ok, i did that and this is the log that was produced:
ComboFix 08-12-14.02 - Owner 2008-12-14 13:12:00.2 - NTFSx86
Microsoft Windows Vista Home Premium 6.0.6001.1.1252.1.1033.18.3070.2007 [GMT -8:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFscript.txt
FILE ::
c:\windows\System32\drivers\msqpdxserv.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\System32\drivers\msqpdxserv.sys
.
((((((((((((((((((((((((( Files Created from 2008-11-14 to 2008-12-14 )))))))))))))))))))))))))))))))
.
2008-12-14 13:09 . 2008-12-14 13:10 d-------- C:\32788R22FWJFW
2008-12-14 13:00 . 2008-12-14 13:10 318,976 --a------ c:\windows\System32\cmd.execf
2008-12-14 07:53 . 2008-12-14 07:53 d-------- c:\program files\Lavasoft
2008-12-14 07:52 . 2008-12-14 07:52 d-------- c:\program files\Common Files\Wise Installation Wizard
2008-12-14 07:08 . 2008-12-14 07:16 d-------- c:\users\All Users\Lavasoft
2008-12-14 07:08 . 2008-12-14 07:16 d-------- c:\programdata\Lavasoft
2008-12-14 06:57 . 2008-12-14 06:57 2,560 --a------ c:\windows\System32\drivers\mchInjDrv.sys
2008-12-14 06:31 . 2008-12-14 06:59 d-a------ c:\users\All Users\TEMP
2008-12-14 06:31 . 2008-12-14 06:59 d-a------ c:\programdata\TEMP
2008-12-11 09:32 . 2008-12-11 09:32 691 --a------ c:\users\Owner\AppData\Roaming\GetValue.vbs
2008-12-11 09:32 . 2008-12-11 09:32 35 --a------ c:\users\Owner\AppData\Roaming\SetValue.bat
2008-12-11 09:10 . 2008-12-11 09:51 256 --a------ c:\windows\wininit.ini
2008-12-11 08:48 . 2008-12-11 09:10 d-------- c:\users\All Users\Registry Helper
2008-12-11 08:48 . 2008-12-11 09:10 d-------- c:\programdata\Registry Helper
2008-12-08 11:24 . 2008-12-08 11:53 d-------- c:\users\All Users\Spybot - Search & Destroy
2008-12-08 11:24 . 2008-12-08 11:53 d-------- c:\programdata\Spybot - Search & Destroy
2008-12-08 11:24 . 2008-12-08 11:52 d-------- c:\program files\Spybot - Search & Destroy
2008-12-07 13:31 . 2008-12-07 13:31 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-12-06 17:53 . 2008-06-19 17:14 781,344 --a------ c:\windows\System32\PresentationNative_v0300.dll
2008-12-06 17:53 . 2008-06-19 17:14 622,080 --a------ c:\windows\System32\icardagt.exe
2008-12-06 17:53 . 2008-06-19 17:14 105,016 --a------ c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2008-12-06 17:53 . 2008-06-19 17:14 97,800 --a------ c:\windows\System32\infocardapi.dll
2008-12-06 17:53 . 2008-06-19 17:14 43,544 --a------ c:\windows\System32\PresentationHostProxy.dll
2008-12-06 17:53 . 2008-06-19 17:14 37,384 --a------ c:\windows\System32\infocardcpl.cpl
2008-12-06 17:53 . 2008-06-19 17:14 11,264 --a------ c:\windows\System32\icardres.dll
2008-12-06 17:52 . 2008-06-19 17:14 326,160 --a------ c:\windows\System32\PresentationHost.exe
2008-12-06 17:09 . 2008-12-06 17:09 d-------- C:\PerfLogs
2008-12-06 14:57 . 2008-07-27 10:00 282,112 --a------ c:\windows\System32\mscoree.dll
2008-12-06 14:57 . 2008-07-27 10:00 158,720 --a------ c:\windows\System32\mscorier.dll
2008-12-06 14:57 . 2008-07-27 10:00 96,760 --a------ c:\windows\System32\dfshim.dll
2008-12-06 14:57 . 2008-07-27 10:00 41,984 --a------ c:\windows\System32\netfxperf.dll
2008-12-06 14:56 . 2008-07-27 10:00 83,968 --a------ c:\windows\System32\mscories.dll
2008-11-30 11:23 . 2008-11-30 11:27 d-------- c:\program files\Driving Test Success ROAD SIGNS
2008-11-28 23:44 . 2008-11-28 23:44 dr------- c:\users\Owner\Pictures
2008-11-27 17:38 . 2008-10-16 13:13 1,809,944 --a------ c:\windows\System32\wuaueng.dll
2008-11-27 17:38 . 2008-10-16 12:56 1,524,736 --a------ c:\windows\System32\wucltux.dll
2008-11-27 17:38 . 2008-10-16 13:09 51,224 --a------ c:\windows\System32\wuauclt.exe
2008-11-27 17:38 . 2008-10-16 13:09 43,544 --a------ c:\windows\System32\wups2.dll
2008-11-27 17:37 . 2008-10-16 13:12 561,688 --a------ c:\windows\System32\wuapi.dll
2008-11-27 17:37 . 2008-10-16 14:08 162,064 --a------ c:\windows\System32\wuwebv.dll
2008-11-27 17:37 . 2008-10-16 12:55 83,456 --a------ c:\windows\System32\wudriver.dll
2008-11-27 17:37 . 2008-10-16 13:08 34,328 --a------ c:\windows\System32\wups.dll
2008-11-27 17:37 . 2008-10-16 13:56 31,232 --a------ c:\windows\System32\wuapp.exe
2008-11-26 15:39 . 2008-11-26 15:40 d-------- c:\program files\Hamachi
2008-11-26 15:39 . 2008-11-26 15:39 25,280 --a------ c:\windows\System32\drivers\hamachi.sys
2008-11-26 13:50 . 2008-10-20 21:25 1,645,568 --a------ c:\windows\System32\connect.dll
2008-11-26 13:50 . 2008-08-27 19:40 712,704 --a------ c:\windows\System32\WindowsCodecs.dll
2008-11-26 13:50 . 2008-08-27 19:40 425,472 --a------ c:\windows\System32\PhotoMetadataHandler.dll
2008-11-26 13:50 . 2008-08-27 19:40 347,136 --a------ c:\windows\System32\WindowsCodecsExt.dll
2008-11-26 13:50 . 2008-10-21 19:57 241,152 --a------ c:\windows\System32\PortableDeviceApi.dll
2008-11-26 13:50 . 2008-01-18 23:36 160,768 --a------ c:\windows\System32\PortableDeviceTypes.dll
2008-11-26 13:50 . 2008-01-18 23:36 94,720 --a------ c:\windows\System32\PortableDeviceClassExtension.dll
2008-11-18 12:19 . 2008-11-18 12:19 d--h----- c:\windows\PIF
2008-11-18 10:40 . 2008-11-18 10:40 d-------- c:\users\All Users\Sports Interactive
2008-11-18 10:40 . 2008-11-18 10:40 d-------- c:\programdata\Sports Interactive
2008-11-18 10:33 . 2005-05-26 15:34 2,297,552 --a------ c:\windows\System32\d3dx9_26.dll
2008-11-18 10:29 . 2008-11-18 10:29 d-------- c:\program files\Sports Interactive
2008-11-18 10:05 . 2008-11-18 10:26 d-------- c:\program files\Common Files\Steam
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-13 11:45 --------- d-----w c:\users\Owner\AppData\Roaming\Azureus
2008-12-12 01:06 2,828 --sha-w c:\users\All Users\KGyGaAvL.sys
2008-12-12 01:06 2,828 --sha-w c:\programdata\KGyGaAvL.sys
2008-12-11 18:07 --------- d-----w c:\programdata\Microsoft Help
2008-12-11 16:49 --------- d-----w c:\program files\Bonjour
2008-12-09 17:11 --------- d-----w c:\program files\Windows Mail
2008-12-07 01:20 174 --sha-w c:\program files\desktop.ini
2008-12-07 01:11 --------- d-----w c:\program files\Windows Sidebar
2008-12-07 01:11 --------- d-----w c:\program files\Windows Photo Gallery
2008-12-07 01:11 --------- d-----w c:\program files\Windows Journal
2008-12-07 01:11 --------- d-----w c:\program files\Windows Defender
2008-12-07 01:11 --------- d-----w c:\program files\Windows Collaboration
2008-12-07 01:11 --------- d-----w c:\program files\Windows Calendar
2008-11-30 19:23 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-29 18:22 --------- d-----w c:\programdata\Symantec
2008-11-28 01:24 --------- d-----w c:\users\Owner\AppData\Roaming\Hamachi
2008-11-27 06:27 --------- d-----w c:\programdata\InterVideo
2008-11-18 18:43 --------- d-----w c:\users\Owner\AppData\Roaming\Sports Interactive
2008-11-05 01:43 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-05 00:48 --------- d-----w c:\program files\Norton 360
2008-10-27 05:20 --------- d-----w c:\program files\Azureus
2008-10-19 16:30 --------- d-----w c:\program files\Apple Software Update
2008-10-19 16:29 --------- d-----w c:\program files\iTunes
2008-10-19 16:29 --------- d-----w c:\program files\iPod
2008-10-19 16:27 --------- d-----w c:\programdata\Apple Computer
2008-10-19 16:27 --------- d-----w c:\program files\QuickTime
2008-10-19 16:27 --------- d-----w c:\program files\Common Files\Apple
2008-10-17 21:00 --------- d-----w c:\users\Owner\AppData\Roaming\TSO
2008-08-28 19:29 88 --sh--r c:\users\All Users\5CD5D7E829.sys
2008-08-28 19:29 88 --sh--r c:\programdata\5CD5D7E829.sys
.
((((((((((((((((((((((((((((( snapshot@2008-12-14_12.41.29.09 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-14 20:17:19 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-12-14 21:08:27 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-12-14 20:17:19 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-12-14 21:08:27 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-12-14 20:38:59 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-12-14 21:10:30 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-12-14 21:10:30 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-12-14 20:38:36 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-12-14 21:10:25 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-12-14 21:10:25 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-12-14 19:09:59 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-12-14 21:10:26 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-12-14 19:09:59 49,152 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-14 21:10:26 49,152 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-14 19:09:59 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-12-14 21:10:26 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-12-14 20:24:37 105,852 ----a-w c:\windows\System32\perfc009.dat
+ 2008-12-14 21:16:38 105,852 ----a-w c:\windows\System32\perfc009.dat
- 2008-12-14 20:24:37 600,378 ----a-w c:\windows\System32\perfh009.dat
+ 2008-12-14 21:16:38 600,378 ----a-w c:\windows\System32\perfh009.dat
- 2008-12-14 20:19:32 9,998 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2542765397-551537198-1868045467-1000_UserData.bin
+ 2008-12-14 21:10:55 10,022 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2542765397-551537198-1868045467-1000_UserData.bin
- 2008-12-14 20:19:31 71,856 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-12-14 21:10:55 71,872 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
ComboFix 08-12-14.02 - Owner 2008-12-14 13:12:00.2 - NTFSx86
Microsoft Windows Vista Home Premium 6.0.6001.1.1252.1.1033.18.3070.2007 [GMT -8:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFscript.txt
FILE ::
c:\windows\System32\drivers\msqpdxserv.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\System32\drivers\msqpdxserv.sys
.
((((((((((((((((((((((((( Files Created from 2008-11-14 to 2008-12-14 )))))))))))))))))))))))))))))))
.
2008-12-14 13:09 . 2008-12-14 13:10
2008-12-14 13:00 . 2008-12-14 13:10 318,976 --a------ c:\windows\System32\cmd.execf
2008-12-14 07:53 . 2008-12-14 07:53
2008-12-14 07:52 . 2008-12-14 07:52
2008-12-14 07:08 . 2008-12-14 07:16
2008-12-14 07:08 . 2008-12-14 07:16
2008-12-14 06:57 . 2008-12-14 06:57 2,560 --a------ c:\windows\System32\drivers\mchInjDrv.sys
2008-12-14 06:31 . 2008-12-14 06:59
2008-12-14 06:31 . 2008-12-14 06:59
2008-12-11 09:32 . 2008-12-11 09:32 691 --a------ c:\users\Owner\AppData\Roaming\GetValue.vbs
2008-12-11 09:32 . 2008-12-11 09:32 35 --a------ c:\users\Owner\AppData\Roaming\SetValue.bat
2008-12-11 09:10 . 2008-12-11 09:51 256 --a------ c:\windows\wininit.ini
2008-12-11 08:48 . 2008-12-11 09:10
2008-12-11 08:48 . 2008-12-11 09:10
2008-12-08 11:24 . 2008-12-08 11:53
2008-12-08 11:24 . 2008-12-08 11:53
2008-12-08 11:24 . 2008-12-08 11:52
2008-12-07 13:31 . 2008-12-07 13:31 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-12-06 17:53 . 2008-06-19 17:14 781,344 --a------ c:\windows\System32\PresentationNative_v0300.dll
2008-12-06 17:53 . 2008-06-19 17:14 622,080 --a------ c:\windows\System32\icardagt.exe
2008-12-06 17:53 . 2008-06-19 17:14 105,016 --a------ c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2008-12-06 17:53 . 2008-06-19 17:14 97,800 --a------ c:\windows\System32\infocardapi.dll
2008-12-06 17:53 . 2008-06-19 17:14 43,544 --a------ c:\windows\System32\PresentationHostProxy.dll
2008-12-06 17:53 . 2008-06-19 17:14 37,384 --a------ c:\windows\System32\infocardcpl.cpl
2008-12-06 17:53 . 2008-06-19 17:14 11,264 --a------ c:\windows\System32\icardres.dll
2008-12-06 17:52 . 2008-06-19 17:14 326,160 --a------ c:\windows\System32\PresentationHost.exe
2008-12-06 17:09 . 2008-12-06 17:09
2008-12-06 14:57 . 2008-07-27 10:00 282,112 --a------ c:\windows\System32\mscoree.dll
2008-12-06 14:57 . 2008-07-27 10:00 158,720 --a------ c:\windows\System32\mscorier.dll
2008-12-06 14:57 . 2008-07-27 10:00 96,760 --a------ c:\windows\System32\dfshim.dll
2008-12-06 14:57 . 2008-07-27 10:00 41,984 --a------ c:\windows\System32\netfxperf.dll
2008-12-06 14:56 . 2008-07-27 10:00 83,968 --a------ c:\windows\System32\mscories.dll
2008-11-30 11:23 . 2008-11-30 11:27
2008-11-28 23:44 . 2008-11-28 23:44
2008-11-27 17:38 . 2008-10-16 13:13 1,809,944 --a------ c:\windows\System32\wuaueng.dll
2008-11-27 17:38 . 2008-10-16 12:56 1,524,736 --a------ c:\windows\System32\wucltux.dll
2008-11-27 17:38 . 2008-10-16 13:09 51,224 --a------ c:\windows\System32\wuauclt.exe
2008-11-27 17:38 . 2008-10-16 13:09 43,544 --a------ c:\windows\System32\wups2.dll
2008-11-27 17:37 . 2008-10-16 13:12 561,688 --a------ c:\windows\System32\wuapi.dll
2008-11-27 17:37 . 2008-10-16 14:08 162,064 --a------ c:\windows\System32\wuwebv.dll
2008-11-27 17:37 . 2008-10-16 12:55 83,456 --a------ c:\windows\System32\wudriver.dll
2008-11-27 17:37 . 2008-10-16 13:08 34,328 --a------ c:\windows\System32\wups.dll
2008-11-27 17:37 . 2008-10-16 13:56 31,232 --a------ c:\windows\System32\wuapp.exe
2008-11-26 15:39 . 2008-11-26 15:40
2008-11-26 15:39 . 2008-11-26 15:39 25,280 --a------ c:\windows\System32\drivers\hamachi.sys
2008-11-26 13:50 . 2008-10-20 21:25 1,645,568 --a------ c:\windows\System32\connect.dll
2008-11-26 13:50 . 2008-08-27 19:40 712,704 --a------ c:\windows\System32\WindowsCodecs.dll
2008-11-26 13:50 . 2008-08-27 19:40 425,472 --a------ c:\windows\System32\PhotoMetadataHandler.dll
2008-11-26 13:50 . 2008-08-27 19:40 347,136 --a------ c:\windows\System32\WindowsCodecsExt.dll
2008-11-26 13:50 . 2008-10-21 19:57 241,152 --a------ c:\windows\System32\PortableDeviceApi.dll
2008-11-26 13:50 . 2008-01-18 23:36 160,768 --a------ c:\windows\System32\PortableDeviceTypes.dll
2008-11-26 13:50 . 2008-01-18 23:36 94,720 --a------ c:\windows\System32\PortableDeviceClassExtension.dll
2008-11-18 12:19 . 2008-11-18 12:19
2008-11-18 10:40 . 2008-11-18 10:40
2008-11-18 10:40 . 2008-11-18 10:40
2008-11-18 10:33 . 2005-05-26 15:34 2,297,552 --a------ c:\windows\System32\d3dx9_26.dll
2008-11-18 10:29 . 2008-11-18 10:29
2008-11-18 10:05 . 2008-11-18 10:26
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-13 11:45 --------- d-----w c:\users\Owner\AppData\Roaming\Azureus
2008-12-12 01:06 2,828 --sha-w c:\users\All Users\KGyGaAvL.sys
2008-12-12 01:06 2,828 --sha-w c:\programdata\KGyGaAvL.sys
2008-12-11 18:07 --------- d-----w c:\programdata\Microsoft Help
2008-12-11 16:49 --------- d-----w c:\program files\Bonjour
2008-12-09 17:11 --------- d-----w c:\program files\Windows Mail
2008-12-07 01:20 174 --sha-w c:\program files\desktop.ini
2008-12-07 01:11 --------- d-----w c:\program files\Windows Sidebar
2008-12-07 01:11 --------- d-----w c:\program files\Windows Photo Gallery
2008-12-07 01:11 --------- d-----w c:\program files\Windows Journal
2008-12-07 01:11 --------- d-----w c:\program files\Windows Defender
2008-12-07 01:11 --------- d-----w c:\program files\Windows Collaboration
2008-12-07 01:11 --------- d-----w c:\program files\Windows Calendar
2008-11-30 19:23 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-29 18:22 --------- d-----w c:\programdata\Symantec
2008-11-28 01:24 --------- d-----w c:\users\Owner\AppData\Roaming\Hamachi
2008-11-27 06:27 --------- d-----w c:\programdata\InterVideo
2008-11-18 18:43 --------- d-----w c:\users\Owner\AppData\Roaming\Sports Interactive
2008-11-05 01:43 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-05 00:48 --------- d-----w c:\program files\Norton 360
2008-10-27 05:20 --------- d-----w c:\program files\Azureus
2008-10-19 16:30 --------- d-----w c:\program files\Apple Software Update
2008-10-19 16:29 --------- d-----w c:\program files\iTunes
2008-10-19 16:29 --------- d-----w c:\program files\iPod
2008-10-19 16:27 --------- d-----w c:\programdata\Apple Computer
2008-10-19 16:27 --------- d-----w c:\program files\QuickTime
2008-10-19 16:27 --------- d-----w c:\program files\Common Files\Apple
2008-10-17 21:00 --------- d-----w c:\users\Owner\AppData\Roaming\TSO
2008-08-28 19:29 88 --sh--r c:\users\All Users\5CD5D7E829.sys
2008-08-28 19:29 88 --sh--r c:\programdata\5CD5D7E829.sys
.
((((((((((((((((((((((((((((( snapshot@2008-12-14_12.41.29.09 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-14 20:17:19 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-12-14 21:08:27 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-12-14 20:17:19 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-12-14 21:08:27 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-12-14 20:38:59 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-12-14 21:10:30 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-12-14 21:10:30 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-12-14 20:38:36 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-12-14 21:10:25 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-12-14 21:10:25 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-12-14 19:09:59 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-12-14 21:10:26 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-12-14 19:09:59 49,152 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-14 21:10:26 49,152 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-14 19:09:59 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-12-14 21:10:26 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-12-14 20:24:37 105,852 ----a-w c:\windows\System32\perfc009.dat
+ 2008-12-14 21:16:38 105,852 ----a-w c:\windows\System32\perfc009.dat
- 2008-12-14 20:24:37 600,378 ----a-w c:\windows\System32\perfh009.dat
+ 2008-12-14 21:16:38 600,378 ----a-w c:\windows\System32\perfh009.dat
- 2008-12-14 20:19:32 9,998 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2542765397-551537198-1868045467-1000_UserData.bin
+ 2008-12-14 21:10:55 10,022 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2542765397-551537198-1868045467-1000_UserData.bin
- 2008-12-14 20:19:31 71,856 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-12-14 21:10:55 71,872 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin