This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ping.exe and high CPU usage

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, From the past few days, i came across a problem where CPU usage goes very high sometimes 100% due to a ping.exe process. If i will kill this process in task manager then within few minutes it starts automatically and again its affects the CPU usage and computer speed. I have run the DDS tool and this is the content of the DDS.txt file that it produced . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 23:00:02.17 on Mon 12/19/2011 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.523 [GMT -8:00] . AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\Program Files\Intel\WiFi\bin\S24EvMon.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\svchost.exe -k NecUsbSevice C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe svchost.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\mqsvc.exe C:\WINDOWS\system32\mqtgsvc.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe C:\WINDOWS\eHome\ehmsas.exe C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Internet Download Manager\IDMan.exe C:\WINDOWS\system32\wbem\unsecapp.exe C:\Program Files\CleanMyPC\Registry Cleaner\RCHelper.exe C:\Program Files\Internet Download Manager\IEMonitor.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE C:\Program Files\AIM\aim.exe C:\WINDOWS\system32\taskmgr.exe C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\WINDOWS\System32\ping.exe C:\Documents and Settings\Pankaj\Desktop\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.Google.com uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Page_URL = hxxp://www.Google.com mDefault_Search_URL = hxxp://www.Google.com/ mSearch Page = hxxp://www.Google.com/ mStart Page = hxxp://www.Google.com uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uURLSearchHooks: AOL Messaging Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\prxtbuTor.dll mURLSearchHooks: AOL Messaging Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll mWinlogon: Shell=Explorer.exe chrome.exe, c:\documents and settings\all users\application data\ka01300abccd01300\kA01300AbCcD01300.exe mWinlogon: UIHost=%SystemRoot%\system32\logonui.exe BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - avast! WebRep BHO: Catcher Class: {adecbed6-0366-4377-a739-e69dfba04663} - c:\program files\moyea\flv downloader\MoyeaCth.dll BHO: AOL Messaging Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\prxtbuTor.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\prxtbuTor.dll TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - TB: AOL Messaging Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot uRun: [Registry Cleaner Scheduler] "c:\program files\cleanmypc\registry cleaner\RCHelper.exe" /startup mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe mRun: [MsmqIntCert] regsvr32 /s mqrt.dll mRun: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [IntelZeroConfig] "c:\program files\intel\wifi\bin\ZCfgSvc.exe" mRun: [IntelWireless] "c:\program files\common files\intel\wirelesscommon\iFrmewrk.exe" /tf Intel Wireless Tray mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [vptray] c:\progra~1\symant~1\VPTray.exe dRunOnce: [RunNarrator] Narrator.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hppavi~1.lnk - c:\program files\hewlett-packard\hp pavilion webcam\HPWebcam.exe IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm IE: Download with IDM - c:\program files\internet download manager\IEExt.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000 IE: Send To &Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL LSP: mswsock.dll DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} - hxxp://sifyimg.speedera.net/sify.com/eot/tdserver.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1238516119640 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://aolsvc.aol.com/onlinegames/bejeweled2/popcaploader_v10.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: NavLogon - c:\windows\system32\NavLogon.dll Notify: NecUsb3Sevice - USB3Nw32.dll Notify: USB3Nw32 - USB3Nw32.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\pankaj\applic~1\mozilla\firefox\profiles\lctr927l.default\ FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com/?src=aim&ncid=snsusaimc00000001 FF - component: c:\documents and settings\pankaj\application data\mozilla\firefox\profiles\lctr927l.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko19.dll FF - component: c:\documents and settings\pankaj\application data\mozilla\firefox\profiles\lctr927l.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko5.dll FF - component: c:\documents and settings\pankaj\application data\mozilla\firefox\profiles\lctr927l.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko6.dll FF - component: c:\documents and settings\pankaj\application data\mozilla\firefox\profiles\lctr927l.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko7.dll FF - component: c:\documents and settings\pankaj\application data\mozilla\firefox\profiles\lctr927l.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko8.dll FF - plugin: c:\documents and settings\pankaj\application data\mozilla\plugins\npgoogletalk.dll FF - plugin: c:\documents and settings\pankaj\application data\mozilla\plugins\npgtpo3dautoplugin.dll FF - plugin: c:\documents and settings\pankaj\local settings\application data\facebook\video\skype\npFacebookVideoCalling.dll FF - plugin: c:\documents and settings\pankaj\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.141.5\npGoogleOneClick7.dll FF - plugin: c:\program files\google\update\1.2.145.5\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Ext: SearchPreview: {EF522540-89F5-46b9-B6FE-1829E2B572C6} - %profile%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6} FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} . —- FIREFOX POLICIES —- FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false ============= SERVICES / DRIVERS =============== . R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2009-6-14 339328] R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2009-6-14 55168] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-12-8 106104] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20111216.002\naveng.sys [2011-12-16 86136] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20111216.002\navex15.sys [2011-12-16 1576312] R3 NETwLx32; Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [2011-11-27 6609920] S1 vdrv7000;vdrv7000;c:\windows\system32\drivers\vdrv7000.sys –> c:\windows\system32\drivers\vdrv7000.sys [?] S3 PROCEXP150;PROCEXP150;\??\c:\windows\system32\drivers\procexp150.sys –> c:\windows\system32\drivers\PROCEXP150.SYS [?] S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\drivers\s115bus.sys [2009-3-22 83208] S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\drivers\s115mdfl.sys [2009-3-22 15112] S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\drivers\s115mdm.sys [2009-3-22 108680] S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s115mgmt.sys [2009-3-22 100488] S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\drivers\s115obex.sys [2009-3-22 98568] S4 Apache2.2;Apache2.2;c:\program files\apache software foundation\apache2.2\bin\httpd.exe [2009-9-28 24645] . =============== Created Last 30 ================ . 2071-07-25 03:43:30 203576 -c—-w- c:\program files\microsoft games\age of empires iii\autopatcher2.exe 2011-12-20 06:14:57 ——– d—–w- C:\TDSSKiller_Quarantine 2011-12-18 20:35:29 ——– d—–w- C:\ubuntu(2) 2011-12-18 18:23:00 ——– d—–w- c:\docume~1\alluse~1\applic~1\Intel(2) 2011-12-18 06:46:42 ——– d—–w- c:\program files\CleanMyPC 2011-12-18 06:35:35 ——– d—–w- c:\program files\Wise PC Doctor 2011-12-09 05:03:51 ——– d—–w- c:\docume~1\pankaj\locals~1\applic~1\Symantec 2011-12-09 05:02:27 60800 —-a-w- c:\windows\system32\S32EVNT1.DLL 2011-12-09 05:02:26 123952 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2011-12-09 05:00:07 ——– d—–w- c:\program files\Symantec AntiVirus 2011-11-29 20:59:52 ——– d—–w- c:\program files\AIM Toolbar 2011-11-29 20:59:37 ——– d—–w- c:\program files\common files\Software Update Utility 2011-11-29 20:58:51 ——– d—–w- c:\program files\AIM 2011-11-28 03:57:49 ——– d—–w- c:\program files\Broadcom 2011-11-28 03:27:38 ——– d—–w- c:\docume~1\pankaj\applic~1\Intel 2011-11-28 03:27:01 675840 —-a-w- c:\windows\system32\NETwLc32.dll 2011-11-28 03:27:01 6609920 —-a-w- c:\windows\system32\drivers\NETwLx32.sys 2011-11-28 03:27:01 2756608 —-a-w- c:\windows\system32\NETwLr32.dll 2011-11-28 03:26:27 ——– d—–w- c:\program files\common files\Intel 2011-11-25 06:02:40 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-25 05:32:02 ——– d—–w- c:\program files\Conduit 2011-11-25 05:32:00 ——– d—–w- c:\docume~1\pankaj\locals~1\applic~1\uTorrentBar 2011-11-25 05:31:59 ——– d—–w- c:\docume~1\pankaj\locals~1\applic~1\Conduit 2011-11-25 05:31:56 ——– d—–w- c:\program files\uTorrentBar 2011-11-25 05:31:46 ——– d—–w- c:\program files\uTorrent 2011-11-25 05:31:02 ——– d—–w- c:\docume~1\pankaj\locals~1\applic~1\uTorrent 2011-11-25 05:31:02 ——– d—–w- c:\docume~1\pankaj\applic~1\uTorrent 2011-11-23 09:11:42 ——– d—–w- c:\program files\Tweet Adder 3 2011-11-23 09:05:00 ——– d—–w- c:\docume~1\pankaj\applic~1\TweetAdder3 2011-11-23 07:26:50 ——– d—–w- c:\docume~1\pankaj\applic~1\A47B1 2011-11-23 07:26:43 ——– d—–w- c:\program files\LP 2011-11-22 21:48:04 ——– d—–w- C:\wamp . ==================== Find3M ==================== . 2011-09-26 06:11:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll 2011-09-26 06:11:20 220160 —-a-w- c:\windows\system32\oleacc.dll 2011-09-26 06:11:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll . ============= FINISH: 23:01:51.00 =============== It also produced a file called "Attach" and the instructions said to zipped the file and attach with the post. so I've attached that file. Any help that you can give me with my problem will be appreciated. Regards, Meghna

Attachments:

Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)










Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
TDDSKiller log file:


21:12:41.0640 4484 TDSS rootkit removing tool [removed] Dec 13 2011 10:39:31
21:12:42.0203 4484 ============================================================
21:12:42.0203 4484 Current date / time: 2011/12/20 21:12:42.0203
21:12:42.0203 4484 SystemInfo:
21:12:42.0203 4484
21:12:42.0203 4484 OS Version: 5.1.2600 ServicePack: 3.0
21:12:42.0203 4484 Product type: Workstation
21:12:42.0203 4484 ComputerName: PC187869777259
21:12:42.0203 4484 UserName: Pankaj
21:12:42.0203 4484 Windows directory: C:\WINDOWS
21:12:42.0203 4484 System windows directory: C:\WINDOWS
21:12:42.0203 4484 Processor architecture: Intel x86
21:12:42.0203 4484 Number of processors: 2
21:12:42.0203 4484 Page size: 0x1000
21:12:42.0203 4484 Boot type: Normal boot
21:12:42.0203 4484 ============================================================
21:12:43.0078 4484 Initialize success
21:12:45.0140 5588 ============================================================
21:12:45.0140 5588 Scan started
21:12:45.0140 5588 Mode: Manual;
21:12:45.0140 5588 ============================================================
21:12:47.0515 5588 .afd - ok
21:12:47.0671 5588 Abiosdsk - ok
21:12:47.0765 5588 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
21:12:47.0781 5588 abp480n5 - ok
21:12:47.0875 5588 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
21:12:47.0875 5588 ACPI - ok
21:12:47.0921 5588 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
21:12:47.0921 5588 ACPIEC - ok
21:12:47.0968 5588 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
21:12:48.0015 5588 adpu160m - ok
21:12:48.0187 5588 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
21:12:48.0187 5588 aec - ok
21:12:48.0343 5588 Afd (f6b7b1ecd7b41736bdb6ff4b092bcb79) C:\WINDOWS\System32\drivers\afd.sys
21:12:48.0343 5588 Afd - ok
21:12:48.0453 5588 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
21:12:48.0468 5588 agp440 - ok
21:12:48.0531 5588 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
21:12:48.0562 5588 agpCPQ - ok
21:12:48.0625 5588 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
21:12:48.0656 5588 Aha154x - ok
21:12:48.0812 5588 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
21:12:48.0843 5588 aic78u2 - ok
21:12:48.0953 5588 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
21:12:48.0968 5588 aic78xx - ok
21:12:49.0078 5588 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
21:12:49.0078 5588 AliIde - ok
21:12:49.0156 5588 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
21:12:49.0171 5588 alim1541 - ok
21:12:49.0250 5588 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
21:12:49.0265 5588 amdagp - ok
21:12:49.0421 5588 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
21:12:49.0437 5588 amsint - ok
21:12:49.0546 5588 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
21:12:49.0578 5588 Arp1394 - ok
21:12:49.0656 5588 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
21:12:49.0671 5588 asc - ok
21:12:49.0750 5588 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
21:12:49.0796 5588 asc3350p - ok
21:12:49.0890 5588 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
21:12:49.0937 5588 asc3550 - ok
21:12:50.0078 5588 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
21:12:50.0093 5588 AsyncMac - ok
21:12:50.0203 5588 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
21:12:50.0203 5588 atapi - ok
21:12:50.0234 5588 Atdisk - ok
21:12:50.0281 5588 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
21:12:50.0312 5588 Atmarpc - ok
21:12:50.0390 5588 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
21:12:50.0406 5588 audstub - ok
21:12:50.0500 5588 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
21:12:50.0500 5588 Beep - ok
21:12:50.0609 5588 btaudio (3bc0afbd546162fe6ed6ccb15befad73) C:\WINDOWS\system32\drivers\btaudio.sys
21:12:50.0656 5588 btaudio - ok
21:12:50.0765 5588 BTDriver (1d25fb8b6b073e6f4fb51034f734ea2c) C:\WINDOWS\system32\DRIVERS\btport.sys
21:12:50.0812 5588 BTDriver - ok
21:12:51.0000 5588 BTKRNL (9515d10ceaf284ab1a21934e1958d4fd) C:\WINDOWS\system32\DRIVERS\btkrnl.sys
21:12:51.0156 5588 BTKRNL - ok
21:12:51.0359 5588 BTWDNDIS (66bff2643e5f6a0f80208dde1c4b653a) C:\WINDOWS\system32\DRIVERS\btwdndis.sys
21:12:51.0453 5588 BTWDNDIS - ok
21:12:51.0562 5588 btwmodem (49d358c0f2eebdd545270f6935b63ad9) C:\WINDOWS\system32\DRIVERS\btwmodem.sys
21:12:51.0656 5588 btwmodem - ok
21:12:51.0812 5588 BTWUSB (4272bab9291d26da5ac913bc79c3ce85) C:\WINDOWS\system32\Drivers\btwusb.sys
21:12:51.0812 5588 BTWUSB - ok
21:12:51.0921 5588 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
21:12:51.0968 5588 cbidf - ok
21:12:52.0000 5588 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
21:12:52.0000 5588 cbidf2k - ok
21:12:52.0062 5588 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
21:12:52.0078 5588 CCDECODE - ok
21:12:52.0187 5588 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
21:12:52.0234 5588 cd20xrnt - ok
21:12:52.0359 5588 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
21:12:52.0359 5588 Cdaudio - ok
21:12:52.0453 5588 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
21:12:52.0453 5588 Cdfs - ok
21:12:52.0468 5588 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
21:12:52.0593 5588 Cdrom - ok
21:12:52.0781 5588 Changer - ok
21:12:52.0875 5588 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
21:12:52.0890 5588 CmBatt - ok
21:12:52.0984 5588 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
21:12:53.0015 5588 CmdIde - ok
21:12:53.0078 5588 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
21:12:53.0093 5588 Compbatt - ok
21:12:53.0140 5588 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
21:12:53.0156 5588 Cpqarray - ok
21:12:53.0187 5588 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
21:12:53.0218 5588 dac2w2k - ok
21:12:53.0250 5588 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
21:12:53.0281 5588 dac960nt - ok
21:12:53.0453 5588 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
21:12:53.0453 5588 Disk - ok
21:12:53.0546 5588 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
21:12:53.0593 5588 dmboot - ok
21:12:53.0656 5588 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
21:12:53.0671 5588 dmio - ok
21:12:53.0703 5588 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
21:12:53.0703 5588 dmload - ok
21:12:53.0781 5588 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
21:12:53.0781 5588 DMusic - ok
21:12:53.0859 5588 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
21:12:53.0890 5588 dpti2o - ok
21:12:53.0953 5588 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
21:12:53.0953 5588 drmkaud - ok
21:12:54.0125 5588 E100B (6ca101f9aa3d845ba31f6e13c01301a8) C:\WINDOWS\system32\DRIVERS\e100b325.sys
21:12:54.0125 5588 E100B - ok
21:12:54.0203 5588 eabfiltr (b5cb3084046146fd2587d8c9b219feb4) C:\WINDOWS\system32\DRIVERS\eabfiltr.sys
21:12:54.0203 5588 eabfiltr - ok
21:12:54.0265 5588 eabusb (231f4547ae1e4b3e60eca66c3a96d218) C:\WINDOWS\system32\DRIVERS\eabusb.sys
21:12:54.0281 5588 eabusb - ok
21:12:54.0500 5588 eeCtrl (75e8b69f28c813675b16db357f20720f) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
21:12:54.0515 5588 eeCtrl - ok
21:12:54.0703 5588 EraserUtilRebootDrv (720b18d76de9e603b626dfcd6f1fca7c) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
21:12:54.0703 5588 EraserUtilRebootDrv - ok
21:12:54.0890 5588 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
21:12:54.0890 5588 Fastfat - ok
21:12:54.0968 5588 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
21:12:55.0000 5588 Fdc - ok
21:12:55.0046 5588 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
21:12:55.0046 5588 Fips - ok
21:12:55.0093 5588 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
21:12:55.0109 5588 Flpydisk - ok
21:12:55.0171 5588 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
21:12:55.0171 5588 FltMgr - ok
21:12:55.0359 5588 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
21:12:55.0375 5588 Fs_Rec - ok
21:12:55.0453 5588 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
21:12:55.0468 5588 Ftdisk - ok
21:12:55.0531 5588 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
21:12:55.0640 5588 GEARAspiWDM - ok
21:12:55.0812 5588 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
21:12:55.0828 5588 Gpc - ok
21:12:55.0921 5588 HBtnKey (4d4d97671c63c3af869b3518e6054204) C:\WINDOWS\system32\DRIVERS\cpqbttn.sys
21:12:55.0937 5588 HBtnKey - ok
21:12:56.0031 5588 HdAudAddService (88e368ddc0b2200200d6810f63aab97f) C:\WINDOWS\system32\drivers\CHDAud.sys
21:12:56.0062 5588 HdAudAddService - ok
21:12:56.0125 5588 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
21:12:56.0125 5588 HDAudBus - ok
21:12:56.0218 5588 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
21:12:56.0218 5588 HidUsb - ok
21:12:56.0343 5588 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
21:12:56.0359 5588 hpn - ok
21:12:56.0437 5588 HSFHWAZL (89e256c5f5346be265d9f86ac8625d4f) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
21:12:56.0468 5588 HSFHWAZL - ok
21:12:56.0593 5588 HSF_DPV (0e44af3828111d4c3e73c33ac95226d8) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
21:12:56.0687 5588 HSF_DPV - ok
21:12:56.0812 5588 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
21:12:56.0828 5588 HTTP - ok
21:12:56.0906 5588 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
21:12:56.0921 5588 i2omgmt - ok
21:12:57.0031 5588 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
21:12:57.0078 5588 i2omp - ok
21:12:57.0109 5588 i8042prt (cdb490ccd89055439a778e16f2d37e81) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
21:12:57.0156 5588 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\i8042prt.sys. Real md5: cdb490ccd89055439a778e16f2d37e81, Fake md5: d296f811ee4079bcc7c7e643034f2ad1
21:12:57.0156 5588 i8042prt ( ForgedFile.Multi.Generic ) - warning
21:12:57.0156 5588 i8042prt - detected ForgedFile.Multi.Generic (1)
21:12:57.0203 5588 iaStor (309c4d86d989fb1fcf64bd30dc81c51b) C:\WINDOWS\system32\DRIVERS\iaStor.sys
21:12:57.0218 5588 iaStor - ok
21:12:57.0250 5588 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
21:12:57.0265 5588 Imapi - ok
21:12:57.0437 5588 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
21:12:57.0437 5588 ini910u - ok
21:12:57.0500 5588 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
21:12:57.0515 5588 IntelIde - ok
21:12:57.0593 5588 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
21:12:57.0593 5588 intelppm - ok
21:12:57.0625 5588 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
21:12:57.0640 5588 Ip6Fw - ok
21:12:57.0656 5588 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
21:12:57.0671 5588 IpFilterDriver - ok
21:12:57.0703 5588 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
21:12:57.0718 5588 IpInIp - ok
21:12:57.0750 5588 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
21:12:57.0750 5588 IpNat - ok
21:12:57.0828 5588 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
21:12:57.0828 5588 IPSec - ok
21:12:57.0984 5588 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
21:12:57.0984 5588 IRENUM - ok
21:12:58.0109 5588 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
21:12:58.0109 5588 isapnp - ok
21:12:58.0187 5588 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
21:12:58.0203 5588 Kbdclass - ok
21:12:58.0281 5588 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
21:12:58.0281 5588 kbdhid - ok
21:12:58.0359 5588 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
21:12:58.0375 5588 kmixer - ok
21:12:58.0562 5588 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
21:12:58.0562 5588 KSecDD - ok
21:12:58.0640 5588 lbrtfdc - ok
21:12:58.0703 5588 mdmxsdk (74f4372af97a587ecec527ec34955712) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
21:12:58.0703 5588 mdmxsdk - ok
21:12:58.0796 5588 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys
21:12:58.0812 5588 MHNDRV - ok
21:12:58.0843 5588 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
21:12:58.0843 5588 mnmdd - ok
21:12:58.0890 5588 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
21:12:58.0890 5588 Modem - ok
21:12:59.0031 5588 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
21:12:59.0046 5588 Mouclass - ok
21:12:59.0125 5588 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
21:12:59.0125 5588 mouhid - ok
21:12:59.0203 5588 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
21:12:59.0203 5588 MountMgr - ok
21:12:59.0250 5588 MQAC (70c14f5cca5cf73f8a645c73a01d8726) C:\WINDOWS\system32\drivers\mqac.sys
21:12:59.0265 5588 MQAC - ok
21:12:59.0328 5588 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
21:12:59.0328 5588 mraid35x - ok
21:12:59.0531 5588 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
21:12:59.0546 5588 MRxDAV - ok
21:12:59.0640 5588 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
21:12:59.0656 5588 MRxSmb - ok
21:12:59.0671 5588 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
21:12:59.0687 5588 Msfs - ok
21:12:59.0718 5588 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
21:12:59.0734 5588 MSKSSRV - ok
21:12:59.0765 5588 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
21:12:59.0765 5588 MSPCLOCK - ok
21:12:59.0812 5588 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
21:12:59.0812 5588 MSPQM - ok
21:12:59.0843 5588 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
21:12:59.0843 5588 mssmbios - ok
21:12:59.0937 5588 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
21:12:59.0937 5588 MSTEE - ok
21:12:59.0968 5588 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
21:12:59.0984 5588 Mup - ok
21:13:00.0109 5588 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
21:13:00.0125 5588 NABTSFEC - ok
21:13:00.0375 5588 NAVENG (862f55824ac81295837b0ab63f91071f) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20111216.002\naveng.sys
21:13:00.0390 5588 NAVENG - ok
21:13:00.0546 5588 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20111216.002\navex15.sys
21:13:00.0609 5588 NAVEX15 - ok
21:13:00.0812 5588 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
21:13:00.0812 5588 NDIS - ok
21:13:00.0875 5588 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
21:13:00.0906 5588 NdisIP - ok
21:13:00.0984 5588 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
21:13:01.0000 5588 NdisTapi - ok
21:13:01.0046 5588 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
21:13:01.0046 5588 Ndisuio - ok
21:13:01.0125 5588 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
21:13:01.0218 5588 NdisWan - ok
21:13:01.0390 5588 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
21:13:01.0406 5588 NDProxy - ok
21:13:01.0484 5588 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
21:13:01.0484 5588 NetBIOS - ok
21:13:01.0578 5588 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
21:13:01.0578 5588 NetBT - ok
21:13:02.0015 5588 NETwLx32 (72062b53186e4a3f5fcbc41ebb62b905) C:\WINDOWS\system32\DRIVERS\NETwLx32.sys
21:13:02.0296 5588 NETwLx32 - ok
21:13:02.0468 5588 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
21:13:02.0515 5588 NIC1394 - ok
21:13:02.0625 5588 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
21:13:02.0625 5588 Npfs - ok
21:13:02.0703 5588 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
21:13:02.0734 5588 Ntfs - ok
21:13:02.0781 5588 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
21:13:02.0781 5588 Null - ok
21:13:03.0093 5588 nv (b79e623da3614cef319b03696e821ba9) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
21:13:03.0312 5588 nv - ok
21:13:03.0406 5588 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
21:13:03.0406 5588 NwlnkFlt - ok
21:13:03.0484 5588 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
21:13:03.0500 5588 NwlnkFwd - ok
21:13:03.0562 5588 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
21:13:03.0562 5588 ohci1394 - ok
21:13:03.0750 5588 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys
21:13:03.0765 5588 Parport - ok
21:13:03.0828 5588 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
21:13:03.0828 5588 PartMgr - ok
21:13:03.0937 5588 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
21:13:03.0953 5588 ParVdm - ok
21:13:04.0000 5588 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
21:13:04.0000 5588 PCI - ok
21:13:04.0046 5588 PCIDump - ok
21:13:04.0125 5588 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
21:13:04.0125 5588 PCIIde - ok
21:13:04.0250 5588 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
21:13:04.0265 5588 Pcmcia - ok
21:13:04.0312 5588 PDCOMP - ok
21:13:04.0343 5588 PDFRAME - ok
21:13:04.0390 5588 PDRELI - ok
21:13:04.0421 5588 PDRFRAME - ok
21:13:04.0484 5588 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
21:13:04.0500 5588 perc2 - ok
21:13:04.0578 5588 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
21:13:04.0593 5588 perc2hib - ok
21:13:04.0796 5588 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
21:13:04.0843 5588 PptpMiniport - ok
21:13:04.0937 5588 PQNTDrv (04f3971b70a7855f04d351aa4bee7799) C:\WINDOWS\system32\drivers\PQNTDrv.sys
21:13:04.0937 5588 PQNTDrv - ok
21:13:04.0968 5588 PROCEXP150 - ok
21:13:05.0015 5588 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
21:13:05.0031 5588 PSched - ok
21:13:05.0140 5588 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
21:13:05.0140 5588 Ptilink - ok
21:13:05.0328 5588 PxHelp20 (86724469cd077901706854974cd13c3e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
21:13:05.0328 5588 PxHelp20 - ok
21:13:05.0406 5588 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
21:13:05.0421 5588 ql1080 - ok
21:13:05.0484 5588 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
21:13:05.0500 5588 Ql10wnt - ok
21:13:05.0578 5588 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
21:13:05.0609 5588 ql12160 - ok
21:13:05.0703 5588 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
21:13:05.0718 5588 ql1240 - ok
21:13:05.0781 5588 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
21:13:05.0796 5588 ql1280 - ok
21:13:05.0953 5588 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
21:13:05.0953 5588 RasAcd - ok
21:13:06.0046 5588 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
21:13:06.0046 5588 Rasl2tp - ok
21:13:06.0109 5588 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
21:13:06.0125 5588 RasPppoe - ok
21:13:06.0203 5588 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
21:13:06.0218 5588 Raspti - ok
21:13:06.0265 5588 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
21:13:06.0281 5588 Rdbss - ok
21:13:06.0359 5588 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
21:13:06.0375 5588 RDPCDD - ok
21:13:06.0453 5588 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
21:13:06.0484 5588 rdpdr - ok
21:13:06.0546 5588 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
21:13:06.0593 5588 RDPWD - ok
21:13:06.0671 5588 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
21:13:06.0703 5588 redbook - ok
21:13:06.0750 5588 rimmptsk (7a6648b61661b1421ffab762e391e33f) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
21:13:06.0750 5588 rimmptsk - ok
21:13:06.0781 5588 rimsptsk (d0a35b7670aa3558eaab483f64446496) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
21:13:06.0812 5588 rimsptsk - ok
21:13:06.0937 5588 rismxdp (3ac17802740c3a4764dc9750e92e6233) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys
21:13:06.0953 5588 rismxdp - ok
21:13:07.0046 5588 RMCAST (96f7a9a7bf0c9c0440a967440065d33c) C:\WINDOWS\system32\drivers\RMCast.sys
21:13:07.0062 5588 RMCAST - ok
21:13:07.0109 5588 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
21:13:07.0125 5588 rtl8139 - ok
21:13:07.0156 5588 s115bus (e1ab463b36a7ef31d8a73a97a9b57afa) C:\WINDOWS\system32\DRIVERS\s115bus.sys
21:13:07.0234 5588 s115bus - ok
21:13:07.0359 5588 s115mdfl (e24113fc13b8737c94cf4e3415488c76) C:\WINDOWS\system32\DRIVERS\s115mdfl.sys
21:13:07.0437 5588 s115mdfl - ok
21:13:07.0546 5588 s115mdm (4029e49e7c673aa0670bd206b0af1b5b) C:\WINDOWS\system32\DRIVERS\s115mdm.sys
21:13:07.0609 5588 s115mdm - ok
21:13:07.0734 5588 s115mgmt (eb02ab4ca8bccecfde236cad8fc6e135) C:\WINDOWS\system32\DRIVERS\s115mgmt.sys
21:13:07.0812 5588 s115mgmt - ok
21:13:07.0953 5588 s115obex (089869db9ffd2ac807fa87fe82ac7761) C:\WINDOWS\system32\DRIVERS\s115obex.sys
21:13:08.0000 5588 s115obex - ok
21:13:08.0109 5588 s24trans (27fc71da659305e260acbda15a318399) C:\WINDOWS\system32\DRIVERS\s24trans.sys
21:13:08.0109 5588 s24trans - ok
21:13:08.0281 5588 SAVRT (e768eff5753906272e375282d7a511e0) C:\Program Files\Symantec AntiVirus\savrt.sys
21:13:08.0343 5588 SAVRT - ok
21:13:08.0359 5588 SAVRTPEL (d9d45ad65063e8966acafb1f574c8617) C:\Program Files\Symantec AntiVirus\Savrtpel.sys
21:13:08.0406 5588 SAVRTPEL - ok
21:13:08.0578 5588 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
21:13:08.0609 5588 sdbus - ok
21:13:08.0796 5588 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
21:13:08.0843 5588 Secdrv - ok
21:13:08.0906 5588 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys
21:13:08.0906 5588 Serial - ok
21:13:08.0953 5588 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
21:13:08.0968 5588 Sfloppy - ok
21:13:09.0015 5588 Simbad - ok
21:13:09.0078 5588 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
21:13:09.0093 5588 sisagp - ok
21:13:09.0203 5588 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
21:13:09.0218 5588 SLIP - ok
21:13:09.0359 5588 SNP2UVC (fac7b89330e20713950925050c91cd04) C:\WINDOWS\system32\DRIVERS\snp2uvc.sys
21:13:09.0390 5588 SNP2UVC - ok
21:13:09.0468 5588 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
21:13:09.0484 5588 Sparrow - ok
21:13:09.0671 5588 SPBBCDrv (60053e9c1fc4f6887c296c19cb825244) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
21:13:09.0718 5588 SPBBCDrv - ok
21:13:09.0937 5588 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
21:13:09.0937 5588 splitter - ok
21:13:10.0015 5588 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
21:13:10.0015 5588 sr - ok
21:13:10.0109 5588 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
21:13:10.0125 5588 Srv - ok
21:13:10.0203 5588 StMp3Rec (833ac40f6e7be17951d6d9a956829547) C:\WINDOWS\system32\Drivers\StMp3Rec.sys
21:13:10.0218 5588 StMp3Rec - ok
21:13:10.0250 5588 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
21:13:10.0265 5588 streamip - ok
21:13:10.0296 5588 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
21:13:10.0312 5588 swenum - ok
21:13:10.0406 5588 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
21:13:10.0406 5588 swmidi - ok
21:13:10.0531 5588 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
21:13:10.0546 5588 symc810 - ok
21:13:10.0640 5588 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
21:13:10.0671 5588 symc8xx - ok
21:13:10.0781 5588 SymEvent (c5eafb6a8c73fb26b73ee613c1a5aef6) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
21:13:10.0937 5588 SymEvent - ok
21:13:11.0125 5588 SYMREDRV (4ed314756eb2811a9d4226ed4385d35c) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS
21:13:11.0187 5588 SYMREDRV - ok
21:13:11.0250 5588 SYMTDI (4aed788390802b1500e6b05127af3a2e) C:\WINDOWS\System32\Drivers\SYMTDI.SYS
21:13:11.0281 5588 SYMTDI - ok
21:13:11.0375 5588 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
21:13:11.0406 5588 sym_hi - ok
21:13:11.0421 5588 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
21:13:11.0453 5588 sym_u3 - ok
21:13:11.0484 5588 SynTP (369d0626687a968182a9db40fe8a0905) C:\WINDOWS\system32\DRIVERS\SynTP.sys
21:13:11.0531 5588 SynTP - ok
21:13:11.0890 5588 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
21:13:11.0890 5588 sysaudio - ok
21:13:12.0015 5588 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
21:13:12.0015 5588 Tcpip - ok
21:13:12.0062 5588 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
21:13:12.0109 5588 TDPIPE - ok
21:13:12.0171 5588 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
21:13:12.0187 5588 TDTCP - ok
21:13:12.0250 5588 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
21:13:12.0281 5588 TermDD - ok
21:13:12.0375 5588 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
21:13:12.0406 5588 TosIde - ok
21:13:12.0593 5588 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
21:13:12.0609 5588 Udfs - ok
21:13:12.0687 5588 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
21:13:12.0703 5588 ultra - ok
21:13:12.0812 5588 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
21:13:12.0859 5588 Update - ok
21:13:12.0937 5588 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\WINDOWS\system32\Drivers\usbaapl.sys
21:13:12.0953 5588 USBAAPL - ok
21:13:13.0015 5588 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
21:13:13.0031 5588 usbehci - ok
21:13:13.0218 5588 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
21:13:13.0343 5588 usbhub - ok
21:13:13.0421 5588 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
21:13:13.0468 5588 usbscan - ok
21:13:13.0531 5588 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
21:13:13.0546 5588 USBSTOR - ok
21:13:13.0609 5588 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
21:13:13.0625 5588 usbuhci - ok
21:13:13.0625 5588 Suspicious service (NoAccess): vdrv7000
21:13:13.0781 5588 vdrv7000 ( LockedService.Multi.Generic ) - warning
21:13:13.0781 5588 vdrv7000 - detected LockedService.Multi.Generic (1)
21:13:13.0906 5588 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
21:13:13.0906 5588 VgaSave - ok
21:13:13.0968 5588 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
21:13:13.0984 5588 viaagp - ok
21:13:14.0046 5588 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
21:13:14.0046 5588 ViaIde - ok
21:13:14.0078 5588 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
21:13:14.0093 5588 VolSnap - ok
21:13:14.0218 5588 w39n51 (4e7b07653f4f9937cf62ad2869fba520) C:\WINDOWS\system32\DRIVERS\w39n51.sys
21:13:14.0312 5588 w39n51 - ok
21:13:14.0500 5588 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
21:13:14.0500 5588 Wanarp - ok
21:13:14.0531 5588 WDICA - ok
21:13:14.0578 5588 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
21:13:14.0593 5588 wdmaud - ok
21:13:14.0687 5588 winachsf (214bc3ad84907ad6ad655ac5465f449a) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
21:13:14.0765 5588 winachsf - ok
21:13:14.0859 5588 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
21:13:14.0859 5588 WmiAcpi - ok
21:13:15.0031 5588 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
21:13:15.0046 5588 WpdUsb - ok
21:13:15.0218 5588 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
21:13:15.0234 5588 WSTCODEC - ok
21:13:15.0296 5588 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
21:13:15.0312 5588 WudfPf - ok
21:13:15.0359 5588 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
21:13:15.0390 5588 WudfRd - ok
21:13:15.0468 5588 MBR (0x1B8) (665277635dc8ba83deae12eadedb75a0) \Device\Harddisk0\DR0
21:13:15.0484 5588 \Device\Harddisk0\DR0 - ok
21:13:15.0484 5588 Boot (0x1200) (67b4396fd1817b82544d9cae57085e76) \Device\Harddisk0\DR0\Partition0
21:13:15.0484 5588 \Device\Harddisk0\DR0\Partition0 - ok
21:13:15.0531 5588 Boot (0x1200) (2aafa6fabe338b8879db716c340d119e) \Device\Harddisk0\DR0\Partition1
21:13:15.0531 5588 \Device\Harddisk0\DR0\Partition1 - ok
21:13:15.0562 5588 Boot (0x1200) (ded710de799658b39cf1b7c2ee08c8b2) \Device\Harddisk0\DR0\Partition2
21:13:15.0562 5588 \Device\Harddisk0\DR0\Partition2 - ok
21:13:15.0562 5588 ============================================================
21:13:15.0562 5588 Scan finished
21:13:15.0562 5588 ============================================================
21:13:15.0593 4424 Detected object count: 2
21:13:15.0593 4424 Actual detected object count: 2
21:13:42.0328 4424 i8042prt ( ForgedFile.Multi.Generic ) - skipped by user
21:13:42.0328 4424 i8042prt ( ForgedFile.Multi.Generic ) - User select action: Skip
21:13:42.0328 4424 vdrv7000 ( LockedService.Multi.Generic ) - skipped by user
21:13:42.0328 4424 vdrv7000 ( LockedService.Multi.Generic ) - User select action: Skip
21:14:47.0484 3076 Deinitialize success

ComboFix Log file:


ComboFix 11-12-20.04 - Pankaj 12/20/2011 22:21:46.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.301 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\Ping problem\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Pankaj\Temporary Internet Files\tpg.ico
c:\program files\LP
c:\windows\$NtUninstallKB50715$\1820568216\@
c:\windows\$NtUninstallKB50715$\1820568216\bckfg.tmp
c:\windows\$NtUninstallKB50715$\1820568216\cfg.ini
c:\windows\$NtUninstallKB50715$\1820568216\Desktop.ini
c:\windows\$NtUninstallKB50715$\1820568216\keywords
c:\windows\$NtUninstallKB50715$\1820568216\kwrd.dll
c:\windows\$NtUninstallKB50715$\1820568216\L\trbssmgb
c:\windows\$NtUninstallKB50715$\1820568216\lsflt7.ver
c:\windows\$NtUninstallKB50715$\1820568216\U\00000001.@
c:\windows\$NtUninstallKB50715$\1820568216\U\00000002.@
c:\windows\$NtUninstallKB50715$\1820568216\U\00000004.@
c:\windows\$NtUninstallKB50715$\1820568216\U\80000000.@
c:\windows\$NtUninstallKB50715$\1820568216\U\80000004.@
c:\windows\$NtUninstallKB50715$\1820568216\U\80000032.@
c:\windows\$NtUninstallKB50715$\3765233052
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\kb913800.exe
c:\windows\system\l3codecp.acm
D:\Autorun.inf
c:\windows\$NtUninstallKB50715$ . . . . Failed to delete
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_6TO4
——-\Legacy_ICF
——-\Service_.afd
——-\Service_6to4
.
.
((((((((((((((((((((((((( Files Created from 2011-11-21 to 2011-12-21 )))))))))))))))))))))))))))))))
.
.
2071-07-25 03:43 . 2006-11-21 15:18 203576 -c—-w- c:\program files\Microsoft Games\Age of Empires III\autopatcher2.exe
2011-12-20 06:14 . 2011-12-20 06:14 ——– d—–w- C:\TDSSKiller_Quarantine
2011-12-18 20:35 . 2006-02-10 08:31 ——– d—–w- C:\ubuntu(2)
2011-12-18 18:23 . 2006-02-10 08:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Intel(2)
2011-12-18 06:46 . 2011-12-18 06:46 ——– d—–w- c:\program files\CleanMyPC
2011-12-18 06:35 . 2011-12-18 06:35 ——– d—–w- c:\program files\Wise PC Doctor
2011-12-09 05:03 . 2011-12-09 05:03 ——– d—–w- c:\documents and settings\Pankaj\Local Settings\Application Data\Symantec
2011-12-09 05:02 . 2011-12-09 05:02 60800 —-a-w- c:\windows\system32\S32EVNT1.DLL
2011-12-09 05:02 . 2011-12-09 05:02 123952 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-12-09 05:00 . 2011-12-21 06:43 ——– d—–w- c:\program files\Symantec AntiVirus
2011-11-29 20:59 . 2011-11-29 20:59 ——– d—–w- c:\program files\AIM Toolbar
2011-11-29 20:59 . 2011-11-29 20:59 ——– d—–w- c:\program files\Common Files\Software Update Utility
2011-11-29 20:58 . 2011-11-29 20:58 ——– d—–w- c:\program files\AIM
2011-11-28 03:57 . 2011-11-28 03:57 ——– d—–w- c:\program files\Broadcom
2011-11-28 03:27 . 2011-11-28 03:27 ——– d—–w- c:\documents and settings\Pankaj\Application Data\Intel
2011-11-28 03:27 . 2010-10-07 13:11 6609920 —-a-w- c:\windows\system32\drivers\NETwLx32.sys
2011-11-28 03:27 . 2010-02-25 01:39 675840 —-a-w- c:\windows\system32\NETwLc32.dll
2011-11-28 03:27 . 2010-02-25 01:37 2756608 —-a-w- c:\windows\system32\NETwLr32.dll
2011-11-28 03:26 . 2011-11-28 03:26 ——– d—–w- c:\program files\Common Files\Intel
2011-11-25 06:02 . 2011-11-25 06:02 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-25 05:32 . 2011-11-25 05:32 ——– d—–w- c:\program files\Conduit
2011-11-25 05:31 . 2011-11-28 08:26 ——– d—–w- c:\documents and settings\Pankaj\Local Settings\Application Data\Conduit
2011-11-25 05:31 . 2011-11-25 05:31 ——– d—–w- c:\program files\uTorrent
2011-11-25 05:31 . 2011-12-18 07:35 ——– d—–w- c:\documents and settings\Pankaj\Application Data\uTorrent
2011-11-25 05:31 . 2011-11-25 05:31 ——– d—–w- c:\documents and settings\Pankaj\Local Settings\Application Data\uTorrent
2011-11-23 09:11 . 2011-11-23 09:11 ——– d—–w- c:\program files\Tweet Adder 3
2011-11-23 09:05 . 2011-11-23 09:10 ——– d—–w- c:\documents and settings\Pankaj\Application Data\TweetAdder3
2011-11-23 07:26 . 2011-11-27 20:16 ——– d—–w- c:\documents and settings\Pankaj\Application Data\A47B1
2011-11-22 21:48 . 2011-11-23 09:04 ——– d—–w- C:\wamp
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-26 06:11 . 2008-07-29 14:29 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 06:11 . 2006-03-16 04:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 06:11 . 2006-03-16 04:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2011-05-09 09:49 176936 —-a-w- c:\program files\uTorrentBar\prxtbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2007-07-28 1360304]
"Registry Cleaner Scheduler"="c:\program files\CleanMyPC\Registry Cleaner\RCHelper.exe" [2011-10-06 1401224]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"MsmqIntCert"="mqrt.dll" [2008-04-14 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-23 61952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-17 794713]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-26 7561216]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2011-06-23 1407248]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-06-23 1210640]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-08-03 53096]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2009-09-01 125368]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-12 581693]
HP Pavilion Webcam Tray Icon.lnk - c:\program files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe [2009-11-2 102400]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,32,\
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NecUsb3Sevice]
2006-02-10 09:05 37888 —-a-w- c:\windows\system32\USB3Nw32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\USB3Nw32]
2006-02-10 09:05 37888 —-a-w- c:\windows\system32\USB3Nw32.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor Apache Servers.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Monitor Apache Servers.lnk
backup=c:\windows\pss\Monitor Apache Servers.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Pankaj^Start Menu^Programs^StartUp^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Pankaj\Start Menu\Programs\StartUp\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Pankaj^Start Menu^Programs^StartUp^OneNote Table Of Contents.onetoc2]
path=c:\documents and settings\Pankaj\Start Menu\Programs\StartUp\OneNote Table Of Contents.onetoc2
backup=c:\windows\pss\OneNote Table Of Contents.onetoc2Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 20:55 937920 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim]
2011-05-03 15:43 4321112 —-a-w- c:\program files\AIM\aim.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\autoMe]
2008-05-08 11:24 155648 —-a-w- c:\windows\system32\wscript.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2011-12-02 06:37 137536 —-atw- c:\documents and settings\Pankaj\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-03-22 15:31 133104 —-atw- c:\documents and settings\Pankaj\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 06:14 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-16 15:11 49152 -c–a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
2006-03-15 20:00 44032 —-a-w- c:\windows\ime\imkr6_1\imekrmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2006-03-15 20:00 208952 —-a-w- c:\windows\ime\imjp8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-08 15:39 305440 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Memeo Instant Backup]
2010-04-23 00:33 136416 —-a-w- c:\program files\Memeo\AutoBackup\MemeoLauncher2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
2006-03-15 20:00 59392 —-a-w- c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-04-26 19:48 7561216 —-a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-04-26 19:48 1519616 -c–a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2006-03-15 20:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2006-03-15 20:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
2006-06-19 03:33 163840 —-a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2006-07-11 13:55 102400 -c–a-w- c:\program files\HP\QuickPlay\QPService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 20:24 417792 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecGuard]
2005-10-11 02:23 1187840 —-a-w- c:\windows\SMINST\Recguard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Seagate Dashboard]
2010-04-30 14:47 79112 —-a-w- c:\program files\Seagate\Seagate Dashboard\MemeoLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-05-13 10:42 26192168 —-a-r- c:\documents and settings\Pankaj\Desktop\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2007-06-13 02:46 528384 -c–a-r- c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 06:14 248552 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-11-25 05:31 642424 —-a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2006-10-18 15:35 204288 ——w- c:\program files\Windows Media Player\wmpnscfg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=2 (0x2)
"Tomcat5"=3 (0x3)
"OracleServiceORACLE9I"=2 (0x2)
"OracleOraHome92TNSListener"=2 (0x2)
"OracleOraHome92SNMPPeerMasterAgent"=3 (0x3)
"OracleOraHome92SNMPPeerEncapsulator"=3 (0x3)
"OracleOraHome92PagingServer"=3 (0x3)
"OracleOraHome92HTTPServer"=2 (0x2)
"OracleOraHome92ClientCache"=3 (0x3)
"OracleOraHome92Agent"=2 (0x2)
"OracleMTSRecoveryService"=2 (0x2)
"gusvc"=2 (0x2)
"gupdate1c9c5eed03863b2"=2 (0x2)
"MySQL"=2 (0x2)
"iPod Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"Apache2.2"=2 (0x2)
"VC7SecS"=2 (0x2)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"FirebirdServerDefaultInstance"=3 (0x3)
"FirebirdGuardianDefaultInstance"=2 (0x2)
"SeagateDashboardService"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"MemeoBackgroundService"=2 (0x2)
"LightScribeService"=2 (0x2)
"hpqwmiex"=2 (0x2)
"gupdatem"=3 (0x3)
"AddFiltr"=3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\Pankaj\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Pankaj\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"\\??\\c:\\WINDOWS\\system32\\winlogon.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Pankaj\\Local Settings\\Application Data\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"c:\\Documents and Settings\\Pankaj\\Desktop\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"60006:TCP"= 60006:TCP:Bitcomet 60006 TCP
"60006:UDP"= 60006:UDP:Bitcomet 60006 UDP
"3306:TCP"= 3306:TCP:MySQL Server
"60000:TCP"= 60000:TCP:BitComet 60000 TCP
"60000:UDP"= 60000:UDP:BitComet 60000 UDP
.
R2 NecUsb;USB Service;c:\windows\System32\svchost.exe -k NecUsbSevice [3/15/2006 8:00 PM 14336]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [12/8/2011 9:33 PM 106104]
R3 NETwLx32; Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [11/27/2011 7:27 PM 6609920]
S1 vdrv7000;vdrv7000;c:\windows\system32\DRIVERS\vdrv7000.sys –> c:\windows\system32\DRIVERS\vdrv7000.sys [?]
S3 PROCEXP150;PROCEXP150;\??\c:\windows\system32\Drivers\PROCEXP150.SYS –> c:\windows\system32\Drivers\PROCEXP150.SYS [?]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\drivers\s115bus.sys [3/22/2009 1:24 AM 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\drivers\s115mdfl.sys [3/22/2009 1:24 AM 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\drivers\s115mdm.sys [3/22/2009 1:24 AM 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s115mgmt.sys [3/22/2009 1:25 AM 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\drivers\s115obex.sys [3/22/2009 1:25 AM 98568]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [9/1/2009 1:15 PM 116664]
S4 Apache2.2;Apache2.2;c:\program files\Apache Software Foundation\Apache2.2\bin\httpd.exe [9/28/2009 9:11 AM 24645]
S4 gupdate1c9c5eed03863b2;Google Update Service (gupdate1c9c5eed03863b2);c:\program files\Google\Update\GoogleUpdate.exe [4/25/2009 1:43 PM 133104]
S4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/25/2009 1:43 PM 133104]
S4 MemeoBackgroundService;MemeoBackgroundService;c:\program files\Memeo\AutoBackup\MemeoBackgroundService.exe [4/22/2010 4:33 PM 25824]
S4 OracleServiceORACLE9I;OracleServiceORACLE9I;c:\oracle\ora92\bin\ORACLE.EXE ORACLE9I –> c:\oracle\ora92\bin\ORACLE.EXE ORACLE9I [?]
S4 SeagateDashboardService;Seagate Dashboard Service;c:\program files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [4/30/2010 6:47 AM 14088]
S4 Tomcat5;Apache Tomcat;c:\program files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe [8/28/2008 7:12 PM 57344]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
NecUsbSevice REG_MULTI_SZ NecUsb
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-21 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3641525057-1712457974-3760122168-1005Core.job
- c:\documents and settings\Pankaj\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-12-02 06:37]
.
2011-12-21 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3641525057-1712457974-3760122168-1005UA.job
- c:\documents and settings\Pankaj\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-12-02 06:37]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.Google.com
mStart Page = hxxp://www.Google.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com/?src=aim&ncid=snsusaimc00000001
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: SearchPreview: {EF522540-89F5-46b9-B6FE-1829E2B572C6} - %profile%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-Cpqset - c:\program files\HPQ\Default Settings\cpqset.exe
MSConfigStartUp-googletalk - c:\program files\Google\Google Talk\googletalk.exe
MSConfigStartUp-Messenger (Yahoo!) - c:\program files\Yahoo!\Messenger\YahooMessenger.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-VC7Player - c:\program files\HHVcdV7Sys\VC7Play.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-20 22:43
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OracleOraHome92TNSListener]
"ImagePath"="c:\oracle\ora92\BIN\TNSLSNR "
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):92,0c,85,45,32,2e,48,cc,bf,81,42,1f,89,8b,07,e7,11,e7,ba,fa,a2,
f6,b2,af,5c,70,9d,2f,0f,8e,c7,ff,99,c3,16,65,13,28,3d,b6,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):90,09,93,33,81,88,b0,95,49,2f,bf,eb,44,47,f5,cc,28,bf,c3,0e,07,
87,89,da,b0,dc,b2,a5,91,a3,e5,08,63,10,c9,db,6e,f7,20,ad,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{b75b22cc-db4f-4ccb-9043-6104585c7328}]
@Denied: (Full) (Everyone)
"Model"=dword:00000094
"Therad"=dword:0000000f
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{d0b660cb-9c3f-444b-92f6-a91fbb3121bd}]
@Denied: (Full) (Everyone)
"Model"=dword:00000055
"Therad"=dword:00000008
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(984)
c:\windows\system32\USB3Nw32.dll
.
- - - - - - - > 'explorer.exe'(3496)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\program files\Internet Download Manager\idmmkb.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\msi.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\netprovcredman.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\WiFi\bin\S24EvMon.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\windows\system32\msdtc.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\mqsvc.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\eHome\ehmsas.exe
c:\progra~1\hpq\Shared\HPQTOA~1.EXE
c:\windows\system32\wbem\unsecapp.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 2011-12-20 22:52:18 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-21 06:52
.
Pre-Run: 27,582,271,488 bytes free
Post-Run: 27,833,896,960 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 866E7554DD6C54E873724C5064B5162E

******
After running these, my system startup time is increased a lot. Also my keyboard and touchpad was not working but I reinstalled its driver and it's working now.

Let me know how to make my system more fast and secure.
Please scan the following files


  • Please visit Virus Total by clicking here.
  • Click the Browse button and search for the following file: C:\WINDOWS\system32\DRIVERS\i8042prt.sys
  • Click Open.
  • Then click Send File.
  • Please be patient while the file is scanned.
  • If Virus Total tells you that the file has already been scanned, click "reanalyse now".

Post the results.



Next


Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    i8042prt
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt







Next

Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please










Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Hi Mowman… thank you so much for your help. :) Now most of the things seems fine with no more of the original problem with the ping.exe process except the start up speed. Still my system takes a long time while starting up. One thing more, i am not able to understand the meaning of "Post the Log please" . Does it mean copy and paste the content or attach the log file with the reply. Anyways now i am just copy & paste the whole content. In case if u needed the log files as an attachment then confirm me. I will send it in next reply. Sorry if any inconvenience caused due to this. Here is the Virus Total Result (copy and pasted) : Antivirus Version Last Update Result AhnLab-V3 2011.12.19.03 2011.12.19 - AntiVir 7.11.19.166 2011.12.20 - Antiy-AVL 2.0.3.7 2011.12.20 - Avast 6.0.1289.0 2011.12.20 - AVG 10.0.0.1190 2011.12.20 - BitDefender 7.2 2011.12.20 - ByteHero 1.0.0.1 2011.12.07 - CAT-QuickHeal 12.00 2011.12.20 - ClamAV 0.97.3.0 2011.12.20 - Commtouch 5.3.2.6 2011.12.20 - Comodo 11025 2011.12.20 - DrWeb 5.0.2.03300 2011.12.20 - Emsisoft 5.1.0.11 2011.12.20 - eSafe 7.0.17.0 2011.12.20 - eTrust-Vet 37.0.9638 2011.12.21 - F-Prot 4.6.5.141 2011.12.19 - Fortinet 4.3.388.0 2011.12.20 - GData 22 2011.12.20 - Ikarus T3.1.1.109.0 2011.12.20 - Jiangmin 13.0.900 2011.12.21 - K7AntiVirus 9.119.5720 2011.12.19 - Kaspersky 9.0.0.837 2011.12.22 - McAfee 5.400.0.1158 2011.12.20 - McAfee-GW-Edition 2010.1E 2011.12.21 - Microsoft 1.7903 2011.12.20 - NOD32 6726 2011.12.20 - Norman 6.07.13 2011.12.21 - nProtect 2011-12-20.02 2011.12.20 - Panda 10.0.3.5 2011.12.19 - PCTools 8.0.0.5 2011.12.22 - Prevx 3.0 2011.12.22 - Rising 23.89.03.02 2011.12.22 - Sophos 4.72.0 2011.12.20 - SUPERAntiSpyware 4.40.0.1006 2011.12.20 - Symantec 20111.2.0.82 2011.12.22 - TheHacker 6.7.0.1.362 2011.12.19 - TrendMicro 9.500.0.1008 2011.12.20 - TrendMicro-HouseCall 9.500.0.1008 2011.12.20 - VBA32 3.12.16.4 2011.12.20 - VIPRE 11279 2011.12.20 - ViRobot 2011.12.20.4835 2011.12.20 - VirusBuster 14.1.125.0 2011.12.20 - Additional informationShow all MD5 : 4a0b06aa8943c1e332520f7440c0aa30 SHA1 : 684d74767873a042de4ba26a7d322f1e7ca9d6f7 SHA256: db2452390ccfe67e0c5feb4fd42ca24abe2ddd40d0b22dd5f5b8f70416863918 ssdeep: 768:l6BdF/4kwA2Aezw5YokDNrChLJBoWcH1yaXD3bo7mXv:kn+NAr5DzJc1NU7mX File size : 52480 bytes First seen: 2009-02-26 19:01:04 Last seen : 2011-12-22 06:35:51 TrID: Win64 Executable Generic (87.2%) Win32 Executable Generic (8.6%) Generic Win/DOS Executable (2.0%) DOS Executable Generic (2.0%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%) sigcheck: publisher….: Microsoft Corporation copyright….: © Microsoft Corporation. All rights reserved. product……: Microsoft_ Windows_ Operating System description..: i8042 Port Driver original name: i8042prt.sys internal name: i8042prt.sys file version.: 5.1.2600.5512 (xpsp.080413-2108) comments…..: n/a signers……: - signing date.: - verified…..: Unsigned PEInfo: PE structure information [[ basic data ]] entrypointaddress: 0x9285 timedatestamp….: 0x48025C67 (Sun Apr 13 19:17:59 2008) machinetype……: 0x14c (I386) [[ 8 section(s) ]] name, viradd, virsiz, rawdsiz, ntropy, md5 .text, 0x380, 0x2F7D, 0x2F80, 6.29, 480312771a608f6a5caca6fb9aafa798 .rdata, 0x3300, 0x55C, 0x580, 4.14, 1d223a940005ec034a1f792bb605dd4a .data, 0x3880, 0xD0, 0x100, 2.74, 0ec724d6f97ff023c63a177c0154eb48 PAGE, 0x3980, 0x42DE, 0x4300, 6.46, 0e030b0c09aa6505c55374157ea10e20 PAGEMOUC, 0x7C80, 0x15D1, 0x1600, 5.99, fd5def37fd5ef0dab9a361c228a8fb97 INIT, 0x9280, 0xEEE, 0xF00, 6.04, 95628c2da10f09c0e2bb2adc8a66bd68 .rsrc, 0xA180, 0x2418, 0x2480, 3.42, 16557198c3b57f1269633b7aa1b6aa35 .reloc, 0xC600, 0x6A4, 0x700, 6.51, 6d182043566196ca9d3f6d59e051d169 [[ 3 import(s) ]] HAL.dll: KfAcquireSpinLock, READ_PORT_UCHAR, KfRaiseIrql, KfLowerIrql, WRITE_PORT_UCHAR, KfReleaseSpinLock, KeGetCurrentIrql, KeStallExecutionProcessor ntoskrnl.exe: IoBuildDeviceIoControlRequest, KeInitializeEvent, IoStartPacket, IoAcquireRemoveLockEx, memmove, ObfDereferenceObject, IoGetAttachedDeviceReference, ExAllocatePoolWithTag, WRITE_REGISTER_UCHAR, READ_REGISTER_UCHAR, MmMapIoSpace, KeInsertQueueDpc, KeSetTimer, KeSynchronizeExecution, IoReleaseCancelSpinLock, IoAcquireCancelSpinLock, IoAllocateController, IoDeleteController, MmUnmapIoSpace, KeDelayExecutionThread, RtlQueryRegistryValues, RtlAppendUnicodeToString, wcslen, RtlInitUnicodeString, KeInitializeTimer, KeInitializeSpinLock, IoCreateController, IoInvalidateDeviceState, PoStartNextPowerIrp, PoSetPowerState, KeBugCheckEx, ZwSetValueKey, ZwClose, ZwOpenKey, KeQueryTimeIncrement, KeTickCount, _allmul, IofCallDriver, DbgBreakPointWithStatus, KdDebuggerEnabled, KdDebuggerNotPresent, _except_handler3, IoConnectInterrupt, KeInitializeDpc, KeRemoveQueueDpc, RtlFreeUnicodeString, IoSetDeviceInterfaceState, IoDisconnectInterrupt, KeSetTimerEx, IoFreeIrp, _wcsupr, _alldiv, IoAllocateIrp, MmLockPagableDataSection, IoUnregisterPlugPlayNotification, IoFreeWorkItem, wcscmp, IoQueueWorkItem, IoAllocateWorkItem, KeInitializeTimerEx, IoRegisterPlugPlayNotification, IoInitializeRemoveLockEx, IoDeleteDevice, IoAttachDeviceToDeviceStack, IoCreateDevice, KeSetEvent, IoQueryDeviceDescription, IoRegisterDeviceInterface, ExQueueWorkItem, IoDetachDevice, ExReleaseFastMutexUnsafe, ExAcquireFastMutexUnsafe, IoReleaseRemoveLockAndWaitEx, IoWMIRegistrationControl, PoCallDriver, KeWaitForSingleObject, IoAllocateErrorLogEntry, IoWriteErrorLogEntry, KeCancelTimer, KefAcquireSpinLockAtDpcLevel, ExFreePoolWithTag, KefReleaseSpinLockFromDpcLevel, IoFreeController, IoStartNextPacket, IoReleaseRemoveLockEx, IoOpenDeviceRegistryKey, IofCompleteRequest WMILIB.SYS: WmiSystemControl, WmiCompleteRequest ExifTool: file metadata CharacterSet: Unicode CodeSize: 38784 CompanyName: Microsoft Corporation EntryPoint: 0x9285 FileDescription: i8042 Port Driver FileFlagsMask: 0x003f FileOS: Windows NT 32-bit FileSize: 51 kB FileSubtype: 7 FileType: Win32 EXE FileVersion: 5.1.2600.5512 (xpsp.080413-2108) FileVersionNumber: 5.1.2600.5512 ImageVersion: 5.1 InitializedDataSize: 12800 InternalName: i8042prt.sys LanguageCode: English (U.S.) LegalCopyright: Microsoft Corporation. All rights reserved. LinkerVersion: 7.1 MIMEType: application/octet-stream MachineType: Intel 386 or later, and compatibles OSVersion: 5.1 ObjectFileType: Driver OriginalFilename: i8042prt.sys PEType: PE32 ProductName: Microsoft Windows Operating System ProductVersion: 5.1.2600.5512 ProductVersionNumber: 5.1.2600.5512 Subsystem: Native SubsystemVersion: 5.1 TimeStamp: 2008:04:13 21:17:59+02:00 UninitializedDataSize: 0 System Look Log Result (copy and pasted) : SystemLook 30.07.11 by jpshortstuff Log created at 23:28 on 21/12/2011 by Pankaj Administrator - Elevation successful ========== filefind ========== Searching for "i8042prt" No files found. -= EOF =- Malwarebytes Log Result (copy and pasted) : Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 911122201 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 12/22/2011 12:17:32 AM mbam-log-2011-12-22 (00-17-32).txt Scan type: Quick scan Objects scanned: 231778 Time elapsed: 18 minute(s), 52 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 5 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: c:\WINDOWS\system32\NUSB3w32.dll (Trojan.Dropper) -> Delete on reboot. Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\Pankaj\Local Settings\Application Data\naq.exe" -a "") Good: (iexplore.exe) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: c:\WINDOWS\system32\NUSB3w32.dll (Trojan.Dropper) -> Delete on reboot. c:\documents and settings\Pankaj\Desktop\cnet2_wampserver2_2a-x32_exe.exe (Adware.Downloader) -> Quarantined and deleted successfully. c:\WINDOWS\system32\6to4v32.dll (Trojan.Wimpixo) -> Quarantined and deleted successfully. c:\WINDOWS\system32\certstore.dat (Trojan.Agent) -> Quarantined and deleted successfully. c:\documents and settings\Pankaj\Desktop\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully. Eset Online Scanner Log Result (copy and pasted) : ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=5b6355607bded547b50fd09e82a7ac5b # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-12-22 11:32:36 # local_time=2011-12-22 03:32:36 (-0800, Pacific Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=191009 # found=31 # cleaned=31 # scan_time=10258 C:\Documents and Settings\Pankaj\Application Data\Sun\Java\Deployment\cache\6.0\56\2a521178-6fafd0f5 a variant of Win32/Kryptik.XOD trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\Pankaj\Desktop\Extra Document\VideoConverterSetup.exe a variant of Win32/SweetIM.A application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\Pankaj\My Documents\Downloads\Programs\VideoConverterSetup.exe a variant of Win32/SweetIM.A application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP609\A0530302.exe a variant of Win32/Kryptik.WSK trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP609\A0530303.exe a variant of Win32/Kryptik.WQU trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP609\A0530314.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP609\A0530333.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP609\A0530342.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP609\A0530361.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP609\A0530368.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP609\A0530388.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP609\A0531388.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP610\A0531428.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP610\A0532428.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP610\A0532446.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP611\A0532512.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP611\A0533512.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP611\A0533526.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP612\A0533578.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP612\A0534578.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP612\A0535578.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP612\A0536578.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP612\A0536584.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP612\A0536599.exe a variant of Win32/Kryptik.WSK trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP612\A0536600.exe a variant of Win32/Kryptik.WQU trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP614\A0537217.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP614\A0537223.sys a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP615\A0537956.exe a variant of Win32/SweetIM.A application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\TDSSKiller_Quarantine\19.12.2011_22.13.18\susp0000\svc0000\tsk0000.dta a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\TDSSKiller_Quarantine\19.12.2011_22.13.18\susp0000\svc0000\tsk0001.dta a variant of Win32/Rootkit.Kryptik.GG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\WINDOWS\system32\autorun.ini Win32/AutoRun.Autoit.U worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C Thanks, Meghna
Yes just copy/paste as you are doing.



Allow combofix to update if it asks.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    REGLOCKDEL::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
    
    REGLOCK::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{b75b22cc-db4f-4ccb-9043-6104585c7328}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{d0b660cb-9c3f-444b-92f6-a91fbb3121bd}]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.









  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.

ComboFix Log Result:


ComboFix 11-12-22.04 - Pankaj 12/22/2011 18:24:23.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.400 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\Ping problem\ComboFix.exe
Command switches used :: c:\documents and settings\Pankaj\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *Disabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\windows\system32\oobe\isperror
c:\windows\system32\oobe\isperror\ispcnerr.htm
c:\windows\system32\oobe\isperror\ispdtone.htm
c:\windows\system32\oobe\isperror\isphdshk.htm
c:\windows\system32\oobe\isperror\ispins.htm
c:\windows\system32\oobe\isperror\ispnoanw.htm
c:\windows\system32\oobe\isperror\isppberr.htm
c:\windows\system32\oobe\isperror\ispphbsy.htm
c:\windows\system32\oobe\isperror\ispsbusy.htm
.
.
((((((((((((((((((((((((( Files Created from 2011-11-23 to 2011-12-23 )))))))))))))))))))))))))))))))
.
.
2071-07-25 03:43 . 2006-11-21 15:18 203576 -c—-w- c:\program files\Microsoft Games\Age of Empires III\autopatcher2.exe
2011-12-22 08:31 . 2011-12-22 08:31 ——– d—–w- c:\program files\ESET
2011-12-22 07:40 . 2011-09-01 01:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-22 07:24 . 2011-12-22 07:24 ——– d—–w- c:\documents and settings\Pankaj\Local Settings\Application Data\AIM Toolbar
2011-12-21 18:22 . 2011-12-22 07:20 ——– d–h–w- c:\windows\$hf_mig$
2011-12-21 07:20 . 2011-12-21 07:20 ——– d—–w- c:\windows\system32\wbem\Repository
2011-12-20 06:14 . 2011-12-20 06:14 ——– d—–w- C:\TDSSKiller_Quarantine
2011-12-18 20:35 . 2006-02-10 08:31 ——– d—–w- C:\ubuntu(2)
2011-12-18 18:23 . 2006-02-10 08:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Intel(2)
2011-12-18 06:46 . 2011-12-18 06:46 ——– d—–w- c:\program files\CleanMyPC
2011-12-18 06:35 . 2011-12-18 06:35 ——– d—–w- c:\program files\Wise PC Doctor
2011-12-09 05:03 . 2011-12-09 05:03 ——– d—–w- c:\documents and settings\Pankaj\Local Settings\Application Data\Symantec
2011-12-09 05:02 . 2011-12-09 05:02 60800 —-a-w- c:\windows\system32\S32EVNT1.DLL
2011-12-09 05:02 . 2011-12-09 05:02 123952 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-12-09 05:00 . 2011-12-23 02:18 ——– d—–w- c:\program files\Symantec AntiVirus
2011-11-29 20:59 . 2011-11-29 20:59 ——– d—–w- c:\program files\AIM Toolbar
2011-11-29 20:59 . 2011-11-29 20:59 ——– d—–w- c:\program files\Common Files\Software Update Utility
2011-11-29 20:58 . 2011-11-29 20:58 ——– d—–w- c:\program files\AIM
2011-11-28 03:57 . 2011-11-28 03:57 ——– d—–w- c:\program files\Broadcom
2011-11-28 03:27 . 2011-11-28 03:27 ——– d—–w- c:\documents and settings\Pankaj\Application Data\Intel
2011-11-28 03:27 . 2010-10-07 13:11 6609920 —-a-w- c:\windows\system32\drivers\NETwLx32.sys
2011-11-28 03:27 . 2010-02-25 01:39 675840 —-a-w- c:\windows\system32\NETwLc32.dll
2011-11-28 03:27 . 2010-02-25 01:37 2756608 —-a-w- c:\windows\system32\NETwLr32.dll
2011-11-28 03:26 . 2011-11-28 03:26 ——– d—–w- c:\program files\Common Files\Intel
2011-11-25 06:02 . 2011-11-25 06:02 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-25 05:32 . 2011-11-25 05:32 ——– d—–w- c:\program files\Conduit
2011-11-25 05:31 . 2011-11-28 08:26 ——– d—–w- c:\documents and settings\Pankaj\Local Settings\Application Data\Conduit
2011-11-25 05:31 . 2011-11-25 05:31 ——– d—–w- c:\program files\uTorrent
2011-11-25 05:31 . 2011-12-18 07:35 ——– d—–w- c:\documents and settings\Pankaj\Application Data\uTorrent
2011-11-25 05:31 . 2011-11-25 05:31 ——– d—–w- c:\documents and settings\Pankaj\Local Settings\Application Data\uTorrent
2011-11-23 09:11 . 2011-11-23 09:11 ——– d—–w- c:\program files\Tweet Adder 3
2011-11-23 09:05 . 2011-11-23 09:10 ——– d—–w- c:\documents and settings\Pankaj\Application Data\TweetAdder3
2011-11-23 07:26 . 2011-11-27 20:16 ——– d—–w- c:\documents and settings\Pankaj\Application Data\A47B1
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-23 13:25 . 2006-03-16 04:00 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-04 19:20 . 2006-03-16 04:00 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2006-03-16 04:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2006-03-16 04:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2006-03-16 04:00 385024 —-a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2006-03-16 04:00 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2006-03-16 04:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2006-03-16 04:00 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2006-03-16 04:00 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-10 14:22 . 2006-03-16 04:00 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2006-03-16 04:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 06:11 . 2008-07-29 14:29 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 06:11 . 2006-03-16 04:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 06:11 . 2006-03-16 04:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-21_06.43.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-04-19 06:51 . 2011-04-19 06:51 51024 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_4ddc769f\vcomp90.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90rus.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90kor.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90jpn.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90ita.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90fra.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esp.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esn.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 53584 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90enu.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 63312 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90deu.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90cht.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 35664 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90chs.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90u.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90.dll
+ 2011-05-14 04:17 . 2011-05-14 04:17 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_452bf920\vcomp.dll
+ 2011-05-14 03:45 . 2011-05-14 03:45 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80KOR.dll
+ 2011-05-14 03:45 . 2011-05-14 03:45 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80JPN.dll
+ 2011-05-14 03:45 . 2011-05-14 03:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ITA.dll
+ 2011-05-14 03:45 . 2011-05-14 03:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80FRA.dll
+ 2011-05-14 03:45 . 2011-05-14 03:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ESP.dll
+ 2011-05-14 03:45 . 2011-05-14 03:45 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ENU.dll
+ 2011-05-14 03:45 . 2011-05-14 03:45 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80DEU.dll
+ 2011-05-14 03:45 . 2011-05-14 03:45 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80CHT.dll
+ 2011-05-14 03:45 . 2011-05-14 03:45 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80CHS.dll
+ 2011-05-14 09:06 . 2011-05-14 09:06 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80u.dll
+ 2011-05-14 09:23 . 2011-05-14 09:23 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80.dll
+ 2011-05-14 02:37 . 2011-05-14 02:37 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_a4c618fa\ATL80.dll
+ 2011-12-22 17:48 . 2011-12-22 17:48 16384 c:\windows\Temp\Perflib_Perfdata_5c0.dat
+ 2008-10-22 09:47 . 2011-11-08 13:46 46080 c:\windows\system32\tzchange.exe
- 2008-10-22 09:47 . 2011-07-08 13:49 46080 c:\windows\system32\tzchange.exe
+ 2006-06-29 18:27 . 2011-12-22 07:36 75264 c:\windows\system32\perfc009.dat
- 2006-06-29 18:27 . 2011-11-28 08:25 75264 c:\windows\system32\perfc009.dat
- 2005-07-03 10:11 . 2011-08-22 23:48 66560 c:\windows\system32\mshtmled.dll
+ 2005-07-03 10:11 . 2011-11-04 19:20 66560 c:\windows\system32\mshtmled.dll
- 2009-03-07 23:01 . 2011-08-22 23:48 55296 c:\windows\system32\msfeedsbs.dll
+ 2009-03-07 23:01 . 2011-11-04 19:20 55296 c:\windows\system32\msfeedsbs.dll
- 2006-03-16 04:00 . 2011-08-22 23:48 25600 c:\windows\system32\jsproxy.dll
+ 2006-03-16 04:00 . 2011-11-04 19:20 25600 c:\windows\system32\jsproxy.dll
+ 2006-03-16 04:00 . 2008-04-14 08:48 52480 c:\windows\system32\drivers\i8042prt.sys
- 2006-03-16 04:00 . 2008-04-13 19:18 52480 c:\windows\system32\drivers\i8042prt.sys
- 2009-08-27 16:33 . 2011-08-22 23:48 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2009-08-27 16:33 . 2011-11-04 19:20 12800 c:\windows\system32\dllcache\xpshims.dll
- 2009-03-07 23:01 . 2011-08-22 23:48 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2009-03-07 23:01 . 2011-11-04 19:20 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2009-08-27 16:33 . 2011-11-04 19:20 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2009-08-27 16:33 . 2011-08-22 23:48 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2009-03-07 23:04 . 2011-11-04 19:20 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2009-03-07 23:04 . 2011-08-22 23:48 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2009-03-07 23:03 . 2011-08-22 23:48 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-03-07 23:03 . 2011-11-04 19:20 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-03-16 04:00 . 2008-04-14 08:48 52480 c:\windows\system32\dllcache\i8042prt.sys
+ 2009-12-14 07:08 . 2011-10-28 05:31 33280 c:\windows\system32\dllcache\csrsrv.dll
- 2009-12-14 07:08 . 2011-04-26 11:07 33280 c:\windows\system32\dllcache\csrsrv.dll
- 2010-09-23 10:25 . 2010-09-23 10:25 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2011-07-08 22:00 . 2011-07-08 22:00 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2011-07-07 20:04 . 2011-07-07 20:04 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2010-09-22 20:56 . 2010-09-22 20:56 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2010-09-22 20:56 . 2010-09-22 20:56 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2011-07-07 20:04 . 2011-07-07 20:04 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2010-09-22 20:56 . 2010-09-22 20:56 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2011-07-07 20:03 . 2011-07-07 20:03 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2011-07-07 21:09 . 2011-07-07 21:09 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2010-09-22 21:47 . 2010-09-22 21:47 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2010-09-22 21:47 . 2010-09-22 21:47 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2011-07-07 21:09 . 2011-07-07 21:09 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2009-03-17 05:28 . 2011-12-22 07:39 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-03-17 05:28 . 2010-12-19 17:31 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-03-17 05:28 . 2011-12-22 07:39 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-03-17 05:28 . 2010-12-19 17:31 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-03-17 05:28 . 2011-12-22 07:39 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2009-03-17 05:28 . 2010-12-19 17:31 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2009-10-15 16:33 . 2010-12-19 17:28 35088 c:\windows\Installer\{90120000-0026-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-10-15 16:33 . 2011-12-22 07:38 35088 c:\windows\Installer\{90120000-0026-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-10-15 16:33 . 2011-12-22 07:38 18704 c:\windows\Installer\{90120000-0026-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-10-15 16:33 . 2010-12-19 17:28 18704 c:\windows\Installer\{90120000-0026-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-10-15 16:33 . 2011-12-22 07:38 20240 c:\windows\Installer\{90120000-0026-0000-0000-0000000FF1CE}\cagicon.exe
- 2009-10-15 16:33 . 2010-12-19 17:28 20240 c:\windows\Installer\{90120000-0026-0000-0000-0000000FF1CE}\cagicon.exe
+ 2011-12-22 07:20 . 2011-08-22 23:48 12800 c:\windows\ie8updates\KB2618444-IE8\xpshims.dll
+ 2011-12-22 07:20 . 2011-08-22 23:48 66560 c:\windows\ie8updates\KB2618444-IE8\mshtmled.dll
+ 2011-12-22 07:20 . 2011-08-22 23:48 55296 c:\windows\ie8updates\KB2618444-IE8\msfeedsbs.dll
+ 2011-12-22 07:20 . 2011-08-22 23:48 43520 c:\windows\ie8updates\KB2618444-IE8\licmgr10.dll
+ 2011-12-22 07:20 . 2011-08-22 23:48 25600 c:\windows\ie8updates\KB2618444-IE8\jsproxy.dll
+ 2011-12-22 07:03 . 2011-12-22 07:03 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_415eed68\System.Drawing.Design.dll
+ 2011-12-22 07:03 . 2011-12-22 07:03 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_119845c5\CustomMarshalers.dll
+ 2011-12-22 07:51 . 2011-12-22 07:51 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\2cddd536dadeef050e4247682b0f6a04\UIAutomationProvider.ni.dll
+ 2011-12-22 08:07 . 2011-12-22 08:07 85504 c:\windows\assembly\NativeImages_v2.0.50727_32\ToadDataCompareAndS#\97c84910179c585964f8b45ce5fc2a0a\ToadDataCompareAndSync.ni.dll
+ 2011-12-22 08:13 . 2011-12-22 08:13 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\e3dc8c452a54c727a6ca7da6572192b8\System.Windows.Presentation.ni.dll
+ 2011-12-22 08:12 . 2011-12-22 08:12 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\b39c3a656afed5f571a1c55863849788\System.Web.DynamicData.Design.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\ee79616f6145527dc9d0c02ae2331a8d\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\c41edd92dbe56d371477a9c4fe4dafec\System.AddIn.Contract.ni.dll
+ 2011-12-22 07:39 . 2011-12-22 07:39 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\e202c7cf85beb510d4f424a79f9a89cb\PresentationFontCache.ni.exe
+ 2011-12-22 07:38 . 2011-12-22 07:38 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\4914286e1b121bd100da48944261398b\PresentationCFFRasterizer.ni.dll
+ 2011-12-22 08:07 . 2011-12-22 08:07 68608 c:\windows\assembly\NativeImages_v2.0.50727_32\MySqlSchemaCompare\f03f14ffc09d7cd65f80add483752035\MySqlSchemaCompare.ni.dll
+ 2011-12-22 08:05 . 2011-12-22 08:05 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\b44f32dd3ad15f3299630044c435896b\Microsoft.Vsa.ni.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\8191fe6726ededf330ba744a7da7710e\Microsoft.VisualC.ni.dll
+ 2011-12-22 08:02 . 2011-12-22 08:02 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\b3874dfe33069d1892fad36fdb95685e\Microsoft.Build.Framework.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\a2c03051c7af52312d9befa7d27426e4\Microsoft.Build.Framework.ni.dll
+ 2011-12-22 08:08 . 2011-12-22 08:08 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\c6aad13c348908d22204983686f494ca\dfsvc.ni.exe
+ 2011-12-22 08:06 . 2011-12-22 08:06 97792 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraChar#\15a7aee2d5bf4e00111b8e99321972fe\DevExpress.XtraCharts.v8.3.UI.ni.dll
+ 2011-12-22 08:00 . 2011-12-22 08:00 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\8a693ac0d20014bff4913e64c706a09f\Accessibility.ni.dll
- 2010-10-18 09:43 . 2010-10-18 09:43 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2010-10-18 09:43 . 2010-10-18 09:43 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-12-22 07:36 . 2011-12-22 07:36 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2011-12-22 07:02 . 2011-12-22 07:02 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
- 2010-10-18 09:10 . 2010-10-18 09:10 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2010-10-18 09:44 . 2010-10-18 09:44 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 653136 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 569680 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcm90.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 159048 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_92453bb7\atl90.dll
+ 2011-05-14 09:17 . 2011-05-14 09:17 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll
+ 2011-05-14 09:12 . 2011-05-14 09:12 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcp80.dll
+ 2011-05-14 09:11 . 2011-05-14 09:11 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcm80.dll
+ 2006-03-16 04:00 . 2011-11-04 19:20 105984 c:\windows\system32\url.dll
- 2006-03-16 04:00 . 2011-08-22 23:48 105984 c:\windows\system32\url.dll
+ 2009-04-24 21:20 . 2011-12-21 07:21 295688 c:\windows\system32\Restore\rstrlog.dat
- 2006-06-29 18:27 . 2011-11-28 08:25 455316 c:\windows\system32\perfh009.dat
+ 2006-06-29 18:27 . 2011-12-22 07:36 455316 c:\windows\system32\perfh009.dat
+ 2006-03-16 04:00 . 2011-11-04 19:20 206848 c:\windows\system32\occache.dll
- 2006-03-16 04:00 . 2011-08-22 23:48 206848 c:\windows\system32\occache.dll
+ 2006-03-16 04:00 . 2011-11-04 19:20 611840 c:\windows\system32\mstime.dll
- 2006-03-16 04:00 . 2011-08-22 23:48 611840 c:\windows\system32\mstime.dll
- 2009-03-07 23:02 . 2011-08-22 23:48 602112 c:\windows\system32\msfeeds.dll
+ 2009-03-07 23:02 . 2011-11-04 19:20 602112 c:\windows\system32\msfeeds.dll
+ 2011-12-19 18:31 . 2011-12-21 18:21 103733 c:\windows\system32\itusbcore.dat
- 2006-01-25 10:54 . 2011-08-22 23:48 184320 c:\windows\system32\iepeers.dll
+ 2006-01-25 10:54 . 2011-11-04 19:20 184320 c:\windows\system32\iepeers.dll
- 2006-03-16 04:00 . 2011-08-22 23:48 387584 c:\windows\system32\iedkcs32.dll
+ 2006-03-16 04:00 . 2011-11-04 19:20 387584 c:\windows\system32\iedkcs32.dll
+ 2009-03-15 23:57 . 2011-11-04 19:20 916992 c:\windows\system32\dllcache\wininet.dll
- 2009-03-07 23:04 . 2011-08-22 23:48 105984 c:\windows\system32\dllcache\url.dll
+ 2009-03-07 23:04 . 2011-11-04 19:20 105984 c:\windows\system32\dllcache\url.dll
+ 2009-03-07 23:04 . 2011-11-04 19:20 206848 c:\windows\system32\dllcache\occache.dll
- 2009-03-07 23:04 . 2011-08-22 23:48 206848 c:\windows\system32\dllcache\occache.dll
+ 2009-03-07 23:02 . 2011-11-04 19:20 611840 c:\windows\system32\dllcache\mstime.dll
- 2009-03-07 23:02 . 2011-08-22 23:48 611840 c:\windows\system32\dllcache\mstime.dll
+ 2009-08-27 16:33 . 2011-11-04 19:20 602112 c:\windows\system32\dllcache\msfeeds.dll
- 2009-08-27 16:33 . 2011-08-22 23:48 602112 c:\windows\system32\dllcache\msfeeds.dll
+ 2009-03-15 22:34 . 2011-10-10 14:22 692736 c:\windows\system32\dllcache\inetcomm.dll
- 2009-03-15 22:34 . 2011-05-02 15:31 692736 c:\windows\system32\dllcache\inetcomm.dll
+ 2009-08-27 16:33 . 2011-11-04 19:20 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2009-08-27 16:33 . 2011-08-22 23:48 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2009-03-07 23:01 . 2011-08-22 23:48 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2009-03-07 23:01 . 2011-11-04 19:20 184320 c:\windows\system32\dllcache\iepeers.dll
- 2010-10-18 08:48 . 2011-08-22 23:48 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2010-10-18 08:48 . 2011-11-04 19:20 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2009-03-08 08:39 . 2011-11-04 19:20 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2009-03-08 08:39 . 2011-08-22 23:48 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2009-03-07 23:02 . 2011-08-22 11:56 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2009-03-07 23:02 . 2011-11-04 11:24 174080 c:\windows\system32\dllcache\ie4uinit.exe
- 2011-09-09 09:12 . 2011-09-09 09:12 599040 c:\windows\system32\dllcache\crypt32.dll
+ 2011-09-09 09:12 . 2011-09-28 07:06 599040 c:\windows\system32\dllcache\crypt32.dll
+ 2011-07-07 13:18 . 2011-07-07 13:18 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
- 2010-05-11 01:10 . 2010-05-11 01:10 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
- 2010-05-11 01:10 . 2010-05-11 01:10 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2011-07-07 13:18 . 2011-07-07 13:18 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
- 2010-09-22 20:56 . 2010-09-22 20:56 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2011-07-07 20:04 . 2011-07-07 20:04 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2010-09-22 20:55 . 2010-09-22 20:55 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2011-07-07 20:01 . 2011-07-07 20:01 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2010-09-22 21:47 . 2010-09-22 21:47 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-07-07 21:09 . 2011-07-07 21:09 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-03-18 04:03 . 2011-03-18 04:03 308736 c:\windows\Installer\fc6fb.msp
+ 2011-12-22 07:27 . 2011-12-22 07:27 223744 c:\windows\Installer\15d8c49.msi
+ 2011-12-22 07:06 . 2011-12-22 07:06 467456 c:\windows\Installer\15d8b16.msi
- 2009-03-17 05:28 . 2010-12-19 17:31 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-03-17 05:28 . 2011-12-22 07:39 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-03-17 05:28 . 2011-12-22 07:39 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2009-03-17 05:28 . 2010-12-19 17:31 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2009-03-17 05:28 . 2011-12-22 07:39 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2009-03-17 05:28 . 2010-12-19 17:31 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-03-17 05:28 . 2011-12-22 07:39 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2009-03-17 05:28 . 2010-12-19 17:31 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2009-03-17 05:28 . 2010-12-19 17:31 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-03-17 05:28 . 2011-12-22 07:39 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-03-17 05:28 . 2011-12-22 07:39 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2009-03-17 05:28 . 2010-12-19 17:31 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-03-17 05:28 . 2011-12-22 07:39 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2009-03-17 05:28 . 2010-12-19 17:31 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2009-10-15 16:33 . 2011-12-22 07:38 217864 c:\windows\Installer\{90120000-0026-0000-0000-0000000FF1CE}\misc.exe
- 2009-10-15 16:33 . 2010-12-19 17:28 217864 c:\windows\Installer\{90120000-0026-0000-0000-0000000FF1CE}\misc.exe
+ 2006-10-27 05:30 . 2006-10-27 05:30 482088 c:\windows\Installer\$PatchCache$\Managed\00002109620000000000000000F01FEC\12.0.4518\PORTCONN.DLL
+ 2009-02-14 00:34 . 2009-02-14 00:34 625520 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\GROOVEWEBSERVICES.DLL
+ 2009-02-12 09:49 . 2009-02-12 09:49 688512 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\GROOVEWEBPLATFORMSERVICES.DLL
+ 2009-03-05 23:03 . 2009-03-05 23:03 961888 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\GROOVEUTIL.DLL
+ 2009-02-14 00:33 . 2009-02-14 00:33 337264 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\GROOVE.EXE
+ 2011-12-22 07:20 . 2011-08-22 23:48 916480 c:\windows\ie8updates\KB2618444-IE8\wininet.dll
+ 2011-12-22 07:20 . 2011-08-22 23:48 105984 c:\windows\ie8updates\KB2618444-IE8\url.dll
+ 2011-12-22 07:20 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2618444-IE8\spuninst\updspapi.dll
+ 2011-12-22 07:20 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2618444-IE8\spuninst\spuninst.exe
+ 2011-12-22 07:20 . 2011-08-22 23:48 206848 c:\windows\ie8updates\KB2618444-IE8\occache.dll
+ 2011-12-22 07:20 . 2011-08-22 23:48 611840 c:\windows\ie8updates\KB2618444-IE8\mstime.dll
+ 2011-12-22 07:20 . 2011-08-22 23:48 602112 c:\windows\ie8updates\KB2618444-IE8\msfeeds.dll
+ 2011-12-22 07:20 . 2011-08-22 23:48 247808 c:\windows\ie8updates\KB2618444-IE8\ieproxy.dll
+ 2011-12-22 07:20 . 2011-08-22 23:48 184320 c:\windows\ie8updates\KB2618444-IE8\iepeers.dll
+ 2011-12-22 07:20 . 2011-08-22 23:48 743424 c:\windows\ie8updates\KB2618444-IE8\iedvtool.dll
+ 2011-12-22 07:20 . 2011-08-22 23:48 387584 c:\windows\ie8updates\KB2618444-IE8\iedkcs32.dll
+ 2011-12-22 07:20 . 2011-08-22 11:56 174080 c:\windows\ie8updates\KB2618444-IE8\ie4uinit.exe
+ 2011-12-22 07:03 . 2011-12-22 07:03 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_99a44404\System.Drawing.dll
+ 2011-12-22 07:03 . 2011-12-22 07:03 192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_8786244e\System.Drawing.Design.dll
+ 2011-12-22 07:03 . 2011-12-22 07:03 118784 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_87e383f0\CustomMarshalers.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\5bd92bfe8b9cdfc22ddffb5889917391\WsatConfig.ni.exe
+ 2011-12-22 07:51 . 2011-12-22 07:51 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\e4555833746b95b63cb09929369fd199\WindowsFormsIntegration.ni.dll
+ 2011-12-22 07:51 . 2011-12-22 07:51 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\1d1a920a8e798c76879d56b151789d3e\UIAutomationTypes.ni.dll
+ 2011-12-22 07:50 . 2011-12-22 07:50 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\9f48813b8a911bca465d07bb9f21de79\UIAutomationClient.ni.dll
+ 2011-12-22 08:07 . 2011-12-22 08:07 775168 c:\windows\assembly\NativeImages_v2.0.50727_32\ToadMySQL\01f753f5820afe177f921404c2040134\ToadMySQL.ni.dll
+ 2011-12-22 08:06 . 2011-12-22 08:06 160768 c:\windows\assembly\NativeImages_v2.0.50727_32\ToadDiff\59ca5c20d7be000dd8b0182178a384ea\ToadDiff.ni.dll
+ 2011-12-22 08:06 . 2011-12-22 08:06 882688 c:\windows\assembly\NativeImages_v2.0.50727_32\ToadCommon\0537e7cabe7b81bd29e23d9f6334dfc2\ToadCommon.ni.dll
+ 2011-12-22 08:03 . 2011-12-22 08:03 966144 c:\windows\assembly\NativeImages_v2.0.50727_32\ToadAutomation\3ff378e5ad13ca55966379a84bc259f5\ToadAutomation.ni.dll
+ 2011-12-22 08:13 . 2011-12-22 08:13 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\401e9800bf1b95e68b31f25e751f9c85\System.Xml.Linq.ni.dll
+ 2011-12-22 08:12 . 2011-12-22 08:12 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\d88973d973fd103a597b9936d24a05d8\System.Web.Routing.ni.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\6fd37eb8b2ab8806c1e60a85a4e76d4e\System.Web.RegularExpressions.ni.dll
+ 2011-12-22 08:12 . 2011-12-22 08:12 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\4ad656f4f97f8124715c3f9bb58ae4c8\System.Web.Extensions.Design.ni.dll
+ 2011-12-22 08:12 . 2011-12-22 08:12 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\6621282e48d917b5217f19f4205bc094\System.Web.Entity.ni.dll
+ 2011-12-22 08:12 . 2011-12-22 08:12 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\8b6d46b753fa504c52a4535dbeebd760\System.Web.Entity.Design.ni.dll
+ 2011-12-22 08:12 . 2011-12-22 08:12 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\5c2f899120708ff9bca1761183fff8cf\System.Web.DynamicData.ni.dll
+ 2011-12-22 08:12 . 2011-12-22 08:12 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\d0066da73f9d8625a62e9941fd4830b7\System.Web.Abstractions.ni.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\d1b833901e2b871cdfc6567a8835fcb2\System.Transactions.ni.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\b910614798234a4ef424e5c433a78880\System.ServiceProcess.ni.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\7c74f6789bf79f0a47ab266ec59e8ffb\System.Security.ni.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\b3635d10578820d6e2664948dbeb677c\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\acdd6a93dec265f43d85ce107026750b\System.Runtime.Remoting.ni.dll
+ 2011-12-22 08:12 . 2011-12-22 08:12 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\f44c3c9f1a164b5b82aa12abba44dd90\System.Net.ni.dll
+ 2011-12-22 08:02 . 2011-12-22 08:02 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\212f0dc1ff935933262254a5d17d6f68\System.Messaging.ni.dll
+ 2011-12-22 08:05 . 2011-12-22 08:05 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\3427720a1ee1f357e135d28782a4d2a0\System.Management.ni.dll
+ 2011-12-22 08:12 . 2011-12-22 08:12 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\a1afd0dc2656fc5fb9e6f7600c1c2f9e\System.Management.Instrumentation.ni.dll
+ 2011-12-22 08:07 . 2011-12-22 08:07 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\bd95642c76b184dfb56ca1f0e3312b15\System.IO.Log.ni.dll
+ 2011-12-22 08:07 . 2011-12-22 08:07 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\c68d12e897a9682187c5e8880e9afea0\System.IdentityModel.Selectors.ni.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\9b3fcdffec801eebdf406915bee81ca5\System.EnterpriseServices.Wrapper.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\9b3fcdffec801eebdf406915bee81ca5\System.EnterpriseServices.ni.dll
+ 2011-12-22 07:43 . 2011-12-22 07:43 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\c0a1c1820f1f201acb2800858b0b11be\System.Drawing.Design.ni.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\f95804d63cc64c6d3e9b42ea4fbc1acb\System.DirectoryServices.Protocols.ni.dll
+ 2011-12-22 08:12 . 2011-12-22 08:12 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\c42bb4f1dd0ada0d7c9d89c777214e60\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-12-22 08:12 . 2011-12-22 08:12 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\9690ab33436ff9caab5d53007793c7a2\System.Data.Services.Design.ni.dll
+ 2011-12-22 08:12 . 2011-12-22 08:12 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\6d8338e3a5c72ea6a59484ea8cea1e0c\System.Data.Services.Client.ni.dll
+ 2011-12-22 08:11 . 2011-12-22 08:11 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\3d8c4c5b6083b5eb1a36154df4e9dc11\System.Data.Entity.Design.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\9858abc214864c80575c12432432e806\System.Data.DataSetExtensions.ni.dll
+ 2011-12-22 08:00 . 2011-12-22 08:00 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\fe11b75bf8e05339d9c8491b29c1eb8e\System.Configuration.ni.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\4bd032def64cef58b84dc1dbf42f4036\System.Configuration.Install.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\7e9685891ab29f38264d649519167ae0\System.AddIn.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\dd106333d6092ec130c17b32fabc2c63\SMSvcHost.ni.exe
+ 2011-12-22 08:09 . 2011-12-22 08:09 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\2be1c8e1ebc21b5179dcb5ab132233c7\SMDiagnostics.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\bd79d4c0632779423387a5d67f5109d4\ServiceModelReg.ni.exe
+ 2011-12-22 08:06 . 2011-12-22 08:06 134144 c:\windows\assembly\NativeImages_v2.0.50727_32\Quest.JobManagement#\49a109dca2ac0f7c489bdfa3148eca15\Quest.JobManagement.UI.Plugin.ni.dll
+ 2011-12-22 07:40 . 2011-12-22 07:40 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\f71ea0868e890e31aa26dfc741f08ec4\PresentationFramework.Luna.ni.dll
+ 2011-12-22 07:40 . 2011-12-22 07:40 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\dff7534af203a23b625a6a240db4cf6a\PresentationFramework.Royale.ni.dll
+ 2011-12-22 07:40 . 2011-12-22 07:40 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\5ffd0e730c2c7e5348747fdb8d846be2\PresentationFramework.Classic.ni.dll
+ 2011-12-22 07:40 . 2011-12-22 07:40 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\48ced6b5edb4c1eb76862ad913b37904\PresentationFramework.Aero.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\1d8c007f5808d3ef2922540fbd54973d\MSBuild.ni.exe
+ 2011-12-22 08:00 . 2011-12-22 08:00 863744 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Web.Autho#\a611545a81f3d31365ebb052c763afb6\Microsoft.Web.Authoring.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\a5edf6c87567a63ccfe797b0168c32b9\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-12-22 08:02 . 2011-12-22 08:02 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\fc05a7acfc048ccc2761b32f3a47bb6e\Microsoft.Build.Utilities.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\16dde15b9524001425e9cc934ea284f6\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\80953b78edbca597967ddef4e2c9e764\Microsoft.Build.Engine.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\61aaaa178877493b8490db807f8dfb6f\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2011-12-22 08:04 . 2011-12-22 08:04 879104 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraNavB#\874b4946c87302eccd4c6ed4d8a823f4\DevExpress.XtraNavBar.v8.3.ni.dll
+ 2011-12-22 08:05 . 2011-12-22 08:05 453120 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.Charts.v#\8e6c9c74c74454da1b202a62b54c0579\DevExpress.Charts.v8.3.Core.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\feb39883de6ede97417c527cd49e5bbf\CustomMarshalers.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\ab90f4c5ecc7c534cc2a5fd22ae71e23\ComSvcConfig.ni.exe
+ 2011-12-22 08:00 . 2011-12-22 08:00 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\83eb876f705a0d4b01d0268c723d04de\AspNetMMCExt.ni.dll
+ 2011-12-22 08:05 . 2011-12-22 08:05 574976 c:\windows\assembly\NativeImages_v2.0.50727_32\ActiproSoftware.Win#\615092e04febaae472891a6d57883fcf\ActiproSoftware.WinUICore.Net20.ni.dll
+ 2011-12-22 08:05 . 2011-12-22 08:05 781824 c:\windows\assembly\NativeImages_v2.0.50727_32\ActiproSoftware.Sha#\d79620c195779464ae0909dc3e6a99c7\ActiproSoftware.Shared.Net20.ni.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2010-10-18 09:43 . 2010-10-18 09:43 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2011-12-22 07:36 . 2011-12-22 07:36 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-12-22 07:36 . 2011-12-22 07:36 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2011-12-22 07:36 . 2011-12-22 07:36 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2011-12-22 07:36 . 2011-12-22 07:36 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2011-12-22 07:36 . 2011-12-22 07:36 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2011-12-22 07:36 . 2011-12-22 07:36 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2010-10-18 09:43 . 2010-10-18 09:43 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-12-22 07:29 . 2011-12-22 07:29 350080 c:\windows\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 3781960 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90u.dll
+ 2011-04-19 06:51 . 2011-04-19 06:51 3766600 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90.dll
+ 2011-05-14 04:04 . 2011-05-14 04:04 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfc80u.dll
+ 2011-05-14 04:04 . 2011-05-14 04:04 1101824 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfc80.dll
+ 2006-03-16 04:00 . 2011-11-04 19:20 1212416 c:\windows\system32\urlmon.dll
- 2006-03-16 04:00 . 2011-08-22 23:48 1212416 c:\windows\system32\urlmon.dll
+ 2006-03-16 04:00 . 2011-11-04 19:20 5978112 c:\windows\system32\mshtml.dll
- 2009-03-07 23:02 . 2011-08-22 23:48 2000384 c:\windows\system32\iertutil.dll
+ 2009-03-07 23:02 . 2011-11-04 19:20 2000384 c:\windows\system32\iertutil.dll
+ 2006-06-29 18:18 . 2011-12-22 07:47 1689328 c:\windows\system32\FNTCACHE.DAT
- 2006-06-29 18:18 . 2011-11-02 16:51 1689328 c:\windows\system32\FNTCACHE.DAT
+ 2009-02-09 11:13 . 2011-11-23 13:25 1859584 c:\windows\system32\dllcache\win32k.sys
+ 2009-03-15 23:57 . 2011-11-04 19:20 1212416 c:\windows\system32\dllcache\urlmon.dll
- 2009-03-15 23:57 . 2011-08-22 23:48 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2010-07-16 12:05 . 2011-11-01 16:07 1288704 c:\windows\system32\dllcache\ole32.dll
- 2009-06-03 04:48 . 2010-12-09 13:38 2192768 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2009-06-03 04:48 . 2011-10-25 13:33 2192768 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2009-06-03 04:48 . 2011-10-25 12:52 2027008 c:\windows\system32\dllcache\ntkrpamp.exe
- 2009-06-03 04:48 . 2010-12-09 13:07 2027008 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-02-07 13:32 . 2011-10-25 12:52 2069376 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2009-02-07 13:32 . 2010-12-09 13:07 2069376 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2009-06-03 04:48 . 2010-12-09 13:42 2148864 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2009-06-03 04:48 . 2011-10-25 13:37 2148864 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2009-03-15 23:57 . 2011-11-04 19:20 5978112 c:\windows\system32\dllcache\mshtml.dll
- 2009-08-27 16:33 . 2011-08-22 23:48 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2009-08-27 16:33 . 2011-11-04 19:20 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2011-07-07 13:18 . 2011-07-07 13:18 5912400 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2011-07-07 13:18 . 2011-07-07 13:18 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
- 2010-05-11 01:10 . 2010-05-11 01:10 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2011-07-08 21:59 . 2011-07-08 21:59 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2010-09-23 10:25 . 2010-09-23 10:25 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2010-09-23 10:25 . 2010-09-23 10:25 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2011-07-08 21:59 . 2011-07-08 21:59 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2011-07-07 20:02 . 2011-07-07 20:02 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
- 2010-09-22 20:56 . 2010-09-22 20:56 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2011-07-07 20:02 . 2011-07-07 20:02 2527232 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
- 2010-09-23 10:25 . 2010-09-23 10:25 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2011-07-08 21:59 . 2011-07-08 21:59 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2011-04-29 20:28 . 2011-04-29 20:28 1995264 c:\windows\Installer\fc6ce.msp
+ 2011-09-07 05:46 . 2011-09-07 05:46 9006080 c:\windows\Installer\fc6b8.msp
+ 2011-06-21 19:59 . 2011-06-21 19:59 1764352 c:\windows\Installer\543f5.msp
+ 2011-08-11 01:42 . 2011-08-11 01:42 7070208 c:\windows\Installer\543c2.msp
+ 2011-04-29 20:27 . 2011-04-29 20:27 4158464 c:\windows\Installer\543b4.msp
+ 2011-09-22 00:18 . 2011-09-22 00:18 4985856 c:\windows\Installer\5439b.msp
+ 2011-09-07 05:48 . 2011-09-07 05:48 8181248 c:\windows\Installer\54383.msp
+ 2011-07-27 15:39 . 2011-07-27 15:39 9892352 c:\windows\Installer\5432f.msp
+ 2010-11-21 07:33 . 2010-11-21 07:33 1980928 c:\windows\Installer\54321.msp
+ 2011-08-11 01:43 . 2011-08-11 01:43 3795968 c:\windows\Installer\15d8ca0.msp
+ 2011-11-01 21:34 . 2011-11-01 21:34 4250112 c:\windows\Installer\15d8c86.msp
+ 2011-04-29 20:28 . 2011-04-29 20:28 1995264 c:\windows\Installer\15d8c56.msp
+ 2011-06-21 19:59 . 2011-06-21 19:59 1764352 c:\windows\Installer\15d8c40.msp
+ 2011-08-11 01:42 . 2011-08-11 01:42 7070208 c:\windows\Installer\15d8c0d.msp
+ 2011-09-22 00:18 . 2011-09-22 00:18 4985856 c:\windows\Installer\15d8bff.msp
+ 2011-11-01 21:34 . 2011-11-01 21:34 2247168 c:\windows\Installer\15d8be8.msp
+ 2011-11-12 00:14 . 2011-11-12 00:14 9096192 c:\windows\Installer\15d8bd0.msp
+ 2011-11-01 21:34 . 2011-11-01 21:34 4225536 c:\windows\Installer\15d8bb8.msp
+ 2011-11-01 21:34 . 2011-11-01 21:34 2531840 c:\windows\Installer\15d8b85.msp
+ 2011-11-12 00:15 . 2011-11-12 00:15 1795584 c:\windows\Installer\15d8b51.msp
+ 2011-07-27 15:39 . 2011-07-27 15:39 9892352 c:\windows\Installer\15d8b23.msp
+ 2011-11-12 00:16 . 2011-11-12 00:16 8458240 c:\windows\Installer\15d8b08.msp
- 2009-03-17 05:28 . 2010-12-19 17:31 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-03-17 05:28 . 2011-12-22 07:39 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-03-17 05:28 . 2010-12-19 17:31 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-03-17 05:28 . 2011-12-22 07:39 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2007-10-02 14:21 . 2007-10-02 14:21 8436776 c:\windows\Installer\$PatchCache$\Managed\00002109620000000000000000F01FEC\12.0.6215\OARTCONV.DLL
+ 2009-04-03 12:51 . 2009-04-03 12:51 8543096 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\OARTCONV.DLL
+ 2009-02-14 00:33 . 2009-02-14 00:33 3070832 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\GROOVEDOCUMENTSHARETOOL.DLL
+ 2009-04-02 16:14 . 2009-04-02 16:14 2532224 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\GRAPH.EXE
+ 2011-12-22 07:20 . 2011-08-22 23:48 1212416 c:\windows\ie8updates\KB2618444-IE8\urlmon.dll
+ 2011-12-22 07:20 . 2011-10-03 08:35 5971456 c:\windows\ie8updates\KB2618444-IE8\mshtml.dll
+ 2011-12-22 07:20 . 2011-08-22 23:48 2000384 c:\windows\ie8updates\KB2618444-IE8\iertutil.dll
+ 2009-06-03 04:48 . 2011-10-25 13:33 2192768 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2009-06-03 04:48 . 2010-12-09 13:38 2192768 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2009-06-03 04:48 . 2011-10-25 12:52 2027008 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2009-06-03 04:48 . 2010-12-09 13:07 2027008 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2009-02-07 13:32 . 2010-12-09 13:07 2069376 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-02-07 13:32 . 2011-10-25 12:52 2069376 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2009-06-03 04:48 . 2010-12-09 13:42 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2009-06-03 04:48 . 2011-10-25 13:37 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2011-12-22 07:03 . 2011-12-22 07:03 4792320 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_cbad8678\System.dll
+ 2011-12-22 07:02 . 2011-12-22 07:02 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_43e6b8b0\System.dll
+ 2011-12-22 07:03 . 2011-12-22 07:03 5513216 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_ed0fe5e7\System.Xml.dll
+ 2011-12-22 07:03 . 2011-12-22 07:03 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_82cf5a97\System.Xml.dll
+ 2011-12-22 07:03 . 2011-12-22 07:03 7884800 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_6fbb6808\System.Windows.Forms.dll
+ 2011-12-22 07:03 . 2011-12-22 07:03 3018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_258319b8\System.Windows.Forms.dll
+ 2011-12-22 07:03 . 2011-12-22 07:04 2244608 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_eb2262ee\System.Drawing.dll
+ 2011-12-22 07:03 . 2011-12-22 07:03 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_93e9c1a3\System.Design.dll
+ 2011-12-22 07:03 . 2011-12-22 07:03 3395584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_404e2e33\System.Design.dll
+ 2011-12-22 07:03 . 2011-12-22 07:03 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_4fdc5e90\mscorlib.dll
+ 2011-12-22 07:04 . 2011-12-22 07:04 8908800 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_0bfe2770\mscorlib.dll
+ 2011-12-22 07:38 . 2011-12-22 07:38 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\4c09d11ef6028a34ec8e21554cf763f8\WindowsBase.ni.dll
+ 2011-12-22 07:51 . 2011-12-22 07:51 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\8b7b26a2692718927498ce4f12d6851a\UIAutomationClientsideProviders.ni.dll
+ 2011-12-22 07:44 . 2011-12-22 07:44 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP65A.tmp\System.Printing.dll
+ 2011-12-22 07:38 . 2011-12-22 07:38 7949824 c:\windows\assembly\NativeImages_v2.0.50727_32\System\bfbc0aa08e3e2835bc93a4ab18e61d33\System.ni.dll
+ 2011-12-22 07:50 . 2011-12-22 07:50 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b0481a38064c7799197b94892fa259ee\System.Xml.ni.dll
+ 2011-12-22 08:13 . 2011-12-22 08:13 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\1416ebd7bd12fb73d2db485dac46a14f\System.WorkflowServices.ni.dll
+ 2011-12-22 08:02 . 2011-12-22 08:02 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\58c5e43c797d11b0e7ae8a21251c5eab\System.Workflow.Runtime.ni.dll
+ 2011-12-22 08:02 . 2011-12-22 08:02 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\b639159b9420858cc40238d7d520153d\System.Workflow.ComponentModel.ni.dll
+ 2011-12-22 08:02 . 2011-12-22 08:02 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\c9d06393718fd2ae9f77debffa5e13ab\System.Workflow.Activities.ni.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\b41c0720e577c070fa8a07da08024b8f\System.Web.Services.ni.dll
+ 2011-12-22 08:02 . 2011-12-22 08:02 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\2993090b16014cc2ef2e46a1e8ab1121\System.Web.Mobile.ni.dll
+ 2011-12-22 08:12 . 2011-12-22 08:12 2405376 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\8164a845538b5d57641584d10217a937\System.Web.Extensions.ni.dll
+ 2011-12-22 07:47 . 2011-12-22 07:47 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\2b9fc95fd3ccb74c3bd4d759992b6174\System.Speech.ni.dll
+ 2011-12-22 08:12 . 2011-12-22 08:12 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\05f115324ed6672ff737f45a9ae328bd\System.ServiceModel.Web.ni.dll
+ 2011-12-22 08:07 . 2011-12-22 08:07 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\6815327bf5e5a7e11f678c5d920daecd\System.Runtime.Serialization.ni.dll
+ 2011-12-22 07:47 . 2011-12-22 07:47 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\697da031f0d9086b667d15da3b680eec\System.Printing.ni.dll
+ 2011-12-22 08:07 . 2011-12-22 08:07 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\6f3dcda1d8ceeafa4a96daf1cdc0874c\System.IdentityModel.ni.dll
+ 2011-12-22 07:43 . 2011-12-22 07:43 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\b5ca66105fc2a6a480e97c2a1d9a07cb\System.Drawing.ni.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\7e1fb1f48981a27939e05d8d41973255\System.DirectoryServices.ni.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\5987b2162181b11807dbe0bb58846318\System.Deployment.ni.dll
+ 2011-12-22 07:42 . 2011-12-22 07:42 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\4bfc76600b84064b9da9b8472447a76a\System.Data.ni.dll
+ 2011-12-22 08:00 . 2011-12-22 08:00 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\cdf371320ae729d24fce6ace54d8686f\System.Data.SqlXml.ni.dll
+ 2011-12-22 08:12 . 2011-12-22 08:12 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\40a21b18a5f23ff710e3bd2f21c47e04\System.Data.Services.ni.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 1115136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\b573f9335e9efa33f518f64e3e012723\System.Data.OracleClient.ni.dll
+ 2011-12-22 07:42 . 2011-12-22 07:42 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\7511fba46daaf136f4530469021b5d31\System.Data.Linq.ni.dll
+ 2011-12-22 08:11 . 2011-12-22 08:11 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\602c3b0d924a9d44f47462feb5b165e7\System.Data.Entity.ni.dll
+ 2011-12-22 07:41 . 2011-12-22 07:41 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\7ff66bb01428a93daa0153c04ce172a3\System.Core.ni.dll
+ 2011-12-22 07:41 . 2011-12-22 07:41 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\631044a366eaeb034f67d6b37f9271d5\ReachFramework.ni.dll
+ 2011-12-22 07:40 . 2011-12-22 07:41 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\4c14f4e3adc2f4ec9e6007f9d60741d4\PresentationUI.ni.dll
+ 2011-12-22 07:38 . 2011-12-22 07:38 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\72257bb09d2c4682185de80d5fba88a7\PresentationBuildTasks.ni.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 1602048 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Web.Desig#\0e63fad86a4799b726e7a684080ab1a1\Microsoft.Web.Design.Client.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\ce98f0bb848834053109c2e1d19c8275\Microsoft.VisualBasic.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\aad708e53cfccc80d893fb3bc0f713f6\Microsoft.Transactions.Bridge.ni.dll
+ 2011-12-22 08:05 . 2011-12-22 08:05 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\d577d258b4bef604f3d7946708d682be\Microsoft.JScript.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\ca359b7c568c553d06714df1cdedc96f\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2011-12-22 08:02 . 2011-12-22 08:02 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\6a022d7e94ff082a59d68039495f0bab\Microsoft.Build.Tasks.ni.dll
+ 2011-12-22 08:09 . 2011-12-22 08:09 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\59e7ddfd87ce61aeeef68b55aec7336d\Microsoft.Build.Engine.ni.dll
+ 2011-12-22 08:05 . 2011-12-22 08:05 1757696 c:\windows\assembly\NativeImages_v2.0.50727_32\MailBee.NET\13b5d8a62dd939d52b832efbf071889e\MailBee.NET.ni.dll
+ 2011-12-22 08:03 . 2011-12-22 08:03 1177088 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraVert#\4f33c5d2b926855051801b294f971fdd\DevExpress.XtraVerticalGrid.v8.3.ni.dll
+ 2011-12-22 08:04 . 2011-12-22 08:04 1487872 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraTree#\b6d794531c2e258b19556b3084b6abbb\DevExpress.XtraTreeList.v8.3.ni.dll
+ 2011-12-22 08:04 . 2011-12-22 08:04 6637568 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraRich#\918066a03bf4cd3f0db907444a0f7cc9\DevExpress.XtraRichEdit.v8.3.ni.dll
+ 2011-12-22 08:03 . 2011-12-22 08:03 6495744 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraRepo#\5df687443d8470ef8699540efd211ad6\DevExpress.XtraReports.v8.3.ni.dll
+ 2011-12-22 08:04 . 2011-12-22 08:04 4459008 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraPrin#\518a20a38e718a95d0832577797e760f\DevExpress.XtraPrinting.v8.3.ni.dll
+ 2011-12-22 08:04 . 2011-12-22 08:04 1084416 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraPivo#\c9e9e4a94402eb9743c63540a774b4ea\DevExpress.XtraPivotGrid.v8.3.ni.dll
+ 2011-12-22 08:04 . 2011-12-22 08:04 1388544 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraPivo#\5750aa8c341c97b46f2f4734f3d866d0\DevExpress.XtraPivotGrid.v8.3.Core.ni.dll
+ 2011-12-22 08:06 . 2011-12-22 08:06 1994240 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraLayo#\1598e29425e10978f83124059b75c148\DevExpress.XtraLayout.v8.3.ni.dll
+ 2011-12-22 08:06 . 2011-12-22 08:06 4532224 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraGrid#\bad8a6cded3b1fa36fd502569420e0c9\DevExpress.XtraGrid.v8.3.ni.dll
+ 2011-12-22 08:03 . 2011-12-22 08:03 4737536 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraEdit#\48b545d36ef69c1b5d97a79f4abd8a5b\DevExpress.XtraEditors.v8.3.ni.dll
+ 2011-12-22 08:04 . 2011-12-22 08:04 5067776 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraBars#\49fd50b247308a9eb4f1d85128ba192d\DevExpress.XtraBars.v8.3.ni.dll
+ 2011-12-22 08:03 . 2011-12-22 08:03 6646272 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.Utils.v8#\366339491b337514c8b1eb5a4c72ece4\DevExpress.Utils.v8.3.ni.dll
+ 2011-12-22 08:03 . 2011-12-22 08:03 2352640 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.Data.v8.3\4cebf721d3e3e51339914fb0ae004253\DevExpress.Data.v8.3.ni.dll
+ 2011-12-22 08:05 . 2011-12-22 08:05 2073088 c:\windows\assembly\NativeImages_v2.0.50727_32\ActiproSoftware.UIS#\805647ca8a0998099ffc5b50b6f083a5\ActiproSoftware.UIStudio.Dock.Net20.ni.dll
+ 2011-12-22 08:06 . 2011-12-22 08:06 3555328 c:\windows\assembly\NativeImages_v2.0.50727_32\ActiproSoftware.Syn#\749417907f6843ebeee91ce19cc896c0\ActiproSoftware.SyntaxEditor.Net20.ni.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2011-12-22 07:36 . 2011-12-22 07:36 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2011-12-22 07:36 . 2011-12-22 07:36 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2010-10-18 09:43 . 2010-10-18 09:43 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2010-10-18 09:43 . 2010-10-18 09:43 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
- 2010-10-18 09:43 . 2010-10-18 09:43 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-12-22 07:36 . 2011-12-22 07:36 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2010-10-18 09:44 . 2010-10-18 09:44 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-12-22 07:35 . 2011-12-22 07:35 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-12-22 07:02 . 2011-12-22 07:02 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2010-10-18 09:10 . 2010-10-18 09:10 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2010-10-18 09:10 . 2010-10-18 09:10 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-12-22 07:02 . 2011-12-22 07:02 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-03-18 15:16 . 2011-12-07 19:44 52988224 c:\windows\system32\MRT.exe
- 2009-03-07 23:09 . 2011-08-23 12:18 11081728 c:\windows\system32\ieframe.dll
+ 2009-03-07 23:09 . 2011-11-04 19:20 11081728 c:\windows\system32\ieframe.dll
- 2009-08-27 16:33 . 2011-08-23 12:18 11081728 c:\windows\system32\dllcache\ieframe.dll
+ 2009-08-27 16:33 . 2011-11-04 19:20 11081728 c:\windows\system32\dllcache\ieframe.dll
+ 2011-07-13 06:49 . 2011-07-13 06:49 11459584 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2572067\M2572067Uninstall.msp
+ 2011-07-27 15:37 . 2011-07-27 15:37 11592192 c:\windows\Installer\5436b.msp
+ 2011-07-12 04:43 . 2011-07-12 04:43 11641344 c:\windows\Installer\15d8c92.msp
+ 2011-07-27 15:37 . 2011-07-27 15:37 11592192 c:\windows\Installer\15d8b77.msp
+ 2011-07-12 23:50 . 2011-07-12 23:50 17555968 c:\windows\Installer\15d8af1.msp
+ 2007-10-05 15:14 . 2007-10-05 15:14 14168600 c:\windows\Installer\$PatchCache$\Managed\00002109620000000000000000F01FEC\12.0.6215\OART.DLL
+ 2006-10-27 23:26 . 2006-10-27 23:26 16870712 c:\windows\Installer\$PatchCache$\Managed\00002109620000000000000000F01FEC\12.0.4518\MSO.DLL
+ 2009-04-03 12:51 . 2009-04-03 12:51 16037736 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\OART.DLL
+ 2011-12-22 07:20 . 2011-08-23 12:18 11081728 c:\windows\ie8updates\KB2618444-IE8\ieframe.dll
+ 2011-12-22 07:48 . 2011-12-22 07:48 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\78dc9fa85f4ca5c0b3317f297914748b\System.Windows.Forms.ni.dll
+ 2011-12-22 08:01 . 2011-12-22 08:01 11800576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\9c4c3994c9674c247e1ea624d2cd3e34\System.Web.ni.dll
+ 2011-12-22 08:08 . 2011-12-22 08:08 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\0e4723bd3a0448672dcf77733bdac49a\System.ServiceModel.ni.dll
+ 2011-12-22 07:43 . 2011-12-22 07:43 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\c807faafb3e05f0f2c0fbccb1a22782c\System.Design.ni.dll
+ 2011-12-22 07:40 . 2011-12-22 07:40 14328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2641fe32630772739fbdfdac13e3caab\PresentationFramework.ni.dll
+ 2011-12-22 07:39 . 2011-12-22 07:39 12215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\9c04bbe619924a9ae6404f6e3eb45cf5\PresentationCore.ni.dll
+ 2011-12-22 07:37 . 2011-12-22 07:37 11490816 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\44ecf972f11f3c238782da31f27df7e5\mscorlib.ni.dll
+ 2011-12-22 08:05 . 2011-12-22 08:05 12172800 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraChar#\6c303f48ad2859da633e128468551cea\DevExpress.XtraCharts.v8.3.ni.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2011-05-09 09:49 176936 —-a-w- c:\program files\uTorrentBar\prxtbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2007-07-28 1360304]
"Registry Cleaner Scheduler"="c:\program files\CleanMyPC\Registry Cleaner\RCHelper.exe" [2011-10-06 1401224]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"MsmqIntCert"="mqrt.dll" [2008-04-14 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-23 61952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-17 794713]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-26 7561216]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2011-06-23 1407248]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-06-23 1210640]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-08-03 53096]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2009-09-01 125368]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-12 581693]
HP Pavilion Webcam Tray Icon.lnk - c:\program files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe [2009-11-2 102400]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,32,\
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NecUsb3Sevice]
2006-02-10 09:05 37888 —-a-w- c:\windows\system32\USB3Nw32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\USB3Nw32]
2006-02-10 09:05 37888 —-a-w- c:\windows\system32\USB3Nw32.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor Apache Servers.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Monitor Apache Servers.lnk
backup=c:\windows\pss\Monitor Apache Servers.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Pankaj^Start Menu^Programs^StartUp^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Pankaj\Start Menu\Programs\StartUp\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Pankaj^Start Menu^Programs^StartUp^OneNote Table Of Contents.onetoc2]
path=c:\documents and settings\Pankaj\Start Menu\Programs\StartUp\OneNote Table Of Contents.onetoc2
backup=c:\windows\pss\OneNote Table Of Contents.onetoc2Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 20:55 937920 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim]
2011-05-03 15:43 4321112 —-a-w- c:\program files\AIM\aim.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\autoMe]
2008-05-08 11:24 155648 —-a-w- c:\windows\system32\wscript.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2011-12-02 06:37 137536 —-atw- c:\documents and settings\Pankaj\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-03-22 15:31 133104 —-atw- c:\documents and settings\Pankaj\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 06:14 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-16 15:11 49152 -c–a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
2006-03-15 20:00 44032 —-a-w- c:\windows\ime\imkr6_1\imekrmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2006-03-15 20:00 208952 —-a-w- c:\windows\ime\imjp8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-08 15:39 305440 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Memeo Instant Backup]
2010-04-23 00:33 136416 —-a-w- c:\program files\Memeo\AutoBackup\MemeoLauncher2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
2006-03-15 20:00 59392 —-a-w- c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-04-26 19:48 7561216 —-a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-04-26 19:48 1519616 -c–a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2006-03-15 20:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2006-03-15 20:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
2006-06-19 03:33 163840 —-a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2006-07-11 13:55 102400 -c–a-w- c:\program files\HP\QuickPlay\QPService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 20:24 417792 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecGuard]
2005-10-11 02:23 1187840 —-a-w- c:\windows\SMINST\Recguard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Seagate Dashboard]
2010-04-30 14:47 79112 —-a-w- c:\program files\Seagate\Seagate Dashboard\MemeoLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2007-06-13 02:46 528384 -c–a-r- c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 06:14 248552 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-11-25 05:31 642424 —-a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2006-10-18 15:35 204288 ——w- c:\program files\Windows Media Player\wmpnscfg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=2 (0x2)
"Tomcat5"=3 (0x3)
"OracleServiceORACLE9I"=2 (0x2)
"OracleOraHome92TNSListener"=2 (0x2)
"OracleOraHome92SNMPPeerMasterAgent"=3 (0x3)
"OracleOraHome92SNMPPeerEncapsulator"=3 (0x3)
"OracleOraHome92PagingServer"=3 (0x3)
"OracleOraHome92HTTPServer"=2 (0x2)
"OracleOraHome92ClientCache"=3 (0x3)
"OracleOraHome92Agent"=2 (0x2)
"OracleMTSRecoveryService"=2 (0x2)
"gusvc"=2 (0x2)
"gupdate1c9c5eed03863b2"=2 (0x2)
"MySQL"=2 (0x2)
"iPod Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"Apache2.2"=2 (0x2)
"VC7SecS"=2 (0x2)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"FirebirdServerDefaultInstance"=3 (0x3)
"FirebirdGuardianDefaultInstance"=2 (0x2)
"SeagateDashboardService"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"MemeoBackgroundService"=2 (0x2)
"LightScribeService"=2 (0x2)
"hpqwmiex"=2 (0x2)
"gupdatem"=3 (0x3)
"AddFiltr"=3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\Pankaj\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Pankaj\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"\\??\\c:\\WINDOWS\\system32\\winlogon.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Pankaj\\Local Settings\\Application Data\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"60006:TCP"= 60006:TCP:Bitcomet 60006 TCP
"60006:UDP"= 60006:UDP:Bitcomet 60006 UDP
"3306:TCP"= 3306:TCP:MySQL Server
"60000:TCP"= 60000:TCP:BitComet 60000 TCP
"60000:UDP"= 60000:UDP:BitComet 60000 UDP
.
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [12/8/2011 9:33 PM 106104]
R3 NETwLx32; Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [11/27/2011 7:27 PM 6609920]
S1 vdrv7000;vdrv7000;c:\windows\system32\DRIVERS\vdrv7000.sys –> c:\windows\system32\DRIVERS\vdrv7000.sys [?]
S2 NecUsb;USB Service;c:\windows\System32\svchost.exe -k NecUsbSevice [3/15/2006 8:00 PM 14336]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 PROCEXP150;PROCEXP150;\??\c:\windows\system32\Drivers\PROCEXP150.SYS –> c:\windows\system32\Drivers\PROCEXP150.SYS [?]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\drivers\s115bus.sys [3/22/2009 1:24 AM 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\drivers\s115mdfl.sys [3/22/2009 1:24 AM 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\drivers\s115mdm.sys [3/22/2009 1:24 AM 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s115mgmt.sys [3/22/2009 1:25 AM 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\drivers\s115obex.sys [3/22/2009 1:25 AM 98568]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [9/1/2009 1:15 PM 116664]
S4 Apache2.2;Apache2.2;c:\program files\Apache Software Foundation\Apache2.2\bin\httpd.exe [9/28/2009 9:11 AM 24645]
S4 gupdate1c9c5eed03863b2;Google Update Service (gupdate1c9c5eed03863b2);c:\program files\Google\Update\GoogleUpdate.exe [4/25/2009 1:43 PM 133104]
S4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/25/2009 1:43 PM 133104]
S4 MemeoBackgroundService;MemeoBackgroundService;c:\program files\Memeo\AutoBackup\MemeoBackgroundService.exe [4/22/2010 4:33 PM 25824]
S4 OracleServiceORACLE9I;OracleServiceORACLE9I;c:\oracle\ora92\bin\ORACLE.EXE ORACLE9I –> c:\oracle\ora92\bin\ORACLE.EXE ORACLE9I [?]
S4 SeagateDashboardService;Seagate Dashboard Service;c:\program files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [4/30/2010 6:47 AM 14088]
S4 Tomcat5;Apache Tomcat;c:\program files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe [8/28/2008 7:12 PM 57344]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
NecUsbSevice REG_MULTI_SZ NecUsb
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3641525057-1712457974-3760122168-1005Core.job
- c:\documents and settings\Pankaj\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-12-02 06:37]
.
2011-12-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3641525057-1712457974-3760122168-1005UA.job
- c:\documents and settings\Pankaj\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-12-02 06:37]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.Google.com
mStart Page = hxxp://www.Google.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Send To &Bluetooth; - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/search/search?query={searchTerms}&invocationType;=tb50-ff-aim-chromesbox-en-us
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com/?src=aim&ncid;=snsusaimc00000001
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: SearchPreview: {EF522540-89F5-46b9-B6FE-1829E2B572C6} - %profile%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-Skype - c:\documents and settings\Pankaj\Desktop\Skype.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-22 18:37
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OracleOraHome92TNSListener]
"ImagePath"="c:\oracle\ora92\BIN\TNSLSNR "
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(940)
c:\windows\system32\USB3Nw32.dll
.
Completion time: 2011-12-22 18:40:42
ComboFix-quarantined-files.txt 2011-12-23 02:40
ComboFix2.txt 2011-12-21 06:52
.
Pre-Run: 26,400,690,176 bytes free
Post-Run: 26,393,415,680 bytes free
.
- - End Of File - - 2621E3A96318204A93FB5F1999DFE2F9



OTL log Results:

OTL.txt:



OTL logfile created on: 12/22/2011 7:08:42 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Pankaj\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.04 Mb Total Physical Memory | 471.24 Mb Available Physical Memory | 46.11% Memory free
2.40 Gb Paging File | 1.90 Gb Available in Paging File | 79.28% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 59.45 Gb Total Space | 24.61 Gb Free Space | 41.40% Space Free | Partition Type: NTFS
Drive D: | 11.19 Gb Total Space | 1.20 Gb Free Space | 10.69% Space Free | Partition Type: FAT32
Drive F: | 21.49 Gb Total Space | 0.53 Gb Free Space | 2.44% Space Free | Partition Type: NTFS

Computer Name: PC187869777259 | User Name: Pankaj | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Pankaj\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\CleanMyPC\Registry Cleaner\RCHelper.exe (CleanMyPC Software)
PRC - C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Program Files\AIM\aim.exe (AOL Inc.)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe ()
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\HPQ\Shared\HpqToaster.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files\AIM\nssckbi.dll ()
MOD - C:\WINDOWS\system32\sbe.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\pdf995mon.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe ()
MOD - C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll ()
MOD - C:\WINDOWS\system32\USB3Nw32.dll ()
MOD - C:\Program Files\HPQ\Shared\HpqToaster.exe ()


========== Win32 Services (SafeList) ==========

SRV - (OracleServiceORACLE9I) – File not found
SRV - (OracleOraHome92TNSListener) – File not found
SRV - (NecUsb) – File not found
SRV - (HidServ) – File not found
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (SeagateDashboardService) – C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe (Memeo)
SRV - (MemeoBackgroundService) – C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe (Memeo)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (Tomcat5) – C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe (Apache Software Foundation)
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (AddFiltr) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe (Hewlett-Packard Development Company, L.P.)


========== Driver Services (SafeList) ==========

DRV - (catchme) – File not found
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111216.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111216.002\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NETwLx32) Intel® – C:\WINDOWS\system32\drivers\NETwLx32.sys (Intel Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (RMCAST) – C:\WINDOWS\system32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (MQAC) – C:\WINDOWS\system32\drivers\mqac.sys (Microsoft Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (s115mgmt) Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s115mgmt.sys (MCCI Corporation)
DRV - (s115obex) – C:\WINDOWS\system32\drivers\s115obex.sys (MCCI Corporation)
DRV - (s115mdm) – C:\WINDOWS\system32\drivers\s115mdm.sys (MCCI Corporation)
DRV - (s115mdfl) – C:\WINDOWS\system32\drivers\s115mdfl.sys (MCCI Corporation)
DRV - (s115bus) Sony Ericsson Device 115 driver (WDM) – C:\WINDOWS\system32\drivers\s115bus.sys (MCCI Corporation)
DRV - (StMp3Rec) – C:\WINDOWS\system32\drivers\StMp3Rec.sys (Generic)
DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\WINDOWS\system32\drivers\snp2uvc.sys ()
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\CHDAud.sys (Conexant Systems Inc.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (eabusb) – C:\WINDOWS\system32\drivers\EabUsb.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HBtnKey) – C:\WINDOWS\system32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (eabfiltr) – C:\WINDOWS\system32\drivers\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (PQNTDrv) – C:\WINDOWS\System32\drivers\PQNTDRV.sys (PowerQuest Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.Google.com
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.Google.com
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/search/search?query={searchTerms}&invocationType;=tb50-ff-aim-chromesbox-en-us"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.aol.com/?src=aim&ncid;=snsusaimc00000001"
FF - prefs.js..extensions.enabledItems: {EF522540-89F5-46b9-B6FE-1829E2B572C6}:4.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.8.0.8


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\Pankaj\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Pankaj\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Pankaj\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/20 17:39:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/20 17:39:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2009/11/20 20:24:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Documents and Settings\Pankaj\Application Data\IDM\idmmzcc2 [2009/03/20 08:57:44 | 000,000,000 | —D | M]

[2009/03/16 09:12:51 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Extensions
[2009/06/02 19:25:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Pankaj\Application Data\Mozilla\eclipse1\extensions
[2011/12/22 13:20:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\extensions
[2009/10/12 08:33:41 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/05 20:40:26 | 000,000,000 | —D | M] ("Delicious Bookmarks") – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\extensions\{2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}
[2010/01/23 11:14:27 | 000,000,000 | —D | M] (Dust-Me Selectors) – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\extensions\{3c6e1eed-a07e-4c80-9cf3-66ea0bf40b37}
[2010/04/02 13:24:56 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2009/12/10 07:47:25 | 000,000,000 | —D | M] ("StumbleUpon") – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2011/11/24 21:32:04 | 000,000,000 | —D | M] (uTorrentBar Community Toolbar) – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/11/29 13:00:04 | 000,000,000 | —D | M] (AOL Messaging Toolbar) – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
[2010/04/11 00:04:21 | 000,000,000 | —D | M] (OnlyWire) – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\extensions\{e26ba8db-a646-a44e-997c-2fafeadb50f2}
[2010/01/04 19:28:51 | 000,000,000 | —D | M] (Page Speed) – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}
[2009/12/05 09:23:27 | 000,000,000 | —D | M] (SearchPreview) – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
[2010/01/14 06:06:49 | 000,000,000 | —D | M] (Firebug) – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\extensions\[removed]
[2010/01/14 05:56:29 | 000,000,000 | —D | M] (YSlow) – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\extensions\[removed]
[2009/12/09 07:38:25 | 000,004,554 | —- | M] () – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\searchplugins\aim-search.xml
[2011/12/19 10:39:44 | 000,002,289 | —- | M] () – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\searchplugins\alexa.xml
[2011/11/29 12:59:02 | 000,002,242 | —- | M] () – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\searchplugins\AOL Search.xml
[2010/04/11 05:06:24 | 000,002,105 | —- | M] () – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\searchplugins\digg.xml
[2010/03/26 08:44:29 | 000,001,330 | —- | M] () – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\searchplugins\ezinearticles.xml
[2010/02/03 07:59:58 | 000,003,994 | —- | M] () – C:\Documents and Settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\searchplugins\similar-sites.xml
[2011/12/22 13:20:21 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/09/06 07:56:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/24 10:35:24 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2009/07/17 00:40:12 | 000,704,512 | —- | M] (BitComet) – C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll
[2010/09/14 15:20:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/29 12:59:02 | 000,002,242 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\AOL Search.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.4 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.4 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.4 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.4 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.4 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.4 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.4 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\Pankaj\Application Data\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\Pankaj\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: BitCometAgent (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
CHR - plugin: downloadUpdater (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnu.dll
CHR - plugin: downloadUpdater2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Documents and Settings\Pankaj\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Bejeweled = C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm\2_0\
CHR - Extension: Angry Birds = C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: A Space Shooter for FREE = C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\epbeobdmeddlnkokfiaijkfabecpmifa\4_0\
CHR - Extension: Bird Brawl = C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kmfmnamhddafiplkkobdinpjcnidlplk\1.0.0.0_0\

O1 HOSTS File: ([2011/12/22 18:36:57 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
O2 - BHO: (Catcher Class) - {ADECBED6-0366-4377-A739-E69DFBA04663} - C:\Program Files\Moyea\FLV Downloader\MoyeaCth.dll (Moyea Software Co., Ltd.)
O2 - BHO: (AOL Messaging Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AOL Messaging Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O3 - HKLM\..\Toolbar: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Messaging Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\CHDAudPropShortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
O4 - HKLM..\Run: [MsmqIntCert] C:\WINDOWS\System32\mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKCU..\Run: [Registry Cleaner Scheduler] C:\Program Files\CleanMyPC\Registry Cleaner\RCHelper.exe (CleanMyPC Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\HP Pavilion Webcam Tray Icon.lnk = C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Send To &Bluetooth; - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} http://sifyimg.speedera.net/sify.com/eot/tdserver.cab (TDServer Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1238516119640 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab (PopCapLoader Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A61EDCB7-0362-47DA-849E-D7778C4C10F2}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (%SystemRoot%\system32\logonui.exe) - File not found
O20 - Winlogon\Notify\NavLogon: DllName - (C:\WINDOWS\system32\NavLogon.dll) - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\NecUsb3Sevice: DllName - (USB3Nw32.dll) - C:\WINDOWS\System32\USB3Nw32.dll ()
O20 - Winlogon\Notify\USB3Nw32: DllName - (USB3Nw32.dll) - C:\WINDOWS\System32\USB3Nw32.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\Pankaj\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Pankaj\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 01:37:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/22 19:06:09 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Pankaj\Desktop\OTL.exe
[2011/12/22 00:31:05 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/12/21 23:40:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/12/21 23:40:00 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/12/21 23:24:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Local Settings\Application Data\AIM Toolbar
[2011/12/21 10:22:56 | 000,000,000 | -H-D | C] – C:\WINDOWS\$hf_mig$
[2011/12/20 23:19:13 | 000,000,000 | —D | C] – C:\Config.Msi
[2011/12/20 22:08:58 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/12/20 22:00:35 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/12/20 22:00:34 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/12/20 22:00:34 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/12/20 22:00:34 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/12/20 22:00:16 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/12/20 21:57:10 | 000,000,000 | —D | C] – C:\Qoobox
[2011/12/20 21:56:55 | 000,000,000 | R–D | C] – C:\Documents and Settings\Pankaj\Start Menu\Programs\Administrative Tools
[2011/12/20 21:12:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Desktop\Ping problem
[2011/12/19 22:14:57 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2011/12/19 17:06:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Desktop\Recipe pics
[2011/12/18 12:35:29 | 000,000,000 | —D | C] – C:\ubuntu(2)
[2011/12/18 10:23:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Intel(2)
[2011/12/17 22:46:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CleanMyPC Registry Cleaner
[2011/12/17 22:46:42 | 000,000,000 | —D | C] – C:\Program Files\CleanMyPC
[2011/12/17 22:35:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Wise PC Doctor
[2011/12/17 22:35:35 | 000,000,000 | —D | C] – C:\Program Files\Wise PC Doctor
[2011/12/17 21:47:05 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/17 20:44:30 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/17 20:44:16 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/12/09 13:38:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Desktop\Songs for bhaiya
[2011/12/08 22:19:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Start Menu\Programs\Google Chrome
[2011/12/08 21:03:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Local Settings\Application Data\Symantec
[2011/12/08 21:02:27 | 000,060,800 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2011/12/08 21:02:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Symantec Client Security
[2011/12/08 21:02:26 | 000,123,952 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2011/12/08 21:00:07 | 000,000,000 | —D | C] – C:\Program Files\Symantec AntiVirus
[2011/12/08 20:57:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Desktop\SAV
[2011/12/08 20:45:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Start Menu\Programs\Security Sphere 2012
[2011/12/05 21:20:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Desktop\Personal
[2011/11/29 12:59:52 | 000,000,000 | —D | C] – C:\Program Files\AIM Toolbar
[2011/11/29 12:59:37 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Software Update Utility
[2011/11/29 12:59:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AIM
[2011/11/29 12:58:51 | 000,000,000 | —D | C] – C:\Program Files\AIM
[2011/11/27 21:24:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Intel PROSet Wireless
[2011/11/27 19:57:49 | 000,000,000 | —D | C] – C:\Program Files\Broadcom
[2011/11/27 19:27:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Application Data\Intel
[2011/11/27 19:27:01 | 006,609,920 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\drivers\NETwLx32.sys
[2011/11/27 19:27:01 | 002,756,608 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\NETwLr32.dll
[2011/11/27 19:27:01 | 000,675,840 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\NETwLc32.dll
[2011/11/27 19:26:27 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Intel
[2011/11/24 22:02:40 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/24 21:32:02 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2011/11/24 21:32:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Local Settings\Application Data\uTorrentBar
[2011/11/24 21:31:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Local Settings\Application Data\Conduit
[2011/11/24 21:31:56 | 000,000,000 | —D | C] – C:\Program Files\uTorrentBar
[2011/11/24 21:31:46 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2011/11/24 21:31:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Local Settings\Application Data\uTorrent
[2011/11/24 21:31:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Application Data\uTorrent
[2011/11/23 01:11:42 | 000,000,000 | —D | C] – C:\Program Files\Tweet Adder 3
[2011/11/23 01:11:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Tweet Adder 3
[2011/11/23 01:05:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Application Data\TweetAdder3
[2011/11/23 01:03:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WampServer
[2011/11/23 00:41:52 | 000,099,865 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\xlog.exe
[2011/11/23 00:41:52 | 000,099,865 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\xlog.exe
[2011/11/23 00:41:50 | 000,159,744 | —- | C] (XSS) – C:\WINDOWS\System32\virtdisk.exe
[2011/11/23 00:41:50 | 000,131,072 | —- | C] (XSS) – C:\WINDOWS\System32\VirtualImage.exe
[2011/11/23 00:41:50 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vdsldr.exe
[2011/11/23 00:41:49 | 000,106,496 | —- | C] (XSS) – C:\WINDOWS\System32\UPDeploy.exe
[2011/11/23 00:41:47 | 000,102,400 | —- | C] (SoftThinks) – C:\WINDOWS\System32\start.exe
[2011/11/23 00:41:40 | 001,806,336 | —- | C] (SoftThinks) – C:\WINDOWS\System32\Restore.exe
[2011/11/23 00:41:40 | 000,057,344 | —- | C] (SoftThinks) – C:\WINDOWS\System32\RPONOFF.EXE
[2011/11/23 00:41:38 | 000,147,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\regedit.exe
[2011/11/23 00:41:37 | 000,061,440 | —- | C] (XSS) – C:\WINDOWS\System32\PTConfig.exe
[2011/11/23 00:41:37 | 000,053,248 | —- | C] (XSS) – C:\WINDOWS\System32\QP_BOOTINI.exe
[2011/11/23 00:41:36 | 000,108,057 | —- | C] (Comtrol® Corporation) – C:\WINDOWS\System32\peer.exe
[2011/11/23 00:41:36 | 000,049,152 | —- | C] (XSS) – C:\WINDOWS\System32\PartRemove.exe
[2011/11/23 00:41:36 | 000,045,056 | —- | C] (XSS (eXtended Software Solutions), Germany) – C:\WINDOWS\System32\PAGEFILE.EXE
[2011/11/23 00:41:33 | 000,159,744 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvuide.exe
[2011/11/23 00:41:33 | 000,083,456 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvraidservice.exe
[2011/11/23 00:41:31 | 002,589,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ntkrnlmp.exe
[2011/11/23 00:41:31 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\netcfg.exe
[2011/11/23 00:41:29 | 000,147,456 | —- | C] (XSS) – C:\WINDOWS\System32\MBRInst.exe
[2011/11/23 00:41:29 | 000,049,152 | —- | C] (XSS) – C:\WINDOWS\System32\MOUNT_QP.exe
[2011/11/23 00:41:29 | 000,049,152 | —- | C] (XSS) – C:\WINDOWS\System32\mount.exe
[2011/11/23 00:41:27 | 000,925,696 | —- | C] (SoftThinks) – C:\WINDOWS\System32\LogViewer.exe
[2011/11/23 00:41:20 | 000,137,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\factory.exe
[2011/11/23 00:41:20 | 000,057,344 | —- | C] (XSS) – C:\WINDOWS\System32\FATFMT32.EXE
[2011/11/23 00:41:18 | 000,061,952 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\eqnloop.exe
[2011/11/23 00:41:18 | 000,061,952 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqnloop.exe
[2011/11/23 00:41:18 | 000,051,200 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\eqnlogr.exe
[2011/11/23 00:41:18 | 000,051,200 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqnlogr.exe
[2011/11/23 00:41:17 | 000,053,248 | —- | C] (XSS) – C:\WINDOWS\System32\DSKPART.EXE
[2011/11/23 00:41:17 | 000,053,248 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\eqndiag.exe
[2011/11/23 00:41:17 | 000,053,248 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqndiag.exe
[2011/11/23 00:41:17 | 000,045,056 | —- | C] (XSS) – C:\WINDOWS\System32\Eject.exe
[2011/11/23 00:41:16 | 000,236,060 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\ditrace.exe
[2011/11/23 00:41:16 | 000,236,060 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\ditrace.exe
[2011/11/23 00:41:15 | 000,688,128 | —- | C] (SoftThinks) – C:\WINDOWS\System32\DblRes.exe
[2011/11/23 00:41:15 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\devcon.exe
[2011/11/23 00:41:15 | 000,049,152 | —- | C] (XSS) – C:\WINDOWS\System32\Delay.exe
[2011/11/23 00:41:12 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cmd.exe
[2011/11/23 00:41:12 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\cmd.exe
[2011/11/23 00:41:12 | 000,388,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\cmd2.exe
[2011/11/23 00:41:08 | 000,053,248 | —- | C] (SoftThinks) – C:\WINDOWS\System32\Bootini.exe
[2011/11/23 00:41:08 | 000,045,056 | —- | C] (Softthinks) – C:\WINDOWS\System32\BSUpdate.exe
[2011/11/23 00:30:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Start Menu\Programs\EditPlus 2
[2011/11/22 23:26:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Application Data\A47B1
[2009/11/02 14:13:23 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\csnp2uvc.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/22 19:06:05 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Pankaj\Desktop\OTL.exe
[2011/12/22 18:36:57 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/22 16:42:03 | 000,001,002 | —- | M] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3641525057-1712457974-3760122168-1005UA.job
[2011/12/22 09:50:03 | 000,050,868 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/12/22 09:48:15 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/21 23:47:55 | 001,689,328 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/21 23:36:39 | 000,455,316 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/21 23:36:39 | 000,075,264 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/21 23:24:34 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/12/21 23:23:05 | 000,000,060 | —- | M] () – C:\WINDOWS\wpd99.drv
[2011/12/21 22:42:01 | 000,000,980 | —- | M] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3641525057-1712457974-3760122168-1005Core.job
[2011/12/21 10:21:36 | 000,103,733 | —- | M] () – C:\WINDOWS\System32\itusbcore.dat
[2011/12/21 10:21:36 | 000,000,197 | —- | M] () – C:\WINDOWS\System32\itlsvc.dat
[2011/12/20 22:09:07 | 000,000,325 | RHS- | M] () – C:\boot.ini
[2011/12/19 17:12:08 | 000,044,032 | —- | M] () – C:\Documents and Settings\Pankaj\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/19 14:34:32 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/18 14:13:54 | 000,134,978 | —- | M] () – C:\wubildr
[2011/12/18 14:13:52 | 000,008,192 | —- | M] () – C:\wubildr.mbr
[2011/12/18 04:06:03 | 000,000,209 | —- | M] () – C:\Boot.bak
[2011/12/17 20:18:48 | 000,016,616 | -HS- | M] () – C:\Documents and Settings\Pankaj\Local Settings\Application Data\s1nw45s5ft4iwc
[2011/12/17 20:18:48 | 000,016,616 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\s1nw45s5ft4iwc
[2011/12/09 09:47:35 | 000,000,000 | —- | M] () – C:\WINDOWS\vpc32.INI
[2011/12/08 22:20:02 | 000,002,300 | —- | M] () – C:\Documents and Settings\Pankaj\Desktop\Google Chrome.lnk
[2011/12/08 22:20:02 | 000,002,278 | —- | M] () – C:\Documents and Settings\Pankaj\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/12/08 21:02:35 | 000,123,952 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2011/12/08 21:02:35 | 000,060,800 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2011/12/08 21:02:35 | 000,010,671 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2011/12/08 21:02:35 | 000,000,805 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2011/12/08 20:54:58 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2011/12/05 21:38:14 | 000,000,428 | —- | M] () – C:\Documents and Settings\Pankaj\My Documents\spider.sav
[2011/12/01 21:51:39 | 000,001,609 | —- | M] () – C:\Documents and Settings\Pankaj\Desktop\Services.lnk
[2011/11/29 12:59:15 | 000,001,104 | -H– | M] () – C:\IPH.PH
[2011/11/29 12:59:00 | 000,001,599 | —- | M] () – C:\Documents and Settings\Pankaj\Application Data\Microsoft\Internet Explorer\Quick Launch\AIM.lnk
[2011/11/28 00:28:07 | 000,002,052 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/11/27 18:18:00 | 000,013,644 | -HS- | M] () – C:\Documents and Settings\Pankaj\Local Settings\Application Data\041730n6j756f472t653x1hmb4g0
[2011/11/27 18:18:00 | 000,013,644 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\041730n6j756f472t653x1hmb4g0
[2011/11/24 22:02:40 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/24 21:31:47 | 000,000,655 | —- | M] () – C:\Documents and Settings\Pankaj\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2011/11/23 05:25:32 | 001,859,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\win32k.sys
[2011/11/23 05:25:32 | 001,859,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\win32k.sys
[2011/11/23 01:11:43 | 000,000,773 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TweetAdder3.lnk
[2011/11/23 00:54:55 | 002,006,309 | —- | M] () – C:\WINDOWS\iis6.BAK
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/20 22:09:07 | 000,000,209 | —- | C] () – C:\Boot.bak
[2011/12/20 22:09:01 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/12/20 22:00:35 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/12/20 22:00:34 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/12/20 22:00:34 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/12/20 22:00:34 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/12/20 22:00:34 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/12/19 10:31:55 | 000,103,733 | —- | C] () – C:\WINDOWS\System32\itusbcore.dat
[2011/12/19 10:31:55 | 000,000,197 | —- | C] () – C:\WINDOWS\System32\itlsvc.dat
[2011/12/18 14:13:52 | 000,134,978 | —- | C] () – C:\wubildr
[2011/12/18 14:13:52 | 000,008,192 | —- | C] () – C:\wubildr.mbr
[2011/12/17 20:14:24 | 000,016,616 | -HS- | C] () – C:\Documents and Settings\Pankaj\Local Settings\Application Data\s1nw45s5ft4iwc
[2011/12/17 20:14:24 | 000,016,616 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\s1nw45s5ft4iwc
[2011/12/09 09:47:35 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2011/12/08 22:20:02 | 000,002,300 | —- | C] () – C:\Documents and Settings\Pankaj\Desktop\Google Chrome.lnk
[2011/12/08 22:20:02 | 000,002,278 | —- | C] () – C:\Documents and Settings\Pankaj\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/12/08 21:02:27 | 000,010,671 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2011/12/08 21:02:26 | 000,000,805 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2011/12/05 21:38:14 | 000,000,428 | —- | C] () – C:\Documents and Settings\Pankaj\My Documents\spider.sav
[2011/12/04 19:40:54 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/12/01 22:37:42 | 000,001,002 | —- | C] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3641525057-1712457974-3760122168-1005UA.job
[2011/12/01 22:37:42 | 000,000,980 | —- | C] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3641525057-1712457974-3760122168-1005Core.job
[2011/12/01 21:51:39 | 000,001,609 | —- | C] () – C:\Documents and Settings\Pankaj\Desktop\Services.lnk
[2011/11/29 12:59:00 | 000,001,599 | —- | C] () – C:\Documents and Settings\Pankaj\Application Data\Microsoft\Internet Explorer\Quick Launch\AIM.lnk
[2011/11/28 00:28:07 | 000,002,052 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2011/11/27 12:07:02 | 000,013,644 | -HS- | C] () – C:\Documents and Settings\Pankaj\Local Settings\Application Data\041730n6j756f472t653x1hmb4g0
[2011/11/27 12:07:02 | 000,013,644 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\041730n6j756f472t653x1hmb4g0
[2011/11/24 21:31:47 | 000,000,655 | —- | C] () – C:\Documents and Settings\Pankaj\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2011/11/23 01:11:43 | 000,000,773 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TweetAdder3.lnk
[2011/11/23 00:41:51 | 000,041,472 | —- | C] () – C:\WINDOWS\System32\winpeshl.exe
[2011/11/23 00:41:50 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\VImage.exe
[2011/11/23 00:41:48 | 000,000,042 | —- | C] () – C:\WINDOWS\System32\START.EXE.INI
[2011/11/23 00:41:42 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\SCSP4VOL.exe
[2011/11/23 00:41:36 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\OwnerPatch.exe
[2011/11/23 00:41:33 | 000,239,104 | —- | C] () – C:\WINDOWS\System32\NvRaidMan.exe
[2011/11/23 00:41:20 | 000,495,616 | —- | C] () – C:\WINDOWS\System32\Explo.exe
[2011/11/21 00:20:38 | 000,000,600 | —- | C] () – C:\Documents and Settings\Pankaj\Local Settings\Application Data\PUTTY.RND
[2011/01/04 09:18:03 | 000,002,037 | RHS- | C] () – C:\WINDOWS\System32\setting.ini
[2010/01/16 00:44:47 | 000,088,520 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/12/14 10:14:29 | 000,129,024 | —- | C] () – C:\WINDOWS\System32\AVERM.dll
[2009/11/02 22:47:14 | 000,044,032 | —- | C] () – C:\Documents and Settings\Pankaj\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/02 14:13:23 | 000,102,400 | —- | C] () – C:\WINDOWS\HPWebcam.exe
[2009/11/02 14:10:03 | 000,000,129 | —- | C] () – C:\Documents and Settings\Pankaj\Local Settings\Application Data\fusioncache.dat
[2009/08/15 04:57:43 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/07/11 11:04:43 | 000,000,000 | —- | C] () – C:\WINDOWS\LiveBilliardsDemo.INI
[2009/03/24 11:44:41 | 000,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2009/03/21 22:43:34 | 000,000,135 | —- | C] () – C:\WINDOWS\System32\mp3codec32win.dll
[2009/03/16 09:41:36 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2009/03/16 09:41:36 | 000,000,060 | —- | C] () – C:\WINDOWS\wpd99.drv
[2009/03/16 09:12:52 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/03/14 02:21:10 | 000,000,026 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2006/07/05 11:28:58 | 000,047,744 | —- | C] () – C:\WINDOWS\System32\drivers\snp2uvc.sys
[2006/06/29 11:18:28 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/06/29 11:18:14 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/06/29 10:49:18 | 000,087,268 | —- | C] () – C:\WINDOWS\hpqins69.dat
[2006/06/29 10:46:56 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/06/29 10:43:40 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/06/29 10:27:08 | 000,455,316 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/06/29 10:27:08 | 000,075,264 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/06/29 10:18:06 | 001,689,328 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/06/29 10:13:00 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/06/29 10:08:28 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/05/11 23:53:22 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\btprn2k.dll
[2006/04/26 11:48:00 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/04/26 11:48:00 | 001,519,616 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2006/04/26 11:48:00 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/04/26 11:48:00 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2006/04/26 11:48:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/04/26 11:48:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/04/26 11:48:00 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2006/04/26 11:48:00 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2006/04/26 11:48:00 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/03/15 20:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/03/15 20:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/03/15 20:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/03/15 20:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/03/15 20:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/03/15 20:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/03/15 20:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/03/15 20:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/03/03 23:07:34 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2006/02/10 01:05:09 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\USB3Nw32.dll
[2005/12/02 10:09:10 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/06/18 07:00:52 | 000,070,018 | —- | C] () – C:\WINDOWS\System32\akrip32.dll
[2005/05/05 18:06:32 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2002/05/28 13:55:42 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/05/28 13:54:40 | 000,004,605 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/11/14 00:26:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
[1999/07/29 19:54:34 | 000,000,218 | —- | C] () – C:\WINDOWS\oraodbc.ini

========== LOP Check ==========

[2006/02/10 00:31:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Age of Empires 3
[2006/02/10 00:31:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2006/02/10 00:31:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM Toolbar
[2006/02/10 00:31:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2006/02/10 00:31:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\kA01300AbCcD01300
[2006/02/10 00:31:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MySQL
[2011/12/21 23:23:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2006/02/10 00:31:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pJ01300BpFaG01300
[2010/04/25 07:49:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2009/10/11 11:17:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Quest Software
[2011/04/05 10:40:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2009/03/22 01:20:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Teleca
[2010/05/25 13:54:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TmForever
[2006/02/10 00:31:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/03/22 11:40:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\610V31
[2009/10/31 12:07:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\7Wonders
[2011/11/27 12:16:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\A47B1
[2006/02/09 13:12:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\acccore
[2011/12/22 09:50:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\DMCache
[2009/10/12 10:00:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\EditPlus 2
[2011/05/10 12:35:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\FileZilla
[2011/11/09 23:08:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\funkitron
[2009/09/26 11:00:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\IDM
[2009/04/03 09:14:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\Leadertech
[2011/11/07 10:30:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\Magic Match
[2010/12/19 07:37:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\Memeo
[2009/12/14 09:41:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\Moyea
[2010/11/26 09:45:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\OpenCandy
[2009/03/24 11:44:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\pdf995
[2009/10/11 11:17:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\Quest Software
[2009/11/14 08:36:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\Ringtone
[2010/12/19 07:37:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\Seagate
[2009/03/22 01:55:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\Teleca
[2009/11/20 20:24:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\Thunderbird
[2011/11/23 01:10:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\TweetAdder3
[2011/12/17 23:35:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\uTorrent
[2009/12/23 11:04:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Pankaj\Application Data\Zoundry
[2011/12/21 22:42:01 | 000,000,980 | —- | M] () – C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-3641525057-1712457974-3760122168-1005Core.job
[2011/12/22 16:42:03 | 000,001,002 | —- | M] () – C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-3641525057-1712457974-3760122168-1005UA.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe

< MD5 for: SVCHOST.EXE >
[2010/05/01 17:24:34 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ERDNT\cache\svchost.exe
[2008/04/13 16:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2010/05/01 17:24:34 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\dllcache\svchost.exe
[2010/05/01 17:24:34 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/04/13 16:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ERDNT\cache\userinit.exe
[2008/04/13 16:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 16:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< C:\Windows\assembly\tmp\U\*.* /s >

< End of report >


Extras.txt:



OTL Extras logfile created on: 12/22/2011 7:08:42 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Pankaj\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.04 Mb Total Physical Memory | 471.24 Mb Available Physical Memory | 46.11% Memory free
2.40 Gb Paging File | 1.90 Gb Available in Paging File | 79.28% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 59.45 Gb Total Space | 24.61 Gb Free Space | 41.40% Space Free | Partition Type: NTFS
Drive D: | 11.19 Gb Total Space | 1.20 Gb Free Space | 10.69% Space Free | Partition Type: FAT32
Drive F: | 21.49 Gb Total Space | 0.53 Gb Free Space | 2.44% Space Free | Partition Type: NTFS

Computer Name: PC187869777259 | User Name: Pankaj | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
.reg [@ = regfile] – C:\WINDOWS\System32\regedit.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htafile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [open] – regedit.exe "%1" (Microsoft Corporation)
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"60006:TCP" = 60006:TCP:*:Enabled:Bitcomet 60006 TCP
"60006:UDP" = 60006:UDP:*:Enabled:Bitcomet 60006 UDP
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"3306:TCP" = 3306:TCP:*:Enabled:MySQL Server
"60000:TCP" = 60000:TCP:*:Enabled:BitComet 60000 TCP
"60000:UDP" = 60000:UDP:*:Enabled:BitComet 60000 UDP

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll" = C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin – (Google)
"C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Pankaj\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM – (AOL Inc.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Documents and Settings\Pankaj\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe" = C:\Documents and Settings\Pankaj\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Enabled:Facebook Video Calling Plugin – (Skype Limited)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1CB34CE9-0E6B-493F-BB66-3425E5DF76E5}" = CP_CalendarTemplates1
"{1D7CE340-70C3-4848-BCCF-215950328A4C}" = Facebook Video Calling 1.0.0.8953
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{21DBBDD6-93A5-4326-9A04-C9A5C9148502}" = Norton PartitionMagic
"{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"{23B35809-5E4A-4F14-8332-1CDEDDFAC089}" = CP_Package_Variety2
"{24BEBF2E-73F3-4599-840B-EDC612CCDD0D}" = Destinations
"{25BEC3AB-5CD4-481D-9143-215C1BBB189E}" = Sony Ericsson PC Suite
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 22
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2A548002-9042-4083-A270-B67473DE1073}" = SkinsHP1
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{32A3A4F4-B792-11D6-A78A-00B0D0160130}" = Java™ SE Development Kit 6 Update 13
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.10 A2
"{34F3FCF1-817B-4D61-B6AF-19D9486AFEA0}" = Unload
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = HP Pavilion Webcam
"{3C79DC59-6099-323B-B27B-90B45542B270}" = Google Talk Plugin
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = HP Integrated Module with Bluetooth wireless technology
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FE0CFAB-584A-4AA5-B8CD-C32284CFA308}" = RandMap
"{3FE3D6A5-2F5E-4870-A3AC-D1D88E0B2797}" = Intel® PROSet/Wireless WiFi Software
"{4041C245-7099-4C96-9738-5EBC23827B3C}" = BufferChm
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}" = HP Wireless Assistant 2.00 G2
"{4402084F-61EE-48B2-AFCB-AC1EC2454C79}" = MySQL Server 5.1
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 2.3
"{494D17B5-3369-4905-8C4B-80C972C5E0FF}" = CP_Panorama1Config
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4DA4012B-39AF-48c2-B23B-A4D570D233A6}" = cp_LightScribeConfig
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{522D1D79-9C0A-4361-91F8-2AFF8EC6C2E1}" = CP_Package_Variety1
"{52FBAE98-D389-4281-8C14-21B4046CCB4E}" = SonicAC3Encoder
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{54F0998F-73C8-4b51-8286-FE903C231BED}" = cp_PosterPrintConfig
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{63A3856B-5C0E-4BC1-B508-629AE74B6BBA}" = HP User Guides 0027
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A28AB0B-22B1-494C-AF61-B386EA1736C0}" = LightScribe 1.4.97.1
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{766633B3-1AFA-44B6-A3FC-1DE991CD9C52}" = CP_Package_Basic1
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79F8E1D4-36C1-439C-95FA-F695050B5B07}" = Sonic_PrimoSDK
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{80AE27BA-B0ED-4288-A8B9-D8194BCF4115}" = cp_UpdateProjectsConfig
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110074983}" = BeTrapped!
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110111700}" = Zuma Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110113233}" = Bookworm Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11015843}" = Ricochet Lost Worlds
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110160733}" = Slingo
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110194827}" = Jewel Quest
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110265407}" = Bejeweled 2 Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11029123}" = Bricks of Egypt
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110313550}" = Jigsaw 365
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110354527}" = Chicken Rush
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110379827}" = Wonderland - Secret Worlds
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110411970}" = Chuzzle
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110422467}" = Tiks Texas Hold em
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11050883}" = Bricks of Atlantis
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11052313}" = Magic Match
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110554843}" = Pat Sajak’s Lucky Letters
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111118433}" = Mystery Case Files - Huntsville
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111125700}" = Rainbow Web
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111170320}" = 7 Wonders of the Ancient World
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111177437}" = Mahjong Match
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111195760}" = Mozaki Blocks
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111200223}" = Poker Superstars 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-1112100}" = Mosiac - Tomb of Mystery
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111232687}" = Ocean Express
"{838A1BC9-95CA-4880-9BE3-2A7D23600A2B}" = Macromedia Shockwave Player
"{85262A06-2D8C-4BC1-B6ED-5A705D09CFFC}" = Apache HTTP Server 2.2.14
"{869C3062-4745-4949-B6C9-98AF24D89030}" = PhotoGallery
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E666407-AC41-46a2-9692-6C7BFCBFDD37}" = Memeo Instant Backup
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_WebDesigner_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_WebDesigner_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_WebDesigner_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0026-0000-0000-0000000FF1CE}" = Microsoft Expression Web
"{90120000-0026-0000-0000-0000000FF1CE}_WebDesigner_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0026-0000-0000-0000000FF1CE}_WebDesigner_{9037FDA8-8383-4B6F-859D-D49C3C625225}" = Microsoft Expression Web Service Pack 1 (SP1)
"{90120000-0026-0409-0000-0000000FF1CE}" = Microsoft Expression Web MUI (English)
"{90120000-0026-0409-0000-0000000FF1CE}_WebDesigner_{E1044ED2-E4AD-4B39-B500-31109750F6B4}" = Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_WebDesigner_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_WebDesigner_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{939F8208-C8CE-4AFF-B7BA-ACEB2E74A6CB}" =
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{998D6972-F58E-479D-9248-8F179E55AE38}" = Java DB 10.4.1.3
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9D4ABB0C-F60B-44A6-956C-A4A63D5495C9}" = CueTour
"{9F91B6C4-E892-4978-A571-B5A32BC2082C}" = Symantec AntiVirus
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A777CB31-A5EC-4E32-A462-2E24F45D4D4F}_is1" = Moyea FLV to Video Converter Pro version 1.22.1.7
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio Module
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{B11E71BA-498C-42D4-9F1A-9D7A89D9DA61}" = CP_AtenaShokunin1Config
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic Copy Module
"{B16AF568-A644-483C-A6DA-5028CD019C8C}" = SonicMPEGEncoder
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B57F2FF0-5A25-4332-B503-4592B370C02F}" = CP_Package_Variety3
"{B6A46847-DA79-4927-BC6F-C9EF06B25A4E}" = Tweet Adder 3
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Update
"{BBD3BF67-5B89-4CBB-BA58-5818ED5F3290}" = cp_OnlineProjectsConfig
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C3A11907-930D-41AC-A135-CC3B12F92011}" = Seagate Dashboard
"{C60BA916-9E44-4DA4-B11A-9E27B7624EF5}" = Sony Ericsson Drivers
"{C92E7DF1-624A-4D95-A4C4-18CB491B44A4}" = Sony Ericsson Device Data
"{CB2B2B63-58AB-48F3-AAD5-7E93AFE4268B}" = Quest Software Toad for MySQL Freeware 4.5
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D1BB4446-AE9C-4256-9A7F-4D46604D2462}" = Adobe Setup
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D6BF6477-8369-489F-8DE6-3731F4B88560}" = Sony Ericsson PC Suite
"{D8FFA4C9-421F-4AA9-A9C2-E2BC1CCED6D1}" = Transcend T.sonic 610 MP3 Player
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DF817F49-F4DE-4564-9D0A-68F742A573F9}_is1" = Wise PC Doctor version 3.8.8
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{EA426461-31AA-4AB3-B15D-EDD748F08394}_is1" = Moyea FLV Downloader version 1.8.0.6
"{EC2A8F27-4FBF-4E41-B27B-FE822511B761}" = iTunes
"{EC397D90-720E-426D-B381-0A10C6FD5A49}" = HP Pavilion Webcam Demo
"{F618BD43-1520-450C-BC2C-0F7FA32A6546}" = VCDCut Pro
"{FB09F05F-85C6-4205-B28D-5BF071D276C3}" = muvee autoProducer 5.0
"{FC8D25A7-FF1B-41BB-BB3B-9A06C0A60AE0}" = InstantShareDevices
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_2ac78060bc5856b0c1cf873bb919b58" = Adobe Photoshop CS3
"AIM Toolbar" = AOL Messaging Toolbar
"AIM_7" = AIM 7
"Apache Tomcat 5.5" = Apache Tomcat 5.5 (remove only)
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"Broadcom 802.11b Network Adapter" = Broadcom 802.11 Wireless LAN Adapter
"CDisplay_is1" = CDisplay 1.8
"CleanMyPC - Registry Cleaner_is1" = CleanMyPC - Registry Cleaner
"CNXT_HDAUDIO" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_wis30B2m" = HDAUDIO Soft Data Fax Modem with SmartCP
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ESET Online Scanner" = ESET Online Scanner v3
"HP Imaging Device Functions" = HP Imaging Device Functions 6.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.0
"ie8" = Windows Internet Explorer 8
"InstallShield_{21DBBDD6-93A5-4326-9A04-C9A5C9148502}" = Norton PartitionMagic 8.0
"InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"Internet Download Manager" = Internet Download Manager
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Money2005b" = Microsoft Money
"Monkey's Audio_is1" = Monkey's Audio
"Mozilla Firefox (3.6.25)" = Mozilla Firefox (3.6.25)
"Mozilla Thunderbird (2.0.0.23)" = Mozilla Thunderbird (2.0.0.23)
"NVIDIA Drivers" = NVIDIA Drivers
"Pdf995" = Pdf995
"PROSet" = Intel® PRO Network Connections Drivers
"SAMPDJ" = SAM Party DJ (remove only)
"Sandlot Games Client Services_is1" = Sandlot Games Client Services
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TmNationsForever_is1" = TmNationsForever
"uTorrent" = µTorrent
"uTorrentBar Toolbar" = uTorrentBar Toolbar
"VLC media player" = VLC media player 1.0.3
"WampServer 2_is1" = WampServer 2.2
"WebDesigner" = Microsoft Expression Web
"WGA" = Windows Genuine Advantage Validation Tool
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR archiver
"Zoundry Raven" = Zoundry Raven

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"73c55bb370e137bb" = TraderTerminal
"AOL Messaging Toolbar" = AOL Messaging Toolbar
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/21/2011 2:15:55 AM | Computer Name = PC187869777259 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 12/21/2011 2:15:56 AM | Computer Name = PC187869777259 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 12/21/2011 8:42:12 PM | Computer Name = PC187869777259 | Source = Google Update | ID = 20
Description =

Error - 12/22/2011 4:07:36 AM | Computer Name = PC187869777259 | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Failed to compile: C:\Program Files\Quest Software\Toad for MySQL Freeware 4.5\Toad.exe
. Error code = 0x80131047

Error - 12/22/2011 6:16:44 AM | Computer Name = PC187869777259 | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Risk: Bloodhound.MalPE in File: C:\System Volume
Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP615\A0537943.dll by:
Auto-Protect scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully.

Error - 12/22/2011 6:16:45 AM | Computer Name = PC187869777259 | Source = Symantec AntiVirus | ID = 16711685
Description = Risk Found!Risk: Bloodhound.MalPE in File: C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP615\A0537943.dll
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 12/22/2011 6:16:45 AM | Computer Name = PC187869777259 | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Risk: Bloodhound.MalPE in File: C:\System Volume
Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP615\A0537943.dll by:
Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 12/22/2011 6:18:27 AM | Computer Name = PC187869777259 | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Risk: Bloodhound.MalPE in File: C:\System Volume
Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP615\A0537944.exe by:
Auto-Protect scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully.

Error - 12/22/2011 6:18:28 AM | Computer Name = PC187869777259 | Source = Symantec AntiVirus | ID = 16711685
Description = Risk Found!Risk: Bloodhound.MalPE in File: C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP615\A0537944.exe
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 12/22/2011 6:18:28 AM | Computer Name = PC187869777259 | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Risk: Bloodhound.MalPE in File: C:\System Volume
Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP615\A0537944.exe by:
Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

[ Media Center Events ]
Error - 2/9/2006 2:47:53 PM | Computer Name = PC187869777259 | Source = Recording | ID = 19
Description = The recording schedule has been corrupted and was automatically deleted
on 2/10/2006 12:17:53 AM. You may need to reschedule your recordings.

[ System Events ]
Error - 12/22/2011 1:49:19 PM | Computer Name = PC187869777259 | Source = Service Control Manager | ID = 7001
Description = The Helper NetBIOS di TCP/IP service depends on the Afd service which
failed to start because of the following error: %%31

Error - 12/22/2011 1:49:19 PM | Computer Name = PC187869777259 | Source = Service Control Manager | ID = 7023
Description = The USB Service service terminated with the following error: %%126

Error - 12/22/2011 1:49:25 PM | Computer Name = PC187869777259 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Afd

Error - 12/22/2011 1:49:29 PM | Computer Name = PC187869777259 | Source = Service Control Manager | ID = 7023
Description = The USB Service service terminated with the following error: %%126

Error - 12/22/2011 1:49:32 PM | Computer Name = PC187869777259 | Source = Service Control Manager | ID = 7023
Description = The USB Service service terminated with the following error: %%126

Error - 12/22/2011 1:49:42 PM | Computer Name = PC187869777259 | Source = Service Control Manager | ID = 7023
Description = The USB Service service terminated with the following error: %%126

Error - 12/22/2011 2:05:41 PM | Computer Name = PC187869777259 | Source = Service Control Manager | ID = 7023
Description = The USB Service service terminated with the following error: %%126

Error - 12/22/2011 2:05:51 PM | Computer Name = PC187869777259 | Source = Service Control Manager | ID = 7023
Description = The USB Service service terminated with the following error: %%126

Error - 12/22/2011 2:06:11 PM | Computer Name = PC187869777259 | Source = Service Control Manager | ID = 7023
Description = The USB Service service terminated with the following error: %%126

Error - 12/22/2011 8:06:21 PM | Computer Name = PC187869777259 | Source = Service Control Manager | ID = 7023
Description = The USB Service service terminated with the following error: %%126


< End of report >
Please update Malwarebytes,run a quick scan and post the log.


Please scan the following files


  • Please visit Virus Total by clicking here.
  • Click the Browse button and search for the following file: C:\WINDOWS\System32\USB3Nw32.dll
  • Click Open.
  • Then click Send File.
  • Please be patient while the file is scanned.
  • If Virus Total tells you that the file has already been scanned, click "reanalyse now".

Post the results.
Hi Mowman,

Here's the result:


Malware bytes Log:


Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 911122308

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

12/23/2011 12:26:38 AM
mbam-log-2011-12-23 (00-26-38).txt

Scan type: Quick scan
Objects scanned: 232132
Time elapsed: 12 minute(s), 32 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Virus total Result:



Antivirus Version Last Update Result
AhnLab-V3 2011.12.23.00 2011.12.23 Trojan/Win32.Sasfis
AntiVir 7.11.19.248 2011.12.23 TR/Sasfis.2.98
Antiy-AVL 2.0.3.7 2011.12.23 Trojan/Win32.Sasfis.gen
Avast 6.0.1289.0 2011.12.23 Win32:Malware-gen
AVG 10.0.0.1190 2011.12.23 BackDoor.Generic14.CFLX
BitDefender 7.2 2011.12.23 Gen:Variant.Sasfis.2
ByteHero 1.0.0.1 2011.12.07 -
CAT-QuickHeal 12.00 2011.12.23 -
ClamAV 0.97.3.0 2011.12.23 -
Commtouch 5.3.2.6 2011.12.23 -
Comodo 11062 2011.12.23 TrojWare.Win32.TrojanDownloader.Murlo.~JH2
DrWeb 5.0.2.03300 2011.12.23 Trojan.Siggen3.28020
Emsisoft 5.1.0.11 2011.12.23 Trojan.Win32.Sasfis!IK
eSafe 7.0.17.0 2011.12.22 -
eTrust-Vet 37.0.9641 2011.12.23 -
F-Prot 4.6.5.141 2011.12.22 -
F-Secure 9.0.16440.0 2011.12.23 Gen:Variant.Sasfis.2
Fortinet 4.3.388.0 2011.12.23 W32/Agent.AFE!tr.bdr
GData 22.316/22.599 2011.12.23 Gen:Variant.Sasfis.2
Ikarus T3.1.1.109.0 2011.12.23 Trojan.Win32.Sasfis
Jiangmin 13.0.900 2011.12.23 -
K7AntiVirus 9.120.5757 2011.12.23 Riskware
Kaspersky 9.0.0.837 2011.12.23 Trojan.Win32.Sasfis.ctjn
McAfee 5.400.0.1158 2011.12.23 BackDoor-FDD
McAfee-GW-Edition 2010.1E 2011.12.23 Artemis!5EF8F2162589
Microsoft 1.7903 2011.12.23 -
NOD32 6738 2011.12.23 -
Norman 6.07.13 2011.12.23 -
nProtect 2011-12-22.01 2011.12.22 Gen:Variant.Sasfis.2
Panda 10.0.3.5 2011.12.23 Generic Trojan
PCTools 8.0.0.5 2011.12.23 Trojan.Gen
Prevx 3.0 2011.12.23 -
Rising 23.89.04.02 2011.12.23 Trojan.Win32.Generic.12AB811B
Sophos 4.72.0 2011.12.23 Mal/Agent-AFE
SUPERAntiSpyware 4.40.0.1006 2011.12.23 -
Symantec 20111.2.0.82 2011.12.23 Trojan.Gen
TheHacker 6.7.0.1.362 2011.12.22 -
TrendMicro 9.500.0.1008 2011.12.23 -
TrendMicro-HouseCall 9.500.0.1008 2011.12.23 -
VBA32 3.12.16.4 2011.12.22 Trojan.Sasfis.cqoq
VIPRE 11294 2011.12.23 Trojan.Win32.Generic!BT
ViRobot 2011.12.23.4843 2011.12.23 -
VirusBuster 14.1.131.0 2011.12.23 -
Additional informationShow all
MD5 : 5ef8f2162589de0e370056b6d44fa684
SHA1 : 9f2ab0e9d3118b757a42540a331e1f54e0bc67a1
SHA256: 27eca39cd40ad76d6c280bf4eb6176ea779a05e99cf536e78d136e320c1d29fd
ssdeep: 768:GI/sYkprGfaz3+HfZ5TkzeHy+ES56W8G4O1FVXfmfsT:T/sYGr6i8jTkzeHy+BsHsXfB
File size : 37888 bytes
First seen: 2011-12-19 20:27:29
Last seen : 2011-12-23 17:08:15
TrID:
Win32 Executable Generic (58.3%)
Win16/32 Executable Delphi generic (14.1%)
Generic Win/DOS Executable (13.7%)
DOS Executable Generic (13.6%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x8950
timedatestamp….: 0x2A425E19 (Fri Jun 19 22:22:17 1992)
machinetype……: 0x14c (I386)

[[ 7 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
CODE, 0x1000, 0x797C, 0x7A00, 6.53, c6abfc4e9ff004b05c9067888f1f3f15
DATA, 0x9000, 0x318, 0x400, 2.74, 28a66859116a32bb92c4675740a209e2
BSS, 0xA000, 0xEE1, 0x0, 0.00, d41d8cd98f00b204e9800998ecf8427e
.idata, 0xB000, 0x37C, 0x400, 3.85, 7a682abb758eec5d30120cac1f2e7921
.edata, 0xC000, 0xB3, 0x200, 1.87, fc70ffb881c31a99b07c966f0b403f4b
.reloc, 0xD000, 0x870, 0xA00, 6.17, 8b13208277146b153ea512df0aad94a3
.rsrc, 0xE000, 0x200, 0x200, 3.06, 7dd5508631b499a9adcce8d6321c22f7

[[ 6 import(s) ]]
kernel32.dll: GetCurrentThreadId, ExitProcess, UnhandledExceptionFilter, RtlUnwind, RaiseException, GetSystemTime, FreeLibrary, HeapFree, HeapReAlloc, HeapAlloc, GetProcessHeap
kernel32.dll: TlsSetValue, TlsGetValue, TlsFree, TlsAlloc, LocalFree, LocalAlloc
user32.dll: CharUpperBuffA
kernel32.dll: VirtualQuery, Sleep, SetLastError, GetTickCount, GetProcAddress, GetLastError, FreeLibrary, CompareStringA
user32.dll: wvsprintfA, MessageBoxA
kernel32.dll: lstrlenA, LoadLibraryA, GetModuleHandleA, GetModuleFileNameA, GetFileAttributesA

[[ 5 export(s) ]]
WlLogoffEvent, WlLogonEvent, WlPostShellEvent, WlStartShellEvent, WlStartupEvent
ExifTool:
file metadata
CodeSize: 31232
EntryPoint: 0x8950
FileSize: 37 kB
FileType: Win32 DLL
ImageVersion: 0.0
InitializedDataSize: 5632
LinkerVersion: 2.25
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 4.0
PEType: PE32
Subsystem: Windows GUI
SubsystemVersion: 4.0
TimeStamp: 1992:06:20 00:22:17+02:00
UninitializedDataSize: 0
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    O2 - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
    O20 - Winlogon\Notify\NecUsb3Sevice: DllName - (USB3Nw32.dll) - C:\WINDOWS\System32\USB3Nw32.dll ()
    O20 - Winlogon\Notify\USB3Nw32: DllName - (USB3Nw32.dll) - C:\WINDOWS\System32\USB3Nw32.dll ()
    [2011/12/08 20:45:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Pankaj\Start Menu\Programs\Security Sphere 2012
    
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Hi Mowman,

Today when I started my PC, it got infected with "XP Security 2011" virus that was not allowing to open any programs. Luckily my Task Manager was already open and I saw a process "pqg.exe" that looked suspicious. I killed the process and searched it in C drive. I found it in Application Data folder and deleted it. Then I run Malware bytes program that fixed some registry changes.

Malware Bytes Logs:


Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 911122308

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

12/24/2011 5:40:49 PM
mbam-log-2011-12-24 (17-40-49).txt

Scan type: Quick scan
Objects scanned: 231978
Time elapsed: 12 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 6
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\Pankaj\Local Settings\Application Data\pqg.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe") Good: (firefox.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\Pankaj\Local Settings\Application Data\pqg.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\Pankaj\Local Settings\Application Data\pqg.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

After fixing this, I executed above script. Here are the OTL Logs:


All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NecUsb3Sevice\ deleted successfully.
File C:\WINDOWS\System32\USB3Nw32.dll not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\USB3Nw32\ deleted successfully.
File C:\WINDOWS\System32\USB3Nw32.dll not found.
C:\Documents and Settings\Pankaj\Start Menu\Programs\Security Sphere 2012 folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Flash cache emptied: 41 bytes

User: Guest
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 294871 bytes
->Java cache emptied: 330666 bytes
->FireFox cache emptied: 3815065 bytes
->Flash cache emptied: 3407 bytes

User: LocalService
->Temp folder emptied: 0 bytes

User: Movies

User: NetworkService
->Temp folder emptied: 0 bytes
->Java cache emptied: 24412 bytes
->Flash cache emptied: 27479 bytes

User: Pankaj
->Temp folder emptied: 134300 bytes
->Temporary Internet Files folder emptied: 7323745 bytes
->Java cache emptied: 83631979 bytes
->FireFox cache emptied: 75614108 bytes
->Google Chrome cache emptied: 268515989 bytes
->Flash cache emptied: 8651278 bytes

User: pics

User: Sandy
->Temp folder emptied: 49581 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 134 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 199793 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 79721 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 32280864 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 12019653 bytes

Total Files Cleaned = 470.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 12242011_174947

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…

*****
I know we should not alter anything without asking while our system is being diagnosed but without doing that I was not able to do anything.

I am not sure how I got this virus because I am not going to any unknown websites at all.
Hi Mowman, You have not mentioned any process for running combofix. So should i run it like the first one or the script. Please clarify. Merry Christmas and Happy New Year!! Regards, Meghna
ComboFix Log:


ComboFix 11-12-26.03 - Pankaj 12/27/2011 10:59:31.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.266 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *Disabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: ZoneAlarm Free Firewall *Enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
.
.
((((((((((((((((((((((((( Files Created from 2011-11-27 to 2011-12-27 )))))))))))))))))))))))))))))))
.
.
2071-07-25 03:43 . 2006-11-21 15:18 203576 -c—-w- c:\program files\Microsoft Games\Age of Empires III\autopatcher2.exe
2011-12-27 08:22 . 2011-12-27 08:28 ——– d—–w- c:\documents and settings\Pankaj\Application Data\Windows Live Writer
2011-12-27 08:22 . 2011-12-27 08:22 ——– d—–w- c:\documents and settings\Pankaj\Local Settings\Application Data\Windows Live Writer
2011-12-27 08:18 . 2011-12-27 08:18 ——– d—–w- c:\program files\Microsoft
2011-12-27 08:18 . 2011-12-27 08:19 ——– d—–w- c:\program files\Windows Live
2011-12-27 08:18 . 2011-12-27 08:18 ——– d—–w- c:\program files\Windows Live SkyDrive
2011-12-27 08:13 . 2011-12-27 08:13 ——– d—–w- c:\program files\Common Files\Windows Live
2011-12-27 07:51 . 2011-12-22 05:49 343040 —-a-w- c:\windows\system32\mspaint.exe
2011-12-27 07:51 . 2011-12-22 05:49 343040 —-a-w- c:\windows\system32\dllcache\mspaint.exe
2011-12-25 03:35 . 2011-12-25 03:35 ——– d—–w- c:\documents and settings\Pankaj\Application Data\CheckPoint
2011-12-25 03:35 . 2011-12-25 03:35 ——– d—–w- c:\documents and settings\Pankaj\Local Settings\Application Data\ZoneAlarm_Security
2011-12-25 03:35 . 2011-12-25 03:35 ——– d—–w- c:\program files\ZoneAlarm_Security
2011-12-25 03:34 . 2011-12-25 03:34 ——– d—–w- c:\documents and settings\All Users\Application Data\CheckPoint
2011-12-25 03:32 . 2011-12-25 03:34 ——– d—–w- c:\program files\CheckPoint
2011-12-25 01:49 . 2011-12-25 01:49 ——– d—–w- C:\_OTL
2011-12-22 08:31 . 2011-12-22 08:31 ——– d—–w- c:\program files\ESET
2011-12-22 07:40 . 2011-09-01 01:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-22 07:24 . 2011-12-22 07:24 ——– d—–w- c:\documents and settings\Pankaj\Local Settings\Application Data\AIM Toolbar
2011-12-21 18:22 . 2011-12-22 07:20 ——– d–h–w- c:\windows\$hf_mig$
2011-12-21 07:20 . 2011-12-21 07:20 ——– d—–w- c:\windows\system32\wbem\Repository
2011-12-20 06:14 . 2011-12-20 06:14 ——– d—–w- C:\TDSSKiller_Quarantine
2011-12-18 20:35 . 2006-02-10 08:31 ——– d—–w- C:\ubuntu(2)
2011-12-18 18:23 . 2006-02-10 08:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Intel(2)
2011-12-18 06:46 . 2011-12-18 06:46 ——– d—–w- c:\program files\CleanMyPC
2011-12-18 06:35 . 2011-12-18 06:35 ——– d—–w- c:\program files\Wise PC Doctor
2011-12-09 05:03 . 2011-12-09 05:03 ——– d—–w- c:\documents and settings\Pankaj\Local Settings\Application Data\Symantec
2011-12-09 05:02 . 2011-12-09 05:02 60800 —-a-w- c:\windows\system32\S32EVNT1.DLL
2011-12-09 05:02 . 2011-12-09 05:02 123952 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-12-09 05:00 . 2011-12-27 18:49 ——– d—–w- c:\program files\Symantec AntiVirus
2011-11-29 20:59 . 2011-11-29 20:59 ——– d—–w- c:\program files\AIM Toolbar
2011-11-29 20:59 . 2011-11-29 20:59 ——– d—–w- c:\program files\Common Files\Software Update Utility
2011-11-29 20:58 . 2011-11-29 20:58 ——– d—–w- c:\program files\AIM
2011-11-28 03:57 . 2011-11-28 03:57 ——– d—–w- c:\program files\Broadcom
2011-11-28 03:27 . 2011-11-28 03:27 ——– d—–w- c:\documents and settings\Pankaj\Application Data\Intel
2011-11-28 03:27 . 2010-10-07 13:11 6609920 —-a-w- c:\windows\system32\drivers\NETwLx32.sys
2011-11-28 03:27 . 2010-02-25 01:39 675840 —-a-w- c:\windows\system32\NETwLc32.dll
2011-11-28 03:27 . 2010-02-25 01:37 2756608 —-a-w- c:\windows\system32\NETwLr32.dll
2011-11-28 03:26 . 2011-11-28 03:26 ——– d—–w- c:\program files\Common Files\Intel
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-25 06:02 . 2011-11-25 06:02 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-23 13:25 . 2006-03-16 04:00 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-04 19:20 . 2006-03-16 04:00 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2006-03-16 04:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2006-03-16 04:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2006-03-16 04:00 385024 —-a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2006-03-16 04:00 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2006-03-16 04:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2006-03-16 04:00 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2006-03-16 04:00 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-15 01:38 . 2006-03-04 07:08 456192 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2006-03-16 04:00 692736 —-a-w- c:\windows\system32\inetcomm.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-12-23_02.37.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-27 18:37 . 2011-12-27 18:37 16384 c:\windows\Temp\Perflib_Perfdata_6d8.dat
+ 2006-06-29 18:27 . 2011-12-23 07:01 75686 c:\windows\system32\perfc009.dat
+ 2011-12-25 03:35 . 2011-12-25 03:35 62464 c:\windows\Installer\ba89f.msi
+ 2011-12-25 03:34 . 2011-12-25 03:34 28672 c:\windows\Installer\ba894.msi
+ 2011-12-25 03:34 . 2011-12-25 03:34 41472 c:\windows\Installer\ba889.msi
+ 2011-12-27 08:18 . 2011-12-27 08:18 83456 c:\windows\Installer\1b9032e.msi
+ 2011-12-27 08:18 . 2011-12-27 08:18 27136 c:\windows\Installer\1b90320.msi
+ 2009-03-17 05:28 . 2011-12-23 07:03 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-03-17 05:28 . 2011-12-22 07:39 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-03-17 05:28 . 2011-12-22 07:39 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-03-17 05:28 . 2011-12-23 07:03 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-03-17 05:28 . 2011-12-22 07:39 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-03-17 05:28 . 2011-12-23 07:03 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2011-12-27 18:09 . 2011-12-27 18:09 47616 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\1ee639a35730f580f0266d2466d3976d\WindowsLiveWriter.ni.exe
+ 2011-12-27 18:09 . 2011-12-27 18:09 99840 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\4490f2c7ba373caac054470763d7081d\WindowsLive.Writer.Api.ni.dll
+ 2011-12-23 07:56 . 2011-12-23 07:56 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\888b745ca99d39692c2e9af222e5eae8\UIAutomationProvider.ni.dll
+ 2011-12-23 09:47 . 2011-12-23 09:47 85504 c:\windows\assembly\NativeImages_v2.0.50727_32\ToadDataCompareAndS#\e56c9c7cfa863acf90bbdd1cde6c390e\ToadDataCompareAndSync.ni.dll
+ 2011-12-23 10:08 . 2011-12-23 10:08 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\6c334564da041df8fb75415f2d503224\System.Windows.Presentation.ni.dll
+ 2011-12-23 10:08 . 2011-12-23 10:08 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\a54a122f1070ab71931dd9679ddd8e90\System.Web.DynamicData.Design.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\ac92806d5bd508eb25f1b4b73a36b101\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\e6a9cd66d11a21776dbf425e8e28099c\System.AddIn.Contract.ni.dll
+ 2011-12-23 07:54 . 2011-12-23 07:54 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\66873b557d5c7013e4c630361473b0c2\PresentationFontCache.ni.exe
+ 2011-12-23 07:02 . 2011-12-23 07:02 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5b30652a7b802199984f93b5e414260f\PresentationCFFRasterizer.ni.dll
+ 2011-12-23 09:48 . 2011-12-23 09:48 68608 c:\windows\assembly\NativeImages_v2.0.50727_32\MySqlSchemaCompare\05c26b83a430a5a7ce59cb6094bf678b\MySqlSchemaCompare.ni.dll
+ 2011-12-23 09:45 . 2011-12-23 09:45 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\eaa8d72317e5b8047e413939cc71ffba\Microsoft.Vsa.ni.dll
+ 2011-12-23 07:57 . 2011-12-23 07:57 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\a140509b1342934fc5e58ae22ac9696c\Microsoft.VisualC.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\aefe683674c97a998f4e908c1a7ee7c6\Microsoft.Build.Framework.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\845eef4d09f28da6ee05d99f93c90f6e\Microsoft.Build.Framework.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\ab7ce2d94ca725c3889a4e3c1ee88ece\dfsvc.ni.exe
+ 2011-12-23 09:47 . 2011-12-23 09:47 97792 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraChar#\621fe1f8ea8829dccc27dbcea56279c4\DevExpress.XtraCharts.v8.3.UI.ni.dll
+ 2011-12-23 07:57 . 2011-12-23 07:57 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2011-12-22 07:36 . 2011-12-22 07:36 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2011-12-22 07:35 . 2011-12-22 07:35 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 11:54 . 2008-07-29 11:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2008-07-29 13:23 . 2008-07-29 13:23 626688 c:\windows\WinSxS\amd64_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_a17e7c1e\msvcr90.dll
+ 2008-07-29 13:23 . 2008-07-29 13:23 856576 c:\windows\WinSxS\amd64_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_a17e7c1e\msvcp90.dll
+ 2008-07-29 11:51 . 2008-07-29 11:51 245760 c:\windows\WinSxS\amd64_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_a17e7c1e\msvcm90.dll
+ 2011-11-10 04:01 . 2011-11-10 04:01 525840 c:\windows\system32\vsdatant.sys
+ 2006-06-29 18:27 . 2011-12-23 07:01 455738 c:\windows\system32\perfh009.dat
- 2006-03-04 07:08 . 2011-02-04 12:18 456192 c:\windows\system32\dllcache\encdec.dll
+ 2006-03-04 07:08 . 2011-10-15 01:38 456192 c:\windows\system32\dllcache\encdec.dll
+ 2011-03-25 14:15 . 2011-03-25 14:15 363856 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2011-03-18 04:03 . 2011-03-18 04:03 308736 c:\windows\Installer\2d0651d.msp
+ 2011-12-27 08:19 . 2011-12-27 08:19 569344 c:\windows\Installer\1b90335.msi
+ 2011-12-27 08:18 . 2011-12-27 08:18 155648 c:\windows\Installer\1b90327.msi
+ 2011-12-27 08:18 . 2011-12-27 08:18 140288 c:\windows\Installer\1b90319.msi
+ 2011-12-27 08:18 . 2011-12-27 08:18 202752 c:\windows\Installer\1b90312.msi
+ 2009-03-17 05:28 . 2011-12-23 07:03 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-03-17 05:28 . 2011-12-22 07:39 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-03-17 05:28 . 2011-12-23 07:03 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2009-03-17 05:28 . 2011-12-22 07:39 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2009-03-17 05:28 . 2011-12-23 07:03 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2009-03-17 05:28 . 2011-12-22 07:39 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2009-03-17 05:28 . 2011-12-22 07:39 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2009-03-17 05:28 . 2011-12-23 07:03 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2009-03-17 05:28 . 2011-12-22 07:39 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-03-17 05:28 . 2011-12-23 07:03 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2009-03-17 05:28 . 2011-12-22 07:39 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-03-17 05:28 . 2011-12-23 07:03 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-03-17 05:28 . 2011-12-23 07:03 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2009-03-17 05:28 . 2011-12-22 07:39 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2011-12-23 10:06 . 2011-12-23 10:06 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\c8627df7adb416722d8e0f05c57fef6b\WsatConfig.ni.exe
+ 2011-12-27 18:09 . 2011-12-27 18:09 626688 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\8d9744364ead927be159ddaca5c73b6a\WindowsLiveLocal.WriterPlugin.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 319488 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f3247ee4c8974dcb21978a283ca5dd37\WindowsLive.Writer.Interop.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 334848 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\de41662d8b5a65327eb32e4601b29734\WindowsLive.Writer.Interop.Mshtml.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 594944 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c3eeef28ef5d1fe19442fb127106e180\WindowsLive.Writer.HtmlEditor.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 108544 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\bb87acb24dd38a2a35c460e960909f26\WindowsLive.Writer.Passport.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 322048 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b9c42f04581b04b23db07d4d29e47a1d\WindowsLive.Writer.SpellChecker.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 174080 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\71caec3c513d97567d5196a72ee57ef0\WindowsLive.Writer.BrowserControl.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 118784 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\6adb0eaf9a145a2ba81619e49b1c4480\WindowsLive.Writer.Extensibility.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\599239bb43737ad8063b7e9620a4c16e\WindowsLive.Writer.FileDestinations.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 428032 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\49ab3a63512d9d028cc4fa800c1c3d2f\WindowsLive.Writer.Localization.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 313856 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\3ae7eae306c355e1efb728fac33b3965\WindowsLive.Writer.Interop.SHDocVw.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 851968 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\1fbb3941992cd85018b7c64a68dce3f8\WindowsLive.Writer.BlogClient.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 117760 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\14ddbf463c0b9b17f98d8f048777784a\WindowsLive.Writer.Instrumentation.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 843776 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\0c0afa682f30eb3e75011f1c92b04129\WindowsLive.Writer.Controls.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\097baf70e23eed55818deec43d26c44a\WindowsLive.Writer.Mshtml.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 152064 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\04473507f11eea12b260ab8b2707d423\WindowsLive.Writer.HtmlParser.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 145920 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\a295b8cfd7c63e29f4972592e2b7ef4b\WindowsLive.Client.ni.dll
+ 2011-12-23 07:56 . 2011-12-23 07:56 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\a2c1bb3c5b1447b398e72c56091ca571\WindowsFormsIntegration.ni.dll
+ 2011-12-23 07:56 . 2011-12-23 07:56 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\f102afdffdbe2565bcedb7fa0626b865\UIAutomationTypes.ni.dll
+ 2011-12-23 07:56 . 2011-12-23 07:56 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\ba55240b7753047f8d1b03ef473bf74e\UIAutomationClient.ni.dll
+ 2011-12-23 09:49 . 2011-12-23 09:49 775168 c:\windows\assembly\NativeImages_v2.0.50727_32\ToadMySQL\b57766a4837b5d5ea99eb4ff0b14fc34\ToadMySQL.ni.dll
+ 2011-12-23 09:47 . 2011-12-23 09:47 160768 c:\windows\assembly\NativeImages_v2.0.50727_32\ToadDiff\d199a7122bd52792e215a4f9b8ee5a55\ToadDiff.ni.dll
+ 2011-12-23 09:47 . 2011-12-23 09:47 882688 c:\windows\assembly\NativeImages_v2.0.50727_32\ToadCommon\6cdae9b8646e12820e41ae9ce8d3b52d\ToadCommon.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 966144 c:\windows\assembly\NativeImages_v2.0.50727_32\ToadAutomation\47c6214afbf92478ac3a7b74b771e552\ToadAutomation.ni.dll
+ 2011-12-23 10:08 . 2011-12-23 10:08 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\566b2e11e7f3f6d973b17b86cf42f9bc\System.Xml.Linq.ni.dll
+ 2011-12-23 10:08 . 2011-12-23 10:08 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\3533d614ebecd4344efbee619dd11a74\System.Web.Routing.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\018b6e48c32d5b5d78086998e3505f1c\System.Web.RegularExpressions.ni.dll
+ 2011-12-23 10:08 . 2011-12-23 10:08 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\d93514a764a83b18f6f3547b59cc8ae9\System.Web.Extensions.Design.ni.dll
+ 2011-12-23 10:08 . 2011-12-23 10:08 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\93b5d1b77a74b76ac73cbf51ec871c01\System.Web.Entity.ni.dll
+ 2011-12-23 10:08 . 2011-12-23 10:08 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\d06a7d5872bbe85795f947f6c75d38c6\System.Web.Entity.Design.ni.dll
+ 2011-12-23 10:08 . 2011-12-23 10:08 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\ad0851438a18bf730d974c9b2f5f776a\System.Web.DynamicData.ni.dll
+ 2011-12-23 10:08 . 2011-12-23 10:08 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\734ab0ea87d7dfd5c583eea535c05878\System.Web.Abstractions.ni.dll
+ 2011-12-23 07:57 . 2011-12-23 07:57 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\8efcd633af87989355382b5039f1b7df\System.Transactions.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll
+ 2011-12-23 07:57 . 2011-12-23 07:57 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\36c12de583ee81e9c99acb72b09d77ac\System.Security.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\81096bfe85eb0da5f05e8a127ffa43b2\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2011-12-23 07:57 . 2011-12-23 07:57 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\36bf3d5f05a40c9e3cadca5789c8a469\System.Runtime.Remoting.ni.dll
+ 2011-12-23 10:08 . 2011-12-23 10:08 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\b2a84980f206431821d85d5155d5916f\System.Net.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\8acd508fd65801747e89bb5ab7e981e4\System.Messaging.ni.dll
+ 2011-12-23 09:45 . 2011-12-23 09:45 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\90b90e700e59d73d6d692cf74e1ba16e\System.Management.ni.dll
+ 2011-12-23 10:08 . 2011-12-23 10:08 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\f36eded354122da9555a6c7cdbdb5431\System.Management.Instrumentation.ni.dll
+ 2011-12-23 09:49 . 2011-12-23 09:49 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\20a77c41ee12362d303fb2574fcd5a24\System.IO.Log.ni.dll
+ 2011-12-23 09:49 . 2011-12-23 09:49 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\41c3a2fcffc58b20023c7d54e57ea956\System.IdentityModel.Selectors.ni.dll
+ 2011-12-23 07:57 . 2011-12-23 07:57 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.Wrapper.dll
+ 2011-12-23 07:57 . 2011-12-23 07:57 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.ni.dll
+ 2011-12-23 07:55 . 2011-12-23 07:55 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\896eca06e2d9377b2dc4fad56ce49b07\System.Drawing.Design.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\33e9b0c368c31ef37a2ec7b5a181044b\System.DirectoryServices.Protocols.ni.dll
+ 2011-12-23 10:08 . 2011-12-23 10:08 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\11cdd1c0d65428cd3505d3813d36638c\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-12-23 10:07 . 2011-12-23 10:07 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\e5ada332a9bc3c982e6aede6ba354196\System.Data.Services.Client.ni.dll
+ 2011-12-23 10:08 . 2011-12-23 10:08 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\3f179f373f31817a914b639a56cc0497\System.Data.Services.Design.ni.dll
+ 2011-12-23 10:07 . 2011-12-23 10:07 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\fee1a48b769a8c4beb335ee5ce006091\System.Data.Entity.Design.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\b9d9ff5d03e90ede1116794f2c7dd6da\System.Data.DataSetExtensions.ni.dll
+ 2011-12-23 07:57 . 2011-12-23 07:57 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\29d7091f6eab0ec61c4eb625ed221b73\System.Configuration.Install.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\3048737e9e3bf5173121a084337256bc\System.AddIn.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\6e45cf503f025c5fe814ea7e52f62a78\SMSvcHost.ni.exe
+ 2011-12-23 10:06 . 2011-12-23 10:06 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\474a341340f687bcbd7777f2820a8c7a\SMDiagnostics.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\f2df1ca28301bfe7e1d52b86c8394217\ServiceModelReg.ni.exe
+ 2011-12-23 09:46 . 2011-12-23 09:46 134144 c:\windows\assembly\NativeImages_v2.0.50727_32\Quest.JobManagement#\6a1bb60a874adc635079713614761025\Quest.JobManagement.UI.Plugin.ni.dll
+ 2011-12-23 06:59 . 2011-12-23 06:59 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d548bacfbb5e860debf12027d4b753ae\PresentationFramework.Classic.ni.dll
+ 2011-12-23 07:54 . 2011-12-23 07:54 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c2ebcc8d60422f224b4088f3d7a2ac1f\PresentationFramework.Luna.ni.dll
+ 2011-12-23 07:54 . 2011-12-23 07:54 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\94cfc00ad448575bfb0e67c53b514cd5\PresentationFramework.Aero.ni.dll
+ 2011-12-23 07:54 . 2011-12-23 07:54 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\478d57d96f3d8d5fc15c7ac635a4a6a1\PresentationFramework.Classic.ni.dll
+ 2011-12-23 06:59 . 2011-12-23 06:59 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\24b04dd14603fb47394499ecfedc4afb\PresentationFramework.Royale.ni.dll
+ 2011-12-23 07:54 . 2011-12-23 07:54 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\23c5852ff8ed973ff9b63ce9ba7f91f0\PresentationFramework.Royale.ni.dll
+ 2011-12-23 06:59 . 2011-12-23 06:59 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\0a1dbf17855d43bdf5c904709fdfe1cd\PresentationFramework.Aero.ni.dll
+ 2011-12-23 06:59 . 2011-12-23 06:59 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\088d16321ba4b13795060bb8b9bc4d09\PresentationFramework.Luna.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\04595f414c49cf2a65b349648ba23e62\MSBuild.ni.exe
+ 2011-12-23 07:57 . 2011-12-23 07:57 863744 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Web.Autho#\56a6d3ad3fd82877c4bc5cdde10f7f75\Microsoft.Web.Authoring.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\4cbd7ed9fbf9f1b3cbdf23906cc0f5a3\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\ff6d4892775fd1f9b137f7c92ea453f2\Microsoft.Build.Utilities.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\47ff0720cb80a0fc0bbd15ddc3d12adc\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\da112c5757e3c68d6369b6aa46cc9682\Microsoft.Build.Engine.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\dc278e1123086ae32fec8f7e9751db14\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2011-12-23 09:44 . 2011-12-23 09:44 879104 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraNavB#\4d6cfd8e8689d239304cdcb74d10885b\DevExpress.XtraNavBar.v8.3.ni.dll
+ 2011-12-23 09:45 . 2011-12-23 09:45 453120 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.Charts.v#\19d9ebeba112fdceb1af9d3bf3c911a8\DevExpress.Charts.v8.3.Core.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\3e6deccf191ab943d3a0812a38ab5c97\CustomMarshalers.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\4e68d5df30b197ff72c75f1c3c24b949\ComSvcConfig.ni.exe
+ 2011-12-23 07:57 . 2011-12-23 07:57 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\e1bcee92f5af50d560d577c0a99ea3bd\AspNetMMCExt.ni.dll
+ 2011-12-23 09:45 . 2011-12-23 09:45 574976 c:\windows\assembly\NativeImages_v2.0.50727_32\ActiproSoftware.Win#\ee9141de81dafb0c106947997b2af799\ActiproSoftware.WinUICore.Net20.ni.dll
+ 2011-12-23 09:45 . 2011-12-23 09:45 781824 c:\windows\assembly\NativeImages_v2.0.50727_32\ActiproSoftware.Sha#\4c4f56960fe9ffc54fe45e6ae85186c3\ActiproSoftware.Shared.Net20.ni.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2011-12-22 07:36 . 2011-12-22 07:36 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2011-12-22 07:36 . 2011-12-22 07:36 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2011-12-22 07:36 . 2011-12-22 07:36 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2011-12-22 07:36 . 2011-12-22 07:36 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2011-12-22 07:36 . 2011-12-22 07:36 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2011-12-22 07:36 . 2011-12-22 07:36 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-03-25 14:15 . 2011-03-25 14:15 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
- 2008-07-25 05:47 . 2008-07-25 05:47 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2011-04-29 05:50 . 2011-04-29 05:50 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
- 2010-03-23 00:02 . 2010-03-23 00:02 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2011-05-02 08:06 . 2011-05-02 08:06 2705920 c:\windows\Installer\2d064fc.msp
- 2009-03-17 05:28 . 2011-12-22 07:39 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-03-17 05:28 . 2011-12-23 07:03 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-03-17 05:28 . 2011-12-23 07:03 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2009-03-17 05:28 . 2011-12-22 07:39 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2011-12-27 18:09 . 2011-12-27 18:09 2018816 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\dec788a098576594112a08bb0bf21d95\WindowsLive.Writer.CoreServices.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 1105920 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\6ea9639305271fc22aa925a7356d7db6\WindowsLive.Writer.ApplicationFramework.ni.dll
+ 2011-12-27 18:09 . 2011-12-27 18:09 6392832 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\3203e91891cafbbb289bcde65e6a8389\WindowsLive.Writer.PostEditor.ni.dll
+ 2011-12-23 07:03 . 2011-12-23 07:03 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1adc4ae51a5ac63e896a1402749ca495\WindowsBase.ni.dll
+ 2011-12-23 07:56 . 2011-12-23 07:56 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\55d4813580b1e5d268ff0564942cee9c\UIAutomationClientsideProviders.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 1177088 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP39.tmp\DevExpress.XtraVerticalGrid.v8.3.dll
+ 2011-12-23 07:02 . 2011-12-23 07:02 7950848 c:\windows\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll
+ 2011-12-23 07:56 . 2011-12-23 07:56 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll
+ 2011-12-23 10:08 . 2011-12-23 10:08 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\17902fdb0e0d3bc8b49bce693415fe7e\System.WorkflowServices.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\f72c5f649951b0403e62bfab6c453e6f\System.Workflow.Runtime.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\0aa4f4174204c93cc5181df4a6b2fb09\System.Workflow.ComponentModel.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\921629dc69a5a895101097c88ae67897\System.Workflow.Activities.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\6303e256d2ac0843c3e4c24172c90544\System.Web.Services.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\f5dac0448a1dbe2687a5df92904d6274\System.Web.Mobile.ni.dll
+ 2011-12-23 10:08 . 2011-12-23 10:08 2405376 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\ccaf6bdd256a9b5079fedadcc8993327\System.Web.Extensions.ni.dll
+ 2011-12-23 07:55 . 2011-12-23 07:55 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\10d7daa3d1e62a0e40587cdc707be93f\System.Speech.ni.dll
+ 2011-12-23 10:08 . 2011-12-23 10:08 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\9ec7da53380a754b4ad97709df0dd7e7\System.ServiceModel.Web.ni.dll
+ 2011-12-23 09:49 . 2011-12-23 09:49 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\afd6134c090faf8c29cd64d4835142b2\System.Runtime.Serialization.ni.dll
+ 2011-12-23 07:55 . 2011-12-23 07:55 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\0f8e14bfdb27645fb1a92ce26f9bf521\System.Printing.ni.dll
+ 2011-12-23 09:49 . 2011-12-23 09:49 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\d14065ede44df8e9b5d6b60c5ddccc69\System.IdentityModel.ni.dll
+ 2011-12-23 07:55 . 2011-12-23 07:55 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll
+ 2011-12-23 07:57 . 2011-12-23 07:57 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\91cd88a803768151c6262853d3454ba7\System.DirectoryServices.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\cc5ac99e8af2738e85cda5525fdd944f\System.Deployment.ni.dll
+ 2011-12-23 07:55 . 2011-12-23 07:55 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\ec323cf1df697cc0a45f67de685db90c\System.Data.ni.dll
+ 2011-12-23 07:57 . 2011-12-23 07:57 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\ef748704f543a8791e23387652d34dfb\System.Data.SqlXml.ni.dll
+ 2011-12-23 10:07 . 2011-12-23 10:07 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\541142d8742e6e88f1e729fafee04e71\System.Data.Services.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 1115136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\5d5aa4b926ae422607ea833d934665c2\System.Data.OracleClient.ni.dll
+ 2011-12-23 07:55 . 2011-12-23 07:55 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\d96a94076acb8e0c5a96a1b2de4b3a7a\System.Data.Linq.ni.dll
+ 2011-12-23 10:07 . 2011-12-23 10:07 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\a3ce22c2a84fdcb008d72d230ee0b2c0\System.Data.Entity.ni.dll
+ 2011-12-23 07:55 . 2011-12-23 07:55 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\d507b9e0e50e453793ee5e01c07a5485\System.Core.ni.dll
+ 2011-12-23 07:55 . 2011-12-23 07:55 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\714e9504255565bd9076fe13628e104a\ReachFramework.ni.dll
+ 2011-12-23 07:54 . 2011-12-23 07:54 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\7dc6ee14234b0686182ced75f7dae990\PresentationUI.ni.dll
+ 2011-12-23 07:02 . 2011-12-23 07:02 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b42ad515bb20ec1f1250c040371c6730\PresentationBuildTasks.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 1602048 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Web.Desig#\2de2ff5885b6b229ac31203f193b0b3e\Microsoft.Web.Design.Client.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\24331b719aa25ac2b21099e32232840c\Microsoft.VisualBasic.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\ce1ecd602ca089eb13a9b428dc7f0449\Microsoft.Transactions.Bridge.ni.dll
+ 2011-12-23 09:45 . 2011-12-23 09:45 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\8ad32b72258899177c07dc5912b5b748\Microsoft.JScript.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\50e7c5eb58c982dba7b21cd10a69b095\Microsoft.Build.Tasks.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\415cef6abab5bb959f200f6c537bc289\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\eea7bcc8d356e3f2dcb4f36dfc1c6bc0\Microsoft.Build.Engine.ni.dll
+ 2011-12-23 09:45 . 2011-12-23 09:45 1757696 c:\windows\assembly\NativeImages_v2.0.50727_32\MailBee.NET\e6e28b607e71cad3b78a076c837c276c\MailBee.NET.ni.dll
+ 2011-12-23 09:41 . 2011-12-23 09:41 1177088 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraVert#\ff6928b52a322d53023e509a5a49a742\DevExpress.XtraVerticalGrid.v8.3.ni.dll
+ 2011-12-23 09:43 . 2011-12-23 09:43 1487872 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraTree#\e51c285b25e6ebd0ac19cce858226c05\DevExpress.XtraTreeList.v8.3.ni.dll
+ 2011-12-23 09:43 . 2011-12-23 09:43 6637568 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraRich#\1ff9b04e88f24d268d09bb9be3767872\DevExpress.XtraRichEdit.v8.3.ni.dll
+ 2011-12-23 09:42 . 2011-12-23 09:42 6495744 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraRepo#\05cd0aead7a1620245a211516501231f\DevExpress.XtraReports.v8.3.ni.dll
+ 2011-12-23 09:43 . 2011-12-23 09:43 4459008 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraPrin#\7ffa77dd6594090d35b690b3c5481c23\DevExpress.XtraPrinting.v8.3.ni.dll
+ 2011-12-23 09:44 . 2011-12-23 09:44 1084416 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraPivo#\9db477cf9b33b4f86f540b54fd370724\DevExpress.XtraPivotGrid.v8.3.ni.dll
+ 2011-12-23 09:44 . 2011-12-23 09:44 1388544 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraPivo#\84dfdfc5584cdc5f667bc345c69903ba\DevExpress.XtraPivotGrid.v8.3.Core.ni.dll
+ 2011-12-23 09:46 . 2011-12-23 09:46 1994240 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraLayo#\ad0ae209500b821c5540497e30ad7ef2\DevExpress.XtraLayout.v8.3.ni.dll
+ 2011-12-23 09:46 . 2011-12-23 09:46 4532224 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraGrid#\6142774b9261ff5fee10dd6a66f690d9\DevExpress.XtraGrid.v8.3.ni.dll
+ 2011-12-23 09:42 . 2011-12-23 09:42 4737536 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraEdit#\bd4ecfcb20d391564ff76994c30d8a30\DevExpress.XtraEditors.v8.3.ni.dll
+ 2011-12-23 09:44 . 2011-12-23 09:44 5067776 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraBars#\578743771810956811995477b2acc3d4\DevExpress.XtraBars.v8.3.ni.dll
+ 2011-12-23 09:41 . 2011-12-23 09:41 6646272 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.Utils.v8#\ffd72e546d55a822c2034c574ab57a31\DevExpress.Utils.v8.3.ni.dll
+ 2011-12-23 09:42 . 2011-12-23 09:42 2352640 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.Data.v8.3\afce49fad080749f6244012e6ba4360d\DevExpress.Data.v8.3.ni.dll
+ 2011-12-23 09:45 . 2011-12-23 09:45 2073088 c:\windows\assembly\NativeImages_v2.0.50727_32\ActiproSoftware.UIS#\b429e1699f42381fce531253b82d3dcb\ActiproSoftware.UIStudio.Dock.Net20.ni.dll
+ 2011-12-23 09:47 . 2011-12-23 09:47 3555328 c:\windows\assembly\NativeImages_v2.0.50727_32\ActiproSoftware.Syn#\9c7146261d7241eb0ea97264a42c5c4c\ActiproSoftware.SyntaxEditor.Net20.ni.dll
- 2011-12-22 07:36 . 2011-12-22 07:36 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2011-12-22 07:36 . 2011-12-22 07:36 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2011-12-22 07:36 . 2011-12-22 07:36 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2011-12-22 07:35 . 2011-12-22 07:35 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-12-23 07:01 . 2011-12-23 07:01 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-03-28 11:27 . 2011-03-28 11:27 15456256 c:\windows\Installer\2d06506.msp
+ 2011-12-23 07:55 . 2011-12-23 07:56 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll
+ 2011-12-23 07:58 . 2011-12-23 07:58 11800576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\60df958ca96c9b8945f836759b6abd34\System.Web.ni.dll
+ 2011-12-23 10:06 . 2011-12-23 10:06 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\ceadaf3b3d017c7a1ef10a06f8009f6f\System.ServiceModel.ni.dll
+ 2011-12-23 07:55 . 2011-12-23 07:55 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\c6374d32e4af7b7e3e46b32176f76558\System.Design.ni.dll
+ 2011-12-23 07:54 . 2011-12-23 07:54 14328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\054488924fcc579cce9fa0209dafe28b\PresentationFramework.ni.dll
+ 2011-12-23 07:54 . 2011-12-23 07:54 12215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\b2f0318713eca304eaa9d86fc17edb96\PresentationCore.ni.dll
+ 2011-12-23 07:02 . 2011-12-23 07:02 11490816 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
+ 2011-12-23 09:44 . 2011-12-23 09:45 12172800 c:\windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraChar#\5557fc34107d817b9e05611542976fa0\DevExpress.XtraCharts.v8.3.ni.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTor.dll" [2011-05-09 176936]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\prxtbZone.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
2011-05-09 09:49 176936 —-a-w- c:\program files\ZoneAlarm_Security\prxtbZone.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2011-05-09 09:49 176936 —-a-w- c:\program files\uTorrentBar\prxtbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTor.dll" [2011-05-09 176936]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\prxtbZone.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2007-07-28 1360304]
"Registry Cleaner Scheduler"="c:\program files\CleanMyPC\Registry Cleaner\RCHelper.exe" [2011-10-06 1401224]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"MsmqIntCert"="mqrt.dll" [2008-04-14 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-23 61952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-17 794713]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-26 7561216]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2011-06-23 1407248]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-06-23 1210640]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-08-03 53096]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2009-09-01 125368]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2011-11-03 738944]
"ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2011-11-10 73360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-12 581693]
HP Pavilion Webcam Tray Icon.lnk - c:\program files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe [2009-11-2 102400]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,32,\
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor Apache Servers.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Monitor Apache Servers.lnk
backup=c:\windows\pss\Monitor Apache Servers.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Pankaj^Start Menu^Programs^StartUp^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Pankaj\Start Menu\Programs\StartUp\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Pankaj^Start Menu^Programs^StartUp^OneNote Table Of Contents.onetoc2]
path=c:\documents and settings\Pankaj\Start Menu\Programs\StartUp\OneNote Table Of Contents.onetoc2
backup=c:\windows\pss\OneNote Table Of Contents.onetoc2Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 20:55 937920 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim]
2011-05-03 15:43 4321112 —-a-w- c:\program files\AIM\aim.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\autoMe]
2008-05-08 11:24 155648 —-a-w- c:\windows\system32\wscript.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2011-12-02 06:37 137536 —-atw- c:\documents and settings\Pankaj\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-03-22 15:31 133104 —-atw- c:\documents and settings\Pankaj\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 06:14 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-16 15:11 49152 -c–a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
2006-03-15 20:00 44032 —-a-w- c:\windows\ime\imkr6_1\imekrmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2006-03-15 20:00 208952 —-a-w- c:\windows\ime\imjp8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-08 15:39 305440 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Memeo Instant Backup]
2010-04-23 00:33 136416 —-a-w- c:\program files\Memeo\AutoBackup\MemeoLauncher2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
2006-03-15 20:00 59392 —-a-w- c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-04-26 19:48 7561216 —-a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-04-26 19:48 1519616 -c–a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2006-03-15 20:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2006-03-15 20:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
2006-06-19 03:33 163840 —-a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2006-07-11 13:55 102400 -c–a-w- c:\program files\HP\QuickPlay\QPService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 20:24 417792 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecGuard]
2005-10-11 02:23 1187840 —-a-w- c:\windows\SMINST\Recguard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Seagate Dashboard]
2010-04-30 14:47 79112 —-a-w- c:\program files\Seagate\Seagate Dashboard\MemeoLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2007-06-13 02:46 528384 -c–a-r- c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 06:14 248552 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-11-25 05:31 642424 —-a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2006-10-18 15:35 204288 ——w- c:\program files\Windows Media Player\wmpnscfg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=2 (0x2)
"Tomcat5"=3 (0x3)
"OracleServiceORACLE9I"=2 (0x2)
"OracleOraHome92TNSListener"=2 (0x2)
"OracleOraHome92SNMPPeerMasterAgent"=3 (0x3)
"OracleOraHome92SNMPPeerEncapsulator"=3 (0x3)
"OracleOraHome92PagingServer"=3 (0x3)
"OracleOraHome92HTTPServer"=2 (0x2)
"OracleOraHome92ClientCache"=3 (0x3)
"OracleOraHome92Agent"=2 (0x2)
"OracleMTSRecoveryService"=2 (0x2)
"gusvc"=2 (0x2)
"gupdate1c9c5eed03863b2"=2 (0x2)
"MySQL"=2 (0x2)
"iPod Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"Apache2.2"=2 (0x2)
"VC7SecS"=2 (0x2)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"FirebirdServerDefaultInstance"=3 (0x3)
"FirebirdGuardianDefaultInstance"=2 (0x2)
"SeagateDashboardService"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"MemeoBackgroundService"=2 (0x2)
"LightScribeService"=2 (0x2)
"hpqwmiex"=2 (0x2)
"gupdatem"=3 (0x3)
"AddFiltr"=3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\Pankaj\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Pankaj\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"\\??\\c:\\WINDOWS\\system32\\winlogon.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Pankaj\\Local Settings\\Application Data\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"c:\\Documents and Settings\\Pankaj\\Desktop\\Extra Document\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"60006:TCP"= 60006:TCP:Bitcomet 60006 TCP
"60006:UDP"= 60006:UDP:Bitcomet 60006 UDP
"3306:TCP"= 3306:TCP:MySQL Server
"60000:TCP"= 60000:TCP:BitComet 60000 TCP
"60000:UDP"= 60000:UDP:BitComet 60000 UDP
.
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [11/3/2011 6:44 AM 27016]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [11/3/2011 6:44 AM 497280]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [12/8/2011 9:33 PM 106104]
R3 NETwLx32; Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [11/27/2011 7:27 PM 6609920]
S1 vdrv7000;vdrv7000;c:\windows\system32\DRIVERS\vdrv7000.sys –> c:\windows\system32\DRIVERS\vdrv7000.sys [?]
S2 NecUsb;USB Service;c:\windows\System32\svchost.exe -k NecUsbSevice [3/15/2006 8:00 PM 14336]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 PROCEXP150;PROCEXP150;\??\c:\windows\system32\Drivers\PROCEXP150.SYS –> c:\windows\system32\Drivers\PROCEXP150.SYS [?]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\drivers\s115bus.sys [3/22/2009 1:24 AM 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\drivers\s115mdfl.sys [3/22/2009 1:24 AM 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\drivers\s115mdm.sys [3/22/2009 1:24 AM 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s115mgmt.sys [3/22/2009 1:25 AM 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\drivers\s115obex.sys [3/22/2009 1:25 AM 98568]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [9/1/2009 1:15 PM 116664]
S4 Apache2.2;Apache2.2;c:\program files\Apache Software Foundation\Apache2.2\bin\httpd.exe [9/28/2009 9:11 AM 24645]
S4 gupdate1c9c5eed03863b2;Google Update Service (gupdate1c9c5eed03863b2);c:\program files\Google\Update\GoogleUpdate.exe [4/25/2009 1:43 PM 133104]
S4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/25/2009 1:43 PM 133104]
S4 MemeoBackgroundService;MemeoBackgroundService;c:\program files\Memeo\AutoBackup\MemeoBackgroundService.exe [4/22/2010 4:33 PM 25824]
S4 OracleServiceORACLE9I;OracleServiceORACLE9I;c:\oracle\ora92\bin\ORACLE.EXE ORACLE9I –> c:\oracle\ora92\bin\ORACLE.EXE ORACLE9I [?]
S4 SeagateDashboardService;Seagate Dashboard Service;c:\program files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [4/30/2010 6:47 AM 14088]
S4 Tomcat5;Apache Tomcat;c:\program files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe [8/28/2008 7:12 PM 57344]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WUAUSERV
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
NecUsbSevice REG_MULTI_SZ NecUsb
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3641525057-1712457974-3760122168-1005Core.job
- c:\documents and settings\Pankaj\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-12-02 06:37]
.
2011-12-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3641525057-1712457974-3760122168-1005UA.job
- c:\documents and settings\Pankaj\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-12-02 06:37]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.Google.com
mStart Page = hxxp://www.Google.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\Pankaj\Application Data\Mozilla\Firefox\Profiles\lctr927l.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com/?src=aim&ncid=snsusaimc00000001
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: SearchPreview: {EF522540-89F5-46b9-B6FE-1829E2B572C6} - %profile%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF - Ext: ZoneAlarm Security Community Toolbar: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - %profile%\extensions\{91da5e8a-3318-4f8c-b67e-5964de3ab546}
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-27 11:13
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OracleOraHome92TNSListener]
"ImagePath"="c:\oracle\ora92\BIN\TNSLSNR "
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1000)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'lsass.exe'(1056)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Completion time: 2011-12-27 11:18:43
ComboFix-quarantined-files.txt 2011-12-27 19:18
ComboFix2.txt 2011-12-23 02:40
ComboFix3.txt 2011-12-21 06:52
.
Pre-Run: 25,995,579,392 bytes free
Post-Run: 26,009,980,928 bytes free
.
- - End Of File - - 7943D40C368A95957E874B3FA4B2D6EB

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI