Hello
I 've downloaded the ComboFix and followed all the prompts and below is the ComboFix report:
ComboFix 08-11-22.02 - Toshiba 2008-11-23 19:40:27.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.142 [GMT 0:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\FunWebProducts
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
c:\program files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
c:\program files\MyWebSearch\bar\1.bin\F3REPROX.DLL
c:\program files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
c:\program files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
c:\program files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE
c:\program files\MyWebSearch\bar\1.bin\M3HTML.DLL
c:\program files\MyWebSearch\bar\1.bin\M3IDLE.DLL
c:\program files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
c:\program files\MyWebSearch\bar\1.bin\M3MEDINT.EXE
c:\program files\MyWebSearch\bar\1.bin\M3MSG.DLL
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3SKIN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
c:\program files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
c:\program files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSBAR.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSSVC.EXE
c:\program files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S
c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files\MyWebSearch\bar\Game\CHESS.F3S
c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files\MyWebSearch\bar\icons\CM.ICO
c:\program files\MyWebSearch\bar\icons\MFC.ICO
c:\program files\MyWebSearch\bar\icons\PSS.ICO
c:\program files\MyWebSearch\bar\icons\SMILEY.ICO
c:\program files\MyWebSearch\bar\icons\WB.ICO
c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO
c:\program files\MyWebSearch\bar\Message\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\DOG.F3S
c:\program files\MyWebSearch\bar\Notifier\FISH.F3S
c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S
c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
c:\program files\MyWebSearch\bar\Notifier\MAID.F3S
c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S
c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S
c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S
c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S
c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
c:\programdata\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer
c:\programdata\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer\Privacy Policy.url
c:\programdata\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer\Terms and Conditions.url
c:\programdata\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer\Uninstall.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer\WebMediaPlayer.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer\Website.url
c:\windows\system32\f3PSSavr.scr
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_MyWebSearchService
((((((((((((((((((((((((( Files Created from 2008-10-23 to 2008-11-23 )))))))))))))))))))))))))))))))
.
2008-11-23 07:12 . 2008-11-23 07:12 56 –ah—– c:\windows\System32\ezsidmv.dat
2008-11-22 09:27 . 2008-11-23 11:13 d——– c:\program files\Navilog1
2008-11-22 09:08 . 2008-10-16 21:13 1,809,944 –a—— c:\windows\System32\wuaueng.dll
2008-11-22 09:08 . 2008-10-16 20:56 1,524,736 –a—— c:\windows\System32\wucltux.dll
2008-11-22 09:08 . 2008-10-16 21:09 51,224 –a—— c:\windows\System32\wuauclt.exe
2008-11-22 09:08 . 2008-10-16 21:09 43,544 –a—— c:\windows\System32\wups2.dll
2008-11-22 09:07 . 2008-10-16 21:12 561,688 –a—— c:\windows\System32\wuapi.dll
2008-11-22 09:07 . 2008-10-16 20:55 83,456 –a—— c:\windows\System32\wudriver.dll
2008-11-22 09:07 . 2008-10-16 21:08 34,328 –a—— c:\windows\System32\wups.dll
2008-11-22 09:06 . 2008-10-16 14:08 162,064 –a—— c:\windows\System32\wuwebv.dll
2008-11-22 09:06 . 2008-10-16 13:56 31,232 –a—— c:\windows\System32\wuapp.exe
2008-11-21 19:19 . 2008-11-21 19:19 d——– c:\program files\Trend Micro
2008-11-21 18:46 . 2008-11-23 07:14 d——– c:\users\Toshiba\AppData\Roaming\Uniblue
2008-11-21 18:46 . 2008-11-23 07:14 d——– c:\users\All Users\DriverScanner
2008-11-21 18:46 . 2008-11-23 07:14 d——– c:\programdata\DriverScanner
2008-11-21 18:46 . 2008-11-23 07:14 d——– c:\program files\Uniblue
2008-11-21 17:55 . 2008-04-17 13:12 107,368 –a—— c:\windows\System32\GEARAspi.dll
2008-11-21 17:55 . 2008-04-17 13:12 15,464 –a—— c:\windows\System32\drivers\GEARAspiWDM.sys
2008-11-21 17:54 . 2008-11-21 17:55 d——– c:\users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-21 17:54 . 2008-11-21 17:55 d——– c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-21 17:54 . 2008-11-21 17:55 d——– c:\program files\iTunes
2008-11-21 17:54 . 2008-11-21 17:54 d——– c:\program files\iPod
2008-11-21 17:51 . 2008-11-21 17:52 d——– c:\program files\QuickTime
2008-11-20 09:15 . 2008-11-20 09:16 d——– c:\users\Public\Games
2008-11-19 13:24 . 2008-11-19 13:24 d——– c:\program files\Bonjour
2008-11-19 13:15 . 2008-11-19 13:15 d——– c:\program files\Apple Software Update
2008-11-12 01:28 . 2008-09-10 03:40 1,334,272 –a—— c:\windows\System32\msxml6.dll
2008-11-12 01:28 . 2008-09-05 05:14 1,191,936 –a—— c:\windows\System32\msxml3.dll
2008-11-12 01:28 . 2008-08-27 01:05 212,480 –a—— c:\windows\System32\drivers\mrxsmb10.sys
2008-11-11 21:26 . 2008-11-11 21:26 d——– c:\program files\Veetle
2008-11-11 21:26 . 2008-11-11 21:26 48,396 –a—— c:\windows\UninstVeetleTVPlayer.exe
2008-11-09 09:05 . 2008-11-09 09:05 d——– c:\users\Toshiba\AppData\Roaming\TVU networks
2008-11-04 10:30 . 2008-11-04 10:30 90,112 –a—— c:\windows\System32\QuickTimeVR.qtx
2008-11-04 10:30 . 2008-11-04 10:30 57,344 –a—— c:\windows\System32\QuickTime.qts
2008-11-03 22:37 . 2008-11-03 22:37 d——– c:\users\All Users\TVU Networks
2008-11-03 22:37 . 2008-11-03 22:37 d——– c:\programdata\TVU Networks
2008-11-03 22:37 . 2008-11-03 22:37 d——– c:\program files\TVUPlayer
2008-11-03 10:33 . 2008-11-23 19:28 d——– c:\users\Toshiba\AppData\Roaming\skypePM
2008-11-03 10:31 . 2008-11-04 14:25 d——– c:\users\Toshiba\AppData\Roaming\Skype
2008-11-03 10:29 . 2008-11-03 10:29 d——– c:\program files\Skype
2008-11-03 10:29 . 2008-11-03 10:29 d——– c:\program files\Common Files\Skype
2008-11-02 10:25 . 2008-08-05 09:49 428,544 –a—— c:\windows\System32\EncDec.dll
2008-11-02 10:25 . 2008-08-05 09:49 293,376 –a—— c:\windows\System32\psisdecd.dll
2008-11-02 10:25 . 2008-08-05 09:48 217,088 –a—— c:\windows\System32\psisrndr.ax
2008-11-02 10:25 . 2008-08-05 09:48 177,664 –a—— c:\windows\System32\mpg2splt.ax
2008-11-02 10:25 . 2008-08-05 09:48 80,896 –a—— c:\windows\System32\MSNP.ax
2008-10-29 02:43 . 2008-08-12 03:39 443,392 –a—— c:\windows\System32\win32spl.dll
2008-10-29 02:43 . 2008-09-18 04:56 147,456 –a—— c:\windows\System32\Faultrep.dll
2008-10-29 02:43 . 2008-09-18 04:56 125,952 –a—— c:\windows\System32\wersvc.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-23 19:52 ——— d—–w c:\programdata\Kontiki
2008-11-23 19:28 ——— d—–w c:\users\Toshiba\AppData\Roaming\LimeWire
2008-11-21 17:54 ——— d—–w c:\programdata\Apple Computer
2008-11-21 17:54 ——— d—–w c:\program files\Common Files\Apple
2008-11-18 10:34 ——— d—–w c:\program files\Common Files\Adobe
2008-11-17 03:02 ——— d—–w c:\programdata\Microsoft Help
2008-11-03 10:29 ——— d—–w c:\programdata\Skype
2008-10-16 20:55 ——— d—–w c:\program files\Windows Mail
2008-10-02 03:49 827,392 —-a-w c:\windows\System32\wininet.dll
2008-09-30 16:43 1,286,152 —-a-w c:\windows\System32\msxml4.dll
2008-09-29 05:36 ——— d—–w c:\programdata\WindowsSearch
2008-09-24 08:22 ——— d—–w c:\programdata\wmp
2008-09-18 05:09 3,601,464 —-a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 —-a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 02:16 2,032,640 —-a-w c:\windows\System32\win32k.sys
2008-09-13 10:37 37,888 —-a-w c:\windows\System32\rar.exe
2008-09-05 20:04 144,210,958 —-a-w c:\windows\DUMP2c8b.tmp
2008-08-29 10:18 87,336 —-a-w c:\windows\System32\dns-sd.exe
2008-08-29 09:53 61,440 —-a-w c:\windows\System32\dnssd.dll
2008-08-08 13:56 174 –sha-w c:\program files\desktop.ini
2008-04-02 09:29 16,384 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-04-02 09:29 32,768 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-04-02 09:29 16,384 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-05-11 20:17 16,384 –sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-05-11 20:17 32,768 –sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-05-11 20:17 16,384 –sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((( snapshot@2008-09-13_20.23.12.73 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-23 04:44:47 140,288 —-a-w c:\windows\assembly\GAC_32\mcupdate\6.0.6000.0__31bf3856ad364e35\mcupdate.exe
+ 2008-08-05 09:51:47 140,288 —-a-w c:\windows\assembly\GAC_32\mcupdate\6.0.6000.0__31bf3856ad364e35\mcupdate.exe
+ 2008-09-13 20:43:13 34,088 —-a-w c:\windows\assembly\GAC_MSIL\DiscWriter\2.2.3.0__477a69ee60b50063\DiscWriter.dll
- 2008-04-23 04:44:14 4,046,848 —-a-w c:\windows\assembly\GAC_MSIL\ehshell\6.0.6000.0__31bf3856ad364e35\ehshell.dll
+ 2008-08-05 09:51:30 4,046,848 —-a-w c:\windows\assembly\GAC_MSIL\ehshell\6.0.6000.0__31bf3856ad364e35\ehshell.dll
+ 2008-09-13 20:43:12 5,632 —-a-w c:\windows\assembly\GAC_MSIL\Interop.NeroBurnAdvrCntrl2Lib\1.0.0.0__477a69ee60b50063\Interop.NeroBurnAdvrCntrl2Lib.dll
+ 2008-09-13 20:43:12 172,032 —-a-w c:\windows\assembly\GAC_MSIL\Interop.NEROLib\1.4.0.0__477a69ee60b50063\Interop.NEROLib.dll
+ 2008-09-13 20:43:12 24,576 —-a-w c:\windows\assembly\GAC_MSIL\Interop.NeroMCEWrapper\1.0.0.0__477a69ee60b50063\Interop.NeroMCEWrapper.dll
+ 2008-09-13 20:43:13 28,672 —-a-w c:\windows\assembly\GAC_MSIL\Interop.NeroVisionAPI\1.3.0.0__477a69ee60b50063\Interop.NeroVisionAPI.dll
- 2008-04-23 04:45:00 1,957,888 —-a-w c:\windows\assembly\GAC_MSIL\Microsoft.MediaCenter.UI\6.0.6000.0__31bf3856ad364e35\Microsoft.MediaCenter.UI.dll
+ 2008-08-05 09:51:56 1,957,888 —-a-w c:\windows\assembly\GAC_MSIL\Microsoft.MediaCenter.UI\6.0.6000.0__31bf3856ad364e35\Microsoft.MediaCenter.UI.dll
+ 2008-09-13 20:43:13 714,024 —-a-w c:\windows\assembly\GAC_MSIL\NeroBurnSettingsMCML\2.2.3.0__477a69ee60b50063\NeroBurnSettingsMCML.dll
+ 2008-11-03 03:07:06 2,428,928 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehepg\3cdca1e5ca98fe7c3f4ab8acd32e8c1c\ehepg.ni.dll
+ 2008-11-03 03:08:21 44,544 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtCOM\71f21fd19fc743332713e929b7f466ba\ehExtCOM.ni.dll
+ 2008-11-03 03:08:23 270,336 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtHost\ca3894e7058fbb4133c887b8f967c5f0\ehExtHost.ni.exe
+ 2008-11-03 03:08:04 1,949,696 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\d7fd9d0533242d48d6914a1bf993aadb\ehRecObj.ni.dll
+ 2008-11-03 03:07:56 12,742,656 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ehshell\bc7c35ef31af1909c89cb067da0e0970\ehshell.ni.dll
+ 2008-11-03 03:06:58 737,280 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\mcstore\26383f385450d35ef11998a1c60e6c45\mcstore.ni.dll
+ 2008-11-03 03:08:11 274,432 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\mcupdate\5ffe0057899c1579c865c000554b239b\mcupdate.ni.exe
+ 2008-11-03 03:06:40 5,861,376 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\32c2ab90485e11277b825ec8260de0dc\Microsoft.MediaCenter.UI.ni.dll
+ 2008-11-03 03:07:10 704,512 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\5978cf38d967c9ec0ab694134129b82c\Microsoft.MediaCenter.Sports.ni.dll
+ 2008-11-03 03:06:52 618,496 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\a859b69e0f608b63f6ec8b4dbfa8966a\Microsoft.MediaCenter.ni.dll
+ 2008-11-03 03:06:48 253,952 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\fe6a1bdca6598998fd80b3ee04053741\Microsoft.MediaCenter.Shell.ni.dll
+ 2008-10-04 19:16:46 1,887,080 —-a-w c:\windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
- 2008-04-23 04:42:33 373,248 —-a-w c:\windows\ehome\ehglid.dll
+ 2008-08-05 09:49:54 373,248 —-a-w c:\windows\ehome\ehglid.dll
- 2008-04-23 04:42:33 105,472 —-a-w c:\windows\ehome\ehPresenter.dll
+ 2008-08-05 09:49:54 105,472 —-a-w c:\windows\ehome\ehPresenter.dll
- 2008-04-23 04:42:33 254,464 —-a-w c:\windows\ehome\ehReplay.dll
+ 2008-08-05 09:49:54 254,464 —-a-w c:\windows\ehome\ehReplay.dll
- 2008-04-23 04:44:14 4,046,848 —-a-w c:\windows\ehome\ehshell.dll
+ 2008-08-05 09:51:30 4,046,848 —-a-w c:\windows\ehome\ehshell.dll
- 2008-04-23 04:27:00 18,944 —-a-w c:\windows\ehome\ehtrace.dll
+ 2008-08-06 03:27:39 18,944 —-a-w c:\windows\ehome\ehtrace.dll
- 2008-04-23 04:42:33 522,240 —-a-w c:\windows\ehome\ehui.dll
+ 2008-08-05 09:49:54 522,240 —-a-w c:\windows\ehome\ehui.dll
- 2008-01-19 07:33:22 172,544 —-a-w c:\windows\ehome\McrMgr.exe
+ 2008-08-05 09:49:28 173,056 —-a-w c:\windows\ehome\McrMgr.exe
- 2008-04-23 04:44:47 140,288 —-a-w c:\windows\ehome\mcupdate.exe
+ 2008-08-05 09:51:47 140,288 —-a-w c:\windows\ehome\mcupdate.exe
- 2008-04-23 04:45:00 1,957,888 —-a-w c:\windows\ehome\Microsoft.MediaCenter.UI.dll
+ 2008-08-05 09:51:56 1,957,888 —-a-w c:\windows\ehome\Microsoft.MediaCenter.UI.dll
- 2005-10-20 19:02:28 163,328 —-a-w c:\windows\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-20 20:02:28 163,328 —-a-w c:\windows\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-20 20:02:28 163,328 —-a-w c:\windows\erdnt\subs\ERDNT.EXE
- 2008-09-11 09:29:49 51,200 —-a-w c:\windows\inf\infpub.dat
+ 2008-11-23 00:19:57 51,200 —-a-w c:\windows\inf\infpub.dat
- 2008-09-07 18:45:16 86,016 —-a-w c:\windows\inf\infstor.dat
+ 2008-11-19 13:14:18 86,016 —-a-w c:\windows\inf\infstor.dat
- 2008-09-11 09:29:49 143,360 —-a-w c:\windows\inf\infstrng.dat
+ 2008-11-23 00:19:57 143,360 —-a-w c:\windows\inf\infstrng.dat
+ 2008-11-21 17:56:29 102,400 —-a-r c:\windows\Installer\{318AB667-3230-41B5-A617-CB3BF748D371}\iTunesIco.exe
+ 2008-11-19 13:16:04 27,136 —-a-r c:\windows\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
+ 2008-11-12 03:03:59 32,768 —-a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
+ 2008-11-19 13:24:18 86,016 —-a-r c:\windows\Installer\{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}\PrntWzrdIco.exe
- 2008-09-11 07:33:10 1,165,584 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-11-12 03:19:48 1,165,584 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2008-09-11 07:33:10 20,240 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-11-12 03:19:48 20,240 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-09-11 07:33:10 159,504 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2008-11-12 03:19:48 159,504 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2008-09-11 07:33:10 184,080 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2008-11-12 03:19:48 184,080 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2008-09-11 07:33:10 217,864 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2008-11-12 03:19:48 217,864 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2008-09-11 07:33:10 18,704 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-11-12 03:19:48 18,704 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-09-11 07:33:10 35,088 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-11-12 03:19:49 35,088 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-09-11 07:33:10 845,584 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-11-12 03:19:48 845,584 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2008-09-11 07:33:10 922,384 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-11-12 03:19:48 922,384 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2008-09-11 07:33:10 272,648 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-11-12 03:19:48 272,648 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2008-09-11 07:33:10 888,080 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-11-12 03:19:48 888,080 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-09-11 07:33:10 1,172,240 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-11-12 03:19:48 1,172,240 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-08-02 11:34:42 217,864 —-a-r c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2008-11-12 03:20:09 217,864 —-a-r c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
- 2008-09-11 07:31:38 135,168 —-a-r c:\windows\Installer\{903B0409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-11-12 03:06:17 135,168 —-a-r c:\windows\Installer\{903B0409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-09-11 07:31:38 4,096 —-a-r c:\windows\Installer\{903B0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-11-12 03:06:17 4,096 —-a-r c:\windows\Installer\{903B0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-09-11 07:31:38 147,456 —-a-r c:\windows\Installer\{903B0409-6000-11D3-8CFE-0150048383C9}\pj11icon.exe
+ 2008-11-12 03:06:16 147,456 —-a-r c:\windows\Installer\{903B0409-6000-11D3-8CFE-0150048383C9}\pj11icon.exe
+ 2008-11-18 10:35:07 295,606 —-a-r c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A81300000003}\SC_Reader.exe
- 2000-08-31 07:00:00 28,672 —-a-w c:\windows\Nircmd.exe
+ 2000-08-31 08:00:00 28,672 —-a-w c:\windows\Nircmd.exe
- 2008-09-04 06:53:22 391,776 —-a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2008-09-30 20:26:03 391,856 —-a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2008-09-13 17:29:58 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-11-23 19:47:59 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-09-13 17:29:58 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-11-23 19:47:59 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-09-13 17:31:48 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-11-23 19:49:30 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-09-13 17:32:29 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-11-23 19:50:45 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-11-23 19:50:45 262,144 —ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-07-18 21:08:20 72,256 ——w c:\windows\SoftwareDistribution\SelfUpdate\Handler\WuSetupV.exe
+ 2008-10-16 14:08:00 70,416 ——w c:\windows\SoftwareDistribution\SelfUpdate\Handler\WuSetupV.exe
- 2000-08-31 07:00:00 161,792 —-a-w c:\windows\swreg.exe
+ 2000-08-31 08:00:00 161,792 —-a-w c:\windows\swreg.exe
- 2008-09-13 17:30:08 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-11-23 19:48:06 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-09-13 17:30:08 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-23 19:48:06 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-09-13 17:30:08 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-11-23 19:48:06 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-09-13 19:14:21 262,144 —-a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2008-11-23 19:39:42 262,144 —-a-w c:\windows\System32\config\systemprofile\ntuser.dat
- 2008-01-19 05:29:28 288,256 —-a-w c:\windows\System32\drivers\srv.sys
+ 2008-08-27 01:06:25 288,768 —-a-w c:\windows\System32\drivers\srv.sys
+ 2008-01-19 07:37:09 664,576 —-a-w c:\windows\System32\drivers\UMDF\WpdMtpDr.dll
+ 2008-01-19 06:04:19 39,936 —-a-w c:\windows\System32\drivers\WpdUsb.sys
+ 2008-10-01 13:01:28 32,000 —-a-w c:\windows\System32\DriverStore\FileRepository\usbaapl.inf_3c16a04b\usbaapl.sys
+ 2008-04-17 13:12:54 107,368 -c–a-w c:\windows\System32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspi.dll
+ 2008-04-17 13:12:54 15,464 -c–a-w c:\windows\System32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspiWDM.sys
- 2008-08-20 20:18:34 449,288 —-a-w c:\windows\System32\FNTCACHE.DAT
+ 2008-10-16 20:56:47 449,288 —-a-w c:\windows\System32\FNTCACHE.DAT
- 2008-06-27 04:15:23 6,068,736 —-a-w c:\windows\System32\ieframe.dll
+ 2008-10-02 03:49:14 6,068,736 —-a-w c:\windows\System32\ieframe.dll
- 2008-01-19 07:34:31 270,336 —-a-w c:\windows\System32\iertutil.dll
+ 2008-10-02 03:49:14 270,336 —-a-w c:\windows\System32\iertutil.dll
+ 2006-03-17 10:45:52 1,757,184 —-a-w c:\windows\System32\imagX7.dll
+ 2006-03-17 10:45:54 497,296 —-a-w c:\windows\System32\imagXpr7.dll
+ 2006-03-17 10:45:54 258,048 —-a-w c:\windows\System32\imagXR7.dll
+ 2006-03-17 10:45:54 802,816 —-a-w c:\windows\System32\imagXRA7.dll
- 2008-06-27 04:15:24 28,160 —-a-w c:\windows\System32\jsproxy.dll
+ 2008-10-02 03:49:14 28,160 —-a-w c:\windows\System32\jsproxy.dll
+ 2008-10-05 03:16:26 235,936 —-a-r c:\windows\System32\Macromed\Flash\FlashUtil10a.exe
- 2008-03-21 16:52:43 74,649 —-a-w c:\windows\System32\Macromed\Flash\uninstall_activeX.exe
+ 2008-10-25 21:18:02 89,102 —-a-w c:\windows\System32\Macromed\Flash\uninstall_activeX.exe
- 2008-06-27 04:15:28 64,512 —-a-w c:\windows\System32\migration\WininetPlugin.dll
+ 2008-02-22 05:01:41 64,512 —-a-w c:\windows\System32\migration\WininetPlugin.dll
- 2008-08-26 20:28:12 16,208,504 —-a-w c:\windows\System32\mrt.exe
+ 2008-11-04 00:10:25 17,318,336 —-a-w c:\windows\System32\mrt.exe
- 2008-06-27 04:15:24 3,578,368 —-a-w c:\windows\System32\mshtml.dll
+ 2008-10-02 03:49:15 3,578,880 —-a-w c:\windows\System32\mshtml.dll
- 2008-06-27 04:15:25 671,232 —-a-w c:\windows\System32\mstime.dll
+ 2008-10-02 03:49:16 671,232 —-a-w c:\windows\System32\mstime.dll
+ 2007-12-03 17:04:12 95,600 —-a-w c:\windows\System32\NeroCo.dll
- 2008-01-19 07:35:35 466,944 —-a-w c:\windows\System32\netapi32.dll
+ 2008-10-16 04:47:33 466,944 —-a-w c:\windows\System32\netapi32.dll
- 2008-09-13 11:19:39 106,696 —-a-w c:\windows\System32\perfc009.dat
+ 2008-11-03 01:25:56 106,696 —-a-w c:\windows\System32\perfc009.dat
- 2008-09-13 11:19:39 323,946 —-a-w c:\windows\System32\perfh009.dat
+ 2008-11-03 01:25:56 323,946 —-a-w c:\windows\System32\perfh009.dat
- 2008-09-13 04:04:26 6,553,600 —-a-w c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2008-11-23 01:50:06 6,553,600 —-a-w c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 09:45:39 31,744 —-a-w c:\windows\System32\swsc.exe
+ 2006-03-17 13:49:46 368,640 —-a-w c:\windows\System32\TwnLib4.dll
- 2008-06-27 04:15:28 1,166,336 —-a-w c:\windows\System32\urlmon.dll
+ 2008-10-02 03:49:19 1,166,336 —-a-w c:\windows\System32\urlmon.dll
- 2008-09-13 17:31:56 6,852 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1867382941-178859002-3514349999-1003_UserData.bin
+ 2008-11-23 19:50:56 8,172 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1867382941-178859002-3514349999-1003_UserData.bin
- 2008-09-13 17:31:56 75,590 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-11-23 19:50:56 76,264 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-09-10 01:04:38 4,504 —-a-w c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2008-11-23 00:33:26 8,426 —-a-w c:\windows\System32\WDI\ERCQueuedResolutions.dat
- 2008-09-13 16:30:19 65,948 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-11-23 19:26:36 71,116 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-09-13 07:38:49 233,630 —-a-w c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2008-11-23 00:18:18 252,458 —-a-w c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2006-10-18 09:32:38 807,032 —-a-w c:\windows\System32\wmv9dmod.dll
+ 2008-01-19 07:37:08 33,280 —-a-w c:\windows\System32\WpdConns.dll
+ 2006-11-02 09:46:14 151,552 —-a-w c:\windows\System32\WpdMtp.dll
+ 2008-01-19 07:37:09 60,928 —-a-w c:\windows\System32\WpdMtpUS.dll
+ 2007-03-20 19:22:04 972,336 —-a-w c:\windows\UNNeroBackItUp.exe
+ 2007-12-13 18:09:06 972,072 —-a-w c:\windows\UNNeroMediaHome.exe
+ 2007-02-28 14:41:02 972,336 —-a-w c:\windows\UNNeroShowTime.exe
+ 2007-03-21 19:02:12 972,336 —-a-w c:\windows\UNNeroVision.exe
+ 2007-12-04 08:59:22 972,072 —-a-w c:\windows\UNRecode.exe
+ 2008-09-14 22:40:44 28,672 —-a-w c:\windows\WindowsMobile\Dungeoned for PocketPC\Uninstall.exe
+ 2008-09-16 21:43:06 40,960 —-a-w c:\windows\WindowsMobile\Patiences\Uninstall.exe
- 2008-09-10 10:13:46 130,163,330 —-a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2008-11-22 09:09:08 139,983,429 —-a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2008-08-06 03:28:23 864,256 —-a-w c:\windows\winsxs\msil_ehepg_31bf3856ad364e35_6.0.6000.16724_none_d9ab5d3ed1ce7791\ehepg.dll
+ 2008-08-06 03:22:33 864,256 —-a-w c:\windows\winsxs\msil_ehepg_31bf3856ad364e35_6.0.6000.20889_none_d9f91bf3eb183db4\ehepg.dll
+ 2008-08-06 03:28:25 135,168 —-a-w c:\windows\winsxs\msil_ehexthost_31bf3856ad364e35_6.0.6000.16724_none_bcf0d9f4c1bddadc\ehexthost.exe
+ 2008-08-06 03:22:34 135,168 —-a-w c:\windows\winsxs\msil_ehexthost_31bf3856ad364e35_6.0.6000.20889_none_bd3e98a9db07a0ff\ehexthost.exe
+ 2008-08-06 03:28:27 77,824 —-a-w c:\windows\winsxs\msil_ehiextens_31bf3856ad364e35_6.0.6000.16724_none_fbd3e0d909c338d1\ehiExtens.dll
+ 2008-08-06 03:22:36 77,824 —-a-w c:\windows\winsxs\msil_ehiextens_31bf3856ad364e35_6.0.6000.20889_none_fc219f8e230cfef4\ehiExtens.dll
+ 2008-08-06 03:28:32 4,374,528 —-a-w c:\windows\winsxs\msil_ehshell_31bf3856ad364e35_6.0.6000.16724_none_899e787f448205e3\ehshell.dll
+ 2008-08-06 03:22:41 4,382,720 —-a-w c:\windows\winsxs\msil_ehshell_31bf3856ad364e35_6.0.6000.20889_none_89ec37345dcbcc06\ehshell.dll
+ 2008-08-05 09:51:30 4,046,848 —-a-w c:\windows\winsxs\msil_ehshell_31bf3856ad364e35_6.0.6001.18115_none_8b90875b419f943a\ehshell.dll
+ 2008-08-06 04:03:14 4,046,848 —-a-w c:\windows\winsxs\msil_ehshell_31bf3856ad364e35_6.0.6001.22237_none_8c0684e25acb9e94\ehshell.dll
+ 2008-08-06 03:28:49 1,196,032 —-a-w c:\windows\winsxs\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6000.16724_none_4e9c1
c3698c67c79\Microsoft.MediaCenter.Shell.dll
+ 2008-08-06 03:22:59 1,269,760 —-a-w c:\windows\winsxs\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6000.20889_none_4ee9d
aebb210429c\Microsoft.MediaCenter.Shell.dll
+ 2008-08-06 03:28:50 2,342,912 —-a-w c:\windows\winsxs\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6000.16724_none_312a6ae6
5a1a7993\Microsoft.MediaCenter.UI.dll
+ 2008-08-06 03:23:00 2,351,104 —-a-w c:\windows\winsxs\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6000.20889_none_3178299b
73643fb6\Microsoft.MediaCenter.UI.dll
+ 2008-08-05 09:51:56 1,957,888 —-a-w c:\windows\winsxs\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6001.18115_none_331c79c2
573807ea\Microsoft.MediaCenter.UI.dll
+ 2008-08-06 04:03:38 1,957,888 —-a-w c:\windows\winsxs\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6001.22237_none_33927749
70641244\Microsoft.MediaCenter.UI.dll
+ 2008-08-06 03:28:48 217,088 —-a-w c:\windows\winsxs\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6000.16724_none_2385c3d9cf3
2e5a9\Microsoft.MediaCenter.dll
+ 2008-08-06 03:22:59 217,088 —-a-w c:\windows\winsxs\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6000.20889_none_23d3828ee87
cabcc\Microsoft.MediaCenter.dll
+ 2008-08-06 03:28:43 136,704 —-a-w c:\windows\winsxs\x86_mcupdate_31bf3856ad364e35_6.0.6000.16724_none_c6a4f64faeb4680c\mcupdate.exe
+ 2008-08-06 03:22:54 136,704 —-a-w c:\windows\winsxs\x86_mcupdate_31bf3856ad364e35_6.0.6000.20889_none_c6f2b504c7fe2e2f\mcupdate.exe
+ 2008-08-05 09:51:47 140,288 —-a-w c:\windows\winsxs\x86_mcupdate_31bf3856ad364e35_6.0.6001.18115_none_c897052babd1f663\mcupdate.exe
+ 2008-08-06 04:03:31 140,288 —-a-w c:\windows\winsxs\x86_mcupdate_31bf3856ad364e35_6.0.6001.22237_none_c90d02b2c4fe00bd\mcupdate.exe
+ 2008-10-02 03:49:01 124,928 —-a-w c:\windows\winsxs\x86_microsoft-windows-advpack_31bf3856ad364e35_6.0.6000.16757_none_a9b61b23f5cc373c\advpack.dll
+ 2008-10-02 03:25:49 124,928 —-a-w c:\windows\winsxs\x86_microsoft-windows-advpack_31bf3856ad364e35_6.0.6000.20927_none_aa6029990ed1805a\advpack.dll
+ 2008-08-06 03:27:39 252,416 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6000.16724_none_12bf9ca3a298d741\ehReplay.dll
+ 2008-08-06 03:18:00 254,464 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6000.20889_none_130d5b58bbe29d64\ehReplay.dll
+ 2008-08-05 09:49:54 254,464 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.18115_none_14b1ab7f9fb66598\ehReplay.dll
+ 2008-08-06 03:56:06 254,464 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.22237_none_1527a906b8e26ff2\ehReplay.dll
+ 2008-08-06 03:27:40 6,656 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.16724_none_32320cf9dce03b9f\McrMgr.dll
+ 2008-08-06 03:27:11 173,056 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.16724_none_32320cf9dce03b9f\McrMgr.exe
+ 2008-08-06 03:19:18 6,656 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.20889_none_327fcbaef62a01c2\McrMgr.dll
+ 2008-08-06 02:50:30 173,056 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.20889_none_327fcbaef62a01c2\McrMgr.exe
+ 2008-01-19 07:34:44 6,656 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.18115_none_34241bd5d9fdc9f6\McrMgr.dll
+ 2008-08-05 09:49:28 173,056 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.18115_none_34241bd5d9fdc9f6\McrMgr.exe
+ 2008-08-06 03:57:56 6,656 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.22237_none_349a195cf329d450\McrMgr.dll
+ 2008-08-06 03:27:54 173,056 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.22237_none_349a195cf329d450\McrMgr.exe
+ 2008-08-06 03:27:39 21,504 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehdebug_31bf3856ad364e35_6.0.6000.16724_none_2de5dbb18528130f\ehdebug.dll
+ 2008-08-06 03:17:56 21,504 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehdebug_31bf3856ad364e35_6.0.6000.20889_none_2e339a669e71d932\ehdebug.dll
+ 2008-08-06 03:27:39 372,224 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6000.16724_none_2d43ff096d0817ea\ehglid.dll
+ 2008-08-06 03:17:58 372,736 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6000.20889_none_2d91bdbe8651de0d\ehglid.dll
+ 2008-08-05 09:49:54 373,248 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.18115_none_2f360de56a25a641\ehglid.dll
+ 2008-08-06 03:56:06 373,248 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.22237_none_2fac0b6c8351b09b\ehglid.dll
+ 2008-08-06 03:27:39 105,472 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6000.16724_none_24d0bc2864e02dde\ehPresenter.dll
+ 2008-08-06 03:17:59 105,472 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6000.20889_none_251e7add7e29f401\ehPresenter.dll
+ 2008-08-05 09:49:54 105,472 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.18115_none_26c2cb0461fdbc35\ehPresenter.dll
+ 2008-08-06 03:56:06 105,472 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.22237_none_2738c88b7b29c68f\ehPresenter.dll
+ 2008-08-06 03:21:59 10,094,080 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6000.16724_none_50142885535e3590\ehres.dll
+ 2008-08-06 03:18:12 10,103,808 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6000.20889_none_5061e73a6ca7fbb3\ehres.dll
+ 2008-08-06 03:27:39 18,944 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehtrace_31bf3856ad364e35_6.0.6000.16724_none_36c4edb116c5f8a5\ehtrace.dll
+ 2008-08-06 03:18:12 18,944 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehtrace_31bf3856ad364e35_6.0.6000.20889_none_3712ac66300fbec8\ehtrace.dll
+ 2008-08-06 03:27:39 517,632 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6000.16724_none_cccc40dbcc4dcbaa\ehui.dll
+ 2008-08-06 03:18:12 521,216 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6000.20889_none_cd19ff90e59791cd\ehui.dll
+ 2008-08-05 09:49:54 522,240 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.18115_none_cebe4fb7c96b5a01\ehui.dll
+ 2008-08-06 03:56:08 522,240 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.22237_none_cf344d3ee297645b\ehui.dll
+ 2008-08-06 03:27:39 1,497,600 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehuihlp_31bf3856ad364e35_6.0.6000.16724_none_3a1333122e23804c\ehuihlp.dll
+ 2008-08-06 03:18:13 1,498,112 —-a-w c:\windows\winsxs\x86_microsoft-windows-ehome-ehuihlp_31bf3856ad364e35_6.0.6000.20889_none_3a60f1c7476d466f\ehuihlp.dll
+ 2008-09-18 04:56:02 147,456 —-a-w c:\windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.18145_none_6fe0e04a3ce53cd7\Faultrep.dll
+ 2008-01-19 07:33:35 217,088 —-a-w c:\windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.18145_none_6fe0e04a3ce53cd7\WerFault.exe
+ 2008-01-19 07:33:35 860,160 —-a-w c:\windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.18145_none_6fe0e04a3ce53cd7\WerFaultSecure.exe
+ 2008-09-20 04:00:23 147,456 —-a-w c:\windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.22271_none_70460c29561ecb18\Faultrep.dll
+ 2008-09-20 04:00:16 217,088 —-a-w c:\windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.22271_none_70460c29561ecb18\WerFault.exe
+ 2008-09-20 04:00:16 860,160 —-a-w c:\windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.22271_none_70460c29561ecb18\WerFaultSecure.exe
+ 2008-09-18 04:56:07 125,952 —-a-w c:\windows\winsxs\x86_microsoft-windows-feedback-service_31bf3856ad364e35_6.0.6001.18145_none_79a5b70991018b47\wersvc.dll
+ 2008-09-20 04:00:26 125,952 —-a-w c:\windows\winsxs\x86_microsoft-windows-feedback-service_31bf3856ad364e35_6.0.6001.22271_none_7a0ae2e8aa3b1988\wersvc.dll
+ 2008-10-02 03:49:05 44,544 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..ablenetworkgraphics_31bf3856ad364e35_6.0.6000.16757_none_ebb124d316651d3b\pngfilt.dll
+ 2008-10-02 03:30:07 44,544 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..ablenetworkgraphics_31bf3856ad364e35_6.0.6000.20927_none_ec5b33482f6a6659\pngfilt.dll
+ 2008-10-02 03:49:06 1,159,680 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6000.16757_none_b2cdcd85d9c5949f\urlmon.dll
+ 2008-10-02 03:30:37 1,162,752 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6000.20927_none_b377dbfaf2caddbd\urlmon.dll
+ 2008-10-02 03:49:19 1,166,336 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.18148_none_b4bfdc61d6e322f6\urlmon.dll
+ 2008-10-02 03:34:49 1,166,848 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.22278_none_b5290968f0191693\urlmon.dll
+ 2008-10-02 03:49:04 671,232 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6000.16757_none_deb05c4e7f6e540e\mstime.dll
+ 2008-10-02 03:28:20 671,232 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6000.20927_none_df5a6ac398739d2c\mstime.dll
+ 2008-10-02 03:49:16 671,232 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6001.18148_none_e0a26b2a7c8be265\mstime.dll
+ 2008-10-02 03:34:46 671,232 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6001.22278_none_e10b983195c1d602\mstime.dll
+ 2008-10-02 03:49:02 27,648 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16757_none_ffd3a927a4cebb32\jsproxy.dll
+ 2008-10-02 03:49:06 826,368 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16757_none_ffd3a927a4cebb32\wininet.dll
+ 2008-10-02 03:49:06 64,512 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16757_none_ffd3a927a4cebb32\WininetPlugin.dll
+ 2008-10-02 03:27:01 27,648 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20927_none_007db79cbdd40450\jsproxy.dll
+ 2008-10-02 03:30:45 827,904 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20927_none_007db79cbdd40450\wininet.dll
+ 2008-10-02 03:30:45 64,512 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20927_none_007db79cbdd40450\WininetPlugin.dll
+ 2008-10-02 03:49:14 28,160 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18148_none_01c5b803a1ec4989\jsproxy.dll
+ 2008-10-02 03:49:19 827,392 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18148_none_01c5b803a1ec4989\wininet.dll
+ 2008-02-22 05:01:41 64,512 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18148_none_01c5b803a1ec4989\WininetPlugin.dll
+ 2008-10-02 03:34:46 28,160 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22278_none_022ee50abb223d26\jsproxy.dll
+ 2008-10-02 03:34:49 827,904 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22278_none_022ee50abb223d26\wininet.dll
+ 2008-10-02 03:34:49 64,512 —-a-w c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22278_none_022ee50abb223d26\WininetPlugin.dll
+ 2007-08-21 07:13:31 2,455,488 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.16757_none_f97ccc016eba3585\ieapfltr.dat
+ 2008-10-02 03:49:02 383,488 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.16757_none_f97ccc016eba3585\ieapfltr.dll
+ 2007-08-21 07:13:31 2,455,488 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.20927_none_fa26da7687bf7ea3\ieapfltr.dat
+ 2008-10-02 03:26:47 380,928 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.20927_none_fa26da7687bf7ea3\ieapfltr.dll
+ 2008-10-02 03:49:02 347,136 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.16757_none_95b104b9849fbbb3\dxtmsft.dll
+ 2008-10-02 03:49:02 214,528 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.16757_none_95b104b9849fbbb3\dxtrans.dll
+ 2008-10-02 03:26:19 347,136 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.20927_none_965b132e9da504d1\dxtmsft.dll
+ 2008-10-02 03:26:20 214,528 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.20927_none_965b132e9da504d1\dxtrans.dll
+ 2008-10-02 03:49:03 477,696 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6000.16757_none_46139f1146606e40\mshtmled.dll
+ 2008-10-02 03:27:54 477,696 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6000.20927_none_46bdad865f65b75e\mshtmled.dll
+ 2008-10-02 03:49:03 3,593,216 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.16757_none_112dc84625252468\mshtml.dll
+ 2008-10-02 03:27:54 3,594,752 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.20927_none_11d7d6bb3e2a6d86\mshtml.dll
+ 2008-10-02 03:49:15 3,578,880 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18148_none_131fd7222242b2bf\mshtml.dll
+ 2008-10-02 03:34:46 3,579,392 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22278_none_138904293b78a65c\mshtml.dll
+ 2008-10-02 03:49:02 63,488 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-infocard_31bf3856ad364e35_6.0.6000.16757_none_588635106739b071\icardie.dll
+ 2008-10-02 03:26:46 63,488 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-infocard_31bf3856ad364e35_6.0.6000.20927_none_59304385803ef98f\icardie.dll
+ 2008-10-02 03:48:32 26,624 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16757_none_2d4cb5b31cfa2a15\ieUnatt.exe
+ 2008-10-02 03:50:01 633,632 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16757_none_2d4cb5b31cfa2a15\iexplore.exe
+ 2008-10-02 01:18:42 26,624 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20927_none_2df6c42835ff7333\ieUnatt.exe
+ 2008-10-02 03:32:01 633,632 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20927_none_2df6c42835ff7333\iexplore.exe
+ 2008-10-02 03:49:02 267,776 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6000.16757_none_458e60038f7fd98f\iertutil.dll
+ 2008-10-02 03:49:06 134,144 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6000.16757_none_458e60038f7fd98f\sqmapi.dll
+ 2008-10-02 03:26:48 267,776 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6000.20927_none_46386e78a88522ad\iertutil.dll
+ 2008-10-02 03:30:30 134,144 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6000.20927_none_46386e78a88522ad\sqmapi.dll
+ 2008-10-02 03:49:14 270,336 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18148_none_47806edf8c9d67e6\iertutil.dll
+ 2008-01-19 07:36:35 129,536 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18148_none_47806edf8c9d67e6\sqmapi.dll
+ 2008-10-02 03:34:45 270,848 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.22278_none_47e99be6a5d35b83\iertutil.dll
+ 2008-10-02 03:34:48 129,536 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.22278_none_47e99be6a5d35b83\sqmapi.dll
+ 2008-10-02 03:48:32 70,656 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.16757_none_c3bb6ace6174f2ba\ie4uinit.exe
+ 2008-10-02 03:49:02 44,544 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.16757_none_c3bb6ace6174f2ba\iernonce.dll
+ 2008-10-02 03:49:02 56,320 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.16757_none_c3bb6ace6174f2ba\iesetup.dll
+ 2008-10-02 01:18:33 70,656 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.20927_none_c46579437a7a3bd8\ie4uinit.exe
+ 2008-10-02 03:26:48 44,544 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.20927_none_c46579437a7a3bd8\iernonce.dll
+ 2008-10-02 03:26:48 56,320 —-a-w c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.20927_none_c46579437a7a3bd8\iesetup.dll
+ 2008-10-02 03:49:02 52,736 —-a-w c:\windows\winsxs\x86_microsoft-windows-iebrshim_31bf3856ad364e35_6.0.6000.16757_none_29e0813e6824c817\iebrshim.dll
+ 2008-10-02 03:26:47 52,736 —-a-w c:\windows\winsxs\x86_microsoft-windows-iebrshim_31bf3856ad364e35_6.0.6000.20927_none_2a8a8fb3812a1135\iebrshim.dll
+ 2008-10-02 03:49:02 6,066,176 —-a-w c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.16757_none_628d2249b11ab295\ieframe.dll
+ 2008-10-02 03:49:02 180,736 —-a-w c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.16757_none_628d2249b11ab295\ieui.dll
+ 2008-10-02 03:26:48 6,068,224 —-a-w c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.20927_none_633730beca1ffbb3\ieframe.dll
+ 2008-10-02 03:26:48 180,736 —-a-w c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.20927_none_633730beca1ffbb3\ieui.dll
+ 2008-10-02 03:49:14 6,068,736 —-a-w c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.18148_none_647f3125ae3840ec\ieframe.dll
+ 2008-01-19 07:34:31 180,736 —-a-w c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.18148_none_647f3125ae3840ec\ieui.dll
+ 2008-10-02 03:34:45 6,069,760 —-a-w c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.22278_none_64e85e2cc76e3489\ieframe.dll
+ 2008-10-02 03:34:45 180,736 —-a-w c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.22278_none_64e85e2cc76e3489\ieui.dll
+ 2008-10-02 03:48:32 263,168 —-a-w c:\windows\winsxs\x86_microsoft-windows-ieinstal_31bf3856ad364e35_6.0.6000.16757_none_e6868ec8949e06cd\ieinstal.exe
+ 2008-10-02 01:18:55 263,168 —-a-w c:\windows\winsxs\x86_microsoft-windows-ieinstal_31bf3856ad364e35_6.0.6000.20927_none_e7309d3dada34feb\ieinstal.exe
+ 2008-10-02 03:48:32 301,568 —-a-w c:\windows\winsxs\x86_microsoft-windows-ieuser_31bf3856ad364e35_6.0.6000.16757_none_0b2ec3e4d718c67f\ieuser.exe
+ 2008-10-02 01:18:56 301,568 —-a-w c:\windows\winsxs\x86_microsoft-windows-ieuser_31bf3856ad364e35_6.0.6000.20927_none_0bd8d259f01e0f9d\ieuser.exe
+ 2008-08-06 03:27:40 1,244,672 —-a-w c:\windows\winsxs\x86_microsoft-windows-m..mediadeliveryengine_31bf3856ad364e35_6.0.6000.16724_none_3d328dcd626a3334\mcmde.dll
+ 2008-08-06 03:19:18 1,244,672 —-a-w c:\windows\winsxs\x86_microsoft-windows-m..mediadeliveryengine_31bf3856ad364e35_6.0.6000.20889_none_3d804c827bb3f957\mcmde.dll
+ 2008-09-05 04:48:28 1,194,496 —-a-w c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6000.16745_none_8661c59c99cb7ce9\msxml3.dll
+ 2008-09-05 04:45:14 2,048 —-a-w c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6000.16745_none_8661c59c99cb7ce9\msxml3r.dll
+ 2008-09-05 04:47:44 1,194,496 —-a-w c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6000.20910_none_8706d29fb2d54754\msxml3.dll
+ 2008-09-05 04:47:44 2,048 —-a-w c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6000.20910_none_8706d29fb2d54754\msxml3r.dll
+ 2008-09-05 05:14:05 1,191,936 —-a-w c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.18136_none_8853d47896e90b40\msxml3.dll
+ 2006-11-02 09:41:09 2,048 —-a-w c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.18136_none_8853d47896e90b40\msxml3r.dll
+ 2008-09-05 05:08:23 1,191,936 —-a-w c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.22258_none_88c9d1ffb015159a\msxml3.dll
+ 2008-09-05 05:04:53 2,048 —-a-w c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.22258_none_88c9d1ffb015159a\msxml3r.dll
+ 2008-09-10 03:25:00 1,341,440 —-a-w c:\windows\winsxs\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6000.16747_none_866381d899c9fc7a\msxml6.dll
+ 2008-09-10 03:21:24 2,048 —-a-w c:\windows\winsxs\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6000.16747_none_866381d899c9fc7a\msxml6r.dll
+ 2008-09-10 03:26:42 1,341,440 —-a-w c:\windows\winsxs\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6000.20913_none_87098f25b2d2e03c\msxml6.dll
+ 2008-09-10 03:26:42 2,048 —-a-w c:\windows\winsxs\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6000.20913_none_87098f25b2d2e03c\msxml6r.dll
+ 2008-09-10 03:40:14 1,334,272 —-a-w c:\windows\winsxs\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6001.18138_none_885590b496e78ad1\msxml6.dll
+ 2006-11-02 09:41:09 2,048 —-a-w c:\windows\winsxs\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6001.18138_none_885590b496e78ad1\msxml6r.dll
+ 2008-09-10 03:27:55 1,334,272 —-a-w c:\windows\winsxs\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6001.22261_none_88b7bbb5b023cd0d\msxml6.dll
+ 2008-09-10 03:23:55 2,048 —-a-w c:\windows\winsxs\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6001.22261_none_88b7bbb5b023cd0d\msxml6r.dll
+ 2008-10-16 04:40:36 425,472 —-a-w c:\windows\winsxs\x86_microsoft-windows-netapi32_31bf3856ad364e35_6.0.6000.16764_none_8b10fff30496576a\netapi32.dll
+ 2008-10-16 04:22:27 425,984 —-a-w c:\windows\winsxs\x86_microsoft-windows-netapi32_31bf3856ad364e35_6.0.6000.20937_none_8bbe0f461d98ec8d\netapi32.dll
+ 2008-10-16 04:47:33 466,944 —-a-w c:\windows\winsxs\x86_microsoft-windows-netapi32_31bf3856ad364e35_6.0.6001.18157_none_8d050f6301b2186f\netapi32.dll
+ 2008-10-16 04:38:26 466,944 —-a-w c:\windows\winsxs\x86_microsoft-windows-netapi32_31bf3856ad364e35_6.0.6001.22288_none_8d6f3cb41ae72563\netapi32.dll
+ 2008-09-15 22:27:41 2,413,072 —-a-w c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16764_none_f064ff046e80cc5f\OESpamFilter.dat
+ 2008-09-15 22:27:41 2,413,072 —-a-w c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.20937_none_f1120e5787836182\OESpamFilter.dat
+ 2008-09-15 22:27:41 2,413,072 —-a-w c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18157_none_f2590e746b9c8d64\OESpamFilter.dat
+ 2008-09-15 22:27:41 2,413,072 —-a-w c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22288_none_f2c33bc584d19a58\OESpamFilter.dat
+ 2008-09-18 04:35:05 3,505,208 —-a-w c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16754_none_6a18166cb7216faf\ntkrnlpa.exe
+ 2008-09-18 04:35:07 3,470,904 —-a-w c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16754_none_6a18166cb7216faf\ntoskrnl.exe
+ 2008-09-18 04:27:45 3,506,744 —-a-w c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.20921_none_6abf2403d0296cc8\ntkrnlpa.exe
+ 2008-09-18 04:27:44 3,472,952 —-a-w c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.20921_none_6abf2403d0296cc8\ntoskrnl.exe
+ 2008-09-18 05:09:10 3,601,464 —-a-w c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18145_none_6c0a2548b43efe06\ntkrnlpa.exe
+ 2008-09-18 05:09:09 3,549,240 —-a-w c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18145_none_6c0a2548b43efe06\ntoskrnl.exe
+ 2008-09-18 04:54:44 3,601,976 —-a-w c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22269_none_6c822363cd693b0e\ntkrnlpa.exe
+ 2008-09-18 04:54:49 3,549,752 —-a-w c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22269_none_6c822363cd693b0e\ntoskrnl.exe
+ 2008-08-12 03:29:17 37,376 —-a-w c:\windows\winsxs\x86_microsoft-windows-p..ooler-networkclient_31bf3856ad364e35_6.0.6000.16728_none_377f607173cc72c2\printcom.dll
+ 2008-08-12 03:29:18 441,856 —-a-w c:\windows\winsxs\x86_microsoft-windows-p..ooler-networkclient_31bf3856ad364e35_6.0.6000.16728_none_377f607173cc72c2\win32spl.dll
+ 2008-08-12 03:17:47 37,376 —-a-w c:\windows\winsxs\x86_microsoft-windows-p..ooler-networkclient_31bf3856ad364e35_6.0.6000.20893_none_37b84c568d275770\printcom.dll
+ 2008-08-12 03:18:17 444,928 —-a-w c:\windows\winsxs\x86_microsoft-windows-p..ooler-networkclient_31bf3856ad364e35_6.0.6000.20893_none_37b84c568d275770\win32spl.dll
+ 2008-01-19 07:36:07 37,888 —-a-w c:\windows\winsxs\x86_microsoft-windows-p..ooler-networkclient_31bf3856ad364e35_6.0.6001.18119_none_39716f4d70ea0119\printcom.dll
+ 2008-08-12 03:39:08 443,392 —-a-w c:\windows\winsxs\x86_microsoft-windows-p..ooler-networkclient_31bf3856ad364e35_6.0.6001.18119_none_39716f4d70ea0119\win32spl.dll
+ 2008-08-12 03:25:35 37,888 —-a-w c:\windows\winsxs\x86_microsoft-windows-p..ooler-networkclient_31bf3856ad364e35_6.0.6001.22241_none_39d29a048a2729fe\printcom.dll
+ 2008-08-12 03:25:37 443,392 —-a-w c:\windows\winsxs\x86_microsoft-windows-p..ooler-networkclient_31bf3856ad364e35_6.0.6001.22241_none_39d29a048a2729fe\win32spl.dll
+ 2008-08-26 01:11:59 211,456 —-a-w c:\windows\winsxs\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.0.6000.16738_none_86a5e1554e593846\mrxsmb10.sys
+ 2008-08-27 00:48:36 211,968 —-a-w c:\windows\winsxs\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.0.6000.20904_none_874beea267621c08\mrxsmb10.sys
+ 2008-08-27 01:05:41 212,480 —-a-w c:\windows\winsxs\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.0.6001.18130_none_88841dab4b86fe7f\mrxsmb10.sys
+ 2008-08-27 00:52:38 212,480 —-a-w c:\windows\winsxs\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.0.6001.22252_none_88fa1b3264b308d9\mrxsmb10.sys
+ 2008-08-26 01:12:30 290,304 —-a-w c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6000.16738_none_d7f8bf26f95e2296\srv.sys
+ 2008-08-27 00:49:12 290,816 —-a-w c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6000.20904_none_d89ecc7412670658\srv.sys
+ 2008-08-27 01:06:25 288,768 —-a-w c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6001.18130_none_d9d6fb7cf68be8cf\srv.sys
+ 2008-08-27 00:53:21 288,768 —-a-w c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6001.22252_none_da4cf9040fb7f329\srv.sys
+ 2008-08-06 03:27:39 428,032 —-a-w c:\windows\winsxs\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6000.16724_none_de803b00914caa46\EncDec.dll
+ 2008-08-06 03:18:16 428,032 —-a-w c:\windows\winsxs\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6000.20889_none_decdf9b5aa967069\EncDec.dll
+ 2008-08-05 09:49:58 428,544 —-a-w c:\windows\winsxs\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.18115_none_e07249dc8e6a389d\EncDec.dll
+ 2008-08-06 04:00:35 428,544 —-a-w c:\windows\winsxs\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.22237_none_e0e84763a79642f7\EncDec.dll
+ 2008-08-06 03:27:43 292,352 —-a-w c:\windows\winsxs\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6000.16724_none_da055cba59f5adf1\psisdecd.dll
+ 2008-08-06 03:21:05 292,352 —-a-w c:\windows\winsxs\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6000.20889_none_da531b6f733f7414\psisdecd.dll
+ 2008-08-05 09:49:58 293,376 —-a-w c:\windows\winsxs\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.18115_none_dbf76b9657133c48\psisdecd.dll
+ 2008-08-06 04:00:45 293,376 —-a-w c:\windows\winsxs\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.22237_none_dc6d691d703f46a2\psisdecd.dll
+ 2008-10-16 21:12:19 561,688 —-a-w c:\windows\winsxs\x86_microsoft-windows-w..owsupdateclient-aux_31bf3856ad364e35_7.2.6001.788_none_107673f57a433d77\wuapi.dll
+ 2008-10-16 20:55:59 83,456 —-a-w c:\windows\winsxs\x86_microsoft-windows-w..owsupdateclient-aux_31bf3856ad364e35_7.2.6001.788_none_107673f57a433d77\wudriver.dll
+ 2008-10-16 21:08:57 34,328 —-a-w c:\windows\winsxs\x86_microsoft-windows-w..owsupdateclient-aux_31bf3856ad364e35_7.2.6001.788_none_107673f57a433d77\wups.dll
+ 2008-10-16 13:56:04 31,232 —-a-w c:\windows\winsxs\x86_microsoft-windows-w..pdateclient-activex_31bf3856ad364e35_7.2.6001.788_none_ba8134361ffa6f73\wuapp.exe
+ 2008-10-16 14:08:00 162,064 —-a-w c:\windows\winsxs\x86_microsoft-windows-w..pdateclient-activex_31bf3856ad364e35_7.2.6001.788_none_ba8134361ffa6f73\wuwebv.dll
+ 2008-10-16 21:09:43 51,224 —-a-w c:\windows\winsxs\x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.2.6001.788_none_2a6539a96682e474\wuauclt.exe
+ 2008-10-16 21:13:38 1,809,944 —-a-w c:\windows\winsxs\x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.2.6001.788_none_2a6539a96682e474\wuaueng.dll
+ 2008-10-16 21:09:43 43,544 —-a-w c:\windows\winsxs\x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.2.6001.788_none_2a6539a96682e474\wups2.dll
+ 2008-09-18 02:03:07 2,027,520 —-a-w c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6000.16754_none_b6db2e869d852707\win32k.sys
+ 2008-09-20 01:13:20 2,029,568 —-a-w c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6000.20922_none_b7833c67b68c3d77\win32k.sys
+ 2008-09-18 02:16:28 2,032,640 —-a-w c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6001.18145_none_b8cd3d629aa2b55e\win32k.sys
+ 2008-09-20 01:21:50 2,033,152 —-a-w c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6001.22271_none_b9326941b3dc439f\win32k.sys
+ 2008-10-16 20:56:28 1,524,736 —-a-w c:\windows\winsxs\x86_microsoft-windows-windowsupdateclient-ui_31bf3856ad364e35_7.2.6001.788_none_a8125d5406872725\wucltux.dll
+ 2008-11-12 03:03:59 1,286,152 —-a-w c:\windows\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_b7e00e6c7b30b69b\msxml4.dll
+ 2008-11-12 03:04:03 91,656 —-a-w c:\windows\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_365945b9da656e4d\msxml4r.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-08-05 171448]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-29 21755688]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-22 894248]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Ulead AutoDetector"="c:\program files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe" [2003-11-18 45056]
"Ulead Photo Express Calendar Checker"="c:\program files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe" [2004-01-12 69632]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2007-02-22 112216]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 136768]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-08-13 29744]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 2213160]
"4oD"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 c:\windows\RtHDVCpl.exe]
"Skytel"="Skytel.exe" [2007-06-15 c:\windows\SkyTel.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
c:\users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-02-08 147456]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-05-14 113664]
RAMASST.lnk - c:\windows\System32\RAMASST.exe [2008-05-14 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{657E2790-7A68-44EB-B717-9C7D89E33040}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{A962E0D5-562C-4EAC-AAFE-0E98951BA33B}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{CEFB1A4C-4196-4ED5-91C3-5C51C40DE9B4}c:\\program files\\bitdownload\\bitdownload.exe"= UDP:c:\program files\bitdownload\bitdownload.exe:BitDownload
"UDP Query User{1CC5647E-7BDA-4D2A-AB89-F56532495045}c:\\program files\\bitdownload\\bitdownload.exe"= TCP:c:\program files\bitdownload\bitdownload.exe:BitDownload
"TCP Query User{D504B23E-0E79-4B5C-AFCF-4641A3D69675}c:\\program files\\bitdownload\\bitdownload.exe"= UDP:c:\program files\bitdownload\bitdownload.exe:BitDownload
"UDP Query User{C3130EC2-65C1-43C6-9FBC-F468FBAE2615}c:\\program files\\bitdownload\\bitdownload.exe"= TCP:c:\program files\bitdownload\bitdownload.exe:BitDownload
"TCP Query User{A7917DA3-A0B0-4C21-90C8-E97714F157DE}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{3F8F07C5-BDA2-412B-8797-536CE8806ACB}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"{3302937E-EB92-434D-95B7-1F9BD18757A3}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{A0F47E87-3668-4BC3-94AA-4E2C9B97F7DF}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{21BAEA41-560D-4D76-8850-D53ADFEA00D9}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{49EBA0A9-AE2D-4AD4-993D-6FA3DBDB7614}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{1500C895-2326-446F-B23A-F1FC1C4121C2}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EAA97DAB-8AA3-40AC-8B4B-D9685020FD1F}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{3B505F01-FA9C-4F03-B2E8-9FC2863D93F8}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{16057D6C-BF53-4B22-84D3-645A320C0600}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{62292CD1-4D2F-4367-9564-8521D8B80926}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{0AF14551-7353-4166-8898-99D989DE9993}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{8A84FF83-3AEE-47A4-A398-3FC562E7937E}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{35498E36-7575-493B-A961-D4DCF78CB456}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{33801AA8-3FF6-43EE-88AB-2F495AAC7CD3}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{B5845C2E-1AD1-45F2-AE7A-B7F5246752E3}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{0420E385-645D-41E1-A1EC-33F9B7E8F205}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{ECD2DBEB-DF81-4DFF-B6C7-0F6C9C87621C}"= UDP:c:\program files\McAfee\Common Framework\FrameworkService.exe:McAfee Framework Service
"{A6698BAD-28C3-4629-9B83-053A8B56FEB1}"= TCP:c:\program files\McAfee\Common Framework\FrameworkService.exe:McAfee Framework Service
"{0BC1ACC5-2F22-4C15-8A52-3DC35DFA08E5}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{61568BDD-5D2D-481D-AC5A-5BCF5BB34FE4}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil_.exe:BlueSoleil
"{3448B3C0-6CAB-448F-AAC6-7788071EF9A6}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil_.exe:BlueSoleil
"{C0BDE073-1A9F-43FD-AE21-7D3C9F06F284}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{8AEE36D9-5F73-42B3-8F1E-4E64D6BFEA80}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{6EC89285-C9FB-4655-A203-461C21F05B3E}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{396E548D-C287-4325-B138-F83E16969CF1}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{CCF289AB-27EA-4114-9A5E-A0FFAEF3ED70}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{C50C5BAD-1289-4BC6-B15B-BF917681CA4C}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"{CF46C3AB-633C-4F5C-BF6B-9D2E6A3B0482}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"{63988533-9DCB-4ECE-9B45-49DB5D5D7889}"= Disabled:UDP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{FA0559D9-B3AB-4A88-B272-0B2C1F3CE9A8}"= Disabled:TCP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{13AD6692-36FF-4789-BED0-168807376B51}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil_.exe:BlueSoleil
"{BA8047FC-9E9C-407E-A6DC-66B012E6DEC9}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil_.exe:BlueSoleil
"{91B58C53-162A-49EF-9B25-468AC87FDF74}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{0262F07B-B541-4E5F-B634-C3B150B0575A}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{684B9D67-DE81-4995-BC52-5B13CE1EFC86}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{88FD7088-EE74-4F50-A8F5-A3FD8A01DDF1}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= UDP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"UDP Query User{31DB0BAB-4476-42DE-A513-1680A5ACCC2A}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= TCP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"TCP Query User{D92E2C82-9699-42CA-AD78-94DAA118103A}c:\\users\\toshiba\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= UDP:c:\users\toshiba\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe
"UDP Query User{48EEA5F2-41E0-4DC4-AE75-D8DB8F2F90AF}c:\\users\\toshiba\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= TCP:c:\users\toshiba\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe
"{2C390D6A-CECB-4C3D-AB36-3751ECBFB915}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{9151333D-0FC9-41C4-B8B1-FEBC2C73B2C9}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"TCP Query User{68BF232E-B7C0-468C-8F44-8675C91DEB1E}c:\\program files\\kontiki\\khost.exe"= UDP:c:\program files\kontiki\khost.exe:Delivery Manager
"UDP Query User{B1B62B52-665E-4945-A5CF-D80988D6188B}c:\\program files\\kontiki\\khost.exe"= TCP:c:\program files\kontiki\khost.exe:Delivery Manager
"{385D04FD-A628-4000-84A3-CA059562196C}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{105EDC7E-9F7E-44DF-80EB-89C432E2F968}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"TCP Query User{D7CE99D2-2697-4811-9001-B6721FE16EA8}c:\\program files\\webmediaplayer\\webmediaplayer.exe"= UDP:c:\program files\webmediaplayer\webmediaplayer.exe:WebMediaPlayer
"UDP Query User{BA24DC06-2CDC-40B4-A009-4EC768664BDD}c:\\program files\\webmediaplayer\\webmediaplayer.exe"= TCP:c:\program files\webmediaplayer\webmediaplayer.exe:WebMediaPlayer
"{D85F615F-9C05-41A4-B0B6-5E6C6B371F84}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{99EAC962-86A6-4245-B053-45432C0E6EA1}c:\\program files\\tvuplayer\\tvuplayer.exe"= UDP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"UDP Query User{2A4773D4-61F7-426D-95F7-001EEB626995}c:\\program files\\tvuplayer\\tvuplayer.exe"= TCP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"{E97C5382-0215-4F61-AC12-4C4596BB66FC}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D5DA6B19-6CF5-41C3-B191-62D5BD2CF5A3}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C3D7987C-5625-4CEA-A234-CD77493C0A30}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{9B202BBF-E1FC-4FC8-BDB1-616E2F3FE4C0}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{3C960676-35A5-463A-B79A-FD6DAAA9A0DB}c:\\users\\toshiba\\appdata\\local\\octoshape\\octoshape streaming services\\octoshapeclient.exe"= UDP:c:\users\toshiba\appdata\local\octoshape\octoshape streaming services\octoshapeclient.exe:octoshapeclient.exe
"UDP Query User{C361EC20-DA38-4BC0-9DA6-C97A99F6BD55}c:\\users\\toshiba\\appdata\\local\\octoshape\\octoshape streaming services\\octoshapeclient.exe"= TCP:c:\users\toshiba\appdata\local\octoshape\octoshape streaming services\octoshapeclient.exe:octoshapeclient.exe
R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [2008-08-12 339456]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder
2008-08-17 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
2008-11-23 c:\windows\Tasks\User_Feed_Synchronization-{3F837391-37B4-4652-8F63-A24909EEA1FE}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 07:33]
2008-11-23 c:\windows\Tasks\User_Feed_Synchronization-{99FB82D8-7D7F-4B02-B9E1-3BB97C159D41}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 07:33]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-pipyj - c:\users\toshiba\appdata\local\pipyj.exe
HKCU-Run-TOSCDSPD - TOSCDSPD.EXE
HKLM-Run-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL
HKLM-Run-My Web Search Bar Search Scope Monitor - c:\progra~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\qrhaqn2u.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-23 19:50:19
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\System32\audiodg.exe
c:\program files\ATK Hotkey\ASLDRSrv.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\windows\System32\DVDRAMSV.exe
c:\program files\Kontiki\KService.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe
c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\program files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\System32\TODDSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\ATK Hotkey\HControl.exe
c:\program files\ATK Hotkey\ATKOSD.exe
c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
c:\windows\System32\igfxsrvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
c:\program files\McAfee\Common Framework\Mctray.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\TOSHIBA\ConfigFree\CFSwMgr.exe
.
**************************************************************************
.
Completion time: 2008-11-23 19:59:04 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-23 19:58:28
ComboFix2.txt 2008-09-13 19:24:19
Pre-Run: 6,692,245,504 bytes free
Post-Run: 6,549,893,120 bytes free
748 — E O F — 2008-11-21 06:26:05
Question: Should l enable my antiVirus since l will be going online to respond to you..?