This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Antivirus System Pro - can't get programs to open

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This morning my work computer is infected with Antivirus System Pro, and I can't get my McAfee, MalwareBytes, or HijackThis to open. I just get a message that the file is infected, and then i get a bunch of Antivirus System Pro warnings. I'm also having random Internet Explorer loads with all kinds of nasty websites. I have previously received help here and followed all the directions, so I have ERUNT, MalwareBytes, HijackThis, etc. already installed. Please Help ASAP!!!!
As this is a work computer there are several issues that need to be addressed.

Does your company have an IT department?

If so - the problem should be taken to them

If no IT dept and you are on your own for the upkeep of this machine, there are no guarantees offered from WTT - you follow the advice at your own risk.

Any private or proprietary information contained in the machine, belonging to your company, may be compromised on an open public forum.

WTT cannot be held liable in any way for any inconvenience/problems your company encounters as a result.

If you still wish to continue with the cleaning of the company machine - please do the following:

Please do the following:

Please save this file to your desktop.
  • Click on Start > Run, and copy-paste the following command (the bolded text) into the open run box, then click OK.

    "%userprofile%\desktop\win32kdiag.exe" -f -r

  • When it's finished, there will be a log called Win32kDiag.txt on your desktop.
  • Please open it with notepad and post the contents here.

NEXT

NEXT

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT

Not: GMER may have to be run in safe mode - you may have to rename it REMG.com to get it to run

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



NEXT

  • Download RootRepeal from the following location and save it to your desktop.
  • Extract RootRepeal.exe from the archive.
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check all seven boxes: [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.

NEXT

Please download Sysprot Antirootkit from >>>HERE<<<

Unzip it into a folder on your desktop.

  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select ALL ITEMS
  • Look near the bottom left, and Check Hidden Objects Only
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to.
  • Open the text file and copy/paste the log here.
This is a work computer, but no IT dept. I'm on my own. I was able to get the first Win32kDiag task started, but it seemed to shut down pretty quickly. It did create a txt file, but it won't let me open notepad or double click on the txt file. I keep getting the same warning message that the file is infected. This happens when i try to open anything. Then i was able to download DDS to my desktop, but i could not open it. Same message as all others. Any ideas?
Look in Task manager > Processes tab…

see if there are any processes listed related to Antivirus System Pro, sysguard.exe or svchast.exe and end those processes

Try the programs in safe mode

GMER should work in safe mode, renamed to .com


try this program as well

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Okay, I tried everything you've told me to, in order:

1. Tried the win32kdiag.exe, but it never stops….and thus i never got a log.
2. DDS.txt and Attach.txt logs are pasted below.
3. Ran GMER. After it was done, i got a message saying there was some root activity, but i never got a button or option to save anything. So i just clicked ok and it closed out. I even re-downloaded it using the other link option you gave me, ran it again and same result. Did i miss something?
4. RootRepeal log pasted below.
5. Sysprot log pasted below.
6. OTL.txt and Extras.txt logs pasted below.


DDS (Ver_09-07-30.01) - NTFSx86 NETWORK
Run by [removed] at 11:13:04.07 on Mon 08/31/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.261 [GMT -5:00]

AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\rick_2\desktop\win32kdiag.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Documents and Settings\rick_2\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.oscn.net/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: BHO: {0b7fe966-c2dc-4af7-8a5f-e4141b92546e} - c:\windows\system32\iehelper.dll
BHO: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\progra~1\mcafee\viruss~1\scriptsn.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: PopUpCop: {db43e4e6-ff8a-4018-8c8e-f68587a44a73} - c:\progra~1\popupcop\PopUpCop.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [system tool] c:\program files\bbtmwg\dwkksysguard.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [StorageGuard] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [PCMService] "c:\program files\dell\media experience\PCMService.exe"
mRun: [USIUDF_Eject_Monitor] c:\program files\common files\ulead systems\dvd\USISrv.exe
mRun: [PSDiagnosticM] "c:\program files\linksys wireless-g print server\PSDiagnosticM.exe"
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [KnexStarter] c:\program files\common files\hewlett-packard\hp device communication services\appinterfaces\HPDeviceService.exe
mRun: [RunTasktray] "c:\program files\hewlett-packard\hp easy printer care\hpprun.exe" –regkeypath=software\hewlett-packard\hp easy printer care\HPPRun –valuename=InstallTTM
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [system tool] c:\program files\bbtmwg\dwkksysguard.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Open Image in New Window - c:\progra~1\popupcop\popupcop.dll/imagenew
IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: c:\windows\system32\lsp.dll
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: microsoft.com\office
Trusted Zone: microsoft.com\officeupdate
Trusted Zone: hp.com
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,96/mcinsctl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: HPDCS - {ba135f49-a12c-4e26-a2c4-6ea945999072} - c:\program files\common files\hewlett-packard\hp device communication services\app\hpdcsapp.dll
Handler: hppfile - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - c:\program files\hewlett-packard\hp easy printer care\HPPCtrls.dll
Handler: hppsam - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - c:\program files\hewlett-packard\hp easy printer care\HPPCtrls.dll
Handler: hppzip - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - c:\program files\hewlett-packard\hp easy printer care\HPPCtrls.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: CShellExecuteHookImpl Object: {54d9498b-cf93-414f-8984-8ce7fde0d391} - c:\program files\ewido anti-malware\shellhook.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\rick_2\applic~1\mozilla\firefox\profiles\6ldr4f98.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.oscn.net
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npImgCtl.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R3 lknuhst;Linksys Network USB Host Controller;c:\windows\system32\drivers\lknuhst.sys [2007-5-22 11136]
R3 LKNUHUB;Linksys Network USB Root Hub;c:\windows\system32\drivers\lknuhub.sys [2007-5-22 37248]
S1 ewido security suite driver;ewido security suite driver;c:\program files\ewido anti-malware\guard.sys [2005-12-30 3072]
S1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2006-12-29 214024]
S2 ewido security suite control;ewido security suite control;c:\program files\ewido anti-malware\ewidoctrl.exe [2005-11-30 13888]
S2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2007-7-30 359952]
S2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2006-12-29 144704]
S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064]
S3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2006-12-29 606736]
S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2006-12-29 79880]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2006-12-29 35272]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2006-12-29 34216]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2006-12-29 40552]
S3 TLA13;TLA13;\??\c:\docume~1\rick_2\locals~1\temp\user.bak –> c:\docume~1\rick_2\locals~1\temp\user.bak [?]
S4 ewido security suite guard;ewido security suite guard;c:\program files\ewido anti-malware\ewidoguard.exe [2005-12-18 151616]

=============== Created Last 30 ================

2009-08-31 10:52 8,212 a——- c:\windows\mfebcdata
2009-08-28 12:16 –d-h— c:\windows\PIF
2009-08-28 10:10 12,032 a——- c:\windows\system32\iehelper.dll
2009-08-27 19:14 180,224 a——- c:\windows\system32\lsp.dll
2009-08-27 19:14 222,208 a——- c:\windows\syssvc.exe
2009-08-27 18:44 –d—– c:\program files\bbtmwg
2009-08-27 18:40 –d—– C:\spoolerlogs
2009-08-27 18:19 889,772 a——- c:\windows\system32\xa.tmp
2009-08-24 16:04 –d—– c:\program files\WinPcap
2009-08-11 22:56 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx
2009-08-11 22:55 655,872 ——– c:\windows\system32\dllcache\mstscax.dll
2009-08-05 04:11 204,800 ——– c:\windows\system32\dllcache\mswebdvd.dll

==================== Find3M ====================

2009-08-05 04:11 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-08-03 13:36 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 13:36 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-07-18 11:20 3,062,272 a——- c:\windows\system32\dllcache\mshtml.dll
2009-07-18 11:20 1,506,304 a——- c:\windows\system32\dllcache\shdocvw.dll
2009-07-17 13:55 58,880 a——- c:\windows\system32\dllcache\atl.dll
2009-07-17 13:55 58,880 a——- c:\windows\system32\atl.dll
2009-07-13 23:43 10,841,088 a——- c:\windows\system32\dllcache\wmp.dll
2009-07-13 23:43 286,208 a——- c:\windows\system32\wmpdxm.dll
2009-07-13 23:43 286,208 a——- c:\windows\system32\dllcache\wmpdxm.dll
2009-07-10 08:42 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll
2009-06-25 13:36 661,504 a——- c:\windows\system32\mqqm.dll
2009-06-22 06:49 117,248 a——- c:\windows\system32\mqtgsvc.exe
2009-06-22 06:49 19,968 a——- c:\windows\system32\mqbkup.exe
2009-06-22 06:49 117,248 ——– c:\windows\system32\dllcache\mqtgsvc.exe
2009-06-22 06:49 19,968 ——– c:\windows\system32\dllcache\mqbkup.exe
2009-06-22 06:49 4,608 a——- c:\windows\system32\mqsvc.exe
2009-06-22 06:49 4,608 ——– c:\windows\system32\dllcache\mqsvc.exe
2009-06-22 06:48 91,776 ——– c:\windows\system32\dllcache\mqac.sys
2009-06-22 06:38 18,432 a——- c:\windows\system32\dllcache\iedw.exe
2009-06-16 09:55 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 09:55 82,432 a——- c:\windows\system32\fontsub.dll
2009-06-16 09:55 82,432 a——- c:\windows\system32\dllcache\fontsub.dll
2009-06-16 09:55 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-06-12 06:50 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 06:50 80,896 ——– c:\windows\system32\dllcache\tlntsess.exe
2009-06-12 06:50 76,288 a——- c:\windows\system32\telnet.exe
2009-06-12 06:50 76,288 ——– c:\windows\system32\dllcache\telnet.exe
2009-06-10 09:21 84,992 a——- c:\windows\system32\avifil32.dll
2009-06-10 09:21 84,992 ——– c:\windows\system32\dllcache\avifil32.dll
2009-06-10 01:32 132,096 a——- c:\windows\system32\wkssvc.dll
2009-06-10 01:32 132,096 ——– c:\windows\system32\dllcache\wkssvc.dll
2009-06-05 02:42 655,872 a——- c:\windows\system32\mstscax.dll
2009-06-03 14:27 1,290,752 a——- c:\windows\system32\quartz.dll
2009-06-03 14:27 1,290,752 ——– c:\windows\system32\dllcache\quartz.dll
2009-06-03 10:07 410,984 a——- c:\windows\system32\deploytk.dll
2007-01-08 15:32 92,064 a——- c:\documents and settings\rick_2\mqdmmdm.sys
2007-01-08 15:32 79,328 a——- c:\documents and settings\rick_2\mqdmserd.sys
2007-01-08 15:32 66,656 a——- c:\documents and settings\rick_2\mqdmbus.sys
2007-01-08 15:32 9,232 a——- c:\documents and settings\rick_2\mqdmmdfl.sys
2007-01-08 15:32 6,208 a——- c:\documents and settings\rick_2\mqdmcmnt.sys
2007-01-08 15:32 5,936 a——- c:\documents and settings\rick_2\mqdmwhnt.sys
2007-01-08 15:32 4,048 a——- c:\documents and settings\rick_2\mqdmcr.sys
2007-01-08 15:32 25,600 a——- c:\documents and settings\rick_2\usbsermptxp.sys
2007-01-08 15:32 22,768 a——- c:\documents and settings\rick_2\usbsermpt.sys

============= FINISH: 11:15:31.04 ===============


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-07-30.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 12/10/2003 4:22:48 PM
System Uptime: 8/31/2009 10:54:01 AM (1 hours ago)

Motherboard: Dell Computer Corp. | | 0G1548
Processor: Intel® Pentium® 4 CPU 2.53GHz | Microprocessor | 2525/533mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 74 GiB total, 53.359 GiB free.
D: is CDROM ()
E: is NetworkDisk (NTFS) - 74 GiB total, 53.632 GiB free.
S: is NetworkDisk (NTFS) - 74 GiB total, 53.632 GiB free.

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1858: 8/27/2009 6:32:09 PM - System Checkpoint
RP1859: 8/27/2009 6:32:10 PM - System Checkpoint
RP1860: 8/27/2009 6:32:11 PM - System Checkpoint
RP1861: 8/27/2009 6:32:12 PM - System Checkpoint
RP1862: 8/27/2009 6:32:12 PM - System Checkpoint
RP1863: 8/27/2009 6:32:12 PM - Installed Java™ 6 Update 13
RP1864: 8/27/2009 6:32:12 PM - System Checkpoint
RP1865: 8/27/2009 6:32:13 PM - System Checkpoint
RP1866: 8/27/2009 6:32:13 PM - System Checkpoint
RP1867: 8/27/2009 6:32:14 PM - System Checkpoint
RP1868: 8/27/2009 6:32:14 PM - System Checkpoint
RP1869: 8/27/2009 6:32:15 PM - System Checkpoint
RP1870: 8/27/2009 6:32:15 PM - System Checkpoint
RP1871: 8/27/2009 6:32:15 PM - System Checkpoint
RP1872: 8/27/2009 6:32:16 PM - Software Distribution Service 3.0
RP1873: 8/27/2009 6:32:16 PM - System Checkpoint
RP1874: 8/27/2009 6:32:16 PM - System Checkpoint
RP1875: 8/27/2009 6:32:16 PM - System Checkpoint
RP1876: 8/27/2009 6:32:16 PM - System Checkpoint
RP1877: 8/27/2009 6:32:17 PM - System Checkpoint
RP1878: 8/27/2009 6:32:17 PM - System Checkpoint
RP1879: 8/27/2009 6:32:17 PM - System Checkpoint
RP1880: 8/27/2009 6:32:17 PM - System Checkpoint
RP1881: 8/27/2009 6:32:18 PM - System Checkpoint
RP1882: 8/27/2009 6:32:18 PM - System Checkpoint
RP1883: 8/27/2009 6:32:18 PM - System Checkpoint
RP1884: 8/27/2009 6:32:19 PM - System Checkpoint
RP1885: 8/27/2009 6:32:19 PM - System Checkpoint
RP1886: 8/27/2009 6:32:19 PM - Installed Windows XP WIC.
RP1887: 8/27/2009 6:32:19 PM - Installed Windows KB954550-v5.
RP1888: 8/27/2009 6:32:20 PM - Printer Driver Microsoft XPS Document Writer Installed
RP1889: 8/27/2009 6:32:20 PM - System Checkpoint
RP1890: 8/27/2009 6:32:20 PM - Printer Driver Microsoft XPS Document Writer Installed
RP1891: 8/27/2009 6:32:21 PM - Software Distribution Service 3.0
RP1892: 8/27/2009 6:32:21 PM - System Checkpoint
RP1893: 8/27/2009 6:32:21 PM - System Checkpoint
RP1894: 8/27/2009 6:32:22 PM - System Checkpoint
RP1895: 8/27/2009 6:32:22 PM - System Checkpoint
RP1896: 8/27/2009 6:32:22 PM - System Checkpoint
RP1897: 8/27/2009 6:32:23 PM - System Checkpoint
RP1898: 8/27/2009 6:32:23 PM - System Checkpoint
RP1899: 8/27/2009 6:32:23 PM - System Checkpoint
RP1900: 8/27/2009 6:32:23 PM - Software Distribution Service 3.0
RP1901: 8/27/2009 6:32:24 PM - System Checkpoint
RP1902: 8/27/2009 6:32:24 PM - System Checkpoint
RP1903: 8/27/2009 6:32:24 PM - System Checkpoint
RP1904: 8/27/2009 6:32:25 PM - System Checkpoint
RP1905: 8/27/2009 6:32:25 PM - System Checkpoint
RP1906: 8/27/2009 6:32:25 PM - System Checkpoint
RP1907: 8/27/2009 6:32:25 PM - Software Distribution Service 3.0
RP1908: 8/27/2009 6:32:26 PM - System Checkpoint
RP1909: 8/27/2009 6:32:26 PM - System Checkpoint
RP1910: 8/27/2009 6:32:26 PM - System Checkpoint
RP1911: 8/27/2009 6:32:27 PM - System Checkpoint
RP1912: 8/27/2009 6:32:27 PM - System Checkpoint
RP1913: 8/27/2009 6:32:27 PM - System Checkpoint
RP1914: 8/27/2009 6:32:27 PM - System Checkpoint
RP1915: 8/27/2009 6:32:28 PM - Software Distribution Service 3.0
RP1916: 8/27/2009 6:32:28 PM - Software Distribution Service 3.0
RP1917: 8/27/2009 6:32:28 PM - System Checkpoint
RP1918: 8/27/2009 6:32:28 PM - System Checkpoint
RP1919: 8/27/2009 6:32:29 PM - System Checkpoint
RP1920: 8/27/2009 6:32:29 PM - System Checkpoint
RP1921: 8/27/2009 6:32:29 PM - System Checkpoint
RP1922: 8/27/2009 6:32:29 PM - System Checkpoint
RP1923: 8/27/2009 6:32:30 PM - System Checkpoint
RP1924: 8/27/2009 6:32:30 PM - System Checkpoint
RP1925: 8/27/2009 6:32:30 PM - System Checkpoint
RP1926: 8/27/2009 6:32:30 PM - System Checkpoint
RP1927: 8/27/2009 6:32:30 PM - System Checkpoint
RP1928: 8/27/2009 6:32:31 PM - Software Distribution Service 3.0
RP1929: 8/27/2009 6:32:31 PM - System Checkpoint
RP1930: 8/27/2009 6:32:31 PM - Software Distribution Service 3.0
RP1931: 8/27/2009 6:32:31 PM - System Checkpoint
RP1932: 8/27/2009 6:32:32 PM - System Checkpoint
RP1933: 8/27/2009 6:32:32 PM - System Checkpoint
RP1934: 8/27/2009 6:32:32 PM - System Checkpoint
RP1935: 8/27/2009 6:32:33 PM - System Checkpoint
RP1936: 8/27/2009 6:32:33 PM - System Checkpoint
RP1937: 8/27/2009 6:32:33 PM - System Checkpoint
RP1938: 8/27/2009 6:32:33 PM - System Checkpoint
RP1939: 8/27/2009 6:32:34 PM - System Checkpoint
RP1940: 8/27/2009 6:32:34 PM - System Checkpoint
RP1941: 8/27/2009 6:32:34 PM - Software Distribution Service 3.0
RP1942: 8/28/2009 3:19:10 AM - System Checkpoint

==== Installed Programs ======================

32 Bit HP CIO Components Installer
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Reader 7.0.9
Adobe Shockwave Player
Big Fish Games Client
BlueBeat.com
Broadcom Management Programs
Compatibility Pack for the 2007 Office system
Core Communication Components
Critical Update for Windows Media Player 11 (KB959772)
Dell Digital Jukebox Driver
Dell Media Experience
Dell Networking Guide
Dell Solution Center
DellSupport
Device Data Communication Components
DS21Patch
DVD Slideshow Builder 4.5.0.1
ERUNT 1.1j
ESPNMotion
Events Communication Components
ewido anti-malware
FLV Player 2.0 (build 25)
Google Earth
Google Toolbar for Internet Explorer
Google Updater
Help and Support Customization
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB909394)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
HP Easy Printer Care
HP Printer Settings Tools
HP Printer Usage Report
HP Proactive Services
HP Update
Intel® Extreme Graphics Driver
iolo technologies' System Mechanic
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2
Java™ 6 Update 13
Linksys Wireless-G Print Server
Malwarebytes' Anti-Malware
MathPlayer
McAfee SecurityCenter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft ActiveSync
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Money 2005
Microsoft Office Basic Edition 2003
Microsoft Outlook Personal Folders Backup
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Motorola Driver Installation 3.4.0
Mozilla Firefox (3.5.2)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6 Service Pack 2 (KB954459)
Musicmatch® Jukebox
Need2Find Bar
Operating System Communication Components
PopUpCop
PREMISE Forms Launcher
QuickTime
Security Toolbar
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Encoder (KB954156)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB947864)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
Spybot - Search & Destroy 1.4
Ulead Data-Add 2.0
Ulead DVD MovieFactory 4.0
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB973815)
Visionary Viewer
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage v1.3.0254.0
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Player 11
Windows Mobile® Device Handbook
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WorkgroupShare Client
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Toolbar

==== Event Viewer Messages From Past Week ========

8/28/2009 12:57:51 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McNASvc with arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}
8/28/2009 12:57:16 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
8/28/2009 12:57:11 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec mfehidk MPFP MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
8/28/2009 12:57:11 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.
8/28/2009 12:57:11 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/28/2009 12:57:11 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/28/2009 12:57:11 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
8/28/2009 12:56:51 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
8/28/2009 11:28:42 AM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file hmmapi.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.0.2900.2180.
8/28/2009 11:28:40 AM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\program files\internet explorer\iedw.exe. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.3592.
8/24/2009 5:21:03 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference error message: The referenced assembly is not installed on your system. .
8/24/2009 5:21:03 PM, error: SideBySide [59] - Generate Activation Context failed for C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\MFC80U.DLL. Reference error message: The operation completed successfully. .
8/24/2009 5:21:03 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system.
8/24/2009 5:21:02 PM, error: SideBySide [59] - Generate Activation Context failed for C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\MFC80.DLL. Reference error message: The operation completed successfully. .

==== End Of File ===========================

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/31 11:43
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================

Drivers
——————-
Name: aujasnkj.sys
Image Path: C:\DOCUME~1\rick_2\LOCALS~1\Temp\aujasnkj.sys
Address: 0xF784D000 Size: 84352 File Visible: No Signed: -
Status: -

Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF8052000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8C2C000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF7A1A000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
——————-
Path: C:\WINDOWS\SYSTEM32\kbiwkmfomomkgl.dat
Status: Invisible to the Windows API!

Path: C:\WINDOWS\SYSTEM32\kbiwkmmpaxwtsy.dat
Status: Invisible to the Windows API!

Path: C:\WINDOWS\SYSTEM32\kbiwkmtairxydw.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\SYSTEM32\kbiwkmylkrxdnd.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\SYSTEM32\UACbsqsvsntjp.db
Status: Invisible to the Windows API!

Path: C:\WINDOWS\SYSTEM32\uacinit.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\SYSTEM32\UACiuhxppvbsn.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\SYSTEM32\UACnansiucotl.dat
Status: Invisible to the Windows API!

Path: C:\WINDOWS\SYSTEM32\UACneuaqneqmm.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\SYSTEM32\UACpmooryyoui.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\SYSTEM32\UACtjewaedyuf.dll
Status: Invisible to the Windows API!

Path: c:\windows\temp\mcmsc_l1fcwec73ggfrl3
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: C:\WINDOWS\Temp\UAC485e.tmp
Status: Invisible to the Windows API!

Path: c:\documents and settings\rick_2\desktop\win32kdiag.txt
Status: Size mismatch (API: 11304, Raw: 11211)

Path: C:\WINDOWS\SYSTEM32\DLLCACHE\iuengine.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SYSTEM32\DRIVERS\kbiwkmjcxejbow.sys
Status: Invisible to the Windows API!

Path: C:\WINDOWS\SYSTEM32\DRIVERS\UACohktyagxue.sys
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\rick_2\Local Settings\Temp\UAC9ebe.tmp
Status: Invisible to the Windows API!

Stealth Objects
——————-
Object: Hidden Module [Name: UAC485e.tmpaedyuf.dll]
Process: svchost.exe (PID: 804) Address: 0x00870000 Size: 217088

Object: Hidden Module [Name: UACpmooryyoui.dll]
Process: svchost.exe (PID: 804) Address: 0x00940000 Size: 77824

Object: Hidden Module [Name: UACneuaqneqmm.dll]
Process: svchost.exe (PID: 804) Address: 0x00b90000 Size: 73728

Object: Hidden Module [Name: kbiwkmtairxydw.dll]
Process: svchost.exe (PID: 804) Address: 0x10000000 Size: 57344

Object: Hidden Module [Name: UACpmooryyoui.dll]
Process: Explorer.EXE (PID: 504) Address: 0x00a50000 Size: 77824

Object: Hidden Module [Name: kbiwkmylkrxdnd.dll]
Process: Explorer.EXE (PID: 504) Address: 0x10000000 Size: 28672

Object: Hidden Module [Name: UACtjewaedyuf.dll]
Process: Iexplore.exe (PID: 2060) Address: 0x00aa0000 Size: 217088

Object: Hidden Module [Name: kbiwkmylkrxdnd.dll]
Process: Iexplore.exe (PID: 2060) Address: 0x10000000 Size: 28672

Hidden Services
——————-
Service Name: kbiwkmvoaodqcw
Image Path: C:\WINDOWS\system32\drivers\kbiwkmjcxejbow.sys

Service Name: UACd.sys
Image Path: C:\WINDOWS\system32\drivers\UACohktyagxue.sys

==EOF==

SysProt AntiRootkit v1.0.1.0
by swatkat

********************************************************************************
**********
********************************************************************************
**********

No Hidden Processes found

********************************************************************************
**********
********************************************************************************
**********
No Hidden Kernel Modules found

********************************************************************************
**********
********************************************************************************
**********
No SSDT Hooks found

********************************************************************************
**********
********************************************************************************
**********
No Kernel Hooks found

********************************************************************************
**********
********************************************************************************
**********
No IRP Hooks found

********************************************************************************
**********
********************************************************************************
**********
Ports:
Local Address: DOUG-PC.OK.COX.NET:3635
Remote Address: IW-IN-F156.GOOGLE.COM:HTTP
Type: TCP
Process: 3244 (PID)
State: ESTABLISHED

Local Address: DOUG-PC.OK.COX.NET:3628
Remote Address: IP98-174-28-33.AT.AT.COX.NET:HTTP
Type: TCP
Process: 3244 (PID)
State: ESTABLISHED

Local Address: DOUG-PC.OK.COX.NET:3615
Remote Address: CDS485.DAL.LLNW.NET:HTTP
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC.OK.COX.NET:3614
Remote Address: CDS485.DAL.LLNW.NET:HTTP
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC.OK.COX.NET:3613
Remote Address: CDS485.DAL.LLNW.NET:HTTP
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC.OK.COX.NET:3609
Remote Address: CDS485.DAL.LLNW.NET:HTTP
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC.OK.COX.NET:3604
Remote Address: BIGRESPONSE.COM:HTTP
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC.OK.COX.NET:3603
Remote Address: CDS485.DAL.LLNW.NET:HTTP
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC.OK.COX.NET:3601
Remote Address: CDS485.DAL.LLNW.NET:HTTP
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC.OK.COX.NET:3589
Remote Address: CDS485.DAL.LLNW.NET:HTTP
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC.OK.COX.NET:3579
Remote Address: CDS485.DAL.LLNW.NET:HTTP
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC.OK.COX.NET:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4 (PID)
State: LISTENING

Local Address: DOUG-PC:3634
Remote Address: LOCALHOST:3550
Type: TCP
Process: 3244 (PID)
State: ESTABLISHED

Local Address: DOUG-PC:3626
Remote Address: LOCALHOST:3550
Type: TCP
Process: 3244 (PID)
State: ESTABLISHED

Local Address: DOUG-PC:3612
Remote Address: LOCALHOST:3550
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3611
Remote Address: LOCALHOST:3550
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3608
Remote Address: LOCALHOST:3550
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3605
Remote Address: LOCALHOST:3550
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3599
Remote Address: LOCALHOST:3550
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3597
Remote Address: LOCALHOST:3550
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3596
Remote Address: LOCALHOST:3550
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3583
Remote Address: LOCALHOST:3550
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3578
Remote Address: LOCALHOST:3550
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3634
Type: TCP
Process: 3244 (PID)
State: ESTABLISHED

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3632
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3630
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3626
Type: TCP
Process: 3244 (PID)
State: ESTABLISHED

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3625
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3624
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3622
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3620
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3618
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3616
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3607
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3602
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3595
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3594
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3592
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3586
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3584
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3582
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3581
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3580
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3576
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3573
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3572
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3570
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3568
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3566
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3564
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3562
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3560
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3558
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3556
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3554
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: LOCALHOST:3552
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:3550
Remote Address: 0.0.0.0:0
Type: TCP
Process: 3244 (PID)
State: LISTENING

Local Address: DOUG-PC:3549
Remote Address: LOCALHOST:3550
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:2789
Remote Address: LOCALHOST:2788
Type: TCP
Process: 2504 (PID)
State: ESTABLISHED

Local Address: DOUG-PC:2788
Remote Address: LOCALHOST:2789
Type: TCP
Process: 2504 (PID)
State: ESTABLISHED

Local Address: DOUG-PC:2787
Remote Address: LOCALHOST:2785
Type: TCP
Process: 2504 (PID)
State: ESTABLISHED

Local Address: DOUG-PC:2786
Remote Address: LOCALHOST:3546
Type: TCP
Process: 0 (PID)
State: TIME_WAIT

Local Address: DOUG-PC:2786
Remote Address: 0.0.0.0:0
Type: TCP
Process: 2504 (PID)
State: LISTENING

Local Address: DOUG-PC:2785
Remote Address: LOCALHOST:2787
Type: TCP
Process: 2504 (PID)
State: ESTABLISHED

Local Address: DOUG-PC:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4 (PID)
State: LISTENING

Local Address: DOUG-PC:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: 904 (PID)
State: LISTENING

Local Address: DOUG-PC.OK.COX.NET:138
Remote Address: NA
Type: UDP
Process: 4 (PID)
State: NA

Local Address: DOUG-PC.OK.COX.NET:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: 4 (PID)
State: NA

Local Address: DOUG-PC:3548
Remote Address: NA
Type: UDP
Process: 3244 (PID)
State: NA

Local Address: DOUG-PC:MICROSOFT-DS
Remote Address: NA
Type: UDP
Process: 4 (PID)
State: NA

********************************************************************************
**********
********************************************************************************
**********
No hidden files/folders found
Continuation of logs:

OTL logfile created on: 8/31/2009 3:09:13 PM - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\rick_2\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 273.07 Mb Available Physical Memory | 53.54% Memory free
1.22 Gb Paging File | 1.07 Gb Available in Paging File | 87.47% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.47 Gb Total Space | 53.31 Gb Free Space | 71.59% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 74.46 Gb Total Space | 53.56 Gb Free Space | 71.93% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive S: | 74.46 Gb Total Space | 53.56 Gb Free Space | 71.93% Space Free | Partition Type: NTFS

Computer Name: DOUG-PC
Current User Name: doug
Logged in as Administrator.

Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\Iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\rick_2\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DSBrokerService [On_Demand | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (ewido security suite control [Auto | Stopped]) – C:\Program Files\ewido anti-malware\ewidoctrl.exe (ewido networks)
SRV - (ewido security suite guard [Disabled | Stopped]) – C:\Program Files\ewido anti-malware\ewidoguard.exe (ewido networks)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gusvc [Auto | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Stopped]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (mcmscsvc [Auto | Running]) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McNASvc [Auto | Stopped]) – c:\program files\common files\mcafee\mna\mcnasvc.exe (McAfee, Inc.)
SRV - (McODS [On_Demand | Stopped]) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy [Auto | Stopped]) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McShield [Unknown | Stopped]) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon [On_Demand | Stopped]) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MDM [Auto | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (Net Driver HPZ12 [Auto | Stopped]) – C:\WINDOWS\System32\HPZinw12.dll (Hewlett-Packard)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Stopped]) – C:\WINDOWS\System32\HPZipm12.dll (Hewlett-Packard)
SRV - (UleadBurningHelper [Auto | Stopped]) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (aeaudio [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ati2mtag [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (drvmcdb [Boot | Running]) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm [Auto | Stopped]) – C:\WINDOWS\System32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (DSproct [On_Demand | Stopped]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Stopped]) – C:\WINDOWS\System32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (EL90X [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\el90xnd5.sys (3Com Corporation)
DRV - (EL90XBC [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\el90xbc5.sys (3Com Corporation)
DRV - (ewido security suite driver [System | Stopped]) – C:\Program Files\ewido anti-malware\guard.sys ()
DRV - (i81x [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (iAimFP0 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV01nt.sys (Intel® Corporation)
DRV - (iAimFP1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV02NT.sys (Intel® Corporation)
DRV - (iAimFP2 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV05NT.sys (Intel® Corporation)
DRV - (iAimFP3 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys (Intel® Corporation)
DRV - (iAimFP4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys (Intel® Corporation)
DRV - (iAimTV0 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV01nt.sys (Intel® Corporation)
DRV - (iAimTV1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV02NT.sys (Intel® Corporation)
DRV - (iAimTV3 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV04nt.sys (Intel® Corporation)
DRV - (iAimTV4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys (Intel® Corporation)
DRV - (ialm [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (lknuhst [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\lknuhst.sys (SerComm)
DRV - (LKNUHUB [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\lknuhub.sys (SerComm)
DRV - (mfeavfk [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [System | Stopped]) – C:\WINDOWS\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (mfesmfk [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (motmodem [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\motmodem.sys (Motorola)
DRV - (MPFP [System | Running]) – C:\WINDOWS\System32\Drivers\Mpfp.sys (McAfee, Inc.)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (npf [Auto | Stopped]) – C:\WINDOWS\System32\drivers\npf.sys (CACE Technologies)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) – C:\WINDOWS\System32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ROOTMODEM [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (smwdm [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sscdbhk5 [System | Running]) – C:\WINDOWS\System32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln [System | Running]) – C:\WINDOWS\System32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (tfsnboio [Auto | Stopped]) – C:\WINDOWS\System32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsncofs [Auto | Stopped]) – C:\WINDOWS\System32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsndrct [Auto | Stopped]) – C:\WINDOWS\System32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres [Auto | Stopped]) – C:\WINDOWS\System32\dla\tfsndres.sys (Sonic Solutions)
DRV - (tfsnifs [Auto | Stopped]) – C:\WINDOWS\System32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsnopio [Auto | Stopped]) – C:\WINDOWS\System32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool [Auto | Stopped]) – C:\WINDOWS\System32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsnudf [Auto | Stopped]) – C:\WINDOWS\System32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnudfa [Auto | Stopped]) – C:\WINDOWS\System32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (ULCDRHlp [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\ULCDRHlp.sys (Ulead Systems, Inc.)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (usbser [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\usbser.sys (Microsoft Corporation)
DRV - (usb_rndisx [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\usb8023x.sys (Microsoft Corporation)
DRV - (USIUDF [System | Stopped]) – C:\WINDOWS\System32\Drivers\USIUDF.sys (Ulead Systems, Inc.)
DRV - (wceusbsh [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wceusbsh.sys (Microsoft Corporation)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.msn.com/0/1000/default.asp
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.oscn.net/
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.oscn.net"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.2

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/06/03 10:07:56 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/30 13:07:41 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/19 18:54:18 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/17 09:47:14 | 00,000,000 | —D | M]

[2008/09/09 15:53:31 | 00,000,000 | —D | M] – C:\Documents and Settings\rick_2\Application Data\mozilla\Extensions
[2008/09/09 15:53:31 | 00,000,000 | —D | M] – C:\Documents and Settings\rick_2\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/31 10:20:36 | 00,000,000 | —D | M] – C:\Documents and Settings\rick_2\Application Data\mozilla\Firefox\Profiles\6ldr4f98.default\extensions
[2009/06/30 12:43:13 | 00,000,000 | —D | M] – C:\Documents and Settings\rick_2\Application Data\mozilla\Firefox\Profiles\6ldr4f98.default\extensions\[removed]
[2009/08/31 10:20:36 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/08/17 09:47:14 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/06/03 10:08:46 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/08/17 09:46:35 | 00,023,544 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/17 09:46:35 | 00,137,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/06/17 16:12:42 | 00,114,688 | —- | M] (Adobe Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\np32dsw.dll
[2009/06/03 10:07:53 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2007/05/11 17:41:00 | 00,200,704 | —- | M] (Ancestry.com) – C:\Program Files\mozilla firefox\plugins\npImgCtl.dll
[2009/08/17 09:46:59 | 00,065,016 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2007/03/22 20:23:30 | 00,017,248 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL
[2006/12/18 05:18:30 | 00,077,824 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2006/01/23 10:57:45 | 00,106,496 | —- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2006/01/23 10:57:45 | 00,106,496 | —- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2006/01/18 12:50:00 | 00,319,488 | —- | M] ( ) – C:\Program Files\mozilla firefox\plugins\npsnapfish.dll
[2009/08/17 09:47:06 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/08/17 09:47:06 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/08/17 09:47:06 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/08/17 09:47:06 | 00,002,344 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/08/17 09:47:06 | 00,002,371 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/08/17 09:47:07 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/08/17 09:47:07 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (152 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 91.212.127.221 viruskill2009.microsoft.com
O1 - Hosts: 91.212.127.221 viruskill2009.com
O1 - Hosts: 91.212.127.221 www.viruskill2009.com
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (BHO) - {0B7FE966-C2DC-4af7-8A5F-E4141B92546E} - C:\WINDOWS\System32\iehelper.dll ()
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (PopUpCop) - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - C:\Program Files\PopUpCop\PopUpCop.dll (EdenSoft ™)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [dla] C:\WINDOWS\System32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [KnexStarter] C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\Appinterfaces\HPDeviceService.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\Media Experience\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PSDiagnosticM] C:\Program Files\Linksys Wireless-G Print Server\PSDiagnosticM.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [RunTasktray] File not found
O4 - HKLM..\Run: [StorageGuard] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [system tool] C:\Program Files\bbtmwg\dwkksysguard.exe (Microsoft Corporation)
O4 - HKLM..\Run: [USIUDF_Eject_Monitor] C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe (Ulead Systems)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [system tool] C:\Program Files\bbtmwg\dwkksysguard.exe (Microsoft Corporation)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Search; - File not found
O8 - Extra context menu item: &Yahoo;! Search - C:\Program Files\Yahoo!\Common [2009/05/28 16:47:43 | 00,000,000 | —D | M]
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Open Image in New Window - C:\Program Files\PopUpCop\PopUpCop.dll (EdenSoft ™)
O8 - Extra context menu item: Yahoo! &Dictionary; - C:\Program Files\Yahoo!\Common [2009/05/28 16:47:43 | 00,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Maps; - C:\Program Files\Yahoo!\Common [2009/05/28 16:47:43 | 00,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &SMS; - C:\Program Files\Yahoo!\Common [2009/05/28 16:47:43 | 00,000,000 | —D | M]
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\System32\lsp.dll ()
O15 - HKLM\..Trusted Domains: hp.com ([]https in Trusted sites)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] * in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.windowsupdate] * in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([office] * in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([officeupdate] * in Trusted sites)
O15 - HKCU\..Trusted Domains: 80 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…96/mcinsctl.cab (McAfee.com Operating System Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab (DwnldGroupMgr Class)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\HPDCS {ba135f49-a12c-4e26-a2c4-6ea945999072} - C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\APP\hpdcsapp.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\hppfile {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\hppsam {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\hppzip {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {54D9498B-CF93-414F-8984-8CE7FDE0D391} - C:\Program Files\ewido anti-malware\shellhook.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 14:36:02 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2 C:\WINDOWS\*.tmp files]
[2009/08/31 15:07:19 | 00,514,048 | —- | C] (OldTimer Tools) – C:\Documents and Settings\rick_2\Desktop\OTL.exe
[2009/08/31 15:01:12 | 00,000,000 | —D | C] – C:\Documents and Settings\rick_2\Desktop\gmer
[2009/08/31 15:01:00 | 00,280,282 | —- | C] () – C:\Documents and Settings\rick_2\Desktop\gmer.zip
[2009/08/31 14:56:10 | 00,000,000 | —D | C] – C:\Documents and Settings\rick_2\Desktop\SysProt
[2009/08/31 14:55:39 | 00,354,396 | —- | C] () – C:\Documents and Settings\rick_2\Desktop\SysProt.zip
[2009/08/31 11:42:49 | 00,000,000 | —D | C] – C:\Documents and Settings\rick_2\Desktop\RootRepeal
[2009/08/31 11:42:31 | 00,464,491 | —- | C] () – C:\Documents and Settings\rick_2\Desktop\RootRepeal.zip
[2009/08/31 11:05:08 | 00,000,000 | —D | C] – C:\Documents and Settings\rick_2\Desktop\Old logs
[2009/08/31 10:52:31 | 00,008,212 | —- | C] () – C:\WINDOWS\mfebcdata
[2009/08/28 12:16:15 | 00,359,932 | —- | C] () – C:\Documents and Settings\rick_2\Desktop\dds.pif
[2009/08/28 12:16:10 | 00,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2009/08/28 12:02:45 | 00,046,080 | —- | C] () – C:\Documents and Settings\rick_2\Desktop\Win32kDiag.exe
[2009/08/28 11:04:31 | 03,942,048 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\rick_2\Desktop\mblah.com
[2009/08/28 10:10:58 | 00,012,032 | —- | C] () – C:\WINDOWS\System32\iehelper.dll
[2009/08/27 19:14:28 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\lsp.dll
[2009/08/27 19:14:26 | 00,222,208 | —- | C] () – C:\WINDOWS\syssvc.exe
[2009/08/27 18:44:24 | 00,000,000 | —D | C] – C:\Program Files\bbtmwg
[2009/08/27 18:40:04 | 00,000,000 | —D | C] – C:\spoolerlogs
[2009/08/24 16:04:21 | 00,000,000 | —D | C] – C:\Program Files\WinPcap
[2009/08/11 22:56:33 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dhtmled.ocx
[2009/08/11 22:55:00 | 00,655,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstscax.dll
[2009/08/11 11:21:29 | 00,029,281 | —- | C] () – C:\Documents and Settings\rick_2\My Documents\image3140477.jpg
[2009/08/05 04:11:47 | 00,204,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mswebdvd.dll
[2008/06/06 18:47:38 | 00,163,840 | —- | C] () – C:\WINDOWS\System32\hppatusg01.dll
[2008/06/06 18:46:54 | 00,126,976 | —- | C] () – C:\WINDOWS\System32\HPDevEnm.dll
[2008/05/17 03:02:05 | 00,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2006/04/22 18:00:10 | 00,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2005/07/06 16:04:19 | 00,000,377 | —- | C] () – C:\WINDOWS\pnxtrvu.ini
[2004/10/25 18:09:59 | 00,000,035 | —- | C] () – C:\WINDOWS\A5W.INI
[2004/10/25 17:06:49 | 00,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2004/01/07 09:59:25 | 00,000,116 | —- | C] () – C:\WINDOWS\geoclock.ini
[2003/12/17 16:09:53 | 00,000,036 | —- | C] () – C:\WINDOWS\WestCm.ini
[2003/12/11 14:26:36 | 00,000,793 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/12/11 08:43:10 | 00,000,375 | —- | C] () – C:\WINDOWS\hpbvspst.ini
[2003/12/11 08:43:09 | 00,001,027 | —- | C] () – C:\WINDOWS\hpbvnstp.ini
[2003/12/11 08:42:58 | 00,196,608 | R— | C] () – C:\WINDOWS\System32\HPBVNSTP.DLL
[2003/12/11 08:41:55 | 00,006,163 | —- | C] () – C:\WINDOWS\hplj1300.ini
[2003/12/11 08:21:02 | 00,000,174 | —- | C] () – C:\WINDOWS\System32\mcini.ini
[2003/12/04 14:23:44 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/12/04 14:21:44 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/12/04 14:16:47 | 00,000,171 | —- | C] () – C:\WINDOWS\wininit.ini
[2003/12/04 14:05:16 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/12/04 13:55:42 | 00,000,550 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/10/16 16:50:50 | 00,000,791 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2003/08/13 23:54:00 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/05/22 09:29:17 | 00,094,274 | —- | C] () – C:\WINDOWS\System32\HPBHEALR.DLL
[2003/01/07 16:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/09/03 14:36:02 | 00,000,666 | —- | C] () – C:\WINDOWS\WIN.INI
[2002/09/03 14:26:32 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2000/10/23 19:12:34 | 00,012,800 | —- | C] () – C:\WINDOWS\System32\std-2.1-vc5.0-mt.dll

========== Files - Modified Within 30 Days ==========

[5 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/08/31 15:07:20 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Documents and Settings\rick_2\Desktop\OTL.exe
[2009/08/31 15:01:02 | 00,280,282 | —- | M] () – C:\Documents and Settings\rick_2\Desktop\gmer.zip
[2009/08/31 14:55:44 | 00,354,396 | —- | M] () – C:\Documents and Settings\rick_2\Desktop\SysProt.zip
[2009/08/31 11:42:32 | 00,464,491 | —- | M] () – C:\Documents and Settings\rick_2\Desktop\RootRepeal.zip
[2009/08/31 10:57:45 | 00,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2009/08/31 10:54:17 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2009/08/31 10:53:24 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/08/31 10:52:31 | 00,008,212 | —- | M] () – C:\WINDOWS\mfebcdata
[2009/08/31 10:52:12 | 01,610,590 | -H– | M] () – C:\Documents and Settings\rick_2\Local Settings\Application Data\IconCache.db
[2009/08/31 10:51:41 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/08/28 12:16:16 | 00,359,932 | —- | M] () – C:\Documents and Settings\rick_2\Desktop\dds.pif
[2009/08/28 12:02:46 | 00,046,080 | —- | M] () – C:\Documents and Settings\rick_2\Desktop\Win32kDiag.exe
[2009/08/28 11:04:32 | 03,942,048 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\rick_2\Desktop\mblah.com
[2009/08/28 10:10:58 | 00,012,032 | —- | M] () – C:\WINDOWS\System32\iehelper.dll
[2009/08/28 04:57:13 | 00,222,208 | —- | M] () – C:\WINDOWS\syssvc.exe
[2009/08/27 19:14:29 | 00,180,224 | —- | M] () – C:\WINDOWS\System32\lsp.dll
[2009/08/27 18:43:05 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/08/26 16:51:15 | 00,055,296 | —- | M] () – C:\Documents and Settings\rick_2\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/15 01:51:22 | 00,000,348 | —- | M] () – C:\WINDOWS\tasks\McDefragTask.job
[2009/08/14 03:04:36 | 00,505,240 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/08/14 03:04:36 | 00,444,028 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2009/08/14 03:04:36 | 00,071,904 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2009/08/12 03:07:46 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/08/11 11:21:30 | 00,029,281 | —- | M] () – C:\Documents and Settings\rick_2\My Documents\image3140477.jpg
[2009/08/05 04:11:47 | 00,204,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mswebdvd.dll
[2009/08/05 04:11:47 | 00,204,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mswebdvd.dll
[2009/08/03 13:36:28 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/03 13:36:06 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys

========== LOP Check ==========

[2009/05/28 16:58:42 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2005/05/26 08:34:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2006/04/07 10:08:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DIGStream
[2003/12/11 16:20:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2003/12/11 14:10:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2003/12/26 12:49:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2007/10/08 11:20:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PACE Anti-Piracy
[2007/07/27 11:44:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2003/12/04 13:54:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2007/07/27 12:44:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/09/07 13:31:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2006/01/23 11:19:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/05/11 13:19:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/05/28 16:56:39 | 00,000,000 | RH-D | M] – C:\Documents and Settings\rick_2\Application Data
[2007/09/07 13:31:28 | 00,000,000 | —D | M] – C:\Documents and Settings\rick_2\Application Data\iWin
[2006/05/22 08:55:46 | 00,000,000 | —D | M] – C:\Documents and Settings\rick_2\Application Data\Musicmatch
[2007/10/08 11:20:10 | 00,000,000 | —D | M] – C:\Documents and Settings\rick_2\Application Data\PACE Anti-Piracy
[2006/11/20 16:27:14 | 00,000,000 | —D | M] – C:\Documents and Settings\rick_2\Application Data\PopupCop
[2008/05/19 11:42:51 | 00,000,000 | —D | M] – C:\Documents and Settings\rick_2\Application Data\Snapfish
[2006/01/23 12:31:17 | 00,000,000 | —D | M] – C:\Documents and Settings\rick_2\Application Data\Ulead Systems
[2002/08/29 06:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\DESKTOP.INI
[2009/08/31 10:51:41 | 00,000,868 | —- | M] () – C:\WINDOWS\Tasks\Google Software Updater.job
[2009/08/15 01:51:22 | 00,000,348 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2009/08/01 01:00:00 | 00,000,350 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job
[2009/08/31 10:53:24 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6FDE1666
@Alternate Data Stream - 1083 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:6w0bRhUgp0aI3ZconTgZ
@Alternate Data Stream - 1029 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:JUaHHZEaVkPSzVKNRnZ5
< End of report >


OTL Extras logfile created on: 8/31/2009 3:09:13 PM - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\rick_2\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 273.07 Mb Available Physical Memory | 53.54% Memory free
1.22 Gb Paging File | 1.07 Gb Available in Paging File | 87.47% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.47 Gb Total Space | 53.31 Gb Free Space | 71.59% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 74.46 Gb Total Space | 53.56 Gb Free Space | 71.93% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive S: | 74.46 Gb Total Space | 53.56 Gb Free Space | 71.93% Space Free | Partition Type: NTFS

Computer Name: DOUG-PC
Current User Name: doug
Logged in as Administrator.

Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"135:TCP" = 135:TCP:*:Enabled:RPC
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"80:TCP" = 80:TCP:*:Enabled:Promo
"53:UDP" = 53:UDP:*:Enabled:Promo

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe" = C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe:*:Enabled:HP Easy Printer Care HPPRun – (Hewlett-Packard Company)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – File not found
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – File not found
"C:\Program Files\Electronic Arts\EADM\Core.exe" = C:\Program Files\Electronic Arts\EADM\Core.exe:*:Disabled:EA Download Manager – File not found
"C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe" = C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe:*:Enabled:HP Easy Printer Care HPPRun – (Hewlett-Packard Company)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent – (McAfee, Inc.)
"C:\WINDOWS\Temp\_ex-08.exe" = C:\WINDOWS\Temp\_ex-08.exe:*:Enabled:Promo – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{020CF65F-700F-4E55-AFB7-97024584A2B3}" = Events Communication Components
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{32F66A20-7614-11D4-BD11-00104BD3F987}" = MathPlayer
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{41915A51-6F92-4F0E-87C4-8178785B96CC}" = HP Printer Settings Tools
"{448AB2CB-C94A-47DE-80B8-9D7824DEFA57}" = Ulead DVD MovieFactory 4.0
"{49782B2F-49AE-423D-85D6-4EE7019CEA13}" = HP Easy Printer Care
"{5CB3DDA0-F143-4E65-A2FA-3C95F82139D2}_is1" = DVD Slideshow Builder [removed]
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{67C01AEA-3231-4A83-975B-A2E14D1C2BAC}" = BlueBeat.com
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{7527CD9F-894E-47B3-9AFB-3E680E007051}" = HP Proactive Services
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8 Dell Edition
"{81B3BEF9-5D97-4096-86E9-5B48A5BC32D0}" = Motorola Driver Installation 3.4.0
"{89EE857B-8970-4F9F-AB58-A1C873AC72B3}" = Broadcom Management Programs
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}" = Musicmatch® Jukebox
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{9B79DCB0-AAD7-456B-8D07-433C936FA24B}" = DS21Patch
"{A1E98303-102A-46FB-A2D0-3838C3F64DF2}" = Core Communication Components
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{AD8E6D29-95EC-494E-8AF5-566E784819A6}" = Ulead Data-Add 2.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C0A8F64F-36C8-489F-B813-90D60B541D1E}" = Device Data Communication Components
"{C61244F9-C335-4EE4-BF7B-5CAB855555E3}" = Linksys Wireless-G Print Server
"{C63E7C60-25EB-11D3-8EDA-00A0C911E8E5}" = Microsoft Outlook Personal Folders Backup
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}" = Jasc Paint Shop Photo Album
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D514BD88-33CF-451E-81D6-A528E3BA817A}" = Visionary Viewer
"{D5842AC3-59C7-4DDD-BB33-54FE544DB3DA}" = Operating System Communication Components
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{ECB904FE-CB4D-40A4-A884-E278410F0CE1}" = HP Printer Usage Report
"{F7B0E599-C114-4493-BC4D-D8FC7CBBABBB}" = 32 Bit HP CIO Components Installer
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"BFGC" = Big Fish Games Client
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"ERUNT_is1" = ERUNT 1.1j
"ESPNMotion" = ESPNMotion
"ewidoantimalware" = ewido anti-malware
"FLV Player" = FLV Player 2.0 (build 25)
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"HP Easy Printer Care" = HP Easy Printer Care
"InstallShield_{89EE857B-8970-4F9F-AB58-A1C873AC72B3}" = Broadcom Management Programs
"iolo technologies' System Mechanic" = iolo technologies' System Mechanic
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Money2005b" = Microsoft Money 2005
"Mozilla Firefox (3.5.2)" = Mozilla Firefox (3.5.2)
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Need2FindBar Uninstall" = Need2Find Bar
"PopUpCop" = PopUpCop
"PREMISE Forms Launcher" = PREMISE Forms Launcher
"QuickTime" = QuickTime
"Security Toolbar" = Security Toolbar
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows Mobile Device Handbook" = Windows Mobile® Device Handbook
"Windows XP Service Pack" = Windows XP Service Pack 2
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WorkgroupShareClient" = WorkgroupShare Client
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Customizations" = Yahoo! Browser Services
"Yahoo! Internet Mail" = Yahoo! Internet Mail
"Yahoo! Toolbar" = Yahoo! Toolbar
"YInstHelper" = Yahoo! Install Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/7/2009 9:22:28 AM | Computer Name = DOUG-PC | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 5/7/2009 9:36:46 AM | Computer Name = DOUG-PC | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 5/7/2009 9:37:48 AM | Computer Name = DOUG-PC | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 5/7/2009 9:43:35 AM | Computer Name = DOUG-PC | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 5/7/2009 9:57:39 AM | Computer Name = DOUG-PC | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 5/7/2009 9:58:42 AM | Computer Name = DOUG-PC | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 5/7/2009 10:39:20 AM | Computer Name = DOUG-PC | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 5/7/2009 12:16:36 PM | Computer Name = DOUG-PC | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3399, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 5/7/2009 2:25:52 PM | Computer Name = DOUG-PC | Source = Application Hang | ID = 1002
Description = Hanging application OUTLOOK.EXE, version 11.0.8217.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/7/2009 2:57:05 PM | Computer Name = DOUG-PC | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x00000000.

[ System Events ]
Error - 8/28/2009 1:57:11 PM | Computer Name = DOUG-PC | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 8/28/2009 1:57:11 PM | Computer Name = DOUG-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD Fips intelppm IPSec mfehidk MPFP MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip

Error - 8/28/2009 1:57:16 PM | Computer Name = DOUG-PC | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 8/28/2009 1:57:51 PM | Computer Name = DOUG-PC | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}

Error - 8/28/2009 1:57:54 PM | Computer Name = DOUG-PC | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}

Error - 8/28/2009 1:58:20 PM | Computer Name = DOUG-PC | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 8/28/2009 2:25:50 PM | Computer Name = DOUG-PC | Source = DCOM | ID = 10010
Description = The server {00020906-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 8/31/2009 11:21:22 AM | Computer Name = DOUG-PC | Source = DCOM | ID = 10010
Description = The server {B44D92F9-978C-42F3-9382-6EAD817BA0AE} did not register
with DCOM within the required timeout.

Error - 8/31/2009 11:24:15 AM | Computer Name = DOUG-PC | Source = DCOM | ID = 10010
Description = The server {B44D92F9-978C-42F3-9382-6EAD817BA0AE} did not register
with DCOM within the required timeout.

Error - 8/31/2009 11:27:32 AM | Computer Name = DOUG-PC | Source = DCOM | ID = 10010
Description = The server {B811337D-6A95-4D52-9647-09BBCA0C9D6A} did not register
with DCOM within the required timeout.


< End of report >
Please do the following:

Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–


NOTE:If ComboFix asks to install the Recovery Console, please ALLOW it to do so.
ComboFix 09-08-31.03 - doug 08/31/2009 16:11.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.216 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\windows\Fonts\Wphv07nb.ttf
c:\windows\Installer\11edc37.msp
c:\windows\Installer\11edc48.msp
c:\windows\Installer\29fced9.msp
c:\windows\Installer\be3f9.msi
c:\windows\Installer\c8cf3.msp
c:\windows\Installer\WMEncoder.msi
c:\windows\run.log
c:\windows\syssvc.exe
c:\windows\system32\drivers\kbiwkmjcxejbow.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\drivers\UACohktyagxue.sys
c:\windows\system32\kbiwkmfomomkgl.dat
c:\windows\system32\kbiwkmmpaxwtsy.dat
c:\windows\system32\kbiwkmtairxydw.dll
c:\windows\system32\kbiwkmylkrxdnd.dll
c:\windows\system32\lsp.dll
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\UACbsqsvsntjp.db
c:\windows\system32\uacinit.dll
c:\windows\system32\UACiuhxppvbsn.dll
c:\windows\system32\UACnansiucotl.dat
c:\windows\system32\UACneuaqneqmm.dll
c:\windows\system32\UACpmooryyoui.dll
c:\windows\system32\UACtjewaedyuf.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_kbiwkmvoaodqcw
——-\Legacy_kbiwkmvoaodqcw
——-\Service_UACd.sys
——-\Legacy_UACd.sys
——-\Legacy_NPF
——-\Service_npf


((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-31 )))))))))))))))))))))))))))))))
.

2009-08-28 17:16 . 2009-08-28 17:16 ——– d–h–w- c:\windows\PIF
2009-08-27 23:44 . 2009-08-27 23:44 ——– d—–w- c:\program files\bbtmwg
2009-08-27 23:40 . 2009-08-27 23:40 ——– d—–w- C:\spoolerlogs
2009-08-12 03:55 . 2009-06-05 07:42 655872 ——w- c:\windows\system32\dllcache\mstscax.dll
2009-08-05 09:11 . 2009-08-05 09:11 204800 ——w- c:\windows\system32\dllcache\mswebdvd.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-31 15:08 . 2008-06-03 18:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-28 16:02 . 2009-04-28 16:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-27 23:19 . 2009-08-27 23:19 889772 —-a-w- c:\windows\system32\xa.tmp
2009-08-25 00:27 . 2009-06-05 16:08 3942048 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-05 09:11 . 2002-12-12 06:14 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 18:36 . 2009-04-28 16:01 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 18:36 . 2009-04-28 16:01 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-31 22:01 . 2009-01-14 22:31 ——– d—–w- c:\program files\Microsoft Silverlight
2009-07-17 18:55 . 2002-08-29 11:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-14 04:43 . 2003-12-11 21:15 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-13 17:08 . 2006-12-29 17:37 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-07-13 15:45 . 2003-12-04 19:16 48976 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-10 19:35 . 2006-12-29 17:49 ——– d—–w- c:\program files\McAfee
2009-06-30 01:38 . 2008-04-11 15:38 1878984 —-a-w- c:\documents and settings\rick_2\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-06-26 16:18 . 2004-08-24 01:32 659456 —-a-w- c:\windows\system32\wininet.dll
2009-06-26 16:18 . 2004-08-04 07:56 81920 ——w- c:\windows\system32\ieencode.dll
2009-06-25 18:36 . 2002-08-29 11:00 95744 —-a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36 . 2002-08-29 11:00 661504 —-a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36 . 2002-08-29 11:00 517120 —-a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36 . 2002-08-29 11:00 48640 —-a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36 . 2002-08-29 11:00 471552 —-a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36 . 2002-08-29 11:00 47104 —-a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36 . 2002-08-29 11:00 225280 —-a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36 . 2002-08-29 11:00 186880 —-a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36 . 2002-08-29 11:00 177152 —-a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36 . 2002-08-29 11:00 16896 —-a-w- c:\windows\system32\mqise.dll
2009-06-25 18:36 . 2002-08-29 11:00 138240 —-a-w- c:\windows\system32\mqad.dll
2009-06-25 18:36 . 2002-08-29 11:00 123392 —-a-w- c:\windows\system32\mqrtdep.dll
2009-06-22 11:49 . 2002-08-29 11:00 19968 —-a-w- c:\windows\system32\mqbkup.exe
2009-06-22 11:49 . 2002-08-29 11:00 117248 —-a-w- c:\windows\system32\mqtgsvc.exe
2009-06-22 11:49 . 2002-08-29 11:00 4608 —-a-w- c:\windows\system32\mqsvc.exe
2009-06-22 11:48 . 2002-08-29 11:00 91776 —-a-w- c:\windows\system32\drivers\mqac.sys
2009-06-16 14:55 . 2002-08-29 11:00 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2002-08-29 11:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-12 11:50 . 2002-08-29 11:00 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 11:50 . 2002-08-29 11:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:21 . 2002-08-29 11:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:32 . 2003-10-21 23:06 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-05 07:42 . 2002-08-29 11:00 655872 —-a-w- c:\windows\system32\mstscax.dll
2009-06-03 19:27 . 2003-05-30 15:00 1290752 —-a-w- c:\windows\system32\quartz.dll
2009-06-03 15:07 . 2009-06-03 15:08 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-06-03 15:07 . 2009-06-03 15:07 152576 —-a-w- c:\documents and settings\rick_2\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-05-08_18.31.24 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-31 21:24 . 2009-08-31 21:24 16384 c:\windows\Temp\Perflib_Perfdata_69c.dat
- 2002-08-29 11:00 . 2004-08-04 07:56 50176 c:\windows\SYSTEM32\utilman.exe
+ 2002-08-29 11:00 . 2006-10-04 08:48 50176 c:\windows\SYSTEM32\utilman.exe
- 2002-08-29 11:00 . 2004-08-04 07:56 35840 c:\windows\SYSTEM32\umandlg.dll
+ 2002-08-29 11:00 . 2006-10-04 13:33 35840 c:\windows\SYSTEM32\umandlg.dll
+ 2007-01-29 08:58 . 2009-07-14 11:03 46080 c:\windows\SYSTEM32\tzchange.exe
+ 2008-07-30 02:10 . 2008-07-30 02:10 26112 c:\windows\SYSTEM32\TsWpfWrp.exe
+ 2005-01-01 17:51 . 2007-07-27 15:41 26488 c:\windows\SYSTEM32\spupdsvc.exe
- 2005-01-01 17:51 . 2008-07-09 07:38 26488 c:\windows\SYSTEM32\spupdsvc.exe
+ 2009-06-30 18:05 . 2008-07-06 12:06 89088 c:\windows\SYSTEM32\SPOOL\PRTPROCS\W32X86\filterpipelineprintproc.dll
- 2008-01-31 21:55 . 2007-11-30 12:39 17272 c:\windows\SYSTEM32\spmsg.dll
+ 2008-01-31 21:55 . 2009-05-26 11:40 17272 c:\windows\SYSTEM32\spmsg.dll
+ 2008-07-30 00:59 . 2008-07-30 00:59 43544 c:\windows\SYSTEM32\PresentationHostProxy.dll
- 2002-08-29 11:00 . 2009-02-20 08:30 39424 c:\windows\SYSTEM32\pngfilt.dll
+ 2002-08-29 11:00 . 2009-06-26 16:18 39424 c:\windows\SYSTEM32\pngfilt.dll
+ 2002-09-03 19:51 . 2009-08-14 08:04 71904 c:\windows\SYSTEM32\PERFC009.DAT
+ 2002-11-20 17:50 . 2006-10-04 08:48 53760 c:\windows\SYSTEM32\narrator.exe
- 2002-11-20 17:50 . 2004-08-04 07:56 53760 c:\windows\SYSTEM32\narrator.exe
+ 2008-07-25 16:17 . 2008-07-25 16:17 15360 c:\windows\SYSTEM32\MUI\0409\mscorees.dll
+ 2007-05-08 22:08 . 2007-05-08 22:08 86728 c:\windows\SYSTEM32\msxml6r.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 83968 c:\windows\SYSTEM32\mscories.dll
- 2002-11-20 17:50 . 2004-08-04 07:56 72704 c:\windows\SYSTEM32\magnify.exe
+ 2002-11-20 17:50 . 2006-10-04 08:48 72704 c:\windows\SYSTEM32\magnify.exe
+ 2002-08-29 11:00 . 2009-06-26 16:18 16384 c:\windows\SYSTEM32\jsproxy.dll
- 2002-08-29 11:00 . 2009-02-20 08:30 16384 c:\windows\SYSTEM32\jsproxy.dll
+ 2004-08-26 15:53 . 2009-06-26 16:18 96256 c:\windows\SYSTEM32\inseng.dll
- 2004-08-26 15:53 . 2009-02-20 08:30 96256 c:\windows\SYSTEM32\inseng.dll
+ 2008-07-30 00:24 . 2008-07-30 00:24 97800 c:\windows\SYSTEM32\infocardapi.dll
+ 2008-07-30 00:24 . 2008-07-30 00:24 11264 c:\windows\SYSTEM32\icardres.dll
+ 2004-08-04 07:56 . 2009-06-26 16:18 55808 c:\windows\SYSTEM32\extmgr.dll
- 2004-08-04 07:56 . 2009-02-20 08:30 55808 c:\windows\SYSTEM32\extmgr.dll
+ 2008-07-30 02:10 . 2008-07-30 02:10 73720 c:\windows\SYSTEM32\dxva2.dll
+ 2006-10-04 08:48 . 2006-10-04 08:48 50176 c:\windows\SYSTEM32\DLLCACHE\utilman.exe
+ 2006-10-04 13:33 . 2006-10-04 13:33 35840 c:\windows\SYSTEM32\DLLCACHE\umandlg.dll
+ 2009-06-12 11:50 . 2009-06-12 11:50 80896 c:\windows\SYSTEM32\DLLCACHE\tlntsess.exe
+ 2009-06-12 11:50 . 2009-06-12 11:50 76288 c:\windows\SYSTEM32\DLLCACHE\telnet.exe
+ 2006-05-10 05:23 . 2009-06-26 16:18 39424 c:\windows\SYSTEM32\DLLCACHE\pngfilt.dll
- 2006-05-10 05:23 . 2009-02-20 08:30 39424 c:\windows\SYSTEM32\DLLCACHE\pngfilt.dll
+ 2006-10-04 08:48 . 2006-10-04 08:48 53760 c:\windows\SYSTEM32\DLLCACHE\narrator.exe
+ 2007-07-06 12:46 . 2009-06-25 18:36 48640 c:\windows\SYSTEM32\DLLCACHE\mqupgrd.dll
- 2007-07-06 12:46 . 2007-07-06 12:46 48640 c:\windows\SYSTEM32\DLLCACHE\mqupgrd.dll
+ 2007-07-06 12:46 . 2009-06-25 18:36 95744 c:\windows\SYSTEM32\DLLCACHE\mqsec.dll
- 2007-07-06 12:46 . 2007-07-06 12:46 95744 c:\windows\SYSTEM32\DLLCACHE\mqsec.dll
+ 2007-07-06 12:46 . 2009-06-25 18:36 16896 c:\windows\SYSTEM32\DLLCACHE\mqise.dll
- 2007-07-06 12:46 . 2007-07-06 12:46 16896 c:\windows\SYSTEM32\DLLCACHE\mqise.dll
+ 2007-07-06 12:46 . 2009-06-25 18:36 47104 c:\windows\SYSTEM32\DLLCACHE\mqdscli.dll
- 2007-07-06 12:46 . 2007-07-06 12:46 47104 c:\windows\SYSTEM32\DLLCACHE\mqdscli.dll
+ 2009-06-22 11:49 . 2009-06-22 11:49 19968 c:\windows\SYSTEM32\DLLCACHE\mqbkup.exe
+ 2007-07-06 10:05 . 2009-06-22 11:48 91776 c:\windows\SYSTEM32\DLLCACHE\mqac.sys
+ 2006-10-04 08:48 . 2006-10-04 08:48 72704 c:\windows\SYSTEM32\DLLCACHE\magnify.exe
- 2006-05-10 05:22 . 2009-02-20 08:30 16384 c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 16384 c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
- 2006-05-10 05:22 . 2009-02-20 08:30 96256 c:\windows\SYSTEM32\DLLCACHE\inseng.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 96256 c:\windows\SYSTEM32\DLLCACHE\inseng.dll
- 2009-02-20 08:30 . 2009-02-20 08:30 81920 c:\windows\SYSTEM32\DLLCACHE\ieencode.dll
+ 2009-02-20 08:30 . 2009-06-26 16:18 81920 c:\windows\SYSTEM32\DLLCACHE\ieencode.dll
- 2006-05-09 11:00 . 2009-02-19 09:58 18432 c:\windows\SYSTEM32\DLLCACHE\iedw.exe
+ 2004-08-04 07:56 . 2009-06-22 11:38 18432 c:\windows\SYSTEM32\DLLCACHE\iedw.exe
+ 2002-08-29 11:00 . 2004-08-04 07:56 38912 c:\windows\SYSTEM32\DLLCACHE\hmmapi.dll
+ 2002-08-29 11:00 . 2009-06-16 14:55 82432 c:\windows\SYSTEM32\DLLCACHE\fontsub.dll
+ 2009-06-30 18:03 . 2008-07-06 12:06 89088 c:\windows\SYSTEM32\DLLCACHE\filterpipelineprintproc.dll
- 2006-05-10 05:22 . 2009-02-20 08:30 55808 c:\windows\SYSTEM32\DLLCACHE\extmgr.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 55808 c:\windows\SYSTEM32\DLLCACHE\extmgr.dll
+ 2009-06-10 14:21 . 2009-06-10 14:21 84992 c:\windows\SYSTEM32\DLLCACHE\avifil32.dll
- 2002-08-29 11:00 . 2004-08-04 07:56 58880 c:\windows\SYSTEM32\DLLCACHE\atl.dll
+ 2002-08-29 11:00 . 2009-07-17 18:55 58880 c:\windows\SYSTEM32\DLLCACHE\atl.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 96760 c:\windows\SYSTEM32\dfshim.dll
- 2003-10-16 21:50 . 2009-05-08 17:30 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2003-10-16 21:50 . 2009-08-31 21:06 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
- 2004-02-07 13:11 . 2009-05-08 17:30 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
+ 2004-02-07 13:11 . 2009-08-31 21:06 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
+ 2008-07-30 04:40 . 2008-07-30 04:40 70648 c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
+ 2008-07-30 04:40 . 2008-07-30 04:40 91136 c:\windows\Microsoft.NET\Framework\v3.5\MSBuild.exe
+ 2008-07-30 04:40 . 2008-07-30 04:40 41984 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft.VisualC.STLCLR.dll
+ 2008-07-30 04:40 . 2008-07-30 04:40 40960 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft.Data.Entity.Build.Tasks.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 89080 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.2052.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 92664 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1042.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 95224 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1041.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 89592 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1028.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 84480 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.2052.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 94720 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1042.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 97792 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1041.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 84992 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1028.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 97280 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\DeleteTemp.exe
+ 2008-07-30 04:40 . 2008-07-30 04:40 95224 c:\windows\Microsoft.NET\Framework\v3.5\EdmGen.exe
+ 2008-07-30 04:40 . 2008-07-30 04:40 78856 c:\windows\Microsoft.NET\Framework\v3.5\DataSvcUtil.exe
+ 2008-07-30 04:40 . 2008-07-30 04:40 41984 c:\windows\Microsoft.NET\Framework\v3.5\AddInUtil.exe
+ 2008-07-30 04:40 . 2008-07-30 04:40 41992 c:\windows\Microsoft.NET\Framework\v3.5\AddInProcess32.exe
+ 2008-07-30 04:40 . 2008-07-30 04:40 41992 c:\windows\Microsoft.NET\Framework\v3.5\AddInProcess.exe
+ 2008-07-30 02:10 . 2008-07-30 02:10 46104 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
+ 2008-07-30 00:59 . 2008-07-30 00:59 32768 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationCFFRasterizer.dll
+ 2008-07-30 02:10 . 2008-07-30 02:10 71160 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PenIMC.dll
+ 2008-07-30 00:32 . 2008-07-30 00:32 17448 c:\windows\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\PerformanceCounterInstaller.exe
+ 2008-07-30 00:16 . 2008-07-30 00:16 32768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
+ 2008-07-30 00:16 . 2008-07-30 00:16 73728 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.Install.dll
+ 2008-07-30 00:16 . 2008-07-30 00:16 20504 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceMonikerSupport.dll
+ 2008-07-30 00:16 . 2008-07-30 00:16 11280 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 37896 c:\windows\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 81400 c:\windows\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL
+ 2008-07-25 16:17 . 2008-07-25 16:17 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 57392 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 95232 c:\windows\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 16896 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 61952 c:\windows\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe
+ 2008-07-25 16:17 . 2008-07-25 16:17 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
+ 2008-07-25 16:17 . 2008-07-25 16:17 53248 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
+ 2008-07-25 16:17 . 2008-07-25 16:17 88584 c:\windows\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 24584 c:\windows\Microsoft.NET\Framework\v2.0.50727\normalization.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 31744 c:\windows\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 19456 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscortim.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
+ 2008-07-25 16:16 . 2008-07-25 16:16 18944 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 77312 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 94208 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorld.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 46592 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorie.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 83456 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
+ 2008-07-25 16:16 . 2008-07-25 16:16 97792 c:\windows\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 12800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 40960 c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
+ 2008-07-25 16:17 . 2008-07-25 16:17 72192 c:\windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 65032 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
+ 2008-07-25 16:17 . 2008-07-25 16:17 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEHost.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 18936 c:\windows\Microsoft.NET\Framework\v2.0.50727\fusion.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 62968 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfdll.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 35320 c:\windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe
+ 2008-07-25 16:17 . 2008-07-25 16:17 69120 c:\windows\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 27136 c:\windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 13312 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 80376 c:\windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
+ 2008-07-25 16:17 . 2008-07-25 16:17 89608 c:\windows\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll
+ 2008-11-25 09:59 . 2008-11-25 09:59 31560 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2008-07-25 16:16 . 2008-07-25 16:16 34312 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
+ 2008-07-25 16:16 . 2008-07-25 16:16 33288 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe
+ 2008-07-25 16:16 . 2008-07-25 16:16 24576 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
+ 2008-07-25 16:16 . 2008-07-25 16:16 84480 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 33800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 17416 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 22024 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
+ 2008-07-25 16:17 . 2008-07-25 16:17 58880 c:\windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
+ 2008-07-25 16:16 . 2008-07-25 16:16 98808 c:\windows\Microsoft.NET\Framework\v2.0.50727\alink.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 10752 c:\windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 13824 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 96768 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 16896 c:\windows\Microsoft.NET\Framework\SharedReg12.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 16896 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 16896 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 16896 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 82944 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
+ 2005-08-04 06:04 . 2005-08-04 06:04 20480 c:\windows\Installer\63687.msi
+ 2009-04-28 17:41 . 2009-04-28 17:41 24064 c:\windows\Installer\529bf52.msi
+ 2008-08-14 17:43 . 2008-08-14 17:43 65024 c:\windows\Installer\400154.msi
+ 2009-01-14 22:31 . 2009-01-14 22:31 51712 c:\windows\Installer\2df30f0.msi
+ 2008-07-30 04:07 . 2008-07-30 04:07 23040 c:\windows\Installer\29ebbbba.msp
+ 2009-06-30 18:02 . 2009-06-30 18:02 88576 c:\windows\Installer\29e4f8a5.msi
+ 2003-12-04 19:21 . 2009-08-12 08:08 23040 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2003-12-04 19:21 . 2009-04-30 11:40 23040 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2003-12-04 19:21 . 2009-04-30 11:40 27136 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2003-12-04 19:21 . 2009-08-12 08:08 27136 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2003-12-04 19:21 . 2009-04-30 11:40 11264 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2003-12-04 19:21 . 2009-08-12 08:08 11264 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2003-12-04 19:21 . 2009-08-12 08:08 12288 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2003-12-04 19:21 . 2009-04-30 11:40 12288 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-06-12 08:11 . 2009-06-12 08:11 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2009-01-16 09:01 . 2009-01-16 09:01 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2006-10-27 02:13 . 2006-10-27 02:13 72472 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6021\XL12CNVP.DLL
+ 2006-10-27 02:07 . 2006-10-27 02:07 17680 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6021\PXBPROXY.DLL
+ 2009-06-30 18:03 . 2008-07-06 12:06 89088 c:\windows\Driver Cache\I386\filterpipelineprintproc.dll
+ 2009-08-14 08:11 . 2009-08-14 08:11 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\a715aa442ef87ae99b3ade185599249d\UIAutomationProvider.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\423f794d1f4ed6e120fbb02e436491cb\System.Windows.Presentation.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\19ca1747c1ea18a3b639b302bca8df93\System.Web.DynamicData.Design.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\532438e2acfcadc469a4d468c51f8451\System.ComponentModel.DataAnnotations.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\597b20e1b053d6a510cfe033c07a63e6\System.AddIn.Contract.ni.dll
+ 2009-08-14 08:09 . 2009-08-14 08:09 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\2d7408a0232f2e2efd0d7adf5dfa733a\PresentationFontCache.ni.exe
+ 2009-08-14 08:07 . 2009-08-14 08:07 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\c8fd2d9233f8ea3031fb16f697635231\PresentationCFFRasterizer.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\790cf1edb17ee41b59be62ecbd59613b\Microsoft.Vsa.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e9aba2eab90d647356f65e66053da02b\Microsoft.Build.Framework.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\28343d470d992f169ca0e7cdb3cc3117\Microsoft.Build.Framework.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\f4e38208e88cb4cc314a1d6543b9fcc6\dfsvc.ni.exe
+ 2009-08-14 08:14 . 2009-08-14 08:14 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\11eb4f6606ba01e5128805759121ea6c\Accessibility.ni.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 94208 c:\windows\assembly\GAC_MSIL\WindowsFormsIntegration\3.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 98304 c:\windows\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 40960 c:\windows\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 12288 c:\windows\assembly\GAC_MSIL\System.Windows.Presentation\3.5.0.0__b77a5c561934e089\System.Windows.Presentation.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 61440 c:\windows\assembly\GAC_MSIL\System.Web.Routing\3.5.0.0__31bf3856ad364e35\System.Web.Routing.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 32768 c:\windows\assembly\GAC_MSIL\System.Web.DynamicData.Design\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.Design.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 77824 c:\windows\assembly\GAC_MSIL\System.Web.Abstractions\3.5.0.0__31bf3856ad364e35\System.Web.Abstractions.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 32768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 73728 c:\windows\assembly\GAC_MSIL\System.ServiceModel.Install\3.0.0.0__b77a5c561934e089\System.ServiceModel.Install.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 53248 c:\windows\assembly\GAC_MSIL\System.Data.DataSetExtensions\3.5.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
+ 2009-08-14 08:04 . 2009-08-14 08:04 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 57344 c:\windows\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\3.5.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 45056 c:\windows\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 46104 c:\windows\assembly\GAC_MSIL\PresentationFontCache\3.0.0.0__31bf3856ad364e35\PresentationFontCache.exe
+ 2009-06-30 18:05 . 2009-06-30 18:05 32768 c:\windows\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 41984 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR\1.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.STLCLR.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 94208 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.v3.5.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 39424 c:\windows\$NtUninstallKB972260$\pngfilt.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 16384 c:\windows\$NtUninstallKB972260$\jsproxy.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 96256 c:\windows\$NtUninstallKB972260$\inseng.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 81920 c:\windows\$NtUninstallKB972260$\ieencode.dll
+ 2009-07-30 08:01 . 2009-04-27 09:17 18432 c:\windows\$NtUninstallKB972260$\iedw.exe
+ 2009-07-30 08:01 . 2009-04-29 04:52 55808 c:\windows\$NtUninstallKB972260$\extmgr.dll
+ 2009-06-12 08:08 . 2009-02-20 08:30 39424 c:\windows\$NtUninstallKB969897$\pngfilt.dll
+ 2009-06-12 08:08 . 2009-02-20 08:30 16384 c:\windows\$NtUninstallKB969897$\jsproxy.dll
+ 2009-06-12 08:08 . 2009-02-20 08:30 96256 c:\windows\$NtUninstallKB969897$\inseng.dll
+ 2009-06-12 08:08 . 2009-02-20 08:30 81920 c:\windows\$NtUninstallKB969897$\ieencode.dll
+ 2009-06-12 08:08 . 2009-02-19 09:58 18432 c:\windows\$NtUninstallKB969897$\iedw.exe
+ 2009-06-12 08:08 . 2009-02-20 08:30 55808 c:\windows\$NtUninstallKB969897$\extmgr.dll
+ 2009-07-15 08:01 . 2005-10-17 21:14 80896 c:\windows\$NtUninstallKB961371$\fontsub.dll
+ 2009-07-06 22:13 . 2004-08-04 07:56 50176 c:\windows\$NtUninstallKB925720$\utilman.exe
+ 2009-07-06 22:13 . 2004-08-04 07:56 35840 c:\windows\$NtUninstallKB925720$\umandlg.dll
+ 2009-07-06 22:13 . 2004-08-04 07:56 53760 c:\windows\$NtUninstallKB925720$\narrator.exe
+ 2009-07-06 22:13 . 2004-08-04 07:56 72704 c:\windows\$NtUninstallKB925720$\magnify.exe
+ 2009-07-15 08:05 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB973346\update\spcustom.dll
+ 2009-07-15 08:05 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB973346\spmsg.dll
+ 2009-07-30 08:02 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB972260\update\spcustom.dll
+ 2009-07-30 08:02 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB972260\spmsg.dll
+ 2009-06-26 16:42 . 2009-06-26 16:42 81920 c:\windows\$hf_mig$\KB972260\SP3QFE\ieencode.dll
+ 2009-06-26 16:50 . 2009-06-26 16:50 81920 c:\windows\$hf_mig$\KB972260\SP3GDR\ieencode.dll
+ 2009-06-26 15:59 . 2009-06-26 15:59 39424 c:\windows\$hf_mig$\KB972260\SP2QFE\pngfilt.dll
+ 2009-06-26 15:59 . 2009-06-26 15:59 16384 c:\windows\$hf_mig$\KB972260\SP2QFE\jsproxy.dll
+ 2009-06-26 15:59 . 2009-06-26 15:59 96256 c:\windows\$hf_mig$\KB972260\SP2QFE\inseng.dll
+ 2009-06-26 15:59 . 2009-06-26 15:59 81920 c:\windows\$hf_mig$\KB972260\SP2QFE\ieencode.dll
+ 2009-06-22 11:40 . 2009-06-22 11:40 18432 c:\windows\$hf_mig$\KB972260\SP2QFE\iedw.exe
+ 2009-06-26 15:59 . 2009-06-26 15:59 55808 c:\windows\$hf_mig$\KB972260\SP2QFE\extmgr.dll
+ 2009-07-15 08:04 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB971633\update\spcustom.dll
+ 2009-07-15 08:04 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB971633\spmsg.dll
+ 2009-06-12 08:04 . 2007-11-30 12:39 26488 c:\windows\$hf_mig$\KB970238\update\spcustom.dll
+ 2009-06-12 08:04 . 2007-11-30 12:39 17272 c:\windows\$hf_mig$\KB970238\spmsg.dll
+ 2009-06-12 08:07 . 2007-11-30 12:39 26488 c:\windows\$hf_mig$\KB969898\update\spcustom.dll
+ 2009-06-12 08:07 . 2007-11-30 12:39 17272 c:\windows\$hf_mig$\KB969898\spmsg.dll
+ 2009-06-12 08:08 . 2007-11-30 12:39 26488 c:\windows\$hf_mig$\KB969897\update\spcustom.dll
+ 2009-06-12 08:08 . 2007-11-30 12:39 17272 c:\windows\$hf_mig$\KB969897\spmsg.dll
+ 2009-04-29 04:21 . 2009-04-29 04:21 81920 c:\windows\$hf_mig$\KB969897\SP3QFE\ieencode.dll
+ 2009-04-29 04:46 . 2009-04-29 04:46 81920 c:\windows\$hf_mig$\KB969897\SP3GDR\ieencode.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 39424 c:\windows\$hf_mig$\KB969897\SP2QFE\pngfilt.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 16384 c:\windows\$hf_mig$\KB969897\SP2QFE\jsproxy.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 96256 c:\windows\$hf_mig$\KB969897\SP2QFE\inseng.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 81920 c:\windows\$hf_mig$\KB969897\SP2QFE\ieencode.dll
+ 2009-04-27 09:29 . 2009-04-27 09:29 18432 c:\windows\$hf_mig$\KB969897\SP2QFE\iedw.exe
+ 2009-04-29 04:31 . 2009-04-29 04:31 55808 c:\windows\$hf_mig$\KB969897\SP2QFE\extmgr.dll
+ 2009-06-12 08:02 . 2008-07-09 07:38 26488 c:\windows\$hf_mig$\KB968537\update\spcustom.dll
+ 2009-06-12 08:02 . 2008-07-09 07:38 17272 c:\windows\$hf_mig$\KB968537\spmsg.dll
+ 2009-06-12 08:08 . 2008-07-09 07:38 26488 c:\windows\$hf_mig$\KB961501\update\spcustom.dll
+ 2009-06-12 08:08 . 2008-07-09 07:38 17272 c:\windows\$hf_mig$\KB961501\spmsg.dll
+ 2009-07-15 08:01 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB961371\update\spcustom.dll
+ 2009-07-15 08:01 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB961371\spmsg.dll
+ 2009-06-16 14:43 . 2009-06-16 14:43 81920 c:\windows\$hf_mig$\KB961371\SP3QFE\fontsub.dll
+ 2009-06-16 14:36 . 2009-06-16 14:36 81920 c:\windows\$hf_mig$\KB961371\SP3GDR\fontsub.dll
+ 2009-06-16 14:45 . 2009-06-16 14:45 81920 c:\windows\$hf_mig$\KB961371\SP2QFE\fontsub.dll
+ 2009-07-06 22:15 . 2007-11-30 11:18 26488 c:\windows\$hf_mig$\KB961118\update\spcustom.dll
+ 2009-07-06 22:15 . 2007-11-30 11:18 17272 c:\windows\$hf_mig$\KB961118\spmsg.dll
+ 2009-07-06 22:13 . 2005-10-12 23:16 22752 c:\windows\$hf_mig$\KB925720\update\spcustom.dll
+ 2009-07-06 22:13 . 2005-10-12 23:16 14048 c:\windows\$hf_mig$\KB925720\spmsg.dll
+ 2006-10-04 10:40 . 2006-10-04 10:40 50176 c:\windows\$hf_mig$\KB925720\SP2QFE\utilman.exe
+ 2006-10-04 14:05 . 2006-10-04 14:05 35840 c:\windows\$hf_mig$\KB925720\SP2QFE\umandlg.dll
+ 2006-10-04 10:40 . 2006-10-04 10:40 53760 c:\windows\$hf_mig$\KB925720\SP2QFE\narrator.exe
+ 2006-10-04 10:40 . 2006-10-04 10:40 72704 c:\windows\$hf_mig$\KB925720\SP2QFE\magnify.exe
+ 2009-08-14 08:03 . 2009-08-14 08:03 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2009-06-22 11:49 . 2009-06-22 11:49 4608 c:\windows\SYSTEM32\DLLCACHE\mqsvc.exe
+ 2008-07-30 04:40 . 2008-07-30 04:40 5632 c:\windows\Microsoft.NET\Framework\v3.5\Sentinel.v3.5Client.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 7168 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 5632 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 6656 c:\windows\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 8192 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 9728 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
+ 2008-07-25 16:16 . 2008-07-25 16:16 5120 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
- 2003-12-04 19:21 . 2009-04-30 11:40 4096 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2003-12-04 19:21 . 2009-08-12 08:08 4096 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-06-30 18:07 . 2009-06-30 18:07 5632 c:\windows\assembly\GAC_MSIL\Sentinel.v3.5Client\3.5.0.0__b03f5f7f11d50a3a\Sentinel.v3.5Client.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2007-11-07 07:19 . 2007-11-07 07:19 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcr90.dll
+ 2007-11-07 07:19 . 2007-11-07 07:19 568832 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcp90.dll
+ 2007-11-07 02:23 . 2007-11-07 02:23 224768 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcm90.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 635904 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 558080 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcp80.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcm80.dll
+ 2008-07-30 02:26 . 2008-07-30 02:26 301568 c:\windows\SYSTEM32\XPSViewer\XPSViewer.exe
+ 2009-06-30 18:03 . 2008-07-06 12:06 575488 c:\windows\SYSTEM32\xpsshhdr.dll
+ 2005-05-17 00:25 . 2009-06-22 11:26 352768 c:\windows\SYSTEM32\xpsp3res.dll
+ 2006-10-24 17:30 . 2006-10-24 17:30 276992 c:\windows\SYSTEM32\WMPhoto.dll
+ 2006-10-24 17:29 . 2006-10-24 17:29 352256 c:\windows\SYSTEM32\WindowsCodecsExt.dll
+ 2006-10-24 17:30 . 2006-10-24 17:30 716288 c:\windows\SYSTEM32\WindowsCodecs.dll
+ 2004-10-25 16:39 . 2009-06-26 16:18 616448 c:\windows\SYSTEM32\urlmon.dll
- 2004-10-25 16:39 . 2009-02-20 08:30 616448 c:\windows\SYSTEM32\urlmon.dll
+ 2008-07-30 00:59 . 2008-07-30 00:59 161296 c:\windows\SYSTEM32\UIAutomationCore.dll
+ 2009-06-30 18:04 . 2008-07-06 12:06 765440 c:\windows\SYSTEM32\SPOOL\XPSEP\i386\mxdwdrv.dll
+ 2009-06-30 18:04 . 2008-07-06 12:06 765440 c:\windows\SYSTEM32\SPOOL\XPSEP\i386\i386\mxdwdrv.dll
+ 2009-06-30 18:04 . 2008-07-06 12:06 748032 c:\windows\SYSTEM32\SPOOL\XPSEP\amd64\mxdwdrv.dll
+ 2009-06-30 18:04 . 2008-07-06 12:06 748032 c:\windows\SYSTEM32\SPOOL\XPSEP\amd64\amd64\mxdwdrv.dll
+ 2009-06-30 18:05 . 2008-07-06 12:06 147456 c:\windows\SYSTEM32\SPOOL\PRTPROCS\x64\filterpipelineprintproc.dll
+ 2009-06-30 18:03 . 2008-07-06 10:50 597504 c:\windows\SYSTEM32\SPOOL\PRTPROCS\W32X86\printfilterpipelinesvc.exe
+ 2003-12-11 19:14 . 2008-03-13 04:52 761344 c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\unires.dll
+ 2003-05-22 14:29 . 2008-07-06 12:06 744960 c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\unidrvui.dll
+ 2003-05-22 14:29 . 2008-07-06 12:06 373248 c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\unidrv.dll
+ 2009-06-30 18:03 . 2008-07-06 12:06 198656 c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\mxdwdui.dll
+ 2009-06-30 18:03 . 2008-07-06 12:06 765440 c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\mxdwdrv.dll
- 2004-08-20 20:01 . 2009-02-20 08:30 474112 c:\windows\SYSTEM32\shlwapi.dll
+ 2004-08-20 20:01 . 2009-06-26 16:18 474112 c:\windows\SYSTEM32\shlwapi.dll
+ 2002-08-29 11:00 . 2009-06-25 18:36 169472 c:\windows\SYSTEM32\Setup\msmqocm.dll
+ 2004-12-30 20:46 . 2009-04-15 15:11 584192 c:\windows\SYSTEM32\rpcrt4.dll
- 2004-12-30 20:46 . 2007-07-09 13:09 584192 c:\windows\SYSTEM32\rpcrt4.dll
+ 2006-08-24 21:15 . 2006-08-24 21:15 150808 c:\windows\SYSTEM32\rgb9rast_2.dll
+ 2009-06-30 18:03 . 2008-07-06 12:06 117760 c:\windows\SYSTEM32\prntvpt.dll
+ 2008-07-30 00:59 . 2008-07-30 00:59 781344 c:\windows\SYSTEM32\PresentationNative_v0300.dll
+ 2008-07-30 01:35 . 2008-07-30 01:35 326160 c:\windows\SYSTEM32\PresentationHost.exe
+ 2008-07-30 00:59 . 2008-07-30 00:59 105016 c:\windows\SYSTEM32\PresentationCFFRasterizerNative_v0300.dll
+ 2006-10-24 17:30 . 2006-10-24 17:30 412160 c:\windows\SYSTEM32\photometadatahandler.dll
+ 2002-09-03 19:51 . 2009-08-14 08:04 444028 c:\windows\SYSTEM32\PERFH009.DAT
+ 2003-02-10 16:58 . 2006-10-04 08:48 215552 c:\windows\SYSTEM32\osk.exe
- 2003-02-10 16:58 . 2004-08-04 07:56 215552 c:\windows\SYSTEM32\osk.exe
+ 2002-08-29 11:00 . 2009-06-26 16:18 532480 c:\windows\SYSTEM32\mstime.dll
- 2002-08-29 11:00 . 2009-02-20 08:30 532480 c:\windows\SYSTEM32\mstime.dll
- 2002-08-29 11:00 . 2009-02-20 08:30 146432 c:\windows\SYSTEM32\msrating.dll
+ 2002-08-29 11:00 . 2009-06-26 16:18 146432 c:\windows\SYSTEM32\msrating.dll
+ 2002-08-29 11:00 . 2009-06-26 16:18 449024 c:\windows\SYSTEM32\mshtmled.dll
- 2002-08-29 11:00 . 2009-02-20 08:30 449024 c:\windows\SYSTEM32\mshtmled.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 158720 c:\windows\SYSTEM32\mscorier.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 282112 c:\windows\SYSTEM32\mscoree.dll
+ 2002-08-29 11:00 . 2009-05-07 15:44 344064 c:\windows\SYSTEM32\localspl.dll
+ 2009-06-03 15:08 . 2009-06-03 15:07 148888 c:\windows\SYSTEM32\javaws.exe
+ 2009-06-03 15:08 . 2009-06-03 15:07 144792 c:\windows\SYSTEM32\javaw.exe
+ 2009-06-03 15:08 . 2009-06-03 15:07 144792 c:\windows\SYSTEM32\java.exe
- 2002-08-29 11:00 . 2009-02-20 08:30 251392 c:\windows\SYSTEM32\iepeers.dll
+ 2002-08-29 11:00 . 2009-06-26 16:18 251392 c:\windows\SYSTEM32\iepeers.dll
+ 2008-07-30 00:24 . 2008-07-30 00:24 622080 c:\windows\SYSTEM32\icardagt.exe
+ 2002-09-03 19:42 . 2009-07-06 22:05 195368 c:\windows\SYSTEM32\FNTCACHE.DAT
+ 2008-07-30 02:10 . 2008-07-30 02:10 493048 c:\windows\SYSTEM32\evr.dll
+ 2002-08-29 11:00 . 2009-06-26 16:18 205312 c:\windows\SYSTEM32\dxtrans.dll
- 2002-08-29 11:00 . 2009-02-20 08:30 205312 c:\windows\SYSTEM32\dxtrans.dll
+ 2002-08-29 11:00 . 2009-06-26 16:18 357888 c:\windows\SYSTEM32\dxtmsft.dll
- 2002-08-29 11:00 . 2009-02-20 08:30 357888 c:\windows\SYSTEM32\dxtmsft.dll
+ 2009-06-30 18:03 . 2008-07-06 12:06 575488 c:\windows\SYSTEM32\DLLCACHE\xpsshhdr.dll
+ 2003-12-11 21:15 . 2009-07-14 04:43 286208 c:\windows\SYSTEM32\DLLCACHE\wmpdxm.dll
+ 2006-08-17 12:28 . 2009-06-10 06:32 132096 c:\windows\SYSTEM32\DLLCACHE\wkssvc.dll
- 2006-08-17 12:28 . 2006-08-17 12:28 132096 c:\windows\SYSTEM32\DLLCACHE\wkssvc.dll
+ 2004-08-24 01:32 . 2009-06-26 16:18 659456 c:\windows\SYSTEM32\DLLCACHE\wininet.dll
- 2004-08-24 01:32 . 2009-02-20 08:30 659456 c:\windows\SYSTEM32\DLLCACHE\wininet.dll
- 2004-10-25 16:39 . 2009-02-20 08:30 616448 c:\windows\SYSTEM32\DLLCACHE\urlmon.dll
+ 2004-10-25 16:39 . 2009-06-26 16:18 616448 c:\windows\SYSTEM32\DLLCACHE\urlmon.dll
+ 2009-06-16 14:55 . 2009-06-16 14:55 119808 c:\windows\SYSTEM32\DLLCACHE\t2embed.dll
+ 2004-08-20 20:01 . 2009-06-26 16:18 474112 c:\windows\SYSTEM32\DLLCACHE\shlwapi.dll
- 2004-08-20 20:01 . 2009-02-20 08:30 474112 c:\windows\SYSTEM32\DLLCACHE\shlwapi.dll
+ 2004-12-30 20:46 . 2009-04-15 15:11 584192 c:\windows\SYSTEM32\DLLCACHE\rpcrt4.dll
- 2004-12-30 20:46 . 2007-07-09 13:09 584192 c:\windows\SYSTEM32\DLLCACHE\rpcrt4.dll
+ 2009-06-30 18:03 . 2008-07-06 10:50 597504 c:\windows\SYSTEM32\DLLCACHE\printfilterpipelinesvc.exe
+ 2006-10-04 08:48 . 2006-10-04 08:48 215552 c:\windows\SYSTEM32\DLLCACHE\osk.exe
+ 2006-05-10 05:23 . 2009-06-26 16:18 532480 c:\windows\SYSTEM32\DLLCACHE\mstime.dll
- 2006-05-10 05:23 . 2009-02-20 08:30 532480 c:\windows\SYSTEM32\DLLCACHE\mstime.dll
- 2006-05-10 05:23 . 2009-02-20 08:30 146432 c:\windows\SYSTEM32\DLLCACHE\msrating.dll
+ 2006-05-10 05:23 . 2009-06-26 16:18 146432 c:\windows\SYSTEM32\DLLCACHE\msrating.dll
+ 2009-06-25 18:36 . 2009-06-25 18:36 169472 c:\windows\SYSTEM32\DLLCACHE\msmqocm.dll
- 2006-05-10 05:23 . 2009-02-20 08:30 449024 c:\windows\SYSTEM32\DLLCACHE\mshtmled.dll
+ 2006-05-10 05:23 . 2009-06-26 16:18 449024 c:\windows\SYSTEM32\DLLCACHE\mshtmled.dll
+ 2007-07-06 12:46 . 2009-06-25 18:36 471552 c:\windows\SYSTEM32\DLLCACHE\mqutil.dll
- 2007-07-06 12:46 . 2007-07-06 12:46 471552 c:\windows\SYSTEM32\DLLCACHE\mqutil.dll
+ 2009-06-25 18:36 . 2009-06-25 18:36 186880 c:\windows\SYSTEM32\DLLCACHE\mqtrig.dll
+ 2009-06-22 11:49 . 2009-06-22 11:49 117248 c:\windows\SYSTEM32\DLLCACHE\mqtgsvc.exe
+ 2009-06-25 18:36 . 2009-06-25 18:36 517120 c:\windows\SYSTEM32\DLLCACHE\mqsnap.dll
+ 2009-06-25 18:36 . 2009-06-25 18:36 123392 c:\windows\SYSTEM32\DLLCACHE\mqrtdep.dll
- 2007-07-06 12:46 . 2007-07-06 12:46 177152 c:\windows\SYSTEM32\DLLCACHE\mqrt.dll
+ 2007-07-06 12:46 . 2009-06-25 18:36 177152 c:\windows\SYSTEM32\DLLCACHE\mqrt.dll
+ 2007-07-06 12:46 . 2009-06-25 18:36 661504 c:\windows\SYSTEM32\DLLCACHE\mqqm.dll
+ 2009-06-25 18:36 . 2009-06-25 18:36 225280 c:\windows\SYSTEM32\DLLCACHE\mqoa.dll
- 2007-07-06 12:46 . 2007-07-06 12:46 138240 c:\windows\SYSTEM32\DLLCACHE\mqad.dll
+ 2007-07-06 12:46 . 2009-06-25 18:36 138240 c:\windows\SYSTEM32\DLLCACHE\mqad.dll
+ 2009-05-07 15:44 . 2009-05-07 15:44 344064 c:\windows\SYSTEM32\DLLCACHE\localspl.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 251392 c:\windows\SYSTEM32\DLLCACHE\iepeers.dll
- 2006-05-10 05:22 . 2009-02-20 08:30 251392 c:\windows\SYSTEM32\DLLCACHE\iepeers.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 205312 c:\windows\SYSTEM32\DLLCACHE\dxtrans.dll
- 2006-05-10 05:22 . 2009-02-20 08:30 205312 c:\windows\SYSTEM32\DLLCACHE\dxtrans.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 357888 c:\windows\SYSTEM32\DLLCACHE\dxtmsft.dll
- 2006-05-10 05:22 . 2009-02-20 08:30 357888 c:\windows\SYSTEM32\DLLCACHE\dxtmsft.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 151040 c:\windows\SYSTEM32\DLLCACHE\cdfview.dll
- 2006-05-10 05:22 . 2009-02-20 08:30 151040 c:\windows\SYSTEM32\DLLCACHE\cdfview.dll
+ 2002-08-29 11:00 . 2009-06-26 16:18 151040 c:\windows\SYSTEM32\cdfview.dll
- 2002-08-29 11:00 . 2009-02-20 08:30 151040 c:\windows\SYSTEM32\cdfview.dll
+ 2008-07-30 04:40 . 2008-07-30 04:40 196104 c:\windows\Microsoft.NET\Framework\v3.5\WFServicesReg.exe
+ 2008-07-30 04:40 . 2008-07-30 04:40 802816 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft.Build.Tasks.v3.5.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 984056 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapUI.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 107512 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 111096 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.3082.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 110072 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.2070.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 106488 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1055.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 105976 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1053.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 107000 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1049.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 107512 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1046.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 109048 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1045.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 106488 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1044.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 108536 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1043.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 110072 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1040.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 111096 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1038.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 101368 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1037.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 112120 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1036.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 106488 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1035.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 113656 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1032.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 111608 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1031.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 108536 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1030.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 108536 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1029.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 102904 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1025.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 689152 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vsscenario.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 413184 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vsbasereqs.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 632320 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vs70uimgr.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 652800 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vs_setup.msi
+ 2008-07-29 23:47 . 2008-07-29 23:47 110080 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 131584 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.3082.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 131072 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.2070.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 121344 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1055.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 121344 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1053.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 123904 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1049.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 122880 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1046.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 128512 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1045.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 121856 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1044.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 129024 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1043.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 128512 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1040.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 132096 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1038.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 111104 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1037.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 133120 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1036.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 122368 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1035.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 137728 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1032.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 130048 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1031.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 126464 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1030.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 125440 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1029.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 113152 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1025.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 269304 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
+ 2008-07-29 23:47 . 2008-07-29 23:47 177152 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\HtmlLite.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 276984 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\dlmgr.dll
+ 2008-07-30 04:15 . 2008-07-30 04:15 225490 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\baseline.dat
+ 2008-07-30 04:40 . 2008-07-30 04:40 233976 c:\windows\Microsoft.NET\Framework\v3.5\1033\vbc7ui.dll
+ 2008-07-30 04:40 . 2008-07-30 04:40 168448 c:\windows\Microsoft.NET\Framework\v3.5\1033\cscompui.dll
+ 2008-07-30 01:35 . 2008-07-30 01:35 864256 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationUI.dll
+ 2008-07-30 00:59 . 2008-07-30 00:59 132120 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
+ 2008-07-30 02:10 . 2008-07-30 02:10 806928 c:\windows\Microsoft.NET\Framework\v3.0\WPF\NaturalLanguage6.dll
+ 2008-07-30 00:16 . 2008-07-30 00:16 152576 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\WsatConfig.exe
+ 2008-07-30 00:16 . 2008-07-30 00:16 966656 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
+ 2008-07-30 00:16 . 2008-07-30 00:16 132096 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
+ 2008-07-30 00:16 . 2008-07-30 00:16 110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
+ 2008-07-30 00:16 . 2008-07-30 00:16 156688 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelReg.exe
+ 2008-07-30 00:16 . 2008-07-30 00:16 163840 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.Dtc.dll
+ 2008-07-30 00:16 . 2008-07-30 00:16 397312 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.dll
+ 2008-07-30 00:24 . 2008-07-30 00:24 881664 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
+ 2008-07-30 00:16 . 2008-07-30 00:16 168968 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ComSvcConfig.exe
+ 2008-11-25 09:59 . 2008-11-25 09:59 436040 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 839680 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 835584 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 261632 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 114688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 131072 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 303104 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 372736 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Management.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 113664 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 626688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 188416 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 401408 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 970752 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 745472 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll
+ 2008-11-25 09:59 . 2008-11-25 09:59 486400 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 425984 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 392184 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 118784 c:\windows\Microsoft.NET\Framework\v2.0.50727\shfusion.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 143360 c:\windows\Microsoft.NET\Framework\v2.0.50727\peverify.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 100856 c:\windows\Microsoft.NET\Framework\v2.0.50727\ngen.exe
+ 2008-07-25 16:17 . 2008-07-25 16:17 230912 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 345600 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 114176 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll
+ 2008-11-25 09:59 . 2008-11-25 09:59 364872 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 308224 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll
+ 2008-11-25 09:59 . 2008-11-25 09:59 990032 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 659456 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 372736 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 749568 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 655360 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 348160 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 230904 c:\windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe
+ 2008-07-25 16:17 . 2008-07-25 16:17 798224 c:\windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 575496 c:\windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
+ 2008-07-25 16:16 . 2008-07-25 16:16 507904 c:\windows\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
+ 2008-07-25 16:17 . 2008-07-25 16:17 147968 c:\windows\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 218112 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 193016 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 145408 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll
+ 2002-09-03 19:43 . 2002-09-03 19:43 264704 c:\windows\Installer\F306.MSI
+ 2008-12-13 14:58 . 2008-12-13 14:58 754688 c:\windows\Installer\a3fca80.msp
+ 2009-07-06 22:14 . 2009-07-06 22:14 972800 c:\windows\Installer\804ff.msi
+ 2009-02-06 15:34 . 2009-02-06 15:34 912384 c:\windows\Installer\685b0f3c.msi
+ 2005-08-04 06:05 . 2005-08-04 06:05 916480 c:\windows\Installer\6368c.msi
+ 2003-12-04 19:21 . 2003-12-04 19:21 233472 c:\windows\Installer\5baf7.msi
+ 2003-12-04 19:16 . 2003-12-04 19:16 456704 c:\windows\Installer\5bae4.msi
+ 2003-12-04 19:16 . 2003-12-04 19:16 460800 c:\windows\Installer\5badf.msi
+ 2003-12-04 19:16 . 2003-12-04 19:16 532992 c:\windows\Installer\5bad9.msi
+ 2003-12-04 19:15 . 2003-12-04 19:15 561664 c:\windows\Installer\5babd.msi
+ 2009-01-15 09:01 . 2009-01-15 09:01 470528 c:\windows\Installer\51f886e.msi
+ 2008-08-16 08:01 . 2008-08-16 08:01 431104 c:\windows\Installer\51ee215.msi
+ 2008-06-11 20:02 . 2008-06-11 20:02 830464 c:\windows\Installer\51b5799.msp
+ 2005-08-04 05:42 . 2005-08-04 05:42 155136 c:\windows\Installer\4022b509.msi
+ 2008-08-14 17:45 . 2008-08-14 17:45 497664 c:\windows\Installer\400182.msi
+ 2008-08-14 17:45 . 2008-08-14 17:45 403968 c:\windows\Installer\40017c.msi
+ 2008-08-14 17:45 . 2008-08-14 17:45 407040 c:\windows\Installer\400177.msi
+ 2008-08-14 17:45 . 2008-08-14 17:45 749568 c:\windows\Installer\400172.msi
+ 2008-08-14 17:44 . 2008-08-14 17:44 364032 c:\windows\Installer\40016c.msi
+ 2008-08-14 17:44 . 2008-08-14 17:44 291328 c:\windows\Installer\400166.msi
+ 2008-08-14 17:44 . 2008-08-14 17:44 431104 c:\windows\Installer\400160.msi
+ 2008-08-14 17:43 . 2008-08-14 17:43 228864 c:\windows\Installer\40015a.msi
+ 2009-06-30 18:07 . 2009-06-30 18:07 648192 c:\windows\Installer\29eda7fe.msi
+ 2008-07-30 04:23 . 2008-07-30 04:23 250880 c:\windows\Installer\29ebbbc3.msp
+ 2008-07-30 04:28 . 2008-07-30 04:28 278016 c:\windows\Installer\29ebbbc1.msp
+ 2008-07-30 02:40 . 2008-07-30 02:40 291840 c:\windows\Installer\29ebbbbf.msp
+ 2009-06-30 18:06 . 2009-06-30 18:06 137728 c:\windows\Installer\29ebbbb9.msi
+ 2008-07-30 00:35 . 2008-07-30 00:35 553472 c:\windows\Installer\29e4f8aa.msp
+ 2008-07-30 00:33 . 2008-07-30 00:33 506368 c:\windows\Installer\29e4f8a8.msp
+ 2008-07-30 00:37 . 2008-07-30 00:37 911360 c:\windows\Installer\29e4f8a7.msp
+ 2008-08-14 16:25 . 2008-08-14 16:25 355328 c:\windows\Installer\28901c7b.msi
+ 2008-11-13 09:00 . 2008-11-13 09:00 432640 c:\windows\Installer\255123d7.msi
+ 2008-11-12 22:13 . 2008-11-12 22:13 118784 c:\windows\Installer\22ffc399.msi
+ 2009-06-03 15:07 . 2009-06-03 15:07 598016 c:\windows\Installer\1882a0f4.msi
+ 2003-10-16 21:51 . 2003-10-16 21:51 558592 c:\windows\Installer\14F96.MSI
+ 2003-10-16 21:47 . 2003-10-16 21:47 616448 c:\windows\Installer\14F80.MSI
- 2003-12-04 19:21 . 2009-04-30 11:40 409600 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2003-12-04 19:21 . 2009-08-12 08:08 409600 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2003-12-04 19:21 . 2009-04-30 11:40 286720 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2003-12-04 19:21 . 2009-08-12 08:08 286720 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2003-12-04 19:21 . 2009-04-30 11:40 794624 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2003-12-04 19:21 . 2009-08-12 08:08 794624 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2003-12-04 19:21 . 2009-04-30 11:40 135168 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2003-12-04 19:21 . 2009-08-12 08:08 135168 c:\windows\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-01-16 09:03 . 2009-01-16 09:03 464272 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.8173\OWC11PIA.DLL
+ 2003-07-15 09:18 . 2003-07-15 09:18 141360 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\ATP.DLL
+ 2009-06-30 18:03 . 2008-03-13 04:52 761344 c:\windows\Driver Cache\I386\unires.dll
+ 2009-06-30 18:03 . 2008-07-06 12:06 744960 c:\windows\Driver Cache\I386\unidrvui.dll
+ 2009-06-30 18:03 . 2008-07-06 12:06 373248 c:\windows\Driver Cache\I386\unidrv.dll
+ 2009-06-30 18:03 . 2008-07-06 12:06 198656 c:\windows\Driver Cache\I386\mxdwdui.dll
+ 2009-06-30 18:03 . 2008-07-06 12:06 765440 c:\windows\Driver Cache\I386\mxdwdrv.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\2ef5bc3a2edd7570bb23886a4f32294a\WsatConfig.ni.exe
+ 2009-08-14 08:11 . 2009-08-14 08:11 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\6a818099f0386e2356ae94f886a2196f\WindowsFormsIntegration.ni.dll
+ 2009-08-14 08:11 . 2009-08-14 08:11 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\a6d9503962d47c722231c1478f180695\UIAutomationTypes.ni.dll
+ 2009-08-14 08:11 . 2009-08-14 08:11 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\5c028c3d8db6c0f0277673ea4a2d89fb\UIAutomationClient.ni.dll
+ 2009-08-14 08:17 . 2009-08-14 08:17 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\c338a470b14851ce5987bb0f0869c310\System.Xml.Linq.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\bb77ea11f46ab438b2b7ed7c180011a1\System.Web.Routing.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\6ee255220d90dcbe80c990e443051cc5\System.Web.RegularExpressions.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\58f62044fa702ea6f936071aa5520baa\System.Web.Extensions.Design.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\79c29ac85dd57dd485ab60118ac292ff\System.Web.Entity.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\d3d65e34fa60f0b6c72ca0d12ec89933\System.Web.Entity.Design.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\b7891f5659db299dbd1b3c72db7edb9f\System.Web.DynamicData.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\00ec08741a765c707bd9169346064a81\System.Web.Abstractions.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\5a555c9ae6984c40157cf940bb519f7c\System.Transactions.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\ea3366939280c1715f1c620e33ee3c8a\System.ServiceProcess.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 676352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\1c8df2da33222c048d683017f2095f04\System.Security.ni.dll
+ 2009-08-14 08:15 . 2009-08-14 08:15 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\bfd6e16d8c3589cd2bd3f8d46f0a5402\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\519d9c618341b136f9b963ffb7495308\System.Net.ni.dll
+ 2009-08-14 08:15 . 2009-08-14 08:15 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\8642fdfbf02a6cb6f01169fe6fdb5d11\System.Management.ni.dll
+ 2009-08-14 08:15 . 2009-08-14 08:15 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\1d3fbbd23ce1e8637ef4f40a8d23cd32\System.Management.Instrumentation.ni.dll
+ 2009-08-14 08:13 . 2009-08-14 08:13 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\7c367a96b10d626ec8cbf8149272d845\System.IO.Log.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\68e71147704ef0d34d9a4bece7767fc5\System.IdentityModel.Selectors.ni.dll
+ 2009-08-14 08:15 . 2009-08-14 08:15 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\4267bd908175603006c6c90bb5d900c7\System.EnterpriseServices.Wrapper.dll
+ 2009-08-14 08:15 . 2009-08-14 08:15 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\4267bd908175603006c6c90bb5d900c7\System.EnterpriseServices.ni.dll
+ 2009-08-14 08:11 . 2009-08-14 08:11 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\18bbe2b6717e7f1d1dd672526e9889ee\System.Drawing.Design.ni.dll
+ 2009-08-14 08:15 . 2009-08-14 08:15 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\c434a07332ce490711c27fd0edb7562f\System.DirectoryServices.Protocols.ni.dll
+ 2009-08-14 08:15 . 2009-08-14 08:15 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\8b3bb7a2c2f3ffe94c866283f1cd5957\System.DirectoryServices.AccountManagement.ni.dll
+ 2009-08-14 08:15 . 2009-08-14 08:15 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\a4b887f476fa4b8746a93a9fc2208560\System.Data.Services.Client.ni.dll
+ 2009-08-14 08:15 . 2009-08-14 08:15 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\1cf3acad6553d6c59df576794f4e8bd6\System.Data.Services.Design.ni.dll
+ 2009-08-14 08:15 . 2009-08-14 08:15 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\392de34573f9f8ec885714f2f3e7f07f\System.Data.Entity.Design.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\1db495ff00bbd14df4af6680c4de0653\System.Data.DataSetExtensions.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\b82c00e2d24305ad6cb08556e3779b75\System.Configuration.ni.dll
+ 2009-08-14 08:15 . 2009-08-14 08:15 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\de514e484e49b04b016949d57ffac03e\System.Configuration.Install.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\ce984d754e3c0b6be4504b785cc43574\System.AddIn.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\045dd501b7257b1cc26083538ae69045\SMSvcHost.ni.exe
+ 2009-08-14 08:14 . 2009-08-14 08:14 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\9790551187e294b4ed3aaa1c221891c7\SMDiagnostics.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\10a0c9707876fc1f65e64b811a28b020\ServiceModelReg.ni.exe
+ 2009-08-14 08:10 . 2009-08-14 08:10 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\f475294d8c7dc2dd4febeef27bc0417e\PresentationFramework.Classic.ni.dll
+ 2009-08-14 08:10 . 2009-08-14 08:10 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8003abaf6bcf70f7eb620d06837e897b\PresentationFramework.Luna.ni.dll
+ 2009-08-14 08:10 . 2009-08-14 08:10 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\59a67874d8d8475faa5be1d993083d12\PresentationFramework.Aero.ni.dll
+ 2009-08-14 08:10 . 2009-08-14 08:10 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2c980c9a5051d723c6ec2a78a3d0e2b3\PresentationFramework.Royale.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\6d38e317128608bc4516ea46ab94590e\MSBuild.ni.exe
+ 2009-08-14 08:14 . 2009-08-14 08:14 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\1820d6a012fc0e16c3e1d29d973cd2d0\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\55b9eff9e23359faed4351386c062238\Microsoft.Build.Utilities.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\4217124db1ea5de5f1a1f3eea75e8d32\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\96825c34d7e1f7df1923ff2123bed8da\Microsoft.Build.Engine.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\9b321ebf67587237f576df6104a32588\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\9bea05938bee3555c5aa8763d89a68f9\CustomMarshalers.ni.dll
+ 2009-08-14 08:13 . 2009-08-14 08:13 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\12629e2f3e315459bee67cbbaac85cb2\ComSvcConfig.ni.exe
+ 2009-08-14 08:14 . 2009-08-14 08:14 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\b5b2feadc3943e3976daebc0bcd2b5e2\AspNetMMCExt.ni.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 385024 c:\windows\assembly\GAC_MSIL\UIAutomationClientsideProviders\3.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 167936 c:\windows\assembly\GAC_MSIL\UIAutomationClient\3.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 139264 c:\windows\assembly\GAC_MSIL\System.Xml.Linq\3.5.0.0__b77a5c561934e089\System.Xml.Linq.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 507904 c:\windows\assembly\GAC_MSIL\System.WorkflowServices\3.5.0.0__31bf3856ad364e35\System.WorkflowServices.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 540672 c:\windows\assembly\GAC_MSIL\System.Workflow.Runtime\3.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 335872 c:\windows\assembly\GAC_MSIL\System.Web.Extensions.Design\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.Design.dll
+ 2009-08-14 08:07 . 2009-08-14 08:07 139264 c:\windows\assembly\GAC_MSIL\System.Web.Entity\3.5.0.0__b77a5c561934e089\System.Web.Entity.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 131072 c:\windows\assembly\GAC_MSIL\System.Web.Entity.Design\3.5.0.0__b77a5c561934e089\System.Web.Entity.Design.dll
+ 2009-08-14 08:07 . 2009-08-14 08:07 229376 c:\windows\assembly\GAC_MSIL\System.Web.DynamicData\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 688128 c:\windows\assembly\GAC_MSIL\System.Speech\3.0.0.0__31bf3856ad364e35\System.Speech.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 569344 c:\windows\assembly\GAC_MSIL\System.ServiceModel.Web\3.5.0.0__31bf3856ad364e35\System.ServiceModel.Web.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 966656 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 233472 c:\windows\assembly\GAC_MSIL\System.Net\3.5.0.0__b03f5f7f11d50a3a\System.Net.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 143360 c:\windows\assembly\GAC_MSIL\System.Management.Instrumentation\3.5.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 131072 c:\windows\assembly\GAC_MSIL\System.IO.Log\3.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 430080 c:\windows\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 126976 c:\windows\assembly\GAC_MSIL\System.IdentityModel.Selectors\3.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 286720 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\3.5.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
+ 2009-08-14 08:04 . 2009-08-14 08:04 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2009-08-14 08:04 . 2009-08-14 08:04 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2009-08-14 08:07 . 2009-08-14 08:07 442368 c:\windows\assembly\GAC_MSIL\System.Data.Services\3.5.0.0__b77a5c561934e089\System.Data.Services.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 114688 c:\windows\assembly\GAC_MSIL\System.Data.Services.Design\3.5.0.0__b77a5c561934e089\System.Data.Services.Design.dll
+ 2009-08-14 08:07 . 2009-08-14 08:07 294912 c:\windows\assembly\GAC_MSIL\System.Data.Services.Client\3.5.0.0__b77a5c561934e089\System.Data.Services.Client.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 684032 c:\windows\assembly\GAC_MSIL\System.Data.Linq\3.5.0.0__b77a5c561934e089\System.Data.Linq.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 229376 c:\windows\assembly\GAC_MSIL\System.Data.Entity.Design\3.5.0.0__b77a5c561934e089\System.Data.Entity.Design.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 667648 c:\windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll
+ 2009-08-14 08:04 . 2009-08-14 08:04 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 528384 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 864256 c:\windows\assembly\GAC_MSIL\PresentationUI\3.0.0.0__31bf3856ad364e35\PresentationUI.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 163840 c:\windows\assembly\GAC_MSIL\PresentationFramework.Royale\3.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 397312 c:\windows\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 139264 c:\windows\assembly\GAC_MSIL\PresentationFramework.Classic\3.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 196608 c:\windows\assembly\GAC_MSIL\PresentationFramework.Aero\3.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 598016 c:\windows\assembly\GAC_MSIL\PresentationBuildTasks\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 397312 c:\windows\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 802816 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.v3.5.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 733184 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 106496 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Conversion.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Conversion.v3.5.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 368640 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2009-08-14 08:04 . 2009-08-14 08:04 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 163840 c:\windows\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2009-08-12 08:06 . 2009-08-12 08:06 477056 c:\windows\assembly\GAC\Microsoft.Office.Interop.Owc11\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Owc11.dll
+ 2009-06-30 17:58 . 2006-10-16 21:10 379184 c:\windows\$NtUninstallWIC$\spuninst\updspapi.dll
+ 2009-06-30 17:58 . 2006-10-16 21:10 221488 c:\windows\$NtUninstallWIC$\spuninst\spuninst.exe
+ 2009-07-15 08:05 . 2008-07-08 13:02 382840 c:\windows\$NtUninstallKB973346$\spuninst\updspapi.dll
+ 2009-07-15 08:05 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB973346$\spuninst\spuninst.exe
+ 2009-07-30 08:01 . 2009-04-27 09:18 351744 c:\windows\$NtUninstallKB972260$\xpsp3res.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 659456 c:\windows\$NtUninstallKB972260$\wininet.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 616448 c:\windows\$NtUninstallKB972260$\urlmon.dll
+ 2009-07-30 08:02 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB972260$\spuninst\updspapi.dll
+ 2009-07-30 08:02 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB972260$\spuninst\spuninst.exe
+ 2009-07-30 08:01 . 2009-04-29 04:52 474112 c:\windows\$NtUninstallKB972260$\shlwapi.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 532480 c:\windows\$NtUninstallKB972260$\mstime.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 146432 c:\windows\$NtUninstallKB972260$\msrating.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 449024 c:\windows\$NtUninstallKB972260$\mshtmled.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 251392 c:\windows\$NtUninstallKB972260$\iepeers.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 205312 c:\windows\$NtUninstallKB972260$\dxtrans.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 357888 c:\windows\$NtUninstallKB972260$\dxtmsft.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 151040 c:\windows\$NtUninstallKB972260$\cdfview.dll
+ 2009-07-15 08:04 . 2008-07-09 07:38 382840 c:\windows\$NtUninstallKB971633$\spuninst\updspapi.dll
+ 2009-07-15 08:04 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB971633$\spuninst\spuninst.exe
+ 2009-06-12 08:04 . 2009-02-19 09:47 351744 c:\windows\$NtUninstallKB970238$\xpsp3res.dll
+ 2009-06-12 08:04 . 2007-11-30 12:39 382840 c:\windows\$NtUninstallKB970238$\spuninst\updspapi.dll
+ 2009-06-12 08:04 . 2007-11-30 12:39 231288 c:\windows\$NtUninstallKB970238$\spuninst\spuninst.exe
+ 2009-06-12 08:04 . 2007-07-09 13:09 584192 c:\windows\$NtUninstallKB970238$\rpcrt4.dll
+ 2009-06-12 08:07 . 2007-11-30 12:39 382840 c:\windows\$NtUninstallKB969898$\spuninst\updspapi.dll
+ 2009-06-12 08:07 . 2007-11-30 12:39 231288 c:\windows\$NtUninstallKB969898$\spuninst\spuninst.exe
+ 2009-06-12 08:08 . 2009-04-15 09:24 351744 c:\windows\$NtUninstallKB969897$\xpsp3res.dll
+ 2009-06-12 08:08 . 2009-02-20 08:30 659456 c:\windows\$NtUninstallKB969897$\wininet.dll
+ 2009-06-12 08:08 . 2009-02-20 08:30 616448 c:\windows\$NtUninstallKB969897$\urlmon.dll
+ 2009-06-12 08:08 . 2007-11-30 12:39 382840 c:\windows\$NtUninstallKB969897$\spuninst\updspapi.dll
+ 2009-06-12 08:08 . 2007-11-30 12:39 231288 c:\windows\$NtUninstallKB969897$\spuninst\spuninst.exe
+ 2009-06-12 08:08 . 2009-02-20 08:30 474112 c:\windows\$NtUninstallKB969897$\shlwapi.dll
+ 2009-06-12 08:08 . 2009-02-20 08:30 532480 c:\windows\$NtUninstallKB969897$\mstime.dll
+ 2009-06-12 08:08 . 2009-02-20 08:30 146432 c:\windows\$NtUninstallKB969897$\msrating.dll
+ 2009-06-12 08:08 . 2009-02-20 08:30 449024 c:\windows\$NtUninstallKB969897$\mshtmled.dll
+ 2009-06-12 08:08 . 2009-02-20 08:30 251392 c:\windows\$NtUninstallKB969897$\iepeers.dll
+ 2009-06-12 08:08 . 2009-02-20 08:30 205312 c:\windows\$NtUninstallKB969897$\dxtrans.dll
+ 2009-06-12 08:08 . 2009-02-20 08:30 357888 c:\windows\$NtUninstallKB969897$\dxtmsft.dll
+ 2009-06-12 08:08 . 2009-02-20 08:30 151040 c:\windows\$NtUninstallKB969897$\cdfview.dll
+ 2009-06-12 08:02 . 2008-07-09 07:38 382840 c:\windows\$NtUninstallKB968537$\spuninst\updspapi.dll
+ 2009-06-12 08:02 . 2008-07-09 07:38 231288 c:\windows\$NtUninstallKB968537$\spuninst\spuninst.exe
+ 2009-06-12 08:08 . 2008-07-09 07:38 382840 c:\windows\$NtUninstallKB961501$\spuninst\updspapi.dll
+ 2009-06-12 08:08 . 2008-07-09 07:38 231288 c:\windows\$NtUninstallKB961501$\spuninst\spuninst.exe
+ 2009-06-12 08:08 . 2004-08-04 07:56 341504 c:\windows\$NtUninstallKB961501$\localspl.dll
+ 2009-07-15 08:01 . 2005-10-17 21:14 118272 c:\windows\$NtUninstallKB961371$\t2embed.dll
+ 2009-07-15 08:01 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB961371$\spuninst\updspapi.dll
+ 2009-07-15 08:01 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB961371$\spuninst\spuninst.exe
+ 2009-07-06 22:14 . 2007-11-30 11:18 382840 c:\windows\$NtUninstallKB961118$\spuninst\updspapi.dll
+ 2009-07-06 22:14 . 2007-11-30 11:18 231288 c:\windows\$NtUninstallKB961118$\spuninst\spuninst.exe
+ 2009-07-06 22:13 . 2005-10-12 23:16 371424 c:\windows\$NtUninstallKB925720$\spuninst\updspapi.dll
+ 2009-07-06 22:13 . 2005-10-12 23:16 213216 c:\windows\$NtUninstallKB925720$\spuninst\spuninst.exe
+ 2009-07-06 22:13 . 2004-08-04 07:56 215552 c:\windows\$NtUninstallKB925720$\osk.exe
+ 2009-07-15 08:05 . 2008-07-08 13:02 382840 c:\windows\$hf_mig$\KB973346\update\updspapi.dll
+ 2009-07-15 08:05 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB973346\update\update.exe
+ 2009-07-15 08:05 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB973346\spuninst.exe
+ 2009-07-30 08:02 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB972260\update\updspapi.dll
+ 2009-07-30 08:02 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB972260\update\update.exe
+ 2009-07-30 08:02 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB972260\spuninst.exe
+ 2009-06-26 16:42 . 2009-06-26 16:42 668160 c:\windows\$hf_mig$\KB972260\SP3QFE\wininet.dll
+ 2009-06-26 16:42 . 2009-06-26 16:42 620544 c:\windows\$hf_mig$\KB972260\SP3QFE\urlmon.dll
+ 2009-06-26 16:50 . 2009-06-26 16:50 666624 c:\windows\$hf_mig$\KB972260\SP3GDR\wininet.dll
+ 2009-06-26 16:50 . 2009-06-26 16:50 620032 c:\windows\$hf_mig$\KB972260\SP3GDR\urlmon.dll
+ 2009-06-22 11:26 . 2009-06-22 11:26 352768 c:\windows\$hf_mig$\KB972260\SP2QFE\xpsp3res.dll
+ 2009-06-26 15:59 . 2009-06-26 15:59 668160 c:\windows\$hf_mig$\KB972260\SP2QFE\wininet.dll
+ 2009-06-26 15:59 . 2009-06-26 15:59 620032 c:\windows\$hf_mig$\KB972260\SP2QFE\urlmon.dll
+ 2009-06-26 15:59 . 2009-06-26 15:59 474112 c:\windows\$hf_mig$\KB972260\SP2QFE\shlwapi.dll
+ 2009-06-26 15:59 . 2009-06-26 15:59 532480 c:\windows\$hf_mig$\KB972260\SP2QFE\mstime.dll
+ 2009-06-26 15:59 . 2009-06-26 15:59 146432 c:\windows\$hf_mig$\KB972260\SP2QFE\msrating.dll
+ 2009-06-26 15:59 . 2009-06-26 15:59 449024 c:\windows\$hf_mig$\KB972260\SP2QFE\mshtmled.dll
+ 2009-06-26 15:59 . 2009-06-26 15:59 251904 c:\windows\$hf_mig$\KB972260\SP2QFE\iepeers.dll
+ 2009-06-26 15:59 . 2009-06-26 15:59 205312 c:\windows\$hf_mig$\KB972260\SP2QFE\dxtrans.dll
+ 2009-06-26 15:59 . 2009-06-26 15:59 357888 c:\windows\$hf_mig$\KB972260\SP2QFE\dxtmsft.dll
+ 2009-06-26 15:59 . 2009-06-26 15:59 151040 c:\windows\$hf_mig$\KB972260\SP2QFE\cdfview.dll
+ 2009-07-15 08:04 . 2008-07-09 07:38 382840 c:\windows\$hf_mig$\KB971633\update\updspapi.dll
+ 2009-07-15 08:04 . 2008-07-09 07:38 755576 c:\windows\$hf_mig$\KB971633\update\update.exe
+ 2009-07-15 08:04 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB971633\spuninst.exe
+ 2009-06-12 08:04 . 2007-11-30 12:39 382840 c:\windows\$hf_mig$\KB970238\update\updspapi.dll
+ 2009-06-12 08:04 . 2007-11-30 12:39 755576 c:\windows\$hf_mig$\KB970238\update\update.exe
+ 2009-06-12 08:04 . 2007-11-30 12:39 231288 c:\windows\$hf_mig$\KB970238\spuninst.exe
+ 2009-04-15 15:24 . 2009-04-15 15:24 585216 c:\windows\$hf_mig$\KB970238\SP3QFE\rpcrt4.dll
+ 2009-04-15 14:51 . 2009-04-15 14:51 585216 c:\windows\$hf_mig$\KB970238\SP3GDR\rpcrt4.dll
+ 2009-04-15 09:24 . 2009-04-15 09:24 351744 c:\windows\$hf_mig$\KB970238\SP2QFE\xpsp3res.dll
+ 2009-04-15 15:26 . 2009-04-15 15:26 583168 c:\windows\$hf_mig$\KB970238\SP2QFE\rpcrt4.dll
+ 2009-06-12 08:07 . 2007-11-30 12:39 382840 c:\windows\$hf_mig$\KB969898\update\updspapi.dll
+ 2009-06-12 08:07 . 2007-11-30 12:39 755576 c:\windows\$hf_mig$\KB969898\update\update.exe
+ 2009-06-12 08:07 . 2007-11-30 12:39 231288 c:\windows\$hf_mig$\KB969898\spuninst.exe
+ 2009-06-12 08:08 . 2007-11-30 12:39 382840 c:\windows\$hf_mig$\KB969897\update\updspapi.dll
+ 2009-06-12 08:08 . 2007-11-30 12:39 755576 c:\windows\$hf_mig$\KB969897\update\update.exe
+ 2009-06-12 08:08 . 2007-11-30 12:39 231288 c:\windows\$hf_mig$\KB969897\spuninst.exe
+ 2009-04-29 04:21 . 2009-04-29 04:21 668160 c:\windows\$hf_mig$\KB969897\SP3QFE\wininet.dll
+ 2009-04-29 04:21 . 2009-04-29 04:21 620032 c:\windows\$hf_mig$\KB969897\SP3QFE\urlmon.dll
+ 2009-04-29 04:46 . 2009-04-29 04:46 666624 c:\windows\$hf_mig$\KB969897\SP3GDR\wininet.dll
+ 2009-04-29 04:46 . 2009-04-29 04:46 620032 c:\windows\$hf_mig$\KB969897\SP3GDR\urlmon.dll
+ 2009-04-27 09:18 . 2009-04-27 09:18 351744 c:\windows\$hf_mig$\KB969897\SP2QFE\xpsp3res.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 668160 c:\windows\$hf_mig$\KB969897\SP2QFE\wininet.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 619520 c:\windows\$hf_mig$\KB969897\SP2QFE\urlmon.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 474112 c:\windows\$hf_mig$\KB969897\SP2QFE\shlwapi.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 532480 c:\windows\$hf_mig$\KB969897\SP2QFE\mstime.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 146432 c:\windows\$hf_mig$\KB969897\SP2QFE\msrating.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 449024 c:\windows\$hf_mig$\KB969897\SP2QFE\mshtmled.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 251904 c:\windows\$hf_mig$\KB969897\SP2QFE\iepeers.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 205312 c:\windows\$hf_mig$\KB969897\SP2QFE\dxtrans.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 357888 c:\windows\$hf_mig$\KB969897\SP2QFE\dxtmsft.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 151040 c:\windows\$hf_mig$\KB969897\SP2QFE\cdfview.dll
+ 2009-06-12 08:02 . 2008-07-09 07:38 382840 c:\windows\$hf_mig$\KB968537\update\updspapi.dll
+ 2009-06-12 08:02 . 2008-07-09 07:38 755576 c:\windows\$hf_mig$\KB968537\update\update.exe
+ 2009-06-12 08:02 . 2008-07-09 07:38 231288 c:\windows\$hf_mig$\KB968537\spuninst.exe
+ 2009-06-12 08:08 . 2008-07-09 07:38 382840 c:\windows\$hf_mig$\KB961501\update\updspapi.dll
+ 2009-06-12 08:08 . 2008-07-09 07:38 755576 c:\windows\$hf_mig$\KB961501\update\update.exe
+ 2009-06-12 08:08 . 2008-07-09 07:38 231288 c:\windows\$hf_mig$\KB961501\spuninst.exe
+ 2009-05-07 15:14 . 2009-05-07 15:14 346112 c:\windows\$hf_mig$\KB961501\SP3QFE\localspl.dll
+ 2009-05-07 15:32 . 2009-05-07 15:32 345600 c:\windows\$hf_mig$\KB961501\SP3GDR\localspl.dll
+ 2009-05-07 15:26 . 2009-05-07 15:26 346112 c:\windows\$hf_mig$\KB961501\SP2QFE\localspl.dll
+ 2009-07-15 08:01 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB961371\update\updspapi.dll
+ 2009-07-15 08:01 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB961371\update\update.exe
+ 2009-07-15 08:01 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB961371\spuninst.exe
+ 2009-06-16 14:43 . 2009-06-16 14:43 119808 c:\windows\$hf_mig$\KB961371\SP3QFE\t2embed.dll
+ 2009-06-16 14:36 . 2009-06-16 14:36 119808 c:\windows\$hf_mig$\KB961371\SP3GDR\t2embed.dll
+ 2009-06-16 14:45 . 2009-06-16 14:45 119808 c:\windows\$hf_mig$\KB961371\SP2QFE\t2embed.dll
+ 2009-07-06 22:15 . 2007-11-30 11:18 382840 c:\windows\$hf_mig$\KB961118\update\updspapi.dll
+ 2009-07-06 22:15 . 2007-11-30 11:18 755576 c:\windows\$hf_mig$\KB961118\update\update.exe
+ 2009-07-06 22:15 . 2007-11-30 11:18 231288 c:\windows\$hf_mig$\KB961118\spuninst.exe
+ 2009-07-06 22:13 . 2005-10-12 23:16 371424 c:\windows\$hf_mig$\KB925720\update\updspapi.dll
+ 2009-07-06 22:13 . 2005-10-12 23:16 716000 c:\windows\$hf_mig$\KB925720\update\update.exe
+ 2009-07-06 22:13 . 2005-10-12 23:16 213216 c:\windows\$hf_mig$\KB925720\spuninst.exe
+ 2006-10-04 10:40 . 2006-10-04 10:40 215552 c:\windows\$hf_mig$\KB925720\SP2QFE\osk.exe
+ 2009-06-30 18:03 . 2008-07-06 12:06 1676288 c:\windows\SYSTEM32\xpssvcs.dll
+ 2002-08-29 11:00 . 2009-04-17 09:58 1846656 c:\windows\SYSTEM32\win32k.sys
+ 2002-08-29 11:00 . 2004-07-17 18:35 1326080 c:\windows\SYSTEM32\webfldrs.msi
+ 2009-06-30 18:04 . 2008-07-06 12:06 1676288 c:\windows\SYSTEM32\SPOOL\XPSEP\i386\xpssvcs.dll
+ 2009-06-30 18:04 . 2008-07-06 12:06 1676288 c:\windows\SYSTEM32\SPOOL\XPSEP\i386\i386\xpssvcs.dll
+ 2009-06-30 18:04 . 2008-07-06 22:36 2936832 c:\windows\SYSTEM32\SPOOL\XPSEP\amd64\xpssvcs.dll
+ 2009-06-30 18:04 . 2008-07-06 22:36 2936832 c:\windows\SYSTEM32\SPOOL\XPSEP\amd64\amd64\xpssvcs.dll
+ 2009-06-30 18:03 . 2008-07-06 12:06 1676288 c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\XpsSvcs.dll
+ 2004-11-12 05:20 . 2009-07-18 16:20 1506304 c:\windows\SYSTEM32\shdocvw.dll
+ 2008-08-30 01:06 . 2008-08-30 01:06 1350664 c:\windows\SYSTEM32\msxml6.dll
+ 2004-10-25 16:39 . 2009-07-18 16:20 3062272 c:\windows\SYSTEM32\mshtml.dll
+ 2009-06-30 18:03 . 2008-07-06 12:06 1676288 c:\windows\SYSTEM32\DLLCACHE\xpssvcs.dll
+ 2007-03-08 13:47 . 2009-04-17 09:58 1846656 c:\windows\SYSTEM32\DLLCACHE\win32k.sys
+ 2004-11-12 05:20 . 2009-07-18 16:20 1506304 c:\windows\SYSTEM32\DLLCACHE\shdocvw.dll
+ 2007-10-29 22:43 . 2009-06-03 19:27 1290752 c:\windows\SYSTEM32\DLLCACHE\quartz.dll
+ 2006-11-08 05:06 . 2009-07-10 13:42 1315328 c:\windows\SYSTEM32\DLLCACHE\msoe.dll
+ 2004-10-25 16:39 . 2009-07-18 16:20 3062272 c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 1054208 c:\windows\SYSTEM32\DLLCACHE\danim.dll
- 2006-05-10 05:22 . 2009-02-20 08:30 1054208 c:\windows\SYSTEM32\DLLCACHE\danim.dll
- 2004-08-23 00:34 . 2009-02-20 08:30 1023488 c:\windows\SYSTEM32\DLLCACHE\browseui.dll
+ 2004-08-23 00:34 . 2009-06-26 16:18 1023488 c:\windows\SYSTEM32\DLLCACHE\browseui.dll
+ 2002-08-29 11:00 . 2009-06-26 16:18 1054208 c:\windows\SYSTEM32\danim.dll
- 2002-08-29 11:00 . 2009-02-20 08:30 1054208 c:\windows\SYSTEM32\danim.dll
+ 2003-12-10 22:22 . 2003-10-16 21:47 9121792 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}\Java 2 Runtime Environment, SE v1.4.2.msi
- 2004-08-23 00:34 . 2009-02-20 08:30 1023488 c:\windows\SYSTEM32\browseui.dll
+ 2004-08-23 00:34 . 2009-06-26 16:18 1023488 c:\windows\SYSTEM32\browseui.dll
+ 2004-07-17 18:35 . 2004-07-17 18:35 1326080 c:\windows\ServicePackFiles\i386\webfldrs.msi
+ 2008-07-30 04:40 . 2008-07-30 04:40 1720824 c:\windows\Microsoft.NET\Framework\v3.5\vbc.exe
+ 2008-07-29 23:47 . 2008-07-29 23:47 1054208 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vs_setup.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 1364992 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\SITSetup.dll
+ 2008-07-29 23:47 . 2008-07-29 23:47 1064448 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\gencomp.dll
+ 2008-07-30 04:40 . 2008-07-30 04:40 1548280 c:\windows\Microsoft.NET\Framework\v3.5\csc.exe
+ 2008-12-06 00:35 . 2008-12-06 00:35 1736528 c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll
+ 2008-07-30 02:10 . 2008-07-30 02:10 2637840 c:\windows\Microsoft.NET\Framework\v3.0\WPF\NlsLexicons0009.dll
+ 2008-07-30 02:10 . 2008-07-30 02:10 4883464 c:\windows\Microsoft.NET\Framework\v3.0\WPF\NlsData0009.dll
+ 2008-12-06 01:12 . 2008-12-06 01:12 5931008 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 1344000 c:\windows\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 1172472 c:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
+ 2008-11-25 09:59 . 2008-11-25 09:59 2048000 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2008-11-25 09:59 . 2008-11-25 09:59 5242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 3149824 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 5062656 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
+ 2008-07-25 16:17 . 2008-07-25 16:17 2933248 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.dll
+ 2008-11-25 09:59 . 2008-11-25 09:59 5813576 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2008-11-25 09:59 . 2008-11-25 09:59 4546560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2008-07-25 16:16 . 2008-07-25 16:16 1163768 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscomp.dll
+ 2007-05-25 17:08 . 2007-05-25 17:08 9609728 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp
+ 2005-02-12 09:00 . 2005-02-12 09:00 5864960 c:\windows\Installer\d6242a6d.msp
+ 2004-01-20 17:06 . 2004-01-20 17:06 3487232 c:\windows\Installer\c8d02.msp
+ 2009-01-15 09:35 . 2009-01-15 09:35 4830720 c:\windows\Installer\a45420b.msp
+ 2008-12-13 14:57 . 2008-12-13 14:57 8397824 c:\windows\Installer\a3fca6b.msp
+ 2009-01-14 21:43 . 2009-01-14 21:43 5520384 c:\windows\Installer\85db6492.msp
+ 2009-04-24 17:31 . 2009-04-24 17:31 1425920 c:\windows\Installer\7fc2126.msp
+ 2008-07-31 09:33 . 2008-07-31 09:33 1396224 c:\windows\Installer\719a02ee.msi
+ 2005-04-03 20:37 . 2005-04-03 20:37 2593792 c:\windows\Installer\670fed6.msp
+ 2004-10-21 22:56 . 2004-10-21 22:56 5533696 c:\windows\Installer\670fec4.msp
+ 2005-06-27 05:12 . 2005-06-27 05:12 4980224 c:\windows\Installer\670feb0.msp
+ 2003-12-04 19:21 . 2003-12-04 19:21 4408832 c:\windows\Installer\5baf0.msi
+ 2003-12-04 19:20 . 2003-12-04 19:20 1989632 c:\windows\Installer\5baec.msi
+ 2003-12-04 19:15 . 2003-12-04 19:15 1264128 c:\windows\Installer\5bacc.msi
+ 2003-12-04 19:15 . 2003-12-04 19:15 5688320 c:\windows\Installer\5bac5.msi
+ 2003-12-04 19:15 . 2003-12-04 19:15 3443712 c:\windows\Installer\5bab0.msi
+ 2006-01-23 15:58 . 2006-01-23 15:58 1479168 c:\windows\Installer\590541c2.msi
+ 2006-02-08 17:57 . 2006-02-08 17:57 2179584 c:\windows\Installer\52d0f870.msi
+ 2008-12-12 17:09 . 2008-12-12 17:09 5517824 c:\windows\Installer\51f88a9.msp
+ 2005-10-26 20:59 . 2005-10-26 20:59 2883072 c:\windows\Installer\51f8897.msp
+ 2008-06-20 00:28 . 2008-06-20 00:28 1573376 c:\windows\Installer\51f887e.msp
+ 2007-07-21 19:26 . 2007-07-21 19:26 7574016 c:\windows\Installer\51f8860.msp
+ 2008-10-20 16:18 . 2008-10-20 16:18 6474240 c:\windows\Installer\51f8858.msp
+ 2008-06-11 21:05 . 2008-06-11 21:05 9994240 c:\windows\Installer\51b583b.msp
+ 2008-10-23 04:43 . 2008-10-23 04:43 6820352 c:\windows\Installer\51b5826.msp
+ 2008-10-23 04:48 . 2008-10-23 04:48 7672832 c:\windows\Installer\51b5804.msp
+ 2008-01-31 16:30 . 2008-01-31 16:30 9947648 c:\windows\Installer\51b57e2.msp
+ 2008-01-14 22:53 . 2008-01-14 22:53 5213696 c:\windows\Installer\51b57ca.msp
+ 2008-10-25 15:15 . 2008-10-25 15:15 6227456 c:\windows\Installer\51b57b9.msp
+ 2007-11-08 17:42 . 2007-11-08 17:42 4158464 c:\windows\Installer\51b5788.msp
+ 2009-02-11 20:02 . 2009-02-11 20:02 5519872 c:\windows\Installer\47db4813.msp
+ 2008-08-14 17:46 . 2008-08-14 17:46 1440256 c:\windows\Installer\400188.msi
+ 2009-04-06 22:00 . 2009-04-06 22:00 5518336 c:\windows\Installer\3ccb6f4.msp
+ 2009-03-05 20:40 . 2009-03-05 20:40 6819840 c:\windows\Installer\3ccb6e3.msp
+ 2008-01-29 01:44 . 2008-01-29 01:44 3200000 c:\windows\Installer\347968dd.msi
+ 2008-10-05 10:12 . 2008-10-05 10:12 4784128 c:\windows\Installer\2df30f6.msp
+ 2008-07-30 02:26 . 2008-07-30 02:26 1043456 c:\windows\Installer\29ebbbc2.msp
+ 2008-07-30 03:37 . 2008-07-30 03:37 2679808 c:\windows\Installer\29ebbbc0.msp
+ 2008-07-30 04:15 . 2008-07-30 04:15 3697664 c:\windows\Installer\29ebbbbe.msp
+ 2008-07-30 02:34 . 2008-07-30 02:34 1448448 c:\windows\Installer\29ebbbbd.msp
+ 2008-07-30 03:22 . 2008-07-30 03:22 4137984 c:\windows\Installer\29ebbbbc.msp
+ 2008-07-30 02:18 . 2008-07-30 02:18 3376640 c:\windows\Installer\29ebbbbb.msp
+ 2008-07-30 00:45 . 2008-07-30 00:45 2543616 c:\windows\Installer\29e4f8ae.msp
+ 2008-07-30 00:29 . 2008-07-30 00:29 2926080 c:\windows\Installer\29e4f8ad.msp
+ 2008-07-30 00:41 . 2008-07-30 00:41 6487040 c:\windows\Installer\29e4f8ac.msp
+ 2008-07-30 00:39 . 2008-07-30 00:39 3403264 c:\windows\Installer\29e4f8ab.msp
+ 2008-07-30 00:43 . 2008-07-30 00:43 1013248 c:\windows\Installer\29e4f8a9.msp
+ 2008-07-30 00:31 . 2008-07-30 00:31 6083072 c:\windows\Installer\29e4f8a6.msp
+ 2009-06-30 16:30 . 2009-06-30 16:30 5520384 c:\windows\Installer\28fd05d.msp
+ 2009-05-04 12:46 . 2009-05-04 12:46 8299008 c:\windows\Installer\228b0b4b.msp
+ 2009-05-12 18:01 . 2009-05-12 18:01 6818816 c:\windows\Installer\228b0b42.msp
+ 2009-04-24 17:30 . 2009-04-24 17:30 2583552 c:\windows\Installer\228b0b31.msp
+ 2009-05-28 17:32 . 2009-05-28 17:32 5518848 c:\windows\Installer\228b0b27.msp
+ 2009-04-23 22:57 . 2009-04-23 22:57 7672832 c:\windows\Installer\228b0b16.msp
+ 2009-08-05 07:11 . 2009-08-05 07:11 5518848 c:\windows\Installer\1c3eed24.msp
+ 2009-07-01 18:21 . 2009-07-01 18:21 8891904 c:\windows\Installer\1c3eed12.msp
+ 2007-04-09 15:44 . 2007-04-09 15:44 1392128 c:\windows\Installer\1b61b9a4.msi
+ 2003-10-16 21:51 . 2003-10-16 21:51 9017344 c:\windows\Installer\14F8E.MSI
+ 2003-10-16 21:50 . 2003-10-16 21:50 2120192 c:\windows\Installer\14F85.MSI
+ 2003-10-30 05:11 . 2003-10-30 05:11 4726784 c:\windows\Installer\11edc57.msp
+ 2003-11-13 03:26 . 2003-11-13 03:26 2980864 c:\windows\Installer\11edc46.msp
+ 2007-05-10 19:45 . 2007-05-10 19:45 8069464 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.8173\OWC11.DLL
+ 2005-08-04 06:05 . 2005-08-04 06:05 1863168 c:\windows\Downloaded Installations\{8129B0CC-FFD2-4C0C-B260-EF78419A8159}\HMTCDWizard.msi
+ 2009-08-14 08:07 . 2009-08-14 08:07 3313664 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\14cd5f4b61d35f9b76327d6be9853755\WindowsBase.ni.dll
+ 2009-08-14 08:11 . 2009-08-14 08:11 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\f3c7957351aec85f526a3350c9718b1e\UIAutomationClientsideProviders.ni.dll
+ 2009-08-14 08:06 . 2009-08-14 08:06 7599104 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP6C8.tmp\System.dll
+ 2009-08-14 08:07 . 2009-08-14 08:07 7868416 c:\windows\assembly\NativeImages_v2.0.50727_32\System\80978a322d7dd39f0a71be1251ae395a\System.ni.dll
+ 2009-08-14 08:11 . 2009-08-14 08:11 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\773a9786013451d3baaeff003dc4230f\System.Xml.ni.dll
+ 2009-08-14 08:17 . 2009-08-14 08:17 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\ac1750e78d79520dcf19195772eff1b6\System.WorkflowServices.ni.dll
+ 2009-08-14 08:17 . 2009-08-14 08:17 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\d265da36954fcb4cb7ad5adc693ea0f2\System.Workflow.Runtime.ni.dll
+ 2009-08-14 08:17 . 2009-08-14 08:17 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\693a8fbe6f7ad6e4e429052da4317e59\System.Workflow.ComponentModel.ni.dll
+ 2009-08-14 08:17 . 2009-08-14 08:17 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\cc99fbbac0b6e4e9ca62093e49b0c16b\System.Workflow.Activities.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\b57bb002a655920cbfa2bee29d1e22b7\System.Web.Services.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\81197e32ec931f439b3114e9031b65d6\System.Web.Mobile.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 2403328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\7f64c9d25471b72e1e957bdfe67947c8\System.Web.Extensions.ni.dll
+ 2009-08-14 08:11 . 2009-08-14 08:11 1917440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\63cf639b6e0a3c25c1643c85016e7422\System.Speech.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\340cad17fe57947eacbc8fa2cea780da\System.ServiceModel.Web.ni.dll
+ 2009-08-14 08:13 . 2009-08-14 08:13 2338304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\034c91b133dee73d452652c52767b5ea\System.Runtime.Serialization.ni.dll
+ 2009-08-14 08:11 . 2009-08-14 08:11 1035264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\646ab52eef343380aa002c220dc31e13\System.Printing.ni.dll
+ 2009-08-14 08:13 . 2009-08-14 08:13 1056768 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\c2de8479e54852f56996f79bc93acb13\System.IdentityModel.ni.dll
+ 2009-08-14 08:11 . 2009-08-14 08:11 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3da96ee075bab9202626ae44c18d226c\System.Drawing.ni.dll
+ 2009-08-14 08:15 . 2009-08-14 08:15 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\543aced762f6b0c3f8e037955941afc6\System.DirectoryServices.ni.dll
+ 2009-08-14 08:15 . 2009-08-14 08:15 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\a6b58624486714fa71e5e35186850ff0\System.Deployment.ni.dll
+ 2009-08-14 08:10 . 2009-08-14 08:10 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\c70731047b0022638b3f9fb158948a03\System.Data.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\826b09ab0d0e36f4d631b4cd335df511\System.Data.SqlXml.ni.dll
+ 2009-08-14 08:15 . 2009-08-14 08:15 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\956a513dcbd44d5a6801840ef2b0b47b\System.Data.Services.ni.dll
+ 2009-08-14 08:11 . 2009-08-14 08:11 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\0bbec79460b1137df5313f9baf7b246f\System.Data.Linq.ni.dll
+ 2009-08-14 08:15 . 2009-08-14 08:15 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\6479f975b105808a8d9e7a7fdc762551\System.Data.Entity.ni.dll
+ 2009-08-14 08:10 . 2009-08-14 08:10 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\47d87251e93256c635eb73403b8db33e\System.Core.ni.dll
+ 2009-08-14 08:10 . 2009-08-14 08:10 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\4bfb3048bf200a6a8592d1b4ba861a7f\ReachFramework.ni.dll
+ 2009-08-14 08:10 . 2009-08-14 08:10 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\6bafb1a2a73794ddb9761cb321c9e7e2\PresentationUI.ni.dll
+ 2009-08-14 08:07 . 2009-08-14 08:07 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\e634bc4c4a00635a0a254febab0e2e2c\PresentationBuildTasks.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\1c86afc399d0fdd8e069266ffbe748d1\Microsoft.VisualBasic.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\6b2f62f5e981913fce1d223f645d9ddf\Microsoft.Transactions.Bridge.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\b261961046545831aa60963e84905968\Microsoft.JScript.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\bd241492d96db39f20e758c13c845033\Microsoft.Build.Tasks.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\a47100d8f4574bed2d49d83d0ab8964e\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2009-08-14 08:14 . 2009-08-14 08:14 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\6cfe582681724965fb817e8ece5f0909\Microsoft.Build.Engine.ni.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 1245184 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2009-08-14 08:04 . 2009-08-14 08:04 3149824 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2009-08-14 08:04 . 2009-08-14 08:04 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 1630208 c:\windows\assembly\GAC_MSIL\System.Workflow.ComponentModel\3.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 1138688 c:\windows\assembly\GAC_MSIL\System.Workflow.Activities\3.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2009-08-14 08:07 . 2009-08-14 08:07 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
+ 2009-08-14 08:06 . 2009-08-14 08:06 5931008 c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2009-06-30 18:07 . 2009-06-30 18:07 2879488 c:\windows\assembly\GAC_MSIL\System.Data.Entity\3.5.0.0__b77a5c561934e089\System.Data.Entity.dll
+ 2009-08-14 08:06 . 2009-08-14 08:06 5283840 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-08-14 08:04 . 2009-08-14 08:04 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2009-06-30 18:05 . 2009-06-30 18:05 4210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2009-08-14 08:03 . 2009-08-14 08:03 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 1495552 c:\windows\$NtUninstallKB972260$\shdocvw.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 3060736 c:\windows\$NtUninstallKB972260$\mshtml.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 1054208 c:\windows\$NtUninstallKB972260$\danim.dll
+ 2009-07-30 08:01 . 2009-04-29 04:52 1023488 c:\windows\$NtUninstallKB972260$\browseui.dll
+ 2009-07-15 08:04 . 2008-12-20 22:43 1287680 c:\windows\$NtUninstallKB971633$\quartz.dll
+ 2009-06-12 08:08 . 2009-03-02 23:52 1495552 c:\windows\$NtUninstallKB969897$\shdocvw.dll
+ 2009-06-12 08:08 . 2009-02-20 08:30 3059712 c:\windows\$NtUninstallKB969897$\mshtml.dll
+ 2009-06-12 08:08 . 2009-02-20 08:30 1054208 c:\windows\$NtUninstallKB969897$\danim.dll
+ 2009-06-12 08:08 . 2009-02-20 08:30 1023488 c:\windows\$NtUninstallKB969897$\browseui.dll
+ 2009-06-12 08:02 . 2009-02-09 10:19 1846272 c:\windows\$NtUninstallKB968537$\win32k.sys
+ 2005-01-01 17:47 . 2002-08-29 11:00 1325568 c:\windows\$NtServicePackUninstall$\webfldrs.msi
+ 2009-07-18 15:31 . 2009-07-18 15:31 1509888 c:\windows\$hf_mig$\KB972260\SP3QFE\shdocvw.dll
+ 2009-07-18 15:31 . 2009-07-18 15:31 3069952 c:\windows\$hf_mig$\KB972260\SP3QFE\mshtml.dll
+ 2009-07-18 16:05 . 2009-07-18 16:05 1509888 c:\windows\$hf_mig$\KB972260\SP3GDR\shdocvw.dll
+ 2009-07-18 16:05 . 2009-07-18 16:05 3069440 c:\windows\$hf_mig$\KB972260\SP3GDR\mshtml.dll
+ 2009-07-18 16:00 . 2009-07-18 16:00 1509888 c:\windows\$hf_mig$\KB972260\SP2QFE\shdocvw.dll
+ 2009-07-18 16:00 . 2009-07-18 16:00 3069440 c:\windows\$hf_mig$\KB972260\SP2QFE\mshtml.dll
+ 2009-06-26 15:59 . 2009-06-26 15:59 1054208 c:\windows\$hf_mig$\KB972260\SP2QFE\danim.dll
+ 2009-06-26 15:59 . 2009-06-26 15:59 1024000 c:\windows\$hf_mig$\KB972260\SP2QFE\browseui.dll
+ 2009-06-03 19:12 . 2009-06-03 19:12 1291264 c:\windows\$hf_mig$\KB971633\SP3QFE\quartz.dll
+ 2009-06-03 19:09 . 2009-06-03 19:09 1291264 c:\windows\$hf_mig$\KB971633\SP3GDR\quartz.dll
+ 2009-06-03 19:24 . 2009-06-03 19:24 1291264 c:\windows\$hf_mig$\KB971633\SP2QFE\quartz.dll
+ 2009-04-29 04:21 . 2009-04-29 04:21 1499136 c:\windows\$hf_mig$\KB969897\SP3QFE\shdocvw.dll
+ 2009-04-29 04:21 . 2009-04-29 04:21 3069440 c:\windows\$hf_mig$\KB969897\SP3QFE\mshtml.dll
+ 2009-04-29 04:46 . 2009-04-29 04:46 1499136 c:\windows\$hf_mig$\KB969897\SP3GDR\shdocvw.dll
+ 2009-04-29 04:46 . 2009-04-29 04:46 3068928 c:\windows\$hf_mig$\KB969897\SP3GDR\mshtml.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 1499136 c:\windows\$hf_mig$\KB969897\SP2QFE\shdocvw.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 3068928 c:\windows\$hf_mig$\KB969897\SP2QFE\mshtml.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 1054208 c:\windows\$hf_mig$\KB969897\SP2QFE\danim.dll
+ 2009-04-29 04:31 . 2009-04-29 04:31 1024000 c:\windows\$hf_mig$\KB969897\SP2QFE\browseui.dll
+ 2009-04-17 10:50 . 2009-04-17 10:50 1847808 c:\windows\$hf_mig$\KB968537\SP3QFE\win32k.sys
+ 2009-04-17 12:26 . 2009-04-17 12:26 1847168 c:\windows\$hf_mig$\KB968537\SP3GDR\win32k.sys
+ 2009-04-17 10:09 . 2009-04-17 10:09 1847936 c:\windows\$hf_mig$\KB968537\SP2QFE\win32k.sys
+ 2003-09-17 07:25 . 2009-07-14 04:43 10841088 c:\windows\SYSTEM32\wmp.dll
+ 2005-05-12 08:00 . 2009-07-30 00:49 24281536 c:\windows\SYSTEM32\MRT.exe
+ 2003-09-17 07:25 . 2009-07-14 04:43 10841088 c:\windows\SYSTEM32\DLLCACHE\wmp.dll
+ 2008-12-13 15:21 . 2008-12-13 15:21 10473472 c:\windows\Installer\a3fca75.msp
+ 2004-07-08 05:23 . 2004-07-08 05:23 18643968 c:\windows\Installer\670fe9e.msp
+ 2003-12-04 19:19 . 2003-12-04 19:19 12298240 c:\windows\Installer\5bae8.msi
+ 2008-10-20 16:22 . 2008-10-20 16:22 11758592 c:\windows\Installer\51f88b1.msp
+ 2008-08-11 17:51 . 2008-08-11 17:51 15916544 c:\windows\Installer\51f8886.msp
+ 2008-08-11 17:49 . 2008-08-11 17:49 22457344 c:\windows\Installer\51f8875.msp
+ 2008-09-24 18:05 . 2008-09-24 18:05 16381440 c:\windows\Installer\51f8868.msp
+ 2007-10-15 05:33 . 2007-10-15 05:33 26646016 c:\windows\Installer\51f3712.msp
+ 2008-07-30 14:50 . 2008-07-30 14:50 12506112 c:\windows\Installer\51b5815.msp
+ 2008-06-04 19:29 . 2008-06-04 19:29 16905728 c:\windows\Installer\51b57f3.msp
+ 2008-01-14 21:24 . 2008-01-14 21:24 10721280 c:\windows\Installer\51b57a9.msp
+ 2007-07-11 08:01 . 2007-07-11 08:01 15256576 c:\windows\Installer\2b652d9c.msp
+ 2009-07-22 08:00 . 2009-07-22 08:00 15706112 c:\windows\Installer\26992216.msp
+ 2009-07-01 18:19 . 2009-07-01 18:19 10607104 c:\windows\Installer\1c3eed13.msp
+ 2009-07-31 08:00 . 2009-07-31 08:00 15705600 c:\windows\Installer\1bdda25.msp
+ 2005-01-01 18:45 . 2005-01-01 18:45 19210240 c:\windows\Installer\124661.msp
+ 2003-12-18 21:18 . 2003-12-18 21:18 19008000 c:\windows\Downloaded Installations\{ED9C4B62-65C7-415D-B6EC-C250B60CD0CD}\iTunes.msi
+ 2009-08-14 08:11 . 2009-08-14 08:11 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\63406259e94d5c0ff5b79401dfe113ce\System.Windows.Forms.ni.dll
+ 2009-08-14 08:16 . 2009-08-14 08:16 11796992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\3963ce03d445a8619abbf388d590134b\System.Web.ni.dll
+ 2009-08-14 08:13 . 2009-08-14 08:13 17317888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\4146033013edebd7e0cb604e504ebfee\System.ServiceModel.ni.dll
+ 2009-08-14 08:11 . 2009-08-14 08:11 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\8ee220bc3cce4f7bbd7818946519ed7f\System.Design.ni.dll
+ 2009-08-14 08:10 . 2009-08-14 08:10 14327808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\96e710f47c601cba3f2348a8d11ddede\PresentationFramework.ni.dll
+ 2009-08-14 08:08 . 2009-08-14 08:08 12216320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\956375d487cbef36165b3250030e3574\PresentationCore.ni.dll
+ 2009-08-14 08:06 . 2009-08-14 08:06 11486720 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\6d667f19d687361886990f3ca0f49816\mscorlib.ni.dll
+ 2007-07-27 15:03 . 2007-07-27 15:03 119977472 c:\windows\Installer\51f384d.msp
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-24 68856]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"StorageGuard"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2003-08-27 204800]
"USIUDF_Eject_Monitor"="c:\program files\Common Files\Ulead Systems\DVD\USISrv.exe" [2004-12-23 81920]
"PSDiagnosticM"="c:\program files\Linksys Wireless-G Print Server\PSDiagnosticM.exe" [2007-02-27 315392]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-09 645328]
"KnexStarter"="c:\program files\Common Files\Hewlett-Packard\HP Device Communication Services\Appinterfaces\HPDeviceService.exe" [2008-06-07 73728]
"RunTasktray"="c:\program files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe" [2008-06-06 69120]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-03 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2003-12-18 98304]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP Easy Printer Care\\HPPRun.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Linksys Wireless-G Print Server\\PSDiagnosticM.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:RPC
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"53:UDP"= 53:UDP:Promo

R1 ewido security suite driver;ewido security suite driver;c:\program files\ewido anti-malware\guard.sys [12/30/2005 6:12 AM 3072]
R3 lknuhst;Linksys Network USB Host Controller;c:\windows\SYSTEM32\DRIVERS\lknuhst.sys [5/22/2007 3:43 PM 11136]
R3 LKNUHUB;Linksys Network USB Root Hub;c:\windows\SYSTEM32\DRIVERS\lknuhub.sys [5/22/2007 3:43 PM 37248]
S3 TLA13;TLA13;\??\c:\docume~1\rick_2\LOCALS~1\Temp\user.bak –> c:\docume~1\rick_2\LOCALS~1\Temp\user.bak [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder

2009-08-31 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-26 20:17]

2009-08-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2006-12-29 15:53]

2009-08-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2006-12-29 15:53]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.oscn.net/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: &Search; - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
IE: &Yahoo;! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Open Image in New Window - c:\progra~1\PopUpCop\popupcop.dll/imagenew
IE: Yahoo! &Dictionary; - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: microsoft.com\office
Trusted Zone: microsoft.com\officeupdate
Trusted Zone: hp.com
Handler: HPDCS - {ba135f49-a12c-4e26-a2c4-6ea945999072} - c:\program files\Common Files\Hewlett-Packard\HP Device Communication Services\APP\hpdcsapp.dll
Handler: hppfile - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - c:\program files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
Handler: hppsam - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - c:\program files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
Handler: hppzip - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - c:\program files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
FF - ProfilePath - c:\documents and settings\rick_2\Application Data\Mozilla\Firefox\Profiles\6ldr4f98.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.oscn.net
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npImgCtl.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-31 16:31
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TLA13]
"ImagePath"="\??\c:\docume~1\rick_2\LOCALS~1\Temp\user.bak"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(744)
c:\windows\system32\MPBWave.drv
.
———————— Other Running Processes ————————
.
c:\program files\ewido anti-malware\ewidoctrl.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\Common Files\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\progra~1\McAfee.com\Agent\mcagent.exe
c:\program files\Common Files\Hewlett-Packard\HP Device Communication Services\AppInterfaces\HPDeviceHost.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2009-08-31 16:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-31 21:41
ComboFix2.txt 2009-05-08 18:34

Pre-Run: 56,738,889,728 bytes free
Post-Run: 56,613,068,800 bytes free

1265 — E O F — 2009-08-27 08:00
Additionally, I am now able to open things on my desktop and the Win32Diag.txt log that I could not access earlier: Log file is located at: C:\Documents and Settings\rick_2\Desktop\Win32kDiag.txt Removing all found mount points. Attempting to reset file permissions. WARNING: Could not get backup privileges! Searching 'C:\WINDOWS'… Cannot access: C:\WINDOWS\$NtUninstallKB828028$\msasn1.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828028$\msasn1.dll [1] 2004-03-29 20:48:36 51712 C:\WINDOWS\$NtServicePackUninstall$\msasn1.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 51200 C:\WINDOWS\$NtUninstallKB828028$\msasn1.dll (Microsoft Corporation) [1] 2003-09-19 12:37:54 51712 C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll () [1] 2004-08-04 02:56:42 57344 C:\WINDOWS\ServicePackFiles\i386\msasn1.dll (Microsoft Corporation) [1] 2008-04-13 19:11:58 57344 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\msasn1.dll (Microsoft Corporation) [1] 2004-08-04 02:56:42 57344 C:\WINDOWS\SYSTEM32\DLLCACHE\msasn1.dll (Microsoft Corporation) [1] 2004-08-04 02:56:42 57344 C:\WINDOWS\SYSTEM32\msasn1.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 51200 C:\i386\MSASN1.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll [1] 2005-07-25 23:20:23 225792 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\catsrv.dll (Microsoft Corporation) [1] 2004-03-05 21:16:10 225280 C:\WINDOWS\$NtServicePackUninstall$\catsrv.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 215040 C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 229888 C:\WINDOWS\$NtUninstallKB902400$\catsrv.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 229888 C:\WINDOWS\ServicePackFiles\i386\catsrv.dll (Microsoft Corporation) [1] 2008-04-13 19:11:50 226304 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\catsrv.dll (Microsoft Corporation) [1] 2005-07-25 23:39:42 225792 C:\WINDOWS\SYSTEM32\catsrv.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 215040 C:\i386\CATSRV.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll [1] 2005-07-25 23:20:23 625152 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\catsrvut.dll (Microsoft Corporation) [1] 2004-03-05 21:16:10 594944 C:\WINDOWS\$NtServicePackUninstall$\catsrvut.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 582656 C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 628224 C:\WINDOWS\$NtUninstallKB902400$\catsrvut.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 628224 C:\WINDOWS\ServicePackFiles\i386\catsrvut.dll (Microsoft Corporation) [1] 2008-04-13 19:11:50 625664 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\catsrvut.dll (Microsoft Corporation) [1] 2005-07-25 23:39:43 625152 C:\WINDOWS\SYSTEM32\catsrvut.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 582656 C:\i386\CATSRVUT.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll [1] 2005-07-25 23:20:23 110080 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatex.dll (Microsoft Corporation) [1] 2004-03-05 21:16:10 110080 C:\WINDOWS\$NtServicePackUninstall$\clbcatex.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 100864 C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 110080 C:\WINDOWS\$NtUninstallKB902400$\clbcatex.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 110080 C:\WINDOWS\ServicePackFiles\i386\clbcatex.dll (Microsoft Corporation) [1] 2008-04-13 19:11:50 110592 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\clbcatex.dll (Microsoft Corporation) [1] 2005-07-25 23:39:43 110080 C:\WINDOWS\SYSTEM32\clbcatex.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 100864 C:\i386\CLBCATEX.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll [1] 2005-07-25 23:20:24 498688 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatq.dll (Microsoft Corporation) [1] 2004-03-05 21:16:11 499712 C:\WINDOWS\$NtServicePackUninstall$\clbcatq.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 468480 C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 501248 C:\WINDOWS\$NtUninstallKB902400$\clbcatq.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 501248 C:\WINDOWS\ServicePackFiles\i386\clbcatq.dll (Microsoft Corporation) [1] 2008-04-13 19:11:50 498688 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\clbcatq.dll (Microsoft Corporation) [1] 2005-07-25 23:39:43 498688 C:\WINDOWS\SYSTEM32\clbcatq.dll (Microsoft Corporation) [1] 2005-07-25 23:39:43 498688 C:\WINDOWS\SYSTEM32\DLLCACHE\clbcatq.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 468480 C:\i386\CLBCATQ.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\colbact.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\colbact.dll [1] 2005-07-25 23:20:24 60416 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\colbact.dll (Microsoft Corporation) [1] 2005-07-25 23:20:24 60416 C:\WINDOWS\$hf_mig$\KB956572\SP2QFE\colbact.dll (Microsoft Corporation) [1] 2004-03-05 21:16:10 64512 C:\WINDOWS\$NtServicePackUninstall$\colbact.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 56832 C:\WINDOWS\$NtUninstallKB828741$\colbact.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 62464 C:\WINDOWS\$NtUninstallKB902400$\colbact.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 62464 C:\WINDOWS\ServicePackFiles\i386\colbact.dll (Microsoft Corporation) [1] 2008-04-13 19:11:51 60416 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\colbact.dll (Microsoft Corporation) [1] 2005-07-25 23:39:43 60416 C:\WINDOWS\SYSTEM32\colbact.dll (Microsoft Corporation) [1] 2005-07-25 23:39:43 60416 C:\WINDOWS\SYSTEM32\DLLCACHE\colbact.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 56832 C:\i386\COLBACT.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll [1] 2005-07-25 23:20:24 195072 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\comadmin.dll (Microsoft Corporation) [1] 2004-03-05 21:16:10 187904 C:\WINDOWS\$NtServicePackUninstall$\comadmin.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 186880 C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 195584 C:\WINDOWS\$NtUninstallKB902400$\comadmin.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 195584 C:\WINDOWS\ServicePackFiles\i386\comadmin.dll (Microsoft Corporation) [1] 2008-04-13 19:11:51 195072 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\comadmin.dll (Microsoft Corporation) [1] 2005-07-25 23:39:44 195072 C:\WINDOWS\SYSTEM32\Com\comadmin.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 186880 C:\i386\COMADMIN.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe [1] 2004-02-17 13:49:58 8192 C:\WINDOWS\$NtServicePackUninstall$\comrepl.exe (Microsoft Corporation) [1] 2002-08-29 06:00:00 8192 C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe (Microsoft Corporation) [1] 2004-08-04 02:56:48 9728 C:\WINDOWS\ServicePackFiles\i386\comrepl.exe (Microsoft Corporation) [1] 2008-04-13 19:12:15 9728 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\comrepl.exe (Microsoft Corporation) [1] 2004-08-04 02:56:48 9728 C:\WINDOWS\SYSTEM32\Com\comrepl.exe (Microsoft Corporation) [1] 2002-08-29 06:00:00 8192 C:\i386\COMREPL.EXE (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll [1] 2005-07-25 23:20:27 1267200 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\comsvcs.dll (Microsoft Corporation) [1] 2004-03-05 21:16:11 1194496 C:\WINDOWS\$NtServicePackUninstall$\comsvcs.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 1172992 C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 1251840 C:\WINDOWS\$NtUninstallKB902400$\comsvcs.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 1251840 C:\WINDOWS\ServicePackFiles\i386\comsvcs.dll (Microsoft Corporation) [1] 2008-04-13 19:11:51 1267200 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\comsvcs.dll (Microsoft Corporation) [1] 2005-07-25 23:39:44 1267200 C:\WINDOWS\SYSTEM32\comsvcs.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 1172992 C:\i386\COMSVCS.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\comuid.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\comuid.dll [1] 2005-07-25 23:20:28 540160 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\comuid.dll (Microsoft Corporation) [1] 2004-03-05 21:16:10 499200 C:\WINDOWS\$NtServicePackUninstall$\comuid.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 495616 C:\WINDOWS\$NtUninstallKB828741$\comuid.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 540160 C:\WINDOWS\$NtUninstallKB902400$\comuid.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 540160 C:\WINDOWS\ServicePackFiles\i386\comuid.dll (Microsoft Corporation) [1] 2008-04-13 19:11:51 539648 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\comuid.dll (Microsoft Corporation) [1] 2005-07-25 23:39:45 540160 C:\WINDOWS\SYSTEM32\comuid.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 495616 C:\i386\COMUID.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\es.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\es.dll [1] 2005-07-25 23:20:28 243200 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\es.dll (Microsoft Corporation) [1] 2008-07-07 15:06:43 253952 C:\WINDOWS\$hf_mig$\KB950974\SP2QFE\es.dll (Microsoft Corporation) [1] 2008-07-07 15:26:58 253952 C:\WINDOWS\$hf_mig$\KB950974\SP3GDR\es.dll (Microsoft Corporation) [1] 2008-07-07 15:23:18 253952 C:\WINDOWS\$hf_mig$\KB950974\SP3QFE\es.dll (Microsoft Corporation) [1] 2004-03-05 21:16:11 226816 C:\WINDOWS\$NtServicePackUninstall$\es.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 225280 C:\WINDOWS\$NtUninstallKB828741$\es.dll (Microsoft Corporation) [1] 2004-08-04 02:56:42 243200 C:\WINDOWS\$NtUninstallKB902400$\es.dll (Microsoft Corporation) [1] 2005-07-25 23:39:45 243200 C:\WINDOWS\$NtUninstallKB950974$\es.dll (Microsoft Corporation) [1] 2004-08-04 02:56:42 243200 C:\WINDOWS\ServicePackFiles\i386\es.dll (Microsoft Corporation) [1] 2008-04-13 19:11:53 246272 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\es.dll (Microsoft Corporation) [1] 2008-07-07 15:32:22 253952 C:\WINDOWS\SYSTEM32\DLLCACHE\es.dll (Microsoft Corporation) [1] 2008-07-07 15:32:22 253952 C:\WINDOWS\SYSTEM32\es.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 225280 C:\i386\ES.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll [1] 2005-07-25 23:20:29 425472 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\msdtcprx.dll (Microsoft Corporation) [1] 2006-03-01 14:34:20 426496 C:\WINDOWS\$hf_mig$\KB913580\SP2QFE\msdtcprx.dll (Microsoft Corporation) [1] 2008-06-12 08:47:12 428032 C:\WINDOWS\$hf_mig$\KB952004\SP2QFE\msdtcprx.dll (Microsoft Corporation) [1] 2008-06-12 09:23:32 428032 C:\WINDOWS\$hf_mig$\KB952004\SP3GDR\msdtcprx.dll (Microsoft Corporation) [1] 2008-06-12 09:09:35 428032 C:\WINDOWS\$hf_mig$\KB952004\SP3QFE\msdtcprx.dll (Microsoft Corporation) [1] 2004-03-05 21:16:10 367616 C:\WINDOWS\$NtServicePackUninstall$\msdtcprx.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 359936 C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll (Microsoft Corporation) [1] 2004-08-04 02:56:43 425472 C:\WINDOWS\$NtUninstallKB902400$\msdtcprx.dll (Microsoft Corporation) [1] 2005-07-25 23:39:46 425472 C:\WINDOWS\$NtUninstallKB913580$\msdtcprx.dll (Microsoft Corporation) [1] 2006-03-01 14:42:42 426496 C:\WINDOWS\$NtUninstallKB952004$\msdtcprx.dll (Microsoft Corporation) [1] 2004-08-04 02:56:43 425472 C:\WINDOWS\ServicePackFiles\i386\msdtcprx.dll (Microsoft Corporation) [1] 2008-04-13 19:11:59 427008 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\msdtcprx.dll (Microsoft Corporation) [1] 2008-06-12 09:16:46 428032 C:\WINDOWS\SYSTEM32\DLLCACHE\msdtcprx.dll (Microsoft Corporation) [1] 2008-06-12 09:16:46 428032 C:\WINDOWS\SYSTEM32\msdtcprx.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 359936 C:\i386\MSDTCPRX.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll [1] 2005-07-25 23:20:31 945152 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\msdtctm.dll (Microsoft Corporation) [1] 2006-03-01 14:34:20 956416 C:\WINDOWS\$hf_mig$\KB913580\SP2QFE\msdtctm.dll (Microsoft Corporation) [1] 2008-06-12 08:47:13 956928 C:\WINDOWS\$hf_mig$\KB952004\SP2QFE\msdtctm.dll (Microsoft Corporation) [1] 2008-06-12 09:23:32 956928 C:\WINDOWS\$hf_mig$\KB952004\SP3GDR\msdtctm.dll (Microsoft Corporation) [1] 2008-06-12 09:09:35 956928 C:\WINDOWS\$hf_mig$\KB952004\SP3QFE\msdtctm.dll (Microsoft Corporation) [1] 2004-03-05 21:16:11 977920 C:\WINDOWS\$NtServicePackUninstall$\msdtctm.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 869376 C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll (Microsoft Corporation) [1] 2004-08-04 02:56:43 949248 C:\WINDOWS\$NtUninstallKB902400$\msdtctm.dll (Microsoft Corporation) [1] 2005-07-25 23:39:47 945152 C:\WINDOWS\$NtUninstallKB913580$\msdtctm.dll (Microsoft Corporation) [1] 2006-03-01 14:42:42 956416 C:\WINDOWS\$NtUninstallKB952004$\msdtctm.dll (Microsoft Corporation) [1] 2004-08-04 02:56:43 949248 C:\WINDOWS\ServicePackFiles\i386\msdtctm.dll (Microsoft Corporation) [1] 2008-04-13 19:11:59 956928 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\msdtctm.dll (Microsoft Corporation) [1] 2008-06-12 09:16:46 956928 C:\WINDOWS\SYSTEM32\DLLCACHE\msdtctm.dll (Microsoft Corporation) [1] 2008-06-12 09:16:46 956928 C:\WINDOWS\SYSTEM32\msdtctm.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 869376 C:\i386\MSDTCTM.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll [1] 2005-07-25 23:20:31 161280 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\msdtcuiu.dll (Microsoft Corporation) [1] 2006-03-01 14:34:20 161280 C:\WINDOWS\$hf_mig$\KB913580\SP2QFE\msdtcuiu.dll (Microsoft Corporation) [1] 2008-06-12 08:47:13 161792 C:\WINDOWS\$hf_mig$\KB952004\SP2QFE\msdtcuiu.dll (Microsoft Corporation) [1] 2008-06-12 09:23:32 161792 C:\WINDOWS\$hf_mig$\KB952004\SP3GDR\msdtcuiu.dll (Microsoft Corporation) [1] 2008-06-12 09:09:35 161792 C:\WINDOWS\$hf_mig$\KB952004\SP3QFE\msdtcuiu.dll (Microsoft Corporation) [1] 2004-03-05 21:16:10 150528 C:\WINDOWS\$NtServicePackUninstall$\msdtcuiu.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 151040 C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll (Microsoft Corporation) [1] 2004-08-04 02:56:43 161280 C:\WINDOWS\$NtUninstallKB902400$\msdtcuiu.dll (Microsoft Corporation) [1] 2005-07-25 23:39:47 161280 C:\WINDOWS\$NtUninstallKB913580$\msdtcuiu.dll (Microsoft Corporation) [1] 2006-03-01 14:42:42 161280 C:\WINDOWS\$NtUninstallKB952004$\msdtcuiu.dll (Microsoft Corporation) [1] 2004-08-04 02:56:43 161280 C:\WINDOWS\ServicePackFiles\i386\msdtcuiu.dll (Microsoft Corporation) [1] 2008-04-13 19:11:59 161792 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\msdtcuiu.dll (Microsoft Corporation) [1] 2008-06-12 09:16:46 161792 C:\WINDOWS\SYSTEM32\DLLCACHE\msdtcuiu.dll (Microsoft Corporation) [1] 2008-06-12 09:16:46 161792 C:\WINDOWS\SYSTEM32\msdtcuiu.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 151040 C:\i386\MSDTCUIU.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll [1] 2005-07-25 23:20:39 66560 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\mtxclu.dll (Microsoft Corporation) [1] 2006-03-01 14:34:20 66560 C:\WINDOWS\$hf_mig$\KB913580\SP2QFE\mtxclu.dll (Microsoft Corporation) [1] 2008-06-12 08:47:13 66560 C:\WINDOWS\$hf_mig$\KB952004\SP2QFE\mtxclu.dll (Microsoft Corporation) [1] 2008-06-12 09:23:32 66560 C:\WINDOWS\$hf_mig$\KB952004\SP3GDR\mtxclu.dll (Microsoft Corporation) [1] 2008-06-12 09:09:35 66560 C:\WINDOWS\$hf_mig$\KB952004\SP3QFE\mtxclu.dll (Microsoft Corporation) [1] 2004-03-05 21:16:10 64512 C:\WINDOWS\$NtServicePackUninstall$\mtxclu.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 61440 C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll (Microsoft Corporation) [1] 2004-08-04 02:56:44 66560 C:\WINDOWS\$NtUninstallKB902400$\mtxclu.dll (Microsoft Corporation) [1] 2005-07-25 23:39:47 66560 C:\WINDOWS\$NtUninstallKB913580$\mtxclu.dll (Microsoft Corporation) [1] 2006-03-01 14:42:42 66560 C:\WINDOWS\$NtUninstallKB952004$\mtxclu.dll (Microsoft Corporation) [1] 2004-08-04 02:56:44 66560 C:\WINDOWS\ServicePackFiles\i386\mtxclu.dll (Microsoft Corporation) [1] 2008-04-13 19:12:01 66560 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\mtxclu.dll (Microsoft Corporation) [1] 2008-06-12 09:16:46 66560 C:\WINDOWS\SYSTEM32\DLLCACHE\mtxclu.dll (Microsoft Corporation) [1] 2008-06-12 09:16:46 66560 C:\WINDOWS\SYSTEM32\mtxclu.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 61440 C:\i386\MTXCLU.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll [1] 2005-07-25 23:20:40 91136 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\mtxoci.dll (Microsoft Corporation) [1] 2006-03-01 14:34:20 91136 C:\WINDOWS\$hf_mig$\KB913580\SP2QFE\mtxoci.dll (Microsoft Corporation) [1] 2008-06-12 08:47:13 91648 C:\WINDOWS\$hf_mig$\KB952004\SP2QFE\mtxoci.dll (Microsoft Corporation) [1] 2008-06-12 09:23:32 91648 C:\WINDOWS\$hf_mig$\KB952004\SP3GDR\mtxoci.dll (Microsoft Corporation) [1] 2008-06-12 09:09:35 91648 C:\WINDOWS\$hf_mig$\KB952004\SP3QFE\mtxoci.dll (Microsoft Corporation) [1] 2004-03-05 21:16:10 82432 C:\WINDOWS\$NtServicePackUninstall$\mtxoci.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 83968 C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll (Microsoft Corporation) [1] 2004-08-04 02:56:44 90112 C:\WINDOWS\$NtUninstallKB902400$\mtxoci.dll (Microsoft Corporation) [1] 2005-07-25 23:39:47 91136 C:\WINDOWS\$NtUninstallKB913580$\mtxoci.dll (Microsoft Corporation) [1] 2006-03-01 14:42:42 91136 C:\WINDOWS\$NtUninstallKB952004$\mtxoci.dll (Microsoft Corporation) [1] 2004-08-04 02:56:44 90112 C:\WINDOWS\ServicePackFiles\i386\mtxoci.dll (Microsoft Corporation) [1] 2008-04-13 19:12:01 91648 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\mtxoci.dll (Microsoft Corporation) [1] 2008-06-12 09:16:46 91648 C:\WINDOWS\SYSTEM32\DLLCACHE\mtxoci.dll (Microsoft Corporation) [1] 2008-06-12 09:16:46 91648 C:\WINDOWS\SYSTEM32\mtxoci.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 83968 C:\i386\MTXOCI.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\ole32.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\ole32.dll [1] 2005-01-14 00:07:42 1284608 C:\WINDOWS\$hf_mig$\KB873333\SP2QFE\ole32.dll (Microsoft Corporation) [1] 2005-04-28 14:35:02 1286144 C:\WINDOWS\$hf_mig$\KB894391\SP2QFE\ole32.dll (Microsoft Corporation) [1] 2005-07-25 23:20:40 1285632 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\ole32.dll (Microsoft Corporation) [1] 2004-03-05 21:16:11 1183744 C:\WINDOWS\$NtServicePackUninstall$\ole32.dll (Microsoft Corporation) [1] 2003-08-25 14:53:44 1172992 C:\WINDOWS\$NtUninstallKB828741$\ole32.dll (Microsoft Corporation) [1] 2004-08-04 02:56:44 1281536 C:\WINDOWS\$NtUninstallKB873333$\ole32.dll (Microsoft Corporation) [1] 2005-01-14 03:55:50 1285120 C:\WINDOWS\$NtUninstallKB894391$\ole32.dll (Microsoft Corporation) [1] 2005-04-28 14:31:11 1285120 C:\WINDOWS\$NtUninstallKB902400$\ole32.dll (Microsoft Corporation) [1] 2004-08-04 02:56:44 1281536 C:\WINDOWS\ServicePackFiles\i386\ole32.dll (Microsoft Corporation) [1] 2008-04-13 19:12:02 1287168 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ole32.dll (Microsoft Corporation) [1] 2005-07-25 23:39:48 1285120 C:\WINDOWS\SYSTEM32\DLLCACHE\ole32.dll (Microsoft Corporation) [1] 2005-07-25 23:39:48 1285120 C:\WINDOWS\SYSTEM32\ole32.dll (Microsoft Corporation) [1] 2003-08-25 14:53:44 1172992 C:\i386\OLE32.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll [1] 2007-07-09 08:16:16 582656 C:\WINDOWS\$hf_mig$\KB933729\SP2QFE\rpcrt4.dll (Microsoft Corporation) [1] 2009-04-15 10:26:39 583168 C:\WINDOWS\$hf_mig$\KB970238\SP2QFE\rpcrt4.dll (Microsoft Corporation) [1] 2009-04-15 09:51:25 585216 C:\WINDOWS\$hf_mig$\KB970238\SP3GDR\rpcrt4.dll (Microsoft Corporation) [1] 2009-04-15 10:24:20 585216 C:\WINDOWS\$hf_mig$\KB970238\SP3QFE\rpcrt4.dll (Microsoft Corporation) [1] 2004-03-05 21:16:11 535552 C:\WINDOWS\$NtServicePackUninstall$\rpcrt4.dll (Microsoft Corporation) [1] 2003-08-25 14:53:46 532480 C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll (Microsoft Corporation) [1] 2004-08-04 02:56:44 581120 C:\WINDOWS\$NtUninstallKB933729$\rpcrt4.dll (Microsoft Corporation) [1] 2007-07-09 08:09:42 584192 C:\WINDOWS\$NtUninstallKB970238$\rpcrt4.dll (Microsoft Corporation) [1] 2004-08-04 02:56:44 581120 C:\WINDOWS\ServicePackFiles\i386\rpcrt4.dll (Microsoft Corporation) [1] 2008-04-13 19:12:04 584704 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\rpcrt4.dll (Microsoft Corporation) [1] 2009-04-15 10:11:19 584192 C:\WINDOWS\SYSTEM32\DLLCACHE\rpcrt4.dll (Microsoft Corporation) [1] 2009-04-15 10:11:19 584192 C:\WINDOWS\SYSTEM32\rpcrt4.dll (Microsoft Corporation) [2] 2007-07-09 08:09:42 584192 C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP1872\A0110712.dll (Microsoft Corporation) [2] 2007-07-09 08:09:42 584192 C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP1872\A0110800.dll (Microsoft Corporation) [1] 2003-08-25 14:53:46 532480 C:\i386\RPCRT4.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll [1] 2005-01-14 00:07:42 395776 C:\WINDOWS\$hf_mig$\KB873333\SP2QFE\rpcss.dll (Microsoft Corporation) [1] 2005-04-28 14:35:01 396288 C:\WINDOWS\$hf_mig$\KB894391\SP2QFE\rpcss.dll (Microsoft Corporation) [1] 2005-07-25 23:20:40 398336 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\rpcss.dll (Microsoft Corporation) [1] 2009-02-09 05:01:53 401408 C:\WINDOWS\$hf_mig$\KB956572\SP2QFE\rpcss.dll (Microsoft Corporation) [1] 2009-02-09 07:10:48 401408 C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\rpcss.dll (Microsoft Corporation) [1] 2009-02-09 05:56:36 401408 C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\rpcss.dll (Microsoft Corporation) [1] 2004-03-05 21:16:11 263680 C:\WINDOWS\$NtServicePackUninstall$\rpcss.dll (Microsoft Corporation) [1] 2003-08-25 14:53:40 260608 C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll (Microsoft Corporation) [1] 2004-08-04 02:56:44 395776 C:\WINDOWS\$NtUninstallKB873333$\rpcss.dll (Microsoft Corporation) [1] 2005-01-14 03:55:50 395776 C:\WINDOWS\$NtUninstallKB894391$\rpcss.dll (Microsoft Corporation) [1] 2005-04-28 14:31:11 395776 C:\WINDOWS\$NtUninstallKB902400$\rpcss.dll (Microsoft Corporation) [1] 2005-07-25 23:39:49 397824 C:\WINDOWS\$NtUninstallKB956572$\rpcss.dll (Microsoft Corporation) [1] 2004-08-04 02:56:44 395776 C:\WINDOWS\ServicePackFiles\i386\rpcss.dll (Microsoft Corporation) [1] 2008-04-13 19:12:04 399360 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\rpcss.dll (Microsoft Corporation) [1] 2009-02-09 05:20:34 399360 C:\WINDOWS\SYSTEM32\DLLCACHE\rpcss.dll (Microsoft Corporation) [1] 2009-02-09 05:20:34 399360 C:\WINDOWS\SYSTEM32\rpcss.dll (Microsoft Corporation) [1] 2003-08-25 14:53:40 260608 C:\i386\RPCSS.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\txflog.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB828741$\txflog.dll [1] 2005-07-25 23:20:40 101376 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\txflog.dll (Microsoft Corporation) [1] 2004-03-05 21:16:10 97280 C:\WINDOWS\$NtServicePackUninstall$\txflog.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 90624 C:\WINDOWS\$NtUninstallKB828741$\txflog.dll (Microsoft Corporation) [1] 2004-08-04 02:56:46 101376 C:\WINDOWS\$NtUninstallKB902400$\txflog.dll (Microsoft Corporation) [1] 2004-08-04 02:56:46 101376 C:\WINDOWS\ServicePackFiles\i386\txflog.dll (Microsoft Corporation) [1] 2008-04-13 19:12:07 101376 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\txflog.dll (Microsoft Corporation) [1] 2005-07-25 23:39:49 101376 C:\WINDOWS\SYSTEM32\txflog.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 90624 C:\i386\TXFLOG.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB833407$\bssym7.ttf Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB833407$\bssym7.ttf [1] 2000-11-17 03:33:44 55540 C:\WINDOWS\$NtUninstallKB833407$\bssym7.ttf () [1] 2003-12-12 14:42:28 54412 C:\WINDOWS\Fonts\BSSYM7.TTF () Cannot access: C:\WINDOWS\$NtUninstallKB835732$\callcont.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB835732$\callcont.dll [1] 2004-03-29 20:48:36 364544 C:\WINDOWS\$NtServicePackUninstall$\callcont.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 360448 C:\WINDOWS\$NtUninstallKB835732$\callcont.dll (Microsoft Corporation) [1] 2004-08-04 02:56:41 385024 C:\WINDOWS\ServicePackFiles\i386\callcont.dll (Microsoft Corporation) [1] 2008-04-13 19:11:50 385024 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\callcont.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 360448 C:\i386\CALLCONT.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB835732$\cmdevtgprov.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB835732$\cmdevtgprov.dll [1] 2004-03-29 20:48:36 40960 C:\WINDOWS\$NtServicePackUninstall$\cmdevtgprov.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 34304 C:\WINDOWS\$NtUninstallKB835732$\cmdevtgprov.dll (Microsoft Corporation) [1] 2004-08-04 02:56:42 45568 C:\WINDOWS\SYSTEM32\WBEM\cmdevtgprov.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 34304 C:\i386\CmdEvTgProv.dll (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB835732$\evtgprov.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB835732$\evtgprov.dll [2] 2004-03-29 20:48:36 40960 C:\WINDOWS\$NtServicePackUninstall$\cmdevtgprov.dll (Microsoft Corporation) [1] 2004-03-29 20:48:36 40960 C:\WINDOWS\$NtServicePackUninstall$\evtgprov.dll (Microsoft Corporation) [2] 2002-08-29 06:00:00 34304 C:\WINDOWS\$NtUninstallKB835732$\cmdevtgprov.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 34304 C:\WINDOWS\$NtUninstallKB835732$\evtgprov.dll (Microsoft Corporation) [1] 2004-08-04 02:56:42 45568 C:\WINDOWS\ServicePackFiles\i386\evtgprov.dll (Microsoft Corporation) [1] 2008-04-13 19:11:53 45056 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\evtgprov.dll (Microsoft Corporation) [2] 2004-08-04 02:56:42 45568 C:\WINDOWS\SYSTEM32\WBEM\cmdevtgprov.dll (Microsoft Corporation) [2] 2002-08-29 06:00:00 34304 C:\i386\CmdEvTgProv.dll (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll [1] 2005-10-05 22:18:28 280064 C:\WINDOWS\$hf_mig$\KB896424\SP2QFE\gdi32.dll (Microsoft Corporation) [1] 2005-12-28 22:04:05 280064 C:\WINDOWS\$hf_mig$\KB912919\SP2QFE\gdi32.dll (Microsoft Corporation) [1] 2007-03-08 10:48:36 282112 C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\gdi32.dll (Microsoft Corporation) [1] 2007-06-19 08:37:21 282112 C:\WINDOWS\$hf_mig$\KB938829\SP2QFE\gdi32.dll (Microsoft Corporation) [1] 2008-02-20 01:52:43 282624 C:\WINDOWS\$hf_mig$\KB948590\SP2QFE\gdi32.dll (Microsoft Corporation) [1] 2008-10-23 07:51:04 284160 C:\WINDOWS\$hf_mig$\KB956802\SP2QFE\gdi32.dll (Microsoft Corporation) [1] 2008-10-23 07:36:14 286720 C:\WINDOWS\$hf_mig$\KB956802\SP3GDR\gdi32.dll (Microsoft Corporation) [1] 2008-10-23 07:43:42 286720 C:\WINDOWS\$hf_mig$\KB956802\SP3QFE\gdi32.dll (Microsoft Corporation) [1] 2004-06-17 12:58:35 257536 C:\WINDOWS\$NtServicePackUninstall$\gdi32.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 250368 C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll (Microsoft Corporation) [1] 2004-03-29 20:48:36 257536 C:\WINDOWS\$NtUninstallKB840987$\gdi32.dll (Microsoft Corporation) [1] 2004-08-04 02:56:42 278016 C:\WINDOWS\$NtUninstallKB896424$\gdi32.dll (Microsoft Corporation) [1] 2005-10-05 22:09:36 280064 C:\WINDOWS\$NtUninstallKB912919$\gdi32.dll (Microsoft Corporation) [1] 2005-12-28 21:54:35 280064 C:\WINDOWS\$NtUninstallKB925902$\gdi32.dll (Microsoft Corporation) [1] 2007-03-08 10:36:28 281600 C:\WINDOWS\$NtUninstallKB938829$\gdi32.dll (Microsoft Corporation) [1] 2007-06-19 08:31:19 282112 C:\WINDOWS\$NtUninstallKB948590$\gdi32.dll (Microsoft Corporation) [1] 2008-02-20 01:51:05 282624 C:\WINDOWS\$NtUninstallKB956802$\gdi32.dll (Microsoft Corporation) [1] 2004-08-04 02:56:42 278016 C:\WINDOWS\ServicePackFiles\i386\gdi32.dll (Microsoft Corporation) [1] 2008-04-13 19:11:54 285184 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\gdi32.dll (Microsoft Corporation) [1] 2008-10-23 08:01:36 283648 C:\WINDOWS\SYSTEM32\DLLCACHE\gdi32.dll (Microsoft Corporation) [1] 2008-10-23 08:01:36 283648 C:\WINDOWS\SYSTEM32\gdi32.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 250368 C:\i386\GDI32.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB835732$\h323.tsp Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB835732$\h323.tsp [1] 2004-03-29 20:48:36 253440 C:\WINDOWS\$NtServicePackUninstall$\h323.tsp () [1] 2002-08-29 06:00:00 252928 C:\WINDOWS\$NtUninstallKB835732$\h323.tsp () [1] 2004-08-04 02:56:57 265728 C:\WINDOWS\ServicePackFiles\i386\h323.tsp () [1] 2008-04-13 19:12:45 265728 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\h323.tsp () [1] 2004-08-04 02:56:57 265728 C:\WINDOWS\SYSTEM32\h323.tsp () [1] 2002-08-29 06:00:00 252928 C:\i386\H323.TSP () Cannot access: C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll [1] 2004-03-29 20:48:36 593408 C:\WINDOWS\$NtServicePackUninstall$\h323msp.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 592896 C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll (Microsoft Corporation) [1] 2004-08-04 02:56:42 614912 C:\WINDOWS\ServicePackFiles\i386\h323msp.dll (Microsoft Corporation) [1] 2008-04-13 19:11:54 614912 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\h323msp.dll (Microsoft Corporation) [1] 2004-08-04 02:56:42 614912 C:\WINDOWS\SYSTEM32\h323msp.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 592896 C:\i386\H323MSP.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe [1] 2004-03-29 20:34:15 741376 C:\WINDOWS\$NtServicePackUninstall$\helpctr.exe (Microsoft Corporation) [1] 2002-08-29 06:00:00 742400 C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe (Microsoft Corporation) [1] 2004-08-04 02:56:49 768512 C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exe (Microsoft Corporation) [1] 2004-08-04 02:56:49 768512 C:\WINDOWS\ServicePackFiles\i386\helpctr.exe (Microsoft Corporation) [1] 2008-04-13 19:12:21 769024 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\helpctr.exe (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll [1] 2004-03-29 20:48:36 439808 C:\WINDOWS\$NtServicePackUninstall$\ipnathlp.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 435200 C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll (Microsoft Corporation) [1] 2004-08-04 02:56:42 331264 C:\WINDOWS\ServicePackFiles\i386\ipnathlp.dll (Microsoft Corporation) [1] 2008-04-13 19:11:55 331264 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ipnathlp.dll (Microsoft Corporation) [1] 2004-08-04 02:56:42 331264 C:\WINDOWS\SYSTEM32\ipnathlp.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 435200 C:\i386\IPNATHLP.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll [1] 2004-10-27 20:21:01 721920 C:\WINDOWS\$hf_mig$\KB885835\SP2GDR\lsasrv.dll (Microsoft Corporation) [1] 2004-10-27 20:28:18 721920 C:\WINDOWS\$hf_mig$\KB885835\SP2QFE\lsasrv.dll (Microsoft Corporation) [1] 2006-08-17 07:37:49 726528 C:\WINDOWS\$hf_mig$\KB924270\SP2QFE\lsasrv.dll (Microsoft Corporation) [1] 2007-11-07 04:50:47 727040 C:\WINDOWS\$hf_mig$\KB943485\SP2QFE\lsasrv.dll (Microsoft Corporation) [1] 2009-02-09 05:01:53 728576 C:\WINDOWS\$hf_mig$\KB956572\SP2QFE\lsasrv.dll (Microsoft Corporation) [1] 2009-02-09 07:10:49 729088 C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\lsasrv.dll (Microsoft Corporation) [1] 2009-02-09 05:56:36 729088 C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\lsasrv.dll (Microsoft Corporation) [1] 2004-10-27 20:29:54 681984 C:\WINDOWS\$NtServicePackUninstall$\lsasrv.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 671744 C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll (Microsoft Corporation) [1] 2004-08-04 02:56:42 721920 C:\WINDOWS\$NtUninstallKB885835$\lsasrv.dll (Microsoft Corporation) [1] 2004-03-29 20:48:36 667648 C:\WINDOWS\$NtUninstallKB885835_0$\lsasrv.dll (Microsoft Corporation) [1] 2004-10-27 20:21:01 721920 C:\WINDOWS\$NtUninstallKB924270$\lsasrv.dll (Microsoft Corporation) [1] 2006-08-17 07:28:27 721920 C:\WINDOWS\$NtUninstallKB943485$\lsasrv.dll (Microsoft Corporation) [1] 2007-11-07 04:26:56 721920 C:\WINDOWS\$NtUninstallKB956572$\lsasrv.dll (Microsoft Corporation) [1] 2004-08-04 02:56:42 721920 C:\WINDOWS\ServicePackFiles\i386\lsasrv.dll (Microsoft Corporation) [1] 2008-04-13 19:11:56 728064 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\lsasrv.dll (Microsoft Corporation) [1] 2009-02-09 05:20:34 723456 C:\WINDOWS\SYSTEM32\DLLCACHE\lsasrv.dll (Microsoft Corporation) [1] 2009-02-09 05:20:34 723456 C:\WINDOWS\SYSTEM32\lsasrv.dll (Microsoft Corporation) [1] 2002-08-29 06:00:00 671744 C:\i386\LSASRV.DLL (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Attempting to restore permissions of : C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll [1] 2007-03-08 10:48:36 40960 C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\mf3216.dll (Microsoft Corporation)
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Antivirus_System_Pro_can_t_get_programs_open_t106528.html&view=findpost&p=592234#entry592234

Collect::
c:\windows\system32\xa.tmp
c:\docume~1\rick_2\LOCALS~1\Temp\user.bak

Folder::
c:\program files\bbtmwg

DirLook::
C:\spoolerlogs

Driver::
TLA13

Registry::
[-HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TLA13]

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • ComboFix Log
  • MBAM Log
  • Kaspersky report
ComboFix 09-08-31.03 - doug 08/31/2009 17:40.3.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.263 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\rick_2\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

file zipped: c:\windows\system32\xa.tmp
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\bbtmwg
c:\program files\bbtmwg\dwkksysguard.exe
c:\windows\system32\xa.tmp

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_TLA13


((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-31 )))))))))))))))))))))))))))))))
.

2009-08-28 17:16 . 2009-08-28 17:16 ——– d–h–w- c:\windows\PIF
2009-08-27 23:40 . 2009-08-27 23:40 ——– d—–w- C:\spoolerlogs
2009-08-12 03:55 . 2009-06-05 07:42 655872 ——w- c:\windows\system32\dllcache\mstscax.dll
2009-08-05 09:11 . 2009-08-05 09:11 204800 ——w- c:\windows\system32\dllcache\mswebdvd.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-31 15:08 . 2008-06-03 18:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-28 16:02 . 2009-04-28 16:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-25 00:27 . 2009-06-05 16:08 3942048 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-05 09:11 . 2002-12-12 06:14 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 18:36 . 2009-04-28 16:01 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 18:36 . 2009-04-28 16:01 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-31 22:01 . 2009-01-14 22:31 ——– d—–w- c:\program files\Microsoft Silverlight
2009-07-17 18:55 . 2002-08-29 11:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-14 04:43 . 2003-12-11 21:15 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-13 17:08 . 2006-12-29 17:37 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-07-13 15:45 . 2003-12-04 19:16 48976 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-10 19:35 . 2006-12-29 17:49 ——– d—–w- c:\program files\McAfee
2009-06-30 01:38 . 2008-04-11 15:38 1878984 —-a-w- c:\documents and settings\rick_2\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-06-26 16:18 . 2004-08-24 01:32 659456 ——w- c:\windows\system32\wininet.dll
2009-06-26 16:18 . 2004-08-04 07:56 81920 ——w- c:\windows\system32\ieencode.dll
2009-06-25 18:36 . 2002-08-29 11:00 95744 —-a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36 . 2002-08-29 11:00 661504 —-a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36 . 2002-08-29 11:00 517120 —-a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36 . 2002-08-29 11:00 48640 —-a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36 . 2002-08-29 11:00 471552 —-a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36 . 2002-08-29 11:00 47104 —-a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36 . 2002-08-29 11:00 225280 —-a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36 . 2002-08-29 11:00 186880 —-a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36 . 2002-08-29 11:00 177152 —-a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36 . 2002-08-29 11:00 16896 —-a-w- c:\windows\system32\mqise.dll
2009-06-25 18:36 . 2002-08-29 11:00 138240 —-a-w- c:\windows\system32\mqad.dll
2009-06-25 18:36 . 2002-08-29 11:00 123392 —-a-w- c:\windows\system32\mqrtdep.dll
2009-06-22 11:49 . 2002-08-29 11:00 19968 —-a-w- c:\windows\system32\mqbkup.exe
2009-06-22 11:49 . 2002-08-29 11:00 117248 —-a-w- c:\windows\system32\mqtgsvc.exe
2009-06-22 11:49 . 2002-08-29 11:00 4608 —-a-w- c:\windows\system32\mqsvc.exe
2009-06-22 11:48 . 2002-08-29 11:00 91776 —-a-w- c:\windows\system32\drivers\mqac.sys
2009-06-16 14:55 . 2002-08-29 11:00 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2002-08-29 11:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-12 11:50 . 2002-08-29 11:00 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 11:50 . 2002-08-29 11:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:21 . 2002-08-29 11:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:32 . 2003-10-21 23:06 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-05 07:42 . 2002-08-29 11:00 655872 —-a-w- c:\windows\system32\mstscax.dll
2009-06-03 19:27 . 2003-05-30 15:00 1290752 —-a-w- c:\windows\system32\quartz.dll
2009-06-03 15:07 . 2009-06-03 15:08 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-06-03 15:07 . 2009-06-03 15:07 152576 —-a-w- c:\documents and settings\rick_2\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\spoolerlogs —-

2009-08-27 23:40 . 2009-08-27 23:40 8964 —-a-w- c:\spoolerlogs\spooler.xml


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-24 68856]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"StorageGuard"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2003-08-27 204800]
"USIUDF_Eject_Monitor"="c:\program files\Common Files\Ulead Systems\DVD\USISrv.exe" [2004-12-23 81920]
"PSDiagnosticM"="c:\program files\Linksys Wireless-G Print Server\PSDiagnosticM.exe" [2007-02-27 315392]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-09 645328]
"KnexStarter"="c:\program files\Common Files\Hewlett-Packard\HP Device Communication Services\Appinterfaces\HPDeviceService.exe" [2008-06-07 73728]
"RunTasktray"="c:\program files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe" [2008-06-06 69120]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-03 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2003-12-18 98304]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP Easy Printer Care\\HPPRun.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Linksys Wireless-G Print Server\\PSDiagnosticM.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:RPC
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"53:UDP"= 53:UDP:Promo

R1 ewido security suite driver;ewido security suite driver;c:\program files\ewido anti-malware\guard.sys [12/30/2005 6:12 AM 3072]
R3 lknuhst;Linksys Network USB Host Controller;c:\windows\SYSTEM32\DRIVERS\lknuhst.sys [5/22/2007 3:43 PM 11136]
R3 LKNUHUB;Linksys Network USB Root Hub;c:\windows\SYSTEM32\DRIVERS\lknuhub.sys [5/22/2007 3:43 PM 37248]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder

2009-08-31 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-26 20:17]

2009-08-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2006-12-29 15:53]

2009-08-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2006-12-29 15:53]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.oscn.net/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: &Search; - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
IE: &Yahoo;! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Open Image in New Window - c:\progra~1\PopUpCop\popupcop.dll/imagenew
IE: Yahoo! &Dictionary; - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: microsoft.com\office
Trusted Zone: microsoft.com\officeupdate
Trusted Zone: hp.com
Handler: HPDCS - {ba135f49-a12c-4e26-a2c4-6ea945999072} - c:\program files\Common Files\Hewlett-Packard\HP Device Communication Services\APP\hpdcsapp.dll
Handler: hppfile - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - c:\program files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
Handler: hppsam - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - c:\program files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
Handler: hppzip - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - c:\program files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
FF - ProfilePath - c:\documents and settings\rick_2\Application Data\Mozilla\Firefox\Profiles\6ldr4f98.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.oscn.net
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npImgCtl.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-31 17:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(744)
c:\windows\system32\MPBWave.drv

- - - - - - - > 'explorer.exe'(3928)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\MPBWave.drv
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\ewido anti-malware\ewidoctrl.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\Common Files\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\progra~1\McAfee.com\Agent\mcagent.exe
c:\windows\SYSTEM32\wscntfy.exe
c:\program files\Common Files\Hewlett-Packard\HP Device Communication Services\AppInterfaces\HPDeviceHost.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2009-08-31 17:58 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-31 22:58
ComboFix2.txt 2009-08-31 21:41
ComboFix3.txt 2009-05-08 18:34

Pre-Run: 56,625,115,136 bytes free
Post-Run: 56,588,259,328 bytes free

204 — E O F — 2009-08-27 08:00


Malwarebytes' Anti-Malware 1.40
Database version: 2725
Windows 5.1.2600 Service Pack 2

9/1/2009 10:12:03 AM
mbam-log-2009-09-01 (10-12-03).txt

Scan type: Quick Scan
Objects scanned: 109247
Time elapsed: 7 minute(s), 37 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Tuesday, September 1, 2009
Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, September 01, 2009 18:34:05
Records in database: 2737256
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
S:\

Scan statistics:
Objects scanned: 108194
Threats found: 10
Infected objects found: 16
Suspicious objects found: 3
Scan duration: 03:31:51


File name / Threat / Threats count
C:\Documents and Settings\rick_2\Local Settings\Application Data\Microsoft\Outlook\archive.pst Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Documents and Settings\rick_2\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Qoobox\Quarantine\C\Program Files\Need2Find\bar\1.bin\N2PLUGIN.DLL.vir Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.l 1
C:\Qoobox\Quarantine\C\Program Files\Need2Find\bar\1.bin\NPND2FN.DLL.vir Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.o 1
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\DRIVERS\UACohktyagxue.sys.vir Infected: Rootkit.Win32.Agent.oxr 1
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\lsp.dll.vir Infected: Trojan-Proxy.Win32.Agent.bpi 1
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\UACiuhxppvbsn.dll.vir Infected: Packed.Win32.TDSS.y 1
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\UACneuaqneqmm.dll.vir Infected: Trojan.Win32.TDSS.amwo 1
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\UACpmooryyoui.dll.vir Infected: Packed.Win32.TDSS.y 1
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\UACtjewaedyuf.dll.vir Infected: Trojan.Win32.Tdss.anrc 1
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP1942\A0115010.sys Infected: Rootkit.Win32.Agent.oxr 1
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP1942\A0115011.dll Infected: Trojan.Win32.TDSS.amwo 1
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP1942\A0115012.dll Infected: Trojan.Win32.Tdss.anrc 1
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP1942\A0115013.dll Infected: Packed.Win32.TDSS.y 1
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP1942\A0115014.dll Infected: Packed.Win32.TDSS.y 1
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP1943\A0115037.exe Infected: Trojan-Downloader.Win32.Agent.chzm 1
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP1943\A0115038.dll Infected: Trojan.Win32.BHO.whc 1
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP1943\A0115046.dll Infected: Trojan-Proxy.Win32.Agent.bpi 1
E:\Outlook\Outlook backup.pst Suspicious: Trojan-Spy.HTML.Fraud.gen 1

Selected area has been scanned.
Hi, The items found by kaspersky are in your Outlook email. Unfortunately, it doesn't specify which email is suspicious, so you need to delete anything that appears suspicious, anything with an attachment or from someone you don't know. The reset of the items are in quarantine, which we will clean up shortly. Please post a fresh DDS and Attach.txt and advise how the computer is running now and if there are any outstanding issues.
I deleted quite a few emails in my Outlook. Computer is running pretty darn good right now. Here are my logs:


DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 12:18:27.04 on Wed 09/02/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.38 [GMT -5:00]

AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe
C:\Program Files\Linksys Wireless-G Print Server\PSDiagnosticM.exe
C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\Appinterfaces\HPDeviceService.exe
C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\AppInterfaces\HPDeviceHost.exe
C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
c:\PROGRA~1\mcafee\msc\mcupdui.exe
c:\program files\mcafee\virusscan\mcinsupd.exe
C:\Documents and Settings\rick_2\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.oscn.net/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\progra~1\mcafee\viruss~1\scriptsn.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: PopUpCop: {db43e4e6-ff8a-4018-8c8e-f68587a44a73} - c:\progra~1\popupcop\PopUpCop.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [StorageGuard] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [PCMService] "c:\program files\dell\media experience\PCMService.exe"
mRun: [USIUDF_Eject_Monitor] c:\program files\common files\ulead systems\dvd\USISrv.exe
mRun: [PSDiagnosticM] "c:\program files\linksys wireless-g print server\PSDiagnosticM.exe"
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [KnexStarter] c:\program files\common files\hewlett-packard\hp device communication services\appinterfaces\HPDeviceService.exe
mRun: [RunTasktray] "c:\program files\hewlett-packard\hp easy printer care\hpprun.exe" –regkeypath=software\hewlett-packard\hp easy printer care\HPPRun –valuename=InstallTTM
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Open Image in New Window - c:\progra~1\popupcop\popupcop.dll/imagenew
IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: microsoft.com\office
Trusted Zone: microsoft.com\officeupdate
Trusted Zone: hp.com
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,96/mcinsctl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: HPDCS - {ba135f49-a12c-4e26-a2c4-6ea945999072} - c:\program files\common files\hewlett-packard\hp device communication services\app\hpdcsapp.dll
Handler: hppfile - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - c:\program files\hewlett-packard\hp easy printer care\HPPCtrls.dll
Handler: hppsam - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - c:\program files\hewlett-packard\hp easy printer care\HPPCtrls.dll
Handler: hppzip - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - c:\program files\hewlett-packard\hp easy printer care\HPPCtrls.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: CShellExecuteHookImpl Object: {54d9498b-cf93-414f-8984-8ce7fde0d391} - c:\program files\ewido anti-malware\shellhook.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\rick_2\applic~1\mozilla\firefox\profiles\6ldr4f98.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.oscn.net
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npImgCtl.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R1 ewido security suite driver;ewido security suite driver;c:\program files\ewido anti-malware\guard.sys [2005-12-30 3072]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2006-12-29 214024]
R2 ewido security suite control;ewido security suite control;c:\program files\ewido anti-malware\ewidoctrl.exe [2005-11-30 13888]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2007-7-30 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2006-12-29 144704]
R3 lknuhst;Linksys Network USB Host Controller;c:\windows\system32\drivers\lknuhst.sys [2007-5-22 11136]
R3 LKNUHUB;Linksys Network USB Root Hub;c:\windows\system32\drivers\lknuhub.sys [2007-5-22 37248]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2006-12-29 79880]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2006-12-29 35272]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2006-12-29 34216]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2006-12-29 40552]
S4 ewido security suite guard;ewido security suite guard;c:\program files\ewido anti-malware\ewidoguard.exe [2005-12-18 151616]
S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2006-12-29 606736]

=============== Created Last 30 ================

2009-08-31 16:38 –d—– c:\windows\system32\dllcache\cache
2009-08-31 15:52 229,376 a——- c:\windows\PEV.exe
2009-08-28 12:16 –d-h— c:\windows\PIF
2009-08-27 18:40 –d—– C:\spoolerlogs
2009-08-11 22:56 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx
2009-08-11 22:55 655,872 ——– c:\windows\system32\dllcache\mstscax.dll
2009-08-05 04:11 204,800 ——– c:\windows\system32\dllcache\mswebdvd.dll

==================== Find3M ====================

2009-08-05 04:11 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-08-03 13:36 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 13:36 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-07-18 11:20 3,062,272 a——- c:\windows\system32\dllcache\mshtml.dll
2009-07-18 11:20 3,062,272 a——- c:\windows\system32\dllcache\cache\mshtml.dll
2009-07-18 11:20 1,506,304 a——- c:\windows\system32\dllcache\shdocvw.dll
2009-07-17 13:55 58,880 a——- c:\windows\system32\dllcache\atl.dll
2009-07-17 13:55 58,880 a——- c:\windows\system32\atl.dll
2009-07-13 23:43 10,841,088 a——- c:\windows\system32\dllcache\wmp.dll
2009-07-13 23:43 286,208 a——- c:\windows\system32\wmpdxm.dll
2009-07-13 23:43 286,208 a——- c:\windows\system32\dllcache\wmpdxm.dll
2009-07-10 08:42 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll
2009-06-25 13:36 661,504 a——- c:\windows\system32\mqqm.dll
2009-06-22 06:49 117,248 a——- c:\windows\system32\mqtgsvc.exe
2009-06-22 06:49 19,968 a——- c:\windows\system32\mqbkup.exe
2009-06-22 06:49 117,248 ——– c:\windows\system32\dllcache\mqtgsvc.exe
2009-06-22 06:49 19,968 ——– c:\windows\system32\dllcache\mqbkup.exe
2009-06-22 06:49 4,608 a——- c:\windows\system32\mqsvc.exe
2009-06-22 06:49 4,608 ——– c:\windows\system32\dllcache\mqsvc.exe
2009-06-22 06:48 91,776 ——– c:\windows\system32\dllcache\mqac.sys
2009-06-22 06:38 18,432 a——- c:\windows\system32\dllcache\iedw.exe
2009-06-16 09:55 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 09:55 82,432 a——- c:\windows\system32\fontsub.dll
2009-06-16 09:55 82,432 a——- c:\windows\system32\dllcache\fontsub.dll
2009-06-16 09:55 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-06-12 06:50 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 06:50 80,896 ——– c:\windows\system32\dllcache\tlntsess.exe
2009-06-12 06:50 76,288 a——- c:\windows\system32\telnet.exe
2009-06-12 06:50 76,288 ——– c:\windows\system32\dllcache\telnet.exe
2009-06-10 09:21 84,992 a——- c:\windows\system32\avifil32.dll
2009-06-10 09:21 84,992 ——– c:\windows\system32\dllcache\avifil32.dll
2009-06-10 01:32 132,096 a——- c:\windows\system32\wkssvc.dll
2009-06-10 01:32 132,096 ——– c:\windows\system32\dllcache\wkssvc.dll
2009-06-05 02:42 655,872 a——- c:\windows\system32\mstscax.dll
2007-01-08 15:32 92,064 a——- c:\documents and settings\rick_2\mqdmmdm.sys
2007-01-08 15:32 79,328 a——- c:\documents and settings\rick_2\mqdmserd.sys
2007-01-08 15:32 66,656 a——- c:\documents and settings\rick_2\mqdmbus.sys
2007-01-08 15:32 9,232 a——- c:\documents and settings\rick_2\mqdmmdfl.sys
2007-01-08 15:32 6,208 a——- c:\documents and settings\rick_2\mqdmcmnt.sys
2007-01-08 15:32 5,936 a——- c:\documents and settings\rick_2\mqdmwhnt.sys
2007-01-08 15:32 4,048 a——- c:\documents and settings\rick_2\mqdmcr.sys
2007-01-08 15:32 25,600 a——- c:\documents and settings\rick_2\usbsermptxp.sys
2007-01-08 15:32 22,768 a——- c:\documents and settings\rick_2\usbsermpt.sys

============= FINISH: 12:20:20.04 ===============



UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-07-30.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 12/10/2003 4:22:48 PM
System Uptime: 8/31/2009 5:49:29 PM (43 hours ago)

Motherboard: Dell Computer Corp. | | 0G1548
Processor: Intel® Pentium® 4 CPU 2.53GHz | Microprocessor | 2524/533mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 74 GiB total, 52.461 GiB free.
D: is CDROM ()
E: is NetworkDisk (NTFS) - 74 GiB total, 53.56 GiB free.
S: is NetworkDisk (NTFS) - 74 GiB total, 53.56 GiB free.

==== Disabled Device Manager Items =============

==== System Restore Points ===================


==== Installed Programs ======================

32 Bit HP CIO Components Installer
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Reader 7.0.9
Adobe Shockwave Player
Big Fish Games Client
BlueBeat.com
Broadcom Management Programs
Compatibility Pack for the 2007 Office system
Core Communication Components
Critical Update for Windows Media Player 11 (KB959772)
Dell Digital Jukebox Driver
Dell Media Experience
Dell Networking Guide
Dell Solution Center
DellSupport
Device Data Communication Components
DS21Patch
DVD Slideshow Builder 4.5.0.1
ERUNT 1.1j
ESPNMotion
Events Communication Components
ewido anti-malware
FLV Player 2.0 (build 25)
Google Earth
Google Toolbar for Internet Explorer
Google Updater
Help and Support Customization
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB909394)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
HP Easy Printer Care
HP Printer Settings Tools
HP Printer Usage Report
HP Proactive Services
HP Update
Intel® Extreme Graphics Driver
iolo technologies' System Mechanic
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2
Java™ 6 Update 13
Linksys Wireless-G Print Server
Malwarebytes' Anti-Malware
MathPlayer
McAfee SecurityCenter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft ActiveSync
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Money 2005
Microsoft Office Basic Edition 2003
Microsoft Outlook Personal Folders Backup
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Motorola Driver Installation 3.4.0
Mozilla Firefox (3.5.2)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6 Service Pack 2 (KB954459)
Musicmatch® Jukebox
Need2Find Bar
Operating System Communication Components
PopUpCop
PREMISE Forms Launcher
QuickTime
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Encoder (KB954156)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB947864)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
Spybot - Search & Destroy 1.4
Ulead Data-Add 2.0
Ulead DVD MovieFactory 4.0
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB973815)
Visionary Viewer
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage v1.3.0254.0
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Player 11
Windows Mobile® Device Handbook
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WorkgroupShare Client
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Toolbar

==== End Of File ===========================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI