This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Definitely VERY infected, please help

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My PC has been acting screwey lately. A few weeks ago it wouldnt even start, it would freeze at the screen were Windows was loading up. That happened a few times then it worked fine. But now it's really slow, and I get different types of error messages for Explorer and Firefox. I should note that I have an old PC, so I know it doesnt help, but it does work acceptably… just not lately.
For Firefox I see an error that says: A script on this page may be busy, or it may have stopped responding.
For Explorer its a C++ Runtime Error, that it terminates in an unusual way.
And just today I saw one while using Firefox that was an avira Error. C:/Program Files\Avira\Antivir Desktop\ccwkrlib.dll has been modified or destroyed.
A few days ago I tried running Avira and Superantispyware but both came back clean.
Anyways, here is the OTL log:

OTL logfile created on: 11/10/2011 12:05:27 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

351.48 Mb Total Physical Memory | 182.15 Mb Available Physical Memory | 51.82% Memory free
998.14 Mb Paging File | 652.47 Mb Available in Paging File | 65.37% Paging File free
Paging file location(s): C:\pagefile.sys 572 672 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 53.68 Gb Free Space | 48.02% Space Free | Partition Type: NTFS

Computer Name: OWNER-XUKSZMPNK | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\FireFox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
PRC - C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe (VIA Technologies, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (npf) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (WmXlCore) – C:\WINDOWS\system32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (WmVirHid) – C:\WINDOWS\system32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmFilter) – C:\WINDOWS\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmBEnum) – C:\WINDOWS\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (VIAudio) Vinyl AC'97 Audio Controller (WDM) – C:\WINDOWS\system32\drivers\vinyl97.sys (VIA Technologies, Inc.)
DRV - (videX32) – C:\WINDOWS\System32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (S3Psddr) – C:\WINDOWS\system32\drivers\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (DNINDIS5) – C:\WINDOWS\system32\DNINDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (viaagp1) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (Ptserial) – C:\WINDOWS\system32\drivers\ptserial.sys (PCTEL, INC.)
DRV - (Vpctcom) – C:\WINDOWS\System32\DRIVERS\vpctcom.sys (PCtel, Inc.)
DRV - (Vvoice) – C:\WINDOWS\System32\DRIVERS\vvoice.sys (PCtel, Inc.)
DRV - (Vmodem) – C:\WINDOWS\System32\DRIVERS\vmodem.sys (PCTEL, INC.)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Ask"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p;="
FF - prefs.js..browser.search.order.1: "Ask"
FF - prefs.js..browser.search.selectedEngine: "IMDb"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:III
FF - prefs.js..extensions.enabledItems: {5c8bfb7c-9a54-11dc-8314-0800200c9a66}:3.0.1
FF - prefs.js..keyword.URL: "http://toolbar.ask.com/toolbarv/askRedirect?o=13917&gct;=&gc;=1&q;="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Owner\Application Data\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.709: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.709: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.709: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files\Google\Update\1.2.183.13\npGoogleOneClick8.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.16: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Owner\Application Data\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
FF - HKCU\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/16 10:46:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Components: C:\Program Files\FireFox\components [2011/06/23 00:58:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Plugins: C:\Program Files\FireFox\plugins [2011/07/03 15:25:13 | 000,000,000 | —D | M]

[2008/08/26 20:56:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/11/09 14:47:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions
[2011/04/03 11:39:06 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/08/26 21:31:01 | 000,000,000 | —D | M] (Aero Fox) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}
[2008/08/27 00:58:47 | 000,000,000 | —D | M] (Dallas Cowboys) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\{769d93be-4857-11dc-8314-0800200c9a66}
[2010/03/15 16:14:09 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2009/12/20 18:09:47 | 000,000,000 | —D | M] (Amazon Quick Search) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\{dffa0a29-2400-4d34-b469-efe699ce0115}
[2009/12/20 18:15:45 | 000,000,000 | —D | M] (Amazonbutton+) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\[removed]
[2007/12/08 00:05:49 | 000,000,000 | —D | M] (Xuxen III EDBL) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\[removed]
[2009/04/25 13:46:16 | 000,000,000 | —D | M] (TVU Web Player) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\[removed]
[2011/01/05 15:04:15 | 000,000,000 | —D | M] (vShare) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\vshareus@toolbar
[2008/06/02 00:13:47 | 000,001,193 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\altavista.xml
[2009/12/20 18:18:16 | 000,002,684 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\amazon-search-suggestions.xml
[2011/08/23 20:16:36 | 000,002,333 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\askcom.xml
[2008/08/23 00:27:33 | 000,001,137 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\dictionarycom.xml
[2008/06/02 00:13:48 | 000,002,200 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\gamefaqs.xml
[2008/06/18 23:26:40 | 000,000,908 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\imdb.xml
[2008/04/21 12:09:51 | 000,002,006 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\urban-dictionary.xml
[2008/06/23 21:35:33 | 000,001,108 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\wikipedia-en.xml
[2010/05/29 09:15:10 | 000,001,292 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\wikipedia-es.xml
[2008/08/23 21:51:43 | 000,001,224 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\yahoo-answers.xml
[2010/03/16 10:46:51 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/03/15 17:00:15 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
[2010/07/12 00:02:59 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/03/15 16:59:26 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF

O1 HOSTS File: ([2010/03/14 01:15:05 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No CLSID value found.
O3 - HKLM\..\Toolbar: (att.net Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe (VIA Technologies, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Start WingMan Profiler] C:\PROGRAM FILES\Logitech\GAMING SOFTWARE\LWEMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10e.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: motive.com ([patttbc.att] https in Trusted sites)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} https://pattcw.att.motive.com/wizlet/DSLAct…etInstaller.cab (WebBrowserType Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BC292830-E399-48EB-8B1F-484EE0F8D685}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\vsharechrome - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.dll) - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/01/09 21:40:15 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{0fae7670-8047-11e0-832e-00e04c79f129}\Shell - "" = AutoRun
O33 - MountPoints2\{0fae7670-8047-11e0-832e-00e04c79f129}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{0fae7670-8047-11e0-832e-00e04c79f129}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - ff_vfw.dll File not found
Drivers32: VIDC.FMVC - C:\WINDOWS\System32\fmcodec.DLL (Fox Magic Software)
Drivers32: VIDC.HFYU - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\WINDOWS\System32\I263_32.drv (Intel Corporation)
Drivers32: vidc.I420 - C:\WINDOWS\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\WINDOWS\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: VIDC.X264 - C:\WINDOWS\System32\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/09 13:26:11 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/11/04 12:43:43 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/09 23:41:23 | 000,013,669 | —- | M] () – C:\Documents and Settings\Owner\Desktop\E3.JPG
[2011/11/09 16:15:13 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-796845957-789336058-854245398-1003.job
[2011/11/09 16:15:13 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-796845957-789336058-854245398-1003.job
[2011/11/09 14:36:15 | 000,016,082 | —- | M] () – C:\Documents and Settings\Owner\Desktop\E2.JPG
[2011/11/09 10:26:13 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/08 11:33:45 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{33466F56-B28E-432D-BB34-A90DEADB4A78}.job
[2011/11/07 20:09:58 | 000,472,604 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/07 20:09:58 | 000,084,224 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/07 20:06:09 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2011/11/07 20:05:48 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/07 20:05:43 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/11/04 12:43:35 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/11/03 21:25:37 | 000,020,297 | —- | M] () – C:\Documents and Settings\Owner\Desktop\E1.JPG
[2011/10/24 23:22:38 | 000,089,691 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Klose.jpg
[2011/10/20 09:48:56 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/10/16 03:16:02 | 000,144,424 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/10/16 02:11:09 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/10/14 04:27:40 | 1587,686,488 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Illuminati The Music Industry Exposed [Full Length].avi
[2011/10/11 17:41:01 | 000,000,049 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/09 23:41:21 | 000,013,669 | —- | C] () – C:\Documents and Settings\Owner\Desktop\E3.JPG
[2011/11/07 20:47:55 | 000,016,082 | —- | C] () – C:\Documents and Settings\Owner\Desktop\E2.JPG
[2011/11/03 21:25:36 | 000,020,297 | —- | C] () – C:\Documents and Settings\Owner\Desktop\E1.JPG
[2011/10/24 23:22:34 | 000,089,691 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Klose.jpg
[2011/10/14 01:41:11 | 1587,686,488 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Illuminati The Music Industry Exposed [Full Length].avi
[2011/08/30 10:26:59 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/08/30 10:26:59 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/08/30 10:26:59 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/08/30 10:26:59 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/08/30 10:26:59 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/12/08 18:30:13 | 000,000,037 | —- | C] () – C:\WINDOWS\ULVIO40.INI
[2010/12/08 18:25:49 | 000,000,212 | —- | C] () – C:\WINDOWS\ULead32.ini
[2010/06/29 17:54:37 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2010/03/19 16:39:57 | 008,892,928 | —- | C] () – C:\Documents and Settings\All Users\Application Data\atscie.msi
[2010/02/10 03:12:21 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/12/05 17:34:46 | 000,027,480 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/11/16 10:33:38 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/06/25 20:18:49 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2009/06/25 20:03:31 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2009/06/07 05:27:20 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\vbzlib1.dll
[2009/02/12 21:36:00 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2009/02/12 21:35:50 | 002,041,363 | —- | C] () – C:\WINDOWS\System32\x264vfw.dll
[2009/02/12 21:35:48 | 000,755,027 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/02/12 21:35:48 | 000,159,839 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/11/13 03:20:33 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2008/07/29 18:17:48 | 000,001,160 | —- | C] () – C:\WINDOWS\mozver.dat
[2008/07/21 16:19:55 | 000,112,128 | —- | C] () – C:\WINDOWS\audiow32.dll
[2008/03/04 17:52:34 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\libcurl.dll
[2008/01/24 19:27:24 | 000,421,888 | —- | C] () – C:\WINDOWS\System32\STLibWrapper.dll
[2007/10/31 08:39:54 | 000,059,904 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2007/05/17 12:58:10 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\libexpatw.dll
[2007/02/07 15:14:58 | 000,001,359 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/02/05 10:11:50 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2006/12/18 23:12:42 | 000,054,398 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/12/12 16:49:07 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb6334.dat
[2006/12/12 16:49:05 | 000,009,216 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb8467.dat
[2006/12/12 16:49:05 | 000,000,049 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb41.dat
[2006/12/12 16:48:57 | 000,000,234 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/12/12 16:48:52 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb5436.dat
[2006/12/12 16:48:51 | 000,020,480 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb4827.dat
[2006/12/12 16:48:50 | 000,000,337 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb1942.dat
[2006/12/12 16:48:50 | 000,000,023 | —- | C] () – C:\Documents and Settings\Owner\Application Data\inifile41.ini
[2006/11/26 01:24:03 | 000,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2006/11/23 16:15:53 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/11/22 18:27:08 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2006/11/22 12:18:37 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2006/11/21 22:58:03 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/11/21 22:47:06 | 000,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/11/21 22:47:00 | 000,151,552 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/11/21 20:17:40 | 000,001,536 | —- | C] () – C:\WINDOWS\System32\TrueSoft.dat
[2006/11/21 20:17:36 | 000,000,456 | R— | C] () – C:\WINDOWS\System32\pthsp.dat
[2006/11/21 20:16:49 | 000,173,056 | —- | C] () – C:\WINDOWS\System32\pctspk.exe
[2006/11/21 00:36:28 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/11/20 23:24:39 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\AegisI5.exe
[2006/11/20 23:12:11 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/11/20 23:05:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/11/20 16:58:54 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/11/20 16:57:24 | 000,144,424 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/09/24 12:37:00 | 000,169,472 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2006/08/16 08:47:08 | 000,000,114 | —- | C] () – C:\WINDOWS\PART0100.DAT
[2002/08/29 01:57:58 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2001/08/23 06:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 06:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 06:00:00 | 000,472,604 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 06:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 06:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 06:00:00 | 000,084,224 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 06:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 06:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 06:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 06:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2009/05/15 21:50:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T;
[2009/06/07 12:25:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATTToolbar
[2011/09/08 01:36:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATTYToolbar
[2001/01/09 18:53:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Geek Squad
[2006/11/23 19:45:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kazaa Lite
[2010/03/09 17:49:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2007/08/24 12:53:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\show itch idol that
[2010/04/18 12:13:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/20 12:07:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/17 09:55:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/25 00:09:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/04/18 12:27:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AnvSoft
[2009/05/15 21:51:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AT&T;
[2009/06/07 12:20:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ATTToolbar
[2010/06/24 07:00:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Aura4You
[2010/07/26 21:24:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\avidemux
[2010/04/18 12:19:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Clone2Go Video Converter Professional
[2009/09/12 15:49:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FMZilla
[2010/06/29 16:55:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FreeVideoConverter
[2010/12/06 23:08:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HamsterSoft
[2010/08/09 16:51:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\licenses
[2010/02/25 17:59:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Panda Security
[2010/08/09 16:54:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCMM2009
[2010/08/09 16:50:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCMM2010
[2009/06/25 20:19:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Samsung
[2011/01/05 15:05:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\vShare
[2009/06/14 10:36:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WinPatrol
[2011/11/07 20:06:09 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job
[2011/11/08 11:33:45 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{33466F56-B28E-432D-BB34-A90DEADB4A78}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2001/01/09 18:47:18 | 000,020,156 | —- | M] () – C:\aaw7boot.log
[2001/01/09 21:40:15 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/08/30 09:15:04 | 000,000,282 | -HS- | M] () – C:\boot.ini
[2011/08/30 10:50:40 | 000,008,933 | —- | M] () – C:\ComboFix.txt
[2001/01/09 21:40:15 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2001/01/09 21:40:15 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2001/01/09 21:40:15 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2001/01/09 21:40:15 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2001/01/09 21:40:15 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/11/08 13:28:41 | 704,643,072 | -HS- | M] () – C:\pagefile.sys
[2011/08/30 10:14:17 | 000,000,359 | —- | M] () – C:\rkill.log
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2001/01/09 21:40:15 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2001/01/09 21:40:16 | 000,000,280 | -H– | M] () – C:\sqmdata16.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2010/05/10 09:28:14 | 045,881,127 | —- | M] () – C:\t25g

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/11/20 23:08:24 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2010/03/19 22:33:35 | 000,001,754 | -H– | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/20 16:56:08 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2006/11/20 16:56:08 | 000,626,688 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2006/11/20 16:56:08 | 000,405,504 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/05/30 13:18:56 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/05/30 15:34:10 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/11/20 23:15:56 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/11/04 12:43:35 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-10-20 05:22:59

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7578EF04

< End of report >
————-
That's it I guess… thank you very much for any help.
Hi,

Please do the following:


Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.



NEXT



Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log
Hi CatByte, thank you so much for your help. Here are the logs you asked for.

________________________________________________________________________________
_____
________________________________________________________________________________
_____
________________________________________________________________________________
_____

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-11-13 11:36:57
—————————–
11:36:57.886 OS Version: Windows 5.1.2600 Service Pack 3
11:36:57.886 Number of processors: 1 586 0xA
11:36:57.896 ComputerName: OWNER-XUKSZMPNK UserName: Owner
11:36:59.749 Initialize success
11:42:01.363 AVAST engine defs: 11111301
11:42:32.978 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
11:42:32.978 Disk 0 Vendor: ST3120814A 3.AAJ Size: 114473MB BusType: 3
11:42:35.091 Disk 0 MBR read successfully
11:42:35.091 Disk 0 MBR scan
11:42:35.422 Disk 0 Windows XP default MBR code
11:42:35.452 Disk 0 scanning sectors +234420480
11:42:35.772 Disk 0 scanning C:\WINDOWS\system32\drivers
11:43:27.657 Service scanning
11:43:30.771 Modules scanning
11:43:38.492 Disk 0 trace - called modules:
11:43:38.522 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys videX32.sys PCIIDEX.SYS
11:43:38.532 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82b74030]
11:43:38.532 3 CLASSPNP.SYS[f76c9fd7] -> nt!IofCallDriver -> \Device\00000065[0x82b99188]
11:43:38.582 5 ACPI.sys[f7640620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x82b992a0]
11:43:40.235 AVAST engine scan C:\WINDOWS
11:44:23.287 AVAST engine scan C:\WINDOWS\system32
11:52:56.895 AVAST engine scan C:\WINDOWS\system32\drivers
11:53:45.615 AVAST engine scan C:\Documents and Settings\Owner
12:50:47.055 AVAST engine scan C:\Documents and Settings\All Users
12:52:30.304 Scan finished successfully
13:13:00.472 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat"
13:13:00.553 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"

________________________________________________________________________________
__________
________________________________________________________________________________
__________
________________________________________________________________________________
__________


All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{043C5167-00BB-4324-AF7E-62013FAEDACF} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{043C5167-00BB-4324-AF7E-62013FAEDACF}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Owner\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Owner\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User
->Flash cache emptied: 41620 bytes

User: LocalService
->Flash cache emptied: 5928 bytes

User: NetworkService
->Flash cache emptied: 22919 bytes

User: Owner
->Flash cache emptied: 189267 bytes

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 65536 bytes
->Temporary Internet Files folder emptied: 258492 bytes
->FireFox cache emptied: 2514920 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 821542 bytes
->Flash cache emptied: 0 bytes

User: Owner
->Temp folder emptied: 58570437 bytes
->Temporary Internet Files folder emptied: 800961456 bytes
->Java cache emptied: 309456 bytes
->FireFox cache emptied: 76771781 bytes
->Apple Safari cache emptied: 1068032 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1228999 bytes
%systemroot%\System32 .tmp files removed: 12075025 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 19953795 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 13561526 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 321300 bytes

Total Files Cleaned = 943.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 11132011_131623

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hey again, here is the combofix log:

ComboFix 11-11-13.03 - Owner 11/13/2011 16:16:47.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.351.25 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Owner\My Documents\~WRL0005.tmp
c:\documents and settings\Owner\My Documents\~WRL1309.tmp
c:\documents and settings\Owner\My Documents\~WRL3239.tmp
c:\documents and settings\Owner\My Documents\~WRL3536.tmp
c:\documents and settings\Owner\Start Menu\Internet Explorer.lnk
c:\windows\help\wmplayer.bak
.
.
((((((((((((((((((((((((( Files Created from 2011-10-13 to 2011-11-13 )))))))))))))))))))))))))))))))
.
.
2011-11-13 19:16 . 2011-11-13 19:16 ——– d—–w- C:\_OTL
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-13 17:32 . 2011-06-23 16:11 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22 . 2006-02-27 19:31 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2002-08-29 07:40 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 16:41 . 2008-07-30 00:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 16:41 . 2001-08-23 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 16:41 . 2001-08-23 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20 . 2002-08-29 06:14 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-08-22 23:48 . 2006-06-23 17:33 916480 —-a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2002-08-29 07:41 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-08-22 23:48 . 2002-08-29 07:41 43520 ——w- c:\windows\system32\licmgr10.dll
2011-08-22 11:56 . 2004-08-04 05:59 385024 ——w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2002-08-29 06:01 138496 —-a-w- c:\windows\system32\drivers\afd.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-30_16.44.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-13 19:28 . 2011-11-13 19:28 16384 c:\windows\temp\Perflib_Perfdata_7a0.dat
+ 2007-01-29 08:58 . 2011-07-08 13:49 46080 c:\windows\system32\tzchange.exe
- 2007-01-29 08:58 . 2010-11-03 13:12 46080 c:\windows\system32\tzchange.exe
+ 2001-08-23 12:00 . 2011-11-08 02:09 84224 c:\windows\system32\perfc009.dat
+ 2002-08-29 07:41 . 2011-08-22 23:48 66560 c:\windows\system32\mshtmled.dll
- 2002-08-29 07:41 . 2011-06-23 18:36 66560 c:\windows\system32\mshtmled.dll
- 2009-03-08 10:31 . 2011-06-23 18:36 55296 c:\windows\system32\msfeedsbs.dll
+ 2009-03-08 10:31 . 2011-08-22 23:48 55296 c:\windows\system32\msfeedsbs.dll
- 2001-08-23 12:00 . 2011-06-23 18:36 25600 c:\windows\system32\jsproxy.dll
+ 2001-08-23 12:00 . 2011-08-22 23:48 25600 c:\windows\system32\jsproxy.dll
+ 2010-02-20 15:02 . 2011-08-22 23:48 12800 c:\windows\system32\dllcache\xpshims.dll
- 2010-02-20 15:02 . 2011-06-23 18:36 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2001-08-23 12:00 . 2011-09-26 16:41 20480 c:\windows\system32\dllcache\oleaccrc.dll
- 2010-09-09 14:16 . 2011-06-23 18:36 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2010-09-09 14:16 . 2011-08-22 23:48 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2010-02-20 15:02 . 2011-08-22 23:48 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2010-02-20 15:02 . 2011-06-23 18:36 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2002-08-29 07:41 . 2011-08-22 23:48 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2002-08-29 07:41 . 2011-06-23 18:36 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2001-08-23 12:00 . 2011-06-23 18:36 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2001-08-23 12:00 . 2011-08-22 23:48 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2010-09-23 21:55 . 2010-09-23 21:55 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2011-07-08 19:00 . 2011-07-08 19:00 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2011-07-07 17:04 . 2011-07-07 17:04 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2010-09-23 08:26 . 2010-09-23 08:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2010-09-23 08:26 . 2010-09-23 08:26 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2011-07-07 17:04 . 2011-07-07 17:04 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2010-09-23 08:26 . 2010-09-23 08:26 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2011-07-07 17:03 . 2011-07-07 17:03 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2010-09-23 09:17 . 2010-09-23 09:17 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2011-07-07 18:09 . 2011-07-07 18:09 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2011-07-07 18:09 . 2011-07-07 18:09 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
- 2010-09-23 09:17 . 2010-09-23 09:17 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2011-09-18 08:13 . 2011-09-18 08:13 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2011-06-16 03:23 . 2011-06-16 03:23 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2011-10-16 08:08 . 2011-06-23 18:36 12800 c:\windows\ie8updates\KB2586448-IE8\xpshims.dll
+ 2011-10-16 08:08 . 2011-06-23 18:36 66560 c:\windows\ie8updates\KB2586448-IE8\mshtmled.dll
+ 2011-10-16 08:08 . 2011-06-23 18:36 55296 c:\windows\ie8updates\KB2586448-IE8\msfeedsbs.dll
+ 2011-10-16 08:08 . 2011-06-23 18:36 43520 c:\windows\ie8updates\KB2586448-IE8\licmgr10.dll
+ 2011-10-16 08:08 . 2011-06-23 18:36 25600 c:\windows\ie8updates\KB2586448-IE8\jsproxy.dll
+ 2011-10-20 15:44 . 2011-10-20 15:44 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_fc2c20ca\System.Drawing.Design.dll
+ 2011-10-20 05:23 . 2011-10-20 05:23 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_9f24c7d0\CustomMarshalers.dll
+ 2011-10-16 08:52 . 2011-10-16 08:52 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\888b745ca99d39692c2e9af222e5eae8\UIAutomationProvider.ni.dll
+ 2011-10-16 09:09 . 2011-10-16 09:09 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\6c334564da041df8fb75415f2d503224\System.Windows.Presentation.ni.dll
+ 2011-10-16 09:08 . 2011-10-16 09:08 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\a54a122f1070ab71931dd9679ddd8e90\System.Web.DynamicData.Design.ni.dll
+ 2011-10-16 09:04 . 2011-10-16 09:04 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\ac92806d5bd508eb25f1b4b73a36b101\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-10-16 09:04 . 2011-10-16 09:04 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\e6a9cd66d11a21776dbf425e8e28099c\System.AddIn.Contract.ni.dll
+ 2011-10-16 08:35 . 2011-10-16 08:35 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\66873b557d5c7013e4c630361473b0c2\PresentationFontCache.ni.exe
+ 2011-10-16 08:34 . 2011-10-16 08:34 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5b30652a7b802199984f93b5e414260f\PresentationCFFRasterizer.ni.dll
+ 2011-10-16 09:07 . 2011-10-16 09:07 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\eaa8d72317e5b8047e413939cc71ffba\Microsoft.Vsa.ni.dll
+ 2011-10-16 09:03 . 2011-10-16 09:03 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\aefe683674c97a998f4e908c1a7ee7c6\Microsoft.Build.Framework.ni.dll
+ 2011-10-16 09:04 . 2011-10-16 09:04 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\845eef4d09f28da6ee05d99f93c90f6e\Microsoft.Build.Framework.ni.dll
+ 2011-10-16 09:03 . 2011-10-16 09:03 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\ab7ce2d94ca725c3889a4e3c1ee88ece\dfsvc.ni.exe
+ 2011-10-16 09:01 . 2011-10-16 09:01 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2011-10-16 08:28 . 2011-10-16 08:28 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-10-16 08:28 . 2011-10-16 08:28 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2010-12-04 20:14 . 2010-12-04 20:14 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-10-20 05:22 . 2011-10-20 05:22 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-09-11 05:31 . 2010-11-03 13:12 46080 c:\windows\$NtUninstallKB2570791$\tzchange.exe
+ 2011-09-11 05:31 . 2011-07-09 00:32 16896 c:\windows\$NtUninstallKB2570791$\spuninst\tzchange.dll
+ 2011-09-18 08:13 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2616676\update\spcustom.dll
+ 2011-09-18 08:13 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2616676\spmsg.dll
+ 2011-09-11 05:30 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2607712\update\spcustom.dll
+ 2011-09-11 05:30 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2607712\spmsg.dll
+ 2011-09-18 08:04 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2570947\update\spcustom.dll
+ 2011-09-18 08:04 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2570947\spmsg.dll
+ 2011-10-16 08:10 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2567053\update\spcustom.dll
+ 2011-10-16 08:10 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2567053\spmsg.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2011-10-16 08:28 . 2011-10-16 08:28 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2011-08-14 08:24 . 2011-08-14 08:24 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2002-08-29 07:41 . 2011-06-23 18:36 105984 c:\windows\system32\url.dll
+ 2002-08-29 07:41 . 2011-08-22 23:48 105984 c:\windows\system32\url.dll
+ 2001-08-23 12:00 . 2011-11-08 02:09 472604 c:\windows\system32\perfh009.dat
+ 2001-08-23 12:00 . 2011-08-22 23:48 206848 c:\windows\system32\occache.dll
- 2001-08-23 12:00 . 2011-06-23 18:36 206848 c:\windows\system32\occache.dll
- 2002-08-29 07:41 . 2011-06-23 18:36 611840 c:\windows\system32\mstime.dll
+ 2002-08-29 07:41 . 2011-08-22 23:48 611840 c:\windows\system32\mstime.dll
- 2009-03-08 10:32 . 2011-06-23 18:36 602112 c:\windows\system32\msfeeds.dll
+ 2009-03-08 10:32 . 2011-08-22 23:48 602112 c:\windows\system32\msfeeds.dll
+ 2011-11-13 17:32 . 2011-11-13 17:32 247968 c:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
+ 2011-11-13 17:32 . 2011-11-13 17:32 335520 c:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.dll
+ 2011-10-20 15:48 . 2011-10-20 15:48 247968 c:\windows\system32\Macromed\Flash\FlashUtil11c_Plugin.exe
- 2002-08-29 07:40 . 2011-06-23 18:36 184320 c:\windows\system32\iepeers.dll
+ 2002-08-29 07:40 . 2011-08-22 23:48 184320 c:\windows\system32\iepeers.dll
- 2002-08-29 07:40 . 2011-06-23 18:36 387584 c:\windows\system32\iedkcs32.dll
+ 2002-08-29 07:40 . 2011-08-22 23:48 387584 c:\windows\system32\iedkcs32.dll
+ 2002-08-29 07:41 . 2011-08-22 11:56 174080 c:\windows\system32\ie4uinit.exe
- 2006-11-20 22:57 . 2011-07-16 15:21 144424 c:\windows\system32\FNTCACHE.DAT
+ 2006-11-20 22:57 . 2011-10-16 09:16 144424 c:\windows\system32\FNTCACHE.DAT
+ 2008-04-21 06:44 . 2011-08-22 23:48 916480 c:\windows\system32\dllcache\wininet.dll
- 2008-04-21 06:44 . 2011-06-23 18:36 916480 c:\windows\system32\dllcache\wininet.dll
- 2009-03-08 10:34 . 2011-06-23 18:36 105984 c:\windows\system32\dllcache\url.dll
+ 2009-03-08 10:34 . 2011-08-22 23:48 105984 c:\windows\system32\dllcache\url.dll
+ 2001-08-23 12:00 . 2011-09-26 16:41 220160 c:\windows\system32\dllcache\oleacc.dll
- 2009-03-08 10:34 . 2011-06-23 18:36 206848 c:\windows\system32\dllcache\occache.dll
+ 2009-03-08 10:34 . 2011-08-22 23:48 206848 c:\windows\system32\dllcache\occache.dll
- 2002-08-29 07:41 . 2011-06-23 18:36 611840 c:\windows\system32\dllcache\mstime.dll
+ 2002-08-29 07:41 . 2011-08-22 23:48 611840 c:\windows\system32\dllcache\mstime.dll
- 2010-02-20 15:02 . 2011-06-23 18:36 602112 c:\windows\system32\dllcache\msfeeds.dll
+ 2010-02-20 15:02 . 2011-08-22 23:48 602112 c:\windows\system32\dllcache\msfeeds.dll
+ 2006-02-27 19:31 . 2011-10-10 14:22 692736 c:\windows\system32\dllcache\inetcomm.dll
- 2006-02-27 19:31 . 2011-05-02 15:31 692736 c:\windows\system32\dllcache\inetcomm.dll
+ 2010-02-20 15:02 . 2011-08-22 23:48 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2010-02-20 15:02 . 2011-06-23 18:36 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2010-02-26 05:43 . 2011-08-22 23:48 184320 c:\windows\system32\dllcache\iepeers.dll
- 2010-02-26 05:43 . 2011-06-23 18:36 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2011-01-17 23:34 . 2011-08-22 23:48 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2011-01-17 23:34 . 2011-06-23 18:36 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2002-08-29 07:40 . 2011-08-22 23:48 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2002-08-29 07:40 . 2011-06-23 18:36 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2002-08-29 07:41 . 2011-08-22 11:56 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2011-09-03 10:17 . 2011-09-28 07:06 599040 c:\windows\system32\dllcache\crypt32.dll
- 2002-08-29 06:01 . 2011-02-16 13:22 138496 c:\windows\system32\dllcache\afd.sys
+ 2002-08-29 06:01 . 2011-08-17 13:49 138496 c:\windows\system32\dllcache\afd.sys
- 2011-03-25 11:15 . 2011-03-25 11:15 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2011-07-07 10:18 . 2011-07-07 10:18 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2011-07-07 10:18 . 2011-07-07 10:18 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
- 2011-03-25 11:15 . 2011-03-25 11:15 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2011-07-07 17:04 . 2011-07-07 17:04 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2010-09-23 08:26 . 2010-09-23 08:26 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2011-07-07 17:01 . 2011-07-07 17:01 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2010-09-23 08:25 . 2010-09-23 08:25 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2011-07-07 18:09 . 2011-07-07 18:09 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
- 2010-09-23 09:17 . 2010-09-23 09:17 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-10-16 08:08 . 2011-06-23 18:36 916480 c:\windows\ie8updates\KB2586448-IE8\wininet.dll
+ 2011-10-16 08:08 . 2011-06-23 18:36 105984 c:\windows\ie8updates\KB2586448-IE8\url.dll
+ 2011-10-16 08:08 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2586448-IE8\spuninst\updspapi.dll
+ 2011-10-16 08:08 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2586448-IE8\spuninst\spuninst.exe
+ 2011-10-16 08:08 . 2011-06-23 18:36 206848 c:\windows\ie8updates\KB2586448-IE8\occache.dll
+ 2011-10-16 08:08 . 2011-06-23 18:36 611840 c:\windows\ie8updates\KB2586448-IE8\mstime.dll
+ 2011-10-16 08:08 . 2011-06-23 18:36 602112 c:\windows\ie8updates\KB2586448-IE8\msfeeds.dll
+ 2011-10-16 08:08 . 2011-06-23 18:36 247808 c:\windows\ie8updates\KB2586448-IE8\ieproxy.dll
+ 2011-10-16 08:08 . 2011-06-23 18:36 184320 c:\windows\ie8updates\KB2586448-IE8\iepeers.dll
+ 2011-10-16 08:08 . 2011-06-23 18:36 743424 c:\windows\ie8updates\KB2586448-IE8\iedvtool.dll
+ 2011-10-16 08:08 . 2011-06-23 18:36 387584 c:\windows\ie8updates\KB2586448-IE8\iedkcs32.dll
+ 2011-10-16 08:08 . 2011-06-23 12:05 173568 c:\windows\ie8updates\KB2586448-IE8\ie4uinit.exe
+ 2011-10-20 15:49 . 2011-10-20 15:49 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_c5a8b71e\System.Drawing.dll
+ 2011-10-20 15:55 . 2011-10-20 15:55 192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_f36736ec\System.Drawing.Design.dll
+ 2011-10-20 15:55 . 2011-10-20 15:55 118784 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_8b108b20\CustomMarshalers.dll
+ 2011-10-16 09:03 . 2011-10-16 09:03 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\c8627df7adb416722d8e0f05c57fef6b\WsatConfig.ni.exe
+ 2011-10-16 08:52 . 2011-10-16 08:52 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\a2c1bb3c5b1447b398e72c56091ca571\WindowsFormsIntegration.ni.dll
+ 2011-10-16 08:52 . 2011-10-16 08:52 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\f102afdffdbe2565bcedb7fa0626b865\UIAutomationTypes.ni.dll
+ 2011-10-16 08:51 . 2011-10-16 08:51 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\ba55240b7753047f8d1b03ef473bf74e\UIAutomationClient.ni.dll
+ 2011-10-16 09:10 . 2011-10-16 09:10 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\566b2e11e7f3f6d973b17b86cf42f9bc\System.Xml.Linq.ni.dll
+ 2011-10-16 09:08 . 2011-10-16 09:08 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\3533d614ebecd4344efbee619dd11a74\System.Web.Routing.ni.dll
+ 2011-10-16 09:09 . 2011-10-16 09:09 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\018b6e48c32d5b5d78086998e3505f1c\System.Web.RegularExpressions.ni.dll
+ 2011-10-16 09:09 . 2011-10-16 09:09 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\d93514a764a83b18f6f3547b59cc8ae9\System.Web.Extensions.Design.ni.dll
+ 2011-10-16 09:09 . 2011-10-16 09:09 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\93b5d1b77a74b76ac73cbf51ec871c01\System.Web.Entity.ni.dll
+ 2011-10-16 09:09 . 2011-10-16 09:09 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\d06a7d5872bbe85795f947f6c75d38c6\System.Web.Entity.Design.ni.dll
+ 2011-10-16 09:08 . 2011-10-16 09:08 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\ad0851438a18bf730d974c9b2f5f776a\System.Web.DynamicData.ni.dll
+ 2011-10-16 09:08 . 2011-10-16 09:08 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\734ab0ea87d7dfd5c583eea535c05878\System.Web.Abstractions.ni.dll
+ 2011-10-16 09:08 . 2011-10-16 09:08 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\8efcd633af87989355382b5039f1b7df\System.Transactions.ni.dll
+ 2011-10-16 09:08 . 2011-10-16 09:08 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll
+ 2011-10-16 09:03 . 2011-10-16 09:03 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\36c12de583ee81e9c99acb72b09d77ac\System.Security.ni.dll
+ 2011-10-16 09:07 . 2011-10-16 09:07 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\81096bfe85eb0da5f05e8a127ffa43b2\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2011-10-16 09:07 . 2011-10-16 09:07 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\b2a84980f206431821d85d5155d5916f\System.Net.ni.dll
+ 2011-10-16 09:07 . 2011-10-16 09:07 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\90b90e700e59d73d6d692cf74e1ba16e\System.Management.ni.dll
+ 2011-10-16 09:07 . 2011-10-16 09:07 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\f36eded354122da9555a6c7cdbdb5431\System.Management.Instrumentation.ni.dll
+ 2011-10-16 09:01 . 2011-10-16 09:01 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\20a77c41ee12362d303fb2574fcd5a24\System.IO.Log.ni.dll
+ 2011-10-16 09:01 . 2011-10-16 09:01 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\41c3a2fcffc58b20023c7d54e57ea956\System.IdentityModel.Selectors.ni.dll
+ 2011-10-16 09:07 . 2011-10-16 09:07 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.Wrapper.dll
+ 2011-10-16 09:07 . 2011-10-16 09:07 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.ni.dll
+ 2011-10-16 08:43 . 2011-10-16 08:43 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\896eca06e2d9377b2dc4fad56ce49b07\System.Drawing.Design.ni.dll
+ 2011-10-16 09:07 . 2011-10-16 09:07 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\33e9b0c368c31ef37a2ec7b5a181044b\System.DirectoryServices.Protocols.ni.dll
+ 2011-10-16 09:07 . 2011-10-16 09:07 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\11cdd1c0d65428cd3505d3813d36638c\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-10-16 09:06 . 2011-10-16 09:06 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\e5ada332a9bc3c982e6aede6ba354196\System.Data.Services.Client.ni.dll
+ 2011-10-16 09:06 . 2011-10-16 09:06 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\3f179f373f31817a914b639a56cc0497\System.Data.Services.Design.ni.dll
+ 2011-10-16 09:06 . 2011-10-16 09:06 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\fee1a48b769a8c4beb335ee5ce006091\System.Data.Entity.Design.ni.dll
+ 2011-10-16 09:04 . 2011-10-16 09:04 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\b9d9ff5d03e90ede1116794f2c7dd6da\System.Data.DataSetExtensions.ni.dll
+ 2011-10-16 09:03 . 2011-10-16 09:03 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll
+ 2011-10-16 09:07 . 2011-10-16 09:07 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\29d7091f6eab0ec61c4eb625ed221b73\System.Configuration.Install.ni.dll
+ 2011-10-16 09:04 . 2011-10-16 09:04 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\3048737e9e3bf5173121a084337256bc\System.AddIn.ni.dll
+ 2011-10-16 09:03 . 2011-10-16 09:03 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\6e45cf503f025c5fe814ea7e52f62a78\SMSvcHost.ni.exe
+ 2011-10-16 09:03 . 2011-10-16 09:03 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\474a341340f687bcbd7777f2820a8c7a\SMDiagnostics.ni.dll
+ 2011-10-16 09:03 . 2011-10-16 09:03 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\f2df1ca28301bfe7e1d52b86c8394217\ServiceModelReg.ni.exe
+ 2011-10-16 08:37 . 2011-10-16 08:37 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c2ebcc8d60422f224b4088f3d7a2ac1f\PresentationFramework.Luna.ni.dll
+ 2011-10-16 08:37 . 2011-10-16 08:37 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\94cfc00ad448575bfb0e67c53b514cd5\PresentationFramework.Aero.ni.dll
+ 2011-10-16 08:37 . 2011-10-16 08:37 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\478d57d96f3d8d5fc15c7ac635a4a6a1\PresentationFramework.Classic.ni.dll
+ 2011-10-16 08:37 . 2011-10-16 08:37 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\23c5852ff8ed973ff9b63ce9ba7f91f0\PresentationFramework.Royale.ni.dll
+ 2011-10-16 09:03 . 2011-10-16 09:03 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\04595f414c49cf2a65b349648ba23e62\MSBuild.ni.exe
+ 2011-10-16 09:03 . 2011-10-16 09:03 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\4cbd7ed9fbf9f1b3cbdf23906cc0f5a3\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-10-16 09:04 . 2011-10-16 09:04 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\ff6d4892775fd1f9b137f7c92ea453f2\Microsoft.Build.Utilities.ni.dll
+ 2011-10-16 09:04 . 2011-10-16 09:04 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\47ff0720cb80a0fc0bbd15ddc3d12adc\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2011-10-16 09:04 . 2011-10-16 09:04 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\da112c5757e3c68d6369b6aa46cc9682\Microsoft.Build.Engine.ni.dll
+ 2011-10-16 09:04 . 2011-10-16 09:04 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\dc278e1123086ae32fec8f7e9751db14\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2011-10-16 09:04 . 2011-10-16 09:04 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\3e6deccf191ab943d3a0812a38ab5c97\CustomMarshalers.ni.dll
+ 2011-10-16 09:03 . 2011-10-16 09:03 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\4e68d5df30b197ff72c75f1c3c24b949\ComSvcConfig.ni.exe
+ 2011-10-16 09:01 . 2011-10-16 09:01 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\e1bcee92f5af50d560d577c0a99ea3bd\AspNetMMCExt.ni.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2011-10-16 08:28 . 2011-10-16 08:28 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2011-10-16 08:28 . 2011-10-16 08:28 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2011-10-16 08:28 . 2011-10-16 08:28 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2011-10-16 08:28 . 2011-10-16 08:28 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2011-10-16 08:28 . 2011-10-16 08:28 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2011-10-16 08:28 . 2011-10-16 08:28 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-10-16 08:28 . 2011-10-16 08:28 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-09-18 08:13 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2616676$\spuninst\updspapi.dll
+ 2011-09-18 08:13 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2616676$\spuninst\spuninst.exe
+ 2011-09-18 08:13 . 2011-09-03 10:17 599040 c:\windows\$NtUninstallKB2616676$\crypt32.dll
+ 2011-09-11 05:30 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2607712$\spuninst\updspapi.dll
+ 2011-09-11 05:30 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2607712$\spuninst\spuninst.exe
+ 2011-09-11 05:30 . 2008-04-14 00:11 599040 c:\windows\$NtUninstallKB2607712$\crypt32.dll
+ 2011-09-18 08:04 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2570947$\spuninst\updspapi.dll
+ 2011-09-18 08:04 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2570947$\spuninst\spuninst.exe
+ 2011-09-11 05:31 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2570791$\spuninst\updspapi.dll
+ 2011-09-11 05:31 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2570791$\spuninst\spuninst.exe
+ 2011-09-18 08:13 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2616676\update\updspapi.dll
+ 2011-09-18 08:13 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2616676\update\update.exe
+ 2011-09-18 08:13 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2616676\spuninst.exe
+ 2011-09-09 09:11 . 2011-09-09 09:11 599552 c:\windows\$hf_mig$\KB2616676\SP3QFE\crypt32.dll
+ 2011-09-11 05:30 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2607712\update\updspapi.dll
+ 2011-09-11 05:30 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2607712\update\update.exe
+ 2011-09-11 05:30 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2607712\spuninst.exe
+ 2011-09-03 10:16 . 2011-09-03 10:16 599552 c:\windows\$hf_mig$\KB2607712\SP3QFE\crypt32.dll
+ 2011-09-18 08:04 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2570947\update\updspapi.dll
+ 2011-09-18 08:04 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2570947\update\update.exe
+ 2011-09-18 08:04 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2570947\spuninst.exe
+ 2011-10-16 08:10 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2567053\update\updspapi.dll
+ 2011-10-16 08:10 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2567053\update\update.exe
+ 2011-10-16 08:10 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2567053\spuninst.exe
- 2006-08-31 02:42 . 2011-06-23 18:36 1212416 c:\windows\system32\urlmon.dll
+ 2006-08-31 02:42 . 2011-08-22 23:48 1212416 c:\windows\system32\urlmon.dll
+ 2007-03-27 02:24 . 2011-09-30 20:35 1614404 c:\windows\system32\Restore\rstrlog.dat
+ 2002-08-29 07:41 . 2011-10-03 08:35 5971456 c:\windows\system32\mshtml.dll
+ 2011-10-20 15:48 . 2011-10-20 15:48 8522400 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2009-03-08 10:32 . 2011-08-22 23:48 2000384 c:\windows\system32\iertutil.dll
+ 2008-10-14 21:11 . 2011-09-06 13:20 1858944 c:\windows\system32\dllcache\win32k.sys
- 2008-10-14 21:11 . 2011-06-02 14:02 1858944 c:\windows\system32\dllcache\win32k.sys
+ 2008-06-26 08:15 . 2011-08-22 23:48 1212416 c:\windows\system32\dllcache\urlmon.dll
- 2008-06-26 08:15 . 2011-06-23 18:36 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-21 06:44 . 2011-10-03 08:35 5971456 c:\windows\system32\dllcache\mshtml.dll
+ 2010-02-20 15:02 . 2011-08-22 23:48 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2011-07-07 10:18 . 2011-07-07 10:18 5912400 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
- 2011-03-25 11:15 . 2011-03-25 11:15 5912400 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2011-07-07 10:18 . 2011-07-07 10:18 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
- 2011-03-25 11:15 . 2011-03-25 11:15 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
- 2010-09-23 21:55 . 2010-09-23 21:55 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2011-07-08 18:59 . 2011-07-08 18:59 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2011-07-08 18:59 . 2011-07-08 18:59 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2010-09-23 21:55 . 2010-09-23 21:55 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2011-07-07 17:02 . 2011-07-07 17:02 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
- 2010-09-23 08:26 . 2010-09-23 08:26 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2011-07-07 17:02 . 2011-07-07 17:02 2527232 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
- 2010-09-23 21:55 . 2010-09-23 21:55 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2011-07-08 18:59 . 2011-07-08 18:59 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2011-08-10 22:43 . 2011-08-10 22:43 3795968 c:\windows\Installer\34c5b68.msp
+ 2011-09-07 02:48 . 2011-09-07 02:48 8181248 c:\windows\Installer\340ae24.msp
+ 2011-07-27 12:39 . 2011-07-27 12:39 9892352 c:\windows\Installer\340ae1c.msp
+ 2009-04-03 23:21 . 2009-04-03 23:21 8543096 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6425\OARTCONV.DLL
+ 2011-10-16 08:08 . 2011-06-23 18:36 1212416 c:\windows\ie8updates\KB2586448-IE8\urlmon.dll
+ 2011-10-16 08:08 . 2011-07-25 15:17 5969920 c:\windows\ie8updates\KB2586448-IE8\mshtml.dll
+ 2011-10-16 08:08 . 2011-06-23 18:36 1991680 c:\windows\ie8updates\KB2586448-IE8\iertutil.dll
+ 2011-10-20 15:52 . 2011-10-20 15:52 4792320 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_6d9f5eaf\System.dll
+ 2011-10-20 05:23 . 2011-10-20 05:23 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_293101e1\System.dll
+ 2011-10-20 15:45 . 2011-10-20 15:45 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_4d10a30f\System.Xml.dll
+ 2011-10-25 16:31 . 2011-10-25 16:31 5513216 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_18c97a0b\System.Xml.dll
+ 2011-10-20 15:44 . 2011-10-20 15:44 3018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_c7ee7238\System.Windows.Forms.dll
+ 2011-10-25 16:30 . 2011-10-25 16:30 7884800 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_5073e4ed\System.Windows.Forms.dll
+ 2011-10-25 16:32 . 2011-10-25 16:32 2244608 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_d320273d\System.Drawing.dll
+ 2011-10-20 15:47 . 2011-10-20 15:47 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_fccb6fde\System.Design.dll
+ 2011-10-25 16:31 . 2011-10-25 16:31 3395584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_0f84c862\System.Design.dll
+ 2011-10-26 22:38 . 2011-10-26 22:38 8908800 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_bbcf8476\mscorlib.dll
+ 2011-10-20 15:50 . 2011-10-20 15:50 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_16c558ce\mscorlib.dll
+ 2011-10-16 08:34 . 2011-10-16 08:34 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1adc4ae51a5ac63e896a1402749ca495\WindowsBase.ni.dll
+ 2011-10-16 08:52 . 2011-10-16 08:52 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\55d4813580b1e5d268ff0564942cee9c\UIAutomationClientsideProviders.ni.dll
+ 2011-10-16 08:33 . 2011-10-16 08:33 7950848 c:\windows\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll
+ 2011-10-16 08:51 . 2011-10-16 08:51 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll
+ 2011-10-16 09:10 . 2011-10-16 09:10 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\17902fdb0e0d3bc8b49bce693415fe7e\System.WorkflowServices.ni.dll
+ 2011-10-16 09:10 . 2011-10-16 09:10 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\f72c5f649951b0403e62bfab6c453e6f\System.Workflow.Runtime.ni.dll
+ 2011-10-16 09:10 . 2011-10-16 09:10 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\0aa4f4174204c93cc5181df4a6b2fb09\System.Workflow.ComponentModel.ni.dll
+ 2011-10-16 09:09 . 2011-10-16 09:09 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\921629dc69a5a895101097c88ae67897\System.Workflow.Activities.ni.dll
+ 2011-10-16 09:09 . 2011-10-16 09:09 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\6303e256d2ac0843c3e4c24172c90544\System.Web.Services.ni.dll
+ 2011-10-16 09:09 . 2011-10-16 09:09 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\f5dac0448a1dbe2687a5df92904d6274\System.Web.Mobile.ni.dll
+ 2011-10-16 09:08 . 2011-10-16 09:08 2405376 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\ccaf6bdd256a9b5079fedadcc8993327\System.Web.Extensions.ni.dll
+ 2011-10-16 08:47 . 2011-10-16 08:47 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\10d7daa3d1e62a0e40587cdc707be93f\System.Speech.ni.dll
+ 2011-10-16 09:07 . 2011-10-16 09:07 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\9ec7da53380a754b4ad97709df0dd7e7\System.ServiceModel.Web.ni.dll
+ 2011-10-16 09:01 . 2011-10-16 09:01 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\afd6134c090faf8c29cd64d4835142b2\System.Runtime.Serialization.ni.dll
+ 2011-10-16 08:44 . 2011-10-16 08:44 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\0f8e14bfdb27645fb1a92ce26f9bf521\System.Printing.ni.dll
+ 2011-10-16 09:01 . 2011-10-16 09:01 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\d14065ede44df8e9b5d6b60c5ddccc69\System.IdentityModel.ni.dll
+ 2011-10-16 08:43 . 2011-10-16 08:43 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll
+ 2011-10-16 09:07 . 2011-10-16 09:07 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\91cd88a803768151c6262853d3454ba7\System.DirectoryServices.ni.dll
+ 2011-10-16 09:07 . 2011-10-16 09:07 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\cc5ac99e8af2738e85cda5525fdd944f\System.Deployment.ni.dll
+ 2011-10-16 08:38 . 2011-10-16 08:38 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\ec323cf1df697cc0a45f67de685db90c\System.Data.ni.dll
+ 2011-10-16 09:03 . 2011-10-16 09:03 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\ef748704f543a8791e23387652d34dfb\System.Data.SqlXml.ni.dll
+ 2011-10-16 09:06 . 2011-10-16 09:06 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\541142d8742e6e88f1e729fafee04e71\System.Data.Services.ni.dll
+ 2011-10-16 08:39 . 2011-10-16 08:39 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\d96a94076acb8e0c5a96a1b2de4b3a7a\System.Data.Linq.ni.dll
+ 2011-10-16 09:06 . 2011-10-16 09:06 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\a3ce22c2a84fdcb008d72d230ee0b2c0\System.Data.Entity.ni.dll
+ 2011-10-16 08:37 . 2011-10-16 08:37 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\d507b9e0e50e453793ee5e01c07a5485\System.Core.ni.dll
+ 2011-10-16 08:37 . 2011-10-16 08:37 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\714e9504255565bd9076fe13628e104a\ReachFramework.ni.dll
+ 2011-10-16 08:37 . 2011-10-16 08:37 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\7dc6ee14234b0686182ced75f7dae990\PresentationUI.ni.dll
+ 2011-10-16 08:34 . 2011-10-16 08:34 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b42ad515bb20ec1f1250c040371c6730\PresentationBuildTasks.ni.dll
+ 2011-10-16 09:04 . 2011-10-16 09:04 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\24331b719aa25ac2b21099e32232840c\Microsoft.VisualBasic.ni.dll
+ 2011-10-16 09:03 . 2011-10-16 09:03 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\ce1ecd602ca089eb13a9b428dc7f0449\Microsoft.Transactions.Bridge.ni.dll
+ 2011-10-16 09:07 . 2011-10-16 09:07 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\8ad32b72258899177c07dc5912b5b748\Microsoft.JScript.ni.dll
+ 2011-10-16 09:04 . 2011-10-16 09:04 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\50e7c5eb58c982dba7b21cd10a69b095\Microsoft.Build.Tasks.ni.dll
+ 2011-10-16 09:04 . 2011-10-16 09:04 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\415cef6abab5bb959f200f6c537bc289\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2011-10-16 09:03 . 2011-10-16 09:03 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\eea7bcc8d356e3f2dcb4f36dfc1c6bc0\Microsoft.Build.Engine.ni.dll
+ 2011-10-16 08:28 . 2011-10-16 08:28 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2011-10-16 08:28 . 2011-10-16 08:28 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2011-08-14 08:25 . 2011-08-14 08:25 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
- 2011-08-14 08:23 . 2011-08-14 08:23 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-10-16 08:27 . 2011-10-16 08:27 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-10-16 08:28 . 2011-10-16 08:28 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2011-08-14 08:24 . 2011-08-14 08:24 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-10-16 08:28 . 2011-10-16 08:28 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-10-20 05:22 . 2011-10-20 05:22 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2010-12-04 20:14 . 2010-12-04 20:14 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2011-10-20 05:22 . 2011-10-20 05:22 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2010-12-04 20:14 . 2010-12-04 20:14 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-09-06 13:25 . 2011-09-06 13:25 1867904 c:\windows\$hf_mig$\KB2567053\SP3QFE\win32k.sys
+ 2006-11-23 00:19 . 2011-11-13 09:05 50295240 c:\windows\system32\MRT.exe
- 2009-03-08 10:39 . 2011-06-23 18:36 11081728 c:\windows\system32\ieframe.dll
+ 2009-03-08 10:39 . 2011-08-23 22:48 11081728 c:\windows\system32\ieframe.dll
- 2010-02-20 15:01 . 2011-06-23 18:36 11081728 c:\windows\system32\dllcache\ieframe.dll
+ 2010-02-20 15:01 . 2011-08-23 22:48 11081728 c:\windows\system32\dllcache\ieframe.dll
+ 2011-07-13 03:49 . 2011-07-13 03:49 11459584 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2572067\M2572067Uninstall.msp
+ 2011-07-12 01:43 . 2011-07-12 01:43 11641344 c:\windows\Installer\b644d6e.msp
+ 2011-07-12 20:50 . 2011-07-12 20:50 17555968 c:\windows\Installer\b536cd9.msp
+ 2011-07-12 20:50 . 2011-07-12 20:50 17555968 c:\windows\Installer\13c268f3.msp
+ 2011-10-16 08:08 . 2011-06-23 18:36 11081728 c:\windows\ie8updates\KB2586448-IE8\ieframe.dll
+ 2011-10-16 08:49 . 2011-10-16 08:49 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll
+ 2011-10-16 09:08 . 2011-10-16 09:08 11800576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\60df958ca96c9b8945f836759b6abd34\System.Web.ni.dll
+ 2011-10-16 09:02 . 2011-10-16 09:02 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\ceadaf3b3d017c7a1ef10a06f8009f6f\System.ServiceModel.ni.dll
+ 2011-10-16 08:41 . 2011-10-16 08:41 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\c6374d32e4af7b7e3e46b32176f76558\System.Design.ni.dll
+ 2011-10-16 08:36 . 2011-10-16 08:36 14328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\054488924fcc579cce9fa0209dafe28b\PresentationFramework.ni.dll
+ 2011-10-16 08:35 . 2011-10-16 08:35 12215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\b2f0318713eca304eaa9d86fc17edb96\PresentationCore.ni.dll
+ 2011-10-16 08:32 . 2011-10-16 08:32 11490816 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDeck"="c:\program files\VIA\VIAudioi\SBADeck\ADeck.exe" [2006-11-02 528384]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-02 281768]
"Start WingMan Profiler"="c:\program files\Logitech\GAMING SOFTWARE\LWEMon.exe" [2008-04-04 88584]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-06-07 421160]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-16 202256]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG111T Smart Wizard.lnk]
backup=c:\windows\pss\NETGEAR WG111T Smart Wizard.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-06-08 04:02 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISW.exe]
2007-05-03 18:12 2061816 —-a-w- c:\program files\AT&T\Internet Security Wizard\ISW.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-06-07 22:51 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-06-03 02:44 1660952 —-a-w- c:\program files\Messenger\Msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 17:50 155648 -c–a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 23:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 16:43 248040 -c–a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-03-16 16:41 202256 -c–a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTPreset]
2004-02-25 02:17 45056 -c–a-w- c:\windows\system32\VTPreset.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Messenger\\Msmsgs.exe"=
"c:\\Program Files\\DsNET Corp\\aTube Catcher 2.0\\yct.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/25/2010 7:32 PM 64288]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/17/2010 10:15 AM 66632]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/16/2009 10:33 AM 50704]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2/12/2009 5:30 PM 16512]
S3 ATHFMWDL;NETGEAR WG111T bootloader driver;c:\windows\system32\Drivers\ATHFMWDL.sys –> c:\windows\system32\Drivers\ATHFMWDL.sys [?]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [11/20/2006 11:24 PM 17149]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/17/2010 10:15 AM 12872]
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
2011-11-13 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]
.
2011-11-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-796845957-789336058-854245398-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 03:09]
.
2011-11-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-796845957-789336058-854245398-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 03:09]
.
2011-11-13 c:\windows\Tasks\User_Feed_Synchronization-{33466F56-B28E-432D-BB34-A90DEADB4A78}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 10:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: motive.com\patttbc.att
TCP: DhcpNameServer = 192.168.1.254
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.startup.homepage - www.google.com/
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13917&gct=&gc=1&q=
FF - Ext: Firefox (default): {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\FireFox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Xuxen III EDBL: [removed] - %profile%\extensions\[removed]
FF - Ext: Aero Fox: {5c8bfb7c-9a54-11dc-8314-0800200c9a66} - %profile%\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-ATT-SST_McciTrayApp - c:\program files\ATT-SST\MCCITRAYAPP.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-13 16:37
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
AudioDeck = c:\program files\VIA\VIAudioi\SBADeck\ADeck.exe 1????????????????????????????????????????????????
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(516)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
.
Completion time: 2011-11-13 16:46:42
ComboFix-quarantined-files.txt 2011-11-13 22:46
ComboFix2.txt 2011-08-30 16:50
.
Pre-Run: 58,376,450,048 bytes free
Post-Run: 58,349,236,224 bytes free
.
- - End Of File - - 84BF8DF4BD035793F08AE756B0A9C989
Hi,

Please do the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Hi. Took a while, but here are the logs: ___________________________________________ Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8158 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 11/13/2011 11:06:19 PM mbam-log-2011-11-13 (23-06-19).txt Scan type: Quick scan Objects scanned: 172763 Time elapsed: 11 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) __________________________________ __________________________________ All Esetscan showed was this: C:\Program Files\vShare\imedix-silent.exe Win32/Toolbar.Zugo application
Hi

The zugo toolbar is known to be bundled with adware so I recommend deleting this file and uninstalling the zugo toolbar.

C:\Program Files\vShare\imedix-silent.exe Win32/Toolbar.Zugo application


Please try running a defrag and removing all your temp files:


Download TFC to your desktop
Mirror
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.


NEXT


  • Open My Computer.
  • Right-click the local disk volume that you want to defragment (usually your C:\ drive) > then click Properties.
  • On the Tools tab > click Defragment Now.
  • Click Defragment.



How is the computer running now? Are there any remaining issues.
OK good to hear,

just some housekeeping to do now, please do the following:


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT


Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Just finished uninstalling combofix and otl. Computer is running very smoothly now. I already use WOT, and I'll definitely look into the articles you told me. Thank you so much for your help! :notworthy: :notworthy: :notworthy: Whatthetech rocks!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI