This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] System infected background,popups, other bizzare behavior

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i'm running XP and ive been trying to deal with a slew of malware/adware/rougeware by myself and Im realizing that i'll need some professional help…

Ive used super anti spy ware, norton anti virus, malwarebytes, and still am experiencing to problems

Ive got this-(at one point my desktop picture was replaced by a plain turqouse color like this)
http://forums.whatthetech.com/Your_System_…nd_t108586.html

this- ( This is very, very strange! and scary)
http://www.google.com/search?hl=en&sou…mp;oq=&aqi=

Aswel as those lovely google 'work from home" popups. search engines will redirect SOMETIMES..

it seems like a malwarebytes scan will stop these problems for 4-5 hours and then it will all come back

I ran ATF cleaner and malwarebyes

now my background is almost back to normal, there's still a little of that turqosie color around the icons

I've read a good bit on this site and understand the risks involved with indepth cleaning- THANK YOU folks for voulenteering to help people on this site! I've got NO money to spend getting my computer repaired so you guys are truly doing me a huge favor

here's my last malwarebytes log…

Malwarebytes' Anti-Malware 1.41
Database version: 3270
Windows 5.1.2600 Service Pack 2

12/1/2009 7:42:19 PM
mbam-log-2009-12-01 (19-42-05).txt

Scan type: Quick Scan
Objects scanned: 124990
Time elapsed: 6 minute(s), 19 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 10
Folders Infected: 0
Files Infected: 6

Memory Processes Infected:
C:\WINDOWS\system32\winupdate86.exe (Trojan.Dropper) -> No action taken.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupdate86.exe (Trojan.Dropper) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\wallpaper (Hijack.Wallpaper) -> No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Dropper) -> Data: c:\windows\system32\winlogon86.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Dropper) -> Data: system32\winlogon86.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\winlogon86.exe) Good: (Userinit.exe) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\winupdate86.exe (Trojan.Dropper) -> No action taken.
C:\WINDOWS\system32\winlogon86.exe (Trojan.Dropper) -> No action taken.
C:\WINDOWS\system32\critical_warning.html (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\AVR10.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\winhelper86.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\41.exe (Trojan.FakeAlert) -> No action taken.
Please do the following:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
DDS——————–


DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 20:51:26.20 on Tue 12/01/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.297 [GMT -5:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Jesse\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [Easy SpyRemover] c:\program files\easy spyremover\EasySpyRemover.exe /smart
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [jazazanek] Rundll32.exe "c:\docume~1\alluse~1\applic~1\kunuzavi\kunuzavi.dll",a
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\docume~1\jesse\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
Trusted Zone: line6.net
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
AppInit_DLLs: pagudoru.dll c:\docume~1\alluse~1\applic~1\kunuzavi\kunuzavi.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: bokayoton - {39e30122-b9fa-4ac0-8eae-e244dc882845} - c:\docume~1\alluse~1\applic~1\lewokilo\lewokilo.dll
SSODL: wadomasuj - {9ee98ce3-5812-43bd-856e-1c37a243d4db} - c:\docume~1\alluse~1\applic~1\lewokilo\lewokilo.dll
SSODL: fesovoyob - {67db4455-b5fd-439f-b0bd-48090f5d32c5} - No File
SSODL: zinogikek - {ecba06cb-3cfa-40d8-b987-5c108013ade4} - c:\docume~1\alluse~1\applic~1\kunuzavi\kunuzavi.dll
STS: jugezatag: {39e30122-b9fa-4ac0-8eae-e244dc882845} - c:\docume~1\alluse~1\applic~1\lewokilo\lewokilo.dll
STS: tokatiluy: {9ee98ce3-5812-43bd-856e-1c37a243d4db} - c:\docume~1\alluse~1\applic~1\lewokilo\lewokilo.dll
STS: {67db4455-b5fd-439f-b0bd-48090f5d32c5} - No File
STS: gahurihor: {ecba06cb-3cfa-40d8-b987-5c108013ade4} - c:\docume~1\alluse~1\applic~1\kunuzavi\kunuzavi.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli pasakufe.dll

============= SERVICES / DRIVERS ===============

R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-11-11 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-11-11 74480]
R2 NAVAPEL;NAVAPEL;c:\program files\navnt\Navapel.sys [2001-10-29 9296]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-11-11 7408]
S2 Norton AntiVirus Server;Norton AntiVirus Client;c:\program files\navnt\rtvscan.exe [2001-10-29 466944]
S3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\drivers\l6tportgx.sys –> c:\windows\system32\drivers\L6TPortGX.sys [?]
S3 NAVAP;NAVAP;c:\program files\navnt\navap.sys [2001-10-29 178304]
S3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20091118.003\NAVENG.sys [2009-11-20 84912]
S3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20091118.003\NAVEX15.sys [2009-11-20 1323568]

=============== Created Last 30 ================

2009-11-30 21:15:35 0 d—–w- C:\VundoFix Backups
2009-11-30 01:10:16 0 —-a-w- c:\windows\system32\9961.exe
2009-11-30 00:50:16 0 —-a-w- c:\windows\system32\16827.exe
2009-11-30 00:30:16 0 —-a-w- c:\windows\system32\23281.exe
2009-11-30 00:10:16 0 —-a-w- c:\windows\system32\28145.exe
2009-11-29 23:50:16 0 —-a-w- c:\windows\system32\5705.exe
2009-11-29 23:30:16 0 —-a-w- c:\windows\system32\24464.exe
2009-11-29 23:10:16 0 —-a-w- c:\windows\system32\26962.exe
2009-11-29 22:50:16 0 —-a-w- c:\windows\system32\29358.exe
2009-11-29 22:30:15 0 —-a-w- c:\windows\system32\11478.exe
2009-11-29 22:10:15 0 —-a-w- c:\windows\system32\15724.exe
2009-11-29 21:50:15 0 —-a-w- c:\windows\system32\19169.exe
2009-11-29 21:30:15 0 —-a-w- c:\windows\system32\26500.exe
2009-11-29 21:10:15 0 —-a-w- c:\windows\system32\6334.exe
2009-11-29 20:50:15 0 —-a-w- c:\windows\system32\18467.exe
2009-11-29 19:48:45 1 —-a-w- C:\s
2009-11-28 22:54:02 0 d—–w- c:\windows\system32\wbem\Repository
2009-11-25 00:47:50 0 d—–w- c:\windows\Logs
2009-11-25 00:47:42 0 d—–w- c:\program files\Virtools
2009-11-14 22:13:16 0 d—–w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-11-14 22:12:51 0 d—–w- c:\program files\SUPERAntiSpyware
2009-11-14 22:12:51 0 d—–w- c:\docume~1\jesse\applic~1\SUPERAntiSpyware.com
2009-11-14 09:22:51 0 d—–w- c:\docume~1\alluse~1\applic~1\kunuzavi
2009-11-14 09:22:51 0 d—–w- c:\docume~1\alluse~1\applic~1\hajiruno
2009-11-13 16:12:21 0 d—–w- c:\program files\common files\Wise Installation Wizard
2009-11-12 21:22:27 0 d—–w- c:\docume~1\alluse~1\applic~1\kafimehe
2009-11-12 21:22:26 0 d—–w- c:\docume~1\alluse~1\applic~1\neganosu
2009-11-12 21:22:26 0 d—–w- c:\docume~1\alluse~1\applic~1\jimarofi
2009-11-12 07:08:21 0 d—–w- c:\docume~1\alluse~1\applic~1\lewokilo
2009-11-12 07:08:21 0 d—–w- c:\docume~1\alluse~1\applic~1\lekapuvo
2009-11-12 07:08:21 0 d—–w- c:\docume~1\alluse~1\applic~1\kebavage
2009-11-12 07:08:21 0 d—–w- c:\docume~1\alluse~1\applic~1\hiyivonu
2009-11-11 19:08:02 0 d—–w- c:\docume~1\alluse~1\applic~1\venuheno
2009-11-11 19:08:02 0 d—–w- c:\docume~1\alluse~1\applic~1\jetivobu
2009-11-11 07:07:37 0 d—–w- c:\docume~1\alluse~1\applic~1\wihizada
2009-11-11 07:07:36 0 d—–w- c:\docume~1\alluse~1\applic~1\sagodomo
2009-11-10 19:07:12 0 d—–w- c:\docume~1\alluse~1\applic~1\wujuleza
2009-11-10 19:07:12 0 d—–w- c:\docume~1\alluse~1\applic~1\gofazato
2009-11-06 23:21:07 0 d—–w- C:\.jagex_cache_32
2009-11-06 23:16:00 63 —-a-w- c:\documents and settings\jesse\jagex_runescape_preferences2.dat

==================== Find3M ====================

2009-11-29 02:12:16 95360 —-a-w- c:\windows\system32\drivers\atapi.sys
2009-11-28 20:44:15 38 —-a-w- c:\documents and settings\jesse\jagex_runescape_preferences.dat
2009-08-06 23:54:48 3 –sha-w- c:\windows\system32\bepiyubu.dll
2009-08-07 12:45:13 3 –sha-w- c:\windows\system32\hamifela.dll
2009-08-06 23:54:48 3 –sha-w- c:\windows\system32\hiziwuja.dll
2009-08-07 12:22:40 3 –sha-w- c:\windows\system32\lunoboza.dll
2009-08-07 12:45:13 3 –sha-w- c:\windows\system32\mofinaze.dll
2009-08-07 12:00:08 3 –sha-w- c:\windows\system32\nufuyeyo.dll
2009-08-07 13:07:52 3 –sha-w- c:\windows\system32\rasulodu.dll
2009-08-06 11:50:29 3 –sha-w- c:\windows\system32\suhadovo.dll
2009-08-07 12:00:08 3 –sha-w- c:\windows\system32\vefizife.dll
2009-08-07 12:22:40 3 –sha-w- c:\windows\system32\vohesetu.dll
2009-08-07 13:07:52 3 –sha-w- c:\windows\system32\wapifoko.dll
2009-08-06 11:50:27 3 –sha-w- c:\windows\system32\womifaso.dll

============= FINISH: 20:53:25.65 ===============


ATTACH—————


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 3/15/2007 6:31:14 AM
System Uptime: 12/1/2009 7:43:22 PM (1 hours ago)

Motherboard: Dell Computer Corp. | | 00T606
Processor: Intel® Celeron® CPU 1.80GHz | Microprocessor | 1800/400mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 149 GiB total, 133.967 GiB free.
D: is CDROM ()
E: is CDROM (CDFS)

==== Disabled Device Manager Items =============

Class GUID:
Description: Dell USB Smartcard Keyboard
Device ID: USB\VID_413C&PID_2100&MI_01\6&158DEE56&0&0001
Manufacturer:
Name: Dell USB Smartcard Keyboard
PNP Device ID: USB\VID_413C&PID_2100&MI_01\6&158DEE56&0&0001
Service:

==== System Restore Points ===================

RP574: 9/2/2009 11:48:22 PM - System Checkpoint
RP575: 9/4/2009 12:08:15 AM - System Checkpoint
RP576: 9/5/2009 12:28:19 AM - System Checkpoint
RP577: 9/6/2009 1:28:17 AM - System Checkpoint
RP578: 9/7/2009 11:14:02 AM - System Checkpoint
RP579: 9/8/2009 11:28:19 AM - System Checkpoint
RP580: 9/9/2009 12:28:17 PM - System Checkpoint
RP581: 9/10/2009 1:28:17 PM - System Checkpoint
RP582: 9/11/2009 2:28:18 PM - System Checkpoint
RP583: 9/18/2009 4:48:19 PM - System Checkpoint
RP584: 9/19/2009 5:24:21 PM - System Checkpoint
RP585: 9/20/2009 5:25:23 PM - System Checkpoint
RP586: 9/21/2009 6:24:19 PM - System Checkpoint
RP587: 9/22/2009 7:58:49 PM - System Checkpoint
RP588: 9/23/2009 8:24:21 PM - System Checkpoint
RP589: 9/24/2009 9:36:23 PM - System Checkpoint
RP590: 9/25/2009 10:37:06 PM - System Checkpoint
RP591: 9/26/2009 11:24:05 PM - System Checkpoint
RP592: 9/28/2009 12:28:45 PM - System Checkpoint
RP593: 9/29/2009 12:31:43 PM - System Checkpoint
RP594: 9/30/2009 1:19:41 PM - System Checkpoint
RP595: 10/1/2009 2:19:41 PM - System Checkpoint
RP596: 10/2/2009 2:36:41 PM - System Checkpoint
RP597: 10/3/2009 3:27:35 PM - System Checkpoint
RP598: 10/4/2009 6:44:41 PM - System Checkpoint
RP599: 10/5/2009 8:18:31 PM - System Checkpoint
RP600: 10/6/2009 8:25:48 PM - System Checkpoint
RP601: 10/7/2009 9:25:46 PM - System Checkpoint
RP602: 10/8/2009 9:26:51 PM - System Checkpoint
RP603: 10/9/2009 10:25:47 PM - System Checkpoint
RP604: 10/10/2009 11:25:46 PM - System Checkpoint
RP605: 10/12/2009 12:27:49 AM - System Checkpoint
RP606: 10/13/2009 1:25:30 AM - System Checkpoint
RP607: 10/14/2009 2:25:30 AM - System Checkpoint
RP608: 10/15/2009 3:25:35 AM - System Checkpoint
RP609: 10/16/2009 4:25:32 AM - System Checkpoint
RP610: 10/17/2009 4:45:59 AM - System Checkpoint
RP611: 10/18/2009 5:46:03 AM - System Checkpoint
RP612: 10/19/2009 5:47:07 AM - System Checkpoint
RP613: 10/20/2009 12:01:17 AM - Installed Connect Service
RP614: 10/21/2009 12:44:59 AM - System Checkpoint
RP615: 10/22/2009 1:45:00 AM - System Checkpoint
RP616: 10/23/2009 9:29:30 AM - System Checkpoint
RP617: 10/24/2009 9:43:42 AM - System Checkpoint
RP618: 10/25/2009 8:51:31 AM - System Checkpoint
RP619: 10/26/2009 10:45:39 AM - System Checkpoint
RP620: 10/27/2009 1:12:40 PM - System Checkpoint
RP621: 10/28/2009 1:49:59 PM - System Checkpoint
RP622: 10/29/2009 1:59:30 PM - System Checkpoint
RP623: 10/30/2009 4:25:33 PM - System Checkpoint
RP624: 10/31/2009 5:02:01 PM - System Checkpoint
RP625: 11/1/2009 2:20:30 PM - Removed Apple Mobile Device Support
RP626: 11/2/2009 2:49:19 PM - System Checkpoint
RP627: 11/3/2009 3:49:20 PM - System Checkpoint
RP628: 11/4/2009 4:49:21 PM - System Checkpoint
RP629: 11/5/2009 5:49:20 PM - System Checkpoint
RP630: 11/6/2009 5:50:30 PM - System Checkpoint
RP631: 11/7/2009 6:09:24 PM - System Checkpoint
RP632: 11/8/2009 6:56:28 PM - System Checkpoint
RP633: 11/9/2009 9:16:19 PM - System Checkpoint
RP634: 11/10/2009 9:34:31 PM - System Checkpoint
RP635: 11/11/2009 10:28:35 PM - System Checkpoint
RP636: 11/12/2009 9:21:26 PM - Restore Operation
RP637: 11/12/2009 9:30:19 PM - Restore Operation
RP638: 11/12/2009 9:36:37 PM - Restore Operation
RP639: 11/12/2009 10:11:14 PM - Restore Operation
RP640: 11/13/2009 11:17:19 AM - Restore Operation
RP641: 11/14/2009 11:37:55 AM - System Checkpoint
RP642: 11/14/2009 5:12:48 PM - Installed SUPERAntiSpyware Free Edition
RP643: 11/15/2009 5:34:30 PM - System Checkpoint
RP644: 11/16/2009 7:36:51 PM - System Checkpoint
RP645: 11/17/2009 8:15:37 PM - System Checkpoint
RP646: 11/18/2009 9:28:09 PM - System Checkpoint
RP647: 11/19/2009 9:33:36 PM - System Checkpoint
RP648: 11/20/2009 10:21:17 PM - System Checkpoint
RP649: 11/21/2009 10:47:08 PM - System Checkpoint
RP650: 11/22/2009 11:47:07 PM - System Checkpoint
RP651: 11/23/2009 11:59:02 PM - System Checkpoint
RP652: 11/24/2009 7:47:40 PM - Installed 3DVIA player 5.0
RP653: 11/27/2009 3:12:17 PM - System Checkpoint
RP654: 11/28/2009 3:27:23 PM - System Checkpoint
RP655: 11/28/2009 5:40:04 PM - Restore Operation
RP656: 11/28/2009 5:50:35 PM - Restore Operation
RP657: 11/28/2009 5:52:56 PM - Restore Operation
RP658: 11/29/2009 6:11:56 PM - System Checkpoint
RP659: 11/30/2009 6:41:53 PM - System Checkpoint
RP660: 12/1/2009 8:24:27 PM - System Checkpoint

==== Installed Programs ======================

32 Bit HP CIO Components Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0.5
Adobe Shockwave Player
Apple Mobile Device Support
Apple Software Update
ArcSoft Print Creations
ArcSoft Print Creations - Album Page
ArcSoft Print Creations - Funhouse
ArcSoft Print Creations - Greeting Card
ArcSoft Print Creations - Photo Book
ArcSoft Print Creations - Photo Calendar
ArcSoft Print Creations - Scrapbook
ArcSoft Print Creations - Slimline Card
AT&T Internet Security Wizard 1.5.11
BellSouth Application Management
BufferChm
C4400
C4400_Help
Cards_Calendar_OrderGift_DoMorePlugout
CCleaner (remove only)
CCScore
Copy
CustomerResearchQFolder
Destination Component
DeviceDiscovery
DeviceManagementQFolder
Easy SpyRemover 4.5
ERUNT 1.1j
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSPDock
ESSTOOLS
essvatgt
eSupportQFolder
FastAccess® DSL Help Center 4.1
fflink
GPBaseService
HijackThis 2.0.2
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB932716-v2)
Hotfix for Windows XP (KB945060-v3)
HP Imaging Device Functions 11.0
HP Photosmart Essential 2.5
HP Smart Web Printing
HP Update
HPPhotoSmartPhotobookWebPack1
HPProductAssistant
Intel® Extreme Graphics Driver
Intel® PRO Network Adapters and Drivers
iTunes
J2SE Runtime Environment 5.0 Update 10
Java™ 6 Update 5
kgcbaby
kgchday
kgchlwn
kgcinvt
kgckids
kgcmove
kgcvday
Kodak EasyShare software
LiveUpdate 2.6 (Symantec Corporation)
Macromedia Flash 8 Video Encoder
Malwarebytes' Anti-Malware
MarketResearch
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft User-Mode Driver Framework Feature Pack 1.0
netbrdg
Norton AntiVirus Corporate Edition
OfotoXMI
PanoStandAlone
PS_AIO_03_C4400_ProductContext
PS_AIO_03_C4400_Software
PS_AIO_03_C4400_Software_Min
PSSWCORE
QuickTime
Scan
SFR
SHASTA
skin0001
SKINXSDK
SmartWebPrinting
SolutionCenter
SoulSeek Client 156c
SoundMAX
staticcr
Status
SUPERAntiSpyware Free Edition
Toolbox
TrayApp
UnloadSupport
VideoToolkit01
VPRINTOL
WebFldrs XP
WebReg
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
WIRELESS

==== Event Viewer Messages From Past Week ========

12/1/2009 8:20:57 AM, error: Service Control Manager [7034] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s).
12/1/2009 8:20:57 AM, error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
11/29/2009 3:41:23 PM, error: TermService [1036] - Terminal Server session creation failed. The relevant status code was 0xC0000037.
11/28/2009 6:33:11 PM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery Service service hung on starting.
11/28/2009 6:31:51 PM, error: Service Control Manager [7023] - The Norton AntiVirus Client service terminated with the following error: The environment is incorrect.
11/28/2009 6:31:33 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
11/28/2009 6:31:33 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.
11/28/2009 5:51:45 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
11/28/2009 5:51:45 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
11/25/2009 1:26:54 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

==== End Of File ===========================


GMER—–

GMER 1.0.15.15252 - http://www.gmer.net
Rootkit scan 2009-12-01 21:49:52
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\Jesse\LOCALS~1\Temp\pwadaaod.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xEFDB60B0]

—- Devices - GMER 1.0.15 —-

Device -> \Driver\atapi \Device\Harddisk0\DR0 82341618

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:

Download Combofix from either of the links below. You must rename it to vashmere.exe before saving it.
Save it to your desktop. Change the save as file type to "all files"

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2

———————————————————–


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.

    ———————————————————–

  • Double click on the renamed ComboFix.exe & follow the prompts. When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

———————————————————–

ComboFix 09-12-02.05 - Jesse 12/02/2009 16:11.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.350 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Cleanup Utilities\vashmere.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Jesse\My Documents\explorer.exe
c:\windows\system32\11478.exe
c:\windows\system32\15724.exe
c:\windows\system32\16827.exe
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\23281.exe
c:\windows\system32\24464.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\28145.exe
c:\windows\system32\29358.exe
c:\windows\system32\5705.exe
c:\windows\system32\6334.exe
c:\windows\system32\9961.exe
c:\windows\Tasks\ujoxgcoy.job

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :P
c:\windows\system32\proquota.exe . . . is missing!!

.
((((((((((((((((((((((((( Files Created from 2009-11-02 to 2009-12-02 )))))))))))))))))))))))))))))))
.

2009-11-30 21:15 . 2009-11-30 21:15 ——– d—–w- C:\VundoFix Backups
2009-11-28 22:54 . 2009-11-28 22:54 ——– d—–w- c:\windows\system32\wbem\Repository
2009-11-25 00:47 . 2009-11-25 00:47 ——– d—–w- c:\windows\Logs
2009-11-25 00:47 . 2009-11-25 00:47 ——– d—–w- c:\program files\Virtools
2009-11-14 22:13 . 2009-11-14 22:13 117760 —-a-w- c:\documents and settings\Jesse\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-11-14 22:13 . 2009-11-14 22:13 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-11-14 22:12 . 2009-11-14 22:12 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-11-14 22:12 . 2009-11-14 22:12 ——– d—–w- c:\documents and settings\Jesse\Application Data\SUPERAntiSpyware.com
2009-11-14 09:22 . 2009-11-14 18:29 ——– d—–w- c:\documents and settings\All Users\Application Data\hajiruno
2009-11-14 09:22 . 2009-11-14 16:43 ——– d—–w- c:\documents and settings\All Users\Application Data\kunuzavi
2009-11-13 16:12 . 2009-11-13 16:12 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-11-12 21:22 . 2009-11-28 23:30 ——– d—–w- c:\documents and settings\All Users\Application Data\kafimehe
2009-11-12 21:22 . 2009-11-14 18:29 ——– d—–w- c:\documents and settings\All Users\Application Data\jimarofi
2009-11-12 21:22 . 2009-11-13 16:12 ——– d—–w- c:\documents and settings\All Users\Application Data\neganosu
2009-11-12 15:16 . 2009-11-14 04:10 ——– d—–w- c:\documents and settings\Guest\Application Data\HPAppData
2009-11-12 07:08 . 2009-11-14 18:29 ——– d—–w- c:\documents and settings\All Users\Application Data\lekapuvo
2009-11-12 07:08 . 2009-11-14 18:29 ——– d—–w- c:\documents and settings\All Users\Application Data\kebavage
2009-11-12 07:08 . 2009-11-14 18:29 ——– d—–w- c:\documents and settings\All Users\Application Data\hiyivonu
2009-11-12 07:08 . 2009-11-13 16:12 ——– d—–w- c:\documents and settings\All Users\Application Data\lewokilo
2009-11-11 19:08 . 2009-11-14 18:29 ——– d—–w- c:\documents and settings\All Users\Application Data\venuheno
2009-11-11 19:08 . 2009-11-14 18:29 ——– d—–w- c:\documents and settings\All Users\Application Data\jetivobu
2009-11-11 07:07 . 2009-11-14 18:29 ——– d—–w- c:\documents and settings\All Users\Application Data\wihizada
2009-11-11 07:07 . 2009-11-14 18:29 ——– d—–w- c:\documents and settings\All Users\Application Data\sagodomo
2009-11-10 19:07 . 2009-11-14 18:29 ——– d—–w- c:\documents and settings\All Users\Application Data\wujuleza
2009-11-10 19:07 . 2009-11-14 18:29 ——– d—–w- c:\documents and settings\All Users\Application Data\gofazato
2009-11-09 20:57 . 2009-11-09 20:57 ——– d—–w- c:\documents and settings\Guest\Local Settings\Application Data\Adobe
2009-11-07 19:11 . 2009-11-07 21:27 ——– d—–w- c:\documents and settings\Guest\Local Settings\Application Data\Google
2009-11-07 19:10 . 2009-11-07 19:10 ——– d—–w- c:\documents and settings\Guest\Application Data\Skinux
2009-11-07 14:42 . 2009-11-07 19:04 0 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\APTemp\AP0.dll
2009-11-06 23:21 . 2009-11-06 23:21 ——– d—–w- C:\.jagex_cache_32
2009-11-06 23:16 . 2009-11-28 20:48 63 —-a-w- c:\documents and settings\Jesse\jagex_runescape_preferences2.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-02 21:23 . 2009-08-22 18:20 720 —-a-w- c:\documents and settings\All Users\Application Data\ArcSoft\kodak-printcreations-22-080812-oem\acforall.dll
2009-12-02 20:43 . 2009-04-14 19:03 ——– d—–w- c:\documents and settings\Jesse\Application Data\HPAppData
2009-12-02 03:41 . 2004-08-12 13:17 95360 —-a-w- c:\windows\system32\drivers\atapi.sys
2009-11-30 20:56 . 2008-02-22 22:19 ——– d—–w- c:\program files\Google
2009-11-30 20:56 . 2007-03-15 12:43 ——– d—–w- c:\program files\LimeWire
2009-11-28 23:03 . 2009-07-13 14:44 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-11-28 20:44 . 2008-08-13 04:35 38 —-a-w- c:\documents and settings\Jesse\jagex_runescape_preferences.dat
2009-10-20 23:45 . 2009-04-14 18:56 ——– d—–w- c:\documents and settings\Jesse\Application Data\HP
2009-10-20 23:45 . 2009-04-14 18:35 ——– d—–w- c:\documents and settings\All Users\Application Data\HP
2009-10-20 04:01 . 2007-03-15 11:44 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-09-10 19:54 . 2009-07-13 14:44 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 19:53 . 2009-07-13 14:44 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-06 23:54 . 2009-08-06 23:54 3 –sha-w- c:\windows\system32\bepiyubu.dll
2009-08-07 12:45 . 2009-08-07 12:45 3 –sha-w- c:\windows\system32\hamifela.dll
2009-08-06 23:54 . 2009-08-06 23:54 3 –sha-w- c:\windows\system32\hiziwuja.dll
2009-08-07 12:22 . 2009-08-07 12:22 3 –sha-w- c:\windows\system32\lunoboza.dll
2009-08-07 12:45 . 2009-08-07 12:45 3 –sha-w- c:\windows\system32\mofinaze.dll
2009-08-07 12:00 . 2009-08-07 12:00 3 –sha-w- c:\windows\system32\nufuyeyo.dll
2009-08-07 13:07 . 2009-08-07 13:07 3 –sha-w- c:\windows\system32\rasulodu.dll
2009-08-06 11:50 . 2009-08-06 11:50 3 –sha-w- c:\windows\system32\suhadovo.dll
2009-08-07 12:00 . 2009-08-07 12:00 3 –sha-w- c:\windows\system32\vefizife.dll
2009-08-07 12:22 . 2009-08-07 12:22 3 –sha-w- c:\windows\system32\vohesetu.dll
2009-08-07 13:07 . 2009-08-07 13:07 3 –sha-w- c:\windows\system32\wapifoko.dll
2009-08-06 11:50 . 2009-08-06 11:50 3 –sha-w- c:\windows\system32\womifaso.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-07-28_16.10.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-12-02 04:08 . 2006-12-02 04:08 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2006-12-02 04:26 . 2006-12-02 04:26 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
+ 2006-12-02 04:25 . 2006-12-02 04:25 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
+ 2006-12-02 02:56 . 2006-12-02 02:56 96256 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll
+ 2006-09-28 22:56 . 2006-09-28 22:56 55808 c:\windows\system32\WudfSvc.dll
+ 2006-09-29 00:13 . 2006-09-29 00:13 95344 c:\windows\system32\WUDFCoinstaller.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 38400 c:\windows\system32\wpdshextres.dll
+ 2006-10-19 00:00 . 2006-10-19 00:00 17408 c:\windows\system32\wpdshextautoplay.exe
+ 2006-10-19 01:47 . 2006-10-19 01:47 63488 c:\windows\system32\wpdmtpus.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 35840 c:\windows\system32\wpdconns.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 99840 c:\windows\system32\wmpshell.dll
+ 2004-08-12 13:33 . 2006-10-19 01:47 37376 c:\windows\system32\wmdmps.dll
+ 2004-08-12 13:33 . 2006-10-19 01:47 33792 c:\windows\system32\wmdmlog.dll
+ 2007-03-15 12:31 . 2006-10-16 20:10 23856 c:\windows\system32\spupdsvc.exe
+ 2009-07-30 04:07 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
+ 2007-02-08 05:40 . 2007-02-08 05:40 64512 c:\windows\system32\ptpitcp.dll
+ 2004-08-12 13:26 . 2009-10-25 17:55 62344 c:\windows\system32\perfc009.dat
+ 2004-08-12 13:23 . 2006-10-19 01:47 27136 c:\windows\system32\mspmsnsv.dll
+ 2004-08-12 13:23 . 2005-05-03 16:58 15360 c:\windows\system32\msisip.dll
+ 2004-08-12 13:23 . 2005-05-03 16:58 78848 c:\windows\system32\msiexec.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 74240 c:\windows\system32\mscories.dll
+ 2009-08-08 03:14 . 2009-08-08 03:14 85173 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2008-02-22 21:55 . 2009-08-06 00:01 88589 c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2004-08-12 13:21 . 2006-10-19 01:47 11264 c:\windows\system32\LAPRXY.dll
+ 2009-11-01 19:19 . 2009-08-29 00:42 40448 c:\windows\system32\DRVSTORE\usbaapl_6DA28B91FF48C57089E4D2436654AFA4ECAD0622\usbaapl.sys
+ 2009-11-01 19:19 . 2009-08-29 00:42 17408 c:\windows\system32\DRVSTORE\netaapl_F433E854B3FF3BEE74986FDE8E16A64162342BFF\netaapl.sys
+ 2009-08-22 18:17 . 2007-06-06 13:25 40960 c:\windows\system32\DRVSTORE\kpd_116B8E56BDDDF953EAB6D8D8F5CDA37DE77C0E1A\KPDLM.dll
+ 2009-08-22 18:17 . 2007-06-06 13:36 28672 c:\windows\system32\DRVSTORE\kpd_116B8E56BDDDF953EAB6D8D8F5CDA37DE77C0E1A\KPDGPD.dll
+ 2009-08-22 18:17 . 2007-06-06 13:18 45056 c:\windows\system32\DRVSTORE\kpd_116B8E56BDDDF953EAB6D8D8F5CDA37DE77C0E1A\KPDDynCC.DLL
+ 2006-09-28 23:00 . 2006-09-28 23:00 82944 c:\windows\system32\drivers\WudfRd.sys
+ 2006-09-28 22:55 . 2006-09-28 22:55 77568 c:\windows\system32\drivers\WudfPf.sys
+ 2006-10-19 00:00 . 2006-10-19 00:00 38528 c:\windows\system32\drivers\wpdusb.sys
+ 2008-08-12 03:49 . 2009-08-29 00:42 40448 c:\windows\system32\drivers\usbaapl.sys
+ 2004-08-12 13:17 . 2008-05-02 09:05 62592 c:\windows\system32\drivers\cdrom.sys
+ 2004-08-12 13:34 . 2006-10-19 01:47 99840 c:\windows\system32\dllcache\wmpshell.dll
+ 2007-03-15 11:26 . 2006-10-19 01:46 64000 c:\windows\system32\dllcache\wmplayer.exe
+ 2007-03-15 11:26 . 2006-10-19 01:47 96256 c:\windows\system32\dllcache\wmpband.dll
+ 2004-08-12 13:33 . 2006-10-19 01:47 37376 c:\windows\system32\dllcache\wmdmps.dll
+ 2004-08-12 13:33 . 2006-10-19 01:47 33792 c:\windows\system32\dllcache\wmdmlog.dll
+ 2004-08-12 13:23 . 2006-10-19 01:47 27136 c:\windows\system32\dllcache\mspmsnsv.dll
+ 2004-08-12 13:23 . 2005-05-03 16:58 15360 c:\windows\system32\dllcache\msisip.dll
+ 2004-08-12 13:23 . 2005-05-03 16:58 78848 c:\windows\system32\dllcache\msiexec.exe
+ 2004-08-12 13:21 . 2006-10-19 01:47 11264 c:\windows\system32\dllcache\LAPRXY.dll
+ 2009-08-22 18:05 . 2008-05-02 09:05 62592 c:\windows\system32\dllcache\cdrom.sys
+ 2009-07-28 16:13 . 2004-08-12 13:34 82944 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-07-28 16:13 . 2004-08-12 13:31 24576 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-07-28 16:13 . 2004-08-12 13:30 14336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-07-28 16:13 . 2004-08-12 13:29 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-07-28 16:13 . 2004-08-12 13:26 89088 c:\windows\system32\dllcache\cache\rasauto.dll
+ 2009-07-28 16:13 . 2004-08-12 13:26 17408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-07-28 16:13 . 2004-08-12 13:23 33792 c:\windows\system32\dllcache\cache\msgsvc.dll
+ 2009-07-28 16:13 . 2004-08-12 13:21 13312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-07-28 16:13 . 2004-08-12 13:21 22016 c:\windows\system32\dllcache\cache\lpk.dll
+ 2009-07-28 16:13 . 2004-08-12 13:20 24576 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-07-28 16:13 . 2004-08-12 13:20 29056 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-07-28 16:13 . 2004-08-12 13:18 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
+ 2009-07-28 16:13 . 2004-08-12 13:17 11648 c:\windows\system32\dllcache\cache\acpiec.sys
- 2004-08-12 13:17 . 2004-08-04 04:59 95360 c:\windows\system32\dllcache\atapi.sys
+ 2004-08-12 13:17 . 2009-12-02 03:41 95360 c:\windows\system32\dllcache\atapi.sys
+ 2005-09-23 11:28 . 2005-09-23 11:28 83456 c:\windows\system32\dfshim.dll
+ 2008-12-31 07:22 . 2009-12-02 00:43 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-31 07:22 . 2009-01-02 01:24 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-31 07:22 . 2009-12-02 00:43 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-12-31 07:22 . 2009-01-02 01:24 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-31 07:22 . 2009-12-02 00:43 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-31 07:22 . 2009-01-02 01:24 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2005-09-23 11:28 . 2005-09-23 11:28 28160 c:\windows\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 71680 c:\windows\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL
+ 2005-09-23 11:28 . 2005-09-23 11:28 86016 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 47616 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 85504 c:\windows\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 59072 c:\windows\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 53248 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 78336 c:\windows\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 14848 c:\windows\Microsoft.NET\Framework\v2.0.50727\normalization.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 96440 c:\windows\Microsoft.NET\Framework\v2.0.50727\ngen.exe
+ 2005-09-23 11:29 . 2005-09-23 11:29 22528 c:\windows\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 10240 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscortim.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 66240 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 67072 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 81408 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorld.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorie.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 73216 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 87552 c:\windows\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 12800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 73728 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
+ 2005-09-23 10:36 . 2005-09-23 10:36 85504 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.3082.dll
+ 2005-09-23 10:29 . 2005-09-23 10:29 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.3076.dll
+ 2005-09-23 10:47 . 2005-09-23 10:47 84480 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.2070.dll
+ 2005-09-23 10:30 . 2005-09-23 10:30 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.2052.dll
+ 2005-09-23 10:47 . 2005-09-23 10:47 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1055.dll
+ 2005-09-23 10:47 . 2005-09-23 10:47 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1053.dll
+ 2005-09-23 10:47 . 2005-09-23 10:47 82432 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1049.dll
+ 2005-09-23 10:47 . 2005-09-23 10:47 82432 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1046.dll
+ 2005-09-23 10:46 . 2005-09-23 10:46 83456 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1045.dll
+ 2005-09-23 10:46 . 2005-09-23 10:46 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1044.dll
+ 2005-09-23 10:46 . 2005-09-23 10:46 83456 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1043.dll
+ 2005-09-23 10:44 . 2005-09-23 10:44 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1042.dll
+ 2005-09-23 10:42 . 2005-09-23 10:42 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1041.dll
+ 2005-09-23 10:40 . 2005-09-23 10:40 84480 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1040.dll
+ 2005-09-23 10:40 . 2005-09-23 10:40 83968 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1038.dll
+ 2005-09-23 10:40 . 2005-09-23 10:40 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1037.dll
+ 2005-09-23 10:38 . 2005-09-23 10:38 86016 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1036.dll
+ 2005-09-23 10:38 . 2005-09-23 10:38 81408 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1035.dll
+ 2005-09-23 07:46 . 2005-09-23 07:46 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1033.dll
+ 2005-09-23 10:36 . 2005-09-23 10:36 87552 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1032.dll
+ 2005-09-23 10:34 . 2005-09-23 10:34 85504 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1031.dll
+ 2005-09-23 10:34 . 2005-09-23 10:34 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1030.dll
+ 2005-09-23 10:34 . 2005-09-23 10:34 82944 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1029.dll
+ 2005-09-23 10:32 . 2005-09-23 10:32 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1028.dll
+ 2005-09-23 10:29 . 2005-09-23 10:29 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1025.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 40960 c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 72192 c:\windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 55296 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEHost.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 52736 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfdll.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 31936 c:\windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 68608 c:\windows\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 17920 c:\windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 13312 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 76984 c:\windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 88576 c:\windows\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 29888 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 29896 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 26824 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 13824 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 70656 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 23552 c:\windows\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 10752 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 55488 c:\windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 87552 c:\windows\Microsoft.NET\Framework\v2.0.50727\alink.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 10752 c:\windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 18944 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 86528 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 72704 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
+ 2009-08-22 18:17 . 2009-08-22 18:17 45056 c:\windows\Installer\{FCDB1C92-03C6-4C76-8625-371224256091}\PdockShortcut4.exe
+ 2009-11-14 22:13 . 2009-11-14 22:13 65024 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2009-11-14 22:13 . 2009-11-14 22:13 18944 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2009-08-22 18:13 . 2009-08-22 18:13 92854 c:\windows\Installer\{42938595-0D83-404D-9F73-F8177FDD531A}\EasyShareStartupShortcut10.exe
+ 2009-08-22 18:13 . 2009-08-22 18:13 92854 c:\windows\Installer\{42938595-0D83-404D-9F73-F8177FDD531A}\EasyShareStartMenu10_1.exe
+ 2009-08-22 18:13 . 2009-08-22 18:13 92854 c:\windows\Installer\{42938595-0D83-404D-9F73-F8177FDD531A}\EasyShareDesktopShortcut10.exe
+ 2009-08-22 18:05 . 2008-05-02 09:05 62592 c:\windows\Driver Cache\i386\cdrom.sys
+ 2009-08-22 18:17 . 2009-08-22 18:17 81920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\28d0a69814bb464e8067568b1079c461\Microsoft.Build.Framework.ni.dll
+ 2009-08-22 18:16 . 2009-08-22 18:16 15360 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\a94dc25ab434eb418cf969ff3093b975\dfsvc.ni.exe
+ 2009-08-22 18:15 . 2009-08-22 18:15 26624 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\cb78e50be0de334ea94d67ec7546dde2\Accessibility.ni.dll
+ 2009-08-22 18:13 . 2009-08-22 18:13 86016 c:\windows\assembly\GAC_MSIL\VirtualCollectionBase-Defs-PlatReq\1.0.5227.4054__b0cfd8589c27b05f\VirtualCollectionBase-Defs-PlatReq.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 86016 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 73728 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 36864 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2009-08-22 18:13 . 2009-08-22 18:13 38400 c:\windows\assembly\GAC_32\PeopleRecognition-Defs-PlatReq\1.1.5227.4054__b0cfd8589c27b05f\PeopleRecognition-Defs-PlatReq.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 68608 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2009-07-30 04:07 . 2006-10-04 14:05 39424 c:\windows\AppPatch\acadproc.dll
- 2009-06-01 21:34 . 2009-07-28 02:52 49152 c:\windows\.jagex_cache_32\runescape\jagmisc.dll
+ 2009-06-01 21:34 . 2009-11-07 13:23 49152 c:\windows\.jagex_cache_32\runescape\jagmisc.dll
- 2009-06-01 21:34 . 2009-07-28 02:52 81920 c:\windows\.jagex_cache_32\runescape\jaggl.dll
+ 2009-06-01 21:34 . 2009-11-07 13:34 81920 c:\windows\.jagex_cache_32\runescape\jaggl.dll
+ 2009-07-30 04:03 . 2006-09-28 23:01 58368 c:\windows\$NtUninstallWudf01000$\spuninst\WudfCustom.dll
+ 2009-07-30 04:06 . 2004-08-12 13:34 73728 c:\windows\$NtUninstallwmp11$\wmplayer.exe
+ 2009-07-30 04:06 . 2004-08-12 13:34 98304 c:\windows\$NtUninstallwmp11$\wmpband.dll
+ 2009-07-30 04:04 . 2004-08-12 13:33 23552 c:\windows\$NtUninstallWMFDist11$\wmdmps.dll
+ 2009-07-30 04:04 . 2004-08-12 13:33 27136 c:\windows\$NtUninstallWMFDist11$\wmdmlog.dll
+ 2009-07-30 04:04 . 2006-11-02 15:46 13312 c:\windows\$NtUninstallWMFDist11$\spuninst\wpdinstallutil.dll
+ 2009-07-30 04:04 . 2004-08-12 13:23 52224 c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll
+ 2009-08-22 18:06 . 2004-08-12 13:17 49536 c:\windows\$NtUninstallKB932716-v2$\cdrom.sys
+ 2009-08-22 18:04 . 2004-08-12 13:23 44032 c:\windows\$MSI31Uninstall_KB893803v2$\msisip.dll
+ 2009-08-22 18:04 . 2004-08-12 13:23 77312 c:\windows\$MSI31Uninstall_KB893803v2$\msiexec.exe
+ 2009-08-22 18:06 . 2007-11-30 11:18 26488 c:\windows\$hf_mig$\KB932716-v2\update\spcustom.dll
+ 2009-08-22 18:06 . 2007-11-30 11:18 17272 c:\windows\$hf_mig$\KB932716-v2\spmsg.dll
+ 2009-08-22 18:05 . 2008-05-02 10:49 62976 c:\windows\$hf_mig$\KB932716-v2\SP3QFE\cdrom.sys
+ 2004-08-12 13:34 . 2006-10-19 01:47 4096 c:\windows\system32\wmvdmoe2.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 4096 c:\windows\system32\wmvdmod.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 4096 c:\windows\system32\WMVADVE.DLL
+ 2006-10-19 01:47 . 2006-10-19 01:47 4096 c:\windows\system32\WMVADVD.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 4096 c:\windows\system32\wmsdmoe2.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 4096 c:\windows\system32\wmsdmod.dll
+ 2006-10-19 01:58 . 2006-10-19 01:58 8704 c:\windows\system32\wdfmgr.exe
+ 2006-10-19 01:47 . 2006-10-19 01:47 4096 c:\windows\system32\wdfapi.dll
+ 2006-10-19 01:58 . 2006-10-19 01:58 8704 c:\windows\system32\uwdf.exe
+ 2005-09-23 11:29 . 2005-09-23 11:29 6144 c:\windows\system32\mui\0409\mscorees.dll
+ 2004-08-12 13:22 . 2006-10-19 01:47 4096 c:\windows\system32\MPG4DMOD.dll
+ 2004-08-12 13:22 . 2006-10-19 01:47 4096 c:\windows\system32\MP4SDMOD.dll
+ 2004-08-12 13:22 . 2006-10-19 01:47 4096 c:\windows\system32\MP43DMOD.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 4096 c:\windows\system32\dllcache\wmvdmoe2.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 4096 c:\windows\system32\dllcache\wmvdmod.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 4096 c:\windows\system32\dllcache\wmsdmoe2.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 4096 c:\windows\system32\dllcache\wmsdmod.dll
+ 2004-08-12 13:22 . 2006-10-19 01:47 4096 c:\windows\system32\dllcache\MPG4DMOD.dll
+ 2004-08-12 13:22 . 2006-10-19 01:47 4096 c:\windows\system32\dllcache\MP4SDMOD.dll
+ 2004-08-12 13:22 . 2006-10-19 01:47 4096 c:\windows\system32\dllcache\MP43DMOD.dll
+ 2009-07-28 16:13 . 2004-08-12 13:28 5120 c:\windows\system32\dllcache\cache\sfc.dll
+ 2009-07-28 16:13 . 2004-08-12 13:25 2944 c:\windows\system32\dllcache\cache\null.sys
+ 2009-07-28 16:13 . 2004-08-12 13:17 4224 c:\windows\system32\dllcache\cache\beep.sys
+ 2004-08-12 13:17 . 2006-10-19 01:47 7168 c:\windows\system32\dllcache\asferror.dll
+ 2004-08-12 13:17 . 2006-10-19 01:47 7168 c:\windows\system32\asferror.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 7680 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 9216 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 7168 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 5632 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 5632 c:\windows\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 8192 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 9728 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 9216 c:\windows\Microsoft.NET\Framework\v2.0.50727\fusion.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 4608 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 8192 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 4608 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 7680 c:\windows\Microsoft.NET\Framework\SharedReg12.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 7680 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 7680 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 7680 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
+ 2009-11-14 22:13 . 2009-11-14 22:13 5120 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe
+ 2009-08-22 18:09 . 2009-08-22 18:09 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 5632 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2009-08-22 18:15 . 2009-08-22 18:15 3072 c:\windows\assembly\GAC_32\policy.2.0.EastmanKodakCompany.EasyShare\2.0.4523.7930__e736f44e197b3380\policy.2.0.EastmanKodakCompany.EasyShare.dll
+ 2009-08-22 18:15 . 2009-08-22 18:15 3072 c:\windows\assembly\GAC_32\policy.1.0.EastmanKodakCompany.EasyShare\1.0.0.2__e736f44e197b3380\policy.1.0.EastmanKodakCompany.EasyShare.dll
+ 2009-07-30 04:06 . 2004-08-12 13:17 8192 c:\windows\$NtUninstallwmp11$\asferror.dll
+ 2009-07-30 04:04 . 2004-08-12 13:21 6656 c:\windows\$NtUninstallWMFDist11$\laprxy.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 114176 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2006-09-28 22:56 . 2006-09-28 22:56 316416 c:\windows\system32\WUDFx.dll
+ 2006-09-28 22:56 . 2006-09-28 22:56 165376 c:\windows\system32\WudfPlatform.dll
+ 2006-09-28 22:56 . 2006-09-28 22:56 146432 c:\windows\system32\WudfHost.exe
+ 2006-10-19 01:47 . 2006-10-19 01:47 356352 c:\windows\system32\wpdsp.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 133632 c:\windows\system32\WPDShServiceObj.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 154624 c:\windows\system32\wpdmtp.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 629760 c:\windows\system32\wpd_ci.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 656896 c:\windows\system32\WMVXENCD.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 767488 c:\windows\system32\WMVSENCD.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 603648 c:\windows\system32\WMSPDMOD.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 204288 c:\windows\system32\wmpsrcwp.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 130048 c:\windows\system32\wmpps.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 613376 c:\windows\system32\wmpmde.dll
+ 2006-10-24 16:30 . 2006-10-24 16:30 276992 c:\windows\system32\WMPhoto.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 295936 c:\windows\system32\wmpeffects.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 314880 c:\windows\system32\wmpdxm.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 242688 c:\windows\system32\wmpasf.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 937984 c:\windows\system32\WMNetMgr.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 157184 c:\windows\system32\wmidx.dll
+ 2004-08-12 13:33 . 2006-10-19 01:47 227328 c:\windows\system32\wmerror.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 535040 c:\windows\system32\wmdrmsdk.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 348672 c:\windows\system32\wmdrmnet.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 429056 c:\windows\system32\wmdrmdev.dll
+ 2004-08-12 13:33 . 2006-10-19 01:47 222208 c:\windows\system32\WMASF.dll
+ 2004-08-12 13:33 . 2006-10-19 01:47 757248 c:\windows\system32\WMADMOD.dll
+ 2006-10-24 16:29 . 2006-10-24 16:29 352256 c:\windows\system32\WindowsCodecsExt.dll
+ 2006-10-24 16:30 . 2006-10-24 16:30 716288 c:\windows\system32\WindowsCodecs.dll
+ 2009-03-24 15:25 . 2009-11-28 22:54 132420 c:\windows\system32\Restore\rstrlog.dat
+ 2004-08-12 13:26 . 2006-10-19 01:47 211456 c:\windows\system32\qasf.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 199168 c:\windows\system32\PortableDeviceWMDRM.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 132096 c:\windows\system32\PortableDeviceWiaCompat.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 166912 c:\windows\system32\PortableDeviceTypes.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 101888 c:\windows\system32\PortableDeviceClassExtension.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 284160 c:\windows\system32\PortableDeviceApi.dll
+ 2006-10-24 16:30 . 2008-05-28 07:13 425472 c:\windows\system32\photometadatahandler.dll
+ 2004-08-12 13:26 . 2009-10-25 17:55 401064 c:\windows\system32\perfh009.dat
+ 2004-08-12 13:23 . 2006-10-19 01:47 321536 c:\windows\system32\mswmdm.dll
+ 2004-08-12 13:23 . 2006-10-19 01:47 414208 c:\windows\system32\msscp.dll
+ 2004-08-12 13:23 . 2006-10-19 01:47 175616 c:\windows\system32\mspmsp.dll
+ 2004-08-12 13:23 . 2006-10-19 01:47 179712 c:\windows\system32\msnetobj.dll
+ 2004-08-12 13:23 . 2005-05-03 16:58 884736 c:\windows\system32\msimsg.dll
- 2004-08-12 13:23 . 2004-08-12 13:23 884736 c:\windows\system32\msimsg.dll
+ 2004-08-12 13:23 . 2005-05-03 16:58 271360 c:\windows\system32\msihnd.dll
+ 2006-10-02 19:28 . 2006-10-02 19:28 312128 c:\windows\system32\msdelta.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 150016 c:\windows\system32\mscorier.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 270848 c:\windows\system32\mscoree.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 259072 c:\windows\system32\MPG4DECD.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 317440 c:\windows\system32\MP4SDECD.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 259072 c:\windows\system32\MP43DECD.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 212992 c:\windows\system32\MFPLAT.dll
+ 2008-10-05 03:24 . 2008-10-05 03:24 235936 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-07-18 03:12 . 2009-07-18 03:12 257440 c:\windows\system32\Macromed\Flash\FlashUtil10c.exe
+ 2004-08-12 13:21 . 2006-10-19 00:03 100864 c:\windows\system32\logagent.exe
+ 2007-06-06 13:18 . 2007-06-06 13:18 196608 c:\windows\system32\KPDRES.DLL
+ 2007-06-06 13:38 . 2007-06-06 13:38 237568 c:\windows\system32\KPDPMUI.dll
+ 2007-06-06 13:38 . 2007-06-06 13:38 344064 c:\windows\system32\KPDPM.dll
+ 2009-08-22 18:05 . 2008-05-02 13:30 464384 c:\windows\system32\imapi2fs.dll
+ 2009-08-22 18:05 . 2008-05-02 13:30 317952 c:\windows\system32\imapi2.dll
+ 2009-08-22 18:17 . 2007-06-06 13:46 229376 c:\windows\system32\DRVSTORE\kpd_116B8E56BDDDF953EAB6D8D8F5CDA37DE77C0E1A\KPDVS.dll
+ 2009-08-22 18:17 . 2007-06-06 13:37 278528 c:\windows\system32\DRVSTORE\kpd_116B8E56BDDDF953EAB6D8D8F5CDA37DE77C0E1A\KPDUI.dll
+ 2009-08-22 18:17 . 2007-06-06 13:18 196608 c:\windows\system32\DRVSTORE\kpd_116B8E56BDDDF953EAB6D8D8F5CDA37DE77C0E1A\KPDRES.dll
+ 2009-08-22 18:17 . 2007-06-06 13:37 258048 c:\windows\system32\DRVSTORE\kpd_116B8E56BDDDF953EAB6D8D8F5CDA37DE77C0E1A\KPDGDI.dll
+ 2004-08-12 13:18 . 2006-10-19 01:47 991744 c:\windows\system32\drmv2clt.dll
+ 2006-10-19 00:00 . 2006-10-19 00:00 249856 c:\windows\system32\drmupgds.exe
+ 2006-10-19 01:47 . 2006-10-19 01:47 671232 c:\windows\system32\drivers\UMDF\wpdmtpdr.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 603648 c:\windows\system32\dllcache\WMSPDMOD.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 314880 c:\windows\system32\dllcache\wmpdxm.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 242688 c:\windows\system32\dllcache\wmpasf.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 937984 c:\windows\system32\dllcache\WMNetMgr.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 157184 c:\windows\system32\dllcache\wmidx.dll
+ 2004-08-12 13:33 . 2006-10-19 01:47 227328 c:\windows\system32\dllcache\wmerror.dll
+ 2004-08-12 13:33 . 2006-10-19 01:47 222208 c:\windows\system32\dllcache\WMASF.dll
+ 2004-08-12 13:33 . 2006-10-19 01:47 757248 c:\windows\system32\dllcache\WMADMOD.dll
+ 2004-08-12 13:31 . 2006-11-01 22:31 315904 c:\windows\system32\dllcache\unregmp2.exe
+ 2004-08-12 13:26 . 2006-10-19 01:47 211456 c:\windows\system32\dllcache\qasf.dll
+ 2004-08-12 13:23 . 2006-10-19 01:47 321536 c:\windows\system32\dllcache\mswmdm.dll
+ 2004-08-12 13:23 . 2006-10-19 01:47 414208 c:\windows\system32\dllcache\msscp.dll
+ 2004-08-12 13:23 . 2006-10-19 01:47 175616 c:\windows\system32\dllcache\mspmsp.dll
+ 2004-08-12 13:23 . 2006-10-19 01:47 179712 c:\windows\system32\dllcache\msnetobj.dll
+ 2004-08-12 13:23 . 2005-05-03 16:58 884736 c:\windows\system32\dllcache\msimsg.dll
- 2004-08-12 13:23 . 2004-08-12 13:23 884736 c:\windows\system32\dllcache\msimsg.dll
+ 2004-08-12 13:23 . 2005-05-03 16:58 271360 c:\windows\system32\dllcache\msihnd.dll
+ 2007-03-15 11:26 . 2006-10-19 01:47 243712 c:\windows\system32\dllcache\mpvis.dll
+ 2004-08-12 13:21 . 2006-10-19 00:03 100864 c:\windows\system32\dllcache\logagent.exe
+ 2009-08-22 18:05 . 2008-05-02 13:30 464384 c:\windows\system32\dllcache\imapi2fs.dll
+ 2009-08-22 18:05 . 2008-05-02 13:30 317952 c:\windows\system32\dllcache\imapi2.dll
+ 2004-08-12 13:18 . 2006-10-19 01:47 991744 c:\windows\system32\dllcache\drmv2clt.dll
+ 2004-08-12 13:17 . 2006-10-19 01:47 229376 c:\windows\system32\dllcache\cewmdm.dll
+ 2009-07-28 16:13 . 2004-08-12 13:34 111104 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-07-28 16:13 . 2004-08-12 13:33 502272 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-07-28 16:13 . 2006-11-08 03:03 818688 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-07-28 16:13 . 2004-08-12 13:31 577024 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-07-28 16:13 . 2004-08-12 13:30 295424 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-07-28 16:13 . 2004-08-12 13:30 359040 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-07-28 16:13 . 2004-08-12 13:29 170496 c:\windows\system32\dllcache\cache\srsvc.dll
+ 2009-07-28 16:13 . 2004-08-12 13:28 108032 c:\windows\system32\dllcache\cache\services.exe
+ 2009-07-28 16:13 . 2004-08-12 13:27 395776 c:\windows\system32\dllcache\cache\rpcss.dll
+ 2009-07-28 16:13 . 2004-08-12 13:25 435200 c:\windows\system32\dllcache\cache\ntmssvc.dll
+ 2009-07-28 16:13 . 2004-08-12 13:24 407040 c:\windows\system32\dllcache\cache\netlogon.dll
+ 2009-07-28 16:13 . 2004-08-12 13:24 182912 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-07-28 16:13 . 2004-08-12 13:21 924432 c:\windows\system32\dllcache\cache\mfc40u.dll
+ 2009-07-28 16:13 . 2004-08-12 13:20 983552 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-07-28 16:13 . 2004-08-12 13:20 110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2009-07-28 16:13 . 2004-08-12 13:18 792064 c:\windows\system32\dllcache\cache\comres.dll
+ 2009-07-28 16:13 . 2004-08-12 13:17 611328 c:\windows\system32\dllcache\cache\comctl32.dll
+ 2009-07-28 16:13 . 2004-08-12 13:17 167936 c:\windows\system32\dllcache\cache\appmgmts.dll
+ 2009-07-28 16:13 . 2004-08-04 04:39 142464 c:\windows\system32\dllcache\cache\aec.sys
+ 2004-08-12 13:17 . 2006-10-19 01:47 542720 c:\windows\system32\dllcache\blackbox.dll
+ 2004-08-12 13:17 . 2006-10-19 01:47 229376 c:\windows\system32\cewmdm.dll
+ 2004-08-12 13:17 . 2006-10-19 01:47 542720 c:\windows\system32\blackbox.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 276992 c:\windows\system32\audiodev.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 298496 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 823296 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 835584 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 260096 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 114688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 131072 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 299008 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 368640 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Management.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 114176 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 700416 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 188416 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 397312 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 884736 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 716800 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 482304 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 389120 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 377344 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 107520 c:\windows\Microsoft.NET\Framework\v2.0.50727\shfusion.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 136192 c:\windows\Microsoft.NET\Framework\v2.0.50727\peverify.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 226816 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 330752 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 102400 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 326144 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 288768 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 800768 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 667648 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 372736 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 745472 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 647168 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 413696 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll
+ 2005-09-23 11:57 . 2005-09-23 11:57 245408 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\unicows.dll
+ 2005-09-23 11:01 . 2005-09-23 11:01 609472 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 224952 c:\windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 788992 c:\windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 547840 c:\windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 503808 c:\windows\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 138240 c:\windows\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 208896 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 183808 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 136192 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll
+ 2009-08-22 18:17 . 2009-08-22 18:17 202752 c:\windows\Installer\4b5623d1.msi
+ 2009-08-22 18:16 . 2009-08-22 18:16 182784 c:\windows\Installer\4b5623c0.msi
+ 2009-08-22 18:16 . 2009-08-22 18:16 182784 c:\windows\Installer\4b5623bb.msi
+ 2009-08-22 18:16 . 2009-08-22 18:16 185856 c:\windows\Installer\4b5623b6.msi
+ 2009-08-22 18:15 . 2009-08-22 18:15 307712 c:\windows\Installer\4b5623b1.msi
+ 2009-08-22 18:15 . 2009-08-22 18:15 183808 c:\windows\Installer\4b5623ac.msi
+ 2009-08-22 18:15 . 2009-08-22 18:15 302592 c:\windows\Installer\4b5623a7.msi
+ 2009-08-22 18:15 . 2009-08-22 18:15 190464 c:\windows\Installer\4b5623a2.msi
+ 2009-08-22 18:15 . 2009-08-22 18:15 295936 c:\windows\Installer\4b56239d.msi
+ 2009-08-22 18:15 . 2009-08-22 18:15 370688 c:\windows\Installer\4b562398.msi
+ 2009-08-22 18:15 . 2009-08-22 18:15 404480 c:\windows\Installer\4b562393.msi
+ 2009-08-22 18:15 . 2009-08-22 18:15 213504 c:\windows\Installer\4b56238d.msi
+ 2009-08-22 18:15 . 2009-08-22 18:15 186368 c:\windows\Installer\4b562387.msi
+ 2009-08-22 18:15 . 2009-08-22 18:15 180736 c:\windows\Installer\4b562382.msi
+ 2009-08-22 18:15 . 2009-08-22 18:15 180736 c:\windows\Installer\4b56237d.msi
+ 2009-08-22 18:15 . 2009-08-22 18:15 396800 c:\windows\Installer\4b562378.msi
+ 2009-08-22 18:15 . 2009-08-22 18:15 548352 c:\windows\Installer\4b562373.msi
+ 2009-08-22 18:14 . 2009-08-22 18:14 291840 c:\windows\Installer\4b56236e.msi
+ 2009-08-22 18:14 . 2009-08-22 18:14 357376 c:\windows\Installer\4b562369.msi
+ 2009-08-22 18:14 . 2009-08-22 18:14 291840 c:\windows\Installer\4b562364.msi
+ 2009-08-22 18:13 . 2009-08-22 18:13 182784 c:\windows\Installer\4b56235f.msi
+ 2009-08-22 18:13 . 2009-08-22 18:13 288768 c:\windows\Installer\4b56235a.msi
+ 2009-08-22 18:13 . 2009-08-22 18:13 294912 c:\windows\Installer\4b562355.msi
+ 2009-08-22 18:17 . 2009-08-22 18:17 135168 c:\windows\Installer\{FCDB1C92-03C6-4C76-8625-371224256091}\PdockShortcut5.exe
+ 2004-08-12 13:31 . 2006-11-01 22:31 315904 c:\windows\inf\unregmp2.exe
+ 2009-09-28 14:16 . 2009-09-28 14:16 151552 c:\windows\ERDNT\AutoBackup\9-28-2009\Users\00000002\UsrClass.dat
+ 2009-09-28 14:16 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\9-28-2009\ERDNT.EXE
+ 2009-09-18 16:40 . 2009-09-18 16:40 151552 c:\windows\ERDNT\AutoBackup\9-18-2009\Users\00000002\UsrClass.dat
+ 2009-09-18 16:40 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\9-18-2009\ERDNT.EXE
+ 2009-09-18 00:57 . 2009-09-18 00:57 151552 c:\windows\ERDNT\AutoBackup\9-17-2009\Users\00000002\UsrClass.dat
+ 2009-09-18 00:57 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\9-17-2009\ERDNT.EXE
+ 2009-08-08 03:07 . 2009-08-08 03:07 151552 c:\windows\ERDNT\AutoBackup\8-7-2009\Users\00000002\UsrClass.dat
+ 2009-08-08 03:07 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\8-7-2009\ERDNT.EXE
+ 2009-08-22 19:32 . 2009-08-22 19:32 151552 c:\windows\ERDNT\AutoBackup\8-22-2009\Users\00000002\UsrClass.dat
+ 2009-08-22 19:32 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\8-22-2009\ERDNT.EXE
+ 2009-07-31 00:45 . 2009-07-31 00:45 151552 c:\windows\ERDNT\AutoBackup\7-30-2009\Users\00000002\UsrClass.dat
+ 2009-07-31 00:45 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\7-30-2009\ERDNT.EXE
+ 2009-12-01 19:50 . 2009-12-01 19:50 151552 c:\windows\ERDNT\AutoBackup\12-1-2009\Users\00000002\UsrClass.dat
+ 2009-12-01 19:50 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\12-1-2009\ERDNT.EXE
+ 2009-11-07 19:05 . 2009-11-07 19:05 151552 c:\windows\ERDNT\AutoBackup\11-7-2009\Users\00000002\UsrClass.dat
+ 2009-11-07 19:05 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\11-7-2009\ERDNT.EXE
+ 2009-11-30 05:10 . 2009-11-30 05:10 151552 c:\windows\ERDNT\AutoBackup\11-30-2009\Users\00000002\UsrClass.dat
+ 2009-11-30 05:10 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\11-30-2009\ERDNT.EXE
+ 2009-11-29 20:01 . 2009-11-29 20:01 151552 c:\windows\ERDNT\AutoBackup\11-29-2009\Users\00000002\UsrClass.dat
+ 2009-11-29 20:01 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\11-29-2009\ERDNT.EXE
+ 2009-11-28 21:20 . 2009-11-28 21:20 151552 c:\windows\ERDNT\AutoBackup\11-28-2009\Users\00000002\UsrClass.dat
+ 2009-11-27 19:38 . 2009-11-27 19:38 151552 c:\windows\ERDNT\AutoBackup\11-27-2009\Users\00000002\UsrClass.dat
+ 2009-11-20 23:43 . 2009-11-20 23:43 151552 c:\windows\ERDNT\AutoBackup\11-20-2009\Users\00000002\UsrClass.dat
+ 2009-11-20 23:43 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\11-20-2009\ERDNT.EXE
+ 2009-11-14 13:31 . 2009-11-14 13:31 151552 c:\windows\ERDNT\AutoBackup\11-14-2009\Users\00000002\UsrClass.dat
+ 2009-11-14 13:31 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\11-14-2009\ERDNT.EXE
+ 2009-11-13 21:10 . 2009-11-13 21:10 151552 c:\windows\ERDNT\AutoBackup\11-13-2009\Users\00000002\UsrClass.dat
+ 2009-11-13 21:10 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\11-13-2009\ERDNT.EXE
+ 2009-11-12 23:34 . 2009-11-12 23:34 151552 c:\windows\ERDNT\AutoBackup\11-12-2009\Users\00000002\UsrClass.dat
+ 2009-11-12 23:34 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\11-12-2009\ERDNT.EXE
+ 2009-10-05 15:42 . 2009-10-05 15:42 151552 c:\windows\ERDNT\AutoBackup\10-5-2009\Users\00000002\UsrClass.dat
+ 2009-10-05 15:42 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\10-5-2009\ERDNT.EXE
+ 2009-10-25 17:55 . 2009-10-25 17:55 151552 c:\windows\ERDNT\AutoBackup\10-25-2009\Users\00000002\UsrClass.dat
+ 2009-10-25 17:55 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\10-25-2009\ERDNT.EXE
+ 2009-10-02 18:05 . 2009-10-02 18:05 151552 c:\windows\ERDNT\AutoBackup\10-2-2009\Users\00000002\UsrClass.dat
+ 2009-10-02 18:05 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\10-2-2009\ERDNT.EXE
+ 2009-10-16 23:50 . 2009-10-16 23:50 151552 c:\windows\ERDNT\AutoBackup\10-16-2009\Users\00000002\UsrClass.dat
+ 2009-10-16 23:50 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\10-16-2009\ERDNT.EXE
+ 2009-08-22 18:22 . 2009-08-22 18:22 237568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\76666efb060742439fee81b4d5f1f062\System.Web.RegularExpressions.ni.dll
+ 2009-08-22 18:21 . 2009-08-22 18:21 684032 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\4188762fafbd3745a49f2dcbf5a91f9d\System.Transactions.ni.dll
+ 2009-08-22 18:20 . 2009-08-22 18:20 729088 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\6e1a7f2832b5774f9f1acd06ef16d25f\System.Security.ni.dll
+ 2009-08-22 18:20 . 2009-08-22 18:20 294912 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\0a938b2e8362c649865d1d8329a2cbc7\System.EnterpriseServices.Wrapper.dll
+ 2009-08-22 18:20 . 2009-08-22 18:20 659456 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\0a938b2e8362c649865d1d8329a2cbc7\System.EnterpriseServices.ni.dll
+ 2009-08-22 18:11 . 2009-08-22 18:11 229376 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\f15c85fa7ec2eb499556b5752f505809\System.Drawing.Design.ni.dll
+ 2009-08-22 18:20 . 2009-08-22 18:20 512000 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\e4c251f77ebad3409845e1c9ec122b6d\System.DirectoryServices.Protocols.ni.dll
+ 2009-08-22 18:18 . 2009-08-22 18:18 962560 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\9de06c1782eb084898acefc3338d75d7\System.Configuration.ni.dll
+ 2009-08-22 18:17 . 2009-08-22 18:17 163840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\a981d3c158206c4c90f4c6e4c2f6613d\Microsoft.Build.Utilities.ni.dll
+ 2009-08-22 18:17 . 2009-08-22 18:17 880640 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\48899421f8fae94690710649a021aa6c\Microsoft.Build.Engine.ni.dll
+ 2009-08-22 18:16 . 2009-08-22 18:16 237568 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\9202299e4d06954295e94d0e5297c6b4\CustomMarshalers.ni.dll
+ 2009-08-22 18:16 . 2009-08-22 18:16 860160 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\58f0f616530c8c438b93cfc7d730a6dc\AspNetMMCExt.ni.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 823296 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 299008 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 368640 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 700416 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 397312 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 884736 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 716800 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 389120 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 667648 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 745472 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 647168 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 413696 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 503808 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2009-08-22 18:13 . 2009-08-22 18:13 430080 c:\windows\assembly\GAC_32\WicFileFormat-PlatOpt\1.0.5227.4054__b0cfd8589c27b05f\WicFileFormat-PlatOpt.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 260096 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 114176 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 482304 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2009-08-22 18:15 . 2009-08-22 18:15 258048 c:\windows\assembly\GAC_32\EastmanKodakCompany.EasyShare\2.0.4523.7930__e736f44e197b3380\EastmanKodakCompany.EasyShare.dll
+ 2009-08-22 18:15 . 2009-08-22 18:15 282624 c:\windows\assembly\GAC_32\EastmanKodakCompany.EasyShare\1.0.2698.25402__e736f44e197b3380\EastmanKodakCompany.EasyShare.dll
+ 2009-07-30 04:03 . 2006-09-16 05:05 379184 c:\windows\$NtUninstallWudf01000$\spuninst\updspapi.dll
+ 2009-07-30 04:03 . 2006-09-16 05:05 221488 c:\windows\$NtUninstallWudf01000$\spuninst\spuninst.exe
+ 2009-07-30 04:06 . 2004-08-12 13:34 102400 c:\windows\$NtUninstallwmp11$\wmpshell.dll
+ 2009-07-30 04:06 . 2004-08-12 13:34 233472 c:\windows\$NtUninstallwmp11$\wmpdxm.dll
+ 2009-07-30 04:06 . 2004-08-12 13:34 114688 c:\windows\$NtUninstallwmp11$\wmpasf.dll
+ 2009-07-30 04:06 . 2004-08-12 13:33 168448 c:\windows\$NtUninstallwmp11$\wmerror.dll
+ 2009-07-30 04:06 . 2004-08-12 13:31 208896 c:\windows\$NtUninstallwmp11$\unregmp2.exe
+ 2009-07-30 04:06 . 2006-05-16 22:11 371424 c:\windows\$NtUninstallwmp11$\spuninst\updspapi.dll
+ 2009-07-30 04:06 . 2006-05-16 22:11 213216 c:\windows\$NtUninstallwmp11$\spuninst\spuninst.exe
+ 2009-07-30 04:06 . 2004-08-12 13:28 774144 c:\windows\$NtUninstallwmp11$\setup_wm.exe
+ 2009-07-30 04:06 . 2004-08-12 13:22 368640 c:\windows\$NtUninstallwmp11$\mpvis.dll
+ 2009-07-30 04:04 . 2004-08-12 13:34 809984 c:\windows\$NtUninstallWMFDist11$\wmvdmod.dll
+ 2009-07-30 04:04 . 2004-08-12 13:34 896512 c:\windows\$NtUninstallWMFDist11$\wmspdmoe.dll
+ 2009-07-30 04:04 . 2004-08-12 13:34 484864 c:\windows\$NtUninstallWMFDist11$\wmspdmod.dll
+ 2009-07-30 04:04 . 2004-08-12 13:34 759296 c:\windows\$NtUninstallWMFDist11$\wmsdmod.dll
+ 2009-07-30 04:04 . 2004-08-12 13:34 151552 c:\windows\$NtUninstallWMFDist11$\wmidx.dll
+ 2009-07-30 04:04 . 2004-08-12 13:33 230400 c:\windows\$NtUninstallWMFDist11$\wmasf.dll
+ 2009-07-30 04:04 . 2004-08-12 13:33 670720 c:\windows\$NtUninstallWMFDist11$\wmadmoe.dll
+ 2009-07-30 04:04 . 2004-08-12 13:33 408064 c:\windows\$NtUninstallWMFDist11$\wmadmod.dll
+ 2009-07-30 04:04 . 2006-05-16 22:11 371424 c:\windows\$NtUninstallWMFDist11$\spuninst\updspapi.dll
+ 2009-07-30 04:04 . 2006-05-16 22:11 213216 c:\windows\$NtUninstallWMFDist11$\spuninst\spuninst.exe
+ 2009-07-30 04:04 . 2004-08-12 13:26 237568 c:\windows\$NtUninstallWMFDist11$\qasf.dll
+ 2009-07-30 04:04 . 2004-08-12 13:23 245760 c:\windows\$NtUninstallWMFDist11$\mswmdm.dll
+ 2009-07-30 04:04 . 2004-08-12 13:23 356352 c:\windows\$NtUninstallWMFDist11$\msscp.dll
+ 2009-07-30 04:04 . 2004-08-12 13:23 201728 c:\windows\$NtUninstallWMFDist11$\mspmsp.dll
+ 2009-07-30 04:04 . 2004-08-12 13:23 259072 c:\windows\$NtUninstallWMFDist11$\msnetobj.dll
+ 2009-07-30 04:04 . 2004-08-12 13:22 240640 c:\windows\$NtUninstallWMFDist11$\mpg4dmod.dll
+ 2009-07-30 04:04 . 2004-08-12 13:22 384512 c:\windows\$NtUninstallWMFDist11$\mp4sdmod.dll
+ 2009-07-30 04:04 . 2004-08-12 13:22 310272 c:\windows\$NtUninstallWMFDist11$\mp43dmod.dll
+ 2009-07-30 04:04 . 2004-08-12 13:21 103936 c:\windows\$NtUninstallWMFDist11$\logagent.exe
+ 2009-07-30 04:04 . 2004-08-12 13:18 695296 c:\windows\$NtUninstallWMFDist11$\drmv2clt.dll
+ 2009-07-30 04:04 . 2004-08-12 13:17 159232 c:\windows\$NtUninstallWMFDist11$\cewmdm.dll
+ 2009-07-30 04:04 . 2004-08-12 13:17 286208 c:\windows\$NtUninstallWMFDist11$\blackbox.dll
+ 2009-08-22 18:05 . 2006-10-16 20:10 379184 c:\windows\$NtUninstallWIC$\spuninst\updspapi.dll
+ 2009-08-22 18:05 . 2006-10-16 20:10 221488 c:\windows\$NtUninstallWIC$\spuninst\spuninst.exe
+ 2009-07-30 04:07 . 2006-09-25 21:58 379184 c:\windows\$NtUninstallMSCompPackV1$\spuninst\updspapi.dll
+ 2009-07-30 04:07 . 2006-09-25 21:58 221488 c:\windows\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe
+ 2009-08-22 18:06 . 2007-11-30 12:39 382840 c:\windows\$NtUninstallKB945060-v3$\spuninst\updspapi.dll
+ 2009-08-22 18:06 . 2007-11-30 12:39 231288 c:\windows\$NtUninstallKB945060-v3$\spuninst\spuninst.exe
+ 2009-08-22 18:06 . 2006-10-24 16:30 412160 c:\windows\$NtUninstallKB945060-v3$\photometadatahandler.dll
+ 2009-08-22 18:06 . 2007-11-30 11:18 382840 c:\windows\$NtUninstallKB932716-v2$\spuninst\updspapi.dll
+ 2009-08-22 18:06 . 2007-11-30 11:18 231288 c:\windows\$NtUninstallKB932716-v2$\spuninst\spuninst.exe
+ 2009-07-30 04:07 . 2005-10-12 23:12 371424 c:\windows\$NtUninstallKB926239$\spuninst\updspapi.dll
+ 2009-07-30 04:07 . 2005-10-12 23:12 213216 c:\windows\$NtUninstallKB926239$\spuninst\spuninst.exe
+ 2009-08-22 18:04 . 2005-05-03 16:58 371936 c:\windows\$MSI31Uninstall_KB893803v2$\spuninst\updspapi.dll
+ 2009-08-22 18:04 . 2005-05-03 16:58 209632 c:\windows\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe
+ 2009-08-22 18:04 . 2004-08-12 13:23 884736 c:\windows\$MSI31Uninstall_KB893803v2$\msimsg.dll
+ 2009-08-22 18:04 . 2004-08-12 13:23 331264 c:\windows\$MSI31Uninstall_KB893803v2$\msihnd.dll
+ 2009-08-22 18:06 . 2007-11-30 11:18 382840 c:\windows\$hf_mig$\KB932716-v2\update\updspapi.dll
+ 2009-08-22 18:06 . 2007-11-30 11:18 755576 c:\windows\$hf_mig$\KB932716-v2\update\update.exe
+ 2009-08-22 18:06 . 2007-11-30 11:18 231288 c:\windows\$hf_mig$\KB932716-v2\spuninst.exe
+ 2009-08-22 18:05 . 2008-05-02 13:25 465920 c:\windows\$hf_mig$\KB932716-v2\SP3QFE\imapi2fs.dll
+ 2009-08-22 18:05 . 2008-05-02 13:25 317952 c:\windows\$hf_mig$\KB932716-v2\SP3QFE\imapi2.dll
+ 2006-12-02 04:25 . 2006-12-02 04:25 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
+ 2006-12-02 04:25 . 2006-12-02 04:25 1101824 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
+ 2009-08-22 18:06 . 2009-08-22 18:06 1233920 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d\msxml4.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 2603008 c:\windows\system32\WpdShext.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 1382912 c:\windows\system32\WMVSDECD.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 1574912 c:\windows\system32\WMVENCOD.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 1543680 c:\windows\system32\WMVDECOD.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 2450944 c:\windows\system32\wmvcore.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 1329152 c:\windows\system32\WMSPDMOE.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 8231936 c:\windows\system32\wmploc.dll
+ 2006-10-19 01:47 . 2006-10-19 01:47 1661440 c:\windows\system32\wmpencen.dll
+ 2004-08-12 13:33 . 2006-10-19 01:47 1117696 c:\windows\system32\WMADMOE.dll
+ 2009-11-01 19:19 . 2009-08-29 00:42 2065696 c:\windows\system32\usbaaplrc.dll
+ 2003-04-18 20:46 . 2003-04-18 20:46 1233920 c:\windows\system32\msxml4.dll
+ 2004-08-12 13:23 . 2005-05-03 16:58 2890240 c:\windows\system32\msi.dll
+ 2008-10-05 03:24 . 2008-10-05 03:24 3695008 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2009-11-01 19:19 . 2009-08-29 00:42 2065696 c:\windows\system32\DRVSTORE\usbaapl_6DA28B91FF48C57089E4D2436654AFA4ECAD0622\usbaaplrc.dll
+ 2009-11-01 19:19 . 2009-08-29 00:42 1417504 c:\windows\system32\DRVSTORE\netaapl_F433E854B3FF3BEE74986FDE8E16A64162342BFF\wdfcoinstaller01005.dll
+ 2009-08-22 18:17 . 2007-06-06 13:57 2363392 c:\windows\system32\DRVSTORE\kpd_116B8E56BDDDF953EAB6D8D8F5CDA37DE77C0E1A\xerces-c_2_7.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 2450944 c:\windows\system32\dllcache\wmvcore.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 1329152 c:\windows\system32\dllcache\WMSPDMOE.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 8231936 c:\windows\system32\dllcache\wmploc.dll
+ 2004-08-12 13:33 . 2006-10-19 01:47 1117696 c:\windows\system32\dllcache\WMADMOE.dll
+ 2007-03-15 11:26 . 2006-11-01 22:31 1669120 c:\windows\system32\dllcache\setup_wm.exe
+ 2004-08-12 13:23 . 2005-05-03 16:58 2890240 c:\windows\system32\dllcache\msi.dll
+ 2009-07-28 16:13 . 2004-08-12 13:28 1580544 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-07-28 16:13 . 2004-08-12 13:25 2180992 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-07-28 16:13 . 2004-08-12 13:29 2056832 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-07-28 16:13 . 2004-08-12 13:19 1032192 c:\windows\system32\dllcache\cache\explorer.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 1306624 c:\windows\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 1140920 c:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 2035712 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 5316608 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 3018752 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 5050368 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 2878976 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 5615616 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 4308992 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 1144832 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscomp.dll
+ 2009-11-14 22:13 . 2009-11-14 22:13 1583616 c:\windows\Installer\cbcb75.msi
+ 2009-08-08 03:14 . 2009-08-08 03:14 1021952 c:\windows\Installer\72224.msi
+ 2009-08-22 18:17 . 2009-08-22 18:17 1506304 c:\windows\Installer\4b5623cb.msi
+ 2009-08-22 18:16 . 2009-08-22 18:16 1922560 c:\windows\Installer\4b5623c5.msi
+ 2009-08-22 18:13 . 2009-08-22 18:13 1021440 c:\windows\Installer\4b56234f.msi
+ 2009-08-22 18:09 . 2009-08-22 18:09 2109440 c:\windows\Installer\4b562349.msi
+ 2009-11-01 19:19 . 2009-11-01 19:19 3310592 c:\windows\Installer\24cbb2c8.msi
+ 2009-11-25 00:47 . 2009-11-25 00:47 7668224 c:\windows\Installer\14d4fd4c.msi
+ 2009-09-28 14:16 . 2009-09-28 14:16 4349952 c:\windows\ERDNT\AutoBackup\9-28-2009\Users\00000001\NTUSER.DAT
+ 2009-09-18 16:40 . 2009-09-18 16:40 4349952 c:\windows\ERDNT\AutoBackup\9-18-2009\Users\00000001\NTUSER.DAT
+ 2009-09-18 00:57 . 2009-09-18 00:57 4349952 c:\windows\ERDNT\AutoBackup\9-17-2009\Users\00000001\NTUSER.DAT
+ 2009-08-08 03:06 . 2009-08-08 03:07 4349952 c:\windows\ERDNT\AutoBackup\8-7-2009\Users\00000001\NTUSER.DAT
+ 2009-08-22 19:32 . 2009-08-22 19:32 4349952 c:\windows\ERDNT\AutoBackup\8-22-2009\Users\00000001\NTUSER.DAT
+ 2009-07-31 00:45 . 2009-07-31 00:45 4349952 c:\windows\ERDNT\AutoBackup\7-30-2009\Users\00000001\NTUSER.DAT
+ 2009-12-01 19:50 . 2009-12-01 19:50 4349952 c:\windows\ERDNT\AutoBackup\12-1-2009\Users\00000001\ntuser.dat
+ 2009-11-07 19:05 . 2009-11-07 19:05 4349952 c:\windows\ERDNT\AutoBackup\11-7-2009\Users\00000001\NTUSER.DAT
+ 2009-11-30 05:10 . 2009-11-30 05:10 4349952 c:\windows\ERDNT\AutoBackup\11-30-2009\Users\00000001\ntuser.dat
+ 2009-11-29 20:01 . 2009-11-29 20:01 4349952 c:\windows\ERDNT\AutoBackup\11-29-2009\Users\00000001\ntuser.dat
+ 2009-11-28 21:20 . 2009-11-28 21:20 4349952 c:\windows\ERDNT\AutoBackup\11-28-2009\Users\00000001\NTUSER.DAT
+ 2009-11-27 19:38 . 2009-11-27 19:38 4349952 c:\windows\ERDNT\AutoBackup\11-27-2009\Users\00000001\NTUSER.DAT
+ 2009-11-20 23:43 . 2009-11-20 23:43 4349952 c:\windows\ERDNT\AutoBackup\11-20-2009\Users\00000001\NTUSER.DAT
+ 2009-11-14 13:31 . 2009-11-14 13:31 4349952 c:\windows\ERDNT\AutoBackup\11-14-2009\Users\00000001\NTUSER.DAT
+ 2009-11-13 21:10 . 2009-11-13 21:10 4349952 c:\windows\ERDNT\AutoBackup\11-13-2009\Users\00000001\NTUSER.DAT
+ 2009-11-12 23:34 . 2009-11-12 23:34 4349952 c:\windows\ERDNT\AutoBackup\11-12-2009\Users\00000001\NTUSER.DAT
+ 2009-10-05 15:42 . 2009-10-05 15:42 4349952 c:\windows\ERDNT\AutoBackup\10-5-2009\Users\00000001\NTUSER.DAT
+ 2009-10-25 17:55 . 2009-10-25 17:55 4349952 c:\windows\ERDNT\AutoBackup\10-25-2009\Users\00000001\NTUSER.DAT
+ 2009-10-02 18:05 . 2009-10-02 18:05 4349952 c:\windows\ERDNT\AutoBackup\10-2-2009\Users\00000001\NTUSER.DAT
+ 2009-10-16 23:50 . 2009-10-16 23:50 4349952 c:\windows\ERDNT\AutoBackup\10-16-2009\Users\00000001\NTUSER.DAT
+ 2009-08-22 18:11 . 2009-08-22 18:11 8093696 c:\windows\assembly\NativeImages_v2.0.50727_32\System\9518d49623098f499ae39213fdb3c3c0\System.ni.dll
+ 2009-08-22 18:12 . 2009-08-22 18:12 5640192 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\868779c9063d8d4c88076a754a964397\System.Xml.ni.dll
+ 2009-08-22 18:22 . 2009-08-22 18:22 1945600 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\3cb0b7d66fdbbb41bc8a1c809c363e70\System.Web.Services.ni.dll
+ 2009-08-22 18:22 . 2009-08-22 18:22 2310144 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\afbe3de7495bb741b5ea445b33489b10\System.Web.Mobile.ni.dll
+ 2009-08-22 18:11 . 2009-08-22 18:11 1626112 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5a5577404a6ac24fbb5d596a825b366a\System.Drawing.ni.dll
+ 2009-08-22 18:19 . 2009-08-22 18:19 1220608 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\3d1b9aba8d46eb46975a0db6ffe4631c\System.DirectoryServices.ni.dll
+ 2009-08-22 18:18 . 2009-08-22 18:18 1716224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\c2d4e0f305e6a443aed054fe25759f15\System.Deployment.ni.dll
+ 2009-08-22 18:12 . 2009-08-22 18:12 6688768 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\349a7d5ecc356646b6c76915b2f858b5\System.Data.ni.dll
+ 2009-08-22 18:18 . 2009-08-22 18:18 1724416 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\ce615b2dd960b649a9472376cbe1d286\Microsoft.VisualBasic.ni.dll
+ 2009-08-22 18:17 . 2009-08-22 18:17 1691648 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\cf749d580a2d1241ada33e9ac274345e\Microsoft.Build.Tasks.ni.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 3018752 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 2035712 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 5316608 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 5050368 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 5025792 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 2878976 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2009-08-22 18:09 . 2009-08-22 18:09 4308992 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2009-07-30 04:06 . 2004-08-12 13:34 2940928 c:\windows\$NtUninstallwmp11$\wmploc.dll
+ 2009-07-30 04:06 . 2004-08-12 13:34 4874240 c:\windows\$NtUninstallwmp11$\wmp.dll
+ 2009-07-30 04:04 . 2004-08-12 13:34 1001472 c:\windows\$NtUninstallWMFDist11$\wmvdmoe2.dll
+ 2009-07-30 04:04 . 2004-08-12 13:34 2105344 c:\windows\$NtUninstallWMFDist11$\wmvcore.dll
+ 2009-07-30 04:04 . 2004-08-12 13:34 1119744 c:\windows\$NtUninstallWMFDist11$\wmsdmoe2.dll
+ 2009-07-30 04:04 . 2004-08-12 13:34 1050624 c:\windows\$NtUninstallWMFDist11$\wmnetmgr.dll
+ 2009-08-22 18:04 . 2004-08-12 13:23 2804224 c:\windows\$MSI31Uninstall_KB893803v2$\msi.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 10834432 c:\windows\system32\wmp.dll
+ 2004-08-12 13:34 . 2006-10-19 01:47 10834432 c:\windows\system32\dllcache\wmp.dll
+ 2005-09-23 11:48 . 2005-09-23 11:48 24863744 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\netfx.msi
+ 2009-08-22 18:06 . 2009-08-22 18:06 26360320 c:\windows\Installer\4b56233d.msi
+ 2009-08-22 18:12 . 2009-08-22 18:12 13107200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\a431527cda3cff4cb16d6391a3cabedb\System.Windows.Forms.ni.dll
+ 2009-08-22 18:22 . 2009-08-22 18:22 11808768 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\b09d92b69b9f82408ee8bc75e8ec078a\System.Web.ni.dll
+ 2009-08-22 18:13 . 2009-08-22 18:13 10723328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\98771ea145e6e14ca26bd12ea9ec6f3f\System.Design.ni.dll
+ 2009-08-22 18:10 . 2009-08-22 18:10 11411456 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\c0d4a9849f24ee49be5e1c2bd7d7792d\mscorlib.ni.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-11-11 2001648]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-12 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Easy SpyRemover"="c:\program files\Easy SpyRemover\EasySpyRemover.exe" [2009-07-07 3530480]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-10-10 203264]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

c:\documents and settings\Jesse\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2009-7-10 323584]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\att-nap\\McciBrowser.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\Common Files\\Motive\\McciCMService.exe"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [11/11/2009 10:44 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/11/2009 10:44 AM 74480]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [11/11/2009 10:44 AM 7408]
S3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\Drivers\L6TPortGX.sys –> c:\windows\system32\Drivers\L6TPortGX.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-12-02 c:\windows\Tasks\WebReg HP Photosmart C4400 series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2008-03-26 00:42]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
Trusted Zone: line6.net
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-jazazanek - c:\docume~1\alluse~1\applic~1\kunuzavi\kunuzavi.dll
SharedTaskScheduler-{39e30122-b9fa-4ac0-8eae-e244dc882845} - c:\docume~1\alluse~1\applic~1\lewokilo\lewokilo.dll
SharedTaskScheduler-{9ee98ce3-5812-43bd-856e-1c37a243d4db} - c:\docume~1\alluse~1\applic~1\lewokilo\lewokilo.dll
SharedTaskScheduler-{67db4455-b5fd-439f-b0bd-48090f5d32c5} - (no file)
SharedTaskScheduler-{ecba06cb-3cfa-40d8-b987-5c108013ade4} - c:\docume~1\alluse~1\applic~1\kunuzavi\kunuzavi.dll
SSODL-bokayoton-{39e30122-b9fa-4ac0-8eae-e244dc882845} - c:\docume~1\alluse~1\applic~1\lewokilo\lewokilo.dll
SSODL-wadomasuj-{9ee98ce3-5812-43bd-856e-1c37a243d4db} - c:\docume~1\alluse~1\applic~1\lewokilo\lewokilo.dll
SSODL-fesovoyob-{67db4455-b5fd-439f-b0bd-48090f5d32c5} - (no file)
SSODL-zinogikek-{ecba06cb-3cfa-40d8-b987-5c108013ade4} - c:\docume~1\alluse~1\applic~1\kunuzavi\kunuzavi.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-02 16:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1606980848-1637723038-839522115-1007\Software\SecuROM\License information*]
"datasecu"=hex:c0,6a,1b,31,52,76,b5,3d,d4,84,91,d0,5e,df,c1,70,44,0d,4d,8a,64,
b4,71,1f,c1,e8,8b,73,7e,3f,6d,51,49,ab,00,07,21,25,6e,0e,32,70,31,b7,ab,54,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(660)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(3440)
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\NavNT\defwatch.exe
c:\program files\Common Files\Motive\McciCMService.exe
.
**************************************************************************
.
Completion time: 2009-12-02 16:32 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-02 21:32
ComboFix2.txt 2009-07-29 16:15
ComboFix3.txt 2009-07-28 16:15

Pre-Run: 143,806,431,232 bytes free
Post-Run: 143,786,598,400 bytes free

- - End Of File - - E79DA3122D3D64CD0B91C52DA507110B
I started getting problems because limewire in june. I have tried to remove all files ascociated with it since then, but the word limewire still comes up in alot off these scans… could this be why i keep getting reinfeced? any tips?
Hi,

Please do the following:


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/System_infected_background_popups_other_bizzare_behavior_t108604.html&view=findpost&p=614891#entry614891

Collect::
c:\windows\system32\bepiyubu.dll
c:\windows\system32\hamifela.dll
c:\windows\system32\hiziwuja.dll
c:\windows\system32\lunoboza.dll
c:\windows\system32\mofinaze.dll
c:\windows\system32\nufuyeyo.dll
c:\windows\system32\rasulodu.dll
c:\windows\system32\suhadovo.dll
c:\windows\system32\vefizife.dll
c:\windows\system32\vohesetu.dll
c:\windows\system32\wapifoko.dll
c:\windows\system32\womifaso.dll

Folder::
c:\documents and settings\All Users\Application Data\hajiruno
c:\documents and settings\All Users\Application Data\kunuzavi
c:\documents and settings\All Users\Application Data\kafimehe
c:\documents and settings\All Users\Application Data\jimarofi
c:\documents and settings\All Users\Application Data\neganosu
c:\documents and settings\All Users\Application Data\lekapuvo
c:\documents and settings\All Users\Application Data\kebavage
c:\documents and settings\All Users\Application Data\hiyivonu
c:\documents and settings\All Users\Application Data\lewokilo
c:\documents and settings\All Users\Application Data\venuheno
c:\documents and settings\All Users\Application Data\jetivobu
c:\documents and settings\All Users\Application Data\wihizada
 c:\documents and settings\All Users\Application Data\sagodomo
c:\documents and settings\All Users\Application Data\wujuleza
c:\documents and settings\All Users\Application Data\gofazato
c:\program files\LimeWire

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Thursday, December 3, 2009 Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Thursday, December 03, 2009 20:45:43 Records in database: 3327651 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ Scan statistics: Objects scanned: 37550 Threats found: 31 Infected objects found: 103 Suspicious objects found: 0 Scan duration: 01:56:07 File name / Threat / Threats count C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01140000.VBN Infected: Trojan-Downloader.WMA.GetCodec.b 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01AC0000.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01B40000.VBN Infected: not-a-virus:AdWare.Win32.Agent.zk 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01B40001.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01B40002.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02180000.VBN Infected: Trojan.Win32.Agent.afwg 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02280000.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02400000.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02400001.VBN Infected: Trojan-Downloader.WMA.GetCodec.a 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02440000.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02480000.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\024C0000.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02640000.VBN Infected: Backdoor.Win32.TDSS.blh 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02640001.VBN Infected: Backdoor.Win32.TDSS.asz 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02680000.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02680001.VBN Infected: Backdoor.Win32.TDSS.asz 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02680002.VBN Infected: Backdoor.Win32.TDSS.atb 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02680003.VBN Infected: Backdoor.Win32.TDSS.atb 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02680004.VBN Infected: Backdoor.Win32.TDSS.bkw 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\026C0000.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02880000.VBN Infected: Rootkit.Win32.Clbd.lf 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02880001.VBN Infected: Rootkit.Win32.Clbd.lf 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02880002.VBN Infected: Backdoor.Win32.TDSS.blh 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\038C0000.VBN Infected: Trojan-Dropper.Win32.Agent.avyd 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\038C0001.VBN Infected: Trojan.Win32.Agent2.cgrb 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04F00000.VBN Infected: Packed.Win32.TDSS.aa 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05780000.VBN Infected: Packed.Win32.TDSS.aa 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\057C0000.VBN Infected: Packed.Win32.TDSS.aa 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05A40000.VBN Infected: Packed.Win32.TDSS.aa 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05C00000.VBN Infected: Packed.Win32.TDSS.aa 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05C00001.VBN Infected: Packed.Win32.TDSS.aa 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05E00000.VBN Infected: Packed.Win32.TDSS.aa 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07140000.VBN Infected: Packed.Win32.TDSS.aa 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07380000.VBN Infected: not-a-virus:AdWare.Win32.Agent.zk 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07700000.VBN Infected: Trojan-Downloader.WMA.GetCodec.a 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08500000.VBN Infected: Trojan-Downloader.Win32.DlKroha.r 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08640000.VBN Infected: Backdoor.Win32.TDSS.bkw 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\09200000.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0A880000.VBN Infected: Trojan.Win32.Vilsel.mwj 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0A8C0000.VBN Infected: Trojan.Win32.Monder.cvau 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0A940000.VBN Infected: Trojan.Win32.Vilsel.mwj 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0AD00000.VBN Infected: Packed.Win32.TDSS.aa 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0B700000.VBN Infected: Packed.Win32.TDSS.aa 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0B700001.VBN Infected: Packed.Win32.TDSS.aa 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0B740000.VBN Infected: Packed.Win32.TDSS.aa 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0B740001.VBN Infected: Packed.Win32.TDSS.aa 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0BEC0000.VBN Infected: Packed.Win32.TDSS.aa 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0C5C0000.VBN Infected: Trojan.Win32.Agent.axoc 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0C5C0001.VBN Infected: Trojan.Win32.Agent.axoc 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0C6C0000.VBN Infected: Trojan-Downloader.WMA.GetCodec.a 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0C6C0001.VBN Infected: Trojan.Win32.Agent.axoc 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0C780000.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E140000.VBN Infected: Trojan-Downloader.WMA.GetCodec.y 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E2C0000.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E2C0001.VBN Infected: Trojan-Downloader.WMA.GetCodec.b 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0EDC0000.VBN Infected: Trojan-Downloader.Win32.Agent.ckkp 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0EE00000.VBN Infected: Backdoor.Win32.Bredolab.m 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0EE40000.VBN Infected: Net-Worm.Win32.Koobface.aue 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0EE40001.VBN Infected: Trojan-Downloader.Win32.Agent.ckkp 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0EE80000.VBN Infected: Trojan-Downloader.Win32.Agent.civm 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0EE80001.VBN Infected: Trojan-Dropper.Win32.Agent.avyd 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0EEC0000.VBN Infected: Net-Worm.Win32.Koobface.ayr 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0EEC0001.VBN Infected: Backdoor.Win32.Bredolab.m 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0EF40000.VBN Infected: Net-Worm.Win32.Koobface.ayr 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0EF40001.VBN Infected: Hoax.Win32.Bravia.lj 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0EF80000.VBN Infected: Backdoor.Win32.Bredolab.m 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0EFC0000.VBN Infected: Trojan-Dropper.Win32.Agent.avyd 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F040000.VBN Infected: Trojan.Win32.Mondere.cd 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F040001.VBN Infected: Trojan.Win32.Mondere.cd 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F080000.VBN Infected: Trojan.Win32.Mondere.cd 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F0C0000.VBN Infected: Trojan.Win32.Mondere.cd 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F100000.VBN Infected: Packed.Win32.Tdss.a 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F100001.VBN Infected: Trojan.Win32.Mondere.cd 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F100002.VBN Infected: Trojan.Win32.Mondere.cd 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F100003.VBN Infected: Trojan.Win32.Mondere.cd 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F100004.VBN Infected: Trojan.Win32.Mondere.cd 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F200001.VBN Infected: Packed.Win32.Tdss.a 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F200002.VBN Infected: Packed.Win32.Tdss.a 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F2C0000.VBN Infected: Trojan.Win32.Agent2.cgrb 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F380000.VBN Infected: Trojan.Win32.Agent2.cgrb 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F3C0000.VBN Infected: Trojan-Dropper.Win32.Agent.avyd 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F3C0001.VBN Infected: Trojan-Dropper.Win32.Agent.awrd 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F400000.VBN Infected: Trojan-Dropper.Win32.Agent.awrd 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F480000.VBN Infected: Trojan.Win32.Agent2.cgrb 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0FB00000.VBN Infected: Trojan-Clicker.WMA.Agent.d 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0FC40000.VBN Infected: Trojan-Clicker.WMA.Agent.d 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0FC40001.VBN Infected: Trojan-Clicker.WMA.Agent.d 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\14480000.VBN Infected: Trojan-Downloader.Java.OpenStream.ac 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\14480001.VBN Infected: Trojan-Downloader.Java.OpenStream.ac 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\14480002.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\14480003.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\14480004.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\14480005.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\14480006.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\14480007.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\14480008.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\14480009.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\1448000A.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\1448000B.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\1448000C.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\1448000D.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\Documents and Settings\Jesse\Application Data\Sun\Java\Deployment\cache\6.0\0\1697a940-17e4e2af Infected: Trojan-Downloader.Java.OpenStream.ad 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir Infected: Rootkit.Win32.TDSS.y 1 Selected area has been scanned.
No, the logs will still be there.

Navigate to C:/Combofix.txt for the combofix log and the malwarebytes logs tab - look for the most recent log.
oh, ok thank you.

ComboFix 09-12-02.05 - Jesse 12/02/2009 21:48.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.296 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Cleanup Utilities\vashmere.exe
Command switches used :: c:\documents and settings\Jesse\Desktop\Cleanup Utilities\CFscript.txt

file zipped: c:\windows\system32\bepiyubu.dll
file zipped: c:\windows\system32\hamifela.dll
file zipped: c:\windows\system32\hiziwuja.dll
file zipped: c:\windows\system32\lunoboza.dll
file zipped: c:\windows\system32\mofinaze.dll
file zipped: c:\windows\system32\nufuyeyo.dll
file zipped: c:\windows\system32\rasulodu.dll
file zipped: c:\windows\system32\suhadovo.dll
file zipped: c:\windows\system32\vefizife.dll
file zipped: c:\windows\system32\vohesetu.dll
file zipped: c:\windows\system32\wapifoko.dll
file zipped: c:\windows\system32\womifaso.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\gofazato
c:\documents and settings\All Users\Application Data\hajiruno
c:\documents and settings\All Users\Application Data\hiyivonu
c:\documents and settings\All Users\Application Data\jetivobu
c:\documents and settings\All Users\Application Data\jimarofi
c:\documents and settings\All Users\Application Data\kafimehe
c:\documents and settings\All Users\Application Data\kebavage
c:\documents and settings\All Users\Application Data\kunuzavi
c:\documents and settings\All Users\Application Data\lekapuvo
c:\documents and settings\All Users\Application Data\lewokilo
c:\documents and settings\All Users\Application Data\neganosu
c:\documents and settings\All Users\Application Data\sagodomo
c:\documents and settings\All Users\Application Data\venuheno
c:\documents and settings\All Users\Application Data\wihizada
c:\documents and settings\All Users\Application Data\wujuleza
c:\program files\LimeWire
c:\windows\system32\bepiyubu.dll
c:\windows\system32\hamifela.dll
c:\windows\system32\hiziwuja.dll
c:\windows\system32\lunoboza.dll
c:\windows\system32\mofinaze.dll
c:\windows\system32\nufuyeyo.dll
c:\windows\system32\rasulodu.dll
c:\windows\system32\suhadovo.dll
c:\windows\system32\vefizife.dll
c:\windows\system32\vohesetu.dll
c:\windows\system32\wapifoko.dll
c:\windows\system32\womifaso.dll

c:\windows\system32\proquota.exe . . . is missing!!

.
((((((((((((((((((((((((( Files Created from 2009-11-03 to 2009-12-03 )))))))))))))))))))))))))))))))
.

2009-11-30 21:15 . 2009-11-30 21:15 ——– d—–w- C:\VundoFix Backups
2009-11-28 22:54 . 2009-11-28 22:54 ——– d—–w- c:\windows\system32\wbem\Repository
2009-11-25 00:47 . 2009-11-25 00:47 ——– d—–w- c:\windows\Logs
2009-11-25 00:47 . 2009-11-25 00:47 ——– d—–w- c:\program files\Virtools
2009-11-14 22:13 . 2009-11-14 22:13 117760 —-a-w- c:\documents and settings\Jesse\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-11-14 22:13 . 2009-11-14 22:13 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-11-14 22:12 . 2009-11-14 22:12 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-11-14 22:12 . 2009-11-14 22:12 ——– d—–w- c:\documents and settings\Jesse\Application Data\SUPERAntiSpyware.com
2009-11-13 16:12 . 2009-11-13 16:12 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-11-12 15:16 . 2009-11-14 04:10 ——– d—–w- c:\documents and settings\Guest\Application Data\HPAppData
2009-11-09 20:57 . 2009-11-09 20:57 ——– d—–w- c:\documents and settings\Guest\Local Settings\Application Data\Adobe
2009-11-07 19:11 . 2009-11-07 21:27 ——– d—–w- c:\documents and settings\Guest\Local Settings\Application Data\Google
2009-11-07 19:10 . 2009-11-07 19:10 ——– d—–w- c:\documents and settings\Guest\Application Data\Skinux
2009-11-07 14:42 . 2009-11-07 19:04 0 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\APTemp\AP0.dll
2009-11-06 23:21 . 2009-11-06 23:21 ——– d—–w- C:\.jagex_cache_32
2009-11-06 23:16 . 2009-11-28 20:48 63 —-a-w- c:\documents and settings\Jesse\jagex_runescape_preferences2.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-03 02:40 . 2009-04-14 19:03 ——– d—–w- c:\documents and settings\Jesse\Application Data\HPAppData
2009-12-02 21:23 . 2009-08-22 18:20 720 —-a-w- c:\documents and settings\All Users\Application Data\ArcSoft\kodak-printcreations-22-080812-oem\acforall.dll
2009-12-02 03:41 . 2004-08-12 13:17 95360 ——w- c:\windows\system32\drivers\atapi.sys
2009-11-30 20:56 . 2008-02-22 22:19 ——– d—–w- c:\program files\Google
2009-11-28 23:03 . 2009-07-13 14:44 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-11-28 20:44 . 2008-08-13 04:35 38 —-a-w- c:\documents and settings\Jesse\jagex_runescape_preferences.dat
2009-10-20 23:45 . 2009-04-14 18:56 ——– d—–w- c:\documents and settings\Jesse\Application Data\HP
2009-10-20 23:45 . 2009-04-14 18:35 ——– d—–w- c:\documents and settings\All Users\Application Data\HP
2009-10-20 04:01 . 2007-03-15 11:44 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-09-10 19:54 . 2009-07-13 14:44 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 19:53 . 2009-07-13 14:44 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
.

((((((((((((((((((((((((((((( SnapShot_2009-12-02_21.24.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-02 21:24 . 2009-12-02 21:24 151552 c:\windows\ERDNT\AutoBackup\12-2-2009\Users\00000002\UsrClass.dat
+ 2009-12-02 21:24 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\12-2-2009\ERDNT.EXE
+ 2009-12-02 21:24 . 2009-12-02 21:24 4349952 c:\windows\ERDNT\AutoBackup\12-2-2009\Users\00000001\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-11-11 2001648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Easy SpyRemover"="c:\program files\Easy SpyRemover\EasySpyRemover.exe" [2009-07-07 3530480]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-10-10 203264]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

c:\documents and settings\Jesse\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2009-7-10 323584]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\att-nap\\McciBrowser.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\Common Files\\Motive\\McciCMService.exe"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [11/11/2009 10:44 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/11/2009 10:44 AM 74480]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [11/11/2009 10:44 AM 7408]
S3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\Drivers\L6TPortGX.sys –> c:\windows\system32\Drivers\L6TPortGX.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-12-02 c:\windows\Tasks\WebReg HP Photosmart C4400 series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2008-03-26 00:42]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
Trusted Zone: line6.net
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-02 21:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1606980848-1637723038-839522115-1007\Software\SecuROM\License information*]
"datasecu"=hex:c0,6a,1b,31,52,76,b5,3d,d4,84,91,d0,5e,df,c1,70,44,0d,4d,8a,64,
b4,71,1f,c1,e8,8b,73,7e,3f,6d,51,49,ab,00,07,21,25,6e,0e,32,70,31,b7,ab,54,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(660)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Completion time: 2009-12-02 22:05
ComboFix-quarantined-files.txt 2009-12-03 03:05
ComboFix2.txt 2009-12-02 21:33
ComboFix3.txt 2009-07-29 16:15
ComboFix4.txt 2009-07-28 16:15

Pre-Run: 143,740,231,680 bytes free
Post-Run: 143,746,936,832 bytes free

- - End Of File - - 4CBF953DF8E625BB5717D59F53367DD6
Upload was successful

————————————————————————————————

Malwarebytes' Anti-Malware 1.41
Database version: 3288
Windows 5.1.2600 Service Pack 2

12/3/2009 3:43:37 PM
mbam-log-2009-12-03 (15-43-37).txt

Scan type: Quick Scan
Objects scanned: 117473
Time elapsed: 6 minute(s), 18 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hi,

Please do the following:

Go Start > Run and copy/paste the following single-line command into the Run box and click OK:

cmd /c PEV -l "%systemdrive%\proquota.exe" >Log.txt&Log.txt&del Log.txt

A Notepad file will open. Post the contents of Log.txt in your next reply.


NEXT


Visit ADOBEand download the latest version of Acrobat Reader (version 9.2)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT


[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

  • Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 17. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u17-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
Hi, Can you advise if you have access to your XP installation disk as we need to replace a file from it. Can you also advise how the computer is running now and if there are any outstanding issues.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI