Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Trojan Virus | PC running slow | Internet connection breaking off


  • This topic is locked This topic is locked

#1
kingfisher3210

kingfisher3210

    Member

  • Member
  • PipPip
  • 42 posts
Hello Experts,

I did trend micro online and it found 11 trojans and 40 suspicious items. It cleaned few trojans and advised to restart PC to clean other trojans. How ever at the time of restarting i could not restart windows XP normally and restarted with previous known configuration.

When ever i try to restart windows XP in normal mode, a blue error screen comes. It does not work in safe mode also. When ever i try to restart in safe mode, a blue error screen comes.

Also internet connection keeps breaking off and PC and internet is working slow.

Big thanks in advance to experts who are helping fellow human beings and contributing a lot to global economic growth.

Regards,

Kevin



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:16:29 PM, on 2/9/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Airtel NetXpert\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Airtel NetXpert\bin\tgsrvc.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\DOCUME~1\admin\LOCALS~1\Temp\49859.exe
C:\Program Files\Airtel NetXpert\bin\sprtcmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\wibyw.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\ClickToConvert\C2CMonitor.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\SetPoint\SetPoint.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\admin\LOCALS~1\Temp\pbzo2C441C87.tmp
C:\DOCUME~1\admin\LOCALS~1\Temp\dx2EAABABC.tmp
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.h...sario&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [netxpert] "C:\Program Files\Airtel NetXpert\bin\sprtcmd.exe" /P netxpert
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [gouzoohed] C:\WINDOWS\system32\dumoo.exe
O4 - HKLM\..\Run: [jykussa] C:\WINDOWS\system32\wibyw.exe
O4 - HKLM\..\Run: [coobaroo] C:\WINDOWS\system32\wibyw.exe
O4 - HKLM\..\Run: [vipezou] C:\WINDOWS\system32\tokynnou.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [{A2BECEDB-7C95-C9DE-98EB-83BED9D92E06}] "C:\Documents and Settings\admin\Application Data\Ehuxo\okqu.exe"
O4 - HKUS\S-1-5-18\..\Run: [vipezou] C:\Documents and Settings\LocalService\Application Data\Microsoft\tokynnou.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [vipezou] C:\Documents and Settings\LocalService\Application Data\Microsoft\tokynnou.exe (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: C2CMonitor.lnk = C:\Program Files\ClickToConvert\C2CMonitor.exe
O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: SetPoint.lnk = C:\Program Files\SetPoint\SetPoint.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.ad...Plus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{72525BAD-B524-46BB-BE84-7B331246C8C9}: NameServer = 202.56.215.54,202.56.215.55
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Asset Management Daemon (aaznw6e6uioa36ey) - Unknown owner - C:\WINDOWS\system32\lycoquepa.exe (file missing)
O23 - Service: bcveServ (aiwyuaiuyrteisiy) - Unknown owner - C:\WINDOWS\system32\boozu.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative ALchemy AL1 Licensing Service (cneesoy8ik) - Unknown owner - C:\WINDOWS\system32\noune.exe (file missing)
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (netxpert) (sprtsvc_netxpert) - SupportSoft, Inc. - C:\Program Files\Airtel NetXpert\bin\sprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe
O23 - Service: SupportSoft Repair Service (netxpert) (tgsrvc_netxpert) - SupportSoft, Inc. - C:\Program Files\Airtel NetXpert\bin\tgsrvc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 8442 bytes

Edited by kingfisher3210, 09 February 2011 - 05:40 AM.

  • 0

Advertisements


#2
ali.B

ali.B

    Trusted Helper

  • Malware Removal
  • 3,086 posts
Hello kingfisher3210 :D

Before we begin, I would like to make a few things clear so that we can fix your problem as efficiently as possible:
  • Be sure to follow all my instructions carefully! If there is anything you don''t understand, don't hesitate to ask.
  • Please do not do anything or perform other steps unless I have asked you to do so.
  • Please make sure you post all logs I ask you to, and make sure that the entire log gets posted.


Step 1

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan bot paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Step 2

Download the GMER Rootkit Scanner.

  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe.
    Posted Image
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan...click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED ...
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
      Posted Image
      Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

Please copy and paste the report into your Post.


Things I would like to see in your reply:
  • OTL.txt and Extras.txt
  • GMER Log ark.txt

  • 0

#3
kingfisher3210

kingfisher3210

    Member

  • Topic Starter
  • Member
  • PipPip
  • 42 posts
OTL Extras logfile created on: 2/9/2011 10:12:13 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = D:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

478.00 Mb Total Physical Memory | 108.00 Mb Available Physical Memory | 22.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 1.74 Gb Free Space | 8.90% Space Free | Partition Type: NTFS
Drive D: | 19.53 Gb Total Space | 15.11 Gb Free Space | 77.36% Space Free | Partition Type: NTFS
Drive E: | 16.81 Gb Total Space | 2.55 Gb Free Space | 15.19% Space Free | Partition Type: NTFS

Computer Name: BHARAT | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"7005:TCP" = 7005:TCP:*:Enabled:fhyyy

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Computer, Inc.)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe" = C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe:*:Enabled:FreeCall
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Disabled:Windows Explorer -- (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{026873C3-DBAD-488F-A8D4-1379EE0CA8AB}" = HP Software Update
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 20
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{3248F0A8-6813-11D6-A77B-00B0D0150000}" = J2SE Runtime Environment 5.0
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = HP Integrated Module with Bluetooth wireless technology
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F94119D-1B71-400e-9F04-B4E5CEAE71F8}_is1" = Sothink Movie DVD Maker
"{51BA0AFE-6AA5-4B8C-8BA9-FA6AE5B1EEE0}" = Roxio Media Manager
"{534AA552-E1F1-4965-B2AA-FBDEB0730D60}" = muvee autoProducer 4.0 - SE
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84F1B62A-E6F6-458E-BC19-51DBB14055EA}" = BlackBerry Desktop Software 4.7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8E50332B-772C-4AEA-BF56-94DE6A1D5F10}" = TIxx21
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver
"{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio Module
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic Copy Module
"{BE20E2F5-1903-4AAE-B1AF-2046E586C925}" = iTunes
"{C900EF06-2E76-49C7-8DB0-41F629B21DC5}" = hp psc 1200 series
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BC}" = WinZip 14.0
"{CEB326EC-8F40-47B2-BA22-BB092565D66F}" = Quick Launch Buttons 5.10 B2
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = SetPoint
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Airtel NetXpert_is1" = Airtel NetXpert 3.0
"AviSynth" = AviSynth 2.5
"BitTorrent" = BitTorrent
"BlackBerry_{84F1B62A-E6F6-458E-BC19-51DBB14055EA}" = BlackBerry Desktop Software 4.7
"Broadcom 802.11b Network Adapter" = Broadcom 802.11 Wireless LAN Adapter
"Burn My Files_is1" = Burn My Files
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_8086&DEV_24C6&SUBSYS_3080103C" = SoftV90 Data Fax Modem with SmartCP
"Conexant PCI Audio" = Conexant AC-Link Audio
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Defraggler" = Defraggler
"ffdshow_is1" = ffdshow [rev 2583] [2009-01-05]
"FreeCall_is1" = FreeCall
"HaaliMkx" = Haali Media Splitter
"HP PSC 1200 Series" = HP Photo and Imaging 2.0 - hp psc 1200 series
"InstallShield_{8E50332B-772C-4AEA-BF56-94DE6A1D5F10}" = Texas Instruments PCIxx21/x515 drivers.
"InstallShield_{BE20E2F5-1903-4AAE-B1AF-2046E586C925}" = iTunes
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"QuickTime" = QuickTime
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 1.1.2
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/9/2011 7:33:26 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 9:11:24 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 9:11:24 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 9:21:26 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 9:21:26 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 10:48:24 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 10:48:24 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 11:11:26 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 11:11:26 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 12:28:24 PM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

[ Application Events ]
Error - 2/9/2011 7:33:26 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 9:11:24 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 9:11:24 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 9:21:26 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 9:21:26 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 10:48:24 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 10:48:24 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 11:11:26 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 11:11:26 AM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/9/2011 12:28:24 PM | Computer Name = BHARAT | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

[ System Events ]
Error - 2/9/2011 2:47:05 AM | Computer Name = BHARAT | Source = Service Control Manager | ID = 7000
Description = The Microsoft Kernel Acoustic Echo Canceller service failed to start
due to the following error: %%31

Error - 2/9/2011 6:17:14 AM | Computer Name = BHARAT | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 2/9/2011 6:17:14 AM | Computer Name = BHARAT | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {03CA98D6-FF5D-49B8-ABC6-03DD84127020}

Error - 2/9/2011 6:17:17 AM | Computer Name = BHARAT | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {6D18AD12-BDE3-4393-B311-099C346E6DF9}

Error - 2/9/2011 6:17:17 AM | Computer Name = BHARAT | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {F087771F-D74F-4C1A-BB8A-E16ACA9124EA}

Error - 2/9/2011 6:17:17 AM | Computer Name = BHARAT | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 2/9/2011 7:33:47 AM | Computer Name = BHARAT | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 2/9/2011 7:34:07 AM | Computer Name = BHARAT | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 2/9/2011 7:35:10 AM | Computer Name = BHARAT | Source = Service Control Manager | ID = 7023
Description = The System Installer service terminated with the following error:
%%2

Error - 2/9/2011 7:35:10 AM | Computer Name = BHARAT | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher
9 service to connect.


< End of report >
  • 0

#4
kingfisher3210

kingfisher3210

    Member

  • Topic Starter
  • Member
  • PipPip
  • 42 posts
OTL logfile created on: 2/9/2011 10:12:13 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = D:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

478.00 Mb Total Physical Memory | 108.00 Mb Available Physical Memory | 22.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 1.74 Gb Free Space | 8.90% Space Free | Partition Type: NTFS
Drive D: | 19.53 Gb Total Space | 15.11 Gb Free Space | 77.36% Space Free | Partition Type: NTFS
Drive E: | 16.81 Gb Total Space | 2.55 Gb Free Space | 15.19% Space Free | Partition Type: NTFS

Computer Name: BHARAT | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/09 20:58:00 | 000,602,624 | ---- | M] (OldTimer Tools) -- D:\OTL.exe
PRC - [2010/07/23 03:32:16 | 000,945,720 | ---- | M] (Google Inc.) -- C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2010/05/10 12:32:46 | 000,185,640 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Airtel NetXpert\bin\tgsrvc.exe
PRC - [2010/05/10 12:32:44 | 000,206,120 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Airtel NetXpert\bin\sprtsvc.exe
PRC - [2010/05/10 12:32:44 | 000,206,120 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Airtel NetXpert\bin\sprtcmd.exe
PRC - [2010/02/04 14:00:00 | 000,495,432 | R--- | M] (WinZip Computing, S.L.) -- C:\Program Files\WinZip\WZQKPICK.EXE
PRC - [2009/09/14 16:32:10 | 000,414,720 | ---- | M] () -- C:\Program Files\ClickToConvert\C2CMonitor.exe
PRC - [2009/07/20 12:30:50 | 000,813,584 | ---- | M] (Logitech, Inc.) -- C:\Program Files\SetPoint\SetPoint.exe
PRC - [2009/07/10 12:42:32 | 000,055,824 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
PRC - [2008/11/10 02:18:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/14 17:30:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/09/11 04:40:32 | 000,218,032 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
PRC - [2006/02/15 16:16:02 | 000,581,693 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2004/06/16 18:34:12 | 000,147,456 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
PRC - [2004/06/16 18:22:58 | 000,028,672 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
PRC - [2004/06/16 17:59:18 | 000,286,720 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe


========== Modules (SafeList) ==========

MOD - [2011/02/09 20:58:00 | 000,602,624 | ---- | M] (OldTimer Tools) -- D:\OTL.exe
MOD - [2010/05/10 12:32:44 | 000,116,008 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Airtel NetXpert\bin\sprthook.dll
MOD - [2009/07/20 12:29:06 | 000,045,584 | ---- | M] (Logitech, Inc.) -- C:\Program Files\SetPoint\lgscroll.dll
MOD - [2009/07/12 01:12:06 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
MOD - [2008/04/14 17:30:00 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcp60.dll
MOD - [2006/02/15 16:17:26 | 000,053,248 | ---- | M] () -- C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (cneesoy8ik)
SRV - File not found [Auto | Stopped] -- -- (aiwyuaiuyrteisiy)
SRV - File not found [Auto | Stopped] -- -- (aaznw6e6uioa36ey)
SRV - [2010/05/10 12:32:46 | 000,185,640 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Airtel NetXpert\bin\tgsrvc.exe -- (tgsrvc_netxpert) SupportSoft Repair Service (netxpert)
SRV - [2010/05/10 12:32:44 | 000,206,120 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Airtel NetXpert\bin\sprtsvc.exe -- (sprtsvc_netxpert) SupportSoft Sprocket Service (netxpert)
SRV - [2009/07/21 12:38:56 | 000,386,424 | ---- | M] (SupportSoft, Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe -- (SupportSoft RemoteAssist)
SRV - [2008/11/10 02:18:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2003/03/09 11:01:02 | 000,065,795 | R--- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\vrzgeevn.sys -- (prlvncekqpw)
DRV - [2011/02/08 22:58:40 | 000,052,096 | ---- | M] () [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\drivers\llluxos.sys -- (pjbgnrc)
DRV - [2011/02/08 07:36:36 | 000,000,000 | ---- | M] () [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\drivers\xbombr.sys -- (jdbagqqmuxntxdu)
DRV - [2009/06/17 22:26:32 | 000,028,560 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2009/06/17 22:26:16 | 000,037,392 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2009/06/17 22:26:06 | 000,035,472 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2009/06/17 22:25:34 | 000,010,384 | ---- | M] (Logitech, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\LBeepKE.sys -- (LBeepKE)
DRV - [2008/04/14 17:30:00 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008/04/14 17:30:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2008/04/14 17:30:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2008/04/14 03:35:40 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2006/02/15 15:59:52 | 000,401,664 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2006/02/15 15:56:58 | 001,342,570 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2006/02/15 15:54:46 | 000,030,363 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2006/02/15 15:54:10 | 000,057,096 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2006/02/15 15:51:22 | 000,148,168 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2006/02/15 15:50:14 | 000,044,163 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwhid.sys -- (btwhid)
DRV - [2005/02/11 06:22:36 | 000,157,056 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21)
DRV - [2004/12/15 04:48:34 | 000,207,232 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWICH.sys -- (HSFHWICH)
DRV - [2004/12/15 04:48:28 | 000,703,232 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2004/12/15 04:48:26 | 001,038,208 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2004/12/02 22:06:08 | 000,070,912 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtlnicxp.sys -- (RTL8023xp)
DRV - [2004/11/23 20:27:56 | 000,280,192 | R--- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\camchal.sys -- (CAMCHALA)
DRV - [2004/11/23 20:27:12 | 000,293,120 | R--- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\camcaud.sys -- (CAMCAUD)
DRV - [2004/11/22 16:11:16 | 003,222,784 | R--- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Intel®
DRV - [2004/11/04 23:56:42 | 000,186,016 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2004/04/14 07:36:50 | 000,007,432 | ---- | M] (Hewlett-Packard Company) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\eabfiltr.sys -- (eabfiltr)
DRV - [2003/06/06 11:46:16 | 000,005,220 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\EabUsb.sys -- (eabusb)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2008/04/14 17:30:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [netxpert] C:\Program Files\Airtel NetXpert\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [{A2BECEDB-7C95-C9DE-98EB-83BED9D92E06}] File not found
O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\C2CMonitor.lnk = C:\Program Files\ClickToConvert\C2CMonitor.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe (Research In Motion Limited)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SetPoint.lnk = C:\Program Files\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: TaskMan - (C:\RECYCLER\S-1-5-21-6109066214-9338792590-022010046-8386\sjbsi2d.exe) - C:\RECYCLER\S-1-5-21-6109066214-9338792590-022010046-8386\sjbsi2d.exe ()
O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\admin\fxmdk.exe) - File not found
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\RECYCLER\S-1-5-21-6109066214-9338792590-022010046-8386\sjbsi2d.exe) - C:\RECYCLER\S-1-5-21-6109066214-9338792590-022010046-8386\sjbsi2d.exe ()
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/21 17:25:01 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010/03/06 02:16:42 | 000,000,090 | ---- | M] () - E:\AUTORUN.INF -- [ NTFS ]
O33 - MountPoints2\{5ed3b710-3409-11df-b881-00c09f81ac98}\Shell\AutoRun\command - "" = H:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\cutephoto.exe
O33 - MountPoints2\{5ed3b710-3409-11df-b881-00c09f81ac98}\Shell\open\command - "" = H:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\cutephoto.exe
O33 - MountPoints2\{b6ac0704-7528-11de-b865-00c09f81ac98}\Shell\AutoRun\command - "" = G:\dsncb.exe
O33 - MountPoints2\{b6ac0704-7528-11de-b865-00c09f81ac98}\Shell\Explore\Command - "" = G:\dsncb.exe
O33 - MountPoints2\{b6ac0704-7528-11de-b865-00c09f81ac98}\Shell\Open\Command - "" = G:\dsncb.exe
O33 - MountPoints2\{f3a0fc4e-40a9-11df-b8b8-00c09f81ac98}\Shell - "" = AutoRun
O33 - MountPoints2\{f3a0fc4e-40a9-11df-b8b8-00c09f81ac98}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f3a0fc4e-40a9-11df-b8b8-00c09f81ac98}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\setupSNK.exe -- [2008/04/14 05:42:42 | 000,028,672 | ---- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)

========== Files/Folders - Created Within 30 Days ==========

[2011/02/09 12:17:04 | 000,736,256 | ---- | C] (Windows ® Codename Longhorn DDK provider) -- C:\WINDOWS\System32\drivers\uagxgo.sys
[2011/02/09 12:16:06 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011/02/09 12:16:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin\Start Menu\Programs\HiJackThis
[2011/02/09 11:55:07 | 000,189,520 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/02/08 23:49:51 | 000,315,408 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2011/02/08 23:49:50 | 000,019,472 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klmouflt.sys
[2011/02/08 23:49:47 | 000,036,880 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klbg.sys
[2011/02/08 23:49:41 | 000,088,632 | ---- | C] (Infowatch) -- C:\WINDOWS\System32\drivers\CSCrySec.sys
[2011/02/08 23:49:40 | 000,039,352 | ---- | C] (Infowatch) -- C:\WINDOWS\System32\drivers\CSVirtualDiskDrv.sys
[2011/02/08 23:49:18 | 000,000,000 | --SD | C] -- C:\Documents and Settings\admin\My Documents\Passwords Database
[2011/02/08 23:17:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2011/02/08 23:11:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[27 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/09 22:02:00 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1060284298-1844823847-299502267-1003UA.job
[2011/02/09 17:37:00 | 000,000,390 | ---- | M] () -- C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1269518597.job
[2011/02/09 17:03:08 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/02/09 17:03:02 | 501,731,328 | -HS- | M] () -- C:\hiberfil.sys
[2011/02/09 17:00:59 | 000,736,256 | ---- | M] (Windows ® Codename Longhorn DDK provider) -- C:\WINDOWS\System32\drivers\uagxgo.sys
[2011/02/09 16:59:19 | 000,102,400 | ---- | M] () -- C:\WINDOWS\RegBootClean.exe
[2011/02/09 16:59:19 | 000,011,264 | ---- | M] () -- C:\WINDOWS\DCEBoot.exe
[2011/02/09 16:59:19 | 000,003,700 | ---- | M] () -- C:\WINDOWS\DCEBOOT.CFG
[2011/02/09 12:16:14 | 000,002,447 | ---- | M] () -- C:\Documents and Settings\admin\Desktop\HiJackThis.lnk
[2011/02/08 23:10:49 | 000,315,408 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2011/02/08 22:58:40 | 000,052,096 | ---- | M] () -- C:\WINDOWS\System32\drivers\llluxos.sys
[2011/02/08 20:59:25 | 000,074,240 | ---- | M] () -- C:\Documents and Settings\admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/08 18:00:58 | 000,000,256 | ---- | M] () -- C:\WINDOWS\System32\pool.bin
[2011/02/08 10:02:01 | 000,000,926 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1060284298-1844823847-299502267-1003Core.job
[2011/02/08 09:39:39 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\admin\Local Settings\Application Data\housecall.guid.cache
[2011/02/08 07:36:36 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\xbombr.sys
[2011/02/08 07:32:39 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/02/07 18:40:38 | 000,002,324 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2011/02/07 18:25:05 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[27 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/09 12:16:06 | 000,002,447 | ---- | C] () -- C:\Documents and Settings\admin\Desktop\HiJackThis.lnk
[2011/02/09 12:08:32 | 000,011,264 | ---- | C] () -- C:\WINDOWS\DCEBoot.exe
[2011/02/09 12:08:32 | 000,003,700 | ---- | C] () -- C:\WINDOWS\DCEBOOT.CFG
[2011/02/09 12:08:28 | 000,102,400 | ---- | C] () -- C:\WINDOWS\RegBootClean.exe
[2011/02/08 22:59:29 | 501,731,328 | -HS- | C] () -- C:\hiberfil.sys
[2011/02/08 09:39:39 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\admin\Local Settings\Application Data\housecall.guid.cache
[2011/02/08 07:57:02 | 000,052,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\llluxos.sys
[2011/02/07 18:48:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\drivers\xbombr.sys
[2011/02/07 18:47:48 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\admin\Application Data\HhdFJl61DD.txt
[2011/02/07 18:40:38 | 000,002,324 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2011/02/07 18:25:05 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
[2010/09/23 23:24:10 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010/09/03 12:20:12 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2010/06/29 18:03:24 | 000,217,088 | ---- | C] () -- C:\WINDOWS\System32\LPng.dll
[2010/03/25 17:10:49 | 000,000,390 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010/03/25 17:07:34 | 000,561,152 | R--- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2009/07/20 18:03:14 | 000,074,240 | ---- | C] () -- C:\Documents and Settings\admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/29 16:49:10 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/05/29 13:58:50 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/02/15 16:04:52 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2005/02/12 14:03:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/11/14 12:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll

========== LOP Check ==========

[2011/02/07 22:25:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\BitTorrent
[2010/04/23 20:40:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Blackberry Desktop
[2011/02/09 12:08:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Ehuxo
[2010/03/31 23:48:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\FreeCall
[2010/03/23 15:50:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Intervideo
[2010/08/14 00:04:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Kaosr
[2010/09/23 00:07:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Leadertech
[2009/11/29 22:26:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Research In Motion
[2010/07/22 18:32:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bharti
[2009/07/20 18:15:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InterVideo
[2010/03/30 22:32:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2010/03/21 17:20:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2010/07/22 18:35:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/09/24 01:28:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/09/23 14:32:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2011/02/09 17:37:00 | 000,000,390 | ---- | M] () -- C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1269518597.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/03/21 17:01:51 | 000,015,414 | ---- | M] () -- C:\adobelog.txt
[2010/03/21 17:25:01 | 000,000,050 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010/03/21 19:25:18 | 000,000,192 | ---- | M] () -- C:\BcBtRmv.log
[2009/05/29 11:25:30 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2010/03/21 18:54:18 | 003,396,856 | ---- | M] (Piriform Ltd) -- C:\ccsetup229.exe
[2010/03/21 17:46:22 | 000,000,090 | ---- | M] () -- C:\chpst.log
[2009/05/29 11:47:31 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2010/03/21 17:09:17 | 003,207,344 | ---- | M] () -- C:\DNSP1.LOG
[2011/02/09 17:03:02 | 501,731,328 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/31 18:09:21 | 000,000,522 | ---- | M] () -- C:\hpfr3420.xml
[2010/08/31 18:09:21 | 000,014,095 | ---- | M] () -- C:\hpfr3425.log
[2010/03/21 17:13:28 | 000,000,171 | ---- | M] () -- C:\HSC.log
[2009/05/29 11:47:31 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/03/21 17:30:52 | 000,000,196 | ---- | M] () -- C:\mscuxp.log
[2009/05/29 11:47:31 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2010/03/21 17:27:06 | 000,000,192 | ---- | M] () -- C:\muvee.log
[2008/04/14 17:30:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/04/14 17:30:00 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2011/02/09 17:03:00 | 754,974,720 | -HS- | M] () -- C:\pagefile.sys
[2010/03/21 17:24:59 | 000,000,200 | ---- | M] () -- C:\setup.log
[2010/03/21 17:37:25 | 000,020,928 | ---- | M] () -- C:\sunjava.log
[2010/03/21 16:53:39 | 000,000,191 | ---- | M] () -- C:\syntp.log
[2010/03/21 16:38:26 | 000,000,032 | ---- | M] () -- C:\ticrdbus.log

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/05/29 16:46:42 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2009/05/29 16:46:42 | 001,089,536 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2009/05/29 16:46:42 | 000,901,120 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-03-22 15:37:16

========== Alternate Data Streams ==========

@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC6124CA

< End of report >
  • 0

#5
kingfisher3210

kingfisher3210

    Member

  • Topic Starter
  • Member
  • PipPip
  • 42 posts
Thanks Ali.B for your assistance. I appreciate your time.

The problem is GMER Rootkit Scanner is not working. When ever i click Run to open GMER Rootkit Scanner, nothing happens. I have tried it couple of times and it is not opening.
  • 0

#6
ali.B

ali.B

    Trusted Helper

  • Malware Removal
  • 3,086 posts
hi

Step 1

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    SRV - File not found [Auto | Stopped] -- -- (cneesoy8ik)
    SRV - File not found [Auto | Stopped] -- -- (aiwyuaiuyrteisiy)
    SRV - File not found [Auto | Stopped] -- -- (aaznw6e6uioa36ey)
    DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\vrzgeevn.sys -- (prlvncekqpw)
    DRV - [2011/02/08 22:58:40 | 000,052,096 | ---- | M] () [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\drivers\llluxos.sys -- (pjbgnrc)
    DRV - [2011/02/08 07:36:36 | 000,000,000 | ---- | M] () [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\drivers\xbombr.sys -- (jdbagqqmuxntxdu)
    O4 - HKCU..\Run: [{A2BECEDB-7C95-C9DE-98EB-83BED9D92E06}] File not found
    O20 - HKLM Winlogon: TaskMan - (C:\RECYCLER\S-1-5-21-6109066214-9338792590-022010046-8386\sjbsi2d.exe) - C:\RECYCLER\S-1-5-21-6109066214-9338792590-022010046-8386\sjbsi2d.exe ()
    O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\admin\fxmdk.exe) - File not found
    O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - HKCU Winlogon: Shell - (C:\RECYCLER\S-1-5-21-6109066214-9338792590-022010046-8386\sjbsi2d.exe) - C:\RECYCLER\S-1-5-21-6109066214-9338792590-022010046-8386\sjbsi2d.exe ()
    O33 - MountPoints2\{5ed3b710-3409-11df-b881-00c09f81ac98}\Shell\AutoRun\command - "" = H:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\cutephoto.exe
    O33 - MountPoints2\{5ed3b710-3409-11df-b881-00c09f81ac98}\Shell\open\command - "" = H:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\cutephoto.exe
    O33 - MountPoints2\{b6ac0704-7528-11de-b865-00c09f81ac98}\Shell\AutoRun\command - "" = G:\dsncb.exe
    O33 - MountPoints2\{b6ac0704-7528-11de-b865-00c09f81ac98}\Shell\Explore\Command - "" = G:\dsncb.exe
    O33 - MountPoints2\{b6ac0704-7528-11de-b865-00c09f81ac98}\Shell\Open\Command - "" = G:\dsncb.exe
    O33 - MountPoints2\{f3a0fc4e-40a9-11df-b8b8-00c09f81ac98}\Shell - "" = AutoRun
    O33 - MountPoints2\{f3a0fc4e-40a9-11df-b8b8-00c09f81ac98}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{f3a0fc4e-40a9-11df-b8b8-00c09f81ac98}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
    O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\setupSNK.exe -- [2008/04/14 05:42:42 | 000,028,672 | ---- | M] (Microsoft Corporation)
    
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Step 2

Download ComboFix here :

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Here is a guide on how to disable them

    Click me

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Posted Image



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.


Things I would like to see in your reply:
  • OTL log
  • Combofix.txt

  • 0

#7
kingfisher3210

kingfisher3210

    Member

  • Topic Starter
  • Member
  • PipPip
  • 42 posts
All processes killed
========== OTL ==========
Service cneesoy8ik stopped successfully!
Service cneesoy8ik deleted successfully!
Service aiwyuaiuyrteisiy stopped successfully!
Service aiwyuaiuyrteisiy deleted successfully!
Service aaznw6e6uioa36ey stopped successfully!
Service aaznw6e6uioa36ey deleted successfully!
Service prlvncekqpw stopped successfully!
Service prlvncekqpw deleted successfully!
C:\WINDOWS\system32\drivers\vrzgeevn.sys moved successfully.
Service pjbgnrc stopped successfully!
Service pjbgnrc deleted successfully!
C:\WINDOWS\system32\drivers\llluxos.sys moved successfully.
Service jdbagqqmuxntxdu stopped successfully!
Service jdbagqqmuxntxdu deleted successfully!
C:\WINDOWS\system32\drivers\xbombr.sys moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\{A2BECEDB-7C95-C9DE-98EB-83BED9D92E06} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A2BECEDB-7C95-C9DE-98EB-83BED9D92E06}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\TaskMan:C:\RECYCLER\S-1-5-21-6109066214-9338792590-022010046-8386\sjbsi2d.exe deleted successfully.
C:\RECYCLER\S-1-5-21-6109066214-9338792590-022010046-8386\sjbsi2d.exe moved successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Documents and Settings\admin\fxmdk.exe deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:explorer.exe deleted successfully.
Item C:\WINDOWS\explorer.exe is whitelisted and cannot be moved.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\RECYCLER\S-1-5-21-6109066214-9338792590-022010046-8386\sjbsi2d.exe deleted successfully.
File C:\RECYCLER\S-1-5-21-6109066214-9338792590-022010046-8386\sjbsi2d.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5ed3b710-3409-11df-b881-00c09f81ac98}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5ed3b710-3409-11df-b881-00c09f81ac98}\ not found.
File H:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\cutephoto.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5ed3b710-3409-11df-b881-00c09f81ac98}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5ed3b710-3409-11df-b881-00c09f81ac98}\ not found.
File H:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\cutephoto.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b6ac0704-7528-11de-b865-00c09f81ac98}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b6ac0704-7528-11de-b865-00c09f81ac98}\ not found.
File G:\dsncb.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b6ac0704-7528-11de-b865-00c09f81ac98}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b6ac0704-7528-11de-b865-00c09f81ac98}\ not found.
File G:\dsncb.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b6ac0704-7528-11de-b865-00c09f81ac98}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b6ac0704-7528-11de-b865-00c09f81ac98}\ not found.
File G:\dsncb.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f3a0fc4e-40a9-11df-b8b8-00c09f81ac98}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f3a0fc4e-40a9-11df-b8b8-00c09f81ac98}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f3a0fc4e-40a9-11df-b8b8-00c09f81ac98}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f3a0fc4e-40a9-11df-b8b8-00c09f81ac98}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f3a0fc4e-40a9-11df-b8b8-00c09f81ac98}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f3a0fc4e-40a9-11df-b8b8-00c09f81ac98}\ not found.
File C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ deleted successfully.
E:\setupSNK.exe moved successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: admin
->Temp folder emptied: 2240381112 bytes
->Temporary Internet Files folder emptied: 6422485 bytes
->Java cache emptied: 143294 bytes
->Google Chrome cache emptied: 29470274 bytes
->Flash cache emptied: 1963088 bytes

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: SYSTEM
->Temp folder emptied: 6962976 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2402044 bytes
%systemroot%\System32 .tmp files removed: 6990005 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3792181 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 2,192.00 mb


[EMPTYFLASH]

User: admin
->Flash cache emptied: 0 bytes

User: Administrator

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: SYSTEM

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.20.6 log created on 02102011_100009

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...
  • 0

#8
kingfisher3210

kingfisher3210

    Member

  • Topic Starter
  • Member
  • PipPip
  • 42 posts
OTL logfile created on: 2/10/2011 10:07:32 AM - Run 2
OTL by OldTimer - Version 3.2.20.6 Folder = D:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

478.00 Mb Total Physical Memory | 129.00 Mb Available Physical Memory | 27.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 3.73 Gb Free Space | 19.10% Space Free | Partition Type: NTFS
Drive D: | 19.53 Gb Total Space | 15.09 Gb Free Space | 77.25% Space Free | Partition Type: NTFS
Drive E: | 16.81 Gb Total Space | 2.55 Gb Free Space | 15.19% Space Free | Partition Type: NTFS

Computer Name: BHARAT | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/10 10:07:10 | 000,602,624 | ---- | M] (OldTimer Tools) -- D:\OTL (2).exe
PRC - [2010/11/30 15:00:00 | 000,608,584 | R--- | M] (WinZip Computing, S.L.) -- C:\Program Files\WinZip\WZQKPICK.EXE
PRC - [2010/07/23 03:32:16 | 000,945,720 | ---- | M] (Google Inc.) -- C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2010/05/10 12:32:46 | 000,185,640 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Airtel NetXpert\bin\tgsrvc.exe
PRC - [2010/05/10 12:32:44 | 000,206,120 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Airtel NetXpert\bin\sprtsvc.exe
PRC - [2010/05/10 12:32:44 | 000,206,120 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Airtel NetXpert\bin\sprtcmd.exe
PRC - [2009/09/14 16:32:10 | 000,414,720 | ---- | M] () -- C:\Program Files\ClickToConvert\C2CMonitor.exe
PRC - [2009/07/20 12:30:50 | 000,813,584 | ---- | M] (Logitech, Inc.) -- C:\Program Files\SetPoint\SetPoint.exe
PRC - [2009/07/10 12:42:32 | 000,055,824 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
PRC - [2008/11/10 02:18:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/14 17:30:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/09/11 04:40:32 | 000,218,032 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
PRC - [2006/02/15 16:16:02 | 000,581,693 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2004/06/16 18:34:12 | 000,147,456 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
PRC - [2004/06/16 18:22:58 | 000,028,672 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
PRC - [2004/06/16 17:59:18 | 000,286,720 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe


========== Modules (SafeList) ==========

MOD - [2011/02/10 10:07:10 | 000,602,624 | ---- | M] (OldTimer Tools) -- D:\OTL (2).exe
MOD - [2010/05/10 12:32:44 | 000,116,008 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Airtel NetXpert\bin\sprthook.dll
MOD - [2009/07/20 12:29:06 | 000,045,584 | ---- | M] (Logitech, Inc.) -- C:\Program Files\SetPoint\lgscroll.dll
MOD - [2009/07/12 01:12:06 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
MOD - [2008/04/14 17:30:00 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcp60.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2010/05/10 12:32:46 | 000,185,640 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Airtel NetXpert\bin\tgsrvc.exe -- (tgsrvc_netxpert) SupportSoft Repair Service (netxpert)
SRV - [2010/05/10 12:32:44 | 000,206,120 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Airtel NetXpert\bin\sprtsvc.exe -- (sprtsvc_netxpert) SupportSoft Sprocket Service (netxpert)
SRV - [2009/07/21 12:38:56 | 000,386,424 | ---- | M] (SupportSoft, Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe -- (SupportSoft RemoteAssist)
SRV - [2008/11/10 02:18:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2003/03/09 11:01:02 | 000,065,795 | R--- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)


========== Driver Services (SafeList) ==========

DRV - [2009/06/17 22:26:32 | 000,028,560 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2009/06/17 22:26:16 | 000,037,392 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2009/06/17 22:26:06 | 000,035,472 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2009/06/17 22:25:34 | 000,010,384 | ---- | M] (Logitech, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\LBeepKE.sys -- (LBeepKE)
DRV - [2008/04/14 17:30:00 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008/04/14 17:30:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2008/04/14 17:30:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2008/04/14 03:35:40 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2006/02/15 15:59:52 | 000,401,664 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2006/02/15 15:56:58 | 001,342,570 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2006/02/15 15:54:46 | 000,030,363 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2006/02/15 15:54:10 | 000,057,096 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2006/02/15 15:51:22 | 000,148,168 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2006/02/15 15:50:14 | 000,044,163 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwhid.sys -- (btwhid)
DRV - [2005/02/11 06:22:36 | 000,157,056 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21)
DRV - [2004/12/15 04:48:34 | 000,207,232 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWICH.sys -- (HSFHWICH)
DRV - [2004/12/15 04:48:28 | 000,703,232 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2004/12/15 04:48:26 | 001,038,208 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2004/12/02 22:06:08 | 000,070,912 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtlnicxp.sys -- (RTL8023xp)
DRV - [2004/11/23 20:27:56 | 000,280,192 | R--- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\camchal.sys -- (CAMCHALA)
DRV - [2004/11/23 20:27:12 | 000,293,120 | R--- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\camcaud.sys -- (CAMCAUD)
DRV - [2004/11/22 16:11:16 | 003,222,784 | R--- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Intel®
DRV - [2004/11/04 23:56:42 | 000,186,016 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2004/04/14 07:36:50 | 000,007,432 | ---- | M] (Hewlett-Packard Company) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\eabfiltr.sys -- (eabfiltr)
DRV - [2003/06/06 11:46:16 | 000,005,220 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\EabUsb.sys -- (eabusb)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2011/02/10 10:00:15 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [netxpert] C:\Program Files\Airtel NetXpert\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\C2CMonitor.lnk = C:\Program Files\ClickToConvert\C2CMonitor.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe (Research In Motion Limited)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SetPoint.lnk = C:\Program Files\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/21 17:25:01 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010/03/06 02:16:42 | 000,000,090 | ---- | M] () - E:\AUTORUN.INF -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/02/09 22:58:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinZip
[2011/02/09 22:57:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin\Local Settings\Application Data\WinZip
[2011/02/09 22:57:29 | 000,000,000 | ---D | C] -- C:\Program Files\WinZip
[2011/02/09 12:17:04 | 000,736,256 | ---- | C] (Windows ® Codename Longhorn DDK provider) -- C:\WINDOWS\System32\drivers\uagxgo.sys
[2011/02/09 12:16:06 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011/02/09 12:16:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin\Start Menu\Programs\HiJackThis
[2011/02/09 11:55:07 | 000,189,520 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/02/08 23:49:51 | 000,315,408 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2011/02/08 23:49:50 | 000,019,472 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klmouflt.sys
[2011/02/08 23:49:47 | 000,036,880 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klbg.sys
[2011/02/08 23:49:41 | 000,088,632 | ---- | C] (Infowatch) -- C:\WINDOWS\System32\drivers\CSCrySec.sys
[2011/02/08 23:49:40 | 000,039,352 | ---- | C] (Infowatch) -- C:\WINDOWS\System32\drivers\CSVirtualDiskDrv.sys
[2011/02/08 23:49:18 | 000,000,000 | --SD | C] -- C:\Documents and Settings\admin\My Documents\Passwords Database
[2011/02/08 23:17:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE

========== Files - Modified Within 30 Days ==========

[2011/02/10 10:04:55 | 000,000,256 | ---- | M] () -- C:\WINDOWS\System32\pool.bin
[2011/02/10 10:04:43 | 000,000,431 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2011/02/10 10:02:21 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/02/10 10:02:20 | 501,731,328 | -HS- | M] () -- C:\hiberfil.sys
[2011/02/10 10:00:15 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2011/02/09 23:05:37 | 000,288,107 | ---- | M] () -- C:\Documents and Settings\admin\Desktop\gmer.zip
[2011/02/09 23:02:00 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1060284298-1844823847-299502267-1003UA.job
[2011/02/09 22:58:01 | 000,001,732 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2011/02/09 22:58:01 | 000,001,660 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2011/02/09 17:37:00 | 000,000,390 | ---- | M] () -- C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1269518597.job
[2011/02/09 17:03:37 | 000,184,887 | ---- | M] () -- C:\WINDOWS\System32\drivers\str.sys
[2011/02/09 17:00:59 | 000,736,256 | ---- | M] (Windows ® Codename Longhorn DDK provider) -- C:\WINDOWS\System32\drivers\uagxgo.sys
[2011/02/09 16:59:19 | 000,102,400 | ---- | M] () -- C:\WINDOWS\RegBootClean.exe
[2011/02/09 16:59:19 | 000,011,264 | ---- | M] () -- C:\WINDOWS\DCEBoot.exe
[2011/02/09 16:59:19 | 000,003,700 | ---- | M] () -- C:\WINDOWS\DCEBOOT.CFG
[2011/02/09 12:16:14 | 000,002,447 | ---- | M] () -- C:\Documents and Settings\admin\Desktop\HiJackThis.lnk
[2011/02/08 23:10:49 | 000,315,408 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2011/02/08 20:59:25 | 000,074,240 | ---- | M] () -- C:\Documents and Settings\admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/08 10:02:01 | 000,000,926 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1060284298-1844823847-299502267-1003Core.job
[2011/02/08 09:39:39 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\admin\Local Settings\Application Data\housecall.guid.cache
[2011/02/08 07:32:39 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/02/07 18:40:38 | 000,002,324 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2011/02/07 18:25:05 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf

========== Files Created - No Company Name ==========

[2011/02/09 23:05:34 | 000,288,107 | ---- | C] () -- C:\Documents and Settings\admin\Desktop\gmer.zip
[2011/02/09 22:58:01 | 000,001,732 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2011/02/09 22:58:01 | 000,001,660 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2011/02/09 12:16:06 | 000,002,447 | ---- | C] () -- C:\Documents and Settings\admin\Desktop\HiJackThis.lnk
[2011/02/09 12:08:32 | 000,011,264 | ---- | C] () -- C:\WINDOWS\DCEBoot.exe
[2011/02/09 12:08:32 | 000,003,700 | ---- | C] () -- C:\WINDOWS\DCEBOOT.CFG
[2011/02/09 12:08:28 | 000,102,400 | ---- | C] () -- C:\WINDOWS\RegBootClean.exe
[2011/02/08 22:59:29 | 501,731,328 | -HS- | C] () -- C:\hiberfil.sys
[2011/02/08 09:39:39 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\admin\Local Settings\Application Data\housecall.guid.cache
[2011/02/07 18:48:38 | 000,184,887 | ---- | C] () -- C:\WINDOWS\System32\drivers\str.sys
[2011/02/07 18:47:48 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\admin\Application Data\HhdFJl61DD.txt
[2011/02/07 18:40:38 | 000,002,324 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2011/02/07 18:25:05 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
[2010/09/23 23:24:10 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010/09/03 12:20:12 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2010/06/29 18:03:24 | 000,217,088 | ---- | C] () -- C:\WINDOWS\System32\LPng.dll
[2010/03/25 17:10:49 | 000,000,390 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010/03/25 17:07:34 | 000,561,152 | R--- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2009/07/20 18:03:14 | 000,074,240 | ---- | C] () -- C:\Documents and Settings\admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/29 16:49:10 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/05/29 13:58:50 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/02/15 16:04:52 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2005/02/12 14:03:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/11/14 12:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll

========== LOP Check ==========

[2011/02/07 22:25:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\BitTorrent
[2010/04/23 20:40:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Blackberry Desktop
[2011/02/09 12:08:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Ehuxo
[2010/03/31 23:48:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\FreeCall
[2010/03/23 15:50:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Intervideo
[2010/08/14 00:04:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Kaosr
[2010/09/23 00:07:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Leadertech
[2009/11/29 22:26:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Research In Motion
[2010/07/22 18:32:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bharti
[2009/07/20 18:15:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InterVideo
[2010/03/30 22:32:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2010/03/21 17:20:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2010/07/22 18:35:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/09/24 01:28:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/02/09 22:58:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2011/02/09 17:37:00 | 000,000,390 | ---- | M] () -- C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1269518597.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC6124CA

< End of report >
  • 0

#9
kingfisher3210

kingfisher3210

    Member

  • Topic Starter
  • Member
  • PipPip
  • 42 posts
ComboFix 11-02-09.03 - admin 02/10/2011 10:22:55.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.478.167 [GMT 5.5:30]
Running from: D:\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\admin\My Documents\DPE.DUS
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\drivers\str.sys
E:\Autorun.inf

----- BITS: Possible infected sites -----

hxxp://netxpert.airtelbroadband.in
.
((((((((((((((((((((((((( Files Created from 2011-01-10 to 2011-02-10 )))))))))))))))))))))))))))))))
.

2011-02-09 17:27 . 2011-02-09 17:27 -------- d-----w- c:\documents and settings\admin\Local Settings\Application Data\WinZip
2011-02-09 06:47 . 2011-02-09 11:30 736256 ----a-w- c:\windows\system32\drivers\uagxgo.sys
2011-02-09 06:46 . 2011-02-09 06:46 388096 ----a-r- c:\documents and settings\admin\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-09 06:46 . 2011-02-09 06:46 -------- d-----w- c:\program files\Trend Micro
2011-02-09 06:38 . 2011-02-09 11:29 11264 ----a-w- c:\windows\DCEBoot.exe
2011-02-09 06:38 . 2011-02-09 11:29 102400 ----a-w- c:\windows\RegBootClean.exe
2011-02-09 06:25 . 2010-09-06 09:26 189520 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-02-08 18:19 . 2009-10-02 14:09 19472 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2011-02-08 18:19 . 2009-10-14 15:48 36880 ----a-w- c:\windows\system32\drivers\klbg.sys
2011-02-08 18:19 . 2009-12-14 07:14 88632 ----a-w- c:\windows\system32\drivers\CSCrySec.sys
2011-02-08 18:19 . 2009-12-14 07:14 39352 ----a-w- c:\windows\system32\drivers\CSVirtualDiskDrv.sys
2011-02-08 17:47 . 2011-02-08 17:47 -------- dc----w- c:\windows\system32\DRVSTORE
2011-02-08 12:52 . 2011-02-08 12:52 229888 ----a-w- c:\windows\system32\zehohu.exe
2011-02-08 05:33 . 2011-02-08 06:07 229888 ----a-w- c:\windows\system32\sygougysih.exe
2011-02-08 02:04 . 2011-02-08 02:03 229888 ----a-w- c:\windows\system32\zubed.exe
2011-02-07 16:33 . 2011-02-08 02:40 229888 ----a-w- c:\windows\system32\heny.exe
2011-02-07 13:17 . 2011-02-08 06:07 229888 ----a-w- c:\windows\system32\cywoze.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-07 05:17 . 2010-12-07 05:17 28672 ----a-w- c:\windows\system32\eEmpty.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-10 218032]
"Google Update"="c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-03-26 136176]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-03-19 5248312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"netxpert"="c:\program files\Airtel NetXpert\bin\sprtcmd.exe" [2010-05-10 206120]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-2-15 581693]
C2CMonitor.lnk - c:\program files\ClickToConvert\C2CMonitor.exe [2010-6-29 414720]
Desktop Manager.lnk - c:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2008-9-21 1545488]
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2004-6-16 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2004-6-16 28672]
SetPoint.lnk - c:\program files\SetPoint\SetPoint.exe [2010-10-3 813584]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2010-11-30 608584]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"7005:TCP"= 7005:TCP:fhyyy

R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [10/3/2010 12:01 PM 10384]
R2 sprtsvc_netxpert;SupportSoft Sprocket Service (netxpert);c:\program files\Airtel NetXpert\bin\sprtsvc.exe [7/22/2010 6:35 PM 206120]
R2 tgsrvc_netxpert;SupportSoft Repair Service (netxpert);c:\program files\Airtel NetXpert\bin\tgsrvc.exe [7/22/2010 6:35 PM 185640]
S2 pvheampgi;System Installer;c:\windows\system32\svchost.exe -k netsvcs [4/14/2008 5:30 PM 14336]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
pvheampgi
.
Contents of the 'Scheduled Tasks' folder

2011-02-09 c:\windows\Tasks\FRU Task 2004-06-17 01:06ewlett-Packard2004-06-17 01:06p psc 1200 seriesD66655067F78228D3716D2BFC2C61DA319188DBF269518597.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2004-06-16 12:36]

2011-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1060284298-1844823847-299502267-1003Core.job
- c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-26 09:21]

2011-02-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1060284298-1844823847-299502267-1003UA.job
- c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-26 09:21]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {72525BAD-B524-46BB-BE84-7B331246C8C9} = 202.56.215.54,202.56.215.55
.
- - - - ORPHANS REMOVED - - - -

AddRemove-Defraggler - c:\program files\Defraggler\uninst.exe
AddRemove-FreeCall_is1 - c:\program files\FreeCall.com\FreeCall\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-10 10:33
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-02-10 10:38:37
ComboFix-quarantined-files.txt 2011-02-10 05:08

Pre-Run: 3,920,236,544 bytes free
Post-Run: 3,894,784,000 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - 0552C13135A97AD3075CE7A993E8A881
  • 0

#10
kingfisher3210

kingfisher3210

    Member

  • Topic Starter
  • Member
  • PipPip
  • 42 posts
Thanks Ali.B for your expert guidance. Allah bless you.

Update: After restarting the PC, i found out that i could run GMER Rootkit Scanner. I will wait for your instructions whether to run it now as previously advised by you or not to run it now.
  • 0

Advertisements


#11
ali.B

ali.B

    Trusted Helper

  • Malware Removal
  • 3,086 posts
hi

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

KillAll::

File::
c:\windows\system32\drivers\uagxgo.sys
c:\windows\system32\zehohu.exe
c:\windows\system32\sygougysih.exe
c:\windows\system32\zubed.exe
c:\windows\system32\heny.exe
c:\windows\system32\cywoze.exe

NetSvc::
pvheampgi


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
  • 0

#12
kingfisher3210

kingfisher3210

    Member

  • Topic Starter
  • Member
  • PipPip
  • 42 posts
Thanks Ali.B.




ComboFix 11-02-11.01 - admin 02/12/2011 11:00:43.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.478.148 [GMT 5.5:30]
Running from: D:\ComboFix.exe
Command switches used :: D:\CFScript.txt

FILE ::
"c:\windows\system32\cywoze.exe"
"c:\windows\system32\drivers\uagxgo.sys"
"c:\windows\system32\heny.exe"
"c:\windows\system32\sygougysih.exe"
"c:\windows\system32\zehohu.exe"
"c:\windows\system32\zubed.exe"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\cywoze.exe
c:\windows\system32\heny.exe
c:\windows\system32\sygougysih.exe
c:\windows\system32\zehohu.exe
c:\windows\system32\zubed.exe

----- BITS: Possible infected sites -----

hxxp://netxpert.airtelbroadband.in
.
((((((((((((((((((((((((( Files Created from 2011-01-12 to 2011-02-12 )))))))))))))))))))))))))))))))
.

2011-02-12 05:28 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-02-12 05:28 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2011-02-12 05:28 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-02-12 05:28 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2011-02-12 05:28 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-02-12 05:28 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-02-12 05:28 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2011-02-12 05:28 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2011-02-12 05:14 . 2011-02-12 05:14 -------- d-----w- c:\windows\LastGood.Tmp
2011-02-11 19:50 . 2011-02-11 19:50 -------- d-----w- c:\program files\MSXML 4.0
2011-02-11 14:33 . 2011-02-11 14:33 -------- d-----w- c:\windows\system32\KB905474
2011-02-11 14:23 . 2011-02-12 05:10 -------- d-----w- c:\windows\system32\MpEngineStore
2011-02-11 05:42 . 2010-12-09 13:42 2148864 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-02-11 05:42 . 2010-12-09 13:38 2192768 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-02-11 05:42 . 2010-12-09 13:07 2027008 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-02-11 05:42 . 2010-12-09 13:07 2069376 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2011-02-11 05:10 . 2010-08-13 12:53 5120 ------w- c:\windows\system32\xpsp4res.dll
2011-02-10 05:52 . 2011-02-10 05:52 -------- d-s---w- c:\windows\Cookies
2011-02-09 17:27 . 2011-02-09 17:27 -------- d-----w- c:\documents and settings\admin\Local Settings\Application Data\WinZip
2011-02-09 06:46 . 2011-02-09 06:46 388096 ----a-r- c:\documents and settings\admin\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-09 06:46 . 2011-02-09 06:46 -------- d-----w- c:\program files\Trend Micro
2011-02-09 06:38 . 2011-02-09 11:29 11264 ----a-w- c:\windows\DCEBoot.exe
2011-02-09 06:38 . 2011-02-09 11:29 102400 ----a-w- c:\windows\RegBootClean.exe
2011-02-09 06:25 . 2010-09-06 09:26 189520 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-02-08 18:19 . 2009-10-02 14:09 19472 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2011-02-08 18:19 . 2009-10-14 15:48 36880 ----a-w- c:\windows\system32\drivers\klbg.sys
2011-02-08 18:19 . 2009-12-14 07:14 88632 ----a-w- c:\windows\system32\drivers\CSCrySec.sys
2011-02-08 18:19 . 2009-12-14 07:14 39352 ----a-w- c:\windows\system32\drivers\CSVirtualDiskDrv.sys
2011-02-08 17:47 . 2011-02-08 17:47 -------- dc----w- c:\windows\system32\DRVSTORE

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2008-04-14 12:00 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2008-04-14 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2008-04-14 12:00 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2008-04-14 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 22:15 . 2008-04-14 12:00 667136 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 22:15 . 2008-04-14 12:00 61952 ----a-w- c:\windows\system32\tdc.ocx
2010-12-20 22:15 . 2010-03-26 06:49 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-12-20 17:26 . 2008-04-14 12:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 15:30 . 2008-04-14 12:00 369664 ----a-w- c:\windows\system32\html.iec
2010-12-09 15:15 . 2008-04-14 12:00 718336 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30 . 2008-04-14 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:38 . 2008-04-14 12:00 2192768 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07 . 2008-04-14 00:01 2069376 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-07 05:17 . 2010-12-07 05:17 28672 ----a-w- c:\windows\system32\eEmpty.exe
2010-11-18 18:12 . 2009-05-29 06:13 81920 ----a-w- c:\windows\system32\isign32.dll
.

((((((((((((((((((((((((((((( SnapShot@2011-02-10_05.03.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-28 18:12 . 2009-06-28 18:12 91656 c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
+ 2011-02-12 05:40 . 2011-02-12 05:40 16384 c:\windows\temp\Perflib_Perfdata_d0.dat
+ 2008-04-14 12:00 . 2008-05-09 10:53 90112 c:\windows\system32\wshext.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 90112 c:\windows\system32\wshext.dll
+ 2008-04-14 12:00 . 2009-06-25 08:25 54272 c:\windows\system32\wdigest.dll
+ 2008-04-14 12:00 . 2010-11-03 13:12 46080 c:\windows\system32\tzchange.exe
+ 2008-04-14 12:00 . 2009-06-12 12:31 80896 c:\windows\system32\tlntsess.exe
+ 2008-04-14 12:00 . 2009-06-12 12:31 76288 c:\windows\system32\telnet.exe
+ 2008-04-14 12:00 . 2009-10-21 05:38 75776 c:\windows\system32\strmfilt.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 75776 c:\windows\system32\strmfilt.dll
+ 2008-04-14 12:00 . 2010-08-17 13:17 58880 c:\windows\system32\spoolsv.exe
+ 2008-04-14 12:00 . 2009-06-25 08:25 56832 c:\windows\system32\secur32.dll
+ 2008-04-14 12:00 . 2009-02-06 10:39 35328 c:\windows\system32\sc.exe
+ 2008-04-14 12:00 . 2009-10-12 13:38 79872 c:\windows\system32\raschap.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 79872 c:\windows\system32\raschap.dll
+ 2008-04-14 12:00 . 2011-02-12 05:23 65044 c:\windows\system32\perfc009.dat
+ 2009-11-05 16:47 . 2009-11-05 16:47 11600 c:\windows\system32\mui\0409\mscorees.dll
- 2009-05-29 06:10 . 2008-04-14 12:00 91648 c:\windows\system32\mtxoci.dll
+ 2009-05-29 06:10 . 2008-06-12 14:23 91648 c:\windows\system32\mtxoci.dll
+ 2008-04-14 12:00 . 2008-06-12 14:23 66560 c:\windows\system32\mtxclu.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 66560 c:\windows\system32\mtxclu.dll
+ 2008-04-14 05:42 . 2009-11-27 17:11 17920 c:\windows\system32\msyuv.dll
+ 2008-04-14 12:00 . 2009-11-27 16:07 28672 c:\windows\system32\msvidc32.dll
+ 2008-04-14 12:00 . 2009-11-27 16:07 11264 c:\windows\system32\msrle32.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 11264 c:\windows\system32\msrle32.dll
- 2009-05-29 06:10 . 2008-04-14 12:00 58880 c:\windows\system32\msdtclog.dll
+ 2009-05-29 06:10 . 2008-06-12 14:23 58880 c:\windows\system32\msdtclog.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 83968 c:\windows\system32\mscories.dll
+ 2008-04-14 12:00 . 2008-06-24 16:43 74240 c:\windows\system32\mscms.dll
+ 2008-04-14 12:00 . 2009-09-04 21:03 58880 c:\windows\system32\msasn1.dll
+ 2008-04-14 12:00 . 2008-06-10 00:22 96768 c:\windows\system32\logagent.exe
- 2008-04-14 12:00 . 2005-01-28 08:14 96768 c:\windows\system32\logagent.exe
+ 2008-04-14 05:41 . 2009-11-27 16:07 48128 c:\windows\system32\iyuv_32.dll
+ 2008-04-14 12:00 . 2010-06-17 14:03 80384 c:\windows\system32\iccvid.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 80384 c:\windows\system32\iccvid.dll
+ 2008-04-14 12:00 . 2009-10-21 05:38 25088 c:\windows\system32\httpapi.dll
+ 2008-04-14 12:00 . 2009-10-15 16:28 81920 c:\windows\system32\fontsub.dll
+ 2008-04-14 12:00 . 2010-11-02 15:17 40960 c:\windows\system32\drivers\ndproxy.sys
+ 2008-04-14 12:00 . 2009-06-24 11:18 92928 c:\windows\system32\drivers\ksecdd.sys
- 2008-04-14 12:00 . 2008-04-14 12:00 90112 c:\windows\system32\dllcache\wshext.dll
+ 2008-04-14 12:00 . 2008-05-09 10:53 90112 c:\windows\system32\dllcache\wshext.dll
+ 2008-04-14 12:00 . 2009-06-25 08:25 54272 c:\windows\system32\dllcache\wdigest.dll
+ 2009-05-29 06:13 . 2010-10-11 14:59 45568 c:\windows\system32\dllcache\wab.exe
+ 2008-04-14 12:00 . 2009-06-12 12:31 80896 c:\windows\system32\dllcache\tlntsess.exe
+ 2008-04-14 12:00 . 2009-06-12 12:31 76288 c:\windows\system32\dllcache\telnet.exe
- 2008-04-14 12:00 . 2008-04-14 12:00 75776 c:\windows\system32\dllcache\strmfilt.dll
+ 2008-04-14 12:00 . 2009-10-21 05:38 75776 c:\windows\system32\dllcache\strmfilt.dll
+ 2008-04-14 12:00 . 2010-08-17 13:17 58880 c:\windows\system32\dllcache\spoolsv.exe
+ 2008-04-14 12:00 . 2009-06-25 08:25 56832 c:\windows\system32\dllcache\secur32.dll
+ 2008-04-14 12:00 . 2009-02-06 10:39 35328 c:\windows\system32\dllcache\sc.exe
- 2008-04-14 12:00 . 2008-04-14 12:00 79872 c:\windows\system32\dllcache\raschap.dll
+ 2008-04-14 12:00 . 2009-10-12 13:38 79872 c:\windows\system32\dllcache\raschap.dll
+ 2008-04-14 12:00 . 2010-11-02 15:17 40960 c:\windows\system32\dllcache\ndproxy.sys
+ 2009-05-29 06:10 . 2008-06-12 14:23 91648 c:\windows\system32\dllcache\mtxoci.dll
- 2009-05-29 06:10 . 2008-04-14 12:00 91648 c:\windows\system32\dllcache\mtxoci.dll
+ 2008-04-14 12:00 . 2008-06-12 14:23 66560 c:\windows\system32\dllcache\mtxclu.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 66560 c:\windows\system32\dllcache\mtxclu.dll
+ 2009-11-27 17:11 . 2009-11-27 17:11 17920 c:\windows\system32\dllcache\msyuv.dll
+ 2008-04-14 12:00 . 2009-11-27 16:07 28672 c:\windows\system32\dllcache\msvidc32.dll
+ 2008-04-14 12:00 . 2009-11-27 16:07 11264 c:\windows\system32\dllcache\msrle32.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 11264 c:\windows\system32\dllcache\msrle32.dll
- 2009-05-29 06:10 . 2008-04-14 12:00 58880 c:\windows\system32\dllcache\msdtclog.dll
+ 2009-05-29 06:10 . 2008-06-12 14:23 58880 c:\windows\system32\dllcache\msdtclog.dll
+ 2008-04-14 12:00 . 2008-06-24 16:43 74240 c:\windows\system32\dllcache\mscms.dll
+ 2008-04-14 12:00 . 2009-09-04 21:03 58880 c:\windows\system32\dllcache\msasn1.dll
+ 2008-04-14 12:00 . 2008-06-10 00:22 96768 c:\windows\system32\dllcache\logagent.exe
- 2008-04-14 12:00 . 2005-01-28 08:14 96768 c:\windows\system32\dllcache\logagent.exe
+ 2008-04-14 12:00 . 2009-06-24 11:18 92928 c:\windows\system32\dllcache\ksecdd.sys
+ 2009-11-27 16:07 . 2009-11-27 16:07 48128 c:\windows\system32\dllcache\iyuv_32.dll
- 2009-05-29 06:13 . 2008-04-14 12:00 81920 c:\windows\system32\dllcache\isign32.dll
+ 2009-05-29 06:13 . 2010-11-18 18:12 81920 c:\windows\system32\dllcache\isign32.dll
+ 2010-03-26 06:49 . 2010-12-20 22:15 81920 c:\windows\system32\dllcache\ieencode.dll
- 2010-03-26 06:49 . 2008-04-14 12:00 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2008-04-14 12:00 . 2009-10-21 05:38 25088 c:\windows\system32\dllcache\httpapi.dll
+ 2008-04-14 12:00 . 2009-10-15 16:28 81920 c:\windows\system32\dllcache\fontsub.dll
+ 2008-04-14 12:00 . 2010-12-09 14:30 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2008-04-14 12:00 . 2010-01-13 14:01 86016 c:\windows\system32\dllcache\cabview.dll
+ 2008-04-14 12:00 . 2009-11-27 16:07 84992 c:\windows\system32\dllcache\avifil32.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 84992 c:\windows\system32\dllcache\avifil32.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 58880 c:\windows\system32\dllcache\atl.dll
+ 2008-04-14 12:00 . 2009-07-17 19:01 58880 c:\windows\system32\dllcache\atl.dll
+ 2008-04-14 12:00 . 2010-03-05 14:37 65536 c:\windows\system32\dllcache\asycfilt.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 96760 c:\windows\system32\dfshim.dll
+ 2008-04-14 12:00 . 2010-01-13 14:01 86016 c:\windows\system32\cabview.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 84992 c:\windows\system32\avifil32.dll
+ 2008-04-14 12:00 . 2009-11-27 16:07 84992 c:\windows\system32\avifil32.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 58880 c:\windows\system32\atl.dll
+ 2008-04-14 12:00 . 2009-07-17 19:01 58880 c:\windows\system32\atl.dll
+ 2008-04-14 12:00 . 2010-03-05 14:37 65536 c:\windows\system32\asycfilt.dll
- 2010-03-22 17:47 . 2007-11-30 12:39 26488 c:\windows\SoftwareDistribution\Download\fae8bc4d2da2adc1b9109ef4e6cecd1f\update\spcustom.dll
- 2010-03-22 17:47 . 2007-11-30 12:39 17272 c:\windows\SoftwareDistribution\Download\fae8bc4d2da2adc1b9109ef4e6cecd1f\spmsg.dll
- 2010-08-02 20:49 . 2007-11-30 12:39 26488 c:\windows\SoftwareDistribution\Download\f6ae6c01481096f08117233982ca37f9\update\spcustom.dll
- 2010-08-02 20:49 . 2007-11-30 12:39 17272 c:\windows\SoftwareDistribution\Download\f6ae6c01481096f08117233982ca37f9\spmsg.dll
- 2010-08-03 15:36 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\f2adb0f8440e5dbd459aa6bfcaed1ba5\update\spcustom.dll
- 2010-08-03 15:36 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\f2adb0f8440e5dbd459aa6bfcaed1ba5\spmsg.dll
- 2010-08-02 20:48 . 2008-07-08 13:02 26488 c:\windows\SoftwareDistribution\Download\de81b460c3abcfc5b8494c785a5f3944\update\spcustom.dll
- 2010-08-02 20:48 . 2008-07-08 13:02 17272 c:\windows\SoftwareDistribution\Download\de81b460c3abcfc5b8494c785a5f3944\spmsg.dll
- 2010-08-03 15:38 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\da2a33b6770f970d7fe7262040f98a4f\update\spcustom.dll
- 2010-08-03 15:38 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\da2a33b6770f970d7fe7262040f98a4f\spmsg.dll
- 2010-03-22 17:32 . 2008-07-08 13:02 26488 c:\windows\SoftwareDistribution\Download\d8ef7c8f90f509563f255df3e967b057\update\spcustom.dll
- 2010-03-22 17:32 . 2008-07-08 13:02 17272 c:\windows\SoftwareDistribution\Download\d8ef7c8f90f509563f255df3e967b057\spmsg.dll
- 2010-03-22 17:32 . 2009-10-15 16:39 81920 c:\windows\SoftwareDistribution\Download\d8ef7c8f90f509563f255df3e967b057\SP3QFE\fontsub.dll
- 2010-03-22 17:32 . 2009-10-15 16:28 81920 c:\windows\SoftwareDistribution\Download\d8ef7c8f90f509563f255df3e967b057\SP3GDR\fontsub.dll
- 2010-03-22 17:32 . 2009-10-15 16:56 81920 c:\windows\SoftwareDistribution\Download\d8ef7c8f90f509563f255df3e967b057\SP2QFE\fontsub.dll
- 2010-03-22 17:32 . 2009-10-15 17:21 82432 c:\windows\SoftwareDistribution\Download\d8ef7c8f90f509563f255df3e967b057\SP2GDR\fontsub.dll
- 2010-08-03 15:40 . 2008-07-08 13:02 26488 c:\windows\SoftwareDistribution\Download\d48a3b967ba5709df048e8f2a49cf8a6\update\spcustom.dll
- 2010-08-03 15:40 . 2008-07-08 13:02 17272 c:\windows\SoftwareDistribution\Download\d48a3b967ba5709df048e8f2a49cf8a6\spmsg.dll
- 2010-08-03 15:28 . 2008-07-08 13:02 26488 c:\windows\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\update\spcustom.dll
- 2010-08-03 15:28 . 2008-07-08 13:02 17272 c:\windows\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\spmsg.dll
- 2010-03-22 17:30 . 2008-07-08 13:02 26488 c:\windows\SoftwareDistribution\Download\c263092dccc247f68a43cfee93ecc72d\update\spcustom.dll
- 2010-03-22 17:30 . 2008-07-08 13:02 17272 c:\windows\SoftwareDistribution\Download\c263092dccc247f68a43cfee93ecc72d\spmsg.dll
- 2010-03-22 17:47 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\c0c52c03306062533f7dcb087bfcfa6b\update\spcustom.dll
- 2010-03-22 17:47 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\c0c52c03306062533f7dcb087bfcfa6b\spmsg.dll
- 2010-03-22 17:46 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\b7f0b2892b21211a5630518d058f48d9\update\spcustom.dll
- 2010-03-22 17:46 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\b7f0b2892b21211a5630518d058f48d9\spmsg.dll
- 2010-08-03 15:13 . 2007-11-30 12:39 26488 c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\update\spcustom.dll
- 2010-08-03 15:13 . 2007-11-30 12:39 17272 c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\spmsg.dll
- 2010-03-22 17:32 . 2008-07-08 13:02 26488 c:\windows\SoftwareDistribution\Download\9cf59263a134ab3fbbee78365a2fa5fc\update\spcustom.dll
- 2010-03-22 17:32 . 2008-07-08 13:02 17272 c:\windows\SoftwareDistribution\Download\9cf59263a134ab3fbbee78365a2fa5fc\spmsg.dll
- 2010-03-22 17:32 . 2009-06-09 14:53 53248 c:\windows\SoftwareDistribution\Download\9cf59263a134ab3fbbee78365a2fa5fc\SP2QFE\tsgqec.dll
- 2010-08-03 15:24 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\update\spcustom.dll
- 2010-08-03 15:24 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\spmsg.dll
- 2010-03-22 17:47 . 2007-11-30 12:39 26488 c:\windows\SoftwareDistribution\Download\8cac00e8efc87d728c0261686f85c975\update\spcustom.dll
- 2010-03-22 17:47 . 2007-11-30 12:39 17272 c:\windows\SoftwareDistribution\Download\8cac00e8efc87d728c0261686f85c975\spmsg.dll
- 2010-08-03 15:38 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\update\spcustom.dll
- 2010-08-03 15:38 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\spmsg.dll
- 2010-08-02 20:43 . 2008-07-08 13:02 26488 c:\windows\SoftwareDistribution\Download\78cf8552430e25a8f24bc1e4dfb1970e\update\spcustom.dll
- 2010-08-02 20:43 . 2008-07-08 13:02 17272 c:\windows\SoftwareDistribution\Download\78cf8552430e25a8f24bc1e4dfb1970e\spmsg.dll
- 2010-03-22 17:28 . 2008-07-08 13:02 26488 c:\windows\SoftwareDistribution\Download\75cd10bc79782317976e2a857798ad9f\update\spcustom.dll
- 2010-03-22 17:28 . 2008-07-08 13:02 17272 c:\windows\SoftwareDistribution\Download\75cd10bc79782317976e2a857798ad9f\spmsg.dll
- 2010-08-03 15:27 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\6a410a1bd174bc123056d235ac4829af\update\spcustom.dll
- 2010-08-03 15:27 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\6a410a1bd174bc123056d235ac4829af\spmsg.dll
- 2010-08-03 15:38 . 2008-07-09 07:38 26488 c:\windows\SoftwareDistribution\Download\64cc77a1a7652da2d7ace79940460770\update\spcustom.dll
- 2010-08-03 15:38 . 2008-07-09 07:38 17272 c:\windows\SoftwareDistribution\Download\64cc77a1a7652da2d7ace79940460770\spmsg.dll
- 2010-03-22 17:27 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\5e5aab0184cde550e4ba21f1d2bd377e\update\spcustom.dll
- 2010-03-22 17:27 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\5e5aab0184cde550e4ba21f1d2bd377e\spmsg.dll
- 2010-03-22 17:37 . 2008-07-09 07:38 26488 c:\windows\SoftwareDistribution\Download\593d5ddb620b1f1b4bef986c655fd062\update\spcustom.dll
- 2010-03-22 17:37 . 2008-07-09 07:38 17272 c:\windows\SoftwareDistribution\Download\593d5ddb620b1f1b4bef986c655fd062\spmsg.dll
- 2010-03-22 17:37 . 2009-03-25 05:54 39424 c:\windows\SoftwareDistribution\Download\593d5ddb620b1f1b4bef986c655fd062\SP2QFE\acadproc.dll
- 2010-03-22 17:46 . 2008-07-09 07:38 26488 c:\windows\SoftwareDistribution\Download\55ae228715888b68a08f491655790fa6\update\spcustom.dll
- 2010-03-22 17:46 . 2008-07-09 07:38 17272 c:\windows\SoftwareDistribution\Download\55ae228715888b68a08f491655790fa6\spmsg.dll
- 2010-03-22 17:32 . 2008-07-09 07:38 26488 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\update\spcustom.dll
- 2010-03-22 17:32 . 2008-07-09 07:38 26488 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\spupdsvc.exe
- 2010-03-22 17:32 . 2008-07-09 07:38 17272 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\spmsg.dll
- 2010-03-22 17:32 . 2009-02-06 10:36 35328 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\sc.exe
- 2010-03-22 17:32 . 2009-02-06 10:39 35328 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\sc.exe
- 2010-03-22 17:32 . 2009-02-06 09:54 35328 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\sc.exe
- 2010-03-22 17:32 . 2005-07-26 04:20 60416 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\colbact.dll
- 2010-03-22 17:32 . 2009-02-06 16:54 35328 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\sc.exe
- 2010-03-22 17:32 . 2005-07-26 04:39 60416 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\colbact.dll
- 2010-03-22 17:47 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\50e2c72fd814d3841e776dd2c4918260\update\spcustom.dll
- 2010-03-22 17:47 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\50e2c72fd814d3841e776dd2c4918260\spmsg.dll
- 2010-03-22 17:27 . 2007-11-30 11:18 26488 c:\windows\SoftwareDistribution\Download\4b975c8f39482ac4287e885ca058f798\update\spcustom.dll
- 2010-03-22 17:27 . 2007-11-30 11:18 17272 c:\windows\SoftwareDistribution\Download\4b975c8f39482ac4287e885ca058f798\spmsg.dll
- 2010-03-22 17:11 . 2007-11-30 11:18 26488 c:\windows\SoftwareDistribution\Download\491a2c8e1582f5cdd01f8b3da4b8ef7d\update\spcustom.dll
- 2010-03-22 17:11 . 2007-11-30 11:18 17272 c:\windows\SoftwareDistribution\Download\491a2c8e1582f5cdd01f8b3da4b8ef7d\spmsg.dll
- 2010-08-03 15:40 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\42360c8fdaf030cd25332428cfba61cd\update\spcustom.dll
- 2010-08-03 15:40 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\42360c8fdaf030cd25332428cfba61cd\spmsg.dll
- 2010-03-22 15:39 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\3f62db0dd41de1740f8addce0cc500ec\update\spcustom.dll
- 2010-03-22 15:39 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\3f62db0dd41de1740f8addce0cc500ec\spmsg.dll
- 2010-03-22 17:46 . 2007-11-30 12:39 26488 c:\windows\SoftwareDistribution\Download\37ea7d9587e54acc7afa27dc26096f4f\update\spcustom.dll
- 2010-03-22 17:46 . 2007-11-30 12:39 17272 c:\windows\SoftwareDistribution\Download\37ea7d9587e54acc7afa27dc26096f4f\spmsg.dll
- 2010-03-22 17:37 . 2008-07-08 13:02 26488 c:\windows\SoftwareDistribution\Download\3361704fe1a0367fcfe17758efab6972\update\spcustom.dll
- 2010-03-22 17:37 . 2008-07-08 13:02 17272 c:\windows\SoftwareDistribution\Download\3361704fe1a0367fcfe17758efab6972\spmsg.dll
- 2010-08-03 15:27 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\2e6b16219034e135b4f869efb7a10fee\update\spcustom.dll
- 2010-08-03 15:27 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\2e6b16219034e135b4f869efb7a10fee\spmsg.dll
- 2010-03-22 17:30 . 2008-07-08 13:02 26488 c:\windows\SoftwareDistribution\Download\2c95b28351986132d7f36dd28eece9b0\update\spcustom.dll
- 2010-03-22 17:30 . 2008-07-08 13:02 17272 c:\windows\SoftwareDistribution\Download\2c95b28351986132d7f36dd28eece9b0\spmsg.dll
- 2010-08-02 21:20 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\2c0d861a85182505b6e0107596abb839\update\spcustom.dll
- 2010-08-02 21:20 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\2c0d861a85182505b6e0107596abb839\spmsg.dll
- 2010-08-03 15:38 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\269630a60abe4177f0ba214686d6ebda\update\spcustom.dll
- 2010-08-03 15:38 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\269630a60abe4177f0ba214686d6ebda\spmsg.dll
- 2010-08-02 20:49 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\248802b74506342031e926839639c729\update\spcustom.dll
- 2010-08-02 20:49 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\248802b74506342031e926839639c729\spmsg.dll
- 2010-03-22 17:46 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\23e79e5fb28793d8cb1c2055b0d8dcb9\update\spcustom.dll
- 2010-03-22 17:46 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\23e79e5fb28793d8cb1c2055b0d8dcb9\spmsg.dll
- 2010-08-02 20:50 . 2008-07-08 13:02 26488 c:\windows\SoftwareDistribution\Download\22f1a1e628f2ceada1948d2c604b5154\update\spcustom.dll
- 2010-08-02 20:50 . 2008-07-08 13:02 17272 c:\windows\SoftwareDistribution\Download\22f1a1e628f2ceada1948d2c604b5154\spmsg.dll
- 2010-03-22 17:27 . 2007-11-30 12:39 26488 c:\windows\SoftwareDistribution\Download\1ece269e23f4ef02dbea7dfa6a74a7d0\update\spcustom.dll
- 2010-03-22 17:27 . 2007-11-30 12:39 17272 c:\windows\SoftwareDistribution\Download\1ece269e23f4ef02dbea7dfa6a74a7d0\spmsg.dll
- 2010-08-03 15:40 . 2007-11-30 12:39 26488 c:\windows\SoftwareDistribution\Download\1201b6f74bae1015eceeea43baed9814\update\spcustom.dll
- 2010-08-03 15:40 . 2007-11-30 12:39 17272 c:\windows\SoftwareDistribution\Download\1201b6f74bae1015eceeea43baed9814\spmsg.dll
- 2010-08-03 15:35 . 2008-07-08 13:02 26488 c:\windows\SoftwareDistribution\Download\0fa2ac15b3f3d16ecfc880648002b82e\update\spcustom.dll
- 2010-08-03 15:35 . 2008-07-08 13:02 17272 c:\windows\SoftwareDistribution\Download\0fa2ac15b3f3d16ecfc880648002b82e\spmsg.dll
- 2010-03-22 17:37 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\0dd0244816ffb4b094c1caba4c3b1178\update\spcustom.dll
- 2010-03-22 17:37 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\0dd0244816ffb4b094c1caba4c3b1178\spmsg.dll
- 2010-08-02 20:49 . 2008-07-08 13:02 26488 c:\windows\SoftwareDistribution\Download\01229cf5dcf0df67992cac35a2ba0b3f\update\spcustom.dll
- 2010-08-02 20:49 . 2008-07-08 13:02 17272 c:\windows\SoftwareDistribution\Download\01229cf5dcf0df67992cac35a2ba0b3f\spmsg.dll
- 2010-08-03 15:11 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\0034610052cb298a78a7ba8a4f6282e6\update\spcustom.dll
- 2010-08-03 15:11 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\0034610052cb298a78a7ba8a4f6282e6\spmsg.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 37896 c:\windows\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 81400 c:\windows\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL
+ 2008-07-25 05:47 . 2008-07-25 05:47 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 57392 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 95232 c:\windows\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 16896 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 61952 c:\windows\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe
+ 2008-07-25 05:47 . 2008-07-25 05:47 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- 2005-09-23 01:58 . 2005-09-23 01:58 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- 2005-09-23 01:58 . 2005-09-23 01:58 53248 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
+ 2008-07-25 05:47 . 2008-07-25 05:47 53248 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
+ 2008-07-25 05:47 . 2008-07-25 05:47 88584 c:\windows\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 24584 c:\windows\Microsoft.NET\Framework\v2.0.50727\normalization.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 31744 c:\windows\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 19456 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscortim.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
+ 2008-07-25 05:46 . 2008-07-25 05:46 18944 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 77312 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 94208 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorld.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 46592 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorie.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 83456 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
- 2005-09-23 01:58 . 2005-09-23 01:58 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
+ 2008-07-25 05:46 . 2008-07-25 05:46 97792 c:\windows\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 12800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 12800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 40960 c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
+ 2008-07-25 05:46 . 2008-07-25 05:46 40960 c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
- 2005-09-23 01:58 . 2005-09-23 01:58 72192 c:\windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 72192 c:\windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 65032 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
+ 2008-07-25 05:47 . 2008-07-25 05:47 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
+ 2008-07-25 05:47 . 2008-07-25 05:47 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEHost.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 18936 c:\windows\Microsoft.NET\Framework\v2.0.50727\fusion.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 62968 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfdll.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 35320 c:\windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe
+ 2008-07-25 05:47 . 2008-07-25 05:47 69120 c:\windows\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 27136 c:\windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 13312 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 13312 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 80376 c:\windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
+ 2008-07-25 05:47 . 2008-07-25 05:47 89608 c:\windows\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 33792 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2008-07-25 05:46 . 2008-07-25 05:46 34312 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
+ 2008-07-25 05:46 . 2008-07-25 05:46 33288 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe
+ 2008-07-25 05:46 . 2008-07-25 05:46 24576 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
+ 2008-07-25 05:46 . 2008-07-25 05:46 84480 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 33800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 17416 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 22024 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
+ 2008-07-25 05:46 . 2008-07-25 05:46 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
+ 2008-07-25 05:47 . 2008-07-25 05:47 58880 c:\windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
+ 2008-07-25 05:46 . 2008-07-25 05:46 98808 c:\windows\Microsoft.NET\Framework\v2.0.50727\alink.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 10752 c:\windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 10752 c:\windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 13824 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll
+ 2009-06-24 14:26 . 2009-06-24 14:26 73728 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe
+ 2010-09-23 10:25 . 2010-09-23 10:25 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2009-06-24 14:26 . 2009-06-24 14:26 98304 c:\windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
+ 2010-09-22 20:56 . 2010-09-22 20:56 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2003-02-20 13:39 . 2003-02-20 13:39 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2003-02-20 13:39 . 2003-02-20 13:39 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2010-09-22 20:56 . 2010-09-22 20:56 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2010-09-22 20:56 . 2010-09-22 20:56 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2004-07-14 19:02 . 2004-07-14 19:02 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2010-09-22 21:47 . 2010-09-22 21:47 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2004-07-14 20:19 . 2004-07-14 20:19 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2003-02-20 13:49 . 2003-02-20 13:49 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2010-09-22 21:47 . 2010-09-22 21:47 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 96768 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 16896 c:\windows\Microsoft.NET\Framework\SharedReg12.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 16896 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 16896 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 16896 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 82944 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
+ 2011-02-12 05:23 . 2011-02-12 05:23 88576 c:\windows\Installer\79593.msi
+ 2011-02-11 19:50 . 2011-02-11 19:50 32768 c:\windows\Installer\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}\icon.exe
+ 2011-02-11 19:50 . 2011-02-11 19:50 32768 c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
+ 2009-11-27 17:11 . 2009-11-27 17:11 17920 c:\windows\Driver Cache\i386\msyuv.dll
+ 2009-11-27 16:07 . 2009-11-27 16:07 48128 c:\windows\Driver Cache\i386\iyuv_32.dll
+ 2011-02-12 05:28 . 2008-07-06 12:06 89088 c:\windows\Driver Cache\i386\filterpipelineprintproc.dll
+ 2011-02-10 05:52 . 2011-02-10 04:33 16384 c:\windows\Cookies\index.dat
+ 2011-02-11 19:52 . 2011-02-11 19:52 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_af99b92e\System.Drawing.Design.dll
+ 2011-02-11 19:52 . 2011-02-11 19:52 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_99aa0338\CustomMarshalers.dll
+ 2011-02-12 05:39 . 2011-02-12 05:39 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\a2865dcec9c5d3cc9c55f026cbad6fcc\dfsvc.ni.exe
+ 2011-02-12 05:38 . 2011-02-12 05:38 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\c2af7cfbb47c077029a2645930b4eeac\Accessibility.ni.dll
+ 2011-02-12 05:21 . 2011-02-12 05:21 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2010-03-29 05:57 . 2010-03-29 05:57 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2010-03-29 05:57 . 2010-03-29 05:57 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2010-03-29 05:56 . 2010-03-29 05:56 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2010-03-29 05:56 . 2010-03-29 05:56 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2010-03-29 05:56 . 2010-03-29 05:56 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2010-03-29 05:56 . 2010-03-29 05:56 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2010-03-29 05:56 . 2010-03-29 05:56 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2010-03-29 05:56 . 2010-03-29 05:56 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2010-03-29 05:57 . 2010-03-29 05:57 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2011-02-11 19:52 . 2011-02-11 19:52 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-02-11 14:31 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB981349\update\spcustom.dll
+ 2011-02-11 14:31 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB981349\spmsg.dll
+ 2011-02-11 19:54 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB979482\update\spcustom.dll
+ 2011-02-11 19:54 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB979482\spmsg.dll
+ 2010-03-05 14:52 . 2010-03-05 14:52 65536 c:\windows\$hf_mig$\KB979482\SP3QFE\asycfilt.dll
+ 2011-02-11 14:14 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB979309\update\spcustom.dll
+ 2011-02-11 14:14 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB979309\spmsg.dll
+ 2010-01-13 13:48 . 2010-01-13 13:48 86016 c:\windows\$hf_mig$\KB979309\SP3QFE\cabview.dll
+ 2011-02-11 19:54 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB978706\update\spcustom.dll
+ 2011-02-11 19:54 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB978706\spmsg.dll
+ 2011-02-11 14:17 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB978601\update\spcustom.dll
+ 2011-02-11 14:17 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB978601\spmsg.dll
+ 2011-02-11 19:54 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB978542\update\spcustom.dll
+ 2011-02-11 19:54 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB978542\spmsg.dll
+ 2011-02-11 14:29 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB978338\update\spcustom.dll
+ 2011-02-11 14:29 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB978338\spmsg.dll
+ 2011-02-11 19:55 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB977914\update\spcustom.dll
+ 2011-02-11 19:55 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB977914\spmsg.dll
+ 2009-11-27 16:28 . 2009-11-27 16:28 28672 c:\windows\$hf_mig$\KB977914\SP3QFE\msvidc32.dll
+ 2009-11-27 16:28 . 2009-11-27 16:28 11264 c:\windows\$hf_mig$\KB977914\SP3QFE\msrle32.dll
+ 2009-11-27 16:28 . 2009-11-27 16:28 48128 c:\windows\$hf_mig$\KB977914\SP3QFE\iyuv_32.dll
+ 2009-11-27 16:28 . 2009-11-27 16:28 84992 c:\windows\$hf_mig$\KB977914\SP3QFE\avifil32.dll
+ 2011-02-11 14:23 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB977816\update\spcustom.dll
+ 2011-02-11 14:23 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB977816\spmsg.dll
+ 2011-02-11 14:30 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB975713\update\spcustom.dll
+ 2011-02-11 14:30 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB975713\spmsg.dll
+ 2011-02-11 19:53 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB975562\update\spcustom.dll
+ 2011-02-11 19:53 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB975562\spmsg.dll
+ 2011-02-11 14:25 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB975560\update\spcustom.dll
+ 2011-02-11 14:25 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB975560\spmsg.dll
+ 2009-11-27 17:23 . 2009-11-27 17:23 17920 c:\windows\$hf_mig$\KB975560\SP3QFE\msyuv.dll
+ 2011-02-11 14:13 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB975467\update\spcustom.dll
+ 2011-02-11 14:13 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB975467\spmsg.dll
+ 2011-02-11 14:25 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB974571\update\spcustom.dll
+ 2011-02-11 14:25 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB974571\spmsg.dll
+ 2009-09-04 20:57 . 2009-09-04 20:57 58880 c:\windows\$hf_mig$\KB974571\SP3QFE\msasn1.dll
+ 2011-02-11 14:14 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB974392\update\spcustom.dll
+ 2011-02-11 14:14 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB974392\spmsg.dll
+ 2011-02-11 14:32 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB974318\update\spcustom.dll
+ 2011-02-11 14:32 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB974318\spmsg.dll
+ 2009-10-12 13:28 . 2009-10-12 13:28 79872 c:\windows\$hf_mig$\KB974318\SP3QFE\raschap.dll
+ 2011-02-11 14:28 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB974112\update\spcustom.dll
+ 2011-02-11 14:28 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB974112\spmsg.dll
+ 2011-02-11 14:15 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB973904\update\spcustom.dll
+ 2011-02-11 14:15 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB973904\spmsg.dll
+ 2011-02-11 14:25 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB973869\update\spcustom.dll
+ 2011-02-11 14:25 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB973869\spmsg.dll
+ 2011-02-11 19:54 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB973815\update\spcustom.dll
+ 2011-02-11 19:54 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB973815\spmsg.dll
+ 2011-02-11 14:23 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB973687\update\spcustom.dll
+ 2011-02-11 14:23 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB973687\spmsg.dll
+ 2011-02-11 14:24 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB973507\update\spcustom.dll
+ 2011-02-11 14:24 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB973507\spmsg.dll
+ 2009-07-17 19:25 . 2009-07-17 19:25 58880 c:\windows\$hf_mig$\KB973507\SP3QFE\atl.dll
+ 2011-02-11 14:28 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB972270\update\spcustom.dll
+ 2011-02-11 14:28 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB972270\spmsg.dll
+ 2011-02-11 05:31 . 2009-10-15 16:39 81920 c:\windows\$hf_mig$\KB972270\SP3QFE\fontsub.dll
+ 2011-02-11 14:13 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB971961\update\spcustom.dll
+ 2011-02-11 14:13 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB971961\spmsg.dll
+ 2011-02-11 14:29 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB971657\update\spcustom.dll
+ 2011-02-11 14:29 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB971657\spmsg.dll
+ 2011-02-11 14:31 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB969059\update\spcustom.dll
+ 2011-02-11 14:31 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB969059\spmsg.dll
+ 2011-02-11 14:13 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB968389\update\spcustom.dll
+ 2011-02-11 14:13 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB968389\spmsg.dll
+ 2009-06-25 08:41 . 2009-06-25 08:41 54272 c:\windows\$hf_mig$\KB968389\SP3QFE\wdigest.dll
+ 2009-06-25 08:41 . 2009-06-25 08:41 56832 c:\windows\$hf_mig$\KB968389\SP3QFE\secur32.dll
+ 2009-06-24 10:28 . 2009-06-24 10:28 92928 c:\windows\$hf_mig$\KB968389\SP3QFE\ksecdd.sys
+ 2011-02-11 14:15 . 2008-07-09 07:38 26488 c:\windows\$hf_mig$\KB967715\update\spcustom.dll
+ 2011-02-11 14:15 . 2008-07-09 07:38 17272 c:\windows\$hf_mig$\KB967715\spmsg.dll
+ 2011-02-11 14:26 . 2008-07-09 07:38 26488 c:\windows\$hf_mig$\KB961501\update\spcustom.dll
+ 2011-02-11 14:26 . 2008-07-09 07:38 17272 c:\windows\$hf_mig$\KB961501\spmsg.dll
+ 2011-02-11 19:54 . 2007-11-30 12:39 26488 c:\windows\$hf_mig$\KB960803\update\spcustom.dll
+ 2011-02-11 19:54 . 2007-11-30 12:39 17272 c:\windows\$hf_mig$\KB960803\spmsg.dll
+ 2011-02-11 19:51 . 2007-11-30 11:18 26488 c:\windows\$hf_mig$\KB958644\update\spcustom.dll
+ 2011-02-11 19:51 . 2007-11-30 11:18 17272 c:\windows\$hf_mig$\KB958644\spmsg.dll
+ 2011-02-11 14:27 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB956844\update\spcustom.dll
+ 2011-02-11 14:27 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB956844\spmsg.dll
+ 2011-02-11 19:50 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB956802\update\spcustom.dll
+ 2011-02-11 19:50 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB956802\spmsg.dll
+ 2011-02-11 14:28 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB956744\update\spcustom.dll
+ 2011-02-11 14:28 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB956744\spmsg.dll
+ 2011-02-11 14:27 . 2008-07-09 07:38 26488 c:\windows\$hf_mig$\KB956572\update\spcustom.dll
+ 2011-02-11 14:27 . 2008-07-09 07:38 17272 c:\windows\$hf_mig$\KB956572\spmsg.dll
+ 2011-02-11 05:57 . 2009-02-06 10:36 35328 c:\windows\$hf_mig$\KB956572\SP3QFE\sc.exe
+ 2011-02-11 14:14 . 2007-11-30 12:39 26488 c:\windows\$hf_mig$\KB954459\update\spcustom.dll
+ 2011-02-11 14:14 . 2007-11-30 12:39 17272 c:\windows\$hf_mig$\KB954459\spmsg.dll
+ 2011-02-11 14:16 . 2007-11-30 11:18 26488 c:\windows\$hf_mig$\KB952287\update\spcustom.dll
+ 2011-02-11 14:16 . 2007-11-30 11:18 17272 c:\windows\$hf_mig$\KB952287\spmsg.dll
+ 2011-02-11 14:25 . 2007-11-30 12:39 26488 c:\windows\$hf_mig$\KB952004\update\spcustom.dll
+ 2011-02-11 14:25 . 2007-11-30 12:39 17272 c:\windows\$hf_mig$\KB952004\spmsg.dll
+ 2008-06-12 14:09 . 2008-06-12 14:09 91648 c:\windows\$hf_mig$\KB952004\SP3QFE\mtxoci.dll
+ 2008-06-12 14:09 . 2008-06-12 14:09 66560 c:\windows\$hf_mig$\KB952004\SP3QFE\mtxclu.dll
+ 2008-06-12 14:09 . 2008-06-12 14:09 58880 c:\windows\$hf_mig$\KB952004\SP3QFE\msdtclog.dll
+ 2011-02-11 14:32 . 2007-11-30 12:39 26488 c:\windows\$hf_mig$\KB951978\update\spcustom.dll
+ 2011-02-11 14:32 . 2007-11-30 12:39 17272 c:\windows\$hf_mig$\KB951978\spmsg.dll
+ 2008-05-09 10:45 . 2008-05-09 10:45 90112 c:\windows\$hf_mig$\KB951978\SP3QFE\wshext.dll
+ 2011-02-11 19:55 . 2007-11-30 12:39 26488 c:\windows\$hf_mig$\KB951748\update\spcustom.dll
+ 2011-02-11 19:55 . 2007-11-30 12:39 17272 c:\windows\$hf_mig$\KB951748\spmsg.dll
+ 2011-02-11 14:30 . 2007-11-30 12:39 26488 c:\windows\$hf_mig$\KB950974\update\spcustom.dll
+ 2011-02-11 14:30 . 2007-11-30 12:39 17272 c:\windows\$hf_mig$\KB950974\spmsg.dll
+ 2011-02-11 14:17 . 2007-11-30 12:39 26488 c:\windows\$hf_mig$\KB950762\update\spcustom.dll
+ 2011-02-11 14:17 . 2007-11-30 12:39 17272 c:\windows\$hf_mig$\KB950762\spmsg.dll
+ 2011-02-11 14:14 . 2008-07-09 07:38 26488 c:\windows\$hf_mig$\KB923561\update\spcustom.dll
+ 2011-02-11 14:14 . 2008-07-09 07:38 17272 c:\windows\$hf_mig$\KB923561\spmsg.dll
+ 2011-02-11 14:31 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB2229593\update\spcustom.dll
+ 2011-02-11 14:31 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB2229593\spmsg.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2001-08-17 22:36 . 2009-11-27 16:07 8704 c:\windows\system32\tsbyuv.dll
+ 2009-11-27 16:07 . 2009-11-27 16:07 8704 c:\windows\system32\dllcache\tsbyuv.dll
- 2010-03-22 17:37 . 2008-05-03 11:55 2560 c:\windows\SoftwareDistribution\Download\593d5ddb620b1f1b4bef986c655fd062\SP3QFE\xpsp4res.dll
- 2010-03-22 17:37 . 2008-05-03 11:55 2560 c:\windows\SoftwareDistribution\Download\593d5ddb620b1f1b4bef986c655fd062\SP3GDR\xpsp4res.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 7168 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 7168 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
- 2005-09-23 01:59 . 2005-09-23 01:59 5632 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 5632 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 6656 c:\windows\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 8192 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 8192 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 9728 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
- 2005-09-23 01:58 . 2005-09-23 01:58 9728 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
+ 2008-07-25 05:46 . 2008-07-25 05:46 5120 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
+ 2009-11-27 16:07 . 2009-11-27 16:07 8704 c:\windows\Driver Cache\i386\tsbyuv.dll
- 2010-03-29 05:56 . 2010-03-29 05:56 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2011-02-12 05:23 . 2011-02-12 05:23 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2010-03-29 05:58 . 2010-03-29 05:58 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2010-03-29 05:57 . 2010-03-29 05:57 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2009-11-27 16:28 . 2009-11-27 16:28 8704 c:\windows\$hf_mig$\KB977914\SP3QFE\tsbyuv.dll
+ 2011-02-11 05:12 . 2008-05-03 11:55 2560 c:\windows\$hf_mig$\KB923561\SP3QFE\xpsp4res.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2010-03-29 05:56 . 2010-03-29 05:56 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 635904 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 558080 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcp80.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcm80.dll
+ 2008-04-14 12:00 . 2008-05-08 11:24 155648 c:\windows\system32\wscript.exe
- 2008-04-14 12:00 . 2008-04-14 12:00 155648 c:\windows\system32\wscript.exe
+ 2008-04-14 12:00 . 2009-04-09 19:31 413032 c:\windows\system32\wmspdmod.dll
+ 2008-04-14 12:00 . 2009-07-13 04:38 286720 c:\windows\system32\wmpdxm.dll
+ 2008-04-14 12:00 . 2007-10-27 12:10 227328 c:\windows\system32\wmasf.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 132096 c:\windows\system32\wkssvc.dll
+ 2008-04-14 12:00 . 2009-06-10 06:14 132096 c:\windows\system32\wkssvc.dll
+ 2008-04-14 12:00 . 2009-12-24 06:59 177664 c:\windows\system32\wintrust.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 293376 c:\windows\system32\winsrv.dll
+ 2008-04-14 12:00 . 2010-06-18 17:45 293376 c:\windows\system32\winsrv.dll
+ 2008-04-14 12:00 . 2009-08-25 09:17 354816 c:\windows\system32\winhttp.dll
+ 2009-05-29 06:10 . 2009-02-06 10:10 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2009-05-29 06:10 . 2009-02-09 12:10 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2009-05-29 06:10 . 2009-02-09 12:10 473600 c:\windows\system32\wbem\fastprox.dll
+ 2008-04-14 12:00 . 2010-03-09 11:09 430080 c:\windows\system32\vbscript.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 406016 c:\windows\system32\usp10.dll
+ 2008-04-14 12:00 . 2010-04-16 15:36 406016 c:\windows\system32\usp10.dll
+ 2008-04-14 12:00 . 2010-12-20 22:15 629760 c:\windows\system32\urlmon.dll
+ 2008-04-14 12:00 . 2010-08-27 08:02 119808 c:\windows\system32\t2embed.dll
+ 2008-04-14 12:00 . 2009-08-26 08:00 247326 c:\windows\system32\strmdll.dll
+ 2010-06-29 12:33 . 2008-03-13 04:52 761344 c:\windows\system32\spool\drivers\w32x86\3\unires.dll
+ 2010-06-29 12:33 . 2008-07-06 12:06 744960 c:\windows\system32\spool\drivers\w32x86\3\unidrvui.dll
+ 2010-06-29 12:33 . 2008-07-06 12:06 373248 c:\windows\system32\spool\drivers\w32x86\3\unidrv.dll
+ 2011-02-12 05:28 . 2008-07-06 12:06 198656 c:\windows\system32\spool\drivers\w32x86\3\mxdwdui.dll
+ 2011-02-12 05:28 . 2008-07-06 12:06 765440 c:\windows\system32\spool\drivers\w32x86\3\mxdwdrv.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 474112 c:\windows\system32\shlwapi.dll
+ 2008-04-14 12:00 . 2009-12-08 09:23 474112 c:\windows\system32\shlwapi.dll
+ 2008-04-14 12:00 . 2009-02-06 11:11 110592 c:\windows\system32\services.exe
+ 2008-04-14 12:00 . 2008-05-09 10:53 172032 c:\windows\system32\scrrun.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 172032 c:\windows\system32\scrrun.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 180224 c:\windows\system32\scrobj.dll
+ 2008-04-14 12:00 . 2008-05-09 10:53 180224 c:\windows\system32\scrobj.dll
+ 2008-04-14 12:00 . 2010-06-30 12:31 149504 c:\windows\system32\schannel.dll
+ 2008-04-14 12:00 . 2009-02-09 12:10 401408 c:\windows\system32\rpcss.dll
+ 2008-04-14 12:00 . 2010-08-16 08:45 590848 c:\windows\system32\rpcrt4.dll
+ 2006-08-24 10:45 . 2006-08-24 10:45 150808 c:\windows\system32\rgb9rast_2.dll
+ 2008-04-14 12:00 . 2009-10-12 13:38 149504 c:\windows\system32\rastls.dll
+ 2008-04-14 12:00 . 2011-02-12 05:23 410176 c:\windows\system32\perfh009.dat
+ 2008-04-14 12:00 . 2009-03-06 14:22 284160 c:\windows\system32\pdh.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 284160 c:\windows\system32\pdh.dll
+ 2008-04-14 12:00 . 2010-11-09 14:52 249856 c:\windows\system32\odbc32.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 249856 c:\windows\system32\odbc32.dll
+ 2008-04-14 12:00 . 2009-10-13 10:30 270336 c:\windows\system32\oakley.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 270336 c:\windows\system32\oakley.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 337408 c:\windows\system32\netapi32.dll
+ 2008-04-14 12:00 . 2008-10-15 16:34 337408 c:\windows\system32\netapi32.dll
+ 2008-04-14 12:00 . 2008-06-20 17:46 245248 c:\windows\system32\mswsock.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 245248 c:\windows\system32\mswsock.dll
+ 2008-04-14 12:00 . 2009-08-05 09:01 204800 c:\windows\system32\mswebdvd.dll
+ 2008-04-14 12:00 . 2009-09-11 14:18 136192 c:\windows\system32\msv1_0.dll
+ 2008-04-14 12:00 . 2010-12-20 22:15 532480 c:\windows\system32\mstime.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 532480 c:\windows\system32\mstime.dll
- 2009-05-29 06:10 . 2008-04-14 12:00 343040 c:\windows\system32\mspaint.exe
+ 2009-05-29 06:10 . 2009-12-16 18:43 343040 c:\windows\system32\mspaint.exe
+ 2008-04-14 12:00 . 2010-12-20 22:15 449024 c:\windows\system32\mshtmled.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 449024 c:\windows\system32\mshtmled.dll
- 2009-05-29 06:10 . 2008-04-14 12:00 161792 c:\windows\system32\msdtcuiu.dll
+ 2009-05-29 06:10 . 2008-06-12 14:23 161792 c:\windows\system32\msdtcuiu.dll
+ 2009-05-29 06:10 . 2008-06-12 14:23 956928 c:\windows\system32\msdtctm.dll
- 2009-05-29 06:10 . 2008-04-14 12:00 956928 c:\windows\system32\msdtctm.dll
+ 2009-05-29 06:10 . 2008-06-12 14:23 428032 c:\windows\system32\msdtcprx.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 158720 c:\windows\system32\mscorier.dll
+ 2009-11-05 16:47 . 2009-11-05 16:47 297808 c:\windows\system32\mscoree.dll
+ 2008-04-14 12:00 . 2010-04-05 06:24 384512 c:\windows\system32\mp4sdmod.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 384512 c:\windows\system32\mp4sdmod.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 974848 c:\windows\system32\mfc42u.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 974848 c:\windows\system32\mfc42.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 953856 c:\windows\system32\mfc40u.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 954368 c:\windows\system32\mfc40.dll
+ 2008-04-14 12:00 . 2009-05-07 15:32 345600 c:\windows\system32\localspl.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 989696 c:\windows\system32\kernel32.dll
+ 2008-04-14 12:00 . 2009-03-21 14:06 989696 c:\windows\system32\kernel32.dll
+ 2011-02-11 14:33 . 2009-03-10 16:48 453512 c:\windows\system32\KB905474\wgasetup.exe
+ 2008-04-14 12:00 . 2009-08-13 15:16 512000 c:\windows\system32\jscript.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 512000 c:\windows\system32\jscript.dll
+ 2009-05-29 06:13 . 2010-01-29 15:01 691712 c:\windows\system32\inetcomm.dll
- 2009-05-29 06:13 . 2008-04-14 12:00 691712 c:\windows\system32\inetcomm.dll
+ 2008-04-14 12:00 . 2010-12-20 22:15 251904 c:\windows\system32\iepeers.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 251904 c:\windows\system32\iepeers.dll
+ 2008-04-14 12:00 . 2008-10-23 12:36 286720 c:\windows\system32\gdi32.dll
- 2009-05-29 11:17 . 2010-10-09 17:03 330688 c:\windows\system32\FNTCACHE.DAT
+ 2009-05-29 11:17 . 2011-02-12 05:09 330688 c:\windows\system32\FNTCACHE.DAT
+ 2008-04-14 12:00 . 2008-07-07 20:26 253952 c:\windows\system32\es.dll
+ 2008-04-14 12:00 . 2010-02-11 12:02 226880 c:\windows\system32\drivers\tcpip6.sys
+ 2008-04-14 12:00 . 2008-06-20 11:51 361600 c:\windows\system32\drivers\tcpip.sys
+ 2008-04-14 12:00 . 2010-06-21 15:27 354304 c:\windows\system32\drivers\srv.sys
+ 2008-04-14 12:00 . 2008-05-08 14:02 203136 c:\windows\system32\drivers\rmcast.sys
+ 2008-04-14 12:00 . 2010-02-24 13:11 455680 c:\windows\system32\drivers\mrxsmb.sys
+ 2008-04-14 12:00 . 2009-10-20 16:20 265728 c:\windows\system32\drivers\http.sys
+ 2010-03-22 17:36 . 2008-06-13 11:05 272128 c:\windows\system32\drivers\bthport.sys
+ 2008-04-14 12:00 . 2008-08-14 10:04 138496 c:\windows\system32\drivers\afd.sys
+ 2008-04-14 12:00 . 2008-06-20 17:46 147968 c:\windows\system32\dnsapi.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 147968 c:\windows\system32\dnsapi.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 155648 c:\windows\system32\dllcache\wscript.exe
+ 2008-04-14 12:00 . 2008-05-08 11:24 155648 c:\windows\system32\dllcache\wscript.exe
+ 2009-05-29 06:10 . 2010-07-12 12:55 218112 c:\windows\system32\dllcache\wordpad.exe
+ 2008-04-14 12:00 . 2009-04-09 19:31 413032 c:\windows\system32\dllcache\wmspdmod.dll
+ 2008-04-14 12:00 . 2009-07-13 04:38 286720 c:\windows\system32\dllcache\wmpdxm.dll
+ 2009-05-29 06:10 . 2009-02-06 10:10 227840 c:\windows\system32\dllcache\wmiprvse.exe
+ 2009-05-29 06:10 . 2009-02-09 12:10 453120 c:\windows\system32\dllcache\wmiprvsd.dll
+ 2008-04-14 12:00 . 2007-10-27 12:10 227328 c:\windows\system32\dllcache\wmasf.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 132096 c:\windows\system32\dllcache\wkssvc.dll
+ 2008-04-14 12:00 . 2009-06-10 06:14 132096 c:\windows\system32\dllcache\wkssvc.dll
+ 2008-04-14 12:00 . 2009-12-24 06:59 177664 c:\windows\system32\dllcache\wintrust.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 293376 c:\windows\system32\dllcache\winsrv.dll
+ 2008-04-14 12:00 . 2010-06-18 17:45 293376 c:\windows\system32\dllcache\winsrv.dll
+ 2008-04-14 12:00 . 2010-12-20 22:15 667136 c:\windows\system32\dllcache\wininet.dll
+ 2008-04-14 12:00 . 2009-08-25 09:17 354816 c:\windows\system32\dllcache\winhttp.dll
+ 2008-04-14 12:00 . 2010-03-09 11:09 430080 c:\windows\system32\dllcache\vbscript.dll
+ 2008-04-14 12:00 . 2010-04-16 15:36 406016 c:\windows\system32\dllcache\usp10.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 406016 c:\windows\system32\dllcache\usp10.dll
+ 2008-04-14 12:00 . 2010-12-20 22:15 629760 c:\windows\system32\dllcache\urlmon.dll
- 2009-05-29 06:13 . 2008-04-14 12:00 153088 c:\windows\system32\dllcache\triedit.dll
+ 2009-05-29 06:13 . 2009-06-21 21:44 153088 c:\windows\system32\dllcache\triedit.dll
+ 2008-04-14 12:00 . 2010-02-11 12:02 226880 c:\windows\system32\dllcache\tcpip6.sys
+ 2008-04-14 12:00 . 2008-06-20 11:51 361600 c:\windows\system32\dllcache\tcpip.sys
+ 2008-04-14 12:00 . 2010-08-27 08:02 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2008-04-14 12:00 . 2009-08-26 08:00 247326 c:\windows\system32\dllcache\strmdll.dll
+ 2008-04-14 12:00 . 2010-06-21 15:27 354304 c:\windows\system32\dllcache\srv.sys
+ 2008-04-14 12:00 . 2009-12-08 09:23 474112 c:\windows\system32\dllcache\shlwapi.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 474112 c:\windows\system32\dllcache\shlwapi.dll
+ 2008-04-14 12:00 . 2011-01-21 14:44 439296 c:\windows\system32\dllcache\shimgvw.dll
+ 2008-04-14 12:00 . 2009-02-06 11:11 110592 c:\windows\system32\dllcache\services.exe
+ 2008-04-14 12:00 . 2008-05-09 10:53 172032 c:\windows\system32\dllcache\scrrun.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 172032 c:\windows\system32\dllcache\scrrun.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 180224 c:\windows\system32\dllcache\scrobj.dll
+ 2008-04-14 12:00 . 2008-05-09 10:53 180224 c:\windows\system32\dllcache\scrobj.dll
+ 2008-04-14 12:00 . 2010-06-30 12:31 149504 c:\windows\system32\dllcache\schannel.dll
+ 2008-04-14 12:00 . 2009-02-09 12:10 401408 c:\windows\system32\dllcache\rpcss.dll
+ 2008-04-14 12:00 . 2010-08-16 08:45 590848 c:\windows\system32\dllcache\rpcrt4.dll
+ 2008-04-14 12:00 . 2008-05-08 14:02 203136 c:\windows\system32\dllcache\rmcast.sys
+ 2008-04-14 12:00 . 2009-10-12 13:38 149504 c:\windows\system32\dllcache\rastls.dll
+ 2008-04-14 12:00 . 2009-03-06 14:22 284160 c:\windows\system32\dllcache\pdh.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 284160 c:\windows\system32\dllcache\pdh.dll
+ 2008-04-14 12:00 . 2010-11-09 14:52 249856 c:\windows\system32\dllcache\odbc32.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 249856 c:\windows\system32\dllcache\odbc32.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 270336 c:\windows\system32\dllcache\oakley.dll
+ 2008-04-14 12:00 . 2009-10-13 10:30 270336 c:\windows\system32\dllcache\oakley.dll
+ 2008-04-14 12:00 . 2010-12-09 15:15 718336 c:\windows\system32\dllcache\ntdll.dll
+ 2008-04-14 12:00 . 2008-10-15 16:34 337408 c:\windows\system32\dllcache\netapi32.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 337408 c:\windows\system32\dllcache\netapi32.dll
+ 2008-04-14 12:00 . 2008-06-20 17:46 245248 c:\windows\system32\dllcache\mswsock.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 245248 c:\windows\system32\dllcache\mswsock.dll
+ 2008-04-14 12:00 . 2009-08-05 09:01 204800 c:\windows\system32\dllcache\mswebdvd.dll
+ 2008-04-14 12:00 . 2009-09-11 14:18 136192 c:\windows\system32\dllcache\msv1_0.dll
+ 2008-04-14 12:00 . 2010-12-20 22:15 532480 c:\windows\system32\dllcache\mstime.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 532480 c:\windows\system32\dllcache\mstime.dll
- 2009-05-29 06:10 . 2008-04-14 12:00 343040 c:\windows\system32\dllcache\mspaint.exe
+ 2009-05-29 06:10 . 2009-12-16 18:43 343040 c:\windows\system32\dllcache\mspaint.exe
- 2009-05-29 06:13 . 2008-04-14 12:00 102400 c:\windows\system32\dllcache\msjro.dll
+ 2009-05-29 06:13 . 2010-11-09 14:52 102400 c:\windows\system32\dllcache\msjro.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 449024 c:\windows\system32\dllcache\mshtmled.dll
+ 2008-04-14 12:00 . 2010-12-20 22:15 449024 c:\windows\system32\dllcache\mshtmled.dll
+ 2009-05-29 06:10 . 2008-06-12 14:23 161792 c:\windows\system32\dllcache\msdtcuiu.dll
- 2009-05-29 06:10 . 2008-04-14 12:00 161792 c:\windows\system32\dllcache\msdtcuiu.dll
- 2009-05-29 06:10 . 2008-04-14 12:00 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2009-05-29 06:10 . 2008-06-12 14:23 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2009-05-29 06:10 . 2008-06-12 14:23 428032 c:\windows\system32\dllcache\msdtcprx.dll
- 2009-05-29 06:13 . 2008-04-14 12:00 200704 c:\windows\system32\dllcache\msadox.dll
+ 2009-05-29 06:13 . 2010-11-09 14:52 200704 c:\windows\system32\dllcache\msadox.dll
- 2009-05-29 06:13 . 2008-04-14 12:00 180224 c:\windows\system32\dllcache\msadomd.dll
+ 2009-05-29 06:13 . 2010-11-09 14:52 180224 c:\windows\system32\dllcache\msadomd.dll
+ 2009-05-29 06:13 . 2010-11-09 14:52 536576 c:\windows\system32\dllcache\msado15.dll
- 2009-05-29 06:13 . 2008-04-14 12:00 536576 c:\windows\system32\dllcache\msado15.dll
+ 2009-05-29 06:13 . 2010-11-09 14:52 143360 c:\windows\system32\dllcache\msadco.dll
- 2009-05-29 06:13 . 2008-04-14 12:00 143360 c:\windows\system32\dllcache\msadco.dll
+ 2009-05-29 06:13 . 2008-05-01 14:33 331776 c:\windows\system32\dllcache\msadce.dll
- 2009-05-29 06:13 . 2008-04-14 12:00 331776 c:\windows\system32\dllcache\msadce.dll
+ 2010-08-02 21:25 . 2010-02-24 13:11 455680 c:\windows\system32\dllcache\mrxsmb.sys
+ 2008-04-14 12:00 . 2010-04-05 06:24 384512 c:\windows\system32\dllcache\mp4sdmod.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 384512 c:\windows\system32\dllcache\mp4sdmod.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 974848 c:\windows\system32\dllcache\mfc42u.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 974848 c:\windows\system32\dllcache\mfc42.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 953856 c:\windows\system32\dllcache\mfc40u.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 954368 c:\windows\system32\dllcache\mfc40.dll
+ 2008-04-14 12:00 . 2010-12-20 17:26 730112 c:\windows\system32\dllcache\lsasrv.dll
+ 2008-04-14 12:00 . 2009-05-07 15:32 345600 c:\windows\system32\dllcache\localspl.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 989696 c:\windows\system32\dllcache\kernel32.dll
+ 2008-04-14 12:00 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\kernel32.dll
+ 2008-04-14 12:00 . 2010-12-22 12:34 301568 c:\windows\system32\dllcache\kerberos.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 512000 c:\windows\system32\dllcache\jscript.dll
+ 2008-04-14 12:00 . 2009-08-13 15:16 512000 c:\windows\system32\dllcache\jscript.dll
+ 2009-05-29 06:13 . 2010-01-29 15:01 691712 c:\windows\system32\dllcache\inetcomm.dll
- 2009-05-29 06:13 . 2008-04-14 12:00 691712 c:\windows\system32\dllcache\inetcomm.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 251904 c:\windows\system32\dllcache\iepeers.dll
+ 2008-04-14 12:00 . 2010-12-20 22:15 251904 c:\windows\system32\dllcache\iepeers.dll
+ 2009-10-20 16:20 . 2009-10-20 16:20 265728 c:\windows\system32\dllcache\http.sys
- 2009-05-29 06:13 . 2008-04-14 12:00 744448 c:\windows\system32\dllcache\helpsvc.exe
+ 2009-05-29 06:13 . 2010-06-14 14:31 744448 c:\windows\system32\dllcache\helpsvc.exe
+ 2008-04-14 12:00 . 2008-10-23 12:36 286720 c:\windows\system32\dllcache\gdi32.dll
+ 2009-05-29 06:10 . 2009-02-09 12:10 473600 c:\windows\system32\dllcache\fastprox.dll
+ 2008-04-14 12:00 . 2008-07-07 20:26 253952 c:\windows\system32\dllcache\es.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 147968 c:\windows\system32\dllcache\dnsapi.dll
+ 2008-04-14 12:00 . 2008-06-20 17:46 147968 c:\windows\system32\dllcache\dnsapi.dll
+ 2008-04-14 12:00 . 2008-05-07 09:07 135168 c:\windows\system32\dllcache\cscript.exe
- 2008-04-14 12:00 . 2008-04-14 12:00 617472 c:\windows\system32\dllcache\comctl32.dll
+ 2008-04-14 12:00 . 2010-08-23 16:12 617472 c:\windows\system32\dllcache\comctl32.dll
+ 2010-03-22 17:36 . 2008-06-13 11:05 272128 c:\windows\system32\dllcache\bthport.sys
+ 2008-04-14 12:00 . 2011-01-07 14:09 290048 c:\windows\system32\dllcache\atmfd.dll
+ 2008-04-14 12:00 . 2008-08-14 10:04 138496 c:\windows\system32\dllcache\afd.sys
+ 2008-04-14 12:00 . 2009-02-09 12:10 617472 c:\windows\system32\dllcache\advapi32.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 617472 c:\windows\system32\dllcache\advapi32.dll
+ 2008-04-14 12:00 . 2009-11-21 15:51 471552 c:\windows\system32\dllcache\aclayers.dll
+ 2008-04-14 12:00 . 2010-02-12 04:33 100864 c:\windows\system32\dllcache\6to4svc.dll
+ 2008-04-14 12:00 . 2008-05-07 09:07 135168 c:\windows\system32\cscript.exe
- 2008-04-14 12:00 . 2008-04-14 12:00 617472 c:\windows\system32\comctl32.dll
+ 2008-04-14 12:00 . 2010-08-23 16:12 617472 c:\windows\system32\comctl32.dll
+ 2008-04-14 12:00 . 2009-02-09 12:10 617472 c:\windows\system32\advapi32.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 617472 c:\windows\system32\advapi32.dll
+ 2008-04-14 12:00 . 2010-02-12 04:33 100864 c:\windows\system32\6to4svc.dll
- 2010-03-22 17:47 . 2007-11-30 12:39 382840 c:\windows\SoftwareDistribution\Download\fae8bc4d2da2adc1b9109ef4e6cecd1f\update\updspapi.dll
- 2010-03-22 17:47 . 2007-11-30 12:39 755576 c:\windows\SoftwareDistribution\Download\fae8bc4d2da2adc1b9109ef4e6cecd1f\update\update.exe
- 2010-03-22 17:47 . 2007-11-30 12:39 231288 c:\windows\SoftwareDistribution\Download\fae8bc4d2da2adc1b9109ef4e6cecd1f\spuninst.exe
- 2010-08-02 20:49 . 2007-11-30 12:39 382840 c:\windows\SoftwareDistribution\Download\f6ae6c01481096f08117233982ca37f9\update\updspapi.dll
- 2010-08-02 20:49 . 2007-11-30 12:39 755576 c:\windows\SoftwareDistribution\Download\f6ae6c01481096f08117233982ca37f9\update\update.exe
- 2010-08-02 20:49 . 2007-11-30 12:39 231288 c:\windows\SoftwareDistribution\Download\f6ae6c01481096f08117233982ca37f9\spuninst.exe
- 2010-08-03 15:36 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\f2adb0f8440e5dbd459aa6bfcaed1ba5\update\updspapi.dll
- 2010-08-03 15:36 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\f2adb0f8440e5dbd459aa6bfcaed1ba5\update\update.exe
- 2010-08-03 15:36 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\f2adb0f8440e5dbd459aa6bfcaed1ba5\spuninst.exe
- 2010-08-02 20:48 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\de81b460c3abcfc5b8494c785a5f3944\update\updspapi.dll
- 2010-08-02 20:48 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\de81b460c3abcfc5b8494c785a5f3944\update\update.exe
- 2010-08-02 20:48 . 2008-07-08 13:02 231288 c:\windows\SoftwareDistribution\Download\de81b460c3abcfc5b8494c785a5f3944\spuninst.exe
- 2010-08-03 15:38 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\da2a33b6770f970d7fe7262040f98a4f\update\updspapi.dll
- 2010-08-03 15:38 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\da2a33b6770f970d7fe7262040f98a4f\update\update.exe
- 2010-08-03 15:38 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\da2a33b6770f970d7fe7262040f98a4f\spuninst.exe
- 2010-03-22 17:32 . 2008-07-08 13:02 382840 c:\windows\SoftwareDistribution\Download\d8ef7c8f90f509563f255df3e967b057\update\updspapi.dll
- 2010-03-22 17:32 . 2008-07-08 13:02 755576 c:\windows\SoftwareDistribution\Download\d8ef7c8f90f509563f255df3e967b057\update\update.exe
- 2010-03-22 17:32 . 2008-07-08 13:02 231288 c:\windows\SoftwareDistribution\Download\d8ef7c8f90f509563f255df3e967b057\spuninst.exe
- 2010-03-22 17:32 . 2009-10-15 16:39 119808 c:\windows\SoftwareDistribution\Download\d8ef7c8f90f509563f255df3e967b057\SP3QFE\t2embed.dll
- 2010-03-22 17:32 . 2009-10-15 16:28 119808 c:\windows\SoftwareDistribution\Download\d8ef7c8f90f509563f255df3e967b057\SP3GDR\t2embed.dll
- 2010-03-22 17:32 . 2009-10-15 16:56 119808 c:\windows\SoftwareDistribution\Download\d8ef7c8f90f509563f255df3e967b057\SP2QFE\t2embed.dll
- 2010-08-03 15:40 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\d48a3b967ba5709df048e8f2a49cf8a6\update\updspapi.dll
- 2010-08-03 15:40 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\d48a3b967ba5709df048e8f2a49cf8a6\update\update.exe
- 2010-08-03 15:40 . 2008-07-08 13:02 231288 c:\windows\SoftwareDistribution\Download\d48a3b967ba5709df048e8f2a49cf8a6\spuninst.exe
- 2010-08-03 15:28 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\update\updspapi.dll
- 2010-08-03 15:28 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\update\update.exe
- 2010-08-03 15:28 . 2008-07-08 13:02 231288 c:\windows\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\spuninst.exe
- 2010-03-22 17:30 . 2008-07-08 13:02 382840 c:\windows\SoftwareDistribution\Download\c263092dccc247f68a43cfee93ecc72d\update\updspapi.dll
- 2010-03-22 17:30 . 2008-07-08 13:02 755576 c:\windows\SoftwareDistribution\Download\c263092dccc247f68a43cfee93ecc72d\update\update.exe
- 2010-03-22 17:30 . 2008-07-08 13:02 231288 c:\windows\SoftwareDistribution\Download\c263092dccc247f68a43cfee93ecc72d\spuninst.exe
- 2010-03-22 17:30 . 2009-06-21 21:49 153088 c:\windows\SoftwareDistribution\Download\c263092dccc247f68a43cfee93ecc72d\SP3QFE\triedit.dll
- 2010-03-22 17:30 . 2009-06-21 21:44 153088 c:\windows\SoftwareDistribution\Download\c263092dccc247f68a43cfee93ecc72d\SP3GDR\triedit.dll
- 2010-03-22 17:30 . 2009-06-21 21:55 153088 c:\windows\SoftwareDistribution\Download\c263092dccc247f68a43cfee93ecc72d\SP2QFE\triedit.dll
- 2010-03-22 17:30 . 2009-06-21 22:04 153088 c:\windows\SoftwareDistribution\Download\c263092dccc247f68a43cfee93ecc72d\SP2GDR\triedit.dll
- 2010-03-22 17:47 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\c0c52c03306062533f7dcb087bfcfa6b\update\updspapi.dll
- 2010-03-22 17:47 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\c0c52c03306062533f7dcb087bfcfa6b\update\update.exe
- 2010-03-22 17:47 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\c0c52c03306062533f7dcb087bfcfa6b\spuninst.exe
- 2010-03-22 17:46 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\b7f0b2892b21211a5630518d058f48d9\update\updspapi.dll
- 2010-03-22 17:46 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\b7f0b2892b21211a5630518d058f48d9\update\update.exe
- 2010-03-22 17:46 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\b7f0b2892b21211a5630518d058f48d9\spuninst.exe
- 2010-08-03 15:13 . 2007-11-30 12:39 382840 c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\update\updspapi.dll
- 2010-08-03 15:13 . 2007-11-30 12:39 755576 c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\update\update.exe
- 2010-08-03 15:13 . 2007-11-30 12:39 231288 c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\spuninst.exe
- 2010-03-22 17:32 . 2008-07-08 13:02 382840 c:\windows\SoftwareDistribution\Download\9cf59263a134ab3fbbee78365a2fa5fc\update\updspapi.dll
- 2010-03-22 17:32 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\9cf59263a134ab3fbbee78365a2fa5fc\update\update.exe
- 2010-03-22 17:32 . 2008-07-08 13:02 231288 c:\windows\SoftwareDistribution\Download\9cf59263a134ab3fbbee78365a2fa5fc\spuninst.exe
- 2010-03-22 17:32 . 2009-06-09 14:53 290816 c:\windows\SoftwareDistribution\Download\9cf59263a134ab3fbbee78365a2fa5fc\SP2QFE\rhttpaa.dll
- 2010-03-22 17:32 . 2009-06-09 09:12 677888 c:\windows\SoftwareDistribution\Download\9cf59263a134ab3fbbee78365a2fa5fc\SP2QFE\lhmstsc.exe
- 2010-03-22 17:32 . 2009-06-09 14:53 136192 c:\windows\SoftwareDistribution\Download\9cf59263a134ab3fbbee78365a2fa5fc\SP2QFE\aaclient.dll
- 2010-08-03 15:24 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\update\updspapi.dll
- 2010-08-03 15:24 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\update\update.exe
- 2010-08-03 15:24 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\spuninst.exe
- 2010-03-22 17:47 . 2007-11-30 12:39 382840 c:\windows\SoftwareDistribution\Download\8cac00e8efc87d728c0261686f85c975\update\updspapi.dll
- 2010-03-22 17:47 . 2007-11-30 12:39 755576 c:\windows\SoftwareDistribution\Download\8cac00e8efc87d728c0261686f85c975\update\update.exe
- 2010-03-22 17:47 . 2007-11-30 12:39 231288 c:\windows\SoftwareDistribution\Download\8cac00e8efc87d728c0261686f85c975\spuninst.exe
- 2010-08-03 15:38 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\update\updspapi.dll
- 2010-08-03 15:38 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\update\update.exe
- 2010-08-03 15:38 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\spuninst.exe
- 2010-08-02 20:43 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\78cf8552430e25a8f24bc1e4dfb1970e\update\updspapi.dll
- 2010-08-02 20:43 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\78cf8552430e25a8f24bc1e4dfb1970e\update\update.exe
- 2010-08-02 20:43 . 2008-07-08 13:02 231288 c:\windows\SoftwareDistribution\Download\78cf8552430e25a8f24bc1e4dfb1970e\spuninst.exe
- 2010-03-22 17:28 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\75cd10bc79782317976e2a857798ad9f\update\updspapi.dll
- 2010-03-22 17:28 . 2008-07-08 13:02 755576 c:\windows\SoftwareDistribution\Download\75cd10bc79782317976e2a857798ad9f\update\update.exe
- 2010-03-22 17:28 . 2008-07-08 13:02 231288 c:\windows\SoftwareDistribution\Download\75cd10bc79782317976e2a857798ad9f\spuninst.exe
- 2010-08-03 15:27 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\6a410a1bd174bc123056d235ac4829af\update\updspapi.dll
- 2010-08-03 15:27 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\6a410a1bd174bc123056d235ac4829af\update\update.exe
- 2010-08-03 15:27 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\6a410a1bd174bc123056d235ac4829af\spuninst.exe
- 2010-08-03 15:38 . 2008-07-09 07:38 382840 c:\windows\SoftwareDistribution\Download\64cc77a1a7652da2d7ace79940460770\update\updspapi.dll
- 2010-08-03 15:38 . 2008-07-09 07:38 755576 c:\windows\SoftwareDistribution\Download\64cc77a1a7652da2d7ace79940460770\update\update.exe
- 2010-08-03 15:38 . 2008-07-09 07:38 231288 c:\windows\SoftwareDistribution\Download\64cc77a1a7652da2d7ace79940460770\spuninst.exe
- 2010-03-22 17:27 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\5e5aab0184cde550e4ba21f1d2bd377e\update\updspapi.dll
- 2010-03-22 17:27 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\5e5aab0184cde550e4ba21f1d2bd377e\update\update.exe
- 2010-03-22 17:27 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\5e5aab0184cde550e4ba21f1d2bd377e\spuninst.exe
- 2010-03-22 17:27 . 2009-07-29 14:01 119648 c:\windows\SoftwareDistribution\Download\5e5aab0184cde550e4ba21f1d2bd377e\SP3QFE\msconv97.dll
- 2010-03-22 17:27 . 2009-07-29 14:01 119648 c:\windows\SoftwareDistribution\Download\5e5aab0184cde550e4ba21f1d2bd377e\SP3GDR\msconv97.dll
- 2010-03-22 17:37 . 2008-07-09 07:38 382840 c:\windows\SoftwareDistribution\Download\593d5ddb620b1f1b4bef986c655fd062\update\updspapi.dll
- 2010-03-22 17:37 . 2008-11-15 17:18 755576 c:\windows\SoftwareDistribution\Download\593d5ddb620b1f1b4bef986c655fd062\update\update.exe
- 2010-03-22 17:37 . 2008-07-09 07:38 231288 c:\windows\SoftwareDistribution\Download\593d5ddb620b1f1b4bef986c655fd062\spuninst.exe
- 2010-03-22 17:37 . 2008-04-21 12:15 215552 c:\windows\SoftwareDistribution\Download\593d5ddb620b1f1b4bef986c655fd062\SP3QFE\wordpad.exe
- 2010-03-22 17:37 . 2008-04-21 12:08 215552 c:\windows\SoftwareDistribution\Download\593d5ddb620b1f1b4bef986c655fd062\SP3GDR\wordpad.exe
- 2010-03-22 17:37 . 2008-02-15 09:06 351744 c:\windows\SoftwareDistribution\Download\593d5ddb620b1f1b4bef986c655fd062\SP2QFE\xpsp3res.dll
- 2010-03-22 17:37 . 2008-04-21 09:26 215552 c:\windows\SoftwareDistribution\Download\593d5ddb620b1f1b4bef986c655fd062\SP2QFE\wordpad.exe
- 2010-03-22 17:37 . 2008-02-15 09:06 351744 c:\windows\SoftwareDistribution\Download\593d5ddb620b1f1b4bef986c655fd062\SP2GDR\xpsp3res.dll
- 2010-03-22 17:37 . 2008-04-21 10:02 215552 c:\windows\SoftwareDistribution\Download\593d5ddb620b1f1b4bef986c655fd062\SP2GDR\wordpad.exe
- 2010-03-22 17:46 . 2008-07-09 07:38 382840 c:\windows\SoftwareDistribution\Download\55ae228715888b68a08f491655790fa6\update\updspapi.dll
- 2010-03-22 17:46 . 2008-07-09 07:38 755576 c:\windows\SoftwareDistribution\Download\55ae228715888b68a08f491655790fa6\update\update.exe
- 2010-03-22 17:46 . 2008-07-09 07:38 231288 c:\windows\SoftwareDistribution\Download\55ae228715888b68a08f491655790fa6\spuninst.exe
- 2010-03-22 17:32 . 2008-07-09 07:38 382840 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\update\updspapi.dll
- 2010-03-22 17:32 . 2008-07-09 07:38 755576 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\update\update.exe
- 2010-03-22 17:32 . 2008-07-09 07:38 231288 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\spuninst.exe
- 2010-03-22 17:32 . 2009-02-06 10:15 227840 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\wmiprvse.exe
- 2010-03-22 17:32 . 2009-02-09 10:56 453120 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\wmiprvsd.dll
- 2010-03-22 17:32 . 2009-02-06 11:06 110592 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\services.exe
- 2010-03-22 17:32 . 2009-02-09 10:56 401408 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\rpcss.dll
- 2010-03-22 17:32 . 2009-03-06 13:49 284160 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\pdh.dll
- 2010-03-22 17:32 . 2009-02-09 10:56 715264 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\ntdll.dll
- 2010-03-22 17:32 . 2009-02-09 10:56 729088 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\lsasrv.dll
- 2010-03-22 17:32 . 2009-02-09 10:56 473600 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\fastprox.dll
- 2010-03-22 17:32 . 2009-02-06 10:10 227840 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\wmiprvse.exe
- 2010-03-22 17:32 . 2009-02-09 12:10 453120 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\wmiprvsd.dll
- 2010-03-22 17:32 . 2009-02-06 11:11 110592 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\services.exe
- 2010-03-22 17:32 . 2009-02-09 12:10 401408 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\rpcss.dll
- 2010-03-22 17:32 . 2009-03-06 14:22 284160 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\pdh.dll
- 2010-03-22 17:32 . 2009-02-09 12:10 714752 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\ntdll.dll
- 2010-03-22 17:32 . 2009-02-09 12:10 729088 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\lsasrv.dll
- 2010-03-22 17:32 . 2009-02-09 12:10 473600 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\fastprox.dll
- 2010-03-22 17:32 . 2009-02-09 12:10 617472 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\advapi32.dll
- 2010-03-22 17:32 . 2009-02-06 09:41 227840 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\wmiprvse.exe
- 2010-03-22 17:32 . 2009-02-06 10:22 110592 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\services.exe
- 2010-03-22 17:32 . 2009-02-09 10:01 401408 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\rpcss.dll
- 2010-03-22 17:32 . 2009-03-06 14:00 284160 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\pdh.dll
- 2010-03-22 17:32 . 2009-02-09 10:01 715264 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\ntdll.dll
- 2010-03-22 17:32 . 2009-02-09 10:01 728576 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\lsasrv.dll
- 2010-03-22 17:32 . 2009-02-09 10:01 473088 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\fastprox.dll
- 2010-03-22 17:32 . 2009-02-09 10:01 617984 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\advapi32.dll
- 2010-03-22 17:32 . 2009-02-06 16:39 227840 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\wmiprvse.exe
- 2010-03-22 17:32 . 2009-02-09 10:20 453120 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\wmiprvsd.dll
- 2010-03-22 17:32 . 2009-02-06 17:14 110592 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\services.exe
- 2010-03-22 17:32 . 2009-02-09 10:20 399360 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\rpcss.dll
- 2010-03-22 17:32 . 2009-03-06 14:44 283648 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\pdh.dll
- 2010-03-22 17:32 . 2009-02-09 10:20 714752 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\ntdll.dll
- 2010-03-22 17:32 . 2009-02-09 10:20 723456 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\lsasrv.dll
- 2010-03-22 17:32 . 2009-02-09 10:20 473088 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\fastprox.dll
- 2010-03-22 17:32 . 2009-02-09 10:20 616960 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\advapi32.dll
- 2010-03-22 17:47 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\50e2c72fd814d3841e776dd2c4918260\update\updspapi.dll
- 2010-03-22 17:47 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\50e2c72fd814d3841e776dd2c4918260\update\update.exe
- 2010-03-22 17:47 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\50e2c72fd814d3841e776dd2c4918260\spuninst.exe
- 2010-03-22 17:27 . 2007-11-30 11:18 382840 c:\windows\SoftwareDistribution\Download\4b975c8f39482ac4287e885ca058f798\update\updspapi.dll
- 2010-03-22 17:27 . 2007-11-30 11:18 755576 c:\windows\SoftwareDistribution\Download\4b975c8f39482ac4287e885ca058f798\update\update.exe
- 2010-03-22 17:27 . 2007-11-30 11:18 231288 c:\windows\SoftwareDistribution\Download\4b975c8f39482ac4287e885ca058f798\spuninst.exe
- 2010-03-22 17:27 . 2008-05-01 14:38 331776 c:\windows\SoftwareDistribution\Download\4b975c8f39482ac4287e885ca058f798\SP3QFE\msadce.dll
- 2010-03-22 17:27 . 2008-05-01 14:33 331776 c:\windows\SoftwareDistribution\Download\4b975c8f39482ac4287e885ca058f798\SP3GDR\msadce.dll
- 2010-03-22 17:27 . 2008-05-01 15:04 331776 c:\windows\SoftwareDistribution\Download\4b975c8f39482ac4287e885ca058f798\SP2QFE\msadce.dll
- 2010-03-22 17:27 . 2008-05-01 14:30 331776 c:\windows\SoftwareDistribution\Download\4b975c8f39482ac4287e885ca058f798\SP2GDR\msadce.dll
- 2010-03-22 17:11 . 2007-11-30 11:18 382840 c:\windows\SoftwareDistribution\Download\491a2c8e1582f5cdd01f8b3da4b8ef7d\update\updspapi.dll
- 2010-03-22 17:11 . 2007-11-30 11:18 755576 c:\windows\SoftwareDistribution\Download\491a2c8e1582f5cdd01f8b3da4b8ef7d\update\update.exe
- 2010-03-22 17:11 . 2007-11-30 11:18 231288 c:\windows\SoftwareDistribution\Download\491a2c8e1582f5cdd01f8b3da4b8ef7d\spuninst.exe
- 2010-03-22 17:11 . 2008-10-15 16:25 339456 c:\windows\SoftwareDistribution\Download\491a2c8e1582f5cdd01f8b3da4b8ef7d\SP3QFE\netapi32.dll
- 2010-03-22 17:11 . 2008-10-15 16:34 337408 c:\windows\SoftwareDistribution\Download\491a2c8e1582f5cdd01f8b3da4b8ef7d\SP3GDR\netapi32.dll
- 2010-03-22 17:11 . 2008-10-15 16:53 339456 c:\windows\SoftwareDistribution\Download\491a2c8e1582f5cdd01f8b3da4b8ef7d\SP2QFE\netapi32.dll
- 2010-03-22 17:11 . 2008-10-15 16:57 332800 c:\windows\SoftwareDistribution\Download\491a2c8e1582f5cdd01f8b3da4b8ef7d\SP2GDR\netapi32.dll
- 2010-08-03 15:40 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\42360c8fdaf030cd25332428cfba61cd\update\updspapi.dll
- 2010-08-03 15:40 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\42360c8fdaf030cd25332428cfba61cd\update\update.exe
- 2010-08-03 15:40 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\42360c8fdaf030cd25332428cfba61cd\spuninst.exe
- 2010-03-22 15:39 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\3f62db0dd41de1740f8addce0cc500ec\update\updspapi.dll
- 2010-03-22 15:39 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\3f62db0dd41de1740f8addce0cc500ec\update\update.exe
- 2010-03-22 15:39 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\3f62db0dd41de1740f8addce0cc500ec\spuninst.exe
- 2010-03-22 15:39 . 2009-08-13 15:02 512000 c:\windows\SoftwareDistribution\Download\3f62db0dd41de1740f8addce0cc500ec\SP3QFE\jscript.dll
- 2010-03-22 15:39 . 2009-08-13 15:16 512000 c:\windows\SoftwareDistribution\Download\3f62db0dd41de1740f8addce0cc500ec\SP3GDR\jscript.dll
- 2010-03-22 17:46 . 2007-11-30 12:39 382840 c:\windows\SoftwareDistribution\Download\37ea7d9587e54acc7afa27dc26096f4f\update\updspapi.dll
- 2010-03-22 17:46 . 2007-11-30 12:39 755576 c:\windows\SoftwareDistribution\Download\37ea7d9587e54acc7afa27dc26096f4f\update\update.exe
- 2010-03-22 17:46 . 2007-11-30 12:39 231288 c:\windows\SoftwareDistribution\Download\37ea7d9587e54acc7afa27dc26096f4f\spuninst.exe
- 2010-03-22 17:37 . 2008-07-09 07:38 382840 c:\windows\SoftwareDistribution\Download\3361704fe1a0367fcfe17758efab6972\update\updspapi.dll
- 2010-03-22 17:37 . 2008-07-09 07:38 755576 c:\windows\SoftwareDistribution\Download\3361704fe1a0367fcfe17758efab6972\update\update.exe
- 2010-03-22 17:37 . 2008-07-08 13:02 231288 c:\windows\SoftwareDistribution\Download\3361704fe1a0367fcfe17758efab6972\spuninst.exe
- 2010-08-03 15:27 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\2e6b16219034e135b4f869efb7a10fee\update\updspapi.dll
- 2010-08-03 15:27 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\2e6b16219034e135b4f869efb7a10fee\update\update.exe
- 2010-08-03 15:27 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\2e6b16219034e135b4f869efb7a10fee\spuninst.exe
- 2010-03-22 17:30 . 2008-07-08 13:02 382840 c:\windows\SoftwareDistribution\Download\2c95b28351986132d7f36dd28eece9b0\update\updspapi.dll
- 2010-03-22 17:30 . 2008-07-08 13:02 755576 c:\windows\SoftwareDistribution\Download\2c95b28351986132d7f36dd28eece9b0\update\update.exe
- 2010-03-22 17:30 . 2008-07-08 13:02 231288 c:\windows\SoftwareDistribution\Download\2c95b28351986132d7f36dd28eece9b0\spuninst.exe
- 2010-08-02 21:20 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\2c0d861a85182505b6e0107596abb839\update\update.exe
- 2010-08-02 21:20 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\2c0d861a85182505b6e0107596abb839\spuninst.exe
- 2010-08-02 21:20 . 2010-06-14 14:38 744448 c:\windows\SoftwareDistribution\Download\2c0d861a85182505b6e0107596abb839\SP3QFE\helpsvc.exe
- 2010-08-02 21:20 . 2010-06-14 14:31 744448 c:\windows\SoftwareDistribution\Download\2c0d861a85182505b6e0107596abb839\SP3GDR\helpsvc.exe
- 2010-08-02 21:20 . 2010-06-14 15:13 744448 c:\windows\SoftwareDistribution\Download\2c0d861a85182505b6e0107596abb839\SP2QFE\helpsvc.exe
- 2010-08-02 21:20 . 2010-06-14 14:30 743936 c:\windows\SoftwareDistribution\Download\2c0d861a85182505b6e0107596abb839\SP2GDR\helpsvc.exe
- 2010-08-03 15:38 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\269630a60abe4177f0ba214686d6ebda\update\updspapi.dll
- 2010-08-03 15:38 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\269630a60abe4177f0ba214686d6ebda\update\update.exe
- 2010-08-03 15:38 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\269630a60abe4177f0ba214686d6ebda\spuninst.exe
- 2010-08-02 20:49 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\248802b74506342031e926839639c729\update\updspapi.dll
- 2010-08-02 20:49 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\248802b74506342031e926839639c729\update\update.exe
- 2010-08-02 20:49 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\248802b74506342031e926839639c729\spuninst.exe
- 2010-03-22 17:46 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\23e79e5fb28793d8cb1c2055b0d8dcb9\update\updspapi.dll
- 2010-03-22 17:46 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\23e79e5fb28793d8cb1c2055b0d8dcb9\update\update.exe
- 2010-03-22 17:46 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\23e79e5fb28793d8cb1c2055b0d8dcb9\spuninst.exe
- 2010-08-02 20:50 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\22f1a1e628f2ceada1948d2c604b5154\update\updspapi.dll
- 2010-08-02 20:50 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\22f1a1e628f2ceada1948d2c604b5154\update\update.exe
- 2010-08-02 20:50 . 2008-07-08 13:02 231288 c:\windows\SoftwareDistribution\Download\22f1a1e628f2ceada1948d2c604b5154\spuninst.exe
- 2010-03-22 17:27 . 2007-11-30 12:39 382840 c:\windows\SoftwareDistribution\Download\1ece269e23f4ef02dbea7dfa6a74a7d0\update\updspapi.dll
- 2010-03-22 17:27 . 2007-11-30 12:39 755576 c:\windows\SoftwareDistribution\Download\1ece269e23f4ef02dbea7dfa6a74a7d0\update\update.exe
- 2010-03-22 17:27 . 2007-11-30 12:39 231288 c:\windows\SoftwareDistribution\Download\1ece269e23f4ef02dbea7dfa6a74a7d0\spuninst.exe
- 2010-03-22 17:27 . 2008-05-08 13:58 203136 c:\windows\SoftwareDistribution\Download\1ece269e23f4ef02dbea7dfa6a74a7d0\SP3QFE\rmcast.sys
- 2010-03-22 17:27 . 2008-05-08 14:02 203136 c:\windows\SoftwareDistribution\Download\1ece269e23f4ef02dbea7dfa6a74a7d0\SP3GDR\rmcast.sys
- 2010-03-22 17:27 . 2008-05-08 12:14 203008 c:\windows\SoftwareDistribution\Download\1ece269e23f4ef02dbea7dfa6a74a7d0\SP2QFE\rmcast.sys
- 2010-03-22 17:27 . 2008-05-08 12:28 202752 c:\windows\SoftwareDistribution\Download\1ece269e23f4ef02dbea7dfa6a74a7d0\SP2GDR\rmcast.sys
- 2010-08-03 15:40 . 2007-11-30 12:39 382840 c:\windows\SoftwareDistribution\Download\1201b6f74bae1015eceeea43baed9814\update\updspapi.dll
- 2010-08-03 15:40 . 2007-11-30 12:39 755576 c:\windows\SoftwareDistribution\Download\1201b6f74bae1015eceeea43baed9814\update\update.exe
- 2010-08-03 15:40 . 2007-11-30 12:39 231288 c:\windows\SoftwareDistribution\Download\1201b6f74bae1015eceeea43baed9814\spuninst.exe
- 2010-08-03 15:35 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\0fa2ac15b3f3d16ecfc880648002b82e\update\updspapi.dll
- 2010-08-03 15:35 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\0fa2ac15b3f3d16ecfc880648002b82e\update\update.exe
- 2010-08-03 15:35 . 2008-07-08 13:02 231288 c:\windows\SoftwareDistribution\Download\0fa2ac15b3f3d16ecfc880648002b82e\spuninst.exe
- 2010-03-22 17:37 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\0dd0244816ffb4b094c1caba4c3b1178\update\updspapi.dll
- 2010-03-22 17:37 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\0dd0244816ffb4b094c1caba4c3b1178\update\update.exe
- 2010-03-22 17:37 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\0dd0244816ffb4b094c1caba4c3b1178\spuninst.exe
- 2010-08-02 20:49 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\01229cf5dcf0df67992cac35a2ba0b3f\update\updspapi.dll
- 2010-08-02 20:49 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\01229cf5dcf0df67992cac35a2ba0b3f\update\update.exe
- 2010-08-02 20:49 . 2008-07-08 13:02 231288 c:\windows\SoftwareDistribution\Download\01229cf5dcf0df67992cac35a2ba0b3f\spuninst.exe
- 2010-08-03 15:11 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\0034610052cb298a78a7ba8a4f6282e6\update\updspapi.dll
- 2010-08-03 15:11 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\0034610052cb298a78a7ba8a4f6282e6\update\update.exe
- 2010-08-03 15:11 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\0034610052cb298a78a7ba8a4f6282e6\spuninst.exe
- 2009-05-29 06:13 . 2008-04-14 12:00 744448 c:\windows\pchealth\helpctr\binaries\HelpSvc.exe
+ 2009-05-29 06:13 . 2010-06-14 14:31 744448 c:\windows\pchealth\helpctr\binaries\helpsvc.exe
+ 2008-07-25 05:46 . 2008-07-25 05:46 438272 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 839680 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 835584 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 835584 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 261632 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 114688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 114688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 131072 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 131072 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 303104 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 372736 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Management.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 113664 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 626688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 188416 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 188416 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 401408 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 970752 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 745472 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 486400 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 425984 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 392184 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 118784 c:\windows\Microsoft.NET\Framework\v2.0.50727\shfusion.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 143360 c:\windows\Microsoft.NET\Framework\v2.0.50727\peverify.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 100856 c:\windows\Microsoft.NET\Framework\v2.0.50727\ngen.exe
+ 2008-07-25 05:47 . 2008-07-25 05:47 230912 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 345600 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 114176 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 367104 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 308224 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 998408 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 659456 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll
- 2005-09-23 01:59 . 2005-09-23 01:59 372736 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 372736 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll
- 2005-09-23 01:59 . 2005-09-23 01:59 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 749568 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 655360 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 348160 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 230904 c:\windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe
+ 2008-07-25 05:47 . 2008-07-25 05:47 798224 c:\windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 575496 c:\windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
+ 2008-07-25 05:47 . 2008-07-25 05:47 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
+ 2008-07-25 05:46 . 2008-07-25 05:46 507904 c:\windows\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll
- 2005-09-23 01:58 . 2005-09-23 01:58 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
+ 2008-07-25 05:46 . 2008-07-25 05:46 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
+ 2008-07-25 05:47 . 2008-07-25 05:47 147968 c:\windows\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 218112 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 193016 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 145408 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll
- 2004-07-14 19:03 . 2004-07-14 19:03 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2010-09-22 20:56 . 2010-09-22 20:56 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2004-07-14 18:55 . 2004-07-14 18:55 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2010-09-22 20:55 . 2010-09-22 20:55 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2004-07-14 20:19 . 2004-07-14 20:19 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2010-09-22 21:47 . 2010-09-22 21:47 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2008-07-29 12:05 . 2008-07-29 12:05 553472 c:\windows\Installer\79598.msp
+ 2008-07-29 12:03 . 2008-07-29 12:03 506368 c:\windows\Installer\79596.msp
+ 2008-07-29 12:07 . 2008-07-29 12:07 911360 c:\windows\Installer\79595.msp
+ 2011-02-11 19:50 . 2011-02-11 19:50 432640 c:\windows\Installer\32cba98.msi
+ 2011-02-11 19:50 . 2011-02-11 19:50 429568 c:\windows\Installer\32cba8f.msi
+ 2011-02-12 05:28 . 2008-03-13 04:52 761344 c:\windows\Driver Cache\i386\unires.dll
+ 2011-02-12 05:28 . 2008-07-06 12:06 744960 c:\windows\Driver Cache\i386\unidrvui.dll
+ 2011-02-12 05:28 . 2008-07-06 12:06 373248 c:\windows\Driver Cache\i386\unidrv.dll
+ 2011-02-12 05:28 . 2008-07-06 12:06 198656 c:\windows\Driver Cache\i386\mxdwdui.dll
+ 2011-02-12 05:28 . 2008-07-06 12:06 765440 c:\windows\Driver Cache\i386\mxdwdrv.dll
+ 2010-08-02 21:25 . 2010-02-24 13:11 455680 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2009-10-20 16:20 . 2009-10-20 16:20 265728 c:\windows\Driver Cache\i386\http.sys
+ 2010-03-22 17:36 . 2008-06-13 11:05 272128 c:\windows\Driver Cache\i386\bthport.sys
+ 2011-02-11 19:53 . 2011-02-11 19:53 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_3302d4a3\System.Drawing.dll
+ 2011-02-12 05:33 . 2011-02-12 05:33 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\5f5d64dd0e7991aaaad2d98ee52afe42\System.Drawing.Design.ni.dll
+ 2011-02-12 05:39 . 2011-02-12 05:39 838656 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\daf5ff5e06c80eefa80c6fcc79aec963\Microsoft.Build.Engine.ni.dll
+ 2011-02-12 05:39 . 2011-02-12 05:39 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\e148983beeb0f30918b0564849a16456\CustomMarshalers.ni.dll
+ 2011-02-12 05:38 . 2011-02-12 05:38 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\c7ffd8c23e8de4018a88185b3b60631e\AspNetMMCExt.ni.dll
+ 2011-02-12 05:21 . 2011-02-12 05:21 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2010-03-29 05:58 . 2010-03-29 05:58 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2011-02-12 05:21 . 2011-02-12 05:21 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2011-02-12 05:23 . 2011-02-12 05:23 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2010-03-29 05:57 . 2010-03-29 05:57 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2011-02-12 05:23 . 2011-02-12 05:23 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2010-03-29 05:57 . 2010-03-29 05:57 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2010-03-29 05:57 . 2010-03-29 05:57 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2010-03-29 05:58 . 2010-03-29 05:58 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2011-02-12 05:23 . 2011-02-12 05:23 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2010-03-29 05:57 . 2010-03-29 05:57 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2011-02-12 05:23 . 2011-02-12 05:23 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2010-03-29 05:57 . 2010-03-29 05:57 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2010-03-29 05:58 . 2010-03-29 05:58 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2010-03-29 05:58 . 2010-03-29 05:58 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2011-02-12 05:21 . 2011-02-12 05:21 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2010-03-29 05:56 . 2010-03-29 05:56 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2008-04-14 12:00 . 2009-11-21 15:51 471552 c:\windows\AppPatch\aclayers.dll
+ 2011-02-11 14:31 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB981349\update\updspapi.dll
+ 2011-02-11 14:31 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB981349\update\update.exe
+ 2011-02-11 14:31 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB981349\spuninst.exe
+ 2010-03-09 11:06 . 2010-03-09 11:06 430080 c:\windows\$hf_mig$\KB981349\SP3QFE\vbscript.dll
+ 2011-02-11 19:54 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB979482\update\updspapi.dll
+ 2011-02-11 19:54 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB979482\update\update.exe
+ 2011-02-11 19:54 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB979482\spuninst.exe
+ 2011-02-11 14:14 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB979309\update\updspapi.dll
+ 2011-02-11 14:14 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB979309\update\update.exe
+ 2011-02-11 14:14 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB979309\spuninst.exe
+ 2011-02-11 19:54 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB978706\update\updspapi.dll
+ 2011-02-11 19:54 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB978706\update\update.exe
+ 2011-02-11 19:54 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB978706\spuninst.exe
+ 2009-12-16 18:27 . 2009-12-16 18:27 343040 c:\windows\$hf_mig$\KB978706\SP3QFE\mspaint.exe
+ 2011-02-11 14:17 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB978601\update\updspapi.dll
+ 2011-02-11 14:17 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB978601\update\update.exe
+ 2011-02-11 14:17 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB978601\spuninst.exe
+ 2009-12-24 06:42 . 2009-12-24 06:42 178176 c:\windows\$hf_mig$\KB978601\SP3QFE\wintrust.dll
+ 2011-02-11 19:54 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB978542\update\updspapi.dll
+ 2011-02-11 19:54 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB978542\update\update.exe
+ 2011-02-11 19:54 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB978542\spuninst.exe
+ 2010-01-29 14:53 . 2010-01-29 14:53 691712 c:\windows\$hf_mig$\KB978542\SP3QFE\inetcomm.dll
+ 2011-02-11 14:29 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB978338\update\updspapi.dll
+ 2011-02-11 14:29 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB978338\update\update.exe
+ 2011-02-11 14:29 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB978338\spuninst.exe
+ 2010-02-11 11:36 . 2010-02-11 11:36 226880 c:\windows\$hf_mig$\KB978338\SP3QFE\tcpip6.sys
+ 2010-02-12 04:27 . 2010-02-12 04:27 100864 c:\windows\$hf_mig$\KB978338\SP3QFE\6to4svc.dll
+ 2011-02-11 19:55 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB977914\update\updspapi.dll
+ 2011-02-11 19:55 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB977914\update\update.exe
+ 2011-02-11 19:55 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB977914\spuninst.exe
+ 2011-02-11 14:23 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB977816\update\updspapi.dll
+ 2011-02-11 14:23 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB977816\update\update.exe
+ 2011-02-11 14:23 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB977816\spuninst.exe
+ 2011-02-11 14:30 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB975713\update\updspapi.dll
+ 2011-02-11 14:30 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB975713\update\update.exe
+ 2011-02-11 14:30 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB975713\spuninst.exe
+ 2009-12-08 09:01 . 2009-12-08 09:01 474112 c:\windows\$hf_mig$\KB975713\SP3QFE\shlwapi.dll
+ 2011-02-11 19:53 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB975562\update\updspapi.dll
+ 2011-02-11 19:53 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB975562\update\update.exe
+ 2011-02-11 19:53 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB975562\spuninst.exe
+ 2011-02-11 14:25 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB975560\update\updspapi.dll
+ 2011-02-11 14:25 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB975560\update\update.exe
+ 2011-02-11 14:25 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB975560\spuninst.exe
+ 2011-02-11 14:13 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB975467\update\updspapi.dll
+ 2011-02-11 14:13 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB975467\update\update.exe
+ 2011-02-11 14:13 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB975467\spuninst.exe
+ 2009-09-11 14:13 . 2009-09-11 14:13 136704 c:\windows\$hf_mig$\KB975467\SP3QFE\msv1_0.dll
+ 2011-02-11 14:25 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB974571\update\updspapi.dll
+ 2011-02-11 14:25 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB974571\update\update.exe
+ 2011-02-11 14:25 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB974571\spuninst.exe
+ 2011-02-11 14:14 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB974392\update\updspapi.dll
+ 2011-02-11 14:14 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB974392\update\update.exe
+ 2011-02-11 14:14 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB974392\spuninst.exe
+ 2009-10-13 10:38 . 2009-10-13 10:38 270336 c:\windows\$hf_mig$\KB974392\SP3QFE\oakley.dll
+ 2011-02-11 14:32 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB974318\update\updspapi.dll
+ 2011-02-11 14:32 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB974318\update\update.exe
+ 2011-02-11 14:32 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB974318\spuninst.exe
+ 2009-10-12 13:28 . 2009-10-12 13:28 150016 c:\windows\$hf_mig$\KB974318\SP3QFE\rastls.dll
+ 2011-02-11 14:28 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB974112\update\updspapi.dll
+ 2011-02-11 14:28 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB974112\update\update.exe
+ 2011-02-11 14:28 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB974112\spuninst.exe
+ 2009-08-26 08:03 . 2009-08-26 08:03 247326 c:\windows\$hf_mig$\KB974112\SP3QFE\strmdll.dll
+ 2011-02-11 14:15 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB973904\update\updspapi.dll
+ 2011-02-11 14:15 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB973904\update\update.exe
+ 2011-02-11 14:15 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB973904\spuninst.exe
+ 2011-02-11 05:20 . 2009-07-29 14:01 119648 c:\windows\$hf_mig$\KB973904\SP3QFE\msconv97.dll
+ 2011-02-11 14:25 . 2008-07-08 13:02 382840 c:\windows\$hf_mig$\KB973869\update\updspapi.dll
+ 2011-02-11 14:25 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB973869\update\update.exe
+ 2011-02-11 14:25 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB973869\spuninst.exe
+ 2011-02-11 19:54 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB973815\update\updspapi.dll
+ 2011-02-11 19:54 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB973815\update\update.exe
+ 2011-02-11 19:54 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB973815\spuninst.exe
+ 2009-08-05 08:52 . 2009-08-05 08:52 204800 c:\windows\$hf_mig$\KB973815\SP3QFE\mswebdvd.dll
+ 2011-02-11 14:23 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB973687\update\updspapi.dll
+ 2011-02-11 14:23 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB973687\update\update.exe
+ 2011-02-11 14:23 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB973687\spuninst.exe
+ 2011-02-11 14:24 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB973507\update\updspapi.dll
+ 2011-02-11 14:24 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB973507\update\update.exe
+ 2011-02-11 14:24 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB973507\spuninst.exe
+ 2011-02-11 14:28 . 2008-07-08 13:02 382840 c:\windows\$hf_mig$\KB972270\update\updspapi.dll
+ 2011-02-11 14:28 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB972270\update\update.exe
+ 2011-02-11 14:28 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB972270\spuninst.exe
+ 2011-02-11 05:31 . 2009-10-15 16:39 119808 c:\windows\$hf_mig$\KB972270\SP3QFE\t2embed.dll
+ 2011-02-11 14:13 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB971961\update\updspapi.dll
+ 2011-02-11 14:13 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB971961\update\update.exe
+ 2011-02-11 14:13 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB971961\spuninst.exe
+ 2011-02-11 05:12 . 2009-08-13 15:02 512000 c:\windows\$hf_mig$\KB971961\SP3QFE\jscript.dll
+ 2011-02-11 14:29 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB971657\update\updspapi.dll
+ 2011-02-11 14:29 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB971657\update\update.exe
+ 2011-02-11 14:29 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB971657\spuninst.exe
+ 2009-06-10 06:17 . 2009-06-10 06:17 134144 c:\windows\$hf_mig$\KB971657\SP3QFE\wkssvc.dll
+ 2011-02-11 14:31 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB969059\update\updspapi.dll
+ 2011-02-11 14:31 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB969059\update\update.exe
+ 2011-02-11 14:31 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB969059\spuninst.exe
+ 2011-02-11 14:13 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB968389\update\updspapi.dll
+ 2011-02-11 14:13 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB968389\update\update.exe
+ 2011-02-11 14:13 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB968389\spuninst.exe
+ 2009-06-25 08:41 . 2009-06-25 08:41 147456 c:\windows\$hf_mig$\KB968389\SP3QFE\schannel.dll
+ 2009-06-25 08:41 . 2009-06-25 08:41 136704 c:\windows\$hf_mig$\KB968389\SP3QFE\msv1_0.dll
+ 2009-06-26 09:41 . 2009-06-26 09:41 730112 c:\windows\$hf_mig$\KB968389\SP3QFE\lsasrv.dll
+ 2009-06-25 08:41 . 2009-06-25 08:41 301568 c:\windows\$hf_mig$\KB968389\SP3QFE\kerberos.dll
+ 2011-02-11 14:15 . 2008-07-09 07:38 382840 c:\windows\$hf_mig$\KB967715\update\updspapi.dll
+ 2011-02-11 14:15 . 2008-07-09 07:38 755576 c:\windows\$hf_mig$\KB967715\update\update.exe
+ 2011-02-11 14:15 . 2008-07-09 07:38 231288 c:\windows\$hf_mig$\KB967715\spuninst.exe
+ 2011-02-11 14:26 . 2008-07-09 07:38 382840 c:\windows\$hf_mig$\KB961501\update\updspapi.dll
+ 2011-02-11 14:26 . 2008-07-09 07:38 755576 c:\windows\$hf_mig$\KB961501\update\update.exe
+ 2011-02-11 14:26 . 2008-07-09 07:38 231288 c:\windows\$hf_mig$\KB961501\spuninst.exe
+ 2009-05-07 15:14 . 2009-05-07 15:14 346112 c:\windows\$hf_mig$\KB961501\SP3QFE\localspl.dll
+ 2011-02-11 19:54 . 2007-11-30 12:39 382840 c:\windows\$hf_mig$\KB960803\update\updspapi.dll
+ 2011-02-11 19:54 . 2007-11-30 12:39 755576 c:\windows\$hf_mig$\KB960803\update\update.exe
+ 2011-02-11 19:54 . 2007-11-30 12:39 231288 c:\windows\$hf_mig$\KB960803\spuninst.exe
+ 2008-12-16 12:22 . 2008-12-16 12:22 354304 c:\windows\$hf_mig$\KB960803\SP3QFE\winhttp.dll
+ 2011-02-11 19:51 . 2007-11-30 11:18 382840 c:\windows\$hf_mig$\KB958644\update\updspapi.dll
+ 2011-02-11 19:51 . 2007-11-30 11:18 755576 c:\windows\$hf_mig$\KB958644\update\update.exe
+ 2011-02-11 19:51 . 2007-11-30 11:18 231288 c:\windows\$hf_mig$\KB958644\spuninst.exe
+ 2011-02-11 14:49 . 2008-10-15 16:25 339456 c:\windows\$hf_mig$\KB958644\SP3QFE\netapi32.dll
+ 2011-02-11 14:27 . 2008-07-08 13:02 382840 c:\windows\$hf_mig$\KB956844\update\updspapi.dll
+ 2011-02-11 14:27 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB956844\update\update.exe
+ 2011-02-11 14:27 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB956844\spuninst.exe
+ 2011-02-11 05:27 . 2009-06-21 21:49 153088 c:\windows\$hf_mig$\KB956844\SP3QFE\triedit.dll
+ 2011-02-11 19:51 . 2008-07-09 07:38 382840 c:\windows\$hf_mig$\KB956802\update\updspapi.dll
+ 2011-02-11 19:50 . 2008-07-09 07:38 755576 c:\windows\$hf_mig$\KB956802\update\update.exe
+ 2011-02-11 19:50 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB956802\spuninst.exe
+ 2008-10-23 12:43 . 2008-10-23 12:43 286720 c:\windows\$hf_mig$\KB956802\SP3QFE\gdi32.dll
+ 2011-02-11 14:28 . 2008-07-08 13:02 382840 c:\windows\$hf_mig$\KB956744\update\updspapi.dll
+ 2011-02-11 14:28 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB956744\update\update.exe
+ 2011-02-11 14:28 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB956744\spuninst.exe
+ 2011-02-11 14:27 . 2008-07-09 07:38 382840 c:\windows\$hf_mig$\KB956572\update\updspapi.dll
+ 2011-02-11 14:27 . 2008-07-09 07:38 755576 c:\windows\$hf_mig$\KB956572\update\update.exe
+ 2011-02-11 14:27 . 2008-07-09 07:38 231288 c:\windows\$hf_mig$\KB956572\spuninst.exe
+ 2011-02-11 05:57 . 2009-02-06 10:15 227840 c:\windows\$hf_mig$\KB956572\SP3QFE\wmiprvse.exe
+ 2011-02-11 05:57 . 2009-02-09 10:56 453120 c:\windows\$hf_mig$\KB956572\SP3QFE\wmiprvsd.dll
+ 2011-02-11 05:57 . 2009-02-06 11:06 110592 c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe
+ 2011-02-11 05:57 . 2009-02-09 10:56 401408 c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll
+ 2011-02-11 05:57 . 2009-03-06 13:49 284160 c:\windows\$hf_mig$\KB956572\SP3QFE\pdh.dll
+ 2011-02-11 05:57 . 2009-02-09 10:56 715264 c:\windows\$hf_mig$\KB956572\SP3QFE\ntdll.dll
+ 2011-02-11 05:57 . 2009-02-09 10:56 729088 c:\windows\$hf_mig$\KB956572\SP3QFE\lsasrv.dll
+ 2011-02-11 05:57 . 2009-02-09 10:56 473600 c:\windows\$hf_mig$\KB956572\SP3QFE\fastprox.dll
+ 2009-02-10 13:56 . 2009-02-10 13:56 617472 c:\windows\$hf_mig$\KB956572\SP3QFE\advapi32.dll
+ 2011-02-11 14:14 . 2007-11-30 12:39 382840 c:\windows\$hf_mig$\KB954459\update\updspapi.dll
+ 2011-02-11 14:14 . 2007-11-30 12:39 755576 c:\windows\$hf_mig$\KB954459\update\update.exe
+ 2011-02-11 14:14 . 2007-11-30 12:39 231288 c:\windows\$hf_mig$\KB954459\spuninst.exe
+ 2011-02-11 14:16 . 2007-11-30 11:18 382840 c:\windows\$hf_mig$\KB952287\update\updspapi.dll
+ 2011-02-11 14:16 . 2007-11-30 11:18 755576 c:\windows\$hf_mig$\KB952287\update\update.exe
+ 2011-02-11 14:16 . 2007-11-30 11:18 231288 c:\windows\$hf_mig$\KB952287\spuninst.exe
+ 2011-02-11 05:21 . 2008-05-01 14:38 331776 c:\windows\$hf_mig$\KB952287\SP3QFE\msadce.dll
+ 2011-02-11 14:25 . 2007-11-30 12:39 382840 c:\windows\$hf_mig$\KB952004\update\updspapi.dll
+ 2011-02-11 14:25 . 2007-11-30 12:39 755576 c:\windows\$hf_mig$\KB952004\update\update.exe
+ 2011-02-11 14:25 . 2007-11-30 12:39 231288 c:\windows\$hf_mig$\KB952004\spuninst.exe
+ 2008-06-12 14:09 . 2008-06-12 14:09 161792 c:\windows\$hf_mig$\KB952004\SP3QFE\msdtcuiu.dll
+ 2008-06-12 14:09 . 2008-06-12 14:09 956928 c:\windows\$hf_mig$\KB952004\SP3QFE\msdtctm.dll
+ 2008-06-12 14:09 . 2008-06-12 14:09 428032 c:\windows\$hf_mig$\KB952004\SP3QFE\msdtcprx.dll
+ 2011-02-11 14:32 . 2007-11-30 12:39 382840 c:\windows\$hf_mig$\KB951978\update\updspapi.dll
+ 2011-02-11 14:32 . 2007-11-30 12:39 755576 c:\windows\$hf_mig$\KB951978\update\update.exe
+ 2011-02-11 14:32 . 2007-11-30 12:39 231288 c:\windows\$hf_mig$\KB951978\spuninst.exe
+ 2008-05-08 11:24 . 2008-05-08 11:24 155648 c:\windows\$hf_mig$\KB951978\SP3QFE\wscript.exe
+ 2008-05-09 10:45 . 2008-05-09 10:45 430080 c:\windows\$hf_mig$\KB951978\SP3QFE\vbscript.dll
+ 2008-05-09 10:45 . 2008-05-09 10:45 172032 c:\windows\$hf_mig$\KB951978\SP3QFE\scrrun.dll
+ 2008-05-09 10:45 . 2008-05-09 10:45 180224 c:\windows\$hf_mig$\KB951978\SP3QFE\scrobj.dll
+ 2008-05-09 10:45 . 2008-05-09 10:45 512000 c:\windows\$hf_mig$\KB951978\SP3QFE\jscript.dll
+ 2008-05-07 09:07 . 2008-05-07 09:07 135168 c:\windows\$hf_mig$\KB951978\SP3QFE\cscript.exe
+ 2011-02-11 19:55 . 2007-11-30 12:39 382840 c:\windows\$hf_mig$\KB951748\update\updspapi.dll
+ 2011-02-11 19:55 . 2007-11-30 12:39 755576 c:\windows\$hf_mig$\KB951748\update\update.exe
+ 2011-02-11 19:55 . 2007-11-30 12:39 231288 c:\windows\$hf_mig$\KB951748\spuninst.exe
+ 2008-06-20 11:16 . 2008-06-20 11:16 225856 c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip6.sys
+ 2008-06-20 11:59 . 2008-06-20 11:59 361600 c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
+ 2008-06-20 17:43 . 2008-06-20 17:43 245248 c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll
+ 2008-06-20 17:43 . 2008-06-20 17:43 147968 c:\windows\$hf_mig$\KB951748\SP3QFE\dnsapi.dll
+ 2008-06-20 11:48 . 2008-06-20 11:48 138496 c:\windows\$hf_mig$\KB951748\SP3QFE\afd.sys
+ 2011-02-11 14:30 . 2007-11-30 12:39 382840 c:\windows\$hf_mig$\KB950974\update\updspapi.dll
+ 2011-02-11 14:30 . 2007-11-30 12:39 755576 c:\windows\$hf_mig$\KB950974\update\update.exe
+ 2011-02-11 14:30 . 2007-11-30 12:39 231288 c:\windows\$hf_mig$\KB950974\spuninst.exe
+ 2008-07-07 20:23 . 2008-07-07 20:23 253952 c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
+ 2011-02-11 14:17 . 2007-11-30 12:39 382840 c:\windows\$hf_mig$\KB950762\update\updspapi.dll
+ 2011-02-11 14:17 . 2007-11-30 12:39 755576 c:\windows\$hf_mig$\KB950762\update\update.exe
+ 2011-02-11 14:17 . 2007-11-30 12:39 231288 c:\windows\$hf_mig$\KB950762\spuninst.exe
+ 2011-02-11 05:55 . 2008-05-08 13:58 203136 c:\windows\$hf_mig$\KB950762\SP3QFE\rmcast.sys
+ 2011-02-11 14:14 . 2008-07-09 07:38 382840 c:\windows\$hf_mig$\KB923561\update\updspapi.dll
+ 2011-02-11 14:14 . 2008-11-15 17:18 755576 c:\windows\$hf_mig$\KB923561\update\update.exe
+ 2011-02-11 14:14 . 2008-07-09 07:38 231288 c:\windows\$hf_mig$\KB923561\spuninst.exe
+ 2011-02-11 05:12 . 2008-04-21 12:15 215552 c:\windows\$hf_mig$\KB923561\SP3QFE\wordpad.exe
+ 2011-02-11 14:31 . 2010-02-22 14:23 382840 c:\windows\$hf_mig$\KB2229593\update\updspapi.dll
+ 2011-02-11 14:31 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB2229593\update\update.exe
+ 2011-02-11 14:31 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB2229593\spuninst.exe
+ 2011-02-11 05:33 . 2010-06-14 14:38 744448 c:\windows\$hf_mig$\KB2229593\SP3QFE\helpsvc.exe
+ 2010-03-22 17:36 . 2009-08-13 13:55 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll
+ 2011-02-11 05:39 . 2010-08-23 16:12 1054208 c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
+ 2009-07-20 18:33 . 2009-07-20 18:33 1348432 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9876.0_x-ww_a621d1d5\msxml4.dll
+ 2008-09-30 11:12 . 2008-09-30 11:12 1286152 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
+ 2008-04-14 12:00 . 2010-04-03 01:09 2377576 c:\windows\system32\WMVCore.dll
+ 2008-04-14 12:00 . 2010-08-25 01:53 5541888 c:\windows\system32\wmp.dll
+ 2008-04-14 12:00 . 2008-06-10 00:58 1028096 c:\windows\system32\WMNetmgr.dll
+ 2011-02-12 05:28 . 2008-07-06 12:06 1676288 c:\windows\system32\spool\drivers\w32x86\3\XpsSvcs.dll
+ 2008-04-14 12:00 . 2011-01-21 14:44 8462336 c:\windows\system32\shell32.dll
+ 2008-04-14 12:00 . 2010-12-20 22:15 1510400 c:\windows\system32\shdocvw.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 1435648 c:\windows\system32\query.dll
+ 2008-04-14 12:00 . 2009-07-17 16:22 1435648 c:\windows\system32\query.dll
+ 2008-04-14 12:00 . 2010-02-05 18:27 1291776 c:\windows\system32\quartz.dll
+ 2008-04-14 12:00 . 2010-07-16 12:05 1288192 c:\windows\system32\ole32.dll
+ 2008-04-14 12:00 . 2009-07-31 04:35 1372672 c:\windows\system32\msxml6.dll
+ 2009-07-20 18:35 . 2009-07-20 18:35 1348432 c:\windows\system32\msxml4.dll
+ 2008-04-14 12:00 . 2010-06-14 07:41 1172480 c:\windows\system32\msxml3.dll
+ 2009-05-29 06:10 . 2009-06-10 03:49 2066432 c:\windows\system32\mstscax.dll
+ 2008-04-14 12:00 . 2010-12-20 22:15 3078144 c:\windows\system32\mshtml.dll
+ 2011-02-11 14:33 . 2009-03-10 16:56 1403264 c:\windows\system32\KB905474\wganotifypackageinner.exe
+ 2008-04-14 12:00 . 2010-04-03 01:09 2377576 c:\windows\system32\dllcache\WMVCore.dll
+ 2008-04-14 12:00 . 2010-08-25 01:53 5541888 c:\windows\system32\dllcache\wmp.dll
+ 2008-04-14 12:00 . 2008-06-10 00:58 1028096 c:\windows\system32\dllcache\WMNetmgr.dll
+ 2008-04-14 12:00 . 2010-12-31 13:10 1854976 c:\windows\system32\dllcache\win32k.sys
+ 2008-04-14 12:00 . 2011-01-21 14:44 8462336 c:\windows\system32\dllcache\shell32.dll
+ 2008-04-14 12:00 . 2010-12-20 22:15 1510400 c:\windows\system32\dllcache\shdocvw.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 1435648 c:\windows\system32\dllcache\query.dll
+ 2008-04-14 12:00 . 2009-07-17 16:22 1435648 c:\windows\system32\dllcache\query.dll
+ 2008-04-14 12:00 . 2010-02-05 18:27 1291776 c:\windows\system32\dllcache\quartz.dll
+ 2008-04-14 12:00 . 2010-07-16 12:05 1288192 c:\windows\system32\dllcache\ole32.dll
+ 2008-04-14 12:00 . 2009-07-31 04:35 1372672 c:\windows\system32\dllcache\msxml6.dll
+ 2008-04-14 12:00 . 2010-06-14 07:41 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2009-06-10 03:49 . 2009-06-10 03:49 2066432 c:\windows\system32\dllcache\mstscax.dll
+ 2009-05-29 06:13 . 2010-01-29 15:01 1315328 c:\windows\system32\dllcache\msoe.dll
+ 2008-04-14 12:00 . 2010-12-20 22:15 3078144 c:\windows\system32\dllcache\mshtml.dll
+ 2009-05-29 06:13 . 2010-06-18 13:36 3558912 c:\windows\system32\dllcache\moviemk.exe
- 2009-05-29 06:13 . 2008-04-14 12:00 3558912 c:\windows\system32\dllcache\moviemk.exe
+ 2008-04-14 12:00 . 2010-12-20 22:15 1025024 c:\windows\system32\dllcache\browseui.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 1025024 c:\windows\system32\dllcache\browseui.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 1025024 c:\windows\system32\browseui.dll
+ 2008-04-14 12:00 . 2010-12-20 22:15 1025024 c:\windows\system32\browseui.dll
- 2010-03-22 17:32 . 2009-06-09 15:21 2067968 c:\windows\SoftwareDistribution\Download\9cf59263a134ab3fbbee78365a2fa5fc\SP3QFE\lhmstscx.dll
- 2010-03-22 17:32 . 2009-06-09 14:53 2067968 c:\windows\SoftwareDistribution\Download\9cf59263a134ab3fbbee78365a2fa5fc\SP2QFE\lhmstscx.dll
- 2010-03-22 17:32 . 2009-06-09 15:06 1871872 c:\windows\SoftwareDistribution\Download\9cf59263a134ab3fbbee78365a2fa5fc\SP2GDR\lhmstscx.dll
- 2010-03-22 17:28 . 2009-07-31 04:24 1447424 c:\windows\SoftwareDistribution\Download\75cd10bc79782317976e2a857798ad9f\SP3QFE\msxml6.dll
- 2010-03-22 17:28 . 2009-07-31 04:24 1172480 c:\windows\SoftwareDistribution\Download\75cd10bc79782317976e2a857798ad9f\SP3QFE\msxml3.dll
- 2010-03-22 17:28 . 2009-07-31 04:35 1172480 c:\windows\SoftwareDistribution\Download\75cd10bc79782317976e2a857798ad9f\SP3GDR\msxml3.dll
- 2010-03-22 17:28 . 2009-07-31 04:36 1172480 c:\windows\SoftwareDistribution\Download\75cd10bc79782317976e2a857798ad9f\SP2QFE\msxml3.dll
- 2010-03-22 17:28 . 2009-07-31 04:57 1172480 c:\windows\SoftwareDistribution\Download\75cd10bc79782317976e2a857798ad9f\SP2GDR\msxml3.dll
- 2010-03-22 17:32 . 2009-02-06 10:30 2023936 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\ntkrpamp.exe
- 2010-03-22 17:31 . 2009-02-06 10:30 2066176 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\ntkrnlpa.exe
- 2010-03-22 17:32 . 2009-02-06 11:03 2145280 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\ntkrnlmp.exe
- 2010-03-22 17:32 . 2009-02-06 11:08 2189056 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\ntoskrnl.exe
- 2010-03-22 17:32 . 2009-02-06 10:32 2023936 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\ntkrpamp.exe
- 2010-03-22 17:32 . 2009-02-06 11:06 2145280 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\ntkrnlmp.exe
- 2010-03-22 17:32 . 2009-02-06 10:32 2186112 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\ntoskrnl.exe
- 2010-03-22 17:32 . 2009-02-06 09:49 2020864 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\ntkrpamp.exe
- 2010-03-22 17:32 . 2009-02-06 09:49 2062976 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\ntkrnlpa.exe
- 2010-03-22 17:32 . 2009-02-06 10:29 2142720 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\ntkrnlmp.exe
- 2010-03-22 17:32 . 2009-02-06 17:24 2180480 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\ntoskrnl.exe
- 2010-03-22 17:32 . 2009-02-06 16:49 2015744 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\ntkrpamp.exe
- 2010-03-22 17:32 . 2009-02-06 16:49 2057728 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\ntkrnlpa.exe
- 2010-03-22 17:32 . 2009-02-06 17:22 2136064 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\ntkrnlmp.exe
+ 2008-07-25 05:46 . 2008-07-25 05:46 1344000 c:\windows\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 1172472 c:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
+ 2008-07-25 05:47 . 2008-07-25 05:47 2048000 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 5238784 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 3149824 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 5062656 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 2933248 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 5815296 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2008-07-25 05:47 . 2008-07-25 05:47 4546560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2008-07-25 05:46 . 2008-07-25 05:46 1163768 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscomp.dll
+ 2010-09-23 10:25 . 2010-09-23 10:25 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2010-09-23 10:25 . 2010-09-23 10:25 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2010-09-22 20:56 . 2010-09-22 20:56 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2010-09-22 20:55 . 2010-09-22 20:55 2523136 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2010-09-23 10:25 . 2010-09-23 10:25 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2008-07-29 12:15 . 2008-07-29 12:15 2543616 c:\windows\Installer\7959c.msp
+ 2008-07-29 11:59 . 2008-07-29 11:59 2926080 c:\windows\Installer\7959b.msp
+ 2008-07-29 12:11 . 2008-07-29 12:11 6487040 c:\windows\Installer\7959a.msp
+ 2008-07-29 12:09 . 2008-07-29 12:09 3403264 c:\windows\Installer\79599.msp
+ 2008-07-29 12:13 . 2008-07-29 12:13 1013248 c:\windows\Installer\79597.msp
+ 2008-07-29 12:01 . 2008-07-29 12:01 6083072 c:\windows\Installer\79594.msp
+ 2011-02-11 05:42 . 2010-12-09 13:38 2192768 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2011-02-11 05:42 . 2010-12-09 13:07 2027008 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2011-02-11 05:42 . 2010-12-09 13:07 2069376 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2011-02-11 05:42 . 2010-12-09 13:42 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2011-02-11 19:52 . 2011-02-11 19:52 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_f06d4a78\System.dll
+ 2011-02-11 19:53 . 2011-02-11 19:53 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_f2658e29\System.Xml.dll
+ 2011-02-11 19:53 . 2011-02-11 19:53 3018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_89e1091f\System.Windows.Forms.dll
+ 2011-02-11 19:53 . 2011-02-11 19:53 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_f0678e85\System.Design.dll
+ 2011-02-11 19:53 . 2011-02-11 19:53 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_e31a00af\mscorlib.dll
+ 2011-02-12 05:32 . 2011-02-12 05:32 7867392 c:\windows\assembly\NativeImages_v2.0.50727_32\System\aa7926460a336408c8041330ad90929d\System.ni.dll
+ 2011-02-12 05:34 . 2011-02-12 05:34 5449728 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\36f3953f24d4f0b767bf172331ad6f3e\System.Xml.ni.dll
+ 2011-02-12 05:33 . 2011-02-12 05:33 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6978f2e90f13bc720d57fa6895c911e2\System.Drawing.ni.dll
+ 2011-02-12 05:32 . 2011-02-12 05:32 6614016 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\0b40341027c01716cec1dd97592698e0\System.Data.ni.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 3149824 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2011-02-12 05:23 . 2011-02-12 05:23 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2011-02-12 05:21 . 2011-02-12 05:22 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2011-02-12 05:22 . 2011-02-12 05:22 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2011-02-12 05:21 . 2011-02-12 05:21 5238784 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-02-12 05:23 . 2011-02-12 05:23 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-02-12 05:22 . 2011-02-12 05:23 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-02-11 19:52 . 2011-02-11 19:52 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2011-02-11 19:52 . 2011-02-11 19:52 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2010-01-29 14:53 . 2010-01-29 14:53 1315328 c:\windows\$hf_mig$\KB978542\SP3QFE\msoe.dll
+ 2010-02-05 18:29 . 2010-02-05 18:29 1291776 c:\windows\$hf_mig$\KB975562\SP3QFE\quartz.dll
+ 2009-11-27 17:23 . 2009-11-27 17:23 1291776 c:\windows\$hf_mig$\KB975560\SP3QFE\quartz.dll
+ 2011-02-11 05:23 . 2009-07-31 04:24 1447424 c:\windows\$hf_mig$\KB973687\SP3QFE\msxml6.dll
+ 2011-02-11 05:23 . 2009-07-31 04:24 1172480 c:\windows\$hf_mig$\KB973687\SP3QFE\msxml3.dll
+ 2009-07-17 16:01 . 2009-07-17 16:01 1435648 c:\windows\$hf_mig$\KB969059\SP3QFE\query.dll
+ 2008-06-17 19:04 . 2008-06-17 19:04 8461824 c:\windows\$hf_mig$\KB967715\SP3QFE\shell32.dll
+ 2011-02-11 05:31 . 2009-06-09 15:21 2067968 c:\windows\$hf_mig$\KB956744\SP3QFE\lhmstscx.dll
+ 2009-02-07 14:05 . 2009-02-07 14:05 2189184 c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe
+ 2011-02-11 05:57 . 2009-02-06 10:30 2023936 c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrpamp.exe
+ 2011-02-11 05:57 . 2009-02-06 10:30 2066176 c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
+ 2011-02-11 05:57 . 2009-02-06 11:03 2145280 c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlmp.exe
+ 2008-09-10 01:10 . 2008-09-10 01:10 1379840 c:\windows\$hf_mig$\KB954459\SP3QFE\msxml6.dll
+ 2010-03-26 06:34 . 2011-02-04 12:04 37443528 c:\windows\system32\MRT.exe
+ 2010-09-24 08:38 . 2010-09-24 08:38 11430400 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2416447\M2416447Uninstall.msp
+ 2010-09-24 01:38 . 2010-09-24 01:38 17518080 c:\windows\Installer\32cbab5.msp
+ 2011-02-12 05:34 . 2011-02-12 05:34 12428800 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\9a254c455892c02355ab0ab0f0727c5b\System.Windows.Forms.ni.dll
+ 2011-02-12 05:33 . 2011-02-12 05:33 10681344 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\204db7071fb26343b0fd3f3d140c0bf8\System.Design.ni.dll
+ 2011-02-12 05:27 . 2011-02-12 05:27 11485184 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9adb89fa22fd5b4ce433b5aca7fb1b07\mscorlib.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-10 218032]
"Google Update"="c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-03-26 136176]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-03-19 5248312]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"netxpert"="c:\program files\Airtel NetXpert\bin\sprtcmd.exe" [2010-05-10 206120]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-2-15 581693]
C2CMonitor.lnk - c:\program files\ClickToConvert\C2CMonitor.exe [2010-6-29 414720]
Desktop Manager.lnk - c:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2008-9-21 1545488]
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2004-6-16 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2004-6-16 28672]
SetPoint.lnk - c:\program files\SetPoint\SetPoint.exe [2010-10-3 813584]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2010-11-30 608584]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"7005:TCP"= 7005:TCP:fhyyy

R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [10/3/2010 12:01 PM 10384]
R2 sprtsvc_netxpert;SupportSoft Sprocket Service (netxpert);c:\program files\Airtel NetXpert\bin\sprtsvc.exe [7/22/2010 6:35 PM 206120]
R2 tgsrvc_netxpert;SupportSoft Repair Service (netxpert);c:\program files\Airtel NetXpert\bin\tgsrvc.exe [7/22/2010 6:35 PM 185640]
S2 pvheampgi;System Installer;c:\windows\system32\svchost.exe -k netsvcs [4/14/2008 5:30 PM 14336]
.
Contents of the 'Scheduled Tasks' folder

2011-02-11 c:\windows\Tasks\FRU Task 2004-06-17 01:06ewlett-Packard2004-06-17 01:06p psc 1200 seriesD66655067F78228D3716D2BFC2C61DA319188DBF269518597.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2004-06-16 12:36]

2011-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1060284298-1844823847-299502267-1003Core.job
- c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-26 09:21]

2011-02-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1060284298-1844823847-299502267-1003UA.job
- c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-26 09:21]

2011-02-12 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2011-02-11 16:48]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {72525BAD-B524-46BB-BE84-7B331246C8C9} = 202.56.215.54,202.56.215.55
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-12 11:13
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2076)
c:\program files\SetPoint\lgscroll.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\windows\system32\wdfmgr.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\progra~1\Yahoo!\Messenger\ymsgr_tray.exe
c:\windows\System32\logon.scr
.
**************************************************************************
.
Completion time: 2011-02-12 11:16:57 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-12 05:46
ComboFix2.txt 2011-02-10 05:08

Pre-Run: 2,818,764,800 bytes free
Post-Run: 2,757,697,536 bytes free

Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - DAEB3B5CA32C4786CD3F62FEAF823B60
  • 0

#13
ali.B

ali.B

    Trusted Helper

  • Malware Removal
  • 3,086 posts
hi

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

Driver::
pvheampgi


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
  • 0

#14
kingfisher3210

kingfisher3210

    Member

  • Topic Starter
  • Member
  • PipPip
  • 42 posts
Thanks ali.B for your expertise.



ComboFix 11-02-12.01 - admin 02/13/2011 13:51:14.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.478.129 [GMT 5.5:30]
Running from: D:\ComboFix.exe
Command switches used :: D:\CFScript.txt
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

----- BITS: Possible infected sites -----

hxxp://netxpert.airtelbroadband.in
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_PVHEAMPGI
-------\Service_pvheampgi


((((((((((((((((((((((((( Files Created from 2011-01-13 to 2011-02-13 )))))))))))))))))))))))))))))))
.

2011-02-12 19:01 . 2011-02-12 19:01 -------- d-----w- c:\windows\system32\XPSViewer
2011-02-12 19:00 . 2011-02-12 19:00 -------- d-----w- c:\program files\MSBuild
2011-02-12 19:00 . 2011-02-12 19:00 -------- d-----w- c:\program files\Reference Assemblies
2011-02-12 05:28 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-02-12 05:28 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2011-02-12 05:28 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-02-12 05:28 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2011-02-12 05:28 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-02-12 05:28 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-02-12 05:28 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2011-02-12 05:28 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2011-02-11 19:50 . 2011-02-11 19:50 -------- d-----w- c:\program files\MSXML 4.0
2011-02-11 14:33 . 2011-02-11 14:33 -------- d-----w- c:\windows\system32\KB905474
2011-02-11 14:23 . 2011-02-12 05:10 -------- d-----w- c:\windows\system32\MpEngineStore
2011-02-11 05:42 . 2010-12-09 13:42 2148864 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-02-11 05:42 . 2010-12-09 13:38 2192768 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-02-11 05:42 . 2010-12-09 13:07 2027008 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-02-11 05:42 . 2010-12-09 13:07 2069376 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2011-02-11 05:10 . 2010-08-26 12:52 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-10 05:52 . 2011-02-10 05:52 -------- d-s---w- c:\windows\Cookies
2011-02-09 17:27 . 2011-02-09 17:27 -------- d-----w- c:\documents and settings\admin\Local Settings\Application Data\WinZip
2011-02-09 06:46 . 2011-02-09 06:46 388096 ----a-r- c:\documents and settings\admin\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-09 06:46 . 2011-02-09 06:46 -------- d-----w- c:\program files\Trend Micro
2011-02-09 06:38 . 2011-02-09 11:29 11264 ----a-w- c:\windows\DCEBoot.exe
2011-02-09 06:38 . 2011-02-09 11:29 102400 ----a-w- c:\windows\RegBootClean.exe
2011-02-09 06:25 . 2010-09-06 09:26 189520 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-02-08 18:19 . 2009-10-02 14:09 19472 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2011-02-08 18:19 . 2009-10-14 15:48 36880 ----a-w- c:\windows\system32\drivers\klbg.sys
2011-02-08 18:19 . 2009-12-14 07:14 88632 ----a-w- c:\windows\system32\drivers\CSCrySec.sys
2011-02-08 18:19 . 2009-12-14 07:14 39352 ----a-w- c:\windows\system32\drivers\CSVirtualDiskDrv.sys
2011-02-08 17:47 . 2011-02-08 17:47 -------- dc----w- c:\windows\system32\DRVSTORE

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2008-04-14 12:00 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2008-04-14 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2008-04-14 12:00 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2008-04-14 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 22:15 . 2008-04-14 12:00 667136 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 22:15 . 2008-04-14 12:00 61952 ----a-w- c:\windows\system32\tdc.ocx
2010-12-20 22:15 . 2010-03-26 06:49 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-12-20 17:26 . 2008-04-14 12:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 15:30 . 2008-04-14 12:00 369664 ----a-w- c:\windows\system32\html.iec
2010-12-09 15:15 . 2008-04-14 12:00 718336 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30 . 2008-04-14 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:38 . 2008-04-14 12:00 2192768 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07 . 2008-04-14 00:01 2069376 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-07 05:17 . 2010-12-07 05:17 28672 ----a-w- c:\windows\system32\eEmpty.exe
2010-11-18 18:12 . 2009-05-29 06:13 81920 ----a-w- c:\windows\system32\isign32.dll
.

((((((((((((((((((((((((((((( SnapShot_2011-02-12_05.41.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-02-13 08:34 . 2011-02-13 08:34 16384 c:\windows\temp\Perflib_Perfdata_f4.dat
+ 2008-07-29 15:40 . 2008-07-29 15:40 26112 c:\windows\system32\TsWpfWrp.exe
+ 2008-04-14 12:00 . 2010-08-27 05:57 99840 c:\windows\system32\srvsvc.dll
+ 2008-07-29 14:29 . 2008-07-29 14:29 43544 c:\windows\system32\PresentationHostProxy.dll
+ 2008-04-14 12:00 . 2011-02-12 19:09 72824 c:\windows\system32\perfc009.dat
+ 2008-07-29 13:54 . 2008-07-29 13:54 97800 c:\windows\system32\infocardapi.dll
+ 2008-07-29 13:54 . 2008-07-29 13:54 11264 c:\windows\system32\icardres.dll
+ 2008-07-29 15:40 . 2008-07-29 15:40 73720 c:\windows\system32\dxva2.dll
+ 2008-04-14 12:00 . 2010-08-27 05:57 99840 c:\windows\system32\dllcache\srvsvc.dll
+ 2008-07-29 18:10 . 2008-07-29 18:10 70648 c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
+ 2008-07-29 18:10 . 2008-07-29 18:10 91136 c:\windows\Microsoft.NET\Framework\v3.5\MSBuild.exe
+ 2008-07-29 18:10 . 2008-07-29 18:10 41984 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft.VisualC.STLCLR.dll
+ 2008-07-29 18:10 . 2008-07-29 18:10 40960 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft.Data.Entity.Build.Tasks.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 89080 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.2052.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 92664 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1042.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 95224 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1041.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 89592 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1028.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 84480 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.2052.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 94720 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1042.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 97792 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1041.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 84992 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1028.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 97280 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\DeleteTemp.exe
+ 2008-07-29 18:10 . 2008-07-29 18:10 95224 c:\windows\Microsoft.NET\Framework\v3.5\EdmGen.exe
+ 2008-07-29 18:10 . 2008-07-29 18:10 78856 c:\windows\Microsoft.NET\Framework\v3.5\DataSvcUtil.exe
+ 2008-07-29 18:10 . 2008-07-29 18:10 41984 c:\windows\Microsoft.NET\Framework\v3.5\AddInUtil.exe
+ 2008-07-29 18:10 . 2008-07-29 18:10 41992 c:\windows\Microsoft.NET\Framework\v3.5\AddInProcess32.exe
+ 2008-07-29 18:10 . 2008-07-29 18:10 41992 c:\windows\Microsoft.NET\Framework\v3.5\AddInProcess.exe
+ 2008-07-29 15:40 . 2008-07-29 15:40 46104 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
+ 2008-07-29 14:29 . 2008-07-29 14:29 32768 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationCFFRasterizer.dll
+ 2008-07-29 15:40 . 2008-07-29 15:40 71160 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PenIMC.dll
+ 2008-07-29 14:02 . 2008-07-29 14:02 17448 c:\windows\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\PerformanceCounterInstaller.exe
+ 2008-07-29 13:46 . 2008-07-29 13:46 32768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
+ 2008-07-29 13:46 . 2008-07-29 13:46 73728 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.Install.dll
+ 2008-07-29 13:46 . 2008-07-29 13:46 20504 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceMonikerSupport.dll
+ 2008-07-29 13:46 . 2008-07-29 13:46 11280 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
+ 2008-11-24 23:29 . 2008-11-24 23:29 31560 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2008-07-29 15:37 . 2008-07-29 15:37 23040 c:\windows\Installer\106c73e.msp
+ 2011-02-13 08:03 . 2011-02-13 08:03 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\a715aa442ef87ae99b3ade185599249d\UIAutomationProvider.ni.dll
+ 2011-02-13 08:14 . 2011-02-13 08:14 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\532438e2acfcadc469a4d468c51f8451\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-02-13 08:14 . 2011-02-13 08:14 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\597b20e1b053d6a510cfe033c07a63e6\System.AddIn.Contract.ni.dll
+ 2011-02-13 07:55 . 2011-02-13 07:55 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\2d7408a0232f2e2efd0d7adf5dfa733a\PresentationFontCache.ni.exe
+ 2011-02-13 07:54 . 2011-02-13 07:54 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\c8fd2d9233f8ea3031fb16f697635231\PresentationCFFRasterizer.ni.dll
+ 2011-02-13 08:14 . 2011-02-13 08:14 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e9aba2eab90d647356f65e66053da02b\Microsoft.Build.Framework.ni.dll
+ 2011-02-13 08:13 . 2011-02-13 08:13 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\28343d470d992f169ca0e7cdb3cc3117\Microsoft.Build.Framework.ni.dll
+ 2011-02-13 08:13 . 2011-02-13 08:13 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\f4e38208e88cb4cc314a1d6543b9fcc6\dfsvc.ni.exe
+ 2011-02-13 08:13 . 2011-02-13 08:13 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\11eb4f6606ba01e5128805759121ea6c\Accessibility.ni.dll
+ 2011-02-12 19:01 . 2011-02-12 19:01 94208 c:\windows\assembly\GAC_MSIL\WindowsFormsIntegration\3.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 98304 c:\windows\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 40960 c:\windows\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 12288 c:\windows\assembly\GAC_MSIL\System.Windows.Presentation\3.5.0.0__b77a5c561934e089\System.Windows.Presentation.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 61440 c:\windows\assembly\GAC_MSIL\System.Web.Routing\3.5.0.0__31bf3856ad364e35\System.Web.Routing.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2011-02-12 05:21 . 2011-02-12 05:21 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 32768 c:\windows\assembly\GAC_MSIL\System.Web.DynamicData.Design\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.Design.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 77824 c:\windows\assembly\GAC_MSIL\System.Web.Abstractions\3.5.0.0__31bf3856ad364e35\System.Web.Abstractions.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 32768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 73728 c:\windows\assembly\GAC_MSIL\System.ServiceModel.Install\3.0.0.0__b77a5c561934e089\System.ServiceModel.Install.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 53248 c:\windows\assembly\GAC_MSIL\System.Data.DataSetExtensions\3.5.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-02-12 19:08 . 2011-02-12 19:08 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 57344 c:\windows\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\3.5.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 45056 c:\windows\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 46104 c:\windows\assembly\GAC_MSIL\PresentationFontCache\3.0.0.0__31bf3856ad364e35\PresentationFontCache.exe
+ 2011-02-12 19:00 . 2011-02-12 19:00 32768 c:\windows\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 41984 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR\1.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.STLCLR.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-02-12 19:08 . 2011-02-12 19:08 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 94208 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.v3.5.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2008-07-29 18:10 . 2008-07-29 18:10 5632 c:\windows\Microsoft.NET\Framework\v3.5\Sentinel.v3.5Client.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 5632 c:\windows\assembly\GAC_MSIL\Sentinel.v3.5Client\3.5.0.0__b03f5f7f11d50a3a\Sentinel.v3.5Client.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2011-02-12 19:08 . 2011-02-12 19:08 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2011-02-12 05:23 . 2011-02-12 05:23 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2007-11-06 20:49 . 2007-11-06 20:49 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcr90.dll
+ 2007-11-06 20:49 . 2007-11-06 20:49 568832 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcp90.dll
+ 2007-11-06 15:53 . 2007-11-06 15:53 224768 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcm90.dll
+ 2008-07-29 15:56 . 2008-07-29 15:56 301568 c:\windows\system32\XPSViewer\XPSViewer.exe
+ 2008-07-29 14:29 . 2008-07-29 14:29 161296 c:\windows\system32\UIAutomationCore.dll
+ 2008-07-29 14:29 . 2008-07-29 14:29 781344 c:\windows\system32\PresentationNative_v0300.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 326160 c:\windows\system32\PresentationHost.exe
+ 2008-07-29 14:29 . 2008-07-29 14:29 105016 c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
+ 2008-04-14 12:00 . 2011-02-12 19:09 445472 c:\windows\system32\perfh009.dat
+ 2009-05-29 06:13 . 2010-06-09 07:43 692736 c:\windows\system32\inetcomm.dll
+ 2008-07-29 13:54 . 2008-07-29 13:54 622080 c:\windows\system32\icardagt.exe
+ 2009-05-29 11:17 . 2011-02-13 07:53 333872 c:\windows\system32\FNTCACHE.DAT
+ 2008-07-29 15:40 . 2008-07-29 15:40 493048 c:\windows\system32\evr.dll
+ 2008-04-14 12:00 . 2010-08-26 13:39 357248 c:\windows\system32\drivers\srv.sys
+ 2008-04-14 12:00 . 2010-08-26 13:39 357248 c:\windows\system32\dllcache\srv.sys
+ 2009-05-29 06:13 . 2010-06-09 07:43 692736 c:\windows\system32\dllcache\inetcomm.dll
+ 2008-07-29 18:10 . 2008-07-29 18:10 196104 c:\windows\Microsoft.NET\Framework\v3.5\WFServicesReg.exe
+ 2008-07-29 18:10 . 2008-07-29 18:10 802816 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft.Build.Tasks.v3.5.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 984056 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapUI.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 107512 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 111096 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.3082.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 110072 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.2070.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 106488 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1055.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 105976 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1053.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 107000 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1049.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 107512 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1046.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 109048 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1045.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 106488 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1044.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 108536 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1043.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 110072 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1040.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 111096 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1038.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 101368 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1037.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 112120 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1036.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 106488 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1035.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 113656 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1032.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 111608 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1031.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 108536 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1030.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 108536 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1029.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 102904 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1025.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 689152 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vsscenario.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 413184 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vsbasereqs.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 632320 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vs70uimgr.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 652800 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vs_setup.msi
+ 2008-07-29 13:17 . 2008-07-29 13:17 110080 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 131584 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.3082.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 131072 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.2070.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 121344 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1055.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 121344 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1053.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 123904 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1049.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 122880 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1046.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 128512 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1045.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 121856 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1044.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 129024 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1043.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 128512 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1040.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 132096 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1038.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 111104 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1037.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 133120 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1036.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 122368 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1035.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 137728 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1032.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 130048 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1031.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 126464 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1030.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 125440 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1029.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 113152 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1025.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 269304 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
+ 2008-07-29 13:17 . 2008-07-29 13:17 177152 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\HtmlLite.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 276984 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\dlmgr.dll
+ 2008-07-29 17:45 . 2008-07-29 17:45 225490 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\baseline.dat
+ 2008-07-29 18:10 . 2008-07-29 18:10 233976 c:\windows\Microsoft.NET\Framework\v3.5\1033\vbc7ui.dll
+ 2008-07-29 18:10 . 2008-07-29 18:10 168448 c:\windows\Microsoft.NET\Framework\v3.5\1033\cscompui.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 864256 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationUI.dll
+ 2008-07-29 14:29 . 2008-07-29 14:29 132120 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
+ 2008-07-29 15:40 . 2008-07-29 15:40 806928 c:\windows\Microsoft.NET\Framework\v3.0\WPF\NaturalLanguage6.dll
+ 2008-07-29 13:46 . 2008-07-29 13:46 152576 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\WsatConfig.exe
+ 2008-07-29 13:46 . 2008-07-29 13:46 966656 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
+ 2008-07-29 13:46 . 2008-07-29 13:46 132096 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
+ 2008-07-29 13:46 . 2008-07-29 13:46 110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
+ 2008-07-29 13:46 . 2008-07-29 13:46 156688 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelReg.exe
+ 2008-07-29 13:46 . 2008-07-29 13:46 163840 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.Dtc.dll
+ 2008-07-29 13:46 . 2008-07-29 13:46 397312 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.dll
+ 2008-07-29 13:54 . 2008-07-29 13:54 881664 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
+ 2008-07-29 13:46 . 2008-07-29 13:46 168968 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ComSvcConfig.exe
+ 2008-11-24 23:29 . 2008-11-24 23:29 436040 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
+ 2008-11-24 23:29 . 2008-11-24 23:29 486400 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll
- 2008-07-25 05:47 . 2008-07-25 05:47 486400 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll
+ 2008-11-24 23:29 . 2008-11-24 23:29 364872 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2008-11-24 23:29 . 2008-11-24 23:29 990032 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2008-12-13 04:28 . 2008-12-13 04:28 754688 c:\windows\Installer\108a738.msp
+ 2011-02-12 19:03 . 2011-02-12 19:03 648192 c:\windows\Installer\108a70f.msi
+ 2008-07-29 15:53 . 2008-07-29 15:53 250880 c:\windows\Installer\106c747.msp
+ 2008-07-29 15:58 . 2008-07-29 15:58 278016 c:\windows\Installer\106c745.msp
+ 2008-07-29 14:10 . 2008-07-29 14:10 291840 c:\windows\Installer\106c743.msp
+ 2011-02-12 19:01 . 2011-02-12 19:01 137728 c:\windows\Installer\106c73d.msi
+ 2011-02-13 08:13 . 2011-02-13 08:13 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\2ef5bc3a2edd7570bb23886a4f32294a\WsatConfig.ni.exe
+ 2011-02-13 08:03 . 2011-02-13 08:03 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\6a818099f0386e2356ae94f886a2196f\WindowsFormsIntegration.ni.dll
+ 2011-02-13 08:03 . 2011-02-13 08:03 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\a6d9503962d47c722231c1478f180695\UIAutomationTypes.ni.dll
+ 2011-02-13 08:03 . 2011-02-13 08:03 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\5c028c3d8db6c0f0277673ea4a2d89fb\UIAutomationClient.ni.dll
+ 2011-02-13 08:13 . 2011-02-13 08:13 676352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\1c8df2da33222c048d683017f2095f04\System.Security.ni.dll
+ 2011-02-13 08:10 . 2011-02-13 08:10 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\7c367a96b10d626ec8cbf8149272d845\System.IO.Log.ni.dll
+ 2011-02-13 08:10 . 2011-02-13 08:10 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\68e71147704ef0d34d9a4bece7767fc5\System.IdentityModel.Selectors.ni.dll
+ 2011-02-13 08:01 . 2011-02-13 08:01 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\18bbe2b6717e7f1d1dd672526e9889ee\System.Drawing.Design.ni.dll
+ 2011-02-13 08:14 . 2011-02-13 08:14 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\1db495ff00bbd14df4af6680c4de0653\System.Data.DataSetExtensions.ni.dll
+ 2011-02-13 08:13 . 2011-02-13 08:13 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\b82c00e2d24305ad6cb08556e3779b75\System.Configuration.ni.dll
+ 2011-02-13 08:14 . 2011-02-13 08:14 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\ce984d754e3c0b6be4504b785cc43574\System.AddIn.ni.dll
+ 2011-02-13 08:13 . 2011-02-13 08:13 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\045dd501b7257b1cc26083538ae69045\SMSvcHost.ni.exe
+ 2011-02-13 08:13 . 2011-02-13 08:13 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\9790551187e294b4ed3aaa1c221891c7\SMDiagnostics.ni.dll
+ 2011-02-13 08:13 . 2011-02-13 08:13 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\10a0c9707876fc1f65e64b811a28b020\ServiceModelReg.ni.exe
+ 2011-02-13 07:57 . 2011-02-13 07:57 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\f475294d8c7dc2dd4febeef27bc0417e\PresentationFramework.Classic.ni.dll
+ 2011-02-13 07:57 . 2011-02-13 07:57 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8003abaf6bcf70f7eb620d06837e897b\PresentationFramework.Luna.ni.dll
+ 2011-02-13 07:57 . 2011-02-13 07:57 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\59a67874d8d8475faa5be1d993083d12\PresentationFramework.Aero.ni.dll
+ 2011-02-13 07:57 . 2011-02-13 07:57 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2c980c9a5051d723c6ec2a78a3d0e2b3\PresentationFramework.Royale.ni.dll
+ 2011-02-13 08:13 . 2011-02-13 08:13 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\6d38e317128608bc4516ea46ab94590e\MSBuild.ni.exe
+ 2011-02-13 08:13 . 2011-02-13 08:13 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\1820d6a012fc0e16c3e1d29d973cd2d0\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-02-13 08:14 . 2011-02-13 08:14 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\55b9eff9e23359faed4351386c062238\Microsoft.Build.Utilities.ni.dll
+ 2011-02-13 08:14 . 2011-02-13 08:14 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\4217124db1ea5de5f1a1f3eea75e8d32\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2011-02-13 08:14 . 2011-02-13 08:14 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\96825c34d7e1f7df1923ff2123bed8da\Microsoft.Build.Engine.ni.dll
+ 2011-02-13 08:14 . 2011-02-13 08:14 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\9b321ebf67587237f576df6104a32588\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2011-02-13 08:13 . 2011-02-13 08:13 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\9bea05938bee3555c5aa8763d89a68f9\CustomMarshalers.ni.dll
+ 2011-02-13 08:13 . 2011-02-13 08:13 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\12629e2f3e315459bee67cbbaac85cb2\ComSvcConfig.ni.exe
+ 2011-02-13 08:13 . 2011-02-13 08:13 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\b5b2feadc3943e3976daebc0bcd2b5e2\AspNetMMCExt.ni.dll
+ 2011-02-12 19:01 . 2011-02-12 19:01 385024 c:\windows\assembly\GAC_MSIL\UIAutomationClientsideProviders\3.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
+ 2011-02-12 19:01 . 2011-02-12 19:01 167936 c:\windows\assembly\GAC_MSIL\UIAutomationClient\3.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 139264 c:\windows\assembly\GAC_MSIL\System.Xml.Linq\3.5.0.0__b77a5c561934e089\System.Xml.Linq.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 507904 c:\windows\assembly\GAC_MSIL\System.WorkflowServices\3.5.0.0__31bf3856ad364e35\System.WorkflowServices.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 540672 c:\windows\assembly\GAC_MSIL\System.Workflow.Runtime\3.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2011-02-12 05:21 . 2011-02-12 05:21 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2011-02-12 05:21 . 2011-02-12 05:21 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 335872 c:\windows\assembly\GAC_MSIL\System.Web.Extensions.Design\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.Design.dll
+ 2011-02-12 19:11 . 2011-02-12 19:11 139264 c:\windows\assembly\GAC_MSIL\System.Web.Entity\3.5.0.0__b77a5c561934e089\System.Web.Entity.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 131072 c:\windows\assembly\GAC_MSIL\System.Web.Entity.Design\3.5.0.0__b77a5c561934e089\System.Web.Entity.Design.dll
+ 2011-02-12 19:11 . 2011-02-12 19:11 229376 c:\windows\assembly\GAC_MSIL\System.Web.DynamicData\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 688128 c:\windows\assembly\GAC_MSIL\System.Speech\3.0.0.0__31bf3856ad364e35\System.Speech.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2011-02-12 05:23 . 2011-02-12 05:23 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 569344 c:\windows\assembly\GAC_MSIL\System.ServiceModel.Web\3.5.0.0__31bf3856ad364e35\System.ServiceModel.Web.dll
- 2011-02-12 05:23 . 2011-02-12 05:23 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 966656 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 233472 c:\windows\assembly\GAC_MSIL\System.Net\3.5.0.0__b03f5f7f11d50a3a\System.Net.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2011-02-12 19:08 . 2011-02-12 19:08 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 143360 c:\windows\assembly\GAC_MSIL\System.Management.Instrumentation\3.5.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 131072 c:\windows\assembly\GAC_MSIL\System.IO.Log\3.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 430080 c:\windows\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
+ 2011-02-12 19:01 . 2011-02-12 19:01 126976 c:\windows\assembly\GAC_MSIL\System.IdentityModel.Selectors\3.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2011-02-12 05:23 . 2011-02-12 05:23 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 286720 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\3.5.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2011-02-12 19:08 . 2011-02-12 19:08 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2011-02-12 19:08 . 2011-02-12 19:08 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2011-02-12 19:11 . 2011-02-12 19:11 442368 c:\windows\assembly\GAC_MSIL\System.Data.Services\3.5.0.0__b77a5c561934e089\System.Data.Services.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 114688 c:\windows\assembly\GAC_MSIL\System.Data.Services.Design\3.5.0.0__b77a5c561934e089\System.Data.Services.Design.dll
+ 2011-02-12 19:11 . 2011-02-12 19:11 294912 c:\windows\assembly\GAC_MSIL\System.Data.Services.Client\3.5.0.0__b77a5c561934e089\System.Data.Services.Client.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 684032 c:\windows\assembly\GAC_MSIL\System.Data.Linq\3.5.0.0__b77a5c561934e089\System.Data.Linq.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 229376 c:\windows\assembly\GAC_MSIL\System.Data.Entity.Design\3.5.0.0__b77a5c561934e089\System.Data.Entity.Design.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 667648 c:\windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll
- 2011-02-12 05:23 . 2011-02-12 05:23 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2011-02-12 19:08 . 2011-02-12 19:08 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-02-12 19:08 . 2011-02-12 19:08 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 528384 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2011-02-12 19:01 . 2011-02-12 19:01 864256 c:\windows\assembly\GAC_MSIL\PresentationUI\3.0.0.0__31bf3856ad364e35\PresentationUI.dll
+ 2011-02-12 19:01 . 2011-02-12 19:01 163840 c:\windows\assembly\GAC_MSIL\PresentationFramework.Royale\3.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
+ 2011-02-12 19:01 . 2011-02-12 19:01 397312 c:\windows\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
+ 2011-02-12 19:01 . 2011-02-12 19:01 139264 c:\windows\assembly\GAC_MSIL\PresentationFramework.Classic\3.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
+ 2011-02-12 19:01 . 2011-02-12 19:01 196608 c:\windows\assembly\GAC_MSIL\PresentationFramework.Aero\3.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 598016 c:\windows\assembly\GAC_MSIL\PresentationBuildTasks\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 397312 c:\windows\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 802816 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.v3.5.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 733184 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 106496 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Conversion.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Conversion.v3.5.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2011-02-12 05:21 . 2011-02-12 05:21 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 368640 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-02-12 19:08 . 2011-02-12 19:08 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 163840 c:\windows\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2008-07-29 18:10 . 2008-07-29 18:10 1720824 c:\windows\Microsoft.NET\Framework\v3.5\vbc.exe
+ 2008-07-29 13:17 . 2008-07-29 13:17 1054208 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vs_setup.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 1364992 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\SITSetup.dll
+ 2008-07-29 13:17 . 2008-07-29 13:17 1064448 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\gencomp.dll
+ 2008-07-29 18:10 . 2008-07-29 18:10 1548280 c:\windows\Microsoft.NET\Framework\v3.5\csc.exe
+ 2008-12-05 14:05 . 2008-12-05 14:05 1736528 c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll
+ 2008-07-29 15:40 . 2008-07-29 15:40 2637840 c:\windows\Microsoft.NET\Framework\v3.0\WPF\NlsLexicons0009.dll
+ 2008-07-29 15:40 . 2008-07-29 15:40 4883464 c:\windows\Microsoft.NET\Framework\v3.0\WPF\NlsData0009.dll
+ 2008-12-05 14:42 . 2008-12-05 14:42 5931008 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll
+ 2008-11-24 23:29 . 2008-11-24 23:29 2048000 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
- 2008-07-25 05:47 . 2008-07-25 05:47 2048000 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
+ 2008-11-24 23:29 . 2008-11-24 23:29 5242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2008-11-24 23:29 . 2008-11-24 23:29 5813576 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
- 2008-07-25 05:47 . 2008-07-25 05:47 4546560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2008-11-24 23:29 . 2008-11-24 23:29 4546560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2008-12-13 04:27 . 2008-12-13 04:27 8397824 c:\windows\Installer\108a71f.msp
+ 2008-07-29 13:56 . 2008-07-29 13:56 1043456 c:\windows\Installer\106c746.msp
+ 2008-07-29 15:07 . 2008-07-29 15:07 2679808 c:\windows\Installer\106c744.msp
+ 2008-07-29 15:45 . 2008-07-29 15:45 3697664 c:\windows\Installer\106c742.msp
+ 2008-07-29 14:04 . 2008-07-29 14:04 1448448 c:\windows\Installer\106c741.msp
+ 2008-07-29 14:52 . 2008-07-29 14:52 4137984 c:\windows\Installer\106c740.msp
+ 2008-07-29 13:48 . 2008-07-29 13:48 3376640 c:\windows\Installer\106c73f.msp
+ 2011-02-13 07:54 . 2011-02-13 07:55 3313664 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\14cd5f4b61d35f9b76327d6be9853755\WindowsBase.ni.dll
+ 2011-02-13 08:03 . 2011-02-13 08:03 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\f3c7957351aec85f526a3350c9718b1e\UIAutomationClientsideProviders.ni.dll
+ 2011-02-13 07:54 . 2011-02-13 07:54 7868416 c:\windows\assembly\NativeImages_v2.0.50727_32\System\80978a322d7dd39f0a71be1251ae395a\System.ni.dll
+ 2011-02-13 08:02 . 2011-02-13 08:02 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\773a9786013451d3baaeff003dc4230f\System.Xml.ni.dll
+ 2011-02-13 08:01 . 2011-02-13 08:01 1917440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\63cf639b6e0a3c25c1643c85016e7422\System.Speech.ni.dll
+ 2011-02-13 08:11 . 2011-02-13 08:11 2338304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\034c91b133dee73d452652c52767b5ea\System.Runtime.Serialization.ni.dll
+ 2011-02-13 08:01 . 2011-02-13 08:01 1035264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\646ab52eef343380aa002c220dc31e13\System.Printing.ni.dll
+ 2011-02-13 08:10 . 2011-02-13 08:10 1056768 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\c2de8479e54852f56996f79bc93acb13\System.IdentityModel.ni.dll
+ 2011-02-13 08:01 . 2011-02-13 08:01 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3da96ee075bab9202626ae44c18d226c\System.Drawing.ni.dll
+ 2011-02-13 07:59 . 2011-02-13 07:59 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\c70731047b0022638b3f9fb158948a03\System.Data.ni.dll
+ 2011-02-13 08:13 . 2011-02-13 08:13 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\826b09ab0d0e36f4d631b4cd335df511\System.Data.SqlXml.ni.dll
+ 2011-02-13 07:59 . 2011-02-13 07:59 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\0bbec79460b1137df5313f9baf7b246f\System.Data.Linq.ni.dll
+ 2011-02-13 07:58 . 2011-02-13 07:58 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\47d87251e93256c635eb73403b8db33e\System.Core.ni.dll
+ 2011-02-13 07:57 . 2011-02-13 07:57 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\4bfb3048bf200a6a8592d1b4ba861a7f\ReachFramework.ni.dll
+ 2011-02-13 07:57 . 2011-02-13 07:57 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\6bafb1a2a73794ddb9761cb321c9e7e2\PresentationUI.ni.dll
+ 2011-02-13 07:54 . 2011-02-13 07:54 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\e634bc4c4a00635a0a254febab0e2e2c\PresentationBuildTasks.ni.dll
+ 2011-02-13 08:14 . 2011-02-13 08:14 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\1c86afc399d0fdd8e069266ffbe748d1\Microsoft.VisualBasic.ni.dll
+ 2011-02-13 08:13 . 2011-02-13 08:13 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\6b2f62f5e981913fce1d223f645d9ddf\Microsoft.Transactions.Bridge.ni.dll
+ 2011-02-13 08:14 . 2011-02-13 08:14 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\bd241492d96db39f20e758c13c845033\Microsoft.Build.Tasks.ni.dll
+ 2011-02-13 08:14 . 2011-02-13 08:14 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\a47100d8f4574bed2d49d83d0ab8964e\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2011-02-13 08:13 . 2011-02-13 08:13 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\6cfe582681724965fb817e8ece5f0909\Microsoft.Build.Engine.ni.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 1245184 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2011-02-12 19:08 . 2011-02-12 19:08 3149824 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 3149824 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2011-02-12 05:23 . 2011-02-12 05:23 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2011-02-12 19:08 . 2011-02-12 19:08 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 1630208 c:\windows\assembly\GAC_MSIL\System.Workflow.ComponentModel\3.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 1138688 c:\windows\assembly\GAC_MSIL\System.Workflow.Activities\3.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
- 2011-02-12 05:21 . 2011-02-12 05:22 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2011-02-12 19:11 . 2011-02-12 19:11 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
+ 2011-02-12 19:10 . 2011-02-12 19:10 5931008 c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
- 2011-02-12 05:22 . 2011-02-12 05:22 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2011-02-12 19:02 . 2011-02-12 19:02 2879488 c:\windows\assembly\GAC_MSIL\System.Data.Entity\3.5.0.0__b77a5c561934e089\System.Data.Entity.dll
+ 2011-02-12 19:10 . 2011-02-12 19:10 5283840 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2011-02-12 19:07 . 2011-02-12 19:07 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2011-02-12 05:23 . 2011-02-12 05:23 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-02-12 19:08 . 2011-02-12 19:08 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-02-12 19:00 . 2011-02-12 19:00 4210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2011-02-12 05:22 . 2011-02-12 05:23 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-02-12 19:08 . 2011-02-12 19:08 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2008-12-13 04:51 . 2008-12-13 04:51 10473472 c:\windows\Installer\108a72b.msp
+ 2011-02-13 08:02 . 2011-02-13 08:02 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\63406259e94d5c0ff5b79401dfe113ce\System.Windows.Forms.ni.dll
+ 2011-02-13 08:13 . 2011-02-13 08:13 17317888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\85a68b5908535729e0458a1a58001df3\System.ServiceModel.ni.dll
+ 2011-02-13 08:00 . 2011-02-13 08:00 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\8ee220bc3cce4f7bbd7818946519ed7f\System.Design.ni.dll
+ 2011-02-13 07:56 . 2011-02-13 07:56 14327808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\96e710f47c601cba3f2348a8d11ddede\PresentationFramework.ni.dll
+ 2011-02-13 07:55 . 2011-02-13 07:55 12216320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\956375d487cbef36165b3250030e3574\PresentationCore.ni.dll
+ 2011-02-12 19:10 . 2011-02-12 19:11 11486720 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\6d667f19d687361886990f3ca0f49816\mscorlib.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-10 218032]
"Google Update"="c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-03-26 136176]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-03-19 5248312]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"netxpert"="c:\program files\Airtel NetXpert\bin\sprtcmd.exe" [2010-05-10 206120]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-2-15 581693]
C2CMonitor.lnk - c:\program files\ClickToConvert\C2CMonitor.exe [2010-6-29 414720]
Desktop Manager.lnk - c:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2008-9-21 1545488]
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2004-6-16 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2004-6-16 28672]
SetPoint.lnk - c:\program files\SetPoint\SetPoint.exe [2010-10-3 813584]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2010-11-30 608584]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"7005:TCP"= 7005:TCP:fhyyy

R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [10/3/2010 12:01 PM 10384]
R2 sprtsvc_netxpert;SupportSoft Sprocket Service (netxpert);c:\program files\Airtel NetXpert\bin\sprtsvc.exe [7/22/2010 6:35 PM 206120]
R2 tgsrvc_netxpert;SupportSoft Repair Service (netxpert);c:\program files\Airtel NetXpert\bin\tgsrvc.exe [7/22/2010 6:35 PM 185640]
.
Contents of the 'Scheduled Tasks' folder

2011-02-11 c:\windows\Tasks\FRU Task 2004-06-17 01:06ewlett-Packard2004-06-17 01:06p psc 1200 seriesD66655067F78228D3716D2BFC2C61DA319188DBF269518597.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2004-06-16 12:36]

2011-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1060284298-1844823847-299502267-1003Core.job
- c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-26 09:21]

2011-02-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1060284298-1844823847-299502267-1003UA.job
- c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-26 09:21]

2011-02-13 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2011-02-11 16:48]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {72525BAD-B524-46BB-BE84-7B331246C8C9} = 202.56.215.54,202.56.215.55
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-13 14:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(1324)
c:\program files\SetPoint\lgscroll.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\progra~1\Yahoo!\Messenger\ymsgr_tray.exe
c:\windows\System32\logon.scr
.
**************************************************************************
.
Completion time: 2011-02-13 14:10:01 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-13 08:39
ComboFix2.txt 2011-02-12 05:46
ComboFix3.txt 2011-02-10 05:08

Pre-Run: 2,165,522,432 bytes free
Post-Run: 2,102,804,480 bytes free

Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - 8D60CDD5507AD300F209364978246BE9
  • 0

#15
ali.B

ali.B

    Trusted Helper

  • Malware Removal
  • 3,086 posts
hi

Step 1

Posted Image Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

Step 2

Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic


Things i would like to see in your reply:
  • Malwarebytes Results.
  • Eset scanner report.
  • Update on how your computer is running

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP