Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Start menu, desktop icons and taskbar disappear and reappear


  • Please log in to reply

#1
livedead

livedead

    Member

  • Member
  • PipPip
  • 29 posts
Logs

OTList1

OTListIt logfile created on: 4/21/2009 9:09:28 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\New-April\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.37 Mb Total Physical Memory | 342.07 Mb Available Physical Memory | 67.96% Memory free
1.20 Gb Paging File | 1.11 Gb Available in Paging File | 92.35% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 51.64 Gb Total Space | 37.57 Gb Free Space | 72.75% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RUPA-CE5DB493CD
Current User Name: New-April
Logged in as Administrator.

Current Boot Mode: SafeMode with Networking
Scan Mode: Current user

Extras


OTListIt Extras logfile created on: 4/21/2009 9:09:28 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\New-April\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.37 Mb Total Physical Memory | 342.07 Mb Available Physical Memory | 67.96% Memory free
1.20 Gb Paging File | 1.11 Gb Available in Paging File | 92.35% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 51.64 Gb Total Space | 37.57 Gb Free Space | 72.75% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RUPA-CE5DB493CD
Current User Name: New-April
Logged in as Administrator.

Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:*:Enabled:CyberLink PowerDVD DX (CyberLink Corp.)
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:*:Enabled:CyberLink PowerDVD DX Resident Program (CyberLink Corp.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:*:Enabled:CyberLink PowerDVD DX (CyberLink Corp.)
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:*:Enabled:CyberLink PowerDVD DX Resident Program (CyberLink Corp.)
C:\Documents and Settings\Rupa\Local Settings\netdetect.exe:*:Enabled:netdetect File not found

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{098122AB-C605-4853-B441-C0A4EB359B75}" = DirectXInstallService
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3FB3647F-B6A6-46B4-8613-A09BCFAB80F0}" = Roxio Creator Premier 10
"{469EF13B-4AD0-48D7-AF89-6B92278293E2}" = Roxio Creator Premier
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6DB501ED-E18F-210C-96AE-A3B422EA067E}" = Search Assistant Searchersmart
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver for Mobile
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Roxio CinePlayer Decoder Pack
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9C9D0F85-5658-4A5E-95A9-65F7DB2916EE}" = Broadcom 440x 10/100 Integrated Controller
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = C-Major Audio
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{EC877639-07AB-495C-BFD1-D63AF9140810}" = Roxio Activation Module
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator Premier
"{FCD9CD52-7222-4672-94A0-A722BA702FD0}" = Dell Resource CD
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"avast!" = avast! Antivirus
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"Cambridge Ed TestPrep PLUS" = Cambridge Ed TestPrep PLUS
"CNXT_MODEM_PCI_VEN_8086&DEV_24x6&SUBSYS_542214F1" = Conexant D110 MDC V.92 Modem
"ERUNT_is1" = ERUNT 1.1j
"GoToAssist" = GoToAssist 8.0.0.514
"GRE POWERPREP" = GRE POWERPREP
"LiveUpdate" = LiveUpdate 3.0 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MetaFrame Presentation Server Web Client for Win32" = MetaFrame Presentation Server Web Client for Win32
"Mozilla Firefox (3.0.8)" = Mozilla Firefox (3.0.8)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NAV" = Norton AntiVirus
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/16/2009 2:29:20 PM | Computer Name = RUPA-CE5DB493CD | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The server name or address could not be resolved

Error - 4/16/2009 3:39:00 PM | Computer Name = RUPA-CE5DB493CD | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

Error - 4/16/2009 8:57:35 PM | Computer Name = RUPA-CE5DB493CD | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

Error - 4/17/2009 2:48:52 PM | Computer Name = RUPA-CE5DB493CD | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

Error - 4/20/2009 2:58:07 PM | Computer Name = RUPA-CE5DB493CD | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

Error - 4/20/2009 5:41:52 PM | Computer Name = RUPA-CE5DB493CD | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

Error - 4/20/2009 6:03:14 PM | Computer Name = RUPA-CE5DB493CD | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

Error - 4/20/2009 6:19:14 PM | Computer Name = RUPA-CE5DB493CD | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

Error - 4/20/2009 6:24:20 PM | Computer Name = RUPA-CE5DB493CD | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

Error - 4/21/2009 12:02:15 PM | Computer Name = RUPA-CE5DB493CD | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

[ System Events ]
Error - 4/20/2009 6:37:14 PM | Computer Name = RUPA-CE5DB493CD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 4/20/2009 6:48:12 PM | Computer Name = RUPA-CE5DB493CD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 4/21/2009 1:19:04 AM | Computer Name = RUPA-CE5DB493CD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 4/21/2009 11:56:31 AM | Computer Name = RUPA-CE5DB493CD | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000243'
while processing the file 'SrtETmp' on the volume 'HarddiskVolume2'. It has stopped
monitoring the volume.

Error - 4/21/2009 12:03:50 PM | Computer Name = RUPA-CE5DB493CD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 4/21/2009 12:04:25 PM | Computer Name = RUPA-CE5DB493CD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service wuauserv with
arguments "" in order to run the server: {9B1F122C-2982-4E91-AA8B-E071D54F2A4D}

Error - 4/21/2009 12:04:27 PM | Computer Name = RUPA-CE5DB493CD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service wuauserv with
arguments "" in order to run the server: {9B1F122C-2982-4E91-AA8B-E071D54F2A4D}

Error - 4/21/2009 12:04:29 PM | Computer Name = RUPA-CE5DB493CD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service wuauserv with
arguments "" in order to run the server: {9B1F122C-2982-4E91-AA8B-E071D54F2A4D}

Error - 4/21/2009 12:04:56 PM | Computer Name = RUPA-CE5DB493CD | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Aavmker4 APPDRV aswSP BHDrvx86 ccHP eeCtrl Fips IDSxpx86 intelppm SASDIFSV SASKUTIL SRTSP SRTSPX
SYMTDI

Error - 4/21/2009 12:07:52 PM | Computer Name = RUPA-CE5DB493CD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}


< End of report >

Rooter

Microsoft Windows XP Home Edition (5.1.2600) Service Pack 2

C:\ [Fixed] - NTFS - (Total:52878 Mo/Free:1604 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)

Tue 04/21/2009| 9:06

----------------------\\ Processes..

--Locked-- [System Process]
---------- System
---------- \SystemRoot\System32\smss.exe
---------- \??\C:\WINDOWS\system32\csrss.exe
---------- \??\C:\WINDOWS\system32\winlogon.exe
---------- C:\WINDOWS\system32\services.exe
---------- C:\WINDOWS\system32\lsass.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\Explorer.EXE
---------- C:\Program Files\Mozilla Firefox\firefox.exe
---------- C:\Documents and Settings\New-April\Desktop\Rooter.exe
---------- C:\WINDOWS\system32\cmd.exe
---------- C:\Rooter$\RK.exe

----------------------\\ Search..

----------------------\\ ROOTKIT !!



1 - "C:\Rooter$\Rooter_1.txt" - Tue 04/21/2009| 9:06

----------------------\\ Scan completed at 9:06
  • 0

Advertisements


#2
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello livedead and welcome to Geeks to go. :)
Sorry about the delay.


Could you please run another scan with OTListIt2 and post the OTListIt.txt in your next reply.
  • 0

#3
livedead

livedead

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Hi Jimmy

Thank you for your reply

The OLTListIt Log:

OTListIt logfile created on: 4/25/2009 11:12:53 PM - Run 2
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\New-April\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.37 Mb Total Physical Memory | 269.56 Mb Available Physical Memory | 53.55% Memory free
1.20 Gb Paging File | 1.01 Gb Available in Paging File | 84.09% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 51.64 Gb Total Space | 37.52 Gb Free Space | 72.65% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RUPA-CE5DB493CD
Current User Name: New-April
Logged in as Administrator.

Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\New-April\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aswUpdSv [Auto | Stopped]) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (avast! Antivirus [Auto | Stopped]) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Stopped]) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Stopped]) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (bgsvcgen [Auto | Stopped]) -- C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation)
SRV - (GoToAssist [On_Demand | Stopped]) -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (gusvc [Disabled | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Stopped]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LiveUpdate [On_Demand | Stopped]) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE (Symantec Corporation)
SRV - (NICCONFIGSVC [Auto | Stopped]) -- C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe (Dell Inc.)
SRV - (Norton AntiVirus [Auto | Stopped]) -- C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe (Symantec Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (RoxLiveShare10 [Auto | Stopped]) -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe (Sonic Solutions)
SRV - (RoxMediaDB10 [On_Demand | Stopped]) -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (RoxWatch10 [Auto | Stopped]) -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe (Sonic Solutions)
SRV - (stllssvr [On_Demand | Stopped]) -- C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
SRV - (wltrysvc [Auto | Stopped]) -- C:\WINDOWS\System32\WLTRYSVC.EXE ()
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (Aavmker4 [System | Stopped]) -- C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (APPDRV [System | Stopped]) -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (aswFsBlk [Auto | Stopped]) -- C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Stopped]) -- C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Stopped]) -- C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) -- C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (BCM43XX [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\bcmwl5.sys (Broadcom Corporation)
DRV - (bcm4sbxp [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BHDrvx86 [System | Stopped]) -- C:\WINDOWS\System32\Drivers\NAV\1005000.086\BHDrvx86.sys (Symantec Corporation)
DRV - (ccHP [System | Stopped]) -- C:\WINDOWS\System32\Drivers\NAV\1005000.086\ccHPx86.sys (Symantec Corporation)
DRV - (cercsr6 [Boot | Stopped]) -- C:\WINDOWS\System32\drivers\cercsr6.sys (Adaptec, Inc.)
DRV - (eeCtrl [System | Stopped]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (HSFHWICH [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\HSF_DPV.SYS (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (IDSxpx86 [System | Stopped]) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090414.001\IDSxpx86.sys (Symantec Corporation)
DRV - (mdmxsdk [Auto | Stopped]) -- C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (NAVENG [On_Demand | Stopped]) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090421.006\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Stopped]) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090421.006\NAVEX15.SYS (Symantec Corporation)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (SASDIFSV [System | Stopped]) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Stopped]) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Stopped]) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys ()
DRV - (SRTSP [System | Stopped]) -- C:\WINDOWS\System32\Drivers\NAV\1005000.086\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX [System | Stopped]) -- C:\WINDOWS\system32\drivers\NAV\1005000.086\SRTSPX.SYS (Symantec Corporation)
DRV - (STAC97 [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\STAC97.sys (SigmaTel, Inc.)
DRV - (SymEFA [Boot | Running]) -- C:\WINDOWS\system32\drivers\NAV\1005000.086\SYMEFA.SYS (Symantec Corporation)
DRV - (SymEvent [On_Demand | Stopped]) -- C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMFW [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\NAV\1005000.086\SYMFW.SYS (Symantec Corporation)
DRV - (SYMIDS [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\NAV\1005000.086\SYMIDS.SYS (Symantec Corporation)
DRV - (SymIM [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\SymIM.sys (Symantec Corporation)
DRV - (SymIMMP [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\SymIM.sys (Symantec Corporation)
DRV - (SYMNDIS [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\NAV\1005000.086\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMTDI [System | Stopped]) -- C:\WINDOWS\System32\Drivers\NAV\1005000.086\SYMTDI.SYS (Symantec Corporation)
DRV - (winachsf [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft...p...&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...p...ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...p...&ar=msnhome
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {8545daff-ad1e-493f-a37e-eed1ac79682b}:1.0
FF - prefs.js..extensions.enabledItems: {124F0D6F-DAFC-4E89-A7CB-2ADFD142AAB4}:1.0
FF - prefs.js..extensions.enabledItems: {66332D95-872C-43F8-B0A7-E8254CC2E719}:1.0
FF - prefs.js..extensions.enabledItems: {39B3EB2F-6AEA-4BF7-ADB8-6A760A15E998}:1.0
FF - prefs.js..extensions.enabledItems: {4EE9FD1E-9D55-410F-BC75-296BC9AB9B54}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8

FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008/12/06 14:23:42 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{124F0D6F-DAFC-4E89-A7CB-2ADFD142AAB4}: C:\DOCUMENTS AND SETTINGS\RUPA\LOCAL SETTINGS\APPLICATION DATA\{124F0D6F-DAFC-4E89-A7CB-2ADFD142AAB4} [2009/01/10 21:25:13 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{66332D95-872C-43F8-B0A7-E8254CC2E719}: C:\DOCUMENTS AND SETTINGS\NEW\LOCAL SETTINGS\APPLICATION DATA\{66332D95-872C-43F8-B0A7-E8254CC2E719} [2009/03/18 15:21:47 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{39B3EB2F-6AEA-4BF7-ADB8-6A760A15E998}: C:\DOCUMENTS AND SETTINGS\RUPARAJ\LOCAL SETTINGS\APPLICATION DATA\{39B3EB2F-6AEA-4BF7-ADB8-6A760A15E998} [2009/04/16 12:46:43 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{4EE9FD1E-9D55-410F-BC75-296BC9AB9B54}: C:\DOCUMENTS AND SETTINGS\NEW-APRIL\LOCAL SETTINGS\APPLICATION DATA\{4EE9FD1E-9D55-410F-BC75-296BC9AB9B54} [2009/04/20 09:14:44 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/15 13:12:50 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/31 14:18:36 | 00,000,000 | ---D | M]

[2009/04/15 13:13:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\New-April\Application Data\mozilla\Extensions
[2009/04/15 13:13:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\New-April\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/15 13:13:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\New-April\Application Data\mozilla\Firefox\Profiles\gj03h6mb.default\extensions
[2009/04/21 08:57:05 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/03/31 14:18:36 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/31 14:18:14 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/31 14:18:14 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/12/02 01:04:40 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/12/02 01:04:40 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/12/02 01:04:40 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/12/02 01:04:40 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/12/02 01:04:40 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/12/02 01:04:40 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/12/02 01:04:40 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (783 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 91.207.117.244 browser-security.microsoft.com
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe (Dell Inc.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN File not found
O4 - HKLM..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" (Sonic Solutions)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://myed-nc.wach...perSetupSP1.cab (JuniperSetupSP1 Control)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\gevpco.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\tolodlls.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/04/22 12:59:28 | 00,019,968 | ---- | C] () -- C:\Documents and Settings\New-April\Desktop\draft.doc
[2009/04/21 11:48:08 | 00,019,968 | ---- | C] () -- C:\Documents and Settings\New-April\My Documents\dtr.doc
[2009/04/21 11:05:46 | 00,073,216 | ---- | C] () -- C:\Documents and Settings\New-April\My Documents\Resume-Rupa-Rajamani.doc
[2009/04/21 09:08:45 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\New-April\Desktop\OTListIt2.exe
[2009/04/21 09:06:17 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/04/21 09:06:08 | 00,267,612 | ---- | C] () -- C:\Documents and Settings\New-April\Desktop\Rooter.exe
[2009/04/21 08:28:24 | 00,001,709 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/04/21 08:28:22 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/04/21 08:28:19 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/04/21 08:28:17 | 00,026,944 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/04/21 08:28:10 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\AvastSS.scr
[2009/04/21 08:28:08 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/04/21 08:28:07 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2009/04/21 08:28:06 | 00,094,032 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/04/21 08:28:06 | 00,093,296 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2009/04/21 08:27:21 | 01,256,296 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\aswBoot.exe
[2009/04/21 08:27:21 | 00,380,928 | ---- | C] () -- C:\WINDOWS\System32\actskin4.ocx
[2009/04/21 08:27:15 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/04/21 08:24:57 | 00,308,160 | ---- | C] (ALWIL Software) -- C:\Documents and Settings\New-April\Desktop\avast_home_setup.exe
[2009/04/20 13:35:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\New-April\Application Data\Malwarebytes
[2009/04/20 13:35:54 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/20 13:35:46 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/20 13:35:44 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/20 13:35:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/20 13:35:41 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/20 13:34:23 | 02,967,800 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\New-April\Desktop\mbam-setup.exe
[2009/04/20 13:33:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/04/20 13:32:49 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\New-April\Desktop\NTREGOPT.lnk
[2009/04/20 13:32:49 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\New-April\Desktop\ERUNT.lnk
[2009/04/20 13:32:46 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/04/20 13:31:27 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\New-April\Desktop\erunt_setup.exe
[2009/04/20 13:28:38 | 00,021,504 | ---- | C] (Doug Knox) -- C:\Documents and Settings\New-April\Desktop\SysRestorePoint.exe
[2009/04/20 13:01:48 | 00,000,000 | ---D | C] -- C:\VundoFix Backups
[2009/04/20 11:00:54 | 03,184,656 | -H-- | C] () -- C:\Documents and Settings\New-April\Local Settings\Application Data\IconCache.db
[2009/04/20 09:42:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/04/20 09:42:08 | 00,000,780 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/04/20 09:41:53 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2009/04/20 09:41:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\New-April\Application Data\SUPERAntiSpyware.com
[2009/04/20 09:41:06 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2009/04/20 09:40:02 | 06,289,952 | ---- | C] () -- C:\Documents and Settings\New-April\Desktop\SUPERAntiSpyware.exe
[2009/04/20 09:14:48 | 00,000,000 | R--D | C] -- C:\Documents and Settings\New-April\My Documents\My Videos
[2009/04/20 09:14:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\New-April\Local Settings\Application Data\PowerDVD DX
[2009/04/20 09:14:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\New-April\Local Settings\Application Data\{4EE9FD1E-9D55-410F-BC75-296BC9AB9B54}
[2009/04/16 12:44:00 | 00,001,612 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ExifLauncher2.lnk
[2009/04/15 13:15:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\New-April\Application Data\Macromedia
[2009/04/15 13:15:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\New-April\Application Data\Adobe
[2009/04/15 13:12:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\New-April\Local Settings\Application Data\Mozilla
[2009/04/15 13:12:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\New-April\Application Data\Mozilla
[2009/04/15 13:09:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\New-April\Application Data\Identities
[2009/04/15 13:09:33 | 00,000,000 | R--D | C] -- C:\Documents and Settings\New-April\My Documents\My Music
[2009/04/15 13:09:32 | 00,000,080 | -HS- | C] () -- C:\Documents and Settings\New-April\My Documents\desktop.ini
[2009/04/15 13:09:32 | 00,000,000 | R--D | C] -- C:\Documents and Settings\New-April\My Documents\My Pictures
[2009/04/15 13:09:26 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\New-April\Application Data\desktop.ini
[2009/04/15 13:09:25 | 00,000,084 | -HS- | C] () -- C:\Documents and Settings\New-April\Start Menu\Programs\Startup\desktop.ini
[2009/04/15 13:09:25 | 00,000,000 | --SD | C] -- C:\Documents and Settings\New-April\Application Data\Microsoft
[2009/04/15 13:09:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\New-April\Local Settings\Application Data\Microsoft
[2009/04/14 12:00:51 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusb.dll
[2009/04/14 12:00:47 | 00,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusd.dll
[2009/04/14 12:00:46 | 00,015,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbscan.sys
[2009/04/14 12:00:46 | 00,015,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbscan.sys
[2009/04/14 11:46:40 | 00,086,016 | ---- | C] (B.H.A Corporation) -- C:\WINDOWS\System32\bgsvcgen.exe
[2009/04/14 11:46:40 | 00,057,344 | ---- | C] (B.H.A Corporation) -- C:\WINDOWS\System32\GenSvcInst.exe
[2009/04/14 11:46:40 | 00,049,152 | ---- | C] (BHA) -- C:\WINDOWS\System32\setupsvc.dll
[2009/04/14 11:46:38 | 00,032,256 | ---- | C] (B.H.A Corporation) -- C:\WINDOWS\System32\drivers\cdrbsdrv.sys
[2009/04/14 11:41:53 | 00,208,896 | ---- | C] (FUJI PHOTO FILM CO., LTD.) -- C:\WINDOWS\System32\FFRafShellEx.dll
[2009/04/14 11:41:52 | 00,274,432 | ---- | C] (FUJI PHOTO FILM CO., LTD.) -- C:\WINDOWS\System32\FFTIFF16.dll
[2009/04/14 11:41:52 | 00,155,648 | ---- | C] (FUJI PHOTO FILM CO., LTD.) -- C:\WINDOWS\System32\FFRAFLIB.DLL
[2009/04/13 15:03:44 | 00,002,709 | ---- | C] () -- C:\WINDOWS\System32\tolodlls.dat
[2009/04/06 17:50:06 | 00,002,709 | ---- | C] () -- C:\WINDOWS\System32\ebxcrapex.dat
[2009/04/06 10:17:11 | 00,002,709 | ---- | C] () -- C:\WINDOWS\System32\ydocraev.dat
[2009/04/06 06:44:57 | 00,000,048 | ---- | C] () -- C:\WINDOWS\webica.ini
[2009/04/06 06:43:05 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Resource
[2009/04/02 20:32:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\IBMERS
[2009/03/31 08:16:09 | 00,002,709 | ---- | C] () -- C:\WINDOWS\System32\toandebxto.dat
[2008/12/22 16:04:50 | 00,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI
[2008/12/10 16:44:02 | 00,000,058 | ---- | C] () -- C:\WINDOWS\OSA.INI
[2008/10/30 08:18:24 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/10/29 12:53:28 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2008/10/29 12:53:27 | 00,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2008/10/29 12:22:31 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\stac97co.dll
[2004/08/04 03:00:00 | 00,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2004/08/04 03:00:00 | 00,000,603 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/04 03:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/01/07 16:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/04/22 12:59:29 | 00,019,968 | ---- | M] () -- C:\Documents and Settings\New-April\Desktop\draft.doc
[2009/04/22 08:17:54 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/04/21 22:14:15 | 03,184,656 | -H-- | M] () -- C:\Documents and Settings\New-April\Local Settings\Application Data\IconCache.db
[2009/04/21 11:48:09 | 00,019,968 | ---- | M] () -- C:\Documents and Settings\New-April\My Documents\dtr.doc
[2009/04/21 09:08:46 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\New-April\Desktop\OTListIt2.exe
[2009/04/21 09:06:09 | 00,267,612 | ---- | M] () -- C:\Documents and Settings\New-April\Desktop\Rooter.exe
[2009/04/21 08:56:46 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/04/21 08:28:24 | 00,001,709 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/04/21 08:28:07 | 00,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/04/21 08:24:59 | 00,308,160 | ---- | M] (ALWIL Software) -- C:\Documents and Settings\New-April\Desktop\avast_home_setup.exe
[2009/04/20 13:35:54 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/20 13:34:25 | 02,967,800 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\New-April\Desktop\mbam-setup.exe
[2009/04/20 13:32:49 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\New-April\Desktop\NTREGOPT.lnk
[2009/04/20 13:32:49 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\New-April\Desktop\ERUNT.lnk
[2009/04/20 13:31:28 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\New-April\Desktop\erunt_setup.exe
[2009/04/20 13:28:38 | 00,021,504 | ---- | M] (Doug Knox) -- C:\Documents and Settings\New-April\Desktop\SysRestorePoint.exe
[2009/04/20 09:42:09 | 00,000,780 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/04/20 09:40:05 | 06,289,952 | ---- | M] () -- C:\Documents and Settings\New-April\Desktop\SUPERAntiSpyware.exe
[2009/04/20 09:14:27 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/04/16 12:44:01 | 00,000,603 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/04/16 12:44:01 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/04/16 12:44:01 | 00,000,211 | -HS- | M] () -- C:\boot.ini
[2009/04/15 14:42:17 | 00,239,944 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/15 13:10:06 | 00,000,080 | -HS- | M] () -- C:\Documents and Settings\New-April\My Documents\desktop.ini
[2009/04/15 04:31:42 | 00,356,120 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/15 04:31:42 | 00,312,172 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/04/15 04:31:42 | 00,040,394 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/04/15 03:08:41 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/04/14 11:42:36 | 00,001,612 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ExifLauncher2.lnk
[2009/04/13 15:03:44 | 00,002,709 | ---- | M] () -- C:\WINDOWS\System32\tolodlls.dat
[2009/04/06 17:50:06 | 00,002,709 | ---- | M] () -- C:\WINDOWS\System32\ebxcrapex.dat
[2009/04/06 15:32:54 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 10:17:11 | 00,002,709 | ---- | M] () -- C:\WINDOWS\System32\ydocraev.dat
[2009/04/06 09:13:30 | 00,000,048 | ---- | M] () -- C:\WINDOWS\webica.ini
[2009/04/06 07:57:24 | 24,921,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/03/31 08:16:09 | 00,002,709 | ---- | M] () -- C:\WINDOWS\System32\toandebxto.dat
[2009/03/27 00:09:32 | 01,193,414 | ---- | M] () -- C:\WINDOWS\System32\dllcache\sysmain.sdb

========== Alternate Data Streams ==========

@Alternate Data Stream - 870 bytes -> C:\WINDOWS\System32\msln.exe:16cf792f68a2ab395c7c44cf475eb794
< End of report >
  • 0

#4
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello livedead,

Before we begin I see that you have two anti-virus programs running, I need you to remove one of them. Running two anti-virus programs at the same time can slow your computer down and also the anti-virus programs can conflict with each other. These are the two I see you have running.
Avast and Symantec
If you need help removing one of them please let me know. Please let me know what anti-virus you removed in your next reply.




  • Please open OTListIt2.exe
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
    :Files
    C:\WINDOWS\System32\tolodlls.dat
    C:\WINDOWS\System32\ebxcrapex.dat
    C:\WINDOWS\System32\ydocraev.dat
    C:\WINDOWS\System32\toandebxto.dat
    
    :Commands
    [purity]
    [emptytemp]
    [reboot]
  • Return to OTListIt2, right click in the "Custom Scans/fixes" window (under the light blue bar) and choose Paste.
  • Click the Run Fix button.
  • Let the program run until it is finished, reboot when it is done.
  • It will produce a log for you on reboot, please post that log in your next reply.

  • 0

#5
livedead

livedead

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Hi Jimmy

I have removed Avast from my computer. Have run the custom fix which you mentioned. The log is below. Do let me know what I need to do next. My computer is just not working except in safe mode.

Thanks
Livedead

========== FILES ==========
C:\WINDOWS\System32\tolodlls.dat moved successfully.
C:\WINDOWS\System32\ebxcrapex.dat moved successfully.
C:\WINDOWS\System32\ydocraev.dat moved successfully.
C:\WINDOWS\System32\toandebxto.dat moved successfully.
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\New-April\Local Settings\Temp\etilqs_lDAgJULuTcoENiJV8BH3 scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\New-April\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
File delete failed. C:\Documents and Settings\New-April\Local Settings\Application Data\Mozilla\Firefox\Profiles\gj03h6mb.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\New-April\Local Settings\Application Data\Mozilla\Firefox\Profiles\gj03h6mb.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\New-April\Local Settings\Application Data\Mozilla\Firefox\Profiles\gj03h6mb.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\New-April\Local Settings\Application Data\Mozilla\Firefox\Profiles\gj03h6mb.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\New-April\Local Settings\Application Data\Mozilla\Firefox\Profiles\gj03h6mb.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.

OTListIt2 by OldTimer - Version 2.0.14.0 log created on 04272009_084617

Files moved on Reboot...
File C:\Documents and Settings\New-April\Local Settings\Temp\etilqs_lDAgJULuTcoENiJV8BH3 not found!
C:\Documents and Settings\New-April\Local Settings\Application Data\Mozilla\Firefox\Profiles\gj03h6mb.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\New-April\Local Settings\Application Data\Mozilla\Firefox\Profiles\gj03h6mb.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\New-April\Local Settings\Application Data\Mozilla\Firefox\Profiles\gj03h6mb.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\New-April\Local Settings\Application Data\Mozilla\Firefox\Profiles\gj03h6mb.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\New-April\Local Settings\Application Data\Mozilla\Firefox\Profiles\gj03h6mb.default\urlclassifier3.sqlite moved successfully.

Registry entries deleted on Reboot...
  • 0

#6
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello livedead,

My computer is just not working except in safe mode.

Could you please tell me what it does when trying to start in normal mode?
  • 0

#7
livedead

livedead

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Hi Jimmy

When trying to start in normal mode, every 10 seconds, my desktop icons, taskbar and start menu disappear and reappear. I am not able to click on any icon except for the instant when the icons reappear. I can not access my files and folders. I scanned the computer with superanti spyware and found some trojans which I removed. I scanned it with malwarebytes anti-malware which again found some spyware and removed it. However, it still didn't fix the problem. I don't experience this issue in safe mode. Please let me know if you need any further clarifications.

Thanks
livedead
  • 0

#8
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello livedead,




Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Posted Image



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • 0

#9
livedead

livedead

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Hi Jimmy

Please find the log from the ComboFix scan

ComboFix 09-04-28.02 - New-April 04/28/2009 22:01.1 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.503.391 [GMT -7:00]
Running from: c:\documents and settings\New-April\Desktop\ComboFix.exe
AV: Norton AntiVirus *On-access scanning enabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\c.cgm

.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-29 )))))))))))))))))))))))))))))))
.

2009-04-20 20:32 . 2009-04-20 20:32 -------- d-----w c:\program files\ERUNT
2009-04-20 20:01 . 2009-04-20 20:01 -------- d-----w C:\VundoFix Backups
2009-04-20 16:42 . 2009-04-20 16:42 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-04-20 16:41 . 2009-04-20 16:42 -------- d-----w c:\program files\SUPERAntiSpyware
2009-04-20 16:41 . 2009-04-20 16:41 -------- d-----w c:\documents and settings\New-April\Application Data\SUPERAntiSpyware.com
2009-04-20 16:41 . 2009-04-20 16:41 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-04-20 16:14 . 2009-04-20 16:14 -------- d-----w c:\documents and settings\New-April\Local Settings\Application Data\PowerDVD DX
2009-04-20 16:14 . 2009-04-20 16:14 -------- d-----w c:\documents and settings\New-April\Local Settings\Application Data\{4EE9FD1E-9D55-410F-BC75-296BC9AB9B54}
2009-04-16 19:46 . 2009-04-16 19:46 -------- d-----w c:\documents and settings\Ruparaj\Local Settings\Application Data\{39B3EB2F-6AEA-4BF7-ADB8-6A760A15E998}
2009-04-15 22:11 . 2009-04-15 22:11 -------- d-----w c:\documents and settings\Ruparaj\Local Settings\Application Data\PowerDVD DX
2009-04-15 21:49 . 2009-04-15 21:49 -------- d-----w c:\documents and settings\Ruparaj\Local Settings\Application Data\Mozilla
2009-04-15 20:12 . 2009-04-15 20:12 -------- d-----w c:\documents and settings\New-April\Local Settings\Application Data\Mozilla
2009-04-14 19:00 . 2001-08-18 05:36 5632 ----a-w c:\windows\system32\ptpusb.dll
2009-04-14 19:00 . 2004-08-04 07:56 159232 ----a-w c:\windows\system32\ptpusd.dll
2009-04-14 19:00 . 2004-08-04 05:58 15104 -c--a-w c:\windows\system32\dllcache\usbscan.sys
2009-04-14 19:00 . 2004-08-04 05:58 15104 ----a-w c:\windows\system32\drivers\usbscan.sys
2009-04-14 18:46 . 2005-05-01 00:09 57344 ------w c:\windows\system32\GenSvcInst.exe
2009-04-14 18:46 . 2005-05-01 21:41 49152 ------w c:\windows\system32\setupsvc.dll
2009-04-14 18:46 . 2005-05-01 00:02 86016 ------w c:\windows\system32\bgsvcgen.exe
2009-04-14 18:46 . 2005-05-11 07:33 32256 ------w c:\windows\system32\drivers\cdrbsdrv.sys
2009-04-14 18:43 . 2009-04-15 21:36 -------- d-----w c:\documents and settings\New\Application Data\FUJIFILM
2009-04-14 18:41 . 2006-07-12 21:39 208896 ----a-w c:\windows\system32\FFRafShellEx.dll
2009-04-14 18:41 . 2003-09-03 23:45 274432 ----a-w c:\windows\system32\FFTIFF16.dll
2009-04-14 18:41 . 2004-07-25 04:28 155648 ----a-w c:\windows\system32\FFRAFLIB.DLL
2009-04-07 17:02 . 2009-04-07 17:03 -------- d-----w c:\documents and settings\Rupa\Application Data\ICAClient
2009-04-06 13:43 . 2009-04-06 13:52 -------- d-----w c:\documents and settings\New\Application Data\ICAClient
2009-04-06 13:43 . 2009-04-06 13:43 -------- d-----w c:\windows\system32\Resource
2009-04-03 03:32 . 2009-04-03 03:32 -------- d-----w c:\documents and settings\New\Application Data\IBMERS
2009-04-03 03:32 . 2009-04-03 03:32 -------- d-----w c:\documents and settings\All Users\Application Data\IBMERS
2009-04-01 20:47 . 2009-04-01 20:47 -------- d-----w c:\documents and settings\New\Local Settings\Application Data\Identities

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-29 04:36 . 2008-10-29 20:23 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-29 04:36 . 2008-10-29 20:23 -------- d-----w c:\program files\Symantec
2009-04-27 15:40 . 2009-04-21 15:27 -------- d-----w c:\program files\Alwil Software
2009-04-15 21:38 . 2008-11-17 23:16 -------- d-----w c:\program files\GMATPrep
2009-04-14 18:46 . 2008-10-29 19:22 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-06 13:42 . 2008-10-29 19:14 -------- d-----w c:\program files\Citrix
2009-03-25 22:25 . 2009-03-25 22:25 2709 ----a-w c:\windows\system32\wdllexup.dat
2009-03-25 22:12 . 2009-03-25 22:12 58584 ----a-w c:\documents and settings\New\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-19 05:55 . 2008-11-02 05:26 -------- d-----w c:\program files\Google
2009-03-18 22:10 . 2009-03-18 22:10 2709 ----a-w c:\windows\system32\evporipco.dat
2009-03-18 22:09 . 2009-03-18 22:09 2709 ----a-w c:\windows\system32\jmcrawinto.dat
2009-03-06 14:00 . 2004-08-04 10:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-02-20 08:30 . 2006-03-04 03:33 659456 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:30 . 2004-08-04 10:00 81920 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 10:19 . 2004-08-04 10:00 1846272 ----a-w c:\windows\system32\win32k.sys
2009-02-09 10:01 . 2004-08-04 10:00 728576 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:01 . 2004-08-04 10:00 617984 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:01 . 2004-08-04 10:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:01 . 2004-08-04 10:00 715264 ----a-w c:\windows\system32\ntdll.dll
2009-02-06 10:32 . 2005-03-30 01:23 2186112 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:22 . 2004-08-04 10:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 09:54 . 2004-08-04 10:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 09:49 . 2005-03-30 01:01 2062976 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 20:08 . 2004-08-04 10:00 55808 ----a-w c:\windows\system32\secur32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-03-23 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-06 136600]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2007-12-14 244208]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-06-29 1032192]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-01 1392640]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-10-29 19:14 10536 ----a-w c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-03-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-03-23 72944]
R2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [2007-12-14 309744]
R2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [2007-12-14 166384]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-03 101936]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2007-12-14 1112560]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-03-23 7408]

.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-REGSHAVE - c:\program files\REGSHAVE\REGSHAVE.EXE
Notify-NavLogon - (no file)


.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = hxxp://www.superantispyware.com/applicationdisplay.html?id=1000001553&trial=no&activated=no&appid={5CFCA3FC-A40D-4613-AE0C-62217A2BA002}
FF - ProfilePath - c:\documents and settings\New-April\Application Data\Mozilla\Firefox\Profiles\gj03h6mb.default\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-28 22:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(724)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
.
Completion time: 2009-04-29 22:04
ComboFix-quarantined-files.txt 2009-04-29 05:03

Pre-Run: 40,545,316,864 bytes free
Post-Run: 41,449,463,808 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

139 --- E O F --- 2009-04-15 10:09
  • 0

#10
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello livedead,

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
c:\windows\system32\evporipco.dat
c:\windows\system32\jmcrawinto.dat

SysRst::

Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt. Please post the following report into your next reply:
  • Combofix.txt .

  • 0

Advertisements


#11
livedead

livedead

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Hi

The log with the code you gave is:

ComboFix 09-04-28.02 - New-April 04/28/2009 23:19.2 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.503.305 [GMT -7:00]
Running from: c:\documents and settings\New-April\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\New-April\Desktop\CFScript.txt
AV: Norton AntiVirus *On-access scanning enabled* (Updated)

FILE ::
c:\windows\system32\evporipco.dat
c:\windows\system32\jmcrawinto.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\evporipco.dat
c:\windows\system32\jmcrawinto.dat

.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-29 )))))))))))))))))))))))))))))))
.

2009-04-29 04:27 . 2009-04-29 04:27 -------- d-----w c:\documents and settings\New-April\Local Settings\Application Data\Symantec
2009-04-27 15:46 . 2009-04-27 15:46 -------- d-----w C:\_OTListIt
2009-04-26 16:16 . 2009-04-26 16:16 -------- d-----w c:\documents and settings\New-April\Application Data\AdobeUM
2009-04-26 16:16 . 2009-04-26 16:16 -------- d-----w c:\documents and settings\New-April\Local Settings\Application Data\Adobe
2009-04-21 16:06 . 2009-04-21 16:07 -------- d-----w C:\Rooter$
2009-04-21 15:27 . 2009-04-27 15:40 -------- d-----w c:\program files\Alwil Software
2009-04-20 20:35 . 2009-04-20 20:35 -------- d-----w c:\documents and settings\New-April\Application Data\Malwarebytes
2009-04-20 20:35 . 2009-04-20 20:35 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-20 20:32 . 2009-04-20 20:32 -------- d-----w c:\program files\ERUNT
2009-04-20 20:01 . 2009-04-20 20:01 -------- d-----w C:\VundoFix Backups
2009-04-20 16:42 . 2009-04-20 16:42 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-04-20 16:41 . 2009-04-20 16:42 -------- d-----w c:\program files\SUPERAntiSpyware
2009-04-20 16:41 . 2009-04-20 16:41 -------- d-----w c:\documents and settings\New-April\Application Data\SUPERAntiSpyware.com
2009-04-20 16:41 . 2009-04-20 16:41 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-04-20 16:14 . 2009-04-20 16:14 -------- d-----w c:\documents and settings\New-April\Local Settings\Application Data\PowerDVD DX
2009-04-20 16:14 . 2009-04-20 16:14 -------- d-----w c:\documents and settings\New-April\Local Settings\Application Data\{4EE9FD1E-9D55-410F-BC75-296BC9AB9B54}
2009-04-16 19:46 . 2009-04-16 19:46 -------- d-----w c:\documents and settings\Ruparaj\Local Settings\Application Data\{39B3EB2F-6AEA-4BF7-ADB8-6A760A15E998}
2009-04-15 22:11 . 2009-04-15 22:11 -------- d-----w c:\documents and settings\Ruparaj\Local Settings\Application Data\PowerDVD DX
2009-04-15 21:49 . 2009-04-15 21:49 -------- d-----w c:\documents and settings\Ruparaj\Local Settings\Application Data\Mozilla
2009-04-15 20:12 . 2009-04-15 20:12 -------- d-----w c:\documents and settings\New-April\Local Settings\Application Data\Mozilla
2009-04-14 19:00 . 2001-08-18 05:36 5632 ----a-w c:\windows\system32\ptpusb.dll
2009-04-14 19:00 . 2004-08-04 07:56 159232 ----a-w c:\windows\system32\ptpusd.dll
2009-04-14 19:00 . 2004-08-04 05:58 15104 -c--a-w c:\windows\system32\dllcache\usbscan.sys
2009-04-14 19:00 . 2004-08-04 05:58 15104 ----a-w c:\windows\system32\drivers\usbscan.sys
2009-04-14 18:46 . 2005-05-01 00:09 57344 ------w c:\windows\system32\GenSvcInst.exe
2009-04-14 18:46 . 2005-05-01 21:41 49152 ------w c:\windows\system32\setupsvc.dll
2009-04-14 18:46 . 2005-05-01 00:02 86016 ------w c:\windows\system32\bgsvcgen.exe
2009-04-14 18:46 . 2005-05-11 07:33 32256 ------w c:\windows\system32\drivers\cdrbsdrv.sys
2009-04-14 18:43 . 2009-04-15 21:36 -------- d-----w c:\documents and settings\New\Application Data\FUJIFILM
2009-04-14 18:41 . 2006-07-12 21:39 208896 ----a-w c:\windows\system32\FFRafShellEx.dll
2009-04-14 18:41 . 2003-09-03 23:45 274432 ----a-w c:\windows\system32\FFTIFF16.dll
2009-04-14 18:41 . 2004-07-25 04:28 155648 ----a-w c:\windows\system32\FFRAFLIB.DLL
2009-04-07 17:02 . 2009-04-07 17:03 -------- d-----w c:\documents and settings\Rupa\Application Data\ICAClient
2009-04-06 13:43 . 2009-04-06 13:52 -------- d-----w c:\documents and settings\New\Application Data\ICAClient
2009-04-06 13:43 . 2009-04-06 13:43 -------- d-----w c:\windows\system32\Resource
2009-04-03 03:32 . 2009-04-03 03:32 -------- d-----w c:\documents and settings\New\Application Data\IBMERS
2009-04-03 03:32 . 2009-04-03 03:32 -------- d-----w c:\documents and settings\All Users\Application Data\IBMERS
2009-04-01 20:47 . 2009-04-01 20:47 -------- d-----w c:\documents and settings\New\Local Settings\Application Data\Identities

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-29 04:36 . 2008-10-29 20:23 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-29 04:36 . 2008-10-29 20:23 -------- d-----w c:\program files\Symantec
2009-04-15 21:38 . 2008-11-17 23:16 -------- d-----w c:\program files\GMATPrep
2009-04-14 18:46 . 2008-10-29 19:22 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-06 13:42 . 2008-10-29 19:14 -------- d-----w c:\program files\Citrix
2009-03-25 22:25 . 2009-03-25 22:25 2709 ----a-w c:\windows\system32\wdllexup.dat
2009-03-25 22:12 . 2009-03-25 22:12 58584 ----a-w c:\documents and settings\New\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-19 05:55 . 2008-11-02 05:26 -------- d-----w c:\program files\Google
2009-03-06 14:00 . 2004-08-04 10:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-02-20 08:30 . 2006-03-04 03:33 659456 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:30 . 2004-08-04 10:00 81920 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 10:19 . 2004-08-04 10:00 1846272 ----a-w c:\windows\system32\win32k.sys
2009-02-09 10:01 . 2004-08-04 10:00 728576 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:01 . 2004-08-04 10:00 617984 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:01 . 2004-08-04 10:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:01 . 2004-08-04 10:00 715264 ----a-w c:\windows\system32\ntdll.dll
2009-02-06 10:32 . 2005-03-30 01:23 2186112 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:22 . 2004-08-04 10:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 09:54 . 2004-08-04 10:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 09:49 . 2005-03-30 01:01 2062976 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 20:08 . 2004-08-04 10:00 55808 ----a-w c:\windows\system32\secur32.dll
.

((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\1005000.086\srtspx.sys
02/27/2009 04:02 AM 43696 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030195.sys

c:\32788r22fwjfw\Assoc.cmd
04/24/2009 11:00 PM 3289 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030272.cmd

c:\32788r22fwjfw\Auto-RC.cmd
04/24/2009 11:01 PM 3109 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030273.cmd

c:\32788r22fwjfw\av.cmd
04/24/2009 10:55 PM 537 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030274.cmd

c:\32788r22fwjfw\av.vbs
08/31/2000 08:00 AM 962 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030275.vbs

c:\32788r22fwjfw\AWF.cmd
04/24/2009 11:01 PM 629 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030276.cmd

c:\32788r22fwjfw\Boot-Rk.cmd
04/24/2009 11:07 PM 1868 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030277.cmd

c:\32788r22fwjfw\Boot.bat
04/24/2009 11:01 PM 7600 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030278.bat

c:\32788r22fwjfw\BootSect.dll
08/31/2000 08:00 AM 7680 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030279.dll

c:\32788r22fwjfw\c.bat
04/29/2009 05:00 AM 37569 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030280.bat

c:\32788r22fwjfw\Catch-sub.cmd
08/31/2000 08:00 AM 663 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030281.cmd

c:\32788r22fwjfw\CF-Script.cmd
04/29/2009 12:01 AM 20959 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030282.cmd

c:\32788r22fwjfw\CHCP.bat
04/28/2009 09:28 PM 16 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030283.bat

08/31/2000 08:00 AM 1024 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030284.sys

c:\32788r22fwjfw\Combobatch.bat
04/24/2009 11:02 PM 7469 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030285.bat

c:\32788r22fwjfw\Create.cmd
04/28/2009 04:00 PM 6112 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030286.cmd

c:\32788r22fwjfw\CregC.cmd
04/24/2009 11:07 PM 3310 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030287.cmd

c:\32788r22fwjfw\CSet.cmd
04/24/2009 10:57 PM 1702 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030288.cmd

c:\32788r22fwjfw\DelClsid.bat
04/24/2009 10:57 PM 1770 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030289.bat

c:\32788r22fwjfw\Exe.reg
08/31/2000 08:00 AM 7236 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030290.reg

c:\32788r22fwjfw\FD-SV.cmd
04/24/2009 11:07 PM 1370 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030291.cmd

c:\32788r22fwjfw\ffdefstr.dll
08/31/2000 08:00 AM 36201 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030292.dll

c:\32788r22fwjfw\files.pif
04/29/2009 05:00 AM 2183 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030293.pif

c:\32788r22fwjfw\FIND3M.bat
04/29/2009 12:11 AM 26608 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030294.bat

c:\32788r22fwjfw\FIXLSP.bat
04/24/2009 11:07 PM 3946 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030295.bat

c:\32788r22fwjfw\FKMGen.cmd
04/24/2009 11:04 PM 1023 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030296.cmd

c:\32788r22fwjfw\FProps.vbs
08/31/2000 08:00 AM 15388 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030297.vbs

c:\32788r22fwjfw\GetHive.cmd
04/28/2009 12:11 AM 4896 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030298.cmd

c:\32788r22fwjfw\hidec.exe
08/16/2005 01:54 AM 1536 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030299.exe

c:\32788r22fwjfw\history.bat
04/24/2009 10:57 PM 823 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030300.bat

c:\32788r22fwjfw\Install-RC.cmd
04/24/2009 11:07 PM 5676 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030301.cmd

c:\32788r22fwjfw\katch.cmd
08/31/2000 08:00 AM 754 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030302.cmd

c:\32788r22fwjfw\Kill-All.cmd
04/24/2009 11:05 PM 1589 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030303.cmd

c:\32788r22fwjfw\Kollect.bat
04/24/2009 11:07 PM 3253 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030304.bat

c:\32788r22fwjfw\Lang.bat
04/24/2009 11:07 PM 157648 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030305.bat

c:\32788r22fwjfw\List-B.bat
04/28/2009 01:08 AM 28787 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030306.bat

c:\32788r22fwjfw\List-C.bat
04/29/2009 01:57 AM 202141 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030307.bat

c:\32788r22fwjfw\List-D.bat
04/24/2009 11:07 PM 91483 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030308.bat

c:\32788r22fwjfw\List.bat
04/28/2009 01:11 AM 540197 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030309.bat

c:\32788r22fwjfw\lnkread.vbs
08/31/2000 08:00 AM 2428 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030310.vbs

c:\32788r22fwjfw\md5sum.pif
04/29/2009 05:00 AM 4658 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030311.pif

c:\32788r22fwjfw\MoveIt.bat
08/31/2000 08:00 AM 2328 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030312.bat

c:\32788r22fwjfw\n.com
08/31/2000 08:00 AM 29696 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030313.com

c:\32788r22fwjfw\ND_.bat
04/24/2009 11:07 PM 6029 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030314.bat

c:\32788r22fwjfw\Nircmd.com
08/31/2000 08:00 AM 29696 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030315.com

c:\32788r22fwjfw\NT-OS.cmd
04/29/2009 05:00 AM 10637 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030316.cmd

c:\32788r22fwjfw\OSid.vbs
08/31/2000 08:00 AM 977 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030317.vbs

c:\32788r22fwjfw\pev.exe
04/28/2009 01:28 AM 113152 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030318.exe

c:\32788r22fwjfw\Prep.cmd
04/28/2009 02:14 AM 11303 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030319.cmd

c:\32788r22fwjfw\RegScan.cmd
04/28/2009 04:21 PM 49906 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030321.cmd

c:\32788r22fwjfw\restore_pt.vbs
08/31/2000 08:00 AM 232 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030323.vbs

c:\32788r22fwjfw\RestoreO4.bat
04/24/2009 11:07 PM 1773 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030322.bat

c:\32788r22fwjfw\Rkey.cmd
08/31/2000 08:00 AM 241 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030324.cmd

c:\32788r22fwjfw\SafeBootRepair.bat
04/24/2009 11:07 PM 15360 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030325.bat

c:\32788r22fwjfw\SetEnvmt.bat
04/24/2009 11:07 PM 12666 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030326.bat

c:\32788r22fwjfw\sfx.cmd
04/28/2009 09:28 PM 14 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030327.cmd

c:\32788r22fwjfw\SnapShot.cmd
04/28/2009 05:04 AM 3342 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030328.cmd

c:\32788r22fwjfw\SRestore.cmd
04/24/2009 11:07 PM 2140 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030329.cmd

c:\32788r22fwjfw\SuppScan.cmd
04/24/2009 11:07 PM 17752 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030330.cmd

c:\32788r22fwjfw\SvcDrv.vbs
08/31/2000 08:00 AM 2176 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030331.vbs

c:\32788r22fwjfw\Update-CF.cmd
04/24/2009 11:07 PM 2743 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030333.cmd

C:\BHCA.exe
03/03/2009 03:36 PM 242536 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030039.exe

C:\cltLMJ.dll
02/27/2009 04:02 AM 890248 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030058.dll

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
12/26/2008 01:04 PM 791920 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030207.dll

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090331.007\IDSviA64.sys
01/29/2009 02:50 PM 396848 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP2\A0020706.sys

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090331.007\IDSvix86.sys
01/29/2009 02:50 PM 292912 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP2\A0020709.sys

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090331.007\IDSxpx86.dll
01/29/2009 02:50 PM 447864 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP2\A0020710.dll

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090331.007\IDSXpx86.sys
01/29/2009 02:50 PM 276344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP2\A0020711.sys

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090331.007\Scxpx86.dll
03/16/2009 01:03 PM 533880 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP2\A0020712.dll

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090408.002\IDSviA64.sys
01/29/2009 02:50 PM 396848 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028949.sys

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090408.002\IDSvix86.sys
01/29/2009 02:50 PM 292912 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028952.sys

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090408.002\IDSxpx86.dll
01/29/2009 02:50 PM 447864 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028953.dll

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090408.002\IDSXpx86.sys
01/29/2009 02:50 PM 276344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028954.sys

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090408.002\Scxpx86.dll
03/16/2009 01:03 PM 533880 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028955.dll

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090414.001\IDSviA64.sys
01/29/2009 02:50 PM 396848 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030210.sys

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090414.001\IDSvix86.sys
01/29/2009 02:50 PM 292912 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030213.sys

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090414.001\IDSxpx86.dll
01/29/2009 02:50 PM 447864 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030214.dll

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090414.001\IDSXpx86.sys
01/29/2009 02:50 PM 276344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030215.sys

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090414.001\Scxpx86.dll
03/16/2009 01:03 PM 533880 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030216.dll

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090420.001\IDSviA64.sys
01/29/2009 02:50 PM 396848 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030219.sys

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090420.001\IDSvix86.sys
01/29/2009 02:50 PM 292912 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030222.sys

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090420.001\IDSxpx86.dll
01/29/2009 02:50 PM 447864 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030223.dll

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090420.001\IDSXpx86.sys
01/29/2009 02:50 PM 276344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030224.sys

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090420.001\Scxpx86.dll
03/16/2009 01:03 PM 533880 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030225.dll

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvia64.sys
01/29/2009 02:50 PM 396848 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030228.sys

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvix86.sys
01/29/2009 02:50 PM 292912 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030231.sys

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSxpx86.dll
01/29/2009 02:50 PM 447864 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030232.dll

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSxpx86.sys
01/29/2009 02:50 PM 276344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030233.sys

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\Scxpx86.dll
03/16/2009 01:03 PM 533880 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030234.dll

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
02/27/2009 04:02 AM 165240 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0000008.dll
02/27/2009 04:02 AM 165240 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030240.dll

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
12/26/2008 01:04 PM 136840 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030243.dll

c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
12/05/2008 02:52 AM 1290584 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030244.dll

04/28/2009 11:16 PM 117760 c:\documents and settings\New-April\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
04/20/2009 09:44 AM 117760 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0021734.DLL
04/20/2009 03:50 PM 117760 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030501.DLL

C:\FE024541.dll
09/20/2006 06:02 AM 593920 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010104.dll
09/20/2006 06:02 AM 593920 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010104.dll

C:\NAVPInst.dll
02/27/2009 04:02 AM 51056 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030101.dll

c:\program files\Alwil Software\Avast4\Aavm4h.dll
02/05/2009 01:05 PM 225280 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028795.dll

c:\program files\Alwil Software\Avast4\AavmGuih.dll
02/05/2009 01:08 PM 188416 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028796.dll

c:\program files\Alwil Software\Avast4\AavmRpch.dll
02/05/2009 01:05 PM 20992 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028797.dll

c:\program files\Alwil Software\Avast4\AhResMai.dll
02/05/2009 01:05 PM 35840 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028798.dll

c:\program files\Alwil Software\Avast4\ahResMes.dll
02/05/2009 01:06 PM 32768 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028799.dll

c:\program files\Alwil Software\Avast4\AhResNS.dll
02/05/2009 01:06 PM 35840 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028800.dll

c:\program files\Alwil Software\Avast4\AhResOut.dll
02/05/2009 01:08 PM 29696 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028801.dll

c:\program files\Alwil Software\Avast4\ahResP2P.dll
02/05/2009 01:06 PM 33280 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028802.dll

c:\program files\Alwil Software\Avast4\AhResStd.dll
02/05/2009 01:09 PM 43008 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028803.dll

c:\program files\Alwil Software\Avast4\AhResWS.dll
02/05/2009 01:05 PM 53248 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028804.dll

c:\program files\Alwil Software\Avast4\AhRuiMai.dll
02/05/2009 01:07 PM 94208 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028805.dll

c:\program files\Alwil Software\Avast4\ahRuiMes.dll
02/05/2009 01:06 PM 57344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028806.dll

c:\program files\Alwil Software\Avast4\AhRuiNS.dll
02/05/2009 01:06 PM 57344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028807.dll

c:\program files\Alwil Software\Avast4\AhRuiOut.dll
02/05/2009 01:08 PM 118784 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028808.dll

c:\program files\Alwil Software\Avast4\ahRuiP2P.dll
02/05/2009 01:06 PM 22528 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028809.dll

c:\program files\Alwil Software\Avast4\AhRuiStd.dll
02/05/2009 01:09 PM 57344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028810.dll

c:\program files\Alwil Software\Avast4\AhRuiWS.dll
02/05/2009 01:05 PM 49152 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028811.dll

c:\program files\Alwil Software\Avast4\ashAvast.exe
02/05/2009 01:03 PM 274640 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028812.exe

c:\program files\Alwil Software\Avast4\ashBase.dll
02/05/2009 01:00 PM 225280 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028813.dll

c:\program files\Alwil Software\Avast4\ashBug.exe
02/05/2009 01:03 PM 130440 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028814.exe

c:\program files\Alwil Software\Avast4\ashCfgP.dll
02/05/2009 01:03 PM 98304 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028815.dll

c:\program files\Alwil Software\Avast4\ashCfgT.dll
02/05/2009 01:02 PM 131072 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028816.dll

c:\program files\Alwil Software\Avast4\ashChest.dll
02/05/2009 01:02 PM 151552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028817.dll

c:\program files\Alwil Software\Avast4\ashChest.exe
02/05/2009 01:03 PM 68640 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028818.exe

c:\program files\Alwil Software\Avast4\ashCnsnt.exe
02/05/2009 01:04 PM 39872 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028819.exe

c:\program files\Alwil Software\Avast4\ashDisp.exe
02/05/2009 01:08 PM 81000 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028820.exe

c:\program files\Alwil Software\Avast4\ashLogV.exe
02/05/2009 01:03 PM 50184 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028821.exe

c:\program files\Alwil Software\Avast4\ashMaiSv.exe
02/05/2009 01:08 PM 254040 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028822.exe

c:\program files\Alwil Software\Avast4\ashOutXt.dll
02/05/2009 01:08 PM 204600 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028823.dll

c:\program files\Alwil Software\Avast4\ashPopWz.exe
02/05/2009 01:08 PM 208720 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028824.exe

c:\program files\Alwil Software\Avast4\ashQuick.exe
02/05/2009 01:04 PM 262280 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028825.exe

c:\program files\Alwil Software\Avast4\ashServ.exe
02/05/2009 01:08 PM 138680 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028826.exe

c:\program files\Alwil Software\Avast4\ashShA64.dll
02/05/2009 01:13 PM 81072 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028827.dll

c:\program files\Alwil Software\Avast4\ashShell.dll
02/05/2009 01:04 PM 76880 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028901.dll

c:\program files\Alwil Software\Avast4\ashSimp2.exe
02/05/2009 01:03 PM 126320 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028828.exe

c:\program files\Alwil Software\Avast4\ashSimpl.exe
02/05/2009 01:04 PM 159280 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028829.exe

c:\program files\Alwil Software\Avast4\ashSkPcc.exe
02/05/2009 01:03 PM 17920 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028830.exe

c:\program files\Alwil Software\Avast4\ashSkPck.exe
02/05/2009 01:04 PM 61440 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028831.exe

c:\program files\Alwil Software\Avast4\ashSODBC.dll
02/05/2009 01:00 PM 53248 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028832.dll

c:\program files\Alwil Software\Avast4\ashSSqlt.dll
02/05/2009 01:01 PM 233472 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028833.dll

c:\program files\Alwil Software\Avast4\ashSXML.dll
02/05/2009 01:01 PM 48128 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028834.dll

c:\program files\Alwil Software\Avast4\ashTask.dll
02/05/2009 01:00 PM 118784 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028835.dll

c:\program files\Alwil Software\Avast4\ashUInt.dll
02/05/2009 01:02 PM 331776 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028836.dll

c:\program files\Alwil Software\Avast4\ashUpd.exe
02/05/2009 01:01 PM 52160 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028837.exe

c:\program files\Alwil Software\Avast4\ashWebSv.exe
02/05/2009 01:06 PM 352920 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028838.exe

c:\program files\Alwil Software\Avast4\ashWsFtr.dll
02/05/2009 01:06 PM 49152 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028839.dll

c:\program files\Alwil Software\Avast4\aswAux.dll
02/05/2009 01:00 PM 659456 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028840.dll

c:\program files\Alwil Software\Avast4\aswChLic.exe
02/02/2009 02:42 PM 31552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028841.exe

c:\program files\Alwil Software\Avast4\aswCmnB.dll
02/05/2009 12:58 PM 131072 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028842.dll

c:\program files\Alwil Software\Avast4\aswCmnOS.dll
02/05/2009 12:58 PM 86016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028843.dll

c:\program files\Alwil Software\Avast4\aswCmnS.dll
02/05/2009 12:58 PM 192512 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028844.dll

c:\program files\Alwil Software\Avast4\aswEngin.dll
02/05/2009 01:00 PM 1302528 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028845.dll

c:\program files\Alwil Software\Avast4\aswIdle.dll
02/05/2009 01:01 PM 11584 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028846.dll

c:\program files\Alwil Software\Avast4\aswInteg.dll
02/05/2009 01:00 PM 23040 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028847.dll

c:\program files\Alwil Software\Avast4\aswMonDS.sys
10/06/2008 02:48 AM 706 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028848.sys

c:\program files\Alwil Software\Avast4\aswMonVD.dll
03/05/2005 08:16 AM 3452 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028849.dll

c:\program files\Alwil Software\Avast4\aswRawFS.dll
02/05/2009 12:58 PM 327680 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028850.dll

c:\program files\Alwil Software\Avast4\aswRegSvr.exe
09/16/2003 05:27 AM 22016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028851.exe

c:\program files\Alwil Software\Avast4\aswRes.dll
02/05/2009 12:58 PM 147456 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028852.dll

c:\program files\Alwil Software\Avast4\aswRunDll.exe
07/18/2008 04:38 AM 90296 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028853.exe

c:\program files\Alwil Software\Avast4\aswScan.dll
02/05/2009 12:59 PM 86016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028854.dll

c:\program files\Alwil Software\Avast4\aswUpdSv.exe
02/05/2009 01:01 PM 18752 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028855.exe

c:\program files\Alwil Software\Avast4\AVASTSS.scr
02/05/2009 01:04 PM 97480 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028856.scr

c:\program files\Alwil Software\Avast4\avCommEx.dll
02/05/2009 01:06 PM 106496 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028857.dll

c:\program files\Alwil Software\Avast4\AVSSHOOK.dll
02/05/2009 01:02 PM 13656 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028858.dll

c:\program files\Alwil Software\Avast4\DATA\aswar0.dll
04/21/2009 08:56 AM 365280 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028859.dll

c:\program files\Alwil Software\Avast4\DATA\clnr0.dll
04/21/2009 08:56 AM 391216 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028860.dll

c:\program files\Alwil Software\Avast4\DATA\exts0.dll
04/21/2009 08:56 AM 9080 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028861.dll

c:\program files\Alwil Software\Avast4\DATA\uiaux0.dll
04/21/2009 08:56 AM 1354080 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028862.dll

c:\program files\Alwil Software\Avast4\ENGLISH\Base.dll
02/05/2009 12:58 PM 61440 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028863.dll

c:\program files\Alwil Software\Avast4\ENGLISH\Boot.dll
02/05/2009 12:56 PM 15360 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028864.dll

c:\program files\Alwil Software\Avast4\ENGLISH\Lang.dll
02/05/2009 12:58 PM 2531328 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028865.dll

c:\program files\Alwil Software\Avast4\ENGLISH\LangMai.dll
02/05/2009 12:58 PM 57344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028866.dll

c:\program files\Alwil Software\Avast4\sched.exe
02/05/2009 01:11 PM 52160 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028867.exe

c:\program files\Alwil Software\Avast4\Setup\INF\Aavmker4.sys
02/05/2009 01:05 PM 26944 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028869.sys

c:\program files\Alwil Software\Avast4\Setup\INF\AMD64\Aavmker4.sys
02/05/2009 01:05 PM 25168 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028870.sys

c:\program files\Alwil Software\Avast4\Setup\INF\AMD64\aswFsBlk.sys
02/05/2009 01:07 PM 22096 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028871.sys

c:\program files\Alwil Software\Avast4\Setup\INF\AMD64\aswMem64.exe
02/05/2009 01:13 PM 98064 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028872.exe

c:\program files\Alwil Software\Avast4\Setup\INF\AMD64\aswMon2.sys
02/05/2009 01:08 PM 75856 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028873.sys

c:\program files\Alwil Software\Avast4\Setup\INF\AMD64\aswMonFlt.sys
02/05/2009 01:07 PM 64592 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028874.sys

c:\program files\Alwil Software\Avast4\Setup\INF\AMD64\aswRdr.sys
02/05/2009 01:06 PM 27216 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028875.sys

c:\program files\Alwil Software\Avast4\Setup\INF\AMD64\aswSP.sys
02/05/2009 01:07 PM 89680 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028876.sys

c:\program files\Alwil Software\Avast4\Setup\INF\AMD64\aswTdi.sys
02/05/2009 01:06 PM 58448 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028877.sys

c:\program files\Alwil Software\Avast4\Setup\INF\aswFsBlk.sys
02/05/2009 01:07 PM 20560 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028879.sys

c:\program files\Alwil Software\Avast4\Setup\INF\aswMon.sys
02/05/2009 01:08 PM 93296 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028880.sys

c:\program files\Alwil Software\Avast4\Setup\INF\aswMon2.sys
02/05/2009 01:08 PM 94032 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028882.sys

c:\program files\Alwil Software\Avast4\Setup\INF\aswMonFlt.sys
02/05/2009 01:06 PM 51792 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028884.sys

c:\program files\Alwil Software\Avast4\Setup\INF\AswRdr.sys
02/05/2009 01:06 PM 23152 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028885.sys

c:\program files\Alwil Software\Avast4\Setup\INF\aswSP.sys
02/05/2009 01:07 PM 114768 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028886.sys

c:\program files\Alwil Software\Avast4\Setup\INF\AswTdi.sys
02/05/2009 01:06 PM 51376 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028887.sys

c:\program files\Alwil Software\Avast4\Setup\INF\IA64\aswFsBlk.sys
02/05/2009 01:07 PM 37968 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028888.sys

c:\program files\Alwil Software\Avast4\Setup\INF\IA64\aswMonFlt.sys
02/05/2009 01:07 PM 139344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028889.sys

c:\program files\Alwil Software\Avast4\Setup\INF\IA64\aswRdr.sys
02/05/2009 01:06 PM 55376 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028890.sys

c:\program files\Alwil Software\Avast4\Setup\INF\IA64\aswSP.sys
02/05/2009 01:07 PM 169040 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028891.sys

c:\program files\Alwil Software\Avast4\Setup\INF\IA64\aswTdi.sys
02/05/2009 01:06 PM 127568 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028892.sys

c:\program files\Alwil Software\Avast4\Setup\setiface.dll
04/21/2009 08:27 AM 159792 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028893.dll

c:\program files\Alwil Software\Avast4\VisthAux.exe
02/05/2009 01:03 PM 52160 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028895.exe

c:\program files\Alwil Software\Avast4\VisthLic.exe
02/05/2009 01:03 PM 38848 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028896.exe

c:\program files\Alwil Software\Avast4\VisthUpd.exe
02/05/2009 01:03 PM 38848 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028897.exe

c:\program files\Alwil Software\Avast4\wdp-ash-updscript.vbs
03/22/2006 10:43 AM 1159 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028898.vbs

c:\program files\Alwil Software\Avast4\XT1922.dll
02/05/2009 01:02 PM 917504 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028899.dll

c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll
12/02/2002 01:33 PM 57344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010652.dll

c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
12/02/2002 03:22 PM 5632 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010649.exe

c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll
04/14/2009 11:45 AM 163972 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010650.dll

c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll
02/27/2003 04:12 PM 696320 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010655.dll

c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll
12/02/2002 01:33 PM 237568 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010653.dll

c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll
12/05/2002 02:10 PM 155648 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010651.dll

c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll
04/14/2009 11:45 AM 282756 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010654.dll

03/03/2009 12:03 PM 371248 c:\program files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
03/03/2009 12:03 PM 371248 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0016680.sys

03/03/2009 12:03 PM 101936 c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
03/03/2009 12:03 PM 101936 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0014678.sys

c:\program files\Common Files\Symantec Shared\SEVINST.EXE
02/27/2009 04:02 AM 828808 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030022.EXE

c:\program files\FinePixViewer\borlndmm.dll
03/08/2000 10:00 AM 25600 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010360.dll

c:\program files\FinePixViewer\cc3250mt.dll
03/08/2000 10:00 AM 1496064 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010359.dll

c:\program files\FinePixViewer\download.exe
11/30/2002 06:23 PM 57344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010358.exe

c:\program files\FinePixViewer\DPEditor2.exe
08/29/2006 11:30 AM 1847296 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010357.exe

c:\program files\FinePixViewer\Exif.dll
06/09/2004 07:17 AM 536576 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010356.dll

c:\program files\FinePixViewer\Extensions\Helpers\ColorAdjust.dll
06/29/2006 11:34 AM 90112 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010156.dll

c:\program files\FinePixViewer\Extensions\Helpers\Exif.dll
06/08/2004 01:17 PM 536576 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010178.dll

c:\program files\FinePixViewer\Extensions\Helpers\Exifcrsw.exe
08/09/2006 05:14 PM 69632 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010177.exe

c:\program files\FinePixViewer\Extensions\Helpers\FFTIFF16.dll
03/17/2005 10:31 AM 274432 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010075.dll

c:\program files\FinePixViewer\Extensions\Helpers\FinePix Studio.EXE
12/09/2006 02:37 AM 356352 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010155.EXE

c:\program files\FinePixViewer\Extensions\Helpers\FXHBCLib.dll
06/19/2003 11:58 PM 49152 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010176.dll

c:\program files\FinePixViewer\Extensions\Helpers\FXMJPLib.dll
11/22/2003 12:11 AM 258048 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010175.dll

c:\program files\FinePixViewer\Extensions\Helpers\FxMovieEffectHelper.exe
11/23/2003 04:00 AM 413696 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010174.exe

c:\program files\FinePixViewer\Extensions\Helpers\HUContainer.dll
12/22/2006 09:52 AM 516096 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010154.dll

c:\program files\FinePixViewer\Extensions\Helpers\IMXLauncher.exe
12/25/2004 03:03 AM 237568 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010160.exe

c:\program files\FinePixViewer\Extensions\Helpers\JPEGWriter.exe
12/20/2006 05:00 PM 106496 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010173.exe

c:\program files\FinePixViewer\Extensions\Helpers\jw_ptp_utility_usbscan.dll
12/20/2006 10:12 PM 143360 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010172.dll

c:\program files\FinePixViewer\Extensions\Helpers\jw_ptp_utility_wia.dll
01/11/2007 04:43 PM 126976 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010171.dll

c:\program files\FinePixViewer\Extensions\Helpers\mfc42.dll
06/20/2003 04:05 AM 1015859 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010074.dll

c:\program files\FinePixViewer\Extensions\Helpers\MotionComposition.dll
06/29/2003 11:23 AM 589905 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010170.dll

c:\program files\FinePixViewer\Extensions\Helpers\MotionComposition_R1.dll
06/29/2003 11:23 AM 188503 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010169.dll

c:\program files\FinePixViewer\Extensions\Helpers\MotionPrint.exe
08/14/2006 11:20 AM 3919872 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010168.exe

c:\program files\FinePixViewer\Extensions\Helpers\msvcrt.dll
06/20/2003 04:05 AM 286773 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010073.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\EditPlugin.dll
12/22/2006 12:14 PM 258048 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010123.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\PIR030RAF\Lfcmp12n.dll
03/09/2001 06:00 PM 314368 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010107.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\PIR030RAF\Ltfil12n.dll
03/09/2001 06:00 PM 121344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010106.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\PIR030RAF\Ltkrn12n.dll
03/09/2001 06:00 PM 406016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010105.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FE024541.dll
09/20/2006 06:02 AM 593920 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010104.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FE05DA0D.dll
09/20/2006 06:02 AM 786432 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010103.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FE05EFED.dll
09/20/2006 06:02 AM 655360 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010102.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FE05F051.dll
09/20/2006 06:02 AM 565248 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010101.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FE05F17D.dll
09/20/2006 06:02 AM 622592 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010100.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FE05F3D5.dll
09/20/2006 06:02 AM 565248 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010099.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FE05F3D6.dll
09/20/2006 06:02 AM 618496 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010098.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FE05F3D7.dll
09/20/2006 06:02 AM 569344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010097.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FE05FB41.dll
09/20/2006 06:02 AM 1060864 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010096.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FE05FB42.dll
09/20/2006 06:02 AM 1048576 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010095.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FFTbl.dll
09/20/2006 06:02 AM 167936 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010094.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG024541.dll
09/20/2006 06:02 AM 86016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010093.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG05DA0D.dll
09/20/2006 06:02 AM 86016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010092.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG05EFED.dll
09/20/2006 06:02 AM 86016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010091.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG05F051.dll
09/20/2006 06:02 AM 86016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010090.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG05F17D.dll
09/20/2006 06:02 AM 86016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010089.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG05F245.dll
09/20/2006 06:02 AM 1335296 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010088.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG05F3D5.dll
09/20/2006 06:02 AM 86016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010087.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG05F3D6.dll
09/20/2006 06:02 AM 86016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010086.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG05F3D7.dll
09/20/2006 06:02 AM 86016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010085.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG05FB41.dll
09/20/2006 06:02 AM 86016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010084.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG05FB42.dll
09/20/2006 06:02 AM 86016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010083.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG05FC09.dll
12/21/2006 05:24 AM 1458176 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010082.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG05FC0B.dll
12/21/2006 05:24 AM 1433600 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010081.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG05FF29.dll
09/20/2006 06:02 AM 1175552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010080.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG05FF8D.dll
09/20/2006 06:02 AM 1150976 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010079.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG05FF8E.dll
07/23/2006 05:56 AM 1150976 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010078.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\library\RAFCNV\FG05FF8F.dll
09/20/2006 06:02 AM 1175552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010077.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\PIR020EXT.dll
07/07/2006 06:54 PM 147456 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010122.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\PIR025TIF.dll
07/07/2006 08:15 PM 290816 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010121.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\PIR030RAF.dll
07/07/2006 06:49 PM 167936 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010120.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\PIR050BMP.dll
06/15/2006 12:46 AM 32768 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010119.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\PIW010BMP.dll
06/15/2006 12:46 AM 40960 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010118.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\PIW050EJF.dll
07/07/2006 07:40 PM 151552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010117.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\PIW060EJN.dll
07/07/2006 07:40 PM 151552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010116.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\PIW070EJB.dll
07/07/2006 07:40 PM 151552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010115.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\PIW100ET.dll
07/07/2006 08:03 PM 139264 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010114.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\PIW150EAF.dll
07/07/2006 07:41 PM 151552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010113.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\PIW160EAN.dll
07/07/2006 07:41 PM 151552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010112.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\PIW170EAB.dll
07/07/2006 07:41 PM 151552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010111.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\PIW20016S.dll
07/07/2006 08:00 PM 94208 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010110.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\PIW21016A.dll
07/07/2006 08:00 PM 94208 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010109.dll

c:\program files\FinePixViewer\Extensions\Helpers\Plugins\PIW22016F.dll
07/07/2006 08:00 PM 94208 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010108.dll

c:\program files\FinePixViewer\Extensions\Helpers\RESOURCE\ICXRes.dll
11/19/2006 11:01 PM 155648 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010076.dll

c:\program files\FinePixViewer\fgmlapi.dll
12/06/2005 11:12 PM 86016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010355.dll

c:\program files\FinePixViewer\fgsrapi.dll
12/21/2005 10:18 PM 53248 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010354.dll

c:\program files\FinePixViewer\FinePixViewer.exe
12/22/2006 10:03 PM 1089536 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010353.exe

c:\program files\FinePixViewer\fpv4folder.dll
09/17/2006 06:21 PM 69632 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010352.dll

c:\program files\FinePixViewer\fpv4layoutdb.dll
11/30/2004 10:58 PM 32768 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010351.dll

c:\program files\FinePixViewer\fpv4mailto.dll
03/06/2003 05:42 PM 24576 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010350.dll

c:\program files\FinePixViewer\fpv4print.exe
10/23/2006 08:15 AM 4509696 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010349.exe

c:\program files\FinePixViewer\FSA04cb2k.dll
12/14/2006 11:45 PM 45056 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010348.dll

c:\program files\FinePixViewer\FSA04cb98.dll
12/13/2006 10:23 AM 57344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010347.dll

c:\program files\FinePixViewer\FXMJPLib.dll
11/21/2003 03:11 PM 258048 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010346.dll

c:\program files\FinePixViewer\GF2RSIZE.DLL
03/30/2002 01:26 AM 299008 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010345.DLL

c:\program files\FinePixViewer\gfnapapi.dll
12/12/2001 04:36 PM 530944 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010344.dll

c:\program files\FinePixViewer\gfnp2bc.dll
07/29/2001 05:03 PM 13312 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010341.dll

c:\program files\FinePixViewer\gfnp2lib.dll
07/29/2001 06:01 PM 24576 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010340.dll

c:\program files\FinePixViewer\ibmxmlbc.dll
07/29/2001 03:50 AM 1512960 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010339.dll

c:\program files\FinePixViewer\INSTALLGUIDE\APInit.exe
07/26/2003 10:13 PM 53248 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010182.exe

c:\program files\FinePixViewer\INSTALLGUIDE\DXInstaller.exe
06/02/2005 02:41 AM 49152 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010181.exe

c:\program files\FinePixViewer\INSTALLGUIDE\InstallGuide5.exe
11/14/2006 06:48 PM 1015808 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010167.exe

c:\program files\FinePixViewer\INSTALLGUIDE\msvbvm60.dll
05/27/2000 09:10 AM 1388544 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010179.dll

c:\program files\FinePixViewer\Lfbmp12n.dll
06/30/2003 09:00 AM 30720 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010338.dll

c:\program files\FinePixViewer\Lfcmp12n.dll
06/30/2003 09:00 AM 358912 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010337.dll

c:\program files\FinePixViewer\Lffax12n.dll
06/30/2003 09:00 AM 73728 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010336.dll

c:\program files\FinePixViewer\Lflmb12n.dll
06/30/2003 09:00 AM 31744 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010335.dll

c:\program files\FinePixViewer\Lfpcx12n.dll
06/30/2003 09:00 AM 26112 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010334.dll

c:\program files\FinePixViewer\Lftif12n.dll
06/30/2003 09:00 AM 141312 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010333.dll

c:\program files\FinePixViewer\libeay32.dll
06/23/2001 11:23 PM 708608 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010332.dll

c:\program files\FinePixViewer\Ltdis12n.dll
06/30/2003 09:00 AM 259584 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010331.dll

c:\program files\FinePixViewer\Ltefx12n.dll
06/30/2003 09:00 AM 208384 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010330.dll

c:\program files\FinePixViewer\Ltfil12n.dll
06/30/2003 09:00 AM 131072 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010329.dll

c:\program files\FinePixViewer\Ltimg12n.dll
06/30/2003 09:00 AM 164864 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010328.dll

c:\program files\FinePixViewer\Ltkrn12n.dll
06/30/2003 09:00 AM 406016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010327.dll

c:\program files\FinePixViewer\Lttwn12n.dll
06/30/2003 09:00 AM 35840 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010326.dll

c:\program files\FinePixViewer\Ltwnd12n.dll
06/30/2003 09:00 AM 30208 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010325.dll

c:\program files\FinePixViewer\NETINFapi.dll
01/25/2005 02:46 AM 200704 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010324.dll

c:\program files\FinePixViewer\OPSwitch.exe
01/28/2005 07:38 PM 155648 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010323.exe

c:\program files\FinePixViewer\OrderSoft\Exif.dll
11/17/2005 01:30 AM 532480 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010307.dll

c:\program files\FinePixViewer\OrderSoft\FFSOLib.dll
03/04/2006 07:12 PM 1273919 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010306.dll

c:\program files\FinePixViewer\OrderSoft\FOS.exe
03/04/2006 07:12 PM 1622016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010304.exe

c:\program files\FinePixViewer\OrderSoft\FWHook.dll
03/04/2006 07:12 PM 503808 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010303.dll

c:\program files\FinePixViewer\OrderSoft\libeay32.dll
11/17/2005 01:30 AM 843776 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010302.dll

c:\program files\FinePixViewer\OrderSoft\NWSetup.exe
03/04/2006 07:12 PM 180224 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010298.exe

c:\program files\FinePixViewer\OrderSoft\ssleay32.dll
11/17/2005 01:30 AM 159744 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010297.dll

c:\program files\FinePixViewer\OrderSoft\xerces-c_2_5_0.dll
11/17/2005 01:30 AM 2547712 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010296.dll

c:\program files\FinePixViewer\ptp_util_usbscan.dll
12/01/2006 03:29 PM 94208 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010321.dll

c:\program files\FinePixViewer\PTPBRIDGE.exe
03/22/2006 04:57 PM 15360 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010322.exe

c:\program files\FinePixViewer\QuickDCF2.exe
12/04/2006 04:27 PM 303104 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010320.exe

c:\program files\FinePixViewer\REREDUCT.DLL
12/03/2002 04:07 AM 155648 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010319.DLL

c:\program files\FinePixViewer\Resource\Services\30000\Register.dll
04/07/2005 01:08 AM 90112 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010166.dll

c:\program files\FinePixViewer\Resource\Services\30000\RegisterRes.dll
01/13/2005 02:27 AM 483328 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010165.dll

c:\program files\FinePixViewer\ShowContents.dll
12/21/2004 01:02 PM 77824 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010318.dll

c:\program files\FinePixViewer\ssleay32.dll
06/23/2001 11:24 PM 147456 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010317.dll

c:\program files\FinePixViewer\System\add_bookmark.dll
06/27/2006 04:38 PM 69632 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010294.dll

c:\program files\FinePixViewer\System\Adjust.dll
12/01/2006 06:34 PM 4313088 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010293.dll

c:\program files\FinePixViewer\System\AdjustRes.dll
09/20/2005 06:56 PM 167936 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010292.dll

c:\program files\FinePixViewer\System\AutoCaptureSetting.dll
12/12/2006 06:58 PM 143360 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010291.dll

c:\program files\FinePixViewer\System\AutoFormat.dll
12/01/2006 06:34 PM 466944 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010290.dll

c:\program files\FinePixViewer\System\AutoFormat_res.dll
09/20/2005 06:54 PM 4608 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010289.dll

c:\program files\FinePixViewer\System\AutoResize.dll
12/15/2006 06:39 PM 458752 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010288.dll

c:\program files\FinePixViewer\System\AutoResize_res.dll
09/20/2005 06:54 PM 5120 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010287.dll

c:\program files\FinePixViewer\System\AutoRotate_res.dll
10/04/2006 07:40 PM 10240 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010286.dll

c:\program files\FinePixViewer\System\ChangeInfo.dll
10/31/2006 11:29 AM 405504 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010285.dll

c:\program files\FinePixViewer\System\ChangeInfo_res.dll
09/20/2005 06:54 PM 4608 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010284.dll

c:\program files\FinePixViewer\System\CutText.dll
12/01/2006 06:33 PM 385024 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010283.dll

c:\program files\FinePixViewer\System\CutTextRes.dll
09/20/2005 06:56 PM 90112 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010282.dll

c:\program files\FinePixViewer\System\dc_setting.dll
06/27/2006 04:37 PM 73728 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010281.dll

c:\program files\FinePixViewer\System\dc_setting_res.dll
02/28/2006 01:14 PM 2560 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010280.dll

c:\program files\FinePixViewer\System\DivideFolder.dll
12/01/2006 06:33 PM 69632 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010279.dll

c:\program files\FinePixViewer\System\DivideFolder_res.dll
09/20/2005 06:54 PM 3072 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010278.dll

c:\program files\FinePixViewer\System\DPOFWizard.dll
12/20/2006 02:45 PM 4755456 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010277.dll

c:\program files\FinePixViewer\System\DPOFWizard_res.dll
06/14/2005 07:41 AM 3584000 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010276.dll

c:\program files\FinePixViewer\System\edit_bookmark.dll
06/27/2006 04:36 PM 94208 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010275.dll

c:\program files\FinePixViewer\System\edit_bookmark_res.dll
01/12/2005 01:11 PM 2048 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010274.dll

c:\program files\FinePixViewer\System\FaceDetect\iFaceDetect.dll
09/30/2004 09:00 AM 94208 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010195.dll

c:\program files\FinePixViewer\System\fc_AutoCapture.dll
12/15/2006 09:50 PM 4866048 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010273.dll

c:\program files\FinePixViewer\System\fc_AutoCaptureDS.dll
12/15/2006 09:51 PM 4866048 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010272.dll

c:\program files\FinePixViewer\System\fc_AutoCapturePM.dll
12/15/2006 09:50 PM 4866048 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010271.dll

c:\program files\FinePixViewer\System\fc_AutoCaptureResource.dll
05/01/2006 08:39 PM 3092480 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010270.dll

c:\program files\FinePixViewer\System\fc_AutoRename.dll
12/12/2006 06:58 PM 184320 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010269.dll

c:\program files\FinePixViewer\System\fc_AutoRenameResource.dll
01/17/2005 05:57 PM 69632 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010268.dll

c:\program files\FinePixViewer\System\fc_AutoRotate.dll
12/15/2006 06:40 PM 159744 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010267.dll

c:\program files\FinePixViewer\System\fc_AutoRotateResource.dll
09/20/2005 06:53 PM 10240 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010266.dll

c:\program files\FinePixViewer\System\fc_Open.dll
06/27/2006 04:57 PM 135168 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010265.dll

c:\program files\FinePixViewer\System\fc_RemoveDevice.dll
12/15/2006 09:50 PM 143360 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010264.dll

c:\program files\FinePixViewer\System\fc_RotateLeft.dll
10/26/2006 03:13 PM 151552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010263.dll

c:\program files\FinePixViewer\System\fc_RotateResource.dll
01/17/2005 05:57 PM 45056 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010262.dll

c:\program files\FinePixViewer\System\fc_RotateRight.dll
10/26/2006 03:13 PM 151552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010261.dll

c:\program files\FinePixViewer\System\fc_SaveAs.dll
06/27/2006 04:56 PM 139264 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010260.dll

c:\program files\FinePixViewer\System\fc_SaveAsResource.dll
01/28/2005 07:12 PM 33792 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010259.dll

c:\program files\FinePixViewer\System\FileSelectWizardResource.dll
06/08/2005 06:17 PM 110592 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010258.dll

c:\program files\FinePixViewer\System\fpv_ptp_utility_usbscan.dll
12/04/2006 11:44 PM 135168 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010256.dll

c:\program files\FinePixViewer\System\fpv_ptp_utility_wia.dll
06/05/2006 08:42 PM 102400 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010255.dll

c:\program files\FinePixViewer\System\fpv_ptp_utility_wpd.dll
01/18/2007 12:00 AM 151552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010254.dll

c:\program files\FinePixViewer\System\FPVRes.dll
10/25/2006 05:44 PM 2723840 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010257.dll

c:\program files\FinePixViewer\System\HelperCommand.dll
12/01/2006 11:23 PM 4677632 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010253.dll

c:\program files\FinePixViewer\System\MergeFolder.dll
12/01/2006 06:33 PM 77824 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010252.dll

c:\program files\FinePixViewer\System\MergeFolder_res.dll
09/20/2005 06:54 PM 3072 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010251.dll

c:\program files\FinePixViewer\System\NetPrint.dll
12/01/2006 11:23 PM 4644864 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010250.dll

c:\program files\FinePixViewer\System\NetServiceSetting.dll
06/27/2006 04:35 PM 69632 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010249.dll

c:\program files\FinePixViewer\System\NetServiceSettingRes.dll
01/12/2005 01:23 PM 2048 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010248.dll

c:\program files\FinePixViewer\System\OpenAsRun.dll
12/20/2006 03:10 PM 172032 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010247.dll

c:\program files\FinePixViewer\System\PrintWizard.dll
10/31/2006 11:26 AM 4599808 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010246.dll

c:\program files\FinePixViewer\System\PrintWizard_res.dll
09/20/2005 06:57 PM 102400 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010245.dll

c:\program files\FinePixViewer\System\Redeye.dll
12/01/2006 06:34 PM 368640 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010244.dll

c:\program files\FinePixViewer\System\RedeyeRes.dll
09/20/2005 06:56 PM 61440 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010243.dll

c:\program files\FinePixViewer\System\Search\fpv4search.dll
11/26/2006 02:28 PM 81920 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010194.dll

c:\program files\FinePixViewer\System\SendMail.dll
12/21/2006 08:31 PM 327680 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010242.dll

c:\program files\FinePixViewer\System\SendMailRes.dll
09/20/2005 06:56 PM 3072 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010241.dll

c:\program files\FinePixViewer\System\ServiceCustomize.dll
12/15/2006 09:51 PM 249856 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010240.dll

c:\program files\FinePixViewer\System\ServiceCustomizeRes.dll
01/21/2005 12:46 PM 17920 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010239.dll

c:\program files\FinePixViewer\System\SlideShow.dll
10/26/2006 11:20 AM 204800 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010238.dll

c:\program files\FinePixViewer\System\slideshow_setting.dll
10/26/2006 11:20 AM 94208 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010236.dll

c:\program files\FinePixViewer\System\slideshow_setting_res.dll
10/26/2006 11:20 AM 12288 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010235.dll

c:\program files\FinePixViewer\System\SlideShowRes.dll
10/26/2006 11:20 AM 184320 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010237.dll

c:\program files\FinePixViewer\System\versioninfo.dll
06/27/2006 04:33 PM 94208 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010234.dll

c:\program files\FinePixViewer\System\versioninfo_res.dll
12/12/2006 07:14 PM 49152 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010233.dll

c:\program files\FinePixViewer\terminate.exe
01/23/2005 12:01 PM 45056 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010316.exe

c:\program files\FinePixViewer\unzip32.dll
01/20/2001 08:37 AM 102400 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010315.dll

c:\program files\FinePixViewer\updater.exe
11/30/2002 06:28 PM 57344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010314.exe

c:\program files\FinePixViewer\Upload.exe
02/28/2006 07:41 PM 376832 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010313.exe

c:\program files\FinePixViewer\wia_register_event.dll
11/10/2006 04:32 PM 81920 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010312.dll

c:\program files\FinePixViewer\WMFSDK.dll
06/19/2004 01:51 PM 114688 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010311.dll

c:\program files\GMATPrep\Bin\HTMLViewer.exe
04/13/2005 04:17 PM 28672 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010530.exe

c:\program files\GMATPrep\jre\bin\atl71.dll
12/20/2005 11:04 AM 89088 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010528.dll

c:\program files\GMATPrep\jre\bin\awt.dll
06/03/2004 09:28 PM 987246 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010527.dll

c:\program files\GMATPrep\jre\bin\axbridge.dll
06/03/2004 10:05 PM 94323 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010526.dll

c:\program files\GMATPrep\jre\bin\client\jvm.dll
06/03/2004 09:05 PM 1216642 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010455.dll

c:\program files\GMATPrep\jre\bin\cmm.dll
06/03/2004 09:36 PM 139374 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010525.dll

c:\program files\GMATPrep\jre\bin\dcpr.dll
06/03/2004 09:31 PM 139375 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010524.dll

c:\program files\GMATPrep\jre\bin\dt_shmem.dll
06/03/2004 09:43 PM 24689 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010523.dll

c:\program files\GMATPrep\jre\bin\dt_socket.dll
06/03/2004 09:43 PM 20595 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010522.dll

c:\program files\GMATPrep\jre\bin\eula.dll
06/03/2004 10:05 PM 61547 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010521.dll

c:\program files\GMATPrep\jre\bin\fontmanager.dll
06/03/2004 09:33 PM 327811 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010520.dll

c:\program files\GMATPrep\jre\bin\hpi.dll
06/03/2004 09:05 PM 28791 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010519.dll

c:\program files\GMATPrep\jre\bin\hprof.dll
06/03/2004 09:13 PM 49258 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010518.dll

c:\program files\GMATPrep\jre\bin\ioser12.dll
06/03/2004 09:37 PM 24715 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010517.dll

c:\program files\GMATPrep\jre\bin\izmjnicom.dll
12/20/2005 11:04 AM 180224 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010516.dll

c:\program files\GMATPrep\jre\bin\izmjnicomax.dll
12/20/2005 11:04 AM 172032 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010515.dll

c:\program files\GMATPrep\jre\bin\jaas_nt.dll
06/03/2004 09:40 PM 20611 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010514.dll

c:\program files\GMATPrep\jre\bin\java.dll
06/03/2004 09:08 PM 102515 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010513.dll

c:\program files\GMATPrep\jre\bin\java.exe
06/03/2004 09:09 PM 45161 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010512.exe

c:\program files\GMATPrep\jre\bin\javaw.exe
06/03/2004 09:09 PM 45163 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010511.exe

c:\program files\GMATPrep\jre\bin\jawt.dll
06/03/2004 09:39 PM 20592 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010510.dll

c:\program files\GMATPrep\jre\bin\jcov.dll
06/03/2004 09:13 PM 61544 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010509.dll

c:\program files\GMATPrep\jre\bin\JdbcOdbc.dll
06/03/2004 09:38 PM 49278 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010508.dll

c:\program files\GMATPrep\jre\bin\jdwp.dll
06/03/2004 09:42 PM 102505 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010507.dll

c:\program files\GMATPrep\jre\bin\jpeg.dll
06/03/2004 09:34 PM 122992 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010506.dll

c:\program files\GMATPrep\jre\bin\jpicom32.dll
06/03/2004 10:05 PM 82035 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010505.dll

c:\program files\GMATPrep\jre\bin\jpicpl32.exe
06/03/2004 10:05 PM 16501 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010503.exe

c:\program files\GMATPrep\jre\bin\jpiexp32.dll
06/03/2004 10:05 PM 98419 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010502.dll

c:\program files\GMATPrep\jre\bin\jpins4.dll
06/03/2004 10:05 PM 28783 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010501.dll

c:\program files\GMATPrep\jre\bin\jpins6.dll
06/03/2004 10:05 PM 41071 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010500.dll

c:\program files\GMATPrep\jre\bin\jpins7.dll
06/03/2004 10:05 PM 45167 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010499.dll

c:\program files\GMATPrep\jre\bin\jpinsp.dll
06/03/2004 10:05 PM 86127 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010498.dll

c:\program files\GMATPrep\jre\bin\jpishare.dll
06/03/2004 10:05 PM 77939 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010497.dll

c:\program files\GMATPrep\jre\bin\jsound.dll
06/03/2004 09:19 PM 143480 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010496.dll

c:\program files\GMATPrep\jre\bin\jucheck.exe
06/03/2004 10:05 PM 241777 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010495.exe

c:\program files\GMATPrep\jre\bin\jusched.exe
06/03/2004 10:05 PM 32881 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010494.exe

c:\program files\GMATPrep\jre\bin\keytool.exe
06/03/2004 09:23 PM 45185 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010493.exe

c:\program files\GMATPrep\jre\bin\kinit.exe
06/03/2004 09:23 PM 45181 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010492.exe

c:\program files\GMATPrep\jre\bin\klist.exe
06/03/2004 09:24 PM 45181 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010491.exe

c:\program files\GMATPrep\jre\bin\ktab.exe
06/03/2004 09:24 PM 45179 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010490.exe

c:\program files\GMATPrep\jre\bin\msvcrt.dll
08/31/2004 01:24 PM 266293 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010489.dll

c:\program files\GMATPrep\jre\bin\net.dll
06/03/2004 09:15 PM 57455 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010488.dll

c:\program files\GMATPrep\jre\bin\nio.dll
06/03/2004 09:15 PM 32880 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010487.dll

c:\program files\GMATPrep\jre\bin\NPJava11.dll
06/03/2004 10:05 PM 65647 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010486.dll

c:\program files\GMATPrep\jre\bin\NPJava12.dll
06/03/2004 10:05 PM 65647 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010485.dll

c:\program files\GMATPrep\jre\bin\NPJava13.dll
06/03/2004 10:05 PM 65647 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010484.dll

c:\program files\GMATPrep\jre\bin\NPJava14.dll
06/03/2004 10:05 PM 65647 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010483.dll

c:\program files\GMATPrep\jre\bin\NPJava32.dll
06/03/2004 10:05 PM 65647 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010482.dll

c:\program files\GMATPrep\jre\bin\NPJPI142_05.dll
06/03/2004 10:05 PM 65650 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010481.dll

c:\program files\GMATPrep\jre\bin\NPOJI610.dll
06/03/2004 10:05 PM 65647 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010480.dll

c:\program files\GMATPrep\jre\bin\orbd.exe
06/03/2004 09:41 PM 45204 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010479.exe

c:\program files\GMATPrep\jre\bin\policytool.exe
06/03/2004 09:23 PM 45191 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010478.exe

c:\program files\GMATPrep\jre\bin\RegUtils.dll
06/03/2004 10:05 PM 110707 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010477.dll

c:\program files\GMATPrep\jre\bin\rmi.dll
06/03/2004 09:37 PM 20590 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010476.dll

c:\program files\GMATPrep\jre\bin\rmid.exe
06/03/2004 09:38 PM 45179 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010475.exe

c:\program files\GMATPrep\jre\bin\rmiregistry.exe
06/03/2004 09:38 PM 45191 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010474.exe

c:\program files\GMATPrep\jre\bin\servertool.exe
06/03/2004 09:41 PM 45216 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010473.exe

c:\program files\GMATPrep\jre\bin\SystemInformation.dll
12/20/2005 11:04 AM 28672 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010472.dll

c:\program files\GMATPrep\jre\bin\tnameserv.exe
06/03/2004 09:41 PM 45206 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010471.exe

c:\program files\GMATPrep\jre\bin\verify.dll
06/03/2004 09:05 PM 57453 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010470.dll

c:\program files\GMATPrep\jre\bin\w2k_lsa_auth.dll
08/31/2004 01:24 PM 20563 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010469.dll

c:\program files\GMATPrep\jre\bin\zip.dll
06/03/2004 09:09 PM 53364 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010468.dll

c:\program files\InstallShield Installation Information\{24ED4D80-8294-11D5-96CD-0040266301AD}\_Setup.dll
05/17/2006 06:21 PM 385968 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010364.dll

c:\program files\InstallShield Installation Information\{24ED4D80-8294-11D5-96CD-0040266301AD}\ISSetup.dll
02/18/2007 11:51 PM 552214 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010363.dll

c:\program files\InstallShield Installation Information\{24ED4D80-8294-11D5-96CD-0040266301AD}\setup.exe
05/24/2006 07:10 PM 455600 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010365.exe

c:\program files\InstallShield Installation Information\{5490882C-6961-11D5-BAE5-00E0188E010B}\Setup.exe
05/15/2000 09:08 PM 134656 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010440.exe

c:\program files\InstallShield Installation Information\{B093990A-AAF2-44AC-9216-14BB7A2189B6}\_setup.dll
04/14/2009 11:45 AM 344064 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010617.dll

c:\program files\InstallShield Installation Information\{B093990A-AAF2-44AC-9216-14BB7A2189B6}\setup.exe
12/02/2002 05:33 PM 107512 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010619.exe

c:\program files\InstallShield Installation Information\{B44529FF-501E-47CD-A06D-223C161BE058}\_Setup.dll
05/17/2006 06:21 PM 385968 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010186.dll

c:\program files\InstallShield Installation Information\{B44529FF-501E-47CD-A06D-223C161BE058}\ISSetup.dll
02/18/2007 10:29 PM 552214 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010185.dll

c:\program files\InstallShield Installation Information\{B44529FF-501E-47CD-A06D-223C161BE058}\setup.exe
05/24/2006 07:10 PM 455600 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010187.exe

c:\program files\InstallShield Installation Information\{BFE903DE-4845-4387-9C6C-98B21B8445A3}\_Setup.dll
11/17/2008 04:15 PM 156616 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010534.dll

c:\program files\InstallShield Installation Information\{BFE903DE-4845-4387-9C6C-98B21B8445A3}\ISSetup.dll
11/17/2008 04:15 PM 540968 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010533.dll

c:\program files\InstallShield Installation Information\{BFE903DE-4845-4387-9C6C-98B21B8445A3}\setup.exe
11/17/2008 04:15 PM 378152 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010535.exe

c:\program files\InstallShield Installation Information\{E3B3AB03-8ABC-46CF-8CA9-DB5581E1F368}\Setup.exe
04/11/2001 12:07 PM 166912 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010159.exe

c:\program files\Malwarebytes' Anti-Malware\mbam-dor.exe
04/06/2009 03:32 PM 380048 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030348.exe

c:\program files\Malwarebytes' Anti-Malware\mbam.dll
04/06/2009 03:32 PM 73360 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030349.dll

c:\program files\Malwarebytes' Anti-Malware\mbam.exe
04/06/2009 03:32 PM 1277584 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030346.exe

c:\program files\Malwarebytes' Anti-Malware\mbamext.dll
04/06/2009 03:32 PM 73360 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030352.dll

c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
04/06/2009 03:32 PM 401040 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030341.exe

c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
04/06/2009 03:32 PM 179856 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030340.exe

c:\program files\Malwarebytes' Anti-Malware\ssubtmr6.dll
04/06/2009 03:32 PM 44688 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030343.dll

c:\program files\Malwarebytes' Anti-Malware\unins000.exe
04/20/2009 01:35 PM 690832 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030350.exe

c:\program files\Malwarebytes' Anti-Malware\zlib.dll
04/06/2009 03:32 PM 77968 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030344.dll

04/28/2009 11:40 AM 17400 c:\program files\Mozilla Firefox\AccessibleMarshal.dll
03/31/2009 02:18 PM 17400 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028907.dll
04/27/2009 08:43 AM 17400 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029962.dll

04/28/2009 11:40 AM 23032 c:\program files\Mozilla Firefox\components\browserdirprovider.dll
03/31/2009 02:18 PM 23032 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028909.dll
04/27/2009 08:43 AM 23032 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029964.dll

04/28/2009 11:40 AM 134648 c:\program files\Mozilla Firefox\components\brwsrcmp.dll
03/31/2009 02:18 PM 134648 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028910.dll
04/27/2009 08:43 AM 134648 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029965.dll

04/28/2009 11:40 AM 185848 c:\program files\Mozilla Firefox\crashreporter.exe
03/31/2009 02:18 PM 185848 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028911.exe
04/27/2009 08:43 AM 185848 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029966.exe

04/28/2009 11:40 AM 307704 c:\program files\Mozilla Firefox\firefox.exe
03/31/2009 02:18 PM 307704 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028912.exe
04/27/2009 08:43 AM 307704 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029967.exe

04/28/2009 11:40 AM 233472 c:\program files\Mozilla Firefox\freebl3.dll
03/31/2009 02:18 PM 233472 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028913.dll
04/27/2009 08:43 AM 233472 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029968.dll

04/28/2009 11:40 AM 697336 c:\program files\Mozilla Firefox\js3250.dll
03/31/2009 02:18 PM 697848 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028914.dll
04/27/2009 08:43 AM 697848 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029969.dll

04/28/2009 11:40 AM 710136 c:\program files\Mozilla Firefox\mozcrt19.dll
03/31/2009 02:18 PM 710136 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028915.dll
04/27/2009 08:43 AM 710136 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029970.dll

04/28/2009 11:40 AM 198136 c:\program files\Mozilla Firefox\nspr4.dll
03/31/2009 02:18 PM 198136 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028916.dll
04/27/2009 08:43 AM 198136 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029971.dll

04/28/2009 11:40 AM 718328 c:\program files\Mozilla Firefox\nss3.dll
03/31/2009 02:18 PM 718328 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028917.dll
04/27/2009 08:43 AM 718328 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029972.dll

04/28/2009 11:40 AM 292344 c:\program files\Mozilla Firefox\nssckbi.dll
03/31/2009 02:18 PM 292344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028918.dll
04/27/2009 08:43 AM 292344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029973.dll

04/28/2009 11:40 AM 103928 c:\program files\Mozilla Firefox\nssdbm3.dll
03/31/2009 02:18 PM 103928 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028919.dll
04/27/2009 08:43 AM 103928 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029974.dll

04/28/2009 11:40 AM 87544 c:\program files\Mozilla Firefox\nssutil3.dll
03/31/2009 02:18 PM 87544 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028920.dll
04/27/2009 08:43 AM 87544 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029975.dll

04/28/2009 11:40 AM 20472 c:\program files\Mozilla Firefox\plc4.dll
03/31/2009 02:18 PM 20472 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028922.dll
04/27/2009 08:43 AM 20472 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029977.dll

04/28/2009 11:40 AM 17400 c:\program files\Mozilla Firefox\plds4.dll
03/31/2009 02:18 PM 17400 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028923.dll
04/27/2009 08:43 AM 17400 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029978.dll

04/28/2009 11:40 AM 65528 c:\program files\Mozilla Firefox\plugins\npnul32.dll
03/31/2009 02:18 PM 65528 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028924.dll
04/27/2009 08:43 AM 65528 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029979.dll

04/28/2009 11:40 AM 103928 c:\program files\Mozilla Firefox\smime3.dll
03/31/2009 02:18 PM 103928 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028925.dll
04/27/2009 08:43 AM 103928 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029980.dll

04/28/2009 11:40 AM 151552 c:\program files\Mozilla Firefox\softokn3.dll
03/31/2009 02:18 PM 151552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028926.dll
04/27/2009 08:43 AM 151552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029981.dll

04/28/2009 11:40 AM 395768 c:\program files\Mozilla Firefox\sqlite3.dll
03/31/2009 02:18 PM 395768 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028927.dll
04/27/2009 08:43 AM 395768 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029982.dll

04/28/2009 11:40 AM 136696 c:\program files\Mozilla Firefox\ssl3.dll
03/31/2009 02:18 PM 136696 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028928.dll
04/27/2009 08:43 AM 136696 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029983.dll

04/28/2009 11:40 AM 509544 c:\program files\Mozilla Firefox\uninstall\helper.exe
03/31/2009 02:18 PM 509536 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028929.exe
04/27/2009 08:43 AM 509536 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029984.exe

04/28/2009 11:40 AM 242168 c:\program files\Mozilla Firefox\updater.exe
03/31/2009 02:18 PM 242168 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028930.exe
04/27/2009 08:43 AM 242168 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029985.exe

04/28/2009 11:40 AM 17912 c:\program files\Mozilla Firefox\xpcom.dll
03/31/2009 02:18 PM 17912 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028931.dll
04/27/2009 08:43 AM 17912 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029986.dll

04/28/2009 11:41 AM 9756664 c:\program files\Mozilla Firefox\xul.dll
03/31/2009 02:18 PM 9732600 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028932.dll
04/27/2009 08:43 AM 9758200 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029987.dll

c:\program files\Norton AntiVirus\Branding\muis.dll
12/26/2008 01:04 PM 9072 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030206.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\AppMgr32.dll
02/27/2009 04:02 AM 268656 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030029.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\AVExclu.dll
02/27/2009 04:02 AM 122736 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030030.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\AVifc.dll
02/27/2009 04:02 AM 409968 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030031.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\AVMail.dll
02/27/2009 04:02 AM 72560 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030032.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\AVModule.dll
02/27/2009 04:02 AM 1061744 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030033.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\AVPAPP32.dll
02/27/2009 04:02 AM 223600 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030034.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\AVPSVC32.dll
02/27/2009 04:02 AM 187248 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030035.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\avScanUI.dll
02/27/2009 04:02 AM 505712 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030036.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\avScnTsk.dll
02/27/2009 04:02 AM 172912 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030037.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\bbRGen.dll
03/03/2009 03:36 PM 345488 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030038.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\BHCA.exe
03/03/2009 03:36 PM 242536 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030039.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\BHClient.dll
03/03/2009 03:36 PM 242576 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030040.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\BHSvcPlg.dll
03/03/2009 03:36 PM 1703824 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030041.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccAlert.dll
02/27/2009 04:02 AM 210280 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030042.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccEmlPxy.dll
03/03/2009 03:36 PM 257384 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030043.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccErrDsp.dll
02/27/2009 04:02 AM 97640 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030044.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccGEvt.dll
02/27/2009 04:02 AM 277864 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030045.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccGLog.dll
02/27/2009 04:02 AM 192360 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030046.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccIPC.dll
02/27/2009 04:02 AM 147816 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030256.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccJobMgr.dll
02/27/2009 04:02 AM 381800 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030047.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccL80.dll
02/27/2009 04:02 AM 517480 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030048.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccL80U.dll
02/27/2009 04:02 AM 523624 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030257.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccScanw.dll
02/27/2009 04:02 AM 328552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030049.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccSEBind.dll
02/27/2009 04:02 AM 597864 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030050.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccSet.dll
02/27/2009 04:02 AM 254824 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030258.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccSEUPDT.exe
02/27/2009 04:02 AM 108392 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030051.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccSubEng.dll
02/27/2009 04:02 AM 245096 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030052.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccSvc.dll
02/27/2009 04:02 AM 122728 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030053.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
02/27/2009 04:02 AM 115560 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030054.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccVrTrst.dll
02/27/2009 04:02 AM 80744 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030259.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\cltAlDis.dll
02/27/2009 04:02 AM 251272 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030055.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\cltAlert.dll
02/27/2009 04:02 AM 112008 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030056.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\cltLMC.dll
02/27/2009 04:02 AM 99720 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030260.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\CLTLMH.EXE
02/27/2009 04:02 AM 1009032 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030057.EXE

c:\program files\Norton AntiVirus\Engine\16.5.0.134\cltLMJ.dll
02/27/2009 04:02 AM 890248 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030058.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\CLTLMS.DLL
02/27/2009 04:02 AM 419208 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030059.DLL

c:\program files\Norton AntiVirus\Engine\16.5.0.134\cltNAHD.dll
02/27/2009 04:02 AM 112008 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030060.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\cltRDUrl.dll
02/27/2009 04:02 AM 54664 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030061.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\cltui.dll
02/27/2009 04:02 AM 536960 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030062.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\dec_abi.dll
02/27/2009 04:02 AM 2106720 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030063.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\DefUtDCD.dll
02/27/2009 04:02 AM 681336 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030064.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\diLueCbk.dll
03/03/2009 03:36 PM 65904 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030065.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\diMaster.dll
03/03/2009 03:36 PM 130416 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030066.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\DNLP0808.exe
02/27/2009 04:02 AM 279920 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030067.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ducclib.dll
02/27/2009 04:02 AM 28536 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030068.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\DuLuCbk.dll
02/27/2009 04:02 AM 83296 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030069.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ecmldr32.DLL
02/27/2009 04:02 AM 42864 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030070.DLL

c:\program files\Norton AntiVirus\Engine\16.5.0.134\EFACli.dll
02/27/2009 04:02 AM 42856 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030261.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\EFAInst.exe
02/27/2009 04:02 AM 27496 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030071.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\FOIEnum.exe
02/27/2009 04:02 AM 103792 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030072.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\FWCore.dll
02/27/2009 04:02 AM 114032 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030073.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\FWGenPlg.dll
02/27/2009 04:02 AM 98160 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030074.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\FWHelper.dll
02/27/2009 04:02 AM 106352 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030075.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\fwMCPlug.dll
02/27/2009 04:02 AM 242544 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030076.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\FWSesAl.dll
02/27/2009 04:02 AM 177008 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030077.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\FWSetup.dll
02/27/2009 04:02 AM 89968 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030262.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\GadgetCA.exe
02/27/2009 04:02 AM 160128 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030078.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\hncore.dll
02/27/2009 04:02 AM 471408 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030079.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\hndisco.dll
02/27/2009 04:02 AM 141168 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030080.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\HSLoader.exe
02/27/2009 04:02 AM 107392 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030081.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\hsui.dll
02/27/2009 04:02 AM 173440 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030082.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\htec.dll
02/27/2009 04:02 AM 148856 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030083.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\HTECSub.dll
02/27/2009 04:02 AM 66936 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030084.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\IDSAux.dll
02/27/2009 04:02 AM 111992 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030085.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\IMCfg.dll
02/27/2009 04:02 AM 66928 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030263.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\InstCA.exe
03/03/2009 03:36 PM 51568 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030086.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\IPSBHO.dll
02/27/2009 04:02 AM 107896 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030087.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\IPSFFPl.dll
02/27/2009 04:02 AM 165240 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030088.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\IPSPlug.dll
02/27/2009 04:02 AM 120184 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030089.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\isDataPr.dll
02/27/2009 04:02 AM 471408 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030264.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ISDataSv.dll
02/27/2009 04:02 AM 183664 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030090.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\isError.dll
02/27/2009 04:02 AM 55152 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030091.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\isPwd.dll
02/27/2009 04:02 AM 107888 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030265.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\Lue.dll
02/27/2009 04:02 AM 935776 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030092.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\MCMGR32.dll
02/27/2009 04:02 AM 99696 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030093.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\MCUI32.exe
02/27/2009 04:02 AM 442224 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030094.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\Microsoft.VC80.CRT\msvcm80.dll
02/27/2009 04:02 AM 479232 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030096.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\Microsoft.VC80.CRT\msvcp80.dll
02/27/2009 04:02 AM 548864 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030097.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\Microsoft.VC80.CRT\msvcr80.dll
02/27/2009 04:02 AM 626688 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030098.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\msl.dll
02/27/2009 04:02 AM 268648 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030099.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\NAVLogV.dll
02/27/2009 04:02 AM 376176 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030100.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\NAVPInst.dll
02/27/2009 04:02 AM 51056 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030101.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\NavShExt.dll
03/03/2009 03:36 PM 269680 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030102.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\NAVTskWz.dll
02/27/2009 04:02 AM 794480 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030103.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\Navw32.exe
02/27/2009 04:02 AM 135536 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030104.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\navwnt.exe
02/27/2009 04:02 AM 60784 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030105.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ncwTrust.dll
02/27/2009 04:02 AM 719216 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030106.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\netmap.dll
02/27/2009 04:02 AM 730480 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030107.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\NISPlug.dll
02/27/2009 04:02 AM 12904 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030108.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\nmapapp.exe
02/27/2009 04:02 AM 197488 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030109.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\nnmgr.dll
02/27/2009 04:02 AM 1208688 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030110.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\NPCGadget.dll
02/27/2009 04:02 AM 69504 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030111.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\NPCStatus.dll
02/27/2009 04:02 AM 2247040 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030112.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\NPCTray.dll
02/27/2009 04:02 AM 236416 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030113.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\NUMEng.dll
02/27/2009 04:02 AM 119168 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030114.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\NumGui.dll
02/27/2009 04:02 AM 135040 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030115.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\OCSCtl.exe
02/27/2009 04:02 AM 222568 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030116.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\OEHeur.dll
02/27/2009 04:02 AM 44392 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030117.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\OfficeAV.dll
02/27/2009 04:02 AM 68464 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030118.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\patch25d.dll
02/27/2009 04:02 AM 33672 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030119.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\QBackup.dll
02/27/2009 04:02 AM 110960 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030120.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\RuleUI.dll
02/27/2009 04:02 AM 441200 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030121.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\SavRT32.dll
02/27/2009 04:02 AM 31608 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030122.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\ScanLess.dll
02/27/2009 04:02 AM 302448 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030123.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\SDKCmn.dll
02/27/2009 04:02 AM 177520 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030124.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\Settings.dll
02/27/2009 04:02 AM 808816 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030125.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\Sevinst.exe
02/27/2009 04:02 AM 828808 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030023.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\SNDSvc.dll
02/27/2009 04:02 AM 185736 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030127.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\Srtsp32.dll
02/27/2009 04:02 AM 300408 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030148.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\sshelper.exe
02/27/2009 04:02 AM 71032 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030149.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\syknlu.exe
03/03/2009 03:36 PM 219488 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030151.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\SymClgX.dll
03/03/2009 03:36 PM 107912 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0029993.dll
04/28/2009 09:27 PM 275848 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030153.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\SymHTML.dll
02/27/2009 04:02 AM 1784152 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030154.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\SymIM\symim.sys
02/27/2009 04:02 AM 36400 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030156.sys

c:\program files\Norton AntiVirus\Engine\16.5.0.134\SymIM\symimv.sys
02/27/2009 04:02 AM 25136 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030159.sys

c:\program files\Norton AntiVirus\Engine\16.5.0.134\SymIMIns.exe
02/27/2009 04:02 AM 189832 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030162.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\SymNeti.dll
02/27/2009 04:02 AM 197000 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030163.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\SymRdrSv.dll
03/03/2009 03:36 PM 30600 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030164.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\SymRedir.dll
02/27/2009 04:02 AM 50056 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030165.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\SymSHAx9.dll
02/27/2009 04:02 AM 120200 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030166.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\tgctlcm.dll
02/27/2009 04:02 AM 292216 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030167.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\tgctlsi.dll
02/27/2009 04:02 AM 1156544 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030169.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\tgctlsr.dll
02/27/2009 04:02 AM 583104 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030171.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\uiAlert.dll
02/27/2009 04:02 AM 292224 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030173.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\UICntnr.dll
02/27/2009 04:02 AM 41344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030174.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\uiGadCtl.dll
02/27/2009 04:02 AM 50560 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030175.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\uiHost.dll
02/27/2009 04:02 AM 100736 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030176.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\uiPerfsv.dll
02/27/2009 04:02 AM 119680 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030177.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\uiPfStub.dll
02/27/2009 04:02 AM 133504 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030178.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\uiStub.exe
02/27/2009 04:02 AM 94592 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030179.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\uiWebHst.dll
02/27/2009 04:02 AM 103296 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030180.dll

c:\program files\Norton AntiVirus\Engine\16.5.0.134\WFPUnins.exe
02/27/2009 04:02 AM 23944 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030181.exe

c:\program files\Norton AntiVirus\Engine\16.5.0.134\WSCStub.exe
02/27/2009 04:02 AM 96456 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030182.exe

c:\program files\Norton AntiVirus\MUI\16.5.0.134\09\01\rcAlert.dll
02/27/2009 04:05 AM 53096 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030235.dll

c:\program files\Norton AntiVirus\MUI\16.5.0.134\09\01\rcEmlPxy.dll
02/27/2009 04:05 AM 13160 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030236.dll

c:\program files\Norton AntiVirus\MUI\16.5.0.134\09\01\rcErrDsp.dll
02/27/2009 04:05 AM 22888 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030237.dll

c:\program files\Norton AntiVirus\MUI\16.5.0.134\09\01\rcSvcHst.dll
02/27/2009 04:05 AM 9064 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030238.dll

c:\program files\Norton Support\sshelper.exe
02/27/2009 04:02 AM 71032 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030002.exe

c:\program files\Norton Support\tgctlcm.dll
02/27/2009 04:02 AM 292216 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030004.dll

c:\program files\Norton Support\tgctlsi.dll
02/27/2009 04:02 AM 1156544 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030005.dll

c:\program files\Norton Support\tgctlsr.dll
02/27/2009 04:02 AM 583104 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030006.dll

c:\program files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV\2454B0AB\16.5.0.134\ccL80U.dll
12/05/2008 02:52 AM 522088 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030266.dll

c:\program files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV\2454B0AB\16.5.0.134\cltLMSx.dll
12/26/2008 12:32 PM 791920 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030251.dll

c:\program files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV\2454B0AB\16.5.0.134\Engine.dll
03/05/2009 12:50 PM 1328160 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030252.dll

c:\program files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV\2454B0AB\16.5.0.134\InstStub.exe
03/03/2009 03:37 PM 970576 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030267.exe

c:\program files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV\2454B0AB\16.5.0.134\InstUI.dll
12/05/2008 02:52 AM 2129440 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030253.dll

c:\program files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV\2454B0AB\16.5.0.134\Microsoft.VC80.CRT\msvcm80.dll
12/26/2008 12:32 PM 479232 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030248.dll

c:\program files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV\2454B0AB\16.5.0.134\Microsoft.VC80.CRT\msvcp80.dll
12/26/2008 12:32 PM 548864 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030249.dll

c:\program files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV\2454B0AB\16.5.0.134\Microsoft.VC80.CRT\msvcr80.dll
12/26/2008 12:32 PM 626688 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030250.dll

c:\program files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV\2454B0AB\16.5.0.134\ProdCbk.dll
02/27/2009 04:02 AM 298864 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030254.dll

c:\program files\PIXELA\ImageMixer\AplIns.dll
12/09/2004 09:45 PM 32768 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010615.dll

c:\program files\PIXELA\ImageMixer\AsfDec.dll
12/08/2004 04:39 PM 1511491 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010614.dll

c:\program files\PIXELA\ImageMixer\AsfDecMulti.dll
12/08/2004 04:20 PM 1519693 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010613.dll

c:\program files\PIXELA\ImageMixer\BGOLDLIB.dll
10/20/2005 07:29 PM 1019904 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010567.dll

c:\program files\PIXELA\ImageMixer\bgsvcctl.dll
04/30/2005 05:06 PM 77824 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010565.dll

c:\program files\PIXELA\ImageMixer\Blend.dll
12/08/2004 04:39 PM 50176 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010612.dll

c:\program files\PIXELA\ImageMixer\BW50_8.drv
07/20/2005 09:43 PM 90112 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010564.drv

c:\program files\PIXELA\ImageMixer\CDD2000_8.drv
07/20/2005 09:43 PM 69632 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010563.drv

c:\program files\PIXELA\ImageMixer\CDR10X_8.drv
07/20/2005 09:43 PM 73728 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010562.drv

c:\program files\PIXELA\ImageMixer\CDR200_8.drv
07/20/2005 09:44 PM 69632 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010561.drv

c:\program files\PIXELA\ImageMixer\CDR400_8.drv
07/20/2005 09:44 PM 98304 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010560.drv

c:\program files\PIXELA\ImageMixer\CDR50S_8.drv
07/20/2005 09:43 PM 77824 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010559.drv

c:\program files\PIXELA\ImageMixer\CDR55S_8.drv
07/20/2005 09:43 PM 81920 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010558.drv

c:\program files\PIXELA\ImageMixer\cdrbs2k.dll
02/02/2005 02:44 PM 53248 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010557.dll

c:\program files\PIXELA\ImageMixer\CDRBSVSD.DLL
05/10/2005 06:28 PM 53248 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010556.DLL

c:\program files\PIXELA\ImageMixer\CDU926S_8.drv
07/20/2005 09:44 PM 81920 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010555.drv

c:\program files\PIXELA\ImageMixer\CGENERAL8.DLL
07/26/2005 11:18 PM 131072 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010554.DLL

c:\program files\PIXELA\ImageMixer\COMCDROM_8.drv
07/28/2005 08:30 PM 184320 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010553.drv

c:\program files\PIXELA\ImageMixer\Copybit.dll
12/08/2004 04:39 PM 43520 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010611.dll

c:\program files\PIXELA\ImageMixer\CRW4260_8.Drv
07/20/2005 09:45 PM 69632 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010552.Drv

c:\program files\PIXELA\ImageMixer\CRX510E_8.drv
07/28/2005 08:30 PM 675840 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010551.drv

c:\program files\PIXELA\ImageMixer\cw7501_8.drv
07/20/2005 09:46 PM 69632 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010550.drv

c:\program files\PIXELA\ImageMixer\Decjpg.dll
12/08/2004 04:39 PM 79360 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010610.dll

c:\program files\PIXELA\ImageMixer\Dibapi.dll
12/16/2004 05:19 PM 360448 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010609.dll

c:\program files\PIXELA\ImageMixer\dvdAuthoring.dll
10/28/2004 01:55 PM 352256 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010608.dll

c:\program files\PIXELA\ImageMixer\dvdcdlib.dll
12/08/2004 03:23 PM 188416 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010607.dll

c:\program files\PIXELA\ImageMixer\DVDRCTRL.dll
12/08/2004 03:23 PM 199168 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010606.dll

c:\program files\PIXELA\ImageMixer\EncoderInterface.dll
03/31/2004 05:46 PM 147456 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010605.dll

c:\program files\PIXELA\ImageMixer\EncodeToMpegLibrary.dll
03/31/2004 05:46 PM 204800 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010604.dll

c:\program files\PIXELA\ImageMixer\Exif.dll
12/08/2004 04:21 PM 532480 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010603.dll

c:\program files\PIXELA\ImageMixer\FontEnum.dll
12/08/2004 04:39 PM 30720 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010602.dll

c:\program files\PIXELA\ImageMixer\FXCDLib.dll
12/08/2004 03:23 PM 438272 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010601.dll

c:\program files\PIXELA\ImageMixer\FXMJPLib.dll
12/08/2004 03:23 PM 258048 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010600.dll

c:\program files\PIXELA\ImageMixer\ImageMixerVCDRes.dll
12/28/2004 04:53 PM 3399680 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010570.dll

c:\program files\PIXELA\ImageMixer\Immesres.dll
12/28/2004 03:59 PM 397312 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010569.dll

c:\program files\PIXELA\ImageMixer\IMMovieCutterRes.dll
12/20/2004 03:41 PM 479232 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010599.dll

c:\program files\PIXELA\ImageMixer\IMMovieCutterResL.dll
12/17/2004 11:32 AM 53248 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010568.dll

c:\program files\PIXELA\ImageMixer\improvement_filter.dll
09/02/2003 04:20 PM 94208 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010598.dll

c:\program files\PIXELA\ImageMixer\IMxDVD2.exe
01/13/2005 08:41 PM 999424 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010597.exe

c:\program files\PIXELA\ImageMixer\IMxMovieEditor.exe
12/13/2004 01:36 PM 421888 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010596.exe

c:\program files\PIXELA\ImageMixer\MakeVCDInfo.dll
12/08/2004 04:39 PM 45056 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010595.dll

c:\program files\PIXELA\ImageMixer\mp620XS_8.drv
07/20/2005 09:46 PM 90112 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010549.drv

c:\program files\PIXELA\ImageMixer\MpegChecker.dll
12/08/2004 04:39 PM 45056 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010594.dll

c:\program files\PIXELA\ImageMixer\mpegCutter.dll
12/08/2004 04:39 PM 188416 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010593.dll

c:\program files\PIXELA\ImageMixer\MpegSplitterMixerLibrary.dll
03/31/2004 05:46 PM 237568 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010592.dll

c:\program files\PIXELA\ImageMixer\MpgBasic.dll
03/31/2004 05:46 PM 110592 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010591.dll

c:\program files\PIXELA\ImageMixer\MpgJudge.dll
12/08/2004 04:39 PM 126976 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010590.dll

c:\program files\PIXELA\ImageMixer\MpvpxMMX.dll
05/28/2003 01:28 PM 69632 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010589.dll

c:\program files\PIXELA\ImageMixer\MpvpxSS2.dll
05/28/2003 01:28 PM 86016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010588.dll

c:\program files\PIXELA\ImageMixer\MpvpxSSE.dll
05/28/2003 01:28 PM 69632 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010587.dll

c:\program files\PIXELA\ImageMixer\MpvpxX86.dll
05/28/2003 01:28 PM 73728 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010586.dll

c:\program files\PIXELA\ImageMixer\MsgDlg.dll
12/13/2004 06:42 PM 180224 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010585.dll

c:\program files\PIXELA\ImageMixer\OSR1HELP.DLL
10/02/1998 12:40 PM 17408 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010548.DLL

c:\program files\PIXELA\ImageMixer\pixejpg.dll
12/08/2004 04:39 PM 167936 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010584.dll

c:\program files\PIXELA\ImageMixer\px_filter.dll
12/08/2004 04:39 PM 73728 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010580.dll

c:\program files\PIXELA\ImageMixer\px_mpeg_util.dll
09/02/2003 04:20 PM 81920 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010576.dll

c:\program files\PIXELA\ImageMixer\px_mpega.dll
09/02/2003 04:20 PM 131072 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010579.dll

c:\program files\PIXELA\ImageMixer\px_mpegv.dll
04/16/2004 02:37 PM 303104 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010578.dll

c:\program files\PIXELA\ImageMixer\px_mpegvd.dll
09/02/2003 04:20 PM 65536 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010577.dll

c:\program files\PIXELA\ImageMixer\px_MpvDecMMX.dll
09/02/2003 04:20 PM 122880 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010575.dll

c:\program files\PIXELA\ImageMixer\px_MpvDecSSE.dll
09/02/2003 04:20 PM 122880 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010574.dll

c:\program files\PIXELA\ImageMixer\px_MpvDecX86.dll
09/02/2003 04:20 PM 122880 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010573.dll

c:\program files\PIXELA\ImageMixer\PxNT2KCL.dll
12/08/2004 03:24 PM 155648 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010583.dll

c:\program files\PIXELA\ImageMixer\PxScalingFilter.dll
12/08/2004 03:24 PM 118784 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010582.dll

c:\program files\PIXELA\ImageMixer\PxWn9xCL.dll
12/08/2004 03:24 PM 155648 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010581.dll

c:\program files\PIXELA\ImageMixer\Rbc.dll
12/08/2004 04:40 PM 57344 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010572.dll

c:\program files\PIXELA\ImageMixer\RO1060C_8.drv
07/20/2005 09:47 PM 77824 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010544.drv

c:\program files\PIXELA\ImageMixer\ro1420c_8.drv
07/20/2005 09:47 PM 86016 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010543.drv

c:\program files\PIXELA\ImageMixer\SFFFAKE_8.dll
10/19/2005 11:56 AM 65536 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010542.dll

c:\program files\PIXELA\ImageMixer\STDCDR_8.drv
09/13/2005 06:08 PM 151552 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010540.drv

c:\program files\PIXELA\ImageMixer\STDCDRS_8.drv
09/13/2005 06:08 PM 147456 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010541.drv

c:\program files\PIXELA\ImageMixer\stdsff_8.drv
09/13/2005 04:17 PM 757760 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010538.drv

c:\program files\PIXELA\ImageMixer\stdsff2_8.drv
10/21/2005 04:57 PM 770048 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010539.drv

c:\program files\PIXELA\ImageMixer\WriteCheck.dll
12/10/2004 05:25 PM 196608 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010571.dll

c:\program files\PIXELA\ImageMixer\xrw2010_8.drv
07/20/2005 09:54 PM 73728 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010537.drv

c:\program files\PIXELA\ImageMixer\xrw204x_8.drv
07/20/2005 09:53 PM 81920 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010536.drv

c:\program files\REGSHAVE\REGSHAVE.EXE
02/04/2002 10:32 PM 53248 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010436.EXE

c:\program files\Symantec\S32EVNT1.DLL
03/03/2009 03:37 PM 60808 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030014.DLL

c:\program files\Symantec\SYMEVENT.SYS
03/03/2009 03:37 PM 124464 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030017.SYS

c:\symim\symimv.sys
02/27/2009 04:02 AM 25136 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030159.sys

c:\windows\Mrera.dll
{414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0021735.dll

c:\windows\system32\aswBoot.exe
02/05/2009 01:11 PM 1256296 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028791.exe

c:\windows\system32\AvastSS.scr
02/05/2009 01:04 PM 97480 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028790.scr

c:\windows\system32\drivers\aavmker4.sys
02/05/2009 01:05 PM 26944 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028784.sys

c:\windows\system32\drivers\aswFsBlk.sys
02/05/2009 01:07 PM 20560 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028783.sys

c:\windows\system32\drivers\aswmon.sys
02/05/2009 01:08 PM 93296 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028785.sys

c:\windows\system32\drivers\aswmon2.sys
02/05/2009 01:08 PM 94032 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028786.sys

c:\windows\system32\drivers\aswRdr.sys
02/05/2009 01:06 PM 23152 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028788.sys

c:\windows\system32\drivers\aswSP.sys
02/05/2009 01:07 PM 114768 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028782.sys

c:\windows\system32\drivers\aswTdi.sys
02/05/2009 01:06 PM 51376 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0028787.sys

c:\windows\system32\drivers\mbam.sys
04/06/2009 03:32 PM 15504 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030339.sys

c:\windows\system32\drivers\mbamswissarmy.sys
04/06/2009 03:32 PM 38496 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030345.sys

c:\windows\system32\drivers\NAV\1005000.086\BHDrvx86.sys
02/27/2009 04:02 AM 258608 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030185.sys

c:\windows\system32\drivers\NAV\1005000.086\cchpx86.sys
03/03/2009 03:36 PM 482352 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030188.sys

c:\windows\system32\drivers\NAV\1005000.086\srtsp.sys
02/27/2009 04:02 AM 307760 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030192.sys

c:\windows\system32\drivers\NAV\1005000.086\srtspx.cat
02/27/2009 04:02 AM 7372 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030193.cat

c:\windows\system32\drivers\NAV\1005000.086\srtspx.sys
02/27/2009 04:02 AM 43696 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030195.sys

c:\windows\system32\drivers\NAV\1005000.086\SymEFA.sys
02/27/2009 04:02 AM 310320 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030198.sys

c:\windows\system32\drivers\NAV\1005000.086\symfw.sys
02/27/2009 04:02 AM 89776 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030199.sys

c:\windows\system32\drivers\NAV\1005000.086\symids.sys
02/27/2009 04:02 AM 34736 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030200.sys

c:\windows\system32\drivers\NAV\1005000.086\symndis.sys
02/27/2009 04:02 AM 37296 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030201.sys

c:\windows\system32\drivers\NAV\1005000.086\symndisv.sys
02/27/2009 04:02 AM 39984 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030202.sys

c:\windows\system32\drivers\NAV\1005000.086\symtdi.sys
02/27/2009 04:02 AM 217392 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030205.sys

c:\windows\system32\drivers\SYMEVENT.SYS
03/03/2009 03:37 PM 124464 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030016.SYS

c:\windows\system32\drivers\SymIM.sys
02/27/2009 04:02 AM 36400 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030007.sys

c:\windows\system32\drivers\VC4CB104.SYS
11/25/2001 04:11 AM 81924 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010442.SYS

c:\windows\system32\FCLKBTN.DLL
02/13/2002 03:00 AM 45056 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010444.DLL

c:\windows\system32\FINFCHECK.dll
02/27/2002 04:27 AM 65536 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010441.dll

c:\windows\system32\FINFCOPY.dll
06/25/2002 10:06 AM 45056 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010437.dll

c:\windows\system32\FREGSHEX.DLL
02/05/2002 09:33 AM 69632 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP1\A0010443.DLL

c:\windows\system32\qidmiihxfg.dll-uninst.exe
{414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP3\A0021724.exe

c:\windows\system32\S32EVNT1.DLL
03/03/2009 03:37 PM 60808 {414C40C7-9698-4DF6-BB82-64F0AEBD2F91}\RP4\A0030015.DLL
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-03-23 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-06 136600]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2007-12-14 244208]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-06-29 1032192]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-01 1392640]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-10-29 19:14 10536 ----a-w c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-03-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-03-23 72944]
R2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [2007-12-14 309744]
R2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [2007-12-14 166384]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-03 101936]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2007-12-14 1112560]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-03-23 7408]

.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = hxxp://www.superantispyware.com/applicationdisplay.html?id=1000001553&trial=no&activated=no&appid={5CFCA3FC-A40D-4613-AE0C-62217A2BA002}
FF - ProfilePath - c:\documents and settings\New-April\Application Data\Mozilla\Firefox\Profiles\gj03h6mb.default\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-28 23:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(728)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
.
Completion time: 2009-04-29 23:22
ComboFix-quarantined-files.txt 2009-04-29 06:22
ComboFix2.txt 2009-04-29 05:04

Pre-Run: 41,475,596,288 bytes free
Post-Run: 41,471,741,952 bytes free

1709 --- E O F --- 2009-04-15 10:09
  • 0

#12
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello livedead,

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<--- ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
  • 0

#13
livedead

livedead

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Hi Jimmy2012

I did not get any message about Rootkit activity. Prior to posting my issue, I had tried all the steps mentioned in the guide like the rooter, erunt etc. Please find below the contents of GMER.txt:

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-04-29 13:14:34
Windows 5.1.2600 Service Pack 2


---- Devices - GMER 1.0.15 ----

Device \FileSystem\Fastfat \Fat F7931C8A

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----
  • 0

#14
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello livedead,

Prior to posting my issue, I had tried all the steps mentioned in the guide like the rooter

I just wanted to take another look and make sure there was nothing hiding there. :)




  • Please start Malwarebytes' Anti-Malware and update it.
  • To update please do this, click Update and then click Check for Updates.
  • It will now install any updates it finds.
  • Once it is done updating please click Scanner and then click "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.








Please do an online scan with Kaspersky WebScanner
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure the following is checked.
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
~~~~~~~~~~~~~~~
In your next reply please have these logs.
The Malwarebytes log
And the Kaspersky log
  • 0

#15
livedead

livedead

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Hi Jimmy2012

The Kaspersky web scanner is not installing. I get an error message every time I try saying the application failed to initialize. The Malwarebyte logs are below. No malicious items were found

Malwarebytes' Anti-Malware 1.36
Database version: 2060
Windows 5.1.2600 Service Pack 2

4/29/2009 2:38:16 PM
mbam-log-2009-04-29 (14-38-16).txt

Scan type: Quick Scan
Objects scanned: 99486
Time elapsed: 2 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP