This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected With Virus

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is infected and I have ran all scans and the virus is still present causing security alerts and pop ups. Need help. I have ran malwarebytes, anti vira, and anti spyware programs. Thanks
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

β€’Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
β€’If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
β€’Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
β€’Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post
β€’Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
β€’This may cause a delay in response time, but I will do my best to keep it as short as possible.
β€’I will reply back shortly with instructions.
Please do the following

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<β€” ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
ComboFix 10-08-24.0C - user 08/26/2010 0:53.3.1 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.734 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\user\Local Settings\Application Data\erxusnukg
c:\documents and settings\user\Local Settings\Application Data\erxusnukg\khqvafkshdw.exe

.
((((((((((((((((((((((((( Files Created from 2010-07-26 to 2010-08-26 )))))))))))))))))))))))))))))))
.

2010-08-24 21:40 . 2010-08-24 21:40 ——– d—–w- C:\Cache
2010-08-01 23:53 . 2010-08-01 23:53 ——– d—–w- c:\program files\Market Samurai
2010-07-31 18:25 . 2010-07-31 18:25 ——– d—–w- c:\program files\Lame for Audacity
2010-07-31 17:54 . 2010-07-31 17:54 ——– d—–w- c:\program files\Audacity
2010-07-29 02:58 . 2010-07-29 02:58 ——– d—–w- c:\program files\Auto Clicker

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-26 04:37 . 2010-07-13 00:32 ——– d—–w- c:\program files\OnlyWire
2010-08-26 03:26 . 2010-07-12 20:16 ——– d—–w- c:\documents and settings\All Users\Application Data\ATTYToolbar
2010-08-12 20:57 . 2010-07-12 20:16 ——– d—–w- c:\documents and settings\user\Application Data\Yahoo!
2010-08-11 09:38 . 2009-12-07 20:28 68648 β€”-a-w- c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-07 02:45 . 2010-06-01 10:53 63488 β€”-a-w- c:\documents and settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-08-07 02:44 . 2009-12-10 16:23 117760 β€”-a-w- c:\documents and settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-08-07 02:42 . 2009-12-10 16:22 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-08-02 00:04 . 2010-05-24 04:16 55172 β€”ha-w- c:\windows\system32\mlfcache.dat
2010-07-23 09:02 . 2010-07-23 09:02 ——– d—–w- c:\program files\ESET
2010-07-22 07:09 . 2010-07-22 07:09 ——– d—–w- c:\program files\MSBuild
2010-07-22 07:09 . 2010-07-22 07:09 ——– d—–w- c:\program files\Reference Assemblies
2010-07-21 18:23 . 2010-07-21 18:23 ——– d—–w- c:\documents and settings\user\Application Data\Media Player Classic
2010-07-21 15:51 . 2010-07-21 15:51 ——– d—–w- c:\program files\XP Codec Pack
2010-07-21 15:16 . 2010-07-21 15:16 ——– d—–w- c:\program files\Realtek AC97
2010-07-21 15:16 . 2009-12-07 21:20 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-07-21 15:09 . 2010-07-21 15:09 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2010-07-21 15:08 . 2010-07-21 15:08 ——– d—–w- c:\program files\PC Drivers HeadQuarters
2010-07-21 14:35 . 2010-07-21 14:34 ——– d—–w- c:\program files\MSN Toolbar Installer
2010-07-21 14:35 . 2010-01-27 16:54 ——– d—–w- c:\program files\Microsoft
2010-07-21 14:35 . 2010-07-21 14:35 ——– d—–w- c:\program files\MSN Toolbar
2010-07-21 14:35 . 2010-07-21 14:35 ——– d—–w- c:\program files\Microsoft Silverlight
2010-07-21 14:34 . 2010-07-21 14:34 ——– d—–w- c:\documents and settings\All Users\Application Data\UAB
2010-07-21 14:34 . 2010-07-21 14:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Driver Inspector
2010-07-21 14:31 . 2010-07-21 14:31 ——– d—–w- c:\program files\Driver Inspector
2010-07-21 13:49 . 2010-07-21 13:49 ——– d—–w- c:\program files\Conduit
2010-07-21 06:34 . 2010-07-21 06:33 ——– d—–w- c:\program files\QuickTime
2010-07-21 06:33 . 2010-07-21 06:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-07-20 11:39 . 2010-07-20 11:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-07-13 03:39 . 2010-07-12 18:56 ——– d—–w- c:\program files\Common Files\Motive
2010-07-13 01:03 . 2010-05-24 02:32 ——– d—–w- c:\program files\Traffic Travis v3
2010-07-13 01:03 . 2010-06-15 03:46 4703927 β€”-a-w- c:\documents and settings\user\Application Data\Affilorama\TrafficTravisv3\temp\traffic_travis.exe
2010-07-13 00:32 . 2010-07-13 00:32 ——– d—–w- c:\program files\Common Files\Snipitron LLC
2010-07-12 20:43 . 2010-07-12 18:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Motive
2010-07-12 20:38 . 2010-07-12 18:57 ——– d—–w- c:\documents and settings\user\Application Data\Motive
2010-07-12 20:38 . 2010-07-12 20:36 ——– d—–w- c:\program files\ATT-SST
2010-07-12 20:32 . 2010-07-12 20:32 ——– d—–w- c:\program files\ATT
2010-07-12 20:18 . 2010-07-12 20:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-07-12 20:16 . 2010-07-12 20:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-07-12 20:16 . 2010-07-12 20:16 ——– d—–w- c:\program files\Yahoo!
2010-07-12 18:56 . 2010-07-12 18:56 ——– d—–w- c:\program files\ATT-HSI
2010-06-30 12:31 . 2001-08-23 12:00 149504 β€”-a-w- c:\windows\system32\schannel.dll
2010-06-24 12:15 . 2001-08-23 12:00 832512 β€”-a-w- c:\windows\system32\wininet.dll
2010-06-24 12:15 . 2009-12-07 19:54 78336 β€”β€”w- c:\windows\system32\ieencode.dll
2010-06-24 12:15 . 2001-08-23 12:00 17408 β€”-a-w- c:\windows\system32\corpol.dll
2010-06-23 13:44 . 2001-08-23 12:00 1851904 β€”-a-w- c:\windows\system32\win32k.sys
2010-06-22 23:07 . 2010-06-22 23:07 501936 β€”-a-w- c:\documents and settings\All Users\Application Data\Google\Google Toolbar\Update\gtb22AD.tmp.exe
2010-06-21 15:27 . 2001-08-23 12:00 354304 β€”-a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2001-08-23 12:00 80384 β€”-a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2009-12-07 19:35 744448 β€”-a-w- c:\windows\PCHEALTH\HELPCTR\Binaries\helpsvc.exe
2010-06-14 07:41 . 2001-08-23 12:00 1172480 β€”-a-w- c:\windows\system32\msxml3.dll
.

((((((((((((((((((((((((((((( SnapShot_2010-07-22_07.30.55 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-12-10 19:02 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
+ 2009-12-10 19:02 . 2010-02-22 14:23 17272 c:\windows\system32\spmsg.dll
+ 2010-03-31 04:16 . 2010-03-31 04:16 99176 c:\windows\system32\PresentationHostProxy.dll
- 2001-08-23 12:00 . 2010-05-04 17:20 44544 c:\windows\system32\pngfilt.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 44544 c:\windows\system32\pngfilt.dll
- 2001-08-23 12:00 . 2008-04-14 00:09 24064 c:\windows\system32\pidgen.dll
+ 2001-08-23 12:00 . 2008-04-13 21:11 24064 c:\windows\system32\pidgen.dll
+ 2001-08-23 12:00 . 2010-08-11 07:07 68070 c:\windows\system32\perfc009.dat
+ 2009-11-07 05:07 . 2009-11-07 05:07 49488 c:\windows\system32\netfxperf.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 52224 c:\windows\system32\msfeedsbs.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 52224 c:\windows\system32\msfeedsbs.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 27648 c:\windows\system32\jsproxy.dll
- 2001-08-23 12:00 . 2010-05-04 17:20 27648 c:\windows\system32\jsproxy.dll
- 2007-08-13 23:39 . 2010-05-04 12:39 13824 c:\windows\system32\ieudinit.exe
+ 2007-08-13 23:39 . 2010-06-23 12:06 13824 c:\windows\system32\ieudinit.exe
- 2001-08-23 12:00 . 2010-05-04 17:20 44544 c:\windows\system32\iernonce.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 44544 c:\windows\system32\iernonce.dll
+ 2001-08-23 12:00 . 2010-06-23 12:06 70656 c:\windows\system32\ie4uinit.exe
- 2001-08-23 12:00 . 2010-05-04 12:39 70656 c:\windows\system32\ie4uinit.exe
+ 2007-08-13 23:36 . 2010-06-24 12:15 63488 c:\windows\system32\icardie.dll
- 2007-08-13 23:36 . 2010-05-04 17:20 63488 c:\windows\system32\icardie.dll
+ 2007-08-13 23:36 . 2010-06-24 12:15 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2007-08-13 23:36 . 2010-05-04 17:20 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2009-12-07 18:23 . 2008-04-13 21:11 24064 c:\windows\system32\dllcache\pidgen.dll
- 2009-12-07 18:23 . 2008-04-14 00:09 24064 c:\windows\system32\dllcache\pidgen.dll
- 2009-12-07 19:32 . 2010-05-04 17:20 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2009-12-07 19:32 . 2010-06-24 12:15 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-12-07 19:32 . 2010-06-23 12:06 13824 c:\windows\system32\dllcache\ieudinit.exe
- 2009-12-07 19:32 . 2010-05-04 12:39 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2007-08-13 23:39 . 2010-06-24 12:15 44544 c:\windows\system32\dllcache\iernonce.dll
- 2007-08-13 23:39 . 2010-05-04 17:20 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2009-09-25 05:37 . 2010-06-24 12:15 78336 c:\windows\system32\dllcache\ieencode.dll
- 2009-09-25 05:37 . 2010-05-04 17:20 78336 c:\windows\system32\dllcache\ieencode.dll
+ 2007-08-13 23:39 . 2010-06-23 12:06 70656 c:\windows\system32\dllcache\ie4uinit.exe
- 2007-08-13 23:39 . 2010-05-04 12:39 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2009-12-07 19:32 . 2010-06-24 12:15 63488 c:\windows\system32\dllcache\icardie.dll
- 2009-12-07 19:32 . 2010-05-04 17:20 63488 c:\windows\system32\dllcache\icardie.dll
+ 2007-08-13 23:42 . 2010-06-24 12:15 17408 c:\windows\system32\dllcache\corpol.dll
- 2007-08-13 23:42 . 2010-05-04 17:20 17408 c:\windows\system32\dllcache\corpol.dll
- 2008-07-29 23:16 . 2008-07-29 23:16 32768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
+ 2010-04-08 03:48 . 2010-04-08 03:48 32768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
+ 2009-11-07 05:07 . 2009-11-07 05:07 13648 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
+ 2010-03-23 09:31 . 2010-03-23 09:31 30544 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2009-11-07 05:07 . 2009-11-07 05:07 13648 c:\windows\Microsoft.NET\Framework\SharedReg12.dll
+ 2009-11-07 05:07 . 2009-11-07 05:07 13648 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
+ 2009-11-07 05:07 . 2009-11-07 05:07 13648 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
+ 2009-11-07 05:07 . 2009-11-07 05:07 13648 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
+ 2009-11-07 05:07 . 2009-11-07 05:07 13664 c:\windows\Microsoft.NET\Framework\sbs_wminet_utils.dll
+ 2009-11-07 05:07 . 2009-11-07 05:07 13688 c:\windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll
+ 2009-11-07 05:07 . 2009-11-07 05:07 13664 c:\windows\Microsoft.NET\Framework\sbs_system.data.dll
+ 2009-11-07 05:07 . 2009-11-07 05:07 13696 c:\windows\Microsoft.NET\Framework\sbs_system.configuration.install.dll
+ 2009-11-07 05:07 . 2009-11-07 05:07 13656 c:\windows\Microsoft.NET\Framework\sbs_mscorsec.dll
+ 2009-11-07 05:07 . 2009-11-07 05:07 13656 c:\windows\Microsoft.NET\Framework\sbs_mscorrc.dll
+ 2009-11-07 05:07 . 2009-11-07 05:07 13656 c:\windows\Microsoft.NET\Framework\sbs_mscordbi.dll
+ 2009-11-07 05:07 . 2009-11-07 05:07 13672 c:\windows\Microsoft.NET\Framework\sbs_microsoft.jscript.dll
+ 2009-11-07 05:07 . 2009-11-07 05:07 13664 c:\windows\Microsoft.NET\Framework\sbs_diasymreader.dll
+ 2009-11-07 05:07 . 2009-11-07 05:07 86864 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
+ 2010-08-01 23:53 . 2010-08-01 23:53 73216 c:\windows\Installer\29641f4.msi
+ 2010-08-11 07:10 . 2010-05-04 17:20 44544 c:\windows\ie7updates\KB2183461-IE7\pngfilt.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 52224 c:\windows\ie7updates\KB2183461-IE7\msfeedsbs.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 27648 c:\windows\ie7updates\KB2183461-IE7\jsproxy.dll
+ 2010-08-11 07:10 . 2010-05-04 12:39 13824 c:\windows\ie7updates\KB2183461-IE7\ieudinit.exe
+ 2010-08-11 07:10 . 2010-05-04 17:20 44544 c:\windows\ie7updates\KB2183461-IE7\iernonce.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 78336 c:\windows\ie7updates\KB2183461-IE7\ieencode.dll
+ 2010-08-11 07:10 . 2010-05-04 12:39 70656 c:\windows\ie7updates\KB2183461-IE7\ie4uinit.exe
+ 2010-08-11 07:10 . 2010-05-04 17:20 63488 c:\windows\ie7updates\KB2183461-IE7\icardie.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 17408 c:\windows\ie7updates\KB2183461-IE7\corpol.dll
+ 2010-08-11 07:19 . 2010-08-11 07:19 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\5ec9dec678303ebff0ef018edb5ec595\UIAutomationProvider.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\46ef15b88ef577de4882c519329fc5d2\System.Windows.Presentation.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\aada360296a42e0413579a19c771ec2d\System.Web.DynamicData.Design.ni.dll
+ 2010-08-11 09:21 . 2010-08-11 09:21 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\2b5ff2c6358c483eb1439b99badb54fd\System.ComponentModel.DataAnnotations.ni.dll
+ 2010-08-11 09:21 . 2010-08-11 09:21 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\6125ff5a4fcd93d70a246cbff3005d42\System.AddIn.Contract.ni.dll
+ 2010-08-11 07:11 . 2010-08-11 07:11 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\de26af01222270c121788161496fcfe7\PresentationFontCache.ni.exe
+ 2010-08-11 07:10 . 2010-08-11 07:10 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\3c5adeedb70e6e052a6556c6ab9b6918\PresentationCFFRasterizer.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\5e5176efbfeb803b7f217525beec6844\Microsoft.Vsa.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\272d51526813ea113970b8e890c92ee2\Microsoft.VisualC.ni.dll
+ 2010-08-11 09:20 . 2010-08-11 09:20 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e1d4e0b1f112000ab33bbaf88bd9ed99\Microsoft.Build.Framework.ni.dll
+ 2010-08-11 09:21 . 2010-08-11 09:21 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\4200cf5b7f247ec1b997808c6d1ba7d1\Microsoft.Build.Framework.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 73728 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\2bf4bc4ce4b5576b8954a55f14a6a497\DriversHQ.DriverDetective.ExceptionLogging.ni.dll
+ 2010-08-11 09:20 . 2010-08-11 09:20 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\50b7fc7f36c76313cbb434b10923e4e9\dfsvc.ni.exe
+ 2010-08-11 09:18 . 2010-08-11 09:18 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\5ffa548547613dbc5a92f2c5b7cad196\Accessibility.ni.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2010-07-22 07:09 . 2010-07-22 07:09 32768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
+ 2010-07-23 07:08 . 2010-07-23 07:08 32768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2010-08-11 07:07 . 2010-08-11 07:07 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2010-08-11 07:07 . 2010-08-11 07:07 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2010-07-22 07:14 . 2010-07-22 07:14 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2010-07-22 07:14 . 2010-07-22 07:14 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2001-08-23 12:00 . 2010-05-04 17:20 233472 c:\windows\system32\webcheck.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 233472 c:\windows\system32\webcheck.dll
- 2001-08-23 12:00 . 2010-05-04 17:20 105984 c:\windows\system32\url.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 105984 c:\windows\system32\url.dll
+ 2010-03-31 04:10 . 2010-03-31 04:10 295264 c:\windows\system32\PresentationHost.exe
+ 2001-08-23 12:00 . 2010-08-11 07:07 433218 c:\windows\system32\perfh009.dat
- 2001-08-23 12:00 . 2010-05-04 17:20 102912 c:\windows\system32\occache.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 102912 c:\windows\system32\occache.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 671232 c:\windows\system32\mstime.dll
- 2001-08-23 12:00 . 2010-05-04 17:20 671232 c:\windows\system32\mstime.dll
- 2001-08-23 12:00 . 2010-05-04 17:20 193024 c:\windows\system32\msrating.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 193024 c:\windows\system32\msrating.dll
- 2001-08-23 12:00 . 2010-05-04 17:20 477696 c:\windows\system32\mshtmled.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 477696 c:\windows\system32\mshtmled.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 459264 c:\windows\system32\msfeeds.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 459264 c:\windows\system32\msfeeds.dll
+ 2009-11-07 05:07 . 2009-11-07 05:07 297808 c:\windows\system32\mscoree.dll
- 2007-08-13 23:34 . 2010-05-04 17:20 268288 c:\windows\system32\iertutil.dll
+ 2007-08-13 23:34 . 2010-06-24 12:15 268288 c:\windows\system32\iertutil.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 192512 c:\windows\system32\iepeers.dll
- 2001-08-23 12:00 . 2010-05-04 17:20 192512 c:\windows\system32\iepeers.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 385024 c:\windows\system32\iedkcs32.dll
- 2001-08-23 12:00 . 2010-05-04 17:20 385024 c:\windows\system32\iedkcs32.dll
- 2007-07-11 17:27 . 2010-05-04 17:20 380928 c:\windows\system32\ieapfltr.dll
+ 2007-07-11 17:27 . 2010-06-24 12:15 380928 c:\windows\system32\ieapfltr.dll
- 2001-08-23 12:00 . 2010-04-16 11:43 161792 c:\windows\system32\ieakui.dll
+ 2001-08-23 12:00 . 2010-06-17 15:11 161792 c:\windows\system32\ieakui.dll
- 2001-08-23 12:00 . 2010-05-04 17:20 230400 c:\windows\system32\ieaksie.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 230400 c:\windows\system32\ieaksie.dll
- 2001-08-23 12:00 . 2010-05-04 17:20 153088 c:\windows\system32\ieakeng.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 153088 c:\windows\system32\ieakeng.dll
- 2009-12-07 11:16 . 2010-07-22 07:30 273840 c:\windows\system32\FNTCACHE.DAT
+ 2009-12-07 11:16 . 2010-08-11 09:24 273840 c:\windows\system32\FNTCACHE.DAT
- 2009-12-07 19:54 . 2010-05-04 17:20 133120 c:\windows\system32\extmgr.dll
+ 2009-12-07 19:54 . 2010-06-24 12:15 133120 c:\windows\system32\extmgr.dll
- 2001-08-23 12:00 . 2010-05-04 17:20 214528 c:\windows\system32\dxtrans.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 214528 c:\windows\system32\dxtrans.dll
- 2001-08-23 12:00 . 2010-05-04 17:20 347136 c:\windows\system32\dxtmsft.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 347136 c:\windows\system32\dxtmsft.dll
+ 2001-08-23 12:00 . 2008-04-13 21:11 102912 c:\windows\system32\dpcdll.dll
- 2001-08-23 12:00 . 2008-04-14 00:10 102912 c:\windows\system32\dpcdll.dll
+ 2009-09-25 05:37 . 2010-06-24 12:15 832512 c:\windows\system32\dllcache\wininet.dll
- 2009-09-25 05:37 . 2010-05-04 17:20 832512 c:\windows\system32\dllcache\wininet.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 233472 c:\windows\system32\dllcache\webcheck.dll
- 2007-08-13 23:44 . 2010-05-04 17:20 105984 c:\windows\system32\dllcache\url.dll
+ 2007-08-13 23:44 . 2010-06-24 12:15 105984 c:\windows\system32\dllcache\url.dll
+ 2009-12-07 17:57 . 2010-06-21 15:27 354304 c:\windows\system32\dllcache\srv.sys
+ 2008-12-05 06:54 . 2010-06-30 12:31 149504 c:\windows\system32\dllcache\schannel.dll
+ 2007-08-13 23:44 . 2010-06-24 12:15 102912 c:\windows\system32\dllcache\occache.dll
- 2007-08-13 23:44 . 2010-05-04 17:20 102912 c:\windows\system32\dllcache\occache.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 671232 c:\windows\system32\dllcache\mstime.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 671232 c:\windows\system32\dllcache\mstime.dll
+ 2007-08-13 23:44 . 2010-06-24 12:15 193024 c:\windows\system32\dllcache\msrating.dll
- 2007-08-13 23:44 . 2010-05-04 17:20 193024 c:\windows\system32\dllcache\msrating.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 477696 c:\windows\system32\dllcache\mshtmled.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2009-12-07 19:32 . 2010-06-24 12:15 459264 c:\windows\system32\dllcache\msfeeds.dll
- 2009-12-07 19:32 . 2010-05-04 17:20 459264 c:\windows\system32\dllcache\msfeeds.dll
- 2007-08-13 23:43 . 2010-04-16 11:43 634656 c:\windows\system32\dllcache\iexplore.exe
+ 2007-08-13 23:43 . 2010-06-17 15:12 634656 c:\windows\system32\dllcache\iexplore.exe
+ 2009-12-07 19:32 . 2010-06-24 12:15 268288 c:\windows\system32\dllcache\iertutil.dll
- 2009-12-07 19:32 . 2010-05-04 17:20 268288 c:\windows\system32\dllcache\iertutil.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 192512 c:\windows\system32\dllcache\iepeers.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 192512 c:\windows\system32\dllcache\iepeers.dll
- 2007-08-13 23:39 . 2010-05-04 17:20 385024 c:\windows\system32\dllcache\iedkcs32.dll
+ 2007-08-13 23:39 . 2010-06-24 12:15 385024 c:\windows\system32\dllcache\iedkcs32.dll
+ 2009-12-07 19:32 . 2010-06-24 12:15 380928 c:\windows\system32\dllcache\ieapfltr.dll
- 2009-12-07 19:32 . 2010-05-04 17:20 380928 c:\windows\system32\dllcache\ieapfltr.dll
- 2001-08-23 12:00 . 2010-04-16 11:43 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2001-08-23 12:00 . 2010-06-17 15:11 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2007-08-13 23:39 . 2010-06-24 12:15 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2007-08-13 23:39 . 2010-05-04 17:20 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2007-08-13 23:39 . 2010-06-24 12:15 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2007-08-13 23:39 . 2010-05-04 17:20 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 133120 c:\windows\system32\dllcache\extmgr.dll
- 2007-08-13 23:35 . 2010-05-04 17:20 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2007-08-13 23:35 . 2010-06-24 12:15 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2007-08-13 23:35 . 2010-05-04 17:20 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2007-08-13 23:35 . 2010-06-24 12:15 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2009-12-07 18:23 . 2008-04-13 21:11 102912 c:\windows\system32\dllcache\dpcdll.dll
- 2009-12-07 18:23 . 2008-04-14 00:10 102912 c:\windows\system32\dllcache\dpcdll.dll
+ 2007-08-13 23:39 . 2010-06-24 12:15 124928 c:\windows\system32\dllcache\advpack.dll
- 2007-08-13 23:39 . 2010-05-04 17:20 124928 c:\windows\system32\dllcache\advpack.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 124928 c:\windows\system32\advpack.dll
- 2001-08-23 12:00 . 2010-05-04 17:20 124928 c:\windows\system32\advpack.dll
+ 2010-03-31 04:16 . 2010-03-31 04:16 130408 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
+ 2010-04-08 03:48 . 2010-04-08 03:48 970752 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
+ 2010-04-08 03:48 . 2010-04-08 03:48 110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
- 2008-07-29 23:16 . 2008-07-29 23:16 110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
+ 2010-03-23 09:31 . 2010-03-23 09:31 435024 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
- 2008-07-25 15:17 . 2008-07-25 15:17 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
+ 2010-02-09 16:22 . 2010-02-09 16:22 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
+ 2010-05-11 10:40 . 2010-05-11 10:40 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2010-05-11 10:40 . 2010-05-11 10:40 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2009-03-20 15:48 . 2009-03-20 15:48 183808 c:\windows\Installer\503af25.msp
+ 2010-02-25 04:14 . 2010-02-25 04:14 543232 c:\windows\Installer\503af01.msp
+ 2010-08-11 07:10 . 2010-05-04 17:20 832512 c:\windows\ie7updates\KB2183461-IE7\wininet.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 233472 c:\windows\ie7updates\KB2183461-IE7\webcheck.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 105984 c:\windows\ie7updates\KB2183461-IE7\url.dll
+ 2010-08-11 07:10 . 2010-02-22 14:23 382840 c:\windows\ie7updates\KB2183461-IE7\spuninst\updspapi.dll
+ 2010-08-11 07:10 . 2010-02-22 14:23 231288 c:\windows\ie7updates\KB2183461-IE7\spuninst\spuninst.exe
+ 2010-08-11 07:10 . 2010-05-04 17:20 102912 c:\windows\ie7updates\KB2183461-IE7\occache.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 671232 c:\windows\ie7updates\KB2183461-IE7\mstime.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 193024 c:\windows\ie7updates\KB2183461-IE7\msrating.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 477696 c:\windows\ie7updates\KB2183461-IE7\mshtmled.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 459264 c:\windows\ie7updates\KB2183461-IE7\msfeeds.dll
+ 2010-08-11 07:10 . 2010-04-16 11:43 634656 c:\windows\ie7updates\KB2183461-IE7\iexplore.exe
+ 2010-08-11 07:10 . 2010-05-04 17:20 268288 c:\windows\ie7updates\KB2183461-IE7\iertutil.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 192512 c:\windows\ie7updates\KB2183461-IE7\iepeers.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 385024 c:\windows\ie7updates\KB2183461-IE7\iedkcs32.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 380928 c:\windows\ie7updates\KB2183461-IE7\ieapfltr.dll
+ 2010-08-11 07:10 . 2010-04-16 11:43 161792 c:\windows\ie7updates\KB2183461-IE7\ieakui.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 230400 c:\windows\ie7updates\KB2183461-IE7\ieaksie.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 153088 c:\windows\ie7updates\KB2183461-IE7\ieakeng.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 133120 c:\windows\ie7updates\KB2183461-IE7\extmgr.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 214528 c:\windows\ie7updates\KB2183461-IE7\dxtrans.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 347136 c:\windows\ie7updates\KB2183461-IE7\dxtmsft.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 124928 c:\windows\ie7updates\KB2183461-IE7\advpack.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\XPBurnComponent\fa286db493d5e1ae5e3fb933e6af6bf2\XPBurnComponent.ni.dll
+ 2010-08-11 09:20 . 2010-08-11 09:20 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\a16b8bcca59515281688ec856c034698\WsatConfig.ni.exe
+ 2010-08-11 07:19 . 2010-08-11 07:19 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\672c4d8e3c33e309c1ed90fa4cb85aba\WindowsFormsIntegration.ni.dll
+ 2010-08-11 07:19 . 2010-08-11 07:19 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\cd91a32f4e36ccb2981c72c0d333e928\UIAutomationTypes.ni.dll
+ 2010-08-11 07:19 . 2010-08-11 07:19 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\9df760fdf8071c7b0de78f39de365e6a\UIAutomationClient.ni.dll
+ 2010-08-11 09:31 . 2010-08-11 09:31 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\ff53d5b5249a2841ee196294429f51cf\System.Xml.Linq.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\5e16c279496a553c988c6199f0cee8aa\System.Web.Routing.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\d0ae809162b55e2fa958739177476af8\System.Web.RegularExpressions.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\720b28d81e987b889180b291ea19b821\System.Web.Extensions.Design.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\da36fd678161cd3444ef547c894e3f35\System.Web.Entity.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\49ae7c73fac8827123d5db1714c22599\System.Web.Entity.Design.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\ce3aa27d3c4c052845ac5abb1374defa\System.Web.DynamicData.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\95fab896ef2af14876e3e1524379773b\System.Web.Abstractions.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\26d5bf1f7e700c2c19aa9b1da5519b24\System.Transactions.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b000cc703c9d95593b516bf2c2ec316\System.ServiceProcess.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\75e331a5d731d8e207be07adc06dec23\System.Security.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\dd7497aa089340600c8c5af8ab421ff7\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\3de39eb60b9d32af46f32f6c7a88fc7f\System.Runtime.Remoting.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\2a080994f308f347b0497bb8804861cf\System.Net.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\bc1cf48ba7dc00f45d0e949c49ab677a\System.Management.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\904fda53006680a67f917ab638be0305\System.Management.Instrumentation.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\4490976887e2e5a3b594041edbdf5064\System.IO.Log.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\77b9f6f6671aaaeb84c6907d467e792c\System.IdentityModel.Selectors.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\15724a7517f939c9b300f341fb5620b8\System.EnterpriseServices.Wrapper.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\15724a7517f939c9b300f341fb5620b8\System.EnterpriseServices.ni.dll
+ 2010-08-11 07:17 . 2010-08-11 07:17 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\90199b4aa63b1b9c8ed0c3de16eec824\System.Drawing.Design.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\849e98c9f428a12cb581320a23f69dbd\System.DirectoryServices.AccountManagement.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\7a823a4f61cf8c86aad02559f8fed07b\System.DirectoryServices.Protocols.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\ad95820d2e29e8d55c0d8a838214c6e5\System.Data.Services.Design.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\617acb0d900bdde947ec79f7b5ccc183\System.Data.Services.Client.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\488c4017d45e861644a34fae557aa80f\System.Data.Entity.Design.ni.dll
+ 2010-08-11 09:21 . 2010-08-11 09:21 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\41345e34f26854fc1878eae3e4d5d4a5\System.Data.DataSetExtensions.ni.dll
+ 2010-08-11 09:18 . 2010-08-11 09:18 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\ab688d0f9f333ba117832726bfb589c1\System.Configuration.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\b48677ab9aa7a6830785f67b8478b4da\System.Configuration.Install.ni.dll
+ 2010-08-11 09:21 . 2010-08-11 09:21 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\93a0958d5557e2b380647af0171ad354\System.AddIn.ni.dll
+ 2010-08-11 09:20 . 2010-08-11 09:20 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\d0758f84e927e3f0a15a6cde1b96d835\SMSvcHost.ni.exe
+ 2010-08-11 09:20 . 2010-08-11 09:20 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\8043a108e3bb2d3dcc84b547b8085e99\SMDiagnostics.ni.dll
+ 2010-08-11 09:20 . 2010-08-11 09:20 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\5aeb40ff7128df2881fb03c01d070b20\ServiceModelReg.ni.exe
+ 2010-08-11 07:15 . 2010-08-11 07:15 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e7e7321956e6822b1bf3691c35c842f6\PresentationFramework.Aero.ni.dll
+ 2010-08-11 07:16 . 2010-08-11 07:16 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a14488afff027f0f2985e659449097f5\PresentationFramework.Royale.ni.dll
+ 2010-08-11 07:15 . 2010-08-11 07:15 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\787e60c5dd562cb45887080095d2a3b7\PresentationFramework.Classic.ni.dll
+ 2010-08-11 07:15 . 2010-08-11 07:15 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2313ccc125dcb6a9800048ec1c51ec12\PresentationFramework.Luna.ni.dll
+ 2010-08-11 09:20 . 2010-08-11 09:20 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\5db9c32d9f352162e6da220ca463db0d\MSBuild.ni.exe
+ 2010-08-11 09:20 . 2010-08-11 09:20 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\fcf975f74bd134d8e0fa8f37c5bc6a8c\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 303616 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\ded51f470bae90ffbb64b5d482d070d9\Microsoft.Practices.ObjectBuilder.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 309248 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\b3723ae635ec35d5248c060081db6dd7\Microsoft.Practices.EnterpriseLibrary.Common.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 148992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\a34d1bc4cc8cbc44220b5e478bb657ee\Microsoft.Practices.EnterpriseLibrary.Security.Cryptography.ni.dll
+ 2010-08-11 09:21 . 2010-08-11 09:21 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\d6b9038136600fbfbbbd7460dc19da19\Microsoft.Build.Utilities.ni.dll
+ 2010-08-11 09:21 . 2010-08-11 09:21 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\585cc7218599e7806521d0e737ba5ffb\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2010-08-11 09:21 . 2010-08-11 09:21 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\3057ec53731286e69e389d103c32fa41\Microsoft.Build.Engine.ni.dll
+ 2010-08-11 09:20 . 2010-08-11 09:20 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\914e338ac6e92714f3e32ae5d89bf03b\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 230400 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\c2396d95d397f4292aa7a928ca1bbc1f\Microsoft.ApplicationBlocks.Updater.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 338944 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\b686cc597df38918b464c038008a1f35\DriversHQ.DriverDetective.Client.Communication.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\95215f55e53b86337954c7ca2480e195\DriversHQ.DriverDetective.Common.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 529920 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.Common\f24f0553025c0fa9c7cc2230fffe2e78\DriversHQ.Common.ni.dll
+ 2010-08-11 09:20 . 2010-08-11 09:20 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\12ae6f3635448471fc9f7d8bfe39c67d\CustomMarshalers.ni.dll
+ 2010-08-11 09:20 . 2010-08-11 09:20 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\daca3c9ad6d867d3fec70d14b4f20cf3\ComSvcConfig.ni.exe
+ 2010-08-11 09:18 . 2010-08-11 09:18 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\56aec0938ef1bbdeca65b07a5fe8cd39\AspNetMMCExt.ni.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2010-07-23 07:08 . 2010-07-23 07:08 970752 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2010-07-23 07:08 . 2010-07-23 07:08 438272 c:\windows\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2010-08-11 07:07 . 2010-08-11 07:07 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2010-08-11 07:07 . 2010-08-11 07:07 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2010-08-11 07:07 . 2010-08-11 07:07 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2010-08-11 07:07 . 2010-08-11 07:07 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2010-07-23 07:08 . 2010-07-23 07:08 110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
- 2010-07-22 07:09 . 2010-07-22 07:09 110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2010-08-11 07:07 . 2010-08-11 07:07 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2010-07-23 07:16 . 2007-11-30 11:18 382840 c:\windows\$NtUninstallKB961118$\spuninst\updspapi.dll
+ 2010-07-23 07:16 . 2007-11-30 11:18 231288 c:\windows\$NtUninstallKB961118$\spuninst\spuninst.exe
- 2001-08-23 12:00 . 2010-05-04 17:20 1168384 c:\windows\system32\urlmon.dll
+ 2001-08-23 12:00 . 2010-06-24 12:15 1168384 c:\windows\system32\urlmon.dll
+ 2001-08-23 12:00 . 2010-07-27 06:30 8462336 c:\windows\system32\shell32.dll
- 2001-08-23 12:00 . 2010-02-17 13:10 2189952 c:\windows\system32\ntoskrnl.exe
+ 2001-08-23 12:00 . 2010-04-28 02:25 2189952 c:\windows\system32\ntoskrnl.exe
+ 2001-08-17 13:48 . 2010-04-27 13:05 2066816 c:\windows\system32\ntkrnlpa.exe
- 2001-08-17 13:48 . 2010-02-16 13:25 2066816 c:\windows\system32\ntkrnlpa.exe
+ 2001-08-23 12:00 . 2010-06-24 12:15 3600896 c:\windows\system32\mshtml.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 6067200 c:\windows\system32\ieframe.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 6067200 c:\windows\system32\ieframe.dll
+ 2009-08-14 13:21 . 2010-06-23 13:44 1851904 c:\windows\system32\dllcache\win32k.sys
- 2009-09-25 05:37 . 2010-05-04 17:20 1168384 c:\windows\system32\dllcache\urlmon.dll
+ 2009-09-25 05:37 . 2010-06-24 12:15 1168384 c:\windows\system32\dllcache\urlmon.dll
+ 2008-06-17 19:02 . 2010-07-27 06:30 8462336 c:\windows\system32\dllcache\shell32.dll
- 2009-12-07 18:24 . 2010-02-17 13:10 2189952 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2009-12-07 18:24 . 2010-04-28 02:25 2189952 c:\windows\system32\dllcache\ntoskrnl.exe
- 2009-12-07 18:24 . 2010-02-16 13:25 2024448 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-12-07 18:24 . 2010-04-27 13:05 2024448 c:\windows\system32\dllcache\ntkrpamp.exe
- 2009-02-08 00:02 . 2010-02-16 13:25 2066816 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2009-02-08 00:02 . 2010-04-27 13:05 2066816 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2009-12-07 18:24 . 2010-04-27 13:59 2146304 c:\windows\system32\dllcache\ntkrnlmp.exe
- 2009-12-07 18:24 . 2010-02-16 14:08 2146304 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2009-12-07 17:54 . 2010-06-14 07:41 1172480 c:\windows\system32\dllcache\msxml3.dll
- 2009-12-07 17:54 . 2009-07-31 04:35 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2009-09-25 05:37 . 2010-06-24 12:15 3600896 c:\windows\system32\dllcache\mshtml.dll
+ 2010-03-11 00:03 . 2010-06-18 13:36 3558912 c:\windows\system32\dllcache\moviemk.exe
- 2010-03-11 00:03 . 2009-10-23 15:28 3558912 c:\windows\system32\dllcache\moviemk.exe
- 2009-12-07 19:32 . 2010-05-04 17:20 6067200 c:\windows\system32\dllcache\ieframe.dll
+ 2009-12-07 19:32 . 2010-06-24 12:15 6067200 c:\windows\system32\dllcache\ieframe.dll
+ 2009-11-07 05:06 . 2009-11-07 05:06 1130824 c:\windows\system32\dfshim.dll
+ 2010-04-08 03:48 . 2010-04-08 03:48 5967872 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll
- 2008-11-25 08:59 . 2008-11-25 08:59 5242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2010-03-23 09:32 . 2010-03-23 09:32 5242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2010-03-23 09:32 . 2010-03-23 09:32 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2010-05-11 10:40 . 2010-05-11 10:40 5812560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2010-05-11 10:40 . 2010-05-11 10:40 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2009-11-09 04:25 . 2009-11-09 04:25 1935360 c:\windows\Installer\503af3e.msp
+ 2010-04-12 02:17 . 2010-04-12 02:17 2607104 c:\windows\Installer\503af0d.msp
+ 2010-04-12 02:17 . 2010-04-12 02:17 4210688 c:\windows\Installer\503af0c.msp
+ 2010-06-20 08:01 . 2010-06-20 08:01 8040960 c:\windows\Installer\26e450.msp
+ 2010-08-11 07:10 . 2010-05-04 17:20 1168384 c:\windows\ie7updates\KB2183461-IE7\urlmon.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 3600384 c:\windows\ie7updates\KB2183461-IE7\mshtml.dll
+ 2010-08-11 07:10 . 2010-05-04 17:20 6067200 c:\windows\ie7updates\KB2183461-IE7\ieframe.dll
- 2009-12-07 18:24 . 2010-02-17 13:10 2189952 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2009-12-07 18:24 . 2010-04-28 02:25 2189952 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2009-12-07 18:24 . 2010-02-16 13:25 2024448 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-12-07 18:24 . 2010-04-27 13:05 2024448 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-02-08 00:02 . 2010-04-27 13:05 2066816 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2009-02-08 00:02 . 2010-02-16 13:25 2066816 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-12-07 18:24 . 2010-04-27 13:59 2146304 c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2009-12-07 18:24 . 2010-02-16 14:08 2146304 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2010-08-11 07:10 . 2010-08-11 07:10 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cec7ecb8eac09dd630d180ce87d23b80\WindowsBase.ni.dll
+ 2010-08-11 07:19 . 2010-08-11 07:19 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\b7f6e7b265f9aae807ddc4284563e550\UIAutomationClientsideProviders.ni.dll
+ 2010-08-11 07:10 . 2010-08-11 07:10 7949824 c:\windows\assembly\NativeImages_v2.0.50727_32\System\08ffa4d388d5f007869aa7651c458e7c\System.ni.dll
+ 2010-08-11 07:19 . 2010-08-11 07:19 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\a6dbe24cbfe3ab6b318ed3095cc572d8\System.Xml.ni.dll
+ 2010-08-11 09:31 . 2010-08-11 09:31 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\60b3c9a63b2065a6952d16256545c25d\System.WorkflowServices.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\5cc2a23ce8ac371c7a97b5e542ee27ed\System.Workflow.Runtime.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\c0aabf67e7ef98dc10c3e174c136731b\System.Workflow.ComponentModel.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\66682c8a064608ba4ffd0463cf09aef9\System.Workflow.Activities.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\2d662564b8d9c57a34c588cc2970902b\System.Web.Services.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\9b455702c9b7b02c5708406f87986751\System.Web.Mobile.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 2403328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\49c7a1c78ed9502ba97c11e6bd993f63\System.Web.Extensions.ni.dll
+ 2010-08-11 07:17 . 2010-08-11 07:17 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\5eb08849d17b272ed2a393420cb0305b\System.Speech.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\f5790a1b7b41e7b8d05f01b549c80f39\System.ServiceModel.Web.ni.dll
+ 2010-08-11 09:20 . 2010-08-11 09:20 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\8061a0f5c1c2ee0549e19224352f67fa\System.Runtime.Serialization.ni.dll
+ 2010-08-11 07:17 . 2010-08-11 07:17 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\99767d4df92b83fdfb06012512722ec1\System.Printing.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\0885f31c21b796465fde6297dba20981\System.IdentityModel.ni.dll
+ 2010-08-11 07:17 . 2010-08-11 07:17 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dcc0244092fe52e6885b50be25ef3b31\System.Drawing.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\d20b7e58607ddb1ded9b687627ae8c21\System.DirectoryServices.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\daa33674d4250e38a24b70180d209ac8\System.Deployment.ni.dll
+ 2010-08-11 07:17 . 2010-08-11 07:17 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\f04ef00e652a8655a717639e8aeb7b63\System.Data.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\f0470c2be4e6bb1dadbeed43e4e8af5c\System.Data.SqlXml.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\23cf0498f2ebe4c8ffa5cc79efca2dc5\System.Data.Services.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 1115136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\58202ed61096113d08815c0a78313b66\System.Data.OracleClient.ni.dll
+ 2010-08-11 07:17 . 2010-08-11 07:17 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\c18c236a09e715138daec2e25be205bb\System.Data.Linq.ni.dll
+ 2010-08-11 09:22 . 2010-08-11 09:22 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\6ce886492d9b6a34555be3f328682ec2\System.Data.Entity.ni.dll
+ 2010-08-11 07:16 . 2010-08-11 07:16 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\faeda674832135a080bc73eda51813ff\System.Core.ni.dll
+ 2010-08-11 07:16 . 2010-08-11 07:16 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\3e85c3d63ce3c3f37061aa626feb2a52\ReachFramework.ni.dll
+ 2010-08-11 07:16 . 2010-08-11 07:16 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\bf67db30179ff6e8cb1bdbaa290d122e\PresentationUI.ni.dll
+ 2010-08-11 07:10 . 2010-08-11 07:10 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\835786d8a0caabae09ad440f6e3abfc6\PresentationBuildTasks.ni.dll
+ 2010-08-11 09:21 . 2010-08-11 09:21 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\9732a7c993055f82040642966db07ccf\Microsoft.VisualBasic.ni.dll
+ 2010-08-11 09:20 . 2010-08-11 09:20 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\773d7bf69a9a0c0556aa41f53e75ab05\Microsoft.Transactions.Bridge.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\16ff33f07efdb9da2a18e27585c604be\Microsoft.JScript.ni.dll
+ 2010-08-11 09:21 . 2010-08-11 09:21 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\d0fb91b296616a1a844bf265947018ee\Microsoft.Build.Tasks.ni.dll
+ 2010-08-11 09:21 . 2010-08-11 09:21 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\892e993c8df1c75081113131dc429c15\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2010-08-11 09:20 . 2010-08-11 09:20 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\d0beebd2c9045158cdcd4bd5987b717b\Microsoft.Build.Engine.ni.dll
+ 2010-08-11 09:18 . 2010-08-11 09:18 3916288 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\1bc348a5fef4d6061bb3415f4f486969\DriversHQ.DriverDetective.Client.ni.exe
+ 2010-07-23 07:15 . 2010-07-23 07:15 1249280 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2010-08-11 07:07 . 2010-08-11 07:07 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2010-07-23 07:08 . 2010-07-23 07:08 5967872 c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2010-07-23 07:15 . 2010-07-23 07:15 5279744 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2010-07-22 07:14 . 2010-07-22 07:14 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2010-08-11 07:07 . 2010-08-11 07:07 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2010-07-22 07:09 . 2010-07-22 07:09 4210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2010-07-23 07:15 . 2010-07-23 07:15 4210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2010-08-11 07:06 . 2010-08-11 07:06 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2009-12-07 19:04 . 2010-08-03 18:09 35962312 c:\windows\system32\MRT.exe
+ 2010-05-19 17:08 . 2010-05-19 17:08 11408896 c:\windows\Installer\8e81582.msp
+ 2009-08-15 00:32 . 2009-08-15 00:32 11110912 c:\windows\Installer\503af53.msp
+ 2010-03-31 05:23 . 2010-03-31 05:23 15638528 c:\windows\Installer\503af4a.msp
+ 2010-04-12 02:17 . 2010-04-12 02:17 14599680 c:\windows\Installer\503af1b.msp
+ 2010-08-11 07:18 . 2010-08-11 07:18 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\439c466b60614915587c5273eaf0ca7f\System.Windows.Forms.ni.dll
+ 2010-08-11 09:19 . 2010-08-11 09:19 11798016 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\411a627d6f5cb83509332253406988e5\System.Web.ni.dll
+ 2010-08-11 09:20 . 2010-08-11 09:20 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\f523a69e7c93ee4f245c996eac4b3a57\System.ServiceModel.ni.dll
+ 2010-08-11 07:17 . 2010-08-11 07:17 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\b307acf63075b997d02a97a7492d0d9c\System.Design.ni.dll
+ 2010-08-11 07:12 . 2010-08-11 07:13 14328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a632f3ef85ffd35341b383eed577cb93\PresentationFramework.ni.dll
+ 2010-08-11 07:11 . 2010-08-11 07:11 12215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\f00db8db51f5707c7fe52c0683dc6136\PresentationCore.ni.dll
+ 2010-08-11 07:09 . 2010-08-11 07:09 11490816 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7bffd7ff2009f421fe5d229927588496\mscorlib.ni.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-06-16 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATT-SST_McciTrayApp"="c:\program files\ATT-SST\McciTrayApp.exe" [2010-06-30 1573888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe" [2009-12-09 240992]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
OnlyWire.LNK - c:\program files\OnlyWire\OnlyWireWindows.exe [2010-6-23 621384]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 β€”-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 β€”-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 β€”-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 β€”-a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-09-20 02:48 455968 β€”-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 β€”-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 19:57 153136 β€”-a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
2010-01-05 10:20 160592 β€”-a-w- c:\program files\Siber Systems\AI RoboForm\robotaskbaricon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2007-04-16 19:28 577536 β€”-a-w- c:\windows\soundman.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-11 20:21 246504 β€”-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-08-07 02:42 2403568 β€”-a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
2006-09-14 23:54 53248 β€”-a-w- c:\windows\system32\VTTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]
2007-04-25 20:41 176128 β€”-a-w- c:\windows\system32\VTTrayp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2006-11-04 00:20 866584 β€”-a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\ATT-HSI\\McciBrowser.exe"=
"c:\\Program Files\\OnlyWire\\OnlyWireWindows.exe"=
"c:\\Program Files\\SUPERAntiSpyware\\SUPERANTISPYWARE.EXE"=
"c:\\Program Files\\SUPERAntiSpyware\\RUNSAS.EXE"=

R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [11/23/2009 9:43 AM 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/23/2009 9:43 AM 67656]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [6/16/2010 12:42 AM 136176]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [11/23/2009 9:43 AM 12872]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe –> c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-09-20 02:46 451872 β€”-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-08-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2010-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-16 04:42]

2010-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-16 04:42]

2010-08-26 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
β€”β€”- Supplementary Scan β€”β€”-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride =
uInternet Settings,ProxyServer = http=127.0.0.1:6522
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\uuaj139b.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=BABTDF&PC=BBLN&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=BABTDF&PC=BBLN&q=
FF - component: c:\program files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\components\SEPsearchhelperff.dll
FF - component: c:\program files\Siber Systems\AI RoboForm\Firefox\components\rfproxy_31.dll
FF - plugin: c:\documents and settings\user\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\Common Files\Motive\npMotive.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

β€”- FIREFOX POLICIES β€”-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-kbbhwkpn - c:\documents and settings\user\Local Settings\Application Data\erxusnukg\khqvafkshdw.exe
HKLM-Run-kbbhwkpn - c:\documents and settings\user\Local Settings\Application Data\erxusnukg\khqvafkshdw.exe
MSConfigStartUp-avgnt - c:\program files\Avira\AntiVir Desktop\avgnt.exe
AddRemove-LAME for Audacity_is1 - c:\documents and settings\user\My Documents\Mekas Files\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-26 00:57
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
β€”β€”β€”β€”β€”β€”β€” DLLs Loaded Under Running Processes β€”β€”β€”β€”β€”β€”β€”

- - - - - - - > 'winlogon.exe'(232)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
.
Completion time: 2010-08-26 01:00:07
ComboFix-quarantined-files.txt 2010-08-26 04:59
ComboFix2.txt 2010-07-22 07:34
ComboFix3.txt 2010-07-20 11:02

Pre-Run: 22,946,025,472 bytes free
Post-Run: 23,211,724,800 bytes free

- - End Of File - - 23C63EC811A1627F8258BE62A6B18D70

The pop ups have stopped btw.
Please do the following


COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    DDS::
    uInternet Settings,ProxyServer = http=127.0.0.1:6522
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.





  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.






I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.


How is your computer running now?
EST Scan Results

C:\Documents and Settings\user\My Documents\Downloads\AutoClick.exe Win32/TrojanClicker.Agent.NFX trojan
C:\Documents and Settings\user\My Documents\Downloads\avi2video_install.exe Win32/Adware.MarketScore.A application
C:\Qoobox\Quarantine\C\Documents and Settings\user\Local Settings\Application Data\erxusnukg\khqvafkshdw.exe.vir Win32/Adware.SpywareProtect2009 application
C:\System Volume Information\_restore{7DBA9B48-CDAC-44D6-B9BB-C42570EAE0A1}\RP276\A0501679.exe Win32/Adware.SpywareProtect2009 application


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4487

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

8/26/2010 8:00:11 PM
mbam-log-2010-08-26 (20-00-11).txt

Scan type: Quick scan
Objects scanned: 129845
Time elapsed: 6 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


ComboFix 10-08-24.0C - user 08/26/2010 17:55:53.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.483 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\user\Desktop\CFScript.txt
.

((((((((((((((((((((((((( Files Created from 2010-07-26 to 2010-08-26 )))))))))))))))))))))))))))))))
.

2010-08-24 21:40 . 2010-08-24 21:40 ——– d—–w- C:\Cache
2010-08-01 23:53 . 2010-08-01 23:53 ——– d—–w- c:\program files\Market Samurai
2010-07-31 18:25 . 2010-07-31 18:25 ——– d—–w- c:\program files\Lame for Audacity
2010-07-31 17:54 . 2010-07-31 17:54 ——– d—–w- c:\program files\Audacity
2010-07-29 02:58 . 2010-07-29 02:58 ——– d—–w- c:\program files\Auto Clicker

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-26 22:00 . 2010-07-13 00:32 ——– d—–w- c:\program files\OnlyWire
2010-08-26 03:26 . 2010-07-12 20:16 ——– d—–w- c:\documents and settings\All Users\Application Data\ATTYToolbar
2010-08-12 20:57 . 2010-07-12 20:16 ——– d—–w- c:\documents and settings\user\Application Data\Yahoo!
2010-08-11 09:38 . 2009-12-07 20:28 68648 β€”-a-w- c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-07 02:45 . 2010-06-01 10:53 63488 β€”-a-w- c:\documents and settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-08-07 02:44 . 2009-12-10 16:23 117760 β€”-a-w- c:\documents and settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-08-07 02:42 . 2009-12-10 16:22 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-08-02 00:04 . 2010-05-24 04:16 55172 β€”ha-w- c:\windows\system32\mlfcache.dat
2010-07-23 09:02 . 2010-07-23 09:02 ——– d—–w- c:\program files\ESET
2010-07-22 07:09 . 2010-07-22 07:09 ——– d—–w- c:\program files\MSBuild
2010-07-22 07:09 . 2010-07-22 07:09 ——– d—–w- c:\program files\Reference Assemblies
2010-07-21 18:23 . 2010-07-21 18:23 ——– d—–w- c:\documents and settings\user\Application Data\Media Player Classic
2010-07-21 15:51 . 2010-07-21 15:51 ——– d—–w- c:\program files\XP Codec Pack
2010-07-21 15:16 . 2010-07-21 15:16 ——– d—–w- c:\program files\Realtek AC97
2010-07-21 15:16 . 2009-12-07 21:20 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-07-21 15:09 . 2010-07-21 15:09 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2010-07-21 15:08 . 2010-07-21 15:08 ——– d—–w- c:\program files\PC Drivers HeadQuarters
2010-07-21 14:35 . 2010-07-21 14:34 ——– d—–w- c:\program files\MSN Toolbar Installer
2010-07-21 14:35 . 2010-01-27 16:54 ——– d—–w- c:\program files\Microsoft
2010-07-21 14:35 . 2010-07-21 14:35 ——– d—–w- c:\program files\MSN Toolbar
2010-07-21 14:35 . 2010-07-21 14:35 ——– d—–w- c:\program files\Microsoft Silverlight
2010-07-21 14:34 . 2010-07-21 14:34 ——– d—–w- c:\documents and settings\All Users\Application Data\UAB
2010-07-21 14:34 . 2010-07-21 14:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Driver Inspector
2010-07-21 14:31 . 2010-07-21 14:31 ——– d—–w- c:\program files\Driver Inspector
2010-07-21 13:49 . 2010-07-21 13:49 ——– d—–w- c:\program files\Conduit
2010-07-21 06:34 . 2010-07-21 06:33 ——– d—–w- c:\program files\QuickTime
2010-07-21 06:33 . 2010-07-21 06:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-07-20 11:39 . 2010-07-20 11:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-07-13 03:39 . 2010-07-12 18:56 ——– d—–w- c:\program files\Common Files\Motive
2010-07-13 01:03 . 2010-05-24 02:32 ——– d—–w- c:\program files\Traffic Travis v3
2010-07-13 01:03 . 2010-06-15 03:46 4703927 β€”-a-w- c:\documents and settings\user\Application Data\Affilorama\TrafficTravisv3\temp\traffic_travis.exe
2010-07-13 00:32 . 2010-07-13 00:32 ——– d—–w- c:\program files\Common Files\Snipitron LLC
2010-07-12 20:43 . 2010-07-12 18:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Motive
2010-07-12 20:38 . 2010-07-12 18:57 ——– d—–w- c:\documents and settings\user\Application Data\Motive
2010-07-12 20:38 . 2010-07-12 20:36 ——– d—–w- c:\program files\ATT-SST
2010-07-12 20:32 . 2010-07-12 20:32 ——– d—–w- c:\program files\ATT
2010-07-12 20:18 . 2010-07-12 20:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-07-12 20:16 . 2010-07-12 20:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-07-12 20:16 . 2010-07-12 20:16 ——– d—–w- c:\program files\Yahoo!
2010-07-12 18:56 . 2010-07-12 18:56 ——– d—–w- c:\program files\ATT-HSI
2010-06-30 12:31 . 2001-08-23 12:00 149504 β€”-a-w- c:\windows\system32\schannel.dll
2010-06-24 12:15 . 2001-08-23 12:00 832512 β€”-a-w- c:\windows\system32\wininet.dll
2010-06-24 12:15 . 2009-12-07 19:54 78336 β€”β€”w- c:\windows\system32\ieencode.dll
2010-06-24 12:15 . 2001-08-23 12:00 17408 β€”-a-w- c:\windows\system32\corpol.dll
2010-06-23 13:44 . 2001-08-23 12:00 1851904 β€”-a-w- c:\windows\system32\win32k.sys
2010-06-22 23:07 . 2010-06-22 23:07 501936 β€”-a-w- c:\documents and settings\All Users\Application Data\Google\Google Toolbar\Update\gtb22AD.tmp.exe
2010-06-21 15:27 . 2001-08-23 12:00 354304 β€”-a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2001-08-23 12:00 80384 β€”-a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2009-12-07 19:35 744448 β€”-a-w- c:\windows\PCHEALTH\HELPCTR\Binaries\helpsvc.exe
2010-06-14 07:41 . 2001-08-23 12:00 1172480 β€”-a-w- c:\windows\system32\msxml3.dll
.

((((((((((((((((((((((((((((( SnapShot_2010-08-26_04.57.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-26 21:50 . 2010-08-26 21:50 16384 c:\windows\temp\Perflib_Perfdata_6e4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-06-16 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATT-SST_McciTrayApp"="c:\program files\ATT-SST\McciTrayApp.exe" [2010-06-30 1573888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe" [2009-12-09 240992]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
OnlyWire.LNK - c:\program files\OnlyWire\OnlyWireWindows.exe [2010-6-23 621384]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 β€”-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 β€”-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 β€”-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 β€”-a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-09-20 02:48 455968 β€”-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 β€”-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 19:57 153136 β€”-a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
2010-01-05 10:20 160592 β€”-a-w- c:\program files\Siber Systems\AI RoboForm\robotaskbaricon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2007-04-16 19:28 577536 β€”-a-w- c:\windows\soundman.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-11 20:21 246504 β€”-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-08-07 02:42 2403568 β€”-a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
2006-09-14 23:54 53248 β€”-a-w- c:\windows\system32\VTTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]
2007-04-25 20:41 176128 β€”-a-w- c:\windows\system32\VTTrayp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2006-11-04 00:20 866584 β€”-a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\ATT-HSI\\McciBrowser.exe"=
"c:\\Program Files\\OnlyWire\\OnlyWireWindows.exe"=
"c:\\Program Files\\SUPERAntiSpyware\\SUPERANTISPYWARE.EXE"=
"c:\\Program Files\\SUPERAntiSpyware\\RUNSAS.EXE"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [11/23/2009 9:43 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/23/2009 9:43 AM 67656]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [6/16/2010 12:42 AM 136176]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [11/23/2009 9:43 AM 12872]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe –> c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-09-20 02:46 451872 β€”-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-08-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2010-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-16 04:42]

2010-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-16 04:42]

2010-08-26 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
β€”β€”- Supplementary Scan β€”β€”-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride =
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\uuaj139b.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=BABTDF&PC=BBLN&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=BABTDF&PC=BBLN&q=
FF - component: c:\program files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\components\SEPsearchhelperff.dll
FF - component: c:\program files\Siber Systems\AI RoboForm\Firefox\components\rfproxy_31.dll
FF - plugin: c:\documents and settings\user\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\Common Files\Motive\npMotive.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

β€”- FIREFOX POLICIES β€”-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-26 18:00
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
β€”β€”β€”β€”β€”β€”β€” DLLs Loaded Under Running Processes β€”β€”β€”β€”β€”β€”β€”

- - - - - - - > 'winlogon.exe'(692)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(1028)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-08-26 18:02:21
ComboFix-quarantined-files.txt 2010-08-26 22:02
ComboFix2.txt 2010-08-26 05:00
ComboFix3.txt 2010-07-22 07:34
ComboFix4.txt 2010-07-20 11:02

Pre-Run: 23,190,134,784 bytes free
Post-Run: 23,189,774,336 bytes free

- - End Of File - - B8AAC772EF0CB44EE100A7E0BD9B6F77

Computer seems to be running normally. There are no more popups.
Delete these two files

C:\Documents and Settings\user\My Documents\Downloads\AutoClick.exe
C:\Documents and Settings\user\My Documents\Downloads\avi2video_install.exe

You now appear clean of infections.Please do the following

Delete GMER,ESET,HJT DDS and any logs you have.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
πŸ–ΌClick to load external image (Posted Image)




[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 21 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 21 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u21 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Javaβ„’ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u21-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.




Clean out your temp files.
Download Attribune's ATF Cleaner and save to your desktop.
Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program
.



Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smΓΆrgΓ₯sbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI