ComboFix 10-03-29.04 - ok 04/01/2010 14:23:06.7.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.60 [GMT 8:00]
Running from: c:\documents and settings\ok\Desktop\george.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\BitDefender\BitDefender Online Backup\ntSVc.ocx
c:\recycler\S-1-5-21-0470139243-9417863185-526554628-4960
c:\recycler\S-1-5-21-1295679671-4747332963-047672340-2482
c:\recycler\S-1-5-21-1623003875-2089148023-828350667-9924
c:\recycler\S-1-5-21-4796818899-2293880736-113404778-4796
c:\recycler\S-1-5-21-5017285481-0403918316-966136236-2737
c:\recycler\S-1-5-21-5379338124-4573719183-397162818-2314
c:\recycler\S-1-5-21-6680479454-5345885333-737425136-8233
c:\recycler\S-1-5-21-9673862540-6569721590-412745037-9644
c:\windows\system32\37.scr
c:\windows\system32\38.exe
c:\windows\system32\42.scr
c:\windows\system32\50.exe
c:\windows\system32\60.scr
c:\windows\system32\72.scr
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ABP470N5
-------\Legacy_VMWARESERVICE
-------\Service_abp470n5
((((((((((((((((((((((((( Files Created from 2010-03-01 to 2010-04-01 )))))))))))))))))))))))))))))))
.
23069-02-25 02:38 . 2009-02-25 03:37 152576 ----a-w- c:\documents and settings\ok\Application Data\Sun\Java\jre1.6.0_11\lzma.dll
23069-02-25 02:25 . 23069-02-25 02:25 -------- d-----w- c:\program files\LimeWire
23069-02-25 02:13 . 2010-04-01 06:32 -------- d-----w- c:\documents and settings\ok\Application Data\DMCache
23069-02-25 02:12 . 2010-03-26 14:00 -------- d-----w- c:\program files\Internet Download Manager
2010-03-31 05:17 . 2010-03-31 05:17 -------- d-----w- c:\program files\ERUNT
2010-03-31 00:57 . 2010-03-31 00:58 -------- d-----w- c:\program files\Ask.com
2010-03-31 00:53 . 2010-03-31 01:03 -------- d-----w- c:\documents and settings\ok\Application Data\Trillian
2010-03-31 00:51 . 2010-03-31 15:23 -------- d-----w- c:\program files\Trillian
2010-03-29 15:27 . 2010-03-29 15:39 -------- d-----w- c:\windows\SxsCaPendDel
2010-03-29 03:28 . 2010-03-29 03:27 151552 --sh--r- c:\windows\system32\xfgnl.exe
2010-03-28 08:17 . 2010-03-28 08:17 -------- d-----w- c:\documents and settings\ok\Application Data\Microsoft Games
2010-03-28 08:12 . 2010-03-28 08:12 -------- d-----w- c:\program files\GameSpy Arcade
2010-03-28 08:04 . 2010-03-28 08:04 -------- d-----w- c:\program files\Microsoft Games
2010-03-27 03:03 . 2010-03-27 03:03 4 ----a-w- c:\windows\system32\aspdict-en.dat
2010-03-27 03:03 . 2010-03-27 03:03 16 ----a-w- c:\windows\system32\asdict.dat
2010-03-26 18:58 . 2010-03-26 18:58 -------- d-----w- c:\documents and settings\ok\Application Data\BitDefender
2010-03-26 18:58 . 2010-03-26 18:58 -------- d-----w- C:\Binaries
2010-03-26 18:57 . 2010-03-26 19:04 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender
2010-03-26 18:57 . 2010-03-26 18:58 -------- d-----w- c:\program files\BitDefender
2010-03-26 18:55 . 2010-03-26 18:56 -------- d-----w- c:\windows\system32\URTTemp
2010-03-26 18:53 . 2010-03-26 18:58 -------- d-----w- c:\program files\Common Files\BitDefender
2010-03-26 14:00 . 2010-03-26 14:00 198064 ----a-w- c:\documents and settings\ok\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2010-03-26 13:56 . 2010-03-28 07:59 -------- d-----w- c:\documents and settings\ok\Application Data\IDM
2010-03-23 11:10 . 2010-03-31 13:02 -------- d-----w- c:\documents and settings\ok\Application Data\skypePM
2010-03-23 11:10 . 2010-03-23 11:10 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-03-23 11:09 . 2010-03-31 13:25 -------- d-----w- c:\documents and settings\ok\Application Data\Skype
2010-03-23 11:09 . 2010-03-23 11:09 -------- d-----w- c:\program files\Common Files\Skype
2010-03-23 11:09 . 2010-03-23 11:09 -------- d-----r- c:\program files\Skype
2010-03-23 11:08 . 2010-03-23 11:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-03-22 14:55 . 2010-03-22 14:55 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-01 04:54 . 2009-10-22 01:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-01 04:43 . 2003-08-24 16:13 -------- d-----w- c:\documents and settings\ok\Application Data\U3
2010-03-31 00:27 . 2009-08-05 21:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-03-31 00:27 . 2009-08-05 21:04 -------- d-----w- c:\program files\Yahoo!
2010-03-29 16:05 . 2009-10-26 01:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-03-29 15:33 . 2009-10-26 01:06 -------- d-----w- c:\documents and settings\ok\Application Data\Yahoo!
2010-03-29 07:24 . 2009-10-22 01:58 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 07:24 . 2009-10-22 01:58 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-27 07:13 . 2003-08-25 00:26 -------- d-----w- c:\program files\RO
2010-03-27 00:40 . 2009-12-07 10:49 106464 ----a-w- c:\windows\system32\drivers\bdhv.sys
2010-03-27 00:40 . 2009-12-07 10:46 153448 ----a-w- c:\windows\system32\drivers\bdfm.sys
2010-03-27 00:36 . 2003-08-24 16:07 -------- d-----w- c:\documents and settings\ok\Application Data\Samsung
2010-03-27 00:36 . 2003-08-24 16:06 -------- d-----w- c:\program files\Samsung
2010-03-27 00:34 . 2003-08-24 16:07 -------- d-----w- c:\program files\PC Connectivity Solution
2010-03-25 07:07 . 2010-01-02 05:53 -------- d-----w- c:\documents and settings\ok\Application Data\Orbit
.
((((((((((((((((((((((((((((( SnapShot@2003-08-24_16.23.21 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-11 16:02 . 2009-07-11 16:02 51008 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
+ 2007-11-06 18:19 . 2007-11-06 18:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2009-07-11 16:02 . 2009-07-11 16:02 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
+ 2009-07-11 16:02 . 2009-07-11 16:02 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
+ 2009-07-11 16:02 . 2009-07-11 16:02 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
+ 2009-07-11 16:02 . 2009-07-11 16:02 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
+ 2009-07-11 16:02 . 2009-07-11 16:02 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
+ 2009-07-11 16:02 . 2009-07-11 16:02 61760 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
+ 2009-07-11 16:02 . 2009-07-11 16:02 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
+ 2009-07-11 16:02 . 2009-07-11 16:02 53568 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
+ 2009-07-11 16:02 . 2009-07-11 16:02 63296 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
+ 2009-07-11 16:02 . 2009-07-11 16:02 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
+ 2009-07-11 16:02 . 2009-07-11 16:02 35648 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
+ 2008-07-29 00:05 . 2008-07-29 00:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 00:05 . 2008-07-29 00:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 00:05 . 2008-07-29 00:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 00:05 . 2008-07-29 00:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 00:05 . 2008-07-29 00:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 00:05 . 2008-07-29 00:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 00:05 . 2008-07-29 00:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 00:05 . 2008-07-29 00:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 00:05 . 2008-07-29 00:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 00:05 . 2008-07-29 00:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 00:05 . 2008-07-29 00:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2009-07-11 16:05 . 2009-07-11 16:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
+ 2009-07-11 16:05 . 2009-07-11 16:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
+ 2008-07-28 22:07 . 2008-07-28 22:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-28 22:07 . 2008-07-28 22:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2009-07-11 12:54 . 2009-07-11 12:54 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e79c4723\vcomp.dll
+ 2009-07-11 12:32 . 2009-07-11 12:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80KOR.dll
+ 2009-07-11 12:32 . 2009-07-11 12:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80JPN.dll
+ 2009-07-11 12:32 . 2009-07-11 12:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ITA.dll
+ 2009-07-11 12:32 . 2009-07-11 12:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80FRA.dll
+ 2009-07-11 12:32 . 2009-07-11 12:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ESP.dll
+ 2009-07-11 12:32 . 2009-07-11 12:32 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll
+ 2009-07-11 12:32 . 2009-07-11 12:32 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80DEU.dll
+ 2009-07-11 12:32 . 2009-07-11 12:32 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHT.dll
+ 2009-07-11 12:32 . 2009-07-11 12:32 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHS.dll
+ 2009-07-11 17:07 . 2009-07-11 17:07 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll
+ 2009-07-11 17:19 . 2009-07-11 17:19 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll
+ 2009-07-11 11:41 . 2009-07-11 11:41 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
+ 2010-03-28 08:14 . 2010-03-28 08:14 82432 c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\msxml4r.dll
+ 2010-04-01 06:31 . 2010-04-01 06:31 16384 c:\windows\temp\Perflib_Perfdata_724.dat
+ 2009-07-31 22:56 . 2009-08-06 11:24 53472 c:\windows\system32\wuauclt.exe
+ 2003-02-20 21:16 . 2003-02-20 21:16 49152 c:\windows\system32\URTTemp\regtlib.exe
+ 2010-03-26 18:55 . 2003-02-20 11:09 77824 c:\windows\system32\URTTemp\mscorsn.dll
+ 2010-03-26 16:16 . 2005-03-21 07:00 13536 c:\windows\system32\spmsg.dll
+ 2010-03-27 03:19 . 2009-08-06 11:24 44768 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.4.7600.226\wups2.dll
+ 2010-03-27 03:19 . 2009-08-06 11:24 35552 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.4.7600.226\wups.dll
+ 2003-08-24 16:08 . 2009-01-15 03:11 12160 c:\windows\system32\Samsung_USB_Drivers\7\i386\ssecwhnt.sys
+ 2003-08-24 16:08 . 2009-01-15 03:11 25856 c:\windows\system32\Samsung_USB_Drivers\7\i386\ssecnd5.sys
+ 2003-08-24 16:08 . 2009-01-15 03:11 14976 c:\windows\system32\Samsung_USB_Drivers\7\i386\ssecmdfl.sys
+ 2003-08-24 16:08 . 2009-01-15 03:11 10624 c:\windows\system32\Samsung_USB_Drivers\7\i386\sseccrnt.sys
+ 2003-08-24 16:08 . 2009-01-15 03:11 12160 c:\windows\system32\Samsung_USB_Drivers\7\i386\sseccmnt.sys
+ 2003-08-24 16:08 . 2009-01-15 03:11 86528 c:\windows\system32\Samsung_USB_Drivers\7\i386\ssecbus.sys
+ 2003-08-24 16:08 . 2007-07-05 04:38 73728 c:\windows\system32\Samsung_USB_Drivers\6_old\SSBCUninstall.exe
+ 2003-08-24 16:08 . 2007-07-05 04:38 12160 c:\windows\system32\Samsung_USB_Drivers\6_old\i386\ssbcwhnt.sys
+ 2003-08-24 16:08 . 2007-07-05 04:38 14848 c:\windows\system32\Samsung_USB_Drivers\6_old\i386\ssbcmdfl.sys
+ 2003-08-24 16:08 . 2007-07-05 04:38 12160 c:\windows\system32\Samsung_USB_Drivers\6_old\i386\ssbccmnt.sys
+ 2003-08-24 16:08 . 2007-07-05 04:38 83328 c:\windows\system32\Samsung_USB_Drivers\6_old\i386\ssbcbus.sys
+ 2003-08-24 16:08 . 2009-03-20 02:01 73728 c:\windows\system32\Samsung_USB_Drivers\6\SS_BUninstall.exe
+ 2003-08-24 16:08 . 2009-03-20 02:01 12160 c:\windows\system32\Samsung_USB_Drivers\6\i386\ss_bwhnt.sys
+ 2003-08-24 16:08 . 2009-03-20 02:01 98560 c:\windows\system32\Samsung_USB_Drivers\6\i386\ss_bserd.sys
+ 2003-08-24 16:08 . 2009-03-20 02:01 14976 c:\windows\system32\Samsung_USB_Drivers\6\i386\ss_bmdfl.sys
+ 2003-08-24 16:08 . 2009-03-20 02:01 12160 c:\windows\system32\Samsung_USB_Drivers\6\i386\ss_bcmnt.sys
+ 2003-08-24 16:08 . 2009-03-20 02:01 90112 c:\windows\system32\Samsung_USB_Drivers\6\i386\ss_bbus.sys
+ 2003-08-24 16:08 . 2009-02-25 02:13 74240 c:\windows\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
+ 2003-08-24 16:08 . 2009-02-25 02:13 12160 c:\windows\system32\Samsung_USB_Drivers\5\i386\sssdwhnt.sys
+ 2003-08-24 16:08 . 2009-02-25 02:13 14976 c:\windows\system32\Samsung_USB_Drivers\5\i386\sssdmdfl.sys
+ 2003-08-24 16:08 . 2009-02-25 02:13 12160 c:\windows\system32\Samsung_USB_Drivers\5\i386\sssdcmnt.sys
+ 2003-08-24 16:08 . 2009-02-25 02:13 87296 c:\windows\system32\Samsung_USB_Drivers\5\i386\sssdbus.sys
+ 2003-08-24 16:08 . 2007-07-03 08:53 70824 c:\windows\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
+ 2003-08-24 16:08 . 2007-07-03 08:59 86824 c:\windows\system32\Samsung_USB_Drivers\3\i386\sscdserd.sys
+ 2003-08-24 16:08 . 2007-07-03 08:57 11944 c:\windows\system32\Samsung_USB_Drivers\3\i386\sscdmdfl.sys
+ 2003-08-24 16:08 . 2007-07-03 08:54 80552 c:\windows\system32\Samsung_USB_Drivers\3\i386\sscdbus.sys
+ 2003-08-24 16:08 . 2007-05-02 03:12 72968 c:\windows\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
+ 2003-08-24 16:08 . 2007-05-02 03:12 12424 c:\windows\system32\Samsung_USB_Drivers\2\i386\ssm_whnt.sys
+ 2003-08-24 16:08 . 2007-05-02 03:12 15112 c:\windows\system32\Samsung_USB_Drivers\2\i386\ssm_mdfl.sys
+ 2003-08-24 16:08 . 2007-05-02 03:12 12424 c:\windows\system32\Samsung_USB_Drivers\2\i386\ssm_cmnt.sys
+ 2003-08-24 16:08 . 2007-05-02 03:12 83592 c:\windows\system32\Samsung_USB_Drivers\2\i386\ssm_bus.sys
+ 2003-08-24 16:08 . 2007-05-02 03:11 72968 c:\windows\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
+ 2003-08-24 16:08 . 2007-05-02 03:11 12424 c:\windows\system32\Samsung_USB_Drivers\1\i386\ss_whnt.sys
+ 2003-08-24 16:08 . 2007-05-02 03:11 15112 c:\windows\system32\Samsung_USB_Drivers\1\i386\ss_mdfl.sys
+ 2003-08-24 16:08 . 2007-05-02 03:11 12424 c:\windows\system32\Samsung_USB_Drivers\1\i386\ss_cmnt.sys
+ 2003-08-24 16:08 . 2007-05-02 03:11 83592 c:\windows\system32\Samsung_USB_Drivers\1\i386\ss_bus.sys
+ 2001-08-23 12:00 . 2010-03-26 18:57 53812 c:\windows\system32\perfc009.dat
+ 2003-08-24 16:08 . 2007-05-02 08:31 90624 c:\windows\system32\nmwcdcls.dll
+ 2003-02-20 11:16 . 2003-02-20 11:16 32768 c:\windows\system32\netfxperf.dll
+ 2003-04-18 07:29 . 2003-04-18 07:29 82432 c:\windows\system32\msxml4r.dll
+ 2002-01-04 18:38 . 2002-01-04 18:38 54784 c:\windows\system32\msvci70.dll
+ 2004-08-03 22:56 . 2005-03-21 07:00 15360 c:\windows\system32\msisip.dll
+ 2004-08-03 22:56 . 2005-03-21 07:00 78848 c:\windows\system32\msiexec.exe
+ 2003-02-20 10:43 . 2003-02-20 10:43 16896 c:\windows\system32\mscorier.dll
+ 2003-08-24 16:08 . 2009-03-31 01:39 36608 c:\windows\system32\FsUsbExDisk.Sys
+ 2003-08-24 16:08 . 2008-01-14 10:39 25600 c:\windows\system32\DRVSTORE\shpusb_558D416BCEB984F35885804D3E1A9C3773F1B17C\i386\SHPUSB.sys
+ 2003-08-24 16:08 . 2008-01-14 10:39 30208 c:\windows\system32\DRVSTORE\shpacm_18A9B92ED8DEDC602E49E767FA4BE98A30525207\i386\SHPACM.sys
+ 2003-08-24 16:08 . 2007-09-17 07:53 21632 c:\windows\system32\DRVSTORE\pccsmcfd_4A1E30386F4D0DEC8F5DF262CFBD8845EEBAB175\pccsmcfd.sys
+ 2003-08-24 16:08 . 2007-05-02 08:31 12288 c:\windows\system32\DRVSTORE\nmwcdsam2k_880D94EACF26DB5FF04E2A3B3A16959D5F0A0274\nmwcdsacm.sys
+ 2003-08-24 16:08 . 2007-05-02 08:31 12288 c:\windows\system32\DRVSTORE\nmwcdsacj_880D94EACF26DB5FF04E2A3B3A16959D5F0A0274\nmwcdsacj.sys
+ 2003-08-24 16:08 . 2007-05-02 08:31 90624 c:\windows\system32\DRVSTORE\nmwcdsa_880D94EACF26DB5FF04E2A3B3A16959D5F0A0274\nmwcdcls.dll
+ 2003-08-24 16:08 . 2009-03-20 02:01 12160 c:\windows\system32\drivers\ss_bwhnt.sys
+ 2003-08-24 16:08 . 2009-03-20 02:01 12160 c:\windows\system32\drivers\ss_bwh.sys
+ 2003-08-24 16:08 . 2009-03-20 02:01 14976 c:\windows\system32\drivers\ss_bmdfl.sys
+ 2003-08-24 16:08 . 2009-03-20 02:01 12160 c:\windows\system32\drivers\ss_bcmnt.sys
+ 2003-08-24 16:08 . 2009-03-20 02:01 12160 c:\windows\system32\drivers\ss_bcm.sys
+ 2003-08-24 16:08 . 2009-03-20 02:01 90112 c:\windows\system32\drivers\ss_bbus.sys
+ 2004-07-17 09:36 . 2003-04-19 17:17 11376 c:\windows\system32\drivers\secdrv.sys
+ 2003-08-24 16:08 . 2007-09-17 07:53 21632 c:\windows\system32\drivers\pccsmcfd.sys
+ 2009-09-22 00:22 . 2009-09-22 00:22 83208 c:\windows\system32\drivers\BDVEDISK.sys
+ 2009-12-23 01:25 . 2003-08-24 16:32 56816 c:\windows\system32\drivers\avgntflt.sys
+ 2009-07-31 22:56 . 2009-08-06 11:24 53472 c:\windows\system32\dllcache\wuauclt.exe
+ 2004-08-03 22:56 . 2005-03-21 07:00 15360 c:\windows\system32\dllcache\msisip.dll
+ 2004-08-03 22:56 . 2005-03-21 07:00 78848 c:\windows\system32\dllcache\msiexec.exe
+ 2004-08-03 22:56 . 2009-08-06 11:24 96480 c:\windows\system32\dllcache\cdm.dll
+ 2004-08-03 22:56 . 2009-08-06 11:24 96480 c:\windows\system32\cdm.dll
+ 2001-03-02 12:52 . 2001-03-02 12:52 15360 c:\windows\system32\asfsipc.dll
+ 2009-08-05 21:05 . 2005-08-18 01:39 90112 c:\windows\soundman.exe
+ 2009-08-06 11:24 . 2009-08-06 11:24 44768 c:\windows\SoftwareDistribution\SelfUpdate\Default\wups2.dll
+ 2009-08-06 11:24 . 2009-08-06 11:24 35552 c:\windows\SoftwareDistribution\SelfUpdate\Default\wups.dll
+ 2009-08-06 11:24 . 2009-08-06 11:24 53472 c:\windows\SoftwareDistribution\SelfUpdate\Default\wuauclt.exe
+ 2009-08-06 11:24 . 2009-08-06 11:24 96480 c:\windows\SoftwareDistribution\SelfUpdate\Default\cdm.dll
+ 2003-02-20 12:10 . 2003-02-20 12:10 31744 c:\windows\Microsoft.NET\Framework\v1.1.4322\WMINet_Utils.dll
+ 2003-02-20 23:24 . 2003-02-20 23:24 57344 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.RegularExpressions.dll
+ 2003-02-20 23:26 . 2003-02-20 23:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2003-02-20 11:09 . 2003-02-20 11:09 64000 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.Thunk.dll
+ 2003-02-20 23:26 . 2003-02-20 23:26 65536 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.Design.dll
+ 2003-02-20 23:26 . 2003-02-20 23:26 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.DirectoryServices.dll
+ 2003-02-20 23:26 . 2003-02-20 23:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Configuration.Install.dll
+ 2003-02-20 23:25 . 2003-02-20 23:25 12288 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegSvcs.exe
+ 2003-02-20 23:26 . 2003-02-20 23:26 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegCode.dll
+ 2003-02-20 23:25 . 2003-02-20 23:25 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegAsm.exe
+ 2003-02-20 11:09 . 2003-02-20 11:09 90112 c:\windows\Microsoft.NET\Framework\v1.1.4322\PerfCounter.dll
+ 2003-02-20 11:09 . 2003-02-20 11:09 73728 c:\windows\Microsoft.NET\Framework\v1.1.4322\ngen.exe
+ 2003-02-20 10:43 . 2003-02-20 10:43 22528 c:\windows\Microsoft.NET\Framework\v1.1.4322\MUI\0409\mscorsecr.dll
+ 2003-02-20 11:18 . 2003-02-20 11:18 20480 c:\windows\Microsoft.NET\Framework\v1.1.4322\mtxoci8.dll
+ 2003-02-20 11:09 . 2003-02-20 11:09 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2003-02-20 11:09 . 2003-02-20 11:09 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsec.dll
+ 2003-02-20 11:06 . 2003-02-20 11:06 65536 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorpe.dll
+ 2003-02-20 11:09 . 2003-02-20 11:09 98304 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2003-02-20 11:09 . 2003-02-20 11:09 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2003-02-20 11:09 . 2003-02-20 11:09 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbc.dll
+ 2003-02-20 23:25 . 2003-02-20 23:25 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\MigPolWin.exe
+ 2003-02-20 23:25 . 2003-02-20 23:25 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\MigPol.exe
+ 2003-02-20 23:25 . 2003-02-20 23:25 11264 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2003-02-20 23:24 . 2003-02-20 23:24 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.dll
+ 2003-02-20 23:24 . 2003-02-20 23:24 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.Vsa.dll
+ 2003-02-20 23:24 . 2003-02-20 23:24 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\jsc.exe
+ 2003-02-20 23:24 . 2003-02-20 23:24 26112 c:\windows\Microsoft.NET\Framework\v1.1.4322\ISymWrapper.dll
+ 2003-02-20 11:22 . 2003-02-20 11:22 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\InstallUtilLib.dll
+ 2003-02-20 23:24 . 2003-02-20 23:24 15872 c:\windows\Microsoft.NET\Framework\v1.1.4322\InstallUtil.exe
+ 2003-02-20 23:24 . 2003-02-20 23:24 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEHost.dll
+ 2003-02-20 20:12 . 2003-02-20 20:12 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\cvtres.exe
+ 2003-02-20 23:24 . 2003-02-20 23:24 33792 c:\windows\Microsoft.NET\Framework\v1.1.4322\CustomMarshalers.dll
+ 2003-02-20 23:24 . 2003-02-20 23:24 12288 c:\windows\Microsoft.NET\Framework\v1.1.4322\cscompmgd.dll
+ 2003-02-21 02:20 . 2003-02-21 02:20 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\csc.exe
+ 2003-02-20 11:09 . 2003-02-20 11:09 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2003-02-20 23:24 . 2003-02-20 23:24 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe
+ 2003-02-20 23:24 . 2003-02-20 23:24 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\CasPol.exe
+ 2003-02-20 11:19 . 2003-02-20 11:19 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2003-02-20 11:19 . 2003-02-20 11:19 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
+ 2003-02-20 11:19 . 2003-02-20 11:19 20480 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_regiis.exe
+ 2003-02-20 11:19 . 2003-02-20 11:19 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_rc.dll
+ 2003-02-20 11:19 . 2003-02-20 11:19 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2003-02-20 21:00 . 2003-02-20 21:00 98304 c:\windows\Microsoft.NET\Framework\v1.1.4322\alink.dll
+ 2003-02-20 19:55 . 2003-02-20 19:55 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\cscompui.dll
+ 2003-02-20 18:59 . 2003-02-20 18:59 16896 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\alinkui.dll
+ 2003-02-20 11:09 . 2003-02-20 11:09 57344 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
+ 2010-03-28 08:14 . 2010-03-28 08:14 89600 c:\windows\Installer\8ca4.msi
+ 2003-08-24 16:08 . 2003-08-24 16:08 10134 c:\windows\Installer\{AC599724-5755-48C1-ABE7-ABB857652930}\ARPPRODUCTICON.exe
+ 2010-03-26 18:59 . 2010-03-26 18:59 57344 c:\windows\Installer\{1895A08A-0DEC-4855-B1F4-1B95FB39901B}\texticon.exe
+ 2010-03-26 18:59 . 2010-03-26 18:59 32768 c:\windows\Installer\{1895A08A-0DEC-4855-B1F4-1B95FB39901B}\maintenance_icon.exe
+ 2010-03-26 18:59 . 2010-03-26 18:59 61440 c:\windows\Installer\{1895A08A-0DEC-4855-B1F4-1B95FB39901B}\helpicon.exe
+ 2010-03-26 18:56 . 2010-03-26 18:56 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_b959e1ae\System.Drawing.Design.dll
+ 2010-03-26 18:56 . 2010-03-26 18:56 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_780b15c2\CustomMarshalers.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 57344 c:\windows\assembly\GAC\System.Web.RegularExpressions\1.0.5000.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 77824 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 64000 c:\windows\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.Thunk.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 65536 c:\windows\assembly\GAC\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 86016 c:\windows\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 77824 c:\windows\assembly\GAC\System.Configuration.Install\1.0.5000.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 32768 c:\windows\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\RegCode.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 32768 c:\windows\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 11264 c:\windows\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 28672 c:\windows\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 26112 c:\windows\assembly\GAC\ISymWrapper\1.0.5000.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 32768 c:\windows\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\IEHost.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 33792 c:\windows\assembly\GAC\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 12288 c:\windows\assembly\GAC\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2003-08-24 16:08 . 2007-07-03 09:00 9256 c:\windows\system32\Samsung_USB_Drivers\3\i386\sscdwhnt.sys
+ 2003-08-24 16:08 . 2007-07-03 08:56 9256 c:\windows\system32\Samsung_USB_Drivers\3\i386\sscdcmnt.sys
+ 2001-03-02 12:52 . 2001-03-02 12:52 8704 c:\windows\system32\npwmsdrm.dll
+ 2003-02-20 10:43 . 2003-02-20 10:43 4096 c:\windows\system32\mui\0409\mscoreer.dll
+ 2003-08-24 16:08 . 2008-01-14 10:39 6656 c:\windows\system32\DRVSTORE\shpacm_18A9B92ED8DEDC602E49E767FA4BE98A30525207\i386\SHPACMFilter.sys
+ 2003-08-24 16:08 . 2007-05-02 08:31 8320 c:\windows\system32\DRVSTORE\nmwcdsac_880D94EACF26DB5FF04E2A3B3A16959D5F0A0274\nmwcdsac.sys
+ 2007-10-25 09:26 . 2007-10-25 09:26 5632 c:\windows\system32\drivers\StarOpen.sys
+ 2003-02-20 11:09 . 2003-02-20 11:09 9216 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscortim.dll
+ 2003-02-20 23:25 . 2003-02-20 23:25 6656 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft_VsaVb.dll
+ 2003-02-20 23:25 . 2003-02-20 23:25 6144 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualC.Dll
+ 2003-02-20 23:24 . 2003-02-20 23:24 4608 c:\windows\Microsoft.NET\Framework\v1.1.4322\IIEHost.dll
+ 2003-02-20 23:24 . 2003-02-20 23:24 7168 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEExecRemote.dll
+ 2003-02-20 23:24 . 2003-02-20 23:24 7680 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEExec.exe
+ 2003-02-20 23:24 . 2003-02-20 23:24 7680 c:\windows\Microsoft.NET\Framework\v1.1.4322\Accessibility.dll
+ 2003-02-20 11:09 . 2003-02-20 11:09 5120 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
+ 2002-05-14 01:42 . 2002-05-14 01:42 5120 c:\windows\Microsoft.NET\Framework\sbs_wminet_utils.dll
+ 2002-06-27 04:45 . 2002-06-27 04:45 5120 c:\windows\Microsoft.NET\Framework\sbs_VsaVb7rt.dll
+ 2002-05-14 01:42 . 2002-05-14 01:42 5120 c:\windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll
+ 2002-05-14 01:42 . 2002-05-14 01:42 5120 c:\windows\Microsoft.NET\Framework\sbs_system.data.dll
+ 2002-05-14 01:42 . 2002-05-14 01:42 5120 c:\windows\Microsoft.NET\Framework\sbs_system.configuration.install.dll
+ 2002-05-14 01:42 . 2002-05-14 01:42 5120 c:\windows\Microsoft.NET\Framework\sbs_mscorsec.dll
+ 2002-07-19 03:52 . 2002-07-19 03:52 5120 c:\windows\Microsoft.NET\Framework\sbs_mscorrc.dll
+ 2002-05-14 01:42 . 2002-05-14 01:42 5120 c:\windows\Microsoft.NET\Framework\sbs_mscordbi.dll
+ 2002-05-14 01:42 . 2002-05-14 01:42 5632 c:\windows\Microsoft.NET\Framework\sbs_microsoft.vsa.vb.codedomprocessor.dll
+ 2002-05-14 01:42 . 2002-05-14 01:42 5120 c:\windows\Microsoft.NET\Framework\sbs_microsoft.jscript.dll
+ 2002-05-14 01:42 . 2002-05-14 01:42 5120 c:\windows\Microsoft.NET\Framework\sbs_iehost.dll
+ 2002-05-14 01:42 . 2002-05-14 01:42 5120 c:\windows\Microsoft.NET\Framework\sbs_diasymreader.dll
+ 2003-08-24 16:08 . 2003-08-24 16:08 3262 c:\windows\Installer\{7E84FAC8-C518-40F9-9807-7455301D6D25}\ARPPRODUCTICON.exe
+ 2010-03-26 18:55 . 2010-03-26 18:55 6656 c:\windows\assembly\GAC\Microsoft_VsaVb\7.0.5000.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 6144 c:\windows\assembly\GAC\Microsoft.VisualC\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualC.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 4608 c:\windows\assembly\GAC\IIEHost\1.0.5000.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 7168 c:\windows\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 7680 c:\windows\assembly\GAC\Accessibility\1.0.5000.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2009-07-11 16:02 . 2009-07-11 16:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-07-11 16:02 . 2009-07-11 16:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
+ 2009-07-11 16:05 . 2009-07-11 16:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
+ 2008-07-29 00:05 . 2008-07-29 00:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 00:05 . 2008-07-29 00:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-28 19:54 . 2008-07-28 19:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2009-07-11 16:02 . 2009-07-11 16:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2008-07-29 00:05 . 2008-07-29 00:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2009-07-11 17:12 . 2009-07-11 17:12 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
+ 2009-07-11 17:09 . 2009-07-11 17:09 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
+ 2009-07-11 17:08 . 2009-07-11 17:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
+ 2007-01-31 05:50 . 2007-01-31 05:50 913408 c:\windows\system32\xreglib.dll
+ 2009-07-31 22:56 . 2009-08-06 11:24 209632 c:\windows\system32\wuweb.dll
+ 2009-07-31 22:56 . 2009-08-06 11:24 327896 c:\windows\system32\wucltui.dll
+ 2009-07-31 22:56 . 2009-08-06 11:23 575704 c:\windows\system32\wuapi.dll
+ 2001-05-09 08:50 . 2001-05-09 08:50 446464 c:\windows\system32\wmvdmoe.dll
+ 2001-05-09 08:47 . 2001-05-09 08:47 466944 c:\windows\system32\wmv8dmoe.dll
+ 2001-05-09 09:40 . 2001-05-09 09:40 309584 c:\windows\system32\wmv8dmod.dll
+ 2010-03-26 18:55 . 2003-02-20 20:42 348160 c:\windows\system32\URTTemp\msvcr71.dll
+ 2010-03-26 18:55 . 2003-02-20 11:06 155648 c:\windows\system32\URTTemp\mscoree.dll
+ 2010-03-26 18:55 . 2003-02-20 11:06 282624 c:\windows\system32\URTTemp\fusion.dll
+ 2009-01-15 04:45 . 2009-01-15 04:45 181248 c:\windows\system32\txmlutil.dll
+ 2003-08-24 16:08 . 2009-03-09 07:20 103936 c:\windows\system32\Samsung_USB_Drivers\7\SSECUninstall.exe
+ 2003-08-24 16:08 . 2009-01-15 03:11 109312 c:\windows\system32\Samsung_USB_Drivers\7\i386\ssecunic.sys
+ 2003-08-24 16:08 . 2009-01-15 03:11 104192 c:\windows\system32\Samsung_USB_Drivers\7\i386\ssecobex.sys
+ 2003-08-24 16:08 . 2009-01-15 03:11 108032 c:\windows\system32\Samsung_USB_Drivers\7\i386\ssecmgmt.sys
+ 2003-08-24 16:08 . 2009-01-15 03:11 114304 c:\windows\system32\Samsung_USB_Drivers\7\i386\ssecmdm.sys
+ 2003-08-24 16:08 . 2007-07-05 04:38 109696 c:\windows\system32\Samsung_USB_Drivers\6_old\i386\ssbcmdm.sys
+ 2003-08-24 16:08 . 2009-03-20 02:01 121856 c:\windows\system32\Samsung_USB_Drivers\6\i386\ss_bmdm.sys
+ 2003-08-24 16:08 . 2009-02-25 02:13 106368 c:\windows\system32\Samsung_USB_Drivers\5\i386\sssdobex.sys
+ 2003-08-24 16:08 . 2009-02-25 02:13 110208 c:\windows\system32\Samsung_USB_Drivers\5\i386\sssdmgmt.sys
+ 2003-08-24 16:08 . 2009-02-25 02:13 115968 c:\windows\system32\Samsung_USB_Drivers\5\i386\sssdmdm.sys
+ 2003-08-24 16:08 . 2007-07-03 08:58 106792 c:\windows\system32\Samsung_USB_Drivers\3\i386\sscdmdm.sys
+ 2003-08-24 16:08 . 2007-05-02 03:12 109704 c:\windows\system32\Samsung_USB_Drivers\2\i386\ssm_mdm.sys
+ 2003-08-24 16:08 . 2007-05-02 03:11 109704 c:\windows\system32\Samsung_USB_Drivers\1\i386\ss_mdm.sys
+ 2001-08-23 12:00 . 2010-03-26 18:57 383584 c:\windows\system32\perfh009.dat
+ 2003-02-20 19:42 . 2003-02-20 19:42 348160 c:\windows\system32\msvcr71.dll
+ 2002-01-04 17:37 . 2002-01-04 17:37 344064 c:\windows\system32\msvcr70.dll
+ 2003-03-18 11:14 . 2003-03-18 11:14 499712 c:\windows\system32\msvcp71.dll
+ 2002-01-04 18:40 . 2002-01-04 18:40 487424 c:\windows\system32\msvcp70.dll
+ 2004-08-03 22:56 . 2005-03-21 07:00 884736 c:\windows\system32\msimsg.dll
- 2004-08-03 22:56 . 2004-08-03 22:56 884736 c:\windows\system32\msimsg.dll
+ 2004-08-03 22:56 . 2005-03-21 07:00 271360 c:\windows\system32\msihnd.dll
+ 2003-02-20 11:09 . 2003-02-20 11:09 106496 c:\windows\system32\mscories.dll
+ 2003-02-20 11:06 . 2003-02-20 11:06 155648 c:\windows\system32\mscoree.dll
+ 2004-03-31 04:28 . 2004-03-31 04:28 131072 c:\windows\system32\mapi32.dll
+ 23069-02-25 02:26 . 2010-03-29 01:27 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 23069-02-25 02:26 . 2003-08-24 17:14 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2010-01-27 01:07 . 2010-01-27 01:07 256280 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2010-01-27 00:58 . 2010-01-27 00:58 256280 c:\windows\system32\Macromed\Flash\FlashUtil10e.exe
+ 2009-12-29 04:58 . 2009-12-29 04:57 149280 c:\windows\system32\javaws.exe
+ 2009-12-29 04:58 . 2009-12-29 04:57 145184 c:\windows\system32\javaw.exe
+ 2009-12-29 04:58 . 2009-12-29 04:57 145184 c:\windows\system32\java.exe
+ 2010-01-25 14:48 . 2009-09-09 10:43 210352 c:\windows\system32\idmmbc.dll
+ 2003-08-24 16:08 . 2009-03-31 01:39 233472 c:\windows\system32\FsUsbExService.Exe
+ 2003-08-24 16:08 . 2009-03-31 01:39 110592 c:\windows\system32\FsUsbExDevice.Dll
+ 2003-08-24 16:08 . 2008-03-06 03:14 831048 c:\windows\system32\DRVSTORE\pccswpddri_CAEB6BB34654D5A4CAB32D7967078BA417F01F05\WudfUpdate_01005.dll
+ 2003-08-24 16:08 . 2008-03-06 03:19 534016 c:\windows\system32\DRVSTORE\pccswpddri_CAEB6BB34654D5A4CAB32D7967078BA417F01F05\PCCSWpdDriver.dll
+ 2003-08-24 16:08 . 2007-05-02 08:32 135680 c:\windows\system32\DRVSTORE\nmwcdsa_880D94EACF26DB5FF04E2A3B3A16959D5F0A0274\nmwcdsa.sys
+ 2003-08-24 16:08 . 2009-03-20 02:01 121856 c:\windows\system32\drivers\ss_bmdm.sys
+ 2009-07-24 03:26 . 2009-07-24 03:26 285704 c:\windows\system32\drivers\bdfsfltr.sys
+ 2009-10-19 08:04 . 2009-10-19 08:04 110984 c:\windows\system32\drivers\bdfndisf.sys
+ 2009-07-31 22:56 . 2009-08-06 11:24 209632 c:\windows\system32\dllcache\wuweb.dll
+ 2009-07-31 22:56 . 2009-08-06 11:24 327896 c:\windows\system32\dllcache\wucltui.dll
+ 2009-07-31 22:56 . 2009-08-06 11:23 575704 c:\windows\system32\dllcache\wuapi.dll
- 2004-08-03 22:56 . 2004-08-03 22:56 884736 c:\windows\system32\dllcache\msimsg.dll
+ 2004-08-03 22:56 . 2005-03-21 07:00 884736 c:\windows\system32\dllcache\msimsg.dll
+ 2004-08-03 22:56 . 2005-03-21 07:00 271360 c:\windows\system32\dllcache\msihnd.dll
+ 2009-12-29 04:58 . 2009-12-29 04:57 411368 c:\windows\system32\deploytk.dll
+ 2007-04-11 02:11 . 2007-04-11 02:11 511328 c:\windows\system32\capicom.dll
+ 2009-08-06 11:24 . 2009-08-06 11:24 209632 c:\windows\SoftwareDistribution\SelfUpdate\Default\wuweb.dll
+ 2009-08-06 11:24 . 2009-08-06 11:24 327896 c:\windows\SoftwareDistribution\SelfUpdate\Default\wucltui.dll
+ 2009-08-06 11:23 . 2009-08-06 11:23 575704 c:\windows\SoftwareDistribution\SelfUpdate\Default\wuapi.dll
+ 2003-02-21 02:20 . 2003-02-21 02:20 737280 c:\windows\Microsoft.NET\Framework\v1.1.4322\vbc.exe
+ 2003-02-20 23:27 . 2003-02-20 23:27 569344 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.Services.dll
+ 2003-02-20 23:27 . 2003-02-20 23:27 819200 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.Mobile.dll
+ 2003-02-20 23:27 . 2003-02-20 23:27 126976 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.ServiceProcess.dll
+ 2003-02-20 23:26 . 2003-02-20 23:26 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Serialization.Formatters.Soap.dll
+ 2003-02-20 23:26 . 2003-02-20 23:26 323584 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Remoting.dll
+ 2003-02-20 23:26 . 2003-02-20 23:26 241664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Messaging.dll
+ 2003-02-20 23:26 . 2003-02-20 23:26 368640 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Management.dll
+ 2003-02-20 23:26 . 2003-02-20 23:26 241664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.dll
+ 2003-02-20 23:26 . 2003-02-20 23:26 466944 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.dll
+ 2003-02-20 23:25 . 2003-02-20 23:25 299008 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.OracleClient.dll
+ 2003-02-20 11:09 . 2003-02-20 11:09 319488 c:\windows\Microsoft.NET\Framework\v1.1.4322\SOS.dll
+ 2003-02-20 11:09 . 2003-02-20 11:09 122880 c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusres.dll
+ 2003-02-20 11:09 . 2003-02-20 11:09 253952 c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusion.dll
+ 2003-02-20 20:42 . 2003-02-20 20:42 348160 c:\windows\Microsoft.NET\Framework\v1.1.4322\msvcr71.dll
+ 2003-02-20 11:09 . 2003-02-20 11:09 143360 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorrc.dll
+ 2003-02-20 10:43 . 2003-02-20 10:43 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscormmc.dll
+ 2003-02-20 11:06 . 2003-02-20 11:06 311296 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2003-02-20 11:09 . 2003-02-20 11:09 233472 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbi.dll
+ 2003-02-20 23:26 . 2003-02-20 23:26 299008 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.dll
+ 2003-02-20 23:26 . 2003-02-20 23:26 716800 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.JScript.dll
+ 2003-02-20 11:09 . 2003-02-20 11:09 196608 c:\windows\Microsoft.NET\Framework\v1.1.4322\ilasm.exe
+ 2003-02-20 11:06 . 2003-02-20 11:06 282624 c:\windows\Microsoft.NET\Framework\v1.1.4322\fusion.dll
+ 2003-02-20 11:16 . 2003-02-20 11:16 798720 c:\windows\Microsoft.NET\Framework\v1.1.4322\EventLogMessages.dll
+ 2003-02-21 02:21 . 2003-02-21 02:21 524288 c:\windows\Microsoft.NET\Framework\v1.1.4322\diasymreader.dll
+ 2003-02-21 02:21 . 2003-02-21 02:21 626688 c:\windows\Microsoft.NET\Framework\v1.1.4322\cscomp.dll
+ 2002-07-29 03:11 . 2002-07-29 03:11 219136 c:\windows\Microsoft.NET\Framework\v1.1.4322\c_g18030.dll
+ 2003-02-20 11:19 . 2003-02-20 11:19 253952 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2003-02-20 21:04 . 2003-02-20 21:04 155648 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\Vsavb7rtUI.dll
+ 2003-02-20 19:02 . 2003-02-20 19:02 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\vbc7ui.dll
+ 2003-02-20 10:43 . 2003-02-20 10:43 131072 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
+ 2010-03-29 15:28 . 2010-03-29 15:28 424960 c:\windows\Installer\84dda4.msi
+ 2009-12-29 04:56 . 2009-12-29 04:56 537600 c:\windows\Installer\75e308.msi
+ 2009-12-23 01:23 . 2009-12-23 01:23 228352 c:\windows\Installer\718f8.msi
+ 2003-08-24 16:08 . 2003-08-24 16:08 176128 c:\windows\Installer\4ec10.msi
+ 2003-08-24 16:08 . 2003-08-24 16:08 487424 c:\windows\Installer\4ec0b.msi
+ 2010-03-26 12:58 . 2010-03-26 12:58 219648 c:\windows\Installer\41ac94.msi
+ 2010-03-23 11:09 . 2010-03-23 11:09 371272 c:\windows\Installer\{D103C4BA-F905-437A-8049-DB24763BBE36}\SkypeIcon.exe
+ 2010-03-31 00:58 . 2010-03-31 00:58 102400 c:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\ARPPRODUCTICON.exe
+ 2010-03-26 18:59 . 2010-03-26 18:59 336782 c:\windows\Installer\{1895A08A-0DEC-4855-B1F4-1B95FB39901B}\register_icon.exe
+ 2010-03-31 05:23 . 2010-03-31 05:23 212992 c:\windows\ERDNT\3-31-2010\Users\00000002\UsrClass.dat
+ 2010-03-31 05:23 . 2005-10-20 04:02 163328 c:\windows\ERDNT\3-31-2010\ERDNT.EXE
+ 2010-03-26 18:56 . 2010-03-26 18:56 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_6485f581\System.Drawing.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 569344 c:\windows\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 819200 c:\windows\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 126976 c:\windows\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 131072 c:\windows\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 323584 c:\windows\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 241664 c:\windows\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 368640 c:\windows\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\System.Management.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 241664 c:\windows\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 466944 c:\windows\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 299008 c:\windows\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 299008 c:\windows\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 716800 c:\windows\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2009-07-11 16:02 . 2009-07-11 16:02 3780424 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
+ 2009-07-11 16:02 . 2009-07-11 16:02 3765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll
+ 2008-07-29 00:05 . 2008-07-29 00:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 00:05 . 2008-07-29 00:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
+ 2009-07-11 12:46 . 2009-07-11 12:46 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll
+ 2009-07-11 12:46 . 2009-07-11 12:46 1105920 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll
+ 2010-03-28 08:14 . 2010-03-28 08:14 1230336 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da\msxml4.dll
+ 2009-07-31 22:56 . 2009-08-06 11:23 1929952 c:\windows\system32\wuaueng.dll
+ 2010-03-26 18:55 . 2003-02-20 11:08 2482176 c:\windows\system32\URTTemp\mscorwks.dll
+ 2003-04-18 07:46 . 2003-04-18 07:46 1233920 c:\windows\system32\msxml4.dll
+ 2004-08-03 22:56 . 2005-03-21 07:00 2890240 c:\windows\system32\msi.dll
+ 2010-01-27 01:07 . 2010-01-27 01:07 3884312 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2009-07-31 22:56 . 2009-08-06 11:23 1929952 c:\windows\system32\dllcache\wuaueng.dll
+ 2004-08-03 22:56 . 2005-03-21 07:00 2890240 c:\windows\system32\dllcache\msi.dll
+ 2009-08-06 11:23 . 2009-08-06 11:23 1929952 c:\windows\SoftwareDistribution\SelfUpdate\Default\wuaueng.dll
+ 2003-02-20 21:04 . 2003-02-20 21:04 1032192 c:\windows\Microsoft.NET\Framework\v1.1.4322\VsaVb7rt.dll
+ 2003-02-20 23:27 . 2003-02-20 23:27 1335296 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.XML.dll
+ 2003-02-20 23:27 . 2003-02-20 23:27 2039808 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Windows.Forms.dll
+ 2003-02-20 23:27 . 2003-02-20 23:27 1245184 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2003-02-20 23:26 . 2003-02-20 23:26 1216512 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2003-02-20 23:26 . 2003-02-20 23:26 1699840 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Design.dll
+ 2003-02-20 23:26 . 2003-02-20 23:26 1290240 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.dll
+ 2003-02-20 11:08 . 2003-02-20 11:08 2482176 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2003-02-20 11:07 . 2003-02-20 11:07 2494464 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2003-02-20 23:26 . 2003-02-20 23:26 2088960 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2003-02-20 23:25 . 2003-02-20 23:25 1564672 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorcfg.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 3449344 c:\windows\Installer\88bb20.msi
+ 2010-03-31 00:58 . 2010-03-31 00:58 1860608 c:\windows\Installer\2268cb.msi
+ 2010-03-23 11:09 . 2010-03-23 11:09 1575936 c:\windows\Installer\218f91.msi
+ 2010-03-31 05:23 . 2010-03-31 05:23 2142208 c:\windows\ERDNT\3-31-2010\Users\00000001\NTUSER.DAT
+ 2010-03-26 18:56 . 2010-03-26 18:56 1929216 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_9f401b81\System.dll
+ 2010-03-26 18:56 . 2010-03-26 18:56 2076672 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_e8ebf174\System.Xml.dll
+ 2010-03-26 18:56 . 2010-03-26 18:56 2994176 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_955ff0ed\System.Windows.Forms.dll
+ 2010-03-26 18:56 . 2010-03-26 18:56 1462272 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_d37ffc3a\System.Design.dll
+ 2010-03-26 18:56 . 2010-03-26 18:56 3289088 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_04593493\mscorlib.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 1216512 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 1335296 c:\windows\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\System.Xml.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 2039808 c:\windows\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 1245184 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 1699840 c:\windows\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Design.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 1290240 c:\windows\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\System.Data.dll
+ 2010-03-26 18:55 . 2010-03-26 18:55 1564672 c:\windows\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\mscorcfg.dll
+ 2010-03-26 18:59 . 2010-03-26 18:59 21731328 c:\windows\Installer\88bb27.msi
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-08 1362320]
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-02-08 09:40 1362320 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-08 1362320]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\ok\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-03-22 136176]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2010-01-25 3179952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2005-08-18 90112]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-29 149280]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2010\IEShow.exe" [2009-10-19 71152]
"BDAgent"="c:\program files\BitDefender\BitDefender 2010\bdagent.exe" [2010-01-20 1120704]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\McAfee Security Scan\\1.0.150\\McUICnt.exe"=
"c:\\WINDOWS\\SOUNDMAN.EXE"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"c:\\Program Files\\Mozilla Firefox\\uninstall\\helper.exe"=
"c:\\Program Files\\Granado Espada\\ge.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1309:TCP"= 1309:TCP:sbkie
"3917:TCP"= 3917:TCP:rotuo
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [8/6/2009 5:03 AM 13696]
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2010\bdvedisk.sys [9/22/2009 8:22 AM 83208]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [12/7/2009 6:46 PM 153448]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [10/19/2009 4:04 PM 110984]
S2 pupic;Task Universal;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 6:56 AM 14336]
S2 rrvqfjqz;Config Task;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 6:56 AM 14336]
S2 sbquwk;Security Microsoft;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 6:56 AM 14336]
S2 vottywqu;Support Image;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 6:56 AM 14336]
S2 yzzmxaq;Driver Center;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 6:56 AM 14336]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [10/19/2009 4:06 PM 183880]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [8/25/2003 12:08 AM 36608]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [8/25/2003 12:08 AM 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [8/25/2003 12:08 AM 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [8/25/2003 12:08 AM 121856]
S3 XDva295;XDva295;\??\c:\windows\system32\XDva295.sys --> c:\windows\system32\XDva295.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
dcxsnpux
nqwvetk
xneyhq
pupic
vottywqu
sbquwk
rrvqfjqz
yzzmxaq
.
Contents of the 'Scheduled Tasks' folder
2010-03-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1326574676-682003330-1003Core.job
- c:\documents and settings\ok\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-22 14:31]
2010-04-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1326574676-682003330-1003UA.job
- c:\documents and settings\ok\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-22 14:31]
2010-04-01 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-02-08 09:40]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://yahoo.com/
uInternet Settings,ProxyServer = 0.0.0.0:80
IE: &Google Search - c:\program files\Google\googletoolbar.dll/cmsearch.html
IE: Backward &Links - c:\program files\Google\googletoolbar.dll/cmbacklinks.html
IE: Cac&hed Snapshot of Page - c:\program files\Google\googletoolbar.dll/cmcache.html
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Si&milar Pages - c:\program files\Google\googletoolbar.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\googletoolbar.dll/cmtrans.html
LSP: c:\windows\system32\idmmbc.dll
FF - ProfilePath - c:\documents and settings\ok\Application Data\Mozilla\Firefox\Profiles\zc5edf01.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.ph/
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true.
- - - - ORPHANS REMOVED - - - -
BHO-{74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - (no file)
AddRemove-BearShare MediaBar - c:\program files\BearShare Applications\BearShare MediaBar\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-04-01 14:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\SetID\Internal]
@Denied: (A 2) (LocalSystem)
"DATA"="<settings expireTime=\"0\" productStatus=\"1\" obSize=\"0\" InstallTS=\"2145870353\" isSubsc=\"0\" version=\"12.0.1\" timeDiff=\"1\" oldDevice=\"\" authStatus_ts=\"0\" />"
"Device"="yM29zbvPzMnLvrm+x8fPzce+zro="
DUMPHIVE0.003 (REGF)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{09e0bc77-0c45-4363-aeaf-8ef1e8f64498}]
@Denied: (Full) (Everyone)
"Model"=dword:00000112
"Therad"=dword:0000002b
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):7c,af,e6,4a,95,8c,9f,9a,ba,bd,27,3b,7d,10,68,11,44,46,99,54,eb,
e8,59,f3,9a,0c,7d,ba,7a,03,d1,a4,2b,65,fc,8f,ec,84,30,5c,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):e9,88,8a,48,30,8e,bb,84,dc,cb,ff,38,75,cc,53,26,73,cb,54,17,f4,
f1,48,10,ab,1e,98,6c,ad,14,46,56,d3,ab,d9,a0,b6,ea,91,fc,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9c20e4cd-a7b9-414d-abf4-cbd6b8cae9c5}]
@Denied: (Full) (Everyone)
"Model"=dword:00000057
"Therad"=dword:00000002
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(856)
c:\windows\system32\idmmbc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\SOUNDMAN.EXE
c:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 2010-04-01 14:37:31 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-01 06:37
ComboFix2.txt 2009-10-30 01:39
ComboFix3.txt 2009-10-27 00:07
ComboFix4.txt 2009-10-26 00:12
ComboFix5.txt 2010-04-01 06:21
Pre-Run: 22,084,579,328 bytes free
Post-Run: 22,046,228,480 bytes free
- - End Of File - - 7D3CF5024E2C4A8D8BC37B64C24B2EB3
Thanks for helping