This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

High CPU usage, Ping.exe, browsers redirect, [Closed]

109 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Wicked Kitt_E,

I see that you have Malwarebytes on your system. Please open Malwarebytes, update it and then run a Quick Scan. Please save the log that is created for your next reply.
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply please post the logs created by Malwarebytes and ESET online scan. :)
Here are the two files that you requested: Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8316 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 12/5/2011 9:35:57 AM mbam-log-2011-12-05 (09-35-47).txt Scan type: Quick scan Objects scanned: 292745 Time elapsed: 20 minute(s), 24 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 13 Registry Values Infected: 2 Registry Data Items Infected: 0 Folders Infected: 7 Files Infected: 35 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\AppID\{D2083641-E57F-4eab-BB85-0582424F4A29} (Adware.HotBar.CP) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> No action taken. HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> No action taken. HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> No action taken. HKEY_CLASSES_ROOT\Typelib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D} (Adware.MyWebSearch) -> No action taken. HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495} (Adware.MyWebSearch) -> No action taken. HKEY_CLASSES_ROOT\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C} (Adware.MyWebSearch) -> No action taken. HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA} (Adware.MyWebSearch) -> No action taken. HKEY_CLASSES_ROOT\MyWebSearch.ThirdPartyInstaller (Adware.MyWebSearch) -> No action taken. HKEY_CLASSES_ROOT\MyWebSearch.ThirdPartyInstaller.1 (Adware.MyWebSearch) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> No action taken. HKEY_CURRENT_USER\Software\SolutionAV (Rogue.AntivirSolutionPro) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> No action taken. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Value: f3PopularScreensavers -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions\[removed] (Adware.ClickPotato) -> Value: [removed] -> No action taken. Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\documents and settings\the crew.deam\start menu\Programs\zentom system guard (Rogue.ZentomSystemGuard) -> No action taken. c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed] (PUP.PlaySushi) -> No action taken. c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome (PUP.PlaySushi) -> No action taken. c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components (PUP.PlaySushi) -> No action taken. c:\documents and settings\deano-casino\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed] (PUP.PlaySushi) -> No action taken. c:\documents and settings\deano-casino\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome (PUP.PlaySushi) -> No action taken. c:\documents and settings\deano-casino\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components (PUP.PlaySushi) -> No action taken. Files Infected: c:\documents and settings\deano-casino\my documents\downloads\myfuncards(1).exe (Adware.FunWeb) -> No action taken. c:\documents and settings\deano-casino\my documents\downloads\myfuncards.exe (Adware.FunWeb) -> No action taken. c:\documents and settings\deano-casino\my documents\downloads\setupplaysushi(1).exe (PUP.PlaySushi) -> No action taken. c:\documents and settings\deano-casino\my documents\downloads\clickpotatoinstaller(2).exe (Adware.Hotbar.Gen) -> No action taken. c:\documents and settings\deano-casino\my documents\downloads\clickpotatoinstaller(3).exe (Adware.Hotbar.Gen) -> No action taken. c:\documents and settings\deano-casino\my documents\downloads\clickpotatoinstaller.exe (Adware.Hotbar.Gen) -> No action taken. c:\documents and settings\The Crew\my documents\downloads\flvplayersetup.exe (Adware.Agent) -> No action taken. c:\documents and settings\DEADA275\local settings\Temp\14C.tmp (Trojan.Agent) -> No action taken. c:\documents and settings\DEADA275\local settings\Temp\14D.tmp (Trojan.Agent) -> No action taken. c:\documents and settings\the crew.deam\local settings\Temp\shoptowin11_ff.exe (Adware.Agent) -> No action taken. c:\documents and settings\the crew.deam\local settings\Temp\thpm4588730036398929620.tmp (Trojan.Exploit.Drop.THPM) -> No action taken. c:\documents and settings\the crew.deam\local settings\Temp\thpm512581307115453428.tmp (Trojan.Exploit.Drop.THPM) -> No action taken. c:\documents and settings\the crew.deam\local settings\Temp\nsc29.tmp\tzdworf1.png (Trojan.Agent) -> No action taken. c:\documents and settings\the crew.deam\local settings\Temp\nsc29.tmp\tzdworf2.png (Trojan.Agent) -> No action taken. c:\documents and settings\the crew.deam\local settings\Temp\nsc29.tmp\tzdworf3.png (Trojan.Agent) -> No action taken. c:\documents and settings\the crew.deam\local settings\Temp\nsc29.tmp\tzdworf4.png (Trojan.Agent) -> No action taken. c:\documents and settings\the crew.deam\local settings\Temp\nssCF.tmp\001.jgg (Trojan.Agent) -> No action taken. c:\documents and settings\the crew.deam\local settings\Temp\nssCF.tmp\002.jgg (Trojan.Agent) -> No action taken. c:\documents and settings\the crew.deam\local settings\Temp\nssCF.tmp\003.jgg (Trojan.Agent) -> No action taken. c:\documents and settings\DEADA275\local settings\temporary internet files\Content.IE5\GGUYR5LI\file[1].exe (Trojan.Exploit.Drop) -> No action taken. c:\documents and settings\the crew.deam\Desktop\zentom system guard.lnk (Rogue.ZentomSystemGuard) -> No action taken. c:\documents and settings\the crew.deam\application data\microsoft\internet explorer\quick launch\zentom system guard.lnk (Rogue.ZentomSystemGuard) -> No action taken. c:\documents and settings\the crew.deam\start menu\Programs\zentom system guard\zentom system guard.lnk (Rogue.ZentomSystemGuard) -> No action taken. c:\documents and settings\the crew.deam\start menu\Programs\zentom system guard\uninstall.lnk (Rogue.ZentomSystemGuard) -> No action taken. c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome.manifest (PUP.PlaySushi) -> No action taken. c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\install.rdf (PUP.PlaySushi) -> No action taken. c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome\pstextlinks.jar (PUP.PlaySushi) -> No action taken. c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\playsushi.js (PUP.PlaySushi) -> No action taken. c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\playsushiff.dll (PUP.PlaySushi) -> No action taken. c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\playsushiff.xpt (PUP.PlaySushi) -> No action taken. c:\documents and settings\deano-casino\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome.manifest (PUP.PlaySushi) -> No action taken. c:\documents and settings\deano-casino\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\install.rdf (PUP.PlaySushi) -> No action taken. c:\documents and settings\deano-casino\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome\pstextlinks.jar (PUP.PlaySushi) -> No action taken. c:\documents and settings\deano-casino\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\playsushiff.dll (PUP.PlaySushi) -> No action taken. c:\documents and settings\deano-casino\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\playsushiff.xpt (PUP.PlaySushi) -> No action taken. ESET C:\Documents and Settings\DEADA275\Application Data\Mozilla\Firefox\Profiles\l56b8n5z.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan C:\Documents and Settings\DEADA275\Application Data\Mozilla\Firefox\Profiles\l56b8n5z.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar JS/Agent.NDO trojan C:\Documents and Settings\DEADA275\Application Data\Sun\Java\Deployment\cache\6.0\1\4f8c7441-5be7e971 a variant of Win32/Kryptik.VZH trojan C:\Documents and Settings\DEADA275\Desktop\pcrepairclinic.exe a variant of Win32/Toolbar.Zugo application C:\Documents and Settings\DEADA275\Local Settings\Temp\122.tmp Win32/Olmarik.AWO trojan C:\Documents and Settings\DEADA275\Local Settings\Temp\124.tmp Win32/Olmarik.AWO trojan C:\Documents and Settings\DEADA275\Local Settings\Temp\14C.tmp probably a variant of Win32/Kryptik.WAW trojan C:\Documents and Settings\DEADA275\Local Settings\Temp\14D.tmp probably a variant of Win32/Kryptik.WAW trojan C:\Documents and Settings\DEADA275\Local Settings\Temp\YontooSetup-Silent.exe probably a variant of Win32/Adware.ERSKVQT application C:\Documents and Settings\DEADA275\Local Settings\Temp\F0516A30-BAB0-7891-A724-A8C64FCEF821\MyBabylonTB.exe a variant of Win32/Toolbar.Babylon application C:\Documents and Settings\DEADA275\Local Settings\Temp\ICReinstall\Facemoods.exe probably a variant of Win32/InstallCore.A application C:\Documents and Settings\DEADA275\Local Settings\Temp\ICReinstall\VideoConverterSetup.exe Win32/InstallCore application C:\Documents and Settings\DEADA275\Local Settings\Temp\is-ILLAJ.tmp\getinstalls-silentinstaller.exe a variant of Win32/Toolbar.Zugo application C:\Documents and Settings\DEADA275\Local Settings\Temp\nsi81.tmp\__localxml.xml Win32/DownloadAdmin.A.Gen application C:\Documents and Settings\DEADA275\Local Settings\Temp\nsi81.tmp\2\tr-tightrope-sntb.exe a variant of Win32/Toolbar.Zugo application C:\Documents and Settings\DEADA275\Local Settings\Temporary Internet Files\Content.IE5\GGUYR5LI\file[1].exe a variant of Win32/Kryptik.VZH trojan C:\Documents and Settings\Deano-Casino\Application Data\Sun\Java\Deployment\cache\6.0\0\6add3540-183377f9 multiple threats C:\Documents and Settings\Deano-Casino\Application Data\Sun\Java\Deployment\cache\6.0\27\578d041b-504b640c Java/TrojanDownloader.OpenStream.NCA trojan C:\Documents and Settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller(2).exe a variant of Win32/Adware.HotBar.H application C:\Documents and Settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller(3).exe a variant of Win32/Adware.HotBar.H application C:\Documents and Settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller.exe a variant of Win32/Adware.HotBar.H application C:\Documents and Settings\Deano-Casino\My Documents\Downloads\FixCleanerSetup.exe Win32/Adware.ErrorRepair application C:\Documents and Settings\Deano-Casino\My Documents\Downloads\MyFunCards(1).exe Win32/Toolbar.MyWebSearch application C:\Documents and Settings\Deano-Casino\My Documents\Downloads\MyFunCards.exe Win32/Toolbar.MyWebSearch application C:\Documents and Settings\Deano-Casino\My Documents\Downloads\SetupPlaySushi(1).exe a variant of Win32/Adware.Gamevance.AT application C:\Documents and Settings\MommyDearest\Application Data\Mozilla\Firefox\Profiles\d0mk2i09.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan C:\Documents and Settings\MommyDearest\Application Data\Mozilla\Firefox\Profiles\d0mk2i09.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar JS/Agent.NDO trojan C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\16\773490-73c0e6aa a variant of Win32/Kryptik.WFA trojan C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\18\7624352-152f6a7f a variant of Win32/Kryptik.WDH trojan C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\39\2e1c1fe7-35707573 Win32/Spy.SpyEye.CA trojan C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\52\114fc934-2a0f1d72 a variant of Win32/Kryptik.WEI trojan C:\Documents and Settings\The Crew\My Documents\Downloads\FlvPlayerSetup.exe a variant of Win32/InstallCore.D application C:\Documents and Settings\The Crew\My Documents\Downloads\Softonic-Downloader33501.exe a variant of Win32/SoftonicDownloader.A application C:\Documents and Settings\The Crew\My Documents\Downloads\SoftonicDownloader_for_sevenvg-rc-windows-7-theme.exe a variant of Win32/SoftonicDownloader.A application C:\Documents and Settings\The Crew.DEAM\Application Data\A5D0C6F9CF9CA6969D3E693DC87C3BAF\enemies-names.txt Win32/Adware.AntimalwareDoctor.AE.Gen application C:\Documents and Settings\The Crew.DEAM\Application Data\A5D0C6F9CF9CA6969D3E693DC87C3BAF\local.ini Win32/Adware.AntimalwareDoctor.AE.Gen application C:\Documents and Settings\The Crew.DEAM\Application Data\Mozilla\Firefox\Profiles\lynhlbe0.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan C:\Documents and Settings\The Crew.DEAM\Application Data\Mozilla\Firefox\Profiles\lynhlbe0.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar JS/Agent.NDO trojan C:\Documents and Settings\The Crew.DEAM\Application Data\Sun\Java\Deployment\cache\6.0\6\2eff00c6-751446b3 a variant of Java/Agent.DM trojan C:\Documents and Settings\The Crew.DEAM\Desktop\WhiteSmokeInstaller_9386.exe a variant of Win32/InstallCore.A application C:\Documents and Settings\The Crew.DEAM\Local Settings\Application Data\Google\GoogleUpdate\Googleup.dll a variant of Win32/Kryptik.UXS trojan C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\thpm4588730036398929620.tmp multiple threats C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\thpm512581307115453428.tmp multiple threats C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\YontooSetup-Silent.exe probably a variant of Win32/Adware.ERSKVQT application C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\zugo.exe a variant of Win32/Toolbar.Zugo application C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\ICReinstall\cnet_HC2Setup_exe.exe a variant of Win32/InstallCore.D application C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\ICReinstall\cnet_SetupImgBurn_2_5_5_0_exe.exe a variant of Win32/InstallCore.D application C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\is271270771\WhiteSmokeTrial.exe multiple threats C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf1.png a variant of Win32/Kryptik.UXS trojan C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf2.png a variant of Win32/Kryptik.UXS trojan C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf3.png Win32/TrojanDownloader.Tracur.I trojan C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf4.png a variant of Win32/Kryptik.UXS trojan C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\001.jgg a variant of Win32/Kryptik.UXS trojan C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\002.jgg Win32/BHO.NZK trojan C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\003.jgg Win32/TrojanDownloader.Tracur.I trojan C:\Program Files\FoxTabFLVPlayer\FLVPlayer.exe a variant of Win32/InstallCore.A application C:\Program Files\FoxTabFLVPlayer\Uninstall\Uninstall.exe a variant of Win32/InstallCore.D application C:\Program Files\FoxTabVideoConverter\VideoConverter.exe a variant of Win32/InstallCore.A application C:\Program Files\FoxTabVideoConverter\Uninstall\Uninstall.exe Win32/InstallCore application C:\Program Files\PlaySushi\psuninst.exe a variant of Win32/Adware.Gamevance.BE application C:\Program Files\Uniblue\SpeedUpMyPC\Launcher.exe Win32/SpeedUpMyPC application C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe Win32/SpeedUpMyPC application C:\Program Files\Uniblue\SpeedUpMyPC\spnotifier.exe Win32/SpeedUpMyPC application C:\Program Files\Uniblue\SpeedUpMyPC\sp_move_serial.exe Win32/SpeedUpMyPC application C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe Win32/SpeedUpMyPC application C:\Program Files\WhiteSmoke\HookDllOE.dll probably a variant of Win32/WhiteSmoke application C:\Program Files\WhiteSmoke\WhiteSmokeRegistration.exe a variant of Win32/WhiteSmoke application C:\Program Files\WhiteSmoke\WSEnrichment.exe probably a variant of Win32/WhiteSmoke application C:\Program Files\WhiteSmoke\html\english\dictClientDic\index.html HTML/WhiteSmoke application C:\Program Files\WhiteSmoke\html\english\dictClientDic\translator.html HTML/WhiteSmoke application C:\Program Files\Windows Live\Messenger\msimg32.dll Win32/Toolbar.MyWebSearch application C:\Program Files\Windows Live\Messenger\riched20.dll Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\gn7nuhve.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan C:\Qoobox\Quarantine\C\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\gn7nuhve.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar.vir JS/Agent.NDO trojan C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\B2E9.tmp.vir probably a variant of Win32/Kryptik.WAW trojan C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\KeyboardBackupManager.dll.vir Win32/TrojanDownloader.Tracur.I trojan C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Tarma Installer\{DA00D550-BB91-4A26-AAE5-9172D626CAAE}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application C:\Qoobox\Quarantine\C\Documents and Settings\Deano-Casino\Application Data\Mozilla\Firefox\Profiles\5rlgdvec.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan C:\Qoobox\Quarantine\C\Documents and Settings\Deano-Casino\Application Data\Mozilla\Firefox\Profiles\5rlgdvec.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar.vir JS/Agent.NDO trojan C:\Qoobox\Quarantine\C\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\sj03k314.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan C:\Qoobox\Quarantine\C\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\sj03k314.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar.vir JS/Agent.NDO trojan C:\Qoobox\Quarantine\C\Documents and Settings\The Crew\Application Data\Mozilla\Firefox\Profiles\f40a6q8j.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan C:\Qoobox\Quarantine\C\Documents and Settings\The Crew\Application Data\Mozilla\Firefox\Profiles\f40a6q8j.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar.vir JS/Agent.NDO trojan C:\Qoobox\Quarantine\C\Documents and Settings\The Crew.DEAM\Local Settings\Application Data\ExplorerWin32.dll.vir a variant of Win32/Kryptik.UXS trojan C:\Qoobox\Quarantine\C\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarApp.dll.vir a variant of Win32/Toolbar.Babylon application C:\Qoobox\Quarantine\C\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarsrv.exe.vir probably a variant of Win32/Toolbar.Babylon application C:\Qoobox\Quarantine\C\Program Files\ClickPotatoLite\bin\10.0.728.0\ClickPotatoLiteSA.exe.vir probably a variant of Win32/Adware.180Solutions application C:\Qoobox\Quarantine\C\Program Files\ClickPotatoLite\bin\10.0.728.0\ClickPotatoLiteSAAX.dll.vir a variant of Win32/Adware.HotBar.E application C:\Qoobox\Quarantine\C\Program Files\ClickPotatoLite\bin\10.0.728.0\ClickPotatoLiteSAHook.dll.vir a variant of Win32/Adware.180Solutions application C:\Qoobox\Quarantine\C\Program Files\ClickPotatoLite\bin\10.0.728.0\ClickPotatoLiteUninstaller.exe.vir a variant of Win32/Adware.HotBar.E application C:\Qoobox\Quarantine\C\Program Files\ClickPotatoLite\bin\10.0.728.0\firefox\extensions\plugins\npclntax_ClickPotatoLiteSA.dll.vir probably a variant of Win32/Adware.HotBar.J application C:\Qoobox\Quarantine\C\Program Files\Mozilla Firefox\plugins\npclntax_ClickPotatoLiteSA.dll.vir probably a variant of Win32/Adware.HotBar.J application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL.vir Win32/Adware.FunWeb application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL.vir Win32/Adware.FunWeb application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL.vir Win32/Toolbar.MyWebSearch.G application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL.vir Win32/Toolbar.MyWebSearch.B application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL.vir Win32/Adware.FunWeb application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3REGHK.DLL.vir Win32/Toolbar.MyWebSearch.G application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL.vir Win32/Toolbar.MyWebSearch.D application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE.vir Win32/Adware.FunWeb application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL.vir Win32/Toolbar.MyWebSearch.P application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3AUXSTB.DLL.vir Win32/Toolbar.MyWebSearch.H application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3DLGHK.DLL.vir Win32/Toolbar.MyWebSearch.I application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL.vir Win32/Toolbar.MyWebSearch.F application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL.vir Win32/Toolbar.MyWebSearch.P application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IEOVR.DLL.vir Win32/Toolbar.MyWebSearch.P application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL.vir Win32/Toolbar.MyWebSearch.J application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL.vir Win32/Toolbar.MyWebSearch.P application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE.vir Win32/Toolbar.MyWebSearch.J application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE.vir Win32/Toolbar.MyWebSearch.I application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3TPINST.DLL.vir Win32/Toolbar.MyWebSearch.I application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3UNPAT.DLL.vir a variant of Win32/Toolbar.MyWebSearch.I application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL.vir Win32/Toolbar.MyWebSearch.K application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSMLBTN.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL.vir Win32/Toolbar.MyWebSearch.J application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSUABTN.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Cache\00276091.exe.vir a variant of Win32/Toolbar.MyWebSearch.K application C:\Qoobox\Quarantine\C\Program Files\Search Toolbar\SearchToolbar.dll.vir Win32/Toolbar.Zugo application C:\Qoobox\Quarantine\C\Program Files\StartNow Toolbar\ToOLbar32.dll.vir a variant of Win32/Toolbar.Zugo application C:\Qoobox\Quarantine\C\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe.vir a variant of Win32/Toolbar.Zugo application C:\Qoobox\Quarantine\C\WINDOWS\system32\0.15040859031063447.exe.vir a variant of Win32/Kryptik.WDX trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\0.6344036376832972.exe.vir a variant of Win32/Kryptik.WDX trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\0.9150836843586603.exe.vir a variant of Win32/Kryptik.WDH trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\0.949885126871846.exe.vir Win32/Spy.SpyEye.CA trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\f3PSSavr.scr.vir Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP287\A0507561.dll a variant of Win32/Adware.Yontoo.B application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP287\A0507569.dll a variant of Win32/Adware.Yontoo.B application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0513743.exe a variant of Win32/Adware.OpenInstall application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0513750.exe a variant of Win32/Adware.Gamevance.BE application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0513751.exe Win32/DownloadAdmin.A.Gen application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0513752.exe probably a variant of Win32/Adware.LRYETGT application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0513754.exe a variant of Win32/Toolbar.Zugo application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518769.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518770.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518771.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518772.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518773.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518774.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518775.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520752.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520753.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520754.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520755.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520756.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520757.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520758.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521736.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521737.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521738.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521739.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521740.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521741.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521742.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524737.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524738.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524739.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524740.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524741.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524742.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524743.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525748.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525749.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525750.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525751.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525752.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525753.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525754.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526737.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526738.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526739.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526740.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526741.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526742.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526743.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527735.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527736.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527737.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527738.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527739.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527740.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527741.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530795.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530796.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530797.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530798.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530799.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530800.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530801.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530818.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530819.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530820.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530821.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530822.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530823.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530824.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532770.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532771.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532772.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532773.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532774.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532775.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532789.dll a variant of Win32/Toolbar.Zugo application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532791.exe a variant of Win32/Toolbar.Zugo application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533763.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533790.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533791.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533792.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533793.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533794.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533795.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0534763.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535763.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535782.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535783.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535784.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535785.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535786.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535787.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535828.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535843.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535844.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535845.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535846.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535847.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535848.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535849.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0536828.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537828.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537841.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537842.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537843.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537844.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537845.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537846.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0538828.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539828.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539845.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539865.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539866.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539867.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539868.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539869.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539870.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540845.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540857.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540858.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540859.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540860.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540861.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540862.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540896.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540935.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540936.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540937.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540938.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540939.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540940.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540941.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0541896.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0541914.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0542914.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0543914.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0544914.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545914.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545959.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545960.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545961.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545962.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545963.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545964.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545965.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546914.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546940.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546953.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546954.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546955.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546956.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546957.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546958.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546959.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0547940.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0548940.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0549940.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0549967.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0549985.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0550985.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0551985.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0552001.exe probably a variant of Win32/Kryptik.WAW trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0552985.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553024.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553062.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553063.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553064.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553065.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553066.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553067.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553068.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553076.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554076.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554086.exe a variant of Win32/Kryptik.WDW trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554087.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554088.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554089.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554090.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554091.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554092.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554093.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555076.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555118.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555119.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555120.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555121.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555122.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555123.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556076.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556106.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556107.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556108.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556109.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556110.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556111.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556150.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556205.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556219.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556220.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556221.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556222.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556223.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556224.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556225.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0557205.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0557218.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0558218.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0559218.sys a variant of Win32/Rootkit.Kryptik.FF trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562259.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562260.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562261.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562262.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562263.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562264.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562265.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562502.exe a variant of Win32/Kryptik.VZH trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562542.lnk LNK/URL.B trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562626.exe a variant of Win32/SoftonicDownloader.A application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562627.exe Win32/InstallCore application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562629.exe Win32/InstallCore application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562635.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562636.dll Win32/TrojanDownloader.Tracur.I trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562638.dll a variant of Win32/Adware.Yontoo.B application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562642.dll a variant of Win32/Adware.Yontoo.B application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562646.dll a variant of Win32/Adware.Yontoo.B application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562661.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562668.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562669.dll a variant of Win32/Kryptik.UXS trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562676.exe probably a variant of Win32/Adware.180Solutions application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562677.dll a variant of Win32/Adware.HotBar.E application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562680.dll a variant of Win32/Adware.180Solutions application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562681.exe a variant of Win32/Adware.HotBar.E application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562682.dll probably a variant of Win32/Adware.HotBar.J application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562692.dll probably a variant of Win32/Adware.HotBar.J application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562694.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562695.DLL Win32/Adware.FunWeb application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562696.DLL Win32/Adware.FunWeb application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562697.DLL Win32/Toolbar.MyWebSearch.G application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562698.DLL Win32/Toolbar.MyWebSearch.B application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562699.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562700.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562701.DLL Win32/Adware.FunWeb application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562702.SCR Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562703.DLL Win32/Toolbar.MyWebSearch.G application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562704.DLL Win32/Toolbar.MyWebSearch.D application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562705.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562706.EXE Win32/Adware.FunWeb application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562707.DLL Win32/Toolbar.MyWebSearch.P application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562709.DLL Win32/Toolbar.MyWebSearch.H application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562710.DLL Win32/Toolbar.MyWebSearch.I application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562713.DLL Win32/Toolbar.MyWebSearch.F application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562714.DLL Win32/Toolbar.MyWebSearch.P application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562715.DLL Win32/Toolbar.MyWebSearch.P application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562716.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562718.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562719.DLL Win32/Toolbar.MyWebSearch.J application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562721.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562722.DLL Win32/Toolbar.MyWebSearch.P application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562723.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562724.EXE Win32/Toolbar.MyWebSearch.J application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562725.EXE Win32/Toolbar.MyWebSearch.I application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562726.DLL Win32/Toolbar.MyWebSearch.I application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562727.DLL a variant of Win32/Toolbar.MyWebSearch.I application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562728.DLL Win32/Toolbar.MyWebSearch.K application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562729.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562730.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562731.DLL Win32/Toolbar.MyWebSearch.J application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562732.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562733.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562734.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562735.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562736.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562737.exe a variant of Win32/Toolbar.MyWebSearch.K application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562746.dll Win32/Toolbar.Zugo application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562750.dll a variant of Win32/Toolbar.Zugo application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562751.exe a variant of Win32/Toolbar.Zugo application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562754.exe a variant of Win32/Kryptik.WDX trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562755.exe a variant of Win32/Kryptik.WDX trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562756.exe a variant of Win32/Kryptik.WDH trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562757.exe Win32/Spy.SpyEye.CA trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562760.scr Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562902.manifest Win32/TrojanDownloader.Tracur.F trojan C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562910.dll a variant of Win32/Toolbar.Babylon application C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562912.exe probably a variant of Win32/Toolbar.Babylon application
Hi Wicked Kitt_E,

Please re-run Malwarebytes again and this time be sure to Quarantine/Delete the infections that are found. :)
————-

Your ESET scan found several entries but most of them are already quarantined by ComboFix or in restore points that we will be clearing out later so they are not a problem either. Please do the following…

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    File::
    C:\Documents and Settings\DEADA275\Application Data\Mozilla\Firefox\Profiles\l56b8n5z.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest	
    C:\Documents and Settings\DEADA275\Application Data\Mozilla\Firefox\Profiles\l56b8n5z.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar	
    C:\Documents and Settings\DEADA275\Application Data\Sun\Java\Deployment\cache\6.0\1\4f8c7441-5be7e971	
    C:\Documents and Settings\DEADA275\Desktop\pcrepairclinic.exe	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\122.tmp	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\124.tmp	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\14C.tmp	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\14D.tmp	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\YontooSetup-Silent.exe	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\F0516A30-BAB0-7891-A724-A8C64FCEF821\MyBabylonTB.exe	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\ICReinstall\Facemoods.exe	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\ICReinstall\VideoConverterSetup.exe	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\is-ILLAJ.tmp\getinstalls-silentinstaller.exe	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\nsi81.tmp\__localxml.xml	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\nsi81.tmp\2\tr-tightrope-sntb.exe	
    C:\Documents and Settings\DEADA275\Local Settings\Temporary Internet Files\Content.IE5\GGUYR5LI\file[1].exe	
    C:\Documents and Settings\Deano-Casino\Application Data\Sun\Java\Deployment\cache\6.0\0\6add3540-183377f9	
    C:\Documents and Settings\Deano-Casino\Application Data\Sun\Java\Deployment\cache\6.0\27\578d041b-504b640c 
    C:\Documents and Settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller(2).exe	
    C:\Documents and Settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller(3).exe	
    C:\Documents and Settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller.exe	
    C:\Documents and Settings\Deano-Casino\My Documents\Downloads\FixCleanerSetup.exe	
    C:\Documents and Settings\Deano-Casino\My Documents\Downloads\MyFunCards(1).exe	
    C:\Documents and Settings\Deano-Casino\My Documents\Downloads\MyFunCards.exe	
    C:\Documents and Settings\Deano-Casino\My Documents\Downloads\SetupPlaySushi(1).exe	
    C:\Documents and Settings\MommyDearest\Application Data\Mozilla\Firefox\Profiles\d0mk2i09.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest	
    C:\Documents and Settings\MommyDearest\Application Data\Mozilla\Firefox\Profiles\d0mk2i09.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar	
    C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\16\773490-73c0e6aa	
    C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\18\7624352-152f6a7f	
    C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\39\2e1c1fe7-35707573	
    C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\52\114fc934-2a0f1d72	
    C:\Documents and Settings\The Crew\My Documents\Downloads\FlvPlayerSetup.exe	
    C:\Documents and Settings\The Crew\My Documents\Downloads\Softonic-Downloader33501.exe	
    C:\Documents and Settings\The Crew\My Documents\Downloads\SoftonicDownloader_for_sevenvg-rc-windows-7-theme.exe	
    C:\Documents and Settings\The Crew.DEAM\Application Data\A5D0C6F9CF9CA6969D3E693DC87C3BAF\enemies-names.txt 
    C:\Documents and Settings\The Crew.DEAM\Application Data\A5D0C6F9CF9CA6969D3E693DC87C3BAF\local.ini	
    C:\Documents and Settings\The Crew.DEAM\Application Data\Mozilla\Firefox\Profiles\lynhlbe0.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest
    C:\Documents and Settings\The Crew.DEAM\Application Data\Mozilla\Firefox\Profiles\lynhlbe0.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar	
    C:\Documents and Settings\The Crew.DEAM\Application Data\Sun\Java\Deployment\cache\6.0\6\2eff00c6-751446b3	
    C:\Documents and Settings\The Crew.DEAM\Desktop\WhiteSmokeInstaller_9386.exe	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Application Data\Google\GoogleUpdate\Googleup.dll	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\thpm4588730036398929620.tmp	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\thpm512581307115453428.tmp	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\YontooSetup-Silent.exe	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\zugo.exe	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\ICReinstall\cnet_HC2Setup_exe.exe	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\ICReinstall\cnet_SetupImgBurn_2_5_5_0_exe.exe	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\is271270771\WhiteSmokeTrial.exe	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf1.png	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf2.png	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf3.png	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf4.png	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\001.jgg	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\002.jgg	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\003.jgg	
    C:\Program Files\FoxTabFLVPlayer\FLVPlayer.exe	
    C:\Program Files\FoxTabFLVPlayer\Uninstall\Uninstall.exe	
    C:\Program Files\FoxTabVideoConverter\VideoConverter.exe	
    C:\Program Files\FoxTabVideoConverter\Uninstall\Uninstall.exe	
    C:\Program Files\PlaySushi\psuninst.exe	
    C:\Program Files\WhiteSmoke\HookDllOE.dll	
    C:\Program Files\WhiteSmoke\WhiteSmokeRegistration.exe	
    C:\Program Files\WhiteSmoke\WSEnrichment.exe
    C:\Program Files\WhiteSmoke\html\english\dictClientDic\index.html	
    C:\Program Files\WhiteSmoke\html\english\dictClientDic\translator.html	
    C:\Program Files\Windows Live\Messenger\msimg32.dll	
    C:\Program Files\Windows Live\Messenger\riched20.dll
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

In your next reply please post the new logs created by Malwarebytes and ComboFix and let me know how your system is running now. :)
Here are the results of the malwarebytes and combofix. I fixed the problem with the ps/2 ports not working so the mouse and keyboard is working again. I don't use this computer and no one has mentioned any problems. No ping.exe, redirects,popups or shut downs. I think it runs on the slow side so I probably have to look more at what is installed, what processes are running and start ups. Or it could be I'm just use to my computer because it runs faster.


Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8316

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

12/6/2011 7:51:48 PM
mbam-log-2011-12-06 (19-51-48).txt

Scan type: Quick scan
Objects scanned: 292978
Time elapsed: 18 minute(s), 49 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 13
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 7
Files Infected: 35

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\{D2083641-E57F-4eab-BB85-0582424F4A29} (Adware.HotBar.CP) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.ThirdPartyInstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.ThirdPartyInstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\SolutionAV (Rogue.AntivirSolutionPro) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Value: f3PopularScreensavers -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions\[removed] (Adware.ClickPotato) -> Value: [removed] -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
c:\documents and settings\the crew.deam\start menu\Programs\zentom system guard (Rogue.ZentomSystemGuard) -> Quarantined and deleted successfully.
c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed] (PUP.PlaySushi) -> Quarantined and deleted successfully.
c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome (PUP.PlaySushi) -> Quarantined and deleted successfully.
c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components (PUP.PlaySushi) -> Not selected for removal.
c:\documents and settings\deano-casino\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed] (PUP.PlaySushi) -> Quarantined and deleted successfully.
c:\documents and settings\deano-casino\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome (PUP.PlaySushi) -> Quarantined and deleted successfully.
c:\documents and settings\deano-casino\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components (PUP.PlaySushi) -> Quarantined and deleted successfully.

Files Infected:
c:\documents and settings\deano-casino\my documents\downloads\myfuncards(1).exe (Adware.FunWeb) -> Quarantined and deleted successfully.
c:\documents and settings\deano-casino\my documents\downloads\myfuncards.exe (Adware.FunWeb) -> Quarantined and deleted successfully.
c:\documents and settings\deano-casino\my documents\downloads\setupplaysushi(1).exe (PUP.PlaySushi) -> Not selected for removal.
c:\documents and settings\deano-casino\my documents\downloads\clickpotatoinstaller(2).exe (Adware.Hotbar.Gen) -> Quarantined and deleted successfully.
c:\documents and settings\deano-casino\my documents\downloads\clickpotatoinstaller(3).exe (Adware.Hotbar.Gen) -> Quarantined and deleted successfully.
c:\documents and settings\deano-casino\my documents\downloads\clickpotatoinstaller.exe (Adware.Hotbar.Gen) -> Quarantined and deleted successfully.
c:\documents and settings\The Crew\my documents\downloads\flvplayersetup.exe (Adware.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\DEADA275\local settings\Temp\14C.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\DEADA275\local settings\Temp\14D.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\the crew.deam\local settings\Temp\shoptowin11_ff.exe (Adware.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\the crew.deam\local settings\Temp\thpm4588730036398929620.tmp (Trojan.Exploit.Drop.THPM) -> Quarantined and deleted successfully.
c:\documents and settings\the crew.deam\local settings\Temp\thpm512581307115453428.tmp (Trojan.Exploit.Drop.THPM) -> Quarantined and deleted successfully.
c:\documents and settings\the crew.deam\local settings\Temp\nsc29.tmp\tzdworf1.png (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\the crew.deam\local settings\Temp\nsc29.tmp\tzdworf2.png (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\the crew.deam\local settings\Temp\nsc29.tmp\tzdworf3.png (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\the crew.deam\local settings\Temp\nsc29.tmp\tzdworf4.png (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\the crew.deam\local settings\Temp\nssCF.tmp\001.jgg (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\the crew.deam\local settings\Temp\nssCF.tmp\002.jgg (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\the crew.deam\local settings\Temp\nssCF.tmp\003.jgg (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\DEADA275\local settings\temporary internet files\Content.IE5\GGUYR5LI\file[1].exe (Trojan.Exploit.Drop) -> Quarantined and deleted successfully.
c:\documents and settings\the crew.deam\Desktop\zentom system guard.lnk (Rogue.ZentomSystemGuard) -> Quarantined and deleted successfully.
c:\documents and settings\the crew.deam\application data\microsoft\internet explorer\quick launch\zentom system guard.lnk (Rogue.ZentomSystemGuard) -> Quarantined and deleted successfully.
c:\documents and settings\the crew.deam\start menu\Programs\zentom system guard\zentom system guard.lnk (Rogue.ZentomSystemGuard) -> Quarantined and deleted successfully.
c:\documents and settings\the crew.deam\start menu\Programs\zentom system guard\uninstall.lnk (Rogue.ZentomSystemGuard) -> Quarantined and deleted successfully.
c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome.manifest (PUP.PlaySushi) -> Quarantined and deleted successfully.
c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\install.rdf (PUP.PlaySushi) -> Quarantined and deleted successfully.
c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome\pstextlinks.jar (PUP.PlaySushi) -> Quarantined and deleted successfully.
c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\playsushi.js (PUP.PlaySushi) -> Quarantined and deleted successfully.
c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\playsushiff.dll (PUP.PlaySushi) -> Quarantined and deleted successfully.
c:\documents and settings\DEADA275\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\playsushiff.xpt (PUP.PlaySushi) -> Quarantined and deleted successfully.
c:\documents and settings\deano-casino\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome.manifest (PUP.PlaySushi) -> Quarantined and deleted successfully.
c:\documents and settings\deano-casino\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\install.rdf (PUP.PlaySushi) -> Quarantined and deleted successfully.
c:\documents and settings\deano-casino\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome\pstextlinks.jar (PUP.PlaySushi) -> Quarantined and deleted successfully.
c:\documents and settings\deano-casino\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\playsushiff.dll (PUP.PlaySushi) -> Quarantined and deleted successfully.
c:\documents and settings\deano-casino\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\playsushiff.xpt (PUP.PlaySushi) -> Quarantined and deleted successfully.


ComboFix 11-12-06.01 - Deano-Casino 12/06/2011 20:09:16.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.387 [GMT -7:00]
Running from: C:\ComboFix.exe
Command switches used :: C:\CFScript.txt
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
FILE ::
"c:\documents and settings\DEADA275\Application Data\Mozilla\Firefox\Profiles\l56b8n5z.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest"
"c:\documents and settings\DEADA275\Application Data\Mozilla\Firefox\Profiles\l56b8n5z.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar"
"c:\documents and settings\DEADA275\Application Data\Sun\Java\Deployment\cache\6.0\1\4f8c7441-5be7e971"
"c:\documents and settings\DEADA275\Desktop\pcrepairclinic.exe"
"c:\documents and settings\DEADA275\Local Settings\Temp\122.tmp"
"c:\documents and settings\DEADA275\Local Settings\Temp\124.tmp"
"c:\documents and settings\DEADA275\Local Settings\Temp\14C.tmp"
"c:\documents and settings\DEADA275\Local Settings\Temp\14D.tmp"
"c:\documents and settings\DEADA275\Local Settings\Temp\F0516A30-BAB0-7891-A724-A8C64FCEF821\MyBabylonTB.exe"
"c:\documents and settings\DEADA275\Local Settings\Temp\ICReinstall\Facemoods.exe"
"c:\documents and settings\DEADA275\Local Settings\Temp\ICReinstall\VideoConverterSetup.exe"
"c:\documents and settings\DEADA275\Local Settings\Temp\is-ILLAJ.tmp\getinstalls-silentinstaller.exe"
"c:\documents and settings\DEADA275\Local Settings\Temp\nsi81.tmp\__localxml.xml"
"c:\documents and settings\DEADA275\Local Settings\Temp\nsi81.tmp\2\tr-tightrope-sntb.exe"
"c:\documents and settings\DEADA275\Local Settings\Temp\YontooSetup-Silent.exe"
"c:\documents and settings\DEADA275\Local Settings\Temporary Internet Files\Content.IE5\GGUYR5LI\file[1].exe"
"c:\documents and settings\Deano-Casino\Application Data\Sun\Java\Deployment\cache\6.0\0\6add3540-183377f9"
"c:\documents and settings\Deano-Casino\Application Data\Sun\Java\Deployment\cache\6.0\27\578d041b-504b640c"
"c:\documents and settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller(2).exe"
"c:\documents and settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller(3).exe"
"c:\documents and settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller.exe"
"c:\documents and settings\Deano-Casino\My Documents\Downloads\FixCleanerSetup.exe"
"c:\documents and settings\Deano-Casino\My Documents\Downloads\MyFunCards(1).exe"
"c:\documents and settings\Deano-Casino\My Documents\Downloads\MyFunCards.exe"
"c:\documents and settings\Deano-Casino\My Documents\Downloads\SetupPlaySushi(1).exe"
"c:\documents and settings\MommyDearest\Application Data\Mozilla\Firefox\Profiles\d0mk2i09.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest"
"c:\documents and settings\MommyDearest\Application Data\Mozilla\Firefox\Profiles\d0mk2i09.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar"
"c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\16\773490-73c0e6aa"
"c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\18\7624352-152f6a7f"
"c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\39\2e1c1fe7-35707573"
"c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\52\114fc934-2a0f1d72"
"c:\documents and settings\The Crew.DEAM\Application Data\A5D0C6F9CF9CA6969D3E693DC87C3BAF\enemies-names.txt"
"c:\documents and settings\The Crew.DEAM\Application Data\A5D0C6F9CF9CA6969D3E693DC87C3BAF\local.ini"
"c:\documents and settings\The Crew.DEAM\Application Data\Mozilla\Firefox\Profiles\lynhlbe0.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest"
"c:\documents and settings\The Crew.DEAM\Application Data\Mozilla\Firefox\Profiles\lynhlbe0.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar"
"c:\documents and settings\The Crew.DEAM\Application Data\Sun\Java\Deployment\cache\6.0\6\2eff00c6-751446b3"
"c:\documents and settings\The Crew.DEAM\Desktop\WhiteSmokeInstaller_9386.exe"
"c:\documents and settings\The Crew.DEAM\Local Settings\Application Data\Google\GoogleUpdate\Googleup.dll"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\ICReinstall\cnet_HC2Setup_exe.exe"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\ICReinstall\cnet_SetupImgBurn_2_5_5_0_exe.exe"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\is271270771\WhiteSmokeTrial.exe"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf1.png"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf2.png"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf3.png"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf4.png"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\001.jgg"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\002.jgg"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\003.jgg"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\thpm4588730036398929620.tmp"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\thpm512581307115453428.tmp"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\YontooSetup-Silent.exe"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\zugo.exe"
"c:\documents and settings\The Crew\My Documents\Downloads\FlvPlayerSetup.exe"
"c:\documents and settings\The Crew\My Documents\Downloads\Softonic-Downloader33501.exe"
"c:\documents and settings\The Crew\My Documents\Downloads\SoftonicDownloader_for_sevenvg-rc-windows-7-theme.exe"
"c:\program files\FoxTabFLVPlayer\FLVPlayer.exe"
"c:\program files\FoxTabFLVPlayer\Uninstall\Uninstall.exe"
"c:\program files\FoxTabVideoConverter\Uninstall\Uninstall.exe"
"c:\program files\FoxTabVideoConverter\VideoConverter.exe"
"c:\program files\PlaySushi\psuninst.exe"
"c:\program files\WhiteSmoke\HookDllOE.dll"
"c:\program files\WhiteSmoke\html\english\dictClientDic\index.html"
"c:\program files\WhiteSmoke\html\english\dictClientDic\translator.html"
"c:\program files\WhiteSmoke\WhiteSmokeRegistration.exe"
"c:\program files\WhiteSmoke\WSEnrichment.exe"
"c:\program files\Windows Live\Messenger\msimg32.dll"
"c:\program files\Windows Live\Messenger\riched20.dll"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Deano-Casino\Application Data\Toolbar4
.
.
((((((((((((((((((((((((( Files Created from 2011-11-07 to 2011-12-07 )))))))))))))))))))))))))))))))
.
.
2011-12-01 20:45 . 2011-12-01 20:45 ——– d—–w- C:\tdsskiller
2011-11-23 17:57 . 2011-11-23 17:58 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-11-22 12:19 . 2011-11-22 12:19 ——– d—–w- C:\found.000
2011-11-19 23:45 . 2011-11-19 23:45 ——– d—–w- c:\program files\inKline Global
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\Yontoo Layers
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\FoxTabVideoConverter
2011-11-19 22:15 . 2011-11-19 22:15 ——– d—–w- c:\program files\Emerge Desktop
2011-11-18 07:47 . 2011-11-18 07:48 ——– d—–w- c:\documents and settings\All Users\Application Data\3B35B
2011-11-18 06:52 . 2011-11-18 06:52 ——– d—–w- C:\LB Photo Realism x256 6.9.2
2011-11-16 15:39 . 2011-11-16 15:39 ——– d—–w- c:\documents and settings\All Users\Application Data\F3A9
2011-11-12 14:51 . 2011-11-12 14:52 ——– d—–w- c:\documents and settings\Deano-Casino\Local Settings\Application Data\PageRage
2011-11-08 00:18 . 2011-11-08 00:18 ——– d—–w- c:\documents and settings\Deano-Casino\.autodesk
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-01 12:48 . 2008-04-14 12:00 52480 —-a-w- c:\windows\system32\drivers\i8042prt.sys
2011-12-01 04:44 . 2011-12-01 20:45 1547774 —-a-w- C:\tdsskiller.zip
2011-10-25 08:07 . 2011-10-08 02:26 0 —-a-w- c:\windows\system32\ConduitEngine.tmp
2011-09-23 22:02 . 2011-05-19 20:14 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-24 17:05 . 2011-03-29 21:07 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-01_23.54.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-07 02:55 . 2011-12-07 02:55 16384 c:\windows\Temp\Perflib_Perfdata_594.dat
+ 2009-10-12 19:25 . 2011-09-01 00:00 22216 c:\windows\system32\drivers\mbam.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-09-01 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd}]
2009-11-07 08:07 297808 —-a-w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-09-01 16:16 2532680 —-a-w- c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E601996F-E400-41CA-804B-CD6373A7EEE2}]
2011-03-23 15:12 931696 —-a-w- c:\program files\kikin\ie_kikin.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-07-22 23:53 787744 —-a-w- c:\program files\Yontoo Layers\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-09-01 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-09-01 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2011-06-08 822456]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"P17Helper"="P17.dll" [2005-05-04 64512]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2011-09-10 2338656]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-04-08 13891176]
.
c:\documents and settings\The Crew\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
Styler.lnk - c:\documents and settings\The Crew\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2011-6-16 15086]
.
c:\documents and settings\Deano-Casino\Start Menu\Programs\Startup\AutorunsDisabled
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [N/A]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [N/A]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AutorunsDisabled]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Fliptoast.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Fliptoast.lnk
backup=c:\windows\pss\Fliptoast.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Philips GoGear VIBE Device Manager.lnk]
backup=c:\windows\pss\Philips GoGear VIBE Device Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Desktop]
2011-04-12 07:14 4613624 —-a-w- c:\program files\4shared Desktop\desktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Update]
2011-04-12 07:14 608760 —-a-w- c:\program files\4shared Desktop\checkUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvIcon]
2008-04-13 12:39 49152 —-a-w- c:\program files\Vista Drive Icon\DrvIcon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
2008-04-14 12:00 44032 —-a-w- c:\windows\ime\imkr6_1\imekrmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iMesh]
2011-06-01 19:19 21880240 —-a-w- c:\program files\iMesh Applications\iMesh\iMesh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2008-04-14 12:00 208952 —-a-w- c:\windows\ime\imjp8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
2011-10-08 21:31 366024 —-a-w- c:\program files\IncrediMail\Bin\IncMail.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-07-30 17:41 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2011-02-24 09:57 1753192 —-a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ocs_SM]
2011-09-13 04:59 106496 —-a-w- c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-02-17 17:14 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyPC]
2011-05-24 00:27 67960 —-a-w- c:\program files\Uniblue\SpeedUpMyPC\Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
2010-04-29 16:38 1652736 —-a-r- c:\program files\AWS\WeatherBug\Weather.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"RichVideo"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"Updater Service for StartNow Toolbar"=2 (0x2)
"SearchAnonymizer"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"NMIndexingService"=3 (0x3)
"LightScribeService"=2 (0x2)
"Bonjour Service"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Electronic Arts\\Dead Space\\Dead Space.exe"=
"c:\\Program Files\\Boxee\\BOXEE.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 Beta 5\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\Stanza.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 RC 1\\firefox.exe"=
"c:\\Program Files\\Fox\\Aliens vs. Predator 2\\lithtech.exe"=
"c:\\Program Files\\Lighthouse Interactive\\T34vsTiger\\TvsT.exe"=
"c:\\Program Files\\Ubisoft\\IL-2 Sturmovik Forgotten Battles\\il2.exe"=
"c:\\Program Files\\Lead Pursuit\\Battlefield Operations\\FalconAF.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\TroubleShooter.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\ToolbarUpdate.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\brink\\brink.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\ava\\REACTOR.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\spiral knights\\java_vm\\bin\\javaw.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life\\hl.exe"=
"c:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"=
"c:\\Steam\\steamapps\\common\\call of duty black ops\\BlackOpsMP.exe"=
"c:\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\iBryte\\playbryte\\ibrytedesktop.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImpCnt.exe"=
"c:\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
"c:\\Documents and Settings\\The Crew.DEAM\\Local Settings\\Temp\\incredimail_install.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=
"c:\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Bohemia Interactive\\ArmA 2\\arma2.exe"=
"c:\\Steam\\steamapps\\azcrew\\garrysmod\\hl2.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 3:27 PM 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 3:48 AM 32592]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [11/20/2009 9:23 AM 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/12/2009 9:05 AM 206256]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [12/8/2010 4:12 AM 248656]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11/12/2010 1:19 PM 297168]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/15/2009 11:42 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 74480]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG10\avgwdsvc.exe [2/8/2011 5:33 AM 269520]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [4/27/2011 10:33 PM 2218600]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.2;c:\windows\system32\drivers\libusb0.sys [12/11/2009 9:37 AM 28160]
R3 N3AB;N3AB Wireless Network Adapter Service;c:\windows\system32\drivers\N3AB.sys [10/7/2009 9:39 AM 457312]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [5/12/2011 9:59 AM 1025352]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [8/18/2011 1:33 AM 7390560]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [8/3/2010 3:23 PM 134480]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [8/3/2010 3:23 PM 24144]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [8/3/2010 3:23 PM 27216]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [12/8/2009 3:29 PM 47360]
S3 SaiH075C;SaiH075C;c:\windows\system32\drivers\SaiH075C.sys [5/1/2007 4:11 PM 132232]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 7408]
S3 silabenm;RIGblaster Plug & Play Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys [2/3/2009 7:41 AM 17920]
S3 silabser;RIGblaster Plug & Play Driver;c:\windows\system32\drivers\silabser.sys [2/3/2009 7:41 AM 60544]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [10/8/2009 12:39 PM 94992]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys –> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/12/2009 9:05 AM 348824]
S4 SearchAnonymizer;SearchAnonymizer;c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizerHelper.exe [9/12/2011 9:59 PM 40960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\AutorunsDisabled\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-07-30 17:39 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-07 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2011-04-02 00:24]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-09-26 c:\windows\Tasks\Norton Security Scan for Deano-Casino.job
- c:\progra~1\NORTON~2\Engine\351~1.6\Nss.exe [2011-07-16 11:19]
.
2011-12-07 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-07 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-07 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-05 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-10-25 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-03 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC\spmonitor.exe [2011-08-18 00:27]
.
2011-12-07 c:\windows\Tasks\User_Feed_Synchronization-{D81FAA29-1225-43D0-9C2B-A4B5A9C8A97D}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bigseekpro.com/pivotstickfigure/{5D7E9955-3C04-4B2E-BE43-C161637CC061}
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files\kikin\ie_kikin.dll
TCP: DhcpNameServer = 192.168.1.1 [removed] [removed]
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\documents and settings\Deano-Casino\Application Data\Mozilla\Firefox\Profiles\5rlgdvec.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-06 20:29
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i8042prt]
"ImagePath"="system32\drivers\tskE.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1060284298-1659004503-1177238915-1003\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:31,e4,75,d6,9b,a1,3f,18,f1,28,20,5c,9e,f8,f2,f7,43,3a,5e,af,c0,
98,ad,90,f4,d9,c1,fd,4d,93,dc,2d,41,a7,a0,33,b3,7d,0e,42,26,9e,e5,12,e7,4a,\
"rkeysecu"=hex:b2,95,bd,3c,85,4b,48,d5,56,4b,32,96,d0,df,b0,b6
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3408)
c:\windows\system32\WININET.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-12-06 20:34:56
ComboFix-quarantined-files.txt 2011-12-07 03:34
ComboFix2.txt 2011-12-05 02:19
ComboFix3.txt 2011-12-02 04:51
ComboFix4.txt 2011-12-02 00:03
.
Pre-Run: 45,274,292,224 bytes free
Post-Run: 45,254,467,584 bytes free
.
- - End Of File - - 85DF473484205FA6493D632354E4914F
Hi Wicked Kitt_E,

I think it runs on the slow side so I probably have to look more at what is installed

I think that this may be helped by changing antivirus programs. This system has AVG and is somewhat a resource hog. Switching to a different antivirus program like Microsoft Security Essentials or Avast might help with speed a bit. Let me know if you would like to do this and I can give you the link to the AVG removal tool.
———-


You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 9.4.6 first. Be sure to move any PDF documents to another folder first though.
———-

Please download JavaRa to your desktop and unzip it to its own
folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
    click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
    Java Runtime Environment (JRE) version for your computer.
———-

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "Updater Service for StartNow Toolbar"=-
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Hi Jeff, :( Just wanted to let you know the computer had a setback and the ping.exe showed up again. Popups, Google redirects(but not with AVG Security search) and dog slow computer speeds again. It was running fine and then yesterday evening it went down hill again. I did update the AVG . I will change virus protection when this computer is healed. How is this ping.exe coming back? is it a website or did someone downloaded something?
Hi Wicked Kitt_E,

This computer was heavily infected so it is hard to say how it came back. This may have been a newer variant of the ZeroAccess Rootkit I told you about in the beginning.
————

Please download GetPartitions from the link below to your Desktop

getpartitions.exe

Double-Click (right-click and Run as Administrator Vista/7 users) the icon to run it.
When complete it will produce a log found at C:\DiskReport.txt
Please post the contents of that log into your next reply.
———-
Well this really bites about its return. So far ping hasn't showed up yet but I haven't been surfing that long on here. So what do you suggest the best course of action? I hate to give up. This is one of my weakness, I don't know when to give up on a issue when it comes down with computers. But if you think its best to wipe it clean and start over than I will concede. Since this isn't my computer I don't have a lot of time to mess with it to fix it. Here is the Disk Report: Microsoft DiskPart version 5.1.3565 Copyright © 1999-2003 Microsoft Corporation. On computer: DEAM Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– Volume 0 D DVD-ROM 0 B Volume 1 C NTFS Partition 279 GB Healthy System
Hi Wicked Kitt_E,

I hate to give up.

I am not ready to give up. :) However something you just wrote is the determining factor.

Since this isn't my computer I don't have a lot of time to mess with it to fix it.

Honestly the quickest route if you don't have time is to go ahead and do a format and re-install, but that is up to you on what you would like to do. :)

Quite honestly, this was a heavily infected machine and even when we get the ZeroRootkit infection completely cleared out there is still possibly damage to the good files we will need to contend with. So I would suggest that if you don't have the time to try and clean this that a re-install would be the best course of action in terms of time and knowing for a fact nothing was remaining.

Just let me know what you would like to do. I am ready for whatever route you wish to proceed with. :)
Hi Jeff, We can go ahead and press forward with this issue. Some people get impatient when stuff isn't working right and it should of been fixed yesterday, so I had to explain this might take some time so just chill until it's fixed. So what is the next step?
Ok…sounds good! :) Please go ahead and delete the copy of ComboFix you have and then download a fresh copy. Run ComboFix and then post the newly created log into your next reply. :)
Here is the combofix log:

ComboFix 11-12-12.02 - Deano-Casino 12/12/2011 10:35:33.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.528 [GMT -7:00]
Running from: C:\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Deano-Casino\Application Data\Toolbar4
c:\documents and settings\NetworkService\Application Data\Adobe\sp.DLL
c:\windows\$NtUninstallKB64546$
c:\windows\$NtUninstallKB64546$\1191843243
c:\windows\$NtUninstallKB64546$\4008776403\@
c:\windows\$NtUninstallKB64546$\4008776403\bckfg.tmp
c:\windows\$NtUninstallKB64546$\4008776403\cfg.ini
c:\windows\$NtUninstallKB64546$\4008776403\Desktop.ini
c:\windows\$NtUninstallKB64546$\4008776403\keywords
c:\windows\$NtUninstallKB64546$\4008776403\kwrd.dll
c:\windows\$NtUninstallKB64546$\4008776403\L\tigsyscw
c:\windows\$NtUninstallKB64546$\4008776403\lsflt7.ver
c:\windows\$NtUninstallKB64546$\4008776403\U\00000001.@
c:\windows\$NtUninstallKB64546$\4008776403\U\00000002.@
c:\windows\$NtUninstallKB64546$\4008776403\U\00000004.@
c:\windows\$NtUninstallKB64546$\4008776403\U\80000000.@
c:\windows\$NtUninstallKB64546$\4008776403\U\80000004.@
c:\windows\$NtUninstallKB64546$\4008776403\U\80000032.@
c:\windows\CSC\d6
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_SPService
.
.
((((((((((((((((((((((((( Files Created from 2011-11-12 to 2011-12-12 )))))))))))))))))))))))))))))))
.
.
2011-12-12 05:42 . 2011-12-12 05:44 ——– d—–w- c:\documents and settings\Administrator\.minecraft
2011-12-09 22:28 . 2011-12-09 22:30 79872 —-a-w- c:\windows\system32\G4E7R0u.com_
2011-12-07 06:12 . 2011-12-07 06:12 ——– d—–w- C:\76eb605531d17f49d13974016cf124
2011-12-07 05:59 . 2011-12-07 06:18 ——– d—–w- c:\windows\SxsCaPendDel
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\documents and settings\Deano-Casino\Application Data\AVG Secure Search
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\program files\Common Files\AVG Secure Search
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\program files\AVG Secure Search
2011-12-07 04:12 . 2011-12-07 04:12 ——– d—–w- c:\documents and settings\The Crew\Application Data\AVG2012
2011-12-07 04:12 . 2011-12-07 04:12 ——– d—–w- c:\documents and settings\Deano-Casino\Application Data\AVG2012
2011-12-01 20:45 . 2011-12-01 20:45 ——– d—–w- C:\tdsskiller
2011-11-23 17:57 . 2011-11-23 17:58 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-11-22 12:19 . 2011-11-22 12:19 ——– d—–w- C:\found.000
2011-11-19 23:45 . 2011-11-19 23:45 ——– d—–w- c:\program files\inKline Global
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\Yontoo Layers
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\FoxTabVideoConverter
2011-11-19 22:15 . 2011-11-19 22:15 ——– d—–w- c:\program files\Emerge Desktop
2011-11-18 07:47 . 2011-11-18 07:48 ——– d—–w- c:\documents and settings\All Users\Application Data\3B35B
2011-11-18 06:52 . 2011-11-18 06:52 ——– d—–w- C:\LB Photo Realism x256 6.9.2
2011-11-16 15:39 . 2011-11-16 15:39 ——– d—–w- c:\documents and settings\All Users\Application Data\F3A9
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-01 12:48 . 2008-04-14 12:00 52480 —-a-w- c:\windows\system32\drivers\i8042prt.sys
2011-12-01 04:44 . 2011-12-01 20:45 1547774 —-a-w- C:\tdsskiller.zip
2011-10-25 08:07 . 2011-10-08 02:26 0 —-a-w- c:\windows\system32\ConduitEngine.tmp
2011-10-10 14:22 . 2009-10-07 00:45 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 13:23 . 2010-12-08 11:12 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 13:21 . 2010-08-03 22:23 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-09-28 07:06 . 2008-04-14 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 18:41 . 2008-07-30 02:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 18:41 . 2008-04-14 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 18:41 . 2008-04-14 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-23 22:02 . 2011-05-19 20:14 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-24 17:05 . 2011-03-29 21:07 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-01_23.54.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-04-19 05:51 . 2011-04-19 05:51 51024 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_4ddc769f\vcomp90.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90rus.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90kor.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90jpn.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90ita.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90fra.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esp.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esn.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 53584 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90enu.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 63312 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90deu.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90cht.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 35664 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90chs.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90u.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90.dll
+ 2011-05-14 03:17 . 2011-05-14 03:17 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_452bf920\vcomp.dll
+ 2011-05-14 02:45 . 2011-05-14 02:45 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80KOR.dll
+ 2011-05-14 02:45 . 2011-05-14 02:45 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80JPN.dll
+ 2011-05-14 02:45 . 2011-05-14 02:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ITA.dll
+ 2011-05-14 02:45 . 2011-05-14 02:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80FRA.dll
+ 2011-05-14 02:45 . 2011-05-14 02:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ESP.dll
+ 2011-05-14 02:45 . 2011-05-14 02:45 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ENU.dll
+ 2011-05-14 02:45 . 2011-05-14 02:45 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80DEU.dll
+ 2011-05-14 02:45 . 2011-05-14 02:45 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80CHT.dll
+ 2011-05-14 02:45 . 2011-05-14 02:45 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80CHS.dll
+ 2011-05-14 08:06 . 2011-05-14 08:06 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80u.dll
+ 2011-05-14 08:23 . 2011-05-14 08:23 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80.dll
+ 2011-05-14 01:37 . 2011-05-14 01:37 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_a4c618fa\ATL80.dll
+ 2011-12-12 18:06 . 2011-12-12 18:06 16384 c:\windows\Temp\Perflib_Perfdata_a0.dat
- 2008-04-14 12:00 . 2010-11-03 13:12 46080 c:\windows\system32\tzchange.exe
+ 2008-04-14 12:00 . 2011-07-08 13:49 46080 c:\windows\system32\tzchange.exe
+ 2008-04-14 12:00 . 2011-12-08 04:45 84518 c:\windows\system32\perfc009.dat
+ 2008-04-14 12:00 . 2011-08-22 23:48 66560 c:\windows\system32\mshtmled.dll
- 2008-04-14 12:00 . 2010-12-20 23:59 66560 c:\windows\system32\mshtmled.dll
- 2009-03-08 11:31 . 2010-12-20 23:59 55296 c:\windows\system32\msfeedsbs.dll
+ 2009-03-08 11:31 . 2011-08-22 23:48 55296 c:\windows\system32\msfeedsbs.dll
- 2008-04-14 12:00 . 2010-12-20 23:59 43520 c:\windows\system32\licmgr10.dll
+ 2008-04-14 12:00 . 2011-08-22 23:48 43520 c:\windows\system32\licmgr10.dll
- 2008-04-14 12:00 . 2010-12-20 23:59 25600 c:\windows\system32\jsproxy.dll
+ 2008-04-14 12:00 . 2011-08-22 23:48 25600 c:\windows\system32\jsproxy.dll
+ 2008-04-14 12:00 . 2011-07-08 14:02 10496 c:\windows\system32\drivers\ndistapi.sys
+ 2009-10-12 19:25 . 2011-09-01 00:00 22216 c:\windows\system32\drivers\mbam.sys
+ 2010-09-07 10:48 . 2011-09-13 13:30 32592 c:\windows\system32\drivers\avgrkx86.sys
- 2010-09-07 10:48 . 2011-03-16 23:03 32592 c:\windows\system32\drivers\avgrkx86.sys
+ 2010-09-07 10:48 . 2011-08-08 13:08 40016 c:\windows\system32\drivers\avgmfx86.sys
+ 2010-08-03 22:23 . 2011-07-11 08:14 24272 c:\windows\system32\drivers\AVGIDSFilter.sys
+ 2010-09-13 22:27 . 2011-07-11 08:14 23120 c:\windows\system32\drivers\AVGIDSEH.sys
- 2008-04-14 12:00 . 2008-04-14 12:00 45568 c:\windows\system32\dnsrslvr.dll
+ 2008-04-14 12:00 . 2009-04-20 17:17 45568 c:\windows\system32\dnsrslvr.dll
- 2009-11-30 15:16 . 2010-12-20 23:59 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2009-11-30 15:16 . 2011-08-22 23:48 12800 c:\windows\system32\dllcache\xpshims.dll
- 2008-04-14 12:00 . 2009-10-08 21:56 20480 c:\windows\system32\dllcache\oleaccrc.dll
+ 2008-04-14 12:00 . 2011-09-26 18:41 20480 c:\windows\system32\dllcache\oleaccrc.dll
+ 2008-04-14 12:00 . 2011-07-08 14:02 10496 c:\windows\system32\dllcache\ndistapi.sys
+ 2008-04-14 12:00 . 2011-08-22 23:48 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2008-04-14 12:00 . 2010-12-20 23:59 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2009-11-30 15:16 . 2010-12-20 23:59 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2009-11-30 15:16 . 2011-08-22 23:48 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-04-14 12:00 . 2010-12-20 23:59 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2008-04-14 12:00 . 2011-08-22 23:48 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2008-04-14 12:00 . 2011-08-22 23:48 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2008-04-14 12:00 . 2010-12-20 23:59 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 45568 c:\windows\system32\dllcache\dnsrslvr.dll
+ 2008-04-14 12:00 . 2009-04-20 17:17 45568 c:\windows\system32\dllcache\dnsrslvr.dll
- 2008-04-14 12:00 . 2010-12-09 14:30 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2008-04-14 12:00 . 2011-04-26 11:07 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2008-04-14 12:00 . 2011-04-26 11:07 33280 c:\windows\system32\csrsrv.dll
- 2008-04-14 12:00 . 2010-12-09 14:30 33280 c:\windows\system32\csrsrv.dll
- 2010-09-23 22:55 . 2010-09-23 22:55 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2011-07-08 21:00 . 2011-07-08 21:00 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
- 2010-09-23 09:26 . 2010-09-23 09:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2011-07-07 19:04 . 2011-07-07 19:04 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2010-09-23 09:26 . 2010-09-23 09:26 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2011-07-07 19:04 . 2011-07-07 19:04 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2011-07-07 19:03 . 2011-07-07 19:03 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2010-09-23 09:26 . 2010-09-23 09:26 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2010-09-23 10:17 . 2010-09-23 10:17 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2011-07-07 20:09 . 2011-07-07 20:09 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2011-07-07 20:09 . 2011-07-07 20:09 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
- 2010-09-23 10:17 . 2010-09-23 10:17 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
- 2010-12-19 07:24 . 2010-12-19 07:24 49936 c:\windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe
+ 2011-12-08 04:35 . 2011-12-08 04:35 49936 c:\windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe
- 2009-10-17 15:01 . 2010-12-19 07:24 40960 c:\windows\Installer\{90850409-6000-11D3-8CFE-0150048383C9}\wrdvicon.exe
+ 2009-10-17 15:01 . 2011-12-07 06:02 40960 c:\windows\Installer\{90850409-6000-11D3-8CFE-0150048383C9}\wrdvicon.exe
+ 2011-12-08 04:35 . 2011-12-08 04:35 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2010-12-19 07:24 . 2010-12-19 07:24 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2010-06-07 04:52 . 2011-03-12 23:04 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2010-06-07 04:52 . 2011-12-08 04:37 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2011-12-07 06:03 . 2010-12-20 23:59 12800 c:\windows\ie8updates\KB2586448-IE8\xpshims.dll
+ 2011-12-07 06:03 . 2010-12-20 23:59 66560 c:\windows\ie8updates\KB2586448-IE8\mshtmled.dll
+ 2011-12-07 06:03 . 2010-12-20 23:59 55296 c:\windows\ie8updates\KB2586448-IE8\msfeedsbs.dll
+ 2011-12-07 06:03 . 2010-12-20 23:59 43520 c:\windows\ie8updates\KB2586448-IE8\licmgr10.dll
+ 2011-12-07 06:03 . 2010-12-20 23:59 25600 c:\windows\ie8updates\KB2586448-IE8\jsproxy.dll
+ 2011-12-07 05:54 . 2011-12-07 05:54 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_31f35476\System.Drawing.Design.dll
+ 2011-12-07 05:54 . 2011-12-07 05:54 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_70d20b22\CustomMarshalers.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 47616 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\47e0dd4fe04c9e5ac5191967d85d6931\WindowsLiveWriter.ni.exe
+ 2011-12-08 22:12 . 2011-12-08 22:12 99840 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\8379dc38b3fd1cbcb00b46e92b086848\WindowsLive.Writer.Api.ni.dll
+ 2011-12-08 22:05 . 2011-12-08 22:05 24576 c:\windows\assembly\NativeImages_v2.0.50727_32\WiaProxy32\d5cd392b58b4fca02e9b69425633375e\WiaProxy32.ni.exe
+ 2011-12-08 18:18 . 2011-12-08 18:18 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\1492e9393417d6e91b5ddc746b5ef320\UIAutomationProvider.ni.dll
+ 2011-12-09 01:31 . 2011-12-09 01:31 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\343c52b741531ce9ae874ea7508831a7\System.Windows.Presentation.ni.dll
+ 2011-12-08 23:34 . 2011-12-08 23:34 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\246110974e3c48733458819b07464b23\System.Web.DynamicData.Design.ni.dll
+ 2011-12-08 22:26 . 2011-12-08 22:26 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\ace861fe8dbf146c3e449abaa7691e9f\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-12-08 22:26 . 2011-12-08 22:26 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\177a17af98d803ab79006d6785706462\System.AddIn.Contract.ni.dll
+ 2011-12-08 22:25 . 2011-12-08 22:25 69632 c:\windows\assembly\NativeImages_v2.0.50727_32\QTPluginLib\e9571cb5f81ce9c02837bcc0029f3176\QTPluginLib.ni.dll
+ 2011-12-08 17:42 . 2011-12-08 17:42 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\40ee65aacd9d7472cd6f8dddbfca604b\PresentationFontCache.ni.exe
+ 2011-12-08 04:47 . 2011-12-08 04:47 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\12c424eed7ee0e9c017bf72ff09eb78c\PresentationCFFRasterizer.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\f9c514544c8e23220493cd42a0e20678\Microsoft.Vsa.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\a96b02abbfcaae424cfb91a198a9e0e9\Microsoft.VisualC.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 19456 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\fb545879af01e0ad8d38e89eb93ecdbc\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 31232 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\f80aaa90ab588eee908157b037e390f3\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 39936 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\f651195f6fca83fcc66751c54b02bf56\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 35840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\eeb01729312fcdd74d1b2772920719f1\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 30720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\ed59b4e4eb7cae29a8595b55d101829a\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 30720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\e7ffeda981717f1927b7b4b9afd4394f\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 18944 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\e0710763480c91425df0997b2f60af98\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\df1f23b22469bb893886c7d5eef7a6de\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-12-08 22:15 . 2011-12-08 22:15 33280 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\db9f8a68442f22e16d6039dfb60a2ff9\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-12-08 22:15 . 2011-12-08 22:15 16384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\d5db1562b89d4a4952e989994ba19ca3\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 36352 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\d05ae5a8c852d671a6c1f8007ad419fc\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 18944 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\c6f7c03a983910f16c355270ffc23530\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 19456 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\c3839b2c499d7e256c8a9b6a8b312a34\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 37376 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\be2fa199b85c7820aa867d3ccc84941a\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 32768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\b7497b3ff96c364d2730fa5b55404739\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 45568 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\b7265a6308be016b6c81db5085daf1dc\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-12-08 22:15 . 2011-12-08 22:15 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\b5e68486c39b0752de5bb144af2f7de6\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 18944 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\b2422ae2f6806ee473eebde11c70de61\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-12-08 22:15 . 2011-12-08 22:15 16384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\b04e76f39ac4918bcef59c7a18458942\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 19456 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\a8844048139471f4c7914a41f36a7e81\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 28672 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\a5d01d3f0085febf96c8d2aca6adb029\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-12-08 22:15 . 2011-12-08 22:15 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\a2df76f99c32ba9ddcd5540cbe9160ce\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-12-08 22:15 . 2011-12-08 22:15 16896 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\9f9dde45cf6f4cfb8eaa059a7ea742a1\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 28672 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\9b37a4d9fc21512ef3d1584f39f8d279\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 35328 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\9804c5ec5e7a8945d4da1c7e3caf40c7\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-12-08 22:15 . 2011-12-08 22:15 16896 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\920535669a5d8195d3d2ee4286d46e28\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 20992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\874cf99c8b9ff8436c4752c719ad9148\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 35840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\7ea17cc0fd933ca0b0fa45254ef42bb6\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 17920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\76da20752bc89db0fd168a46408fe145\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-12-08 22:15 . 2011-12-08 22:15 16384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\70ace5342bc5e80e4c43df681b73b065\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 31232 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\6b6a7c3cf2de26872a3bc29a2d48d1d9\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 36352 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\4fece4b0f86d43fff61fc24b341480fe\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 18944 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\4ce5b4c585d0b3a89e5fa1fe51c40cf3\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 30208 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\4a2c30677a2e45b936c287fa0a42d3ec\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 31232 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\4909c7c72fe6217e79fad2c169e4aef7\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-12-08 22:15 . 2011-12-08 22:15 16896 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\3a5233e10de32d4b59fd3d66c57453e2\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 18944 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\35994c6bc62d0ab9341d8aeda1539ac3\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-12-08 22:15 . 2011-12-08 22:15 16384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\2f3452b2e0d42c6c067a996a1ac903c1\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\29e58a784b3202cfa0fb183760ff6c88\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 33792 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\2108c82165ae1eacca1cfa79a62f4f1a\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-12-08 22:15 . 2011-12-08 22:15 17920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\18c740125eec6a8caec010cb1ffa8165\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 18432 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\16f523ceb9fa57a85775042809d766ee\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 30208 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\0fe4eb7e116bacc97d476713af23f42e\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-12-08 22:15 . 2011-12-08 22:15 17408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\01eba2bdd4d6baa3102dc8610e8cec92\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-12-08 22:13 . 2011-12-08 22:13 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\f5057c30d89ad8d99e38c946a68def9e\Microsoft.Build.Framework.ni.dll
+ 2011-12-08 22:13 . 2011-12-08 22:13 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\623c05a555ac0719a1367f511d4a9270\Microsoft.Build.Framework.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.WIA\98c93980bcd7a4ce51a2f11bf2a35543\Interop.WIA.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 73728 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\c77004af5163570e8d105896465e3fcd\DriversHQ.DriverDetective.ExceptionLogging.ni.dll
+ 2011-12-08 22:13 . 2011-12-08 22:13 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\c40d3caad8bff3c52db7e7562286406a\dfsvc.ni.exe
+ 2011-12-08 21:44 . 2011-12-08 21:44 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\d9228d58804dfd75fd92a4d12ffac8af\Accessibility.ni.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2010-10-24 19:15 . 2010-10-24 19:15 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2010-10-24 18:50 . 2010-10-24 18:50 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-12-07 05:54 . 2011-12-07 05:54 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2009-10-07 19:07 . 2011-02-17 12:32 5120 c:\windows\system32\xpsp4res.dll
- 2009-10-07 19:07 . 2010-08-26 12:52 5120 c:\windows\system32\xpsp4res.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2010-10-24 19:15 . 2010-10-24 19:15 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2010-10-24 19:14 . 2010-10-24 19:14 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 653136 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 569680 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcm90.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 159048 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_92453bb7\atl90.dll
+ 2011-05-14 08:17 . 2011-05-14 08:17 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll
+ 2011-05-14 08:12 . 2011-05-14 08:12 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcp80.dll
+ 2011-05-14 08:11 . 2011-05-14 08:11 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcm80.dll
- 2008-04-14 12:00 . 2010-06-18 17:45 293376 c:\windows\system32\winsrv.dll
+ 2008-04-14 12:00 . 2011-06-20 17:44 293376 c:\windows\system32\winsrv.dll
+ 2008-04-14 12:00 . 2011-08-22 23:48 916480 c:\windows\system32\wininet.dll
- 2008-04-14 12:00 . 2010-12-20 23:59 916480 c:\windows\system32\wininet.dll
+ 2008-04-14 12:00 . 2011-03-04 06:37 420864 c:\windows\system32\vbscript.dll
+ 2008-04-14 12:00 . 2011-08-22 23:48 105984 c:\windows\system32\url.dll
- 2008-04-14 12:00 . 2009-03-08 11:34 105984 c:\windows\system32\url.dll
+ 2008-04-14 12:00 . 2011-04-29 17:25 151552 c:\windows\system32\schannel.dll
+ 2008-04-14 12:00 . 2011-12-08 04:45 477426 c:\windows\system32\perfh009.dat
+ 2008-04-14 12:00 . 2010-12-20 17:32 551936 c:\windows\system32\oleaut32.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 551936 c:\windows\system32\oleaut32.dll
+ 2008-04-14 12:00 . 2011-08-22 23:48 206848 c:\windows\system32\occache.dll
- 2008-04-14 12:00 . 2010-12-20 23:59 206848 c:\windows\system32\occache.dll
+ 2008-04-14 12:00 . 2008-06-20 16:02 245248 c:\windows\system32\mswsock.dll
- 2008-04-14 12:00 . 2008-06-20 17:46 245248 c:\windows\system32\mswsock.dll
+ 2008-04-14 12:00 . 2011-08-22 23:48 611840 c:\windows\system32\mstime.dll
- 2008-04-14 12:00 . 2010-12-20 23:59 611840 c:\windows\system32\mstime.dll
- 2009-03-08 11:32 . 2010-12-20 23:59 602112 c:\windows\system32\msfeeds.dll
+ 2009-03-08 11:32 . 2011-08-22 23:48 602112 c:\windows\system32\msfeeds.dll
+ 2008-04-14 12:00 . 2011-02-08 13:33 974848 c:\windows\system32\mfc42u.dll
- 2008-04-14 12:00 . 2010-09-18 19:23 974848 c:\windows\system32\mfc42u.dll
+ 2008-04-14 12:00 . 2011-02-08 13:33 978944 c:\windows\system32\mfc42.dll
- 2008-04-14 12:00 . 2009-12-09 05:53 726528 c:\windows\system32\jscript.dll
+ 2008-04-14 12:00 . 2011-03-04 06:37 726528 c:\windows\system32\jscript.dll
- 2008-04-14 12:00 . 2010-12-20 23:59 184320 c:\windows\system32\iepeers.dll
+ 2008-04-14 12:00 . 2011-08-22 23:48 184320 c:\windows\system32\iepeers.dll
+ 2008-04-14 12:00 . 2011-08-22 23:48 387584 c:\windows\system32\iedkcs32.dll
- 2008-04-14 12:00 . 2010-12-20 23:59 387584 c:\windows\system32\iedkcs32.dll
+ 2008-04-14 12:00 . 2011-08-22 11:56 174080 c:\windows\system32\ie4uinit.exe
+ 2009-10-06 17:31 . 2011-12-07 06:18 144424 c:\windows\system32\FNTCACHE.DAT
- 2009-10-06 17:31 . 2011-09-26 04:53 144424 c:\windows\system32\FNTCACHE.DAT
+ 2008-04-14 12:00 . 2011-02-17 13:18 357888 c:\windows\system32\drivers\srv.sys
- 2009-10-07 00:43 . 2008-04-14 12:00 139656 c:\windows\system32\drivers\rdpwd.sys
+ 2009-10-07 00:43 . 2011-06-24 14:10 139656 c:\windows\system32\drivers\rdpwd.sys
+ 2008-04-14 12:00 . 2011-04-21 13:37 105472 c:\windows\system32\drivers\mup.sys
+ 2008-04-14 12:00 . 2011-07-15 13:29 456320 c:\windows\system32\drivers\mrxsmb.sys
+ 2010-08-03 22:23 . 2011-07-11 08:14 134608 c:\windows\system32\drivers\AVGIDSDriver.sys
+ 2008-04-14 12:00 . 2011-08-17 13:49 138496 c:\windows\system32\drivers\afd.sys
- 2008-04-14 12:00 . 2008-08-14 10:04 138496 c:\windows\system32\drivers\afd.sys
+ 2008-04-14 12:00 . 2011-03-03 06:55 149504 c:\windows\system32\dnsapi.dll
- 2008-04-14 12:00 . 2010-06-18 17:45 293376 c:\windows\system32\dllcache\winsrv.dll
+ 2008-04-14 12:00 . 2011-06-20 17:44 293376 c:\windows\system32\dllcache\winsrv.dll
+ 2008-04-14 12:00 . 2011-08-22 23:48 916480 c:\windows\system32\dllcache\wininet.dll
- 2008-04-14 12:00 . 2010-12-20 23:59 916480 c:\windows\system32\dllcache\wininet.dll
+ 2009-10-07 00:46 . 2011-04-30 03:01 758784 c:\windows\system32\dllcache\vgx.dll
+ 2008-04-14 12:00 . 2011-03-04 06:37 420864 c:\windows\system32\dllcache\vbscript.dll
+ 2008-04-14 12:00 . 2011-08-22 23:48 105984 c:\windows\system32\dllcache\url.dll
- 2008-04-14 12:00 . 2009-03-08 11:34 105984 c:\windows\system32\dllcache\url.dll
+ 2008-04-14 12:00 . 2011-02-17 13:18 357888 c:\windows\system32\dllcache\srv.sys
+ 2008-04-14 12:00 . 2011-04-29 17:25 151552 c:\windows\system32\dllcache\schannel.dll
+ 2009-10-07 00:43 . 2011-06-24 14:10 139656 c:\windows\system32\dllcache\rdpwd.sys
- 2009-10-07 00:43 . 2008-04-14 12:00 139656 c:\windows\system32\dllcache\rdpwd.sys
- 2008-04-14 12:00 . 2008-04-14 12:00 551936 c:\windows\system32\dllcache\oleaut32.dll
+ 2008-04-14 12:00 . 2010-12-20 17:32 551936 c:\windows\system32\dllcache\oleaut32.dll
- 2008-04-14 12:00 . 2009-10-08 21:57 220160 c:\windows\system32\dllcache\oleacc.dll
+ 2008-04-14 12:00 . 2011-09-26 18:41 220160 c:\windows\system32\dllcache\oleacc.dll
+ 2008-04-14 12:00 . 2011-08-22 23:48 206848 c:\windows\system32\dllcache\occache.dll
- 2008-04-14 12:00 . 2010-12-20 23:59 206848 c:\windows\system32\dllcache\occache.dll
+ 2008-04-14 12:00 . 2011-04-21 13:37 105472 c:\windows\system32\dllcache\mup.sys
- 2008-04-14 12:00 . 2008-06-20 17:46 245248 c:\windows\system32\dllcache\mswsock.dll
+ 2008-04-14 12:00 . 2008-06-20 16:02 245248 c:\windows\system32\dllcache\mswsock.dll
- 2008-04-14 12:00 . 2010-12-20 23:59 611840 c:\windows\system32\dllcache\mstime.dll
+ 2008-04-14 12:00 . 2011-08-22 23:48 611840 c:\windows\system32\dllcache\mstime.dll
+ 2009-11-30 15:16 . 2011-08-22 23:48 602112 c:\windows\system32\dllcache\msfeeds.dll
- 2009-11-30 15:16 . 2010-12-20 23:59 602112 c:\windows\system32\dllcache\msfeeds.dll
+ 2009-11-29 13:13 . 2011-07-15 13:29 456320 c:\windows\system32\dllcache\mrxsmb.sys
- 2008-04-14 12:00 . 2010-09-18 19:23 974848 c:\windows\system32\dllcache\mfc42u.dll
+ 2008-04-14 12:00 . 2011-02-08 13:33 974848 c:\windows\system32\dllcache\mfc42u.dll
+ 2008-04-14 12:00 . 2011-02-08 13:33 978944 c:\windows\system32\dllcache\mfc42.dll
- 2008-04-14 12:00 . 2009-12-09 05:53 726528 c:\windows\system32\dllcache\jscript.dll
+ 2008-04-14 12:00 . 2011-03-04 06:37 726528 c:\windows\system32\dllcache\jscript.dll
- 2009-10-07 00:45 . 2010-06-09 07:43 692736 c:\windows\system32\dllcache\inetcomm.dll
+ 2009-10-07 00:45 . 2011-10-10 14:22 692736 c:\windows\system32\dllcache\inetcomm.dll
- 2009-11-30 15:16 . 2010-12-20 23:59 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2009-11-30 15:16 . 2011-08-22 23:48 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2008-04-14 12:00 . 2011-08-22 23:48 184320 c:\windows\system32\dllcache\iepeers.dll
- 2008-04-14 12:00 . 2010-12-20 23:59 184320 c:\windows\system32\dllcache\iepeers.dll
- 2010-06-16 15:12 . 2010-12-20 23:59 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2010-06-16 15:12 . 2011-08-22 23:48 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2008-04-14 12:00 . 2011-08-22 23:48 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2008-04-14 12:00 . 2010-12-20 23:59 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-04-14 12:00 . 2011-08-22 11:56 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-04-14 12:00 . 2011-03-03 06:55 149504 c:\windows\system32\dllcache\dnsapi.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 599040 c:\windows\system32\dllcache\crypt32.dll
+ 2008-04-14 12:00 . 2011-09-28 07:06 599040 c:\windows\system32\dllcache\crypt32.dll
+ 2008-04-14 12:00 . 2011-02-15 12:56 290432 c:\windows\system32\dllcache\atmfd.dll
+ 2008-04-14 12:00 . 2011-08-17 13:49 138496 c:\windows\system32\dllcache\afd.sys
- 2008-04-14 12:00 . 2008-08-14 10:04 138496 c:\windows\system32\dllcache\afd.sys
+ 2008-04-14 12:00 . 2011-02-15 12:56 290432 c:\windows\system32\atmfd.dll
+ 2011-03-25 13:15 . 2011-03-25 13:15 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
- 2010-05-11 13:40 . 2010-05-11 13:40 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2011-03-25 13:15 . 2011-03-25 13:15 363856 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
- 2010-05-11 13:40 . 2010-05-11 13:40 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2011-03-25 13:15 . 2011-03-25 13:15 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
- 2010-09-23 09:26 . 2010-09-23 09:26 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2011-07-07 19:04 . 2011-07-07 19:04 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2011-07-07 19:01 . 2011-07-07 19:01 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2010-09-23 09:25 . 2010-09-23 09:25 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2010-09-23 10:17 . 2010-09-23 10:17 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-07-07 20:09 . 2011-07-07 20:09 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-12-07 06:11 . 2011-12-07 06:11 223744 c:\windows\Installer\532e14.msi
+ 2011-12-07 06:00 . 2011-12-07 06:00 467456 c:\windows\Installer\532de1.msi
- 2009-10-17 15:01 . 2010-12-19 07:24 135168 c:\windows\Installer\{90850409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-10-17 15:01 . 2011-12-07 06:02 135168 c:\windows\Installer\{90850409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2011-12-07 06:03 . 2010-12-20 23:59 916480 c:\windows\ie8updates\KB2586448-IE8\wininet.dll
+ 2011-12-07 06:03 . 2009-03-08 11:34 105984 c:\windows\ie8updates\KB2586448-IE8\url.dll
+ 2011-12-07 06:03 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2586448-IE8\spuninst\updspapi.dll
+ 2011-12-07 06:03 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2586448-IE8\spuninst\spuninst.exe
+ 2011-12-07 06:03 . 2010-12-20 23:59 206848 c:\windows\ie8updates\KB2586448-IE8\occache.dll
+ 2011-12-07 06:03 . 2010-12-20 23:59 611840 c:\windows\ie8updates\KB2586448-IE8\mstime.dll
+ 2011-12-07 06:03 . 2010-12-20 23:59 602112 c:\windows\ie8updates\KB2586448-IE8\msfeeds.dll
+ 2011-12-07 06:03 . 2010-12-20 23:59 247808 c:\windows\ie8updates\KB2586448-IE8\ieproxy.dll
+ 2011-12-07 06:03 . 2010-12-20 23:59 184320 c:\windows\ie8updates\KB2586448-IE8\iepeers.dll
+ 2011-12-07 06:03 . 2010-12-20 23:59 743424 c:\windows\ie8updates\KB2586448-IE8\iedvtool.dll
+ 2011-12-07 06:03 . 2010-12-20 23:59 387584 c:\windows\ie8updates\KB2586448-IE8\iedkcs32.dll
+ 2011-12-07 06:03 . 2010-12-20 12:55 173568 c:\windows\ie8updates\KB2586448-IE8\ie4uinit.exe
+ 2011-12-07 05:56 . 2009-03-08 11:33 759296 c:\windows\ie8updates\KB2544521-IE8\vgx.dll
+ 2011-12-07 05:56 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2544521-IE8\spuninst\updspapi.dll
+ 2011-12-07 05:56 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2544521-IE8\spuninst\spuninst.exe
+ 2011-12-07 05:56 . 2010-03-10 06:15 420352 c:\windows\ie8updates\KB2510531-IE8\vbscript.dll
+ 2011-12-07 05:56 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2510531-IE8\spuninst\updspapi.dll
+ 2011-12-07 05:56 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2510531-IE8\spuninst\spuninst.exe
+ 2011-12-07 05:56 . 2009-12-09 05:53 726528 c:\windows\ie8updates\KB2510531-IE8\jscript.dll
+ 2009-11-29 13:13 . 2011-07-15 13:29 456320 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2011-12-07 05:55 . 2011-12-07 05:55 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_061634ac\System.Drawing.dll
+ 2011-12-07 05:55 . 2011-12-07 05:55 192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_ba9e312d\System.Drawing.Design.dll
+ 2011-12-07 05:55 . 2011-12-07 05:55 118784 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_3e136743\CustomMarshalers.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\XPBurnComponent\2c97eae1d4baf90cdd074422f73a3c09\XPBurnComponent.ni.dll
+ 2011-12-08 22:13 . 2011-12-08 22:13 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\cc14c69205b984edba1db26fd5e421ac\WsatConfig.ni.exe
+ 2011-12-08 22:12 . 2011-12-08 22:12 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\be230222afc4ac16af2745c66a9b5014\WindowsLiveLocal.WriterPlugin.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 152064 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\fc0df76553f27dbe81b44e1feff6241a\WindowsLive.Writer.HtmlParser.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 334848 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\fa2482d4152af4d1792570932da229d6\WindowsLive.Writer.Interop.Mshtml.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f56e04e5688b837d1da24f16c7bd23c1\WindowsLive.Writer.Mshtml.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 851968 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ed2c16c41895f3ca9a221c54ef0afb95\WindowsLive.Writer.BlogClient.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 313856 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\d78f83ddd58e30d6b7beb63b7534f092\WindowsLive.Writer.Interop.SHDocVw.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 428032 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b732fc4a98715dc49365641879c7cde0\WindowsLive.Writer.Localization.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b6a4d3bddbbafbcc633e7d09a3b3b7c0\WindowsLive.Writer.FileDestinations.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 117760 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b2fa3d80779829ca0d29b039eba7b6c8\WindowsLive.Writer.Instrumentation.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 843776 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b1408a406bf6cedf6dabd8bb91b10933\WindowsLive.Writer.Controls.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 108544 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\a46a0c3a6f9cdd29bc9e1518ddfff1cf\WindowsLive.Writer.Passport.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 174080 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\8c5e2af7f9432f5937528be8eca7e74f\WindowsLive.Writer.BrowserControl.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 319488 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\6303299e64ab859f46036cfbf2426d11\WindowsLive.Writer.Interop.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 594944 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\51cf4e293cd48162a780437877102c77\WindowsLive.Writer.HtmlEditor.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 322048 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\17a0bb4a638ab04b49710aa1976adfbd\WindowsLive.Writer.SpellChecker.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 118784 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\03b22b0e79cac36b7d600f7759fcea32\WindowsLive.Writer.Extensibility.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 145920 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\6ccef8f8ef1459d95a24a40f6ca4e138\WindowsLive.Client.ni.dll
+ 2011-12-08 18:18 . 2011-12-08 18:18 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\39ce0c9c9cc294c0ee26c4ff01522961\WindowsFormsIntegration.ni.dll
+ 2011-12-08 18:17 . 2011-12-08 18:17 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\431e918aee8da919f5b9e3a5195ccf93\UIAutomationClient.ni.dll
+ 2011-12-09 00:20 . 2011-12-09 00:20 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP410.tmp\System.Web.Entity.Design.dll
+ 2011-12-08 23:15 . 2011-12-08 23:15 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3F2.tmp\System.Web.Routing.dll
+ 2011-12-08 22:52 . 2011-12-08 22:52 169984 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3DC.tmp\System.Management.Automation.resources.dll
+ 2011-12-08 17:47 . 2011-12-08 17:47 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1A.tmp\PresentationFramework.Aero.dll
+ 2011-12-09 01:40 . 2011-12-09 01:40 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\946eefb99bc116ee68e0e7c69a5a8a5c\System.Xml.Linq.ni.dll
+ 2011-12-09 01:31 . 2011-12-09 01:31 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\a82eef3128b9527dc05b3c8667e713bc\System.Web.Routing.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\203c148c913357bfc2ae9d209101f2b3\System.Web.RegularExpressions.ni.dll
+ 2011-12-09 00:37 . 2011-12-09 00:37 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\f89fe39468ea6faf71c4257c89cf3c54\System.Web.Extensions.Design.ni.dll
+ 2011-12-08 23:37 . 2011-12-08 23:37 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\2314ff800782dc85224e69e802a073f7\System.Web.Entity.ni.dll
+ 2011-12-09 00:34 . 2011-12-09 00:34 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\f690a8f5d784a5bb20f2cbaa7277eb6c\System.Web.Entity.Design.ni.dll
+ 2011-12-08 23:33 . 2011-12-08 23:33 548864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\c2e3f12791a8ea21342124bff6ac080f\System.Web.DynamicData.ni.dll
+ 2011-12-08 23:11 . 2011-12-08 23:11 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\5f8e87b47465a038403e73012c6d102a\System.Web.Abstractions.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\846dd505f97805f00999ee26aec9bf75\System.Transactions.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\70a1400affdc775d7c7398e036359286\System.ServiceProcess.ni.dll
+ 2011-12-08 21:57 . 2011-12-08 21:57 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\de9cd25ccb24bcf8a0316756e766721f\System.Security.ni.dll
+ 2011-12-08 21:57 . 2011-12-08 21:57 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\21248037960cf6dfa2ce401d355bd6c9\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b7e0214a811f81e09041864081139641\System.Runtime.Remoting.ni.dll
+ 2011-12-08 22:54 . 2011-12-08 22:54 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\480ea914e13fe41cdd8fb542bb1f7e81\System.Net.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\6e563a58e6fc0117070d5b8fd59e4e1b\System.Management.ni.dll
+ 2011-12-08 22:54 . 2011-12-08 22:54 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\dc72c7581f1b3794c0ea595ba02ff7ad\System.Management.Instrumentation.ni.dll
+ 2011-12-08 22:53 . 2011-12-08 22:53 177664 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\bb547b7b93e6b60893a7c7c1421b928f\System.Management.Automation.resources.ni.dll
+ 2011-12-08 22:31 . 2011-12-08 22:31 172544 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\b9c71ec060b92fc33fdee5781cd69a1d\System.Management.Automation.resources.ni.dll
+ 2011-12-08 22:53 . 2011-12-08 22:53 169472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\a98a5d4526a89b0ec9dc772bca4b7a28\System.Management.Automation.resources.ni.dll
+ 2011-12-08 22:52 . 2011-12-08 22:52 181248 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\99288fe5d657d3ad338b06be80129cee\System.Management.Automation.resources.ni.dll
+ 2011-12-08 22:53 . 2011-12-08 22:53 154624 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\6b9ad98853d7033e1707298b719a2997\System.Management.Automation.resources.ni.dll
+ 2011-12-08 22:53 . 2011-12-08 22:53 154112 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\5f2c4c29a6cd2b6ff117c4d5e27a9fd3\System.Management.Automation.resources.ni.dll
+ 2011-12-08 22:53 . 2011-12-08 22:53 221184 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\55dc0d461d47a4aedc2c4d30fa772e59\System.Management.Automation.resources.ni.dll
+ 2011-12-08 22:31 . 2011-12-08 22:31 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\4a44c4f6282edacbf9206f19cab4379d\System.Management.Automation.resources.ni.dll
+ 2011-12-08 22:31 . 2011-12-08 22:31 160256 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\35b34a452180a868171e1364bcc02208\System.Management.Automation.resources.ni.dll
+ 2011-12-08 22:53 . 2011-12-08 22:53 188928 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\2fed8358e79b5eb67eae317b8d062c08\System.Management.Automation.resources.ni.dll
+ 2011-12-08 22:10 . 2011-12-08 22:10 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\fcf8612a210d1f76e0b37dc8467b4696\System.IO.Log.ni.dll
+ 2011-12-08 22:10 . 2011-12-08 22:10 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\ec017b5a95d02fccaefd835490ef1e14\System.IdentityModel.Selectors.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\75f452279422a7898e840ee5768c9d2e\System.EnterpriseServices.Wrapper.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\75f452279422a7898e840ee5768c9d2e\System.EnterpriseServices.ni.dll
+ 2011-12-08 18:11 . 2011-12-08 18:11 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\f7cd3d07c15366b76fe4c38d24455d6b\System.Drawing.Design.ni.dll
+ 2011-12-08 22:30 . 2011-12-08 22:30 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\822c996e6ad4901219b7de399a6f78bf\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\1ffe911e62f482e42be2c4428bd08c10\System.DirectoryServices.Protocols.ni.dll
+ 2011-12-08 22:30 . 2011-12-08 22:30 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\e1c009b2c9becdb732a2ea45f32a46b8\System.Data.Services.Design.ni.dll
+ 2011-12-08 22:29 . 2011-12-08 22:29 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\04267c1dbdcdd8ec37e1518126767ead\System.Data.Entity.Design.ni.dll
+ 2011-12-08 22:26 . 2011-12-08 22:26 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\f2a6d41b3f6e26eea6dcac9298aa637b\System.Data.DataSetExtensions.ni.dll
+ 2011-12-08 21:57 . 2011-12-08 21:57 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\77df2cd21a5b85a1605b335aa9ad9d44\System.Configuration.ni.dll
+ 2011-12-08 21:57 . 2011-12-08 21:57 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\585e68739b2a8aff61ee6b2786513245\System.Configuration.Install.ni.dll
+ 2011-12-08 22:26 . 2011-12-08 22:26 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\fbf6ef12d1456058acde29f2640092fb\System.AddIn.ni.dll
+ 2011-12-08 22:13 . 2011-12-08 22:13 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\896e42071939e038008b0bbbfed1213c\SMSvcHost.ni.exe
+ 2011-12-08 22:13 . 2011-12-08 22:13 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\ca07e9cf488af1290d2340d682574a24\SMDiagnostics.ni.dll
+ 2011-12-08 22:13 . 2011-12-08 22:13 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\a5aa977dd575a6beb3a416bd480b98a7\ServiceModelReg.ni.exe
+ 2011-12-08 17:52 . 2011-12-08 17:52 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\f52e48f55258d0a04fbab3a1f93752e9\PresentationFramework.Classic.ni.dll
+ 2011-12-08 17:59 . 2011-12-08 17:59 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\b7795999cc67f3a6cec40f5b24005e00\PresentationFramework.Luna.ni.dll
+ 2011-12-08 18:01 . 2011-12-08 18:01 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\09f5af61ea2af04eb32c04b3091ffc86\PresentationFramework.Royale.ni.dll
+ 2011-12-08 22:04 . 2011-12-08 22:04 900096 c:\windows\assembly\NativeImages_v2.0.50727_32\PaintDotNet.SystemL#\359964375cbd59cebf5b5248e700980f\PaintDotNet.SystemLayer.ni.dll
+ 2011-12-08 22:04 . 2011-12-08 22:04 161280 c:\windows\assembly\NativeImages_v2.0.50727_32\PaintDotNet.SystemL#\2447b346de034dfb6df8bddb5d37fe67\PaintDotNet.SystemLayer.Native.x86.ni.dll
+ 2011-12-08 22:04 . 2011-12-08 22:04 388608 c:\windows\assembly\NativeImages_v2.0.50727_32\PaintDotNet.Resourc#\e083236b043754bb73c6c94cabd3b81f\PaintDotNet.Resources.ni.dll
+ 2011-12-08 22:04 . 2011-12-08 22:04 813056 c:\windows\assembly\NativeImages_v2.0.50727_32\PaintDotNet.Effects\92e7ce899af8113e239c1d816587972e\PaintDotNet.Effects.ni.dll
+ 2011-12-08 22:04 . 2011-12-08 22:04 568832 c:\windows\assembly\NativeImages_v2.0.50727_32\PaintDotNet.Data\5640218f2347b5a6936cf0ed70339d66\PaintDotNet.Data.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 816128 c:\windows\assembly\NativeImages_v2.0.50727_32\PaintDotNet.Base\fb5351d952ad079475d47ccf4980327c\PaintDotNet.Base.ni.dll
+ 2011-12-08 22:13 . 2011-12-08 22:13 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\2d89c7b72bc8e527b26d5b6f3b931012\MSBuild.ni.exe
+ 2011-12-08 22:13 . 2011-12-08 22:13 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\39e9d172f0cf5eec30b1b67212cc032b\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 148992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\3ffb079ac25db6c8cdce1eaa39f2a956\Microsoft.Practices.EnterpriseLibrary.Security.Cryptography.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 303616 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\1c9ef0df15600a2699a9fe818f25b63c\Microsoft.Practices.ObjectBuilder.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 309248 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\190c5f102eb62939b1749b7c1308f49d\Microsoft.Practices.EnterpriseLibrary.Common.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 968192 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\eae2ab662e4b44aacd4cebd3f9b6c34f\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 433664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\9bcb002ea577b825f7c7872ec21b78a3\Microsoft.PowerShell.Commands.Management.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 492032 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\97869a9a27244319a1bcb5c2d446a1cc\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2011-12-08 22:15 . 2011-12-08 22:15 148480 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\4d166154a2d5a4497acccfcd08355267\Microsoft.PowerShell.Security.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\f1b0ec3ccde9142e67ac681fb521ac66\Microsoft.Build.Utilities.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\9250f038410f0d6432e3ccb0b046862b\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2011-12-08 22:13 . 2011-12-08 22:13 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\a4672179aba638cd78bdfe268391b47b\Microsoft.Build.Engine.ni.dll
+ 2011-12-08 22:13 . 2011-12-08 22:13 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\37db660a84ee52b61a7ca55812581bbd\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 230400 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\b0d29feeeda290856bee15d0fccab7d9\Microsoft.ApplicationBlocks.Updater.ni.dll
+ 2011-12-08 22:13 . 2011-12-08 22:13 312320 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.SHDocVw\210e0c5602a300f3f7cd63ee81437521\Interop.SHDocVw.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 547840 c:\windows\assembly\NativeImages_v2.0.50727_32\ICSharpCode.SharpZi#\1e25a95f3506bace6c9475638c730dbb\ICSharpCode.SharpZipLib.ni.dll
+ 2011-12-08 21:57 . 2011-12-08 21:57 338944 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\b513b8ca568600b340178284779aa724\DriversHQ.DriverDetective.Client.Communication.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\1aeda53532a33c47ed8426a54c36385c\DriversHQ.DriverDetective.Common.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 529920 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.Common\e9b38c4a3d81a763931c4ba57fe66c83\DriversHQ.Common.ni.dll
+ 2011-12-08 22:13 . 2011-12-08 22:13 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\80bd17388778c90f301746ad88700758\CustomMarshalers.ni.dll
+ 2011-12-08 22:13 . 2011-12-08 22:13 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\fe9a21b94803f74697bb42b9d1fdea5b\ComSvcConfig.ni.exe
+ 2011-12-08 21:56 . 2011-12-08 21:56 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\f160c8e40b60edd47ae74b0b911fece1\AspNetMMCExt.ni.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2010-10-24 19:15 . 2010-10-24 19:15 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2010-10-24 19:15 . 2010-10-24 19:15 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2010-10-24 19:15 . 2010-10-24 19:15 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2010-10-24 19:15 . 2010-10-24 19:15 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2010-10-24 19:15 . 2010-10-24 19:15 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-12-07 04:41 . 2010-10-23 00:51 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22509_x-ww_c7dad023\GdiPlus.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 3781960 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90u.dll
+ 2011-04-19 05:51 . 2011-04-19 05:51 3766600 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90.dll
+ 2011-05-14 03:04 . 2011-05-14 03:04 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfc80u.dll
+ 2011-05-14 03:04 . 2011-05-14 03:04 1101824 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfc80.dll
+ 2008-04-14 12:00 . 2011-09-06 13:20 1858944 c:\windows\system32\win32k.sys
+ 2008-04-14 12:00 . 2011-08-22 23:48 1212416 c:\windows\system32\urlmon.dll
+ 2008-04-14 12:00 . 2011-10-03 08:35 5971456 c:\windows\system32\mshtml.dll
+ 2009-03-08 11:32 . 2011-08-22 23:48 2000384 c:\windows\system32\iertutil.dll
+ 2008-04-14 12:00 . 2011-09-06 13:20 1858944 c:\windows\system32\dllcache\win32k.sys
+ 2008-04-14 12:00 . 2011-08-22 23:48 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-14 12:00 . 2011-10-03 08:35 5971456 c:\windows\system32\dllcache\mshtml.dll
+ 2009-11-30 15:16 . 2011-08-22 23:48 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2011-03-25 13:15 . 2011-03-25 13:15 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
- 2008-07-25 18:17 . 2008-07-25 18:17 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
- 2010-03-23 12:32 . 2010-03-23 12:32 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2011-04-29 04:50 . 2011-04-29 04:50 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2011-03-25 13:15 . 2011-03-25 13:15 5912400 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
- 2010-05-11 13:40 . 2010-05-11 13:40 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2011-03-25 13:15 . 2011-03-25 13:15 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2011-07-08 20:59 . 2011-07-08 20:59 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2010-09-23 22:55 . 2010-09-23 22:55 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2011-07-08 20:59 . 2011-07-08 20:59 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2010-09-23 22:55 . 2010-09-23 22:55 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2011-07-07 19:02 . 2011-07-07 19:02 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
- 2010-09-23 09:26 . 2010-09-23 09:26 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2011-07-07 19:02 . 2011-07-07 19:02 2527232 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2011-07-08 20:59 . 2011-07-08 20:59 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
- 2010-09-23 22:55 . 2010-09-23 22:55 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2011-05-02 07:06 . 2011-05-02 07:06 2705920 c:\windows\Installer\a424fc.msp
+ 2011-08-11 00:43 . 2011-08-11 00:43 3795968 c:\windows\Installer\a424e7.msp
+ 2011-04-29 19:28 . 2011-04-29 19:28 1995264 c:\windows\Installer\532e1b.msp
+ 2011-08-11 00:42 . 2011-08-11 00:42 7070208 c:\windows\Installer\532e0d.msp
+ 2011-05-18 01:28 . 2011-05-18 01:28 6862848 c:\windows\Installer\532e05.msp
+ 2011-09-07 04:48 . 2011-09-07 04:48 8181248 c:\windows\Installer\532dfc.msp
+ 2011-07-27 14:39 . 2011-07-27 14:39 9892352 c:\windows\Installer\532df0.msp
+ 2010-11-21 06:33 . 2010-11-21 06:33 1980928 c:\windows\Installer\532de8.msp
+ 2011-04-29 19:30 . 2011-04-29 19:30 1197056 c:\windows\Installer\532dd0.msp
+ 2011-12-07 04:15 . 2011-12-07 04:15 4671488 c:\windows\Installer\15227e.msi
+ 2011-12-07 04:07 . 2011-12-07 04:07 2186240 c:\windows\Installer\15225b.msi
+ 2009-04-04 01:21 . 2009-04-04 01:21 8543096 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6425\OARTCONV.DLL
+ 2011-12-07 06:03 . 2010-12-20 23:59 1210880 c:\windows\ie8updates\KB2586448-IE8\urlmon.dll
+ 2011-12-07 06:03 . 2010-12-20 23:59 5961216 c:\windows\ie8updates\KB2586448-IE8\mshtml.dll
+ 2011-12-07 06:03 . 2010-12-20 23:59 1991680 c:\windows\ie8updates\KB2586448-IE8\iertutil.dll
+ 2011-12-07 05:55 . 2011-12-07 05:55 4792320 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_b2e8f2ce\System.dll
+ 2011-12-07 05:54 . 2011-12-07 05:54 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_80276940\System.dll
+ 2011-12-07 05:56 . 2011-12-07 05:56 5513216 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_e5c3651b\System.Xml.dll
+ 2011-12-07 05:55 . 2011-12-07 05:55 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_3525181b\System.Xml.dll
+ 2011-12-07 05:56 . 2011-12-07 05:56 7884800 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_ff8256a6\System.Windows.Forms.dll
+ 2011-12-07 05:55 . 2011-12-07 05:55 3018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_f81e6b27\System.Windows.Forms.dll
+ 2011-12-07 05:56 . 2011-12-07 05:56 2244608 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_71ae18ca\System.Drawing.dll
+ 2011-12-07 05:56 . 2011-12-07 05:56 3395584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_f19bfd77\System.Design.dll
+ 2011-12-07 05:55 . 2011-12-07 05:55 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_7ce1f6ef\System.Design.dll
+ 2011-12-07 05:56 . 2011-12-07 05:56 8908800 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_27d55bb4\mscorlib.dll
+ 2011-12-07 05:55 . 2011-12-07 05:55 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_2640b73a\mscorlib.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 6392832 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\cc51b3dd4d9c89a2c0c1280de68948ce\WindowsLive.Writer.PostEditor.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 2002432 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\95c198599047f7c9253cd76b5abd8d10\WindowsLive.Writer.CoreServices.ni.dll
+ 2011-12-08 22:12 . 2011-12-08 22:12 1105920 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\7d8a845118aca7d541ce818b367540f8\WindowsLive.Writer.ApplicationFramework.ni.dll
+ 2011-12-08 04:47 . 2011-12-08 04:47 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\fd6e0cd6f124a6d041ef1b4c9a5f080b\WindowsBase.ni.dll
+ 2011-12-08 18:18 . 2011-12-08 18:18 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\162600dde59fbaa0c048a949158ecba3\UIAutomationClientsideProviders.ni.dll
+ 2011-12-09 01:32 . 2011-12-09 01:32 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP5A.tmp\System.Workflow.Activities.dll
+ 2011-12-08 04:47 . 2011-12-08 04:47 7950848 c:\windows\assembly\NativeImages_v2.0.50727_32\System\e6c79e1d71b0c9000afd7e5e439b5c54\System.ni.dll
+ 2011-12-08 18:14 . 2011-12-08 18:14 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\10154dcad2d62f226af2fd4211460a4b\System.Xml.ni.dll
+ 2011-12-09 01:40 . 2011-12-09 01:40 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\22229a30650a9afbac984e1093898b13\System.WorkflowServices.ni.dll
+ 2011-12-09 01:39 . 2011-12-09 01:39 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\4d6b3cc1fc7a4788612241af7966715a\System.Workflow.Runtime.ni.dll
+ 2011-12-09 01:38 . 2011-12-09 01:38 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\e4c9853af945c9cfede19f3faf18af6e\System.Workflow.ComponentModel.ni.dll
+ 2011-12-09 01:37 . 2011-12-09 01:37 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\ab4b50c7c789e46a485903365765fde8\System.Workflow.Activities.ni.dll
+ 2011-12-08 21:57 . 2011-12-08 21:57 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\a2392c995b1bb6b63079091259222357\System.Web.Services.ni.dll
+ 2011-12-09 01:30 . 2011-12-09 01:30 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\3da92a0b9b8ac97e11ca8bf4df671a78\System.Web.Mobile.ni.dll
+ 2011-12-08 23:32 . 2011-12-08 23:32 2405376 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\01f4d6aa3299a41b8578b7e96afdcfb1\System.Web.Extensions.ni.dll
+ 2011-12-08 18:12 . 2011-12-08 18:12 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\e1208f0d981c420fc59f806bfbaa713b\System.Speech.ni.dll
+ 2011-12-08 23:09 . 2011-12-08 23:09 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\27e1b8dfd5e1ccf2c5b9efc51f674c69\System.ServiceModel.Web.ni.dll
+ 2011-12-08 22:10 . 2011-12-08 22:10 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\dece01bd9e9c32e47630fdfc78d3bd32\System.Runtime.Serialization.ni.dll
+ 2011-12-08 18:12 . 2011-12-08 18:12 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\90b444d02047ef27921153d46967ef0e\System.Printing.ni.dll
+ 2011-12-08 22:31 . 2011-12-08 22:31 4949504 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\8a9589fd87302a1333af22962bb5f1f1\System.Management.Automation.ni.dll
+ 2011-12-08 22:10 . 2011-12-08 22:10 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\a50e2fc92db32751857fb8d297f9d7bc\System.IdentityModel.ni.dll
+ 2011-12-08 18:11 . 2011-12-08 18:11 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\7ed09623172a292eaee51e2e3bcaf784\System.Drawing.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\259ecf480769f4e60514b7ae2abaa6f1\System.DirectoryServices.ni.dll
+ 2011-12-08 21:57 . 2011-12-08 21:57 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\71cf3eb40fc38e6ac8fba09e872d2878\System.Deployment.ni.dll
+ 2011-12-08 18:08 . 2011-12-08 18:08 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\db2d84e279807592a680ef4135e9fe9a\System.Data.ni.dll
+ 2011-12-08 21:57 . 2011-12-08 21:57 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\0b16305773369cf740c6a2b1f1d785b2\System.Data.SqlXml.ni.dll
+ 2011-12-08 22:29 . 2011-12-08 22:29 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\c1b9b8ce390548dcca661a5e6a908408\System.Data.Services.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 1115136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\c729750d54f6e7427230622bcccd4709\System.Data.OracleClient.ni.dll
+ 2011-12-08 18:09 . 2011-12-08 18:09 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\571af34939797a7c1cd05b0b925a45bf\System.Data.Linq.ni.dll
+ 2011-12-08 22:28 . 2011-12-08 22:28 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\2b58cc071d6bf0c741e91f86c09de5d7\System.Data.Entity.ni.dll
+ 2011-12-08 18:07 . 2011-12-08 18:07 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\e54e013315849f5e34d8f2a8e7fdb450\System.Core.ni.dll
+ 2011-12-08 18:06 . 2011-12-08 18:06 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\24ab0cacc77e8696ceff3157942a2de4\ReachFramework.ni.dll
+ 2011-12-08 22:25 . 2011-12-08 22:25 2355200 c:\windows\assembly\NativeImages_v2.0.50727_32\QTTabBar\7ffaf86ab1ec046e12320f3eba93af79\QTTabBar.ni.dll
+ 2011-12-08 18:04 . 2011-12-08 18:04 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\fac1ca86f4fea17de40d7fdaba38563e\PresentationUI.ni.dll
+ 2011-12-08 04:47 . 2011-12-08 04:47 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b187becbc388c4ce7f33ede4da76e7b1\PresentationBuildTasks.ni.dll
+ 2011-12-08 22:04 . 2011-12-08 22:04 3192832 c:\windows\assembly\NativeImages_v2.0.50727_32\PaintDotNet\2b62afd29286711f88d12defd79a667c\PaintDotNet.ni.exe
+ 2011-12-08 22:04 . 2011-12-08 22:04 1850880 c:\windows\assembly\NativeImages_v2.0.50727_32\PaintDotNet.Core\bd787cb864d5f5b726e61af6413af823\PaintDotNet.Core.ni.dll
+ 2011-12-08 22:25 . 2011-12-08 22:25 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\c6b19db2534042d435ede580f92bc75c\Microsoft.VisualBasic.ni.dll
+ 2011-12-08 22:13 . 2011-12-08 22:13 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\08594c4ba9ea0253a836fe1d8d341984\Microsoft.Transactions.Bridge.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\345abd035c9378667b1cac54c1f21c97\Microsoft.JScript.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\906cd5555b79e4e0486dc8ef2a748b13\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2011-12-08 22:14 . 2011-12-08 22:14 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\7baff7d694394aaba490082c88d48fd2\Microsoft.Build.Tasks.ni.dll
+ 2011-12-08 22:13 . 2011-12-08 22:13 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\235a22e1ae9742bb724d411629dd99d5\Microsoft.Build.Engine.ni.dll
+ 2011-12-08 21:57 . 2011-12-08 21:57 3916288 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\310a9c38921c99fb8e51cba7b7ac973f\DriversHQ.DriverDetective.Client.ni.exe
- 2010-10-24 19:15 . 2010-10-24 19:15 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2010-10-24 19:15 . 2010-10-24 19:15 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-12-08 04:45 . 2011-12-08 04:45 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2010-10-24 19:14 . 2010-10-24 19:14 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-12-07 05:54 . 2011-12-07 05:54 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2010-10-24 18:51 . 2010-10-24 18:51 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2011-12-07 05:54 . 2011-12-07 05:54 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2010-10-24 18:50 . 2010-10-24 18:50 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-10-12 23:37 . 2011-10-28 05:04 50295240 c:\windows\system32\MRT.exe
+ 2009-03-08 11:39 . 2011-08-24 00:48 11081728 c:\windows\system32\ieframe.dll
+ 2009-11-30 15:16 . 2011-08-24 00:48 11081728 c:\windows\system32\dllcache\ieframe.dll
+ 2011-07-13 05:49 . 2011-07-13 05:49 11459584 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2572067\M2572067Uninstall.msp
+ 2011-03-28 10:27 . 2011-03-28 10:27 15456256 c:\windows\Installer\a42508.msp
+ 2011-12-08 04:35 . 2011-12-08 04:35 20333568 c:\windows\Installer\a424f6.msp
+ 2011-07-12 03:43 . 2011-07-12 03:43 11641344 c:\windows\Installer\532e21.msp
+ 2011-07-12 22:50 . 2011-07-12 22:50 17555968 c:\windows\Installer\532dc9.msp
+ 2009-04-04 01:21 . 2009-04-04 01:21 16037736 c:\windows\Installer\$PatchCache$\Managed\00002159FA0090400000000000F01FEC\12.0.6425\OART.DLL
+ 2011-12-07 06:03 . 2010-12-21 12:29 11080704 c:\windows\ie8updates\KB2586448-IE8\ieframe.dll
+ 2011-12-08 04:37 . 2011-12-08 04:37 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP5B6.tmp\System.Design.dll
+ 2011-12-08 18:13 . 2011-12-08 18:13 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d00cc387e462e4c3cdcd112b137cac87\System.Windows.Forms.ni.dll
+ 2011-12-08 21:58 . 2011-12-08 21:58 11800576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\40893760431f8f0dcce3e18630e45b23\System.Web.ni.dll
+ 2011-12-08 22:11 . 2011-12-08 22:11 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\e3a0205acab2215fbad7927d9d483aeb\System.ServiceModel.ni.dll
+ 2011-12-08 18:10 . 2011-12-08 18:10 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\63ad0cd9b5e038c8e2e41415657db8fc\System.Design.ni.dll
+ 2011-12-08 17:44 . 2011-12-08 17:44 14328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\704556e34128441ea9f1a81cc89f8a79\PresentationFramework.ni.dll
+ 2011-12-08 17:40 . 2011-12-08 17:40 12215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\5f332c48d03eca57419c4f0e884092ee\PresentationCore.ni.dll
+ 2011-12-08 04:46 . 2011-12-08 04:46 11490816 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\0309936a8e1672d39b9cf14463ce69f9\mscorlib.ni.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd}]
2009-11-07 08:07 297808 —-a-w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2011-12-07 04:15 1451336 —-a-w- c:\program files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E601996F-E400-41CA-804B-CD6373A7EEE2}]
2011-03-23 15:12 931696 —-a-w- c:\program files\kikin\ie_kikin.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-07-22 23:53 787744 —-a-w- c:\program files\Yontoo Layers\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll" [2011-12-07 1451336]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2011-06-08 822456]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"P17Helper"="P17.dll" [2005-05-04 64512]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-10-25 2415456]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-04-08 13891176]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2011-12-07 218464]
.
c:\documents and settings\The Crew\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
Styler.lnk - c:\documents and settings\The Crew\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2011-6-16 15086]
.
c:\documents and settings\Deano-Casino\Start Menu\Programs\Startup\AutorunsDisabled
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [N/A]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [N/A]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AutorunsDisabled]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Fliptoast.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Fliptoast.lnk
backup=c:\windows\pss\Fliptoast.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Philips GoGear VIBE Device Manager.lnk]
backup=c:\windows\pss\Philips GoGear VIBE Device Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Desktop]
2011-04-12 07:14 4613624 —-a-w- c:\program files\4shared Desktop\desktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Update]
2011-04-12 07:14 608760 —-a-w- c:\program files\4shared Desktop\checkUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvIcon]
2008-04-13 12:39 49152 —-a-w- c:\program files\Vista Drive Icon\DrvIcon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
2008-04-14 12:00 44032 —-a-w- c:\windows\ime\imkr6_1\imekrmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iMesh]
2011-06-01 19:19 21880240 —-a-w- c:\program files\iMesh Applications\iMesh\iMesh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2008-04-14 12:00 208952 —-a-w- c:\windows\ime\imjp8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
2011-10-08 21:31 366024 —-a-w- c:\program files\IncrediMail\Bin\IncMail.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-07-30 17:41 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2011-02-24 09:57 1753192 —-a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ocs_SM]
2011-09-13 04:59 106496 —-a-w- c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-02-17 17:14 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyPC]
2011-05-24 00:27 67960 —-a-w- c:\program files\Uniblue\SpeedUpMyPC\Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
2010-04-29 16:38 1652736 —-a-r- c:\program files\AWS\WeatherBug\Weather.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"RichVideo"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"Updater Service for StartNow Toolbar"=2 (0x2)
"SearchAnonymizer"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"NMIndexingService"=3 (0x3)
"LightScribeService"=2 (0x2)
"Bonjour Service"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Electronic Arts\\Dead Space\\Dead Space.exe"=
"c:\\Program Files\\Boxee\\BOXEE.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 Beta 5\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\Stanza.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 RC 1\\firefox.exe"=
"c:\\Program Files\\Fox\\Aliens vs. Predator 2\\lithtech.exe"=
"c:\\Program Files\\Lighthouse Interactive\\T34vsTiger\\TvsT.exe"=
"c:\\Program Files\\Ubisoft\\IL-2 Sturmovik Forgotten Battles\\il2.exe"=
"c:\\Program Files\\Lead Pursuit\\Battlefield Operations\\FalconAF.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\TroubleShooter.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\ToolbarUpdate.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\brink\\brink.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\ava\\REACTOR.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\spiral knights\\java_vm\\bin\\javaw.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life\\hl.exe"=
"c:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"=
"c:\\Steam\\steamapps\\common\\call of duty black ops\\BlackOpsMP.exe"=
"c:\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\iBryte\\playbryte\\ibrytedesktop.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImpCnt.exe"=
"c:\\Documents and Settings\\The Crew.DEAM\\Local Settings\\Temp\\incredimail_install.exe"=
"c:\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Bohemia Interactive\\ArmA 2\\arma2.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
"c:\\Steam\\steamapps\\azcrew\\garrysmod\\hl2.exe"=
"c:\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 3:27 PM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 3:48 AM 32592]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [11/20/2009 9:23 AM 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/12/2009 9:05 AM 206256]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [12/8/2010 4:12 AM 230608]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/15/2009 11:42 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 74480]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 6:09 AM 192776]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [4/27/2011 10:33 PM 2218600]
R2 vToolbarUpdater;vToolbarUpdater;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [12/6/2011 9:15 PM 246624]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.2;c:\windows\system32\drivers\libusb0.sys [12/11/2009 9:37 AM 28160]
R3 N3AB;N3AB Wireless Network Adapter Service;c:\windows\system32\drivers\N3AB.sys [10/7/2009 9:39 AM 457312]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 6:25 AM 4433248]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [8/3/2010 3:23 PM 134608]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [8/3/2010 3:23 PM 24272]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [8/3/2010 3:23 PM 16720]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [12/8/2009 3:29 PM 47360]
S3 SaiH075C;SaiH075C;c:\windows\system32\drivers\SaiH075C.sys [5/1/2007 4:11 PM 132232]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 7408]
S3 silabenm;RIGblaster Plug & Play Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys [2/3/2009 7:41 AM 17920]
S3 silabser;RIGblaster Plug & Play Driver;c:\windows\system32\drivers\silabser.sys [2/3/2009 7:41 AM 60544]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [10/8/2009 12:39 PM 94992]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys –> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/12/2009 9:05 AM 348824]
S4 SearchAnonymizer;SearchAnonymizer;c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizerHelper.exe [9/12/2011 9:59 PM 40960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\AutorunsDisabled\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-07-30 17:39 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-09 c:\windows\Tasks\At10.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-09 c:\windows\Tasks\At12.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-10 c:\windows\Tasks\At14.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-10 c:\windows\Tasks\At16.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At18.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-11 c:\windows\Tasks\At2.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-10 c:\windows\Tasks\At20.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At22.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-11 c:\windows\Tasks\At24.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-11 c:\windows\Tasks\At26.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-11 c:\windows\Tasks\At28.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-11 c:\windows\Tasks\At30.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-11 c:\windows\Tasks\At32.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-11 c:\windows\Tasks\At34.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At36.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At38.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-11 c:\windows\Tasks\At4.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At40.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At42.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At44.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At46.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-11 c:\windows\Tasks\At48.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-09 c:\windows\Tasks\At6.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-09 c:\windows\Tasks\At8.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2011-04-02 00:24]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-09-26 c:\windows\Tasks\Norton Security Scan for Deano-Casino.job
- c:\progra~1\NORTON~2\Engine\351~1.6\Nss.exe [2011-07-16 11:19]
.
2011-12-12 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-12 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-12 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-12 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-10-25 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC\spmonitor.exe [2011-08-18 00:27]
.
2011-12-12 c:\windows\Tasks\User_Feed_Synchronization-{D81FAA29-1225-43D0-9C2B-A4B5A9C8A97D}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bigseekpro.com/pivotstickfigure/{5D7E9955-3C04-4B2E-BE43-C161637CC061}
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files\kikin\ie_kikin.dll
TCP: DhcpNameServer = 192.168.1.1 [removed] [removed]
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\documents and settings\Deano-Casino\Application Data\Mozilla\Firefox\Profiles\5rlgdvec.default\
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bd8b798bc-6ae6-4a18-90fc-15f2bf54a416%7D&mid=27ee163b2f4cb34ac3e1da2365327ceb-06ce4fc639803a2e3563922518183d8e94088cb9&ds=AVG&v=8.0.0.40&lang=en&pr=fr&d=2011-12-06%2021%3A15%3A09&sap=ku&q=
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
ShellIconOverlayIdentifiers-{96AFBE69-C3B0-4b00-8578-D933D2896EE2} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-12 11:08
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1060284298-1659004503-1177238915-1003\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:31,e4,75,d6,9b,a1,3f,18,f1,28,20,5c,9e,f8,f2,f7,43,3a,5e,af,c0,
98,ad,90,f4,d9,c1,fd,4d,93,dc,2d,41,a7,a0,33,b3,7d,0e,42,26,9e,e5,12,e7,4a,\
"rkeysecu"=hex:b2,95,bd,3c,85,4b,48,d5,56,4b,32,96,d0,df,b0,b6
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3820)
c:\windows\system32\WININET.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\WinSCP\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\progra~1\AVG\AVG2012\avgrsx.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\AVG\AVG2012\avgnsx.exe
c:\program files\AVG\AVG2012\avgemcx.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\Rundll32.exe
.
**************************************************************************
.
Completion time: 2011-12-12 11:15:05 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-12 18:15
ComboFix2.txt 2011-12-07 03:34
ComboFix3.txt 2011-12-05 02:19
ComboFix4.txt 2011-12-02 04:51
ComboFix5.txt 2011-12-12 17:22
.
Pre-Run: 33,606,508,544 bytes free
Post-Run: 34,223,316,992 bytes free
.
- - End Of File - - 16BEBEB98EF9C26B3FAB95DC2ACA4BB8
Hi Jeff, Here is the TDSSKiller txt: 17:01:17.0531 1856 TDSS rootkit removing tool [removed] Dec 7 2011 13:21:06 17:01:17.0906 1856 ============================================================ 17:01:17.0906 1856 Current date / time: 2011/12/12 17:01:17.0906 17:01:17.0906 1856 SystemInfo: 17:01:17.0906 1856 17:01:17.0906 1856 OS Version: 5.1.2600 ServicePack: 3.0 17:01:17.0906 1856 Product type: Workstation 17:01:17.0906 1856 ComputerName: DEAM 17:01:17.0906 1856 UserName: Deano-Casino 17:01:17.0906 1856 Windows directory: C:\WINDOWS 17:01:17.0906 1856 System windows directory: C:\WINDOWS 17:01:17.0906 1856 Processor architecture: Intel x86 17:01:17.0906 1856 Number of processors: 2 17:01:17.0906 1856 Page size: 0x1000 17:01:17.0906 1856 Boot type: Normal boot 17:01:17.0906 1856 ============================================================ 17:01:19.0625 1856 Initialize success 17:01:46.0984 2372 ============================================================ 17:01:46.0984 2372 Scan started 17:01:46.0984 2372 Mode: Manual; 17:01:46.0984 2372 ============================================================ 17:01:49.0828 2372 Abiosdsk - ok 17:01:50.0015 2372 abp480n5 - ok 17:01:50.0328 2372 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 17:01:50.0593 2372 ACPI - ok 17:01:50.0953 2372 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 17:01:51.0125 2372 ACPIEC - ok 17:01:51.0484 2372 adpu160m - ok 17:01:51.0703 2372 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 17:01:51.0937 2372 aec - ok 17:01:52.0203 2372 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 17:01:52.0218 2372 AFD - ok 17:01:52.0390 2372 Aha154x - ok 17:01:52.0500 2372 aic78u2 - ok 17:01:52.0625 2372 aic78xx - ok 17:01:52.0828 2372 AliIde - ok 17:01:53.0031 2372 amsint - ok 17:01:53.0250 2372 asc - ok 17:01:53.0406 2372 asc3350p - ok 17:01:53.0593 2372 asc3550 - ok 17:01:53.0734 2372 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 17:01:54.0046 2372 AsyncMac - ok 17:01:54.0296 2372 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 17:01:54.0296 2372 atapi - ok 17:01:54.0468 2372 Atdisk - ok 17:01:54.0640 2372 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 17:01:54.0890 2372 Atmarpc - ok 17:01:55.0671 2372 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 17:01:55.0750 2372 audstub - ok 17:01:56.0109 2372 AVGIDSDriver (4fa401b33c1b50c816486f6951244a14) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys 17:01:56.0250 2372 AVGIDSDriver - ok 17:01:56.0296 2372 AVGIDSEH (69578bc9d43d614c6b3455db4af19762) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys 17:01:56.0453 2372 AVGIDSEH - ok 17:01:56.0921 2372 AVGIDSFilter (6df528406aa22201f392b9b19121cd6f) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys 17:01:56.0937 2372 AVGIDSFilter - ok 17:01:57.0218 2372 AVGIDSShim (1e01c2166b5599802bcd61b9691f7476) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys 17:01:57.0218 2372 AVGIDSShim - ok 17:01:57.0546 2372 Avgldx86 (bf8118cd5e2255387b715b534d64acd1) C:\WINDOWS\system32\DRIVERS\avgldx86.sys 17:01:57.0562 2372 Avgldx86 - ok 17:01:57.0953 2372 Avgmfx86 (1c77ef67f196466adc9924cb288afe87) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 17:01:57.0968 2372 Avgmfx86 - ok 17:01:58.0218 2372 Avgrkx86 (f2038ed7284b79dcef581468121192a9) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys 17:01:58.0250 2372 Avgrkx86 - ok 17:01:58.0937 2372 BANTExt (5d7be7b19e827125e016325334e58ff1) C:\WINDOWS\System32\Drivers\BANTExt.sys 17:01:59.0703 2372 BANTExt - ok 17:02:00.0609 2372 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 17:02:01.0062 2372 Beep - ok 17:02:01.0859 2372 Bridge (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys 17:02:02.0375 2372 Bridge - ok 17:02:02.0437 2372 BridgeMP (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys 17:02:02.0453 2372 BridgeMP - ok 17:02:02.0515 2372 catchme - ok 17:02:03.0640 2372 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 17:02:03.0843 2372 cbidf2k - ok 17:02:04.0515 2372 cd20xrnt - ok 17:02:04.0812 2372 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 17:02:05.0125 2372 Cdaudio - ok 17:02:05.0406 2372 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 17:02:05.0484 2372 Cdfs - ok 17:02:05.0953 2372 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 17:02:06.0062 2372 Cdrom - ok 17:02:06.0531 2372 Changer - ok 17:02:06.0640 2372 CmdIde - ok 17:02:06.0859 2372 Cpqarray - ok 17:02:06.0968 2372 cpuz132 - ok 17:02:07.0343 2372 ctsfm2k (8db84de3aab34a8b4c2f644eff41cd76) C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys 17:02:07.0531 2372 ctsfm2k - ok 17:02:07.0781 2372 dac2w2k - ok 17:02:08.0265 2372 dac960nt - ok 17:02:08.0859 2372 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 17:02:08.0921 2372 Disk - ok 17:02:09.0625 2372 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 17:02:09.0921 2372 dmboot - ok 17:02:10.0953 2372 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\DRIVERS\dmio.sys 17:02:11.0187 2372 dmio - ok 17:02:11.0984 2372 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 17:02:12.0359 2372 dmload - ok 17:02:13.0093 2372 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 17:02:13.0234 2372 DMusic - ok 17:02:14.0000 2372 dpti2o - ok 17:02:14.0140 2372 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 17:02:14.0203 2372 drmkaud - ok 17:02:14.0468 2372 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 17:02:14.0843 2372 Fastfat - ok 17:02:15.0281 2372 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 17:02:15.0312 2372 Fdc - ok 17:02:15.0718 2372 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 17:02:15.0843 2372 Fips - ok 17:02:16.0234 2372 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 17:02:16.0312 2372 Flpydisk - ok 17:02:16.0734 2372 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 17:02:16.0828 2372 FltMgr - ok 17:02:16.0984 2372 fssfltr (c6ee3a87fe609d3e1db9dbd072a248de) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys 17:02:17.0031 2372 fssfltr - ok 17:02:17.0218 2372 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 17:02:17.0296 2372 Fs_Rec - ok 17:02:17.0640 2372 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 17:02:17.0796 2372 Ftdisk - ok 17:02:18.0125 2372 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 17:02:18.0140 2372 GEARAspiWDM - ok 17:02:18.0828 2372 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 17:02:18.0890 2372 Gpc - ok 17:02:19.0312 2372 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 17:02:19.0406 2372 HDAudBus - ok 17:02:20.0062 2372 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 17:02:20.0234 2372 hidusb - ok 17:02:20.0656 2372 hpn - ok 17:02:20.0828 2372 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys 17:02:20.0953 2372 HPZid412 - ok 17:02:21.0406 2372 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 17:02:21.0515 2372 HPZipr12 - ok 17:02:21.0906 2372 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys 17:02:22.0046 2372 HPZius12 - ok 17:02:22.0625 2372 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 17:02:22.0765 2372 HTTP - ok 17:02:23.0250 2372 i2omgmt - ok 17:02:23.0296 2372 i2omp - ok 17:02:23.0453 2372 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 17:02:23.0468 2372 i8042prt - ok 17:02:23.0656 2372 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 17:02:23.0812 2372 Imapi - ok 17:02:24.0296 2372 ini910u - ok 17:02:24.0640 2372 IntelIde - ok 17:02:24.0812 2372 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 17:02:24.0859 2372 intelppm - ok 17:02:25.0125 2372 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 17:02:25.0171 2372 Ip6Fw - ok 17:02:25.0765 2372 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 17:02:25.0843 2372 IpFilterDriver - ok 17:02:26.0046 2372 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 17:02:26.0171 2372 IpInIp - ok 17:02:26.0671 2372 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 17:02:26.0796 2372 IpNat - ok 17:02:27.0156 2372 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 17:02:27.0328 2372 IPSec - ok 17:02:27.0921 2372 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 17:02:27.0984 2372 IRENUM - ok 17:02:28.0343 2372 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 17:02:28.0468 2372 isapnp - ok 17:02:28.0921 2372 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 17:02:28.0968 2372 Kbdclass - ok 17:02:29.0375 2372 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 17:02:29.0437 2372 kbdhid - ok 17:02:29.0593 2372 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 17:02:29.0609 2372 kmixer - ok 17:02:29.0828 2372 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 17:02:29.0859 2372 KSecDD - ok 17:02:30.0218 2372 lbrtfdc - ok 17:02:30.0390 2372 libusb0 (03e12dbfacf1aeb86c553b0db488fb81) C:\WINDOWS\system32\drivers\libusb0.sys 17:02:30.0687 2372 libusb0 - ok 17:02:31.0187 2372 MBAMSwissArmy - ok 17:02:31.0265 2372 MCSTRM - ok 17:02:31.0593 2372 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 17:02:31.0703 2372 mnmdd - ok 17:02:31.0859 2372 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 17:02:32.0031 2372 Modem - ok 17:02:32.0281 2372 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 17:02:32.0328 2372 Mouclass - ok 17:02:32.0406 2372 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 17:02:32.0453 2372 mouhid - ok 17:02:32.0546 2372 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 17:02:32.0546 2372 MountMgr - ok 17:02:32.0593 2372 mraid35x - ok 17:02:32.0640 2372 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 17:02:32.0640 2372 MRxDAV - ok 17:02:32.0703 2372 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 17:02:32.0718 2372 MRxSmb - ok 17:02:33.0140 2372 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 17:02:33.0250 2372 Msfs - ok 17:02:34.0046 2372 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 17:02:34.0125 2372 MSKSSRV - ok 17:02:34.0578 2372 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 17:02:34.0640 2372 MSPCLOCK - ok 17:02:34.0703 2372 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 17:02:34.0765 2372 MSPQM - ok 17:02:34.0828 2372 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 17:02:34.0828 2372 mssmbios - ok 17:02:34.0890 2372 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 17:02:34.0890 2372 Mup - ok 17:02:34.0968 2372 N3AB (0bb59b42cf3431d55a0bfbb5d7f77ee5) C:\WINDOWS\system32\DRIVERS\N3AB.sys 17:02:35.0093 2372 N3AB - ok 17:02:35.0359 2372 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 17:02:35.0531 2372 NDIS - ok 17:02:35.0593 2372 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 17:02:35.0593 2372 NdisTapi - ok 17:02:35.0671 2372 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 17:02:35.0687 2372 Ndisuio - ok 17:02:35.0781 2372 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 17:02:35.0812 2372 NdisWan - ok 17:02:35.0984 2372 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 17:02:35.0984 2372 NDProxy - ok 17:02:36.0046 2372 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 17:02:36.0078 2372 NetBIOS - ok 17:02:36.0171 2372 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 17:02:36.0187 2372 NetBT - ok 17:02:36.0328 2372 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 17:02:36.0359 2372 Npfs - ok 17:02:36.0453 2372 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 17:02:36.0468 2372 Ntfs - ok 17:02:36.0531 2372 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 17:02:36.0531 2372 Null - ok 17:02:36.0984 2372 nv (f1de35c89d98a883d1b4030dc9896855) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 17:02:37.0421 2372 nv - ok 17:02:37.0500 2372 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 17:02:37.0500 2372 NwlnkFlt - ok 17:02:37.0546 2372 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 17:02:37.0562 2372 NwlnkFwd - ok 17:02:37.0640 2372 ossrv (103a9b117a7d9903111955cdafe65ac6) C:\WINDOWS\system32\DRIVERS\ctoss2k.sys 17:02:37.0687 2372 ossrv - ok 17:02:37.0796 2372 P17 (df886ffed69aead0cf608b89b18c3f6f) C:\WINDOWS\system32\drivers\P17.sys 17:02:37.0875 2372 P17 - ok 17:02:37.0921 2372 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 17:02:37.0937 2372 Parport - ok 17:02:38.0031 2372 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 17:02:38.0046 2372 PartMgr - ok 17:02:38.0125 2372 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 17:02:38.0125 2372 ParVdm - ok 17:02:38.0171 2372 pavboot (3adb8bd6154a3ef87496e8fce9c22493) C:\WINDOWS\system32\drivers\pavboot.sys 17:02:38.0171 2372 pavboot - ok 17:02:38.0265 2372 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 17:02:38.0296 2372 PCI - ok 17:02:38.0359 2372 PCIDump - ok 17:02:38.0390 2372 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 17:02:38.0390 2372 PCIIde - ok 17:02:38.0453 2372 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 17:02:38.0500 2372 Pcmcia - ok 17:02:38.0593 2372 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys 17:02:38.0750 2372 pcouffin - ok 17:02:38.0921 2372 PCTCore (d302a59e6d1842a201930928a5bad68b) C:\WINDOWS\system32\drivers\PCTCore.sys 17:02:38.0937 2372 PCTCore - ok 17:02:38.0953 2372 PDCOMP - ok 17:02:38.0968 2372 PDFRAME - ok 17:02:39.0000 2372 PDRELI - ok 17:02:39.0015 2372 PDRFRAME - ok 17:02:39.0031 2372 perc2 - ok 17:02:39.0046 2372 perc2hib - ok 17:02:39.0140 2372 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 17:02:39.0171 2372 PptpMiniport - ok 17:02:39.0203 2372 prodrv06 (18d9789a4664bf417eea944d2776091a) C:\WINDOWS\System32\drivers\prodrv06.sys 17:02:39.0406 2372 prodrv06 - ok 17:02:39.0609 2372 prohlp02 (8cc9671a7ed2902e747ee0892e1c8575) C:\WINDOWS\system32\drivers\prohlp02.sys 17:02:39.0843 2372 prohlp02 - ok 17:02:39.0968 2372 prosync1 (960bce3ed38761b446aabac06c76badf) C:\WINDOWS\system32\drivers\prosync1.sys 17:02:40.0109 2372 prosync1 - ok 17:02:40.0250 2372 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 17:02:40.0296 2372 PSched - ok 17:02:40.0312 2372 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 17:02:40.0375 2372 Ptilink - ok 17:02:40.0421 2372 ql1080 - ok 17:02:40.0437 2372 Ql10wnt - ok 17:02:40.0453 2372 ql12160 - ok 17:02:40.0500 2372 ql1240 - ok 17:02:40.0515 2372 ql1280 - ok 17:02:40.0578 2372 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 17:02:40.0593 2372 RasAcd - ok 17:02:40.0671 2372 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 17:02:40.0703 2372 Rasl2tp - ok 17:02:40.0765 2372 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 17:02:40.0812 2372 RasPppoe - ok 17:02:40.0875 2372 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 17:02:40.0906 2372 Raspti - ok 17:02:41.0000 2372 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 17:02:41.0046 2372 Rdbss - ok 17:02:41.0125 2372 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 17:02:41.0125 2372 RDPCDD - ok 17:02:41.0187 2372 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 17:02:41.0250 2372 rdpdr - ok 17:02:41.0343 2372 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 17:02:41.0359 2372 RDPWD - ok 17:02:41.0406 2372 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 17:02:41.0437 2372 redbook - ok 17:02:41.0578 2372 rt2870 (b10c0cea067240b6741cc7862f63d2fd) C:\WINDOWS\system32\DRIVERS\rt2870.sys 17:02:41.0640 2372 rt2870 - ok 17:02:41.0703 2372 RTL8023xp (cf84b1f0e8b14d4120aaf9cf35cbb265) C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys 17:02:41.0765 2372 RTL8023xp - ok 17:02:41.0828 2372 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 17:02:41.0843 2372 rtl8139 - ok 17:02:41.0921 2372 SaiH075C (de7a2fc379671998865122a08fd9db52) C:\WINDOWS\system32\DRIVERS\SaiH075C.sys 17:02:41.0953 2372 SaiH075C - ok 17:02:42.0015 2372 SASDIFSV (5bf35c4ea3f00fa8d3f1e5bf03d24584) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 17:02:42.0109 2372 SASDIFSV - ok 17:02:42.0140 2372 SASENUM (a22f08c98ac2f44587bf3a1fb52bf8cd) C:\Program Files\SUPERAntiSpyware\SASENUM.SYS 17:02:42.0328 2372 SASENUM - ok 17:02:42.0531 2372 SASKUTIL (c7d81c10d3befeee41f3408714637438) C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys 17:02:42.0625 2372 SASKUTIL - ok 17:02:42.0812 2372 Secdrv (07f7f501ad50de2ba2d5842d9b6d6155) C:\WINDOWS\system32\DRIVERS\secdrv.sys 17:02:42.0968 2372 Secdrv - ok 17:02:43.0140 2372 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 17:02:43.0171 2372 serenum - ok 17:02:43.0203 2372 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 17:02:43.0218 2372 Serial - ok 17:02:43.0265 2372 sfhlp01 (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys 17:02:43.0375 2372 sfhlp01 - ok 17:02:43.0515 2372 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 17:02:43.0531 2372 Sfloppy - ok 17:02:43.0609 2372 silabenm (c16173316918a1360dc22947c4ff6352) C:\WINDOWS\system32\DRIVERS\silabenm.sys 17:02:43.0671 2372 silabenm - ok 17:02:43.0703 2372 silabser (093c31ec727ecbcbe38992fc69657594) C:\WINDOWS\system32\DRIVERS\silabser.sys 17:02:43.0734 2372 silabser - ok 17:02:43.0750 2372 Simbad - ok 17:02:43.0781 2372 Sparrow - ok 17:02:43.0828 2372 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 17:02:43.0843 2372 splitter - ok 17:02:43.0921 2372 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 17:02:43.0953 2372 sr - ok 17:02:44.0015 2372 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 17:02:44.0031 2372 Srv - ok 17:02:44.0078 2372 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 17:02:44.0093 2372 swenum - ok 17:02:44.0156 2372 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 17:02:44.0171 2372 swmidi - ok 17:02:44.0218 2372 symc810 - ok 17:02:44.0328 2372 symc8xx - ok 17:02:44.0343 2372 sym_hi - ok 17:02:44.0375 2372 sym_u3 - ok 17:02:44.0406 2372 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 17:02:44.0406 2372 sysaudio - ok 17:02:44.0500 2372 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 17:02:44.0515 2372 Tcpip - ok 17:02:44.0562 2372 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 17:02:44.0578 2372 TDPIPE - ok 17:02:44.0656 2372 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 17:02:44.0656 2372 TDTCP - ok 17:02:44.0687 2372 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 17:02:44.0734 2372 TermDD - ok 17:02:44.0828 2372 TosIde - ok 17:02:44.0875 2372 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 17:02:44.0906 2372 Udfs - ok 17:02:44.0953 2372 ultra - ok 17:02:45.0000 2372 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 17:02:45.0031 2372 Update - ok 17:02:45.0062 2372 USBAAPL - ok 17:02:45.0093 2372 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 17:02:45.0109 2372 usbaudio - ok 17:02:45.0187 2372 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 17:02:45.0203 2372 usbccgp - ok 17:02:45.0265 2372 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 17:02:45.0296 2372 usbehci - ok 17:02:45.0328 2372 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 17:02:45.0343 2372 usbhub - ok 17:02:45.0406 2372 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 17:02:45.0406 2372 usbohci - ok 17:02:45.0468 2372 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 17:02:45.0500 2372 usbprint - ok 17:02:45.0546 2372 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 17:02:45.0578 2372 usbscan - ok 17:02:45.0656 2372 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 17:02:45.0687 2372 USBSTOR - ok 17:02:45.0781 2372 VBoxNetAdp (4529f598bf8c8dbeda96be6ae5991c4a) C:\WINDOWS\system32\DRIVERS\VBoxNetAdp.sys 17:02:45.0796 2372 VBoxNetAdp - ok 17:02:45.0875 2372 VBoxNetFlt - ok 17:02:45.0906 2372 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 17:02:45.0937 2372 VgaSave - ok 17:02:46.0015 2372 ViaIde - ok 17:02:46.0031 2372 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 17:02:46.0046 2372 VolSnap - ok 17:02:46.0125 2372 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 17:02:46.0156 2372 Wanarp - ok 17:02:46.0375 2372 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys 17:02:46.0609 2372 Wdf01000 - ok 17:02:46.0687 2372 WDICA - ok 17:02:46.0734 2372 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 17:02:46.0765 2372 wdmaud - ok 17:02:46.0843 2372 WmBEnum (84a90f13eebf4380345ef9474d30f10e) C:\WINDOWS\system32\drivers\WmBEnum.sys 17:02:46.0859 2372 WmBEnum - ok 17:02:46.0906 2372 WmFilter (eb0034ac02a44dc784a3174d2b81e764) C:\WINDOWS\system32\drivers\WmFilter.sys 17:02:46.0921 2372 WmFilter - ok 17:02:46.0968 2372 WmHidLo (31d2906d59f127654964be334b615720) C:\WINDOWS\system32\drivers\WmHidLo.sys 17:02:46.0984 2372 WmHidLo - ok 17:02:47.0078 2372 WmVirHid (72c4f5a748c74d8d4016ccfa7367210f) C:\WINDOWS\system32\drivers\WmVirHid.sys 17:02:47.0078 2372 WmVirHid - ok 17:02:47.0093 2372 WmXlCore (eacdcced934a185e61ce0684f71c2dec) C:\WINDOWS\system32\drivers\WmXlCore.sys 17:02:47.0109 2372 WmXlCore - ok 17:02:47.0171 2372 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\Drivers\wpdusb.sys 17:02:47.0250 2372 WpdUsb - ok 17:02:47.0359 2372 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 17:02:47.0390 2372 WS2IFSL - ok 17:02:47.0500 2372 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 17:02:47.0546 2372 WudfPf - ok 17:02:47.0656 2372 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 17:02:47.0718 2372 WudfRd - ok 17:02:47.0812 2372 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 17:02:47.0937 2372 \Device\Harddisk0\DR0 - ok 17:02:47.0953 2372 Boot (0x1200) (f926653c38f5e7cf6a08e058c59b7ae9) \Device\Harddisk0\DR0\Partition0 17:02:47.0953 2372 \Device\Harddisk0\DR0\Partition0 - ok 17:02:47.0953 2372 ============================================================ 17:02:47.0953 2372 Scan finished 17:02:47.0953 2372 ============================================================ 17:02:47.0984 5272 Detected object count: 0 17:02:47.0984 5272 Actual detected object count: 0 17:03:49.0187 2304 Deinitialize success
Hi Wicked Kitt_E,

Thanks for that TDSSKiller log. :)
————

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    AtJob::
    
    DirLook::
    c:\documents and settings\All Users\Application Data\3B35B
    c:\documents and settings\All Users\Application Data\F3A9
    
    File::
    c:\windows\system32\G4E7R0u.com_
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "Updater Service for StartNow Toolbar"=-
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI