This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

need help have trojan horsePSW.Agent [Solved]

61 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm running an older Del desktop pentium 4 with WindowsXP. I've aquired a Trojan HorsePSW.Agent.ASTO in my sytem 32 drivers file, and can't get rid of it. I have run the program "hijackthis" and the log information is below:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:12:21 PM, on 2/11/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\admin\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=5060919
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O2 - BHO: Inbox Toolbar - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O3 - Toolbar: &Inbox Toolbar - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\admin\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1159284260343
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://camera6.buffalotrace.com/activex/AMC.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://cam2.asa.utk.edu/activex/AxisCamControl.cab
O16 - DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} (AudioHandlerEmbedded) - http://www.boydsnest-ti.com/activex/AMC.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://205.241.135.70/activex/AMC.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intuit Update Service v4 (IntuitUpdateServiceV4) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 8511 bytes


Thank you in advance for any help,
spidey52
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

First we need to make all files and folders VISIBLE:

  • Go to Start >> Control Panel >> Folder Options >> View
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with ok
———-

Please download DDS from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe. :)
Hi spidey,

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.

If you would like to format and reinstall your Operating System please let me know and we can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help. :)
———-

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
Hi spidey,

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
———-

In your next reply please post the logs made by TDSSKiller and ComboFix. :)
Hi Jeff, Here's the logs from TDSkiller and combo fix. the computer is still up and working………………pretty slow and can't change the monitor settings(you be half blind and still see the icons they are so large). I appreciate all the help, spidey
Hi spidey, While I am looking over the ComboFix log could you please post the log made by TDSSKiller? You attached two ComboFix logs. :) Oh…could you please just copy/paste the logs into your replies as well? It makes it easier for me to read. Thanks.
Jeff, Sorry for the confussion, had a hard time finding the log…………….. 21:00:12.0343 2588 TDSS rootkit removing tool [removed] Feb 9 2012 10:12:57 21:00:13.0671 2588 ============================================================ 21:00:13.0671 2588 Current date / time: 2012/02/12 21:00:13.0671 21:00:13.0671 2588 SystemInfo: 21:00:13.0671 2588 21:00:13.0671 2588 OS Version: 5.1.2600 ServicePack: 3.0 21:00:13.0671 2588 Product type: Workstation 21:00:13.0671 2588 ComputerName: BRUCE 21:00:13.0671 2588 UserName: admin 21:00:13.0671 2588 Windows directory: C:\WINDOWS 21:00:13.0671 2588 System windows directory: C:\WINDOWS 21:00:13.0671 2588 Processor architecture: Intel x86 21:00:13.0671 2588 Number of processors: 1 21:00:13.0671 2588 Page size: 0x1000 21:00:13.0671 2588 Boot type: Normal boot 21:00:13.0671 2588 ============================================================ 21:00:17.0828 2588 Drive \Device\Harddisk0\DR0 - Size: 0x2540BE4000 (149.01 Gb), SectorSize: 0x200, Cylinders: 0x4BFC, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 21:00:17.0843 2588 Drive \Device\Harddisk1\DR1 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 21:00:17.0843 2588 \Device\Harddisk0\DR0: 21:00:17.0843 2588 MBR used 21:00:17.0843 2588 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x139C5, BlocksNum 0xD92C09F 21:00:17.0843 2588 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xD93FA64, BlocksNum 0x49F411B 21:00:17.0843 2588 \Device\Harddisk1\DR1: 21:00:17.0843 2588 MBR used 21:00:17.0843 2588 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x950E482 21:00:17.0984 2588 Initialize success 21:00:17.0984 2588 ============================================================ 21:00:23.0859 3712 ============================================================ 21:00:23.0859 3712 Scan started 21:00:23.0859 3712 Mode: Manual; 21:00:23.0859 3712 ============================================================ 21:00:27.0656 3712 Abiosdsk - ok 21:00:28.0015 3712 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 21:00:28.0015 3712 abp480n5 - ok 21:00:28.0281 3712 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 21:00:28.0296 3712 ACPI - ok 21:00:28.0703 3712 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 21:00:28.0703 3712 ACPIEC - ok 21:00:29.0140 3712 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 21:00:29.0140 3712 adpu160m - ok 21:00:29.0671 3712 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 21:00:29.0796 3712 aec - ok 21:00:30.0468 3712 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 21:00:30.0515 3712 AFD - ok 21:00:30.0859 3712 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 21:00:30.0859 3712 agp440 - ok 21:00:31.0265 3712 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 21:00:31.0296 3712 agpCPQ - ok 21:00:32.0156 3712 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 21:00:32.0203 3712 Aha154x - ok 21:00:32.0640 3712 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 21:00:32.0671 3712 aic78u2 - ok 21:00:33.0312 3712 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 21:00:33.0312 3712 aic78xx - ok 21:00:33.0562 3712 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 21:00:33.0593 3712 AliIde - ok 21:00:33.0750 3712 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys 21:00:33.0750 3712 alim1541 - ok 21:00:33.0875 3712 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys 21:00:33.0875 3712 amdagp - ok 21:00:33.0921 3712 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 21:00:33.0921 3712 amsint - ok 21:00:33.0968 3712 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 21:00:33.0968 3712 asc - ok 21:00:34.0015 3712 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 21:00:34.0031 3712 asc3350p - ok 21:00:34.0078 3712 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 21:00:34.0078 3712 asc3550 - ok 21:00:34.0281 3712 ASCTRM (d880831279ed91f9a4190a2db9539ea9) C:\WINDOWS\system32\drivers\ASCTRM.sys 21:00:34.0281 3712 ASCTRM - ok 21:00:34.0421 3712 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 21:00:34.0421 3712 AsyncMac - ok 21:00:34.0546 3712 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\ATAPI.SYS 21:00:34.0546 3712 atapi - ok 21:00:34.0593 3712 Atdisk - ok 21:00:34.0734 3712 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 21:00:34.0734 3712 Atmarpc - ok 21:00:34.0812 3712 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 21:00:34.0812 3712 audstub - ok 21:00:34.0953 3712 AVGIDSDriver (4fa401b33c1b50c816486f6951244a14) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys 21:00:34.0953 3712 AVGIDSDriver - ok 21:00:35.0140 3712 AVGIDSEH (69578bc9d43d614c6b3455db4af19762) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys 21:00:35.0140 3712 AVGIDSEH - ok 21:00:35.0250 3712 AVGIDSFilter (6df528406aa22201f392b9b19121cd6f) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys 21:00:35.0250 3712 AVGIDSFilter - ok 21:00:35.0359 3712 AVGIDSShim (1e01c2166b5599802bcd61b9691f7476) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys 21:00:35.0359 3712 AVGIDSShim - ok 21:00:35.0484 3712 Avgldx86 (bf8118cd5e2255387b715b534d64acd1) C:\WINDOWS\system32\DRIVERS\avgldx86.sys 21:00:35.0500 3712 Avgldx86 - ok 21:00:35.0703 3712 Avgmfx86 (1c77ef67f196466adc9924cb288afe87) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 21:00:35.0718 3712 Avgmfx86 - ok 21:00:35.0828 3712 Avgrkx86 (f2038ed7284b79dcef581468121192a9) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys 21:00:35.0828 3712 Avgrkx86 - ok 21:00:35.0968 3712 Avgtdix (a6d562b612216d8d02a35ebeb92366bd) C:\WINDOWS\system32\DRIVERS\avgtdix.sys 21:00:35.0984 3712 Avgtdix - ok 21:00:36.0078 3712 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 21:00:36.0078 3712 Beep - ok 21:00:36.0390 3712 catchme - ok 21:00:36.0546 3712 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 21:00:36.0546 3712 cbidf - ok 21:00:37.0640 3712 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 21:00:37.0640 3712 cbidf2k - ok 21:00:37.0671 3712 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 21:00:37.0687 3712 cd20xrnt - ok 21:00:37.0734 3712 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 21:00:37.0750 3712 Cdaudio - ok 21:00:37.0843 3712 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 21:00:37.0843 3712 Cdfs - ok 21:00:37.0968 3712 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 21:00:38.0015 3712 Cdrom - ok 21:00:38.0093 3712 Changer - ok 21:00:38.0265 3712 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 21:00:38.0265 3712 CmdIde - ok 21:00:38.0343 3712 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 21:00:38.0343 3712 Cpqarray - ok 21:00:38.0468 3712 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 21:00:38.0484 3712 dac2w2k - ok 21:00:38.0515 3712 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 21:00:38.0515 3712 dac960nt - ok 21:00:38.0671 3712 DELL_A02 (f45086cd562b583dcbe4459d4dcf3a32) C:\WINDOWS\system32\DRIVERS\PRISMA02.sys 21:00:38.0687 3712 DELL_A02 - ok 21:00:38.0859 3712 DigiartyVirtualCDBus (74c79938aa7b65b17d8e7722bd602095) C:\WINDOWS\system32\drivers\DigiartyVirtualCDBus.sys 21:00:38.0875 3712 DigiartyVirtualCDBus - ok 21:00:39.0015 3712 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 21:00:39.0015 3712 Disk - ok 21:00:39.0125 3712 DLABMFSM (0659e6e0a95564f958d9df7313f7701e) C:\WINDOWS\system32\DLA\DLABMFSM.SYS 21:00:39.0125 3712 DLABMFSM - ok 21:00:39.0234 3712 DLABOIOM (8691c78908f0bd66170669db268369f2) C:\WINDOWS\system32\DLA\DLABOIOM.SYS 21:00:39.0234 3712 DLABOIOM - ok 21:00:39.0359 3712 DLACDBHM (76167b5eb2dffc729edc36386876b40b) C:\WINDOWS\system32\Drivers\DLACDBHM.SYS 21:00:39.0406 3712 DLACDBHM - ok 21:00:39.0562 3712 DLADResM (5615744a1056933b90e6ac54feb86f35) C:\WINDOWS\system32\DLA\DLADResM.SYS 21:00:39.0562 3712 DLADResM - ok 21:00:39.0640 3712 DLAIFS_M (1aeca2afa5005ce4a550cf8eb55a8c88) C:\WINDOWS\system32\DLA\DLAIFS_M.SYS 21:00:39.0703 3712 DLAIFS_M - ok 21:00:39.0859 3712 DLAOPIOM (840e7f6abb885c72b9ffddb022ef5b6d) C:\WINDOWS\system32\DLA\DLAOPIOM.SYS 21:00:39.0859 3712 DLAOPIOM - ok 21:00:39.0921 3712 DLAPoolM (0294d18731ac05da80132ce88f8a876b) C:\WINDOWS\system32\DLA\DLAPoolM.SYS 21:00:39.0921 3712 DLAPoolM - ok 21:00:40.0031 3712 DLARTL_M (91886fed52a3f9966207bce46cfd794f) C:\WINDOWS\system32\Drivers\DLARTL_M.SYS 21:00:40.0078 3712 DLARTL_M - ok 21:00:40.0328 3712 DLAUDFAM (cca4e121d599d7d1706a30f603731e59) C:\WINDOWS\system32\DLA\DLAUDFAM.SYS 21:00:40.0328 3712 DLAUDFAM - ok 21:00:40.0421 3712 DLAUDF_M (7dab85c33135df24419951da4e7d38e5) C:\WINDOWS\system32\DLA\DLAUDF_M.SYS 21:00:40.0421 3712 DLAUDF_M - ok 21:00:40.0609 3712 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 21:00:40.0781 3712 dmboot - ok 21:00:41.0125 3712 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 21:00:41.0125 3712 dmio - ok 21:00:41.0265 3712 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 21:00:41.0281 3712 dmload - ok 21:00:41.0421 3712 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 21:00:41.0453 3712 DMusic - ok 21:00:41.0671 3712 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 21:00:41.0687 3712 dpti2o - ok 21:00:41.0906 3712 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 21:00:41.0906 3712 drmkaud - ok 21:00:42.0062 3712 DRVMCDB (c00440385cf9f3d142917c63f989e244) C:\WINDOWS\system32\Drivers\DRVMCDB.SYS 21:00:42.0109 3712 DRVMCDB - ok 21:00:42.0156 3712 DRVNDDM (6e6ab29d3c06e64ce81feacda85394b5) C:\WINDOWS\system32\Drivers\DRVNDDM.SYS 21:00:42.0156 3712 DRVNDDM - ok 21:00:42.0250 3712 DSproct - ok 21:00:42.0468 3712 E100B (7d91dc6342248369f94d6eba0cf42e99) C:\WINDOWS\system32\DRIVERS\e100b325.sys 21:00:42.0468 3712 E100B - ok 21:00:42.0781 3712 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 21:00:42.0796 3712 Fastfat - ok 21:00:42.0953 3712 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 21:00:42.0953 3712 Fdc - ok 21:00:43.0062 3712 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 21:00:43.0062 3712 Fips - ok 21:00:43.0140 3712 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 21:00:43.0140 3712 Flpydisk - ok 21:00:43.0187 3712 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 21:00:43.0203 3712 FltMgr - ok 21:00:43.0375 3712 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 21:00:43.0390 3712 Fs_Rec - ok 21:00:43.0484 3712 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 21:00:43.0500 3712 Ftdisk - ok 21:00:43.0734 3712 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 21:00:43.0750 3712 Gpc - ok 21:00:43.0921 3712 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 21:00:43.0937 3712 HidUsb - ok 21:00:44.0046 3712 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 21:00:44.0046 3712 hpn - ok 21:00:44.0140 3712 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 21:00:44.0156 3712 HTTP - ok 21:00:44.0250 3712 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 21:00:44.0281 3712 i2omgmt - ok 21:00:44.0437 3712 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys 21:00:44.0437 3712 i2omp - ok 21:00:44.0781 3712 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 21:00:44.0781 3712 i8042prt - ok 21:00:45.0000 3712 ialm (0294a30b302ca71a2c26e582dda93486) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys 21:00:45.0203 3712 ialm - ok 21:00:45.0421 3712 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 21:00:45.0421 3712 Imapi - ok 21:00:45.0812 3712 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 21:00:45.0812 3712 ini910u - ok 21:00:45.0984 3712 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 21:00:45.0984 3712 IntelIde - ok 21:00:46.0156 3712 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 21:00:46.0156 3712 intelppm - ok 21:00:46.0265 3712 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 21:00:46.0265 3712 Ip6Fw - ok 21:00:46.0375 3712 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 21:00:46.0406 3712 IpFilterDriver - ok 21:00:46.0578 3712 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 21:00:46.0578 3712 IpInIp - ok 21:00:46.0796 3712 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 21:00:46.0828 3712 IpNat - ok 21:00:46.0968 3712 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 21:00:46.0968 3712 IPSec - ok 21:00:47.0109 3712 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 21:00:47.0109 3712 IRENUM - ok 21:00:47.0328 3712 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 21:00:47.0328 3712 isapnp - ok 21:00:47.0703 3712 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 21:00:47.0703 3712 Kbdclass - ok 21:00:47.0843 3712 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 21:00:47.0843 3712 kbdhid - ok 21:00:47.0984 3712 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 21:00:48.0000 3712 kmixer - ok 21:00:48.0250 3712 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 21:00:48.0265 3712 KSecDD - ok 21:00:48.0359 3712 lbrtfdc - ok 21:00:48.0515 3712 MBAMSwissArmy (c7dd7d9739785bd3a6b8499eec1dee7e) C:\WINDOWS\system32\drivers\mbamswissarmy.sys 21:00:48.0515 3712 MBAMSwissArmy - ok 21:00:48.0578 3712 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 21:00:48.0578 3712 mnmdd - ok 21:00:48.0703 3712 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 21:00:48.0703 3712 Modem - ok 21:00:48.0812 3712 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 21:00:48.0812 3712 Mouclass - ok 21:00:49.0000 3712 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 21:00:49.0000 3712 mouhid - ok 21:00:49.0296 3712 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 21:00:49.0312 3712 MountMgr - ok 21:00:49.0765 3712 MpKsl0f135ce1 - ok 21:00:49.0796 3712 MpKsl4894e515 - ok 21:00:49.0953 3712 mr7910 (6aa46f9896d3c9e5a00e01bb416c707b) C:\WINDOWS\system32\DRIVERS\mr7910.sys 21:00:49.0953 3712 mr7910 - ok 21:00:50.0015 3712 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 21:00:50.0015 3712 mraid35x - ok 21:00:50.0125 3712 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 21:00:50.0125 3712 MRxDAV - ok 21:00:50.0234 3712 MRxSmb (5a52ec4c22a8e9065bf5080432899801) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 21:00:50.0265 3712 MRxSmb ( Virus.Win32.ZAccess.c ) - infected 21:00:50.0265 3712 MRxSmb - detected Virus.Win32.ZAccess.c (0) 21:00:50.0546 3712 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 21:00:50.0546 3712 Msfs - ok 21:00:50.0687 3712 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 21:00:50.0687 3712 MSKSSRV - ok 21:00:50.0812 3712 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 21:00:50.0812 3712 MSPCLOCK - ok 21:00:50.0953 3712 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 21:00:50.0953 3712 MSPQM - ok 21:00:51.0093 3712 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 21:00:51.0093 3712 mssmbios - ok 21:00:51.0281 3712 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 21:00:51.0281 3712 Mup - ok 21:00:51.0421 3712 NAVENG - ok 21:00:51.0437 3712 NAVEX15 - ok 21:00:51.0750 3712 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 21:00:51.0765 3712 NDIS - ok 21:00:51.0953 3712 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 21:00:51.0953 3712 NdisTapi - ok 21:00:52.0109 3712 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 21:00:52.0109 3712 Ndisuio - ok 21:00:52.0250 3712 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 21:00:52.0250 3712 NdisWan - ok 21:00:52.0515 3712 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 21:00:52.0578 3712 NDProxy - ok 21:00:52.0875 3712 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 21:00:52.0875 3712 NetBIOS - ok 21:00:53.0093 3712 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 21:00:53.0109 3712 NetBT - ok 21:00:53.0281 3712 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 21:00:53.0281 3712 Npfs - ok 21:00:53.0406 3712 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 21:00:53.0437 3712 Ntfs - ok 21:00:53.0750 3712 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 21:00:53.0750 3712 Null - ok 21:00:53.0968 3712 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 21:00:54.0687 3712 nv - ok 21:00:55.0218 3712 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 21:00:55.0234 3712 NwlnkFlt - ok 21:00:55.0656 3712 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 21:00:55.0656 3712 NwlnkFwd - ok 21:00:56.0328 3712 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 21:00:56.0421 3712 Parport - ok 21:00:57.0406 3712 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 21:00:57.0437 3712 PartMgr - ok 21:00:58.0093 3712 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 21:00:58.0187 3712 ParVdm - ok 21:00:58.0703 3712 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 21:00:58.0781 3712 PCI - ok 21:00:59.0015 3712 PCIDump - ok 21:00:59.0187 3712 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 21:00:59.0218 3712 PCIIde - ok 21:00:59.0468 3712 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 21:00:59.0484 3712 Pcmcia - ok 21:00:59.0687 3712 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys 21:00:59.0703 3712 pcouffin - ok 21:00:59.0796 3712 PDCOMP - ok 21:00:59.0921 3712 PDFRAME - ok 21:00:59.0968 3712 PDRELI - ok 21:01:00.0156 3712 PDRFRAME - ok 21:01:00.0281 3712 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 21:01:00.0296 3712 perc2 - ok 21:01:00.0437 3712 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 21:01:00.0437 3712 perc2hib - ok 21:01:00.0671 3712 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 21:01:00.0687 3712 PptpMiniport - ok 21:01:00.0781 3712 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 21:01:00.0781 3712 PSched - ok 21:01:00.0937 3712 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 21:01:00.0937 3712 Ptilink - ok 21:01:01.0046 3712 PxHelp20 (feffcfdc528764a04c8ed63d5fa6e711) C:\WINDOWS\system32\Drivers\PxHelp20.sys 21:01:01.0093 3712 PxHelp20 - ok 21:01:01.0281 3712 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 21:01:01.0281 3712 ql1080 - ok 21:01:01.0406 3712 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 21:01:01.0406 3712 Ql10wnt - ok 21:01:01.0640 3712 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 21:01:01.0640 3712 ql12160 - ok 21:01:01.0828 3712 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 21:01:01.0828 3712 ql1240 - ok 21:01:02.0000 3712 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 21:01:02.0015 3712 ql1280 - ok 21:01:02.0250 3712 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 21:01:02.0250 3712 RasAcd - ok 21:01:02.0421 3712 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 21:01:02.0421 3712 Rasl2tp - ok 21:01:02.0531 3712 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 21:01:02.0531 3712 RasPppoe - ok 21:01:02.0625 3712 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 21:01:02.0625 3712 Raspti - ok 21:01:02.0765 3712 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 21:01:02.0765 3712 Rdbss - ok 21:01:02.0921 3712 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 21:01:02.0921 3712 RDPCDD - ok 21:01:03.0187 3712 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 21:01:03.0187 3712 rdpdr - ok 21:01:03.0343 3712 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 21:01:03.0343 3712 RDPWD - ok 21:01:03.0500 3712 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 21:01:03.0531 3712 redbook - ok 21:01:03.0875 3712 RimUsb (4f4a4c09cc5be58a76cac1c337e004e6) C:\WINDOWS\system32\Drivers\RimUsb.sys 21:01:03.0875 3712 RimUsb - ok 21:01:04.0390 3712 RimVSerPort (3a5633ad615e2b15291bd0b1b97ccd8a) C:\WINDOWS\system32\DRIVERS\RimSerial.sys 21:01:04.0437 3712 RimVSerPort - ok 21:01:04.0828 3712 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys 21:01:04.0875 3712 ROOTMODEM - ok 21:01:05.0625 3712 RT61 (581e74880aeb1dba1cb5ac8e6e6c0a69) C:\WINDOWS\system32\DRIVERS\RT61.sys 21:01:05.0796 3712 RT61 - ok 21:01:06.0390 3712 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 21:01:06.0390 3712 Secdrv - ok 21:01:06.0796 3712 senfilt (b9c7617c1e8ab6fdff75d3c8dafcb4c8) C:\WINDOWS\system32\drivers\senfilt.sys 21:01:06.0906 3712 senfilt - ok 21:01:07.0234 3712 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 21:01:07.0265 3712 serenum - ok 21:01:07.0812 3712 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 21:01:07.0812 3712 Serial - ok 21:01:08.0609 3712 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\DRIVERS\sfloppy.sys 21:01:08.0625 3712 Sfloppy - ok 21:01:08.0968 3712 Simbad - ok 21:01:09.0062 3712 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys 21:01:09.0078 3712 sisagp - ok 21:01:09.0296 3712 smwdm (0066ff77aeb4ae70066f7e94d5a6d866) C:\WINDOWS\system32\drivers\smwdm.sys 21:01:09.0406 3712 smwdm - ok 21:01:09.0468 3712 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 21:01:09.0468 3712 Sparrow - ok 21:01:09.0640 3712 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 21:01:09.0640 3712 splitter - ok 21:01:09.0859 3712 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 21:01:09.0890 3712 sr - ok 21:01:10.0000 3712 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 21:01:10.0171 3712 Srv - ok 21:01:10.0343 3712 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 21:01:10.0343 3712 swenum - ok 21:01:10.0484 3712 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 21:01:10.0500 3712 swmidi - ok 21:01:10.0578 3712 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 21:01:10.0578 3712 symc810 - ok 21:01:10.0687 3712 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 21:01:10.0703 3712 symc8xx - ok 21:01:10.0875 3712 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 21:01:10.0890 3712 sym_hi - ok 21:01:11.0078 3712 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 21:01:11.0078 3712 sym_u3 - ok 21:01:11.0250 3712 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 21:01:11.0265 3712 sysaudio - ok 21:01:11.0390 3712 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 21:01:11.0437 3712 Tcpip - ok 21:01:11.0531 3712 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 21:01:11.0531 3712 TDPIPE - ok 21:01:11.0796 3712 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 21:01:11.0812 3712 TDTCP - ok 21:01:11.0890 3712 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 21:01:11.0906 3712 TermDD - ok 21:01:12.0000 3712 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 21:01:12.0000 3712 TosIde - ok 21:01:12.0140 3712 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 21:01:12.0156 3712 Udfs - ok 21:01:12.0312 3712 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 21:01:12.0312 3712 ultra - ok 21:01:12.0546 3712 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 21:01:12.0578 3712 Update - ok 21:01:12.0734 3712 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 21:01:12.0750 3712 usbaudio - ok 21:01:12.0875 3712 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 21:01:12.0875 3712 usbccgp - ok 21:01:12.0984 3712 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 21:01:12.0984 3712 usbehci - ok 21:01:13.0156 3712 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 21:01:13.0156 3712 usbhub - ok 21:01:13.0375 3712 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 21:01:13.0390 3712 usbprint - ok 21:01:13.0515 3712 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 21:01:13.0531 3712 usbscan - ok 21:01:13.0718 3712 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 21:01:13.0718 3712 USBSTOR - ok 21:01:13.0828 3712 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 21:01:13.0875 3712 usbuhci - ok 21:01:14.0000 3712 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 21:01:14.0000 3712 VgaSave - ok 21:01:14.0156 3712 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys 21:01:14.0187 3712 viaagp - ok 21:01:14.0328 3712 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 21:01:14.0328 3712 ViaIde - ok 21:01:14.0468 3712 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 21:01:14.0484 3712 VolSnap - ok 21:01:14.0656 3712 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 21:01:14.0656 3712 Wanarp - ok 21:01:14.0718 3712 wanatw - ok 21:01:14.0906 3712 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys 21:01:14.0953 3712 Wdf01000 - ok 21:01:15.0078 3712 WDICA - ok 21:01:15.0250 3712 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 21:01:15.0250 3712 wdmaud - ok 21:01:15.0468 3712 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys 21:01:15.0484 3712 WpdUsb - ok 21:01:15.0546 3712 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 21:01:15.0562 3712 WS2IFSL - ok 21:01:15.0656 3712 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 21:01:15.0687 3712 WudfPf - ok 21:01:15.0765 3712 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 21:01:15.0765 3712 WudfRd - ok 21:01:15.0843 3712 MBR (0x1B8) (5cb90281d1a59b251f6603134774eec3) \Device\Harddisk0\DR0 21:01:15.0921 3712 \Device\Harddisk0\DR0 - ok 21:01:15.0953 3712 MBR (0x1B8) (35c6b2fcde68facbefe0a4a7200bae58) \Device\Harddisk1\DR1 21:01:19.0281 3712 \Device\Harddisk1\DR1 - ok 21:01:19.0328 3712 Boot (0x1200) (d53e996d73cfd1edd2e0b1849ebf6faf) \Device\Harddisk0\DR0\Partition0 21:01:19.0343 3712 \Device\Harddisk0\DR0\Partition0 - ok 21:01:19.0406 3712 Boot (0x1200) (606dd7db2130494a0b2cf77d4d79466e) \Device\Harddisk0\DR0\Partition1 21:01:19.0406 3712 \Device\Harddisk0\DR0\Partition1 - ok 21:01:19.0421 3712 Boot (0x1200) (5cf32d648cf8630dbbda4fc451b563cc) \Device\Harddisk1\DR1\Partition0 21:01:19.0421 3712 \Device\Harddisk1\DR1\Partition0 - ok 21:01:19.0421 3712 ============================================================ 21:01:19.0421 3712 Scan finished 21:01:19.0421 3712 ============================================================ 21:01:19.0453 2936 Detected object count: 1 21:01:19.0453 2936 Actual detected object count: 1 21:01:28.0828 2936 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys - copied to quarantine 21:01:28.0906 2936 VerifyFileNameVersionInfo: GetFileVersionInfoSizeW(C:\WINDOWS\system32\drivers\mrxsmb.sys) error 1813 21:01:35.0171 2936 Backup copy found, using it.. 21:01:35.0203 2936 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys - will be cured on reboot 21:01:42.0437 2936 MRxSmb ( Virus.Win32.ZAccess.c ) - User select action: Cure 21:01:52.0890 3860 Deinitialize success Thank you, Bruce
Hi spidey,

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scans put the following in
    • netsvcs
    • CREATERESTOREPOINT
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
      Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
———-
Jeff,
Here's the OTL.txt:

OTL logfile created on: 2/15/2012 7:39:20 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\admin\Desktop\what the tech
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1021.98 Mb Total Physical Memory | 629.51 Mb Available Physical Memory | 61.60% Memory free
1.66 Gb Paging File | 1.25 Gb Available in Paging File | 75.32% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.59 Gb Total Space | 55.28 Gb Free Space | 50.91% Space Free | Partition Type: NTFS
Drive D: | 36.98 Gb Total Space | 36.90 Gb Free Space | 99.80% Space Free | Partition Type: NTFS
Drive F: | 74.53 Gb Total Space | 9.47 Gb Free Space | 12.71% Space Free | Partition Type: NTFS

Computer Name: BRUCE | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\admin\Desktop\what the tech\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\PSIService.exe ()
PRC - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe (Computer Associates)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\a0e090647c856fe52e1f1e5d2a25b1ac\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\7f18fb1e1acae58c6a572faf922bfa3a\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\a2baf116d3055aadb99b77e327a74907\System.EnterpriseServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Transactions\344c1e000e4158cc37a5e9068e095d40\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\cb7cfe8f0e8532f6381c22bf719a95dc\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\a401952384c24581989cdc85270f3d9d\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Data\494945003f729a5d6ec21324dff8c7b9\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\f2a34f1fb98ab9e8a76a22e132e18b21\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\c04dcef499114715d2a222c01ea6b227\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\52598abacb89081ab248f435d9dabdf4\System.Core.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\af709611f9ffff0544b1d750303c4afa\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\52f4f785f7cf45a64606a8e13c8cf04c\mscorlib.ni.dll ()
MOD - C:\WINDOWS\system32\mkunicode.dll ()
MOD - C:\WINDOWS\system32\mmfinfo.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\WINDOWS\system32\Primomonnt.dll ()
MOD - C:\WINDOWS\system32\PSIService.exe ()
MOD - C:\WINDOWS\system32\DLAAPI_W.DLL ()
MOD - C:\WINDOWS\system32\DELG1LMK.DLL ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\WINDOWS\system32\lexdlls.dlL ()


========== Win32 Services (SafeList) ==========

SRV - (NecUsb3) – File not found
SRV - (helpsvc) – File not found
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (IntuitUpdateServiceV4) – C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit Inc.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FreeAgentGoNext Service) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (TNaviSrv) – C:\WINDOWS\system32\ppped.dll (Oak Technology Inc.)
SRV - (ProtexisLicensing) – C:\WINDOWS\system32\PSIService.exe ()
SRV - (CA_LIC_SRVR) – C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe (Computer Associates)
SRV - (LogWatch) – C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe (Computer Associates)
SRV - (CA_LIC_CLNT) – C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe (Computer Associates)


========== Driver Services (SafeList) ==========

DRV - (NPF) WinPcap Packet Driver (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (DigiartyVirtualCDBus) – C:\WINDOWS\system32\drivers\DigiartyVirtualCDBus.sys (Digiarty Software, Inc.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (DLADResM) – C:\WINDOWS\system32\DLA\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (mr7910) – C:\WINDOWS\system32\drivers\mr7910.sys (Mars Semiconductor Corp.)
DRV - (DELL_A02) – C:\WINDOWS\system32\drivers\PRISMA02.sys (Conexant Systems, Inc.)
DRV - (RT61) Linksys Wireless-G PCI Adapter Driver(RT61) – C:\WINDOWS\system32\drivers\rt61.sys (Ralink Technology Inc.)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5060919
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5060919

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaultthis.engineName: "PageRage Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=IEFM1&q;="
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://go.microsoft.com/fwlink/?LinkId=69157"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:12.0.0.1912
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=IEFM1&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG2012\Firefox\ [2012/01/31 17:51:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/01/31 17:51:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/03 20:32:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/29 16:51:51 | 000,000,000 | —D | M]

[2008/10/03 08:51:30 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\admin\Application Data\Mozilla\Extensions
[2012/01/06 21:14:17 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\arkm7om1.default\extensions
[2010/06/13 11:40:42 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\arkm7om1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/09/27 16:58:19 | 000,000,000 | —D | M] ("Inbox Toolbar") – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\arkm7om1.default\extensions\[removed]
[2011/10/15 10:44:38 | 000,001,819 | —- | M] () – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\arkm7om1.default\searchplugins\bing.xml
[2010/11/23 12:02:06 | 000,000,919 | —- | M] () – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\arkm7om1.default\searchplugins\conduit.xml
[2011/10/15 10:44:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/12 17:24:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/04/24 13:17:33 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/22 20:22:23 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2012/01/31 17:51:10 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG2012\FIREFOX
[2010/05/12 17:24:29 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2012/02/13 20:42:20 | 000,000,761 | RHS- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Inbox Toolbar) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O3 - HKLM\..\Toolbar: (&Inbox; Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {00000000-0000-0000-0000-000000000000} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Inbox; Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - mswsock.dll File not found
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1159284260343 (WUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} http://camera6.buffalotrace.com/activex/AMC.cab (AxisMediaControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://cam2.asa.utk.edu/activex/AxisCamControl.cab (CamImage Class)
O16 - DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} http://www.boydsnest-ti.com/activex/AMC.cab (AudioHandlerEmbedded)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://205.241.135.70/activex/AMC.cab (AxisMediaControlEmb Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6C3FCFF1-3A2F-4CD6-86B5-1366FB7D2EFF}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\inbox {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NecUsb3Sevices: DllName - (USB3Sw32.dll) - File not found
O20 - Winlogon\Notify\USB3Sw32: DllName - (USB3Sw32.dll) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 16:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /k:D *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: TNaviSrv - C:\WINDOWS\system32\ppped.dll (Oak Technology Inc.)
NetSvcs: WmdmPmSp - File not found
NetSvcs: helpsvc - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/02/15 19:25:25 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2012/02/13 20:44:18 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/02/13 20:40:43 | 000,281,104 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2012/02/13 20:40:43 | 000,100,880 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\Packet.dll
[2012/02/13 20:40:43 | 000,050,704 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2012/02/12 21:25:13 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv10nt.sys
[2012/02/12 21:25:13 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv10nt.sys
[2012/02/12 21:25:13 | 000,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv06nt.sys
[2012/02/12 21:25:13 | 000,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv06nt.sys
[2012/02/12 21:25:12 | 000,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv11nt.sys
[2012/02/12 21:25:12 | 000,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv11nt.sys
[2012/02/12 21:25:12 | 000,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv09nt.sys
[2012/02/12 21:25:12 | 000,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv09nt.sys
[2012/02/12 21:25:11 | 000,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv08nt.sys
[2012/02/12 21:25:11 | 000,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv08nt.sys
[2012/02/12 21:25:08 | 000,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv07nt.sys
[2012/02/12 21:25:08 | 000,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv07nt.sys
[2012/02/12 21:24:25 | 000,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\recagent.sys
[2012/02/12 21:24:25 | 000,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\recagent.sys
[2012/02/12 21:24:04 | 000,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xsxx.sys
[2012/02/12 21:24:04 | 000,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1xsxx.sys
[2012/02/12 21:24:03 | 000,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xbxx.sys
[2012/02/12 21:24:03 | 000,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1xbxx.sys
[2012/02/12 21:23:53 | 000,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1ttxx.sys
[2012/02/12 21:23:53 | 000,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1ttxx.sys
[2012/02/12 21:23:52 | 000,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1snxx.sys
[2012/02/12 21:23:52 | 000,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1snxx.sys
[2012/02/12 21:23:51 | 000,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1rvxx.sys
[2012/02/12 21:23:51 | 000,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1rvxx.sys
[2012/02/12 21:23:50 | 000,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1raxx.sys
[2012/02/12 21:23:50 | 000,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1raxx.sys
[2012/02/12 21:23:50 | 000,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1pdxx.sys
[2012/02/12 21:23:50 | 000,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1pdxx.sys
[2012/02/12 21:23:49 | 000,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1mdxx.sys
[2012/02/12 21:23:49 | 000,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1mdxx.sys
[2012/02/12 21:23:47 | 000,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1btxx.sys
[2012/02/12 21:23:47 | 000,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1btxx.sys
[2012/02/12 20:46:23 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2012/02/12 20:46:23 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2012/02/12 20:46:22 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2012/02/12 20:46:22 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2012/02/12 20:44:05 | 004,402,282 | R— | C] (Swearware) – C:\Documents and Settings\admin\Desktop\ComboFix.exe
[2012/02/12 20:42:22 | 000,000,000 | —D | C] – C:\Qoobox
[2012/02/12 20:36:29 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/02/12 11:18:27 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Desktop\what the tech
[2012/02/11 15:32:26 | 000,000,000 | RH-D | C] – C:\Documents and Settings\admin\Recent
[2012/02/05 22:44:00 | 000,000,000 | —D | C] – C:\Config.Msi
[2012/02/05 21:02:14 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Desktop\Holli
[2012/02/04 16:04:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\TurboTax 2011
[2009/02/08 16:44:02 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\admin\Application Data\pcouffin.sys
[2009/01/03 14:51:23 | 002,567,672 | —- | C] (Wimpy FLV Player) – C:\Program Files\Wimpy FLV Player.exe
[2008/05/19 15:02:46 | 000,955,704 | —- | C] (JAM Software) – C:\Program Files\TreeSizeFree.exe
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/02/15 19:42:12 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/02/15 19:39:03 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/15 19:23:34 | 089,138,198 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2012/02/15 19:16:23 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/02/15 19:15:14 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/15 19:14:12 | 000,000,000 | -HS- | M] () – C:\WINDOWS\System32\dds_trash_log.cmd
[2012/02/15 19:14:05 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/02/13 20:42:20 | 000,000,761 | RHS- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/02/13 20:40:43 | 000,281,104 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2012/02/13 20:40:43 | 000,100,880 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\Packet.dll
[2012/02/13 20:40:43 | 000,050,704 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2012/02/12 20:38:26 | 004,402,282 | R— | M] (Swearware) – C:\Documents and Settings\admin\Desktop\ComboFix.exe
[2012/02/12 15:07:11 | 000,103,733 | —- | M] () – C:\WINDOWS\System32\itusbcore.dat
[2012/02/12 15:07:11 | 000,000,197 | —- | M] () – C:\WINDOWS\System32\itlsvc.dat
[2012/02/11 19:50:22 | 000,002,521 | —- | M] () – C:\Documents and Settings\admin\Desktop\Microsoft Office Outlook 2007.lnk
[2012/02/10 21:49:23 | 000,344,931 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjg.avm
[2012/02/09 16:55:59 | 000,000,135 | —- | M] () – C:\Documents and Settings\admin\default.pls
[2012/02/09 16:53:03 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012/02/08 20:20:35 | 000,002,393 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TurboTax 2011.lnk
[2012/02/05 22:57:09 | 000,535,468 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/02/05 22:57:09 | 000,102,478 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/02/04 16:19:53 | 000,000,590 | —- | M] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.400.32.bc
[2012/02/04 10:11:20 | 001,102,798 | —- | M] () – C:\Documents and Settings\admin\Desktop\Teamster - Proposal from Hostess Brands - 2-3-12.pdf
[2012/02/01 20:47:49 | 000,151,552 | —- | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/31 17:51:19 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/01/28 21:21:10 | 000,000,282 | -HS- | M] () – C:\boot.ini
[2012/01/27 22:00:23 | 000,006,496 | —- | M] () – C:\Documents and Settings\admin\Application Data\PrimoPDFSet.xml
[2012/01/25 20:32:44 | 000,085,670 | —- | M] () – C:\Documents and Settings\admin\Desktop\estimate.pdf
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/02/12 20:46:23 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/02/12 20:46:23 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/02/12 20:46:23 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/02/12 20:46:23 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/02/12 20:46:22 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/02/12 15:07:11 | 000,103,733 | —- | C] () – C:\WINDOWS\System32\itusbcore.dat
[2012/02/12 15:07:11 | 000,000,197 | —- | C] () – C:\WINDOWS\System32\itlsvc.dat
[2012/02/09 15:29:12 | 000,000,000 | -HS- | C] () – C:\WINDOWS\System32\dds_trash_log.cmd
[2012/02/04 22:51:58 | 001,323,262 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-2175378804-878084744-2452809072-1008-0.dat
[2012/02/04 22:51:49 | 001,323,262 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/02/04 16:12:50 | 000,000,590 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.400.32.bc
[2012/02/04 16:05:40 | 000,002,393 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TurboTax 2011.lnk
[2012/02/04 10:11:19 | 001,102,798 | —- | C] () – C:\Documents and Settings\admin\Desktop\Teamster - Proposal from Hostess Brands - 2-3-12.pdf
[2012/01/25 20:32:44 | 000,085,670 | —- | C] () – C:\Documents and Settings\admin\Desktop\estimate.pdf
[2011/12/02 21:32:29 | 000,001,394 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\720788v1w137o246s325e7geu5i1
[2011/12/02 21:32:29 | 000,001,394 | -HS- | C] () – C:\Documents and Settings\admin\Local Settings\Application Data\720788v1w137o246s325e7geu5i1
[2011/05/31 20:12:10 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/12/29 07:45:36 | 000,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2010/12/14 16:21:34 | 000,000,036 | —- | C] () – C:\Documents and Settings\admin\Local Settings\Application Data\housecall.guid.cache
[2010/12/14 10:08:24 | 000,000,000 | —- | C] () – C:\Documents and Settings\admin\Application Data\bd5ae5f333bc2d23e52489e5a4abe78e–3763827969
[2010/12/14 10:06:19 | 000,000,008 | —- | C] () – C:\Documents and Settings\admin\Application Data\7e4e4b43.dat
[2010/05/24 13:33:00 | 004,670,829 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/05/24 13:33:00 | 001,529,856 | —- | C] () – C:\WINDOWS\System32\ff_samplerate.dll
[2010/05/24 13:33:00 | 001,447,921 | —- | C] () – C:\WINDOWS\System32\ffmpegmt.dll
[2010/05/24 13:33:00 | 000,877,385 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2010/05/24 13:33:00 | 000,810,113 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/05/24 13:33:00 | 000,336,384 | —- | C] () – C:\WINDOWS\System32\ff_libfaad2.dll
[2010/05/24 13:33:00 | 000,324,096 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/05/24 13:33:00 | 000,248,320 | —- | C] () – C:\WINDOWS\System32\ff_kernelDeint.dll
[2010/05/24 13:33:00 | 000,216,576 | —- | C] () – C:\WINDOWS\System32\ff_libdts.dll
[2010/05/24 13:33:00 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\ff_libmad.dll
[2010/05/24 13:33:00 | 000,145,408 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/05/24 13:33:00 | 000,139,944 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/05/24 13:33:00 | 000,121,856 | —- | C] () – C:\WINDOWS\System32\ff_liba52.dll
[2010/05/24 13:33:00 | 000,116,736 | —- | C] () – C:\WINDOWS\System32\ff_tremor.dll
[2010/05/24 13:33:00 | 000,108,032 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/05/24 13:33:00 | 000,100,864 | —- | C] () – C:\WINDOWS\System32\ff_wmv9.dll
[2010/05/24 13:33:00 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\ff_unrar.dll
[2010/05/19 14:59:20 | 000,150,528 | —- | C] () – C:\WINDOWS\System32\mkx.dll
[2010/05/19 14:59:10 | 000,109,568 | —- | C] () – C:\WINDOWS\System32\avi.dll
[2010/05/19 14:59:02 | 000,141,824 | —- | C] () – C:\WINDOWS\System32\mp4.dll
[2010/05/19 14:58:52 | 000,123,392 | —- | C] () – C:\WINDOWS\System32\ogm.dll
[2010/05/19 14:58:24 | 000,113,152 | —- | C] () – C:\WINDOWS\System32\dsmux.exe
[2010/05/19 14:58:18 | 000,154,112 | —- | C] () – C:\WINDOWS\System32\ts.dll
[2010/05/19 14:58:08 | 000,249,856 | —- | C] () – C:\WINDOWS\System32\dxr.dll
[2010/05/19 14:57:42 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\avs.dll
[2010/05/19 14:57:38 | 000,137,728 | —- | C] () – C:\WINDOWS\System32\mkv2vfr.exe
[2010/05/19 14:57:26 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\avss.dll
[2010/05/19 14:57:20 | 000,358,400 | —- | C] () – C:\WINDOWS\System32\gdsmux.exe
[2010/05/19 14:55:40 | 000,080,384 | —- | C] () – C:\WINDOWS\System32\mkzlib.dll
[2010/05/19 14:55:36 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\mkunicode.dll
[2010/05/15 16:33:42 | 000,004,096 | -H– | C] () – C:\Documents and Settings\admin\Local Settings\Application Data\keyfile3.drm
[2010/04/27 16:45:07 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/27 16:45:07 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/04/26 18:13:25 | 000,014,494 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\b08620CF7A25y
[2010/04/26 18:13:25 | 000,014,494 | -HS- | C] () – C:\Documents and Settings\admin\Local Settings\Application Data\b08620CF7A25y
[2010/04/24 19:08:32 | 000,013,712 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\b5bq8uC1G1B
[2010/04/24 19:08:32 | 000,013,712 | -HS- | C] () – C:\Documents and Settings\admin\Local Settings\Application Data\b5bq8uC1G1B
[2010/01/20 21:37:09 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\FileOps.exe
[2009/08/11 15:21:26 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\ac3config.exe
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/07/06 18:15:33 | 000,189,952 | —- | C] () – C:\WINDOWS\Qcard32.dll
[2009/06/28 12:45:26 | 000,000,036 | —- | C] () – C:\WINDOWS\marscam.ini
[2009/06/07 10:24:04 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/04/22 17:35:32 | 000,001,139 | —- | C] () – C:\WINDOWS\checkip.dat
[2009/04/22 17:35:18 | 000,001,137 | —- | C] () – C:\WINDOWS\ipconfig.dat
[2009/02/27 18:17:23 | 000,000,040 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2009/02/08 16:44:02 | 000,007,887 | —- | C] () – C:\Documents and Settings\admin\Application Data\pcouffin.cat
[2009/02/08 16:44:02 | 000,001,144 | —- | C] () – C:\Documents and Settings\admin\Application Data\pcouffin.inf
[2009/02/05 18:02:15 | 000,016,896 | —- | C] () – C:\Documents and Settings\admin\Application Data\dvd.bmk
[2009/02/01 10:07:51 | 000,006,496 | —- | C] () – C:\Documents and Settings\admin\Application Data\PrimoPDFSet.xml
[2009/01/26 20:43:14 | 000,025,601 | —- | C] () – C:\WINDOWS\CSTBox.INI
[2009/01/13 20:58:38 | 000,176,235 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2009/01/11 16:36:26 | 000,000,525 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2009/01/11 11:30:19 | 000,000,603 | —- | C] () – C:\Program Files\Shortcut to WS_FTP95.lnk
[2009/01/10 16:15:44 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\mmfinfo.dll
[2009/01/05 20:15:46 | 000,000,008 | RHS- | C] () – C:\WINDOWS\System32\1C02B127CC.sys
[2009/01/03 13:39:16 | 000,000,016 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2009/01/03 12:17:00 | 000,151,552 | —- | C] () – C:\Documents and Settings\admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/31 16:43:57 | 000,000,128 | —- | C] () – C:\Documents and Settings\admin\Local Settings\Application Data\fusioncache.dat
[2008/11/06 09:37:32 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/05/16 10:58:04 | 000,012,632 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2008/04/28 11:13:33 | 000,000,310 | —- | C] () – C:\WINDOWS\primopdf.ini
[2007/10/13 03:30:20 | 000,000,137 | —- | C] () – C:\WINDOWS\System32\Registration.ini
[2006/11/15 10:05:57 | 000,007,310 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/11/15 10:05:57 | 000,000,088 | RHS- | C] () – C:\WINDOWS\System32\AB72D94BAB.sys
[2006/11/09 15:07:44 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/11/02 20:40:12 | 000,174,656 | —- | C] () – C:\WINDOWS\System32\PSIService.exe
[2006/09/26 09:52:32 | 000,094,208 | R— | C] () – C:\WINDOWS\System32\WIAIPH.dll
[2006/09/26 09:52:32 | 000,086,016 | R— | C] () – C:\WINDOWS\System32\WIAEH.dll
[2006/09/26 09:52:32 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\WIASTIIO.dll
[2006/09/26 09:52:32 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\Sswiadrv.dll
[2006/09/26 09:51:10 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\DELG1CI.exe
[2006/09/26 09:51:10 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\SVSetup.Exe
[2006/09/26 09:51:10 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\DELG1CI.dll
[2006/09/26 09:51:10 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\SVSetup.dll
[2006/09/26 09:51:03 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\DPSetup.Exe
[2006/09/26 09:51:03 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\DPSetup.dll
[2006/09/26 09:51:02 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\DP1815ci.exe
[2006/09/26 09:51:02 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\DP1815ci.dll
[2006/09/26 09:39:07 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\d1815ci.exe
[2006/09/26 09:39:07 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\d1815ci.dll
[2006/09/26 09:39:06 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\VdSetup.Exe
[2006/09/26 09:39:06 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\VdSetup.dll
[2006/09/26 09:39:06 | 000,022,663 | —- | C] () – C:\WINDOWS\System32\DELG1LMK.DLL
[2006/09/26 09:34:30 | 000,001,364 | —- | C] () – C:\WINDOWS\DKAAG2DD.ini
[2006/09/26 09:13:48 | 000,000,047 | —- | C] () – C:\WINDOWS\InoSetup.ini
[2006/09/26 08:54:31 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/09/19 09:26:16 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/09/19 09:16:16 | 000,000,370 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/09/19 09:12:12 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2006/09/19 09:10:28 | 000,712,704 | —- | C] () – C:\WINDOWS\System32\DellSystemRestore.dll
[2006/09/19 09:07:18 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/09/19 09:05:46 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/09/19 08:42:20 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2006/09/19 08:41:58 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2006/09/19 08:41:54 | 000,000,392 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/09/16 23:36:50 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/16 23:36:50 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2006/09/08 14:06:02 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\CoPrism.dll
[2004/08/11 16:24:19 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/11 16:19:30 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/11 16:12:14 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/11 16:11:31 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/11 16:07:24 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/11 16:06:43 | 001,771,448 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/11 16:00:30 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/11 16:00:28 | 000,535,468 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/11 16:00:28 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/11 16:00:28 | 000,102,478 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/11 16:00:28 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/11 16:00:27 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/11 16:00:26 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/11 16:00:24 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/11 16:00:19 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/11 16:00:19 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/11 16:00:12 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/11 16:00:04 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2003/04/18 12:45:00 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\lexdlls.dlL
[2002/10/06 12:42:56 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/10/04 17:04:24 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2002/10/04 17:04:24 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/10/04 17:04:16 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/05/15 17:38:40 | 000,091,136 | —- | C] () – C:\WINDOWS\System32\mp4fil32.dll

========== LOP Check ==========

[2011/03/14 17:56:56 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\4Media
[2009/01/10 18:58:54 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Astro Gemini Software
[2011/10/09 09:58:54 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\AVG2012
[2012/01/07 10:52:21 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Blackberry Desktop
[2011/06/15 20:59:32 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\calibre
[2012/02/06 18:52:09 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Canon
[2012/01/06 20:22:18 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Digiarty
[2010/12/18 18:10:02 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\ElevatedDiagnostics
[2009/05/23 09:41:47 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\ICQ
[2011/09/27 16:58:43 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Inbox Toolbar
[2009/01/04 17:31:10 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\JAM Software
[2009/01/01 17:00:07 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Leadertech
[2011/02/05 19:22:31 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\LimeWire
[2012/02/12 20:15:49 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\MailWasherFree
[2008/11/28 14:26:05 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\mjusbsp
[2009/01/02 21:05:18 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\NoteTab Light
[2012/01/07 10:29:23 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Research In Motion
[2009/01/11 16:36:32 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\ScanSoft
[2011/06/14 18:18:20 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Softplicity
[2010/02/22 17:49:54 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Uniblue
[2012/01/07 18:31:51 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Vso
[2011/02/28 19:42:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2012/02/12 15:25:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2010/12/14 10:21:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/10/19 17:21:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/04/13 17:57:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fAh06511jCiMl06511
[2010/12/14 10:17:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fGjBn01847
[2012/02/15 19:26:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2009/02/04 17:46:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pingotron.com
[2012/01/07 10:24:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2009/05/27 19:53:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/06/10 20:26:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2009/02/27 18:17:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2009/01/11 16:36:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2009/01/11 16:36:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2006/09/19 09:08:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/02/23 21:05:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2009/09/12 20:44:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2012/01/08 18:13:41 | 000,000,268 | —- | M] () – C:\WINDOWS\Tasks\prismShakeIcon.job

========== Purity Check ==========



< End of report >
Jeff,
Here's the extras.text:

OTL Extras logfile created on: 2/15/2012 7:39:20 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\admin\Desktop\what the tech
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1021.98 Mb Total Physical Memory | 629.51 Mb Available Physical Memory | 61.60% Memory free
1.66 Gb Paging File | 1.25 Gb Available in Paging File | 75.32% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.59 Gb Total Space | 55.28 Gb Free Space | 50.91% Space Free | Partition Type: NTFS
Drive D: | 36.98 Gb Total Space | 36.90 Gb Free Space | 99.80% Space Free | Partition Type: NTFS
Drive F: | 74.53 Gb Total Space | 9.47 Gb Free Space | 12.71% Space Free | Partition Type: NTFS

Computer Name: BRUCE | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"56522:TCP" = 56522:TCP:*:Enabled:Pando
"56522:UDP" = 56522:UDP:*:Enabled:Pando
"56310:TCP" = 56310:TCP:*:Enabled:Pando
"56310:UDP" = 56310:UDP:*:Enabled:Pando
"4481:TCP" = 4481:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4481:UDP" = 4481:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
"4482:TCP" = 4482:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4482:UDP" = 4482:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Dell\Dell Laser MFP 1815\NetworkScan\DNSCST.exe" = C:\Program Files\Dell\Dell Laser MFP 1815\NetworkScan\DNSCST.exe:*:Enabled:DNSCST Module – (Dell)
"C:\Documents and Settings\admin\Application Data\mjusbsp\magicJack.exe" = C:\Documents and Settings\admin\Application Data\mjusbsp\magicJack.exe:*:Enabled:magicJack – (magicJack L.P.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox – (Mozilla Corporation)
"F:\Program Files\WS_FTP\WS_FTP95.exe" = F:\Program Files\WS_FTP\WS_FTP95.exe:*:Enabled:WS_FTP 95 – (Ipswitch, Inc. 81 Hartwell Ave. Lexington, MA)
"C:\Program Files\ICQ6.5\ICQ.exe" = C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 – (ICQ, LLC.)
"C:\Program Files\ScanSoft\OmniPageSE\EregEng\NAVBrowser.exe" = C:\Program Files\ScanSoft\OmniPageSE\EregEng\NAVBrowser.exe:*:Enabled:NAVBrowser – (Naviant, Inc.)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Pando Networks\Pando\Pando.exe" = C:\Program Files\Pando Networks\Pando\Pando.exe:*:Enabled:Pando – (Pando Networks)
"C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe" = C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe:*:Enabled:BlackBerry Desktop Software – (Research In Motion)
"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update v4 Shared Downloads Server – (Intuit Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{03F1CC67-5BD8-4C36-8394-76311B2AE69A}" = ArcSoft PhotoStudio 5
"{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
"{083E0D59-B6B4-4570-AA0A-37F5B4526CF5}" = AVG 2012
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{0D557AE9-1484-4E22-978F-A372EE04F16F}" = TurboTax 2010 wmoiper
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = Qualxserve Service Agreement
"{12665B01-3F3A-4433-B179-9D8E352D7547}" = Try Corel Snapfire muvee autoProducer add on
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2086A549-ED96-4dc9-BBE3-0538AB29ABEC}" = PSP Thumbnail Handler
"{20F51690-133A-453C-B616-1C15AB2C0EF0}" = SBA
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 26
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{30C10EE3-EFB3-4B7A-9CDC-50790C2B5200}" = CA Licensing
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C814DE3-7174-4148-A3E2-43FFC4F21033}" = Nero 7 Essentials
"{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}" = Dell CinePlayer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EFC72DA-2314-4E5D-AC8E-1C954CDB8BBF}" = AVG 2012
"{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5AD96CF5-2627-4F29-9D2D-72FCD85F6355}" = AVG 2011
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{5D1F6855-AA3F-422F-AB17-8777588EE3B7}" = Templates for Today's Time-Crunched Professional
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{612AD33D-9824-4E87-8396-92374E91C4BB}_is1" = Inbox Toolbar
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{6249C22D-E6A8-407B-BA8B-40298848ED94}" = OmniPage SE
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{6346B2AE-0DBB-45A3-9ECA-D23CAC27AB7E}" = TurboTax 2011 wiliper
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{6693E024-E2D3-477C-8EF9-4D484F3B3071}" = Seagate Manager Installer
"{67183F00-3DDC-497B-A090-4E2B79EAF1CD}" = Photo Viewer
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{70632C41-BDAC-4128-9FBF-287F9FF53DE5}" = TurboTax 2010 wiliper
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8A9B8148-DDD7-448F-BD6C-358386D32354}" = Corel Photo Album 6
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{45055A10-CE0A-48B8-BCC2-C9A4DFF72332}" =
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-0080-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A23061AF-5361-433C-B7F0-CE5F79A22C49}" = AVG 2011
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}" = Pando
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.3
"{AD5145FC-A333-4961-9407-F08EA64C7E5E}" = calibre
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B702CCCE-3176-4DBF-B932-D1B8F402F330}" = Digital Content Portal
"{BCE46757-7674-4416-BEDB-68205A60409E}" = Canon CanoScan Toolbox 4.1
"{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}" = Windows Rights Management Client with Service Pack 2
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1D14C0D-FDAA-4DF2-8441-A902805CCE8C}" = ArcSoft PhotoBase 3
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CAF5B770-082F-40C4-853D-3973BB81BDAA}" = TurboTax 2011 WinPerTaxSupport
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}" = WinZip 12.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.1.9.347
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ)
"{E2750613-73F1-43B9-9B0B-387E5543971F}" = CD LabelMaker 5
"{E463E171-4082-4744-A466-F7CBE8502789}" = TurboTax 2011 WinPerReleaseEngine
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility SP2
"{EE556A3E-EB37-4392-9637-BAA8EC2F47FA}" = TurboTax 2011 wrapper
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F909BB1B-3FC1-4EDA-AF1F-8F1A89163591}" = BlackBerry Desktop Software 6.1
"{FAD3D68B-2F9C-459B-AA79-C04B9090FD72}" = TurboTax 2011 WinPerFedFormset
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"693218053459EBF14C6505EA1172F17672B50DD1" = Windows Driver Package - (mr7910) Image (08/08/2006 1.4.0.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS5" = Adobe Photoshop CS5
"Adobe Shockwave Player" = Adobe Shockwave Player
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"AVG" = AVG 2012
"AVI Movie Player" = AVI Movie Player
"AXIS Media Control" = AXIS Media Control
"AXIS Media Control Embedded" = AXIS Media Control Embedded
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.1
"CCleaner" = CCleaner (remove only)
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Dell Laser MFP 1815" = Dell Laser MFP 1815 Software Uninstall
"Dell Printer Software Uninstall" = Dell Printer Software Uninstall
"hp deskjet 840c series" = hp deskjet 840c series (Remove only)
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{6693E024-E2D3-477C-8EF9-4D484F3B3071}" = Seagate Manager Installer
"InternetRadioFan_is1" = Internet RadioFan 1.3.0
"MailWasher Free_is1" = MailWasher Free 6.5.2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Media Player - Codec Pack" = Media Player Codec Pack 3.9.6
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.0.19)" = Mozilla Firefox (3.0.19)
"MRU-Blaster_is1" = MRU-Blaster v1.5 (Database 3/28/2004)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NoteTab Light 5_is1" = NoteTab Light 5 (Remove only)
"PrimoPDF4.1.0.9" = PrimoPDF
"Prism" = Prism Video File Converter
"PROPLUS" = Microsoft Office Professional Plus 2007
"PROSet" = Intel® PRO Network Adapters and Drivers
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer Basic
"SearchAssist" = SearchAssist
"Solitaire" = Solitaire
"SpywareBlaster_is1" = SpywareBlaster 4.3
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Total Audio Converter_is1" = TotalAudioConverter
"TurboTax 2010" = TurboTax 2010
"TurboTax 2011" = TurboTax 2011
"ViewpointMediaPlayer" = Viewpoint Media Player
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WinX DVD Copy Pro_is1" = WinX DVD Copy Pro 3.4.3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YouTubeGet_is1" = YouTubeGet 5.9.1

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"SugarSync" = SugarSync Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/10/2012 10:37:42 PM | Computer Name = BRUCE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 2/10/2012 10:37:42 PM | Computer Name = BRUCE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 2/11/2012 5:15:51 AM | Computer Name = BRUCE | Source = ESENT | ID = 490
Description = svchost (1280) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 2/11/2012 5:15:52 AM | Computer Name = BRUCE | Source = ESENT | ID = 490
Description = svchost (1280) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 2/11/2012 5:15:54 AM | Computer Name = BRUCE | Source = ESENT | ID = 490
Description = svchost (1280) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 2/11/2012 6:07:23 PM | Computer Name = BRUCE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/11/2012 6:45:12 PM | Computer Name = BRUCE | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x01c00fef.

Error - 2/12/2012 11:25:34 PM | Computer Name = BRUCE | Source = Application Error | ID = 1000
Description = Faulting application pev.3xe, version 0.0.0.0, faulting module pev.3xe,
version 0.0.0.0, fault address 0x00081dc9.

Error - 2/13/2012 12:18:45 AM | Computer Name = BRUCE | Source = Application Hang | ID = 1002
Description = Hanging application rundll32.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/15/2012 9:36:26 PM | Computer Name = BRUCE | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.31.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ OSession Events ]
Error - 12/12/2011 11:13:12 PM | Computer Name = BRUCE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 35
seconds with 0 seconds of active time. This session ended with a crash.

Error - 12/12/2011 11:13:54 PM | Computer Name = BRUCE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 34
seconds with 0 seconds of active time. This session ended with a crash.

Error - 12/30/2011 6:55:52 PM | Computer Name = BRUCE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6562.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 97
seconds with 60 seconds of active time. This session ended with a crash.

Error - 12/30/2011 7:47:52 PM | Computer Name = BRUCE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6562.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 1578
seconds with 420 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 2/15/2012 9:16:30 PM | Computer Name = BRUCE | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 2/15/2012 9:16:37 PM | Computer Name = BRUCE | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 2/15/2012 9:17:30 PM | Computer Name = BRUCE | Source = System Error | ID = 1003
Description = Error code 100000d1, parameter1 6e6f6960, parameter2 00000002, parameter3
00000000, parameter4 f6f59570.

Error - 2/15/2012 9:18:20 PM | Computer Name = BRUCE | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 2/15/2012 9:18:52 PM | Computer Name = BRUCE | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 2/15/2012 9:21:31 PM | Computer Name = BRUCE | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 2/15/2012 9:21:42 PM | Computer Name = BRUCE | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 2/15/2012 9:24:29 PM | Computer Name = BRUCE | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 2/15/2012 9:39:43 PM | Computer Name = BRUCE | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 2/15/2012 9:41:45 PM | Computer Name = BRUCE | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127


< End of report >


Thank you Spidey
Hi spidey,

Looks like we have a new variant of this ZeroAccess infection. Just so you know, this may take some time to finish…

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    File::
    C:\WINDOWS\system32\ppped.dll
    
    Netsvc::
    TNaviSrv
    
    Driver::
    TNaviSrv
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Hi Jeff,
Here's the log after combofix ran:

ComboFix 12-02-12.01 - admin 02/16/2012 18:45:07.3.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\admin\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Symantec AntiVirus Corporate Edition *Disabled/Outdated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
FILE ::
"c:\windows\system32\ppped.dll"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\$NtUninstallKB38146$\3326877575
c:\windows\$NtUninstallKB38146$\954117596\@
c:\windows\$NtUninstallKB38146$\954117596\cfg.ini
c:\windows\$NtUninstallKB38146$\954117596\Desktop.ini
c:\windows\$NtUninstallKB38146$\954117596\L\iahonoel
c:\windows\$NtUninstallKB38146$\954117596\U\00000001.@
c:\windows\$NtUninstallKB38146$\954117596\U\00000002.@
c:\windows\$NtUninstallKB38146$\954117596\U\00000004.@
c:\windows\$NtUninstallKB38146$\954117596\U\80000000.@
c:\windows\$NtUninstallKB38146$\954117596\U\80000004.@
c:\windows\$NtUninstallKB38146$\954117596\U\80000032.@
c:\windows\$NtUninstallKB38146$\954117596\version
c:\windows\system32\Packet.dll
c:\windows\system32\wpcap.dll
.
c:\windows\system32\drivers\Serial.sys was missing
Restored copy from - c:\windows\ServicePackFiles\i386\serial.sys
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_NPF
——-\Legacy_TNAVISRV
——-\Service_NPF
——-\Service_TNaviSrv
.
.
((((((((((((((((((((((((( Files Created from 2012-01-17 to 2012-02-17 )))))))))))))))))))))))))))))))
.
.
2012-02-17 00:55 . 2008-04-13 19:15 64512 —-a-w- c:\windows\system32\drivers\Serial.sys
2012-02-17 00:10 . 2008-04-13 18:36 187776 —-a-w- c:\windows\system32\drivers\acpi.sys
2012-02-16 01:21 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\iacenc.dll
2012-02-16 01:21 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\dllcache\iacenc.dll
2012-02-14 02:40 . 2012-02-14 02:40 50704 —-a-w- c:\windows\system32\drivers\npf.sys
2012-02-13 03:25 . 2004-08-04 04:29 25471 —-a-w- c:\windows\system32\dllcache\watv10nt.sys
2012-02-13 03:25 . 2004-08-04 04:29 22271 —-a-w- c:\windows\system32\dllcache\watv06nt.sys
2012-02-13 03:25 . 2004-08-04 04:29 11935 —-a-w- c:\windows\system32\dllcache\wadv11nt.sys
2012-02-13 03:25 . 2004-08-04 04:29 11871 —-a-w- c:\windows\system32\dllcache\wadv09nt.sys
2012-02-13 03:25 . 2004-08-04 04:29 11295 —-a-w- c:\windows\system32\dllcache\wadv08nt.sys
2012-02-13 03:25 . 2004-08-04 04:29 11807 —-a-w- c:\windows\system32\dllcache\wadv07nt.sys
2012-02-13 03:24 . 2004-08-04 04:41 13776 —-a-w- c:\windows\system32\dllcache\recagent.sys
2012-02-13 03:24 . 2004-08-04 04:29 34735 —-a-w- c:\windows\system32\dllcache\ati1xsxx.sys
2012-02-13 03:24 . 2004-08-04 04:29 29455 —-a-w- c:\windows\system32\dllcache\ati1xbxx.sys
2012-02-13 03:23 . 2004-08-04 04:29 21343 —-a-w- c:\windows\system32\dllcache\ati1ttxx.sys
2012-02-13 03:23 . 2004-08-04 04:29 26367 —-a-w- c:\windows\system32\dllcache\ati1snxx.sys
2012-02-13 03:23 . 2004-08-04 04:29 63663 —-a-w- c:\windows\system32\dllcache\ati1rvxx.sys
2012-02-13 03:23 . 2004-08-04 04:29 30671 —-a-w- c:\windows\system32\dllcache\ati1raxx.sys
2012-02-13 03:23 . 2004-08-04 04:29 12047 —-a-w- c:\windows\system32\dllcache\ati1pdxx.sys
2012-02-13 03:23 . 2004-08-04 04:29 11615 —-a-w- c:\windows\system32\dllcache\ati1mdxx.sys
2012-02-13 03:23 . 2004-08-04 04:29 56623 —-a-w- c:\windows\system32\dllcache\ati1btxx.sys
2012-02-13 03:02 . 2012-02-13 03:02 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2012-02-13 02:36 . 2012-02-13 02:36 ——– d—–w- C:\TDSSKiller_Quarantine
2012-02-09 21:29 . 2012-02-16 23:55 0 –sha-w- c:\windows\system32\dds_trash_log.cmd
2012-02-04 22:12 . 2012-02-04 22:12 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-13 03:03 . 2006-09-19 14:40 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2012-01-12 16:53 . 2004-08-11 22:00 1859968 —-a-w- c:\windows\system32\win32k.sys
2012-01-07 19:26 . 2012-01-07 02:22 163616 —-a-w- c:\windows\system32\drivers\DigiartyVirtualCDBus.sys
2011-12-17 19:46 . 2004-08-11 22:00 916992 —-a-w- c:\windows\system32\wininet.dll
2011-12-17 19:46 . 2004-08-11 22:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46 . 2004-08-11 22:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:22 . 2004-08-11 22:00 385024 —-a-w- c:\windows\system32\html.iec
2011-11-25 21:57 . 2004-08-11 22:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-11-19 16:26 . 2011-10-10 22:20 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2008-05-19 21:02 . 2008-05-19 21:02 955704 —-a-w- c:\program files\TreeSizeFree.exe
2006-09-13 12:21 . 2009-01-03 20:51 2567672 —-a-w- c:\program files\Wimpy FLV Player.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2012-02-13_03.46.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-02-17 01:04 . 2012-02-17 01:04 16384 c:\windows\Temp\Perflib_Perfdata_8d8.dat
+ 2012-02-17 01:04 . 2012-02-17 01:04 16384 c:\windows\Temp\Perflib_Perfdata_4bc.dat
+ 2004-08-11 22:00 . 2011-12-17 19:46 66560 c:\windows\system32\mshtmled.dll
- 2004-08-11 22:00 . 2011-11-04 19:20 66560 c:\windows\system32\mshtmled.dll
+ 2007-08-13 23:54 . 2011-12-17 19:46 55296 c:\windows\system32\msfeedsbs.dll
- 2007-08-13 23:54 . 2011-11-04 19:20 55296 c:\windows\system32\msfeedsbs.dll
+ 2004-08-11 22:00 . 2011-12-17 19:46 25600 c:\windows\system32\jsproxy.dll
- 2004-08-11 22:00 . 2011-11-04 19:20 25600 c:\windows\system32\jsproxy.dll
- 2011-12-26 20:13 . 2011-11-04 19:20 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2011-12-26 20:13 . 2011-12-17 19:46 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2006-09-19 15:01 . 2011-12-17 19:46 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2006-09-19 15:01 . 2011-11-04 19:20 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2008-08-10 17:40 . 2011-12-17 19:46 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-08-10 17:40 . 2011-11-04 19:20 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2007-08-13 23:44 . 2011-12-17 19:46 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2007-08-13 23:44 . 2011-11-04 19:20 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2006-09-19 15:01 . 2011-11-04 19:20 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-09-19 15:01 . 2011-12-17 19:46 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2006-09-26 14:42 . 2012-02-13 02:54 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2006-09-26 14:42 . 2012-02-14 02:34 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2006-09-26 14:42 . 2012-02-14 02:34 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-09-26 14:42 . 2012-02-13 02:54 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2012-02-13 03:02 . 2012-02-14 02:34 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2012-02-13 03:02 . 2012-02-13 02:54 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2012-02-13 03:02 . 2012-02-13 02:54 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2012-02-14 02:56 . 2012-02-14 02:34 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2012-02-16 02:05 . 2012-02-16 02:05 87408 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 87408 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
+ 2012-02-16 02:05 . 2012-02-16 02:05 93024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 93024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 35688 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
+ 2012-02-16 02:05 . 2012-02-16 02:05 35688 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 17784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
+ 2012-02-16 02:05 . 2012-02-16 02:05 17784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
+ 2012-02-16 02:05 . 2012-02-16 02:05 58240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 58240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 44920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 44920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 37240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 37240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 64352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 64352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 51032 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 51032 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 50552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 50552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 81784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 81784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 81800 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 81800 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 39784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 39784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 68952 c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 68952 c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 12128 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2012-02-06 04:57 . 2012-02-06 04:57 12128 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 97680 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 97680 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 17240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 17240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2012-02-16 02:03 . 2012-02-16 02:03 78168 c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 78168 c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 81248 c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 81248 c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2010-03-04 00:35 . 2012-02-16 02:01 35088 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
- 2010-03-04 00:35 . 2012-01-11 05:01 35088 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
- 2010-03-04 00:35 . 2012-01-11 05:01 18704 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\mspicons.exe
+ 2010-03-04 00:35 . 2012-02-16 02:01 18704 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\mspicons.exe
- 2010-03-04 00:35 . 2012-01-11 05:01 20240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\cagicon.exe
+ 2010-03-04 00:35 . 2012-02-16 02:01 20240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\cagicon.exe
- 2010-06-03 23:01 . 2011-10-14 01:29 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2010-06-03 23:01 . 2012-02-16 02:12 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2012-02-16 02:12 . 2011-11-04 19:20 12800 c:\windows\ie8updates\KB2647516-IE8\xpshims.dll
+ 2012-02-16 02:12 . 2011-11-04 19:20 66560 c:\windows\ie8updates\KB2647516-IE8\mshtmled.dll
+ 2012-02-16 02:12 . 2011-11-04 19:20 55296 c:\windows\ie8updates\KB2647516-IE8\msfeedsbs.dll
+ 2012-02-16 02:12 . 2011-11-04 19:20 43520 c:\windows\ie8updates\KB2647516-IE8\licmgr10.dll
+ 2012-02-16 02:12 . 2011-11-04 19:20 25600 c:\windows\ie8updates\KB2647516-IE8\jsproxy.dll
+ 2012-02-17 00:25 . 2012-02-17 00:25 14848 c:\windows\assembly\NativeImages_v4.0.30319_32\TVM\6665874987aa1e6cf9d49cf58d176227\TVM.ni.dll
+ 2012-02-17 00:29 . 2012-02-17 00:29 35328 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Pres#\604691fa729c36593aa141b07addb1da\System.Windows.Presentation.ni.dll
+ 2012-02-17 00:29 . 2012-02-17 00:29 71680 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Applicat#\df5e961346901ef1662daac2708f3888\System.Web.ApplicationServices.ni.dll
+ 2012-02-17 00:29 . 2012-02-17 00:29 82432 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\ce55cdba82e9103fc891b17d90f5a38f\System.ServiceModel.Channels.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 22016 c:\windows\assembly\NativeImages_v2.0.50727_32\TVM\8cf541848cc03d993ebd868e7aed1927\TVM.ni.dll
+ 2012-02-17 00:22 . 2012-02-17 00:22 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\dab766b18e6fe0a8f53a93c56be7b40e\System.Windows.Presentation.ni.dll
+ 2012-02-17 00:22 . 2012-02-17 00:22 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\31b65443e56a470d199f293085576e05\System.Web.DynamicData.Design.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\89dfd3999ad1d72c59243d7b4bf40d5a\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-02-17 00:03 . 2012-02-17 00:03 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\3aa4296d4aa01fe0533de2c15f818d5f\PresentationFontCache.ni.exe
+ 2012-02-17 00:01 . 2012-02-17 00:01 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\820acb71782d9cd006800b3ac7e1ca53\PresentationCFFRasterizer.ni.dll
+ 2012-02-17 00:21 . 2012-02-17 00:21 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\d07f0222f62dbed7898a6e2e909d407a\Microsoft.Vsa.ni.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2012-01-11 05:04 . 2012-01-11 05:04 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2012-01-11 05:05 . 2012-01-11 05:05 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2012-01-11 05:05 . 2012-01-11 05:05 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2012-02-06 04:57 . 2012-02-16 02:03 109568 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492\System.EnterpriseServices.Wrapper.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 109568 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492\System.EnterpriseServices.Wrapper.dll
+ 2012-02-06 04:57 . 2012-02-16 02:03 246128 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492\System.EnterpriseServices.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 246128 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492\System.EnterpriseServices.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2011-06-30 03:01 . 2012-01-11 05:05 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2011-06-30 03:01 . 2012-01-11 05:05 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2004-08-11 22:00 . 2011-11-04 19:20 105984 c:\windows\system32\url.dll
+ 2004-08-11 22:00 . 2011-12-17 19:46 105984 c:\windows\system32\url.dll
+ 2004-08-11 22:00 . 2012-02-16 02:24 535468 c:\windows\system32\perfh009.dat
- 2004-08-11 22:00 . 2012-02-06 04:57 535468 c:\windows\system32\perfh009.dat
+ 2004-08-11 22:00 . 2012-02-16 02:24 102478 c:\windows\system32\perfc009.dat
- 2004-08-11 22:00 . 2012-02-06 04:57 102478 c:\windows\system32\perfc009.dat
- 2004-08-11 22:00 . 2011-11-04 19:20 206848 c:\windows\system32\occache.dll
+ 2004-08-11 22:00 . 2011-12-17 19:46 206848 c:\windows\system32\occache.dll
+ 2004-08-11 22:00 . 2011-12-17 19:46 611840 c:\windows\system32\mstime.dll
- 2004-08-11 22:00 . 2011-11-04 19:20 611840 c:\windows\system32\mstime.dll
- 2007-08-13 23:54 . 2011-11-04 19:20 602112 c:\windows\system32\msfeeds.dll
+ 2007-08-13 23:54 . 2011-12-17 19:46 602112 c:\windows\system32\msfeeds.dll
+ 2004-08-11 22:00 . 2011-12-17 19:46 184320 c:\windows\system32\iepeers.dll
- 2004-08-11 22:00 . 2011-11-04 19:20 184320 c:\windows\system32\iepeers.dll
- 2004-08-11 22:00 . 2011-11-04 19:20 387584 c:\windows\system32\iedkcs32.dll
+ 2004-08-11 22:00 . 2011-12-17 19:46 387584 c:\windows\system32\iedkcs32.dll
+ 2004-08-11 22:00 . 2011-12-16 12:23 174080 c:\windows\system32\ie4uinit.exe
- 2004-08-11 22:00 . 2011-11-04 11:24 174080 c:\windows\system32\ie4uinit.exe
- 2006-09-19 15:01 . 2011-11-04 19:20 916992 c:\windows\system32\dllcache\wininet.dll
+ 2006-09-19 15:01 . 2011-12-17 19:46 916992 c:\windows\system32\dllcache\wininet.dll
- 2007-08-13 23:44 . 2011-11-04 19:20 105984 c:\windows\system32\dllcache\url.dll
+ 2007-08-13 23:44 . 2011-12-17 19:46 105984 c:\windows\system32\dllcache\url.dll
- 2007-08-13 23:44 . 2011-11-04 19:20 206848 c:\windows\system32\dllcache\occache.dll
+ 2007-08-13 23:44 . 2011-12-17 19:46 206848 c:\windows\system32\dllcache\occache.dll
+ 2006-09-19 15:01 . 2011-12-17 19:46 611840 c:\windows\system32\dllcache\mstime.dll
- 2006-09-19 15:01 . 2011-11-04 19:20 611840 c:\windows\system32\dllcache\mstime.dll
+ 2008-08-10 17:40 . 2011-12-17 19:46 602112 c:\windows\system32\dllcache\msfeeds.dll
- 2008-08-10 17:40 . 2011-11-04 19:20 602112 c:\windows\system32\dllcache\msfeeds.dll
- 2011-12-26 20:13 . 2011-11-04 19:20 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2011-12-26 20:13 . 2011-12-17 19:46 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2006-09-19 15:01 . 2011-11-04 19:20 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2006-09-19 15:01 . 2011-12-17 19:46 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2011-12-26 20:13 . 2011-12-17 19:46 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2011-12-26 20:13 . 2011-11-04 19:20 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2007-08-13 23:39 . 2011-11-04 19:20 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2007-08-13 23:39 . 2011-12-17 19:46 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2007-08-13 23:39 . 2011-11-04 11:24 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-08-13 23:39 . 2011-12-16 12:23 174080 c:\windows\system32\dllcache\ie4uinit.exe
- 2012-02-06 04:58 . 2012-02-06 04:58 350592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
+ 2012-02-16 02:05 . 2012-02-16 02:05 350592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
+ 2012-02-16 02:05 . 2012-02-16 02:05 163168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 163168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 138592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 138592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 699224 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 699224 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 857960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 857960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 675672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 675672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
+ 2012-02-06 04:57 . 2012-02-16 02:04 113512 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 113512 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 129912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 129912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 390008 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 390008 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 505208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 505208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 261472 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 261472 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 122264 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 122264 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 291184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2012-02-06 04:58 . 2012-02-16 02:04 291184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 349568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 349568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 231760 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 231760 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 253280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 253280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 378720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 378720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 134528 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 134528 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 123736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 123736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 392552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 392552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 125816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 125816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 120152 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 120152 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 607064 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2012-02-06 04:57 . 2012-02-16 02:04 607064 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 395120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 395120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 182144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 182144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 285072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 285072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 829280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 829280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 747360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 747360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 436600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 436600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 683872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 683872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 409448 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2012-02-06 04:57 . 2012-02-16 02:04 409448 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 210816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 210816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 149848 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 149848 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 122248 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 122248 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 525704 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 525704 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 112976 c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 112976 c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2012-02-16 02:05 . 2012-02-16 02:05 581464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 581464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 832856 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
+ 2012-02-16 02:05 . 2012-02-16 02:05 832856 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 194424 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
+ 2012-02-16 02:05 . 2012-02-16 02:05 194424 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
+ 2012-02-16 02:05 . 2012-02-16 02:05 478576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 478576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
+ 2012-02-16 02:05 . 2012-02-16 02:05 167288 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 167288 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 232304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2012-02-16 02:05 . 2012-02-16 02:05 232304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 661352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 661352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 349576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 349576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 387960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 387960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 746336 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 746336 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2012-02-16 02:03 . 2012-02-16 02:03 505184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 505184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 269672 c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2012-02-06 04:58 . 2012-02-16 02:04 269672 c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 334688 c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 334688 c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 109568 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-02-06 04:57 . 2012-02-16 02:03 109568 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 246128 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2012-02-06 04:57 . 2012-02-16 02:03 246128 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 170368 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 170368 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2010-03-04 00:35 . 2012-02-16 02:01 888080 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
- 2010-03-04 00:35 . 2012-01-11 05:01 888080 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
- 2010-03-04 00:35 . 2012-01-11 05:01 272648 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pubs.exe
+ 2010-03-04 00:35 . 2012-02-16 02:01 272648 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pubs.exe
- 2010-03-04 00:35 . 2012-01-11 05:01 922384 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pptico.exe
+ 2010-03-04 00:35 . 2012-02-16 02:01 922384 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pptico.exe
+ 2010-03-04 00:35 . 2012-02-16 02:01 845584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
- 2010-03-04 00:35 . 2012-01-11 05:01 845584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
- 2010-03-04 00:35 . 2012-01-11 05:01 217864 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\misc.exe
+ 2010-03-04 00:35 . 2012-02-16 02:01 217864 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\misc.exe
+ 2010-03-04 00:35 . 2012-02-16 02:01 159504 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\inficon.exe
- 2010-03-04 00:35 . 2012-01-11 05:01 159504 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\inficon.exe
+ 2012-02-16 02:12 . 2011-11-04 19:20 916992 c:\windows\ie8updates\KB2647516-IE8\wininet.dll
+ 2012-02-16 02:12 . 2011-11-04 19:20 105984 c:\windows\ie8updates\KB2647516-IE8\url.dll
+ 2012-02-16 02:12 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2647516-IE8\spuninst\updspapi.dll
+ 2012-02-16 02:12 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2647516-IE8\spuninst\spuninst.exe
+ 2012-02-16 02:12 . 2011-11-04 19:20 206848 c:\windows\ie8updates\KB2647516-IE8\occache.dll
+ 2012-02-16 02:12 . 2011-11-04 19:20 611840 c:\windows\ie8updates\KB2647516-IE8\mstime.dll
+ 2012-02-16 02:12 . 2011-11-04 19:20 602112 c:\windows\ie8updates\KB2647516-IE8\msfeeds.dll
+ 2012-02-16 02:12 . 2011-11-04 19:20 247808 c:\windows\ie8updates\KB2647516-IE8\ieproxy.dll
+ 2012-02-16 02:12 . 2011-11-04 19:20 184320 c:\windows\ie8updates\KB2647516-IE8\iepeers.dll
+ 2012-02-16 02:12 . 2011-11-04 19:20 743424 c:\windows\ie8updates\KB2647516-IE8\iedvtool.dll
+ 2012-02-16 02:12 . 2011-11-04 19:20 387584 c:\windows\ie8updates\KB2647516-IE8\iedkcs32.dll
+ 2012-02-16 02:12 . 2011-11-04 11:24 174080 c:\windows\ie8updates\KB2647516-IE8\ie4uinit.exe
+ 2012-02-06 04:57 . 2012-02-06 04:57 409448 c:\windows\assembly\temp\XQ50NY9ATV\System.configuration.dll
+ 2012-02-06 04:58 . 2012-02-06 04:58 291184 c:\windows\assembly\temp\QEXEZRG4RU\System.Runtime.Remoting.dll
+ 2012-02-06 04:57 . 2012-02-06 04:57 607064 c:\windows\assembly\temp\EEX3W25QIM\System.Drawing.dll
+ 2012-02-06 04:58 . 2012-02-06 04:58 269672 c:\windows\assembly\temp\6LMVV4H03G\System.Transactions.dll
+ 2012-02-06 04:57 . 2012-02-06 04:57 113512 c:\windows\assembly\temp\3FMVE83NI2\System.ServiceProcess.dll
+ 2012-02-06 04:57 . 2012-02-06 04:57 109568 c:\windows\assembly\temp\2AQCJQTBW1\System.EnterpriseServices.Wrapper.dll
+ 2012-02-06 04:57 . 2012-02-06 04:57 246128 c:\windows\assembly\temp\2AQCJQTBW1\System.EnterpriseServices.dll
+ 2012-02-17 00:25 . 2012-02-17 00:25 252416 c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsFormsIntegra#\5b2066cece646c758c73a13cca7c82b7\WindowsFormsIntegration.ni.dll
+ 2012-02-17 00:29 . 2012-02-17 00:29 482816 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClient\1bc856ec98668f28b06dc195e6f73603\UIAutomationClient.ni.dll
+ 2012-02-16 02:18 . 2012-02-16 02:18 391680 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\8a6f500c40e3fa7da71110af6c0a60ac\System.Xml.Linq.ni.dll
+ 2012-02-17 00:25 . 2012-02-17 00:25 120320 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Inte#\f066f2b1238b4a5d8147afb94337d8c7\System.Windows.Interactivity.ni.dll
+ 2012-02-16 02:19 . 2012-02-16 02:19 188928 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Inpu#\ca11ffdc7fa5af9ba6902d72b0b932c2\System.Windows.Input.Manipulations.ni.dll
+ 2012-02-16 02:18 . 2012-02-16 02:18 646656 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\c3a03bb69e38f5ed9ebce72d48a722ef\System.Transactions.ni.dll
+ 2012-02-17 00:29 . 2012-02-17 00:29 221696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\d7fbfc6836ce7e53486ddb79b598ca8d\System.ServiceProcess.ni.dll
+ 2012-02-17 00:29 . 2012-02-17 00:29 365056 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\f1a00750deae84241a140f4e4233fe71\System.ServiceModel.Routing.ni.dll
+ 2012-02-16 02:08 . 2012-02-16 02:08 729088 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Security\09ee8d91e80e00991226aec062aa1e92\System.Security.ni.dll
+ 2012-02-16 02:19 . 2012-02-16 02:19 762368 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\01e360ed3a3cb2b0a3c47c7f3eb09e58\System.Runtime.Remoting.ni.dll
+ 2012-02-17 00:23 . 2012-02-17 00:23 653312 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Net\ecf10c574f8bd9a05b021e7880a1041c\System.Net.ni.dll
+ 2012-02-17 00:28 . 2012-02-17 00:28 626176 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Messaging\f751ad889c61578ae7e1d656e798cd72\System.Messaging.ni.dll
+ 2012-02-17 00:28 . 2012-02-17 00:28 395264 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management.I#\98ec4a836fdbe4d88306206d6fc326ec\System.Management.Instrumentation.ni.dll
+ 2012-02-17 00:28 . 2012-02-17 00:28 413696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IO.Log\3aada4dce5c9f819d192b0bba0a298bc\System.IO.Log.ni.dll
+ 2012-02-17 00:28 . 2012-02-17 00:28 229376 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityMode#\015d3fcedc60e04e3fce6aa3b63057d9\System.IdentityModel.Selectors.ni.dll
+ 2012-02-16 02:19 . 2012-02-16 02:19 236032 c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\47a2b7b2fa872de3078d49d0a4c10cb2\System.EnterpriseServices.Wrapper.dll
+ 2012-02-16 02:19 . 2012-02-16 02:19 786944 c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\47a2b7b2fa872de3078d49d0a4c10cb2\System.EnterpriseServices.ni.dll
+ 2012-02-16 02:08 . 2012-02-16 02:08 377344 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Dynamic\30bdf637fad5e84fc46d7322f487c801\System.Dynamic.ni.dll
+ 2012-02-17 00:28 . 2012-02-17 00:28 468992 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\e05bc4bfe46686b77f1e28b466f79363\System.DirectoryServices.Protocols.ni.dll
+ 2012-02-17 00:28 . 2012-02-17 00:28 913920 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\9ada0ce9819a2eeb6d3b7d4942cf278f\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-02-17 00:28 . 2012-02-17 00:28 112640 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Device\fa66f17c3937c91c1b480c24aa602812\System.Device.ni.dll
+ 2012-02-17 00:26 . 2012-02-17 00:26 134656 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.DataSet#\8b353356367e7da5d31e49057a59c749\System.Data.DataSetExtensions.ni.dll
+ 2012-02-16 02:08 . 2012-02-16 02:08 980480 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\363b05dd092178671e56531a9c4999b6\System.Configuration.ni.dll
+ 2012-02-17 00:26 . 2012-02-17 00:26 148480 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuratio#\8e28c1bf907bc67c6685db26050c19bd\System.Configuration.Install.ni.dll
+ 2012-02-17 00:26 . 2012-02-17 00:26 194048 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\ac4bd5fece3ee7b1632817a509bcd909\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-02-16 02:08 . 2012-02-16 02:08 690176 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\768ccd38c2bf1f7045e79ac03cb679f1\System.ComponentModel.Composition.ni.dll
+ 2012-02-17 00:26 . 2012-02-17 00:26 617984 c:\windows\assembly\NativeImages_v4.0.30319_32\System.AddIn\266d00e0694b48964ead82a67657462b\System.AddIn.ni.dll
+ 2012-02-17 00:26 . 2012-02-17 00:26 404992 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.D#\754d38ef09a80e6bc721a0039d72b65b\System.Activities.DurableInstancing.ni.dll
+ 2012-02-17 00:25 . 2012-02-17 00:25 317952 c:\windows\assembly\NativeImages_v4.0.30319_32\SMSvcHost\024df3845eee3a86a396d972162fffc4\SMSvcHost.ni.exe
+ 2012-02-16 02:18 . 2012-02-16 02:18 142848 c:\windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\ba4bc24df463a622c0e918d8c49672ed\SMDiagnostics.ni.dll
+ 2012-02-16 02:06 . 2012-02-16 02:06 450560 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\daec0a92c216faca879f205a2e8e8169\PresentationFramework.Aero.ni.dll
+ 2012-02-16 02:07 . 2012-02-16 02:07 656896 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\942a5e3ee871f5f4a323d95505f9667c\PresentationFramework.Luna.ni.dll
+ 2012-02-16 02:10 . 2012-02-16 02:10 327680 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\65bd29660d00ac08c14edad26ce38e2c\PresentationFramework.Royale.ni.dll
+ 2012-02-16 02:07 . 2012-02-16 02:07 284160 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\446fc2e471272940ddac8c8c949000cf\PresentationFramework.Classic.ni.dll
+ 2012-02-17 00:25 . 2012-02-17 00:25 219648 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\f5b68c14da88f27f5360846828d61dc5\Microsoft.VisualBasic.Compatibility.Data.ni.dll
+ 2012-02-17 00:25 . 2012-02-17 00:25 418816 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\d6386aaa2c8ab67caaee9684c3842c04\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-02-17 00:25 . 2012-02-17 00:25 985088 c:\windows\assembly\NativeImages_v4.0.30319_32\Intuit.Ctg.Wte.Serv#\7cb77ea133c57a9623be66885e7868f0\Intuit.Ctg.Wte.Service.Interface.ni.dll
+ 2012-02-17 00:24 . 2012-02-17 00:24 198656 c:\windows\assembly\NativeImages_v4.0.30319_32\IKVM.Runtime.JNI\83eb66c6dd1478a8178c6a75c591cfa2\IKVM.Runtime.JNI.ni.dll
+ 2012-02-17 00:24 . 2012-02-17 00:24 254976 c:\windows\assembly\NativeImages_v4.0.30319_32\common-utility\debeee8deb8ca7ff852f284ec166c9df\common-utility.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\edc5691acfb65ac37f49de2ec497083a\WsatConfig.ni.exe
+ 2012-02-17 00:10 . 2012-02-17 00:10 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\4ad8369d6a60765d7e9b43cdf9023f41\WindowsFormsIntegration.ni.dll
+ 2012-02-17 00:10 . 2012-02-17 00:10 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\68f4157e570c77df653057c0583395bd\UIAutomationClient.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\c2a12bd4056b44f8005a7eb3af161e6a\System.Xml.Linq.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 116736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Inte#\bbb595104028e3a84714d966779a309e\System.Windows.Interactivity.ni.dll
+ 2012-02-17 00:22 . 2012-02-17 00:22 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\fc63b434b2f253cd27625487f7b02ac0\System.Web.Routing.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\67877f896b2b0e42286e838fe307f3fd\System.Web.RegularExpressions.ni.dll
+ 2012-02-17 00:22 . 2012-02-17 00:22 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\86650d4fb220f94f25bb5da42a03d454\System.Web.Extensions.Design.ni.dll
+ 2012-02-17 00:22 . 2012-02-17 00:22 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\654465871e547e131668874de7c60b8c\System.Web.Entity.ni.dll
+ 2012-02-17 00:22 . 2012-02-17 00:22 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\f0d6895f6e709d425cb5da6053c603d2\System.Web.Entity.Design.ni.dll
+ 2012-02-17 00:22 . 2012-02-17 00:22 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\3f3b7dc7208e302e39a2dfb5b2cb953b\System.Web.DynamicData.ni.dll
+ 2012-02-17 00:22 . 2012-02-17 00:22 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\e9cddd213343f15d611b14620d649bb0\System.Web.Abstractions.ni.dll
+ 2012-02-17 00:17 . 2012-02-17 00:17 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\f25d114cb629d1f512f98883c6535a75\System.Transactions.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\11dcb806c92f55111f5fa9f1a90e3bdd\System.ServiceProcess.ni.dll
+ 2012-02-17 00:17 . 2012-02-17 00:17 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\5fb9981f4147b537b53be9d58bf4e9b4\System.Security.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\1335dd98ce5ce22ad1f51cc274ca5a1d\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\c14e58265386feb509cc61bb5e8dd296\System.Runtime.Remoting.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\a4b2b1ee81acd843970d9a81b281f1c1\System.Net.ni.dll
+ 2012-02-17 00:21 . 2012-02-17 00:21 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\a2a14380e8c9149d5b212d0100ef588a\System.Management.ni.dll
+ 2012-02-17 00:21 . 2012-02-17 00:21 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\e3436edde657a5111d39d5b2eecf9715\System.Management.Instrumentation.ni.dll
+ 2012-02-17 00:17 . 2012-02-17 00:17 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\974ded7dd3bca225a1b90de778846c78\System.IO.Log.ni.dll
+ 2012-02-17 00:17 . 2012-02-17 00:17 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\01eba24390736a59c39becd825b5756e\System.IdentityModel.Selectors.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\c0d15fb6308587fef8744d568e64bcda\System.EnterpriseServices.Wrapper.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\c0d15fb6308587fef8744d568e64bcda\System.EnterpriseServices.ni.dll
+ 2012-02-17 00:08 . 2012-02-17 00:08 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\e9ae7ae6d1e9edc7aaf819889cd1c692\System.Drawing.Design.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\78a370dc153011708dd9e4cb0e606bfc\System.DirectoryServices.Protocols.ni.dll
+ 2012-02-17 00:21 . 2012-02-17 00:21 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\6e644fc7464d9fe23fc9cd6001296f2f\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-02-17 00:20 . 2012-02-17 00:20 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\bac39be66bb9f987c1948b766833f8e6\System.Data.Services.Client.ni.dll
+ 2012-02-17 00:20 . 2012-02-17 00:20 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\2b5ecd231320e57010043c408783d80b\System.Data.Services.Design.ni.dll
+ 2012-02-17 00:20 . 2012-02-17 00:20 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\4ac9ac2326720485aefd4d79d2024945\System.Data.Entity.Design.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\d504d550fd0a6994fcb1466ea7be92af\System.Data.DataSetExtensions.ni.dll
+ 2012-02-17 00:17 . 2012-02-17 00:17 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\94a40f415bfa947e251888bbe88bb973\System.Configuration.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\28637135c6939e74450bbbf110b12643\System.Configuration.Install.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\958b5c0114d664ab5ba72575c301e2ea\System.AddIn.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\4dcff3b0e79fc27e31549bb2af00efb5\SMSvcHost.ni.exe
+ 2012-02-17 00:19 . 2012-02-17 00:19 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\bd3bfd5b6ef659dac4d6cccb34577d33\SMDiagnostics.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\edec83be646eb52204c991371751a428\ServiceModelReg.ni.exe
+ 2012-02-17 00:05 . 2012-02-17 00:05 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\52015457bc28e7a9a563d9eab8ab0015\PresentationFramework.Royale.ni.dll
+ 2012-02-17 00:05 . 2012-02-17 00:05 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\46a680814559114706a33282e9df4b7a\PresentationFramework.Classic.ni.dll
+ 2012-02-17 00:05 . 2012-02-17 00:05 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2713754549b1114c9152d33efe5f72c7\PresentationFramework.Aero.ni.dll
+ 2012-02-17 00:05 . 2012-02-17 00:05 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\1552f18ca434c1dca6d082df476d089a\PresentationFramework.Luna.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\7c51497b188c82e2ccbe6315549ce023\MSBuild.ni.exe
+ 2012-02-17 00:19 . 2012-02-17 00:19 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\f0f6dd614d294295c5d8386cc4192034\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 148480 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\fb938a1d399e2cfca2304bdca4fe76dc\Microsoft.PowerShell.Security.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 968192 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\a03adbb7c3084d986da6e22dcce9805f\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 433664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\8a25afef0d57ac430ba392595eba639f\Microsoft.PowerShell.Commands.Management.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 492032 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\875af0c2a5e8a4bed88232b6f445cfaa\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\fd1338828beec8737fed8f50f4fcc567\Microsoft.Build.Utilities.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\0d5f999c4b7e51151548c37c676c1b8e\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\792168ce8fe03a3db43e12cf736cf91e\Microsoft.Build.Engine.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\0a5277c34ddc1f55df1defb4231e814f\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 960512 c:\windows\assembly\NativeImages_v2.0.50727_32\Intuit.Ctg.Wte.Serv#\27fe08cadaf2f4530b762ca45a122455\Intuit.Ctg.Wte.Service.Interface.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\a8df37aadb089f1f34d3d2f103966fbc\ComSvcConfig.ni.exe
+ 2012-02-17 00:17 . 2012-02-17 00:17 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\25ce400b547f517258c8afb0480390ea\AspNetMMCExt.ni.dll
- 2012-01-11 05:04 . 2012-01-11 05:04 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2011-06-30 03:01 . 2012-01-11 05:05 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2011-06-30 03:01 . 2012-01-11 05:05 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2011-06-30 03:01 . 2012-01-11 05:05 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2011-06-30 03:01 . 2012-01-11 05:05 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2012-02-16 02:22 . 2012-02-16 02:22 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2012-01-11 05:04 . 2012-01-11 05:04 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2011-06-30 03:01 . 2012-01-11 05:05 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2011-06-30 03:01 . 2012-01-11 05:05 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2011-06-30 03:01 . 2012-01-11 05:05 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2012-01-11 05:05 . 2012-01-11 05:05 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2004-08-11 22:00 . 2011-11-04 19:20 1212416 c:\windows\system32\urlmon.dll
+ 2004-08-11 22:00 . 2011-12-17 19:46 1212416 c:\windows\system32\urlmon.dll
+ 2004-08-11 22:00 . 2011-12-17 19:46 5979136 c:\windows\system32\mshtml.dll
+ 2007-08-13 23:34 . 2011-12-17 19:46 2000384 c:\windows\system32\iertutil.dll
- 2007-08-13 23:34 . 2011-11-04 19:20 2000384 c:\windows\system32\iertutil.dll
- 2004-08-11 22:06 . 2011-12-27 13:11 1771448 c:\windows\system32\FNTCACHE.DAT
+ 2004-08-11 22:06 . 2012-02-16 23:55 1771448 c:\windows\system32\FNTCACHE.DAT
+ 2008-10-15 11:42 . 2012-01-12 16:53 1859968 c:\windows\system32\dllcache\win32k.sys
- 2006-09-19 15:01 . 2011-11-04 19:20 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2006-09-19 15:01 . 2011-12-17 19:46 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2006-05-19 13:08 . 2011-12-17 19:46 5979136 c:\windows\system32\dllcache\mshtml.dll
- 2008-08-10 17:40 . 2011-11-04 19:20 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2008-08-10 17:40 . 2011-12-17 19:46 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2011-10-26 20:46 . 2011-10-26 20:46 3511880 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.dll
+ 2011-10-26 09:39 . 2011-10-26 09:39 3186688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 1303896 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2012-02-16 02:05 . 2012-02-16 02:05 1303896 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2012-02-06 04:57 . 2012-02-16 02:04 3511880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 2207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-02-06 04:57 . 2012-02-16 02:04 2207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-02-06 04:57 . 2012-02-16 02:04 5028200 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 5028200 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 1711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 1711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 6067048 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 6067048 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 1026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 1026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 4464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 4464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 1339736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 1339736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 1199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 1199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 1462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 1462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
+ 2012-02-16 02:05 . 2012-02-16 02:05 6346600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 6346600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2012-02-06 04:57 . 2012-02-16 02:04 2970968 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 2970968 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 3545952 c:\windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2012-02-06 04:58 . 2012-02-06 04:58 3545952 c:\windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2012-02-16 02:03 . 2012-02-16 02:03 5197648 c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 5197648 c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-02-16 02:04 . 2012-02-16 02:04 2989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
- 2012-02-06 04:57 . 2012-02-06 04:57 2989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2011-10-31 04:54 . 2011-10-31 04:54 2748416 c:\windows\Installer\2b81e3.msp
+ 2011-10-26 21:38 . 2011-10-26 21:38 2830848 c:\windows\Installer\2b81cf.msp
+ 2012-02-03 21:13 . 2012-02-03 21:13 4988928 c:\windows\Installer\2b81c6.msp
- 2010-03-04 00:35 . 2012-01-11 05:01 1172240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
+ 2010-03-04 00:35 . 2012-02-16 02:01 1172240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
+ 2010-03-04 00:35 . 2012-02-16 02:01 1165584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
- 2010-03-04 00:35 . 2012-01-11 05:01 1165584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
+ 2012-02-16 02:12 . 2011-11-04 19:20 1212416 c:\windows\ie8updates\KB2647516-IE8\urlmon.dll
+ 2012-02-16 02:12 . 2011-11-04 19:20 5978112 c:\windows\ie8updates\KB2647516-IE8\mshtml.dll
+ 2012-02-16 02:12 . 2011-11-04 19:20 2000384 c:\windows\ie8updates\KB2647516-IE8\iertutil.dll
+ 2012-02-06 04:57 . 2012-02-06 04:57 3510600 c:\windows\assembly\temp\O88ED2DADU\System.dll
+ 2012-02-06 04:57 . 2012-02-06 04:57 5028200 c:\windows\assembly\temp\HGNILHDY1X\System.Windows.Forms.dll
+ 2012-02-06 04:57 . 2012-02-06 04:57 2970968 c:\windows\assembly\temp\GWQ24NWWDK\System.Data.dll
+ 2012-02-06 04:57 . 2012-02-06 04:57 2207568 c:\windows\assembly\temp\8F6LC69LRE\System.XML.dll
+ 2012-02-16 02:07 . 2012-02-16 02:07 3798016 c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\ff4ecc058f27a9c36136e5d38e43fb59\WindowsBase.ni.dll
+ 2012-02-17 00:29 . 2012-02-17 00:29 1057792 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClients#\e06dfa0ecf8c6c4f9848eedb9f8db0c5\UIAutomationClientsideProviders.ni.dll
+ 2012-02-16 02:18 . 2012-02-16 02:18 3384832 c:\windows\assembly\NativeImages_v4.0.30319_32\ttax\1e4e724646d5d61262ea804bac8792b0\ttax.ni.dll
+ 2012-02-16 02:06 . 2012-02-16 02:06 9090560 c:\windows\assembly\NativeImages_v4.0.30319_32\System\3ff4657a86a0e14b4be577969e0ec762\System.ni.dll
+ 2012-02-16 02:08 . 2012-02-16 02:08 5618176 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml\21071fcc838660d96f10920c4c3cd206\System.Xml.ni.dll
+ 2012-02-16 02:18 . 2012-02-16 02:18 1781760 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\04326608ac9ad05c2a1e8bd46a068a91\System.Xaml.ni.dll
+ 2012-02-17 00:29 . 2012-02-17 00:29 4545024 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form#\f9d4746b5e5edf68c3001feaa0f03893\System.Windows.Forms.DataVisualization.ni.dll
+ 2012-02-17 00:25 . 2012-02-17 00:25 1859584 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\ce22f267e17c7749c6a0dd2aa3403484\System.Web.Services.ni.dll
+ 2012-02-17 00:29 . 2012-02-17 00:29 2011136 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Speech\7a9b2475f61a6db6393750142765c5f1\System.Speech.ni.dll
+ 2012-02-17 00:29 . 2012-02-17 00:29 1128960 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\b663714058d4a0c1fcaa56e4ac223be5\System.ServiceModel.Discovery.ni.dll
+ 2012-02-17 00:29 . 2012-02-17 00:29 1387520 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\685616ff1660152acefb312db7061435\System.ServiceModel.Activities.ni.dll
+ 2012-02-16 02:18 . 2012-02-16 02:18 2637312 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\9db486997d651f0646a089ff6cfb605e\System.Runtime.Serialization.ni.dll
+ 2012-02-16 02:18 . 2012-02-16 02:18 1020928 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\f56869ede7c0fddb751c39e050dd62a8\System.Runtime.DurableInstancing.ni.dll
+ 2012-02-17 00:23 . 2012-02-17 00:23 1050112 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Printing\1393672b78ebd95ec154740a55fe600b\System.Printing.ni.dll
+ 2012-02-17 00:28 . 2012-02-17 00:28 1218560 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management\b1b57351a88c0c9c46bd9424347336ea\System.Management.ni.dll
+ 2012-02-17 00:28 . 2012-02-17 00:28 1072128 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\a0204aa75b8665f3c674ff18eebbf13f\System.IdentityModel.ni.dll
+ 2012-02-16 02:06 . 2012-02-16 02:06 1652736 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\2ff57b810eb920860469184dd683cb8a\System.Drawing.ni.dll
+ 2012-02-16 02:19 . 2012-02-16 02:19 1172992 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\b828e979c92841bd6a2ddd05ee2b0b73\System.DirectoryServices.ni.dll
+ 2012-02-16 02:19 . 2012-02-16 02:19 1878016 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Deployment\c100e2bfd00aa5b9f3c8e4ab6e2bfaf8\System.Deployment.ni.dll
+ 2012-02-16 02:09 . 2012-02-16 02:09 6798336 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data\97586cdb698c29ba95fd83e44a0c0ca6\System.Data.ni.dll
+ 2012-02-16 02:08 . 2012-02-16 02:08 2545152 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.SqlXml\cc02699121b243dc52e77197ad973fc3\System.Data.SqlXml.ni.dll
+ 2012-02-17 00:28 . 2012-02-17 00:28 1338880 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\81b00eddd2b081f8f7546a290d5ad9ef\System.Data.Services.Client.ni.dll
+ 2012-02-16 02:09 . 2012-02-16 02:09 2512384 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\3d105e94140b8c742ed50a2c6194394c\System.Data.Linq.ni.dll
+ 2012-02-16 02:08 . 2012-02-16 02:08 7054336 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Core\a2b1103ad3d9f329e0c9164994137c81\System.Core.ni.dll
+ 2012-02-17 00:25 . 2012-02-17 00:25 4121088 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities\9ecc40af067f2aca2dda1f71500020fa\System.Activities.ni.dll
+ 2012-02-17 00:26 . 2012-02-17 00:26 3713024 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.P#\17f4e3e5193e8b645d7405eda38596be\System.Activities.Presentation.ni.dll
+ 2012-02-17 00:25 . 2012-02-17 00:25 1518080 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.C#\d0abf08a9033e02b1ac26da22a51b586\System.Activities.Core.Presentation.ni.dll
+ 2012-02-17 00:23 . 2012-02-17 00:23 2859008 c:\windows\assembly\NativeImages_v4.0.30319_32\ReachFramework\9e16cb68553721cdf0bfdb8a74f428ef\ReachFramework.ni.dll
+ 2012-02-17 00:23 . 2012-02-17 00:23 9906688 c:\windows\assembly\NativeImages_v4.0.30319_32\print-engine\6341eb1f5291a37a767c2a0ccee045a2\print-engine.ni.dll
+ 2012-02-16 02:19 . 2012-02-16 02:19 1630208 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationUI\f511ee77a639501cf892d90f33927451\PresentationUI.ni.dll
+ 2012-02-17 00:25 . 2012-02-17 00:25 1836544 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\910f1781ed5873e2f9ffec2b687c3e99\Microsoft.VisualBasic.ni.dll
+ 2012-02-17 00:25 . 2012-02-17 00:25 1136128 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\5f1f374d228aa3523d5c947f0d758627\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2012-02-17 00:25 . 2012-02-17 00:25 1172480 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\1d3556e5e6be255dde120df39bd18709\Microsoft.VisualBasic.Activities.Compiler.ni.dll
+ 2012-02-17 00:25 . 2012-02-17 00:25 1082368 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\a05d0a2bece90cfc10cb64ff7fe39e94\Microsoft.Transactions.Bridge.ni.dll
+ 2012-02-17 00:28 . 2012-02-17 00:28 2452480 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.JScript\101b3fc8861dc9ed88896666432ae7c0\Microsoft.JScript.ni.dll
+ 2012-02-16 02:08 . 2012-02-16 02:08 1616384 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.CSharp\5e4d35f27edcdebe56cc5bb5b5174275\Microsoft.CSharp.ni.dll
+ 2012-02-17 00:25 . 2012-02-17 00:25 1650688 c:\windows\assembly\NativeImages_v4.0.30319_32\Intuit.Ctg.Map\f5064dac191fcddada47c69befca85ca\Intuit.Ctg.Map.ni.dll
+ 2012-02-17 00:23 . 2012-02-17 00:23 2121216 c:\windows\assembly\NativeImages_v4.0.30319_32\IKVM.Runtime\6ed52679f97c61f753fa099a891f9b38\IKVM.Runtime.ni.dll
+ 2012-02-17 00:24 . 2012-02-17 00:24 4391424 c:\windows\assembly\NativeImages_v4.0.30319_32\IKVM.OpenJDK.Util\16be1b1f377121787570cc9f69d59014\IKVM.OpenJDK.Util.ni.dll
+ 2012-02-17 00:24 . 2012-02-17 00:24 1371136 c:\windows\assembly\NativeImages_v4.0.30319_32\IKVM.OpenJDK.Text\05cad06a4077ed73c5d14795deb5640b\IKVM.OpenJDK.Text.ni.dll
+ 2012-02-17 00:24 . 2012-02-17 00:24 6602240 c:\windows\assembly\NativeImages_v4.0.30319_32\IKVM.OpenJDK.Securi#\90793788fccb4b43eb74496ae2fe4af5\IKVM.OpenJDK.Security.ni.dll
+ 2012-02-17 00:24 . 2012-02-17 00:24 8305664 c:\windows\assembly\NativeImages_v4.0.30319_32\IKVM.OpenJDK.Core\659573af3af56b5ab4fc7a0ea72161a9\IKVM.OpenJDK.Core.ni.dll
+ 2012-02-17 00:01 . 2012-02-17 00:01 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\174c2f776741812aed02c337bbcd1dae\WindowsBase.ni.dll
+ 2012-02-17 00:10 . 2012-02-17 00:10 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\94f5164ff4f664c5e4e7fb4c3af1abad\UIAutomationClientsideProviders.ni.dll
+ 2012-02-17 00:17 . 2012-02-17 00:17 3432448 c:\windows\assembly\NativeImages_v2.0.50727_32\ttax\0374673619dd48966dacf9074c729d8f\ttax.ni.dll
+ 2012-02-17 00:00 . 2012-02-17 00:00 7953408 c:\windows\assembly\NativeImages_v2.0.50727_32\System\9e3803cd2a11f056291862e306a8e2b2\System.ni.dll
+ 2012-02-17 00:10 . 2012-02-17 00:10 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\77e1279cbf4eecfb0284b63316fe43fe\System.Xml.ni.dll
+ 2012-02-17 00:22 . 2012-02-17 00:22 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\c4c671c737b553db8e07664816475333\System.WorkflowServices.ni.dll
+ 2012-02-17 00:22 . 2012-02-17 00:22 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\248ea47105ff4af6ee75e6fdd5b450a1\System.Workflow.Runtime.ni.dll
+ 2012-02-17 00:22 . 2012-02-17 00:22 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\80a288b6611668160334668cc2608e4a\System.Workflow.ComponentModel.ni.dll
+ 2012-02-17 00:22 . 2012-02-17 00:22 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\4c27548df5897320840ee0d65db38742\System.Workflow.Activities.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\e9ba004858dcdb5958d86f26f043f85a\System.Web.Services.ni.dll
+ 2012-02-17 00:22 . 2012-02-17 00:22 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\030cde14924eefebc06c240dbfe093a4\System.Web.Mobile.ni.dll
+ 2012-02-17 00:22 . 2012-02-17 00:22 2405888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\6379c8ca8ae11effb415139990923ff1\System.Web.Extensions.ni.dll
+ 2012-02-17 00:09 . 2012-02-17 00:09 1917440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\e456140d5d6c43d7383bd36d3f9e12c6\System.Speech.ni.dll
+ 2012-02-17 00:22 . 2012-02-17 00:22 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\285dfbf2380436e187cb624bd1cd4683\System.ServiceModel.Web.ni.dll
+ 2012-02-17 00:17 . 2012-02-17 00:17 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\f2532204217dc10f152afd077b09927c\System.Runtime.Serialization.ni.dll
+ 2012-02-17 00:09 . 2012-02-17 00:09 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\d51e6bb07124a1d780d1e024858e0dc1\System.Printing.ni.dll
+ 2012-02-17 00:21 . 2012-02-17 00:21 4950016 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\10fdfb918f01ebc41f38a391334146a9\System.Management.Automation.ni.dll
+ 2012-02-17 00:17 . 2012-02-17 00:17 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\8ef05061cd205c4f2a8583d97f32a603\System.IdentityModel.ni.dll
+ 2012-02-17 00:08 . 2012-02-17 00:08 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\9351cf29bb1ba951e45a9b3b0edab937\System.Drawing.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\77d0e93f024055d04c07cc2700b4c590\System.DirectoryServices.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\707a05a7d5a8d99dd56d1d50311a60d2\System.Deployment.ni.dll
+ 2012-02-17 00:05 . 2012-02-17 00:06 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\ae888f8633fce3ff1de98e32bce0abbf\System.Data.ni.dll
+ 2012-02-17 00:17 . 2012-02-17 00:17 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\857300fa64d09c69125451fd8894f3da\System.Data.SqlXml.ni.dll
+ 2012-02-17 00:20 . 2012-02-17 00:20 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\e9d4a1fb13572c769ddd9b86e55baab4\System.Data.Services.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 1115136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\3f2e74586111fb32d5edc059f709fa94\System.Data.OracleClient.ni.dll
+ 2012-02-17 00:06 . 2012-02-17 00:06 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\c3d9c33f71d15a3e2e240092a244eba3\System.Data.Linq.ni.dll
+ 2012-02-17 00:20 . 2012-02-17 00:20 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\19cca2921cfe3d20265389e596ebfd69\System.Data.Entity.ni.dll
+ 2012-02-17 00:05 . 2012-02-17 00:05 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\0a6d6717e76be12295711ff02c7aa1d4\System.Core.ni.dll
+ 2012-02-17 00:05 . 2012-02-17 00:05 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\33cdfb4c322a528260016ac759230501\ReachFramework.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\a6def83aee1aaf3336675ce58ac09013\PresentationUI.ni.dll
+ 2012-02-17 00:01 . 2012-02-17 00:01 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\6c828a4d9907977b6dc87b294d38bbb9\PresentationBuildTasks.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\96e485c02ad346a2bd26a635e7fcb023\Microsoft.VisualBasic.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\f7071f9a1c0523540f6aa7f11c302fb6\Microsoft.Transactions.Bridge.ni.dll
+ 2012-02-17 00:21 . 2012-02-17 00:21 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\806b1d127ed3e906db972751e87585c4\Microsoft.JScript.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\912789fd859e0887e10a935cade08e72\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\6c1d3eec78906cc2a2ecffb013114c50\Microsoft.Build.Tasks.ni.dll
+ 2012-02-17 00:19 . 2012-02-17 00:19 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\d6edd4b4619a9052d3dfe50c3067d5e0\Microsoft.Build.Engine.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 1491968 c:\windows\assembly\NativeImages_v2.0.50727_32\Intuit.Ctg.Map\af7c9798b8ad854f1da9c9a0834030ed\Intuit.Ctg.Map.ni.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 3186688 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2011-06-30 03:01 . 2012-01-11 05:05 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2011-06-30 03:00 . 2012-01-11 05:04 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2012-01-11 05:04 . 2012-01-11 05:04 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2012-02-16 02:22 . 2012-02-16 02:22 5246976 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2012-01-11 05:04 . 2012-01-11 05:04 5246976 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2011-06-30 03:01 . 2012-01-11 05:05 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2011-06-30 03:01 . 2012-01-11 05:05 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-02-16 02:23 . 2012-02-16 02:23 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2006-09-26 15:42 . 2012-02-16 02:13 52550552 c:\windows\system32\MRT.exe
+ 2007-08-13 23:54 . 2011-12-18 20:46 11082240 c:\windows\system32\ieframe.dll
+ 2008-08-10 17:40 . 2011-12-18 20:46 11082240 c:\windows\system32\dllcache\ieframe.dll
+ 2012-02-16 02:10 . 2012-02-16 02:10 20333056 c:\windows\Installer\2b81db.msp
+ 2012-02-16 02:12 . 2011-11-04 19:20 11081728 c:\windows\ie8updates\KB2647516-IE8\ieframe.dll
+ 2012-02-16 02:07 . 2012-02-16 02:07 13137920 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\f28df9c2988724883cf19532d7f9f151\System.Windows.Forms.ni.dll
+ 2012-02-17 00:29 . 2012-02-17 00:29 17996800 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\7c73ac0ffec7d226ca3dac70df184f18\System.ServiceModel.ni.dll
+ 2012-02-17 00:28 . 2012-02-17 00:28 13325312 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity\a275181f49dcdf245ec6a9d9287bb6c6\System.Data.Entity.ni.dll
+ 2012-02-16 02:10 . 2012-02-16 02:10 17671168 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\b72152b4330e2f009a868aa16c47acb4\PresentationFramework.ni.dll
+ 2012-02-16 02:07 . 2012-02-16 02:07 11106816 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\ed36e9ff00f2fb0f33f1c08b20a7afc0\PresentationCore.ni.dll
+ 2012-02-17 00:25 . 2012-02-17 00:25 10001408 c:\windows\assembly\NativeImages_v4.0.30319_32\itext\8671494c2c3552a088ea5072c34d80e2\itext.ni.dll
+ 2012-02-17 00:24 . 2012-02-17 00:24 14786560 c:\windows\assembly\NativeImages_v4.0.30319_32\IKVM.OpenJDK.SwingA#\b9886ac0c7d6503376054e13cc9ac98c\IKVM.OpenJDK.SwingAWT.ni.dll
+ 2012-02-17 00:10 . 2012-02-17 00:10 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ad99ac6b5666edb8ee742dd64f9578af\System.Windows.Forms.ni.dll
+ 2012-02-17 00:18 . 2012-02-17 00:18 11817472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\29bdc8352d3c26e3c572ea60639dec3b\System.Web.ni.dll
+ 2012-02-17 00:21 . 2012-02-17 00:21 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\1cdcd6d97627d345d5ff446e6ec88b97\System.ServiceModel.ni.dll
+ 2012-02-17 00:07 . 2012-02-17 00:07 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\7c8f8fb506c32500acc1b6190d054f26\System.Design.ni.dll
+ 2012-02-17 00:05 . 2012-02-17 00:05 14328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\5060105fb9e169399fe45600b1e9215e\PresentationFramework.ni.dll
+ 2012-02-17 00:02 . 2012-02-17 00:02 12215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\0665bba8c9962deadc418881eb3a2a2a\PresentationCore.ni.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
[HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
2010-05-29 12:45 151552 —-a-w- c:\program files\SugarSync\SugarSyncShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
[HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
2010-05-29 12:45 151552 —-a-w- c:\program files\SugarSync\SugarSyncShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{A759AFF6-5851-457D-A540-F4ECED148351}"
[HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
2010-05-29 12:45 151552 —-a-w- c:\program files\SugarSync\SugarSyncShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
[HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
2010-05-29 12:45 151552 —-a-w- c:\program files\SugarSync\SugarSyncShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\admin\Application Data\mjusbsp\cdloader2.exe" [2008-07-22 50520]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-19 98304]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /k:D *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
2005-10-05 08:12 94208 —-a-w- c:\program files\Dell\Media Experience\DMXLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2005-04-06 00:19 77824 —-a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-04-06 00:22 94208 —-a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-06-10 15:44 249856 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-06-10 15:44 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxMenuMgr]
2009-01-16 21:31 181544 —-a-w- c:\program files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
2005-07-13 00:05 1117184 —-a-w- c:\program files\McAfee\SpamKiller\MSKDetct.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 21:40 155648 —-a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Omnipage]
2002-06-03 17:38 49152 —-a-w- c:\program files\ScanSoft\OmniPageSE\opware32.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2005-04-06 00:23 114688 —-a-w- c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-09-19 15:08 98304 —-a-w- c:\program files\QuickTime\qttask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2006-09-19 15:08 26112 —-a-w- c:\program files\Real\RealPlayer\realplay.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMBBLaunchAgent.exe]
2011-09-01 23:47 90448 —-a-w- c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
2006-08-17 15:00 1116920 —-a-w- c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-10-15 00:42 1404928 —-a-w- c:\program files\Analog Devices\Core\smax4pnp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-04-08 17:59 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"IntuitUpdateService"=2 (0x2)
"FreeAgentGoNext Service"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\Dell Laser MFP 1815\\NetworkScan\\DNSCST.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\admin\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"f:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\ScanSoft\\OmniPageSE\\EregEng\\NAVBrowser.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Pando Networks\\Pando\\Pando.exe"=
"c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56522:TCP"= 56522:TCP:Pando
"56522:UDP"= 56522:UDP:Pando
"56310:TCP"= 56310:TCP:Pando
"56310:UDP"= 56310:UDP:Pando
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 3:27 PM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 3:48 AM 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [12/8/2010 4:12 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11/12/2010 1:19 PM 295248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 5:09 AM 192776]
R2 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [8/25/2011 5:53 PM 13672]
R2 LogWatch;Event Log Watch;c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe [9/20/2002 10:29 AM 53248]
S1 MpKsl0f135ce1;MpKsl0f135ce1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4669EF94-AB70-4E78-B64A-8E1F26187FE3}\MpKsl0f135ce1.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4669EF94-AB70-4E78-B64A-8E1F26187FE3}\MpKsl0f135ce1.sys [?]
S1 MpKsl4894e515;MpKsl4894e515;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4669EF94-AB70-4E78-B64A-8E1F26187FE3}\MpKsl4894e515.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4669EF94-AB70-4E78-B64A-8E1F26187FE3}\MpKsl4894e515.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/10/2011 4:19 PM 136176]
S2 NecUsb3;USB3 Service;c:\windows\System32\svchost.exe -k NecUsb3Sevic [8/11/2004 4:00 PM 14336]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 5:25 AM 4433248]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [8/3/2010 3:23 PM 134608]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [8/3/2010 3:23 PM 24272]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [8/3/2010 3:23 PM 16720]
S3 CA_LIC_CLNT;CA License Client;c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe [9/20/2002 10:27 AM 77824]
S3 CA_LIC_SRVR;CA License Server;c:\program files\CA\SharedComponents\CA_LIC\lic98rmtd.exe [9/20/2002 10:41 AM 77824]
S3 DigiartyVirtualCDBus;Digiarty Virtual Driver;c:\windows\system32\drivers\DigiartyVirtualCDBus.sys [1/6/2012 8:22 PM 163616]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/10/2011 4:19 PM 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [9/22/2009 6:20 PM 38224]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [2/8/2009 4:44 PM 47360]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [1/16/2009 3:31 PM 161064]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
NecUsb3Sevic REG_MULTI_SZ NecUsb3
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-10 22:19]
.
2012-02-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-10 22:19]
.
2012-01-09 c:\windows\Tasks\prismShakeIcon.job
- c:\program files\NCH Software\Prism\prism.exe [2011-07-10 18:19]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
Trusted Zone: intuit.com\ttlc
TCP: DhcpNameServer = [removed] [removed] [removed]
DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} - hxxp://www.boydsnest-ti.com/activex/AMC.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://205.241.135.70/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\admin\Application Data\Mozilla\Firefox\Profiles\arkm7om1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q;=
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q;=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Inbox Toolbar: [removed] - %profile%\extensions\[removed]
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - c:\program files\AVG\AVG2012\Firefox
.
- - - - ORPHANS REMOVED - - - -
.
Notify-NecUsb3Sevices - USB3Sw32.dll
Notify-USB3Sw32 - USB3Sw32.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-16 19:05
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\windows\$NtUninstallKB38146$:SummaryInformation 0 bytes hidden from API
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(1488)
c:\windows\system32\WININET.dll
c:\program files\SugarSync\SugarSyncShellExt.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\windows\system32\CDRTC.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\progra~1\AVG\AVG2012\avgrsx.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\LEXBCES.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG2012\avgnsx.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
c:\windows\system32\PSIService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2012-02-16 19:11:31 - machine was rebooted
ComboFix-quarantined-files.txt 2012-02-17 01:11
ComboFix2.txt 2012-02-13 03:54
ComboFix3.txt 2010-05-04 02:56
.
Pre-Run: 58,250,829,824 bytes free
Post-Run: 58,569,998,336 bytes free
.
- - End Of File - - D26E73EF7576FE2A46D0AA394BDCD6A0


Thanks,
Spidey
Hi spidey,
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    DDS::
    Trusted Zone: intuit.com\ttlc
    
    Firefox::
    FF - ProfilePath - c:\documents and settings\admin\Application Data\Mozilla\Firefox\Profiles\arkm7om1.default\
    FF - Ext: Inbox Toolbar: [removed] - %profile%\extensions\[removed]
    
    File::
    c:\windows\system32\ppped.dll
    
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\Pando Networks\\Pando\\Pando.exe"=-
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "56522:TCP"=-
    "56522:UDP"=-
    "56310:TCP"=-
    "56310:UDP"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NecUsb3Sevices]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\USB3Sw32]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    "NecUsb3Sevic"=-
    
    NetSvc::
    NecUsb3Sevic
    TNaviSrv
    
    Driver::
    NecUsb3
    TNaviSrv
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI