This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

exploit blackhole exploit kit (type 2073)

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi - i'm receiving multiple threat messages from avg about how exploit blackhole exploit kit (type 2073) has been blocked, but avg seems unable to remove it. is this something i can remove myself? i think i would rather have assistance. i've used your forum before, and appreciate the expertise that your volunteers bring to the table.

the complete warning is

ad.zippyadserver.com/serv.php?
size=728x90&type=if&display_code=347101&int=32

exploit blackhole exploit kit (type 2073)

i took the step of running hijack this. here is the log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:12:59 PM, on 11/10/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17098)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb01.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\IntelAppStore\bin\serviceManager.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\QUICKENW\QWDLLS.EXE
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Documents and Settings\T. Carlberg\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/mail?.intl=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb01.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files\Intel\IntelAppStore\bin\serviceManager.lnk"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [2231125297] C:\Documents and Settings\T. Carlberg\Local Settings\Application Data\wuj.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10m_ActiveX.exe -update activex (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10m_ActiveX.exe -update activex (User 'Default user')
O4 - .DEFAULT User Startup: internet explore.lnk = C:\Program Files\Internet Explorer\iexplore.exe (User 'Default user')
O4 - Startup: AVG Tray Icon.lnk = C:\Program Files\AVG\AVG9\avgtray.exe
O4 - Startup: internet explore.lnk = C:\Program Files\Internet Explorer\iexplore.exe
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.intuit.com
O15 - Trusted Zone: http://*.turbotax.com
O15 - Trusted Zone: http://extract.cr.usgs.gov
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

–
End of file - 9362 bytes
Hello symbiosis7 and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

Lets start with some deeper scans. Please work your way through the following steps:

  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.
  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOTKIT" entries


Please post the DDS logs and the GMER log in your next reply. If you encounter any problems with the scans come back and let me know.
hi jontom, and thanks for your assistance. i downloaded & ran dds after disabling avg resident shield. it worked for about a minute, then closed the run window. dds.txt did not open. attach.txt did not open. i ran it again, same story. i downloded gmr.exe, and ran it; the gmr.txt file is attached. let me know what you want done next. tom

Attachments:

Hello symbiosis7

Thank you for the GMER log (there is no need to attach any logs, just post them directly into your replies).

I would very much like to see a system scan before we begin cleaning the machine. If DDS failed to run, lets try OTL instead:


  • Download and run OTL by Oldtimer


    • Please download OTL by Oldtimer by clicking here and save the file (called OTL.scr) to your desktop.
    • Close all open windows on your computer then Double click on the OTL.scr icon to run the program.
    • Check the boxes beside "LOP Check" and "Purity Check".
    • Under Custom Scan paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    /md5stop


    • Click the "Run Scan" button. Do not change any settings unless specifically told to do so. The scan will not take long.

    • When the scan completes, it will open two notepad windows: OTL.Txt and Extras.Txt.
    • Note: These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
    • Please Copy and Paste the contents of both files in your next reply. You may need two posts to fit them both in.

  • aswMBR


    • Download aswMBR.exe to your desktop.
    • Double click the aswMBR.exe to run it.
    • Click the "Scan" button to start scan.

    [external image: Posted Image]

    • On completion of the scan click save log, save it to your desktop and post in your next reply.

    [external image: Posted Image]

    Please post the OTL logs and the aswMBR log in your next reply (you may need to make more than one post to fit all of the information in) :)
jontom - this is from otl.txt:


OTL logfile created on: 11/12/2011 10:27:56 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\T. Carlberg\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.07 Mb Total Physical Memory | 344.12 Mb Available Physical Memory | 33.93% Memory free
2.85 Gb Paging File | 2.13 Gb Available in Paging File | 74.89% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.97 Gb Total Space | 32.40 Gb Free Space | 45.65% Space Free | Partition Type: NTFS
Drive F: | 465.64 Gb Total Space | 251.11 Gb Free Space | 53.93% Space Free | Partition Type: FAT32

Computer Name: MAIN | User Name: T. Carlberg | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/11/12 10:26:39 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\T. Carlberg\Desktop\OTL.scr
PRC - [2011/10/29 08:33:28 | 002,078,048 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/12/01 06:26:40 | 000,574,216 | —- | M] (Intel Corporation) – C:\Program Files\Intel\IntelAppStore\bin\serviceManager.exe
PRC - [2010/11/27 17:32:46 | 000,725,344 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/09/20 08:46:03 | 000,621,920 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/06/24 15:12:44 | 000,515,424 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/06/24 15:12:34 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/06/24 15:12:25 | 001,101,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/06/24 15:12:24 | 000,842,592 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgam.exe
PRC - [2010/05/21 00:28:00 | 011,312,128 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2010/05/21 00:27:58 | 011,318,784 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2009/09/29 08:17:50 | 000,013,088 | —- | M] (Intuit Inc.) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2000/08/07 05:35:37 | 000,192,512 | —- | M] (Hewlett-Packard Company) – C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb01.exe
PRC - [1999/10/22 11:00:32 | 000,043,520 | —- | M] () – C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
PRC - [1999/08/12 06:59:08 | 000,036,864 | —- | M] (Intuit) – C:\QUICKENW\QWDLLS.EXE


========== Modules (No Company Name) ==========

MOD - [2011/07/13 18:49:52 | 000,854,016 | —- | M] () – C:\WINDOWS\assembly\GAC_32\System.Data.SQLite\1.0.61.0__db937bc2d44ff139\System.Data.SQLite.dll
MOD - [2011/07/13 18:49:50 | 000,403,456 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.WindowsFirewallUtilities\5.0.104.0__7ce6deabcb36a8ea\Intuit.Spc.Map.WindowsFirewallUtilities.dll
MOD - [2011/07/13 18:49:50 | 000,270,336 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\log4net\1.2.10.0__1b44e1d426115821\log4net.dll
MOD - [2011/07/13 18:49:49 | 000,471,040 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\5.0.104.0__7ce6deabcb36a8ea\Intuit.Spc.Map.Reporter.dll
MOD - [2011/07/13 18:49:46 | 000,419,616 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Api.Net\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Api.Net.dll
MOD - [2011/07/13 18:49:46 | 000,046,880 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin.dll
MOD - [2011/07/13 18:49:46 | 000,023,840 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.dll
MOD - [2011/07/13 18:49:46 | 000,018,720 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker.dll
MOD - [2011/07/13 18:49:46 | 000,012,064 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract.dll
MOD - [2011/07/13 18:49:45 | 000,270,112 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Core\2.0.445.0__540d4816ead86321\Intuit.Spc.Esd.Core.dll
MOD - [2011/07/13 18:49:45 | 000,120,096 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.DataAccess\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.DataAccess.dll
MOD - [2011/07/13 18:49:45 | 000,070,432 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.Common\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.Common.dll
MOD - [2011/07/13 18:49:44 | 000,121,632 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.BusinessLogic\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.BusinessLogic.dll
MOD - [2011/04/13 07:23:12 | 000,212,992 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e0d56c0582316e9ecb4c18186e37217c\System.ServiceProcess.ni.dll
MOD - [2011/04/12 23:55:51 | 007,949,824 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\f02cf6430a9fc77908a74ab6925cb73c\System.ni.dll
MOD - [2011/04/12 23:55:18 | 011,490,816 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\62d5f089dd51f18472a7caf1593d9f6b\mscorlib.ni.dll
MOD - [2011/04/12 23:54:27 | 003,182,592 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
MOD - [2011/04/12 23:54:26 | 002,933,248 | —- | M] () – C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2011/04/12 23:54:25 | 000,425,984 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
MOD - [2011/04/12 23:54:21 | 000,626,688 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
MOD - [2011/04/12 23:54:21 | 000,303,104 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2011/04/12 23:54:20 | 000,258,048 | —- | M] () – C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
MOD - [2011/04/12 23:54:19 | 002,048,000 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll
MOD - [2011/04/12 23:54:19 | 000,261,632 | —- | M] () – C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2011/04/12 23:54:17 | 000,114,688 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
MOD - [2011/04/12 23:54:11 | 005,025,792 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
MOD - [2011/01/26 08:37:42 | 003,622,128 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\plugin\libbizlplugin.dll
MOD - [2010/12/01 06:26:38 | 000,195,584 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\libgsoap.dll
MOD - [2010/12/01 06:26:36 | 000,400,384 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\sqlite3.dll
MOD - [2010/12/01 06:26:36 | 000,375,808 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\QtXml4.dll
MOD - [2010/12/01 06:26:36 | 000,322,048 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\log4cplus.dll
MOD - [2010/12/01 06:26:36 | 000,013,312 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\featureController.dll
MOD - [2010/12/01 06:26:35 | 002,452,992 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\QtCore4.dll
MOD - [2010/12/01 06:26:35 | 001,008,640 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\QtNetwork4.dll
MOD - [2010/12/01 06:26:34 | 000,062,464 | —- | M] () – C:\Program Files\Intel\IntelAppStore\bin\zlib1.dll
MOD - [2010/05/04 15:36:28 | 000,970,752 | —- | M] () – C:\Program Files\OpenOffice.org 3\program\libxml2.dll
MOD - [2004/04/11 17:57:44 | 000,040,960 | —- | M] () – C:\Program Files\Dell\Media Experience\DirWatcher.dll
MOD - [1999/10/26 12:32:14 | 000,050,176 | —- | M] () – C:\Program Files\Adobe\Acrobat 4.0\Distillr\adistres.dll
MOD - [1999/10/22 11:00:32 | 000,043,520 | —- | M] () – C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (HidServ)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - [2011/07/26 09:16:02 | 001,025,352 | —- | M] () [On_Demand | Stopped] – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe – (AVG Security Toolbar Service)
SRV - [2010/06/24 15:12:34 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2009/09/29 08:17:50 | 000,013,088 | —- | M] (Intuit Inc.) [Auto | Running] – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe – (IntuitUpdateService)


========== Driver Services (SafeList) ==========

DRV - [2011/09/12 19:17:01 | 000,029,712 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2011/05/05 09:26:13 | 000,243,152 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/06/24 15:12:27 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2010/03/04 09:58:11 | 000,052,872 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\System32\Drivers\avgrkx86.sys – (AvgRkx86)
DRV - [2004/03/24 07:12:44 | 000,004,272 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\bvrp_pci.sys – (bvrp_pci)
DRV - [2003/11/17 12:59:20 | 000,212,224 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys – (HSFHWBS2)
DRV - [2003/11/17 12:58:02 | 000,680,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys – (winachsf)
DRV - [2003/11/17 12:56:26 | 001,042,432 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys – (HSF_DP)
DRV - [2003/09/19 14:47:24 | 000,010,368 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys – (pfc)
DRV - [2002/11/08 11:45:06 | 000,017,217 | —- | M] (Dell Computer Corporation) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys – (omci)
DRV - [1999/08/12 06:59:08 | 000,034,916 | —- | M] (Marimba, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\MrtRate.sys – (mrtRate)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/mail?.intl=us
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll File not found



O1 HOSTS File: ([2010/04/12 20:10:28 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb01.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [Intel AppUp(SM) center] C:\Program Files\Intel\IntelAppStore\bin\serviceManager.lnk ()
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" File not found
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [2231125297] C:\Documents and Settings\T. Carlberg\Local Settings\Application Data\wuj.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk = C:\QUICKENW\BILLMIND.EXE (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE (Intuit)
O4 - Startup: C:\Documents and Settings\T. Carlberg\Start Menu\Programs\Startup\AVG Tray Icon.lnk = C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - Startup: C:\Documents and Settings\T. Carlberg\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_20.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: intuit.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKCU\..Trusted Domains: SecurityRisk ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: turbotax.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: usgs.gov ([extract.cr] http in Trusted sites)
O15 - HKCU\..Trusted Domains: yahoo.com ([login] https in Trusted sites)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{124E9C0C-7263-4DDD-A928-3A79B1179208}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\T. Carlberg\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\T. Carlberg\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 11:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2007/06/16 22:04:20 | 000,000,000 | —D | M] - F:\autorun – [ FAT32 ]
O32 - AutoRun File - [2005/11/15 12:08:04 | 000,000,036 | -H– | M] () - F:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/12 10:26:50 | 001,916,416 | —- | C] (AVAST Software) – C:\Documents and Settings\T. Carlberg\Desktop\aswMBR.exe
[2011/11/12 10:26:37 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\T. Carlberg\Desktop\OTL.scr
[2011/11/12 00:53:48 | 000,000,000 | RH-D | C] – C:\Documents and Settings\T. Carlberg\Recent
[2011/11/11 11:34:37 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\T. Carlberg\Desktop\dds.scr
[2011/11/10 16:11:51 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\T. Carlberg\Desktop\HiJackThis.exe
[2011/11/04 11:49:34 | 000,000,000 | —D | C] – C:\Program Files\FamilySearch
[2011/11/04 11:49:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\FamilySearch
[2011/10/30 20:30:16 | 000,000,000 | —D | C] – C:\Documents and Settings\T. Carlberg\Application Data\Amazon
[2011/10/30 20:29:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Amazon
[2011/10/30 20:29:37 | 000,000,000 | —D | C] – C:\Program Files\Amazon
[2011/10/13 14:59:06 | 000,000,000 | —D | C] – C:\Program Files\Citrix
[2006/10/10 13:09:36 | 001,053,198 | —- | C] (Macromedia, Inc.) – C:\Program Files\freemahjongg.exe
[2005/02/25 17:24:19 | 000,018,944 | —- | C] ( ) – C:\WINDOWS\System32\IMPLODE.DLL
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/12 10:31:26 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/11/12 10:27:29 | 000,000,211 | -HS- | M] () – C:\BOOT.INI
[2011/11/12 10:27:03 | 001,916,416 | —- | M] (AVAST Software) – C:\Documents and Settings\T. Carlberg\Desktop\aswMBR.exe
[2011/11/12 10:26:39 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\T. Carlberg\Desktop\OTL.scr
[2011/11/12 09:25:19 | 088,953,134 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/11/12 09:21:16 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/11/12 09:20:32 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2011/11/11 11:46:21 | 000,002,779 | —- | M] () – C:\WINDOWS\winzip32.ini
[2011/11/11 11:34:42 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\T. Carlberg\Desktop\dds.scr
[2011/11/10 16:11:56 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\T. Carlberg\Desktop\HiJackThis.exe
[2011/11/09 17:56:43 | 000,001,043 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2011/11/06 09:05:01 | 000,442,892 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2011/11/06 09:05:01 | 000,072,158 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2011/11/02 22:34:01 | 000,000,896 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/02 07:15:10 | 000,000,892 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/13 14:58:19 | 000,072,080 | —- | M] () – C:\Documents and Settings\T. Carlberg\g2mdlhlpx.exe
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/13 14:58:18 | 000,072,080 | —- | C] () – C:\Documents and Settings\T. Carlberg\g2mdlhlpx.exe
[2011/09/09 15:13:03 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/06/21 22:45:00 | 000,001,862 | -HS- | C] () – C:\Documents and Settings\T. Carlberg\Local Settings\Application Data\2sj84r4yr1d5210755e
[2011/06/21 22:45:00 | 000,001,862 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\2sj84r4yr1d5210755e
[2011/03/21 01:07:29 | 000,147,264 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/07/18 17:04:01 | 000,000,058 | -H– | C] () – C:\WINDOWS\popcreg.dat
[2010/07/18 17:04:01 | 000,000,020 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2010/06/26 11:42:59 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\CommonDL.dll
[2010/06/26 11:42:59 | 000,002,411 | —- | C] () – C:\WINDOWS\System32\lgAxconfig.ini
[2009/06/09 18:13:04 | 000,000,581 | —- | C] () – C:\WINDOWS\ArcPad.INI
[2009/04/01 23:10:40 | 000,000,045 | —- | C] () – C:\WINDOWS\TRIMSURV.INI
[2009/04/01 23:05:11 | 000,002,528 | —- | C] () – C:\Documents and Settings\T. Carlberg\Application Data\$_hpcst$.hpc
[2008/11/19 18:26:37 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/04/09 21:03:39 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008/02/03 19:12:30 | 000,000,048 | —- | C] () – C:\WINDOWS\Usnscsvr.ini
[2007/11/16 12:45:57 | 000,002,779 | —- | C] () – C:\WINDOWS\winzip32.ini
[2007/01/07 11:52:27 | 000,001,369 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/10/22 20:38:20 | 000,000,021 | —- | C] () – C:\WINDOWS\CS_SETUP.ini
[2006/10/12 16:08:39 | 000,000,551 | —- | C] () – C:\Program Files\Shortcut to freemahjongg.exe.lnk
[2006/02/17 00:07:32 | 000,000,004 | —- | C] () – C:\WINDOWS\info147.sys
[2005/09/17 17:04:24 | 000,000,848 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2005/08/07 22:27:43 | 000,000,000 | —- | C] () – C:\WINDOWS\IMPORT71.INI
[2005/05/03 20:34:14 | 000,004,272 | —- | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2005/05/03 20:31:08 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/02/08 22:51:22 | 000,040,129 | —- | C] () – C:\WINDOWS\iccsigs.dat
[2005/02/08 22:51:22 | 000,000,151 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2005/01/21 23:40:15 | 000,000,715 | —- | C] () – C:\WINDOWS\aolback.exe.lnk
[2005/01/02 11:15:36 | 000,458,752 | —- | C] () – C:\WINDOWS\System32\Fpl.dll
[2005/01/02 11:15:22 | 000,332,800 | —- | C] () – C:\WINDOWS\System32\Fpxlib.dll
[2005/01/02 11:15:22 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\Jpeglib.dll
[2005/01/02 11:15:22 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\Cpuinf32.dll
[2004/12/12 21:29:52 | 000,004,248 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2004/11/30 09:57:07 | 000,061,678 | —- | C] () – C:\Documents and Settings\T. Carlberg\Application Data\PFP120JPR.{PB
[2004/11/30 09:57:07 | 000,012,358 | —- | C] () – C:\Documents and Settings\T. Carlberg\Application Data\PFP120JCM.{PB
[2004/11/30 00:23:28 | 000,000,024 | —- | C] () – C:\WINDOWS\qfnonl.ini
[2004/11/29 22:46:19 | 000,009,381 | —- | C] () – C:\WINDOWS\mozver.dat
[2004/11/29 21:35:56 | 000,000,335 | —- | C] () – C:\WINDOWS\mozregistry.dat
[2004/11/29 21:35:07 | 000,000,000 | —- | C] () – C:\WINDOWS\netscape.INI
[2004/11/29 17:48:43 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/11/29 17:31:49 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2004/11/29 17:25:26 | 000,040,828 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/11/29 17:25:10 | 000,634,087 | —- | C] () – C:\WINDOWS\cd32.exe
[2004/11/29 17:18:18 | 000,001,043 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2004/11/29 17:18:17 | 000,006,838 | —- | C] () – C:\WINDOWS\ICOADB32.DAT
[2004/11/29 17:18:17 | 000,000,542 | —- | C] () – C:\WINDOWS\intuprof.ini
[2004/11/29 14:31:07 | 000,147,968 | —- | C] () – C:\Documents and Settings\T. Carlberg\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/11/18 00:42:49 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/11/18 00:40:37 | 000,001,097 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/11/18 00:36:48 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2004/11/18 00:25:16 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2004/11/18 00:24:32 | 000,442,892 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2004/11/18 00:24:32 | 000,072,158 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2004/11/18 00:12:46 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/09/15 20:03:14 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/10 11:13:12 | 000,000,882 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/10 11:08:08 | 000,253,472 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 11:03:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 11:02:16 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 08:08:26 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.BIN
[2004/08/10 08:08:26 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.DAT
[2004/08/04 03:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2004/08/04 03:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2004/08/04 03:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2004/08/04 03:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2004/08/04 03:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2004/08/04 03:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\SECUPD.DAT
[2004/08/04 03:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 03:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2004/07/19 14:01:02 | 000,045,056 | —- | C] () – C:\WINDOWS\SETPWRCG.EXE
[2003/07/31 15:16:46 | 000,000,017 | -H– | C] () – C:\WINDOWS\System32\drivers\DVEMODEM.DAT
[2000/04/04 10:15:00 | 000,000,899 | —- | C] () – C:\WINDOWS\TIMEZONE.INI
[1999/01/22 10:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1979/12/31 22:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2010/08/16 21:33:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/12/27 08:53:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2004/11/18 00:34:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/03/14 22:56:13 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2008/04/20 15:21:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2010/06/26 22:15:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LGMOBILEAX
[2010/07/18 17:04:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2008/09/08 19:38:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\qxwjelar
[2009/11/04 20:55:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Temp
[2009/04/01 23:09:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trimble
[2005/01/21 23:39:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/11/16 11:37:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/10/11 18:19:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/04/28 18:28:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/11/02 17:06:59 | 000,000,000 | —D | M] – C:\Documents and Settings\T. Carlberg\Application Data\Amazon
[2010/04/19 09:53:35 | 000,000,000 | —D | M] – C:\Documents and Settings\T. Carlberg\Application Data\AVG9
[2007/10/11 19:06:47 | 000,000,000 | —D | M] – C:\Documents and Settings\T. Carlberg\Application Data\Grisoft
[2005/01/24 12:54:54 | 000,000,000 | —D | M] – C:\Documents and Settings\T. Carlberg\Application Data\Leadertech
[2006/10/22 20:48:30 | 000,000,000 | —D | M] – C:\Documents and Settings\T. Carlberg\Application Data\Nikon
[2010/11/22 16:07:25 | 000,000,000 | —D | M] – C:\Documents and Settings\T. Carlberg\Application Data\OpenOffice.org
[2011/04/12 19:57:16 | 000,000,000 | —D | M] – C:\Documents and Settings\T. Carlberg\Application Data\Rovio
[2009/04/01 23:09:30 | 000,000,000 | —D | M] – C:\Documents and Settings\T. Carlberg\Application Data\Trimble

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/08/10 11:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/11/12 10:27:29 | 000,000,211 | -HS- | M] () – C:\BOOT.INI
[2004/08/03 22:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/04/12 20:16:16 | 000,010,667 | —- | M] () – C:\ComboFix.txt
[2004/08/10 11:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/02/25 17:25:52 | 000,006,116 | —- | M] () – C:\DeIsL1.isu
[2004/11/18 00:15:28 | 000,004,496 | RH– | M] () – C:\DELL.SDR
[2004/08/10 11:14:36 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 11:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/02/03 00:15:19 | 000,001,536 | -H– | M] () – C:\IPH.PH
[2005/07/17 22:28:19 | 000,102,940 | —- | M] () – C:\mmjb.DDF
[2004/08/10 11:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 03:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/10/18 22:23:47 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2011/11/12 09:20:22 | 2097,152,000 | -HS- | M] () – C:\pagefile.sys
[2011/06/22 18:31:43 | 000,000,404 | —- | M] () – C:\rkill.log
[2007/06/08 14:37:19 | 000,235,988 | —- | M] () – C:\winzip.log

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 11:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 04:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 02:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2007/01/10 23:36:48 | 000,231,936 | —- | M] () – C:\WINDOWS\Usnscsvr.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2009/02/12 23:00:34 | 000,001,754 | -H– | M] () – C:\Documents and Settings\T. Carlberg\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2006/10/10 13:09:36 | 001,053,198 | —- | M] (Macromedia, Inc.) – C:\Program Files\freemahjongg.exe
[2006/10/12 16:08:39 | 000,000,551 | —- | M] () – C:\Program Files\Shortcut to freemahjongg.exe.lnk

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/10 10:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\DEFAULT.SAV
[2004/08/10 10:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\SOFTWARE.SAV
[2004/08/10 10:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2009/04/02 09:23:20 | 000,002,359 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\ GPS Pathfinder Office.lnk
[2009/02/25 19:54:22 | 000,002,447 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Access 9.0.2720.lnk
[2009/08/29 23:11:50 | 000,000,821 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Adobe Photoshop 5.0.lnk
[2011/11/09 11:09:45 | 000,002,305 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Adobe Reader 9.lnk
[2005/02/25 17:24:24 | 000,001,685 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\ArcView GIS 3.2.lnk
[2005/06/20 12:34:45 | 000,000,574 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Calculator.lnk
[2008/10/18 22:30:54 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI
[2009/08/08 17:40:08 | 000,002,471 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Excel 9.0.2720.lnk
[2010/11/22 16:01:01 | 000,000,897 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\OpenOffice.org.lnk

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-17 16:04:53


< MD5 for: EXPLORER.EX_ >
[2004/08/04 03:00:00 | 000,359,533 | —- | M] () MD5=4F061B12F3D5457315A0314954E7EF46 – C:\I386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2011/01/16 15:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Documents and Settings\T. Carlberg\Local Settings\Temp\RarSFX0\procs\explorer.exe
[2007/06/13 03:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2005/08/16 01:54:58 | 000,001,536 | —- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB – C:\Documents and Settings\T. Carlberg\Local Settings\Temp\RarSFX0\h\explorer.exe

< MD5 for: EXPLORER.LNK >
[2008/11/23 16:17:35 | 000,001,475 | —- | M] () MD5=6F71C7603CC287DCF6DDA0F339459B3C – C:\Documents and Settings\T. Carlberg\Start Menu\Explorer.lnk

< MD5 for: EXPLORER.SC_ >
[2004/08/04 03:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\I386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2004/08/04 03:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\EXPLORER.SCF

< MD5 for: IEXPLORE.CHM >
[2004/08/04 03:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\I386\IEXPLORE.CHM
[2004/08/04 03:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\Help\iexplore.chm

< MD5 for: IEXPLORE.EX_ >
[2004/08/04 03:00:00 | 000,037,895 | —- | M] () MD5=F83009589844F0C30801CC2221F06AB9 – C:\I386\IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2009/06/28 23:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/18 21:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/14 22:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2010/12/20 03:25:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=091D358EFC9D22901BD879EF37F0DAC4 – C:\WINDOWS\ie7updates\KB2497640-IE7\iexplore.exe
[2009/04/24 21:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2007/04/24 06:26:26 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=10BDB55982586A432A3951EB19A26009 – C:\WINDOWS\ie7updates\KB937143-IE7\iexplore.exe
[2008/12/18 21:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/04/22 00:02:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=197B7E4030CFBD8D2979D375E1787AA2 – C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[2008/08/22 21:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2010/06/17 07:12:57 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=203E897F843D56496E2CC101DFF6CE34 – C:\WINDOWS\ie7updates\KB2360131-IE7\iexplore.exe
[2008/04/21 23:40:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=232B22817B90AE0AFF2D189E3E3735AC – C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
[2007/12/06 03:01:25 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2703D940A62B731AA220529DD7331A78 – C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
[2007/06/27 00:27:30 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=275CEE268B9E5D82474C43D5D249D111 – C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
[2008/02/29 00:55:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2D0E5592AB5A46C27DAF7CCAFF4F5B59 – C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
[2009/08/26 21:18:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2007/08/17 02:21:21 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=3AC2BC667DA0AF2C968E96E1630F5AB5 – C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe
[2011/01/16 15:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Documents and Settings\T. Carlberg\Local Settings\Temp\RarSFX0\procs\iexplore.exe
[2009/06/29 00:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2011/04/21 02:34:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=3E23DBEBE1020D52C63235E4189FAC03 – C:\WINDOWS\$hf_mig$\KB2530548-IE7\SP3QFE\iexplore.exe
[2011/04/21 02:34:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=3E23DBEBE1020D52C63235E4189FAC03 – C:\WINDOWS\SoftwareDistribution\Download\d8b42e8b95ac6025753f2f219fcb9b81\sp3qfe\iexplore.exe
[2009/10/27 22:54:16 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2006/10/17 13:04:40 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=5334D4461AA92A7B008755FE6D13C5F2 – C:\WINDOWS\ie7updates\KB928090-IE7\iexplore.exe
[2009/12/18 05:05:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINDOWS\ie7updates\KB980182-IE7\iexplore.exe
[2007/08/17 02:12:49 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=5577D0E3AC2F9F035ACD81B44AF5F511 – C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
[2008/04/13 16:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2011/06/22 18:59:48 | 001,007,120 | —- | M] () MD5=62B8E10334799A27218FBE57708A9FC1 – C:\Documents and Settings\T. Carlberg\Desktop\iExplore.exe
[2007/10/10 00:16:56 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB – C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[2008/06/23 01:20:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=64E376A47763DAEABCDA14BD5B6EA286 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2007/02/21 00:00:58 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=683DDE71BCF03B501B912D20CB93B549 – C:\WINDOWS\ie7updates\KB933566-IE7\iexplore.exe
[2008/02/22 01:40:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=6E0888626E0CAC79F57149814E22DB4D – C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[2010/10/18 03:07:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=72D1F43C4146D312B0DB6AB98C21340E – C:\WINDOWS\ie7updates\KB2482017-IE7\iexplore.exe
[2009/10/27 22:54:21 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2007/12/06 00:34:45 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=809D17D8FA0FDAEE07778CD821CAFFDE – C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[2007/01/08 18:08:42 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=93A6A4F5293AE19E3B37021AABCF0902 – C:\WINDOWS\ie7updates\KB931768-IE7\iexplore.exe
[2007/04/24 06:20:41 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=9B3516C1F30DA17ADD3818573047D63C – C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\iexplore.exe
[2008/10/14 23:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2009/02/27 20:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2005/08/16 01:54:58 | 000,001,536 | —- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB – C:\Documents and Settings\T. Carlberg\Local Settings\Temp\RarSFX0\h\iexplore.exe
[2009/05/26 18:47:22 | 000,031,232 | —- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F – C:\Documents and Settings\T. Carlberg\Local Settings\Temp\RarSFX0\nird\iexplore.exe
[2010/06/17 06:45:15 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B0BC6DC9C9277250C5C8F7B7A48A02CC – C:\WINDOWS\$hf_mig$\KB2183461-IE7\SP3QFE\iexplore.exe
[2010/04/16 03:08:29 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B24A4E23A2FEDB6976EB04D334AD82B2 – C:\WINDOWS\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
[2010/02/22 21:20:02 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B5116340B84824DDD0A641E36B126194 – C:\WINDOWS\ie7updates\KB982381-IE7\iexplore.exe
[2011/04/21 02:58:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6E13F9C120C776A89D783E26D6C15C5 – C:\Program Files\Internet Explorer\iexplore.exe
[2011/04/21 02:58:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6E13F9C120C776A89D783E26D6C15C5 – C:\WINDOWS\SoftwareDistribution\Download\d8b42e8b95ac6025753f2f219fcb9b81\sp3gdr\iexplore.exe
[2011/04/21 02:58:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6E13F9C120C776A89D783E26D6C15C5 – C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
[2010/12/20 02:49:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B74CBEBA34E3CAA2CCACC87FEE8A16C0 – C:\WINDOWS\$hf_mig$\KB2482017-IE7\SP3QFE\iexplore.exe
[2009/02/27 20:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2007/06/27 01:16:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=BD8502DFD53FC24FB8D6929DC46B8C2C – C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
[2009/04/24 21:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2010/04/16 03:43:25 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=C4BA5E36FB57F547117305BF1E0FE454 – C:\WINDOWS\ie7updates\KB2183461-IE7\iexplore.exe
[2008/06/23 00:23:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 – C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
[2010/02/22 21:19:59 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=C8DDA4028065D5CE39CBE7A156B72AB9 – C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[2009/12/17 23:00:27 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2007/02/27 22:51:34 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=D321092F8529CDAE843D6E24E3CAC6CB – C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\iexplore.exe
[2010/10/18 02:36:30 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DA6E1F0F1932B62DD2F6ED05541C555C – C:\WINDOWS\$hf_mig$\KB2416400-IE7\SP3QFE\iexplore.exe
[2011/02/14 03:36:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E3CC8CCF21BFDC954255BB17083FB9F0 – C:\WINDOWS\$hf_mig$\KB2497640-IE7\SP3QFE\iexplore.exe
[2011/02/14 04:17:08 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E4A798DFDE7FE6E79F23548F0EF0F844 – C:\WINDOWS\ie7updates\KB2530548-IE7\iexplore.exe
[2010/08/25 03:30:33 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E5412ED9E07C42C20C48D3FF71E6B1E8 – C:\WINDOWS\ie7updates\KB2416400-IE7\iexplore.exe
[2004/08/04 03:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe
[2008/08/22 21:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2007/10/10 02:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe
[2010/08/25 03:07:58 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F047BEB9771E45A05F425499A30F9BBA – C:\WINDOWS\$hf_mig$\KB2360131-IE7\SP3QFE\iexplore.exe
[2009/08/26 21:18:44 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe

< MD5 for: IEXPLORE.EXE.EXP.LOG >
[2011/03/18 16:40:09 | 000,012,293 | —- | M] () MD5=FE63BB1D8B232AB3AC3F943752ED6057 – C:\Program Files\Internet Explorer\iexplore.exe.exp.log

< MD5 for: IEXPLORE.EXE.MUI >
[2006/10/17 13:04:26 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=E83C9C1F9DD9D47BB44871BFC7E69DDD – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE_129510101681562500.EXH >
[2011/05/27 14:50:16 | 000,000,510 | —- | M] () MD5=F3719C648354A4009BE04ADEB884AC21 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129510101681562500.exh

< MD5 for: IEXPLORE.EXE_129510101681562500_F.DMP >
[2011/05/27 14:50:16 | 256,252,710 | —- | M] () MD5=8B639A3A3DD41AC705B315B982A725B8 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129510101681562500_F.dmp

< MD5 for: IEXPLORE.EXE_129510101681562500_M.DMP >
[2011/05/27 14:49:43 | 000,550,332 | —- | M] () MD5=262A4EF9DF8667AB2602E359EEC3980E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129510101681562500_M.dmp

< MD5 for: IEXPLORE.EXE_129510104383593750_F.DMP >
[2011/05/27 14:53:58 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129510104383593750_F.dmp

< MD5 for: IEXPLORE.EXE_129510104383593750_M.DMP >
[2011/05/27 14:53:58 | 000,008,675 | —- | M] () MD5=90F36B65402D8E54441CDF29BCEC8493 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129510104383593750_M.dmp

< MD5 for: IEXPLORE.EXE_129601588885652277_F.DMP >
[2011/09/10 12:09:16 | 000,589,044 | —- | M] () MD5=1D833150B623297A742E2A0F4C75570D – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588885652277_F.dmp

< MD5 for: IEXPLORE.EXE_129601588885652277_M.DMP >
[2011/09/10 12:08:41 | 001,017,775 | —- | M] () MD5=4DDB95DC3DF9CD473C39AC329D1F961C – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588885652277_M.dmp

< MD5 for: IEXPLORE.EXE_129601588886746027_F.DMP >
[2011/09/10 12:09:16 | 036,368,548 | —- | M] () MD5=B37D938288FF9464A90337DF2BA3854C – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588886746027_F.dmp

< MD5 for: IEXPLORE.EXE_129601588886746027_M.DMP >
[2011/09/10 12:08:46 | 001,018,047 | —- | M] () MD5=9E565EE9ED00FF8DDB286E5A7DEC86BD – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588886746027_M.dmp

< MD5 for: IEXPLORE.EXE_129601588891433527_F.DMP >
[2011/09/10 12:09:16 | 030,859,428 | —- | M] () MD5=570BFC99F5F490460EFBFA8CF2088A77 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588891433527_F.dmp

< MD5 for: IEXPLORE.EXE_129601588891433527_M.DMP >
[2011/09/10 12:08:41 | 001,017,775 | —- | M] () MD5=6708A4BAC26AD5B8196D7DBF54989405 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588891433527_M.dmp

< MD5 for: IEXPLORE.EXE_129601588891902277_F.DMP >
[2011/09/10 12:09:16 | 000,242,596 | —- | M] () MD5=8A824D5C9EACA4B5EC89417CDDA3AC8E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588891902277_F.dmp

< MD5 for: IEXPLORE.EXE_129601588891902277_M.DMP >
[2011/09/10 12:08:46 | 001,017,775 | —- | M] () MD5=50315A94BA8C1F863D8EB42A1D192FFA – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588891902277_M.dmp

< MD5 for: IEXPLORE.EXE_129601588892058527_F.DMP >
[2011/09/10 12:09:17 | 016,539,764 | —- | M] () MD5=0110942151877C241F7C7612E8C56999 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588892058527_F.dmp

< MD5 for: IEXPLORE.EXE_129601588892058527_M.DMP >
[2011/09/10 12:08:46 | 001,017,775 | —- | M] () MD5=07B1891032D71C8830E3D9A609A2A2C2 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588892058527_M.dmp

< MD5 for: IEXPLORE.EXE_129601588892214777_F.DMP >
[2011/09/10 12:09:16 | 000,256,260 | —- | M] () MD5=77613405D2CA244C0A3A9671E1D41194 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588892214777_F.dmp

< MD5 for: IEXPLORE.EXE_129601588892214777_M.DMP >
[2011/09/10 12:08:46 | 001,017,775 | —- | M] () MD5=ACF2E8EE5640A6F537B0E0B798407B5B – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129601588892214777_M.dmp

< MD5 for: IEXPLORE.EXE_129625086350625000_F.DMP >
[2011/10/07 16:50:41 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086350625000_F.dmp

< MD5 for: IEXPLORE.EXE_129625086350625000_M.DMP >
[2011/10/07 16:50:41 | 000,002,978 | —- | M] () MD5=48C0E3E19BD522596394200FD42A8FE6 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086350625000_M.dmp

< MD5 for: IEXPLORE.EXE_129625086352031250_F.DMP >
[2011/10/07 16:50:41 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086352031250_F.dmp

< MD5 for: IEXPLORE.EXE_129625086352031250_M.DMP >
[2011/10/07 16:50:41 | 000,002,978 | —- | M] () MD5=CDF1DE6EDE108F8430E3BAEAD5F33E77 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086352031250_M.dmp

< MD5 for: IEXPLORE.EXE_129625086352656250_F.DMP >
[2011/10/07 16:50:41 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086352656250_F.dmp

< MD5 for: IEXPLORE.EXE_129625086352656250_M.DMP >
[2011/10/07 16:50:41 | 000,002,962 | —- | M] () MD5=A8252AE4741641E5390BB2C667C3964F – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086352656250_M.dmp

< MD5 for: IEXPLORE.EXE_129625086353281250_F.DMP >
[2011/10/07 16:50:41 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086353281250_F.dmp

< MD5 for: IEXPLORE.EXE_129625086353281250_M.DMP >
[2011/10/07 16:50:41 | 000,002,978 | —- | M] () MD5=0EC57E2B342935359E74C9609C9E84AE – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086353281250_M.dmp

< MD5 for: IEXPLORE.EXE_129625086353593750_F.DMP >
[2011/10/07 16:50:41 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086353593750_F.dmp

< MD5 for: IEXPLORE.EXE_129625086353593750_M.DMP >
[2011/10/07 16:50:41 | 000,002,978 | —- | M] () MD5=68553CE091A6F3F3B437FDC9A8346FDC – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086353593750_M.dmp

< MD5 for: IEXPLORE.EXE_129625086353906250_F.DMP >
[2011/10/07 16:50:41 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086353906250_F.dmp

< MD5 for: IEXPLORE.EXE_129625086353906250_M.DMP >
[2011/10/07 16:50:41 | 000,002,962 | —- | M] () MD5=301054320E928692A203E178F77068AB – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086353906250_M.dmp

< MD5 for: IEXPLORE.EXE_129625086355156250_F.DMP >
[2011/10/07 16:50:35 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086355156250_F.dmp

< MD5 for: IEXPLORE.EXE_129625086355156250_M.DMP >
[2011/10/07 16:50:35 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086355156250_M.dmp

< MD5 for: IEXPLORE.EXE_129625086359375000_F.DMP >
[2011/10/07 16:50:41 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086359375000_F.dmp

< MD5 for: IEXPLORE.EXE_129625086359375000_M.DMP >
[2011/10/07 16:50:41 | 000,002,962 | —- | M] () MD5=06E190F645CE7E047EA89F7C3D27BEC5 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625086359375000_M.dmp

< MD5 for: IEXPLORE.EXE_129625136157812500_F.DMP >
[2011/10/07 18:13:36 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625136157812500_F.dmp

< MD5 for: IEXPLORE.EXE_129625136157812500_M.DMP >
[2011/10/07 18:13:35 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129625136157812500_M.dmp

< MD5 for: IEXPLORE.EXE_129643353311750000_F.DMP >
[2011/10/28 20:15:31 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129643353311750000_F.dmp

< MD5 for: IEXPLORE.EXE_129643353311750000_M.DMP >
[2011/10/28 20:15:31 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129643353311750000_M.dmp

< MD5 for: IEXPLORE.EXE_129645082446250000_F.DMP >
[2011/10/30 20:17:59 | 020,742,620 | —- | M] () MD5=377754828791126A22020359A5AE7A84 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129645082446250000_F.dmp

< MD5 for: IEXPLORE.EXE_129645082446250000_M.DMP >
[2011/10/30 20:17:44 | 000,655,524 | —- | M] () MD5=6A61E00B64CE712CFAA2FBC89A071936 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129645082446250000_M.dmp

< MD5 for: IEXPLORE.EXE_129645082448906250_F.DMP >
[2011/10/30 20:17:58 | 020,742,620 | —- | M] () MD5=EEB0B12F5C880C8631B8801ADBE14C8A – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129645082448906250_F.dmp

< MD5 for: IEXPLORE.EXE_129645082448906250_M.DMP >
[2011/10/30 20:17:44 | 000,654,460 | —- | M] () MD5=E91DB7D7A77BE1236FBD16F1CED73F55 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129645082448906250_M.dmp

< MD5 for: IEXPLORE.EXE_129645082450156250_F.DMP >
[2011/10/30 20:17:59 | 020,742,620 | —- | M] () MD5=9712C6CF42DC19726C98F60215EAD108 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129645082450156250_F.dmp

< MD5 for: IEXPLORE.EXE_129645082450156250_M.DMP >
[2011/10/30 20:17:41 | 000,655,524 | —- | M] () MD5=F87DE5F77FE61DC7F05FD4E0D8931294 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129645082450156250_M.dmp

< MD5 for: IEXPLORE.EXE_129648421191875000_F.DMP >
[2011/11/03 17:03:07 | 029,324,566 | —- | M] () MD5=7B43C6AE15D356443959CD3345EC4D0C – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129648421191875000_F.dmp

< MD5 for: IEXPLORE.EXE_129648421191875000_M.DMP >
[2011/11/03 17:02:24 | 001,085,340 | —- | M] () MD5=D4E6B1DCBBBFB3EE93EDC1E0C753794F – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129648421191875000_M.dmp

< MD5 for: IEXPLORE.EXE_129648421195937500_F.DMP >
[2011/11/03 17:03:07 | 029,324,566 | —- | M] () MD5=2EA0068F75BD1488D42C4289B480E25A – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129648421195937500_F.dmp

< MD5 for: IEXPLORE.EXE_129648421195937500_M.DMP >
[2011/11/03 17:02:23 | 001,085,340 | —- | M] () MD5=3FDA6EDBF3EC8FAF3EEF2A9BFE125E29 – C:\Documents and Settings\All Users\Application Data\avg9\Dumps\iexplore.exe_129648421195937500_M.dmp

< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2011/11/02 21:58:57 | 000,095,374 | —- | M] () MD5=6C2F1406923F4915100C801D8BB18434 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf

< MD5 for: IEXPLORE.HLP >
[2004/08/04 03:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\I386\IEXPLORE.HLP
[2004/08/04 03:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\IEXPLORE.HLP

< MD5 for: WINLOGON.EXE >
[2004/08/04 03:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\I386\WINLOGON.EXE
[2009/05/26 18:47:22 | 000,031,232 | —- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F – C:\Documents and Settings\T. Carlberg\Local Settings\Temp\RarSFX0\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SYSTEM32\winlogon.exe

< End of report >
… and this is from extras.txt:


OTL Extras logfile created on: 11/12/2011 10:27:56 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\T. Carlberg\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.07 Mb Total Physical Memory | 344.12 Mb Available Physical Memory | 33.93% Memory free
2.85 Gb Paging File | 2.13 Gb Available in Paging File | 74.89% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.97 Gb Total Space | 32.40 Gb Free Space | 45.65% Space Free | Partition Type: NTFS
Drive F: | 465.64 Gb Total Space | 251.11 Gb Free Space | 53.93% Space Free | Partition Type: FAT32

Computer Name: MAIN | User Name: T. Carlberg | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"AntiVirusDisableNotify" = 1
"UpdatesDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\SYSTEM32\DPVSETUP.EXE" = C:\WINDOWS\SYSTEM32\DPVSETUP.EXE:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax
"C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager
"C:\Program Files\AVG\AVG9\avgam.exe" = C:\Program Files\AVG\AVG9\avgam.exe:*:Enabled:avgam.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgdiagex.exe" = C:\Program Files\AVG\AVG9\avgdiagex.exe:*:Enabled:avgdiagex.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\WINDOWS\SYSTEM32\javaw.exe" = C:\WINDOWS\SYSTEM32\javaw.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.6
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.3
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{7EC68A50-D653-11D8-A3B3-0010B5C6624C}" = HyperNiche v.1 beta
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{AD4203ED-7683-435E-B436-C299773A9936}" = MapSource - US Topo v3.02
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{D94A8E22-DF2B-4107-9E51-608A60A7671D}" = Personal Ancestral File 5
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EE7C3A14-1D20-49F6-B903-491561076F0F}" = ArcSoft Software Suite
"{F13BA02B-435A-11D2-A597-00104B97152B}" = ER Mapper imagery plugin for ArcView® 3.1 Onwards v2.4
"{FD6C6B7F-5696-48C5-A601-2EE9E50C3D46}" = WD Firewire HID Driver
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"Adobe Acrobat 4.0" = Adobe Acrobat 4.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AVG9Uninstall" = AVG 9.0
"Bejeweled 2 Deluxe" = Bejeweled 2 Deluxe
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"DAO 3.5" = DAO 3.5
"DellSupport" = Dell Support 5.0.0 (630)
"ERUNT_is1" = ERUNT 1.1j
"ESRI ArcPad 7.0.1" = ESRI ArcPad 7.0.1
"FileZilla" = FileZilla (remove only)
"HijackThis" = HijackThis 2.0.2
"hp deskjet 990c series" = hp deskjet 990c series (Remove only)
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Intel AppUp(SM) center 18988" = Intel AppUp(SM) center
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Adapters and Drivers
"Quicken Basic 2000" = Quicken Basic 2000
"Quicken Lawyer 2003 Personal" = Quicken Lawyer 2003 Personal
"StreetPlugin" = Learn2 Player (Uninstall Only)
"TurboTax 2009" = TurboTax 2009
"Usnscsvr" = Usnscsvr
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ArcView GIS 3.2" = ArcView GIS 3.2
"Glucofacts Deluxe Updater 2.0" = Glucofacts Deluxe Updater 2.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/27/2011 3:47:15 AM | Computer Name = MAIN | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium – Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 9/27/2011 3:47:20 AM | Computer Name = MAIN | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium – Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 9/27/2011 3:47:22 AM | Computer Name = MAIN | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium – Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 9/27/2011 7:46:52 AM | Computer Name = MAIN | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium – Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 9/28/2011 11:35:13 PM | Computer Name = MAIN | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium – Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 9/28/2011 11:35:18 PM | Computer Name = MAIN | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium – Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 9/28/2011 11:35:22 PM | Computer Name = MAIN | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium – Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 9/28/2011 11:35:43 PM | Computer Name = MAIN | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium – Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 10/9/2011 12:06:16 AM | Computer Name = MAIN | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium – Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 10/27/2011 11:17:47 PM | Computer Name = MAIN | Source = Application Error | ID = 1000
Description = Faulting application avgwdsvc.exe, version 9.0.0.832, faulting module
avgcfgx.dll, version 9.0.0.855, fault address 0x00025c71.

[ System Events ]
Error - 11/2/2011 9:22:31 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/2/2011 9:22:31 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/2/2011 9:22:31 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/2/2011 9:22:32 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/2/2011 9:22:32 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/2/2011 9:22:32 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/2/2011 9:22:32 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/2/2011 9:22:32 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/2/2011 9:34:02 PM | Computer Name = MAIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gupdate with
arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69}

Error - 11/3/2011 2:34:00 AM | Computer Name = MAIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gupdate with
arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69}


< End of report >
and finally the log from aswMBR. since you did not specify, i did not allow the utility to download the avast virus definitions database. aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-11-12 11:55:44 —————————– 11:55:44.296 OS Version: Windows 5.1.2600 Service Pack 3 11:55:44.296 Number of processors: 2 586 0x304 11:55:44.296 ComputerName: MAIN UserName: 11:55:44.828 Initialize success 11:55:48.375 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17 11:55:48.375 Disk 0 Vendor: Size: 0MB BusType: 0 11:55:50.421 Disk 0 MBR read successfully 11:55:50.421 Disk 0 MBR scan 11:55:50.421 Disk 0 Whistler@MBR code has been found 11:55:50.421 Disk 0 MBR hidden 11:55:50.421 Disk 0 MBR [Whistler] **ROOTKIT** 11:55:50.453 Disk 0 scanning C:\WINDOWS\system32\drivers 11:56:01.171 Service scanning 11:56:02.750 Modules scanning 11:56:14.437 Disk 0 trace - called modules: 11:56:14.437 ntoskrnl.exe >>UNKNOWN [0x8681ca0a]<< 11:56:14.437 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86f49ab8] 11:56:14.437 \Driver\Disk[0x86f51498] -> IRP_MJ_READ -> 0x8681ca0a 11:56:14.437 Scan finished successfully 11:56:19.515 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\T. Carlberg\Desktop\MBR.dat" 11:56:19.515 The log file has been saved successfully to "C:\Documents and Settings\T. Carlberg\Desktop\aswMBR.txt"
Hello symbiosis7

Thank you for the log.

Please work your way through the following steps:

  • Combofix


  • Download ComboFix from one of the following locations:

    Link 1
    Link 2

  • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • Should there be issues with internet afterward:

    In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.
ok, i downloaded combofix, and allowed it to upgrade to the newer version. i disabled avg's resident shield and then ran combofix. my computer rebooted a couple times, eventually displaying this log:

ComboFix 11-11-12.04 - T. Carlberg 11/12/2011 12:58:19.5.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.454 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\AVG\avi7.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\crt_x64.msi
c:\documents and settings\All Users\Application Data\TEMP\AVG\files.dat
c:\documents and settings\All Users\Application Data\TEMP\AVG\incavi.avm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_cz.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_da.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_fr.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ge.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_hu.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_id.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_in.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_it.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_jp.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ko.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ms.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_nl.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pb.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pl.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pt.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ru.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sc.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sk.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sp.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_tr.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_us.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zh.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zt.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\microavi.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\miniavi.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.dat
c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.ini
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupcz.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupda.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupfr.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupge.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setuphu.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupid.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupin.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupit.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupjp.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupko.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupms.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupnl.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setuppb.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setuppl.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setuppt.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupru.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupsc.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupsk.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupsp.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setuptr.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupus.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupzh.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\setupzt.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\vcredis1.cab
c:\documents and settings\All Users\Application Data\TEMP\AVG\vcredist.msi
c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
c:\documents and settings\T. Carlberg\g2mdlhlpx.exe
c:\documents and settings\T. Carlberg\Start Menu\Internet Explore.lnk
c:\documents and settings\T. Carlberg\WINDOWS
c:\windows\dasetup.log
c:\windows\system32\DC120fc7_32.dll
c:\windows\system32\rnaph.dll
F:\autorun.inf . . . . Failed to delete
.
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\ERDNT\cache\userinit.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-10-12 to 2011-11-12 )))))))))))))))))))))))))))))))
.
.
2011-11-04 19:49 . 2011-11-04 19:49 ——– d—–w- c:\program files\FamilySearch
2011-10-31 04:30 . 2011-11-03 01:06 ——– d—–w- c:\documents and settings\T. Carlberg\Application Data\Amazon
2011-10-31 04:29 . 2011-11-03 01:06 ——– d—–w- c:\program files\Amazon
2011-10-13 22:59 . 2011-11-03 03:39 ——– d—–w- c:\program files\Citrix
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-13 03:17 . 2007-01-06 00:29 29712 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2006-10-10 21:09 . 2006-10-10 21:09 1053198 —-a-w- c:\program files\freemahjongg.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-07-26 17:15 2532680 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-08-24 57344]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb01.exe" [2000-08-07 192512]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"Intel AppUp(SM) center"="c:\program files\Intel\IntelAppStore\bin\serviceManager.lnk" [2011-04-13 933]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10m_ActiveX.exe" [2011-02-18 234656]
.
c:\documents and settings\T. Carlberg\Start Menu\Programs\Startup\
AVG Tray Icon.lnk - c:\program files\AVG\AVG9\avgtray.exe [2010-6-24 2078048]
internet explore.lnk - c:\program files\Internet Explorer\iexplore.exe [2004-8-4 634648]
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe [2005-4-2 43520]
Billminder.lnk - c:\quickenw\BILLMIND.EXE [2004-11-29 36864]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2004-11-18 24576]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
Quicken Startup.lnk - c:\quickenw\QWDLLS.EXE [2004-11-29 36864]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-06-24 23:12 12536 —-a-w- c:\windows\SYSTEM32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Themes"=2 (0x2)
"TapiSrv"=3 (0x3)
"SysmonLog"=3 (0x3)
"Schedule"=2 (0x2)
"SCardSvr"=3 (0x3)
"mnmsrvc"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"iPod Service"=3 (0x3)
"helpsvc"=2 (0x2)
"gupdatem"=3 (0x3)
"gupdate"=2 (0x2)
"Eventlog"=2 (0x2)
"ERSvc"=2 (0x2)
"CiSvc"=3 (0x3)
"Bonjour Service"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\SYSTEM32\\DPVSETUP.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\WINDOWS\\SYSTEM32\\javaw.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R0 AvgRkx86;avgrkx86.sys;c:\windows\SYSTEM32\DRIVERS\avgrkx86.sys [4/20/2008 3:20 PM 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [4/20/2008 3:20 PM 216400]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [4/20/2008 3:20 PM 243152]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [6/24/2010 3:12 PM 308136]
R2 mrtRate;mrtRate;c:\windows\SYSTEM32\DRIVERS\MrtRate.sys [11/29/2004 5:18 PM 34916]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [10/26/2010 10:22 AM 1025352]
S4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/17/2009 8:42 PM 135664]
S4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [12/17/2009 8:42 PM 135664]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WUAUSERV
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-18 04:42]
.
2011-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-18 04:42]
.
.
——- Supplementary Scan ——-
.
uStart Page = https://login.yahoo.com/config/mail?.intl=us
mWindow Title = Humboldt Internet
uInternet Settings,ProxyOverride = *.local
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
Trusted Zone: intuit.com
Trusted Zone: intuit.com\ttlc
Trusted Zone: SecurityRisk
Trusted Zone: turbotax.com
Trusted Zone: usgs.gov\extract.cr
Trusted Zone: yahoo.com\login
TCP: DhcpNameServer = [removed] [removed]
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-12 13:14
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
c:\program files\Internet Explorer\iexplore.exe [880] 0x867C1388
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600
.
CreateFile("\\.\PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3260)
c:\windows\system32\WININET.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\AVG\AVG9\avgam.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Intel\IntelAppStore\bin\serviceManager.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\AVG\AVG9\avgcsrvx.exe
.
**************************************************************************
.
Completion time: 2011-11-12 13:23:51 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-12 21:23
ComboFix2.txt 2010-04-13 04:16
.
Pre-Run: 34,632,900,608 bytes free
Post-Run: 35,396,108,288 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - CFB22E58C36A28DCF16902C3547F7199
Hello symbiosis7

Thank you for the log.

We still have more work to do:

  • Please open OTL


    • Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

      :OTL
      PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
      O15 - HKCU\..Trusted Domains: intuit.com ([]* in Trusted sites)
      O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
      O15 - HKCU\..Trusted Domains: SecurityRisk ([]about in Trusted sites)
      O15 - HKCU\..Trusted Domains: turbotax.com ([]http in Trusted sites)
      O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
      O15 - HKCU\..Trusted Domains: usgs.gov ([extract.cr] http in Trusted sites)
      O15 - HKCU\..Trusted Domains: yahoo.com ([login] https in Trusted sites)
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [start explorer]
      [Reboot]
    • Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
    • Allow the program to run unhindered.
    • Your machine will re-start itself. This is normal.
    • A log will be created after your machine reboots. Please post the contents of the log in your next reply.

  • Please attach the Following File

    • When you ran aswMBR, a file called MBR.dat would have been created on your desktop.
    • The full path to the file is C:\Documents and Settings\T. Carlberg\Desktop\MBR.dat
    • I would like you to attach this file to a post in your next reply.


    Once the MBR.dat file has been attached and sent here, run the following tool (Please make sure you attach the MBR.dat file first - very important):

  • TDSS Killer


    • Please read carefully and follow these steps.
    • Download TDSSKiller and save it to your Desktop.
    • Extract its contents to your desktop.
    • Once extracted, open the TDSSKiller folder and double click on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

    Please post the OTL log and the TDSSKiller log in your next reply.
hi jontom - i ran otl.scr as per your last post. closed all windows first, but checked neither the lop nor the purity checkboxes, as you did not specify to do so. here's the log. i have tried several times to attach the mbr.dat file; the forum software says "you are not allowed to upload files of that thype". i tried altering the extension (*.datx, *.doc, *.xxx) but all fail, albeit in different ways; ex. the *.doc says i did not select a file to upload. i will wait to hear back from you before running the tdsskiller, since it sounds like doing so will alter the mbr.dat file. All processes killed ========== OTL ========== No active process named explorer.exe was found! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\intuit.com\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\intuit.com\ttlc\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\SecurityRisk\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\turbotax.com\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\turbotax.com\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\usgs.gov\extract.cr\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\yahoo.com\login\ deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: T. Carlberg ->Temp folder emptied: 431626 bytes ->Temporary Internet Files folder emptied: 90554118 bytes ->Java cache emptied: 1379294 bytes ->Flash cache emptied: 112269 bytes User: T5A5E~1~CAR %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 13759505 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 6175905 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 40590752 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 32599616 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 177.00 mb [EMPTYFLASH] User: Administrator User: All Users User: Default User User: LocalService ->Flash cache emptied: 0 bytes User: NetworkService User: T. Carlberg ->Flash cache emptied: 0 bytes User: T5A5E~1~CAR Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 11132011_111708 Files\Folders moved on Reboot… C:\Documents and Settings\T. Carlberg\Local Settings\Temp\config.dat moved successfully. C:\Documents and Settings\T. Carlberg\Local Settings\Temp\WCESLog.log moved successfully. File\Folder C:\WINDOWS\temp\1629b184-b845-427f-a61d-e8248940d598.tmp not found! File\Folder C:\WINDOWS\temp\1f633c71-8272-45b5-bf61-67002809c815.tmp not found! File\Folder C:\WINDOWS\temp\433809f8-b5d5-4e3b-abf7-f05fb3c0a73c.tmp not found! File\Folder C:\WINDOWS\temp\887a04f9-51cf-4223-b3c6-f5254fcece08.tmp not found! File\Folder C:\WINDOWS\temp\97b628d2-8646-4d3e-9a38-fdc5d654f91e.tmp not found! File\Folder C:\WINDOWS\temp\9a5640d7-02e1-4f52-945d-c8e65db001dd.tmp not found! File\Folder C:\WINDOWS\temp\cff3adbd-c537-4470-9068-ac26d5a6051f.tmp not found! C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\NGMNZE5P\iframe3[10].htm moved successfully. File\Folder C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\MVCBM3IS\300x250[1].htm not found! C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\H73E27U0\st[2].htm moved successfully. C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\H73E27U0\st[5].htm moved successfully. File\Folder C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\4LT4S77P\st[10] not found! C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\4LT4S77P\st[1].htm moved successfully. C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\AntiPhishing\A0AB7674-8D67-4F4D-B5E1-96FAEADFB79D.dat moved successfully. Registry entries deleted on Reboot…
Hello symbiosis7

You may need to zip the file prior to the upload.

Try right clicking on the file and select Send to ===> Compressed (Zipped) Folder.

The zipped file will appear on your desktop. If the upload fails again just let me know (we have other options available) :)
ok, looks like zipping the mbr file allowed the upload. and here's the tdsskiller log: 16:44:09.0421 1336 TDSS rootkit removing tool [removed] Nov 11 2011 15:47:15 16:44:09.0953 1336 ============================================================ 16:44:09.0953 1336 Current date / time: 2011/11/13 16:44:09.0953 16:44:09.0953 1336 SystemInfo: 16:44:09.0953 1336 16:44:09.0953 1336 OS Version: 5.1.2600 ServicePack: 3.0 16:44:09.0953 1336 Product type: Workstation 16:44:09.0953 1336 ComputerName: MAIN 16:44:09.0953 1336 UserName: T. Carlberg 16:44:09.0953 1336 Windows directory: C:\WINDOWS 16:44:09.0953 1336 System windows directory: C:\WINDOWS 16:44:09.0953 1336 Processor architecture: Intel x86 16:44:09.0953 1336 Number of processors: 2 16:44:09.0953 1336 Page size: 0x1000 16:44:09.0953 1336 Boot type: Normal boot 16:44:09.0953 1336 ============================================================ 16:44:17.0343 1336 Initialize success 16:44:47.0500 2420 ============================================================ 16:44:47.0500 2420 Scan started 16:44:47.0500 2420 Mode: Manual; 16:44:47.0500 2420 ============================================================ 16:44:50.0531 2420 Abiosdsk - ok 16:44:50.0609 2420 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 16:44:50.0703 2420 abp480n5 - ok 16:44:50.0765 2420 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 16:44:50.0843 2420 ACPI - ok 16:44:50.0890 2420 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 16:44:50.0953 2420 ACPIEC - ok 16:44:50.0968 2420 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 16:44:50.0984 2420 adpu160m - ok 16:44:51.0015 2420 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys 16:44:51.0156 2420 aeaudio - ok 16:44:51.0218 2420 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 16:44:51.0234 2420 aec - ok 16:44:51.0296 2420 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 16:44:51.0296 2420 AFD - ok 16:44:51.0406 2420 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 16:44:51.0453 2420 agp440 - ok 16:44:51.0500 2420 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 16:44:51.0546 2420 agpCPQ - ok 16:44:51.0546 2420 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 16:44:51.0640 2420 Aha154x - ok 16:44:51.0671 2420 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 16:44:51.0718 2420 aic78u2 - ok 16:44:51.0781 2420 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 16:44:51.0828 2420 aic78xx - ok 16:44:51.0843 2420 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 16:44:51.0890 2420 AliIde - ok 16:44:51.0906 2420 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys 16:44:51.0921 2420 alim1541 - ok 16:44:51.0968 2420 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys 16:44:52.0046 2420 amdagp - ok 16:44:52.0062 2420 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 16:44:52.0062 2420 amsint - ok 16:44:52.0109 2420 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 16:44:52.0140 2420 asc - ok 16:44:52.0156 2420 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 16:44:52.0187 2420 asc3350p - ok 16:44:52.0281 2420 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 16:44:52.0312 2420 asc3550 - ok 16:44:52.0390 2420 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 16:44:52.0437 2420 AsyncMac - ok 16:44:52.0468 2420 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 16:44:52.0468 2420 atapi - ok 16:44:52.0484 2420 Atdisk - ok 16:44:52.0531 2420 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 16:44:52.0593 2420 Atmarpc - ok 16:44:52.0640 2420 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 16:44:52.0656 2420 audstub - ok 16:44:52.0718 2420 AvgLdx86 (b8c187439d27aba430dd69fdcf1fa657) C:\WINDOWS\System32\Drivers\avgldx86.sys 16:44:52.0750 2420 AvgLdx86 - ok 16:44:52.0781 2420 AvgMfx86 (80ff2b1b7eeda966394f0baa895bbf4b) C:\WINDOWS\System32\Drivers\avgmfx86.sys 16:44:52.0812 2420 AvgMfx86 - ok 16:44:52.0859 2420 AvgRkx86 (5bbcd8646074a3af4ee9b321d12c2b64) C:\WINDOWS\system32\Drivers\avgrkx86.sys 16:44:52.0859 2420 AvgRkx86 - ok 16:44:52.0921 2420 AvgTdiX (9a7a93388f503a34e7339ae7f9997449) C:\WINDOWS\System32\Drivers\avgtdix.sys 16:44:52.0921 2420 AvgTdiX - ok 16:44:52.0937 2420 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 16:44:53.0000 2420 Beep - ok 16:44:53.0062 2420 bvrp_pci (c945dc4eee3f624dfd07788ea7f0db0a) C:\WINDOWS\system32\drivers\bvrp_pci.sys 16:44:53.0156 2420 bvrp_pci - ok 16:44:53.0265 2420 catchme - ok 16:44:53.0343 2420 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 16:44:53.0343 2420 cbidf - ok 16:44:53.0375 2420 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 16:44:53.0375 2420 cbidf2k - ok 16:44:53.0406 2420 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 16:44:53.0453 2420 cd20xrnt - ok 16:44:53.0484 2420 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 16:44:53.0531 2420 Cdaudio - ok 16:44:53.0562 2420 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 16:44:53.0609 2420 Cdfs - ok 16:44:53.0656 2420 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 16:44:53.0687 2420 Cdrom - ok 16:44:53.0703 2420 Changer - ok 16:44:53.0734 2420 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 16:44:53.0765 2420 CmdIde - ok 16:44:53.0796 2420 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 16:44:53.0859 2420 Cpqarray - ok 16:44:53.0921 2420 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 16:44:53.0984 2420 dac2w2k - ok 16:44:53.0984 2420 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 16:44:54.0015 2420 dac960nt - ok 16:44:54.0062 2420 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 16:44:54.0078 2420 Disk - ok 16:44:54.0156 2420 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 16:44:54.0281 2420 dmboot - ok 16:44:54.0406 2420 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 16:44:54.0437 2420 dmio - ok 16:44:54.0500 2420 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 16:44:54.0515 2420 dmload - ok 16:44:54.0578 2420 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 16:44:54.0640 2420 DMusic - ok 16:44:54.0687 2420 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 16:44:54.0703 2420 dpti2o - ok 16:44:54.0750 2420 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 16:44:54.0812 2420 drmkaud - ok 16:44:54.0843 2420 drvmcdb (b15f9e526ba511a48b1b1b8537815740) C:\WINDOWS\system32\drivers\drvmcdb.sys 16:44:54.0937 2420 drvmcdb - ok 16:44:54.0953 2420 drvnddm (fa4670cae95ae2bb857c68e535661145) C:\WINDOWS\system32\drivers\drvnddm.sys 16:44:55.0031 2420 drvnddm - ok 16:44:55.0109 2420 E100B (7d91dc6342248369f94d6eba0cf42e99) C:\WINDOWS\system32\DRIVERS\e100b325.sys 16:44:55.0187 2420 E100B - ok 16:44:55.0281 2420 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 16:44:55.0296 2420 Fastfat - ok 16:44:55.0343 2420 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 16:44:55.0375 2420 Fdc - ok 16:44:55.0421 2420 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 16:44:55.0421 2420 Fips - ok 16:44:55.0468 2420 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 16:44:55.0515 2420 Flpydisk - ok 16:44:55.0562 2420 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 16:44:55.0578 2420 FltMgr - ok 16:44:55.0593 2420 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 16:44:55.0640 2420 Fs_Rec - ok 16:44:55.0703 2420 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 16:44:55.0734 2420 Ftdisk - ok 16:44:55.0781 2420 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 16:44:55.0796 2420 GEARAspiWDM - ok 16:44:55.0812 2420 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 16:44:55.0843 2420 Gpc - ok 16:44:55.0906 2420 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 16:44:55.0937 2420 HidUsb - ok 16:44:56.0000 2420 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 16:44:56.0000 2420 hpn - ok 16:44:56.0062 2420 HSFHWBS2 (77e4ff0b73bc0aeaaf39bf0c8104231f) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys 16:44:56.0125 2420 HSFHWBS2 - ok 16:44:56.0187 2420 HSF_DP (60e1604729a15ef4a3b05f298427b3b1) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys 16:44:56.0234 2420 HSF_DP - ok 16:44:56.0328 2420 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 16:44:56.0468 2420 HTTP - ok 16:44:56.0500 2420 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 16:44:56.0500 2420 i2omgmt - ok 16:44:56.0531 2420 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys 16:44:56.0609 2420 i2omp - ok 16:44:56.0625 2420 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 16:44:56.0625 2420 i8042prt - ok 16:44:56.0718 2420 ialm (5a8e05f1d5c36abd58cffa111eb325ea) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys 16:44:56.0843 2420 ialm - ok 16:44:56.0921 2420 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 16:44:56.0921 2420 Imapi - ok 16:44:56.0968 2420 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 16:44:57.0000 2420 ini910u - ok 16:44:57.0015 2420 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 16:44:57.0046 2420 IntelIde - ok 16:44:57.0093 2420 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 16:44:57.0109 2420 intelppm - ok 16:44:57.0203 2420 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 16:44:57.0203 2420 Ip6Fw - ok 16:44:57.0218 2420 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 16:44:57.0234 2420 IpFilterDriver - ok 16:44:57.0250 2420 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 16:44:57.0250 2420 IpInIp - ok 16:44:57.0265 2420 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 16:44:57.0312 2420 IpNat - ok 16:44:57.0390 2420 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 16:44:57.0421 2420 IPSec - ok 16:44:57.0437 2420 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 16:44:57.0468 2420 IRENUM - ok 16:44:57.0500 2420 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 16:44:57.0578 2420 isapnp - ok 16:44:57.0625 2420 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 16:44:57.0671 2420 Kbdclass - ok 16:44:57.0718 2420 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 16:44:57.0734 2420 kmixer - ok 16:44:57.0781 2420 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 16:44:57.0843 2420 KSecDD - ok 16:44:57.0890 2420 lbrtfdc - ok 16:44:57.0953 2420 mdmxsdk (eeaea6514ba7c9d273b5e87c4e1aab30) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 16:44:58.0000 2420 mdmxsdk - ok 16:44:58.0062 2420 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 16:44:58.0093 2420 mnmdd - ok 16:44:58.0156 2420 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 16:44:58.0156 2420 Modem - ok 16:44:58.0187 2420 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys 16:44:58.0187 2420 MODEMCSA - ok 16:44:58.0218 2420 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 16:44:58.0265 2420 Mouclass - ok 16:44:58.0328 2420 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 16:44:58.0375 2420 MountMgr - ok 16:44:58.0421 2420 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 16:44:58.0421 2420 mraid35x - ok 16:44:58.0484 2420 mrtRate (6075de2ad531f6e30c9995dfda22001f) C:\WINDOWS\system32\drivers\mrtRate.sys 16:44:58.0531 2420 mrtRate - ok 16:44:58.0578 2420 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 16:44:58.0609 2420 MRxDAV - ok 16:44:58.0687 2420 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 16:44:58.0718 2420 MRxSmb - ok 16:44:58.0781 2420 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 16:44:58.0812 2420 Msfs - ok 16:44:58.0890 2420 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 16:44:58.0921 2420 MSKSSRV - ok 16:44:58.0968 2420 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 16:44:58.0968 2420 MSPCLOCK - ok 16:44:59.0031 2420 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 16:44:59.0078 2420 MSPQM - ok 16:44:59.0156 2420 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16:44:59.0203 2420 mssmbios - ok 16:44:59.0265 2420 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 16:44:59.0312 2420 Mup - ok 16:44:59.0343 2420 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 16:44:59.0421 2420 NDIS - ok 16:44:59.0468 2420 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 16:44:59.0468 2420 NdisTapi - ok 16:44:59.0500 2420 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16:44:59.0578 2420 Ndisuio - ok 16:44:59.0625 2420 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 16:44:59.0656 2420 NdisWan - ok 16:44:59.0703 2420 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 16:44:59.0750 2420 NDProxy - ok 16:44:59.0812 2420 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 16:44:59.0843 2420 NetBIOS - ok 16:44:59.0937 2420 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 16:44:59.0953 2420 NetBT - ok 16:45:00.0015 2420 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 16:45:00.0031 2420 Npfs - ok 16:45:00.0109 2420 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 16:45:00.0140 2420 Ntfs - ok 16:45:00.0171 2420 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 16:45:00.0187 2420 Null - ok 16:45:00.0281 2420 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 16:45:00.0328 2420 nv - ok 16:45:00.0359 2420 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 16:45:00.0421 2420 NwlnkFlt - ok 16:45:00.0453 2420 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 16:45:00.0468 2420 NwlnkFwd - ok 16:45:00.0500 2420 omci (53d5f1278d9edb21689bbbcecc09108d) C:\WINDOWS\system32\DRIVERS\omci.sys 16:45:00.0562 2420 omci - ok 16:45:00.0625 2420 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 16:45:00.0671 2420 Parport - ok 16:45:00.0718 2420 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 16:45:00.0718 2420 PartMgr - ok 16:45:00.0750 2420 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 16:45:00.0750 2420 ParVdm - ok 16:45:00.0765 2420 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 16:45:00.0859 2420 PCI - ok 16:45:00.0859 2420 PCIDump - ok 16:45:00.0890 2420 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 16:45:00.0937 2420 PCIIde - ok 16:45:00.0968 2420 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 16:45:01.0031 2420 Pcmcia - ok 16:45:01.0062 2420 PDCOMP - ok 16:45:01.0078 2420 PDFRAME - ok 16:45:01.0093 2420 PDRELI - ok 16:45:01.0093 2420 PDRFRAME - ok 16:45:01.0140 2420 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 16:45:01.0171 2420 perc2 - ok 16:45:01.0234 2420 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 16:45:01.0234 2420 perc2hib - ok 16:45:01.0312 2420 pfc (444f122e68db44c0589227781f3c8b3f) C:\WINDOWS\system32\drivers\pfc.sys 16:45:01.0390 2420 pfc - ok 16:45:01.0453 2420 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 16:45:01.0515 2420 PptpMiniport - ok 16:45:01.0578 2420 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 16:45:01.0625 2420 PSched - ok 16:45:01.0687 2420 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 16:45:01.0718 2420 Ptilink - ok 16:45:01.0765 2420 PxHelp20 (1962166e0ceb740704f30fa55ad3d509) C:\WINDOWS\system32\Drivers\PxHelp20.sys 16:45:01.0828 2420 PxHelp20 - ok 16:45:01.0843 2420 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 16:45:01.0859 2420 ql1080 - ok 16:45:01.0875 2420 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 16:45:01.0875 2420 Ql10wnt - ok 16:45:01.0937 2420 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 16:45:01.0968 2420 ql12160 - ok 16:45:02.0015 2420 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 16:45:02.0062 2420 ql1240 - ok 16:45:02.0078 2420 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 16:45:02.0093 2420 ql1280 - ok 16:45:02.0140 2420 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 16:45:02.0203 2420 RasAcd - ok 16:45:02.0250 2420 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 16:45:02.0250 2420 Rasl2tp - ok 16:45:02.0312 2420 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 16:45:02.0390 2420 RasPppoe - ok 16:45:02.0406 2420 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 16:45:02.0484 2420 Raspti - ok 16:45:02.0500 2420 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 16:45:02.0515 2420 Rdbss - ok 16:45:02.0531 2420 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 16:45:02.0562 2420 RDPCDD - ok 16:45:02.0625 2420 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 16:45:02.0625 2420 rdpdr - ok 16:45:02.0687 2420 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 16:45:02.0703 2420 RDPWD - ok 16:45:02.0750 2420 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 16:45:02.0765 2420 redbook - ok 16:45:02.0875 2420 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 16:45:02.0937 2420 Secdrv - ok 16:45:02.0984 2420 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 16:45:02.0984 2420 serenum - ok 16:45:03.0000 2420 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 16:45:03.0046 2420 Serial - ok 16:45:03.0078 2420 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 16:45:03.0109 2420 Sfloppy - ok 16:45:03.0125 2420 Simbad - ok 16:45:03.0171 2420 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys 16:45:03.0171 2420 sisagp - ok 16:45:03.0234 2420 smwdm (4aa922332433cdeb8b82c072c212e32e) C:\WINDOWS\system32\drivers\smwdm.sys 16:45:03.0328 2420 smwdm - ok 16:45:03.0421 2420 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 16:45:03.0468 2420 Sparrow - ok 16:45:03.0531 2420 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 16:45:03.0531 2420 splitter - ok 16:45:03.0593 2420 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 16:45:03.0656 2420 sr - ok 16:45:03.0718 2420 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 16:45:03.0796 2420 Srv - ok 16:45:03.0859 2420 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys 16:45:03.0875 2420 sscdbhk5 - ok 16:45:03.0890 2420 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys 16:45:03.0968 2420 ssrtln - ok 16:45:04.0031 2420 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 16:45:04.0046 2420 swenum - ok 16:45:04.0078 2420 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 16:45:04.0093 2420 swmidi - ok 16:45:04.0109 2420 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 16:45:04.0187 2420 symc810 - ok 16:45:04.0203 2420 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 16:45:04.0203 2420 symc8xx - ok 16:45:04.0218 2420 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 16:45:04.0250 2420 sym_hi - ok 16:45:04.0265 2420 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 16:45:04.0265 2420 sym_u3 - ok 16:45:04.0312 2420 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 16:45:04.0359 2420 sysaudio - ok 16:45:04.0421 2420 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 16:45:04.0562 2420 Tcpip - ok 16:45:04.0656 2420 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 16:45:04.0703 2420 TDPIPE - ok 16:45:04.0765 2420 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 16:45:04.0796 2420 TDTCP - ok 16:45:04.0843 2420 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 16:45:04.0875 2420 TermDD - ok 16:45:04.0984 2420 tfsnboio (1d265cd2fb1673a0873bf8cec19ddc7f) C:\WINDOWS\system32\dla\tfsnboio.sys 16:45:05.0031 2420 tfsnboio - ok 16:45:05.0078 2420 tfsncofs (62e4901295e0467cac78e5b4b131ae5c) C:\WINDOWS\system32\dla\tfsncofs.sys 16:45:05.0171 2420 tfsncofs - ok 16:45:05.0218 2420 tfsndrct (a2f380f9252ab3464c859adf91eead9c) C:\WINDOWS\system32\dla\tfsndrct.sys 16:45:05.0265 2420 tfsndrct - ok 16:45:05.0312 2420 tfsndres (eee79bbefe9c6a2a3ce6c8753cfea950) C:\WINDOWS\system32\dla\tfsndres.sys 16:45:05.0390 2420 tfsndres - ok 16:45:05.0453 2420 tfsnifs (9d644eb11fec9487450c4cfcd63a5df4) C:\WINDOWS\system32\dla\tfsnifs.sys 16:45:05.0531 2420 tfsnifs - ok 16:45:05.0562 2420 tfsnopio (e656af05c67edb7c0e9230a5df71ed1b) C:\WINDOWS\system32\dla\tfsnopio.sys 16:45:05.0656 2420 tfsnopio - ok 16:45:05.0718 2420 tfsnpool (64fccb9cce703ca507dffc3cebf6b2cb) C:\WINDOWS\system32\dla\tfsnpool.sys 16:45:05.0781 2420 tfsnpool - ok 16:45:05.0828 2420 tfsnudf (48bc9d8ab4e4b9bff70fb18e55cec3d6) C:\WINDOWS\system32\dla\tfsnudf.sys 16:45:05.0859 2420 tfsnudf - ok 16:45:05.0984 2420 tfsnudfa (79f60822224256b49bfc855da8d651d5) C:\WINDOWS\system32\dla\tfsnudfa.sys 16:45:06.0046 2420 tfsnudfa - ok 16:45:06.0140 2420 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 16:45:06.0140 2420 TosIde - ok 16:45:06.0203 2420 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 16:45:06.0250 2420 Udfs - ok 16:45:06.0281 2420 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 16:45:06.0281 2420 ultra - ok 16:45:06.0343 2420 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 16:45:06.0375 2420 Update - ok 16:45:06.0437 2420 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 16:45:06.0468 2420 usbccgp - ok 16:45:06.0515 2420 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 16:45:06.0515 2420 usbehci - ok 16:45:06.0562 2420 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 16:45:06.0593 2420 usbhub - ok 16:45:06.0703 2420 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 16:45:06.0703 2420 usbscan - ok 16:45:06.0750 2420 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 16:45:06.0750 2420 USBSTOR - ok 16:45:06.0812 2420 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 16:45:06.0859 2420 usbuhci - ok 16:45:06.0906 2420 usb_rndisx (b6cc50279d6cd28e090a5d33244adc9a) C:\WINDOWS\system32\DRIVERS\usb8023x.sys 16:45:06.0937 2420 usb_rndisx - ok 16:45:06.0984 2420 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 16:45:07.0000 2420 VgaSave - ok 16:45:07.0093 2420 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys 16:45:07.0093 2420 viaagp - ok 16:45:07.0125 2420 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 16:45:07.0125 2420 ViaIde - ok 16:45:07.0140 2420 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 16:45:07.0171 2420 VolSnap - ok 16:45:07.0218 2420 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 16:45:07.0250 2420 Wanarp - ok 16:45:07.0265 2420 wanatw - ok 16:45:07.0281 2420 WDICA - ok 16:45:07.0328 2420 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 16:45:07.0359 2420 wdmaud - ok 16:45:07.0437 2420 winachsf (f59ed5a43b988a18ef582bb07b2327a7) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 16:45:07.0515 2420 winachsf - ok 16:45:07.0609 2420 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 16:45:07.0703 2420 WudfPf - ok 16:45:07.0765 2420 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 16:45:07.0843 2420 WudfRd - ok 16:45:07.0906 2420 MBR (0x1B8) (9c603bc3977968c891de319283e1e7af) \Device\Harddisk0\DR0 16:45:07.0906 2420 \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - infected 16:45:07.0906 2420 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Wistler.a (0) 16:45:07.0906 2420 MBR (0x1B8) (b16a2359f4962b0c622d81a1c1f4b703) \Device\Harddisk1\DR4 16:45:07.0906 2420 \Device\Harddisk1\DR4 - ok 16:45:07.0921 2420 Boot (0x1200) (6755ac694578a40eb27944f7dda2b76b) \Device\Harddisk0\DR0\Partition0 16:45:07.0921 2420 \Device\Harddisk0\DR0\Partition0 - ok 16:45:08.0312 2420 Boot (0x1200) (b1e27aa018409de6bfd73f8afb883a65) \Device\Harddisk1\DR4\Partition0 16:45:08.0312 2420 \Device\Harddisk1\DR4\Partition0 - ok 16:45:08.0312 2420 ============================================================ 16:45:08.0312 2420 Scan finished 16:45:08.0312 2420 ============================================================ 16:45:08.0328 2816 Detected object count: 1 16:45:08.0328 2816 Actual detected object count: 1 16:47:00.0375 2816 \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - will be cured on reboot 16:47:00.0375 2816 \Device\Harddisk0\DR0 - ok 16:47:00.0375 2816 \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - User select action: Cure 16:47:24.0312 2848 Deinitialize success

Attachments:

Hello symbiosis7

Thank you for the log.

looks like zipping the mbr file allowed the upload

That did the job nicely :thumbup:

Please run ComboFix again and post the log in your next reply.

If ComboFix notifies you that an update is available please allow it to be installed :)
combofix done!

ComboFix 11-11-14.02 - T. Carlberg 11/14/2011 12:15:32.6.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.315 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
F:\autorun.inf . . . . Failed to delete
.
.
((((((((((((((((((((((((( Files Created from 2011-10-14 to 2011-11-14 )))))))))))))))))))))))))))))))
.
.
2011-11-13 19:17 . 2011-11-13 19:17 ——– d—–w- C:\_OTL
2011-11-12 21:25 . 2011-06-24 14:10 139656 ——w- c:\windows\system32\dllcache\rdpwd.sys
2011-11-12 21:25 . 2011-07-08 14:02 10496 ——w- c:\windows\system32\dllcache\ndistapi.sys
2011-11-04 19:49 . 2011-11-04 19:49 ——– d—–w- c:\program files\FamilySearch
2011-10-31 04:30 . 2011-11-03 01:06 ——– d—–w- c:\documents and settings\T. Carlberg\Application Data\Amazon
2011-10-31 04:29 . 2011-11-03 01:06 ——– d—–w- c:\program files\Amazon
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-10 14:22 . 2004-08-04 11:00 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-04 11:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 19:41 . 2008-07-30 02:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 19:41 . 2004-08-04 11:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 19:41 . 2004-08-04 11:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-13 03:17 . 2007-01-06 00:29 29712 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2011-09-06 13:20 . 2004-08-04 11:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-08-17 21:32 . 2004-08-04 11:00 832512 —-a-w- c:\windows\system32\wininet.dll
2011-08-17 21:32 . 2004-08-04 11:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2011-08-17 21:32 . 2004-08-04 11:00 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2011-08-17 21:32 . 2004-08-04 11:00 17408 —-a-w- c:\windows\system32\corpol.dll
2011-08-17 13:49 . 2004-08-04 11:00 138496 —-a-w- c:\windows\system32\drivers\afd.sys
2011-08-17 12:22 . 2004-08-04 11:00 389120 —-a-w- c:\windows\system32\html.iec
2006-10-10 21:09 . 2006-10-10 21:09 1053198 —-a-w- c:\program files\freemahjongg.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-12_21.13.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-01-29 08:58 . 2011-07-08 13:49 46080 c:\windows\SYSTEM32\tzchange.exe
- 2007-01-29 08:58 . 2010-11-03 13:12 46080 c:\windows\SYSTEM32\tzchange.exe
- 2005-06-19 08:58 . 2007-07-28 06:11 26488 c:\windows\SYSTEM32\spupdsvc.exe
+ 2005-06-19 08:58 . 2011-08-12 21:51 26488 c:\windows\SYSTEM32\spupdsvc.exe
- 2004-08-04 11:00 . 2011-04-25 15:51 44544 c:\windows\SYSTEM32\pngfilt.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 44544 c:\windows\SYSTEM32\pngfilt.dll
+ 2004-11-18 08:24 . 2011-11-13 08:59 72160 c:\windows\SYSTEM32\PERFC009.DAT
- 2006-10-27 23:09 . 2011-04-25 15:51 52224 c:\windows\SYSTEM32\msfeedsbs.dll
+ 2006-10-27 23:09 . 2011-08-17 21:32 52224 c:\windows\SYSTEM32\msfeedsbs.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 27648 c:\windows\SYSTEM32\jsproxy.dll
- 2004-08-04 11:00 . 2011-04-25 15:51 27648 c:\windows\SYSTEM32\jsproxy.dll
- 2006-10-27 10:44 . 2011-04-25 12:00 13824 c:\windows\SYSTEM32\ieudinit.exe
+ 2006-10-27 10:44 . 2011-08-17 12:21 13824 c:\windows\SYSTEM32\ieudinit.exe
+ 2004-08-04 11:00 . 2011-08-17 21:32 44544 c:\windows\SYSTEM32\iernonce.dll
- 2004-08-04 11:00 . 2011-04-25 15:51 44544 c:\windows\SYSTEM32\iernonce.dll
+ 2004-08-04 11:00 . 2011-08-17 12:21 70656 c:\windows\SYSTEM32\ie4uinit.exe
- 2004-08-04 11:00 . 2011-04-25 12:00 70656 c:\windows\SYSTEM32\ie4uinit.exe
+ 2006-10-17 20:58 . 2011-08-17 21:32 63488 c:\windows\SYSTEM32\icardie.dll
- 2006-10-17 20:58 . 2011-04-25 15:51 63488 c:\windows\SYSTEM32\icardie.dll
+ 2004-08-04 11:00 . 2011-07-08 14:02 10496 c:\windows\SYSTEM32\DRIVERS\ndistapi.sys
+ 2006-05-10 05:23 . 2011-08-17 21:32 44544 c:\windows\SYSTEM32\DLLCACHE\pngfilt.dll
- 2006-05-10 05:23 . 2011-04-25 15:51 44544 c:\windows\SYSTEM32\DLLCACHE\pngfilt.dll
+ 2011-09-26 19:41 . 2011-09-26 19:41 20480 c:\windows\SYSTEM32\DLLCACHE\oleaccrc.dll
+ 2007-05-10 01:08 . 2011-08-17 21:32 52224 c:\windows\SYSTEM32\DLLCACHE\msfeedsbs.dll
- 2007-05-10 01:08 . 2011-04-25 15:51 52224 c:\windows\SYSTEM32\DLLCACHE\msfeedsbs.dll
- 2006-05-10 05:22 . 2011-04-25 15:51 27648 c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
+ 2006-05-10 05:22 . 2011-08-17 21:32 27648 c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
+ 2007-05-10 01:08 . 2011-08-17 12:21 13824 c:\windows\SYSTEM32\DLLCACHE\ieudinit.exe
- 2007-05-10 01:08 . 2011-04-25 12:00 13824 c:\windows\SYSTEM32\DLLCACHE\ieudinit.exe
- 2006-10-27 10:44 . 2011-04-25 15:51 44544 c:\windows\SYSTEM32\DLLCACHE\iernonce.dll
+ 2006-10-27 10:44 . 2011-08-17 21:32 44544 c:\windows\SYSTEM32\DLLCACHE\iernonce.dll
+ 2009-02-20 18:09 . 2011-08-17 21:32 78336 c:\windows\SYSTEM32\DLLCACHE\ieencode.dll
- 2009-02-20 18:09 . 2011-04-25 15:51 78336 c:\windows\SYSTEM32\DLLCACHE\ieencode.dll
+ 2006-10-27 10:44 . 2011-08-17 12:21 70656 c:\windows\SYSTEM32\DLLCACHE\ie4uinit.exe
- 2006-10-27 10:44 . 2011-04-25 12:00 70656 c:\windows\SYSTEM32\DLLCACHE\ie4uinit.exe
- 2007-08-20 10:04 . 2011-04-25 15:51 63488 c:\windows\SYSTEM32\DLLCACHE\icardie.dll
+ 2007-08-20 10:04 . 2011-08-17 21:32 63488 c:\windows\SYSTEM32\DLLCACHE\icardie.dll
- 2009-12-14 07:08 . 2010-12-09 14:30 33280 c:\windows\SYSTEM32\DLLCACHE\csrsrv.dll
+ 2009-12-14 07:08 . 2011-04-26 11:07 33280 c:\windows\SYSTEM32\DLLCACHE\csrsrv.dll
- 2009-06-29 16:12 . 2011-04-25 15:51 17408 c:\windows\SYSTEM32\DLLCACHE\corpol.dll
+ 2009-06-29 16:12 . 2011-08-17 21:32 17408 c:\windows\SYSTEM32\DLLCACHE\corpol.dll
- 2004-08-04 11:00 . 2010-12-09 14:30 33280 c:\windows\SYSTEM32\csrsrv.dll
+ 2004-08-04 11:00 . 2011-04-26 11:07 33280 c:\windows\SYSTEM32\csrsrv.dll
- 2011-09-09 23:10 . 2011-09-09 23:10 78924 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\AntiPhishing\A0AB7674-8D67-4F4D-B5E1-96FAEADFB79D.dat
+ 2011-11-14 00:47 . 2011-11-14 00:47 78924 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\AntiPhishing\A0AB7674-8D67-4F4D-B5E1-96FAEADFB79D.dat
- 2010-09-23 22:55 . 2010-09-23 22:55 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2011-07-08 22:00 . 2011-07-08 22:00 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
- 2010-09-23 09:26 . 2010-09-23 09:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2011-07-07 20:04 . 2011-07-07 20:04 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2011-07-07 20:04 . 2011-07-07 20:04 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2010-09-23 09:26 . 2010-09-23 09:26 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2010-09-23 09:26 . 2010-09-23 09:26 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2011-07-07 20:03 . 2011-07-07 20:03 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2011-07-07 21:09 . 2011-07-07 21:09 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2010-09-23 10:17 . 2010-09-23 10:17 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2011-07-07 21:09 . 2011-07-07 21:09 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
- 2010-09-23 10:17 . 2010-09-23 10:17 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 44544 c:\windows\ie7updates\KB2586448-IE7\pngfilt.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 52224 c:\windows\ie7updates\KB2586448-IE7\msfeedsbs.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 27648 c:\windows\ie7updates\KB2586448-IE7\jsproxy.dll
+ 2011-11-13 08:32 . 2011-04-25 12:00 13824 c:\windows\ie7updates\KB2586448-IE7\ieudinit.exe
+ 2011-11-13 08:32 . 2011-04-25 15:51 44544 c:\windows\ie7updates\KB2586448-IE7\iernonce.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 78336 c:\windows\ie7updates\KB2586448-IE7\ieencode.dll
+ 2011-11-13 08:32 . 2011-04-25 12:00 70656 c:\windows\ie7updates\KB2586448-IE7\ie4uinit.exe
+ 2011-11-13 08:32 . 2011-04-25 15:51 63488 c:\windows\ie7updates\KB2586448-IE7\icardie.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 17408 c:\windows\ie7updates\KB2586448-IE7\corpol.dll
+ 2011-11-13 18:43 . 2011-11-13 18:43 90112 c:\windows\ASSEMBLY\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_94f2add1\System.Drawing.Design.dll
+ 2011-11-13 18:42 . 2011-11-13 18:42 61440 c:\windows\ASSEMBLY\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_27cabedc\CustomMarshalers.dll
+ 2011-11-13 08:49 . 2011-11-13 08:49 60928 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\UIAutomationProvider\e945a5f391364545485d15af876ab830\UIAutomationProvider.ni.dll
+ 2011-11-13 18:48 . 2011-11-13 18:48 60928 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\UIAutomationProvider\888b745ca99d39692c2e9af222e5eae8\UIAutomationProvider.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 21504 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\TVM\78224b12859d6696032e4410a13f8d94\TVM.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 37888 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Windows.Pres#\6c334564da041df8fb75415f2d503224\System.Windows.Presentation.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 36864 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.DynamicD#\a54a122f1070ab71931dd9679ddd8e90\System.Web.DynamicData.Design.ni.dll
+ 2011-11-13 18:53 . 2011-11-13 18:53 94208 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.ComponentMod#\ac92806d5bd508eb25f1b4b73a36b101\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-11-13 18:53 . 2011-11-13 18:53 82944 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.AddIn.Contra#\e6a9cd66d11a21776dbf425e8e28099c\System.AddIn.Contract.ni.dll
+ 2011-11-13 18:44 . 2011-11-13 18:44 47104 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\PresentationFontCac#\66873b557d5c7013e4c630361473b0c2\PresentationFontCache.ni.exe
+ 2011-11-13 18:42 . 2011-11-13 18:42 39424 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\PresentationCFFRast#\5b30652a7b802199984f93b5e414260f\PresentationCFFRasterizer.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 55296 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Vsa\eaa8d72317e5b8047e413939cc71ffba\Microsoft.Vsa.ni.dll
+ 2011-11-13 18:51 . 2011-11-13 18:51 15872 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.VisualC\a140509b1342934fc5e58ae22ac9696c\Microsoft.VisualC.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 74752 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\aefe683674c97a998f4e908c1a7ee7c6\Microsoft.Build.Framework.ni.dll
+ 2011-11-13 18:53 . 2011-11-13 18:53 65024 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\845eef4d09f28da6ee05d99f93c90f6e\Microsoft.Build.Framework.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 68608 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Intuit.Ctg.Wte.Inte#\0ea5a5c4bd15ef1076a3719ae918f937\Intuit.Ctg.Wte.InterviewControlLibrary.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 14336 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\dfsvc\ab7ce2d94ca725c3889a4e3c1ee88ece\dfsvc.ni.exe
+ 2011-11-13 18:50 . 2011-11-13 18:50 25600 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 77824 c:\windows\ASSEMBLY\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 77824 c:\windows\ASSEMBLY\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 81920 c:\windows\ASSEMBLY\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 81920 c:\windows\ASSEMBLY\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 81920 c:\windows\ASSEMBLY\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 81920 c:\windows\ASSEMBLY\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 32768 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 32768 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 12800 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 12800 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 28672 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 28672 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 77824 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 77824 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 36864 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 36864 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 77824 c:\windows\ASSEMBLY\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 77824 c:\windows\ASSEMBLY\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 13312 c:\windows\ASSEMBLY\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 13312 c:\windows\ASSEMBLY\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 10752 c:\windows\ASSEMBLY\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 10752 c:\windows\ASSEMBLY\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 72192 c:\windows\ASSEMBLY\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 72192 c:\windows\ASSEMBLY\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 69120 c:\windows\ASSEMBLY\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 69120 c:\windows\ASSEMBLY\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2010-10-07 05:57 . 2010-10-07 05:57 81920 c:\windows\ASSEMBLY\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-11-13 08:28 . 2011-11-13 08:28 81920 c:\windows\ASSEMBLY\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 7168 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 7168 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 5632 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 5632 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2011-04-13 07:54 . 2011-04-13 07:54 6656 c:\windows\ASSEMBLY\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 6656 c:\windows\ASSEMBLY\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 8192 c:\windows\ASSEMBLY\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 8192 c:\windows\ASSEMBLY\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2004-08-04 11:00 . 2010-06-18 17:45 293376 c:\windows\SYSTEM32\winsrv.dll
+ 2004-08-04 11:00 . 2011-06-20 17:44 293376 c:\windows\SYSTEM32\winsrv.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 233472 c:\windows\SYSTEM32\webcheck.dll
- 2004-08-04 11:00 . 2011-04-25 15:51 233472 c:\windows\SYSTEM32\webcheck.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 106496 c:\windows\SYSTEM32\url.dll
+ 2004-08-04 11:00 . 2011-04-29 17:25 151552 c:\windows\SYSTEM32\schannel.dll
+ 2004-11-18 08:24 . 2011-11-13 08:59 442894 c:\windows\SYSTEM32\PERFH009.DAT
- 2004-08-04 11:00 . 2011-04-25 15:51 102912 c:\windows\SYSTEM32\occache.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 102912 c:\windows\SYSTEM32\occache.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 671232 c:\windows\SYSTEM32\mstime.dll
- 2004-08-04 11:00 . 2011-04-25 15:51 671232 c:\windows\SYSTEM32\mstime.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 193024 c:\windows\SYSTEM32\msrating.dll
- 2004-08-04 11:00 . 2011-04-25 15:51 193024 c:\windows\SYSTEM32\msrating.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 478720 c:\windows\SYSTEM32\mshtmled.dll
+ 2006-10-27 23:09 . 2011-08-17 21:32 468480 c:\windows\SYSTEM32\msfeeds.dll
- 2006-10-27 23:09 . 2011-04-25 15:51 468480 c:\windows\SYSTEM32\msfeeds.dll
+ 2006-10-17 20:57 . 2011-08-17 21:32 268288 c:\windows\SYSTEM32\iertutil.dll
- 2006-10-17 20:57 . 2011-04-25 15:51 268288 c:\windows\SYSTEM32\iertutil.dll
- 2004-08-04 11:00 . 2011-04-25 15:51 192512 c:\windows\SYSTEM32\iepeers.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 192512 c:\windows\SYSTEM32\iepeers.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 384512 c:\windows\SYSTEM32\iedkcs32.dll
- 2004-08-04 11:00 . 2011-04-25 15:51 384512 c:\windows\SYSTEM32\iedkcs32.dll
+ 2006-10-17 20:27 . 2011-08-17 21:32 380928 c:\windows\SYSTEM32\ieapfltr.dll
- 2006-10-17 20:27 . 2011-04-25 15:51 380928 c:\windows\SYSTEM32\ieapfltr.dll
- 2004-08-04 11:00 . 2011-04-21 10:56 161792 c:\windows\SYSTEM32\ieakui.dll
+ 2004-08-04 11:00 . 2011-08-17 11:00 161792 c:\windows\SYSTEM32\ieakui.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 230400 c:\windows\SYSTEM32\ieaksie.dll
- 2004-08-04 11:00 . 2011-04-25 15:51 230400 c:\windows\SYSTEM32\ieaksie.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 153088 c:\windows\SYSTEM32\ieakeng.dll
- 2004-08-04 11:00 . 2011-04-25 15:51 153088 c:\windows\SYSTEM32\ieakeng.dll
+ 2004-08-10 19:08 . 2011-11-13 18:40 253472 c:\windows\SYSTEM32\FNTCACHE.DAT
- 2004-08-10 19:08 . 2011-04-13 15:12 253472 c:\windows\SYSTEM32\FNTCACHE.DAT
- 2004-08-04 11:00 . 2011-04-25 15:51 133120 c:\windows\SYSTEM32\extmgr.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 133120 c:\windows\SYSTEM32\extmgr.dll
- 2004-08-04 11:00 . 2011-04-25 15:51 214528 c:\windows\SYSTEM32\dxtrans.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 214528 c:\windows\SYSTEM32\dxtrans.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 347136 c:\windows\SYSTEM32\dxtmsft.dll
- 2004-08-04 11:00 . 2011-04-25 15:51 347136 c:\windows\SYSTEM32\dxtmsft.dll
- 2004-08-04 11:00 . 2008-04-14 00:13 139656 c:\windows\SYSTEM32\DRIVERS\rdpwd.sys
+ 2004-08-04 11:00 . 2011-06-24 14:10 139656 c:\windows\SYSTEM32\DRIVERS\rdpwd.sys
- 2004-08-04 11:00 . 2011-04-29 16:19 456320 c:\windows\SYSTEM32\DRIVERS\mrxsmb.sys
+ 2004-08-04 11:00 . 2011-07-15 13:29 456320 c:\windows\SYSTEM32\DRIVERS\mrxsmb.sys
- 2010-06-18 17:45 . 2010-06-18 17:45 293376 c:\windows\SYSTEM32\DLLCACHE\winsrv.dll
+ 2010-06-18 17:45 . 2011-06-20 17:44 293376 c:\windows\SYSTEM32\DLLCACHE\winsrv.dll
+ 2006-05-10 05:23 . 2011-08-17 21:32 832512 c:\windows\SYSTEM32\DLLCACHE\wininet.dll
- 2006-05-10 05:23 . 2011-04-25 15:51 832512 c:\windows\SYSTEM32\DLLCACHE\wininet.dll
- 2006-10-27 23:09 . 2011-04-25 15:51 233472 c:\windows\SYSTEM32\DLLCACHE\webcheck.dll
+ 2006-10-27 23:09 . 2011-08-17 21:32 233472 c:\windows\SYSTEM32\DLLCACHE\webcheck.dll
+ 2006-10-17 21:05 . 2011-08-17 21:32 106496 c:\windows\SYSTEM32\DLLCACHE\url.dll
+ 2008-12-05 06:54 . 2011-04-29 17:25 151552 c:\windows\SYSTEM32\DLLCACHE\schannel.dll
+ 2011-09-26 19:41 . 2011-09-26 19:41 220160 c:\windows\SYSTEM32\DLLCACHE\oleacc.dll
- 2006-10-17 21:04 . 2011-04-25 15:51 102912 c:\windows\SYSTEM32\DLLCACHE\occache.dll
+ 2006-10-17 21:04 . 2011-08-17 21:32 102912 c:\windows\SYSTEM32\DLLCACHE\occache.dll
+ 2006-05-10 05:23 . 2011-08-17 21:32 671232 c:\windows\SYSTEM32\DLLCACHE\mstime.dll
- 2006-05-10 05:23 . 2011-04-25 15:51 671232 c:\windows\SYSTEM32\DLLCACHE\mstime.dll
+ 2006-05-10 05:23 . 2011-08-17 21:32 193024 c:\windows\SYSTEM32\DLLCACHE\msrating.dll
- 2006-05-10 05:23 . 2011-04-25 15:51 193024 c:\windows\SYSTEM32\DLLCACHE\msrating.dll
+ 2006-05-10 05:23 . 2011-08-17 21:32 478720 c:\windows\SYSTEM32\DLLCACHE\mshtmled.dll
- 2007-05-10 01:08 . 2011-04-25 15:51 468480 c:\windows\SYSTEM32\DLLCACHE\msfeeds.dll
+ 2007-05-10 01:08 . 2011-08-17 21:32 468480 c:\windows\SYSTEM32\DLLCACHE\msfeeds.dll
+ 2008-11-20 02:15 . 2011-07-15 13:29 456320 c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
- 2008-11-20 02:15 . 2011-04-29 16:19 456320 c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
- 2008-08-15 03:36 . 2011-05-02 15:31 692736 c:\windows\SYSTEM32\DLLCACHE\inetcomm.dll
+ 2008-08-15 03:36 . 2011-10-10 14:22 692736 c:\windows\SYSTEM32\DLLCACHE\inetcomm.dll
+ 2006-10-17 21:04 . 2011-08-17 11:01 634632 c:\windows\SYSTEM32\DLLCACHE\iexplore.exe
- 2007-05-10 01:08 . 2011-04-25 15:51 268288 c:\windows\SYSTEM32\DLLCACHE\iertutil.dll
+ 2007-05-10 01:08 . 2011-08-17 21:32 268288 c:\windows\SYSTEM32\DLLCACHE\iertutil.dll
+ 2006-05-10 05:22 . 2011-08-17 21:32 192512 c:\windows\SYSTEM32\DLLCACHE\iepeers.dll
- 2006-05-10 05:22 . 2011-04-25 15:51 192512 c:\windows\SYSTEM32\DLLCACHE\iepeers.dll
- 2006-10-27 10:44 . 2011-04-25 15:51 384512 c:\windows\SYSTEM32\DLLCACHE\iedkcs32.dll
+ 2006-10-27 10:44 . 2011-08-17 21:32 384512 c:\windows\SYSTEM32\DLLCACHE\iedkcs32.dll
- 2007-05-10 01:08 . 2011-04-25 15:51 380928 c:\windows\SYSTEM32\DLLCACHE\ieapfltr.dll
+ 2007-05-10 01:08 . 2011-08-17 21:32 380928 c:\windows\SYSTEM32\DLLCACHE\ieapfltr.dll
+ 2006-10-27 10:42 . 2011-08-17 11:00 161792 c:\windows\SYSTEM32\DLLCACHE\ieakui.dll
- 2006-10-27 10:42 . 2011-04-21 10:56 161792 c:\windows\SYSTEM32\DLLCACHE\ieakui.dll
- 2006-10-27 10:44 . 2011-04-25 15:51 230400 c:\windows\SYSTEM32\DLLCACHE\ieaksie.dll
+ 2006-10-27 10:44 . 2011-08-17 21:32 230400 c:\windows\SYSTEM32\DLLCACHE\ieaksie.dll
- 2006-10-27 10:44 . 2011-04-25 15:51 153088 c:\windows\SYSTEM32\DLLCACHE\ieakeng.dll
+ 2006-10-27 10:44 . 2011-08-17 21:32 153088 c:\windows\SYSTEM32\DLLCACHE\ieakeng.dll
+ 2006-05-10 05:22 . 2011-08-17 21:32 133120 c:\windows\SYSTEM32\DLLCACHE\extmgr.dll
- 2006-05-10 05:22 . 2011-04-25 15:51 133120 c:\windows\SYSTEM32\DLLCACHE\extmgr.dll
- 2006-05-10 05:22 . 2011-04-25 15:51 214528 c:\windows\SYSTEM32\DLLCACHE\dxtrans.dll
+ 2006-05-10 05:22 . 2011-08-17 21:32 214528 c:\windows\SYSTEM32\DLLCACHE\dxtrans.dll
+ 2006-05-10 05:22 . 2011-08-17 21:32 347136 c:\windows\SYSTEM32\DLLCACHE\dxtmsft.dll
- 2006-05-10 05:22 . 2011-04-25 15:51 347136 c:\windows\SYSTEM32\DLLCACHE\dxtmsft.dll
+ 2011-09-28 07:06 . 2011-09-28 07:06 599040 c:\windows\SYSTEM32\DLLCACHE\crypt32.dll
- 2008-06-20 11:40 . 2011-02-16 13:22 138496 c:\windows\SYSTEM32\DLLCACHE\afd.sys
+ 2008-06-20 11:40 . 2011-08-17 13:49 138496 c:\windows\SYSTEM32\DLLCACHE\afd.sys
- 2006-10-27 10:44 . 2011-04-25 15:51 124928 c:\windows\SYSTEM32\DLLCACHE\advpack.dll
+ 2006-10-27 10:44 . 2011-08-17 21:32 124928 c:\windows\SYSTEM32\DLLCACHE\advpack.dll
- 2011-06-27 03:16 . 2011-11-12 21:14 114688 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
+ 2011-06-27 03:16 . 2011-11-14 00:47 114688 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
- 2004-08-04 11:00 . 2011-04-25 15:51 124928 c:\windows\SYSTEM32\advpack.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 124928 c:\windows\SYSTEM32\advpack.dll
+ 2011-07-07 13:18 . 2011-07-07 13:18 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
- 2011-01-18 11:39 . 2011-01-18 11:39 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2011-03-25 14:15 . 2011-03-25 14:15 363856 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
- 2011-01-18 11:39 . 2011-01-18 11:39 363856 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
- 2011-01-18 11:39 . 2011-01-18 11:39 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2011-07-07 13:18 . 2011-07-07 13:18 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2011-07-07 20:04 . 2011-07-07 20:04 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2010-09-23 09:26 . 2010-09-23 09:26 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2010-09-23 09:25 . 2010-09-23 09:25 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2011-07-07 20:01 . 2011-07-07 20:01 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2011-07-07 21:09 . 2011-07-07 21:09 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
- 2010-09-23 10:17 . 2010-09-23 10:17 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 832512 c:\windows\ie7updates\KB2586448-IE7\wininet.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 233472 c:\windows\ie7updates\KB2586448-IE7\webcheck.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 105984 c:\windows\ie7updates\KB2586448-IE7\url.dll
+ 2011-11-13 08:32 . 2010-07-05 13:16 382840 c:\windows\ie7updates\KB2586448-IE7\spuninst\updspapi.dll
+ 2011-11-13 08:32 . 2010-07-05 13:15 231288 c:\windows\ie7updates\KB2586448-IE7\spuninst\spuninst.exe
+ 2011-11-13 08:32 . 2011-04-25 15:51 102912 c:\windows\ie7updates\KB2586448-IE7\occache.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 671232 c:\windows\ie7updates\KB2586448-IE7\mstime.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 193024 c:\windows\ie7updates\KB2586448-IE7\msrating.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 478208 c:\windows\ie7updates\KB2586448-IE7\mshtmled.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 468480 c:\windows\ie7updates\KB2586448-IE7\msfeeds.dll
+ 2011-11-13 08:32 . 2011-04-21 10:58 634648 c:\windows\ie7updates\KB2586448-IE7\iexplore.exe
+ 2011-11-13 08:32 . 2011-04-25 15:51 268288 c:\windows\ie7updates\KB2586448-IE7\iertutil.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 192512 c:\windows\ie7updates\KB2586448-IE7\iepeers.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 384512 c:\windows\ie7updates\KB2586448-IE7\iedkcs32.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 380928 c:\windows\ie7updates\KB2586448-IE7\ieapfltr.dll
+ 2011-11-13 08:32 . 2011-04-21 10:56 161792 c:\windows\ie7updates\KB2586448-IE7\ieakui.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 230400 c:\windows\ie7updates\KB2586448-IE7\ieaksie.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 153088 c:\windows\ie7updates\KB2586448-IE7\ieakeng.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 133120 c:\windows\ie7updates\KB2586448-IE7\extmgr.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 214528 c:\windows\ie7updates\KB2586448-IE7\dxtrans.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 347136 c:\windows\ie7updates\KB2586448-IE7\dxtmsft.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 124928 c:\windows\ie7updates\KB2586448-IE7\advpack.dll
- 2008-11-20 02:15 . 2011-04-29 16:19 456320 c:\windows\Driver Cache\I386\mrxsmb.sys
+ 2008-11-20 02:15 . 2011-07-15 13:29 456320 c:\windows\Driver Cache\I386\mrxsmb.sys
+ 2011-11-13 18:44 . 2011-11-13 18:44 835584 c:\windows\ASSEMBLY\TMP\CGRG88XS\System.Drawing.dll
+ 2011-11-13 19:47 . 2011-11-13 19:47 835584 c:\windows\ASSEMBLY\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_9e82bb5b\System.Drawing.dll
+ 2011-11-13 19:47 . 2011-11-13 19:47 192512 c:\windows\ASSEMBLY\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_8b48fd63\System.Drawing.Design.dll
+ 2011-11-13 19:47 . 2011-11-13 19:47 118784 c:\windows\ASSEMBLY\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_18c725d2\CustomMarshalers.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 321536 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\WsatConfig\c8627df7adb416722d8e0f05c57fef6b\WsatConfig.ni.exe
+ 2011-11-13 18:48 . 2011-11-13 18:48 240128 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\a2c1bb3c5b1447b398e72c56091ca571\WindowsFormsIntegration.ni.dll
+ 2011-11-13 18:48 . 2011-11-13 18:48 187904 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\UIAutomationTypes\f102afdffdbe2565bcedb7fa0626b865\UIAutomationTypes.ni.dll
+ 2011-11-13 08:49 . 2011-11-13 08:49 187904 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\UIAutomationTypes\9da95d4a319b7271d1f05f61f4b744d6\UIAutomationTypes.ni.dll
+ 2011-11-13 18:48 . 2011-11-13 18:48 447488 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\UIAutomationClient\ba55240b7753047f8d1b03ef473bf74e\UIAutomationClient.ni.dll
+ 2011-11-13 18:55 . 2011-11-13 18:55 400896 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Xml.Linq\566b2e11e7f3f6d973b17b86cf42f9bc\System.Xml.Linq.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 129536 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Routing\3533d614ebecd4344efbee619dd11a74\System.Web.Routing.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 202240 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.RegularE#\018b6e48c32d5b5d78086998e3505f1c\System.Web.RegularExpressions.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 859648 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Extensio#\d93514a764a83b18f6f3547b59cc8ae9\System.Web.Extensions.Design.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 328704 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Entity\93b5d1b77a74b76ac73cbf51ec871c01\System.Web.Entity.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 301056 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Entity.D#\d06a7d5872bbe85795f947f6c75d38c6\System.Web.Entity.Design.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 547328 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.DynamicD#\ad0851438a18bf730d974c9b2f5f776a\System.Web.DynamicData.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 141312 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Abstract#\734ab0ea87d7dfd5c583eea535c05878\System.Web.Abstractions.ni.dll
+ 2011-11-13 18:51 . 2011-11-13 18:51 627200 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Transactions\8efcd633af87989355382b5039f1b7df\System.Transactions.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 212992 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll
+ 2011-11-13 18:51 . 2011-11-13 18:51 679936 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Security\36c12de583ee81e9c99acb72b09d77ac\System.Security.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 311296 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Runtime.Seri#\81096bfe85eb0da5f05e8a127ffa43b2\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2011-11-13 18:51 . 2011-11-13 18:51 771584 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Runtime.Remo#\36bf3d5f05a40c9e3cadca5789c8a469\System.Runtime.Remoting.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 621056 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Net\b2a84980f206431821d85d5155d5916f\System.Net.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 998400 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Management\90b90e700e59d73d6d692cf74e1ba16e\System.Management.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 330752 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Management.I#\f36eded354122da9555a6c7cdbdb5431\System.Management.Instrumentation.ni.dll
+ 2011-11-13 18:50 . 2011-11-13 18:50 381440 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.IO.Log\20a77c41ee12362d303fb2574fcd5a24\System.IO.Log.ni.dll
+ 2011-11-13 18:50 . 2011-11-13 18:50 212992 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.IdentityMode#\41c3a2fcffc58b20023c7d54e57ea956\System.IdentityModel.Selectors.ni.dll
+ 2011-11-13 18:51 . 2011-11-13 18:51 280064 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.Wrapper.dll
+ 2011-11-13 18:51 . 2011-11-13 18:51 627712 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.ni.dll
+ 2011-11-13 18:47 . 2011-11-13 18:47 208384 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Drawing.Desi#\896eca06e2d9377b2dc4fad56ce49b07\System.Drawing.Design.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 455680 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.DirectorySer#\33e9b0c368c31ef37a2ec7b5a181044b\System.DirectoryServices.Protocols.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 881152 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.DirectorySer#\11cdd1c0d65428cd3505d3813d36638c\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 939008 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.Service#\e5ada332a9bc3c982e6aede6ba354196\System.Data.Services.Client.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 354816 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.Service#\3f179f373f31817a914b639a56cc0497\System.Data.Services.Design.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 756736 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.Entity.#\fee1a48b769a8c4beb335ee5ce006091\System.Data.Entity.Design.ni.dll
+ 2011-11-13 18:53 . 2011-11-13 18:53 135680 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.DataSet#\b9d9ff5d03e90ede1116794f2c7dd6da\System.Data.DataSetExtensions.ni.dll
+ 2011-11-13 18:51 . 2011-11-13 18:51 971264 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 141312 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Configuratio#\29d7091f6eab0ec61c4eb625ed221b73\System.Configuration.Install.ni.dll
+ 2011-11-13 18:53 . 2011-11-13 18:53 633856 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.AddIn\3048737e9e3bf5173121a084337256bc\System.AddIn.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 366080 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\SMSvcHost\6e45cf503f025c5fe814ea7e52f62a78\SMSvcHost.ni.exe
+ 2011-11-13 18:52 . 2011-11-13 18:52 256000 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\SMDiagnostics\474a341340f687bcbd7777f2820a8c7a\SMDiagnostics.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 320512 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\ServiceModelReg\f2df1ca28301bfe7e1d52b86c8394217\ServiceModelReg.ni.exe
+ 2011-11-13 08:54 . 2011-11-13 08:54 224768 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\PresentationFramewo#\f9eb3c7eebb63be5bd4b6350c037c9df\PresentationFramework.Classic.ni.dll
+ 2011-11-13 08:54 . 2011-11-13 08:54 368128 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\PresentationFramewo#\d4bf068c76bea484af0a8c596f5aeaa5\PresentationFramework.Aero.ni.dll
+ 2011-11-13 18:45 . 2011-11-13 18:45 539648 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\PresentationFramewo#\c2ebcc8d60422f224b4088f3d7a2ac1f\PresentationFramework.Luna.ni.dll
+ 2011-11-13 18:45 . 2011-11-13 18:45 368128 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\PresentationFramewo#\94cfc00ad448575bfb0e67c53b514cd5\PresentationFramework.Aero.ni.dll
+ 2011-11-13 08:54 . 2011-11-13 08:54 258048 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\PresentationFramewo#\8ee8c616242ded2ac2f66a5505ef79de\PresentationFramework.Royale.ni.dll
+ 2011-11-13 08:54 . 2011-11-13 08:54 539648 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\PresentationFramewo#\6ca13ff0ee3c41c0485e6060df8b9c12\PresentationFramework.Luna.ni.dll
+ 2011-11-13 18:45 . 2011-11-13 18:45 224768 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\PresentationFramewo#\478d57d96f3d8d5fc15c7ac635a4a6a1\PresentationFramework.Classic.ni.dll
+ 2011-11-13 18:45 . 2011-11-13 18:45 258048 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\PresentationFramewo#\23c5852ff8ed973ff9b63ce9ba7f91f0\PresentationFramework.Royale.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 133632 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\MSBuild\04595f414c49cf2a65b349648ba23e62\MSBuild.ni.exe
+ 2011-11-13 18:52 . 2011-11-13 18:52 386560 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Transacti#\4cbd7ed9fbf9f1b3cbdf23906cc0f5a3\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-11-13 18:53 . 2011-11-13 18:53 144384 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\ff6d4892775fd1f9b137f7c92ea453f2\Microsoft.Build.Utilities.ni.dll
+ 2011-11-13 18:53 . 2011-11-13 18:53 175104 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\47ff0720cb80a0fc0bbd15ddc3d12adc\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2011-11-13 18:53 . 2011-11-13 18:53 839680 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\da112c5757e3c68d6369b6aa46cc9682\Microsoft.Build.Engine.ni.dll
+ 2011-11-13 18:53 . 2011-11-13 18:53 222720 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\dc278e1123086ae32fec8f7e9751db14\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 696320 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\log4net\be23c163048bbb0f72cfa339ef0eb193\log4net.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 657408 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Intuit.Ctg.Wte.Serv#\b0783407654136f3cf47af5c317b796a\Intuit.Ctg.Wte.Service.Interface.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 802304 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Infragistics2.Share#\678767d5d111687c54f32a60b42d66db\Infragistics2.Shared.v8.2.ni.dll
+ 2011-11-13 18:53 . 2011-11-13 18:53 220672 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\CustomMarshalers\3e6deccf191ab943d3a0812a38ab5c97\CustomMarshalers.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 410112 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\ComSvcConfig\4e68d5df30b197ff72c75f1c3c24b949\ComSvcConfig.ni.exe
+ 2011-11-13 18:50 . 2011-11-13 18:50 842240 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\AspNetMMCExt\e1bcee92f5af50d560d577c0a99ea3bd\AspNetMMCExt.ni.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 839680 c:\windows\ASSEMBLY\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 839680 c:\windows\ASSEMBLY\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 835584 c:\windows\ASSEMBLY\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 835584 c:\windows\ASSEMBLY\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 114688 c:\windows\ASSEMBLY\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 114688 c:\windows\ASSEMBLY\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 258048 c:\windows\ASSEMBLY\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 258048 c:\windows\ASSEMBLY\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 131072 c:\windows\ASSEMBLY\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 131072 c:\windows\ASSEMBLY\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 303104 c:\windows\ASSEMBLY\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 303104 c:\windows\ASSEMBLY\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 258048 c:\windows\ASSEMBLY\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 258048 c:\windows\ASSEMBLY\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 372736 c:\windows\ASSEMBLY\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 372736 c:\windows\ASSEMBLY\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 626688 c:\windows\ASSEMBLY\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 626688 c:\windows\ASSEMBLY\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 401408 c:\windows\ASSEMBLY\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 401408 c:\windows\ASSEMBLY\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 188416 c:\windows\ASSEMBLY\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 188416 c:\windows\ASSEMBLY\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 970752 c:\windows\ASSEMBLY\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 970752 c:\windows\ASSEMBLY\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 745472 c:\windows\ASSEMBLY\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 745472 c:\windows\ASSEMBLY\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 425984 c:\windows\ASSEMBLY\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 425984 c:\windows\ASSEMBLY\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 110592 c:\windows\ASSEMBLY\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 110592 c:\windows\ASSEMBLY\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 659456 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 659456 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 372736 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 372736 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 110592 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 110592 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 749568 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 749568 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 655360 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 655360 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 348160 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 348160 c:\windows\ASSEMBLY\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 507904 c:\windows\ASSEMBLY\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 507904 c:\windows\ASSEMBLY\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 261632 c:\windows\ASSEMBLY\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 261632 c:\windows\ASSEMBLY\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 113664 c:\windows\ASSEMBLY\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 113664 c:\windows\ASSEMBLY\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 258048 c:\windows\ASSEMBLY\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 258048 c:\windows\ASSEMBLY\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-11-13 08:51 . 2011-11-13 08:58 486400 c:\windows\ASSEMBLY\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 486400 c:\windows\ASSEMBLY\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2004-08-04 11:00 . 2011-08-17 21:32 1168896 c:\windows\SYSTEM32\urlmon.dll
- 2004-08-04 11:00 . 2011-04-25 15:51 1168896 c:\windows\SYSTEM32\urlmon.dll
+ 2004-08-04 11:00 . 2011-09-05 07:48 3615744 c:\windows\SYSTEM32\mshtml.dll
- 2006-10-27 23:09 . 2011-04-25 15:51 6076416 c:\windows\SYSTEM32\ieframe.dll
+ 2006-10-27 23:09 . 2011-08-17 21:32 6076416 c:\windows\SYSTEM32\ieframe.dll
+ 2008-10-16 02:22 . 2011-09-06 13:20 1858944 c:\windows\SYSTEM32\DLLCACHE\win32k.sys
- 2006-05-10 05:23 . 2011-04-25 15:51 1168896 c:\windows\SYSTEM32\DLLCACHE\urlmon.dll
+ 2006-05-10 05:23 . 2011-08-17 21:32 1168896 c:\windows\SYSTEM32\DLLCACHE\urlmon.dll
+ 2006-05-19 15:08 . 2011-09-05 07:48 3615744 c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
+ 2007-05-10 01:08 . 2011-08-17 21:32 6076416 c:\windows\SYSTEM32\DLLCACHE\ieframe.dll
- 2007-05-10 01:08 . 2011-04-25 15:51 6076416 c:\windows\SYSTEM32\DLLCACHE\ieframe.dll
+ 2004-11-29 22:12 . 2011-11-14 00:47 4669440 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-07-25 18:17 . 2008-07-25 18:17 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2011-03-25 14:15 . 2011-03-25 14:15 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
- 2010-03-23 12:32 . 2010-03-23 12:32 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2011-04-29 05:50 . 2011-04-29 05:50 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2011-07-07 13:18 . 2011-07-07 13:18 5912400 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
- 2011-01-18 11:39 . 2011-01-18 11:39 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2011-07-07 13:18 . 2011-07-07 13:18 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2011-07-08 21:59 . 2011-07-08 21:59 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2010-09-23 22:55 . 2010-09-23 22:55 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2010-09-23 22:55 . 2010-09-23 22:55 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2011-07-08 21:59 . 2011-07-08 21:59 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2010-09-23 09:26 . 2010-09-23 09:26 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2011-07-07 20:02 . 2011-07-07 20:02 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2011-07-07 20:02 . 2011-07-07 20:02 2527232 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2011-07-08 21:59 . 2011-07-08 21:59 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
- 2010-09-23 22:55 . 2010-09-23 22:55 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2011-05-02 08:06 . 2011-05-02 08:06 2705920 c:\windows\Installer\2762812.msp
+ 2011-11-13 08:32 . 2011-04-25 15:51 1168896 c:\windows\ie7updates\KB2586448-IE7\urlmon.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 3608576 c:\windows\ie7updates\KB2586448-IE7\mshtml.dll
+ 2011-11-13 08:32 . 2011-04-25 15:51 6076416 c:\windows\ie7updates\KB2586448-IE7\ieframe.dll
+ 2011-11-13 08:29 . 2011-11-13 08:29 1966080 c:\windows\ASSEMBLY\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_35e1fc12\System.dll
+ 2011-11-13 19:47 . 2011-11-13 19:47 4792320 c:\windows\ASSEMBLY\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_2e421ff2\System.dll
+ 2011-11-13 19:47 . 2011-11-13 19:47 5513216 c:\windows\ASSEMBLY\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_9704cd60\System.Xml.dll
+ 2011-11-13 18:44 . 2011-11-13 18:44 2088960 c:\windows\ASSEMBLY\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_84370a48\System.Xml.dll
+ 2011-11-13 19:47 . 2011-11-13 19:47 7884800 c:\windows\ASSEMBLY\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_5b2516fa\System.Windows.Forms.dll
+ 2011-11-13 18:44 . 2011-11-13 18:44 3018752 c:\windows\ASSEMBLY\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_082cda3f\System.Windows.Forms.dll
+ 2011-11-13 19:47 . 2011-11-13 19:47 2244608 c:\windows\ASSEMBLY\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_1da062e1\System.Drawing.dll
+ 2011-11-13 19:47 . 2011-11-13 19:47 3395584 c:\windows\ASSEMBLY\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_8fb1f04b\System.Design.dll
+ 2011-11-13 18:44 . 2011-11-13 18:44 1470464 c:\windows\ASSEMBLY\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_5b07a861\System.Design.dll
+ 2011-11-13 19:47 . 2011-11-13 19:47 8908800 c:\windows\ASSEMBLY\NativeImages1_v1.1.4322\MSCORLIB\1.0.5000.0__b77a5c561934e089_fc381ceb\mscorlib.dll
+ 2011-11-13 19:47 . 2011-11-13 19:47 3391488 c:\windows\ASSEMBLY\NativeImages1_v1.1.4322\MSCORLIB\1.0.5000.0__b77a5c561934e089_f1566001\mscorlib.dll
+ 2011-11-13 18:42 . 2011-11-13 18:42 3325440 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\WindowsBase\1adc4ae51a5ac63e896a1402749ca495\WindowsBase.ni.dll
+ 2011-11-13 18:48 . 2011-11-13 18:48 1049600 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\UIAutomationClients#\55d4813580b1e5d268ff0564942cee9c\UIAutomationClientsideProviders.ni.dll
+ 2011-11-13 18:51 . 2011-11-13 18:51 4170240 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\ttax\87b422c64df073b3edbfb7af155bc04d\ttax.ni.dll
+ 2011-11-13 09:00 . 2011-11-13 09:00 7950848 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll
+ 2011-11-13 18:48 . 2011-11-13 18:48 5450752 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll
+ 2011-11-13 18:55 . 2011-11-13 18:55 1356288 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.WorkflowServ#\17902fdb0e0d3bc8b49bce693415fe7e\System.WorkflowServices.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 1908224 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Workflow.Run#\f72c5f649951b0403e62bfab6c453e6f\System.Workflow.Runtime.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 4514304 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Workflow.Com#\0aa4f4174204c93cc5181df4a6b2fb09\System.Workflow.ComponentModel.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 2992640 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Workflow.Act#\921629dc69a5a895101097c88ae67897\System.Workflow.Activities.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 1840640 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Services\6303e256d2ac0843c3e4c24172c90544\System.Web.Services.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 2209280 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Mobile\f5dac0448a1dbe2687a5df92904d6274\System.Web.Mobile.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 2405376 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Extensio#\ccaf6bdd256a9b5079fedadcc8993327\System.Web.Extensions.ni.dll
+ 2011-11-13 18:47 . 2011-11-13 18:47 1917952 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Speech\10d7daa3d1e62a0e40587cdc707be93f\System.Speech.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 1706496 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.ServiceModel#\9ec7da53380a754b4ad97709df0dd7e7\System.ServiceModel.Web.ni.dll
+ 2011-11-13 18:50 . 2011-11-13 18:50 2345472 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Runtime.Seri#\afd6134c090faf8c29cd64d4835142b2\System.Runtime.Serialization.ni.dll
+ 2011-11-13 18:47 . 2011-11-13 18:47 1035776 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Printing\0f8e14bfdb27645fb1a92ce26f9bf521\System.Printing.ni.dll
+ 2011-11-13 18:50 . 2011-11-13 18:50 1070080 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.IdentityModel\d14065ede44df8e9b5d6b60c5ddccc69\System.IdentityModel.ni.dll
+ 2011-11-13 18:47 . 2011-11-13 18:47 1587200 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll
+ 2011-11-13 18:51 . 2011-11-13 18:51 1116672 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.DirectorySer#\91cd88a803768151c6262853d3454ba7\System.DirectoryServices.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 1801216 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Deployment\cc5ac99e8af2738e85cda5525fdd944f\System.Deployment.ni.dll
+ 2011-11-13 18:46 . 2011-11-13 18:46 6616576 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data\ec323cf1df697cc0a45f67de685db90c\System.Data.ni.dll
+ 2011-11-13 18:51 . 2011-11-13 18:51 2510336 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.SqlXml\ef748704f543a8791e23387652d34dfb\System.Data.SqlXml.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 1328128 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.Services\541142d8742e6e88f1e729fafee04e71\System.Data.Services.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 1115136 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.OracleC#\5d5aa4b926ae422607ea833d934665c2\System.Data.OracleClient.ni.dll
+ 2011-11-13 18:46 . 2011-11-13 18:46 2516480 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.Linq\d96a94076acb8e0c5a96a1b2de4b3a7a\System.Data.Linq.ni.dll
+ 2011-11-13 18:54 . 2011-11-13 18:54 9924096 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.Entity\a3ce22c2a84fdcb008d72d230ee0b2c0\System.Data.Entity.ni.dll
+ 2011-11-13 18:46 . 2011-11-13 18:46 2295296 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Core\d507b9e0e50e453793ee5e01c07a5485\System.Core.ni.dll
+ 2011-11-13 18:45 . 2011-11-13 18:45 2128896 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\ReachFramework\714e9504255565bd9076fe13628e104a\ReachFramework.ni.dll
+ 2011-11-13 18:45 . 2011-11-13 18:45 1657856 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\PresentationUI\7dc6ee14234b0686182ced75f7dae990\PresentationUI.ni.dll
+ 2011-11-13 18:41 . 2011-11-13 18:41 1451008 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\PresentationBuildTa#\b42ad515bb20ec1f1250c040371c6730\PresentationBuildTasks.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 1712128 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\24331b719aa25ac2b21099e32232840c\Microsoft.VisualBasic.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 1093120 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Transacti#\ce1ecd602ca089eb13a9b428dc7f0449\Microsoft.Transactions.Bridge.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 2332160 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.JScript\8ad32b72258899177c07dc5912b5b748\Microsoft.JScript.ni.dll
+ 2011-11-13 18:53 . 2011-11-13 18:53 1620992 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\50e7c5eb58c982dba7b21cd10a69b095\Microsoft.Build.Tasks.ni.dll
+ 2011-11-13 18:53 . 2011-11-13 18:53 1966080 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\415cef6abab5bb959f200f6c537bc289\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2011-11-13 18:53 . 2011-11-13 18:53 1888768 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\eea7bcc8d356e3f2dcb4f36dfc1c6bc0\Microsoft.Build.Engine.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 1328128 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Intuit.Ctg.Map\2700eff4339a6a0bf7a8084f336f8c50\Intuit.Ctg.Map.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 2597376 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Infragistics2.Win.M#\edcaf3ed41a6cf6810b6bca9691a1b08\Infragistics2.Win.Misc.v8.2.ni.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 3182592 c:\windows\ASSEMBLY\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 3182592 c:\windows\ASSEMBLY\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 2048000 c:\windows\ASSEMBLY\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 2048000 c:\windows\ASSEMBLY\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 5025792 c:\windows\ASSEMBLY\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 5025792 c:\windows\ASSEMBLY\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 5062656 c:\windows\ASSEMBLY\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
- 2011-04-13 07:54 . 2011-04-13 07:54 5062656 c:\windows\ASSEMBLY\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 5242880 c:\windows\ASSEMBLY\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 5242880 c:\windows\ASSEMBLY\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 2933248 c:\windows\ASSEMBLY\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 2933248 c:\windows\ASSEMBLY\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2010-10-07 06:02 . 2011-04-13 07:54 4550656 c:\windows\ASSEMBLY\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-11-13 08:58 . 2011-11-13 08:58 4550656 c:\windows\ASSEMBLY\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2010-10-07 05:57 . 2010-10-07 05:57 1232896 c:\windows\ASSEMBLY\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2011-11-13 08:28 . 2011-11-13 08:28 1232896 c:\windows\ASSEMBLY\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2010-10-07 05:57 . 2010-10-07 05:57 1265664 c:\windows\ASSEMBLY\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-11-13 08:28 . 2011-11-13 08:28 1265664 c:\windows\ASSEMBLY\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2005-05-12 10:00 . 2011-10-28 06:04 50295240 c:\windows\SYSTEM32\MRT.exe
+ 2011-07-13 06:49 . 2011-07-13 06:49 11459584 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2572067\M2572067Uninstall.msp
+ 2011-03-28 11:27 . 2011-03-28 11:27 15456256 c:\windows\Installer\276281b.msp
+ 2011-07-12 04:43 . 2011-07-12 04:43 11641344 c:\windows\Installer\276280a.msp
+ 2011-07-12 23:50 . 2011-07-12 23:50 17555968 c:\windows\Installer\26aa6c8.msp
+ 2011-11-13 18:47 . 2011-11-13 18:48 12430848 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 11800576 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web\60df958ca96c9b8945f836759b6abd34\System.Web.ni.dll
+ 2011-11-13 18:51 . 2011-11-13 18:51 17403904 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.ServiceModel\ceadaf3b3d017c7a1ef10a06f8009f6f\System.ServiceModel.ni.dll
+ 2011-11-13 18:47 . 2011-11-13 18:47 10683392 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Design\c6374d32e4af7b7e3e46b32176f76558\System.Design.ni.dll
+ 2011-11-13 18:44 . 2011-11-13 18:45 14328320 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\PresentationFramewo#\054488924fcc579cce9fa0209dafe28b\PresentationFramework.ni.dll
+ 2011-11-13 18:43 . 2011-11-13 18:43 12215808 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\PresentationCore\b2f0318713eca304eaa9d86fc17edb96\PresentationCore.ni.dll
+ 2011-11-13 08:59 . 2011-11-13 09:00 11490816 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
+ 2011-11-13 08:44 . 2011-11-13 08:44 11490816 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\mscorlib\c2678ff865d430dbcc94740aa5efdabc\mscorlib.ni.dll
+ 2011-11-13 18:52 . 2011-11-13 18:52 10334208 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Infragistics2.Win.v#\b62b6ab0137eb89d4a73def305b4acf3\Infragistics2.Win.v8.2.ni.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-07-26 17:15 2532680 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-08-24 57344]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb01.exe" [2000-08-07 192512]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"Intel AppUp(SM) center"="c:\program files\Intel\IntelAppStore\bin\serviceManager.lnk" [2011-04-13 933]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10m_ActiveX.exe" [2011-02-18 234656]
.
c:\documents and settings\T. Carlberg\Start Menu\Programs\Startup\
AVG Tray Icon.lnk - c:\program files\AVG\AVG9\avgtray.exe [2010-6-24 2078048]
internet explore.lnk - c:\program files\Internet Explorer\iexplore.exe [2004-8-4 634632]
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe [2005-4-2 43520]
Billminder.lnk - c:\quickenw\BILLMIND.EXE [2004-11-29 36864]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2004-11-18 24576]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
Quicken Startup.lnk - c:\quickenw\QWDLLS.EXE [2004-11-29 36864]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-06-24 23:12 12536 —-a-w- c:\windows\SYSTEM32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Themes"=2 (0x2)
"TapiSrv"=3 (0x3)
"SysmonLog"=3 (0x3)
"Schedule"=2 (0x2)
"SCardSvr"=3 (0x3)
"mnmsrvc"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"iPod Service"=3 (0x3)
"helpsvc"=2 (0x2)
"gupdatem"=3 (0x3)
"gupdate"=2 (0x2)
"Eventlog"=2 (0x2)
"ERSvc"=2 (0x2)
"CiSvc"=3 (0x3)
"Bonjour Service"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\SYSTEM32\\DPVSETUP.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\WINDOWS\\SYSTEM32\\javaw.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R0 AvgRkx86;avgrkx86.sys;c:\windows\SYSTEM32\DRIVERS\avgrkx86.sys [4/20/2008 3:20 PM 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [4/20/2008 3:20 PM 216400]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [4/20/2008 3:20 PM 243152]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [6/24/2010 3:12 PM 308136]
R2 mrtRate;mrtRate;c:\windows\SYSTEM32\DRIVERS\MrtRate.sys [11/29/2004 5:18 PM 34916]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [10/26/2010 10:22 AM 1025352]
S4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/17/2009 8:42 PM 135664]
S4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [12/17/2009 8:42 PM 135664]
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-18 04:42]
.
2011-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-18 04:42]
.
.
——- Supplementary Scan ——-
.
uStart Page = https://login.yahoo.com/config/mail?.intl=us
mWindow Title = Humboldt Internet
uInternet Settings,ProxyOverride = *.local
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
TCP: DhcpNameServer = [removed] [removed]
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-14 12:29
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3276)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\AVG\AVG9\avgam.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Intel\IntelAppStore\bin\serviceManager.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\iPod\bin\iPodService.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
.
**************************************************************************
.
Completion time: 2011-11-14 12:36:35 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-14 20:36
ComboFix2.txt 2011-11-12 21:23
ComboFix3.txt 2010-04-13 04:16
.
Pre-Run: 34,361,921,536 bytes free
Post-Run: 34,414,575,616 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 5E4542AC0AE7C60726AA5DDF939FC165

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI