This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack this please

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

can anyone help me with this

This is hijacklog from me.izit have any problem with malware?

Thank you :)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:19:52 PM, on 15/1/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe
C:\Users\Firdaus\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
C:\Users\Firdaus\AppData\Roaming\whitepixel\HKEY_LOCAL_MACHINE.exe
C:\Users\Firdaus\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86) (x86)\Lexmark 2600 Series\ezprint.exe
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Users\Firdaus\Downloads\Microsoft Office Professional Plus 2010 Activator [blaze69]\keygen.exe
C:\Users\Firdaus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Firdaus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Firdaus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Firdaus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Firdaus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Firdaus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.ap.dell.com/content/default.as…;l=en&s=gen
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2737658
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.Facesounds.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 211.138.124.232:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;172.16.110.33:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FAIESSO Helper Object - {A2F122DA-055F-4df7-8F24-7354DBDBA85B} - c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: eSnipBHO - {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [FATrayAlert] c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
O4 - HKLM\..\Run: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [lxdnmon.exe] "C:\Program Files (x86) (x86)\Lexmark 2600 Series\lxdnmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files (x86) (x86)\Lexmark 2600 Series\ezprint.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Users\Firdaus\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Users\Firdaus\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
O4 - HKCU\..\Run: [HKEY_LOCAL_MACHINE] C:\Users\Firdaus\AppData\Roaming\whitepixel\HKEY_LOCAL_MACHINE.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Send image to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\vmware\vmware workstation\vsocklib.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{0282556B-EA02-4ABF-8C86-0127D44031AF}: NameServer = 10.54.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{B641FD9E-0457-4CDF-A47A-E824C18C2D7F}: NameServer = 208.67.222.222,208.67.222.220
O17 - HKLM\System\CS1\Services\Tcpip\..\{0282556B-EA02-4ABF-8C86-0127D44031AF}: NameServer = 10.54.0.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{0282556B-EA02-4ABF-8C86-0127D44031AF}: NameServer = 10.54.0.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: FastAccess - c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: FAService - Sensible Vision - c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 16521 bytes

there was a popups that show ''The application failed to initialize'
I tried to run my virus scan and malwarebytes' anti-malware but the pupup still appear when i restart my computer.
Then i created a hijack log
Anyone can help me with this?

Regard,

Firdaus
Hello and :welcome:

I will be helping you remove malware on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • If you do not reply within 3 days after my last response, I will be asking you whether you still need assistance and if you still don't reply within 48 hours then the topic will be closed.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________


You will need to right click and choose "Run as Administrator" to run the tools we will use.


Windows 7's restore is excellent. Let's try running system restore to a date prior to the computer problem first and see how it goes:
  • Restart your computer to the System Recovery Options screen.
  • Select the System Restore option.
  • Click on the System Restore button.
  • If You Have Not Done a System Restore Before -
    • Click on the Next button
  • If You Have Done a System Restore Before -
    • Select (dot) Choose a different restore point, and click on the Next buton.
  • Select (click on) a listed restore point that you want to restore Windows 7 back to. Choose a date prior to your computer problems.
    NOTE: Check the Show other restore points box to see any restore points (older) that may not be listed here.
  • Click on the Next button.
    NOTE: Make sure that the restore point you want is still selected (highlighted).
  • Click on the Finish button.
  • Click on Yes to confirm.
    WARNING: This will immediately restart your computer to finish the system restore.
  • After the computer has restarted, click on the Close button.
Source with pictures: http://www.sevenforums.com/tutorials/700-system-restore.html

–Next–

Please download DDS by sUBs from one of the following links and save it to your desktop.

    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel.
  • Browse for the attachment file you want to upload, then click the green Upload button.
  • Once it has uploaded, click the Manage Current Attachments drop down box.
  • Click on to insert the attachment into your post
Please post both DDS logs in your next reply.

–Next–

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

[external image: Posted Image]
Click the image to enlarge it

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
  • Right click GMER.exe then choose "Run as Administrator" to run the tool.
    [external image: Posted Image]
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
      [external image: Posted Image]
      Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Please copy and paste the report into your Post.

To post in your next reply:
1. The problem gone?
2. DDS logs.
3. GMER log.
Hi,

There issue is still there. Every time i restart my machine, the popup 'The application failed to initialize' still appear.Help me please

DDS log

DDS (Ver_10-12-12.02) - NTFS_AMD64
Run by [removed] at 22:25:53.38 on Mon 17/01/2011
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_23
Microsoft Windows 7 Home Basic 6.1.7600.0.1252.60.1033.18.2010.826 [GMT 8:00]

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\system32\taskhost.exe
c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
C:\Windows\SysWOW64\vmnat.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
C:\Windows\SysWOW64\vmnetdhcp.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Shadow Defender\DefenderDaemon.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
C:\Users\Firdaus\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
C:\Users\Firdaus\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\Windows\system32\SearchIndexer.exe
C:\Users\Firdaus\AppData\Roaming\whitepixel\HKEY_LOCAL_MACHINE.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86) (x86)\Lexmark 2600 Series\lxdnmon.exe
C:\Program Files (x86) (x86)\Lexmark 2600 Series\ezprint.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\System32\jusched.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Users\Firdaus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Firdaus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Firdaus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskhost.exe
C:\Users\Firdaus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Users\Firdaus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Dell Support Center\pcdrcui.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Firdaus\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uSearch Page =
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2737658
uDefault_Page_URL = hxxp://www1.ap.dell.com/content/default.aspx?c=my&l=en&s=gen
uSearch Bar =
mStart Page = hxxp://search.Facesounds.com
uInternet Settings,ProxyOverride = local;172.16.110.33:80
uInternet Settings,ProxyServer = 211.138.124.232:80
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: FAIESSOHelper Class: {a2f122da-055f-4df7-8f24-7354dbdba85b} - c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll
BHO: {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Google Update] "C:\Users\Firdaus\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
uRun: [Octoshape Streaming Services] "C:\Users\Firdaus\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
uRun: [HKEY_LOCAL_MACHINE] C:\Users\Firdaus\AppData\Roaming\whitepixel\HKEY_LOCAL_MACHINE.exe
mRun: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
mRun: [FATrayAlert] c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
mRun: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [FAStartup]
mRun: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
mRun: [lxdnmon.exe] "C:\Program Files (x86) (x86)\Lexmark 2600 Series\lxdnmon.exe"
mRun: [EzPrint] "C:\Program Files (x86) (x86)\Lexmark 2600 Series\ezprint.exe"
mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe
StartupFolder: C:\Users\Firdaus\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLDO~1.LNK - C:\Program Files\Dell\DellDock\DellDock.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
TCP: {0282556B-EA02-4ABF-8C86-0127D44031AF} = 10.54.0.1
TCP: {B641FD9E-0457-4CDF-A47A-E824C18C2D7F} = 208.67.222.222,208.67.222.220
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Notify: FastAccess - c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll
LSA: Notification Packages = scecli FAPassSync
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
BHO-X64: Hotspot Shield Class: {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
mRun-x64: [Apoint] C:\Program Files\DellTPad\Apoint.exe
mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe
mRun-x64: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe
mRun-x64: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
mRun-x64: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe
mRun-x64: [Shadow Defender Daemon] "C:\Program Files\Shadow Defender\DefenderDaemon.exe" /Auto
mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

================= FIREFOX ===================

FF - ProfilePath - C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2737658&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - prefs.js: keyword.URL - hxxp://search.Facesounds.com/?q=
FF - prefs.js: network.proxy.ftp - 211.138.124.232
FF - prefs.js: network.proxy.ftp_port - 80
FF - prefs.js: network.proxy.gopher - [removed]
FF - prefs.js: network.proxy.gopher_port - 80
FF - prefs.js: network.proxy.http - [removed]
FF - prefs.js: network.proxy.http_port - 80
FF - prefs.js: network.proxy.socks - [removed]
FF - prefs.js: network.proxy.socks_port - 80
FF - prefs.js: network.proxy.ssl - 211.138.124.232
FF - prefs.js: network.proxy.ssl_port - 80
FF - prefs.js: network.proxy.type - 0
FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - component: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordlegacyext.dll
FF - component: C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\components\FFExternalAlert.dll
FF - component: C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\components\RadioWMPCore.dll
FF - component: C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
FF - component: C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\extensions\{f999a48b-1950-4d81-9971-79018f807b4b}\components\FFExternalAlert.dll
FF - component: C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\extensions\{f999a48b-1950-4d81-9971-79018f807b4b}\components\RadioWMPCore.dll
FF - component: C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Users\Firdaus\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Users\Firdaus\AppData\Local\Yahoo!\BrowserPlus\2.7.1\Plugins\npybrowserplus_2.7.1.dll
FF - plugin: C:\Users\Firdaus\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: C:\Users\Firdaus\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension for Firefox: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Cooliris: [removed] - %profile%\extensions\[removed]
FF - Ext: Softonic English Toolbar: {930f1200-f5f1-4870-bac6-e233ec8e7023} - %profile%\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}
FF - Ext: BitDefender QuickScan: {e001c731-5e37-4538-a5cb-8168736a2360} - %profile%\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
FF - Ext: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - %profile%\extensions\{f999a48b-1950-4d81-9971-79018f807b4b}
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2011-01-15 07:30:33 ——– d—–w- C:\PROGRA~3\Webroot
2011-01-15 07:29:04 ——– d—–w- C:\Users\Firdaus\AppData\Roaming\Uniblue
2011-01-15 07:28:29 ——– d—–w- C:\Users\Firdaus\AppData\Local\PackageAware
2011-01-15 06:31:44 ——– d—–w- C:\Program Files (x86)\Trend Micro
2011-01-14 16:30:48 6315 —-a-w- C:\z.tmp
2011-01-14 16:24:39 ——– d—–w- C:\Windows\PCHEALTH
2011-01-14 16:24:39 ——– d—–w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2011-01-14 16:19:54 ——– d—–w- C:\Program Files (x86)\Microsoft Visual Studio 8
2011-01-14 16:18:30 ——– d—–w- C:\Program Files (x86)\Microsoft Analysis Services
2011-01-14 15:45:09 ——– d—–w- C:\Users\Firdaus\AppData\Roaming\whitepixel
2011-01-14 13:36:29 8199504 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{647E1085-A284-4DEE-B867-99832C3CF38E}\mpengine.dll
2011-01-12 12:07:27 720896 —-a-w- C:\Windows\System32\odbc32.dll
2011-01-12 12:07:26 573440 —-a-w- C:\Windows\SysWow64\odbc32.dll
2011-01-12 12:07:26 495616 —-a-w- C:\Program Files\Common Files\System\ado\msadox.dll
2011-01-12 12:07:26 466944 —-a-w- C:\Program Files\Common Files\System\ado\msadomd.dll
2011-01-12 12:07:26 258048 —-a-w- C:\Program Files\Common Files\System\msadc\msadco.dll
2011-01-12 12:07:26 1425408 —-a-w- C:\Program Files\Common Files\System\ado\msado15.dll
2011-01-12 12:07:25 987136 —-a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll
2011-01-12 12:07:25 372736 —-a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll
2011-01-12 12:07:25 352256 —-a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll
2011-01-12 12:07:25 208896 —-a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll
2011-01-08 11:12:06 ——– d—–w- C:\Windows\XSxS
2011-01-08 11:12:06 ——– d—–w- C:\Users\Firdaus\AppData\Local\Xenocode
2011-01-08 11:12:06 ——– d—–w- C:\Program Files (x86)\Xenocode
2011-01-08 09:49:47 ——– d—–w- C:\Program Files (x86)\Artisteer 2
2011-01-07 20:40:48 253952 —-a-w- C:\Windows\Pjepoa.exe
2011-01-07 20:15:24 ——– d—–w- C:\Users\Firdaus\AppData\Roaming\Artisteer
2011-01-07 11:34:45 ——– d—–w- C:\Program Files (x86)\MySQL
2011-01-07 10:19:00 ——– d—–w- C:\xampp-win32-1.7.3
2011-01-04 11:26:22 ——– d—–w- C:\PROGRA~3\Ezprint

==================== Find3M ====================

2010-11-20 20:57:57 499712 —-a-w- C:\Windows\SysWow64\msvcp71.dll
2010-11-12 10:53:06 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2010-11-04 06:35:53 1194496 —-a-w- C:\Windows\System32\wininet.dll
2010-11-04 06:31:34 57856 —-a-w- C:\Windows\System32\licmgr10.dll
2010-11-04 05:52:17 978944 —-a-w- C:\Windows\SysWow64\wininet.dll
2010-11-04 05:48:36 44544 —-a-w- C:\Windows\SysWow64\licmgr10.dll
2010-11-04 05:16:14 482816 —-a-w- C:\Windows\System32\html.iec
2010-11-04 04:41:26 386048 —-a-w- C:\Windows\SysWow64\html.iec
2010-11-04 04:35:37 1638912 —-a-w- C:\Windows\System32\mshtml.tlb
2010-11-04 04:08:54 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2010-11-02 05:18:17 524288 —-a-w- C:\Windows\System32\wmicmiplugin.dll
2010-11-02 05:17:38 473600 —-a-w- C:\Windows\System32\taskcomp.dll
2010-11-02 05:17:38 1169408 —-a-w- C:\Windows\System32\taskschd.dll
2010-11-02 05:16:53 1114624 —-a-w- C:\Windows\System32\schedsvc.dll
2010-11-02 05:10:47 464384 —-a-w- C:\Windows\System32\taskeng.exe
2010-11-02 05:10:32 285696 —-a-w- C:\Windows\System32\schtasks.exe
2010-11-02 04:40:36 496128 —-a-w- C:\Windows\SysWow64\taskschd.dll
2010-11-02 04:40:36 305152 —-a-w- C:\Windows\SysWow64\taskcomp.dll
2010-11-02 04:34:44 192000 —-a-w- C:\Windows\SysWow64\taskeng.exe
2010-11-02 04:34:33 179712 —-a-w- C:\Windows\SysWow64\schtasks.exe
2010-10-27 05:06:22 2048 —-a-w- C:\Windows\System32\tzres.dll
2010-10-27 04:32:36 2048 —-a-w- C:\Windows\SysWow64\tzres.dll
2010-10-20 05:20:01 46080 —-a-w- C:\Windows\System32\atmlib.dll
2010-10-20 04:54:18 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll
2010-10-20 03:09:15 3124224 —-a-w- C:\Windows\System32\win32k.sys
2010-10-20 03:05:46 367104 —-a-w- C:\Windows\System32\atmfd.dll
2010-10-20 02:58:41 294400 —-a-w- C:\Windows\SysWow64\atmfd.dll

============= FINISH: 22:29:02.71 ===============


GMER log

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-01-18 01:00:15
Windows 6.1.7600
Running: gmer.exe


—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\904ce5d84474
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\904ce5d84474@001963f45a34 0x63 0x0B 0x21 0x01 …
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\904ce5d84474@6c0e0d0f6e89 0x88 0x70 0xE7 0xA7 …
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\904ce5d84474 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\904ce5d84474@001963f45a34 0x63 0x0B 0x21 0x01 …
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\904ce5d84474@6c0e0d0f6e89 0x88 0x70 0xE7 0xA7 …

—- Files - GMER 1.0.15 —-

File C:\Users\Firdaus\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00005a 0 bytes

—- EOF - GMER 1.0.15 —-
Hi,

You aren't running Anti Virus Software

Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, web server, or network.
Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories.
We'll install one after.

You also forgot to include the Attach.txt in your reply, this may provide an additional insight regarding your computer. Please post it on your next reply.

Also, can you remember any software you removed from your computer before the problem occured?

You set these proxies?

uInternet Settings,ProxyOverride = local;172.16.110.33:80
uInternet Settings,ProxyServer = 211.138.124.232:80

–Next–

Please go to Virus Total
  • Click on Browse.
  • On the File Upload window, copy/paste the text below into the File name box or by navigating (browse) to this file:
    C:\Users\Firdaus\AppData\Roaming\whitepixel\HKEY_LOCAL_MACHINE.exe
  • Click Send file. Allow the file to be scanned. If it says already scanned – click Reanalyze Now
Repeat the procedure with the following files:
C:\Windows\System32\jusched.exe
C:\Windows\System32\odbc32.dll
C:\Windows\SysWow64\odbc32.dll
C:\Windows\Pjepoa.exe


Please post the results or Virus Total's report link in your next reply.

To post in your next reply:
1. Regarding my questions above.
2. Attach.txt log.
3. VirusTotal logs.
Hi,

Firstly, I'm so sorry because I forgot to include attach.txt previously so I post it in this reply.

Now, I already install the antivirus for my computer which is avast free antivirus and kaspersky internet security trial for temporary.

I don't really actually remove any software before the problem occured, but the software that i removed from my computer after the problem is microsoft office professional 2010 plus and avast free antivirus which is after i'm done with system restore instruction.

Yes,I do set proxy server 211.138.124.232 but i disable it.

The virus total log link is here

1) C:\Users\Firdaus\AppData\Roaming\whitepixel\HKEY_LOCAL_MACHINE.exe

- http://www.virustotal.com/file-scan/report…f0e2-1295355447

2) C:\Windows\System32\odbc32.dll

- http://www.virustotal.com/file-scan/report…3bd7-1295356190

3) C:\Windows\SysWow64\odbc32.dll

- http://www.virustotal.com/file-scan/report…3bd7-1295356425

4) C:\Windows\Pjepoa.exe

- http://www.virustotal.com/file-scan/report…3197-1295356451


i can't find any of this file 'C:\Windows\System32\jusched.exe' unfortunately i can't scan it through virustotal.com



Regard,

Firdaus

Attachments:

Hi,

Firstly, I'm so sorry because I forgot to include attach.txt previously so I post it in this reply.

That's alright. :)

Now, I already install the antivirus for my computer which is avast free antivirus and kaspersky internet security trial for temporary.

Running more than one anti virus at the same time does not only slow down your computer but provides less protection than they are programmed to do, due to the fact that they will be conflicting with each other rather than providing sufficient protection for your computer. Please uninstall one of your anti virus before proceeding with any of the fixes.

–Next–

Please read through these instructions to familiarize yourself with what to expect when this tool runs

Download Combofix from either of the links below. Save it to your desktop.

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty in properly disabling your protective programs, refer to this link - How to Disable your Security Programs
——————————————————————–

  • Close any open browsers.
  • Right click on ComboFix.exe then choose Run as Administrator & follow the prompts.
Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making Internet Explorer the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.
Hi inzanity,

Now, my computer is free from any malware and trojan after using combofix

Thank you very much for the guideline and advise. :thumbup:

By the way, I already uninstall the other antivirus and just keep the one which is avast in my machine.

Here is the combofix log you ask previously


Regard,

Firdaus ;)


Combofix log

ComboFix 11-01-18.04 - Firdaus 19/01/2011 19:50:02.1.2 - x64
Microsoft Windows 7 Home Basic 6.1.7600.0.1252.60.1033.18.2010.799 [GMT 8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Firdaus\AppData\Roaming\whitepixel
c:\windows\system32\system
c:\windows\system32\twunk_32.exe
c:\windows\SysWow64\system
c:\windows\SysWow64\twunk_32.exe
c:\windows\XSxS
C:\z.tmp

.
((((((((((((((((((((((((( Files Created from 2010-12-19 to 2011-01-19 )))))))))))))))))))))))))))))))
.

2011-01-19 11:44 . 2011-01-19 11:45 ——– d—–w- C:\32788R22FWJFW
2011-01-17 23:05 . 2011-01-13 08:37 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-01-17 23:05 . 2011-01-13 08:41 273488 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-01-17 23:05 . 2011-01-13 08:37 29264 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-01-17 23:05 . 2011-01-13 08:40 51792 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-01-17 23:05 . 2011-01-13 08:47 237168 —-a-w- c:\windows\system32\aswBoot.exe
2011-01-17 23:05 . 2011-01-13 08:37 62032 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-01-17 23:05 . 2011-01-13 08:47 38848 —-a-w- c:\windows\avastSS.scr
2011-01-17 23:05 . 2011-01-13 08:47 188216 —-a-w- c:\windows\SysWow64\aswBoot.exe
2011-01-17 23:02 . 2010-06-20 16:23 266714 —-a-w- c:\windows\KMSAct.exe
2011-01-17 17:34 . 2011-01-17 17:34 ——– d—–w- c:\program files (x86)\Microsoft Synchronization Services
2011-01-17 17:34 . 2011-01-17 17:34 ——– d—–w- c:\program files (x86)\Microsoft.NET
2011-01-17 17:18 . 2011-01-17 17:35 ——– d—–w- c:\windows\SHELLNEW
2011-01-17 17:16 . 2011-01-17 17:16 ——– d—–r- C:\MSOCache
2011-01-15 07:30 . 2011-01-15 08:20 ——– d—–w- c:\programdata\Webroot
2011-01-15 07:29 . 2011-01-15 07:29 ——– d—–w- c:\users\Firdaus\AppData\Roaming\Uniblue
2011-01-15 07:28 . 2011-01-15 07:28 ——– d—–w- c:\users\Firdaus\AppData\Local\PackageAware
2011-01-15 06:31 . 2011-01-15 06:31 ——– d—–w- c:\program files (x86)\Trend Micro
2011-01-14 16:24 . 2011-01-14 16:24 ——– d—–w- c:\windows\PCHEALTH
2011-01-14 16:24 . 2011-01-14 16:24 ——– d—–w- c:\program files (x86)\Microsoft Sync Framework
2011-01-14 16:24 . 2011-01-14 16:24 ——– d—–w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2011-01-14 16:19 . 2011-01-17 17:19 ——– d—–w- c:\program files (x86)\Microsoft Visual Studio 8
2011-01-14 16:18 . 2011-01-14 16:18 ——– d—–w- c:\program files (x86)\Microsoft Analysis Services
2011-01-12 12:07 . 2010-10-16 05:17 720896 —-a-w- c:\windows\system32\odbc32.dll
2011-01-12 12:07 . 2010-10-16 05:16 495616 —-a-w- c:\program files\Common Files\System\ado\msadox.dll
2011-01-12 12:07 . 2010-10-16 05:16 466944 —-a-w- c:\program files\Common Files\System\ado\msadomd.dll
2011-01-12 12:07 . 2010-10-16 05:16 1425408 —-a-w- c:\program files\Common Files\System\ado\msado15.dll
2011-01-12 12:07 . 2010-10-16 05:16 258048 —-a-w- c:\program files\Common Files\System\msadc\msadco.dll
2011-01-12 12:07 . 2010-10-16 04:34 573440 —-a-w- c:\windows\SysWow64\odbc32.dll
2011-01-12 12:07 . 2010-10-16 04:33 372736 —-a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll
2011-01-12 12:07 . 2010-10-16 04:33 352256 —-a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll
2011-01-12 12:07 . 2010-10-16 04:33 987136 —-a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
2011-01-12 12:07 . 2010-10-16 04:33 208896 —-a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll
2011-01-08 11:12 . 2011-01-08 11:12 ——– d—–w- c:\users\Firdaus\AppData\Local\Xenocode
2011-01-08 11:12 . 2011-01-08 11:12 ——– d—–w- c:\program files (x86)\Xenocode
2011-01-08 09:49 . 2011-01-08 09:54 ——– d—–w- c:\program files (x86)\Artisteer 2
2011-01-07 20:15 . 2011-01-07 20:15 ——– d—–w- c:\users\Firdaus\AppData\Roaming\Artisteer
2011-01-07 11:34 . 2011-01-07 11:34 ——– d—–w- c:\program files (x86)\MySQL
2011-01-07 10:19 . 2011-01-07 10:19 ——– d—–w- C:\xampp-win32-1.7.3
2011-01-04 11:26 . 2011-01-04 11:26 ——– d—–w- c:\programdata\Ezprint

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-20 20:57 . 2010-11-20 20:57 499712 —-a-w- c:\windows\SysWow64\msvcp71.dll
2010-11-12 10:53 . 2010-05-07 08:45 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll
2010-11-04 06:35 . 2010-12-16 03:27 1194496 —-a-w- c:\windows\system32\wininet.dll
2010-11-04 06:31 . 2010-12-16 03:27 57856 —-a-w- c:\windows\system32\licmgr10.dll
2010-11-04 05:52 . 2010-12-16 03:27 978944 —-a-w- c:\windows\SysWow64\wininet.dll
2010-11-04 05:48 . 2010-12-16 03:27 44544 —-a-w- c:\windows\SysWow64\licmgr10.dll
2010-11-04 05:16 . 2010-12-16 03:27 482816 —-a-w- c:\windows\system32\html.iec
2010-11-04 04:41 . 2010-12-16 03:27 386048 —-a-w- c:\windows\SysWow64\html.iec
2010-11-04 04:35 . 2010-12-16 03:27 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2010-11-04 04:08 . 2010-12-16 03:27 1638912 —-a-w- c:\windows\SysWow64\mshtml.tlb
2010-11-02 05:18 . 2010-12-16 05:14 524288 —-a-w- c:\windows\system32\wmicmiplugin.dll
2010-11-02 05:17 . 2010-12-16 05:14 1169408 —-a-w- c:\windows\system32\taskschd.dll
2010-11-02 05:17 . 2010-12-16 05:14 473600 —-a-w- c:\windows\system32\taskcomp.dll
2010-11-02 05:16 . 2010-12-16 05:14 1114624 —-a-w- c:\windows\system32\schedsvc.dll
2010-11-02 05:10 . 2010-12-16 05:14 464384 —-a-w- c:\windows\system32\taskeng.exe
2010-11-02 05:10 . 2010-12-16 05:14 285696 —-a-w- c:\windows\system32\schtasks.exe
2010-11-02 04:40 . 2010-12-16 05:14 496128 —-a-w- c:\windows\SysWow64\taskschd.dll
2010-11-02 04:40 . 2010-12-16 05:14 305152 —-a-w- c:\windows\SysWow64\taskcomp.dll
2010-11-02 04:34 . 2010-12-16 05:14 192000 —-a-w- c:\windows\SysWow64\taskeng.exe
2010-11-02 04:34 . 2010-12-16 05:14 179712 —-a-w- c:\windows\SysWow64\schtasks.exe
2010-10-27 05:06 . 2010-12-16 03:05 2048 —-a-w- c:\windows\system32\tzres.dll
2010-10-27 04:32 . 2010-12-16 03:05 2048 —-a-w- c:\windows\SysWow64\tzres.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Google Update"="c:\users\Firdaus\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-07-03 136176]
"Messenger (Yahoo!)"="c:\progra~2\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]
"Octoshape Streaming Services"="c:\users\Firdaus\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-08 70936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 1807600]
"FATrayAlert"="c:\program files (x86)\Sensible Vision\Fast Access\FATrayMon.exe" [2009-06-24 95496]
"PDVDDXSrv"="c:\program files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-06-24 409744]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-10-15 498160]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2010-12-02 74752]
"vmware-tray"="c:\program files (x86)\VMware\VMware Workstation\vmware-tray.exe" [2010-03-09 129584]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-22 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2010-11-20 274608]
"lxdnmon.exe"="c:\program files (x86) (x86)\Lexmark 2600 Series\lxdnmon.exe" [2009-10-28 660136]
"EzPrint"="c:\program files (x86) (x86)\Lexmark 2600 Series\ezprint.exe" [2009-10-28 107176]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe" [2010-07-21 165184]

c:\users\Firdaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-9-22 1316192]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-2 1079584]

c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-9-22 1316192]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FastAccess]
2009-06-24 22:31 140552 —-a-w- c:\program files (x86)\Sensible Vision\Fast Access\FALogNot.dll

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

R0 Shadow;Shadow; [x]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-17 136176]
R3 FACAP;facap, FastAccess Video Capture;c:\windows\system32\DRIVERS\facap.sys [2008-09-25 238848]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 netr7364;RT73 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr7364.sys [2009-06-10 707072]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2010-11-18 25072]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-05-08 215552]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S0 diskpt;diskpt;c:\windows\SYSTEM32\drivers\diskpt.sys [2010-02-08 249184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe [2009-03-02 89600]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-01-13 62032]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
S2 FAService;FAService;c:\program files (x86)\Sensible Vision\Fast Access\FAService.exe [2009-06-24 2368776]
S2 HssWd;Hotspot Shield Monitoring Service;c:\program files (x86)\Hotspot Shield\bin\hsswd.exe [2010-06-23 322608]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 47632]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2010-08-20 689472]
S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [2010-03-09 126000]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [2010-03-09 540672]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-08-05 35104]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2009-06-15 172704]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-05-22 215040]

.
Contents of the 'Scheduled Tasks' folder

2011-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-17 06:21]

2011-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-17 06:21]

2011-01-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-309132136-2634883446-1347342510-1000Core.job
- c:\users\Firdaus\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-03 13:00]

2011-01-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-309132136-2634883446-1347342510-1000UA.job
- c:\users\Firdaus\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-03 13:00]

2011-01-13 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2010-11-18 15:13]

2011-01-19 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\pcdrcui.exe [2010-11-18 15:13]
.

——— x86-64 ———–


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2010-06-23 02:49 284208 —-a-w- c:\program files (x86)\Hotspot Shield\HssIE\HssIE_64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF5092.cfxxe" [X]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-03-10 309760]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-06-05 165912]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-06-05 385560]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-06-05 365080]
"Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4968960]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-06-29 444416]
"QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2009-07-02 3180624]
"Shadow Defender Daemon"="c:\program files\Shadow Defender\DefenderDaemon.exe" [2010-02-09 302908]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-05 500208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid;=CT2737658
mStart Page = hxxp://search.Facesounds.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = local;172.16.110.33:80
uInternet Settings,ProxyServer = 211.138.124.232:80
IE: E&xport; to Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\program files (x86)\VMware\VMware Workstation\vsocklib.dll
TCP: {0282556B-EA02-4ABF-8C86-0127D44031AF} = 10.54.0.1
TCP: {B641FD9E-0457-4CDF-A47A-E824C18C2D7F} = 208.67.222.222,208.67.222.220
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
FF - ProfilePath - c:\users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2737658&SearchSource;=3&q;={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - prefs.js: keyword.URL - hxxp://search.Facesounds.com/?q=
FF - prefs.js: network.proxy.ftp - 211.138.124.232
FF - prefs.js: network.proxy.ftp_port - 80
FF - prefs.js: network.proxy.gopher - [removed]
FF - prefs.js: network.proxy.gopher_port - 80
FF - prefs.js: network.proxy.http - [removed]
FF - prefs.js: network.proxy.http_port - 80
FF - prefs.js: network.proxy.socks - [removed]
FF - prefs.js: network.proxy.socks_port - 80
FF - prefs.js: network.proxy.ssl - [removed]
FF - prefs.js: network.proxy.ssl_port - 80
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension for Firefox: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Cooliris: [removed] - %profile%\extensions\[removed]
FF - Ext: Softonic English Toolbar: {930f1200-f5f1-4870-bac6-e233ec8e7023} - %profile%\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}
FF - Ext: BitDefender QuickScan: {e001c731-5e37-4538-a5cb-8168736a2360} - %profile%\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
FF - Ext: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - %profile%\extensions\{f999a48b-1950-4d81-9971-79018f807b4b}
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Wow6432Node-HKLM-Run-FAStartup - (no file)
Wow6432Node-HKLM-Run-DellSupportCenter - c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe
SafeBoot-mcmscsvc
SafeBoot-MCODS
Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)



[HKEY_LOCAL_MACHINE\system\ControlSet001\services\PCDSRVC{1E208CE0-FB7451FF-06020101}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-309132136-2634883446-1347342510-1000\Software\SecuROM\License information*]
"datasecu"=hex:d0,2b,c1,5e,53,5a,d5,1a,aa,59,93,75,48,85,f3,de,09,d9,fb,e5,95,
88,83,1c,8a,f3,34,f7,ad,81,27,08,91,dc,de,9d,60,ab,4a,db,5e,8f,26,c4,8e,7d,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb

[HKEY_USERS\S-1-5-21-309132136-2634883446-1347342510-1000_Classes\Wow6432Node\CLSID\{4508ad7f-f5b4-4db6-b6f3-f53a438fb8d5}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:000000c6
"Therad"=dword:00000014

[HKEY_USERS\S-1-5-21-309132136-2634883446-1347342510-1000_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):f8,b4,50,75,5b,f3,ec,ed,0c,4a,ca,a4,87,a6,ce,ea,99,a8,0e,11,d1,
e5,e0,8e,57,d4,c1,a3,f6,05,6b,e8,f0,96,8a,2f,ff,05,91,85,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\SysWOW64\vmnat.exe
c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files (x86)\VMware\VMware Workstation\vmware-authd.exe
c:\windows\SysWOW64\vmnetdhcp.exe
c:\program files (x86)\Hotspot Shield\bin\openvpnas.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe
c:\users\Firdaus\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe
c:\program files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
c:\program files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
.
**************************************************************************
.
Completion time: 2011-01-19 20:21:30 - machine was rebooted
ComboFix-quarantined-files.txt 2011-01-19 12:21

Pre-Run: 15,847,596,032 bytes free
Post-Run: 14,583,664,640 bytes free

- - End Of File - - 497C4A29C038370000B5879BA6138AC7
Hi,

Glad it's getting better. But we are not done yet. :)

Some of your problems may be due to the use of P2P applications such as BitTorrent and LimeWire.

P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

P2P (File Sharing ) programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realize. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

This article from InfoWorld illustrates the dangers of a poorly configured P2P program.
http://www.infoworld.com/d/security-centra…-p-id-theft-103

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.

I would recommend that you uninstall BitTorrent and LimeWire, via Control Panel -> Programs and Features.

However, if you do not wish to remove this program please be advised not to use the said program during the course of cleaning your machine.

References for the risk of these programs can be found in these links:
http://www.esecurityguy.com/p2p_file_sharing
http://www.microsoft.com/protect/data/down…ilesharing.aspx

–Next–

Please do the following:

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty in properly disabling your protective programs, refer to this link - How to Disable your Security Programs
——————————————————————–

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

http://forums.whatthetech.com/index.php?showtopic=116584&pid=707074&st=0&#entry707074

Collect::
c:\windows\KMSAct.exe
C:\Windows\Pjepoa.exe

DDS::
uRun: [HKEY_LOCAL_MACHINE] C:\Users\Firdaus\AppData\Roaming\whitepixel\HKEY_LOCAL_MACHINE.exe

RegLockDel::
[HKEY_USERS\S-1-5-21-309132136-2634883446-1347342510-1000_Classes\Wow6432Node\CLSID\{4508ad7f-f5b4-4db6-b6f3-f53a438fb8d5}]
[HKEY_USERS\S-1-5-21-309132136-2634883446-1347342510-1000_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
Hi,

Due to your references,I immediately uninstall bittorent and limewire in my computer.Thanks again for your guidelines.

By the way,I am wondering why its take to long for combofix to scan my machine?because i start drag the CFScript.txt into Combofix, and its take about 17 hours from 3.00 am to 8.10 p.m to produce a log?

Here the Combofix.log you ask previously ;


ComboFix 11-01-19.04 - Firdaus 21/01/2011 0:42.3.2 - x64
Microsoft Windows 7 Home Basic 6.1.7600.0.1252.60.1033.18.2010.985 [GMT 8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Firdaus\Desktop\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Enabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\KMSAct.exe
c:\windows\SysWow64\FAib.dll

.
((((((((((((((((((((((((( Files Created from 2010-12-20 to 2011-01-20 )))))))))))))))))))))))))))))))
.

2011-01-20 22:46 . 2011-01-20 22:46 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2011-01-20 22:46 . 2011-01-20 22:46 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-01-20 04:45 . 2011-01-20 04:45 ——– d—–w- c:\windows\en
2011-01-20 04:28 . 2010-09-22 16:36 48488 —-a-w- c:\windows\system32\drivers\fssfltr.sys
2011-01-20 04:27 . 2011-01-20 04:27 ——– d—–w- c:\program files\Windows Live
2011-01-20 04:21 . 2011-01-20 04:21 ——– d—–w- c:\program files (x86)\MSN Toolbar
2011-01-20 04:20 . 2011-01-20 04:24 ——– d—–w- c:\program files (x86)\Bing Bar Installer
2011-01-20 04:05 . 2011-01-20 04:05 469256 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\43b155f21cbb85709\InstallManager_WLE_WLE.exe
2011-01-20 04:05 . 2011-01-20 04:05 15712 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\3f11cbde1cbb85708\MeshBetaRemover.exe
2011-01-20 04:05 . 2011-01-20 04:05 94040 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\3c6ba8301cbb85707\DSETUP.dll
2011-01-20 04:05 . 2011-01-20 04:05 525656 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\3c6ba8301cbb85707\DXSETUP.exe
2011-01-20 04:05 . 2011-01-20 04:05 1691480 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\3c6ba8301cbb85707\dsetup32.dll
2011-01-20 04:05 . 2011-01-20 04:05 525656 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\3814e7fc1cbb85706\DXSETUP.exe
2011-01-20 04:05 . 2011-01-20 04:05 1691480 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\3814e7fc1cbb85706\dsetup32.dll
2011-01-20 04:05 . 2011-01-20 04:05 94040 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\3814e7fc1cbb85706\DSETUP.dll
2011-01-20 04:04 . 2011-01-20 05:50 ——– d—–w- c:\users\Firdaus\AppData\Local\Windows Live
2011-01-20 04:03 . 2010-05-23 08:35 257024 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 04:03 . 2010-05-23 08:35 206848 —-a-w- c:\windows\system32\mfps.dll
2011-01-20 04:03 . 2010-05-23 10:15 1619456 —-a-w- c:\windows\SysWow64\WMVDECOD.DLL
2011-01-20 04:03 . 2010-05-23 10:11 196608 —-a-w- c:\windows\SysWow64\mfreadwrite.dll
2011-01-20 04:03 . 2010-05-23 08:37 1888256 —-a-w- c:\windows\system32\WMVDECOD.DLL
2011-01-20 04:03 . 2010-05-23 10:11 3181568 —-a-w- c:\windows\SysWow64\mf.dll
2011-01-20 04:03 . 2010-05-23 08:35 4068864 —-a-w- c:\windows\system32\mf.dll
2011-01-19 11:52 . 2010-11-10 05:35 8199504 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{308D3E89-0D43-4494-A612-252BA1083839}\mpengine.dll
2011-01-18 12:12 . 2010-03-24 06:59 1736608 —-a-w- c:\windows\system32\ntdll.dll
2011-01-18 12:12 . 2010-03-24 06:37 1289528 —-a-w- c:\windows\SysWow64\ntdll.dll
2011-01-18 12:12 . 2010-10-19 08:47 7680 —-a-w- c:\program files\Internet Explorer\iecompat.dll
2011-01-18 12:12 . 2010-10-19 08:10 7680 —-a-w- c:\program files (x86)\Internet Explorer\iecompat.dll
2011-01-18 12:12 . 2009-09-26 06:20 223448 —-a-w- c:\windows\system32\drivers\fvevol.sys
2011-01-18 12:11 . 2010-07-13 05:37 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2011-01-18 12:11 . 2009-12-22 08:36 243200 —-a-w- c:\windows\system32\wow64.dll
2011-01-18 12:11 . 2009-12-22 08:23 25600 —-a-w- c:\windows\SysWow64\setup16.exe
2011-01-18 12:11 . 2009-12-22 08:24 14336 —-a-w- c:\windows\SysWow64\ntvdm64.dll
2011-01-18 12:11 . 2009-12-22 08:22 5120 —-a-w- c:\windows\SysWow64\wow32.dll
2011-01-18 12:11 . 2009-12-22 04:28 7680 —-a-w- c:\windows\SysWow64\instnm.exe
2011-01-18 12:11 . 2009-12-22 04:28 2048 —-a-w- c:\windows\SysWow64\user.exe
2011-01-18 12:11 . 2010-04-07 07:10 571904 —-a-w- c:\windows\SysWow64\oleaut32.dll
2011-01-18 12:11 . 2010-04-07 07:37 861184 —-a-w- c:\windows\system32\oleaut32.dll
2011-01-18 11:39 . 2010-03-04 04:40 184832 —-a-w- c:\windows\system32\drivers\usbvideo.sys
2011-01-18 11:39 . 2010-03-04 04:32 243712 —-a-w- c:\windows\system32\drivers\ks.sys
2011-01-17 23:05 . 2011-01-13 08:37 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-01-17 23:05 . 2011-01-13 08:41 273488 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-01-17 23:05 . 2011-01-13 08:37 29264 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-01-17 23:05 . 2011-01-13 08:40 51792 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-01-17 23:05 . 2011-01-13 08:47 237168 —-a-w- c:\windows\system32\aswBoot.exe
2011-01-17 23:05 . 2011-01-13 08:37 62032 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-01-17 23:05 . 2011-01-13 08:47 38848 —-a-w- c:\windows\avastSS.scr
2011-01-17 23:05 . 2011-01-13 08:47 188216 —-a-w- c:\windows\SysWow64\aswBoot.exe
2011-01-17 17:34 . 2011-01-17 17:34 ——– d—–w- c:\program files (x86)\Microsoft Synchronization Services
2011-01-17 17:34 . 2011-01-20 12:27 ——– d—–w- c:\program files (x86)\Microsoft.NET
2011-01-17 17:18 . 2011-01-17 17:35 ——– d—–w- c:\windows\SHELLNEW
2011-01-17 17:16 . 2011-01-17 17:16 ——– d—–r- C:\MSOCache
2011-01-15 07:30 . 2011-01-15 08:20 ——– d—–w- c:\programdata\Webroot
2011-01-15 07:29 . 2011-01-15 07:29 ——– d—–w- c:\users\Firdaus\AppData\Roaming\Uniblue
2011-01-15 07:28 . 2011-01-15 07:28 ——– d—–w- c:\users\Firdaus\AppData\Local\PackageAware
2011-01-15 06:31 . 2011-01-15 06:31 ——– d—–w- c:\program files (x86)\Trend Micro
2011-01-14 16:24 . 2011-01-20 04:33 ——– d—–w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2011-01-14 16:24 . 2011-01-14 16:24 ——– d—–w- c:\windows\PCHEALTH
2011-01-14 16:24 . 2011-01-14 16:24 ——– d—–w- c:\program files (x86)\Microsoft Sync Framework
2011-01-14 16:19 . 2011-01-17 17:19 ——– d—–w- c:\program files (x86)\Microsoft Visual Studio 8
2011-01-14 16:18 . 2011-01-14 16:18 ——– d—–w- c:\program files (x86)\Microsoft Analysis Services
2011-01-12 12:07 . 2010-10-16 05:17 720896 —-a-w- c:\windows\system32\odbc32.dll
2011-01-12 12:07 . 2010-10-16 05:16 495616 —-a-w- c:\program files\Common Files\System\ado\msadox.dll
2011-01-12 12:07 . 2010-10-16 05:16 466944 —-a-w- c:\program files\Common Files\System\ado\msadomd.dll
2011-01-12 12:07 . 2010-10-16 05:16 1425408 —-a-w- c:\program files\Common Files\System\ado\msado15.dll
2011-01-12 12:07 . 2010-10-16 05:16 258048 —-a-w- c:\program files\Common Files\System\msadc\msadco.dll
2011-01-12 12:07 . 2010-10-16 04:34 573440 —-a-w- c:\windows\SysWow64\odbc32.dll
2011-01-12 12:07 . 2010-10-16 04:33 372736 —-a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll
2011-01-12 12:07 . 2010-10-16 04:33 352256 —-a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll
2011-01-12 12:07 . 2010-10-16 04:33 987136 —-a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
2011-01-12 12:07 . 2010-10-16 04:33 208896 —-a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll
2011-01-08 11:12 . 2011-01-08 11:12 ——– d—–w- c:\users\Firdaus\AppData\Local\Xenocode
2011-01-08 11:12 . 2011-01-08 11:12 ——– d—–w- c:\program files (x86)\Xenocode
2011-01-08 09:49 . 2011-01-08 09:54 ——– d—–w- c:\program files (x86)\Artisteer 2
2011-01-07 20:15 . 2011-01-07 20:15 ——– d—–w- c:\users\Firdaus\AppData\Roaming\Artisteer
2011-01-07 11:34 . 2011-01-07 11:34 ——– d—–w- c:\program files (x86)\MySQL
2011-01-07 10:19 . 2011-01-07 10:19 ——– d—–w- C:\xampp-win32-1.7.3
2011-01-04 11:26 . 2011-01-04 11:26 ——– d—–w- c:\programdata\Ezprint

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-20 20:57 . 2010-11-20 20:57 499712 —-a-w- c:\windows\SysWow64\msvcp71.dll
2010-11-12 10:53 . 2010-05-07 08:45 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll
2010-11-04 06:35 . 2010-12-16 03:27 1194496 —-a-w- c:\windows\system32\wininet.dll
2010-11-04 06:31 . 2010-12-16 03:27 57856 —-a-w- c:\windows\system32\licmgr10.dll
2010-11-04 05:52 . 2010-12-16 03:27 978944 —-a-w- c:\windows\SysWow64\wininet.dll
2010-11-04 05:48 . 2010-12-16 03:27 44544 —-a-w- c:\windows\SysWow64\licmgr10.dll
2010-11-04 05:16 . 2010-12-16 03:27 482816 —-a-w- c:\windows\system32\html.iec
2010-11-04 04:41 . 2010-12-16 03:27 386048 —-a-w- c:\windows\SysWow64\html.iec
2010-11-04 04:35 . 2010-12-16 03:27 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2010-11-04 04:08 . 2010-12-16 03:27 1638912 —-a-w- c:\windows\SysWow64\mshtml.tlb
2010-11-02 05:18 . 2010-12-16 05:14 524288 —-a-w- c:\windows\system32\wmicmiplugin.dll
2010-11-02 05:17 . 2010-12-16 05:14 1169408 —-a-w- c:\windows\system32\taskschd.dll
2010-11-02 05:17 . 2010-12-16 05:14 473600 —-a-w- c:\windows\system32\taskcomp.dll
2010-11-02 05:16 . 2010-12-16 05:14 1114624 —-a-w- c:\windows\system32\schedsvc.dll
2010-11-02 05:10 . 2010-12-16 05:14 464384 —-a-w- c:\windows\system32\taskeng.exe
2010-11-02 05:10 . 2010-12-16 05:14 285696 —-a-w- c:\windows\system32\schtasks.exe
2010-11-02 04:40 . 2010-12-16 05:14 496128 —-a-w- c:\windows\SysWow64\taskschd.dll
2010-11-02 04:40 . 2010-12-16 05:14 305152 —-a-w- c:\windows\SysWow64\taskcomp.dll
2010-11-02 04:34 . 2010-12-16 05:14 192000 —-a-w- c:\windows\SysWow64\taskeng.exe
2010-11-02 04:34 . 2010-12-16 05:14 179712 —-a-w- c:\windows\SysWow64\schtasks.exe
2010-10-27 05:06 . 2010-12-16 03:05 2048 —-a-w- c:\windows\system32\tzres.dll
2010-10-27 04:32 . 2010-12-16 03:05 2048 —-a-w- c:\windows\SysWow64\tzres.dll
.

((((((((((((((((((((((((((((( SnapShot_2011-01-20_08.56.56 )))))))))))))))))))))))))))))))))))))))))
.
- 2010-03-16 06:49 . 2011-01-20 05:20 32768 c:\windows\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2010-03-16 06:49 . 2011-01-20 22:40 32768 c:\windows\Temp\Temporary Internet Files\Content.IE5\index.dat
- 2010-03-16 06:49 . 2011-01-20 05:20 16384 c:\windows\Temp\History\History.IE5\index.dat
+ 2010-03-16 06:49 . 2011-01-20 22:40 16384 c:\windows\Temp\History\History.IE5\index.dat
- 2010-03-16 06:49 . 2011-01-20 05:20 32768 c:\windows\Temp\Cookies\index.dat
+ 2010-03-16 06:49 . 2011-01-20 22:40 32768 c:\windows\Temp\Cookies\index.dat
+ 2010-03-11 09:20 . 2011-01-20 12:48 72382 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-01-20 16:32 47838 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2011-01-20 05:21 47838 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-03-16 06:51 . 2011-01-20 16:32 23272 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-309132136-2634883446-1347342510-1000_UserData.bin
- 2010-03-16 06:51 . 2011-01-20 05:21 23272 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-309132136-2634883446-1347342510-1000_UserData.bin
+ 2009-07-14 04:46 . 2011-01-20 12:19 63688 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2010-03-18 19:36 . 2011-01-20 16:34 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-03-18 19:36 . 2011-01-20 05:24 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-03-18 19:36 . 2011-01-20 16:34 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-03-18 19:36 . 2011-01-20 05:24 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-03-18 05:16 . 2010-03-18 05:16 87408 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WindowsFormsIntegration.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 93024 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\UIAutomationTypes.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 35688 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\UIAutomationProvider.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 17784 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\System.Windows.Presentation.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 58240 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\System.Windows.Input.Manipulations.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 83272 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PenIMC.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 39256 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WMINet_Utils.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 44920 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.ApplicationServices.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 37240 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.Channels.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 64352 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Numerics.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 52608 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.EnterpriseServices.Thunk.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 51032 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Device.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 50552 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.DataSetExtensions.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 81784 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Configuration.Install.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 81800 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.ComponentModel.DataAnnotations.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 39784 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.AddIn.Contract.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 68952 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMDiagnostics.dll
+ 2010-03-18 19:58 . 2010-03-18 19:58 96088 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\SetupUtility.exe
+ 2010-03-18 20:16 . 2010-03-18 20:16 78152 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Setup.exe
+ 2010-03-18 20:16 . 2010-03-18 20:16 18776 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\3082\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 14168 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\3076\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18776 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\2070\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 14168 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\2052\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 17752 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1055\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 17752 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1053\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1049\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1046\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1045\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 17752 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1044\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 19288 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1043\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 15192 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1042\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 15704 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1041\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1040\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18776 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1038\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 16728 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1037\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18776 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1036\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1035\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 17240 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1033\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 19288 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1032\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18776 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1031\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1030\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1029\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 14168 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1028\SetupResources.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 17240 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\1025\SetupResources.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 48512 c:\windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelPerformanceCounters.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 14160 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SbsNclPerf.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 65360 c:\windows\Microsoft.NET\Framework64\v4.0.30319\regtlibv12.exe
+ 2010-03-18 06:27 . 2010-03-18 06:27 32080 c:\windows\Microsoft.NET\Framework64\v4.0.30319\RegSvcs.exe
+ 2010-03-18 06:27 . 2010-03-18 06:27 51528 c:\windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe
+ 2010-03-18 06:27 . 2010-03-18 06:27 24408 c:\windows\Microsoft.NET\Framework64\v4.0.30319\normalization.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 67920 c:\windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 27984 c:\windows\Microsoft.NET\Framework64\v4.0.30319\MUI\0409\mscorsecr.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 45904 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorpe.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 20816 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscoreeis.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 62880 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Windows.ApplicationServer.Applications.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 12128 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.VisualC.Dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 97680 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 36168 c:\windows\Microsoft.NET\Framework64\v4.0.30319\jsc.exe
+ 2010-03-18 06:27 . 2010-03-18 06:27 94552 c:\windows\Microsoft.NET\Framework64\v4.0.30319\ISymWrapper.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 67416 c:\windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtilLib.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 27480 c:\windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe
+ 2010-03-18 06:27 . 2010-03-18 06:27 48456 c:\windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 11592 c:\windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe
+ 2010-03-18 06:27 . 2010-03-18 06:27 35656 c:\windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe
+ 2010-03-18 06:27 . 2010-03-18 06:27 91488 c:\windows\Microsoft.NET\Framework64\v4.0.30319\CustomMarshalers.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 53072 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Culture.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 94536 c:\windows\Microsoft.NET\Framework64\v4.0.30319\CasPol.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 29008 c:\windows\Microsoft.NET\Framework64\v4.0.30319\AddInUtil.exe
+ 2010-03-18 06:27 . 2010-03-18 06:27 29528 c:\windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess32.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 29016 c:\windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 17240 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Accessibility.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 10064 c:\windows\Microsoft.NET\Framework64\v4.0.30319\1033\CvtResUI.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 24400 c:\windows\Microsoft.NET\Framework64\v4.0.30319\1033\alinkui.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 87408 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsFormsIntegration.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 93024 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\UIAutomationTypes.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 35688 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\UIAutomationProvider.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 17784 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\System.Windows.Presentation.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 58240 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\System.Windows.Input.Manipulations.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 67912 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PenIMC.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 31576 c:\windows\Microsoft.NET\Framework\v4.0.30319\WMINet_Utils.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 44920 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.ApplicationServices.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 37240 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceModel.Channels.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 64352 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Numerics.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 45952 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.EnterpriseServices.Thunk.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 51032 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Device.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 50552 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Data.DataSetExtensions.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 81784 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Configuration.Install.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 81800 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.ComponentModel.DataAnnotations.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 39784 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.AddIn.Contract.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 68952 c:\windows\Microsoft.NET\Framework\v4.0.30319\SMDiagnostics.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 42880 c:\windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelPerformanceCounters.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 13648 c:\windows\Microsoft.NET\Framework\v4.0.30319\SbsNclPerf.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 58192 c:\windows\Microsoft.NET\Framework\v4.0.30319\regtlibv12.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 32592 c:\windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 52040 c:\windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 21336 c:\windows\Microsoft.NET\Framework\v4.0.30319\normalization.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 56656 c:\windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 27984 c:\windows\Microsoft.NET\Framework\v4.0.30319\MUI\0409\mscorsecr.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 40784 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorpe.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 20816 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscoreeis.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 62880 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Windows.ApplicationServer.Applications.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 12128 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.VisualC.Dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 97680 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 36168 c:\windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 78168 c:\windows\Microsoft.NET\Framework\v4.0.30319\ISymWrapper.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 58200 c:\windows\Microsoft.NET\Framework\v4.0.30319\InstallUtilLib.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 27992 c:\windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 42312 c:\windows\Microsoft.NET\Framework\v4.0.30319\fusion.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 11592 c:\windows\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 88904 c:\windows\Microsoft.NET\Framework\v4.0.30319\dfdll.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 31048 c:\windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 81248 c:\windows\Microsoft.NET\Framework\v4.0.30319\CustomMarshalers.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 44368 c:\windows\Microsoft.NET\Framework\v4.0.30319\Culture.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 95048 c:\windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 29008 c:\windows\Microsoft.NET\Framework\v4.0.30319\AddInUtil.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 29528 c:\windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 29016 c:\windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 17240 c:\windows\Microsoft.NET\Framework\v4.0.30319\Accessibility.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 10064 c:\windows\Microsoft.NET\Framework\v4.0.30319\1033\CvtResUI.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 24400 c:\windows\Microsoft.NET\Framework\v4.0.30319\1033\alinkui.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 87408 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 93024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 35688 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 17784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 58240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
+ 2011-01-20 12:35 . 2011-01-20 12:35 44920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
+ 2011-01-20 12:36 . 2011-01-20 12:36 37240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
+ 2011-01-20 12:35 . 2011-01-20 12:35 64352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
+ 2011-01-20 12:35 . 2011-01-20 12:35 51032 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
+ 2011-01-20 12:34 . 2011-01-20 12:34 50552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
+ 2011-01-20 12:33 . 2011-01-20 12:33 81784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-01-20 12:34 . 2011-01-20 12:34 81800 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
+ 2011-01-20 12:34 . 2011-01-20 12:34 39784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
+ 2011-01-20 12:35 . 2011-01-20 12:35 68952 c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
+ 2011-01-20 12:35 . 2011-01-20 12:35 62880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.ApplicationServer.Applications\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Windows.ApplicationServer.Applications.dll
+ 2011-01-20 12:33 . 2011-01-20 12:33 12128 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-01-20 12:35 . 2011-01-20 12:35 97680 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2011-01-20 12:33 . 2011-01-20 12:33 17240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2011-01-20 12:32 . 2011-01-20 12:32 94552 c:\windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2011-01-20 12:33 . 2011-01-20 12:33 91488 c:\windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2011-01-20 12:30 . 2011-01-20 12:30 78168 c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2011-01-20 12:30 . 2011-01-20 12:30 81248 c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2011-01-20 16:55 . 2011-01-20 16:55 10752 c:\windows\assembly\NativeImages_v4.0.30319_64\dfsvc\a354197a45ffa73be93177ed5b0ce377\dfsvc.ni.exe
+ 2011-01-20 16:54 . 2011-01-20 16:54 57856 c:\windows\assembly\NativeImages_v4.0.30319_64\Accessibility\dea86a81aacc28e408507e311da6d2fa\Accessibility.ni.dll
+ 2011-01-20 13:03 . 2011-01-20 13:03 61440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\1a7d8a4e19551215600c58866cf3637d\WindowsLiveWriter.ni.exe
+ 2011-01-20 13:04 . 2011-01-20 13:04 80896 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\1c56d310963e650054cced796a3e332a\WindowsLive.Writer.Passport.ni.dll
- 2010-05-13 04:56 . 2011-01-20 04:59 7130 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2010-05-13 04:56 . 2011-01-20 12:45 7130 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2010-03-11 09:17 . 2011-01-20 13:36 4394 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Bluetooth\bthservsdp.dat
- 2010-03-11 09:17 . 2011-01-20 05:16 4394 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Bluetooth\bthservsdp.dat
+ 2011-01-20 13:37 . 2011-01-20 16:28 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-01-20 05:17 . 2011-01-20 05:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-01-20 05:17 . 2011-01-20 05:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-01-20 13:37 . 2011-01-20 16:28 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.3082.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.3076.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.2070.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8024 c:\windows\Microsoft.NET\NETFXRepair.2052.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.1055.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.1053.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 9048 c:\windows\Microsoft.NET\NETFXRepair.1049.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.1046.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.1045.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.1044.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.1043.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.1042.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.1041.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.1040.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.1038.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.1037.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 9048 c:\windows\Microsoft.NET\NETFXRepair.1036.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 9048 c:\windows\Microsoft.NET\NETFXRepair.1035.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.1033.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 9048 c:\windows\Microsoft.NET\NETFXRepair.1032.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.1031.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.1030.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.1029.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8024 c:\windows\Microsoft.NET\NETFXRepair.1028.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8536 c:\windows\Microsoft.NET\NETFXRepair.1025.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 8032 c:\windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelRegUI.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 8040 c:\windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 8032 c:\windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8032 c:\windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelRegUI.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8040 c:\windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelInstallRC.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 8032 c:\windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelEvents.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 771424 c:\windows\SysWOW64\msvcr100_clr0400.dll
+ 2010-03-19 23:02 . 2011-01-20 22:29 392994 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2009-07-14 02:36 . 2011-01-20 12:28 629834 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-01-20 12:28 111970 c:\windows\system32\perfc009.dat
+ 2010-03-18 06:27 . 2010-03-18 06:27 827744 c:\windows\system32\msvcr100_clr0400.dll
+ 2011-01-16 12:14 . 2011-01-20 12:10 818896 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2011-01-16 12:14 . 2011-01-20 05:16 818896 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2009-07-14 05:01 . 2011-01-20 05:16 508704 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-01-20 13:36 508704 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-03-18 05:16 . 2010-03-18 05:16 114520 c:\windows\Microsoft.NET\NETFXRepair.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 350592 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\UIAutomationClientsideProviders.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 163168 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\UIAutomationClient.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 675672 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\System.Speech.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 335712 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\System.Printing.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 581464 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\ReachFramework.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 832856 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationUI.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 225640 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationHost_v0400.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 194424 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.Royale.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 478576 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.Luna.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 167288 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.Classic.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 232304 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.Aero.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 138592 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Xml.Linq.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 699224 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Xaml.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 857960 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.Services.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 288616 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Transactions.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 113512 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceProcess.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 129912 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.Routing.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 390008 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.Discovery.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 505208 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.Activities.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 261472 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Security.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 122264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 291184 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Remoting.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 349568 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.DurableInstancing.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 231760 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Net.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 253280 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Messaging.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 134528 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Management.Instrumentation.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 378720 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Management.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 123736 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.IO.Log.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 125816 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.IdentityModel.Selectors.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 392552 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.IdentityModel.dll
+ 2010-03-17 21:46 . 2010-03-17 21:46 125440 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.EnterpriseServices.Wrapper.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 237424 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.EnterpriseServices.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 120152 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Dynamic.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 607064 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Drawing.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 182144 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.DirectoryServices.Protocols.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 395120 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.DirectoryServices.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 285072 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.DirectoryServices.AccountManagement.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 829280 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Deployment.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 747360 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.SqlXml.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 436600 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.Services.Client.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 683872 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.Linq.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 409448 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.configuration.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 210816 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.ComponentModel.Composition.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 149848 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.AddIn.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 122248 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Activities.DurableInstancing.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 525704 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Activities.Core.Presentation.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 112976 c:\windows\Microsoft.NET\Framework64\v4.0.30319\sysglobl.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 597832 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SOS.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 124240 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
+ 2009-08-31 10:44 . 2009-08-31 10:44 144416 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\sqmapi.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 295248 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\SetupUi.dll
+ 2010-03-18 20:16 . 2010-03-18 20:16 807256 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\SetupEngine.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 235872 c:\windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelReg.exe
+ 2010-03-18 06:27 . 2010-03-18 06:27 130392 c:\windows\Microsoft.NET\Framework64\v4.0.30319\PerfCounter.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 168776 c:\windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe
+ 2010-03-18 06:27 . 2010-03-18 06:27 138576 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
+ 2010-03-18 06:27 . 2010-03-18 06:27 543056 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvc.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 114520 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsecimpl.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 372560 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 183640 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 578896 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 661352 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.VisualBasic.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 349576 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.VisualBasic.Compatibility.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 187776 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Transactions.Bridge.Dtc.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 387960 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Transactions.Bridge.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 746336 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.JScript.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 505184 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.CSharp.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 794464 c:\windows\Microsoft.NET\Framework64\v4.0.30319\EventLogMessages.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 939864 c:\windows\Microsoft.NET\Framework64\v4.0.30319\diasymreader.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 123720 c:\windows\Microsoft.NET\Framework64\v4.0.30319\dfdll.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 138584 c:\windows\Microsoft.NET\Framework64\v4.0.30319\CORPerfMonExt.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 105296 c:\windows\Microsoft.NET\Framework64\v4.0.30319\AppLaunch.exe
+ 2010-03-18 06:27 . 2010-03-18 06:27 134984 c:\windows\Microsoft.NET\Framework64\v4.0.30319\alink.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 166224 c:\windows\Microsoft.NET\Framework64\v4.0.30319\AdoNetDiag.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 255304 c:\windows\Microsoft.NET\Framework64\v4.0.30319\1033\vbc7ui.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 255896 c:\windows\Microsoft.NET\Framework64\v4.0.30319\1033\Microsoft.VisualBasic.Activities.CompilerUI.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 182088 c:\windows\Microsoft.NET\Framework64\v4.0.30319\1033\cscui.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 350592 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\UIAutomationClientsideProviders.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 163168 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\UIAutomationClient.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 675672 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\System.Speech.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 334688 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\System.Printing.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 581464 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\ReachFramework.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 832856 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationUI.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 801136 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationNative_v0400.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 181096 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationHost_v0400.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 194424 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.Royale.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 478576 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.Luna.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 167288 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.Classic.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 232304 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.Aero.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 807264 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\NaturalLanguage6.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 138592 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Xml.Linq.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 699224 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Xaml.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 857960 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.Services.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 269672 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Transactions.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 113512 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceProcess.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 129912 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceModel.Routing.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 390008 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceModel.Discovery.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 505208 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceModel.Activities.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 261472 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Security.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 122264 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 291184 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Remoting.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 349568 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.DurableInstancing.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 231760 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Net.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 253280 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Messaging.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 134528 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Management.Instrumentation.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 378720 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Management.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 123736 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.IO.Log.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 125816 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.IdentityModel.Selectors.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 392552 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.IdentityModel.dll
+ 2010-03-17 16:51 . 2010-03-17 16:51 109568 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.EnterpriseServices.Wrapper.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 246128 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.EnterpriseServices.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 120152 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Dynamic.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 607064 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Drawing.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 182144 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.DirectoryServices.Protocols.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 395120 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.DirectoryServices.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 285072 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.DirectoryServices.AccountManagement.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 829280 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Deployment.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 747360 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Data.SqlXml.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 436600 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Data.Services.Client.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 683872 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Data.Linq.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 409448 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.configuration.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 210816 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.ComponentModel.Composition.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 149848 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.AddIn.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 122248 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Activities.DurableInstancing.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 525704 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Activities.Core.Presentation.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 112976 c:\windows\Microsoft.NET\Framework\v4.0.30319\sysglobl.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 517448 c:\windows\Microsoft.NET\Framework\v4.0.30319\SOS.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 124240 c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 173920 c:\windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelReg.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 121688 c:\windows\Microsoft.NET\Framework\v4.0.30319\PerfCounter.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 150856 c:\windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 130384 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 335184 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvc.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 110936 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsecimpl.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 372048 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 145752 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorpehost.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 413008 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 955728 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordbi.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 661352 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.VisualBasic.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 349576 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.VisualBasic.Compatibility.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 170368 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Transactions.Bridge.Dtc.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 387960 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Transactions.Bridge.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 746336 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.JScript.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 505184 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.CSharp.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 794464 c:\windows\Microsoft.NET\Framework\v4.0.30319\EventLogMessages.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 688472 c:\windows\Microsoft.NET\Framework\v4.0.30319\diasymreader.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 129880 c:\windows\Microsoft.NET\Framework\v4.0.30319\CORPerfMonExt.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 385864 c:\windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 105808 c:\windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 105288 c:\windows\Microsoft.NET\Framework\v4.0.30319\alink.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 139088 c:\windows\Microsoft.NET\Framework\v4.0.30319\AdoNetDiag.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 255304 c:\windows\Microsoft.NET\Framework\v4.0.30319\1033\vbc7ui.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 255896 c:\windows\Microsoft.NET\Framework\v4.0.30319\1033\Microsoft.VisualBasic.Activities.CompilerUI.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 182088 c:\windows\Microsoft.NET\Framework\v4.0.30319\1033\cscui.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 350592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 163168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
+ 2011-01-20 12:35 . 2011-01-20 12:35 138592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 699224 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 857960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 675672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
+ 2011-01-20 12:34 . 2011-01-20 12:34 113512 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2011-01-20 12:36 . 2011-01-20 12:36 129912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
+ 2011-01-20 12:36 . 2011-01-20 12:36 390008 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
+ 2011-01-20 12:36 . 2011-01-20 12:36 505208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
+ 2011-01-20 12:34 . 2011-01-20 12:34 261472 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-01-20 12:36 . 2011-01-20 12:36 122264 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 291184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2011-01-20 12:36 . 2011-01-20 12:36 349568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
+ 2011-01-20 12:35 . 2011-01-20 12:35 231760 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
+ 2011-01-20 12:36 . 2011-01-20 12:36 253280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2011-01-20 12:34 . 2011-01-20 12:34 378720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2011-01-20 12:35 . 2011-01-20 12:35 134528 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
+ 2011-01-20 12:36 . 2011-01-20 12:36 123736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
+ 2011-01-20 12:36 . 2011-01-20 12:36 392552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
+ 2011-01-20 12:36 . 2011-01-20 12:36 125816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
+ 2011-01-20 12:33 . 2011-01-20 12:33 120152 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
+ 2011-01-20 12:34 . 2011-01-20 12:34 607064 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2011-01-20 12:33 . 2011-01-20 12:33 395120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2011-01-20 12:33 . 2011-01-20 12:33 182144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2011-01-20 12:33 . 2011-01-20 12:33 285072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
+ 2011-01-20 12:33 . 2011-01-20 12:33 829280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2011-01-20 12:33 . 2011-01-20 12:33 747360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2011-01-20 12:35 . 2011-01-20 12:35 436600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
+ 2011-01-20 12:34 . 2011-01-20 12:34 683872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
+ 2011-01-20 12:33 . 2011-01-20 12:33 409448 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2011-01-20 12:34 . 2011-01-20 12:34 210816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
+ 2011-01-20 12:34 . 2011-01-20 12:34 149848 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll
+ 2011-01-20 12:36 . 2011-01-20 12:36 122248 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
+ 2011-01-20 12:35 . 2011-01-20 12:35 525704 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
+ 2011-01-20 12:33 . 2011-01-20 12:33 112976 c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 581464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 832856 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 194424 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 478576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 167288 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 232304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2011-01-20 12:33 . 2011-01-20 12:33 661352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2011-01-20 12:35 . 2011-01-20 12:35 349576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2011-01-20 12:35 . 2011-01-20 12:35 387960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
+ 2011-01-20 12:33 . 2011-01-20 12:33 746336 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2011-01-20 12:32 . 2011-01-20 12:32 505184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 288616 c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 335712 c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2011-01-20 12:32 . 2011-01-20 12:32 125440 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2011-01-20 12:32 . 2011-01-20 12:32 237424 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-01-20 12:35 . 2011-01-20 12:35 187776 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2011-01-20 12:32 . 2011-01-20 12:32 269672 c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2011-01-20 12:32 . 2011-01-20 12:32 334688 c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2011-01-20 12:30 . 2011-01-20 12:30 109568 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2011-01-20 12:30 . 2011-01-20 12:30 246128 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-01-20 12:31 . 2011-01-20 12:31 170368 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2011-01-20 17:47 . 2011-01-20 17:47 424960 c:\windows\assembly\NativeImages_v4.0.30319_64\SMSvcHost\ef022a4092ef0a271b4dd7d12264dae8\SMSvcHost.ni.exe
+ 2011-01-20 17:48 . 2011-01-20 17:48 276992 c:\windows\assembly\NativeImages_v4.0.30319_64\CustomMarshalers\484c3c0ed451c906dec30445553d8fc1\CustomMarshalers.ni.dll
+ 2011-01-20 12:50 . 2011-01-20 12:50 690176 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\ea21918644eb5bcc678bd72c4c7564a8\System.ComponentModel.Composition.ni.dll
+ 2011-01-20 13:08 . 2011-01-20 13:08 634368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\da03cf74d1a0ae469e900559c58ce7c3\WindowsLiveLocal.WriterPlugin.ni.dll
+ 2011-01-20 13:04 . 2011-01-20 13:04 174080 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f18b174c2399ef63bfbb7593471af6f0\WindowsLive.Writer.BrowserControl.ni.dll
+ 2011-01-20 13:04 . 2011-01-20 13:04 156672 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f0f3b1ab9bc51749b0755e096e3a1022\WindowsLive.Writer.HtmlParser.ni.dll
+ 2011-01-20 13:04 . 2011-01-20 13:04 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\e7250f69097b1d008b36187a31221c13\WindowsLive.Writer.Mshtml.ni.dll
+ 2011-01-20 13:04 . 2011-01-20 13:04 313856 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\e0babbc3d3f187878fea690528553190\WindowsLive.Writer.Interop.SHDocVw.ni.dll
+ 2011-01-20 13:06 . 2011-01-20 13:06 871424 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\bcc6fff9c5d31e671dc2db9e97a40d91\WindowsLive.Writer.BlogClient.ni.dll
+ 2011-01-20 13:04 . 2011-01-20 13:04 374272 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b61774176bf9583ffc7fe34d127a3501\WindowsLive.Writer.Interop.Mshtml.ni.dll
+ 2011-01-20 13:04 . 2011-01-20 13:04 101376 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\afe4c86f112afbd802f90a7cd4a8e238\WindowsLive.Writer.Api.ni.dll
+ 2011-01-20 13:04 . 2011-01-20 13:04 665600 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\a6b1df8e43c3703906bd13bfbbc1ff73\WindowsLive.Writer.Interop.ni.dll
+ 2011-01-20 13:04 . 2011-01-20 13:04 146432 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\79396a535e4c9b21b926951b015547ed\WindowsLive.Writer.Instrumentation.ni.dll
+ 2011-01-20 13:06 . 2011-01-20 13:06 326144 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\64ccd8749a21b24e9aa1d0fdd59df478\WindowsLive.Writer.SpellChecker.ni.dll
+ 2011-01-20 13:04 . 2011-01-20 13:04 780800 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\616af906a262ab0ba58125082bdee293\WindowsLive.Writer.Controls.ni.dll
+ 2011-01-20 13:07 . 2011-01-20 13:07 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\5cd3dd2eb2a819e7b4d22f95a28933fb\WindowsLive.Writer.FileDestinations.ni.dll
+ 2011-01-20 13:04 . 2011-01-20 13:04 122368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\447414d6dad428772654ef0672e945b6\WindowsLive.Writer.Extensibility.ni.dll
+ 2011-01-20 13:05 . 2011-01-20 13:05 890880 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\3a93fba89f4df11045af196748b0f593\WindowsLive.Writer.HtmlEditor.ni.dll
+ 2011-01-20 13:07 . 2011-01-20 13:07 223232 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\caaf1d059daf459ac4cf10c8019f3e44\WindowsLive.Client.ni.dll
- 2010-07-25 13:02 . 2011-01-20 05:16 1181994 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-309132136-2634883446-1347342510-1000-12288.dat
+ 2010-07-25 13:02 . 2011-01-20 13:36 1181994 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-309132136-2634883446-1347342510-1000-12288.dat
+ 2010-03-18 06:27 . 2010-03-18 06:27 2153816 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\wpfgfx_v0400.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 1303896 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WindowsBase.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 1098096 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationNative_v0400.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 6346600 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 3453792 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationCore.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 2650464 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\NlsLexicons0009.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 6353752 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\NlsData0009.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 1367904 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\NaturalLanguage6.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 3170632 c:\windows\Microsoft.NET\Framework64\v4.0.30319\vbc.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 2207568 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.XML.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 4982120 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Windows.Forms.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 1711496 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Windows.Forms.DataVisualization.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 6067048 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 1026936 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 3481928 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 4464480 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.Entity.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 3111768 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 1339736 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Core.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 1462648 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Activities.Presentation.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 1199968 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Activities.dll
+ 2010-03-18 21:41 . 2010-03-18 21:41 1901056 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\netfx_core_x64.msi
+ 2010-03-18 06:27 . 2010-03-18 06:27 4960080 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorlib.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 1453392 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordbi.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 1513304 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordacwks.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 3563408 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 2492232 c:\windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe
+ 2010-03-18 06:27 . 2010-03-18 06:27 1524552 c:\windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll
+ 2010-03-18 06:27 . 2010-03-18 06:27 9798472 c:\windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 1663320 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\wpfgfx_v0400.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 1303896 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsBase.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 6346600 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 3545952 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationCore.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 2650464 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\NlsLexicons0009.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 4881752 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\NlsData0009.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 2199880 c:\windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 2207568 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.XML.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 4982120 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Windows.Forms.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 1711496 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Windows.Forms.DataVisualization.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 6067048 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceModel.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 1026936 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 3481928 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 4464480 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Data.Entity.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 2970968 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Data.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 1339736 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Core.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 1462648 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Activities.Presentation.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 1199968 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Activities.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 5196112 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 1141592 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordacwks.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 2989456 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2010-03-18 05:16 . 2010-03-18 05:16 1972552 c:\windows\Microsoft.NET\Framework\v4.0.30319\csc.exe
+ 2010-03-18 05:16 . 2010-03-18 05:16 6730056 c:\windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 1303896 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2011-01-20 12:34 . 2011-01-20 12:34 3481928 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
+ 2011-01-20 12:34 . 2011-01-20 12:34 2207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
+ 2011-01-20 12:34 . 2011-01-20 12:34 4982120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2011-01-20 12:34 . 2011-01-20 12:34 1711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
+ 2011-01-20 12:36 . 2011-01-20 12:36 6067048 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2011-01-20 12:36 . 2011-01-20 12:36 1026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
+ 2011-01-20 12:34 . 2011-01-20 12:34 4464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
+ 2011-01-20 12:34 . 2011-01-20 12:34 1339736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
+ 2011-01-20 12:36 . 2011-01-20 12:36 1199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
+ 2011-01-20 12:35 . 2011-01-20 12:35 1462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 6346600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2011-01-20 12:33 . 2011-01-20 12:33 3111768 c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-01-20 12:37 . 2011-01-20 12:37 3453792 c:\windows\Microsoft.NET\assembly\GAC_64\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2011-01-20 12:32 . 2011-01-20 12:32 4960080 c:\windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-01-20 12:35 . 2011-01-20 12:35 3563408 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2011-01-20 12:30 . 2011-01-20 12:30 2970968 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-01-20 12:32 . 2011-01-20 12:32 3545952 c:\windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2011-01-20 12:30 . 2011-01-20 12:30 5196112 c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-01-20 12:31 . 2011-01-20 12:31 2989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2010-03-18 21:41 . 2010-03-18 21:41 1901056 c:\windows\Installer\808cb.msi
+ 2010-03-18 21:41 . 2010-03-18 21:41 1901056 c:\windows\Installer\808c6.msi
+ 2011-01-20 22:42 . 2011-01-20 22:42 6972928 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml\5d9f385419332f14eaf937556199856f\System.Xml.ni.dll
+ 2011-01-20 22:41 . 2011-01-20 22:41 1247232 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\11581b5eba4b3ff58441c638ab66c742\System.Configuration.ni.dll
+ 2011-01-20 22:40 . 2011-01-20 22:40 1968640 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.CSharp\4e7049d81f575a6e0652f7af80040a17\Microsoft.CSharp.ni.dll
+ 2011-01-20 12:50 . 2011-01-20 12:50 9000960 c:\windows\assembly\NativeImages_v4.0.30319_32\System\161c6f80ad93b0505054d244f1c6243c\System.ni.dll
+ 2011-01-20 12:50 . 2011-01-20 12:50 5571584 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml\2d7c29ad77c15abfa6a8fe6d24840a91\System.Xml.ni.dll
+ 2011-01-20 12:50 . 2011-01-20 12:50 1651200 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\2fe09cc54a8390b20e380239db34228f\System.Drawing.ni.dll
+ 2011-01-20 12:50 . 2011-01-20 12:50 6754816 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data\c12e10c218be4be353975af6abb072d9\System.Data.ni.dll
+ 2011-01-20 12:50 . 2011-01-20 12:50 2499072 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\73dd24232790e0e5c2649dde8e65516c\System.Data.Linq.ni.dll
+ 2011-01-20 12:50 . 2011-01-20 12:50 7025664 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Core\85693dfd9ba4905b0fd947fdb51446d5\System.Core.ni.dll
+ 2011-01-20 13:04 . 2011-01-20 13:04 7024640 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ecbdeb284eb7283023f7bde571fa6f83\WindowsLive.Writer.PostEditor.ni.dll
+ 2011-01-20 13:04 . 2011-01-20 13:04 1346560 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\bd5234746de53f5653283ed2c203db4a\WindowsLive.Writer.Localization.ni.dll
+ 2011-01-20 13:04 . 2011-01-20 13:04 2193408 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\83af9c3dfb8177ce4b4122b2fdb1158e\WindowsLive.Writer.CoreServices.ni.dll
+ 2011-01-20 13:04 . 2011-01-20 13:04 1284608 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\784ce508e9080504961450bc6d4be29a\WindowsLive.Writer.ApplicationFramework.ni.dll
- 2009-07-14 02:34 . 2011-01-20 06:04 10088448 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2009-07-14 02:34 . 2011-01-20 12:30 10088448 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2011-01-20 17:46 . 2011-01-20 17:46 11722240 c:\windows\assembly\NativeImages_v4.0.30319_64\System\0f8f78b729ce16dd078f5d5f734a1110\System.ni.dll
+ 2011-01-20 22:40 . 2011-01-20 22:40 10199552 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Core\7a93c267da35a5f16b6fa5a10482eb4e\System.Core.ni.dll
+ 2011-01-20 12:42 . 2011-01-20 12:42 19348992 c:\windows\assembly\NativeImages_v4.0.30319_64\mscorlib\bc19222db4406c472d9aa1f8b6e0f470\mscorlib.ni.dll
+ 2011-01-20 12:50 . 2011-01-20 12:50 13006336 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\f3cdd09fc0acc85c7febbd2e2ef9c4e5\System.Windows.Forms.ni.dll
+ 2011-01-20 12:49 . 2011-01-20 12:49 14415872 c:\windows\assembly\NativeImages_v4.0.30319_32\mscorlib\4ff1f12a08d455f195ba996fe77497c6\mscorlib.ni.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-09-22 4240760]
"Google Update"="c:\users\Firdaus\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-07-03 136176]
"Messenger (Yahoo!)"="c:\progra~2\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]
"Octoshape Streaming Services"="c:\users\Firdaus\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-08 70936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 1807600]
"FATrayAlert"="c:\program files (x86)\Sensible Vision\Fast Access\FATrayMon.exe" [2009-06-24 95496]
"PDVDDXSrv"="c:\program files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-06-24 409744]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-10-15 498160]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2010-12-02 74752]
"vmware-tray"="c:\program files (x86)\VMware\VMware Workstation\vmware-tray.exe" [2010-03-09 129584]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-22 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2010-11-20 274608]
"lxdnmon.exe"="c:\program files (x86) (x86)\Lexmark 2600 Series\lxdnmon.exe" [2009-10-28 660136]
"EzPrint"="c:\program files (x86) (x86)\Lexmark 2600 Series\ezprint.exe" [2009-10-28 107176]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"FAStartup"="" [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe" [2010-07-21 165184]

c:\users\Firdaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-9-22 1316192]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-2 1079584]

c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-9-22 1316192]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FastAccess]
2009-06-24 22:31 140552 —-a-w- c:\program files (x86)\Sensible Vision\Fast Access\FALogNot.dll

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

R0 Shadow;Shadow; [x]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-17 136176]
R3 CFcatchme;CFcatchme;c:\users\Firdaus\AppData\Local\Temp\CFcatchme.sys [x]
R3 FACAP;facap, FastAccess Video Capture;c:\windows\system32\DRIVERS\facap.sys [2008-09-25 238848]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 netr7364;RT73 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr7364.sys [2009-06-10 707072]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2010-11-18 25072]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-05-08 215552]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 diskpt;diskpt;c:\windows\SYSTEM32\drivers\diskpt.sys [2010-02-08 249184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe [2009-03-02 89600]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-01-13 62032]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
S2 FAService;FAService;c:\program files (x86)\Sensible Vision\Fast Access\FAService.exe [2009-06-24 2368776]
S2 HssWd;Hotspot Shield Monitoring Service;c:\program files (x86)\Hotspot Shield\bin\hsswd.exe [2010-06-23 322608]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 47632]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2010-08-20 689472]
S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [2010-03-09 126000]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [2010-03-09 540672]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-08-05 35104]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2009-06-15 172704]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-05-22 215040]

.
Contents of the 'Scheduled Tasks' folder

2011-01-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-17 06:21]

2011-01-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-17 06:21]

2011-01-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-309132136-2634883446-1347342510-1000Core.job
- c:\users\Firdaus\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-03 13:00]

2011-01-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-309132136-2634883446-1347342510-1000UA.job
- c:\users\Firdaus\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-03 13:00]

2011-01-13 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2010-11-18 15:13]

2011-01-20 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\pcdrcui.exe [2010-11-18 15:13]
.

——— x86-64 ———–


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-03-10 309760]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-06-05 165912]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-06-05 385560]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-06-05 365080]
"Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4968960]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-06-29 444416]
"Shadow Defender Daemon"="c:\program files\Shadow Defender\DefenderDaemon.exe" [2010-02-09 302908]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-05 500208]
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2737658
mStart Page = hxxp://search.Facesounds.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = local;172.16.110.33:80
uInternet Settings,ProxyServer = 211.138.124.232:80
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\program files (x86)\VMware\VMware Workstation\vsocklib.dll
TCP: {0282556B-EA02-4ABF-8C86-0127D44031AF} = 10.54.0.1
TCP: {B641FD9E-0457-4CDF-A47A-E824C18C2D7F} = 208.67.222.222,208.67.222.220
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
FF - ProfilePath - c:\users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2737658&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - prefs.js: keyword.URL - hxxp://search.Facesounds.com/?q=
FF - prefs.js: network.proxy.ftp - 211.138.124.232
FF - prefs.js: network.proxy.ftp_port - 80
FF - prefs.js: network.proxy.gopher - [removed]
FF - prefs.js: network.proxy.gopher_port - 80
FF - prefs.js: network.proxy.http - [removed]
FF - prefs.js: network.proxy.http_port - 80
FF - prefs.js: network.proxy.socks - [removed]
FF - prefs.js: network.proxy.socks_port - 80
FF - prefs.js: network.proxy.ssl - [removed]
FF - prefs.js: network.proxy.ssl_port - 80
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension for Firefox: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Cooliris: [removed] - %profile%\extensions\[removed]
FF - Ext: Softonic English Toolbar: {930f1200-f5f1-4870-bac6-e233ec8e7023} - %profile%\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}
FF - Ext: BitDefender QuickScan: {e001c731-5e37-4538-a5cb-8168736a2360} - %profile%\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
FF - Ext: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - %profile%\extensions\{f999a48b-1950-4d81-9971-79018f807b4b}
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)


.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-309132136-2634883446-1347342510-1000\Software\SecuROM\License information*]
"datasecu"=hex:d0,2b,c1,5e,53,5a,d5,1a,aa,59,93,75,48,85,f3,de,09,d9,fb,e5,95,
88,83,1c,8a,f3,34,f7,ad,81,27,08,91,dc,de,9d,60,ab,4a,db,5e,8f,26,c4,8e,7d,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-01-21 19:59:21
ComboFix-quarantined-files.txt 2011-01-21 11:59
ComboFix2.txt 2011-01-19 12:21

Pre-Run: 13,203,488,768 bytes free
Post-Run: 12,810,293,248 bytes free

- - End Of File - - 3B3F2BBE062D77212FD6DBE855D0FB6B
Hi,

Thanks for you patience. :)

It may have been due to an update made to your system between runs of Combofix.

Please do the following:

Download Malwarebytes' Anti-Malware to your desktop.
  • Right-click mbam-setup.exe then choose "Run as Administrator" and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post back the log.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.

–Next–

Right click Internet Explorer or Firefox then choose "Run as Administrator" to run the program.

NOTE: After scanning with ESET, close your browser then run it without administrator privileges for your browsing.

Go here to run an online scanner from ESET.

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
–Next–

Run a fresh DDS scan for me please then post the logs.

To post in your next reply:
1. Malwarebytes' log.
2. ESET log.
3. DDS logs.
4. How is your computer?
Hi,

I encounter another problem.

When i start my computer, there was a popup FATrayALert.exe appear and written 'The program cant start because FAib.dll is missing from your computer.Try reinstalling the program to fix this problem'. And then when i close the popup,its still appear again and again.What should I do?

This is the logs you ask previously ;

Regard,

Firdaus

1. Malwarebytes' log.

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 5567

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

22/1/2011 10:53:12 AM
mbam-log-2011-01-22 (10-53-12).txt

Scan type: Quick scan
Objects scanned: 159980
Time elapsed: 34 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


2. ESET log.

ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.7600.16385 (win7_rtm.090713-1255)
# OnlineScanner.ocx=1.0.0.6419
# api_version=3.0.2
# EOSSerial=33fce25d14c4a94a9121a4874d1bea4c
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-01-22 05:50:33
# local_time=2011-01-22 01:50:33 (+0800, Malay Peninsula Standard Time)
# country="Malaysia"
# lang=1033
# osver=6.1.7600 NT
# compatibility_mode=768 16777215 100 0 21496997 21496997 0 0
# compatibility_mode=1024 16777215 100 0 23384002 23384002 0 0
# compatibility_mode=5893 16776573 100 94 46628 47297186 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=231725
# found=11
# cleaned=0
# scan_time=8122
C:\$RECYCLE.BIN\S-1-5-21-309132136-2634883446-1347342510-1000\$RDM7VI2.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\$RECYCLE.BIN\S-1-5-21-309132136-2634883446-1347342510-1000\$REEM56V.exe Win32/Adware.RegistryEasy application (unable to clean) 00000000000000000000000000000000 I
C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe a variant of Win32/HotSpotShield application (unable to clean) 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\Windows\KMSAct.exe.vir Win32/HackKMS.A application (unable to clean) 00000000000000000000000000000000 I
C:\Users\Firdaus\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000635 Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Users\Firdaus\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00063b Win32/Adware.RegistryEasy application (unable to clean) 00000000000000000000000000000000 I
C:\Users\Firdaus\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WZUB88T7\index-functions[1].js Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
D:\Education\CCNA\vce reader.zip a variant of Win32/HackTool.Patcher.A application (unable to clean) 00000000000000000000000000000000 I
D:\Software\Aktivator Microsoft Office 2010Blog MAok\O2ACK1.3.exe probably a variant of Win32/Agent.DMNPCPA trojan (unable to clean) 00000000000000000000000000000000 I
D:\Software\Aktivator Microsoft Office 2010Blog MAok\Resources\KMSAct\KMSAct.exe Win32/HackKMS.A application (unable to clean) 00000000000000000000000000000000 I
D:\Software\KMS Activator for Microsoft Office 2010 Applications x86 x64 Multilingual-FIXISO~DiBYA\KMS Activator.exe a variant of Win32/HackKMS.A application (unable to clean) 00000000000000000000000000000000 I


3. DDS logs




DDS (Ver_10-12-12.02) - NTFS_AMD64
Run by [removed] at 13:54:51.04 on Sat 22/01/2011
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_23
Microsoft Windows 7 Home Basic 6.1.7600.0.1252.60.1033.18.2010.720 [GMT 8:00]

AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
C:\Windows\SysWOW64\vmnat.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe
C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\SysWOW64\vmnetdhcp.exe
C:\Windows\System32\igfxtray.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Shadow Defender\DefenderDaemon.exe
C:\Users\Firdaus\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
C:\Users\Firdaus\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86) (x86)\Lexmark 2600 Series\ezprint.exe
C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnetwk.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Windows Live\Companion\companionuser.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Windows\system32\notepad.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Dell Support Center\imstrayicon.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Firdaus\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2737658
mStart Page = hxxp://search.Facesounds.com
uInternet Settings,ProxyOverride = local;172.16.110.33:80
uInternet Settings,ProxyServer = 211.138.124.232:80
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: FAIESSOHelper Class: {a2f122da-055f-4df7-8f24-7354dbdba85b} - c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
BHO: {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Google Update] "C:\Users\Firdaus\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
uRun: [Octoshape Streaming Services] "C:\Users\Firdaus\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
mRun: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
mRun: [FATrayAlert] c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
mRun: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
mRun: [lxdnmon.exe] "C:\Program Files (x86) (x86)\Lexmark 2600 Series\lxdnmon.exe"
mRun: [EzPrint] "C:\Program Files (x86) (x86)\Lexmark 2600 Series\ezprint.exe"
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [FAStartup]
mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe
StartupFolder: C:\Users\Firdaus\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLDO~1.LNK - C:\Program Files\Dell\DellDock\DellDock.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: Send image to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
LSP: C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
TCP: {0282556B-EA02-4ABF-8C86-0127D44031AF} = 10.54.0.1
TCP: {B641FD9E-0457-4CDF-A47A-E824C18C2D7F} = 208.67.222.222,208.67.222.220
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: FastAccess - c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
mRun-x64: [Apoint] C:\Program Files\DellTPad\Apoint.exe
mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe
mRun-x64: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe
mRun-x64: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
mRun-x64: [Shadow Defender Daemon] "C:\Program Files\Shadow Defender\DefenderDaemon.exe" /Auto
mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL

================= FIREFOX ===================

FF - ProfilePath - C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2737658&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - prefs.js: keyword.URL - hxxp://search.Facesounds.com/?q=
FF - prefs.js: network.proxy.ftp - 211.138.124.232
FF - prefs.js: network.proxy.ftp_port - 80
FF - prefs.js: network.proxy.gopher - [removed]
FF - prefs.js: network.proxy.gopher_port - 80
FF - prefs.js: network.proxy.http - [removed]
FF - prefs.js: network.proxy.http_port - 80
FF - prefs.js: network.proxy.socks - [removed]
FF - prefs.js: network.proxy.socks_port - 80
FF - prefs.js: network.proxy.ssl - 211.138.124.232
FF - prefs.js: network.proxy.ssl_port - 80
FF - prefs.js: network.proxy.type - 0
FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - component: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordlegacyext.dll
FF - component: C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\components\FFExternalAlert.dll
FF - component: C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\components\RadioWMPCore.dll
FF - component: C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
FF - component: C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\extensions\{f999a48b-1950-4d81-9971-79018f807b4b}\components\FFExternalAlert.dll
FF - component: C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\extensions\{f999a48b-1950-4d81-9971-79018f807b4b}\components\RadioWMPCore.dll
FF - component: C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Users\Firdaus\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Users\Firdaus\AppData\Local\Yahoo!\BrowserPlus\2.7.1\Plugins\npybrowserplus_2.7.1.dll
FF - plugin: C:\Users\Firdaus\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: C:\Users\Firdaus\AppData\Roaming\Mozilla\Firefox\Profiles\08h69mbk.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: C:\Users\Firdaus\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension for Firefox: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Cooliris: [removed] - %profile%\extensions\[removed]
FF - Ext: Softonic English Toolbar: {930f1200-f5f1-4870-bac6-e233ec8e7023} - %profile%\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}
FF - Ext: BitDefender QuickScan: {e001c731-5e37-4538-a5cb-8168736a2360} - %profile%\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
FF - Ext: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - %profile%\extensions\{f999a48b-1950-4d81-9971-79018f807b4b}
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext

============= SERVICES / DRIVERS ===============

R0 diskpt;diskpt;C:\Windows\System32\drivers\diskpt.sys [2010-3-16 249184]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2011-1-18 273488]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2011-1-18 20560]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2011-1-18 62032]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2010-3-11 35104]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2010-3-11 172704]
S3 FACAP;facap, FastAccess Video Capture;C:\Windows\System32\drivers\facap.sys [2008-9-25 238848]

=============== Created Last 30 ================

2011-01-22 03:27:57 ——– d—–w- C:\Program Files (x86)\ESET
2011-01-21 14:38:28 7844688 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{4E2705C2-8BAA-4CFD-913F-1501CC3CBE5B}\mpengine.dll
2011-01-21 12:11:21 ——– d-sh–w- C:\$RECYCLE.BIN
2011-01-20 04:45:23 ——– d—–w- C:\Windows\en
2011-01-20 04:28:06 48488 —-a-w- C:\Windows\System32\drivers\fssfltr.sys
2011-01-20 04:05:32 469256 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\43b155f21cbb85709\InstallManager_WLE_WLE.exe
2011-01-20 04:05:19 15712 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\3f11cbde1cbb85708\MeshBetaRemover.exe
2011-01-20 04:05:16 94040 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\3c6ba8301cbb85707\DSETUP.dll
2011-01-20 04:05:16 525656 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\3c6ba8301cbb85707\DXSETUP.exe
2011-01-20 04:05:16 1691480 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\3c6ba8301cbb85707\dsetup32.dll
2011-01-20 04:05:09 525656 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\3814e7fc1cbb85706\DXSETUP.exe
2011-01-20 04:05:09 1691480 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\3814e7fc1cbb85706\dsetup32.dll
2011-01-20 04:05:08 94040 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\3814e7fc1cbb85706\DSETUP.dll
2011-01-20 04:04:34 ——– d—–w- C:\Users\Firdaus\AppData\Local\Windows Live
2011-01-20 04:03:11 257024 —-a-w- C:\Windows\System32\mfreadwrite.dll
2011-01-20 04:03:11 206848 —-a-w- C:\Windows\System32\mfps.dll
2011-01-20 04:03:10 196608 —-a-w- C:\Windows\SysWow64\mfreadwrite.dll
2011-01-20 04:03:10 1888256 —-a-w- C:\Windows\System32\WMVDECOD.DLL
2011-01-20 04:03:10 1619456 —-a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2011-01-20 04:03:09 4068864 —-a-w- C:\Windows\System32\mf.dll
2011-01-20 04:03:09 3181568 —-a-w- C:\Windows\SysWow64\mf.dll
2011-01-19 11:46:09 89088 —-a-w- C:\Windows\MBR.exe
2011-01-19 11:46:09 256512 —-a-w- C:\Windows\PEV.exe
2011-01-19 11:46:08 98816 —-a-w- C:\Windows\sed.exe
2011-01-19 11:46:08 161792 —-a-w- C:\Windows\SWREG.exe
2011-01-18 12:12:59 1736608 —-a-w- C:\Windows\System32\ntdll.dll
2011-01-18 12:12:59 1289528 —-a-w- C:\Windows\SysWow64\ntdll.dll
2011-01-18 12:12:54 7680 —-a-w- C:\Program Files\Internet Explorer\iecompat.dll
2011-01-18 12:12:54 7680 —-a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll
2011-01-18 12:12:50 223448 —-a-w- C:\Windows\System32\drivers\fvevol.sys
2011-01-18 12:11:39 27008 —-a-w- C:\Windows\System32\drivers\Diskdump.sys
2011-01-18 12:11:37 243200 —-a-w- C:\Windows\System32\wow64.dll
2011-01-18 12:11:35 25600 —-a-w- C:\Windows\SysWow64\setup16.exe
2011-01-18 12:11:34 5120 —-a-w- C:\Windows\SysWow64\wow32.dll
2011-01-18 12:11:34 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-01-18 12:11:33 7680 —-a-w- C:\Windows\SysWow64\instnm.exe
2011-01-18 12:11:29 2048 —-a-w- C:\Windows\SysWow64\user.exe
2011-01-18 12:11:23 571904 —-a-w- C:\Windows\SysWow64\oleaut32.dll
2011-01-18 12:11:21 861184 —-a-w- C:\Windows\System32\oleaut32.dll
2011-01-18 11:39:06 184832 —-a-w- C:\Windows\System32\drivers\usbvideo.sys
2011-01-18 11:39:00 243712 —-a-w- C:\Windows\System32\drivers\ks.sys
2011-01-17 23:05:45 62032 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2011-01-17 23:05:28 38848 —-a-w- C:\Windows\avastSS.scr
2011-01-17 17:34:46 ——– d—–w- C:\Program Files (x86)\Microsoft Synchronization Services
2011-01-17 17:18:08 ——– d—–w- C:\Windows\SHELLNEW
2011-01-15 07:30:33 ——– d—–w- C:\PROGRA~3\Webroot
2011-01-15 07:29:04 ——– d—–w- C:\Users\Firdaus\AppData\Roaming\Uniblue
2011-01-15 07:28:29 ——– d—–w- C:\Users\Firdaus\AppData\Local\PackageAware
2011-01-15 06:31:44 ——– d—–w- C:\Program Files (x86)\Trend Micro
2011-01-14 16:24:39 ——– d—–w- C:\Windows\PCHEALTH
2011-01-14 16:24:39 ——– d—–w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2011-01-14 16:19:54 ——– d—–w- C:\Program Files (x86)\Microsoft Visual Studio 8
2011-01-14 16:18:30 ——– d—–w- C:\Program Files (x86)\Microsoft Analysis Services
2011-01-12 12:07:27 720896 —-a-w- C:\Windows\System32\odbc32.dll
2011-01-12 12:07:26 573440 —-a-w- C:\Windows\SysWow64\odbc32.dll
2011-01-12 12:07:26 495616 —-a-w- C:\Program Files\Common Files\System\ado\msadox.dll
2011-01-12 12:07:26 466944 —-a-w- C:\Program Files\Common Files\System\ado\msadomd.dll
2011-01-12 12:07:26 258048 —-a-w- C:\Program Files\Common Files\System\msadc\msadco.dll
2011-01-12 12:07:26 1425408 —-a-w- C:\Program Files\Common Files\System\ado\msado15.dll
2011-01-12 12:07:25 987136 —-a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll
2011-01-12 12:07:25 372736 —-a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll
2011-01-12 12:07:25 352256 —-a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll
2011-01-12 12:07:25 208896 —-a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll
2011-01-08 11:12:06 ——– d—–w- C:\Users\Firdaus\AppData\Local\Xenocode
2011-01-08 11:12:06 ——– d—–w- C:\Program Files (x86)\Xenocode
2011-01-08 09:49:47 ——– d—–w- C:\Program Files (x86)\Artisteer 2
2011-01-07 20:15:24 ——– d—–w- C:\Users\Firdaus\AppData\Roaming\Artisteer
2011-01-07 11:34:45 ——– d—–w- C:\Program Files (x86)\MySQL
2011-01-07 10:19:00 ——– d—–w- C:\xampp-win32-1.7.3
2011-01-04 11:26:22 ——– d—–w- C:\PROGRA~3\Ezprint

==================== Find3M ====================

2010-11-20 20:57:57 499712 —-a-w- C:\Windows\SysWow64\msvcp71.dll
2010-11-12 10:53:06 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2010-11-04 06:35:53 1194496 —-a-w- C:\Windows\System32\wininet.dll
2010-11-04 06:31:34 57856 —-a-w- C:\Windows\System32\licmgr10.dll
2010-11-04 05:52:17 978944 —-a-w- C:\Windows\SysWow64\wininet.dll
2010-11-04 05:48:36 44544 —-a-w- C:\Windows\SysWow64\licmgr10.dll
2010-11-04 05:16:14 482816 —-a-w- C:\Windows\System32\html.iec
2010-11-04 04:41:26 386048 —-a-w- C:\Windows\SysWow64\html.iec
2010-11-04 04:35:37 1638912 —-a-w- C:\Windows\System32\mshtml.tlb
2010-11-04 04:08:54 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2010-11-02 05:18:17 524288 —-a-w- C:\Windows\System32\wmicmiplugin.dll
2010-11-02 05:17:38 473600 —-a-w- C:\Windows\System32\taskcomp.dll
2010-11-02 05:17:38 1169408 —-a-w- C:\Windows\System32\taskschd.dll
2010-11-02 05:16:53 1114624 —-a-w- C:\Windows\System32\schedsvc.dll
2010-11-02 05:10:47 464384 —-a-w- C:\Windows\System32\taskeng.exe
2010-11-02 05:10:32 285696 —-a-w- C:\Windows\System32\schtasks.exe
2010-11-02 04:40:36 496128 —-a-w- C:\Windows\SysWow64\taskschd.dll
2010-11-02 04:40:36 305152 —-a-w- C:\Windows\SysWow64\taskcomp.dll
2010-11-02 04:34:44 192000 —-a-w- C:\Windows\SysWow64\taskeng.exe
2010-11-02 04:34:33 179712 —-a-w- C:\Windows\SysWow64\schtasks.exe
2010-10-27 05:06:22 2048 —-a-w- C:\Windows\System32\tzres.dll
2010-10-27 04:32:36 2048 —-a-w- C:\Windows\SysWow64\tzres.dll

============= FINISH: 14:22:37.44 ===============

Attachments:

Hi,

You may need to reinstall your FastAccess as some of it's files may have been corrupted.


Some infections found by ESET are already quarantined or in your recycle bin and no longer poses a threat. Some of them are in your cache or temporary directory which we will be cleaning out later.

But the crack files needs to go as the problem you had may have been due to these crack files and WTT does not support the use of any illegal software as mentioned in our Terms of Use:

Please do the following:

Download TFC to your desktop
  • Close any open windows.
  • Right click the TFC icon then choose "Run as Administrator" to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
–Next–

Please do the following:

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty in properly disabling your protective programs, refer to this link - How to Disable your Security Programs
——————————————————————–

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

File::
D:\Education\CCNA\vce reader.zip
D:\Software\Aktivator Microsoft Office 2010Blog MAok\O2ACK1.3.exe
D:\Software\Aktivator Microsoft Office 2010Blog MAok\Resources\KMSAct\KMSAct.exe
D:\Software\KMS Activator for Microsoft Office 2010 Applications x86 x64 Multilingual-FIXISO~DiBYA\KMS Activator.exe

DDS::
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
BHO: {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - No File
mRun: [FAStartup]

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.


To post in your next reply:
1. Combofix log.
2. Any better?
Hi, I'm sorry for the late reply.I been working lately and don't have enough time to scan through combofix and for your information my computer is working fine. Actually I just wondering, its this CFScript you give will terminated my office professional 2010 activation?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI