This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Fake Anitvirus spyware and pop-ups

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Anti-Virus Agent Pro Fake anti-virus remover

Also SpywareRemover 2009 pop-ups

Hijackthis Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:53:55 PM, on 4/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\eTSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\brastia.exe
C:\WINDOWS\system32\mrtMngr.EXE
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\prunnet.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\mshta.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\BASHIR\Application Data\Mozilla\Profiles\default\4hnv1dyt.slt\prefs.js)
O1 - Hosts: 82.98.231.89 browser-security.microsoft.com
O1 - Hosts: 82.98.231.89 best-click-scanner.info
O1 - Hosts: 82.98.231.89 antivirus-xp-pro-2009.com
O1 - Hosts: 82.98.231.89 microsoft.infosecuritycenter.com
O1 - Hosts: 82.98.231.89 microsoft.softwaresecurityhelp.com
O1 - Hosts: 82.98.231.89 onlinenotifyq.net
O1 - Hosts: 82.98.231.89 antivirusxp-pro-2009.com
O1 - Hosts: 82.98.231.89 microsoft.browser-security-center.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {258d60ec-df03-40c0-aa1d-dcc7b07b8051} - C:\WINDOWS\system32\hegizuku.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [eFax 4.2] "C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [eTCertManger] C:\WINDOWS\system32\eTCrtMng.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [brastia] C:\WINDOWS\system32\brastia.exe
O4 - HKLM\..\Run: [Antivirus Agent Pro] C:\Program Files\Antivirus Agent Pro\aap.exe
O4 - HKLM\..\Run: [gepufurajo] Rundll32.exe "C:\WINDOWS\system32\renibupu.dll",s
O4 - HKLM\..\Run: [prunnet] "C:\WINDOWS\system32\prunnet.exe"
O4 - HKLM\..\Run: [Gzicogufagelew] rundll32.exe "C:\WINDOWS\Btisuwimuwe.dll",e
O4 - HKLM\..\Run: [4054f450] rundll32.exe "C:\WINDOWS\system32\wekateme.dll",b
O4 - HKLM\..\Run: [CPM4367c7cc] Rundll32.exe "C:\WINDOWS\system32\gidobedi.dll",a
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [PicoZip] C:\Program Files\PicoZip\PicoZipTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [prunnet] "C:\WINDOWS\system32\prunnet.exe"
O4 - Global Startup: eFax 4.2.lnk = C:\Program Files\eFax Messenger 4.2\J2GTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google AdSense Preview Tool - http://pagead2.googlesyndication.com/pagea…en/preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Webpage Capture - {1F958B09-6612-7a0e-9223-4C7324C57B23} - C:\Program Files\Webpage Capture\Webpage Capture.exe (file missing)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll/206 (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {28E52D43-46EB-439B-8334-DA8D9C63D5B7} (ENCMAX Control) - http://junaidbashir.isanexpert.com/system/ENCMAX.cab
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://vcuhsra.mcvh-vcu.edu/vdesk/terminal…,2008,1015,1912
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/24.9/uploader2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6C275925-A1ED-4DD2-9CEE-9823F5FDAA10} (F5 Networks SSLTunnel) - https://vcuhsra.mcvh-vcu.edu/vdesk/terminal…,2008,1015,1902
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} (F5 Networks SuperHost Class) - https://vcuhsra.mcvh-vcu.edu/vdesk/terminal…,2008,1015,1907
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://vcuhsra.mcvh-vcu.edu/f5-w-687474703…#036;/dwa7W.cab
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} (F5 Networks Host Control) - https://vcuhsra.mcvh-vcu.edu/vdesk/terminal…,2008,1015,1906
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.62/code/iPIX-ImageWell-ipix.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\rofefuzi.dll c:\windows\system32\gidobedi.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\gidobedi.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\gidobedi.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: eToken Notification Service (ETOKSRV) - Aladdin Knowledge Systems, Ltd. - C:\WINDOWS\system32\eTSrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 14419 bytes
Hello stech

Welcome to the Whatthetech Malware Removal Forum,

All advice given by anyone volunteering here, is taken at your own risk.
While best efforts are made to assist in removing infections safely, unexpected stuff can happen.



Download the HostsXpert 4.2.0.0. - Hosts File Manager.
  • Unzip HostsXpert 4.2.0.0 - Hosts File Manager to a convenient folder such as C:\HostsXpert
  • Click HostsXpert.exe to Run HostsXpert - Hosts File Manager from its new home
  • Click "Make Hosts Writable?" in the upper right corner (If available).
  • Click Restore Microsoft's Hosts file and then click OK.
  • Click the X to exit the program.
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.








Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Everything is the same. Still getting pop-ups. I still have the Antivirus Agent Pro program (virus software) installed on my computer

Hijackthis Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:29, on 2009-04-11
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\eTSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\brastia.exe
C:\WINDOWS\system32\mrtMngr.EXE
C:\WINDOWS\system32\config\systemprofile\Application Data\psvrr.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Bashir\Application Data\psvr32.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Documents and Settings\Bashir\Application Data\pidle\pidle.exe
C:\Documents and Settings\Bashir\Application Data\digifast\digifast.exe
C:\Documents and Settings\Bashir\Application Data\Microsoft\Windows\lqitbde.exe
C:\Program Files\eFax Messenger 4.2\J2GTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\BASHIR\Application Data\Mozilla\Profiles\default\4hnv1dyt.slt\prefs.js)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: CPV - {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - C:\Program Files\WWShow\WWShow.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: HelloWorldBHO - {D88E1558-7C2D-407A-953A-C044F5607CEA} - C:\Program Files\Jcore\Jcore2.dll
O2 - BHO: Microsoft Video Converter - {ED23079B-A24E-4126-A086-8D2B18B20E36} - %SystemRoot%\system32\wtl32locale.dll (file missing)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [eFax 4.2] "C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [eTCertManger] C:\WINDOWS\system32\eTCrtMng.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [brastia] C:\WINDOWS\system32\brastia.exe
O4 - HKLM\..\Run: [Java Load] C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\websvr.exe
O4 - HKLM\..\Run: [WinProx32_1] C:\WINDOWS\system32\config\systemprofile\Application Data\psvrr.exe
O4 - HKLM\..\Run: [ftn2ksv] C:\WINDOWS\system32\ftn2ksv.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [PicoZip] C:\Program Files\PicoZip\PicoZipTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [pidle] "C:\Documents and Settings\Bashir\Application Data\pidle\pidle.exe" 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139
O4 - HKCU\..\Run: [DigiFast] C:\Documents and Settings\Bashir\Application Data\digifast\digifast.exe
O4 - HKCU\..\Run: [SfKg6wIPuSpdc] C:\Documents and Settings\Bashir\Application Data\Microsoft\Windows\lqitbde.exe
O4 - HKCU\..\Run: [WinProx32_1] C:\WINDOWS\system32\config\systemprofile\Application Data\psvrr.exe
O4 - HKUS\S-1-5-18\..\Run: [nDler2] \\?\globalroot\systemroot\system32\nDler2.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [WinProx32_1] C:\WINDOWS\system32\config\systemprofile\Application Data\psvrr.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [nDler2] \\?\globalroot\systemroot\system32\nDler2.exe (User 'Default user')
O4 - Global Startup: eFax 4.2.lnk = C:\Program Files\eFax Messenger 4.2\J2GTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google AdSense Preview Tool - http://pagead2.googlesyndication.com/pagea…en/preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Webpage Capture - {1F958B09-6612-7a0e-9223-4C7324C57B23} - C:\Program Files\Webpage Capture\Webpage Capture.exe (file missing)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll/206 (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {28E52D43-46EB-439B-8334-DA8D9C63D5B7} (ENCMAX Control) - http://junaidbashir.isanexpert.com/system/ENCMAX.cab
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://vcuhsra.mcvh-vcu.edu/vdesk/terminal…,2008,1015,1912
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/24.9/uploader2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6C275925-A1ED-4DD2-9CEE-9823F5FDAA10} (F5 Networks SSLTunnel) - https://vcuhsra.mcvh-vcu.edu/vdesk/terminal…,2008,1015,1902
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} (F5 Networks SuperHost Class) - https://vcuhsra.mcvh-vcu.edu/vdesk/terminal…,2008,1015,1907
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://vcuhsra.mcvh-vcu.edu/f5-w-687474703…#036;/dwa7W.cab
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} (F5 Networks Host Control) - https://vcuhsra.mcvh-vcu.edu/vdesk/terminal…,2008,1015,1906
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.62/code/iPIX-ImageWell-ipix.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: eToken Notification Service (ETOKSRV) - Aladdin Knowledge Systems, Ltd. - C:\WINDOWS\system32\eTSrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 14899 bytes

Combo Fix Log

ComboFix 09-04-04.01 - Bashir 2009-04-11 8:22:05.8 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.196 [GMT -4:00]
Running from: C:\Downloads\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Bashir\Application Data\twain\Twain.exe
C:\Documents and Settings\Bashir\Application Data\wiaserva.log
C:\Documents and Settings\Bashir\Local Settings\Temporary Internet Files\bestwiner.stt
C:\Documents and Settings\Bashir\Local Settings\Temporary Internet Files\CPV.stt
C:\Documents and Settings\Bashir\Local Settings\Temporary Internet Files\fbk.sts
C:\WINDOWS\patch.exe
C:\WINDOWS\system32\drivers\seneka.sys
C:\WINDOWS\system32\drivers\senekankarjwba.sys
C:\WINDOWS\system32\lowsec
C:\WINDOWS\system32\lowsec\local.ds
C:\WINDOWS\system32\lowsec\user.ds
C:\WINDOWS\system32\sdra64.exe
C:\WINDOWS\system32\senekaejemaqoy.dll
C:\WINDOWS\system32\senekaftqmxgwy.dll
C:\WINDOWS\system32\senekakyjlqjea.dat
C:\WINDOWS\system32\senekanfvumene.dll
C:\WINDOWS\system32\senekaxilwtjnp.dat
C:\WINDOWS\system32\sys.dat
C:\WINDOWS\system32\wbem\grpconv.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SENEKA


((((((((((((((((((((((((( Files Created from 2009-03-11 to 2009-04-11 )))))))))))))))))))))))))))))))
.

2009-04-11 07:03 . 2009-04-11 07:03 13,824 –a—— C:\WINDOWS\system32\ftn2ksv.exe
2009-04-11 07:03 . 2009-04-11 07:03 4,224 –a—— C:\WINDOWS\system32\drivers\ftnet2k.sys
2009-04-10 23:19 . 2009-04-10 23:30 d——– C:\Documents and Settings\Bashir\Application Data\digifast
2009-04-10 23:09 . 2009-04-10 23:09 d——– C:\Program Files\WWShow
2009-04-10 23:04 . 2009-04-10 23:04 d——– C:\Program Files\Jcore
2009-04-10 22:20 . 2009-04-10 23:10 465,874 –a—— C:\WINDOWS\system32\config\systemprofile\Application Data\psvrr.exe
2009-04-10 14:10 . 2009-04-10 14:10 20,480 –a—— C:\WINDOWS\system32\nDler2.exe
2009-04-09 23:00 . 2009-04-10 08:46 408 –a—— C:\WINDOWS\Onudevax.dat
2009-04-09 23:00 . 2009-04-10 00:45 0 –a—— C:\WINDOWS\Rliwecaz.bin
2009-04-09 22:58 . 2009-04-09 22:58 d——– C:\Documents and Settings\Bashir\Application Data\pidle
2009-04-09 22:58 . 2009-04-09 22:58 84,045 –a—— C:\WINDOWS\system32\ftp_non_crp.exe
2009-04-09 22:58 . 2009-04-09 22:58 155 –a—— C:\WINDOWS\system32\SelfDel.bat
2009-04-09 21:38 . 2009-04-10 19:22 d——– C:\Program Files\Antivirus Agent Pro
2009-04-09 19:18 . 2009-04-09 19:18 3,437 –a—— C:\WINDOWS\2bbc.n4f
2009-04-09 19:15 . 2009-04-09 19:15 20,480 –a—— C:\WINDOWS\system32\winarps32.exe
2009-04-09 18:46 . 2009-04-09 18:46 988,672 –a—— C:\WINDOWS\system32\nsysk.ini
2009-04-09 18:46 . 2007-04-16 11:52 984,576 –a—— C:\WINDOWS\system32\osysk.dat
2009-04-09 18:46 . 2009-04-09 18:46 830,464 –a—— C:\WINDOWS\system32\nsysw.ini
2009-04-09 18:46 . 2008-12-20 19:15 826,368 –a—— C:\WINDOWS\system32\osysw.dat
2009-04-09 18:46 . 2009-04-09 18:46 87,040 –a—— C:\WINDOWS\system32\azton.mt
2009-04-09 18:46 . 2009-04-09 18:46 28,880 –a—— C:\WINDOWS\system32\ldshyf1.old
2009-04-09 18:46 . 2009-04-09 18:46 21,504 –a—— C:\WINDOWS\system32\nsysp.ini
2009-04-09 18:46 . 2009-04-09 18:46 19,079 –a—— C:\WINDOWS\system32\wincode.dat
2009-04-09 18:46 . 2004-08-04 01:56 17,408 –a—— C:\WINDOWS\system32\osysp.dat
2009-04-09 18:46 . 2009-04-09 18:46 9,728 –a—— C:\WINDOWS\system32\brastia.exe
2009-04-09 18:46 . 2009-04-09 18:46 6,407 –a—— C:\WINDOWS\system32\krncode.dat
2009-04-09 18:46 . 2009-04-09 18:46 1,575 –a—— C:\WINDOWS\system32\pwrcode.dat
2009-04-09 14:26 . 2009-04-09 14:26 d——– C:\Command & Conquer Generals
2009-04-09 13:31 . 2009-04-09 13:31 d——– C:\Program Files\Common Files\EasyInfo
2009-04-09 11:59 . 2009-04-09 13:17 d——– C:\Program Files\Panzer Claws II
2009-04-09 11:25 . 2009-04-09 11:25 98,304 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2009-04-09 09:41 . 2009-04-09 09:41 d——– C:\Medal Of Honar ALLIED Assults
2009-04-09 09:26 . 2007-05-31 19:30 266,088 –a—— C:\WINDOWS\system32\xactengine2_8.dll
2009-04-09 09:26 . 2007-05-31 19:29 18,280 –a—— C:\WINDOWS\system32\x3daudio1_2.dll
2009-04-09 09:24 . 2009-04-09 09:24 324 –a—— C:\WINDOWS\game.ini
2009-03-19 11:55 . 2009-03-19 11:55 d——– C:\Documents and Settings\Bashir\Application Data\webex
2009-03-19 01:32 . 2009-03-19 00:41 229,376 –a—— C:\WINDOWS\system32\config\systemprofile\Application Data\psvr32.exe
2009-03-15 18:22 . 2009-03-15 18:22 d——– C:\Documents and Settings\Bashir\Application Data\Common Files
2009-03-15 13:52 . 2006-10-26 19:56 32,592 –a—— C:\WINDOWS\system32\msonpmon.dll
2009-03-15 13:46 . 2009-03-15 13:46 d——– C:\Program Files\MSBuild
2009-03-15 13:43 . 2009-03-15 13:43 d——– C:\Program Files\Microsoft.NET
2009-03-15 13:33 . 2009-03-15 13:33 d——– C:\Program Files\Microsoft Visual Studio 8
2009-03-15 13:30 . 2009-03-15 13:30 dr-h—– C:\MSOCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-11 12:25 ——— d—–w C:\Documents and Settings\Bashir\Application Data\Twain
2009-04-11 12:17 ——— d—–w C:\Program Files\BitComet
2009-04-11 11:02 ——— d—–w C:\Program Files\7-Zip
2009-04-10 18:23 ——— d—–w C:\Documents and Settings\Bashir\Application Data\gtk-2.0
2009-04-10 10:41 ——— d—–w C:\Program Files\QuickTime
2009-04-10 10:41 ——— d—–w C:\Program Files\MSN Messenger
2009-04-10 10:41 ——— d—–w C:\Program Files\iTunes
2009-04-10 10:41 ——— d—–w C:\Program Files\FreeFTP
2009-04-09 23:18 ——— d—–w C:\Program Files\REFN
2009-04-09 23:18 ——— d—–w C:\Program Files\FileZilla
2009-04-09 23:18 ——— d—–w C:\Program Files\eRightSoft
2009-04-09 23:18 ——— d—–w C:\Program Files\Elcomsoft
2009-04-09 21:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2009-04-06 14:02 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-03-15 17:47 ——— d—–w C:\Program Files\Microsoft Works
2009-03-12 23:53 ——— d—–w C:\Program Files\Macromedia
2009-03-12 23:50 ——— d—–w C:\Program Files\Common Files\Macromedia
2009-03-12 23:43 ——— d—–w C:\Program Files\Common Files\Research In Motion
2009-03-12 23:20 ——— d—–w C:\Program Files\Google
2009-03-05 13:33 ——— d—–w C:\Program Files\QUICKENW
2009-03-02 17:06 ——— d—–w C:\Program Files\Citrix
2009-02-25 20:39 ——— d—–w C:\Program Files\MSECache
2008-09-09 22:04 56,912 —-a-w C:\Documents and Settings\Bashir\g2mdlhlpx.exe
2007-09-03 04:12 6,274,206 —-a-w C:\Program Files\BitTorrent-5.0.8.exe
2007-01-08 22:24 21,822,168 —-a-w C:\Program Files\AdbeRdr80_en_US.exe
2007-01-08 22:13 7,050,552 —-a-w C:\Program Files\psa30se_en_us.exe
2005-08-08 21:01 2,323 —-a-w C:\Program Files\MSN Messenger 6.2.lnk
2005-02-17 02:21 26,262,528 —-a-w C:\Program Files\NortonVirus.exe
2005-02-16 02:17 1,867 —-a-w C:\Program Files\Norton AntiVirus 2002.lnk
2009-03-19 15:54 27,976 —-a-w C:\Program Files\mozilla firefox\plugins\atgpcdec.dll
2009-03-19 15:54 125,848 —-a-w C:\Program Files\mozilla firefox\plugins\atgpcext.dll
2009-03-19 15:54 46,408 —-a-w C:\Program Files\mozilla firefox\plugins\atmccli.dll
2009-03-19 15:55 98,712 —-a-w C:\Program Files\mozilla firefox\plugins\ieatgpc.dll
2009-04-11 03:20 73,728 —-a-w C:\Program Files\mozilla firefox\components\dfff.dll
2009-03-05 01:30 67,688 —-a-w C:\Program Files\mozilla firefox\components\jar50.dll
2009-03-05 01:30 54,368 —-a-w C:\Program Files\mozilla firefox\components\jsd3250.dll
2009-03-05 01:30 34,944 —-a-w C:\Program Files\mozilla firefox\components\myspell.dll
2009-03-05 01:30 46,712 —-a-w C:\Program Files\mozilla firefox\components\spellchk.dll
2009-03-05 01:30 172,136 —-a-w C:\Program Files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((( snapshot_2009-01-19_11.47.38.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-09 10:20:05 1,847,424 —-a-w C:\WINDOWS\$hf_mig$\KB958690\SP2QFE\win32k.sys
+ 2009-02-09 11:13:27 1,846,784 —-a-w C:\WINDOWS\$hf_mig$\KB958690\SP3GDR\win32k.sys
+ 2009-02-09 11:08:53 1,847,552 —-a-w C:\WINDOWS\$hf_mig$\KB958690\SP3QFE\win32k.sys
+ 2008-07-09 07:38:24 17,272 —-a-w C:\WINDOWS\$hf_mig$\KB958690\spmsg.dll
+ 2008-07-09 07:38:25 231,288 —-a-w C:\WINDOWS\$hf_mig$\KB958690\spuninst.exe
+ 2008-07-09 07:38:24 26,488 —-a-w C:\WINDOWS\$hf_mig$\KB958690\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 —-a-w C:\WINDOWS\$hf_mig$\KB958690\update\update.exe
+ 2008-07-09 07:38:37 382,840 —-a-w C:\WINDOWS\$hf_mig$\KB958690\update\updspapi.dll
+ 2008-12-05 06:41:26 144,896 —-a-w C:\WINDOWS\$hf_mig$\KB960225\SP2QFE\schannel.dll
+ 2008-12-05 06:54:55 144,896 —-a-w C:\WINDOWS\$hf_mig$\KB960225\SP3GDR\schannel.dll
+ 2008-12-05 06:58:08 144,896 —-a-w C:\WINDOWS\$hf_mig$\KB960225\SP3QFE\schannel.dll
+ 2007-11-30 11:18:51 17,272 —-a-w C:\WINDOWS\$hf_mig$\KB960225\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w C:\WINDOWS\$hf_mig$\KB960225\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w C:\WINDOWS\$hf_mig$\KB960225\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w C:\WINDOWS\$hf_mig$\KB960225\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w C:\WINDOWS\$hf_mig$\KB960225\update\updspapi.dll
+ 2008-07-09 07:38:24 17,272 —-a-w C:\WINDOWS\$hf_mig$\KB960715\spmsg.dll
+ 2008-07-09 07:38:25 231,288 —-a-w C:\WINDOWS\$hf_mig$\KB960715\spuninst.exe
+ 2008-07-09 07:38:24 26,488 —-a-w C:\WINDOWS\$hf_mig$\KB960715\update\spcustom.dll
+ 2008-11-15 17:18:04 755,576 —-a-w C:\WINDOWS\$hf_mig$\KB960715\update\update.exe
+ 2008-07-09 07:38:37 382,840 —-a-w C:\WINDOWS\$hf_mig$\KB960715\update\updspapi.dll
+ 2008-12-20 23:55:43 124,928 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\advpack.dll
+ 2008-12-20 23:55:44 347,136 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\dxtmsft.dll
+ 2008-12-20 23:55:44 214,528 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\dxtrans.dll
+ 2008-12-20 23:55:44 132,608 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\extmgr.dll
+ 2008-12-20 23:55:45 63,488 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\icardie.dll
+ 2008-12-19 09:41:51 70,656 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ie4uinit.exe
+ 2008-12-20 23:55:45 153,088 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieakeng.dll
+ 2008-12-20 23:55:45 230,400 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieaksie.dll
+ 2008-12-19 05:24:02 161,792 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieapfltr.dat
+ 2008-12-20 23:55:46 380,928 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieapfltr.dll
+ 2008-12-20 23:55:46 388,608 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iedkcs32.dll
+ 2008-12-20 23:55:50 6,068,736 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieframe.dll
+ 2008-12-20 23:55:50 44,544 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iernonce.dll
+ 2008-12-20 23:55:50 267,776 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iertutil.dll
+ 2008-12-19 09:41:52 13,824 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieudinit.exe
+ 2008-12-19 05:25:30 634,024 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
+ 2008-12-20 23:55:51 27,648 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\jsproxy.dll
+ 2008-12-20 23:55:51 459,264 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\msfeeds.dll
+ 2008-12-20 23:55:51 52,224 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\msfeedsbs.dll
+ 2009-01-16 16:24:38 3,596,288 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\mshtml.dll
+ 2008-12-20 23:55:56 477,696 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\mshtmled.dll
+ 2008-12-20 23:55:56 193,024 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\msrating.dll
+ 2008-12-20 23:55:57 671,232 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\mstime.dll
+ 2008-12-20 23:55:57 102,912 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\occache.dll
+ 2008-12-20 23:55:57 44,544 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\pngfilt.dll
+ 2008-12-20 23:55:57 105,984 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\url.dll
+ 2008-12-20 23:55:59 1,163,264 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\urlmon.dll
+ 2008-12-20 23:55:59 233,472 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\webcheck.dll
+ 2008-12-20 23:56:00 827,904 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:36 14,048 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\update\updspapi.dll
+ 2008-06-17 19:02:19 8,461,312 —-a-w C:\WINDOWS\$hf_mig$\KB967715\SP3GDR\shell32.dll
+ 2008-06-17 19:04:34 8,461,824 —-a-w C:\WINDOWS\$hf_mig$\KB967715\SP3QFE\shell32.dll
+ 2008-07-09 07:38:24 17,272 —-a-w C:\WINDOWS\$hf_mig$\KB967715\spmsg.dll
+ 2008-07-09 07:38:25 231,288 —-a-w C:\WINDOWS\$hf_mig$\KB967715\spuninst.exe
+ 2008-07-09 07:38:24 26,488 —-a-w C:\WINDOWS\$hf_mig$\KB967715\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 —-a-w C:\WINDOWS\$hf_mig$\KB967715\update\update.exe
+ 2008-07-09 07:38:37 382,840 —-a-w C:\WINDOWS\$hf_mig$\KB967715\update\updspapi.dll
+ 2008-07-09 07:38:25 231,288 -c—-w C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe
+ 2008-07-09 07:38:37 382,840 -c—-w C:\WINDOWS\$NtUninstallKB960715$\spuninst\updspapi.dll
+ 2007-10-26 03:34:01 8,460,288 -c—-w C:\WINDOWS\$NtUninstallKB967715$\shell32.dll
+ 2008-07-09 07:38:25 231,288 -c—-w C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe
+ 2008-07-09 07:38:37 382,840 -c—-w C:\WINDOWS\$NtUninstallKB967715$\spuninst\updspapi.dll
+ 2007-10-29 10:04:03 350,720 -c—-w C:\WINDOWS\$NtUninstallKB967715$\xpsp3res.dll
- 2005-12-03 19:47:42 110,592 —-a-w C:\WINDOWS\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll
+ 2009-03-15 19:53:48 110,592 —-a-w C:\WINDOWS\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll
+ 2009-03-15 17:46:55 65,536 —-a-w C:\WINDOWS\assembly\GAC\dao\10.0.4504.0__31bf3856ad364e35\DAO.DLL
+ 2009-03-15 17:47:00 4,608 —-a-w C:\WINDOWS\assembly\GAC\Extensibility\7.0.3300.0__b03f5f7f11d50a3a\extensibility.dll
+ 2009-03-15 17:46:54 1,215,328 —-a-w C:\WINDOWS\assembly\GAC\IACore\1.7.6223.0__31bf3856ad364e35\IACore.dll
+ 2009-03-15 17:46:54 82,784 —-a-w C:\WINDOWS\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
+ 2009-03-15 17:46:46 31,560 —-a-w C:\WINDOWS\assembly\GAC\ipdmctrl\11.0.0.0__71e9bce111e9429c\IPDMCTRL.DLL
+ 2009-04-09 13:25:31 53,248 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2009-04-09 13:25:31 12,800 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2009-04-09 13:25:32 473,600 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2009-04-09 13:25:23 2,676,224 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:25 2,846,720 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:26 563,712 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:26 567,296 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:27 576,000 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:27 577,024 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:28 577,536 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:29 577,536 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:29 578,560 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:32 578,560 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:32 145,920 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2009-04-09 13:25:32 159,232 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2009-04-09 13:25:33 364,544 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2009-04-09 13:25:33 178,176 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2009-04-09 13:25:31 223,232 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2009-03-15 17:46:46 16,712 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.InfoPath.Permission\12.0.0.0__71e9bce111e9429c\Microsoft.Office.InfoPath.Permission.dll
+ 2009-03-15 17:44:09 80,696 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access.Dao\12.0.0.0__71e9bce111e9429c\Microsoft.Office.interop.access.dao.dll
+ 2009-03-15 17:45:26 1,612,592 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Access.dll
+ 2009-03-15 17:45:27 1,276,720 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
+ 2009-03-15 17:45:27 150,320 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
+ 2009-03-15 17:46:48 404,296 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.InfoPath.SemiTrust\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.SemiTrust.dll
+ 2009-03-15 17:45:30 88,896 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.InfoPath.Xml\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.Xml.dll
+ 2009-03-15 17:45:30 146,232 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.InfoPath\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.dll
+ 2009-03-15 17:46:23 17,208 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.OneNote\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OneNote.dll
+ 2009-03-15 17:45:28 920,376 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Outlook\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll
+ 2009-03-15 17:45:29 35,648 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll
+ 2009-03-16 07:16:12 250,928 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2009-03-15 17:45:29 232,248 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Publisher\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Publisher.dll
+ 2009-03-15 17:45:28 20,280 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
+ 2009-03-16 07:08:37 783,744 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
+ 2009-03-15 17:46:56 13,312 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.stdformat.dll
+ 2009-03-15 17:45:27 371,496 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop.Forms\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.Forms.dll
+ 2009-03-15 17:45:29 64,288 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2009-03-15 17:46:56 229,376 —-a-w C:\WINDOWS\assembly\GAC\mscomctl\10.0.4504.0__31bf3856ad364e35\MSCOMCTL.DLL
- 2005-12-03 19:47:42 4,096 —-a-w C:\WINDOWS\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll
+ 2009-03-15 19:53:48 4,096 —-a-w C:\WINDOWS\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll
+ 2009-03-15 17:45:28 416,544 —-a-w C:\WINDOWS\assembly\GAC\office\12.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2009-03-15 17:44:05 12,104 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Access\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Access.dll
+ 2009-03-15 17:44:11 12,096 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Excel.dll
+ 2009-03-15 17:45:49 12,096 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Graph.dll
+ 2009-03-15 17:46:49 12,616 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml.dll
+ 2009-03-15 17:46:48 12,616 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.InfoPath\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.dll
+ 2009-03-15 17:46:26 12,104 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Outlook\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Outlook.dll
+ 2009-03-15 17:46:24 12,632 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl.dll
+ 2009-03-15 17:46:26 12,112 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll
+ 2009-03-15 17:46:37 12,104 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Publisher\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Publisher.dll
+ 2009-03-15 17:46:12 12,104 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll
+ 2009-03-15 17:46:43 12,096 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll
+ 2009-03-15 17:46:15 12,080 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Vbe.Interop.dll
+ 2009-03-15 17:46:14 11,544 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.office\12.0.0.0__71e9bce111e9429c\Policy.11.0.Office.dll
- 2005-12-03 19:47:42 16,384 —-a-w C:\WINDOWS\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll
+ 2009-03-15 19:53:47 16,384 —-a-w C:\WINDOWS\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll
+ 2009-03-16 07:09:23 120,408 —-a-w C:\WINDOWS\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
+ 2009-03-15 17:47:08 367,400 —-a-w C:\WINDOWS\assembly\GAC_32\Microsoft.VisualStudio.Tools.Applications.InteropAdapter\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.InteropAdapter.dll
+ 2009-03-16 07:09:23 611,392 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll
+ 2009-03-15 17:46:47 43,840 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.FormControl\12.0.0.0__71e9bce111e9429c\microsoft.office.infopath.formcontrol.dll
+ 2009-03-15 17:46:48 39,728 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Vsta\12.0.0.0__71e9bce111e9429c\Microsoft.Office.InfoPath.Vsta.dll
+ 2009-03-15 17:46:48 60,200 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.dll
+ 2009-03-15 17:46:53 211,736 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Adapter\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Adapter.dll
+ 2009-03-15 17:46:53 105,248 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.AddInManager\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.AddInManager.dll
+ 2009-03-15 17:46:52 330,520 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Blueprints\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Blueprints.dll
+ 2009-03-15 17:46:53 39,712 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel.dll
+ 2009-03-15 17:46:53 39,704 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Contract\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Contract.dll
+ 2009-03-15 17:46:52 72,472 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.DesignTime\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.DesignTime.dll
+ 2009-03-15 17:46:53 47,832 —-a-w C:\WINDOWS\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
+ 2009-03-15 17:46:53 39,624 —-a-w C:\WINDOWS\assembly\GAC_MSIL\System.AddIn\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.dll
+ 2008-10-15 17:12:18 279,160 —-a-w C:\WINDOWS\Downloaded Program Files\Conflict.0\f5instd.exe
+ 2008-10-15 17:10:30 115,320 —-a-w C:\WINDOWS\Downloaded Program Files\Conflict.0\F5InstH.exe
+ 2008-10-15 17:10:32 33,400 —-a-w C:\WINDOWS\Downloaded Program Files\Conflict.0\F5InstP.dll
+ 2008-10-15 17:12:20 262,776 —-a-w C:\WINDOWS\Downloaded Program Files\Conflict.0\InstallerControl.dll
- 2007-12-13 17:08:02 21,120 —-a-w C:\WINDOWS\Downloaded Program Files\F5ElHelper.dll
+ 2008-10-15 17:06:46 22,136 —-a-w C:\WINDOWS\Downloaded Program Files\F5ElHelper.dll
- 2007-12-13 17:08:00 135,296 —-a-w C:\WINDOWS\Downloaded Program Files\F5ElHelper.exe
+ 2008-10-15 17:06:44 137,336 —-a-w C:\WINDOWS\Downloaded Program Files\F5ElHelper.exe
+ 2009-02-02 23:07:40 1,914,440 —-a-w C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
- 2007-12-13 17:09:00 319,616 —-a-w C:\WINDOWS\Downloaded Program Files\urSuperHost.dll
+ 2008-10-15 17:07:46 322,680 —-a-w C:\WINDOWS\Downloaded Program Files\urSuperHost.dll
- 2007-12-13 17:05:26 1,080,960 —-a-w C:\WINDOWS\Downloaded Program Files\urTermProxy.dll
+ 2008-10-15 17:03:38 1,083,512 —-a-w C:\WINDOWS\Downloaded Program Files\urTermProxy.dll
- 2007-12-13 17:08:02 423,552 —-a-w C:\WINDOWS\Downloaded Program Files\urxhost.dll
+ 2008-10-15 17:06:46 431,224 —-a-w C:\WINDOWS\Downloaded Program Files\urxhost.dll
- 2007-12-13 17:08:02 59,520 —-a-w C:\WINDOWS\Downloaded Program Files\urxhostres.dll
+ 2008-10-15 17:06:48 64,120 —-a-w C:\WINDOWS\Downloaded Program Files\urxhostres.dll
- 2007-12-13 17:05:26 66,176 —-a-w C:\WINDOWS\Downloaded Program Files\utunres.dll
+ 2008-10-15 17:03:38 66,168 —-a-w C:\WINDOWS\Downloaded Program Files\utunres.dll
- 2005-10-21 01:02:28 163,328 —-a-w C:\WINDOWS\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 00:02:28 163,328 —-a-w C:\WINDOWS\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 —-a-w C:\WINDOWS\ERDNT\subs\ERDNT.EXE
+ 2008-10-16 20:38:34 124,928 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\advpack.dll
+ 2008-10-16 20:38:34 347,136 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\dxtmsft.dll
+ 2008-10-16 20:38:34 214,528 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\dxtrans.dll
+ 2008-10-16 20:38:35 133,120 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\extmgr.dll
+ 2008-10-16 20:38:35 63,488 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\icardie.dll
+ 2008-10-16 13:11:09 70,656 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ie4uinit.exe
+ 2008-10-16 20:38:35 153,088 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieakeng.dll
+ 2008-10-16 20:38:35 230,400 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieaksie.dll
+ 2008-10-15 07:04:53 161,792 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieakui.dll
+ 2008-10-16 20:38:35 383,488 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieapfltr.dll
+ 2008-10-16 20:38:35 384,512 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\iedkcs32.dll
+ 2008-10-16 20:38:37 6,066,176 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieframe.dll
+ 2008-10-16 20:38:37 44,544 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\iernonce.dll
+ 2008-10-16 20:38:37 267,776 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\iertutil.dll
+ 2008-10-16 13:11:09 13,824 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieudinit.exe
+ 2008-10-15 07:06:26 633,632 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
+ 2008-10-16 20:38:37 27,648 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\jsproxy.dll
+ 2008-10-16 20:38:37 459,264 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\msfeeds.dll
+ 2008-10-16 20:38:37 52,224 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\msfeedsbs.dll
+ 2008-12-13 06:40:02 3,593,216 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\mshtml.dll
+ 2008-10-16 20:38:38 477,696 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\mshtmled.dll
+ 2008-10-16 20:38:38 193,024 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\msrating.dll
+ 2008-10-16 20:38:39 671,232 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\mstime.dll
+ 2008-10-16 20:38:39 102,912 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\occache.dll
+ 2008-10-16 20:38:39 44,544 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\pngfilt.dll
+ 2007-03-06 01:22:41 213,216 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\updspapi.dll
+ 2008-10-16 20:38:39 105,984 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\url.dll
+ 2008-10-16 20:38:39 1,160,192 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\urlmon.dll
+ 2008-10-16 20:38:39 233,472 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\webcheck.dll
+ 2008-10-16 20:38:40 826,368 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\wininet.dll
+ 2006-10-26 23:49:48 1,011,488 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109010090400000000000F01FEC\12.0.4518\MSDAIPP.DLL
+ 2006-10-26 23:49:46 970,528 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109010090400000000000F01FEC\12.0.4518\MSONSEXT.DLL
+ 2006-10-27 19:00:10 576,376 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACACEDAO.DLL
+ 2006-10-27 01:18:12 162,616 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACCWIZ.DLL
+ 2006-10-27 19:00:12 1,751,904 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACECORE.DLL
+ 2006-10-27 19:00:10 576,376 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEDAO.DLL
+ 2006-10-27 19:00:06 47,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEERR.DLL
+ 2006-10-27 19:00:08 191,360 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEES.DLL
+ 2006-10-27 00:13:34 338,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEEXCH.DLL
+ 2006-10-27 00:13:44 629,616 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEEXCL.DLL
+ 2006-10-27 00:13:28 207,736 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACELTS.DLL
+ 2006-10-27 00:13:32 279,352 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODBC.DLL
+ 2006-10-27 00:13:08 15,160 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODDBS.DLL
+ 2006-10-27 00:13:08 15,160 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODEXL.DLL
+ 2006-10-27 00:13:08 15,160 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODPDX.DLL
+ 2006-10-27 00:13:12 15,160 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODTXT.DLL
+ 2006-10-27 19:00:06 387,960 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEOLEDB.DLL
+ 2006-10-27 00:13:38 392,048 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEPDE.DLL
+ 2006-10-27 00:13:30 260,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACER2X.DLL
+ 2006-10-27 00:13:32 289,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACER3X.DLL
+ 2006-10-27 00:13:20 56,120 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACERCLR.DLL
+ 2006-10-27 00:13:38 551,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEREP.DLL
+ 2006-10-27 00:13:30 224,104 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACETXT.DLL
+ 2006-10-27 19:40:34 208,760 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEWSS.DLL
+ 2006-10-27 00:13:34 371,568 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEXBE.DLL
+ 2006-10-27 19:41:04 399,640 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CDLMSO.DLL
+ 2006-10-26 23:59:24 205,616 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CLVIEW.EXE
+ 2006-10-27 01:30:42 65,312 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\COLLIMP.DLL
+ 2006-10-27 19:16:36 133,936 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CONTAB32.DLL
+ 2006-10-27 00:12:52 189,760 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CONTACTPICKER.DLL
+ 2006-10-27 00:55:32 87,344 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DLGSETP.DLL
+ 2006-10-27 04:48:08 234,784 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DRAT.EXE
+ 2006-10-26 23:48:14 439,568 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DWDCW20.DLL
+ 2006-10-26 23:48:14 434,528 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DWTRIG20.EXE
+ 2006-10-27 19:07:36 17,891,112 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EXCEL.EXE
+ 2006-10-26 18:10:08 1,190,688 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FM20.DLL
+ 2006-10-26 18:04:58 75,576 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FORM.DLL
+ 2006-10-26 23:21:24 1,682,232 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FPSRVUTL.DLL
+ 2006-10-27 19:09:36 983,376 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FPWEC.DLL
+ 2006-10-27 00:02:12 2,526,520 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GRAPH.EXE
+ 2006-10-27 19:37:44 338,216 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVE.EXE
+ 2006-10-27 19:38:02 6,191,400 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEACCOUNTMGR.DLL
+ 2006-10-27 19:37:44 284,448 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEAUDIO.DLL
+ 2006-10-27 04:47:54 65,824 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEAUDITSERVICE.EXE
+ 2006-10-27 19:37:40 34,088 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEAUTOPROXY.DLL
+ 2006-10-27 19:37:44 300,336 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECALENDARTOOL.DLL
+ 2006-10-27 04:47:44 33,568 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECLEAN.EXE
+ 2006-10-27 19:37:56 2,689,336 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMONCOMPONENTS.DLL
+ 2006-10-27 19:38:00 3,508,544 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMUNICATIONSSERVICES.DLL
+ 2006-10-27 19:37:40 117,584 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMUNICATIONSSTATUSANDCONTROL.DLL
+ 2006-10-27 19:37:50 768,304 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMPONENTMGR.DLL
+ 2006-10-27 19:37:52 1,359,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECRYPTO.DLL
+ 2006-10-27 04:48:24 377,136 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEDATAVIEWERTOOL.DLL
+ 2006-10-27 19:37:58 3,071,288 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEDOCUMENTSHARETOOL.DLL
+ 2006-10-27 19:37:44 284,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEFETCHSERVICES.DLL
+ 2006-10-27 04:48:00 197,920 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEGAMES.DLL
+ 2006-10-27 04:48:18 317,736 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEMIGRATOR.EXE
+ 2006-10-27 04:48:40 1,555,232 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEMISC.DLL
+ 2006-10-27 04:47:42 31,016 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEMONITOR.EXE
+ 2006-10-27 04:47:40 22,808 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVENEW.DLL
+ 2006-10-27 04:48:02 224,048 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEPROJECTTOOLSET.DLL
+ 2006-10-27 19:38:04 7,053,096 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVERESOURCE.DLL
+ 2006-10-27 04:48:42 2,210,608 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESHELLEXTENSIONS.DLL
+ 2006-10-27 04:48:18 363,304 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESKETCHTOOL.DLL
+ 2006-10-27 04:47:40 16,688 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESTDURLLAUNCHER.EXE
+ 2006-10-27 19:37:56 2,738,472 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESTORAGEMGR.DLL
+ 2006-10-27 19:37:38 35,112 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESYSTEMMODE.DLL
+ 2006-10-27 04:48:02 222,512 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESYSTEMSERVICES.DLL
+ 2006-10-27 19:37:50 1,163,048 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVETEXTTOOLS.DLL
+ 2006-10-27 19:38:00 4,746,536 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVETRANSCEIVER.DLL
+ 2006-10-27 19:37:54 1,396,008 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEUIFRAMEWORK.DLL
+ 2006-10-27 04:48:34 955,680 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEUTIL.DLL
+ 2006-10-27 19:37:40 268,080 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEWEBBROWSERTOOL2.DLL
+ 2006-10-27 04:48:26 572,216 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEWEBPLATFORMSERVICES.DLL
+ 2006-10-27 19:37:48 631,080 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEWEBSERVICES.DLL
+ 2006-10-27 00:12:52 173,328 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IEAWSDC.DLL
+ 2006-10-27 00:55:38 138,024 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IMPMAIL.DLL
+ 2006-10-27 19:10:08 1,439,032 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\INFOPATH.EXE
+ 2006-10-27 19:10:10 5,456,704 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPDESIGN.DLL
+ 2006-10-27 19:10:10 5,281,592 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPEDITOR.DLL
+ 2006-10-27 01:42:00 176,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPOLK.DLL
+ 2009-03-15 17:46:47 609,104 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPOMHOST.DLL
+ 2009-03-15 17:46:48 118,112 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPOMINT.DLL
+ 2006-10-26 23:55:10 828,704 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MEDCAT.DLL
+ 2006-10-27 00:55:48 340,248 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MIMEDIR.DLL
+ 2006-10-27 19:04:08 497,504 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MORPH9.DLL
+ 2006-10-27 19:01:34 10,371,880 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSACCESS.EXE
+ 2006-10-27 01:18:06 66,880 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSAEXP30.DLL
+ 2006-10-26 17:58:14 117,552 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSCONV97.DLL
+ 2006-10-27 19:26:40 16,870,712 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSO.DLL
+ 2006-10-27 18:59:06 161,080 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOCF.DLL
+ 2006-10-26 23:48:12 14,664 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOCFU.DLL
+ 2006-10-27 00:12:58 428,816 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSODCW.DLL
+ 2006-10-27 01:13:36 26,936 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOEURO.DLL
+ 2006-10-27 00:00:08 6,635,320 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSORES.DLL
+ 2006-10-26 17:56:36 436,520 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSORUN.DLL
+ 2006-10-27 19:04:10 9,581,360 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSPUB.EXE
+ 2006-10-26 23:50:04 672,024 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSQRY32.EXE
+ 2006-10-26 17:56:40 505,136 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSSOAP30.DLL
+ 2006-10-26 23:55:12 832,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSTORDB.EXE
+ 2006-10-26 23:55:06 538,904 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSTORES.DLL
+ 2006-10-27 00:12:30 65,824 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\NAME.DLL
+ 2006-10-27 19:14:34 14,151,456 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OART.DLL
+ 2006-10-27 00:06:54 232,816 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ODEPLOY.EXE
+ 2006-10-27 00:14:06 7,033,152 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OFFOWC.DLL
+ 2006-10-27 19:18:36 1,658,152 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OGL.DLL
+ 2006-10-27 00:00:08 274,744 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OIS.EXE
+ 2006-10-27 00:00:12 998,208 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OISAPP.DLL
+ 2006-10-27 00:00:10 285,008 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OISGRAPH.DLL
+ 2006-10-27 19:16:46 2,939,704 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OLMAPI32.DLL
+ 2006-10-27 00:34:12 660,792 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OMSMAIN.DLL
+ 2006-10-27 00:34:10 192,848 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OMSXP32.DLL
+ 2006-10-27 00:32:42 604,000 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONBTTNIE.DLL
+ 2006-10-27 19:39:36 687,432 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONBTTNOL.DLL
+ 2006-10-27 19:03:04 1,018,664 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONENOTE.EXE
+ 2006-10-27 00:24:54 98,632 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONENOTEM.EXE
+ 2006-10-27 00:24:50 72,504 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONFILTER.DLL
+ 2006-10-27 00:24:58 1,165,112 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONLIBS.DLL
+ 2006-10-27 19:03:06 6,579,512 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONMAIN.DLL
+ 2006-10-27 00:23:00 782,720 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONSYNCPC.DLL
+ 2006-10-27 00:07:04 6,536,992 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OSETUP.DLL
+ 2006-09-15 20:25:18 3,611,416 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLFLTR.DAT
+ 2006-07-26 22:53:56 459,080 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLFLTR.DLL
+ 2006-10-27 19:16:44 594,256 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLMIME.DLL
+ 2006-10-27 19:16:48 12,813,096 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLOOK.EXE
+ 2006-10-27 19:16:40 176,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLPH.DLL
+ 2006-10-27 19:16:36 46,864 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLRPC.DLL
+ 2006-10-27 01:30:44 482,088 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PORTCONN.DLL
+ 2006-10-27 19:04:06 465,200 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\POWERPNT.EXE
+ 2006-10-27 19:04:06 7,980,848 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPCORE.DLL
+ 2009-03-15 17:45:29 248,632 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPTPIA.DLL
+ 2006-10-26 23:52:10 2,012,480 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPTVIEW.EXE
+ 2006-10-27 00:09:36 136,008 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PRTF9.DLL
+ 2006-10-26 18:05:00 77,144 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PSOM.DLL
+ 2006-10-27 00:55:54 413,472 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PSTPRX32.DLL
+ 2006-10-27 19:04:06 624,456 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PTXT9.DLL
+ 2006-10-27 00:09:44 590,144 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PUBCONV.DLL
+ 2006-10-27 01:13:38 38,168 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REFEDIT.DLL
+ 2006-10-27 01:42:12 744,808 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REGFORM.EXE
+ 2006-10-26 18:04:44 19,784 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REVERSE.DLL
+ 2006-10-27 00:55:44 263,520 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SCNPST32.DLL
+ 2006-10-27 00:55:44 272,744 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SCNPST64.DLL
+ 2006-10-27 00:13:00 503,624 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SELFCERT.EXE
+ 2006-10-27 00:06:58 439,600 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SETUP.EXE
+ 2006-10-27 01:18:16 502,608 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SOA.DLL
+ 2006-07-28 19:21:58 277,320 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SSGEN.DLL
+ 2006-10-27 18:57:08 2,330,968 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\STSLIST.DLL
+ 2006-10-26 18:04:48 29,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\THOCRAPI.DLL
+ 2006-10-26 18:05:04 126,784 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWCUTCHR.DLL
+ 2006-10-26 18:05:02 86,840 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWCUTLIN.DLL
+ 2006-10-26 18:04:56 58,168 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWLAY32.DLL
+ 2006-10-26 18:04:48 27,456 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWORIENT.DLL
+ 2006-10-26 18:04:54 51,008 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWRECE.DLL
+ 2006-10-26 18:04:44 19,784 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWRECS.DLL
+ 2006-10-26 18:04:58 76,624 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWSTRUCT.DLL
+ 2006-09-30 04:42:56 2,583,344 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VBE6.DLL
+ 2006-10-27 03:00:12 1,841,984 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VVIEWDWG.DLL
+ 2006-10-27 02:58:38 3,732,792 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VVIEWER.DLL
+ 2006-10-27 19:23:04 347,432 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WINWORD.EXE
+ 2009-03-15 17:45:29 781,104 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WORDPIA.DLL
+ 2006-10-27 19:23:08 17,483,560 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WWLIB.DLL
+ 2006-10-26 18:05:08 1,181,520 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XIMAGE3B.DLL
+ 2006-10-27 01:17:08 11,072 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XLCALL32.DLL
+ 2006-10-26 18:05:08 530,760 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XPAGE3C.DLL
+ 2007-10-06 00:37:38 17,927,192 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\EXCEL.EXE
+ 2007-08-29 03:38:10 500,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MORPH9.DLL
+ 2007-09-15 01:45:58 16,901,168 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSO.DLL
+ 2007-08-29 03:38:46 9,584,512 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSPUB.EXE
+ 2007-10-03 00:51:22 8,436,776 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OARTCONV.DLL
+ 2007-08-29 04:19:24 1,654,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OGL.DLL
+ 2007-08-29 03:06:16 467,840 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\POWERPNT.EXE
+ 2007-08-29 03:06:44 7,990,144 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PPCORE.DLL
+ 2009-03-16 07:10:03 251,272 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PPTPIA.DLL
+ 2007-08-24 07:43:28 138,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PRTF9.DLL
+ 2007-08-29 03:39:14 625,560 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PTXT9.DLL
+ 2007-08-24 07:43:36 593,296 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PUBCONV.DLL
+ 2007-08-29 03:16:00 350,064 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\WINWORD.EXE
+ 2007-09-06 21:56:32 17,490,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\WWLIB.DLL
+ 2007-08-24 09:14:14 13,712 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\XLCALL32.DLL
+ 2009-03-16 07:22:34 1,165,584 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-03-16 07:22:35 20,240 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-03-16 07:22:34 159,504 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2009-03-16 07:22:34 184,080 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-03-16 07:22:34 217,864 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-03-16 07:22:35 18,704 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-03-16 07:22:35 35,088 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-03-16 07:22:34 845,584 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2009-03-16 07:22:34 922,384 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-03-16 07:22:35 272,648 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2009-03-16 07:22:35 888,080 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-03-16 07:22:34 1,172,240 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-03-16 07:14:12 217,864 —-a-r C:\WINDOWS\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2005-03-18 20:23:10 53,248 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2005-03-18 20:23:10 12,800 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Diagnostics.dll
+ 2005-03-18 20:23:14 473,600 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3D.dll
+ 2004-09-29 16:38:58 2,676,224 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-03-18 20:23:10 145,920 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectDraw.dll
+ 2005-03-18 20:23:10 159,232 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectInput.dll
+ 2005-03-18 20:23:14 364,544 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectPlay.dll
+ 2005-03-18 20:23:12 178,176 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectSound.dll
+ 2005-03-18 20:23:14 223,232 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.dll
+ 2004-12-01 19:53:06 2,846,720 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-02-05 23:32:54 563,712 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-03-18 21:23:14 567,296 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-05-26 19:15:56 576,000 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-07-22 21:21:34 577,024 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-09-28 18:11:52 577,536 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-12-05 21:20:50 577,536 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll
+ 2006-02-03 11:40:48 578,560 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2910.0\Microsoft.DirectX.Direct3DX.dll
+ 2006-03-31 15:27:50 578,560 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\Microsoft.DirectX.Direct3DX.dll
- 2000-08-31 13:00:00 29,696 —-a-w C:\WINDOWS\NIRCMD.exe
+ 2000-08-31 12:00:00 29,696 —-a-w C:\WINDOWS\NIRCMD.exe
- 2000-08-31 13:00:00 161,792 —-a-w C:\WINDOWS\SWREG.exe
+ 2000-08-31 12:00:00 161,792 —-a-w C:\WINDOWS\SWREG.exe
- 2008-10-16 20:38:34 124,928 —-a-w C:\WINDOWS\system32\advpack.dll
+ 2008-12-20 23:15:11 124,928 —-a-w C:\WINDOWS\system32\advpack.dll
- 2009-01-15 00:00:57 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2009-04-11 12:20:49 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2009-04-05 20:01:30 10,027 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\~tempinfo.dat
+ 2009-04-11 04:33:03 297,691 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\clkw.exe
+ 2009-04-11 06:35:09 301,828 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\minisvr4.exe
+ 2009-04-11 09:17:03 465,874 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\part.exe
+ 2009-04-11 09:58:18 364,657 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\websvr.exe
- 2009-01-15 00:00:57 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-04-11 12:20:49 49,152 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-04-11 03:52:25 32,768 –sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009041020090411\index.dat
+ 2009-04-10 18:10:24 32,768 –sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009041120090412\index.dat
+ 2009-04-10 18:24:16 78,924 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat
+ 2009-04-10 18:10:50 297,691 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8XIBK92J\clkw[1].exe
+ 2009-04-10 23:26:54 301,828 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8XIBK92J\minisvr4[1].exe
+ 2009-04-10 18:57:37 364,657 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8XIBK92J\websvr[1].exe
+ 2009-04-11 02:20:11 465,874 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GPAN41UJ\part[1].exe
- 2009-01-15 00:00:57 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-04-11 12:20:49 147,456 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-03-12 20:42:30 1,123,696 —-a-w C:\WINDOWS\system32\D3DCompiler_33.dll
+ 2007-05-16 20:45:16 1,124,720 —-a-w C:\WINDOWS\system32\D3DCompiler_34.dll
+ 2007-03-15 20:57:58 443,752 —-a-w C:\WINDOWS\system32\d3dx10_33.dll
+ 2007-05-16 20:45:16 443,752 —-a-w C:\WINDOWS\system32\d3dx10_34.dll
+ 2005-02-05 23:45:26 2,222,800 —-a-w C:\WINDOWS\system32\d3dx9_24.dll
+ 2005-03-18 21:19:58 2,337,488 —-a-w C:\WINDOWS\system32\d3dx9_25.dll
+ 2005-05-26 19:34:52 2,297,552 —-a-w C:\WINDOWS\system32\d3dx9_26.dll
+ 2005-07-22 23:59:04 2,319,568 —-a-w C:\WINDOWS\system32\d3dx9_27.dll
+ 2005-12-05 22:09:18 2,323,664 —-a-w C:\WINDOWS\system32\d3dx9_28.dll
+ 2006-02-03 12:43:16 2,332,368 —-a-w C:\WINDOWS\system32\d3dx9_29.dll
+ 2006-03-31 16:40:58 2,388,176 —-a-w C:\WINDOWS\system32\d3dx9_30.dll
+ 2006-09-28 20:05:20 2,414,360 —-a-w C:\WINDOWS\system32\d3dx9_31.dll
+ 2007-03-12 20:42:30 3,495,784 —-a-w C:\WINDOWS\system32\d3dx9_33.dll
+ 2007-05-16 20:45:16 3,497,832 —-a-w C:\WINDOWS\system32\d3dx9_34.dll
- 2008-10-16 20:38:34 124,928 -c—-w C:\WINDOWS\system32\dllcache\advpack.dll
+ 2008-12-20 23:15:11 124,928 -c–a-w C:\WINDOWS\system32\dllcache\advpack.dll
- 2008-10-16 20:38:34 347,136 -c–a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 -c–a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2008-10-16 20:38:34 214,528 -c–a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-12-20 23:15:13 214,528 -c–a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
- 2008-10-16 20:38:35 133,120 -c–a-w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-12-20 23:15:13 133,120 -c–a-w C:\WINDOWS\system32\dllcache\extmgr.dll
- 2008-10-16 20:38:35 63,488 -c—-w C:\WINDOWS\system32\dllcache\icardie.dll
+ 2008-12-20 23:15:13 63,488 -c–a-w C:\WINDOWS\system32\dllcache\icardie.dll
- 2008-10-16 13:11:09 70,656 -c—-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
+ 2008-12-19 09:10:15 70,656 -c–a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
- 2008-10-16 20:38:35 153,088 -c—-w C:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 -c–a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
- 2008-10-16 20:38:35 230,400 -c—-w C:\WINDOWS\system32\dllcache\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 -c–a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
- 2008-10-15 07:04:53 161,792 -c–a-w C:\WINDOWS\system32\dllcache\ieakui.dll
+ 2008-12-19 05:23:56 161,792 -c–a-w C:\WINDOWS\system32\dllcache\ieakui.dll
- 2008-10-16 20:38:35 383,488 -c—-w C:\WINDOWS\system32\dllcache\ieapfltr.dll
+ 2008-12-20 23:15:15 383,488 -c–a-w C:\WINDOWS\system32\dllcache\ieapfltr.dll
- 2008-10-16 20:38:35 384,512 -c—-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 -c–a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
- 2008-10-16 20:38:37 6,066,176 -c—-w C:\WINDOWS\system32\dllcache\ieframe.dll
+ 2008-12-20 23:15:21 6,066,688 -c–a-w C:\WINDOWS\system32\dllcache\ieframe.dll
- 2008-10-16 20:38:37 44,544 -c—-w C:\WINDOWS\system32\dllcache\iernonce.dll
+ 2008-12-20 23:15:21 44,544 -c–a-w C:\WINDOWS\system32\dllcache\iernonce.dll
- 2008-10-16 20:38:37 267,776 -c—-w C:\WINDOWS\system32\dllcache\iertutil.dll
+ 2008-12-20 23:15:22 267,776 -c–a-w C:\WINDOWS\system32\dllcache\iertutil.dll
- 2008-10-16 13:11:09 13,824 -c—-w C:\WINDOWS\system32\dllcache\ieudinit.exe
+ 2008-12-19 09:10:15 13,824 -c–a-w C:\WINDOWS\system32\dllcache\ieudinit.exe
- 2008-10-15 07:06:26 633,632 -c—-w C:\WINDOWS\system32\dllcache\iexplore.exe
+ 2008-12-19 05:25:25 634,024 -c–a-w C:\WINDOWS\system32\dllcache\iexplore.exe
- 2008-10-16 20:38:37 27,648 -c–a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-12-20 23:15:23 27,648 -c–a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
- 2008-10-16 20:38:37 459,264 -c—-w C:\WINDOWS\system32\dllcache\msfeeds.dll
+ 2008-12-20 23:15:23 459,264 -c–a-w C:\WINDOWS\system32\dllcache\msfeeds.dll
- 2008-10-16 20:38:37 52,224 -c—-w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 -c–a-w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
- 2008-12-13 06:40:02 3,593,216 -c–a-w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2009-01-17 02:35:14 3,594,752 -c–a-w C:\WINDOWS\system32\dllcache\mshtml.dll
- 2008-10-16 20:38:38 477,696 -c–a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 -c–a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2008-10-16 20:38:38 193,024 -c–a-w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-12-20 23:15:31 193,024 -c–a-w C:\WINDOWS\system32\dllcache\msrating.dll
- 2008-10-16 20:38:39 671,232 -c–a-w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-12-20 23:15:32 671,232 -c–a-w C:\WINDOWS\system32\dllcache\mstime.dll
- 2008-10-16 20:38:39 102,912 -c—-w C:\WINDOWS\system32\dllcache\occache.dll
+ 2008-12-20 23:15:38 102,912 -c–a-w C:\WINDOWS\system32\dllcache\occache.dll
- 2008-10-16 20:38:39 44,544 -c–a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 -c–a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
- 2007-04-25 14:21:15 144,896 -c—-w C:\WINDOWS\system32\dllcache\schannel.dll
+ 2008-12-05 07:12:45 144,896 -c–a-w C:\WINDOWS\system32\dllcache\schannel.dll
- 2007-10-26 03:34:01 8,460,288 -c–a-w C:\WINDOWS\system32\dllcache\shell32.dll
+ 2008-07-03 13:03:29 8,460,800 -c–a-w C:\WINDOWS\system32\dllcache\shell32.dll
- 2008-10-16 20:38:39 105,984 -c—-w C:\WINDOWS\system32\dllcache\url.dll
+ 2008-12-20 23:15:39 105,984 -c–a-w C:\WINDOWS\system32\dllcache\url.dll
- 2008-10-16 20:38:39 1,160,192 -c–a-w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 -c–a-w C:\WINDOWS\system32\dllcache\urlmon.dll
- 2008-10-16 20:38:39 233,472 -c—-w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2008-12-20 23:15:40 233,472 -c–a-w C:\WINDOWS\system32\dllcache\webcheck.dll
- 2008-09-15 11:57:41 1,846,016 -c—-w C:\WINDOWS\system32\dllcache\win32k.sys
+ 2009-02-09 10:19:34 1,846,272 -c–a-w C:\WINDOWS\system32\dllcache\win32k.sys
- 2008-10-16 20:38:40 826,368 -c–a-w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-12-20 23:15:41 826,368 -c–a-w C:\WINDOWS\system32\dllcache\wininet.dll
- 2007-04-23 00:15:25 36,624 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
+ 2008-07-31 22:17:04 43,872 —-a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
- 2008-10-16 20:38:34 347,136 —-a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 —-a-w C:\WINDOWS\system32\dxtmsft.dll
- 2008-10-16 20:38:34 214,528 —-a-w C:\WINDOWS\system32\dxtrans.dll
+ 2008-12-20 23:15:13 214,528 —-a-w C:\WINDOWS\system32\dxtrans.dll
- 2008-10-16 20:38:35 133,120 —-a-w C:\WINDOWS\system32\extmgr.dll
+ 2008-12-20 23:15:13 133,120 —-a-w C:\WINDOWS\system32\extmgr.dll
- 2007-06-06 14:53:34 1,195,888 —-a-w C:\WINDOWS\system32\FM20.DLL
+ 2007-08-23 05:03:38 1,195,888 —-a-w C:\WINDOWS\system32\FM20.DLL
- 2007-03-22 23:17:04 35,440 —-a-w C:\WINDOWS\system32\FM20ENU.DLL
+ 2006-10-26 18:10:06 33,088 —-a-w C:\WINDOWS\system32\FM20ENU.DLL
- 2008-10-16 07:12:40 290,888 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2009-03-16 07:30:06 272,576 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2009-04-10 02:48:20 51,200 –sha-w C:\WINDOWS\system32\fuhaleke.exe
- 2008-10-16 20:38:35 63,488 —-a-w C:\WINDOWS\system32\icardie.dll
+ 2008-12-20 23:15:13 63,488 —-a-w C:\WINDOWS\system32\icardie.dll
- 2008-10-16 13:11:09 70,656 —-a-w C:\WINDOWS\system32\ie4uinit.exe
+ 2008-12-19 09:10:15 70,656 —-a-w C:\WINDOWS\system32\ie4uinit.exe
- 2008-10-16 20:38:35 153,088 —-a-w C:\WINDOWS\system32\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 —-a-w C:\WINDOWS\system32\ieakeng.dll
- 2008-10-16 20:38:35 230,400 —-a-w C:\WINDOWS\system32\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 —-a-w C:\WINDOWS\system32\ieaksie.dll
- 2008-10-15 07:04:53 161,792 —-a-w C:\WINDOWS\system32\ieakui.dll
+ 2008-12-19 05:23:56 161,792 —-a-w C:\WINDOWS\system32\ieakui.dll
- 2008-10-16 20:38:35 383,488 —-a-w C:\WINDOWS\system32\ieapfltr.dll
+ 2008-12-20 23:15:15 383,488 —-a-w C:\WINDOWS\system32\ieapfltr.dll
- 2008-10-16 20:38:35 384,512 —-a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 —-a-w C:\WINDOWS\system32\iedkcs32.dll
- 2008-10-16 20:38:37 6,066,176 —-a-w C:\WINDOWS\system32\ieframe.dll
+ 2008-12-20 23:15:21 6,066,688 —-a-w C:\WINDOWS\system32\ieframe.dll
- 2008-10-16 20:38:37 44,544 —-a-w C:\WINDOWS\system32\iernonce.dll
+ 2008-12-20 23:15:21 44,544 —-a-w C:\WINDOWS\system32\iernonce.dll
- 2008-10-16 20:38:37 267,776 —-a-w C:\WINDOWS\system32\iertutil.dll
+ 2008-12-20 23:15:22 267,776 —-a-w C:\WINDOWS\system32\iertutil.dll
- 2008-10-16 13:11:09 13,824 —-a-w C:\WINDOWS\system32\ieudinit.exe
+ 2008-12-19 09:10:15 13,824 —-a-w C:\WINDOWS\system32\ieudinit.exe
- 2002-08-21 10:10:16 204,800 —-a-w C:\WINDOWS\system32\INKED.DLL
+ 2006-10-26 17:45:04 207,360 —-a-w C:\WINDOWS\system32\INKED.DLL
- 2008-10-16 20:38:37 27,648 —-a-w C:\WINDOWS\system32\jsproxy.dll
+ 2008-12-20 23:15:23 27,648 —-a-w C:\WINDOWS\system32\jsproxy.dll
+ 2003-11-04 20:10:36 98,304 —-a-w C:\WINDOWS\system32\lffax13n.dll
+ 2003-11-04 20:11:32 155,648 —-a-w C:\WINDOWS\system32\lftif13n.dll
+ 2003-12-12 21:06:30 1,693,696 —-a-w C:\WINDOWS\system32\ltclr13n.dll
+ 2009-02-03 02:07:18 240,544 —-a-r C:\WINDOWS\system32\Macromed\Flash\FlashUtil10b.exe
- 2005-08-27 18:08:06 1,398,408 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
+ 2009-02-03 02:15:28 3,771,296 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
+ 2009-02-03 02:15:30 240,544 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
- 2008-10-02 05:44:06 74,137 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-02-28 17:44:07 89,102 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-03-11 17:45:34 84,661 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
- 2008-10-16 20:38:37 459,264 —-a-w C:\WINDOWS\system32\msfeeds.dll
+ 2008-12-20 23:15:23 459,264 —-a-w C:\WINDOWS\system32\msfeeds.dll
- 2008-10-16 20:38:37 52,224 —-a-w C:\WINDOWS\system32\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 —-a-w C:\WINDOWS\system32\msfeedsbs.dll
- 2008-12-13 06:40:02 3,593,216 —-a-w C:\WINDOWS\system32\mshtml.dll
+ 2009-01-17 02:35:14 3,594,752 —-a-w C:\WINDOWS\system32\mshtml.dll
- 2008-10-16 20:38:38 477,696 —-a-w C:\WINDOWS\system32\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 —-a-w C:\WINDOWS\system32\mshtmled.dll
- 2008-10-16 20:38:38 193,024 —-a-w C:\WINDOWS\system32\msrating.dll
+ 2008-12-20 23:15:31 193,024 —-a-w C:\WINDOWS\system32\msrating.dll
- 2000-07-15 05:00:00 118,784 —-a-w C:\WINDOWS\system32\MSSTDFMT.DLL
+ 2006-07-24 14:50:38 125,744 —-a-w C:\WINDOWS\system32\MSSTDFMT.DLL
- 2008-10-16 20:38:39 671,232 —-a-w C:\WINDOWS\system32\mstime.dll
+ 2008-12-20 23:15:32 671,232 —-a-w C:\WINDOWS\system32\mstime.dll
- 2008-10-16 20:38:39 102,912 —-a-w C:\WINDOWS\system32\occache.dll
+ 2008-12-20 23:15:38 102,912 —-a-w C:\WINDOWS\system32\occache.dll
- 2008-11-13 11:53:45 64,404 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2009-04-01 01:18:16 65,248 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-11-13 11:53:45 408,000 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2009-04-01 01:18:16 410,904 —-a-w C:\WINDOWS\system32\perfh009.dat
- 2008-10-16 20:38:39 44,544 —-a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 —-a-w C:\WINDOWS\system32\pngfilt.dll
- 2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
+ 2008-12-05 07:12:45 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
- 1998-03-25 01:54:08 15,872 —-a-w C:\WINDOWS\system32\SCP32.DLL
+ 2006-07-24 14:50:40 39,728 —-a-w C:\WINDOWS\system32\SCP32.DLL
- 2007-10-26 03:34:01 8,460,288 —-a-w C:\WINDOWS\system32\shell32.dll
+ 2008-07-03 13:03:29 8,460,800 —-a-w C:\WINDOWS\system32\shell32.dll
- 2007-11-30 12:39:22 17,272 ——w C:\WINDOWS\system32\spmsg.dll
+ 2008-07-09 07:38:24 17,272 ——w C:\WINDOWS\system32\spmsg.dll
+ 2006-10-26 23:56:16 864,080 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\msonpdrv.dll
+ 2006-10-26 23:56:14 67,408 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\msonpui.dll
+ 2006-10-26 23:56:16 864,080 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\msonpdrv.dll
+ 2006-10-26 23:56:14 67,408 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\msonpui.dll
+ 2006-10-26 23:56:12 33,104 —-a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
- 2006-10-16 21:10:58 23,856 —-a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2007-07-27 13:41:38 26,488 —-a-w C:\WINDOWS\system32\spupdsvc.exe
- 2008-10-16 20:38:39 105,984 —-a-w C:\WINDOWS\system32\url.dll
+ 2008-12-20 23:15:39 105,984 —-a-w C:\WINDOWS\system32\url.dll
- 2008-10-16 20:38:39 1,160,192 —-a-w C:\WINDOWS\system32\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 —-a-w C:\WINDOWS\system32\urlmon.dll
- 1998-12-24 16:23:22 40,960 —-a-w C:\WINDOWS\system32\VBAME.DLL
+ 2006-07-24 14:50:40 47,920 —-a-w C:\WINDOWS\system32\VBAME.DLL
- 2008-10-16 20:38:39 233,472 —-a-w C:\WINDOWS\system32\webcheck.dll
+ 2008-12-20 23:15:40 233,472 —-a-w C:\WINDOWS\system32\webcheck.dll
- 2008-09-15 11:57:41 1,846,016 —-a-w C:\WINDOWS\system32\win32k.sys
+ 2009-02-09 10:19:34 1,846,272 —-a-w C:\WINDOWS\system32\win32k.sys
- 2008-10-16 20:38:40 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
+ 2008-12-20 23:15:41 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
- 2002-08-21 10:13:12 189,952 —-a-w C:\WINDOWS\system32\WISPTIS.EXE
+ 2006-10-26 17:45:04 293,376 —-a-w C:\WINDOWS\system32\WISPTIS.EXE
- 2007-06-12 04:51:12 10,834,944 —-a-w C:\WINDOWS\system32\wmp.dll
+ 2008-11-11 22:34:42 10,838,016 —-a-w C:\WINDOWS\system32\wmp.dll
+ 2007-04-16 15:52:53 246,848 —-a-w C:\WINDOWS\system32\wtl32locale.dll
+ 2006-02-03 12:41:26 14,032 —-a-w C:\WINDOWS\system32\x3daudio1_0.dll
+ 2007-03-05 16:42:18 15,128 —-a-w C:\WINDOWS\system32\x3daudio1_1.dll
+ 2006-02-03 12:42:06 230,096 —-a-w C:\WINDOWS\system32\xactengine2_0.dll
+ 2006-03-31 16:39:48 229,584 —-a-w C:\WINDOWS\system32\xactengine2_1.dll
+ 2006-05-31 11:24:16 230,168 —-a-w C:\WINDOWS\system32\xactengine2_2.dll
+ 2006-07-28 13:30:32 236,824 —-a-w C:\WINDOWS\system32\xactengine2_3.dll
+ 2006-09-28 20:05:56 237,848 —-a-w C:\WINDOWS\system32\xactengine2_4.dll
+ 2006-12-08 16:02:00 251,672 —-a-w C:\WINDOWS\system32\xactengine2_5.dll
+ 2007-01-24 19:27:30 255,848 —-a-w C:\WINDOWS\system32\xactengine2_6.dll
+ 2007-04-04 22:55:00 261,480 —-a-w C:\WINDOWS\system32\xactengine2_7.dll
+ 2006-03-31 16:39:24 62,672 —-a-w C:\WINDOWS\system32\xinput1_1.dll
+ 2006-07-28 13:30:14 62,744 —-a-w C:\WINDOWS\system32\xinput1_2.dll
+ 2007-04-04 22:53:42 81,768 —-a-w C:\WINDOWS\system32\xinput1_3.dll
+ 2005-12-05 22:07:30 61,136 —-a-w C:\WINDOWS\system32\xinput9_1_0.dll
- 2007-10-29 10:04:03 350,720 —-a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2008-02-15 09:06:21 351,744 —-a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2009-04-10 02:48:20 41,984 –sha-w C:\WINDOWS\system32\zusudupe.exe
- 2005-09-23 04:49:12 95,744 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
+ 2006-10-26 17:40:34 95,744 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
- 2005-09-23 11:29:16 479,232 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2006-10-26 17:40:36 479,232 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
- 2005-09-23 11:29:16 548,864 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2006-10-26 17:40:36 548,864 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
- 2005-09-23 11:29:16 626,688 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
+ 2006-10-26 17:40:36 626,688 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
- 2005-09-23 06:16:02 1,093,632 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
+ 2006-10-26 17:40:36 1,093,632 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
- 2005-09-23 06:16:06 1,079,808 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
+ 2006-10-26 17:40:36 1,079,808 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
- 2005-09-23 06:16:08 69,632 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
+ 2006-10-26 17:40:36 69,632 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
- 2005-09-23 06:16:10 57,344 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
+ 2006-10-26 17:40:36 57,344 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
- 2005-09-23 05:58:06 40,960 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll
+ 2006-10-26 17:40:36 40,960 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll
- 2005-09-23 05:58:06 45,056 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll
+ 2006-10-26 17:40:36 45,056 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll
- 2005-09-23 05:58:06 65,536 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll
+ 2006-10-26 17:40:36 65,536 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll
- 2005-09-23 05:58:06 57,344 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll
+ 2006-10-26 17:40:36 57,344 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll
- 2005-09-23 05:58:06 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll
+ 2006-10-26 17:40:36 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll
- 2005-09-23 05:58:06 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll
+ 2006-10-26 17:40:36 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll
- 2005-09-23 05:58:06 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll
+ 2006-10-26 17:40:36 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll
- 2005-09-23 05:58:06 49,152 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll
+ 2006-10-26 17:40:36 49,152 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll
- 2005-09-23 05:58:06 49,152 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll
+ 2006-10-26 17:40:36 49,152 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
stech

I need to see the entire Combofix log, I know its long , you can omit this section for now


((((((((((((((((((((((((((((( snapshot_2009-01-19_11.47.38.41 )))))))))))))))))))))))))))))))))))))))))
ComboFix 09-04-04.01 - Bashir 2009-04-11 8:22:05.8 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.196 [GMT -4:00] Running from: C:\Downloads\ComboFix.exe AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\Bashir\Application Data\twain\Twain.exe C:\Documents and Settings\Bashir\Application Data\wiaserva.log C:\Documents and Settings\Bashir\Local Settings\Temporary Internet Files\bestwiner.stt C:\Documents and Settings\Bashir\Local Settings\Temporary Internet Files\CPV.stt C:\Documents and Settings\Bashir\Local Settings\Temporary Internet Files\fbk.sts C:\WINDOWS\patch.exe C:\WINDOWS\system32\drivers\seneka.sys C:\WINDOWS\system32\drivers\senekankarjwba.sys C:\WINDOWS\system32\lowsec C:\WINDOWS\system32\lowsec\local.ds C:\WINDOWS\system32\lowsec\user.ds C:\WINDOWS\system32\sdra64.exe C:\WINDOWS\system32\senekaejemaqoy.dll C:\WINDOWS\system32\senekaftqmxgwy.dll C:\WINDOWS\system32\senekakyjlqjea.dat C:\WINDOWS\system32\senekanfvumene.dll C:\WINDOWS\system32\senekaxilwtjnp.dat C:\WINDOWS\system32\sys.dat C:\WINDOWS\system32\wbem\grpconv.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Service_SENEKA ((((((((((((((((((((((((( Files Created from 2009-03-11 to 2009-04-11 ))))))))))))))))))))))))))))))) . 2009-04-11 07:03 . 2009-04-11 07:03 13,824 –a—— C:\WINDOWS\system32\ftn2ksv.exe 2009-04-11 07:03 . 2009-04-11 07:03 4,224 –a—— C:\WINDOWS\system32\drivers\ftnet2k.sys 2009-04-10 23:19 . 2009-04-10 23:30 d——– C:\Documents and Settings\Bashir\Application Data\digifast 2009-04-10 23:09 . 2009-04-10 23:09 d——– C:\Program Files\WWShow 2009-04-10 23:04 . 2009-04-10 23:04 d——– C:\Program Files\Jcore 2009-04-10 22:20 . 2009-04-10 23:10 465,874 –a—— C:\WINDOWS\system32\config\systemprofile\Application Data\psvrr.exe 2009-04-10 14:10 . 2009-04-10 14:10 20,480 –a—— C:\WINDOWS\system32\nDler2.exe 2009-04-09 23:00 . 2009-04-10 08:46 408 –a—— C:\WINDOWS\Onudevax.dat 2009-04-09 23:00 . 2009-04-10 00:45 0 –a—— C:\WINDOWS\Rliwecaz.bin 2009-04-09 22:58 . 2009-04-09 22:58 d——– C:\Documents and Settings\Bashir\Application Data\pidle 2009-04-09 22:58 . 2009-04-09 22:58 84,045 –a—— C:\WINDOWS\system32\ftp_non_crp.exe 2009-04-09 22:58 . 2009-04-09 22:58 155 –a—— C:\WINDOWS\system32\SelfDel.bat 2009-04-09 21:38 . 2009-04-10 19:22 d——– C:\Program Files\Antivirus Agent Pro 2009-04-09 19:18 . 2009-04-09 19:18 3,437 –a—— C:\WINDOWS\2bbc.n4f 2009-04-09 19:15 . 2009-04-09 19:15 20,480 –a—— C:\WINDOWS\system32\winarps32.exe 2009-04-09 18:46 . 2009-04-09 18:46 988,672 –a—— C:\WINDOWS\system32\nsysk.ini 2009-04-09 18:46 . 2007-04-16 11:52 984,576 –a—— C:\WINDOWS\system32\osysk.dat 2009-04-09 18:46 . 2009-04-09 18:46 830,464 –a—— C:\WINDOWS\system32\nsysw.ini 2009-04-09 18:46 . 2008-12-20 19:15 826,368 –a—— C:\WINDOWS\system32\osysw.dat 2009-04-09 18:46 . 2009-04-09 18:46 87,040 –a—— C:\WINDOWS\system32\azton.mt 2009-04-09 18:46 . 2009-04-09 18:46 28,880 –a—— C:\WINDOWS\system32\ldshyf1.old 2009-04-09 18:46 . 2009-04-09 18:46 21,504 –a—— C:\WINDOWS\system32\nsysp.ini 2009-04-09 18:46 . 2009-04-09 18:46 19,079 –a—— C:\WINDOWS\system32\wincode.dat 2009-04-09 18:46 . 2004-08-04 01:56 17,408 –a—— C:\WINDOWS\system32\osysp.dat 2009-04-09 18:46 . 2009-04-09 18:46 9,728 –a—— C:\WINDOWS\system32\brastia.exe 2009-04-09 18:46 . 2009-04-09 18:46 6,407 –a—— C:\WINDOWS\system32\krncode.dat 2009-04-09 18:46 . 2009-04-09 18:46 1,575 –a—— C:\WINDOWS\system32\pwrcode.dat 2009-04-09 14:26 . 2009-04-09 14:26 d——– C:\Command & Conquer Generals 2009-04-09 13:31 . 2009-04-09 13:31 d——– C:\Program Files\Common Files\EasyInfo 2009-04-09 11:59 . 2009-04-09 13:17 d——– C:\Program Files\Panzer Claws II 2009-04-09 11:25 . 2009-04-09 11:25 98,304 –a—— C:\WINDOWS\system32\CmdLineExt.dll 2009-04-09 09:41 . 2009-04-09 09:41 d——– C:\Medal Of Honar ALLIED Assults 2009-04-09 09:26 . 2007-05-31 19:30 266,088 –a—— C:\WINDOWS\system32\xactengine2_8.dll 2009-04-09 09:26 . 2007-05-31 19:29 18,280 –a—— C:\WINDOWS\system32\x3daudio1_2.dll 2009-04-09 09:24 . 2009-04-09 09:24 324 –a—— C:\WINDOWS\game.ini 2009-03-19 11:55 . 2009-03-19 11:55 d——– C:\Documents and Settings\Bashir\Application Data\webex 2009-03-19 01:32 . 2009-03-19 00:41 229,376 –a—— C:\WINDOWS\system32\config\systemprofile\Application Data\psvr32.exe 2009-03-15 18:22 . 2009-03-15 18:22 d——– C:\Documents and Settings\Bashir\Application Data\Common Files 2009-03-15 13:52 . 2006-10-26 19:56 32,592 –a—— C:\WINDOWS\system32\msonpmon.dll 2009-03-15 13:46 . 2009-03-15 13:46 d——– C:\Program Files\MSBuild 2009-03-15 13:43 . 2009-03-15 13:43 d——– C:\Program Files\Microsoft.NET 2009-03-15 13:33 . 2009-03-15 13:33 d——– C:\Program Files\Microsoft Visual Studio 8 2009-03-15 13:30 . 2009-03-15 13:30 dr-h—– C:\MSOCache . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-04-11 12:25 ——— d—–w C:\Documents and Settings\Bashir\Application Data\Twain 2009-04-11 12:17 ——— d—–w C:\Program Files\BitComet 2009-04-11 11:02 ——— d—–w C:\Program Files\7-Zip 2009-04-10 18:23 ——— d—–w C:\Documents and Settings\Bashir\Application Data\gtk-2.0 2009-04-10 10:41 ——— d—–w C:\Program Files\QuickTime 2009-04-10 10:41 ——— d—–w C:\Program Files\MSN Messenger 2009-04-10 10:41 ——— d—–w C:\Program Files\iTunes 2009-04-10 10:41 ——— d—–w C:\Program Files\FreeFTP 2009-04-09 23:18 ——— d—–w C:\Program Files\REFN 2009-04-09 23:18 ——— d—–w C:\Program Files\FileZilla 2009-04-09 23:18 ——— d—–w C:\Program Files\eRightSoft 2009-04-09 23:18 ——— d—–w C:\Program Files\Elcomsoft 2009-04-09 21:29 ——— d–h–w C:\Program Files\InstallShield Installation Information 2009-04-06 14:02 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help 2009-03-15 17:47 ——— d—–w C:\Program Files\Microsoft Works 2009-03-12 23:53 ——— d—–w C:\Program Files\Macromedia 2009-03-12 23:50 ——— d—–w C:\Program Files\Common Files\Macromedia 2009-03-12 23:43 ——— d—–w C:\Program Files\Common Files\Research In Motion 2009-03-12 23:20 ——— d—–w C:\Program Files\Google 2009-03-05 13:33 ——— d—–w C:\Program Files\QUICKENW 2009-03-02 17:06 ——— d—–w C:\Program Files\Citrix 2009-02-25 20:39 ——— d—–w C:\Program Files\MSECache 2008-09-09 22:04 56,912 —-a-w C:\Documents and Settings\Bashir\g2mdlhlpx.exe 2007-09-03 04:12 6,274,206 —-a-w C:\Program Files\BitTorrent-5.0.8.exe 2007-01-08 22:24 21,822,168 —-a-w C:\Program Files\AdbeRdr80_en_US.exe 2007-01-08 22:13 7,050,552 —-a-w C:\Program Files\psa30se_en_us.exe 2005-08-08 21:01 2,323 —-a-w C:\Program Files\MSN Messenger 6.2.lnk 2005-02-17 02:21 26,262,528 —-a-w C:\Program Files\NortonVirus.exe 2005-02-16 02:17 1,867 —-a-w C:\Program Files\Norton AntiVirus 2002.lnk 2009-03-19 15:54 27,976 —-a-w C:\Program Files\mozilla firefox\plugins\atgpcdec.dll 2009-03-19 15:54 125,848 —-a-w C:\Program Files\mozilla firefox\plugins\atgpcext.dll 2009-03-19 15:54 46,408 —-a-w C:\Program Files\mozilla firefox\plugins\atmccli.dll 2009-03-19 15:55 98,712 —-a-w C:\Program Files\mozilla firefox\plugins\ieatgpc.dll 2009-04-11 03:20 73,728 —-a-w C:\Program Files\mozilla firefox\components\dfff.dll 2009-03-05 01:30 67,688 —-a-w C:\Program Files\mozilla firefox\components\jar50.dll 2009-03-05 01:30 54,368 —-a-w C:\Program Files\mozilla firefox\components\jsd3250.dll 2009-03-05 01:30 34,944 —-a-w C:\Program Files\mozilla firefox\components\myspell.dll 2009-03-05 01:30 46,712 —-a-w C:\Program Files\mozilla firefox\components\spellchk.dll 2009-03-05 01:30 172,136 —-a-w C:\Program Files\mozilla firefox\components\xpinstal.dll . ((((((((((((((((((((((((((((( snapshot_2009-01-19_11.47.38.41 ))))))))))))))))))))))))))))))))))))))))) . + 2009-02-09 10:20:05 1,847,424 —-a-w C:\WINDOWS\$hf_mig$\KB958690\SP2QFE\win32k.sys + 2009-02-09 11:13:27 1,846,784 —-a-w C:\WINDOWS\$hf_mig$\KB958690\SP3GDR\win32k.sys + 2009-02-09 11:08:53 1,847,552 —-a-w C:\WINDOWS\$hf_mig$\KB958690\SP3QFE\win32k.sys + 2008-07-09 07:38:24 17,272 —-a-w C:\WINDOWS\$hf_mig$\KB958690\spmsg.dll + 2008-07-09 07:38:25 231,288 —-a-w C:\WINDOWS\$hf_mig$\KB958690\spuninst.exe + 2008-07-09 07:38:24 26,488 —-a-w C:\WINDOWS\$hf_mig$\KB958690\update\spcustom.dll + 2008-07-09 07:38:29 755,576 —-a-w C:\WINDOWS\$hf_mig$\KB958690\update\update.exe + 2008-07-09 07:38:37 382,840 —-a-w C:\WINDOWS\$hf_mig$\KB958690\update\updspapi.dll + 2008-12-05 06:41:26 144,896 —-a-w C:\WINDOWS\$hf_mig$\KB960225\SP2QFE\schannel.dll + 2008-12-05 06:54:55 144,896 —-a-w C:\WINDOWS\$hf_mig$\KB960225\SP3GDR\schannel.dll + 2008-12-05 06:58:08 144,896 —-a-w C:\WINDOWS\$hf_mig$\KB960225\SP3QFE\schannel.dll + 2007-11-30 11:18:51 17,272 —-a-w C:\WINDOWS\$hf_mig$\KB960225\spmsg.dll + 2007-11-30 11:18:51 231,288 —-a-w C:\WINDOWS\$hf_mig$\KB960225\spuninst.exe + 2007-11-30 11:18:51 26,488 —-a-w C:\WINDOWS\$hf_mig$\KB960225\update\spcustom.dll + 2007-11-30 12:39:22 755,576 —-a-w C:\WINDOWS\$hf_mig$\KB960225\update\update.exe + 2007-11-30 12:39:22 382,840 —-a-w C:\WINDOWS\$hf_mig$\KB960225\update\updspapi.dll + 2008-07-09 07:38:24 17,272 —-a-w C:\WINDOWS\$hf_mig$\KB960715\spmsg.dll + 2008-07-09 07:38:25 231,288 —-a-w C:\WINDOWS\$hf_mig$\KB960715\spuninst.exe + 2008-07-09 07:38:24 26,488 —-a-w C:\WINDOWS\$hf_mig$\KB960715\update\spcustom.dll + 2008-11-15 17:18:04 755,576 —-a-w C:\WINDOWS\$hf_mig$\KB960715\update\update.exe + 2008-07-09 07:38:37 382,840 —-a-w C:\WINDOWS\$hf_mig$\KB960715\update\updspapi.dll + 2008-12-20 23:55:43 124,928 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\advpack.dll + 2008-12-20 23:55:44 347,136 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\dxtmsft.dll + 2008-12-20 23:55:44 214,528 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\dxtrans.dll + 2008-12-20 23:55:44 132,608 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\extmgr.dll + 2008-12-20 23:55:45 63,488 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\icardie.dll + 2008-12-19 09:41:51 70,656 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ie4uinit.exe + 2008-12-20 23:55:45 153,088 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieakeng.dll + 2008-12-20 23:55:45 230,400 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieaksie.dll + 2008-12-19 05:24:02 161,792 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieakui.dll + 2007-04-17 09:32:38 2,455,488 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieapfltr.dat + 2008-12-20 23:55:46 380,928 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieapfltr.dll + 2008-12-20 23:55:46 388,608 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iedkcs32.dll + 2008-12-20 23:55:50 6,068,736 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieframe.dll + 2008-12-20 23:55:50 44,544 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iernonce.dll + 2008-12-20 23:55:50 267,776 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iertutil.dll + 2008-12-19 09:41:52 13,824 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieudinit.exe + 2008-12-19 05:25:30 634,024 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe + 2008-12-20 23:55:51 27,648 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\jsproxy.dll + 2008-12-20 23:55:51 459,264 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\msfeeds.dll + 2008-12-20 23:55:51 52,224 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\msfeedsbs.dll + 2009-01-16 16:24:38 3,596,288 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\mshtml.dll + 2008-12-20 23:55:56 477,696 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\mshtmled.dll + 2008-12-20 23:55:56 193,024 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\msrating.dll + 2008-12-20 23:55:57 671,232 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\mstime.dll + 2008-12-20 23:55:57 102,912 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\occache.dll + 2008-12-20 23:55:57 44,544 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\pngfilt.dll + 2008-12-20 23:55:57 105,984 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\url.dll + 2008-12-20 23:55:59 1,163,264 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\urlmon.dll + 2008-12-20 23:55:59 233,472 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\webcheck.dll + 2008-12-20 23:56:00 827,904 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll + 2007-03-06 01:22:36 14,048 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\spmsg.dll + 2007-03-06 01:22:41 213,216 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\spuninst.exe + 2007-03-06 01:22:34 22,752 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\update\spcustom.dll + 2007-03-06 01:22:59 716,000 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\update\update.exe + 2007-03-06 01:23:51 371,424 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\update\updspapi.dll + 2008-06-17 19:02:19 8,461,312 —-a-w C:\WINDOWS\$hf_mig$\KB967715\SP3GDR\shell32.dll + 2008-06-17 19:04:34 8,461,824 —-a-w C:\WINDOWS\$hf_mig$\KB967715\SP3QFE\shell32.dll + 2008-07-09 07:38:24 17,272 —-a-w C:\WINDOWS\$hf_mig$\KB967715\spmsg.dll + 2008-07-09 07:38:25 231,288 —-a-w C:\WINDOWS\$hf_mig$\KB967715\spuninst.exe + 2008-07-09 07:38:24 26,488 —-a-w C:\WINDOWS\$hf_mig$\KB967715\update\spcustom.dll + 2008-07-09 07:38:29 755,576 —-a-w C:\WINDOWS\$hf_mig$\KB967715\update\update.exe + 2008-07-09 07:38:37 382,840 —-a-w C:\WINDOWS\$hf_mig$\KB967715\update\updspapi.dll + 2008-07-09 07:38:25 231,288 -c—-w C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe + 2008-07-09 07:38:37 382,840 -c—-w C:\WINDOWS\$NtUninstallKB960715$\spuninst\updspapi.dll + 2007-10-26 03:34:01 8,460,288 -c—-w C:\WINDOWS\$NtUninstallKB967715$\shell32.dll + 2008-07-09 07:38:25 231,288 -c—-w C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe + 2008-07-09 07:38:37 382,840 -c—-w C:\WINDOWS\$NtUninstallKB967715$\spuninst\updspapi.dll + 2007-10-29 10:04:03 350,720 -c—-w C:\WINDOWS\$NtUninstallKB967715$\xpsp3res.dll - 2005-12-03 19:47:42 110,592 —-a-w C:\WINDOWS\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll + 2009-03-15 19:53:48 110,592 —-a-w C:\WINDOWS\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll + 2009-03-15 17:46:55 65,536 —-a-w C:\WINDOWS\assembly\GAC\dao\10.0.4504.0__31bf3856ad364e35\DAO.DLL + 2009-03-15 17:47:00 4,608 —-a-w C:\WINDOWS\assembly\GAC\Extensibility\7.0.3300.0__b03f5f7f11d50a3a\extensibility.dll + 2009-03-15 17:46:54 1,215,328 —-a-w C:\WINDOWS\assembly\GAC\IACore\1.7.6223.0__31bf3856ad364e35\IACore.dll + 2009-03-15 17:46:54 82,784 —-a-w C:\WINDOWS\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll + 2009-03-15 17:46:46 31,560 —-a-w C:\WINDOWS\assembly\GAC\ipdmctrl\11.0.0.0__71e9bce111e9429c\IPDMCTRL.DLL + 2009-04-09 13:25:31 53,248 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll + 2009-04-09 13:25:31 12,800 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll + 2009-04-09 13:25:32 473,600 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll + 2009-04-09 13:25:23 2,676,224 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2009-04-09 13:25:25 2,846,720 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2009-04-09 13:25:26 563,712 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2009-04-09 13:25:26 567,296 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2009-04-09 13:25:27 576,000 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2009-04-09 13:25:27 577,024 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2009-04-09 13:25:28 577,536 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2009-04-09 13:25:29 577,536 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2009-04-09 13:25:29 578,560 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2009-04-09 13:25:32 578,560 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2009-04-09 13:25:32 145,920 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll + 2009-04-09 13:25:32 159,232 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll + 2009-04-09 13:25:33 364,544 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll + 2009-04-09 13:25:33 178,176 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll + 2009-04-09 13:25:31 223,232 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll + 2009-03-15 17:46:46 16,712 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.InfoPath.Permission\12.0.0.0__71e9bce111e9429c\Microsoft.Office.InfoPath.Permission.dll + 2009-03-15 17:44:09 80,696 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access.Dao\12.0.0.0__71e9bce111e9429c\Microsoft.Office.interop.access.dao.dll + 2009-03-15 17:45:26 1,612,592 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Access.dll + 2009-03-15 17:45:27 1,276,720 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll + 2009-03-15 17:45:27 150,320 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll + 2009-03-15 17:46:48 404,296 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.InfoPath.SemiTrust\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.SemiTrust.dll + 2009-03-15 17:45:30 88,896 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.InfoPath.Xml\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.Xml.dll + 2009-03-15 17:45:30 146,232 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.InfoPath\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.dll + 2009-03-15 17:46:23 17,208 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.OneNote\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OneNote.dll + 2009-03-15 17:45:28 920,376 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Outlook\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll + 2009-03-15 17:45:29 35,648 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll + 2009-03-16 07:16:12 250,928 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll + 2009-03-15 17:45:29 232,248 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Publisher\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Publisher.dll + 2009-03-15 17:45:28 20,280 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll + 2009-03-16 07:08:37 783,744 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll + 2009-03-15 17:46:56 13,312 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.stdformat.dll + 2009-03-15 17:45:27 371,496 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop.Forms\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.Forms.dll + 2009-03-15 17:45:29 64,288 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll + 2009-03-15 17:46:56 229,376 —-a-w C:\WINDOWS\assembly\GAC\mscomctl\10.0.4504.0__31bf3856ad364e35\MSCOMCTL.DLL - 2005-12-03 19:47:42 4,096 —-a-w C:\WINDOWS\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll + 2009-03-15 19:53:48 4,096 —-a-w C:\WINDOWS\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll + 2009-03-15 17:45:28 416,544 —-a-w C:\WINDOWS\assembly\GAC\office\12.0.0.0__71e9bce111e9429c\OFFICE.DLL + 2009-03-15 17:44:05 12,104 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Access\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Access.dll + 2009-03-15 17:44:11 12,096 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Excel.dll + 2009-03-15 17:45:49 12,096 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Graph.dll + 2009-03-15 17:46:49 12,616 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml.dll + 2009-03-15 17:46:48 12,616 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.InfoPath\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.dll + 2009-03-15 17:46:26 12,104 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Outlook\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Outlook.dll + 2009-03-15 17:46:24 12,632 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl.dll + 2009-03-15 17:46:26 12,112 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll + 2009-03-15 17:46:37 12,104 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Publisher\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Publisher.dll + 2009-03-15 17:46:12 12,104 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll + 2009-03-15 17:46:43 12,096 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll + 2009-03-15 17:46:15 12,080 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Vbe.Interop.dll + 2009-03-15 17:46:14 11,544 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.office\12.0.0.0__71e9bce111e9429c\Policy.11.0.Office.dll - 2005-12-03 19:47:42 16,384 —-a-w C:\WINDOWS\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll + 2009-03-15 19:53:47 16,384 —-a-w C:\WINDOWS\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll + 2009-03-16 07:09:23 120,408 —-a-w C:\WINDOWS\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll + 2009-03-15 17:47:08 367,400 —-a-w C:\WINDOWS\assembly\GAC_32\Microsoft.VisualStudio.Tools.Applications.InteropAdapter\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.InteropAdapter.dll + 2009-03-16 07:09:23 611,392 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll + 2009-03-15 17:46:47 43,840 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.FormControl\12.0.0.0__71e9bce111e9429c\microsoft.office.infopath.formcontrol.dll + 2009-03-15 17:46:48 39,728 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Vsta\12.0.0.0__71e9bce111e9429c\Microsoft.Office.InfoPath.Vsta.dll + 2009-03-15 17:46:48 60,200 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.dll + 2009-03-15 17:46:53 211,736 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Adapter\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Adapter.dll + 2009-03-15 17:46:53 105,248 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.AddInManager\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.AddInManager.dll + 2009-03-15 17:46:52 330,520 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Blueprints\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Blueprints.dll + 2009-03-15 17:46:53 39,712 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel.dll + 2009-03-15 17:46:53 39,704 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Contract\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Contract.dll + 2009-03-15 17:46:52 72,472 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.DesignTime\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.DesignTime.dll + 2009-03-15 17:46:53 47,832 —-a-w C:\WINDOWS\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll + 2009-03-15 17:46:53 39,624 —-a-w C:\WINDOWS\assembly\GAC_MSIL\System.AddIn\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.dll + 2008-10-15 17:12:18 279,160 —-a-w C:\WINDOWS\Downloaded Program Files\Conflict.0\f5instd.exe + 2008-10-15 17:10:30 115,320 —-a-w C:\WINDOWS\Downloaded Program Files\Conflict.0\F5InstH.exe + 2008-10-15 17:10:32 33,400 —-a-w C:\WINDOWS\Downloaded Program Files\Conflict.0\F5InstP.dll + 2008-10-15 17:12:20 262,776 —-a-w C:\WINDOWS\Downloaded Program Files\Conflict.0\InstallerControl.dll - 2007-12-13 17:08:02 21,120 —-a-w C:\WINDOWS\Downloaded Program Files\F5ElHelper.dll + 2008-10-15 17:06:46 22,136 —-a-w C:\WINDOWS\Downloaded Program Files\F5ElHelper.dll - 2007-12-13 17:08:00 135,296 —-a-w C:\WINDOWS\Downloaded Program Files\F5ElHelper.exe + 2008-10-15 17:06:44 137,336 —-a-w C:\WINDOWS\Downloaded Program Files\F5ElHelper.exe + 2009-02-02 23:07:40 1,914,440 —-a-w C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe - 2007-12-13 17:09:00 319,616 —-a-w C:\WINDOWS\Downloaded Program Files\urSuperHost.dll + 2008-10-15 17:07:46 322,680 —-a-w C:\WINDOWS\Downloaded Program Files\urSuperHost.dll - 2007-12-13 17:05:26 1,080,960 —-a-w C:\WINDOWS\Downloaded Program Files\urTermProxy.dll + 2008-10-15 17:03:38 1,083,512 —-a-w C:\WINDOWS\Downloaded Program Files\urTermProxy.dll - 2007-12-13 17:08:02 423,552 —-a-w C:\WINDOWS\Downloaded Program Files\urxhost.dll + 2008-10-15 17:06:46 431,224 —-a-w C:\WINDOWS\Downloaded Program Files\urxhost.dll - 2007-12-13 17:08:02 59,520 —-a-w C:\WINDOWS\Downloaded Program Files\urxhostres.dll + 2008-10-15 17:06:48 64,120 —-a-w C:\WINDOWS\Downloaded Program Files\urxhostres.dll - 2007-12-13 17:05:26 66,176 —-a-w C:\WINDOWS\Downloaded Program Files\utunres.dll + 2008-10-15 17:03:38 66,168 —-a-w C:\WINDOWS\Downloaded Program Files\utunres.dll - 2005-10-21 01:02:28 163,328 —-a-w C:\WINDOWS\ERDNT\Hiv-backup\ERDNT.EXE + 2005-10-21 00:02:28 163,328 —-a-w C:\WINDOWS\ERDNT\Hiv-backup\ERDNT.EXE + 2005-10-21 01:02:28 163,328 —-a-w C:\WINDOWS\ERDNT\subs\ERDNT.EXE + 2008-10-16 20:38:34 124,928 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\advpack.dll + 2008-10-16 20:38:34 347,136 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\dxtmsft.dll + 2008-10-16 20:38:34 214,528 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\dxtrans.dll + 2008-10-16 20:38:35 133,120 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\extmgr.dll + 2008-10-16 20:38:35 63,488 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\icardie.dll + 2008-10-16 13:11:09 70,656 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ie4uinit.exe + 2008-10-16 20:38:35 153,088 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieakeng.dll + 2008-10-16 20:38:35 230,400 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieaksie.dll + 2008-10-15 07:04:53 161,792 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieakui.dll + 2008-10-16 20:38:35 383,488 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieapfltr.dll + 2008-10-16 20:38:35 384,512 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\iedkcs32.dll + 2008-10-16 20:38:37 6,066,176 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieframe.dll + 2008-10-16 20:38:37 44,544 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\iernonce.dll + 2008-10-16 20:38:37 267,776 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\iertutil.dll + 2008-10-16 13:11:09 13,824 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieudinit.exe + 2008-10-15 07:06:26 633,632 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe + 2008-10-16 20:38:37 27,648 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\jsproxy.dll + 2008-10-16 20:38:37 459,264 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\msfeeds.dll + 2008-10-16 20:38:37 52,224 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\msfeedsbs.dll + 2008-12-13 06:40:02 3,593,216 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\mshtml.dll + 2008-10-16 20:38:38 477,696 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\mshtmled.dll + 2008-10-16 20:38:38 193,024 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\msrating.dll + 2008-10-16 20:38:39 671,232 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\mstime.dll + 2008-10-16 20:38:39 102,912 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\occache.dll + 2008-10-16 20:38:39 44,544 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\pngfilt.dll + 2007-03-06 01:22:41 213,216 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe + 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\updspapi.dll + 2008-10-16 20:38:39 105,984 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\url.dll + 2008-10-16 20:38:39 1,160,192 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\urlmon.dll + 2008-10-16 20:38:39 233,472 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\webcheck.dll + 2008-10-16 20:38:40 826,368 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\wininet.dll + 2006-10-26 23:49:48 1,011,488 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109010090400000000000F01FEC\12.0.4518\MSDAIPP.DLL + 2006-10-26 23:49:46 970,528 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109010090400000000000F01FEC\12.0.4518\MSONSEXT.DLL + 2006-10-27 19:00:10 576,376 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACACEDAO.DLL + 2006-10-27 01:18:12 162,616 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACCWIZ.DLL + 2006-10-27 19:00:12 1,751,904 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACECORE.DLL + 2006-10-27 19:00:10 576,376 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEDAO.DLL + 2006-10-27 19:00:06 47,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEERR.DLL + 2006-10-27 19:00:08 191,360 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEES.DLL + 2006-10-27 00:13:34 338,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEEXCH.DLL + 2006-10-27 00:13:44 629,616 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEEXCL.DLL + 2006-10-27 00:13:28 207,736 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACELTS.DLL + 2006-10-27 00:13:32 279,352 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODBC.DLL + 2006-10-27 00:13:08 15,160 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODDBS.DLL + 2006-10-27 00:13:08 15,160 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODEXL.DLL + 2006-10-27 00:13:08 15,160 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODPDX.DLL + 2006-10-27 00:13:12 15,160 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODTXT.DLL + 2006-10-27 19:00:06 387,960 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEOLEDB.DLL + 2006-10-27 00:13:38 392,048 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEPDE.DLL + 2006-10-27 00:13:30 260,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACER2X.DLL + 2006-10-27 00:13:32 289,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACER3X.DLL + 2006-10-27 00:13:20 56,120 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACERCLR.DLL + 2006-10-27 00:13:38 551,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEREP.DLL + 2006-10-27 00:13:30 224,104 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACETXT.DLL + 2006-10-27 19:40:34 208,760 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEWSS.DLL + 2006-10-27 00:13:34 371,568 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEXBE.DLL + 2006-10-27 19:41:04 399,640 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CDLMSO.DLL + 2006-10-26 23:59:24 205,616 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CLVIEW.EXE + 2006-10-27 01:30:42 65,312 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\COLLIMP.DLL + 2006-10-27 19:16:36 133,936 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CONTAB32.DLL + 2006-10-27 00:12:52 189,760 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CONTACTPICKER.DLL + 2006-10-27 00:55:32 87,344 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DLGSETP.DLL + 2006-10-27 04:48:08 234,784 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DRAT.EXE + 2006-10-26 23:48:14 439,568 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DWDCW20.DLL + 2006-10-26 23:48:14 434,528 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DWTRIG20.EXE + 2006-10-27 19:07:36 17,891,112 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EXCEL.EXE + 2006-10-26 18:10:08 1,190,688 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FM20.DLL + 2006-10-26 18:04:58 75,576 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FORM.DLL + 2006-10-26 23:21:24 1,682,232 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FPSRVUTL.DLL + 2006-10-27 19:09:36 983,376 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FPWEC.DLL + 2006-10-27 00:02:12 2,526,520 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GRAPH.EXE + 2006-10-27 19:37:44 338,216 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVE.EXE + 2006-10-27 19:38:02 6,191,400 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEACCOUNTMGR.DLL + 2006-10-27 19:37:44 284,448 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEAUDIO.DLL + 2006-10-27 04:47:54 65,824 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEAUDITSERVICE.EXE + 2006-10-27 19:37:40 34,088 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEAUTOPROXY.DLL + 2006-10-27 19:37:44 300,336 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECALENDARTOOL.DLL + 2006-10-27 04:47:44 33,568 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECLEAN.EXE + 2006-10-27 19:37:56 2,689,336 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMONCOMPONENTS.DLL + 2006-10-27 19:38:00 3,508,544 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMUNICATIONSSERVICES.DLL + 2006-10-27 19:37:40 117,584 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMUNICATIONSSTATUSANDCONTROL.DLL + 2006-10-27 19:37:50 768,304 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMPONENTMGR.DLL + 2006-10-27 19:37:52 1,359,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECRYPTO.DLL + 2006-10-27 04:48:24 377,136 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEDATAVIEWERTOOL.DLL + 2006-10-27 19:37:58 3,071,288 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEDOCUMENTSHARETOOL.DLL + 2006-10-27 19:37:44 284,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEFETCHSERVICES.DLL + 2006-10-27 04:48:00 197,920 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEGAMES.DLL + 2006-10-27 04:48:18 317,736 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEMIGRATOR.EXE + 2006-10-27 04:48:40 1,555,232 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEMISC.DLL + 2006-10-27 04:47:42 31,016 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEMONITOR.EXE + 2006-10-27 04:47:40 22,808 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVENEW.DLL + 2006-10-27 04:48:02 224,048 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEPROJECTTOOLSET.DLL + 2006-10-27 19:38:04 7,053,096 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVERESOURCE.DLL + 2006-10-27 04:48:42 2,210,608 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESHELLEXTENSIONS.DLL + 2006-10-27 04:48:18 363,304 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESKETCHTOOL.DLL + 2006-10-27 04:47:40 16,688 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESTDURLLAUNCHER.EXE + 2006-10-27 19:37:56 2,738,472 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESTORAGEMGR.DLL + 2006-10-27 19:37:38 35,112 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESYSTEMMODE.DLL + 2006-10-27 04:48:02 222,512 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESYSTEMSERVICES.DLL + 2006-10-27 19:37:50 1,163,048 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVETEXTTOOLS.DLL + 2006-10-27 19:38:00 4,746,536 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVETRANSCEIVER.DLL + 2006-10-27 19:37:54 1,396,008 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEUIFRAMEWORK.DLL + 2006-10-27 04:48:34 955,680 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEUTIL.DLL + 2006-10-27 19:37:40 268,080 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEWEBBROWSERTOOL2.DLL + 2006-10-27 04:48:26 572,216 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEWEBPLATFORMSERVICES.DLL + 2006-10-27 19:37:48 631,080 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEWEBSERVICES.DLL + 2006-10-27 00:12:52 173,328 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IEAWSDC.DLL + 2006-10-27 00:55:38 138,024 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IMPMAIL.DLL + 2006-10-27 19:10:08 1,439,032 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\INFOPATH.EXE + 2006-10-27 19:10:10 5,456,704 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPDESIGN.DLL + 2006-10-27 19:10:10 5,281,592 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPEDITOR.DLL + 2006-10-27 01:42:00 176,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPOLK.DLL + 2009-03-15 17:46:47 609,104 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPOMHOST.DLL + 2009-03-15 17:46:48 118,112 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPOMINT.DLL + 2006-10-26 23:55:10 828,704 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MEDCAT.DLL + 2006-10-27 00:55:48 340,248 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MIMEDIR.DLL + 2006-10-27 19:04:08 497,504 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MORPH9.DLL + 2006-10-27 19:01:34 10,371,880 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSACCESS.EXE + 2006-10-27 01:18:06 66,880 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSAEXP30.DLL + 2006-10-26 17:58:14 117,552 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSCONV97.DLL + 2006-10-27 19:26:40 16,870,712 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSO.DLL + 2006-10-27 18:59:06 161,080 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOCF.DLL + 2006-10-26 23:48:12 14,664 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOCFU.DLL + 2006-10-27 00:12:58 428,816 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSODCW.DLL + 2006-10-27 01:13:36 26,936 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOEURO.DLL + 2006-10-27 00:00:08 6,635,320 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSORES.DLL + 2006-10-26 17:56:36 436,520 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSORUN.DLL + 2006-10-27 19:04:10 9,581,360 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSPUB.EXE + 2006-10-26 23:50:04 672,024 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSQRY32.EXE + 2006-10-26 17:56:40 505,136 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSSOAP30.DLL + 2006-10-26 23:55:12 832,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSTORDB.EXE + 2006-10-26 23:55:06 538,904 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSTORES.DLL + 2006-10-27 00:12:30 65,824 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\NAME.DLL + 2006-10-27 19:14:34 14,151,456 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OART.DLL + 2006-10-27 00:06:54 232,816 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ODEPLOY.EXE + 2006-10-27 00:14:06 7,033,152 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OFFOWC.DLL + 2006-10-27 19:18:36 1,658,152 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OGL.DLL + 2006-10-27 00:00:08 274,744 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OIS.EXE + 2006-10-27 00:00:12 998,208 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OISAPP.DLL + 2006-10-27 00:00:10 285,008 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OISGRAPH.DLL + 2006-10-27 19:16:46 2,939,704 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OLMAPI32.DLL + 2006-10-27 00:34:12 660,792 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OMSMAIN.DLL + 2006-10-27 00:34:10 192,848 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OMSXP32.DLL + 2006-10-27 00:32:42 604,000 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONBTTNIE.DLL + 2006-10-27 19:39:36 687,432 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONBTTNOL.DLL + 2006-10-27 19:03:04 1,018,664 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONENOTE.EXE + 2006-10-27 00:24:54 98,632 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONENOTEM.EXE + 2006-10-27 00:24:50 72,504 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONFILTER.DLL + 2006-10-27 00:24:58 1,165,112 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONLIBS.DLL + 2006-10-27 19:03:06 6,579,512 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONMAIN.DLL + 2006-10-27 00:23:00 782,720 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONSYNCPC.DLL + 2006-10-27 00:07:04 6,536,992 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OSETUP.DLL + 2006-09-15 20:25:18 3,611,416 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLFLTR.DAT + 2006-07-26 22:53:56 459,080 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLFLTR.DLL + 2006-10-27 19:16:44 594,256 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLMIME.DLL + 2006-10-27 19:16:48 12,813,096 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLOOK.EXE + 2006-10-27 19:16:40 176,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLPH.DLL + 2006-10-27 19:16:36 46,864 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLRPC.DLL + 2006-10-27 01:30:44 482,088 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PORTCONN.DLL + 2006-10-27 19:04:06 465,200 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\POWERPNT.EXE + 2006-10-27 19:04:06 7,980,848 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPCORE.DLL + 2009-03-15 17:45:29 248,632 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPTPIA.DLL + 2006-10-26 23:52:10 2,012,480 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPTVIEW.EXE + 2006-10-27 00:09:36 136,008 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PRTF9.DLL + 2006-10-26 18:05:00 77,144 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PSOM.DLL + 2006-10-27 00:55:54 413,472 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PSTPRX32.DLL + 2006-10-27 19:04:06 624,456 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PTXT9.DLL + 2006-10-27 00:09:44 590,144 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PUBCONV.DLL + 2006-10-27 01:13:38 38,168 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REFEDIT.DLL + 2006-10-27 01:42:12 744,808 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REGFORM.EXE + 2006-10-26 18:04:44 19,784 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REVERSE.DLL + 2006-10-27 00:55:44 263,520 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SCNPST32.DLL + 2006-10-27 00:55:44 272,744 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SCNPST64.DLL + 2006-10-27 00:13:00 503,624 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SELFCERT.EXE + 2006-10-27 00:06:58 439,600 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SETUP.EXE + 2006-10-27 01:18:16 502,608 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SOA.DLL + 2006-07-28 19:21:58 277,320 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SSGEN.DLL + 2006-10-27 18:57:08 2,330,968 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\STSLIST.DLL + 2006-10-26 18:04:48 29,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\THOCRAPI.DLL + 2006-10-26 18:05:04 126,784 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWCUTCHR.DLL + 2006-10-26 18:05:02 86,840 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWCUTLIN.DLL + 2006-10-26 18:04:56 58,168 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWLAY32.DLL + 2006-10-26 18:04:48 27,456 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWORIENT.DLL + 2006-10-26 18:04:54 51,008 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWRECE.DLL + 2006-10-26 18:04:44 19,784 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWRECS.DLL + 2006-10-26 18:04:58 76,624 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWSTRUCT.DLL + 2006-09-30 04:42:56 2,583,344 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VBE6.DLL + 2006-10-27 03:00:12 1,841,984 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VVIEWDWG.DLL + 2006-10-27 02:58:38 3,732,792 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VVIEWER.DLL + 2006-10-27 19:23:04 347,432 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WINWORD.EXE + 2009-03-15 17:45:29 781,104 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WORDPIA.DLL + 2006-10-27 19:23:08 17,483,560 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WWLIB.DLL + 2006-10-26 18:05:08 1,181,520 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XIMAGE3B.DLL + 2006-10-27 01:17:08 11,072 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XLCALL32.DLL + 2006-10-26 18:05:08 530,760 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XPAGE3C.DLL + 2007-10-06 00:37:38 17,927,192 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\EXCEL.EXE + 2007-08-29 03:38:10 500,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MORPH9.DLL + 2007-09-15 01:45:58 16,901,168 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSO.DLL + 2007-08-29 03:38:46 9,584,512 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSPUB.EXE + 2007-10-03 00:51:22 8,436,776 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OARTCONV.DLL + 2007-08-29 04:19:24 1,654,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OGL.DLL + 2007-08-29 03:06:16 467,840 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\POWERPNT.EXE + 2007-08-29 03:06:44 7,990,144 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PPCORE.DLL + 2009-03-16 07:10:03 251,272 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PPTPIA.DLL + 2007-08-24 07:43:28 138,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PRTF9.DLL + 2007-08-29 03:39:14 625,560 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PTXT9.DLL + 2007-08-24 07:43:36 593,296 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PUBCONV.DLL + 2007-08-29 03:16:00 350,064 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\WINWORD.EXE + 2007-09-06 21:56:32 17,490,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\WWLIB.DLL + 2007-08-24 09:14:14 13,712 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\XLCALL32.DLL + 2009-03-16 07:22:34 1,165,584 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe + 2009-03-16 07:22:35 20,240 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe + 2009-03-16 07:22:34 159,504 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe + 2009-03-16 07:22:34 184,080 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe + 2009-03-16 07:22:34 217,864 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe + 2009-03-16 07:22:35 18,704 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe + 2009-03-16 07:22:35 35,088 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe + 2009-03-16 07:22:34 845,584 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe + 2009-03-16 07:22:34 922,384 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe + 2009-03-16 07:22:35 272,648 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe + 2009-03-16 07:22:35 888,080 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe + 2009-03-16 07:22:34 1,172,240 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe + 2009-03-16 07:14:12 217,864 —-a-r C:\WINDOWS\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe + 2005-03-18 20:23:10 53,248 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.AudioVideoPlayback.dll + 2005-03-18 20:23:10 12,800 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Diagnostics.dll + 2005-03-18 20:23:14 473,600 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3D.dll + 2004-09-29 16:38:58 2,676,224 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3DX.dll + 2005-03-18 20:23:10 145,920 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectDraw.dll + 2005-03-18 20:23:10 159,232 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectInput.dll + 2005-03-18 20:23:14 364,544 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectPlay.dll + 2005-03-18 20:23:12 178,176 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectSound.dll + 2005-03-18 20:23:14 223,232 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.dll + 2004-12-01 19:53:06 2,846,720 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\Microsoft.DirectX.Direct3DX.dll + 2005-02-05 23:32:54 563,712 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\Microsoft.DirectX.Direct3DX.dll + 2005-03-18 21:23:14 567,296 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\Microsoft.DirectX.Direct3DX.dll + 2005-05-26 19:15:56 576,000 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\Microsoft.DirectX.Direct3DX.dll + 2005-07-22 21:21:34 577,024 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll + 2005-09-28 18:11:52 577,536 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\Microsoft.DirectX.Direct3DX.dll + 2005-12-05 21:20:50 577,536 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll + 2006-02-03 11:40:48 578,560 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2910.0\Microsoft.DirectX.Direct3DX.dll + 2006-03-31 15:27:50 578,560 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\Microsoft.DirectX.Direct3DX.dll - 2000-08-31 13:00:00 29,696 —-a-w C:\WINDOWS\NIRCMD.exe + 2000-08-31 12:00:00 29,696 —-a-w C:\WINDOWS\NIRCMD.exe - 2000-08-31 13:00:00 161,792 —-a-w C:\WINDOWS\SWREG.exe + 2000-08-31 12:00:00 161,792 —-a-w C:\WINDOWS\SWREG.exe - 2008-10-16 20:38:34 124,928 —-a-w C:\WINDOWS\system32\advpack.dll + 2008-12-20 23:15:11 124,928 —-a-w C:\WINDOWS\system32\advpack.dll - 2009-01-15 00:00:57 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat + 2009-04-11 12:20:49 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat + 2009-04-05 20:01:30 10,027 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\~tempinfo.dat + 2009-04-11 04:33:03 297,691 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\clkw.exe + 2009-04-11 06:35:09 301,828 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\minisvr4.exe + 2009-04-11 09:17:03 465,874 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\part.exe + 2009-04-11 09:58:18 364,657 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\websvr.exe - 2009-01-15 00:00:57 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat + 2009-04-11 12:20:49 49,152 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat + 2009-04-11 03:52:25 32,768 –sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009041020090411\index.dat + 2009-04-10 18:10:24 32,768 –sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009041120090412\index.dat + 2009-04-10 18:24:16 78,924 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat + 2009-04-10 18:10:50 297,691 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8XIBK92J\clkw[1].exe + 2009-04-10 23:26:54 301,828 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8XIBK92J\minisvr4[1].exe + 2009-04-10 18:57:37 364,657 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8XIBK92J\websvr[1].exe + 2009-04-11 02:20:11 465,874 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GPAN41UJ\part[1].exe - 2009-01-15 00:00:57 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat + 2009-04-11 12:20:49 147,456 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat + 2007-03-12 20:42:30 1,123,696 —-a-w C:\WINDOWS\system32\D3DCompiler_33.dll + 2007-05-16 20:45:16 1,124,720 —-a-w C:\WINDOWS\system32\D3DCompiler_34.dll + 2007-03-15 20:57:58 443,752 —-a-w C:\WINDOWS\system32\d3dx10_33.dll + 2007-05-16 20:45:16 443,752 —-a-w C:\WINDOWS\system32\d3dx10_34.dll + 2005-02-05 23:45:26 2,222,800 —-a-w C:\WINDOWS\system32\d3dx9_24.dll + 2005-03-18 21:19:58 2,337,488 —-a-w C:\WINDOWS\system32\d3dx9_25.dll + 2005-05-26 19:34:52 2,297,552 —-a-w C:\WINDOWS\system32\d3dx9_26.dll + 2005-07-22 23:59:04 2,319,568 —-a-w C:\WINDOWS\system32\d3dx9_27.dll + 2005-12-05 22:09:18 2,323,664 —-a-w C:\WINDOWS\system32\d3dx9_28.dll + 2006-02-03 12:43:16 2,332,368 —-a-w C:\WINDOWS\system32\d3dx9_29.dll + 2006-03-31 16:40:58 2,388,176 —-a-w C:\WINDOWS\system32\d3dx9_30.dll + 2006-09-28 20:05:20 2,414,360 —-a-w C:\WINDOWS\system32\d3dx9_31.dll + 2007-03-12 20:42:30 3,495,784 —-a-w C:\WINDOWS\system32\d3dx9_33.dll + 2007-05-16 20:45:16 3,497,832 —-a-w C:\WINDOWS\system32\d3dx9_34.dll - 2008-10-16 20:38:34 124,928 -c—-w C:\WINDOWS\system32\dllcache\advpack.dll + 2008-12-20 23:15:11 124,928 -c–a-w C:\WINDOWS\system32\dllcache\advpack.dll - 2008-10-16 20:38:34 347,136 -c–a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll + 2008-12-20 23:15:12 347,136 -c–a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll - 2008-10-16 20:38:34 214,528 -c–a-w C:\WINDOWS\system32\dllcache\dxtrans.dll + 2008-12-20 23:15:13 214,528 -c–a-w C:\WINDOWS\system32\dllcache\dxtrans.dll - 2008-10-16 20:38:35 133,120 -c–a-w C:\WINDOWS\system32\dllcache\extmgr.dll + 2008-12-20 23:15:13 133,120 -c–a-w C:\WINDOWS\system32\dllcache\extmgr.dll - 2008-10-16 20:38:35 63,488 -c—-w C:\WINDOWS\system32\dllcache\icardie.dll + 2008-12-20 23:15:13 63,488 -c–a-w C:\WINDOWS\system32\dllcache\icardie.dll - 2008-10-16 13:11:09 70,656 -c—-w C:\WINDOWS\system32\dllcache\ie4uinit.exe + 2008-12-19 09:10:15 70,656 -c–a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe - 2008-10-16 20:38:35 153,088 -c—-w C:\WINDOWS\system32\dllcache\ieakeng.dll + 2008-12-20 23:15:14 153,088 -c–a-w C:\WINDOWS\system32\dllcache\ieakeng.dll - 2008-10-16 20:38:35 230,400 -c—-w C:\WINDOWS\system32\dllcache\ieaksie.dll + 2008-12-20 23:15:14 230,400 -c–a-w C:\WINDOWS\system32\dllcache\ieaksie.dll - 2008-10-15 07:04:53 161,792 -c–a-w C:\WINDOWS\system32\dllcache\ieakui.dll + 2008-12-19 05:23:56 161,792 -c–a-w C:\WINDOWS\system32\dllcache\ieakui.dll - 2008-10-16 20:38:35 383,488 -c—-w C:\WINDOWS\system32\dllcache\ieapfltr.dll + 2008-12-20 23:15:15 383,488 -c–a-w C:\WINDOWS\system32\dllcache\ieapfltr.dll - 2008-10-16 20:38:35 384,512 -c—-w C:\WINDOWS\system32\dllcache\iedkcs32.dll + 2008-12-20 23:15:16 384,512 -c–a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll - 2008-10-16 20:38:37 6,066,176 -c—-w C:\WINDOWS\system32\dllcache\ieframe.dll + 2008-12-20 23:15:21 6,066,688 -c–a-w C:\WINDOWS\system32\dllcache\ieframe.dll - 2008-10-16 20:38:37 44,544 -c—-w C:\WINDOWS\system32\dllcache\iernonce.dll + 2008-12-20 23:15:21 44,544 -c–a-w C:\WINDOWS\system32\dllcache\iernonce.dll - 2008-10-16 20:38:37 267,776 -c—-w C:\WINDOWS\system32\dllcache\iertutil.dll + 2008-12-20 23:15:22 267,776 -c–a-w C:\WINDOWS\system32\dllcache\iertutil.dll - 2008-10-16 13:11:09 13,824 -c—-w C:\WINDOWS\system32\dllcache\ieudinit.exe + 2008-12-19 09:10:15 13,824 -c–a-w C:\WINDOWS\system32\dllcache\ieudinit.exe - 2008-10-15 07:06:26 633,632 -c—-w C:\WINDOWS\system32\dllcache\iexplore.exe + 2008-12-19 05:25:25 634,024 -c–a-w C:\WINDOWS\system32\dllcache\iexplore.exe - 2008-10-16 20:38:37 27,648 -c–a-w C:\WINDOWS\system32\dllcache\jsproxy.dll + 2008-12-20 23:15:23 27,648 -c–a-w C:\WINDOWS\system32\dllcache\jsproxy.dll - 2008-10-16 20:38:37 459,264 -c—-w C:\WINDOWS\system32\dllcache\msfeeds.dll + 2008-12-20 23:15:23 459,264 -c–a-w C:\WINDOWS\system32\dllcache\msfeeds.dll - 2008-10-16 20:38:37 52,224 -c—-w C:\WINDOWS\system32\dllcache\msfeedsbs.dll + 2008-12-20 23:15:24 52,224 -c–a-w C:\WINDOWS\system32\dllcache\msfeedsbs.dll - 2008-12-13 06:40:02 3,593,216 -c–a-w C:\WINDOWS\system32\dllcache\mshtml.dll + 2009-01-17 02:35:14 3,594,752 -c–a-w C:\WINDOWS\system32\dllcache\mshtml.dll - 2008-10-16 20:38:38 477,696 -c–a-w C:\WINDOWS\system32\dllcache\mshtmled.dll + 2008-12-20 23:15:30 477,696 -c–a-w C:\WINDOWS\system32\dllcache\mshtmled.dll - 2008-10-16 20:38:38 193,024 -c–a-w C:\WINDOWS\system32\dllcache\msrating.dll + 2008-12-20 23:15:31 193,024 -c–a-w C:\WINDOWS\system32\dllcache\msrating.dll - 2008-10-16 20:38:39 671,232 -c–a-w C:\WINDOWS\system32\dllcache\mstime.dll + 2008-12-20 23:15:32 671,232 -c–a-w C:\WINDOWS\system32\dllcache\mstime.dll - 2008-10-16 20:38:39 102,912 -c—-w C:\WINDOWS\system32\dllcache\occache.dll + 2008-12-20 23:15:38 102,912 -c–a-w C:\WINDOWS\system32\dllcache\occache.dll - 2008-10-16 20:38:39 44,544 -c–a-w C:\WINDOWS\system32\dllcache\pngfilt.dll + 2008-12-20 23:15:38 44,544 -c–a-w C:\WINDOWS\system32\dllcache\pngfilt.dll - 2007-04-25 14:21:15 144,896 -c—-w C:\WINDOWS\system32\dllcache\schannel.dll + 2008-12-05 07:12:45 144,896 -c–a-w C:\WINDOWS\system32\dllcache\schannel.dll - 2007-10-26 03:34:01 8,460,288 -c–a-w C:\WINDOWS\system32\dllcache\shell32.dll + 2008-07-03 13:03:29 8,460,800 -c–a-w C:\WINDOWS\system32\dllcache\shell32.dll - 2008-10-16 20:38:39 105,984 -c—-w C:\WINDOWS\system32\dllcache\url.dll + 2008-12-20 23:15:39 105,984 -c–a-w C:\WINDOWS\system32\dllcache\url.dll - 2008-10-16 20:38:39 1,160,192 -c–a-w C:\WINDOWS\system32\dllcache\urlmon.dll + 2008-12-20 23:15:40 1,160,192 -c–a-w C:\WINDOWS\system32\dllcache\urlmon.dll - 2008-10-16 20:38:39 233,472 -c—-w C:\WINDOWS\system32\dllcache\webcheck.dll + 2008-12-20 23:15:40 233,472 -c–a-w C:\WINDOWS\system32\dllcache\webcheck.dll - 2008-09-15 11:57:41 1,846,016 -c—-w C:\WINDOWS\system32\dllcache\win32k.sys + 2009-02-09 10:19:34 1,846,272 -c–a-w C:\WINDOWS\system32\dllcache\win32k.sys - 2008-10-16 20:38:40 826,368 -c–a-w C:\WINDOWS\system32\dllcache\wininet.dll + 2008-12-20 23:15:41 826,368 -c–a-w C:\WINDOWS\system32\dllcache\wininet.dll - 2007-04-23 00:15:25 36,624 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys + 2008-07-31 22:17:04 43,872 —-a-w C:\WINDOWS\system32\drivers\pxhelp20.sys - 2008-10-16 20:38:34 347,136 —-a-w C:\WINDOWS\system32\dxtmsft.dll + 2008-12-20 23:15:12 347,136 —-a-w C:\WINDOWS\system32\dxtmsft.dll - 2008-10-16 20:38:34 214,528 —-a-w C:\WINDOWS\system32\dxtrans.dll + 2008-12-20 23:15:13 214,528 —-a-w C:\WINDOWS\system32\dxtrans.dll - 2008-10-16 20:38:35 133,120 —-a-w C:\WINDOWS\system32\extmgr.dll + 2008-12-20 23:15:13 133,120 —-a-w C:\WINDOWS\system32\extmgr.dll - 2007-06-06 14:53:34 1,195,888 —-a-w C:\WINDOWS\system32\FM20.DLL + 2007-08-23 05:03:38 1,195,888 —-a-w C:\WINDOWS\system32\FM20.DLL - 2007-03-22 23:17:04 35,440 —-a-w C:\WINDOWS\system32\FM20ENU.DLL + 2006-10-26 18:10:06 33,088 —-a-w C:\WINDOWS\system32\FM20ENU.DLL - 2008-10-16 07:12:40 290,888 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT + 2009-03-16 07:30:06 272,576 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT + 2009-04-10 02:48:20 51,200 –sha-w C:\WINDOWS\system32\fuhaleke.exe - 2008-10-16 20:38:35 63,488 —-a-w C:\WINDOWS\system32\icardie.dll + 2008-12-20 23:15:13 63,488 —-a-w C:\WINDOWS\system32\icardie.dll - 2008-10-16 13:11:09 70,656 —-a-w C:\WINDOWS\system32\ie4uinit.exe + 2008-12-19 09:10:15 70,656 —-a-w C:\WINDOWS\system32\ie4uinit.exe - 2008-10-16 20:38:35 153,088 —-a-w C:\WINDOWS\system32\ieakeng.dll + 2008-12-20 23:15:14 153,088 —-a-w C:\WINDOWS\system32\ieakeng.dll - 2008-10-16 20:38:35 230,400 —-a-w C:\WINDOWS\system32\ieaksie.dll + 2008-12-20 23:15:14 230,400 —-a-w C:\WINDOWS\system32\ieaksie.dll - 2008-10-15 07:04:53 161,792 —-a-w C:\WINDOWS\system32\ieakui.dll + 2008-12-19 05:23:56 161,792 —-a-w C:\WINDOWS\system32\ieakui.dll - 2008-10-16 20:38:35 383,488 —-a-w C:\WINDOWS\system32\ieapfltr.dll + 2008-12-20 23:15:15 383,488 —-a-w C:\WINDOWS\system32\ieapfltr.dll - 2008-10-16 20:38:35 384,512 —-a-w C:\WINDOWS\system32\iedkcs32.dll + 2008-12-20 23:15:16 384,512 —-a-w C:\WINDOWS\system32\iedkcs32.dll - 2008-10-16 20:38:37 6,066,176 —-a-w C:\WINDOWS\system32\ieframe.dll + 2008-12-20 23:15:21 6,066,688 —-a-w C:\WINDOWS\system32\ieframe.dll - 2008-10-16 20:38:37 44,544 —-a-w C:\WINDOWS\system32\iernonce.dll + 2008-12-20 23:15:21 44,544 —-a-w C:\WINDOWS\system32\iernonce.dll - 2008-10-16 20:38:37 267,776 —-a-w C:\WINDOWS\system32\iertutil.dll + 2008-12-20 23:15:22 267,776 —-a-w C:\WINDOWS\system32\iertutil.dll - 2008-10-16 13:11:09 13,824 —-a-w C:\WINDOWS\system32\ieudinit.exe + 2008-12-19 09:10:15 13,824 —-a-w C:\WINDOWS\system32\ieudinit.exe - 2002-08-21 10:10:16 204,800 —-a-w C:\WINDOWS\system32\INKED.DLL + 2006-10-26 17:45:04 207,360 —-a-w C:\WINDOWS\system32\INKED.DLL - 2008-10-16 20:38:37 27,648 —-a-w C:\WINDOWS\system32\jsproxy.dll + 2008-12-20 23:15:23 27,648 —-a-w C:\WINDOWS\system32\jsproxy.dll + 2003-11-04 20:10:36 98,304 —-a-w C:\WINDOWS\system32\lffax13n.dll + 2003-11-04 20:11:32 155,648 —-a-w C:\WINDOWS\system32\lftif13n.dll + 2003-12-12 21:06:30 1,693,696 —-a-w C:\WINDOWS\system32\ltclr13n.dll + 2009-02-03 02:07:18 240,544 —-a-r C:\WINDOWS\system32\Macromed\Flash\FlashUtil10b.exe - 2005-08-27 18:08:06 1,398,408 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll + 2009-02-03 02:15:28 3,771,296 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll + 2009-02-03 02:15:30 240,544 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe - 2008-10-02 05:44:06 74,137 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe + 2009-02-28 17:44:07 89,102 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe + 2009-03-11 17:45:34 84,661 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe - 2008-10-16 20:38:37 459,264 —-a-w C:\WINDOWS\system32\msfeeds.dll + 2008-12-20 23:15:23 459,264 —-a-w C:\WINDOWS\system32\msfeeds.dll - 2008-10-16 20:38:37 52,224 —-a-w C:\WINDOWS\system32\msfeedsbs.dll + 2008-12-20 23:15:24 52,224 —-a-w C:\WINDOWS\system32\msfeedsbs.dll - 2008-12-13 06:40:02 3,593,216 —-a-w C:\WINDOWS\system32\mshtml.dll + 2009-01-17 02:35:14 3,594,752 —-a-w C:\WINDOWS\system32\mshtml.dll - 2008-10-16 20:38:38 477,696 —-a-w C:\WINDOWS\system32\mshtmled.dll + 2008-12-20 23:15:30 477,696 —-a-w C:\WINDOWS\system32\mshtmled.dll - 2008-10-16 20:38:38 193,024 —-a-w C:\WINDOWS\system32\msrating.dll + 2008-12-20 23:15:31 193,024 —-a-w C:\WINDOWS\system32\msrating.dll - 2000-07-15 05:00:00 118,784 —-a-w C:\WINDOWS\system32\MSSTDFMT.DLL + 2006-07-24 14:50:38 125,744 —-a-w C:\WINDOWS\system32\MSSTDFMT.DLL - 2008-10-16 20:38:39 671,232 —-a-w C:\WINDOWS\system32\mstime.dll + 2008-12-20 23:15:32 671,232 —-a-w C:\WINDOWS\system32\mstime.dll - 2008-10-16 20:38:39 102,912 —-a-w C:\WINDOWS\system32\occache.dll + 2008-12-20 23:15:38 102,912 —-a-w C:\WINDOWS\system32\occache.dll - 2008-11-13 11:53:45 64,404 —-a-w C:\WINDOWS\system32\perfc009.dat + 2009-04-01 01:18:16 65,248 —-a-w C:\WINDOWS\system32\perfc009.dat - 2008-11-13 11:53:45 408,000 —-a-w C:\WINDOWS\system32\perfh009.dat + 2009-04-01 01:18:16 410,904 —-a-w C:\WINDOWS\system32\perfh009.dat - 2008-10-16 20:38:39 44,544 —-a-w C:\WINDOWS\system32\pngfilt.dll + 2008-12-20 23:15:38 44,544 —-a-w C:\WINDOWS\system32\pngfilt.dll - 2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll + 2008-12-05 07:12:45 144,896 —-a-w C:\WINDOWS\system32\schannel.dll - 1998-03-25 01:54:08 15,872 —-a-w C:\WINDOWS\system32\SCP32.DLL + 2006-07-24 14:50:40 39,728 —-a-w C:\WINDOWS\system32\SCP32.DLL - 2007-10-26 03:34:01 8,460,288 —-a-w C:\WINDOWS\system32\shell32.dll + 2008-07-03 13:03:29 8,460,800 —-a-w C:\WINDOWS\system32\shell32.dll - 2007-11-30 12:39:22 17,272 ——w C:\WINDOWS\system32\spmsg.dll + 2008-07-09 07:38:24 17,272 ——w C:\WINDOWS\system32\spmsg.dll + 2006-10-26 23:56:16 864,080 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\msonpdrv.dll + 2006-10-26 23:56:14 67,408 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\msonpui.dll + 2006-10-26 23:56:16 864,080 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\msonpdrv.dll + 2006-10-26 23:56:14 67,408 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\msonpui.dll + 2006-10-26 23:56:12 33,104 —-a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll - 2006-10-16 21:10:58 23,856 —-a-w C:\WINDOWS\system32\spupdsvc.exe + 2007-07-27 13:41:38 26,488 —-a-w C:\WINDOWS\system32\spupdsvc.exe - 2008-10-16 20:38:39 105,984 —-a-w C:\WINDOWS\system32\url.dll + 2008-12-20 23:15:39 105,984 —-a-w C:\WINDOWS\system32\url.dll - 2008-10-16 20:38:39 1,160,192 —-a-w C:\WINDOWS\system32\urlmon.dll + 2008-12-20 23:15:40 1,160,192 —-a-w C:\WINDOWS\system32\urlmon.dll - 1998-12-24 16:23:22 40,960 —-a-w C:\WINDOWS\system32\VBAME.DLL + 2006-07-24 14:50:40 47,920 —-a-w C:\WINDOWS\system32\VBAME.DLL - 2008-10-16 20:38:39 233,472 —-a-w C:\WINDOWS\system32\webcheck.dll + 2008-12-20 23:15:40 233,472 —-a-w C:\WINDOWS\system32\webcheck.dll - 2008-09-15 11:57:41 1,846,016 —-a-w C:\WINDOWS\system32\win32k.sys + 2009-02-09 10:19:34 1,846,272 —-a-w C:\WINDOWS\system32\win32k.sys - 2008-10-16 20:38:40 826,368 —-a-w C:\WINDOWS\system32\wininet.dll + 2008-12-20 23:15:41 826,368 —-a-w C:\WINDOWS\system32\wininet.dll - 2002-08-21 10:13:12 189,952 —-a-w C:\WINDOWS\system32\WISPTIS.EXE + 2006-10-26 17:45:04 293,376 —-a-w C:\WINDOWS\system32\WISPTIS.EXE - 2007-06-12 04:51:12 10,834,944 —-a-w C:\WINDOWS\system32\wmp.dll + 2008-11-11 22:34:42 10,838,016 —-a-w C:\WINDOWS\system32\wmp.dll + 2007-04-16 15:52:53 246,848 —-a-w C:\WINDOWS\system32\wtl32locale.dll + 2006-02-03 12:41:26 14,032 —-a-w C:\WINDOWS\system32\x3daudio1_0.dll + 2007-03-05 16:42:18 15,128 —-a-w C:\WINDOWS\system32\x3daudio1_1.dll + 2006-02-03 12:42:06 230,096 —-a-w C:\WINDOWS\system32\xactengine2_0.dll + 2006-03-31 16:39:48 229,584 —-a-w C:\WINDOWS\system32\xactengine2_1.dll + 2006-05-31 11:24:16 230,168 —-a-w C:\WINDOWS\system32\xactengine2_2.dll + 2006-07-28 13:30:32 236,824 —-a-w C:\WINDOWS\system32\xactengine2_3.dll + 2006-09-28 20:05:56 237,848 —-a-w C:\WINDOWS\system32\xactengine2_4.dll + 2006-12-08 16:02:00 251,672 —-a-w C:\WINDOWS\system32\xactengine2_5.dll + 2007-01-24 19:27:30 255,848 —-a-w C:\WINDOWS\system32\xactengine2_6.dll + 2007-04-04 22:55:00 261,480 —-a-w C:\WINDOWS\system32\xactengine2_7.dll + 2006-03-31 16:39:24 62,672 —-a-w C:\WINDOWS\system32\xinput1_1.dll + 2006-07-28 13:30:14 62,744 —-a-w C:\WINDOWS\system32\xinput1_2.dll + 2007-04-04 22:53:42 81,768 —-a-w C:\WINDOWS\system32\xinput1_3.dll + 2005-12-05 22:07:30 61,136 —-a-w C:\WINDOWS\system32\xinput9_1_0.dll - 2007-10-29 10:04:03 350,720 —-a-w C:\WINDOWS\system32\xpsp3res.dll + 2008-02-15 09:06:21 351,744 —-a-w C:\WINDOWS\system32\xpsp3res.dll + 2009-04-10 02:48:20 41,984 –sha-w C:\WINDOWS\system32\zusudupe.exe - 2005-09-23 04:49:12 95,744 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll + 2006-10-26 17:40:34 95,744 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll - 2005-09-23 11:29:16 479,232 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll + 2006-10-26 17:40:36 479,232 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll - 2005-09-23 11:29:16 548,864 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll + 2006-10-26 17:40:36 548,864 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll - 2005-09-23 11:29:16 626,688 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll + 2006-10-26 17:40:36 626,688 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll - 2005-09-23 06:16:02 1,093,632 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll + 2006-10-26 17:40:36 1,093,632 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll - 2005-09-23 06:16:06 1,079,808 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll + 2006-10-26 17:40:36 1,079,808 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll - 2005-09-23 06:16:08 69,632 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll + 2006-10-26 17:40:36 69,632 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll - 2005-09-23 06:16:10 57,344 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll + 2006-10-26 17:40:36 57,344 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll - 2005-09-23 05:58:06 40,960 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll + 2006-10-26 17:40:36 40,960 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll - 2005-09-23 05:58:06 45,056 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll + 2006-10-26 17:40:36 45,056 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll - 2005-09-23 05:58:06 65,536 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll + 2006-10-26 17:40:36 65,536 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll - 2005-09-23 05:58:06 57,344 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll + 2006-10-26 17:40:36 57,344 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll - 2005-09-23 05:58:06 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll + 2006-10-26 17:40:36 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll - 2005-09-23 05:58:06 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll + 2006-10-26 17:40:36 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll - 2005-09-23 05:58:06 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll + 2006-10-26 17:40:36 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll - 2005-09-23 05:58:06 49,152 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll + 2006-10-26 17:40:36 49,152 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll - 2005-09-23 05:58:06 49,152 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll + 2006-10-26 17:40:36 49,152 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll . – Snapshot reset to current date – . ((((((((((((((((((((((((((((((((((((((((((((( AWF )))))))))))))))))))))))))))))))))))))))))))))))))))))))))) .
stech,

You copy and pasted the same log.

C:\ComboFix.txt <–You can find the log here, it will open in Notepad



Delete all this from the log and post the rest of it

((((((((((((((((((((((((((((( snapshot_2009-01-19_11.47.38.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-09 10:20:05 1,847,424 —-a-w C:\WINDOWS\$hf_mig$\KB958690\SP2QFE\win32k.sys
+ 2009-02-09 11:13:27 1,846,784 —-a-w C:\WINDOWS\$hf_mig$\KB958690\SP3GDR\win32k.sys
+ 2009-02-09 11:08:53 1,847,552 —-a-w C:\WINDOWS\$hf_mig$\KB958690\SP3QFE\win32k.sys
+ 2008-07-09 07:38:24 17,272 —-a-w C:\WINDOWS\$hf_mig$\KB958690\spmsg.dll
+ 2008-07-09 07:38:25 231,288 —-a-w C:\WINDOWS\$hf_mig$\KB958690\spuninst.exe
+ 2008-07-09 07:38:24 26,488 —-a-w C:\WINDOWS\$hf_mig$\KB958690\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 —-a-w C:\WINDOWS\$hf_mig$\KB958690\update\update.exe
+ 2008-07-09 07:38:37 382,840 —-a-w C:\WINDOWS\$hf_mig$\KB958690\update\updspapi.dll
+ 2008-12-05 06:41:26 144,896 —-a-w C:\WINDOWS\$hf_mig$\KB960225\SP2QFE\schannel.dll
+ 2008-12-05 06:54:55 144,896 —-a-w C:\WINDOWS\$hf_mig$\KB960225\SP3GDR\schannel.dll
+ 2008-12-05 06:58:08 144,896 —-a-w C:\WINDOWS\$hf_mig$\KB960225\SP3QFE\schannel.dll
+ 2007-11-30 11:18:51 17,272 —-a-w C:\WINDOWS\$hf_mig$\KB960225\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w C:\WINDOWS\$hf_mig$\KB960225\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w C:\WINDOWS\$hf_mig$\KB960225\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w C:\WINDOWS\$hf_mig$\KB960225\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w C:\WINDOWS\$hf_mig$\KB960225\update\updspapi.dll
+ 2008-07-09 07:38:24 17,272 —-a-w C:\WINDOWS\$hf_mig$\KB960715\spmsg.dll
+ 2008-07-09 07:38:25 231,288 —-a-w C:\WINDOWS\$hf_mig$\KB960715\spuninst.exe
+ 2008-07-09 07:38:24 26,488 —-a-w C:\WINDOWS\$hf_mig$\KB960715\update\spcustom.dll
+ 2008-11-15 17:18:04 755,576 —-a-w C:\WINDOWS\$hf_mig$\KB960715\update\update.exe
+ 2008-07-09 07:38:37 382,840 —-a-w C:\WINDOWS\$hf_mig$\KB960715\update\updspapi.dll
+ 2008-12-20 23:55:43 124,928 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\advpack.dll
+ 2008-12-20 23:55:44 347,136 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\dxtmsft.dll
+ 2008-12-20 23:55:44 214,528 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\dxtrans.dll
+ 2008-12-20 23:55:44 132,608 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\extmgr.dll
+ 2008-12-20 23:55:45 63,488 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\icardie.dll
+ 2008-12-19 09:41:51 70,656 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ie4uinit.exe
+ 2008-12-20 23:55:45 153,088 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieakeng.dll
+ 2008-12-20 23:55:45 230,400 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieaksie.dll
+ 2008-12-19 05:24:02 161,792 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieapfltr.dat
+ 2008-12-20 23:55:46 380,928 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieapfltr.dll
+ 2008-12-20 23:55:46 388,608 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iedkcs32.dll
+ 2008-12-20 23:55:50 6,068,736 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieframe.dll
+ 2008-12-20 23:55:50 44,544 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iernonce.dll
+ 2008-12-20 23:55:50 267,776 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iertutil.dll
+ 2008-12-19 09:41:52 13,824 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\ieudinit.exe
+ 2008-12-19 05:25:30 634,024 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
+ 2008-12-20 23:55:51 27,648 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\jsproxy.dll
+ 2008-12-20 23:55:51 459,264 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\msfeeds.dll
+ 2008-12-20 23:55:51 52,224 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\msfeedsbs.dll
+ 2009-01-16 16:24:38 3,596,288 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\mshtml.dll
+ 2008-12-20 23:55:56 477,696 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\mshtmled.dll
+ 2008-12-20 23:55:56 193,024 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\msrating.dll
+ 2008-12-20 23:55:57 671,232 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\mstime.dll
+ 2008-12-20 23:55:57 102,912 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\occache.dll
+ 2008-12-20 23:55:57 44,544 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\pngfilt.dll
+ 2008-12-20 23:55:57 105,984 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\url.dll
+ 2008-12-20 23:55:59 1,163,264 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\urlmon.dll
+ 2008-12-20 23:55:59 233,472 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\webcheck.dll
+ 2008-12-20 23:56:00 827,904 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:36 14,048 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w C:\WINDOWS\$hf_mig$\KB961260-IE7\update\updspapi.dll
+ 2008-06-17 19:02:19 8,461,312 —-a-w C:\WINDOWS\$hf_mig$\KB967715\SP3GDR\shell32.dll
+ 2008-06-17 19:04:34 8,461,824 —-a-w C:\WINDOWS\$hf_mig$\KB967715\SP3QFE\shell32.dll
+ 2008-07-09 07:38:24 17,272 —-a-w C:\WINDOWS\$hf_mig$\KB967715\spmsg.dll
+ 2008-07-09 07:38:25 231,288 —-a-w C:\WINDOWS\$hf_mig$\KB967715\spuninst.exe
+ 2008-07-09 07:38:24 26,488 —-a-w C:\WINDOWS\$hf_mig$\KB967715\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 —-a-w C:\WINDOWS\$hf_mig$\KB967715\update\update.exe
+ 2008-07-09 07:38:37 382,840 —-a-w C:\WINDOWS\$hf_mig$\KB967715\update\updspapi.dll
+ 2008-07-09 07:38:25 231,288 -c—-w C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe
+ 2008-07-09 07:38:37 382,840 -c—-w C:\WINDOWS\$NtUninstallKB960715$\spuninst\updspapi.dll
+ 2007-10-26 03:34:01 8,460,288 -c—-w C:\WINDOWS\$NtUninstallKB967715$\shell32.dll
+ 2008-07-09 07:38:25 231,288 -c—-w C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe
+ 2008-07-09 07:38:37 382,840 -c—-w C:\WINDOWS\$NtUninstallKB967715$\spuninst\updspapi.dll
+ 2007-10-29 10:04:03 350,720 -c—-w C:\WINDOWS\$NtUninstallKB967715$\xpsp3res.dll
- 2005-12-03 19:47:42 110,592 —-a-w C:\WINDOWS\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll
+ 2009-03-15 19:53:48 110,592 —-a-w C:\WINDOWS\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll
+ 2009-03-15 17:46:55 65,536 —-a-w C:\WINDOWS\assembly\GAC\dao\10.0.4504.0__31bf3856ad364e35\DAO.DLL
+ 2009-03-15 17:47:00 4,608 —-a-w C:\WINDOWS\assembly\GAC\Extensibility\7.0.3300.0__b03f5f7f11d50a3a\extensibility.dll
+ 2009-03-15 17:46:54 1,215,328 —-a-w C:\WINDOWS\assembly\GAC\IACore\1.7.6223.0__31bf3856ad364e35\IACore.dll
+ 2009-03-15 17:46:54 82,784 —-a-w C:\WINDOWS\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
+ 2009-03-15 17:46:46 31,560 —-a-w C:\WINDOWS\assembly\GAC\ipdmctrl\11.0.0.0__71e9bce111e9429c\IPDMCTRL.DLL
+ 2009-04-09 13:25:31 53,248 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2009-04-09 13:25:31 12,800 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2009-04-09 13:25:32 473,600 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2009-04-09 13:25:23 2,676,224 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:25 2,846,720 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:26 563,712 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:26 567,296 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:27 576,000 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:27 577,024 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:28 577,536 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:29 577,536 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:29 578,560 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:32 578,560 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-04-09 13:25:32 145,920 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2009-04-09 13:25:32 159,232 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2009-04-09 13:25:33 364,544 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2009-04-09 13:25:33 178,176 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2009-04-09 13:25:31 223,232 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2009-03-15 17:46:46 16,712 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.InfoPath.Permission\12.0.0.0__71e9bce111e9429c\Microsoft.Office.InfoPath.Permission.dll
+ 2009-03-15 17:44:09 80,696 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access.Dao\12.0.0.0__71e9bce111e9429c\Microsoft.Office.interop.access.dao.dll
+ 2009-03-15 17:45:26 1,612,592 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Access.dll
+ 2009-03-15 17:45:27 1,276,720 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
+ 2009-03-15 17:45:27 150,320 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
+ 2009-03-15 17:46:48 404,296 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.InfoPath.SemiTrust\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.SemiTrust.dll
+ 2009-03-15 17:45:30 88,896 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.InfoPath.Xml\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.Xml.dll
+ 2009-03-15 17:45:30 146,232 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.InfoPath\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.dll
+ 2009-03-15 17:46:23 17,208 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.OneNote\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OneNote.dll
+ 2009-03-15 17:45:28 920,376 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Outlook\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll
+ 2009-03-15 17:45:29 35,648 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll
+ 2009-03-16 07:16:12 250,928 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2009-03-15 17:45:29 232,248 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Publisher\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Publisher.dll
+ 2009-03-15 17:45:28 20,280 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
+ 2009-03-16 07:08:37 783,744 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
+ 2009-03-15 17:46:56 13,312 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.stdformat.dll
+ 2009-03-15 17:45:27 371,496 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop.Forms\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.Forms.dll
+ 2009-03-15 17:45:29 64,288 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2009-03-15 17:46:56 229,376 —-a-w C:\WINDOWS\assembly\GAC\mscomctl\10.0.4504.0__31bf3856ad364e35\MSCOMCTL.DLL
- 2005-12-03 19:47:42 4,096 —-a-w C:\WINDOWS\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll
+ 2009-03-15 19:53:48 4,096 —-a-w C:\WINDOWS\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll
+ 2009-03-15 17:45:28 416,544 —-a-w C:\WINDOWS\assembly\GAC\office\12.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2009-03-15 17:44:05 12,104 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Access\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Access.dll
+ 2009-03-15 17:44:11 12,096 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Excel.dll
+ 2009-03-15 17:45:49 12,096 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Graph.dll
+ 2009-03-15 17:46:49 12,616 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml.dll
+ 2009-03-15 17:46:48 12,616 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.InfoPath\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.dll
+ 2009-03-15 17:46:26 12,104 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Outlook\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Outlook.dll
+ 2009-03-15 17:46:24 12,632 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl.dll
+ 2009-03-15 17:46:26 12,112 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll
+ 2009-03-15 17:46:37 12,104 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Publisher\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Publisher.dll
+ 2009-03-15 17:46:12 12,104 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll
+ 2009-03-15 17:46:43 12,096 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll
+ 2009-03-15 17:46:15 12,080 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Vbe.Interop.dll
+ 2009-03-15 17:46:14 11,544 —-a-w C:\WINDOWS\assembly\GAC\Policy.11.0.office\12.0.0.0__71e9bce111e9429c\Policy.11.0.Office.dll
- 2005-12-03 19:47:42 16,384 —-a-w C:\WINDOWS\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll
+ 2009-03-15 19:53:47 16,384 —-a-w C:\WINDOWS\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll
+ 2009-03-16 07:09:23 120,408 —-a-w C:\WINDOWS\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
+ 2009-03-15 17:47:08 367,400 —-a-w C:\WINDOWS\assembly\GAC_32\Microsoft.VisualStudio.Tools.Applications.InteropAdapter\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.InteropAdapter.dll
+ 2009-03-16 07:09:23 611,392 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll
+ 2009-03-15 17:46:47 43,840 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.FormControl\12.0.0.0__71e9bce111e9429c\microsoft.office.infopath.formcontrol.dll
+ 2009-03-15 17:46:48 39,728 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Vsta\12.0.0.0__71e9bce111e9429c\Microsoft.Office.InfoPath.Vsta.dll
+ 2009-03-15 17:46:48 60,200 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.dll
+ 2009-03-15 17:46:53 211,736 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Adapter\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Adapter.dll
+ 2009-03-15 17:46:53 105,248 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.AddInManager\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.AddInManager.dll
+ 2009-03-15 17:46:52 330,520 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Blueprints\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Blueprints.dll
+ 2009-03-15 17:46:53 39,712 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel.dll
+ 2009-03-15 17:46:53 39,704 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Contract\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Contract.dll
+ 2009-03-15 17:46:52 72,472 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.DesignTime\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.DesignTime.dll
+ 2009-03-15 17:46:53 47,832 —-a-w C:\WINDOWS\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
+ 2009-03-15 17:46:53 39,624 —-a-w C:\WINDOWS\assembly\GAC_MSIL\System.AddIn\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.dll
+ 2008-10-15 17:12:18 279,160 —-a-w C:\WINDOWS\Downloaded Program Files\Conflict.0\f5instd.exe
+ 2008-10-15 17:10:30 115,320 —-a-w C:\WINDOWS\Downloaded Program Files\Conflict.0\F5InstH.exe
+ 2008-10-15 17:10:32 33,400 —-a-w C:\WINDOWS\Downloaded Program Files\Conflict.0\F5InstP.dll
+ 2008-10-15 17:12:20 262,776 —-a-w C:\WINDOWS\Downloaded Program Files\Conflict.0\InstallerControl.dll
- 2007-12-13 17:08:02 21,120 —-a-w C:\WINDOWS\Downloaded Program Files\F5ElHelper.dll
+ 2008-10-15 17:06:46 22,136 —-a-w C:\WINDOWS\Downloaded Program Files\F5ElHelper.dll
- 2007-12-13 17:08:00 135,296 —-a-w C:\WINDOWS\Downloaded Program Files\F5ElHelper.exe
+ 2008-10-15 17:06:44 137,336 —-a-w C:\WINDOWS\Downloaded Program Files\F5ElHelper.exe
+ 2009-02-02 23:07:40 1,914,440 —-a-w C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
- 2007-12-13 17:09:00 319,616 —-a-w C:\WINDOWS\Downloaded Program Files\urSuperHost.dll
+ 2008-10-15 17:07:46 322,680 —-a-w C:\WINDOWS\Downloaded Program Files\urSuperHost.dll
- 2007-12-13 17:05:26 1,080,960 —-a-w C:\WINDOWS\Downloaded Program Files\urTermProxy.dll
+ 2008-10-15 17:03:38 1,083,512 —-a-w C:\WINDOWS\Downloaded Program Files\urTermProxy.dll
- 2007-12-13 17:08:02 423,552 —-a-w C:\WINDOWS\Downloaded Program Files\urxhost.dll
+ 2008-10-15 17:06:46 431,224 —-a-w C:\WINDOWS\Downloaded Program Files\urxhost.dll
- 2007-12-13 17:08:02 59,520 —-a-w C:\WINDOWS\Downloaded Program Files\urxhostres.dll
+ 2008-10-15 17:06:48 64,120 —-a-w C:\WINDOWS\Downloaded Program Files\urxhostres.dll
- 2007-12-13 17:05:26 66,176 —-a-w C:\WINDOWS\Downloaded Program Files\utunres.dll
+ 2008-10-15 17:03:38 66,168 —-a-w C:\WINDOWS\Downloaded Program Files\utunres.dll
- 2005-10-21 01:02:28 163,328 —-a-w C:\WINDOWS\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 00:02:28 163,328 —-a-w C:\WINDOWS\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 —-a-w C:\WINDOWS\ERDNT\subs\ERDNT.EXE
+ 2008-10-16 20:38:34 124,928 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\advpack.dll
+ 2008-10-16 20:38:34 347,136 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\dxtmsft.dll
+ 2008-10-16 20:38:34 214,528 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\dxtrans.dll
+ 2008-10-16 20:38:35 133,120 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\extmgr.dll
+ 2008-10-16 20:38:35 63,488 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\icardie.dll
+ 2008-10-16 13:11:09 70,656 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ie4uinit.exe
+ 2008-10-16 20:38:35 153,088 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieakeng.dll
+ 2008-10-16 20:38:35 230,400 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieaksie.dll
+ 2008-10-15 07:04:53 161,792 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieakui.dll
+ 2008-10-16 20:38:35 383,488 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieapfltr.dll
+ 2008-10-16 20:38:35 384,512 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\iedkcs32.dll
+ 2008-10-16 20:38:37 6,066,176 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieframe.dll
+ 2008-10-16 20:38:37 44,544 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\iernonce.dll
+ 2008-10-16 20:38:37 267,776 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\iertutil.dll
+ 2008-10-16 13:11:09 13,824 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\ieudinit.exe
+ 2008-10-15 07:06:26 633,632 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
+ 2008-10-16 20:38:37 27,648 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\jsproxy.dll
+ 2008-10-16 20:38:37 459,264 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\msfeeds.dll
+ 2008-10-16 20:38:37 52,224 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\msfeedsbs.dll
+ 2008-12-13 06:40:02 3,593,216 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\mshtml.dll
+ 2008-10-16 20:38:38 477,696 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\mshtmled.dll
+ 2008-10-16 20:38:38 193,024 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\msrating.dll
+ 2008-10-16 20:38:39 671,232 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\mstime.dll
+ 2008-10-16 20:38:39 102,912 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\occache.dll
+ 2008-10-16 20:38:39 44,544 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\pngfilt.dll
+ 2007-03-06 01:22:41 213,216 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\updspapi.dll
+ 2008-10-16 20:38:39 105,984 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\url.dll
+ 2008-10-16 20:38:39 1,160,192 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\urlmon.dll
+ 2008-10-16 20:38:39 233,472 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\webcheck.dll
+ 2008-10-16 20:38:40 826,368 -c—-w C:\WINDOWS\ie7updates\KB961260-IE7\wininet.dll
+ 2006-10-26 23:49:48 1,011,488 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109010090400000000000F01FEC\12.0.4518\MSDAIPP.DLL
+ 2006-10-26 23:49:46 970,528 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109010090400000000000F01FEC\12.0.4518\MSONSEXT.DLL
+ 2006-10-27 19:00:10 576,376 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACACEDAO.DLL
+ 2006-10-27 01:18:12 162,616 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACCWIZ.DLL
+ 2006-10-27 19:00:12 1,751,904 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACECORE.DLL
+ 2006-10-27 19:00:10 576,376 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEDAO.DLL
+ 2006-10-27 19:00:06 47,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEERR.DLL
+ 2006-10-27 19:00:08 191,360 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEES.DLL
+ 2006-10-27 00:13:34 338,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEEXCH.DLL
+ 2006-10-27 00:13:44 629,616 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEEXCL.DLL
+ 2006-10-27 00:13:28 207,736 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACELTS.DLL
+ 2006-10-27 00:13:32 279,352 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODBC.DLL
+ 2006-10-27 00:13:08 15,160 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODDBS.DLL
+ 2006-10-27 00:13:08 15,160 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODEXL.DLL
+ 2006-10-27 00:13:08 15,160 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODPDX.DLL
+ 2006-10-27 00:13:12 15,160 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODTXT.DLL
+ 2006-10-27 19:00:06 387,960 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEOLEDB.DLL
+ 2006-10-27 00:13:38 392,048 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEPDE.DLL
+ 2006-10-27 00:13:30 260,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACER2X.DLL
+ 2006-10-27 00:13:32 289,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACER3X.DLL
+ 2006-10-27 00:13:20 56,120 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACERCLR.DLL
+ 2006-10-27 00:13:38 551,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEREP.DLL
+ 2006-10-27 00:13:30 224,104 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACETXT.DLL
+ 2006-10-27 19:40:34 208,760 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEWSS.DLL
+ 2006-10-27 00:13:34 371,568 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEXBE.DLL
+ 2006-10-27 19:41:04 399,640 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CDLMSO.DLL
+ 2006-10-26 23:59:24 205,616 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CLVIEW.EXE
+ 2006-10-27 01:30:42 65,312 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\COLLIMP.DLL
+ 2006-10-27 19:16:36 133,936 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CONTAB32.DLL
+ 2006-10-27 00:12:52 189,760 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CONTACTPICKER.DLL
+ 2006-10-27 00:55:32 87,344 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DLGSETP.DLL
+ 2006-10-27 04:48:08 234,784 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DRAT.EXE
+ 2006-10-26 23:48:14 439,568 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DWDCW20.DLL
+ 2006-10-26 23:48:14 434,528 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DWTRIG20.EXE
+ 2006-10-27 19:07:36 17,891,112 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EXCEL.EXE
+ 2006-10-26 18:10:08 1,190,688 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FM20.DLL
+ 2006-10-26 18:04:58 75,576 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FORM.DLL
+ 2006-10-26 23:21:24 1,682,232 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FPSRVUTL.DLL
+ 2006-10-27 19:09:36 983,376 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FPWEC.DLL
+ 2006-10-27 00:02:12 2,526,520 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GRAPH.EXE
+ 2006-10-27 19:37:44 338,216 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVE.EXE
+ 2006-10-27 19:38:02 6,191,400 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEACCOUNTMGR.DLL
+ 2006-10-27 19:37:44 284,448 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEAUDIO.DLL
+ 2006-10-27 04:47:54 65,824 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEAUDITSERVICE.EXE
+ 2006-10-27 19:37:40 34,088 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEAUTOPROXY.DLL
+ 2006-10-27 19:37:44 300,336 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECALENDARTOOL.DLL
+ 2006-10-27 04:47:44 33,568 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECLEAN.EXE
+ 2006-10-27 19:37:56 2,689,336 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMONCOMPONENTS.DLL
+ 2006-10-27 19:38:00 3,508,544 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMUNICATIONSSERVICES.DLL
+ 2006-10-27 19:37:40 117,584 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMUNICATIONSSTATUSANDCONTROL.DLL
+ 2006-10-27 19:37:50 768,304 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMPONENTMGR.DLL
+ 2006-10-27 19:37:52 1,359,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECRYPTO.DLL
+ 2006-10-27 04:48:24 377,136 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEDATAVIEWERTOOL.DLL
+ 2006-10-27 19:37:58 3,071,288 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEDOCUMENTSHARETOOL.DLL
+ 2006-10-27 19:37:44 284,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEFETCHSERVICES.DLL
+ 2006-10-27 04:48:00 197,920 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEGAMES.DLL
+ 2006-10-27 04:48:18 317,736 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEMIGRATOR.EXE
+ 2006-10-27 04:48:40 1,555,232 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEMISC.DLL
+ 2006-10-27 04:47:42 31,016 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEMONITOR.EXE
+ 2006-10-27 04:47:40 22,808 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVENEW.DLL
+ 2006-10-27 04:48:02 224,048 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEPROJECTTOOLSET.DLL
+ 2006-10-27 19:38:04 7,053,096 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVERESOURCE.DLL
+ 2006-10-27 04:48:42 2,210,608 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESHELLEXTENSIONS.DLL
+ 2006-10-27 04:48:18 363,304 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESKETCHTOOL.DLL
+ 2006-10-27 04:47:40 16,688 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESTDURLLAUNCHER.EXE
+ 2006-10-27 19:37:56 2,738,472 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESTORAGEMGR.DLL
+ 2006-10-27 19:37:38 35,112 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESYSTEMMODE.DLL
+ 2006-10-27 04:48:02 222,512 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESYSTEMSERVICES.DLL
+ 2006-10-27 19:37:50 1,163,048 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVETEXTTOOLS.DLL
+ 2006-10-27 19:38:00 4,746,536 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVETRANSCEIVER.DLL
+ 2006-10-27 19:37:54 1,396,008 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEUIFRAMEWORK.DLL
+ 2006-10-27 04:48:34 955,680 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEUTIL.DLL
+ 2006-10-27 19:37:40 268,080 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEWEBBROWSERTOOL2.DLL
+ 2006-10-27 04:48:26 572,216 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEWEBPLATFORMSERVICES.DLL
+ 2006-10-27 19:37:48 631,080 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEWEBSERVICES.DLL
+ 2006-10-27 00:12:52 173,328 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IEAWSDC.DLL
+ 2006-10-27 00:55:38 138,024 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IMPMAIL.DLL
+ 2006-10-27 19:10:08 1,439,032 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\INFOPATH.EXE
+ 2006-10-27 19:10:10 5,456,704 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPDESIGN.DLL
+ 2006-10-27 19:10:10 5,281,592 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPEDITOR.DLL
+ 2006-10-27 01:42:00 176,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPOLK.DLL
+ 2009-03-15 17:46:47 609,104 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPOMHOST.DLL
+ 2009-03-15 17:46:48 118,112 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPOMINT.DLL
+ 2006-10-26 23:55:10 828,704 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MEDCAT.DLL
+ 2006-10-27 00:55:48 340,248 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MIMEDIR.DLL
+ 2006-10-27 19:04:08 497,504 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MORPH9.DLL
+ 2006-10-27 19:01:34 10,371,880 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSACCESS.EXE
+ 2006-10-27 01:18:06 66,880 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSAEXP30.DLL
+ 2006-10-26 17:58:14 117,552 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSCONV97.DLL
+ 2006-10-27 19:26:40 16,870,712 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSO.DLL
+ 2006-10-27 18:59:06 161,080 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOCF.DLL
+ 2006-10-26 23:48:12 14,664 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOCFU.DLL
+ 2006-10-27 00:12:58 428,816 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSODCW.DLL
+ 2006-10-27 01:13:36 26,936 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOEURO.DLL
+ 2006-10-27 00:00:08 6,635,320 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSORES.DLL
+ 2006-10-26 17:56:36 436,520 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSORUN.DLL
+ 2006-10-27 19:04:10 9,581,360 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSPUB.EXE
+ 2006-10-26 23:50:04 672,024 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSQRY32.EXE
+ 2006-10-26 17:56:40 505,136 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSSOAP30.DLL
+ 2006-10-26 23:55:12 832,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSTORDB.EXE
+ 2006-10-26 23:55:06 538,904 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSTORES.DLL
+ 2006-10-27 00:12:30 65,824 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\NAME.DLL
+ 2006-10-27 19:14:34 14,151,456 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OART.DLL
+ 2006-10-27 00:06:54 232,816 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ODEPLOY.EXE
+ 2006-10-27 00:14:06 7,033,152 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OFFOWC.DLL
+ 2006-10-27 19:18:36 1,658,152 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OGL.DLL
+ 2006-10-27 00:00:08 274,744 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OIS.EXE
+ 2006-10-27 00:00:12 998,208 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OISAPP.DLL
+ 2006-10-27 00:00:10 285,008 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OISGRAPH.DLL
+ 2006-10-27 19:16:46 2,939,704 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OLMAPI32.DLL
+ 2006-10-27 00:34:12 660,792 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OMSMAIN.DLL
+ 2006-10-27 00:34:10 192,848 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OMSXP32.DLL
+ 2006-10-27 00:32:42 604,000 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONBTTNIE.DLL
+ 2006-10-27 19:39:36 687,432 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONBTTNOL.DLL
+ 2006-10-27 19:03:04 1,018,664 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONENOTE.EXE
+ 2006-10-27 00:24:54 98,632 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONENOTEM.EXE
+ 2006-10-27 00:24:50 72,504 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONFILTER.DLL
+ 2006-10-27 00:24:58 1,165,112 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONLIBS.DLL
+ 2006-10-27 19:03:06 6,579,512 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONMAIN.DLL
+ 2006-10-27 00:23:00 782,720 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONSYNCPC.DLL
+ 2006-10-27 00:07:04 6,536,992 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OSETUP.DLL
+ 2006-09-15 20:25:18 3,611,416 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLFLTR.DAT
+ 2006-07-26 22:53:56 459,080 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLFLTR.DLL
+ 2006-10-27 19:16:44 594,256 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLMIME.DLL
+ 2006-10-27 19:16:48 12,813,096 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLOOK.EXE
+ 2006-10-27 19:16:40 176,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLPH.DLL
+ 2006-10-27 19:16:36 46,864 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLRPC.DLL
+ 2006-10-27 01:30:44 482,088 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PORTCONN.DLL
+ 2006-10-27 19:04:06 465,200 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\POWERPNT.EXE
+ 2006-10-27 19:04:06 7,980,848 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPCORE.DLL
+ 2009-03-15 17:45:29 248,632 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPTPIA.DLL
+ 2006-10-26 23:52:10 2,012,480 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPTVIEW.EXE
+ 2006-10-27 00:09:36 136,008 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PRTF9.DLL
+ 2006-10-26 18:05:00 77,144 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PSOM.DLL
+ 2006-10-27 00:55:54 413,472 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PSTPRX32.DLL
+ 2006-10-27 19:04:06 624,456 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PTXT9.DLL
+ 2006-10-27 00:09:44 590,144 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PUBCONV.DLL
+ 2006-10-27 01:13:38 38,168 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REFEDIT.DLL
+ 2006-10-27 01:42:12 744,808 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REGFORM.EXE
+ 2006-10-26 18:04:44 19,784 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REVERSE.DLL
+ 2006-10-27 00:55:44 263,520 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SCNPST32.DLL
+ 2006-10-27 00:55:44 272,744 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SCNPST64.DLL
+ 2006-10-27 00:13:00 503,624 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SELFCERT.EXE
+ 2006-10-27 00:06:58 439,600 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SETUP.EXE
+ 2006-10-27 01:18:16 502,608 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SOA.DLL
+ 2006-07-28 19:21:58 277,320 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SSGEN.DLL
+ 2006-10-27 18:57:08 2,330,968 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\STSLIST.DLL
+ 2006-10-26 18:04:48 29,976 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\THOCRAPI.DLL
+ 2006-10-26 18:05:04 126,784 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWCUTCHR.DLL
+ 2006-10-26 18:05:02 86,840 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWCUTLIN.DLL
+ 2006-10-26 18:04:56 58,168 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWLAY32.DLL
+ 2006-10-26 18:04:48 27,456 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWORIENT.DLL
+ 2006-10-26 18:04:54 51,008 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWRECE.DLL
+ 2006-10-26 18:04:44 19,784 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWRECS.DLL
+ 2006-10-26 18:04:58 76,624 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWSTRUCT.DLL
+ 2006-09-30 04:42:56 2,583,344 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VBE6.DLL
+ 2006-10-27 03:00:12 1,841,984 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VVIEWDWG.DLL
+ 2006-10-27 02:58:38 3,732,792 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VVIEWER.DLL
+ 2006-10-27 19:23:04 347,432 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WINWORD.EXE
+ 2009-03-15 17:45:29 781,104 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WORDPIA.DLL
+ 2006-10-27 19:23:08 17,483,560 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WWLIB.DLL
+ 2006-10-26 18:05:08 1,181,520 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XIMAGE3B.DLL
+ 2006-10-27 01:17:08 11,072 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XLCALL32.DLL
+ 2006-10-26 18:05:08 530,760 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XPAGE3C.DLL
+ 2007-10-06 00:37:38 17,927,192 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\EXCEL.EXE
+ 2007-08-29 03:38:10 500,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MORPH9.DLL
+ 2007-09-15 01:45:58 16,901,168 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSO.DLL
+ 2007-08-29 03:38:46 9,584,512 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSPUB.EXE
+ 2007-10-03 00:51:22 8,436,776 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OARTCONV.DLL
+ 2007-08-29 04:19:24 1,654,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OGL.DLL
+ 2007-08-29 03:06:16 467,840 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\POWERPNT.EXE
+ 2007-08-29 03:06:44 7,990,144 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PPCORE.DLL
+ 2009-03-16 07:10:03 251,272 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PPTPIA.DLL
+ 2007-08-24 07:43:28 138,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PRTF9.DLL
+ 2007-08-29 03:39:14 625,560 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PTXT9.DLL
+ 2007-08-24 07:43:36 593,296 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PUBCONV.DLL
+ 2007-08-29 03:16:00 350,064 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\WINWORD.EXE
+ 2007-09-06 21:56:32 17,490,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\WWLIB.DLL
+ 2007-08-24 09:14:14 13,712 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\XLCALL32.DLL
+ 2009-03-16 07:22:34 1,165,584 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-03-16 07:22:35 20,240 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-03-16 07:22:34 159,504 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2009-03-16 07:22:34 184,080 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-03-16 07:22:34 217,864 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-03-16 07:22:35 18,704 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-03-16 07:22:35 35,088 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-03-16 07:22:34 845,584 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2009-03-16 07:22:34 922,384 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-03-16 07:22:35 272,648 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2009-03-16 07:22:35 888,080 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-03-16 07:22:34 1,172,240 —-a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-03-16 07:14:12 217,864 —-a-r C:\WINDOWS\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2005-03-18 20:23:10 53,248 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2005-03-18 20:23:10 12,800 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Diagnostics.dll
+ 2005-03-18 20:23:14 473,600 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3D.dll
+ 2004-09-29 16:38:58 2,676,224 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-03-18 20:23:10 145,920 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectDraw.dll
+ 2005-03-18 20:23:10 159,232 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectInput.dll
+ 2005-03-18 20:23:14 364,544 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectPlay.dll
+ 2005-03-18 20:23:12 178,176 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectSound.dll
+ 2005-03-18 20:23:14 223,232 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.dll
+ 2004-12-01 19:53:06 2,846,720 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-02-05 23:32:54 563,712 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-03-18 21:23:14 567,296 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-05-26 19:15:56 576,000 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-07-22 21:21:34 577,024 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-09-28 18:11:52 577,536 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-12-05 21:20:50 577,536 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll
+ 2006-02-03 11:40:48 578,560 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2910.0\Microsoft.DirectX.Direct3DX.dll
+ 2006-03-31 15:27:50 578,560 —-a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\Microsoft.DirectX.Direct3DX.dll
- 2000-08-31 13:00:00 29,696 —-a-w C:\WINDOWS\NIRCMD.exe
+ 2000-08-31 12:00:00 29,696 —-a-w C:\WINDOWS\NIRCMD.exe
- 2000-08-31 13:00:00 161,792 —-a-w C:\WINDOWS\SWREG.exe
+ 2000-08-31 12:00:00 161,792 —-a-w C:\WINDOWS\SWREG.exe
- 2008-10-16 20:38:34 124,928 —-a-w C:\WINDOWS\system32\advpack.dll
+ 2008-12-20 23:15:11 124,928 —-a-w C:\WINDOWS\system32\advpack.dll
- 2009-01-15 00:00:57 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2009-04-11 12:20:49 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2009-04-05 20:01:30 10,027 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\~tempinfo.dat
+ 2009-04-11 04:33:03 297,691 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\clkw.exe
+ 2009-04-11 06:35:09 301,828 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\minisvr4.exe
+ 2009-04-11 09:17:03 465,874 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\part.exe
+ 2009-04-11 09:58:18 364,657 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\websvr.exe
- 2009-01-15 00:00:57 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-04-11 12:20:49 49,152 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-04-11 03:52:25 32,768 –sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009041020090411\index.dat
+ 2009-04-10 18:10:24 32,768 –sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009041120090412\index.dat
+ 2009-04-10 18:24:16 78,924 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat
+ 2009-04-10 18:10:50 297,691 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8XIBK92J\clkw[1].exe
+ 2009-04-10 23:26:54 301,828 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8XIBK92J\minisvr4[1].exe
+ 2009-04-10 18:57:37 364,657 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8XIBK92J\websvr[1].exe
+ 2009-04-11 02:20:11 465,874 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GPAN41UJ\part[1].exe
- 2009-01-15 00:00:57 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-04-11 12:20:49 147,456 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-03-12 20:42:30 1,123,696 —-a-w C:\WINDOWS\system32\D3DCompiler_33.dll
+ 2007-05-16 20:45:16 1,124,720 —-a-w C:\WINDOWS\system32\D3DCompiler_34.dll
+ 2007-03-15 20:57:58 443,752 —-a-w C:\WINDOWS\system32\d3dx10_33.dll
+ 2007-05-16 20:45:16 443,752 —-a-w C:\WINDOWS\system32\d3dx10_34.dll
+ 2005-02-05 23:45:26 2,222,800 —-a-w C:\WINDOWS\system32\d3dx9_24.dll
+ 2005-03-18 21:19:58 2,337,488 —-a-w C:\WINDOWS\system32\d3dx9_25.dll
+ 2005-05-26 19:34:52 2,297,552 —-a-w C:\WINDOWS\system32\d3dx9_26.dll
+ 2005-07-22 23:59:04 2,319,568 —-a-w C:\WINDOWS\system32\d3dx9_27.dll
+ 2005-12-05 22:09:18 2,323,664 —-a-w C:\WINDOWS\system32\d3dx9_28.dll
+ 2006-02-03 12:43:16 2,332,368 —-a-w C:\WINDOWS\system32\d3dx9_29.dll
+ 2006-03-31 16:40:58 2,388,176 —-a-w C:\WINDOWS\system32\d3dx9_30.dll
+ 2006-09-28 20:05:20 2,414,360 —-a-w C:\WINDOWS\system32\d3dx9_31.dll
+ 2007-03-12 20:42:30 3,495,784 —-a-w C:\WINDOWS\system32\d3dx9_33.dll
+ 2007-05-16 20:45:16 3,497,832 —-a-w C:\WINDOWS\system32\d3dx9_34.dll
- 2008-10-16 20:38:34 124,928 -c—-w C:\WINDOWS\system32\dllcache\advpack.dll
+ 2008-12-20 23:15:11 124,928 -c–a-w C:\WINDOWS\system32\dllcache\advpack.dll
- 2008-10-16 20:38:34 347,136 -c–a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 -c–a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2008-10-16 20:38:34 214,528 -c–a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-12-20 23:15:13 214,528 -c–a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
- 2008-10-16 20:38:35 133,120 -c–a-w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-12-20 23:15:13 133,120 -c–a-w C:\WINDOWS\system32\dllcache\extmgr.dll
- 2008-10-16 20:38:35 63,488 -c—-w C:\WINDOWS\system32\dllcache\icardie.dll
+ 2008-12-20 23:15:13 63,488 -c–a-w C:\WINDOWS\system32\dllcache\icardie.dll
- 2008-10-16 13:11:09 70,656 -c—-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
+ 2008-12-19 09:10:15 70,656 -c–a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
- 2008-10-16 20:38:35 153,088 -c—-w C:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 -c–a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
- 2008-10-16 20:38:35 230,400 -c—-w C:\WINDOWS\system32\dllcache\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 -c–a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
- 2008-10-15 07:04:53 161,792 -c–a-w C:\WINDOWS\system32\dllcache\ieakui.dll
+ 2008-12-19 05:23:56 161,792 -c–a-w C:\WINDOWS\system32\dllcache\ieakui.dll
- 2008-10-16 20:38:35 383,488 -c—-w C:\WINDOWS\system32\dllcache\ieapfltr.dll
+ 2008-12-20 23:15:15 383,488 -c–a-w C:\WINDOWS\system32\dllcache\ieapfltr.dll
- 2008-10-16 20:38:35 384,512 -c—-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 -c–a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
- 2008-10-16 20:38:37 6,066,176 -c—-w C:\WINDOWS\system32\dllcache\ieframe.dll
+ 2008-12-20 23:15:21 6,066,688 -c–a-w C:\WINDOWS\system32\dllcache\ieframe.dll
- 2008-10-16 20:38:37 44,544 -c—-w C:\WINDOWS\system32\dllcache\iernonce.dll
+ 2008-12-20 23:15:21 44,544 -c–a-w C:\WINDOWS\system32\dllcache\iernonce.dll
- 2008-10-16 20:38:37 267,776 -c—-w C:\WINDOWS\system32\dllcache\iertutil.dll
+ 2008-12-20 23:15:22 267,776 -c–a-w C:\WINDOWS\system32\dllcache\iertutil.dll
- 2008-10-16 13:11:09 13,824 -c—-w C:\WINDOWS\system32\dllcache\ieudinit.exe
+ 2008-12-19 09:10:15 13,824 -c–a-w C:\WINDOWS\system32\dllcache\ieudinit.exe
- 2008-10-15 07:06:26 633,632 -c—-w C:\WINDOWS\system32\dllcache\iexplore.exe
+ 2008-12-19 05:25:25 634,024 -c–a-w C:\WINDOWS\system32\dllcache\iexplore.exe
- 2008-10-16 20:38:37 27,648 -c–a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-12-20 23:15:23 27,648 -c–a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
- 2008-10-16 20:38:37 459,264 -c—-w C:\WINDOWS\system32\dllcache\msfeeds.dll
+ 2008-12-20 23:15:23 459,264 -c–a-w C:\WINDOWS\system32\dllcache\msfeeds.dll
- 2008-10-16 20:38:37 52,224 -c—-w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 -c–a-w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
- 2008-12-13 06:40:02 3,593,216 -c–a-w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2009-01-17 02:35:14 3,594,752 -c–a-w C:\WINDOWS\system32\dllcache\mshtml.dll
- 2008-10-16 20:38:38 477,696 -c–a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 -c–a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2008-10-16 20:38:38 193,024 -c–a-w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-12-20 23:15:31 193,024 -c–a-w C:\WINDOWS\system32\dllcache\msrating.dll
- 2008-10-16 20:38:39 671,232 -c–a-w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-12-20 23:15:32 671,232 -c–a-w C:\WINDOWS\system32\dllcache\mstime.dll
- 2008-10-16 20:38:39 102,912 -c—-w C:\WINDOWS\system32\dllcache\occache.dll
+ 2008-12-20 23:15:38 102,912 -c–a-w C:\WINDOWS\system32\dllcache\occache.dll
- 2008-10-16 20:38:39 44,544 -c–a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 -c–a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
- 2007-04-25 14:21:15 144,896 -c—-w C:\WINDOWS\system32\dllcache\schannel.dll
+ 2008-12-05 07:12:45 144,896 -c–a-w C:\WINDOWS\system32\dllcache\schannel.dll
- 2007-10-26 03:34:01 8,460,288 -c–a-w C:\WINDOWS\system32\dllcache\shell32.dll
+ 2008-07-03 13:03:29 8,460,800 -c–a-w C:\WINDOWS\system32\dllcache\shell32.dll
- 2008-10-16 20:38:39 105,984 -c—-w C:\WINDOWS\system32\dllcache\url.dll
+ 2008-12-20 23:15:39 105,984 -c–a-w C:\WINDOWS\system32\dllcache\url.dll
- 2008-10-16 20:38:39 1,160,192 -c–a-w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 -c–a-w C:\WINDOWS\system32\dllcache\urlmon.dll
- 2008-10-16 20:38:39 233,472 -c—-w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2008-12-20 23:15:40 233,472 -c–a-w C:\WINDOWS\system32\dllcache\webcheck.dll
- 2008-09-15 11:57:41 1,846,016 -c—-w C:\WINDOWS\system32\dllcache\win32k.sys
+ 2009-02-09 10:19:34 1,846,272 -c–a-w C:\WINDOWS\system32\dllcache\win32k.sys
- 2008-10-16 20:38:40 826,368 -c–a-w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-12-20 23:15:41 826,368 -c–a-w C:\WINDOWS\system32\dllcache\wininet.dll
- 2007-04-23 00:15:25 36,624 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
+ 2008-07-31 22:17:04 43,872 —-a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
- 2008-10-16 20:38:34 347,136 —-a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 —-a-w C:\WINDOWS\system32\dxtmsft.dll
- 2008-10-16 20:38:34 214,528 —-a-w C:\WINDOWS\system32\dxtrans.dll
+ 2008-12-20 23:15:13 214,528 —-a-w C:\WINDOWS\system32\dxtrans.dll
- 2008-10-16 20:38:35 133,120 —-a-w C:\WINDOWS\system32\extmgr.dll
+ 2008-12-20 23:15:13 133,120 —-a-w C:\WINDOWS\system32\extmgr.dll
- 2007-06-06 14:53:34 1,195,888 —-a-w C:\WINDOWS\system32\FM20.DLL
+ 2007-08-23 05:03:38 1,195,888 —-a-w C:\WINDOWS\system32\FM20.DLL
- 2007-03-22 23:17:04 35,440 —-a-w C:\WINDOWS\system32\FM20ENU.DLL
+ 2006-10-26 18:10:06 33,088 —-a-w C:\WINDOWS\system32\FM20ENU.DLL
- 2008-10-16 07:12:40 290,888 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2009-03-16 07:30:06 272,576 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2009-04-10 02:48:20 51,200 –sha-w C:\WINDOWS\system32\fuhaleke.exe
- 2008-10-16 20:38:35 63,488 —-a-w C:\WINDOWS\system32\icardie.dll
+ 2008-12-20 23:15:13 63,488 —-a-w C:\WINDOWS\system32\icardie.dll
- 2008-10-16 13:11:09 70,656 —-a-w C:\WINDOWS\system32\ie4uinit.exe
+ 2008-12-19 09:10:15 70,656 —-a-w C:\WINDOWS\system32\ie4uinit.exe
- 2008-10-16 20:38:35 153,088 —-a-w C:\WINDOWS\system32\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 —-a-w C:\WINDOWS\system32\ieakeng.dll
- 2008-10-16 20:38:35 230,400 —-a-w C:\WINDOWS\system32\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 —-a-w C:\WINDOWS\system32\ieaksie.dll
- 2008-10-15 07:04:53 161,792 —-a-w C:\WINDOWS\system32\ieakui.dll
+ 2008-12-19 05:23:56 161,792 —-a-w C:\WINDOWS\system32\ieakui.dll
- 2008-10-16 20:38:35 383,488 —-a-w C:\WINDOWS\system32\ieapfltr.dll
+ 2008-12-20 23:15:15 383,488 —-a-w C:\WINDOWS\system32\ieapfltr.dll
- 2008-10-16 20:38:35 384,512 —-a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 —-a-w C:\WINDOWS\system32\iedkcs32.dll
- 2008-10-16 20:38:37 6,066,176 —-a-w C:\WINDOWS\system32\ieframe.dll
+ 2008-12-20 23:15:21 6,066,688 —-a-w C:\WINDOWS\system32\ieframe.dll
- 2008-10-16 20:38:37 44,544 —-a-w C:\WINDOWS\system32\iernonce.dll
+ 2008-12-20 23:15:21 44,544 —-a-w C:\WINDOWS\system32\iernonce.dll
- 2008-10-16 20:38:37 267,776 —-a-w C:\WINDOWS\system32\iertutil.dll
+ 2008-12-20 23:15:22 267,776 —-a-w C:\WINDOWS\system32\iertutil.dll
- 2008-10-16 13:11:09 13,824 —-a-w C:\WINDOWS\system32\ieudinit.exe
+ 2008-12-19 09:10:15 13,824 —-a-w C:\WINDOWS\system32\ieudinit.exe
- 2002-08-21 10:10:16 204,800 —-a-w C:\WINDOWS\system32\INKED.DLL
+ 2006-10-26 17:45:04 207,360 —-a-w C:\WINDOWS\system32\INKED.DLL
- 2008-10-16 20:38:37 27,648 —-a-w C:\WINDOWS\system32\jsproxy.dll
+ 2008-12-20 23:15:23 27,648 —-a-w C:\WINDOWS\system32\jsproxy.dll
+ 2003-11-04 20:10:36 98,304 —-a-w C:\WINDOWS\system32\lffax13n.dll
+ 2003-11-04 20:11:32 155,648 —-a-w C:\WINDOWS\system32\lftif13n.dll
+ 2003-12-12 21:06:30 1,693,696 —-a-w C:\WINDOWS\system32\ltclr13n.dll
+ 2009-02-03 02:07:18 240,544 —-a-r C:\WINDOWS\system32\Macromed\Flash\FlashUtil10b.exe
- 2005-08-27 18:08:06 1,398,408 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
+ 2009-02-03 02:15:28 3,771,296 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
+ 2009-02-03 02:15:30 240,544 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
- 2008-10-02 05:44:06 74,137 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-02-28 17:44:07 89,102 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-03-11 17:45:34 84,661 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
- 2008-10-16 20:38:37 459,264 —-a-w C:\WINDOWS\system32\msfeeds.dll
+ 2008-12-20 23:15:23 459,264 —-a-w C:\WINDOWS\system32\msfeeds.dll
- 2008-10-16 20:38:37 52,224 —-a-w C:\WINDOWS\system32\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 —-a-w C:\WINDOWS\system32\msfeedsbs.dll
- 2008-12-13 06:40:02 3,593,216 —-a-w C:\WINDOWS\system32\mshtml.dll
+ 2009-01-17 02:35:14 3,594,752 —-a-w C:\WINDOWS\system32\mshtml.dll
- 2008-10-16 20:38:38 477,696 —-a-w C:\WINDOWS\system32\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 —-a-w C:\WINDOWS\system32\mshtmled.dll
- 2008-10-16 20:38:38 193,024 —-a-w C:\WINDOWS\system32\msrating.dll
+ 2008-12-20 23:15:31 193,024 —-a-w C:\WINDOWS\system32\msrating.dll
- 2000-07-15 05:00:00 118,784 —-a-w C:\WINDOWS\system32\MSSTDFMT.DLL
+ 2006-07-24 14:50:38 125,744 —-a-w C:\WINDOWS\system32\MSSTDFMT.DLL
- 2008-10-16 20:38:39 671,232 —-a-w C:\WINDOWS\system32\mstime.dll
+ 2008-12-20 23:15:32 671,232 —-a-w C:\WINDOWS\system32\mstime.dll
- 2008-10-16 20:38:39 102,912 —-a-w C:\WINDOWS\system32\occache.dll
+ 2008-12-20 23:15:38 102,912 —-a-w C:\WINDOWS\system32\occache.dll
- 2008-11-13 11:53:45 64,404 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2009-04-01 01:18:16 65,248 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-11-13 11:53:45 408,000 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2009-04-01 01:18:16 410,904 —-a-w C:\WINDOWS\system32\perfh009.dat
- 2008-10-16 20:38:39 44,544 —-a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 —-a-w C:\WINDOWS\system32\pngfilt.dll
- 2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
+ 2008-12-05 07:12:45 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
- 1998-03-25 01:54:08 15,872 —-a-w C:\WINDOWS\system32\SCP32.DLL
+ 2006-07-24 14:50:40 39,728 —-a-w C:\WINDOWS\system32\SCP32.DLL
- 2007-10-26 03:34:01 8,460,288 —-a-w C:\WINDOWS\system32\shell32.dll
+ 2008-07-03 13:03:29 8,460,800 —-a-w C:\WINDOWS\system32\shell32.dll
- 2007-11-30 12:39:22 17,272 ——w C:\WINDOWS\system32\spmsg.dll
+ 2008-07-09 07:38:24 17,272 ——w C:\WINDOWS\system32\spmsg.dll
+ 2006-10-26 23:56:16 864,080 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\msonpdrv.dll
+ 2006-10-26 23:56:14 67,408 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\msonpui.dll
+ 2006-10-26 23:56:16 864,080 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\msonpdrv.dll
+ 2006-10-26 23:56:14 67,408 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\msonpui.dll
+ 2006-10-26 23:56:12 33,104 —-a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
- 2006-10-16 21:10:58 23,856 —-a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2007-07-27 13:41:38 26,488 —-a-w C:\WINDOWS\system32\spupdsvc.exe
- 2008-10-16 20:38:39 105,984 —-a-w C:\WINDOWS\system32\url.dll
+ 2008-12-20 23:15:39 105,984 —-a-w C:\WINDOWS\system32\url.dll
- 2008-10-16 20:38:39 1,160,192 —-a-w C:\WINDOWS\system32\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 —-a-w C:\WINDOWS\system32\urlmon.dll
- 1998-12-24 16:23:22 40,960 —-a-w C:\WINDOWS\system32\VBAME.DLL
+ 2006-07-24 14:50:40 47,920 —-a-w C:\WINDOWS\system32\VBAME.DLL
- 2008-10-16 20:38:39 233,472 —-a-w C:\WINDOWS\system32\webcheck.dll
+ 2008-12-20 23:15:40 233,472 —-a-w C:\WINDOWS\system32\webcheck.dll
- 2008-09-15 11:57:41 1,846,016 —-a-w C:\WINDOWS\system32\win32k.sys
+ 2009-02-09 10:19:34 1,846,272 —-a-w C:\WINDOWS\system32\win32k.sys
- 2008-10-16 20:38:40 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
+ 2008-12-20 23:15:41 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
- 2002-08-21 10:13:12 189,952 —-a-w C:\WINDOWS\system32\WISPTIS.EXE
+ 2006-10-26 17:45:04 293,376 —-a-w C:\WINDOWS\system32\WISPTIS.EXE
- 2007-06-12 04:51:12 10,834,944 —-a-w C:\WINDOWS\system32\wmp.dll
+ 2008-11-11 22:34:42 10,838,016 —-a-w C:\WINDOWS\system32\wmp.dll
+ 2007-04-16 15:52:53 246,848 —-a-w C:\WINDOWS\system32\wtl32locale.dll
+ 2006-02-03 12:41:26 14,032 —-a-w C:\WINDOWS\system32\x3daudio1_0.dll
+ 2007-03-05 16:42:18 15,128 —-a-w C:\WINDOWS\system32\x3daudio1_1.dll
+ 2006-02-03 12:42:06 230,096 —-a-w C:\WINDOWS\system32\xactengine2_0.dll
+ 2006-03-31 16:39:48 229,584 —-a-w C:\WINDOWS\system32\xactengine2_1.dll
+ 2006-05-31 11:24:16 230,168 —-a-w C:\WINDOWS\system32\xactengine2_2.dll
+ 2006-07-28 13:30:32 236,824 —-a-w C:\WINDOWS\system32\xactengine2_3.dll
+ 2006-09-28 20:05:56 237,848 —-a-w C:\WINDOWS\system32\xactengine2_4.dll
+ 2006-12-08 16:02:00 251,672 —-a-w C:\WINDOWS\system32\xactengine2_5.dll
+ 2007-01-24 19:27:30 255,848 —-a-w C:\WINDOWS\system32\xactengine2_6.dll
+ 2007-04-04 22:55:00 261,480 —-a-w C:\WINDOWS\system32\xactengine2_7.dll
+ 2006-03-31 16:39:24 62,672 —-a-w C:\WINDOWS\system32\xinput1_1.dll
+ 2006-07-28 13:30:14 62,744 —-a-w C:\WINDOWS\system32\xinput1_2.dll
+ 2007-04-04 22:53:42 81,768 —-a-w C:\WINDOWS\system32\xinput1_3.dll
+ 2005-12-05 22:07:30 61,136 —-a-w C:\WINDOWS\system32\xinput9_1_0.dll
- 2007-10-29 10:04:03 350,720 —-a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2008-02-15 09:06:21 351,744 —-a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2009-04-10 02:48:20 41,984 –sha-w C:\WINDOWS\system32\zusudupe.exe
- 2005-09-23 04:49:12 95,744 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
+ 2006-10-26 17:40:34 95,744 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
- 2005-09-23 11:29:16 479,232 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2006-10-26 17:40:36 479,232 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
- 2005-09-23 11:29:16 548,864 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2006-10-26 17:40:36 548,864 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
- 2005-09-23 11:29:16 626,688 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
+ 2006-10-26 17:40:36 626,688 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
- 2005-09-23 06:16:02 1,093,632 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
+ 2006-10-26 17:40:36 1,093,632 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
- 2005-09-23 06:16:06 1,079,808 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
+ 2006-10-26 17:40:36 1,079,808 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
- 2005-09-23 06:16:08 69,632 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
+ 2006-10-26 17:40:36 69,632 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
- 2005-09-23 06:16:10 57,344 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
+ 2006-10-26 17:40:36 57,344 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
- 2005-09-23 05:58:06 40,960 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll
+ 2006-10-26 17:40:36 40,960 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll
- 2005-09-23 05:58:06 45,056 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll
+ 2006-10-26 17:40:36 45,056 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll
- 2005-09-23 05:58:06 65,536 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll
+ 2006-10-26 17:40:36 65,536 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll
- 2005-09-23 05:58:06 57,344 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll
+ 2006-10-26 17:40:36 57,344 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll
- 2005-09-23 05:58:06 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll
+ 2006-10-26 17:40:36 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll
- 2005-09-23 05:58:06 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll
+ 2006-10-26 17:40:36 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll
- 2005-09-23 05:58:06 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll
+ 2006-10-26 17:40:36 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll
- 2005-09-23 05:58:06 49,152 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll
+ 2006-10-26 17:40:36 49,152 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll
- 2005-09-23 05:58:06 49,152 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll
+ 2006-10-26 17:40:36 49,152 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll
ComboFix Log

ComboFix 09-04-12.02 - Bashir 2009-04-11 21:20.9 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.112 [GMT -4:00]
Running from: c:\downloads\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Bashir\Application Data\psvr32.exe
c:\documents and settings\Bashir\Local Settings\Temporary Internet Files\CPV.stt
c:\documents and settings\Bashir\Local Settings\Temporary Internet Files\fbk.sts
.
—- Previous Run ——-
.
c:\documents and settings\Bashir\Application Data\twain\Twain.exe
c:\documents and settings\Bashir\Application Data\wiaserva.log
c:\documents and settings\Bashir\Local Settings\Temporary Internet Files\bestwiner.stt
c:\documents and settings\Bashir\Local Settings\Temporary Internet Files\CPV.stt
c:\documents and settings\Bashir\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\patch.exe
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\drivers\senekankarjwba.sys
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\sdra64.exe
c:\windows\system32\senekaejemaqoy.dll
c:\windows\system32\senekaftqmxgwy.dll
c:\windows\system32\senekakyjlqjea.dat
c:\windows\system32\senekanfvumene.dll
c:\windows\system32\senekaxilwtjnp.dat
c:\windows\system32\sys.dat
c:\windows\system32\wbem\grpconv.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SENEKA


((((((((((((((((((((((((( Files Created from 2009-03-12 to 2009-04-12 )))))))))))))))))))))))))))))))
.

2009-04-11 13:47 . 2009-04-11 06:34 ——– d—–w C:\call of duty 44
2009-04-11 11:03 . 2009-04-11 11:03 4224 —-a-w c:\windows\system32\drivers\ftnet2k.sys
2009-04-11 11:03 . 2009-04-11 11:03 13824 —-a-w c:\windows\system32\ftn2ksv.exe
2009-04-11 08:30 . 2009-04-11 08:30 ——– d—–w C:\VundoFix Backups
2009-04-11 06:44 . 2009-04-11 07:09 ——– d—–w c:\program files\The Mark
2009-04-11 06:05 . 2009-04-11 06:05 ——– d-sh–w C:\found.000
2009-04-11 03:19 . 2009-04-11 15:30 ——– d—–w c:\documents and settings\Bashir\Application Data\digifast
2009-04-11 03:09 . 2009-04-11 03:09 ——– d—–w c:\program files\WWShow
2009-04-11 03:04 . 2009-04-11 03:04 ——– d—–w c:\program files\Jcore
2009-04-11 02:20 . 2009-04-11 03:10 465874 —-a-w c:\windows\system32\config\systemprofile\Application Data\psvrr.exe
2009-04-10 18:10 . 2009-04-10 18:10 20480 —-a-w c:\windows\system32\nDler2.exe
2009-04-10 03:00 . 2009-04-10 04:45 0 —-a-w c:\windows\Rliwecaz.bin
2009-04-10 03:00 . 2009-04-10 12:46 408 —-a-w c:\windows\Onudevax.dat
2009-04-10 02:58 . 2009-04-10 02:58 155 —-a-w c:\windows\system32\SelfDel.bat
2009-04-10 02:58 . 2009-04-10 02:58 84045 —-a-w c:\windows\system32\ftp_non_crp.exe
2009-04-10 02:58 . 2009-04-10 02:58 ——– d—–w c:\documents and settings\Bashir\Application Data\pidle
2009-04-10 01:38 . 2009-04-10 23:22 ——– d—–w c:\program files\Antivirus Agent Pro
2009-04-09 23:18 . 2009-04-09 23:18 3437 —-a-w c:\windows\2bbc.n4f
2009-04-09 23:15 . 2009-04-09 23:15 20480 —-a-w c:\windows\system32\winarps32.exe
2009-04-09 22:46 . 2009-04-09 22:46 6407 —-a-w c:\windows\system32\krncode.dat
2009-04-09 22:46 . 2009-04-09 22:46 21504 —-a-w c:\windows\system32\nsysp.ini
2009-04-09 22:46 . 2009-04-09 22:46 19079 —-a-w c:\windows\system32\wincode.dat
2009-04-09 22:46 . 2009-04-09 22:46 1575 —-a-w c:\windows\system32\pwrcode.dat
2009-04-09 22:46 . 2004-08-04 05:56 17408 —-a-w c:\windows\system32\osysp.dat
2009-04-09 22:46 . 2009-04-09 22:46 988672 —-a-w c:\windows\system32\nsysk.ini
2009-04-09 22:46 . 2009-04-09 22:46 830464 —-a-w c:\windows\system32\nsysw.ini
2009-04-09 22:46 . 2008-12-20 23:15 826368 —-a-w c:\windows\system32\osysw.dat
2009-04-09 22:46 . 2007-04-16 15:52 984576 —-a-w c:\windows\system32\osysk.dat
2009-04-09 22:46 . 2009-04-09 22:46 87040 —-a-w c:\windows\system32\azton.mt
2009-04-09 22:46 . 2009-04-09 22:46 28880 —-a-w c:\windows\system32\ldshyf1.old
2009-04-09 22:46 . 2009-04-09 22:46 9728 —-a-w c:\windows\system32\brastia.exe
2009-04-09 18:26 . 2009-04-09 18:26 ——– d—–w C:\Command & Conquer Generals
2009-04-09 17:31 . 2009-04-09 17:31 ——– d—–w c:\program files\Common Files\EasyInfo
2009-04-09 15:59 . 2009-04-09 17:17 ——– d—–w c:\program files\Panzer Claws II
2009-04-09 15:25 . 2009-04-09 15:25 98304 —-a-w c:\windows\system32\CmdLineExt.dll
2009-04-09 13:41 . 2009-04-09 13:41 ——– d—–w C:\Medal Of Honar ALLIED Assults
2009-04-09 13:26 . 2007-05-31 23:30 266088 —-a-w c:\windows\system32\xactengine2_8.dll
2009-04-09 13:26 . 2007-05-31 23:29 18280 —-a-w c:\windows\system32\x3daudio1_2.dll
2009-04-09 13:24 . 2009-04-11 13:59 324 —-a-w c:\windows\game.ini
2009-03-19 15:55 . 2009-03-19 15:55 ——– d—–w c:\documents and settings\Bashir\Application Data\webex
2009-03-19 05:32 . 2009-03-19 04:41 229376 —-a-w c:\windows\system32\config\systemprofile\Application Data\psvr32.exe
2009-03-15 22:22 . 2009-03-15 22:22 ——– d—–w c:\documents and settings\Bashir\Application Data\Common Files
2009-03-15 17:52 . 2006-10-26 23:56 32592 —-a-w c:\windows\system32\msonpmon.dll
2009-03-15 17:46 . 2009-03-15 17:46 ——– d—–w c:\program files\MSBuild
2009-03-15 17:43 . 2009-03-15 17:43 ——– d—–w c:\program files\Microsoft.NET
2009-03-15 17:33 . 2009-03-15 17:33 ——– d—–w c:\program files\Microsoft Visual Studio 8
2009-03-15 17:30 . 2009-03-15 17:30 ——– d–h–r C:\MSOCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-12 01:34 . 2008-01-18 01:35 16394 —-a-w C:\neoLogitCore.log
2009-04-12 01:34 . 2008-01-18 01:35 25039 —-a-w C:\neoLogitCore.lo_
2009-04-11 17:26 . 2002-08-02 04:07 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-11 11:02 . 2006-08-24 01:02 ——– d—–w c:\program files\7-Zip
2009-04-11 08:30 . 2009-04-11 08:30 102 —-a-w C:\VundoFix.txt
2009-04-11 07:04 . 2009-02-25 21:47 ——– d—–w c:\program files\BitComet
2009-04-11 06:34 . 2009-01-22 02:05 ——– d—–w c:\documents and settings\Bashir\Application Data\Twain
2009-04-10 18:23 . 2008-11-27 01:20 ——– d—–w c:\documents and settings\Bashir\Application Data\gtk-2.0
2009-04-10 10:41 . 2007-10-05 10:41 ——– d—–w c:\program files\iTunes
2009-04-10 10:41 . 2007-05-19 02:43 ——– d—–w c:\program files\QuickTime
2009-04-10 10:41 . 2006-06-09 01:17 ——– d—–w c:\program files\FreeFTP
2009-04-10 10:41 . 2005-02-17 11:56 ——– d—–w c:\program files\MSN Messenger
2009-04-10 02:48 . 2009-01-10 02:48 51200 –sha-w c:\windows\system32\fuhaleke.exe
2009-04-10 02:48 . 2009-01-10 02:48 41984 –sha-w c:\windows\system32\zusudupe.exe
2009-04-09 23:18 . 2007-07-12 01:31 ——– d—–w c:\program files\Elcomsoft
2009-04-09 23:18 . 2007-01-18 00:52 ——– d—–w c:\program files\REFN
2009-04-09 23:18 . 2007-01-16 00:44 ——– d—–w c:\program files\eRightSoft
2009-04-09 23:18 . 2006-03-07 14:53 ——– d—–w c:\program files\FileZilla
2009-04-06 14:02 . 2009-02-25 20:42 ——– d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-15 17:47 . 2002-08-02 04:51 ——– d—–w c:\program files\Microsoft Works
2009-03-12 23:53 . 2005-03-25 00:14 ——– d—–w c:\program files\Macromedia
2009-03-12 23:50 . 2007-06-18 12:04 ——– d—–w c:\program files\Common Files\Macromedia
2009-03-12 23:43 . 2007-11-30 01:03 ——– d—–w c:\program files\Common Files\Research In Motion
2009-03-12 23:20 . 2007-02-04 13:59 ——– d—–w c:\program files\Google
2009-03-05 13:33 . 2002-08-02 04:58 ——– d—–w c:\program files\QUICKENW
2009-03-02 17:06 . 2008-09-09 22:04 ——– d—–w c:\program files\Citrix
2009-02-25 20:39 . 2009-02-23 22:06 ——– d—–w c:\program files\MSECache
2009-02-09 10:19 . 2005-02-16 02:13 1846272 —-a-w c:\windows\system32\win32k.sys
2008-09-09 22:04 . 2008-09-09 22:04 56912 —-a-w c:\documents and settings\Bashir\g2mdlhlpx.exe
2007-09-03 04:12 . 2007-09-03 04:12 6274206 —-a-w c:\program files\BitTorrent-5.0.8.exe
2007-01-08 22:24 . 2007-01-08 22:13 21822168 —-a-w c:\program files\AdbeRdr80_en_US.exe
2007-01-08 22:13 . 2007-01-08 22:09 7050552 —-a-w c:\program files\psa30se_en_us.exe
2005-08-08 21:01 . 2005-02-17 11:56 2323 —-a-w c:\program files\MSN Messenger 6.2.lnk
2005-02-17 02:21 . 2005-02-17 02:20 26262528 —-a-w c:\program files\NortonVirus.exe
2005-02-16 02:17 . 2002-08-02 08:01 1867 —-a-w c:\program files\Norton AntiVirus 2002.lnk
2009-03-19 15:2009-03-19 15:54 54:15 . c:\program files\mozilla firefox\plugins\atgpcdec.dll
2009-03-19 15:2009-03-19 15:54 54:16 . c:\program files\mozilla firefox\plugins\atgpcext.dll
2009-03-19 15:2009-03-19 15:55 54:54 . c:\program files\mozilla firefox\plugins\atmccli.dll
2009-03-19 15:2009-03-19 15:55 55:08 . c:\program files\mozilla firefox\plugins\ieatgpc.dll
2009-04-11 03:2009-04-11 03:20 20:21 . c:\program files\mozilla firefox\components\dfff.dll
2009-03-05 01:2007-05-14 03:27 30:33 . c:\program files\mozilla firefox\components\jar50.dll
2009-03-05 01:2007-05-14 03:27 30:34 . c:\program files\mozilla firefox\components\jsd3250.dll
2009-03-05 01:2007-05-14 03:27 30:34 . c:\program files\mozilla firefox\components\myspell.dll
2009-03-05 01:2007-05-14 03:27 30:38 . c:\program files\mozilla firefox\components\spellchk.dll
2009-03-05 01:2007-05-14 03:27 30:38 . c:\program files\mozilla firefox\components\xpinstal.dll
2009-04-10 02:48 . 2009-01-10 02:48 51200 –sha-w c:\windows\system32\fuhaleke.exe
2009-04-10 02:48 . 2009-01-10 02:48 41984 –sha-w c:\windows\system32\zusudupe.exe
2009-04-11 03:52 . 2009-04-10 18:10 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009041020090411\index.dat
2009-04-10 18:10 . 2009-04-11 04:02 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009041120090412\index.dat
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 36,864 2001-07-25 04:34 c:\cpqs\scom\bak\srmclean.exe

—-a-w 63,712 2007-03-09 15:09 c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\bak\apdproxy.exe

—-a-w 40,048 2007-05-11 07:06 c:\program files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe

—-a-w 43,008 2007-06-20 03:28 c:\program files\BitTorrent\bak\bittorrent.exe

—-a-r 155,648 2003-10-14 14:22 c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\bak\SSBkgdupdate.exe

—-a-w 143,360 2002-02-21 02:40 c:\program files\compaq\Coloreal\bak\coloreal.exe

—-a-w 32,768 2001-12-15 05:01 c:\program files\compaq\Easy Access Button Support\bak\StartEAK.exe

—-a-w 107,008 2006-07-14 20:36 c:\program files\eFax Messenger 4.2\bak\J2GDllCmd.exe

—-a-w 49,152 2003-08-04 21:28 c:\program files\HP\HP Software Update\bak\HPWuSchd.exe

—-a-w 241,664 2003-12-22 12:38 c:\program files\HP\hpcoretech\bak\hpcmpmgr.exe

—-a-w 49,263 2006-11-09 19:07 c:\program files\Java\jre1.5.0_10\bin\bak\jusched.exe

—-a-w 40,960 2004-04-14 19:04 c:\program files\ScanSoft\PaperPort\bak\IndexSearch.exe

—-a-w 57,393 2004-04-14 18:46 c:\program files\ScanSoft\PaperPort\bak\pptd40nt.exe

—-a-w 155,648 2002-05-09 15:01 c:\program files\VERITAS Software\Update Manager\bak\sgtray.exe
—-a-w 155,648 2002-05-09 06:01 c:\program files\VERITAS Software\Update Manager\sgtray.exe

—-a-w 3,084,288 2005-08-19 23:34 c:\program files\Yahoo!\Messenger\bak\ypager.exe

—-a-w 86,016 2002-06-08 08:20 c:\qoobox\Quarantine\C\Program Files\WildTangent\DDC\ActiveMenu\bak\DDCActiveMenu.exe.vir

—-a-w 122,880 2002-06-08 08:18 c:\qoobox\Quarantine\C\Program Files\WildTangent\DDC\DDCManager\bak\DDCMan.exe.vir

—-a-w 15,360 2004-08-04 05:56 c:\qoobox\Quarantine\C\WINDOWS\system32\bak\ctfmon.exe.vir

—-a-w 212,992 2002-07-05 00:55 c:\windows\SMINST\bak\RECGUARD.EXE

—-a-w 52,736 1998-05-07 23:04 c:\windows\system\bak\hpsysdrv.exe

—-a-w 98,304 2006-01-25 19:03 c:\windows\system32\bak\eTCrtMng.exe

—-a-w 114,688 2002-05-15 10:20 c:\windows\system32\bak\hkcmd.exe

—-a-w 155,648 2002-05-15 10:29 c:\windows\system32\bak\igfxtray.exe

—-a-w 106,549 2002-07-16 15:03 c:\windows\system32\dla\bak\tfswctrl.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Microsoft Works Update Detection"="c:\program files\Microsoft Works\WkDetect.exe" [N/A]
"PicoZip"="c:\program files\PicoZip\PicoZipTray.exe" [N/A]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"BitTorrent"="c:\program files\BitTorrent\bittorrent.exe" [N/A]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 1207080]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe" [2008-10-16 4347120]
"pidle"="c:\documents and settings\Bashir\Application Data\pidle\pidle.exe" [2009-04-09 56832]
"DigiFast"="c:\documents and settings\Bashir\Application Data\digifast\digifast.exe" [2009-04-10 225792]
"SfKg6wIPuSpdc"="c:\documents and settings\Bashir\Application Data\Microsoft\Windows\lqitbde.exe" [2009-04-10 35840]
"WinProx32_1"="c:\windows\system32\config\systemprofile\Application Data\psvrr.exe" [2009-04-10 465874]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [N/A]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [N/A]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [N/A]
"StorageGuard"="c:\program files\VERITAS Software\Update Manager\sgtray.exe" [2002-05-09 155648]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [N/A]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [N/A]
"WCOLOREAL"="c:\program files\COMPAQ\Coloreal\coloreal.exe" [N/A]
"srmclean"="c:\cpqs\Scom\srmclean.exe" [N/A]
"CPQEASYACC"="c:\program files\COMPAQ\Easy Access Button Support\StartEAK.exe" [N/A]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [N/A]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [N/A]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [N/A]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd.exe" [N/A]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [N/A]
"eFax 4.2"="c:\program files\eFax Messenger 4.2\J2GDllCmd.exe" [N/A]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [N/A]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [N/A]
"eTCertManger"="c:\windows\system32\eTCrtMng.exe" [N/A]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-12-11 267048]
"QAGENT"="c:\program files\QUICKENW\QAGENT.EXE" [2001-08-01 94208]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-02-14 185896]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-06-09 66680]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2004-08-02 124232]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"brastia"="c:\windows\system32\brastia.exe" [2009-04-09 9728]
"Java Load"="c:\windows\system32\config\systemprofile\Local Settings\Application Data\websvr.exe" [2009-04-11 364657]
"WinProx32_1"="c:\windows\system32\config\systemprofile\Application Data\psvrr.exe" [2009-04-10 465874]
"ftn2ksv"="c:\windows\system32\ftn2ksv.exe" [2009-04-11 13824]
"Antivirus Agent Pro"="c:\program files\Antivirus Agent Pro\aap.exe" [2009-04-09 784384]
"DXDllRegExe"="dxdllreg.exe" [N/A]
"atr.exe"="" [N/A]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"nDler2"="\\?\globalroot\systemroot\system32\nDler2.exe" [?]
"WinProx32_1"="c:\windows\system32\config\systemprofile\Application Data\psvrr.exe" [2009-04-10 465874]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
eFax 4.2.lnk - c:\program files\eFax Messenger 4.2\J2GTray.exe [2006-09-06 612352]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\FileZilla\\FileZilla.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Infogrames\\Line of Sight - Vietnam Demo\\Vietnamd.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Medal Of Honar ALLIED Assults\\MOHAA\\MOHAA.exe"=
"c:\\WINDOWS\\system32\\config\\systemprofile\\Local Settings\\Application Data\\websvr.exe"=
"c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\psvr32.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"23058:TCP"= 23058:TCP:BitComet 23058 TCP
"23058:UDP"= 23058:UDP:BitComet 23058 UDP

R0 aylnlfdx;aylnlfdx; [x]
R3 AKSUP;AKSUP;c:\windows\system32\drivers\aksup.sys [2006-01-22 34406]
R3 EraserUtilDrvI7;EraserUtilDrvI7; [x]
R3 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2006-06-15 115952]
R4 kbdmlt48;kbdmlt48; [x]
S2 mrtRate;mrtRate; [x]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-12-17 99376]
S3 ftnet2k;ftnet2k;c:\windows\system32\drivers\ftnet2k.sys [2009-04-11 4224]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2bfb14a3-0b45-11da-b21c-00e018d72cbf}]
\Shell\AutoRun\command - F:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{96fb7311-c18d-11dd-b3e1-00e018d72cbf}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ccecc5dc-df61-11d9-b204-00e018d72cbf}]
\Shell\AutoRun\command - F:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder

2009-04-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-04-11 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]

2009-04-11 c:\windows\Tasks\SDMsgUpdate (TE).job
- c:\progra~1\SMARTD~1\Messages\SDNotify.exe [2007-09-26 09:53]

2009-04-11 c:\windows\Tasks\User_Feed_Synchronization-{87A6F6B2-1018-4A52-96C0-7516BDA9C844}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]
.
- - - - ORPHANS REMOVED - - - -

BHO-{ED23079B-A24E-4126-A086-8D2B18B20E36} - %SystemRoot%\system32\wtl32locale.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Google AdSense Preview Tool - http://pagead2.googlesyndication.com/pagea…en/preview.html
IE: {{1F958B09-6612-7a0e-9223-4C7324C57B23} - c:\program files\Webpage Capture\Webpage Capture.exe
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {28E52D43-46EB-439B-8334-DA8D9C63D5B7} - hxxp://junaidbashir.isanexpert.com/system/ENCMAX.cab
FF - ProfilePath - c:\documents and settings\Bashir\Application Data\Mozilla\Firefox\Profiles\uxpye9t3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - component: c:\program files\Mozilla Firefox\components\dfff.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\qfaservices.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-11 21:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-04-11 21:44
ComboFix-quarantined-files.txt 2009-04-12 01:44
ComboFix2.txt 2009-01-26 18:08
ComboFix3.txt 2009-01-26 03:35
ComboFix4.txt 2009-01-23 14:47
ComboFix5.txt 2009-04-11 12:15

Pre-Run: 37,085,605,888 bytes free
Post-Run: 37,115,015,168 bytes free

327 — E O F — 2009-04-06 16:26
Thank You Stech,

This is where we are at. This is one heavily infected computer, I am not looking at one infection but many. They are serious infections. If you look on your Combofix log under the AWF heading, all those files and programs are infected , and this is just the tip of the iceburg. If this was my computer I would do a format and a clean install of windows as this computer may be compromised, what that means is that with the infections on this computer, even after its cleaned I would not trust it to do any online banking and such. This option of course is entirely up to you. Keep in mind also that with the amount of infections on this computer it can't be cleaned with the click of a mouse, its going to take some time and work.

Let me explain how you most likely got infected. P2P ( File Sharing Programs ) your downloading files and what not from an unknown source, its like playing Russian Roulette malwarewise.

Read our policy on this please.

We have noticed that many people seeking help from us are coming with infections contracted from the use of P2P programs.

Because of this, we changed our malware forum's policy on the use of P2P file sharing programs.

  • If your helper detects the presence of such programs on your computer he/she will ask you to remove them. Help will be withdrawn should you not agree to their removal.
  • If we clean your computer of infection, and you return to us a short time later with an infection contracted by the use of P2P programs, volunteer analysts will refuse their help.

We do not ask you to do this without reason.


P2P (File Sharing ) programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realize. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

This article from InfoWorld illustrates the dangers of a poorly configured P2P program.
http://www.infoworld.com/article/07/09/06/…ID-theft_1.html

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.


c:\program files\BitComet
c:\program files\BitTorrent-5.0.8.exe

What I would like you to do is if you decide to continue with the cleaning, uninstall both these programs from the Add Remove Programs in the Control Panel and post a fresh Hijackthis log please.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:45:04, on 4/12/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\eTSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QUICKENW\QAGENT.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\brastia.exe
C:\WINDOWS\system32\mrtMngr.EXE
C:\WINDOWS\system32\config\systemprofile\Application Data\psvrr.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Bashir\Application Data\psvr32.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Documents and Settings\Bashir\Application Data\pidle\pidle.exe
C:\Documents and Settings\Bashir\Application Data\digifast\digifast.exe
C:\Documents and Settings\Bashir\Application Data\Microsoft\Windows\lqitbde.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\BASHIR\Application Data\Mozilla\Profiles\default\4hnv1dyt.slt\prefs.js)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [eFax 4.2] "C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [eTCertManger] C:\WINDOWS\system32\eTCrtMng.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [brastia] C:\WINDOWS\system32\brastia.exe
O4 - HKLM\..\Run: [Java Load] C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\websvr.exe
O4 - HKLM\..\Run: [WinProx32_1] C:\WINDOWS\system32\config\systemprofile\Application Data\psvrr.exe
O4 - HKLM\..\Run: [ftn2ksv] C:\WINDOWS\system32\ftn2ksv.exe
O4 - HKLM\..\Run: [Antivirus Agent Pro] C:\Program Files\Antivirus Agent Pro\aaaaaaap.exe
O4 - HKLM\..\RunOnce: [] C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe -z
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [PicoZip] C:\Program Files\PicoZip\PicoZipTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [pidle] "C:\Documents and Settings\Bashir\Application Data\pidle\pidle.exe" 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139
O4 - HKCU\..\Run: [DigiFast] C:\Documents and Settings\Bashir\Application Data\digifast\digifast.exe
O4 - HKCU\..\Run: [SfKg6wIPuSpdc] C:\Documents and Settings\Bashir\Application Data\Microsoft\Windows\lqitbde.exe
O4 - HKCU\..\Run: [WinProx32_1] C:\WINDOWS\system32\config\systemprofile\Application Data\psvrr.exe
O4 - HKUS\S-1-5-18\..\Run: [nDler2] \\?\globalroot\systemroot\system32\nDler2.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [WinProx32_1] C:\WINDOWS\system32\config\systemprofile\Application Data\psvrr.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [nDler2] \\?\globalroot\systemroot\system32\nDler2.exe (User 'Default user')
O4 - Global Startup: eFax 4.2.lnk = C:\Program Files\eFax Messenger 4.2\J2GTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google AdSense Preview Tool - http://pagead2.googlesyndication.com/pagea…en/preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Webpage Capture - {1F958B09-6612-7a0e-9223-4C7324C57B23} - C:\Program Files\Webpage Capture\Webpage Capture.exe (file missing)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {28E52D43-46EB-439B-8334-DA8D9C63D5B7} (ENCMAX Control) - http://junaidbashir.isanexpert.com/system/ENCMAX.cab
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://vcuhsra.mcvh-vcu.edu/vdesk/terminal…,2008,1015,1912
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/24.9/uploader2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6C275925-A1ED-4DD2-9CEE-9823F5FDAA10} (F5 Networks SSLTunnel) - https://vcuhsra.mcvh-vcu.edu/vdesk/terminal…,2008,1015,1902
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} (F5 Networks SuperHost Class) - https://vcuhsra.mcvh-vcu.edu/vdesk/terminal…,2008,1015,1907
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://vcuhsra.mcvh-vcu.edu/f5-w-687474703…#036;/dwa7W.cab
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} (F5 Networks Host Control) - https://vcuhsra.mcvh-vcu.edu/vdesk/terminal…,2008,1015,1906
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.62/code/iPIX-ImageWell-ipix.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: eToken Notification Service (ETOKSRV) - Aladdin Knowledge Systems, Ltd. - C:\WINDOWS\system32\eTSrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 13433 bytes
Hi,

Thanks for understanding about file sharing. Hope you had a nice holiday weekend.

Lets start the cleaning.

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.<– Don't forget this
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a New Hijackthis log.





Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.
Good Morning Stech,

Sorry you had to go through that. Lots of bad malware going around. FYI, while I was out of state during the xmas holidays, doing what I do I cleaned 5 infected computers for friends, all got infected from there kids downloading music from file sharing programs. The programs themselves are ok, its just that you never know where that file is coming from or what it has bundled with it.

If you use Java, make sure its the latest version

Go to your Control Panel and click on the Java Icon ( looks like a little coffee cup ) click on About and you should have Version 6 Update 13, if not proceed with the instructions.


Download the latest version Here save it, do not install it yet.

JRE 6 Update 13 <–This is what you need

  • Go to your Add Remove Programs in the Control Panel and uninstall any previous versions of Java
  • Reboot your computer
  • Install the latest version
You can verify the installation Here



Open Internet Explorer and go to Tools> Windows Updates and make sure you have the latest critical updates, you should have SP3 Service Pack 3 and beyond. You can right click on My Computer and go to Properties and it will show what service pack you have installed.





  • How did I get infected in the first place ?
    Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports



Keep in mind if you install some of these programs. Only ONE Anti Virus and only ONE Firewall is recommended, more is overkill and can cause you problems. You can install all the Spyware programs I have listed without any problems. If you install Spyware Blaster and Spyware Guard, they will conflict with the TeaTimer in Spybot , you can still install Spybot Search and Destroy but do not enable the TeaTimer .



Here are some free programs to install, all free and highly regarded by the fine people in the Malware Removal Community
  • Spybot Search and Destroy 1.6
    Check for Updates/ Immunize and run a Full System Scan on a regular basis. If you install Spyware Blaster ( Recommended ) then do not enable the TeaTimer in Spybot Search and Destroy.
  • Spyware Blaster It will prevent most spyware from ever being installed. No scan to run, just update about once a week and enable all protection.
  • Spyware Guard It offers realtime protection from spyware installation attempts, again, no scan to run, just install it and let it do its thing.
  • IE-Spyad
    IE-Spyad places over 6000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 3 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.


Safe Surfn
Ken
I am still getting pop-ups and evens messages that I have virus or malware on my computer.

here is my newly Hijackthis Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:32:36 PM, on 4/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://store.presario.net/scripts/redirect…c02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://rd.yahoo.com/customize/yessentials_…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/yessentials_…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://store.presario.net/scripts/redirect…c02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5b7f9f3c-fee2-4908-8f40-ab78258f3223} - C:\WINDOWS\system32\dofoferu.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [bifonedige] Rundll32.exe "C:\WINDOWS\system32\vakemuna.dll",s
O4 - HKLM\..\Run: [3cf82a16] rundll32.exe "C:\WINDOWS\system32\muvobuwe.dll",b
O4 - HKLM\..\Run: [CPM3fcb198a] Rundll32.exe "C:\WINDOWS\system32\kogonubo.dll",a
O4 - HKLM\..\RunOnce: [Compaq_RBA] C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe -z
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\seduvumo.dll c:\windows\system32\kogonubo.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kogonubo.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kogonubo.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 9510 bytes
Hi Stech,

Did you do a reformat and a clean install of windows or just a repair, a clean install should not have viruses, looks like where back to square one. :blush:

Remove these with HJT

O2 - BHO: (no name) - {5b7f9f3c-fee2-4908-8f40-ab78258f3223} - C:\WINDOWS\system32\dofoferu.dll

O4 - HKLM\..\Run: [bifonedige] Rundll32.exe "C:\WINDOWS\system32\vakemuna.dll",s
O4 - HKLM\..\Run: [3cf82a16] rundll32.exe "C:\WINDOWS\system32\muvobuwe.dll",b
O4 - HKLM\..\Run: [CPM3fcb198a] Rundll32.exe "C:\WINDOWS\system32\kogonubo.dll",a

O20 - AppInit_DLLs: C:\WINDOWS\system32\seduvumo.dll c:\windows\system32\kogonubo.dll

O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kogonubo.dll

O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kogonubo.dll





Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.<– Don't forget this
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a New Hijackthis log.
New Hijackthis Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:23:19 PM, on 4/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\VERITAS Software\Update Manager\sgtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://store.presario.net/scripts/redirect…c02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://rd.yahoo.com/customize/yessentials_…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/yessentials_…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://store.presario.net/scripts/redirect…c02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\RunOnce: [Compaq_RBA] C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe -z
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 8938 bytes

MBAM Log

Malwarebytes' Anti-Malware 1.36
Database version: 1987
Windows 5.1.2600 Service Pack 3

4/15/2009 10:17:41 PM
mbam-log-2009-04-15 (22-17-41).txt

Scan type: Quick Scan
Objects scanned: 78898
Time elapsed: 5 minute(s), 49 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 5
Registry Keys Infected: 7
Registry Values Infected: 5
Registry Data Items Infected: 4
Folders Infected: 0
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\dofoferu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\vakemuna.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\kogonubo.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\seduvumo.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\muvobuwe.dll (Trojan.Vundo.H) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5b7f9f3c-fee2-4908-8f40-ab78258f3223} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5b7f9f3c-fee2-4908-8f40-ab78258f3223} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5b7f9f3c-fee2-4908-8f40-ab78258f3223} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\3cf82a16 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bifonedige (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm3fcb198a (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\kogonubo.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\seduvumo.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\seduvumo.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\muvobuwe.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\ewubovum.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vakemuna.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\kogonubo.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\dofoferu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\seduvumo.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\Documents and Settings\M Bashir\Local Settings\Temp\googleupdate.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI