2006-01-05 19:11:02 80480 -c--a-w- c:\program files\common files\microsoft shared\replication manager 4.0\msrpfs40.dll
2006-01-05 19:11:02 35424 ----a-w- c:\windows\system32\msrecr40.dll
2006-01-05 18:55:07 -------- d-----w- c:\program files\Setup NetZero
2005-12-27 18:22:59 274432 ----a-w- c:\windows\TLCUninstall.exe
2005-12-14 17:52:36 163840 ----a-w- c:\windows\system32\Thayer Birding Software.scr
2005-12-14 17:50:33 -------- d-----w- c:\program files\Thayer Birding Software
2005-12-09 18:47:32 1645320 ----a-w- c:\windows\system32\gdiplus.dll
2005-11-23 21:15:38 15616 ----a-w- c:\documents and settings\all users\application data\microsoft\identitycrl\ppcrlconfig.dll
2005-11-19 01:51:50 69632 ----a-w- c:\windows\system32\lfgif13n.dll
2005-11-19 01:51:44 57344 ----a-w- c:\windows\system32\lfbmp13n.dll
2005-11-19 01:51:44 462848 ----a-w- c:\windows\system32\ltkrn13n.dll
2005-11-19 01:51:44 450560 ----a-w- c:\windows\system32\ltimg13n.dll
2005-11-19 01:51:44 401408 ----a-w- c:\windows\system32\lfcmp13n.dll
2005-11-19 01:51:44 299008 ----a-w- c:\windows\system32\ltdis13n.dll
2005-11-19 01:51:44 206336 ----a-w- c:\windows\system32\ltefx13n.dll
2005-11-19 01:51:44 163840 ----a-w- c:\windows\system32\ltfil13n.dll
2005-10-29 03:49:42 84480 ------w- c:\windows\system32\pintool.exe
2005-10-29 03:49:40 25600 ------w- c:\windows\system32\bcsprsrc.dll
2005-10-29 03:49:40 151552 ------w- c:\windows\system32\ifxcardm.dll
2005-10-29 03:49:40 133120 ------w- c:\windows\system32\axaltocm.dll
2005-10-28 20:40:16 96792 ------w- c:\windows\system32\basecsp.dll
2005-08-25 17:10:25 81920 -c--a-w- c:\windows\asr32311.dll
2005-08-25 17:09:40 96256 ----a-w- c:\windows\system32\Smackw32.dll
2005-08-25 17:09:39 -------- d-----w- c:\program files\LSGE7
2005-07-26 04:31:13 74752 ----a-w- c:\windows\system32\olecli32.dll
2005-06-10 15:44:02 81920 -c--a-w- c:\program files\common files\installshield\updateservice\issch.exe
2005-06-10 15:44:02 618496 ----a-w- c:\program files\common files\installshield\updateservice\agent.exe
2005-06-10 15:44:02 368640 -c--a-w- c:\program files\common files\installshield\updateservice\_isusres.dll
2005-06-10 15:44:02 278528 -c--a-w- c:\program files\common files\installshield\updateservice\ISDM.exe
2005-05-04 04:06:30 1411816 ----a-w- c:\program files\common files\system\ole db\MSDMINE.DLL
2005-05-04 04:06:28 465640 ----a-w- c:\program files\common files\system\ole db\MSDMENG.DLL
2005-05-04 04:06:28 1071856 ----a-w- c:\program files\common files\system\ole db\MSMDGD80.DLL
2005-05-04 04:06:26 240360 ----a-w- c:\program files\common files\system\ole db\MSMDCB80.DLL
2005-05-04 04:06:26 228152 ----a-w- c:\program files\common files\system\ole db\MSOLUI80.DLL
2005-05-04 04:06:24 199408 ----a-w- c:\program files\common files\system\ole db\MSMDUN80.DLL
2005-05-03 01:52:56 5856 ----a-w- c:\windows\system32\INET16.DLL
2005-05-03 01:52:04 -------- d-----w- c:\windows\Intuit
2005-05-03 01:52:04 -------- d-----w- c:\program files\QUICKENW
2005-04-22 05:20:24 57344 -c--a-w- c:\windows\system32\dllcache\agentdpv.dll
2005-03-16 19:45:58 8359936 ------w- c:\program files\microsoft games\zoo tycoon 2\SETUPENU.DLL
2005-03-16 19:45:51 589824 ------w- c:\program files\microsoft games\zoo tycoon 2\UNINSTAL.EXE
2005-01-14 01:14:29 -------- d-----w- c:\program files\Yahoo!
2005-01-04 07:02:47 -------- d-----w- c:\program files\CitrusWare
2005-01-04 07:01:27 249856 -c----w- c:\windows\Setup1.exe
2005-01-04 07:01:25 73216 -c--a-w- c:\windows\ST6UNST.EXE
2004-12-26 20:14:38 -------- d-----w- c:\program files\ValuSoft
2004-12-26 20:05:25 394240 -c--a-w- c:\windows\system32\dllcache\diactfrm.dll
2004-12-26 20:05:25 394240 ----a-w- c:\windows\system32\diactfrm.dll
2004-12-26 20:05:19 46592 ----a-w- c:\windows\system32\dxdllreg.exe
2004-12-26 18:52:11 -------- d--h--w- c:\windows\msdownld.tmp
2004-12-25 22:45:58 -------- d-----w- c:\program files\S3
2004-12-25 14:44:28 -------- d-----w- c:\windows\RegisteredPackages
2004-12-18 08:08:22 3935744 ------w- c:\program files\microsoft games\zoo tycoon 2\zt.exe
2004-12-17 21:24:00 45056 ------w- c:\program files\microsoft games\zoo tycoon 2\strings.dll
2004-10-01 21:08:00 370688 ------w- c:\program files\microsoft games\zoo tycoon 2\mss32.dll
2004-10-01 21:05:00 395400 ------w- c:\program files\microsoft games\zoo tycoon 2\ipworks5.dll
2004-10-01 20:53:00 186952 -c----w- c:\program files\microsoft games\zoo tycoon 2\dw.exe
2004-10-01 20:52:00 338944 ------w- c:\program files\microsoft games\zoo tycoon 2\binkw32.dll
2004-10-01 20:49:00 54688 -c----w- c:\program files\microsoft games\zoo tycoon 2\1033\dwintl.dll
2004-09-23 22:58:27 73728 ------w- c:\program files\microsoft games\zoo tycoon 2\Eula.dll
2004-09-21 00:12:48 109256 -c--a-w- c:\program files\common files\microsoft shared\dw\1025\DWINTL20.DLL
2004-09-15 22:38:39 77824 -c----w- c:\program files\microsoft games\zoo tycoon 2\mgspid.dll
2004-08-04 07:56:57 57856 ----a-w- c:\windows\system32\SET1F5.tmp
2004-08-04 07:55:59 63488 ----a-w- c:\windows\system32\SET445.tmp
2004-08-04 07:55:59 285696 ------w- c:\windows\system32\SET451.tmp
2004-08-04 05:31:43 152576 ----a-w- c:\windows\system32\SET234.tmp
2004-08-04 05:31:43 137216 ----a-w- c:\windows\system32\SET3C6.tmp
2004-08-04 05:22:58 526848 ------w- c:\windows\system32\SET390.tmp
2004-08-04 05:21:50 28672 -c--a-w- c:\program files\common files\system\ole db\SET4B7.tmp
2004-08-04 05:21:47 90112 ------w- c:\windows\system32\SET1F3.tmp
2004-08-04 05:21:46 61440 -c--a-w- c:\program files\common files\system\ole db\SET4B9.tmp
2004-08-04 05:21:44 81920 -c--a-w- c:\program files\common files\system\ado\SET53B.tmp
2004-08-04 05:21:43 81920 -c--a-w- c:\program files\common files\system\ado\SET53C.tmp
2004-08-04 05:21:43 61440 -c--a-w- c:\program files\common files\system\ado\SET53E.tmp
2004-08-04 05:21:43 61440 -c--a-w- c:\program files\common files\system\ado\SET53D.tmp
2004-08-04 04:56:58 21504 ------w- c:\windows\system32\spupdwxp.exe
2004-08-04 04:56:58 11776 ------w- c:\windows\system32\spnpinst.exe
2004-07-17 18:40:21 19528 -c--a-w- c:\windows\002559_.tmp
2004-06-03 19:24:52 167168 ----a-w- c:\windows\system32\drivers\s3gnbm.sys
2004-06-03 19:24:28 402560 ----a-w- c:\windows\system32\s3gnb.dll
2004-05-27 20:00:52 118784 ----a-r- c:\windows\system32\HPODXPAT.DLL
2004-04-23 18:42:26 409600 -c--a-w- c:\program files\common files\installshield\driver\10\intel 32\ISRT.dll
2004-04-19 21:23:16 540772 -c--a-w- c:\program files\common files\installshield\driver\10\intel 32\_ISRES1033.dll
2004-04-19 04:45:50 761856 -c--a-w- c:\program files\common files\installshield\driver\10\intel 32\IDriver2.exe
2004-04-19 04:45:50 761856 -c--a-w- c:\program files\common files\installshield\driver\10\intel 32\IDriver.exe
2004-04-19 04:40:34 180224 -c--a-w- c:\program files\common files\installshield\driver\10\intel 32\iGdiCnv.dll
2004-04-19 04:40:16 262144 -c--a-w- c:\program files\common files\installshield\driver\10\intel 32\IScrCnv.dll
2004-04-19 04:39:38 172032 -c--a-w- c:\program files\common files\installshield\driver\10\intel 32\IUserCnv.dll
2004-04-19 04:36:36 32768 -c--a-w- c:\program files\common files\installshield\driver\10\intel 32\objpscnv.dll
2004-04-08 18:12:42 70144 ----a-w- c:\windows\system32\QuickTimeCheck.ocx
2004-04-08 18:12:41 430592 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2004-04-08 18:12:41 323072 ----a-w- c:\windows\system32\QuickTime.cpl
2004-04-08 18:12:41 2017280 ----a-w- c:\windows\system32\QuickTimeMusicalInstruments.qtx
2004-04-08 18:12:40 5524992 ----a-w- c:\windows\system32\QuickTime.qts
2004-04-08 18:12:39 959488 ----a-w- c:\windows\system32\qd3d.dll
2004-04-08 18:12:39 685056 ----a-w- c:\windows\system32\rave.dll
2004-04-08 18:12:39 67072 ----a-w- c:\windows\system32\QD3DCustomElements.q3x
2004-04-08 18:12:39 290304 ----a-w- c:\windows\system32\QD3D_IR2.q3x
2004-04-08 18:12:39 127488 ----a-w- c:\windows\system32\3DViewer.dll
2004-04-07 22:58:47 172032 ----a-w- c:\windows\system32\TTSServer.dll
2004-03-29 22:50:04 54688 -c----w- c:\program files\microsoft games\zoo tycoon 2\1028\dwintl.dll
2004-03-25 21:02:28 86016 ----a-w- c:\windows\unvise32qt.exe
2004-03-25 21:02:25 106496 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2004-03-25 21:02:25 106496 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2004-03-25 21:02:25 106496 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2004-03-25 21:02:25 106496 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2004-03-25 21:02:25 106496 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2004-03-25 21:01:20 -------- d-----w- c:\windows\system32\QuickTime
2004-03-23 16:23:30 352256 ----a-r- c:\windows\eSellerateEngine.dll
2004-03-21 06:26:16 -------- d-----w- c:\windows\ServicePackFiles
2004-03-21 06:26:16 -------- d-----w- c:\windows\ehome
2004-03-21 06:15:02 446464 ------w- c:\windows\system32\wmvdmoe.dll
2004-03-21 06:12:12 311327 ------w- c:\windows\system32\wmv8dmod.dll
2004-03-21 06:10:48 520192 -c--a-w- c:\program files\windows media player\wmpvis.dll
2004-03-21 06:08:24 77824 ------w- c:\windows\system32\wmpstub.exe
2004-03-21 06:08:12 3371008 -c--a-w- c:\windows\system32\dllcache\wmploc.dll
2004-03-21 06:01:34 163897 -c--a-w- c:\program files\movie maker\wmmutil.dll
2004-03-21 06:01:23 319542 ----a-w- c:\program files\movie maker\wmmres.dll
2004-03-21 06:00:58 110648 -c--a-w- c:\program files\movie maker\wmmfilt.dll
2004-03-21 05:59:16 89600 ------w- c:\windows\system32\wmidx.ocx
2004-03-21 05:58:47 51200 ------w- c:\windows\system32\wmerrenu.dll
2004-03-21 03:14:45 169984 ------w- c:\windows\system32\sccbase.dll
2004-03-21 02:48:31 94208 -c--a-w- c:\program files\msn\msncorefiles\popc.dll
2004-03-21 02:02:02 364544 -c--a-w- c:\windows\system32\dllcache\npdsplay.dll
2004-03-21 02:02:02 364544 -c--a-w- c:\program files\windows media player\npdsplay.dll
2004-03-21 01:57:46 1677312 ------w- c:\windows\system32\wmvcore2.dll
2004-03-20 23:53:32 241725 ------w- c:\windows\system32\msuni11.dll
2004-03-20 23:39:38 36864 -c--a-w- c:\program files\msn\msncorefiles\setup\msnunin.exe
2004-03-20 23:39:13 94208 -c--a-w- c:\program files\msn\msncorefiles\msnspell.dll
2004-03-20 23:39:05 28672 -c--a-w- c:\program files\msn\msncorefiles\setup\migrate.dll
2004-03-20 23:39:04 77824 -c--a-w- c:\program files\msn\msncorefiles\msnmtllc.dll
2004-03-20 23:38:59 57344 -c--a-w- c:\program files\msn\msncorefiles\migrate.dll
2004-03-20 23:38:56 978944 -c--a-w- c:\program files\msn\msncorefiles\msnmetal.dll
2004-03-20 23:37:08 94208 ----a-w- c:\program files\msn\msncorefiles\msn6.exe
2004-03-20 23:24:14 69663 -c--a-w- c:\program files\messenger\msmsgsin.exe
2004-03-20 23:20:05 360448 -c--a-w- c:\program files\msn\msncorefiles\msmom.dll
2004-03-20 23:13:11 368710 ------w- c:\windows\system32\msisam11.dll
2004-03-20 23:11:09 271360 ------w- c:\windows\system32\msihnd.dll
2004-03-20 23:10:33 78848 ------w- c:\windows\system32\msiexec.exe
2004-03-20 23:10:00 2854400 ----a-w- c:\windows\system32\msi.dll
2004-03-20 22:49:48 61440 -c--a-w- c:\program files\msn\msncorefiles\msdbx.dll
2004-03-20 22:01:58 163840 ------w- c:\windows\system32\mindex.dll
2004-03-20 21:52:51 245760 -c--a-w- c:\program files\msn\msncorefiles\logonmgr.dll
2004-03-20 20:15:39 42537 ------w- c:\windows\system32\keyboard.sys
2004-03-20 18:55:56 19274 -c--a-w- c:\windows\000001_.tmp
2004-03-20 18:38:30 162120 -c--a-w- c:\program files\msn\msncorefiles\dw.exe
2004-03-20 18:35:02 258296 -c--a-w- c:\windows\system32\dllcache\drmclien.dll
2004-03-20 18:26:45 24576 ------w- c:\windows\system32\dbmsvinn.dll
2004-03-20 18:26:42 20480 ------w- c:\windows\system32\dbmsadsn.dll
2004-03-20 18:22:23 24576 -c--a-w- c:\program files\msn\msncorefiles\custdial.dll
2004-03-20 18:16:28 77824 -c--a-w- c:\program files\msn\msncorefiles\copymar.exe
2004-03-20 18:05:33 96480 -c--a-w- c:\windows\system32\dllcache\cdm.dll
2004-03-20 18:00:12 77824 -c--a-w- c:\program files\msn\msncorefiles\update.exe
2004-03-18 12:44:29 1663068 ----a-w- c:\windows\system32\libmmd.dll
2004-03-02 14:38:34 -------- d-----w- c:\program files\AWS
2004-02-25 01:17:18 45056 ----a-w- c:\windows\system32\VTPreset.exe
2004-02-19 20:11:35 -------- d-----w- c:\windows\rvrcache
2004-02-18 08:41:56 339968 ----a-w- c:\windows\system32\S3Ovrlay.dll
2004-02-10 09:26:56 229376 ----a-w- c:\windows\system32\S3Info2.dll
2004-01-30 20:24:31 -------- d-----w- c:\windows\APW_DATA
2004-01-20 08:09:18 348160 ----a-w- c:\windows\system32\S3Gamma2.dll
2003-12-30 18:01:30 -------- d-----w- c:\program files\Pan Interactive
2003-12-30 02:07:27 -------- d-----w- c:\program files\common files\Vivendi Universal Games
2003-12-30 02:07:26 -------- d-----w- c:\documents and settings\all users\application data\Vivendi Universal Games
2003-12-30 00:08:18 -------- d-----w- c:\documents and settings\all users\application data\VUG
2003-12-29 23:50:09 101888 ------w- c:\windows\system32\VB6STKIT.DLL
2003-12-29 23:50:07 115920 ------w- c:\windows\system32\MSINET.OCX
2003-12-29 23:48:32 -------- d-----w- c:\program files\common files\Vivendi Universal
2003-12-25 16:09:35 286720 ----a-w- c:\windows\iun507.exe
2003-12-25 16:08:06 -------- d-----w- c:\program files\BigIdea
2003-12-25 13:43:56 -------- d-----w- c:\program files\Twister
2003-12-19 23:12:38 761856 ----a-w- c:\windows\system32\nbicdnt.dll
2003-11-27 17:15:02 -------- d-----w- c:\windows\BBSTORE
2003-11-23 20:29:56 -------- d-----w- c:\windows\CWONDERS
2003-11-23 20:29:17 346112 -c--a-r- c:\windows\system\QTIM32.DLL
2003-11-23 20:29:16 12800 -c--a-w- c:\windows\system\WING32.DLL
2003-11-20 19:03:58 221184 ----a-w- c:\program files\common files\microsoft shared\translat\WTSP61MS.DLL
2003-11-10 22:18:02 761856 ----a-w- c:\program files\common files\installshield\driver\9\intel 32\IDriver2.exe
2003-11-10 22:18:02 761856 ----a-w- c:\program files\common files\installshield\driver\9\intel 32\IDriver.exe
2003-11-10 22:16:22 401408 ----a-w- c:\program files\common files\installshield\driver\9\intel 32\ISRT.dll
2003-11-10 22:13:20 188416 ----a-w- c:\program files\common files\installshield\driver\9\intel 32\iGdiCnv.dll
2003-11-10 22:13:02 266240 ----a-w- c:\program files\common files\installshield\driver\9\intel 32\IScrCnv.dll
2003-11-10 22:12:24 192512 ----a-w- c:\program files\common files\installshield\driver\9\intel 32\IUserCnv.dll
2003-11-10 22:10:12 32768 ----a-w- c:\program files\common files\installshield\driver\9\intel 32\objpscnv.dll
2003-10-25 14:08:47 -------- d-----w- c:\documents and settings\all users\application data\Broderbund LLC
2003-10-25 14:08:03 2454528 ------w- c:\windows\system32\IPLM6.DLL
2003-10-25 14:08:03 2250752 ------w- c:\windows\system32\IPLP6.DLL
2003-10-25 14:08:03 2206208 ------w- c:\windows\system32\IPLPX.DLL
2003-10-25 14:08:03 2153984 ------w- c:\windows\system32\IPLP5.DLL
2003-10-25 14:08:02 69120 ------w- c:\windows\system32\IPL.DLL
2003-10-25 14:08:02 2563072 ------w- c:\windows\system32\IPLA6.DLL
2003-10-25 14:08:02 2363392 ------w- c:\windows\system32\IPLM5.DLL
2003-10-25 14:07:59 -------- d-----w- c:\program files\Broderbund
2003-09-23 07:07:26 458752 ----a-w- c:\windows\system32\S3Disply.dll
2003-09-23 06:46:32 69690 ----a-w- c:\windows\system32\S3uninst.exe
2003-09-06 19:27:12 -------- d-----w- c:\program files\Infogrames Interactive
2003-09-03 08:53:48 299008 ----a-w- c:\program files\common files\installshield\driver\9\intel 32\_ISRES1033.dll
2003-08-30 02:04:40 26112 ----a-w- c:\windows\system32\xpsp1hfm.exe
2003-08-30 02:04:40 -------- dc-h--w- c:\windows\$xpsp1hfm$
2003-08-29 03:02:35 198424 -c--a-w- c:\windows\system32\dllcache\iuengine.dll
2003-08-29 03:02:35 198424 ----a-w- c:\windows\system32\iuengine.dll
2003-08-08 19:44:48 111192 -c--a-w- c:\program files\common files\microsoft shared\dw\3082\DWINTL20.DLL
2003-08-08 18:35:44 112216 -c--a-w- c:\program files\common files\microsoft shared\dw\1036\DWINTL20.DLL
2003-08-08 18:34:08 111704 -c--a-w- c:\program files\common files\microsoft shared\dw\1040\DWINTL20.DLL
2003-08-05 04:46:18 81920 ------w- c:\program files\microsoft games\zoo tycoon 2\splash.exe
2003-07-15 02:54:00 109120 -c--a-w- c:\program files\common files\microsoft shared\dw\1042\DWINTL20.DLL
2003-07-15 02:53:46 109120 -c--a-w- c:\program files\common files\microsoft shared\dw\1028\DWINTL20.DLL
2003-07-15 02:53:28 112704 -c--a-w- c:\program files\common files\microsoft shared\dw\1031\DWINTL20.DLL
2003-07-15 02:53:22 109120 -c--a-w- c:\program files\common files\microsoft shared\dw\1041\DWINTL20.DLL
2003-07-15 02:53:12 109120 -c--a-w- c:\program files\common files\microsoft shared\dw\2052\DWINTL20.DLL
2003-06-23 07:44:36 1415680 ----a-w- c:\windows\system32\wmv9vcm.dll
2003-05-02 16:18:48 81920 ----a-w- c:\program files\common files\microsoft shared\translat\MSB1STAR.DLL
2003-04-18 23:57:26 60000 -c----w- c:\program files\microsoft games\zoo tycoon 2\1036\dwintl.dll
2003-04-18 23:57:26 55440 -c----w- c:\program files\microsoft games\zoo tycoon 2\3082\dwintl.dll
2003-04-18 23:57:26 55440 -c----w- c:\program files\microsoft games\zoo tycoon 2\1053\dwintl.dll
2003-04-18 23:57:26 55440 -c----w- c:\program files\microsoft games\zoo tycoon 2\1046\dwintl.dll
2003-04-18 23:57:26 55440 -c----w- c:\program files\microsoft games\zoo tycoon 2\1040\dwintl.dll
2003-04-18 23:57:26 54688 -c----w- c:\program files\microsoft games\zoo tycoon 2\1042\dwintl.dll
2003-04-18 23:57:24 54688 -c----w- c:\program files\microsoft games\zoo tycoon 2\1031\dwintl.dll
2003-04-15 00:00:52 203432 -c----w- c:\program files\messenger\_003231_.tmp.dll
2003-04-01 17:19:10 32768 -c--a-w- c:\program files\common files\installshield\driver\8\intel 32\objps8.dll
2003-04-01 17:18:50 188416 -c--a-w- c:\program files\common files\installshield\driver\8\intel 32\IUser8.dll
2003-04-01 17:18:30 327680 -c--a-w- c:\program files\common files\installshield\driver\8\intel 32\ISRT.dll
2003-04-01 17:18:10 237568 -c--a-w- c:\program files\common files\installshield\driver\8\intel 32\IScript8.dll
2003-03-31 19:29:00 625537 ----a-w- c:\windows\system32\drivers\ltmdmnt.sys
2003-03-28 23:21:36 647168 -c--a-w- c:\program files\common files\installshield\driver\8\intel 32\IDriver2.exe
2003-03-28 23:21:36 647168 -c--a-w- c:\program files\common files\installshield\driver\8\intel 32\IDriver.exe
2003-03-24 18:59:32 543304 ----a-w- c:\program files\common files\microsoft shared\equation\EQNEDT32.EXE
2003-03-19 23:14:50 53248 ----a-w- c:\windows\system32\pagesync.dll
2003-03-19 23:14:44 151552 ----a-w- c:\windows\system32\imsitour.dll
2003-03-19 23:14:42 630784 ----a-w- c:\windows\system32\imsisync.dll
2003-03-19 23:14:40 909312 ----a-w- c:\windows\system32\imsireg.dll
2003-03-19 23:14:32 135168 ----a-w- c:\windows\system32\Quest.dll
2003-03-19 02:20:00 1060864 ----a-w- c:\windows\system32\mfc71.dll
2003-03-19 02:12:12 1047552 ----a-w- c:\windows\system32\MFC71u.dll
2003-03-19 01:44:38 57344 ----a-w- c:\windows\system32\MFC71ENU.DLL
2003-03-19 01:44:38 49152 ----a-w- c:\windows\system32\MFC71KOR.DLL
2003-03-19 01:44:36 61440 ----a-w- c:\windows\system32\MFC71ITA.DLL
2003-03-19 01:44:36 61440 ----a-w- c:\windows\system32\MFC71ESP.DLL
2003-03-19 01:44:36 45056 ----a-w- c:\windows\system32\MFC71CHT.DLL
2003-03-19 01:44:36 40960 ----a-w- c:\windows\system32\MFC71CHS.DLL
2003-03-19 01:44:34 65536 ----a-w- c:\windows\system32\MFC71DEU.DLL
2003-03-19 01:44:34 61440 ----a-w- c:\windows\system32\MFC71FRA.DLL
2003-03-19 01:44:34 49152 ----a-w- c:\windows\system32\MFC71JPN.DLL
2003-03-05 23:45:24 290816 -c--a-w- c:\program files\common files\installshield\driver\8\intel 32\_ISRES1033.dll
2003-03-03 21:28:12 64096 ----a-w- c:\program files\common files\microsoft shared\equation\1033\EEINTL.DLL
2003-02-27 01:16:13 27632 -c--a-w- c:\windows\system\ctl3dv2.dll
2003-02-21 17:01:37 -------- d-----w- c:\program files\The Learning Company
2003-01-28 20:37:36 -------- d-----w- c:\windows\PROGRAM
2003-01-28 20:37:36 -------- d-----w- c:\windows\GARDEN
2003-01-27 15:31:08 286768 -c--a-w- c:\windows\MVIEWER2.EXE
2003-01-27 15:31:08 27136 ------w- c:\windows\system32\VERMONT1.DLL
2003-01-27 15:31:08 12416 ------w- c:\windows\system32\VRX1.DLL
2003-01-27 15:31:07 35312 ------w- c:\windows\system32\DUNZIP.DLL
2003-01-27 15:31:06 107520 ------w- c:\windows\system32\SIMANT.DLL
2003-01-18 14:23:37 18432 -c----w- c:\program files\common files\microsoft shared\msinfo\IMGWALK.dll
2003-01-18 14:23:37 16304 -c----w- c:\program files\common files\microsoft shared\msinfo\Msinf16h.exe
2003-01-17 16:28:31 216064 ----a-w- c:\windows\iun3405.exe
2003-01-06 02:21:55 95232 ------w- c:\windows\system32\LFKODAK.DLL
2003-01-06 02:21:55 306688 ------w- c:\windows\system32\LFFPX7.DLL
2002-12-28 02:08:38 24576 ------w- c:\windows\system32\Awcodc32.dll
2002-12-28 02:08:35 6144 ------w- c:\windows\system32\Awdcxc32.dll
2002-12-28 02:08:35 11776 ------w- c:\windows\system32\Awdenc32.dll
2002-12-28 02:08:35 10240 ------w- c:\windows\system32\Awview32.dll
2002-12-28 02:03:49 1022976 ------w- c:\windows\system32\SierraNW.dll
2002-12-28 02:03:48 231936 ------w- c:\windows\system32\SNWValid.dll
2002-12-28 00:50:00 398416 ------w- c:\windows\system32\Vbrun300.dll
2002-12-28 00:49:58 -------- d-----w- c:\program files\Compton's Home Library
2002-12-25 14:14:16 -------- d-----w- c:\program files\HeadGames
2002-12-20 18:02:44 1077336 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2002-12-17 23:09:04 286720 -c--a-w- c:\windows\iun506.exe
2002-12-17 23:09:04 -------- d-----w- c:\program files\Ultimate Game Pak
2002-12-16 00:11:38 93184 -c--a-w- c:\windows\system\MVMCI2.DLL
2002-12-16 00:11:38 53760 -c--a-w- c:\windows\system\MVSRCH2.DLL
2002-12-16 00:11:38 52224 -c--a-w- c:\windows\system\MVFS2.DLL
2002-12-16 00:11:38 286704 -c--a-w- c:\windows\system\MVIEWER2.EXE
2002-12-16 00:11:38 24576 -c--a-w- c:\windows\system\MVTITLE2.DLL
2002-12-16 00:11:38 19968 -c--a-w- c:\windows\system\MVBRKR2.DLL
2002-12-16 00:11:38 160256 -c--a-w- c:\windows\system\MVFTSUI2.DLL
2002-12-16 00:11:38 138864 -c--a-w- c:\windows\system\MVBMP2.DLL
2002-12-16 00:11:37 14416 -c--a-w- c:\windows\system\CTL3D.DLL
2002-12-16 00:11:37 12288 -c--a-w- c:\windows\system\MVAPI2.DLL
2002-12-16 00:11:37 11264 -c--a-w- c:\windows\system\MVAUDIO.DLL
2002-12-16 00:11:37 105072 -c--a-w- c:\windows\system\MMP.DLL
2002-12-02 18:10:12 -------- d-----w- c:\program files\WCA
2002-12-01 02:21:48 60457 ------w- c:\windows\system32\EBPMON3.DLL
2002-12-01 02:21:47 56832 ------w- c:\windows\system32\ECBTEG.DLL
2002-12-01 02:21:47 34304 ------w- c:\windows\system32\EBPCHP.DLL
2002-12-01 02:21:47 166400 ------w- c:\windows\system32\EBAPI3.DLL
2002-12-01 02:21:46 69120 ------w- c:\windows\system32\EAL.EXE
2002-12-01 02:21:46 44544 ------w- c:\windows\system32\EAL32.DLL
2002-11-30 16:48:17 299520 ----a-w- c:\windows\uninst.exe
2002-11-29 18:05:17 15664 ------w- c:\windows\system32\PSUITE.SCR
2002-11-29 18:05:14 -------- d-----w- c:\program files\MGI
2002-11-28 04:41:31 57344 ----a-w- c:\windows\system32\tlcsel32.dll
2002-11-28 04:41:31 16540 ----a-w- c:\windows\system32\tlcsel17.dll
2002-11-28 04:06:28 -------- d--h--w- C:\~cevts_001_tmp.dir
2002-11-28 03:19:08 54272 ----a-w- c:\windows\system32\drivers\swmidi.sys
2002-11-28 03:18:34 2944 ----a-w- c:\windows\system32\drivers\msmpu401.sys
2002-08-29 10:41:00 101888 -c----w- c:\windows\Tlcsel.bin
2002-08-29 10:41:00 101888 ------w- c:\windows\system32\Mfts50.dll
2002-08-22 11:45:34 32768 ----a-w- c:\program files\common files\microsoft shared\office12\vs runtime\1033\vsbrowseUI.dll
2002-08-07 23:06:42 54688 -c----w- c:\program files\microsoft games\zoo tycoon 2\1041\dwintl.dll
2002-08-06 12:27:44 -------- d-----r- C:\Program Files
2002-08-06 12:26:48 -------- d-----r- c:\documents and settings\all users\Documents
2002-08-06 12:26:18 -------- d-----r- c:\windows\Offline Web Pages
2002-08-06 12:23:34 -------- dcsh--r- c:\windows\system32\dllcache
2002-08-06 02:05:59 12288 -c--a-w- c:\windows\system32\wbem\wbemads.dll
2002-08-06 02:04:59 44032 -c--a-w- c:\windows\system32\dllcache\msxml3r.dll
2002-08-06 02:03:49 42768 -c--a-w- c:\windows\system32\dllcache\dpwsock.dll
2002-07-27 03:33:49 -------- d-s---w- c:\windows\system32\Microsoft
2002-07-27 03:33:19 -------- d-----w- c:\documents and settings\all users\application data\Symantec
2002-07-27 03:33:14 -------- d-----w- c:\program files\common files\Symantec Shared
2002-07-25 21:17:53 151552 ------w- c:\windows\system32\igfxres.dll
2002-07-25 00:39:39 82864 ----a-w- c:\windows\UNWISE.EXE
2002-07-25 00:39:38 7407 ------w- c:\windows\system32\pcdr_cs.vxd
2002-07-25 00:39:38 44192 ----a-w- c:\windows\system32\drivers\PcdrNt.sys
2002-07-25 00:39:38 377600 ------w- c:\windows\system32\BOCOLE.DLL
2002-07-25 00:39:38 167456 ------w- c:\windows\system32\Bocof.dll
2002-07-25 00:39:36 -------- d-----w- c:\program files\PC-Doctor for Windows XP
2002-07-25 00:36:12 -------- d-----w- c:\program files\HP Instant Support
2002-07-25 00:35:16 40960 ------w- c:\windows\system32\omano.dll
2002-07-25 00:35:16 -------- d---a-w- c:\windows\system32\hpintro
2002-07-25 00:33:13 90112 ----a-r- c:\windows\bwUnin-6.1.0.153.exe
2002-07-25 00:33:13 -------- d-----w- c:\program files\hp center
2002-07-25 00:33:12 -------- d-----w- c:\program files\BackWeb
2002-07-25 00:33:09 86 ------w- c:\windows\system32\installink.bat
2002-07-25 00:33:09 45056 ------w- c:\windows\system32\runclose.ocx
2002-07-25 00:33:09 -------- d---a-w- c:\windows\system32\keep in touch with HP_files
2002-07-25 00:33:00 89360 ----a-w- c:\windows\system32\VB5DB.DLL
2002-07-25 00:32:47 -------- d-----w- c:\windows\speech
2002-07-25 00:32:45 -------- d-----w- c:\windows\lhsp
2002-07-25 00:32:35 77824 ------w- c:\windows\system32\hpaghlpr.dll
2002-07-25 00:32:31 45056 ------w- c:\windows\system32\hpREG.DLL
2002-07-25 00:32:31 24576 ------w- c:\windows\system32\syscontr.dll
2002-07-25 00:05:04 -------- d-----w- c:\windows\SMINST
2002-07-25 00:04:31 -------- d-----w- c:\program files\AtBackup
2002-07-25 00:02:12 -------- d-----w- c:\program files\common files\Borland Shared
2002-07-25 00:02:11 -------- d-----w- c:\windows\ShellNew
2002-07-25 00:01:45 -------- d-----w- c:\program files\Corel
2002-07-25 00:01:31 -------- d-----w- c:\windows\Corel
2002-07-24 23:59:59 225280 ------w- c:\program files\internet explorer\plugins\NPDocBox.dll
2002-07-24 23:59:59 -------- d-----w- c:\windows\Profiles
2002-07-24 23:59:56 -------- d-----w- c:\windows\system32\Adobe
2002-07-24 23:58:19 -------- d-----w- c:\program files\Sonic
2002-07-24 23:47:58 -------- d-----w- c:\windows\HPTK
2002-07-24 23:43:43 77312 ------w- c:\windows\system32\TWAIN_32.DLL
2002-07-24 23:43:43 212480 ------w- c:\windows\system32\PCDLIB32.DLL
2002-07-24 23:38:33 109248 ----a-w- c:\windows\system32\mswinsck.ocx
2002-07-24 23:38:28 -------- d-----w- c:\program files\WildTangent
2002-07-24 23:35:57 -------- d-----w- c:\program files\MUSICMATCH
2002-07-24 23:35:24 -------- dc----w- c:\program files\HPSelect
2002-07-24 23:34:36 98352 -c--a-w- c:\windows\dla.exe
2002-07-24 23:34:36 81552 ----a-w- c:\windows\system32\drivers\drvmcdb.sys
2002-07-24 23:34:36 61492 ------w- c:\windows\system32\tfswapi.dll
2002-07-24 23:34:36 5589 ----a-w- c:\windows\system32\drivers\sscdbhk5.sys
2002-07-24 23:34:36 40368 ----a-w- c:\windows\system32\drivers\drvnddm.sys
2002-07-24 23:34:36 22995 ----a-w- c:\windows\system32\drivers\ssrtln.sys
2002-07-24 23:34:36 -------- d-----w- c:\windows\system32\dla
2002-07-24 23:34:34 -------- d-----w- c:\program files\DLA
2002-07-24 23:33:56 -------- d-----w- c:\program files\VERITAS Software
2002-07-24 23:33:47 -------- d-----w- c:\program files\RecordNow
2002-07-24 23:31:32 225280 ----a-w- c:\program files\common files\installshield\iscript\IScript.dll
2002-07-24 23:31:31 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2002-07-24 23:31:31 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2002-07-24 23:31:31 212992 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ILog.dll
2002-07-24 23:31:31 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2002-07-24 23:23:38 -------- d-----w- c:\documents and settings\all users\application data\Sbsi
2002-07-24 23:22:27 81920 ------w- c:\windows\system32\ps2.EXE
2002-07-24 23:22:20 81920 ------w- c:\windows\system32\ps2.bat
2002-07-24 23:22:20 19072 ----a-w- c:\windows\system32\drivers\PS2.sys
2002-07-24 23:21:32 35840 ----a-w- c:\windows\system32\drivers\AFS2K.SYS
2002-07-24 23:20:17 36864 ------w- c:\windows\system32\HPUNINST.DLL
2002-07-24 23:19:50 -------- d-----w- c:\program files\HP Photosmart 11
2002-07-24 23:02:32 -------- d-----w- c:\windows\nview
2002-07-24 23:02:30 -------- d-----w- c:\windows\system32\ReinstallBackups
2002-07-24 23:00:11 52736 ----a-w- c:\windows\system\hpsysdrv.exe
2002-07-24 22:59:26 716288 ------w- c:\windows\system32\RDBios32.DLL
2002-07-24 22:58:11 65536 ------w- c:\windows\system32\PyWinTypes22.dll
2002-07-24 22:58:11 299073 ------w- c:\windows\system32\PythonCOM22.dll
.
==================== Find3M ====================
.
2011-07-07 00:52:42 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-07 00:52:42 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-17 19:51:06 16704 ----a-w- c:\windows\system32\roboot.exe
2010-06-14 14:30:28 743936 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-05-06 10:41:53 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-06 10:41:50 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-05-02 05:56:34 1850880 ------w- c:\windows\system32\win32k.sys
2010-04-20 05:51:20 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-03-10 06:15:52 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-09 13:21:12 874224 ----a-w- c:\windows\system32\SSDW3B32.ocx
2010-03-09 13:21:12 72192 ----a-w- c:\windows\system32\ssprn32.dll
2010-03-09 13:21:12 61440 ----a-w- c:\windows\system32\ssmedt32.dll
2010-03-09 13:21:12 415504 ----a-w- c:\windows\system32\msrepl35.dll
2010-03-09 13:21:12 252688 ----a-w- c:\windows\system32\msexcl35.dll
2010-03-09 13:21:12 24848 ----a-w- c:\windows\system32\msjter35.dll
2010-03-09 13:21:12 166672 ----a-w- c:\windows\system32\mstext35.dll
2010-03-09 13:21:12 123664 ----a-w- c:\windows\system32\Msjint35.dll
2010-03-05 14:57:17 65536 ----a-w- c:\windows\system32\asycfilt.dll
2010-02-24 12:31:30 454016 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 13:19:55 2181376 ------w- c:\windows\system32\ntoskrnl.exe
2010-02-16 12:39:04 2058368 ------w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:47:05 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:01:43 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2010-02-05 18:40:58 1291264 ----a-w- c:\windows\system32\quartz.dll
2010-01-29 15:08:04 683520 ------w- c:\windows\system32\inetcomm.dll
2010-01-29 14:43:39 307260 ----a-w- c:\windows\system32\l3codeca.acm
2010-01-29 14:43:39 143422 ----a-w- c:\windows\system32\l3codecx.ax
2010-01-13 14:10:54 85504 ------w- c:\windows\system32\cabview.dll
2009-12-31 16:14:12 352640 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-24 07:05:26 177664 ----a-w- c:\windows\system32\wintrust.dll
2009-12-16 12:58:04 343040 ------w- c:\windows\system32\mspaint.exe
2009-12-14 07:35:35 33280 ------w- c:\windows\system32\csrsrv.dll
2009-11-27 17:33:35 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:37:27 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:37:27 84992 ------w- c:\windows\system32\avifil32.dll
2009-11-27 16:37:27 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:37:27 28672 ------w- c:\windows\system32\msvidc32.dll
2009-11-27 16:37:27 11264 ------w- c:\windows\system32\msrle32.dll
2009-11-21 16:36:13 470528 ----a-w- c:\windows\apppatch\aclayers.dll
2009-10-21 06:00:55 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 06:00:55 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 14:58:48 263552 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-16 03:51:48 119808 ------w- c:\windows\system32\t2embed.dll
2009-10-15 17:21:47 82432 ------w- c:\windows\system32\fontsub.dll
2009-10-13 10:53:29 266752 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:54:17 69632 ----a-w- c:\windows\system32\raschap.dll
2009-10-12 13:54:17 112128 ----a-w- c:\windows\system32\rastls.dll
2009-09-11 14:33:52 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 20:45:26 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-01 14:32:11 282654 ------w- c:\windows\system32\msaud32.acm
2009-08-26 08:16:37 247326 ------w- c:\windows\system32\strmdll.dll
2009-08-25 09:47:14 352256 ----a-w- c:\windows\system32\winhttp.dll
2009-08-05 09:11:47 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 18:55:28 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-17 16:27:47 1435648 ------w- c:\windows\system32\query.dll
2009-07-13 14:08:14 286720 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-25 08:44:41 724480 ------w- c:\windows\system32\lsasrv.dll
2009-06-25 08:44:41 59392 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:44:41 56320 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:44:41 298496 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:44:41 168448 ----a-w- c:\windows\system32\schannel.dll
2009-06-22 11:34:52 92544 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-12 11:50:53 76288 ------w- c:\windows\system32\telnet.exe
2009-06-10 06:32:40 132096 ------w- c:\windows\system32\wkssvc.dll
2009-06-05 07:42:37 655872 ------w- c:\windows\system32\mstscax.dll
2009-05-07 15:44:00 344064 ------w- c:\windows\system32\localspl.dll
2009-04-15 15:11:19 584192 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-10 05:01:38 413032 ----a-w- c:\windows\system32\wmspdmod.dll
2009-03-08 09:35:10 385024 ----a-w- c:\windows\system32\html.iec
2009-03-08 09:34:30 43008 ----a-w- c:\windows\system32\licmgr10.dll
2009-03-08 09:33:40 18944 ----a-w- c:\windows\system32\corpol.dll
2009-03-08 09:32:56 72704 ----a-w- c:\windows\system32\admparse.dll
2009-03-08 09:32:50 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-03-08 09:31:38 34816 ----a-w- c:\windows\system32\imgutil.dll
2009-03-08 09:31:18 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-03-08 09:31:02 45568 ----a-w- c:\windows\system32\mshta.exe
2009-03-08 09:31:02 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2009-03-08 09:30:56 66560 ----a-w- c:\windows\system32\tdc.ocx
2009-03-08 09:22:38 156160 ----a-w- c:\windows\system32\msls31.dll
2009-03-06 14:44:35 283648 ------w- c:\windows\system32\pdh.dll
2009-02-09 10:20:34 399360 ----a-w- c:\windows\system32\rpcss.dll
2009-02-09 10:20:33 714752 ------w- c:\windows\system32\ntdll.dll
2009-02-09 10:20:33 616960 ------w- c:\windows\system32\advapi32.dll
2009-02-09 10:20:33 473088 ----a-w- c:\windows\system32\wbem\fastprox.dll
2009-02-09 10:20:32 453120 ----a-w- c:\windows\system32\wbem\wmiprvsd.dll
2009-02-06 17:14:03 110592 ------w- c:\windows\system32\services.exe
2009-02-06 16:54:36 35328 ------w- c:\windows\system32\sc.exe
2009-02-06 16:39:29 227840 ----a-w- c:\windows\system32\wbem\wmiprvse.exe
2008-10-23 13:01:36 283648 ----a-w- c:\windows\system32\gdi32.dll
2008-08-14 09:51:43 138368 ----a-w- c:\windows\system32\drivers\afd.sys
2008-07-07 20:32:22 253952 ----a-w- c:\windows\system32\es.dll
2008-06-24 16:23:05 74240 ----a-w- c:\windows\system32\mscms.dll
2008-06-20 17:41:10 245248 ----a-w- c:\windows\system32\mswsock.dll
2008-06-20 10:45:13 360320 ----a-w- c:\windows\system32\drivers\tcpip.sys
2008-06-13 13:10:50 272128 ------w- c:\windows\system32\drivers\bthport.sys
2008-06-12 14:16:46 956928 ------w- c:\windows\system32\msdtctm.dll
2008-06-12 14:16:46 91648 ----a-w- c:\windows\system32\mtxoci.dll
2008-06-12 14:16:46 66560 ----a-w- c:\windows\system32\mtxclu.dll
2008-06-12 14:16:46 58880 ------w- c:\windows\system32\msdtclog.dll
2008-06-12 14:16:46 428032 ------w- c:\windows\system32\msdtcprx.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.netWindows 5.1.2600 Disk: WDC_WD400BB-60JKC0 rev.05.01C05 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xF75FEF00]<<
_asm { MOV EAX, [ESP+0x4]; MOV ECX, [EAX+0x28]; PUSH EBP; MOV EBP, [ECX+0x4]; PUSH ESI; MOV ESI, [ESP+0x10]; PUSH EDI; MOV EDI, [ESI+0x60]; MOV AL, [EDI]; CMP AL, 0x16; JNZ 0x36; PUSH ESI; }
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x85BD1478]
3 CLASSPNP[0xF74C805B] -> nt!IofCallDriver[0x804E37D5] -> [0x85A7ABF0]
\Driver\00000719[0x85A7AF38] -> IRP_MJ_CREATE -> 0xF75FEF00
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x85B5C31B
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 16:03:08.56 ===============