1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Pc is acting up, would like diagnostic help.

Discussion in 'Malware and Virus Removal Archive' started by Forsaken Knight, 2012/01/21.

  1. 2012/01/21
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    [Inactive] Pc is acting up, would like diagnostic help.

    Description: Hi, I have been having some alarming issues as of late. I have recently had 2 BSOD

    happen today. I couldn't take a picture of my pc screen before the BSOD restarted my pc. I do

    recall that it had something to do with the "Kernal ". I tried to update my anti-virus, avast, and

    I kept getting errors not long after I tried to update my anti-virus. I tried shutting down my

    fire wall and trying this, but still avast anti-virus ran into an error. I tried updating windows

    defender, and it was sucessful. I tried updating Malware-bytes, and it was successful. Overall,

    the freeze then crash of my pc has been recent. I'd say in the time I have been gone that I

    haven't posted here, 3, maybe 4, times my pc has freezed on me. One about a month or more ago,

    one this past work week, and two today. I do not know what the cause might be. I have not often,

    more like rarely, check my email, and I do the basic things towards my routine each day. I go to

    a site to play a F2P game, I play itunes radio, I have taskmanager up just in case. and I have

    been on google doing basic searches for stuff I do not know what is meant by the word (looking up

    meanings and such). I always keep my firewall and anti-virus on. Currently, I can not access

    itunes radio sections that I do not normally check. I can access the itunes store, so that does

    mean that Itunes can access the net. When ever I run a scan from avast anti-virus, windows

    defender, malware bytes, nothing comes up as a problem. I always seem to get a clean pc, but the

    BSOD alarms me, so I am sceptical.

    I have an updated version of zone alarm on my pc as my fire wall.

    I have avaast anti-vius, on my pc.
     
  2. 2012/01/21
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    Malwarebytes Anti-Malware 1.60.0.1800
    www.malwarebytes.org

    Database version: v2012.01.21.02

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    walmart :: WALMART-PC [administrator]

    1/21/2012 2:45:00 PM
    mbam-log-2012-01-21 (14-45-00).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra |

    Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 199295
    Time elapsed: 8 minute(s), 9 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
     

  3. to hide this advert.

  4. 2012/01/21
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    Gmer didn't find anything. when I tried to save a log, all I got was a black document. Here is the screen shot of the results.

    [​IMG]

    Uploaded with ImageShack.us
     
  5. 2012/01/21
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows 7 Home Premium Edition
    Windows Information: Service Pack 1 (build 7601), 64-bit
    Base Board Manufacturer: eMachines
    BIOS Manufacturer: eMachines
    System Manufacturer: eMachines
    System Product Name: eMachines E725
    Logical Drives Mask: 0x0000000c

    Kernel Drivers (total 198):
    0x02C11000 \SystemRoot\system32\ntoskrnl.exe
    0x031FA000 \SystemRoot\system32\hal.dll
    0x00BC6000 \SystemRoot\system32\kdcom.dll
    0x00CF1000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
    0x00D40000 \SystemRoot\system32\PSHED.dll
    0x00D54000 \SystemRoot\system32\CLFS.SYS
    0x00C00000 \SystemRoot\system32\CI.dll
    0x00E7F000 \SystemRoot\system32\drivers\Wdf01000.sys
    0x00F23000 \SystemRoot\system32\drivers\WDFLDR.SYS
    0x00F32000 \SystemRoot\system32\drivers\ACPI.sys
    0x00F89000 \SystemRoot\system32\drivers\WMILIB.SYS
    0x00F92000 \SystemRoot\system32\drivers\msisadrv.sys
    0x00F9C000 \SystemRoot\system32\drivers\pci.sys
    0x00FCF000 \SystemRoot\system32\drivers\vdrvroot.sys
    0x00FDC000 \SystemRoot\System32\drivers\partmgr.sys
    0x00FF1000 \SystemRoot\system32\DRIVERS\compbatt.sys
    0x00E00000 \SystemRoot\system32\DRIVERS\BATTC.SYS
    0x00E0C000 \SystemRoot\system32\drivers\volmgr.sys
    0x00E21000 \SystemRoot\System32\drivers\volmgrx.sys
    0x00CC0000 \SystemRoot\System32\drivers\mountmgr.sys
    0x0101A000 \SystemRoot\system32\DRIVERS\iaStor.sys
    0x01136000 \SystemRoot\system32\drivers\atapi.sys
    0x0113F000 \SystemRoot\system32\drivers\ataport.SYS
    0x01169000 \SystemRoot\system32\drivers\amdxata.sys
    0x01174000 \SystemRoot\system32\drivers\fltmgr.sys
    0x011C0000 \SystemRoot\system32\drivers\fileinfo.sys
    0x0123F000 \SystemRoot\System32\Drivers\Ntfs.sys
    0x01455000 \SystemRoot\System32\Drivers\msrpc.sys
    0x014B3000 \SystemRoot\System32\Drivers\ksecdd.sys
    0x014CE000 \SystemRoot\System32\Drivers\cng.sys
    0x01540000 \SystemRoot\System32\drivers\pcw.sys
    0x01551000 \SystemRoot\System32\Drivers\Fs_Rec.sys
    0x0167B000 \SystemRoot\system32\drivers\ndis.sys
    0x0176E000 \SystemRoot\system32\drivers\NETIO.SYS
    0x017CE000 \SystemRoot\System32\Drivers\ksecpkg.sys
    0x018C1000 \SystemRoot\System32\drivers\tcpip.sys
    0x01AC5000 \SystemRoot\System32\drivers\fwpkclnt.sys
    0x01B0F000 \SystemRoot\system32\drivers\volsnap.sys
    0x01B5B000 \SystemRoot\System32\Drivers\spldr.sys
    0x01B63000 \SystemRoot\System32\drivers\rdyboost.sys
    0x01B9D000 \SystemRoot\System32\Drivers\mup.sys
    0x01BAF000 \SystemRoot\System32\drivers\hwpolicy.sys
    0x01BB8000 \SystemRoot\System32\DRIVERS\fvevol.sys
    0x01800000 \SystemRoot\system32\DRIVERS\disk.sys
    0x01816000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
    0x02E00000 \SystemRoot\system32\drivers\cdrom.sys
    0x02E2A000 \SystemRoot\System32\Drivers\aswSnx.SYS
    0x02EC0000 \SystemRoot\System32\Drivers\Null.SYS
    0x01854000 \SystemRoot\System32\Drivers\Beep.SYS
    0x0185B000 \SystemRoot\System32\drivers\vga.sys
    0x01869000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
    0x0188E000 \SystemRoot\System32\drivers\watchdog.sys
    0x0189E000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0x018A7000 \SystemRoot\system32\drivers\rdpencdd.sys
    0x018B0000 \SystemRoot\system32\drivers\rdprefmp.sys
    0x01BF2000 \SystemRoot\System32\Drivers\Msfs.SYS
    0x01600000 \SystemRoot\System32\Drivers\Npfs.SYS
    0x01611000 \SystemRoot\system32\DRIVERS\tdx.sys
    0x01633000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0x01640000 \SystemRoot\System32\Drivers\aswTdi.SYS
    0x0155B000 \SystemRoot\system32\drivers\afd.sys
    0x01652000 \SystemRoot\System32\Drivers\aswRdr.SYS
    0x01400000 \SystemRoot\System32\DRIVERS\netbt.sys
    0x03C36000 \SystemRoot\system32\DRIVERS\vsdatant.sys
    0x03CCB000 \SystemRoot\system32\DRIVERS\wfplwf.sys
    0x03CD4000 \SystemRoot\system32\DRIVERS\pacer.sys
    0x03CFA000 \SystemRoot\system32\DRIVERS\vwififlt.sys
    0x03D10000 \SystemRoot\system32\DRIVERS\netbios.sys
    0x03D1F000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0x03D3A000 \SystemRoot\system32\drivers\termdd.sys
    0x03D4E000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0x03D9F000 \SystemRoot\system32\drivers\nsiproxy.sys
    0x03DAB000 \SystemRoot\system32\drivers\mssmbios.sys
    0x03DB6000 \SystemRoot\System32\drivers\discache.sys
    0x03DC5000 \SystemRoot\System32\Drivers\dfsc.sys
    0x03DE3000 \SystemRoot\system32\DRIVERS\blbdrive.sys
    0x040D0000 \SystemRoot\System32\Drivers\aswSP.SYS
    0x04121000 \SystemRoot\system32\DRIVERS\tunnel.sys
    0x04147000 \SystemRoot\system32\DRIVERS\intelppm.sys
    0x04A89000 \SystemRoot\system32\DRIVERS\igdkmd64.sys
    0x044E0000 \SystemRoot\System32\drivers\dxgkrnl.sys
    0x04400000 \SystemRoot\System32\drivers\dxgmms1.sys
    0x04446000 \SystemRoot\system32\DRIVERS\usbuhci.sys
    0x04453000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0x044A9000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0x044BA000 \SystemRoot\system32\drivers\HDAudBus.sys
    0x05200000 \SystemRoot\system32\DRIVERS\bcmwl664.sys
    0x054DB000 \SystemRoot\system32\DRIVERS\vwifibus.sys
    0x054E8000 \SystemRoot\system32\DRIVERS\L1C62x64.sys
    0x054FB000 \SystemRoot\system32\DRIVERS\CmBatt.sys
    0x05500000 \SystemRoot\system32\drivers\i8042prt.sys
    0x0551E000 \SystemRoot\SysWOW64\Drivers\DKbFltr.sys
    0x0552A000 \SystemRoot\system32\drivers\kbdclass.sys
    0x05539000 \SystemRoot\system32\DRIVERS\SynTP.sys
    0x05582000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0x05584000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0x05593000 \??\C:\Windows\system32\drivers\UBHelper.sys
    0x0559B000 \??\C:\Windows\system32\drivers\NTIDrvr.sys
    0x055A3000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
    0x055B0000 \SystemRoot\system32\drivers\wmiacpi.sys
    0x055B9000 \SystemRoot\system32\drivers\CompositeBus.sys
    0x055C9000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
    0x045D4000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0x055DF000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0x05191000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0x051C0000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0x051DB000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0x04A00000 \SystemRoot\system32\DRIVERS\rassstp.sys
    0x055EB000 \SystemRoot\system32\drivers\SaiBus.sys
    0x055F6000 \SystemRoot\system32\drivers\swenum.sys
    0x04A1A000 \SystemRoot\system32\drivers\ks.sys
    0x04A5D000 \SystemRoot\system32\drivers\umbus.sys
    0x0415D000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0x04A6F000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0x055F8000 \SystemRoot\system32\DRIVERS\SaiMini.sys
    0x041B7000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    0x041D0000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0x05806000 \SystemRoot\system32\drivers\RTKVHD64.sys
    0x04000000 \SystemRoot\system32\drivers\portcls.sys
    0x0403D000 \SystemRoot\system32\drivers\drmk.sys
    0x059E5000 \SystemRoot\system32\drivers\ksthunk.sys
    0x059EB000 \SystemRoot\system32\drivers\kbdhid.sys
    0x0405F000 \SystemRoot\system32\DRIVERS\mouhid.sys
    0x000A0000 \SystemRoot\System32\win32k.sys
    0x0406C000 \SystemRoot\System32\drivers\Dxapi.sys
    0x04078000 \SystemRoot\System32\Drivers\crashdmp.sys
    0x02EC9000 \SystemRoot\System32\Drivers\dump_iaStor.sys
    0x04086000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
    0x04099000 \SystemRoot\system32\DRIVERS\SaiU5F0D.sys
    0x040A2000 \SystemRoot\system32\DRIVERS\hidusb.sys
    0x03C00000 \SystemRoot\system32\DRIVERS\SaiH5F0D.sys
    0x040B0000 \SystemRoot\system32\DRIVERS\monitor.sys
    0x00400000 \SystemRoot\System32\TSDDD.dll
    0x007C0000 \SystemRoot\System32\cdd.dll
    0x040BE000 \SystemRoot\system32\DRIVERS\point64.sys
    0x008F0000 \SystemRoot\System32\ATMFD.DLL
    0x041D9000 \SystemRoot\system32\drivers\luafv.sys
    0x01200000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
    0x03C29000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
    0x011D4000 \SystemRoot\system32\drivers\WudfPf.sys
    0x02FE5000 \SystemRoot\system32\DRIVERS\lltdio.sys
    0x0281F000 \SystemRoot\system32\DRIVERS\nwifi.sys
    0x02872000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0x02885000 \SystemRoot\system32\DRIVERS\rspndr.sys
    0x0289D000 \??\C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys
    0x028A9000 \SystemRoot\system32\drivers\HTTP.sys
    0x02972000 \SystemRoot\system32\DRIVERS\bowser.sys
    0x02990000 \SystemRoot\System32\drivers\mpsdrv.sys
    0x029A8000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0x00DB2000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
    0x029D5000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
    0x06C54000 \SystemRoot\system32\drivers\peauth.sys
    0x06CFA000 \SystemRoot\System32\Drivers\secdrv.SYS
    0x06D05000 \SystemRoot\System32\DRIVERS\srvnet.sys
    0x06D36000 \SystemRoot\System32\drivers\tcpipreg.sys
    0x06D48000 \SystemRoot\System32\DRIVERS\srv2.sys
    0x07056000 \SystemRoot\System32\DRIVERS\srv.sys
    0x070EE000 \SystemRoot\system32\DRIVERS\psi_mf.sys
    0x76F00000 \Windows\System32\ntdll.dll
    0x47640000 \Windows\System32\smss.exe
    0xFF220000 \Windows\System32\apisetschema.dll
    0xFF160000 \Windows\System32\autochk.exe
    0xFF130000 \Windows\System32\oleaut32.dll
    0xFF060000 \Windows\System32\usp10.dll
    0x76DA0000 \Windows\System32\wininet.dll
    0xFF000000 \Windows\System32\Wldap32.dll
    0xFEED0000 \Windows\System32\rpcrt4.dll
    0xFEEC0000 \Windows\System32\nsi.dll
    0xFEE20000 \Windows\System32\comdlg32.dll
    0xFED10000 \Windows\System32\msctf.dll
    0xFECC0000 \Windows\System32\ws2_32.dll
    0x76B90000 \Windows\System32\iertutil.dll
    0x770D0000 \Windows\System32\normaliz.dll
    0xFEBE0000 \Windows\System32\advapi32.dll
    0xFEBB0000 \Windows\System32\imm32.dll
    0xFDE20000 \Windows\System32\shell32.dll
    0xFDDB0000 \Windows\System32\gdi32.dll
    0xFDD30000 \Windows\System32\shlwapi.dll
    0xFDCB0000 \Windows\System32\difxapi.dll
    0xFDCA0000 \Windows\System32\lpk.dll
    0xFDC80000 \Windows\System32\imagehlp.dll
    0xFDC60000 \Windows\System32\sechost.dll
    0x76A70000 \Windows\System32\kernel32.dll
    0xFDBC0000 \Windows\System32\clbcatq.dll
    0x76970000 \Windows\System32\user32.dll
    0xFD9B0000 \Windows\System32\ole32.dll
    0xFD7D0000 \Windows\System32\setupapi.dll
    0xFD730000 \Windows\System32\msvcrt.dll
    0x770C0000 \Windows\System32\psapi.dll
    0x76820000 \Windows\System32\urlmon.dll
    0xFD710000 \Windows\System32\devobj.dll
    0xFD670000 \Windows\System32\comctl32.dll
    0xFD500000 \Windows\System32\crypt32.dll
    0xFD490000 \Windows\System32\KernelBase.dll
    0xFD450000 \Windows\System32\wintrust.dll
    0xFD410000 \Windows\System32\cfgmgr32.dll
    0xFD400000 \Windows\System32\msasn1.dll
    0x74E60000 \Windows\SysWOW64\normaliz.dll

    Processes (total 89):
    0 System Idle Process
    4 System
    340 C:\Windows\System32\smss.exe
    496 csrss.exe
    544 C:\Windows\System32\wininit.exe
    564 csrss.exe
    612 C:\Windows\System32\services.exe
    620 C:\Windows\System32\lsass.exe
    628 C:\Windows\System32\lsm.exe
    660 C:\Windows\System32\winlogon.exe
    792 C:\Windows\System32\svchost.exe
    884 C:\Windows\System32\svchost.exe
    972 C:\Windows\System32\svchost.exe
    1012 C:\Windows\System32\svchost.exe
    380 C:\Windows\System32\svchost.exe
    480 C:\Windows\System32\svchost.exe
    1148 C:\Windows\System32\svchost.exe
    1344 C:\Windows\System32\dwm.exe
    1368 C:\Windows\explorer.exe
    1480 C:\Windows\System32\wlanext.exe
    1488 C:\Windows\System32\conhost.exe
    1628 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    1668 C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe
    1872 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    1892 C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    1076 C:\Program Files\eMachines\eMachines Power Management\ePowerTray.exe
    1080 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    2228 C:\Windows\System32\igfxsrvc.exe
    2384 C:\Windows\System32\taskhost.exe
    2392 C:\Windows\System32\spoolsv.exe
    2500 C:\Windows\System32\svchost.exe
    2620 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    2692 C:\Windows\System32\hkcmd.exe
    2720 C:\Windows\System32\igfxpers.exe
    2736 C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
    2756 C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
    2784 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    2796 C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    2868 C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe
    2916 C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
    3000 C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
    2444 C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    2220 C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
    2808 C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
    1340 C:\Program Files\Bonjour\mDNSResponder.exe
    3052 C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe
    2460 C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe
    3124 C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
    3212 C:\Program Files (x86)\Secunia\PSI\psia.exe
    3344 C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
    3372 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    3436 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
    3468 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    3800 C:\Windows\System32\svchost.exe
    3956 C:\Windows\System32\SearchIndexer.exe
    3768 C:\Windows\System32\svchost.exe
    4160 C:\Windows\System32\svchost.exe
    4264 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    4304 C:\Program Files\Windows Media Player\wmpnetwk.exe
    4568 C:\Program Files (x86)\Launch Manager\LManager.exe
    4672 C:\Windows\System32\igfxext.exe
    4736 C:\Windows\System32\wbem\unsecapp.exe
    4788 WmiPrvSE.exe
    4864 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    4128 C:\Program Files\eMachines\eMachines Power Management\ePowerEvent.exe
    4368 C:\Program Files (x86)\iTunes\iTunesHelper.exe
    4856 C:\Program Files (x86)\Secunia\PSI\sua.exe
    4916 C:\Windows\System32\svchost.exe
    5480 C:\Program Files\iPod\bin\iPodService.exe
    5836 dllhost.exe
    1308 C:\Windows\System32\taskmgr.exe
    4596 C:\Windows\System32\svchost.exe
    4880 C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
    2284 C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
    2420 C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
    1452 C:\Program Files (x86)\Internet Explorer\iexplore.exe
    5076 C:\Program Files (x86)\Internet Explorer\iexplore.exe
    2532 C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
    6012 C:\Program Files (x86)\Internet Explorer\iexplore.exe
    1464 C:\Windows\SysWOW64\ctfmon.exe
    2128 C:\Windows\System32\notepad.exe
    3328 C:\Program Files (x86)\Internet Explorer\iexplore.exe
    1624 C:\Windows\System32\SearchProtocolHost.exe
    5088 C:\Windows\System32\SearchFilterHost.exe
    5572 C:\Windows\System32\audiodg.exe
    2412 dllhost.exe
    5844 dllhost.exe
    4032 C:\Users\walmart\Desktop\MBRCheck.exe
    5264 C:\Windows\System32\conhost.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000003`069e5800 (NTFS)

    PhysicalDrive0 Model Number: WDCWD2500BEVT-22ZCT0, Rev: 11.01A11

    Size Device Name MBR Status
    --------------------------------------------
    232 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
    SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79


    Done!
     
  6. 2012/01/21
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
  7. 2012/01/21
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    aswMBR version 0.9.9.1297 Copyright(c) 2011 AVAST Software
    Run date: 2012-01-21 18:14:43
    -----------------------------
    18:14:43.166 OS Version: Windows x64 6.1.7601 Service Pack 1
    18:14:43.166 Number of processors: 2 586 0x170A
    18:14:43.181 ComputerName: WALMART-PC UserName: walmart
    18:14:44.835 Initialize success
    18:14:44.882 AVAST engine defs: 12012100
    18:14:46.457 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
    18:14:46.473 Disk 0 Vendor: WDC_WD25 11.0 Size: 238475MB BusType: 3
    18:14:46.520 Disk 0 MBR read successfully
    18:14:46.520 Disk 0 MBR scan
    18:14:46.535 Disk 0 Windows 7 default MBR code
    18:14:46.535 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 12291 MB offset 63
    18:14:46.551 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 101 MB offset 25173855
    18:14:46.566 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 226080 MB offset 25382700
    18:14:46.582 Service scanning
    18:14:47.846 Modules scanning
    18:14:47.846 Disk 0 trace - called modules:
    18:14:47.908 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
    18:14:47.924 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8002f2d060]
    18:14:47.924 3 CLASSPNP.SYS[fffff8800181743f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8002dfa050]
    18:14:49.109 AVAST engine scan C:\Windows
    18:15:05.631 AVAST engine scan C:\Windows\system32
    18:16:33.568 AVAST engine scan C:\Windows\system32\drivers
    18:16:42.881 AVAST engine scan C:\Users\walmart
    18:17:33.004 Disk 0 MBR has been saved successfully to "C:\Users\walmart\Desktop\MBR.dat "
    18:17:33.020 The log file has been saved successfully to "C:\Users\walmart\Desktop\aswMBR done on sat jan 21 2012.txt "
     
  8. 2012/01/21
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    Note: aswMBR kept running into some issue with avast even when I would turn off avast.
     
  9. 2012/01/21
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    .
    DDS (Ver_2011-08-26.01) - NTFSAMD64
    Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
    Run by walmart at 18:22:21 on 2012-01-21
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3002.1148 [GMT -5:00]
    .
    AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
    SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    FW: ZoneAlarm Free Firewall *Enabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\WLANExt.exe
    C:\Windows\system32\conhost.exe
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    C:\Program Files\eMachines\eMachines Power Management\ePowerTray.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
    C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe
    C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
    C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
    C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
    C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe
    C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe
    C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
    C:\Program Files (x86)\Secunia\PSI\PSIA.exe
    C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files (x86)\Launch Manager\LManager.exe
    C:\Windows\system32\igfxext.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Program Files\eMachines\eMachines Power Management\ePowerEvent.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files (x86)\Secunia\PSI\sua.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\System32\taskmgr.exe
    C:\Windows\system32\svchost.exe -k SDRSVC
    C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
    C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
    C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Windows\SysWOW64\ctfmon.exe
    C:\Windows\system32\NOTEPAD.EXE
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.com/webhp?sourceid=navclient&ie=UTF-8&rlz=1T4ACEW_enUS368US370
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    uDefault_Search_URL = hxxp://www.google.com/ie
    mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&m=e725&r=273603108715l04f4z1m5r4422023o
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    uURLSearchHooks: FCToolbarURLSearchHook Class: {868978c8-95f3-4020-a5cd-5a16d60e36ca} - C:\Program Files (x86)\Dividend Miles Toolbar\Helper.dll
    uURLSearchHooks: H - No File
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: Dividend Miles Toolbar BHO: {69cd690c-70b1-4333-ad69-28fff7118c56} - C:\Program Files (x86)\Dividend Miles Toolbar\Toolbar.dll
    BHO: ZoneAlarm Security Engine Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin

    \TrustCheckerIEPlugin.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - C:\Program Files (x86)\WOT\WOT.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    TB: Dividend Miles Toolbar: {3948072d-28fe-4206-9f7f-2aff92b24679} - C:\Program Files (x86)\Dividend Miles Toolbar\Toolbar.dll
    TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - C:\Program Files (x86)\WOT\WOT.dll
    TB: ZoneAlarm Security Engine: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
    uRun: [FileHippo.com] "C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background
    mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
    mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
    mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe "
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe "
    mRun: [ZoneAlarm] "C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe "
    mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe "
    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe "
    StartupFolder: C:\Users\walmart\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\AVAST!~1.LNK - C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    StartupFolder: C:\Users\walmart\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program

    \quickstart.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SECUNI~1.LNK - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
    IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
    DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
    TCP: Interfaces\{0ACAFB23-3CB5-48B5-9D25-9351FC1E144F}\059434B495132333 : DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{0ACAFB23-3CB5-48B5-9D25-9351FC1E144F}\E4457425F557B46424730596549303074627D674832424D623C40563161734 : DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{0ACAFB23-3CB5-48B5-9D25-9351FC1E144F}\E4457425F5C4A487679456 : DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{0ACAFB23-3CB5-48B5-9D25-9351FC1E144F}\E4457425F5E43784E4A5972373242376C616E405556793948797433526576424 : DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{0ACAFB23-3CB5-48B5-9D25-9351FC1E144F}\E4457425F5E49676E6C674F61326777407A685B4 : DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{0ACAFB23-3CB5-48B5-9D25-9351FC1E144F}\E4457425F5F6449694752446A4539405439527951513 : DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{DD5D3D63-591C-47D3-8673-1AEDDEB14120} : DhcpNameServer = 75.75.75.75 75.75.76.76
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: Dividend Miles Toolbar BHO: {69CD690C-70B1-4333-AD69-28FFF7118C56} - C:\Program Files (x86)\Dividend Miles Toolbar\Toolbar.dll
    BHO-X64: FCTBPos00Pos - No File
    BHO-X64: ZoneAlarm Security Engine Registrar: {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin

    \TrustCheckerIEPlugin.dll
    BHO-X64: ZoneAlarm Security Engine Registrar - No File
    BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live

    \WindowsLiveLogin.dll
    BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO-X64: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    TB-X64: Dividend Miles Toolbar: {3948072D-28FE-4206-9F7F-2AFF92B24679} - C:\Program Files (x86)\Dividend Miles Toolbar\Toolbar.dll
    TB-X64: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
    TB-X64: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
    TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    mRun-x64: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
    mRun-x64: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
    mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe "
    mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe "
    mRun-x64: [ZoneAlarm] "C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe "
    mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe "
    mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe "
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\walmart\AppData\Roaming\Mozilla\Firefox\Profiles\obavtsyv.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2611275&SearchSource=3&q={searchTerms}
    FF - prefs.js: browser.search.selectedEngine -
    FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
    FF - prefs.js: network.proxy.type - 0
    FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
    FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
    FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
    FF - plugin: C:\Program Files (x86)\NOS\bin\np_gp.dll
    FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
    FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    FF - plugin: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
    R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
    R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
    R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
    R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
    R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
    R2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-12-16 44768]
    R2 ePowerSvc;Acer ePower Service;C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe [2009-11-5 844320]
    R2 Greg_Service;GRegService;C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe [2009-8-28 1150496]
    R2 ISWKL;ZoneAlarm Toolbar ISWKL;C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys [2011-11-3 33672]
    R2 IswSvc;ZoneAlarm Toolbar IswSvc;C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe [2011-11-3 827520]
    R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-6-17 144640]
    R2 Secunia PSI Agent;Secunia PSI Agent;C:\Program Files (x86)\Secunia\PSI\psia.exe [2011-4-19 993848]
    R2 Secunia Update Agent;Secunia Update Agent;C:\Program Files (x86)\Secunia\PSI\sua.exe [2011-4-19 399416]
    R2 Updater Service;Updater Service;C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe [2009-11-5 240160]
    R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);C:\Windows\system32\DRIVERS\L1C62x64.sys --> C:\Windows\system32\DRIVERS

    \L1C62x64.sys [?]
    R3 PSI;PSI;C:\Windows\system32\DRIVERS\psi_mf.sys --> C:\Windows\system32\DRIVERS\psi_mf.sys [?]
    R3 SaiH5F0D;SaiH5F0D;C:\Windows\system32\DRIVERS\SaiH5F0D.sys --> C:\Windows\system32\DRIVERS\SaiH5F0D.sys [?]
    R3 SaiU5F0D;SaiU5F0D;C:\Windows\system32\DRIVERS\SaiU5F0D.sys --> C:\Windows\system32\DRIVERS\SaiU5F0D.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-3-12 135664]
    S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
    S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840]
    S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-3-12 135664]
    S3 nosGetPlusHelper;getPlus(R) Helper 3004;C:\Windows\System32\svchost.exe -k nosGetPlusHelper [2009-7-13 20992]
    S3 NTIBackupSvc;NTI Backup Now 5 Backup Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-6-17 50432]
    S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2009-11-5 225280]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
    S3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;C:\Windows\system32\DRIVERS\WN111v2x.sys --> C:\Windows\system32\DRIVERS\WN111v2x.sys [?]
    S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
    .
    =============== Created Last 30 ================
    .
    2012-01-21 19:36:14 -------- d-----w- C:\Users\walmart\AppData\Local\{56F488CA-AB94-40FA-87D5-5319F67A9F39}
    2012-01-21 19:35:56 -------- d-----w- C:\Users\walmart\AppData\Local\{7B589482-97E4-4C0B-A0CE-724F8FD5854F}
    2012-01-21 14:58:56 -------- d-----w- C:\Users\walmart\AppData\Local\{A2F568FB-09E0-4AA7-9C7A-B58A25A4A8EE}
    2012-01-20 17:12:05 8602168 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7DBD3E82-3BA8-47AB-B12C-38FE62882CF8}\mpengine.dll
    2012-01-15 19:49:01 -------- d-----w- C:\Users\walmart\AppData\Local\{70386153-4445-46F6-A552-E53A479F9846}
    2012-01-15 19:48:46 -------- d-----w- C:\Users\walmart\AppData\Local\{D92B6E17-99CF-4E4D-9DC8-BBC7586CAB04}
    2012-01-11 21:25:52 -------- d-----w- C:\Users\walmart\AppData\Local\{5EE02F28-6F7E-4C5C-B801-E0B9E9EB5ECF}
    2012-01-11 04:29:08 1572864 ----a-w- C:\Windows\System32\quartz.dll
    2012-01-11 04:29:08 1328128 ----a-w- C:\Windows\SysWow64\quartz.dll
    2012-01-11 04:29:07 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
    2012-01-11 04:29:06 366592 ----a-w- C:\Windows\System32\qdvd.dll
    2012-01-11 04:29:04 1731920 ----a-w- C:\Windows\System32\ntdll.dll
    2012-01-11 04:29:04 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
    2012-01-11 04:29:03 77312 ----a-w- C:\Windows\System32\packager.dll
    2012-01-11 04:29:02 67072 ----a-w- C:\Windows\SysWow64\packager.dll
    2012-01-02 03:29:04 -------- d-----w- C:\Users\walmart\AppData\Local\{205F1A5C-B131-47A6-82E3-04B90098FF3A}
    2012-01-01 06:35:14 -------- d-----w- C:\Users\walmart\AppData\Local\{F6D7996A-F71F-4C40-9726-735AAAE78634}
    2012-01-01 06:35:00 -------- d-----w- C:\Users\walmart\AppData\Local\{97FB0C94-0E07-4352-9B83-E406FAB7CF4D}
    2011-12-29 01:13:37 -------- d-----w- C:\Program Files\iPod
    2011-12-29 01:13:36 -------- d-----w- C:\Program Files\iTunes
    2011-12-29 01:13:36 -------- d-----w- C:\Program Files (x86)\iTunes
    2011-12-29 01:08:16 -------- d-----w- C:\Program Files\Bonjour
    2011-12-29 01:08:16 -------- d-----w- C:\Program Files (x86)\Bonjour
    2011-12-28 22:10:41 -------- d-----w- C:\Users\walmart\AppData\Local\{269EF253-9E81-4C71-AC1B-953C1A72B11C}
    .
    ==================== Find3M ====================
    .
    2011-12-10 20:24:08 23152 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2011-11-28 18:01:25 41184 ----a-w- C:\Windows\avastSS.scr
    2011-11-28 17:54:06 591192 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
    2011-11-28 17:52:11 66904 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
    2011-11-24 04:52:09 3145216 ----a-w- C:\Windows\System32\win32k.sys
    2011-11-18 21:26:30 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2011-11-17 06:49:14 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
    2011-11-17 06:49:14 152432 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
    2011-11-17 06:44:43 459232 ----a-w- C:\Windows\System32\drivers\cng.sys
    2011-11-17 06:35:28 395776 ----a-w- C:\Windows\System32\webio.dll
    2011-11-17 06:35:26 29184 ----a-w- C:\Windows\System32\sspisrv.dll
    2011-11-17 06:35:26 136192 ----a-w- C:\Windows\System32\sspicli.dll
    2011-11-17 06:35:25 340992 ----a-w- C:\Windows\System32\schannel.dll
    2011-11-17 06:35:25 28160 ----a-w- C:\Windows\System32\secur32.dll
    2011-11-17 06:35:19 1447936 ----a-w- C:\Windows\System32\lsasrv.dll
    2011-11-17 06:33:55 31232 ----a-w- C:\Windows\System32\lsass.exe
    2011-11-17 05:35:02 314880 ----a-w- C:\Windows\SysWow64\webio.dll
    2011-11-17 05:34:52 224768 ----a-w- C:\Windows\SysWow64\schannel.dll
    2011-11-17 05:34:52 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
    2011-11-17 05:28:48 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
    2011-11-15 19:29:56 270720 ------w- C:\Windows\System32\MpSigStub.exe
    2011-11-05 05:32:50 2048 ----a-w- C:\Windows\System32\tzres.dll
    2011-11-05 04:26:03 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
    2011-11-04 01:53:39 2309120 ----a-w- C:\Windows\System32\jscript9.dll
    2011-11-04 01:44:47 1390080 ----a-w- C:\Windows\System32\wininet.dll
    2011-11-04 01:44:21 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl
    2011-11-04 01:43:01 627600 ----a-w- C:\Windows\System32\deployJava1.dll
    2011-11-04 01:34:43 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
    2011-11-03 22:47:42 1798144 ----a-w- C:\Windows\SysWow64\jscript9.dll
    2011-11-03 22:40:21 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
    2011-11-03 22:39:47 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll
    2011-11-03 22:31:57 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2011-10-26 05:21:20 43520 ----a-w- C:\Windows\System32\csrsrv.dll
    2011-10-24 19:29:02 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
    2011-10-24 19:29:02 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
    .
    ============= FINISH: 18:25:57.44 ===============
     
  10. 2012/01/21
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume2
    Install Date: 3/1/2010 6:28:55 AM
    System Uptime: 1/21/2012 2:34:23 PM (4 hours ago)
    .
    Motherboard: eMachines | | eMachines E725
    Processor: Pentium(R) Dual-Core CPU T4400 @ 2.20GHz | uPGA-478 | 1584/200mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 221 GiB total, 146.515 GiB free.
    D: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP363: 1/1/2012 10:38:26 PM - Windows Backup
    RP364: 1/3/2012 11:33:02 AM - Windows Update
    RP365: 1/6/2012 5:31:47 PM - Windows Update
    RP366: 1/8/2012 4:54:51 PM - Windows Update
    RP367: 1/10/2012 11:30:34 PM - Windows Update
    RP368: 1/15/2012 10:27:51 AM - Windows Update
    RP369: 1/15/2012 7:00:20 PM - Windows Backup
    RP370: 1/20/2012 12:10:40 PM - Windows Update
    .
    ==== Installed Programs ======================
    .
    Update for Microsoft Office 2007 (KB2508958)
    Acrobat.com
    Adobe Acrobat 4.0
    Adobe AIR
    Adobe Download Manager
    Adobe Reader X (10.1.1)
    Age Of Wonders
    AirRivals_EN 1.0.0.39
    Apple Application Support
    Apple Software Update
    Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
    avast! Free Antivirus
    Compatibility Pack for the 2007 Office system
    D3DX10
    Data Lifeguard Diagnostic for Windows 1.24
    DFOLauncher
    Dividend Miles Toolbar
    eBay Worldwide
    eMachines Games
    eMachines Power Management
    eMachines Recovery Management
    eMachines Registration
    eMachines ScreenSaver
    eMachines Updater
    ESET Online Scanner v3
    FileHippo.com Update Checker
    Google Chrome
    Google Earth
    Google Toolbar for Internet Explorer
    Google Update Helper
    Identity Card
    Java Auto Updater
    Java(TM) 6 Update 29
    JetFighter IV
    Junk Mail filter update
    Launch Manager
    Malwarebytes Anti-Malware version 1.60.0.1800
    Mesh Runtime
    Messenger Companion
    Microsoft Office 2007 Service Pack 3 (SP3)
    Microsoft Office Access MUI (English) 2007
    Microsoft Office Access Setup Metadata MUI (English) 2007
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office File Validation Add-In
    Microsoft Office Home and Student 2007
    Microsoft Office InfoPath MUI (English) 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office Outlook Connector
    Microsoft Office Outlook MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office Professional Plus 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    Microsoft Office Publisher MUI (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Suite Activation Assistant
    Microsoft Office Word MUI (English) 2007
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Works
    Mozilla Firefox 4.0.1 (x86 en-US)
    MSVCRT
    MSVCRT_amd64
    MyScribe
    Nexon Game Manager
    Norton Online Backup
    NTI Backup Now 5
    NTI Backup Now Standard
    NTI Media Maker 8
    OpenOffice.org 3.3
    Pando Media Booster
    Picasa 3
    QuickTime
    Realtek High Definition Audio Driver
    Realtek USB 2.0 Card Reader
    Revo Uninstaller 1.93
    Safari
    Secunia PSI (2.0.0.3003)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
    Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
    Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
    Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2596686) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition
    Update for Microsoft Office Access 2007 Help (KB963663)
    Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office Infopath 2007 Help (KB963662)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Outlook 2007 Help (KB963677)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Publisher 2007 Help (KB963667)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 Help (KB963665)
    VC 9.0 Runtime
    Welcome Center
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Installer
    Windows Live Mail
    Windows Live Mesh
    Windows Live Mesh ActiveX Control for Remote Connections
    Windows Live Messenger
    Windows Live Messenger Companion Core
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live Sync
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer Resources
    WOT for Internet Explorer
    ZoneAlarm Firewall
    ZoneAlarm Free
    ZoneAlarm Security
    .
    ==== Event Viewer Messages From Past Week ========
    .
    1/21/2012 9:07:39 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was

    reached while waiting for a transaction response from the WinDefend service.
    1/21/2012 6:18:14 PM, Error: Ntfs [55] - The file system structure on the disk is corrupt and

    unusable. Please run the chkdsk utility on the volume eMachines.
    1/21/2012 2:39:11 PM, Error: Ntfs [55] - The file system structure on the disk is corrupt and

    unusable. Please run the chkdsk utility on the volume C:.
    1/21/2012 2:32:22 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was

    reached while waiting for a transaction response from the wscsvc service.
    1/21/2012 2:32:22 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was

    reached while waiting for a transaction response from the ShellHWDetection service.
    1/18/2012 3:11:30 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was

    reached while waiting for a transaction response from the Netman service.
    1/16/2012 5:39:43 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was

    reached while waiting for a transaction response from the Wlansvc service.
    1/16/2012 11:53:39 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds)

    was reached while waiting for a transaction response from the lmhosts service.
    .
    ==== End Of File ===========================
     
  11. 2012/01/21
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    If I have missed anything, please inform me so I may go back and redo a step. Thank you for your time. I look forward to receiving help upon this matter of mine.
     
  12. 2012/01/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    =============================================================

    Is it the very same computer we cleaned 6 times in 2011 only?
     
  13. 2012/01/22
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0

    Was it 6 times in one year? I thought it was half or less than that.

    Yes, the same laptop.

    Also, I should point out that I closed my laptop last night. I didn't shutdown, I closed it so that it would go into hibernation mode. Upon starting it up today, the pc did an auto check disk before anything opened up. This was done in the DOS format of white text with black background.

    Finally, of course I will abide by the rules and try to quickly respond as best as I possibly can.
     
  14. 2012/01/22
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    So far I don't see much....

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    [color= "Blue"]**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**[/color]
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on [color= "Red"]this link[/color] to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • [color= "Red"]WARNING:[/color] Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results ". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion ", restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode (How to...)

    2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  15. 2012/01/23
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    ComboFix 12-01-23.02 - walmart 01/23/2012 21:20:44.5.2 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3002.1562 [GMT -5:00]
    Running from: c:\users\walmart\Desktop\ComboFix.exe
    AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
    FW: ZoneAlarm Free Firewall *Enabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
    SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\windows\system32\java.exe
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-12-24 to 2012-01-24 )))))))))))))))))))))))))))))))
    .
    .
    2012-01-24 02:31 . 2012-01-24 02:31 -------- d-----w- c:\users\Public\AppData\Local\temp
    2012-01-24 02:31 . 2012-01-24 02:31 -------- d-----w- c:\users\Default\AppData\Local\temp
    2012-01-24 02:31 . 2012-01-24 02:31 -------- d-----w- c:\users\AppData\AppData\Local\temp
    2012-01-22 18:36 . 2012-01-22 18:36 -------- d-----w- C:\found.000
    2012-01-20 17:12 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7DBD3E82-3BA8-47AB-B12C-38FE62882CF8}\mpengine.dll
    2012-01-11 04:29 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
    2012-01-11 04:29 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
    2012-01-11 04:29 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
    2012-01-11 04:29 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
    2012-01-11 04:29 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
    2012-01-11 04:29 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
    2012-01-11 04:29 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
    2012-01-11 04:29 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
    2011-12-29 01:13 . 2011-12-29 01:13 -------- d-----w- c:\program files\iPod
    2011-12-29 01:13 . 2011-12-29 01:14 -------- d-----w- c:\program files\iTunes
    2011-12-29 01:13 . 2011-12-29 01:14 -------- d-----w- c:\program files (x86)\iTunes
    2011-12-29 01:08 . 2011-12-29 01:08 -------- d-----w- c:\program files\Bonjour
    2011-12-29 01:08 . 2011-12-29 01:08 -------- d-----w- c:\program files (x86)\Bonjour
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-12-10 20:24 . 2011-11-17 21:35 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-11-28 18:01 . 2011-01-09 22:27 41184 ----a-w- c:\windows\avastSS.scr
    2011-11-28 18:01 . 2010-05-03 04:02 199816 ----a-w- c:\windows\SysWow64\aswBoot.exe
    2011-11-28 18:01 . 2011-02-05 20:05 256960 ----a-w- c:\windows\system32\aswBoot.exe
    2011-11-28 17:54 . 2011-04-18 20:34 591192 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2011-11-28 17:53 . 2010-05-03 04:02 304472 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2011-11-28 17:52 . 2010-05-03 04:02 42328 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2011-11-28 17:52 . 2010-05-03 04:02 58712 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2011-11-28 17:52 . 2010-05-03 04:02 66904 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
    2011-11-28 17:51 . 2010-05-03 04:02 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2011-11-24 04:52 . 2011-12-15 18:36 3145216 ----a-w- c:\windows\system32\win32k.sys
    2011-11-18 21:26 . 2011-11-18 20:46 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2011-11-15 19:29 . 2010-05-03 02:32 270720 ------w- c:\windows\system32\MpSigStub.exe
    2011-11-05 05:32 . 2011-12-15 18:36 2048 ----a-w- c:\windows\system32\tzres.dll
    2011-11-05 04:26 . 2011-12-15 18:36 2048 ----a-w- c:\windows\SysWow64\tzres.dll
    2011-11-04 01:53 . 2011-12-16 04:40 2309120 ----a-w- c:\windows\system32\jscript9.dll
    2011-11-04 01:44 . 2011-12-16 04:40 1390080 ----a-w- c:\windows\system32\wininet.dll
    2011-11-04 01:44 . 2011-12-16 04:40 1493504 ----a-w- c:\windows\system32\inetcpl.cpl
    2011-11-04 01:43 . 2011-11-04 01:43 627600 ----a-w- c:\windows\system32\deployJava1.dll
    2011-11-04 01:34 . 2011-12-16 04:40 2382848 ----a-w- c:\windows\system32\mshtml.tlb
    2011-11-03 22:47 . 2011-12-16 04:40 1798144 ----a-w- c:\windows\SysWow64\jscript9.dll
    2011-11-03 22:40 . 2011-12-16 04:40 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
    2011-11-03 22:39 . 2011-12-16 04:40 1127424 ----a-w- c:\windows\SysWow64\wininet.dll
    2011-11-03 22:31 . 2011-12-16 04:40 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
    2011-10-26 05:21 . 2011-12-15 18:36 43520 ----a-w- c:\windows\system32\csrsrv.dll
    .
    .
    ((((((((((((((((((((((((((((( SnapShot@2011-10-31_22.11.34 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2012-01-13 21:37 . 2011-11-17 05:28 96768 c:\windows\SysWOW64\sspicli.dll
    - 2011-06-27 01:39 . 2010-11-20 12:08 96768 c:\windows\SysWOW64\sspicli.dll
    - 2011-06-27 01:39 . 2010-11-20 12:21 22016 c:\windows\SysWOW64\secur32.dll
    + 2012-01-13 21:37 . 2011-11-17 05:34 22016 c:\windows\SysWOW64\secur32.dll
    - 2011-10-13 14:16 . 2011-09-01 02:23 72704 c:\windows\SysWOW64\mshtmled.dll
    + 2011-12-16 04:40 . 2011-11-03 22:32 72704 c:\windows\SysWOW64\mshtmled.dll
    + 2011-12-16 04:40 . 2011-11-03 22:37 66048 c:\windows\SysWOW64\migration\WininetPlugin.dll
    - 2011-10-13 14:16 . 2011-09-01 02:26 66048 c:\windows\SysWOW64\migration\WininetPlugin.dll
    + 2011-12-16 04:40 . 2011-11-03 22:37 65024 c:\windows\SysWOW64\jsproxy.dll
    - 2011-10-13 14:16 . 2011-09-01 02:26 65024 c:\windows\SysWOW64\jsproxy.dll
    + 2011-08-31 04:05 . 2011-08-31 04:05 73064 c:\windows\SysWOW64\dnssd.dll
    + 2011-08-31 04:05 . 2011-08-31 04:05 83816 c:\windows\SysWOW64\dns-sd.exe
    - 2009-07-14 04:54 . 2011-10-31 22:10 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-07-14 04:54 . 2012-01-24 02:33 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-07-14 04:54 . 2011-10-31 22:10 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2009-07-14 04:54 . 2012-01-24 02:33 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2009-07-14 04:54 . 2012-01-24 02:33 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-07-14 04:54 . 2011-10-31 22:10 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-11-05 17:49 . 2012-01-24 02:35 60506 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2009-07-14 05:10 . 2012-01-24 02:35 39506 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
    + 2012-01-13 21:37 . 2011-11-17 06:35 29184 c:\windows\system32\sspisrv.dll
    - 2011-06-27 01:40 . 2010-11-20 13:27 29184 c:\windows\system32\sspisrv.dll
    + 2009-11-05 18:01 . 2009-02-27 08:42 66440 c:\windows\system32\spool\drivers\x64\msonpui.dll
    - 2011-06-27 01:40 . 2010-11-20 13:27 28160 c:\windows\system32\secur32.dll
    + 2012-01-13 21:37 . 2011-11-17 06:35 28160 c:\windows\system32\secur32.dll
    - 2011-10-13 14:16 . 2011-09-01 05:12 96256 c:\windows\system32\mshtmled.dll
    + 2011-12-16 04:40 . 2011-11-04 01:35 96256 c:\windows\system32\mshtmled.dll
    + 2011-12-16 04:40 . 2011-11-04 01:41 86528 c:\windows\system32\migration\WininetPlugin.dll
    - 2011-10-13 14:16 . 2011-09-01 05:15 86528 c:\windows\system32\migration\WininetPlugin.dll
    - 2009-07-13 23:20 . 2009-07-14 01:39 31232 c:\windows\system32\lsass.exe
    + 2012-01-13 21:37 . 2011-11-17 06:33 31232 c:\windows\system32\lsass.exe
    - 2011-10-13 14:16 . 2011-09-01 05:15 85504 c:\windows\system32\jsproxy.dll
    + 2011-12-16 04:40 . 2011-11-04 01:41 85504 c:\windows\system32\jsproxy.dll
    + 2009-07-14 05:30 . 2011-12-29 01:11 86016 c:\windows\system32\DriverStore\infpub.dat
    - 2009-07-14 05:30 . 2011-07-13 07:05 86016 c:\windows\system32\DriverStore\infpub.dat
    + 2011-08-02 22:38 . 2011-08-02 22:38 51712 c:\windows\system32\DriverStore\FileRepository\usbaapl64.inf_amd64_neutral_f9d62789100b9e9b\usbaapl64.sys
    + 2011-08-01 20:59 . 2011-08-01 20:59 45416 c:\windows\system32\DriverStore\FileRepository\point64.inf_amd64_neutral_b1cf5e889e918ca6\point64.sys
    + 2011-08-01 20:59 . 2011-08-01 20:59 23960 c:\windows\system32\DriverStore\FileRepository\nuidfltr.inf_amd64_neutral_a071a87dc95c1c15\nuidfltr.sys
    + 2011-08-02 22:38 . 2011-08-02 22:38 22528 c:\windows\system32\DriverStore\FileRepository\netaapl64.inf_amd64_neutral_dc2cbd989eec1514\netaapl64.sys
    + 2011-07-28 23:37 . 2011-07-28 23:37 52584 c:\windows\system32\DriverStore\FileRepository\dc3du.inf_amd64_neutral_74c6c3670a9a8e89\dc3d.sys
    + 2011-08-01 20:59 . 2011-08-01 20:59 52584 c:\windows\system32\DriverStore\FileRepository\dc3dh.inf_amd64_neutral_73d3d011f5a03306\dc3d.sys
    + 2011-08-01 20:59 . 2011-08-01 20:59 45416 c:\windows\system32\drivers\point64.sys
    + 2012-01-13 21:37 . 2011-11-17 06:49 95600 c:\windows\system32\drivers\ksecdd.sys
    + 2011-08-31 04:05 . 2011-08-31 04:05 85864 c:\windows\system32\dnssd.dll
    + 2011-08-31 04:05 . 2011-08-31 04:05 96104 c:\windows\system32\dns-sd.exe
    - 2010-01-06 17:26 . 2011-10-30 22:47 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2010-01-06 17:26 . 2012-01-21 20:47 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2011-12-03 17:45 . 2012-01-21 20:47 49152 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2009-07-14 04:54 . 2011-10-30 22:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-07-14 04:54 . 2012-01-21 20:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-07-14 04:46 . 2012-01-18 17:03 94000 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
    + 2012-01-07 18:59 . 2011-12-25 20:40 43280 c:\windows\Microsoft.NET\Framework64\v2.0.50727\aspnet_wp.exe
    + 2012-01-07 18:59 . 2011-12-25 20:42 31504 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
    - 2011-10-13 14:21 . 2011-10-13 14:21 87408 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
    + 2012-01-08 22:02 . 2012-01-08 22:02 87408 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 93024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
    + 2012-01-08 22:02 . 2012-01-08 22:02 93024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
    + 2012-01-08 22:02 . 2012-01-08 22:02 35688 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 35688 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
    + 2012-01-08 22:02 . 2012-01-08 22:02 11120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 11120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
    + 2012-01-08 22:02 . 2012-01-08 22:02 17784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 17784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
    + 2012-01-08 22:02 . 2012-01-08 22:02 58240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 58240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 44920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 44920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 37240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 37240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 64352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 64352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 51032 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 51032 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 50552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 50552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 81784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 81784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 81800 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 81800 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 39784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 39784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 68952 c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 68952 c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 62880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.ApplicationServer.Applications\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Windows.ApplicationServer.Applications.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 62880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.ApplicationServer.Applications\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Windows.ApplicationServer.Applications.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 12128 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 12128 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 97680 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 97680 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 17240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 17240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 94552 c:\windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 94552 c:\windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 91488 c:\windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 91488 c:\windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    + 2012-01-08 22:00 . 2012-01-08 22:00 78168 c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    - 2011-10-13 14:20 . 2011-10-13 14:20 78168 c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    + 2012-01-08 22:00 . 2012-01-08 22:00 81248 c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    - 2011-10-13 14:20 . 2011-10-13 14:20 81248 c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    - 2011-09-22 15:49 . 2011-09-22 15:49 49936 c:\windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe
    + 2011-12-16 04:45 . 2011-12-16 04:45 49936 c:\windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe
    - 2009-11-05 18:01 . 2011-09-22 15:49 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
    + 2009-11-05 18:01 . 2011-12-16 04:45 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
    - 2009-11-05 18:01 . 2011-09-22 15:49 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
    + 2009-11-05 18:01 . 2011-12-16 04:45 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
    - 2009-11-05 18:01 . 2011-09-22 15:49 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
    + 2009-11-05 18:01 . 2011-12-16 04:45 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
    + 2011-12-16 04:45 . 2011-12-16 04:45 35600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
    - 2011-09-22 15:49 . 2011-09-22 15:49 35600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
    + 2010-06-08 16:19 . 2012-01-11 04:31 35088 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
    - 2010-06-08 16:19 . 2011-10-13 14:17 35088 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
    + 2010-06-08 16:19 . 2012-01-11 04:31 18704 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\mspicons.exe
    - 2010-06-08 16:19 . 2011-10-13 14:17 18704 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\mspicons.exe
    - 2010-06-08 16:19 . 2011-10-13 14:17 20240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\cagicon.exe
    + 2010-06-08 16:19 . 2012-01-11 04:31 20240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\cagicon.exe
    + 2011-11-19 20:22 . 2011-11-19 20:22 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
    + 2011-11-19 20:22 . 2011-11-19 20:22 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74.exe
    + 2011-11-19 20:22 . 2011-11-19 20:22 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
    + 2011-11-19 20:22 . 2011-11-19 20:22 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
    + 2011-11-19 20:22 . 2011-11-19 20:22 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\googleearth.exe1_F6A848FB884248E6A4CDCBDCF41F6A74.exe
    + 2011-11-19 20:22 . 2011-11-19 20:22 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\googleearth.exe_F6A848FB884248E6A4CDCBDCF41F6A74.exe
    + 2011-11-19 20:22 . 2011-11-19 20:22 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\ARPPRODUCTICON.exe
    + 2009-02-26 21:09 . 2009-02-26 21:09 10120 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\XLCALL32.DLL
    + 2009-02-27 02:43 . 2009-02-27 02:43 71520 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\XL12CNVP.DLL
    + 2009-02-27 01:45 . 2009-02-27 01:45 20808 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\WRD12EXE.EXE
    + 2006-07-24 18:50 . 2006-07-24 18:50 47920 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\VBAME.DLL
    + 2009-02-26 19:24 . 2009-02-26 19:24 71536 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ONFILTER.DLL
    + 2009-02-26 19:24 . 2009-02-26 19:24 97680 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ONENOTEM.EXE
    + 2006-07-24 18:50 . 2006-07-24 18:50 92976 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSADDNDR.DLL
    + 2009-04-02 20:01 . 2009-04-02 20:01 56680 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\EXP_XPS.DLL
    + 2009-04-04 02:46 . 2009-04-04 02:46 97640 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\EXP_PDF.DLL
    + 2006-10-27 04:13 . 2006-10-27 04:13 56192 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\ACECNFLT.EXE
    + 2009-02-26 21:09 . 2009-02-26 21:09 10120 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\XLCALL32.DLL
    + 2009-02-27 02:43 . 2009-02-27 02:43 71520 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\XL12CNVP.DLL
    + 2009-02-27 01:45 . 2009-02-27 01:45 20808 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\WRD12EXE.EXE
    + 2011-05-31 21:31 . 2011-05-31 21:31 32128 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\VPREVIEW.EXE
    + 2006-07-24 18:50 . 2006-07-24 18:50 47920 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\VBAME.DLL
    + 2011-07-20 10:17 . 2011-07-20 10:17 33152 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\SETLANG.EXE
    + 2011-07-27 09:53 . 2011-07-27 09:53 39464 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\REFIEBAR.DLL
    + 2009-02-27 00:21 . 2009-02-27 00:21 38224 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\REFEDIT.DLL
    + 2011-07-20 10:32 . 2011-07-20 10:32 47496 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\PUBTRAP.DLL
    + 2009-02-26 16:09 . 2009-02-26 16:09 43352 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\OUTLRPC.DLL
    + 2011-07-27 10:17 . 2011-07-27 10:17 22432 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\OISCTRL.DLL
    + 2011-07-27 10:25 . 2011-07-27 10:25 53728 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\OFFRHD.DLL
    + 2011-07-27 09:53 . 2011-07-27 09:53 64872 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\NAME.DLL
    + 2009-02-26 22:07 . 2009-02-26 22:07 67440 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSOHTMED.EXE
    + 2009-02-26 22:07 . 2009-02-26 22:07 75120 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSOHEV.DLL
    + 2009-02-27 00:21 . 2009-02-27 00:21 25968 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSOEURO.DLL
    + 2011-07-27 09:34 . 2011-07-27 09:34 13712 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSOCFU.DLL
    + 2006-07-24 18:50 . 2006-07-24 18:50 92976 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSADDNDR.DLL
    + 2009-02-26 16:09 . 2009-02-26 16:09 20352 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MLSHEXT.DLL
    + 2011-05-31 21:26 . 2011-05-31 21:26 88448 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\METCONV.DLL
    + 2011-07-27 22:49 . 2011-07-27 22:49 56696 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\EXP_XPS.DLL
    + 2011-07-27 22:49 . 2011-07-27 22:49 95608 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\EXP_PDF.DLL
    + 2009-02-26 22:07 . 2009-02-26 22:07 53120 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\AUTHZAX.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 55168 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACERCLR.DLL
    + 2009-02-26 16:18 . 2009-02-26 16:18 14192 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACEODTXT.DLL
    + 2009-02-26 16:18 . 2009-02-26 16:18 14192 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACEODPDX.DLL
    + 2009-02-26 16:18 . 2009-02-26 16:18 14192 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACEODEXL.DLL
    + 2009-02-26 16:18 . 2009-02-26 16:18 14192 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACEODDBS.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 47024 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACEERR.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 55240 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACECNFLT.EXE
    + 2010-06-08 16:17 . 2010-06-08 16:17 35648 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\OLCTLPIA.DLL
    + 2009-04-02 20:01 . 2009-04-02 20:01 56680 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\EXP_XPS.DLL
    + 2009-04-04 02:46 . 2009-04-04 02:46 97640 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\EXP_PDF.DLL
    + 2009-03-06 10:48 . 2009-03-06 10:48 55152 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\ACERCLR.DLL
    + 2006-10-27 04:13 . 2006-10-27 04:13 56192 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\ACECNFLT.EXE
    + 2012-01-09 22:39 . 2012-01-09 22:39 54784 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\6c13d7fb161ed4d7da730a70375b07c9\System.Web.DynamicData.Design.ni.dll
    + 2012-01-09 22:32 . 2012-01-09 22:32 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\94787ab3efcc074396a60ff3d83edf78\System.Web.DynamicData.Design.ni.dll
    + 2011-11-04 01:49 . 2011-11-04 01:49 11264 c:\windows\assembly\GAC_MSIL\cli_basetypes\1.0.18.0__ce2cb7e279207b9e\cli_basetypes.dll
    + 2011-11-04 01:49 . 2011-11-04 01:49 64000 c:\windows\assembly\GAC_32\cli_cppuhelper\1.0.21.0__ce2cb7e279207b9e\cli_cppuhelper.dll
    + 2011-11-18 21:40 . 2011-11-18 21:40 11144 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll
    - 2009-11-05 18:03 . 2009-11-05 18:03 63336 c:\windows\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
    + 2011-11-18 21:40 . 2011-11-18 21:40 63336 c:\windows\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
    + 2011-11-18 21:43 . 2011-11-18 21:43 34696 c:\windows\assembly\GAC\Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll
    + 2010-04-05 07:18 . 2011-12-28 22:07 7462 c:\windows\system32\wdi\ERCQueuedResolutions.dat
    + 2010-03-01 11:35 . 2012-01-24 02:35 9324
     
  16. 2012/01/23
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2631836602-637535096-2860635993-1000_UserData.bin
    + 2011-11-11 00:44 . 2011-11-11 00:44 9560 c:\windows\system32\NetworkList\Icons\{337E0821-7D1A-4531-A039-CABDDA8101DC}_48.bin
    + 2011-11-11 00:44 . 2011-11-11 00:44 4280 c:\windows\system32\NetworkList\Icons\{337E0821-7D1A-4531-A039-CABDDA8101DC}_32.bin
    + 2011-11-11 00:44 . 2011-11-11 00:44 2456 c:\windows\system32\NetworkList\Icons\{337E0821-7D1A-4531-A039-CABDDA8101DC}_24.bin
    + 2012-01-24 02:32 . 2012-01-24 02:32 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2011-10-31 22:10 . 2011-10-31 22:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    + 2012-01-24 02:32 . 2012-01-24 02:32 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    - 2011-10-31 22:10 . 2011-10-31 22:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2011-11-04 01:49 . 2011-11-04 01:49 3072 c:\windows\assembly\GAC_MSIL\policy.1.0.cli_uretypes\7.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_uretypes.dll
    + 2011-11-04 01:49 . 2011-11-04 01:49 3072 c:\windows\assembly\GAC_MSIL\policy.1.0.cli_ure\21.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_ure.dll
    + 2011-11-04 01:50 . 2011-11-04 01:50 3072 c:\windows\assembly\GAC_MSIL\policy.1.0.cli_oootypes\7.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_oootypes.dll
    + 2011-11-04 01:49 . 2011-11-04 01:49 3072 c:\windows\assembly\GAC_MSIL\policy.1.0.cli_basetypes\18.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_basetypes.dll
    + 2011-11-04 01:49 . 2011-11-04 01:49 7680 c:\windows\assembly\GAC_MSIL\cli_ure\1.0.21.0__ce2cb7e279207b9e\cli_ure.dll
    + 2011-11-04 01:50 . 2011-11-04 01:50 3072 c:\windows\assembly\GAC_32\policy.1.0.cli_cppuhelper\21.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_cppuhelper.dll
    + 2012-01-13 21:37 . 2011-11-17 05:35 314880 c:\windows\SysWOW64\webio.dll
    - 2011-06-27 01:42 . 2010-11-20 12:21 314880 c:\windows\SysWOW64\webio.dll
    - 2011-10-13 14:16 . 2011-09-01 02:27 231936 c:\windows\SysWOW64\url.dll
    + 2011-12-16 04:40 . 2011-11-03 22:38 231936 c:\windows\SysWOW64\url.dll
    + 2012-01-13 21:37 . 2011-11-17 05:34 224768 c:\windows\SysWOW64\schannel.dll
    + 2011-11-18 20:46 . 2011-11-18 21:26 247968 c:\windows\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe
    + 2011-11-18 20:46 . 2011-11-18 21:26 335520 c:\windows\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.dll
    - 2011-10-13 14:16 . 2011-09-01 02:24 716800 c:\windows\SysWOW64\jscript.dll
    + 2011-12-16 04:40 . 2011-11-03 22:34 716800 c:\windows\SysWOW64\jscript.dll
    - 2011-06-17 23:50 . 2011-05-04 08:52 157472 c:\windows\SysWOW64\javaws.exe
    + 2011-11-04 01:40 . 2011-10-03 09:06 157472 c:\windows\SysWOW64\javaws.exe
    - 2011-06-17 23:50 . 2011-05-04 08:52 145184 c:\windows\SysWOW64\javaw.exe
    + 2011-11-04 01:40 . 2011-10-03 09:06 145184 c:\windows\SysWOW64\javaw.exe
    - 2011-06-17 23:50 . 2011-05-04 08:52 145184 c:\windows\SysWOW64\java.exe
    + 2011-11-04 01:40 . 2011-10-03 09:06 145184 c:\windows\SysWOW64\java.exe
    - 2011-10-13 14:16 . 2011-09-01 02:21 176640 c:\windows\SysWOW64\ieui.dll
    + 2011-12-16 04:40 . 2011-11-03 22:28 176640 c:\windows\SysWOW64\ieui.dll
    + 2011-12-15 18:36 . 2011-10-15 05:38 534528 c:\windows\SysWOW64\EncDec.dll
    - 2011-03-09 22:29 . 2010-12-23 05:54 534528 c:\windows\SysWOW64\EncDec.dll
    - 2010-05-16 04:12 . 2011-05-04 08:52 472808 c:\windows\SysWOW64\deployJava1.dll
    + 2010-05-16 04:12 . 2011-10-03 09:06 472808 c:\windows\SysWOW64\deployJava1.dll
    + 2012-01-13 21:37 . 2011-11-17 06:35 395776 c:\windows\system32\webio.dll
    - 2011-06-27 01:42 . 2010-11-20 13:27 395776 c:\windows\system32\webio.dll
    + 2010-03-01 15:37 . 2011-12-09 16:00 232374 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin
    + 2011-12-16 04:40 . 2011-11-04 01:43 237056 c:\windows\system32\url.dll
    - 2011-10-13 14:16 . 2011-09-01 05:16 237056 c:\windows\system32\url.dll
    + 2012-01-13 21:37 . 2011-11-17 06:35 136192 c:\windows\system32\sspicli.dll
    - 2011-06-27 01:41 . 2010-11-20 13:27 136192 c:\windows\system32\sspicli.dll
    + 2009-11-05 18:01 . 2009-02-27 08:42 863128 c:\windows\system32\spool\drivers\x64\msonpdrv.dll
    + 2012-01-13 21:37 . 2011-11-17 06:35 340992 c:\windows\system32\schannel.dll
    - 2011-06-27 01:42 . 2010-11-20 13:27 340992 c:\windows\system32\schannel.dll
    - 2009-07-14 02:36 . 2011-10-13 14:20 624178 c:\windows\system32\perfh009.dat
    + 2009-07-14 02:36 . 2012-01-08 22:00 624178 c:\windows\system32\perfh009.dat
    - 2009-07-14 02:36 . 2011-10-13 14:20 106522 c:\windows\system32\perfc009.dat
    + 2009-07-14 02:36 . 2012-01-08 22:00 106522 c:\windows\system32\perfc009.dat
    + 2011-11-18 21:25 . 2011-11-18 21:26 461984 c:\windows\system32\Macromed\Flash\FlashUtil64_11_1_102_ActiveX.exe
    + 2011-11-18 21:25 . 2011-11-18 21:26 376480 c:\windows\system32\Macromed\Flash\FlashUtil64_11_1_102_ActiveX.dll
    + 2011-12-16 04:40 . 2011-11-04 01:39 818688 c:\windows\system32\jscript.dll
    + 2011-11-04 01:43 . 2011-11-04 01:43 252296 c:\windows\system32\javaws.exe
    + 2011-11-04 01:43 . 2011-11-04 01:43 188808 c:\windows\system32\javaw.exe
    + 2011-05-18 13:08 . 2011-05-18 13:08 465408 c:\windows\system32\ipcoin82.dll
    - 2011-10-13 14:16 . 2011-09-01 05:08 248320 c:\windows\system32\ieui.dll
    + 2011-12-16 04:40 . 2011-11-04 01:30 248320 c:\windows\system32\ieui.dll
    + 2009-07-14 04:45 . 2011-12-16 18:29 446032 c:\windows\system32\FNTCACHE.DAT
    + 2011-12-15 18:36 . 2011-10-15 06:31 723456 c:\windows\system32\EncDec.dll
    + 2009-07-14 05:30 . 2011-12-29 01:11 143360 c:\windows\system32\DriverStore\infstrng.dat
    - 2009-07-14 05:30 . 2011-07-13 07:05 143360 c:\windows\system32\DriverStore\infstrng.dat
    - 2009-07-14 05:30 . 2011-07-13 07:05 143360 c:\windows\system32\DriverStore\infstor.dat
    + 2009-07-14 05:30 . 2011-12-29 01:11 143360 c:\windows\system32\DriverStore\infstor.dat
    + 2011-05-07 22:51 . 2011-05-07 22:51 454232 c:\windows\system32\DriverStore\FileRepository\vsdatant.inf_amd64_neutral_0a0e8d9d2ce16ccc\vsdatant.sys
    + 2011-05-18 13:08 . 2011-05-18 13:08 465408 c:\windows\system32\DriverStore\FileRepository\ipcdless.inf_amd64_neutral_165412f37e9f9224\ipcoin82.dll
    + 2011-08-01 20:59 . 2011-08-01 20:59 470376 c:\windows\system32\DriverStore\FileRepository\dc3dh.inf_amd64_neutral_73d3d011f5a03306\ipcoin82.dll
    + 2011-05-07 22:51 . 2011-05-07 22:51 454232 c:\windows\system32\drivers\vsdatant.sys
    + 2012-01-13 21:37 . 2011-11-17 06:49 152432 c:\windows\system32\drivers\ksecpkg.sys
    + 2012-01-13 21:37 . 2011-11-17 06:44 459232 c:\windows\system32\drivers\cng.sys
    + 2009-07-14 05:01 . 2012-01-24 02:32 442940 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    + 2011-12-26 10:47 . 2011-12-26 10:47 261912 c:\windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelReg.exe
    + 2012-01-07 18:59 . 2011-12-25 20:40 746256 c:\windows\Microsoft.NET\Framework64\v2.0.50727\webengine.dll
    + 2011-12-26 09:39 . 2011-12-26 09:39 192792 c:\windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelReg.exe
    + 2012-01-07 18:59 . 2011-12-25 20:42 437520 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
    + 2012-01-08 22:02 . 2012-01-08 22:02 350592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 350592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 163168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
    + 2012-01-08 22:02 . 2012-01-08 22:02 163168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 138592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 138592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 699224 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 699224 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 857960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 857960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 675672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 675672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 113512 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 113512 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 129912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 129912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 390008 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 390008 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 505208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 505208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 261472 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 261472 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 122264 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 122264 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 291184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 291184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 349568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 349568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 236880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 236880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 253280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 253280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 378720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 378720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 134528 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 134528 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 123736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 123736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 392552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 392552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 125816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 125816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 120152 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 120152 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 607064 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 607064 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 395120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 395120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 182144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 182144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 285072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 285072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 829280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 829280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 747360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 747360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 436600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 436600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 683872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 683872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 409448 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 409448 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 210816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 210816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 149848 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 149848 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 122248 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 122248 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 525704 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 525704 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 112976 c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 112976 c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 581464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
    + 2012-01-08 22:02 . 2012-01-08 22:02 581464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 832856 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
    + 2012-01-08 22:02 . 2012-01-08 22:02 832856 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
    + 2012-01-08 22:02 . 2012-01-08 22:02 194424 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 194424 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
    + 2012-01-08 22:02 . 2012-01-08 22:02 478576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 478576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 167288 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
    + 2012-01-08 22:02 . 2012-01-08 22:02 167288 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 232304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
    + 2012-01-08 22:02 . 2012-01-08 22:02 232304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 661352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 661352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 349576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 349576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 387960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 387960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 746336 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 746336 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 505184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 505184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 288616 c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 288616 c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 335712 c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 335712 c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 125440 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 125440 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 237424 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 237424 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 187776 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 187776 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 269672 c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 269672 c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 334688 c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 334688 c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
    + 2012-01-08 22:00 . 2012-01-08 22:00 109568 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    - 2011-10-13 14:20 . 2011-10-13 14:20 109568 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    - 2011-10-13 14:20 . 2011-10-13 14:20 246128 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    + 2012-01-08 22:00 . 2012-01-08 22:00 246128 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 170368 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 170368 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    + 2011-11-04 01:42 . 2011-11-04 01:42 973312 c:\windows\Installer\9e49f.msi
    + 2011-11-04 01:41 . 2011-11-04 01:41 207360 c:\windows\Installer\9e49b.msi
    + 2011-12-29 01:08 . 2011-12-29 01:08 897024 c:\windows\Installer\{F2AF3E5D-9697-485C-A5AC-E2B9468C446A}\SafariIco.exe
    + 2011-12-29 01:14 . 2011-12-29 01:14 380928 c:\windows\Installer\{D66F0C3C-24F2-4463-9E2F-4381E5C40A26}\iTunesIco.exe
    + 2009-11-05 18:01 . 2011-12-16 04:45 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
    - 2009-11-05 18:01 . 2011-09-22 15:49 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
    + 2009-11-05 18:01 . 2011-12-16 04:45 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
    - 2009-11-05 18:01 . 2011-09-22 15:49 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
    - 2009-11-05 18:01 . 2011-09-22 15:49 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
    + 2009-11-05 18:01 . 2011-12-16 04:45 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
    + 2009-11-05 18:01 . 2011-12-16 04:45 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
    - 2009-11-05 18:01 . 2011-09-22 15:49 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
    + 2011-11-18 21:39 . 2011-11-18 21:39 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
    - 2010-03-10 11:04 . 2010-03-10 11:04 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
    - 2010-06-08 16:19 . 2011-10-13 14:17 888080 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
    + 2010-06-08 16:19 . 2012-01-11 04:31 888080 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
    - 2010-06-08 16:19 . 2011-10-13 14:17 272648 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pubs.exe
    + 2010-06-08 16:19 . 2012-01-11 04:31 272648 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pubs.exe
    + 2010-06-08 16:19 . 2012-01-11 04:31 922384 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pptico.exe
    - 2010-06-08 16:19 . 2011-10-13 14:17 922384 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pptico.exe
    + 2010-06-08 16:19 . 2012-01-11 04:31 845584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
    - 2010-06-08 16:19 . 2011-10-13 14:17 845584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
    + 2010-06-08 16:19 . 2012-01-11 04:31 217864 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\misc.exe
    - 2010-06-08 16:19 . 2011-10-13 14:17 217864 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\misc.exe
    - 2010-06-08 16:19 . 2011-10-13 14:17 159504 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\inficon.exe
    + 2010-06-08 16:19 . 2012-01-11 04:31 159504 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\inficon.exe
    + 2011-09-14 09:54 . 2011-09-14 09:54 236904 c:\windows\Installer\$PatchCache$\Managed\638401577CACE4443AE9F3455191245F\4.0.0\OutlookChangeNotifierAddIn_x64.dll
    + 2011-09-14 09:54 . 2011-09-14 09:54 227176 c:\windows\Installer\$PatchCache$\Managed\638401577CACE4443AE9F3455191245F\4.0.0\OutlookChangeNotifierAddIn.dll
    + 2009-02-26 22:45 . 2009-02-26 22:45 509256 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\WRD12CVR.DLL
    + 2011-05-31 20:58 . 2011-05-31 20:58 521080 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\POWERPNT.EXE
    + 2007-06-08 03:51 . 2007-06-08 03:51 465800 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OUTLFLTR.DLL
    + 2008-03-19 14:27 . 2008-03-19 14:27 661536 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OGALEGIT.DLL
    + 2006-07-24 18:50 . 2006-07-24 18:50 125744 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSSTDFMT.DLL
    + 2006-10-27 04:13 . 2006-10-27 04:13 764800 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\ACECNF.DLL
    + 2009-02-26 22:45 . 2009-02-26 22:45 509256 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\WRD12CVR.DLL
    + 2011-09-16 01:41 . 2011-09-16 01:41 408936 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\WINWORD.EXE
    + 2007-06-07 23:51 . 2007-06-07 23:51 125320 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\SSGEN.DLL
    + 2011-07-27 09:58 . 2011-07-27 09:58 439160 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\SETUP.EXE
    + 2011-07-27 09:54 . 2011-07-27 09:54 503184 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\SELFCERT.EXE
    + 2011-07-20 10:32 . 2011-07-20 10:32 593288 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\PUBCONV.DLL
    + 2011-07-27 09:42 . 2011-07-27 09:42 625040 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\PTXT9.DLL
    + 2011-07-20 10:32 . 2011-07-20 10:32 135056 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\PRTF9.DLL
    + 2011-05-27 02:13 . 2011-05-27 02:13 368520 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\PPSLAX.DLL
    + 2011-05-31 20:58 . 2011-05-31 20:58 521080 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\POWERPNT.EXE
    + 2011-07-27 09:36 . 2011-07-27 09:36 481640 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\PORTCONN.DLL
    + 2007-06-08 03:51 . 2007-06-08 03:51 465800 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\OUTLFLTR.DLL
    + 2011-07-27 10:17 . 2011-07-27 10:17 284560 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\OISGRAPH.DLL
    + 2011-07-27 10:16 . 2011-07-27 10:16 997768 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\OISAPP.DLL
    + 2011-07-27 10:16 . 2011-07-27 10:16 273792 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\OIS.EXE
    + 2008-03-19 14:27 . 2008-03-19 14:27 661536 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\OGALEGIT.DLL
    + 2009-02-26 20:24 . 2009-02-26 20:24 231864 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ODEPLOY.EXE
    + 2011-07-20 10:22 . 2011-07-20 10:22 538968 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSTORES.DLL
    + 2011-07-20 10:22 . 2011-07-20 10:22 144728 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSTORE.EXE
    + 2011-07-20 10:22 . 2011-07-20 10:22 832360 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSTORDB.EXE
    + 2006-07-24 18:50 . 2006-07-24 18:50 125744 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSSTDFMT.DLL
    + 2009-02-26 03:02 . 2009-02-26 03:02 504176 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSSOAP30.DLL
    + 2011-07-27 11:10 . 2011-07-27 11:10 670560 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSQRY32.EXE
    + 2011-05-31 22:19 . 2011-05-31 22:19 732000 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSPROOF6.DLL
    + 2009-02-26 02:46 . 2009-02-26 02:46 435568 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSORUN.DLL
    + 2011-07-27 09:53 . 2011-07-27 09:53 427856 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSODCW.DLL
    + 2011-07-27 09:34 . 2011-07-27 09:34 160632 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSOCF.DLL
    + 2011-06-23 14:54 . 2011-06-23 14:54 119160 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSCONV97.DLL
    + 2011-07-27 09:42 . 2011-07-27 09:42 497056 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MORPH9.DLL
    + 2011-07-20 10:22 . 2011-07-20 10:22 828264 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MEDCAT.DLL
    + 2011-07-27 22:49 . 2011-07-27 22:49 177536 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\IETAG.DLL
    + 2009-02-26 20:24 . 2009-02-26 20:24 970128 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\FPWEC.DLL
    + 2009-02-26 16:09 . 2009-02-26 16:09 154000 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ENVELOPE.DLL
    + 2011-07-27 10:13 . 2011-07-27 10:13 434080 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\DWTRIG20.EXE
    + 2011-07-27 09:53 . 2011-07-27 09:53 105872 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\DSSM.EXE
    + 2011-07-27 09:53 . 2011-07-27 09:53 188800 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\CONTACTPICKER.DLL
    + 2011-07-27 11:13 . 2011-07-27 11:13 204664 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\CLVIEW.EXE
    + 2011-07-27 11:20 . 2011-07-27 11:20 400216 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\CDLMSO.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 370608 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACEXBE.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 223152 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACETXT.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 550840 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACEREP.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 288688 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACER3X.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 255920 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACER2X.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 391096 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACEPDE.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 378808 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACEOLEDB.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 278912 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACEODBC.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 206776 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACELTS.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 632752 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACEEXCL.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 337848 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACEEXCH.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 186304 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACEES.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 571320 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACEDAO.DLL
    + 2011-07-27 09:41 . 2011-07-27 09:41 763848 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACECNF.DLL
    + 2006-10-27 19:35 . 2006-10-27 19:35 436512 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\UMOUTLOOKADDIN.DLL
    + 2006-10-27 04:13 . 2006-10-27 04:13 764800 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\ACECNF.DLL
    + 2008-10-25 08:51 . 2008-10-25 08:51 844696 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.4518\OICE.EXE
    + 2012-01-11 04:29 . 2011-10-29 05:23 465920 c:\windows\ehome\mstvcapn.dll
    - 2011-06-27 01:41 . 2010-11-20 13:27 465920 c:\windows\ehome\mstvcapn.dll
     
  17. 2012/01/23
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    + 2012-01-09 22:39 . 2012-01-09 22:39 187392 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Routing\f715b47c2f0440ea23a71f1076b0af2b\System.Web.Routing.ni.dll
    + 2012-01-09 22:39 . 2012-01-09 22:39 449024 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity\d258f45340e6e538a19a56d1165b750f\System.Web.Entity.ni.dll
    + 2012-01-09 22:39 . 2012-01-09 22:39 398848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity.D#\6f6d11e33e2f3f6bddd4c33809340a48\System.Web.Entity.Design.ni.dll
    + 2012-01-09 22:39 . 2012-01-09 22:39 753664 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\bca38e802e2b45f80f8fbde2b54ce0a2\System.Web.DynamicData.ni.dll
    + 2012-01-09 22:38 . 2012-01-09 22:38 204800 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Abstract#\0e411c30fc2caebb55813b8fa0689d42\System.Web.Abstractions.ni.dll
    + 2012-01-09 22:30 . 2012-01-09 22:30 634368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\3ce94143060c3c8c9962f2160e908d8c\WindowsLiveLocal.WriterPlugin.ni.dll
    + 2012-01-09 22:30 . 2012-01-09 22:30 156672 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\dcc5d5ba905f05acef59b46aab72d78b\WindowsLive.Writer.HtmlParser.ni.dll
    + 2012-01-09 22:30 . 2012-01-09 22:30 871424 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\cdd1b8e0dbca86ad17055586dc2e5869\WindowsLive.Writer.BlogClient.ni.dll
    + 2012-01-09 22:30 . 2012-01-09 22:30 891392 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\6cd04e54bc2f43a62c5968e7a1924eb4\WindowsLive.Writer.HtmlEditor.ni.dll
    + 2012-01-09 22:32 . 2012-01-09 22:32 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\8e576ae7d946a5440bddfdbe06818a8b\System.Web.Routing.ni.dll
    + 2012-01-09 22:32 . 2012-01-09 22:32 860160 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\5bd4f855a0b0386cb4baf093216ad2d3\System.Web.Extensions.Design.ni.dll
    + 2012-01-09 22:32 . 2012-01-09 22:32 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\8d56e2f2a05dbde707d87cb3bdf0dffc\System.Web.Entity.ni.dll
    + 2012-01-09 22:32 . 2012-01-09 22:32 301568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\f560658d9ee6d2786cab976e775758d6\System.Web.Entity.Design.ni.dll
    + 2012-01-09 22:32 . 2012-01-09 22:32 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\e94f08faeb08a8ee9d51a3480083bd07\System.Web.DynamicData.ni.dll
    + 2012-01-09 22:32 . 2012-01-09 22:32 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\2dc7ec41005f6e6fe45e0cc0a20a12bc\System.Web.Abstractions.ni.dll
    + 2012-01-08 22:07 . 2012-01-08 22:07 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b559a471eef00081f0b5c2719d1d9623\System.Runtime.Remoting.ni.dll
    + 2012-01-09 22:32 . 2012-01-09 22:32 763392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\e6fa2be533d9e540ccafe51980ae0103\System.Data.Entity.Design.ni.dll
    + 2011-11-18 21:43 . 2011-11-18 21:43 608136 c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll
    + 2011-11-04 01:49 . 2011-11-04 01:49 118784 c:\windows\assembly\GAC_MSIL\cli_uretypes\1.0.7.0__ce2cb7e279207b9e\cli_uretypes.dll
    + 2011-11-04 01:49 . 2011-11-04 01:49 892928 c:\windows\assembly\GAC_MSIL\cli_oootypes\1.0.7.0__ce2cb7e279207b9e\cli_oootypes.dll
    + 2011-11-18 21:43 . 2011-11-18 21:43 117160 c:\windows\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
    - 2009-11-05 18:03 . 2009-11-05 18:03 870256 c:\windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
    + 2011-11-18 21:40 . 2011-11-18 21:40 870256 c:\windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
    + 2011-11-18 21:41 . 2011-11-18 21:41 350080 c:\windows\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
    + 2011-11-18 21:40 . 2011-11-18 21:40 149368 c:\windows\assembly\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
    + 2011-12-16 04:40 . 2011-11-03 22:40 1103360 c:\windows\SysWOW64\urlmon.dll
    + 2011-12-16 04:40 . 2011-11-03 22:32 1792000 c:\windows\SysWOW64\iertutil.dll
    + 2011-12-16 04:40 . 2011-11-03 22:46 9705472 c:\windows\SysWOW64\ieframe.dll
    + 2011-04-13 22:40 . 2011-04-13 22:40 4284416 c:\windows\SysWOW64\GPhotos.scr
    + 2011-07-07 07:28 . 2011-07-07 07:28 1193320 c:\windows\SysWOW64\FM20.DLL
    + 2011-12-16 04:40 . 2011-11-04 01:46 1345536 c:\windows\system32\urlmon.dll
    + 2012-01-13 21:37 . 2011-11-17 06:35 1447936 c:\windows\system32\lsasrv.dll
    - 2011-06-27 01:42 . 2010-11-20 13:26 1447936 c:\windows\system32\lsasrv.dll
    + 2011-12-16 04:40 . 2011-11-04 01:36 2144256 c:\windows\system32\iertutil.dll
    + 2011-08-02 22:38 . 2011-08-02 22:38 4517664 c:\windows\system32\DriverStore\FileRepository\usbaapl64.inf_amd64_neutral_f9d62789100b9e9b\usbaaplrc.dll
    + 2011-08-01 20:59 . 2011-08-01 20:59 1721576 c:\windows\system32\DriverStore\FileRepository\point64.inf_amd64_neutral_b1cf5e889e918ca6\wdfcoinstaller01009.dll
    + 2011-08-01 20:59 . 2011-08-01 20:59 1721576 c:\windows\system32\DriverStore\FileRepository\nuidfltr.inf_amd64_neutral_a071a87dc95c1c15\wdfcoinstaller01009.dll
    + 2010-04-19 23:29 . 2010-04-19 23:29 1721576 c:\windows\system32\DriverStore\FileRepository\netaapl64.inf_amd64_neutral_dc2cbd989eec1514\wdfcoinstaller01009.dll
    + 2011-07-28 23:37 . 2011-07-28 23:37 1721576 c:\windows\system32\DriverStore\FileRepository\dc3du.inf_amd64_neutral_74c6c3670a9a8e89\WdfCoInstaller01009.dll
    + 2011-08-01 20:59 . 2011-08-01 20:59 1721576 c:\windows\system32\DriverStore\FileRepository\dc3dh.inf_amd64_neutral_73d3d011f5a03306\WdfCoInstaller01009.dll
    + 2011-11-09 21:31 . 2011-09-29 16:29 1923952 c:\windows\system32\drivers\tcpip.sys
    + 2009-07-14 04:45 . 2012-01-15 19:50 7113171 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
    - 2009-07-14 04:45 . 2011-10-26 14:49 7113171 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
    + 2011-06-27 08:10 . 2012-01-23 23:59 2627828 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2631836602-637535096-2860635993-1000-12288.dat
    + 2012-01-07 18:59 . 2011-12-25 20:40 5263360 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Web.dll
    + 2012-01-07 18:59 . 2011-12-25 20:42 5255168 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 1368920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
    + 2012-01-08 22:02 . 2012-01-08 22:02 1368920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 3510600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 3510600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 2207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 2207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 5028200 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 5028200 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 1711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 1711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 6097256 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 6097256 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 1026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 1026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 4464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 4464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 1354584 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 1354584 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 1199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 1199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 1462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 1462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 6428520 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 6428520 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 3116376 c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 3116376 c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 3824480 c:\windows\Microsoft.NET\assembly\GAC_64\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 3824480 c:\windows\Microsoft.NET\assembly\GAC_64\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 4967248 c:\windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 4967248 c:\windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 3563408 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 3563408 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
    - 2011-10-13 14:20 . 2011-10-13 14:20 2975064 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
    + 2012-01-08 22:00 . 2012-01-08 22:00 2975064 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 3788128 c:\windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 3788128 c:\windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
    - 2011-10-13 14:20 . 2011-10-13 14:20 5197648 c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
    + 2012-01-08 22:00 . 2012-01-08 22:00 5197648 c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
    + 2012-01-08 22:01 . 2012-01-08 22:01 2989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
    - 2011-10-13 14:21 . 2011-10-13 14:21 2989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
    + 2011-12-29 01:07 . 2011-12-29 01:07 2682368 c:\windows\Installer\a33c44.msi
    + 2011-01-18 09:06 . 2011-01-18 09:06 2994176 c:\windows\Installer\9f28c.msi
    + 2011-11-10 23:00 . 2011-11-10 23:00 2887680 c:\windows\Installer\51793.msi
    + 2011-11-10 23:01 . 2011-11-10 23:01 4893696 c:\windows\Installer\5178e.msi
    + 2011-11-10 23:01 . 2011-11-10 23:01 9885696 c:\windows\Installer\51789.msi
    + 2011-11-01 18:34 . 2011-11-01 18:34 1552384 c:\windows\Installer\4d7ae361.msp
    + 2011-11-01 18:34 . 2011-11-01 18:34 4250112 c:\windows\Installer\4d7ae338.msp
    + 2011-11-01 18:34 . 2011-11-01 18:34 2247168 c:\windows\Installer\4d7ae300.msp
    + 2011-11-11 21:14 . 2011-11-11 21:14 9096192 c:\windows\Installer\4d7ae2dd.msp
    + 2011-11-01 18:34 . 2011-11-01 18:34 4225536 c:\windows\Installer\4d7ae2cc.msp
    + 2011-11-01 18:34 . 2011-11-01 18:34 2531840 c:\windows\Installer\4d7ae28c.msp
    + 2011-11-11 21:15 . 2011-11-11 21:15 1795584 c:\windows\Installer\4d7ae272.msp
    + 2011-11-11 21:16 . 2011-11-11 21:16 8458240 c:\windows\Installer\4d7ae240.msp
    + 2011-10-17 18:26 . 2011-10-17 18:26 1437184 c:\windows\Installer\4be7e99.msi
    + 2011-09-15 23:40 . 2011-09-15 23:40 7959552 c:\windows\Installer\3132d4.msp
    + 2011-09-15 23:34 . 2011-09-15 23:34 8499712 c:\windows\Installer\3132b6.msp
    + 2011-09-15 23:35 . 2011-09-15 23:35 1411072 c:\windows\Installer\312fcc.msp
    + 2011-08-01 20:59 . 2011-08-01 20:59 1978368 c:\windows\Installer\2fa52.msi
    + 2011-08-01 20:59 . 2011-08-01 20:59 2081792 c:\windows\Installer\2f8c4.msi
    + 2011-12-09 00:24 . 2011-12-09 00:24 4989952 c:\windows\Installer\2e921701.msp
    + 2011-12-26 11:24 . 2011-12-26 11:24 8835072 c:\windows\Installer\22de6d70.msp
    + 2009-11-05 18:01 . 2011-12-16 04:45 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
    - 2009-11-05 18:01 . 2011-09-22 15:49 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
    + 2010-06-08 16:19 . 2012-01-11 04:31 1172240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
    - 2010-06-08 16:19 . 2011-10-13 14:17 1172240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
    - 2010-06-08 16:19 . 2011-10-13 14:17 1165584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
    + 2010-06-08 16:19 . 2012-01-11 04:31 1165584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
    + 2011-08-17 14:49 . 2011-08-17 14:49 4683624 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\WRD12CNV.DLL
    + 2009-10-10 03:10 . 2009-10-10 03:10 2594632 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\VBE6.DLL
    + 2011-05-31 22:24 . 2011-05-31 22:24 2014592 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\PPTVIEW.EXE
    + 2011-07-27 09:44 . 2011-07-27 09:44 8494968 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\PPCORE.DLL
    + 2011-07-07 07:58 . 2011-07-07 07:58 1616240 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OGL.DLL
    + 2011-08-03 05:14 . 2011-08-03 05:14 8579448 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OARTCONV.DLL
    + 2011-07-27 10:47 . 2011-07-27 10:47 2532736 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\GRAPH.EXE
    + 2006-10-27 04:25 . 2006-10-27 04:25 2172688 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\PSRCHFEA.DLL
    + 2011-08-17 14:49 . 2011-08-17 14:49 4683624 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\WRD12CNV.DLL
    + 2011-07-20 13:12 . 2011-07-20 13:12 3750776 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\VVIEWER.DLL
    + 2011-06-29 12:02 . 2011-06-29 12:02 1846656 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\VVIEWDWG.DLL
    + 2009-10-10 03:10 . 2009-10-10 03:10 2594632 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\VBE6.DLL
    + 2011-07-27 23:15 . 2011-07-27 23:15 2335648 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\STSLIST.DLL
    + 2011-05-31 22:24 . 2011-05-31 22:24 2014592 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\PPTVIEW.EXE
    + 2011-07-27 09:44 . 2011-07-27 09:44 8494968 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\PPCORE.DLL
    + 2011-07-27 09:59 . 2011-07-27 09:59 6540136 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\OSETUP.DLL
    + 2011-07-07 07:58 . 2011-07-07 07:58 1616240 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\OGL.DLL
    + 2011-07-27 10:51 . 2011-07-27 10:51 7040896 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\OFFOWC.DLL
    + 2011-08-03 05:14 . 2011-08-03 05:14 8579448 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\OARTCONV.DLL
    + 2011-07-20 10:31 . 2011-07-20 10:31 1523632 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\NLSD0000.DLL
    + 2011-07-27 09:42 . 2011-07-27 09:42 9596784 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSPUB.EXE
    + 2011-05-27 00:28 . 2011-05-27 00:28 6637952 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSORES.DLL
    + 2011-07-27 10:09 . 2011-07-27 10:09 5310848 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\IPEDITOR.DLL
    + 2011-07-27 10:47 . 2011-07-27 10:47 2532736 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\GRAPH.EXE
    + 2011-06-22 13:16 . 2011-06-22 13:16 1681784 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\FPSRVUTL.DLL
    + 2011-07-07 07:28 . 2011-07-07 07:28 1193320 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\FM20.DLL
    + 2011-08-03 23:27 . 2011-08-03 23:27 1415072 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\ACECORE.DLL
    + 2011-07-27 09:44 . 2011-07-27 09:44 1791824 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6612\PPCNV.DLL
    + 2012-01-09 22:39 . 2012-01-09 22:39 1818112 c:\windows\assembly\NativeImages_v2.0.50727_64\System.WorkflowServ#\455567dae39910d806447b77ee657a85\System.WorkflowServices.ni.dll
    + 2012-01-08 22:06 . 2012-01-08 22:06 2711040 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Run#\45339e741d73e8f1f9393df8163c8c00\System.Workflow.Runtime.ni.dll
    + 2012-01-08 22:06 . 2012-01-08 22:06 5957632 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Com#\48ef2f59740ad3d438d0514b335dd334\System.Workflow.ComponentModel.ni.dll
    + 2012-01-08 22:06 . 2012-01-08 22:06 3895296 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Act#\7972e04df268430da009e63e90ff4ca9\System.Workflow.Activities.ni.dll
    + 2012-01-08 22:05 . 2012-01-08 22:05 2292224 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Services\8d374a0a9c49f485a7ce6e89ec354b4c\System.Web.Services.ni.dll
    + 2012-01-09 22:39 . 2012-01-09 22:39 3336704 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Mobile\91ecefc70d74ed44e5139ea2929adbb8\System.Web.Mobile.ni.dll
    + 2012-01-09 22:38 . 2012-01-09 22:38 3044352 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\71da5a6d09e12eb94be32935e4a8d5a2\System.Web.Extensions.ni.dll
    + 2012-01-09 22:39 . 2012-01-09 22:39 1155072 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\2bb91a2edcc92d2bb79007e7d2ddc2ae\System.Web.Extensions.Design.ni.dll
    + 2012-01-09 22:38 . 2012-01-09 22:38 2312704 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel#\3a6ac85c04453976c0f3a7c6a64ec43a\System.ServiceModel.Web.ni.dll
    + 2012-01-08 22:04 . 2012-01-08 22:04 1022976 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Remo#\d12c2299179cb05591cf08c8712a6495\System.Runtime.Remoting.ni.dll
    + 2012-01-09 22:35 . 2012-01-09 22:35 1444352 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityModel\1f90d38a42906a776be313d9720e350d\System.IdentityModel.ni.dll
    + 2012-01-09 22:38 . 2012-01-09 22:38 2805760 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Services\1d2c369d8e2d6f95c99ca90aca273418\System.Data.Services.ni.dll
    + 2012-01-09 22:38 . 2012-01-09 22:38 1080320 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity.#\b7bd7d91dc9abd73f2506bb7a0292373\System.Data.Entity.Design.ni.dll
    + 2012-01-09 22:37 . 2012-01-09 22:37 7970304 c:\windows\assembly\NativeImages_v2.0.50727_64\MIGUIControls\53fcf7f34708a9482d3e4059ce29608c\MIGUIControls.ni.dll
    + 2012-01-09 22:37 . 2012-01-09 22:37 2131968 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\486ff8cee09c8c63aa9c60ff4f5feafa\Microsoft.VisualBasic.ni.dll
    + 2012-01-09 22:37 . 2012-01-09 22:37 2176512 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\b68f19bf3f3d545547d2b680eb54a660\Microsoft.PowerShell.Commands.Utility.ni.dll
    + 2012-01-09 22:35 . 2012-01-09 22:35 8979456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\7e81f50c34dec17b90bfebec5929853a\Microsoft.MediaCenter.UI.ni.dll
    + 2012-01-09 22:35 . 2012-01-09 22:35 1516544 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\65a892a923b49b062bd8fc97254940d3\Microsoft.MediaCenter.ni.dll
    + 2012-01-09 22:37 . 2012-01-09 22:37 1508864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\33fd1381f221898a53253303cb7e5380\Microsoft.MediaCenter.Bml.ni.dll
    + 2012-01-09 22:30 . 2012-01-09 22:30 7025152 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f41e64e045cd090194cb0d841be0c9b6\WindowsLive.Writer.PostEditor.ni.dll
    + 2012-01-09 22:30 . 2012-01-09 22:30 2193408 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f07f84522a403885f7de2b26d57bc592\WindowsLive.Writer.CoreServices.ni.dll
    + 2012-01-09 22:32 . 2012-01-09 22:32 1358336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\a612958eaf641f0ba83b0daae44cb7b1\System.WorkflowServices.ni.dll
    + 2012-01-08 22:07 . 2012-01-08 22:07 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\ad68aa9e6fa1ec8005e1f604579a76be\System.Workflow.Runtime.ni.dll
    + 2012-01-08 22:07 . 2012-01-08 22:07 4515840 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\00b0a14ef5cb0154db7989da39a7f1e5\System.Workflow.ComponentModel.ni.dll
    + 2012-01-08 22:07 . 2012-01-08 22:07 2995200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\54873f241a4ad6d2a13e48d2da444538\System.Workflow.Activities.ni.dll
    + 2012-01-08 22:07 . 2012-01-08 22:07 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\be4f1d78d06979df7fd08dedf0d8c804\System.Web.Services.ni.dll
    + 2012-01-09 22:32 . 2012-01-09 22:32 2209792 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\d957ec1fb12ff02282a7f73d6318b66b\System.Web.Mobile.ni.dll
    + 2012-01-09 22:32 . 2012-01-09 22:32 2404352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\a90f033a5a062ff29f7df8f9edc1a80c\System.Web.Extensions.ni.dll
    + 2012-01-09 22:32 . 2012-01-09 22:32 1707008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\828e31a37bfd9d432083be6307845630\System.ServiceModel.Web.ni.dll
    + 2012-01-09 22:30 . 2012-01-09 22:30 1083392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\c0d9df88f2b37d14cf416281364c5b7f\System.IdentityModel.ni.dll
    + 2012-01-09 22:32 . 2012-01-09 22:32 2029568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\76e676a9b6387aad5544d61a4ac12a78\System.Data.Services.ni.dll
    + 2012-01-09 22:31 . 2012-01-09 22:31 6438912 c:\windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls\20d18697deb8413c01119531c6b987ad\MIGUIControls.ni.dll
    + 2012-01-09 22:31 . 2012-01-09 22:31 1670144 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\dd759df05fad8dc6d3404e8e02b40819\Microsoft.VisualBasic.ni.dll
    + 2012-01-09 22:31 . 2012-01-09 22:31 1681920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\695508ea67706e5f66208cabe5363099\Microsoft.PowerShell.Commands.Utility.ni.dll
    + 2012-01-09 22:31 . 2012-01-09 22:31 1009664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\5662462cfa995c71817791af93686db2\Microsoft.MediaCenter.ni.dll
    + 2012-01-09 22:31 . 2012-01-09 22:31 6499840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\4676e3f99469bd1120f8aed9cf37e4d2\Microsoft.MediaCenter.UI.ni.dll
    - 2011-06-27 01:42 . 2010-11-05 01:53 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
    + 2012-01-07 18:59 . 2011-12-25 20:42 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
    + 2012-01-07 18:59 . 2011-12-25 20:40 5263360 c:\windows\assembly\GAC_64\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
    + 2012-01-07 18:59 . 2011-12-25 20:42 5255168 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
    + 2011-11-18 21:40 . 2011-11-18 21:40 1279864 c:\windows\assembly\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
    + 2011-11-10 14:49 . 2011-08-30 04:21 12872704 c:\windows\SysWOW64\shell32.dll
    + 2011-12-16 04:40 . 2011-11-03 23:02 12279808 c:\windows\SysWOW64\mshtml.dll
    + 2009-07-14 02:34 . 2012-01-15 19:46 10747904 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
    - 2009-07-14 02:34 . 2011-10-13 14:47 10747904 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
    + 2011-11-10 14:49 . 2011-08-30 05:25 14173184 c:\windows\system32\shell32.dll
    + 2011-12-16 04:40 . 2011-11-04 02:38 17786368 c:\windows\system32\mshtml.dll
    + 2010-04-21 19:37 . 2012-01-11 04:32 54008112 c:\windows\system32\MRT.exe
    + 2011-12-16 04:40 . 2011-11-04 01:59 10886656 c:\windows\system32\ieframe.dll
    + 2010-12-28 05:44 . 2012-01-24 02:32 14676117 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2631836602-637535096-2860635993-1000-8192.dat
    + 2011-12-29 01:11 . 2011-12-29 01:11 44934656 c:\windows\Installer\a34aa4.msi
    + 2011-12-29 01:10 . 2011-12-29 01:10 11081728 c:\windows\Installer\a3406a.msi
    + 2011-12-29 01:09 . 2011-12-29 01:09 26820096 c:\windows\Installer\a34009.msi
    + 2011-12-29 01:08 . 2011-12-29 01:08 18706944 c:\windows\Installer\a33d2a.msi
    + 2011-12-29 01:07 . 2011-12-29 01:07 20304896 c:\windows\Installer\a33bd9.msi
    + 2011-09-15 23:39 . 2011-09-15 23:39 11163136 c:\windows\Installer\3132cb.msp
    + 2011-09-15 23:38 . 2011-09-15 23:38 10838528 c:\windows\Installer\3132c0.msp
    + 2011-09-15 23:37 . 2011-09-15 23:37 16691712 c:\windows\Installer\312fd3.msp
    + 2011-09-15 23:37 . 2011-09-15 23:37 34428416 c:\windows\Installer\312fcd.msp
    + 2011-09-15 23:37 . 2011-09-15 23:37 37148160 c:\windows\Installer\312fc1.msp
    + 2011-09-15 23:37 . 2011-09-15 23:37 38176256 c:\windows\Installer\312fb5.msp
    + 2011-08-30 13:40 . 2011-08-30 13:40 15145832 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\XL12CNV.EXE
    + 2011-08-17 15:01 . 2011-08-17 15:01 16149352 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OART.DLL
    + 2011-08-04 00:53 . 2011-08-04 00:53 17324928 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSO.DLL
    + 2011-08-31 01:25 . 2011-08-31 01:25 18367336 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\EXCEL.EXE
    + 2011-08-30 13:40 . 2011-08-30 13:40 15145832 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\XL12CNV.EXE
    + 2011-09-16 01:42 . 2011-09-16 01:42 18115432 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\WWLIB.DLL
    + 2011-08-17 15:01 . 2011-08-17 15:01 16149352 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\OART.DLL
    + 2011-08-04 00:53 . 2011-08-04 00:53 17324928 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\MSO.DLL
    + 2011-08-31 01:25 . 2011-08-31 01:25 18367336 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6612\EXCEL.EXE
    + 2011-08-30 13:40 . 2011-08-30 13:40 15145832 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6612\XL12CNV.EXE
    + 2012-01-08 22:05 . 2012-01-08 22:05 15270912 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web\ab920a032a9b63aa07f26c5592d7c72c\System.Web.ni.dll
    + 2012-01-09 22:35 . 2012-01-09 22:35 23913984 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel\4bf05a9a1aebde89033c40b9e51af495\System.ServiceModel.ni.dll
    + 2012-01-08 22:06 . 2012-01-08 22:06 13609472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Design\665178c1ccfd538896eaa0fff283b6ef\System.Design.ni.dll
    + 2012-01-09 22:36 . 2012-01-09 22:36 25470976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehshell\897b2e70eb1754bf8c557fadd93faf98\ehshell.ni.dll
    + 2012-01-08 22:07 . 2012-01-08 22:07 11833344 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\b41e38edbd6dfe20997f6ea7c080aceb\System.Web.ni.dll
    + 2012-01-09 22:30 . 2012-01-09 22:30 17478656 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\7bc7e33d4568a214f226cdb6a161a37a\System.ServiceModel.ni.dll
    + 2012-01-08 22:07 . 2012-01-08 22:07 10580480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\70f9f6de6dc9611157ed563bdb4e79a4\System.Design.ni.dll
    + 2011-09-15 23:34 . 2011-09-15 23:34 428804608 c:\windows\Installer\313136.msp
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{868978c8-95f3-4020-a5cd-5a16d60e36ca} "= "c:\program files (x86)\Dividend Miles Toolbar\Helper.dll" [2011-06-09 357376]
    .
    [HKEY_CLASSES_ROOT\clsid\{868978c8-95f3-4020-a5cd-5a16d60e36ca}]
    [HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook.1]
    [HKEY_CLASSES_ROOT\TypeLib\{18AB4FA0-5522-4114-9654-5CCE2F9D172E}]
    [HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook]
    .
    [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{69CD690C-70B1-4333-AD69-28FFF7118C56}]
    2011-06-09 01:27 1544192 ----a-w- c:\program files (x86)\Dividend Miles Toolbar\Toolbar.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{3948072D-28FE-4206-9F7F-2AFF92B24679} "= "c:\program files (x86)\Dividend Miles Toolbar\Toolbar.dll" [2011-06-09 1544192]
    .
    [HKEY_CLASSES_ROOT\clsid\{3948072d-28fe-4206-9f7f-2aff92b24679}]
    [HKEY_CLASSES_ROOT\FCTB000063323.IEToolbar.1]
    [HKEY_CLASSES_ROOT\TypeLib\{8406FB26-8A92-4574-8C97-410FCDAD7F00}]
    [HKEY_CLASSES_ROOT\FCTB000063323.IEToolbar]
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "FileHippo.com "= "c:\program files (x86)\FileHippo.com\UpdateChecker.exe" [2010-08-09 248832]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "LManager "= "c:\program files (x86)\Launch Manager\LManager.exe" [2009-08-18 1157128]
    "NortonOnlineBackupReminder "= "c:\program files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-07-25 588648]
    "AppleSyncNotifier "= "c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392]
    "Adobe ARM "= "c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    "SunJavaUpdateSched "= "c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
    "ZoneAlarm "= "c:\program files (x86)\CheckPoint\ZoneAlarm\zatray.exe" [2011-11-10 73360]
    "APSDaemon "= "c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
    "QuickTime Task "= "c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
    "iTunesHelper "= "c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-12-08 421736]
    .
    c:\users\walmart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    avast! Free Antivirus.lnk - c:\program files\Alwil Software\Avast5\AvastUI.exe [2011-12-16 3744552]
    OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-4-19 291896]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin "= 5 (0x5)
    "ConsentPromptBehaviorUser "= 3 (0x3)
    "EnableUIADesktopToggle "= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
    "aux "=wdmaud.drv
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-13 135664]
    R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
    R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-13 135664]
    R3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe [2009-07-14 27136]
    R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-06-18 50432]
    R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [2009-09-02 225280]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
    R3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;c:\windows\system32\DRIVERS\WN111v2x.sys [x]
    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
    S1 aswSnx;aswSnx; [x]
    S1 aswSP;aswSP; [x]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
    S2 aswFsBlk;aswFsBlk; [x]
    S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
    S2 ePowerSvc;Acer ePower Service;c:\program files\eMachines\eMachines Power Management\ePowerSvc.exe [2009-09-30 844320]
    S2 Greg_Service;GRegService;c:\program files (x86)\eMachines\Registration\GregHSRW.exe [2009-08-28 1150496]
    S2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [2011-11-03 33672]
    S2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\IswSvc.exe [2011-11-03 827520]
    S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-06-18 144640]
    S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-04-19 993848]
    S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2011-04-19 399416]
    S2 Updater Service;Updater Service;c:\program files\eMachines\eMachines Updater\UpdaterService.exe [2009-07-04 240160]
    S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys [x]
    S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x]
    S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [x]
    S3 SaiH5F0D;SaiH5F0D;c:\windows\system32\DRIVERS\SaiH5F0D.sys [x]
    S3 SaiU5F0D;SaiU5F0D;c:\windows\system32\DRIVERS\SaiU5F0D.sys [x]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *NewlyCreated* - WS2IFSL
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
    nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-01-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-13 04:02]
    .
    2012-01-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-13 04:02]
    .
    .
    --------- x86-64 -----------
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
    @= "{472083B0-C522-11CF-8763-00608CC02F24} "
    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
    2011-11-28 18:01 134384 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IAAnotif "= "c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-10-13 186904]
    "RtHDVCpl "= "c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-28 7982112]
    "Acer ePower Management "= "c:\program files\eMachines\eMachines Power Management\ePowerTray.exe" [2009-09-30 823840]
    "SynTPEnh "= "c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
    "OOTag "= "c:\windows\oobeoffer\oobeoffer\ootag.exe" [2009-09-28 23072]
    "IgfxTray "= "c:\windows\system32\igfxtray.exe" [2009-09-02 159232]
    "HotKeysCmds "= "c:\windows\system32\hkcmd.exe" [2009-09-02 380928]
    "Persistence "= "c:\windows\system32\igfxpers.exe" [2009-09-02 358912]
    "ProfilerU "= "c:\program files\Saitek\SD6\Software\ProfilerU.exe" [2009-06-03 357888]
    "SaiMfd "= "c:\program files\Saitek\SD6\Software\SaiMfd.exe" [2009-06-03 194560]
    "IntelliPoint "= "c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
    "ISW "= "c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2011-11-03 1125504]
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/webhp?sourceid=navclient&ie=UTF-8&rlz=1T4ACEW_enUS368US370
    uLocal Page = c:\windows\system32\blank.htm
    uDefault_Search_URL = hxxp://www.google.com/ie
    mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&m=e725&r=273603108715l04f4z1m5r4422023o
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
    TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
    FF - ProfilePath - c:\users\walmart\AppData\Roaming\Mozilla\Firefox\Profiles\obavtsyv.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2611275&SearchSource=3&q={searchTerms}
    FF - prefs.js: browser.search.selectedEngine -
    FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
    FF - prefs.js: network.proxy.type - 0
    .
    - - - - ORPHANS REMOVED - - - -
    .
    WebBrowser-{3948072D-28FE-4206-9F7F-2AFF92B24679} - (no file)
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @= "FlashBroker "
    "LocalizedString "= "@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101 "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled "=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @= "c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @= "Shockwave Flash Object "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @= "c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx "
    "ThreadingModel "= "Apartment "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @= "0 "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @= "ShockwaveFlash.ShockwaveFlash.10 "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @= "c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1 "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @= "{D27CDB6B-AE6D-11cf-96B8-444553540000} "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @= "1.0 "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @= "ShockwaveFlash.ShockwaveFlash "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @= "Macromedia Flash Factory Object "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @= "c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx "
    "ThreadingModel "= "Apartment "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @= "FlashFactory.FlashFactory.1 "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @= "c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1 "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @= "{D27CDB6B-AE6D-11cf-96B8-444553540000} "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @= "1.0 "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @= "FlashFactory.FlashFactory "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @= "IFlashBroker4 "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @= "{00020424-0000-0000-C000-000000000046} "
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "
    "Version "= "1.0 "
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Alwil Software\Avast5\AvastSvc.exe
    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    .
    **************************************************************************
    .
    Completion time: 2012-01-23 21:47:35 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-01-24 02:47
    ComboFix2.txt 2011-10-31 22:19
    .
    Pre-Run: 156,708,917,248 bytes free
    Post-Run: 156,409,339,904 bytes free
    .
    - - End Of File - - 495C0CA4F5174B0B73806079A7179864
     
  18. 2012/01/23
    Forsaken Knight

    Forsaken Knight Well-Known Member Thread Starter

    Joined:
    2007/12/01
    Messages:
    512
    Likes Received:
    0
    It took about 30 to 34 minutes for the whole process, including displaying the log file so that I can save it, close it, and restart my laptop pc machine.

    I thought I should mention this.
     
  19. 2012/01/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    All looks clean....

    In this forum, we make sure, your computer is free of malware and your computer is clean :)
    Because the access to malware forum is very limited, your best option is to create new topic about your current issue, at Windows section.
    You'll get more attention.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.