINDOWS/system32/dllcache/cmstp.exe 39424 ..c. r/rr-xr-xr-x 0 0 8214-128-1 /WINDOWS/system32/dllcache/cmutil.dll 32768 ..c. r/rr-xr-xr-x 0 0 8215-128-1 /WINDOWS/system32/dllcache/cnetcfg.dll 26624 ..c. r/rr-xr-xr-x 0 0 8216-128-1 /WINDOWS/system32/dllcache/cnvfat.dll 60416 ..c. r/rr-xr-xr-x 0 0 8217-128-1 /WINDOWS/system32/dllcache/colbact.dll 28160 ..c. r/rr-xr-xr-x 0 0 8218-128-1 /WINDOWS/system32/dllcache/comaddin.dll 195072 ..c. r/rr-xr-xr-x 0 0 8219-128-1 /WINDOWS/system32/dllcache/comadmin.dll 76255 ..c. r/rr-xr-xr-x 0 0 822-128-3 /WINDOWS/inf/mdmgl006.inf 3584 ..c. r/rr-xr-xr-x 0 0 8220-128-1 /WINDOWS/system32/dllcache/comcat.dll 15872 ..c. r/rr-xr-xr-x 0 0 8221-128-1 /WINDOWS/system32/dllcache/comp.exe 32816 ..c. r/rr-xr-xr-x 0 0 8222-128-1 /WINDOWS/system32/dllcache/commdlg.dll 17408 ..c. r/rr-xr-xr-x 0 0 8223-128-1 /WINDOWS/system32/dllcache/compact.exe 24064 ..c. r/rr-xr-xr-x 0 0 8224-128-3 /WINDOWS/system32/dllcache/compfilt.dll 30160 ..c. r/rr-xr-xr-x 0 0 8225-128-1 /WINDOWS/system32/dllcache/compobj.dll 229376 ..c. r/rr-xr-xr-x 0 0 8226-128-1 /WINDOWS/system32/dllcache/compstui.dll 97792 ..c. r/rr-xr-xr-x 0 0 8227-128-1 /WINDOWS/system32/dllcache/comrepl.dll 9728 ..c. r/rr-xr-xr-x 0 0 8228-128-1 /WINDOWS/system32/dllcache/comrepl.exe 6144 ..c. r/rr-xr-xr-x 0 0 8229-128-1 /WINDOWS/system32/dllcache/comrereg.exe 102685 ..c. r/rr-xr-xr-x 0 0 823-128-3 /WINDOWS/inf/mdmgl007.inf 792064 ..c. r/rr-xr-xr-x 0 0 8230-128-1 /WINDOWS/system32/dllcache/comres.dll 274944 ..c. r/rr-xr-xr-x 0 0 8231-128-1 /WINDOWS/system32/dllcache/comsetup.dll 167424 ..c. r/rr-xr-xr-x 0 0 8232-128-1 /WINDOWS/system32/dllcache/comsnap.dll 1267200 ..c. r/rr-xr-xr-x 0 0 8233-128-1 /WINDOWS/system32/dllcache/comsvcs.dll 539648 ..c. r/rr-xr-xr-x 0 0 8234-128-1 /WINDOWS/system32/dllcache/comuid.dll 1032192 ..c. r/rr-xr-xr-x 0 0 8235-128-1 /WINDOWS/system32/dllcache/conf.exe 45056 ..c. r/rr-xr-xr-x 0 0 8236-128-1 /WINDOWS/system32/dllcache/confmrsl.dll 357888 ..c. r/rr-xr-xr-x 0 0 8237-128-1 /WINDOWS/system32/dllcache/confmsp.dll 27648 ..c. r/rr-xr-xr-x 0 0 8238-128-1 /WINDOWS/system32/dllcache/conime.exe 66560 ..c. r/rr-xr-xr-x 0 0 8239-128-1 /WINDOWS/system32/dllcache/console.dll 40207 ..c. r/rr-xr-xr-x 0 0 824-128-3 /WINDOWS/inf/mdmgl008.inf 8192 ..c. r/rr-xr-xr-x 0 0 8240-128-1 /WINDOWS/system32/dllcache/control.exe 33792 ..c. r/rr-xr-xr-x 0 0 8241-128-3 /WINDOWS/system32/dllcache/controt.dll 13824 ..c. r/rr-xr-xr-x 0 0 8242-128-1 /WINDOWS/system32/dllcache/convert.exe 56320 ..c. r/rr-xr-xr-x 0 0 8243-128-3 /WINDOWS/system32/dllcache/convlog.exe 35328 ..c. r/rr-xr-xr-x 0 0 8244-128-1 /WINDOWS/system32/dllcache/corpol.dll 20480 ..c. r/rr-xr-xr-x 0 0 8245-128-3 /WINDOWS/system32/dllcache/counters.dll 27097 ..c. r/rr-xr-xr-x 0 0 8246-128-1 /WINDOWS/system32/dllcache/country.sys 57399 ..c. r/rr-xr-xr-x 0 0 8247-128-3 /WINDOWS/system32/dllcache/cplexe.exe 18944 ..c. r/rr-xr-xr-x 0 0 8248-128-3 /WINDOWS/system32/dllcache/cprofile.exe 12800 ..c. r/rr-xr-xr-x 0 0 8249-128-1 /WINDOWS/system32/dllcache/credssp.dll 108097 ..c. r/rr-xr-xr-x 0 0 825-128-3 /WINDOWS/inf/mdmgl009.inf 163840 ..c. r/rr-xr-xr-x 0 0 8250-128-1 /WINDOWS/system32/dllcache/credui.dll 149019 ..c. r/rr-xr-xr-x 0 0 8251-128-1 /WINDOWS/system32/dllcache/crtdll.dll 101888 ..c. r/rr-xr-xr-x 0 0 8252-128-1 /WINDOWS/system32/dllcache/cscdll.dll 139264 ..c. r/rr-xr-xr-x 0 0 8253-128-1 /WINDOWS/system32/dllcache/cscript.exe 326656 ..c. r/rr-xr-xr-x 0 0 8254-128-1 /WINDOWS/system32/dllcache/cscui.dll 32256 ..c. r/rr-xr-xr-x 0 0 8255-128-1 /WINDOWS/system32/dllcache/csrsrv.dll 6144 ..c. r/rr-xr-xr-x 0 0 8256-128-1 /WINDOWS/system32/dllcache/csrss.exe 73728 ..c. r/rr-xr-xr-x 0 0 8257-128-1 /WINDOWS/system32/dllcache/csseqchk.dll 15360 ..c. r/rr-xr-xr-x 0 0 8258-128-1 /WINDOWS/system32/dllcache/ctfmon.exe 27200 ..c. r/rr-xr-xr-x 0 0 8259-128-1 /WINDOWS/system32/dllcache/ctl3dv2.dll 55401 ..c. r/rr-xr-xr-x 0 0 826-128-3 /WINDOWS/inf/mdmgl010.inf 8386 ..c. r/rr-xr-xr-x 0 0 8260-128-1 /WINDOWS/system32/dllcache/ctype.nls 33792 ..c. r/rr-xr-xr-x 0 0 8261-128-1 /WINDOWS/system32/dllcache/custsat.dll 1179648 ..c. r/rr-xr-xr-x 0 0 8262-128-1 /WINDOWS/system32/dllcache/d3d8.dll 8192 ..c. r/rr-xr-xr-x 0 0 8263-128-1 /WINDOWS/system32/dllcache/d3d8thk.dll 1689088 ..c. r/rr-xr-xr-x 0 0 8264-128-1 /WINDOWS/system32/dllcache/d3d9.dll 436224 ..c. r/rr-xr-xr-x 0 0 8265-128-1 /WINDOWS/system32/dllcache/d3dim.dll 824320 ..c. r/rr-xr-xr-x 0 0 8266-128-1 /WINDOWS/system32/dllcache/d3dim700.dll 34816 ..c. r/rr-xr-xr-x 0 0 8267-128-1 /WINDOWS/system32/dllcache/d3dpmesh.dll 590336 ..c. r/rr-xr-xr-x 0 0 8268-128-1 /WINDOWS/system32/dllcache/d3dramp.dll 350208 ..c. r/rr-xr-xr-x 0 0 8269-128-1 /WINDOWS/system32/dllcache/d3drm.dll 19420 ..c. r/rr-xr-xr-x 0 0 827-128-3 /WINDOWS/inf/mdmgsm.inf 47616 ..c. r/rr-xr-xr-x 0 0 8270-128-1 /WINDOWS/system32/dllcache/d3dxof.dll 1054208 ..c. r/rr-xr-xr-x 0 0 8271-128-1 /WINDOWS/system32/dllcache/danim.dll 54272 ..c. r/rr-xr-xr-x 0 0 8272-128-1 /WINDOWS/system32/dllcache/dataclen.dll 165376 ..c. r/rr-xr-xr-x 0 0 8273-128-1 /WINDOWS/system32/dllcache/datime.dll 42496 ..c. r/rr-xr-xr-x 0 0 8274-128-3 /WINDOWS/system32/dllcache/davcdata.exe 25088 ..c. r/rr-xr-xr-x 0 0 8275-128-1 /WINDOWS/system32/dllcache/davclnt.dll 153088 ..c. r/rr-xr-xr-x 0 0 8276-128-1 /WINDOWS/system32/dllcache/daxctle.ocx 78848 ..c. r/rr-xr-xr-x 0 0 8277-128-3 /WINDOWS/system32/dllcache/dayi.ime 847872 ..c. r/rr-xr-xr-x 0 0 8278-128-1 /WINDOWS/system32/dllcache/dbgeng.dll 640000 ..c. r/rr-xr-xr-x 0 0 8279-128-1 /WINDOWS/system32/dllcache/dbghelp.dll 2507 ..c. r/rr-xr-xr-x 0 0 828-128-3 /WINDOWS/inf/mdmhaeu.inf 110592 ..c. r/rr-xr-xr-x 0 0 8280-128-1 /WINDOWS/system32/dllcache/dbnetlib.dll 40960 ..c. r/rr-xr-xr-x 0 0 8281-128-1 /WINDOWS/system32/dllcache/dcap32.dll 8704 ..c. r/rr-xr-xr-x 0 0 8282-128-1 /WINDOWS/system32/dllcache/dciman32.dll 6144 ..c. r/rr-xr-xr-x 0 0 8283-128-1 /WINDOWS/system32/dllcache/dcomcnfg.exe 39424 ..c. r/rr-xr-xr-x 0 0 8284-128-1 /WINDOWS/system32/dllcache/ddeml.dll 30208 ..c. r/rr-xr-xr-x 0 0 8285-128-1 /WINDOWS/system32/dllcache/ddeshare.exe 279552 ..c. r/rr-xr-xr-x 0 0 8286-128-1 /WINDOWS/system32/dllcache/ddraw.dll 27136 ..c. r/rr-xr-xr-x 0 0 8287-128-1 /WINDOWS/system32/dllcache/ddrawex.dll 20634 ..c. r/rr-xr-xr-x 0 0 8288-128-1 /WINDOWS/system32/dllcache/debug.exe 25088 ..c. r/rr-xr-xr-x 0 0 8289-128-1 /WINDOWS/system32/dllcache/defrag.exe 33270 ..c. r/rr-xr-xr-x 0 0 829-128-3 /WINDOWS/inf/mdmhandy.inf 135168 ..c. r/rr-xr-xr-x 0 0 8290-128-1 /WINDOWS/system32/dllcache/desk.cpl 16384 ..c. r/rr-xr-xr-x 0 0 8291-128-1 /WINDOWS/system32/dllcache/deskadp.dll 16896 ..c. r/rr-xr-xr-x 0 0 8292-128-1 /WINDOWS/system32/dllcache/deskmon.dll 18432 ..c. r/rr-xr-xr-x 0 0 8293-128-1 /WINDOWS/system32/dllcache/deskperf.dll 59904 ..c. r/rr-xr-xr-x 0 0 8294-128-1 /WINDOWS/system32/dllcache/devenum.dll 282624 ..c. r/rr-xr-xr-x 0 0 8295-128-1 /WINDOWS/system32/dllcache/devmgr.dll 82944 ..c. r/rr-xr-xr-x 0 0 8296-128-1 /WINDOWS/system32/dllcache/dfrgfat.exe 105472 ..c. r/rr-xr-xr-x 0 0 8297-128-1 /WINDOWS/system32/dllcache/dfrgntfs.exe 51200 ..c. r/rr-xr-xr-x 0 0 8298-128-1 /WINDOWS/system32/dllcache/dfrgres.dll 39424 ..c. r/rr-xr-xr-x 0 0 8299-128-1 /WINDOWS/system32/dllcache/dfrgsnap.dll 568 .a.. d/dr-xr-xr-x 0 0 83-144-1 /WINDOWS/system32/icsxml 50945 ..c. r/rr-xr-xr-x 0 0 830-128-3 /WINDOWS/inf/mdmhay2.inf 124416 ..c. r/rr-xr-xr-x 0 0 8300-128-1 /WINDOWS/system32/dllcache/dfrgui.dll 28672 ..c. r/rr-xr-xr-x 0 0 8301-128-1 /WINDOWS/system32/dllcache/dfsshlex.dll 111104 ..c. r/rr-xr-xr-x 0 0 8302-128-1 /WINDOWS/system32/dllcache/dgnet.dll 176157 ..c. r/rr-xr-xr-x 0 0 8303-128-1 /WINDOWS/system32/dllcache/dgrpsetu.dll 85020 ..c. r/rr-xr-xr-x 0 0 8304-128-1 /WINDOWS/system32/dllcache/dgsetup.dll 126976 ..c. r/rr-xr-xr-x 0 0 8305-128-1 /WINDOWS/system32/dllcache/dhcpcsvc.dll 379904 ..c. r/rr-xr-xr-x 0 0 8306-128-1 /WINDOWS/system32/dllcache/dhcpmon.dll 48640 ..c. r/rr-xr-xr-x 0 0 8307-128-1 /WINDOWS/system32/dllcache/dhcpqec.dll 74240 ..c. r/rr-xr-xr-x 0 0 8308-128-1 /WINDOWS/system32/dllcache/dhcpsapi.dll 128512 ..c. r/rr-xr-xr-x 0 0 8309-128-1 /WINDOWS/system32/dllcache/dhtmled.ocx 72863 ..c. r/rr-xr-xr-x 0 0 831-128-3 /WINDOWS/inf/mdmhayes.inf 394240 ..c. r/rr-xr-xr-x 0 0 8310-128-1 /WINDOWS/system32/dllcache/diactfrm.dll 539136 ..c. r/rr-xr-xr-x 0 0 8311-128-1 /WINDOWS/system32/dllcache/dialer.exe 87040 ..c. r/rr-xr-xr-x 0 0 8312-128-1 /WINDOWS/system32/dllcache/diantz.exe 68608 ..c. r/rr-xr-xr-x 0 0 8313-128-1 /WINDOWS/system32/dllcache/digest.dll 44032 ..c. r/rr-xr-xr-x 0 0 8314-128-1 /WINDOWS/system32/dllcache/dimap.dll 158720 ..c. r/rr-xr-xr-x 0 0 8315-128-1 /WINDOWS/system32/dllcache/dinput.dll 181760 ..c. r/rr-xr-xr-x 0 0 8316-128-1 /WINDOWS/system32/dllcache/dinput8.dll 86528 ..c. r/rr-xr-xr-x 0 0 8317-128-1 /WINDOWS/system32/dllcache/directdb.dll 1504256 ..c. r/rr-xr-xr-x 0 0 8318-128-1 /WINDOWS/system32/dllcache/diskcopy.dll 14208 ..c. r/rr-xr-xr-x 0 0 8319-128-1 /WINDOWS/system32/dllcache/diskdump.sys 20236 ..c. r/rr-xr-xr-x 0 0 832-128-3 /WINDOWS/inf/mdminfot.inf 163840 ..c. r/rr-xr-xr-x 0 0 8320-128-1 /WINDOWS/system32/dllcache/diskpart.exe 17920 ..c. r/rr-xr-xr-x 0 0 8321-128-1 /WINDOWS/system32/dllcache/diskperf.exe 5120 ..c. r/rr-xr-xr-x 0 0 8322-128-1 /WINDOWS/system32/dllcache/dllhost.exe 4608 ..c. r/rr-xr-xr-x 0 0 8323-128-1 /WINDOWS/system32/dllcache/dllhst3g.exe 224768 ..c. r/rr-xr-xr-x 0 0 8324-128-1 /WINDOWS/system32/dllcache/dmadmin.exe 28672 ..c. r/rr-xr-xr-x 0 0 8325-128-1 /WINDOWS/system32/dllcache/dmband.dll 799744 ..c. r/rr-xr-xr-x 0 0 8326-128-1 /WINDOWS/system32/dllcache/dmboot.sys 61440 ..c. r/rr-xr-xr-x 0 0 8327-128-1 /WINDOWS/system32/dllcache/dmcompos.dll 330752 ..c. r/rr-xr-xr-x 0 0 8328-128-1 /WINDOWS/system32/dllcache/dmconfig.dll 285184 ..c. r/rr-xr-xr-x 0 0 8329-128-1 /WINDOWS/system32/dllcache/dmdlgs.dll 15157 ..c. r/rr-xr-xr-x 0 0 833-128-3 /WINDOWS/inf/mdmintel.inf 200704 ..c. r/rr-xr-xr-x 0 0 8330-128-1 /WINDOWS/system32/dllcache/dmdskmgr.dll 118784 ..c. r/rr-xr-xr-x 0 0 8331-128-1 /WINDOWS/system32/dllcache/dmdskres.dll 181248 ..c. r/rr-xr-xr-x 0 0 8332-128-1 /WINDOWS/system32/dllcache/dmime.dll 18432 ..c. r/rr-xr-xr-x 0 0 8333-128-1 /WINDOWS/system32/dllcache/dmintf.dll 153344 ..c. r/rr-xr-xr-x 0 0 8334-128-1 /WINDOWS/system32/dllcache/dmio.sys 5888 ..c. r/rr-xr-xr-x 0 0 8335-128-1 /WINDOWS/system32/dllcache/dmload.sys 35840 ..c. r/rr-xr-xr-x 0 0 8336-128-1 /WINDOWS/system32/dllcache/dmloader.dll 19456 ..c. r/rr-xr-xr-x 0 0 8337-128-1 /WINDOWS/system32/dllcache/dmocx.dll 15872 ..c. r/rr-xr-xr-x 0 0 8338-128-1 /WINDOWS/system32/dllcache/dmremote.exe 82432 ..c. r/rr-xr-xr-x 0 0 8339-128-1 /WINDOWS/system32/dllcache/dmscript.dll 17801 ..c. r/rr-xr-xr-x 0 0 834-128-3 /WINDOWS/inf/mdmiodat.inf 23552 ..c. r/rr-xr-xr-x 0 0 8340-128-1 /WINDOWS/system32/dllcache/dmserver.dll 105984 ..c. r/rr-xr-xr-x 0 0 8341-128-1 /WINDOWS/system32/dllcache/dmstyle.dll 103424 ..c. r/rr-xr-xr-x 0 0 8342-128-1 /WINDOWS/system32/dllcache/dmsynth.dll 104448 ..c. r/rr-xr-xr-x 0 0 8343-128-1 /WINDOWS/system32/dllcache/dmusic.dll 61440 ..c. r/rr-xr-xr-x 0 0 8344-128-1 /WINDOWS/system32/dllcache/dmview.ocx 147968 ..c. r/rr-xr-xr-x 0 0 8345-128-1 /WINDOWS/system32/dllcache/dnsapi.dll 45568 ..c. r/rr-xr-xr-x 0 0 8346-128-1 /WINDOWS/system32/dllcache/dnsrslvr.dll 46080 ..c. r/rr-xr-xr-x 0 0 8347-128-1 /WINDOWS/system32/dllcache/docprop.dll 48128 ..c. r/rr-xr-xr-x 0 0 8348-128-1 /WINDOWS/system32/dllcache/docprop2.dll 10752 ..c. r/rr-xr-xr-x 0 0 8349-128-1 /WINDOWS/system32/dllcache/doskey.exe 44961 ..c. r/rr-xr-xr-x 0 0 835-128-3 /WINDOWS/inf/mdmisdn.inf 53840 ..c. r/rr-xr-xr-x 0 0 8350-128-1 /WINDOWS/system32/dllcache/dosx.exe 26112 ..c. r/rr-xr-xr-x 0 0 8351-128-1 /WINDOWS/system32/dllcache/dot3api.dll 57856 ..c. r/rr-xr-xr-x 0 0 8352-128-1 /WINDOWS/system32/dllcache/dot3cfg.dll 9216 ..c. r/rr-xr-xr-x 0 0 8353-128-1 /WINDOWS/system32/dllcache/dot3dlg.dll 39936 ..c. r/rr-xr-xr-x 0 0 8354-128-1 /WINDOWS/system32/dllcache/dot3clnt.dll 56320 ..c. r/rr-xr-xr-x 0 0 8355-128-1 /WINDOWS/system32/dllcache/dot3msm.dll 132096 ..c. r/rr-xr-xr-x 0 0 8356-128-1 /WINDOWS/system32/dllcache/dot3svc.dll 650752 ..c. r/rr-xr-xr-x 0 0 8357-128-1 /WINDOWS/system32/dllcache/dot3ui.dll 102912 ..c. r/rr-xr-xr-x 0 0 8358-128-1 /WINDOWS/system32/dllcache/dpcdll.dll 33040 ..c. r/rr-xr-xr-x 0 0 8359-128-1 /WINDOWS/system32/dllcache/dplay.dll 14269 ..c. r/rr-xr-xr-x 0 0 836-128-3 /WINDOWS/inf/MDMJF56E.INF 29696 ..c. r/rr-xr-xr-x 0 0 8360-128-1 /WINDOWS/system32/dllcache/dplaysvr.exe 229888 ..c. r/rr-xr-xr-x 0 0 8361-128-1 /WINDOWS/system32/dllcache/dplayx.dll 23552 ..c. r/rr-xr-xr-x 0 0 8362-128-1 /WINDOWS/system32/dllcache/dpmodemx.dll 3072 ..c. r/rr-xr-xr-x 0 0 8363-128-1 /WINDOWS/system32/dllcache/dpnaddr.dll 375296 ..c. r/rr-xr-xr-x 0 0 8364-128-1 /WINDOWS/system32/dllcache/dpnet.dll 35328 ..c. r/rr-xr-xr-x 0 0 8365-128-1 /WINDOWS/system32/dllcache/dpnhpast.dll 60928 ..c. r/rr-xr-xr-x 0 0 8366-128-1 /WINDOWS/system32/dllcache/dpnhupnp.dll 3072 ..c. r/rr-xr-xr-x 0 0 8367-128-1 /WINDOWS/system32/dllcache/dpnlobby.dll 62464 ..c. r/rr-xr-xr-x 0 0 8368-128-1 /WINDOWS/system32/dllcache/dpnmodem.dll 17920 ..c. r/rr-xr-xr-x 0 0 8369-128-1 /WINDOWS/system32/dllcache/dpnsvr.exe 4466 ..c. r/rr-xr-xr-x 0 0 837-128-3 /WINDOWS/inf/mdmke.inf 61952 ..c. r/rr-xr-xr-x 0 0 8370-128-1 /WINDOWS/system32/dllcache/dpnwsock.dll 53520 ..c. r/rr-xr-xr-x 0 0 8371-128-1 /WINDOWS/system32/dllcache/dpserial.dll 21504 ..c. r/rr-xr-xr-x 0 0 8372-128-1 /WINDOWS/system32/dllcache/dpvacm.dll 212480 ..c. r/rr-xr-xr-x 0 0 8373-128-1 /WINDOWS/system32/dllcache/dpvoice.dll 83456 ..c. r/rr-xr-xr-x 0 0 8374-128-1 /WINDOWS/system32/dllcache/dpvsetup.exe 116736 ..c. r/rr-xr-xr-x 0 0 8375-128-1 /WINDOWS/system32/dllcache/dpvvox.dll 42768 ..c. r/rr-xr-xr-x 0 0 8376-128-1 /WINDOWS/system32/dllcache/dpwsock.dll 57344 ..c. r/rr-xr-xr-x 0 0 8377-128-1 /WINDOWS/system32/dllcache/dpwsockx.dll 62976 ..c. r/rr-xr-xr-x 0 0 8378-128-1 /WINDOWS/system32/dllcache/drvqry.exe 695808 ..c. r/rr-xr-xr-x 0 0 8379-128-1 /WINDOWS/system32/dllcache/drmv2clt.dll 5711 ..c. r/rr-xr-xr-x 0 0 838-128-3 /WINDOWS/inf/mdmkortx.inf 14336 ..c. r/rr-xr-xr-x 0 0 8380-128-1 /WINDOWS/system32/dllcache/drprov.dll 28112 ..c. r/rr-xr-xr-x 0 0 8381-128-1 /WINDOWS/system32/dllcache/drwatson.exe 45568 ..c. r/rr-xr-xr-x 0 0 8382-128-1 /WINDOWS/system32/dllcache/drwtsn32.exe 4656 ..c. r/rr-xr-xr-x 0 0 8383-128-1 /WINDOWS/system32/dllcache/ds16gt.dll 62976 ..c. r/rr-xr-xr-x 0 0 8384-128-1 /WINDOWS/system32/dllcache/dsauth.dll 181248 ..c. r/rr-xr-xr-x 0 0 8385-128-1 /WINDOWS/system32/dllcache/dsdmo.dll 71680 ..c. r/rr-xr-xr-x 0 0 8386-128-1 /WINDOWS/system32/dllcache/dsdmoprp.dll 92672 ..c. r/rr-xr-xr-x 0 0 8387-128-1 /WINDOWS/system32/dllcache/dskquota.dll 155648 ..c. r/rr-xr-xr-x 0 0 8388-128-1 /WINDOWS/system32/dllcache/dskquoui.dll 367616 ..c. r/rr-xr-xr-x 0 0 8389-128-1 /WINDOWS/system32/dllcache/dsound.dll 10336 ..c. r/rr-xr-xr-x 0 0 839-128-3 /WINDOWS/inf/mdmlasat.inf 1293824 ..c. r/rr-xr-xr-x 0 0 8390-128-1 /WINDOWS/system32/dllcache/dsound3d.dll 142848 ..c. r/rr-xr-xr-x 0 0 8391-128-1 /WINDOWS/system32/dllcache/dsprop.dll 120320 ..c. r/rr-xr-xr-x 0 0 8392-128-1 /WINDOWS/system32/dllcache/dsprov.dll 4096 ..c. r/rr-xr-xr-x 0 0 8393-128-1 /WINDOWS/system32/dllcache/dsprpres.dll 239104 ..c. r/rr-xr-xr-x 0 0 8394-128-1 /WINDOWS/system32/dllcache/dsquery.dll 51200 ..c. r/rr-xr-xr-x 0 0 8395-128-1 /WINDOWS/system32/dllcache/dssec.dll 113152 ..c. r/rr-xr-xr-x 0 0 8396-128-1 /WINDOWS/system32/dllcache/dsuiext.dll 19456 ..c. r/rr-xr-xr-x 0 0 8397-128-1 /WINDOWS/system32/dllcache/dswave.dll 10752 ..c. r/rr-xr-xr-x 0 0 8398-128-1 /WINDOWS/system32/dllcache/dumprep.exe 304128 ..c. r/rr-xr-xr-x 0 0 8399-128-1 /WINDOWS/system32/dllcache/duser.dll 23090 ..c. r/rr-xr-xr-x 0 0 840-128-3 /WINDOWS/inf/mdmlasno.inf 17920 ..c. r/rr-xr-xr-x 0 0 8400-128-1 /WINDOWS/system32/dllcache/dvdupgrd.exe 55632 ..c. r/rr-xr-xr-x 0 0 8401-128-1 /WINDOWS/system32/dllcache/dwil1033.dll 180224 ..c. r/rr-xr-xr-x 0 0 8402-128-1 /WINDOWS/system32/dllcache/dwwin.exe 619008 ..c. r/rr-xr-xr-x 0 0 8403-128-1 /WINDOWS/system32/dllcache/dx7vb.dll 1227264 ..c. r/rr-xr-xr-x 0 0 8404-128-1 /WINDOWS/system32/dllcache/dx8vb.dll 10496 ..c. r/rr-xr-xr-x 0 0 8405-128-1 /WINDOWS/system32/dllcache/dxapi.sys 1298432 ..c. r/rr-xr-xr-x 0 0 8406-128-1 /WINDOWS/system32/dllcache/dxdiag.exe 2113536 ..c. r/rr-xr-xr-x 0 0 8407-128-1 /WINDOWS/system32/dllcache/dxdiagn.dll 3328 ..c. r/rr-xr-xr-x 0 0 8408-128-1 /WINDOWS/system32/dllcache/dxgthk.sys 357888 ..c. r/rr-xr-xr-x 0 0 8409-128-1 /WINDOWS/system32/dllcache/dxtmsft.dll 22424 ..c. r/rr-xr-xr-x 0 0 841-128-3 /WINDOWS/inf/mdmlucnt.inf 205312 ..c. r/rr-xr-xr-x 0 0 8410-128-1 /WINDOWS/system32/dllcache/dxtrans.dll 30720 ..c. r/rr-xr-xr-x 0 0 8411-128-1 /WINDOWS/system32/dllcache/eapolqec.dll 184832 ..c. r/rr-xr-xr-x 0 0 8412-128-1 /WINDOWS/system32/dllcache/eapp3hst.dll 126976 ..c. r/rr-xr-xr-x 0 0 8413-128-1 /WINDOWS/system32/dllcache/eappcfg.dll 94208 ..c. r/rr-xr-xr-x 0 0 8414-128-1 /WINDOWS/system32/dllcache/eappgnui.dll 180224 ..c. r/rr-xr-xr-x 0 0 8415-128-1 /WINDOWS/system32/dllcache/eapphost.dll 40960 ..c. r/rr-xr-xr-x 0 0 8416-128-1 /WINDOWS/system32/dllcache/eappprxy.dll 59392 ..c. r/rr-xr-xr-x 0 0 8417-128-1 /WINDOWS/system32/dllcache/eapqec.dll 33792 ..c. r/rr-xr-xr-x 0 0 8418-128-1 /WINDOWS/system32/dllcache/eapsvc.dll 514587 ..c. r/rr-xr-xr-x 0 0 8419-128-3 /WINDOWS/system32/dllcache/edb500.dll 9494 ..c. r/rr-xr-xr-x 0 0 842-128-3 /WINDOWS/inf/mdmmc288.inf 12642 ..c. r/rr-xr-xr-x 0 0 8420-128-1 /WINDOWS/system32/dllcache/edlin.exe 26624 ..c. r/rr-xr-xr-x 0 0 8421-128-1 /WINDOWS/system32/dllcache/efsadu.dll 183296 ..c. r/rr-xr-xr-x 0 0 8422-128-1 /WINDOWS/system32/dllcache/els.dll 20480 ..c. r/rr-xr-xr-x 0 0 8423-128-1 /WINDOWS/system32/dllcache/encapi.dll 186880 ..c. r/rr-xr-xr-x 0 0 8424-128-1 /WINDOWS/system32/dllcache/encdec.dll 103424 ..c. r/rr-xr-xr-x 0 0 8425-128-1 /WINDOWS/system32/dllcache/eqnclass.dll 23040 ..c. r/rr-xr-xr-x 0 0 8426-128-1 /WINDOWS/system32/dllcache/ersvc.dll 246272 ..c. r/rr-xr-xr-x 0 0 8427-128-1 /WINDOWS/system32/dllcache/es.dll 1082368 ..c. r/rr-xr-xr-x 0 0 8428-128-1 /WINDOWS/system32/dllcache/esent.dll 1114896 ..c. r/rr-xr-xr-x 0 0 8429-128-1 /WINDOWS/system32/dllcache/esent97.dll 5103 ..c. r/rr-xr-xr-x 0 0 843-128-3 /WINDOWS/inf/mdmmcd.inf 17408 ..c. r/rr-xr-xr-x 0 0 8430-128-1 /WINDOWS/system32/dllcache/esentprf.dll 39424 ..c. r/rr-xr-xr-x 0 0 8431-128-1 /WINDOWS/system32/dllcache/esentutl.exe 247808 ..c. r/rr-xr-xr-x 0 0 8432-128-1 /WINDOWS/system32/dllcache/esscli.dll 31744 ..c. r/rr-xr-xr-x 0 0 8433-128-3 /WINDOWS/system32/dllcache/esucmd.dll 57856 ..c. r/rr-xr-xr-x 0 0 8434-128-3 /WINDOWS/system32/dllcache/esuimgd.dll 45056 ..c. r/rr-xr-xr-x 0 0 8435-128-3 /WINDOWS/system32/dllcache/esunid.dll 25856 ..c. r/rr-xr-xr-x 0 0 8436-128-3 /WINDOWS/system32/dllcache/et4000.sys 193024 ..c. r/rr-xr-xr-x 0 0 8437-128-1 /WINDOWS/system32/dllcache/eudcedit.exe 33280 ..c. r/rr-xr-xr-x 0 0 8438-128-1 /WINDOWS/system32/dllcache/eventcls.dll 50688 ..c. r/rr-xr-xr-x 0 0 8439-128-1 /WINDOWS/system32/dllcache/evcreate.exe 46074 ..c. r/rr-xr-xr-x 0 0 844-128-3 /WINDOWS/inf/mdmmcom.inf 56320 ..c. r/rr-xr-xr-x 0 0 8440-128-1 /WINDOWS/system32/dllcache/eventlog.dll 97965 ..c. r/rr-xr-xr-x 0 0 8441-128-1 /WINDOWS/system32/dllcache/evtquery.vbs 82944 ..c. r/rr-xr-xr-x 0 0 8442-128-1 /WINDOWS/system32/dllcache/evtrig.exe 8704 ..c. r/rr-xr-xr-x 0 0 8443-128-1 /WINDOWS/system32/dllcache/eventvwr.exe 101888 ..c. r/rr-xr-xr-x 0 0 8444-128-3 /WINDOWS/system32/dllcache/evntagnt.dll 24064 ..c. r/rr-xr-xr-x 0 0 8445-128-3 /WINDOWS/system32/dllcache/evntcmd.exe 21504 ..c. r/rr-xr-xr-x 0 0 8446-128-1 /WINDOWS/system32/dllcache/evntrprv.dll 92160 ..c. r/rr-xr-xr-x 0 0 8447-128-3 /WINDOWS/system32/dllcache/evntwin.exe 8424 ..c. r/rr-xr-xr-x 0 0 8448-128-1 /WINDOWS/system32/dllcache/exe2bin.exe 15872 ..c. r/rr-xr-xr-x 0 0 8449-128-1 /WINDOWS/system32/dllcache/expand.exe 36375 ..c. r/rr-xr-xr-x 0 0 845-128-3 /WINDOWS/inf/mdmmct.inf 1033728 ..c. r/rr-xr-xr-x 0 0 8450-128-1 /WINDOWS/system32/dllcache/explorer.exe 14336 ..c. r/rr-xr-xr-x 0 0 8451-128-3 /WINDOWS/system32/dllcache/exstrace.dll 55808 ..c. r/rr-xr-xr-x 0 0 8452-128-1 /WINDOWS/system32/dllcache/extmgr.dll 24064 ..c. r/rr-xr-xr-x 0 0 8453-128-1 /WINDOWS/system32/dllcache/extrac32.exe 125952 ..c. r/rr-xr-xr-x 0 0 8454-128-1 /WINDOWS/system32/dllcache/exts.dll 7168 ..c. r/rr-xr-xr-x 0 0 8455-128-3 /WINDOWS/system32/dllcache/f3ahvoas.dll 882 ..c. r/rr-xr-xr-x 0 0 8456-128-1 /WINDOWS/system32/dllcache/fastopen.exe 472064 ..c. r/rr-xr-xr-x 0 0 8457-128-1 /WINDOWS/system32/dllcache/fastprox.dll 80384 ..c. r/rr-xr-xr-x 0 0 8458-128-1 /WINDOWS/system32/dllcache/faultrep.dll 14848 ..c. r/rr-xr-xr-x 0 0 8459-128-1 /WINDOWS/system32/dllcache/fc.exe 8451 ..c. r/rr-xr-xr-x 0 0 846-128-3 /WINDOWS/inf/mdmmega.inf 124928 ..c. r/rr-xr-xr-x 0 0 8460-128-1 /WINDOWS/system32/dllcache/fde.dll 43520 ..c. r/rr-xr-xr-x 0 0 8461-128-3 /WINDOWS/system32/dllcache/EXCH_fcachdll.dll 73728 ..c. r/rr-xr-xr-x 0 0 8462-128-1 /WINDOWS/system32/dllcache/fdeploy.dll 21504 ..c. r/rr-xr-xr-x 0 0 8463-128-1 /WINDOWS/system32/dllcache/feclient.dll 337920 ..c. r/rr-xr-xr-x 0 0 8464-128-1 /WINDOWS/system32/dllcache/filemgmt.dll 9216 ..c. r/rr-xr-xr-x 0 0 8465-128-1 /WINDOWS/system32/dllcache/find.exe 27136 ..c. r/rr-xr-xr-x 0 0 8466-128-1 /WINDOWS/system32/dllcache/findstr.exe 9216 ..c. r/rr-xr-xr-x 0 0 8467-128-1 /WINDOWS/system32/dllcache/finger.exe 44544 ..c. r/rr-xr-xr-x 0 0 8468-128-1 /WINDOWS/system32/dllcache/fips.sys 80896 ..c. r/rr-xr-xr-x 0 0 8469-128-1 /WINDOWS/system32/dllcache/firewall.cpl 71827 ..c. r/rr-xr-xr-x 0 0 847-128-3 /WINDOWS/inf/mdmmetri.inf 3072 ..c. r/rr-xr-xr-x 0 0 8470-128-1 /WINDOWS/system32/dllcache/fixmapi.exe 14848 ..c. r/rr-xr-xr-x 0 0 8471-128-3 /WINDOWS/system32/dllcache/flattemp.exe 87552 ..c. r/rr-xr-xr-x 0 0 8472-128-1 /WINDOWS/system32/dllcache/fldrclnr.dll 16896 ..c. r/rr-xr-xr-x 0 0 8473-128-1 /WINDOWS/system32/dllcache/fltlib.dll 23040 ..c. r/rr-xr-xr-x 0 0 8474-128-1 /WINDOWS/system32/dllcache/fltmc.exe 129792 ..c. r/rr-xr-xr-x 0 0 8475-128-1 /WINDOWS/system32/dllcache/fltmgr.sys 16384 ..c. r/rr-xr-xr-x 0 0 8476-128-1 /WINDOWS/system32/dllcache/fmifs.dll 382976 ..c. r/rr-xr-xr-x 0 0 8477-128-1 /WINDOWS/system32/dllcache/fontext.dll 80896 ..c. r/rr-xr-xr-x 0 0 8478-128-1 /WINDOWS/system32/dllcache/fontsub.dll 20992 ..c. r/rr-xr-xr-x 0 0 8479-128-1 /WINDOWS/system32/dllcache/fontview.exe 48614 ..c. r/rr-xr-xr-x 0 0 848-128-3 /WINDOWS/inf/mdmmhrtz.inf 7680 ..c. r/rr-xr-xr-x 0 0 8480-128-1 /WINDOWS/system32/dllcache/forcedos.exe 32828 ..c. r/rr-xr-xr-x 0 0 8481-128-1 /WINDOWS/system32/dllcache/fp40ext.dll 9344 ..c. r/rr-xr-xr-x 0 0 8482-128-1 /WINDOWS/system32/dllcache/framebuf.dll 15098 ..c. r/rr-xr-xr-x 0 0 8483-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/C40C5665D2C06F965D1A6A40B84[1].jpg 24632 ..c. r/rr-xr-xr-x 0 0 8484-128-3 /WINDOWS/system32/dllcache/fpadmcgi.exe 20541 ..c. r/rr-xr-xr-x 0 0 8485-128-3 /WINDOWS/system32/dllcache/fpadmdll.dll 94208 ..c. r/rr-xr-xr-x 0 0 8486-128-3 /WINDOWS/system32/dllcache/fpencode.dll 185344 ..c. r/rr-xr-xr-x 0 0 8487-128-1 /WINDOWS/system32/dllcache/framedyn.dll 55296 ..c. r/rr-xr-xr-x 0 0 8488-128-1 /WINDOWS/system32/dllcache/freecell.exe 7936 ..c. r/rr-xr-xr-x 0 0 8489-128-1 /WINDOWS/system32/dllcache/fs_rec.sys 57835 ..c. r/rr-xr-xr-x 0 0 849-128-3 /WINDOWS/inf/mdmmhza.inf 6144 ..c. r/rr-xr-xr-x 0 0 8490-128-1 /WINDOWS/system32/dllcache/fsconins.dll 81408 ..c. r/rr-xr-xr-x 0 0 8491-128-1 /WINDOWS/system32/dllcache/fsusd.dll 56320 ..c. r/rr-xr-xr-x 0 0 8492-128-1 /WINDOWS/system32/dllcache/fsutil.exe 6144 ..c. r/rr-xr-xr-x 0 0 8493-128-3 /WINDOWS/system32/dllcache/ftlx041e.dll 42496 ..c. r/rr-xr-xr-x 0 0 8494-128-1 /WINDOWS/system32/dllcache/ftp.exe 7680 ..c. r/rr-xr-xr-x 0 0 8495-128-3 /WINDOWS/system32/dllcache/ftpctrs2.dll 6144 ..c. r/rr-xr-xr-x 0 0 8496-128-3 /WINDOWS/system32/dllcache/ftpmib.dll 125952 ..c. r/rr-xr-xr-x 0 0 8497-128-3 /WINDOWS/system32/dllcache/ftpsv251.dll 176128 ..c. r/rr-xr-xr-x 0 0 8498-128-1 /WINDOWS/system32/dllcache/ftsrch.dll 60416 ..c. r/rr-xr-xr-x 0 0 8499-128-1 /WINDOWS/system32/dllcache/fwcfg.dll 160 .a.. d/dr-xr-xr-x 0 0 85-144-1 /WINDOWS/system32/mui/0009 127277 ..c. r/rr-xr-xr-x 0 0 850-128-3 /WINDOWS/inf/mdmmhzel.inf 53248 ..c. r/rr-xr-xr-x 0 0 8500-128-1 /WINDOWS/system32/dllcache/fwdprov.dll 451584 ..c. r/rr-xr-xr-x 0 0 8501-128-3 /WINDOWS/system32/dllcache/fxsapi.dll 111104 ..c. r/rr-xr-xr-x 0 0 8502-128-3 /WINDOWS/system32/dllcache/fxscfgwz.dll 142848 ..c. r/rr-xr-xr-x 0 0 8503-128-3 /WINDOWS/system32/dllcache/fxsclnt.exe 132608 ..c. r/rr-xr-xr-x 0 0 8504-128-3 /WINDOWS/system32/dllcache/fxsclntr.dll 72192 ..c. r/rr-xr-xr-x 0 0 8505-128-3 /WINDOWS/system32/dllcache/fxscom.dll 285184 ..c. r/rr-xr-xr-x 0 0 8506-128-3 /WINDOWS/system32/dllcache/fxscomex.dll 229376 ..c. r/rr-xr-xr-x 0 0 8507-128-3 /WINDOWS/system32/dllcache/fxscover.exe 26624 ..c. r/rr-xr-xr-x 0 0 8508-128-3 /WINDOWS/system32/dllcache/fxsdrv.dll 55296 ..c. r/rr-xr-xr-x 0 0 8509-128-3 /WINDOWS/system32/dllcache/fxsevent.dll 56849 ..c. r/rr-xr-xr-x 0 0 851-128-3 /WINDOWS/inf/mdmmhzk1.inf 23552 ..c. r/rr-xr-xr-x 0 0 8510-128-3 /WINDOWS/system32/dllcache/fxsext32.dll 23552 ..c. r/rr-xr-xr-x 0 0 8511-128-3 /WINDOWS/system32/dllcache/fxsmon.dll 132608 ..c. r/rr-xr-xr-x 0 0 8512-128-1 /WINDOWS/system32/dllcache/fxsocm.dll 8704 ..c. r/rr-xr-xr-x 0 0 8513-128-3 /WINDOWS/system32/dllcache/fxsperf.dll 6656 ..c. r/rr-xr-xr-x 0 0 8514-128-3 /WINDOWS/system32/dllcache/fxsres.dll 31744 ..c. r/rr-xr-xr-x 0 0 8515-128-3 /WINDOWS/system32/dllcache/fxsroute.dll 11264 ..c. r/rr-xr-xr-x 0 0 8516-128-3 /WINDOWS/system32/dllcache/fxssend.exe 562176 ..c. r/rr-xr-xr-x 0 0 8517-128-3 /WINDOWS/system32/dllcache/fxsst.dll 267776 ..c. r/rr-xr-xr-x 0 0 8518-128-3 /WINDOWS/system32/dllcache/fxssvc.exe 246272 ..c. r/rr-xr-xr-x 0 0 8519-128-3 /WINDOWS/system32/dllcache/fxst30.dll 4410 ..c. r/rr-xr-xr-x 0 0 852-128-3 /WINDOWS/inf/mdmminij.inf 397312 ..c. r/rr-xr-xr-x 0 0 8520-128-3 /WINDOWS/system32/dllcache/fxstiff.dll 154112 ..c. r/rr-xr-xr-x 0 0 8521-128-3 /WINDOWS/system32/dllcache/fxsui.dll 192512 ..c. r/rr-xr-xr-x 0 0 8522-128-3 /WINDOWS/system32/dllcache/fxswzrd.dll 400384 ..c. r/rr-xr-xr-x 0 0 8523-128-3 /WINDOWS/system32/dllcache/fxsxp32.dll 41472 ..c. r/rr-xr-xr-x 0 0 8524-128-1 /WINDOWS/system32/dllcache/g711codc.ax 76800 ..c. r/rr-xr-xr-x 0 0 8525-128-1 /WINDOWS/system32/dllcache/gcdef.dll 24576 ..c. r/rr-xr-xr-x 0 0 8526-128-1 /WINDOWS/system32/dllcache/gdi.exe 285184 ..c. r/rr-xr-xr-x 0 0 8527-128-1 /WINDOWS/system32/dllcache/gdi32.dll 24772 ..c. r/rr-xr-xr-x 0 0 8528-128-1 /WINDOWS/system32/dllcache/geo.nls 59904 ..c. r/rr-xr-xr-x 0 0 8529-128-1 /WINDOWS/system32/dllcache/getmac.exe 8360 ..c. r/rr-xr-xr-x 0 0 853-128-3 /WINDOWS/inf/mdmmod.inf 605696 ..c. r/rr-xr-xr-x 0 0 8530-128-1 /WINDOWS/system32/dllcache/getuname.dll 285184 ..c. r/rr-xr-xr-x 0 0 8531-128-1 /WINDOWS/system32/dllcache/glmf32.dll 122880 ..c. r/rr-xr-xr-x 0 0 8532-128-1 /WINDOWS/system32/dllcache/glu32.dll 3440660 ..c. r/rr-xr-xr-x 0 0 8533-128-1 /WINDOWS/system32/dllcache/gm.dls 566784 ..c. r/rr-xr-xr-x 0 0 8534-128-1 /WINDOWS/system32/dllcache/gpedit.dll 101888 ..c. r/rr-xr-xr-x 0 0 8535-128-1 /WINDOWS/system32/dllcache/gpkcsp.dll 9728 ..c. r/rr-xr-xr-x 0 0 8536-128-1 /WINDOWS/system32/dllcache/gpkrsrc.dll 120832 ..c. r/rr-xr-xr-x 0 0 8537-128-1 /WINDOWS/system32/dllcache/gprslt.exe 199680 ..c. r/rr-xr-xr-x 0 0 8538-128-1 /WINDOWS/system32/dllcache/gptext.dll 57344 ..c. r/rr-xr-xr-x 0 0 8539-128-1 /WINDOWS/system32/dllcache/gpupdate.exe 48015 ..c. r/rr-xr-xr-x 0 0 854-128-3 /WINDOWS/inf/mdmmoto.inf 39424 ..c. r/rr-xr-xr-x 0 0 8540-128-1 /WINDOWS/system32/dllcache/grpconv.exe 133120 ..c. r/rr-xr-xr-x 0 0 8541-128-1 /WINDOWS/system32/dllcache/guitrn.dll 32256 ..c. r/rr-xr-xr-x 0 0 8542-128-3 /WINDOWS/system32/dllcache/gzip.dll 265728 ..c. r/rr-xr-xr-x 0 0 8543-128-1 /WINDOWS/system32/dllcache/h323.tsp 57344 ..c. r/rr-xr-xr-x 0 0 8544-128-1 /WINDOWS/system32/dllcache/h323cc.dll 614912 ..c. r/rr-xr-xr-x 0 0 8545-128-1 /WINDOWS/system32/dllcache/h323msp.dll 108827 ..c. r/rr-xr-xr-x 0 0 8546-128-3 /WINDOWS/system32/dllcache/hanja.lex 36864 ..c. r/rr-xr-xr-x 0 0 8547-128-3 /WINDOWS/system32/dllcache/hanjadic.dll 6656 ..c. r/rr-xr-xr-x 0 0 8548-128-1 /WINDOWS/system32/dllcache/hcappres.dll 155136 ..c. r/rr-xr-xr-x 0 0 8549-128-1 /WINDOWS/system32/dllcache/hdwwiz.cpl 12221 ..c. r/rr-xr-xr-x 0 0 855-128-3 /WINDOWS/inf/mdmmoto1.inf 15872 ..c. r/rr-xr-xr-x 0 0 8550-128-1 /WINDOWS/system32/dllcache/help.exe 769024 ..c. r/rr-xr-xr-x 0 0 8551-128-1 /WINDOWS/system32/dllcache/helpctr.exe 99840 ..c. r/rr-xr-xr-x 0 0 8552-128-1 /WINDOWS/system32/dllcache/helphost.exe 744448 ..c. r/rr-xr-xr-x 0 0 8553-128-1 /WINDOWS/system32/dllcache/helpsvc.exe 10752 ..c. r/rr-xr-xr-x 0 0 8554-128-1 /WINDOWS/system32/dllcache/hh.exe 545280 ..c. r/rr-xr-xr-x 0 0 8555-128-1 /WINDOWS/system32/dllcache/hhctrl.ocx 87552 ..c. r/rr-xr-xr-x 0 0 8556-128-1 /WINDOWS/system32/dllcache/hhctrlui.dll 41472 ..c. r/rr-xr-xr-x 0 0 8557-128-1 /WINDOWS/system32/dllcache/hhsetup.dll 29696 ..c. r/rr-xr-xr-x 0 0 8558-128-1 /WINDOWS/system32/dllcache/hidphone.tsp 4768 ..c. r/rr-xr-xr-x 0 0 8559-128-1 /WINDOWS/system32/dllcache/himem.sys 2857 ..c. r/rr-xr-xr-x 0 0 856-128-3 /WINDOWS/inf/mdmmotou.inf 72704 ..c. r/rr-xr-xr-x 0 0 8560-128-1 /WINDOWS/system32/dllcache/hlink.dll 38912 ..c. r/rr-xr-xr-x 0 0 8561-128-1 /WINDOWS/system32/dllcache/hmmapi.dll 344064 ..c. r/rr-xr-xr-x 0 0 8562-128-1 /WINDOWS/system32/dllcache/hnetcfg.dll 14848 ..c. r/rr-xr-xr-x 0 0 8563-128-1 /WINDOWS/system32/dllcache/hnetmon.dll 330752 ..c. r/rr-xr-xr-x 0 0 8564-128-1 /WINDOWS/system32/dllcache/hnetwiz.dll 39936 ..c. r/rr-xr-xr-x 0 0 8565-128-3 /WINDOWS/system32/dllcache/hostmib.dll 7680 ..c. r/rr-xr-xr-x 0 0 8566-128-1 /WINDOWS/system32/dllcache/hostname.exe 144896 ..c. r/rr-xr-xr-x 0 0 8567-128-1 /WINDOWS/system32/dllcache/hotplug.dll 57409 ..c. r/rr-xr-xr-x 0 0 8568-128-1 /WINDOWS/system32/dllcache/hrtz.dll 1175635 ..c. r/rr-xr-xr-x 0 0 8569-128-1 /WINDOWS/system32/dllcache/hrtzres.dll 53355 ..c. r/rr-xr-xr-x 0 0 857-128-3 /WINDOWS/inf/mdmmts.inf 42573 ..c. r/rr-xr-xr-x 0 0 8570-128-1 /WINDOWS/system32/dllcache/hrtzzm.exe 18432 ..c. r/rr-xr-xr-x 0 0 8571-128-1 /WINDOWS/system32/dllcache/hscupd.exe 13312 ..c. r/rr-xr-xr-x 0 0 8572-128-1 /WINDOWS/system32/dllcache/htrn_jis.dll 24576 ..c. r/rr-xr-xr-x 0 0 8573-128-1 /WINDOWS/system32/dllcache/httpapi.dll 268288 ..c. r/rr-xr-xr-x 0 0 8574-128-3 /WINDOWS/system32/dllcache/httpext.dll 8192 ..c. r/rr-xr-xr-x 0 0 8575-128-3 /WINDOWS/system32/dllcache/httpmb51.dll 61440 ..c. r/rr-xr-xr-x 0 0 8576-128-3 /WINDOWS/system32/dllcache/httpod51.dll 41984 ..c. r/rr-xr-xr-x 0 0 8577-128-1 /WINDOWS/system32/dllcache/htui.dll 10096640 ..c. r/rr-xr-xr-x 0 0 8578-128-3 /WINDOWS/system32/dllcache/hwxcht.dll 13463552 ..c. r/rr-xr-xr-x 0 0 8579-128-3 /WINDOWS/system32/dllcache/hwxjpn.dll 11634 ..c. r/rr-xr-xr-x 0 0 858-128-3 /WINDOWS/inf/mdmneuhs.inf 10129408 ..c. r/rr-xr-xr-x 0 0 8580-128-3 /WINDOWS/system32/dllcache/hwxkor.dll 23552 ..c. r/rr-xr-xr-x 0 0 8581-128-1 /WINDOWS/system32/dllcache/iasacct.dll 41472 ..c. r/rr-xr-xr-x 0 0 8582-128-1 /WINDOWS/system32/dllcache/iasads.dll 32256 ..c. r/rr-xr-xr-x 0 0 8583-128-1 /WINDOWS/system32/dllcache/iashlpr.dll 62464 ..c. r/rr-xr-xr-x 0 0 8584-128-1 /WINDOWS/system32/dllcache/iasnap.dll 17920 ..c. r/rr-xr-xr-x 0 0 8585-128-1 /WINDOWS/system32/dllcache/iaspolcy.dll 119808 ..c. r/rr-xr-xr-x 0 0 8586-128-1 /WINDOWS/system32/dllcache/iasrad.dll 141312 ..c. r/rr-xr-xr-x 0 0 8587-128-1 /WINDOWS/system32/dllcache/iasrecst.dll 86528 ..c. r/rr-xr-xr-x 0 0 8588-128-1 /WINDOWS/system32/dllcache/iassam.dll 247808 ..c. r/rr-xr-xr-x 0 0 8589-128-1 /WINDOWS/system32/dllcache/iassdo.dll 7974 ..c. r/rr-xr-xr-x 0 0 859-128-3 /WINDOWS/inf/Mdmnis1u.inf 59392 ..c. r/rr-xr-xr-x 0 0 8590-128-1 /WINDOWS/system32/dllcache/iassvcs.dll 11264 ..c. r/rr-xr-xr-x 0 0 8591-128-1 /WINDOWS/system32/dllcache/icaapi.dll 16384 ..c. r/rr-xr-xr-x 0 0 8592-128-1 /WINDOWS/system32/dllcache/icfgnt5.dll 254976 ..c. r/rr-xr-xr-x 0 0 8593-128-1 /WINDOWS/system32/dllcache/icm32.dll 3584 ..c. r/rr-xr-xr-x 0 0 8594-128-1 /WINDOWS/system32/dllcache/icmp.dll 54784 ..c. r/rr-xr-xr-x 0 0 8595-128-1 /WINDOWS/system32/dllcache/icmui.dll 61440 ..c. r/rr-xr-xr-x 0 0 8596-128-1 /WINDOWS/system32/dllcache/icwconn.dll 214528 ..c. r/rr-xr-xr-x 0 0 8597-128-1 /WINDOWS/system32/dllcache/icwconn1.exe 86016 ..c. r/rr-xr-xr-x 0 0 8598-128-1 /WINDOWS/system32/dllcache/icwconn2.exe 73728 ..c. r/rr-xr-xr-x 0 0 8599-128-1 /WINDOWS/system32/dllcache/icwdial.dll 8042 ..c. r/rr-xr-xr-x 0 0 860-128-3 /WINDOWS/inf/Mdmnis2u.inf 32768 ..c. r/rr-xr-xr-x 0 0 8600-128-1 /WINDOWS/system32/dllcache/icwdl.dll 172032 ..c. r/rr-xr-xr-x 0 0 8601-128-1 /WINDOWS/system32/dllcache/icwhelp.dll 65536 ..c. r/rr-xr-xr-x 0 0 8602-128-1 /WINDOWS/system32/dllcache/icwphbk.dll 61440 ..c. r/rr-xr-xr-x 0 0 8603-128-1 /WINDOWS/system32/dllcache/icwres.dll 24576 ..c. r/rr-xr-xr-x 0 0 8604-128-1 /WINDOWS/system32/dllcache/icwrmind.exe 73728 ..c. r/rr-xr-xr-x 0 0 8605-128-1 /WINDOWS/system32/dllcache/icwtutor.exe 49152 ..c. r/rr-xr-xr-x 0 0 8606-128-1 /WINDOWS/system32/dllcache/icwutil.dll 120832 ..c. r/rr-xr-xr-x 0 0 8607-128-1 /WINDOWS/system32/dllcache/idq.dll 34304 ..c. r/rr-xr-xr-x 0 0 8608-128-1 /WINDOWS/system32/dllcache/ie4uinit.exe 143360 ..c. r/rr-xr-xr-x 0 0 8609-128-1 /WINDOWS/system32/dllcache/ieakeng.dll 4091 ..c. r/rr-xr-xr-x 0 0 861-128-3 /WINDOWS/inf/Mdmnis3t.inf 216576 ..c. r/rr-xr-xr-x 0 0 8610-128-1 /WINDOWS/system32/dllcache/ieaksie.dll 221184 ..c. r/rr-xr-xr-x 0 0 8611-128-1 /WINDOWS/system32/dllcache/ieakui.dll 323584 ..c. r/rr-xr-xr-x 0 0 8612-128-1 /WINDOWS/system32/dllcache/iedkcs32.dll 18432 ..c. r/rr-xr-xr-x 0 0 8613-128-1 /WINDOWS/system32/dllcache/iedw.exe 81920 ..c. r/rr-xr-xr-x 0 0 8614-128-1 /WINDOWS/system32/dllcache/ieencode.dll 93184 ..c. r/rr-xr-xr-x 0 0 8615-128-1 /WINDOWS/system32/dllcache/ieinfo5.ocx 251904 ..c. r/rr-xr-xr-x 0 0 8616-128-1 /WINDOWS/system32/dllcache/iepeers.dll 48640 ..c. r/rr-xr-xr-x 0 0 8617-128-1 /WINDOWS/system32/dllcache/iernonce.dll 62976 ..c. r/rr-xr-xr-x 0 0 8618-128-1 /WINDOWS/system32/dllcache/iesetup.dll 93184 ..c. r/rr-xr-xr-x 0 0 8619-128-1 /WINDOWS/system32/dllcache/iexplore.exe 4130 ..c. r/rr-xr-xr-x 0 0 862-128-3 /WINDOWS/inf/Mdmnis5t.inf 114688 ..c. r/rr-xr-xr-x 0 0 8620-128-1 /WINDOWS/system32/dllcache/iexpress.exe 135680 ..c. r/rr-xr-xr-x 0 0 8621-128-1 /WINDOWS/system32/dllcache/ifmon.dll 70656 ..c. r/rr-xr-xr-x 0 0 8622-128-1 /WINDOWS/system32/dllcache/ifsutil.dll 8192 ..c. r/rr-xr-xr-x 0 0 8623-128-1 /WINDOWS/system32/dllcache/igmpagnt.dll 505344 ..c. r/rr-xr-xr-x 0 0 8624-128-1 /WINDOWS/system32/dllcache/iis.dll 25088 ..c. r/rr-xr-xr-x 0 0 8625-128-3 /WINDOWS/system32/dllcache/iisadmin.dll 145408 ..c. r/rr-xr-xr-x 0 0 8626-128-3 /WINDOWS/system32/dllcache/iische51.dll 60928 ..c. r/rr-xr-xr-x 0 0 8627-128-3 /WINDOWS/system32/dllcache/iisclex4.dll 19456 ..c. r/rr-xr-xr-x 0 0 8628-128-3 /WINDOWS/system32/dllcache/iiscrmap.dll 7168 ..c. r/rr-xr-xr-x 0 0 8629-128-3 /WINDOWS/system32/dllcache/iisfecnv.dll 5904 ..c. r/rr-xr-xr-x 0 0 863-128-3 /WINDOWS/inf/mdmnokia.inf 79872 ..c. r/rr-xr-xr-x 0 0 8630-128-3 /WINDOWS/system32/dllcache/iislog51.dll 3584 ..c. r/rr-xr-xr-x 0 0 8631-128-3 /WINDOWS/system32/dllcache/iismui.dll 9216 ..c. r/rr-xr-xr-x 0 0 8632-128-1 /WINDOWS/system32/dllcache/iissuba.dll 6656 ..c. r/rr-xr-xr-x 0 0 8633-128-3 /WINDOWS/system32/dllcache/iissync.exe 81920 ..c. r/rr-xr-xr-x 0 0 8634-128-1 /WINDOWS/system32/dllcache/ils.dll 144384 ..c. r/rr-xr-xr-x 0 0 8635-128-1 /WINDOWS/system32/dllcache/imagehlp.dll 150528 ..c. r/rr-xr-xr-x 0 0 8636-128-1 /WINDOWS/system32/dllcache/imapi.exe 134339 ..c. r/rr-xr-xr-x 0 0 8637-128-3 /WINDOWS/system32/dllcache/imekr.lex 94720 ..c. r/rr-xr-xr-x 0 0 8638-128-3 /WINDOWS/system32/dllcache/imekr61.ime 106496 ..c. r/rr-xr-xr-x 0 0 8639-128-3 /WINDOWS/system32/dllcache/imekrcic.dll 11615 ..c. r/rr-xr-xr-x 0 0 864-128-3 /WINDOWS/inf/mdmnova.inf 86016 ..c. r/rr-xr-xr-x 0 0 8640-128-3 /WINDOWS/system32/dllcache/imekrmbx.dll 44032 ..c. r/rr-xr-xr-x 0 0 8641-128-3 /WINDOWS/system32/dllcache/imekrmig.exe 102463 ..c. r/rr-xr-xr-x 0 0 8642-128-3 /WINDOWS/system32/dllcache/imepadsm.dll 311359 ..c. r/rr-xr-xr-x 0 0 8643-128-3 /WINDOWS/system32/dllcache/imepadsv.exe 35840 ..c. r/rr-xr-xr-x 0 0 8644-128-1 /WINDOWS/system32/dllcache/imgutil.dll 340023 ..c. r/rr-xr-xr-x 0 0 8645-128-3 /WINDOWS/system32/dllcache/imjp81.ime 811064 ..c. r/rr-xr-xr-x 0 0 8646-128-3 /WINDOWS/system32/dllcache/imjp81k.dll 368696 ..c. r/rr-xr-xr-x 0 0 8647-128-3 /WINDOWS/system32/dllcache/imjpcic.dll 716856 ..c. r/rr-xr-xr-x 0 0 8648-128-3 /WINDOWS/system32/dllcache/imjpcus.dll 57398 ..c. r/rr-xr-xr-x 0 0 8649-128-3 /WINDOWS/system32/dllcache/imjpdadm.exe 6343 ..c. r/rr-xr-xr-x 0 0 865-128-3 /WINDOWS/inf/mdmntt1.INF 81976 ..c. r/rr-xr-xr-x 0 0 8650-128-3 /WINDOWS/system32/dllcache/imjpdct.dll 307257 ..c. r/rr-xr-xr-x 0 0 8651-128-3 /WINDOWS/system32/dllcache/imjpdct.exe 155705 ..c. r/rr-xr-xr-x 0 0 8652-128-3 /WINDOWS/system32/dllcache/imjpdsvr.exe 196665 ..c. r/rr-xr-xr-x 0 0 8653-128-3 /WINDOWS/system32/dllcache/imjpinst.exe 208952 ..c. r/rr-xr-xr-x 0 0 8654-128-3 /WINDOWS/system32/dllcache/imjpmig.exe 233527 ..c. r/rr-xr-xr-x 0 0 8655-128-3 /WINDOWS/system32/dllcache/imjprw.exe 45109 ..c. r/rr-xr-xr-x 0 0 8656-128-3 /WINDOWS/system32/dllcache/imjpuex.exe 262200 ..c. r/rr-xr-xr-x 0 0 8657-128-3 /WINDOWS/system32/dllcache/imjputy.exe 274489 ..c. r/rr-xr-xr-x 0 0 8658-128-3 /WINDOWS/system32/dllcache/imjputyc.dll 59904 ..c. r/rr-xr-xr-x 0 0 8659-128-3 /WINDOWS/system32/dllcache/imkrinst.exe 12343 ..c. r/rr-xr-xr-x 0 0 866-128-3 /WINDOWS/inf/mdmnttd2.inf 102456 ..c. r/rr-xr-xr-x 0 0 8660-128-3 /WINDOWS/system32/dllcache/imlang.dll 110080 ..c. r/rr-xr-xr-x 0 0 8661-128-1 /WINDOWS/system32/dllcache/imm32.dll 59392 ..c. r/rr-xr-xr-x 0 0 8662-128-3 /WINDOWS/system32/dllcache/imscinst.exe 123392 ..c. r/rr-xr-xr-x 0 0 8663-128-1 /WINDOWS/system32/dllcache/imsinsnt.dll 471102 ..c. r/rr-xr-xr-x 0 0 8664-128-3 /WINDOWS/system32/dllcache/imskdic.dll 315455 ..c. r/rr-xr-xr-x 0 0 8665-128-3 /WINDOWS/system32/dllcache/imskf.dll 274432 ..c. r/rr-xr-xr-x 0 0 8666-128-1 /WINDOWS/system32/dllcache/inetcfg.dll 691712 ..c. r/rr-xr-xr-x 0 0 8667-128-1 /WINDOWS/system32/dllcache/inetcomm.dll 360960 ..c. r/rr-xr-xr-x 0 0 8668-128-1 /WINDOWS/system32/dllcache/inetcpl.cpl 110592 ..c. r/rr-xr-xr-x 0 0 8669-128-1 /WINDOWS/system32/dllcache/inetcplc.dll 12166 ..c. r/rr-xr-xr-x 0 0 867-128-3 /WINDOWS/inf/mdmnttd6.inf 15360 ..c. r/rr-xr-xr-x 0 0 8670-128-3 /WINDOWS/system32/dllcache/inetin51.exe 32768 ..c. r/rr-xr-xr-x 0 0 8671-128-1 /WINDOWS/system32/dllcache/inetmib1.dll 75264 ..c. r/rr-xr-xr-x 0 0 8672-128-1 /WINDOWS/system32/dllcache/inetpp.dll 15872 ..c. r/rr-xr-xr-x 0 0 8673-128-1 /WINDOWS/system32/dllcache/inetppui.dll 48128 ..c. r/rr-xr-xr-x 0 0 8674-128-1 /WINDOWS/system32/dllcache/inetres.dll 20480 ..c. r/rr-xr-xr-x 0 0 8675-128-1 /WINDOWS/system32/dllcache/inetwiz.exe 257024 ..c. r/rr-xr-xr-x 0 0 8676-128-3 /WINDOWS/system32/dllcache/infocomm.dll 8704 ..c. r/rr-xr-xr-x 0 0 8677-128-3 /WINDOWS/system32/dllcache/infoctrs.dll 450560 ..c. r/rr-xr-xr-x 0 0 8678-128-1 /WINDOWS/system32/dllcache/infosoft.dll 147456 ..c. r/rr-xr-xr-x 0 0 8679-128-1 /WINDOWS/system32/dllcache/initpki.dll 4557 ..c. r/rr-xr-xr-x 0 0 868-128-3 /WINDOWS/inf/mdmnttme.INF 123392 ..c. r/rr-xr-xr-x 0 0 8680-128-1 /WINDOWS/system32/dllcache/input.dll 96256 ..c. r/rr-xr-xr-x 0 0 8681-128-1 /WINDOWS/system32/dllcache/inseng.dll 129536 ..c. r/rr-xr-xr-x 0 0 8682-128-1 /WINDOWS/system32/dllcache/intl.cpl 30720 ..c. r/rr-xr-xr-x 0 0 8683-128-1 /WINDOWS/system32/dllcache/iologmsg.dll 36608 ..c. r/rr-xr-xr-x 0 0 8684-128-1 /WINDOWS/system32/dllcache/ip6fw.sys 17408 ..c. r/rr-xr-xr-x 0 0 8685-128-1 /WINDOWS/system32/dllcache/ipconf.tsp 55808 ..c. r/rr-xr-xr-x 0 0 8686-128-1 /WINDOWS/system32/dllcache/ipconfig.exe 32896 ..c. r/rr-xr-xr-x 0 0 8687-128-1 /WINDOWS/system32/dllcache/ipfltdrv.sys 94720 ..c. r/rr-xr-xr-x 0 0 8688-128-1 /WINDOWS/system32/dllcache/iphlpapi.dll 20864 ..c. r/rr-xr-xr-x 0 0 8689-128-1 /WINDOWS/system32/dllcache/ipinip.sys 8012 ..c. r/rr-xr-xr-x 0 0 869-128-3 /WINDOWS/inf/mdmnttp.inf 161280 ..c. r/rr-xr-xr-x 0 0 8690-128-1 /WINDOWS/system32/dllcache/ipmontr.dll 152832 ..c. r/rr-xr-xr-x 0 0 8691-128-1 /WINDOWS/system32/dllcache/ipnat.sys 331264 ..c. r/rr-xr-xr-x 0 0 8692-128-1 /WINDOWS/system32/dllcache/ipnathlp.dll 330752 ..c. r/rr-xr-xr-x 0 0 8693-128-1 /WINDOWS/system32/dllcache/ippromon.dll 35328 ..c. r/rr-xr-xr-x 0 0 8694-128-3 /WINDOWS/system32/dllcache/iprip.dll 3584 ..c. r/rr-xr-xr-x 0 0 8695-128-1 /WINDOWS/system32/dllcache/iprop.dll 4096 ..c. r/rr-xr-xr-x 0 0 8696-128-1 /WINDOWS/system32/dllcache/iprtprio.dll 177152 ..c. r/rr-xr-xr-x 0 0 8697-128-1 /WINDOWS/system32/dllcache/iprtrmgr.dll 44032 ..c. r/rr-xr-xr-x 0 0 8698-128-1 /WINDOWS/system32/dllcache/ipsec6.exe 349696 ..c. r/rr-xr-xr-x 0 0 8699-128-1 /WINDOWS/system32/dllcache/ipsecsnp.dll 56 .a.. d/dr-xr-xr-x 0 0 87-144-5 /WINDOWS/AppPatch 8611 ..c. r/rr-xr-xr-x 0 0 870-128-3 /WINDOWS/inf/mdmnttp2.inf 183808 ..c. r/rr-xr-xr-x 0 0 8700-128-1 /WINDOWS/system32/dllcache/ipsecsvc.dll 384000 ..c. r/rr-xr-xr-x 0 0 8701-128-1 /WINDOWS/system32/dllcache/ipsmsnap.dll 53248 ..c. r/rr-xr-xr-x 0 0 8702-128-1 /WINDOWS/system32/dllcache/ipv6.exe 59904 ..c. r/rr-xr-xr-x 0 0 8703-128-1 /WINDOWS/system32/dllcache/ipv6mon.dll 83968 ..c. r/rr-xr-xr-x 0 0 8704-128-1 /WINDOWS/system32/dllcache/ipxmontr.dll 69120 ..c. r/rr-xr-xr-x 0 0 8705-128-1 /WINDOWS/system32/dllcache/ipxpromn.dll 21504 ..c. r/rr-xr-xr-x 0 0 8706-128-1 /WINDOWS/system32/dllcache/ipxrip.dll 23552 ..c. r/rr-xr-xr-x 0 0 8707-128-1 /WINDOWS/system32/dllcache/ipxroute.exe 39936 ..c. r/rr-xr-xr-x 0 0 8708-128-1 /WINDOWS/system32/dllcache/ipxrtmgr.dll 66560 ..c. r/rr-xr-xr-x 0 0 8709-128-1 /WINDOWS/system32/dllcache/ipxsap.dll 4170 ..c. r/rr-xr-xr-x 0 0 871-128-3 /WINDOWS/inf/mdmnttte.inf 22016 ..c. r/rr-xr-xr-x 0 0 8710-128-1 /WINDOWS/system32/dllcache/ipxwan.dll 13312 ..c. r/rr-xr-xr-x 0 0 8711-128-1 /WINDOWS/system32/dllcache/irclass.dll 11264 ..c. r/rr-xr-xr-x 0 0 8712-128-1 /WINDOWS/system32/dllcache/irenum.sys 7168 ..c. r/rr-xr-xr-x 0 0 8713-128-3 /WINDOWS/system32/dllcache/isapips.dll 26624 ..c. r/rr-xr-xr-x 0 0 8714-128-3 /WINDOWS/system32/dllcache/iscomlog.dll 81920 ..c. r/rr-xr-xr-x 0 0 8715-128-1 /WINDOWS/system32/dllcache/isign32.dll 16384 ..c. r/rr-xr-xr-x 0 0 8716-128-1 /WINDOWS/system32/dllcache/isignup.exe 32768 ..c. r/rr-xr-xr-x 0 0 8717-128-1 /WINDOWS/system32/dllcache/isrdbg32.dll 191488 ..c. r/rr-xr-xr-x 0 0 8718-128-1 /WINDOWS/system32/dllcache/iuengine.dll 9216 ..c. r/rr-xr-xr-x 0 0 8719-128-3 /WINDOWS/system32/dllcache/iwrps.dll 8438 ..c. r/rr-xr-xr-x 0 0 872-128-3 /WINDOWS/inf/mdmolic.inf 54272 ..c. r/rr-xr-xr-x 0 0 8720-128-1 /WINDOWS/system32/dllcache/ixsso.dll 362496 ..c. r/rr-xr-xr-x 0 0 8721-128-1 /WINDOWS/system32/dllcache/jet500.dll 47952 ..c. r/rr-xr-xr-x 0 0 8722-128-1 /WINDOWS/system32/dllcache/jobexec.dll 68608 ..c. r/rr-xr-xr-x 0 0 8723-128-1 /WINDOWS/system32/dllcache/joy.cpl 18432 ..c. r/rr-xr-xr-x 0 0 8724-128-3 /WINDOWS/system32/dllcache/jupiw.dll 6144 ..c. r/rr-xr-xr-x 0 0 8725-128-3 /WINDOWS/system32/dllcache/kbd101.dll 6144 ..c. r/rr-xr-xr-x 0 0 8726-128-3 /WINDOWS/system32/dllcache/kbd101a.dll 6144 ..c. r/rr-xr-xr-x 0 0 8727-128-3 /WINDOWS/system32/dllcache/kbd106n.dll 5632 ..c. r/rr-xr-xr-x 0 0 8728-128-3 /WINDOWS/system32/dllcache/kbda1.dll 5632 ..c. r/rr-xr-xr-x 0 0 8729-128-3 /WINDOWS/system32/dllcache/kbda2.dll 71404 ..c. r/rr-xr-xr-x 0 0 873-128-3 /WINDOWS/inf/mdmomrn3.inf 5632 ..c. r/rr-xr-xr-x 0 0 8730-128-3 /WINDOWS/system32/dllcache/kbda3.dll 6656 ..c. r/rr-xr-xr-x 0 0 8731-128-1 /WINDOWS/system32/dllcache/kbdal.dll 5120 ..c. r/rr-xr-xr-x 0 0 8732-128-3 /WINDOWS/system32/dllcache/kbdarme.dll 5120 ..c. r/rr-xr-xr-x 0 0 8733-128-3 /WINDOWS/system32/dllcache/kbdarmw.dll 6144 ..c. r/rr-xr-xr-x 0 0 8734-128-3 /WINDOWS/system32/dllcache/kbdax2.dll 5632 ..c. r/rr-xr-xr-x 0 0 8735-128-1 /WINDOWS/system32/dllcache/kbdaze.dll 5632 ..c. r/rr-xr-xr-x 0 0 8736-128-1 /WINDOWS/system32/dllcache/kbdazel.dll 6144 ..c. r/rr-xr-xr-x 0 0 8737-128-1 /WINDOWS/system32/dllcache/kbdbe.dll 6144 ..c. r/rr-xr-xr-x 0 0 8738-128-1 /WINDOWS/system32/dllcache/kbdbene.dll 5632 ..c. r/rr-xr-xr-x 0 0 8739-128-1 /WINDOWS/system32/dllcache/kbdblr.dll 4541 ..c. r/rr-xr-xr-x 0 0 874-128-3 /WINDOWS/inf/mdmoptn.inf 6144 ..c. r/rr-xr-xr-x 0 0 8740-128-1 /WINDOWS/system32/dllcache/kbdbr.dll 5632 ..c. r/rr-xr-xr-x 0 0 8741-128-1 /WINDOWS/system32/dllcache/kbdbu.dll 6144 ..c. r/rr-xr-xr-x 0 0 8742-128-1 /WINDOWS/system32/dllcache/kbdca.dll 7680 ..c. r/rr-xr-xr-x 0 0 8743-128-1 /WINDOWS/system32/dllcache/kbdcan.dll 6656 ..c. r/rr-xr-xr-x 0 0 8744-128-1 /WINDOWS/system32/dllcache/kbdcr.dll 7168 ..c. r/rr-xr-xr-x 0 0 8745-128-1 /WINDOWS/system32/dllcache/kbdcz.dll 6656 ..c. r/rr-xr-xr-x 0 0 8746-128-1 /WINDOWS/system32/dllcache/kbdcz1.dll 6656 ..c. r/rr-xr-xr-x 0 0 8747-128-1 /WINDOWS/system32/dllcache/kbdcz2.dll 6144 ..c. r/rr-xr-xr-x 0 0 8748-128-1 /WINDOWS/system32/dllcache/kbdda.dll 5632 ..c. r/rr-xr-xr-x 0 0 8749-128-3 /WINDOWS/system32/dllcache/kbddiv1.dll 31555 ..c. r/rr-xr-xr-x 0 0 875-128-3 /WINDOWS/inf/mdmosi.inf 5632 ..c. r/rr-xr-xr-x 0 0 8750-128-3 /WINDOWS/system32/dllcache/kbddiv2.dll 5120 ..c. r/rr-xr-xr-x 0 0 8751-128-1 /WINDOWS/system32/dllcache/kbddv.dll 6144 ..c. r/rr-xr-xr-x 0 0 8752-128-1 /WINDOWS/system32/dllcache/kbdes.dll 6144 ..c. r/rr-xr-xr-x 0 0 8753-128-1 /WINDOWS/system32/dllcache/kbdest.dll 5632 ..c. r/rr-xr-xr-x 0 0 8754-128-3 /WINDOWS/system32/dllcache/kbdfa.dll 6144 ..c. r/rr-xr-xr-x 0 0 8755-128-1 /WINDOWS/system32/dllcache/kbdfc.dll 6144 ..c. r/rr-xr-xr-x 0 0 8756-128-1 /WINDOWS/system32/dllcache/kbdfi.dll 7168 ..c. r/rr-xr-xr-x 0 0 8757-128-1 /WINDOWS/system32/dllcache/kbdfi1.dll 6144 ..c. r/rr-xr-xr-x 0 0 8758-128-1 /WINDOWS/system32/dllcache/kbdfo.dll 6144 ..c. r/rr-xr-xr-x 0 0 8759-128-1 /WINDOWS/system32/dllcache/kbdfr.dll 17976 ..c. r/rr-xr-xr-x 0 0 876-128-3 /WINDOWS/inf/mdmpace.inf 5632 ..c. r/rr-xr-xr-x 0 0 8760-128-1 /WINDOWS/system32/dllcache/kbdgae.dll 5120 ..c. r/rr-xr-xr-x 0 0 8761-128-3 /WINDOWS/system32/dllcache/kbdgeo.dll 6144 ..c. r/rr-xr-xr-x 0 0 8762-128-1 /WINDOWS/system32/dllcache/kbdgkl.dll 6144 ..c. r/rr-xr-xr-x 0 0 8763-128-1 /WINDOWS/system32/dllcache/kbdgr.dll 6144 ..c. r/rr-xr-xr-x 0 0 8764-128-1 /WINDOWS/system32/dllcache/kbdgr1.dll 5632 ..c. r/rr-xr-xr-x 0 0 8765-128-1 /WINDOWS/system32/dllcache/kbdhe.dll 5632 ..c. r/rr-xr-xr-x 0 0 8766-128-1 /WINDOWS/system32/dllcache/kbdhe220.dll 5632 ..c. r/rr-xr-xr-x 0 0 8767-128-1 /WINDOWS/system32/dllcache/kbdhe319.dll 5632 ..c. r/rr-xr-xr-x 0 0 8768-128-3 /WINDOWS/system32/dllcache/kbdheb.dll 6144 ..c. r/rr-xr-xr-x 0 0 8769-128-1 /WINDOWS/system32/dllcache/kbdhela2.dll 2500 ..c. r/rr-xr-xr-x 0 0 877-128-3 /WINDOWS/inf/mdmpbit.inf 6656 ..c. r/rr-xr-xr-x 0 0 8770-128-1 /WINDOWS/system32/dllcache/kbdhela3.dll 8192 ..c. r/rr-xr-xr-x 0 0 8771-128-1 /WINDOWS/system32/dllcache/kbdhept.dll 6656 ..c. r/rr-xr-xr-x 0 0 8772-128-1 /WINDOWS/system32/dllcache/kbdhu.dll 5632 ..c. r/rr-xr-xr-x 0 0 8773-128-1 /WINDOWS/system32/dllcache/kbdhu1.dll 7168 ..c. r/rr-xr-xr-x 0 0 8774-128-3 /WINDOWS/system32/dllcache/kbdibm02.dll 6144 ..c. r/rr-xr-xr-x 0 0 8775-128-1 /WINDOWS/system32/dllcache/kbdic.dll 6144 ..c. r/rr-xr-xr-x 0 0 8776-128-1 /WINDOWS/system32/dllcache/kbdinbe1.dll 6144 ..c. r/rr-xr-xr-x 0 0 8777-128-1 /WINDOWS/system32/dllcache/kbdinben.dll 5632 ..c. r/rr-xr-xr-x 0 0 8778-128-3 /WINDOWS/system32/dllcache/kbdindev.dll 5632 ..c. r/rr-xr-xr-x 0 0 8779-128-3 /WINDOWS/system32/dllcache/kbdinguj.dll 55506 ..c. r/rr-xr-xr-x 0 0 878-128-3 /WINDOWS/inf/mdmpenr.inf 5632 ..c. r/rr-xr-xr-x 0 0 8780-128-3 /WINDOWS/system32/dllcache/kbdinhin.dll 5632 ..c. r/rr-xr-xr-x 0 0 8781-128-3 /WINDOWS/system32/dllcache/kbdinkan.dll 6656 ..c. r/rr-xr-xr-x 0 0 8782-128-1 /WINDOWS/system32/dllcache/kbdinmal.dll 5632 ..c. r/rr-xr-xr-x 0 0 8783-128-3 /WINDOWS/system32/dllcache/kbdinmar.dll 6144 ..c. r/rr-xr-xr-x 0 0 8784-128-3 /WINDOWS/system32/dllcache/kbdinpun.dll 5632 ..c. r/rr-xr-xr-x 0 0 8785-128-3 /WINDOWS/system32/dllcache/kbdintam.dll 5632 ..c. r/rr-xr-xr-x 0 0 8786-128-3 /WINDOWS/system32/dllcache/kbdintel.dll 5632 ..c. r/rr-xr-xr-x 0 0 8787-128-1 /WINDOWS/system32/dllcache/kbdir.dll 5632 ..c. r/rr-xr-xr-x 0 0 8788-128-1 /WINDOWS/system32/dllcache/kbdit.dll 5632 ..c. r/rr-xr-xr-x 0 0 8789-128-1 /WINDOWS/system32/dllcache/kbdit142.dll 10576 ..c. r/rr-xr-xr-x 0 0 879-128-3 /WINDOWS/inf/mdmpin.inf 5632 ..c. r/rr-xr-xr-x 0 0 8790-128-1 /WINDOWS/system32/dllcache/kbdkaz.dll 5632 ..c. r/rr-xr-xr-x 0 0 8791-128-1 /WINDOWS/system32/dllcache/kbdkyr.dll 6656 ..c. r/rr-xr-xr-x 0 0 8792-128-1 /WINDOWS/system32/dllcache/kbdla.dll 6656 ..c. r/rr-xr-xr-x 0 0 8793-128-3 /WINDOWS/system32/dllcache/kbdlk41a.dll 6144 ..c. r/rr-xr-xr-x 0 0 8794-128-3 /WINDOWS/system32/dllcache/kbdlk41j.dll 5632 ..c. r/rr-xr-xr-x 0 0 8795-128-1 /WINDOWS/system32/dllcache/kbdlt.dll 5632 ..c. r/rr-xr-xr-x 0 0 8796-128-1 /WINDOWS/system32/dllcache/kbdlt1.dll 6144 ..c. r/rr-xr-xr-x 0 0 8797-128-1 /WINDOWS/system32/dllcache/kbdlv.dll 6144 ..c. r/rr-xr-xr-x 0 0 8798-128-1 /WINDOWS/system32/dllcache/kbdlv1.dll 6144 ..c. r/rr-xr-xr-x 0 0 8799-128-1 /WINDOWS/system32/dllcache/kbdmac.dll 480 .a.. d/dr-xr-xr-x 0 0 88-144-1 /WINDOWS/Debug 3187 ..c. r/rr-xr-xr-x 0 0 880-128-3 /WINDOWS/inf/mdmpn1.inf 5632 ..c. r/rr-xr-xr-x 0 0 8800-128-1 /WINDOWS/system32/dllcache/kbdmaori.dll 6144 ..c. r/rr-xr-xr-x 0 0 8801-128-1 /WINDOWS/system32/dllcache/kbdmlt47.dll 6144 ..c. r/rr-xr-xr-x 0 0 8802-128-1 /WINDOWS/system32/dllcache/kbdmlt48.dll 5632 ..c. r/rr-xr-xr-x 0 0 8803-128-1 /WINDOWS/system32/dllcache/kbdmon.dll 6144 ..c. r/rr-xr-xr-x 0 0 8804-128-1 /WINDOWS/system32/dllcache/kbdne.dll 7168 ..c. r/rr-xr-xr-x 0 0 8805-128-1 /WINDOWS/system32/dllcache/kbdnec.dll 7168 ..c. r/rr-xr-xr-x 0 0 8806-128-3 /WINDOWS/system32/dllcache/kbdnec95.dll 9216 ..c. r/rr-xr-xr-x 0 0 8807-128-3 /WINDOWS/system32/dllcache/kbdnecat.dll 7680 ..c. r/rr-xr-xr-x 0 0 8808-128-3 /WINDOWS/system32/dllcache/kbdnecnt.dll 6144 ..c. r/rr-xr-xr-x 0 0 8809-128-1 /WINDOWS/system32/dllcache/kbdno.dll 37657 ..c. r/rr-xr-xr-x 0 0 881-128-3 /WINDOWS/inf/mdmpp.inf 7168 ..c. r/rr-xr-xr-x 0 0 8810-128-1 /WINDOWS/system32/dllcache/kbdno1.dll 6656 ..c. r/rr-xr-xr-x 0 0 8811-128-1 /WINDOWS/system32/dllcache/kbdpl.dll 5632 ..c. r/rr-xr-xr-x 0 0 8812-128-1 /WINDOWS/system32/dllcache/kbdpl1.dll 6144 ..c. r/rr-xr-xr-x 0 0 8813-128-1 /WINDOWS/system32/dllcache/kbdpo.dll 5632 ..c. r/rr-xr-xr-x 0 0 8814-128-1 /WINDOWS/system32/dllcache/kbdro.dll 5632 ..c. r/rr-xr-xr-x 0 0 8815-128-1 /WINDOWS/system32/dllcache/kbdru.dll 5632 ..c. r/rr-xr-xr-x 0 0 8816-128-1 /WINDOWS/system32/dllcache/kbdru1.dll 6144 ..c. r/rr-xr-xr-x 0 0 8817-128-1 /WINDOWS/system32/dllcache/kbdsf.dll 6656 ..c. r/rr-xr-xr-x 0 0 8818-128-1 /WINDOWS/system32/dllcache/kbdsg.dll 6656 ..c. r/rr-xr-xr-x 0 0 8819-128-1 /WINDOWS/system32/dllcache/kbdsl.dll 7619 ..c. r/rr-xr-xr-x 0 0 882-128-3 /WINDOWS/inf/mdmpsion.inf 6656 ..c. r/rr-xr-xr-x 0 0 8820-128-1 /WINDOWS/system32/dllcache/kbdsl1.dll 7680 ..c. r/rr-xr-xr-x 0 0 8821-128-1 /WINDOWS/system32/dllcache/kbdsmsfi.dll 7680 ..c. r/rr-xr-xr-x 0 0 8822-128-1 /WINDOWS/system32/dllcache/kbdsmsno.dll 6144 ..c. r/rr-xr-xr-x 0 0 8823-128-1 /WINDOWS/system32/dllcache/kbdsp.dll 6144 ..c. r/rr-xr-xr-x 0 0 8824-128-1 /WINDOWS/system32/dllcache/kbdsw.dll 5632 ..c. r/rr-xr-xr-x 0 0 8825-128-3 /WINDOWS/system32/dllcache/kbdsyr1.dll 5632 ..c. r/rr-xr-xr-x 0 0 8826-128-3 /WINDOWS/system32/dllcache/kbdsyr2.dll 5632 ..c. r/rr-xr-xr-x 0 0 8827-128-1 /WINDOWS/system32/dllcache/kbdtat.dll 5632 ..c. r/rr-xr-xr-x 0 0 8828-128-3 /WINDOWS/system32/dllcache/kbdth0.dll 5632 ..c. r/rr-xr-xr-x 0 0 8829-128-3 /WINDOWS/system32/dllcache/kbdth1.dll 51556 ..c. r/rr-xr-xr-x 0 0 883-128-3 /WINDOWS/inf/mdmracal.inf 6144 ..c. r/rr-xr-xr-x 0 0 8830-128-3 /WINDOWS/system32/dllcache/kbdth2.dll 6144 ..c. r/rr-xr-xr-x 0 0 8831-128-3 /WINDOWS/system32/dllcache/kbdth3.dll 6144 ..c. r/rr-xr-xr-x 0 0 8832-128-1 /WINDOWS/system32/dllcache/kbdtuf.dll 6144 ..c. r/rr-xr-xr-x 0 0 8833-128-1 /WINDOWS/system32/dllcache/kbdtuq.dll 5632 ..c. r/rr-xr-xr-x 0 0 8834-128-1 /WINDOWS/system32/dllcache/kbduk.dll 7168 ..c. r/rr-xr-xr-x 0 0 8835-128-1 /WINDOWS/system32/dllcache/kbdukx.dll 5632 ..c. r/rr-xr-xr-x 0 0 8836-128-1 /WINDOWS/system32/dllcache/kbdur.dll 5632 ..c. r/rr-xr-xr-x 0 0 8837-128-3 /WINDOWS/system32/dllcache/kbdurdu.dll 5632 ..c. r/rr-xr-xr-x 0 0 8838-128-1 /WINDOWS/system32/dllcache/kbdus.dll 5632 ..c. r/rr-xr-xr-x 0 0 8839-128-3 /WINDOWS/system32/dllcache/kbdusa.dll 13178 ..c. r/rr-xr-xr-x 0 0 884-128-3 /WINDOWS/inf/mdmrock.inf 6144 ..c. r/rr-xr-xr-x 0 0 8840-128-1 /WINDOWS/system32/dllcache/kbdusl.dll 6144 ..c. r/rr-xr-xr-x 0 0 8841-128-1 /WINDOWS/system32/dllcache/kbdusr.dll 6144 ..c. r/rr-xr-xr-x 0 0 8842-128-1 /WINDOWS/system32/dllcache/kbdusx.dll 5632 ..c. r/rr-xr-xr-x 0 0 8843-128-1 /WINDOWS/system32/dllcache/kbduzb.dll 5632 ..c. r/rr-xr-xr-x 0 0 8844-128-3 /WINDOWS/system32/dllcache/kbdvntc.dll 5632 ..c. r/rr-xr-xr-x 0 0 8845-128-1 /WINDOWS/system32/dllcache/kbdycc.dll 6656 ..c. r/rr-xr-xr-x 0 0 8846-128-1 /WINDOWS/system32/dllcache/kbdycl.dll 7424 ..c. r/rr-xr-xr-x 0 0 8847-128-1 /WINDOWS/system32/dllcache/kd1394.dll 7040 ..c. r/rr-xr-xr-x 0 0 8848-128-1 /WINDOWS/system32/dllcache/kdcom.dll 299520 ..c. r/rr-xr-xr-x 0 0 8849-128-1 /WINDOWS/system32/dllcache/kerberos.dll 40809 ..c. r/rr-xr-xr-x 0 0 885-128-3 /WINDOWS/inf/mdmrock3.inf 42809 ..c. r/rr-xr-xr-x 0 0 8850-128-1 /WINDOWS/system32/dllcache/key01.sys 42537 ..c. r/rr-xr-xr-x 0 0 8851-128-1 /WINDOWS/system32/dllcache/keyboard.sys 2000 ..c. r/rr-xr-xr-x 0 0 8852-128-1 /WINDOWS/system32/dllcache/keyboard.drv 150528 ..c. r/rr-xr-xr-x 0 0 8853-128-1 /WINDOWS/system32/dllcache/keymgr.dll 33280 ..c. r/rr-xr-xr-x 0 0 8854-128-1 /WINDOWS/system32/dllcache/kmddsp.tsp 61440 ..c. r/rr-xr-xr-x 0 0 8855-128-1 /WINDOWS/system32/dllcache/kmsvc.dll 70656 ..c. r/rr-xr-xr-x 0 0 8856-128-3 /WINDOWS/system32/dllcache/korwbrkr.dll 1158818 ..c. r/rr-xr-xr-x 0 0 8857-128-3 /WINDOWS/system32/dllcache/korwbrkr.lex 92224 ..c. r/rr-xr-xr-x 0 0 8858-128-1 /WINDOWS/system32/dllcache/krnl386.exe 24576 ..c. r/rr-xr-xr-x 0 0 8859-128-1 /WINDOWS/system32/dllcache/krnlprov.dll 45601 ..c. r/rr-xr-xr-x 0 0 886-128-3 /WINDOWS/inf/mdmrock4.inf 47066 ..c. r/rr-xr-xr-x 0 0 8860-128-3 /WINDOWS/system32/dllcache/ksc.nls 92288 ..c. r/rr-xr-xr-x 0 0 8861-128-1 /WINDOWS/system32/dllcache/ksecdd.sys 37376 ..c. r/rr-xr-xr-x 0 0 8862-128-1 /WINDOWS/system32/dllcache/l2store.dll 168 ..c. r/rr-xr-xr-x 0 0 8863-128-1 /WINDOWS/system32/dllcache/l_except.nls 7046 ..c. r/rr-xr-xr-x 0 0 8864-128-1 /WINDOWS/system32/dllcache/l_intl.nls 9728 ..c. r/rr-xr-xr-x 0 0 8865-128-1 /WINDOWS/system32/dllcache/label.exe 89600 ..c. r/rr-xr-xr-x 0 0 8866-128-1 /WINDOWS/system32/dllcache/langwrbk.dll 423936 ..c. r/rr-xr-xr-x 0 0 8867-128-1 /WINDOWS/system32/dllcache/licdll.dll 22016 ..c. r/rr-xr-xr-x 0 0 8868-128-1 /WINDOWS/system32/dllcache/licmgr10.dll 58880 ..c. r/rr-xr-xr-x 0 0 8869-128-1 /WINDOWS/system32/dllcache/licwmi.dll 79128 ..c. r/rr-xr-xr-x 0 0 887-128-3 /WINDOWS/inf/mdmrock5.inf 29696 ..c. r/rr-xr-xr-x 0 0 8870-128-1 /WINDOWS/system32/dllcache/lights.exe 19968 ..c. r/rr-xr-xr-x 0 0 8871-128-1 /WINDOWS/system32/dllcache/linkinfo.dll 13824 ..c. r/rr-xr-xr-x 0 0 8872-128-1 /WINDOWS/system32/dllcache/lmhsvc.dll 33792 ..c. r/rr-xr-xr-x 0 0 8873-128-3 /WINDOWS/system32/dllcache/lmmib2.dll 399872 ..c. r/rr-xr-xr-x 0 0 8874-128-1 /WINDOWS/system32/dllcache/lmrt.dll 25088 ..c. r/rr-xr-xr-x 0 0 8875-128-1 /WINDOWS/system32/dllcache/lnkstub.exe 97280 ..c. r/rr-xr-xr-x 0 0 8876-128-1 /WINDOWS/system32/dllcache/loadperf.dll 265948 ..c. r/rr-xr-xr-x 0 0 8877-128-1 /WINDOWS/system32/dllcache/locale.nls 221696 ..c. r/rr-xr-xr-x 0 0 8878-128-1 /WINDOWS/system32/dllcache/localsec.dll 343040 ..c. r/rr-xr-xr-x 0 0 8879-128-1 /WINDOWS/system32/dllcache/localspl.dll 26660 ..c. r/rr-xr-xr-x 0 0 888-128-3 /WINDOWS/inf/mdmsier.inf 11776 ..c. r/rr-xr-xr-x 0 0 8880-128-1 /WINDOWS/system32/dllcache/localui.dll 75264 ..c. r/rr-xr-xr-x 0 0 8881-128-1 /WINDOWS/system32/dllcache/locator.exe 5120 ..c. r/rr-xr-xr-x 0 0 8882-128-1 /WINDOWS/system32/dllcache/lodctr.exe 19968 ..c. r/rr-xr-xr-x 0 0 8883-128-1 /WINDOWS/system32/dllcache/log.dll 50176 ..c. r/rr-xr-xr-x 0 0 8884-128-1 /WINDOWS/system32/dllcache/loghours.dll 59392 ..c. r/rr-xr-xr-x 0 0 8885-128-1 /WINDOWS/system32/dllcache/logman.exe 15360 ..c. r/rr-xr-xr-x 0 0 8886-128-1 /WINDOWS/system32/dllcache/logoff.exe 220672 ..c. r/rr-xr-xr-x 0 0 8887-128-1 /WINDOWS/system32/dllcache/logon.scr 514560 ..c. r/rr-xr-xr-x 0 0 8888-128-1 /WINDOWS/system32/dllcache/logonui.exe 22016 ..c. r/rr-xr-xr-x 0 0 8889-128-3 /WINDOWS/system32/dllcache/logscrpt.dll 6606 ..c. r/rr-xr-xr-x 0 0 889-128-3 /WINDOWS/inf/mdmsmart.inf 13312 ..c. r/rr-xr-xr-x 0 0 8890-128-3 /WINDOWS/system32/dllcache/lonsint.dll 22528 ..c. r/rr-xr-xr-x 0 0 8891-128-3 /WINDOWS/system32/dllcache/lpdsvc.dll 22016 ..c. r/rr-xr-xr-x 0 0 8892-128-1 /WINDOWS/system32/dllcache/lpk.dll 6144 ..c. r/rr-xr-xr-x 0 0 8893-128-1 /WINDOWS/system32/dllcache/lpq.exe 8192 ..c. r/rr-xr-xr-x 0 0 8894-128-1 /WINDOWS/system32/dllcache/lpr.exe 10240 ..c. r/rr-xr-xr-x 0 0 8895-128-1 /WINDOWS/system32/dllcache/lprhelp.dll 18944 ..c. r/rr-xr-xr-x 0 0 8896-128-3 /WINDOWS/system32/dllcache/lprmon.dll 9216 ..c. r/rr-xr-xr-x 0 0 8897-128-1 /WINDOWS/system32/dllcache/lprmonui.dll 13312 ..c. r/rr-xr-xr-x 0 0 8898-128-1 /WINDOWS/system32/dllcache/lsass.exe 643717 ..c. r/rr-xr-xr-x 0 0 8899-128-1 /WINDOWS/system32/dllcache/ltts1033.lxa 152 .ac. d/dr-xr-xr-x 0 0 89-144-1 /WINDOWS/Debug/UserMode 49212 ..c. r/rr-xr-xr-x 0 0 890-128-3 /WINDOWS/inf/mdmsonyu.inf 4190352 ..c. r/rr-xr-xr-x 0 0 8900-128-1 /WINDOWS/system32/dllcache/luna.mst 2560 ..c. r/rr-xr-xr-x 0 0 8901-128-1 /WINDOWS/system32/dllcache/lz32.dll 8192 ..c. r/rr-xr-xr-x 0 0 8902-128-1 /WINDOWS/system32/dllcache/mag_hook.dll 9936 ..c. r/rr-xr-xr-x 0 0 8903-128-1 /WINDOWS/system32/dllcache/lzexpand.dll 72704 ..c. r/rr-xr-xr-x 0 0 8904-128-1 /WINDOWS/system32/dllcache/magnify.exe 187904 ..c. r/rr-xr-xr-x 0 0 8905-128-1 /WINDOWS/system32/dllcache/main.cpl 65536 ..c. r/rr-xr-xr-x 0 0 8906-128-3 /WINDOWS/system32/dllcache/EXCH_mailmsg.dll 57344 ..c. r/rr-xr-xr-x 0 0 8907-128-1 /WINDOWS/system32/dllcache/makecab.exe 14336 ..c. r/rr-xr-xr-x 0 0 8908-128-1 /WINDOWS/system32/dllcache/mcastmib.dll 7680 ..c. r/rr-xr-xr-x 0 0 8909-128-1 /WINDOWS/system32/dllcache/mcd.sys 41189 ..c. r/rr-xr-xr-x 0 0 891-128-3 /WINDOWS/inf/mdmspq28.inf 10240 ..c. r/rr-xr-xr-x 0 0 8910-128-1 /WINDOWS/system32/dllcache/mcd32.dll 10496 ..c. r/rr-xr-xr-x 0 0 8911-128-1 /WINDOWS/system32/dllcache/mcdsrv32.dll 4608 ..c. r/rr-xr-xr-x 0 0 8912-128-1 /WINDOWS/system32/dllcache/mchgrcoi.dll 84480 ..c. r/rr-xr-xr-x 0 0 8913-128-1 /WINDOWS/system32/dllcache/mciavi32.dll 73376 ..c. r/rr-xr-xr-x 0 0 8914-128-1 /WINDOWS/system32/dllcache/mciavi.drv 17408 ..c. r/rr-xr-xr-x 0 0 8915-128-1 /WINDOWS/system32/dllcache/mcicda.dll 8192 ..c. r/rr-xr-xr-x 0 0 8916-128-1 /WINDOWS/system32/dllcache/mciole16.dll 7680 ..c. r/rr-xr-xr-x 0 0 8917-128-1 /WINDOWS/system32/dllcache/mciole32.dll 35328 ..c. r/rr-xr-xr-x 0 0 8918-128-1 /WINDOWS/system32/dllcache/mciqtz32.dll 23040 ..c. r/rr-xr-xr-x 0 0 8919-128-1 /WINDOWS/system32/dllcache/mciseq.dll 649 ..c. r/rr-xr-xr-x 0 0 892-128-1 /WINDOWS/inf/mdmsetup.inf 23552 ..c. r/rr-xr-xr-x 0 0 8920-128-1 /WINDOWS/system32/dllcache/mciwave.dll 25264 ..c. r/rr-xr-xr-x 0 0 8921-128-1 /WINDOWS/system32/dllcache/mciseq.drv 37888 ..c. r/rr-xr-xr-x 0 0 8922-128-3 /WINDOWS/system32/dllcache/md5filt.dll 28160 ..c. r/rr-xr-xr-x 0 0 8923-128-1 /WINDOWS/system32/dllcache/mciwave.drv 50176 ..c. r/rr-xr-xr-x 0 0 8924-128-1 /WINDOWS/system32/dllcache/mdhcp.dll 118272 ..c. r/rr-xr-xr-x 0 0 8925-128-1 /WINDOWS/system32/dllcache/mdminst.dll 26624 ..c. r/rr-xr-xr-x 0 0 8926-128-3 /WINDOWS/system32/dllcache/mdsync.dll 16896 ..c. r/rr-xr-xr-x 0 0 8927-128-1 /WINDOWS/system32/dllcache/medctroc.dll 39274 ..c. r/rr-xr-xr-x 0 0 8928-128-1 /WINDOWS/system32/dllcache/mem.exe 85504 ..c. r/rr-xr-xr-x 0 0 8929-128-3 /WINDOWS/system32/dllcache/metada51.dll 13934 ..c. r/rr-xr-xr-x 0 0 893-128-3 /WINDOWS/inf/mdmsiil6.INF 40960 ..c. r/rr-xr-xr-x 0 0 8930-128-1 /WINDOWS/system32/dllcache/mf3216.dll 92032 ..c. r/rr-xr-xr-x 0 0 8931-128-3 /WINDOWS/system32/dllcache/mga.dll 92416 ..c. r/rr-xr-xr-x 0 0 8932-128-3 /WINDOWS/system32/dllcache/mga.sys 14848 ..c. r/rr-xr-xr-x 0 0 8933-128-1 /WINDOWS/system32/dllcache/mgmtapi.dll 184320 ..c. r/rr-xr-xr-x 0 0 8934-128-1 /WINDOWS/system32/dllcache/mmc30.dll 18944 ..c. r/rr-xr-xr-x 0 0 8935-128-1 /WINDOWS/system32/dllcache/midimap.dll 274432 ..c. r/rr-xr-xr-x 0 0 8936-128-1 /WINDOWS/system32/dllcache/migism.dll 34304 ..c. r/rr-xr-xr-x 0 0 8937-128-1 /WINDOWS/system32/dllcache/migisol.exe 60928 ..c. r/rr-xr-xr-x 0 0 8938-128-1 /WINDOWS/system32/dllcache/miglibnt.dll 103936 ..c. r/rr-xr-xr-x 0 0 8939-128-1 /WINDOWS/system32/dllcache/migload.exe 13769 ..c. r/rr-xr-xr-x 0 0 894-128-3 /WINDOWS/inf/mdmsii64.INF 786432 ..c. r/rr-xr-xr-x 0 0 8940-128-1 /WINDOWS/system32/dllcache/migrate.exe 7680 ..c. r/rr-xr-xr-x 0 0 8941-128-3 /WINDOWS/system32/dllcache/migregdb.exe 245248 ..c. r/rr-xr-xr-x 0 0 8942-128-1 /WINDOWS/system32/dllcache/migwiz.exe 29696 ..c. r/rr-xr-xr-x 0 0 8943-128-1 /WINDOWS/system32/dllcache/mimefilt.dll 673088 ..c. r/rr-xr-xr-x 0 0 8944-128-1 /WINDOWS/system32/dllcache/mlang.dat 586240 ..c. r/rr-xr-xr-x 0 0 8945-128-1 /WINDOWS/system32/dllcache/mlang.dll 3584 ..c. r/rr-xr-xr-x 0 0 8946-128-1 /WINDOWS/system32/dllcache/mll_hp.dll 7680 ..c. r/rr-xr-xr-x 0 0 8947-128-1 /WINDOWS/system32/dllcache/mll_mtf.dll 5632 ..c. r/rr-xr-xr-x 0 0 8948-128-1 /WINDOWS/system32/dllcache/mll_qic.dll 1414656 ..c. r/rr-xr-xr-x 0 0 8949-128-1 /WINDOWS/system32/dllcache/mmc.exe 5026 ..c. r/rr-xr-xr-x 0 0 895-128-3 /WINDOWS/inf/mdmsun1.inf 163328 ..c. r/rr-xr-xr-x 0 0 8950-128-1 /WINDOWS/system32/dllcache/mmcbase.dll 397312 ..c. r/rr-xr-xr-x 0 0 8951-128-1 /WINDOWS/system32/dllcache/mmcex.dll 106496 ..c. r/rr-xr-xr-x 0 0 8952-128-1 /WINDOWS/system32/dllcache/Mmcfxc.dll 1872896 ..c. r/rr-xr-xr-x 0 0 8953-128-1 /WINDOWS/system32/dllcache/mmcndmgr.dll 33792 ..c. r/rr-xr-xr-x 0 0 8954-128-1 /WINDOWS/system32/dllcache/mmcperf.exe 61440 ..c. r/rr-xr-xr-x 0 0 8955-128-1 /WINDOWS/system32/dllcache/mmcshext.dll 12288 ..c. r/rr-xr-xr-x 0 0 8956-128-1 /WINDOWS/system32/dllcache/mmdrv.dll 17408 ..c. r/rr-xr-xr-x 0 0 8957-128-1 /WINDOWS/system32/dllcache/mmfutil.dll 618496 ..c. r/rr-xr-xr-x 0 0 8958-128-1 /WINDOWS/system32/dllcache/mmsys.cpl 119808 ..c. r/rr-xr-xr-x 0 0 8959-128-1 /WINDOWS/system32/dllcache/mmutilse.dll 21547 ..c. r/rr-xr-xr-x 0 0 896-128-3 /WINDOWS/inf/mdmsun2.inf 68768 ..c. r/rr-xr-xr-x 0 0 8960-128-1 /WINDOWS/system32/dllcache/mmsystem.dll 1152 ..c. r/rr-xr-xr-x 0 0 8961-128-1 /WINDOWS/system32/dllcache/mmtask.tsk 34560 ..c. r/rr-xr-xr-x 0 0 8962-128-1 /WINDOWS/system32/dllcache/mnmdd.dll 4224 ..c. r/rr-xr-xr-x 0 0 8963-128-1 /WINDOWS/system32/dllcache/mnmdd.sys 32768 ..c. r/rr-xr-xr-x 0 0 8964-128-1 /WINDOWS/system32/dllcache/mnmsrvc.exe 207360 ..c. r/rr-xr-xr-x 0 0 8965-128-1 /WINDOWS/system32/dllcache/mobsync.dll 143360 ..c. r/rr-xr-xr-x 0 0 8966-128-1 /WINDOWS/system32/dllcache/mobsync.exe 153600 ..c. r/rr-xr-xr-x 0 0 8967-128-1 /WINDOWS/system32/dllcache/modemui.dll 10112 ..c. r/rr-xr-xr-x 0 0 8968-128-1 /WINDOWS/system32/dllcache/modex.dll 16384 ..c. r/rr-xr-xr-x 0 0 8969-128-1 /WINDOWS/system32/dllcache/mofcomp.exe 29925 ..c. r/rr-xr-xr-x 0 0 897-128-3 /WINDOWS/inf/mdmsupr3.inf 123904 ..c. r/rr-xr-xr-x 0 0 8970-128-1 /WINDOWS/system32/dllcache/mofd.dll 216064 ..c. r/rr-xr-xr-x 0 0 8971-128-1 /WINDOWS/system32/dllcache/moricons.dll 42368 ..c. r/rr-xr-xr-x 0 0 8972-128-1 /WINDOWS/system32/dllcache/mountmgr.sys 8192 ..c. r/rr-xr-xr-x 0 0 8973-128-1 /WINDOWS/system32/dllcache/mountvol.exe 3558912 ..c. r/rr-xr-xr-x 0 0 8974-128-1 /WINDOWS/system32/dllcache/moviemk.exe 2032 ..c. r/rr-xr-xr-x 0 0 8975-128-1 /WINDOWS/system32/dllcache/mouse.drv 310272 ..c. r/rr-xr-xr-x 0 0 8976-128-1 /WINDOWS/system32/dllcache/mp43dmod.dll 384512 ..c. r/rr-xr-xr-x 0 0 8977-128-1 /WINDOWS/system32/dllcache/mp4sdmod.dll 118272 ..c. r/rr-xr-xr-x 0 0 8978-128-1 /WINDOWS/system32/dllcache/mpg2data.ax 148992 ..c. r/rr-xr-xr-x 0 0 8979-128-1 /WINDOWS/system32/dllcache/mpg2splt.ax 116718 ..c. r/rr-xr-xr-x 0 0 898-128-3 /WINDOWS/inf/mdmsupra.inf 240640 ..c. r/rr-xr-xr-x 0 0 8980-128-1 /WINDOWS/system32/dllcache/mpg4dmod.dll 123392 ..c. r/rr-xr-xr-x 0 0 8981-128-1 /WINDOWS/system32/dllcache/mplay32.exe 22016 ..c. r/rr-xr-xr-x 0 0 8982-128-1 /WINDOWS/system32/dllcache/mpnotify.exe 59904 ..c. r/rr-xr-xr-x 0 0 8983-128-1 /WINDOWS/system32/dllcache/mpr.dll 87040 ..c. r/rr-xr-xr-x 0 0 8984-128-1 /WINDOWS/system32/dllcache/mprapi.dll 69120 ..c. r/rr-xr-xr-x 0 0 8985-128-1 /WINDOWS/system32/dllcache/mprddm.dll 53248 ..c. r/rr-xr-xr-x 0 0 8986-128-1 /WINDOWS/system32/dllcache/mprdim.dll 99840 ..c. r/rr-xr-xr-x 0 0 8987-128-1 /WINDOWS/system32/dllcache/mprmsg.dll 47104 ..c. r/rr-xr-xr-x 0 0 8988-128-1 /WINDOWS/system32/dllcache/mprui.dll 368640 ..c. r/rr-xr-xr-x 0 0 8989-128-1 /WINDOWS/system32/dllcache/mpvis.dll 45880 ..c. r/rr-xr-xr-x 0 0 899-128-3 /WINDOWS/inf/mdmtdk.inf 92544 ..c. r/rr-xr-xr-x 0 0 8990-128-1 /WINDOWS/system32/dllcache/mqac.sys 138240 ..c. r/rr-xr-xr-x 0 0 8991-128-1 /WINDOWS/system32/dllcache/mqad.dll 19968 ..c. r/rr-xr-xr-x 0 0 8992-128-1 /WINDOWS/system32/dllcache/mqbkup.exe 10752 ..c. r/rr-xr-xr-x 0 0 8993-128-1 /WINDOWS/system32/dllcache/mqcertui.dll 47616 ..c. r/rr-xr-xr-x 0 0 8994-128-1 /WINDOWS/system32/dllcache/mqdscli.dll 60928 ..c. r/rr-xr-xr-x 0 0 8995-128-1 /WINDOWS/system32/dllcache/mqgentr.dll 16896 ..c. r/rr-xr-xr-x 0 0 8996-128-1 /WINDOWS/system32/dllcache/mqise.dll 89088 ..c. r/rr-xr-xr-x 0 0 8997-128-1 /WINDOWS/system32/dllcache/mqlogmgr.dll 225280 ..c. r/rr-xr-xr-x 0 0 8998-128-1 /WINDOWS/system32/dllcache/mqoa.dll 81408 ..c. r/rr-xr-xr-x 0 0 8999-128-1 /WINDOWS/system32/dllcache/mqoa.tlb 16181 ..c. r/rr-xr-xr-x 0 0 900-128-3 /WINDOWS/inf/mdmtdkj2.inf 36864 ..c. r/rr-xr-xr-x 0 0 9000-128-1 /WINDOWS/system32/dllcache/mqoa10.tlb 55296 ..c. r/rr-xr-xr-x 0 0 9001-128-1 /WINDOWS/system32/dllcache/mqoa20.tlb 8192 ..c. r/rr-xr-xr-x 0 0 9002-128-1 /WINDOWS/system32/dllcache/mqperf.dll 663040 ..c. r/rr-xr-xr-x 0 0 9003-128-1 /WINDOWS/system32/dllcache/mqqm.dll 177152 ..c. r/rr-xr-xr-x 0 0 9004-128-1 /WINDOWS/system32/dllcache/mqrt.dll 123904 ..c. r/rr-xr-xr-x 0 0 9005-128-1 /WINDOWS/system32/dllcache/mqrtdep.dll 95744 ..c. r/rr-xr-xr-x 0 0 9006-128-1 /WINDOWS/system32/dllcache/mqsec.dll 517632 ..c. r/rr-xr-xr-x 0 0 9007-128-1 /WINDOWS/system32/dllcache/mqsnap.dll 4608 ..c. r/rr-xr-xr-x 0 0 9008-128-1 /WINDOWS/system32/dllcache/mqsvc.exe 117248 ..c. r/rr-xr-xr-x 0 0 9009-128-1 /WINDOWS/system32/dllcache/mqtgsvc.exe 18322 ..c. r/rr-xr-xr-x 0 0 901-128-3 /WINDOWS/inf/mdmtdkj3.inf 187392 ..c. r/rr-xr-xr-x 0 0 9010-128-1 /WINDOWS/system32/dllcache/mqtrig.dll 49152 ..c. r/rr-xr-xr-x 0 0 9011-128-1 /WINDOWS/system32/dllcache/mqupgrd.dll 471552 ..c. r/rr-xr-xr-x 0 0 9012-128-1 /WINDOWS/system32/dllcache/mqutil.dll 12800 ..c. r/rr-xr-xr-x 0 0 9013-128-1 /WINDOWS/system32/dllcache/mrinfo.exe 180608 ..c. r/rr-xr-xr-x 0 0 9014-128-1 /WINDOWS/system32/dllcache/mrxdav.sys 102912 ..c. r/rr-xr-xr-x 0 0 9015-128-1 /WINDOWS/system32/dllcache/msaatext.dll 61168 ..c. r/rr-xr-xr-x 0 0 9016-128-1 /WINDOWS/system32/dllcache/msacm.dll 71680 ..c. r/rr-xr-xr-x 0 0 9017-128-1 /WINDOWS/system32/dllcache/msacm32.dll 81920 ..c. r/rr-xr-xr-x 0 0 9018-128-1 /WINDOWS/system32/dllcache/msado25.tlb 81920 ..c. r/rr-xr-xr-x 0 0 9019-128-1 /WINDOWS/system32/dllcache/msado26.tlb 13219 ..c. r/rr-xr-xr-x 0 0 902-128-3 /WINDOWS/inf/mdmtdkj4.inf 81920 ..c. r/rr-xr-xr-x 0 0 9020-128-1 /WINDOWS/system32/dllcache/msado27.tlb 3584 ..c. r/rr-xr-xr-x 0 0 9021-128-1 /WINDOWS/system32/dllcache/msafd.dll 86016 ..c. r/rr-xr-xr-x 0 0 9022-128-1 /WINDOWS/system32/dllcache/msapsspc.dll 57344 ..c. r/rr-xr-xr-x 0 0 9023-128-1 /WINDOWS/system32/dllcache/msasn1.dll 65024 ..c. r/rr-xr-xr-x 0 0 9024-128-1 /WINDOWS/system32/dllcache/msaudite.dll 220160 ..c. r/rr-xr-xr-x 0 0 9025-128-1 /WINDOWS/system32/dllcache/mscandui.dll 7168 ..c. r/rr-xr-xr-x 0 0 9026-128-1 /WINDOWS/system32/dllcache/mscat32.dll 817 ..c. r/rr-xr-xr-x 0 0 9027-128-1 /WINDOWS/system32/dllcache/mscdexnt.exe 73728 ..c. r/rr-xr-xr-x 0 0 9028-128-1 /WINDOWS/system32/dllcache/mscms.dll 69632 ..c. r/rr-xr-xr-x 0 0 9029-128-1 /WINDOWS/system32/dllcache/msconf.dll 18040 ..c. r/rr-xr-xr-x 0 0 903-128-3 /WINDOWS/inf/mdmtdkj5.inf 169984 ..c. r/rr-xr-xr-x 0 0 9030-128-1 /WINDOWS/system32/dllcache/msconfig.exe 12288 ..c. r/rr-xr-xr-x 0 0 9031-128-1 /WINDOWS/system32/dllcache/mscpx32r.dll 297984 ..c. r/rr-xr-xr-x 0 0 9032-128-1 /WINDOWS/system32/dllcache/msctf.dll 177152 ..c. r/rr-xr-xr-x 0 0 9033-128-1 /WINDOWS/system32/dllcache/msctfime.ime 68608 ..c. r/rr-xr-xr-x 0 0 9034-128-1 /WINDOWS/system32/dllcache/msctfp.dll 118784 ..c. r/rr-xr-xr-x 0 0 9035-128-1 /WINDOWS/system32/dllcache/msdadiag.dll 16384 ..c. r/rr-xr-xr-x 0 0 9036-128-1 /WINDOWS/system32/dllcache/msdaorar.dll 151552 ..c. r/rr-xr-xr-x 0 0 9037-128-1 /WINDOWS/system32/dllcache/msdart.dll 94208 ..c. r/rr-xr-xr-x 0 0 9038-128-1 /WINDOWS/system32/dllcache/msdatl3.dll 14336 ..c. r/rr-xr-xr-x 0 0 9039-128-1 /WINDOWS/system32/dllcache/msdmo.dll 9891 ..c. r/rr-xr-xr-x 0 0 904-128-3 /WINDOWS/inf/mdmtdkj6.inf 6144 ..c. r/rr-xr-xr-x 0 0 9040-128-1 /WINDOWS/system32/dllcache/msdtc.exe 58880 ..c. r/rr-xr-xr-x 0 0 9041-128-1 /WINDOWS/system32/dllcache/msdtclog.dll 427008 ..c. r/rr-xr-xr-x 0 0 9042-128-1 /WINDOWS/system32/dllcache/msdtcprx.dll 90112 ..c. r/rr-xr-xr-x 0 0 9043-128-1 /WINDOWS/system32/dllcache/msdtcstp.dll 956928 ..c. r/rr-xr-xr-x 0 0 9044-128-1 /WINDOWS/system32/dllcache/msdtctm.dll 161792 ..c. r/rr-xr-xr-x 0 0 9045-128-1 /WINDOWS/system32/dllcache/msdtcuiu.dll 19072 ..c. r/rr-xr-xr-x 0 0 9046-128-1 /WINDOWS/system32/dllcache/msfs.sys 539136 ..c. r/rr-xr-xr-x 0 0 9047-128-1 /WINDOWS/system32/dllcache/msftedit.dll 20992 ..c. r/rr-xr-xr-x 0 0 9048-128-1 /WINDOWS/system32/dllcache/msg.exe 997376 ..c. r/rr-xr-xr-x 0 0 9049-128-1 /WINDOWS/system32/dllcache/msgina.dll 12840 ..c. r/rr-xr-xr-x 0 0 905-128-3 /WINDOWS/inf/mdmtdkj7.inf 35072 ..c. r/rr-xr-xr-x 0 0 9050-128-1 /WINDOWS/system32/dllcache/msgpc.sys 3166208 ..c. r/rr-xr-xr-x 0 0 9051-128-1 /WINDOWS/system32/dllcache/msgr3en.dll 15360 ..c. r/rr-xr-xr-x 0 0 9052-128-1 /WINDOWS/system32/dllcache/msgrocm.dll 33792 ..c. r/rr-xr-xr-x 0 0 9053-128-1 /WINDOWS/system32/dllcache/msgsvc.dll 126976 ..c. r/rr-xr-xr-x 0 0 9054-128-1 /WINDOWS/system32/dllcache/mshearts.exe 29184 ..c. r/rr-xr-xr-x 0 0 9055-128-1 /WINDOWS/system32/dllcache/mshta.exe 3066880 ..c. r/rr-xr-xr-x 0 0 9056-128-1 /WINDOWS/system32/dllcache/mshtml.dll 1351168 ..c. r/rr-xr-xr-x 0 0 9057-128-1 /WINDOWS/system32/dllcache/mshtml.tlb 449024 ..c. r/rr-xr-xr-x 0 0 9058-128-1 /WINDOWS/system32/dllcache/mshtmled.dll 56832 ..c. r/rr-xr-xr-x 0 0 9059-128-1 /WINDOWS/system32/dllcache/mshtmler.dll 9421 ..c. r/rr-xr-xr-x 0 0 906-128-3 /WINDOWS/inf/mdmtexas.inf 2843136 ..c. r/rr-xr-xr-x 0 0 9060-128-1 /WINDOWS/system32/dllcache/msi.dll 51712 ..c. r/rr-xr-xr-x 0 0 9061-128-1 /WINDOWS/system32/dllcache/msident.dll 6656 ..c. r/rr-xr-xr-x 0 0 9062-128-1 /WINDOWS/system32/dllcache/msidle.dll 14848 ..c. r/rr-xr-xr-x 0 0 9063-128-1 /WINDOWS/system32/dllcache/msidntld.dll 248832 ..c. r/rr-xr-xr-x 0 0 9064-128-1 /WINDOWS/system32/dllcache/msieftp.dll 78848 ..c. r/rr-xr-xr-x 0 0 9065-128-1 /WINDOWS/system32/dllcache/msiexec.exe 271360 ..c. r/rr-xr-xr-x 0 0 9066-128-1 /WINDOWS/system32/dllcache/msihnd.dll 4608 ..c. r/rr-xr-xr-x 0 0 9067-128-1 /WINDOWS/system32/dllcache/msimg32.dll 60416 ..c. r/rr-xr-xr-x 0 0 9068-128-1 /WINDOWS/system32/dllcache/msimn.exe 884736 ..c. r/rr-xr-xr-x 0 0 9069-128-1 /WINDOWS/system32/dllcache/msimsg.dll 35903 ..c. r/rr-xr-xr-x 0 0 907-128-3 /WINDOWS/inf/mdmti.inf 159232 ..c. r/rr-xr-xr-x 0 0 9070-128-1 /WINDOWS/system32/dllcache/msimtf.dll 376832 ..c. r/rr-xr-xr-x 0 0 9071-128-1 /WINDOWS/system32/dllcache/msinfo.dll 39936 ..c. r/rr-xr-xr-x 0 0 9072-128-1 /WINDOWS/system32/dllcache/msinfo32.exe 273920 ..c. r/rr-xr-xr-x 0 0 9073-128-1 /WINDOWS/system32/dllcache/msiprov.dll 98304 ..c. r/rr-xr-xr-x 0 0 9074-128-3 /WINDOWS/system32/dllcache/msir3jp.dll 1875968 ..c. r/rr-xr-xr-x 0 0 9075-128-3 /WINDOWS/system32/dllcache/msir3jp.lex 40960 ..c. r/rr-xr-xr-x 0 0 9076-128-3 /WINDOWS/system32/dllcache/msiregmv.exe 15360 ..c. r/rr-xr-xr-x 0 0 9077-128-1 /WINDOWS/system32/dllcache/msisip.dll 355112 ..c. r/rr-xr-xr-x 0 0 9078-128-1 /WINDOWS/system32/dllcache/msjetol1.dll 25088 ..c. r/rr-xr-xr-x 0 0 9079-128-1 /WINDOWS/system32/dllcache/mslbui.dll 33891 ..c. r/rr-xr-xr-x 0 0 908-128-3 /WINDOWS/inf/mdmtosh.inf 146432 ..c. r/rr-xr-xr-x 0 0 9080-128-1 /WINDOWS/system32/dllcache/msls31.dll 39936 ..c. r/rr-xr-xr-x 0 0 9081-128-1 /WINDOWS/system32/dllcache/mslwvtts.dll 170496 ..c. r/rr-xr-xr-x 0 0 9082-128-1 /WINDOWS/system32/dllcache/msmqocm.dll 259072 ..c. r/rr-xr-xr-x 0 0 9083-128-1 /WINDOWS/system32/dllcache/msnetobj.dll 290816 ..c. r/rr-xr-xr-x 0 0 9084-128-1 /WINDOWS/system32/dllcache/msnsspc.dll 122368 ..c. r/rr-xr-xr-x 0 0 9085-128-1 /WINDOWS/system32/dllcache/msobcomm.dll 16384 ..c. r/rr-xr-xr-x 0 0 9086-128-1 /WINDOWS/system32/dllcache/msobdl.dll 33280 ..c. r/rr-xr-xr-x 0 0 9087-128-1 /WINDOWS/system32/dllcache/msobjs.dll 565248 ..c. r/rr-xr-xr-x 0 0 9088-128-1 /WINDOWS/system32/dllcache/msobmain.dll 30720 ..c. r/rr-xr-xr-x 0 0 9089-128-1 /WINDOWS/system32/dllcache/msobshel.dll 13556 ..c. r/rr-xr-xr-x 0 0 909-128-3 /WINDOWS/inf/mdmtron.inf 19456 ..c. r/rr-xr-xr-x 0 0 9090-128-1 /WINDOWS/system32/dllcache/msobweb.dll 1314816 ..c. r/rr-xr-xr-x 0 0 9091-128-1 /WINDOWS/system32/dllcache/msoe.dll 252928 ..c. r/rr-xr-xr-x 0 0 9092-128-1 /WINDOWS/system32/dllcache/msoeacct.dll 2479616 ..c. r/rr-xr-xr-x 0 0 9093-128-1 /WINDOWS/system32/dllcache/msoeres.dll 105984 ..c. r/rr-xr-xr-x 0 0 9094-128-1 /WINDOWS/system32/dllcache/msoert2.dll 29184 ..c. r/rr-xr-xr-x 0 0 9095-128-1 /WINDOWS/system32/dllcache/msoobe.exe 20480 ..c. r/rr-xr-xr-x 0 0 9096-128-1 /WINDOWS/system32/dllcache/msorc32r.dll 343040 ..c. r/rr-xr-xr-x 0 0 9097-128-1 /WINDOWS/system32/dllcache/mspaint.exe 29696 ..c. r/rr-xr-xr-x 0 0 9098-128-1 /WINDOWS/system32/dllcache/mspatcha.dll 52224 ..c. r/rr-xr-xr-x 0 0 9099-128-1 /WINDOWS/system32/dllcache/mspmsnsv.dll 472 .ac. d/dr-xr-xr-x 0 0 91-144-1 /WINDOWS/Help/Tours 3032 ..c. r/rr-xr-xr-x 0 0 910-128-3 /WINDOWS/inf/mdmusrf.inf 201728 ..c. r/rr-xr-xr-x 0 0 9100-128-1 /WINDOWS/system32/dllcache/mspmsp.dll 41984 ..c. r/rr-xr-xr-x 0 0 9101-128-1 /WINDOWS/system32/dllcache/msports.dll 48128 ..c. r/rr-xr-xr-x 0 0 9102-128-1 /WINDOWS/system32/dllcache/msprivs.dll 69632 ..c. r/rr-xr-xr-x 0 0 9103-128-1 /WINDOWS/system32/dllcache/msr2c.dll 7168 ..c. r/rr-xr-xr-x 0 0 9104-128-1 /WINDOWS/system32/dllcache/msr2cenu.dll 60416 ..c. r/rr-xr-xr-x 0 0 9105-128-1 /WINDOWS/system32/dllcache/msratelc.dll 146432 ..c. r/rr-xr-xr-x 0 0 9106-128-1 /WINDOWS/system32/dllcache/msrating.dll 11264 ..c. r/rr-xr-xr-x 0 0 9107-128-1 /WINDOWS/system32/dllcache/msrle32.dll 134656 ..c. r/rr-xr-xr-x 0 0 9108-128-1 /WINDOWS/system32/dllcache/mssap.dll 69632 ..c. r/rr-xr-xr-x 0 0 9109-128-1 /WINDOWS/system32/dllcache/msscds32.ax 12211 ..c. r/rr-xr-xr-x 0 0 911-128-3 /WINDOWS/inf/mdmusrg.inf 356352 ..c. r/rr-xr-xr-x 0 0 9110-128-1 /WINDOWS/system32/dllcache/msscp.dll 110592 ..c. r/rr-xr-xr-x 0 0 9111-128-1 /WINDOWS/system32/dllcache/msscript.ocx 155136 ..c. r/rr-xr-xr-x 0 0 9112-128-1 /WINDOWS/system32/dllcache/mssha.dll 76800 ..c. r/rr-xr-xr-x 0 0 9113-128-1 /WINDOWS/system32/dllcache/msshamsg.dll 35840 ..c. r/rr-xr-xr-x 0 0 9114-128-1 /WINDOWS/system32/dllcache/mssign32.dll 235520 ..c. r/rr-xr-xr-x 0 0 9115-128-1 /WINDOWS/system32/dllcache/mssoap1.dll 23552 ..c. r/rr-xr-xr-x 0 0 9116-128-1 /WINDOWS/system32/dllcache/mssoapr.dll 13312 ..c. r/rr-xr-xr-x 0 0 9117-128-1 /WINDOWS/system32/dllcache/msswch.dll 6656 ..c. r/rr-xr-xr-x 0 0 9118-128-1 /WINDOWS/system32/dllcache/msswchx.exe 274432 ..c. r/rr-xr-xr-x 0 0 9119-128-1 /WINDOWS/system32/dllcache/mst120.dll 57364 ..c. r/rr-xr-xr-x 0 0 912-128-3 /WINDOWS/inf/mdmusrgl.inf 57344 ..c. r/rr-xr-xr-x 0 0 9120-128-1 /WINDOWS/system32/dllcache/mst123.dll 274944 ..c. r/rr-xr-xr-x 0 0 9121-128-1 /WINDOWS/system32/dllcache/mstask.dll 532480 ..c. r/rr-xr-xr-x 0 0 9122-128-1 /WINDOWS/system32/dllcache/mstime.dll 12288 ..c. r/rr-xr-xr-x 0 0 9123-128-1 /WINDOWS/system32/dllcache/mstinit.exe 116224 ..c. r/rr-xr-xr-x 0 0 9124-128-1 /WINDOWS/system32/dllcache/mstlsapi.dll 677888 ..c. r/rr-xr-xr-x 0 0 9125-128-1 /WINDOWS/system32/dllcache/lhmstsc.exe 2061824 ..c. r/rr-xr-xr-x 0 0 9126-128-1 /WINDOWS/system32/dllcache/lhmstscx.dll 195072 ..c. r/rr-xr-xr-x 0 0 9127-128-1 /WINDOWS/system32/dllcache/msutb.dll 132608 ..c. r/rr-xr-xr-x 0 0 9128-128-1 /WINDOWS/system32/dllcache/msv1_0.dll 57344 ..c. r/rr-xr-xr-x 0 0 9129-128-1 /WINDOWS/system32/dllcache/msvcirt.dll 3736 ..c. r/rr-xr-xr-x 0 0 913-128-3 /WINDOWS/inf/mdmusrsp.inf 565760 ..c. r/rr-xr-xr-x 0 0 9130-128-1 /WINDOWS/system32/dllcache/msvcp50.dll 413696 ..c. r/rr-xr-xr-x 0 0 9131-128-1 /WINDOWS/system32/dllcache/msvcp60.dll 253952 ..c. r/rr-xr-xr-x 0 0 9132-128-1 /WINDOWS/system32/dllcache/msvcrt20.dll 121344 ..c. r/rr-xr-xr-x 0 0 9133-128-1 /WINDOWS/system32/dllcache/msvfw32.dll 25600 ..c. r/rr-xr-xr-x 0 0 9134-128-1 /WINDOWS/system32/dllcache/msvidc32.dll 1428992 ..c. r/rr-xr-xr-x 0 0 9135-128-1 /WINDOWS/system32/dllcache/msvidctl.dll 72704 ..c. r/rr-xr-xr-x 0 0 9136-128-1 /WINDOWS/system32/dllcache/msw3prt.dll 126912 ..c. r/rr-xr-xr-x 0 0 9137-128-1 /WINDOWS/system32/dllcache/msvideo.dll 203776 ..c. r/rr-xr-xr-x 0 0 9138-128-1 /WINDOWS/system32/dllcache/mswebdvd.dll 245760 ..c. r/rr-xr-xr-x 0 0 9139-128-1 /WINDOWS/system32/dllcache/mswmdm.dll 2423 ..c. r/rr-xr-xr-x 0 0 914-128-3 /WINDOWS/inf/mdmvdot.inf 245248 ..c. r/rr-xr-xr-x 0 0 9140-128-1 /WINDOWS/system32/dllcache/mswsock.dll 506368 ..c. r/rr-xr-xr-x 0 0 9141-128-1 /WINDOWS/system32/dllcache/msxml.dll 701440 ..c. r/rr-xr-xr-x 0 0 9142-128-1 /WINDOWS/system32/dllcache/msxml2.dll 37916 ..c. r/rr-xr-xr-x 0 0 9143-128-1 /WINDOWS/system32/dllcache/msxml2r.dll 1104896 ..c. r/rr-xr-xr-x 0 0 9144-128-1 /WINDOWS/system32/dllcache/msxml3.dll 44032 ..c. r/rr-xr-xr-x 0 0 9145-128-1 /WINDOWS/system32/dllcache/msxml3r.dll 26624 ..c. r/rr-xr-xr-x 0 0 9146-128-1 /WINDOWS/system32/dllcache/msxmlr.dll 1306624 ..c. r/rr-xr-xr-x 0 0 9147-128-1 /WINDOWS/system32/dllcache/msxml6.dll 79872 ..c. r/rr-xr-xr-x 0 0 9148-128-1 /WINDOWS/system32/dllcache/msxml6r.dll 19456 ..c. r/rr-xr-xr-x 0 0 9149-128-1 /WINDOWS/system32/dllcache/mtsadmin.tlb 130588 ..c. r/rr-xr-xr-x 0 0 915-128-3 /WINDOWS/inf/mdmwhql0.inf 119808 ..c. r/rr-xr-xr-x 0 0 9150-128-3 /WINDOWS/system32/dllcache/mtstocom.exe 66560 ..c. r/rr-xr-xr-x 0 0 9151-128-1 /WINDOWS/system32/dllcache/mtxclu.dll 30720 ..c. r/rr-xr-xr-x 0 0 9152-128-1 /WINDOWS/system32/dllcache/mtxdm.dll 4096 ..c. r/rr-xr-xr-x 0 0 9153-128-1 /WINDOWS/system32/dllcache/mtxex.dll 34304 ..c. r/rr-xr-xr-x 0 0 9154-128-1 /WINDOWS/system32/dllcache/mtxlegih.dll 91648 ..c. r/rr-xr-xr-x 0 0 9155-128-1 /WINDOWS/system32/dllcache/mtxoci.dll 90624 ..c. r/rr-xr-xr-x 0 0 9156-128-1 /WINDOWS/system32/dllcache/muisetup.exe 229439 ..c. r/rr-xr-xr-x 0 0 9157-128-3 /WINDOWS/system32/dllcache/multibox.dll 105344 ..c. r/rr-xr-xr-x 0 0 9158-128-1 /WINDOWS/system32/dllcache/mup.sys 90112 ..c. r/rr-xr-xr-x 0 0 9159-128-1 /WINDOWS/system32/dllcache/mycomput.dll 37708 ..c. r/rr-xr-xr-x 0 0 916-128-3 /WINDOWS/inf/mdmx5560.inf 90624 ..c. r/rr-xr-xr-x 0 0 9160-128-1 /WINDOWS/system32/dllcache/mydocs.dll 221184 ..c. r/rr-xr-xr-x 0 0 9161-128-1 /WINDOWS/system32/dllcache/nac.dll 30208 ..c. r/rr-xr-xr-x 0 0 9162-128-1 /WINDOWS/system32/dllcache/napipsec.dll 193024 ..c. r/rr-xr-xr-x 0 0 9163-128-1 /WINDOWS/system32/dllcache/napmontr.dll 176640 ..c. r/rr-xr-xr-x 0 0 9164-128-1 /WINDOWS/system32/dllcache/napstat.exe 53760 ..c. r/rr-xr-xr-x 0 0 9165-128-1 /WINDOWS/system32/dllcache/narrator.exe 35840 ..c. r/rr-xr-xr-x 0 0 9166-128-1 /WINDOWS/system32/dllcache/narrhook.dll 20480 ..c. r/rr-xr-xr-x 0 0 9167-128-1 /WINDOWS/system32/dllcache/nbtstat.exe 36352 ..c. r/rr-xr-xr-x 0 0 9168-128-1 /WINDOWS/system32/dllcache/ncobjapi.dll 35840 ..c. r/rr-xr-xr-x 0 0 9169-128-1 /WINDOWS/system32/dllcache/ncpa.cpl 108001 ..c. r/rr-xr-xr-x 0 0 917-128-3 /WINDOWS/inf/mdmzoom.inf 47104 ..c. r/rr-xr-xr-x 0 0 9170-128-1 /WINDOWS/system32/dllcache/ncprov.dll 7680 ..c. r/rr-xr-xr-x 0 0 9171-128-1 /WINDOWS/system32/dllcache/ncxpnt.dll 17920 ..c. r/rr-xr-xr-x 0 0 9172-128-1 /WINDOWS/system32/dllcache/nddeapi.dll 4096 ..c. r/rr-xr-xr-x 0 0 9173-128-1 /WINDOWS/system32/dllcache/nddeapir.exe 18944 ..c. r/rr-xr-xr-x 0 0 9174-128-1 /WINDOWS/system32/dllcache/nddenb32.dll 182656 ..c. r/rr-xr-xr-x 0 0 9175-128-1 /WINDOWS/system32/dllcache/ndis.sys 57344 ..c. r/rr-xr-xr-x 0 0 9176-128-1 /WINDOWS/system32/dllcache/ndisnpp.dll 10112 ..c. r/rr-xr-xr-x 0 0 9177-128-1 /WINDOWS/system32/dllcache/ndistapi.sys 40576 ..c. r/rr-xr-xr-x 0 0 9178-128-1 /WINDOWS/system32/dllcache/ndproxy.sys 56832 ..c. r/rr-xr-xr-x 0 0 9179-128-1 /WINDOWS/system32/dllcache/ndptsp.tsp 52556 ..c. r/rr-xr-xr-x 0 0 918-128-3 /WINDOWS/inf/mdmzyp.inf 42496 ..c. r/rr-xr-xr-x 0 0 9180-128-1 /WINDOWS/system32/dllcache/net.exe 124928 ..c. r/rr-xr-xr-x 0 0 9181-128-1 /WINDOWS/system32/dllcache/net1.exe 108464 ..c. r/rr-xr-xr-x 0 0 9182-128-1 /WINDOWS/system32/dllcache/netapi.dll 34688 ..c. r/rr-xr-xr-x 0 0 9183-128-1 /WINDOWS/system32/dllcache/netbios.sys 162816 ..c. r/rr-xr-xr-x 0 0 9184-128-1 /WINDOWS/system32/dllcache/netbt.sys 622592 ..c. r/rr-xr-xr-x 0 0 9185-128-1 /WINDOWS/system32/dllcache/netcfgx.dll 111104 ..c. r/rr-xr-xr-x 0 0 9186-128-1 /WINDOWS/system32/dllcache/netdde.exe 214016 ..c. r/rr-xr-xr-x 0 0 9187-128-1 /WINDOWS/system32/dllcache/netevent.dll 126976 ..c. r/rr-xr-xr-x 0 0 9188-128-1 /WINDOWS/system32/dllcache/netfxocm.dll 253952 ..c. r/rr-xr-xr-x 0 0 9189-128-1 /WINDOWS/system32/dllcache/neth.dll 80419 ..c. r/rr-xr-xr-x 0 0 919-128-3 /WINDOWS/inf/mdmzyxel.inf 139264 ..c. r/rr-xr-xr-x 0 0 9190-128-1 /WINDOWS/system32/dllcache/netid.dll 407040 ..c. r/rr-xr-xr-x 0 0 9191-128-1 /WINDOWS/system32/dllcache/netlogon.dll 198144 ..c. r/rr-xr-xr-x 0 0 9192-128-1 /WINDOWS/system32/dllcache/netman.dll 171008 ..c. r/rr-xr-xr-x 0 0 9193-128-1 /WINDOWS/system32/dllcache/netmsg.dll 77312 ..c. r/rr-xr-xr-x 0 0 9194-128-1 /WINDOWS/system32/dllcache/netoc.dll 875008 ..c. r/rr-xr-xr-x 0 0 9195-128-1 /WINDOWS/system32/dllcache/netplwiz.dll 11776 ..c. r/rr-xr-xr-x 0 0 9196-128-1 /WINDOWS/system32/dllcache/netrap.dll 25600 ..c. r/rr-xr-xr-x 0 0 9197-128-1 /WINDOWS/system32/dllcache/netsetup.cpl 329728 ..c. r/rr-xr-xr-x 0 0 9198-128-1 /WINDOWS/system32/dllcache/netsetup.exe 86016 ..c. r/rr-xr-xr-x 0 0 9199-128-1 /WINDOWS/system32/dllcache/netsh.exe 144 .a.. d/dr-xr-xr-x 0 0 92-144-1 /WINDOWS/Resources 103924 ..c. r/rr-xr-xr-x 0 0 920-128-3 /WINDOWS/inf/mdmzyxlg.inf 1703936 ..c. r/rr-xr-xr-x 0 0 9200-128-1 /WINDOWS/system32/dllcache/netshell.dll 36864 ..c. r/rr-xr-xr-x 0 0 9201-128-1 /WINDOWS/system32/dllcache/netstat.exe 80896 ..c. r/rr-xr-xr-x 0 0 9202-128-1 /WINDOWS/system32/dllcache/netui0.dll 245760 ..c. r/rr-xr-xr-x 0 0 9203-128-1 /WINDOWS/system32/dllcache/netui1.dll 308224 ..c. r/rr-xr-xr-x 0 0 9204-128-1 /WINDOWS/system32/dllcache/netui2.dll 247808 ..c. r/rr-xr-xr-x 0 0 9205-128-1 /WINDOWS/system32/dllcache/newdev.dll 53248 ..c. r/rr-xr-xr-x 0 0 9206-128-3 /WINDOWS/system32/dllcache/nextlink.dll 98304 ..c. r/rr-xr-xr-x 0 0 9207-128-1 /WINDOWS/system32/dllcache/nlhtml.dll 4399505 ..c. r/rr-xr-xr-x 0 0 9208-128-1 /WINDOWS/system32/dllcache/nls302en.lex 7052 ..c. r/rr-xr-xr-x 0 0 9209-128-1 /WINDOWS/system32/dllcache/nlsfunc.exe 229376 ..c. r/rr-xr-xr-x 0 0 9210-128-1 /WINDOWS/system32/dllcache/nmas.dll 28672 ..c. r/rr-xr-xr-x 0 0 9211-128-1 /WINDOWS/system32/dllcache/nmasnt.dll 81920 ..c. r/rr-xr-xr-x 0 0 9212-128-1 /WINDOWS/system32/dllcache/nmchat.dll 77824 ..c. r/rr-xr-xr-x 0 0 9213-128-1 /WINDOWS/system32/dllcache/nmcom.dll 12288 ..c. r/rr-xr-xr-x 0 0 9214-128-1 /WINDOWS/system32/dllcache/nmevtmsg.dll 151552 ..c. r/rr-xr-xr-x 0 0 9215-128-1 /WINDOWS/system32/dllcache/nmft.dll 28672 ..c. r/rr-xr-xr-x 0 0 9216-128-1 /WINDOWS/system32/dllcache/nmmkcert.dll 40320 ..c. r/rr-xr-xr-x 0 0 9217-128-1 /WINDOWS/system32/dllcache/nmnt.sys 172032 ..c. r/rr-xr-xr-x 0 0 9218-128-1 /WINDOWS/system32/dllcache/nmoldwb.dll 188416 ..c. r/rr-xr-xr-x 0 0 9219-128-1 /WINDOWS/system32/dllcache/nmwb.dll 35328 ..c. r/rr-xr-xr-x 0 0 9220-128-1 /WINDOWS/system32/dllcache/notiflag.exe 69120 ..c. r/rr-xr-xr-x 0 0 9221-128-1 /WINDOWS/system32/dllcache/notepad.exe 226816 ..c. r/rr-xr-xr-x 0 0 9222-128-1 /WINDOWS/system32/dllcache/npdrmv2.dll 30848 ..c. r/rr-xr-xr-x 0 0 9223-128-1 /WINDOWS/system32/dllcache/npfs.sys 15360 ..c. r/rr-xr-xr-x 0 0 9224-128-1 /WINDOWS/system32/dllcache/nppagent.exe 54784 ..c. r/rr-xr-xr-x 0 0 9225-128-1 /WINDOWS/system32/dllcache/npptools.dll 44544 ..c. r/rr-xr-xr-x 0 0 9226-128-3 /WINDOWS/system32/dllcache/nsepm.dll 76800 ..c. r/rr-xr-xr-x 0 0 9227-128-1 /WINDOWS/system32/dllcache/nslookup.exe 1200640 ..c. r/rr-xr-xr-x 0 0 9228-128-1 /WINDOWS/system32/dllcache/ntbackup.exe 27866 ..c. r/rr-xr-xr-x 0 0 9229-128-1 /WINDOWS/system32/dllcache/ntdos.sys 13259 ..c. r/rr-xr-xr-x 0 0 923-128-3 /WINDOWS/inf/memcard.inf 29146 ..c. r/rr-xr-xr-x 0 0 9230-128-1 /WINDOWS/system32/dllcache/ntdos404.sys 29370 ..c. r/rr-xr-xr-x 0 0 9231-128-1 /WINDOWS/system32/dllcache/ntdos411.sys 29274 ..c. r/rr-xr-xr-x 0 0 9232-128-1 /WINDOWS/system32/dllcache/ntdos412.sys 29146 ..c. r/rr-xr-xr-x 0 0 9233-128-1 /WINDOWS/system32/dllcache/ntdos804.sys 67072 ..c. r/rr-xr-xr-x 0 0 9234-128-1 /WINDOWS/system32/dllcache/ntdsapi.dll 26112 ..c. r/rr-xr-xr-x 0 0 9235-128-1 /WINDOWS/system32/dllcache/ntdsbcli.dll 212992 ..c. r/rr-xr-xr-x 0 0 9236-128-1 /WINDOWS/system32/dllcache/ntevt.dll 33840 ..c. r/rr-xr-xr-x 0 0 9237-128-1 /WINDOWS/system32/dllcache/ntio.sys 38912 ..c. r/rr-xr-xr-x 0 0 9238-128-3 /WINDOWS/system32/dllcache/EXCH_ntfsdrv.dll 34560 ..c. r/rr-xr-xr-x 0 0 9239-128-1 /WINDOWS/system32/dllcache/ntio404.sys 2257 ..c. r/rr-xr-xr-x 0 0 924-128-3 /WINDOWS/inf/memstpci.inf 35648 ..c. r/rr-xr-xr-x 0 0 9240-128-1 /WINDOWS/system32/dllcache/ntio411.sys 35424 ..c. r/rr-xr-xr-x 0 0 9241-128-1 /WINDOWS/system32/dllcache/ntio412.sys 34560 ..c. r/rr-xr-xr-x 0 0 9242-128-1 /WINDOWS/system32/dllcache/ntio804.sys 44032 ..c. r/rr-xr-xr-x 0 0 9243-128-1 /WINDOWS/system32/dllcache/ntlanman.dll 57856 ..c. r/rr-xr-xr-x 0 0 9244-128-1 /WINDOWS/system32/dllcache/ntlanui.dll 14336 ..c. r/rr-xr-xr-x 0 0 9245-128-1 /WINDOWS/system32/dllcache/ntlanui2.dll 8192 ..c. r/rr-xr-xr-x 0 0 9246-128-1 /WINDOWS/system32/dllcache/ntlsapi.dll 118784 ..c. r/rr-xr-xr-x 0 0 9247-128-1 /WINDOWS/system32/dllcache/ntmarta.dll 40960 ..c. r/rr-xr-xr-x 0 0 9248-128-1 /WINDOWS/system32/dllcache/ntmsapi.dll 179200 ..c. r/rr-xr-xr-x 0 0 9249-128-1 /WINDOWS/system32/dllcache/ntmsdba.dll 362496 ..c. r/rr-xr-xr-x 0 0 925-128-3 /WINDOWS/Resources/Themes/Luna/Shell/Metallic/shellstyle.dll 36864 ..c. r/rr-xr-xr-x 0 0 9250-128-1 /WINDOWS/system32/dllcache/ntmsevt.dll 488448 ..c. r/rr-xr-xr-x 0 0 9251-128-1 /WINDOWS/system32/dllcache/ntmsmgr.dll 435200 ..c. r/rr-xr-xr-x 0 0 9252-128-1 /WINDOWS/system32/dllcache/ntmssvc.dll 62976 ..c. r/rr-xr-xr-x 0 0 9253-128-1 /WINDOWS/system32/dllcache/ntoc.dll 91136 ..c. r/rr-xr-xr-x 0 0 9254-128-1 /WINDOWS/system32/dllcache/ntprint.dll 31744 ..c. r/rr-xr-xr-x 0 0 9255-128-1 /WINDOWS/system32/dllcache/ntsd.exe 36864 ..c. r/rr-xr-xr-x 0 0 9256-128-1 /WINDOWS/system32/dllcache/ntsdexts.dll 143360 ..c. r/rr-xr-xr-x 0 0 9257-128-1 /WINDOWS/system32/dllcache/ntshrui.dll 420864 ..c. r/rr-xr-xr-x 0 0 9258-128-1 /WINDOWS/system32/dllcache/ntvdm.exe 15360 ..c. r/rr-xr-xr-x 0 0 9259-128-1 /WINDOWS/system32/dllcache/ntvdmd.dll 1316 ..c. r/rr-xr-xr-x 0 0 926-128-3 /WINDOWS/inf/mf.inf 2944 ..c. r/rr-xr-xr-x 0 0 9260-128-1 /WINDOWS/system32/dllcache/null.sys 257024 ..c. r/rr-xr-xr-x 0 0 9261-128-1 /WINDOWS/system32/dllcache/nusrmgr.cpl 3252 ..c. r/rr-xr-xr-x 0 0 9262-128-1 /WINDOWS/system32/dllcache/nw16.exe 20480 ..c. r/rr-xr-xr-x 0 0 9263-128-1 /WINDOWS/system32/dllcache/nwcfg.dll 6144 ..c. r/rr-xr-xr-x 0 0 9264-128-1 /WINDOWS/system32/dllcache/nwevent.dll 12416 ..c. r/rr-xr-xr-x 0 0 9265-128-1 /WINDOWS/system32/dllcache/nwlnkflt.sys 32512 ..c. r/rr-xr-xr-x 0 0 9266-128-1 /WINDOWS/system32/dllcache/nwlnkfwd.sys 88320 ..c. r/rr-xr-xr-x 0 0 9267-128-1 /WINDOWS/system32/dllcache/nwlnkipx.sys 63232 ..c. r/rr-xr-xr-x 0 0 9268-128-1 /WINDOWS/system32/dllcache/nwlnknb.sys 55936 ..c. r/rr-xr-xr-x 0 0 9269-128-1 /WINDOWS/system32/dllcache/nwlnkspx.sys 142336 ..c. r/rr-xr-xr-x 0 0 9270-128-1 /WINDOWS/system32/dllcache/nwprovau.dll 163584 ..c. r/rr-xr-xr-x 0 0 9271-128-1 /WINDOWS/system32/dllcache/nwrdr.sys 126464 ..c. r/rr-xr-xr-x 0 0 9272-128-1 /WINDOWS/system32/dllcache/nwscript.exe 65536 ..c. r/rr-xr-xr-x 0 0 9273-128-1 /WINDOWS/system32/dllcache/nwwks.dll 270336 ..c. r/rr-xr-xr-x 0 0 9274-128-1 /WINDOWS/system32/dllcache/oakley.dll 286208 ..c. r/rr-xr-xr-x 0 0 9275-128-1 /WINDOWS/system32/dllcache/objsel.dll 96256 ..c. r/rr-xr-xr-x 0 0 9276-128-1 /WINDOWS/system32/dllcache/occache.dll 15360 ..c. r/rr-xr-xr-x 0 0 9277-128-1 /WINDOWS/system32/dllcache/ocgen.dll 17408 ..c. r/rr-xr-xr-x 0 0 9278-128-1 /WINDOWS/system32/dllcache/ocmsn.dll 26224 ..c. r/rr-xr-xr-x 0 0 9279-128-1 /WINDOWS/system32/dllcache/odbc16gt.dll 23439 ..c. r/rr-xr-xr-x 0 0 928-128-3 /WINDOWS/Help/mfcuix.hlp 12288 ..c. r/rr-xr-xr-x 0 0 9280-128-1 /WINDOWS/system32/dllcache/odbcp32r.dll 104448 ..c. r/rr-xr-xr-x 0 0 9281-128-1 /WINDOWS/system32/dllcache/oeimport.dll 60416 ..c. r/rr-xr-xr-x 0 0 9282-128-1 /WINDOWS/system32/dllcache/oemig50.exe 35328 ..c. r/rr-xr-xr-x 0 0 9283-128-1 /WINDOWS/system32/dllcache/oemiglib.dll 192000 ..c. r/rr-xr-xr-x 0 0 9284-128-1 /WINDOWS/system32/dllcache/offfilt.dll 39744 ..c. r/rr-xr-xr-x 0 0 9285-128-1 /WINDOWS/system32/dllcache/ole2.dll 169520 ..c. r/rr-xr-xr-x 0 0 9286-128-1 /WINDOWS/system32/dllcache/ole2disp.dll 153008 ..c. r/rr-xr-xr-x 0 0 9287-128-1 /WINDOWS/system32/dllcache/ole2nls.dll 163328 ..c. r/rr-xr-xr-x 0 0 9288-128-1 /WINDOWS/system32/dllcache/oleacc.dll 16896 ..c. r/rr-xr-xr-x 0 0 9289-128-1 /WINDOWS/system32/dllcache/oleaccrc.dll 4673 ..c. r/rr-xr-xr-x 0 0 929-128-3 /WINDOWS/inf/mfsocket.inf 74752 ..c. r/rr-xr-xr-x 0 0 9290-128-1 /WINDOWS/system32/dllcache/olecli32.dll 82944 ..c. r/rr-xr-xr-x 0 0 9291-128-1 /WINDOWS/system32/dllcache/olecli.dll 37376 ..c. r/rr-xr-xr-x 0 0 9292-128-1 /WINDOWS/system32/dllcache/olecnv32.dll 122880 ..c. r/rr-xr-xr-x 0 0 9293-128-1 /WINDOWS/system32/dllcache/oledlg.dll 107008 ..c. r/rr-xr-xr-x 0 0 9294-128-1 /WINDOWS/system32/dllcache/oleprn.dll 22016 ..c. r/rr-xr-xr-x 0 0 9295-128-1 /WINDOWS/system32/dllcache/olesvr32.dll 24064 ..c. r/rr-xr-xr-x 0 0 9296-128-1 /WINDOWS/system32/dllcache/olesvr.dll 69120 ..c. r/rr-xr-xr-x 0 0 9297-128-1 /WINDOWS/system32/dllcache/olethk32.dll 144384 ..c. r/rr-xr-xr-x 0 0 9298-128-1 /WINDOWS/system32/dllcache/onex.dll 51200 ..c. r/rr-xr-xr-x 0 0 9299-128-1 /WINDOWS/system32/dllcache/oobebaln.exe 592 .ac. d/dr-xr-xr-x 0 0 93-144-1 /WINDOWS/Resources/Themes 2394 ..c. r/rr-xr-xr-x 0 0 930-128-3 /WINDOWS/inf/mfsupra.inf 67584 ..c. r/rr-xr-xr-x 0 0 9300-128-1 /WINDOWS/system32/dllcache/opnfiles.exe 713728 ..c. r/rr-xr-xr-x 0 0 9301-128-1 /WINDOWS/system32/dllcache/opengl32.dll 215552 ..c. r/rr-xr-xr-x 0 0 9302-128-1 /WINDOWS/system32/dllcache/osk.exe 67584 ..c. r/rr-xr-xr-x 0 0 9303-128-1 /WINDOWS/system32/dllcache/osuninst.dll 40448 ..c. r/rr-xr-xr-x 0 0 9304-128-1 /WINDOWS/system32/dllcache/osuninst.exe 153600 ..c. r/rr-xr-xr-x 0 0 9305-128-1 /WINDOWS/system32/dllcache/p2p.dll 105472 ..c. r/rr-xr-xr-x 0 0 9306-128-1 /WINDOWS/system32/dllcache/p2pgasvc.dll 313856 ..c. r/rr-xr-xr-x 0 0 9307-128-1 /WINDOWS/system32/dllcache/p2pgraph.dll 115712 ..c. r/rr-xr-xr-x 0 0 9308-128-1 /WINDOWS/system32/dllcache/p2pnetsh.dll 554496 ..c. r/rr-xr-xr-x 0 0 9309-128-1 /WINDOWS/system32/dllcache/p2psvc.dll 58368 ..c. r/rr-xr-xr-x 0 0 9310-128-1 /WINDOWS/system32/dllcache/packager.exe 15872 ..c. r/rr-xr-xr-x 0 0 9311-128-3 /WINDOWS/system32/dllcache/padrs404.dll 36927 ..c. r/rr-xr-xr-x 0 0 9312-128-3 /WINDOWS/system32/dllcache/padrs411.dll 14336 ..c. r/rr-xr-xr-x 0 0 9313-128-3 /WINDOWS/system32/dllcache/padrs412.dll 15360 ..c. r/rr-xr-xr-x 0 0 9314-128-3 /WINDOWS/system32/dllcache/padrs804.dll 31744 ..c. r/rr-xr-xr-x 0 0 9315-128-3 /WINDOWS/system32/dllcache/pagecnt.dll 167219 ..c. r/rr-xr-xr-x 0 0 9316-128-1 /WINDOWS/system32/dllcache/pagefile.vbs 10240 ..c. r/rr-xr-xr-x 0 0 9317-128-1 /WINDOWS/system32/dllcache/panmap.dll 19712 ..c. r/rr-xr-xr-x 0 0 9318-128-1 /WINDOWS/system32/dllcache/partmgr.sys 6784 ..c. r/rr-xr-xr-x 0 0 9319-128-1 /WINDOWS/system32/dllcache/parvdm.sys 629 ..c. r/rr-xr-xr-x 0 0 932-128-1 /WINDOWS/inf/minioc.inf 21504 ..c. r/rr-xr-xr-x 0 0 9320-128-1 /WINDOWS/system32/dllcache/pathping.exe 67584 ..c. r/rr-xr-xr-x 0 0 9321-128-1 /WINDOWS/system32/dllcache/pautoenr.dll 102912 ..c. r/rr-xr-xr-x 0 0 9322-128-1 /WINDOWS/system32/dllcache/pchshell.dll 38400 ..c. r/rr-xr-xr-x 0 0 9323-128-1 /WINDOWS/system32/dllcache/pchsvc.dll 0 ..c. r/rr-xr-xr-x 0 0 9324-128-1 /Documents and Settings/malware/Local Settings/Temp/mmc131F4D54.xml 15360 ..c. r/rr-xr-xr-x 0 0 9325-128-1 /WINDOWS/system32/dllcache/pentnt.exe 39936 ..c. r/rr-xr-xr-x 0 0 9326-128-1 /WINDOWS/system32/dllcache/perfctrs.dll 26624 ..c. r/rr-xr-xr-x 0 0 9327-128-1 /WINDOWS/system32/dllcache/perfdisk.dll 15872 ..c. r/rr-xr-xr-x 0 0 9328-128-1 /WINDOWS/system32/dllcache/perfmon.exe 17920 ..c. r/rr-xr-xr-x 0 0 9329-128-1 /WINDOWS/system32/dllcache/perfnet.dll 5632 ..c. r/rr-xr-xr-x 0 0 9330-128-1 /WINDOWS/system32/dllcache/perfnw.dll 25088 ..c. r/rr-xr-xr-x 0 0 9331-128-1 /WINDOWS/system32/dllcache/perfos.dll 34816 ..c. r/rr-xr-xr-x 0 0 9332-128-1 /WINDOWS/system32/dllcache/perfproc.dll 12288 ..c. r/rr-xr-xr-x 0 0 9333-128-1 /WINDOWS/system32/dllcache/perfts.dll 20992 ..c. r/rr-xr-xr-x 0 0 9334-128-3 /WINDOWS/system32/dllcache/permchk.dll 79360 ..c. r/rr-xr-xr-x 0 0 9335-128-3 /WINDOWS/system32/dllcache/phon.ime 176128 ..c. r/rr-xr-xr-x 0 0 9336-128-1 /WINDOWS/system32/dllcache/photowiz.dll 358 ..c. r/rr-xr-xr-x 0 0 9337-128-1 /WINDOWS/system32/dllcache/pid.inf 24576 ..c. r/rr-xr-xr-x 0 0 9338-128-1 /WINDOWS/system32/dllcache/pidgen.dll 35328 ..c. r/rr-xr-xr-x 0 0 9339-128-1 /WINDOWS/system32/dllcache/pifmgr.dll 281088 ..c. r/rr-xr-xr-x 0 0 9340-128-1 /WINDOWS/system32/dllcache/pinball.exe 17920 ..c. r/rr-xr-xr-x 0 0 9341-128-1 /WINDOWS/system32/dllcache/ping.exe 33280 ..c. r/rr-xr-xr-x 0 0 9342-128-1 /WINDOWS/system32/dllcache/ping6.exe 175104 ..c. r/rr-xr-xr-x 0 0 9343-128-3 /WINDOWS/system32/dllcache/pintlcsa.dll 53760 ..c. r/rr-xr-xr-x 0 0 9344-128-3 /WINDOWS/system32/dllcache/pintlcsd.dll 482304 ..c. r/rr-xr-xr-x 0 0 9345-128-3 /WINDOWS/system32/dllcache/pintlgnt.ime 70144 ..c. r/rr-xr-xr-x 0 0 9346-128-3 /WINDOWS/system32/dllcache/pintlphr.exe 30720 ..c. r/rr-xr-xr-x 0 0 9347-128-1 /WINDOWS/system32/dllcache/plustab.dll 67584 ..c. r/rr-xr-xr-x 0 0 9348-128-3 /WINDOWS/system32/dllcache/pmigrate.dll 46592 ..c. r/rr-xr-xr-x 0 0 9349-128-1 /WINDOWS/system32/dllcache/pmspl.dll 6144 ..c. r/rr-xr-xr-x 0 0 9350-128-3 /WINDOWS/system32/dllcache/pmxgl.dll 11264 ..c. r/rr-xr-xr-x 0 0 9351-128-3 /WINDOWS/system32/dllcache/pmxmcro.dll 131584 ..c. r/rr-xr-xr-x 0 0 9352-128-3 /WINDOWS/system32/dllcache/pmxviceo.dll 39424 ..c. r/rr-xr-xr-x 0 0 9353-128-1 /WINDOWS/system32/dllcache/pngfilt.dll 58880 ..c. r/rr-xr-xr-x 0 0 9354-128-1 /WINDOWS/system32/dllcache/pnrpnsp.dll 92672 ..c. r/rr-xr-xr-x 0 0 9355-128-1 /WINDOWS/system32/dllcache/policman.dll 105472 ..c. r/rr-xr-xr-x 0 0 9356-128-1 /WINDOWS/system32/dllcache/polstore.dll 114688 ..c. r/rr-xr-xr-x 0 0 9357-128-1 /WINDOWS/system32/dllcache/powercfg.cpl 49152 ..c. r/rr-xr-xr-x 0 0 9358-128-1 /WINDOWS/system32/dllcache/powercfg.exe 17408 ..c. r/rr-xr-xr-x 0 0 9359-128-1 /WINDOWS/system32/dllcache/powrprof.dll 83748 ..c. r/rr-xr-xr-x 0 0 9360-128-3 /WINDOWS/system32/dllcache/prc.nls 83748 ..c. r/rr-xr-xr-x 0 0 9361-128-3 /WINDOWS/system32/dllcache/prcp.nls 16384 ..c. r/rr-xr-xr-x 0 0 9362-128-1 /WINDOWS/system32/dllcache/prflbmsg.dll 9216 ..c. r/rr-xr-xr-x 0 0 9363-128-1 /WINDOWS/system32/dllcache/print.exe 560640 ..c. r/rr-xr-xr-x 0 0 9364-128-1 /WINDOWS/system32/dllcache/printui.dll 35755 ..c. r/rr-xr-xr-x 0 0 9365-128-1 /WINDOWS/system32/dllcache/prncnfg.vbs 25415 ..c. r/rr-xr-xr-x 0 0 9366-128-1 /WINDOWS/system32/dllcache/prndrvr.vbs 21527 ..c. r/rr-xr-xr-x 0 0 9367-128-1 /WINDOWS/system32/dllcache/prnjobs.vbs 32546 ..c. r/rr-xr-xr-x 0 0 9368-128-1 /WINDOWS/system32/dllcache/prnmngr.vbs 29454 ..c. r/rr-xr-xr-x 0 0 9369-128-1 /WINDOWS/system32/dllcache/prnport.vbs 17135 ..c. r/rr-xr-xr-x 0 0 937-128-3 /WINDOWS/Help/mls_trb.chm 15860 ..c. r/rr-xr-xr-x 0 0 9370-128-1 /WINDOWS/system32/dllcache/prnqctl.vbs 81920 ..c. r/rr-xr-xr-x 0 0 9371-128-1 /WINDOWS/system32/dllcache/proctexe.ocx 27648 ..c. r/rr-xr-xr-x 0 0 9372-128-1 /WINDOWS/system32/dllcache/profmap.dll 109568 ..c. r/rr-xr-xr-x 0 0 9373-128-1 /WINDOWS/system32/dllcache/progman.exe 50176 ..c. r/rr-xr-xr-x 0 0 9374-128-1 /WINDOWS/system32/dllcache/proquota.exe 237056 ..c. r/rr-xr-xr-x 0 0 9375-128-1 /WINDOWS/system32/dllcache/provthrd.dll 9216 ..c. r/rr-xr-xr-x 0 0 9376-128-1 /WINDOWS/system32/dllcache/proxycfg.exe 23040 ..c. r/rr-xr-xr-x 0 0 9377-128-1 /WINDOWS/system32/dllcache/psapi.dll 96768 ..c. r/rr-xr-xr-x 0 0 9378-128-1 /WINDOWS/system32/dllcache/psbase.dll 10752 ..c. r/rr-xr-xr-x 0 0 9379-128-1 /WINDOWS/system32/dllcache/pschdprf.dll 37298 ..c. r/rr-xr-xr-x 0 0 938-128-3 /WINDOWS/Help/mmc_dlg.hlp 69120 ..c. r/rr-xr-xr-x 0 0 9380-128-1 /WINDOWS/system32/dllcache/psched.sys 8192 ..c. r/rr-xr-xr-x 0 0 9381-128-1 /WINDOWS/system32/dllcache/psnppagn.dll 43520 ..c. r/rr-xr-xr-x 0 0 9382-128-1 /WINDOWS/system32/dllcache/pstorec.dll 34304 ..c. r/rr-xr-xr-x 0 0 9383-128-1 /WINDOWS/system32/dllcache/pstorsvc.dll 17792 ..c. r/rr-xr-xr-x 0 0 9384-128-1 /WINDOWS/system32/dllcache/ptilink.sys 3708 ..c. r/rr-xr-xr-x 0 0 9385-128-1 /WINDOWS/system32/dllcache/pubprn.vbs 7680 ..c. r/rr-xr-xr-x 0 0 9386-128-3 /WINDOWS/system32/dllcache/pwsdata.dll 16896 ..c. r/rr-xr-xr-x 0 0 9387-128-1 /WINDOWS/system32/dllcache/qappsrv.exe 237568 ..c. r/rr-xr-xr-x 0 0 9388-128-1 /WINDOWS/system32/dllcache/qasf.dll 192512 ..c. r/rr-xr-xr-x 0 0 9389-128-1 /WINDOWS/system32/dllcache/qcap.dll 279040 ..c. r/rr-xr-xr-x 0 0 9390-128-1 /WINDOWS/system32/dllcache/qdv.dll 386048 ..c. r/rr-xr-xr-x 0 0 9391-128-1 /WINDOWS/system32/dllcache/qdvd.dll 562176 ..c. r/rr-xr-xr-x 0 0 9392-128-1 /WINDOWS/system32/dllcache/qedit.dll 733696 ..c. r/rr-xr-xr-x 0 0 9393-128-1 /WINDOWS/system32/dllcache/qedwipes.dll 150528 ..c. r/rr-xr-xr-x 0 0 9394-128-1 /WINDOWS/system32/dllcache/qagent.dll 291328 ..c. r/rr-xr-xr-x 0 0 9395-128-1 /WINDOWS/system32/dllcache/qagentrt.dll 62464 ..c. r/rr-xr-xr-x 0 0 9396-128-1 /WINDOWS/system32/dllcache/qcliprov.dll 409088 ..c. r/rr-xr-xr-x 0 0 9397-128-1 /WINDOWS/system32/dllcache/qmgr.dll 18944 ..c. r/rr-xr-xr-x 0 0 9398-128-1 /WINDOWS/system32/dllcache/qmgrprxy.dll 8192 ..c. r/rr-xr-xr-x 0 0 9399-128-1 /WINDOWS/system32/dllcache/qosname.dll 360 .ac. d/dr-xr-xr-x 0 0 94-144-1 /WINDOWS/Resources/Themes/Luna 19968 ..c. r/rr-xr-xr-x 0 0 9400-128-1 /WINDOWS/system32/dllcache/qprocess.exe 1288192 ..c. r/rr-xr-xr-x 0 0 9401-128-1 /WINDOWS/system32/dllcache/quartz.dll 1435648 ..c. r/rr-xr-xr-x 0 0 9402-128-1 /WINDOWS/system32/dllcache/query.dll 9728 ..c. r/rr-xr-xr-x 0 0 9403-128-3 /WINDOWS/system32/dllcache/query.exe 77824 ..c. r/rr-xr-xr-x 0 0 9404-128-3 /WINDOWS/system32/dllcache/quick.ime 16384 ..c. r/rr-xr-xr-x 0 0 9405-128-3 /WINDOWS/system32/dllcache/quser.exe 76800 ..c. r/rr-xr-xr-x 0 0 9406-128-1 /WINDOWS/system32/dllcache/qutil.dll 22016 ..c. r/rr-xr-xr-x 0 0 9407-128-1 /WINDOWS/system32/dllcache/qwinsta.exe 605050 ..c. r/rr-xr-xr-x 0 0 9408-128-1 /WINDOWS/system32/dllcache/r1033tts.lxa 43520 ..c. r/rr-xr-xr-x 0 0 9409-128-1 /WINDOWS/system32/dllcache/racpldlg.dll 20736 ..c. r/rr-xr-xr-x 0 0 9410-128-3 /WINDOWS/system32/dllcache/ramdisk.sys 8832 ..c. r/rr-xr-xr-x 0 0 9411-128-1 /WINDOWS/system32/dllcache/rasacd.sys 7680 ..c. r/rr-xr-xr-x 0 0 9412-128-1 /WINDOWS/system32/dllcache/rasadhlp.dll 237056 ..c. r/rr-xr-xr-x 0 0 9413-128-1 /WINDOWS/system32/dllcache/rasapi32.dll 88576 ..c. r/rr-xr-xr-x 0 0 9414-128-1 /WINDOWS/system32/dllcache/rasauto.dll 11776 ..c. r/rr-xr-xr-x 0 0 9415-128-1 /WINDOWS/system32/dllcache/rasautou.exe 79872 ..c. r/rr-xr-xr-x 0 0 9416-128-1 /WINDOWS/system32/dllcache/raschap.dll 11776 ..c. r/rr-xr-xr-x 0 0 9417-128-1 /WINDOWS/system32/dllcache/rasctrs.dll 11264 ..c. r/rr-xr-xr-x 0 0 9418-128-1 /WINDOWS/system32/dllcache/rasdial.exe 658432 ..c. r/rr-xr-xr-x 0 0 9419-128-1 /WINDOWS/system32/dllcache/rasdlg.dll 51328 ..c. r/rr-xr-xr-x 0 0 9420-128-1 /WINDOWS/system32/dllcache/rasl2tp.sys 61440 ..c. r/rr-xr-xr-x 0 0 9421-128-1 /WINDOWS/system32/dllcache/rasman.dll 186368 ..c. r/rr-xr-xr-x 0 0 9422-128-1 /WINDOWS/system32/dllcache/rasmans.dll 143360 ..c. r/rr-xr-xr-x 0 0 9423-128-1 /WINDOWS/system32/dllcache/rasmontr.dll 22528 ..c. r/rr-xr-xr-x 0 0 9424-128-1 /WINDOWS/system32/dllcache/rasmxs.dll 56832 ..c. r/rr-xr-xr-x 0 0 9425-128-1 /WINDOWS/system32/dllcache/rasphone.exe 210944 ..c. r/rr-xr-xr-x 0 0 9426-128-1 /WINDOWS/system32/dllcache/rasppp.dll 41472 ..c. r/rr-xr-xr-x 0 0 9427-128-1 /WINDOWS/system32/dllcache/raspppoe.sys 48384 ..c. r/rr-xr-xr-x 0 0 9428-128-1 /WINDOWS/system32/dllcache/raspptp.sys 16512 ..c. r/rr-xr-xr-x 0 0 9429-128-1 /WINDOWS/system32/dllcache/raspti.sys 18920 ..c. r/rr-xr-xr-x 0 0 943-128-3 /WINDOWS/Help/mobsync.chm 61952 ..c. r/rr-xr-xr-x 0 0 9430-128-1 /WINDOWS/system32/dllcache/rasqec.dll 23552 ..c. r/rr-xr-xr-x 0 0 9431-128-1 /WINDOWS/system32/dllcache/rasrad.dll 16384 ..c. r/rr-xr-xr-x 0 0 9432-128-1 /WINDOWS/system32/dllcache/rassapi.dll 12800 ..c. r/rr-xr-xr-x 0 0 9433-128-1 /WINDOWS/system32/dllcache/rasser.dll 58368 ..c. r/rr-xr-xr-x 0 0 9434-128-1 /WINDOWS/system32/dllcache/rastapi.dll 150016 ..c. r/rr-xr-xr-x 0 0 9435-128-1 /WINDOWS/system32/dllcache/rastls.dll 34432 ..c. r/rr-xr-xr-x 0 0 9436-128-1 /WINDOWS/system32/dllcache/rawwan.sys 102400 ..c. r/rr-xr-xr-x 0 0 9437-128-1 /WINDOWS/system32/dllcache/rcbdyctl.dll 35840 ..c. r/rr-xr-xr-x 0 0 9438-128-1 /WINDOWS/system32/dllcache/rcimlby.exe 21504 ..c. r/rr-xr-xr-x 0 0 9439-128-1 /WINDOWS/system32/dllcache/rcp.exe 16149 ..c. r/rr-xr-xr-x 0 0 944-128-3 /WINDOWS/Help/mobsync.hlp 175744 ..c. r/rr-xr-xr-x 0 0 9440-128-1 /WINDOWS/system32/dllcache/rdbss.sys 147968 ..c. r/rr-xr-xr-x 0 0 9441-128-1 /WINDOWS/system32/dllcache/rdchost.dll 4224 ..c. r/rr-xr-xr-x 0 0 9442-128-1 /WINDOWS/system32/dllcache/rdpcdd.sys 4096 ..c. r/rr-xr-xr-x 0 0 9443-128-1 /WINDOWS/system32/dllcache/rdpcfgex.dll 62976 ..c. r/rr-xr-xr-x 0 0 9444-128-1 /WINDOWS/system32/dllcache/rdpclip.exe 92424 ..c. r/rr-xr-xr-x 0 0 9445-128-1 /WINDOWS/system32/dllcache/rdpdd.dll 19968 ..c. r/rr-xr-xr-x 0 0 9446-128-1 /WINDOWS/system32/dllcache/rdpsnd.dll 139656 ..c. r/rr-xr-xr-x 0 0 9447-128-1 /WINDOWS/system32/dllcache/rdpwd.sys 87176 ..c. r/rr-xr-xr-x 0 0 9448-128-1 /WINDOWS/system32/dllcache/rdpwsx.dll 13824 ..c. r/rr-xr-xr-x 0 0 9449-128-1 /WINDOWS/system32/dllcache/rdsaddin.exe 67072 ..c. r/rr-xr-xr-x 0 0 9450-128-1 /WINDOWS/system32/dllcache/rdshost.exe 7168 ..c. r/rr-xr-xr-x 0 0 9451-128-1 /WINDOWS/system32/dllcache/recover.exe 3338 ..c. r/rr-xr-xr-x 0 0 9452-128-1 /WINDOWS/system32/dllcache/redir.exe 50176 ..c. r/rr-xr-xr-x 0 0 9453-128-1 /WINDOWS/system32/dllcache/reg.exe 49664 ..c. r/rr-xr-xr-x 0 0 9454-128-1 /WINDOWS/system32/dllcache/regapi.dll 146432 ..c. r/rr-xr-xr-x 0 0 9455-128-1 /WINDOWS/system32/dllcache/regedit.exe 3584 ..c. r/rr-xr-xr-x 0 0 9456-128-1 /WINDOWS/system32/dllcache/regedt32.exe 33792 ..c. r/rr-xr-xr-x 0 0 9457-128-1 /WINDOWS/system32/dllcache/regini.exe 14848 ..c. r/rr-xr-xr-x 0 0 9458-128-3 /WINDOWS/system32/dllcache/register.exe 59904 ..c. r/rr-xr-xr-x 0 0 9459-128-1 /WINDOWS/system32/dllcache/regsvc.dll 20366 ..c. r/rr-xr-xr-x 0 0 946-128-3 /WINDOWS/Help/modem.hlp 11776 ..c. r/rr-xr-xr-x 0 0 9460-128-1 /WINDOWS/system32/dllcache/regsvr32.exe 4608 ..c. r/rr-xr-xr-x 0 0 9461-128-1 /WINDOWS/system32/dllcache/regwiz.exe 23040 ..c. r/rr-xr-xr-x 0 0 9462-128-3 /WINDOWS/system32/dllcache/EXCH_regtrace.exe 397824 ..c. r/rr-xr-xr-x 0 0 9463-128-1 /WINDOWS/system32/dllcache/regwizc.dll 32768 ..c. r/rr-xr-xr-x 0 0 9464-128-1 /WINDOWS/system32/dllcache/relog.exe 60416 ..c. r/rr-xr-xr-x 0 0 9465-128-1 /WINDOWS/system32/dllcache/remotepg.dll 76800 ..c. r/rr-xr-xr-x 0 0 9466-128-1 /WINDOWS/system32/dllcache/remotesp.tsp 107520 ..c. r/rr-xr-xr-x 0 0 9467-128-1 /WINDOWS/system32/dllcache/rend.dll 178176 ..c. r/rr-xr-xr-x 0 0 9468-128-1 /WINDOWS/system32/dllcache/repdrvfs.dll 12800 ..c. r/rr-xr-xr-x 0 0 9469-128-1 /WINDOWS/system32/dllcache/replace.exe 4386 ..c. r/rr-xr-xr-x 0 0 947-128-3 /WINDOWS/inf/modemcsa.inf 9728 ..c. r/rr-xr-xr-x 0 0 9470-128-1 /WINDOWS/system32/dllcache/reset.exe 58880 ..c. r/rr-xr-xr-x 0 0 9471-128-1 /WINDOWS/system32/dllcache/resutils.dll 13824 ..c. r/rr-xr-xr-x 0 0 9472-128-1 /WINDOWS/system32/dllcache/rexec.exe 290304 ..c. r/rr-xr-xr-x 0 0 9473-128-1 /WINDOWS/system32/dllcache/rhttpaa.dll 202624 ..c. r/rr-xr-xr-x 0 0 9474-128-1 /WINDOWS/system32/dllcache/rmcast.sys 30592 ..c. r/rr-xr-xr-x 0 0 9475-128-1 /WINDOWS/system32/dllcache/rndismp.sys 3072 ..c. r/rr-xr-xr-x 0 0 9476-128-1 /WINDOWS/system32/dllcache/rnr20.dll 26112 ..c. r/rr-xr-xr-x 0 0 9477-128-3 /WINDOWS/system32/dllcache/romanime.ime 5888 ..c. r/rr-xr-xr-x 0 0 9478-128-1 /WINDOWS/system32/dllcache/rootmdm.sys 19968 ..c. r/rr-xr-xr-x 0 0 9479-128-1 /WINDOWS/system32/dllcache/route.exe 25600 ..c. r/rr-xr-xr-x 0 0 9480-128-1 /WINDOWS/system32/dllcache/routemon.exe 6656 ..c. r/rr-xr-xr-x 0 0 9481-128-1 /WINDOWS/system32/dllcache/routetab.dll 22016 ..c. r/rr-xr-xr-x 0 0 9482-128-1 /WINDOWS/system32/dllcache/rpcns4.dll 4096 ..c. r/rr-xr-xr-x 0 0 9483-128-3 /WINDOWS/system32/dllcache/rpcref.dll 584704 ..c. r/rr-xr-xr-x 0 0 9484-128-1 /WINDOWS/system32/dllcache/rpcrt4.dll 399360 ..c. r/rr-xr-xr-x 0 0 9485-128-1 /WINDOWS/system32/dllcache/rpcss.dll 61440 ..c. r/rr-xr-xr-x 0 0 9486-128-1 /WINDOWS/system32/dllcache/rrcm.dll 28672 ..c. r/rr-xr-xr-x 0 0 9487-128-1 /WINDOWS/system32/dllcache/rsfsaps.dll 14848 ..c. r/rr-xr-xr-x 0 0 9488-128-1 /WINDOWS/system32/dllcache/rsh.exe 39936 ..c. r/rr-xr-xr-x 0 0 9489-128-1 /WINDOWS/system32/dllcache/rshx32.dll 52117 ..c. r/rr-xr-xr-x 0 0 949-128-3 /WINDOWS/inf/monitor.inf 49152 ..c. r/rr-xr-xr-x 0 0 9490-128-1 /WINDOWS/system32/dllcache/rsm.exe 18944 ..c. r/rr-xr-xr-x 0 0 9491-128-1 /WINDOWS/system32/dllcache/rsmps.dll 24576 ..c. r/rr-xr-xr-x 0 0 9492-128-1 /WINDOWS/system32/dllcache/rsmsink.exe 49152 ..c. r/rr-xr-xr-x 0 0 9493-128-1 /WINDOWS/system32/dllcache/rsmui.exe 107520 ..c. r/rr-xr-xr-x 0 0 9494-128-1 /WINDOWS/system32/dllcache/rsnotify.exe 62976 ..c. r/rr-xr-xr-x 0 0 9495-128-1 /WINDOWS/system32/dllcache/rsopprov.exe 380416 ..c. r/rr-xr-xr-x 0 0 9496-128-1 /WINDOWS/system32/dllcache/rstrui.exe 132608 ..c. r/rr-xr-xr-x 0 0 9497-128-1 /WINDOWS/system32/dllcache/rsvp.exe 23552 ..c. r/rr-xr-xr-x 0 0 9498-128-1 /WINDOWS/system32/dllcache/rsvpmsg.dll 9728 ..c. r/rr-xr-xr-x 0 0 9499-128-1 /WINDOWS/system32/dllcache/rsvpperf.dll 568 .ac. d/dr-xr-xr-x 0 0 95-144-1 /WINDOWS/Resources/Themes/Luna/Shell 47730 ..c. r/rr-xr-xr-x 0 0 950-128-3 /WINDOWS/inf/monitor2.inf 92672 ..c. r/rr-xr-xr-x 0 0 9500-128-1 /WINDOWS/system32/dllcache/rsvpsp.dll 77312 ..c. r/rr-xr-xr-x 0 0 9501-128-1 /WINDOWS/system32/dllcache/rtcshare.exe 31744 ..c. r/rr-xr-xr-x 0 0 9502-128-1 /WINDOWS/system32/dllcache/rtipxmib.dll 98304 ..c. r/rr-xr-xr-x 0 0 9503-128-1 /WINDOWS/system32/dllcache/rtm.dll 44032 ..c. r/rr-xr-xr-x 0 0 9504-128-1 /WINDOWS/system32/dllcache/rtutils.dll 16384 ..c. r/rr-xr-xr-x 0 0 9505-128-1 /WINDOWS/system32/dllcache/runas.exe 33280 ..c. r/rr-xr-xr-x 0 0 9506-128-1 /WINDOWS/system32/dllcache/rundll32.exe 14336 ..c. r/rr-xr-xr-x 0 0 9507-128-1 /WINDOWS/system32/dllcache/runonce.exe 48706 ..c. r/rr-xr-xr-x 0 0 9508-128-1 /WINDOWS/system32/dllcache/rvse.dll 753236 ..c. r/rr-xr-xr-x 0 0 9509-128-1 /WINDOWS/system32/dllcache/rvseres.dll 41883 ..c. r/rr-xr-xr-x 0 0 951-128-3 /WINDOWS/inf/monitor3.inf 42574 ..c. r/rr-xr-xr-x 0 0 9510-128-1 /WINDOWS/system32/dllcache/rvsezm.exe 27648 ..c. r/rr-xr-xr-x 0 0 9511-128-3 /WINDOWS/system32/dllcache/rw001ext.dll 29184 ..c. r/rr-xr-xr-x 0 0 9512-128-3 /WINDOWS/system32/dllcache/rw330ext.dll 79872 ..c. r/rr-xr-xr-x 0 0 9513-128-3 /WINDOWS/system32/dllcache/rwia001.dll 79872 ..c. r/rr-xr-xr-x 0 0 9514-128-3 /WINDOWS/system32/dllcache/rwia330.dll 15872 ..c. r/rr-xr-xr-x 0 0 9515-128-1 /WINDOWS/system32/dllcache/rwinsta.exe 9728 ..c. r/rr-xr-xr-x 0 0 9516-128-3 /WINDOWS/system32/dllcache/rwnh.dll 43520 ..c. r/rr-xr-xr-x 0 0 9517-128-1 /WINDOWS/system32/dllcache/safrcdlg.dll 29696 ..c. r/rr-xr-xr-x 0 0 9518-128-1 /WINDOWS/system32/dllcache/safrdm.dll 45568 ..c. r/rr-xr-xr-x 0 0 9519-128-1 /WINDOWS/system32/dllcache/safrslv.dll 40054 ..c. r/rr-xr-xr-x 0 0 952-128-3 /WINDOWS/inf/monitor4.inf 888 ..c. r/rr-xr-xr-x 0 0 9520-128-1 /WINDOWS/system32/dllcache/sam.sdf 1685606 ..c. r/rr-xr-xr-x 0 0 9521-128-1 /WINDOWS/system32/dllcache/sam.spd 155648 ..c. r/rr-xr-xr-x 0 0 9522-128-1 /WINDOWS/system32/dllcache/sapi.cpl 741376 ..c. r/rr-xr-xr-x 0 0 9523-128-1 /WINDOWS/system32/dllcache/sapi.dll 36864 ..c. r/rr-xr-xr-x 0 0 9524-128-1 /WINDOWS/system32/dllcache/sapisvr.exe 13312 ..c. r/rr-xr-xr-x 0 0 9525-128-1 /WINDOWS/system32/dllcache/savedump.exe 270848 ..c. r/rr-xr-xr-x 0 0 9526-128-1 /WINDOWS/system32/dllcache/sbe.dll 159232 ..c. r/rr-xr-xr-x 0 0 9527-128-1 /WINDOWS/system32/dllcache/sbeio.dll 31232 ..c. r/rr-xr-xr-x 0 0 9528-128-1 /WINDOWS/system32/dllcache/sc.exe 69632 ..c. r/rr-xr-xr-x 0 0 9529-128-1 /WINDOWS/system32/dllcache/scarddlg.dll 60593 ..c. r/rr-xr-xr-x 0 0 953-128-3 /WINDOWS/inf/monitor5.inf 118784 ..c. r/rr-xr-xr-x 0 0 9530-128-1 /WINDOWS/system32/dllcache/scardssp.dll 95744 ..c. r/rr-xr-xr-x 0 0 9531-128-1 /WINDOWS/system32/dllcache/scardsvr.exe 169984 ..c. r/rr-xr-xr-x 0 0 9532-128-1 /WINDOWS/system32/dllcache/sccbase.dll 171008 ..c. r/rr-xr-xr-x 0 0 9533-128-1 /WINDOWS/system32/dllcache/sccsccp.dll 181248 ..c. r/rr-xr-xr-x 0 0 9534-128-1 /WINDOWS/system32/dllcache/scecli.dll 314880 ..c. r/rr-xr-xr-x 0 0 9535-128-1 /WINDOWS/system32/dllcache/scesrv.dll 192512 ..c. r/rr-xr-xr-x 0 0 9536-128-1 /WINDOWS/system32/dllcache/schedsvc.dll 121856 ..c. r/rr-xr-xr-x 0 0 9537-128-1 /WINDOWS/system32/dllcache/sctasks.exe 20480 ..c. r/rr-xr-xr-x 0 0 9538-128-1 /WINDOWS/system32/dllcache/sclgntfy.dll 36352 ..c. r/rr-xr-xr-x 0 0 9539-128-1 /WINDOWS/system32/dllcache/scrcons.exe 45673 ..c. r/rr-xr-xr-x 0 0 954-128-3 /WINDOWS/inf/monitor6.inf 26624 ..c. r/rr-xr-xr-x 0 0 9540-128-1 /WINDOWS/system32/dllcache/scredir.dll 215552 ..c. r/rr-xr-xr-x 0 0 9541-128-1 /WINDOWS/system32/dllcache/script.dll 10240 ..c. r/rr-xr-xr-x 0 0 9542-128-1 /WINDOWS/system32/dllcache/scriptpw.dll 57856 ..c. r/rr-xr-xr-x 0 0 9543-128-3 /WINDOWS/system32/dllcache/EXCH_scripto.dll 9216 ..c. r/rr-xr-xr-x 0 0 9544-128-1 /WINDOWS/system32/dllcache/scrnsave.scr 130048 ..c. r/rr-xr-xr-x 0 0 9545-128-1 /WINDOWS/system32/dllcache/sdpblb.dll 18944 ..c. r/rr-xr-xr-x 0 0 9546-128-1 /WINDOWS/system32/dllcache/secedit.exe 18944 ..c. r/rr-xr-xr-x 0 0 9547-128-1 /WINDOWS/system32/dllcache/seclogon.dll 56320 ..c. r/rr-xr-xr-x 0 0 9548-128-1 /WINDOWS/system32/dllcache/secur32.dll 5632 ..c. r/rr-xr-xr-x 0 0 9549-128-1 /WINDOWS/system32/dllcache/security.dll 40439 ..c. r/rr-xr-xr-x 0 0 955-128-3 /WINDOWS/inf/monitor7.inf 29184 ..c. r/rr-xr-xr-x 0 0 9550-128-1 /WINDOWS/system32/dllcache/sendcmsg.dll 54784 ..c. r/rr-xr-xr-x 0 0 9551-128-1 /WINDOWS/system32/dllcache/sendmail.dll 39424 ..c. r/rr-xr-xr-x 0 0 9552-128-1 /WINDOWS/system32/dllcache/sens.dll 7168 ..c. r/rr-xr-xr-x 0 0 9553-128-1 /WINDOWS/system32/dllcache/sensapi.dll 13824 ..c. r/rr-xr-xr-x 0 0 9554-128-1 /WINDOWS/system32/dllcache/senscfg.dll 221696 ..c. r/rr-xr-xr-x 0 0 9555-128-3 /WINDOWS/system32/dllcache/seo.dll 14336 ..c. r/rr-xr-xr-x 0 0 9556-128-1 /WINDOWS/system32/dllcache/serialui.dll 26112 ..c. r/rr-xr-xr-x 0 0 9557-128-3 /WINDOWS/system32/dllcache/EXCH_seos.dll 56320 ..c. r/rr-xr-xr-x 0 0 9558-128-1 /WINDOWS/system32/dllcache/servdeps.dll 108544 ..c. r/rr-xr-xr-x 0 0 9559-128-1 /WINDOWS/system32/dllcache/services.exe 52670 ..c. r/rr-xr-xr-x 0 0 956-128-3 /WINDOWS/inf/monitor8.inf 14848 ..c. r/rr-xr-xr-x 0 0 9560-128-1 /WINDOWS/system32/dllcache/serwvdrv.dll 141312 ..c. r/rr-xr-xr-x 0 0 9561-128-1 /WINDOWS/system32/dllcache/sessmgr.exe 31232 ..c. r/rr-xr-xr-x 0 0 9562-128-1 /WINDOWS/system32/dllcache/sethc.exe 23040 ..c. r/rr-xr-xr-x 0 0 9563-128-1 /WINDOWS/system32/dllcache/setup.exe 73216 ..c. r/rr-xr-xr-x 0 0 9564-128-1 /WINDOWS/system32/dllcache/setup50.exe 774144 ..c. r/rr-xr-xr-x 0 0 9565-128-1 /WINDOWS/system32/dllcache/setup_wm.exe 414208 ..c. r/rr-xr-xr-x 0 0 9566-128-1 /WINDOWS/system32/dllcache/setupdll.dll 32768 ..c. r/rr-xr-xr-x 0 0 9567-128-1 /WINDOWS/system32/dllcache/setupn.exe 101376 ..c. r/rr-xr-xr-x 0 0 9568-128-1 /WINDOWS/system32/dllcache/setupqry.dll 140288 ..c. r/rr-xr-xr-x 0 0 9569-128-1 /WINDOWS/system32/dllcache/sfc_os.dll 23552 ..c. r/rr-xr-xr-x 0 0 9570-128-1 /WINDOWS/system32/dllcache/sfmapi.dll 14848 ..c. r/rr-xr-xr-x 0 0 9571-128-1 /WINDOWS/system32/dllcache/shadow.exe 882 ..c. r/rr-xr-xr-x 0 0 9572-128-1 /WINDOWS/system32/dllcache/share.exe 549376 ..c. r/rr-xr-xr-x 0 0 9573-128-1 /WINDOWS/system32/dllcache/shdoclc.dll 1499136 ..c. r/rr-xr-xr-x 0 0 9574-128-1 /WINDOWS/system32/dllcache/shdocvw.dll 8461312 ..c. r/rr-xr-xr-x 0 0 9575-128-1 /WINDOWS/system32/dllcache/shell32.dll 5120 ..c. r/rr-xr-xr-x 0 0 9576-128-1 /WINDOWS/system32/dllcache/shell.dll 361472 ..c. r/rr-xr-xr-x 0 0 9577-128-1 /WINDOWS/system32/dllcache/blue_ss.dll 435712 ..c. r/rr-xr-xr-x 0 0 9578-128-1 /WINDOWS/system32/dllcache/class_ss.dll 362496 ..c. r/rr-xr-xr-x 0 0 9579-128-1 /WINDOWS/system32/dllcache/home_ss.dll 20877 ..c. r/rr-xr-xr-x 0 0 958-128-3 /WINDOWS/Help/mouse.chm 362496 ..c. r/rr-xr-xr-x 0 0 9580-128-1 /WINDOWS/system32/dllcache/metal_ss.dll 25088 ..c. r/rr-xr-xr-x 0 0 9581-128-1 /WINDOWS/system32/dllcache/shfolder.dll 68096 ..c. r/rr-xr-xr-x 0 0 9582-128-1 /WINDOWS/system32/dllcache/shgina.dll 438272 ..c. r/rr-xr-xr-x 0 0 9583-128-1 /WINDOWS/system32/dllcache/shimgvw.dll 474112 ..c. r/rr-xr-xr-x 0 0 9584-128-1 /WINDOWS/system32/dllcache/shlwapi.dll 152064 ..c. r/rr-xr-xr-x 0 0 9585-128-1 /WINDOWS/system32/dllcache/shmedia.dll 45056 ..c. r/rr-xr-xr-x 0 0 9586-128-1 /WINDOWS/system32/dllcache/shmgrate.exe 77824 ..c. r/rr-xr-xr-x 0 0 9587-128-1 /WINDOWS/system32/dllcache/shrpubw.exe 27648 ..c. r/rr-xr-xr-x 0 0 9588-128-1 /WINDOWS/system32/dllcache/shscrap.dll 135168 ..c. r/rr-xr-xr-x 0 0 9589-128-1 /WINDOWS/system32/dllcache/shsvcs.dll 19456 ..c. r/rr-xr-xr-x 0 0 9590-128-1 /WINDOWS/system32/dllcache/shutdown.exe 66113 ..c. r/rr-xr-xr-x 0 0 9591-128-1 /WINDOWS/system32/dllcache/shvl.dll 2178131 ..c. r/rr-xr-xr-x 0 0 9592-128-1 /WINDOWS/system32/dllcache/shvlres.dll 42573 ..c. r/rr-xr-xr-x 0 0 9593-128-1 /WINDOWS/system32/dllcache/shvlzm.exe 13312 ..c. r/rr-xr-xr-x 0 0 9594-128-1 /WINDOWS/system32/dllcache/sigtab.dll 70144 ..c. r/rr-xr-xr-x 0 0 9595-128-1 /WINDOWS/system32/dllcache/sigverif.exe 16384 ..c. r/rr-xr-xr-x 0 0 9596-128-1 /WINDOWS/system32/dllcache/simpdata.tlb 18944 ..c. r/rr-xr-xr-x 0 0 9597-128-3 /WINDOWS/system32/dllcache/simptcp.dll 13824 ..c. r/rr-xr-xr-x 0 0 9598-128-1 /WINDOWS/system32/dllcache/sisbkup.dll 5632 ..c. r/rr-xr-xr-x 0 0 9599-128-1 /WINDOWS/system32/dllcache/skdll.dll 272 .ac. d/dr-xr-xr-x 0 0 96-144-1 /WINDOWS/Resources/Themes/Luna/Shell/NormalColor 15998 ..c. r/rr-xr-xr-x 0 0 960-128-3 /WINDOWS/Help/mouse.hlp 26112 ..c. r/rr-xr-xr-x 0 0 9600-128-1 /WINDOWS/system32/dllcache/skeys.exe 306176 ..c. r/rr-xr-xr-x 0 0 9601-128-1 /WINDOWS/system32/dllcache/slbcsp.dll 98304 ..c. r/rr-xr-xr-x 0 0 9602-128-1 /WINDOWS/system32/dllcache/slbiop.dll 14848 ..c. r/rr-xr-xr-x 0 0 9603-128-1 /WINDOWS/system32/dllcache/slbrccsp.dll 25088 ..c. r/rr-xr-xr-x 0 0 9604-128-3 /WINDOWS/system32/dllcache/sm59w.dll 30208 ..c. r/rr-xr-xr-x 0 0 9605-128-3 /WINDOWS/system32/dllcache/sm81w.dll 30208 ..c. r/rr-xr-xr-x 0 0 9606-128-3 /WINDOWS/system32/dllcache/sm87w.dll 26112 ..c. r/rr-xr-xr-x 0 0 9607-128-3 /WINDOWS/system32/dllcache/sm89w.dll 26112 ..c. r/rr-xr-xr-x 0 0 9608-128-3 /WINDOWS/system32/dllcache/sm8aw.dll 29184 ..c. r/rr-xr-xr-x 0 0 9609-128-3 /WINDOWS/system32/dllcache/sm8cw.dll 177025 ..c. r/rr-xr-xr-x 0 0 961-128-3 /WINDOWS/Help/mpconcepts.chm 26112 ..c. r/rr-xr-xr-x 0 0 9610-128-3 /WINDOWS/system32/dllcache/sm8dw.dll 26112 ..c. r/rr-xr-xr-x 0 0 9611-128-3 /WINDOWS/system32/dllcache/sm90w.dll 26624 ..c. r/rr-xr-xr-x 0 0 9612-128-3 /WINDOWS/system32/dllcache/sm92w.dll 26624 ..c. r/rr-xr-xr-x 0 0 9613-128-3 /WINDOWS/system32/dllcache/sm93w.dll 38912 ..c. r/rr-xr-xr-x 0 0 9614-128-3 /WINDOWS/system32/dllcache/sm9aw.dll 31744 ..c. r/rr-xr-xr-x 0 0 9615-128-3 /WINDOWS/system32/dllcache/sma3w.dll 31744 ..c. r/rr-xr-xr-x 0 0 9616-128-3 /WINDOWS/system32/dllcache/smb6w.dll 8192 ..c. r/rr-xr-xr-x 0 0 9617-128-1 /WINDOWS/system32/dllcache/smbinst.exe 14592 ..c. r/rr-xr-xr-x 0 0 9618-128-1 /WINDOWS/system32/dllcache/smclib.sys 236544 ..c. r/rr-xr-xr-x 0 0 9619-128-3 /WINDOWS/system32/dllcache/smi2smir.exe 11187 ..c. r/rr-xr-xr-x 0 0 962-128-3 /WINDOWS/Help/mpnetwrk.hlp 15872 ..c. r/rr-xr-xr-x 0 0 9620-128-3 /WINDOWS/system32/dllcache/smierrsm.dll 5632 ..c. r/rr-xr-xr-x 0 0 9621-128-3 /WINDOWS/system32/dllcache/smierrsy.dll 5632 ..c. r/rr-xr-xr-x 0 0 9622-128-3 /WINDOWS/system32/dllcache/smimsgif.dll 362496 ..c. r/rr-xr-xr-x 0 0 9623-128-1 /WINDOWS/system32/dllcache/smlogcfg.dll 89600 ..c. r/rr-xr-xr-x 0 0 9624-128-1 /WINDOWS/system32/dllcache/smlogsvc.exe 50688 ..c. r/rr-xr-xr-x 0 0 9625-128-1 /WINDOWS/system32/dllcache/smss.exe 10752 ..c. r/rr-xr-xr-x 0 0 9626-128-3 /WINDOWS/system32/dllcache/smtpapi.dll 40960 ..c. r/rr-xr-xr-x 0 0 9627-128-1 /WINDOWS/system32/dllcache/smtpcons.dll 456192 ..c. r/rr-xr-xr-x 0 0 9628-128-3 /WINDOWS/system32/dllcache/smtpsvc.dll 12288 ..c. r/rr-xr-xr-x 0 0 9629-128-3 /WINDOWS/system32/dllcache/EXCH_smtpctrs.dll 131584 ..c. r/rr-xr-xr-x 0 0 9630-128-1 /WINDOWS/system32/dllcache/sndrec32.exe 138752 ..c. r/rr-xr-xr-x 0 0 9631-128-1 /WINDOWS/system32/dllcache/sndvol32.exe 34816 ..c. r/rr-xr-xr-x 0 0 9632-128-1 /WINDOWS/system32/dllcache/sniffpol.dll 33280 ..c. r/rr-xr-xr-x 0 0 9633-128-3 /WINDOWS/system32/dllcache/snmp.exe 18944 ..c. r/rr-xr-xr-x 0 0 9634-128-1 /WINDOWS/system32/dllcache/snmpapi.dll 259072 ..c. r/rr-xr-xr-x 0 0 9635-128-3 /WINDOWS/system32/dllcache/snmpcl.dll 358400 ..c. r/rr-xr-xr-x 0 0 9636-128-3 /WINDOWS/system32/dllcache/snmpincl.dll 6144 ..c. r/rr-xr-xr-x 0 0 9637-128-3 /WINDOWS/system32/dllcache/snmpmib.dll 188416 ..c. r/rr-xr-xr-x 0 0 9638-128-3 /WINDOWS/system32/dllcache/snmpsmir.dll 182272 ..c. r/rr-xr-xr-x 0 0 9639-128-1 /WINDOWS/system32/dllcache/snmpsnap.dll 10240 ..c. r/rr-xr-xr-x 0 0 9640-128-3 /WINDOWS/system32/dllcache/snmpstup.dll 39936 ..c. r/rr-xr-xr-x 0 0 9641-128-3 /WINDOWS/system32/dllcache/snmpthrd.dll 8704 ..c. r/rr-xr-xr-x 0 0 9642-128-3 /WINDOWS/system32/dllcache/snmptrap.exe 130048 ..c. r/rr-xr-xr-x 0 0 9643-128-1 /WINDOWS/system32/dllcache/softkbd.dll 7168 ..c. r/rr-xr-xr-x 0 0 9644-128-3 /WINDOWS/system32/dllcache/EXCH_snprfdll.dll 143422 ..c. r/rr-xr-xr-x 0 0 9645-128-3 /WINDOWS/system32/dllcache/softkey.dll 5632 ..c. r/rr-xr-xr-x 0 0 9646-128-1 /WINDOWS/system32/dllcache/softpub.dll 56832 ..c. r/rr-xr-xr-x 0 0 9647-128-1 /WINDOWS/system32/dllcache/sol.exe 24576 ..c. r/rr-xr-xr-x 0 0 9648-128-1 /WINDOWS/system32/dllcache/sort.exe 262148 ..c. r/rr-xr-xr-x 0 0 9649-128-1 /WINDOWS/system32/dllcache/sortkey.nls 23044 ..c. r/rr-xr-xr-x 0 0 9650-128-1 /WINDOWS/system32/dllcache/sorttbls.nls 77824 ..c. r/rr-xr-xr-x 0 0 9651-128-1 /WINDOWS/system32/dllcache/spcommon.dll 1744 ..c. r/rr-xr-xr-x 0 0 9652-128-1 /WINDOWS/system32/dllcache/sound.drv 61440 ..c. r/rr-xr-xr-x 0 0 9653-128-1 /WINDOWS/system32/dllcache/spcplui.dll 62976 ..c. r/rr-xr-xr-x 0 0 9654-128-1 /WINDOWS/system32/dllcache/spgrmr.dll 538624 ..c. r/rr-xr-xr-x 0 0 9655-128-1 /WINDOWS/system32/dllcache/spider.exe 12800 ..c. r/rr-xr-xr-x 0 0 9656-128-1 /WINDOWS/system32/dllcache/spiisupd.exe 11264 ..c. r/rr-xr-xr-x 0 0 9657-128-1 /WINDOWS/system32/dllcache/spnpinst.exe 75264 ..c. r/rr-xr-xr-x 0 0 9658-128-1 /WINDOWS/system32/dllcache/spoolss.dll 57856 ..c. r/rr-xr-xr-x 0 0 9659-128-1 /WINDOWS/system32/dllcache/spoolsv.exe 9728 ..c. r/rr-xr-xr-x 0 0 9660-128-1 /WINDOWS/system32/dllcache/sprestrt.exe 250368 ..c. r/rr-xr-xr-x 0 0 9661-128-1 /WINDOWS/system32/dllcache/sptip.dll 774144 ..c. r/rr-xr-xr-x 0 0 9662-128-1 /WINDOWS/system32/dllcache/spttseng.dll 24661 ..c. r/rr-xr-xr-x 0 0 9663-128-1 /WINDOWS/system32/dllcache/spxcoins.dll 151552 ..c. r/rr-xr-xr-x 0 0 9664-128-1 /WINDOWS/system32/dllcache/sqldb20.dll 462848 ..c. r/rr-xr-xr-x 0 0 9665-128-1 /WINDOWS/system32/dllcache/sqlqp20.dll 110592 ..c. r/rr-xr-xr-x 0 0 9666-128-1 /WINDOWS/system32/dllcache/sqlse20.dll 180800 ..c. r/rr-xr-xr-x 0 0 9667-128-1 /WINDOWS/system32/dllcache/sqlunirl.dll 217088 ..c. r/rr-xr-xr-x 0 0 9668-128-1 /WINDOWS/system32/dllcache/sqlxmlx.dll 73472 ..c. r/rr-xr-xr-x 0 0 9669-128-1 /WINDOWS/system32/dllcache/sr.sys 58434 ..c. r/rr-xr-xr-x 0 0 9670-128-1 /WINDOWS/system32/dllcache/srchctls.dll 726078 ..c. r/rr-xr-xr-x 0 0 9671-128-1 /WINDOWS/system32/dllcache/srchui.dll 67584 ..c. r/rr-xr-xr-x 0 0 9672-128-1 /WINDOWS/system32/dllcache/srclient.dll 47104 ..c. r/rr-xr-xr-x 0 0 9673-128-1 /WINDOWS/system32/dllcache/srdiag.exe 984 ..c. r/rr-xr-xr-x 0 0 9674-128-1 /WINDOWS/system32/dllcache/srframe.mmf 239104 ..c. r/rr-xr-xr-x 0 0 9675-128-1 /WINDOWS/system32/dllcache/srrstr.dll 171008 ..c. r/rr-xr-xr-x 0 0 9676-128-1 /WINDOWS/system32/dllcache/srsvc.dll 101376 ..c. r/rr-xr-xr-x 0 0 9677-128-3 /WINDOWS/system32/dllcache/srusbusd.dll 334848 ..c. r/rr-xr-xr-x 0 0 9678-128-1 /WINDOWS/system32/dllcache/srv.sys 96768 ..c. r/rr-xr-xr-x 0 0 9679-128-1 /WINDOWS/system32/dllcache/srvsvc.dll 704512 ..c. r/rr-xr-xr-x 0 0 9680-128-1 /WINDOWS/system32/dllcache/ss3dfo.scr 19968 ..c. r/rr-xr-xr-x 0 0 9681-128-1 /WINDOWS/system32/dllcache/ssbezier.scr 34816 ..c. r/rr-xr-xr-x 0 0 9682-128-1 /WINDOWS/system32/dllcache/ssdpapi.dll 71680 ..c. r/rr-xr-xr-x 0 0 9683-128-1 /WINDOWS/system32/dllcache/ssdpsrv.dll 393216 ..c. r/rr-xr-xr-x 0 0 9684-128-1 /WINDOWS/system32/dllcache/ssflwbox.scr 45056 ..c. r/rr-xr-xr-x 0 0 9685-128-3 /WINDOWS/system32/dllcache/ssinc51.dll 20992 ..c. r/rr-xr-xr-x 0 0 9686-128-1 /WINDOWS/system32/dllcache/ssmarque.scr 47104 ..c. r/rr-xr-xr-x 0 0 9687-128-1 /WINDOWS/system32/dllcache/ssmypics.scr 18944 ..c. r/rr-xr-xr-x 0 0 9688-128-1 /WINDOWS/system32/dllcache/ssmyst.scr 46592 ..c. r/rr-xr-xr-x 0 0 9689-128-3 /WINDOWS/system32/dllcache/sspifilt.dll 610304 ..c. r/rr-xr-xr-x 0 0 9690-128-1 /WINDOWS/system32/dllcache/sspipes.scr 14336 ..c. r/rr-xr-xr-x 0 0 9691-128-1 /WINDOWS/system32/dllcache/ssstars.scr 679936 ..c. r/rr-xr-xr-x 0 0 9692-128-1 /WINDOWS/system32/dllcache/sstext3d.scr 33280 ..c. r/rr-xr-xr-x 0 0 9693-128-1 /WINDOWS/system32/dllcache/sstub.dll 16896 ..c. r/rr-xr-xr-x 0 0 9694-128-3 /WINDOWS/system32/dllcache/status.dll 59392 ..c. r/rr-xr-xr-x 0 0 9695-128-1 /WINDOWS/system32/dllcache/stclient.dll 5532 ..c. r/rr-xr-xr-x 0 0 9696-128-1 /WINDOWS/system32/dllcache/stdole.tlb 7168 ..c. r/rr-xr-xr-x 0 0 9697-128-1 /WINDOWS/system32/dllcache/stdole32.tlb 86528 ..c. r/rr-xr-xr-x 0 0 9698-128-1 /WINDOWS/system32/dllcache/stdprov.dll 68096 ..c. r/rr-xr-xr-x 0 0 9699-128-1 /WINDOWS/system32/dllcache/sti.dll 136704 ..c. r/rr-xr-xr-x 0 0 9700-128-1 /WINDOWS/system32/dllcache/sti_ci.dll 14848 ..c. r/rr-xr-xr-x 0 0 9701-128-1 /WINDOWS/system32/dllcache/stimon.exe 121856 ..c. r/rr-xr-xr-x 0 0 9702-128-1 /WINDOWS/system32/dllcache/stobject.dll 4208 ..c. r/rr-xr-xr-x 0 0 9703-128-1 /WINDOWS/system32/dllcache/storage.dll 75776 ..c. r/rr-xr-xr-x 0 0 9704-128-1 /WINDOWS/system32/dllcache/strmfilt.dll 9216 ..c. r/rr-xr-xr-x 0 0 9705-128-1 /WINDOWS/system32/dllcache/subst.exe 46592 ..c. r/rr-xr-xr-x 0 0 9706-128-3 /WINDOWS/system32/dllcache/svcext51.dll 14336 ..c. r/rr-xr-xr-x 0 0 9707-128-1 /WINDOWS/system32/dllcache/svchost.exe 6144 ..c. r/rr-xr-xr-x 0 0 9708-128-1 /WINDOWS/system32/dllcache/svcpack.dll 138752 ..c. r/rr-xr-xr-x 0 0 9709-128-1 /WINDOWS/system32/dllcache/swprv.dll 713216 ..c. r/rr-xr-xr-x 0 0 9710-128-1 /WINDOWS/system32/dllcache/sxs.dll 51200 ..c. r/rr-xr-xr-x 0 0 9711-128-1 /WINDOWS/system32/dllcache/syncapp.exe 57856 ..c. r/rr-xr-xr-x 0 0 9712-128-1 /WINDOWS/system32/dllcache/synceng.dll 191488 ..c. r/rr-xr-xr-x 0 0 9713-128-1 /WINDOWS/system32/dllcache/syncui.dll 300544 ..c. r/rr-xr-xr-x 0 0 9714-128-1 /WINDOWS/system32/dllcache/sysdm.cpl 18896 ..c. r/rr-xr-xr-x 0 0 9715-128-1 /WINDOWS/system32/dllcache/sysedit.exe 15872 ..c. r/rr-xr-xr-x 0 0 9716-128-1 /WINDOWS/system32/dllcache/sysinv.dll 36864 ..c. r/rr-xr-xr-x 0 0 9717-128-1 /WINDOWS/system32/dllcache/syskey.exe 193024 ..c. r/rr-xr-xr-x 0 0 9718-128-1 /WINDOWS/system32/dllcache/sysmod.dll 72387 ..c. r/rr-xr-xr-x 0 0 9719-128-1 /WINDOWS/system32/dllcache/archvapp.inf 17920 ..c. r/rr-xr-xr-x 0 0 9720-128-1 /WINDOWS/system32/dllcache/cobramsg.dll 115200 ..c. r/rr-xr-xr-x 0 0 9721-128-1 /WINDOWS/system32/dllcache/guitrna.dll 261120 ..c. r/rr-xr-xr-x 0 0 9722-128-1 /WINDOWS/system32/dllcache/migisma.dll 241152 ..c. r/rr-xr-xr-x 0 0 9723-128-1 /WINDOWS/system32/dllcache/migwiza.exe 199680 ..c. r/rr-xr-xr-x 0 0 9724-128-1 /WINDOWS/system32/dllcache/scripta.dll 173568 ..c. r/rr-xr-xr-x 0 0 9725-128-1 /WINDOWS/system32/dllcache/sysmoda.dll 218624 ..c. r/rr-xr-xr-x 0 0 9726-128-1 /WINDOWS/system32/dllcache/sysmon.ocx 990208 ..c. r/rr-xr-xr-x 0 0 9727-128-1 /WINDOWS/system32/dllcache/syssetup.dll 71680 ..c. r/rr-xr-xr-x 0 0 9728-128-1 /WINDOWS/system32/dllcache/sysinfo.exe 3360 ..c. r/rr-xr-xr-x 0 0 9729-128-1 /WINDOWS/system32/dllcache/system.drv 3072 ..c. r/rr-xr-xr-x 0 0 9730-128-1 /WINDOWS/system32/dllcache/systray.exe 117760 ..c. r/rr-xr-xr-x 0 0 9731-128-1 /WINDOWS/system32/dllcache/t2embed.dll 33792 ..c. r/rr-xr-xr-x 0 0 9732-128-1 /WINDOWS/system32/dllcache/tabletoc.dll 14976 ..c. r/rr-xr-xr-x 0 0 9733-128-1 /WINDOWS/system32/dllcache/tape.sys 858624 ..c. r/rr-xr-xr-x 0 0 9734-128-1 /WINDOWS/system32/dllcache/tapi3.dll 19200 ..c. r/rr-xr-xr-x 0 0 9735-128-1 /WINDOWS/system32/dllcache/tapi.dll 181760 ..c. r/rr-xr-xr-x 0 0 9736-128-1 /WINDOWS/system32/dllcache/tapi32.dll 5632 ..c. r/rr-xr-xr-x 0 0 9737-128-1 /WINDOWS/system32/dllcache/tapiperf.dll 249856 ..c. r/rr-xr-xr-x 0 0 9738-128-1 /WINDOWS/system32/dllcache/tapisrv.dll 78848 ..c. r/rr-xr-xr-x 0 0 9739-128-1 /WINDOWS/system32/dllcache/tapiui.dll 31924 ..c. r/rr-xr-xr-x 0 0 974-128-3 /WINDOWS/Help/mqsnap.hlp 76288 ..c. r/rr-xr-xr-x 0 0 9740-128-1 /WINDOWS/system32/dllcache/taskkill.exe 77824 ..c. r/rr-xr-xr-x 0 0 9741-128-1 /WINDOWS/system32/dllcache/tasklist.exe 15360 ..c. r/rr-xr-xr-x 0 0 9742-128-1 /WINDOWS/system32/dllcache/taskman.exe 135680 ..c. r/rr-xr-xr-x 0 0 9743-128-1 /WINDOWS/system32/dllcache/taskmgr.exe 12288 ..c. r/rr-xr-xr-x 0 0 9744-128-1 /WINDOWS/system32/dllcache/tcmsetup.exe 361344 ..c. r/rr-xr-xr-x 0 0 9745-128-1 /WINDOWS/system32/dllcache/tcpip.sys 225664 ..c. r/rr-xr-xr-x 0 0 9746-128-1 /WINDOWS/system32/dllcache/tcpip6.sys 14848 ..c. r/rr-xr-xr-x 0 0 9747-128-1 /WINDOWS/system32/dllcache/tcpmib.dll 45568 ..c. r/rr-xr-xr-x 0 0 9748-128-1 /WINDOWS/system32/dllcache/tcpmon.dll 45568 ..c. r/rr-xr-xr-x 0 0 9749-128-1 /WINDOWS/system32/dllcache/tcpmonui.dll 324 ..c. r/rr-xr-xr-x 0 0 975-128-1 /WINDOWS/inf/mqsysoc.inf 19456 ..c. r/rr-xr-xr-x 0 0 9750-128-1 /WINDOWS/system32/dllcache/tcpsvcs.exe 13192 ..c. r/rr-xr-xr-x 0 0 9751-128-3 /WINDOWS/system32/dllcache/tdasync.sys 61440 ..c. r/rr-xr-xr-x 0 0 9752-128-1 /WINDOWS/system32/dllcache/tdc.ocx 19072 ..c. r/rr-xr-xr-x 0 0 9753-128-1 /WINDOWS/system32/dllcache/tdi.sys 21896 ..c. r/rr-xr-xr-x 0 0 9754-128-3 /WINDOWS/system32/dllcache/tdipx.sys 12040 ..c. r/rr-xr-xr-x 0 0 9755-128-1 /WINDOWS/system32/dllcache/tdpipe.sys 19464 ..c. r/rr-xr-xr-x 0 0 9756-128-3 /WINDOWS/system32/dllcache/tdspx.sys 21896 ..c. r/rr-xr-xr-x 0 0 9757-128-1 /WINDOWS/system32/dllcache/tdtcp.sys 28160 ..c. r/rr-xr-xr-x 0 0 9758-128-1 /WINDOWS/system32/dllcache/telephon.cpl 75776 ..c. r/rr-xr-xr-x 0 0 9759-128-1 /WINDOWS/system32/dllcache/telnet.exe 358400 ..c. r/rr-xr-xr-x 0 0 9760-128-1 /WINDOWS/system32/dllcache/termmgr.dll 295424 ..c. r/rr-xr-xr-x 0 0 9761-128-1 /WINDOWS/system32/dllcache/termsrv.dll 16896 ..c. r/rr-xr-xr-x 0 0 9762-128-1 /WINDOWS/system32/dllcache/tftp.exe 185344 ..c. r/rr-xr-xr-x 0 0 9763-128-3 /WINDOWS/system32/dllcache/thawbrkr.dll 385536 ..c. r/rr-xr-xr-x 0 0 9764-128-1 /WINDOWS/system32/dllcache/themeui.dll 94208 ..c. r/rr-xr-xr-x 0 0 9765-128-1 /WINDOWS/system32/dllcache/timedate.cpl 571392 ..c. r/rr-xr-xr-x 0 0 9766-128-3 /WINDOWS/system32/dllcache/tintlgnt.ime 4048 ..c. r/rr-xr-xr-x 0 0 9767-128-1 /WINDOWS/system32/dllcache/timer.drv 44032 ..c. r/rr-xr-xr-x 0 0 9768-128-3 /WINDOWS/system32/dllcache/tintlphr.exe 455168 ..c. r/rr-xr-xr-x 0 0 9769-128-3 /WINDOWS/system32/dllcache/tintsetp.exe 61440 ..c. r/rr-xr-xr-x 0 0 9770-128-1 /WINDOWS/system32/dllcache/tlntadmn.exe 78336 ..c. r/rr-xr-xr-x 0 0 9771-128-1 /WINDOWS/system32/dllcache/tlntsess.exe 73216 ..c. r/rr-xr-xr-x 0 0 9772-128-1 /WINDOWS/system32/dllcache/tlntsvr.exe 7168 ..c. r/rr-xr-xr-x 0 0 9773-128-1 /WINDOWS/system32/dllcache/tlntsvrp.dll 10240 ..c. r/rr-xr-xr-x 0 0 9774-128-3 /WINDOWS/system32/dllcache/tmigrate.dll 61952 ..c. r/rr-xr-xr-x 0 0 9775-128-1 /WINDOWS/system32/dllcache/tmplprov.dll 13888 ..c. r/rr-xr-xr-x 0 0 9776-128-1 /WINDOWS/system32/dllcache/toolhelp.dll 33792 ..c. r/rr-xr-xr-x 0 0 9777-128-3 /WINDOWS/system32/dllcache/tools.dll 3374640 ..c. r/rr-xr-xr-x 0 0 9778-128-1 /WINDOWS/system32/dllcache/tourW.exe 347136 ..c. r/rr-xr-xr-x 0 0 9779-128-1 /WINDOWS/system32/dllcache/tourstrt.exe 259584 ..c. r/rr-xr-xr-x 0 0 9780-128-1 /WINDOWS/system32/dllcache/tracerpt.exe 12288 ..c. r/rr-xr-xr-x 0 0 9781-128-1 /WINDOWS/system32/dllcache/tracert.exe 31744 ..c. r/rr-xr-xr-x 0 0 9782-128-1 /WINDOWS/system32/dllcache/tracert6.exe 31232 ..c. r/rr-xr-xr-x 0 0 9783-128-1 /WINDOWS/system32/dllcache/traffic.dll 40960 ..c. r/rr-xr-xr-x 0 0 9784-128-1 /WINDOWS/system32/dllcache/trialoc.dll 153088 ..c. r/rr-xr-xr-x 0 0 9785-128-1 /WINDOWS/system32/dllcache/triedit.dll 90112 ..c. r/rr-xr-xr-x 0 0 9786-128-1 /WINDOWS/system32/dllcache/trkwks.dll 59904 ..c. r/rr-xr-xr-x 0 0 9787-128-1 /WINDOWS/system32/dllcache/trnsprov.dll 52224 ..c. r/rr-xr-xr-x 0 0 9788-128-1 /WINDOWS/system32/dllcache/tsappcmp.dll 93696 ..c. r/rr-xr-xr-x 0 0 9789-128-1 /WINDOWS/system32/dllcache/tscfgwmi.dll 14848 ..c. r/rr-xr-xr-x 0 0 9790-128-1 /WINDOWS/system32/dllcache/tscon.exe 15360 ..c. r/rr-xr-xr-x 0 0 9791-128-1 /WINDOWS/system32/dllcache/tsd32.dll 12168 ..c. r/rr-xr-xr-x 0 0 9792-128-1 /WINDOWS/system32/dllcache/tsddd.dll 14848 ..c. r/rr-xr-xr-x 0 0 9793-128-1 /WINDOWS/system32/dllcache/tsdiscon.exe 53248 ..c. r/rr-xr-xr-x 0 0 9794-128-1 /WINDOWS/system32/dllcache/tsgqec.dll 279040 ..c. r/rr-xr-xr-x 0 0 9795-128-1 /WINDOWS/system32/dllcache/tshoot.dll 16384 ..c. r/rr-xr-xr-x 0 0 9796-128-1 /WINDOWS/system32/dllcache/tskill.exe 130048 ..c. r/rr-xr-xr-x 0 0 9797-128-1 /WINDOWS/system32/dllcache/tsoc.dll 50688 ..c. r/rr-xr-xr-x 0 0 9798-128-1 /WINDOWS/system32/dllcache/tspkg.dll 14336 ..c. r/rr-xr-xr-x 0 0 9799-128-3 /WINDOWS/system32/dllcache/tsprof.exe 16896 ..c. r/rr-xr-xr-x 0 0 9800-128-1 /WINDOWS/system32/dllcache/tsshutdn.exe 94784 ..c. r/rr-xr-xr-x 0 0 9801-128-1 /WINDOWS/system32/dllcache/twain.dll 50688 ..c. r/rr-xr-xr-x 0 0 9802-128-1 /WINDOWS/system32/dllcache/twain_32.dll 57856 ..c. r/rr-xr-xr-x 0 0 9803-128-1 /WINDOWS/system32/dllcache/twext.dll 101376 ..c. r/rr-xr-xr-x 0 0 9804-128-1 /WINDOWS/system32/dllcache/txflog.dll 36352 ..c. r/rr-xr-xr-x 0 0 9805-128-1 /WINDOWS/system32/dllcache/typeperf.exe 66048 ..c. r/rr-xr-xr-x 0 0 9806-128-1 /WINDOWS/system32/dllcache/udfs.sys 26624 ..c. r/rr-xr-xr-x 0 0 9807-128-1 /WINDOWS/system32/dllcache/udhisapi.dll 82432 ..c. r/rr-xr-xr-x 0 0 9808-128-1 /WINDOWS/system32/dllcache/ufat.dll 103424 ..c. r/rr-xr-xr-x 0 0 9809-128-3 /WINDOWS/system32/dllcache/uihelper.dll 275456 ..c. r/rr-xr-xr-x 0 0 9810-128-1 /WINDOWS/system32/dllcache/ulib.dll 35840 ..c. r/rr-xr-xr-x 0 0 9811-128-1 /WINDOWS/system32/dllcache/umandlg.dll 13312 ..c. r/rr-xr-xr-x 0 0 9812-128-1 /WINDOWS/system32/dllcache/umdmxfrm.dll 32339 ..c. r/rr-xr-xr-x 0 0 9813-128-1 /WINDOWS/system32/dllcache/uniansi.dll 65024 ..c. r/rr-xr-xr-x 0 0 9814-128-3 /WINDOWS/system32/dllcache/unicdime.ime 89588 ..c. r/rr-xr-xr-x 0 0 9815-128-1 /WINDOWS/system32/dllcache/unicode.nls 76288 ..c. r/rr-xr-xr-x 0 0 9816-128-3 /WINDOWS/system32/dllcache/uniime.dll 206848 ..c. r/rr-xr-xr-x 0 0 9817-128-1 /WINDOWS/system32/dllcache/unimdm.tsp 74240 ..c. r/rr-xr-xr-x 0 0 9818-128-1 /WINDOWS/system32/dllcache/unimdmat.dll 13824 ..c. r/rr-xr-xr-x 0 0 9819-128-1 /WINDOWS/system32/dllcache/uniplat.dll 17240 ..c. r/rr-xr-xr-x 0 0 982-128-3 /WINDOWS/Help/msconfig.chm 4096 ..c. r/rr-xr-xr-x 0 0 9820-128-1 /WINDOWS/system32/dllcache/unlodctr.exe 16896 ..c. r/rr-xr-xr-x 0 0 9821-128-1 /WINDOWS/system32/dllcache/unsecapp.exe 316416 ..c. r/rr-xr-xr-x 0 0 9822-128-1 /WINDOWS/system32/dllcache/untfs.dll 384768 ..c. r/rr-xr-xr-x 0 0 9823-128-1 /WINDOWS/system32/dllcache/update.sys 116224 ..c. r/rr-xr-xr-x 0 0 9824-128-1 /WINDOWS/system32/dllcache/updprov.dll 150528 ..c. r/rr-xr-xr-x 0 0 9825-128-1 /WINDOWS/system32/dllcache/uploadm.exe 133632 ..c. r/rr-xr-xr-x 0 0 9826-128-1 /WINDOWS/system32/dllcache/upnp.dll 16896 ..c. r/rr-xr-xr-x 0 0 9827-128-1 /WINDOWS/system32/dllcache/upnpcont.exe 185856 ..c. r/rr-xr-xr-x 0 0 9828-128-1 /WINDOWS/system32/dllcache/upnphost.dll 239616 ..c. r/rr-xr-xr-x 0 0 9829-128-1 /WINDOWS/system32/dllcache/upnpui.dll 1701 ..c. r/rr-xr-xr-x 0 0 983-128-3 /WINDOWS/inf/mscpqpa1.inf 18432 ..c. r/rr-xr-xr-x 0 0 9830-128-1 /WINDOWS/system32/dllcache/ups.exe 17920 ..c. r/rr-xr-xr-x 0 0 9831-128-1 /WINDOWS/system32/dllcache/ureg.dll 12800 ..c. r/rr-xr-xr-x 0 0 9832-128-1 /WINDOWS/system32/dllcache/usb8023.sys 16896 ..c. r/rr-xr-xr-x 0 0 9833-128-1 /WINDOWS/system32/dllcache/usbmon.dll 47872 ..c. r/rr-xr-xr-x 0 0 9834-128-1 /WINDOWS/system32/dllcache/user.exe 578560 ..c. r/rr-xr-xr-x 0 0 9835-128-1 /WINDOWS/system32/dllcache/user32.dll 727040 ..c. r/rr-xr-xr-x 0 0 9836-128-1 /WINDOWS/system32/dllcache/userenv.dll 26112 ..c. r/rr-xr-xr-x 0 0 9837-128-1 /WINDOWS/system32/dllcache/userinit.exe 406016 ..c. r/rr-xr-xr-x 0 0 9838-128-1 /WINDOWS/system32/dllcache/usp10.dll 25600 ..c. r/rr-xr-xr-x 0 0 9839-128-1 /WINDOWS/system32/dllcache/utildll.dll 15723 ..c. r/rr-xr-xr-x 0 0 984-128-3 /WINDOWS/Help/msdasc.chm 50176 ..c. r/rr-xr-xr-x 0 0 9840-128-1 /WINDOWS/system32/dllcache/utilman.exe 218624 ..c. r/rr-xr-xr-x 0 0 9841-128-1 /WINDOWS/system32/dllcache/uxtheme.dll 53248 ..c. r/rr-xr-xr-x 0 0 9842-128-1 /WINDOWS/system32/dllcache/vbicodec.ax 30208 ..c. r/rr-xr-xr-x 0 0 9843-128-1 /WINDOWS/system32/dllcache/vbisurf.ax 7680 ..c. r/rr-xr-xr-x 0 0 9844-128-1 /WINDOWS/system32/dllcache/vcdex.dll 26112 ..c. r/rr-xr-xr-x 0 0 9845-128-1 /WINDOWS/system32/dllcache/vdmdbg.dll 51712 ..c. r/rr-xr-xr-x 0 0 9846-128-1 /WINDOWS/system32/dllcache/vdmredir.dll 26624 ..c. r/rr-xr-xr-x 0 0 9847-128-1 /WINDOWS/system32/dllcache/verifier.dll 9008 ..c. r/rr-xr-xr-x 0 0 9848-128-1 /WINDOWS/system32/dllcache/ver.dll 98304 ..c. r/rr-xr-xr-x 0 0 9849-128-1 /WINDOWS/system32/dllcache/verifier.exe 18944 ..c. r/rr-xr-xr-x 0 0 9850-128-1 /WINDOWS/system32/dllcache/version.dll 9344 ..c. r/rr-xr-xr-x 0 0 9851-128-1 /WINDOWS/system32/dllcache/vga.dll 20992 ..c. r/rr-xr-xr-x 0 0 9852-128-1 /WINDOWS/system32/dllcache/vga.sys 2176 ..c. r/rr-xr-xr-x 0 0 9853-128-1 /WINDOWS/system32/dllcache/vga.drv 51456 ..c. r/rr-xr-xr-x 0 0 9854-128-1 /WINDOWS/system32/dllcache/vga256.dll 18176 ..c. r/rr-xr-xr-x 0 0 9855-128-1 /WINDOWS/system32/dllcache/vga64k.dll 851968 ..c. r/rr-xr-xr-x 0 0 9856-128-1 /WINDOWS/system32/dllcache/vgx.dll 81664 ..c. r/rr-xr-xr-x 0 0 9857-128-1 /WINDOWS/system32/dllcache/videoprt.sys 131584 ..c. r/rr-xr-xr-x 0 0 9858-128-1 /WINDOWS/system32/dllcache/viewprov.dll 4608 ..c. r/rr-xr-xr-x 0 0 9859-128-1 /WINDOWS/system32/dllcache/vjoy.dll 31107 ..c. r/rr-xr-xr-x 0 0 986-128-3 /WINDOWS/inf/msdv.inf 18944 ..c. r/rr-xr-xr-x 0 0 9860-128-1 /WINDOWS/system32/dllcache/vmmreg32.dll 426041 ..c. r/rr-xr-xr-x 0 0 9861-128-3 /WINDOWS/system32/dllcache/voicepad.dll 86073 ..c. r/rr-xr-xr-x 0 0 9862-128-3 /WINDOWS/system32/dllcache/voicesub.dll 52352 ..c. r/rr-xr-xr-x 0 0 9863-128-1 /WINDOWS/system32/dllcache/volsnap.sys 16896 ..c. r/rr-xr-xr-x 0 0 9864-128-1 /WINDOWS/system32/dllcache/vss_ps.dll 33792 ..c. r/rr-xr-xr-x 0 0 9865-128-1 /WINDOWS/system32/dllcache/vssadmin.exe 430592 ..c. r/rr-xr-xr-x 0 0 9866-128-1 /WINDOWS/system32/dllcache/vssapi.dll 289792 ..c. r/rr-xr-xr-x 0 0 9867-128-1 /WINDOWS/system32/dllcache/vssvc.exe 19456 ..c. r/rr-xr-xr-x 0 0 9868-128-1 /WINDOWS/system32/dllcache/vwipxspx.dll 1129 ..c. r/rr-xr-xr-x 0 0 9869-128-1 /WINDOWS/system32/dllcache/vwipxspx.exe 48256 ..c. r/rr-xr-xr-x 0 0 9870-128-3 /WINDOWS/system32/dllcache/w32.dll 175104 ..c. r/rr-xr-xr-x 0 0 9871-128-1 /WINDOWS/system32/dllcache/w32time.dll 49664 ..c. r/rr-xr-xr-x 0 0 9872-128-1 /WINDOWS/system32/dllcache/w32tm.exe 22016 ..c. r/rr-xr-xr-x 0 0 9873-128-1 /WINDOWS/system32/dllcache/w32topl.dll 4608 ..c. r/rr-xr-xr-x 0 0 9874-128-3 /WINDOWS/system32/dllcache/w3ctrs51.dll 73728 ..c. r/rr-xr-xr-x 0 0 9875-128-3 /WINDOWS/system32/dllcache/w3ext.dll 15872 ..c. r/rr-xr-xr-x 0 0 9876-128-1 /WINDOWS/system32/dllcache/w3ssl.dll 5632 ..c. r/rr-xr-xr-x 0 0 9877-128-3 /WINDOWS/system32/dllcache/w3svapi.dll 364032 ..c. r/rr-xr-xr-x 0 0 9878-128-3 /WINDOWS/system32/dllcache/w3svc.dll 46080 ..c. r/rr-xr-xr-x 0 0 9879-128-1 /WINDOWS/system32/dllcache/wab.exe 510976 ..c. r/rr-xr-xr-x 0 0 9880-128-1 /WINDOWS/system32/dllcache/wab32.dll 249856 ..c. r/rr-xr-xr-x 0 0 9881-128-1 /WINDOWS/system32/dllcache/wab32res.dll 32768 ..c. r/rr-xr-xr-x 0 0 9882-128-1 /WINDOWS/system32/dllcache/wabfind.dll 85504 ..c. r/rr-xr-xr-x 0 0 9883-128-1 /WINDOWS/system32/dllcache/wabimp.dll 30208 ..c. r/rr-xr-xr-x 0 0 9884-128-1 /WINDOWS/system32/dllcache/wabmig.exe 76800 ..c. r/rr-xr-xr-x 0 0 9885-128-3 /WINDOWS/system32/dllcache/wam51.dll 9216 ..c. r/rr-xr-xr-x 0 0 9886-128-3 /WINDOWS/system32/dllcache/wamps51.dll 53248 ..c. r/rr-xr-xr-x 0 0 9887-128-3 /WINDOWS/system32/dllcache/wamreg51.dll 34560 ..c. r/rr-xr-xr-x 0 0 9888-128-1 /WINDOWS/system32/dllcache/wanarp.sys 17664 ..c. r/rr-xr-xr-x 0 0 9889-128-1 /WINDOWS/system32/dllcache/watchdog.sys 215552 ..c. r/rr-xr-xr-x 0 0 9890-128-1 /WINDOWS/system32/dllcache/wavemsp.dll 12288 ..c. r/rr-xr-xr-x 0 0 9891-128-1 /WINDOWS/system32/dllcache/wb32.exe 12288 ..c. r/rr-xr-xr-x 0 0 9892-128-1 /WINDOWS/system32/dllcache/wbemads.dll 31232 ..c. r/rr-xr-xr-x 0 0 9893-128-1 /WINDOWS/system32/dllcache/wbemads.tlb 196608 ..c. r/rr-xr-xr-x 0 0 9894-128-1 /WINDOWS/system32/dllcache/wbemcntl.dll 214528 ..c. r/rr-xr-xr-x 0 0 9895-128-1 /WINDOWS/system32/dllcache/wbemcomn.dll 71680 ..c. r/rr-xr-xr-x 0 0 9896-128-1 /WINDOWS/system32/dllcache/wbemcons.dll 531456 ..c. r/rr-xr-xr-x 0 0 9897-128-1 /WINDOWS/system32/dllcache/wbemcore.dll 178176 ..c. r/rr-xr-xr-x 0 0 9898-128-1 /WINDOWS/system32/dllcache/wbemdisp.dll 59904 ..c. r/rr-xr-xr-x 0 0 9899-128-1 /WINDOWS/system32/dllcache/wbemdisp.tlb 11211 ..c. r/rr-xr-xr-x 0 0 990-128-3 /WINDOWS/Help/mshearts.hlp 273920 ..c. r/rr-xr-xr-x 0 0 9900-128-1 /WINDOWS/system32/dllcache/wbemess.dll 43008 ..c. r/rr-xr-xr-x 0 0 9901-128-1 /WINDOWS/system32/dllcache/wbemperf.dll 18944 ..c. r/rr-xr-xr-x 0 0 9902-128-1 /WINDOWS/system32/dllcache/wbemprox.dll 43520 ..c. r/rr-xr-xr-x 0 0 9903-128-1 /WINDOWS/system32/dllcache/wbemsvc.dll 116224 ..c. r/rr-xr-xr-x 0 0 9904-128-1 /WINDOWS/system32/dllcache/wbemtest.exe 197120 ..c. r/rr-xr-xr-x 0 0 9905-128-1 /WINDOWS/system32/dllcache/wbemupgd.dll 49152 ..c. r/rr-xr-xr-x 0 0 9906-128-1 /WINDOWS/system32/dllcache/wdigest.dll 276480 ..c. r/rr-xr-xr-x 0 0 9907-128-1 /WINDOWS/system32/dllcache/webcheck.dll 68096 ..c. r/rr-xr-xr-x 0 0 9908-128-1 /WINDOWS/system32/dllcache/webclnt.dll 40448 ..c. r/rr-xr-xr-x 0 0 9909-128-1 /WINDOWS/system32/dllcache/webhits.dll 227 ..c. r/rr-xr-xr-x 0 0 991-128-1 /WINDOWS/Help/mshearts.cnt 135680 ..c. r/rr-xr-xr-x 0 0 9910-128-1 /WINDOWS/system32/dllcache/webvw.dll 41600 ..c. r/rr-xr-xr-x 0 0 9911-128-3 /WINDOWS/system32/dllcache/weitekp9.dll 31232 ..c. r/rr-xr-xr-x 0 0 9912-128-3 /WINDOWS/system32/dllcache/weitekp9.sys 65024 ..c. r/rr-xr-xr-x 0 0 9913-128-1 /WINDOWS/system32/dllcache/wextract.exe 433664 ..c. r/rr-xr-xr-x 0 0 9914-128-1 /WINDOWS/system32/dllcache/wiaacmgr.exe 13600 ..c. r/rr-xr-xr-x 0 0 9915-128-1 /WINDOWS/system32/dllcache/wfwnet.drv 463360 ..c. r/rr-xr-xr-x 0 0 9916-128-1 /WINDOWS/system32/dllcache/wiadefui.dll 124416 ..c. r/rr-xr-xr-x 0 0 9917-128-1 /WINDOWS/system32/dllcache/wiadss.dll 75776 ..c. r/rr-xr-xr-x 0 0 9918-128-1 /WINDOWS/system32/dllcache/wiascr.dll 333824 ..c. r/rr-xr-xr-x 0 0 9919-128-1 /WINDOWS/system32/dllcache/wiaservc.dll 3677 ..c. r/rr-xr-xr-x 0 0 992-128-3 /WINDOWS/inf/msinfo32.inf 40448 ..c. r/rr-xr-xr-x 0 0 9920-128-1 /WINDOWS/system32/dllcache/wiasf.ax 589312 ..c. r/rr-xr-xr-x 0 0 9921-128-1 /WINDOWS/system32/dllcache/wiashext.dll 111104 ..c. r/rr-xr-xr-x 0 0 9922-128-1 /WINDOWS/system32/dllcache/wiavideo.dll 145408 ..c. r/rr-xr-xr-x 0 0 9923-128-1 /WINDOWS/system32/dllcache/wiavusd.dll 9216 ..c. r/rr-xr-xr-x 0 0 9924-128-1 /WINDOWS/system32/dllcache/wifeman.dll 1845632 ..c. r/rr-xr-xr-x 0 0 9925-128-1 /WINDOWS/system32/dllcache/win32k.sys 102400 ..c. r/rr-xr-xr-x 0 0 9926-128-1 /WINDOWS/system32/dllcache/win32spl.dll 13312 ..c. r/rr-xr-xr-x 0 0 9927-128-1 /WINDOWS/system32/dllcache/win87em.dll 79360 ..c. r/rr-xr-xr-x 0 0 9928-128-3 /WINDOWS/system32/dllcache/winar30.ime 1647616 ..c. r/rr-xr-xr-x 0 0 9929-128-1 /WINDOWS/system32/dllcache/winbrand.dll 35328 ..c. r/rr-xr-xr-x 0 0 9930-128-1 /WINDOWS/system32/dllcache/winchat.exe 9216 ..c. r/rr-xr-xr-x 0 0 9931-128-1 /WINDOWS/system32/dllcache/winfax.dll 72704 ..c. r/rr-xr-xr-x 0 0 9932-128-3 /WINDOWS/system32/dllcache/wingb.ime 256192 ..c. r/rr-xr-xr-x 0 0 9933-128-1 /WINDOWS/system32/dllcache/winhelp.exe 283648 ..c. r/rr-xr-xr-x 0 0 9934-128-1 /WINDOWS/system32/dllcache/winhlp32.exe 8192 ..c. r/rr-xr-xr-x 0 0 9935-128-1 /WINDOWS/system32/dllcache/winhstb.exe 354304 ..c. r/rr-xr-xr-x 0 0 9936-128-1 /WINDOWS/system32/dllcache/winhttp.dll 65536 ..c. r/rr-xr-xr-x 0 0 9937-128-3 /WINDOWS/system32/dllcache/winime.ime 32256 ..c. r/rr-xr-xr-x 0 0 9938-128-1 /WINDOWS/system32/dllcache/winipsec.dll 13312 ..c. r/rr-xr-xr-x 0 0 9939-128-1 /WINDOWS/system32/dllcache/winmgmt.exe 31768 ..c. r/rr-xr-xr-x 0 0 994-128-3 /WINDOWS/inf/msmouse.inf 16384 ..c. r/rr-xr-xr-x 0 0 9940-128-1 /WINDOWS/system32/dllcache/winmgmtr.dll 119808 ..c. r/rr-xr-xr-x 0 0 9941-128-1 /WINDOWS/system32/dllcache/winmine.exe 176128 ..c. r/rr-xr-xr-x 0 0 9942-128-1 /WINDOWS/system32/dllcache/winmm.dll 11776 ..c. r/rr-xr-xr-x 0 0 9943-128-1 /WINDOWS/system32/dllcache/winmsd.exe 5120 ..c. r/rr-xr-xr-x 0 0 9944-128-1 /WINDOWS/system32/dllcache/winnls.dll 756224 ..c. r/rr-xr-xr-x 0 0 9945-128-1 /WINDOWS/system32/dllcache/winntbbu.dll 156672 ..c. r/rr-xr-xr-x 0 0 9946-128-3 /WINDOWS/system32/dllcache/winpy.ime 16896 ..c. r/rr-xr-xr-x 0 0 9947-128-1 /WINDOWS/system32/dllcache/winrnr.dll 99328 ..c. r/rr-xr-xr-x 0 0 9948-128-1 /WINDOWS/system32/dllcache/winscard.dll 17408 ..c. r/rr-xr-xr-x 0 0 9949-128-1 /WINDOWS/system32/dllcache/winshfhc.dll 72885 ..c. r/rr-xr-xr-x 0 0 995-128-3 /WINDOWS/Help/msmq.chm 2864 ..c. r/rr-xr-xr-x 0 0 9950-128-1 /WINDOWS/system32/dllcache/winsock.dll 156672 ..c. r/rr-xr-xr-x 0 0 9951-128-3 /WINDOWS/system32/dllcache/winsp.ime 2112 ..c. r/rr-xr-xr-x 0 0 9952-128-1 /WINDOWS/system32/dllcache/winspool.exe 146432 ..c. r/rr-xr-xr-x 0 0 9953-128-1 /WINDOWS/system32/dllcache/winspool.drv 293376 ..c. r/rr-xr-xr-x 0 0 9954-128-1 /WINDOWS/system32/dllcache/winsrv.dll 53760 ..c. r/rr-xr-xr-x 0 0 9955-128-1 /WINDOWS/system32/dllcache/winsta.dll 18944 ..c. r/rr-xr-xr-x 0 0 9956-128-1 /WINDOWS/system32/dllcache/winstrm.dll 5632 ..c. r/rr-xr-xr-x 0 0 9957-128-1 /WINDOWS/system32/dllcache/winver.exe 156672 ..c. r/rr-xr-xr-x 0 0 9958-128-3 /WINDOWS/system32/dllcache/winzm.ime 25088 ..c. r/rr-xr-xr-x 0 0 9959-128-1 /WINDOWS/system32/dllcache/wisc10.dll 6398 ..c. r/rr-xr-xr-x 0 0 996-128-3 /WINDOWS/inf/msmqocm.inf 132096 ..c. r/rr-xr-xr-x 0 0 9960-128-1 /WINDOWS/system32/dllcache/wkssvc.dll 69120 ..c. r/rr-xr-xr-x 0 0 9961-128-1 /WINDOWS/system32/dllcache/wlanapi.dll 172032 ..c. r/rr-xr-xr-x 0 0 9962-128-1 /WINDOWS/system32/dllcache/wldap32.dll 92672 ..c. r/rr-xr-xr-x 0 0 9963-128-1 /WINDOWS/system32/dllcache/wlnotify.dll 408064 ..c. r/rr-xr-xr-x 0 0 9964-128-1 /WINDOWS/system32/dllcache/wmadmod.dll 670720 ..c. r/rr-xr-xr-x 0 0 9965-128-1 /WINDOWS/system32/dllcache/wmadmoe.dll 230912 ..c. r/rr-xr-xr-x 0 0 9966-128-1 /WINDOWS/system32/dllcache/wmasf.dll 27136 ..c. r/rr-xr-xr-x 0 0 9967-128-1 /WINDOWS/system32/dllcache/wmdmlog.dll 23552 ..c. r/rr-xr-xr-x 0 0 9968-128-1 /WINDOWS/system32/dllcache/wmdmps.dll 51200 ..c. r/rr-xr-xr-x 0 0 9969-128-1 /WINDOWS/system32/dllcache/wmerrenu.dll 19904 ..c. r/rr-xr-xr-x 0 0 997-128-3 /WINDOWS/inf/msmscsi.inf 168448 ..c. r/rr-xr-xr-x 0 0 9970-128-1 /WINDOWS/system32/dllcache/wmerror.dll 5632 ..c. r/rr-xr-xr-x 0 0 9971-128-1 /WINDOWS/system32/dllcache/wmi.dll 45568 ..c. r/rr-xr-xr-x 0 0 9972-128-1 /WINDOWS/system32/dllcache/wmi2xml.dll 196608 ..c. r/rr-xr-xr-x 0 0 9973-128-1 /WINDOWS/system32/dllcache/wmiadap.exe 6656 ..c. r/rr-xr-xr-x 0 0 9974-128-1 /WINDOWS/system32/dllcache/wmiapres.dll 88576 ..c. r/rr-xr-xr-x 0 0 9975-128-1 /WINDOWS/system32/dllcache/wmiaprpl.dll 126464 ..c. r/rr-xr-xr-x 0 0 9976-128-1 /WINDOWS/system32/dllcache/wmiapsrv.exe 358912 ..c. r/rr-xr-xr-x 0 0 9977-128-1 /WINDOWS/system32/dllcache/wmic.exe 60928 ..c. r/rr-xr-xr-x 0 0 9978-128-1 /WINDOWS/system32/dllcache/wmicookr.dll 140800 ..c. r/rr-xr-xr-x 0 0 9979-128-1 /WINDOWS/system32/dllcache/wmidcprv.dll 8151 ..c. r/rr-xr-xr-x 0 0 998-128-3 /WINDOWS/inf/msmusb.inf 151552 ..c. r/rr-xr-xr-x 0 0 9980-128-1 /WINDOWS/system32/dllcache/wmidx.dll 4352 ..c. r/rr-xr-xr-x 0 0 9981-128-1 /WINDOWS/system32/dllcache/wmilib.sys 61440 ..c. r/rr-xr-xr-x 0 0 9982-128-1 /WINDOWS/system32/dllcache/wmimsg.dll 156672 ..c. r/rr-xr-xr-x 0 0 9983-128-1 /WINDOWS/system32/dllcache/wmipcima.dll 132096 ..c. r/rr-xr-xr-x 0 0 9984-128-1 /WINDOWS/system32/dllcache/wmipdskq.dll 75264 ..c. r/rr-xr-xr-x 0 0 9985-128-1 /WINDOWS/system32/dllcache/wmipicmp.dll 61952 ..c. r/rr-xr-xr-x 0 0 9986-128-1 /WINDOWS/system32/dllcache/wmipiprt.dll 62464 ..c. r/rr-xr-xr-x 0 0 9987-128-1 /WINDOWS/system32/dllcache/wmipjobj.dll 18944 ..c. r/rr-xr-xr-x 0 0 9988-128-1 /WINDOWS/system32/dllcache/wmiprop.dll 144896 ..c. r/rr-xr-xr-x 0 0 9989-128-1 /WINDOWS/system32/dllcache/wmiprov.dll 1842 ..c. r/rr-xr-xr-x 0 0 999-128-3 /WINDOWS/inf/msnike.inf 437248 ..c. r/rr-xr-xr-x 0 0 9990-128-1 /WINDOWS/system32/dllcache/wmiprvsd.dll 218112 ..c. r/rr-xr-xr-x 0 0 9991-128-1 /WINDOWS/system32/dllcache/wmiprvse.exe 41472 ..c. r/rr-xr-xr-x 0 0 9992-128-1 /WINDOWS/system32/dllcache/wmipsess.dll 55808 ..c. r/rr-xr-xr-x 0 0 9993-128-1 /WINDOWS/system32/dllcache/wmiscmgr.dll 144896 ..c. r/rr-xr-xr-x 0 0 9994-128-1 /WINDOWS/system32/dllcache/wmisvc.dll 52224 ..c. r/rr-xr-xr-x 0 0 9995-128-1 /WINDOWS/system32/dllcache/wmitimep.dll 95232 ..c. r/rr-xr-xr-x 0 0 9996-128-1 /WINDOWS/system32/dllcache/wmiutils.dll 167936 ..c. r/rr-xr-xr-x 0 0 9997-128-1 /WINDOWS/system32/dllcache/wmm2ae.dll 4096 ..c. r/rr-xr-xr-x 0 0 9998-128-1 /WINDOWS/system32/dllcache/wmm2eres.dll 7680 ..c. r/rr-xr-xr-x 0 0 9999-128-1 /WINDOWS/system32/dllcache/wmm2ext.dll Fri Jul 01 2011 15:09:00 48 .ac. d/dr-xr-xr-x 0 0 100-144-1 /WINDOWS/system32/oobe/html/oemcust 33280 ..c. r/rr-xr-xr-x 0 0 1000-128-3 /WINDOWS/system32/msobjs.dll 41984 ..c. r/rr-xr-xr-x 0 0 1002-128-3 /WINDOWS/system32/msports.dll 60416 ..c. r/rr-xr-xr-x 0 0 1004-128-3 /WINDOWS/system32/msratelc.dll 35840 ..c. r/rr-xr-xr-x 0 0 1007-128-3 /WINDOWS/system32/mssign32.dll 4608 ..c. r/rr-xr-xr-x 0 0 1008-128-3 /WINDOWS/system32/mssip32.dll 13312 ..c. r/rr-xr-xr-x 0 0 1009-128-3 /WINDOWS/system32/msswch.dll 48 .ac. d/dr-xr-xr-x 0 0 101-144-1 /WINDOWS/system32/oobe/html/oemhw 6656 ..c. r/rr-xr-xr-x 0 0 1010-128-3 /WINDOWS/system32/msswchx.exe 1355776 ..c. r/rr-xr-xr-x 0 0 1013-128-3 /WINDOWS/system32/msvbvm50.dll 565760 ..c. r/rr-xr-xr-x 0 0 1014-128-3 /WINDOWS/system32/msvcp50.dll 25600 ..c. r/rr-xr-xr-x 0 0 1015-128-3 /WINDOWS/system32/msvidc32.dll 126912 ..c. r/rr-xr-xr-x 0 0 1016-128-3 /WINDOWS/system32/msvideo.dll 37916 ..c. r/rr-xr-xr-x 0 0 1017-128-3 /WINDOWS/system32/msxml2r.dll 44032 ..c. r/rr-xr-xr-x 0 0 1018-128-3 /WINDOWS/system32/msxml3r.dll 48 .ac. d/dr-xr-xr-x 0 0 102-144-1 /WINDOWS/system32/oobe/html/oemreg 90112 ..c. r/rr-xr-xr-x 0 0 1021-128-3 /WINDOWS/system32/mycomput.dll 35840 ..c. r/rr-xr-xr-x 0 0 1022-128-3 /WINDOWS/system32/narrhook.dll 20480 ..c. r/rr-xr-xr-x 0 0 1023-128-3 /WINDOWS/system32/nbtstat.exe 7680 ..c. r/rr-xr-xr-x 0 0 1024-128-3 /WINDOWS/system32/ncxpnt.dll 35840 ..c. r/rr-xr-xr-x 0 0 1025-128-3 /WINDOWS/system32/ncpa.cpl 168 .ac. d/dr-xr-xr-x 0 0 103-144-5 /WINDOWS/system32/oobe/images 108464 ..c. r/rr-xr-xr-x 0 0 1031-128-3 /WINDOWS/system32/netapi.dll 8192 ..c. r/rr-xr-xr-x 0 0 10335-128-3 /WINDOWS/REGLOCS.OLD 56 ..c. d/dr-xr-xr-x 0 0 10367-144-6 /WINDOWS/SoftwareDistribution 78 ..c. r/rr-xr-xr-x 0 0 10388-128-1 /WINDOWS/system32/Restore/MachineGuid.txt 168 .ac. d/dr-xr-xr-x 0 0 104-144-5 /WINDOWS/system32/oobe/setup 0 ..c. r/rr-xr-xr-x 0 0 10402-128-12 /WINDOWS/0.log 56 ..c. d/dr-xr-xr-x 0 0 10413-144-6 /WINDOWS/Prefetch 253952 ..c. r/rr-xr-xr-x 0 0 1047-128-3 /WINDOWS/system32/neth.dll 48 .ac. d/dr-xr-xr-x 0 0 105-144-1 /WINDOWS/system32/oobe/sample 75 ..c. r/rr-xr-xr-x 0 0 10547-128-1 /WINDOWS/system32/wbem/Logs/wbemprox.log 3824 ..c. r/rr-xr-xr-x 0 0 10652-128-4 /WINDOWS/system32/wbem/Performance/WmiApRpl.ini 10281 ..c. r/rr-xr-xr-x 0 0 10661-128-3 /WINDOWS/system32/oobe/actsetup/stgact.htm 2042 ..c. r/rr-xr-xr-x 0 0 10670-128-3 /WINDOWS/system32/wbem/Logs/wmiadap.log 136 ..c. d/dr-xr-xr-x 0 0 10687-144-1 /DRIVERS 2656 ..c. r/rr-xr-xr-x 0 0 1072-128-3 /WINDOWS/system32/netware.drv 13646 ..c. r/rr-xr-xr-x 0 0 10801-128-3 /WINDOWS/system32/wpa.bak 621944 ..c. r/rr-xr-xr-x 0 0 10820-128-3 /WINDOWS/system32/pskill.exe 105264 ..c. r/rr-xr-xr-x 0 0 10821-128-3 /WINDOWS/system32/pspasswd.exe 207664 ..c. r/rr-xr-xr-x 0 0 10822-128-4 /WINDOWS/system32/psshutdown.exe 187184 ..c. r/rr-xr-xr-x 0 0 10823-128-4 /WINDOWS/system32/pssuspend.exe 64126 ..c. r/rr-xr-xr-x 0 0 10824-128-3 /WINDOWS/system32/Pstools.chm 7052 ..c. r/rr-xr-xr-x 0 0 1085-128-3 /WINDOWS/system32/nlsfunc.exe 39 ..c. r/rr-xr-xr-x 0 0 10860-128-1 /WINDOWS/system32/psversion.txt 741 ..c. r/rr-xr-xr-x 0 0 1088-128-3 /WINDOWS/system32/noise.dat 149848 ..c. r/rr-xr-xr-x 0 0 1089-128-3 /WINDOWS/system32/noise.deu 751 ..c. r/rr-xr-xr-x 0 0 1090-128-3 /WINDOWS/system32/noise.eng 751 ..c. r/rr-xr-xr-x 0 0 1091-128-3 /WINDOWS/system32/noise.enu 177152 ..c. r/rr-xr-xr-x 0 0 10915-128-3 /WINDOWS/system32/pkiview.dll 25906 ..c. r/rr-xr-xr-x 0 0 10916-128-3 /WINDOWS/system32/pkiview.msc 19684 ..c. r/rr-xr-xr-x 0 0 1092-128-3 /WINDOWS/system32/noise.esn 49196 ..c. r/rr-xr-xr-x 0 0 1093-128-3 /WINDOWS/system32/noise.fra 19618 ..c. r/rr-xr-xr-x 0 0 1094-128-3 /WINDOWS/system32/noise.ita 13256 ..c. r/rr-xr-xr-x 0 0 1095-128-3 /WINDOWS/system32/noise.nld 13730 ..c. r/rr-xr-xr-x 0 0 1096-128-3 /WINDOWS/system32/noise.sve 144 ..c. d/dr-xr-xr-x 0 0 110-144-1 /WINDOWS/Provisioning 27866 ..c. r/rr-xr-xr-x 0 0 1103-128-3 /WINDOWS/system32/ntdos.sys 29370 ..c. r/rr-xr-xr-x 0 0 1104-128-3 /WINDOWS/system32/ntdos411.sys 29274 ..c. r/rr-xr-xr-x 0 0 1105-128-3 /WINDOWS/system32/ntdos412.sys 29146 ..c. r/rr-xr-xr-x 0 0 1106-128-3 /WINDOWS/system32/ntdos404.sys 29146 ..c. r/rr-xr-xr-x 0 0 1107-128-3 /WINDOWS/system32/ntdos804.sys 26112 ..c. r/rr-xr-xr-x 0 0 1108-128-3 /WINDOWS/system32/ntdsbcli.dll 183160 ..c. r/rr-xr-xr-x 0 0 11098-128-4 /WINDOWS/system32/PsLoggedon.exe 178040 ..c. r/rr-xr-xr-x 0 0 11099-128-4 /WINDOWS/system32/psloglist.exe 169848 ..c. r/rr-xr-xr-x 0 0 11100-128-4 /WINDOWS/system32/PsService.exe 381816 ..c. r/rr-xr-xr-x 0 0 11101-128-3 /WINDOWS/system32/PsExec.exe 333176 ..c. r/rr-xr-xr-x 0 0 11102-128-3 /WINDOWS/system32/PsGetsid.exe 390520 ..c. r/rr-xr-xr-x 0 0 11103-128-3 /WINDOWS/system32/PsInfo.exe 231288 ..c. r/rr-xr-xr-x 0 0 11104-128-3 /WINDOWS/system32/PsList.exe 284160 ..c. r/rr-xr-xr-x 0 0 11105-128-1 /WINDOWS/system32/pdh.dll 45568 ..c. r/rr-xr-xr-x 0 0 11108-128-3 /WINDOWS/system32/dd.exe 9728 ..c. r/rr-xr-xr-x 0 0 11109-128-3 /WINDOWS/system32/getopt.dll 48794 ..c. r/rr-xr-xr-x 0 0 1111-128-3 /WINDOWS/system32/ntimage.gif 14848 ..c. r/rr-xr-xr-x 0 0 11110-128-3 /WINDOWS/system32/md5lib.dll 487424 ..c. r/r--x--x--x 0 0 11111-128-3 /WINDOWS/system32/MSVCP70.DLL 344064 ..c. r/rr-xr-xr-x 0 0 11112-128-3 /WINDOWS/system32/msvcr70.dll 60 ..c. r/rr-xr-xr-x 0 0 11113-128-1 /WINDOWS/system32/pssshutdown.txt 308736 ..c. r/rr-xr-xr-x 0 0 11114-128-3 /WINDOWS/system32/wget.exe 51712 ..c. r/rr-xr-xr-x 0 0 11115-128-3 /WINDOWS/system32/zlibU.dll 899 ..c. r/rr-xr-xr-x 0 0 11116-128-3 /get.bat 272 ..c. r/rr-xr-xr-x 0 0 11117-128-1 /get.reg 57856 ..c. r/rr-xr-xr-x 0 0 1112-128-3 /WINDOWS/system32/ntlanui.dll 0 ..c. r/rr-xr-xr-x 0 0 11120-128-1 /zero.txt.txt 14336 ..c. r/rr-xr-xr-x 0 0 1113-128-3 /WINDOWS/system32/ntlanui2.dll 36864 ..c. r/rr-xr-xr-x 0 0 1114-128-3 /WINDOWS/system32/ntmsevt.dll 26209 ..c. r/rr-xr-xr-x 0 0 1115-128-3 /WINDOWS/system32/ntmsmgr.msc 32968 ..c. r/rr-xr-xr-x 0 0 1116-128-3 /WINDOWS/system32/ntmsoprq.msc 31744 ..c. r/rr-xr-xr-x 0 0 1117-128-3 /WINDOWS/system32/ntsd.exe 36864 ..c. r/rr-xr-xr-x 0 0 1118-128-3 /WINDOWS/system32/ntsdexts.dll 48 ..c. d/dr-xr-xr-x 0 0 112-144-1 /WINDOWS/system32/1025 3252 ..c. r/rr-xr-xr-x 0 0 1121-128-3 /WINDOWS/system32/nw16.exe 17408 ..c. r/rr-xr-xr-x 0 0 1122-128-3 /WINDOWS/system32/nwapi16.dll 36864 ..c. r/rr-xr-xr-x 0 0 1123-128-3 /WINDOWS/system32/nwc.cpl 20480 ..c. r/rr-xr-xr-x 0 0 1124-128-3 /WINDOWS/system32/nwcfg.dll 6144 ..c. r/rr-xr-xr-x 0 0 1127-128-3 /WINDOWS/system32/nwevent.dll 48 ..c. d/dr-xr-xr-x 0 0 113-144-1 /WINDOWS/system32/1028 126464 ..c. r/rr-xr-xr-x 0 0 1132-128-3 /WINDOWS/system32/nwscript.exe 13107200 ..c. r/rr-xr-xr-x 0 0 1137-128-3 /WINDOWS/system32/oembios.bin 4461 ..c. r/rr-xr-xr-x 0 0 1138-128-3 /WINDOWS/system32/oembios.dat 6761 ..c. r/rr-xr-xr-x 0 0 1139-128-3 /WINDOWS/system32/oembios.sig 48 ..c. d/dr-xr-xr-x 0 0 114-144-1 /WINDOWS/system32/1031 39744 ..c. r/rr-xr-xr-x 0 0 1141-128-3 /WINDOWS/system32/ole2.dll 169520 ..c. r/rr-xr-xr-x 0 0 1142-128-3 /WINDOWS/system32/ole2disp.dll 153008 ..c. r/rr-xr-xr-x 0 0 1143-128-3 /WINDOWS/system32/ole2nls.dll 163328 ..c. r/rr-xr-xr-x 0 0 1144-128-3 /WINDOWS/system32/oleacc.dll 16896 ..c. r/rr-xr-xr-x 0 0 1145-128-3 /WINDOWS/system32/oleaccrc.dll 0 ..c. r/rr-xr-xr-x 0 0 11452-128-3 /ok.txt 0 ..c. r/rr-xr-xr-x 0 0 11453-128-3 /WINDOWS/system32/sandnet.exe 82944 ..c. r/rr-xr-xr-x 0 0 1146-128-3 /WINDOWS/system32/olecli.dll 738 ..c. r/rr-xr-xr-x 0 0 11465-128-4 /WINDOWS/system32/wbem/Performance/WmiApRpl.h 24064 ..c. r/rr-xr-xr-x 0 0 1147-128-3 /WINDOWS/system32/olesvr.dll 152 ..c. d/dr-xr-xr-x 0 0 115-144-1 /WINDOWS/system32/1033 14527 ..c. r/rr-xr-xr-x 0 0 1158-128-3 /WINDOWS/system32/ras/pad.inf 167219 ..c. r/rr-xr-xr-x 0 0 1159-128-3 /WINDOWS/system32/pagefileconfig.vbs 48 ..c. d/dr-xr-xr-x 0 0 116-144-1 /WINDOWS/system32/1037 10240 ..c. r/rr-xr-xr-x 0 0 1160-128-3 /WINDOWS/system32/panmap.dll 21504 ..c. r/rr-xr-xr-x 0 0 1161-128-3 /WINDOWS/system32/pathping.exe 114 ..c. r/rr-xr-xr-x 0 0 1162-128-1 /WINDOWS/system32/pcl.sep 427 ..c. r/rr-xr-xr-x 0 0 1164-128-1 /WINDOWS/system32/perfci.h 2891 ..c. r/rr-xr-xr-x 0 0 1165-128-3 /WINDOWS/system32/perfci.ini 28626 ..c. r/rr-xr-xr-x 0 0 1166-128-3 /WINDOWS/system32/perfd009.dat 140 ..c. r/rr-xr-xr-x 0 0 1167-128-1 /WINDOWS/system32/perffilt.h 1152 ..c. r/rr-xr-xr-x 0 0 1168-128-3 /WINDOWS/system32/perffilt.ini 272128 ..c. r/rr-xr-xr-x 0 0 1169-128-3 /WINDOWS/system32/perfi009.dat 48 ..c. d/dr-xr-xr-x 0 0 117-144-1 /WINDOWS/system32/1041 58273 ..c. r/r--x--x--x 0 0 1170-128-3 /WINDOWS/system32/perfmon.msc 5632 ..c. r/rr-xr-xr-x 0 0 1171-128-3 /WINDOWS/system32/perfnw.dll 12288 ..c. r/rr-xr-xr-x 0 0 1172-128-3 /WINDOWS/system32/perfts.dll 435 ..c. r/rr-xr-xr-x 0 0 1173-128-1 /WINDOWS/system32/perfwci.h 2732 ..c. r/rr-xr-xr-x 0 0 1174-128-3 /WINDOWS/system32/perfwci.ini 48 ..c. d/dr-xr-xr-x 0 0 118-144-1 /WINDOWS/system32/1042 35328 ..c. r/rr-xr-xr-x 0 0 1183-128-3 /WINDOWS/system32/pifmgr.dll 33280 ..c. r/rr-xr-xr-x 0 0 1185-128-3 /WINDOWS/system32/ping6.exe 30720 ..c. r/rr-xr-xr-x 0 0 1186-128-3 /WINDOWS/system32/plustab.dll 46592 ..c. r/rr-xr-xr-x 0 0 1187-128-3 /WINDOWS/system32/pmspl.dll 48 ..c. d/dr-xr-xr-x 0 0 119-144-1 /WINDOWS/system32/1054 2815 ..c. r/rr-xr-xr-x 0 0 1191-128-3 /WINDOWS/system32/ras/pppmenu.scp 16384 ..c. r/rr-xr-xr-x 0 0 1192-128-3 /WINDOWS/system32/prflbmsg.dll 9216 ..c. r/rr-xr-xr-x 0 0 1193-128-3 /WINDOWS/system32/print.exe 35755 ..c. r/rr-xr-xr-x 0 0 1196-128-3 /WINDOWS/system32/prncnfg.vbs 25415 ..c. r/rr-xr-xr-x 0 0 1197-128-3 /WINDOWS/system32/prndrvr.vbs 21527 ..c. r/rr-xr-xr-x 0 0 1198-128-3 /WINDOWS/system32/prnjobs.vbs 32546 ..c. r/rr-xr-xr-x 0 0 1199-128-3 /WINDOWS/system32/prnmngr.vbs 48 ..c. d/dr-xr-xr-x 0 0 120-144-1 /WINDOWS/system32/2052 29454 ..c. r/rr-xr-xr-x 0 0 1200-128-3 /WINDOWS/system32/prnport.vbs 15860 ..c. r/rr-xr-xr-x 0 0 1201-128-3 /WINDOWS/system32/prnqctl.vbs 343 ..c. r/rr-xr-xr-x 0 0 1202-128-1 /WINDOWS/system32/prodspec.ini 799 ..c. r/rr-xr-xr-x 0 0 1207-128-3 /WINDOWS/Web/printers/prtwebvw.css 3010 ..c. r/rr-xr-xr-x 0 0 1208-128-3 /WINDOWS/system32/pschdcnt.h 10752 ..c. r/rr-xr-xr-x 0 0 1209-128-3 /WINDOWS/system32/pschdprf.dll 48 ..c. d/dr-xr-xr-x 0 0 121-144-1 /WINDOWS/system32/3076 6877 ..c. r/rr-xr-xr-x 0 0 1210-128-3 /WINDOWS/system32/pschdprf.ini 51 ..c. r/rr-xr-xr-x 0 0 1211-128-1 /WINDOWS/system32/pscript.sep 8192 ..c. r/rr-xr-xr-x 0 0 1212-128-3 /WINDOWS/system32/psnppagn.dll 3708 ..c. r/rr-xr-xr-x 0 0 1214-128-3 /WINDOWS/system32/pubprn.vbs 8192 ..c. r/rr-xr-xr-x 0 0 1218-128-3 /WINDOWS/system32/qosname.dll 11776 ..c. r/rr-xr-xr-x 0 0 1219-128-3 /WINDOWS/system32/rasautou.exe 360 .ac. d/dr-xr-xr-x 0 0 122-144-1 /WINDOWS/system32/wbem/xml 1818 ..c. r/rr-xr-xr-x 0 0 1220-128-3 /WINDOWS/system32/rasctrnm.h 11776 ..c. r/rr-xr-xr-x 0 0 1221-128-3 /WINDOWS/system32/rasctrs.dll 3458 ..c. r/rr-xr-xr-x 0 0 1222-128-3 /WINDOWS/system32/rasctrs.ini 11264 ..c. r/rr-xr-xr-x 0 0 1223-128-3 /WINDOWS/system32/rasdial.exe 143360 ..c. r/rr-xr-xr-x 0 0 1224-128-3 /WINDOWS/system32/rasmontr.dll 22528 ..c. r/rr-xr-xr-x 0 0 1225-128-3 /WINDOWS/system32/rasmxs.dll 23552 ..c. r/rr-xr-xr-x 0 0 1226-128-3 /WINDOWS/system32/rasrad.dll 12800 ..c. r/rr-xr-xr-x 0 0 1227-128-3 /WINDOWS/system32/rasser.dll 56 .ac. d/dr-xr-xr-x 0 0 123-144-5 /WINDOWS/system32/usmt 7168 ..c. r/rr-xr-xr-x 0 0 1234-128-3 /WINDOWS/system32/recover.exe 57344 ..c. r/rr-xr-xr-x 0 0 1236-128-3 /WINDOWS/system32/gpupdate.exe 3584 ..c. r/rr-xr-xr-x 0 0 1239-128-3 /WINDOWS/system32/regedt32.exe 48 ..c. d/dr-xr-xr-x 0 0 124-144-1 /WINDOWS/system32/inetsrv 4608 ..c. r/rr-xr-xr-x 0 0 1240-128-3 /WINDOWS/system32/regwiz.exe 32768 ..c. r/rr-xr-xr-x 0 0 1241-128-3 /WINDOWS/system32/relog.exe 107520 ..c. r/rr-xr-xr-x 0 0 1242-128-3 /WINDOWS/system32/rend.dll 12800 ..c. r/rr-xr-xr-x 0 0 1243-128-3 /WINDOWS/system32/replace.exe 3584 ..c. r/rr-xr-xr-x 0 0 1245-128-3 /WINDOWS/system32/riched32.dll 160 ..c. d/dr-xr-xr-x 0 0 125-144-1 /WINDOWS/mui 3072 ..c. r/rr-xr-xr-x 0 0 1250-128-3 /WINDOWS/system32/rnr20.dll 19968 ..c. r/rr-xr-xr-x 0 0 1254-128-3 /WINDOWS/system32/route.exe 25600 ..c. r/rr-xr-xr-x 0 0 1255-128-3 /WINDOWS/system32/routemon.exe 6656 ..c. r/rr-xr-xr-x 0 0 1256-128-3 /WINDOWS/system32/routetab.dll 22016 ..c. r/rr-xr-xr-x 0 0 1257-128-3 /WINDOWS/system32/rpcns4.dll 3167 ..c. r/rr-xr-xr-x 0 0 1259-128-3 /WINDOWS/system32/rsaci.rat 296 .ac. d/dr-xr-xr-x 0 0 126-144-5 /WINDOWS/WinSxS 28672 ..c. r/rr-xr-xr-x 0 0 1260-128-3 /WINDOWS/system32/rsfsaps.dll 49152 ..c. r/rr-xr-xr-x 0 0 1261-128-3 /WINDOWS/system32/rsm.exe 24576 ..c. r/rr-xr-xr-x 0 0 1265-128-3 /WINDOWS/system32/rsmsink.exe 49152 ..c. r/rr-xr-xr-x 0 0 1266-128-3 /WINDOWS/system32/rsmui.exe 283888 ..c. r/rr-xr-xr-x 0 0 1268-128-3 /WINDOWS/system32/wbem/rsop.mfl 44451 ..c. r/r--x--x--x 0 0 1269-128-3 /WINDOWS/system32/rsop.msc 56 .ac. d/dr-xr-xr-x 0 0 127-144-7 /WINDOWS/WinSxS/Manifests 62976 ..c. r/rr-xr-xr-x 0 0 1270-128-3 /WINDOWS/system32/rsopprov.exe 132608 ..c. r/rr-xr-xr-x 0 0 1271-128-3 /WINDOWS/system32/rsvp.exe 12082 ..c. r/rr-xr-xr-x 0 0 1272-128-3 /WINDOWS/system32/rsvp.ini 3178 ..c. r/rr-xr-xr-x 0 0 1273-128-3 /WINDOWS/system32/rsvpcnts.h 23552 ..c. r/rr-xr-xr-x 0 0 1274-128-3 /WINDOWS/system32/rsvpmsg.dll 9728 ..c. r/rr-xr-xr-x 0 0 1275-128-3 /WINDOWS/system32/rsvpperf.dll 98304 ..c. r/rr-xr-xr-x 0 0 1276-128-3 /WINDOWS/system32/rtm.dll 16384 ..c. r/rr-xr-xr-x 0 0 1277-128-3 /WINDOWS/system32/runas.exe 48 .ac. d/dr-xr-xr-x 0 0 128-144-1 /WINDOWS/WinSxS/InstallTemp 31232 ..c. r/rr-xr-xr-x 0 0 1283-128-3 /WINDOWS/system32/sc.exe 118784 ..c. r/rr-xr-xr-x 0 0 1286-128-3 /WINDOWS/system32/scardssp.dll 4357 ..c. r/rr-xr-xr-x 0 0 1289-128-3 /WINDOWS/system32/wbem/scersop.mof 56 ..c. d/dr-xr-xr-x 0 0 129-144-5 /WINDOWS/ime 26624 ..c. r/rr-xr-xr-x 0 0 1292-128-3 /WINDOWS/system32/scredir.dll 10240 ..c. r/rr-xr-xr-x 0 0 1293-128-3 /WINDOWS/system32/scriptpw.dll 130048 ..c. r/rr-xr-xr-x 0 0 1295-128-3 /WINDOWS/system32/sdpblb.dll 36364 ..c. r/rr-xr-xr-x 0 0 1302-128-3 /WINDOWS/system32/secpol.msc 13824 ..c. r/rr-xr-xr-x 0 0 1306-128-3 /WINDOWS/system32/senscfg.dll 14336 ..c. r/rr-xr-xr-x 0 0 1307-128-3 /WINDOWS/system32/serialui.dll 360 ..c. d/dr-xr-xr-x 0 0 131-144-1 /WINDOWS/system32/IME 33464 ..c. r/rr-xr-xr-x 0 0 1310-128-3 /WINDOWS/system32/services.msc 14848 ..c. r/rr-xr-xr-x 0 0 1311-128-3 /WINDOWS/system32/serwvdrv.dll 240120 ..c. r/rr-xr-xr-x 0 0 1312-128-3 /WINDOWS/system32/setup.bmp 414208 ..c. r/rr-xr-xr-x 0 0 1314-128-3 /WINDOWS/system32/setupdll.dll 11753 ..c. r/rr-xr-xr-x 0 0 1315-128-3 /WINDOWS/system32/setver.exe 9728 ..c. r/rr-xr-xr-x 0 0 1316-128-3 /WINDOWS/system32/sfc.exe 23552 ..c. r/rr-xr-xr-x 0 0 1317-128-3 /WINDOWS/system32/sfmapi.dll 882 ..c. r/rr-xr-xr-x 0 0 1319-128-3 /WINDOWS/system32/share.exe 5120 ..c. r/rr-xr-xr-x 0 0 1320-128-3 /WINDOWS/system32/shell.dll 13824 ..c. r/rr-xr-xr-x 0 0 1323-128-3 /WINDOWS/system32/sisbkup.dll 5632 ..c. r/rr-xr-xr-x 0 0 1324-128-3 /WINDOWS/system32/skdll.dll 14848 ..c. r/rr-xr-xr-x 0 0 1325-128-3 /WINDOWS/system32/slbrccsp.dll 2375 ..c. r/rr-xr-xr-x 0 0 1327-128-3 /WINDOWS/system32/ras/slip.scp 2813 ..c. r/rr-xr-xr-x 0 0 1328-128-3 /WINDOWS/system32/ras/slipmenu.scp 5632 ..c. r/rr-xr-xr-x 0 0 1332-128-3 /WINDOWS/system32/softpub.dll 1744 ..c. r/rr-xr-xr-x 0 0 1334-128-3 /WINDOWS/system32/sound.drv 69632 ..c. r/rr-xr-xr-x 0 0 1341-128-3 /WINDOWS/system32/spnike.dll 9728 ..c. r/rr-xr-xr-x 0 0 1342-128-3 /WINDOWS/system32/sprestrt.exe 70656 ..c. r/rr-xr-xr-x 0 0 1343-128-3 /WINDOWS/system32/sprio600.dll 72192 ..c. r/rr-xr-xr-x 0 0 1344-128-3 /WINDOWS/system32/sprio800.dll 46133 ..c. r/rr-xr-xr-x 0 0 1345-128-3 /WINDOWS/system32/sqlsodbc.chm 24603 ..c. r/rr-xr-xr-x 0 0 1346-128-3 /WINDOWS/system32/sqlwid.dll 49179 ..c. r/rr-xr-xr-x 0 0 1347-128-3 /WINDOWS/system32/sqlwoa.dll 3799 ..c. r/rr-xr-xr-x 0 0 1349-128-3 /WINDOWS/system32/wbem/sr.mof 3144 ..c. r/rr-xr-xr-x 0 0 1351-128-3 /WINDOWS/system32/spool/drivers/color/sRGB Color Space Profile.icm 4208 ..c. r/rr-xr-xr-x 0 0 1358-128-3 /WINDOWS/system32/storage.dll 8192 ..c. r/rr-xr-xr-x 0 0 1359-128-3 /WINDOWS/system32/streamci.dll 9216 ..c. r/rr-xr-xr-x 0 0 1360-128-3 /WINDOWS/system32/subst.exe 6144 ..c. r/rr-xr-xr-x 0 0 1363-128-3 /WINDOWS/system32/svcpack.dll 6213 ..c. r/rr-xr-xr-x 0 0 1365-128-3 /WINDOWS/system32/ras/switch.inf 138752 ..c. r/rr-xr-xr-x 0 0 1366-128-3 /WINDOWS/system32/swprv.dll 51200 ..c. r/rr-xr-xr-x 0 0 1368-128-3 /WINDOWS/system32/syncapp.exe 18896 ..c. r/rr-xr-xr-x 0 0 1373-128-3 /WINDOWS/system32/sysedit.exe 15872 ..c. r/rr-xr-xr-x 0 0 1374-128-3 /WINDOWS/system32/sysinv.dll 36864 ..c. r/rr-xr-xr-x 0 0 1375-128-3 /WINDOWS/system32/syskey.exe 3214 ..c. r/rr-xr-xr-x 0 0 1378-128-3 /WINDOWS/system32/sysprint.sep 3577 ..c. r/rr-xr-xr-x 0 0 1379-128-3 /WINDOWS/system32/sysprtj.sep 3360 ..c. r/rr-xr-xr-x 0 0 1381-128-3 /WINDOWS/system32/system.drv 3072 ..c. r/rr-xr-xr-x 0 0 1382-128-3 /WINDOWS/system32/systray.exe 19200 ..c. r/rr-xr-xr-x 0 0 1383-128-3 /WINDOWS/system32/tapi.dll 5632 ..c. r/rr-xr-xr-x 0 0 1386-128-3 /WINDOWS/system32/tapiperf.dll 78848 ..c. r/rr-xr-xr-x 0 0 1387-128-3 /WINDOWS/system32/tapiui.dll 15360 ..c. r/rr-xr-xr-x 0 0 1389-128-3 /WINDOWS/system32/taskman.exe 248 ..c. d/dr-xr-xr-x 0 0 139-144-1 /WINDOWS/pchealth 12288 ..c. r/rr-xr-xr-x 0 0 1392-128-3 /WINDOWS/system32/tcmsetup.exe 19456 ..c. r/rr-xr-xr-x 0 0 1395-128-3 /WINDOWS/system32/tcpsvcs.exe 28160 ..c. r/rr-xr-xr-x 0 0 1396-128-3 /WINDOWS/system32/telephon.cpl 16896 ..c. r/rr-xr-xr-x 0 0 1399-128-3 /WINDOWS/system32/tftp.exe 4048 ..c. r/rr-xr-xr-x 0 0 1400-128-3 /WINDOWS/system32/timer.drv 1045 ..c. r/rr-xr-xr-x 0 0 1402-128-3 /WINDOWS/Web/tips.gif 13888 ..c. r/rr-xr-xr-x 0 0 1403-128-3 /WINDOWS/system32/toolhelp.dll 31744 ..c. r/rr-xr-xr-x 0 0 1406-128-3 /WINDOWS/system32/tracert6.exe 31232 ..c. r/rr-xr-xr-x 0 0 1407-128-3 /WINDOWS/system32/traffic.dll 52224 ..c. r/rr-xr-xr-x 0 0 1408-128-3 /WINDOWS/system32/tsappcmp.dll 8192 ..c. r/rr-xr-xr-x 0 0 1411-128-3 /WINDOWS/system32/tsbyuv.dll 15360 ..c. r/rr-xr-xr-x 0 0 1412-128-3 /WINDOWS/system32/tsd32.dll 8192 ..c. r/rr-xr-xr-x 0 0 1414-128-3 /WINDOWS/system32/tssoft32.acm 94784 ..c. r/rr-xr-xr-x 0 0 1415-128-3 /WINDOWS/twain.dll 49680 ..c. r/rr-xr-xr-x 0 0 1416-128-3 /WINDOWS/twunk_16.exe 25600 ..c. r/rr-xr-xr-x 0 0 1417-128-3 /WINDOWS/twunk_32.exe 177856 ..c. r/rr-xr-xr-x 0 0 1418-128-3 /WINDOWS/system32/typelib.dll 36352 ..c. r/rr-xr-xr-x 0 0 1419-128-3 /WINDOWS/system32/typeperf.exe 48 ..c. d/dr-xr-xr-x 0 0 142-144-1 /WINDOWS/system32/3com_dmi 82432 ..c. r/rr-xr-xr-x 0 0 1420-128-3 /WINDOWS/system32/ufat.dll 13312 ..c. r/rr-xr-xr-x 0 0 1423-128-3 /WINDOWS/system32/umdmxfrm.dll 4096 ..c. r/rr-xr-xr-x 0 0 1425-128-3 /WINDOWS/system32/unlodctr.exe 17920 ..c. r/rr-xr-xr-x 0 0 1427-128-3 /WINDOWS/system32/ureg.dll 360 ..c. d/dr-xr-xr-x 0 0 143-144-1 /WINDOWS/PeerNet 47872 ..c. r/rr-xr-xr-x 0 0 1431-128-3 /WINDOWS/system32/user.exe 25600 ..c. r/rr-xr-xr-x 0 0 1433-128-3 /WINDOWS/system32/utildll.dll 18832 ..c. r/rr-xr-xr-x 0 0 1436-128-3 /WINDOWS/system32/v7vga.rom 7680 ..c. r/rr-xr-xr-x 0 0 1437-128-3 /WINDOWS/system32/vcdex.dll 9008 ..c. r/rr-xr-xr-x 0 0 1439-128-3 /WINDOWS/system32/ver.dll 56 .ac. d/dr-xr-xr-x 0 0 144-144-5 /WINDOWS/system32/wbem/Logs 98304 ..c. r/rr-xr-xr-x 0 0 1440-128-3 /WINDOWS/system32/verifier.exe 20535 ..c. r/rr-xr-xr-x 0 0 1442-128-3 /WINDOWS/system32/vfpodbc.dll 2176 ..c. r/rr-xr-xr-x 0 0 1443-128-3 /WINDOWS/system32/vga.drv 4608 ..c. r/rr-xr-xr-x 0 0 1446-128-3 /WINDOWS/system32/vjoy.dll 33792 ..c. r/rr-xr-xr-x 0 0 1449-128-3 /WINDOWS/system32/vssadmin.exe 152 ..c. d/dr-xr-xr-x 0 0 145-144-1 /WINDOWS/ehome 16896 ..c. r/rr-xr-xr-x 0 0 1450-128-3 /WINDOWS/system32/vss_ps.dll 19456 ..c. r/rr-xr-xr-x 0 0 1451-128-3 /WINDOWS/system32/vwipxspx.dll 1129 ..c. r/rr-xr-xr-x 0 0 1452-128-3 /WINDOWS/system32/vwipxspx.exe 49664 ..c. r/rr-xr-xr-x 0 0 1453-128-3 /WINDOWS/system32/w32tm.exe 22016 ..c. r/rr-xr-xr-x 0 0 1454-128-3 /WINDOWS/system32/w32topl.dll 65489 ..c. r/rr-xr-xr-x 0 0 1457-128-3 /WINDOWS/system32/wbcache.deu 65489 ..c. r/rr-xr-xr-x 0 0 1458-128-3 /WINDOWS/system32/wbcache.enu 65489 ..c. r/rr-xr-xr-x 0 0 1459-128-3 /WINDOWS/system32/wbcache.esn 56 ..c. d/dr-xr-xr-x 0 0 146-144-6 /WINDOWS/Network Diagnostic 65489 ..c. r/rr-xr-xr-x 0 0 1460-128-3 /WINDOWS/system32/wbcache.fra 65489 ..c. r/rr-xr-xr-x 0 0 1461-128-3 /WINDOWS/system32/wbcache.ita 65489 ..c. r/rr-xr-xr-x 0 0 1462-128-3 /WINDOWS/system32/wbcache.nld 65489 ..c. r/rr-xr-xr-x 0 0 1463-128-3 /WINDOWS/system32/wbcache.sve 1309184 ..c. r/rr-xr-xr-x 0 0 1464-128-3 /WINDOWS/system32/wbdbase.deu 957440 ..c. r/rr-xr-xr-x 0 0 1465-128-3 /WINDOWS/system32/wbdbase.enu 750080 ..c. r/rr-xr-xr-x 0 0 1466-128-3 /WINDOWS/system32/wbdbase.esn 786944 ..c. r/rr-xr-xr-x 0 0 1467-128-3 /WINDOWS/system32/wbdbase.fra 867840 ..c. r/rr-xr-xr-x 0 0 1468-128-3 /WINDOWS/system32/wbdbase.ita 1095680 ..c. r/rr-xr-xr-x 0 0 1469-128-3 /WINDOWS/system32/wbdbase.nld 216 ..c. d/dr-xr-xr-x 0 0 147-144-6 /WINDOWS/L2Schemas 937984 ..c. r/rr-xr-xr-x 0 0 1470-128-3 /WINDOWS/system32/wbdbase.sve 4096 ..c. r/rr-xr-xr-x 0 0 1473-128-3 /WINDOWS/system32/wdl.trm 496 ..c. d/dr-xr-xr-x 0 0 148-144-1 /WINDOWS/system32/mui/0401 496 ..c. d/dr-xr-xr-x 0 0 149-144-1 /WINDOWS/system32/mui/0404 40448 ..c. r/rr-xr-xr-x 0 0 1494-128-3 /WINDOWS/system32/webhits.dll 13600 ..c. r/rr-xr-xr-x 0 0 1495-128-3 /WINDOWS/system32/wfwnet.drv 9632 ..c. r/rr-xr-xr-x 0 0 1496-128-3 /WINDOWS/system32/wbem/whqlprov.mof 40448 ..c. r/rr-xr-xr-x 0 0 1497-128-3 /WINDOWS/system32/wiasf.ax 3584 ..c. r/rr-xr-xr-x 0 0 1498-128-3 /WINDOWS/twain_32/wiatwain.ds 145408 ..c. r/rr-xr-xr-x 0 0 1499-128-3 /WINDOWS/system32/wiavusd.dll 496 ..c. d/dr-xr-xr-x 0 0 150-144-1 /WINDOWS/system32/mui/0405 9216 ..c. r/rr-xr-xr-x 0 0 1500-128-3 /WINDOWS/system32/wifeman.dll 18432 ..c. r/rr-xr-xr-x 0 0 1501-128-3 /WINDOWS/system32/win.com 13312 ..c. r/rr-xr-xr-x 0 0 1502-128-3 /WINDOWS/system32/win87em.dll 9216 ..c. r/rr-xr-xr-x 0 0 1506-128-3 /WINDOWS/system32/winfax.dll 256192 ..c. r/rr-xr-xr-x 0 0 1507-128-3 /WINDOWS/winhelp.exe 32674 ..c. r/rr-xr-xr-x 0 0 1508-128-3 /WINDOWS/system32/winhelp.hlp 496 ..c. d/dr-xr-xr-x 0 0 151-144-1 /WINDOWS/system32/mui/0406 8192 ..c. r/rr-xr-xr-x 0 0 1511-128-3 /WINDOWS/system32/winhlp32.exe 11776 ..c. r/rr-xr-xr-x 0 0 1513-128-3 /WINDOWS/system32/winmsd.exe 2080 ..c. r/rr-xr-xr-x 0 0 1514-128-3 /WINDOWS/system32/winoldap.mod 2864 ..c. r/rr-xr-xr-x 0 0 1515-128-3 /WINDOWS/system32/winsock.dll 2112 ..c. r/rr-xr-xr-x 0 0 1516-128-3 /WINDOWS/system32/winspool.exe 18944 ..c. r/rr-xr-xr-x 0 0 1517-128-3 /WINDOWS/system32/winstrm.dll 496 ..c. d/dr-xr-xr-x 0 0 152-144-1 /WINDOWS/system32/mui/0407 18944 ..c. r/rr-xr-xr-x 0 0 1520-128-3 /WINDOWS/system32/wmiprop.dll 55808 ..c. r/rr-xr-xr-x 0 0 1521-128-3 /WINDOWS/system32/wmiscmgr.dll 2736 ..c. r/rr-xr-xr-x 0 0 1522-128-3 /WINDOWS/system32/wowdeb.exe 10368 ..c. r/rr-xr-xr-x 0 0 1523-128-3 /WINDOWS/system32/wowexec.exe 3200 ..c. r/rr-xr-xr-x 0 0 1524-128-3 /WINDOWS/system32/wowfax.dll 13824 ..c. r/rr-xr-xr-x 0 0 1525-128-3 /WINDOWS/system32/wowfaxui.dll 496 ..c. d/dr-xr-xr-x 0 0 153-144-1 /WINDOWS/system32/mui/0408 9216 ..c. r/rr-xr-xr-x 0 0 1532-128-3 /WINDOWS/system32/wshatm.dll 11776 ..c. r/rr-xr-xr-x 0 0 1534-128-3 /WINDOWS/system32/wshisn.dll 7168 ..c. r/rr-xr-xr-x 0 0 1535-128-3 /WINDOWS/system32/wshnetbs.dll 496 ..c. d/dr-xr-xr-x 0 0 154-144-1 /WINDOWS/system32/mui/040b 32256 ..c. r/rr-xr-xr-x 0 0 1543-128-3 /WINDOWS/system32/wupdmgr.exe 8261 ..c. r/rr-xr-xr-x 0 0 1544-128-3 /WINDOWS/system32/Setup/zoneoc.dll 697 ..c. r/rr-xr-xr-x 0 0 1545-128-1 /WINDOWS/system32/noise.tha 69886 ..c. r/rr-xr-xr-x 0 0 1546-128-3 /WINDOWS/system32/edit.com 10790 ..c. r/rr-xr-xr-x 0 0 1547-128-3 /WINDOWS/system32/edit.hlp 1696 ..c. r/rr-xr-xr-x 0 0 1549-128-3 /WINDOWS/system32/noise.chs 496 ..c. d/dr-xr-xr-x 0 0 155-144-1 /WINDOWS/system32/mui/040C 1696 ..c. r/rr-xr-xr-x 0 0 1550-128-3 /WINDOWS/system32/noise.cht 51200 ..c. r/rr-xr-xr-x 0 0 1551-128-3 /WINDOWS/system32/wmerrenu.dll 496 .ac. d/dr-xr-xr-x 0 0 156-144-1 /WINDOWS/system32/mui/040D 82944 ..c. r/rr-xr-xr-x 0 0 1563-128-3 /WINDOWS/clock.avi 27136 ..c. r/rr-xr-xr-x 0 0 1565-128-3 /WINDOWS/system32/ctl3d32.dll 590336 ..c. r/rr-xr-xr-x 0 0 1567-128-3 /WINDOWS/system32/d3dramp.dll 496 .ac. d/dr-xr-xr-x 0 0 157-144-1 /WINDOWS/system32/mui/040e 127213 ..c. r/rr-xr-xr-x 0 0 1571-128-3 /WINDOWS/system32/ega.cpi 6144 ..c. r/rr-xr-xr-x 0 0 1573-128-3 /WINDOWS/system32/Setup/fsconins.dll 496 .ac. d/dr-xr-xr-x 0 0 158-144-1 /WINDOWS/system32/mui/0410 14576 ..c. r/rr-xr-xr-x 0 0 1582-128-3 /WINDOWS/system32/spool/drivers/color/is330.icm 496 .ac. d/dr-xr-xr-x 0 0 159-144-1 /WINDOWS/system32/mui/0411 496 .ac. d/dr-xr-xr-x 0 0 160-144-1 /WINDOWS/system32/mui/0412 496 .ac. d/dr-xr-xr-x 0 0 161-144-1 /WINDOWS/system32/mui/0413 51712 ..c. r/rr-xr-xr-x 0 0 1611-128-3 /WINDOWS/system32/migpwd.exe 25088 ..c. r/rr-xr-xr-x 0 0 1612-128-3 /WINDOWS/system32/lnkstub.exe 69632 ..c. r/rr-xr-xr-x 0 0 1616-128-3 /WINDOWS/system32/msr2c.dll 73802 ..c. r/rr-xr-xr-x 0 0 1617-128-3 /WINDOWS/system32/msrclr40.dll 28746 ..c. r/rr-xr-xr-x 0 0 1618-128-3 /WINDOWS/system32/msrecr40.dll 7168 ..c. r/rr-xr-xr-x 0 0 1619-128-3 /WINDOWS/system32/msr2cenu.dll 496 .ac. d/dr-xr-xr-x 0 0 162-144-1 /WINDOWS/system32/mui/0414 253952 ..c. r/rr-xr-xr-x 0 0 1620-128-3 /WINDOWS/system32/msvcrt20.dll 496 .ac. d/dr-xr-xr-x 0 0 163-144-1 /WINDOWS/system32/mui/0415 496 .ac. d/dr-xr-xr-x 0 0 164-144-1 /WINDOWS/system32/mui/0416 496 .ac. d/dr-xr-xr-x 0 0 165-144-1 /WINDOWS/system32/mui/0419 496 .ac. d/dr-xr-xr-x 0 0 166-144-1 /WINDOWS/system32/mui/041D 496 .ac. d/dr-xr-xr-x 0 0 167-144-1 /WINDOWS/system32/mui/041f 496 .ac. d/dr-xr-xr-x 0 0 168-144-1 /WINDOWS/system32/mui/0804 496 .ac. d/dr-xr-xr-x 0 0 169-144-1 /WINDOWS/system32/mui/0816 496 .ac. d/dr-xr-xr-x 0 0 170-144-1 /WINDOWS/system32/mui/0C0A 160 ..c. d/dr-xr-xr-x 0 0 171-144-1 /WINDOWS/system32/mui/0402 160 .ac. d/dr-xr-xr-x 0 0 172-144-1 /WINDOWS/system32/mui/0418 157696 ..c. r/rr-xr-xr-x 0 0 1723-128-3 /WINDOWS/system32/paqsp.dll 15360 ..c. r/rr-xr-xr-x 0 0 1724-128-3 /WINDOWS/system32/pentnt.exe 160 .ac. d/dr-xr-xr-x 0 0 173-144-1 /WINDOWS/system32/mui/041a 496 .ac. d/dr-xr-xr-x 0 0 174-144-1 /WINDOWS/system32/mui/041b 160 .ac. d/dr-xr-xr-x 0 0 175-144-1 /WINDOWS/system32/mui/041e 496 .ac. d/dr-xr-xr-x 0 0 176-144-1 /WINDOWS/system32/mui/0424 61500 ..c. r/rr-xr-xr-x 0 0 1761-128-3 /WINDOWS/system32/usrcntra.dll 69699 ..c. r/rr-xr-xr-x 0 0 1762-128-3 /WINDOWS/system32/usrcoina.dll 77890 ..c. r/rr-xr-xr-x 0 0 1763-128-3 /WINDOWS/system32/usrdpa.dll 323641 ..c. r/rr-xr-xr-x 0 0 1764-128-3 /WINDOWS/system32/usrdtea.dll 86073 ..c. r/rr-xr-xr-x 0 0 1765-128-3 /WINDOWS/system32/usrfaxa.dll 53305 ..c. r/rr-xr-xr-x 0 0 1766-128-3 /WINDOWS/system32/usrlbva.dll 77891 ..c. r/rr-xr-xr-x 0 0 1767-128-3 /WINDOWS/system32/usrmlnka.exe 61508 ..c. r/rr-xr-xr-x 0 0 1768-128-3 /WINDOWS/system32/usrprbda.exe 77883 ..c. r/rr-xr-xr-x 0 0 1769-128-3 /WINDOWS/system32/usrrtosa.dll 160 .ac. d/dr-xr-xr-x 0 0 177-144-1 /WINDOWS/system32/mui/0425 49211 ..c. r/rr-xr-xr-x 0 0 1770-128-3 /WINDOWS/system32/usrsdpia.dll 69700 ..c. r/rr-xr-xr-x 0 0 1771-128-3 /WINDOWS/system32/usrshuta.exe 41019 ..c. r/rr-xr-xr-x 0 0 1772-128-3 /WINDOWS/system32/usrsvpia.dll 102457 ..c. r/rr-xr-xr-x 0 0 1773-128-3 /WINDOWS/system32/usrv42a.dll 49209 ..c. r/rr-xr-xr-x 0 0 1774-128-3 /WINDOWS/system32/usrv80a.dll 45116 ..c. r/rr-xr-xr-x 0 0 1775-128-3 /WINDOWS/system32/usrvoica.dll 49211 ..c. r/rr-xr-xr-x 0 0 1776-128-3 /WINDOWS/system32/usrvpa.dll 18944 ..c. r/rr-xr-xr-x 0 0 1778-128-3 /WINDOWS/vmmreg32.dll 160 .ac. d/dr-xr-xr-x 0 0 178-144-1 /WINDOWS/system32/mui/0426 40448 ..c. r/rr-xr-xr-x 0 0 1784-128-3 /WINDOWS/system32/osuninst.exe 160 .ac. d/dr-xr-xr-x 0 0 179-144-1 /WINDOWS/system32/mui/0427 56 ..c. d/dr-xr-xr-x 0 0 180-144-5 /WINDOWS/system32/en 56 .ac. d/dr-xr-xr-x 0 0 181-144-6 /WINDOWS/system32/scripting 12288 ..c. r/rr-xr-xr-x 0 0 182-128-3 /WINDOWS/system32/bootvid.dll 7040 ..c. r/rr-xr-xr-x 0 0 183-128-3 /WINDOWS/system32/kdcom.dll 66082 ..c. r/rr-xr-xr-x 0 0 184-128-3 /WINDOWS/system32/c_1252.nls 66594 ..c. r/rr-xr-xr-x 0 0 185-128-3 /WINDOWS/system32/c_437.nls 7046 ..c. r/rr-xr-xr-x 0 0 186-128-3 /WINDOWS/system32/l_intl.nls 61952 ..c. r/rr-xr-xr-x 0 0 1876-128-3 /WINDOWS/system32/acelpdec.ax 83456 ..c. r/rr-xr-xr-x 0 0 1877-128-3 /WINDOWS/system32/l3codecx.ax 51456 ..c. r/rr-xr-xr-x 0 0 1880-128-3 /WINDOWS/system32/vga256.dll 18176 ..c. r/rr-xr-xr-x 0 0 1881-128-3 /WINDOWS/system32/vga64k.dll 706048 ..c. r/rr-xr-xr-x 0 0 1931-128-3 /WINDOWS/system32/ntdll.dll 50688 ..c. r/rr-xr-xr-x 0 0 1932-128-3 /WINDOWS/system32/smss.exe 588800 ..c. r/rr-xr-xr-x 0 0 1933-128-3 /WINDOWS/system32/autochk.exe 1614848 ..c. r/rr-xr-xr-x 0 0 1935-128-3 /WINDOWS/system32/sfcfiles.dll 617472 ..c. r/rr-xr-xr-x 0 0 1936-128-3 /WINDOWS/system32/advapi32.dll 276992 ..c. r/rr-xr-xr-x 0 0 1937-128-3 /WINDOWS/system32/comdlg32.dll 285184 ..c. r/rr-xr-xr-x 0 0 1938-128-3 /WINDOWS/system32/gdi32.dll 144384 ..c. r/rr-xr-xr-x 0 0 1939-128-3 /WINDOWS/system32/imagehlp.dll 989696 ..c. r/rr-xr-xr-x 0 0 1940-128-3 /WINDOWS/system32/kernel32.dll 1287168 ..c. r/rr-xr-xr-x 0 0 1941-128-3 /WINDOWS/system32/ole32.dll 551936 ..c. r/rr-xr-xr-x 0 0 1942-128-3 /WINDOWS/system32/oleaut32.dll 74752 ..c. r/rr-xr-xr-x 0 0 1943-128-3 /WINDOWS/system32/olecli32.dll 37376 ..c. r/rr-xr-xr-x 0 0 1944-128-3 /WINDOWS/system32/olecnv32.dll 584704 ..c. r/rr-xr-xr-x 0 0 1945-128-3 /WINDOWS/system32/rpcrt4.dll 37888 ..c. r/rr-xr-xr-x 0 0 1947-128-3 /WINDOWS/system32/url.dll 619520 ..c. r/rr-xr-xr-x 0 0 1948-128-3 /WINDOWS/system32/urlmon.dll 578560 ..c. r/rr-xr-xr-x 0 0 1949-128-3 /WINDOWS/system32/user32.dll 18944 ..c. r/rr-xr-xr-x 0 0 1950-128-3 /WINDOWS/system32/version.dll 666112 ..c. r/rr-xr-xr-x 0 0 1951-128-3 /WINDOWS/system32/wininet.dll 172032 ..c. r/rr-xr-xr-x 0 0 1952-128-3 /WINDOWS/system32/wldap32.dll 474112 ..c. r/rr-xr-xr-x 0 0 1953-128-3 /WINDOWS/system32/shlwapi.dll 617472 ..c. r/rr-xr-xr-x 0 0 1954-128-3 /WINDOWS/system32/comctl32.dll 343040 ..c. r/rr-xr-xr-x 0 0 1955-128-3 /WINDOWS/system32/msvcrt.dll 59904 ..c. r/rr-xr-xr-x 0 0 1956-128-3 /WINDOWS/system32/mpr.dll 420864 ..c. r/rr-xr-xr-x 0 0 1957-128-3 /WINDOWS/system32/ntvdm.exe 264192 ..c. r/rr-xr-xr-x 0 0 1958-128-3 /WINDOWS/system32/wow32.dll 599040 ..c. r/rr-xr-xr-x 0 0 1959-128-3 /WINDOWS/system32/crypt32.dll 727040 ..c. r/rr-xr-xr-x 0 0 1960-128-3 /WINDOWS/system32/userenv.dll 57344 ..c. r/rr-xr-xr-x 0 0 1961-128-3 /WINDOWS/system32/msasn1.dll 1845632 ..c. r/rr-xr-xr-x 0 0 1962-128-3 /WINDOWS/system32/win32k.sys 17664 ..c. r/rr-xr-xr-x 0 0 1963-128-3 /WINDOWS/system32/watchdog.sys 6144 ..c. r/rr-xr-xr-x 0 0 1964-128-3 /WINDOWS/system32/csrss.exe 32256 ..c. r/rr-xr-xr-x 0 0 1965-128-3 /WINDOWS/system32/csrsrv.dll 52736 ..c. r/rr-xr-xr-x 0 0 1966-128-3 /WINDOWS/system32/basesrv.dll 293376 ..c. r/rr-xr-xr-x 0 0 1967-128-3 /WINDOWS/system32/winsrv.dll 265948 ..c. r/rr-xr-xr-x 0 0 1968-128-3 /WINDOWS/system32/locale.nls 23044 ..c. r/rr-xr-xr-x 0 0 1969-128-3 /WINDOWS/system32/sorttbls.nls 507904 ..c. r/rr-xr-xr-x 0 0 1971-128-3 /WINDOWS/system32/winlogon.exe 17920 ..c. r/rr-xr-xr-x 0 0 1972-128-3 /WINDOWS/system32/nddeapi.dll 56320 ..c. r/rr-xr-xr-x 0 0 1973-128-3 /WINDOWS/system32/secur32.dll 53760 ..c. r/rr-xr-xr-x 0 0 1974-128-3 /WINDOWS/system32/winsta.dll 27648 ..c. r/rr-xr-xr-x 0 0 1975-128-3 /WINDOWS/system32/profmap.dll 337408 ..c. r/rr-xr-xr-x 0 0 1976-128-3 /WINDOWS/system32/netapi32.dll 49664 ..c. r/rr-xr-xr-x 0 0 1977-128-3 /WINDOWS/system32/regapi.dll 82432 ..c. r/rr-xr-xr-x 0 0 1978-128-3 /WINDOWS/system32/ws2_32.dll 19968 ..c. r/rr-xr-xr-x 0 0 1979-128-3 /WINDOWS/system32/ws2help.dll 262148 ..c. r/rr-xr-xr-x 0 0 1980-128-3 /WINDOWS/system32/sortkey.nls 997376 ..c. r/rr-xr-xr-x 0 0 1983-128-3 /WINDOWS/system32/msgina.dll 249856 ..c. r/rr-xr-xr-x 0 0 1984-128-3 /WINDOWS/system32/odbc32.dll 713216 ..c. r/rr-xr-xr-x 0 0 1985-128-3 /WINDOWS/system32/sxs.dll 94208 ..c. r/rr-xr-xr-x 0 0 1986-128-3 /WINDOWS/system32/odbcint.dll 135168 ..c. r/rr-xr-xr-x 0 0 1987-128-3 /WINDOWS/system32/shsvcs.dll 985088 ..c. r/rr-xr-xr-x 0 0 1988-128-3 /WINDOWS/system32/setupapi.dll 5120 ..c. r/rr-xr-xr-x 0 0 1989-128-3 /WINDOWS/system32/sfc.dll 2560 ..c. r/rr-xr-xr-x 0 0 199-128-3 /WINDOWS/system32/lz32.dll 176640 ..c. r/rr-xr-xr-x 0 0 1990-128-3 /WINDOWS/system32/wintrust.dll 25088 ..c. r/rr-xr-xr-x 0 0 1991-128-3 /WINDOWS/system32/slayerxp.dll 125952 ..c. r/rr-xr-xr-x 0 0 1992-128-3 /WINDOWS/system32/apphelp.dll 98304 ..c. r/rr-xr-xr-x 0 0 1993-128-3 /WINDOWS/system32/ahui.exe 108544 ..c. r/rr-xr-xr-x 0 0 1994-128-3 /WINDOWS/system32/services.exe 13312 ..c. r/rr-xr-xr-x 0 0 1995-128-3 /WINDOWS/system32/lsass.exe 314880 ..c. r/rr-xr-xr-x 0 0 1996-128-3 /WINDOWS/system32/scesrv.dll 123392 ..c. r/rr-xr-xr-x 0 0 1997-128-3 /WINDOWS/system32/umpnpmgr.dll 728064 ..c. r/rr-xr-xr-x 0 0 1998-128-3 /WINDOWS/system32/lsasrv.dll 33280 ..c. r/rr-xr-xr-x 0 0 1999-128-3 /WINDOWS/system32/cryptdll.dll 22016 ..c. r/rr-xr-xr-x 0 0 200-128-3 /WINDOWS/system32/olesvr32.dll 36352 ..c. r/rr-xr-xr-x 0 0 2000-128-3 /WINDOWS/system32/ncobjapi.dll 415744 ..c. r/rr-xr-xr-x 0 0 2001-128-3 /WINDOWS/system32/samsrv.dll 147968 ..c. r/rr-xr-xr-x 0 0 2002-128-3 /WINDOWS/system32/dnsapi.dll 64000 ..c. r/rr-xr-xr-x 0 0 2003-128-3 /WINDOWS/system32/samlib.dll 67072 ..c. r/rr-xr-xr-x 0 0 2004-128-3 /WINDOWS/system32/ntdsapi.dll 144384 ..c. r/rr-xr-xr-x 0 0 2005-128-3 /WINDOWS/system32/schannel.dll 60416 ..c. r/rr-xr-xr-x 0 0 2006-128-3 /WINDOWS/system32/cabinet.dll 48128 ..c. r/rr-xr-xr-x 0 0 2007-128-3 /WINDOWS/system32/msprivs.dll 299520 ..c. r/rr-xr-xr-x 0 0 2008-128-3 /WINDOWS/system32/kerberos.dll 110080 ..c. r/rr-xr-xr-x 0 0 2009-128-3 /WINDOWS/system32/imm32.dll 69120 ..c. r/rr-xr-xr-x 0 0 201-128-3 /WINDOWS/system32/olethk32.dll 176128 ..c. r/rr-xr-xr-x 0 0 2010-128-3 /WINDOWS/system32/winmm.dll 132608 ..c. r/rr-xr-xr-x 0 0 2011-128-3 /WINDOWS/system32/msv1_0.dll 407040 ..c. r/rr-xr-xr-x 0 0 2012-128-3 /WINDOWS/system32/netlogon.dll 49152 ..c. r/rr-xr-xr-x 0 0 2013-128-3 /WINDOWS/system32/wdigest.dll 208384 ..c. r/rr-xr-xr-x 0 0 2014-128-3 /WINDOWS/system32/rsaenh.dll 99328 ..c. r/rr-xr-xr-x 0 0 2015-128-3 /WINDOWS/system32/winscard.dll 56320 ..c. r/rr-xr-xr-x 0 0 2016-128-3 /WINDOWS/system32/eventlog.dll 181248 ..c. r/rr-xr-xr-x 0 0 2017-128-3 /WINDOWS/system32/scecli.dll 14336 ..c. r/rr-xr-xr-x 0 0 2018-128-3 /WINDOWS/system32/svchost.exe 399360 ..c. r/rr-xr-xr-x 0 0 2019-128-3 /WINDOWS/system32/rpcss.dll 89588 ..c. r/rr-xr-xr-x 0 0 202-128-3 /WINDOWS/system32/unicode.nls 245248 ..c. r/rr-xr-xr-x 0 0 2020-128-3 /WINDOWS/system32/mswsock.dll 19456 ..c. r/rr-xr-xr-x 0 0 2021-128-3 /WINDOWS/system32/wshtcpip.dll 94720 ..c. r/rr-xr-xr-x 0 0 2023-128-3 /WINDOWS/system32/iphlpapi.dll 126976 ..c. r/rr-xr-xr-x 0 0 2024-128-3 /WINDOWS/system32/dhcpcsvc.dll 16896 ..c. r/rr-xr-xr-x 0 0 2025-128-3 /WINDOWS/system32/winrnr.dll 7680 ..c. r/rr-xr-xr-x 0 0 2026-128-3 /WINDOWS/system32/rasadhlp.dll 44032 ..c. r/rr-xr-xr-x 0 0 2029-128-3 /WINDOWS/system32/rtutils.dll 218624 ..c. r/rr-xr-xr-x 0 0 2030-128-3 /WINDOWS/system32/uxtheme.dll 18432 ..c. r/rr-xr-xr-x 0 0 2031-128-3 /WINDOWS/system32/wtsapi32.dll 23552 ..c. r/rr-xr-xr-x 0 0 2032-128-3 /WINDOWS/system32/wdmaud.drv 45568 ..c. r/rr-xr-xr-x 0 0 2033-128-3 /WINDOWS/system32/dnsrslvr.dll 13824 ..c. r/rr-xr-xr-x 0 0 2034-128-3 /WINDOWS/system32/lmhsvc.dll 6656 ..c. r/rr-xr-xr-x 0 0 2035-128-3 /WINDOWS/system32/msidle.dll 57856 ..c. r/rr-xr-xr-x 0 0 2036-128-3 /WINDOWS/system32/spoolsv.exe 118784 ..c. r/rr-xr-xr-x 0 0 2037-128-3 /WINDOWS/system32/ntmarta.dll 132096 ..c. r/rr-xr-xr-x 0 0 2038-128-3 /WINDOWS/system32/wkssvc.dll 71680 ..c. r/rr-xr-xr-x 0 0 2039-128-3 /WINDOWS/system32/msacm32.dll 42496 ..c. r/rr-xr-xr-x 0 0 2040-128-3 /WINDOWS/system32/audiosrv.dll 16896 ..c. r/rr-xr-xr-x 0 0 2041-128-3 /WINDOWS/system32/cfgmgr32.dll 246272 ..c. r/rr-xr-xr-x 0 0 2042-128-3 /WINDOWS/system32/es.dll 33792 ..c. r/rr-xr-xr-x 0 0 2043-128-3 /WINDOWS/system32/msgsvc.dll 183808 ..c. r/rr-xr-xr-x 0 0 2044-128-3 /WINDOWS/system32/ipsecsvc.dll 80384 ..c. r/rr-xr-xr-x 0 0 2045-128-3 /WINDOWS/system32/faultrep.dll 270336 ..c. r/rr-xr-xr-x 0 0 2046-128-3 /WINDOWS/system32/oakley.dll 59904 ..c. r/rr-xr-xr-x 0 0 2047-128-3 /WINDOWS/system32/regsvc.dll 32256 ..c. r/rr-xr-xr-x 0 0 2048-128-3 /WINDOWS/system32/winipsec.dll 23552 ..c. r/rr-xr-xr-x 0 0 2049-128-3 /WINDOWS/system32/dmserver.dll 68096 ..c. r/rr-xr-xr-x 0 0 2050-128-3 /WINDOWS/system32/webclnt.dll 62464 ..c. r/rr-xr-xr-x 0 0 2051-128-3 /WINDOWS/system32/cryptsvc.dll 194560 ..c. r/rr-xr-xr-x 0 0 2052-128-3 /WINDOWS/system32/certcli.dll 58880 ..c. r/rr-xr-xr-x 0 0 2053-128-3 /WINDOWS/system32/atl.dll 1082368 ..c. r/rr-xr-xr-x 0 0 2054-128-3 /WINDOWS/system32/esent.dll 34304 ..c. r/rr-xr-xr-x 0 0 2055-128-3 /WINDOWS/system32/pstorsvc.dll 14336 ..c. r/rr-xr-xr-x 0 0 2056-128-3 /WINDOWS/system32/drprov.dll 96768 ..c. r/rr-xr-xr-x 0 0 2057-128-3 /WINDOWS/system32/psbase.dll 44032 ..c. r/rr-xr-xr-x 0 0 2058-128-3 /WINDOWS/system32/ntlanman.dll 80896 ..c. r/rr-xr-xr-x 0 0 2059-128-3 /WINDOWS/system32/netui0.dll 9344 ..c. r/rr-xr-xr-x 0 0 206-128-3 /WINDOWS/system32/vga.dll 245760 ..c. r/rr-xr-xr-x 0 0 2060-128-3 /WINDOWS/system32/netui1.dll 175104 ..c. r/rr-xr-xr-x 0 0 2061-128-3 /WINDOWS/system32/w32time.dll 11776 ..c. r/rr-xr-xr-x 0 0 2062-128-3 /WINDOWS/system32/netrap.dll 413696 ..c. r/rr-xr-xr-x 0 0 2063-128-3 /WINDOWS/system32/msvcp60.dll 25088 ..c. r/rr-xr-xr-x 0 0 2064-128-3 /WINDOWS/system32/davclnt.dll 138752 ..c. r/rr-xr-xr-x 0 0 2065-128-3 /WINDOWS/system32/dssenh.dll 22528 ..c. r/rr-xr-xr-x 0 0 2066-128-3 /WINDOWS/system32/wsock32.dll 3584 ..c. r/rr-xr-xr-x 0 0 2067-128-3 /WINDOWS/system32/icmp.dll 87040 ..c. r/rr-xr-xr-x 0 0 2068-128-3 /WINDOWS/system32/mprapi.dll 193536 ..c. r/rr-xr-xr-x 0 0 2069-128-3 /WINDOWS/system32/activeds.dll 231 ..c. r/rr-xr-xr-x 0 0 207-128-1 /WINDOWS/system.ini 143360 ..c. r/rr-xr-xr-x 0 0 2070-128-3 /WINDOWS/system32/adsldpc.dll 90112 ..c. r/rr-xr-xr-x 0 0 2071-128-3 /WINDOWS/system32/trkwks.dll 18944 ..c. r/rr-xr-xr-x 0 0 2072-128-3 /WINDOWS/system32/seclogon.dll 96768 ..c. r/rr-xr-xr-x 0 0 2073-128-3 /WINDOWS/system32/srvsvc.dll 39424 ..c. r/rr-xr-xr-x 0 0 2074-128-3 /WINDOWS/system32/sens.dll 25088 ..c. r/rr-xr-xr-x 0 0 2076-128-3 /WINDOWS/system32/shfolder.dll 77824 ..c. r/rr-xr-xr-x 0 0 2077-128-3 /WINDOWS/system32/browser.dll 16896 ..c. r/rr-xr-xr-x 0 0 2078-128-3 /WINDOWS/system32/stdole2.tlb 237056 ..c. r/rr-xr-xr-x 0 0 2079-128-3 /WINDOWS/system32/rasapi32.dll 61440 ..c. r/rr-xr-xr-x 0 0 2080-128-3 /WINDOWS/system32/rasman.dll 181760 ..c. r/rr-xr-xr-x 0 0 2081-128-3 /WINDOWS/system32/tapi32.dll 7168 ..c. r/rr-xr-xr-x 0 0 2082-128-3 /WINDOWS/system32/sensapi.dll 101888 ..c. r/rr-xr-xr-x 0 0 2083-128-3 /WINDOWS/system32/cscdll.dll 92672 ..c. r/rr-xr-xr-x 0 0 2084-128-3 /WINDOWS/system32/wlnotify.dll 146432 ..c. r/rr-xr-xr-x 0 0 2085-128-3 /WINDOWS/system32/winspool.drv 326656 ..c. r/rr-xr-xr-x 0 0 2086-128-3 /WINDOWS/system32/cscui.dll 17408 ..c. r/rr-xr-xr-x 0 0 2087-128-3 /WINDOWS/system32/powrprof.dll 423936 ..c. r/rr-xr-xr-x 0 0 2088-128-3 /WINDOWS/system32/licdll.dll 102912 ..c. r/rr-xr-xr-x 0 0 2089-128-3 /WINDOWS/system32/dpcdll.dll 26112 ..c. r/rr-xr-xr-x 0 0 2090-128-3 /WINDOWS/system32/userinit.exe 75264 ..c. r/rr-xr-xr-x 0 0 2091-128-3 /WINDOWS/system32/spoolss.dll 116224 ..c. r/rr-xr-xr-x 0 0 2092-128-3 /WINDOWS/system32/mstlsapi.dll 1025024 ..c. r/rr-xr-xr-x 0 0 2094-128-3 /WINDOWS/system32/browseui.dll 343040 ..c. r/rr-xr-xr-x 0 0 2095-128-3 /WINDOWS/system32/localspl.dll 1499136 ..c. r/rr-xr-xr-x 0 0 2096-128-3 /WINDOWS/system32/shdocvw.dll 47104 ..c. r/rr-xr-xr-x 0 0 2097-128-3 /WINDOWS/system32/cnbjmon.dll 15360 ..c. r/rr-xr-xr-x 0 0 2098-128-3 /WINDOWS/system32/pjlmon.dll 45568 ..c. r/rr-xr-xr-x 0 0 2099-128-3 /WINDOWS/system32/tcpmon.dll 16896 ..c. r/rr-xr-xr-x 0 0 2100-128-3 /WINDOWS/system32/usbmon.dll 12168 ..c. r/rr-xr-xr-x 0 0 2101-128-3 /WINDOWS/system32/tsddd.dll 92424 ..c. r/rr-xr-xr-x 0 0 2102-128-3 /WINDOWS/system32/rdpdd.dll 102400 ..c. r/rr-xr-xr-x 0 0 2103-128-3 /WINDOWS/system32/win32spl.dll 75264 ..c. r/rr-xr-xr-x 0 0 2104-128-3 /WINDOWS/system32/inetpp.dll 135168 ..c. r/rr-xr-xr-x 0 0 2105-128-3 /WINDOWS/system32/desk.cpl 385536 ..c. r/rr-xr-xr-x 0 0 2106-128-3 /WINDOWS/system32/themeui.dll 4608 ..c. r/rr-xr-xr-x 0 0 2107-128-3 /WINDOWS/system32/msimg32.dll 2843136 ..c. r/rr-xr-xr-x 0 0 2108-128-3 /WINDOWS/system32/msi.dll 146432 ..c. r/rr-xr-xr-x 0 0 2109-128-3 /WINDOWS/regedit.exe 62464 ..c. r/rr-xr-xr-x 0 0 2110-128-3 /WINDOWS/system32/authz.dll 115712 ..c. r/rr-xr-xr-x 0 0 2111-128-3 /WINDOWS/system32/aclui.dll 275456 ..c. r/rr-xr-xr-x 0 0 2112-128-3 /WINDOWS/system32/ulib.dll 98304 ..c. r/rr-xr-xr-x 0 0 2113-128-3 /WINDOWS/system32/actxprxy.dll 34304 ..c. r/rr-xr-xr-x 0 0 2114-128-3 /WINDOWS/system32/ie4uinit.exe 99840 ..c. r/rr-xr-xr-x 0 0 2115-128-3 /WINDOWS/system32/advpack.dll 389120 ..c. r/rr-xr-xr-x 0 0 2116-128-3 /WINDOWS/system32/cmd.exe 19968 ..c. r/rr-xr-xr-x 0 0 2117-128-3 /WINDOWS/system32/linkinfo.dll 143360 ..c. r/rr-xr-xr-x 0 0 2118-128-3 /WINDOWS/system32/ntshrui.dll 84992 ..c. r/rr-xr-xr-x 0 0 2119-128-3 /WINDOWS/system32/avifil32.dll 121344 ..c. r/rr-xr-xr-x 0 0 2120-128-3 /WINDOWS/system32/msvfw32.dll 506368 ..c. r/rr-xr-xr-x 0 0 2121-128-3 /WINDOWS/system32/msxml.dll 151552 ..c. r/rr-xr-xr-x 0 0 2122-128-3 /WINDOWS/system32/msdart.dll 33280 ..c. r/rr-xr-xr-x 0 0 2123-128-3 /WINDOWS/system32/rundll32.exe 11776 ..c. r/rr-xr-xr-x 0 0 2124-128-3 /WINDOWS/system32/regsvr32.exe 990208 ..c. r/rr-xr-xr-x 0 0 2125-128-3 /WINDOWS/system32/syssetup.dll 150528 ..c. r/rr-xr-xr-x 0 0 2126-128-3 /WINDOWS/system32/imapi.exe 55808 ..c. r/rr-xr-xr-x 0 0 2127-128-3 /WINDOWS/system32/ipconfig.exe 198144 ..c. r/rr-xr-xr-x 0 0 2128-128-3 /WINDOWS/system32/netman.dll 78848 ..c. r/rr-xr-xr-x 0 0 2129-128-3 /WINDOWS/system32/msiexec.exe 8386 ..c. r/rr-xr-xr-x 0 0 213-128-3 /WINDOWS/system32/ctype.nls 1326080 ..c. r/rr-xr-xr-x 0 0 2130-128-3 /WINDOWS/system32/webfldrs.msi 884736 ..c. r/rr-xr-xr-x 0 0 2131-128-3 /WINDOWS/system32/msimsg.dll 42496 ..c. r/rr-xr-xr-x 0 0 2132-128-3 /WINDOWS/system32/net.exe 124928 ..c. r/rr-xr-xr-x 0 0 2133-128-3 /WINDOWS/system32/net1.exe 276480 ..c. r/rr-xr-xr-x 0 0 2134-128-3 /WINDOWS/system32/webcheck.dll 43520 ..c. r/rr-xr-xr-x 0 0 2135-128-3 /WINDOWS/system32/pstorec.dll 207360 ..c. r/rr-xr-xr-x 0 0 2136-128-3 /WINDOWS/system32/mobsync.dll 147456 ..c. r/rr-xr-xr-x 0 0 2137-128-3 /WINDOWS/system32/initpki.dll 323584 ..c. r/rr-xr-xr-x 0 0 2138-128-3 /WINDOWS/system32/iedkcs32.dll 23024 ..c. r/rr-xr-xr-x 0 0 2139-128-3 /WINDOWS/system32/ieuinit.inf 5632 ..c. r/rr-xr-xr-x 0 0 214-128-3 /WINDOWS/system32/kbdus.dll 51712 ..c. r/rr-xr-xr-x 0 0 2140-128-3 /WINDOWS/system32/msident.dll 1288192 ..c. r/rr-xr-xr-x 0 0 2141-128-3 /WINDOWS/system32/quartz.dll 67584 ..c. r/rr-xr-xr-x 0 0 2142-128-3 /WINDOWS/system32/pautoenr.dll 512512 ..c. r/rr-xr-xr-x 0 0 2143-128-3 /WINDOWS/system32/cryptui.dll 433664 ..c. r/rr-xr-xr-x 0 0 2144-128-3 /WINDOWS/system32/riched20.dll 64512 ..c. r/rr-xr-xr-x 0 0 2145-128-3 /WINDOWS/system32/cryptnet.dll 23040 ..c. r/rr-xr-xr-x 0 0 2146-128-3 /WINDOWS/system32/psapi.dll 97280 ..c. r/rr-xr-xr-x 0 0 2147-128-3 /WINDOWS/system32/loadperf.dll 5632 ..c. r/rr-xr-xr-x 0 0 2148-128-3 /WINDOWS/system32/wmi.dll 1703936 ..c. r/rr-xr-xr-x 0 0 2149-128-3 /WINDOWS/system32/netshell.dll 150016 ..c. r/rr-xr-xr-x 0 0 2151-128-3 /WINDOWS/system32/rastls.dll 79872 ..c. r/rr-xr-xr-x 0 0 2152-128-3 /WINDOWS/system32/raschap.dll 344064 ..c. r/rr-xr-xr-x 0 0 2153-128-3 /WINDOWS/system32/hnetcfg.dll 121856 ..c. r/rr-xr-xr-x 0 0 2154-128-3 /WINDOWS/system32/stobject.dll 29184 ..c. r/rr-xr-xr-x 0 0 2155-128-3 /WINDOWS/system32/batmeter.dll 163840 ..c. r/rr-xr-xr-x 0 0 2157-128-3 /WINDOWS/system32/credui.dll 25088 ..c. r/rr-xr-xr-x 0 0 2158-128-3 /WINDOWS/system32/defrag.exe 82944 ..c. r/rr-xr-xr-x 0 0 2159-128-3 /WINDOWS/system32/dfrgfat.exe 430592 ..c. r/rr-xr-xr-x 0 0 2160-128-3 /WINDOWS/system32/vssapi.dll 105472 ..c. r/rr-xr-xr-x 0 0 2161-128-3 /WINDOWS/system32/dfrgntfs.exe 27136 ..c. r/rr-xr-xr-x 0 0 2162-128-3 /WINDOWS/system32/findstr.exe 220672 ..c. r/rr-xr-xr-x 0 0 2163-128-3 /WINDOWS/system32/logon.scr 69120 ..c. r/rr-xr-xr-x 0 0 2164-128-3 /WINDOWS/system32/notepad.exe 24576 ..c. r/rr-xr-xr-x 0 0 2165-128-3 /WINDOWS/system32/sort.exe 640000 ..c. r/rr-xr-xr-x 0 0 2166-128-3 /WINDOWS/system32/dbghelp.dll 16896 ..c. r/rr-xr-xr-x 0 0 2167-128-3 /WINDOWS/system32/more.com 5632 ..c. r/rr-xr-xr-x 0 0 2168-128-3 /WINDOWS/system32/winver.exe 514560 ..c. r/rr-xr-xr-x 0 0 2174-128-3 /WINDOWS/system32/logonui.exe 560640 ..c. r/rr-xr-xr-x 0 0 2175-128-3 /WINDOWS/system32/printui.dll 20480 ..c. r/rr-xr-xr-x 0 0 2176-128-3 /WINDOWS/system32/sclgntfy.dll 68096 ..c. r/rr-xr-xr-x 0 0 2177-128-3 /WINDOWS/system32/shgina.dll 549888 ..c. r/rr-xr-xr-x 0 0 2178-128-3 /WINDOWS/system32/appwiz.cpl 63488 ..c. r/rr-xr-xr-x 0 0 2181-128-3 /WINDOWS/system32/browselc.dll 1179648 ..c. r/rr-xr-xr-x 0 0 2183-128-3 /WINDOWS/system32/d3d8.dll 3066880 ..c. r/rr-xr-xr-x 0 0 2186-128-3 /WINDOWS/system32/mshtml.dll 304128 ..c. r/rr-xr-xr-x 0 0 2189-128-3 /WINDOWS/system32/duser.dll 100352 ..c. r/rr-xr-xr-x 0 0 2191-128-3 /WINDOWS/system32/6to4svc.dll 4096 ..c. r/rr-xr-xr-x 0 0 2199-128-3 /WINDOWS/system32/actmovie.exe 61440 ..c. r/rr-xr-xr-x 0 0 2201-128-3 /WINDOWS/system32/admparse.dll 175616 ..c. r/rr-xr-xr-x 0 0 2202-128-3 /WINDOWS/system32/adsldp.dll 68096 ..c. r/rr-xr-xr-x 0 0 2203-128-3 /WINDOWS/system32/adsmsext.dll 263680 ..c. r/rr-xr-xr-x 0 0 2204-128-3 /WINDOWS/system32/adsnt.dll 123392 ..c. r/rr-xr-xr-x 0 0 2205-128-3 /WINDOWS/system32/adsnw.dll 477 ..c. r/rr-xr-xr-x 0 0 224-128-1 /WINDOWS/win.ini 44544 ..c. r/rr-xr-xr-x 0 0 2242-128-3 /WINDOWS/system32/alg.exe 17408 ..c. r/rr-xr-xr-x 0 0 2243-128-3 /WINDOWS/system32/alrsvc.dll 70656 ..c. r/rr-xr-xr-x 0 0 2246-128-3 /WINDOWS/system32/amstream.dll 167936 ..c. r/rr-xr-xr-x 0 0 2249-128-3 /WINDOWS/system32/appmgmts.dll 214016 ..c. r/rr-xr-xr-x 0 0 225-128-3 /WINDOWS/system32/netevent.dll 295936 ..c. r/rr-xr-xr-x 0 0 2250-128-3 /WINDOWS/system32/appmgr.dll 114688 ..c. r/rr-xr-xr-x 0 0 2254-128-3 /WINDOWS/system32/asctrls.ocx 30208 ..c. r/rr-xr-xr-x 0 0 2255-128-3 /WINDOWS/system32/asr_fmt.exe 32768 ..c. r/rr-xr-xr-x 0 0 2256-128-3 /WINDOWS/system32/asr_pfu.exe 65024 ..c. r/rr-xr-xr-x 0 0 2257-128-3 /WINDOWS/system32/asycfilt.dll 25088 ..c. r/rr-xr-xr-x 0 0 2259-128-3 /WINDOWS/system32/at.exe 11264 ..c. r/rr-xr-xr-x 0 0 2262-128-3 /WINDOWS/system32/atmadm.exe 285696 ..c. r/rr-xr-xr-x 0 0 2264-128-3 /WINDOWS/system32/atmfd.dll 30208 ..c. r/rr-xr-xr-x 0 0 2266-128-3 /WINDOWS/system32/atmlib.dll 12288 ..c. r/rr-xr-xr-x 0 0 2267-128-3 /WINDOWS/system32/attrib.exe 14336 ..c. r/rr-xr-xr-x 0 0 2268-128-3 /WINDOWS/system32/auditusr.exe 602624 ..c. r/rr-xr-xr-x 0 0 2269-128-3 /WINDOWS/system32/autoconv.exe 580608 ..c. r/rr-xr-xr-x 0 0 2270-128-3 /WINDOWS/system32/autofmt.exe 11264 ..c. r/rr-xr-xr-x 0 0 2271-128-3 /WINDOWS/system32/autolfn.exe 233472 ..c. r/rr-xr-xr-x 0 0 2272-128-3 /WINDOWS/system32/azroles.dll 17408 ..c. r/rr-xr-xr-x 0 0 2279-128-3 /WINDOWS/system32/bidispl.dll 142848 ..c. r/rr-xr-xr-x 0 0 2281-128-3 /WINDOWS/system32/bootcfg.exe 78336 ..c. r/rr-xr-xr-x 0 0 2283-128-3 /WINDOWS/system32/browsewm.dll 20992 ..c. r/rr-xr-xr-x 0 0 2285-128-3 /WINDOWS/system32/bthci.dll 110592 ..c. r/rr-xr-xr-x 0 0 2287-128-3 /WINDOWS/system32/bthprops.cpl 30208 ..c. r/rr-xr-xr-x 0 0 2288-128-3 /WINDOWS/system32/bthserv.dll 50688 ..c. r/rr-xr-xr-x 0 0 2291-128-3 /WINDOWS/system32/btpanui.dll 84480 ..c. r/rr-xr-xr-x 0 0 2292-128-3 /WINDOWS/system32/cabview.dll 19968 ..c. r/rr-xr-xr-x 0 0 2293-128-3 /WINDOWS/system32/cacls.exe 50688 ..c. r/rr-xr-xr-x 0 0 2294-128-3 /WINDOWS/system32/camocx.dll 150016 ..c. r/rr-xr-xr-x 0 0 2295-128-3 /WINDOWS/system32/capesnpn.dll 151040 ..c. r/rr-xr-xr-x 0 0 2298-128-3 /WINDOWS/system32/cdfview.dll 66560 ..c. r/rr-xr-xr-x 0 0 2299-128-3 /WINDOWS/system32/cdm.dll 2091520 ..c. r/rr-xr-xr-x 0 0 2300-128-3 /WINDOWS/system32/cdosys.dll 457728 ..c. r/rr-xr-xr-x 0 0 2302-128-3 /WINDOWS/system32/certmgr.dll 148480 ..c. r/rr-xr-xr-x 0 0 2304-128-3 /WINDOWS/system32/cic.dll 69120 ..c. r/rr-xr-xr-x 0 0 2305-128-3 /WINDOWS/system32/ciodm.dll 56832 ..c. r/rr-xr-xr-x 0 0 2306-128-3 /WINDOWS/system32/cipher.exe 5632 ..c. r/rr-xr-xr-x 0 0 2307-128-3 /WINDOWS/system32/cisvc.exe 64000 ..c. r/rr-xr-xr-x 0 0 2308-128-3 /WINDOWS/system32/cleanmgr.exe 77824 ..c. r/rr-xr-xr-x 0 0 2309-128-3 /WINDOWS/system32/cliconfg.dll 20480 ..c. r/rr-xr-xr-x 0 0 2310-128-3 /WINDOWS/system32/cliconfg.exe 24576 ..c. r/rr-xr-xr-x 0 0 2311-128-3 /WINDOWS/system32/cliconfg.rll 33280 ..c. r/rr-xr-xr-x 0 0 2312-128-3 /WINDOWS/system32/clipsrv.exe 58368 ..c. r/rr-xr-xr-x 0 0 2313-128-3 /WINDOWS/system32/clusapi.dll 15872 ..c. r/rr-xr-xr-x 0 0 2314-128-3 /WINDOWS/system32/cmcfg32.dll 344064 ..c. r/rr-xr-xr-x 0 0 2315-128-3 /WINDOWS/system32/cmdial32.dll 25600 ..c. r/rr-xr-xr-x 0 0 2316-128-3 /WINDOWS/system32/cmdl32.exe 39936 ..c. r/rr-xr-xr-x 0 0 2317-128-3 /WINDOWS/system32/cmmon32.exe 13312 ..c. r/rr-xr-xr-x 0 0 2318-128-3 /WINDOWS/system32/cmsetACL.dll 63488 ..c. r/rr-xr-xr-x 0 0 2319-128-3 /WINDOWS/system32/cmstp.exe 39424 ..c. r/rr-xr-xr-x 0 0 2320-128-3 /WINDOWS/system32/cmutil.dll 252928 ..c. r/rr-xr-xr-x 0 0 2322-128-3 /WINDOWS/system32/compatUI.dll 229376 ..c. r/rr-xr-xr-x 0 0 2323-128-3 /WINDOWS/system32/compstui.dll 792064 ..c. r/rr-xr-xr-x 0 0 2324-128-3 /WINDOWS/system32/comres.dll 274944 ..c. r/rr-xr-xr-x 0 0 2325-128-3 /WINDOWS/system32/Setup/comsetup.dll 357888 ..c. r/rr-xr-xr-x 0 0 2328-128-3 /WINDOWS/system32/confmsp.dll 27648 ..c. r/rr-xr-xr-x 0 0 2329-128-3 /WINDOWS/system32/conime.exe 35328 ..c. r/rr-xr-xr-x 0 0 2330-128-3 /WINDOWS/system32/corpol.dll 12800 ..c. r/rr-xr-xr-x 0 0 2332-128-3 /WINDOWS/system32/credssp.dll 74752 ..c. r/rr-xr-xr-x 0 0 2334-128-3 /WINDOWS/system32/cryptdlg.dll 53760 ..c. r/rr-xr-xr-x 0 0 2335-128-3 /WINDOWS/system32/cryptext.dll 139264 ..c. r/rr-xr-xr-x 0 0 2336-128-3 /WINDOWS/system32/cscript.exe 11776 ..c. r/rr-xr-xr-x 0 0 2337-128-3 /WINDOWS/system32/scripting/cscript.exe.mui 8192 ..c. r/rr-xr-xr-x 0 0 2339-128-3 /WINDOWS/system32/d3d8thk.dll 20480 ..c. r/rr-xr-xr-x 0 0 234-128-3 /WINDOWS/system32/msacm32.drv 1689088 ..c. r/rr-xr-xr-x 0 0 2340-128-3 /WINDOWS/system32/d3d9.dll 824320 ..c. r/rr-xr-xr-x 0 0 2341-128-3 /WINDOWS/system32/d3dim700.dll 1054208 ..c. r/rr-xr-xr-x 0 0 2342-128-3 /WINDOWS/system32/danim.dll 54272 ..c. r/rr-xr-xr-x 0 0 2343-128-3 /WINDOWS/system32/dataclen.dll 165376 ..c. r/rr-xr-xr-x 0 0 2345-128-3 /WINDOWS/system32/datime.dll 153088 ..c. r/rr-xr-xr-x 0 0 2346-128-3 /WINDOWS/system32/daxctle.ocx 24576 ..c. r/rr-xr-xr-x 0 0 2347-128-3 /WINDOWS/system32/dbmsrpcn.dll 110592 ..c. r/rr-xr-xr-x 0 0 2348-128-3 /WINDOWS/system32/dbnetlib.dll 28672 ..c. r/rr-xr-xr-x 0 0 2349-128-3 /WINDOWS/system32/dbnmpntw.dll 1804 ..c. r/rr-xr-xr-x 0 0 2350-128-3 /WINDOWS/system32/Dcache.bin 8704 ..c. r/rr-xr-xr-x 0 0 2351-128-3 /WINDOWS/system32/dciman32.dll 30208 ..c. r/rr-xr-xr-x 0 0 2352-128-3 /WINDOWS/system32/ddeshare.exe 279552 ..c. r/rr-xr-xr-x 0 0 2353-128-3 /WINDOWS/system32/ddraw.dll 27136 ..c. r/rr-xr-xr-x 0 0 2354-128-3 /WINDOWS/system32/ddrawex.dll 59904 ..c. r/rr-xr-xr-x 0 0 2356-128-3 /WINDOWS/system32/devenum.dll 282624 ..c. r/rr-xr-xr-x 0 0 2357-128-3 /WINDOWS/system32/devmgr.dll 28672 ..c. r/rr-xr-xr-x 0 0 2359-128-3 /WINDOWS/system32/dfsshlex.dll 171008 ..c. r/rr-xr-xr-x 0 0 236-128-3 /WINDOWS/system32/netmsg.dll 39424 ..c. r/rr-xr-xr-x 0 0 2360-128-3 /WINDOWS/system32/dfrgsnap.dll 124416 ..c. r/rr-xr-xr-x 0 0 2361-128-3 /WINDOWS/system32/dfrgui.dll 111104 ..c. r/rr-xr-xr-x 0 0 2362-128-3 /WINDOWS/system32/dgnet.dll 379904 ..c. r/rr-xr-xr-x 0 0 2363-128-3 /WINDOWS/system32/dhcpmon.dll 48640 ..c. r/rr-xr-xr-x 0 0 2364-128-3 /WINDOWS/system32/dhcpqec.dll 87040 ..c. r/rr-xr-xr-x 0 0 2365-128-3 /WINDOWS/system32/diantz.exe 68608 ..c. r/rr-xr-xr-x 0 0 2366-128-3 /WINDOWS/system32/digest.dll 19456 ..c. r/rr-xr-xr-x 0 0 2367-128-3 /WINDOWS/system32/dimsntfy.dll 39936 ..c. r/rr-xr-xr-x 0 0 2368-128-3 /WINDOWS/system32/dimsroam.dll 13646 ..c. r/rr-xr-xr-x 0 0 237-128-3 /WINDOWS/system32/wpa.dbl 158720 ..c. r/rr-xr-xr-x 0 0 2370-128-3 /WINDOWS/system32/dinput.dll 181760 ..c. r/rr-xr-xr-x 0 0 2371-128-3 /WINDOWS/system32/dinput8.dll 1504256 ..c. r/rr-xr-xr-x 0 0 2373-128-3 /WINDOWS/system32/diskcopy.dll 163840 ..c. r/rr-xr-xr-x 0 0 2374-128-3 /WINDOWS/system32/diskpart.exe 32768 ..c. r/rr-xr-xr-x 0 0 2375-128-3 /WINDOWS/system32/dispex.dll 5120 ..c. r/rr-xr-xr-x 0 0 2376-128-3 /WINDOWS/system32/dllhost.exe 224768 ..c. r/rr-xr-xr-x 0 0 2377-128-3 /WINDOWS/system32/dmadmin.exe 28672 ..c. r/rr-xr-xr-x 0 0 2378-128-3 /WINDOWS/system32/dmband.dll 10752 ..c. r/rr-xr-xr-x 0 0 238-128-3 /WINDOWS/system32/clb.dll 61440 ..c. r/rr-xr-xr-x 0 0 2380-128-3 /WINDOWS/system32/dmcompos.dll 285184 ..c. r/rr-xr-xr-x 0 0 2381-128-3 /WINDOWS/system32/dmdlgs.dll 200704 ..c. r/rr-xr-xr-x 0 0 2382-128-3 /WINDOWS/system32/dmdskmgr.dll 181248 ..c. r/rr-xr-xr-x 0 0 2383-128-3 /WINDOWS/system32/dmime.dll 35840 ..c. r/rr-xr-xr-x 0 0 2384-128-3 /WINDOWS/system32/dmloader.dll 15872 ..c. r/rr-xr-xr-x 0 0 2385-128-3 /WINDOWS/system32/dmremote.exe 82432 ..c. r/rr-xr-xr-x 0 0 2386-128-3 /WINDOWS/system32/dmscript.dll 105984 ..c. r/rr-xr-xr-x 0 0 2387-128-3 /WINDOWS/system32/dmstyle.dll 103424 ..c. r/rr-xr-xr-x 0 0 2388-128-3 /WINDOWS/system32/dmsynth.dll 104448 ..c. r/rr-xr-xr-x 0 0 2389-128-3 /WINDOWS/system32/dmusic.dll 26624 ..c. r/rr-xr-xr-x 0 0 239-128-3 /WINDOWS/system32/msxmlr.dll 52224 ..c. r/rr-xr-xr-x 0 0 2390-128-3 /WINDOWS/system32/dmutil.dll 48128 ..c. r/rr-xr-xr-x 0 0 2391-128-3 /WINDOWS/system32/docprop2.dll 53840 ..c. r/rr-xr-xr-x 0 0 2392-128-3 /WINDOWS/system32/dosx.exe 26112 ..c. r/rr-xr-xr-x 0 0 2393-128-3 /WINDOWS/system32/dot3api.dll 57856 ..c. r/rr-xr-xr-x 0 0 2394-128-3 /WINDOWS/system32/dot3cfg.dll 9216 ..c. r/rr-xr-xr-x 0 0 2395-128-3 /WINDOWS/system32/dot3dlg.dll 39936 ..c. r/rr-xr-xr-x 0 0 2396-128-3 /WINDOWS/system32/dot3gpclnt.dll 56320 ..c. r/rr-xr-xr-x 0 0 2397-128-3 /WINDOWS/system32/dot3msm.dll 132096 ..c. r/rr-xr-xr-x 0 0 2398-128-3 /WINDOWS/system32/dot3svc.dll 650752 ..c. r/rr-xr-xr-x 0 0 2399-128-3 /WINDOWS/system32/dot3ui.dll 149019 ..c. r/rr-xr-xr-x 0 0 240-128-3 /WINDOWS/system32/crtdll.dll 29696 ..c. r/rr-xr-xr-x 0 0 2400-128-3 /WINDOWS/system32/dplaysvr.exe 229888 ..c. r/rr-xr-xr-x 0 0 2401-128-3 /WINDOWS/system32/dplayx.dll 23552 ..c. r/rr-xr-xr-x 0 0 2402-128-3 /WINDOWS/system32/dpmodemx.dll 3072 ..c. r/rr-xr-xr-x 0 0 2403-128-3 /WINDOWS/system32/dpnaddr.dll 375296 ..c. r/rr-xr-xr-x 0 0 2404-128-3 /WINDOWS/system32/dpnet.dll 35328 ..c. r/rr-xr-xr-x 0 0 2405-128-3 /WINDOWS/system32/dpnhpast.dll 60928 ..c. r/rr-xr-xr-x 0 0 2406-128-3 /WINDOWS/system32/dpnhupnp.dll 3072 ..c. r/rr-xr-xr-x 0 0 2407-128-3 /WINDOWS/system32/dpnlobby.dll 17920 ..c. r/rr-xr-xr-x 0 0 2408-128-3 /WINDOWS/system32/dpnsvr.exe 21504 ..c. r/rr-xr-xr-x 0 0 2409-128-3 /WINDOWS/system32/dpvacm.dll 14848 ..c. r/rr-xr-xr-x 0 0 241-128-3 /WINDOWS/system32/msidntld.dll 212480 ..c. r/rr-xr-xr-x 0 0 2410-128-3 /WINDOWS/system32/dpvoice.dll 83456 ..c. r/rr-xr-xr-x 0 0 2411-128-3 /WINDOWS/system32/dpvsetup.exe 116736 ..c. r/rr-xr-xr-x 0 0 2412-128-3 /WINDOWS/system32/dpvvox.dll 57344 ..c. r/rr-xr-xr-x 0 0 2413-128-3 /WINDOWS/system32/dpwsockx.dll 62976 ..c. r/rr-xr-xr-x 0 0 2416-128-3 /WINDOWS/system32/driverquery.exe 4656 ..c. r/rr-xr-xr-x 0 0 2417-128-3 /WINDOWS/system32/ds16gt.dLL 16384 ..c. r/rr-xr-xr-x 0 0 2418-128-3 /WINDOWS/system32/ds32gt.dll 181248 ..c. r/rr-xr-xr-x 0 0 2419-128-3 /WINDOWS/system32/dsdmo.dll 47104 ..c. r/rr-xr-xr-x 0 0 242-128-3 /WINDOWS/system32/mprui.dll 71680 ..c. r/rr-xr-xr-x 0 0 2420-128-3 /WINDOWS/system32/dsdmoprp.dll 92672 ..c. r/rr-xr-xr-x 0 0 2421-128-3 /WINDOWS/system32/dskquota.dll 155648 ..c. r/rr-xr-xr-x 0 0 2422-128-3 /WINDOWS/system32/dskquoui.dll 367616 ..c. r/rr-xr-xr-x 0 0 2424-128-3 /WINDOWS/system32/dsound.dll 1293824 ..c. r/rr-xr-xr-x 0 0 2425-128-3 /WINDOWS/system32/dsound3d.dll 142848 ..c. r/rr-xr-xr-x 0 0 2426-128-3 /WINDOWS/system32/dsprop.dll 4096 ..c. r/rr-xr-xr-x 0 0 2427-128-3 /WINDOWS/system32/dsprpres.dll 239104 ..c. r/rr-xr-xr-x 0 0 2428-128-3 /WINDOWS/system32/dsquery.dll 51200 ..c. r/rr-xr-xr-x 0 0 2429-128-3 /WINDOWS/system32/dssec.dll 308224 ..c. r/rr-xr-xr-x 0 0 243-128-3 /WINDOWS/system32/netui2.dll 113152 ..c. r/rr-xr-xr-x 0 0 2430-128-3 /WINDOWS/system32/dsuiext.dll 19456 ..c. r/rr-xr-xr-x 0 0 2431-128-3 /WINDOWS/system32/dswave.dll 10752 ..c. r/rr-xr-xr-x 0 0 2433-128-3 /WINDOWS/system32/dumprep.exe 17920 ..c. r/rr-xr-xr-x 0 0 2434-128-3 /WINDOWS/system32/dvdupgrd.exe 619008 ..c. r/rr-xr-xr-x 0 0 2436-128-3 /WINDOWS/system32/dx7vb.dll 1227264 ..c. r/rr-xr-xr-x 0 0 2437-128-3 /WINDOWS/system32/dx8vb.dll 1298432 ..c. r/rr-xr-xr-x 0 0 2438-128-3 /WINDOWS/system32/dxdiag.exe 2113536 ..c. r/rr-xr-xr-x 0 0 2439-128-3 /WINDOWS/system32/dxdiagn.dll 51200 ..c. r/rr-xr-xr-x 0 0 244-128-3 /WINDOWS/system32/dfrgres.dll 357888 ..c. r/rr-xr-xr-x 0 0 2441-128-3 /WINDOWS/system32/dxtmsft.dll 205312 ..c. r/rr-xr-xr-x 0 0 2442-128-3 /WINDOWS/system32/dxtrans.dll 180224 ..c. r/rr-xr-xr-x 0 0 2443-128-3 /WINDOWS/system32/dwwin.exe 102446 ..c. r/rr-xr-xr-x 0 0 245-128-3 /WINDOWS/system32/net.hlp 30720 ..c. r/rr-xr-xr-x 0 0 2452-128-3 /WINDOWS/system32/eapolqec.dll 59392 ..c. r/rr-xr-xr-x 0 0 2453-128-3 /WINDOWS/system32/eapqec.dll 33792 ..c. r/rr-xr-xr-x 0 0 2454-128-3 /WINDOWS/system32/eapsvc.dll 184832 ..c. r/rr-xr-xr-x 0 0 2455-128-3 /WINDOWS/system32/eapp3hst.dll 126976 ..c. r/rr-xr-xr-x 0 0 2456-128-3 /WINDOWS/system32/eappcfg.dll 180224 ..c. r/rr-xr-xr-x 0 0 2457-128-3 /WINDOWS/system32/eapphost.dll 40960 ..c. r/rr-xr-xr-x 0 0 2458-128-3 /WINDOWS/system32/eappprxy.dll 94208 ..c. r/rr-xr-xr-x 0 0 2459-128-3 /WINDOWS/system32/eappgnui.dll 40394 ..c. r/rr-xr-xr-x 0 0 246-128-3 /WINDOWS/system32/perfc009.dat 26624 ..c. r/rr-xr-xr-x 0 0 2460-128-3 /WINDOWS/system32/efsadu.dll 183296 ..c. r/rr-xr-xr-x 0 0 2461-128-3 /WINDOWS/system32/els.dll 20480 ..c. r/rr-xr-xr-x 0 0 2462-128-3 /WINDOWS/system32/encapi.dll 186880 ..c. r/rr-xr-xr-x 0 0 2463-128-3 /WINDOWS/system32/encdec.dll 23040 ..c. r/rr-xr-xr-x 0 0 2464-128-3 /WINDOWS/system32/ersvc.dll 193024 ..c. r/rr-xr-xr-x 0 0 2465-128-3 /WINDOWS/system32/eudcedit.exe 7005 ..c. r/rr-xr-xr-x 0 0 2466-128-3 /WINDOWS/system32/eula.txt 50688 ..c. r/rr-xr-xr-x 0 0 2468-128-3 /WINDOWS/system32/eventcreate.exe 21504 ..c. r/rr-xr-xr-x 0 0 2469-128-3 /WINDOWS/system32/wbem/evntrprv.dll 312172 ..c. r/rr-xr-xr-x 0 0 247-128-3 /WINDOWS/system32/perfh009.dat 45056 ..c. r/rr-xr-xr-x 0 0 2470-128-3 /WINDOWS/system32/wbem/CmdEvTgProv.dll 2073 ..c. r/rr-xr-xr-x 0 0 2471-128-3 /WINDOWS/system32/wbem/CmdEvTgProv.mof 82944 ..c. r/rr-xr-xr-x 0 0 2472-128-3 /WINDOWS/system32/eventtriggers.exe 380445 ..c. r/rr-xr-xr-x 0 0 2473-128-3 /WINDOWS/system32/expsrv.dll 55808 ..c. r/rr-xr-xr-x 0 0 2474-128-3 /WINDOWS/system32/extmgr.dll 24064 ..c. r/rr-xr-xr-x 0 0 2475-128-3 /WINDOWS/system32/extrac32.exe 125952 ..c. r/rr-xr-xr-x 0 0 2476-128-3 /WINDOWS/system32/exts.dll 124928 ..c. r/rr-xr-xr-x 0 0 2477-128-3 /WINDOWS/system32/fde.dll 73728 ..c. r/rr-xr-xr-x 0 0 2478-128-3 /WINDOWS/system32/fdeploy.dll 21504 ..c. r/rr-xr-xr-x 0 0 2479-128-3 /WINDOWS/system32/feclient.dll 66560 ..c. r/rr-xr-xr-x 0 0 248-128-3 /WINDOWS/system32/console.dll 337920 ..c. r/rr-xr-xr-x 0 0 2482-128-3 /WINDOWS/system32/filemgmt.dll 80896 ..c. r/rr-xr-xr-x 0 0 2483-128-3 /WINDOWS/system32/firewall.cpl 87552 ..c. r/rr-xr-xr-x 0 0 2484-128-3 /WINDOWS/system32/fldrclnr.dll 382976 ..c. r/rr-xr-xr-x 0 0 2486-128-3 /WINDOWS/system32/fontext.dll 80896 ..c. r/rr-xr-xr-x 0 0 2487-128-3 /WINDOWS/system32/fontsub.dll 20992 ..c. r/rr-xr-xr-x 0 0 2488-128-3 /WINDOWS/system32/fontview.exe 7680 ..c. r/rr-xr-xr-x 0 0 2489-128-3 /WINDOWS/system32/forcedos.exe 29696 ..c. r/rr-xr-xr-x 0 0 2490-128-3 /WINDOWS/system32/format.com 32828 ..c. r/rr-xr-xr-x 0 0 2491-128-3 /WINDOWS/system32/Setup/fp40ext.dll 9344 ..c. r/rr-xr-xr-x 0 0 2493-128-3 /WINDOWS/system32/framebuf.dll 193024 ..c. r/rr-xr-xr-x 0 0 2494-128-3 /WINDOWS/system32/fsquirt.exe 42496 ..c. r/rr-xr-xr-x 0 0 2495-128-3 /WINDOWS/system32/ftp.exe 60416 ..c. r/rr-xr-xr-x 0 0 2496-128-3 /WINDOWS/system32/fwcfg.dll 132608 ..c. r/rr-xr-xr-x 0 0 2497-128-3 /WINDOWS/system32/Setup/fxsocm.dll 59904 ..c. r/rr-xr-xr-x 0 0 2499-128-3 /WINDOWS/system32/getmac.exe 122880 ..c. r/rr-xr-xr-x 0 0 2500-128-3 /WINDOWS/system32/glu32.dll 566784 ..c. r/rr-xr-xr-x 0 0 2501-128-3 /WINDOWS/system32/gpedit.dll 101888 ..c. r/rr-xr-xr-x 0 0 2502-128-3 /WINDOWS/system32/gpkcsp.dll 9728 ..c. r/rr-xr-xr-x 0 0 2503-128-3 /WINDOWS/system32/gpkrsrc.dll 120832 ..c. r/rr-xr-xr-x 0 0 2504-128-3 /WINDOWS/system32/gpresult.exe 199680 ..c. r/rr-xr-xr-x 0 0 2505-128-3 /WINDOWS/system32/gptext.dll 39424 ..c. r/rr-xr-xr-x 0 0 2506-128-3 /WINDOWS/system32/grpconv.exe 265728 ..c. r/rr-xr-xr-x 0 0 2507-128-3 /WINDOWS/system32/h323.tsp 614912 ..c. r/rr-xr-xr-x 0 0 2508-128-3 /WINDOWS/system32/h323msp.dll 155136 ..c. r/rr-xr-xr-x 0 0 2513-128-3 /WINDOWS/system32/hdwwiz.cpl 15872 ..c. r/rr-xr-xr-x 0 0 2514-128-3 /WINDOWS/system32/help.exe 10752 ..c. r/rr-xr-xr-x 0 0 2515-128-3 /WINDOWS/hh.exe 545280 ..c. r/rr-xr-xr-x 0 0 2516-128-3 /WINDOWS/system32/hhctrl.ocx 41472 ..c. r/rr-xr-xr-x 0 0 2517-128-3 /WINDOWS/system32/hhsetup.dll 20992 ..c. r/rr-xr-xr-x 0 0 2518-128-3 /WINDOWS/system32/hid.dll 29696 ..c. r/rr-xr-xr-x 0 0 2520-128-3 /WINDOWS/system32/hidphone.tsp 72704 ..c. r/rr-xr-xr-x 0 0 2522-128-3 /WINDOWS/system32/hlink.dll 330752 ..c. r/rr-xr-xr-x 0 0 2523-128-3 /WINDOWS/system32/hnetwiz.dll 329728 ..c. r/rr-xr-xr-x 0 0 2524-128-3 /WINDOWS/system32/netsetup.exe 929 ..c. r/rr-xr-xr-x 0 0 2525-128-3 /WINDOWS/system32/homepage.inf 144896 ..c. r/rr-xr-xr-x 0 0 2526-128-3 /WINDOWS/system32/hotplug.dll 369664 ..c. r/rr-xr-xr-x 0 0 2529-128-3 /WINDOWS/system32/html.iec 24576 ..c. r/rr-xr-xr-x 0 0 2531-128-3 /WINDOWS/system32/httpapi.dll 41984 ..c. r/rr-xr-xr-x 0 0 2532-128-3 /WINDOWS/system32/htui.dll 119808 ..c. r/rr-xr-xr-x 0 0 2533-128-3 /WINDOWS/system32/iasrad.dll 80384 ..c. r/rr-xr-xr-x 0 0 2534-128-3 /WINDOWS/system32/iccvid.dll 254976 ..c. r/rr-xr-xr-x 0 0 2535-128-3 /WINDOWS/system32/icm32.dll 120832 ..c. r/rr-xr-xr-x 0 0 2536-128-3 /WINDOWS/system32/idq.dll 143360 ..c. r/rr-xr-xr-x 0 0 2539-128-3 /WINDOWS/system32/ieakeng.dll 216576 ..c. r/rr-xr-xr-x 0 0 2540-128-3 /WINDOWS/system32/ieaksie.dll 81920 ..c. r/rr-xr-xr-x 0 0 2541-128-3 /WINDOWS/system32/ieencode.dll 251904 ..c. r/rr-xr-xr-x 0 0 2542-128-3 /WINDOWS/system32/iepeers.dll 48640 ..c. r/rr-xr-xr-x 0 0 2543-128-3 /WINDOWS/system32/iernonce.dll 62976 ..c. r/rr-xr-xr-x 0 0 2544-128-3 /WINDOWS/system32/iesetup.dll 114688 ..c. r/rr-xr-xr-x 0 0 2546-128-3 /WINDOWS/system32/iexpress.exe 135680 ..c. r/rr-xr-xr-x 0 0 2547-128-3 /WINDOWS/system32/ifmon.dll 8192 ..c. r/rr-xr-xr-x 0 0 2548-128-3 /WINDOWS/system32/igmpagnt.dll 505344 ..c. r/rr-xr-xr-x 0 0 2549-128-3 /WINDOWS/system32/Setup/iis.dll 16384 ..c. r/rr-xr-xr-x 0 0 2552-128-3 /WINDOWS/system32/imaadp32.acm 36921 ..c. r/rr-xr-xr-x 0 0 2553-128-3 /WINDOWS/system32/imeshare.dll 35840 ..c. r/rr-xr-xr-x 0 0 2554-128-3 /WINDOWS/system32/imgutil.dll 123392 ..c. r/rr-xr-xr-x 0 0 2556-128-3 /WINDOWS/system32/Setup/imsinsnt.dll 360960 ..c. r/rr-xr-xr-x 0 0 2557-128-3 /WINDOWS/system32/inetcpl.cpl 32768 ..c. r/rr-xr-xr-x 0 0 2558-128-3 /WINDOWS/system32/inetmib1.dll 15872 ..c. r/rr-xr-xr-x 0 0 2559-128-3 /WINDOWS/system32/inetppui.dll 123392 ..c. r/rr-xr-xr-x 0 0 2564-128-3 /WINDOWS/system32/input.dll 96256 ..c. r/rr-xr-xr-x 0 0 2568-128-3 /WINDOWS/system32/inseng.dll 956990 ..c. r/rr-xr-xr-x 0 0 2569-128-3 /WINDOWS/system32/instcat.sql 129536 ..c. r/rr-xr-xr-x 0 0 2571-128-3 /WINDOWS/system32/intl.cpl 17408 ..c. r/rr-xr-xr-x 0 0 2574-128-3 /WINDOWS/system32/ipconf.tsp 161280 ..c. r/rr-xr-xr-x 0 0 2576-128-3 /WINDOWS/system32/ipmontr.dll 331264 ..c. r/rr-xr-xr-x 0 0 2578-128-3 /WINDOWS/system32/ipnathlp.dll 10541 ..c. r/rr-xr-xr-x 0 0 2579-128-3 /WINDOWS/Web/printers/ipp_0001.asp 1970 ..c. r/rr-xr-xr-x 0 0 2580-128-3 /WINDOWS/Web/printers/ipp_0002.asp 9402 ..c. r/rr-xr-xr-x 0 0 2581-128-3 /WINDOWS/Web/printers/ipp_0004.asp 9025 ..c. r/rr-xr-xr-x 0 0 2582-128-3 /WINDOWS/Web/printers/ipp_0005.asp 5649 ..c. r/rr-xr-xr-x 0 0 2583-128-3 /WINDOWS/Web/printers/ipp_0006.asp 8939 ..c. r/rr-xr-xr-x 0 0 2584-128-3 /WINDOWS/Web/printers/ipp_0007.asp 7681 ..c. r/rr-xr-xr-x 0 0 2585-128-3 /WINDOWS/Web/printers/ipp_0010.asp 912 ..c. r/rr-xr-xr-x 0 0 2586-128-3 /WINDOWS/Web/printers/ipp_0013.asp 1812 ..c. r/rr-xr-xr-x 0 0 2587-128-3 /WINDOWS/Web/printers/ipp_0014.asp 14277 ..c. r/rr-xr-xr-x 0 0 2588-128-3 /WINDOWS/Web/printers/ipp_util.inc 330752 ..c. r/rr-xr-xr-x 0 0 2589-128-3 /WINDOWS/system32/ippromon.dll 177152 ..c. r/rr-xr-xr-x 0 0 2590-128-3 /WINDOWS/system32/iprtrmgr.dll 349696 ..c. r/rr-xr-xr-x 0 0 2591-128-3 /WINDOWS/system32/ipsecsnp.dll 384000 ..c. r/rr-xr-xr-x 0 0 2593-128-3 /WINDOWS/system32/ipsmsnap.dll 53248 ..c. r/rr-xr-xr-x 0 0 2595-128-3 /WINDOWS/system32/ipv6.exe 59904 ..c. r/rr-xr-xr-x 0 0 2596-128-3 /WINDOWS/system32/ipv6mon.dll 23552 ..c. r/rr-xr-xr-x 0 0 2597-128-3 /WINDOWS/system32/ipxroute.exe 22016 ..c. r/rr-xr-xr-x 0 0 2598-128-3 /WINDOWS/system32/ipxwan.dll 380416 ..c. r/rr-xr-xr-x 0 0 2600-128-3 /WINDOWS/system32/irprops.cpl 155136 ..c. r/rr-xr-xr-x 0 0 2601-128-3 /WINDOWS/system32/itircl.dll 138240 ..c. r/rr-xr-xr-x 0 0 2602-128-3 /WINDOWS/system32/itss.dll 191488 ..c. r/rr-xr-xr-x 0 0 2603-128-3 /WINDOWS/system32/iuengine.dll 54272 ..c. r/rr-xr-xr-x 0 0 2604-128-3 /WINDOWS/system32/ixsso.dll 163840 ..c. r/rr-xr-xr-x 0 0 2605-128-3 /WINDOWS/system32/jgdw400.dll 27648 ..c. r/rr-xr-xr-x 0 0 2606-128-3 /WINDOWS/system32/jgpl400.dll 68608 ..c. r/rr-xr-xr-x 0 0 2607-128-3 /WINDOWS/system32/joy.cpl 512000 ..c. r/rr-xr-xr-x 0 0 2608-128-3 /WINDOWS/system32/jscript.dll 12800 ..c. r/rr-xr-xr-x 0 0 2609-128-3 /WINDOWS/system32/scripting/jscript.dll.mui 15872 ..c. r/rr-xr-xr-x 0 0 2610-128-3 /WINDOWS/system32/jsproxy.dll 6144 ..c. r/rr-xr-xr-x 0 0 2611-128-3 /WINDOWS/system32/kbdbhc.dll 7168 ..c. r/rr-xr-xr-x 0 0 2612-128-3 /WINDOWS/system32/kbdfi1.dll 6144 ..c. r/rr-xr-xr-x 0 0 2613-128-3 /WINDOWS/system32/kbdiultn.dll 5632 ..c. r/rr-xr-xr-x 0 0 2614-128-3 /WINDOWS/system32/kbdmaori.dll 6144 ..c. r/rr-xr-xr-x 0 0 2615-128-3 /WINDOWS/system32/kbdmlt47.dll 6144 ..c. r/rr-xr-xr-x 0 0 2616-128-3 /WINDOWS/system32/kbdmlt48.dll 7168 ..c. r/rr-xr-xr-x 0 0 2617-128-3 /WINDOWS/system32/kbdnec.dll 7168 ..c. r/rr-xr-xr-x 0 0 2618-128-3 /WINDOWS/system32/kbdno1.dll 7680 ..c. r/rr-xr-xr-x 0 0 2619-128-3 /WINDOWS/system32/kbdsmsfi.dll 7680 ..c. r/rr-xr-xr-x 0 0 2620-128-3 /WINDOWS/system32/kbdsmsno.dll 7168 ..c. r/rr-xr-xr-x 0 0 2621-128-3 /WINDOWS/system32/kbdukx.dll 7424 ..c. r/rr-xr-xr-x 0 0 2622-128-3 /WINDOWS/system32/kd1394.dll 42537 ..c. r/rr-xr-xr-x 0 0 2624-128-3 /WINDOWS/system32/keyboard.sys 33280 ..c. r/rr-xr-xr-x 0 0 2625-128-3 /WINDOWS/system32/kmddsp.tsp 61440 ..c. r/rr-xr-xr-x 0 0 2626-128-3 /WINDOWS/system32/kmsvc.dll 8192 ..c. r/rr-xr-xr-x 0 0 2627-128-3 /WINDOWS/system32/Setup/koc.dll 37376 ..c. r/rr-xr-xr-x 0 0 2632-128-3 /WINDOWS/system32/l2gpstore.dll 22016 ..c. r/rr-xr-xr-x 0 0 2640-128-3 /WINDOWS/system32/licmgr10.dll 399872 ..c. r/rr-xr-xr-x 0 0 2641-128-3 /WINDOWS/system32/lmrt.dll 221696 ..c. r/rr-xr-xr-x 0 0 2642-128-3 /WINDOWS/system32/localsec.dll 11776 ..c. r/rr-xr-xr-x 0 0 2643-128-3 /WINDOWS/system32/localui.dll 75264 ..c. r/rr-xr-xr-x 0 0 2644-128-3 /WINDOWS/system32/locator.exe 487 ..c. r/rr-xr-xr-x 0 0 2645-128-1 /WINDOWS/system32/login.cmd 59392 ..c. r/rr-xr-xr-x 0 0 2646-128-3 /WINDOWS/system32/logman.exe 22016 ..c. r/rr-xr-xr-x 0 0 2647-128-3 /WINDOWS/system32/lpk.dll 10240 ..c. r/rr-xr-xr-x 0 0 2648-128-3 /WINDOWS/system32/lprhelp.dll 150528 ..c. r/rr-xr-xr-x 0 0 2653-128-3 /WINDOWS/system32/keymgr.dll 72704 ..c. r/rr-xr-xr-x 0 0 2656-128-3 /WINDOWS/system32/magnify.exe 57344 ..c. r/rr-xr-xr-x 0 0 2657-128-3 /WINDOWS/system32/makecab.exe 14336 ..c. r/rr-xr-xr-x 0 0 2658-128-3 /WINDOWS/system32/mcastmib.dll 84480 ..c. r/rr-xr-xr-x 0 0 2660-128-3 /WINDOWS/system32/mciavi32.dll 35328 ..c. r/rr-xr-xr-x 0 0 2661-128-3 /WINDOWS/system32/mciqtz32.dll 23040 ..c. r/rr-xr-xr-x 0 0 2662-128-3 /WINDOWS/system32/mciseq.dll 23552 ..c. r/rr-xr-xr-x 0 0 2663-128-3 /WINDOWS/system32/mciwave.dll 118272 ..c. r/rr-xr-xr-x 0 0 2668-128-3 /WINDOWS/system32/mdminst.dll 40960 ..c. r/rr-xr-xr-x 0 0 2675-128-3 /WINDOWS/system32/mf3216.dll 927504 ..c. r/rr-xr-xr-x 0 0 2676-128-3 /WINDOWS/system32/mfc40u.dll 1028096 ..c. r/rr-xr-xr-x 0 0 2677-128-3 /WINDOWS/system32/mfc42.dll 981760 ..c. r/rr-xr-xr-x 0 0 2678-128-3 /WINDOWS/system32/mfc42u.dll 22528 ..c. r/rr-xr-xr-x 0 0 2679-128-3 /WINDOWS/system32/mfcsubs.dll 14848 ..c. r/rr-xr-xr-x 0 0 2680-128-3 /WINDOWS/system32/mgmtapi.dll 18944 ..c. r/rr-xr-xr-x 0 0 2681-128-3 /WINDOWS/system32/midimap.dll 60928 ..c. r/rr-xr-xr-x 0 0 2682-128-3 /WINDOWS/system32/miglibnt.dll 29696 ..c. r/rr-xr-xr-x 0 0 2683-128-3 /WINDOWS/system32/mimefilt.dll 586240 ..c. r/rr-xr-xr-x 0 0 2685-128-3 /WINDOWS/system32/mlang.dll 1414656 ..c. r/rr-xr-xr-x 0 0 2686-128-3 /WINDOWS/system32/mmc.exe 184320 ..c. r/rr-xr-xr-x 0 0 2687-128-3 /WINDOWS/system32/microsoft.managementconsole.dll 397312 ..c. r/rr-xr-xr-x 0 0 2689-128-3 /WINDOWS/system32/mmcex.dll 106496 ..c. r/rr-xr-xr-x 0 0 2691-128-3 /WINDOWS/system32/mmcfxcommon.dll 33792 ..c. r/rr-xr-xr-x 0 0 2693-128-3 /WINDOWS/system32/mmcperf.exe 163328 ..c. r/rr-xr-xr-x 0 0 2694-128-3 /WINDOWS/system32/mmcbase.dll 1872896 ..c. r/rr-xr-xr-x 0 0 2696-128-3 /WINDOWS/system32/mmcndmgr.dll 61440 ..c. r/rr-xr-xr-x 0 0 2697-128-3 /WINDOWS/system32/mmcshext.dll 618496 ..c. r/rr-xr-xr-x 0 0 2699-128-3 /WINDOWS/system32/mmsys.cpl 68768 ..c. r/rr-xr-xr-x 0 0 2700-128-3 /WINDOWS/system32/mmsystem.dll 143360 ..c. r/rr-xr-xr-x 0 0 2701-128-3 /WINDOWS/system32/mobsync.exe 153600 ..c. r/rr-xr-xr-x 0 0 2703-128-3 /WINDOWS/system32/modemui.dll 118272 ..c. r/rr-xr-xr-x 0 0 2707-128-3 /WINDOWS/system32/mpeg2data.ax 148992 ..c. r/rr-xr-xr-x 0 0 2708-128-3 /WINDOWS/system32/mpg2splt.ax 53248 ..c. r/rr-xr-xr-x 0 0 2709-128-3 /WINDOWS/system32/mprdim.dll 138240 ..c. r/rr-xr-xr-x 0 0 2711-128-3 /WINDOWS/system32/mqad.dll 19968 ..c. r/rr-xr-xr-x 0 0 2712-128-3 /WINDOWS/system32/mqbkup.exe 47616 ..c. r/rr-xr-xr-x 0 0 2713-128-3 /WINDOWS/system32/mqdscli.dll 16896 ..c. r/rr-xr-xr-x 0 0 2714-128-3 /WINDOWS/system32/mqise.dll 89088 ..c. r/rr-xr-xr-x 0 0 2715-128-3 /WINDOWS/system32/mqlogmgr.dll 225280 ..c. r/rr-xr-xr-x 0 0 2716-128-3 /WINDOWS/system32/mqoa.dll 663040 ..c. r/rr-xr-xr-x 0 0 2717-128-3 /WINDOWS/system32/mqqm.dll 177152 ..c. r/rr-xr-xr-x 0 0 2718-128-3 /WINDOWS/system32/mqrt.dll 123904 ..c. r/rr-xr-xr-x 0 0 2719-128-3 /WINDOWS/system32/mqrtdep.dll 95744 ..c. r/rr-xr-xr-x 0 0 2720-128-3 /WINDOWS/system32/mqsec.dll 517632 ..c. r/rr-xr-xr-x 0 0 2721-128-3 /WINDOWS/system32/mqsnap.dll 4608 ..c. r/rr-xr-xr-x 0 0 2722-128-3 /WINDOWS/system32/mqsvc.exe 117248 ..c. r/rr-xr-xr-x 0 0 2723-128-3 /WINDOWS/system32/mqtgsvc.exe 187392 ..c. r/rr-xr-xr-x 0 0 2724-128-3 /WINDOWS/system32/mqtrig.dll 49152 ..c. r/rr-xr-xr-x 0 0 2725-128-3 /WINDOWS/system32/mqupgrd.dll 471552 ..c. r/rr-xr-xr-x 0 0 2726-128-3 /WINDOWS/system32/mqutil.dll 14848 ..c. r/rr-xr-xr-x 0 0 2727-128-3 /WINDOWS/system32/msadp32.acm 3584 ..c. r/rr-xr-xr-x 0 0 2728-128-3 /WINDOWS/system32/msafd.dll 86016 ..c. r/rr-xr-xr-x 0 0 2729-128-3 /WINDOWS/system32/msapsspc.dll 73728 ..c. r/rr-xr-xr-x 0 0 2732-128-3 /WINDOWS/system32/mscms.dll 12288 ..c. r/rr-xr-xr-x 0 0 2733-128-3 /WINDOWS/system32/mscpx32r.dLL 36864 ..c. r/rr-xr-xr-x 0 0 2734-128-3 /WINDOWS/system32/mscpxl32.dLL 118784 ..c. r/rr-xr-xr-x 0 0 2735-128-3 /WINDOWS/system32/msdadiag.dll 12288 ..c. r/rr-xr-xr-x 0 0 2736-128-3 /WINDOWS/system32/msdatsrc.tlb 14336 ..c. r/rr-xr-xr-x 0 0 2737-128-3 /WINDOWS/system32/msdmo.dll 29184 ..c. r/rr-xr-xr-x 0 0 2739-128-3 /WINDOWS/system32/mshta.exe 1351168 ..c. r/rr-xr-xr-x 0 0 2740-128-3 /WINDOWS/system32/mshtml.tlb 449024 ..c. r/rr-xr-xr-x 0 0 2741-128-3 /WINDOWS/system32/mshtmled.dll 56832 ..c. r/rr-xr-xr-x 0 0 2742-128-3 /WINDOWS/system32/mshtmler.dll 248832 ..c. r/rr-xr-xr-x 0 0 2743-128-3 /WINDOWS/system32/msieftp.dll 271360 ..c. r/rr-xr-xr-x 0 0 2744-128-3 /WINDOWS/system32/msihnd.dll 15360 ..c. r/rr-xr-xr-x 0 0 2747-128-3 /WINDOWS/system32/msisip.dll 1516568 ..c. r/rr-xr-xr-x 0 0 2748-128-3 /WINDOWS/system32/msjet40.dll 355112 ..c. r/rr-xr-xr-x 0 0 2749-128-3 /WINDOWS/system32/msjetoledb40.dll 151583 ..c. r/rr-xr-xr-x 0 0 2750-128-3 /WINDOWS/system32/msjint40.dll 60192 ..c. r/rr-xr-xr-x 0 0 2751-128-3 /WINDOWS/system32/msjter40.dll 248608 ..c. r/rr-xr-xr-x 0 0 2752-128-3 /WINDOWS/system32/msjtes40.dll 170496 ..c. r/rr-xr-xr-x 0 0 2755-128-3 /WINDOWS/system32/Setup/msmqocm.dll 290816 ..c. r/rr-xr-xr-x 0 0 2756-128-3 /WINDOWS/system32/msnsspc.dll 20480 ..c. r/rr-xr-xr-x 0 0 2758-128-3 /WINDOWS/system32/msorc32r.dll 143360 ..c. r/rr-xr-xr-x 0 0 2759-128-3 /WINDOWS/system32/msorcl32.dll 707 ..c. r/rr-xr-xr-x 0 0 276-128-1 /WINDOWS/_default.pif 29696 ..c. r/rr-xr-xr-x 0 0 2760-128-3 /WINDOWS/system32/mspatcha.dll 146432 ..c. r/rr-xr-xr-x 0 0 2763-128-3 /WINDOWS/system32/msrating.dll 322336 ..c. r/rr-xr-xr-x 0 0 2764-128-3 /WINDOWS/system32/msrd3x40.dll 11264 ..c. r/rr-xr-xr-x 0 0 2765-128-3 /WINDOWS/system32/msrle32.dll 134656 ..c. r/rr-xr-xr-x 0 0 2766-128-3 /WINDOWS/system32/mssap.dll 110592 ..c. r/rr-xr-xr-x 0 0 2767-128-3 /WINDOWS/system32/msscript.ocx 5632 ..c. r/rr-xr-xr-x 0 0 2768-128-3 /WINDOWS/system32/scripting/msscript.ocx.mui 155136 ..c. r/rr-xr-xr-x 0 0 2769-128-3 /WINDOWS/system32/mssha.dll 2151 ..c. r/rr-xr-xr-x 0 0 277-128-3 /WINDOWS/system32/12520437.cpx 76800 ..c. r/rr-xr-xr-x 0 0 2770-128-3 /WINDOWS/system32/msshavmsg.dll 532480 ..c. r/rr-xr-xr-x 0 0 2774-128-3 /WINDOWS/system32/mstime.dll 1384479 ..c. r/rr-xr-xr-x 0 0 2775-128-3 /WINDOWS/system32/msvbvm60.dll 57344 ..c. r/rr-xr-xr-x 0 0 2776-128-3 /WINDOWS/system32/msvcirt.dll 61440 ..c. r/rr-xr-xr-x 0 0 2777-128-3 /WINDOWS/system32/msvcrt40.dll 1428992 ..c. r/rr-xr-xr-x 0 0 2778-128-3 /WINDOWS/system32/msvidctl.dll 72704 ..c. r/rr-xr-xr-x 0 0 2779-128-3 /WINDOWS/system32/msw3prt.dll 2233 ..c. r/rr-xr-xr-x 0 0 278-128-3 /WINDOWS/system32/12520850.cpx 838432 ..c. r/rr-xr-xr-x 0 0 2780-128-3 /WINDOWS/system32/mswdat10.dll 203776 ..c. r/rr-xr-xr-x 0 0 2781-128-3 /WINDOWS/system32/mswebdvd.dll 621344 ..c. r/rr-xr-xr-x 0 0 2782-128-3 /WINDOWS/system32/mswstr10.dll 701440 ..c. r/rr-xr-xr-x 0 0 2783-128-3 /WINDOWS/system32/msxml2.dll 1104896 ..c. r/rr-xr-xr-x 0 0 2784-128-3 /WINDOWS/system32/msxml3.dll 1306624 ..c. r/rr-xr-xr-x 0 0 2785-128-3 /WINDOWS/system32/msxml6.dll 79872 ..c. r/rr-xr-xr-x 0 0 2786-128-3 /WINDOWS/system32/msxml6r.dll 16896 ..c. r/rr-xr-xr-x 0 0 2787-128-3 /WINDOWS/system32/msyuv.dll 66560 ..c. r/rr-xr-xr-x 0 0 2789-128-3 /WINDOWS/system32/mtxclu.dll 638 ..c. r/rr-xr-xr-x 0 0 2792-128-4 /WINDOWS/system32/wbem/napclientprov.mof 3990 ..c. r/rr-xr-xr-x 0 0 2793-128-3 /WINDOWS/system32/wbem/napclientschema.mof 30208 ..c. r/rr-xr-xr-x 0 0 2794-128-3 /WINDOWS/system32/napipsec.dll 193024 ..c. r/rr-xr-xr-x 0 0 2795-128-3 /WINDOWS/system32/napmontr.dll 176640 ..c. r/rr-xr-xr-x 0 0 2796-128-3 /WINDOWS/system32/napstat.exe 53760 ..c. r/rr-xr-xr-x 0 0 2797-128-3 /WINDOWS/system32/narrator.exe 4096 ..c. r/rr-xr-xr-x 0 0 2798-128-3 /WINDOWS/system32/nddeapir.exe 18944 ..c. r/rr-xr-xr-x 0 0 2799-128-3 /WINDOWS/system32/nddenb32.dll 56 .ac. d/dr-xr-xr-x 0 0 28-144-6 /WINDOWS 57344 ..c. r/rr-xr-xr-x 0 0 2800-128-3 /WINDOWS/system32/npp/ndisnpp.dll 56832 ..c. r/rr-xr-xr-x 0 0 2802-128-3 /WINDOWS/system32/ndptsp.tsp 622592 ..c. r/rr-xr-xr-x 0 0 2805-128-3 /WINDOWS/system32/netcfgx.dll 111104 ..c. r/rr-xr-xr-x 0 0 2806-128-3 /WINDOWS/system32/netdde.exe 126976 ..c. r/rr-xr-xr-x 0 0 2807-128-3 /WINDOWS/system32/Setup/netfxocm.dll 139264 ..c. r/rr-xr-xr-x 0 0 2810-128-3 /WINDOWS/system32/netid.dll 77312 ..c. r/rr-xr-xr-x 0 0 2814-128-3 /WINDOWS/system32/Setup/netoc.dll 875008 ..c. r/rr-xr-xr-x 0 0 2816-128-3 /WINDOWS/system32/netplwiz.dll 25600 ..c. r/rr-xr-xr-x 0 0 2819-128-3 /WINDOWS/system32/netsetup.cpl 25600 ..c. r/rr-xr-xr-x 0 0 282-128-3 /WINDOWS/system32/aaaamon.dll 86016 ..c. r/rr-xr-xr-x 0 0 2820-128-3 /WINDOWS/system32/netsh.exe 36864 ..c. r/rr-xr-xr-x 0 0 2821-128-3 /WINDOWS/system32/netstat.exe 247808 ..c. r/rr-xr-xr-x 0 0 2825-128-3 /WINDOWS/system32/newdev.dll 98304 ..c. r/rr-xr-xr-x 0 0 2828-128-3 /WINDOWS/system32/nlhtml.dll 15360 ..c. r/rr-xr-xr-x 0 0 2831-128-3 /WINDOWS/system32/npp/nppagent.exe 54784 ..c. r/rr-xr-xr-x 0 0 2832-128-3 /WINDOWS/system32/npptools.dll 76800 ..c. r/rr-xr-xr-x 0 0 2833-128-3 /WINDOWS/system32/nslookup.exe 1200640 ..c. r/rr-xr-xr-x 0 0 2834-128-3 /WINDOWS/system32/ntbackup.exe 90112 ..c. r/rr-xr-xr-x 0 0 2836-128-3 /WINDOWS/system32/Setup/msdtcstp.dll 33840 ..c. r/rr-xr-xr-x 0 0 2838-128-3 /WINDOWS/system32/ntio.sys 34560 ..c. r/rr-xr-xr-x 0 0 2839-128-3 /WINDOWS/system32/ntio404.sys 35648 ..c. r/rr-xr-xr-x 0 0 2840-128-3 /WINDOWS/system32/ntio411.sys 35424 ..c. r/rr-xr-xr-x 0 0 2841-128-3 /WINDOWS/system32/ntio412.sys 34560 ..c. r/rr-xr-xr-x 0 0 2842-128-3 /WINDOWS/system32/ntio804.sys 8192 ..c. r/rr-xr-xr-x 0 0 2843-128-3 /WINDOWS/system32/ntlsapi.dll 40960 ..c. r/rr-xr-xr-x 0 0 2844-128-3 /WINDOWS/system32/ntmsapi.dll 179200 ..c. r/rr-xr-xr-x 0 0 2845-128-3 /WINDOWS/system32/ntmsdba.dll 488448 ..c. r/rr-xr-xr-x 0 0 2846-128-3 /WINDOWS/system32/ntmsmgr.dll 435200 ..c. r/rr-xr-xr-x 0 0 2847-128-3 /WINDOWS/system32/ntmssvc.dll 62976 ..c. r/rr-xr-xr-x 0 0 2848-128-3 /WINDOWS/system32/Setup/ntoc.dll 91136 ..c. r/rr-xr-xr-x 0 0 2849-128-3 /WINDOWS/system32/ntprint.dll 15360 ..c. r/rr-xr-xr-x 0 0 2851-128-3 /WINDOWS/system32/ntvdmd.dll 257024 ..c. r/rr-xr-xr-x 0 0 2852-128-3 /WINDOWS/system32/nusrmgr.cpl 64000 ..c. r/rr-xr-xr-x 0 0 2854-128-3 /WINDOWS/system32/nwapi32.dll 142336 ..c. r/rr-xr-xr-x 0 0 2856-128-3 /WINDOWS/system32/nwprovau.dll 65536 ..c. r/rr-xr-xr-x 0 0 2858-128-3 /WINDOWS/system32/nwwks.dll 286208 ..c. r/rr-xr-xr-x 0 0 2859-128-3 /WINDOWS/system32/objsel.dll 96256 ..c. r/rr-xr-xr-x 0 0 2860-128-3 /WINDOWS/system32/occache.dll 15360 ..c. r/rr-xr-xr-x 0 0 2861-128-3 /WINDOWS/system32/Setup/ocgen.dll 67584 ..c. r/rr-xr-xr-x 0 0 2862-128-3 /WINDOWS/system32/ocmanage.dll 26224 ..c. r/rr-xr-xr-x 0 0 2863-128-3 /WINDOWS/system32/odbc16gt.dll 16384 ..c. r/rr-xr-xr-x 0 0 2864-128-3 /WINDOWS/system32/odbc32gt.dll 32768 ..c. r/rr-xr-xr-x 0 0 2865-128-3 /WINDOWS/system32/odbcad32.exe 24576 ..c. r/rr-xr-xr-x 0 0 2866-128-3 /WINDOWS/system32/odbcbcp.dll 69632 ..c. r/rr-xr-xr-x 0 0 2867-128-3 /WINDOWS/system32/odbcconf.exe 135168 ..c. r/rr-xr-xr-x 0 0 2868-128-3 /WINDOWS/system32/odbcconf.dll 4310 ..c. r/rr-xr-xr-x 0 0 2869-128-3 /WINDOWS/system32/odbcconf.rsp 129536 ..c. r/rr-xr-xr-x 0 0 287-128-3 /WINDOWS/system32/acledit.dll 32768 ..c. r/rr-xr-xr-x 0 0 2870-128-3 /WINDOWS/system32/odbccp32.cpl 106496 ..c. r/rr-xr-xr-x 0 0 2871-128-3 /WINDOWS/system32/odbccp32.dll 65536 ..c. r/rr-xr-xr-x 0 0 2872-128-3 /WINDOWS/system32/odbccr32.dll 65536 ..c. r/rr-xr-xr-x 0 0 2873-128-3 /WINDOWS/system32/odbccu32.dll 53279 ..c. r/rr-xr-xr-x 0 0 2874-128-3 /WINDOWS/system32/odbcji32.dll 278559 ..c. r/rr-xr-xr-x 0 0 2875-128-3 /WINDOWS/system32/odbcjt32.dll 12288 ..c. r/rr-xr-xr-x 0 0 2876-128-3 /WINDOWS/system32/odbcp32r.dll 147456 ..c. r/rr-xr-xr-x 0 0 2877-128-3 /WINDOWS/system32/odbctrac.dll 192000 ..c. r/rr-xr-xr-x 0 0 2879-128-3 /WINDOWS/system32/offfilt.dll 122880 ..c. r/rr-xr-xr-x 0 0 2880-128-3 /WINDOWS/system32/oledlg.dll 107008 ..c. r/rr-xr-xr-x 0 0 2881-128-3 /WINDOWS/system32/oleprn.dll 84992 ..c. r/rr-xr-xr-x 0 0 2882-128-3 /WINDOWS/system32/olepro32.dll 144384 ..c. r/rr-xr-xr-x 0 0 2883-128-3 /WINDOWS/system32/onex.dll 67584 ..c. r/rr-xr-xr-x 0 0 2885-128-3 /WINDOWS/system32/openfiles.exe 713728 ..c. r/rr-xr-xr-x 0 0 2886-128-3 /WINDOWS/system32/opengl32.dll 215552 ..c. r/rr-xr-xr-x 0 0 2887-128-3 /WINDOWS/system32/osk.exe 153600 ..c. r/rr-xr-xr-x 0 0 2888-128-3 /WINDOWS/system32/p2p.dll 105472 ..c. r/rr-xr-xr-x 0 0 2890-128-3 /WINDOWS/system32/p2pgasvc.dll 313856 ..c. r/rr-xr-xr-x 0 0 2891-128-3 /WINDOWS/system32/p2pgraph.dll 115712 ..c. r/rr-xr-xr-x 0 0 2892-128-3 /WINDOWS/system32/p2pnetsh.dll 554496 ..c. r/rr-xr-xr-x 0 0 2893-128-3 /WINDOWS/system32/p2psvc.dll 58368 ..c. r/rr-xr-xr-x 0 0 2894-128-3 /WINDOWS/system32/packager.exe 16889 ..c. r/rr-xr-xr-x 0 0 2895-128-3 /WINDOWS/Web/printers/page1.asp 56 .ac. d/dr-xr-xr-x 0 0 29-144-7 /WINDOWS/system32 111104 ..c. r/rr-xr-xr-x 0 0 290-128-3 /WINDOWS/system32/activeds.tlb 39936 ..c. r/rr-xr-xr-x 0 0 2901-128-3 /WINDOWS/system32/perfctrs.dll 26624 ..c. r/rr-xr-xr-x 0 0 2902-128-3 /WINDOWS/system32/perfdisk.dll 15872 ..c. r/rr-xr-xr-x 0 0 2903-128-3 /WINDOWS/system32/perfmon.exe 17920 ..c. r/rr-xr-xr-x 0 0 2904-128-3 /WINDOWS/system32/perfnet.dll 25088 ..c. r/rr-xr-xr-x 0 0 2905-128-3 /WINDOWS/system32/perfos.dll 34816 ..c. r/rr-xr-xr-x 0 0 2906-128-3 /WINDOWS/system32/perfproc.dll 412160 ..c. r/rr-xr-xr-x 0 0 2907-128-3 /WINDOWS/system32/photometadatahandler.dll 176128 ..c. r/rr-xr-xr-x 0 0 2908-128-3 /WINDOWS/system32/photowiz.dll 35328 ..c. r/rr-xr-xr-x 0 0 2909-128-3 /WINDOWS/system32/pid.dll 358 ..c. r/rr-xr-xr-x 0 0 2910-128-1 /WINDOWS/system32/pid.inf 24576 ..c. r/rr-xr-xr-x 0 0 2911-128-3 /WINDOWS/system32/pidgen.dll 17920 ..c. r/rr-xr-xr-x 0 0 2912-128-3 /WINDOWS/system32/ping.exe 39424 ..c. r/rr-xr-xr-x 0 0 2913-128-3 /WINDOWS/system32/pngfilt.dll 58880 ..c. r/rr-xr-xr-x 0 0 2915-128-3 /WINDOWS/system32/pnrpnsp.dll 105472 ..c. r/rr-xr-xr-x 0 0 2916-128-3 /WINDOWS/system32/polstore.dll 114688 ..c. r/rr-xr-xr-x 0 0 2917-128-3 /WINDOWS/system32/powercfg.cpl 49152 ..c. r/rr-xr-xr-x 0 0 2918-128-3 /WINDOWS/system32/powercfg.exe 109568 ..c. r/rr-xr-xr-x 0 0 2920-128-3 /WINDOWS/system32/progman.exe 50176 ..c. r/rr-xr-xr-x 0 0 2921-128-3 /WINDOWS/system32/proquota.exe 9216 ..c. r/rr-xr-xr-x 0 0 2922-128-3 /WINDOWS/system32/proxycfg.exe 150528 ..c. r/rr-xr-xr-x 0 0 2923-128-3 /WINDOWS/system32/qagent.dll 291328 ..c. r/rr-xr-xr-x 0 0 2924-128-3 /WINDOWS/system32/qagentrt.dll 237568 ..c. r/rr-xr-xr-x 0 0 2925-128-3 /WINDOWS/system32/qasf.dll 192512 ..c. r/rr-xr-xr-x 0 0 2926-128-3 /WINDOWS/system32/qcap.dll 62464 ..c. r/rr-xr-xr-x 0 0 2927-128-3 /WINDOWS/system32/qcliprov.dll 279040 ..c. r/rr-xr-xr-x 0 0 2928-128-3 /WINDOWS/system32/qdv.dll 386048 ..c. r/rr-xr-xr-x 0 0 2929-128-3 /WINDOWS/system32/qdvd.dll 562176 ..c. r/rr-xr-xr-x 0 0 2930-128-3 /WINDOWS/system32/qedit.dll 733696 ..c. r/rr-xr-xr-x 0 0 2931-128-3 /WINDOWS/system32/qedwipes.dll 1435648 ..c. r/rr-xr-xr-x 0 0 2933-128-3 /WINDOWS/system32/query.dll 76800 ..c. r/rr-xr-xr-x 0 0 2934-128-3 /WINDOWS/system32/qutil.dll 88576 ..c. r/rr-xr-xr-x 0 0 2936-128-3 /WINDOWS/system32/rasauto.dll 658432 ..c. r/rr-xr-xr-x 0 0 2937-128-3 /WINDOWS/system32/rasdlg.dll 186368 ..c. r/rr-xr-xr-x 0 0 2938-128-3 /WINDOWS/system32/rasmans.dll 56832 ..c. r/rr-xr-xr-x 0 0 2939-128-3 /WINDOWS/system32/rasphone.exe 210944 ..c. r/rr-xr-xr-x 0 0 2940-128-3 /WINDOWS/system32/rasppp.dll 61952 ..c. r/rr-xr-xr-x 0 0 2941-128-3 /WINDOWS/system32/rasqec.dll 16384 ..c. r/rr-xr-xr-x 0 0 2942-128-3 /WINDOWS/system32/rassapi.dll 58368 ..c. r/rr-xr-xr-x 0 0 2943-128-3 /WINDOWS/system32/rastapi.dll 102400 ..c. r/rr-xr-xr-x 0 0 2944-128-3 /WINDOWS/system32/rcbdyctl.dll 35840 ..c. r/rr-xr-xr-x 0 0 2945-128-3 /WINDOWS/system32/rcimlby.exe 21504 ..c. r/rr-xr-xr-x 0 0 2946-128-3 /WINDOWS/system32/rcp.exe 3338 ..c. r/rr-xr-xr-x 0 0 2948-128-3 /WINDOWS/system32/redir.exe 50176 ..c. r/rr-xr-xr-x 0 0 2949-128-3 /WINDOWS/system32/reg.exe 26112 ..c. r/rr-xr-xr-x 0 0 295-128-3 /WINDOWS/system32/adptif.dll 397824 ..c. r/rr-xr-xr-x 0 0 2951-128-3 /WINDOWS/system32/regwizc.dll 76800 ..c. r/rr-xr-xr-x 0 0 2953-128-3 /WINDOWS/system32/remotesp.tsp 58880 ..c. r/rr-xr-xr-x 0 0 2954-128-3 /WINDOWS/system32/resutils.dll 13824 ..c. r/rr-xr-xr-x 0 0 2955-128-3 /WINDOWS/system32/rexec.exe 539136 ..c. r/rr-xr-xr-x 0 0 2956-128-3 /WINDOWS/system32/msftedit.dll 161792 ..c. r/rr-xr-xr-x 0 0 296-128-3 /WINDOWS/system32/adsnds.dll 14848 ..c. r/rr-xr-xr-x 0 0 2961-128-3 /WINDOWS/system32/rsh.exe 39936 ..c. r/rr-xr-xr-x 0 0 2962-128-3 /WINDOWS/system32/rshx32.dll 18944 ..c. r/rr-xr-xr-x 0 0 2963-128-3 /WINDOWS/system32/rsmps.dll 107520 ..c. r/rr-xr-xr-x 0 0 2964-128-3 /WINDOWS/system32/rsnotify.exe 88644 ..c. r/rr-xr-xr-x 0 0 2966-128-3 /WINDOWS/system32/wbem/rsop.mof 92672 ..c. r/rr-xr-xr-x 0 0 2967-128-3 /WINDOWS/system32/rsvpsp.dll 77312 ..c. r/rr-xr-xr-x 0 0 2968-128-3 /WINDOWS/system32/rtcshare.exe 31744 ..c. r/rr-xr-xr-x 0 0 2969-128-3 /WINDOWS/system32/rtipxmib.dll 9029 ..c. r/rr-xr-xr-x 0 0 297-128-3 /WINDOWS/system32/ansi.sys 14336 ..c. r/rr-xr-xr-x 0 0 2970-128-3 /WINDOWS/system32/runonce.exe 13312 ..c. r/rr-xr-xr-x 0 0 2971-128-3 /WINDOWS/system32/savedump.exe 270848 ..c. r/rr-xr-xr-x 0 0 2972-128-3 /WINDOWS/system32/sbe.dll 159232 ..c. r/rr-xr-xr-x 0 0 2973-128-3 /WINDOWS/system32/sbeio.dll 69632 ..c. r/rr-xr-xr-x 0 0 2974-128-3 /WINDOWS/system32/scarddlg.dll 95744 ..c. r/rr-xr-xr-x 0 0 2975-128-3 /WINDOWS/system32/scardsvr.exe 169984 ..c. r/rr-xr-xr-x 0 0 2976-128-3 /WINDOWS/system32/sccbase.dll 171008 ..c. r/rr-xr-xr-x 0 0 2977-128-3 /WINDOWS/system32/sccsccp.dll 9216 ..c. r/rr-xr-xr-x 0 0 2979-128-3 /WINDOWS/system32/scrnsave.scr 180224 ..c. r/rr-xr-xr-x 0 0 2980-128-3 /WINDOWS/system32/scrobj.dll 9216 ..c. r/rr-xr-xr-x 0 0 2981-128-3 /WINDOWS/system32/scripting/scrobj.dll.mui 172032 ..c. r/rr-xr-xr-x 0 0 2982-128-3 /WINDOWS/system32/scrrun.dll 9728 ..c. r/rr-xr-xr-x 0 0 2983-128-3 /WINDOWS/system32/scripting/scrrun.dll.mui 121856 ..c. r/rr-xr-xr-x 0 0 2986-128-3 /WINDOWS/system32/schtasks.exe 77312 ..c. r/rr-xr-xr-x 0 0 2987-128-3 /WINDOWS/system32/sdbinst.exe 102912 ..c. r/rr-xr-xr-x 0 0 299-128-3 /WINDOWS/system32/apcups.dll 29184 ..c. r/rr-xr-xr-x 0 0 2990-128-3 /WINDOWS/system32/sdhcinst.dll 18944 ..c. r/rr-xr-xr-x 0 0 2992-128-3 /WINDOWS/system32/secedit.exe 4569 ..c. r/rr-xr-xr-x 0 0 2994-128-3 /WINDOWS/system32/secupd.dat 7208 ..c. r/rr-xr-xr-x 0 0 2995-128-3 /WINDOWS/system32/secupd.sig 5632 ..c. r/rr-xr-xr-x 0 0 2996-128-3 /WINDOWS/system32/security.dll 29184 ..c. r/rr-xr-xr-x 0 0 2997-128-3 /WINDOWS/system32/sendcmsg.dll 54784 ..c. r/rr-xr-xr-x 0 0 2999-128-3 /WINDOWS/system32/sendmail.dll 56 ..c. d/dr-xr-xr-x 0 0 30-144-5 /WINDOWS/system32/config 12498 ..c. r/rr-xr-xr-x 0 0 300-128-3 /WINDOWS/system32/append.exe 31232 ..c. r/rr-xr-xr-x 0 0 3000-128-3 /WINDOWS/system32/sethc.exe 23040 ..c. r/rr-xr-xr-x 0 0 3001-128-3 /WINDOWS/system32/setup.exe 32768 ..c. r/rr-xr-xr-x 0 0 3002-128-3 /WINDOWS/system32/setupn.exe 101376 ..c. r/rr-xr-xr-x 0 0 3003-128-3 /WINDOWS/system32/Setup/setupqry.dll 140288 ..c. r/rr-xr-xr-x 0 0 3005-128-3 /WINDOWS/system32/sfc_os.dll 549376 ..c. r/rr-xr-xr-x 0 0 3010-128-3 /WINDOWS/system32/shdoclc.dll 65024 ..c. r/rr-xr-xr-x 0 0 3012-128-3 /WINDOWS/system32/shimeng.dll 438272 ..c. r/rr-xr-xr-x 0 0 3013-128-3 /WINDOWS/system32/shimgvw.dll 45056 ..c. r/rr-xr-xr-x 0 0 3015-128-3 /WINDOWS/system32/shmgrate.exe 77824 ..c. r/rr-xr-xr-x 0 0 3016-128-3 /WINDOWS/system32/shrpubw.exe 27648 ..c. r/rr-xr-xr-x 0 0 3017-128-3 /WINDOWS/system32/shscrap.dll 19456 ..c. r/rr-xr-xr-x 0 0 3018-128-3 /WINDOWS/system32/shutdown.exe 13312 ..c. r/rr-xr-xr-x 0 0 3019-128-3 /WINDOWS/system32/sigtab.dll 70144 ..c. r/rr-xr-xr-x 0 0 3020-128-3 /WINDOWS/system32/sigverif.exe 16384 ..c. r/rr-xr-xr-x 0 0 3021-128-3 /WINDOWS/system32/simpdata.tlb 26112 ..c. r/rr-xr-xr-x 0 0 3022-128-3 /WINDOWS/system32/skeys.exe 306176 ..c. r/rr-xr-xr-x 0 0 3023-128-3 /WINDOWS/system32/slbcsp.dll 98304 ..c. r/rr-xr-xr-x 0 0 3024-128-3 /WINDOWS/system32/slbiop.dll 8192 ..c. r/rr-xr-xr-x 0 0 3025-128-3 /WINDOWS/system32/smbinst.exe 362496 ..c. r/rr-xr-xr-x 0 0 3028-128-3 /WINDOWS/system32/smlogcfg.dll 89600 ..c. r/rr-xr-xr-x 0 0 3029-128-3 /WINDOWS/system32/smlogsvc.exe 19456 ..c. r/rr-xr-xr-x 0 0 303-128-3 /WINDOWS/system32/arp.exe 18944 ..c. r/rr-xr-xr-x 0 0 3031-128-3 /WINDOWS/system32/snmpapi.dll 182272 ..c. r/rr-xr-xr-x 0 0 3032-128-3 /WINDOWS/system32/snmpsnap.dll 12800 ..c. r/rr-xr-xr-x 0 0 3037-128-3 /WINDOWS/system32/spiisupd.exe 32256 ..c. r/rr-xr-xr-x 0 0 304-128-3 /WINDOWS/system32/asr_ldm.exe 442368 ..c. r/rr-xr-xr-x 0 0 3042-128-3 /WINDOWS/system32/sqlsrv32.dll 90112 ..c. r/rr-xr-xr-x 0 0 3043-128-3 /WINDOWS/system32/sqlsrv32.rll 180800 ..c. r/rr-xr-xr-x 0 0 3044-128-3 /WINDOWS/system32/sqlunirl.dll 704512 ..c. r/rr-xr-xr-x 0 0 3046-128-3 /WINDOWS/system32/ss3dfo.scr 19968 ..c. r/rr-xr-xr-x 0 0 3047-128-3 /WINDOWS/system32/ssbezier.scr 34816 ..c. r/rr-xr-xr-x 0 0 3048-128-3 /WINDOWS/system32/ssdpapi.dll 71680 ..c. r/rr-xr-xr-x 0 0 3049-128-3 /WINDOWS/system32/ssdpsrv.dll 393216 ..c. r/rr-xr-xr-x 0 0 3050-128-3 /WINDOWS/system32/ssflwbox.scr 20992 ..c. r/rr-xr-xr-x 0 0 3051-128-3 /WINDOWS/system32/ssmarque.scr 18944 ..c. r/rr-xr-xr-x 0 0 3052-128-3 /WINDOWS/system32/ssmyst.scr 47104 ..c. r/rr-xr-xr-x 0 0 3053-128-3 /WINDOWS/system32/ssmypics.scr 610304 ..c. r/rr-xr-xr-x 0 0 3054-128-3 /WINDOWS/system32/sspipes.scr 14336 ..c. r/rr-xr-xr-x 0 0 3055-128-3 /WINDOWS/system32/ssstars.scr 679936 ..c. r/rr-xr-xr-x 0 0 3056-128-3 /WINDOWS/system32/sstext3d.scr 7168 ..c. r/rr-xr-xr-x 0 0 3058-128-3 /WINDOWS/system32/stdole32.tlb 68096 ..c. r/rr-xr-xr-x 0 0 3059-128-3 /WINDOWS/system32/sti.dll 136704 ..c. r/rr-xr-xr-x 0 0 3060-128-3 /WINDOWS/system32/sti_ci.dll 14848 ..c. r/rr-xr-xr-x 0 0 3061-128-3 /WINDOWS/system32/stimon.exe 75776 ..c. r/rr-xr-xr-x 0 0 3064-128-3 /WINDOWS/system32/strmfilt.dll 57856 ..c. r/rr-xr-xr-x 0 0 3066-128-3 /WINDOWS/system32/synceng.dll 191488 ..c. r/rr-xr-xr-x 0 0 3067-128-3 /WINDOWS/system32/syncui.dll 300544 ..c. r/rr-xr-xr-x 0 0 3069-128-3 /WINDOWS/system32/sysdm.cpl 13312 ..c. r/rr-xr-xr-x 0 0 307-128-3 /WINDOWS/system32/atkctrs.dll 71680 ..c. r/rr-xr-xr-x 0 0 3070-128-3 /WINDOWS/system32/systeminfo.exe 218624 ..c. r/rr-xr-xr-x 0 0 3071-128-3 /WINDOWS/system32/sysmon.ocx 106496 ..c. r/rr-xr-xr-x 0 0 3073-128-3 /WINDOWS/system32/sysocmgr.exe 117760 ..c. r/rr-xr-xr-x 0 0 3078-128-3 /WINDOWS/system32/t2embed.dll 858624 ..c. r/rr-xr-xr-x 0 0 3082-128-3 /WINDOWS/system32/tapi3.dll 249856 ..c. r/rr-xr-xr-x 0 0 3083-128-3 /WINDOWS/system32/tapisrv.dll 76288 ..c. r/rr-xr-xr-x 0 0 3084-128-3 /WINDOWS/system32/taskkill.exe 77824 ..c. r/rr-xr-xr-x 0 0 3085-128-3 /WINDOWS/system32/tasklist.exe 135680 ..c. r/rr-xr-xr-x 0 0 3086-128-3 /WINDOWS/system32/taskmgr.exe 14848 ..c. r/rr-xr-xr-x 0 0 3088-128-3 /WINDOWS/system32/tcpmib.dll 53478 ..c. r/rr-xr-xr-x 0 0 3089-128-3 /WINDOWS/system32/tcpmon.ini 34816 ..c. r/rr-xr-xr-x 0 0 309-128-3 /WINDOWS/system32/atmpvcno.dll 45568 ..c. r/rr-xr-xr-x 0 0 3090-128-3 /WINDOWS/system32/tcpmonui.dll 61440 ..c. r/rr-xr-xr-x 0 0 3091-128-3 /WINDOWS/system32/tdc.ocx 75776 ..c. r/rr-xr-xr-x 0 0 3093-128-3 /WINDOWS/system32/telnet.exe 862 ..c. r/rr-xr-xr-x 0 0 3094-128-3 /WINDOWS/system32/termcap 358400 ..c. r/rr-xr-xr-x 0 0 3095-128-3 /WINDOWS/system32/termmgr.dll 94208 ..c. r/rr-xr-xr-x 0 0 3096-128-3 /WINDOWS/system32/timedate.cpl 13469 ..c. r/rr-xr-xr-x 0 0 3097-128-3 /WINDOWS/Web/tip.htm 7168 ..c. r/rr-xr-xr-x 0 0 3098-128-3 /WINDOWS/system32/tlntsvrp.dll 78336 ..c. r/rr-xr-xr-x 0 0 3099-128-3 /WINDOWS/system32/tlntsess.exe 56 ..c. d/dr-xr-xr-x 0 0 31-144-6 /WINDOWS/system32/drivers 61440 ..c. r/rr-xr-xr-x 0 0 3100-128-3 /WINDOWS/system32/tlntadmn.exe 73216 ..c. r/rr-xr-xr-x 0 0 3101-128-3 /WINDOWS/system32/tlntsvr.exe 259584 ..c. r/rr-xr-xr-x 0 0 3102-128-3 /WINDOWS/system32/tracerpt.exe 12288 ..c. r/rr-xr-xr-x 0 0 3103-128-3 /WINDOWS/system32/tracert.exe 12800 ..c. r/rr-xr-xr-x 0 0 3104-128-3 /WINDOWS/system32/tree.com 15872 ..c. r/rr-xr-xr-x 0 0 3105-128-3 /WINDOWS/system32/w3ssl.dll 130048 ..c. r/rr-xr-xr-x 0 0 3108-128-3 /WINDOWS/system32/Setup/tsoc.dll 50688 ..c. r/rr-xr-xr-x 0 0 3111-128-3 /WINDOWS/twain_32.dll 57856 ..c. r/rr-xr-xr-x 0 0 3114-128-3 /WINDOWS/system32/twext.dll 101376 ..c. r/rr-xr-xr-x 0 0 3115-128-3 /WINDOWS/system32/txflog.dll 60416 ..c. r/rr-xr-xr-x 0 0 3116-128-3 /WINDOWS/system32/tzchange.exe 26624 ..c. r/rr-xr-xr-x 0 0 3118-128-3 /WINDOWS/system32/udhisapi.dll 35840 ..c. r/rr-xr-xr-x 0 0 3119-128-3 /WINDOWS/system32/umandlg.dll 67584 ..c. r/rr-xr-xr-x 0 0 3120-128-3 /WINDOWS/system32/osuninst.dll 206848 ..c. r/rr-xr-xr-x 0 0 3121-128-3 /WINDOWS/system32/unimdm.tsp 74240 ..c. r/rr-xr-xr-x 0 0 3122-128-3 /WINDOWS/system32/unimdmat.dll 13824 ..c. r/rr-xr-xr-x 0 0 3123-128-3 /WINDOWS/system32/uniplat.dll 316416 ..c. r/rr-xr-xr-x 0 0 3124-128-3 /WINDOWS/system32/untfs.dll 133632 ..c. r/rr-xr-xr-x 0 0 3126-128-3 /WINDOWS/system32/upnp.dll 16896 ..c. r/rr-xr-xr-x 0 0 3127-128-3 /WINDOWS/system32/upnpcont.exe 185856 ..c. r/rr-xr-xr-x 0 0 3128-128-3 /WINDOWS/system32/upnphost.dll 239616 ..c. r/rr-xr-xr-x 0 0 3129-128-3 /WINDOWS/system32/upnpui.dll 80384 ..c. r/rr-xr-xr-x 0 0 313-128-3 /WINDOWS/system32/autodisc.dll 18432 ..c. r/rr-xr-xr-x 0 0 3130-128-3 /WINDOWS/system32/ups.exe 406016 ..c. r/rr-xr-xr-x 0 0 3137-128-3 /WINDOWS/system32/usp10.dll 50176 ..c. r/rr-xr-xr-x 0 0 3138-128-3 /WINDOWS/system32/utilman.exe 30749 ..c. r/rr-xr-xr-x 0 0 3139-128-3 /WINDOWS/system32/vbajet32.dll 53248 ..c. r/rr-xr-xr-x 0 0 3140-128-3 /WINDOWS/system32/vbicodec.ax 30208 ..c. r/rr-xr-xr-x 0 0 3141-128-3 /WINDOWS/system32/vbisurf.ax 434176 ..c. r/rr-xr-xr-x 0 0 3142-128-3 /WINDOWS/system32/vbscript.dll 11264 ..c. r/rr-xr-xr-x 0 0 3143-128-3 /WINDOWS/system32/scripting/vbscript.dll.mui 26112 ..c. r/rr-xr-xr-x 0 0 3144-128-3 /WINDOWS/system32/vdmdbg.dll 51712 ..c. r/rr-xr-xr-x 0 0 3145-128-3 /WINDOWS/system32/vdmredir.dll 28672 ..c. r/rr-xr-xr-x 0 0 3146-128-3 /WINDOWS/system32/verclsid.exe 26624 ..c. r/rr-xr-xr-x 0 0 3147-128-3 /WINDOWS/system32/verifier.dll 289792 ..c. r/rr-xr-xr-x 0 0 3148-128-3 /WINDOWS/system32/vssvc.exe 215552 ..c. r/rr-xr-xr-x 0 0 3149-128-3 /WINDOWS/system32/wavemsp.dll 69584 ..c. r/rr-xr-xr-x 0 0 315-128-3 /WINDOWS/system32/avicap.dll 43008 ..c. r/rr-xr-xr-x 0 0 3151-128-3 /WINDOWS/system32/wbem/wbemperf.dll 135680 ..c. r/rr-xr-xr-x 0 0 3155-128-3 /WINDOWS/system32/webvw.dll 65024 ..c. r/rr-xr-xr-x 0 0 3156-128-3 /WINDOWS/system32/wextract.exe 433664 ..c. r/rr-xr-xr-x 0 0 3158-128-3 /WINDOWS/system32/wiaacmgr.exe 463360 ..c. r/rr-xr-xr-x 0 0 3159-128-3 /WINDOWS/system32/wiadefui.dll 64000 ..c. r/rr-xr-xr-x 0 0 316-128-3 /WINDOWS/system32/avicap32.dll 124416 ..c. r/rr-xr-xr-x 0 0 3160-128-3 /WINDOWS/system32/wiadss.dll 75776 ..c. r/rr-xr-xr-x 0 0 3161-128-3 /WINDOWS/system32/wiascr.dll 333824 ..c. r/rr-xr-xr-x 0 0 3162-128-3 /WINDOWS/system32/wiaservc.dll 589312 ..c. r/rr-xr-xr-x 0 0 3163-128-3 /WINDOWS/system32/wiashext.dll 111104 ..c. r/rr-xr-xr-x 0 0 3164-128-3 /WINDOWS/system32/wiavideo.dll 1647616 ..c. r/rr-xr-xr-x 0 0 3165-128-3 /WINDOWS/system32/winbrand.dll 712704 ..c. r/rr-xr-xr-x 0 0 3166-128-3 /WINDOWS/system32/windowscodecs.dll 346112 ..c. r/rr-xr-xr-x 0 0 3167-128-3 /WINDOWS/system32/windowscodecsext.dll 283648 ..c. r/rr-xr-xr-x 0 0 3168-128-3 /WINDOWS/winhlp32.exe 354304 ..c. r/rr-xr-xr-x 0 0 3169-128-3 /WINDOWS/system32/winhttp.dll 109456 ..c. r/rr-xr-xr-x 0 0 317-128-3 /WINDOWS/system32/avifile.dll 5120 ..c. r/rr-xr-xr-x 0 0 3170-128-3 /WINDOWS/system32/winnls.dll 756224 ..c. r/rr-xr-xr-x 0 0 3171-128-3 /WINDOWS/system32/winntbbu.dll 276992 ..c. r/rr-xr-xr-x 0 0 3172-128-3 /WINDOWS/system32/wmphoto.dll 32256 ..c. r/rr-xr-xr-x 0 0 3174-128-3 /WINDOWS/system32/wpabaln.exe 11264 ..c. r/rr-xr-xr-x 0 0 3175-128-3 /WINDOWS/system32/wpnpinst.exe 1229 ..c. r/rr-xr-xr-x 0 0 3176-128-3 /WINDOWS/system32/wbem/wscenter.mof 13824 ..c. r/rr-xr-xr-x 0 0 3177-128-3 /WINDOWS/system32/wscntfy.exe 155648 ..c. r/rr-xr-xr-x 0 0 3178-128-3 /WINDOWS/system32/wscript.exe 10240 ..c. r/rr-xr-xr-x 0 0 3179-128-3 /WINDOWS/system32/scripting/wscript.exe.mui 80896 ..c. r/rr-xr-xr-x 0 0 3180-128-3 /WINDOWS/system32/wscsvc.dll 148480 ..c. r/rr-xr-xr-x 0 0 3181-128-3 /WINDOWS/system32/wscui.cpl 604160 ..c. r/rr-xr-xr-x 0 0 3182-128-3 /WINDOWS/system32/wsecedit.dll 108032 ..c. r/rr-xr-xr-x 0 0 3183-128-3 /WINDOWS/system32/wshbth.dll 36864 ..c. r/rr-xr-xr-x 0 0 3184-128-3 /WINDOWS/system32/wshcon.dll 90112 ..c. r/rr-xr-xr-x 0 0 3185-128-3 /WINDOWS/system32/wshext.dll 5632 ..c. r/rr-xr-xr-x 0 0 3186-128-3 /WINDOWS/system32/scripting/wshext.dll.mui 14336 ..c. r/rr-xr-xr-x 0 0 3187-128-3 /WINDOWS/system32/wship6.dll 135168 ..c. r/rr-xr-xr-x 0 0 3188-128-3 /WINDOWS/system32/wshom.ocx 7168 ..c. r/rr-xr-xr-x 0 0 3189-128-3 /WINDOWS/system32/scripting/wshom.ocx.mui 28420 ..c. r/rr-xr-xr-x 0 0 319-128-3 /WINDOWS/system32/bios1.rom 11264 ..c. r/rr-xr-xr-x 0 0 3190-128-3 /WINDOWS/system32/WshRm.dll 41984 ..c. r/rr-xr-xr-x 0 0 3191-128-3 /WINDOWS/system32/wsnmp32.dll 50688 ..c. r/rr-xr-xr-x 0 0 3193-128-3 /WINDOWS/system32/wstdecod.dll 164352 ..c. r/rr-xr-xr-x 0 0 3194-128-3 /WINDOWS/system32/wstpager.ax 239616 ..c. r/rr-xr-xr-x 0 0 3195-128-3 /WINDOWS/system32/wstrenderer.ax 383488 ..c. r/rr-xr-xr-x 0 0 3196-128-3 /WINDOWS/system32/wzcdlg.dll 52736 ..c. r/rr-xr-xr-x 0 0 3197-128-3 /WINDOWS/system32/wzcsapi.dll 483840 ..c. r/rr-xr-xr-x 0 0 3198-128-3 /WINDOWS/system32/wzcsvc.dll 56 ..c. d/dr-xr-xr-x 0 0 32-144-5 /WINDOWS/system 8191 ..c. r/rr-xr-xr-x 0 0 320-128-3 /WINDOWS/system32/bios4.rom 91648 ..c. r/rr-xr-xr-x 0 0 3203-128-3 /WINDOWS/system32/xactsrv.dll 30720 ..c. r/rr-xr-xr-x 0 0 3204-128-3 /WINDOWS/system32/xcopy.exe 174200 ..c. r/rr-xr-xr-x 0 0 3205-128-3 /WINDOWS/system32/xenroll.dll 129024 ..c. r/rr-xr-xr-x 0 0 3224-128-3 /WINDOWS/system32/xmlprov.dll 50176 ..c. r/rr-xr-xr-x 0 0 3225-128-3 /WINDOWS/system32/xmlprovi.dll 4608 ..c. r/rr-xr-xr-x 0 0 325-128-3 /WINDOWS/system32/bootok.exe 338432 ..c. r/rr-xr-xr-x 0 0 3254-128-3 /WINDOWS/system32/zipfldr.dll 6144 ..c. r/rr-xr-xr-x 0 0 3257-128-3 /WINDOWS/system32/kbdinbe1.dll 6144 ..c. r/rr-xr-xr-x 0 0 3258-128-3 /WINDOWS/system32/kbdinben.dll 6656 ..c. r/rr-xr-xr-x 0 0 3259-128-3 /WINDOWS/system32/kbdinmal.dll 5120 ..c. r/rr-xr-xr-x 0 0 326-128-3 /WINDOWS/system32/bootvrfy.exe 6144 ..c. r/rr-xr-xr-x 0 0 3260-128-3 /WINDOWS/system32/kbdnepr.dll 6144 ..c. r/rr-xr-xr-x 0 0 3261-128-3 /WINDOWS/system32/kbdpash.dll 297984 ..c. r/rr-xr-xr-x 0 0 3263-128-3 /WINDOWS/system32/MSCTF.dll 68608 ..c. r/rr-xr-xr-x 0 0 3264-128-3 /WINDOWS/system32/MSCTFP.dll 195072 ..c. r/rr-xr-xr-x 0 0 3265-128-3 /WINDOWS/system32/msutb.dll 15360 ..c. r/rr-xr-xr-x 0 0 3268-128-3 /WINDOWS/system32/ctfmon.exe 159232 ..c. r/rr-xr-xr-x 0 0 3269-128-3 /WINDOWS/system32/MSIMTF.dll 25088 ..c. r/rr-xr-xr-x 0 0 3272-128-3 /WINDOWS/system32/mslbui.dll 177152 ..c. r/rr-xr-xr-x 0 0 3273-128-3 /WINDOWS/system32/MSCTFIME.IME 33792 ..c. r/rr-xr-xr-x 0 0 3274-128-3 /WINDOWS/system32/Setup/tabletoc.dll 16896 ..c. r/rr-xr-xr-x 0 0 3276-128-3 /WINDOWS/system32/Setup/medctroc.dll 187392 ..c. r/rr-xr-xr-x 0 0 3280-128-3 /WINDOWS/system32/xpsp1res.dll 197632 ..c. r/rr-xr-xr-x 0 0 3288-128-3 /WINDOWS/system32/mui/040C/xpsp1res.dll 181760 ..c. r/rr-xr-xr-x 0 0 3289-128-3 /WINDOWS/system32/mui/040D/xpsp1res.dll 195584 ..c. r/rr-xr-xr-x 0 0 3290-128-3 /WINDOWS/system32/mui/040e/xpsp1res.dll 195072 ..c. r/rr-xr-xr-x 0 0 3291-128-3 /WINDOWS/system32/mui/0410/xpsp1res.dll 171008 ..c. r/rr-xr-xr-x 0 0 3292-128-3 /WINDOWS/system32/mui/0411/xpsp1res.dll 167936 ..c. r/rr-xr-xr-x 0 0 3293-128-3 /WINDOWS/system32/mui/0412/xpsp1res.dll 196096 ..c. r/rr-xr-xr-x 0 0 3294-128-3 /WINDOWS/system32/mui/0413/xpsp1res.dll 189440 ..c. r/rr-xr-xr-x 0 0 3295-128-3 /WINDOWS/system32/mui/0414/xpsp1res.dll 194560 ..c. r/rr-xr-xr-x 0 0 3296-128-3 /WINDOWS/system32/mui/0415/xpsp1res.dll 192512 ..c. r/rr-xr-xr-x 0 0 3297-128-3 /WINDOWS/system32/mui/0416/xpsp1res.dll 192512 ..c. r/rr-xr-xr-x 0 0 3298-128-3 /WINDOWS/system32/mui/0419/xpsp1res.dll 188928 ..c. r/rr-xr-xr-x 0 0 3299-128-3 /WINDOWS/system32/mui/041D/xpsp1res.dll 664 .ac. d/dr-xr-xr-x 0 0 33-144-1 /WINDOWS/system32/ras 188928 ..c. r/rr-xr-xr-x 0 0 3300-128-3 /WINDOWS/system32/mui/041f/xpsp1res.dll 161280 ..c. r/rr-xr-xr-x 0 0 3301-128-3 /WINDOWS/system32/mui/0804/xpsp1res.dll 194560 ..c. r/rr-xr-xr-x 0 0 3302-128-3 /WINDOWS/system32/mui/0816/xpsp1res.dll 196096 ..c. r/rr-xr-xr-x 0 0 3303-128-3 /WINDOWS/system32/mui/0C0A/xpsp1res.dll 190464 ..c. r/rr-xr-xr-x 0 0 3305-128-3 /WINDOWS/system32/mui/0418/xpsp1res.dll 188928 ..c. r/rr-xr-xr-x 0 0 3306-128-3 /WINDOWS/system32/mui/041a/xpsp1res.dll 192512 ..c. r/rr-xr-xr-x 0 0 3307-128-3 /WINDOWS/system32/mui/041b/xpsp1res.dll 188416 ..c. r/rr-xr-xr-x 0 0 3308-128-3 /WINDOWS/system32/mui/041e/xpsp1res.dll 192512 ..c. r/rr-xr-xr-x 0 0 3309-128-3 /WINDOWS/system32/mui/0424/xpsp1res.dll 186880 ..c. r/rr-xr-xr-x 0 0 3310-128-3 /WINDOWS/system32/mui/0425/xpsp1res.dll 188928 ..c. r/rr-xr-xr-x 0 0 3311-128-3 /WINDOWS/system32/mui/0426/xpsp1res.dll 189952 ..c. r/rr-xr-xr-x 0 0 3312-128-3 /WINDOWS/system32/mui/0427/xpsp1res.dll 2897920 ..c. r/rr-xr-xr-x 0 0 3313-128-3 /WINDOWS/system32/xpsp2res.dll 793088 ..c. r/rr-xr-xr-x 0 0 3321-128-3 /WINDOWS/system32/mui/040C/xpsp2res.dll 2842112 ..c. r/rr-xr-xr-x 0 0 3322-128-3 /WINDOWS/system32/mui/040D/xpsp2res.dll 769536 ..c. r/rr-xr-xr-x 0 0 3323-128-3 /WINDOWS/system32/mui/040e/xpsp2res.dll 769536 ..c. r/rr-xr-xr-x 0 0 3324-128-3 /WINDOWS/system32/mui/0410/xpsp2res.dll 562688 ..c. r/rr-xr-xr-x 0 0 3325-128-3 /WINDOWS/system32/mui/0411/xpsp2res.dll 543744 ..c. r/rr-xr-xr-x 0 0 3326-128-3 /WINDOWS/system32/mui/0412/xpsp2res.dll 769024 ..c. r/rr-xr-xr-x 0 0 3327-128-3 /WINDOWS/system32/mui/0413/xpsp2res.dll 716288 ..c. r/rr-xr-xr-x 0 0 3328-128-3 /WINDOWS/system32/mui/0414/xpsp2res.dll 759808 ..c. r/rr-xr-xr-x 0 0 3329-128-3 /WINDOWS/system32/mui/0415/xpsp2res.dll 752128 ..c. r/rr-xr-xr-x 0 0 3330-128-3 /WINDOWS/system32/mui/0416/xpsp2res.dll 736768 ..c. r/rr-xr-xr-x 0 0 3331-128-3 /WINDOWS/system32/mui/0419/xpsp2res.dll 724480 ..c. r/rr-xr-xr-x 0 0 3332-128-3 /WINDOWS/system32/mui/041D/xpsp2res.dll 724480 ..c. r/rr-xr-xr-x 0 0 3333-128-3 /WINDOWS/system32/mui/041f/xpsp2res.dll 470016 ..c. r/rr-xr-xr-x 0 0 3334-128-3 /WINDOWS/system32/mui/0804/xpsp2res.dll 751616 ..c. r/rr-xr-xr-x 0 0 3335-128-3 /WINDOWS/system32/mui/0816/xpsp2res.dll 773632 ..c. r/rr-xr-xr-x 0 0 3336-128-3 /WINDOWS/system32/mui/0C0A/xpsp2res.dll 757248 ..c. r/rr-xr-xr-x 0 0 3337-128-3 /WINDOWS/system32/mui/041b/xpsp2res.dll 732160 ..c. r/rr-xr-xr-x 0 0 3338-128-3 /WINDOWS/system32/mui/0424/xpsp2res.dll 689152 ..c. r/rr-xr-xr-x 0 0 3339-128-3 /WINDOWS/system32/xpsp3res.dll 66082 ..c. r/rr-xr-xr-x 0 0 334-128-3 /WINDOWS/system32/c_037.nls 663040 ..c. r/rr-xr-xr-x 0 0 3347-128-3 /WINDOWS/system32/mui/040C/xpsp3res.dll 620544 ..c. r/rr-xr-xr-x 0 0 3348-128-3 /WINDOWS/system32/mui/040D/xpsp3res.dll 645120 ..c. r/rr-xr-xr-x 0 0 3349-128-3 /WINDOWS/system32/mui/040e/xpsp3res.dll 66082 ..c. r/rr-xr-xr-x 0 0 335-128-3 /WINDOWS/system32/c_10000.nls 658432 ..c. r/rr-xr-xr-x 0 0 3350-128-3 /WINDOWS/system32/mui/0410/xpsp3res.dll 412672 ..c. r/rr-xr-xr-x 0 0 3351-128-3 /WINDOWS/system32/mui/0411/xpsp3res.dll 392704 ..c. r/rr-xr-xr-x 0 0 3352-128-3 /WINDOWS/system32/mui/0412/xpsp3res.dll 645120 ..c. r/rr-xr-xr-x 0 0 3353-128-3 /WINDOWS/system32/mui/0413/xpsp3res.dll 591872 ..c. r/rr-xr-xr-x 0 0 3354-128-3 /WINDOWS/system32/mui/0414/xpsp3res.dll 641024 ..c. r/rr-xr-xr-x 0 0 3355-128-3 /WINDOWS/system32/mui/0415/xpsp3res.dll 620032 ..c. r/rr-xr-xr-x 0 0 3356-128-3 /WINDOWS/system32/mui/0416/xpsp3res.dll 627200 ..c. r/rr-xr-xr-x 0 0 3357-128-3 /WINDOWS/system32/mui/0419/xpsp3res.dll 590848 ..c. r/rr-xr-xr-x 0 0 3358-128-3 /WINDOWS/system32/mui/041D/xpsp3res.dll 592896 ..c. r/rr-xr-xr-x 0 0 3359-128-3 /WINDOWS/system32/mui/041f/xpsp3res.dll 66082 ..c. r/rr-xr-xr-x 0 0 336-128-3 /WINDOWS/system32/c_10079.nls 322560 ..c. r/rr-xr-xr-x 0 0 3360-128-3 /WINDOWS/system32/mui/0804/xpsp3res.dll 639488 ..c. r/rr-xr-xr-x 0 0 3361-128-3 /WINDOWS/system32/mui/0816/xpsp3res.dll 648704 ..c. r/rr-xr-xr-x 0 0 3362-128-3 /WINDOWS/system32/mui/0C0A/xpsp3res.dll 577536 ..c. r/rr-xr-xr-x 0 0 3363-128-3 /WINDOWS/system32/mui/041b/xpsp3res.dll 576512 ..c. r/rr-xr-xr-x 0 0 3364-128-3 /WINDOWS/system32/mui/0424/xpsp3res.dll 438784 ..c. r/rr-xr-xr-x 0 0 3365-128-3 /WINDOWS/system32/xpob2res.dll 66082 ..c. r/rr-xr-xr-x 0 0 337-128-3 /WINDOWS/system32/c_1026.nls 384000 ..c. r/rr-xr-xr-x 0 0 3374-128-3 /WINDOWS/system32/mui/040D/xpob2res.dll 434176 ..c. r/rr-xr-xr-x 0 0 3375-128-3 /WINDOWS/system32/mui/040e/xpob2res.dll 413696 ..c. r/rr-xr-xr-x 0 0 3376-128-3 /WINDOWS/system32/mui/0410/xpob2res.dll 275456 ..c. r/rr-xr-xr-x 0 0 3377-128-3 /WINDOWS/system32/mui/0411/xpob2res.dll 306688 ..c. r/rr-xr-xr-x 0 0 3378-128-3 /WINDOWS/system32/mui/0412/xpob2res.dll 401920 ..c. r/rr-xr-xr-x 0 0 3379-128-3 /WINDOWS/system32/mui/0413/xpob2res.dll 66082 ..c. r/rr-xr-xr-x 0 0 338-128-3 /WINDOWS/system32/c_1250.nls 353792 ..c. r/rr-xr-xr-x 0 0 3380-128-3 /WINDOWS/system32/mui/0414/xpob2res.dll 391680 ..c. r/rr-xr-xr-x 0 0 3381-128-3 /WINDOWS/system32/mui/0415/xpob2res.dll 409600 ..c. r/rr-xr-xr-x 0 0 3382-128-3 /WINDOWS/system32/mui/0416/xpob2res.dll 427008 ..c. r/rr-xr-xr-x 0 0 3383-128-3 /WINDOWS/system32/mui/0419/xpob2res.dll 363008 ..c. r/rr-xr-xr-x 0 0 3384-128-3 /WINDOWS/system32/mui/041D/xpob2res.dll 390144 ..c. r/rr-xr-xr-x 0 0 3385-128-3 /WINDOWS/system32/mui/041f/xpob2res.dll 270336 ..c. r/rr-xr-xr-x 0 0 3386-128-3 /WINDOWS/system32/mui/0804/xpob2res.dll 435200 ..c. r/rr-xr-xr-x 0 0 3387-128-3 /WINDOWS/system32/mui/0816/xpob2res.dll 446464 ..c. r/rr-xr-xr-x 0 0 3388-128-3 /WINDOWS/system32/mui/0C0A/xpob2res.dll 405504 ..c. r/rr-xr-xr-x 0 0 3389-128-3 /WINDOWS/system32/mui/041b/xpob2res.dll 66082 ..c. r/rr-xr-xr-x 0 0 339-128-3 /WINDOWS/system32/c_1251.nls 408576 ..c. r/rr-xr-xr-x 0 0 3390-128-3 /WINDOWS/system32/mui/0424/xpob2res.dll 2109440 ..c. r/rr-xr-xr-x 0 0 3393-128-3 /WINDOWS/system32/wmvcore.dll 230912 ..c. r/rr-xr-xr-x 0 0 3394-128-3 /WINDOWS/system32/wmasf.dll 20480 ..c. r/rr-xr-xr-x 0 0 3395-128-3 /WINDOWS/system32/wmpcore.dll 2940928 ..c. r/rr-xr-xr-x 0 0 3396-128-3 /WINDOWS/system32/wmploc.dll 102400 ..c. r/rr-xr-xr-x 0 0 3397-128-3 /WINDOWS/system32/wmpshell.dll 844314 ..c. r/rr-xr-xr-x 0 0 3399-128-3 /WINDOWS/system32/msdxm.ocx 352 .ac. d/dr-xr-xr-x 0 0 34-144-1 /WINDOWS/system32/spool 66082 ..c. r/rr-xr-xr-x 0 0 340-128-3 /WINDOWS/system32/c_1253.nls 498742 ..c. r/rr-xr-xr-x 0 0 3400-128-3 /WINDOWS/system32/dxmasf.dll 20480 ..c. r/rr-xr-xr-x 0 0 3401-128-3 /WINDOWS/system32/wmp.ocx 72387 ..c. r/rr-xr-xr-x 0 0 3403-128-3 /WINDOWS/system32/usmt/archvapp.inf 17920 ..c. r/rr-xr-xr-x 0 0 3408-128-3 /WINDOWS/system32/usmt/cobramsg.dll 66082 ..c. r/rr-xr-xr-x 0 0 341-128-3 /WINDOWS/system32/c_1254.nls 133120 ..c. r/rr-xr-xr-x 0 0 3411-128-3 /WINDOWS/system32/usmt/guitrn.dll 115200 ..c. r/rr-xr-xr-x 0 0 3412-128-3 /WINDOWS/system32/usmt/guitrna.dll 199680 ..c. r/rr-xr-xr-x 0 0 3415-128-3 /WINDOWS/system32/iac25_32.ax 2560 ..c. r/rr-xr-xr-x 0 0 3416-128-3 /WINDOWS/system32/usmt/iconlib.dll 848384 ..c. r/rr-xr-xr-x 0 0 3417-128-3 /WINDOWS/system32/ir41_32.ax 120320 ..c. r/rr-xr-xr-x 0 0 3418-128-3 /WINDOWS/system32/ir41_qc.dll 338432 ..c. r/rr-xr-xr-x 0 0 3419-128-3 /WINDOWS/system32/ir41_qcx.dll 66082 ..c. r/rr-xr-xr-x 0 0 342-128-3 /WINDOWS/system32/c_1255.nls 755200 ..c. r/rr-xr-xr-x 0 0 3420-128-3 /WINDOWS/system32/ir50_32.dll 200192 ..c. r/rr-xr-xr-x 0 0 3421-128-3 /WINDOWS/system32/ir50_qc.dll 183808 ..c. r/rr-xr-xr-x 0 0 3422-128-3 /WINDOWS/system32/ir50_qcx.dll 154624 ..c. r/rr-xr-xr-x 0 0 3423-128-3 /WINDOWS/system32/ivfsrc.ax 47616 ..c. r/rr-xr-xr-x 0 0 3424-128-3 /WINDOWS/system32/iyuv_32.dll 92224 ..c. r/rr-xr-xr-x 0 0 3425-128-3 /WINDOWS/system32/krnl386.exe 19968 ..c. r/rr-xr-xr-x 0 0 3426-128-3 /WINDOWS/system32/usmt/log.dll 66082 ..c. r/rr-xr-xr-x 0 0 343-128-3 /WINDOWS/system32/c_1256.nls 282296 ..c. r/rr-xr-xr-x 0 0 3432-128-3 /WINDOWS/system32/usmt/migapp.inf 2978 ..c. r/rr-xr-xr-x 0 0 3433-128-3 /WINDOWS/system32/usmt/migism.inf 274432 ..c. r/rr-xr-xr-x 0 0 3434-128-3 /WINDOWS/system32/usmt/migism.dll 261120 ..c. r/rr-xr-xr-x 0 0 3435-128-3 /WINDOWS/system32/usmt/migisma.dll 103936 ..c. r/rr-xr-xr-x 0 0 3436-128-3 /WINDOWS/system32/usmt/migload.exe 66509 ..c. r/rr-xr-xr-x 0 0 3437-128-3 /WINDOWS/system32/usmt/migsys.inf 4060 ..c. r/rr-xr-xr-x 0 0 3438-128-3 /WINDOWS/system32/usmt/miguser.inf 245248 ..c. r/rr-xr-xr-x 0 0 3439-128-3 /WINDOWS/system32/usmt/migwiz.exe 66082 ..c. r/rr-xr-xr-x 0 0 344-128-3 /WINDOWS/system32/c_1257.nls 241152 ..c. r/rr-xr-xr-x 0 0 3440-128-3 /WINDOWS/system32/usmt/migwiza.exe 4638 ..c. r/rr-xr-xr-x 0 0 3443-128-3 /WINDOWS/system32/usmt/migwiz.inf 1392 ..c. r/rr-xr-xr-x 0 0 3444-128-3 /WINDOWS/system32/usmt/migwiz.exe.manifest 518944 ..c. r/rr-xr-xr-x 0 0 3445-128-3 /WINDOWS/system32/msexch40.dll 326432 ..c. r/rr-xr-xr-x 0 0 3446-128-3 /WINDOWS/system32/msexcl40.dll 294912 ..c. r/rr-xr-xr-x 0 0 3447-128-3 /WINDOWS/system32/msh263.drv 219936 ..c. r/rr-xr-xr-x 0 0 3448-128-3 /WINDOWS/system32/msltus40.dll 66082 ..c. r/rr-xr-xr-x 0 0 345-128-3 /WINDOWS/system32/c_1258.nls 355104 ..c. r/rr-xr-xr-x 0 0 3450-128-3 /WINDOWS/system32/mspbde40.dll 432928 ..c. r/rr-xr-xr-x 0 0 3451-128-3 /WINDOWS/system32/msrd2x40.dll 559904 ..c. r/rr-xr-xr-x 0 0 3452-128-3 /WINDOWS/system32/msrepl40.dll 264992 ..c. r/rr-xr-xr-x 0 0 3453-128-3 /WINDOWS/system32/mstext40.dll 355104 ..c. r/rr-xr-xr-x 0 0 3454-128-3 /WINDOWS/system32/msxbde40.dll 139810 ..c. r/rr-xr-xr-x 0 0 346-128-3 /WINDOWS/system32/c_20261.nls 20511 ..c. r/rr-xr-xr-x 0 0 3466-128-3 /WINDOWS/system32/oddbse32.dll 20510 ..c. r/rr-xr-xr-x 0 0 3467-128-3 /WINDOWS/system32/odexl32.dll 20510 ..c. r/rr-xr-xr-x 0 0 3468-128-3 /WINDOWS/system32/odfox32.dll 20510 ..c. r/rr-xr-xr-x 0 0 3469-128-3 /WINDOWS/system32/odpdx32.dll 66082 ..c. r/rr-xr-xr-x 0 0 347-128-3 /WINDOWS/system32/c_20866.nls 20511 ..c. r/rr-xr-xr-x 0 0 3470-128-3 /WINDOWS/system32/odtext32.dll 81920 ..c. r/rr-xr-xr-x 0 0 3471-128-3 /WINDOWS/system32/proctexe.ocx 215552 ..c. r/rr-xr-xr-x 0 0 3473-128-3 /WINDOWS/system32/usmt/script.dll 199680 ..c. r/rr-xr-xr-x 0 0 3474-128-3 /WINDOWS/system32/usmt/scripta.dll 11264 ..c. r/rr-xr-xr-x 0 0 3475-128-3 /WINDOWS/system32/spnpinst.exe 825260 ..c. r/rr-xr-xr-x 0 0 3476-128-3 /WINDOWS/system32/usmt/sysfiles.inf 193024 ..c. r/rr-xr-xr-x 0 0 3477-128-3 /WINDOWS/system32/usmt/sysmod.dll 173568 ..c. r/rr-xr-xr-x 0 0 3478-128-3 /WINDOWS/system32/usmt/sysmoda.dll 347136 ..c. r/rr-xr-xr-x 0 0 3479-128-3 /WINDOWS/system32/tourstart.exe 66082 ..c. r/rr-xr-xr-x 0 0 348-128-3 /WINDOWS/system32/c_20905.nls 50688 ..c. r/rr-xr-xr-x 0 0 3480-128-3 /WINDOWS/system32/tspkg.dll 13962 ..c. r/rr-xr-xr-x 0 0 3482-128-3 /WINDOWS/system32/usmt/usmtdef.inf 66082 ..c. r/rr-xr-xr-x 0 0 349-128-3 /WINDOWS/system32/c_21866.nls 240 .ac. d/dr-xr-xr-x 0 0 35-144-1 /WINDOWS/system32/spool/drivers 66082 ..c. r/rr-xr-xr-x 0 0 350-128-3 /WINDOWS/system32/c_28591.nls 66082 ..c. r/rr-xr-xr-x 0 0 351-128-3 /WINDOWS/system32/c_28592.nls 69120 ..c. r/rr-xr-xr-x 0 0 3518-128-3 /WINDOWS/system32/wlanapi.dll 66082 ..c. r/rr-xr-xr-x 0 0 352-128-3 /WINDOWS/system32/c_28593.nls 121856 ..c. r/rr-xr-xr-x 0 0 3520-128-3 /WINDOWS/system32/xmllite.dll 66082 ..c. r/rr-xr-xr-x 0 0 353-128-3 /WINDOWS/system32/c_28598.nls 66082 ..c. r/rr-xr-xr-x 0 0 354-128-3 /WINDOWS/system32/c_28605.nls 66082 ..c. r/rr-xr-xr-x 0 0 355-128-3 /WINDOWS/system32/c_500.nls 17408 ..c. r/rr-xr-xr-x 0 0 3550-128-3 /WINDOWS/system32/Setup/ocmsn.dll 8192 ..c. r/rr-xr-xr-x 0 0 3552-128-3 /WINDOWS/system32/asferror.dll 286720 ..c. r/rr-xr-xr-x 0 0 3553-128-3 /WINDOWS/system32/blackbox.dll 159232 ..c. r/rr-xr-xr-x 0 0 3554-128-3 /WINDOWS/system32/cewmdm.dll 299520 ..c. r/rr-xr-xr-x 0 0 3555-128-3 /WINDOWS/system32/drmclien.dll 87040 ..c. r/rr-xr-xr-x 0 0 3556-128-3 /WINDOWS/system32/drmstor.dll 695808 ..c. r/rr-xr-xr-x 0 0 3557-128-3 /WINDOWS/system32/drmv2clt.dll 290816 ..c. r/rr-xr-xr-x 0 0 3558-128-3 /WINDOWS/system32/l3codeca.acm 6656 ..c. r/rr-xr-xr-x 0 0 3559-128-3 /WINDOWS/system32/laprxy.dll 66594 ..c. r/rr-xr-xr-x 0 0 356-128-3 /WINDOWS/system32/c_775.nls 103936 ..c. r/rr-xr-xr-x 0 0 3560-128-3 /WINDOWS/system32/logagent.exe 310272 ..c. r/rr-xr-xr-x 0 0 3561-128-3 /WINDOWS/system32/mp43dmod.dll 384512 ..c. r/rr-xr-xr-x 0 0 3562-128-3 /WINDOWS/system32/mp4sdmod.dll 240640 ..c. r/rr-xr-xr-x 0 0 3563-128-3 /WINDOWS/system32/mpg4dmod.dll 262144 ..c. r/rr-xr-xr-x 0 0 3564-128-3 /WINDOWS/system32/mpg4ds32.ax 221184 ..c. r/rr-xr-xr-x 0 0 3565-128-3 /WINDOWS/system32/msadds32.ax 294912 ..c. r/rr-xr-xr-x 0 0 3566-128-3 /WINDOWS/system32/msaud32.acm 4126 ..c. r/rr-xr-xr-x 0 0 3567-128-3 /WINDOWS/system32/msdxmlc.dll 259072 ..c. r/rr-xr-xr-x 0 0 3568-128-3 /WINDOWS/system32/msnetobj.dll 201728 ..c. r/rr-xr-xr-x 0 0 3569-128-3 /WINDOWS/system32/mspmsp.dll 66594 ..c. r/rr-xr-xr-x 0 0 357-128-3 /WINDOWS/system32/c_850.nls 52224 ..c. r/rr-xr-xr-x 0 0 3570-128-3 /WINDOWS/system32/mspmsnsv.dll 69632 ..c. r/rr-xr-xr-x 0 0 3571-128-3 /WINDOWS/system32/msscds32.ax 356352 ..c. r/rr-xr-xr-x 0 0 3572-128-3 /WINDOWS/system32/msscp.dll 245760 ..c. r/rr-xr-xr-x 0 0 3573-128-3 /WINDOWS/system32/mswmdm.dll 152064 ..c. r/rr-xr-xr-x 0 0 3576-128-3 /WINDOWS/system32/shmedia.dll 86016 ..c. r/rr-xr-xr-x 0 0 3578-128-3 /WINDOWS/system32/sl_anet.acm 246814 ..c. r/rr-xr-xr-x 0 0 3579-128-3 /WINDOWS/system32/strmdll.dll 66594 ..c. r/rr-xr-xr-x 0 0 358-128-3 /WINDOWS/system32/c_860.nls 408064 ..c. r/rr-xr-xr-x 0 0 3580-128-3 /WINDOWS/system32/wmadmod.dll 670720 ..c. r/rr-xr-xr-x 0 0 3581-128-3 /WINDOWS/system32/wmadmoe.dll 27136 ..c. r/rr-xr-xr-x 0 0 3583-128-3 /WINDOWS/system32/wmdmlog.dll 23552 ..c. r/rr-xr-xr-x 0 0 3584-128-3 /WINDOWS/system32/wmdmps.dll 168448 ..c. r/rr-xr-xr-x 0 0 3585-128-3 /WINDOWS/system32/wmerror.dll 151552 ..c. r/rr-xr-xr-x 0 0 3587-128-3 /WINDOWS/system32/wmidx.dll 1053184 ..c. r/rr-xr-xr-x 0 0 3588-128-3 /WINDOWS/system32/wmnetmgr.dll 66594 ..c. r/rr-xr-xr-x 0 0 359-128-3 /WINDOWS/system32/c_861.nls 20480 ..c. r/rr-xr-xr-x 0 0 3590-128-3 /WINDOWS/system32/wmpcd.dll 4874240 ..c. r/rr-xr-xr-x 0 0 3592-128-3 /WINDOWS/system32/wmp.dll 114688 ..c. r/rr-xr-xr-x 0 0 3593-128-3 /WINDOWS/system32/wmpasf.dll 233472 ..c. r/rr-xr-xr-x 0 0 3594-128-3 /WINDOWS/system32/wmpdxm.dll 20480 ..c. r/rr-xr-xr-x 0 0 3598-128-3 /WINDOWS/system32/wmpui.dll 759296 ..c. r/rr-xr-xr-x 0 0 3599-128-3 /WINDOWS/system32/wmsdmod.dll 136 .ac. d/dr-xr-xr-x 0 0 36-144-1 /WINDOWS/system32/spool/drivers/w32x86 66594 ..c. r/rr-xr-xr-x 0 0 360-128-3 /WINDOWS/system32/c_863.nls 115200 ..c. r/rr-xr-xr-x 0 0 3600-128-3 /WINDOWS/system32/wmsdmoe.dll 1119744 ..c. r/rr-xr-xr-x 0 0 3601-128-3 /WINDOWS/system32/wmsdmoe2.dll 485376 ..c. r/rr-xr-xr-x 0 0 3602-128-3 /WINDOWS/system32/wmspdmod.dll 897024 ..c. r/rr-xr-xr-x 0 0 3603-128-3 /WINDOWS/system32/wmspdmoe.dll 303616 ..c. r/rr-xr-xr-x 0 0 3604-128-3 /WINDOWS/system32/wmstream.dll 278559 ..c. r/rr-xr-xr-x 0 0 3605-128-3 /WINDOWS/system32/wmv8ds32.ax 809984 ..c. r/rr-xr-xr-x 0 0 3606-128-3 /WINDOWS/system32/wmvdmod.dll 1001472 ..c. r/rr-xr-xr-x 0 0 3607-128-3 /WINDOWS/system32/wmvdmoe2.dll 258048 ..c. r/rr-xr-xr-x 0 0 3608-128-3 /WINDOWS/system32/wmvds32.ax 15360 ..c. r/rr-xr-xr-x 0 0 3609-128-3 /WINDOWS/system32/Setup/msgrocm.dll 66594 ..c. r/rr-xr-xr-x 0 0 361-128-3 /WINDOWS/system32/c_865.nls 71680 ..c. r/rr-xr-xr-x 0 0 3612-128-3 /WINDOWS/system32/blastcln.exe 17408 ..c. r/rr-xr-xr-x 0 0 3613-128-3 /WINDOWS/system32/winshfhc.dll 2188928 ..c. r/rr-xr-xr-x 0 0 3615-128-3 /WINDOWS/system32/ntoskrnl.exe 2065792 ..c. r/rr-xr-xr-x 0 0 3616-128-3 /WINDOWS/system32/ntkrnlpa.exe 131840 ..c. r/rr-xr-xr-x 0 0 3617-128-3 /WINDOWS/system32/hal.dll 66594 ..c. r/rr-xr-xr-x 0 0 362-128-3 /WINDOWS/system32/c_874.nls 7168 ..c. r/rr-xr-xr-x 0 0 3628-128-3 /WINDOWS/system32/hccoin.dll 162850 ..c. r/rr-xr-xr-x 0 0 363-128-3 /WINDOWS/system32/c_932.nls 196642 ..c. r/rr-xr-xr-x 0 0 364-128-3 /WINDOWS/system32/c_936.nls 261 ..c. r/rr-xr-xr-x 0 0 3641-128-3 /WINDOWS/system32/$winnt$.inf 196642 ..c. r/rr-xr-xr-x 0 0 365-128-3 /WINDOWS/system32/c_949.nls 90296 ..c. r/rr-xr-xr-x 0 0 3651-128-3 /WINDOWS/system32/FNTCACHE.DAT 56 .ac. d/dr-xr-xr-x 0 0 3654-144-6 /Documents and Settings 812482 ..c. r/rr-xr-xr-x 0 0 3658-128-3 /WINDOWS/setuplog.txt 196642 ..c. r/rr-xr-xr-x 0 0 366-128-3 /WINDOWS/system32/c_950.nls 170957 ..c. r/rr-xr-xr-x 0 0 3661-128-3 /WINDOWS/setupact.log 0 ..c. r/rr-xr-xr-x 0 0 3662-128-1 /WINDOWS/setuperr.log 10680 ..c. r/rr-xr-xr-x 0 0 3667-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.2600.2000_x-ww_bcc9a281.cat 1237 ..c. r/rr-xr-xr-x 0 0 3668-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.2600.2000_x-ww_bcc9a281.Manifest 152 .ac. d/dr-xr-xr-x 0 0 3669-144-1 /WINDOWS/WinSxS/x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c 1724416 ..c. r/rr-xr-xr-x 0 0 3670-128-3 /WINDOWS/WinSxS/x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c/GdiPlus.dll 10680 ..c. r/rr-xr-xr-x 0 0 3671-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c.cat 397 ..c. r/rr-xr-xr-x 0 0 3672-128-1 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c.Manifest 56 .ac. d/dr-xr-xr-x 0 0 3673-144-5 /WINDOWS/WinSxS/Policies 56 .ac. d/dr-xr-xr-x 0 0 3674-144-6 /WINDOWS/WinSxS/Policies/x86_policy.1.0.Microsoft.Windows.GdiPlus_6595b64144ccf1df_x-ww_4e8510ac 10680 ..c. r/rr-xr-xr-x 0 0 3675-128-4 /WINDOWS/WinSxS/Policies/x86_policy.1.0.Microsoft.Windows.GdiPlus_6595b64144ccf1df_x-ww_4e8510ac/1.0.2600.5512.cat 605 ..c. r/rr-xr-xr-x 0 0 3676-128-4 /WINDOWS/WinSxS/Policies/x86_policy.1.0.Microsoft.Windows.GdiPlus_6595b64144ccf1df_x-ww_4e8510ac/1.0.2600.5512.Policy 152 .ac. d/dr-xr-xr-x 0 0 3677-144-1 /WINDOWS/WinSxS/x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.0.0_x-ww_8d353f13 1724416 ..c. r/r--x--x--x 0 0 3678-128-3 /WINDOWS/WinSxS/x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.0.0_x-ww_8d353f13/GdiPlus.dll 10512 ..c. r/r--x--x--x 0 0 3679-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.0.0_x-ww_8d353f13.cat 391 ..c. r/rr-xr-xr-x 0 0 3680-128-1 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.0.0_x-ww_8d353f13.Manifest 56 .ac. d/dr-xr-xr-x 0 0 3681-144-6 /WINDOWS/WinSxS/Policies/x86_policy.5.1.Microsoft.Windows.SystemCompatible_6595b64144ccf1df_x-ww_a0111510 10680 ..c. r/rr-xr-xr-x 0 0 3682-128-4 /WINDOWS/WinSxS/Policies/x86_policy.5.1.Microsoft.Windows.SystemCompatible_6595b64144ccf1df_x-ww_a0111510/5.1.2600.2000.cat 625 ..c. r/rr-xr-xr-x 0 0 3683-128-4 /WINDOWS/WinSxS/Policies/x86_policy.5.1.Microsoft.Windows.SystemCompatible_6595b64144ccf1df_x-ww_a0111510/5.1.2600.2000.Policy 7236 ..c. r/r--x--x--x 0 0 3684-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.0.0_x-ww_fc342b0b.cat 640 ..c. r/rr-xr-xr-x 0 0 3685-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.0.0_x-ww_fc342b0b.Manifest 152 .ac. d/dr-xr-xr-x 0 0 3686-144-1 /WINDOWS/WinSxS/x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7 853504 ..c. r/rr-xr-xr-x 0 0 3687-128-3 /WINDOWS/WinSxS/x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7/dxmrtp.dll 10678 ..c. r/rr-xr-xr-x 0 0 3688-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7.cat 1883 ..c. r/rr-xr-xr-x 0 0 3689-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7.Manifest 152 .ac. d/dr-xr-xr-x 0 0 3690-144-1 /WINDOWS/WinSxS/x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95 991232 ..c. r/rr-xr-xr-x 0 0 3691-128-3 /WINDOWS/WinSxS/x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95/rtcdll.dll 10678 ..c. r/rr-xr-xr-x 0 0 3692-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95.cat 1187 ..c. r/rr-xr-xr-x 0 0 3693-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95.Manifest 152 .ac. d/dr-xr-xr-x 0 0 3694-144-1 /WINDOWS/WinSxS/x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0 132096 ..c. r/rr-xr-xr-x 0 0 3695-128-3 /WINDOWS/WinSxS/x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0/rtcres.dll 10678 ..c. r/rr-xr-xr-x 0 0 3696-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0.cat 460 ..c. r/rr-xr-xr-x 0 0 3697-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0.Manifest 56 .ac. d/dr-xr-xr-x 0 0 3698-144-6 /WINDOWS/WinSxS/Policies/x86_policy.5.2.Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_x-ww_362e60dd 10678 ..c. r/rr-xr-xr-x 0 0 3699-128-4 /WINDOWS/WinSxS/Policies/x86_policy.5.2.Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_x-ww_362e60dd/5.2.2.3.cat 48 .ac. d/dr-xr-xr-x 0 0 37-144-1 /WINDOWS/system32/spool/drivers/w32x86/3 641 ..c. r/rr-xr-xr-x 0 0 3700-128-4 /WINDOWS/WinSxS/Policies/x86_policy.5.2.Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_x-ww_362e60dd/5.2.2.3.Policy 56 .ac. d/dr-xr-xr-x 0 0 3701-144-6 /WINDOWS/WinSxS/Policies/x86_policy.5.2.Microsoft.Windows.Networking.Rtcdll_6595b64144ccf1df_x-ww_c7b7206f 10678 ..c. r/rr-xr-xr-x 0 0 3702-128-4 /WINDOWS/WinSxS/Policies/x86_policy.5.2.Microsoft.Windows.Networking.Rtcdll_6595b64144ccf1df_x-ww_c7b7206f/5.2.2.3.cat 641 ..c. r/rr-xr-xr-x 0 0 3703-128-4 /WINDOWS/WinSxS/Policies/x86_policy.5.2.Microsoft.Windows.Networking.Rtcdll_6595b64144ccf1df_x-ww_c7b7206f/5.2.2.3.Policy 160 .ac. d/dr-xr-xr-x 0 0 3704-144-1 /WINDOWS/WinSxS/x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83 1054208 ..c. r/rr-xr-xr-x 0 0 3705-128-3 /WINDOWS/WinSxS/x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83/comctl32.dll 10682 ..c. r/rr-xr-xr-x 0 0 3706-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83.cat 1862 ..c. r/rr-xr-xr-x 0 0 3707-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83.Manifest 56 .ac. d/dr-xr-xr-x 0 0 3708-144-6 /WINDOWS/WinSxS/Policies/x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775 10678 ..c. r/rr-xr-xr-x 0 0 3709-128-4 /WINDOWS/WinSxS/Policies/x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775/6.0.2600.5512.cat 621 ..c. r/rr-xr-xr-x 0 0 3710-128-4 /WINDOWS/WinSxS/Policies/x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775/6.0.2600.5512.Policy 56 .ac. d/dr-xr-xr-x 0 0 3711-144-6 /WINDOWS/WinSxS/x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7 995384 ..c. r/r--x--x--x 0 0 3712-128-3 /WINDOWS/WinSxS/x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7/mfc42u.dll 995383 ..c. r/r--x--x--x 0 0 3713-128-3 /WINDOWS/WinSxS/x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7/mfc42.dll 74802 ..c. r/r--x--x--x 0 0 3714-128-3 /WINDOWS/WinSxS/x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7/atl.dll 401462 ..c. r/r--x--x--x 0 0 3715-128-3 /WINDOWS/WinSxS/x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7/msvcp60.dll 7232 ..c. r/r--x--x--x 0 0 3716-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7.cat 1819 ..c. r/rr-xr-xr-x 0 0 3717-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7.Manifest 160 .ac. d/dr-xr-xr-x 0 0 3718-144-1 /WINDOWS/WinSxS/x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a 921088 ..c. r/r--x--x--x 0 0 3719-128-3 /WINDOWS/WinSxS/x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a/comctl32.dll 359936 ..c. r/rr-xr-xr-x 0 0 372-128-3 /WINDOWS/system32/cards.dll 7238 ..c. r/r--x--x--x 0 0 3720-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.cat 1784 ..c. r/rr-xr-xr-x 0 0 3721-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a.Manifest 256 .ac. d/dr-xr-xr-x 0 0 3722-144-1 /WINDOWS/WinSxS/x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63 343040 ..c. r/rr-xr-xr-x 0 0 3723-128-3 /WINDOWS/WinSxS/x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63/msvcrt.dll 57344 ..c. r/rr-xr-xr-x 0 0 3724-128-3 /WINDOWS/WinSxS/x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63/msvcirt.dll 10682 ..c. r/rr-xr-xr-x 0 0 3725-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63.cat 500 ..c. r/rr-xr-xr-x 0 0 3726-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63.Manifest 56 .ac. d/dr-xr-xr-x 0 0 3727-144-6 /WINDOWS/WinSxS/Policies/x86_policy.7.0.Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_x-ww_a317e4b3 10682 ..c. r/rr-xr-xr-x 0 0 3728-128-4 /WINDOWS/WinSxS/Policies/x86_policy.7.0.Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_x-ww_a317e4b3/7.0.2600.5512.cat 623 ..c. r/rr-xr-xr-x 0 0 3729-128-4 /WINDOWS/WinSxS/Policies/x86_policy.7.0.Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_x-ww_a317e4b3/7.0.2600.5512.Policy 256 .ac. d/dr-xr-xr-x 0 0 3730-144-1 /WINDOWS/WinSxS/x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a 322560 ..c. r/r--x--x--x 0 0 3731-128-3 /WINDOWS/WinSxS/x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a/msvcrt.dll 50688 ..c. r/r--x--x--x 0 0 3732-128-3 /WINDOWS/WinSxS/x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a/msvcirt.dll 7238 ..c. r/r--x--x--x 0 0 3733-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a.cat 494 ..c. r/rr-xr-xr-x 0 0 3734-128-4 /WINDOWS/WinSxS/Manifests/x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a.Manifest 271475 ..c. r/rr-xr-xr-x 0 0 3735-128-3 /WINDOWS/setupapi.log 27648 ..c. r/rr-xr-xr-x 0 0 374-128-3 /WINDOWS/system32/ccfgnt.dll 576 ..c. d/dr-xr-xr-x 0 0 3751-144-1 /WINDOWS/system32/CatRoot 56 ..c. d/dr-xr-xr-x 0 0 3753-144-5 /WINDOWS/system32/CatRoot2 16535 ..c. r/r--x--x--x 0 0 3755-128-3 /WINDOWS/SET8.tmp 1296669 ..c. r/r--x--x--x 0 0 3766-128-3 /WINDOWS/SET3.tmp 1088840 ..c. r/r--x--x--x 0 0 3776-128-3 /WINDOWS/SET4.tmp 42339 ..c. r/rr-xr-xr-x 0 0 379-128-3 /WINDOWS/system32/certmgr.msc 144 .ac. d/dr-xr-xr-x 0 0 38-144-1 /WINDOWS/system32/spool/prtprocs 75 ..c. r/rr-xr-xr-x 0 0 383-128-1 /WINDOWS/system32/View Channels.scf 7680 ..c. r/rr-xr-xr-x 0 0 384-128-3 /WINDOWS/system32/chcp.com 48 .a.. d/dr-xr-xr-x 0 0 3842-144-1 /Documents and Settings/All Users/Desktop 11776 ..c. r/rr-xr-xr-x 0 0 385-128-3 /WINDOWS/system32/chkdsk.exe 11264 ..c. r/rr-xr-xr-x 0 0 386-128-3 /WINDOWS/system32/chkntfs.exe 163328 ..c. r/rr-xr-xr-x 0 0 389-128-3 /WINDOWS/system32/ciadmin.dll 48 .ac. d/dr-xr-xr-x 0 0 39-144-1 /WINDOWS/system32/spool/prtprocs/w32x86 69120 ..c. r/rr-xr-xr-x 0 0 3905-128-3 /WINDOWS/NOTEPAD.EXE 74752 ..c. r/rr-xr-xr-x 0 0 3906-128-3 /WINDOWS/system32/storprop.dll 8704 ..c. r/rr-xr-xr-x 0 0 3909-128-3 /WINDOWS/system32/batt.dll 41762 ..c. r/rr-xr-xr-x 0 0 391-128-3 /WINDOWS/system32/ciadv.msc 1688 ..c. r/rr-xr-xr-x 0 0 3911-128-3 /WINDOWS/system32/AUTOEXEC.NT 2577 ..c. r/rr-xr-xr-x 0 0 3912-128-3 /WINDOWS/system32/CONFIG.TMP 15360 ..c. r/rr-xr-xr-x 0 0 3913-128-3 /WINDOWS/TASKMAN.EXE 8192 ..c. r/rr-xr-xr-x 0 0 392-128-3 /WINDOWS/system32/cidaemon.exe 103424 ..c. r/rr-xr-xr-x 0 0 3935-128-3 /WINDOWS/system32/EqnClass.Dll 24661 ..c. r/rr-xr-xr-x 0 0 3936-128-3 /WINDOWS/system32/spxcoins.dll 85020 ..c. r/rr-xr-xr-x 0 0 3937-128-3 /WINDOWS/system32/dgsetup.dll 176157 ..c. r/rr-xr-xr-x 0 0 3938-128-3 /WINDOWS/system32/dgrpsetu.dll 13312 ..c. r/rr-xr-xr-x 0 0 3939-128-3 /WINDOWS/system32/irclass.dll 66082 ..c. r/rr-xr-xr-x 0 0 3941-128-3 /WINDOWS/system32/c_20127.nls 733 ..c. r/rr-xr-xr-x 0 0 395-128-3 /WINDOWS/system32/ras/cis.scp 1052 ..c. r/rr-xr-xr-x 0 0 3951-128-3 /WINDOWS/regopt.log 66594 ..c. r/rr-xr-xr-x 0 0 3952-128-3 /WINDOWS/system32/c_852.nls 66082 ..c. r/rr-xr-xr-x 0 0 3953-128-3 /WINDOWS/system32/c_10010.nls 66082 ..c. r/rr-xr-xr-x 0 0 3954-128-3 /WINDOWS/system32/c_10029.nls 66082 ..c. r/rr-xr-xr-x 0 0 3955-128-3 /WINDOWS/system32/c_10082.nls 6656 ..c. r/r--x--x--x 0 0 3956-128-3 /WINDOWS/system32/kbdycl.dll 6656 ..c. r/r--x--x--x 0 0 3957-128-3 /WINDOWS/system32/KBDAL.DLL 6656 ..c. r/r--x--x--x 0 0 3958-128-3 /WINDOWS/system32/kbdcr.dll 7168 ..c. r/r--x--x--x 0 0 3959-128-3 /WINDOWS/system32/kbdcz.dll 7680 ..c. r/rr-xr-xr-x 0 0 396-128-3 /WINDOWS/system32/ckcnv.exe 6656 ..c. r/r--x--x--x 0 0 3960-128-3 /WINDOWS/system32/kbdcz1.dll 6656 ..c. r/r--x--x--x 0 0 3961-128-3 /WINDOWS/system32/kbdcz2.dll 6656 ..c. r/r--x--x--x 0 0 3962-128-3 /WINDOWS/system32/kbdhu.dll 5632 ..c. r/r--x--x--x 0 0 3963-128-3 /WINDOWS/system32/kbdhu1.dll 5632 ..c. r/r--x--x--x 0 0 3964-128-3 /WINDOWS/system32/kbdpl1.dll 6656 ..c. r/r--x--x--x 0 0 3965-128-3 /WINDOWS/system32/kbdpl.dll 5632 ..c. r/r--x--x--x 0 0 3966-128-3 /WINDOWS/system32/kbdro.dll 6656 ..c. r/r--x--x--x 0 0 3967-128-3 /WINDOWS/system32/kbdsl.dll 6656 ..c. r/r--x--x--x 0 0 3968-128-3 /WINDOWS/system32/kbdsl1.dll 435712 ..c. r/rr-xr-xr-x 0 0 398-128-3 /WINDOWS/system32/shellstyle.dll 66594 ..c. r/rr-xr-xr-x 0 0 3988-128-3 /WINDOWS/system32/c_855.nls 66594 ..c. r/rr-xr-xr-x 0 0 3989-128-3 /WINDOWS/system32/c_866.nls 71859 ..c. r/rr-xr-xr-x 0 0 399-128-3 /WINDOWS/system32/cliconf.chm 66082 ..c. r/rr-xr-xr-x 0 0 3990-128-3 /WINDOWS/system32/C_28594.NLS 6144 ..c. r/r--x--x--x 0 0 3991-128-3 /WINDOWS/system32/kbdest.dll 6144 ..c. r/r--x--x--x 0 0 3992-128-3 /WINDOWS/system32/kbdlv.dll 6144 ..c. r/r--x--x--x 0 0 3993-128-3 /WINDOWS/system32/kbdlv1.dll 5632 ..c. r/r--x--x--x 0 0 3994-128-3 /WINDOWS/system32/kbdlt.dll 5632 ..c. r/r--x--x--x 0 0 3995-128-3 /WINDOWS/system32/kbdlt1.dll 48 .ac. d/dr-xr-xr-x 0 0 40-144-1 /WINDOWS/system32/wins 66594 ..c. r/rr-xr-xr-x 0 0 4011-128-3 /WINDOWS/system32/c_737.nls 66594 ..c. r/rr-xr-xr-x 0 0 4012-128-3 /WINDOWS/system32/c_869.nls 66082 ..c. r/rr-xr-xr-x 0 0 4013-128-3 /WINDOWS/system32/c_875.nls 66082 ..c. r/rr-xr-xr-x 0 0 4014-128-3 /WINDOWS/system32/c_10006.nls 66082 ..c. r/rr-xr-xr-x 0 0 4015-128-3 /WINDOWS/system32/C_28597.NLS 5632 ..c. r/r--x--x--x 0 0 4016-128-3 /WINDOWS/system32/kbdhe.dll 6144 ..c. r/r--x--x--x 0 0 4017-128-3 /WINDOWS/system32/kbdgkl.dll 5632 ..c. r/r--x--x--x 0 0 4018-128-3 /WINDOWS/system32/kbdhe220.dll 5632 ..c. r/r--x--x--x 0 0 4019-128-3 /WINDOWS/system32/kbdhe319.dll 6144 ..c. r/r--x--x--x 0 0 4020-128-3 /WINDOWS/system32/kbdhela2.dll 6656 ..c. r/r--x--x--x 0 0 4021-128-3 /WINDOWS/system32/kbdhela3.dll 8192 ..c. r/r--x--x--x 0 0 4022-128-3 /WINDOWS/system32/kbdhept.dll 40505 ..c. r/rr-xr-xr-x 0 0 403-128-3 /WINDOWS/system32/cmdlib.wsc 61172 ..c. r/rr-xr-xr-x 0 0 404-128-3 /WINDOWS/system32/cmmgr32.hlp 66082 ..c. r/rr-xr-xr-x 0 0 4047-128-3 /WINDOWS/system32/c_10007.nls 66082 ..c. r/rr-xr-xr-x 0 0 4048-128-3 /WINDOWS/system32/c_10017.nls 66082 ..c. r/rr-xr-xr-x 0 0 4049-128-3 /WINDOWS/system32/C_28595.NLS 64 ..c. r/rr-xr-xr-x 0 0 405-128-1 /WINDOWS/system32/cmos.ram 5632 ..c. r/r--x--x--x 0 0 4050-128-3 /WINDOWS/system32/kbdblr.dll 5632 ..c. r/r--x--x--x 0 0 4051-128-3 /WINDOWS/system32/kbdbu.dll 5632 ..c. r/r--x--x--x 0 0 4052-128-3 /WINDOWS/system32/kbdru.dll 5632 ..c. r/r--x--x--x 0 0 4053-128-3 /WINDOWS/system32/kbdru1.dll 5632 ..c. r/r--x--x--x 0 0 4054-128-3 /WINDOWS/system32/kbdycc.dll 5632 ..c. r/r--x--x--x 0 0 4055-128-3 /WINDOWS/system32/kbdur.dll 5632 ..c. r/r--x--x--x 0 0 4056-128-3 /WINDOWS/system32/kbdkaz.dll 5632 ..c. r/r--x--x--x 0 0 4057-128-3 /WINDOWS/system32/kbduzb.dll 5632 ..c. r/r--x--x--x 0 0 4058-128-3 /WINDOWS/system32/kbdaze.dll 5632 ..c. r/r--x--x--x 0 0 4059-128-3 /WINDOWS/system32/kbdtat.dll 14336 ..c. r/rr-xr-xr-x 0 0 406-128-3 /WINDOWS/system32/cmpbk32.dll 5632 ..c. r/r--x--x--x 0 0 4060-128-3 /WINDOWS/system32/kbdmon.dll 5632 ..c. r/r--x--x--x 0 0 4061-128-3 /WINDOWS/system32/kbdkyr.dll 32768 ..c. r/rr-xr-xr-x 0 0 408-128-3 /WINDOWS/system32/cnetcfg.dll 66082 ..c. r/rr-xr-xr-x 0 0 4084-128-3 /WINDOWS/system32/c_10081.nls 66594 ..c. r/rr-xr-xr-x 0 0 4085-128-3 /WINDOWS/system32/c_857.nls 66082 ..c. r/rr-xr-xr-x 0 0 4086-128-3 /WINDOWS/system32/c_28599.nls 6144 ..c. r/r--x--x--x 0 0 4087-128-3 /WINDOWS/system32/kbdtuf.dll 6144 ..c. r/r--x--x--x 0 0 4088-128-3 /WINDOWS/system32/kbdtuq.dll 5632 ..c. r/r--x--x--x 0 0 4089-128-3 /WINDOWS/system32/kbdazel.dll 26624 ..c. r/rr-xr-xr-x 0 0 409-128-3 /WINDOWS/system32/cnvfat.dll 48 ..c. d/dr-xr-xr-x 0 0 41-144-1 /WINDOWS/system32/dhcp 3584 ..c. r/rr-xr-xr-x 0 0 411-128-3 /WINDOWS/system32/comcat.dll 66082 ..c. r/rr-xr-xr-x 0 0 4115-128-3 /WINDOWS/system32/c_28603.nls 10544 ..c. r/rr-xr-xr-x 0 0 412-128-3 /WINDOWS/system32/comm.drv 56 ..c. d/d--x--x--x 0 0 4123-144-6 /Program Files 50620 ..c. r/rr-xr-xr-x 0 0 413-128-3 /WINDOWS/system32/command.com 32816 ..c. r/rr-xr-xr-x 0 0 414-128-3 /WINDOWS/system32/commdlg.dll 4161 ..c. r/rr-xr-xr-x 0 0 4146-128-3 /WINDOWS/ODBCINST.INI 356120 ..c. r/rr-xr-xr-x 0 0 4149-128-4 /WINDOWS/system32/PerfStringBackup.INI 14772 ..c. r/rr-xr-xr-x 0 0 4152-128-3 /WINDOWS/ocgen.log 11537 ..c. r/rr-xr-xr-x 0 0 4154-128-3 /WINDOWS/FaxSetup.log 49385 ..c. r/rr-xr-xr-x 0 0 4157-128-3 /WINDOWS/iis6.log 15905 ..c. r/rr-xr-xr-x 0 0 4159-128-3 /WINDOWS/comsetup.log 7916 ..c. r/rr-xr-xr-x 0 0 4161-128-4 /WINDOWS/ntdtcsetup.log 10802 ..c. r/rr-xr-xr-x 0 0 4164-128-3 /WINDOWS/tsoc.log 10186 ..c. r/rr-xr-xr-x 0 0 4166-128-3 /WINDOWS/msmqinst.log 4382 ..c. r/rr-xr-xr-x 0 0 4168-128-3 /WINDOWS/imsins.log 15872 ..c. r/rr-xr-xr-x 0 0 417-128-3 /WINDOWS/system32/comp.exe 871 ..c. r/rr-xr-xr-x 0 0 4171-128-3 /WINDOWS/msgsocm.log 17408 ..c. r/rr-xr-xr-x 0 0 418-128-3 /WINDOWS/system32/compact.exe 1252 ..c. r/rr-xr-xr-x 0 0 4186-128-3 /WINDOWS/tabletoc.log 1487 ..c. r/rr-xr-xr-x 0 0 4188-128-3 /WINDOWS/MedCtrOC.log 2790 ..c. r/rr-xr-xr-x 0 0 4190-128-3 /WINDOWS/netfxocm.log 885 ..c. r/rr-xr-xr-x 0 0 4192-128-3 /WINDOWS/ocmsn.log 56 ..c. d/dr-xr-xr-x 0 0 42-144-5 /WINDOWS/repair 38302 ..c. r/rr-xr-xr-x 0 0 420-128-3 /WINDOWS/system32/compmgmt.msc 0 ..c. r/rr-xr-xr-x 0 0 4206-128-1 /WINDOWS/system32/h323log.txt 30160 ..c. r/rr-xr-xr-x 0 0 422-128-3 /WINDOWS/system32/compobj.dll 8192 ..c. r/rr-xr-xr-x 0 0 424-128-3 /WINDOWS/system32/control.exe 13824 ..c. r/rr-xr-xr-x 0 0 425-128-3 /WINDOWS/system32/convert.exe 27097 ..c. r/rr-xr-xr-x 0 0 427-128-3 /WINDOWS/system32/country.sys 73728 ..c. r/rr-xr-xr-x 0 0 432-128-3 /WINDOWS/system32/csseqchk.dll 27200 ..c. r/rr-xr-xr-x 0 0 433-128-3 /WINDOWS/system32/ctl3dv2.dll 436224 ..c. r/rr-xr-xr-x 0 0 440-128-3 /WINDOWS/system32/d3dim.dll 34816 ..c. r/rr-xr-xr-x 0 0 441-128-3 /WINDOWS/system32/d3dpmesh.dll 350208 ..c. r/rr-xr-xr-x 0 0 442-128-3 /WINDOWS/system32/d3drm.dll 47616 ..c. r/rr-xr-xr-x 0 0 443-128-3 /WINDOWS/system32/d3dxof.dll 847872 ..c. r/rr-xr-xr-x 0 0 444-128-3 /WINDOWS/system32/dbgeng.dll 39424 ..c. r/rr-xr-xr-x 0 0 445-128-3 /WINDOWS/system32/ddeml.dll 20634 ..c. r/rr-xr-xr-x 0 0 448-128-3 /WINDOWS/system32/debug.exe 168 ..c. d/dr-xr-xr-x 0 0 45-144-6 /WINDOWS/inf 16384 ..c. r/rr-xr-xr-x 0 0 451-128-3 /WINDOWS/system32/deskadp.dll 16896 ..c. r/rr-xr-xr-x 0 0 452-128-3 /WINDOWS/system32/deskmon.dll 18432 ..c. r/rr-xr-xr-x 0 0 453-128-3 /WINDOWS/system32/deskperf.dll 33079 ..c. r/rr-xr-xr-x 0 0 455-128-3 /WINDOWS/system32/devmgmt.msc 56 ..c. d/dr-xr-xr-x 0 0 46-144-6 /WINDOWS/Help 41397 ..c. r/rr-xr-xr-x 0 0 460-128-3 /WINDOWS/system32/dfrg.msc 1540 ..c. r/rr-xr-xr-x 0 0 463-128-3 /WINDOWS/system32/wbem/dgnet.mof 74240 ..c. r/rr-xr-xr-x 0 0 464-128-3 /WINDOWS/system32/dhcpsapi.dll 394240 ..c. r/rr-xr-xr-x 0 0 465-128-3 /WINDOWS/system32/diactfrm.dll 44032 ..c. r/rr-xr-xr-x 0 0 474-128-3 /WINDOWS/system32/dimap.dll 9216 ..c. r/rr-xr-xr-x 0 0 476-128-3 /WINDOWS/system32/diskcomp.com 7168 ..c. r/rr-xr-xr-x 0 0 477-128-3 /WINDOWS/system32/diskcopy.com 48 ..c. d/dr-xr-xr-x 0 0 48-144-1 /WINDOWS/Config 33673 ..c. r/rr-xr-xr-x 0 0 480-128-3 /WINDOWS/system32/diskmgmt.msc 17920 ..c. r/rr-xr-xr-x 0 0 481-128-3 /WINDOWS/system32/diskperf.exe 0 ..c. r/rr-xr-xr-x 0 0 4825-128-1 /WINDOWS/Sti_Trace.log 74240 ..c. r/rr-xr-xr-x 0 0 4826-128-3 /WINDOWS/system32/usbui.dll 8192 ..c. r/rr-xr-xr-x 0 0 4829-128-3 /WINDOWS/system32/wshirda.dll 151552 ..c. r/rr-xr-xr-x 0 0 4830-128-3 /WINDOWS/system32/irftp.exe 28160 ..c. r/rr-xr-xr-x 0 0 4832-128-3 /WINDOWS/system32/irmon.dll 49 ..c. r/rr-xr-xr-x 0 0 4841-128-1 /WINDOWS/wiaservc.log 501 ..c. r/rr-xr-xr-x 0 0 4842-128-1 /WINDOWS/wiadebug.log 3120 ..c. r/rr-xr-xr-x 0 0 4844-128-3 /WINDOWS/system32/pid.PNF 48 .ac. d/dr-xr-xr-x 0 0 4851-144-1 /WINDOWS/system32/spool/PRINTERS 200 ..c. r/rr-xr-xr-x 0 0 4857-128-1 /WINDOWS/cmsetacl.log 4608 ..c. r/rr-xr-xr-x 0 0 486-128-3 /WINDOWS/system32/dllhst3g.exe 185344 ..c. r/rr-xr-xr-x 0 0 4861-128-3 /WINDOWS/system32/cmprops.dll 58880 ..c. r/rr-xr-xr-x 0 0 4864-128-3 /WINDOWS/system32/licwmi.dll 17408 ..c. r/rr-xr-xr-x 0 0 4865-128-3 /WINDOWS/system32/mmfutil.dll 56320 ..c. r/rr-xr-xr-x 0 0 4866-128-3 /WINDOWS/system32/servdeps.dll 1358848 ..c. r/rr-xr-xr-x 0 0 4867-128-3 /WINDOWS/system32/wbem/cimwin32.dll 2503 ..c. r/rr-xr-xr-x 0 0 4868-128-3 /WINDOWS/system32/wbem/csv.xsl 247808 ..c. r/rr-xr-xr-x 0 0 4869-128-3 /WINDOWS/system32/wbem/esscli.dll 330752 ..c. r/rr-xr-xr-x 0 0 487-128-3 /WINDOWS/system32/dmconfig.dll 472064 ..c. r/rr-xr-xr-x 0 0 4870-128-3 /WINDOWS/system32/wbem/fastprox.dll 185344 ..c. r/rr-xr-xr-x 0 0 4871-128-3 /WINDOWS/system32/wbem/framedyn.dll 4933 ..c. r/rr-xr-xr-x 0 0 4872-128-3 /WINDOWS/system32/wbem/hform.xsl 4598 ..c. r/rr-xr-xr-x 0 0 4873-128-3 /WINDOWS/system32/wbem/htable.xsl 24576 ..c. r/rr-xr-xr-x 0 0 4874-128-3 /WINDOWS/system32/wbem/krnlprov.dll 9261 ..c. r/rr-xr-xr-x 0 0 4875-128-3 /WINDOWS/system32/wbem/mof.xsl 16384 ..c. r/rr-xr-xr-x 0 0 4876-128-3 /WINDOWS/system32/wbem/mofcomp.exe 123904 ..c. r/rr-xr-xr-x 0 0 4877-128-3 /WINDOWS/system32/wbem/mofd.dll 47104 ..c. r/rr-xr-xr-x 0 0 4878-128-3 /WINDOWS/system32/wbem/ncprov.dll 212992 ..c. r/rr-xr-xr-x 0 0 4879-128-3 /WINDOWS/system32/wbem/ntevt.dll 118784 ..c. r/rr-xr-xr-x 0 0 488-128-3 /WINDOWS/system32/dmdskres.dll 92672 ..c. r/rr-xr-xr-x 0 0 4880-128-3 /WINDOWS/system32/wbem/policman.dll 237056 ..c. r/rr-xr-xr-x 0 0 4881-128-3 /WINDOWS/system32/wbem/provthrd.dll 623 ..c. r/rr-xr-xr-x 0 0 4882-128-1 /WINDOWS/system32/wbem/rawxml.xsl 178176 ..c. r/rr-xr-xr-x 0 0 4883-128-3 /WINDOWS/system32/wbem/repdrvfs.dll 36352 ..c. r/rr-xr-xr-x 0 0 4884-128-3 /WINDOWS/system32/wbem/scrcons.exe 86528 ..c. r/rr-xr-xr-x 0 0 4885-128-3 /WINDOWS/system32/wbem/stdprov.dll 6000 ..c. r/rr-xr-xr-x 0 0 4886-128-3 /WINDOWS/system32/wbem/texttable.xsl 2766 ..c. r/rr-xr-xr-x 0 0 4887-128-3 /WINDOWS/system32/wbem/textvaluelist.xsl 131584 ..c. r/rr-xr-xr-x 0 0 4888-128-3 /WINDOWS/system32/wbem/viewprov.dll 196608 ..c. r/rr-xr-xr-x 0 0 4889-128-3 /WINDOWS/system32/wbem/wbemcntl.dll 18432 ..c. r/rr-xr-xr-x 0 0 489-128-3 /WINDOWS/system32/dmintf.dll 214528 ..c. r/rr-xr-xr-x 0 0 4890-128-3 /WINDOWS/system32/wbem/wbemcomn.dll 71680 ..c. r/rr-xr-xr-x 0 0 4891-128-3 /WINDOWS/system32/wbem/wbemcons.dll 531456 ..c. r/rr-xr-xr-x 0 0 4892-128-3 /WINDOWS/system32/wbem/wbemcore.dll 178176 ..c. r/rr-xr-xr-x 0 0 4893-128-3 /WINDOWS/system32/wbem/wbemdisp.dll 273920 ..c. r/rr-xr-xr-x 0 0 4894-128-3 /WINDOWS/system32/wbem/wbemess.dll 18944 ..c. r/rr-xr-xr-x 0 0 4895-128-3 /WINDOWS/system32/wbem/wbemprox.dll 43520 ..c. r/rr-xr-xr-x 0 0 4896-128-3 /WINDOWS/system32/wbem/wbemsvc.dll 116224 ..c. r/rr-xr-xr-x 0 0 4897-128-3 /WINDOWS/system32/wbem/wbemtest.exe 197120 ..c. r/rr-xr-xr-x 0 0 4898-128-3 /WINDOWS/system32/wbem/wbemupgd.dll 196608 ..c. r/rr-xr-xr-x 0 0 4899-128-3 /WINDOWS/system32/wbem/wmiadap.exe 56 ..c. d/dr-xr-xr-x 0 0 49-144-5 /WINDOWS/msagent 19456 ..c. r/rr-xr-xr-x 0 0 490-128-3 /WINDOWS/system32/dmocx.dll 6656 ..c. r/rr-xr-xr-x 0 0 4900-128-3 /WINDOWS/system32/wbem/wmiapres.dll 88576 ..c. r/rr-xr-xr-x 0 0 4901-128-3 /WINDOWS/system32/wbem/wmiaprpl.dll 126464 ..c. r/rr-xr-xr-x 0 0 4902-128-3 /WINDOWS/system32/wbem/wmiapsrv.exe 358912 ..c. r/rr-xr-xr-x 0 0 4903-128-3 /WINDOWS/system32/wbem/wmic.exe 60928 ..c. r/rr-xr-xr-x 0 0 4904-128-3 /WINDOWS/system32/wbem/wmicookr.dll 140800 ..c. r/rr-xr-xr-x 0 0 4905-128-3 /WINDOWS/system32/wbem/wmidcprv.dll 156672 ..c. r/rr-xr-xr-x 0 0 4906-128-3 /WINDOWS/system32/wbem/wmipcima.dll 132096 ..c. r/rr-xr-xr-x 0 0 4907-128-3 /WINDOWS/system32/wbem/wmipdskq.dll 61952 ..c. r/rr-xr-xr-x 0 0 4908-128-3 /WINDOWS/system32/wbem/wmipiprt.dll 62464 ..c. r/rr-xr-xr-x 0 0 4909-128-3 /WINDOWS/system32/wbem/wmipjobj.dll 61440 ..c. r/rr-xr-xr-x 0 0 491-128-3 /WINDOWS/system32/dmview.ocx 144896 ..c. r/rr-xr-xr-x 0 0 4910-128-3 /WINDOWS/system32/wbem/wmiprov.dll 437248 ..c. r/rr-xr-xr-x 0 0 4911-128-3 /WINDOWS/system32/wbem/wmiprvsd.dll 218112 ..c. r/rr-xr-xr-x 0 0 4912-128-3 /WINDOWS/system32/wbem/wmiprvse.exe 41472 ..c. r/rr-xr-xr-x 0 0 4913-128-3 /WINDOWS/system32/wbem/wmipsess.dll 144896 ..c. r/rr-xr-xr-x 0 0 4914-128-3 /WINDOWS/system32/wbem/wmisvc.dll 95232 ..c. r/rr-xr-xr-x 0 0 4915-128-3 /WINDOWS/system32/wbem/wmiutils.dll 1743 ..c. r/rr-xr-xr-x 0 0 4916-128-3 /WINDOWS/system32/wbem/xml.xsl 2870 ..c. r/rr-xr-xr-x 0 0 4917-128-3 /WINDOWS/system32/wbem/xsl-mappings.xml 1961486 ..c. r/rr-xr-xr-x 0 0 4918-128-3 /WINDOWS/system32/wbem/cimwin32.mfl 2775842 ..c. r/rr-xr-xr-x 0 0 4919-128-3 /WINDOWS/system32/wbem/cimwin32.mof 29290 ..c. r/rr-xr-xr-x 0 0 4920-128-3 /WINDOWS/system32/wbem/cli.mof 32758 ..c. r/rr-xr-xr-x 0 0 4921-128-3 /WINDOWS/system32/wbem/cliegaliases.mfl 2570538 ..c. r/rr-xr-xr-x 0 0 4922-128-3 /WINDOWS/system32/wbem/cliegaliases.mof 9748 ..c. r/rr-xr-xr-x 0 0 4923-128-3 /WINDOWS/system32/wbem/licwmi.mfl 15586 ..c. r/rr-xr-xr-x 0 0 4924-128-3 /WINDOWS/system32/wbem/licwmi.mof 10688 ..c. r/rr-xr-xr-x 0 0 4925-128-3 /WINDOWS/system32/wbem/wmi.mof 498688 ..c. r/rr-xr-xr-x 0 0 4926-128-3 /WINDOWS/system32/clbcatq.dll 167424 ..c. r/rr-xr-xr-x 0 0 4927-128-3 /WINDOWS/system32/comsnap.dll 539648 ..c. r/rr-xr-xr-x 0 0 4928-128-3 /WINDOWS/system32/comuid.dll 1267200 ..c. r/rr-xr-xr-x 0 0 4929-128-3 /WINDOWS/system32/comsvcs.dll 46080 ..c. r/rr-xr-xr-x 0 0 493-128-3 /WINDOWS/system32/docprop.dll 226304 ..c. r/rr-xr-xr-x 0 0 4930-128-3 /WINDOWS/system32/catsrv.dll 625664 ..c. r/rr-xr-xr-x 0 0 4931-128-3 /WINDOWS/system32/catsrvut.dll 110592 ..c. r/rr-xr-xr-x 0 0 4932-128-3 /WINDOWS/system32/clbcatex.dll 85504 ..c. r/rr-xr-xr-x 0 0 4933-128-3 /WINDOWS/system32/catsrvps.dll 59392 ..c. r/rr-xr-xr-x 0 0 4934-128-3 /WINDOWS/system32/stclient.dll 97792 ..c. r/rr-xr-xr-x 0 0 4935-128-3 /WINDOWS/system32/comrepl.dll 28160 ..c. r/rr-xr-xr-x 0 0 4936-128-3 /WINDOWS/system32/comaddin.dll 60416 ..c. r/rr-xr-xr-x 0 0 4937-128-3 /WINDOWS/system32/colbact.dll 56 ..c. d/dr-xr-xr-x 0 0 4938-144-5 /WINDOWS/system32/Com 10752 ..c. r/rr-xr-xr-x 0 0 494-128-3 /WINDOWS/system32/doskey.exe 30720 ..c. r/rr-xr-xr-x 0 0 4940-128-3 /WINDOWS/system32/mtxdm.dll 4096 ..c. r/rr-xr-xr-x 0 0 4941-128-3 /WINDOWS/system32/mtxex.dll 34304 ..c. r/rr-xr-xr-x 0 0 4942-128-3 /WINDOWS/system32/mtxlegih.dll 6144 ..c. r/rr-xr-xr-x 0 0 4943-128-3 /WINDOWS/system32/dcomcnfg.exe 6144 ..c. r/rr-xr-xr-x 0 0 4948-128-3 /WINDOWS/system32/msdtc.exe 58880 ..c. r/rr-xr-xr-x 0 0 4949-128-3 /WINDOWS/system32/msdtclog.dll 11776 ..c. r/rr-xr-xr-x 0 0 4950-128-3 /WINDOWS/system32/xolehlp.dll 956928 ..c. r/rr-xr-xr-x 0 0 4951-128-3 /WINDOWS/system32/msdtctm.dll 427008 ..c. r/rr-xr-xr-x 0 0 4952-128-3 /WINDOWS/system32/msdtcprx.dll 91648 ..c. r/rr-xr-xr-x 0 0 4953-128-3 /WINDOWS/system32/mtxoci.dll 161792 ..c. r/rr-xr-xr-x 0 0 4954-128-3 /WINDOWS/system32/msdtcuiu.dll 248 ..c. d/dr-xr-xr-x 0 0 4955-144-1 /WINDOWS/system32/MsDtc 38912 ..c. r/rr-xr-xr-x 0 0 4958-128-3 /WINDOWS/system32/cfgbkend.dll 11264 ..c. r/rr-xr-xr-x 0 0 4959-128-3 /WINDOWS/system32/icaapi.dll 19968 ..c. r/rr-xr-xr-x 0 0 4960-128-3 /WINDOWS/system32/qprocess.exe 62976 ..c. r/rr-xr-xr-x 0 0 4961-128-3 /WINDOWS/system32/rdpclip.exe 19968 ..c. r/rr-xr-xr-x 0 0 4962-128-3 /WINDOWS/system32/rdpsnd.dll 87176 ..c. r/rr-xr-xr-x 0 0 4963-128-3 /WINDOWS/system32/rdpwsx.dll 295424 ..c. r/rr-xr-xr-x 0 0 4964-128-3 /WINDOWS/system32/termsrv.dll 147968 ..c. r/rr-xr-xr-x 0 0 4965-128-3 /WINDOWS/system32/rdchost.dll 141312 ..c. r/rr-xr-xr-x 0 0 4966-128-3 /WINDOWS/system32/sessmgr.exe 67072 ..c. r/rr-xr-xr-x 0 0 4967-128-3 /WINDOWS/system32/rdshost.exe 13824 ..c. r/rr-xr-xr-x 0 0 4968-128-3 /WINDOWS/system32/rdsaddin.exe 60416 ..c. r/rr-xr-xr-x 0 0 4969-128-3 /WINDOWS/system32/remotepg.dll 33040 ..c. r/rr-xr-xr-x 0 0 497-128-3 /WINDOWS/system32/dplay.dll 677888 ..c. r/rr-xr-xr-x 0 0 4970-128-3 /WINDOWS/system32/mstsc.exe 2061824 ..c. r/rr-xr-xr-x 0 0 4971-128-3 /WINDOWS/system32/mstscax.dll 136192 ..c. r/rr-xr-xr-x 0 0 4972-128-3 /WINDOWS/system32/aaclient.dll 290304 ..c. r/rr-xr-xr-x 0 0 4973-128-3 /WINDOWS/system32/rhttpaa.dll 53248 ..c. r/rr-xr-xr-x 0 0 4974-128-3 /WINDOWS/system32/tsgqec.dll 93696 ..c. r/rr-xr-xr-x 0 0 4975-128-3 /WINDOWS/system32/tscfgwmi.dll 99750 ..c. r/rr-xr-xr-x 0 0 4979-128-3 /WINDOWS/system32/wbem/tscfgwmi.mof 62464 ..c. r/rr-xr-xr-x 0 0 498-128-3 /WINDOWS/system32/dpnmodem.dll 58096 ..c. r/rr-xr-xr-x 0 0 4980-128-3 /WINDOWS/system32/wbem/tscfgwmi.mfl 728 ..c. d/dr-xr-xr-x 0 0 4981-144-1 /WINDOWS/system32/en-US 538624 ..c. r/rr-xr-xr-x 0 0 4985-128-3 /WINDOWS/system32/spider.exe 102912 ..c. r/rr-xr-xr-x 0 0 4986-128-3 /WINDOWS/system32/clipbrd.exe 343040 ..c. r/rr-xr-xr-x 0 0 4987-128-3 /WINDOWS/system32/mspaint.exe 61952 ..c. r/rr-xr-xr-x 0 0 499-128-3 /WINDOWS/system32/dpnwsock.dll 347136 ..c. r/rr-xr-xr-x 0 0 4992-128-3 /WINDOWS/system32/hypertrm.dll 123392 ..c. r/rr-xr-xr-x 0 0 4993-128-3 /WINDOWS/system32/mplay32.exe 131584 ..c. r/rr-xr-xr-x 0 0 4994-128-3 /WINDOWS/system32/sndrec32.exe 68608 ..c. r/rr-xr-xr-x 0 0 4995-128-3 /WINDOWS/system32/access.cpl 184320 ..c. r/rr-xr-xr-x 0 0 4996-128-3 /WINDOWS/system32/accwiz.exe 53520 ..c. r/rr-xr-xr-x 0 0 500-128-3 /WINDOWS/system32/dpserial.dll 42768 ..c. r/rr-xr-xr-x 0 0 501-128-3 /WINDOWS/system32/dpwsock.dll 63488 ..c. r/rr-xr-xr-x 0 0 5024-128-3 /WINDOWS/system32/wmimgmt.msc 120320 ..c. r/rr-xr-xr-x 0 0 5025-128-3 /WINDOWS/system32/wbem/dsprov.dll 53248 ..c. r/rr-xr-xr-x 0 0 5026-128-3 /WINDOWS/system32/wbem/fwdprov.dll 2598 ..c. r/rr-xr-xr-x 0 0 5027-128-3 /WINDOWS/system32/wbem/htable-sortby.xsl 273920 ..c. r/rr-xr-xr-x 0 0 5028-128-3 /WINDOWS/system32/wbem/msiprov.dll 40960 ..c. r/rr-xr-xr-x 0 0 5029-128-3 /WINDOWS/system32/wbem/smtpcons.dll 3247 ..c. r/rr-xr-xr-x 0 0 5030-128-3 /WINDOWS/system32/wbem/texttablewsys.xsl 61952 ..c. r/rr-xr-xr-x 0 0 5031-128-3 /WINDOWS/system32/wbem/tmplprov.dll 59904 ..c. r/rr-xr-xr-x 0 0 5032-128-3 /WINDOWS/system32/wbem/trnsprov.dll 16896 ..c. r/rr-xr-xr-x 0 0 5033-128-3 /WINDOWS/system32/wbem/unsecapp.exe 116224 ..c. r/rr-xr-xr-x 0 0 5034-128-3 /WINDOWS/system32/wbem/updprov.dll 12288 ..c. r/rr-xr-xr-x 0 0 5035-128-3 /WINDOWS/system32/wbem/wbemads.dll 31232 ..c. r/rr-xr-xr-x 0 0 5036-128-3 /WINDOWS/system32/wbem/wbemads.tlb 59904 ..c. r/rr-xr-xr-x 0 0 5037-128-3 /WINDOWS/system32/wbem/wbemdisp.tlb 13312 ..c. r/rr-xr-xr-x 0 0 5038-128-3 /WINDOWS/system32/wbem/winmgmt.exe 16384 ..c. r/rr-xr-xr-x 0 0 5039-128-3 /WINDOWS/system32/wbem/winmgmtr.dll 28112 ..c. r/rr-xr-xr-x 0 0 504-128-3 /WINDOWS/system32/drwatson.exe 9442 ..c. r/rr-xr-xr-x 0 0 5040-128-3 /WINDOWS/system32/wbem/wmiclimofformat.xsl 3247 ..c. r/rr-xr-xr-x 0 0 5041-128-3 /WINDOWS/system32/wbem/wmiclitableformat.xsl 3921 ..c. r/rr-xr-xr-x 0 0 5042-128-3 /WINDOWS/system32/wbem/wmiclitableformatnosys.xsl 485 ..c. r/rr-xr-xr-x 0 0 5043-128-1 /WINDOWS/system32/wbem/wmiclivalueformat.xsl 61440 ..c. r/rr-xr-xr-x 0 0 5044-128-3 /WINDOWS/system32/wbem/wmimsg.dll 75264 ..c. r/rr-xr-xr-x 0 0 5045-128-3 /WINDOWS/system32/wbem/wmipicmp.dll 52224 ..c. r/rr-xr-xr-x 0 0 5046-128-3 /WINDOWS/system32/wbem/wmitimep.dll 11052 ..c. r/rr-xr-xr-x 0 0 5047-128-3 /WINDOWS/system32/wbem/dsprov.mfl 18398 ..c. r/rr-xr-xr-x 0 0 5048-128-3 /WINDOWS/system32/wbem/dsprov.mof 6100 ..c. r/rr-xr-xr-x 0 0 5049-128-3 /WINDOWS/system32/wbem/fconprov.mfl 8790 ..c. r/rr-xr-xr-x 0 0 5050-128-3 /WINDOWS/system32/wbem/fconprov.mof 3092 ..c. r/rr-xr-xr-x 0 0 5051-128-3 /WINDOWS/system32/wbem/fevprov.mfl 4392 ..c. r/rr-xr-xr-x 0 0 5052-128-3 /WINDOWS/system32/wbem/fevprov.mof 8564 ..c. r/rr-xr-xr-x 0 0 5053-128-3 /WINDOWS/system32/wbem/krnlprov.mfl 12712 ..c. r/rr-xr-xr-x 0 0 5054-128-3 /WINDOWS/system32/wbem/krnlprov.mof 108452 ..c. r/rr-xr-xr-x 0 0 5055-128-3 /WINDOWS/system32/wbem/msi.mfl 165430 ..c. r/rr-xr-xr-x 0 0 5056-128-3 /WINDOWS/system32/wbem/msi.mof 626 ..c. r/rr-xr-xr-x 0 0 5057-128-1 /WINDOWS/system32/wbem/ncprov.mfl 2880 ..c. r/rr-xr-xr-x 0 0 5058-128-3 /WINDOWS/system32/wbem/ncprov.mof 20544 ..c. r/rr-xr-xr-x 0 0 5059-128-3 /WINDOWS/system32/wbem/ntevt.mfl 45568 ..c. r/rr-xr-xr-x 0 0 506-128-3 /WINDOWS/system32/drwtsn32.exe 29762 ..c. r/rr-xr-xr-x 0 0 5060-128-3 /WINDOWS/system32/wbem/ntevt.mof 4900 ..c. r/rr-xr-xr-x 0 0 5061-128-3 /WINDOWS/system32/wbem/policman.mfl 12150 ..c. r/rr-xr-xr-x 0 0 5062-128-3 /WINDOWS/system32/wbem/policman.mof 38578 ..c. r/rr-xr-xr-x 0 0 5063-128-3 /WINDOWS/system32/wbem/regevent.mfl 46372 ..c. r/rr-xr-xr-x 0 0 5064-128-3 /WINDOWS/system32/wbem/regevent.mof 16337 ..c. r/rr-xr-xr-x 0 0 5065-128-3 /WINDOWS/system32/wbem/scm.mof 3354 ..c. r/rr-xr-xr-x 0 0 5066-128-3 /WINDOWS/system32/wbem/scrcons.mfl 5728 ..c. r/rr-xr-xr-x 0 0 5067-128-3 /WINDOWS/system32/wbem/scrcons.mof 33524 ..c. r/rr-xr-xr-x 0 0 5068-128-3 /WINDOWS/system32/wbem/secrcw32.mfl 58746 ..c. r/rr-xr-xr-x 0 0 5069-128-3 /WINDOWS/system32/wbem/secrcw32.mof 2762 ..c. r/rr-xr-xr-x 0 0 5070-128-3 /WINDOWS/system32/wbem/smtpcons.mfl 4100 ..c. r/rr-xr-xr-x 0 0 5071-128-3 /WINDOWS/system32/wbem/smtpcons.mof 2228 ..c. r/rr-xr-xr-x 0 0 5072-128-3 /WINDOWS/system32/wbem/subscrpt.mof 63684 ..c. r/rr-xr-xr-x 0 0 5073-128-3 /WINDOWS/system32/wbem/system.mof 7894 ..c. r/rr-xr-xr-x 0 0 5074-128-3 /WINDOWS/system32/wbem/tmplprov.mfl 12144 ..c. r/rr-xr-xr-x 0 0 5075-128-3 /WINDOWS/system32/wbem/tmplprov.mof 2026 ..c. r/rr-xr-xr-x 0 0 5076-128-3 /WINDOWS/system32/wbem/trnsprov.mfl 4998 ..c. r/rr-xr-xr-x 0 0 5077-128-3 /WINDOWS/system32/wbem/trnsprov.mof 13488 ..c. r/rr-xr-xr-x 0 0 5078-128-3 /WINDOWS/system32/wbem/updprov.mfl 20720 ..c. r/rr-xr-xr-x 0 0 5079-128-3 /WINDOWS/system32/wbem/updprov.mof 62976 ..c. r/rr-xr-xr-x 0 0 508-128-3 /WINDOWS/system32/dsauth.dll 13110 ..c. r/rr-xr-xr-x 0 0 5080-128-3 /WINDOWS/system32/wbem/wbemcons.mfl 18004 ..c. r/rr-xr-xr-x 0 0 5081-128-3 /WINDOWS/system32/wbem/wbemcons.mof 4370 ..c. r/rr-xr-xr-x 0 0 5082-128-3 /WINDOWS/system32/wbem/wmi.mfl 28846 ..c. r/rr-xr-xr-x 0 0 5083-128-3 /WINDOWS/system32/wbem/wmipcima.mfl 41402 ..c. r/rr-xr-xr-x 0 0 5084-128-3 /WINDOWS/system32/wbem/wmipcima.mof 8210 ..c. r/rr-xr-xr-x 0 0 5085-128-3 /WINDOWS/system32/wbem/wmipdskq.mfl 13342 ..c. r/rr-xr-xr-x 0 0 5086-128-3 /WINDOWS/system32/wbem/wmipdskq.mof 13926 ..c. r/rr-xr-xr-x 0 0 5087-128-3 /WINDOWS/system32/wbem/wmipicmp.mfl 19356 ..c. r/rr-xr-xr-x 0 0 5088-128-3 /WINDOWS/system32/wbem/wmipicmp.mof 17046 ..c. r/rr-xr-xr-x 0 0 5089-128-3 /WINDOWS/system32/wbem/wmipiprt.mfl 23692 ..c. r/rr-xr-xr-x 0 0 5090-128-3 /WINDOWS/system32/wbem/wmipiprt.mof 44160 ..c. r/rr-xr-xr-x 0 0 5091-128-3 /WINDOWS/system32/wbem/wmipjobj.mfl 61208 ..c. r/rr-xr-xr-x 0 0 5092-128-3 /WINDOWS/system32/wbem/wmipjobj.mof 9488 ..c. r/rr-xr-xr-x 0 0 5093-128-3 /WINDOWS/system32/wbem/wmipsess.mfl 13880 ..c. r/rr-xr-xr-x 0 0 5094-128-3 /WINDOWS/system32/wbem/wmipsess.mof 3994 ..c. r/rr-xr-xr-x 0 0 5095-128-3 /WINDOWS/system32/wbem/wmitimep.mfl 6494 ..c. r/rr-xr-xr-x 0 0 5096-128-3 /WINDOWS/system32/wbem/wmitimep.mof 9018 ..c. r/rr-xr-xr-x 0 0 5097-128-3 /WINDOWS/system32/wbem/xml/cim20.dtd 12356 ..c. r/rr-xr-xr-x 0 0 5098-128-3 /WINDOWS/system32/wbem/xml/wmi20.dtd 45568 ..c. r/rr-xr-xr-x 0 0 5099-128-3 /WINDOWS/system32/wbem/xml/wmi2xml.dll 56 ..c. d/dr-xr-xr-x 0 0 51-144-6 /WINDOWS/Cursors 768 ..c. r/rr-xr-xr-x 0 0 5104-128-3 /WINDOWS/system32/msdtcprf.h 1931 ..c. r/rr-xr-xr-x 0 0 5105-128-3 /WINDOWS/system32/msdtcprf.ini 15872 ..c. r/rr-xr-xr-x 0 0 5107-128-3 /WINDOWS/system32/cdmodem.dll 15360 ..c. r/rr-xr-xr-x 0 0 5108-128-3 /WINDOWS/system32/logoff.exe 20992 ..c. r/rr-xr-xr-x 0 0 5109-128-3 /WINDOWS/system32/msg.exe 81 ..c. r/rr-xr-xr-x 0 0 511-128-1 /WINDOWS/system32/dsound.vxd 16896 ..c. r/rr-xr-xr-x 0 0 5110-128-3 /WINDOWS/system32/qappsrv.exe 22016 ..c. r/rr-xr-xr-x 0 0 5111-128-3 /WINDOWS/system32/qwinsta.exe 4096 ..c. r/rr-xr-xr-x 0 0 5112-128-3 /WINDOWS/system32/rdpcfgex.dll 33792 ..c. r/rr-xr-xr-x 0 0 5113-128-3 /WINDOWS/system32/regini.exe 15872 ..c. r/rr-xr-xr-x 0 0 5114-128-3 /WINDOWS/system32/rwinsta.exe 14848 ..c. r/rr-xr-xr-x 0 0 5115-128-3 /WINDOWS/system32/shadow.exe 14848 ..c. r/rr-xr-xr-x 0 0 5116-128-3 /WINDOWS/system32/tscon.exe 14848 ..c. r/rr-xr-xr-x 0 0 5117-128-3 /WINDOWS/system32/tsdiscon.exe 3286 ..c. r/rr-xr-xr-x 0 0 5118-128-3 /WINDOWS/system32/tslabels.h 13223 ..c. r/rr-xr-xr-x 0 0 5119-128-3 /WINDOWS/system32/tslabels.ini 218003 ..c. r/rr-xr-xr-x 0 0 512-128-3 /WINDOWS/system32/dssec.dat 16896 ..c. r/rr-xr-xr-x 0 0 5120-128-3 /WINDOWS/system32/tsshutdn.exe 16384 ..c. r/rr-xr-xr-x 0 0 5121-128-3 /WINDOWS/system32/tskill.exe 1161 ..c. r/rr-xr-xr-x 0 0 5122-128-3 /WINDOWS/system32/usrlogon.cmd 9728 ..c. r/rr-xr-xr-x 0 0 5123-128-3 /WINDOWS/system32/reset.exe 55296 ..c. r/rr-xr-xr-x 0 0 5124-128-3 /WINDOWS/system32/freecell.exe 126976 ..c. r/rr-xr-xr-x 0 0 5127-128-3 /WINDOWS/system32/mshearts.exe 119808 ..c. r/rr-xr-xr-x 0 0 5129-128-3 /WINDOWS/system32/winmine.exe 56832 ..c. r/rr-xr-xr-x 0 0 5132-128-3 /WINDOWS/system32/sol.exe 114688 ..c. r/rr-xr-xr-x 0 0 5136-128-3 /WINDOWS/system32/calc.exe 80384 ..c. r/rr-xr-xr-x 0 0 5139-128-3 /WINDOWS/system32/charmap.exe 55296 ..c. r/rr-xr-xr-x 0 0 514-128-3 /WINDOWS/system32/dvdplay.exe 22984 ..c. r/rr-xr-xr-x 0 0 5140-128-3 /WINDOWS/system32/bopomofo.uce 24006 ..c. r/rr-xr-xr-x 0 0 5141-128-3 /WINDOWS/system32/gb2312.uce 605696 ..c. r/rr-xr-xr-x 0 0 5142-128-3 /WINDOWS/system32/getuname.dll 60458 ..c. r/rr-xr-xr-x 0 0 5143-128-3 /WINDOWS/system32/ideograf.uce 6948 ..c. r/rr-xr-xr-x 0 0 5144-128-3 /WINDOWS/system32/kanji_1.uce 8484 ..c. r/rr-xr-xr-x 0 0 5145-128-3 /WINDOWS/system32/kanji_2.uce 12876 ..c. r/rr-xr-xr-x 0 0 5146-128-3 /WINDOWS/system32/korean.uce 16740 ..c. r/rr-xr-xr-x 0 0 5147-128-3 /WINDOWS/system32/shiftjis.uce 93702 ..c. r/rr-xr-xr-x 0 0 5148-128-3 /WINDOWS/system32/subrange.uce 1272 ..c. r/rr-xr-xr-x 0 0 5151-128-3 /WINDOWS/Blue Lace 16.bmp 65978 ..c. r/rr-xr-xr-x 0 0 5152-128-3 /WINDOWS/Soap Bubbles.bmp 17062 ..c. r/rr-xr-xr-x 0 0 5153-128-3 /WINDOWS/Coffee Bean.bmp 16730 ..c. r/rr-xr-xr-x 0 0 5154-128-3 /WINDOWS/FeatherTexture.bmp 17336 ..c. r/rr-xr-xr-x 0 0 5155-128-3 /WINDOWS/Gone Fishing.bmp 26582 ..c. r/rr-xr-xr-x 0 0 5156-128-3 /WINDOWS/Greenstone.bmp 65954 ..c. r/rr-xr-xr-x 0 0 5157-128-3 /WINDOWS/Prairie Wind.bmp 17362 ..c. r/rr-xr-xr-x 0 0 5158-128-3 /WINDOWS/Rhododendron.bmp 26680 ..c. r/rr-xr-xr-x 0 0 5159-128-3 /WINDOWS/River Sumida.bmp 65832 ..c. r/rr-xr-xr-x 0 0 5160-128-3 /WINDOWS/Santa Fe Stucco.bmp 9522 ..c. r/rr-xr-xr-x 0 0 5161-128-3 /WINDOWS/Zapotec.bmp 12642 ..c. r/rr-xr-xr-x 0 0 517-128-3 /WINDOWS/system32/edlin.exe 320 ..c. d/dr-xr-xr-x 0 0 52-144-5 /WINDOWS/Media 35328 ..c. r/rr-xr-xr-x 0 0 5246-128-3 /WINDOWS/system32/winchat.exe 227840 ..c. r/rr-xr-xr-x 0 0 5251-128-3 /WINDOWS/system32/avtapi.dll 16384 ..c. r/rr-xr-xr-x 0 0 5252-128-3 /WINDOWS/system32/avmeter.dll 73216 ..c. r/rr-xr-xr-x 0 0 5253-128-3 /WINDOWS/system32/avwav.dll 44544 ..c. r/rr-xr-xr-x 0 0 5256-128-3 /WINDOWS/system32/hticons.dll 138752 ..c. r/rr-xr-xr-x 0 0 5257-128-3 /WINDOWS/system32/sndvol32.exe 1114896 ..c. r/rr-xr-xr-x 0 0 528-128-3 /WINDOWS/system32/esent97.dll 17408 ..c. r/rr-xr-xr-x 0 0 529-128-3 /WINDOWS/system32/esentprf.dll 248 ..c. d/dr-xr-xr-x 0 0 53-144-1 /WINDOWS/java 6708 ..c. r/rr-xr-xr-x 0 0 530-128-3 /WINDOWS/system32/esentprf.hxx 1015477 ..c. r/rr-xr-xr-x 0 0 531-128-3 /WINDOWS/system32/esentprf.ini 39424 ..c. r/rr-xr-xr-x 0 0 532-128-3 /WINDOWS/system32/esentutl.exe 33280 ..c. r/rr-xr-xr-x 0 0 535-128-3 /WINDOWS/system32/eventcls.dll 8704 ..c. r/rr-xr-xr-x 0 0 536-128-3 /WINDOWS/system32/eventvwr.exe 56678 ..c. r/rr-xr-xr-x 0 0 537-128-3 /WINDOWS/system32/eventvwr.msc 5370 ..c. r/rr-xr-xr-x 0 0 538-128-3 /WINDOWS/system32/wbem/evntrprv.mof 97965 ..c. r/rr-xr-xr-x 0 0 540-128-3 /WINDOWS/system32/eventquery.vbs 8424 ..c. r/rr-xr-xr-x 0 0 541-128-3 /WINDOWS/system32/exe2bin.exe 15872 ..c. r/rr-xr-xr-x 0 0 542-128-3 /WINDOWS/system32/expand.exe 80 ..c. r/rr-xr-xr-x 0 0 543-128-1 /WINDOWS/explorer.scf 882 ..c. r/rr-xr-xr-x 0 0 544-128-3 /WINDOWS/system32/fastopen.exe 5632 ..c. r/rr-xr-xr-x 0 0 5443-128-3 /WINDOWS/system32/write.exe 14848 ..c. r/rr-xr-xr-x 0 0 545-128-3 /WINDOWS/system32/fc.exe 936 ..c. r/rr-xr-xr-x 0 0 5493-128-3 /WINDOWS/wmsetup.log 130 ..c. r/rr-xr-xr-x 0 0 5497-128-1 /WINDOWS/DtcInstall.log 56 ..c. d/dr-xr-xr-x 0 0 5503-144-6 /WINDOWS/Registration 36 ..c. r/rr-xr-xr-x 0 0 5505-128-1 /WINDOWS/vb.ini 37 ..c. r/rr-xr-xr-x 0 0 5506-128-1 /WINDOWS/vbaddin.ini 9216 ..c. r/rr-xr-xr-x 0 0 551-128-3 /WINDOWS/system32/find.exe 21640 ..c. r/rr-xr-xr-x 0 0 5511-128-4 /WINDOWS/system32/emptyregdb.dat 9216 ..c. r/rr-xr-xr-x 0 0 552-128-3 /WINDOWS/system32/finger.exe 3072 ..c. r/rr-xr-xr-x 0 0 553-128-3 /WINDOWS/system32/fixmapi.exe 257 ..c. r/rr-xr-xr-x 0 0 5538-128-1 /WINDOWS/system32/wbem/Logs/FrameWork.log 264 .ac. d/dr-xr-xr-x 0 0 5539-144-1 /WINDOWS/system32/wbem/Performance 5347 ..c. r/rr-xr-xr-x 0 0 5541-128-3 /WINDOWS/system32/wbem/Logs/setup.log 11057 ..c. r/rr-xr-xr-x 0 0 5543-128-3 /WINDOWS/system32/wbem/Logs/mofcomp.log 1004 ..c. r/rr-xr-xr-x 0 0 5544-128-3 /WINDOWS/system32/wbem/Logs/wmiprov.log 56 .ac. d/dr-xr-xr-x 0 0 5545-144-7 /WINDOWS/system32/wbem/AutoRecover 56 .ac. d/dr-xr-xr-x 0 0 5546-144-5 /WINDOWS/system32/wbem/Repository/FS 20 ..c. r/rr-xr-xr-x 0 0 5547-128-1 /WINDOWS/system32/wbem/Repository/$WinMgmt.CFG 3160 ..c. r/rr-xr-xr-x 0 0 5548-128-3 /WINDOWS/system32/wbem/Repository/FS/MAPPING1.MAP 3160 ..c. r/rr-xr-xr-x 0 0 5549-128-3 /WINDOWS/system32/wbem/Repository/FS/MAPPING2.MAP 4 ..c. r/rr-xr-xr-x 0 0 5550-128-1 /WINDOWS/system32/wbem/Repository/FS/MAPPING.VER 524 ..c. r/rr-xr-xr-x 0 0 5551-128-1 /WINDOWS/system32/wbem/Repository/FS/INDEX.MAP 2636 ..c. r/rr-xr-xr-x 0 0 5552-128-3 /WINDOWS/system32/wbem/Repository/FS/OBJECTS.MAP 5300224 ..c. r/rr-xr-xr-x 0 0 5553-128-4 /WINDOWS/system32/wbem/Repository/FS/OBJECTS.DATA 999424 ..c. r/rr-xr-xr-x 0 0 5554-128-3 /WINDOWS/system32/wbem/Repository/FS/INDEX.BTR 401 ..c. r/rr-xr-xr-x 0 0 5555-128-1 /WINDOWS/system32/wbem/Logs/replog.log 64281 ..c. r/rr-xr-xr-x 0 0 5556-128-3 /WINDOWS/system32/wbem/Logs/wbemcore.log 2775948 ..c. r/rr-xr-xr-x 0 0 5557-128-4 /WINDOWS/system32/wbem/AutoRecover/26C097A9392F8C541AD42E89B7909073.mof 1961592 ..c. r/rr-xr-xr-x 0 0 5558-128-4 /WINDOWS/system32/wbem/AutoRecover/3EC317800FF508210BB945C81C0EACE7.mof 130456 ..c. r/rr-xr-xr-x 0 0 5559-128-4 /WINDOWS/system32/wbem/AutoRecover/0A9DBC92D554324656F61F9862679F27.mof 41508 ..c. r/rr-xr-xr-x 0 0 5560-128-4 /WINDOWS/system32/wbem/AutoRecover/2AA23BB86A5EBD8BC2D820944E55B233.mof 28952 ..c. r/rr-xr-xr-x 0 0 5561-128-4 /WINDOWS/system32/wbem/AutoRecover/C92641594A6F2DA8A55FE4738AFDA539.mof 46478 ..c. r/rr-xr-xr-x 0 0 5562-128-4 /WINDOWS/system32/wbem/AutoRecover/A7575F8DE31A912FFE91A7A41B1E382A.mof 38684 ..c. r/rr-xr-xr-x 0 0 5563-128-4 /WINDOWS/system32/wbem/AutoRecover/CA0106054EB09C302ED3E0669F99D021.mof 29862 ..c. r/rr-xr-xr-x 0 0 5564-128-4 /WINDOWS/system32/wbem/AutoRecover/37134956F76D3C30C9BE0C12571CAF43.mof 20644 ..c. r/rr-xr-xr-x 0 0 5565-128-4 /WINDOWS/system32/wbem/AutoRecover/DFD614E4D613EF4506AC8F525F5F514B.mof 58852 ..c. r/rr-xr-xr-x 0 0 5566-128-4 /WINDOWS/system32/wbem/AutoRecover/E737DE61441445E1FDFCA45EF5E7D987.mof 33630 ..c. r/rr-xr-xr-x 0 0 5567-128-4 /WINDOWS/system32/wbem/AutoRecover/02E78424AB18BDBFA706C08B7D7B9F1D.mof 18500 ..c. r/rr-xr-xr-x 0 0 5568-128-4 /WINDOWS/system32/wbem/AutoRecover/C81ACF420917AA0F87487BC4D958BEB4.mof 11154 ..c. r/rr-xr-xr-x 0 0 5569-128-4 /WINDOWS/system32/wbem/AutoRecover/958A50DFF8A9DF5FAEA042AC9F60815F.mof 165526 ..c. r/rr-xr-xr-x 0 0 5570-128-4 /WINDOWS/system32/wbem/AutoRecover/DC999686F8B85B326CEDFA199DD07F72.mof 108548 ..c. r/rr-xr-xr-x 0 0 5571-128-4 /WINDOWS/system32/wbem/AutoRecover/6B38F33147D0369D5038BBB61C7A31C8.mof 12256 ..c. r/rr-xr-xr-x 0 0 5572-128-4 /WINDOWS/system32/wbem/AutoRecover/2CFB5B149FA396D1AEA5F89B1C5A8D81.mof 5006 ..c. r/rr-xr-xr-x 0 0 5573-128-4 /WINDOWS/system32/wbem/AutoRecover/60A06765DDFE47EF7240BD9C1EB29EFE.mof 129294 ..c. r/rr-xr-xr-x 0 0 5574-128-4 /WINDOWS/system32/wbem/AutoRecover/72F867EF62976CE9F70993FF3E68A4EB.mof 10784 ..c. r/rr-xr-xr-x 0 0 5575-128-4 /WINDOWS/system32/wbem/AutoRecover/E04DE4CDFEC284A342159BB920976701.mof 4466 ..c. r/rr-xr-xr-x 0 0 5576-128-4 /WINDOWS/system32/wbem/AutoRecover/7A62FA52E22CE751514BC93BE067BC80.mof 32772 ..c. r/rr-xr-xr-x 0 0 5577-128-4 /WINDOWS/system32/wbem/AutoRecover/BE81B2C0741907C1FC1C42B6223E59AD.mof 4496 ..c. r/rr-xr-xr-x 0 0 5578-128-4 /WINDOWS/system32/wbem/AutoRecover/CFC35B349D24A8495FD2CEAB15C32D88.mof 3196 ..c. r/rr-xr-xr-x 0 0 5579-128-4 /WINDOWS/system32/wbem/AutoRecover/20D2C3B8CE10B96CE6B8A3C241EF4416.mof 16384 ..c. r/rr-xr-xr-x 0 0 558-128-3 /WINDOWS/system32/fmifs.dll 6600 ..c. r/rr-xr-xr-x 0 0 5580-128-4 /WINDOWS/system32/wbem/AutoRecover/EDBF963FB003D0670AA9C2219BD091FB.mof 4100 ..c. r/rr-xr-xr-x 0 0 5581-128-4 /WINDOWS/system32/wbem/AutoRecover/852ECCDBABE77624586E4417FE66F857.mof 13448 ..c. r/rr-xr-xr-x 0 0 5582-128-4 /WINDOWS/system32/wbem/AutoRecover/2C142C4C15E3B8D139B98154CD083071.mof 8316 ..c. r/rr-xr-xr-x 0 0 5583-128-4 /WINDOWS/system32/wbem/AutoRecover/ABB70D53B97FC8002205F77E02C97304.mof 19462 ..c. r/rr-xr-xr-x 0 0 5584-128-4 /WINDOWS/system32/wbem/AutoRecover/AE7023598F41510BF261111652046301.mof 14032 ..c. r/rr-xr-xr-x 0 0 5585-128-4 /WINDOWS/system32/wbem/AutoRecover/A99860BB696AE92ED001E48B014365CE.mof 23798 ..c. r/rr-xr-xr-x 0 0 5586-128-4 /WINDOWS/system32/wbem/AutoRecover/092389D621F5A8834203DAAC74CCA279.mof 17152 ..c. r/rr-xr-xr-x 0 0 5587-128-4 /WINDOWS/system32/wbem/AutoRecover/2A61A823DC2C1C838EE71C4351BED0B4.mof 61314 ..c. r/rr-xr-xr-x 0 0 5588-128-4 /WINDOWS/system32/wbem/AutoRecover/FAAD7D567E76CAB10704AFD7C0488F23.mof 44266 ..c. r/rr-xr-xr-x 0 0 5589-128-4 /WINDOWS/system32/wbem/AutoRecover/2CE64FBD51953C097BB5470043A6DAF9.mof 13986 ..c. r/rr-xr-xr-x 0 0 5590-128-4 /WINDOWS/system32/wbem/AutoRecover/42355E8E232EF8CADD187D531DEC55DD.mof 9594 ..c. r/rr-xr-xr-x 0 0 5591-128-4 /WINDOWS/system32/wbem/AutoRecover/AEA50E449C23761CA4D9B7F9ED0D9C89.mof 12818 ..c. r/rr-xr-xr-x 0 0 5592-128-4 /WINDOWS/system32/wbem/AutoRecover/8636DC7F9479DACE6778109CB4FB4B01.mof 8670 ..c. r/rr-xr-xr-x 0 0 5593-128-4 /WINDOWS/system32/wbem/AutoRecover/DBD781C2C031C708BCB490F228E7BEF9.mof 29386 ..c. r/rr-xr-xr-x 0 0 5594-128-4 /WINDOWS/system32/wbem/AutoRecover/88744D2A29102FC88ECF505DD2E984FC.mof 99856 ..c. r/rr-xr-xr-x 0 0 5595-128-4 /WINDOWS/system32/wbem/AutoRecover/C6300BFE37ADE6B52EC023F66124985F.mof 58202 ..c. r/rr-xr-xr-x 0 0 5596-128-4 /WINDOWS/system32/wbem/AutoRecover/701B705ED7DF100F88D5BC4A595E938D.mof 15688 ..c. r/rr-xr-xr-x 0 0 5597-128-4 /WINDOWS/system32/wbem/AutoRecover/79E817BC978E2D450EB9E3794DFDA6CF.mof 9850 ..c. r/rr-xr-xr-x 0 0 5598-128-4 /WINDOWS/system32/wbem/AutoRecover/26D6C4EB696DD0C83F5D5BF2235000A7.mof 10848 ..c. r/rr-xr-xr-x 0 0 5599-128-4 /WINDOWS/system32/wbem/AutoRecover/E441354B9FE5F63362A481C9B9195A73.mof 48 .ac. d/dr-xr-xr-x 0 0 56-144-1 /WINDOWS/system32/ShellExt 16914 ..c. r/rr-xr-xr-x 0 0 5600-128-4 /WINDOWS/system32/wbem/AutoRecover/42C894EEACAD83A4E41154685841B3E1.mof 7694 ..c. r/rr-xr-xr-x 0 0 5601-128-4 /WINDOWS/system32/wbem/AutoRecover/1E97A05DE566CF6EEAE29D0634E27392.mof 4260 ..c. r/rr-xr-xr-x 0 0 5602-128-4 /WINDOWS/system32/wbem/AutoRecover/D92470B796B6B18F9EE52301857F0567.mof 3182 ..c. r/rr-xr-xr-x 0 0 5603-128-4 /WINDOWS/system32/wbem/AutoRecover/2DA80135BA8EC175C9B1C1598F659434.mof 19372 ..c. r/rr-xr-xr-x 0 0 5604-128-4 /WINDOWS/system32/wbem/AutoRecover/608B41C6A2CD9460C2263E6CD80C335A.mof 43182 ..c. r/rr-xr-xr-x 0 0 5605-128-4 /WINDOWS/system32/wbem/AutoRecover/731AE1FC8C795979F40FAD645FFBAEB1.mof 88742 ..c. r/rr-xr-xr-x 0 0 5606-128-4 /WINDOWS/system32/wbem/AutoRecover/C3A0BE17B37ACE48BE78B31580231AE9.mof 283986 ..c. r/rr-xr-xr-x 0 0 5607-128-4 /WINDOWS/system32/wbem/AutoRecover/D724DF13E0B0DF051EB5D403DD8EF2FC.mof 2566 ..c. r/rr-xr-xr-x 0 0 5608-128-4 /WINDOWS/system32/wbem/AutoRecover/9AD3182A2F39A3E091E15109132EC6CC.mof 1394 ..c. r/rr-xr-xr-x 0 0 5609-128-4 /WINDOWS/system32/wbem/AutoRecover/7F417E1A6D819A9B2FEB55DA6858EA0A.mof 8102 ..c. r/rr-xr-xr-x 0 0 5610-128-4 /WINDOWS/system32/wbem/AutoRecover/903E49C444C46FEF5F2C3A189C9CEF71.mof 1022 ..c. r/rr-xr-xr-x 0 0 5611-128-4 /WINDOWS/sessmgr.setup.log 32760 ..c. r/rr-xr-xr-x 0 0 565-128-3 /WINDOWS/system32/fsmgmt.msc 81408 ..c. r/rr-xr-xr-x 0 0 566-128-3 /WINDOWS/system32/fsusd.dll 56320 ..c. r/rr-xr-xr-x 0 0 567-128-3 /WINDOWS/system32/fsutil.exe 176128 ..c. r/rr-xr-xr-x 0 0 568-128-3 /WINDOWS/system32/ftsrch.dll 274432 ..c. r/rr-xr-xr-x 0 0 5699-128-3 /WINDOWS/system32/inetcfg.dll 56 .ac. d/d--x--x--x 0 0 57-144-5 /WINDOWS/Web 81920 ..c. r/rr-xr-xr-x 0 0 5700-128-3 /WINDOWS/system32/isign32.dll 73728 ..c. r/rr-xr-xr-x 0 0 5701-128-3 /WINDOWS/system32/icwdial.dll 65536 ..c. r/rr-xr-xr-x 0 0 5702-128-3 /WINDOWS/system32/icwphbk.dll 274944 ..c. r/rr-xr-xr-x 0 0 5706-128-3 /WINDOWS/system32/mstask.dll 12288 ..c. r/rr-xr-xr-x 0 0 5707-128-3 /WINDOWS/system32/mstinit.exe 192512 ..c. r/rr-xr-xr-x 0 0 5708-128-3 /WINDOWS/system32/schedsvc.dll 691712 ..c. r/rr-xr-xr-x 0 0 5718-128-3 /WINDOWS/system32/inetcomm.dll 48128 ..c. r/rr-xr-xr-x 0 0 5719-128-3 /WINDOWS/system32/inetres.dll 252928 ..c. r/rr-xr-xr-x 0 0 5727-128-3 /WINDOWS/system32/msoeacct.dll 105984 ..c. r/rr-xr-xr-x 0 0 5728-128-3 /WINDOWS/system32/msoert2.dll 41472 ..c. r/rr-xr-xr-x 0 0 573-128-3 /WINDOWS/system32/g711codc.ax 69632 ..c. r/rr-xr-xr-x 0 0 5747-128-3 /WINDOWS/system32/msconf.dll 32768 ..c. r/rr-xr-xr-x 0 0 5748-128-3 /WINDOWS/system32/mnmsrvc.exe 28672 ..c. r/rr-xr-xr-x 0 0 5749-128-3 /WINDOWS/system32/nmmkcert.dll 188416 ..c. r/rr-xr-xr-x 0 0 5750-128-3 /WINDOWS/system32/msh261.drv 34560 ..c. r/rr-xr-xr-x 0 0 5751-128-3 /WINDOWS/system32/mnmdd.dll 32768 ..c. r/rr-xr-xr-x 0 0 5752-128-3 /WINDOWS/system32/isrdbg32.dll 81920 ..c. r/rr-xr-xr-x 0 0 5753-128-3 /WINDOWS/system32/ils.dll 67584 ..c. r/rr-xr-xr-x 0 0 5758-128-3 /WINDOWS/system32/srclient.dll 171008 ..c. r/rr-xr-xr-x 0 0 5759-128-3 /WINDOWS/system32/srsvc.dll 76800 ..c. r/rr-xr-xr-x 0 0 576-128-3 /WINDOWS/system32/gcdef.dll 239104 ..c. r/rr-xr-xr-x 0 0 5760-128-3 /WINDOWS/system32/srrstr.dll 696 .ac. d/dr-xr-xr-x 0 0 5761-144-1 /WINDOWS/system32/Restore 380416 ..c. r/rr-xr-xr-x 0 0 5763-128-3 /WINDOWS/system32/Restore/rstrui.exe 23040 ..c. r/rr-xr-xr-x 0 0 5765-128-3 /WINDOWS/system32/fltMc.exe 16896 ..c. r/rr-xr-xr-x 0 0 5766-128-3 /WINDOWS/system32/fltlib.dll 4292 ..c. r/rr-xr-xr-x 0 0 5767-128-3 /WINDOWS/Web/safemode.htt 24576 ..c. r/rr-xr-xr-x 0 0 577-128-3 /WINDOWS/system32/gdi.exe 43520 ..c. r/rr-xr-xr-x 0 0 5780-128-3 /WINDOWS/system32/racpldlg.dll 43520 ..c. r/rr-xr-xr-x 0 0 5781-128-3 /WINDOWS/system32/safrcdlg.dll 29696 ..c. r/rr-xr-xr-x 0 0 5782-128-3 /WINDOWS/system32/safrdm.dll 45568 ..c. r/rr-xr-xr-x 0 0 5783-128-3 /WINDOWS/system32/safrslv.dll 91215 ..c. r/rr-xr-xr-x 0 0 5787-128-3 /WINDOWS/system32/oobe/actshell.htm 42593 ..c. r/rr-xr-xr-x 0 0 5788-128-3 /WINDOWS/system32/oobe/dtsgnup.htm 48410 ..c. r/rr-xr-xr-x 0 0 5789-128-3 /WINDOWS/system32/oobe/agtcore.js 267850 ..c. r/rr-xr-xr-x 0 0 5790-128-3 /WINDOWS/system32/oobe/agtscrpt.js 3201 ..c. r/rr-xr-xr-x 0 0 5791-128-3 /WINDOWS/system32/oobe/agtscrp2.js 18843 ..c. r/rr-xr-xr-x 0 0 5792-128-3 /WINDOWS/system32/oobe/dialmgr.js 19346 ..c. r/rr-xr-xr-x 0 0 5793-128-3 /WINDOWS/system32/oobe/error.js 13137 ..c. r/rr-xr-xr-x 0 0 5794-128-3 /WINDOWS/system32/oobe/iconnect.js 1044 ..c. r/rr-xr-xr-x 0 0 5795-128-3 /WINDOWS/system32/oobe/sconnect.js 16987 ..c. r/rr-xr-xr-x 0 0 5796-128-3 /WINDOWS/system32/oobe/dslmain.js 1249 ..c. r/rr-xr-xr-x 0 0 5797-128-3 /WINDOWS/system32/oobe/isptype.js 17175 ..c. r/rr-xr-xr-x 0 0 5798-128-3 /WINDOWS/system32/oobe/icsmgr.js 23735 ..c. r/rr-xr-xr-x 0 0 5799-128-3 /WINDOWS/system32/oobe/migrate.js 56 .ac. d/dr-xr-xr-x 0 0 58-144-5 /WINDOWS/system32/Setup 24772 ..c. r/rr-xr-xr-x 0 0 580-128-3 /WINDOWS/system32/geo.nls 11257 ..c. r/rr-xr-xr-x 0 0 5800-128-3 /WINDOWS/system32/oobe/mousetut.js 173413 ..c. r/rr-xr-xr-x 0 0 5801-128-3 /WINDOWS/system32/oobe/msobshel.htm 9607 ..c. r/rr-xr-xr-x 0 0 5802-128-3 /WINDOWS/system32/oobe/oobeutil.js 339 ..c. r/rr-xr-xr-x 0 0 5803-128-1 /WINDOWS/system32/oobe/migip.dun 576 ..c. r/rr-xr-xr-x 0 0 5804-128-1 /WINDOWS/system32/oobe/migx25a.dun 627 ..c. r/rr-xr-xr-x 0 0 5805-128-1 /WINDOWS/system32/oobe/migx25b.dun 576 ..c. r/rr-xr-xr-x 0 0 5806-128-1 /WINDOWS/system32/oobe/migx25c.dun 403 ..c. r/rr-xr-xr-x 0 0 5807-128-1 /WINDOWS/system32/oobe/obeip.dun 242 ..c. r/rr-xr-xr-x 0 0 5808-128-1 /WINDOWS/system32/oobe/migrate.isp 269 ..c. r/rr-xr-xr-x 0 0 5809-128-1 /WINDOWS/system32/oobe/msobe.isp 285184 ..c. r/rr-xr-xr-x 0 0 581-128-3 /WINDOWS/system32/glmf32.dll 124 ..c. r/rr-xr-xr-x 0 0 5810-128-1 /WINDOWS/system32/oobe/reg.isp 7160 ..c. r/rr-xr-xr-x 0 0 5811-128-3 /WINDOWS/system32/oobe/migrate.obe 23917 ..c. r/rr-xr-xr-x 0 0 5812-128-3 /WINDOWS/system32/oobe/phone.inf 7160 ..c. r/rr-xr-xr-x 0 0 5813-128-3 /WINDOWS/system32/oobe/phone.obe 51200 ..c. r/rr-xr-xr-x 0 0 5814-128-3 /WINDOWS/system32/oobe/oobebaln.exe 240 ..c. r/rr-xr-xr-x 0 0 5815-128-1 /WINDOWS/system32/oobe/oobeinfo.ini 29184 ..c. r/rr-xr-xr-x 0 0 5816-128-3 /WINDOWS/system32/oobe/msoobe.exe 19456 ..c. r/rr-xr-xr-x 0 0 5817-128-3 /WINDOWS/system32/oobe/msobweb.dll 122368 ..c. r/rr-xr-xr-x 0 0 5818-128-3 /WINDOWS/system32/oobe/msobcomm.dll 30720 ..c. r/rr-xr-xr-x 0 0 5819-128-3 /WINDOWS/system32/oobe/msobshel.dll 565248 ..c. r/rr-xr-xr-x 0 0 5820-128-3 /WINDOWS/system32/oobe/msobmain.dll 16384 ..c. r/rr-xr-xr-x 0 0 5821-128-3 /WINDOWS/system32/oobe/msobdl.dll 32004 ..c. r/rr-xr-xr-x 0 0 5822-128-3 /WINDOWS/system32/oobe/updshell.htm 56 .ac. d/dr-xr-xr-x 0 0 5823-144-5 /WINDOWS/system32/oobe/error 3384 ..c. r/rr-xr-xr-x 0 0 5824-128-3 /WINDOWS/system32/oobe/error/cnncterr.htm 3039 ..c. r/rr-xr-xr-x 0 0 5825-128-3 /WINDOWS/system32/oobe/error/dialtone.htm 2255 ..c. r/rr-xr-xr-x 0 0 5826-128-3 /WINDOWS/system32/oobe/error/hndshake.htm 2163 ..c. r/rr-xr-xr-x 0 0 5827-128-3 /WINDOWS/system32/oobe/error/isp2busy.htm 6328 ..c. r/rr-xr-xr-x 0 0 5828-128-3 /WINDOWS/system32/oobe/error/noanswer.htm 2044 ..c. r/rr-xr-xr-x 0 0 5829-128-3 /WINDOWS/system32/oobe/error/pberr.htm 2663 ..c. r/rr-xr-xr-x 0 0 5830-128-3 /WINDOWS/system32/oobe/error/pulse.htm 6128 ..c. r/rr-xr-xr-x 0 0 5831-128-3 /WINDOWS/system32/oobe/error/toobusy.htm 300 ..c. r/rr-xr-xr-x 0 0 5832-128-1 /WINDOWS/system32/oobe/images/arrow.gif 3461 ..c. r/rr-xr-xr-x 0 0 5833-128-3 /WINDOWS/system32/oobe/images/backdown.jpg 2817 ..c. r/rr-xr-xr-x 0 0 5834-128-3 /WINDOWS/system32/oobe/images/backoff.jpg 3557 ..c. r/rr-xr-xr-x 0 0 5835-128-3 /WINDOWS/system32/oobe/images/backover.jpg 3540 ..c. r/rr-xr-xr-x 0 0 5836-128-3 /WINDOWS/system32/oobe/images/backup.jpg 978 ..c. r/rr-xr-xr-x 0 0 5837-128-3 /WINDOWS/system32/oobe/images/btn1.gif 978 ..c. r/rr-xr-xr-x 0 0 5838-128-3 /WINDOWS/system32/oobe/images/btn2.gif 978 ..c. r/rr-xr-xr-x 0 0 5839-128-3 /WINDOWS/system32/oobe/images/btn3.gif 54 ..c. r/rr-xr-xr-x 0 0 5840-128-1 /WINDOWS/system32/oobe/images/bullet1.gif 4616 ..c. r/rr-xr-xr-x 0 0 5841-128-3 /WINDOWS/system32/oobe/images/clickerx.wav 559 ..c. r/rr-xr-xr-x 0 0 5842-128-1 /WINDOWS/system32/oobe/images/clickhr.gif 4795 ..c. r/rr-xr-xr-x 0 0 5843-128-3 /WINDOWS/system32/oobe/images/dialtone.gif 124383 ..c. r/rr-xr-xr-x 0 0 5844-128-3 /WINDOWS/system32/oobe/images/dialup.gif 2135 ..c. r/rr-xr-xr-x 0 0 5845-128-3 /WINDOWS/system32/oobe/images/greenshd.gif 1234 ..c. r/rr-xr-xr-x 0 0 5846-128-3 /WINDOWS/system32/oobe/images/grn_btn.gif 9513 ..c. r/rr-xr-xr-x 0 0 5847-128-3 /WINDOWS/system32/oobe/images/hand1.gif 9257 ..c. r/rr-xr-xr-x 0 0 5848-128-3 /WINDOWS/system32/oobe/images/hand2.gif 665107 ..c. r/rr-xr-xr-x 0 0 5849-128-3 /WINDOWS/system32/oobe/images/intro.wmv 7972 ..c. r/rr-xr-xr-x 0 0 5850-128-3 /WINDOWS/system32/oobe/images/magnify.gif 2700 ..c. r/rr-xr-xr-x 0 0 5851-128-3 /WINDOWS/system32/oobe/images/merlin.gif 17745 ..c. r/rr-xr-xr-x 0 0 5852-128-3 /WINDOWS/system32/oobe/images/monitor.gif 21991 ..c. r/rr-xr-xr-x 0 0 5853-128-3 /WINDOWS/system32/oobe/images/monitor2.gif 2730 ..c. r/rr-xr-xr-x 0 0 5854-128-3 /WINDOWS/system32/oobe/images/mouse.gif 10567 ..c. r/rr-xr-xr-x 0 0 5855-128-3 /WINDOWS/system32/oobe/images/mousewn1.gif 14679 ..c. r/rr-xr-xr-x 0 0 5856-128-3 /WINDOWS/system32/oobe/images/mslogo.jpg 9131 ..c. r/rr-xr-xr-x 0 0 5857-128-3 /WINDOWS/system32/oobe/images/newbtm1.jpg 8727 ..c. r/rr-xr-xr-x 0 0 5858-128-3 /WINDOWS/system32/oobe/images/newbtm8.jpg 56043 ..c. r/rr-xr-xr-x 0 0 5859-128-3 /WINDOWS/system32/oobe/images/newmark1.jpg 38987 ..c. r/rr-xr-xr-x 0 0 5860-128-3 /WINDOWS/system32/oobe/images/newmark8.jpg 8806 ..c. r/rr-xr-xr-x 0 0 5861-128-3 /WINDOWS/system32/oobe/images/newtop1.jpg 8048 ..c. r/rr-xr-xr-x 0 0 5862-128-3 /WINDOWS/system32/oobe/images/newtop8.jpg 3439 ..c. r/rr-xr-xr-x 0 0 5863-128-3 /WINDOWS/system32/oobe/images/nextdown.jpg 2705 ..c. r/rr-xr-xr-x 0 0 5864-128-3 /WINDOWS/system32/oobe/images/nextoff.jpg 3554 ..c. r/rr-xr-xr-x 0 0 5865-128-3 /WINDOWS/system32/oobe/images/nextover.jpg 3539 ..c. r/rr-xr-xr-x 0 0 5866-128-3 /WINDOWS/system32/oobe/images/nextup.jpg 3364 ..c. r/rr-xr-xr-x 0 0 5867-128-3 /WINDOWS/system32/oobe/images/oemcoa.jpg 3343 ..c. r/rr-xr-xr-x 0 0 5868-128-3 /WINDOWS/system32/oobe/images/oemlogo.gif 993 ..c. r/rr-xr-xr-x 0 0 5869-128-3 /WINDOWS/system32/oobe/images/prodkey.gif 34871 ..c. r/rr-xr-xr-x 0 0 587-128-3 /WINDOWS/system32/gpedit.msc 1230 ..c. r/rr-xr-xr-x 0 0 5870-128-3 /WINDOWS/system32/oobe/images/progress.gif 1174050 ..c. r/rr-xr-xr-x 0 0 5871-128-3 /WINDOWS/system32/oobe/images/qmark.acs 2479 ..c. r/rr-xr-xr-x 0 0 5872-128-3 /WINDOWS/system32/oobe/images/qmark.gif 2119 ..c. r/rr-xr-xr-x 0 0 5873-128-3 /WINDOWS/system32/oobe/images/redshd.gif 3556 ..c. r/rr-xr-xr-x 0 0 5874-128-3 /WINDOWS/system32/oobe/images/skipdown.jpg 2759 ..c. r/rr-xr-xr-x 0 0 5875-128-3 /WINDOWS/system32/oobe/images/skipoff.jpg 3485 ..c. r/rr-xr-xr-x 0 0 5876-128-3 /WINDOWS/system32/oobe/images/skipover.jpg 3483 ..c. r/rr-xr-xr-x 0 0 5877-128-3 /WINDOWS/system32/oobe/images/skipup.jpg 38558 ..c. r/rr-xr-xr-x 0 0 5878-128-3 /WINDOWS/system32/oobe/images/thanks10.png 26392 ..c. r/rr-xr-xr-x 0 0 5879-128-3 /WINDOWS/system32/oobe/images/thanks8.png 2624518 ..c. r/rr-xr-xr-x 0 0 5880-128-3 /WINDOWS/system32/oobe/images/title.wma 44244 ..c. r/rr-xr-xr-x 0 0 5881-128-3 /WINDOWS/system32/oobe/images/wpaback.jpg 11746 ..c. r/rr-xr-xr-x 0 0 5882-128-3 /WINDOWS/system32/oobe/images/wpabtm.jpg 5823 ..c. r/rr-xr-xr-x 0 0 5883-128-3 /WINDOWS/system32/oobe/images/wpaflag.jpg 25759 ..c. r/rr-xr-xr-x 0 0 5884-128-3 /WINDOWS/system32/oobe/images/wpakey.jpg 17719 ..c. r/rr-xr-xr-x 0 0 5885-128-3 /WINDOWS/system32/oobe/images/wpatop.jpg 56 .ac. d/dr-xr-xr-x 0 0 5886-144-5 /WINDOWS/system32/oobe/regerror 2909 ..c. r/rr-xr-xr-x 0 0 5887-128-3 /WINDOWS/system32/oobe/regerror/rcnterr.htm 2597 ..c. r/rr-xr-xr-x 0 0 5888-128-3 /WINDOWS/system32/oobe/regerror/rdtone.htm 1895 ..c. r/rr-xr-xr-x 0 0 5889-128-3 /WINDOWS/system32/oobe/regerror/rhndshk.htm 26112 ..c. r/rr-xr-xr-x 0 0 589-128-3 /WINDOWS/system32/graftabl.com 6067 ..c. r/rr-xr-xr-x 0 0 5890-128-3 /WINDOWS/system32/oobe/regerror/rnoansw.htm 1750 ..c. r/rr-xr-xr-x 0 0 5891-128-3 /WINDOWS/system32/oobe/regerror/rnomdm.htm 1769 ..c. r/rr-xr-xr-x 0 0 5892-128-3 /WINDOWS/system32/oobe/regerror/rpberr.htm 2292 ..c. r/rr-xr-xr-x 0 0 5893-128-3 /WINDOWS/system32/oobe/regerror/rpulse.htm 5998 ..c. r/rr-xr-xr-x 0 0 5894-128-3 /WINDOWS/system32/oobe/regerror/rtoobusy.htm 56 .ac. d/dr-xr-xr-x 0 0 5895-144-5 /WINDOWS/system32/oobe/actsetup 3196 ..c. r/rr-xr-xr-x 0 0 5896-128-3 /WINDOWS/system32/oobe/actsetup/actconn.htm 1829 ..c. r/rr-xr-xr-x 0 0 5897-128-3 /WINDOWS/system32/oobe/actsetup/actdone.htm 5579 ..c. r/rr-xr-xr-x 0 0 5898-128-3 /WINDOWS/system32/oobe/actsetup/activ.htm 2018 ..c. r/rr-xr-xr-x 0 0 5899-128-3 /WINDOWS/system32/oobe/actsetup/activerr.htm 56 .ac. d/dr-xr-xr-x 0 0 59-144-5 /WINDOWS/Web/printers 19694 ..c. r/rr-xr-xr-x 0 0 590-128-3 /WINDOWS/system32/graphics.com 8306 ..c. r/rr-xr-xr-x 0 0 5900-128-3 /WINDOWS/system32/oobe/actsetup/activsvc.htm 4171 ..c. r/rr-xr-xr-x 0 0 5901-128-3 /WINDOWS/system32/oobe/actsetup/actlan.htm 18740 ..c. r/rr-xr-xr-x 0 0 5902-128-3 /WINDOWS/system32/oobe/actsetup/adeskerr.htm 4706 ..c. r/rr-xr-xr-x 0 0 5903-128-3 /WINDOWS/system32/oobe/actsetup/adrdyreg.htm 4527 ..c. r/rr-xr-xr-x 0 0 5904-128-3 /WINDOWS/system32/oobe/actsetup/apolicy.htm 4700 ..c. r/rr-xr-xr-x 0 0 5905-128-3 /WINDOWS/system32/oobe/actsetup/aprvcyms.htm 4007 ..c. r/rr-xr-xr-x 0 0 5906-128-3 /WINDOWS/system32/oobe/actsetup/areg1.htm 2182 ..c. r/rr-xr-xr-x 0 0 5907-128-3 /WINDOWS/system32/oobe/actsetup/aregdial.htm 1891 ..c. r/rr-xr-xr-x 0 0 5908-128-3 /WINDOWS/system32/oobe/actsetup/aregdone.htm 2286 ..c. r/rr-xr-xr-x 0 0 5909-128-3 /WINDOWS/system32/oobe/actsetup/aregsty2.css 21232 ..c. r/rr-xr-xr-x 0 0 591-128-3 /WINDOWS/system32/graphics.pro 2277 ..c. r/rr-xr-xr-x 0 0 5910-128-3 /WINDOWS/system32/oobe/actsetup/aregstyl.css 7187 ..c. r/rr-xr-xr-x 0 0 5911-128-3 /WINDOWS/system32/oobe/actsetup/ausrinfo.htm 3972 ..c. r/rr-xr-xr-x 0 0 5912-128-3 /WINDOWS/system32/oobe/html/mouse/mouse.htm 2299 ..c. r/rr-xr-xr-x 0 0 5913-128-3 /WINDOWS/system32/oobe/html/mouse/mouse_a.htm 2338 ..c. r/rr-xr-xr-x 0 0 5914-128-3 /WINDOWS/system32/oobe/html/mouse/mouse_b.htm 3622 ..c. r/rr-xr-xr-x 0 0 5915-128-3 /WINDOWS/system32/oobe/html/mouse/mouse_c.htm 2244 ..c. r/rr-xr-xr-x 0 0 5916-128-3 /WINDOWS/system32/oobe/html/mouse/mouse_d.htm 3663 ..c. r/rr-xr-xr-x 0 0 5917-128-3 /WINDOWS/system32/oobe/html/mouse/mouse_e.htm 2275 ..c. r/rr-xr-xr-x 0 0 5918-128-3 /WINDOWS/system32/oobe/html/mouse/mouse_f.htm 3255 ..c. r/rr-xr-xr-x 0 0 5919-128-3 /WINDOWS/system32/oobe/html/mouse/mouse_g.htm 2837 ..c. r/rr-xr-xr-x 0 0 5920-128-3 /WINDOWS/system32/oobe/html/mouse/mouse_h.htm 3250 ..c. r/rr-xr-xr-x 0 0 5921-128-3 /WINDOWS/system32/oobe/html/mouse/mouse_i.htm 2805 ..c. r/rr-xr-xr-x 0 0 5922-128-3 /WINDOWS/system32/oobe/html/mouse/mouse_j.htm 2729 ..c. r/rr-xr-xr-x 0 0 5923-128-3 /WINDOWS/system32/oobe/html/mouse/mouse_k.htm 56 .ac. d/dr-xr-xr-x 0 0 5924-144-5 /WINDOWS/system32/oobe/html/mouse/images 72921 ..c. r/rr-xr-xr-x 0 0 5925-128-3 /WINDOWS/system32/oobe/html/mouse/images/bulzano.jpg 40046 ..c. r/rr-xr-xr-x 0 0 5926-128-3 /WINDOWS/system32/oobe/html/mouse/images/bulzanom.jpg 1188 ..c. r/rr-xr-xr-x 0 0 5927-128-3 /WINDOWS/system32/oobe/html/mouse/images/but1_dwn.gif 543 ..c. r/rr-xr-xr-x 0 0 5928-128-1 /WINDOWS/system32/oobe/html/mouse/images/but1_idl.gif 1190 ..c. r/rr-xr-xr-x 0 0 5929-128-3 /WINDOWS/system32/oobe/html/mouse/images/but1_up.gif 751 ..c. r/rr-xr-xr-x 0 0 5930-128-3 /WINDOWS/system32/oobe/html/mouse/images/but2_dwn.gif 409 ..c. r/rr-xr-xr-x 0 0 5931-128-1 /WINDOWS/system32/oobe/html/mouse/images/but2_idl.gif 753 ..c. r/rr-xr-xr-x 0 0 5932-128-3 /WINDOWS/system32/oobe/html/mouse/images/but2_up.gif 981 ..c. r/rr-xr-xr-x 0 0 5933-128-3 /WINDOWS/system32/oobe/html/mouse/images/but3_dwn.gif 590 ..c. r/rr-xr-xr-x 0 0 5934-128-1 /WINDOWS/system32/oobe/html/mouse/images/but3_idl.gif 983 ..c. r/rr-xr-xr-x 0 0 5935-128-3 /WINDOWS/system32/oobe/html/mouse/images/but3_up.gif 825 ..c. r/rr-xr-xr-x 0 0 5936-128-3 /WINDOWS/system32/oobe/html/mouse/images/but4_dwn.gif 436 ..c. r/rr-xr-xr-x 0 0 5937-128-1 /WINDOWS/system32/oobe/html/mouse/images/but4_idl.gif 823 ..c. r/rr-xr-xr-x 0 0 5938-128-3 /WINDOWS/system32/oobe/html/mouse/images/but4_up.gif 6829 ..c. r/rr-xr-xr-x 0 0 5939-128-3 /WINDOWS/system32/oobe/html/mouse/images/clicking.gif 17486 ..c. r/rr-xr-xr-x 0 0 5940-128-3 /WINDOWS/system32/oobe/html/mouse/images/desktop3.gif 35268 ..c. r/rr-xr-xr-x 0 0 5941-128-3 /WINDOWS/system32/oobe/html/mouse/images/heidelb.jpg 20512 ..c. r/rr-xr-xr-x 0 0 5942-128-3 /WINDOWS/system32/oobe/html/mouse/images/heidelbm.jpg 47282 ..c. r/rr-xr-xr-x 0 0 5943-128-3 /WINDOWS/system32/oobe/html/mouse/images/mouse4.gif 4361 ..c. r/rr-xr-xr-x 0 0 5944-128-3 /WINDOWS/system32/oobe/html/mouse/images/mouseimg.gif 42189 ..c. r/rr-xr-xr-x 0 0 5945-128-3 /WINDOWS/system32/oobe/html/mouse/images/paris.jpg 25628 ..c. r/rr-xr-xr-x 0 0 5946-128-3 /WINDOWS/system32/oobe/html/mouse/images/parism.jpg 39156 ..c. r/rr-xr-xr-x 0 0 5947-128-3 /WINDOWS/system32/oobe/html/mouse/images/pisa.jpg 22602 ..c. r/rr-xr-xr-x 0 0 5948-128-3 /WINDOWS/system32/oobe/html/mouse/images/pisam.jpg 38850 ..c. r/rr-xr-xr-x 0 0 5949-128-3 /WINDOWS/system32/oobe/html/mouse/images/prague.jpg 4768 ..c. r/rr-xr-xr-x 0 0 595-128-3 /WINDOWS/system32/himem.sys 23646 ..c. r/rr-xr-xr-x 0 0 5950-128-3 /WINDOWS/system32/oobe/html/mouse/images/praguem.jpg 63016 ..c. r/rr-xr-xr-x 0 0 5951-128-3 /WINDOWS/system32/oobe/html/mouse/images/tyrol.jpg 33735 ..c. r/rr-xr-xr-x 0 0 5952-128-3 /WINDOWS/system32/oobe/html/mouse/images/tyrolm.jpg 49251 ..c. r/rr-xr-xr-x 0 0 5953-128-3 /WINDOWS/system32/oobe/html/mouse/images/venice.jpg 27707 ..c. r/rr-xr-xr-x 0 0 5954-128-3 /WINDOWS/system32/oobe/html/mouse/images/venicem.jpg 52203 ..c. r/rr-xr-xr-x 0 0 5955-128-3 /WINDOWS/system32/oobe/html/mouse/images/verona.jpg 30177 ..c. r/rr-xr-xr-x 0 0 5956-128-3 /WINDOWS/system32/oobe/html/mouse/images/veronam.jpg 152 .ac. d/dr-xr-xr-x 0 0 5957-144-1 /WINDOWS/system32/oobe/icserror 3286 ..c. r/rr-xr-xr-x 0 0 5958-128-3 /WINDOWS/system32/oobe/icserror/icsdc.htm 56 .ac. d/dr-xr-xr-x 0 0 5959-144-5 /WINDOWS/system32/oobe/isperror 3359 ..c. r/rr-xr-xr-x 0 0 5960-128-3 /WINDOWS/system32/oobe/isperror/ispcnerr.htm 3015 ..c. r/rr-xr-xr-x 0 0 5961-128-3 /WINDOWS/system32/oobe/isperror/ispdtone.htm 2200 ..c. r/rr-xr-xr-x 0 0 5962-128-3 /WINDOWS/system32/oobe/isperror/isppberr.htm 2310 ..c. r/rr-xr-xr-x 0 0 5963-128-3 /WINDOWS/system32/oobe/isperror/isphdshk.htm 2542 ..c. r/rr-xr-xr-x 0 0 5964-128-3 /WINDOWS/system32/oobe/isperror/ispins.htm 6494 ..c. r/rr-xr-xr-x 0 0 5965-128-3 /WINDOWS/system32/oobe/isperror/ispnoanw.htm 6180 ..c. r/rr-xr-xr-x 0 0 5966-128-3 /WINDOWS/system32/oobe/isperror/ispphbsy.htm 2329 ..c. r/rr-xr-xr-x 0 0 5967-128-3 /WINDOWS/system32/oobe/isperror/ispsbusy.htm 4200 ..c. r/rr-xr-xr-x 0 0 5968-128-3 /WINDOWS/system32/oobe/setup/act_plcy.htm 3815 ..c. r/rr-xr-xr-x 0 0 5969-128-3 /WINDOWS/system32/oobe/setup/acterror.htm 4138 ..c. r/rr-xr-xr-x 0 0 5970-128-3 /WINDOWS/system32/oobe/setup/activate.htm 5443 ..c. r/rr-xr-xr-x 0 0 5971-128-3 /WINDOWS/system32/oobe/setup/au_plcy.htm 5579 ..c. r/rr-xr-xr-x 0 0 5972-128-3 /WINDOWS/system32/oobe/setup/autoupdt.htm 7132 ..c. r/rr-xr-xr-x 0 0 5973-128-3 /WINDOWS/system32/oobe/setup/oobestyl.css 3615 ..c. r/rr-xr-xr-x 0 0 5974-128-3 /WINDOWS/system32/oobe/setup/badeula.htm 4101 ..c. r/rr-xr-xr-x 0 0 5975-128-3 /WINDOWS/system32/oobe/setup/badpkey.htm 5404 ..c. r/rr-xr-xr-x 0 0 5976-128-3 /WINDOWS/system32/oobe/setup/compname.htm 2171 ..c. r/rr-xr-xr-x 0 0 5977-128-3 /WINDOWS/system32/oobe/setup/dialup.htm 5462 ..c. r/rr-xr-xr-x 0 0 5978-128-3 /WINDOWS/system32/oobe/setup/drdyisp.htm 5356 ..c. r/rr-xr-xr-x 0 0 5979-128-3 /WINDOWS/system32/oobe/setup/drdymig.htm 8404 ..c. r/rr-xr-xr-x 0 0 598-128-3 /WINDOWS/system32/wbem/hnetcfg.mof 5337 ..c. r/rr-xr-xr-x 0 0 5980-128-3 /WINDOWS/system32/oobe/setup/drdyoem.htm 7325 ..c. r/rr-xr-xr-x 0 0 5981-128-3 /WINDOWS/system32/oobe/setup/drdyref.htm 926 ..c. r/rr-xr-xr-x 0 0 5982-128-3 /WINDOWS/system32/oobe/setup/dtiwait.htm 3216 ..c. r/rr-xr-xr-x 0 0 5983-128-3 /WINDOWS/system32/oobe/setup/fini.htm 2549 ..c. r/rr-xr-xr-x 0 0 5984-128-3 /WINDOWS/system32/oobe/setup/hnwprmpt.htm 3394 ..c. r/rr-xr-xr-x 0 0 5985-128-3 /WINDOWS/system32/oobe/setup/iconn.htm 7608 ..c. r/rr-xr-xr-x 0 0 5986-128-3 /WINDOWS/system32/oobe/setup/ics.htm 3728 ..c. r/rr-xr-xr-x 0 0 5987-128-3 /WINDOWS/system32/oobe/setup/ident1.htm 8348 ..c. r/rr-xr-xr-x 0 0 5988-128-3 /WINDOWS/system32/oobe/setup/ident2.htm 4739 ..c. r/rr-xr-xr-x 0 0 5989-128-3 /WINDOWS/system32/oobe/setup/isp.htm 14848 ..c. r/rr-xr-xr-x 0 0 599-128-3 /WINDOWS/system32/hnetmon.dll 1143 ..c. r/rr-xr-xr-x 0 0 5990-128-3 /WINDOWS/system32/oobe/setup/ispwait.htm 4072 ..c. r/rr-xr-xr-x 0 0 5991-128-3 /WINDOWS/system32/oobe/setup/jndomain.htm 3306 ..c. r/rr-xr-xr-x 0 0 5992-128-3 /WINDOWS/system32/oobe/setup/jndom_a.htm 4288 ..c. r/rr-xr-xr-x 0 0 5993-128-3 /WINDOWS/system32/oobe/setup/keybd.htm 2865 ..c. r/rr-xr-xr-x 0 0 5994-128-3 /WINDOWS/system32/oobe/setup/keybdcmt.htm 2268 ..c. r/rr-xr-xr-x 0 0 5995-128-3 /WINDOWS/system32/oobe/setup/migdial.htm 4353 ..c. r/rr-xr-xr-x 0 0 5996-128-3 /WINDOWS/system32/oobe/setup/miglist.htm 3619 ..c. r/rr-xr-xr-x 0 0 5997-128-3 /WINDOWS/system32/oobe/setup/migpage.htm 10936 ..c. r/rr-xr-xr-x 0 0 5998-128-3 /WINDOWS/system32/oobe/setup/neweula.htm 3214 ..c. r/rr-xr-xr-x 0 0 5999-128-3 /WINDOWS/system32/oobe/setup/neweula2.htm 520 .ac. d/dr-xr-xr-x 0 0 60-144-1 /WINDOWS/system32/spool/drivers/color 2153 ..c. r/rr-xr-xr-x 0 0 6000-128-3 /WINDOWS/system32/oobe/setup/oempriv.htm 83 ..c. r/rr-xr-xr-x 0 0 6001-128-1 /WINDOWS/system32/oobe/setup/Oobedisc.htm 10971 ..c. r/rr-xr-xr-x 0 0 6002-128-3 /WINDOWS/system32/oobe/setup/prodkey.htm 4864 ..c. r/rr-xr-xr-x 0 0 6003-128-3 /WINDOWS/system32/oobe/setup/prvcyms.htm 9849 ..c. r/rr-xr-xr-x 0 0 6004-128-3 /WINDOWS/system32/oobe/setup/refdial.htm 6457 ..c. r/rr-xr-xr-x 0 0 6005-128-3 /WINDOWS/system32/oobe/setup/reg1.htm 8477 ..c. r/rr-xr-xr-x 0 0 6006-128-3 /WINDOWS/system32/oobe/setup/reg3.htm 2411 ..c. r/rr-xr-xr-x 0 0 6007-128-3 /WINDOWS/system32/oobe/setup/regdial.htm 3700 ..c. r/rr-xr-xr-x 0 0 6008-128-3 /WINDOWS/system32/oobe/setup/security.htm 3099 ..c. r/rr-xr-xr-x 0 0 6009-128-3 /WINDOWS/system32/oobe/setup/timezone.htm 7680 ..c. r/rr-xr-xr-x 0 0 601-128-3 /WINDOWS/system32/hostname.exe 5932 ..c. r/rr-xr-xr-x 0 0 6010-128-3 /WINDOWS/system32/oobe/setup/username.htm 17301 ..c. r/rr-xr-xr-x 0 0 6011-128-3 /WINDOWS/system32/oobe/setup/welcome.htm 272 .ac. d/dr-xr-xr-x 0 0 6012-144-1 /WINDOWS/system32/oobe/html/iconnect 11205 ..c. r/rr-xr-xr-x 0 0 6013-128-3 /WINDOWS/system32/oobe/html/iconnect/iconnect.htm 3362 ..c. r/rr-xr-xr-x 0 0 6014-128-3 /WINDOWS/system32/oobe/html/iconnect/icntlast.htm 360 .ac. d/dr-xr-xr-x 0 0 6015-144-1 /WINDOWS/system32/oobe/html/dslmain 4587 ..c. r/rr-xr-xr-x 0 0 6016-128-3 /WINDOWS/system32/oobe/html/dslmain/dslmain.htm 7746 ..c. r/rr-xr-xr-x 0 0 6017-128-3 /WINDOWS/system32/oobe/html/dslmain/dsl_a.htm 6445 ..c. r/rr-xr-xr-x 0 0 6018-128-3 /WINDOWS/system32/oobe/html/dslmain/dsl_b.htm 152 .ac. d/dr-xr-xr-x 0 0 6019-144-1 /WINDOWS/system32/oobe/html/isptype 5183 ..c. r/rr-xr-xr-x 0 0 6020-128-3 /WINDOWS/system32/oobe/html/isptype/isptype.htm 272 .ac. d/dr-xr-xr-x 0 0 6021-144-1 /WINDOWS/system32/oobe/html/sconnect 3332 ..c. r/rr-xr-xr-x 0 0 6022-128-3 /WINDOWS/system32/oobe/html/sconnect/sconnect.htm 3621 ..c. r/rr-xr-xr-x 0 0 6023-128-3 /WINDOWS/system32/oobe/html/sconnect/scntlast.htm 409088 ..c. r/rr-xr-xr-x 0 0 6046-128-3 /WINDOWS/system32/qmgr.dll 18944 ..c. r/rr-xr-xr-x 0 0 6047-128-3 /WINDOWS/system32/qmgrprxy.dll 8192 ..c. r/rr-xr-xr-x 0 0 6048-128-3 /WINDOWS/system32/bitsprx2.dll 7168 ..c. r/rr-xr-xr-x 0 0 6049-128-3 /WINDOWS/system32/bitsprx3.dll 7168 ..c. r/rr-xr-xr-x 0 0 6050-128-3 /WINDOWS/system32/bitsprx4.dll 430592 ..c. r/rr-xr-xr-x 0 0 6051-128-3 /WINDOWS/system32/wuapi.dll 111104 ..c. r/rr-xr-xr-x 0 0 6052-128-3 /WINDOWS/system32/wuauclt.exe 165888 ..c. r/rr-xr-xr-x 0 0 6053-128-3 /WINDOWS/system32/wuauclt1.exe 162304 ..c. r/rr-xr-xr-x 0 0 6054-128-3 /WINDOWS/system32/wuaucpl.cpl 32256 ..c. r/rr-xr-xr-x 0 0 6055-128-3 /WINDOWS/system32/wups.dll 1135616 ..c. r/rr-xr-xr-x 0 0 6056-128-3 /WINDOWS/system32/wuaueng.dll 183296 ..c. r/rr-xr-xr-x 0 0 6057-128-3 /WINDOWS/system32/wuaueng1.dll 6656 ..c. r/rr-xr-xr-x 0 0 6058-128-3 /WINDOWS/system32/wuauserv.dll 112640 ..c. r/rr-xr-xr-x 0 0 6059-128-3 /WINDOWS/system32/wucltui.dll 120320 ..c. r/rr-xr-xr-x 0 0 6060-128-3 /WINDOWS/system32/wuweb.dll 41472 ..c. r/rr-xr-xr-x 0 0 609-128-3 /WINDOWS/system32/iasads.dll 23392 ..c. r/rr-xr-xr-x 0 0 6090-128-3 /WINDOWS/system32/nscompat.tlb 144 ..c. d/dr-xr-xr-x 0 0 6091-144-1 /WINDOWS/system32/Macromed 664 ..c. d/dr-xr-xr-x 0 0 6096-144-1 /WINDOWS/srchasst 56 .ac. d/dr-xr-xr-x 0 0 61-144-6 /WINDOWS/system32/wbem 23552 ..c. r/rr-xr-xr-x 0 0 610-128-3 /WINDOWS/system32/iasacct.dll 32256 ..c. r/rr-xr-xr-x 0 0 611-128-3 /WINDOWS/system32/iashlpr.dll 62464 ..c. r/rr-xr-xr-x 0 0 612-128-3 /WINDOWS/system32/iasnap.dll 17920 ..c. r/rr-xr-xr-x 0 0 613-128-3 /WINDOWS/system32/iaspolcy.dll 16384 ..c. r/rr-xr-xr-x 0 0 6134-128-3 /WINDOWS/system32/icfgnt5.dll 65 ..c. r/r--x--x--x 0 0 6136-128-1 /WINDOWS/Tasks/desktop.ini 141312 ..c. r/rr-xr-xr-x 0 0 614-128-3 /WINDOWS/system32/iasrecst.dll 86528 ..c. r/rr-xr-xr-x 0 0 615-128-3 /WINDOWS/system32/iassam.dll 247808 ..c. r/rr-xr-xr-x 0 0 616-128-3 /WINDOWS/system32/iassdo.dll 59392 ..c. r/rr-xr-xr-x 0 0 617-128-3 /WINDOWS/system32/iassvcs.dll 64512 ..c. r/rr-xr-xr-x 0 0 6183-128-3 /WINDOWS/system32/acctres.dll 118784 ..c. r/rr-xr-xr-x 0 0 6191-128-3 /WINDOWS/system32/msg723.acm 12288 ..c. r/rr-xr-xr-x 0 0 6192-128-3 /WINDOWS/system32/nmevtmsg.dll 984 ..c. r/rr-xr-xr-x 0 0 6197-128-3 /WINDOWS/system32/Restore/srframe.mmf 47104 ..c. r/rr-xr-xr-x 0 0 6198-128-3 /WINDOWS/system32/Restore/srdiag.exe 248 .ac. d/dr-xr-xr-x 0 0 62-144-1 /WINDOWS/system32/wbem/Repository 830 ..c. r/rr-xr-xr-x 0 0 6225-128-3 /WINDOWS/Web/deskmovr.htt 64 ..c. r/rr-xr-xr-x 0 0 6226-128-1 /WINDOWS/Web/bullet.gif 2642 ..c. r/rr-xr-xr-x 0 0 6227-128-3 /WINDOWS/Web/exclam.gif 56 .ac. d/d--x--x--x 0 0 6228-144-6 /WINDOWS/Web/Wallpaper 77445 ..c. r/rr-xr-xr-x 0 0 6229-128-3 /WINDOWS/Web/Wallpaper/Moon flower.jpg 54784 ..c. r/rr-xr-xr-x 0 0 623-128-3 /WINDOWS/system32/icmui.dll 81433 ..c. r/rr-xr-xr-x 0 0 6230-128-3 /WINDOWS/Web/Wallpaper/Red moon desert.jpg 63871 ..c. r/rr-xr-xr-x 0 0 6231-128-3 /WINDOWS/Web/Wallpaper/Vortec space.jpg 63244 ..c. r/rr-xr-xr-x 0 0 6232-128-3 /WINDOWS/Web/Wallpaper/Ascent.jpg 66287 ..c. r/rr-xr-xr-x 0 0 6233-128-3 /WINDOWS/Web/Wallpaper/Autumn.jpg 62050 ..c. r/rr-xr-xr-x 0 0 6234-128-3 /WINDOWS/Web/Wallpaper/Friend.jpg 42728 ..c. r/rr-xr-xr-x 0 0 6235-128-3 /WINDOWS/Web/Wallpaper/Home.jpg 33780 ..c. r/rr-xr-xr-x 0 0 6236-128-3 /WINDOWS/Web/Wallpaper/Peace.jpg 86685 ..c. r/rr-xr-xr-x 0 0 6237-128-3 /WINDOWS/Web/Wallpaper/Power.jpg 57925 ..c. r/rr-xr-xr-x 0 0 6238-128-3 /WINDOWS/Web/Wallpaper/Purple flower.jpg 44190 ..c. r/rr-xr-xr-x 0 0 6239-128-3 /WINDOWS/Web/Wallpaper/Radiance.jpg 59600 ..c. r/rr-xr-xr-x 0 0 6240-128-3 /WINDOWS/Web/Wallpaper/Stonehenge.jpg 73159 ..c. r/rr-xr-xr-x 0 0 6241-128-3 /WINDOWS/Web/Wallpaper/Tulips.jpg 37246 ..c. r/rr-xr-xr-x 0 0 6242-128-3 /WINDOWS/Web/Wallpaper/Wind.jpg 63655 ..c. r/rr-xr-xr-x 0 0 6243-128-3 /WINDOWS/Web/Wallpaper/Crystal.jpg 58589 ..c. r/rr-xr-xr-x 0 0 6244-128-3 /WINDOWS/Web/Wallpaper/Ripple.jpg 61365 ..c. r/rr-xr-xr-x 0 0 6245-128-3 /WINDOWS/Web/Wallpaper/Azul.jpg 50511 ..c. r/rr-xr-xr-x 0 0 6246-128-3 /WINDOWS/Web/Wallpaper/Follow.jpg 56772 ..c. r/rr-xr-xr-x 0 0 6248-128-3 /WINDOWS/Web/Wallpaper/Windows XP.jpg 2 ..c. r/rr-xr-xr-x 0 0 6249-128-1 /WINDOWS/desktop.ini 2 ..c. r/rr-xr-xr-x 0 0 6250-128-1 /WINDOWS/system32/desktop.ini 11264 ..c. r/rr-xr-xr-x 0 0 6265-128-3 /WINDOWS/system32/atrace.dll 21538 ..c. r/rr-xr-xr-x 0 0 627-128-3 /WINDOWS/system32/wbem/ieinfo5.mof 221184 ..c. r/rr-xr-xr-x 0 0 629-128-3 /WINDOWS/system32/ieakui.dll 48 ..c. d/dr-xr-xr-x 0 0 63-144-1 /WINDOWS/addins 144 ..c. d/dr-xr-xr-x 0 0 6328-144-1 /WINDOWS/system32/DirectX 70656 ..c. r/rr-xr-xr-x 0 0 636-128-3 /WINDOWS/system32/ifsutil.dll 9216 ..c. r/rr-xr-xr-x 0 0 639-128-3 /WINDOWS/system32/iissuba.dll 48 ..c. d/dr-xr-xr-x 0 0 64-144-1 /WINDOWS/Connection Wizard 110592 ..c. r/rr-xr-xr-x 0 0 643-128-3 /WINDOWS/system32/inetcplc.dll 450560 ..c. r/rr-xr-xr-x 0 0 644-128-3 /WINDOWS/system32/infosoft.dll 30720 ..c. r/rr-xr-xr-x 0 0 647-128-3 /WINDOWS/system32/iologmsg.dll 144 ..c. d/dr-xr-xr-x 0 0 65-144-1 /WINDOWS/Driver Cache 11114 ..c. r/rr-xr-xr-x 0 0 650-128-3 /WINDOWS/Web/printers/ipp_0000.inc 1518 ..c. r/rr-xr-xr-x 0 0 651-128-3 /WINDOWS/Web/printers/images/ipp_0002.gif 369 ..c. r/rr-xr-xr-x 0 0 652-128-1 /WINDOWS/Web/printers/ipp_0003.asp 899 ..c. r/rr-xr-xr-x 0 0 653-128-3 /WINDOWS/Web/printers/images/ipp_0003.gif 895 ..c. r/rr-xr-xr-x 0 0 654-128-3 /WINDOWS/Web/printers/images/ipp_0004.gif 255 ..c. r/rr-xr-xr-x 0 0 655-128-1 /WINDOWS/Web/printers/images/ipp_0005.gif 749 ..c. r/r--x--x--x 0 0 6554-128-4 /WINDOWS/system32/ncpa.cpl.manifest 749 ..c. r/r--x--x--x 0 0 6555-128-4 /WINDOWS/system32/nwc.cpl.manifest 749 ..c. r/r--x--x--x 0 0 6556-128-4 /WINDOWS/system32/sapi.cpl.manifest 749 ..c. r/r--x--x--x 0 0 6557-128-4 /WINDOWS/system32/wuaucpl.cpl.manifest 749 ..c. r/r--x--x--x 0 0 6558-128-4 /WINDOWS/system32/cdplayer.exe.manifest 749 ..c. r/r--x--x--x 0 0 6559-128-4 /WINDOWS/WindowsShell.Manifest 1265 ..c. r/rr-xr-xr-x 0 0 656-128-3 /WINDOWS/Web/printers/images/ipp_0012.gif 488 ..c. r/r--x--x--x 0 0 6562-128-1 /WINDOWS/system32/logonui.exe.manifest 488 ..c. r/r--x--x--x 0 0 6563-128-1 /WINDOWS/system32/WindowsLogon.manifest 152 ..c. d/d--x--x--x 0 0 6566-144-1 /WINDOWS/Offline Web Pages 1440054 ..c. r/rr-xr-xr-x 0 0 6569-128-3 /WINDOWS/Web/Wallpaper/Bliss.bmp 570 ..c. r/rr-xr-xr-x 0 0 657-128-1 /WINDOWS/Web/printers/ipp_0015.asp 902 ..c. r/rr-xr-xr-x 0 0 658-128-3 /WINDOWS/Web/printers/images/ipp_0015.gif 520 ..c. r/rr-xr-xr-x 0 0 659-128-1 /WINDOWS/Web/printers/ipp_adsi.inc 428 ..c. r/rr-xr-xr-x 0 0 660-128-1 /WINDOWS/Web/printers/ipp_res.inc 3584 ..c. r/rr-xr-xr-x 0 0 661-128-3 /WINDOWS/system32/iprop.dll 4096 ..c. r/rr-xr-xr-x 0 0 662-128-3 /WINDOWS/system32/iprtprio.dll 44032 ..c. r/rr-xr-xr-x 0 0 663-128-3 /WINDOWS/system32/ipsec6.exe 83968 ..c. r/rr-xr-xr-x 0 0 666-128-3 /WINDOWS/system32/ipxmontr.dll 69120 ..c. r/rr-xr-xr-x 0 0 667-128-3 /WINDOWS/system32/ipxpromn.dll 21504 ..c. r/rr-xr-xr-x 0 0 668-128-3 /WINDOWS/system32/ipxrip.dll 39936 ..c. r/rr-xr-xr-x 0 0 669-128-3 /WINDOWS/system32/ipxrtmgr.dll 56 ..c. d/dr-xr-xr-x 0 0 67-144-5 /WINDOWS/security 66560 ..c. r/rr-xr-xr-x 0 0 670-128-3 /WINDOWS/system32/ipxsap.dll 199168 ..c. r/rr-xr-xr-x 0 0 671-128-3 /WINDOWS/system32/ir32_32.dll 105264 ..c. r/rr-xr-xr-x 0 0 6798-128-3 /WINDOWS/system32/psfile.exe 362496 ..c. r/rr-xr-xr-x 0 0 680-128-3 /WINDOWS/system32/jet500.dll 44544 ..c. r/rr-xr-xr-x 0 0 681-128-3 /WINDOWS/system32/jgaw400.dll 35840 ..c. r/rr-xr-xr-x 0 0 682-128-3 /WINDOWS/system32/jgmd400.dll 45568 ..c. r/rr-xr-xr-x 0 0 683-128-3 /WINDOWS/system32/jgsd400.dll 65536 ..c. r/rr-xr-xr-x 0 0 684-128-3 /WINDOWS/system32/jgsh400.dll 47952 ..c. r/rr-xr-xr-x 0 0 685-128-3 /WINDOWS/system32/jobexec.dll 14710 ..c. r/rr-xr-xr-x 0 0 687-128-3 /WINDOWS/system32/kb16.com 6144 ..c. r/rr-xr-xr-x 0 0 688-128-3 /WINDOWS/system32/kbdbe.dll 6144 ..c. r/rr-xr-xr-x 0 0 689-128-3 /WINDOWS/system32/kbdbene.dll 264 .ac. d/dr-xr-xr-x 0 0 69-144-1 /WINDOWS/system32/npp 6144 ..c. r/rr-xr-xr-x 0 0 690-128-3 /WINDOWS/system32/kbdbr.dll 6144 ..c. r/rr-xr-xr-x 0 0 691-128-3 /WINDOWS/system32/kbdca.dll 7680 ..c. r/rr-xr-xr-x 0 0 692-128-3 /WINDOWS/system32/kbdcan.dll 6144 ..c. r/rr-xr-xr-x 0 0 693-128-3 /WINDOWS/system32/kbdda.dll 5120 ..c. r/rr-xr-xr-x 0 0 694-128-3 /WINDOWS/system32/kbddv.dll 6144 ..c. r/rr-xr-xr-x 0 0 695-128-3 /WINDOWS/system32/kbdes.dll 6144 ..c. r/rr-xr-xr-x 0 0 696-128-3 /WINDOWS/system32/kbdfc.dll 6144 ..c. r/rr-xr-xr-x 0 0 697-128-3 /WINDOWS/system32/kbdfi.dll 6144 ..c. r/rr-xr-xr-x 0 0 698-128-3 /WINDOWS/system32/kbdfo.dll 6144 ..c. r/rr-xr-xr-x 0 0 699-128-3 /WINDOWS/system32/kbdfr.dll 248 ..c. d/dr-xr-xr-x 0 0 70-144-1 /WINDOWS/system32/ias 5632 ..c. r/rr-xr-xr-x 0 0 700-128-3 /WINDOWS/system32/kbdgae.dll 6144 ..c. r/rr-xr-xr-x 0 0 701-128-3 /WINDOWS/system32/kbdgr.dll 6144 ..c. r/rr-xr-xr-x 0 0 702-128-3 /WINDOWS/system32/kbdgr1.dll 6144 ..c. r/rr-xr-xr-x 0 0 703-128-3 /WINDOWS/system32/kbdic.dll 5632 ..c. r/rr-xr-xr-x 0 0 704-128-3 /WINDOWS/system32/kbdir.dll 5632 ..c. r/rr-xr-xr-x 0 0 705-128-3 /WINDOWS/system32/kbdit.dll 5632 ..c. r/rr-xr-xr-x 0 0 706-128-3 /WINDOWS/system32/kbdit142.dll 6656 ..c. r/rr-xr-xr-x 0 0 707-128-3 /WINDOWS/system32/kbdla.dll 6144 ..c. r/rr-xr-xr-x 0 0 708-128-3 /WINDOWS/system32/kbdmac.dll 6144 ..c. r/rr-xr-xr-x 0 0 709-128-3 /WINDOWS/system32/kbdne.dll 6144 ..c. r/rr-xr-xr-x 0 0 710-128-3 /WINDOWS/system32/kbdno.dll 6144 ..c. r/rr-xr-xr-x 0 0 711-128-3 /WINDOWS/system32/kbdpo.dll 6144 ..c. r/rr-xr-xr-x 0 0 712-128-3 /WINDOWS/system32/kbdsf.dll 6656 ..c. r/rr-xr-xr-x 0 0 713-128-3 /WINDOWS/system32/kbdsg.dll 6144 ..c. r/rr-xr-xr-x 0 0 714-128-3 /WINDOWS/system32/kbdsp.dll 6144 ..c. r/rr-xr-xr-x 0 0 715-128-3 /WINDOWS/system32/kbdsw.dll 5632 ..c. r/rr-xr-xr-x 0 0 716-128-3 /WINDOWS/system32/kbduk.dll 6144 ..c. r/rr-xr-xr-x 0 0 717-128-3 /WINDOWS/system32/kbdusl.dll 6144 ..c. r/rr-xr-xr-x 0 0 718-128-3 /WINDOWS/system32/kbdusr.dll 6144 ..c. r/rr-xr-xr-x 0 0 719-128-3 /WINDOWS/system32/kbdusx.dll 48 .ac. d/dr-xr-xr-x 0 0 72-144-6 /WINDOWS/Temp 42809 ..c. r/rr-xr-xr-x 0 0 722-128-3 /WINDOWS/system32/key01.sys 2000 ..c. r/rr-xr-xr-x 0 0 725-128-3 /WINDOWS/system32/keyboard.drv 174020 ..c. r/rr-xr-xr-x 0 0 728-128-3 /WINDOWS/system32/spool/drivers/color/kodak_dc.icm 168 ..c. r/rr-xr-xr-x 0 0 729-128-1 /WINDOWS/system32/l_except.nls 720 .ac. d/dr-xr-xr-x 0 0 73-144-1 /WINDOWS/Web/printers/images 9728 ..c. r/rr-xr-xr-x 0 0 730-128-3 /WINDOWS/system32/label.exe 89600 ..c. r/rr-xr-xr-x 0 0 732-128-3 /WINDOWS/system32/langwrbk.dll 221600 ..c. r/rr-xr-xr-x 0 0 733-128-3 /WINDOWS/system32/lanman.drv 29696 ..c. r/rr-xr-xr-x 0 0 735-128-3 /WINDOWS/system32/lights.exe 1131 ..c. r/rr-xr-xr-x 0 0 737-128-3 /WINDOWS/system32/loadfix.com 48 ..c. d/dr-xr-xr-x 0 0 74-144-1 /WINDOWS/system32/export 5120 ..c. r/rr-xr-xr-x 0 0 740-128-3 /WINDOWS/system32/lodctr.exe 50176 ..c. r/rr-xr-xr-x 0 0 741-128-3 /WINDOWS/system32/loghours.dll 6144 ..c. r/rr-xr-xr-x 0 0 744-128-3 /WINDOWS/system32/lpq.exe 8192 ..c. r/rr-xr-xr-x 0 0 745-128-3 /WINDOWS/system32/lpr.exe 9216 ..c. r/rr-xr-xr-x 0 0 746-128-3 /WINDOWS/system32/lprmonui.dll 42166 ..c. r/rr-xr-xr-x 0 0 748-128-3 /WINDOWS/system32/lusrmgr.msc 232 .ac. d/dr-xr-xr-x 0 0 75-144-1 /WINDOWS/system32/wbem/mof 9936 ..c. r/rr-xr-xr-x 0 0 751-128-3 /WINDOWS/system32/lzexpand.dll 8192 ..c. r/rr-xr-xr-x 0 0 752-128-3 /WINDOWS/system32/mag_hook.dll 8820 ..c. r/rr-xr-xr-x 0 0 7536-128-4 /WINDOWS/system32/wbem/AutoRecover/6FFF7467A5B40765D5740A413CA8BB8A.mof 112128 ..c. r/rr-xr-xr-x 0 0 7542-128-3 /WINDOWS/system32/mapi32.dll 833 ..c. r/rr-xr-xr-x 0 0 7543-128-3 /WINDOWS/OEWABLog.txt 316640 ..c. r/rr-xr-xr-x 0 0 7551-128-3 /WINDOWS/WMSysPr9.prx 16832 ..c. r/rr-xr-xr-x 0 0 7553-128-3 /WINDOWS/system32/amcompat.tlb 187904 ..c. r/rr-xr-xr-x 0 0 756-128-3 /WINDOWS/system32/main.cpl 112128 ..c. r/rr-xr-xr-x 0 0 757-128-3 /WINDOWS/system32/mapistub.dll 0 ..c. r/rr-xr-xr-x 0 0 7570-128-1 /CONFIG.SYS 0 ..c. r/rr-xr-xr-x 0 0 7571-128-1 /AUTOEXEC.BAT 0 ..c. r/rr-xr-xr-x 0 0 7574-128-1 /WINDOWS/control.ini 2577 ..c. r/rr-xr-xr-x 0 0 7575-128-3 /WINDOWS/system32/CONFIG.NT 10240 ..c. r/rr-xr-xr-x 0 0 759-128-3 /WINDOWS/system32/mcd32.dll 48 .ac. d/dr-xr-xr-x 0 0 76-144-1 /WINDOWS/system32/wbem/mof/good 10496 ..c. r/rr-xr-xr-x 0 0 760-128-3 /WINDOWS/system32/mcdsrv32.dll 4608 ..c. r/rr-xr-xr-x 0 0 761-128-3 /WINDOWS/system32/mchgrcoi.dll 73376 ..c. r/rr-xr-xr-x 0 0 762-128-3 /WINDOWS/system32/mciavi.drv 17408 ..c. r/rr-xr-xr-x 0 0 763-128-3 /WINDOWS/system32/mcicda.dll 48 .ac. d/dr-xr-xr-x 0 0 7632-144-1 /WINDOWS/system32/xircom 48 .ac. d/dr-xr-xr-x 0 0 7637-144-1 /WINDOWS/system32/wbem/snmp 8192 ..c. r/rr-xr-xr-x 0 0 764-128-3 /WINDOWS/system32/mciole16.dll 7680 ..c. r/rr-xr-xr-x 0 0 765-128-3 /WINDOWS/system32/mciole32.dll 25264 ..c. r/rr-xr-xr-x 0 0 766-128-3 /WINDOWS/system32/mciseq.drv 28160 ..c. r/rr-xr-xr-x 0 0 767-128-3 /WINDOWS/system32/mciwave.drv 50176 ..c. r/rr-xr-xr-x 0 0 768-128-3 /WINDOWS/system32/mdhcp.dll 48 .ac. d/dr-xr-xr-x 0 0 77-144-1 /WINDOWS/system32/wbem/mof/bad 152 .ac. d/dr-xr-xr-x 0 0 78-144-1 /WINDOWS/twain_32 144 ..c. d/dr-xr-xr-x 0 0 79-144-1 /WINDOWS/msapps 568 ..c. d/dr-xr-xr-x 0 0 83-144-1 /WINDOWS/system32/icsxml 56 .ac. d/dr-xr-xr-x 0 0 84-144-5 /WINDOWS/system32/mui 160 ..c. d/dr-xr-xr-x 0 0 85-144-1 /WINDOWS/system32/mui/0009 48 .ac. d/dr-xr-xr-x 0 0 86-144-1 /WINDOWS/system32/mui/dispspec 56 ..c. d/dr-xr-xr-x 0 0 87-144-5 /WINDOWS/AppPatch 480 ..c. d/dr-xr-xr-x 0 0 88-144-1 /WINDOWS/Debug 168 .ac. d/dr-xr-xr-x 0 0 90-144-5 /WINDOWS/system32/oobe 144 ..c. d/dr-xr-xr-x 0 0 92-144-1 /WINDOWS/Resources 147968 ..c. r/rr-xr-xr-x 0 0 921-128-3 /WINDOWS/system32/mdwmdmsp.dll 39274 ..c. r/rr-xr-xr-x 0 0 922-128-3 /WINDOWS/system32/mem.exe 924432 ..c. r/rr-xr-xr-x 0 0 927-128-3 /WINDOWS/system32/mfc40.dll 46258 ..c. r/rr-xr-xr-x 0 0 931-128-3 /WINDOWS/system32/mib.bin 673088 ..c. r/rr-xr-xr-x 0 0 933-128-3 /WINDOWS/system32/mlang.dat 3584 ..c. r/rr-xr-xr-x 0 0 934-128-3 /WINDOWS/system32/mll_hp.dll 7680 ..c. r/rr-xr-xr-x 0 0 935-128-3 /WINDOWS/system32/mll_mtf.dll 5632 ..c. r/rr-xr-xr-x 0 0 936-128-3 /WINDOWS/system32/mll_qic.dll 1492 ..c. r/rr-xr-xr-x 0 0 939-128-3 /WINDOWS/system32/mmdriver.inf 12288 ..c. r/rr-xr-xr-x 0 0 940-128-3 /WINDOWS/system32/mmdrv.dll 1152 ..c. r/rr-xr-xr-x 0 0 941-128-3 /WINDOWS/system32/mmtask.tsk 119808 ..c. r/rr-xr-xr-x 0 0 942-128-3 /WINDOWS/system32/mmutilse.dll 19456 ..c. r/rr-xr-xr-x 0 0 945-128-3 /WINDOWS/system32/mode.com 10112 ..c. r/rr-xr-xr-x 0 0 948-128-3 /WINDOWS/system32/modex.dll 8192 ..c. r/rr-xr-xr-x 0 0 957-128-3 /WINDOWS/system32/mountvol.exe 2032 ..c. r/rr-xr-xr-x 0 0 959-128-3 /WINDOWS/system32/mouse.drv 22016 ..c. r/rr-xr-xr-x 0 0 963-128-3 /WINDOWS/system32/mpnotify.exe 69120 ..c. r/rr-xr-xr-x 0 0 964-128-3 /WINDOWS/system32/mprddm.dll 99840 ..c. r/rr-xr-xr-x 0 0 965-128-3 /WINDOWS/system32/mprmsg.dll 10752 ..c. r/rr-xr-xr-x 0 0 966-128-3 /WINDOWS/system32/mqcertui.dll 60928 ..c. r/rr-xr-xr-x 0 0 967-128-3 /WINDOWS/system32/mqgentr.dll 81408 ..c. r/rr-xr-xr-x 0 0 968-128-3 /WINDOWS/system32/mqoa.tlb 36864 ..c. r/rr-xr-xr-x 0 0 969-128-3 /WINDOWS/system32/mqoa10.tlb 56 .ac. d/dr-xr-xr-x 0 0 97-144-5 /WINDOWS/system32/oobe/html 55296 ..c. r/rr-xr-xr-x 0 0 970-128-3 /WINDOWS/system32/mqoa20.tlb 8192 ..c. r/rr-xr-xr-x 0 0 971-128-3 /WINDOWS/system32/mqperf.dll 10110 ..c. r/rr-xr-xr-x 0 0 972-128-3 /WINDOWS/system32/mqperf.ini 2755 ..c. r/rr-xr-xr-x 0 0 973-128-3 /WINDOWS/system32/mqprfsym.h 12800 ..c. r/rr-xr-xr-x 0 0 976-128-3 /WINDOWS/system32/mrinfo.exe 102912 ..c. r/rr-xr-xr-x 0 0 977-128-3 /WINDOWS/system32/msaatext.dll 61168 ..c. r/rr-xr-xr-x 0 0 978-128-3 /WINDOWS/system32/msacm.dll 65024 ..c. r/rr-xr-xr-x 0 0 979-128-3 /WINDOWS/system32/msaudite.dll 48 .ac. d/dr-xr-xr-x 0 0 98-144-1 /WINDOWS/system32/oobe/html/ispsgnup 7168 ..c. r/rr-xr-xr-x 0 0 980-128-3 /WINDOWS/system32/mscat32.dll 817 ..c. r/rr-xr-xr-x 0 0 981-128-3 /WINDOWS/system32/mscdexnt.exe 1405 ..c. r/rr-xr-xr-x 0 0 985-128-3 /WINDOWS/msdfmap.ini 94282 ..c. r/rr-xr-xr-x 0 0 987-128-3 /WINDOWS/system32/msencode.dll 9216 ..c. r/rr-xr-xr-x 0 0 988-128-3 /WINDOWS/system32/msg711.acm 19968 ..c. r/rr-xr-xr-x 0 0 989-128-3 /WINDOWS/system32/msgsm32.acm 56 .ac. d/dr-xr-xr-x 0 0 99-144-5 /WINDOWS/system32/oobe/html/mouse 146432 ..c. r/rr-xr-xr-x 0 0 993-128-3 /WINDOWS/system32/msls31.dll Fri Jul 01 2011 15:09:01 22984 mac. r/rrwxrwxrwx 0 0 11161-128-4 /WINDOWS/Prefetch/ATTRIB.EXE-39EAFB02.pf Fri Jul 01 2011 15:09:06 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Internet Explorer/Main 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{E2E2DD38-D088-4134-82B7-F2BA38496583}/iexplore 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{FB5F1910-F110-11D2-BB9E-00C04F795683}/iexplore 105 mac. r/rrwxrwxrwx 0 0 10315-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/ac3[1].htm 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.findfertile.org/ac3.php?aid=531&sid=direc20 cache stored in: SLK18LSF/ac3[1].htm - HTTP/1.1 200 OK - Content-Length: 105 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://www.findfertile.org/ac3.php?aid=531&sid=direc20 (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 32768 m... r/rr-xr-xr-x 0 0 10638-128-3 /Documents and Settings/malware/Local Settings/History/History.IE5/MSHist012011070120110702/index.dat Fri Jul 01 2011 15:09:21 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://www.mevio.com/episode/286410/le-monnier-my-heart (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 0 m... 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:www.mevio.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) Fri Jul 01 2011 15:09:22 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/15992/episodes/286643/thumbs/gamesweaseltv-us-e.jpg?r=1309448670 cache stored in: QJM5KT6J/gamesweaseltv-us-e[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 1879 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/19758/shows/thumbs/techhijack.png?r=1254097773 cache stored in: UPQVMROL/techhijack[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 9270 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 1879 macb r/rrwxrwxrwx 0 0 11281-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/gamesweaseltv-us-e[1].jpg 9270 macb r/rrwxrwxrwx 0 0 11340-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/techhijack[1].png 598195 ...b r/rrwxrwxrwx 0 0 11457-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/ladyfest-band1[1].jpg Fri Jul 01 2011 15:09:23 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/shows/static/css/images/mevio-megahit.jpg?r=38841 cache stored in: QJM5KT6J/mevio-megahit[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 5012 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/shows/static/css/images/success-checkmark.png?r=38841 cache stored in: YZCXGNW1/success-checkmark[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 1039 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.le-monnier.co.uk/wp-content/gallery/gig-ladyfest-southend-on-sea-essex-11th-june-2011/ladyfest-band1.jpg cache stored in: UPQVMROL/ladyfest-band1[1].jpg - HTTP/1.1 200 OK - ETag: "14d4003f-920b3-4a58718dac0c0" - Content-Length: 598195 - Keep-Alive: timeout=2- max=100 - Content-Type: image/jpeg (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 598195 mac. r/rrwxrwxrwx 0 0 11457-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/ladyfest-band1[1].jpg Fri Jul 01 2011 15:09:24 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://www.findfertile.org/go.php?userip=198.176.229.10&referer=http://www.findfertile.org/search.php?q=james+bond&aid=531&sid=direc20&curl=http://64.111.211.158/c.php?s=eNotU9muqkoQ_SCTTQ9A0w_7QRAHBGUU5OWGZlBmEEQ0fPzxnNys1JBKrVSlUqtYEOYhXCReWk6uMeu-3cX1pTCK9e8CfgDA5F8QBbwgACEgXycBCeMlqrdjGBi3a02f4fr3d4kpD6AAIEUJQTSLgCCKSKISYDwQMcP_RXHyTRkDGEf0L1hMGGQ8xDGMvjMWCOAiLOmpvZQ7OtWf9XXecCepOEInGapS1DX5_nTukYVW571Zv8sZGuJtY41e8iAU6QMRM4cAWnW7hpfMKx5XERm9KQmwWxEyPqup-e6eTHMvcLtGMgWzQYii52cOcrhiQtQckvtp2Pe71Nyu9n5I04PIzG09xW4WCIk8bKt8PG24w1vilW2k0-YsmiTkPnduXClwXdGxGbgbYVOm2OG7FNymOAfOayu-hBAf20rTMtnuPnxxn1YX-RDqTTvFhC89Oe1nLT1tFfHm8ZdDrBl8CZjzBiwOJvNl0-v65rdcMObC-5WXQ1O3q_vOTWMFZ3FvfRyH7cHt3RnDq22PXqDK1tXuy1o5HBDtDXlE9EzUTm0-M7AOttUboN_Di6ddvHWhK-V9a6xogRszTVAl3319ptrVOl7V1EjXonp9fNaNFz8MLnP2p5tbJ1rpd71mGZ8W55EXzQbbDOF5oBFpTNv1XgorNH_g3n0i7sfkFiQPqV-ZnX2ebRsZ1ubQPVbV2pBsPfPPKvZ63Z128v1khSW0zxNt0rNhzLIgF_uXO0yt-vRNlS_QDXW24nhRpRuzZ8S0vIfdLj7SFl3c-HJ-3BJ5_p6izV3HiQ81EXGmnN4nWafr0Xw-ZHXac34lHbtj-fFHuukc4M4f-Wk6T3iV0-dRna79Ptdys8O2BXunDY1boOakfhTzuMmGy4YXnSsqYj_Luq1aVsojDx8TlbnGRTn4XSCVfiARf76v9QPBskCJ_4HC10T8Aym__C3BJcEJ1utLmfine7KrJpYLBUNfOviHBf_fEXastusw0EDkz5Ve03f4-qqNQIKlTGSYMYnQJEUgojyNcMwkPkshv4gZSyNAJCQQPuV5kccgScQMi19ZJjEifwBxvEd7&aid=531&sid=direc20 (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) Fri Jul 01 2011 15:09:25 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://search.clickwhale.com/results/?partnerid=113973&appid=23411&subid=&ip=198.176.229.10&cid=251223&entry=james bond&qs=JQwDFAMXaSFTVkVJQEdaSRpYUURuW0sTAwFFeFpWR0hFQlxcSFNAVTZUXV5cVBB9VkUWC01ER19eGRcRdQofTVxLEHVWVUJfHhZUX0ARERdmWkscBQEdcllUS0BDRE8LAUxASD1UBQQYFQV2D0ZAH1VGDxgZVg9ENxwOERgMTytAAB0UVgUcChxYHBU2WQhEWVMQdFpWExxFFlkMWBQUEGtPHARRVBN1V1ZHQUFFW0kFVhxTPAdLEwcSHWMcBhREVgYHBFMSB1UgGhkRCwxEeFxTQktERV1dSEZETicIChkIWBJ3XlZLXwUGBVIGVVVRdloMVV4DBXcIFAUOXhENGg1AVUg8B0MTAwgFdwgVGx0VG0xdCEZOVTwEAh1JV0ZgXQUREBRRWgtYExERY0ddQFxUBXdYFgYULwcGGhxCRARgDQwUAwt_dF9QS05DK1tcWhAQfnZbWwUYCH8oCwcbDB1RWgsNUUIEYV8YBAE6QyQDExMQFxpMXApkRVQwCBkZAwsOJgEOXykRBgwBGkhPRgUACRUDFg== cache stored in: SLK18LSF/CAN3LL82.htm - HTTP/1.1 200 OK - Content-Type: text/html_charset=ISO-8859-1 - Content-Length: 5325 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://click.mygeek.com/presults.jsp?partnerid=113973&appid=23411&subid=&ip=198.176.229.10&cid=251223&entry=james bond&qs=JQwDFAMXaSFTVkVJQEdaSRpYUURuW0sTAwFFeFpWR0hFQlxcSFNAVTZUXV5cVBB9VkUWC01ER19eGRcRdQofTVxLEHVWVUJfHhZUX0ARERdmWkscBQEdcllUS0BDRE8LAUxASD1UBQQYFQV2D0ZAH1VGDxgZVg9ENxwOERgMTytAAB0UVgUcChxYHBU2WQhEWVMQdFpWExxFFlkMWBQUEGtPHARRVBN1V1ZHQUFFW0kFVhxTPAdLEwcSHWMcBhREVgYHBFMSB1UgGhkRCwxEeFxTQktERV1dSEZETicIChkIWBJ3XlZLXwUGBVIGVVVRdloMVV4DBXcIFAUOXhENGg1AVUg8B0MTAwgFdwgVGx0VG0xdCEZOVTwEAh1JV0ZgXQUREBRRWgtYExERY0ddQFxUBXdYFgYULwcGGhxCRARgDQwUAwt_dF9QS05DK1tcWhAQfnZbWwUYCH8oCwcbDB1RWgsNUUIEYV8YBAE6QyQDExMQFxpMXApkRVQwCBkZAwsOJgEOXykRBgwBGkhPRgUACRUDFg==&REFERER=http://www.findfertile.org/ac3.php?q=james+bond&aid=531&sid=direc20&POS=128x261&VIEWPORT=571x257&IFRAME=N&COOKIES=Y&RES=800x600 (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:mygeek.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:search.clickwhale.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 93 macb r/rrwxrwxrwx 0 0 11377-128-1 /Documents and Settings/malware/Cookies/malware@search.clickwhale[1].txt 5325 macb r/rrwxrwxrwx 0 0 11681-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/CAN3LL82.htm 559 macb r/rrwxrwxrwx 0 0 11689-128-1 /Documents and Settings/malware/Cookies/malware@mygeek[1].txt Fri Jul 01 2011 15:09:26 6351 macb r/rrwxrwxrwx 0 0 11701-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/globalbundle[2].js 18633 macb r/rrwxrwxrwx 0 0 11702-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/ie6[2].css 129171 macb r/rrwxrwxrwx 0 0 11703-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/all[2].js 3222 macb r/rrwxrwxrwx 0 0 11705-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/video[2].css 2489 macb r/rrwxrwxrwx 0 0 11706-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/print[1].css 138439 macb r/rrwxrwxrwx 0 0 11707-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/all[1].css 6656 macb r/rrwxrwxrwx 0 0 11709-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/ie67[2].css 102489 macb r/rrwxrwxrwx 0 0 11711-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/mootools-1.2.1-all[2].js 285 ...b r/rrwxrwxrwx 0 0 11794-128-1 /Documents and Settings/malware/Cookies/malware@www.education[1].txt Fri Jul 01 2011 15:09:27 48 .a.. d/drwxrwxrwx 0 0 10477-144-1 /Documents and Settings/malware/Application Data/Microsoft/SystemCertificates/My/CTLs 48 .a.. d/drwxrwxrwx 0 0 10478-144-1 /Documents and Settings/malware/Application Data/Microsoft/SystemCertificates/My/CRLs 48 .a.. d/drwxrwxrwx 0 0 10479-144-1 /Documents and Settings/malware/Application Data/Microsoft/SystemCertificates/My/Certificates 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/themes/sky/i/boxes/box-simple-beige-inner.gif cache stored in: SLK18LSF/box-simple-beige-inner[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Cache: HIT - Content-Length: 3295 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:educationcom.112.2o7.net/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 1552 macb r/rrwxrwxrwx 0 0 11700-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/gradient-sprite-x[1].png 8565 macb r/rrwxrwxrwx 0 0 11704-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/actions-sprite[1].png 34011 macb r/rrwxrwxrwx 0 0 11708-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/s_code[2].js 9540 macb r/rrwxrwxrwx 0 0 11710-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/4thofjuly[1].png 14366 macb r/rrwxrwxrwx 0 0 11712-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/header-sprite[1].png 123 macb r/rrwxrwxrwx 0 0 11713-128-1 /Documents and Settings/malware/Cookies/malware@educationcom.112.2o7[1].txt 5115 macb r/rrwxrwxrwx 0 0 11714-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/Loading_30[1].jpg 1558 macb r/rrwxrwxrwx 0 0 11715-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/flex-button-orange-corners2[1].gif 122190 macb r/rrwxrwxrwx 0 0 11716-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/featured-thing[1].htm 33606 macb r/rrwxrwxrwx 0 0 11717-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/sky-sprite[1].png 1367 macb r/rrwxrwxrwx 0 0 11718-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/google_custom_search_watermark[1].gif 34011 ...b r/rrwxrwxrwx 0 0 11719-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/s_code[1].js 38928 macb r/rrwxrwxrwx 0 0 11720-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/widget[2] 11985 ...b r/rrwxrwxrwx 0 0 11722-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/getfiledata[1].png 11691 macb r/rrwxrwxrwx 0 0 11723-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/overeating-thumb[1].png 12146 macb r/rrwxrwxrwx 0 0 11724-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/sunscreen-and-skin-cancer-thumb[1].png 13330 ...b r/rrwxrwxrwx 0 0 11725-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/fruit-cobbler-thumb[1].png 12543 macb r/rrwxrwxrwx 0 0 11726-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/lemon-coconut-squares-thumb[1].png 12469 ...b r/rrwxrwxrwx 0 0 11727-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/pain-depice-thumb[1].png 12683 ...b r/rrwxrwxrwx 0 0 11728-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/bullying-thumb[1].png 3295 macb r/rrwxrwxrwx 0 0 11729-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/box-simple-beige-inner[1].gif 14294 ...b r/rrwxrwxrwx 0 0 11730-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/confidence-thumb[1].png 769 ...b r/rrwxrwxrwx 0 0 11756-128-4 /Documents and Settings/malware/Cookies/malware@education[2].txt Fri Jul 01 2011 15:09:28 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://00.edu-cdn.com/files/static/video/channels/video_files/gotomom/goodgirlbadboy-thumb.png cache stored in: YZCXGNW1/goodgirlbadboy-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 12147 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/files/static/video/channels/video_files/gotomom/playgroundetiquette-thumb.png cache stored in: UPQVMROL/playgroundetiquette-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 13622 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/files/static/video/channels/video_files/naptimechef/fruit-cobbler-thumb.png cache stored in: YZCXGNW1/fruit-cobbler-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 13330 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://02.edu-cdn.com/files/static/video/channels/video_files/gotomom/changingtabletips-thumb.png cache stored in: QJM5KT6J/changingtabletips-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 11825 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://02.edu-cdn.com/files/static/video/channels/video_files/gotomom/sorry-thumb.png cache stored in: UPQVMROL/sorry-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 12620 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://02.edu-cdn.com/getfiledata.php?id=137981 cache stored in: YZCXGNW1/getfiledata[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - X-Powered-By: PHP/5.3.5 - Content-Length: 11985 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://03.edu-cdn.com/files/static/video/channels/video_files/gotomom/combattingnightmares-thumb.png cache stored in: YZCXGNW1/combattingnightmares-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 12889 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://04.edu-cdn.com/files/static/video/channels/video_files/gotomom/dramaticplay-thumb.png cache stored in: YZCXGNW1/dramaticplay-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 14042 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.education.com/static/logos/goto-mom-logo.jpg cache stored in: UPQVMROL/goto-mom-logo[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - Content-Length: 2633 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 112 macb r/rrwxrwxrwx 0 0 11699-128-1 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/MetaData/23B523C9E7746F715D33C6527C18EB9D 11985 mac. r/rrwxrwxrwx 0 0 11722-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/getfiledata[1].png 13330 mac. r/rrwxrwxrwx 0 0 11725-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/fruit-cobbler-thumb[1].png 12469 mac. r/rrwxrwxrwx 0 0 11727-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/pain-depice-thumb[1].png 12683 mac. r/rrwxrwxrwx 0 0 11728-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/bullying-thumb[1].png 14294 mac. r/rrwxrwxrwx 0 0 11730-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/confidence-thumb[1].png 12632 macb r/rrwxrwxrwx 0 0 11732-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/babydiscipline-thumb[1].png 12646 macb r/rrwxrwxrwx 0 0 11733-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/wheels-on-the-bus-sing-along-thumb[1].png 11761 macb r/rrwxrwxrwx 0 0 11734-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/online-bullying-thumb[1].png 11825 macb r/rrwxrwxrwx 0 0 11735-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/changingtabletips-thumb[1].png 13103 macb r/rrwxrwxrwx 0 0 11736-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/alphabet-song-sing-along-thumb[1].png 2633 macb r/rrwxrwxrwx 0 0 11737-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/goto-mom-logo[1].jpg 11390 macb r/rrwxrwxrwx 0 0 11738-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/cinderella-thumb[1].png 11430 macb r/rrwxrwxrwx 0 0 11739-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/snacking-thumb[1].png 12620 macb r/rrwxrwxrwx 0 0 11740-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/sorry-thumb[1].png 13622 macb r/rrwxrwxrwx 0 0 11741-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/playgroundetiquette-thumb[1].png 319 ...b r/rrwxrwxrwx 0 0 11742-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/;sz=728x90;tile=1;ord=1749812902[1].htm 12889 macb r/rrwxrwxrwx 0 0 11743-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/combattingnightmares-thumb[1].png 5682 macb r/rrwxrwxrwx 0 0 11744-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/fourth_of_july_tic_tac_toe_featured[1].jpg 35108 macb r/rrwxrwxrwx 0 0 11745-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/summer_safety_featured[1].jpg 43335 macb r/rrwxrwxrwx 0 0 11746-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/patriotic_pinwheel_featured[1].jpg 14042 macb r/rrwxrwxrwx 0 0 11747-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/dramaticplay-thumb[1].png 1319 macb r/rrwxrwxrwx 0 0 11748-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/IconOnlyCollisionMarker[1].png 13083 macb r/rrwxrwxrwx 0 0 11749-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/gooddreambox-thumb[1].png 1417 macb r/rrwxrwxrwx 0 0 11750-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/box-grey-310[1].png 319 ...b r/rrwxrwxrwx 0 0 11751-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/;sz=728x90;ord=1749812902[1].htm 500 macb r/rrwxrwxrwx 0 0 11752-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/searchbox-bg[1].png 1325 macb r/rrwxrwxrwx 0 0 11753-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/searchbox-corners-sprite[1].gif 663 macb r/rrwxrwxrwx 0 0 11754-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/bg-advertisement-large[1].gif 253 macb r/rrwxrwxrwx 0 0 11755-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/footer-sides-sprite[1].gif 12147 macb r/rrwxrwxrwx 0 0 11757-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/goodgirlbadboy-thumb[1].png 58845 macb r/rrwxrwxrwx 0 0 11760-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/edulib[1].js 3184 macb r/rrwxrwxrwx 0 0 11761-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/casaleJTag[1].js 176992 macb r/rrwxrwxrwx 0 0 11762-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/qkThH4wTENY[1].js 1177 macb r/rrwxrwxrwx 0 0 11763-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/ql9vukDCc4R[1].png 1648 macb r/rrwxrwxrwx 0 0 11764-128-4 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/Content/23B523C9E7746F715D33C6527C18EB9D 15401 ...b r/rrwxrwxrwx 0 0 11766-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/in-YgSjHErD[2].css 178 macb r/rrwxrwxrwx 0 0 11767-128-1 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/MetaData/D0F063B6B88A2B8BFE21C3993A613447 2157 macb r/rrwxrwxrwx 0 0 11768-128-4 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/Content/D0F063B6B88A2B8BFE21C3993A613447 Fri Jul 01 2011 15:09:29 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png cache stored in: YZCXGNW1/adc-en-100c-000000[1].png - HTTP/1.1 200 OK - P3P: policyref="http://www.googleadservices.com/pagead/p3p.xml"- CP="NOI DEV PSA PSD IVA PVD OTP OUR OTR IND OTC" - Content-Type: image/png - X-Content-Type-Options: nosniff - Content-Length: 543 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pagead2.googlesyndication.com/pagead/sma8.js cache stored in: SLK18LSF/sma8[2].js - HTTP/1.1 200 OK - Content-Length: 4553 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:atdmt.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:wtp101.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 3676 macb r/rrwxrwxrwx 0 0 11617-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/VideoHandler[1].js 286 ...b r/rrwxrwxrwx 0 0 11679-128-1 /Documents and Settings/malware/Cookies/malware@mathtag[2].txt 543 macb r/rrwxrwxrwx 0 0 11765-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/adc-en-100c-000000[1].png 15401 mac. r/rrwxrwxrwx 0 0 11766-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/in-YgSjHErD[2].css 2199 macb r/rrwxrwxrwx 0 0 11769-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/26271-15[4].js 458 ...b r/rrwxrwxrwx 0 0 11772-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/;sz=300x250;tile=2;ord=1749812902[1].htm 3222 macb r/rrwxrwxrwx 0 0 11777-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/plusone[1].js 2034 macb r/rrwxrwxrwx 0 0 11778-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26270-2[2].js 102 macb r/rrwxrwxrwx 0 0 11780-128-1 /Documents and Settings/malware/Cookies/malware@wtp101[2].txt 467 macb r/rrwxrwxrwx 0 0 11781-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/j[1].com-ParentingVideos&a=2&id=514392089&p=6&v=2&inif=1&l=0&t=0&w=800&h=570&z=420&C=1 482 macb r/rrwxrwxrwx 0 0 11782-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/j[1].com-ParentingVideos&a=2&id=514400264&p=6&v=2&inif=1&l=0&t=0&w=800&h=570&z=420&C=1 1087 macb r/rrwxrwxrwx 0 0 11783-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/plusone-unsupported[1].js 4553 macb r/rrwxrwxrwx 0 0 11784-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/sma8[2].js 9932 macb r/rrwxrwxrwx 0 0 11787-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/replaceholder[1].js 49 ...b r/rrwxrwxrwx 0 0 11951-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tap[1].gif Fri Jul 01 2011 15:09:30 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adi/N4375.Casale/B5142683.69_sz=728x90_click0=http://c.casalemedia.com/c/2/1/85037/_ord=0957733402 cache stored in: YZCXGNW1/_ord=0957733402[1].htm - HTTP/1.1 200 OK - Content-Length: 5582 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://s0.2mdn.net/2972082/Sanctuary_728x90_v2.jpg cache stored in: QJM5KT6J/Sanctuary_728x90_v2[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Content-Type-Options: nosniff - Content-Length: 17329 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://spe.atdmt.com/ds/WOWCMWCMOPEM/10_Pemco_Q3_rev/Pemco0020_728x90_TopDown.gif?ver=1 cache stored in: QJM5KT6J/Pemco0020_728x90_TopDown[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - Content-Length: 14326 - Allow: GET (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:adshuffle.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 m... 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:simpli.fi/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:www.education.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 608 macb r/rrwxrwxrwx 0 0 11601-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/dref=http%3A%2F%2Fwww.mevio[1].com%2Fepisode%2F286410%2Fle-monnier-my-heart 331 macb r/rrwxrwxrwx 0 0 11625-128-1 /Documents and Settings/malware/Cookies/malware@adshuffle[1].txt 2197 macb r/rrwxrwxrwx 0 0 11678-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/26271-2[2].js 5620 macb r/rrwxrwxrwx 0 0 11697-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/view[1].htm 34011 mac. r/rrwxrwxrwx 0 0 11719-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/s_code[1].js 5582 macb r/rrwxrwxrwx 0 0 11776-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/;ord=0957733402[1].htm 5265 macb r/rrwxrwxrwx 0 0 11790-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/quant[1].js 14326 macb r/rrwxrwxrwx 0 0 11792-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/Pemco0020_728x90_TopDown[1].gif 17329 macb r/rrwxrwxrwx 0 0 11793-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/Sanctuary_728x90_v2[1].jpg 285 mac. r/rrwxrwxrwx 0 0 11794-128-1 /Documents and Settings/malware/Cookies/malware@www.education[1].txt Fri Jul 01 2011 15:09:31 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adi/video.education.com/video_kw=Video+The+Not+So+Perfect+Parent_position=bottom_mtfIFPath=/doubleclick/_sz=728x90_ord=938096156? cache stored in: YZCXGNW1/_sz=728x90_ord=938096156[1].htm - HTTP/1.1 200 OK - Content-Length: 453 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adi/video.education.com/video_kw=Video+The+Not+So+Perfect+Parent_position=top_mtfIFPath=/doubleclick/_sz=300x250_tile=2_ord=938096156? cache stored in: UPQVMROL/_sz=300x250_tile=2_ord=938096156[1].htm - HTTP/1.1 200 OK - Content-Length: 458 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adi/video.education.com/video_kw=Video+The+Not+So+Perfect+Parent_position=top_mtfIFPath=/doubleclick/_sz=728x90_tile=1_ord=938096156? cache stored in: YZCXGNW1/_sz=728x90_tile=1_ord=938096156[1].htm - HTTP/1.1 200 OK - Content-Length: 319 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 453 macb r/rrwxrwxrwx 0 0 11795-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/;sz=728x90;ord=938096156[1].htm 2898 macb r/rrwxrwxrwx 0 0 11800-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/bk-static[1].js 458 macb r/rrwxrwxrwx 0 0 11801-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/;sz=300x250;tile=2;ord=938096156[1].htm 37210 macb r/rrwxrwxrwx 0 0 11802-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/2ff94d3000b6425bbb11d3a4c26305e3[1].jpg 319 macb r/rrwxrwxrwx 0 0 11805-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/;sz=728x90;tile=1;ord=938096156[1].htm Fri Jul 01 2011 15:09:32 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.collective-media.net/cmadj/say.education/lifestyle.ros_anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+The+Not+So+Perfect+Parent;position=top;mtfIFPath=/doubleclick/;_kw=_mc=c_dcopt=ist_sz=728x90_net=say_ord=8916908375990082_env=ifr_ord1=765811_cmpgurl=http%3A/www.education.com/video/gotomom/%3Fcid%3D62000.0001%26utm_source%3Dadon_113973_23411_%26utm_medium%3Dcpc%26utm_campaign%3DEducation.com-ParentingVideos%26fb_xd_fragment%23%3F%3D%26cb%3Df1ba5e6524e938e%26relation%3Dparent%26transport%3Dfragment%26frame%3Df3835f4c8c9c028?01AD=3-xxJEBA-u1-bQlNSmIpFFVWT5pS5sgzlQO93przAoY_JKttig10zpA&01RI=09023644AD25BC5&01NA= cache stored in: SLK18LSF/V.com-ParentingVideos%26fb_xd_fragment%23%3F%3D%26cb%3Df1ba5e6524e938e%26relation%3Dparent%26transport%3Dfragment%26frame%3Df3835f4c8c9c028 - HTTP/1.1 200 OK - Content-Length: 8089 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/say.education/lifestyle.ros_net=say_u=-say-30210614710_1309558137-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+The+Not+So+Perfect+Parent;position=top;mtfIFPath=/doubleclick/;_kw=_mc=c_dcopt=ist_cmw=owl_sz=728x90_net=say_env=ifr_ord1=765811_contx=education_dc=s_btg=_ord=8916908375990082? cache stored in: YZCXGNW1/3Bposition=top;mtfIFPath=/doubleclick/;_kw=_mc=c_dcopt=ist_cmw=owl_sz=728x90_net=say_env=ifr_ord1=765811_contx=education_dc=s_btg=_ord=8916908375990082 - HTTP/1.1 200 OK - Content-Type: application/x-javascript - Content-Length: 178 - Content-Encoding: gzip (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ec.atdmt.com/ds/WOWCMWCMOPEM/Sasquatch_March_2009/300x250_Sasquatch_Search.gif?ver=1 cache stored in: UPQVMROL/300x250_Sasquatch_Search[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - Content-Length: 12820 - Allow: GET (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://r.nexac.com/e/getdata.xgi?dt=br&pkey=xkeii93kdn349&reppipe=-&edr=off&repequal=_&ru=http://a.collective-media.net/datapair?net=na&pasv=0&id=&pid=&segs= cache stored in: QJM5KT6J/getdata[1].htm - HTTP/1.1 200 OK - Transfer-Encoding: chunked - Pragma: no-cache - P3P: policyref="http://www.nextaction.net/P3P/PolicyReferences.xml"- CP="NOI DSP COR NID CURa ADMa DEVa TAIo PSAo PSDo HISa OUR DELa SAMo UNRo OTRo BUS UNI PUR COM NAV INT DEM STA PRE" - X-Powered-By: Jigawatts - Content-type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://spe.atdmt.com/ds/WOWCMWCMOPEM/10_Pemco_Q3_rev/Pemco0020_728x90_UtilityKilt.gif?ver=1 cache stored in: QJM5KT6J/Pemco0020_728x90_UtilityKilt[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - Content-Length: 13319 - Allow: GET (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:abmr.net/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 m... 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:nexac.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 1027 ...b r/rrwxrwxrwx 0 0 11300-128-4 /Documents and Settings/malware/Cookies/malware@bluekai[2].txt 196 macb r/rrwxrwxrwx 0 0 11321-128-1 /Documents and Settings/malware/Cookies/malware@abmr[1].txt 467 macb r/rrwxrwxrwx 0 0 11545-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/o%2BPerfect%2BParent%3Bposition%3Dtop%3BmtfIFPath%3D%2Fdoubleclick%2F%3B;kw=;mc=c;dcopt=ist;sz=728x90;ord=8916908375990082? 88069 ...b r/rrwxrwxrwx 0 0 11788-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/jwplayer[2].swf 238 macb r/rrwxrwxrwx 0 0 11809-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/ment#?=&cb=f1ba5e6524e938e&relation=parent&transport=fragment&frame=f3835f4c8c9c028&a=4&id=515000085&p=6&v=2&inif=1&l=0&t=0&w=800&h=570&z=420 237 macb r/rrwxrwxrwx 0 0 11810-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/ment#?=&cb=f1ba5e6524e938e&relation=parent&transport=fragment&frame=f3835f4c8c9c028&a=2&id=515000159&p=6&v=2&inif=1&l=0&t=0&w=800&h=570&z=420 640 macb r/rrwxrwxrwx 0 0 11814-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/.com/video;kw=Video+The+Not+So+Perfect+Parent;position=top;mtfIFPath=/doubleclick/;;kw=;mc=c;dcopt=ist;sz=728x90;ord=8916908375990082 12820 macb r/rrwxrwxrwx 0 0 11816-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/300x250_Sasquatch_Search[1].gif 178 macb r/rrwxrwxrwx 0 0 11819-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/3Bposition=top;mtfIFPath=/doubleclick/;;kw=;mc=c;dcopt=ist;cmw=owl;sz=728x90;net=say;env=ifr;ord1=765811;contx=education;dc=s;btg=;ord=8916908375990082 13319 macb r/rrwxrwxrwx 0 0 11822-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/Pemco0020_728x90_UtilityKilt[1].gif 8089 macb r/rrwxrwxrwx 0 0 11823-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/V.com-ParentingVideos%26fb_xd_fragment%23%3F%3D%26cb%3Df1ba5e6524e938e%26relation%3Dparent%26transport%3Dfragment%26frame%3Df3835f4c8c9c028 1 macb r/rrwxrwxrwx 0 0 11825-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/getdata[1].htm 606 ...b r/rrwxrwxrwx 0 0 11981-128-4 /Documents and Settings/malware/Cookies/malware@ad.yieldmanager[1].txt Fri Jul 01 2011 15:09:33 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://seg.sharethis.com/getSegment.php?purl=http://www.education.com/video/gotomom/?cid=62000.0001&utm_source=adon_113973_23411_&utm_medium=cpc&utm_campaign=Education.com-ParentingVideos&fb_xd_fragment#?=&cb=f1ba5e6524e938e&relation=parent&transport=fragment&frame=f3835f4c8c9c028&jsref=http://www.education.com/video/gotomom/?cid=62000.0001&utm_source=adon_113973_23411_&utm_medium=cpc&utm_campaign=Education.com-ParentingVideos&rnd=1309558173078 cache stored in: UPQVMROL/CACJ7ZEO.htm - HTTP/1.1 200 OK - Content-Type: text/html - Transfer-Encoding: chunked - X-Powered-By: PHP/5.3.3 - P3P: "policyref="/w3c/p3p.xml"- CP="ALL DSP COR CURa ADMa DEVa TAIa PSAa PSDa OUR IND UNI COM NAV INT DEM" (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://seg.sharethis.com/getSegment.php?purl=http://www.education.com/video/gotomom/?cid=62000.0001&utm_source=adon_113973_23411_&utm_medium=cpc&utm_campaign=Education.com-ParentingVideos&jsref=http://search.clickwhale.com/results/?partnerid=113973&appid=23411&subid=&ip=198.176.229.10&cid=251223&entry=james%20bond&qs=JQwDFAMXaSFTVkVJQEdaSRpYUURuW0sTAwFFeFpWR0hFQlxcSFNAVTZUXV5cVBB9VkUWC01ER19eGRcRdQofTVxLEHVWVUJfHhZUX0ARERdmWkscBQEdcllUS0BDRE8LAUxASD1UBQQYFQV2D0ZAH1VGDxgZVg9ENxwOERgMTytAAB0UVgUcChxYHBU2WQhEWVMQdFpWExxFFlkMWBQUEGtPHARRVBN1V1ZHQUFFW0kFVhxTPAdLEwcSHWMcBhREVgYHBFMSB1UgGhkRCwxEeFxTQktERV1dSEZETicIChkIWBJ3XlZLXwUGBVIGVVVRdloMVV4DBXcIFAUOXhENGg1AVUg8B0MTAwgFdwgVGx0VG0xdCEZOVTwEAh1JV0ZgXQUREBRRWgtYExERY0ddQFxUBXdYFgYULwcGGhxCRARgDQwUAwt_dF9QS05DK1tcWhAQfnZbWwUYCH8oCwcbDB1RWgsNUUIEYV8YBAE6QyQDExMQFxpMXApkRVQwCBkZAwsOJgEOXykRBgwBGkhPRgUACRUDFg==&rnd=1309558173171 cache stored in: UPQVMROL/CA6D1T8I.htm - HTTP/1.1 200 OK - Content-Type: text/html - Transfer-Encoding: chunked - X-Powered-By: PHP/5.3.3 - P3P: "policyref="/w3c/p3p.xml"- CP="ALL DSP COR CURa ADMa DEVa TAIa PSAa PSDa OUR IND UNI COM NAV INT DEM" (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:sharethis.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 152 ..c. d/drwxrwxrwx 0 0 10632-144-1 /Documents and Settings/malware/Local Settings/History/History.IE5/MSHist012011070120110702 0 macb 0 0 0 10638 [Internet Explorer] (Last Access) User: malware URL::Host: edge.sharethis.com (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/MSHist012011070120110702/index.dat) 32768 ..c. r/rr-xr-xr-x 0 0 10638-128-3 /Documents and Settings/malware/Local Settings/History/History.IE5/MSHist012011070120110702/index.dat 6523 macb r/rrwxrwxrwx 0 0 11525-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/index.153077cd0748e8ed1ab600da3c912069[1].htm 88069 mac. r/rrwxrwxrwx 0 0 11788-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/jwplayer[2].swf 1289 macb r/rrwxrwxrwx 0 0 11827-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CA6D1T8I.htm 1289 macb r/rrwxrwxrwx 0 0 11828-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CACJ7ZEO.htm 94 macb r/rrwxrwxrwx 0 0 11829-128-1 /Documents and Settings/malware/Cookies/malware@sharethis[2].txt 53969 macb r/rrwxrwxrwx 0 0 11830-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/st.4952f9ace8ee52d9e51dcb4c550d5573[1].js 13126 macb r/rrwxrwxrwx 0 0 11831-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/share.0699a6fb1a5680f5fe296b96b196b4ab[1].css Fri Jul 01 2011 15:09:57 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adi/video.education.com/video_kw=Video+The+Not+So+Perfect+Parent_position=top_mtfIFPath=/doubleclick/_sz=300x250_tile=2_ord=1749812902? cache stored in: SLK18LSF/_sz=300x250_tile=2_ord=1749812902[1].htm - HTTP/1.1 200 OK - Content-Length: 458 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 458 mac. r/rrwxrwxrwx 0 0 11772-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/;sz=300x250;tile=2;ord=1749812902[1].htm Fri Jul 01 2011 15:09:58 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.collective-media.net/cmadj/say.education/lifestyle.ros_anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+The+Not+So+Perfect+Parent;position=bottom;mtfIFPath=/doubleclic_kw=_mc=c_dcopt=ist_sz=728x90_net=say_ord=2196496170833953.7_env=ifr_ord1=868574_cmpgurl=http%3A//www.education.com/video/gotomom/%3Fcid%3D62000.0001%26utm_source%3Dadon_113973_23411_%26utm_medium%3Dcpc%26utm_campaign%3DEducation.com-ParentingVideos? cache stored in: SLK18LSF/%3Fcid%3D62000.0001%26utm_source%3Dadon_113973_23411_%26utm_medium%3Dcpc%26utm_campaign%3DEducation[2].com-ParentingVideos - HTTP/1.1 200 OK - Content-Length: 7866 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.collective-media.net/cmadj/say.education/lifestyle.ros_anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+The+Not+So+Perfect+Parent;position=bottom;mtfIFPath=/doubleclic_kw=_mc=c_dcopt=ist_sz=728x90_net=say_ord=9040507934376458_env=ifr_ord1=897636_cmpgurl=http%3A//www.education.com/video/gotomom/%3Fcid%3D62000.0001%26utm_source%3Dadon_113973_23411_%26utm_medium%3Dcpc%26utm_campaign%3DEducation.com-ParentingVideos? cache stored in: QJM5KT6J/%3Fcid%3D62000.0001%26utm_source%3Dadon_113973_23411_%26utm_medium%3Dcpc%26utm_campaign%3DEducation[2].com-ParentingVideos - HTTP/1.1 200 OK - Content-Length: 7447 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.collective-media.net/datapair?net=ex&segs=&op=add cache stored in: SLK18LSF/datapair[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - P3P: policyref="http://a.collective-media.net/static/p3p.xml"- CP="CAO DSP COR CURa ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM PRE" - Content-Length: 42 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adi/video.education.com/video_kw=Video+The+Not+So+Perfect+Parent_position=bottom_mtfIFPath=/doubleclick/_sz=728x90_ord=1749812902? cache stored in: YZCXGNW1/_sz=728x90_ord=1749812902[1].htm - HTTP/1.1 200 OK - Content-Length: 319 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adi/video.education.com/video_kw=Video+The+Not+So+Perfect+Parent_position=top_mtfIFPath=/doubleclick/_sz=728x90_tile=1_ord=1749812902? cache stored in: QJM5KT6J/_sz=728x90_tile=1_ord=1749812902[1].htm - HTTP/1.1 200 OK - Content-Length: 319 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/N6333.272756.AOL-ADVERTISING/B5635693.3_sz=728x90_click=http://r1-ads.ace.advertising.com/click/site=0000807610/mnum=0001038267/cstr=88084081=_4e0e4593-3565712326-807610^1038267^1183^0-1_/xsxdata=$xsxdata/bnum=88084081/optn=64?trg=_ord=3565712326? cache stored in: QJM5KT6J/optn=64[4] - HTTP/1.1 200 OK - Content-Length: 6191 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/say.education/lifestyle.ros_net=say_u=-say-30108703297_1309558163-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+The+Not+So+Perfect+Parent;position=bottom;mtfIFPath=/doubleclic_kw=_mc=c_dcopt=ist_cmw=owl_sz=728x90_net=say_env=ifr_ord1=897636_contx=education_dc=s_btg=_ord=9040507934376458? cache stored in: SLK18LSF/ent;position=bottom;mtfIFPath=/doubleclic_kw=_mc=c_dcopt=ist_cmw=owl_sz=728x90_net=say_env=ifr_ord1=897636_contx=education_dc=s_btg=_ord=9040507934376458 - HTTP/1.1 200 OK - Content-Type: application/x-javascript - Content-Length: 178 - Content-Encoding: gzip (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/say.education/lifestyle.ros_net=say_u=-say-30309602133_1309558163-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+The+Not+So+Perfect+Parent;position=bottom;mtfIFPath=/doubleclic_kw=_mc=c_dcopt=ist_cmw=owl_sz=728x90_net=say_env=ifr_ord1=868574_contx=education_dc=s_btg=_ord=2196496170833953.7? cache stored in: UPQVMROL/lifestyle.ros_net=say_u=-say-30309602133_1309558163-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education[2].7 - HTTP/1.1 200 OK - Content-Length: 206 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://s0.2mdn.net/2784362/YAA_728x90_a.gif cache stored in: UPQVMROL/YAA_728x90_a[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Content-Type-Options: nosniff - Content-Length: 7373 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://spe.atdmt.com/ds/WOWCMWCMOPEM/Sasquatch_March_2009/300x250_Sasquatch_Little_Different.gif?ver=1 cache stored in: UPQVMROL/300x250_Sasquatch_Little_Different[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - Content-Length: 13923 - Allow: GET (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:msn.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 639 ...b r/rrwxrwxrwx 0 0 11193-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/custom[1] 238 macb r/rrwxrwxrwx 0 0 11675-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/j[1].com-ParentingVideos&a=4&id=521720078&p=6&v=2&inif=1&l=0&t=0&w=800&h=570&z=420 319 mac. r/rrwxrwxrwx 0 0 11742-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/;sz=728x90;tile=1;ord=1749812902[1].htm 319 mac. r/rrwxrwxrwx 0 0 11751-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/;sz=728x90;ord=1749812902[1].htm 462 macb r/rrwxrwxrwx 0 0 11758-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/ot%2BSo%2BPerfect%2BParent%3Bposition%3Dbottom%3BmtfIFPath%3D%2Fdoubleclic;kw=;mc=c;dcopt=ist;sz=728x90;ord=9040507934376458? 605 macb r/rrwxrwxrwx 0 0 11796-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/dref=http%3A%2F%2Fwww.education.com%2Fvideo%2Fgotomom%2F%3Fcid%3D62000[1].com-ParentingVideos 464 macb r/rrwxrwxrwx 0 0 11806-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CAZHPRDR.7? 638 macb r/rrwxrwxrwx 0 0 11821-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/lifestyle.ros;anx=10;referer=http://ad.doubleclick.net/adi/video.education[1].7 7866 macb r/rrwxrwxrwx 0 0 11834-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/%3Fcid%3D62000.0001%26utm_source%3Dadon_113973_23411_%26utm_medium%3Dcpc%26utm_campaign%3DEducation[2].com-ParentingVideos 13923 macb r/rrwxrwxrwx 0 0 11835-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/300x250_Sasquatch_Little_Different[1].gif 636 macb r/rrwxrwxrwx 0 0 11836-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/ODYN.com/video;kw=Video+The+Not+So+Perfect+Parent;position=bottom;mtfIFPath=/doubleclic;kw=;mc=c;dcopt=ist;sz=728x90;ord=9040507934376458 206 macb r/rrwxrwxrwx 0 0 11837-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/lifestyle.ros;net=say;u=,say-30309602133_1309558163,1210b8131a8c6a2,education,;;anx=10;referer=http://ad.doubleclick.net/adi/video.education[2].7 7447 macb r/rrwxrwxrwx 0 0 11838-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/%3Fcid%3D62000.0001%26utm_source%3Dadon_113973_23411_%26utm_medium%3Dcpc%26utm_campaign%3DEducation[2].com-ParentingVideos 603 macb r/rrwxrwxrwx 0 0 11839-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/dref=http%3A%2F%2Fwww.education.com%2Fvideo%2Fgotomom%2F%3Fcid%3D62000[2].com-ParentingVideos 178 macb r/rrwxrwxrwx 0 0 11840-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/ent;position=bottom;mtfIFPath=/doubleclic;kw=;mc=c;dcopt=ist;cmw=owl;sz=728x90;net=say;env=ifr;ord1=897636;contx=education;dc=s;btg=;ord=9040507934376458 869 ...b r/rrwxrwxrwx 0 0 11842-128-4 /Documents and Settings/malware/Cookies/malware@exelator[1].txt 42 macb r/rrwxrwxrwx 0 0 11843-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/datapair[1].gif 7373 macb r/rrwxrwxrwx 0 0 11844-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/YAA_728x90_a[1].gif 6191 macb r/rrwxrwxrwx 0 0 11845-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/optn=64[4] Fri Jul 01 2011 15:09:59 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www2.sesamestats.com/paneltracking.aspx?bannerid=JBOLARetailnonCamp&BannerPos=dnt&BannerSite=www.anysite.com&CampaignId=JetBlue&mediaType=Banner&mediaSource=Internet cache stored in: YZCXGNW1/paneltracking[1].gif - HTTP/1.1 200 OK - ETag: "22ba9d43aa1d26928512e501f6a029a5:1267715541" - Content-Length: 58 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 58 macb r/rrwxrwxrwx 0 0 11846-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/paneltracking[1].gif Fri Jul 01 2011 15:10:15 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://www.education.com/video/cookingwithkids (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 65536 m.c. r/rr-xr-xr-x 0 0 10527-128-4 /Documents and Settings/malware/Local Settings/History/History.IE5/index.dat Fri Jul 01 2011 15:10:16 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/files/static/nav-feature/4thofjuly.png cache stored in: QJM5KT6J/4thofjuly[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 9540 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/themes/sky/i/Loading_30.gif cache stored in: YZCXGNW1/Loading_30[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "57441a9ef726a2127c0ea309b6d35830" - Pragma: Expires:Sat- 02 Jul 2011 00:22:46 GMT - X-Cache: HIT - X-Powered-By: PHP/5.3.5 - Content-Length: 5115 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/themes/sky/i/actions-sprite.png cache stored in: SLK18LSF/actions-sprite[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 8565 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/themes/sky/i/buttons/flex-button-orange-corners2.gif cache stored in: UPQVMROL/flex-button-orange-corners2[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Cache: HIT - Content-Length: 1558 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/themes/sky/i/gradients/gradient-sprite-x.png?rev=4 cache stored in: QJM5KT6J/gradient-sprite-x[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 1552 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/themes/sky/i/neckup/header-sprite.png cache stored in: QJM5KT6J/header-sprite[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 14366 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/themes/sky/i/sky-sprite.png?rev=4 cache stored in: YZCXGNW1/sky-sprite[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 33606 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://w.sharethis.com/button/css/sharethis.5a38f5a9c07cb53d1f16671f83f1c3bf.css cache stored in: UPQVMROL/sharethis.5a38f5a9c07cb53d1f16671f83f1c3bf[3].css - HTTP/1.1 200 OK - Content-Length: 2162 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.education.com/featured-thing.jpg cache stored in: YZCXGNW1/featured-thing[1].htm - HTTP/1.1 200 OK - Content-Length: 122190 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.education.com/js/s_code.js?ver=19398 cache stored in: UPQVMROL/s_code[2].js - HTTP/1.1 200 OK - Content-Length: 34011 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.google.com/coop/images/google_custom_search_watermark.gif cache stored in: SLK18LSF/google_custom_search_watermark[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Content-Type-Options: nosniff - Content-Length: 1367 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 2162 macb r/rrwxrwxrwx 0 0 11615-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/sharethis.5a38f5a9c07cb53d1f16671f83f1c3bf[3].css 44 macb r/rrwxrwxrwx 0 0 11849-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/gradient-input-blue[1].gif Fri Jul 01 2011 15:10:17 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://00.edu-cdn.com/files/static/video/channels/video_files/gotomom/gooddreambox-thumb.png cache stored in: SLK18LSF/gooddreambox-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 13083 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://00.edu-cdn.com/files/static/video/channels/video_files/naptimechef/ricotta-stuffed-shells-thumb.png cache stored in: YZCXGNW1/ricotta-stuffed-shells-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 12885 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://00.edu-cdn.com/files/static/video/channels/video_files/raising-healthy-kids/snacking-thumb.png cache stored in: UPQVMROL/snacking-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 11430 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://00.edu-cdn.com/files/static/video/channels/video_files/speakaboos/cinderella-thumb.png cache stored in: UPQVMROL/cinderella-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 11390 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/files/static/nav-feature/patriotic_pinwheel_featured.jpg cache stored in: YZCXGNW1/patriotic_pinwheel_featured[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 43335 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/files/static/video/channels/video_files/gotomom/babydiscipline-thumb.png cache stored in: QJM5KT6J/babydiscipline-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 12632 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/files/static/video/channels/video_files/gotomom/notsoperfectparent-thumb.png cache stored in: YZCXGNW1/notsoperfectparent-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 12945 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/files/static/video/channels/video_files/naptimechef/panini-and-truffle-chips-thumb.png cache stored in: YZCXGNW1/panini-and-truffle-chips-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 14105 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/files/static/video/channels/video_files/naptimechef/polenta-thumb.png cache stored in: QJM5KT6J/polenta-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 14010 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/files/static/video/channels/video_files/raising-healthy-kids/sunscreen-and-skin-cancer-thumb.png cache stored in: YZCXGNW1/sunscreen-and-skin-cancer-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 12146 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/themes/edu/i/bg-advertisement-large.gif cache stored in: QJM5KT6J/bg-advertisement-large[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Cache: HIT - Content-Length: 663 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/themes/sky/i/boxes/box-grey-310.png cache stored in: SLK18LSF/box-grey-310[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 1417 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://02.edu-cdn.com/files/static/nav-feature/fourth_of_july_tic_tac_toe_featured.jpg cache stored in: YZCXGNW1/fourth_of_july_tic_tac_toe_featured[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 5682 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://02.edu-cdn.com/files/static/video/channels/video_files/child-development/online-bullying-thumb.png cache stored in: QJM5KT6J/online-bullying-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 11761 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://02.edu-cdn.com/files/static/video/channels/video_files/naptimechef/chimichurri-thumb.png cache stored in: YZCXGNW1/chimichurri-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 14155 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://02.edu-cdn.com/files/static/video/channels/video_files/naptimechef/lemon-coconut-squares-thumb.png cache stored in: SLK18LSF/lemon-coconut-squares-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 12543 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://02.edu-cdn.com/files/static/video/channels/video_files/naptimechef/poached-salmon-with-leeks-thumb.png cache stored in: YZCXGNW1/poached-salmon-with-leeks-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 13622 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://02.edu-cdn.com/themes/sky/i/page/footer-sides-sprite.gif cache stored in: UPQVMROL/footer-sides-sprite[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Cache: HIT - Content-Length: 253 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://02.edu-cdn.com/themes/sky/i/searchbox/searchbox-bg.png cache stored in: SLK18LSF/searchbox-bg[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 500 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://02.edu-cdn.com/themes/sky/i/searchbox/searchbox-corners-sprite.gif cache stored in: SLK18LSF/searchbox-corners-sprite[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Cache: HIT - Content-Length: 1325 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://03.edu-cdn.com/files/static/nav-feature/summer_safety_featured.jpg cache stored in: YZCXGNW1/summer_safety_featured[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 35108 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://03.edu-cdn.com/files/static/video/channels/video_files/child-development/bullying-thumb.png cache stored in: SLK18LSF/bullying-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 12683 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://03.edu-cdn.com/files/static/video/channels/video_files/naptimechef/pain-depice-thumb.png cache stored in: SLK18LSF/pain-depice-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 12469 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://03.edu-cdn.com/files/static/video/channels/video_files/naptimechef/scallops-and-pasta-thumb.png cache stored in: YZCXGNW1/scallops-and-pasta-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 12995 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://03.edu-cdn.com/files/static/video/channels/video_files/speakaboos/alphabet-song-sing-along-thumb.png cache stored in: QJM5KT6J/alphabet-song-sing-along-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 13103 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://04.edu-cdn.com/files/static/video/channels/video_files/child-development/confidence-thumb.png cache stored in: QJM5KT6J/confidence-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 14294 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://04.edu-cdn.com/files/static/video/channels/video_files/naptimechef/strawberry-mint-ice-cream-thumb.png cache stored in: YZCXGNW1/strawberry-mint-ice-cream-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 13399 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://04.edu-cdn.com/files/static/video/channels/video_files/raising-healthy-kids/overeating-thumb.png cache stored in: YZCXGNW1/overeating-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 11691 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://04.edu-cdn.com/files/static/video/channels/video_files/speakaboos/wheels-on-the-bus-sing-along-thumb.png cache stored in: QJM5KT6J/wheels-on-the-bus-sing-along-thumb[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 12646 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://04.edu-cdn.com/i/IconOnlyCollisionMarker.png cache stored in: YZCXGNW1/IconOnlyCollisionMarker[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 1319 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.collective-media.net/cmadj/say.education/lifestyle.ros_anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doublec_kw=_mc=c_dcopt=ist_sz=728x90_net=say_ord=1888539316562802.7_env=ifr_ord1=443527_cmpgurl=http%3A//www.education.com/video/cookingwithkids/? cache stored in: QJM5KT6J/cookingwithkids[1] - HTTP/1.1 200 OK - Content-Length: 7445 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cdn.optmd.com/V2/85378/215019/0610_001_B_300250_A_2011.gif cache stored in: SLK18LSF/0610_001_B_300250_A_2011[1].gif - HTTP/1.1 200 OK - ETag: "c7d94-5dc4-49f1811e38ec0" - Content-Length: 24004 - P3P: policyref="/w3c/p3p.xml"- CP="NOI DSP COR DEVa TAIa OUR BUS UNI" - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://js.casalemedia.com/casaleJTag.js cache stored in: UPQVMROL/casaleJTag[1].js - HTTP/1.1 200 OK - ETag: "88404e-c70-a1cd3440" - Content-Length: 3184 - P3P: policyref="/w3c/p3p.xml"- CP="NOI DSP COR DEVa TAIa OUR BUS UNI" - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://w.sharethis.com/images/rotating-icon.gif?CXNID=1000014.0NXC cache stored in: YZCXGNW1/rotating-icon[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - Content-Length: 2340 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.education.com/static/logos/naptime-chef-logo.png cache stored in: QJM5KT6J/naptime-chef-logo[1].png - HTTP/1.1 200 OK - Content-Type: image/png - Content-Length: 2298 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:casalemedia.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 12945 macb r/rrwxrwxrwx 0 0 11307-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/notsoperfectparent-thumb[1].png 472 macb r/rrwxrwxrwx 0 0 11411-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/trawberry%2BRaspberry%2BCobbler%3Bposition%3Dbottom%3BmtfIFPath%3D%2Fdoublec;kw=;mc=c;dcopt=ist;sz=728x90;ord=8432332732450455? 14105 macb r/rrwxrwxrwx 0 0 11721-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/panini-and-truffle-chips-thumb[1].png 13622 macb r/rrwxrwxrwx 0 0 11731-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/poached-salmon-with-leeks-thumb[1].png 13399 macb r/rrwxrwxrwx 0 0 11759-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/strawberry-mint-ice-cream-thumb[1].png 2298 macb r/rrwxrwxrwx 0 0 11770-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/naptime-chef-logo[1].png 12995 macb r/rrwxrwxrwx 0 0 11786-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/scallops-and-pasta-thumb[1].png 12885 macb r/rrwxrwxrwx 0 0 11789-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/ricotta-stuffed-shells-thumb[1].png 14155 macb r/rrwxrwxrwx 0 0 11791-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/chimichurri-thumb[1].png 2340 macb r/rrwxrwxrwx 0 0 11803-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/rotating-icon[1].gif 14010 macb r/rrwxrwxrwx 0 0 11811-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/polenta-thumb[1].png 144361 macb r/rrwxrwxrwx 0 0 11812-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/featured-thing[1].htm 1045 ...b r/rrwxrwxrwx 0 0 11817-128-4 /Documents and Settings/malware/Cookies/malware@revsci[2].txt 319 ...b r/rrwxrwxrwx 0 0 11820-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/;sz=728x90;ord=447150484[1].htm 632 macb r/rrwxrwxrwx 0 0 11824-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/life[1].com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doublec;kw=;mc=c;dcopt=ist;sz=728x90;ord=8432332732450455 474 macb r/rrwxrwxrwx 0 0 11832-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/CAIZGT27.7? 321 ...b r/rrwxrwxrwx 0 0 11833-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/;sz=300x250;tile=2;ord=447150484[1].htm 319 ...b r/rrwxrwxrwx 0 0 11848-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/;sz=728x90;tile=1;ord=447150484[1].htm 634 macb r/rrwxrwxrwx 0 0 11851-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/lifestyle.ros;anx=10;referer=http://ad.doubleclick.net/adi/video.education[1].7 793 macb r/rrwxrwxrwx 0 0 11852-128-4 /Documents and Settings/malware/Cookies/malware@casalemedia[2].txt 7445 macb r/rrwxrwxrwx 0 0 11853-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/cookingwithkids[1] 379 macb r/rrwxrwxrwx 0 0 11854-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/j[1].com/video/cookingwithkids/&a=4&id=526736301&p=6&v=2&inif=1&l=0&t=0&w=800&h=570&z=420 24004 macb r/rrwxrwxrwx 0 0 11856-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/0610_001_B_300250_A_2011[1].gif Fri Jul 01 2011 15:10:18 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://00.edu-cdn.com/js/moo/edulib.js?ver=19398 cache stored in: UPQVMROL/edulib[1].js - HTTP/1.1 200 OK - Content-Length: 58845 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://00.edu-cdn.com/js/s_code.js?ver=19398 cache stored in: UPQVMROL/s_code[1].js - HTTP/1.1 200 OK - Content-Length: 34011 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/themes/sky/css/all.css?ver=19398 cache stored in: UPQVMROL/all[1].css - HTTP/1.1 200 OK - Content-Length: 138439 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/themes/sky/css/ie67.css?ver=19398 cache stored in: UPQVMROL/ie67[2].css - HTTP/1.1 200 OK - Content-Length: 6656 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/themes/sky/css/video.css?ver=19398 cache stored in: SLK18LSF/video[2].css - HTTP/1.1 200 OK - Content-Length: 3222 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://02.edu-cdn.com/themes/sky/css/ie6.css?ver=19398 cache stored in: SLK18LSF/ie6[2].css - HTTP/1.1 200 OK - Content-Length: 18633 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://02.edu-cdn.com/themes/sky/css/print.css?ver=19398 cache stored in: QJM5KT6J/print[1].css - HTTP/1.1 200 OK - Content-Length: 2489 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://03.edu-cdn.com/js/moo/mootools-1.2.1-all.js?ver=19398 cache stored in: YZCXGNW1/mootools-1.2.1-all[2].js - HTTP/1.1 200 OK - Content-Length: 102489 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://04.edu-cdn.com/bundle/globalbundle.js?bundle_files=js/moo/global/ cache stored in: QJM5KT6J/globalbundle[2].js - HTTP/1.1 200 OK - Content-Length: 6351 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.collective-media.net/cmadj/say.education/lifestyle.ros_anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doublec_kw=_mc=c_dcopt=ist_sz=728x90_net=say_ord=8432332732450455_env=ifr_ord1=896214_cmpgurl=http%3A//www.education.com/video/cookingwithkids/? cache stored in: QJM5KT6J/cookingwithkids[2] - HTTP/1.1 200 OK - Content-Length: 7443 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/say.education/lifestyle.ros_net=say_u=-say-30115902019_1309558182-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doublec_kw=_mc=c_dcopt=ist_cmw=owl_sz=728x90_net=say_env=ifr_ord1=443527_contx=education_dc=s_btg=_ord=1888539316562802.7? cache stored in: UPQVMROL/lifestyle.ros_net=say_u=-say-30115902019_1309558182-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education[2].7 - HTTP/1.1 200 OK - Content-Length: 1226 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://connect.facebook.net/en_US/all.js cache stored in: YZCXGNW1/all[2].js - HTTP/1.1 200 OK - Content-Length: 129171 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://d.agkn.com/pixel!t=932!?che=1045870298&atr=1-32827-33519-38844 cache stored in: QJM5KT6J/pixel!t=932![1].gif - HTTP/1.1 200 OK - P3P: CP="NOI DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" - ETag: W/"43-1308732886000" - Content-Type: image/gif - Content-Language: en-US - Content-Length: 43 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://w.sharethis.com/widget/?mootools=0&button=false&tabs=email,web,post&charset=utf-8&style=rotate&publisher=d0d0d8a8-d1f8-49ff-9318-fed5383cff80&headerbg=#446e3f&linkfg=#0c4392 cache stored in: QJM5KT6J/widget[2] - HTTP/1.1 200 OK - Content-Length: 38928 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://apis.google.com/js/plusone.js cache stored in: UPQVMROL/plusone[1].js - HTTP/1.1 200 OK - Content-Length: 3222 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://ssl.gstatic.com/webclient/js/gc/22203364-e7648d15/plusone-unsupported.js cache stored in: UPQVMROL/plusone-unsupported[1].js - HTTP/1.1 200 OK - Content-Length: 1087 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:agkn.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 7443 macb r/rrwxrwxrwx 0 0 11807-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/cookingwithkids[2] 43 macb r/rrwxrwxrwx 0 0 11826-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/pixel!t=932![1].gif 180 macb r/rrwxrwxrwx 0 0 11859-128-1 /Documents and Settings/malware/Cookies/malware@agkn[2].txt 1226 macb r/rrwxrwxrwx 0 0 11861-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/lifestyle.ros;net=say;u=,say-30115902019_1309558182,1210b8131a8c6a2,education,;;anx=10;referer=http://ad.doubleclick.net/adi/video.education[2].7 544 ...b r/rrwxrwxrwx 0 0 11863-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/obbler;position=bottom;mtfIFPath=/doublec;kw=;mc=c;dcopt=ist;cmw=owl;sz=728x90;net=say;env=ifr;ord1=896214;contx=education;dc=s;btg=;ord=8432332732450455 1995 ...b r/rrwxrwxrwx 0 0 11892-128-4 /Documents and Settings/malware/Cookies/malware@rubiconproject[2].txt 83 ...b r/rrwxrwxrwx 0 0 12038-128-1 /Documents and Settings/malware/Cookies/malware@tap.rubiconproject[2].txt Fri Jul 01 2011 15:10:19 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://02.edu-cdn.com/js/moo/replaceholder.js?ver=19398 cache stored in: QJM5KT6J/replaceholder[1].js - HTTP/1.1 200 OK - Content-Length: 9932 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://03.edu-cdn.com/js/moo/VideoHandler.js?ver=19398 cache stored in: SLK18LSF/VideoHandler[1].js - HTTP/1.1 200 OK - Content-Length: 3676 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adi/video.education.com/video_kw=Video+Strawberry+Raspberry+Cobbler_position=bottom_mtfIFPath=/doubleclick/_sz=728x90_ord=68949411? cache stored in: SLK18LSF/_sz=728x90_ord=68949411[1].htm - HTTP/1.1 200 OK - Content-Length: 319 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adi/video.education.com/video_kw=Video+Strawberry+Raspberry+Cobbler_position=top_mtfIFPath=/doubleclick/_sz=300x250_tile=2_ord=68949411? cache stored in: UPQVMROL/_sz=300x250_tile=2_ord=68949411[1].htm - HTTP/1.1 200 OK - Content-Length: 321 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adi/video.education.com/video_kw=Video+Strawberry+Raspberry+Cobbler_position=top_mtfIFPath=/doubleclick/_sz=728x90_tile=1_ord=68949411? cache stored in: UPQVMROL/_sz=728x90_tile=1_ord=68949411[1].htm - HTTP/1.1 200 OK - Content-Length: 319 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/say.education/lifestyle.ros_net=say_u=-say-30312937048_1309558182-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doublec_kw=_mc=c_dcopt=ist_cmw=owl_sz=728x90_net=say_env=ifr_ord1=896214_contx=education_dc=s_btg=_ord=8432332732450455? cache stored in: QJM5KT6J/obbler;position=bottom;mtfIFPath=/doublec_kw=_mc=c_dcopt=ist_cmw=owl_sz=728x90_net=say_env=ifr_ord1=896214_contx=education_dc=s_btg=_ord=8432332732450455 - HTTP/1.1 200 OK - Content-Type: application/x-javascript - Content-Length: 544 - Content-Encoding: gzip (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://static.ak.fbcdn.net/rsrc.php/v1/yM/r/qkThH4wTENY.js cache stored in: SLK18LSF/qkThH4wTENY[1].js - HTTP/1.1 200 OK - Content-Length: 176992 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://static.ak.fbcdn.net/rsrc.php/v1/yU/r/in-YgSjHErD.css cache stored in: QJM5KT6J/in-YgSjHErD[2].css - HTTP/1.1 200 OK - Content-Length: 15401 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://static.ak.fbcdn.net/rsrc.php/v1/z7/r/ql9vukDCc4R.png cache stored in: SLK18LSF/ql9vukDCc4R[1].png - HTTP/1.1 200 OK - Content-Length: 1177 - Content-Type: image/png - X-FB-Server: 10.30.147.193 - X-Cnection: close (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.bkrtx.com/js/bk-static.js cache stored in: YZCXGNW1/bk-static[1].js - HTTP/1.1 200 OK - ETag: "38b83c4-b52-4a6e0af03f580" - Content-Length: 2898 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.education.com/files/static/video/jwplayer.swf cache stored in: SLK18LSF/jwplayer[2].swf - HTTP/1.1 200 OK - Content-Type: application/x-shockwave-flash - Content-Length: 88069 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:education.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:revsci.net/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 769 mac. r/rrwxrwxrwx 0 0 11756-128-4 /Documents and Settings/malware/Cookies/malware@education[2].txt 1045 mac. r/rrwxrwxrwx 0 0 11817-128-4 /Documents and Settings/malware/Cookies/malware@revsci[2].txt 540 macb r/rrwxrwxrwx 0 0 11858-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/CAKNE9IL.757? 539 macb r/rrwxrwxrwx 0 0 11862-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/rawberry%2BRaspberry%2BCobbler%3Bposition%3Dtop%3BmtfIFPath%3D%2Fdoubleclic;kw=;mc=c;dcopt=ist;sz=300x250;ord=8029360707880961? 544 mac. r/rrwxrwxrwx 0 0 11863-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/obbler;position=bottom;mtfIFPath=/doublec;kw=;mc=c;dcopt=ist;cmw=owl;sz=728x90;net=say;env=ifr;ord1=896214;contx=education;dc=s;btg=;ord=8432332732450455 1454 macb r/rrwxrwxrwx 0 0 11865-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/jstag[1] 319 macb r/rrwxrwxrwx 0 0 11870-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/;sz=728x90;ord=68949411[1].htm 321 macb r/rrwxrwxrwx 0 0 11871-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/;sz=300x250;tile=2;ord=68949411[1].htm 319 macb r/rrwxrwxrwx 0 0 11872-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/;sz=728x90;tile=1;ord=68949411[1].htm Fri Jul 01 2011 15:10:20 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.collective-media.net/cmadj/say.education/lifestyle.ros_anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doublec_kw=_mc=c_dcopt=ist_sz=728x90_net=say_ord=1096744041590904.1_env=ifr_ord1=908595_cmpgurl=http%3A//www.education.com/video/cookingwithkids/%3Ffb_xd_fragment%23%3F%3D%26cb%3Df201858760d99fc%26relation%3Dparent%26transport%3Dfragment%26frame%3Df10d949f0cc29a6? cache stored in: YZCXGNW1/%3Ffb_xd_fragment%23%3F%3D%26cb%3Df201858760d99fc%26relation%3Dparent%26transport%3Dfragment%26frame%3Df10d949f0cc29a6[2] - HTTP/1.1 200 OK - Content-Length: 7445 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.collective-media.net/cmadj/say.education/lifestyle.ros_anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doublec_kw=_mc=c_dcopt=ist_sz=728x90_net=say_ord=28360776158620.757_env=ifr_ord1=23715_cmpgurl=http%3A//www.education.com/video/cookingwithkids/%3Ffb_xd_fragment%23%3F%3D%26cb%3Df201858760d99fc%26relation%3Dparent%26transport%3Dfragment%26frame%3Df10d949f0cc29a6? cache stored in: SLK18LSF/%3Ffb_xd_fragment%23%3F%3D%26cb%3Df201858760d99fc%26relation%3Dparent%26transport%3Dfragment%26frame%3Df10d949f0cc29a6[2] - HTTP/1.1 200 OK - Content-Length: 7444 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.collective-media.net/cmadj/say.education/lifestyle.ros_anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=top;mtfIFPath=/doubleclic_kw=_mc=c_dcopt=ist_sz=300x250_net=say_ord=8029360707880961_env=ifr_ord1=458785_cmpgurl=http%3A//www.education.com/video/cookingwithkids/%3Ffb_xd_fragment%23%3F%3D%26cb%3Df201858760d99fc%26relation%3Dparent%26transport%3Dfragment%26frame%3Df10d949f0cc29a6? cache stored in: QJM5KT6J/%3Ffb_xd_fragment%23%3F%3D%26cb%3Df201858760d99fc%26relation%3Dparent%26transport%3Dfragment%26frame%3Df10d949f0cc29a6[2] - HTTP/1.1 200 OK - Content-Length: 7445 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/say.education/lifestyle.ros_net=say_u=-say-30202126879_1309558185-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doublec_kw=_mc=c_dcopt=ist_cmw=owl_sz=728x90_net=say_env=ifr_ord1=23715_contx=education_dc=s_btg=_ord=28360776158620.757? cache stored in: SLK18LSF/lifestyle.ros_net=say_u=-say-30202126879_1309558185-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education[2].757 - HTTP/1.1 200 OK - Content-Length: 1226 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/say.education/lifestyle.ros_net=say_u=-say-30204264968_1309558185-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doublec_kw=_mc=c_dcopt=ist_cmw=owl_sz=728x90_net=say_env=ifr_ord1=908595_contx=education_dc=s_btg=_ord=1096744041590904.1? cache stored in: YZCXGNW1/lifestyle.ros_net=say_u=-say-30204264968_1309558185-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education[2].1 - HTTP/1.1 200 OK - Content-Length: 1226 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/say.education/lifestyle.ros_net=say_u=-say-30206141887_1309558185-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=top;mtfIFPath=/doubleclic_kw=_mc=c_dcopt=ist_cmw=owl_sz=300x250_net=say_env=ifr_ord1=458785_contx=education_dc=s_btg=_ord=8029360707880961? cache stored in: QJM5KT6J/bbler;position=top;mtfIFPath=/doubleclic_kw=_mc=c_dcopt=ist_cmw=owl_sz=300x250_net=say_env=ifr_ord1=458785_contx=education_dc=s_btg=_ord=8029360707880961 - HTTP/1.1 200 OK - Content-Type: application/x-javascript - Content-Length: 178 - Content-Encoding: gzip (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://data.aggregateknowledge.com/pixel!t=649!?che=1544754739&atr=1-65-2130-14821-14828-14869-14970 cache stored in: QJM5KT6J/pixel!t=649![1].gif - HTTP/1.1 200 OK - P3P: CP="NOI DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" - ETag: W/"43-1308732886000" - Content-Type: image/gif - Content-Language: en-US - Content-Length: 43 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-2237930296469909&output=html&h=90&slotname=9246371595&w=728&ea=0&flash=6.0.79.0&url=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doubleclick/;sz=728x90;ord=447150484?&dt=1309558220265&shv=r20110622&jsv=r20110627&saldr=1&correlator=1309558220265&frm=8&adk=2416968638&ga_vid=1083898643.1309558220&ga_sid=1309558220&ga_hid=1274369418&ga_fc=0&u_tz=-420&u_his=4&u_java=1&u_h=600&u_w=800&u_ah=570&u_aw=800&u_cd=32&u_nplug=0&u_nmime=0&biw=-12245933&bih=-12245933&ifk=2959361923&fu=0&ifi=1&dtd=47 cache stored in: YZCXGNW1/CAB6KRQB.htm - HTTP/1.1 200 OK - Content-Length: 4845 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-2237930296469909&output=html&h=90&slotname=9246371595&w=728&ea=0&flash=6.0.79.0&url=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=top;mtfIFPath=/doubleclick/;sz=728x90;tile=1;ord=447150484?&dt=1309558220093&shv=r20110622&jsv=r20110627&saldr=1&correlator=1309558220171&frm=8&adk=2416968638&ga_vid=885560672.1309558220&ga_sid=1309558220&ga_hid=721252793&ga_fc=0&u_tz=-420&u_his=4&u_java=1&u_h=600&u_w=800&u_ah=570&u_aw=800&u_cd=32&u_nplug=0&u_nmime=0&biw=-12245933&bih=-12245933&ifk=1767621636&eid=36815002&fu=0&ifi=1&dtd=141 cache stored in: UPQVMROL/CAK12JYJ.htm - HTTP/1.1 200 OK - Content-Length: 4863 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://googleads.g.doubleclick.net/pagead/imgad?id=CIin0ryV3NCi2AEQ2AUYWjIIGUyyHYwCqhM cache stored in: SLK18LSF/imgad[1].jpg - HTTP/1.1 200 OK - P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml"- CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR" - Content-Type: image/jpeg - X-Content-Type-Options: nosniff - Content-Length: 48146 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pagead2.googlesyndication.com/pagead/osd.js cache stored in: YZCXGNW1/osd[1].js - HTTP/1.1 200 OK - Content-Length: 10981 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://uac.advertising.com/wrapper/aceUACping.htm cache stored in: SLK18LSF/aceUACping[1].htm - HTTP/1.1 200 OK - Content-Length: 2793 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:doubleclick.net/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:p-td.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:pubmatic.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 43 macb r/rrwxrwxrwx 0 0 11551-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/pixel!t=649![1].gif 634 macb r/rrwxrwxrwx 0 0 11808-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/lifestyle.ros;anx=10;referer=http://ad.doubleclick.net/adi/video.education[1].757 287 macb r/rrwxrwxrwx 0 0 11813-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/render_ads[2].js 10981 macb r/rrwxrwxrwx 0 0 11815-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/osd[1].js 28 macb r/rrwxrwxrwx 0 0 11875-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tion=bottom;mtfIFPath=/doubleclick/;sz=728x90;ord=447150484?&cid=oxpv1:34-632-1929-1968-5551&hrid=4e2d6d7145f82aa0ff7ffd6c96c817f7-1309558183 633 macb r/rrwxrwxrwx 0 0 11879-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/lif[1].com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=top;mtfIFPath=/doubleclic;kw=;mc=c;dcopt=ist;sz=300x250;ord=8029360707880961 28 macb r/rrwxrwxrwx 0 0 11880-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/op;mtfIFPath=/doubleclick/;sz=728x90;tile=1;ord=447150484?&cid=oxpv1:34-632-1929-1968-5551&hrid=83fd4986d7bbab9ed642a099bd8daaad-1309558184 190 macb r/rrwxrwxrwx 0 0 11881-128-1 /Documents and Settings/malware/Cookies/malware@pubmatic[2].txt 7444 macb r/rrwxrwxrwx 0 0 11882-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/%3Ffb_xd_fragment%23%3F%3D%26cb%3Df201858760d99fc%26relation%3Dparent%26transport%3Dfragment%26frame%3Df10d949f0cc29a6[2] 7445 macb r/rrwxrwxrwx 0 0 11883-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/%3Ffb_xd_fragment%23%3F%3D%26cb%3Df201858760d99fc%26relation%3Dparent%26transport%3Dfragment%26frame%3Df10d949f0cc29a6[2] 13092 macb r/rrwxrwxrwx 0 0 11885-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/show_ads[2].js 48867 macb r/rrwxrwxrwx 0 0 11886-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/show_ads_impl[2].js 540 macb r/rrwxrwxrwx 0 0 11887-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CAW1N89C.1? 634 macb r/rrwxrwxrwx 0 0 11888-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/lifestyle.ros;anx=10;referer=http://ad.doubleclick.net/adi/video.education[1].1 178 macb r/rrwxrwxrwx 0 0 11889-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/bbler;position=top;mtfIFPath=/doubleclic;kw=;mc=c;dcopt=ist;cmw=owl;sz=300x250;net=say;env=ifr;ord1=458785;contx=education;dc=s;btg=;ord=8029360707880961 7445 macb r/rrwxrwxrwx 0 0 11890-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/%3Ffb_xd_fragment%23%3F%3D%26cb%3Df201858760d99fc%26relation%3Dparent%26transport%3Dfragment%26frame%3Df10d949f0cc29a6[2] 52 macb r/rrwxrwxrwx 0 0 11893-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/test_domain[2].js 81 macb r/rrwxrwxrwx 0 0 11894-128-1 /Documents and Settings/malware/Cookies/malware@p-td[1].txt 134 macb r/rrwxrwxrwx 0 0 11896-128-1 /Documents and Settings/malware/Cookies/malware@doubleclick[2].txt 1226 macb r/rrwxrwxrwx 0 0 11897-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/lifestyle.ros;net=say;u=,say-30202126879_1309558185,1210b8131a8c6a2,education,;;anx=10;referer=http://ad.doubleclick.net/adi/video.education[2].757 1226 macb r/rrwxrwxrwx 0 0 11898-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/lifestyle.ros;net=say;u=,say-30204264968_1309558185,1210b8131a8c6a2,education,;;anx=10;referer=http://ad.doubleclick.net/adi/video.education[2].1 4863 macb r/rrwxrwxrwx 0 0 11899-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CAK12JYJ.htm 48146 macb r/rrwxrwxrwx 0 0 11900-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/imgad[1].jpg 720 macb r/rrwxrwxrwx 0 0 11901-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/ad_choices_en[1].png 265 macb r/rrwxrwxrwx 0 0 11904-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/ad_choices_i[1].png 4845 macb r/rrwxrwxrwx 0 0 11905-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CAB6KRQB.htm 726 macb r/rrwxrwxrwx 0 0 11906-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/abg[1].js 28 macb r/rrwxrwxrwx 0 0 11908-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/ition=bottom;mtfIFPath=/doubleclick/;sz=728x90;ord=68949411?&cid=oxpv1:34-632-1929-1968-5551&hrid=cdf5ffcc613c1bbeb643d9a5ffb94eda-1309558185 Fri Jul 01 2011 15:10:21 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://edge.sharethis.com/share4x/index.153077cd0748e8ed1ab600da3c912069.html cache stored in: QJM5KT6J/index.153077cd0748e8ed1ab600da3c912069[1].htm - HTTP/1.1 200 OK - Content-Length: 6523 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-2237930296469909&output=html&h=90&slotname=9246371595&w=728&ea=0&flash=6.0.79.0&url=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doubleclick/;sz=728x90;ord=68949411?&dt=1309558220953&shv=r20110622&jsv=r20110627&saldr=1&correlator=1309558220968&frm=8&adk=2416968638&ga_vid=1605499097.1309558221&ga_sid=1309558221&ga_hid=1225558833&ga_fc=0&u_tz=-420&u_his=4&u_java=1&u_h=600&u_w=800&u_ah=570&u_aw=800&u_cd=32&u_nplug=0&u_nmime=0&biw=-12245933&bih=-12245933&ifk=2566201910&fu=0&ifi=1&dtd=31 cache stored in: UPQVMROL/CA0F2LS5.htm - HTTP/1.1 200 OK - Content-Length: 4914 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-2237930296469909&output=html&h=90&slotname=9246371595&w=728&ea=0&flash=6.0.79.0&url=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=top;mtfIFPath=/doubleclick/;sz=728x90;tile=1;ord=68949411?&dt=1309558221031&shv=r20110622&jsv=r20110627&saldr=1&correlator=1309558221062&frm=8&adk=2416968638&ga_vid=1257968834.1309558221&ga_sid=1309558221&ga_hid=278675666&ga_fc=0&u_tz=-420&u_his=4&u_java=1&u_h=600&u_w=800&u_ah=570&u_aw=800&u_cd=32&u_nplug=0&u_nmime=0&biw=-12245933&bih=-12245933&ifk=1033151036&fu=0&ifi=1&dtd=62 cache stored in: SLK18LSF/CA2ZC1MB.htm - HTTP/1.1 200 OK - Content-Length: 4883 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://seg.sharethis.com/getSegment.php?purl=http://www.education.com/video/cookingwithkids/&jsref=http://www.education.com/video/gotomom/?cid=62000.0001&utm_source=adon_113973_23411_&utm_medium=cpc&utm_campaign=Education.com-ParentingVideos&rnd=1309558221640 cache stored in: QJM5KT6J/CA2JGXLX.htm - HTTP/1.1 200 OK - Content-Type: text/html - Transfer-Encoding: chunked - X-Powered-By: PHP/5.3.3 - P3P: "policyref="/w3c/p3p.xml"- CP="ALL DSP COR CURa ADMa DEVa TAIa PSAa PSDa OUR IND UNI COM NAV INT DEM" (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://w.sharethis.com/share4x/css/share.0699a6fb1a5680f5fe296b96b196b4ab.css cache stored in: QJM5KT6J/share.0699a6fb1a5680f5fe296b96b196b4ab[1].css - HTTP/1.1 200 OK - Content-Length: 13126 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://w.sharethis.com/share4x/js/st.4952f9ace8ee52d9e51dcb4c550d5573.js cache stored in: YZCXGNW1/st.4952f9ace8ee52d9e51dcb4c550d5573[1].js - HTTP/1.1 200 OK - Content-Length: 53969 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://edge.sharethis.com/share4x/index.153077cd0748e8ed1ab600da3c912069.html (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 0 macb 0 0 0 10638 [Internet Explorer] (Last Access) User: malware URL:http://edge.sharethis.com/share4x/index.153077cd0748e8ed1ab600da3c912069.html (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/MSHist012011070120110702/index.dat) 28 macb r/rrwxrwxrwx 0 0 11909-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/top;mtfIFPath=/doubleclick/;sz=728x90;tile=1;ord=68949411?&cid=oxpv1:34-632-1929-1968-5551&hrid=36042b098f76e1e69af7ece1c4dd56ae-1309558185 4914 macb r/rrwxrwxrwx 0 0 11911-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CA0F2LS5.htm 4883 macb r/rrwxrwxrwx 0 0 11913-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/CA2ZC1MB.htm 1327 macb r/rrwxrwxrwx 0 0 11914-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/CA2JGXLX.htm Fri Jul 01 2011 15:10:41 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/3c0/9dc/3c09dcbc9bfaf8ff0b375c1a281de587d36fc0d1.jpg?url=http://origin.psstatic.podshow.com/images/shows/25593/episodes/285301/large/ridethepine-us-e.jpg?r=1308445971&width=200&height=112&scheme=1 cache stored in: UPQVMROL/3c09dcbc9bfaf8ff0b375c1a281de587d36fc0d1[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 33148 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/419/7df/4197dfa1f28d2d77f56f6f8e1eb334e36a0bd5a6.jpg?url=http://origin.thumbs.mevio.com/media/21346/episodes/286599/thumbnail.jpg&width=120&height=90&scheme=2 cache stored in: YZCXGNW1/4197dfa1f28d2d77f56f6f8e1eb334e36a0bd5a6[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2901 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/a38/5d8/a385d84a49104a8e6e89ab1f02f3ee37315af579.jpg?url=http://origin.psstatic.podshow.com/images/shows/25593/episodes/283523/large/ridethepine-us-e.jpg?r=1307230490&width=200&height=112&scheme=1 cache stored in: SLK18LSF/a385d84a49104a8e6e89ab1f02f3ee37315af579[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 42046 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/be2/3cc/be23ccff241abc0d69c1ca7aa4657a5ea147f4c7.jpg?url=http://origin.psstatic.podshow.com/images/shows/25593/episodes/283976/large/ridethepine-us-e.jpg?r=1307499416&width=200&height=112&scheme=1 cache stored in: QJM5KT6J/be23ccff241abc0d69c1ca7aa4657a5ea147f4c7[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 29264 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/f08/636/f0863610f92898641b1fc1ddb20f84d66eff4aa5.jpg?url=http://origin.psstatic.podshow.com/images/shows/25593/episodes/285678/large/ridethepine-us-e.jpg?r=1308712677&width=200&height=112&scheme=1 cache stored in: UPQVMROL/f0863610f92898641b1fc1ddb20f84d66eff4aa5[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 33324 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/photo_default.jpg cache stored in: QJM5KT6J/photo_default[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2734 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/25593/shows/thumbs/ridethepine.jpg?r=1305944903 cache stored in: UPQVMROL/ridethepine[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3063 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/shows/27109/episodes/286744/small/hotoff-us-e.jpg?r=1309474711 cache stored in: UPQVMROL/hotoff-us-e[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 7011 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/12684/gallery/thumbs/7530.jpg cache stored in: YZCXGNW1/7530[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3334 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/1631/gallery/thumbs/1667.jpg cache stored in: QJM5KT6J/1667[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2833 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/19088/gallery/thumbs/12368.jpg cache stored in: SLK18LSF/12368[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2015 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/23020/gallery/thumbs/14567.gif cache stored in: SLK18LSF/14567[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Cache: HIT - Content-Length: 3711 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/24759/gallery/thumbs/15561.jpg cache stored in: YZCXGNW1/15561[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3402 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/260433/gallery/thumbs/147123.jpg cache stored in: YZCXGNW1/147123[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2900 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/264359/gallery/thumbs/121400.jpg cache stored in: QJM5KT6J/121400[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3623 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/28617/gallery/thumbs/17778.gif cache stored in: SLK18LSF/17778[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Cache: HIT - Content-Length: 3381 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/31103/gallery/thumbs/19262.gif cache stored in: QJM5KT6J/19262[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Cache: HIT - Content-Length: 4540 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/3247/gallery/thumbs/2510.jpg cache stored in: UPQVMROL/2510[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2903 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/3850/gallery/thumbs/2780.jpg cache stored in: QJM5KT6J/2780[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3200 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/5827/gallery/thumbs/4646.jpg cache stored in: UPQVMROL/4646[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2831 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/62/gallery/thumbs/avatar.png cache stored in: YZCXGNW1/avatar[2].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 6317 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/combined/shows.css?r=38841 cache stored in: UPQVMROL/shows[2].css - HTTP/1.1 200 OK - Content-Length: 33316 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/js/combined/showPage.js?r=38841 cache stored in: QJM5KT6J/showPage[2].js - HTTP/1.1 200 OK - Content-Length: 98741 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/js/tpl_comments.js?r=38841 cache stored in: UPQVMROL/tpl_comments[2].js - HTTP/1.1 200 OK - Content-Length: 3493 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/js/tpl_shows.js?r=38841 cache stored in: SLK18LSF/tpl_shows[2].js - HTTP/1.1 200 OK - Content-Length: 65677 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/us/images/defaults/profile/thumbs/default.jpg cache stored in: YZCXGNW1/default[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 1222 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://ridethepine.mevio.com (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 26709 ...b r/rrwxrwxrwx 0 0 11656-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/470b5f6bab808d8ae2766563de8af5950dabb1f2[1].jpg 42046 macb r/rrwxrwxrwx 0 0 11674-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/a385d84a49104a8e6e89ab1f02f3ee37315af579[1].jpg 33324 macb r/rrwxrwxrwx 0 0 11698-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/f0863610f92898641b1fc1ddb20f84d66eff4aa5[1].jpg 33148 macb r/rrwxrwxrwx 0 0 11771-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/3c09dcbc9bfaf8ff0b375c1a281de587d36fc0d1[1].jpg 3711 macb r/rrwxrwxrwx 0 0 11773-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/14567[1].gif 6317 macb r/rrwxrwxrwx 0 0 11775-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/avatar[2].png 3381 macb r/rrwxrwxrwx 0 0 11874-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/17778[1].gif 187068 ...b r/rrwxrwxrwx 0 0 11917-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/281467[1].jpg 4540 macb r/rrwxrwxrwx 0 0 11918-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/19262[1].gif 3402 macb r/rrwxrwxrwx 0 0 11919-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/15561[1].jpg 29264 macb r/rrwxrwxrwx 0 0 11920-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/be23ccff241abc0d69c1ca7aa4657a5ea147f4c7[1].jpg 3623 macb r/rrwxrwxrwx 0 0 11921-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/121400[1].jpg 3334 macb r/rrwxrwxrwx 0 0 11922-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/7530[1].jpg 2831 macb r/rrwxrwxrwx 0 0 11925-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/4646[1].jpg 3200 macb r/rrwxrwxrwx 0 0 11926-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/2780[1].jpg 2015 macb r/rrwxrwxrwx 0 0 11927-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/12368[1].jpg 3063 macb r/rrwxrwxrwx 0 0 11928-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/ridethepine[1].jpg 33362 ...b r/rrwxrwxrwx 0 0 11929-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/d4e94ed88a079b7c1524f4943cce2cae8a4aad02[1].jpg 331 ...b r/rrwxrwxrwx 0 0 11930-128-1 /Documents and Settings/malware/Cookies/malware@ridethepine.mevio[1].txt 12346 ...b r/rrwxrwxrwx 0 0 11931-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/269246[1].jpg Fri Jul 01 2011 15:10:42 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/100/123/100123abfd89d6c3eb6faa6bdde9144d04449269.jpg?url=http://origin.psstatic.podshow.com/images/shows/25593/episodes/280917/large/ridethepine-us-e.jpg?r=1305516742&width=200&height=112&scheme=1 cache stored in: SLK18LSF/100123abfd89d6c3eb6faa6bdde9144d04449269[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 36894 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/470/b5f/470b5f6bab808d8ae2766563de8af5950dabb1f2.jpg?url=http://origin.psstatic.podshow.com/images/shows/25593/episodes/281287/large/ridethepine-us-e.jpg?r=1305777076&width=200&height=112&scheme=1 cache stored in: YZCXGNW1/470b5f6bab808d8ae2766563de8af5950dabb1f2[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 26709 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/59b/c51/59bc51247aa0498e166e50d0e00d9caa5417a2e5.jpg?url=http://origin.psstatic.podshow.com/images/shows/25593/episodes/280165/large/ridethepine-us-e.jpg?r=1304996532&width=200&height=112&scheme=1 cache stored in: QJM5KT6J/59bc51247aa0498e166e50d0e00d9caa5417a2e5[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 38257 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/8cc/0be/8cc0be920b4a8da156805f84dcab9570dfc8ec0b.jpg?url=http://origin.psstatic.podshow.com/images/shows/25593/episodes/277547/large/ridethepine-us-e.jpg?r=1303528849&width=200&height=112&scheme=1 cache stored in: UPQVMROL/8cc0be920b4a8da156805f84dcab9570dfc8ec0b[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 35098 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/96e/0e6/96e0e6c13d0397d352c1e6e1b7410078393fd80d.jpg?url=http://origin.psstatic.podshow.com/images/shows/25593/episodes/279815/large/ridethepine-us-e.jpg?r=1304730143&width=200&height=112&scheme=1 cache stored in: UPQVMROL/96e0e6c13d0397d352c1e6e1b7410078393fd80d[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 26525 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/d4e/94e/d4e94ed88a079b7c1524f4943cce2cae8a4aad02.jpg?url=http://origin.psstatic.podshow.com/images/shows/25593/episodes/282027/large/ridethepine-us-e.jpg?r=1306199281&width=200&height=112&scheme=1 cache stored in: UPQVMROL/d4e94ed88a079b7c1524f4943cce2cae8a4aad02[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 33362 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/e11/04a/e1104a962f9825885d4dc4c7ca553879d854f7d6.jpg?url=http://origin.psstatic.podshow.com/images/shows/25593/episodes/280475/large/ridethepine-us-e.jpg?r=1305174276&width=200&height=112&scheme=1 cache stored in: SLK18LSF/e1104a962f9825885d4dc4c7ca553879d854f7d6[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 37583 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/848605/gallery/large/281467.jpg cache stored in: YZCXGNW1/281467[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 187068 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/848605/gallery/large/281468.jpg cache stored in: QJM5KT6J/281468[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 11136 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/848605/gallery/large/281469.gif cache stored in: SLK18LSF/281469[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Cache: HIT - Content-Length: 9151 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/848605/gallery/large/281470.jpg cache stored in: UPQVMROL/281470[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 122504 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/848605/gallery/med/269246.jpg cache stored in: YZCXGNW1/269246[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 12346 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:ridethepine.mevio.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 37583 macb r/rrwxrwxrwx 0 0 11539-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/e1104a962f9825885d4dc4c7ca553879d854f7d6[1].jpg 26709 mac. r/rrwxrwxrwx 0 0 11656-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/470b5f6bab808d8ae2766563de8af5950dabb1f2[1].jpg 38257 macb r/rrwxrwxrwx 0 0 11915-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/59bc51247aa0498e166e50d0e00d9caa5417a2e5[1].jpg 187068 mac. r/rrwxrwxrwx 0 0 11917-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/281467[1].jpg 36894 macb r/rrwxrwxrwx 0 0 11924-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/100123abfd89d6c3eb6faa6bdde9144d04449269[1].jpg 33362 mac. r/rrwxrwxrwx 0 0 11929-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/d4e94ed88a079b7c1524f4943cce2cae8a4aad02[1].jpg 331 mac. r/rrwxrwxrwx 0 0 11930-128-1 /Documents and Settings/malware/Cookies/malware@ridethepine.mevio[1].txt 12346 mac. r/rrwxrwxrwx 0 0 11931-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/269246[1].jpg 9151 macb r/rrwxrwxrwx 0 0 11932-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/281469[1].gif 11136 macb r/rrwxrwxrwx 0 0 11934-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/281468[1].jpg 122504 macb r/rrwxrwxrwx 0 0 11935-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/281470[1].jpg 26525 macb r/rrwxrwxrwx 0 0 11936-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/96e0e6c13d0397d352c1e6e1b7410078393fd80d[1].jpg 35098 macb r/rrwxrwxrwx 0 0 11937-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/8cc0be920b4a8da156805f84dcab9570dfc8ec0b[1].jpg Fri Jul 01 2011 15:10:43 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/shows/static/css/images/box-heading.png?r=38841 cache stored in: SLK18LSF/box-heading[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 2680 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/shows/static/css/images/box-shadows.png?r=38841 cache stored in: QJM5KT6J/box-shadows[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 999 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.facebook.com/extern/login_status.php?api_key=c99345b4de38e993c64ef4654ac9164b&extern=2&channel=http://ridethepine.mevio.com/rest/facebook/xd_receiver.php&locale=en_US cache stored in: QJM5KT6J/login_status[2].htm - HTTP/1.1 200 OK - Content-Length: 1113 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 1113 macb r/rrwxrwxrwx 0 0 11939-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/login_status[2].htm Fri Jul 01 2011 15:10:44 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ridethepine.mevio.com/rest/facebook/xd_receiver.php cache stored in: SLK18LSF/xd_receiver[1].htm - HTTP/1.1 200 OK - Content-Length: 591 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/shows/static/css/images/showicons.png?r=38841 cache stored in: QJM5KT6J/showicons[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 5130 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 591 macb r/rrwxrwxrwx 0 0 11941-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/xd_receiver[1].htm Fri Jul 01 2011 15:10:47 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.collective-media.net/cmadj/say.education/lifestyle.ros_anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doublec_kw=_mc=c_dcopt=ist_sz=728x90_net=say_ord=5898682066020169_env=ifr_ord1=216082_cmpgurl=http%3A//www.education.com/video/cookingwithkids/? cache stored in: YZCXGNW1/cookingwithkids[2] - HTTP/1.1 200 OK - Content-Length: 7443 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.collective-media.net/cmadj/say.education/lifestyle.ros_anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=top;mtfIFPath=/doubleclic_kw=_mc=c_dcopt=ist_sz=300x250_net=say_ord=5852495192354399_env=ifr_ord1=578234_cmpgurl=http%3A//www.education.com/video/cookingwithkids/? cache stored in: SLK18LSF/cookingwithkids[4] - HTTP/1.1 200 OK - Content-Length: 7445 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.collective-media.net/cmadj/say.education/lifestyle.ros_anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=top;mtfIFPath=/doubleclic_kw=_mc=c_dcopt=ist_sz=728x90_net=say_ord=4069872453600203.5_env=ifr_ord1=411320_cmpgurl=http%3A//www.education.com/video/cookingwithkids/? cache stored in: UPQVMROL/cookingwithkids[2] - HTTP/1.1 200 OK - Content-Length: 7445 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/say.education/lifestyle.ros_net=say_u=-say-30100768967_1309558212-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=top;mtfIFPath=/doubleclic_kw=_mc=c_dcopt=ist_cmw=owl_sz=300x250_net=say_env=ifr_ord1=578234_contx=education_dc=s_btg=_ord=5852495192354399? cache stored in: UPQVMROL/bbler;position=top;mtfIFPath=/doubleclic_kw=_mc=c_dcopt=ist_cmw=owl_sz=300x250_net=say_env=ifr_ord1=578234_contx=education_dc=s_btg=_ord=5852495192354399 - HTTP/1.1 200 OK - Content-Type: application/x-javascript - Content-Length: 178 - Content-Encoding: gzip (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://r.openx.net/set?pid=408c9df8-85fe-6893-4938-ccbfd204601e&rtb=5849478133596709538 cache stored in: QJM5KT6J/set[1].gif - HTTP/1.1 200 OK - Pragma: no-cache - P3P: CP="CUR ADM OUR NOR STA NID" - Content-Length: 43 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:openx.net/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:turn.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 500 macb r/rrwxrwxrwx 0 0 11850-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/rawberry%2BRaspberry%2BCobbler%3Bposition%3Dtop%3BmtfIFPath%3D%2Fdoubleclic;kw=;mc=c;dcopt=ist;sz=300x250;ord=5852495192354399? 7445 macb r/rrwxrwxrwx 0 0 11864-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/cookingwithkids[4] 477 macb r/rrwxrwxrwx 0 0 11876-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CAYRGTQD.5? 633 macb r/rrwxrwxrwx 0 0 11878-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/lif[1].com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=top;mtfIFPath=/doubleclic;kw=;mc=c;dcopt=ist;sz=300x250;ord=5852495192354399 97 macb r/rrwxrwxrwx 0 0 11884-128-1 /Documents and Settings/malware/Cookies/malware@openx[1].txt 678 ...b r/rrwxrwxrwx 0 0 11891-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/dref=http%3A%2F%2Fwww.education[1].com%2Fvideo%2Fcookingwithkids%2F 43 macb r/rrwxrwxrwx 0 0 11902-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/set[1].gif 178 macb r/rrwxrwxrwx 0 0 11944-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/bbler;position=top;mtfIFPath=/doubleclic;kw=;mc=c;dcopt=ist;cmw=owl;sz=300x250;net=say;env=ifr;ord1=578234;contx=education;dc=s;btg=;ord=5852495192354399 634 macb r/rrwxrwxrwx 0 0 11945-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/lifestyle.ros;anx=10;referer=http://ad.doubleclick.net/adi/video.education[1].5 478 macb r/rrwxrwxrwx 0 0 11946-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/trawberry%2BRaspberry%2BCobbler%3Bposition%3Dbottom%3BmtfIFPath%3D%2Fdoublec;kw=;mc=c;dcopt=ist;sz=728x90;ord=5898682066020169? 632 macb r/rrwxrwxrwx 0 0 11947-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/life[1].com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doublec;kw=;mc=c;dcopt=ist;sz=728x90;ord=5898682066020169 81 macb r/rrwxrwxrwx 0 0 11948-128-1 /Documents and Settings/malware/Cookies/malware@turn[1].txt 7445 macb r/rrwxrwxrwx 0 0 11949-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/cookingwithkids[2] 7443 macb r/rrwxrwxrwx 0 0 11950-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/cookingwithkids[2] 902 ...b r/rrwxrwxrwx 0 0 11993-128-4 /Documents and Settings/malware/Cookies/malware@collective-media[1].txt Fri Jul 01 2011 15:10:48 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/N6457.4298.ADVERTISING.COM/B4840137.64_sz=300x250_medium=cpc_campaign=ron_source=adv_a=banner_i=burger_s=300x250_p=0000807609_click=http://r1-ads.ace.advertising.com/click/site=0000807609/mnum=0000939560/cstr=10093984=_4e0e45c5-3572274364-807609^939560^1183^0-1_/xsxdata=$xsxdata/bnum=10093984/optn=64?trg=_ord=3572274364? cache stored in: UPQVMROL/optn=64[2] - HTTP/1.1 200 OK - Content-Length: 6223 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/say.education/lifestyle.ros_net=say_u=-say-30202011094_1309558213-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=top;mtfIFPath=/doubleclic_kw=_mc=c_dcopt=ist_cmw=owl_sz=728x90_net=say_env=ifr_ord1=411320_contx=education_dc=s_btg=_ord=4069872453600203.5? cache stored in: SLK18LSF/lifestyle.ros_net=say_u=-say-30202011094_1309558213-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education[2].5 - HTTP/1.1 200 OK - Content-Length: 1226 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/say.education/lifestyle.ros_net=say_u=-say-30218018003_1309558213-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doublec_kw=_mc=c_dcopt=ist_cmw=owl_sz=728x90_net=say_env=ifr_ord1=216082_contx=education_dc=s_btg=_ord=5898682066020169? cache stored in: QJM5KT6J/obbler;position=bottom;mtfIFPath=/doublec_kw=_mc=c_dcopt=ist_cmw=owl_sz=728x90_net=say_env=ifr_ord1=216082_contx=education_dc=s_btg=_ord=5898682066020169 - HTTP/1.1 200 OK - Content-Type: application/x-javascript - Content-Length: 543 - Content-Encoding: gzip (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://bid.openx.net/jstag cache stored in: SLK18LSF/jstag[1] - HTTP/1.1 200 OK - Content-Type: text/javascript_ charset=iso-8859-1 - P3P: CP="CUR ADM OUR NOR STA NID" - Content-Length: 1454 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://bn.xp1.ru4.com/nf?_pnot=0&_tpc=http://bid.openx.net/click?cd=H4sIAAAAAAAAABXL3QlCMQwG0M9fChecwjcJtLdNbjKAjzpE03QCwYVcxb3E834W7ABcRx9RJgupB1MLb6R5ColyX61GZ9GE_fNy_y44_IcZ143NqDgXqm0V8ixOORprWOlzRMIR2G4JJ-DzTjgDrwd-PB332nMAAAA=&dst=http%3A%2F%2Fallstate.com&_wp=AAABMOfAjJwjg7XitTy8onxN7bmlFsBhtdpqFg&_nv=1&_CDbg=17087057&_eo=97956&_sm=0&_nm=FgAAAAAAAABzZXJpYWxpemF0aW9uOjphcmNoaXZlBQQIBAgBAAAAAAEBAAEAAAAAAFG6BAEAAAAAwp4KAQAAAAC9oAQBAAAAAGynCgEAAAAAxaIKAQAAAAAGuAQBAAAAADZ7-0EAAAAAAADwPwAAAAAAAAAApH4BAAAAAACjLQAAAAAAAKR-AQAAAAAAJAAAAAAAAABkYmRlMWY1Ni04Y2U1LTRlYzQtODBmNi02ODViMjkzZWI1NjgkAAAAAAAAADkyYjNmODFlLTM3MTItNGI4Mi1mNTBkLWM1M2NkMjdmN2VhMAAAAAAAAAAADgAAAAAAAAAxOTguMTc2LjIyOS4xMAYAAAAAAAAANzI4eDkwGAAAAAAAAABodHRwOi8vd3d3LmVkdWNhdGlvbi5jb20zAAAAAAAAADk5NTM3NTk5JTJEMWM1MSUyRDM0MjYlMkRjMDZjJTJEMGU0NThlOTFiZmRlXl40MjEwMwIAAAAAAAAAMjMDAAAAHQAAAAAAAAAAAAAAAAAAAADFRQ5OAAAAAA== cache stored in: SLK18LSF/CAPMND12.htm - HTTP/1.1 200 OK - P3p: policyref="/w3c/p3p.xml"- CP="NON DSP COR PSAa OUR STP UNI" - Pragma: no-cache - Content-type: text/html - Content-length: 1433 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-2237930296469909&output=html&h=90&slotname=9246371595&w=728&ea=0&flash=6.0.79.0&url=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=top;mtfIFPath=/doubleclick/;sz=728x90;tile=1;ord=447150484?&dt=1309558248765&shv=r20110622&jsv=r20110627&saldr=1&correlator=1309558248796&frm=8&adk=2416968638&ga_vid=1957759159.1309558249&ga_sid=1309558249&ga_hid=111871895&ga_fc=0&u_tz=-420&u_his=4&u_java=1&u_h=600&u_w=800&u_ah=570&u_aw=800&u_cd=32&u_nplug=0&u_nmime=0&biw=-12245933&bih=-12245933&ifk=104515425&fu=0&ifi=1&dtd=47 cache stored in: YZCXGNW1/CA09AZ0X.htm - HTTP/1.1 200 OK - Content-Length: 5356 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://googleads.g.doubleclick.net/pagead/test_domain.js cache stored in: QJM5KT6J/test_domain[2].js - HTTP/1.1 200 OK - Content-Length: 52 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png cache stored in: SLK18LSF/ad_choices_en[1].png - HTTP/1.1 200 OK - P3P: policyref="http://www.googleadservices.com/pagead/p3p.xml"- CP="NOI DEV PSA PSD IVA PVD OTP OUR OTR IND OTC" - Content-Type: image/png - X-Content-Type-Options: nosniff - Content-Length: 720 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png cache stored in: UPQVMROL/ad_choices_i[1].png - HTTP/1.1 200 OK - P3P: policyref="http://www.googleadservices.com/pagead/p3p.xml"- CP="NOI DEV PSA PSD IVA PVD OTP OUR OTR IND OTC" - Content-Type: image/png - X-Content-Type-Options: nosniff - Content-Length: 265 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pagead2.googlesyndication.com/pagead/js/r20110622/r20110627/abg.js cache stored in: QJM5KT6J/abg[1].js - HTTP/1.1 200 OK - Content-Length: 726 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pagead2.googlesyndication.com/pagead/js/r20110622/r20110627/show_ads_impl.js cache stored in: UPQVMROL/show_ads_impl[2].js - HTTP/1.1 200 OK - Content-Length: 48867 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pagead2.googlesyndication.com/pagead/render_ads.js cache stored in: SLK18LSF/render_ads[2].js - HTTP/1.1 200 OK - Content-Length: 287 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pagead2.googlesyndication.com/pagead/show_ads.js cache stored in: YZCXGNW1/show_ads[2].js - HTTP/1.1 200 OK - Content-Length: 13092 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://s0.2mdn.net/2895566/300250-hotdang-nat.jpg cache stored in: YZCXGNW1/300250-hotdang-nat[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Content-Type-Options: nosniff - Content-Length: 31178 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:d.tradex.openx.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:ru4.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 1433 macb r/rrwxrwxrwx 0 0 11305-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/CAPMND12.htm 43 macb r/rrwxrwxrwx 0 0 11518-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/pc[1] 678 mac. r/rrwxrwxrwx 0 0 11891-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/dref=http%3A%2F%2Fwww.education[1].com%2Fvideo%2Fcookingwithkids%2F 543 macb r/rrwxrwxrwx 0 0 11952-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/obbler;position=bottom;mtfIFPath=/doublec;kw=;mc=c;dcopt=ist;cmw=owl;sz=728x90;net=say;env=ifr;ord1=216082;contx=education;dc=s;btg=;ord=5898682066020169 1226 macb r/rrwxrwxrwx 0 0 11953-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/lifestyle.ros;net=say;u=,say-30202011094_1309558213,1210b8131a8c6a2,education,;;anx=10;referer=http://ad.doubleclick.net/adi/video.education[2].5 6223 macb r/rrwxrwxrwx 0 0 11955-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/optn=64[2] 104 macb r/rrwxrwxrwx 0 0 11956-128-1 /Documents and Settings/malware/Cookies/malware@d.tradex.openx[1].txt 31178 macb r/rrwxrwxrwx 0 0 11957-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/300250-hotdang-nat[1].jpg 2034 macb r/rrwxrwxrwx 0 0 11959-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/26270-2[2].js 3566 macb r/rrwxrwxrwx 0 0 11961-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/tion=bottom;mtfIFPath=/doubleclick/;sz=728x90;ord=447150484?&cid=oxpv1:34-632-1929-1968-5551&hrid=c0aed95de7cab8d0692f6cf4e96e925a-1309558213 27 macb r/rrwxrwxrwx 0 0 11962-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/op;mtfIFPath=/doubleclick/;sz=728x90;tile=1;ord=447150484?&cid=oxpv1:34-632-1929-1968-5551&hrid=a16c7d40422247443fa99673b4aa3811-1309558213 5356 macb r/rrwxrwxrwx 0 0 11963-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/CA09AZ0X.htm 49 macb r/rrwxrwxrwx 0 0 11964-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tap[3].gif 153 macb r/rrwxrwxrwx 0 0 11965-128-1 /Documents and Settings/malware/Cookies/malware@ru4[2].txt 918 ...b r/rrwxrwxrwx 0 0 11986-128-4 /Documents and Settings/malware/Cookies/malware@invitemedia[2].txt Fri Jul 01 2011 15:10:49 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) LEAK record URL:http://servedby.adxpose.com/adxpose/find_ad.js cache stored in: YZCXGNW1/find_ad[1].js - HTTP/1.1 200 - ETag: "b958507f4a1625ef14135371f1b1b98f:1309368071" - Content-Type: application/x-javascript - Content-Encoding: gzip - Content-Length: 1103 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adi/N5271.159469.AOD-INVITE/B5501350.4_sz=728x90_pc=[TPAS_ID]_click=http://g.ca.bid.invitemedia.com/pixel?returnType=redirect&key=Click&message=eJwVjDsOwzAMQ68SaK4ByZL16W2Cwp6CbpmC3r30xPcAkg.p0vuo7K6vg7RD3MxTYAIhXpLqGU1OzmbG2s6Y3NZnzlW82NNpT3e5QiW27Z9CDmRoBdCA3_u6gA6U0XnI7w_GARru&redirectURL=_ord=0f183687-1a08-4403-a7e0-fceef90f0686? cache stored in: SLK18LSF/pixel[1].htm - HTTP/1.1 200 OK - Content-Length: 6838 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adi/x1.rtb/allstate/poem1_sz=728x90_click=http://bn.xp1.ru4.com/bclick?_f=dbde1f56-8ce5-4ec4-80f6-685b293eb568&_o=15719&_eo=97956&_et=1309558213&_a=17087057&_s=11683&_d=17473218&_c=17080509&_pm=97956&_pn=17475436&redirect=_u=17475436_ord=2448040? cache stored in: UPQVMROL/bclick[1].htm - HTTP/1.1 200 OK - Content-Length: 7758 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://edge.quantserve.com/quant.js cache stored in: QJM5KT6J/quant[1].js - HTTP/1.1 200 OK - Content-Length: 5265 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://g.ca.bid.invitemedia.com/rubicon_imp?returnType=image&key=AdImp&cost=0.735504&creativeID=117461&message=eJwVjDsOwzAMQ68SaK4ByZL16W2Cwp6CbpmC3r30xPcAkg.p0vuo7K6vg7RD3MxTYAIhXpLqGU1OzmbG2s6Y3NZnzlW82NNpT3e5QiW27Z9CDmRoBdCA3_u6gA6U0XnI7w_GARru&managed=false cache stored in: QJM5KT6J/rubicon_imp[1].gif - HTTP/1.0 200 OK - P3P: policyref="/w3c/p3p.xml"- CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC" - Content-Type: image/gif - Pragma: no-cache - Content-Length: 43 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pixel.invitemedia.com/data_sync?partner_id=77&exchange_id=9 cache stored in: QJM5KT6J/data_sync[1].htm - HTTP/1.0 200 OK - P3P: policyref="/w3c/p3p.xml"- CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC" - Content-Type: text/html - Pragma: no-cache - Content-Length: 512 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://s0.2mdn.net/1917241/1-AHNL0918_Truth_Save45_728x90.jpg cache stored in: YZCXGNW1/1-AHNL0918_Truth_Save45_728x90[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Content-Type-Options: nosniff - Content-Length: 19195 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://servedby.adxpose.com/adxpose/find_ad.js cache stored in: YZCXGNW1/find_ad[2].js - HTTP/1.1 200 OK - Content-Length: 2481 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 6838 macb r/rrwxrwxrwx 0 0 11291-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/pixel[1].htm 0 macb r/rrwxrwxrwx 0 0 11818-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/pxrucm[1].htm 43 macb r/rrwxrwxrwx 0 0 11860-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/rubicon_imp[1].gif 7758 macb r/rrwxrwxrwx 0 0 11967-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/bclick[1].htm 19195 macb r/rrwxrwxrwx 0 0 11968-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/1-AHNL0918_Truth_Save45_728x90[1].jpg 2456 macb r/rrwxrwxrwx 0 0 11972-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/26271-15[2].js 744 macb r/rrwxrwxrwx 0 0 11973-128-3 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/CAOK913A 4525 macb r/rrwxrwxrwx 0 0 11974-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/26271-2[3].js 512 macb r/rrwxrwxrwx 0 0 11976-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/data_sync[1].htm 2481 macb r/rrwxrwxrwx 0 0 11979-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/find_ad[2].js Fri Jul 01 2011 15:10:50 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/cm.appnexus/wireless_ron_sz=300x250_app=wireless_ron_click0=http://ib.adnxs.com/click?muNWQmeR-D8IVWr2QKv1PwAAAAAAAPg_FM_ZAkKr9T_FILByaJH4P9JAT0EG8m05omJy4l6FLVHGRQ5OAAAAAEG7BwDLAQAANwEAAAIAAABtLwcAzwkBAAEAAABVU0QAVVNEACwB-gCkIJ8DwQ0BAQUCAQQAAAAAlSLPQAAAAAA./cnd=!4gRBKAi9gQYQ7d4cGM-TBCAA/referrer=http://ridethepine.mevio.com//clickenc=_ord=1309558214? cache stored in: SLK18LSF/CA0XYZGP. - HTTP/1.1 200 OK - Content-Length: 9625 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cdn.doubleverify.com/script7.js?agnc=2981993&cmp=5629905&crt=42724427&crtname=&adnet=&dvtagver=3.3.1346.2176&adsrv=1&plc=65638121&advid=2981993&sid=457626&adid=242743000 cache stored in: UPQVMROL/script7[2].js - HTTP/1.1 200 OK - Content-Length: 40021 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cheetah.vizu.com/a.gif?cid=1947_adid=42621945_siteid=N5271.159469.AOD-INVITE_adtype=1_stype=7_siteurl=qydjuk.com_wc=portland_cust1=_cust2=_cust3=_cust4=_cust5=_ver=v5_o=winxp_ua=msie_uv=6.0_lan=en-us_fv=null_id=1309558250265_t=1309558250281 cache stored in: QJM5KT6J/a[1].gif - HTTP/1.1 200 OK - X-Px: ht lax-am6-n10.panthercdn.com - ETag: "3c04c-2b-edb95b80" - Content-Length: 43 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cheetah.vizu.com/f.gif?cd=4_cid=1947_adid=42621945_siteid=N5271.159469.AOD-INVITE_adtype=1_stype=7_siteurl=qydjuk.com_wc=portland_cust1=_cust2=_cust3=_cust4=_cust5=_ver=v5_o=winxp_ua=msie_uv=6.0_lan=en-us_fv=null_id=1309558250265_t=1309558250296f.gif?cid=1947_adid=42621945_siteid=N5271.159469.AOD-INVITE_adtype=1_stype=7_siteurl=qydjuk.com_wc=portland_cust1=_cust2=_cust3=_cust4=_cust5=_ver=v5_o=winxp_ua=msie_uv=6.0_lan=en-us_fv=null_id=1309558250265_t=1309558250296 cache stored in: UPQVMROL/CA0RMZ4D.gif - HTTP/1.1 200 OK - X-Px: ht lax-am6-n10.panthercdn.com - ETag: "3c050-2b-edb95b80" - Content-Length: 43 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cheetah.vizu.com/i.gif?cid=1947_adid=42621945_siteid=N5271.159469.AOD-INVITE_adtype=1_stype=7_siteurl=qydjuk.com_wc=portland_cust1=_cust2=_cust3=_cust4=_cust5=_ver=v5_o=winxp_ua=msie_uv=6.0_lan=en-us_fv=null_id=1309558250265_t=1309558250296 cache stored in: SLK18LSF/i[1].gif - HTTP/1.1 200 OK - X-Px: ht lax-am6-n10.panthercdn.com - ETag: "3c051-2b-775728c0" - Content-Length: 43 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://data.aggregateknowledge.com/pixel!t=650!?che=1364060&camid=5629905&plaid=65638121&creid=42724427&adgid=242743000 cache stored in: UPQVMROL/pixel!t=650![1].gif - HTTP/1.1 200 OK - P3P: CP="NOI DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" - ETag: W/"43-1308732886000" - Content-Type: image/gif - Content-Language: en-US - Content-Length: 43 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://log50.doubleverify.com/visitor.aspx?query=agnc=2981993&cmp=5629905&crt=42724427&crtname=&adnet=&dvtagver=3.3.1346.2176&adsrv=1&plc=65638121&advid=2981993&sid=457626&adid=242743000&&srcurl=http://qydjuk.com/fw-nonplayer-banner.php?w=300&h=250&fwcsid=home&btf=1&is_ex=no&btype=1&zone=shows&num=7&random=0.22802316464568123 cache stored in: UPQVMROL/CAWBQ9IH.jpg - HTTP/1.1 200 OK - Content-Length: 0 - Content-Type: image/jpeg - X-AspNet-Version: 2.0.50727 - X-Powered-By: ASP.NET (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pixel.invitemedia.com/adnxs_sync?uid=5849478133596709538 cache stored in: SLK18LSF/adnxs_sync[1].gif - HTTP/1.0 200 OK - P3P: policyref="/w3c/p3p.xml"- CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC" - Content-Type: image/gif - Pragma: no-cache - Content-Length: 43 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pixel.rubiconproject.com/tap.php?v=6895!_0 cache stored in: UPQVMROL/tap[1].gif - HTTP/1.1 200 OK - X-Powered-By: PHP/5.1.6 - P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" - Content-Length: 49 - Keep-Alive: timeout=45- max=480 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://puma.vizu.com/cdn/00/00/19/47/smart_tag.js?adid=42621945_siteid=N5271.159469.AOD-INVITE_wc=portland_ord=[RANDOM] cache stored in: QJM5KT6J/smart_tag[2].js - HTTP/1.1 200 OK - Content-Length: 12686 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://s0.2mdn.net/2981993/300x250_062011_NATL_PROMO_INCREDIBLE2_v2.swf cache stored in: UPQVMROL/300x250_062011_NATL_PROMO_INCREDIBLE2_v2[1].swf - HTTP/1.1 200 OK - Content-Type: application/x-shockwave-flash - X-Content-Type-Options: nosniff - Content-Length: 30302 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://s0.2mdn.net/3175310/728x90_SONIC_BURGERS_LTO_051611.jpg cache stored in: SLK18LSF/728x90_SONIC_BURGERS_LTO_051611[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Content-Type-Options: nosniff - Content-Length: 30605 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:ad.yieldmanager.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:aggregateknowledge.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:displaymarketplace.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:invitemedia.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 30605 macb r/rrwxrwxrwx 0 0 11295-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/728x90_SONIC_BURGERS_LTO_051611[1].jpg 43 macb r/rrwxrwxrwx 0 0 11299-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/i[1].gif 0 macb r/rrwxrwxrwx 0 0 11507-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CAWBQ9IH.jpg 43 macb r/rrwxrwxrwx 0 0 11524-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/adnxs_sync[1].gif 82 macb r/rrwxrwxrwx 0 0 11692-128-1 /Documents and Settings/malware/Cookies/malware@displaymarketplace[1].txt 221 ...b r/rrwxrwxrwx 0 0 11694-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/rubicon_sync[1].htm 350 mac. r/rrwxrwxrwx 0 0 11774-128-1 /Documents and Settings/malware/Cookies/malware@aggregateknowledge[2].txt 49 mac. r/rrwxrwxrwx 0 0 11951-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/tap[1].gif 9625 macb r/rrwxrwxrwx 0 0 11980-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/CA0XYZGP 606 mac. r/rrwxrwxrwx 0 0 11981-128-4 /Documents and Settings/malware/Cookies/malware@ad.yieldmanager[1].txt 684 macb r/rrwxrwxrwx 0 0 11982-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/imp[4] 5088 macb r/rrwxrwxrwx 0 0 11983-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/displayscript[1].js 12686 macb r/rrwxrwxrwx 0 0 11984-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/smart_tag[2].js 43 macb r/rrwxrwxrwx 0 0 11985-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/pixel!t=650![1].gif 918 mac. r/rrwxrwxrwx 0 0 11986-128-4 /Documents and Settings/malware/Cookies/malware@invitemedia[2].txt 43 macb r/rrwxrwxrwx 0 0 11987-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/a[1].gif 43 macb r/rrwxrwxrwx 0 0 11988-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CA0RMZ4D.gif Fri Jul 01 2011 15:10:58 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Application Popup/26_Info_Windows - Delayed Write Filed - Windows was unable to save all the data for the file //System32//496A8300. The data has been lost. This error may be caused by a failure of your computer hardware. (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 15:11:17 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.collective-media.net/cmadj/say.education/lifestyle.ros_anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doublec_kw=_mc=c_dcopt=ist_sz=728x90_net=say_ord=1161457868414135.7_env=ifr_ord1=9781_cmpgurl=http%3A//www.education.com/video/cookingwithkids/? cache stored in: UPQVMROL/cookingwithkids[3] - HTTP/1.1 200 OK - Content-Length: 7443 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.collective-media.net/cmadj/say.education/lifestyle.ros_anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doublec_kw=_mc=c_dcopt=ist_sz=728x90_net=say_ord=2702389741219982.5_env=ifr_ord1=764815_cmpgurl=http%3A//www.education.com/video/cookingwithkids/? cache stored in: QJM5KT6J/cookingwithkids[4] - HTTP/1.1 200 OK - Content-Length: 7445 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adi/video.education.com/video_kw=Video+Strawberry+Raspberry+Cobbler_position=bottom_mtfIFPath=/doubleclick/_sz=728x90_ord=447150484? cache stored in: UPQVMROL/_sz=728x90_ord=447150484[1].htm - HTTP/1.1 200 OK - Content-Length: 319 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adi/video.education.com/video_kw=Video+Strawberry+Raspberry+Cobbler_position=top_mtfIFPath=/doubleclick/_sz=300x250_tile=2_ord=447150484? cache stored in: SLK18LSF/_sz=300x250_tile=2_ord=447150484[1].htm - HTTP/1.1 200 OK - Content-Length: 321 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adi/video.education.com/video_kw=Video+Strawberry+Raspberry+Cobbler_position=top_mtfIFPath=/doubleclick/_sz=728x90_tile=1_ord=447150484? cache stored in: UPQVMROL/_sz=728x90_tile=1_ord=447150484[1].htm - HTTP/1.1 200 OK - Content-Length: 319 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ads.sixapart.com/custom?id=say.education/lifestyle.ros/300x250&js=1 cache stored in: QJM5KT6J/custom[1] - HTTP/1.0 200 OK - Content-Type: text/javascript_ charset=utf-8 - Content-length: 639 - Pragma: no-cache (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ads.sixapart.com/custom?id=say.education/lifestyle.ros/728x90&js=1 cache stored in: QJM5KT6J/custom[2] - HTTP/1.0 200 OK - Content-Type: text/javascript_ charset=utf-8 - Content-length: 636 - Pragma: no-cache (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:adnxs.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:collective-media.net/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 639 mac. r/rrwxrwxrwx 0 0 11193-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/custom[1] 636 macb r/rrwxrwxrwx 0 0 11276-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/custom[2] 469 macb r/rrwxrwxrwx 0 0 11785-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/rawberry%2BRaspberry%2BCobbler%3Bposition%3Dtop%3BmtfIFPath%3D%2Fdoubleclic;kw=;mc=c;dcopt=ist;sz=300x250;ord=6753657440704408? 549 macb r/rrwxrwxrwx 0 0 11799-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CAY707SJ.7? 634 macb r/rrwxrwxrwx 0 0 11804-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/lifestyle.ros;anx=10;referer=http://ad.doubleclick.net/adi/video.education[1].7 319 mac. r/rrwxrwxrwx 0 0 11820-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/;sz=728x90;ord=447150484[1].htm 321 mac. r/rrwxrwxrwx 0 0 11833-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/;sz=300x250;tile=2;ord=447150484[1].htm 319 mac. r/rrwxrwxrwx 0 0 11848-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/;sz=728x90;tile=1;ord=447150484[1].htm 497 macb r/rrwxrwxrwx 0 0 11873-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/CAANWP69.5? 633 ...b r/rrwxrwxrwx 0 0 11910-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/lif[1].com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=top;mtfIFPath=/doubleclic;kw=;mc=c;dcopt=ist;sz=300x250;ord=6753657440704408 634 macb r/rrwxrwxrwx 0 0 11960-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/lifestyle.ros;anx=10;referer=http://ad.doubleclick.net/adi/video.education[1].5 807 macb r/rrwxrwxrwx 0 0 11966-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/image[1].gif 7443 macb r/rrwxrwxrwx 0 0 11970-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/cookingwithkids[3] 9359 mac. r/rrwxrwxrwx 0 0 11990-128-4 /Documents and Settings/malware/Cookies/malware@adnxs[1].txt 7445 macb r/rrwxrwxrwx 0 0 11992-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/cookingwithkids[4] 902 mac. r/rrwxrwxrwx 0 0 11993-128-4 /Documents and Settings/malware/Cookies/malware@collective-media[1].txt Fri Jul 01 2011 15:11:18 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.collective-media.net/cmadj/say.education/lifestyle.ros_anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=top;mtfIFPath=/doubleclic_kw=_mc=c_dcopt=ist_sz=300x250_net=say_ord=6753657440704408_env=ifr_ord1=183903_cmpgurl=http%3A//www.education.com/video/cookingwithkids/? cache stored in: SLK18LSF/cookingwithkids[5] - HTTP/1.1 200 OK - Content-Length: 7445 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a1.interclick.com/getInPageJS.aspx?a=53&b=51556&cid=634237964237568639 cache stored in: SLK18LSF/getInPageJS[1].htm - HTTP/1.1 200 OK - Content-Length: 6352 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/N4190.advertising.com/B5416523_sz=300x250_click=http://r1-ads.ace.advertising.com/click/site=0000807609/mnum=0001008683/cstr=29628270=_4e0e45e3-0706750464-807609^1008683^1183^0-1_/xsxdata=$xsxdata/bnum=29628270/optn=64?trg=_ord=0706750464? cache stored in: UPQVMROL/optn=64[1] - HTTP/1.1 200 OK - Content-Length: 5327 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/N5654.128132.INTERCLICK/B5590507.4_sz=728x90_click=http://a1.interclick.com/icaid/171627/tid/a3192cd9-8a6b-4562-8341-a9e6cd1bbe58/click.ic?_ord=634451406441722953? cache stored in: YZCXGNW1/click[2].ic - HTTP/1.1 200 OK - Content-Length: 5636 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/say.education/lifestyle.ros_net=say_u=-say-30208127146_1309558243-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=top;mtfIFPath=/doubleclic_kw=_mc=c_dcopt=ist_cmw=owl_sz=300x250_net=say_env=ifr_ord1=183903_contx=education_dc=s_btg=_ord=6753657440704408? cache stored in: QJM5KT6J/bbler;position=top;mtfIFPath=/doubleclic_kw=_mc=c_dcopt=ist_cmw=owl_sz=300x250_net=say_env=ifr_ord1=183903_contx=education_dc=s_btg=_ord=6753657440704408 - HTTP/1.1 200 OK - Content-Type: application/x-javascript - Content-Length: 178 - Content-Encoding: gzip (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/say.education/lifestyle.ros_net=say_u=-say-30314962377_1309558242-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doublec_kw=_mc=c_dcopt=ist_cmw=owl_sz=728x90_net=say_env=ifr_ord1=9781_contx=education_dc=s_btg=_ord=1161457868414135.7? cache stored in: YZCXGNW1/lifestyle.ros_net=say_u=-say-30314962377_1309558242-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education[2].7 - HTTP/1.1 200 OK - Content-Length: 1251 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ad.doubleclick.net/adj/say.education/lifestyle.ros_net=say_u=-say-30321035690_1309558243-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education.com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=bottom;mtfIFPath=/doublec_kw=_mc=c_dcopt=ist_cmw=owl_sz=728x90_net=say_env=ifr_ord1=764815_contx=education_dc=s_btg=_ord=2702389741219982.5? cache stored in: UPQVMROL/lifestyle.ros_net=say_u=-say-30321035690_1309558243-1210b8131a8c6a2-education-__anx=10_referer=http://ad.doubleclick.net/adi/video.education[2].5 - HTTP/1.1 200 OK - Content-Length: 1251 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cdn.interclick.com/DtCol.aspx cache stored in: SLK18LSF/DtCol[1].htm - HTTP/1.1 200 OK - Content-Length: 3790 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://s0.2mdn.net/2272874/Orkin_Ad.com_LToEat_300x250_2011_8778714752.jpg cache stored in: SLK18LSF/Orkin_Ad.com_LToEat_300x250_2011_8778714752[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Content-Type-Options: nosniff - Content-Length: 15244 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://s0.2mdn.net/2653838/statefarm_ddc_v1_728x90.jpg cache stored in: QJM5KT6J/statefarm_ddc_v1_728x90[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Content-Type-Options: nosniff - Content-Length: 17288 - X-XSS-Protection: 1_ mode=block (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://s0.2mdn.net/879366/flashwrite_1_2.js cache stored in: UPQVMROL/flashwrite_1_2[2].js - HTTP/1.1 200 OK - Content-Length: 801 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://tags.bluekai.com/site/3085?id=5849478133596709538 cache stored in: UPQVMROL/3085[1].gif - HTTP/1.1 200 OK - P3P: CP="NOI DSP COR CUR ADMo DEVo PSAo PSDo OUR SAMo BUS UNI NAV"- policyref="http://tags.bluekai.com/w3c/p3p.xml" - BK-Server: f778 - Content-Length: 62 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:a1.interclick.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:w55c.net/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 595 macb r/rrwxrwxrwx 0 0 11895-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/dref=http%3A%2F%2Fwww.education[1].com%2Fvideo%2Fcookingwithkids%2F 633 mac. r/rrwxrwxrwx 0 0 11910-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/lif[1].com/video;kw=Video+Strawberry+Raspberry+Cobbler;position=top;mtfIFPath=/doubleclic;kw=;mc=c;dcopt=ist;sz=300x250;ord=6753657440704408 62 macb r/rrwxrwxrwx 0 0 11991-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/3085[1].gif 7445 macb r/rrwxrwxrwx 0 0 11994-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/cookingwithkids[5] 105 macb r/rrwxrwxrwx 0 0 11995-128-1 /Documents and Settings/malware/Cookies/malware@w55c[1].txt 178 macb r/rrwxrwxrwx 0 0 11996-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/bbler;position=top;mtfIFPath=/doubleclic;kw=;mc=c;dcopt=ist;cmw=owl;sz=300x250;net=say;env=ifr;ord1=183903;contx=education;dc=s;btg=;ord=6753657440704408 1251 macb r/rrwxrwxrwx 0 0 11997-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/lifestyle.ros;net=say;u=,say-30314962377_1309558242,1210b8131a8c6a2,education,;;anx=10;referer=http://ad.doubleclick.net/adi/video.education[2].7 486 macb r/rrwxrwxrwx 0 0 11998-128-1 /Documents and Settings/malware/Cookies/malware@a1.interclick[1].txt 1251 macb r/rrwxrwxrwx 0 0 11999-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/lifestyle.ros;net=say;u=,say-30321035690_1309558243,1210b8131a8c6a2,education,;;anx=10;referer=http://ad.doubleclick.net/adi/video.education[2].5 6352 macb r/rrwxrwxrwx 0 0 12001-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/getInPageJS[1].htm 17288 macb r/rrwxrwxrwx 0 0 12003-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/statefarm_ddc_v1_728x90[1].jpg 5636 macb r/rrwxrwxrwx 0 0 12004-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/click[2].ic 15244 macb r/rrwxrwxrwx 0 0 12005-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/Orkin_Ad.com_LToEat_300x250_2011_8778714752[1].jpg 5327 macb r/rrwxrwxrwx 0 0 12006-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/optn=64[1] 3790 macb r/rrwxrwxrwx 0 0 12008-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/DtCol[1].htm 311 ...b r/rrwxrwxrwx 0 0 12031-128-1 /Documents and Settings/malware/Cookies/malware@interclick[2].txt Fri Jul 01 2011 15:11:19 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a1.interclick.com/gtpdp.aspx?i=50 cache stored in: SLK18LSF/gtpdp[1].htm - HTTP/1.1 200 OK - Content-Length: 1580 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://adadvisor.net/adscores/g.js?sid=9212076087 cache stored in: YZCXGNW1/g[1].js - HTTP/1.1 200 OK - P3P: policyref="http://www.adadvisor.net/w3c/p3p.xml"-CP="NOI NID" - Content-Length: 38 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cdn.interclick.com/RSltPrc.aspx?i=100&e=1310163079078 cache stored in: QJM5KT6J/RSltPrc[1].htm - HTTP/1.1 200 OK - X-Px: ht lax-am6-n19.panthercdn.com - P3P: policyref="http://www.interclick.com/w3c/p3p.xml"-CP="NON DSP ADM DEV PSD OUR IND PRE NAV UNI" - Content-Length: 694 - Content-Type: text/html_ charset=utf-8 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cdn.interclick.com/RSltPrc.aspx?i=100&e=1310163079093 cache stored in: YZCXGNW1/RSltPrc[1].htm - HTTP/1.1 200 OK - X-Px: ht lax-am6-n19.panthercdn.com - P3P: policyref="http://www.interclick.com/w3c/p3p.xml"-CP="NON DSP ADM DEV PSD OUR IND PRE NAV UNI" - Content-Length: 694 - Content-Type: text/html_ charset=utf-8 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cdn.interclick.com/RSltPrc.aspx?i=20&e=1312150279031 cache stored in: SLK18LSF/RSltPrc[1].htm - HTTP/1.1 200 OK - X-Px: ht lax-am6-n19.panthercdn.com - P3P: policyref="http://www.interclick.com/w3c/p3p.xml"-CP="NON DSP ADM DEV PSD OUR IND PRE NAV UNI" - Content-Length: 694 - Content-Type: text/html_ charset=utf-8 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cdn.interclick.com/RSltPrc.aspx?i=20&e=1312150279093 cache stored in: SLK18LSF/RSltPrc[2].htm - HTTP/1.1 200 OK - X-Px: ht lax-am6-n19.panthercdn.com - P3P: policyref="http://www.interclick.com/w3c/p3p.xml"-CP="NON DSP ADM DEV PSD OUR IND PRE NAV UNI" - Content-Length: 694 - Content-Type: text/html_ charset=utf-8 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cdn.interclick.com/RSltPrc.aspx?i=50&e=1312150279203 cache stored in: QJM5KT6J/RSltPrc[2].htm - HTTP/1.1 200 OK - X-Px: ht lax-am6-n19.panthercdn.com - P3P: policyref="http://www.interclick.com/w3c/p3p.xml"-CP="NON DSP ADM DEV PSD OUR IND PRE NAV UNI" - Content-Length: 694 - Content-Type: text/html_ charset=utf-8 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cdn.interclick.com/RSltPrc.aspx?i=50&e=1312150279421 cache stored in: QJM5KT6J/RSltPrc[3].htm - HTTP/1.1 200 OK - X-Px: ht lax-am6-n19.panthercdn.com - P3P: policyref="http://www.interclick.com/w3c/p3p.xml"-CP="NON DSP ADM DEV PSD OUR IND PRE NAV UNI" - Content-Length: 694 - Content-Type: text/html_ charset=utf-8 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cdn.interclick.com/RSltPrc.aspx?i=90&r=&e=1310163079312 cache stored in: YZCXGNW1/RSltPrc[2].htm - HTTP/1.1 200 OK - X-Px: ht lax-am6-n19.panthercdn.com - P3P: policyref="http://www.interclick.com/w3c/p3p.xml"-CP="NON DSP ADM DEV PSD OUR IND PRE NAV UNI" - Content-Length: 694 - Content-Type: text/html_ charset=utf-8 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cdn.interclick.com/bkdp.aspx cache stored in: YZCXGNW1/bkdp[1].htm - HTTP/1.1 200 OK - Content-Length: 1549 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://cdn.interclick.com/ticolscr.aspx cache stored in: QJM5KT6J/ticolscr[1].htm - HTTP/1.1 200 OK - Content-Length: 1665 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ic.nexac.com/DlCkRd.aspx cache stored in: SLK18LSF/DlCkRd[1].htm - HTTP/1.1 200 OK - Content-Length: 1536 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://load.s3.amazonaws.com/pixel.gif cache stored in: UPQVMROL/pixel[1].gif - HTTP/1.1 200 OK - x-amz-id-2: orXFR9JIhFgEackeV1I2wzCwRkdahtL1VnNw2lEI+1RhBf4069pJa4PT4tNm1zDw - x-amz-request-id: A9507A659740171A - x-amz-meta-s3fox-filesize: 43 - x-amz-meta-s3fox-modifiedtime: 1297679395316 - ETag: "fc94fb0c3ed8a8f909dbc7630a0987ff" - Content-Type: image/gif - Content-Length: 43 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:bluekai.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:exelator.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:interclick.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 1027 mac. r/rrwxrwxrwx 0 0 11300-128-4 /Documents and Settings/malware/Cookies/malware@bluekai[2].txt 869 mac. r/rrwxrwxrwx 0 0 11842-128-4 /Documents and Settings/malware/Cookies/malware@exelator[1].txt 694 macb r/rrwxrwxrwx 0 0 12000-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/RSltPrc[3].htm 1665 macb r/rrwxrwxrwx 0 0 12012-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/ticolscr[1].htm 1549 macb r/rrwxrwxrwx 0 0 12013-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/bkdp[1].htm 38 macb r/rrwxrwxrwx 0 0 12016-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/g[1].js 694 macb r/rrwxrwxrwx 0 0 12017-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/RSltPrc[1].htm 694 macb r/rrwxrwxrwx 0 0 12018-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/RSltPrc[1].htm 1580 macb r/rrwxrwxrwx 0 0 12020-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/gtpdp[1].htm 694 macb r/rrwxrwxrwx 0 0 12021-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/RSltPrc[1].htm 694 macb r/rrwxrwxrwx 0 0 12022-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/RSltPrc[2].htm 694 macb r/rrwxrwxrwx 0 0 12024-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/RSltPrc[2].htm 1536 macb r/rrwxrwxrwx 0 0 12026-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/DlCkRd[1].htm 694 macb r/rrwxrwxrwx 0 0 12028-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/RSltPrc[2].htm 43 macb r/rrwxrwxrwx 0 0 12030-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/pixel[1].gif 311 mac. r/rrwxrwxrwx 0 0 12031-128-1 /Documents and Settings/malware/Cookies/malware@interclick[2].txt Fri Jul 01 2011 15:11:27 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://wd.sharethis.com/api/sharer.php?destination=twitter&url=http://www.education.com/video/cookingwithkids/&title=null&publisher=d0d0d8a8-d1f8-49ff-9318-fed5383cff80&fpc=7639673-130e7bfd914-42860506-3&sessionID=1309558216906.12487&source=chicklet&service=legacy&type=null (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) Fri Jul 01 2011 15:11:28 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://01.edu-cdn.com/themes/sky/i/gradients/gradient-input-blue.gif cache stored in: SLK18LSF/gradient-input-blue[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Cache: HIT - Content-Length: 44 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 898 ...b r/rrwxrwxrwx 0 0 11868-128-4 /Documents and Settings/malware/Cookies/malware@twitter[1].txt Fri Jul 01 2011 15:11:29 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) LEAK record URL:http://a1.twimg.com/a/1309465578/javascripts/loadrunner.js cache stored in: QJM5KT6J/loadrunner[1].js - HTTP/1.1 200 OK - Content-Type: application/javascript - ETag: "17ef743e176e81d7cefba0c679a1cf52" - x-amz-id-2: LeG4FPFq11m2f2XML3HJuS3ifplsXuPxi+NPqDJSQy1X6mwVRAmAMm0M2Gxf6q0X - x-amz-request-id: 2F48C33C58E465E3 - Content-Encoding: deflate - X-WR-MODIFICATION: Content-Length - Content-Length: 2211 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a0.twimg.com/a/1309465578/phoenix/css/tfw.bundle.css cache stored in: SLK18LSF/tfw.bundle[2].css - HTTP/1.1 200 OK - Content-Length: 36010 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a0.twimg.com/a/1309465578/phoenix/img/buttons/bg-btn-blue.gif cache stored in: QJM5KT6J/bg-btn-blue[1].gif - HTTP/1.1 200 OK - x-amz-id-2: cFcJCeTr+RZQ7fFIOQlFbPxpFXDyHRQmVCwsBUCK4bMCOVj3+hAxy2wRy/618hgE - x-amz-request-id: 04A5EC50F27E4501 - ETag: "b20350e85964259db52e1630b7227238" - Content-Length: 635 - X-Amz-Cf-Id: 480b7f16b0085402ff797e93b530457268b24443b6795884dead33451f1be61a34d6dccd5cfbae7d-3213c05ae8fec2307c831689ea7b4e5d6672b16fc4d49f9b5c28d5f18a757089d4615983d1546650 - X-CDN: AKAM - X-CDN: AKAM - Content-Type: image/gif - X-CDN: AKAM (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a0.twimg.com/a/1309465578/phoenix/img/buttons/bg-btn-signup.png cache stored in: YZCXGNW1/bg-btn-signup[1].png - HTTP/1.1 200 OK - x-amz-id-2: 4WiJezbKCzkQFNouxDbxS6JE1cuXx0VsmNXrNqUpwLrmt9c7O37dlSWzEWaFe1g5 - x-amz-request-id: 5E051C991A2F8948 - ETag: "1577efa3fc347bbef3a7397f34689835" - Content-Length: 346 - X-Amz-Cf-Id: 775d043d0de8277c53eb9c6e85430953b0065ee777dd9894adc0b6a7cd769f9dcef458395d286faf-1399073eb7c7402ea52711c677dad81b5dcab8203b7d1a57b4620351217a8e62d149fe5e8231a416 - X-CDN: AKAM - Content-Type: image/png - X-CDN: AKAM (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a0.twimg.com/a/1309465578/phoenix/img/buttons/bg-btn.gif cache stored in: UPQVMROL/bg-btn[1].gif - HTTP/1.1 200 OK - x-amz-id-2: E0HVOxO2uJoC+Qvbp1BAJT7iC8+Bx2JSng0dvTCTi0sApxo2ItkY7Yq6nlTGTbzo - x-amz-request-id: E582CA8B4A184F6C - ETag: "ba5a2b3972d4507e8dd43512b425c8d8" - Content-Length: 594 - X-Amz-Cf-Id: 022537c7fd07a38865ea46d1707d18e10382a465c4711d2fdb0b264c1211f2c292a9478faa1934ce - X-CDN: AKAM - Content-Type: image/gif - X-CDN: AKAM (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a0.twimg.com/a/1309465578/phoenix/img/twitter_logo_right.png cache stored in: YZCXGNW1/twitter_logo_right[1].png - HTTP/1.1 200 OK - x-amz-id-2: BkjIbE5kWvBtuaY0P3w7EmFcesJLBmnh9v17ONmfQbW8ODgFwkFjzl8n4OH6ht64 - x-amz-request-id: 5D1BA3CC33D94464 - ETag: "35953926709f9a7f603e5c0ce74edff8" - Content-Length: 1046 - X-Amz-Cf-Id: 3d01b0474cb35086f81aea32473a0f4077bd7dd6d61bad56ef1d734128622877b9c5b6607d8417fa-0ed4ac94b7a1de641fc532040de94f0db39146ba930ba0cd7cb8fe4045b5e6d9c876c8355485ea4b - X-CDN: AKAM - X-CDN: AKAM - Content-Type: image/png - X-CDN: AKAM (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a1.twimg.com/a/1309465578/javascripts/loadrunner.js cache stored in: QJM5KT6J/loadrunner[2].js - HTTP/1.1 200 OK - Content-Length: 5305 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a1.twimg.com/a/1309465578/javascripts/modules/imports/jquery.js cache stored in: YZCXGNW1/jquery[2].js - HTTP/1.1 200 OK - Content-Length: 78054 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a1.twimg.com/a/1309465578/javascripts/modules/tfw/intents/main.js cache stored in: UPQVMROL/main[2].js - HTTP/1.1 200 OK - Content-Length: 14083 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:twitter.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 36010 macb r/rrwxrwxrwx 0 0 11779-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/tfw.bundle[2].css 635 macb r/rrwxrwxrwx 0 0 11798-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/bg-btn-blue[1].gif 346 macb r/rrwxrwxrwx 0 0 11841-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/bg-btn-signup[1].png 594 macb r/rrwxrwxrwx 0 0 11847-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/bg-btn[1].gif 1046 macb r/rrwxrwxrwx 0 0 11855-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/twitter_logo_right[1].png 5305 macb r/rrwxrwxrwx 0 0 11867-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/loadrunner[2].js 898 mac. r/rrwxrwxrwx 0 0 11868-128-4 /Documents and Settings/malware/Cookies/malware@twitter[1].txt 14083 macb r/rrwxrwxrwx 0 0 11869-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/main[2].js 78054 macb r/rrwxrwxrwx 0 0 11877-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/jquery[2].js Fri Jul 01 2011 15:11:30 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://tfw-current.s3.amazonaws.com/xd/ft.swf?callback=__xdcbnull&token=null&debug=undefined cache stored in: SLK18LSF/ft[1].swf - HTTP/1.1 200 OK - x-amz-id-2: L4vYJ+8S8zTPsLtdfX1ElmvHFH2l1W8eaqP/u49JHgKg9UmMCpXhb7TBgj/kRKwx - x-amz-request-id: B9124E73ADCD95B4 - ETag: "df5e189129f871dc426b23b677279e7c" - Content-Type: application/x-shockwave-flash - Content-Length: 1277 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 98 macb r/rrwxrwxrwx 0 0 11866-128-1 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/MetaData/4DB1DABDF57ED9997FE8DCC77E93C04F 6523 macb r/rrwxrwxrwx 0 0 11903-128-4 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/Content/4DB1DABDF57ED9997FE8DCC77E93C04F 146 macb r/rrwxrwxrwx 0 0 11907-128-1 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/MetaData/2659C1A560AB92C9C29D4B2B25815AE8 545 macb r/rrwxrwxrwx 0 0 11912-128-1 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/Content/2659C1A560AB92C9C29D4B2B25815AE8 106 macb r/rrwxrwxrwx 0 0 11943-128-1 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/MetaData/DEEA0BD81CC3B68E08E92D12B0916963 24894 macb r/rrwxrwxrwx 0 0 11958-128-4 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/Content/DEEA0BD81CC3B68E08E92D12B0916963 1277 macb r/rrwxrwxrwx 0 0 11989-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/ft[1].swf Fri Jul 01 2011 15:11:56 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/combined/channels.css?r=38841 cache stored in: QJM5KT6J/channels[1].css - HTTP/1.1 200 OK - Content-Length: 18839 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/combined/index.css?r=38841 cache stored in: QJM5KT6J/index[1].css - HTTP/1.1 200 OK - Content-Length: 26185 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/ie6-fixes.css?r=38841 cache stored in: SLK18LSF/ie6-fixes[2].css - HTTP/1.1 200 OK - Content-Length: 1604 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/images/dropdown-arrows.png?r=38841 cache stored in: QJM5KT6J/dropdown-arrows[2].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 950 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/js/combined/index.js?r=38841 cache stored in: UPQVMROL/index[2].js - HTTP/1.1 200 OK - Content-Length: 157999 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://www.mevio.com/channels (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) Fri Jul 01 2011 15:11:57 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://api.connect.facebook.com/static/v0.4/client_restserver.php?r=1309194222 cache stored in: YZCXGNW1/client_restserver[1].htm - HTTP/1.1 200 OK - Content-Length: 665 - Content-Type: text/html_ charset=utf-8 - X-FB-Server: 10.32.21.113 - X-Cnection: close (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/1c3/718/1c3718ab1198cf7d902953af721665810e4a36c4.jpg?url=http://origin.thumbs.mevio.com/media/27056/episodes/270143/thumbnail.jpg&width=200&height=112&scheme=1 cache stored in: UPQVMROL/1c3718ab1198cf7d902953af721665810e4a36c4[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 6030 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/253/5f5/2535f5bb2c11acfcc712f982ff726ec6a6676dee.jpg?url=http://origin.psstatic.podshow.com/images/shows/27017/episodes/270412/large/shellypalmerdaily-us-e.jpg?r=1298584025&width=200&height=112&scheme=1 cache stored in: YZCXGNW1/2535f5bb2c11acfcc712f982ff726ec6a6676dee[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 7739 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/390/d8d/390d8d4e7d61f34bceeac78e44564723131e8754.png?url=http://origin.psstatic.podshow.com/images/shows/19008/episodes/268653/large/okinsider-us-e.png?r=1297880714&width=200&height=112&scheme=1 cache stored in: YZCXGNW1/390d8d4e7d61f34bceeac78e44564723131e8754[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 30915 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/500/21e/50021ee7fded0de4baf2235b2b688d3ec4d239cc.jpg?url=http://origin.psstatic.podshow.com/images/shows/21849/episodes/286858/large/presspause-us-e.jpg?r=1309545471&width=200&height=112&scheme=1 cache stored in: SLK18LSF/50021ee7fded0de4baf2235b2b688d3ec4d239cc[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 14652 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/5e1/dc9/5e1dc9c9cf66bed0178c7e0e506dc8cb5c26ed0e.jpg?url=http://origin.thumbs.mevio.com/media/23312/episodes/278477/thumbnail.jpg&width=200&height=112&scheme=1 cache stored in: QJM5KT6J/5e1dc9c9cf66bed0178c7e0e506dc8cb5c26ed0e[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 6006 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/6fb/01f/6fb01f5c5db444ce2234e613417516a173440878.jpg?url=http://origin.psstatic.podshow.com/images/shows/27124/episodes/269813/large/celebritycrush-us-e.jpg?r=1298076467&width=200&height=112&scheme=1 cache stored in: SLK18LSF/6fb01f5c5db444ce2234e613417516a173440878[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 9573 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/86b/d89/86bd8960d4cea3b0f5a738477a3b83c599e8fd0b.jpg?url=http://origin.psstatic.podshow.com/images/shows/23473/episodes/268754/large/dailyappshow-us-e.jpg?r=1298527072&width=200&height=112&scheme=1 cache stored in: SLK18LSF/86bd8960d4cea3b0f5a738477a3b83c599e8fd0b[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 5512 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/8c8/4d1/8c84d1b79cb887b3ded16f0ea9ee43c56aa8c710.jpg?url=http://origin.psstatic.podshow.com/images/shows/26969/episodes/270054/large/vatortv-us-e.jpg?r=1298583368&width=200&height=112&scheme=1 cache stored in: UPQVMROL/8c84d1b79cb887b3ded16f0ea9ee43c56aa8c710[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 5034 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://img.mevio.com/images/a0b/81d/a0b81d701aa656e10eaec01d3b61148516307691.jpg?url=http://origin.thumbs.mevio.com/media/23473/episodes/286274/thumbnail.jpg&width=200&height=112&scheme=1 cache stored in: SLK18LSF/a0b81d701aa656e10eaec01d3b61148516307691[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 3452 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/joinNow25high.gif cache stored in: SLK18LSF/joinNow25high[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Cache: HIT - Content-Length: 794 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/481030/channels/small/631999.jpg?r=38841 cache stored in: YZCXGNW1/631999[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 5843 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://psstatic.podshow.com/images/users/481030/gallery/thumbs/194178.jpg?r=38841 cache stored in: YZCXGNW1/194178[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 2393 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://static.ak.connect.facebook.com/connect.php cache stored in: SLK18LSF/connect[2].php - HTTP/1.1 200 OK - Content-Length: 18453 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://static.ak.connect.facebook.com/connect.php/en_US cache stored in: UPQVMROL/en_US[1] - HTTP/1.1 200 OK - Content-Length: 18453 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://static.ak.connect.facebook.com/connect.php/en_US/css/bookmark-button-css/connect-button-css/share-button-css/FB.Connect-css/connect-css cache stored in: QJM5KT6J/connect-css[1].css - HTTP/1.1 200 OK - Content-Length: 14288 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://static.ak.connect.facebook.com/connect.php/en_US/js/Api/CanvasUtil/Connect/XFBML cache stored in: SLK18LSF/XFBML[2] - HTTP/1.1 200 OK - Content-Length: 211318 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://static.ak.connect.facebook.com/js/api_lib/v0.4/FeatureLoader.js.php cache stored in: QJM5KT6J/FeatureLoader.js[2].php - HTTP/1.1 200 OK - Content-Length: 18453 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://static.podshow.com/MEVIO_Assets/PromoRollV4.jpg cache stored in: YZCXGNW1/PromoRollV4[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 58767 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/channels/static/css/images/ctrl-vert-scroll.png?r=38841 cache stored in: QJM5KT6J/ctrl-vert-scroll[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 1023 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/player/static/css/images/actionBar.png?r=38841 cache stored in: SLK18LSF/actionBar[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 2132 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/player/static/css/images/mevio-m-neverback-24x24.gif?r=38841 cache stored in: UPQVMROL/mevio-m-neverback-24x24[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Cache: HIT - Content-Length: 3320 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/images/logo-and-footer.jpg?r=38841 cache stored in: QJM5KT6J/logo-and-footer[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 11097 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/images/now-playing-bg.jpg?r=38841 cache stored in: UPQVMROL/now-playing-bg[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 610 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/images/small-icons.png?r=38841 cache stored in: SLK18LSF/small-icons[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 2132 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/js/tpl_channels.js?r=38841 cache stored in: YZCXGNW1/tpl_channels[2].js - HTTP/1.1 200 OK - Content-Length: 7834 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/js/tpl_htdocs.js?r=38841 cache stored in: UPQVMROL/tpl_htdocs[1].js - HTTP/1.1 200 OK - Content-Length: 78342 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/js/tpl_player.js?r=38841 cache stored in: YZCXGNW1/tpl_player[2].js - HTTP/1.1 200 OK - Content-Length: 20356 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/widgets/mwm/MevioBPFX.swf?r=38841 cache stored in: SLK18LSF/MevioBPFX[1].swf - HTTP/1.1 200 OK - Content-Type: application/x-shockwave-flash - X-Cache: HIT - Content-Length: 295610 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.facebook.com/extern/login_status.php?api_key=c99345b4de38e993c64ef4654ac9164b&extern=2&channel=http://www.mevio.com/rest/facebook/xd_receiver.php&locale=en_US cache stored in: YZCXGNW1/login_status[1].htm - HTTP/1.1 200 OK - Content-Length: 1107 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 14652 macb r/rrwxrwxrwx 0 0 10624-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/50021ee7fded0de4baf2235b2b688d3ec4d239cc[1].jpg 5843 macb r/rrwxrwxrwx 0 0 11201-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/631999[1].jpg 1107 mac. r/rrwxrwxrwx 0 0 11324-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/login_status[1].htm 18453 macb r/rrwxrwxrwx 0 0 11916-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/FeatureLoader.js[2].php 2393 macb r/rrwxrwxrwx 0 0 11938-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/194178[1].jpg 30915 macb r/rrwxrwxrwx 0 0 11940-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/390d8d4e7d61f34bceeac78e44564723131e8754[1].png 3452 macb r/rrwxrwxrwx 0 0 11942-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/a0b81d701aa656e10eaec01d3b61148516307691[1].jpg 7739 macb r/rrwxrwxrwx 0 0 11954-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/2535f5bb2c11acfcc712f982ff726ec6a6676dee[1].jpg 5512 macb r/rrwxrwxrwx 0 0 11971-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/86bd8960d4cea3b0f5a738477a3b83c599e8fd0b[1].jpg 6006 macb r/rrwxrwxrwx 0 0 11975-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/5e1dc9c9cf66bed0178c7e0e506dc8cb5c26ed0e[1].jpg 9573 macb r/rrwxrwxrwx 0 0 11977-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/6fb01f5c5db444ce2234e613417516a173440878[1].jpg 6030 macb r/rrwxrwxrwx 0 0 12009-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/1c3718ab1198cf7d902953af721665810e4a36c4[1].jpg 5034 macb r/rrwxrwxrwx 0 0 12010-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/8c84d1b79cb887b3ded16f0ea9ee43c56aa8c710[1].jpg Fri Jul 01 2011 15:11:58 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://static.ak.connect.facebook.com/js/api_lib/v0.4/XdCommReceiver.js cache stored in: QJM5KT6J/XdCommReceiver[2].js - HTTP/1.1 200 OK - Content-Length: 3386 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.mevio.com/rest/facebook/xd_receiver.php cache stored in: QJM5KT6J/xd_receiver[1].htm - HTTP/1.1 200 OK - Content-Length: 591 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 591 mac. r/rrwxrwxrwx 0 0 11390-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/xd_receiver[1].htm Fri Jul 01 2011 15:12:03 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.triggit.com/pxrucm cache stored in: UPQVMROL/pxrucm[1].htm - HTTP/1.1 200 OK - Content-Length: 0 - Content-Type: text/html_ charset=ISO-8859-1 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pixel.rubiconproject.com/tap.php?v=4222&nid=1512&put=4e0e4205-113a-18ce-3bd3-cb95dc5f0a68 cache stored in: SLK18LSF/tap[3].gif - HTTP/1.1 200 OK - X-Powered-By: PHP/5.1.6 - P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" - Content-Length: 49 - Keep-Alive: timeout=45 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pixel.rubiconproject.com/tap.php?v=6286&nid=2132&put=3FFC002F477E3179BBFCF6FDE779AF63&expires=365 cache stored in: UPQVMROL/tap[3].gif - HTTP/1.1 200 OK - X-Powered-By: PHP/5.1.6 - P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" - Content-Length: 49 - Keep-Alive: timeout=45 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:mathtag.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 286 mac. r/rrwxrwxrwx 0 0 11679-128-1 /Documents and Settings/malware/Cookies/malware@mathtag[2].txt 49 macb r/rrwxrwxrwx 0 0 12002-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/tap[3].gif 2034 macb r/rrwxrwxrwx 0 0 12027-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26317-2[2].js 2197 macb r/rrwxrwxrwx 0 0 12029-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/26318-2[1].js Fri Jul 01 2011 15:12:59 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/player/static/css/images/player-icons.png?r=38841 cache stored in: YZCXGNW1/player-icons[2].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 3681 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/css/images/play-trans.png?r=38841 cache stored in: QJM5KT6J/play-trans[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Cache: HIT - Content-Length: 435 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ui.mevio.com/static/us/images/defaults/shows/small/default.jpg?r=38841 cache stored in: YZCXGNW1/default[2].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Cache: HIT - Content-Length: 23216 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.mevio.com/player/?format=json&action=play&eId=269813 cache stored in: SLK18LSF/player[1] - HTTP/1.1 200 OK - Content-Length: 5924 - Content-Type: application/json (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:mevio.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 658 macb r/rrwxrwxrwx 0 0 11623-128-4 /Documents and Settings/malware/Cookies/malware@mevio[1].txt 5924 macb r/rrwxrwxrwx 0 0 12019-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/player[1] Fri Jul 01 2011 15:13:00 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a.tribalfusion.com/displayAd.js?dver=0.3&th=11243549426 cache stored in: UPQVMROL/displayAd[2].js - HTTP/1.1 200 OK - Content-Length: 60 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://b.scorecardresearch.com/beacon.js cache stored in: YZCXGNW1/beacon[2].js - HTTP/1.1 200 OK - Content-Length: 3447 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://media2.adshuffle.com/asSwfObj13.js cache stored in: YZCXGNW1/asSwfObj13[2].js - HTTP/1.1 200 OK - Content-Length: 1748 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://media2.adshuffle.com/images/797734/2ff94d3000b6425bbb11d3a4c26305e3.jpg cache stored in: SLK18LSF/2ff94d3000b6425bbb11d3a4c26305e3[1].jpg - HTTP/1.1 200 OK - X-Px: ht lax-am6-n25.panthercdn.com - ETag: "49bce2fd3310cc1:2a65" - P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTR STP IND DEM" - Content-Length: 37210 - Content-Type: image/jpeg (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pcm3.map.pulsemgr.com/uds/pc?ptnr=21280&sig=6f737abf3f6bb5f84a1ad1dc0be05ab8 cache stored in: SLK18LSF/pc[1] - HTTP/1.1 200 OK - Content-Length: 43 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pixel.fimserve.com/fan.php cache stored in: YZCXGNW1/fan[1].gif - HTTP/1.1 200 OK - X-Powered-By: PHP/5.1.6 - P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" - Content-Length: 49 - Keep-Alive: timeout=45 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pixel.invitemedia.com/rubicon_sync?publisher_user_id=9992958d20baa129364ad075cb0e709082fefde0&publisher_dsp_id=2101&publisher_call_type=iframe&publisher_redirecturl=http://tap.rubiconproject.com/oz/feeds/invite-media-rtb/tokens/ cache stored in: UPQVMROL/rubicon_sync[1].htm - HTTP/1.0 200 OK - P3P: policyref="/w3c/p3p.xml"- CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC" - Content-Type: text/html - Pragma: no-cache - Content-Length: 221 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://tags.expo9.exponential.com/tags/PodShow/ROS/tags.js cache stored in: QJM5KT6J/tags[2].js - HTTP/1.1 200 OK - Content-Length: 12576 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://tap2-cdn.rubiconproject.com/partner/scripts/rubicon/emily.html?pc=8142/13187 cache stored in: UPQVMROL/emily[1].htm - HTTP/1.1 200 OK - Content-Length: 6621 - Content-Type: text/html (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://uac.advertising.com/wrapper/aceUAC.js cache stored in: YZCXGNW1/aceUAC[1].js - HTTP/1.1 200 OK - Content-Length: 15168 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:media6degrees.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:scorecardresearch.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:tap.rubiconproject.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:tribalfusion.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 260 macb r/rrwxrwxrwx 0 0 11690-128-1 /Documents and Settings/malware/Cookies/malware@media6degrees[2].txt 221 mac. r/rrwxrwxrwx 0 0 11694-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/rubicon_sync[1].htm 5620 macb r/rrwxrwxrwx 0 0 11797-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/view[2].htm 608 macb r/rrwxrwxrwx 0 0 11933-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/dref=http%3A%2F%2Fwww.mevio[1].com%2Fchannels%2F 1151 ...b r/rrwxrwxrwx 0 0 12023-128-4 /Documents and Settings/malware/Cookies/malware@advertising[1].txt 2197 macb r/rrwxrwxrwx 0 0 12025-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/26318-2[2].js 198 macb r/rrwxrwxrwx 0 0 12032-128-1 /Documents and Settings/malware/Cookies/malware@tribalfusion[1].txt 2034 macb r/rrwxrwxrwx 0 0 12034-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/26317-2[1].js 105 macb r/rrwxrwxrwx 0 0 12035-128-1 /Documents and Settings/malware/Cookies/malware@scorecardresearch[2].txt 49 macb r/rrwxrwxrwx 0 0 12036-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/fan[1].gif 83 mac. r/rrwxrwxrwx 0 0 12038-128-1 /Documents and Settings/malware/Cookies/malware@tap.rubiconproject[2].txt Fri Jul 01 2011 15:13:01 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://pixel.rubiconproject.com/tap.php?v=5852&nid=2101&put=dc7062af-f72b-463f-aa84-0c45e217bcba cache stored in: QJM5KT6J/tap[1].gif - HTTP/1.1 200 OK - X-Powered-By: PHP/5.1.6 - P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT" - Content-Length: 49 - Keep-Alive: timeout=45- max=496 - Content-Type: image/gif (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:pixel.rubiconproject.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:rubiconproject.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 49 macb r/rrwxrwxrwx 0 0 11676-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/tap[1].gif 277 macb r/rrwxrwxrwx 0 0 11857-128-1 /Documents and Settings/malware/Cookies/malware@pixel.rubiconproject[2].txt 1995 mac. r/rrwxrwxrwx 0 0 11892-128-4 /Documents and Settings/malware/Cookies/malware@rubiconproject[2].txt Fri Jul 01 2011 15:13:09 7485 macb r/rrwxrwxrwx 0 0 12040-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/buttons_new[2].css 163223 macb r/rrwxrwxrwx 0 0 12042-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/twitter[2].css 9333 macb r/rrwxrwxrwx 0 0 12044-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/geo[2].css Fri Jul 01 2011 15:13:10 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://www.google.com/recaptcha/api/image?c=03AHJ_Vutf-m-ZA-PTjLXvaEWr0tq_l0yHYnz-0VEECL1WOOJzFp_gds2WUFf3tJDnr_hY7MTSxOpPQIKinvM5Tjy_f4BLcpol28PDlCqNPqFQ3o448q6NbjDZWGluwULnIySOAOVQOTlCokOlJer_L6shwmcEfTGBGA cache stored in: QJM5KT6J/image[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Content-Type-Options: nosniff - X-XSS-Protection: 1_ mode=block - Content-Length: 3004 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 56 mac. d/drwxrwxrwx 0 0 11628-144-5 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/MetaData 56 mac. d/drwxrwxrwx 0 0 11629-144-5 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/Content 7637 macb r/rrwxrwxrwx 0 0 12033-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/bg-clouds[1].png 68 macb r/rrwxrwxrwx 0 0 12039-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/arr2[1].gif 759 macb r/rrwxrwxrwx 0 0 12041-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/loader[1].gif 4956 macb r/rrwxrwxrwx 0 0 12043-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/bird_key[1].png 2543 macb r/rrwxrwxrwx 0 0 12045-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/twitter_logo_header[1].png 2543 macb r/rrwxrwxrwx 0 0 12046-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/twitter_logo_header[2].png 94 macb r/rrwxrwxrwx 0 0 12047-128-1 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/MetaData/60E31627FDA0A46932B0E5948949F2A5 898 macb r/rrwxrwxrwx 0 0 12048-128-4 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/Content/60E31627FDA0A46932B0E5948949F2A5 104 macb r/rrwxrwxrwx 0 0 12049-128-1 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/MetaData/5F74056C561F814B7771CB2993A44DEB 26808 macb r/rrwxrwxrwx 0 0 12050-128-4 /Documents and Settings/malware/Application Data/Microsoft/CryptnetUrlCache/Content/5F74056C561F814B7771CB2993A44DEB 155 macb r/rrwxrwxrwx 0 0 12052-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/text[1].gif 26125 macb r/rrwxrwxrwx 0 0 12053-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/recaptcha[2].js 3176 macb r/rrwxrwxrwx 0 0 12054-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/sprite[1].png 369 macb r/rrwxrwxrwx 0 0 12055-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/refresh[1].gif 134 macb r/rrwxrwxrwx 0 0 12056-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/audio[1].gif 375 macb r/rrwxrwxrwx 0 0 12057-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/help[1].gif 55026 macb r/rrwxrwxrwx 0 0 12059-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/jquery.min[2].js 3004 macb r/rrwxrwxrwx 0 0 12060-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/image[1].jpg 189167 ...b r/rrwxrwxrwx 0 0 12061-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/twitter[2].js Fri Jul 01 2011 15:13:11 56 mac. d/drwxrwxrwx 0 0 10457-144-6 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1 189167 mac. r/rrwxrwxrwx 0 0 12061-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/twitter[2].js 2332 macb r/rrwxrwxrwx 0 0 12062-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/jquery.tipsy.min[2].js 22495 macb r/rrwxrwxrwx 0 0 12063-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/jsapi[2] 3392 macb r/rrwxrwxrwx 0 0 12064-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/gears_init[2].js 11841 macb r/rrwxrwxrwx 0 0 12065-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/mustache[2].js 52386 macb r/rrwxrwxrwx 0 0 12066-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/geov1[2].js 3853 macb r/rrwxrwxrwx 0 0 12067-128-5 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/api[2].js Fri Jul 01 2011 15:14:11 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Internet Explorer/International 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Internet Explorer/International/CpMRU 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://arcadeweb.com/aj/i.php?lpID=3709&urlID=313&subID=AW000102 cache stored in: UPQVMROL/i[1].htm - HTTP/1.1 200 OK - Pragma: no-cache - Content-Length: 5177 - Content-Type: text/html_ charset=US-ASCII (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://r1-ads.ace.advertising.com/click/site=0000788695/mnum=0001036308/cstr=57579680=_4e0e464a-4012235138-788695^1036308^83^0-1_/xsxdata=$XSXDATA/bnum=57579680/optn=64?trg=http://this.content.served.by.adshuffle.com/p/kl/46/799/r/12/4/8/ru/d3d3Lm1ldmlvLmNvbQ==/293955817/v/576462396488562496/ac/797734/b/276763/c/476776/click.html (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:by.adshuffle.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:this.content.served.by.adshuffle.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 313 mac. r/rrwxrwxrwx 0 0 11618-128-1 /Documents and Settings/malware/Cookies/malware@by.adshuffle[2].txt 148 macb r/rrwxrwxrwx 0 0 12011-128-1 /Documents and Settings/malware/Cookies/malware@this.content.served.by.adshuffle[2].txt 5177 macb r/rrwxrwxrwx 0 0 12068-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/i[1].htm Fri Jul 01 2011 15:14:12 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{D27CDB6E-AE6D-11CF-96B8-444553540000}/iexplore 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://aa.static.facdn.com/lp/037/09/images/AW_Logo_LP.png cache stored in: YZCXGNW1/AW_Logo_LP[1].png - HTTP/1.1 200 OK - Content-Type: image/png - ETag: "3642106224" - Content-Length: 9453 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://aa.static.facdn.com/lp/037/09/images/jewelcraft-bgrepeat.jpg cache stored in: SLK18LSF/jewelcraft-bgrepeat[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - ETag: "3780911822" - Content-Length: 61259 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab cache stored in: YZCXGNW1/swflash[1].cab - HTTP/1.1 200 - ETag: "9c8565-2ecfda-54273b40" - Content-Type: text/plain - Content-Length: 3067866 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://leadback.advertising.com/adcedge/lb?site=695501&srvc=1&betr=arcadewebvisit_cs=1&betq=13703=438910 cache stored in: SLK18LSF/lb[1].gif - HTTP/1.1 200 OK - X-Powered-By: ASP.NET - X-AspNet-Version: 2.0.50727 - P3P: CP=NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV - Content-Type: image/gif - Content-Length: 49 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://web1.awcdn.com/content/images/AW_FooterUni.png cache stored in: YZCXGNW1/AW_FooterUni[1].png - HTTP/1.1 200 OK - Content-Type: image/png - ETag: "2554877748" - Content-Length: 4502 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 507904 m.c. r/rr-xr-xr-x 0 0 10525-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:advertising.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 4502 macb r/rrwxrwxrwx 0 0 11923-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/AW_FooterUni[1].png 9453 macb r/rrwxrwxrwx 0 0 12007-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/AW_Logo_LP[1].png 5 macb r/rrwxrwxrwx 0 0 12014-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/YZCXGNW1/apiApp[1].htm 61259 macb r/rrwxrwxrwx 0 0 12015-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/jewelcraft-bgrepeat[1].jpg 1151 mac. r/rrwxrwxrwx 0 0 12023-128-4 /Documents and Settings/malware/Cookies/malware@advertising[1].txt 49 macb r/rrwxrwxrwx 0 0 12037-128-1 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/lb[1].gif Fri Jul 01 2011 15:14:13 56 mac. d/drwxrwxrwx 0 0 10472-144-6 /Documents and Settings/malware/Cookies 0 macb 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:?CodeDownloadErrorLog!name={D27CDB6E-AE6D-11CF-96B8-444553540000} cache stored in: QJM5KT6J/CAN87RV1.HTM (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.google-analytics.com/ga.js cache stored in: YZCXGNW1/ga[2].js - HTTP/1.1 200 OK - Content-Length: 27240 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:microsoft.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 1176 macb r/rrwxrwxrwx 0 0 12058-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/CAN87RV1.HTM Fri Jul 01 2011 15:14:17 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://www.google.com/recaptcha/api/image?c=03AHJ_Vuveye6Qv-ZSyIuZ7l3Q9iKxPXq8uBUYQ2qREdSNc0NNio7KvPvt0iFyncenDoA1DpzizpWfJFGWTixiGxBtNBWpFROCG-d4Y2M-vQOR2Ncg6jD14H7goIhCP7WJsxLOYiZ0lkfY6M_Rp-bS5pLfAkvkzuoeWA cache stored in: UPQVMROL/image[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Content-Type-Options: nosniff - X-XSS-Protection: 1_ mode=block - Content-Length: 2656 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 539 ...b r/rrwxrwxrwx 0 0 11969-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/challenge[1] 2656 macb r/rrwxrwxrwx 0 0 12051-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/image[1].jpg Fri Jul 01 2011 15:15:19 56 mac. d/drwxrwxrwx 0 0 10458-144-6 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL 56 mac. d/drwxrwxrwx 0 0 10459-144-6 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a0.twimg.com/a/1309465578/javascripts/lib/gears_init.js?1309198824 cache stored in: UPQVMROL/gears_init[2].js - HTTP/1.1 200 OK - Content-Length: 3392 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a0.twimg.com/a/1309465578/javascripts/lib/jquery.tipsy.min.js?1309198824 cache stored in: YZCXGNW1/jquery.tipsy.min[2].js - HTTP/1.1 200 OK - Content-Length: 2332 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a0.twimg.com/a/1309465578/stylesheets/buttons_new.css?1309198825 cache stored in: UPQVMROL/buttons_new[2].css - HTTP/1.1 200 OK - Content-Length: 7485 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a1.twimg.com/a/1309465578/javascripts/api.js?1309198824 cache stored in: QJM5KT6J/api[2].js - HTTP/1.1 200 OK - Content-Length: 3853 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a1.twimg.com/a/1309465578/javascripts/geov1.js?1309198824 cache stored in: SLK18LSF/geov1[2].js - HTTP/1.1 200 OK - Content-Length: 52386 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a1.twimg.com/a/1309465578/javascripts/lib/mustache.js?1309198824 cache stored in: YZCXGNW1/mustache[2].js - HTTP/1.1 200 OK - Content-Length: 11841 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a2.twimg.com/a/1309465578/images/twitter_logo_header.png cache stored in: QJM5KT6J/twitter_logo_header[1].png - HTTP/1.1 200 OK - Content-Type: image/png - ETag: "551ecfdb7af638964c514e8c6f105164" - x-amz-id-2: 71A6I9HnXFkJGnfnH9e2QtFZyA8tAxu24jvOAx6N/OyiWLyaySEvGZy4P3/rOSge - x-amz-request-id: 2EE3B72F2523C4C9 - Content-Length: 2543 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a2.twimg.com/a/1309465578/javascripts/twitter.js?1309198824 cache stored in: UPQVMROL/twitter[2].js - HTTP/1.1 200 OK - Content-Length: 189167 - Content-Type: application/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a3.twimg.com/a/1309465578/images/arr2.gif cache stored in: UPQVMROL/arr2[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - ETag: "c12a96cac00911d308e0b44f5ec62a60" - x-amz-id-2: onfd58T1oCl70O98DZmbHyW2GBmPM4Exp/aTR0GEfQSJWsDBnaraVv5Fzr9ZE4O+ - x-amz-request-id: A5852815F65F679A - Content-Length: 68 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a3.twimg.com/a/1309465578/images/bg-clouds.png cache stored in: SLK18LSF/bg-clouds[1].png - HTTP/1.1 200 OK - Content-Type: image/png - ETag: "8388f9f5ebca3dd2c58b44f190687497" - x-amz-id-2: y2GY/AArfprlS2TYskBbpW+KcTL3spVB1DAuNnJRqAYTDH3ZKQ6w/hmX+kcCOJUl - x-amz-request-id: B14E8319A1A0655A - Content-Length: 7637 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a3.twimg.com/a/1309465578/images/loader.gif cache stored in: SLK18LSF/loader[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - ETag: "8a053d64758c68c6412c01aa0717634b" - x-amz-id-2: UGpGwZJ4ig+hfduS9ZJM3nniYBlbVqZebnl7+YOGfjvXgeJZJJVfEeo4qGcL8k5a - x-amz-request-id: 2F2FDE1550595D13 - Content-Length: 759 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a3.twimg.com/a/1309465578/stylesheets/geo.css?1309198825 cache stored in: YZCXGNW1/geo[2].css - HTTP/1.1 200 OK - Content-Length: 9333 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://a3.twimg.com/a/1309465578/stylesheets/twitter.css?1309198825 cache stored in: YZCXGNW1/twitter[2].css - HTTP/1.1 200 OK - Content-Length: 163223 - Content-Type: text/css (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://ajax.googleapis.com/ajax/libs/jquery/1.3.0/jquery.min.js cache stored in: QJM5KT6J/jquery.min[2].js - HTTP/1.1 200 OK - Content-Length: 55026 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://twitter.com/images/reset_pw/bird_key.png cache stored in: QJM5KT6J/bird_key[1].png - HTTP/1.1 200 OK - Content-Length: 4956 - X-XSS-Protection: 1_ mode=block - Keep-Alive: timeout=15- max=99 - Content-Type: image/png (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://twitter.com/images/twitter_logo_header.png cache stored in: QJM5KT6J/twitter_logo_header[2].png - HTTP/1.1 200 OK - Content-Length: 2543 - X-XSS-Protection: 1_ mode=block - Content-Type: image/png (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:http://www.google.com/jsapi cache stored in: SLK18LSF/jsapi[2] - HTTP/1.1 200 OK - Content-Length: 22495 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://www.google.com/recaptcha/api//img/white/audio.gif cache stored in: YZCXGNW1/audio[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Content-Type-Options: nosniff - X-XSS-Protection: 1_ mode=block - Content-Length: 134 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://www.google.com/recaptcha/api//img/white/help.gif cache stored in: SLK18LSF/help[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Content-Type-Options: nosniff - X-XSS-Protection: 1_ mode=block - Content-Length: 375 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://www.google.com/recaptcha/api//img/white/refresh.gif cache stored in: QJM5KT6J/refresh[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Content-Type-Options: nosniff - X-XSS-Protection: 1_ mode=block - Content-Length: 369 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://www.google.com/recaptcha/api//img/white/sprite.png cache stored in: YZCXGNW1/sprite[1].png - HTTP/1.1 200 OK - Content-Type: image/png - X-Content-Type-Options: nosniff - X-XSS-Protection: 1_ mode=block - Content-Length: 3176 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://www.google.com/recaptcha/api//img/white/text.gif cache stored in: SLK18LSF/text[1].gif - HTTP/1.1 200 OK - Content-Type: image/gif - X-Content-Type-Options: nosniff - X-XSS-Protection: 1_ mode=block - Content-Length: 155 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://www.google.com/recaptcha/api/challenge?k=6LfbTAAAAAAAAE0hk8Vnfd1THHnn9lJuow6fgulO&lang=en cache stored in: UPQVMROL/challenge[1] - HTTP/1.1 200 OK - Content-Length: 539 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://www.google.com/recaptcha/api/image?c=03AHJ_VutA4CthXhnCkZ_461Kcs6S8KydrXCJVS6vpVjg7hEDu7d7w3uZUDkFLRaZVwg_vJy-_zqr3hCqBFBAyywF-6-3_dRpZwlsfV_aChoON4iLA92MYDYr1C1eCFdWk-ZKi07m8D0uOVfP_urj4xO80LIcMxHP7Kg cache stored in: SLK18LSF/image[1].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Content-Type-Options: nosniff - X-XSS-Protection: 1_ mode=block - Content-Length: 3059 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://www.google.com/recaptcha/api/js/recaptcha.js cache stored in: UPQVMROL/recaptcha[2].js - HTTP/1.1 200 OK - Content-Length: 26125 - Content-Type: application/x-javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://twitter.com/account/resend_password (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 539 mac. r/rrwxrwxrwx 0 0 11969-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/challenge[1] 3059 macb r/rrwxrwxrwx 0 0 11978-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/image[1].jpg 3597 macb r/rrwxrwxrwx 0 0 12069-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/SLK18LSF/resend_password[1] Fri Jul 01 2011 15:15:39 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://arcadeweb.com/aj/clk.php?p=OTgzMTAwOTgxNw69rw2wL2pNBaYXLAIr5vl4DA9X3o6AhcoyGaZCGxW1506Y9Px1XLrTMoi+NidEMGcM43aXi9OWuW4Yi7U6jThbA5GIzLd37Ey71N5YGEOxrJaokh6B9dvPO56pO1EGL+c7dHE+qqG6QgG1RsOONQY= (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:http://d1.arcadeweb.com/aj/download/YTE3MzA4MTc0MzAjPKA90VCTsbN7rDQOwci3fReJyFJHJUrYs3tPa7cl5JNsn0E1LJw90ZYyW4BMUiKxzh5udUBCB0Kjv9IYaGr6Iy8H9UJg6c1FaOH4Dibz0DZ2%2FWqMWv91K%2FkMUVe5tKY%3D/SetupArcadeWeb.exe (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 0 macb 0 0 0 10534 [Internet Explorer] (Last time cookie passed to website/Website modified cookie) User: Cookie:malware URL:arcadeweb.com/ (file: /media/sdb1/Documents and Settings/malware/Cookies/index.dat) 691 macb r/rrwxrwxrwx 0 0 12070-128-4 /Documents and Settings/malware/Cookies/malware@arcadeweb[2].txt Fri Jul 01 2011 15:16:31 56 mac. d/drwxrwxrwx 0 0 10460-144-6 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://www.google.com/recaptcha/api/image?c=03AHJ_Vut-NuNCvQ6OooLYQ0GwtTs1YTP5ag-qXI31tPX3Kc100cWTraLYKixEBG5vPsWwvrh6qyUSPFoE3LEEb3dlS8MohkZr73O_yiqzQgbYRhQNKqC-dELVFIFuXQQ_9v__69UUWacQ3bupett9K3rkYeIkJVTT3A cache stored in: UPQVMROL/image[2].jpg - HTTP/1.1 200 OK - Content-Type: image/jpeg - X-Content-Type-Options: nosniff - X-XSS-Protection: 1_ mode=block - Content-Length: 4403 (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 m... 0 0 0 10525 [Internet Explorer] (Content viewed/Content saved to drive) URL:https://www.google.com/recaptcha/api/reload?c=03AHJ_VutA4CthXhnCkZ_461Kcs6S8KydrXCJVS6vpVjg7hEDu7d7w3uZUDkFLRaZVwg_vJy-_zqr3hCqBFBAyywF-6-3_dRpZwlsfV_aChoON4iLA92MYDYr1C1eCFdWk-ZKi07m8D0uOVfP_urj4xO80LIcMxHP7Kg&k=6LfbTAAAAAAAAE0hk8Vnfd1THHnn9lJuow6fgulO&reason=r&type=image&lang=en cache stored in: QJM5KT6J/reload[1] - HTTP/1.1 200 OK - Content-Length: 201 - Content-Type: text/javascript (file: /media/sdb1/Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/index.dat) 0 macb 0 0 0 10527 [Internet Explorer] (Last Access) User: malware URL:javascript:Recaptcha.reload ()_ (file: /media/sdb1/Documents and Settings/malware/Local Settings/History/History.IE5/index.dat) 201 macb r/rrwxrwxrwx 0 0 11624-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/QJM5KT6J/reload[1] 4403 macb r/rrwxrwxrwx 0 0 12071-128-4 /Documents and Settings/malware/Local Settings/Temporary Internet Files/Content.IE5/UPQVMROL/image[2].jpg Fri Jul 01 2011 15:17:08 48 .a.. d/dr-xr-xr-x 0 0 10452-144-1 /Documents and Settings/malware/NetHood 8461312 ..c. r/rr-xr-xr-x 0 0 1946-128-3 /WINDOWS/system32/shell32.dll 1033728 ..c. r/rr-xr-xr-x 0 0 2093-128-3 /WINDOWS/explorer.exe 90624 ..c. r/rr-xr-xr-x 0 0 2187-128-3 /WINDOWS/system32/mydocs.dll 216064 ..c. r/rr-xr-xr-x 0 0 2704-128-3 /WINDOWS/system32/moricons.dll Fri Jul 01 2011 15:17:13 0 macb 0 0 0 10413 [XP Prefetch] (Last run) LOGONUI.EXE-0AF22957.pf - [LOGONUI.EXE] was executed - run count [9]- full path: [C:/WINDOWS/SYSTEM32/LOGONUI.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/NETAPI32.DLL - WINDOWS/SYSTEM32/OLE32.DLL - WINDOWS/SYSTEM32/OLEAUT32.DLL - WINDOWS/SYSTEM32/DUSER.DLL - WINDOWS/SYSTEM32/MSIMG32.DLL - WINDOWS/SYSTEM32/OLEACC.DLL - WINDOWS/SYSTEM32/MSVCP60.DLL - WINDOWS/SYSTEM32/SHIMENG.DLL - WINDOWS/APPPATCH/ACGENRAL.DLL - WINDOWS/SYSTEM32/WINMM.DLL - WINDOWS/SYSTEM32/MSACM32.DLL - WINDOWS/SYSTEM32/VERSION.DLL - WINDOWS/SYSTEM32/USERENV.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL - WINDOWS/SYSTEM32/OLEACCRC.DLL - WINDOWS/SYSTEM32/RPCSS.DLL - WINDOWS/SYSTEM32/CLBCATQ.DLL - WINDOWS/SYSTEM32/COMRES.DLL - WINDOWS/SYSTEM32/SHGINA.DLL - WINDOWS/SYSTEM32/WINSTA.DLL - WINDOWS/SYSTEM32/SAMLIB.DLL - WINDOWS/SYSTEM32/MSGINA.DLL - WINDOWS/SYSTEM32/ODBC32.DLL - WINDOWS/SYSTEM32/COMDLG32.DLL - WINDOWS/SYSTEM32/ODBCINT.DLL - WINDOWS/SYSTEM32/SHIMGVW.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.GDIPLUS_6595B64144CCF1DF_1.0.2600.5512_X-WW_DFB54E0C/GDIPLUS.DLL - WINDOWS/SYSTEM32/MSCMS.DLL - WINDOWS/SYSTEM32/NTMARTA.DLL - WINDOWS/SYSTEM32/WLDAP32.DLL} (file: /media/sdb1/WINDOWS/Prefetch/LOGONUI.EXE-0AF22957.pf) 73728 .a.. r/rr-xr-xr-x 0 0 2732-128-3 /WINDOWS/system32/mscms.dll 438272 .a.. r/rr-xr-xr-x 0 0 3013-128-3 /WINDOWS/system32/shimgvw.dll 56 .a.. d/drwxrwxrwx 0 0 3737-144-6 /Documents and Settings/All Users/Application Data/Microsoft 3742290 mac. r/rr-xr-xr-x 0 0 7593-128-4 /Documents and Settings/malware/Local Settings/Application Data/IconCache.db Fri Jul 01 2011 15:17:15 0 macb 0 0 0 10413 [XP Prefetch] (Last run) WSCNTFY.EXE-1B24F5EB.pf - [WSCNTFY.EXE] was executed - run count [7]- full path: [C:/WINDOWS/SYSTEM32/WSCNTFY.EXE] - DLLs loaded: {WINDOWS/SYSTEM32/NTDLL.DLL - WINDOWS/SYSTEM32/KERNEL32.DLL - WINDOWS/SYSTEM32/MSVCRT.DLL - WINDOWS/SYSTEM32/USER32.DLL - WINDOWS/SYSTEM32/GDI32.DLL - WINDOWS/SYSTEM32/SHELL32.DLL - WINDOWS/SYSTEM32/ADVAPI32.DLL - WINDOWS/SYSTEM32/RPCRT4.DLL - WINDOWS/SYSTEM32/SECUR32.DLL - WINDOWS/SYSTEM32/SHLWAPI.DLL - WINDOWS/WINSXS/X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83/COMCTL32.DLL - WINDOWS/SYSTEM32/XPSP2RES.DLL - WINDOWS/SYSTEM32/UXTHEME.DLL} (file: /media/sdb1/WINDOWS/Prefetch/WSCNTFY.EXE-1B24F5EB.pf) Fri Jul 01 2011 15:17:16 9516 mac. r/rrwxrwxrwx 0 0 10585-128-4 /WINDOWS/Prefetch/WSCNTFY.EXE-1B24F5EB.pf Fri Jul 01 2011 15:17:23 23826 mac. r/rrwxrwxrwx 0 0 10557-128-4 /WINDOWS/Prefetch/LOGONUI.EXE-0AF22957.pf Fri Jul 01 2011 15:17:29 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer Fri Jul 01 2011 15:17:30 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/Explorer/TrayNotify 0 m... 0 0 0 0 REG_User_malware/Software/Microsoft/Windows/CurrentVersion/WindowsUpdate 786432 ma.. r/rr-xr-xr-x 0 0 10441-128-4 /Documents and Settings/malware/NTUSER.DAT 1024 mac. r/rr-xr-xr-x 0 0 10538-128-4 /Documents and Settings/malware/ntuser.dat.LOG 262144 .a.. r/rr-xr-xr-x 0 0 10540-128-3 /Documents and Settings/malware/Local Settings/Application Data/Microsoft/Windows/UsrClass.dat 178 mac. r/rr-xr-xr-x 0 0 10542-128-1 /Documents and Settings/malware/ntuser.ini 178 ..c. r/rr-xr-xr-x 0 0 12072-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/A0000136.ini 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) Application Popup/45_Info_ (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) Fri Jul 01 2011 15:17:31 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Session Manager/AppCompatibility 2950 mac. r/rr-xr-xr-x 0 0 10403-128-3 /WINDOWS/SchedLgU.Txt 6 mac. r/rr-xr-xr-x 0 0 10412-128-13 /WINDOWS/Tasks/SA.DAT 130 mac. r/rrwxrwxrwx 0 0 10423-128-79 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/drivetable.txt 53669 mac. r/rr-xr-xr-x 0 0 10427-128-3 /WINDOWS/system32/wbem/Logs/wbemess.log 83990 mac. r/rrwxrwxrwx 0 0 11179-128-3 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/RP12/change.log 65536 mac. r/rr-xr-xr-x 0 0 3659-128-1 /WINDOWS/system32/config/AppEvent.Evt 131072 macb 0 0 0 3663 [Event Log] (Time generated/Time written) EventLog/6006_Info_ (file: /media/sdb1/WINDOWS/system32/config/SysEvent.Evt) 131072 mac. r/rr-xr-xr-x 0 0 3663-128-1 /WINDOWS/system32/config/SysEvent.Evt 3160 .a.. r/rr-xr-xr-x 0 0 5549-128-3 /WINDOWS/system32/wbem/Repository/FS/MAPPING2.MAP 32490 mac. r/rr-xr-xr-x 0 0 6538-128-4 /WINDOWS/WindowsUpdate.log Fri Jul 01 2011 15:17:33 2048 mac. r/rrwxrwxrwx 0 0 10294-128-1 /WINDOWS/bootstat.dat 1024 mac. r/rr-xr-xr-x 0 0 3638-128-3 /WINDOWS/system32/config/software.LOG Fri Jul 01 2011 15:17:34 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Watchdog/Display 0 m... 0 0 0 0 REG_System_system/ControlSet001/Control/Windows 3407872 ma.. r/rr-xr-xr-x 0 0 10295-128-3 /WINDOWS/system32/config/system 9437184 ma.. r/rr-xr-xr-x 0 0 10297-128-3 /WINDOWS/system32/config/software 262144 ma.. r/rr-xr-xr-x 0 0 10299-128-3 /WINDOWS/system32/config/default 262144 .a.. r/rr-xr-xr-x 0 0 10326-128-3 /Documents and Settings/NetworkService/Local Settings/Application Data/Microsoft/Windows/UsrClass.dat 237568 ma.. r/rr-xr-xr-x 0 0 10361-128-4 /Documents and Settings/LocalService/NTUSER.DAT 262144 .a.. r/rr-xr-xr-x 0 0 10393-128-3 /Documents and Settings/LocalService/Local Settings/Application Data/Microsoft/Windows/UsrClass.dat 237568 ma.. r/rr-xr-xr-x 0 0 3634-128-4 /Documents and Settings/NetworkService/NTUSER.DAT 1024 mac. r/rr-xr-xr-x 0 0 3637-128-3 /WINDOWS/system32/config/system.LOG 262144 ma.. r/rr-xr-xr-x 0 0 3647-128-3 /WINDOWS/system32/config/SECURITY 262144 ma.. r/rr-xr-xr-x 0 0 3648-128-3 /WINDOWS/system32/config/SAM Fri Jul 01 2011 15:17:35 24 mac. r/rrwxrwxrwx 0 0 10440-128-1 /System Volume Information/_restore{A4323E41-9E96-4A95-B645-4A36ED086BEA}/_driver.cfg