Yes those files were sitting there before I ever thought of contacting you, but seems like they were just saved and sitting there on that particular screen in avast.
aswMBR
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-09-09 10:25:28
-----------------------------
10:25:28.104 OS Version: Windows x64 6.0.6002 Service Pack 2
10:25:28.104 Number of processors: 2 586 0x170A
10:25:28.104 ComputerName: PATRICK-PC UserName: patrick
10:25:30.179 Initialize success
10:25:30.912 AVAST engine defs: 11090900
10:25:54.141 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
10:25:54.141 Disk 0 Vendor: WDC_WD32 12.0 Size: 305245MB BusType: 3
10:25:54.219 Disk 0 MBR read successfully
10:25:54.234 Disk 0 MBR scan
10:25:54.234 Disk 0 Windows VISTA default MBR code
10:25:54.234 Service scanning
10:25:55.966 Modules scanning
10:25:55.966 Disk 0 trace - called modules:
10:25:56.028 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
10:25:56.028 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800682e790]
10:25:56.028 3 CLASSPNP.SYS[fffffa6000dd3c33] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004c48050]
10:25:57.339 AVAST engine scan C:\Windows
10:26:00.708 AVAST engine scan C:\Windows\system32
10:27:13.981 AVAST engine scan C:\Windows\system32\drivers
10:27:22.530 AVAST engine scan C:\Users\patrick
10:31:16.390 AVAST engine scan C:\ProgramData
10:34:31.792 Scan finished successfully
10:37:35.045 Disk 0 MBR has been saved successfully to "F:\MBR.dat"
10:37:35.076 The log file has been saved successfully to "F:\aswMBR.txt"
ComboFix
I dragged the file into combofix, it updated and began scanning.It did say "failed to get data for 'EnableLUA' after it started. Didnt see it do anything like a fix, but i let it do its thing anyway, below is the log.
ComboFix 11-09-09.03 - patrick 09/09/2011 10:45:37.2.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3963.2185 [GMT -4:00]
Running from: c:\users\patrick\Desktop\ComboFix.exe
Command switches used :: c:\users\patrick\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\assembly\GAC_32\Desktop.ini"
"c:\windows\assembly\GAC_64\Desktop.ini"
"c:\windows\assembly\tmp\U\800000cf.@"
"c:\windows\system32\consrv.dll"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
.
.
((((((((((((((((((((((((( Files Created from 2011-08-09 to 2011-09-09 )))))))))))))))))))))))))))))))
.
.
2011-09-09 14:55 . 2011-09-09 14:57 -------- d-----w- c:\users\patrick\AppData\Local\temp
2011-09-09 14:55 . 2011-09-09 14:55 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-09-08 22:13 . 2011-09-08 22:13 -------- d-----w- c:\windows\LastGood.Tmp
2011-09-08 19:47 . 2011-09-08 19:47 -------- d-----w- c:\program files (x86)\ESET
2011-09-08 19:40 . 2011-09-08 19:40 -------- d-----w- c:\programdata\Panda Security
2011-09-08 19:40 . 2011-09-08 19:40 -------- d-----w- c:\program files (x86)\Panda USB Vaccine
2011-09-08 14:14 . 2011-09-08 14:14 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-09-08 14:13 . 2011-09-08 14:13 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-09-08 14:13 . 2011-09-08 14:13 -------- d-----w- c:\program files (x86)\Java
2011-09-08 00:58 . 2011-09-08 00:58 -------- d-----w- C:\_OTL
2011-09-07 03:59 . 2011-01-13 07:41 273488 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-09-07 03:59 . 2011-01-13 07:37 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-09-07 03:59 . 2011-01-13 07:37 29264 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-09-07 03:59 . 2011-01-13 07:40 51792 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-09-07 03:59 . 2011-01-13 07:37 62032 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-09-07 03:59 . 2011-01-13 07:47 38848 ----a-w- c:\windows\avastSS.scr
2011-09-07 03:59 . 2011-01-13 07:47 188216 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-08-31 17:09 . 2011-07-11 13:45 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-31 17:09 . 2011-07-11 13:25 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-08-18 07:11 . 2011-08-18 07:11 -------- d-----w- c:\program files\Alwil Software
2011-08-18 05:09 . 2011-06-06 10:59 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-08-18 05:09 . 2011-06-06 10:59 2409784 ----a-w- c:\program files (x86)\Windows Mail\OESpamFilter.dat
2011-08-18 05:08 . 2011-06-17 16:16 451072 ----a-w- c:\windows\system32\winsrv.dll
2011-08-18 05:08 . 2011-07-06 15:49 275456 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-18 05:08 . 2011-06-17 20:14 1427344 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-18 05:08 . 2011-06-20 08:45 4699536 ----a-w- c:\windows\system32\ntoskrnl.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-04 05:23 . 2011-08-04 05:23 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-08-04 05:23 . 2011-08-04 05:23 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-08-04 05:23 . 2011-08-04 05:23 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-08-04 05:23 . 2011-08-04 05:23 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-08-04 05:23 . 2011-08-04 05:23 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-08-04 05:23 . 2011-08-04 05:23 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-08-04 05:23 . 2011-08-04 05:23 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-08-04 05:23 . 2011-08-04 05:23 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-08-04 05:23 . 2011-08-04 05:23 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-08-04 05:23 . 2011-08-04 05:23 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-08-04 05:23 . 2011-08-04 05:23 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-08-04 05:23 . 2011-08-04 05:23 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-08-04 05:23 . 2011-08-04 05:23 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-08-04 05:23 . 2011-08-04 05:23 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-08-04 05:23 . 2011-08-04 05:23 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-08-04 05:23 . 2011-08-04 05:23 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-08-04 05:23 . 2011-08-04 05:23 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-08-04 05:23 . 2011-08-04 05:23 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-08-04 05:23 . 2011-08-04 05:23 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-08-04 05:23 . 2011-08-04 05:23 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-08-04 05:23 . 2011-08-04 05:23 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-08-04 05:23 . 2011-08-04 05:23 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-08-04 05:23 . 2011-08-04 05:23 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-08-04 05:23 . 2011-08-04 05:23 448512 ----a-w- c:\windows\system32\html.iec
2011-08-04 05:23 . 2011-08-04 05:23 222208 ----a-w- c:\windows\system32\msls31.dll
2011-08-04 05:23 . 2011-08-04 05:23 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-08-04 05:23 . 2011-08-04 05:23 12288 ----a-w- c:\windows\system32\mshta.exe
2011-08-04 05:23 . 2011-08-04 05:23 114176 ----a-w- c:\windows\system32\admparse.dll
2011-08-04 05:23 . 2011-08-04 05:23 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-08-04 05:23 . 2011-08-04 05:23 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-08-04 05:23 . 2011-08-04 05:23 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-08-04 05:23 . 2011-08-04 05:23 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-04 05:23 . 2011-08-04 05:23 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-08-04 05:23 . 2011-08-04 05:23 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-08-04 05:23 . 2011-08-04 05:23 160256 ----a-w- c:\windows\system32\wextract.exe
2011-08-04 05:23 . 2011-08-04 05:23 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-07-27 04:53 . 2011-07-24 02:57 246272 ----a-w- c:\windows\unrar.exe
2011-07-13 04:53 . 2011-08-03 23:55 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{15B09B15-09A7-4798-8906-2E12C2896F82}\mpengine.dll
2011-07-06 23:52 . 2011-02-21 00:14 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-06 23:52 . 2011-02-21 00:14 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-21 01:42 . 2011-05-26 15:06 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-06-14 01:34 . 2009-10-14 07:30 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2011-06-14 01:34 . 2009-01-08 07:43 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-09-08_00.48.58 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-21 03:20 . 2011-09-08 00:49 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-01-21 03:20 . 2011-09-09 14:57 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-01-21 03:20 . 2011-09-09 14:57 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-01-21 03:20 . 2011-09-08 00:49 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-01-21 03:20 . 2011-09-08 00:49 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-01-21 03:20 . 2011-09-09 14:57 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-01-21 02:23 . 2011-09-09 14:58 73038 c:\windows\system32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 15:45 . 2011-09-09 14:58 85832 c:\windows\system32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-09-08 07:29 . 2011-09-09 14:58 18088 c:\windows\system32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3484157149-2296695972-584191382-1000_UserData.bin
+ 2009-12-03 13:27 . 2009-12-03 13:27 74272 c:\windows\system32\RtNicProp64.dll
+ 2009-12-03 13:27 . 2009-12-03 13:27 74272 c:\windows\system32\DriverStore\FileRepository\netrtx64.inf_5681466c\RtNicProp64.dll
- 2009-09-08 07:26 . 2011-08-04 14:47 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-09-08 07:26 . 2011-09-08 19:40 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-09-08 07:26 . 2011-08-04 14:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-09-08 19:40 . 2011-09-08 19:40 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-09-08 07:26 . 2011-09-08 19:40 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-09-08 07:26 . 2011-08-04 14:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-09-08 20:05 . 2011-09-08 20:05 22016 c:\windows\Installer\13f5f7a.msi
+ 2006-11-02 12:40 . 2011-09-08 22:13 86016 c:\windows\inf\infstor.dat
- 2006-11-02 12:40 . 2011-07-14 07:19 86016 c:\windows\inf\infstor.dat
+ 2006-11-02 12:40 . 2011-09-08 22:13 51200 c:\windows\inf\infpub.dat
- 2006-11-02 12:40 . 2011-07-14 07:19 51200 c:\windows\inf\infpub.dat
+ 2011-09-08 22:50 . 2011-09-08 22:50 42496 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Pres#\357c754688a5756ac7fc4fc831ffbf03\System.Windows.Presentation.ni.dll
+ 2011-09-08 22:50 . 2011-09-08 22:50 86016 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Applicat#\f7738bf2ff3dc492be82f64880dcfc4c\System.Web.ApplicationServices.ni.dll
+ 2011-09-08 22:54 . 2011-09-08 22:54 35328 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Pres#\b25f69257705a10c95b7b3189e2fc390\System.Windows.Presentation.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 71680 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Applicat#\c43c3b0a5d254895dd63c46bad2f23c0\System.Web.ApplicationServices.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 82432 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\a1fdc3ccb352a4ad6ee0efa0eaee40fb\System.ServiceModel.Channels.ni.dll
+ 2009-10-23 21:33 . 2011-09-08 00:59 1580 c:\windows\system32\WDI\ERCQueuedResolutions.dat
+ 2011-09-09 14:56 . 2011-09-09 14:56 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-09-08 00:48 . 2011-09-08 00:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-09-09 14:56 . 2011-09-09 14:56 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-09-08 00:48 . 2011-09-08 00:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-09-08 14:13 . 2011-09-08 14:13 157472 c:\windows\SysWOW64\javaws.exe
+ 2011-09-08 14:13 . 2011-09-08 14:13 145184 c:\windows\SysWOW64\javaw.exe
+ 2011-09-08 14:13 . 2011-09-08 14:13 145184 c:\windows\SysWOW64\java.exe
+ 2010-01-05 20:39 . 2010-01-05 20:39 107552 c:\windows\system32\RTNUninst64.dll
- 2006-11-02 12:46 . 2011-09-08 00:31 607406 c:\windows\system32\perfh009.dat
+ 2006-11-02 12:46 . 2011-09-08 22:12 607406 c:\windows\system32\perfh009.dat
- 2006-11-02 12:46 . 2011-09-08 00:31 105014 c:\windows\system32\perfc009.dat
+ 2006-11-02 12:46 . 2011-09-08 22:12 105014 c:\windows\system32\perfc009.dat
+ 2010-01-05 20:39 . 2010-01-05 20:39 107552 c:\windows\system32\DriverStore\FileRepository\netrtx64.inf_5681466c\RTNUninst64.dll
+ 2010-06-23 13:21 . 2010-06-23 13:21 318568 c:\windows\system32\DriverStore\FileRepository\netrtx64.inf_5681466c\Rtlh64.sys
+ 2010-06-23 13:21 . 2010-06-23 13:21 318568 c:\windows\system32\drivers\Rtlh64.sys
+ 2010-10-29 07:16 . 2011-09-09 14:55 391484 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2010-10-29 07:16 . 2011-09-08 00:47 391484 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-10-29 07:16 . 2011-09-08 21:44 780316 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3484157149-2296695972-584191382-1000-8192.dat
+ 2011-09-08 21:21 . 2011-09-08 21:21 392252 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3484157149-2296695972-584191382-1000-4096.dat
+ 2011-09-08 14:14 . 2011-09-08 14:14 203776 c:\windows\Installer\2d1b930.msi
+ 2011-09-08 14:13 . 2011-09-08 14:13 901120 c:\windows\Installer\2d1b92b.msi
- 2006-11-02 12:40 . 2011-07-14 07:19 143360 c:\windows\inf\infstrng.dat
+ 2006-11-02 12:40 . 2011-09-08 22:13 143360 c:\windows\inf\infstrng.dat
+ 2011-09-08 22:50 . 2011-09-08 22:50 322048 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsFormsIntegra#\6c332f5c8c795f7e5415d94bf1d68b0b\WindowsFormsIntegration.ni.dll
+ 2011-09-08 22:50 . 2011-09-08 22:50 645120 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClient\0b326be8df8a20d09e9eb8e827c7258c\UIAutomationClient.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 525824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Linq\c767821a3004226d67edf155d5737083\System.Xml.Linq.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 254976 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Inpu#\a7fe785edf8113c49b5fa6adcb537408\System.Windows.Input.Manipulations.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 903168 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Transactions\0cad532e2fb59585cc790c3fe656e64f\System.Transactions.ni.dll
+ 2011-09-08 22:50 . 2011-09-08 22:50 280576 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceProce#\ee501cc4420ce53f2ded79b3ad798c90\System.ServiceProcess.ni.dll
+ 2011-09-08 22:50 . 2011-09-08 22:50 107520 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\e3cbf844da8dbc1190d37abc30570e29\System.ServiceModel.Channels.ni.dll
+ 2011-09-08 22:50 . 2011-09-08 22:50 507904 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\4b2c5b2baad543993991af8e6e347964\System.ServiceModel.Routing.ni.dll
+ 2011-09-08 22:44 . 2011-09-08 22:44 939520 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Security\bd4e7dba4c1d18de2bb92f050691f714\System.Security.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 987648 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Remo#\3ae7f226fe2de56b8a1417d52ed51029\System.Runtime.Remoting.ni.dll
+ 2011-09-08 22:49 . 2011-09-08 22:49 930304 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Net\41d449b0be8ff6b6dc9174313db88459\System.Net.ni.dll
+ 2011-09-08 22:49 . 2011-09-08 22:49 781824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Messaging\f8aa02fc7b4467081e19e35a5601f518\System.Messaging.ni.dll
+ 2011-09-08 22:49 . 2011-09-08 22:49 521728 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Management.I#\4fc188ed573c4a57a0287938986f6a1c\System.Management.Instrumentation.ni.dll
+ 2011-09-08 22:49 . 2011-09-08 22:49 531456 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IO.Log\0cca1aa68edcb1f5ee92fc8aaa2c7d51\System.IO.Log.ni.dll
+ 2011-09-08 22:49 . 2011-09-08 22:49 290816 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IdentityMode#\80d06aff25a9994a00f2976a1cb06733\System.IdentityModel.Selectors.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 348672 c:\windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\df0ac9043e9b88bcafa5b378994d8365\System.EnterpriseServices.Wrapper.dll
+ 2011-09-08 22:44 . 2011-09-08 22:44 511488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Dynamic\ce5254e2408f77d6a09d30508f8dd52a\System.Dynamic.ni.dll
+ 2011-09-08 22:49 . 2011-09-08 22:49 628736 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\6048f7c3071c23536b976d262c34fae1\System.DirectoryServices.Protocols.ni.dll
+ 2011-09-08 22:49 . 2011-09-08 22:49 141824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Device\80d5d1a7442173fc59c419b8d1c647ff\System.Device.ni.dll
+ 2011-09-08 22:48 . 2011-09-08 22:48 176128 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.DataSet#\33038b29c486ff870f23a6b37e5b9d11\System.Data.DataSetExtensions.ni.dll
+ 2011-09-08 22:48 . 2011-09-08 22:48 181248 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuratio#\c509822f920d2613ab999e6148ab8099\System.Configuration.Install.ni.dll
+ 2011-09-08 22:47 . 2011-09-08 22:47 255488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\e0dc7e5bc5e66268387e19c10727a030\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-09-08 22:47 . 2011-09-08 22:47 865792 c:\windows\assembly\NativeImages_v4.0.30319_64\System.AddIn\55d507e7cc2017d6eed82527df1e910a\System.AddIn.ni.dll
+ 2011-09-08 22:47 . 2011-09-08 22:47 553472 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.D#\0a65293a0732eaeb538fb5d9accafe92\System.Activities.DurableInstancing.ni.dll
+ 2011-09-08 22:43 . 2011-09-08 22:43 430080 c:\windows\assembly\NativeImages_v4.0.30319_64\SMSvcHost\7597686f1c999b6491518ff47508acdf\SMSvcHost.ni.exe
+ 2011-09-08 22:46 . 2011-09-08 22:46 184832 c:\windows\assembly\NativeImages_v4.0.30319_64\SMDiagnostics\53d186939a3367ce3b37c84464370ca6\SMDiagnostics.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 387584 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\eb1dae468677366538f99b623e7a7018\PresentationFramework.Royale.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 745984 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\1e80fa78c14d8cac7feaa1d70ffb0a38\PresentationFramework.Luna.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 331264 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\196d1a63ee35811bd9ce868bc70273a7\PresentationFramework.Classic.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 555520 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\039366972f5ad8f34025c5aed57c1929\PresentationFramework.Aero.ni.dll
+ 2011-09-08 22:44 . 2011-09-08 22:44 421888 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\cd5602c2be34ac18dcedad7409340a73\Microsoft.VisualBasic.Compatibility.Data.ni.dll
+ 2011-09-08 22:44 . 2011-09-08 22:44 600064 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\85e60ede22b298d7e5fcc17757f74ef1\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-09-08 22:54 . 2011-09-08 22:54 252416 c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsFormsIntegra#\6472eef5098d682d9fe1ba988f0e2a16\WindowsFormsIntegration.ni.dll
+ 2011-09-08 22:54 . 2011-09-08 22:54 482816 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClient\30c40325e5863915a93fdbc61888017e\UIAutomationClient.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 391680 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\21077827f11f2b5473a075c2cfe52869\System.Xml.Linq.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 188928 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Inpu#\fd14fbfb1b15903bf9fb8b712e497117\System.Windows.Input.Manipulations.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 646656 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\35088dcea3449dd518738b606bd9a150\System.Transactions.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 221696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\e5e480c7ee8c4e0e0a08bb9d809da311\System.ServiceProcess.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 365056 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\e6c0820211b8ef81c6273f1e2159662b\System.ServiceModel.Routing.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 729088 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Security\f0273f74592371ee808687bbe3b47c96\System.Security.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 762368 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\d1da56a093b968d79f7ab3fb10a9b9ca\System.Runtime.Remoting.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 653312 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Net\6a64161b2b9795a2db7404b1c4594a1f\System.Net.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 626176 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Messaging\db4a2bdca79d189d8d4a5beaf5798eff\System.Messaging.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 395264 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management.I#\da1301f9af8b84875439449d68ed6488\System.Management.Instrumentation.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 413696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IO.Log\cf5e78d682f36ee0cf243c9c0086d9c4\System.IO.Log.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 229376 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityMode#\2322a873c1b039804c0606c71852d192\System.IdentityModel.Selectors.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 236032 c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\535974de0ac28f073025a0d2cfae1568\System.EnterpriseServices.Wrapper.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 786944 c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\535974de0ac28f073025a0d2cfae1568\System.EnterpriseServices.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 377344 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Dynamic\e208a029639dec267bb888366feba173\System.Dynamic.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 913920 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\0c37a3bc52d0a8fb2343f912da4a49a6\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 468992 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\062b6ae9f82eb189eb383c26d0a40996\System.DirectoryServices.Protocols.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 112640 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Device\d325ed56b35d4745619121ae9293bf07\System.Device.ni.dll
+ 2011-09-08 22:52 . 2011-09-08 22:52 134656 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.DataSet#\544584967fdc7025f6a4506696110493\System.Data.DataSetExtensions.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 980480 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\adeec723413d77446d6606813c050048\System.Configuration.ni.dll
+ 2011-09-08 22:52 . 2011-09-08 22:52 148480 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuratio#\acd1a7754df6d47b53df162dfe63de92\System.Configuration.Install.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 690176 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\17aff9c2c94f82753e669acc12631cfb\System.ComponentModel.Composition.ni.dll
+ 2011-09-08 22:52 . 2011-09-08 22:52 194048 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\0f2c28024362223e2f9d3666bacdae54\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-09-08 22:52 . 2011-09-08 22:52 617984 c:\windows\assembly\NativeImages_v4.0.30319_32\System.AddIn\9c18864a019ded007f212239f6b5a37a\System.AddIn.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 404992 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.D#\736a509c3674fdfd018ae4530d12397a\System.Activities.DurableInstancing.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 317952 c:\windows\assembly\NativeImages_v4.0.30319_32\SMSvcHost\227ebd4817d958e0ccb2234fd8dfc9ce\SMSvcHost.ni.exe
+ 2011-09-08 22:51 . 2011-09-08 22:51 142848 c:\windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\04375632f6906bd95e87c5d85b31e2a6\SMDiagnostics.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 656896 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\b2449fe3db220f6110d76287246caaf6\PresentationFramework.Luna.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 327680 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\814807b505a3f318fbd225ac41897a3f\PresentationFramework.Royale.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 284160 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\63a4e0d2a3a83df23a2d120127e9312f\PresentationFramework.Classic.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 450560 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\404f0d161b7bfc2c1ef9a4b47c37bfa8\PresentationFramework.Aero.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 302592 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\852401258217bcde129d29d7c15d0162\Microsoft.VisualBasic.Compatibility.Data.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 418816 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\982b28a3e0a3f8818f893a3331d9f0bd\Microsoft.Transactions.Bridge.Dtc.ni.dll
- 2009-06-16 23:52 . 2011-09-08 00:47 2309048 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-06-16 23:52 . 2011-09-09 14:55 2309048 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2011-08-04 15:35 . 2011-09-07 18:48 1587092 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3484157149-2296695972-584191382-1000-12288.dat
+ 2011-08-04 15:35 . 2011-09-08 21:21 1587092 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3484157149-2296695972-584191382-1000-12288.dat
+ 2011-04-28 12:48 . 2011-04-28 12:48 3510600 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.dll
- 2011-03-23 02:01 . 2011-03-23 02:01 3510600 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.dll
+ 2011-04-28 12:48 . 2011-04-28 12:48 3510600 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.dll
- 2011-03-23 02:01 . 2011-03-23 02:01 3510600 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.dll
+ 2011-04-28 13:57 . 2011-04-28 13:57 2721280 c:\windows\Installer\9fa7b.msp
+ 2011-09-08 22:44 . 2011-09-08 22:44 5176320 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsBase\5202133e255ce05947b8afe895e3f76f\WindowsBase.ni.dll
+ 2011-09-08 22:50 . 2011-09-08 22:50 1430016 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClients#\a9bf6deb79fd9d2b2541a950ab75a70f\UIAutomationClientsideProviders.ni.dll
+ 2011-09-08 22:44 . 2011-09-08 22:44 7038976 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml\1ac4e05bc3b2813ddadb59ba9f0fd961\System.Xml.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 2447360 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xaml\37ecfcc3de7bdc36ba1c3dfb7ee6a6d5\System.Xaml.ni.dll
+ 2011-09-08 22:50 . 2011-09-08 22:50 5627392 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\66beb5e0938298c2812c188925644c94\System.Windows.Forms.DataVisualization.ni.dll
+ 2011-09-08 22:50 . 2011-09-08 22:50 2222592 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services\3b31367a53da33699ed7f053f1157593\System.Web.Services.ni.dll
+ 2011-09-08 22:50 . 2011-09-08 22:50 2733568 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Speech\23e8fddabb602c3efb1e0a66f37fab2f\System.Speech.ni.dll
+ 2011-09-08 22:50 . 2011-09-08 22:50 1561600 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\713b393e8d7075bd1a3683f9e6f6b268\System.ServiceModel.Discovery.ni.dll
+ 2011-09-08 22:50 . 2011-09-08 22:50 1904640 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\49d303c42b9b694447a3ba6e2a1548cf\System.ServiceModel.Activities.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 3404288 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\6c1acbeb3e61475007b5d20745cad8e8\System.Runtime.Serialization.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 1346560 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Dura#\12d17462d5e3ba196e299bb0f1f0b20d\System.Runtime.DurableInstancing.ni.dll
+ 2011-09-08 22:47 . 2011-09-08 22:47 1422336 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Printing\ed79f8685b97f5520a3169860c8df9f8\System.Printing.ni.dll
+ 2011-09-08 22:49 . 2011-09-08 22:49 1470464 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Management\58696f56812c7ea9dc5fde8baa3a4b2a\System.Management.ni.dll
+ 2011-09-08 22:49 . 2011-09-08 22:49 1416192 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IdentityModel\ad8f2f562edccb394180c80e54ddfb21\System.IdentityModel.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 1096704 c:\windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\df0ac9043e9b88bcafa5b378994d8365\System.EnterpriseServices.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 2290688 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\058e1143c689861be149cf7c1fcf597a\System.Drawing.ni.dll
+ 2011-09-08 22:49 . 2011-09-08 22:49 1217024 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\eb5e94ddc12db438063a90394e46f070\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 1622016 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\0cf67c3a77fd159d0af43d16663b1a65\System.DirectoryServices.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 2400256 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Deployment\39ccef129f4a96c17b6406678d53c87b\System.Deployment.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 8580608 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data\fc45ad58e3a025051ededa0efbae404f\System.Data.ni.dll
+ 2011-09-08 22:44 . 2011-09-08 22:44 3386880 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.SqlXml\ed5027c747ed64957ac313befd47e345\System.Data.SqlXml.ni.dll
+ 2011-09-08 22:49 . 2011-09-08 22:49 1791488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\c6f24f3171576104e80b12c4f4254ed2\System.Data.Services.Client.ni.dll
+ 2011-09-08 22:49 . 2011-09-08 22:49 3380736 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Linq\5f31190f3c1a0ec0518782618b804517\System.Data.Linq.ni.dll
+ 2011-09-08 22:44 . 2011-09-08 22:44 1255424 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\fcf22c02eb60f8d045daa4386bb604f3\System.Configuration.ni.dll
+ 2011-09-08 22:47 . 2011-09-08 22:47 1002496 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\6f848e806caa9545c09866dd0950d853\System.ComponentModel.Composition.ni.dll
+ 2011-09-08 22:47 . 2011-09-08 22:47 5680640 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities\c073f492e366b50d599e8f1447579946\System.Activities.ni.dll
+ 2011-09-08 22:47 . 2011-09-08 22:47 4887040 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.P#\6f2faf3f19358776373922b510603a8f\System.Activities.Presentation.ni.dll
+ 2011-09-08 22:47 . 2011-09-08 22:47 2005504 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.C#\9a2609f428f731670b3a730cb3f88dd4\System.Activities.Core.Presentation.ni.dll
+ 2011-09-08 22:47 . 2011-09-08 22:47 4127232 c:\windows\assembly\NativeImages_v4.0.30319_64\ReachFramework\dbe098606014df542c37b96962fd8717\ReachFramework.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 2032128 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationUI\00416e9efbc68509f113692996b45e75\PresentationUI.ni.dll
+ 2011-09-08 22:44 . 2011-09-08 22:44 2314752 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\d83a6fc3a6bd96beaa9845201290f292\Microsoft.VisualBasic.ni.dll
+ 2011-09-08 22:44 . 2011-09-08 22:44 1622528 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\c386ff5a7c5bfa6b1dfdc6f53119b3a6\Microsoft.VisualBasic.Activities.Compiler.ni.dll
+ 2011-09-08 22:44 . 2011-09-08 22:44 1843200 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\36347f2a750bf1af184da9b6783a376c\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2011-09-08 22:44 . 2011-09-08 22:44 1510400 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\e174701b531de21d8a96ea8ea5975000\Microsoft.Transactions.Bridge.ni.dll
+ 2011-09-08 22:49 . 2011-09-08 22:49 3312128 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.JScript\9f986e23b6ecb48281324d51fdb6e799\Microsoft.JScript.ni.dll
+ 2011-09-08 22:44 . 2011-09-08 22:44 2009088 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.CSharp\5046c55b7feb9c9156d18fe1d4735480\Microsoft.CSharp.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 3798016 c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\34f85cc53f8487a29fcaf90c9efd93b2\WindowsBase.ni.dll
+ 2011-09-08 22:54 . 2011-09-08 22:54 1057792 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClients#\7589c9739d52787b05c68a143d20dcee\UIAutomationClientsideProviders.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 9085952 c:\windows\assembly\NativeImages_v4.0.30319_32\System\b13a0678a604588bfb6a4ebfadc32cb0\System.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 5618176 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml\bbcb0d5e67db5452b3ba77fd71ea182d\System.Xml.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 1781760 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\3aa498d229252ab540482ccecaab8f85\System.Xaml.ni.dll
+ 2011-09-08 22:54 . 2011-09-08 22:54 4545024 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form#\4742ebf18e4d1f9f6a464afb3f2e884d\System.Windows.Forms.DataVisualization.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 1859584 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\374d8a7604c668bf76fbf3ba05e61f35\System.Web.Services.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 2011136 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Speech\36b38adc49360fcc35892ab7fb15c9d8\System.Speech.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 1128960 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\e2abacbaf2e4786339eba541d3d5596c\System.ServiceModel.Discovery.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 1387520 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\0f9b303dde68998490e8b5be32c6147a\System.ServiceModel.Activities.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 2637312 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\020ccbaa78022e92722e98d1c677bfed\System.Runtime.Serialization.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 1020928 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\65c22515c57fbe4a3c3a6382986d7192\System.Runtime.DurableInstancing.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 1050112 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Printing\16fb985d0651d7c5d25aa06de7921eee\System.Printing.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 1218560 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management\2c94c3a30c2464d14c3edb1ef5ad9c18\System.Management.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 1072128 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\0d26f913a3620a32aac1bf34e380ede0\System.IdentityModel.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 1652736 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\8c3b1fb3982b305452a4c7c8cdcb1934\System.Drawing.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 1172992 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\9e98b2fb9d6c6bfd22331a3612e1ae77\System.DirectoryServices.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 1878016 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Deployment\738bd15095d25b3df67f7574274e3480\System.Deployment.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 6798336 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data\a2191137e48d026aafbd8395d767afa1\System.Data.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 2545152 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.SqlXml\921f450dafcc9c118240bdc111f85c7b\System.Data.SqlXml.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 1338880 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\392366875f6c71fdd16e1db79062ebb1\System.Data.Services.Client.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 2512384 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\12d1f89d64401ab14f15e3e5e4ddf966\System.Data.Linq.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 7054336 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Core\2adac0cd51859321437cc684331a3b45\System.Core.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 4121088 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities\9bbcd5e6d245a8b7799b5425b2b2b302\System.Activities.ni.dll
+ 2011-09-08 22:52 . 2011-09-08 22:52 3713024 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.P#\276bef59e43e2fa5b005d47b1a898d80\System.Activities.Presentation.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 1518080 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.C#\2899fc096074503091d61f6744c11845\System.Activities.Core.Presentation.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 2859008 c:\windows\assembly\NativeImages_v4.0.30319_32\ReachFramework\56e13dd851c3818cad1ae86777baedda\ReachFramework.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 1630208 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationUI\5e48f32fa425c2e822776c54d4a98093\PresentationUI.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 1139200 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\a75299879ae349d917320df0d68e6e2b\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 1172480 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\5753643b5768a762ff52c1a3e86437a8\Microsoft.VisualBasic.Activities.Compiler.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 1836544 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\3a35d8c95c2a851e1175cc02d3ad3e50\Microsoft.VisualBasic.ni.dll
+ 2011-09-08 22:51 . 2011-09-08 22:51 1082368 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\ba6e30d4928b782b24606e333d72e9bd\Microsoft.Transactions.Bridge.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 2452480 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.JScript\6fb9478d3774d431ccd29f7524446f18\Microsoft.JScript.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 1616384 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.CSharp\7c28712cdf88f58930538dcc2f342a78\Microsoft.CSharp.ni.dll
+ 2006-11-02 12:33 . 2011-09-08 21:21 11010048 c:\windows\system32\SMI\Store\Machine\schema.dat
- 2006-11-02 12:33 . 2011-09-01 19:33 11010048 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2011-09-08 21:37 . 2011-09-08 21:37 11872768 c:\windows\assembly\NativeImages_v4.0.30319_64\System\e033094f5df23aa619519b537eb14448\System.ni.dll
+ 2011-09-08 22:47 . 2011-09-08 22:47 17288192 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\e0091eb98fa841649b6fad17bb0e7262\System.Windows.Forms.ni.dll
+ 2011-09-08 22:50 . 2011-09-08 22:50 24483840 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel\a73197785f07721fd89b02713b6f0b86\System.ServiceModel.ni.dll
+ 2011-09-08 22:48 . 2011-09-08 22:48 18434048 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Entity\fe4d47d9ba672ae77c737bb7ad518324\System.Data.Entity.ni.dll
+ 2011-09-08 22:43 . 2011-09-08 22:43 10422272 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Core\4ef06cf2c3950f4d4b9037b841c05914\System.Core.ni.dll
+ 2011-09-08 22:46 . 2011-09-08 22:46 23242240 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\9b38883339d48793df2b27d247e73971\PresentationFramework.ni.dll
+ 2011-09-08 22:45 . 2011-09-08 22:45 15102976 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationCore\7b4a4ec0cae68a2c165b0a73be99105d\PresentationCore.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 13137920 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\f72ff4e603cc8879eb7b18841bfa9c0c\System.Windows.Forms.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 17996800 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\af95bce9a5fcfe3119fc175cc9b0b3d5\System.ServiceModel.ni.dll
+ 2011-09-08 22:53 . 2011-09-08 22:53 13325312 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity\ce6c51d21159048033141cfc37c74aa2\System.Data.Entity.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 17671168 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\1be95cb0b36c0cc1a0b13d20387e0bcc\PresentationFramework.ni.dll
+ 2011-09-08 21:38 . 2011-09-08 21:38 11106816 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\957a34ba01f489cf306bd9aeffcbf67b\PresentationCore.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files (x86)\Real\realplayer\update\realsched.exe" [2011-06-14 273544]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RkHit.sys]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"DisableThumbnailCache"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate1ca4a03d9039b50;Google Update Service (gupdate1ca4a03d9039b50);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-10-10 133104]
R3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-10-10 133104]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 camsvc;TOSHIBA Web Camera Service;c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe [2009-04-17 20544]
S2 ConfigFree Gadget Service;ConfigFree Gadget Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe [2009-03-07 36864]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448]
S2 RSELSVC;TOSHIBA Modem region select service;c:\program files\TOSHIBA\rselect\RSelSvc.exe [2009-02-19 55808]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-04-15 251392]
S2 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-03-17 84480]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x]
S3 NETw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\NETw5v64.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-10-10 23:46]
.
2011-09-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-10-10 23:46]
.
.
--------- x86-64 -----------
.
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.254
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\program files (x86)\Panda USB Vaccine\USBVaccine.exe
.
**************************************************************************
.
Completion time: 2011-09-09 11:03:25 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-09 15:03
ComboFix2.txt 2011-09-08 00:54
.
Pre-Run: 190,479,319,040 bytes free
Post-Run: 190,674,128,896 bytes free
.
- - End Of File - - E801A0D054EF785F03981AE3BD5DB652
OTL
When we use OTL and we paste a fix, will pressing scan alone do a scan and also do the fix that was pasted? I pasted the stuff you told me to, and hit scan, but I'm not sure if it did anything with the "fix" that we pasted. Anyways, the log is below of when the scan was done.
OTL logfile created on: 9/9/2011 11:05:55 AM - Run 4
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Users\patrick\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.87 Gb Total Physical Memory | 2.36 Gb Available Physical Memory | 60.90% Memory free
7.92 Gb Paging File | 6.36 Gb Available in Paging File | 80.38% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 286.58 Gb Total Space | 177.62 Gb Free Space | 61.98% Space Free | Partition Type: NTFS
Drive F: | 1.86 Gb Total Space | 1.80 Gb Free Space | 96.52% Space Free | Partition Type: FAT32
Computer Name: PATRICK-PC | User Name: patrick | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/09/07 01:54:50 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\patrick\Desktop\OTL.exe
PRC - [2011/06/13 21:34:37 | 000,273,544 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\realplayer\Update\realsched.exe
PRC - [2011/01/13 03:47:33 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2009/09/23 16:45:50 | 001,287,176 | ---- | M] (Panda Security) -- C:\Program Files (x86)\Panda USB Vaccine\USBVaccine.exe
PRC - [2009/04/16 21:42:58 | 000,020,544 | ---- | M] (TOSHIBA) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
PRC - [2009/03/30 19:57:22 | 000,083,312 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
PRC - [2009/03/10 21:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2009/03/06 20:27:10 | 000,036,864 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
========== Modules (No Company Name) ========== ========== Win32 Services (SafeList) ========== SRV:
64bit: - [2011/01/13 03:47:33 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV:
64bit: - [2009/04/14 20:57:28 | 000,251,392 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\TECO\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV:
64bit: - [2009/03/17 14:48:54 | 000,084,480 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV:
64bit: - [2009/03/06 21:30:32 | 000,488,288 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV:
64bit: - [2009/02/19 17:53:28 | 000,055,808 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\rselect\RSelSvc.exe -- (RSELSVC)
SRV:
64bit: - [2008/10/16 21:05:00 | 001,449,984 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:
64bit: - [2008/10/16 20:27:20 | 000,826,368 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:
64bit: - [2008/03/18 15:26:56 | 000,015,872 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\SysNative\agr64svc.exe -- (AgereModemAudio)
SRV:
64bit: - [2007/11/21 19:53:16 | 000,135,168 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\SysNative\TODDSrv.exe -- (TODDSrv)
SRV - [2010/07/28 17:36:52 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/04/16 21:42:58 | 000,020,544 | ---- | M] (TOSHIBA) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe -- (camsvc)
SRV - [2009/03/30 19:57:22 | 000,083,312 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe -- (TNaviSrv)
SRV - [2009/03/30 00:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/03/10 21:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2009/03/06 20:27:10 | 000,036,864 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe -- (ConfigFree Gadget Service)
SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
========== Driver Services (SafeList) ========== DRV:
64bit: - [2011/01/13 03:41:44 | 000,273,488 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:
64bit: - [2011/01/13 03:40:20 | 000,051,792 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:
64bit: - [2011/01/13 03:37:34 | 000,029,264 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr.sys -- (aswRdr)
DRV:
64bit: - [2011/01/13 03:37:23 | 000,062,032 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:
64bit: - [2011/01/13 03:37:12 | 000,020,560 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:
64bit: - [2010/09/23 00:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\fssfltr.sys -- (fssfltr)
DRV:
64bit: - [2010/06/23 09:21:34 | 000,318,568 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys -- (RTL8169)
DRV:
64bit: - [2009/03/18 14:46:44 | 000,032,832 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\pgeffect.sys -- (PGEffect)
DRV:
64bit: - [2009/03/18 13:20:08 | 000,265,776 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\SynTP.sys -- (SynTP)
DRV:
64bit: - [2009/03/11 19:35:48 | 000,071,168 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTSTOR64.SYS -- (RTSTOR)
DRV:
64bit: - [2009/03/03 15:14:24 | 008,040,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\igdkmd64.sys -- (igfx)
DRV:
64bit: - [2009/03/02 19:20:18 | 000,035,840 | R--- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BVRPMPR5a64.SYS -- (BVRPMPR5a64)
DRV:
64bit: - [2009/02/11 20:26:18 | 000,407,576 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\iaStor.sys -- (iaStor)
DRV:
64bit: - [2009/01/27 22:12:14 | 000,504,912 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\tos_sps64.sys -- (tos_sps64)
DRV:
64bit: - [2008/11/17 10:50:30 | 004,751,360 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\NETw5v64.sys -- (NETw5v64) Intel®
DRV:
64bit: - [2008/03/21 15:47:14 | 001,253,376 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\agrsm64.sys -- (AgereSoftModem)
DRV:
64bit: - [2007/12/11 17:03:36 | 000,027,272 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\tdcmdpst.sys -- (tdcmdpst)
DRV:
64bit: - [2007/11/09 17:00:30 | 000,026,968 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\TVALZ_O.SYS -- (TVALZ)
DRV:
64bit: - [2007/07/03 21:05:18 | 000,114,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\sscdserd.sys -- (sscdserd) SAMSUNG Mobile Modem Diagnostic Serial Port (WDM)
DRV:
64bit: - [2007/07/03 21:04:44 | 000,142,504 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\sscdmdm.sys -- (sscdmdm)
DRV:
64bit: - [2007/07/03 21:04:16 | 000,016,040 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\sscdmdfl.sys -- (sscdmdfl)
DRV:
64bit: - [2007/07/03 21:02:12 | 000,105,128 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV:
64bit: - [2006/11/20 01:11:06 | 000,008,704 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\FwLnk.sys -- (FwLnk)
DRV - [2003/07/30 05:02:00 | 000,047,872 | ---- | M] (Sonic Solutions) [Kernel | Boot | Stopped] -- C:\Windows\system32\DRIVERS\PxHelp64.sys -- (PxHelp64)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3484157149-2296695972-584191382-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-3484157149-2296695972-584191382-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP =
IE - HKU\S-1-5-21-3484157149-2296695972-584191382-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3484157149-2296695972-584191382-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.652: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.652: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.71\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.71\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/08/31 16:55:27 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2011/09/09 10:57:15 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKU\S-1-5-21-3484157149-2296695972-584191382-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-3484157149-2296695972-584191382-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3484157149-2296695972-584191382-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3484157149-2296695972-584191382-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000025 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000026 - File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - File not found
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset...lineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{25A69E9C-CD10-42B0-A99F-A0C2FBF785EC}: DhcpNameServer = 192.168.1.254
O18:
64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:
64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:
64bit: - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\patrick\Pictures\2009-11-04 Mixed\Mixed 133.JPG
O24 - Desktop BackupWallPaper: C:\Users\patrick\Pictures\2009-11-04 Mixed\Mixed 133.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/09/08 15:41:14 | 000,000,016 | -H-- | M] () - F:\AUTORUN.INF -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2011/09/09 11:03:28 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/09/09 11:03:27 | 000,000,000 | ---D | C] -- C:\Users\patrick\AppData\Local\temp
[2011/09/09 11:02:53 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/09/08 15:47:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2011/09/08 15:40:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Panda Security
[2011/09/08 15:40:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security
[2011/09/08 15:40:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Panda USB Vaccine
[2011/09/08 10:14:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2011/09/08 10:14:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2011/09/08 10:13:21 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll
[2011/09/08 10:13:21 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2011/09/08 10:13:21 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2011/09/08 10:13:21 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2011/09/08 10:13:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2011/09/07 20:58:00 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/09/07 20:57:01 | 000,581,120 | ---- | C] (OldTimer Tools) -- C:\Users\patrick\Desktop\OTL.exe
[2011/09/07 20:34:00 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/09/07 20:34:00 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/09/07 20:34:00 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/09/07 20:33:54 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/09/07 20:33:50 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/09/07 20:30:57 | 004,201,032 | R--- | C] (Swearware) -- C:\Users\patrick\Desktop\ComboFix.exe
[2011/09/07 20:30:52 | 000,000,000 | ---D | C] -- C:\Users\patrick\Desktop\tdsskiller
[2011/09/07 17:52:14 | 000,000,000 | ---D | C] -- C:\Users\patrick\Desktop\RK_Quarantine
[2011/09/06 23:59:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2011/09/06 23:59:37 | 000,273,488 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2011/09/06 23:59:37 | 000,020,560 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2011/09/06 23:59:36 | 000,029,264 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr.sys
[2011/09/06 23:59:35 | 000,062,032 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2011/09/06 23:59:35 | 000,051,792 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2011/09/06 23:59:24 | 000,038,848 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2011/09/06 23:59:23 | 000,188,216 | ---- | C] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2011/08/18 03:11:32 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2011/08/18 02:58:36 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011/08/18 02:58:36 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011/08/18 02:58:35 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011/08/18 02:58:35 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011/08/18 02:58:34 | 002,303,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2011/08/18 02:58:34 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011/08/18 02:58:34 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2011/08/18 02:58:34 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2011/08/18 02:58:33 | 000,818,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011/08/18 01:08:59 | 000,451,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2011/08/18 01:08:58 | 000,180,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xmllite.dll
[2011/08/18 01:08:48 | 004,699,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
========== Files - Modified Within 30 Days ========== [2011/09/09 11:03:05 | 000,707,392 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/09/09 11:03:05 | 000,607,406 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/09/09 11:03:05 | 000,105,014 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/09/09 10:57:15 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011/09/09 10:57:01 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/09/09 10:56:51 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/09 10:56:51 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/09 10:56:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/09/09 10:56:36 | 4156,542,976 | -HS- | M] () -- C:\hiberfil.sys
[2011/09/09 10:42:50 | 004,201,032 | R--- | M] (Swearware) -- C:\Users\patrick\Desktop\ComboFix.exe
[2011/09/09 10:10:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/08 10:13:12 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll
[2011/09/08 10:13:12 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2011/09/08 10:13:12 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2011/09/08 10:13:12 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2011/09/07 16:36:46 | 000,001,460 | ---- | M] () -- C:\Users\patrick\AppData\Local\d3d9caps64.dat
[2011/09/07 02:10:28 | 000,418,952 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/09/07 01:54:50 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\patrick\Desktop\OTL.exe
[2011/09/07 00:12:25 | 000,000,121 | ---- | M] () -- C:\Windows\wininit.ini
[2011/09/06 23:59:38 | 000,001,807 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011/09/06 23:59:35 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2011/09/05 12:05:38 | 000,002,036 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2011/08/18 02:31:31 | 952,948,500 | ---- | M] () -- C:\Windows\MEMORY.DMP
========== Files Created - No Company Name ========== [2011/09/07 20:34:00 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/09/07 20:34:00 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/09/07 20:34:00 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/09/07 20:34:00 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/09/07 20:34:00 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/09/07 19:35:24 | 4156,542,976 | -HS- | C] () -- C:\hiberfil.sys
[2011/09/07 00:12:25 | 000,000,121 | ---- | C] () -- C:\Windows\wininit.ini
[2011/09/06 23:59:38 | 000,001,807 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011/07/23 23:48:30 | 000,721,764 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/07/23 22:57:04 | 000,246,272 | ---- | C] () -- C:\Windows\unrar.exe
[2011/06/03 09:38:28 | 000,001,460 | ---- | C] () -- C:\Users\patrick\AppData\Local\d3d9caps64.dat
[2011/02/13 02:23:58 | 000,000,680 | ---- | C] () -- C:\Users\patrick\AppData\Local\d3d9caps.dat
[2010/08/05 13:40:14 | 000,004,096 | -H-- | C] () -- C:\Users\patrick\AppData\Local\keyfile3.drm
[2009/12/14 20:14:33 | 000,222,552 | ---- | C] () -- C:\Windows\RM.exe
[2009/12/14 19:52:26 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2009/12/14 17:28:02 | 000,000,000 | ---- | C] () -- C:\Users\patrick\AppData\Roaming\wklnhst.dat
[2009/12/03 22:36:55 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2009/12/03 22:36:24 | 000,107,612 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009/12/03 22:35:57 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/10/11 04:30:37 | 000,017,043 | ---- | C] () -- C:\Users\patrick\AppData\Roaming\UserTile.png
[2009/09/28 17:36:05 | 000,005,632 | ---- | C] () -- C:\Users\patrick\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/28 16:25:53 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/09/08 03:28:20 | 000,000,013 | RHS- | C] () -- C:\Windows\SysWow64\drivers\fbd.sys
[2009/06/16 20:23:35 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2009/05/03 03:00:45 | 000,209,040 | ---- | C] () -- C:\Windows\SysWow64\IVIresizeW7.dll
[2009/05/03 03:00:45 | 000,196,752 | ---- | C] () -- C:\Windows\SysWow64\IVIresizeP6.dll
[2009/05/03 03:00:45 | 000,192,656 | ---- | C] () -- C:\Windows\SysWow64\IVIresizePX.dll
[2009/05/03 03:00:44 | 000,204,944 | ---- | C] () -- C:\Windows\SysWow64\IVIresizeA6.dll
[2009/05/03 03:00:44 | 000,196,752 | ---- | C] () -- C:\Windows\SysWow64\IVIresizeM6.dll
[2009/05/03 03:00:44 | 000,024,720 | ---- | C] () -- C:\Windows\SysWow64\IVIresize.dll
[2009/05/03 01:26:27 | 000,018,904 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2009/03/03 15:12:44 | 000,445,796 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin
[2009/03/03 15:12:44 | 000,147,172 | ---- | C] () -- C:\Windows\SysWow64\igfcg550.bin
[2009/03/03 15:12:42 | 002,026,604 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin
[2008/01/20 22:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2006/11/02 11:37:05 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 08:37:14 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2006/11/02 08:24:17 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 08:18:17 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2006/11/02 05:47:54 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2003/07/31 10:09:30 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\px.ini
[2003/01/07 19:05:08 | 000,002,695 | ---- | C] () -- C:\Windows\SysWow64\OUTLPERF.INI
[2002/05/24 04:00:00 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\lockout.dll
[2002/05/24 04:00:00 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\lockres.dll
========== LOP Check ========== [2011/01/20 04:18:48 | 000,000,000 | ---D | M] -- C:\Users\patrick\AppData\Roaming\CometPlayer
[2010/08/04 22:22:42 | 000,000,000 | ---D | M] -- C:\Users\patrick\AppData\Roaming\iWin
[2009/09/13 04:28:22 | 000,000,000 | ---D | M] -- C:\Users\patrick\AppData\Roaming\Leadertech
[2011/08/05 20:18:51 | 000,000,000 | ---D | M] -- C:\Users\patrick\AppData\Roaming\mjusbsp
[2010/10/12 21:43:23 | 000,000,000 | ---D | M] -- C:\Users\patrick\AppData\Roaming\PDF Viewer
[2009/12/14 20:24:57 | 000,000,000 | ---D | M] -- C:\Users\patrick\AppData\Roaming\Smith Micro
[2011/03/25 20:10:39 | 000,000,000 | ---D | M] -- C:\Users\patrick\AppData\Roaming\TeamViewer
[2009/12/14 17:28:05 | 000,000,000 | ---D | M] -- C:\Users\patrick\AppData\Roaming\Template
[2010/12/27 22:38:15 | 000,000,000 | ---D | M] -- C:\Users\patrick\AppData\Roaming\TigerPlayer
[2009/09/08 03:56:47 | 000,000,000 | ---D | M] -- C:\Users\patrick\AppData\Roaming\TOSHIBA
[2009/09/09 05:14:35 | 000,000,000 | ---D | M] -- C:\Users\patrick\AppData\Roaming\WildTangent
[2009/09/08 03:27:56 | 000,000,000 | ---D | M] -- C:\Users\patrick\AppData\Roaming\WinBatch
[2011/09/09 10:55:43 | 000,032,596 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ========== ========== Custom Scans ========== < C:\windows\assembly\*. >[2011/08/05 20:18:43 | 000,000,000 | ---D | M] -- C:\windows\assembly\GAC
[2011/09/09 10:54:58 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32
[2011/09/09 10:54:58 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64
[2011/08/05 20:19:11 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_MSIL
[2011/08/31 13:17:20 | 000,000,000 | ---D | M] -- C:\windows\assembly\NativeImages_v2.0.50727_32
[2011/08/31 13:13:20 | 000,000,000 | ---D | M] -- C:\windows\assembly\NativeImages_v2.0.50727_64
[2011/09/08 18:54:05 | 000,000,000 | ---D | M] -- C:\windows\assembly\NativeImages_v4.0.30319_32
[2011/09/08 18:50:50 | 000,000,000 | ---D | M] -- C:\windows\assembly\NativeImages_v4.0.30319_64
[2011/09/08 17:37:01 | 000,000,000 | ---D | M] -- C:\windows\assembly\temp
[2011/09/08 17:37:01 | 000,000,000 | ---D | M] -- C:\windows\assembly\tmp
< C:\windows\assembly\*.* >[2006/11/02 11:30:40 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
[2009/12/14 19:24:52 | 000,000,000 | RH-- | M] () -- C:\windows\assembly\PublisherPolicy.tme
[2009/09/15 23:48:42 | 000,000,000 | RH-- | M] () -- C:\windows\assembly\pubpol14.dat
[2009/12/14 19:24:52 | 000,000,000 | RH-- | M] () -- C:\windows\assembly\pubpol27.dat
< C:\windows\assembly\GAC_32\*. >[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\CustomMarshalers
[2011/08/05 20:17:36 | 000,000,000 | ---D | M] -- C:\windows\assembly\GAC_32\ehexthost32
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\ISymWrapper
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\Microsoft.Ink
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\Microsoft.Interop.Security.AzRoles
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\mscorlib
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\napcrypt
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\naphlpr
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\Policy.1.0.Microsoft.Ink
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\Policy.1.0.Microsoft.Interop.Security.AzRoles
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\Policy.1.2.Microsoft.Interop.Security.AzRoles
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\Policy.1.7.Microsoft.Ink
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\PresentationCore
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\System.Data
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\System.Data.OracleClient
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\System.EnterpriseServices
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\System.Printing
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\System.Transactions
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_32\System.Web
< C:\windows\assembly\GAC_32\*.* >File not found -- C:\windows\assembly\GAC_32\
< C:\windows\assembly\GAC_64\*. >[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\BDATunePIA
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\CustomMarshalers
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\ISymWrapper
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\mcstoredb
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\mcupdate
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\Mcx2Dvcs
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\Microsoft.Ink
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\Microsoft.Interop.Security.AzRoles
[2011/08/05 20:17:36 | 000,000,000 | ---D | M] -- C:\windows\assembly\GAC_64\Microsoft.MediaCenter.Interop
[2011/08/05 20:17:36 | 000,000,000 | ---D | M] -- C:\windows\assembly\GAC_64\Microsoft.MediaCenter.iTV.Media
[2011/08/05 20:17:36 | 000,000,000 | ---D | M] -- C:\windows\assembly\GAC_64\Microsoft.MediaCenter.Mheg
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\mscorlib
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\napcrypt
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\naphlpr
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\Policy.1.0.Microsoft.Ink
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\Policy.1.0.Microsoft.Interop.Security.AzRoles
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\Policy.1.2.Microsoft.Interop.Security.AzRoles
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\Policy.1.7.Microsoft.Ink
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\PresentationCore
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\System.Data
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\System.Data.OracleClient
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\System.EnterpriseServices
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\System.Printing
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\System.Transactions
[2011/08/05 20:17:36 | 000,000,000 | R--D | M] -- C:\windows\assembly\GAC_64\System.Web
< C:\windows\assembly\GAC_64\*.* >File not found -- C:\windows\assembly\GAC_64\
< C:\windows\assembly\tmp\*.* /s >[2011/09/07 15:34:07 | 000,002,144 | -HS- | M] () -- C:\windows\assembly\tmp\click.tlb
[2011/09/07 17:52:10 | 000,002,540 | -HS- | M] () -- C:\windows\assembly\tmp\loader.tlb
[2011/07/23 23:09:51 | 000,002,048 | ---- | M] () -- C:\windows\assembly\tmp\{1B372133-BFFA-4dba-9CCF-5474BED6A9F6}
[2011/07/23 23:10:57 | 000,002,560 | ---- | M] () -- C:\windows\assembly\tmp\U\000000c0.@
[2011/07/23 23:10:57 | 000,002,048 | ---- | M] () -- C:\windows\assembly\tmp\U\000000cb.@
[2011/08/14 23:00:25 | 000,001,536 | ---- | M] () -- C:\windows\assembly\tmp\U\000000cf.@
[2011/07/23 23:10:57 | 000,017,920 | ---- | M] () -- C:\windows\assembly\tmp\U\80000000.@
[2011/09/07 19:36:39 | 000,070,144 | ---- | M] () -- C:\windows\assembly\tmp\U\800000c0.@
[2011/09/07 15:30:07 | 000,027,136 | ---- | M] () -- C:\windows\assembly\tmp\U\800000cb.@
[2011/09/07 20:24:40 | 000,000,000 | ---- | M] () -- C:\windows\assembly\tmp\U\800000cf.$
< End of report >