This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Horse Hider.mpr

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My AVG and Adaware, are being obstructed from running as they should. AVG starts to scan and runs for three days without finishing untill I terminate it. The only thing it found was Trojan Horse Hider.mpr but it will not heal it and is not able to put it in the vault so that I can delete it. I keep getting Adaware pop ups saying that Adaware was interupted whilst running though I didnt run it, nor had it been scheduled to run. Also Internet sites that have anything to do with online scanners will not open.
My son uses the computer a lot in the evenings to watch regular films which he gets access from various internet sites and I think that it these sites that have caused the problems, as I have had to remove a number of viruses in the past few weeks but maybe not all Though I am unable to do much about the latest Trojan Horse Hider.mpr and am therefor seeking your help.
Once clean I will be removing my sons account, as I have too many important things to use my comp for.
I thank you in anticipation

Plese see DDS.txt and Attach.txt

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 20:47:50.25 on 29/08/2011
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_12
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1023.280 [GMT 1:00]
.
AV: AVG Anti-Virus Free *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
FW: ZoneAlarm Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\iolo\common\lib\ioloServiceManager.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\System32\HPZipm12.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\ViaVoice\Bin\engine.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Owner\Desktop\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.ntlworld.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: IncrediMail MediaBar 2 Toolbar: {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} -
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
uRun: [Google Update] "c:\documents and settings\owner\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [AVG8_TRAY] c:\program files\avg\avg8\avgtray.exe
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
dRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0)
IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\program files\microsoft activesync\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\program files\microsoft activesync\INetRepl.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab
DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - hxxp://www.ipix.com/viewers/ipixx.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab
DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - hxxp://sib1.od2.com/common/Member/ClientInstall/10.00.0036/OCI/setup.exe
DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1151858104609
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38121.3895949074
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game09.zylom.com/activex/zylomgamesplayer.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} - hxxps://signin3.valueactive.com/Register/Branding/olr3313/OCX/flashax.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} - hxxp://www2.incredimail.com/contents/setup/downloader/imloader.cab
DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} - hxxp://chat.msn.com/bin/msnchat45.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} - c:\program files\microsoft activesync\aatp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
WinCE Filter: image/bmp - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\cenetflt.dll
WinCE Filter: image/gif - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\cenetflt.dll
WinCE Filter: image/jpeg - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\cenetflt.dll
WinCE Filter: image/xbm - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\cenetflt.dll
WinCE Filter: text/asp - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\program files\microsoft activesync\cenetflt.dll
WinCE Filter: text/html - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\program files\microsoft activesync\cenetflt.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No File
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\6umuci8i.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2384137&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://sport.virginmedia.com/
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar&a=1&search=
FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\6umuci8i.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\6umuci8i.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar-ff3.dll
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\owner\application data\mozilla\firefox\profiles\6umuci8i.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
FF - plugin: c:\documents and settings\owner\local settings\application data\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPVISLITE.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npviewpoint.dll
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\program files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Ext: Forecastfox: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} - %profile%\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Clipmarks: {e1170235-2845-420c-acc3-42261a29dd46} - %profile%\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
FF - Ext: Adobe DLM (powered by getPlus®): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - %profile%\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - c:\program files\avg\avg8\Firefox
FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - true
.
============= SERVICES / DRIVERS ===============
.
R0 BsStor;InCD Storage Helper Driver;c:\windows\system32\drivers\bsstor.sys [2004-5-14 9088]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-7-26 64512]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2011-7-22 13496]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-10 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-6-10 27784]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-6-10 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2009-2-27 532224]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-3 297752]
R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2008-10-3 700336]
R2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2008-10-3 700336]
R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?]
R3 AEILAB;AEI USB To Fast Ethernet Adapter;c:\windows\system32\drivers\AEILAB.SYS [2006-6-18 24299]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-8-18 15232]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-7-9 908056]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-4-27 136176]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-8-18 2151640]
S2 ousbehci;NEC PCI to USB Enhanced Host Controller;c:\windows\system32\drivers\ousbehci.sys [2006-6-4 45696]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-4-27 136176]
S3 INQ1usbser;INQ1 USB Device for Legacy Serial Communication;c:\windows\system32\drivers\INQ1usbser.sys [2009-12-6 103680]
S3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows\system32\drivers\ousb2hub.sys [2006-6-4 56960]
S3 qcusbmdm6k;WP-S1 Proprietary USB Driver;c:\windows\system32\drivers\qcusbmdm6k.sys [2008-5-15 65024]
S3 qcusbnmea;WP-S1 NMEA Port;c:\windows\system32\drivers\qcusbnmea.sys [2008-5-15 65024]
S3 qcusbpcsync;WP-S1 PCSYNC Port;c:\windows\system32\drivers\qcusbpcsync.sys [2008-5-15 65024]
S3 qcusbser6k;WP-S1 Diagnostic Port;c:\windows\system32\drivers\qcusbser6k.sys [2008-5-15 65024]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\sisoftware\sisoftware sandra lite 2011.sp1\RpcAgentSrv.exe [2011-3-9 93848]
S3 uac4pdt;PDT USB Composite Class Filter Driver;c:\windows\system32\drivers\uac4pdt.sys [2006-6-30 15232]
S4 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-7-25 353168]
S4 BsUDF;InCD UDF Driver;c:\windows\system32\drivers\bsudf.sys [2004-5-14 329728]
.
=============== Created Last 30 ================
.
2011-08-27 23:40:53 ——– d—–w- c:\docume~1\owner\locals~1\applic~1\cucddaca
2011-08-19 21:02:27 ——– d—–w- c:\program files\IncredimailBackup
2011-08-17 21:30:45 ——– d—–w- c:\docume~1\owner\locals~1\applic~1\Thunderbird
2011-08-17 19:34:16 ——– d—–w- c:\program files\Reynardware Incredimail Converter
2011-08-17 19:08:18 77824 —-a-w- c:\windows\system32\ExplorerDir.ocx
2011-08-17 19:08:18 21504 —-a-w- c:\windows\system32\TABCTFR.DLL
2011-08-17 19:08:18 147456 —-a-w- c:\windows\system32\vbzip11.dll
2011-08-17 19:08:18 119568 —-a-w- c:\windows\system32\VB6FR.DLL
2011-08-17 19:08:17 32768 —-a-w- c:\windows\system32\CMDLGFR.DLL
2011-08-17 19:08:17 141312 —-a-w- c:\windows\system32\MSCMCFR.DLL
2011-08-10 23:03:17 ——– d—–w- c:\program files\iPod
2011-08-10 23:03:09 ——– d—–w- c:\program files\iTunes
2011-08-10 22:57:06 ——– d—–w- c:\program files\Bonjour
.
==================== Find3M ====================
.
2011-08-11 08:37:02 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-12 10:20:54 83816 —-a-w- c:\windows\system32\dns-sd.exe
2011-07-12 10:20:54 73064 —-a-w- c:\windows\system32\dnssd.dll
2011-07-12 10:20:54 50536 —-a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 10:20:54 178536 —-a-w- c:\windows\system32\dnssdX.dll
2011-07-05 17:37:00 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 17:37:00 69632 —-a-w- c:\windows\system32\QuickTime.qts
2006-11-24 02:20:55 35646644 —-a-w- c:\program files\nisas05eng_in.exe
2006-11-24 02:20:49 5913195 —-a-w- c:\program files\dia-0.92.2-1-setup.exe
2006-11-24 02:20:49 2745808 —-a-w- c:\program files\erasersetup.exe
2006-11-24 02:20:48 348672 —-a-w- c:\program files\vb40032.dll
2006-11-24 02:20:48 237568 —-a-w- c:\program files\uninstall morpheus toolbar.dll
2006-02-21 16:54:36 4004827 —-a-w- c:\program files\SISetup.ex
2005-09-12 18:28:22 455 —-a-w- c:\program files\layout.bin
2005-03-21 16:45:45 11776 —-a-w- c:\program files\vb4de32.dll
2005-03-21 16:45:45 10240 —-a-w- c:\program files\psapi.dll
2005-03-21 16:45:44 5632 —-a-w- c:\program files\disabled.exe
.
============= FINISH: 20:51:14.85 ===============

[attachment removed: Attach.zip]
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Hello Mowman

Many thanks :) for looking at my logs for me. Here is the Combofix log as requested.

ComboFix 11-09-01.02 - Owner 01/09/2011 17:06:53.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1023.146 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
FW: ZoneAlarm Firewall *Enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\xml10.tmp
c:\documents and settings\All Users\Application Data\xml11.tmp
c:\documents and settings\All Users\Application Data\xml15.tmp
c:\documents and settings\All Users\Application Data\xml16.tmp
c:\documents and settings\All Users\Application Data\xml17.tmp
c:\documents and settings\All Users\Application Data\xml5A.tmp
c:\documents and settings\All Users\Application Data\xml5B.tmp
c:\documents and settings\All Users\Application Data\xml5C.tmp
c:\documents and settings\All Users\Application Data\xml5D.tmp
c:\documents and settings\All Users\Application Data\xmlF.tmp
c:\windows\system32\activeds.dll.bkup
c:\windows\system32\actxprxy.dll.bkup
c:\windows\system32\adsldpc.dll.bkup
c:\windows\system32\advpack.dll.bkup
c:\windows\system32\basesrv.dll.bkup
c:\windows\system32\batmeter.dll.bkup
c:\windows\system32\browselc.dll.bkup
c:\windows\system32\catsrv.dll.bkup
c:\windows\system32\catsrvut.dll.bkup
c:\windows\system32\certcli.dll.bkup
c:\windows\system32\CF31468.exe
c:\windows\system32\cnbjmon.dll.bkup
c:\windows\system32\comsvcs.dll.bkup
c:\windows\system32\credui.dll.bkup
c:\windows\system32\cryptdll.dll.bkup
c:\windows\system32\cryptsvc.dll.bkup
c:\windows\system32\cscui.dll.bkup
c:\windows\system32\dhcpcsvc.dll.bkup
c:\windows\system32\dssenh.dll.bkup
c:\windows\system32\duser.dll.bkup
c:\windows\system32\eraser.dll.bkup
c:\windows\system32\esent.dll.bkup
c:\windows\system32\eventlog.dll.bkup
c:\windows\system32\hpzsnt09.dll.bkup
c:\windows\system32\imagehlp.dll.bkup
c:\windows\system32\incinerator.dll.bkup
c:\windows\system32\inetpp.dll.bkup
c:\windows\system32\ipnathlp.dll.bkup
c:\windows\system32\ipsecsvc.dll.bkup
c:\windows\system32\kerberos.dll.bkup
c:\windows\system32\libeay32_0.9.6l.dll.bkup
c:\windows\system32\localspl.dll.bkup
c:\windows\system32\lsasrv.dll.bkup
c:\windows\system32\mfcsubs.dll.bkup
c:\windows\system32\modemui.dll.bkup
c:\windows\system32\mprapi.dll.bkup
c:\windows\system32\mscms.dll.bkup
c:\windows\system32\msprivs.dll.bkup
c:\windows\system32\mstask.dll.bkup
c:\windows\system32\mstlsapi.dll.bkup
c:\windows\system32\msutb.dll.bkup
c:\windows\system32\msvfw32.dll.bkup
c:\windows\system32\msxml3r.dll.bkup
c:\windows\system32\ncobjapi.dll.bkup
c:\windows\system32\netlogon.dll.bkup
c:\windows\system32\netshell.dll.bkup
c:\windows\system32\ntdsapi.dll.bkup
c:\windows\system32\nv4_disp.dll.bkup
c:\windows\system32\nvshell.dll.bkup
c:\windows\system32\nvwddi.dll.bkup
c:\windows\system32\oakley.dll.bkup
c:\windows\system32\olecli32.dll.bkup
c:\windows\system32\olepro32.dll.bkup
c:\windows\system32\olesvr32.dll.bkup
c:\windows\system32\olethk32.dll.bkup
c:\windows\system32\powrprof.dll.bkup
c:\windows\system32\profmap.dll.bkup
c:\windows\system32\psbase.dll.bkup
c:\windows\system32\qmgr.dll.bkup
c:\windows\system32\rapi.dll.bkup
c:\windows\system32\raschap.dll.bkup
c:\windows\system32\rasdlg.dll.bkup
c:\windows\system32\rasmans.dll.bkup
c:\windows\system32\rasppp.dll.bkup
c:\windows\system32\rastls.dll.bkup
c:\windows\system32\regapi.dll.bkup
c:\windows\system32\resutils.dll.bkup
c:\windows\system32\samsrv.dll.bkup
c:\windows\system32\scecli.dll.bkup
c:\windows\system32\scesrv.dll.bkup
c:\windows\system32\schedsvc.dll.bkup
c:\windows\system32\shsvcs.dll.bkup
c:\windows\system32\spoolss.dll.bkup
c:\windows\system32\srsvc.dll.bkup
c:\windows\system32\srvsvc.dll.bkup
c:\windows\system32\ssdpapi.dll.bkup
c:\windows\system32\sti.dll.bkup
c:\windows\system32\tapisrv.dll.bkup
c:\windows\system32\tcpmon.dll.bkup
c:\windows\system32\tds3shl.dll.bkup
c:\windows\system32\termsrv.dll.bkup
c:\windows\system32\themeui.dll.bkup
c:\windows\system32\trkwks.dll.bkup
c:\windows\system32\unimdmat.dll.bkup
c:\windows\system32\upnp.dll.bkup
c:\windows\system32\uxtheme.dll.bkup
c:\windows\system32\w32time.dll.bkup
c:\windows\system32\webclnt.dll.bkup
c:\windows\system32\wiaservc.dll.bkup
c:\windows\system32\win32spl.dll.bkup
c:\windows\system32\winhttp.dll.bkup
c:\windows\system32\winipsec.dll.bkup
c:\windows\system32\winscard.dll.bkup
c:\windows\system32\wintrust.dll.bkup
c:\windows\system32\wow32.dll.bkup
c:\windows\system32\wzcsvc.dll.bkup
c:\windows\system32\xpsp2res.dll.bkup
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_uac4pdt
——-\Service_uac4pdt
.
.
((((((((((((((((((((((((( Files Created from 2011-08-01 to 2011-09-01 )))))))))))))))))))))))))))))))
.
.
2011-08-27 23:40 . 2011-08-30 15:25 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\cucddaca
2011-08-19 21:02 . 2011-08-19 21:02 ——– d—–w- c:\program files\IncredimailBackup
2011-08-17 21:30 . 2011-09-01 14:14 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Thunderbird
2011-08-17 21:30 . 2011-08-17 21:30 ——– d—–w- c:\documents and settings\Owner\Application Data\Thunderbird
2011-08-17 21:30 . 2011-09-01 14:14 ——– d—–w- c:\program files\Mozilla Thunderbird
2011-08-17 19:34 . 2011-08-17 20:00 ——– d—–w- c:\program files\Reynardware Incredimail Converter
2011-08-17 19:08 . 2005-04-18 16:39 77824 —-a-w- c:\windows\system32\ExplorerDir.ocx
2011-08-17 19:08 . 2003-01-26 15:48 147456 —-a-w- c:\windows\system32\vbzip11.dll
2011-08-17 19:08 . 2000-10-01 20:00 119568 —-a-w- c:\windows\system32\VB6FR.DLL
2011-08-17 19:08 . 1998-07-13 00:00 21504 —-a-w- c:\windows\system32\TABCTFR.DLL
2011-08-17 19:08 . 1998-07-13 00:00 141312 —-a-w- c:\windows\system32\MSCMCFR.DLL
2011-08-17 19:08 . 1998-07-12 20:00 32768 —-a-w- c:\windows\system32\CMDLGFR.DLL
2011-08-10 23:03 . 2011-08-10 23:03 ——– d—–w- c:\program files\iPod
2011-08-10 23:03 . 2011-08-10 23:04 ——– d—–w- c:\program files\iTunes
2011-08-10 22:57 . 2011-08-10 22:57 ——– d—–w- c:\program files\Bonjour
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-18 14:25 . 2010-07-26 16:05 64512 —-a-w- c:\windows\system32\drivers\Lbd.sys
2011-08-11 08:37 . 2011-05-23 18:46 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-12 10:20 . 2011-07-12 10:20 83816 —-a-w- c:\windows\system32\dns-sd.exe
2011-07-12 10:20 . 2011-07-12 10:20 73064 —-a-w- c:\windows\system32\dnssd.dll
2011-07-12 10:20 . 2011-07-12 10:20 50536 —-a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 10:20 . 2011-07-12 10:20 178536 —-a-w- c:\windows\system32\dnssdX.dll
2011-07-06 18:52 . 2008-12-21 01:34 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-07-06 18:52 . 2008-12-21 01:34 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-05 17:37 . 2011-07-05 17:37 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 17:37 . 2011-07-05 17:37 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-07-02 16:45 . 2010-07-26 16:04 101720 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2006-11-24 02:20 . 2005-10-03 13:26 35646644 —-a-w- c:\program files\nisas05eng_in.exe
2006-11-24 02:20 . 2006-06-29 22:30 5913195 —-a-w- c:\program files\dia-0.92.2-1-setup.exe
2006-11-24 02:20 . 2003-01-19 16:09 2745808 —-a-w- c:\program files\erasersetup.exe
2006-11-24 02:20 . 2006-11-05 23:00 237568 —-a-w- c:\program files\uninstall morpheus toolbar.dll
2006-11-24 02:20 . 1996-01-12 00:00 348672 —-a-w- c:\program files\vb40032.dll
2006-02-21 16:54 . 2009-01-13 16:49 4004827 —-a-w- c:\program files\SISetup.ex
2005-09-12 18:28 . 2009-01-13 16:49 455 —-a-w- c:\program files\layout.bin
2005-03-21 16:45 . 1999-12-10 12:00 10240 —-a-w- c:\program files\psapi.dll
2005-03-21 16:45 . 1996-01-12 00:00 11776 —-a-w- c:\program files\vb4de32.dll
2005-03-21 16:45 . 2003-06-13 12:21 5632 —-a-w- c:\program files\disabled.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\program files\AVG\AVG8\avgtray.exe" [2010-07-09 2048352]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2010-11-17 329096]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-21 08:09 11952 —-a-w- c:\windows\system32\avgrsstx.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GraphicsPlus.lnk]
backup=c:\windows\pss\GraphicsPlus.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus Organizer EasyClip.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus QuickStart.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus SmartCenter.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus SuiteStart.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Ashampoo Mail Virus Blocker Server.lnk]
backup=c:\windows\pss\Ashampoo Mail Virus Blocker Server.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Lotus SmartSuite Release 9 Registration.lnk]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2005-01-12 14:54 241664 —-a-w- c:\program files\HP\hpcoretech\hpcmpmgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 04:42 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-05 17:36 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Owner\\My Documents\\My Downloads\\incredimail_install.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\incmail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\VoipCheap\\voipcheap.exe"=
"c:\\Program Files\\PPMate\\ppmate.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncrediMail_Install.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2011.SP1\\RpcAgentSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2011.SP1\\WNt500x86\\RpcSandraSrv.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\IncrediMail\\Data\\Runtime\\IncrediMail_Install.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 BsStor;InCD Storage Helper Driver;c:\windows\system32\drivers\bsstor.sys [14/05/2004 03:49 9088]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [26/07/2010 17:05 64512]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [22/07/2011 16:47 13496]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/06/2008 00:08 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/06/2008 00:08 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 19:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 19:41 67656]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [09/07/2009 08:35 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [03/07/2008 23:56 297752]
R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [03/10/2008 23:39 700336]
R2 ioloSystemService;iolo System Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [03/10/2008 23:39 700336]
R3 AEILAB;AEI USB To Fast Ethernet Adapter;c:\windows\system32\drivers\AEILAB.SYS [18/06/2006 12:55 24299]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27/04/2010 21:52 136176]
S2 ousbehci;NEC PCI to USB Enhanced Host Controller;c:\windows\system32\drivers\ousbehci.sys [04/06/2006 17:23 45696]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [27/04/2010 21:52 136176]
S3 INQ1usbser;INQ1 USB Device for Legacy Serial Communication;c:\windows\system32\drivers\INQ1usbser.sys [06/12/2009 14:50 103680]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18/08/2011 15:25 2151640]
S3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows\system32\drivers\ousb2hub.sys [04/06/2006 17:23 56960]
S3 qcusbmdm6k;WP-S1 Proprietary USB Driver;c:\windows\system32\drivers\qcusbmdm6k.sys [15/05/2008 17:31 65024]
S3 qcusbnmea;WP-S1 NMEA Port;c:\windows\system32\drivers\qcusbnmea.sys [15/05/2008 17:31 65024]
S3 qcusbpcsync;WP-S1 PCSYNC Port;c:\windows\system32\drivers\qcusbpcsync.sys [15/05/2008 17:31 65024]
S3 qcusbser6k;WP-S1 Diagnostic Port;c:\windows\system32\drivers\qcusbser6k.sys [15/05/2008 17:31 65024]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2011.SP1\RpcAgentSrv.exe [09/03/2011 23:37 93848]
S4 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [25/07/2011 21:02 353168]
S4 BsUDF;InCD UDF Driver;c:\windows\system32\drivers\bsudf.sys [14/05/2004 03:49 329728]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WUAUSERV
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-08-18 14:25]
.
2011-08-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2011-09-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-09-30 15:52]
.
2011-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-27 20:51]
.
2011-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-27 20:51]
.
2011-08-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1292428093-484061587-839522115-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-01 17:02]
.
2011-09-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1292428093-484061587-839522115-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-01 17:02]
.
2011-09-01 c:\windows\Tasks\SpeedyPC Program Check.job
- c:\program files\SpeedyPC\SpeedyPC.exe [2010-05-19 23:10]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.ntlworld.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &ieSpell; Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling; - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
TCP: DhcpNameServer = [removed] [removed]
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game09.zylom.com/activex/zylomgamesplayer.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\6umuci8i.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2384137&SearchSource;=3&q;={searchTerms}
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://sport.virginmedia.com/
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar&a;=1&search;=
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\program files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Ext: Forecastfox: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} - %profile%\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Clipmarks: {e1170235-2845-420c-acc3-42261a29dd46} - %profile%\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
FF - Ext: Adobe DLM (powered by getPlus®): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - %profile%\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - c:\program files\AVG\AVG8\Firefox
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
AddRemove-HijackThis - c:\documents and settings\Owner\Desktop\Utilities\HJT\HijackThis.exe
AddRemove-Morpheus - c:\program files\Morpheus\UninstMorpheus.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-01 17:39
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1292428093-484061587-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(732)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(3124)
c:\windows\system32\WININET.dll
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\SCardSvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\System32\HPZipm12.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-09-01 17:55:31 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-01 16:55
ComboFix2.txt 2008-12-31 11:22
.
Pre-Run: 25,860,964,352 bytes free
Post-Run: 25,799,729,152 bytes free
.
- - End Of File - - 49FADC6A4EF2FE3539EE9E8B38B47B20
Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please










Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Hello mowman

Please find the logs as requested.

Malwarebytes' Anti-Malware

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Database version: 7635

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11

02/09/2011 10:20:23
mbam-log-2011-09-02 (10-20-23).txt

Scan type: Quick scan
Objects scanned: 249186
Time elapsed: 34 minute(s), 14 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


ESET log

# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=439422360089294c9f99b5aaced0fe2a
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-09-02 12:46:41
# local_time=2011-09-02 01:46:41 (+0000, GMT Daylight Time)
# country="United Kingdom"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 85309574 85309574 0 0
# compatibility_mode=1024 16777175 100 0 101903226 101903226 0 0
# compatibility_mode=6912 16777215 100 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 492 492 0 0
# compatibility_mode=9217 16777214 100 74 61733 99361811 0 0
# scanned=129966
# found=3
# cleaned=3
# scan_time=11485
C:\Documents and Settings\Owner\My Documents\My Downloads\burn4free_setup.exe multiple threats (deleted - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\Owner\My Documents\My Downloads\setup_SpinPalace.exe a variant of Win32/PrimeCasino application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Program Files\uninstall morpheus toolbar.dll Win32/Toolbar.Morpheus application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

AV: AVG Anti-Virus Free *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}

You have 2 antivirus installed,you should only have one as they conflict,you should remove one of them.

Please re run DDS and post the log,also tell me how the computer is running now.
Hello there again mowman Have had AVG anti virus for many years on its own, but I didnt know that the update of Ad-Aware gave me another anti-virus. So, all things considered I have uninstalled Ad-Aware When I ran ESET my AVG picked up Trojan horse Agent 3.AGCY and between the two of them it got nucked. Things certainly seem to be running smoother, but not 100% sure that all problems are gone. Here are the DDS logs you requested. DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 21:52:48.25 on 02/09/2011 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_12 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1023.221 [GMT 1:00] . AV: AVG Anti-Virus Free *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: ZoneAlarm Firewall *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\iolo\common\lib\ioloServiceManager.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\HPZipm12.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe svchost.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\IncrediMail\bin\IncMail.exe C:\Program Files\IncrediMail\Bin\ImApp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Documents and Settings\Owner\Desktop\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.ntlworld.com uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mStart Page = about:blank uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File mRun: [AVG8_TRAY] c:\program files\avg\avg8\avgtray.exe mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe" mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot dRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0) IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\program files\microsoft activesync\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\program files\microsoft activesync\INetRepl.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - hxxp://www.ipix.com/viewers/ipixx.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - hxxp://sib1.od2.com/common/Member/ClientInstall/10.00.0036/OCI/setup.exe DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1151858104609 DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38121.3895949074 DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game09.zylom.com/activex/zylomgamesplayer.cab DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} - hxxps://signin3.valueactive.com/Register/Branding/olr3313/OCX/flashax.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} - hxxp://www2.incredimail.com/contents/setup/downloader/imloader.cab DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} - hxxp://chat.msn.com/bin/msnchat45.cab Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} - c:\program files\microsoft activesync\aatp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL WinCE Filter: image/bmp - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\cenetflt.dll WinCE Filter: image/gif - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\cenetflt.dll WinCE Filter: image/jpeg - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\cenetflt.dll WinCE Filter: image/xbm - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\cenetflt.dll WinCE Filter: text/asp - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\program files\microsoft activesync\cenetflt.dll WinCE Filter: text/html - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\program files\microsoft activesync\cenetflt.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL Notify: avgrsstarter - avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\6umuci8i.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2384137&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - MyStart Search FF - prefs.js: browser.startup.homepage - hxxp://sport.virginmedia.com/ FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar&a=1&search= FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\6umuci8i.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\6umuci8i.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar-ff3.dll FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - plugin: c:\documents and settings\owner\application data\mozilla\firefox\profiles\6umuci8i.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll FF - plugin: c:\documents and settings\owner\local settings\application data\google\update\1.3.21.65\npGoogleUpdate3.dll FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPVISLITE.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npviewpoint.dll FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\program files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} FF - Ext: Forecastfox: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} - %profile%\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} FF - Ext: Clipmarks: {e1170235-2845-420c-acc3-42261a29dd46} - %profile%\extensions\{e1170235-2845-420c-acc3-42261a29dd46} FF - Ext: Adobe DLM (powered by getPlus®): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - %profile%\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - c:\program files\avg\avg8\Firefox FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension . —- FIREFOX POLICIES —- FF - user.js: browser.cache.memory.capacity - 16000 FF - user.js: browser.chrome.favicons - false FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.turbo.enabled - true FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.urlbar.autofill - true FF - user.js: content.max.tokenizing.time - 3000000 FF - user.js: content.maxtextrun - 4095 FF - user.js: content.notify.backoffcount - 5 FF - user.js: content.notify.interval - 1000000 FF - user.js: content.notify.ontimer - true FF - user.js: content.switch.threshold - 1000000 FF - user.js: dom.disable_window_status_change - true FF - user.js: network.http.max-connections - 48 FF - user.js: network.http.max-connections-per-server - 16 FF - user.js: network.http.max-persistent-connections-per-proxy - 16 FF - user.js: network.http.max-persistent-connections-per-server - 8 FF - user.js: network.http.pipelining - true FF - user.js: network.http.pipelining.firstrequest - true FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.proxy.pipelining - true FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: nglayout.initialpaint.delay - 1000 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 FF - user.js: yahoo.homepage.dontask - true . ============= SERVICES / DRIVERS =============== . R0 BsStor;InCD Storage Helper Driver;c:\windows\system32\drivers\bsstor.sys [2004-5-14 9088] R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2011-7-22 13496] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-10 335240] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-6-10 27784] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-6-10 108552] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656] R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2009-2-27 532224] R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-7-9 908056] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-3 297752] R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2008-10-3 700336] R2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2008-10-3 700336] R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?] R3 AEILAB;AEI USB To Fast Ethernet Adapter;c:\windows\system32\drivers\AEILAB.SYS [2006-6-18 24299] S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-4-27 136176] S2 ousbehci;NEC PCI to USB Enhanced Host Controller;c:\windows\system32\drivers\ousbehci.sys [2006-6-4 45696] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-4-27 136176] S3 INQ1usbser;INQ1 USB Device for Legacy Serial Communication;c:\windows\system32\drivers\INQ1usbser.sys [2009-12-6 103680] S3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows\system32\drivers\ousb2hub.sys [2006-6-4 56960] S3 qcusbmdm6k;WP-S1 Proprietary USB Driver;c:\windows\system32\drivers\qcusbmdm6k.sys [2008-5-15 65024] S3 qcusbnmea;WP-S1 NMEA Port;c:\windows\system32\drivers\qcusbnmea.sys [2008-5-15 65024] S3 qcusbpcsync;WP-S1 PCSYNC Port;c:\windows\system32\drivers\qcusbpcsync.sys [2008-5-15 65024] S3 qcusbser6k;WP-S1 Diagnostic Port;c:\windows\system32\drivers\qcusbser6k.sys [2008-5-15 65024] S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\sisoftware\sisoftware sandra lite 2011.sp1\RpcAgentSrv.exe [2011-3-9 93848] S4 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-7-25 353168] S4 BsUDF;InCD UDF Driver;c:\windows\system32\drivers\bsudf.sys [2004-5-14 329728] . =============== Created Last 30 ================ . 2011-09-02 09:27:11 ——– d—–w- c:\program files\ESET 2011-09-01 16:02:41 98816 —-a-w- c:\windows\sed.exe 2011-09-01 16:02:41 518144 —-a-w- c:\windows\SWREG.exe 2011-09-01 16:02:41 256000 —-a-w- c:\windows\PEV.exe 2011-09-01 16:02:41 208896 —-a-w- c:\windows\MBR.exe 2011-08-27 23:40:53 ——– d—–w- c:\docume~1\owner\locals~1\applic~1\cucddaca 2011-08-19 21:02:27 ——– d—–w- c:\program files\IncredimailBackup 2011-08-17 21:30:45 ——– d—–w- c:\docume~1\owner\locals~1\applic~1\Thunderbird 2011-08-17 19:34:16 ——– d—–w- c:\program files\Reynardware Incredimail Converter 2011-08-17 19:08:18 77824 —-a-w- c:\windows\system32\ExplorerDir.ocx 2011-08-17 19:08:18 21504 —-a-w- c:\windows\system32\TABCTFR.DLL 2011-08-17 19:08:18 147456 —-a-w- c:\windows\system32\vbzip11.dll 2011-08-17 19:08:18 119568 —-a-w- c:\windows\system32\VB6FR.DLL 2011-08-17 19:08:17 32768 —-a-w- c:\windows\system32\CMDLGFR.DLL 2011-08-17 19:08:17 141312 —-a-w- c:\windows\system32\MSCMCFR.DLL 2011-08-10 23:03:17 ——– d—–w- c:\program files\iPod 2011-08-10 23:03:09 ——– d—–w- c:\program files\iTunes 2011-08-10 22:57:06 ——– d—–w- c:\program files\Bonjour . ==================== Find3M ==================== . 2011-08-11 08:37:02 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-07-12 10:20:54 83816 —-a-w- c:\windows\system32\dns-sd.exe 2011-07-12 10:20:54 73064 —-a-w- c:\windows\system32\dnssd.dll 2011-07-12 10:20:54 50536 —-a-w- c:\windows\system32\jdns_sd.dll 2011-07-12 10:20:54 178536 —-a-w- c:\windows\system32\dnssdX.dll 2011-07-05 17:37:00 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2011-07-05 17:37:00 69632 —-a-w- c:\windows\system32\QuickTime.qts 2006-11-24 02:20:55 35646644 —-a-w- c:\program files\nisas05eng_in.exe 2006-11-24 02:20:49 5913195 —-a-w- c:\program files\dia-0.92.2-1-setup.exe 2006-11-24 02:20:49 2745808 —-a-w- c:\program files\erasersetup.exe 2006-11-24 02:20:48 348672 —-a-w- c:\program files\vb40032.dll 2006-02-21 16:54:36 4004827 —-a-w- c:\program files\SISetup.ex 2005-09-12 18:28:22 455 —-a-w- c:\program files\layout.bin 2005-03-21 16:45:45 11776 —-a-w- c:\program files\vb4de32.dll 2005-03-21 16:45:45 10240 —-a-w- c:\program files\psapi.dll 2005-03-21 16:45:44 5632 —-a-w- c:\program files\disabled.exe . ============= FINISH: 21:55:24.14 =============== [attachment removed: Attach2.zip]

Things certainly seem to be running smoother, but not 100% sure that all problems are gone.

Can you be specific as what problems remain as I can see no more evidence of malware in your logs.

Things certainly seem to be running smoother, but not 100% sure that all problems are gone.


Hello mowman

This was just me saying, yes all seemed so much better, :thumbup: but I was'nt sure, or did not know if technically my system was clean.

I still have DDS, ComboFix and their log files on my desktop. Can I now delete all these. Also are there any othere files that you have seen that you feel should be deleted, or any other suggestions you would like to make.

Thank you
You appear clean of infections,please do the following.

Delete DDS,ESET and any logs you have



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean out your temp files.
Download Attribune's ATF Cleaner and save to your desktop.
Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program
.













[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 7 and save it to your desktop.
  • Scroll down to where it says JDK 7 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 7 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-7-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.











Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing
Hello mowman

Thank you for re-opening my thread.

AVG is till finding viruses as listed below

Resident Shield detection
Infection;"Object";"Result";"Detection time";"Object Type";"Process"
Trojan horse Agent3.AGCY;"C:\System Volume Information\_restore{96190446-8936-4027-8FC4-59B8E38CE747}\RP817\A0244834.exe";"Moved to Virus Vault";"06/09/2011, 10:39:31";"file";"C:\WINDOWS\system32\svchost.exe"


Also the BlueSOD came up with AIE Lab.Sys (dumping physical memory to disk) But I turned the computer off before the memory dump was completed.

Also during the runninig of Combo fix I had a 3 warnings from Zone Alarm
1. NIR CMD IP127.0.0.1:port135 (this I allowed)
2. PEV 3XE IP [removed].DNS (this I allowed)
3. PEV 3XE IP [removed].DNS (this time I dissallowed)

Below is the new log for Combo fix


ComboFix 11-09-06.03 - Owner 06/09/2011 14:07:38.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1023.343 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\NetworkService\Local Settings\Application Data\ApplicationHistory
c:\documents and settings\NetworkService\Local Settings\Application Data\ApplicationHistory\mswmccds.exe.5bdff540.ini
c:\documents and settings\NetworkService\Local Settings\Application Data\ApplicationHistory\mswmccds.exe.5bdff540.ini.inuse
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\csc.exe.3e4ac0af.ini
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\hpqgalry.exe.cf8dd223.ini
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\hpqimvac.exe.290054de.ini
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\HpqPhUnl.exe.e1eda619.ini
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\hpqpos.exe.2a8da59e.ini
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\hpqqpa.exe.5046474c.ini
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\hpqselsk.exe.a048b05c.ini
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\hpqthb08.exe.a935d1e0.ini
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\MsiExec.exe.8cb23528.ini.inuse
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\mswmc.exe.ed1fcd7a.ini
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\ngen.exe.2c05686e.ini
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\SL2.tmp.a6fca343.ini
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\SL3.tmp.eae90244.ini
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\SLE9.tmp.5c00fa15.ini
.
.
((((((((((((((((((((((((( Files Created from 2011-08-06 to 2011-09-06 )))))))))))))))))))))))))))))))
.
.
2011-09-02 08:16 . 2011-06-24 14:10 139656 -c—-w- c:\windows\system32\dllcache\rdpwd.sys
2011-09-02 08:16 . 2011-04-21 13:37 105472 -c—-w- c:\windows\system32\dllcache\mup.sys
2011-09-02 08:14 . 2011-07-08 14:02 10496 -c—-w- c:\windows\system32\dllcache\ndistapi.sys
2011-08-27 23:40 . 2011-09-02 10:25 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\cucddaca
2011-08-19 21:02 . 2011-08-19 21:02 ——– d—–w- c:\program files\IncredimailBackup
2011-08-17 21:30 . 2011-09-01 14:14 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Thunderbird
2011-08-17 21:30 . 2011-08-17 21:30 ——– d—–w- c:\documents and settings\Owner\Application Data\Thunderbird
2011-08-17 21:30 . 2011-09-05 22:04 ——– d—–w- c:\program files\Mozilla Thunderbird
2011-08-17 19:34 . 2011-08-17 20:00 ——– d—–w- c:\program files\Reynardware Incredimail Converter
2011-08-17 19:08 . 2005-04-18 16:39 77824 —-a-w- c:\windows\system32\ExplorerDir.ocx
2011-08-17 19:08 . 2003-01-26 15:48 147456 —-a-w- c:\windows\system32\vbzip11.dll
2011-08-17 19:08 . 2000-10-01 20:00 119568 —-a-w- c:\windows\system32\VB6FR.DLL
2011-08-17 19:08 . 1998-07-13 00:00 21504 —-a-w- c:\windows\system32\TABCTFR.DLL
2011-08-17 19:08 . 1998-07-13 00:00 141312 —-a-w- c:\windows\system32\MSCMCFR.DLL
2011-08-17 19:08 . 1998-07-12 20:00 32768 —-a-w- c:\windows\system32\CMDLGFR.DLL
2011-08-10 23:03 . 2011-08-10 23:03 ——– d—–w- c:\program files\iPod
2011-08-10 23:03 . 2011-08-10 23:04 ——– d—–w- c:\program files\iTunes
2011-08-10 22:57 . 2011-08-10 22:57 ——– d—–w- c:\program files\Bonjour
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-11 08:37 . 2011-05-23 18:46 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-15 13:29 . 2001-08-18 12:00 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-12 10:20 . 2011-07-12 10:20 83816 —-a-w- c:\windows\system32\dns-sd.exe
2011-07-12 10:20 . 2011-07-12 10:20 73064 —-a-w- c:\windows\system32\dnssd.dll
2011-07-12 10:20 . 2011-07-12 10:20 50536 —-a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 10:20 . 2011-07-12 10:20 178536 —-a-w- c:\windows\system32\dnssdX.dll
2011-07-08 14:02 . 2001-08-18 12:00 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys
2011-07-06 18:52 . 2008-12-21 01:34 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-07-06 18:52 . 2008-12-21 01:34 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-05 17:37 . 2011-07-05 17:37 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 17:37 . 2011-07-05 17:37 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-07-02 16:45 . 2010-07-26 16:04 101720 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-06-24 14:10 . 2004-05-14 00:36 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-21 18:45 . 2004-01-21 15:16 832512 —-a-w- c:\windows\system32\wininet.dll
2011-06-21 18:45 . 2004-08-04 07:56 78336 —-a-w- c:\windows\system32\ieencode.dll
2011-06-21 18:45 . 2004-05-14 16:36 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2011-06-21 18:45 . 2001-08-18 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2011-06-21 11:47 . 2004-08-04 05:59 389120 —-a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2001-08-18 12:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2006-11-24 02:20 . 2005-10-03 13:26 35646644 —-a-w- c:\program files\nisas05eng_in.exe
2006-11-24 02:20 . 2006-06-29 22:30 5913195 —-a-w- c:\program files\dia-0.92.2-1-setup.exe
2006-11-24 02:20 . 2003-01-19 16:09 2745808 —-a-w- c:\program files\erasersetup.exe
2006-11-24 02:20 . 1996-01-12 00:00 348672 —-a-w- c:\program files\vb40032.dll
2006-02-21 16:54 . 2009-01-13 16:49 4004827 —-a-w- c:\program files\SISetup.ex
2005-09-12 18:28 . 2009-01-13 16:49 455 —-a-w- c:\program files\layout.bin
2005-03-21 16:45 . 1999-12-10 12:00 10240 —-a-w- c:\program files\psapi.dll
2005-03-21 16:45 . 1996-01-12 00:00 11776 —-a-w- c:\program files\vb4de32.dll
2005-03-21 16:45 . 2003-06-13 12:21 5632 —-a-w- c:\program files\disabled.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-09-01_16.40.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-13 19:17 . 2011-05-13 19:17 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_452bf920\vcomp.dll
+ 2011-05-13 18:45 . 2011-05-13 18:45 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80KOR.dll
+ 2011-05-13 18:45 . 2011-05-13 18:45 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80JPN.dll
+ 2011-05-13 18:45 . 2011-05-13 18:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ITA.dll
+ 2011-05-13 18:45 . 2011-05-13 18:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80FRA.dll
+ 2011-05-13 18:45 . 2011-05-13 18:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ESP.dll
+ 2011-05-13 18:45 . 2011-05-13 18:45 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ENU.dll
+ 2011-05-13 18:45 . 2011-05-13 18:45 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80DEU.dll
+ 2011-05-13 18:45 . 2011-05-13 18:45 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80CHT.dll
+ 2011-05-13 18:45 . 2011-05-13 18:45 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80CHS.dll
+ 2011-05-14 00:06 . 2011-05-14 00:06 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80u.dll
+ 2011-05-14 00:23 . 2011-05-14 00:23 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80.dll
+ 2011-05-13 17:37 . 2011-05-13 17:37 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_a4c618fa\ATL80.dll
+ 2011-09-06 11:45 . 2011-09-06 11:45 16384 c:\windows\TEMP\Perflib_Perfdata_1f0.dat
+ 2007-01-29 08:58 . 2011-07-08 13:49 46080 c:\windows\system32\tzchange.exe
- 2007-01-29 08:58 . 2010-11-03 13:12 46080 c:\windows\system32\tzchange.exe
+ 2010-12-10 17:29 . 2010-12-10 17:29 64864 c:\windows\system32\sqlctr90.dll
- 2004-05-14 16:49 . 2011-02-17 19:00 44544 c:\windows\system32\pngfilt.dll
+ 2004-05-14 16:49 . 2011-06-21 18:45 44544 c:\windows\system32\pngfilt.dll
+ 2001-08-18 12:00 . 2011-09-03 18:02 86182 c:\windows\system32\perfc009.dat
- 2001-08-18 12:00 . 2011-07-09 22:57 86182 c:\windows\system32\perfc009.dat
+ 2006-11-07 21:03 . 2011-06-21 18:45 52224 c:\windows\system32\msfeedsbs.dll
- 2006-11-07 21:03 . 2011-02-17 19:00 52224 c:\windows\system32\msfeedsbs.dll
+ 2001-08-18 12:00 . 2011-06-21 18:45 27648 c:\windows\system32\jsproxy.dll
- 2001-08-18 12:00 . 2011-02-17 19:00 27648 c:\windows\system32\jsproxy.dll
+ 2006-11-07 03:26 . 2011-06-21 11:46 13824 c:\windows\system32\ieudinit.exe
- 2006-11-07 03:26 . 2011-02-17 11:43 13824 c:\windows\system32\ieudinit.exe
+ 2001-08-18 12:00 . 2011-06-21 18:45 44544 c:\windows\system32\iernonce.dll
- 2001-08-18 12:00 . 2011-02-17 19:00 44544 c:\windows\system32\iernonce.dll
+ 2004-05-14 16:35 . 2011-06-21 11:46 70656 c:\windows\system32\ie4uinit.exe
- 2004-05-14 16:35 . 2011-02-17 11:43 70656 c:\windows\system32\ie4uinit.exe
+ 2006-10-17 11:58 . 2011-06-21 18:45 63488 c:\windows\system32\icardie.dll
- 2006-10-17 11:58 . 2011-02-17 19:00 63488 c:\windows\system32\icardie.dll
+ 2004-05-14 16:49 . 2011-06-21 18:45 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2004-05-14 16:49 . 2011-02-17 19:00 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2007-05-08 21:49 . 2011-02-17 19:00 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2007-05-08 21:49 . 2011-06-21 18:45 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2001-08-18 12:00 . 2011-06-21 18:45 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2001-08-18 12:00 . 2011-02-17 19:00 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2007-05-08 21:49 . 2011-02-17 11:43 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2007-05-08 21:49 . 2011-06-21 11:46 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2001-08-18 12:00 . 2011-06-21 18:45 44544 c:\windows\system32\dllcache\iernonce.dll
- 2001-08-18 12:00 . 2011-02-17 19:00 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2009-02-20 18:09 . 2011-06-21 18:45 78336 c:\windows\system32\dllcache\ieencode.dll
- 2009-02-20 18:09 . 2011-02-17 19:00 78336 c:\windows\system32\dllcache\ieencode.dll
- 2004-05-14 16:35 . 2011-02-17 11:43 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2004-05-14 16:35 . 2011-06-21 11:46 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-08-20 10:04 . 2011-06-21 18:45 63488 c:\windows\system32\dllcache\icardie.dll
- 2007-08-20 10:04 . 2011-02-17 19:00 63488 c:\windows\system32\dllcache\icardie.dll
- 2009-12-14 07:08 . 2010-12-09 14:30 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2009-12-14 07:08 . 2011-04-26 11:07 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2009-06-29 16:12 . 2011-06-21 18:45 17408 c:\windows\system32\dllcache\corpol.dll
- 2009-06-29 16:12 . 2011-02-17 19:00 17408 c:\windows\system32\dllcache\corpol.dll
+ 2001-08-18 12:00 . 2011-04-26 11:07 33280 c:\windows\system32\csrsrv.dll
- 2001-08-18 12:00 . 2010-12-09 14:30 33280 c:\windows\system32\csrsrv.dll
+ 2009-05-26 19:09 . 2011-09-04 20:30 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-05-26 19:09 . 2011-08-22 19:52 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-05-14 00:42 . 2011-08-22 19:52 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2004-05-14 00:42 . 2011-09-04 20:30 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2004-05-14 00:42 . 2011-08-22 19:52 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2011-09-04 20:30 . 2011-09-04 20:30 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2011-07-09 23:05 . 2011-09-02 22:03 65536 c:\windows\Installer\{5007E629-8769-44BB-BD51-A20B6DCC5CC9}\NewShortcut2.0CB67C87_CD34_43E3_92C0_6091F902D467.exe
- 2011-07-09 23:05 . 2011-07-09 23:05 65536 c:\windows\Installer\{5007E629-8769-44BB-BD51-A20B6DCC5CC9}\NewShortcut2.0CB67C87_CD34_43E3_92C0_6091F902D467.exe
- 2011-07-09 23:05 . 2011-07-09 23:05 25214 c:\windows\Installer\{5007E629-8769-44BB-BD51-A20B6DCC5CC9}\ARPPRODUCTICON.exe
+ 2011-07-09 23:05 . 2011-09-02 22:03 25214 c:\windows\Installer\{5007E629-8769-44BB-BD51-A20B6DCC5CC9}\ARPPRODUCTICON.exe
+ 2011-09-02 22:12 . 2011-02-17 19:00 44544 c:\windows\ie7updates\KB2559049-IE7\pngfilt.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 52224 c:\windows\ie7updates\KB2559049-IE7\msfeedsbs.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 27648 c:\windows\ie7updates\KB2559049-IE7\jsproxy.dll
+ 2011-09-02 22:12 . 2011-02-17 11:43 13824 c:\windows\ie7updates\KB2559049-IE7\ieudinit.exe
+ 2011-09-02 22:12 . 2011-02-17 19:00 44544 c:\windows\ie7updates\KB2559049-IE7\iernonce.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 78336 c:\windows\ie7updates\KB2559049-IE7\ieencode.dll
+ 2011-09-02 22:12 . 2011-02-17 11:43 70656 c:\windows\ie7updates\KB2559049-IE7\ie4uinit.exe
+ 2011-09-02 22:12 . 2011-02-17 19:00 63488 c:\windows\ie7updates\KB2559049-IE7\icardie.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 17408 c:\windows\ie7updates\KB2559049-IE7\corpol.dll
+ 2011-09-03 06:52 . 2011-09-03 06:52 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\1492e9393417d6e91b5ddc746b5ef320\UIAutomationProvider.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\343c52b741531ce9ae874ea7508831a7\System.Windows.Presentation.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\246110974e3c48733458819b07464b23\System.Web.DynamicData.Design.ni.dll
+ 2011-09-03 07:45 . 2011-09-03 07:45 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\ace861fe8dbf146c3e449abaa7691e9f\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-09-03 07:45 . 2011-09-03 07:45 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\177a17af98d803ab79006d6785706462\System.AddIn.Contract.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 96256 c:\windows\assembly\NativeImages_v2.0.50727_32\SbaXmlRequestHandler\31092633a807b37dfaf4e37b5b9f5a3e\SbaXmlRequestHandler.ni.dll
+ 2011-09-03 07:42 . 2011-09-03 07:42 13824 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAKB\ffc22c78403496da9434d7dd380bef4c\SBAKB.ni.dll
+ 2011-09-03 07:42 . 2011-09-03 07:42 13312 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAK\1197ac8d43cecfd8b4b7b57eaf79e848\SBAK.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 14848 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAIUI\c4b7a0dcd40522a9f056c0c18e3cec69\SBAIUI.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 72192 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAIREPORTINGV3\489b8240d37baad92f14037421c70e79\SBAIREPORTINGV3.ni.dll
+ 2011-09-03 07:39 . 2011-09-03 07:39 13824 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAIAPIENUS\ae0fc7b35de1f8685a19e96f51ba6a56\SBAIAPIENUS.ni.dll
+ 2011-09-03 07:39 . 2011-09-03 07:39 26112 c:\windows\assembly\NativeImages_v2.0.50727_32\SBACryptoServices\545e9e5f4d243cfdf8b0edfe4dbca2b8\SBACryptoServices.ni.dll
+ 2011-09-03 07:39 . 2011-09-03 07:39 14848 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAComponents\9137f7a2a76f2874e54b91e4b44745a2\SBAComponents.ni.dll
+ 2011-09-03 07:38 . 2011-09-03 07:38 80896 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAAPIEnUS\30177ae904a7f9240409e9d75e286719\SBAAPIEnUS.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\SBA.MsHtmHstInterop\3e06877384ecdf60f5c5d6e7de378c50\SBA.MsHtmHstInterop.ni.dll
+ 2011-09-03 06:44 . 2011-09-03 06:44 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\40ee65aacd9d7472cd6f8dddbfca604b\PresentationFontCache.ni.exe
+ 2011-09-03 06:42 . 2011-09-03 06:42 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\12c424eed7ee0e9c017bf72ff09eb78c\PresentationCFFRasterizer.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\NameParser\0deb6bb74dbbdbd7f37b4f472d28e8af\NameParser.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 26624 c:\windows\assembly\NativeImages_v2.0.50727_32\MigrationInterface\43ce2eda060b9c271b6518a99862cb35\MigrationInterface.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\f9c514544c8e23220493cd42a0e20678\Microsoft.Vsa.ni.dll
+ 2011-09-03 07:38 . 2011-09-03 07:38 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\a96b02abbfcaae424cfb91a198a9e0e9\Microsoft.VisualC.ni.dll
+ 2011-09-03 18:21 . 2011-09-03 18:21 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\3202e833a47d25344529db21d282702c\Microsoft.SqlServer.CustomControls.ni.dll
+ 2011-09-03 07:39 . 2011-09-03 07:39 53760 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.Ac#\adf6d7c4ddbea81007490ee052d2d3b4\Microsoft.Office.Accounting.Core.Common.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Interop.e#\8678ce5b391103d611078eea8a631b72\Microsoft.Interop.eCRM.NetFw.ni.dll
+ 2011-09-03 07:45 . 2011-09-03 07:45 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\f5057c30d89ad8d99e38c946a68def9e\Microsoft.Build.Framework.ni.dll
+ 2011-09-03 07:44 . 2011-09-03 07:44 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\623c05a555ac0719a1367f511d4a9270\Microsoft.Build.Framework.ni.dll
+ 2011-09-03 07:43 . 2011-09-03 07:43 73728 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\b8b3c022ff6942753b5c6140f0b906d7\DriversHQ.DriverDetective.ExceptionLogging.ni.dll
+ 2011-09-03 07:44 . 2011-09-03 07:44 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\c40d3caad8bff3c52db7e7562286406a\dfsvc.ni.exe
+ 2011-09-03 07:41 . 2011-09-03 07:41 38400 c:\windows\assembly\NativeImages_v2.0.50727_32\AddressParser\322e4f17eec93c0a46f15807f7baa7a2\AddressParser.ni.dll
+ 2011-09-03 07:38 . 2011-09-03 07:38 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\d9228d58804dfd75fd92a4d12ffac8af\Accessibility.ni.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2011-04-14 02:23 . 2011-04-14 02:23 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-09-03 18:01 . 2011-09-03 18:01 42848 c:\windows\assembly\GAC_MSIL\Microsoft.SqlServer.WmiEnum\9.0.242.0__89845dcd8080cc91\Microsoft.SqlServer.WmiEnum.dll
+ 2011-09-03 18:01 . 2011-09-03 18:01 38752 c:\windows\assembly\GAC_MSIL\Microsoft.SqlServer.ServiceBrokerEnum\9.0.242.0__89845dcd8080cc91\Microsoft.SqlServer.ServiceBrokerEnum.dll
+ 2011-09-03 18:01 . 2011-09-03 18:01 67424 c:\windows\assembly\GAC_MSIL\Microsoft.SqlServer.RegSvrEnum\9.0.242.0__89845dcd8080cc91\Microsoft.SqlServer.RegSvrEnum.dll
+ 2011-09-03 17:52 . 2011-09-03 17:52 42848 c:\windows\assembly\GAC_MSIL\Microsoft.SqlServer.CustomControls\9.0.242.0__89845dcd8080cc91\Microsoft.SqlServer.CustomControls.dll
+ 2011-09-03 18:01 . 2011-09-03 18:01 34656 c:\windows\assembly\GAC_MSIL\Microsoft.DataWarehouse.Interfaces\9.0.242.0__89845dcd8080cc91\Microsoft.DataWarehouse.Interfaces.DLL
+ 2011-09-02 22:22 . 2011-09-02 22:22 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2011-09-02 22:02 . 2011-09-02 22:02 51120 c:\windows\assembly\GAC_32\serialsdkEnUs\4.0.1001.0__31bf3856ad364e35\serialsdkEnUs.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 51120 c:\windows\assembly\GAC_32\SbaXmlRequestHandler\4.0.1001.0__31bf3856ad364e35\SbaXmlRequestHandler.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 60848 c:\windows\assembly\GAC_32\SbaWatson\4.0.1001.0__31bf3856ad364e35\SbaWatson.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 25008 c:\windows\assembly\GAC_32\SbaWatson.XmlSerializers\4.0.1001.0__31bf3856ad364e35\SbaWatson.XmlSerializers.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 67504 c:\windows\assembly\GAC_32\SBAUI.XmlSerializers\4.0.1001.0__31bf3856ad364e35\SBAUI.XmlSerializers.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 59312 c:\windows\assembly\GAC_32\SBASQM\4.0.1001.0__31bf3856ad364e35\SBASQM.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 42928 c:\windows\assembly\GAC_32\SbaSmartDoc\4.0.1001.0__31bf3856ad364e35\SbaSmartDoc.dll
+ 2011-09-02 22:02 . 2011-09-02 22:02 12208 c:\windows\assembly\GAC_32\SBAReportingEnUS\4.0.1001.0__31bf3856ad364e35\SBAReportingEnUS.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 64944 c:\windows\assembly\GAC_32\sbaprint\4.0.1001.0__31bf3856ad364e35\sbaprint.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 92080 c:\windows\assembly\GAC_32\SBAPAYROLL\4.0.1001.0__31bf3856ad364e35\SBAPAYROLL.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 16304 c:\windows\assembly\GAC_32\SBACryptoServices\4.0.1001.0__31bf3856ad364e35\SBACryptoServices.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 12208 c:\windows\assembly\GAC_32\SBAComponents\4.0.1001.0__31bf3856ad364e35\SBAComponents.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 21424 c:\windows\assembly\GAC_32\SBAAPIProxy\4.0.1001.0__31bf3856ad364e35\SBAAPIProxy.dll
+ 2011-09-02 22:02 . 2011-09-02 22:02 63408 c:\windows\assembly\GAC_32\SBAAPIEnUS\4.0.1001.0__31bf3856ad364e35\SBAAPIENUS.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 17840 c:\windows\assembly\GAC_32\NameParser\4.0.1001.0__31bf3856ad364e35\NameParser.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 15280 c:\windows\assembly\GAC_32\MigrationInterface\4.0.1001.0__31bf3856ad364e35\MigrationInterface.dll
+ 2011-09-03 18:01 . 2011-09-03 18:01 74592 c:\windows\assembly\GAC_32\Microsoft.SqlServer.MgdSqlDumper\9.0.242.0__89845dcd8080cc91\microsoft.sqlserver.mgdsqldumper.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 42928 c:\windows\assembly\GAC_32\Microsoft.Office.Accounting.Core.Common\4.0.1001.0__31bf3856ad364e35\Microsoft.Office.Accounting.Core.Common.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 63408 c:\windows\assembly\GAC_32\ImportExport\4.0.1001.0__31bf3856ad364e35\ImportExport.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 17840 c:\windows\assembly\GAC_32\AddressParser\4.0.1001.0__31bf3856ad364e35\AddressParser.dll
- 2011-04-14 02:23 . 2011-04-14 02:23 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2006-10-07 21:43 . 2011-09-06 12:18 4212 c:\windows\system32\zllictbl.dat
- 2006-10-07 21:43 . 2011-09-01 12:53 4212 c:\windows\system32\zllictbl.dat
+ 2011-09-02 22:22 . 2011-09-02 22:22 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2011-04-14 02:23 . 2011-04-14 02:23 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2011-05-14 00:17 . 2011-05-14 00:17 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll
+ 2011-05-14 00:12 . 2011-05-14 00:12 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcp80.dll
+ 2011-05-14 00:11 . 2011-05-14 00:11 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcm80.dll
- 2004-05-14 16:54 . 2011-02-17 19:00 233472 c:\windows\system32\webcheck.dll
+ 2004-05-14 16:54 . 2011-06-21 18:45 233472 c:\windows\system32\webcheck.dll
+ 2004-05-14 16:54 . 2011-06-21 18:45 106496 c:\windows\system32\url.dll
+ 2001-08-18 12:00 . 2011-04-29 17:25 151552 c:\windows\system32\schannel.dll
- 2001-08-18 12:00 . 2011-07-09 22:57 481178 c:\windows\system32\perfh009.dat
+ 2001-08-18 12:00 . 2011-09-03 18:02 481178 c:\windows\system32\perfh009.dat
- 2001-08-18 12:00 . 2008-04-14 04:42 551936 c:\windows\system32\oleaut32.dll
+ 2001-08-18 12:00 . 2010-12-20 17:32 551936 c:\windows\system32\oleaut32.dll
+ 2001-08-18 12:00 . 2011-06-21 18:45 102912 c:\windows\system32\occache.dll
- 2001-08-18 12:00 . 2011-02-17 19:00 102912 c:\windows\system32\occache.dll
+ 2004-05-14 16:44 . 2011-06-21 18:45 671232 c:\windows\system32\mstime.dll
- 2004-05-14 16:44 . 2011-02-17 19:00 671232 c:\windows\system32\mstime.dll
+ 2004-05-14 16:43 . 2011-06-21 18:45 193024 c:\windows\system32\msrating.dll
- 2004-05-14 16:43 . 2011-02-17 19:00 193024 c:\windows\system32\msrating.dll
+ 2004-05-14 16:42 . 2011-06-21 18:45 478720 c:\windows\system32\mshtmled.dll
+ 2006-11-07 21:03 . 2011-06-21 18:45 468480 c:\windows\system32\msfeeds.dll
- 2006-11-07 21:03 . 2011-02-17 19:00 468480 c:\windows\system32\msfeeds.dll
+ 2004-06-07 13:19 . 2011-05-02 15:31 692736 c:\windows\system32\inetcomm.dll
- 2004-06-07 13:19 . 2011-03-07 05:33 692736 c:\windows\system32\inetcomm.dll
+ 2006-10-17 11:57 . 2011-06-21 18:45 268288 c:\windows\system32\iertutil.dll
- 2006-10-17 11:57 . 2011-02-17 19:00 268288 c:\windows\system32\iertutil.dll
+ 2004-05-14 16:35 . 2011-06-21 18:45 192512 c:\windows\system32\iepeers.dll
- 2004-05-14 16:35 . 2011-02-17 19:00 192512 c:\windows\system32\iepeers.dll
- 2004-05-14 16:35 . 2011-02-17 19:00 384512 c:\windows\system32\iedkcs32.dll
+ 2004-05-14 16:35 . 2011-06-21 18:45 384512 c:\windows\system32\iedkcs32.dll
- 2006-10-17 11:27 . 2011-02-17 19:00 380928 c:\windows\system32\ieapfltr.dll
+ 2006-10-17 11:27 . 2011-06-21 18:45 380928 c:\windows\system32\ieapfltr.dll
+ 2001-08-18 12:00 . 2011-06-20 11:27 161792 c:\windows\system32\ieakui.dll
- 2001-08-18 12:00 . 2011-02-14 12:15 161792 c:\windows\system32\ieakui.dll
+ 2004-05-14 16:35 . 2011-06-21 18:45 230400 c:\windows\system32\ieaksie.dll
- 2004-05-14 16:35 . 2011-02-17 19:00 230400 c:\windows\system32\ieaksie.dll
+ 2004-05-14 16:35 . 2011-06-21 18:45 153088 c:\windows\system32\ieakeng.dll
- 2004-05-14 16:35 . 2011-02-17 19:00 153088 c:\windows\system32\ieakeng.dll
- 2004-05-13 19:29 . 2011-04-14 02:47 239144 c:\windows\system32\FNTCACHE.DAT
+ 2004-05-13 19:29 . 2011-09-03 06:40 239144 c:\windows\system32\FNTCACHE.DAT
- 2004-08-04 07:56 . 2011-02-17 19:00 133120 c:\windows\system32\extmgr.dll
+ 2004-08-04 07:56 . 2011-06-21 18:45 133120 c:\windows\system32\extmgr.dll
- 2004-05-14 16:33 . 2011-02-17 19:00 214528 c:\windows\system32\dxtrans.dll
+ 2004-05-14 16:33 . 2011-06-21 18:45 214528 c:\windows\system32\dxtrans.dll
+ 2004-05-14 16:33 . 2011-06-21 18:45 347136 c:\windows\system32\dxtmsft.dll
- 2004-05-14 16:33 . 2011-02-17 19:00 347136 c:\windows\system32\dxtmsft.dll
+ 2001-08-18 12:00 . 2011-04-21 13:37 105472 c:\windows\system32\drivers\mup.sys
+ 2001-08-18 12:00 . 2011-02-16 13:22 138496 c:\windows\system32\drivers\afd.sys
- 2001-08-18 12:00 . 2008-10-16 14:43 138496 c:\windows\system32\drivers\afd.sys
+ 2010-06-18 17:45 . 2011-06-20 17:44 293376 c:\windows\system32\dllcache\winsrv.dll
- 2010-06-18 17:45 . 2010-06-18 17:45 293376 c:\windows\system32\dllcache\winsrv.dll
- 2004-01-21 15:16 . 2011-02-17 19:00 832512 c:\windows\system32\dllcache\wininet.dll
+ 2004-01-21 15:16 . 2011-06-21 18:45 832512 c:\windows\system32\dllcache\wininet.dll
- 2004-05-14 16:54 . 2011-02-17 19:00 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2004-05-14 16:54 . 2011-06-21 18:45 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2004-05-14 16:54 . 2011-04-30 08:50 766464 c:\windows\system32\dllcache\vgx.dll
+ 2004-05-14 16:54 . 2011-06-21 18:45 106496 c:\windows\system32\dllcache\url.dll
+ 2008-12-05 06:54 . 2011-04-29 17:25 151552 c:\windows\system32\dllcache\schannel.dll
+ 2010-12-20 17:32 . 2010-12-20 17:32 551936 c:\windows\system32\dllcache\oleaut32.dll
- 2001-08-18 12:00 . 2011-02-17 19:00 102912 c:\windows\system32\dllcache\occache.dll
+ 2001-08-18 12:00 . 2011-06-21 18:45 102912 c:\windows\system32\dllcache\occache.dll
- 2004-05-14 16:44 . 2011-02-17 19:00 671232 c:\windows\system32\dllcache\mstime.dll
+ 2004-05-14 16:44 . 2011-06-21 18:45 671232 c:\windows\system32\dllcache\mstime.dll
- 2004-05-14 16:43 . 2011-02-17 19:00 193024 c:\windows\system32\dllcache\msrating.dll
+ 2004-05-14 16:43 . 2011-06-21 18:45 193024 c:\windows\system32\dllcache\msrating.dll
+ 2004-05-14 16:42 . 2011-06-21 18:45 478720 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-05-08 21:49 . 2011-06-21 18:45 468480 c:\windows\system32\dllcache\msfeeds.dll
- 2007-05-08 21:49 . 2011-02-17 19:00 468480 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-11-12 08:54 . 2011-07-15 13:29 456320 c:\windows\system32\dllcache\mrxsmb.sys
- 2008-08-14 04:24 . 2011-03-07 05:33 692736 c:\windows\system32\dllcache\inetcomm.dll
+ 2008-08-14 04:24 . 2011-05-02 15:31 692736 c:\windows\system32\dllcache\inetcomm.dll
- 2004-05-14 16:35 . 2011-02-14 12:17 634648 c:\windows\system32\dllcache\iexplore.exe
+ 2004-05-14 16:35 . 2011-06-20 11:29 634648 c:\windows\system32\dllcache\iexplore.exe
- 2007-05-08 21:49 . 2011-02-17 19:00 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2007-05-08 21:49 . 2011-06-21 18:45 268288 c:\windows\system32\dllcache\iertutil.dll
- 2004-05-14 16:35 . 2011-02-17 19:00 192512 c:\windows\system32\dllcache\iepeers.dll
+ 2004-05-14 16:35 . 2011-06-21 18:45 192512 c:\windows\system32\dllcache\iepeers.dll
+ 2004-05-14 16:35 . 2011-06-21 18:45 384512 c:\windows\system32\dllcache\iedkcs32.dll
- 2004-05-14 16:35 . 2011-02-17 19:00 384512 c:\windows\system32\dllcache\iedkcs32.dll
+ 2007-05-08 21:49 . 2011-06-21 18:45 380928 c:\windows\system32\dllcache\ieapfltr.dll
- 2007-05-08 21:49 . 2011-02-17 19:00 380928 c:\windows\system32\dllcache\ieapfltr.dll
- 2001-08-18 12:00 . 2011-02-14 12:15 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2001-08-18 12:00 . 2011-06-20 11:27 161792 c:\windows\system32\dllcache\ieakui.dll
- 2004-05-14 16:35 . 2011-02-17 19:00 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2004-05-14 16:35 . 2011-06-21 18:45 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2004-05-14 16:35 . 2011-06-21 18:45 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2004-05-14 16:35 . 2011-02-17 19:00 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2004-08-04 07:56 . 2011-06-21 18:45 133120 c:\windows\system32\dllcache\extmgr.dll
- 2004-08-04 07:56 . 2011-02-17 19:00 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2004-05-14 16:33 . 2011-06-21 18:45 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2004-05-14 16:33 . 2011-02-17 19:00 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2004-05-14 16:33 . 2011-02-17 19:00 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2004-05-14 16:33 . 2011-06-21 18:45 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-06-20 11:40 . 2011-02-16 13:22 138496 c:\windows\system32\dllcache\afd.sys
- 2008-06-20 11:40 . 2008-10-16 14:43 138496 c:\windows\system32\dllcache\afd.sys
+ 2004-05-14 16:30 . 2011-06-21 18:45 124928 c:\windows\system32\dllcache\advpack.dll
- 2004-05-14 16:30 . 2011-02-17 19:00 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-05-14 16:30 . 2011-06-21 18:45 124928 c:\windows\system32\advpack.dll
- 2004-05-14 16:30 . 2011-02-17 19:00 124928 c:\windows\system32\advpack.dll
- 2011-01-18 03:39 . 2011-01-18 03:39 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2011-03-25 05:15 . 2011-03-25 05:15 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
- 2011-01-18 03:39 . 2011-01-18 03:39 363856 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2011-03-25 05:15 . 2011-03-25 05:15 363856 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
- 2011-01-18 03:39 . 2011-01-18 03:39 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2011-03-25 05:15 . 2011-03-25 05:15 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2011-09-03 18:06 . 2011-09-03 18:06 814080 c:\windows\Installer\265aca9.msi
+ 2011-09-03 17:49 . 2011-09-03 17:49 809984 c:\windows\Installer\265abfe.msi
+ 2011-09-02 22:01 . 2011-09-02 22:01 467456 c:\windows\Installer\173bac5.msi
+ 2011-09-02 22:12 . 2011-02-17 19:00 832512 c:\windows\ie7updates\KB2559049-IE7\wininet.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 233472 c:\windows\ie7updates\KB2559049-IE7\webcheck.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 105984 c:\windows\ie7updates\KB2559049-IE7\url.dll
+ 2011-09-02 22:12 . 2010-07-05 13:16 382840 c:\windows\ie7updates\KB2559049-IE7\spuninst\updspapi.dll
+ 2011-09-02 22:12 . 2010-07-05 13:15 231288 c:\windows\ie7updates\KB2559049-IE7\spuninst\spuninst.exe
+ 2011-09-02 22:12 . 2011-02-17 19:00 102912 c:\windows\ie7updates\KB2559049-IE7\occache.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 671232 c:\windows\ie7updates\KB2559049-IE7\mstime.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 193024 c:\windows\ie7updates\KB2559049-IE7\msrating.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 478208 c:\windows\ie7updates\KB2559049-IE7\mshtmled.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 468480 c:\windows\ie7updates\KB2559049-IE7\msfeeds.dll
+ 2011-09-02 22:12 . 2011-02-14 12:17 634648 c:\windows\ie7updates\KB2559049-IE7\iexplore.exe
+ 2011-09-02 22:12 . 2011-02-17 19:00 268288 c:\windows\ie7updates\KB2559049-IE7\iertutil.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 192512 c:\windows\ie7updates\KB2559049-IE7\iepeers.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 384512 c:\windows\ie7updates\KB2559049-IE7\iedkcs32.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 380928 c:\windows\ie7updates\KB2559049-IE7\ieapfltr.dll
+ 2011-09-02 22:12 . 2011-02-14 12:15 161792 c:\windows\ie7updates\KB2559049-IE7\ieakui.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 230400 c:\windows\ie7updates\KB2559049-IE7\ieaksie.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 153088 c:\windows\ie7updates\KB2559049-IE7\ieakeng.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 133120 c:\windows\ie7updates\KB2559049-IE7\extmgr.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 214528 c:\windows\ie7updates\KB2559049-IE7\dxtrans.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 347136 c:\windows\ie7updates\KB2559049-IE7\dxtmsft.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 124928 c:\windows\ie7updates\KB2559049-IE7\advpack.dll
+ 2011-09-02 22:13 . 2007-07-12 23:31 765952 c:\windows\ie7updates\KB2544521-IE7\vgx.dll
+ 2011-09-02 22:13 . 2010-07-05 13:16 382840 c:\windows\ie7updates\KB2544521-IE7\spuninst\updspapi.dll
+ 2011-09-02 22:13 . 2010-07-05 13:15 231288 c:\windows\ie7updates\KB2544521-IE7\spuninst\spuninst.exe
+ 2008-11-12 08:54 . 2011-07-15 13:29 456320 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2011-09-03 07:43 . 2011-09-03 07:43 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\XPBurnComponent\ec7c3c8f012305fc43122dd6829585d8\XPBurnComponent.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 539136 c:\windows\assembly\NativeImages_v2.0.50727_32\Xceed.Zip\b83579e3f09c75c91f949e7f01a83268\Xceed.Zip.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 661504 c:\windows\assembly\NativeImages_v2.0.50727_32\Xceed.Grid.UIStyle\813cbc98396658a4728333f53637002b\Xceed.Grid.UIStyle.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 311808 c:\windows\assembly\NativeImages_v2.0.50727_32\Xceed.FileSystem\e7e429f725f51b963f4aaafcc7d78d3c\Xceed.FileSystem.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 267264 c:\windows\assembly\NativeImages_v2.0.50727_32\Xceed.Compression\449925f81363e529e431ade62e4e0981\Xceed.Compression.ni.dll
+ 2011-09-03 07:44 . 2011-09-03 07:44 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\cc14c69205b984edba1db26fd5e421ac\WsatConfig.ni.exe
+ 2011-09-03 06:52 . 2011-09-03 06:52 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\39ce0c9c9cc294c0ee26c4ff01522961\WindowsFormsIntegration.ni.dll
+ 2011-09-03 06:52 . 2011-09-03 06:52 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\3740d6db28af31a6523a79fcdd71fbeb\UIAutomationTypes.ni.dll
+ 2011-09-03 06:52 . 2011-09-03 06:52 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\431e918aee8da919f5b9e3a5195ccf93\UIAutomationClient.ni.dll
+ 2011-09-03 07:48 . 2011-09-03 07:48 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\946eefb99bc116ee68e0e7c69a5a8a5c\System.Xml.Linq.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\a82eef3128b9527dc05b3c8667e713bc\System.Web.Routing.ni.dll
+ 2011-09-03 07:39 . 2011-09-03 07:39 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\203c148c913357bfc2ae9d209101f2b3\System.Web.RegularExpressions.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\f89fe39468ea6faf71c4257c89cf3c54\System.Web.Extensions.Design.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\2314ff800782dc85224e69e802a073f7\System.Web.Entity.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\f690a8f5d784a5bb20f2cbaa7277eb6c\System.Web.Entity.Design.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\c5c96400424b85536443623f96f64581\System.Web.DynamicData.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\5f8e87b47465a038403e73012c6d102a\System.Web.Abstractions.ni.dll
+ 2011-09-03 07:38 . 2011-09-03 07:38 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\846dd505f97805f00999ee26aec9bf75\System.Transactions.ni.dll
+ 2011-09-03 07:39 . 2011-09-03 07:39 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\70a1400affdc775d7c7398e036359286\System.ServiceProcess.ni.dll
+ 2011-09-03 07:38 . 2011-09-03 07:38 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\de9cd25ccb24bcf8a0316756e766721f\System.Security.ni.dll
+ 2011-09-03 07:39 . 2011-09-03 07:39 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\21248037960cf6dfa2ce401d355bd6c9\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2011-09-03 07:38 . 2011-09-03 07:38 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b7e0214a811f81e09041864081139641\System.Runtime.Remoting.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\480ea914e13fe41cdd8fb542bb1f7e81\System.Net.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\6e563a58e6fc0117070d5b8fd59e4e1b\System.Management.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\dc72c7581f1b3794c0ea595ba02ff7ad\System.Management.Instrumentation.ni.dll
+ 2011-09-03 07:43 . 2011-09-03 07:43 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\fcf8612a210d1f76e0b37dc8467b4696\System.IO.Log.ni.dll
+ 2011-09-03 07:43 . 2011-09-03 07:43 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\ec017b5a95d02fccaefd835490ef1e14\System.IdentityModel.Selectors.ni.dll
+ 2011-09-03 07:38 . 2011-09-03 07:38 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\75f452279422a7898e840ee5768c9d2e\System.EnterpriseServices.Wrapper.dll
+ 2011-09-03 07:38 . 2011-09-03 07:38 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\75f452279422a7898e840ee5768c9d2e\System.EnterpriseServices.ni.dll
+ 2011-09-03 06:50 . 2011-09-03 06:50 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\f7cd3d07c15366b76fe4c38d24455d6b\System.Drawing.Design.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\822c996e6ad4901219b7de399a6f78bf\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-09-03 07:39 . 2011-09-03 07:39 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\1ffe911e62f482e42be2c4428bd08c10\System.DirectoryServices.Protocols.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\e1c009b2c9becdb732a2ea45f32a46b8\System.Data.Services.Design.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\1defd94e1662a4478ccf2cd0b1b4e6a6\System.Data.Services.Client.ni.dll
+ 2011-09-03 07:46 . 2011-09-03 07:46 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\04267c1dbdcdd8ec37e1518126767ead\System.Data.Entity.Design.ni.dll
+ 2011-09-03 07:45 . 2011-09-03 07:45 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\f2a6d41b3f6e26eea6dcac9298aa637b\System.Data.DataSetExtensions.ni.dll
+ 2011-09-03 07:38 . 2011-09-03 07:38 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\77df2cd21a5b85a1605b335aa9ad9d44\System.Configuration.ni.dll
+ 2011-09-03 07:39 . 2011-09-03 07:39 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\585e68739b2a8aff61ee6b2786513245\System.Configuration.Install.ni.dll
+ 2011-09-03 07:45 . 2011-09-03 07:45 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\fbf6ef12d1456058acde29f2640092fb\System.AddIn.ni.dll
+ 2011-09-03 07:44 . 2011-09-03 07:44 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\896e42071939e038008b0bbbfed1213c\SMSvcHost.ni.exe
+ 2011-09-03 07:44 . 2011-09-03 07:44 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\ca07e9cf488af1290d2340d682574a24\SMDiagnostics.ni.dll
+ 2011-09-03 07:44 . 2011-09-03 07:44 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\a5aa977dd575a6beb3a416bd480b98a7\ServiceModelReg.ni.exe
+ 2011-09-03 07:42 . 2011-09-03 07:42 106496 c:\windows\assembly\NativeImages_v2.0.50727_32\SbaWatson\00681874d14c782805d9e10b5b914927\SbaWatson.ni.dll
+ 2011-09-03 07:43 . 2011-09-03 07:43 115200 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAUI.XmlSerializers\cdacdc2940abc89ef9f9c419796d35d6\SBAUI.XmlSerializers.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 101376 c:\windows\assembly\NativeImages_v2.0.50727_32\SBASQM\cafaefc45ce39ef19cc2919036674800\SBASQM.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 260096 c:\windows\assembly\NativeImages_v2.0.50727_32\SBASpreadsheetML\0918f1064156f2246c8fbc7e5068b665\SBASpreadsheetML.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 121856 c:\windows\assembly\NativeImages_v2.0.50727_32\sbaprint\cb210d4b61c9f654d2f11a54eb255e8a\sbaprint.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 183296 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAPAYROLL\5dc857474211f89ebab03ad2cbc6f19c\SBAPAYROLL.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 425984 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAMasterDataWriter\c0bcce539fc05aed197f0e081977debf\SBAMasterDataWriter.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 107520 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAIREPORTING\69349f2a84a3eafab57de9c2a291f9ff\SBAIREPORTING.ni.dll
+ 2011-09-03 07:38 . 2011-09-03 07:38 285696 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAIAPIV4\bf6ef88fa6b18f3495992bc727c4250a\SBAIAPIV4.ni.dll
+ 2011-09-03 07:38 . 2011-09-03 07:38 418816 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAIAPIV3\27e0ff302f9abe4097b6b30a76843362\SBAIAPIV3.ni.dll
+ 2011-09-03 07:38 . 2011-09-03 07:38 636416 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAIAPIV2\d560475f75ec931655a6f02f95b62fa7\SBAIAPIV2.ni.dll
+ 2011-09-03 07:38 . 2011-09-03 07:38 532992 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAIAPI\870459885c23b567c06b59732666a8b2\SBAIAPI.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 380928 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAECOMM\3d5a4c39767330a5e10adfcfc29265e5\SBAECOMM.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 333312 c:\windows\assembly\NativeImages_v2.0.50727_32\SBA.Interop.SHDocVw\1f8a031e081b32d8fa8f26a56350447a\SBA.Interop.SHDocVw.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 110080 c:\windows\assembly\NativeImages_v2.0.50727_32\SBA.AxInterop.SHDoc#\681b5943fa11c675cf178a2655d54c45\SBA.AxInterop.SHDocVw.ni.dll
+ 2011-09-03 06:46 . 2011-09-03 06:46 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\f52e48f55258d0a04fbab3a1f93752e9\PresentationFramework.Classic.ni.dll
+ 2011-09-03 06:45 . 2011-09-03 06:45 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\cf812b99f587ab514afb36fa9d4c1567\PresentationFramework.Aero.ni.dll
+ 2011-09-03 06:46 . 2011-09-03 06:46 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\b7795999cc67f3a6cec40f5b24005e00\PresentationFramework.Luna.ni.dll
+ 2011-09-03 06:46 . 2011-09-03 06:46 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\09f5af61ea2af04eb32c04b3091ffc86\PresentationFramework.Royale.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 104960 c:\windows\assembly\NativeImages_v2.0.50727_32\ParseLib2\481e6978ef5128fccdb462d1efb422d5\ParseLib2.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 924672 c:\windows\assembly\NativeImages_v2.0.50727_32\office\cec8a180108df125b2ce11ab33c1d468\office.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 321024 c:\windows\assembly\NativeImages_v2.0.50727_32\MSIDCRL.Managed\9855d9649bdba272bb3bb1db55d32194\MSIDCRL.Managed.ni.dll
+ 2011-09-03 07:44 . 2011-09-03 07:44 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\2d89c7b72bc8e527b26d5b6f3b931012\MSBuild.ni.exe
+ 2011-09-03 07:41 . 2011-09-03 07:41 813056 c:\windows\assembly\NativeImages_v2.0.50727_32\MoneyMigrationWrapp#\703378f9c6ce0d61a1a8ab460d94544a\MoneyMigrationWrapper.ni.dll
+ 2011-09-03 07:44 . 2011-09-03 07:44 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\39e9d172f0cf5eec30b1b67212cc032b\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-09-03 18:21 . 2011-09-03 18:21 530432 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\43062d816d1afc9a22dc31b4f2eddd05\Microsoft.SqlServer.GridControl.ni.dll
+ 2011-09-03 18:21 . 2011-09-03 18:21 989184 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\3be081982500ee8cf0971e0bda910df1\Microsoft.SqlServer.WizardFrameworkLite.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 534528 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SBA.Offic#\1774c8cae6ecd540782551ae57da72ee\Microsoft.SBA.OfficeLive.ni.dll
+ 2011-09-03 07:43 . 2011-09-03 07:43 303616 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\a47216005006207a6d45adadafe1deca\Microsoft.Practices.ObjectBuilder.ni.dll
+ 2011-09-03 07:43 . 2011-09-03 07:43 148992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\8b7c044daa42b52ac743c6d6bcbc96fb\Microsoft.Practices.EnterpriseLibrary.Security.Cryptography.ni.dll
+ 2011-09-03 07:43 . 2011-09-03 07:43 309248 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\323014752ec989bc25f6c820c3d0692f\Microsoft.Practices.EnterpriseLibrary.Common.ni.dll
+ 2011-09-03 18:21 . 2011-09-03 18:21 231936 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.NetEnterp#\b088cbdacae3848d60b168f4143722d5\Microsoft.NetEnterpriseServers.ExceptionMessageBox.ni.dll
+ 2011-09-03 07:45 . 2011-09-03 07:45 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\f1b0ec3ccde9142e67ac681fb521ac66\Microsoft.Build.Utilities.ni.dll
+ 2011-09-03 07:45 . 2011-09-03 07:45 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\9250f038410f0d6432e3ccb0b046862b\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2011-09-03 07:45 . 2011-09-03 07:45 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\a4672179aba638cd78bdfe268391b47b\Microsoft.Build.Engine.ni.dll
+ 2011-09-03 07:44 . 2011-09-03 07:44 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\37db660a84ee52b61a7ca55812581bbd\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2011-09-03 07:43 . 2011-09-03 07:43 230912 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\f4a138299ccea0f83a0539bbf6302fba\Microsoft.ApplicationBlocks.Updater.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 119808 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Advertisi#\eb321487bc33ad7a3f14504b55fd01a9\Microsoft.Advertising.Publisher.Client.Controls.ni.dll
+ 2011-09-03 07:43 . 2011-09-03 07:43 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.WUApiLib\12778b30b26cc1072ef5c7751e0c1d40\Interop.WUApiLib.ni.dll
+ 2011-09-03 07:43 . 2011-09-03 07:43 330240 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\dfcb82b622ddf9729dd4b597d3c8cbaa\DriversHQ.DriverDetective.Common.ni.dll
+ 2011-09-03 07:43 . 2011-09-03 07:43 378368 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\76947a9c9ff6b06360c83f7f5a5943bf\DriversHQ.DriverDetective.Client.Communication.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 333824 c:\windows\assembly\NativeImages_v2.0.50727_32\DataMigration\fb2eb456bb776c449f7a8c88cde193a8\DataMigration.ni.dll
+ 2011-09-03 07:44 . 2011-09-03 07:44 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\80bd17388778c90f301746ad88700758\CustomMarshalers.ni.dll
+ 2011-09-03 07:44 . 2011-09-03 07:44 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\fe9a21b94803f74697bb42b9d1fdea5b\ComSvcConfig.ni.exe
+ 2011-09-03 07:38 . 2011-09-03 07:38 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\f160c8e40b60edd47ae74b0b911fece1\AspNetMMCExt.ni.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2011-04-14 02:23 . 2011-04-14 02:23 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2011-04-14 02:23 . 2011-04-14 02:23 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2011-04-14 02:23 . 2011-04-14 02:23 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2011-04-14 02:23 . 2011-04-14 02:23 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2011-04-14 02:23 . 2011-04-14 02:23 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2011-04-14 02:23 . 2011-04-14 02:23 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 370608 c:\windows\assembly\GAC_MSIL\SBASpreadsheetML.XmlSerializers\4.0.1001.0__31bf3856ad364e35\SBASpreadsheetML.XmlSerializers.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2011-09-03 17:52 . 2011-09-03 17:52 591712 c:\windows\assembly\GAC_MSIL\Microsoft.SqlServer.WizardFrameworkLite\9.0.242.0__89845dcd8080cc91\Microsoft.SqlServer.WizardFrameworkLite.dll
+ 2011-09-03 18:01 . 2011-09-03 18:01 919392 c:\windows\assembly\GAC_MSIL\Microsoft.SqlServer.SqlEnum\9.0.242.0__89845dcd8080cc91\Microsoft.SqlServer.SqlEnum.dll
+ 2011-09-03 18:01 . 2011-09-03 18:01 218976 c:\windows\assembly\GAC_MSIL\Microsoft.SqlServer.SmoEnum\9.0.242.0__89845dcd8080cc91\Microsoft.SqlServer.SmoEnum.dll
+ 2011-09-03 18:01 . 2011-09-03 18:01 554848 c:\windows\assembly\GAC_MSIL\Microsoft.SqlServer.Rmo\9.0.242.0__89845dcd8080cc91\Microsoft.SqlServer.Rmo.dll
+ 2011-09-03 17:52 . 2011-09-03 17:52 198496 c:\windows\assembly\GAC_MSIL\Microsoft.SqlServer.GridControl\9.0.242.0__89845dcd8080cc91\Microsoft.SqlServer.GridControl.dll
+ 2011-09-03 18:01 . 2011-09-03 18:01 153440 c:\windows\assembly\GAC_MSIL\Microsoft.SqlServer.ConnectionInfo\9.0.242.0__89845dcd8080cc91\Microsoft.SqlServer.ConnectionInfo.dll
+ 2011-09-03 17:52 . 2011-09-03 17:52 132960 c:\windows\assembly\GAC_MSIL\Microsoft.NetEnterpriseServers.ExceptionMessageBox\9.0.242.0__89845dcd8080cc91\Microsoft.NetEnterpriseServers.ExceptionMessageBox.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2011-09-03 18:01 . 2011-09-03 18:01 137056 c:\windows\assembly\GAC_MSIL\Microsoft.AnalysisServices.DeploymentEngine\9.0.242.0__89845dcd8080cc91\Microsoft.AnalysisServices.DeploymentEngine.dll
+ 2011-09-03 18:01 . 2011-09-03 18:01 542560 c:\windows\assembly\GAC_MSIL\Microsoft.AnalysisServices.AdomdClient\9.0.242.0__89845dcd8080cc91\Microsoft.AnalysisServices.AdomdClient.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 612272 c:\windows\assembly\GAC_32\serialsdk\4.0.1001.0__31bf3856ad364e35\serialsdk.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 116656 c:\windows\assembly\GAC_32\SBASpreadsheetML\4.0.1001.0__31bf3856ad364e35\SBASpreadsheetML.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 133040 c:\windows\assembly\GAC_32\SBAMasterDataWriter\4.0.1001.0__31bf3856ad364e35\SBAMasterDataWriter.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 161712 c:\windows\assembly\GAC_32\SBAECOMM\4.0.1001.0__31bf3856ad364e35\SBAECOMM.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 116656 c:\windows\assembly\GAC_32\OFXDriver\4.0.1001.0__31bf3856ad364e35\OFXDriver.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 210864 c:\windows\assembly\GAC_32\MSIDCRL.Managed\4.0.1001.0__31bf3856ad364e35\MSIDCRL.Managed.dll
+ 2011-09-02 22:02 . 2011-09-02 22:02 381872 c:\windows\assembly\GAC_32\MoneyMigrationWrapper\4.0.1001.0__31bf3856ad364e35\MoneyMigrationWrapper.dll
+ 2011-09-03 18:01 . 2011-09-03 18:01 359776 c:\windows\assembly\GAC_32\Microsoft.SqlServer.BatchParser\9.0.242.0__89845dcd8080cc91\microsoft.sqlserver.batchparser.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 235440 c:\windows\assembly\GAC_32\Microsoft.SBA.OfficeLive\4.0.1001.0__31bf3856ad364e35\Microsoft.SBA.OfficeLive.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 169904 c:\windows\assembly\GAC_32\EnumScriptResource\4.0.1001.0__31bf3856ad364e35\enumscriptresource.dll
+ 2011-05-13 19:04 . 2011-05-13 19:04 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfc80u.dll
+ 2011-05-13 19:04 . 2011-05-13 19:04 1101824 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfc80.dll
+ 2001-08-18 12:00 . 2011-06-02 14:02 1858944 c:\windows\system32\win32k.sys
+ 2004-01-21 15:20 . 2011-06-21 18:45 1168896 c:\windows\system32\urlmon.dll
+ 2010-12-10 17:29 . 2010-12-10 17:29 2248032 c:\windows\system32\sqlncli.dll
+ 2004-07-07 17:37 . 2011-07-22 16:35 3613696 c:\windows\system32\mshtml.dll
+ 2006-11-07 21:03 . 2011-06-21 18:45 6076416 c:\windows\system32\ieframe.dll
+ 2008-10-17 00:52 . 2011-06-02 14:02 1858944 c:\windows\system32\dllcache\win32k.sys
+ 2004-01-21 15:20 . 2011-06-21 18:45 1168896 c:\windows\system32\dllcache\urlmon.dll
+ 2004-07-07 17:37 . 2011-07-22 16:35 3613696 c:\windows\system32\dllcache\mshtml.dll
+ 2007-05-08 21:49 . 2011-06-21 18:45 6076416 c:\windows\system32\dllcache\ieframe.dll
+ 2011-03-25 05:15 . 2011-03-25 05:15 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
- 2008-07-25 10:17 . 2008-07-25 10:17 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
- 2010-03-23 04:32 . 2010-03-23 04:32 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2011-04-28 20:50 . 2011-04-28 20:50 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2011-03-25 05:15 . 2011-03-25 05:15 5912400 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
- 2011-01-18 03:39 . 2011-01-18 03:39 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2011-03-25 05:15 . 2011-03-25 05:15 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2011-09-03 18:13 . 2011-09-03 18:13 5180928 c:\windows\Installer\265acf5.msi
+ 2011-09-03 18:02 . 2011-09-03 18:02 6642688 c:\windows\Installer\265ac9f.msi
+ 2011-09-03 18:00 . 2011-09-03 18:00 1075712 c:\windows\Installer\265ac41.msi
+ 2011-05-01 23:06 . 2011-05-01 23:06 2705920 c:\windows\Installer\18288e6.msp
+ 2011-09-02 22:12 . 2011-02-17 19:00 1168384 c:\windows\ie7updates\KB2559049-IE7\urlmon.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 3607040 c:\windows\ie7updates\KB2559049-IE7\mshtml.dll
+ 2011-09-02 22:12 . 2011-02-17 19:00 6075904 c:\windows\ie7updates\KB2559049-IE7\ieframe.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 2102272 c:\windows\assembly\NativeImages_v2.0.50727_32\Xceed.Grid\0aae07c71522632bc89f199e2986f9c8\Xceed.Grid.ni.dll
+ 2011-09-03 06:43 . 2011-09-03 06:43 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\fd6e0cd6f124a6d041ef1b4c9a5f080b\WindowsBase.ni.dll
+ 2011-09-03 06:52 . 2011-09-03 06:52 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\162600dde59fbaa0c048a949158ecba3\UIAutomationClientsideProviders.ni.dll
+ 2011-09-03 06:42 . 2011-09-03 06:42 7950848 c:\windows\assembly\NativeImages_v2.0.50727_32\System\e6c79e1d71b0c9000afd7e5e439b5c54\System.ni.dll
+ 2011-09-03 06:52 . 2011-09-03 06:52 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\10154dcad2d62f226af2fd4211460a4b\System.Xml.ni.dll
+ 2011-09-03 07:48 . 2011-09-03 07:48 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\22229a30650a9afbac984e1093898b13\System.WorkflowServices.ni.dll
+ 2011-09-03 07:48 . 2011-09-03 07:48 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\4d6b3cc1fc7a4788612241af7966715a\System.Workflow.Runtime.ni.dll
+ 2011-09-03 07:48 . 2011-09-03 07:48 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\e4c9853af945c9cfede19f3faf18af6e\System.Workflow.ComponentModel.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\ab4b50c7c789e46a485903365765fde8\System.Workflow.Activities.ni.dll
+ 2011-09-03 07:39 . 2011-09-03 07:39 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\a2392c995b1bb6b63079091259222357\System.Web.Services.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\3da92a0b9b8ac97e11ca8bf4df671a78\System.Web.Mobile.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 2405376 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\01f4d6aa3299a41b8578b7e96afdcfb1\System.Web.Extensions.ni.dll
+ 2011-09-03 06:50 . 2011-09-03 06:50 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\e1208f0d981c420fc59f806bfbaa713b\System.Speech.ni.dll
+ 2011-09-03 07:47 . 2011-09-03 07:47 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\27e1b8dfd5e1ccf2c5b9efc51f674c69\System.ServiceModel.Web.ni.dll
+ 2011-09-03 07:43 . 2011-09-03 07:43 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\dece01bd9e9c32e47630fdfc78d3bd32\System.Runtime.Serialization.ni.dll
+ 2011-09-03 06:50 . 2011-09-03 06:50 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\90b444d02047ef27921153d46967ef0e\System.Printing.ni.dll
+ 2011-09-03 07:43 . 2011-09-03 07:43 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\a50e2fc92db32751857fb8d297f9d7bc\System.IdentityModel.ni.dll
+ 2011-09-03 06:50 . 2011-09-03 06:50 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\7ed09623172a292eaee51e2e3bcaf784\System.Drawing.ni.dll
+ 2011-09-03 07:38 . 2011-09-03 07:38 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\259ecf480769f4e60514b7ae2abaa6f1\System.DirectoryServices.ni.dll
+ 2011-09-03 07:39 . 2011-09-03 07:39 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\71cf3eb40fc38e6ac8fba09e872d2878\System.Deployment.ni.dll
+ 2011-09-03 06:48 . 2011-09-03 06:48 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\db2d84e279807592a680ef4135e9fe9a\System.Data.ni.dll
+ 2011-09-03 07:38 . 2011-09-03 07:38 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\0b16305773369cf740c6a2b1f1d785b2\System.Data.SqlXml.ni.dll
+ 2011-09-03 07:46 . 2011-09-03 07:46 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\c1b9b8ce390548dcca661a5e6a908408\System.Data.Services.ni.dll
+ 2011-09-03 07:39 . 2011-09-03 07:39 1115136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\c729750d54f6e7427230622bcccd4709\System.Data.OracleClient.ni.dll
+ 2011-09-03 06:49 . 2011-09-03 06:49 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\571af34939797a7c1cd05b0b925a45bf\System.Data.Linq.ni.dll
+ 2011-09-03 07:46 . 2011-09-03 07:46 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\2b58cc071d6bf0c741e91f86c09de5d7\System.Data.Entity.ni.dll
+ 2011-09-03 06:47 . 2011-09-03 06:47 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\e54e013315849f5e34d8f2a8e7fdb450\System.Core.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 2101248 c:\windows\assembly\NativeImages_v2.0.50727_32\serialsdk\34c3c1f0fd60d91d251d521927f96d67\serialsdk.ni.dll
+ 2011-09-03 07:43 . 2011-09-03 07:43 2075648 c:\windows\assembly\NativeImages_v2.0.50727_32\sbauienus\ae57628958463e856851e06a1d642c46\sbauienus.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 2265088 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAResources\ee35f5cf2194d6e56840da077ba2d2ef\SBAResources.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 1992704 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAReporting\8fd66120845cc40685d8b9c6eff51504\SBAReporting.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 1709568 c:\windows\assembly\NativeImages_v2.0.50727_32\SBA.interop.coreobj#\f434a0af46f65541f0e779b32c75b1e3\SBA.interop.coreobjx50.ni.dll
+ 2011-09-03 06:47 . 2011-09-03 06:47 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\24ab0cacc77e8696ceff3157942a2de4\ReachFramework.ni.dll
+ 2011-09-03 06:46 . 2011-09-03 06:46 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\fac1ca86f4fea17de40d7fdaba38563e\PresentationUI.ni.dll
+ 2011-09-03 06:42 . 2011-09-03 06:42 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b187becbc388c4ce7f33ede4da76e7b1\PresentationBuildTasks.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\c6b19db2534042d435ede580f92bc75c\Microsoft.VisualBasic.ni.dll
+ 2011-09-03 07:44 . 2011-09-03 07:44 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\08594c4ba9ea0253a836fe1d8d341984\Microsoft.Transactions.Bridge.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\345abd035c9378667b1cac54c1f21c97\Microsoft.JScript.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:40 2922496 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.BusinessS#\d82702d10de82f14acbb1487b65aa975\Microsoft.BusinessSolutions.SBA.Interop.Excel.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 1753600 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.BusinessS#\aca48e7c1856a99e99f918ab394d81f5\Microsoft.BusinessSolutions.SBA.Interop.Word.ni.dll
+ 2011-09-03 07:42 . 2011-09-03 07:42 3933696 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.BusinessS#\a045769a66bf0f42d079d10fab439391\Microsoft.BusinessSolutions.SBA.Interop.Access.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 2301952 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.BusinessS#\9a51d749ccf23a96cb62c12edd1007bf\Microsoft.BusinessSolutions.SBA.Interop.Outlook.ni.dll
+ 2011-09-03 07:45 . 2011-09-03 07:45 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\906cd5555b79e4e0486dc8ef2a748b13\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2011-09-03 07:45 . 2011-09-03 07:45 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\7baff7d694394aaba490082c88d48fd2\Microsoft.Build.Tasks.ni.dll
+ 2011-09-03 07:44 . 2011-09-03 07:44 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\235a22e1ae9742bb724d411629dd99d5\Microsoft.Build.Engine.ni.dll
+ 2011-09-03 07:41 . 2011-09-03 07:41 7210496 c:\windows\assembly\NativeImages_v2.0.50727_32\DundasWinChart\4e2e1725113ca890da915904d36c55eb\DundasWinChart.ni.dll
+ 2011-09-03 07:43 . 2011-09-03 07:43 4674048 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\e795633d9b9a1c6c7726e7528e79d0b8\DriversHQ.DriverDetective.Client.ni.exe
+ 2011-09-03 07:43 . 2011-09-03 07:43 1132032 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.Common\95d5a8dd5573866db3b97981dc551e4f\DriversHQ.Common.ni.dll
- 2011-04-14 02:23 . 2011-04-14 02:23 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2011-04-14 02:23 . 2011-04-14 02:23 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2011-09-03 18:01 . 2011-09-03 18:01 1603424 c:\windows\assembly\GAC_MSIL\Microsoft.SqlServer.Smo\9.0.242.0__89845dcd8080cc91\Microsoft.SqlServer.Smo.dll
+ 2011-09-03 18:01 . 2011-09-03 18:01 1214304 c:\windows\assembly\GAC_MSIL\Microsoft.AnalysisServices\9.0.242.0__89845dcd8080cc91\Microsoft.AnalysisServices.DLL
+ 2011-09-02 22:22 . 2011-09-02 22:22 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2011-04-14 02:23 . 2011-04-14 02:23 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-09-02 22:02 . 2011-09-02 22:02 1750960 c:\windows\assembly\GAC_32\sbauienus\4.0.1001.0__31bf3856ad364e35\sbauienus.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 1836976 c:\windows\assembly\GAC_32\SBAResources\4.0.1001.0__31bf3856ad364e35\SBAResources.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 1075120 c:\windows\assembly\GAC_32\SBAReporting\4.0.1001.0__31bf3856ad364e35\SBAReporting.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 5785520 c:\windows\assembly\GAC_32\SBAAPI\4.0.1001.0__31bf3856ad364e35\SBAAPI.dll
+ 2011-09-02 22:22 . 2011-09-02 22:22 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2011-04-14 02:22 . 2011-04-14 02:22 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-09-03 18:01 . 2011-09-03 18:01 1625440 c:\windows\assembly\GAC_32\Microsoft.SqlServer.Replication\9.0.242.0__89845dcd8080cc91\Microsoft.SqlServer.Replication.dll
+ 2005-05-12 10:25 . 2011-07-30 09:05 52390856 c:\windows\system32\mrt.exe
+ 2011-03-28 02:27 . 2011-03-28 02:27 15456256 c:\windows\Installer\18288f2.msp
+ 2009-12-14 04:58 . 2009-12-14 04:58 35161600 c:\windows\Installer\173bb0e.msp
+ 2011-09-03 06:51 . 2011-09-03 06:51 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d00cc387e462e4c3cdcd112b137cac87\System.Windows.Forms.ni.dll
+ 2011-09-03 07:39 . 2011-09-03 07:39 11800576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\40893760431f8f0dcce3e18630e45b23\System.Web.ni.dll
+ 2011-09-03 07:44 . 2011-09-03 07:44 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\e3a0205acab2215fbad7927d9d483aeb\System.ServiceModel.ni.dll
+ 2011-09-03 06:50 . 2011-09-03 06:50 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\63ad0cd9b5e038c8e2e41415657db8fc\System.Design.ni.dll
+ 2011-09-03 07:40 . 2011-09-03 07:41 11275264 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAReportingBitmap\3634c2cf63ec28379fa714dba91ec91d\SBAReportingBitmap.ni.dll
+ 2011-09-03 07:38 . 2011-09-03 07:38 10401280 c:\windows\assembly\NativeImages_v2.0.50727_32\SBAAPI\8c12ae49e01cc69198ceceab007f38dc\SBAAPI.ni.dll
+ 2011-09-03 06:45 . 2011-09-03 06:45 14328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\704556e34128441ea9f1a81cc89f8a79\PresentationFramework.ni.dll
+ 2011-09-03 06:43 . 2011-09-03 06:43 12215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\5f332c48d03eca57419c4f0e884092ee\PresentationCore.ni.dll
+ 2011-09-03 06:42 . 2011-09-03 06:42 11490816 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\0309936a8e1672d39b9cf14463ce69f9\mscorlib.ni.dll
+ 2011-09-03 07:42 . 2011-09-03 07:42 17678336 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.mshtml\f23be365b43ed7bf3ada8216cd105374\Microsoft.mshtml.ni.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 17594288 c:\windows\assembly\GAC_32\SBAUI\4.0.1001.0__31bf3856ad364e35\SBAUI.dll
+ 2011-09-02 22:03 . 2011-09-02 22:03 11286448 c:\windows\assembly\GAC_32\SBAReportingBitmap\4.0.1001.0__31bf3856ad364e35\SBAReportingBitmap.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\program files\AVG\AVG8\avgtray.exe" [2010-07-09 2048352]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2010-11-17 329096]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-21 08:09 11952 —-a-w- c:\windows\system32\avgrsstx.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GraphicsPlus.lnk]
backup=c:\windows\pss\GraphicsPlus.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus Organizer EasyClip.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus QuickStart.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus SmartCenter.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus SuiteStart.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Ashampoo Mail Virus Blocker Server.lnk]
backup=c:\windows\pss\Ashampoo Mail Virus Blocker Server.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Lotus SmartSuite Release 9 Registration.lnk]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2005-01-12 14:54 241664 —-a-w- c:\program files\HP\hpcoretech\hpcmpmgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 04:42 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-05 17:36 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Owner\\My Documents\\My Downloads\\incredimail_install.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\incmail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\VoipCheap\\voipcheap.exe"=
"c:\\Program Files\\PPMate\\ppmate.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncrediMail_Install.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2011.SP1\\RpcAgentSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2011.SP1\\WNt500x86\\RpcSandraSrv.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\IncrediMail\\Data\\Runtime\\IncrediMail_Install.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 BsStor;InCD Storage Helper Driver;c:\windows\system32\drivers\bsstor.sys [14/05/2004 03:49 9088]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [22/07/2011 16:47 13496]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/06/2008 00:08 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/06/2008 00:08 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 19:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 19:41 67656]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [09/07/2009 08:35 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [03/07/2008 23:56 297752]
R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [03/10/2008 23:39 700336]
R2 ioloSystemService;iolo System Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [03/10/2008 23:39 700336]
R3 AEILAB;AEI USB To Fast Ethernet Adapter;c:\windows\system32\drivers\AEILAB.SYS [18/06/2006 12:55 24299]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys –> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27/04/2010 21:52 136176]
S2 ousbehci;NEC PCI to USB Enhanced Host Controller;c:\windows\system32\drivers\ousbehci.sys [04/06/2006 17:23 45696]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [27/04/2010 21:52 136176]
S3 INQ1usbser;INQ1 USB Device for Legacy Serial Communication;c:\windows\system32\drivers\INQ1usbser.sys [06/12/2009 14:50 103680]
S3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows\system32\drivers\ousb2hub.sys [04/06/2006 17:23 56960]
S3 qcusbmdm6k;WP-S1 Proprietary USB Driver;c:\windows\system32\drivers\qcusbmdm6k.sys [15/05/2008 17:31 65024]
S3 qcusbnmea;WP-S1 NMEA Port;c:\windows\system32\drivers\qcusbnmea.sys [15/05/2008 17:31 65024]
S3 qcusbpcsync;WP-S1 PCSYNC Port;c:\windows\system32\drivers\qcusbpcsync.sys [15/05/2008 17:31 65024]
S3 qcusbser6k;WP-S1 Diagnostic Port;c:\windows\system32\drivers\qcusbser6k.sys [15/05/2008 17:31 65024]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2011.SP1\RpcAgentSrv.exe [09/03/2011 23:37 93848]
S4 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [25/07/2011 21:02 353168]
S4 BsUDF;InCD UDF Driver;c:\windows\system32\drivers\bsudf.sys [14/05/2004 03:49 329728]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2011-09-06 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-09-30 15:52]
.
2011-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-27 20:51]
.
2011-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-27 20:51]
.
2011-08-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1292428093-484061587-839522115-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-01 17:02]
.
2011-09-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1292428093-484061587-839522115-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-01 17:02]
.
2011-09-05 c:\windows\Tasks\SpeedyPC Program Check.job
- c:\program files\SpeedyPC\SpeedyPC.exe [2010-05-19 23:10]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.ntlworld.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
TCP: DhcpNameServer = [removed] [removed]
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game09.zylom.com/activex/zylomgamesplayer.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\6umuci8i.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2384137&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://sport.virginmedia.com/
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar&a=1&search=
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\program files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Ext: Forecastfox: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} - %profile%\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Clipmarks: {e1170235-2845-420c-acc3-42261a29dd46} - %profile%\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
FF - Ext: Adobe DLM (powered by getPlus®): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - %profile%\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - c:\program files\AVG\AVG8\Firefox
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-06 14:38
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1292428093-484061587-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(728)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2011-09-06 14:48:21
ComboFix-quarantined-files.txt 2011-09-06 13:48
ComboFix2.txt 2011-09-01 16:55
ComboFix3.txt 2008-12-31 11:22
.
Pre-Run: 26,246,447,104 bytes free
Post-Run: 26,228,957,184 bytes free
.
- - End Of File - - 669C12D2E4D25DF2808B9122D0CC2CDE

AVG is till finding viruses as listed below

Resident Shield detection
Infection;"Object";"Result";"Detection time";"Object Type";"Process"
Trojan horse Agent3.AGCY;"C:\System Volume Information\_restore{96190446-8936-4027-8FC4-59B8E38CE747}\RP817\A0244834.exe";"Moved to Virus Vault";"06/09/2011, 10:39:31";"file";"C:\WINDOWS\system32\svchost.exe"

These are harmless as they are in system restore,Please go to Start>run and type combofix /uninstall and press enter,this will remove all those entries and clear out system restore.

Also during the runninig of Combo fix I had a 3 warnings from Zone Alarm
1. NIR CMD IP127.0.0.1:port135 (this I allowed)
2. PEV 3XE IP [removed].DNS (this I allowed)
3. PEV 3XE IP [removed].DNS (this time I dissallowed)

These are just Combofix processes.


Also the BlueSOD came up with AIE Lab.Sys (dumping physical memory to disk) But I turned the computer off before the memory dump was completed.

This is new,has this happened before? After uninstalling Combofix run the computer for a day or so and see how it goes then post back here.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI