1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Trojan problem

Discussion in 'Malware and Virus Removal Archive' started by dave1234, 2012/03/27.

  1. 2012/03/27
    dave1234

    dave1234 Well-Known Member Thread Starter

    Joined:
    2002/12/21
    Messages:
    196
    Likes Received:
    0
    [Resolved] Trojan problem

    Need help with trojan please

    Logs

    Malwarebytes Anti-Malware 1.60.1.1000
    www.malwarebytes.org

    Database version: v2012.03.27.08

    Windows XP Service Pack 3 x86 NTFS
    Internet Explorer 8.0.6001.18702
    David Peters :: D124YR81 [administrator]

    3/27/2012 5:56:54 PM
    mbam-log-2012-03-27 (17-56-54).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 216022
    Time elapsed: 12 minute(s), 30 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 1
    HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Shell (Backdoor.Agent.Gen) -> Data: C:\Documents and Settings\David Peters\Local Settings\Application Data\bc5c6f8d\X -> Quarantined and deleted successfully.

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 4
    C:\Documents and Settings\David Peters\Local Settings\temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> Quarantined and deleted successfully.
    C:\Documents and Settings\LocalService\Local Settings\temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> Quarantined and deleted successfully.
    C:\Documents and Settings\NetworkService\Local Settings\temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> Quarantined and deleted successfully.
    C:\WINDOWS\temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> Quarantined and deleted successfully.

    (end)


    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-03-27 20:46:42
    -----------------------------
    20:46:42.843 OS Version: Windows 5.1.2600 Service Pack 3
    20:46:42.843 Number of processors: 2 586 0x403
    20:46:42.843 ComputerName: D124YR81 UserName:
    20:46:45.421 Initialize success
    20:47:25.046 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
    20:47:25.046 Disk 0 Vendor: Maxtor_6L080M0 BANC1G10 Size: 76293MB BusType: 3
    20:47:25.125 Disk 0 MBR read successfully
    20:47:25.125 Disk 0 MBR scan
    20:47:25.125 Disk 0 unknown MBR code
    20:47:25.156 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
    20:47:25.234 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 73171 MB offset 80325
    20:47:25.328 Disk 0 Partition 3 00 DB CP/M / CTOS Dell 8.0 3074 MB offset 149934645
    20:47:25.531 Disk 0 scanning sectors +156232125
    20:47:26.046 Disk 0 scanning C:\WINDOWS\system32\drivers
    20:48:35.343 Service scanning
    20:48:42.609 Service MpKsl70549428 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D1D3BD90-D755-47E0-808F-471E406D3BFD}\MpKsl70549428.sys **LOCKED** 32
    20:48:51.171 Modules scanning
    20:49:11.187 Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys **SUSPICIOUS**
    20:50:02.812 Disk 0 trace - called modules:
    20:50:02.906 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x82bcebc0]<<
    20:50:02.906 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82d8aab8]
    20:50:02.921 3 CLASSPNP.SYS[f85a7fd7] -> nt!IofCallDriver -> [0x82cc4a38]
    20:50:02.937 \Driver\00001328[0x82c76030] -> IRP_MJ_CREATE -> 0x82bcebc0
    20:50:02.953 Scan finished successfully
    20:50:46.156 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\David Peters\Desktop\MBR.dat "
    20:50:46.171 The log file has been saved successfully to "C:\Documents and Settings\David Peters\Desktop\aswMBR.txt "


    GMER 1.0.15.15641 - http://www.gmer.net
    Rootkit scan 2012-03-27 21:16:31
    Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e Maxtor_6L080M0 rev.BANC1G10
    Running: gmer.exe; Driver: C:\DOCUME~1\DAVIDP~1\LOCALS~1\Temp\ffdyapod.sys


    ---- Kernel code sections - GMER 1.0.15 ----

    .text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF742E000, 0x29C9F0, 0xE8000020]
    .text cdrom.sys F8687301 103 Bytes [00, 00, 00, 40, 00, 00, C0, ...]
    .text cdrom.sys F8687369 674 Bytes [0E, 00, 00, 80, E7, 00, 00, ...]
    .text cdrom.sys F868760C 24 Bytes [04, 8D, 45, 18, 50, FF, 75, ...]
    .text cdrom.sys F8687625 143 Bytes [83, C4, 20, 5D, C2, 14, 00, ...]
    .text cdrom.sys F86876B5 363 Bytes [84, C9, 75, F9, 2B, C2, 40, ...]
    .text ...
    .INIT C:\WINDOWS\system32\DRIVERS\cdrom.sys entry point in ".INIT" section [0xF8695522]
    ? C:\WINDOWS\system32\DRIVERS\cdrom.sys suspicious PE modification

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[116] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[116] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[116] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[116] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[116] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[116] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[116] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[116] @ C:\WINDOWS\system32\shell32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[116] @ C:\WINDOWS\system32\shell32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[356] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [00F62BC8] C:\WINDOWS\system32\VSINIT.dll (TrueVector Service/Zone Labs, LLC)
    IAT C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[356] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!UnhandledExceptionFilter] [00F62CE9] C:\WINDOWS\system32\VSINIT.dll (TrueVector Service/Zone Labs, LLC)
    IAT C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[356] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!TerminateProcess] [00F62CB8] C:\WINDOWS\system32\VSINIT.dll (TrueVector Service/Zone Labs, LLC)
    IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[852] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[852] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[852] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[852] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[852] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[852] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[852] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[852] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[852] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[852] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[852] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Microsoft Security Client\msseces.exe[1584] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Microsoft Security Client\msseces.exe[1584] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Microsoft Security Client\msseces.exe[1584] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Microsoft Security Client\msseces.exe[1584] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\Microsoft Security Client\msseces.exe[1584] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Microsoft Security Client\msseces.exe[1584] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Microsoft Security Client\msseces.exe[1584] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Microsoft Security Client\msseces.exe[1584] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\Microsoft Security Client\msseces.exe[1584] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\Microsoft Security Client\msseces.exe[1584] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\Microsoft Security Client\msseces.exe[1584] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\DivX\DivX Update\DivXUpdate.exe[1632] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\DivX\DivX Update\DivXUpdate.exe[1632] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\DivX\DivX Update\DivXUpdate.exe[1632] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\DivX\DivX Update\DivXUpdate.exe[1632] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\DivX\DivX Update\DivXUpdate.exe[1632] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\DivX\DivX Update\DivXUpdate.exe[1632] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\DivX\DivX Update\DivXUpdate.exe[1632] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\DivX\DivX Update\DivXUpdate.exe[1632] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\DivX\DivX Update\DivXUpdate.exe[1632] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\DivX\DivX Update\DivXUpdate.exe[1632] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\DivX\DivX Update\DivXUpdate.exe[1632] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\explorer.exe[1868] @ C:\WINDOWS\explorer.exe [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\explorer.exe[1868] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\explorer.exe[1868] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\explorer.exe[1868] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\explorer.exe[1868] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\explorer.exe[1868] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\explorer.exe[1868] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\explorer.exe[1868] @ C:\WINDOWS\system32\CRYPT32.dll [ADVAPI32.dll!CryptGetUserKey] [77E4560A] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\WINDOWS\explorer.exe[1868] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\WINDOWS\explorer.exe[1868] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\WINDOWS\explorer.exe[1868] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\explorer.exe[1868] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\WINDOWS\explorer.exe[1868] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\iTunes\iTunesHelper.exe[2264] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\iTunes\iTunesHelper.exe[2264] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\iTunes\iTunesHelper.exe[2264] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\iTunes\iTunesHelper.exe[2264] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\iTunes\iTunesHelper.exe[2264] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\iTunes\iTunesHelper.exe[2264] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\iTunes\iTunesHelper.exe[2264] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\iTunes\iTunesHelper.exe[2264] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\iTunes\iTunesHelper.exe[2264] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\system32\ctfmon.exe[2332] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\system32\ctfmon.exe[2332] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\system32\ctfmon.exe[2332] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\system32\ctfmon.exe[2332] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\system32\ctfmon.exe[2332] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\WINDOWS\system32\ctfmon.exe[2332] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\system32\ctfmon.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\system32\ctfmon.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\system32\ctfmon.exe[2332] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\WINDOWS\system32\ctfmon.exe[2332] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\system32\ctfmon.exe[2332] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\DOCUME~1\DAVIDP~1\LOCALS~1\Temp\Rar$EX00.625\gmer.exe[2840] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\DOCUME~1\DAVIDP~1\LOCALS~1\Temp\Rar$EX00.625\gmer.exe[2840] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\DOCUME~1\DAVIDP~1\LOCALS~1\Temp\Rar$EX00.625\gmer.exe[2840] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\DOCUME~1\DAVIDP~1\LOCALS~1\Temp\Rar$EX00.625\gmer.exe[2840] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\DOCUME~1\DAVIDP~1\LOCALS~1\Temp\Rar$EX00.625\gmer.exe[2840] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\DOCUME~1\DAVIDP~1\LOCALS~1\Temp\Rar$EX00.625\gmer.exe[2840] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\DOCUME~1\DAVIDP~1\LOCALS~1\Temp\Rar$EX00.625\gmer.exe[2840] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\DOCUME~1\DAVIDP~1\LOCALS~1\Temp\Rar$EX00.625\gmer.exe[2840] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\DOCUME~1\DAVIDP~1\LOCALS~1\Temp\Rar$EX00.625\gmer.exe[2840] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\notepad.exe[4016] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\notepad.exe[4016] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\notepad.exe[4016] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\notepad.exe[4016] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\notepad.exe[4016] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\notepad.exe[4016] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\WINDOWS\notepad.exe[4016] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\notepad.exe[4016] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\notepad.exe[4016] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\WINDOWS\notepad.exe[4016] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\WINDOWS\notepad.exe[4016] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\WinRAR\WinRAR.exe[4048] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\WinRAR\WinRAR.exe[4048] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\WinRAR\WinRAR.exe[4048] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\WinRAR\WinRAR.exe[4048] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\WinRAR\WinRAR.exe[4048] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\WinRAR\WinRAR.exe[4048] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.DLL (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\WinRAR\WinRAR.exe[4048] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\WinRAR\WinRAR.exe[4048] @ C:\WINDOWS\system32\OLE32.DLL [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
    IAT C:\Program Files\WinRAR\WinRAR.exe[4048] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.DLL (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\WinRAR\WinRAR.exe[4048] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.DLL (Advanced Windows 32 Base API/Microsoft Corporation)
    IAT C:\Program Files\WinRAR\WinRAR.exe[4048] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)

    ---- Devices - GMER 1.0.15 ----

    Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
    Device A9C5AD20

    AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    ---- Modules - GMER 1.0.15 ----

    Module (noname) (*** hidden *** ) F8627000-F8636000 (61440 bytes)

    ---- Threads - GMER 1.0.15 ----

    Thread System [4:124] 82BCF540
    Thread System [4:128] 82BCF540
    Thread services.exe [1116:1320] 0076EE96

    ---- Files - GMER 1.0.15 ----

    File C:\WINDOWS\$NtUninstallKB11310$\3160174477 0 bytes
    File C:\WINDOWS\$NtUninstallKB11310$\3160174477\@ 2048 bytes
    File C:\WINDOWS\$NtUninstallKB11310$\3160174477\L 0 bytes
    File C:\WINDOWS\$NtUninstallKB11310$\3160174477\L\odetmngk 62976 bytes
    File C:\WINDOWS\$NtUninstallKB11310$\3160174477\loader.tlb 2632 bytes
    File C:\WINDOWS\$NtUninstallKB11310$\3160174477\U 0 bytes
    File C:\WINDOWS\$NtUninstallKB11310$\3160174477\U\@00000001 45968 bytes
    File C:\WINDOWS\$NtUninstallKB11310$\3160174477\U\@000000c0 2560 bytes
    File C:\WINDOWS\$NtUninstallKB11310$\3160174477\U\@000000cb 704 bytes
    File C:\WINDOWS\$NtUninstallKB11310$\3160174477\U\@000000cf 1536 bytes
    File C:\WINDOWS\$NtUninstallKB11310$\3160174477\U\@80000000 73728 bytes
    File C:\WINDOWS\$NtUninstallKB11310$\3160174477\U\@800000c0 43008 bytes
    File C:\WINDOWS\$NtUninstallKB11310$\3160174477\U\@800000cb 25600 bytes
    File C:\WINDOWS\$NtUninstallKB11310$\3160174477\U\@800000cf 31232 bytes
    File C:\WINDOWS\$NtUninstallKB11310$\680285935 0 bytes

    ---- EOF - GMER 1.0.15 ----


    DDS would not run. I will try again.

    Thanks
    Dave
     
  2. 2012/03/27
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ============================================================

    You're infected with a rootkit thus a problem with running DDS.
    Leave DDS alone for now.

    Download TDSSKiller and save it to your desktop.
    • Extract (unzip) its contents to your desktop.
    • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
     

  3. to hide this advert.

  4. 2012/03/28
    dave1234

    dave1234 Well-Known Member Thread Starter

    Joined:
    2002/12/21
    Messages:
    196
    Likes Received:
    0
    05:44:25.0000 3308 TDSS rootkit removing tool 2.7.23.0 Mar 26 2012 13:40:18
    05:44:25.0296 3308 ============================================================
    05:44:25.0296 3308 Current date / time: 2012/03/28 05:44:25.0296
    05:44:25.0296 3308 SystemInfo:
    05:44:25.0296 3308
    05:44:25.0296 3308 OS Version: 5.1.2600 ServicePack: 3.0
    05:44:25.0296 3308 Product type: Workstation
    05:44:25.0296 3308 ComputerName: D124YR81
    05:44:25.0296 3308 UserName: David Peters
    05:44:25.0296 3308 Windows directory: C:\WINDOWS
    05:44:25.0296 3308 System windows directory: C:\WINDOWS
    05:44:25.0296 3308 Processor architecture: Intel x86
    05:44:25.0296 3308 Number of processors: 2
    05:44:25.0296 3308 Page size: 0x1000
    05:44:25.0296 3308 Boot type: Normal boot
    05:44:25.0296 3308 ============================================================
    05:44:35.0296 3308 Drive \Device\Harddisk0\DR0 - Size: 0x12A05F2000 (74.51 Gb), SectorSize: 0x200, Cylinders: 0x25FE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
    05:44:35.0328 3308 \Device\Harddisk0\DR0:
    05:44:35.0328 3308 MBR used
    05:44:35.0328 3308 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x139C5, BlocksNum 0x8EE9870
    05:44:35.0390 3308 Initialize success
    05:44:35.0390 3308 ============================================================
    05:44:47.0718 0132 ============================================================
    05:44:47.0718 0132 Scan started
    05:44:47.0718 0132 Mode: Manual;
    05:44:47.0718 0132 ============================================================
    05:44:47.0968 0132 Abiosdsk - ok
    05:44:48.0046 0132 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
    05:44:48.0046 0132 abp480n5 - ok
    05:44:48.0140 0132 acdservice (b89cfbe8cb247b57d8c10adaa66b462b) C:\WINDOWS\system32\FETNDIS.dll
    05:44:48.0140 0132 Suspicious file (NoAccess): C:\WINDOWS\system32\FETNDIS.dll. md5: b89cfbe8cb247b57d8c10adaa66b462b
    05:44:48.0140 0132 acdservice ( LockedFile.Multi.Generic ) - warning
    05:44:48.0140 0132 acdservice - detected LockedFile.Multi.Generic (1)
    05:44:48.0296 0132 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
    05:44:48.0296 0132 ACPI - ok
    05:44:48.0359 0132 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
    05:44:48.0359 0132 ACPIEC - ok
    05:44:48.0437 0132 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
    05:44:48.0437 0132 adpu160m - ok
    05:44:48.0515 0132 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
    05:44:48.0531 0132 aec - ok
    05:44:48.0687 0132 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
    05:44:48.0750 0132 AFD - ok
    05:44:48.0859 0132 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
    05:44:48.0875 0132 agp440 - ok
    05:44:48.0937 0132 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
    05:44:48.0937 0132 agpCPQ - ok
    05:44:48.0984 0132 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
    05:44:48.0984 0132 Aha154x - ok
    05:44:49.0046 0132 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
    05:44:49.0046 0132 aic78u2 - ok
    05:44:49.0125 0132 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
    05:44:49.0125 0132 aic78xx - ok
    05:44:49.0203 0132 Alerter (a9a3daa780ca6c9671a19d52456705b4) C:\WINDOWS\system32\alrsvc.dll
    05:44:49.0203 0132 Alerter - ok
    05:44:49.0281 0132 ALG (8c515081584a38aa007909cd02020b3d) C:\WINDOWS\System32\alg.exe
    05:44:49.0281 0132 ALG - ok
    05:44:49.0343 0132 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
    05:44:49.0343 0132 AliIde - ok
    05:44:49.0406 0132 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
    05:44:49.0406 0132 alim1541 - ok
    05:44:49.0500 0132 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
    05:44:49.0500 0132 amdagp - ok
    05:44:49.0578 0132 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
    05:44:49.0609 0132 amsint - ok
    05:44:49.0718 0132 Apple Mobile Device (d8e18021f91ad79ca8491cb5a5da22d4) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    05:44:49.0718 0132 Apple Mobile Device - ok
    05:44:49.0796 0132 AppMgmt - ok
    05:44:49.0875 0132 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
    05:44:49.0875 0132 asc - ok
    05:44:49.0953 0132 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
    05:44:49.0953 0132 asc3350p - ok
    05:44:50.0000 0132 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
    05:44:50.0000 0132 asc3550 - ok
    05:44:50.0125 0132 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
    05:44:50.0156 0132 aspnet_state - ok
    05:44:50.0234 0132 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
    05:44:50.0234 0132 AsyncMac - ok
    05:44:50.0328 0132 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
    05:44:50.0328 0132 atapi - ok
    05:44:50.0359 0132 Atdisk - ok
    05:44:50.0453 0132 Ati HotKey Poller (281d26df656e53dab568214ee282ec46) C:\WINDOWS\system32\Ati2evxx.exe
    05:44:51.0250 0132 Ati HotKey Poller - ok
    05:44:51.0656 0132 ati2mtag (c2b6f2161abd498d2b453050ffc81812) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
    05:44:53.0140 0132 ati2mtag - ok
    05:44:53.0281 0132 AtiHdmiService (dc6957811ff95f2dd3004361b20d8d3f) C:\WINDOWS\system32\drivers\AtiHdmi.sys
    05:44:53.0343 0132 AtiHdmiService - ok
    05:44:53.0421 0132 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
    05:44:53.0421 0132 Atmarpc - ok
    05:44:53.0515 0132 AudioSrv (def7a7882bec100fe0b2ce2549188f9d) C:\WINDOWS\System32\audiosrv.dll
    05:44:53.0515 0132 AudioSrv - ok
    05:44:53.0640 0132 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
    05:44:53.0640 0132 audstub - ok
    05:44:53.0828 0132 Autocomplete (6b2f566321d64b46822dee7a8cbe0f75) C:\Program Files\Acesoft\Tracks Eraser Pro\delautocomp.exe
    05:44:54.0296 0132 Autocomplete - ok
    05:44:54.0390 0132 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
    05:44:54.0390 0132 Beep - ok
    05:44:54.0468 0132 BITS (574738f61fca2935f5265dc4e5691314) C:\WINDOWS\system32\qmgr.dll
    05:44:54.0531 0132 BITS - ok
    05:44:54.0781 0132 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe
    05:44:54.0796 0132 Bonjour Service - ok
    05:44:54.0859 0132 Browser (a06ce3399d16db864f55faeb1f1927a9) C:\WINDOWS\System32\browser.dll
    05:44:54.0859 0132 Browser - ok
    05:44:55.0093 0132 catchme - ok
    05:44:55.0156 0132 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
    05:44:55.0156 0132 cbidf - ok
    05:44:55.0265 0132 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
    05:44:55.0265 0132 cbidf2k - ok
    05:44:55.0312 0132 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
    05:44:55.0312 0132 cd20xrnt - ok
    05:44:55.0375 0132 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
    05:44:55.0375 0132 Cdaudio - ok
    05:44:55.0453 0132 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
    05:44:55.0453 0132 Cdfs - ok
    05:44:55.0515 0132 Cdrom (6f53aaac92fbcf732acd17597626eb1e) C:\WINDOWS\system32\DRIVERS\cdrom.sys
    05:44:55.0609 0132 Cdrom - ok
    05:44:55.0781 0132 Changer - ok
    05:44:55.0984 0132 CiSvc (1cfe720eb8d93a7158a4ebc3ab178bde) C:\WINDOWS\system32\cisvc.exe
    05:44:55.0984 0132 CiSvc - ok
    05:44:56.0078 0132 ClipSrv (34cbe729f38138217f9c80212a2a0c82) C:\WINDOWS\system32\clipsrv.exe
    05:44:56.0093 0132 ClipSrv - ok
    05:44:56.0234 0132 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    05:44:56.0296 0132 clr_optimization_v2.0.50727_32 - ok
    05:44:56.0390 0132 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
    05:44:56.0390 0132 CmdIde - ok
    05:44:56.0484 0132 cmdmon (b89cfbe8cb247b57d8c10adaa66b462b) C:\WINDOWS\system32\cpqvcagent.dll
    05:44:56.0500 0132 Suspicious file (NoAccess): C:\WINDOWS\system32\cpqvcagent.dll. md5: b89cfbe8cb247b57d8c10adaa66b462b
    05:44:56.0500 0132 cmdmon ( LockedFile.Multi.Generic ) - warning
    05:44:56.0500 0132 cmdmon - detected LockedFile.Multi.Generic (1)
    05:44:56.0703 0132 COMSysApp - ok
    05:44:56.0765 0132 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
    05:44:56.0765 0132 Cpqarray - ok
    05:44:56.0859 0132 CryptSvc (3d4e199942e29207970e04315d02ad3b) C:\WINDOWS\System32\cryptsvc.dll
    05:44:56.0859 0132 CryptSvc - ok
    05:44:56.0953 0132 cusrvc (b89cfbe8cb247b57d8c10adaa66b462b) C:\WINDOWS\system32\RimSerPort.dll
    05:44:56.0953 0132 Suspicious file (NoAccess): C:\WINDOWS\system32\RimSerPort.dll. md5: b89cfbe8cb247b57d8c10adaa66b462b
    05:44:56.0953 0132 cusrvc ( LockedFile.Multi.Generic ) - warning
    05:44:56.0953 0132 cusrvc - detected LockedFile.Multi.Generic (1)
    05:44:57.0109 0132 CVirtA (b5ecadf7708960f1818c7fa015f4c239) C:\WINDOWS\system32\DRIVERS\CVirtA.sys
    05:44:57.0156 0132 CVirtA - ok
    05:44:57.0296 0132 CVPND (30443eef52f5fb043654859eaa8e5247) C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    05:44:57.0343 0132 CVPND - ok
    05:44:57.0484 0132 CVPNDRVA (cb90b2762b1a1d0b40496400c55b6ade) C:\WINDOWS\system32\Drivers\CVPNDRVA.sys
    05:44:57.0500 0132 CVPNDRVA - ok
    05:44:57.0562 0132 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
    05:44:57.0640 0132 dac2w2k - ok
    05:44:57.0734 0132 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
    05:44:57.0765 0132 dac960nt - ok
    05:44:57.0843 0132 DcomLaunch (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll
    05:44:57.0906 0132 DcomLaunch - ok
    05:44:57.0984 0132 Dhcp (5e38d7684a49cacfb752b046357e0589) C:\WINDOWS\System32\dhcpcsvc.dll
    05:44:57.0984 0132 Dhcp - ok
    05:44:58.0062 0132 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
    05:44:58.0062 0132 Disk - ok
    05:44:58.0078 0132 dmadmin - ok
    05:44:58.0156 0132 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
    05:44:58.0187 0132 dmboot - ok
    05:44:58.0265 0132 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
    05:44:58.0281 0132 dmio - ok
    05:44:58.0406 0132 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
    05:44:58.0406 0132 dmload - ok
    05:44:58.0484 0132 dmserver (57edec2e5f59f0335e92f35184bc8631) C:\WINDOWS\System32\dmserver.dll
    05:44:58.0500 0132 dmserver - ok
    05:44:58.0546 0132 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
    05:44:58.0546 0132 DMusic - ok
    05:44:58.0734 0132 DNE (b5aa5aa5ac327bd7c1aec0c58f0c1144) C:\WINDOWS\system32\DRIVERS\dne2000.sys
    05:44:58.0734 0132 DNE - ok
    05:44:58.0812 0132 Dnscache (5f7e24fa9eab896051ffb87f840730d2) C:\WINDOWS\System32\dnsrslvr.dll
    05:44:58.0812 0132 Dnscache - ok
    05:44:58.0906 0132 Dot3svc (0f0f6e687e5e15579ef4da8dd6945814) C:\WINDOWS\System32\dot3svc.dll
    05:44:58.0968 0132 Dot3svc - ok
    05:44:59.0046 0132 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
    05:44:59.0046 0132 dpti2o - ok
    05:44:59.0125 0132 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
    05:44:59.0125 0132 drmkaud - ok
    05:44:59.0265 0132 DSBrokerService (fe80901578e7e3da70299a5aeb2b7fbd) C:\Program Files\DellSupport\brkrsvc.exe
    05:44:59.0265 0132 DSBrokerService - ok
    05:44:59.0359 0132 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
    05:44:59.0359 0132 DSproct - ok
    05:44:59.0421 0132 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
    05:44:59.0437 0132 dsunidrv - ok
    05:44:59.0468 0132 E100B (95974e66d3de4951d29e28e8bc0b644c) C:\WINDOWS\system32\DRIVERS\e100b325.sys
    05:44:59.0484 0132 E100B - ok
    05:44:59.0578 0132 EapHost (2187855a7703adef0cef9ee4285182cc) C:\WINDOWS\System32\eapsvc.dll
    05:44:59.0578 0132 EapHost - ok
    05:44:59.0750 0132 elagopro (b89cfbe8cb247b57d8c10adaa66b462b) C:\WINDOWS\system32\msiserver.dll
    05:44:59.0765 0132 Suspicious file (NoAccess): C:\WINDOWS\system32\msiserver.dll. md5: b89cfbe8cb247b57d8c10adaa66b462b
    05:44:59.0765 0132 elagopro ( LockedFile.Multi.Generic ) - warning
    05:44:59.0765 0132 elagopro - detected LockedFile.Multi.Generic (1)
    05:44:59.0828 0132 ERSvc (bc93b4a066477954555966d77fec9ecb) C:\WINDOWS\System32\ersvc.dll
    05:44:59.0828 0132 ERSvc - ok
    05:44:59.0953 0132 Eventlog (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
    05:44:59.0968 0132 Eventlog - ok
    05:45:00.0015 0132 EventSystem (d4991d98f2db73c60d042f1aef79efae) C:\WINDOWS\system32\es.dll
    05:45:00.0015 0132 EventSystem - ok
    05:45:00.0171 0132 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
    05:45:00.0171 0132 Fastfat - ok
    05:45:00.0265 0132 FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
    05:45:00.0265 0132 FastUserSwitchingCompatibility - ok
    05:45:00.0343 0132 Fax (e97d6a8684466df94ff3bc24fb787a07) C:\WINDOWS\system32\fxssvc.exe
    05:45:00.0375 0132 Fax - ok
    05:45:00.0421 0132 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
    05:45:00.0421 0132 Fdc - ok
    05:45:00.0484 0132 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
    05:45:00.0484 0132 Fips - ok
    05:45:00.0546 0132 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
    05:45:00.0578 0132 Flpydisk - ok
    05:45:00.0796 0132 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
    05:45:00.0796 0132 FltMgr - ok
    05:45:01.0046 0132 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
    05:45:01.0046 0132 FontCache3.0.0.0 - ok
    05:45:01.0125 0132 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
    05:45:01.0125 0132 Fs_Rec - ok
    05:45:01.0156 0132 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
    05:45:01.0156 0132 Ftdisk - ok
    05:45:01.0234 0132 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
    05:45:01.0234 0132 GEARAspiWDM - ok
    05:45:01.0296 0132 gearsecurity (b89cfbe8cb247b57d8c10adaa66b462b) C:\WINDOWS\system32\swmsflt.dll
    05:45:01.0312 0132 Suspicious file (NoAccess): C:\WINDOWS\system32\swmsflt.dll. md5: b89cfbe8cb247b57d8c10adaa66b462b
    05:45:01.0312 0132 gearsecurity ( LockedFile.Multi.Generic ) - warning
    05:45:01.0312 0132 gearsecurity - detected LockedFile.Multi.Generic (1)
    05:45:01.0375 0132 getPlusHelper - ok
    05:45:01.0531 0132 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
    05:45:01.0531 0132 Gpc - ok
    05:45:01.0687 0132 gupdate1c9c3951be7f6a0 (626a24ed1228580b9518c01930936df9) C:\Program Files\Google\Update\GoogleUpdate.exe
    05:45:01.0750 0132 gupdate1c9c3951be7f6a0 - ok
    05:45:01.0781 0132 gupdatem (626a24ed1228580b9518c01930936df9) C:\Program Files\Google\Update\GoogleUpdate.exe
    05:45:01.0781 0132 gupdatem - ok
    05:45:01.0953 0132 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
    05:45:01.0953 0132 HDAudBus - ok
    05:45:02.0062 0132 helpsvc (4fcca060dfe0c51a09dd5c3843888bcd) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
    05:45:02.0062 0132 helpsvc - ok
    05:45:02.0093 0132 HidServ - ok
    05:45:02.0171 0132 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
    05:45:02.0187 0132 HidUsb - ok
    05:45:02.0265 0132 hkmsvc (8878bd685e490239777bfe51320b88e9) C:\WINDOWS\System32\kmsvc.dll
    05:45:02.0281 0132 hkmsvc - ok
    05:45:02.0359 0132 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
    05:45:02.0359 0132 hpn - ok
    05:45:02.0453 0132 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
    05:45:02.0468 0132 HTTP - ok
    05:45:02.0578 0132 HTTPFilter (6100a808600f44d999cebdef8841c7a3) C:\WINDOWS\System32\w3ssl.dll
    05:45:02.0593 0132 HTTPFilter - ok
    05:45:02.0718 0132 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
    05:45:02.0718 0132 i2omgmt - ok
    05:45:02.0781 0132 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
    05:45:02.0781 0132 i2omp - ok
    05:45:02.0828 0132 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
    05:45:02.0828 0132 i8042prt - ok
    05:45:02.0921 0132 ialm (240d0f5d7caafd87bd8d801a97bbe041) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
    05:45:02.0953 0132 ialm - ok
    05:45:03.0078 0132 IDriverT (6f95324909b502e2651442c1548ab12f) C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    05:45:03.0078 0132 IDriverT - ok
    05:45:03.0265 0132 idsvc (c01ac32dc5c03076cfb852cb5da5229c) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
    05:45:03.0296 0132 idsvc - ok
    05:45:03.0406 0132 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
    05:45:03.0406 0132 Imapi - ok
    05:45:03.0484 0132 ImapiService (30deaf54a9755bb8546168cfe8a6b5e1) C:\WINDOWS\system32\imapi.exe
    05:45:03.0500 0132 ImapiService - ok
    05:45:03.0562 0132 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
    05:45:03.0562 0132 ini910u - ok
    05:45:03.0656 0132 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
    05:45:03.0656 0132 IntelIde - ok
    05:45:03.0734 0132 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
    05:45:03.0734 0132 intelppm - ok
    05:45:03.0796 0132 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
    05:45:03.0796 0132 Ip6Fw - ok
    05:45:03.0890 0132 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
    05:45:03.0906 0132 IpFilterDriver - ok
    05:45:03.0968 0132 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
    05:45:03.0984 0132 IpInIp - ok
    05:45:04.0031 0132 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
    05:45:04.0046 0132 IpNat - ok
    05:45:04.0203 0132 iPod Service (33642c17c232aa272c68e446a2619899) C:\Program Files\iPod\bin\iPodService.exe
    05:45:04.0250 0132 iPod Service - ok
    05:45:04.0359 0132 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
    05:45:04.0453 0132 IPSec - ok
    05:45:04.0531 0132 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
    05:45:04.0531 0132 IRENUM - ok
    05:45:04.0640 0132 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
    05:45:04.0640 0132 isapnp - ok
    05:45:04.0796 0132 JavaQuickStarterService (9dba73c2f1e76ec4cb837e67c5743596) C:\Program Files\Java\jre6\bin\jqs.exe
    05:45:04.0796 0132 JavaQuickStarterService - ok
    05:45:04.0968 0132 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
    05:45:04.0968 0132 Kbdclass - ok
    05:45:05.0000 0132 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
    05:45:05.0000 0132 kbdhid - ok
    05:45:05.0046 0132 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
    05:45:05.0062 0132 kmixer - ok
    05:45:05.0125 0132 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
    05:45:05.0125 0132 KSecDD - ok
    05:45:05.0203 0132 lanmanserver (3a7c3cbe5d96b8ae96ce81f0b22fb527) C:\WINDOWS\System32\srvsvc.dll
    05:45:05.0218 0132 lanmanserver - ok
    05:45:05.0296 0132 lanmanworkstation (a8888a5327621856c0cec4e385f69309) C:\WINDOWS\System32\wkssvc.dll
    05:45:05.0296 0132 lanmanworkstation - ok
    05:45:05.0328 0132 Lbd - ok
    05:45:05.0406 0132 lbrtfdc - ok
    05:45:05.0531 0132 LmHosts (a7db739ae99a796d91580147e919cc59) C:\WINDOWS\System32\lmhsvc.dll
    05:45:05.0546 0132 LmHosts - ok
    05:45:05.0750 0132 Messenger (986b1ff5814366d71e0ac5755c88f2d3) C:\WINDOWS\System32\msgsvc.dll
    05:45:05.0765 0132 Messenger - ok
    05:45:05.0906 0132 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
    05:45:05.0906 0132 mnmdd - ok
    05:45:06.0000 0132 mnmsrvc (d18f1f0c101d06a1c1adf26eed16fcdd) C:\WINDOWS\system32\mnmsrvc.exe
    05:45:06.0015 0132 mnmsrvc - ok
    05:45:06.0093 0132 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
    05:45:06.0093 0132 Modem - ok
    05:45:06.0140 0132 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
    05:45:06.0140 0132 Mouclass - ok
    05:45:06.0218 0132 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
    05:45:06.0218 0132 mouhid - ok
    05:45:06.0250 0132 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
    05:45:06.0250 0132 MountMgr - ok
    05:45:06.0484 0132 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
    05:45:06.0484 0132 MpFilter - ok
    05:45:07.0046 0132 MpKsla6af447e (a69630d039c38018689190234f866d77) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{83EDABB1-23C9-4539-B4B3-D82ED0670DCC}\MpKsla6af447e.sys
    05:45:07.0046 0132 MpKsla6af447e - ok
    05:45:07.0234 0132 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
    05:45:07.0296 0132 mraid35x - ok
    05:45:07.0328 0132 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
    05:45:07.0328 0132 mraid35x - ok
    05:45:07.0546 0132 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
    05:45:07.0562 0132 MRxDAV - ok
    05:45:07.0796 0132 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
    05:45:07.0812 0132 MRxSmb - ok
    05:45:07.0921 0132 MSDTC (a137f1470499a205abbb9aafb3b6f2b1) C:\WINDOWS\system32\msdtc.exe
    05:45:07.0921 0132 MSDTC - ok
    05:45:07.0968 0132 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
    05:45:07.0984 0132 Msfs - ok
    05:45:08.0046 0132 msgame (b89cfbe8cb247b57d8c10adaa66b462b) C:\WINDOWS\system32\emitray.dll
    05:45:08.0062 0132 Suspicious file (NoAccess): C:\WINDOWS\system32\emitray.dll. md5: b89cfbe8cb247b57d8c10adaa66b462b
    05:45:08.0062 0132 msgame ( LockedFile.Multi.Generic ) - warning
    05:45:08.0062 0132 msgame - detected LockedFile.Multi.Generic (1)
    05:45:08.0203 0132 MSIServer - ok
    05:45:08.0390 0132 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
    05:45:08.0390 0132 MSKSSRV - ok
    05:45:08.0515 0132 MsMpSvc (cfce43b70ca0cc4dcc8adb62b792b173) c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
    05:45:08.0515 0132 MsMpSvc - ok
    05:45:08.0718 0132 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
    05:45:08.0718 0132 MSPCLOCK - ok
    05:45:08.0796 0132 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
    05:45:08.0796 0132 MSPQM - ok
    05:45:08.0859 0132 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
    05:45:08.0875 0132 mssmbios - ok
    05:45:08.0984 0132 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
    05:45:08.0984 0132 Mup - ok
    05:45:09.0062 0132 napagent (0102140028fad045756796e1c685d695) C:\WINDOWS\System32\qagentrt.dll
    05:45:09.0078 0132 napagent - ok
    05:45:09.0187 0132 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
    05:45:09.0187 0132 NDIS - ok
    05:45:09.0265 0132 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
    05:45:09.0265 0132 NdisTapi - ok
    05:45:09.0296 0132 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
    05:45:09.0296 0132 Ndisuio - ok
    05:45:09.0343 0132 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
    05:45:09.0343 0132 NdisWan - ok
    05:45:09.0390 0132 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
    05:45:09.0390 0132 NDProxy - ok
    05:45:09.0453 0132 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
    05:45:09.0453 0132 NetBIOS - ok
    05:45:09.0500 0132 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
    05:45:09.0578 0132 NetBT - ok
    05:45:09.0687 0132 NetDDE (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
    05:45:09.0703 0132 NetDDE - ok
    05:45:09.0703 0132 NetDDEdsdm (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
    05:45:09.0703 0132 NetDDEdsdm - ok
    05:45:09.0812 0132 Netlogon (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
    05:45:09.0812 0132 Netlogon - ok
    05:45:09.0859 0132 Netman (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS\System32\netman.dll
    05:45:09.0906 0132 Netman - ok
    05:45:10.0109 0132 NetSvc (9da26b773bd04b867a8e9f427cd048fc) C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    05:45:10.0218 0132 NetSvc - ok
    05:45:10.0421 0132 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
    05:45:10.0421 0132 NetTcpPortSharing - ok
    05:45:10.0531 0132 Nla (943337d786a56729263071623bbb9de5) C:\WINDOWS\System32\mswsock.dll
    05:45:10.0609 0132 Nla - ok
    05:45:10.0671 0132 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
    05:45:10.0671 0132 Npfs - ok
    05:45:10.0718 0132 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
    05:45:10.0750 0132 Ntfs - ok
    05:45:10.0812 0132 NtLmSsp (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
    05:45:10.0812 0132 NtLmSsp - ok
    05:45:11.0000 0132 NtmsSvc (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS\system32\ntmssvc.dll
    05:45:11.0015 0132 NtmsSvc - ok
    05:45:11.0062 0132 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
    05:45:11.0062 0132 Null - ok
    05:45:11.0187 0132 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
    05:45:11.0312 0132 nv - ok
    05:45:11.0421 0132 nvgts (b89cfbe8cb247b57d8c10adaa66b462b) C:\WINDOWS\system32\umwdf.dll
    05:45:11.0421 0132 Suspicious file (NoAccess): C:\WINDOWS\system32\umwdf.dll. md5: b89cfbe8cb247b57d8c10adaa66b462b
    05:45:11.0421 0132 nvgts ( LockedFile.Multi.Generic ) - warning
    05:45:11.0421 0132 nvgts - detected LockedFile.Multi.Generic (1)
    05:45:11.0546 0132 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
    05:45:11.0593 0132 NwlnkFlt - ok
    05:45:11.0781 0132 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
    05:45:11.0781 0132 NwlnkFwd - ok
    05:45:11.0906 0132 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
    05:45:11.0906 0132 Parport - ok
    05:45:12.0000 0132 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
    05:45:12.0015 0132 PartMgr - ok
    05:45:12.0062 0132 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
    05:45:12.0062 0132 ParVdm - ok
    05:45:12.0125 0132 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
    05:45:12.0125 0132 PCI - ok
    05:45:12.0156 0132 PCIDump - ok
    05:45:12.0187 0132 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
    05:45:12.0187 0132 PCIIde - ok
    05:45:12.0265 0132 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
    05:45:12.0296 0132 Pcmcia - ok
    05:45:12.0328 0132 PDCOMP - ok
    05:45:12.0375 0132 PDFRAME - ok
    05:45:12.0406 0132 PDRELI - ok
    05:45:12.0437 0132 PDRFRAME - ok
    05:45:12.0484 0132 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
    05:45:12.0500 0132 perc2 - ok
    05:45:12.0781 0132 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
    05:45:12.0796 0132 perc2hib - ok
    05:45:13.0078 0132 PlugPlay (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
    05:45:13.0078 0132 PlugPlay - ok
    05:45:13.0406 0132 PolicyAgent (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
    05:45:13.0406 0132 PolicyAgent - ok
    05:45:13.0765 0132 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
    05:45:13.0796 0132 PptpMiniport - ok
    05:45:13.0921 0132 ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
    05:45:13.0921 0132 ProtectedStorage - ok
    05:45:13.0953 0132 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
    05:45:13.0953 0132 PSched - ok
    05:45:13.0984 0132 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
    05:45:13.0984 0132 Ptilink - ok
    05:45:14.0046 0132 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
    05:45:14.0046 0132 PxHelp20 - ok
    05:45:14.0125 0132 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
    05:45:14.0125 0132 ql1080 - ok
    05:45:14.0203 0132 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
    05:45:14.0218 0132 Ql10wnt - ok
    05:45:14.0296 0132 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
    05:45:14.0296 0132 ql12160 - ok
    05:45:14.0343 0132 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
    05:45:14.0343 0132 ql1240 - ok
    05:45:14.0390 0132 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
    05:45:14.0390 0132 ql1280 - ok
    05:45:14.0546 0132 RampartSvc - ok
    05:45:14.0640 0132 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
    05:45:14.0640 0132 RasAcd - ok
    05:45:14.0718 0132 RasAuto (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS\System32\rasauto.dll
    05:45:14.0718 0132 RasAuto - ok
    05:45:14.0828 0132 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
    05:45:14.0828 0132 Rasl2tp - ok
    05:45:14.0953 0132 RasMan (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS\System32\rasmans.dll
    05:45:14.0953 0132 RasMan - ok
    05:45:15.0000 0132 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
    05:45:15.0000 0132 RasPppoe - ok
    05:45:15.0031 0132 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
    05:45:15.0031 0132 Raspti - ok
    05:45:15.0109 0132 rassstp (b89cfbe8cb247b57d8c10adaa66b462b) C:\WINDOWS\system32\VRADFIL.dll
    05:45:15.0109 0132 Suspicious file (NoAccess): C:\WINDOWS\system32\VRADFIL.dll. md5: b89cfbe8cb247b57d8c10adaa66b462b
    05:45:15.0125 0132 rassstp ( LockedFile.Multi.Generic ) - warning
    05:45:15.0125 0132 rassstp - detected LockedFile.Multi.Generic (1)
    05:45:15.0234 0132 rcvpn (bca39c96b11318cbc2797c4b842e22e4) C:\WINDOWS\system32\DRIVERS\rcvpn.sys
    05:45:15.0265 0132 rcvpn - ok
    05:45:15.0359 0132 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
    05:45:15.0406 0132 Rdbss - ok
    05:45:15.0500 0132 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
    05:45:15.0500 0132 RDPCDD - ok
    05:45:15.0578 0132 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
    05:45:15.0609 0132 rdpdr - ok
    05:45:16.0015 0132 RDPWD (5b3055daa788bd688594d2f5981f2a83) C:\WINDOWS\system32\drivers\RDPWD.sys
    05:45:16.0046 0132 RDPWD - ok
    05:45:16.0140 0132 RDSessMgr (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS\system32\sessmgr.exe
    05:45:16.0156 0132 RDSessMgr - ok
    05:45:16.0250 0132 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
    05:45:16.0312 0132 redbook - ok
    05:45:16.0406 0132 RemoteAccess (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS\System32\mprdim.dll
    05:45:16.0406 0132 RemoteAccess - ok
    05:45:16.0500 0132 RimUsb (0f6756ef8bda6dfa7be50465c83132bb) C:\WINDOWS\system32\Drivers\RimUsb.sys
    05:45:16.0500 0132 RimUsb - ok
    05:45:16.0562 0132 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\WINDOWS\system32\DRIVERS\RimSerial.sys
    05:45:16.0562 0132 RimVSerPort - ok
    05:45:16.0640 0132 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
    05:45:16.0640 0132 ROOTMODEM - ok
    05:45:16.0781 0132 Roxio UPnP Renderer 9 (f3395d205dec030dce54d4575774cfba) C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
    05:45:16.0781 0132 Roxio UPnP Renderer 9 - ok
    05:45:16.0828 0132 Roxio Upnp Server 9 (95519cbef94773af7cd2b26029dceea7) C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
    05:45:16.0843 0132 Roxio Upnp Server 9 - ok
    05:45:16.0953 0132 RoxLiveShare9 (b9ea6e59e526b10a2a09f5b9d729797d) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
    05:45:16.0968 0132 RoxLiveShare9 - ok
    05:45:17.0031 0132 RoxMediaDB9 (3daf385624abf3c3bbfb05cff2aca7d6) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    05:45:17.0062 0132 RoxMediaDB9 - ok
    05:45:17.0109 0132 RoxWatch9 (8f366d03a7fda7527f76f01f695b0205) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    05:45:17.0125 0132 RoxWatch9 - ok
    05:45:17.0265 0132 RpcLocator (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS\system32\locator.exe
    05:45:17.0265 0132 RpcLocator - ok
    05:45:17.0359 0132 RpcSs (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\System32\rpcss.dll
    05:45:17.0359 0132 RpcSs - ok
    05:45:17.0421 0132 RSVP (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe
    05:45:17.0437 0132 RSVP - ok
    05:45:17.0531 0132 SamSs (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
    05:45:17.0531 0132 SamSs - ok
    05:45:17.0609 0132 SASDIFSV (5bf35c4ea3f00fa8d3f1e5bf03d24584) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
    05:45:17.0781 0132 SASDIFSV - ok
    05:45:17.0843 0132 SASENUM (a22f08c98ac2f44587bf3a1fb52bf8cd) C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
    05:45:17.0859 0132 SASENUM - ok
    05:45:17.0859 0132 SASKUTIL (c7d81c10d3befeee41f3408714637438) C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
    05:45:17.0906 0132 SASKUTIL - ok
    05:45:18.0031 0132 SCardSvr (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS\System32\SCardSvr.exe
    05:45:18.0031 0132 SCardSvr - ok
    05:45:18.0125 0132 Schedule (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS\system32\schedsvc.dll
    05:45:18.0140 0132 Schedule - ok
    05:45:18.0218 0132 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
    05:45:18.0218 0132 Secdrv - ok
    05:45:18.0281 0132 seclogon (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS\System32\seclogon.dll
    05:45:18.0281 0132 seclogon - ok
    05:45:18.0312 0132 SENS (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS\system32\sens.dll
    05:45:18.0312 0132 SENS - ok
    05:45:18.0390 0132 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
    05:45:18.0390 0132 serenum - ok
    05:45:18.0484 0132 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
    05:45:18.0484 0132 Serial - ok
    05:45:18.0578 0132 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
    05:45:18.0625 0132 Sfloppy - ok
    05:45:18.0750 0132 SharedAccess (83f41d0d89645d7235c051ab1d9523ac) C:\WINDOWS\System32\ipnathlp.dll
    05:45:18.0765 0132 SharedAccess - ok
    05:45:18.0859 0132 ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
    05:45:18.0859 0132 ShellHWDetection - ok
    05:45:18.0906 0132 Simbad - ok
    05:45:19.0000 0132 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
    05:45:19.0000 0132 sisagp - ok
    05:45:19.0078 0132 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
    05:45:19.0078 0132 Sparrow - ok
    05:45:19.0140 0132 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
    05:45:19.0156 0132 splitter - ok
    05:45:19.0234 0132 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
    05:45:19.0234 0132 Spooler - ok
    05:45:19.0328 0132 sprtsvc_dellsupportcenter - ok
    05:45:19.0468 0132 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
    05:45:19.0468 0132 sr - ok
    05:45:19.0531 0132 srservice (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS\system32\srsvc.dll
    05:45:19.0546 0132 srservice - ok
    05:45:19.0640 0132 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
    05:45:19.0671 0132 Srv - ok
    05:45:19.0718 0132 SSDPSRV (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS\System32\ssdpsrv.dll
    05:45:19.0718 0132 SSDPSRV - ok
    05:45:19.0796 0132 STHDA (352b663a81402be7cd7bd4ea27c9998c) C:\WINDOWS\system32\drivers\sthda.sys
    05:45:19.0812 0132 STHDA - ok
    05:45:19.0906 0132 stisvc (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS\system32\wiaservc.dll
    05:45:19.0921 0132 stisvc - ok
    05:45:19.0953 0132 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
    05:45:19.0953 0132 swenum - ok
    05:45:19.0984 0132 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
    05:45:20.0000 0132 swmidi - ok
    05:45:20.0078 0132 SwPrv - ok
    05:45:20.0140 0132 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
    05:45:20.0140 0132 symc810 - ok
    05:45:20.0234 0132 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
    05:45:20.0234 0132 symc8xx - ok
    05:45:20.0312 0132 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
    05:45:20.0312 0132 sym_hi - ok
    05:45:20.0359 0132 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
    05:45:20.0375 0132 sym_u3 - ok
    05:45:20.0437 0132 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
    05:45:20.0453 0132 sysaudio - ok
    05:45:20.0515 0132 SysmonLog (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS\system32\smlogsvc.exe
    05:45:20.0515 0132 SysmonLog - ok
    05:45:20.0671 0132 TapiSrv (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS\System32\tapisrv.dll
    05:45:20.0687 0132 TapiSrv - ok
    05:45:20.0796 0132 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
    05:45:20.0812 0132 Tcpip - ok
    05:45:20.0906 0132 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
    05:45:20.0906 0132 TDPIPE - ok
    05:45:21.0046 0132 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
    05:45:21.0046 0132 TDTCP - ok
    05:45:21.0171 0132 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
    05:45:21.0171 0132 TermDD - ok
    05:45:21.0250 0132 TermService (ff3477c03be7201c294c35f684b3479f) C:\WINDOWS\System32\termsrv.dll
    05:45:21.0265 0132 TermService - ok
    05:45:21.0343 0132 Themes (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
    05:45:21.0343 0132 Themes - ok
    05:45:21.0453 0132 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
    05:45:21.0453 0132 TosIde - ok
    05:45:21.0531 0132 TrkWks (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS\system32\trkwks.dll
    05:45:21.0531 0132 TrkWks - ok
    05:45:21.0671 0132 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
    05:45:21.0671 0132 Udfs - ok
    05:45:21.0750 0132 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
    05:45:21.0750 0132 ultra - ok
    05:45:21.0859 0132 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
    05:45:21.0906 0132 Update - ok
    05:45:22.0031 0132 upnphost (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS\System32\upnphost.dll
    05:45:22.0046 0132 upnphost - ok
    05:45:22.0125 0132 UPS (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS\System32\ups.exe
    05:45:22.0125 0132 UPS - ok
    05:45:22.0218 0132 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\WINDOWS\system32\Drivers\usbaapl.sys
    05:45:22.0250 0132 USBAAPL - ok
    05:45:22.0390 0132 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
    05:45:22.0390 0132 usbccgp - ok
    05:45:22.0640 0132 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
    05:45:22.0640 0132 usbehci - ok
    05:45:22.0765 0132 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
    05:45:22.0765 0132 usbhub - ok
    05:45:22.0890 0132 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
    05:45:22.0890 0132 usbprint - ok
    05:45:22.0953 0132 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
    05:45:22.0953 0132 usbscan - ok
    05:45:23.0156 0132 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
    05:45:23.0156 0132 USBSTOR - ok
    05:45:23.0234 0132 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
    05:45:23.0234 0132 usbuhci - ok
    05:45:23.0359 0132 USB_RNDIS_XP (b89cfbe8cb247b57d8c10adaa66b462b) C:\WINDOWS\system32\smcirda.dll
    05:45:23.0375 0132 Suspicious file (NoAccess): C:\WINDOWS\system32\smcirda.dll. md5: b89cfbe8cb247b57d8c10adaa66b462b
    05:45:23.0375 0132 USB_RNDIS_XP ( LockedFile.Multi.Generic ) - warning
    05:45:23.0375 0132 USB_RNDIS_XP - detected LockedFile.Multi.Generic (1)
    05:45:23.0656 0132 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
    05:45:23.0656 0132 VgaSave - ok
    05:45:23.0734 0132 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
    05:45:23.0734 0132 viaagp - ok
    05:45:23.0921 0132 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
    05:45:23.0921 0132 ViaIde - ok
    05:45:24.0015 0132 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
    05:45:24.0031 0132 VolSnap - ok
    05:45:24.0171 0132 vsdatant (0354ba3a5ba5e28cc247eb5f5dd8793c) C:\WINDOWS\system32\vsdatant.sys
    05:45:24.0187 0132 vsdatant - ok
    05:45:24.0281 0132 VSS (7a9db3a67c333bf0bd42e42b8596854b) C:\WINDOWS\System32\vssvc.exe
    05:45:24.0375 0132 VSS - ok
    05:45:24.0453 0132 w32time (54af4b1d5459500ef0937f6d33b1914f) C:\WINDOWS\system32\w32time.dll
    05:45:24.0468 0132 w32time - ok
    05:45:24.0625 0132 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
    05:45:24.0625 0132 Wanarp - ok
    05:45:24.0750 0132 wanatw - ok
    05:45:24.0781 0132 WDICA - ok
    05:45:24.0968 0132 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
    05:45:24.0968 0132 wdmaud - ok
    05:45:25.0140 0132 WebClient (77a354e28153ad2d5e120a5a8687bc06) C:\WINDOWS\System32\webclnt.dll
    05:45:25.0171 0132 WebClient - ok
    05:45:25.0484 0132 winmgmt (2d0e4ed081963804ccc196a0929275b5) C:\WINDOWS\system32\wbem\WMIsvc.dll
    05:45:25.0578 0132 winmgmt - ok
    05:45:25.0859 0132 WmdmPmSN (c51b4a5c05a5475708e3c81c7765b71d) C:\WINDOWS\system32\MsPMSNSv.dll
    05:45:25.0890 0132 WmdmPmSN - ok
    05:45:26.0203 0132 WmiApSrv (e0673f1106e62a68d2257e376079f821) C:\WINDOWS\system32\wbem\wmiapsrv.exe
    05:45:26.0218 0132 WmiApSrv - ok
    05:45:26.0546 0132 WMPNetworkSvc (f74e3d9a7fa9556c3bbb14d4e5e63d3b) C:\Program Files\Windows Media Player\WMPNetwk.exe
    05:45:26.0640 0132 WMPNetworkSvc - ok
    05:45:26.0968 0132 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
    05:45:27.0015 0132 WpdUsb - ok
    05:45:27.0328 0132 wuauserv (35321fb577cdc98ce3eb3a3eb9e4610a) C:\WINDOWS\system32\wuauserv.dll
    05:45:27.0359 0132 wuauserv - ok
    05:45:27.0609 0132 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
    05:45:27.0625 0132 WudfPf - ok
    05:45:27.0968 0132 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
    05:45:27.0968 0132 WudfRd - ok
    05:45:28.0140 0132 WudfSvc (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll
    05:45:28.0140 0132 WudfSvc - ok
    05:45:28.0421 0132 WZCSVC (81dc3f549f44b1c1fff022dec9ecf30b) C:\WINDOWS\System32\wzcsvc.dll
    05:45:28.0468 0132 WZCSVC - ok
    05:45:28.0703 0132 xmlprov (295d21f14c335b53cb8154e5b1f892b9) C:\WINDOWS\System32\xmlprov.dll
    05:45:28.0718 0132 xmlprov - ok
    05:45:29.0015 0132 z525mgmt (b89cfbe8cb247b57d8c10adaa66b462b) C:\WINDOWS\system32\asyncmac.dll
    05:45:29.0015 0132 Suspicious file (NoAccess): C:\WINDOWS\system32\asyncmac.dll. md5: b89cfbe8cb247b57d8c10adaa66b462b
    05:45:29.0015 0132 z525mgmt ( LockedFile.Multi.Generic ) - warning
    05:45:29.0015 0132 z525mgmt - detected LockedFile.Multi.Generic (1)
    05:45:29.0078 0132 MBR (0x1B8) (b16a2359f4962b0c622d81a1c1f4b703) \Device\Harddisk0\DR0
    05:45:29.0156 0132 \Device\Harddisk0\DR0 - ok
    05:45:29.0187 0132 Boot (0x1200) (5ce50ee8af3cc790b4a72be44f765f56) \Device\Harddisk0\DR0\Partition0
    05:45:29.0203 0132 \Device\Harddisk0\DR0\Partition0 - ok
    05:45:29.0203 0132 ============================================================
    05:45:29.0203 0132 Scan finished
    05:45:29.0203 0132 ============================================================
    05:45:29.0218 2232 Detected object count: 10
    05:45:29.0218 2232 Actual detected object count: 10
    05:46:29.0328 2232 acdservice ( LockedFile.Multi.Generic ) - skipped by user
    05:46:29.0328 2232 acdservice ( LockedFile.Multi.Generic ) - User select action: Skip
    05:46:29.0343 2232 cmdmon ( LockedFile.Multi.Generic ) - skipped by user
    05:46:29.0343 2232 cmdmon ( LockedFile.Multi.Generic ) - User select action: Skip
    05:46:29.0343 2232 cusrvc ( LockedFile.Multi.Generic ) - skipped by user
    05:46:29.0343 2232 cusrvc ( LockedFile.Multi.Generic ) - User select action: Skip
    05:46:29.0343 2232 elagopro ( LockedFile.Multi.Generic ) - skipped by user
    05:46:29.0343 2232 elagopro ( LockedFile.Multi.Generic ) - User select action: Skip
    05:46:29.0343 2232 gearsecurity ( LockedFile.Multi.Generic ) - skipped by user
    05:46:29.0343 2232 gearsecurity ( LockedFile.Multi.Generic ) - User select action: Skip
    05:46:29.0343 2232 msgame ( LockedFile.Multi.Generic ) - skipped by user
    05:46:29.0343 2232 msgame ( LockedFile.Multi.Generic ) - User select action: Skip
    05:46:29.0343 2232 nvgts ( LockedFile.Multi.Generic ) - skipped by user
    05:46:29.0343 2232 nvgts ( LockedFile.Multi.Generic ) - User select action: Skip
    05:46:29.0343 2232 rassstp ( LockedFile.Multi.Generic ) - skipped by user
    05:46:29.0343 2232 rassstp ( LockedFile.Multi.Generic ) - User select action: Skip
    05:46:29.0359 2232 USB_RNDIS_XP ( LockedFile.Multi.Generic ) - skipped by user
    05:46:29.0359 2232 USB_RNDIS_XP ( LockedFile.Multi.Generic ) - User select action: Skip
    05:46:29.0359 2232 z525mgmt ( LockedFile.Multi.Generic ) - skipped by user
    05:46:29.0359 2232 z525mgmt ( LockedFile.Multi.Generic ) - User select action: Skip
     
  5. 2012/03/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results ". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion ", restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.
    Vista and Win7 users need to right click Rkill and choose Run as Administrator
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    * Rkill.com
    * Rkill.scr
    * Rkill.exe
    • Double-click on the Rkill icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.
    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  6. 2012/03/28
    dave1234

    dave1234 Well-Known Member Thread Starter

    Joined:
    2002/12/21
    Messages:
    196
    Likes Received:
    0
    ComboFix 12-03-28.02 - David Peters 03/28/2012 20:19:46.8.2 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.197 [GMT -4:00]
    Running from: c:\documents and settings\David Peters\My Documents\Downloads\ComboFix.exe
    AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
    AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\David Peters\Application Data\PriceGong
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\1.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\a.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\b.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\c.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\d.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\e.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\f.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\g.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\h.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\i.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\j.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\k.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\l.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\m.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\mru.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\n.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\o.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\p.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\q.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\r.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\s.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\t.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\u.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\v.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\w.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\x.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\y.xml
    c:\documents and settings\David Peters\Application Data\PriceGong\Data\z.xml
    c:\documents and settings\David Peters\Local Settings\Application Data\bc5c6f8d
    c:\documents and settings\David Peters\Local Settings\Application Data\bc5c6f8d\@
    c:\documents and settings\David Peters\Local Settings\Application Data\bc5c6f8d\U\000000cb.@
    c:\documents and settings\David Peters\Local Settings\Application Data\bc5c6f8d\X
    c:\documents and settings\David Peters\Recent\513131978255122748771526959551216535149447773337926816489574145323337561785812533557455382554796875653799983657432827849584379195.212
    c:\documents and settings\David Peters\Recent\872995555969518587933842378296261234427752194473662431355557144592944379625361945818572882787863294447128315581924814683296938718.961
    c:\documents and settings\David Peters\Recent\895387458187663168977686556581242819141666193138448696894737272587527188445624839768363325668756719536429852556132511478892737979.166
    c:\documents and settings\David Peters\Recent\998482757839923316446378931825123517999165585791974651415259743217112948639683537327197522822732229979166467386936927859779193716.181
    c:\windows\$NtUninstallKB11310$
    c:\windows\$NtUninstallKB11310$\3160174477\@
    c:\windows\$NtUninstallKB11310$\3160174477\L\odetmngk
    c:\windows\$NtUninstallKB11310$\3160174477\loader.tlb
    c:\windows\$NtUninstallKB11310$\3160174477\U\@00000001
    c:\windows\$NtUninstallKB11310$\3160174477\U\@000000c0
    c:\windows\$NtUninstallKB11310$\3160174477\U\@000000cb
    c:\windows\$NtUninstallKB11310$\3160174477\U\@000000cf
    c:\windows\$NtUninstallKB11310$\3160174477\U\@80000000
    c:\windows\$NtUninstallKB11310$\3160174477\U\@800000c0
    c:\windows\$NtUninstallKB11310$\3160174477\U\@800000cb
    c:\windows\$NtUninstallKB11310$\3160174477\U\@800000cf
    c:\windows\$NtUninstallKB11310$\680285935
    c:\windows\system32\dds_log_ad13.cmd
    .
    Infected copy of c:\windows\system32\drivers\cdrom.sys was found and disinfected
    Restored copy from - c:\windows\ServicePackFiles\i386\cdrom.sys
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-02-28 to 2012-03-29 )))))))))))))))))))))))))))))))
    .
    .
    2012-03-29 00:39 . 2012-03-29 00:39 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0D18E41F-EBED-4A1F-A226-3D59CA43E3ED}\offreg.dll
    2012-03-28 22:39 . 2012-03-14 02:15 6582328 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0D18E41F-EBED-4A1F-A226-3D59CA43E3ED}\mpengine.dll
    2012-03-27 11:41 . 2012-03-27 11:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
    2012-03-17 22:46 . 2012-03-17 22:46 592824 ----a-w- c:\program files\Mozilla Firefox\gkmedias.dll
    2012-03-17 22:46 . 2012-03-17 22:46 44472 ----a-w- c:\program files\Mozilla Firefox\mozglue.dll
    2012-03-08 12:37 . 2012-03-08 12:37 86016 ---ha-w- c:\windows\fastay32.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-03-14 02:15 . 2011-11-01 09:16 6582328 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2012-02-03 09:22 . 2004-08-10 18:51 1860096 ----a-w- c:\windows\system32\win32k.sys
    2012-01-31 12:44 . 2010-10-22 22:58 237072 ------w- c:\windows\system32\MpSigStub.exe
    2012-01-11 19:06 . 2012-02-15 10:37 3072 ------w- c:\windows\system32\iacenc.dll
    2012-01-09 16:20 . 2004-08-10 19:01 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
    2012-01-04 00:48 . 2012-01-04 00:48 354176 ----a-w- c:\windows\system32\DivXControlPanelApplet.cpl
    2012-03-17 22:46 . 2011-05-24 00:29 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    2004-08-04 11:00 94784 -csh--w- c:\windows\twain.dll
    2008-04-14 00:12 50688 -csh--w- c:\windows\twain_32.dll
    .
    .
    ((((((((((((((((((((((((((((( SnapShot_2011-07-07_01.21.42 )))))))))))))))))))))))))))))))))))))))))
    .
    + 1999-12-07 05:00 . 1999-12-07 05:00 24976 c:\windows\twain_16.dll
    + 2012-03-29 00:38 . 2012-03-29 00:38 16384 c:\windows\temp\Perflib_Perfdata_2ac.dat
    + 2007-11-15 00:04 . 2007-11-15 00:04 83432 c:\windows\system32\vsdata.dll
    - 2007-01-29 08:58 . 2010-11-03 13:12 46080 c:\windows\system32\tzchange.exe
    + 2007-01-29 08:58 . 2011-11-08 13:46 46080 c:\windows\system32\tzchange.exe
    + 2011-10-31 22:30 . 2005-11-08 14:58 24876 c:\windows\system32\ReinstallBackups\0017\DriverFiles\rcvpn.sys
    + 2004-08-10 18:51 . 2012-03-29 00:43 73004 c:\windows\system32\perfc009.dat
    + 2004-08-10 18:51 . 2011-11-18 12:35 60416 c:\windows\system32\packager.exe
    + 2004-08-10 18:51 . 2011-09-26 15:41 20480 c:\windows\system32\oleaccrc.dll
    + 2004-08-10 18:51 . 2011-12-17 19:46 66560 c:\windows\system32\mshtmled.dll
    - 2004-08-10 18:51 . 2011-04-25 16:11 66560 c:\windows\system32\mshtmled.dll
    + 2009-03-08 08:31 . 2011-12-17 19:46 55296 c:\windows\system32\msfeedsbs.dll
    - 2009-03-08 08:31 . 2011-04-25 16:11 55296 c:\windows\system32\msfeedsbs.dll
    + 2004-08-10 18:51 . 2011-10-14 14:47 23040 c:\windows\system32\mciseq.dll
    - 2004-08-10 18:51 . 2008-04-14 00:11 23040 c:\windows\system32\mciseq.dll
    + 2004-08-10 18:51 . 2011-12-17 19:46 43520 c:\windows\system32\licmgr10.dll
    - 2004-08-10 18:51 . 2011-04-25 16:11 43520 c:\windows\system32\licmgr10.dll
    - 2004-08-10 18:51 . 2011-04-25 16:11 25600 c:\windows\system32\jsproxy.dll
    + 2004-08-10 18:51 . 2011-12-17 19:46 25600 c:\windows\system32\jsproxy.dll
    + 2011-10-26 01:31 . 2011-08-02 21:38 42496 c:\windows\system32\DRVSTORE\usbaapl_091115F4EDEB41DBA0EC91574CE905B4E0482482\usbaapl.sys
    + 2011-10-26 01:31 . 2011-08-02 21:38 18432 c:\windows\system32\DRVSTORE\netaapl_63AA05C4700EB9CAF2D048DAC1D06D764A0D4C41\netaapl.sys
    + 2009-11-06 13:40 . 2011-08-02 21:38 42496 c:\windows\system32\drivers\usbaapl.sys
    + 2004-08-04 05:08 . 2008-04-13 18:45 49408 c:\windows\system32\drivers\stream.sys
    - 2004-08-04 05:08 . 2008-04-13 18:45 49408 c:\windows\system32\drivers\stream.sys
    + 2011-01-12 00:01 . 2005-11-08 13:58 24876 c:\windows\system32\drivers\rcvpn.sys
    - 2011-01-12 00:01 . 2005-11-08 14:58 24876 c:\windows\system32\drivers\rcvpn.sys
    + 2011-01-12 00:02 . 2008-03-19 14:12 86552 c:\windows\system32\drivers\RCFOX.SYS
    - 2011-01-12 00:02 . 2008-03-19 15:12 86552 c:\windows\system32\drivers\RCFOX.SYS
    + 2004-08-10 18:51 . 2011-07-08 14:02 10496 c:\windows\system32\drivers\ndistapi.sys
    + 2009-09-13 10:17 . 2011-12-10 20:24 20464 c:\windows\system32\drivers\mbam.sys
    + 2007-07-20 23:40 . 2007-07-20 23:40 84992 c:\windows\system32\drivers\AtiHdmi.sys
    + 2011-01-27 03:12 . 2011-01-27 03:12 53248 c:\windows\system32\drivers\ati2erec.dll
    - 2010-11-12 00:44 . 2010-11-12 00:44 94208 c:\windows\system32\dpl100.dll
    + 2011-07-22 20:51 . 2011-07-22 20:51 94208 c:\windows\system32\dpl100.dll
    + 2011-08-31 03:05 . 2011-08-31 03:05 73064 c:\windows\system32\dnssd.dll
    + 2011-08-31 03:05 . 2011-08-31 03:05 83816 c:\windows\system32\dns-sd.exe
    - 2009-07-03 09:18 . 2011-04-25 16:11 12800 c:\windows\system32\dllcache\xpshims.dll
    + 2009-07-03 09:18 . 2011-12-17 19:46 12800 c:\windows\system32\dllcache\xpshims.dll
    + 2004-08-04 05:08 . 2008-04-13 18:45 49408 c:\windows\system32\dllcache\stream.sys
    + 2011-11-18 12:35 . 2011-11-18 12:35 60416 c:\windows\system32\dllcache\packager.exe
    + 2004-08-10 18:51 . 2011-09-26 15:41 20480 c:\windows\system32\dllcache\oleaccrc.dll
    + 2011-08-10 22:13 . 2011-07-08 14:02 10496 c:\windows\system32\dllcache\ndistapi.sys
    + 2009-03-08 08:31 . 2011-12-17 19:46 66560 c:\windows\system32\dllcache\mshtmled.dll
    - 2009-03-08 08:31 . 2011-04-25 16:11 66560 c:\windows\system32\dllcache\mshtmled.dll
    - 2009-07-29 09:36 . 2011-04-25 16:11 55296 c:\windows\system32\dllcache\msfeedsbs.dll
    + 2009-07-29 09:36 . 2011-12-17 19:46 55296 c:\windows\system32\dllcache\msfeedsbs.dll
    + 2011-10-14 14:47 . 2011-10-14 14:47 23040 c:\windows\system32\dllcache\mciseq.dll
    + 2009-03-08 08:34 . 2011-12-17 19:46 43520 c:\windows\system32\dllcache\licmgr10.dll
    - 2009-03-08 08:34 . 2011-04-25 16:11 43520 c:\windows\system32\dllcache\licmgr10.dll
    - 2009-03-08 08:33 . 2011-04-25 16:11 25600 c:\windows\system32\dllcache\jsproxy.dll
    + 2009-03-08 08:33 . 2011-12-17 19:46 25600 c:\windows\system32\dllcache\jsproxy.dll
    + 2004-08-10 19:02 . 2008-04-14 00:12 20480 c:\windows\system32\dllcache\inetwiz.exe
    + 2004-08-10 19:02 . 2008-04-14 00:11 49152 c:\windows\system32\dllcache\icwutil.dll
    + 2004-08-10 19:02 . 2008-04-14 00:12 24576 c:\windows\system32\dllcache\icwrmind.exe
    + 2004-08-10 19:02 . 2008-04-14 00:11 32768 c:\windows\system32\dllcache\icwdl.dll
    + 2004-08-10 19:02 . 2008-04-14 00:12 86016 c:\windows\system32\dllcache\icwconn2.exe
    + 2004-08-10 19:02 . 2008-04-14 00:11 61440 c:\windows\system32\dllcache\icwconn.dll
    + 2005-11-02 08:25 . 2008-04-13 18:45 60160 c:\windows\system32\dllcache\drmk.sys
    + 2009-12-14 07:08 . 2011-10-28 05:31 33280 c:\windows\system32\dllcache\csrsrv.dll
    - 2009-12-14 07:08 . 2010-12-09 14:30 33280 c:\windows\system32\dllcache\csrsrv.dll
    + 2004-08-10 18:50 . 2011-10-28 05:31 33280 c:\windows\system32\csrsrv.dll
    - 2004-08-10 18:50 . 2010-12-09 14:30 33280 c:\windows\system32\csrsrv.dll
    + 2001-11-09 21:01 . 2001-11-09 21:01 24064 c:\windows\system32\ativcoxx.dll
    + 2011-01-27 03:21 . 2011-01-27 03:21 17408 c:\windows\system32\atitvo32.dll
    + 2009-06-22 21:34 . 2009-06-22 21:34 45056 c:\windows\system32\ATIODCLI.exe
    + 2011-01-27 03:13 . 2011-01-27 03:13 64512 c:\windows\system32\atimpc32.dll
    + 2011-01-27 03:28 . 2011-01-27 03:28 53248 c:\windows\system32\ATIDDC.DLL
    + 2011-01-27 04:01 . 2011-01-27 04:01 57344 c:\windows\system32\aticalrt.dll
    + 2011-01-27 04:00 . 2011-01-27 04:00 53248 c:\windows\system32\aticalcl.dll
    + 2011-01-27 03:31 . 2011-01-27 03:31 26112 c:\windows\system32\Ati2mdxx.exe
    + 2011-01-27 03:31 . 2011-01-27 03:31 43520 c:\windows\system32\ati2edxx.dll
    + 2011-01-27 03:13 . 2011-01-27 03:13 64512 c:\windows\system32\amdpcom32.dll
    + 2011-12-25 08:49 . 2011-12-25 08:49 31504 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
    - 2010-09-23 19:55 . 2010-09-23 19:55 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
    + 2011-12-25 16:07 . 2011-12-25 16:07 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
    - 2010-09-23 06:26 . 2010-09-23 06:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
    + 2011-12-25 03:55 . 2011-12-25 03:55 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
    + 2011-12-25 03:55 . 2011-12-25 03:55 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
    - 2010-09-23 06:26 . 2010-09-23 06:26 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
    - 2010-09-23 06:26 . 2010-09-23 06:26 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
    + 2011-12-25 03:55 . 2011-12-25 03:55 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
    - 2010-09-23 07:17 . 2010-09-23 07:17 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
    + 2011-12-25 04:49 . 2011-12-25 04:49 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
    + 2011-12-25 04:49 . 2011-12-25 04:49 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
    - 2010-09-23 07:17 . 2010-09-23 07:17 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
    + 2012-03-21 09:38 . 2012-03-21 09:38 22016 c:\windows\Installer\5ab3f.msi
    + 2012-02-19 23:45 . 2012-02-19 23:45 36352 c:\windows\Installer\10401508.msi
    + 2011-10-26 01:34 . 2011-10-26 01:34 27136 c:\windows\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\AppleSoftwareUpdateIco.exe
    + 2011-11-21 11:15 . 2011-11-21 11:15 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
    + 2011-11-21 11:15 . 2011-11-21 11:15 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74.exe
    + 2011-11-21 11:15 . 2011-11-21 11:15 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
    + 2011-11-21 11:15 . 2011-11-21 11:15 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
    + 2011-11-21 11:15 . 2011-11-21 11:15 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\googleearth.exe1_F6A848FB884248E6A4CDCBDCF41F6A74.exe
    + 2011-11-21 11:15 . 2011-11-21 11:15 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\googleearth.exe_F6A848FB884248E6A4CDCBDCF41F6A74.exe
    + 2011-11-21 11:15 . 2011-11-21 11:15 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\ARPPRODUCTICON.exe
    + 2012-02-16 08:02 . 2011-11-04 19:20 12800 c:\windows\ie8updates\KB2647516-IE8\xpshims.dll
    + 2012-02-16 08:02 . 2011-11-04 19:20 66560 c:\windows\ie8updates\KB2647516-IE8\mshtmled.dll
    + 2012-02-16 08:02 . 2011-11-04 19:20 55296 c:\windows\ie8updates\KB2647516-IE8\msfeedsbs.dll
    + 2012-02-16 08:02 . 2011-11-04 19:20 43520 c:\windows\ie8updates\KB2647516-IE8\licmgr10.dll
    + 2012-02-16 08:02 . 2011-11-04 19:20 25600 c:\windows\ie8updates\KB2647516-IE8\jsproxy.dll
    + 2011-12-15 15:35 . 2011-08-22 23:48 12800 c:\windows\ie8updates\KB2618444-IE8\xpshims.dll
    + 2011-12-15 15:35 . 2011-08-22 23:48 66560 c:\windows\ie8updates\KB2618444-IE8\mshtmled.dll
    + 2011-12-15 15:35 . 2011-08-22 23:48 55296 c:\windows\ie8updates\KB2618444-IE8\msfeedsbs.dll
    + 2011-12-15 15:35 . 2011-08-22 23:48 43520 c:\windows\ie8updates\KB2618444-IE8\licmgr10.dll
    + 2011-12-15 15:35 . 2011-08-22 23:48 25600 c:\windows\ie8updates\KB2618444-IE8\jsproxy.dll
    + 2011-10-14 07:02 . 2011-06-23 18:36 12800 c:\windows\ie8updates\KB2586448-IE8\xpshims.dll
    + 2011-10-14 07:02 . 2011-06-23 18:36 66560 c:\windows\ie8updates\KB2586448-IE8\mshtmled.dll
    + 2011-10-14 07:02 . 2011-06-23 18:36 55296 c:\windows\ie8updates\KB2586448-IE8\msfeedsbs.dll
    + 2011-10-14 07:02 . 2011-06-23 18:36 43520 c:\windows\ie8updates\KB2586448-IE8\licmgr10.dll
    + 2011-10-14 07:02 . 2011-06-23 18:36 25600 c:\windows\ie8updates\KB2586448-IE8\jsproxy.dll
    + 2011-08-11 01:14 . 2011-04-25 16:11 12800 c:\windows\ie8updates\KB2559049-IE8\xpshims.dll
    + 2011-08-11 01:14 . 2011-04-25 16:11 66560 c:\windows\ie8updates\KB2559049-IE8\mshtmled.dll
    + 2011-08-11 01:14 . 2011-04-25 16:11 55296 c:\windows\ie8updates\KB2559049-IE8\msfeedsbs.dll
    + 2011-08-11 01:14 . 2011-04-25 16:11 43520 c:\windows\ie8updates\KB2559049-IE8\licmgr10.dll
    + 2011-08-11 01:14 . 2011-04-25 16:11 25600 c:\windows\ie8updates\KB2559049-IE8\jsproxy.dll
    + 2012-01-12 08:08 . 2012-01-12 08:08 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_ab5a6a14\System.Drawing.Design.dll
    + 2012-01-12 08:08 . 2012-01-12 08:08 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_e0ce0942\CustomMarshalers.dll
    + 2011-10-14 22:01 . 2011-10-14 22:01 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\888b745ca99d39692c2e9af222e5eae8\UIAutomationProvider.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\dab766b18e6fe0a8f53a93c56be7b40e\System.Windows.Presentation.ni.dll
    + 2011-10-14 22:14 . 2011-10-14 22:14 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\6c334564da041df8fb75415f2d503224\System.Windows.Presentation.ni.dll
    + 2012-01-12 08:14 . 2012-01-12 08:14 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\750de53f30e516eb2c62de9bab7954e9\System.Web.DynamicData.Design.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\31b65443e56a470d199f293085576e05\System.Web.DynamicData.Design.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\ac92806d5bd508eb25f1b4b73a36b101\System.ComponentModel.DataAnnotations.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\89dfd3999ad1d72c59243d7b4bf40d5a\System.ComponentModel.DataAnnotations.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\e6a9cd66d11a21776dbf425e8e28099c\System.AddIn.Contract.ni.dll
    + 2011-10-14 21:59 . 2011-10-14 21:59 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\66873b557d5c7013e4c630361473b0c2\PresentationFontCache.ni.exe
    + 2012-02-16 08:11 . 2012-02-16 08:11 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\3aa4296d4aa01fe0533de2c15f818d5f\PresentationFontCache.ni.exe
    + 2012-02-16 08:11 . 2012-02-16 08:11 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\820acb71782d9cd006800b3ac7e1ca53\PresentationCFFRasterizer.ni.dll
    + 2011-10-14 21:58 . 2011-10-14 21:58 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5b30652a7b802199984f93b5e414260f\PresentationCFFRasterizer.ni.dll
    + 2011-10-14 22:14 . 2011-10-14 22:14 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\eaa8d72317e5b8047e413939cc71ffba\Microsoft.Vsa.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\d07f0222f62dbed7898a6e2e909d407a\Microsoft.Vsa.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\aefe683674c97a998f4e908c1a7ee7c6\Microsoft.Build.Framework.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\845eef4d09f28da6ee05d99f93c90f6e\Microsoft.Build.Framework.ni.dll
    + 2011-10-14 22:11 . 2011-10-14 22:11 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\ab7ce2d94ca725c3889a4e3c1ee88ece\dfsvc.ni.exe
    + 2011-10-14 22:02 . 2011-10-14 22:02 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    + 2012-01-12 08:08 . 2012-01-12 08:08 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
    - 2010-10-08 02:53 . 2010-10-08 02:53 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
    + 2011-12-15 15:30 . 2011-07-08 13:49 46080 c:\windows\$NtUninstallKB2633952$\tzchange.exe
    + 2011-12-15 15:30 . 2011-11-08 14:58 16896 c:\windows\$NtUninstallKB2633952$\spuninst\tzchange.dll
    + 2011-12-15 15:30 . 2011-04-26 11:07 33280 c:\windows\$NtUninstallKB2620712$\csrsrv.dll
    + 2012-01-12 08:10 . 2008-04-14 00:11 23040 c:\windows\$NtUninstallKB2598479$\mciseq.dll
    + 2012-01-12 08:02 . 2008-04-14 00:12 58368 c:\windows\$NtUninstallKB2584146$\packager.exe
    + 2011-08-25 08:22 . 2010-11-03 13:12 46080 c:\windows\$NtUninstallKB2570791$\tzchange.exe
    + 2011-08-25 08:22 . 2011-07-09 00:32 16896 c:\windows\$NtUninstallKB2570791$\spuninst\tzchange.dll
    + 2011-08-11 01:14 . 2008-04-13 18:57 10112 c:\windows\$NtUninstallKB2566454$\ndistapi.sys
    + 2011-10-14 07:08 . 2004-08-04 11:00 16896 c:\windows\$NtUninstallKB2564958$\oleaccrc.dll
    + 2011-07-14 01:45 . 2010-12-09 14:30 33280 c:\windows\$NtUninstallKB2507938$\csrsrv.dll
    + 2012-02-16 08:02 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2661637\update\spcustom.dll
    + 2012-02-16 08:02 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2661637\spmsg.dll
    + 2012-02-16 08:03 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2660465\update\spcustom.dll
    + 2012-02-16 08:03 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2660465\spmsg.dll
    + 2012-02-16 08:03 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2647516-IE8\update\spcustom.dll
    + 2012-02-16 08:03 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2647516-IE8\spmsg.dll
    + 2012-02-15 10:37 . 2011-12-17 19:45 12800 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\xpshims.dll
    + 2012-02-15 10:37 . 2011-12-17 19:45 66560 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\mshtmled.dll
    + 2012-02-15 10:37 . 2011-12-17 19:45 55296 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\msfeedsbs.dll
    + 2012-02-15 10:37 . 2011-12-17 19:45 43520 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\licmgr10.dll
    + 2012-02-15 10:37 . 2011-12-17 19:45 25600 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\jsproxy.dll
    + 2012-01-12 08:16 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2646524\update\spcustom.dll
    + 2012-01-12 08:16 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2646524\spmsg.dll
    + 2011-11-12 02:14 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2641690\update\spcustom.dll
    + 2011-11-12 02:14 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2641690\spmsg.dll
    + 2011-12-15 15:36 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2639417\update\spcustom.dll
    + 2011-12-15 15:36 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2639417\spmsg.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2633171\update\spcustom.dll
    + 2011-12-15 10:02 . 2011-10-26 10:50 16896 c:\windows\$hf_mig$\KB2633171\update\mpsyschk.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2633171\spmsg.dll
    + 2012-01-12 08:16 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2631813\update\spcustom.dll
    + 2012-01-12 08:16 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2631813\spmsg.dll
    + 2011-12-15 15:36 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2624667\update\spcustom.dll
    + 2011-12-15 15:36 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2624667\spmsg.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2620712\update\spcustom.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2620712\spmsg.dll
    + 2011-10-28 05:31 . 2011-10-28 05:31 33280 c:\windows\$hf_mig$\KB2620712\SP3QFE\csrsrv.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2619339\update\spcustom.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2619339\spmsg.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2618451\update\spcustom.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2618451\spmsg.dll
    + 2011-12-15 15:35 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2618444-IE8\update\spcustom.dll
    + 2011-12-15 15:35 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2618444-IE8\spmsg.dll
    + 2011-12-15 10:01 . 2011-11-04 19:19 12800 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\xpshims.dll
    + 2011-12-15 10:01 . 2011-11-04 19:19 66560 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\mshtmled.dll
    + 2011-12-15 10:01 . 2011-11-04 19:19 55296 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\msfeedsbs.dll
    + 2011-12-15 10:01 . 2011-11-04 19:19 43520 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\licmgr10.dll
    + 2011-12-15 10:01 . 2011-11-04 19:19 25600 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\jsproxy.dll
    + 2011-09-16 02:07 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2616676\update\spcustom.dll
    + 2011-09-16 02:07 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2616676\spmsg.dll
    + 2011-09-08 02:21 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2607712\update\spcustom.dll
    + 2011-09-08 02:21 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2607712\spmsg.dll
    + 2012-01-12 08:02 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2603381\update\spcustom.dll
    + 2012-01-12 08:02 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2603381\spmsg.dll
    + 2012-01-12 08:10 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2598479\update\spcustom.dll
    + 2012-01-12 08:10 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2598479\spmsg.dll
    + 2011-10-14 14:45 . 2011-10-14 14:45 23040 c:\windows\$hf_mig$\KB2598479\SP3QFE\mciseq.dll
    + 2011-10-14 07:03 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2592799\update\spcustom.dll
    + 2011-10-14 07:03 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2592799\spmsg.dll
    + 2011-10-14 07:03 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2586448-IE8\update\spcustom.dll
    + 2011-10-14 07:03 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2586448-IE8\spmsg.dll
    + 2011-10-13 20:10 . 2011-08-22 23:47 12800 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\xpshims.dll
    + 2011-10-13 20:10 . 2011-08-22 23:47 66560 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mshtmled.dll
    + 2011-10-13 20:10 . 2011-08-22 23:47 55296 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\msfeedsbs.dll
    + 2011-10-13 20:10 . 2011-08-22 23:47 43520 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\licmgr10.dll
    + 2011-10-13 20:10 . 2011-08-22 23:47 25600 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\jsproxy.dll
    + 2012-01-18 02:30 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2585542\update\spcustom.dll
    + 2012-01-18 02:30 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2585542\spmsg.dll
    + 2012-01-12 08:02 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2584146\update\spcustom.dll
    + 2012-01-12 08:02 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2584146\spmsg.dll
    + 2011-11-18 12:41 . 2011-11-18 12:41 60416 c:\windows\$hf_mig$\KB2584146\SP3QFE\packager.exe
    + 2011-09-16 02:03 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2570947\update\spcustom.dll
    + 2011-09-16 02:03 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2570947\spmsg.dll
    + 2011-08-11 01:19 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2570222\update\spcustom.dll
    + 2011-08-11 01:19 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2570222\spmsg.dll
    + 2011-08-11 01:19 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2567680\update\spcustom.dll
    + 2011-08-11 01:19 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2567680\spmsg.dll
    + 2011-10-14 07:03 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2567053\update\spcustom.dll
    + 2011-10-14 07:03 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2567053\spmsg.dll
    + 2011-08-11 01:14 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2566454\update\spcustom.dll
    + 2011-08-11 01:14 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2566454\spmsg.dll
    + 2011-08-10 22:13 . 2011-07-08 13:51 10496 c:\windows\$hf_mig$\KB2566454\SP3QFE\ndistapi.sys
    + 2011-08-11 01:14 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2562937\update\spcustom.dll
    + 2011-08-11 01:14 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2562937\spmsg.dll
    + 2011-08-11 01:14 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2559049-IE8\update\spcustom.dll
    + 2011-08-11 01:14 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2559049-IE8\spmsg.dll
    + 2011-08-10 22:13 . 2011-06-23 18:33 12800 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\xpshims.dll
    + 2011-08-10 22:13 . 2011-06-23 18:33 66560 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\mshtmled.dll
    + 2011-08-10 22:13 . 2011-06-23 18:33 55296 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\msfeedsbs.dll
    + 2011-08-10 22:13 . 2011-06-23 18:33 43520 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\licmgr10.dll
    + 2011-08-10 22:13 . 2011-06-23 18:33 25600 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\jsproxy.dll
    + 2011-07-14 01:41 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2555917\update\spcustom.dll
    + 2011-07-14 01:41 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2555917\spmsg.dll
    + 2011-11-09 13:11 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2544893-v2\update\spcustom.dll
    + 2011-11-09 13:11 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2544893-v2\spmsg.dll
    + 2011-08-11 01:19 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2536276-v2\update\spcustom.dll
    + 2011-08-11 01:19 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2536276-v2\spmsg.dll
    + 2011-07-14 01:45 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2507938\update\spcustom.dll
    + 2011-07-14 01:45 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2507938\spmsg.dll
    + 2011-04-26 11:02 . 2011-04-26 11:02 33280 c:\windows\$hf_mig$\KB2507938\SP3QFE\csrsrv.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
    + 2006-02-05 17:42 . 2012-03-23 00:12 1734 c:\windows\system32\KGyGaAvL.sys
    + 2007-01-19 01:28 . 2007-01-19 01:28 5275 c:\windows\system32\drivers\CVirtA.sys
    + 2005-11-02 08:25 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\ksuser.dll
    + 2012-02-15 10:37 . 2012-01-11 19:06 3072 c:\windows\system32\dllcache\iacenc.dll
    - 2006-03-13 13:39 . 2009-01-10 18:22 1635 c:\windows\option.dat
    + 2006-03-13 13:39 . 2011-08-21 20:19 1635 c:\windows\option.dat
    + 2011-12-29 02:42 . 2011-12-29 02:42 6144 c:\windows\Installer\{1CE60928-8325-49A8-8B06-633E48DD2B67}\Icon3E5562ED1.exe
    - 2011-06-28 22:00 . 2011-06-28 22:00 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
    + 2012-02-15 10:37 . 2012-01-11 19:05 3072 c:\windows\$hf_mig$\KB2661637\SP3QFE\iacenc.dll
    + 2012-01-11 16:11 . 2011-11-03 18:17 4608 c:\windows\$hf_mig$\KB2603381\update\customaddreg.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
    - 2004-08-10 18:51 . 2010-06-18 17:45 293376 c:\windows\system32\winsrv.dll
    + 2004-08-10 18:51 . 2011-11-25 21:57 293376 c:\windows\system32\winsrv.dll
    - 2004-08-10 18:51 . 2008-04-14 00:12 176128 c:\windows\system32\winmm.dll
    + 2004-08-10 18:51 . 2011-10-14 14:47 176128 c:\windows\system32\winmm.dll
    + 2004-08-10 18:51 . 2011-12-17 19:46 916992 c:\windows\system32\wininet.dll
    - 2004-08-10 18:51 . 2009-08-25 09:17 354816 c:\windows\system32\winhttp.dll
    + 2004-08-10 18:51 . 2011-11-16 14:21 354816 c:\windows\system32\winhttp.dll
    + 2007-11-15 00:04 . 2007-11-15 00:04 157160 c:\windows\system32\vsinit.dll
    + 2007-11-15 00:05 . 2007-11-15 00:05 394952 c:\windows\system32\vsdatant.sys
    + 2010-09-27 17:03 . 2010-09-27 17:03 201512 c:\windows\system32\vpnapi.dll
    - 2004-08-10 18:51 . 2009-03-08 08:34 105984 c:\windows\system32\url.dll
    + 2004-08-10 18:51 . 2011-12-17 19:46 105984 c:\windows\system32\url.dll
    + 2008-07-30 00:59 . 2011-09-26 15:41 611328 c:\windows\system32\uiautomationcore.dll
    + 2004-08-10 18:51 . 2011-11-16 14:21 152064 c:\windows\system32\schannel.dll
    - 2004-08-10 18:51 . 2008-04-14 00:12 386048 c:\windows\system32\qdvd.dll
    + 2004-08-10 18:51 . 2011-11-03 15:28 386048 c:\windows\system32\qdvd.dll
    + 2004-08-10 18:51 . 2012-03-29 00:43 445798 c:\windows\system32\perfh009.dat
    + 2004-08-10 18:51 . 2011-09-26 15:41 220160 c:\windows\system32\oleacc.dll
    + 2011-01-27 03:32 . 2011-01-27 03:32 155648 c:\windows\system32\Oemdspif.dll
    + 2004-08-10 18:51 . 2011-12-17 19:46 206848 c:\windows\system32\occache.dll
    - 2004-08-10 18:51 . 2011-04-25 16:11 206848 c:\windows\system32\occache.dll
    + 2004-08-10 18:51 . 2011-12-17 19:46 611840 c:\windows\system32\mstime.dll
    - 2004-08-10 18:51 . 2011-04-25 16:11 611840 c:\windows\system32\mstime.dll
    + 2009-03-08 08:32 . 2011-12-17 19:46 602112 c:\windows\system32\msfeeds.dll
    - 2009-03-08 08:32 . 2011-04-25 16:11 602112 c:\windows\system32\msfeeds.dll
    + 2011-12-01 10:53 . 2011-12-01 10:53 247968 c:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
    + 2011-12-01 10:53 . 2011-12-01 10:53 335520 c:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.dll
    + 2011-11-09 10:42 . 2011-11-09 10:42 247968 c:\windows\system32\Macromed\Flash\FlashUtil11c_ActiveX.exe
    + 2011-07-08 10:28 . 2011-05-04 08:52 157472 c:\windows\system32\javaws.exe
    - 2011-04-20 11:14 . 2011-02-03 01:40 157472 c:\windows\system32\javaws.exe
    + 2011-07-08 10:28 . 2011-05-04 08:52 145184 c:\windows\system32\javaw.exe
    - 2011-04-20 11:14 . 2011-02-03 01:40 145184 c:\windows\system32\javaw.exe
    + 2011-07-08 10:28 . 2011-05-04 08:52 145184 c:\windows\system32\java.exe
    - 2011-04-20 11:14 . 2011-02-03 01:40 145184 c:\windows\system32\java.exe
    - 2004-08-10 19:02 . 2011-05-02 15:31 692736 c:\windows\system32\inetcomm.dll
    + 2004-08-10 19:02 . 2011-10-10 14:22 692736 c:\windows\system32\inetcomm.dll
    - 2004-08-10 18:51 . 2011-04-25 16:11 184320 c:\windows\system32\iepeers.dll
    + 2004-08-10 18:51 . 2011-12-17 19:46 184320 c:\windows\system32\iepeers.dll
    - 2004-08-10 18:51 . 2011-04-25 16:11 387584 c:\windows\system32\iedkcs32.dll
    + 2004-08-10 18:51 . 2011-12-17 19:46 387584 c:\windows\system32\iedkcs32.dll
    + 2004-08-10 18:51 . 2011-12-16 12:23 174080 c:\windows\system32\ie4uinit.exe
    - 2004-08-10 18:57 . 2011-04-14 09:08 406304 c:\windows\system32\FNTCACHE.DAT
    + 2004-08-10 18:57 . 2012-03-15 09:45 406304 c:\windows\system32\FNTCACHE.DAT
    + 2004-08-10 18:51 . 2011-10-18 11:13 186880 c:\windows\system32\encdec.dll
    - 2004-08-10 18:51 . 2011-02-09 13:53 186880 c:\windows\system32\encdec.dll
    + 2004-03-16 17:58 . 2008-04-13 19:19 146048 c:\windows\system32\drivers\portcls.sys
    - 2004-03-16 17:58 . 2008-04-13 19:19 146048 c:\windows\system32\drivers\portcls.sys
    + 2005-11-02 08:07 . 2011-07-15 13:29 456320 c:\windows\system32\drivers\mrxsmb.sys
    - 2005-11-02 08:07 . 2011-04-29 16:19 456320 c:\windows\system32\drivers\mrxsmb.sys
    + 2010-03-26 01:30 . 2011-04-18 17:18 165648 c:\windows\system32\drivers\MpFilter.sys
    + 2011-01-12 00:01 . 2008-11-16 23:39 131984 c:\windows\system32\drivers\dne2000.sys
    + 2010-09-27 16:56 . 2010-09-27 16:56 308859 c:\windows\system32\drivers\CVPNDRVA.sys
    + 2004-08-10 18:50 . 2011-08-17 13:49 138496 c:\windows\system32\drivers\afd.sys
    - 2004-08-10 18:50 . 2011-02-16 13:22 138496 c:\windows\system32\drivers\afd.sys
    + 2011-08-31 03:05 . 2011-08-31 03:05 178536 c:\windows\system32\dnssdX.dll
    + 2011-01-12 00:01 . 2008-11-16 23:39 106768 c:\windows\system32\dneinobj.dll
    - 2010-06-18 17:45 . 2010-06-18 17:45 293376 c:\windows\system32\dllcache\winsrv.dll
    + 2010-06-18 17:45 . 2011-11-25 21:57 293376 c:\windows\system32\dllcache\winsrv.dll
    + 2011-10-14 14:47 . 2011-10-14 14:47 176128 c:\windows\system32\dllcache\winmm.dll
    + 2008-04-21 06:44 . 2011-12-17 19:46 916992 c:\windows\system32\dllcache\wininet.dll
    + 2008-12-16 12:30 . 2011-11-16 14:21 354816 c:\windows\system32\dllcache\winhttp.dll
    - 2008-12-16 12:30 . 2009-08-25 09:17 354816 c:\windows\system32\dllcache\winhttp.dll
    + 2009-03-08 08:34 . 2011-12-17 19:46 105984 c:\windows\system32\dllcache\url.dll
    - 2009-03-08 08:34 . 2009-03-08 08:34 105984 c:\windows\system32\dllcache\url.dll
    + 2008-12-05 06:54 . 2011-11-16 14:21 152064 c:\windows\system32\dllcache\schannel.dll
    + 2011-08-10 22:13 . 2012-01-09 16:20 139784 c:\windows\system32\dllcache\rdpwd.sys
    + 2011-11-03 15:28 . 2011-11-03 15:28 386048 c:\windows\system32\dllcache\qdvd.dll
    + 2004-03-16 17:58 . 2008-04-13 19:19 146048 c:\windows\system32\dllcache\portcls.sys
    + 2011-09-26 15:41 . 2011-09-26 15:41 220160 c:\windows\system32\dllcache\oleacc.dll
    + 2009-03-08 08:34 . 2011-12-17 19:46 206848 c:\windows\system32\dllcache\occache.dll
    - 2009-03-08 08:34 . 2011-04-25 16:11 206848 c:\windows\system32\dllcache\occache.dll
    - 2009-03-08 08:32 . 2011-04-25 16:11 611840 c:\windows\system32\dllcache\mstime.dll
    + 2009-03-08 08:32 . 2011-12-17 19:46 611840 c:\windows\system32\dllcache\mstime.dll
    - 2009-07-29 09:36 . 2011-04-25 16:11 602112 c:\windows\system32\dllcache\msfeeds.dll
    + 2009-07-29 09:36 . 2011-12-17 19:46 602112 c:\windows\system32\dllcache\msfeeds.dll
    + 2004-08-10 19:02 . 2008-04-14 00:12 169984 c:\windows\system32\dllcache\msconfig.exe
    + 2004-08-10 19:02 . 2010-11-09 14:52 143360 c:\windows\system32\dllcache\msadco.dll
    - 2010-11-09 14:52 . 2010-11-09 14:52 143360 c:\windows\system32\dllcache\msadco.dll
    - 2008-11-12 00:59 . 2011-04-29 16:19 456320 c:\windows\system32\dllcache\mrxsmb.sys
    + 2008-11-12 00:59 . 2011-07-15 13:29 456320 c:\windows\system32\dllcache\mrxsmb.sys
    + 2004-08-04 05:15 . 2008-04-13 19:16 141056 c:\windows\system32\dllcache\ks.sys
    + 2008-08-14 10:05 . 2011-10-10 14:22 692736 c:\windows\system32\dllcache\inetcomm.dll
    - 2008-08-14 10:05 . 2011-05-02 15:31 692736 c:\windows\system32\dllcache\inetcomm.dll
    + 2009-07-03 09:18 . 2011-12-17 19:46 247808 c:\windows\system32\dllcache\ieproxy.dll
    - 2009-07-03 09:18 . 2011-04-25 16:11 247808 c:\windows\system32\dllcache\ieproxy.dll
    + 2009-03-08 08:31 . 2011-12-17 19:46 184320 c:\windows\system32\dllcache\iepeers.dll
    - 2009-03-08 08:31 . 2011-04-25 16:11 184320 c:\windows\system32\dllcache\iepeers.dll
    + 2010-06-10 21:09 . 2011-12-17 19:46 743424 c:\windows\system32\dllcache\iedvtool.dll
    - 2010-06-10 21:09 . 2011-04-25 16:11 743424 c:\windows\system32\dllcache\iedvtool.dll
    - 2009-03-08 18:09 . 2011-04-25 16:11 387584 c:\windows\system32\dllcache\iedkcs32.dll
    + 2009-03-08 18:09 . 2011-12-17 19:46 387584 c:\windows\system32\dllcache\iedkcs32.dll
    + 2009-03-08 08:32 . 2011-12-16 12:23 174080 c:\windows\system32\dllcache\ie4uinit.exe
    + 2004-08-10 19:02 . 2008-04-14 00:11 172032 c:\windows\system32\dllcache\icwhelp.dll
    + 2004-08-10 19:02 . 2008-04-14 00:12 214528 c:\windows\system32\dllcache\icwconn1.exe
    - 2011-02-09 13:53 . 2011-02-09 13:53 186880 c:\windows\system32\dllcache\encdec.dll
    + 2011-02-09 13:53 . 2011-10-18 11:13 186880 c:\windows\system32\dllcache\encdec.dll
    + 2011-09-03 10:17 . 2011-09-28 07:06 599040 c:\windows\system32\dllcache\crypt32.dll
    + 2008-08-22 22:46 . 2011-01-27 03:51 302080 c:\windows\system32\dllcache\ati2dvag.dll
    + 2008-08-22 22:46 . 2011-01-27 03:15 847872 c:\windows\system32\dllcache\ati2cqag.dll
    + 2004-08-10 18:50 . 2008-04-14 00:11 214016 c:\windows\system32\dllcache\agentctl.dll
    + 2008-06-20 11:40 . 2011-08-17 13:49 138496 c:\windows\system32\dllcache\afd.sys
    - 2008-06-20 11:40 . 2011-02-16 13:22 138496 c:\windows\system32\dllcache\afd.sys
    + 2011-01-08 03:11 . 2011-05-04 08:52 472808 c:\windows\system32\deployJava1.dll
    - 2011-01-08 03:11 . 2011-02-03 01:40 472808 c:\windows\system32\deployJava1.dll
    + 2010-09-27 16:57 . 2010-09-27 16:57 197416 c:\windows\system32\CSGina.dll
    - 2004-08-10 18:50 . 2008-04-14 00:11 599040 c:\windows\system32\crypt32.dll
    + 2004-08-10 18:50 . 2011-09-28 07:06 599040 c:\windows\system32\crypt32.dll
    + 2011-01-27 03:26 . 2011-01-27 03:26 887724 c:\windows\system32\ativva6x.dat
    + 2011-01-27 03:32 . 2011-01-27 03:32 212992 c:\windows\system32\atipdlxx.dll
    + 2011-01-27 03:21 . 2011-01-27 03:21 483328 c:\windows\system32\atiok3x2.dll
    + 2010-08-28 00:32 . 2010-08-28 00:32 294912 c:\windows\system32\ATIODE.exe
    + 2011-01-27 03:23 . 2011-01-27 03:23 651264 c:\windows\system32\atikvmag.dll
    + 2011-01-27 03:41 . 2011-01-27 03:41 311296 c:\windows\system32\atiiiexx.dll
    + 2010-12-17 21:00 . 2010-12-17 21:00 227587 c:\windows\system32\atiicdxx.dat
    + 2011-01-27 03:52 . 2011-01-27 03:52 462848 c:\windows\system32\ATIDEMGX.dll
    + 2009-05-12 03:35 . 2009-05-12 03:35 118784 c:\windows\system32\atibtmon.exe
    + 2011-01-27 03:27 . 2011-01-27 03:27 143360 c:\windows\system32\atiapfxx.exe
    + 2011-01-27 03:21 . 2011-01-27 03:21 196608 c:\windows\system32\atiadlxx.dll
    + 2011-01-27 03:30 . 2011-01-27 03:30 638976 c:\windows\system32\ati2evxx.exe
    + 2011-01-27 03:31 . 2011-01-27 03:31 188416 c:\windows\system32\ati2evxx.dll
    + 2008-08-22 22:46 . 2011-01-27 03:51 302080 c:\windows\system32\ati2dvag.dll
    + 2008-08-22 22:46 . 2011-01-27 03:15 847872 c:\windows\system32\ati2cqag.dll
     
  7. 2012/03/28
    dave1234

    dave1234 Well-Known Member Thread Starter

    Joined:
    2002/12/21
    Messages:
    196
    Likes Received:
    0
    cont

    + 2011-12-25 08:49 . 2011-12-25 08:49 436496 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
    + 2011-07-07 09:18 . 2011-07-07 09:18 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
    - 2011-03-25 10:15 . 2011-03-25 10:15 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
    - 2011-03-25 10:15 . 2011-03-25 10:15 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
    + 2011-07-07 09:18 . 2011-07-07 09:18 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
    + 2011-12-25 03:55 . 2011-12-25 03:55 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
    - 2010-09-23 06:26 . 2010-09-23 06:26 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
    - 2010-09-23 06:25 . 2010-09-23 06:25 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
    + 2011-12-25 03:53 . 2011-12-25 03:53 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
    - 2010-09-23 07:17 . 2010-09-23 07:17 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
    + 2011-12-25 04:49 . 2011-12-25 04:49 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
    + 2011-10-01 12:44 . 2011-10-01 12:44 178688 c:\windows\Installer\c6d93c.msi
    + 2011-12-25 10:40 . 2011-12-25 10:40 819200 c:\windows\Installer\432bc89.msp
    + 2011-08-09 03:12 . 2011-08-09 03:12 785920 c:\windows\Installer\3dd86b6.msi
    + 2011-08-09 03:11 . 2011-08-09 03:11 483840 c:\windows\Installer\3dd8697.msi
    + 2011-08-09 03:11 . 2011-08-09 03:11 301056 c:\windows\Installer\3dd868f.msi
    + 2011-07-08 10:29 . 2011-07-08 10:29 203776 c:\windows\Installer\2fd18b.msi
    + 2011-10-26 01:41 . 2011-10-26 01:41 380928 c:\windows\Installer\{29ED20C9-5E15-4969-9279-25BF3727A3DA}\iTunesIco.exe
    + 2012-02-16 08:02 . 2011-11-04 19:20 916992 c:\windows\ie8updates\KB2647516-IE8\wininet.dll
    + 2012-02-16 08:02 . 2011-11-04 19:20 105984 c:\windows\ie8updates\KB2647516-IE8\url.dll
    + 2012-02-16 08:03 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2647516-IE8\spuninst\updspapi.dll
    + 2012-02-16 08:03 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2647516-IE8\spuninst\spuninst.exe
    + 2012-02-16 08:02 . 2011-11-04 19:20 206848 c:\windows\ie8updates\KB2647516-IE8\occache.dll
    + 2012-02-16 08:02 . 2011-11-04 19:20 611840 c:\windows\ie8updates\KB2647516-IE8\mstime.dll
    + 2012-02-16 08:02 . 2011-11-04 19:20 602112 c:\windows\ie8updates\KB2647516-IE8\msfeeds.dll
    + 2012-02-16 08:02 . 2011-11-04 19:20 247808 c:\windows\ie8updates\KB2647516-IE8\ieproxy.dll
    + 2012-02-16 08:02 . 2011-11-04 19:20 184320 c:\windows\ie8updates\KB2647516-IE8\iepeers.dll
    + 2012-02-16 08:02 . 2011-11-04 19:20 743424 c:\windows\ie8updates\KB2647516-IE8\iedvtool.dll
    + 2012-02-16 08:02 . 2011-11-04 19:20 387584 c:\windows\ie8updates\KB2647516-IE8\iedkcs32.dll
    + 2012-02-16 08:02 . 2011-11-04 11:24 174080 c:\windows\ie8updates\KB2647516-IE8\ie4uinit.exe
    + 2011-12-15 15:35 . 2011-08-22 23:48 916480 c:\windows\ie8updates\KB2618444-IE8\wininet.dll
    + 2011-12-15 15:35 . 2011-08-22 23:48 105984 c:\windows\ie8updates\KB2618444-IE8\url.dll
    + 2011-12-15 15:35 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2618444-IE8\spuninst\updspapi.dll
    + 2011-12-15 15:35 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2618444-IE8\spuninst\spuninst.exe
    + 2011-12-15 15:35 . 2011-08-22 23:48 206848 c:\windows\ie8updates\KB2618444-IE8\occache.dll
    + 2011-12-15 15:35 . 2011-08-22 23:48 611840 c:\windows\ie8updates\KB2618444-IE8\mstime.dll
    + 2011-12-15 15:35 . 2011-08-22 23:48 602112 c:\windows\ie8updates\KB2618444-IE8\msfeeds.dll
    + 2011-12-15 15:35 . 2011-08-22 23:48 247808 c:\windows\ie8updates\KB2618444-IE8\ieproxy.dll
    + 2011-12-15 15:35 . 2011-08-22 23:48 184320 c:\windows\ie8updates\KB2618444-IE8\iepeers.dll
    + 2011-12-15 15:35 . 2011-08-22 23:48 743424 c:\windows\ie8updates\KB2618444-IE8\iedvtool.dll
    + 2011-12-15 15:35 . 2011-08-22 23:48 387584 c:\windows\ie8updates\KB2618444-IE8\iedkcs32.dll
    + 2011-12-15 15:35 . 2011-08-22 11:56 174080 c:\windows\ie8updates\KB2618444-IE8\ie4uinit.exe
    + 2011-10-14 07:02 . 2011-06-23 18:36 916480 c:\windows\ie8updates\KB2586448-IE8\wininet.dll
    + 2011-10-14 07:02 . 2011-06-23 18:36 105984 c:\windows\ie8updates\KB2586448-IE8\url.dll
    + 2011-10-14 07:03 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2586448-IE8\spuninst\updspapi.dll
    + 2011-10-14 07:03 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2586448-IE8\spuninst\spuninst.exe
    + 2011-10-14 07:02 . 2011-06-23 18:36 206848 c:\windows\ie8updates\KB2586448-IE8\occache.dll
    + 2011-10-14 07:02 . 2011-06-23 18:36 611840 c:\windows\ie8updates\KB2586448-IE8\mstime.dll
    + 2011-10-14 07:02 . 2011-06-23 18:36 602112 c:\windows\ie8updates\KB2586448-IE8\msfeeds.dll
    + 2011-10-14 07:02 . 2011-06-23 18:36 247808 c:\windows\ie8updates\KB2586448-IE8\ieproxy.dll
    + 2011-10-14 07:02 . 2011-06-23 18:36 184320 c:\windows\ie8updates\KB2586448-IE8\iepeers.dll
    + 2011-10-14 07:02 . 2011-06-23 18:36 743424 c:\windows\ie8updates\KB2586448-IE8\iedvtool.dll
    + 2011-10-14 07:02 . 2011-06-23 18:36 387584 c:\windows\ie8updates\KB2586448-IE8\iedkcs32.dll
    + 2011-10-14 07:02 . 2011-06-23 12:05 173568 c:\windows\ie8updates\KB2586448-IE8\ie4uinit.exe
    + 2011-08-11 01:14 . 2011-04-25 16:11 916480 c:\windows\ie8updates\KB2559049-IE8\wininet.dll
    + 2011-08-11 01:14 . 2009-03-08 08:34 105984 c:\windows\ie8updates\KB2559049-IE8\url.dll
    + 2011-08-11 01:14 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2559049-IE8\spuninst\updspapi.dll
    + 2011-08-11 01:14 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2559049-IE8\spuninst\spuninst.exe
    + 2011-08-11 01:14 . 2011-04-25 16:11 206848 c:\windows\ie8updates\KB2559049-IE8\occache.dll
    + 2011-08-11 01:14 . 2011-04-25 16:11 611840 c:\windows\ie8updates\KB2559049-IE8\mstime.dll
    + 2011-08-11 01:14 . 2011-04-25 16:11 602112 c:\windows\ie8updates\KB2559049-IE8\msfeeds.dll
    + 2011-08-11 01:14 . 2011-04-25 16:11 247808 c:\windows\ie8updates\KB2559049-IE8\ieproxy.dll
    + 2011-08-11 01:14 . 2011-04-25 16:11 184320 c:\windows\ie8updates\KB2559049-IE8\iepeers.dll
    + 2011-08-11 01:14 . 2011-04-25 16:11 743424 c:\windows\ie8updates\KB2559049-IE8\iedvtool.dll
    + 2011-08-11 01:14 . 2011-04-25 16:11 387584 c:\windows\ie8updates\KB2559049-IE8\iedkcs32.dll
    + 2011-08-11 01:14 . 2011-04-25 12:01 173568 c:\windows\ie8updates\KB2559049-IE8\ie4uinit.exe
    - 2008-11-12 00:59 . 2011-04-29 16:19 456320 c:\windows\Driver Cache\i386\mrxsmb.sys
    + 2008-11-12 00:59 . 2011-07-15 13:29 456320 c:\windows\Driver Cache\i386\mrxsmb.sys
    + 2012-01-12 08:09 . 2012-01-12 08:09 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_b3a575a5\System.Drawing.dll
    + 2012-01-12 08:09 . 2012-01-12 08:09 192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_ed64f336\System.Drawing.Design.dll
    + 2012-01-12 08:09 . 2012-01-12 08:09 118784 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_77948e12\CustomMarshalers.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\edc5691acfb65ac37f49de2ec497083a\WsatConfig.ni.exe
    + 2011-10-14 22:12 . 2011-10-14 22:12 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\c8627df7adb416722d8e0f05c57fef6b\WsatConfig.ni.exe
    + 2011-10-14 22:01 . 2011-10-14 22:01 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\a2c1bb3c5b1447b398e72c56091ca571\WindowsFormsIntegration.ni.dll
    + 2012-02-16 08:13 . 2012-02-16 08:13 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\4ad8369d6a60765d7e9b43cdf9023f41\WindowsFormsIntegration.ni.dll
    + 2011-10-14 22:01 . 2011-10-14 22:01 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\f102afdffdbe2565bcedb7fa0626b865\UIAutomationTypes.ni.dll
    + 2011-10-14 22:01 . 2011-10-14 22:01 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\ba55240b7753047f8d1b03ef473bf74e\UIAutomationClient.ni.dll
    + 2012-02-16 08:13 . 2012-02-16 08:13 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\68f4157e570c77df653057c0583395bd\UIAutomationClient.ni.dll
    + 2012-02-16 08:18 . 2012-02-16 08:18 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\c2a12bd4056b44f8005a7eb3af161e6a\System.Xml.Linq.ni.dll
    + 2011-10-14 22:15 . 2011-10-14 22:15 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\566b2e11e7f3f6d973b17b86cf42f9bc\System.Xml.Linq.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\fc63b434b2f253cd27625487f7b02ac0\System.Web.Routing.ni.dll
    + 2012-01-12 08:13 . 2012-01-12 08:13 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\0bda7bdfaf440d5dd4bc6a1dea7ffa39\System.Web.Routing.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\67877f896b2b0e42286e838fe307f3fd\System.Web.RegularExpressions.ni.dll
    + 2011-10-14 22:14 . 2011-10-14 22:14 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\018b6e48c32d5b5d78086998e3505f1c\System.Web.RegularExpressions.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\86650d4fb220f94f25bb5da42a03d454\System.Web.Extensions.Design.ni.dll
    + 2012-01-12 08:14 . 2012-01-12 08:14 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\6e29f9faa74a48b83a13a3413b826295\System.Web.Extensions.Design.ni.dll
    + 2012-01-12 08:14 . 2012-01-12 08:14 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\be8965fe859bc53dff61579bf626858b\System.Web.Entity.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\654465871e547e131668874de7c60b8c\System.Web.Entity.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\f0d6895f6e709d425cb5da6053c603d2\System.Web.Entity.Design.ni.dll
    + 2012-01-12 08:14 . 2012-01-12 08:14 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\8441b3eb247e0344fede848337ee911c\System.Web.Entity.Design.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\3f3b7dc7208e302e39a2dfb5b2cb953b\System.Web.DynamicData.ni.dll
    + 2012-01-12 08:14 . 2012-01-12 08:14 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\09c6a41f187ba483486cdb92dad714a1\System.Web.DynamicData.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\e9cddd213343f15d611b14620d649bb0\System.Web.Abstractions.ni.dll
    + 2012-01-12 08:13 . 2012-01-12 08:13 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\5efb726d424b9712632eff749411fa89\System.Web.Abstractions.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\f25d114cb629d1f512f98883c6535a75\System.Transactions.ni.dll
    + 2011-10-14 22:14 . 2011-10-14 22:14 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\8efcd633af87989355382b5039f1b7df\System.Transactions.ni.dll
    + 2011-10-14 22:14 . 2011-10-14 22:14 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\11dcb806c92f55111f5fa9f1a90e3bdd\System.ServiceProcess.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\5fb9981f4147b537b53be9d58bf4e9b4\System.Security.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\36c12de583ee81e9c99acb72b09d77ac\System.Security.ni.dll
    + 2011-10-14 22:14 . 2011-10-14 22:14 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\81096bfe85eb0da5f05e8a127ffa43b2\System.Runtime.Serialization.Formatters.Soap.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\1335dd98ce5ce22ad1f51cc274ca5a1d\System.Runtime.Serialization.Formatters.Soap.ni.dll
    + 2011-10-14 22:14 . 2011-10-14 22:14 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\b2a84980f206431821d85d5155d5916f\System.Net.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\a4b2b1ee81acd843970d9a81b281f1c1\System.Net.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\a2a14380e8c9149d5b212d0100ef588a\System.Management.ni.dll
    + 2011-10-14 22:14 . 2011-10-14 22:14 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\90b90e700e59d73d6d692cf74e1ba16e\System.Management.ni.dll
    + 2011-10-14 22:14 . 2011-10-14 22:14 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\f36eded354122da9555a6c7cdbdb5431\System.Management.Instrumentation.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\e3436edde657a5111d39d5b2eecf9715\System.Management.Instrumentation.ni.dll
    + 2011-10-14 22:02 . 2011-10-14 22:02 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\41c3a2fcffc58b20023c7d54e57ea956\System.IdentityModel.Selectors.ni.dll
    + 2012-02-16 08:14 . 2012-02-16 08:14 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\01eba24390736a59c39becd825b5756e\System.IdentityModel.Selectors.ni.dll
    + 2012-02-16 08:16 . 2012-02-16 08:16 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\c0d15fb6308587fef8744d568e64bcda\System.EnterpriseServices.Wrapper.dll
    + 2012-02-16 08:16 . 2012-02-16 08:16 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\c0d15fb6308587fef8744d568e64bcda\System.EnterpriseServices.ni.dll
    + 2011-10-14 22:14 . 2011-10-14 22:14 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.Wrapper.dll
    + 2011-10-14 22:14 . 2011-10-14 22:14 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.ni.dll
    + 2012-02-16 08:12 . 2012-02-16 08:12 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\e9ae7ae6d1e9edc7aaf819889cd1c692\System.Drawing.Design.ni.dll
    + 2011-10-14 22:00 . 2011-10-14 22:00 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\896eca06e2d9377b2dc4fad56ce49b07\System.Drawing.Design.ni.dll
    + 2012-02-16 08:16 . 2012-02-16 08:16 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\78a370dc153011708dd9e4cb0e606bfc\System.DirectoryServices.Protocols.ni.dll
    + 2012-02-16 08:16 . 2012-02-16 08:16 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\6e644fc7464d9fe23fc9cd6001296f2f\System.DirectoryServices.AccountManagement.ni.dll
    + 2011-10-14 22:13 . 2011-10-14 22:13 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\33e9b0c368c31ef37a2ec7b5a181044b\System.DirectoryServices.Protocols.ni.dll
    + 2011-10-14 22:13 . 2011-10-14 22:13 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\11cdd1c0d65428cd3505d3813d36638c\System.DirectoryServices.AccountManagement.ni.dll
    + 2011-10-14 22:13 . 2011-10-14 22:13 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\e5ada332a9bc3c982e6aede6ba354196\System.Data.Services.Client.ni.dll
    + 2012-02-16 08:16 . 2012-02-16 08:16 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\bac39be66bb9f987c1948b766833f8e6\System.Data.Services.Client.ni.dll
    + 2011-10-14 22:13 . 2011-10-14 22:13 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\3f179f373f31817a914b639a56cc0497\System.Data.Services.Design.ni.dll
    + 2012-02-16 08:16 . 2012-02-16 08:16 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\2b5ecd231320e57010043c408783d80b\System.Data.Services.Design.ni.dll
    + 2012-01-12 08:13 . 2012-01-12 08:13 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\f374e8e7849a72d1470b4a6a0771a137\System.Data.Entity.Design.ni.dll
    + 2012-02-16 08:16 . 2012-02-16 08:16 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\4ac9ac2326720485aefd4d79d2024945\System.Data.Entity.Design.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\d504d550fd0a6994fcb1466ea7be92af\System.Data.DataSetExtensions.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\b9d9ff5d03e90ede1116794f2c7dd6da\System.Data.DataSetExtensions.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\94a40f415bfa947e251888bbe88bb973\System.Configuration.ni.dll
    + 2011-10-14 22:14 . 2011-10-14 22:14 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\29d7091f6eab0ec61c4eb625ed221b73\System.Configuration.Install.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\28637135c6939e74450bbbf110b12643\System.Configuration.Install.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\958b5c0114d664ab5ba72575c301e2ea\System.AddIn.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\3048737e9e3bf5173121a084337256bc\System.AddIn.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\6e45cf503f025c5fe814ea7e52f62a78\SMSvcHost.ni.exe
    + 2012-02-16 08:15 . 2012-02-16 08:15 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\4dcff3b0e79fc27e31549bb2af00efb5\SMSvcHost.ni.exe
    + 2012-02-16 08:15 . 2012-02-16 08:15 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\bd3bfd5b6ef659dac4d6cccb34577d33\SMDiagnostics.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\474a341340f687bcbd7777f2820a8c7a\SMDiagnostics.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\edec83be646eb52204c991371751a428\ServiceModelReg.ni.exe
    + 2012-01-12 08:12 . 2012-01-12 08:12 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\439732479756e0f6df88d29e50a402bf\ServiceModelReg.ni.exe
    + 2011-10-14 22:00 . 2011-10-14 22:00 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c2ebcc8d60422f224b4088f3d7a2ac1f\PresentationFramework.Luna.ni.dll
    + 2011-10-14 22:00 . 2011-10-14 22:00 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\94cfc00ad448575bfb0e67c53b514cd5\PresentationFramework.Aero.ni.dll
    + 2012-02-16 08:12 . 2012-02-16 08:12 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\52015457bc28e7a9a563d9eab8ab0015\PresentationFramework.Royale.ni.dll
    + 2011-10-14 22:00 . 2011-10-14 22:00 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\478d57d96f3d8d5fc15c7ac635a4a6a1\PresentationFramework.Classic.ni.dll
    + 2012-02-16 08:12 . 2012-02-16 08:12 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\46a680814559114706a33282e9df4b7a\PresentationFramework.Classic.ni.dll
    + 2012-02-16 08:12 . 2012-02-16 08:12 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2713754549b1114c9152d33efe5f72c7\PresentationFramework.Aero.ni.dll
    + 2011-10-14 22:00 . 2011-10-14 22:00 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\23c5852ff8ed973ff9b63ce9ba7f91f0\PresentationFramework.Royale.ni.dll
    + 2012-02-16 08:12 . 2012-02-16 08:12 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\1552f18ca434c1dca6d082df476d089a\PresentationFramework.Luna.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\7c51497b188c82e2ccbe6315549ce023\MSBuild.ni.exe
    + 2011-10-14 22:12 . 2011-10-14 22:12 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\04595f414c49cf2a65b349648ba23e62\MSBuild.ni.exe
    + 2012-02-16 08:15 . 2012-02-16 08:15 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\f0f6dd614d294295c5d8386cc4192034\Microsoft.Transactions.Bridge.Dtc.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\4cbd7ed9fbf9f1b3cbdf23906cc0f5a3\Microsoft.Transactions.Bridge.Dtc.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\ff6d4892775fd1f9b137f7c92ea453f2\Microsoft.Build.Utilities.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\fd1338828beec8737fed8f50f4fcc567\Microsoft.Build.Utilities.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\47ff0720cb80a0fc0bbd15ddc3d12adc\Microsoft.Build.Utilities.v3.5.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\0d5f999c4b7e51151548c37c676c1b8e\Microsoft.Build.Utilities.v3.5.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\da112c5757e3c68d6369b6aa46cc9682\Microsoft.Build.Engine.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\792168ce8fe03a3db43e12cf736cf91e\Microsoft.Build.Engine.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\dc278e1123086ae32fec8f7e9751db14\Microsoft.Build.Conversion.v3.5.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\0a5277c34ddc1f55df1defb4231e814f\Microsoft.Build.Conversion.v3.5.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\3e6deccf191ab943d3a0812a38ab5c97\CustomMarshalers.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\a8df37aadb089f1f34d3d2f103966fbc\ComSvcConfig.ni.exe
    + 2011-10-14 22:11 . 2011-10-14 22:11 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\4e68d5df30b197ff72c75f1c3c24b949\ComSvcConfig.ni.exe
    + 2012-01-12 08:11 . 2012-01-12 08:11 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\bfcea15c95909860c4f4ac19bd7a2d6c\AspNetMMCExt.ni.dll
    + 2012-02-16 08:14 . 2012-02-16 08:14 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\25ce400b547f517258c8afb0480390ea\AspNetMMCExt.ni.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
    + 2012-02-16 08:02 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2661637$\spuninst\updspapi.dll
    + 2012-02-16 08:02 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2661637$\spuninst\spuninst.exe
    + 2012-02-16 08:03 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2660465$\spuninst\updspapi.dll
    + 2012-02-16 08:03 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2660465$\spuninst\spuninst.exe
    + 2012-01-12 08:16 . 2011-06-20 17:44 293376 c:\windows\$NtUninstallKB2646524$\winsrv.dll
    + 2012-01-12 08:16 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2646524$\spuninst\updspapi.dll
    + 2012-01-12 08:16 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2646524$\spuninst\spuninst.exe
    + 2011-11-12 02:14 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2641690$\spuninst\updspapi.dll
    + 2011-11-12 02:14 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2641690$\spuninst\spuninst.exe
    + 2011-11-12 02:14 . 2011-09-09 09:12 599040 c:\windows\$NtUninstallKB2641690$\crypt32.dll
    + 2011-12-15 15:36 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2639417$\spuninst\updspapi.dll
    + 2011-12-15 15:36 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2639417$\spuninst\spuninst.exe
    + 2011-12-15 15:30 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2633952$\spuninst\updspapi.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2633952$\spuninst\spuninst.exe
    + 2011-12-15 15:30 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2633171$\spuninst\updspapi.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2633171$\spuninst\spuninst.exe
    + 2012-01-12 08:16 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2631813$\spuninst\updspapi.dll
    + 2012-01-12 08:16 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2631813$\spuninst\spuninst.exe
    + 2012-01-12 08:16 . 2008-04-14 00:12 386048 c:\windows\$NtUninstallKB2631813$\qdvd.dll
    + 2011-12-15 15:36 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2624667$\spuninst\updspapi.dll
    + 2011-12-15 15:36 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2624667$\spuninst\spuninst.exe
    + 2011-12-15 15:30 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2620712$\spuninst\updspapi.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2620712$\spuninst\spuninst.exe
    + 2011-12-15 15:30 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2619339$\spuninst\updspapi.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2619339$\spuninst\spuninst.exe
    + 2011-12-15 15:30 . 2011-02-09 13:53 186880 c:\windows\$NtUninstallKB2619339$\encdec.dll
    + 2011-12-15 15:30 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2618451$\spuninst\updspapi.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2618451$\spuninst\spuninst.exe
    + 2011-09-16 02:07 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2616676$\spuninst\updspapi.dll
    + 2011-09-16 02:07 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2616676$\spuninst\spuninst.exe
    + 2011-09-16 02:07 . 2011-09-03 10:17 599040 c:\windows\$NtUninstallKB2616676$\crypt32.dll
    + 2011-09-08 02:21 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2607712$\spuninst\updspapi.dll
    + 2011-09-08 02:21 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2607712$\spuninst\spuninst.exe
    + 2011-09-08 02:21 . 2008-04-14 00:11 599040 c:\windows\$NtUninstallKB2607712$\crypt32.dll
    + 2012-01-12 08:02 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2603381$\spuninst\updspapi.dll
    + 2012-01-12 08:02 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2603381$\spuninst\spuninst.exe
    + 2012-01-12 08:10 . 2008-04-14 00:12 176128 c:\windows\$NtUninstallKB2598479$\winmm.dll
    + 2012-01-12 08:10 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2598479$\spuninst\updspapi.dll
    + 2012-01-12 08:10 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2598479$\spuninst\spuninst.exe
    + 2011-10-14 07:03 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2592799$\spuninst\updspapi.dll
    + 2011-10-14 07:03 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2592799$\spuninst\spuninst.exe
    + 2011-10-14 07:03 . 2011-02-16 13:22 138496 c:\windows\$NtUninstallKB2592799$\afd.sys
    + 2012-01-18 02:30 . 2009-08-25 09:17 354816 c:\windows\$NtUninstallKB2585542$\winhttp.dll
    + 2012-01-18 02:30 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2585542$\spuninst\updspapi.dll
    + 2012-01-18 02:30 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2585542$\spuninst\spuninst.exe
    + 2012-01-18 02:30 . 2011-04-29 17:25 151552 c:\windows\$NtUninstallKB2585542$\schannel.dll
    + 2012-01-12 08:02 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2584146$\spuninst\updspapi.dll
    + 2012-01-12 08:02 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2584146$\spuninst\spuninst.exe
    + 2011-09-16 02:03 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2570947$\spuninst\updspapi.dll
    + 2011-09-16 02:03 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2570947$\spuninst\spuninst.exe
    + 2011-08-25 08:22 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2570791$\spuninst\updspapi.dll
    + 2011-08-25 08:22 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2570791$\spuninst\spuninst.exe
    + 2011-08-11 01:19 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2570222$\spuninst\updspapi.dll
    + 2011-08-11 01:19 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2570222$\spuninst\spuninst.exe
    + 2011-08-11 01:19 . 2008-04-14 00:13 139656 c:\windows\$NtUninstallKB2570222$\rdpwd.sys
    + 2011-08-11 01:19 . 2011-04-26 11:07 293376 c:\windows\$NtUninstallKB2567680$\winsrv.dll
    + 2011-08-11 01:19 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2567680$\spuninst\updspapi.dll
    + 2011-08-11 01:19 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2567680$\spuninst\spuninst.exe
    + 2011-10-14 07:03 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2567053$\spuninst\updspapi.dll
    + 2011-10-14 07:03 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2567053$\spuninst\spuninst.exe
    + 2011-08-11 01:14 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2566454$\spuninst\updspapi.dll
    + 2011-08-11 01:14 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2566454$\spuninst\spuninst.exe
    + 2011-10-14 07:08 . 2008-07-30 00:59 161296 c:\windows\$NtUninstallKB2564958$\uiautomationcore.dll
    + 2011-10-14 07:08 . 2011-08-12 17:51 382840 c:\windows\$NtUninstallKB2564958$\spuninst\updspapi.dll
    + 2011-10-14 07:08 . 2011-08-12 17:51 231288 c:\windows\$NtUninstallKB2564958$\spuninst\spuninst.exe
    + 2011-10-14 07:08 . 2004-08-04 11:00 163328 c:\windows\$NtUninstallKB2564958$\oleacc.dll
    + 2011-08-11 01:14 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2562937$\spuninst\updspapi.dll
    + 2011-08-11 01:14 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2562937$\spuninst\spuninst.exe
    + 2011-07-14 01:41 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2555917$\spuninst\updspapi.dll
    + 2011-07-14 01:41 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2555917$\spuninst\spuninst.exe
    + 2011-11-09 13:11 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2544893-v2$\spuninst\updspapi.dll
    + 2011-11-09 13:11 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2544893-v2$\spuninst\spuninst.exe
    + 2011-11-09 13:11 . 2011-05-02 15:31 692736 c:\windows\$NtUninstallKB2544893-v2$\inetcomm.dll
    + 2011-08-11 01:19 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2536276-v2$\spuninst\updspapi.dll
    + 2011-08-11 01:19 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2536276-v2$\spuninst\spuninst.exe
    + 2011-08-11 01:19 . 2011-04-29 16:19 456320 c:\windows\$NtUninstallKB2536276-v2$\mrxsmb.sys
    + 2011-07-14 01:45 . 2010-06-18 17:45 293376 c:\windows\$NtUninstallKB2507938$\winsrv.dll
    + 2011-07-14 01:45 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2507938$\spuninst\updspapi.dll
    + 2011-07-14 01:45 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2507938$\spuninst\spuninst.exe
    + 2012-02-16 08:02 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2661637\update\updspapi.dll
    + 2012-02-16 08:02 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2661637\update\update.exe
    + 2012-02-16 08:02 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2661637\spuninst.exe
    + 2012-02-16 08:03 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2660465\update\updspapi.dll
    + 2012-02-16 08:03 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2660465\update\update.exe
    + 2012-02-16 08:03 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2660465\spuninst.exe
    + 2012-02-16 08:03 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2647516-IE8\update\updspapi.dll
    + 2012-02-16 08:03 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2647516-IE8\update\update.exe
    + 2012-02-16 08:03 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2647516-IE8\spuninst.exe
    + 2012-02-15 10:37 . 2011-12-17 19:45 919552 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\wininet.dll
    + 2012-02-15 10:37 . 2011-12-17 19:45 105984 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\url.dll
    + 2012-02-15 10:37 . 2011-12-17 19:45 206848 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\occache.dll
    + 2012-02-15 10:37 . 2011-12-17 19:45 611840 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\mstime.dll
    + 2012-02-15 10:37 . 2011-12-17 19:45 602112 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\msfeeds.dll
    + 2012-02-15 10:37 . 2011-12-17 19:45 247808 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\ieproxy.dll
    + 2012-02-15 10:37 . 2011-12-17 19:45 184320 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\iepeers.dll
    + 2012-02-15 10:37 . 2011-12-17 19:45 743424 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\iedvtool.dll
    + 2012-02-15 10:37 . 2011-12-17 19:45 387584 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\iedkcs32.dll
    + 2012-02-15 10:37 . 2011-12-16 12:33 174080 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\ie4uinit.exe
    + 2012-01-12 08:16 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2646524\update\updspapi.dll
    + 2012-01-12 08:16 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2646524\update\update.exe
    + 2012-01-12 08:16 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2646524\spuninst.exe
    + 2011-11-25 21:56 . 2011-11-25 21:56 293376 c:\windows\$hf_mig$\KB2646524\SP3QFE\winsrv.dll
    + 2011-11-12 02:14 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2641690\update\updspapi.dll
    + 2011-11-12 02:14 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2641690\update\update.exe
    + 2011-11-12 02:14 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2641690\spuninst.exe
    + 2011-09-28 07:05 . 2011-09-28 07:05 599552 c:\windows\$hf_mig$\KB2641690\SP3QFE\crypt32.dll
    + 2011-12-15 15:36 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2639417\update\updspapi.dll
    + 2011-12-15 15:36 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2639417\update\update.exe
    + 2011-12-15 15:36 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2639417\spuninst.exe
    + 2011-12-15 15:30 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2633171\update\updspapi.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2633171\update\update.exe
    + 2011-12-15 15:30 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2633171\spuninst.exe
    + 2012-01-12 08:16 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2631813\update\updspapi.dll
    + 2012-01-12 08:16 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2631813\update\update.exe
    + 2012-01-12 08:16 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2631813\spuninst.exe
    + 2011-11-03 15:27 . 2011-11-03 15:27 386048 c:\windows\$hf_mig$\KB2631813\SP3QFE\qdvd.dll
    + 2011-12-15 15:36 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2624667\update\updspapi.dll
    + 2011-12-15 15:36 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2624667\update\update.exe
    + 2011-12-15 15:36 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2624667\spuninst.exe
    + 2011-12-15 15:30 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2620712\update\updspapi.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2620712\update\update.exe
    + 2011-12-15 15:30 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2620712\spuninst.exe
    + 2011-12-15 15:30 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2619339\update\updspapi.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2619339\update\update.exe
    + 2011-12-15 15:30 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2619339\spuninst.exe
    + 2011-10-18 11:12 . 2011-10-18 11:12 186880 c:\windows\$hf_mig$\KB2619339\SP3QFE\encdec.dll
    + 2011-12-15 15:30 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2618451\update\updspapi.dll
    + 2011-12-15 15:30 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2618451\update\update.exe
    + 2011-12-15 15:30 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2618451\spuninst.exe
    + 2011-12-15 15:35 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2618444-IE8\update\updspapi.dll
    + 2011-12-15 15:35 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2618444-IE8\update\update.exe
    + 2011-12-15 15:35 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2618444-IE8\spuninst.exe
    + 2011-12-15 10:01 . 2011-11-04 19:19 919552 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\wininet.dll
    + 2011-12-15 10:01 . 2011-11-04 19:19 105984 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\url.dll
    + 2011-12-15 10:01 . 2011-11-04 19:19 206848 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\occache.dll
    + 2011-12-15 10:01 . 2011-11-04 19:19 611840 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\mstime.dll
    + 2011-12-15 10:01 . 2011-11-04 19:19 602112 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\msfeeds.dll
    + 2011-12-15 10:01 . 2011-11-04 19:19 247808 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\ieproxy.dll
    + 2011-12-15 10:01 . 2011-11-04 19:19 184320 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\iepeers.dll
    + 2011-12-15 10:01 . 2011-11-04 19:19 743424 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\iedvtool.dll
    + 2011-12-15 10:01 . 2011-11-04 19:19 387584 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\iedkcs32.dll
    + 2011-12-15 10:01 . 2011-10-25 12:01 174080 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\ie4uinit.exe
    + 2011-09-16 02:07 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2616676\update\updspapi.dll
    + 2011-09-16 02:07 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2616676\update\update.exe
    + 2011-09-16 02:07 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2616676\spuninst.exe
     
  8. 2012/03/28
    dave1234

    dave1234 Well-Known Member Thread Starter

    Joined:
    2002/12/21
    Messages:
    196
    Likes Received:
    0
    cont

    + 2011-09-09 09:11 . 2011-09-09 09:11 599552 c:\windows\$hf_mig$\KB2616676\SP3QFE\crypt32.dll
    + 2011-09-08 02:21 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2607712\update\updspapi.dll
    + 2011-09-08 02:21 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2607712\update\update.exe
    + 2011-09-08 02:21 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2607712\spuninst.exe
    + 2011-09-03 10:16 . 2011-09-03 10:16 599552 c:\windows\$hf_mig$\KB2607712\SP3QFE\crypt32.dll
    + 2012-01-12 08:02 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2603381\update\updspapi.dll
    + 2012-01-12 08:02 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2603381\update\update.exe
    + 2012-01-12 08:02 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2603381\spuninst.exe
    + 2012-01-12 08:10 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2598479\update\updspapi.dll
    + 2012-01-12 08:10 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2598479\update\update.exe
    + 2012-01-12 08:10 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2598479\spuninst.exe
    + 2011-10-14 14:45 . 2011-10-14 14:45 176128 c:\windows\$hf_mig$\KB2598479\SP3QFE\winmm.dll
    + 2011-10-14 07:03 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2592799\update\updspapi.dll
    + 2011-10-14 07:03 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2592799\update\update.exe
    + 2011-10-14 07:03 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2592799\spuninst.exe
    + 2011-10-13 20:10 . 2011-08-17 13:41 138496 c:\windows\$hf_mig$\KB2592799\SP3QFE\afd.sys
    + 2011-10-14 07:03 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2586448-IE8\update\updspapi.dll
    + 2011-10-14 07:03 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2586448-IE8\update\update.exe
    + 2011-10-14 07:03 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2586448-IE8\spuninst.exe
    + 2011-10-13 20:10 . 2011-08-22 23:47 919552 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\wininet.dll
    + 2011-10-13 20:10 . 2011-08-22 23:47 105984 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\url.dll
    + 2011-10-13 20:10 . 2011-08-22 23:47 206848 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\occache.dll
    + 2011-10-13 20:10 . 2011-08-22 23:47 611840 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mstime.dll
    + 2011-10-13 20:10 . 2011-08-22 23:47 602112 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\msfeeds.dll
    + 2011-10-13 20:10 . 2011-08-22 23:47 247808 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\ieproxy.dll
    + 2011-10-13 20:10 . 2011-08-22 23:47 184320 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\iepeers.dll
    + 2011-10-13 20:10 . 2011-08-22 23:47 743424 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\iedvtool.dll
    + 2011-10-13 20:10 . 2011-08-22 23:47 387584 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\iedkcs32.dll
    + 2011-10-13 20:10 . 2011-08-22 11:52 174080 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\ie4uinit.exe
    + 2012-01-18 02:30 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2585542\update\updspapi.dll
    + 2012-01-18 02:30 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2585542\update\update.exe
    + 2012-01-18 02:30 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2585542\spuninst.exe
    + 2011-11-16 14:20 . 2011-11-16 14:20 354816 c:\windows\$hf_mig$\KB2585542\SP3QFE\winhttp.dll
    + 2011-11-16 14:20 . 2011-11-16 14:20 152064 c:\windows\$hf_mig$\KB2585542\SP3QFE\schannel.dll
    + 2012-01-12 08:02 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2584146\update\updspapi.dll
    + 2012-01-12 08:02 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2584146\update\update.exe
    + 2012-01-12 08:02 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2584146\spuninst.exe
    + 2011-09-16 02:03 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2570947\update\updspapi.dll
    + 2011-09-16 02:03 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2570947\update\update.exe
    + 2011-09-16 02:03 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2570947\spuninst.exe
    + 2011-08-11 01:19 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2570222\update\updspapi.dll
    + 2011-08-11 01:19 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2570222\update\update.exe
    + 2011-08-11 01:19 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2570222\spuninst.exe
    + 2011-08-10 22:13 . 2011-06-24 14:09 139656 c:\windows\$hf_mig$\KB2570222\SP3QFE\rdpwd.sys
    + 2011-08-11 01:19 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2567680\update\updspapi.dll
    + 2011-08-11 01:19 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2567680\update\update.exe
    + 2011-08-11 01:19 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2567680\spuninst.exe
    + 2011-06-20 17:43 . 2011-06-20 17:43 293376 c:\windows\$hf_mig$\KB2567680\SP3QFE\winsrv.dll
    + 2011-10-14 07:03 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2567053\update\updspapi.dll
    + 2011-10-14 07:03 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2567053\update\update.exe
    + 2011-10-14 07:03 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2567053\spuninst.exe
    + 2011-08-11 01:14 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2566454\update\updspapi.dll
    + 2011-08-11 01:14 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2566454\update\update.exe
    + 2011-08-11 01:14 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2566454\spuninst.exe
    + 2011-08-11 01:14 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2562937\update\updspapi.dll
    + 2011-08-11 01:14 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2562937\update\update.exe
    + 2011-08-11 01:14 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2562937\spuninst.exe
    + 2011-08-11 01:14 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2559049-IE8\update\updspapi.dll
    + 2011-08-11 01:14 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2559049-IE8\update\update.exe
    + 2011-08-11 01:14 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2559049-IE8\spuninst.exe
    + 2011-08-10 22:13 . 2011-06-23 18:33 919552 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\wininet.dll
    + 2011-08-10 22:13 . 2011-06-23 18:33 105984 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\url.dll
    + 2011-08-10 22:13 . 2011-06-23 18:33 206848 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\occache.dll
    + 2011-08-10 22:13 . 2011-06-23 18:33 611840 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\mstime.dll
    + 2011-08-10 22:13 . 2011-06-23 18:33 602112 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\msfeeds.dll
    + 2011-08-10 22:13 . 2011-06-23 18:33 247808 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\ieproxy.dll
    + 2011-08-10 22:13 . 2011-06-23 18:33 184320 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\iepeers.dll
    + 2011-08-10 22:13 . 2011-06-23 18:33 743424 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\iedvtool.dll
    + 2011-08-10 22:13 . 2011-06-23 18:33 387584 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\iedkcs32.dll
    + 2011-08-10 22:13 . 2011-06-23 12:19 173568 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\ie4uinit.exe
    + 2011-07-14 01:41 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2555917\update\updspapi.dll
    + 2011-07-14 01:41 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2555917\update\update.exe
    + 2011-07-14 01:41 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2555917\spuninst.exe
    + 2011-11-09 13:11 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2544893-v2\update\updspapi.dll
    + 2011-11-09 13:11 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2544893-v2\update\update.exe
    + 2011-11-09 13:11 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2544893-v2\spuninst.exe
    + 2011-10-10 14:21 . 2011-10-10 14:21 692736 c:\windows\$hf_mig$\KB2544893-v2\SP3QFE\inetcomm.dll
    + 2011-08-11 01:19 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2536276-v2\update\updspapi.dll
    + 2011-08-11 01:19 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2536276-v2\update\update.exe
    + 2011-08-11 01:19 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2536276-v2\spuninst.exe
    + 2011-08-10 22:13 . 2011-07-15 13:29 457856 c:\windows\$hf_mig$\KB2536276-v2\SP3QFE\mrxsmb.sys
    + 2011-07-14 01:45 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2507938\update\updspapi.dll
    + 2011-07-14 01:45 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2507938\update\update.exe
    + 2011-07-14 01:45 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2507938\spuninst.exe
    + 2011-04-26 11:02 . 2011-04-26 11:02 293376 c:\windows\$hf_mig$\KB2507938\SP3QFE\winsrv.dll
    + 2011-07-04 19:31 . 2011-07-04 19:31 1303767 c:\windows\WebACS.exe
    + 2009-11-06 13:40 . 2011-08-02 21:38 4517664 c:\windows\system32\usbaaplrc.dll
    + 2004-08-10 18:51 . 2011-12-17 19:46 1212416 c:\windows\system32\urlmon.dll
    + 2004-08-10 18:51 . 2011-11-03 15:28 1292288 c:\windows\system32\quartz.dll
    + 2004-08-10 18:51 . 2011-11-01 16:07 1288704 c:\windows\system32\ole32.dll
    + 2004-08-10 18:51 . 2011-10-25 13:37 2148864 c:\windows\system32\ntoskrnl.exe
    - 2004-08-10 18:51 . 2010-12-09 13:42 2148864 c:\windows\system32\ntoskrnl.exe
    + 2004-08-04 04:59 . 2011-10-25 12:52 2027008 c:\windows\system32\ntkrnlpa.exe
    - 2004-08-04 04:59 . 2010-12-09 13:07 2027008 c:\windows\system32\ntkrnlpa.exe
    + 2004-08-10 18:51 . 2011-12-17 19:46 5979136 c:\windows\system32\mshtml.dll
    + 2009-03-08 08:32 . 2011-12-17 19:46 2000384 c:\windows\system32\iertutil.dll
    + 2011-10-26 01:31 . 2011-08-02 21:38 4517664 c:\windows\system32\DRVSTORE\usbaapl_091115F4EDEB41DBA0EC91574CE905B4E0482482\usbaaplrc.dll
    + 2011-10-26 01:31 . 2011-08-02 21:38 1461992 c:\windows\system32\DRVSTORE\netaapl_63AA05C4700EB9CAF2D048DAC1D06D764A0D4C41\wdfcoinstaller01009.dll
    + 2008-08-22 22:46 . 2011-01-27 04:34 6406656 c:\windows\system32\drivers\ati2mtag.sys
    + 2008-10-16 05:51 . 2012-02-03 09:22 1860096 c:\windows\system32\dllcache\win32k.sys
    + 2008-06-26 08:15 . 2011-12-17 19:46 1212416 c:\windows\system32\dllcache\urlmon.dll
    + 2008-05-07 05:12 . 2011-11-03 15:28 1292288 c:\windows\system32\dllcache\quartz.dll
    + 2010-07-16 12:05 . 2011-11-01 16:07 1288704 c:\windows\system32\dllcache\ole32.dll
    + 2008-10-16 05:51 . 2011-10-25 13:33 2192768 c:\windows\system32\dllcache\ntoskrnl.exe
    - 2008-10-16 05:51 . 2010-12-09 13:38 2192768 c:\windows\system32\dllcache\ntoskrnl.exe
    + 2008-10-16 05:51 . 2011-10-25 12:52 2027008 c:\windows\system32\dllcache\ntkrpamp.exe
    - 2008-10-16 05:51 . 2010-12-09 13:07 2027008 c:\windows\system32\dllcache\ntkrpamp.exe
    - 2008-10-16 05:51 . 2010-12-09 13:07 2069376 c:\windows\system32\dllcache\ntkrnlpa.exe
    + 2008-10-16 05:51 . 2011-10-25 12:52 2069376 c:\windows\system32\dllcache\ntkrnlpa.exe
    + 2008-10-16 05:51 . 2011-10-25 13:37 2148864 c:\windows\system32\dllcache\ntkrnlmp.exe
    - 2008-10-16 05:51 . 2010-12-09 13:42 2148864 c:\windows\system32\dllcache\ntkrnlmp.exe
    + 2008-04-21 06:44 . 2011-12-17 19:46 5979136 c:\windows\system32\dllcache\mshtml.dll
    + 2009-07-03 09:18 . 2011-12-17 19:46 2000384 c:\windows\system32\dllcache\iertutil.dll
    + 2008-08-22 22:46 . 2011-01-27 03:27 2673280 c:\windows\system32\dllcache\ativvaxx.dll
    + 2008-08-22 22:46 . 2011-01-27 03:42 4029824 c:\windows\system32\dllcache\ati3duag.dll
    + 2008-08-22 22:46 . 2011-01-27 04:34 6406656 c:\windows\system32\dllcache\ati2mtag.sys
    + 2008-08-22 22:46 . 2011-01-27 03:27 2673280 c:\windows\system32\ativvaxx.dll
    + 2011-01-27 03:35 . 2011-01-27 03:35 1112576 c:\windows\system32\ativvamv.dll
    + 2011-01-27 03:59 . 2011-01-27 03:59 4636672 c:\windows\system32\aticaldd.dll
    + 2008-08-22 22:46 . 2011-01-27 03:42 4029824 c:\windows\system32\ati3duag.dll
    + 2011-12-25 08:50 . 2011-12-25 08:50 5246976 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
    + 2011-10-26 08:39 . 2011-10-26 08:39 3186688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
    + 2011-07-07 09:18 . 2011-07-07 09:18 5912400 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
    - 2011-03-25 10:15 . 2011-03-25 10:15 5912400 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
    - 2011-03-25 10:15 . 2011-03-25 10:15 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
    + 2011-07-07 09:18 . 2011-07-07 09:18 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
    + 2011-12-25 16:07 . 2011-12-25 16:07 2064384 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Windows.Forms.dll
    + 2011-12-25 16:06 . 2011-12-25 16:06 1269760 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
    + 2011-12-25 16:06 . 2011-12-25 16:06 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
    - 2010-09-23 19:55 . 2010-09-23 19:55 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
    - 2010-09-23 06:26 . 2010-09-23 06:26 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
    + 2011-12-25 03:54 . 2011-12-25 03:54 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
    + 2011-12-25 03:53 . 2011-12-25 03:53 2527232 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
    - 2010-09-23 19:55 . 2010-09-23 19:55 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
    + 2011-12-25 16:06 . 2011-12-25 16:06 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
    + 2011-12-29 02:42 . 2011-12-29 02:42 4903424 c:\windows\Installer\56a2e.msi
    + 2011-10-31 03:54 . 2011-10-31 03:54 2748416 c:\windows\Installer\4a42889.msp
    + 2011-11-21 11:15 . 2011-11-21 11:15 1435136 c:\windows\Installer\490f4e.msi
    + 2011-12-26 14:59 . 2011-12-26 14:59 4368896 c:\windows\Installer\432bc6a.msp
    + 2011-05-02 04:06 . 2011-05-02 04:06 2705920 c:\windows\Installer\399d130.msp
    + 2011-10-17 18:26 . 2011-10-17 18:26 1437184 c:\windows\Installer\3465fe6.msi
    + 2011-10-26 01:41 . 2011-10-26 01:41 5235200 c:\windows\Installer\2ffba1.msi
    + 2011-10-26 01:34 . 2011-10-26 01:34 1769984 c:\windows\Installer\2ff407.msi
    + 2011-10-26 01:31 . 2011-10-26 01:31 1717248 c:\windows\Installer\2fef07.msi
    + 2011-10-26 01:30 . 2011-10-26 01:30 2002432 c:\windows\Installer\2feec8.msi
    + 2011-10-26 01:28 . 2011-10-26 01:28 1532928 c:\windows\Installer\2fee9a.msi
    + 2012-02-16 08:02 . 2011-11-04 19:20 1212416 c:\windows\ie8updates\KB2647516-IE8\urlmon.dll
    + 2012-02-16 08:02 . 2011-11-04 19:20 5978112 c:\windows\ie8updates\KB2647516-IE8\mshtml.dll
    + 2012-02-16 08:02 . 2011-11-04 19:20 2000384 c:\windows\ie8updates\KB2647516-IE8\iertutil.dll
    + 2011-12-15 15:35 . 2011-08-22 23:48 1212416 c:\windows\ie8updates\KB2618444-IE8\urlmon.dll
    + 2011-12-15 15:35 . 2011-10-03 08:35 5971456 c:\windows\ie8updates\KB2618444-IE8\mshtml.dll
    + 2011-12-15 15:35 . 2011-08-22 23:48 2000384 c:\windows\ie8updates\KB2618444-IE8\iertutil.dll
    + 2011-10-14 07:02 . 2011-06-23 18:36 1212416 c:\windows\ie8updates\KB2586448-IE8\urlmon.dll
    + 2011-10-14 07:02 . 2011-07-25 15:17 5969920 c:\windows\ie8updates\KB2586448-IE8\mshtml.dll
    + 2011-10-14 07:02 . 2011-06-23 18:36 1991680 c:\windows\ie8updates\KB2586448-IE8\iertutil.dll
    + 2011-08-11 01:14 . 2011-04-25 16:11 1211904 c:\windows\ie8updates\KB2559049-IE8\urlmon.dll
    + 2011-08-11 01:14 . 2011-05-30 22:19 5964800 c:\windows\ie8updates\KB2559049-IE8\mshtml.dll
    + 2011-08-11 01:14 . 2011-04-25 16:11 1991680 c:\windows\ie8updates\KB2559049-IE8\iertutil.dll
    + 2008-10-16 05:51 . 2011-10-25 13:33 2192768 c:\windows\Driver Cache\i386\ntoskrnl.exe
    - 2008-10-16 05:51 . 2010-12-09 13:38 2192768 c:\windows\Driver Cache\i386\ntoskrnl.exe
    - 2008-10-16 05:51 . 2010-12-09 13:07 2027008 c:\windows\Driver Cache\i386\ntkrpamp.exe
    + 2008-10-16 05:51 . 2011-10-25 12:52 2027008 c:\windows\Driver Cache\i386\ntkrpamp.exe
    + 2008-10-16 05:51 . 2011-10-25 12:52 2069376 c:\windows\Driver Cache\i386\ntkrnlpa.exe
    - 2008-10-16 05:51 . 2010-12-09 13:07 2069376 c:\windows\Driver Cache\i386\ntkrnlpa.exe
    - 2008-10-16 05:51 . 2010-12-09 13:42 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
    + 2008-10-16 05:51 . 2011-10-25 13:37 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
    + 2012-01-12 08:08 . 2012-01-12 08:08 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_23167d59\System.dll
    + 2012-01-12 08:09 . 2012-01-12 08:09 4792320 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_07c93727\System.dll
    + 2012-01-12 08:09 . 2012-01-12 08:09 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_72b2b2e8\System.Xml.dll
    + 2012-01-12 08:09 . 2012-01-12 08:09 5513216 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_4010470d\System.Xml.dll
    + 2012-01-12 08:08 . 2012-01-12 08:08 3035136 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_f8b85819\System.Windows.Forms.dll
    + 2012-01-12 08:09 . 2012-01-12 08:09 7917568 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_7d42dcf0\System.Windows.Forms.dll
    + 2012-01-12 08:09 . 2012-01-12 08:09 2244608 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_e7dfbfa6\System.Drawing.dll
    + 2012-01-12 08:09 . 2012-01-12 08:09 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_c9da2b34\System.Design.dll
    + 2012-01-12 08:09 . 2012-01-12 08:09 3395584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_34008547\System.Design.dll
    + 2012-01-12 08:09 . 2012-01-12 08:09 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_eb44e727\mscorlib.dll
    + 2012-01-12 08:09 . 2012-01-12 08:10 8908800 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_1580bd19\mscorlib.dll
    + 2011-10-14 21:58 . 2011-10-14 21:58 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1adc4ae51a5ac63e896a1402749ca495\WindowsBase.ni.dll
    + 2012-02-16 08:11 . 2012-02-16 08:11 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\174c2f776741812aed02c337bbcd1dae\WindowsBase.ni.dll
    + 2012-02-16 08:13 . 2012-02-16 08:13 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\94f5164ff4f664c5e4e7fb4c3af1abad\UIAutomationClientsideProviders.ni.dll
    + 2011-10-14 22:01 . 2011-10-14 22:01 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\55d4813580b1e5d268ff0564942cee9c\UIAutomationClientsideProviders.ni.dll
    + 2011-10-14 21:58 . 2011-10-14 21:58 7950848 c:\windows\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll
    + 2012-02-16 08:10 . 2012-02-16 08:10 7953408 c:\windows\assembly\NativeImages_v2.0.50727_32\System\9e3803cd2a11f056291862e306a8e2b2\System.ni.dll
    + 2012-02-16 08:13 . 2012-02-16 08:13 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\77e1279cbf4eecfb0284b63316fe43fe\System.Xml.ni.dll
    + 2011-10-14 22:01 . 2011-10-14 22:01 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll
    + 2012-02-16 08:18 . 2012-02-16 08:18 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\c4c671c737b553db8e07664816475333\System.WorkflowServices.ni.dll
    + 2012-01-12 08:14 . 2012-01-12 08:14 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\05c29118462056cf810df0b6aa660d05\System.WorkflowServices.ni.dll
    + 2012-01-12 08:14 . 2012-01-12 08:14 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\26b3258c559dc0ab6bdce481ffd458b3\System.Workflow.Runtime.ni.dll
    + 2012-02-16 08:18 . 2012-02-16 08:18 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\248ea47105ff4af6ee75e6fdd5b450a1\System.Workflow.Runtime.ni.dll
    + 2012-02-16 08:18 . 2012-02-16 08:18 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\80a288b6611668160334668cc2608e4a\System.Workflow.ComponentModel.ni.dll
    + 2012-01-12 08:14 . 2012-01-12 08:14 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\1642d1b72cd84caf24cbe7c5e8fd8368\System.Workflow.ComponentModel.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\4c27548df5897320840ee0d65db38742\System.Workflow.Activities.ni.dll
    + 2012-01-12 08:14 . 2012-01-12 08:14 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\32ce12c3c2049f2df94c44c94b052e16\System.Workflow.Activities.ni.dll
    + 2012-01-12 08:14 . 2012-01-12 08:14 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\f63ae1310e004777e880f28377bcddd2\System.Web.Services.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\e9ba004858dcdb5958d86f26f043f85a\System.Web.Services.ni.dll
    + 2012-01-12 08:14 . 2012-01-12 08:14 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\c99b02434e71ca9898bebbc08d63e885\System.Web.Mobile.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\030cde14924eefebc06c240dbfe093a4\System.Web.Mobile.ni.dll
    + 2012-01-12 08:14 . 2012-01-12 08:14 2405888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\c8f78b9e94857fdf6c2a378dd1629ee0\System.Web.Extensions.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 2405888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\6379c8ca8ae11effb415139990923ff1\System.Web.Extensions.ni.dll
    + 2012-02-16 08:12 . 2012-02-16 08:12 1917440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\e456140d5d6c43d7383bd36d3f9e12c6\System.Speech.ni.dll
    + 2011-10-14 22:00 . 2011-10-14 22:00 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\10d7daa3d1e62a0e40587cdc707be93f\System.Speech.ni.dll
    + 2012-01-12 08:13 . 2012-01-12 08:13 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\ae749b024162e9ac79110c633b5ce6be\System.ServiceModel.Web.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\285dfbf2380436e187cb624bd1cd4683\System.ServiceModel.Web.ni.dll
    + 2012-02-16 08:14 . 2012-02-16 08:14 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\f2532204217dc10f152afd077b09927c\System.Runtime.Serialization.ni.dll
    + 2011-10-14 22:02 . 2011-10-14 22:02 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\afd6134c090faf8c29cd64d4835142b2\System.Runtime.Serialization.ni.dll
    + 2012-02-16 08:12 . 2012-02-16 08:12 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\d51e6bb07124a1d780d1e024858e0dc1\System.Printing.ni.dll
    + 2011-10-14 22:00 . 2011-10-14 22:00 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\0f8e14bfdb27645fb1a92ce26f9bf521\System.Printing.ni.dll
    + 2012-02-16 08:14 . 2012-02-16 08:14 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\8ef05061cd205c4f2a8583d97f32a603\System.IdentityModel.ni.dll
    + 2012-01-12 08:11 . 2012-01-12 08:11 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\23eb4618c9d171be9fb551a13a475a32\System.IdentityModel.ni.dll
    + 2011-10-14 22:00 . 2011-10-14 22:00 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll
    + 2012-02-16 08:12 . 2012-02-16 08:12 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\9351cf29bb1ba951e45a9b3b0edab937\System.Drawing.ni.dll
    + 2011-10-14 22:13 . 2011-10-14 22:13 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\91cd88a803768151c6262853d3454ba7\System.DirectoryServices.ni.dll
    + 2012-02-16 08:16 . 2012-02-16 08:16 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\77d0e93f024055d04c07cc2700b4c590\System.DirectoryServices.ni.dll
    + 2011-10-14 22:13 . 2011-10-14 22:13 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\cc5ac99e8af2738e85cda5525fdd944f\System.Deployment.ni.dll
    + 2012-02-16 08:16 . 2012-02-16 08:16 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\707a05a7d5a8d99dd56d1d50311a60d2\System.Deployment.ni.dll
    + 2011-10-14 22:00 . 2011-10-14 22:00 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\ec323cf1df697cc0a45f67de685db90c\System.Data.ni.dll
    + 2012-02-16 08:12 . 2012-02-16 08:12 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\ae888f8633fce3ff1de98e32bce0abbf\System.Data.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\ef748704f543a8791e23387652d34dfb\System.Data.SqlXml.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\857300fa64d09c69125451fd8894f3da\System.Data.SqlXml.ni.dll
    + 2012-01-12 08:13 . 2012-01-12 08:13 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\f35064c125799df650c1a959d8fa450b\System.Data.Services.ni.dll
    + 2012-02-16 08:16 . 2012-02-16 08:16 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\e9d4a1fb13572c769ddd9b86e55baab4\System.Data.Services.ni.dll
    + 2011-10-14 22:00 . 2011-10-14 22:00 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\d96a94076acb8e0c5a96a1b2de4b3a7a\System.Data.Linq.ni.dll
    + 2012-02-16 08:12 . 2012-02-16 08:12 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\c3d9c33f71d15a3e2e240092a244eba3\System.Data.Linq.ni.dll
    + 2011-10-14 22:13 . 2011-10-14 22:13 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\a3ce22c2a84fdcb008d72d230ee0b2c0\System.Data.Entity.ni.dll
    + 2012-02-16 08:16 . 2012-02-16 08:16 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\424160369b301ccd1b6fd86265611955\System.Data.Entity.ni.dll
    + 2011-10-14 22:00 . 2011-10-14 22:00 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\d507b9e0e50e453793ee5e01c07a5485\System.Core.ni.dll
    + 2012-02-16 08:12 . 2012-02-16 08:12 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\0a6d6717e76be12295711ff02c7aa1d4\System.Core.ni.dll
    + 2011-10-14 22:00 . 2011-10-14 22:00 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\714e9504255565bd9076fe13628e104a\ReachFramework.ni.dll
    + 2012-02-16 08:12 . 2012-02-16 08:12 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\33cdfb4c322a528260016ac759230501\ReachFramework.ni.dll
    + 2012-02-16 08:12 . 2012-02-16 08:12 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\a6def83aee1aaf3336675ce58ac09013\PresentationUI.ni.dll
    + 2011-10-14 22:00 . 2011-10-14 22:00 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\7dc6ee14234b0686182ced75f7dae990\PresentationUI.ni.dll
    + 2011-10-14 21:58 . 2011-10-14 21:58 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b42ad515bb20ec1f1250c040371c6730\PresentationBuildTasks.ni.dll
    + 2012-02-16 08:11 . 2012-02-16 08:11 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\59cd6ce5a254006179eee92952cd2272\PresentationBuildTasks.ni.dll
    + 2012-01-12 08:13 . 2012-01-12 08:13 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\a86c12788293105a0d9fda1bc90c90bc\Microsoft.VisualBasic.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\96e485c02ad346a2bd26a635e7fcb023\Microsoft.VisualBasic.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\f7071f9a1c0523540f6aa7f11c302fb6\Microsoft.Transactions.Bridge.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\ce1ecd602ca089eb13a9b428dc7f0449\Microsoft.Transactions.Bridge.ni.dll
    + 2011-10-14 22:14 . 2011-10-14 22:14 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\8ad32b72258899177c07dc5912b5b748\Microsoft.JScript.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\806b1d127ed3e906db972751e87585c4\Microsoft.JScript.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\912789fd859e0887e10a935cade08e72\Microsoft.Build.Tasks.v3.5.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\6c1d3eec78906cc2a2ecffb013114c50\Microsoft.Build.Tasks.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\50e7c5eb58c982dba7b21cd10a69b095\Microsoft.Build.Tasks.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\415cef6abab5bb959f200f6c537bc289\Microsoft.Build.Tasks.v3.5.ni.dll
    + 2011-10-14 22:12 . 2011-10-14 22:12 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\eea7bcc8d356e3f2dcb4f36dfc1c6bc0\Microsoft.Build.Engine.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\d6edd4b4619a9052d3dfe50c3067d5e0\Microsoft.Build.Engine.ni.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 3186688 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    - 2010-10-08 03:00 . 2010-10-08 03:00 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
    + 2012-01-12 08:09 . 2012-01-12 08:09 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 5246976 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
    + 2012-02-16 08:09 . 2012-02-16 08:09 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
    + 2011-10-14 12:51 . 2012-02-16 08:09 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
    - 2011-06-28 22:00 . 2011-06-28 22:00 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
    - 2010-10-08 02:53 . 2010-10-08 02:53 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
    + 2012-01-12 08:08 . 2012-01-12 08:08 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
    + 2012-01-12 08:08 . 2012-01-12 08:08 2064384 c:\windows\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\System.Windows.Forms.dll
    + 2012-01-12 08:08 . 2012-01-12 08:08 1269760 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
    + 2012-02-16 08:03 . 2011-11-23 13:25 1859584 c:\windows\$NtUninstallKB2660465$\win32k.sys
    + 2011-12-15 15:36 . 2011-09-06 13:20 1858944 c:\windows\$NtUninstallKB2639417$\win32k.sys
    + 2011-12-15 15:30 . 2010-12-09 13:42 2148864 c:\windows\$NtUninstallKB2633171$\ntoskrnl.exe
    + 2011-12-15 15:30 . 2010-12-09 13:07 2027008 c:\windows\$NtUninstallKB2633171$\ntkrpamp.exe
    + 2011-12-15 15:30 . 2010-12-09 13:07 2027008 c:\windows\$NtUninstallKB2633171$\ntkrnlpa.exe
    + 2011-12-15 15:30 . 2010-12-09 13:42 2148864 c:\windows\$NtUninstallKB2633171$\ntkrnlmp.exe
    + 2012-01-12 08:16 . 2010-02-05 18:27 1291776 c:\windows\$NtUninstallKB2631813$\quartz.dll
    + 2011-12-15 15:36 . 2010-07-16 12:05 1288192 c:\windows\$NtUninstallKB2624667$\ole32.dll
    + 2011-10-14 07:03 . 2011-06-02 14:02 1858944 c:\windows\$NtUninstallKB2567053$\win32k.sys
    + 2011-07-14 01:41 . 2011-03-03 13:21 1857920 c:\windows\$NtUninstallKB2555917$\win32k.sys
    + 2012-01-12 16:54 . 2012-01-12 16:54 1869056 c:\windows\$hf_mig$\KB2660465\SP3QFE\win32k.sys
    + 2012-02-15 10:37 . 2011-12-17 19:45 1214464 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\urlmon.dll
    + 2012-02-15 10:37 . 2011-12-17 19:45 5980160 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\mshtml.dll
    + 2012-02-15 10:37 . 2011-12-17 19:45 2001408 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\iertutil.dll
    + 2011-11-23 13:29 . 2011-11-23 13:29 1868544 c:\windows\$hf_mig$\KB2639417\SP3QFE\win32k.sys
    + 2011-10-25 13:34 . 2011-10-25 13:34 2192768 c:\windows\$hf_mig$\KB2633171\SP3QFE\ntoskrnl.exe
    + 2011-10-25 12:52 . 2011-10-25 12:52 2027008 c:\windows\$hf_mig$\KB2633171\SP3QFE\ntkrpamp.exe
    + 2011-10-25 12:52 . 2011-10-25 12:52 2069376 c:\windows\$hf_mig$\KB2633171\SP3QFE\ntkrnlpa.exe
    + 2011-10-25 13:38 . 2011-10-25 13:38 2148864 c:\windows\$hf_mig$\KB2633171\SP3QFE\ntkrnlmp.exe
    + 2011-11-03 15:27 . 2011-11-03 15:27 1292288 c:\windows\$hf_mig$\KB2631813\SP3QFE\quartz.dll
    + 2011-11-01 16:05 . 2011-11-01 16:05 1289216 c:\windows\$hf_mig$\KB2624667\SP3QFE\ole32.dll
    + 2011-12-15 10:01 . 2011-11-04 19:19 1214464 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\urlmon.dll
    + 2011-12-15 10:01 . 2011-11-04 19:19 5978624 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\mshtml.dll
    + 2011-12-15 10:01 . 2011-11-04 19:19 2001408 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\iertutil.dll
    + 2011-10-13 20:10 . 2011-08-22 23:47 1214464 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\urlmon.dll
    + 2011-10-13 20:10 . 2011-10-03 08:34 5972992 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mshtml.dll
    + 2011-10-13 20:10 . 2011-08-22 23:47 2001408 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\iertutil.dll
    + 2011-09-06 13:25 . 2011-09-06 13:25 1867904 c:\windows\$hf_mig$\KB2567053\SP3QFE\win32k.sys
    + 2011-08-10 22:13 . 2011-06-23 18:33 1214464 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\urlmon.dll
    + 2011-08-10 22:13 . 2011-07-25 15:15 5971456 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\mshtml.dll
    + 2011-08-10 22:13 . 2011-06-23 18:33 1992192 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\iertutil.dll
    + 2011-06-02 14:07 . 2011-06-02 14:07 1867904 c:\windows\$hf_mig$\KB2555917\SP3QFE\win32k.sys
    + 2005-11-16 11:18 . 2012-03-15 03:54 54215544 c:\windows\system32\MRT.exe
    + 2009-03-08 08:39 . 2011-12-18 19:46 11082240 c:\windows\system32\ieframe.dll
    + 2009-07-03 09:18 . 2011-12-18 19:46 11082240 c:\windows\system32\dllcache\ieframe.dll
    + 2011-01-27 04:05 . 2011-01-27 04:05 17252352 c:\windows\system32\atioglxx.dll
    + 2011-12-26 22:02 . 2011-12-26 22:02 12482048 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2656353\M2656353Uninstall.msp
    + 2011-07-12 00:43 . 2011-07-12 00:43 11641344 c:\windows\Installer\f57278.msp
    + 2011-07-12 19:50 . 2011-07-12 19:50 17555968 c:\windows\Installer\f5726f.msp
    + 2011-07-12 00:43 . 2011-07-12 00:43 11641344 c:\windows\Installer\4cc9074.msp
    + 2011-07-12 19:50 . 2011-07-12 19:50 17555968 c:\windows\Installer\4cc9073.msp
    + 2011-12-26 14:02 . 2011-12-26 14:02 19677184 c:\windows\Installer\432bc83.msp
    + 2012-02-19 23:45 . 2012-02-19 23:45 23622656 c:\windows\Installer\1040150e.msp
    + 2012-02-16 08:02 . 2011-11-04 19:20 11081728 c:\windows\ie8updates\KB2647516-IE8\ieframe.dll
    + 2011-12-15 15:35 . 2011-08-23 21:48 11081728 c:\windows\ie8updates\KB2618444-IE8\ieframe.dll
    + 2011-10-14 07:02 . 2011-06-23 18:36 11081728 c:\windows\ie8updates\KB2586448-IE8\ieframe.dll
    + 2011-08-11 01:14 . 2011-04-26 14:11 11081728 c:\windows\ie8updates\KB2559049-IE8\ieframe.dll
    + 2012-02-16 08:13 . 2012-02-16 08:13 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ad99ac6b5666edb8ee742dd64f9578af\System.Windows.Forms.ni.dll
    + 2011-10-14 22:01 . 2011-10-14 22:01 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll
    + 2012-01-12 08:13 . 2012-01-12 08:13 11817472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\62e34cfb5a8b233667c7c5a47a32ad93\System.Web.ni.dll
    + 2012-02-16 08:17 . 2012-02-16 08:17 11817472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\29bdc8352d3c26e3c572ea60639dec3b\System.Web.ni.dll
    + 2012-01-12 08:12 . 2012-01-12 08:12 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\2dac4fc006596760cd4988d0bfd52ff0\System.ServiceModel.ni.dll
    + 2012-02-16 08:15 . 2012-02-16 08:15 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\1cdcd6d97627d345d5ff446e6ec88b97\System.ServiceModel.ni.dll
    + 2012-01-12 08:07 . 2012-01-12 08:07 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\9e15d80ffb037e9171fa4bd2e0233497\System.Design.ni.dll
    + 2012-02-16 08:12 . 2012-02-16 08:12 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\7c8f8fb506c32500acc1b6190d054f26\System.Design.ni.dll
    + 2012-02-16 08:11 . 2012-02-16 08:11 14328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\5060105fb9e169399fe45600b1e9215e\PresentationFramework.ni.dll
    + 2011-10-14 21:59 . 2011-10-14 21:59 14328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\054488924fcc579cce9fa0209dafe28b\PresentationFramework.ni.dll
    + 2011-10-14 21:59 . 2011-10-14 21:59 12215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\b2f0318713eca304eaa9d86fc17edb96\PresentationCore.ni.dll
    + 2012-02-16 08:11 . 2012-02-16 08:11 12215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\0665bba8c9962deadc418881eb3a2a2a\PresentationCore.ni.dll
    + 2011-10-14 21:58 . 2011-10-14 21:58 11490816 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
    + 2012-02-15 10:37 . 2011-12-17 19:45 11085312 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\ieframe.dll
    + 2011-11-05 19:19 . 2011-11-05 19:19 11083776 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\ieframe.dll
    + 2011-10-13 20:10 . 2011-08-22 23:47 11084288 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\ieframe.dll
    + 2011-06-25 05:03 . 2011-06-25 05:03 11083776 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\ieframe.dll
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "igfxhkcmd "= "c:\windows\system32\hkcmd.exe" [2005-07-20 77824]
    "dellsupportcenter "= "c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
    "TkBellExe "= "c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-06 180269]
    "MSC "= "c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
    "QuickTime Task "= "c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
    "DivXUpdate "= "c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
    "APSDaemon "= "c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
    "iTunesHelper "= "c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "DWQueuedReporting "= "c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    VPN Client.lnk - c:\windows\Installer\{1CE60928-8325-49A8-8B06-633E48DD2B67}\Icon3E5562ED7.ico [2011-12-28 6144]
    .
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} "= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @= "Service "
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "Share-to-Web Namespace Daemon "=c:\program files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
    "MMTray "= "c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe "
    "MimBoot "=c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
    "DVDLauncher "= "c:\program files\CyberLink\PowerDVD\DVDLauncher.exe "
    "Malwarebytes Anti-Malware (reboot) "= "c:\program files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    "QuickTime Task "= "c:\program files\QuickTime\qttask.exe" -atboottime
    "Adobe Reader Speed Launcher "= "c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe "
    "Adobe ARM "= "c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe "
    "DellSupportCenter "= "c:\program files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
    "dscactivate "= "c:\program files\Dell Support Center\gs_agent\custom\dsca.exe "
    "TkBellExe "= "c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe "
    "DivXUpdate "= "c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "c:\\StubInstaller.exe "=
    "c:\\Program Files\\AIM\\aim.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe "=
    "c:\\Program Files\\Java\\jre6\\bin\\java.exe "=
    "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe "=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe "=
    "c:\\Program Files\\iTunes\\iTunes.exe "=
    "c:\\Program Files\\ACS\\ACS\\ACS.exe "=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe "=
    "c:\\Program Files\\DivX\\DivX Update\\DivXUpdate.exe "=
    "c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe "=
    "c:\\Program Files\\Google\\Update\\GoogleUpdate.exe "=
    "c:\\Documents and Settings\\David Peters\\My Documents\\Downloads\\aswMBR(1).exe "=
    "c:\\Program Files\\Real\\RealPlayer\\realplay.exe "=
    "c:\\Program Files\\Mozilla Firefox\\plugin-container.exe "=
    .
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/4/2009 2:50 PM 9968]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/4/2009 2:49 PM 74480]
    R3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\drivers\rcvpn.sys [1/11/2011 8:01 PM 24876]
    S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
    S2 gupdate1c9c3951be7f6a0;Google Update Service (gupdate1c9c3951be7f6a0);c:\program files\Google\Update\GoogleUpdate.exe [4/22/2009 5:55 PM 133104]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/22/2009 5:55 PM 133104]
    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/4/2009 2:50 PM 7408]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    getPlusHelper REG_MULTI_SZ getPlusHelper
    .
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    iastor
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-03-26 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
    .
    2012-03-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-22 21:55]
    .
    2012-03-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-22 21:55]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.yahoo.com/
    uInternet Settings,ProxyOverride = *.local
    TCP: DhcpNameServer = 192.168.2.1
    DPF: {BB28FF6E-2BF3-4897-9931-7CDFFAF09670} - hxxp://192.168.2.125:81/cgi-bin/design/html_template/WebACS.cab
    FF - ProfilePath - c:\documents and settings\David Peters\Application Data\Mozilla\Firefox\Profiles\xf6fq6m9.default\
    FF - prefs.js: browser.startup.homepage - hxxps://webtop.webmail.optimum.net/cerulean/
    .
    - - - - ORPHANS REMOVED - - - -
    .
    AddRemove-Free Audio CD Burner_is1 - c:\program files\DVDVideoSoft\Free Audio CD Burner\unins000.exe
    AddRemove-Free YouTube to MP3 Converter_is1 - c:\program files\DVDVideoSoft\Free YouTube to MP3 Converter\unins000.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2012-03-28 20:39
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(1036)
    c:\windows\system32\Ati2evxx.dll
    c:\windows\system32\atiadlxx.dll
    .
    - - - - - - - > 'explorer.exe'(4072)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\Ati2evxx.exe
    c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
    c:\windows\system32\Ati2evxx.exe
    c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Cisco Systems\VPN Client\cvpnd.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Dell Support Center\bin\sprtsvc.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Completion time: 2012-03-28 20:48:03 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-03-29 00:47
    ComboFix2.txt 2011-07-07 01:25
    ComboFix3.txt 2011-04-19 22:00
    .
    Pre-Run: 49,166,307,328 bytes free
    Post-Run: 49,528,782,848 bytes free
    .
    - - End Of File - - 4D3F9F82AA9A53498FE17982C9D35501
     
  9. 2012/03/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Looks good.

    How is computer doing?

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Under the Custom Scan box paste this in:


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\tasks\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  10. 2012/03/28
    dave1234

    dave1234 Well-Known Member Thread Starter

    Joined:
    2002/12/21
    Messages:
    196
    Likes Received:
    0
    This log file is located at C:\rkill.log.
    Please post this only if requested to by the person helping you.
    Otherwise you can close this log when you wish.

    Rkill was run on 03/28/2012 at 21:05:02.
    Operating System: Microsoft Windows XP


    Processes terminated by Rkill or while it was running:



    Rkill completed on 03/28/2012 at 21:05:06.
     
  11. 2012/03/28
    dave1234

    dave1234 Well-Known Member Thread Starter

    Joined:
    2002/12/21
    Messages:
    196
    Likes Received:
    0
    Appears to be OK so far...downloading the OTL now
     
  12. 2012/03/28
    dave1234

    dave1234 Well-Known Member Thread Starter

    Joined:
    2002/12/21
    Messages:
    196
    Likes Received:
    0
    OTL logfile created on: 3/28/2012 9:10:30 PM - Run 4
    OTL by OldTimer - Version 3.2.39.2 Folder = C:\Documents and Settings\David Peters\My Documents\Downloads
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    510.07 Mb Total Physical Memory | 83.18 Mb Available Physical Memory | 16.31% Memory free
    1.21 Gb Paging File | 0.79 Gb Available in Paging File | 65.70% Paging File free
    Paging file location(s): C:\pagefile.sys 756 2000 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 71.46 Gb Total Space | 46.16 Gb Free Space | 64.60% Space Free | Partition Type: NTFS

    Computer Name: D124YR81 | User Name: David Peters | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/03/28 21:07:56 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David Peters\My Documents\Downloads\OTL.exe
    PRC - [2012/03/17 18:46:30 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
    PRC - [2011/07/28 19:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
    PRC - [2011/06/15 15:16:48 | 000,997,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
    PRC - [2011/04/27 15:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
    PRC - [2010/09/27 12:58:24 | 001,528,616 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    PRC - [2009/05/21 11:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    PRC - [2008/08/13 19:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
    PRC - [2006/08/06 12:20:51 | 000,180,269 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/03/17 18:46:28 | 001,969,080 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
    MOD - [2012/02/16 04:13:11 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\77e1279cbf4eecfb0284b63316fe43fe\System.Xml.ni.dll
    MOD - [2012/02/16 04:10:54 | 007,953,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\9e3803cd2a11f056291862e306a8e2b2\System.ni.dll
    MOD - [2011/10/14 17:58:13 | 011,490,816 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
    MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    MOD - [2011/07/28 19:09:42 | 000,096,112 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
    MOD - [2011/07/28 19:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
    MOD - [2010/09/27 13:03:08 | 000,201,512 | ---- | M] () -- C:\WINDOWS\system32\vpnapi.dll
    MOD - [2008/10/04 23:24:02 | 003,695,008 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [On_Demand | Stopped] -- C:\Documents and Settings\David Peters\Desktop\RampartSvc.exe -- (RampartSvc)
    SRV - File not found [Auto | Stopped] -- %systemroot%\system32\sfsync02.dll -- (iastor)
    SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
    SRV - File not found [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R)
    SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
    SRV - [2011/04/27 15:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
    SRV - [2010/09/27 12:58:24 | 001,528,616 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND)
    SRV - [2008/08/13 19:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
    SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
    SRV - [2005/10/28 19:59:30 | 000,027,648 | ---- | M] (Acesoft) [On_Demand | Stopped] -- C:\Program Files\Acesoft\Tracks Eraser Pro\delautocomp.exe -- (Autocomplete)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before Last Install)
    DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before First Install)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
    DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
    DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\DAVIDP~1\LOCALS~1\Temp\mbr.sys -- (mbr)
    DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
    DRV - File not found [File_System | Boot | Stopped] -- system32\DRIVERS\Lbd.sys -- (Lbd)
    DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
    DRV - File not found [Kernel | On_Demand | Running] -- C:\ComboFix\catchme.sys -- (catchme)
    DRV - [2011/01/27 00:34:32 | 006,406,656 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
    DRV - [2010/09/27 12:56:00 | 000,308,859 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys -- (CVPNDRVA)
    DRV - [2009/09/04 14:50:02 | 000,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
    DRV - [2009/09/04 14:50:00 | 000,009,968 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
    DRV - [2009/09/04 14:49:58 | 000,074,480 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
    DRV - [2008/11/16 19:39:44 | 000,131,984 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dne2000.sys -- (DNE)
    DRV - [2007/11/14 20:05:16 | 000,394,952 | ---- | M] (Zone Labs, LLC) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
    DRV - [2007/07/20 19:40:10 | 000,084,992 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
    DRV - [2007/02/25 12:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\dsunidrv.sys -- (dsunidrv)
    DRV - [2007/01/18 21:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CVirtA.sys -- (CVirtA)
    DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
    DRV - [2005/11/08 09:58:20 | 000,024,876 | ---- | M] (SonicWALL, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rcvpn.sys -- (rcvpn)
    DRV - [2005/06/15 00:40:08 | 000,180,864 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA) High Definition Audio Driver (WDM)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
    IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7


    IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
    IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell4me.com/mywaybiz
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
    IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell4me.com/mywaybiz
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-255644176-2114812240-378072284-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    IE - HKU\S-1-5-21-255644176-2114812240-378072284-1006\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKU\S-1-5-21-255644176-2114812240-378072284-1006\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADFA_en
    IE - HKU\S-1-5-21-255644176-2114812240-378072284-1006\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
    IE - HKU\S-1-5-21-255644176-2114812240-378072284-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-21-255644176-2114812240-378072284-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    ========== FireFox ==========

    FF - prefs.js..browser.startup.homepage: "https://webtop.webmail.optimum.net/cerulean/ "
    FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
    FF - user.js - File not found

    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2321: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2379: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@View22/View22: C:\Program Files\View22\Version 3.10.50\NPView22.dll (View22 Technology)
    FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/05/25 06:28:12 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/05/25 06:28:12 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/17 18:46:31 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/08/09 20:04:08 | 000,000,000 | ---D | M]

    [2011/01/09 14:46:39 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\David Peters\Application Data\Mozilla\Extensions
    [2009/02/16 11:48:08 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\David Peters\Application Data\Mozilla\Extensions\mozswing@mozswing.org
    [2012/02/04 13:00:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\David Peters\Application Data\Mozilla\Firefox\Profiles\xf6fq6m9.default\extensions
    [2011/11/09 23:17:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
    [2010/03/16 22:02:43 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
    [2012/03/17 18:46:30 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
    [2011/07/13 17:52:56 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
    [2011/05/04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
    [2011/07/13 17:52:58 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
    [2011/10/05 10:53:37 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
    [2011/11/09 23:17:06 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

    O1 HOSTS File: ([2012/03/28 20:39:16 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
    O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
    O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
    O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
    O4 - HKLM..\RunOnce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll] C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll ()
    O4 - HKLM..\RunOnce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll] C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll ()
    O4 - HKLM..\RunOnce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll] C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll ()
    O4 - HKLM..\RunOnce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll] C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll ()
    O4 - HKLM..\RunOnce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll] C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll ()
    O4 - HKLM..\RunOnce: [B Register C:\Program Files\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll] C:\Program Files\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll (DivX, LLC)
    O4 - HKLM..\RunOnce: [B Register C:\Program Files\DivX\DivX Plus Player\DSEPlugins\DivXDeinterlaceFilter.dll] C:\Program Files\DivX\DivX Plus Player\DSEPlugins\DivXDeinterlaceFilter.dll (DivX, LLC)
    O4 - HKLM..\RunOnce: [B Register C:\Program Files\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll] C:\Program Files\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll (DivX, LLC)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk = C:\WINDOWS\Installer\{1CE60928-8325-49A8-8B06-633E48DD2B67}\Icon3E5562ED7.ico ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-255644176-2114812240-378072284-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-255644176-2114812240-378072284-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKU\S-1-5-21-255644176-2114812240-378072284-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKU\S-1-5-21-255644176-2114812240-378072284-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O15 - HKU\S-1-5-21-255644176-2114812240-378072284-1006\..Trusted Ranges: Range1 ([*] in Trusted sites)
    O16 - DPF: {49232000-16E4-426C-A231-62846947304B} http://ipgweb.cce.hp.com/rdqaio2/downloads/sysinfo.cab (SysData Class)
    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} http://www.photogize.com/bponet/PhotogizeImageUploader4.cab (Image Uploader Control)
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
    O16 - DPF: {BB28FF6E-2BF3-4897-9931-7CDFFAF09670} http://192.168.2.125:81/cgi-bin/design/html_template/WebACS.cab (WebRemotePlayerControl Class)
    O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AA2EA78A-45E4-40BB-8533-75631664F7D4}: DhcpNameServer = 192.168.2.1
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
    O24 - Desktop WallPaper: C:\Documents and Settings\David Peters\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\David Peters\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2004/08/10 15:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    NetSvcs: 6to4 - File not found
    NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
    NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
    NetSvcs: Ias - File not found
    NetSvcs: Iprip - File not found
    NetSvcs: Irmon - File not found
    NetSvcs: NWCWorkstation - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: iastor - %systemroot%\system32\sfsync02.dll File not found
    NetSvcs: WmdmPmSp - File not found

    Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
    Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
    Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
    Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
    Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
    Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
    Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
    Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
    Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
    Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/03/27 07:41:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
    [2012/03/08 08:37:28 | 000,086,016 | -H-- | C] (Kaspersky Lab) -- C:\WINDOWS\fastay32.dll

    ========== Files - Modified Within 30 Days ==========

    [2012/03/28 20:43:04 | 000,445,798 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2012/03/28 20:43:04 | 000,073,004 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2012/03/28 20:43:03 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    [2012/03/28 20:39:59 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2012/03/28 20:39:36 | 000,002,447 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
    [2012/03/28 20:39:16 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2012/03/28 20:38:48 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
    [2012/03/28 20:38:42 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2012/03/28 20:38:36 | 534,925,312 | -HS- | M] () -- C:\hiberfil.sys
    [2012/03/27 20:50:46 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\David Peters\Desktop\MBR.dat
    [2012/03/26 10:42:27 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2012/03/25 12:20:31 | 000,231,936 | ---- | M] () -- C:\Documents and Settings\David Peters\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2012/03/22 20:12:10 | 000,001,734 | -HS- | M] () -- C:\WINDOWS\System32\KGyGaAvL.sys
    [2012/03/20 17:27:15 | 000,001,730 | -H-- | M] () -- C:\Documents and Settings\David Peters\My Documents\Default.rdp
    [2012/03/15 05:45:24 | 000,406,304 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2012/03/14 23:54:30 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2012/03/08 08:37:29 | 000,086,016 | -H-- | M] (Kaspersky Lab) -- C:\WINDOWS\fastay32.dll
    [2012/03/03 14:02:54 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/03/01 19:20:41 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT

    ========== Files Created - No Company Name ==========

    [2012/03/27 20:50:46 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\David Peters\Desktop\MBR.dat
    [2012/02/15 06:37:03 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
    [2011/11/12 15:25:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
    [2011/04/19 17:38:36 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2011/04/19 17:38:36 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2011/04/19 17:38:36 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2011/04/19 17:38:36 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2011/04/19 17:38:36 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2011/04/15 06:01:38 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
    [2011/01/26 23:26:36 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
    [2011/01/26 23:26:36 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
    [2010/12/17 17:00:46 | 000,227,587 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
    [2010/09/27 13:03:08 | 000,201,512 | ---- | C] () -- C:\WINDOWS\System32\vpnapi.dll
    [2010/09/27 12:57:26 | 000,197,416 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
    [2010/09/13 06:33:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Lyejepefoqesod.bin
    [2010/09/13 06:33:07 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Qpohezenocopol.dat

    ========== LOP Check ==========

    [2008/12/20 16:21:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
    [2008/03/05 06:39:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
    [2008/12/20 16:22:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nikon
    [2010/10/22 20:29:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ReviverSoft
    [2008/02/01 06:32:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
    [2008/12/20 16:21:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
    [2012/03/27 07:41:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
    [2008/10/19 18:01:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZipSE
    [2011/10/25 21:40:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    [2009/11/06 09:47:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    [2005/12/30 10:55:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David Peters\Application Data\ACD Systems
    [2008/04/06 10:51:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David Peters\Application Data\ACDInTouch
    [2005/11/14 12:19:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David Peters\Application Data\Aim
    [2010/01/06 06:38:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David Peters\Application Data\GetRightToGo
    [2010/12/16 20:01:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David Peters\Application Data\Gevesu
    [2009/11/14 09:30:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David Peters\Application Data\GlarySoft
    [2005/11/14 12:02:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David Peters\Application Data\Leadertech
    [2008/12/20 16:24:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David Peters\Application Data\Nikon
    [2010/12/09 08:40:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\David Peters\Application Data\Xosyi

    ========== Purity Check ==========



    ========== Custom Scans ==========

    < %SYSTEMDRIVE%\*.* >
    [2011/01/09 22:13:40 | 000,224,665 | ---- | M] () -- C:\aaw7boot.log
    [2009/02/15 14:04:37 | 034,543,112 | ---- | M] (Lavasoft ) -- C:\Ad-AwareAE.exe
    [2004/08/10 15:04:08 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
    [2010/02/26 06:12:01 | 000,891,208 | ---- | M] (AVG Technologies) -- C:\avg_free_stb_en_9_40.exe
    [2009/08/30 06:15:42 | 000,000,211 | ---- | M] () -- C:\Boot.bak
    [2011/01/11 19:32:46 | 000,000,281 | RHS- | M] () -- C:\boot.ini
    [2004/08/03 23:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
    [2012/03/28 20:48:04 | 000,153,063 | ---- | M] () -- C:\ComboFix.txt
    [2004/08/10 15:04:08 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
    [2005/11/02 22:06:56 | 000,004,604 | ---- | M] () -- C:\data
    [2005/11/02 04:11:20 | 000,005,040 | RH-- | M] () -- C:\dell.sdr
    [2006/01/06 04:19:41 | 004,193,599 | ---- | M] () -- C:\EasyShare.dmp
    [2006/03/11 19:06:29 | 007,984,736 | ---- | M] () -- C:\ewido-setup.exe
    [2006/03/12 17:49:17 | 000,167,608 | ---- | M] (Symantec Corporation) -- C:\FxIstbar.exe
    [2012/03/28 20:38:36 | 534,925,312 | -HS- | M] () -- C:\hiberfil.sys
    [2006/03/12 17:47:59 | 000,218,112 | ---- | M] (Soeperman Enterprises Ltd.) -- C:\HijackThis.exe
    [2009/09/12 16:55:48 | 000,010,301 | ---- | M] () -- C:\hijackthis.log
    [2012/03/27 18:29:09 | 000,292,714 | ---- | M] () -- C:\hpfr5550.log
    [2005/11/28 20:17:24 | 000,004,128 | ---- | M] () -- C:\INFCACHE.1
    [2004/08/10 15:04:08 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
    [2005/11/02 04:31:11 | 000,000,826 | -H-- | M] () -- C:\IPH.PH
    [2009/10/16 13:30:11 | 000,155,822 | ---- | M] () -- C:\iPod_log.txt
    [2011/07/08 06:30:05 | 000,060,310 | ---- | M] () -- C:\JavaRa.log
    [2010/12/25 17:50:33 | 000,000,109 | ---- | M] () -- C:\mbam-error.txt
    [2004/08/10 15:04:08 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
    [2004/08/04 07:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
    [2009/01/10 12:04:15 | 000,250,048 | RHS- | M] () -- C:\ntldr
    [2012/03/28 20:38:35 | 792,723,456 | -HS- | M] () -- C:\pagefile.sys
    [2012/03/28 21:05:06 | 000,000,359 | ---- | M] () -- C:\rkill.log
    [2005/10/31 11:56:00 | 000,700,416 | ---- | M] (LimeWire) -- C:\StubInstaller.exe
    [2009/09/13 09:12:51 | 000,001,637 | ---- | M] () -- C:\swlist.reg
    [2005/11/02 04:31:19 | 000,000,087 | ---- | M] () -- C:\SystemInfo.ini
    [2011/04/16 14:12:18 | 000,048,762 | ---- | M] () -- C:\TDSSKiller.2.4.21.0_16.04.2011_14.10.03_log.txt
    [2012/03/28 05:14:41 | 000,088,450 | ---- | M] () -- C:\TDSSKiller.2.7.23.0_28.03.2012_05.04.25_log.txt
    [2012/03/28 05:52:06 | 000,098,612 | ---- | M] () -- C:\TDSSKiller.2.7.23.0_28.03.2012_05.44.25_log.txt
    [2009/01/10 11:36:22 | 000,267,152 | ---- | M] () -- C:\zaSetup_en.exe

    < %systemroot%\Fonts\*.com >

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2010/03/30 10:09:39 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >
    [2008/07/06 08:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
    [2008/07/06 06:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >

    < %PROGRAMFILES%\*.* >
    [2007/03/06 07:27:44 | 000,215,535 | ---- | M] () -- C:\Program Files\hijackthis.zip

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >
    [2004/08/10 14:56:48 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
    [2004/08/10 14:56:46 | 000,634,880 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
    [2004/08/10 14:56:46 | 000,872,448 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav

    < %PROGRAMFILES%\bak. /s >

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
    [2009/01/10 12:14:25 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini

    < %systemroot%\system32\config\systemprofile\*.dat /x >

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2010/03/30 10:14:22 | 000,000,119 | -HS- | M] () -- C:\Documents and Settings\David Peters\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
    [2004/08/10 15:08:38 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\David Peters\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

    < %USERPROFILE%\Desktop\*.exe >
    [2011/07/06 21:09:24 | 004,133,130 | R--- | M] (Swearware) -- C:\Documents and Settings\David Peters\Desktop\ComboFix.exe
    [2010/09/27 12:56:08 | 000,016,505 | ---- | M] () -- C:\Documents and Settings\David Peters\Desktop\DelayInst.exe
    [2010/09/27 12:56:34 | 000,221,315 | ---- | M] () -- C:\Documents and Settings\David Peters\Desktop\installservice.exe
    [2010/09/27 13:05:24 | 000,056,832 | ---- | M] () -- C:\Documents and Settings\David Peters\Desktop\vpnclient_setup.exe

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\tasks\*.* >
    [2012/03/26 10:42:27 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2004/08/04 07:00:00 | 000,000,065 | RH-- | M] () -- C:\WINDOWS\tasks\desktop.ini
    [2012/03/28 20:38:48 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
    [2012/03/28 20:43:03 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    [2012/03/28 20:38:45 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >
    [2009/04/11 08:32:08 | 000,939,956 | ---- | M] () -- C:\Documents and Settings\David Peters\My Documents\7z465.exe
    [2008/04/06 10:51:05 | 012,962,050 | ---- | M] () -- C:\Documents and Settings\David Peters\My Documents\acdsee31updater.exe
    [2009/04/02 06:28:38 | 102,612,888 | ---- | M] (Macrovision Corporation) -- C:\Documents and Settings\David Peters\My Documents\CVSPhotoEditorPlus_120.exe
    [2011/05/25 06:22:57 | 000,912,736 | ---- | M] (DivX, LLC) -- C:\Documents and Settings\David Peters\My Documents\DivXInstaller.exe
    [2011/01/09 14:45:33 | 008,582,536 | ---- | M] (Mozilla) -- C:\Documents and Settings\David Peters\My Documents\Firefox Setup 3.6.13.exe
    [2011/01/07 23:09:04 | 000,883,488 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\David Peters\My Documents\JavaSetup6u23.exe
    [2009/11/14 09:28:54 | 002,308,608 | ---- | M] (GlarySoft.com ) -- C:\Documents and Settings\David Peters\My Documents\qssetup.exe
    [2008/01/28 06:47:16 | 000,325,168 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\David Peters\My Documents\RealPlayer11GOLD.exe
    [2008/04/12 09:10:40 | 001,639,504 | ---- | M] (Acesoft, Inc. ) -- C:\Documents and Settings\David Peters\My Documents\te5.exe
    [2012/01/11 09:26:15 | 001,785,776 | ---- | M] (Acesoft, Inc. ) -- C:\Documents and Settings\David Peters\My Documents\te6.exe
    [2008/10/19 16:48:05 | 000,195,663 | ---- | M] () -- C:\Documents and Settings\David Peters\My Documents\unrarw32.exe
    [2010/03/28 20:05:05 | 008,287,608 | ---- | M] () -- C:\Documents and Settings\David Peters\My Documents\View22_Install_3_10_50.exe
    [2008/10/19 18:01:21 | 002,131,320 | ---- | M] () -- C:\Documents and Settings\David Peters\My Documents\wzipse31.exe
    [2009/09/01 13:08:29 | 000,366,552 | ---- | M] (Digital River, Inc.) -- C:\Documents and Settings\David Peters\My Documents\X12-30263-DLM.exe
    [2007/04/22 07:03:54 | 040,738,456 | ---- | M] () -- C:\Documents and Settings\David Peters\My Documents\zlsSetup_70_337_000_en.exe
    [2007/11/17 11:27:23 | 041,412,496 | ---- | M] () -- C:\Documents and Settings\David Peters\My Documents\zlsSetup_70_408_000_en.exe
    [2008/03/05 06:37:38 | 041,724,304 | ---- | M] () -- C:\Documents and Settings\David Peters\My Documents\zlsSetup_70_462_000_en.exe
    [2008/07/11 20:50:55 | 046,829,456 | ---- | M] () -- C:\Documents and Settings\David Peters\My Documents\zlsSetup_70_483_000_en.exe

    < %USERPROFILE%\*.exe >
    [2005/11/20 23:02:07 | 000,557,056 | ---- | M] (Citrix Online) -- C:\Documents and Settings\David Peters\chatlnk.exe
    [2005/11/18 11:19:36 | 000,000,128 | ---- | M] () -- C:\Documents and Settings\David Peters\zzz.exe

    < %systemroot%\ADDINS\*.* >
    [2004/08/04 07:00:00 | 000,000,791 | ---- | M] () -- C:\WINDOWS\ADDINS\fxsext.ecf

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2010/03/30 10:14:22 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\David Peters\Favorites\Desktop.ini

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

    < dir /b "%systemroot%\*.exe" | find /i " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >
    [2012/03/28 21:05:09 | 004,112,384 | -HS- | M] () -- C:\Documents and Settings\David Peters\Cookies\index.dat

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >
    [2007/06/26 22:10:26 | 000,317,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >
    [2008/04/13 20:11:51 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll
    [2004/08/04 03:06:34 | 000,004,821 | ---- | M] () -- C:\Program Files\Messenger\logowin.gif
    [2004/08/04 03:06:34 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif
    [2008/05/02 10:01:49 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgsc.dll
    [2008/04/13 13:30:28 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll
    [2008/04/13 20:12:28 | 001,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
    [2004/08/04 03:06:36 | 000,002,882 | ---- | M] () -- C:\Program Files\Messenger\newalert.wav
    [2004/08/04 03:06:36 | 000,006,156 | ---- | M] () -- C:\Program Files\Messenger\newemail.wav
    [2004/08/04 03:06:36 | 000,006,160 | ---- | M] () -- C:\Program Files\Messenger\online.wav
    [2004/08/04 03:06:36 | 000,004,454 | ---- | M] () -- C:\Program Files\Messenger\type.wav
    [2004/08/04 03:06:36 | 000,115,981 | ---- | M] () -- C:\Program Files\Messenger\xpmsgr.chm

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >

    < End of report >
     
  13. 2012/03/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I still need Extras.txt log.
     
  14. 2012/03/28
    dave1234

    dave1234 Well-Known Member Thread Starter

    Joined:
    2002/12/21
    Messages:
    196
    Likes Received:
    0
    Extras log was not produced. I searched but could not find it.
     
  15. 2012/03/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    OTL log is clean.

    Last scans...

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.

    2. Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
    • Press "Scan ".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.


    3. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    4. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     
  16. 2012/03/28
    dave1234

    dave1234 Well-Known Member Thread Starter

    Joined:
    2002/12/21
    Messages:
    196
    Likes Received:
    0
    Results of screen317's Security Check version 0.99.24
    Windows XP Service Pack 3 x86
    Internet Explorer 8
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    ESET Online Scanner v3
    Microsoft Security Essentials
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Out of date HijackThis installed!
    AdsGone Popup Killer Spyware Blocker by A1Tech.com
    SUPERAntiSpyware Free Edition
    HijackThis 1.99.1
    CCleaner
    Java(TM) 6 Update 26
    Out of date Java installed!
    Adobe Flash Player ( 10.0.12.36) Flash Player Out of Date!
    Mozilla Firefox (x86 en-US..)
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Windows Defender MSMpEng.exe
    Microsoft Security Essentials msseces.exe
    Microsoft Security Client Antimalware MsMpEng.exe
    ``````````End of Log````````````


    Farbar Service Scanner Version: 01-03-2012
    Ran by David Peters (administrator) on 28-03-2012 at 23:49:07
    Running from "C:\Documents and Settings\David Peters\Desktop "
    Microsoft Windows XP Home Edition Service Pack 3 (X86)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Google IP is accessible.
    Yahoo IP is accessible.


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================


    System Restore:
    ============

    System Restore Disabled Policy:
    ========================


    Security Center:
    ============

    Windows Update:
    ============

    File Check:
    ========
    C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
    C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
    C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
    C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
    C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
    C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
    C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
    C:\WINDOWS\system32\netman.dll => MD5 is legit
    C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
    C:\WINDOWS\system32\srsvc.dll => MD5 is legit
    C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
    C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
    C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
    C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
    C:\WINDOWS\system32\qmgr.dll => MD5 is legit
    C:\WINDOWS\system32\es.dll => MD5 is legit
    C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
    C:\WINDOWS\system32\svchost.exe => MD5 is legit
    C:\WINDOWS\system32\rpcss.dll => MD5 is legit
    C:\WINDOWS\system32\services.exe => MD5 is legit

    Extra List:
    =======
    DNE(9) Gpc(6) IPSec(4) NetBT(5) PSched(7) Tcpip(3)
    0x0A00000004000000010000000200000003000000080000005600000005000000060000000700000009000000
    IpSec Tag value is correct.

    **** End of log ****
     
  17. 2012/03/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    ...and Eset?....
     
  18. 2012/03/29
    dave1234

    dave1234 Well-Known Member Thread Starter

    Joined:
    2002/12/21
    Messages:
    196
    Likes Received:
    0
    Just finished...

    C:\Documents and Settings\David Peters\DoctorWeb\Quarantine\774de4b7-4cd91c78 Java/ClassLoader.Dummy.D trojan
    C:\Documents and Settings\David Peters\DoctorWeb\Quarantine\7dc55cf4-2af858ed Java/ClassLoader.Dummy.D trojan
    C:\Qoobox\Quarantine\C\Documents and Settings\David Peters\Local Settings\Application Data\bc5c6f8d\X.vir a variant of Win32/Kryptik.ADGW trojan
    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\cdrom.sys.vir a variant of Win32/Rootkit.Kryptik.KL trojan
     
  19. 2012/03/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Update Adobe Flash Player
    Download the Latest Adobe Flash for Firefox and IE Without Any Extras: http://www.404techsupport.com/2010/...-flash-for-firefox-and-ie-without-any-extras/

    ===========================================================

    1. Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    2. Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it.
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.
    • Do NOT post JavaRa log.

    =============================================================

    Your computer is clean [​IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [emptyjava]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    13. Please, let me know, how your computer is doing.
     
  20. 2012/03/31
    dave1234

    dave1234 Well-Known Member Thread Starter

    Joined:
    2002/12/21
    Messages:
    196
    Likes Received:
    0
    Computer runs great!
    Thanks Broni.
    Dave
     
  21. 2012/03/31
    dave1234

    dave1234 Well-Known Member Thread Starter

    Joined:
    2002/12/21
    Messages:
    196
    Likes Received:
    0
    All processes killed
    Error: Unable to interpret <Code: > in the current context!
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: David Peters
    ->Temp folder emptied: 49152 bytes
    ->Temporary Internet Files folder emptied: 14520452 bytes
    ->Java cache emptied: 2027 bytes
    ->FireFox cache emptied: 16726325 bytes
    ->Flash cache emptied: 1406 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: eMule_Secure
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: LocalService
    ->Temp folder emptied: 66016 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Temp folder emptied: 11006 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Owner

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 902 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 30.00 mb


    [EMPTYFLASH]

    User: All Users

    User: David Peters
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: eMule_Secure

    User: LocalService
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Flash cache emptied: 0 bytes

    User: Owner

    Total Flash Files Cleaned = 0.00 mb


    [EMPTYJAVA]

    User: All Users

    User: David Peters
    ->Java cache emptied: 0 bytes

    User: Default User

    User: eMule_Secure

    User: LocalService
    ->Java cache emptied: 0 bytes

    User: NetworkService

    User: Owner

    Total Java Files Cleaned = 0.00 mb

    Restore points cleared and new OTL Restore Point set!

    OTL by OldTimer - Version 3.2.39.2 log created on 03312012_101949

    Files\Folders moved on Reboot...
    File\Folder C:\Documents and Settings\David Peters\Local Settings\Temp\Perflib_Perfdata_1524.dat not found!
    C:\Documents and Settings\David Peters\Local Settings\Temporary Internet Files\Content.IE5\YIE399PV\drts[1].htm moved successfully.
    C:\Documents and Settings\David Peters\Local Settings\Temporary Internet Files\Content.IE5\YIE399PV\xd_proxy[1].htm moved successfully.
    C:\Documents and Settings\David Peters\Local Settings\Temporary Internet Files\Content.IE5\WU5JWNWH\fastbutton[1].htm moved successfully.
    C:\Documents and Settings\David Peters\Local Settings\Temporary Internet Files\Content.IE5\V1MSAZR0\p-01-0VIaSjnOLg[1].gif moved successfully.
    C:\Documents and Settings\David Peters\Local Settings\Temporary Internet Files\Content.IE5\L5QOQF7Y\5174[1].htm moved successfully.
    C:\Documents and Settings\David Peters\Local Settings\Temporary Internet Files\Content.IE5\L5QOQF7Y\audmeasure[1].gif moved successfully.
    C:\Documents and Settings\David Peters\Local Settings\Temporary Internet Files\Content.IE5\L5QOQF7Y\L[1].htm moved successfully.
    C:\Documents and Settings\David Peters\Local Settings\Temporary Internet Files\Content.IE5\L5QOQF7Y\p-01-0VIaSjnOLg[1].gif moved successfully.
    C:\Documents and Settings\David Peters\Local Settings\Temporary Internet Files\Content.IE5\5EKV1LI7\like[1].htm moved successfully.
    C:\Documents and Settings\David Peters\Local Settings\Temporary Internet Files\Content.IE5\0IJDLDCB\102241-active-trojan-problem-2[1].html moved successfully.
    C:\Documents and Settings\David Peters\Local Settings\Temporary Internet Files\Content.IE5\0IJDLDCB\;ord=191592666[1].htm moved successfully.

    Registry entries deleted on Reboot...
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.