Spyware Warrior Spyware Warrior
Help with Spyware, Hijacking & Other Internet Nuisances
 
FAQ :: Search :: Memberlist :: Usergroups :: Register
Profile :: Log in to check your private messages :: Log in

Need help removing Smart HDD Malware

 
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Spyware Warrior Forum Index -> Archived Spyware Removal Help Topics
View previous topic :: View next topic  
Author Message
HerbCumbie
Junior Member


Joined: 13 Jan 2005
Last Visit: 14 Nov 2013
Posts: 49

PostPosted: Thu Aug 02, 2012 2:58 pm    Post subject: Need help removing Smart HDD Malware Reply with quote

This morning when I went to use my computer, which had been left on last night, I found multiple pop up dialogs that said "System error" in the dialog title bar and said "Hard disk failure detected" in the body of the dialog. I closed all the dialogs and found that most of my desktop icons/files were not visible. Checking my drives with Windows Explorer, it looked like all files were gone from all drives.

A quick google led me to the conclusion that I probably had the Smart HDD malware. I found the self-help page at bleepingcomputer and downloaded the rkill utility and malwarebytes. I also downloaded the tdsskiller tool.

The tdsskiller tool indicated a clean system.

The rkill utility runs and before completes the computer reboot spontaneously.

The malwarebytes installer runs, then there's an error dialog saying not authorized and it backs out of the install.

Here's the contents of the DDS.TXT file:


.
DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
Internet Explorer: 8.0.6001.18702
Run by Herb at 17:52:07 on 2012-08-02
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2303.2018 [GMT -5:00]
.
.
============== Running Processes ===============
.
C:\WINNT\system32\svchost -k DcomLaunch
svchost.exe
C:\WINNT\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINNT\Explorer.EXE
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uWindows: Load=c:\docume~1\herb\locals~1\temp\{69505~1.EXE
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: {32683183-48A0-441B-A342-7C2A440A9478} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\winnt\system32\ctfmon.exe
mRun: [Synchronization Manager] mobsync.exe /logon
mRun: [NVMixerTray] "c:\program files\nvidia corporation\nvmixer\NVMixerTray.exe"
mRun: [Share-to-Web Namespace Daemon] c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe
mRun: [Sunkist2k] c:\program files\ge\usb 2.0 card reader\shwicon2k.exe
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\winnt\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\winnt\system32\NvMcTray.dll,NvTaskbarInit
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [VMware hqtray] "c:\program files\vmware\vmware player\hqtray.exe"
mRun: [HDAudDeck] c:\program files\via\viaudioi\hdadeck\HDeck.exe 1
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [IEEhbDnrDIeqnkP.exe] c:\documents and settings\all users\application data\IEEhbDnrDIeqnkP.exe
dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: c:\program files\vmware\vmware player\vsocklib.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: Interfaces\{4DC6E9D5-4B66-4074-951C-479C3B15BDB9} : NameServer = 192.168.1.254
TCP: Interfaces\{528C1846-201D-40FA-9412-458CD0864393} : NameServer = 192.168.1.254
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\winnt\system32\WPDShServiceObj.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SI3112r;Silicon Image SiI 3112 SATARaid Controller;c:\winnt\system32\drivers\SI3112r.sys [2005-11-10 116264]
R3 usbfilter;AMD USB Filter Driver;c:\winnt\system32\drivers\usbfilter.sys [2011-2-23 30464]
S1 avkmgr;avkmgr;c:\winnt\system32\drivers\avkmgr.sys [2012-6-15 36000]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files\avira\antivir desktop\sched.exe [2012-6-15 86224]
S2 AntiVirService;Avira Realtime Protection;c:\program files\avira\antivir desktop\avguard.exe [2012-6-15 110032]
S2 avgntflt;avgntflt;c:\winnt\system32\drivers\avgntflt.sys [2012-6-15 83392]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-5-16 135664]
S2 vmci;VMware vmci;c:\winnt\system32\drivers\vmci.sys [2010-11-11 70768]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files\common files\vmware\usb\vmware-usbarbitrator.exe [2010-11-11 539248]
S3 01484335;01484335; [x]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\winnt\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-3-31 250056]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\winnt\system32\drivers\AtihdXP3.sys [2011-2-23 101904]
S3 dkab_device;dkab_device;c:\winnt\system32\dkabcoms.exe -service --> c:\winnt\system32\DKabcoms.exe -service [?]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\winnt\system32\DNINDIS5.sys [2007-5-15 17149]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-5-16 135664]
S3 sunkfilt62;USB 6/1 Driver;c:\winnt\system32\drivers\sunkfilt62.sys [2003-12-26 15460]
S3 usbhub20;USB Hub Support;c:\winnt\system32\drivers\usbhub20.sys [2005-10-13 49776]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\winnt\system32\drivers\viahduaa.sys [2011-2-27 2134256]
S3 WinRM;Windows Remote Management (WS-Management);c:\winnt\system32\svchost.exe -k WINRM [2008-4-14 14336]
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\winnt\system32\drivers\wpn111.sys --> c:\winnt\system32\drivers\WPN111.sys [?]
S4 Utilsiostna;Utilsiostna; [x]
.
=============== Created Last 30 ================
.
2012-08-02 17:31:54 711240 ----a-w- c:\winnt\is-MOL6L.exe
2012-08-02 17:11:32 711240 ----a-w- c:\winnt\is-FJS35.exe
2012-08-02 12:39:05 612518 ---ha-w- c:\winnt\system32\PerfStringBackup.TMP
2012-08-02 11:54:37 343552 ----a-w- c:\documents and settings\all users\application data\IEEhbDnrDIeqnkP.exe
2012-07-29 19:51:39 -------- d-----w- c:\program files\BigPrint
2012-07-25 02:35:11 -------- d-----w- c:\documents and settings\herb\application data\Woodgears.ca
.
==================== Find3M ====================
.
2012-07-26 21:29:18 70344 ---ha-w- c:\winnt\system32\FlashPlayerCPLApp.cpl
2012-07-26 21:29:18 426184 ---ha-w- c:\winnt\system32\FlashPlayerApp.exe
2012-07-03 18:46:44 22344 ----a-w- c:\winnt\system32\drivers\mbam.sys
2012-05-09 14:05:02 73728 ---ha-w- c:\winnt\system32\javacpl.cpl
2012-05-09 14:05:02 476960 ---ha-w- c:\winnt\system32\npdeployJava1.dll
2012-05-09 14:05:02 472864 ---ha-w- c:\winnt\system32\deployJava1.dll
.
============= FINISH: 17:53:26.29 ===============


Here's the dds ATTACH.TXT file contents:

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume4
Install Date: 5/15/2010 8:38:34 PM
System Uptime: 8/2/2012 5:49:35 PM (0 hours ago)
.
Motherboard: ASUSTeK Computer INC. | | M4A785-M
Processor: AMD Phenom(tm) 9750 Quad-Core Processor | AM2 | 2400/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 75 GiB total, 14.402 GiB free.
D: is FIXED (NTFS) - 928 GiB total, 873.297 GiB free.
E: is CDROM ()
F: is FIXED (NTFS) - 466 GiB total, 465.682 GiB free.
G: is Removable
Z: is FIXED (FAT32) - 4 GiB total, 0.899 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
Description: HID Non-User Input Data Filter (KB 911895)
Device ID: HID\VID_045E&PID_00F9&MI_01&COL01\8&2B7A3879&0&0000
Manufacturer: Microsoft
Name: HID Non-User Input Data Filter (KB 911895)
PNP Device ID: HID\VID_045E&PID_00F9&MI_01&COL01\8&2B7A3879&0&0000
Service: NuidFltr
.
Class GUID: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
Description: HID Non-User Input Data Filter (KB 911895)
Device ID: HID\VID_045E&PID_00F9&MI_01&COL03\8&2B7A3879&0&0002
Manufacturer: Microsoft
Name: HID Non-User Input Data Filter (KB 911895)
PNP Device ID: HID\VID_045E&PID_00F9&MI_01&COL03\8&2B7A3879&0&0002
Service: NuidFltr
.
Class GUID:
Description:
Device ID: ACPI\ATK0110\1010110
Manufacturer:
Name:
PNP Device ID: ACPI\ATK0110\1010110
Service:
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Photoshop 6.0
Adobe Photoshop CS
Adobe Reader X (10.1.1)
Adobe Shockwave Player 11.6
Amazon Kindle
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Install Manager
Avira Free Antivirus
Catalyst Control Center InstallProxy
Corel Graphics Suite 11
CutePDF Writer 2.8
Dell Software Uninstall
DesignPro 5.4 Limited Edition
Easy Thumbnails (Remove only)
EasyRecovery Professional
ERUNT 1.1j
Fine Woodworking Archive
GE USB 2.0 Card Reader
Google SketchUp 7
Google SketchUp 8
Google Toolbar for Internet Explorer
Google Update Helper
HiJackThis
Hotfix for MDAC 2.80 (KB911562)
Hotfix for MDAC 2.80 (KB927779)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB2570791)
Hotfix for Windows XP (KB2633952)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB959765)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB979306)
HP Memories Disc
HP Photo and Imaging 2.0 - Scanners
iTunes
Java Auto Updater
Java(TM) 6 Update 32
Logitech Harmony Remote Software
Macromedia Dreamweaver MX 2004
Macromedia Extension Manager
Macromedia Fireworks MX 2004
Macromedia Flash MX 2004
Macromedia FreeHand MXa
Malwarebytes' Anti-Malware
Memorex exPressit Label Design Studio
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2656353)
Microsoft .NET Framework 1.1 Security Update (KB971108)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft IntelliPoint 6.01
Microsoft IntelliType Pro 6.01
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Money 2006
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB954459)
MyTomTom 3.0.2.377
NVIDIA Drivers
NvMixer
Platform
QuickBooks Pro 2006
QuickTime
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft Windows (KB2564958)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2559049)
Security Update for Windows Internet Explorer 8 (KB2586448)
Security Update for Windows Internet Explorer 8 (KB2618444)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2124261)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2290570)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2491683)
Security Update for Windows XP (KB2503665)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2544893)
Security Update for Windows XP (KB2555917)
Security Update for Windows XP (KB2562937)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2567053)
Security Update for Windows XP (KB2567680)
Security Update for Windows XP (KB2570222)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2584146)
Security Update for Windows XP (KB2585542)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB2598479)
Security Update for Windows XP (KB2603381)
Security Update for Windows XP (KB2618451)
Security Update for Windows XP (KB2619339)
Security Update for Windows XP (KB2620712)
Security Update for Windows XP (KB2624667)
Security Update for Windows XP (KB2631813)
Security Update for Windows XP (KB2633171)
Security Update for Windows XP (KB2639417)
Security Update for Windows XP (KB2646524)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953155)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB970483)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975254)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB976323)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Shell Extensions 2.0.2
swMSM
tools-windows
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 8 (KB2447568)
Update for Windows Internet Explorer 8 (KB2598845)
Update for Windows Internet Explorer 8 (KB2632503)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows Internet Explorer 8 (KB980302)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2492386)
Update for Windows XP (KB2541763)
Update for Windows XP (KB2616676-v2)
Update for Windows XP (KB2641690)
Update for Windows XP (KB898461)
Update for Windows XP (KB943729)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VBA (2627.01)
VIA Platform Device Manager
Visual Studio C++ 10.0 Runtime
VMware Player
WebFldrs XP
Windows Defender Signatures
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage v1.3.0254.0
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Management Framework Core
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 9 Hotfix [See KB885492 for more information]
Windows PowerShell(TM) 1.0 MUI pack
WinZip
.
==== Event Viewer Messages From Past Week ========
.
8/2/2012 7:36:28 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the iPod Service service to connect.
8/2/2012 7:36:28 AM, error: Service Control Manager [7000] - The iPod Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/2/2012 7:36:28 AM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
8/2/2012 7:35:00 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the VMware Authorization Service service to connect.
8/2/2012 7:35:00 AM, error: Service Control Manager [7000] - The VMware Authorization Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/2/2012 7:34:06 AM, error: NETLOGON [5719] - No Domain Controller is available for domain BITS due to the following: There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
8/2/2012 7:34:05 AM, error: DCOM [10021] -
8/2/2012 7:34:01 AM, error: NetBT [4307] - Initialization failed because the transport refused to open initial Addresses.
8/2/2012 12:24:28 PM, error: NETLOGON [5776] - Failed to create/open file \system32\config\netlogon.ftl with the following error: Access is denied.
8/2/2012 12:03:58 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
8/2/2012 12:03:47 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AmdPPM avipbb avkmgr Fips ssmdrv
8/2/2012 12:03:47 PM, error: Service Control Manager [7001] - The World Wide Web Publishing service depends on the IIS Admin service which failed to start because of the following error: The dependency service or group failed to start.
8/2/2012 12:03:47 PM, error: Service Control Manager [7001] - The Simple Mail Transport Protocol (SMTP) service depends on the IIS Admin service which failed to start because of the following error: The dependency service or group failed to start.
8/2/2012 12:03:47 PM, error: Service Control Manager [7001] - The FTP Publishing service depends on the IIS Admin service which failed to start because of the following error: The dependency service or group failed to start.
8/2/2012 12:03:23 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
.
==== End Of File ===========================


Thanks in advance for your assistance.

Herb Cumbie
Back to top
View user's profile Send private message
Cypher
Moderator


Joined: 05 Jul 2009
Last Visit: 22 Apr 2014
Posts: 4560
Location: Land Of The Leprechauns

PostPosted: Fri Aug 03, 2012 9:17 am    Post subject: Reply with quote

Hi and welcome back to Spyware Warrior Forum.
My name is Cypher, and I will be helping you with your malware problems.
This may or may not, solve other issues you have with your machine.
If you no longer require help i would be grateful if you would let me know.

Before we start please note the following important guidelines.
  • If you don't know or understand something, please don't hesitate to ask.
  • Only post your problem at One help site. Applying fixes from multiple help sites can cause problems.
  • Only reply to this thread do not start another, Please continue responding until I give you the "All Clean"
    Remember, absence of symptoms does not mean the infection is all gone.
  • Please DO NOT run any other tools or scans whilst I am helping you.
  • Please DO NOT install any other software (or hardware) during the cleaning process.
  • Print each set of instructions... if possible...your Internet connection will not be available during some fix processes.
  • Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
  • Note: No Reply Within 3 Days Will Result In Your Topic Being Closed!
Note: If you haven't done so already, please read this topic Things to know before you post where the conditions for receiving help here are explained.
Quote:
Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Because of this, I advise you to backup any personal files and folders before you start



Download and Run ComboFix

  • Please download ComboFix from one of the following links.

    Link 1.

    Link 2.

    **IMPORTANT !!! Save ComboFix.exe to your Desktop**

  • Please disable any Antivirus or Firewall you have active, as shown in this topic. Please close all open application windows.
  • Double click on ComboFix.exe & follow the prompts
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply

A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper

_________________
Admin/Teacher at Malware Removal University
Member of...

Back to top
View user's profile Send private message
HerbCumbie
Junior Member


Joined: 13 Jan 2005
Last Visit: 14 Nov 2013
Posts: 49

PostPosted: Fri Aug 03, 2012 2:18 pm    Post subject: Reply with quote

Hello Cypher. Thanks for helping me solve this problem.

Backups done.

I tried to use normal mode to download and run ComboFix.exe but it was so tied up by the malware I couldn't do anything there.

I rebooted into Safe Mode with Networking. Downloaded ComboFix.exe to Desktop. Ran ComboFix.exe.

Here's the contents of the log file produced by ComboFix.exe:

ComboFix 12-07-31.06 - Herb 08/03/2012 17:18:40.2.4 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2303.1904 [GMT -5:00]
Running from: c:\documents and settings\Herb\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Application Data\AdobeDLM.log
c:\documents and settings\All Users\Application Data\IEEhbDnrDIeqnkP.exe
c:\documents and settings\All Users\Application Data\TEMP
c:\winnt\dasetup.log
c:\winnt\EventSystem.log
c:\winnt\system32\URTTemp
c:\winnt\system32\URTTemp\fusion.dll
c:\winnt\system32\URTTemp\mscoree.dll
c:\winnt\system32\URTTemp\mscoree.dll.local
c:\winnt\system32\URTTemp\mscorsn.dll
c:\winnt\system32\URTTemp\mscorwks.dll
c:\winnt\system32\URTTemp\msvcr71.dll
c:\winnt\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-07-03 to 2012-08-03 )))))))))))))))))))))))))))))))
.
.
2012-08-02 17:31 . 2012-08-02 17:31 711240 ----a-w- c:\winnt\is-MOL6L.exe
2012-08-02 17:11 . 2012-08-02 17:11 711240 ----a-w- c:\winnt\is-FJS35.exe
2012-08-02 12:39 . 2012-08-02 12:39 612518 ---ha-w- c:\winnt\system32\PerfStringBackup.TMP
2012-07-29 19:51 . 2012-07-29 19:51 -------- d-----w- c:\program files\BigPrint
2012-07-25 02:35 . 2012-07-25 02:35 -------- d--h--w- c:\documents and settings\Herb\Application Data\Woodgears.ca
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-26 21:29 . 2012-03-31 19:10 426184 ---ha-w- c:\winnt\system32\FlashPlayerApp.exe
2012-07-26 21:29 . 2011-06-28 23:14 70344 ---ha-w- c:\winnt\system32\FlashPlayerCPLApp.cpl
2012-07-03 18:46 . 2010-12-19 22:06 22344 ----a-w- c:\winnt\system32\drivers\mbam.sys
2012-05-09 14:05 . 2012-05-09 14:05 73728 ---ha-w- c:\winnt\system32\javacpl.cpl
2012-05-09 14:05 . 2012-05-09 14:05 476960 ---ha-w- c:\winnt\system32\npdeployJava1.dll
2012-05-09 14:05 . 2010-05-16 04:31 472864 ---ha-w- c:\winnt\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2010-12-20_13.22.30 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-07 06:19 . 2007-11-07 06:19 46592 c:\winnt\winsxs\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90kor.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 47104 c:\winnt\winsxs\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90jpn.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 59392 c:\winnt\winsxs\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90ita.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 60416 c:\winnt\winsxs\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90fra.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 59392 c:\winnt\winsxs\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90esp.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 59392 c:\winnt\winsxs\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90esn.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 54272 c:\winnt\winsxs\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90enu.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 60928 c:\winnt\winsxs\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90deu.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 41984 c:\winnt\winsxs\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90cht.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 41472 c:\winnt\winsxs\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90chs.dll
+ 2007-11-07 03:51 . 2007-11-07 03:51 59904 c:\winnt\winsxs\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_a173767a\mfcm90u.dll
+ 2007-11-07 03:51 . 2007-11-07 03:51 59904 c:\winnt\winsxs\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_a173767a\mfcm90.dll
+ 2006-12-02 06:08 . 2006-12-02 06:08 49152 c:\winnt\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
+ 2006-12-02 06:08 . 2006-12-02 06:08 49152 c:\winnt\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2006-12-02 06:08 . 2006-12-02 06:08 61440 c:\winnt\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2006-12-02 06:08 . 2006-12-02 06:08 61440 c:\winnt\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2006-12-02 06:08 . 2006-12-02 06:08 61440 c:\winnt\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2006-12-02 06:08 . 2006-12-02 06:08 57344 c:\winnt\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2006-12-02 06:08 . 2006-12-02 06:08 65536 c:\winnt\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2006-12-02 06:08 . 2006-12-02 06:08 45056 c:\winnt\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2006-12-02 06:08 . 2006-12-02 06:08 40960 c:\winnt\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2006-12-02 06:26 . 2006-12-02 06:26 57856 c:\winnt\winsxs\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
+ 2006-12-02 06:25 . 2006-12-02 06:25 69632 c:\winnt\winsxs\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
+ 2011-05-14 06:06 . 2011-05-14 06:06 57856 c:\winnt\winsxs\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80u.dll
+ 2011-05-14 06:23 . 2011-05-14 06:23 69632 c:\winnt\winsxs\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80.dll
+ 2011-05-13 23:37 . 2011-05-13 23:37 97280 c:\winnt\winsxs\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_a4c618fa\ATL80.dll
+ 2009-10-09 19:56 . 2009-10-09 19:56 14848 c:\winnt\system32\wsmprovhost.exe
+ 2009-10-09 19:56 . 2009-10-09 19:56 12288 c:\winnt\system32\wsmplpxy.dll
+ 2009-10-09 19:56 . 2009-10-09 19:56 12288 c:\winnt\system32\winrssrv.dll
+ 2009-10-09 19:56 . 2009-10-09 19:56 22528 c:\winnt\system32\winrshost.exe
+ 2009-10-09 21:22 . 2009-10-09 21:22 69632 c:\winnt\system32\winrs.exe
+ 2009-10-09 19:56 . 2009-10-09 19:56 25088 c:\winnt\system32\winrmprov.dll
+ 2010-05-16 02:24 . 2009-10-09 19:56 24064 c:\winnt\system32\windowspowershell\v1.0\pwrshsip.dll
- 2008-04-14 05:42 . 2008-04-14 10:42 23552 c:\winnt\system32\wdmaud.drv
+ 2008-04-14 05:42 . 2008-04-14 11:42 23552 c:\winnt\system32\wdmaud.drv
+ 2010-11-11 16:04 . 2010-11-11 16:04 59952 c:\winnt\system32\vnetinst.dll
+ 2010-11-11 19:29 . 2010-11-11 19:29 51312 c:\winnt\system32\vmnetbridge.dll
+ 2011-06-07 08:55 . 2008-04-14 10:42 53760 c:\winnt\system32\vfwwdm32.dll
+ 2011-02-20 04:03 . 2011-02-20 04:03 51024 c:\winnt\system32\vcomp100.dll
+ 2008-04-14 11:42 . 2011-11-08 13:46 46080 c:\winnt\system32\tzchange.exe
- 2008-04-14 11:42 . 2010-01-23 08:11 46080 c:\winnt\system32\tzchange.exe
+ 2008-04-14 11:42 . 2010-08-27 05:57 99840 c:\winnt\system32\srvsvc.dll
+ 2008-04-14 11:42 . 2010-08-17 13:17 58880 c:\winnt\system32\spoolsv.exe
- 2010-05-16 02:38 . 2008-07-08 13:02 17272 c:\winnt\system32\spmsg.dll
+ 2010-05-16 02:38 . 2010-07-05 13:15 17272 c:\winnt\system32\spmsg.dll
+ 2011-09-14 03:43 . 2011-09-14 03:43 37158 c:\winnt\system32\ShellExt\uninst.exe
+ 2011-02-23 17:09 . 2010-01-12 11:35 80416 c:\winnt\system32\RtNicProp32.dll
+ 2011-03-01 02:35 . 2001-11-10 06:01 24064 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\ativcoxx.dll
+ 2011-03-01 02:35 . 2010-11-10 16:25 17408 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\atitvo32.dll
+ 2011-03-01 02:35 . 2009-06-23 06:34 45056 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\ATIODCLI.exe
+ 2011-03-01 02:35 . 2010-11-10 16:18 64512 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\atimpc32.dll
+ 2011-03-01 02:35 . 2010-11-10 16:32 53248 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\ATIDDC.DLL
+ 2011-03-01 02:35 . 2010-11-10 17:08 57344 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\aticalrt.dll
+ 2011-03-01 02:35 . 2010-11-10 17:08 53248 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\aticalcl.dll
+ 2011-03-01 02:35 . 2010-11-10 16:35 26112 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\Ati2mdxx.exe
+ 2011-03-01 02:35 . 2010-11-10 16:17 53248 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\ati2erec.dll
+ 2011-03-01 02:35 . 2010-11-10 16:35 43520 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\ati2edxx.dll
+ 2011-03-01 02:31 . 2009-07-08 18:05 73728 c:\winnt\system32\ReinstallBackups\0009\DriverFiles\RtNicProp32.dll
+ 2011-03-01 02:15 . 2008-04-14 11:51 35840 c:\winnt\system32\ReinstallBackups\0008\DriverFiles\i386\processr.sys
+ 2009-10-09 21:22 . 2009-10-09 21:22 42496 c:\winnt\system32\pwrshplugin.dll
+ 2010-03-31 06:16 . 2010-03-31 06:16 99176 c:\winnt\system32\PresentationHostProxy.dll
+ 2001-05-08 12:00 . 2012-07-20 17:36 93476 c:\winnt\system32\perfc009.dat
+ 2008-04-14 11:42 . 2011-11-18 12:35 60416 c:\winnt\system32\packager.exe
+ 2001-08-23 13:00 . 2011-09-26 16:41 20480 c:\winnt\system32\oleaccrc.dll
- 2001-08-23 13:00 . 2009-10-08 19:56 20480 c:\winnt\system32\oleaccrc.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 49488 c:\winnt\system32\netfxperf.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 11600 c:\winnt\system32\mui\0409\mscorees.dll
- 2008-04-14 11:42 . 2009-03-08 09:31 66560 c:\winnt\system32\mshtmled.dll
+ 2008-04-14 11:42 . 2011-11-04 19:20 66560 c:\winnt\system32\mshtmled.dll
+ 2009-03-08 09:31 . 2011-11-04 19:20 55296 c:\winnt\system32\msfeedsbs.dll
- 2009-03-08 09:31 . 2010-02-25 06:24 55296 c:\winnt\system32\msfeedsbs.dll
+ 2011-02-20 04:03 . 2011-02-20 04:03 81744 c:\winnt\system32\mfcm100u.dll
+ 2011-02-20 04:03 . 2011-02-20 04:03 81744 c:\winnt\system32\mfcm100.dll
+ 2011-02-20 04:03 . 2011-02-20 04:03 60752 c:\winnt\system32\mfc100rus.dll
+ 2011-02-20 04:03 . 2011-02-20 04:03 43344 c:\winnt\system32\mfc100kor.dll
+ 2011-02-20 04:03 . 2011-02-20 04:03 43856 c:\winnt\system32\mfc100jpn.dll
+ 2011-02-20 04:03 . 2011-02-20 04:03 62288 c:\winnt\system32\mfc100ita.dll
+ 2011-02-20 04:03 . 2011-02-20 04:03 64336 c:\winnt\system32\mfc100fra.dll
+ 2011-02-20 04:03 . 2011-02-20 04:03 63824 c:\winnt\system32\mfc100esn.dll
+ 2011-02-20 04:03 . 2011-02-20 04:03 55120 c:\winnt\system32\mfc100enu.dll
+ 2011-02-20 04:03 . 2011-02-20 04:03 64336 c:\winnt\system32\mfc100deu.dll
+ 2011-02-20 04:03 . 2011-02-20 04:03 36176 c:\winnt\system32\mfc100cht.dll
+ 2011-02-20 04:03 . 2011-02-20 04:03 36176 c:\winnt\system32\mfc100chs.dll
- 2008-04-14 11:41 . 2008-04-14 11:41 23040 c:\winnt\system32\mciseq.dll
+ 2008-04-14 11:41 . 2011-10-14 14:47 23040 c:\winnt\system32\mciseq.dll
+ 2008-04-14 11:41 . 2011-11-04 19:20 43520 c:\winnt\system32\licmgr10.dll
- 2008-04-14 11:41 . 2010-02-25 06:24 25600 c:\winnt\system32\jsproxy.dll
+ 2008-04-14 11:41 . 2011-11-04 19:20 25600 c:\winnt\system32\jsproxy.dll
+ 2005-10-13 06:56 . 2010-11-18 18:12 81920 c:\winnt\system32\isign32.dll
- 2005-10-13 06:56 . 2008-04-14 11:41 81920 c:\winnt\system32\isign32.dll
+ 2008-04-14 11:41 . 2010-06-17 14:03 80384 c:\winnt\system32\iccvid.dll
- 2008-04-14 11:41 . 2008-04-14 11:41 80384 c:\winnt\system32\iccvid.dll
+ 2011-02-24 03:55 . 2010-04-29 23:43 30464 c:\winnt\system32\DRVSTORE\USBFilter_A596580098338E8556E41F4B9674C2783E1F08BB\x86\usbfilter.sys
+ 2011-02-24 03:54 . 2010-11-10 16:36 81690 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\oemdspif.dll
+ 2011-02-24 03:54 . 2001-11-10 06:01 12614 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\ativcoxx.dll
+ 2011-02-24 03:54 . 2010-08-28 09:32 81222 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\atiode.exe
+ 2011-02-24 03:54 . 2009-06-23 06:34 25130 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\atiodcli.exe
+ 2011-02-24 03:54 . 2010-11-10 16:18 41414 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\atimpc32.dll
+ 2011-02-24 03:54 . 2010-11-10 16:32 28699 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\atiddc.dll
+ 2011-02-24 03:54 . 2010-11-10 17:08 29988 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\aticalrt.dll
+ 2011-02-24 03:54 . 2010-11-10 17:08 29029 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\aticalcl.dll
+ 2011-02-24 03:54 . 2009-05-12 12:35 71662 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\atibtmon.exe
+ 2011-02-24 03:54 . 2010-11-10 16:31 55071 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\atiapfxx.exe
+ 2011-02-24 03:54 . 2010-11-10 16:35 16309 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\ati2mdxx.exe
+ 2011-02-24 03:54 . 2010-11-10 16:35 81572 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\ati2evxx.dll
+ 2011-02-24 03:54 . 2010-11-10 16:17 13650 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\ati2erec.dll
+ 2011-02-24 03:54 . 2010-11-10 16:35 28842 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\ati2edxx.dll
+ 2010-11-11 16:04 . 2010-11-11 16:04 31280 c:\winnt\system32\drivers\vmusb.sys
+ 2010-11-11 19:31 . 2010-11-11 19:31 23792 c:\winnt\system32\drivers\vmparport.sys
+ 2011-02-27 14:50 . 2010-11-11 19:29 26352 c:\winnt\system32\drivers\vmnetuserif.sys
+ 2010-11-11 19:29 . 2010-11-11 19:29 32752 c:\winnt\system32\drivers\vmnetbridge.sys
+ 2010-11-11 16:04 . 2010-11-11 16:04 16560 c:\winnt\system32\drivers\vmnetadapter.sys
+ 2010-11-11 16:04 . 2010-11-11 16:04 18736 c:\winnt\system32\drivers\vmnet.sys
+ 2011-02-27 14:49 . 2010-11-11 19:30 24688 c:\winnt\system32\drivers\VMkbd.sys
+ 2010-11-11 19:32 . 2010-11-11 19:32 70768 c:\winnt\system32\drivers\vmci.sys
+ 2011-02-24 03:55 . 2010-04-29 23:43 30464 c:\winnt\system32\drivers\usbfilter.sys
+ 2011-07-23 03:40 . 2008-04-14 05:26 12800 c:\winnt\system32\drivers\usb8023x.sys
+ 2008-04-14 00:15 . 2008-04-14 06:15 49408 c:\winnt\system32\drivers\stream.sys
- 2008-04-14 00:15 . 2008-04-14 05:15 49408 c:\winnt\system32\drivers\stream.sys
+ 2010-08-19 19:57 . 2010-08-19 19:57 64960 c:\winnt\system32\drivers\stcp2v30.sys
- 2009-06-06 15:35 . 2010-06-17 20:27 28520 c:\winnt\system32\drivers\ssmdrv.sys
+ 2012-06-16 00:50 . 2010-06-17 20:14 28520 c:\winnt\system32\drivers\ssmdrv.sys
+ 2011-07-23 03:37 . 2008-11-25 11:42 30592 c:\winnt\system32\drivers\rndismpx.sys
+ 2008-04-14 06:26 . 2008-11-25 11:42 30592 c:\winnt\system32\drivers\rndismp.sys
- 2008-04-14 06:26 . 2008-04-14 06:26 30592 c:\winnt\system32\drivers\rndismp.sys
+ 2008-04-14 06:27 . 2010-11-02 15:17 40960 c:\winnt\system32\drivers\ndproxy.sys
+ 2008-04-14 06:27 . 2011-07-08 14:02 10496 c:\winnt\system32\drivers\ndistapi.sys
+ 2010-11-11 18:31 . 2010-11-11 18:31 32368 c:\winnt\system32\drivers\hcmon.sys
+ 2008-04-14 00:15 . 2008-04-14 06:15 60160 c:\winnt\system32\drivers\drmk.sys
- 2008-04-14 00:15 . 2008-04-14 05:15 60160 c:\winnt\system32\drivers\drmk.sys
+ 2012-06-16 00:50 . 2012-04-17 02:18 36000 c:\winnt\system32\drivers\avkmgr.sys
+ 2012-06-16 00:50 . 2012-04-25 05:32 83392 c:\winnt\system32\drivers\avgntflt.sys
+ 2011-02-24 03:54 . 2011-01-27 04:12 53248 c:\winnt\system32\drivers\ati2erec.dll
+ 2007-04-17 03:46 . 2007-04-17 03:46 33792 c:\winnt\system32\drivers\AmdPPM.sys
+ 2012-01-21 08:32 . 2004-10-08 01:16 35840 c:\winnt\system32\drivers\AFS2K.SYS
+ 2008-04-14 11:41 . 2009-04-20 17:17 45568 c:\winnt\system32\dnsrslvr.dll
- 2008-04-14 11:41 . 2008-04-14 11:41 45568 c:\winnt\system32\dnsrslvr.dll
+ 2010-05-16 02:04 . 2011-11-04 19:20 12800 c:\winnt\system32\dllcache\xpshims.dll
- 2010-05-16 02:04 . 2010-02-25 06:24 12800 c:\winnt\system32\dllcache\xpshims.dll
+ 2008-04-14 05:42 . 2008-04-14 11:42 23552 c:\winnt\system32\dllcache\wdmaud.drv
+ 2003-03-03 21:57 . 2010-10-11 14:59 45568 c:\winnt\system32\dllcache\wab.exe
+ 2011-06-07 08:55 . 2008-04-14 10:42 53760 c:\winnt\system32\dllcache\vfwwdm32.dll
+ 2011-07-23 03:40 . 2008-04-14 05:26 12800 c:\winnt\system32\dllcache\usb8023x.sys
+ 2008-04-14 00:15 . 2008-04-14 06:15 49408 c:\winnt\system32\dllcache\stream.sys
- 2008-04-14 00:15 . 2008-04-14 05:15 49408 c:\winnt\system32\dllcache\stream.sys
+ 2008-04-14 11:42 . 2010-08-27 05:57 99840 c:\winnt\system32\dllcache\srvsvc.dll
+ 2008-04-14 11:42 . 2010-08-17 13:17 58880 c:\winnt\system32\dllcache\spoolsv.exe
+ 2011-04-14 03:48 . 2001-08-17 19:56 66048 c:\winnt\system32\dllcache\s3legacy.dll
+ 2011-07-23 03:37 . 2008-11-25 11:42 30592 c:\winnt\system32\dllcache\rndismpx.sys
+ 2008-04-14 06:26 . 2008-11-25 11:42 30592 c:\winnt\system32\dllcache\rndismp.sys
- 2008-04-14 06:26 . 2008-04-14 06:26 30592 c:\winnt\system32\dllcache\rndismp.sys
+ 2008-04-14 11:42 . 2011-11-18 12:35 60416 c:\winnt\system32\dllcache\packager.exe
+ 2001-08-23 13:00 . 2011-09-26 16:41 20480 c:\winnt\system32\dllcache\oleaccrc.dll
- 2001-08-23 13:00 . 2009-10-08 19:56 20480 c:\winnt\system32\dllcache\oleaccrc.dll
+ 2008-04-14 06:27 . 2010-11-02 15:17 40960 c:\winnt\system32\dllcache\ndproxy.sys
+ 2008-04-14 06:27 . 2011-07-08 14:02 10496 c:\winnt\system32\dllcache\ndistapi.sys
+ 2008-04-14 11:42 . 2011-11-04 19:20 66560 c:\winnt\system32\dllcache\mshtmled.dll
- 2008-04-14 11:42 . 2009-03-08 09:31 66560 c:\winnt\system32\dllcache\mshtmled.dll
+ 2010-05-16 02:04 . 2011-11-04 19:20 55296 c:\winnt\system32\dllcache\msfeedsbs.dll
- 2010-05-16 02:04 . 2010-02-25 06:24 55296 c:\winnt\system32\dllcache\msfeedsbs.dll
- 2008-04-14 11:41 . 2008-04-14 11:41 23040 c:\winnt\system32\dllcache\mciseq.dll
+ 2008-04-14 11:41 . 2011-10-14 14:47 23040 c:\winnt\system32\dllcache\mciseq.dll
+ 2008-04-14 11:41 . 2011-11-04 19:20 43520 c:\winnt\system32\dllcache\licmgr10.dll
- 2008-04-14 11:41 . 2010-02-25 06:24 25600 c:\winnt\system32\dllcache\jsproxy.dll
+ 2008-04-14 11:41 . 2011-11-04 19:20 25600 c:\winnt\system32\dllcache\jsproxy.dll
- 2005-10-13 06:56 . 2008-04-14 11:41 81920 c:\winnt\system32\dllcache\isign32.dll
+ 2005-10-13 06:56 . 2010-11-18 18:12 81920 c:\winnt\system32\dllcache\isign32.dll
+ 2008-04-14 00:15 . 2008-04-14 06:15 60160 c:\winnt\system32\dllcache\drmk.sys
- 2008-04-14 00:15 . 2008-04-14 05:15 60160 c:\winnt\system32\dllcache\drmk.sys
- 2008-04-14 11:41 . 2008-04-14 11:41 45568 c:\winnt\system32\dllcache\dnsrslvr.dll
+ 2008-04-14 11:41 . 2009-04-20 17:17 45568 c:\winnt\system32\dllcache\dnsrslvr.dll
+ 2008-04-14 11:41 . 2011-10-28 05:31 33280 c:\winnt\system32\dllcache\csrsrv.dll
- 2008-04-14 11:41 . 2009-12-14 07:08 33280 c:\winnt\system32\dllcache\csrsrv.dll
+ 2011-04-14 03:50 . 2008-04-14 03:04 36463 c:\winnt\system32\dllcache\ati1tuxx.sys
+ 2011-04-14 03:50 . 2008-04-14 03:04 21343 c:\winnt\system32\dllcache\ati1ttxx.sys
+ 2011-04-14 03:50 . 2008-04-14 03:04 26367 c:\winnt\system32\dllcache\ati1snxx.sys
+ 2011-04-14 03:50 . 2008-04-14 03:04 63663 c:\winnt\system32\dllcache\ati1rvxx.sys
+ 2011-04-14 03:50 . 2008-04-14 03:04 30671 c:\winnt\system32\dllcache\ati1raxx.sys
+ 2011-04-14 03:50 . 2008-04-14 03:04 12047 c:\winnt\system32\dllcache\ati1pdxx.sys
+ 2011-04-14 03:50 . 2008-04-14 03:04 11615 c:\winnt\system32\dllcache\ati1mdxx.sys
+ 2011-04-14 03:50 . 2008-04-14 03:04 56623 c:\winnt\system32\dllcache\ati1btxx.sys
+ 2011-04-14 03:50 . 2001-08-17 18:57 77568 c:\winnt\system32\dllcache\ati.sys
+ 2011-04-14 03:50 . 2001-08-17 19:55 96128 c:\winnt\system32\dllcache\ati.dll
+ 2008-04-14 06:10 . 2008-04-14 06:10 96512 c:\winnt\system32\dllcache\atapi.sys
+ 2008-04-14 11:41 . 2010-03-05 14:37 65536 c:\winnt\system32\dllcache\asycfilt.dll
+ 2011-04-14 03:50 . 2001-08-17 17:12 97354 c:\winnt\system32\dllcache\aspndis3.sys
+ 2011-04-14 03:49 . 2001-08-17 18:51 14848 c:\winnt\system32\dllcache\asc3550.sys
+ 2011-04-14 03:49 . 2001-08-17 18:52 22400 c:\winnt\system32\dllcache\asc3350p.sys
+ 2011-04-14 03:49 . 2001-08-17 18:52 26496 c:\winnt\system32\dllcache\asc.sys
+ 2008-04-14 00:21 . 2008-04-14 11:51 60800 c:\winnt\system32\dllcache\arp1394.sys
+ 2010-05-16 00:44 . 2008-04-14 03:05 36224 c:\winnt\system32\dllcache\an983.sys
+ 2011-04-14 03:49 . 2001-08-17 18:52 12032 c:\winnt\system32\dllcache\amsint.sys
+ 2008-04-14 00:01 . 2008-04-14 11:51 37760 c:\winnt\system32\dllcache\amdk7.sys
+ 2008-04-14 00:01 . 2008-04-14 11:51 37376 c:\winnt\system32\dllcache\amdk6.sys
+ 2008-04-14 00:06 . 2008-04-14 11:51 43008 c:\winnt\system32\dllcache\amdagp.sys
+ 2011-04-14 03:49 . 2001-08-17 17:11 16969 c:\winnt\system32\dllcache\amb8002.sys
+ 2008-04-14 00:06 . 2008-04-14 11:51 42752 c:\winnt\system32\dllcache\alim1541.sys
+ 2011-04-14 03:49 . 2001-08-17 18:49 26624 c:\winnt\system32\dllcache\alifir.sys
+ 2011-04-14 03:49 . 2001-08-17 17:11 27678 c:\winnt\system32\dllcache\ali5261.sys
+ 2011-04-14 03:49 . 2001-08-17 19:07 56960 c:\winnt\system32\dllcache\aic78xx.sys
+ 2011-04-14 03:49 . 2001-08-17 19:07 55168 c:\winnt\system32\dllcache\aic78u2.sys
+ 2011-04-14 03:49 . 2001-08-17 18:52 12800 c:\winnt\system32\dllcache\aha154x.sys
+ 2008-04-14 00:06 . 2008-04-14 11:51 44928 c:\winnt\system32\dllcache\agpcpq.sys
+ 2008-04-14 00:06 . 2008-04-14 11:51 42368 c:\winnt\system32\dllcache\agp440.sys
+ 2011-04-14 03:48 . 2001-08-17 17:11 46112 c:\winnt\system32\dllcache\adptsf50.sys
+ 2011-04-14 03:48 . 2008-04-14 03:06 10880 c:\winnt\system32\dllcache\admjoy.sys
+ 2011-04-14 03:48 . 2001-08-17 17:11 20160 c:\winnt\system32\dllcache\adm8511.sys
+ 2001-08-23 13:00 . 2001-08-23 13:00 11648 c:\winnt\system32\dllcache\acpiec.sys
+ 2011-04-14 03:48 . 2001-08-18 03:36 61440 c:\winnt\system32\dllcache\acerscad.dll
+ 2011-04-14 03:48 . 2008-04-14 03:06 84480 c:\winnt\system32\dllcache\ac97via.sys
+ 2011-04-14 03:48 . 2001-08-17 17:20 96256 c:\winnt\system32\dllcache\ac97intc.sys
+ 2011-04-14 03:48 . 2001-08-17 18:52 23552 c:\winnt\system32\dllcache\abp480n5.sys
+ 2011-04-14 03:48 . 2001-08-17 19:55 38400 c:\winnt\system32\dllcache\8514a.dll
+ 2011-04-14 03:48 . 2008-04-14 05:16 48128 c:\winnt\system32\dllcache\61883.sys
+ 2011-04-14 03:48 . 2008-04-14 05:10 12288 c:\winnt\system32\dllcache\4mmdat.sys
+ 2011-04-14 03:48 . 2001-08-17 19:06 11264 c:\winnt\system32\dllcache\1394vdbg.sys
+ 2008-04-14 06:16 . 2008-04-14 06:16 53376 c:\winnt\system32\dllcache\1394bus.sys
+ 2008-04-14 11:41 . 2011-10-28 05:31 33280 c:\winnt\system32\csrsrv.dll
- 2008-04-14 11:41 . 2009-12-14 07:08 33280 c:\winnt\system32\csrsrv.dll
+ 2011-04-30 23:36 . 2009-11-05 13:39 87552 c:\winnt\system32\cpwmon2k.dll
- 2010-05-16 01:38 . 2010-05-16 01:45 32768 c:\winnt\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2011-08-18 14:49 . 2012-03-31 22:08 32768 c:\winnt\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2010-05-16 01:38 . 2012-03-31 22:08 32768 c:\winnt\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2010-05-16 01:38 . 2010-05-16 01:45 32768 c:\winnt\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2011-08-18 14:49 . 2012-03-31 22:08 16384 c:\winnt\system32\config\systemprofile\Cookies\index.dat
- 2010-05-16 01:38 . 2010-05-16 01:45 16384 c:\winnt\system32\config\systemprofile\Cookies\index.dat
+ 2011-02-24 03:54 . 2001-11-09 22:01 24064 c:\winnt\system32\ativcoxx.dll
+ 2011-02-24 03:54 . 2011-01-27 04:21 17408 c:\winnt\system32\atitvo32.dll
+ 2011-02-24 03:54 . 2009-06-22 22:34 45056 c:\winnt\system32\ATIODCLI.exe
+ 2011-02-24 03:54 . 2011-01-27 04:13 64512 c:\winnt\system32\atimpc32.dll
+ 2011-02-24 03:54 . 2011-01-27 04:28 53248 c:\winnt\system32\ATIDDC.DLL
+ 2011-02-24 03:54 . 2011-01-27 05:01 57344 c:\winnt\system32\aticalrt.dll
+ 2011-02-24 03:54 . 2011-01-27 05:00 53248 c:\winnt\system32\aticalcl.dll
+ 2011-02-24 03:54 . 2011-01-27 04:31 26112 c:\winnt\system32\Ati2mdxx.exe
+ 2011-02-24 03:54 . 2011-01-27 04:31 43520 c:\winnt\system32\ati2edxx.dll
+ 2008-04-14 11:41 . 2010-03-05 14:37 65536 c:\winnt\system32\asycfilt.dll
+ 2011-02-24 03:54 . 2011-01-27 04:13 64512 c:\winnt\system32\amdpcom32.dll
+ 2009-06-06 15:45 . 2012-06-03 15:48 87952 c:\winnt\system32\Adobe\Shockwave 11\uninstaller.exe
+ 2012-04-26 13:05 . 2012-04-26 13:05 86016 c:\winnt\system32\Adobe\Shockwave 11\SwMenu.dll
+ 2012-04-26 12:50 . 2012-04-26 12:50 73408 c:\winnt\system32\Adobe\Shockwave 11\gtapi.dll
+ 2012-04-26 12:50 . 2012-04-26 12:50 64512 c:\winnt\system32\Adobe\Shockwave 11\gcapi_dll.dll
+ 2012-04-26 13:06 . 2012-04-26 13:06 12800 c:\winnt\system32\Adobe\Shockwave 11\DynaPlayer.dll
- 2008-07-30 00:16 . 2008-07-30 00:16 32768 c:\winnt\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
+ 2010-04-08 05:48 . 2010-04-08 05:48 32768 c:\winnt\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13648 c:\winnt\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
+ 2011-12-25 09:49 . 2011-12-25 09:49 31504 c:\winnt\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2011-12-25 17:07 . 2011-12-25 17:07 81920 c:\winnt\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2011-12-25 04:55 . 2011-12-25 04:55 77824 c:\winnt\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2008-05-28 05:49 . 2008-05-28 05:49 77824 c:\winnt\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2008-05-28 05:49 . 2008-05-28 05:49 86016 c:\winnt\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2011-12-25 04:55 . 2011-12-25 04:55 86016 c:\winnt\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2011-12-25 04:55 . 2011-12-25 04:55 81920 c:\winnt\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2008-05-28 05:49 . 2008-05-28 05:49 81920 c:\winnt\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2008-05-28 06:30 . 2008-05-28 06:30 32768 c:\winnt\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2011-12-25 05:49 . 2011-12-25 05:49 32768 c:\winnt\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2011-12-25 05:49 . 2011-12-25 05:49 24576 c:\winnt\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
- 2003-02-21 00:19 . 2003-02-21 00:19 24576 c:\winnt\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13648 c:\winnt\Microsoft.NET\Framework\SharedReg12.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13648 c:\winnt\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13648 c:\winnt\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13648 c:\winnt\Microsoft.NET\Framework\sbscmp10.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13664 c:\winnt\Microsoft.NET\Framework\sbs_wminet_utils.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13688 c:\winnt\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13664 c:\winnt\Microsoft.NET\Framework\sbs_system.data.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13696 c:\winnt\Microsoft.NET\Framework\sbs_system.configuration.install.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13656 c:\winnt\Microsoft.NET\Framework\sbs_mscorsec.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13656 c:\winnt\Microsoft.NET\Framework\sbs_mscorrc.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13656 c:\winnt\Microsoft.NET\Framework\sbs_mscordbi.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13672 c:\winnt\Microsoft.NET\Framework\sbs_microsoft.jscript.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13664 c:\winnt\Microsoft.NET\Framework\sbs_diasymreader.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 86864 c:\winnt\Microsoft.NET\Framework\NETFXSBS10.exe
+ 2011-02-27 15:07 . 2011-02-27 15:07 40448 c:\winnt\Installer\dfca6.msi
+ 2012-07-15 21:13 . 2012-07-15 21:13 22016 c:\winnt\Installer\404dc84.msi
+ 2011-02-24 03:53 . 2011-02-24 03:53 10134 c:\winnt\Installer\{FF5146A0-DA27-99A5-F533-682D2B5CBF16}\ARPPRODUCTICON.exe
+ 2011-02-24 03:55 . 2011-02-24 03:55 44758 c:\winnt\Installer\{B5675A93-9E49-42CA-A5A2-2FB77620FED3}\NewShortcut11_EAB9635D261D49BE88DDE71A7C809B2D.exe
+ 2011-02-24 03:53 . 2011-02-24 03:53 77542 c:\winnt\Installer\{9723C9FC-16E4-D329-6DFA-CAFDEEAA6043}\NewShortcut5_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2011-02-24 03:53 . 2011-02-24 03:53 77542 c:\winnt\Installer\{9723C9FC-16E4-D329-6DFA-CAFDEEAA6043}\NewShortcut4_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2011-02-24 03:53 . 2011-02-24 03:53 77542 c:\winnt\Installer\{9723C9FC-16E4-D329-6DFA-CAFDEEAA6043}\NewShortcut3_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2011-02-24 03:53 . 2011-02-24 03:53 77542 c:\winnt\Installer\{9723C9FC-16E4-D329-6DFA-CAFDEEAA6043}\NewShortcut2_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2011-02-24 03:53 . 2011-02-24 03:53 77542 c:\winnt\Installer\{9723C9FC-16E4-D329-6DFA-CAFDEEAA6043}\ARPPRODUCTICON.exe
+ 2005-10-14 00:34 . 2011-09-22 18:26 23040 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2005-10-14 00:34 . 2010-12-18 19:32 23040 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2005-10-14 00:34 . 2010-12-18 19:32 61440 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2005-10-14 00:34 . 2011-09-22 18:26 61440 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2005-10-14 00:34 . 2010-12-18 19:32 27136 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2005-10-14 00:34 . 2011-09-22 18:26 27136 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2005-10-14 00:34 . 2011-09-22 18:26 11264 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2005-10-14 00:34 . 2010-12-18 19:32 11264 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2005-10-14 00:34 . 2010-12-18 19:32 86016 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2005-10-14 00:34 . 2011-09-22 18:26 86016 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2005-10-14 00:34 . 2010-12-18 19:32 12288 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2005-10-14 00:34 . 2011-09-22 18:26 12288 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2005-11-12 02:00 . 2012-01-21 08:31 45056 c:\winnt\Installer\{6CC93102-135E-49E2-99A4-C431E671C12A}\_486AD40031E5_4A05_BAE5_67FC693FE0EF.exe
- 2005-11-12 02:00 . 2005-11-12 02:00 45056 c:\winnt\Installer\{6CC93102-135E-49E2-99A4-C431E671C12A}\_486AD40031E5_4A05_BAE5_67FC693FE0EF.exe
+ 2012-06-03 15:48 . 2012-06-03 15:48 10134 c:\winnt\Installer\{612C34C7-5E90-47D8-9B5C-0F717DD82726}\ARPPRODUCTICON.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 17304 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\ViewerPS.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 35736 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\reader_sl.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 88992 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\PDFPrevHndlr.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 94608 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\eula.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 49064 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acrotextextractor.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 17824 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32Info.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 63912 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acroiehelpershim.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 64928 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroIEHelper.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 63384 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\Acrofx32.dll
+ 2012-01-21 09:07 . 2011-08-22 23:48 12800 c:\winnt\ie8updates\KB2618444-IE8\xpshims.dll
+ 2012-01-21 09:07 . 2011-08-22 23:48 66560 c:\winnt\ie8updates\KB2618444-IE8\mshtmled.dll
+ 2012-01-21 09:07 . 2011-08-22 23:48 55296 c:\winnt\ie8updates\KB2618444-IE8\msfeedsbs.dll
+ 2012-01-21 09:07 . 2011-08-22 23:48 43520 c:\winnt\ie8updates\KB2618444-IE8\licmgr10.dll
+ 2012-01-21 09:07 . 2011-08-22 23:48 25600 c:\winnt\ie8updates\KB2618444-IE8\jsproxy.dll
+ 2011-10-27 06:16 . 2011-06-23 18:36 12800 c:\winnt\ie8updates\KB2586448-IE8\xpshims.dll
+ 2011-10-27 06:16 . 2011-06-23 18:36 66560 c:\winnt\ie8updates\KB2586448-IE8\mshtmled.dll
+ 2011-10-27 06:16 . 2011-06-23 18:36 55296 c:\winnt\ie8updates\KB2586448-IE8\msfeedsbs.dll
+ 2011-10-27 06:16 . 2011-06-23 18:36 43520 c:\winnt\ie8updates\KB2586448-IE8\licmgr10.dll
+ 2011-10-27 06:16 . 2011-06-23 18:36 25600 c:\winnt\ie8updates\KB2586448-IE8\jsproxy.dll
+ 2011-09-08 03:20 . 2010-12-20 23:59 12800 c:\winnt\ie8updates\KB2559049-IE8\xpshims.dll
+ 2011-09-08 03:20 . 2010-12-20 23:59 66560 c:\winnt\ie8updates\KB2559049-IE8\mshtmled.dll
+ 2011-09-08 03:20 . 2010-12-20 23:59 55296 c:\winnt\ie8updates\KB2559049-IE8\msfeedsbs.dll
+ 2011-09-08 03:20 . 2010-12-20 23:59 43520 c:\winnt\ie8updates\KB2559049-IE8\licmgr10.dll
+ 2011-09-08 03:20 . 2010-12-20 23:59 25600 c:\winnt\ie8updates\KB2559049-IE8\jsproxy.dll
+ 2011-03-01 02:32 . 2010-02-25 06:24 12800 c:\winnt\ie8updates\KB2482017-IE8\xpshims.dll
+ 2011-03-01 02:32 . 2009-03-08 09:31 66560 c:\winnt\ie8updates\KB2482017-IE8\mshtmled.dll
+ 2011-03-01 02:32 . 2010-02-25 06:24 55296 c:\winnt\ie8updates\KB2482017-IE8\msfeedsbs.dll
+ 2011-03-01 02:32 . 2009-03-08 09:34 43008 c:\winnt\ie8updates\KB2482017-IE8\licmgr10.dll
+ 2011-03-01 02:32 . 2010-02-25 06:24 25600 c:\winnt\ie8updates\KB2482017-IE8\jsproxy.dll
+ 2011-09-08 03:15 . 2010-02-16 04:50 64000 c:\winnt\ie8updates\KB2447568-IE8\iecompat.dll
+ 2011-07-23 03:37 . 2008-11-25 11:42 30592 c:\winnt\Driver Cache\i386\rndismpx.sys
+ 2012-01-21 09:09 . 2012-01-21 09:09 90112 c:\winnt\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_259dba36\System.Drawing.Design.dll
+ 2012-01-21 09:09 . 2012-01-21 09:09 61440 c:\winnt\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_ea57a84c\CustomMarshalers.dll
+ 2011-10-27 06:16 . 2011-10-27 06:16 60928 c:\winnt\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\888b745ca99d39692c2e9af222e5eae8\UIAutomationProvider.ni.dll
+ 2011-10-27 06:59 . 2011-10-27 06:59 37888 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\6c334564da041df8fb75415f2d503224\System.Windows.Presentation.ni.dll
+ 2012-01-21 09:19 . 2012-01-21 09:19 36864 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\750de53f30e516eb2c62de9bab7954e9\System.Web.DynamicData.Design.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 94208 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\ac92806d5bd508eb25f1b4b73a36b101\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 82944 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\e6a9cd66d11a21776dbf425e8e28099c\System.AddIn.Contract.ni.dll
+ 2011-10-27 06:14 . 2011-10-27 06:14 47104 c:\winnt\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\66873b557d5c7013e4c630361473b0c2\PresentationFontCache.ni.exe
+ 2011-10-27 06:14 . 2011-10-27 06:14 39424 c:\winnt\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5b30652a7b802199984f93b5e414260f\PresentationCFFRasterizer.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 17920 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Run#\a615508098c5f4f5a34e89d22527c9de\Microsoft.WSMan.Runtime.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 21504 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Man#\6fe0ec64be50db1d60d4b6f1ef914215\Microsoft.WSMan.Management.resources.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 55296 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\eaa8d72317e5b8047e413939cc71ffba\Microsoft.Vsa.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 18944 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\fed28cbcdce16c91e2e45676d13b2e19\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 18944 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\fbbbd3bdef6dae16400b70a2f2ad3720\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 35840 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\fa0a536812625ab69e52071f06282f55\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 18432 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\f336ce6e2c551ae93c93f92cf60677bb\Microsoft.PowerShell.Commands.Diagnostics.resources.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 18944 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\ee61c0b8b6b4ad84f3b167b76d8eadb8\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 33280 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\e7c491ceef9613fd6a6adf0b1c1d9ceb\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 19456 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\e60fcb2bfc1086f8dc41584fd2a372cb\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 16896 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\d93cbfcaa668b2b53db534f12ffd362f\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 20992 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\d88da99ecfa388475f402d8e531a67f2\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 36352 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\d66515e04af07be267ca1d1b2b9a1113\Microsoft.PowerShell.GPowerShell.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 45568 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\caec9a9b0ae96df2e324cde6ebcac3e7\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 18432 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\c730db3ee09d7981f9389626c9f14196\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 67072 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\c44cda92e7a0bc4224cb54409aab05f1\Microsoft.PowerShell.Editor.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 30720 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\c1aeb2b76cbafba6515e605b42818a2b\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 30208 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\af2b666789ee8dafa48411236380b730\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 37888 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\aabcc06945dd92c9baeba7c60d381652\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 17920 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\a5c9565f5198a2eb163b4117351755ad\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 31232 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\a040a0716f7566df89a03a147065e7b6\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 28672 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\9e38543d4e7345dc15d59b71c17c322d\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 35840 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\9c8515f8b9e6bac9dca2f752d88bbce6\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 32768 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\8ce19ce94ecab823290e19ab3e7da464\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 19456 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\89d6c6128671e8184aede3b6d8f0fe5c\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 16896 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\7f36ec4601c3b1fcd4198c5aaf3a7b9d\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 16384 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\79df6578b47a615deb987fa09557d870\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 16896 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\7891b4f8446137c93298b36129ee43b4\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 38912 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\73e9eadf2fc234ff59c7297a4a96982b\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 36352 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\72485e06a75e141b0f9d150eaa95fa71\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 36864 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\6e4e01708d885d1f373d52ee694ca0d0\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 36352 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\6d894a74b5252b9e3441c342dfe7b361\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 33792 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\6d3f35d5f4167211ac5fd12cd3d0c50f\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 16384 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\6c26e841c995c8157de38be37f6a62b5\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 18944 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\65af934af23cc59112d080722d9377a9\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 24576 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\65632f4fe9504960d242e8a7e88be8f5\Microsoft.PowerShell.GraphicalHost.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 15872 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\653eba17530d34173df679a78a2e51e1\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 30720 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\522e06dbf6d24654d1101ba9f8092be1\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 16384 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\508bf6c415f98c24c68ca3d5e77afc58\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 31232 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\5031864f32f6f5bf3077eeda8d002dab\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 28672 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\3a2db624a31e527f25e1d20c69bb5e60\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 31744 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\384f30e8714277e4c61af987d2e2e017\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 17920 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\33d29a0607ec489564ca6b69e395d34e\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 37376 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\2dc1acb700ab59b1a41aa7604f44fa41\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 15872 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\29fc15ce93165af62488c27b3ae50241\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 16384 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\254d61afea8c61a334950ee39eb3065c\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 45568 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\11238f751fe2a04f80448c83041c70d7\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 39936 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\0d4d57c7ed48fa23070836319f7f2f99\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 31232 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\065ac03dc714efba4ef493719f59eea1\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 16896 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\0235131ec8d6cfca14d7e2197167e50e\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 18944 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\00d4a310524a80140fa4b1e05a4156e2\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 74752 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\aefe683674c97a998f4e908c1a7ee7c6\Microsoft.Build.Framework.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 65024 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\845eef4d09f28da6ee05d99f93c90f6e\Microsoft.Build.Framework.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 14848 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.Backgroun#\f667da1d215cd7d804c2e57a16aeb5e1\Microsoft.BackgroundIntelligentTransfer.Management.resources.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 91648 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.Backgroun#\17fc30ccabf04ef1cf60a571067bc6dc\Microsoft.BackgroundIntelligentTransfer.Management.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 14336 c:\winnt\assembly\NativeImages_v2.0.50727_32\dfsvc\ab7ce2d94ca725c3889a4e3c1ee88ece\dfsvc.ni.exe
+ 2011-10-27 06:17 . 2011-10-27 06:17 25600 c:\winnt\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 77824 c:\winnt\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 77824 c:\winnt\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-03-01 02:18 . 2011-03-01 02:18 32768 c:\winnt\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
- 2010-05-16 03:18 . 2010-05-16 03:18 32768 c:\winnt\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 81920 c:\winnt\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 81920 c:\winnt\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 81920 c:\winnt\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 81920 c:\winnt\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 13824 c:\winnt\assembly\GAC_MSIL\Microsoft.WSMan.Management.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 32768 c:\winnt\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 32768 c:\winnt\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 12800 c:\winnt\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 12800 c:\winnt\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 28672 c:\winnt\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 28672 c:\winnt\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 69632 c:\winnt\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 16896 c:\winnt\assembly\GAC_MSIL\Microsoft.PowerShell.GraphicalHost.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.GraphicalHost.resources.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 40960 c:\winnt\assembly\GAC_MSIL\Microsoft.PowerShell.GPowerShell.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.GPowerShell.resources.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 69632 c:\winnt\assembly\GAC_MSIL\Microsoft.PowerShell.Editor.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Editor.resources.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 40960 c:\winnt\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.resources.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 49152 c:\winnt\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.resources.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 36864 c:\winnt\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.resources.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 10752 c:\winnt\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.resources.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 77824 c:\winnt\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 77824 c:\winnt\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 36864 c:\winnt\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 36864 c:\winnt\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 57344 c:\winnt\assembly\GAC_MSIL\Microsoft.BackgroundIntelligentTransfer.Management\1.0.0.0__31bf3856ad364e35\Microsoft.BackgroundIntelligentTransfer.Management.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 77824 c:\winnt\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 77824 c:\winnt\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 13312 c:\winnt\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 13312 c:\winnt\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 10752 c:\winnt\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 10752 c:\winnt\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 72192 c:\winnt\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 72192 c:\winnt\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 69120 c:\winnt\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 69120 c:\winnt\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-01-21 09:09 . 2012-01-21 09:09 81920 c:\winnt\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 8192 c:\winnt\winsxs\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 8192 c:\winnt\winsxs\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2010-05-16 02:25 . 2011-02-17 12:32 5120 c:\winnt\system32\xpsp4res.dll
+ 2009-10-09 19:56 . 2009-10-09 19:56 2048 c:\winnt\system32\winrsmgr.dll
- 2010-05-16 02:24 . 2007-06-30 18:49 4608 c:\winnt\system32\windowspowershell\v1.0\pwrshmsg.dll
+ 2010-05-16 02:24 . 2009-10-09 21:23 4608 c:\winnt\system32\windowspowershell\v1.0\pwrshmsg.dll
+ 2009-10-09 21:23 . 2009-10-09 21:23 4096 c:\winnt\system32\windowspowershell\v1.0\powershell_ise.resources.dll
+ 2005-10-28 22:42 . 2008-04-14 11:41 4096 c:\winnt\system32\ksuser.dll
- 2005-10-28 22:42 . 2008-04-14 10:41 4096 c:\winnt\system32\ksuser.dll
+ 2011-02-24 03:54 . 2010-11-10 16:25 8348 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\atitvo32.dll
+ 2011-02-23 16:42 . 2008-04-14 06:06 8832 c:\winnt\system32\drivers\wmiacpi.sys
+ 2011-02-23 16:42 . 2008-04-14 06:06 8832 c:\winnt\system32\dllcache\wmiacpi.sys
+ 2005-10-28 22:42 . 2008-04-14 11:41 4096 c:\winnt\system32\dllcache\ksuser.dll
+ 2010-05-16 02:04 . 2011-08-16 10:45 6144 c:\winnt\system32\dllcache\iecompat.dll
+ 2011-04-14 03:49 . 2001-08-17 18:47 6272 c:\winnt\system32\dllcache\apmbatt.sys
+ 2011-04-14 03:49 . 2001-08-17 18:51 5248 c:\winnt\system32\dllcache\aliide.sys
+ 2011-04-14 03:48 . 2008-04-14 10:41 3775 c:\winnt\system32\dllcache\adv11nt5.dll
+ 2011-04-14 03:48 . 2008-04-14 10:41 3711 c:\winnt\system32\dllcache\adv09nt5.dll
+ 2011-04-14 03:48 . 2008-04-14 10:41 3135 c:\winnt\system32\dllcache\adv08nt5.dll
+ 2011-04-14 03:48 . 2008-04-14 10:41 3647 c:\winnt\system32\dllcache\adv07nt5.dll
+ 2011-04-14 03:48 . 2008-04-14 10:41 3615 c:\winnt\system32\dllcache\adv05nt5.dll
+ 2011-04-14 03:48 . 2008-04-14 10:41 3967 c:\winnt\system32\dllcache\adv02nt5.dll
+ 2011-04-14 03:48 . 2008-04-14 10:41 4255 c:\winnt\system32\dllcache\adv01nt5.dll
+ 2011-04-14 03:48 . 2001-08-17 18:53 7424 c:\winnt\system32\dllcache\adicvls.sys
+ 2010-12-15 14:12 . 2012-08-02 11:52 1984 c:\winnt\system32\d3d9caps.dat
+ 2012-01-21 08:32 . 2012-01-21 08:32 4150 c:\winnt\Installer\{B376402D-58EA-45EA-BD50-DD924EB67A70}\hpmd.exe
+ 2005-10-14 00:34 . 2011-09-22 18:26 4096 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2005-10-14 00:34 . 2010-12-18 19:32 4096 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2011-10-27 06:16 . 2010-10-18 11:10 7680 c:\winnt\ie8updates\KB2598845-IE8\iecompat.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 7168 c:\winnt\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 7168 c:\winnt\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 7168 c:\winnt\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 5632 c:\winnt\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2010-05-16 04:06 . 2010-05-16 04:06 5632 c:\winnt\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 9216 c:\winnt\assembly\GAC_MSIL\Microsoft.PowerShell.Security.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Security.resources.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 7168 c:\winnt\assembly\GAC_MSIL\Microsoft.BackgroundIntelligentTransfer.Management.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.BackgroundIntelligentTransfer.Management.resources.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 6656 c:\winnt\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 6656 c:\winnt\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 8192 c:\winnt\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 8192 c:\winnt\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 113664 c:\winnt\winsxs\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 113664 c:\winnt\winsxs\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 258048 c:\winnt\winsxs\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 258048 c:\winnt\winsxs\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 161784 c:\winnt\winsxs\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_312cf0e9\atl90.dll
- 2006-12-02 03:54 . 2006-12-02 03:54 626688 c:\winnt\winsxs\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
+ 2006-12-02 04:54 . 2006-12-02 04:54 626688 c:\winnt\winsxs\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
+ 2006-12-02 04:54 . 2006-12-02 04:54 548864 c:\winnt\winsxs\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
- 2006-12-02 03:54 . 2006-12-02 03:54 548864 c:\winnt\winsxs\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
- 2006-12-02 03:54 . 2006-12-02 03:54 479232 c:\winnt\winsxs\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-02 04:54 . 2006-12-02 04:54 479232 c:\winnt\wi
Back to top
View user's profile Send private message
HerbCumbie
Junior Member


Joined: 13 Jan 2005
Last Visit: 14 Nov 2013
Posts: 49

PostPosted: Fri Aug 03, 2012 2:25 pm    Post subject: Reply with quote

File got truncated during upload. Here's more:

+ 2006-12-02 04:54 . 2006-12-02 04:54 479232 c:\winnt\winsxs\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2011-05-14 06:17 . 2011-05-14 06:17 632656 c:\winnt\winsxs\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll
+ 2011-05-14 06:12 . 2011-05-14 06:12 554832 c:\winnt\winsxs\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcp80.dll
+ 2011-05-14 06:11 . 2011-05-14 06:11 479232 c:\winnt\winsxs\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcm80.dll
+ 2009-10-09 19:56 . 2009-10-09 19:56 209408 c:\winnt\system32\WsmWmiPl.dll
+ 2009-10-09 21:22 . 2009-10-09 21:22 368640 c:\winnt\system32\WsmRes.dll
+ 2009-10-09 19:56 . 2009-10-09 19:56 139776 c:\winnt\system32\WsmAuto.dll
+ 2009-10-09 19:56 . 2009-10-09 19:56 225280 c:\winnt\system32\wsmanhttpconfig.exe
- 2008-04-14 11:42 . 2008-04-14 11:42 293376 c:\winnt\system32\winsrv.dll
+ 2008-04-14 11:42 . 2011-11-25 21:57 293376 c:\winnt\system32\winsrv.dll
+ 2009-10-09 19:56 . 2009-10-09 19:56 233984 c:\winnt\system32\winrscmd.dll
+ 2009-08-01 04:27 . 2009-08-01 04:27 201184 c:\winnt\system32\winrm.vbs
+ 2008-04-14 11:42 . 2011-10-14 14:47 176128 c:\winnt\system32\winmm.dll
- 2008-04-14 11:42 . 2008-04-14 11:42 176128 c:\winnt\system32\winmm.dll
+ 2008-04-14 11:42 . 2011-11-04 19:20 916992 c:\winnt\system32\wininet.dll
+ 2008-04-14 11:42 . 2011-11-16 14:21 354816 c:\winnt\system32\winhttp.dll
- 2008-04-14 11:42 . 2009-08-25 09:17 354816 c:\winnt\system32\winhttp.dll
+ 2009-10-09 21:23 . 2009-10-09 21:23 148480 c:\winnt\system32\windowspowershell\v1.0\pspluginwkr.dll
+ 2009-10-09 19:57 . 2009-10-09 19:57 204800 c:\winnt\system32\windowspowershell\v1.0\powershell_ise.exe
+ 2010-05-16 02:24 . 2009-10-09 19:56 448000 c:\winnt\system32\windowspowershell\v1.0\powershell.exe
+ 2009-10-09 19:57 . 2009-10-09 19:57 112640 c:\winnt\system32\windowspowershell\v1.0\Modules\BitsTransfer\microsoft.backgroundintelligenttransfer.management.interop.dll
+ 2009-07-16 15:22 . 2009-07-16 15:22 126976 c:\winnt\system32\windowspowershell\v1.0\CompiledComposition.Microsoft.PowerShell.GPowerShell.dll
+ 2009-10-09 21:23 . 2009-10-09 21:23 178176 c:\winnt\system32\wevtfwd.dll
+ 2011-02-27 14:50 . 2010-11-11 19:31 760432 c:\winnt\system32\vnetlib.dll
+ 2011-02-27 14:50 . 2010-11-11 19:31 334448 c:\winnt\system32\vmnetdhcp.exe
+ 2010-11-11 18:04 . 2010-11-11 18:04 252528 c:\winnt\system32\vmnc.dll
+ 2011-02-27 14:50 . 2010-11-11 19:31 404080 c:\winnt\system32\vmnat.exe
+ 2008-04-14 11:42 . 2011-03-04 06:37 420864 c:\winnt\system32\vbscript.dll
- 2008-04-14 11:42 . 2008-04-14 11:42 406016 c:\winnt\system32\usp10.dll
+ 2008-04-14 11:42 . 2010-04-16 15:36 406016 c:\winnt\system32\usp10.dll
+ 2008-04-14 11:42 . 2011-11-04 19:20 105984 c:\winnt\system32\url.dll
- 2008-04-14 11:42 . 2009-03-08 09:34 105984 c:\winnt\system32\url.dll
+ 2009-10-08 19:57 . 2011-09-26 16:41 611328 c:\winnt\system32\uiautomationcore.dll
- 2009-10-08 19:57 . 2009-10-08 19:57 611328 c:\winnt\system32\uiautomationcore.dll
- 2008-04-14 11:42 . 2009-10-15 16:28 119808 c:\winnt\system32\t2embed.dll
+ 2008-04-14 11:42 . 2010-08-27 08:02 119808 c:\winnt\system32\t2embed.dll
+ 2011-04-30 23:36 . 2006-11-02 09:46 543232 c:\winnt\system32\spool\drivers\w32x86\PSCRIPT5.DLL
+ 2011-04-30 23:36 . 2006-11-02 09:46 728576 c:\winnt\system32\spool\drivers\w32x86\PS5UI.DLL
+ 2005-11-16 20:09 . 2006-11-02 09:46 543232 c:\winnt\system32\spool\drivers\w32x86\3\PSCRIPT5.DLL
+ 2005-11-16 20:09 . 2006-11-02 09:46 728576 c:\winnt\system32\spool\drivers\w32x86\3\PS5UI.DLL
- 2008-04-14 11:42 . 2008-04-14 11:42 135168 c:\winnt\system32\shsvcs.dll
+ 2008-04-14 11:42 . 2009-07-27 23:17 135168 c:\winnt\system32\shsvcs.dll
+ 2008-04-14 11:42 . 2011-01-21 14:44 439296 c:\winnt\system32\shimgvw.dll
+ 2006-08-15 13:34 . 2006-08-15 13:34 135168 c:\winnt\system32\ShellExt\METouch.dll
+ 2008-04-14 11:42 . 2011-11-16 14:21 152064 c:\winnt\system32\schannel.dll
- 2008-04-14 11:42 . 2008-04-14 11:42 270848 c:\winnt\system32\sbe.dll
+ 2008-04-14 11:42 . 2011-02-09 13:53 270848 c:\winnt\system32\sbe.dll
+ 2010-01-12 11:35 . 2010-01-12 11:35 100896 c:\winnt\system32\RTNUninst32.dll
+ 2008-04-14 11:42 . 2010-08-16 08:45 590848 c:\winnt\system32\rpcrt4.dll
+ 2011-03-01 02:35 . 2010-11-10 16:36 155648 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\Oemdspif.dll
+ 2011-03-01 02:35 . 2010-11-10 16:33 887724 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\ativva6x.dat
+ 2011-03-01 02:35 . 2010-11-10 16:36 212992 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\atipdlxx.dll
+ 2011-03-01 02:35 . 2010-11-10 16:34 393216 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\atiok3x2.dll
+ 2011-03-01 02:35 . 2010-08-28 09:32 294912 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\ATIODE.exe
+ 2011-03-01 02:35 . 2010-11-10 16:28 651264 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\atikvmag.dll
+ 2011-03-01 02:35 . 2010-11-10 17:01 311296 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\atiiiexx.dll
+ 2011-03-01 02:35 . 2010-09-23 09:27 223990 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\atiicdxx.dat
+ 2011-03-01 02:35 . 2010-11-10 16:56 450560 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\ATIDEMGX.dll
+ 2011-03-01 02:35 . 2009-05-12 12:35 118784 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\atibtmon.exe
+ 2011-03-01 02:35 . 2010-11-10 16:31 143360 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\atiapfxx.exe
+ 2011-03-01 02:35 . 2010-11-10 16:26 196608 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\atiadlxx.dll
+ 2011-03-01 02:35 . 2010-11-10 16:34 614400 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\ati2evxx.exe
+ 2011-03-01 02:35 . 2010-11-10 16:35 159744 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\ati2evxx.dll
+ 2011-03-01 02:35 . 2010-11-10 16:55 301056 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\ati2dvag.dll
+ 2011-03-01 02:35 . 2010-11-10 16:20 704512 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\ati2cqag.dll
+ 2011-03-01 02:31 . 2009-07-28 22:55 143360 c:\winnt\system32\ReinstallBackups\0009\DriverFiles\Rtenicxp.sys
+ 2008-04-14 11:42 . 2011-11-03 15:28 386048 c:\winnt\system32\qdvd.dll
- 2008-04-14 11:42 . 2008-04-14 11:42 386048 c:\winnt\system32\qdvd.dll
+ 2010-03-31 06:10 . 2010-03-31 06:10 295264 c:\winnt\system32\PresentationHost.exe
+ 2001-05-08 12:00 . 2012-07-20 17:36 505896 c:\winnt\system32\perfh009.dat
- 2008-04-14 11:42 . 2008-04-14 11:42 551936 c:\winnt\system32\oleaut32.dll
+ 2008-04-14 11:42 . 2010-12-20 17:32 551936 c:\winnt\system32\oleaut32.dll
- 2001-08-23 13:00 . 2009-10-08 19:57 220160 c:\winnt\system32\oleacc.dll
+ 2001-08-23 13:00 . 2011-09-26 16:41 220160 c:\winnt\system32\oleacc.dll
+ 2011-02-24 03:54 . 2011-01-27 04:32 155648 c:\winnt\system32\Oemdspif.dll
+ 2008-04-14 11:42 . 2010-11-09 14:52 249856 c:\winnt\system32\odbc32.dll
- 2008-04-14 11:42 . 2008-04-14 11:42 249856 c:\winnt\system32\odbc32.dll
- 2008-04-14 11:42 . 2010-02-25 06:24 206848 c:\winnt\system32\occache.dll
+ 2008-04-14 11:42 . 2011-11-04 19:20 206848 c:\winnt\system32\occache.dll
+ 2008-04-14 11:41 . 2010-12-09 15:15 718336 c:\winnt\system32\ntdll.dll
+ 2008-04-14 11:42 . 2008-06-20 16:02 245248 c:\winnt\system32\mswsock.dll
- 2008-04-14 11:42 . 2008-06-20 17:46 245248 c:\winnt\system32\mswsock.dll
+ 2011-02-19 05:40 . 2011-02-19 05:40 773968 c:\winnt\system32\msvcr100.dll
+ 2011-02-20 04:03 . 2011-02-20 04:03 421200 c:\winnt\system32\msvcp100.dll
+ 2010-05-16 01:21 . 2011-01-27 11:57 677888 c:\winnt\system32\mstsc.exe
- 2010-05-16 01:21 . 2008-04-14 11:42 677888 c:\winnt\system32\mstsc.exe
+ 2008-04-14 11:42 . 2011-11-04 19:20 611840 c:\winnt\system32\mstime.dll
- 2008-04-14 11:42 . 2010-02-25 06:24 611840 c:\winnt\system32\mstime.dll
+ 2009-03-08 09:32 . 2011-11-04 19:20 602112 c:\winnt\system32\msfeeds.dll
+ 2009-11-06 04:17 . 2009-11-06 04:17 297808 c:\winnt\system32\mscoree.dll
- 2006-10-19 02:47 . 2006-10-19 02:47 317440 c:\winnt\system32\MP4SDECD.dll
+ 2006-10-19 02:47 . 2010-03-30 18:24 317440 c:\winnt\system32\mp4sdecd.dll
+ 2007-04-03 14:44 . 2011-02-08 13:33 974848 c:\winnt\system32\mfc42u.dll
+ 2008-04-14 11:41 . 2011-02-08 13:33 978944 c:\winnt\system32\mfc42.dll
+ 2008-04-14 11:41 . 2010-09-18 06:53 953856 c:\winnt\system32\mfc40u.dll
+ 2001-08-23 13:00 . 2010-09-18 06:53 954368 c:\winnt\system32\mfc40.dll
+ 2012-07-26 21:29 . 2012-07-26 21:29 686792 c:\winnt\system32\Macromed\Flash\FlashUtil32_11_3_300_268_Plugin.exe
+ 2012-07-26 20:29 . 2012-07-26 20:29 686792 c:\winnt\system32\Macromed\Flash\FlashUtil32_11_3_300_268_ActiveX.exe
+ 2012-07-26 20:29 . 2012-07-26 20:29 466632 c:\winnt\system32\Macromed\Flash\FlashUtil32_11_3_300_268_ActiveX.dll
+ 2012-03-31 19:10 . 2012-07-26 21:29 250056 c:\winnt\system32\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2008-04-14 11:41 . 2010-12-20 17:26 730112 c:\winnt\system32\lsasrv.dll
- 2008-04-14 11:41 . 2009-06-25 08:25 730112 c:\winnt\system32\lsasrv.dll
+ 2008-04-14 11:41 . 2010-12-22 12:34 301568 c:\winnt\system32\kerberos.dll
- 2008-04-14 11:41 . 2009-06-25 08:25 301568 c:\winnt\system32\kerberos.dll
- 2008-04-14 11:41 . 2009-12-09 05:53 726528 c:\winnt\system32\jscript.dll
+ 2008-04-14 11:41 . 2011-10-28 16:07 726528 c:\winnt\system32\jscript.dll
+ 2012-05-09 14:05 . 2012-05-09 14:05 157472 c:\winnt\system32\javaws.exe
+ 2012-05-09 14:05 . 2012-05-09 14:05 149280 c:\winnt\system32\javaw.exe
+ 2012-05-09 14:05 . 2012-05-09 14:05 149280 c:\winnt\system32\java.exe
- 2010-12-14 20:53 . 2010-12-20 13:20 248131 c:\winnt\system32\inetsrv\MetaBase.bin
+ 2010-12-14 20:53 . 2012-08-03 22:07 248131 c:\winnt\system32\inetsrv\MetaBase.bin
- 2010-05-16 01:21 . 2008-04-14 11:41 257024 c:\winnt\system32\inetsrv\infocomm.dll
+ 2010-05-16 01:21 . 2010-07-27 06:35 257024 c:\winnt\system32\inetsrv\infocomm.dll
+ 2006-04-11 05:35 . 2010-06-30 20:38 369664 c:\winnt\system32\inetsrv\asp.dll
- 2006-04-11 05:35 . 2008-04-14 11:41 369664 c:\winnt\system32\inetsrv\asp.dll
+ 2004-10-14 17:19 . 2011-10-10 14:22 692736 c:\winnt\system32\inetcomm.dll
+ 2008-04-14 11:41 . 2011-11-04 19:20 184320 c:\winnt\system32\iepeers.dll
- 2008-04-14 11:41 . 2010-02-25 06:24 184320 c:\winnt\system32\iepeers.dll
+ 2008-04-14 11:41 . 2011-11-04 19:20 387584 c:\winnt\system32\iedkcs32.dll
- 2008-04-14 11:41 . 2010-02-25 06:24 387584 c:\winnt\system32\iedkcs32.dll
+ 2008-04-14 11:42 . 2011-11-04 11:24 174080 c:\winnt\system32\ie4uinit.exe
+ 2003-02-28 17:10 . 2003-02-28 17:10 274432 c:\winnt\system32\hpgwiamd.dll
+ 2008-04-14 06:01 . 2008-04-14 06:01 134400 c:\winnt\system32\hal.dll
+ 2010-05-16 01:21 . 2011-02-11 13:25 229888 c:\winnt\system32\fxscover.exe
+ 2005-10-13 00:37 . 2012-01-21 15:30 472376 c:\winnt\system32\FNTCACHE.DAT
- 2005-10-13 00:37 . 2010-05-16 03:45 472376 c:\winnt\system32\FNTCACHE.DAT
+ 2008-04-14 11:41 . 2011-10-18 11:13 186880 c:\winnt\system32\encdec.dll
- 2008-04-14 11:41 . 2008-04-14 11:41 186880 c:\winnt\system32\encdec.dll
+ 2011-02-24 03:54 . 2010-11-10 16:33 887724 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\ativva6x.dat
+ 2011-02-24 03:54 . 2010-11-10 16:36 110215 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\atipdlxx.dll
+ 2011-02-24 03:54 . 2010-11-10 16:34 194472 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\atiok3x2.dll
+ 2011-02-24 03:54 . 2010-11-10 16:28 334432 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\atikvmag.dll
+ 2011-02-24 03:54 . 2010-11-10 17:01 311296 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\atiiiexx.dll
+ 2011-02-24 03:54 . 2010-09-23 09:27 223990 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\atiicdxx.dat
+ 2011-02-24 03:54 . 2010-11-10 16:56 450560 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\atidemgx.dll
+ 2011-02-24 03:54 . 2010-11-10 16:26 106226 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\atiadlxx.dll
+ 2011-02-24 03:54 . 2010-11-10 16:34 324326 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\ati2evxx.exe
+ 2011-02-24 03:54 . 2010-11-10 16:55 189252 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\ati2dvag.dll
+ 2011-02-24 03:54 . 2010-11-10 16:20 360757 c:\winnt\system32\DRVSTORE\CX109537_787126B608D71DC90465E5944A6F4F42826D03A7\B108299\ati2cqag.dll
+ 2011-02-24 03:54 . 2010-08-20 00:41 101904 c:\winnt\system32\DRVSTORE\AtihdXP3_2E5722E86E96A19A59CDE99F20E276E078028941\AtihdXP3.sys
+ 2010-11-11 19:32 . 2010-11-11 19:32 854128 c:\winnt\system32\drivers\vmx86.sys
+ 2011-06-07 08:55 . 2008-04-14 05:16 121984 c:\winnt\system32\drivers\usbvideo.sys
+ 2008-04-14 06:45 . 2011-02-17 13:18 357888 c:\winnt\system32\drivers\srv.sys
+ 2011-02-23 17:09 . 2010-07-06 09:13 234392 c:\winnt\system32\drivers\Rtenicxp.sys
- 2010-05-16 01:21 . 2008-04-14 11:43 139656 c:\winnt\system32\drivers\rdpwd.sys
+ 2010-05-16 01:21 . 2011-06-24 14:10 139656 c:\winnt\system32\drivers\rdpwd.sys
+ 2008-04-14 00:49 . 2008-04-14 06:49 146048 c:\winnt\system32\drivers\portcls.sys
- 2008-04-14 00:49 . 2008-04-14 05:49 146048 c:\winnt\system32\drivers\portcls.sys
+ 2008-04-14 06:47 . 2011-04-21 13:37 105472 c:\winnt\system32\drivers\mup.sys
+ 2008-04-14 06:47 . 2011-07-15 13:29 456320 c:\winnt\system32\drivers\mrxsmb.sys
+ 2008-04-14 00:46 . 2008-04-14 06:46 141056 c:\winnt\system32\drivers\ks.sys
- 2008-04-14 00:46 . 2008-04-14 05:46 141056 c:\winnt\system32\drivers\ks.sys
+ 2012-06-16 00:50 . 2012-04-27 15:20 137928 c:\winnt\system32\drivers\avipbb.sys
+ 2011-02-24 03:54 . 2010-08-20 00:41 101904 c:\winnt\system32\drivers\AtihdXP3.sys
+ 2008-04-14 06:49 . 2011-08-17 13:49 138496 c:\winnt\system32\drivers\afd.sys
- 2008-04-14 06:49 . 2008-08-14 10:04 138496 c:\winnt\system32\drivers\afd.sys
+ 2008-04-14 11:41 . 2011-03-03 06:55 149504 c:\winnt\system32\dnsapi.dll
+ 2008-04-30 06:08 . 2010-07-12 12:55 218112 c:\winnt\system32\dllcache\wordpad.exe
- 2008-04-14 11:42 . 2008-04-14 11:42 293376 c:\winnt\system32\dllcache\winsrv.dll
+ 2008-04-14 11:42 . 2011-11-25 21:57 293376 c:\winnt\system32\dllcache\winsrv.dll
+ 2008-04-14 11:42 . 2011-10-14 14:47 176128 c:\winnt\system32\dllcache\winmm.dll
- 2008-04-14 11:42 . 2008-04-14 11:42 176128 c:\winnt\system32\dllcache\winmm.dll
+ 2008-04-14 11:42 . 2011-11-04 19:20 916992 c:\winnt\system32\dllcache\wininet.dll
+ 2008-04-14 11:42 . 2011-11-16 14:21 354816 c:\winnt\system32\dllcache\winhttp.dll
- 2008-04-14 11:42 . 2009-08-25 09:17 354816 c:\winnt\system32\dllcache\winhttp.dll
+ 2004-03-11 00:09 . 2011-04-30 03:01 758784 c:\winnt\system32\dllcache\vgx.dll
+ 2008-04-14 11:42 . 2011-03-04 06:37 420864 c:\winnt\system32\dllcache\vbscript.dll
+ 2008-04-14 11:42 . 2010-04-16 15:36 406016 c:\winnt\system32\dllcache\usp10.dll
- 2008-04-14 11:42 . 2008-04-14 11:42 406016 c:\winnt\system32\dllcache\usp10.dll
+ 2011-06-07 08:55 . 2008-04-14 05:16 121984 c:\winnt\system32\dllcache\usbvideo.sys
+ 2008-04-14 11:42 . 2011-11-04 19:20 105984 c:\winnt\system32\dllcache\url.dll
- 2008-04-14 11:42 . 2009-03-08 09:34 105984 c:\winnt\system32\dllcache\url.dll
- 2008-04-14 11:42 . 2009-10-15 16:28 119808 c:\winnt\system32\dllcache\t2embed.dll
+ 2008-04-14 11:42 . 2010-08-27 08:02 119808 c:\winnt\system32\dllcache\t2embed.dll
+ 2008-04-14 06:45 . 2011-02-17 13:18 357888 c:\winnt\system32\dllcache\srv.sys
+ 2008-04-14 11:42 . 2009-07-27 23:17 135168 c:\winnt\system32\dllcache\shsvcs.dll
- 2008-04-14 11:42 . 2008-04-14 11:42 135168 c:\winnt\system32\dllcache\shsvcs.dll
+ 2008-04-14 11:42 . 2011-01-21 14:44 439296 c:\winnt\system32\dllcache\shimgvw.dll
+ 2008-04-14 11:42 . 2011-11-16 14:21 152064 c:\winnt\system32\dllcache\schannel.dll
+ 2008-04-14 11:42 . 2011-02-09 13:53 270848 c:\winnt\system32\dllcache\sbe.dll
- 2008-04-14 11:42 . 2008-04-14 11:42 270848 c:\winnt\system32\dllcache\sbe.dll
+ 2008-04-14 11:42 . 2010-08-16 08:45 590848 c:\winnt\system32\dllcache\rpcrt4.dll
+ 2010-05-16 01:21 . 2011-06-24 14:10 139656 c:\winnt\system32\dllcache\rdpwd.sys
- 2010-05-16 01:21 . 2008-04-14 11:43 139656 c:\winnt\system32\dllcache\rdpwd.sys
+ 2008-04-14 11:42 . 2011-11-03 15:28 386048 c:\winnt\system32\dllcache\qdvd.dll
- 2008-04-14 11:42 . 2008-04-14 11:42 386048 c:\winnt\system32\dllcache\qdvd.dll
+ 2008-04-14 00:49 . 2008-04-14 06:49 146048 c:\winnt\system32\dllcache\portcls.sys
- 2008-04-14 00:49 . 2008-04-14 05:49 146048 c:\winnt\system32\dllcache\portcls.sys
+ 2008-04-14 11:42 . 2010-12-20 17:32 551936 c:\winnt\system32\dllcache\oleaut32.dll
- 2008-04-14 11:42 . 2008-04-14 11:42 551936 c:\winnt\system32\dllcache\oleaut32.dll
+ 2001-08-23 13:00 . 2011-09-26 16:41 220160 c:\winnt\system32\dllcache\oleacc.dll
- 2001-08-23 13:00 . 2009-10-08 19:57 220160 c:\winnt\system32\dllcache\oleacc.dll
+ 2008-04-14 11:42 . 2010-11-09 14:52 249856 c:\winnt\system32\dllcache\odbc32.dll
- 2008-04-14 11:42 . 2008-04-14 11:42 249856 c:\winnt\system32\dllcache\odbc32.dll
- 2008-04-14 11:42 . 2010-02-25 06:24 206848 c:\winnt\system32\dllcache\occache.dll
+ 2008-04-14 11:42 . 2011-11-04 19:20 206848 c:\winnt\system32\dllcache\occache.dll
+ 2008-04-14 11:41 . 2010-12-09 15:15 718336 c:\winnt\system32\dllcache\ntdll.dll
+ 2008-04-14 06:47 . 2011-04-21 13:37 105472 c:\winnt\system32\dllcache\mup.sys
+ 2008-04-14 11:42 . 2008-06-20 16:02 245248 c:\winnt\system32\dllcache\mswsock.dll
- 2008-04-14 11:42 . 2008-06-20 17:46 245248 c:\winnt\system32\dllcache\mswsock.dll
+ 2008-04-14 11:42 . 2011-11-04 19:20 611840 c:\winnt\system32\dllcache\mstime.dll
- 2008-04-14 11:42 . 2010-02-25 06:24 611840 c:\winnt\system32\dllcache\mstime.dll
- 2005-11-09 04:29 . 2008-04-14 11:42 102400 c:\winnt\system32\dllcache\msjro.dll
+ 2005-11-09 04:29 . 2010-11-09 14:52 102400 c:\winnt\system32\dllcache\msjro.dll
+ 2010-05-16 02:04 . 2011-11-04 19:20 602112 c:\winnt\system32\dllcache\msfeeds.dll
- 2005-11-09 04:29 . 2008-04-14 11:42 200704 c:\winnt\system32\dllcache\msadox.dll
+ 2005-11-09 04:29 . 2010-11-09 14:52 200704 c:\winnt\system32\dllcache\msadox.dll
+ 2005-11-09 04:29 . 2010-11-09 14:52 180224 c:\winnt\system32\dllcache\msadomd.dll
- 2005-11-09 04:29 . 2008-04-14 11:42 180224 c:\winnt\system32\dllcache\msadomd.dll
- 2005-11-09 04:29 . 2008-04-14 11:42 536576 c:\winnt\system32\dllcache\msado15.dll
+ 2005-11-09 04:29 . 2010-11-09 14:52 536576 c:\winnt\system32\dllcache\msado15.dll
+ 2005-11-09 04:29 . 2010-11-09 14:52 143360 c:\winnt\system32\dllcache\msadco.dll
- 2005-11-09 04:29 . 2008-04-14 11:42 143360 c:\winnt\system32\dllcache\msadco.dll
+ 2010-05-16 02:32 . 2011-07-15 13:29 456320 c:\winnt\system32\dllcache\mrxsmb.sys
+ 2010-03-30 18:24 . 2010-03-30 18:24 317440 c:\winnt\system32\dllcache\mp4sdecd.dll
+ 2007-04-03 14:44 . 2011-02-08 13:33 974848 c:\winnt\system32\dllcache\mfc42u.dll
+ 2008-04-14 11:41 . 2011-02-08 13:33 978944 c:\winnt\system32\dllcache\mfc42.dll
+ 2008-04-14 11:41 . 2010-09-18 06:53 953856 c:\winnt\system32\dllcache\mfc40u.dll
+ 2001-08-23 13:00 . 2010-09-18 06:53 954368 c:\winnt\system32\dllcache\mfc40.dll
- 2008-04-14 11:41 . 2009-06-25 08:25 730112 c:\winnt\system32\dllcache\lsasrv.dll
+ 2008-04-14 11:41 . 2010-12-20 17:26 730112 c:\winnt\system32\dllcache\lsasrv.dll
- 2010-05-16 01:21 . 2008-04-14 11:42 677888 c:\winnt\system32\dllcache\lhmstsc.exe
+ 2010-05-16 01:21 . 2011-01-27 11:57 677888 c:\winnt\system32\dllcache\lhmstsc.exe
+ 2008-04-14 00:46 . 2008-04-14 06:46 141056 c:\winnt\system32\dllcache\ks.sys
- 2008-04-14 00:46 . 2008-04-14 05:46 141056 c:\winnt\system32\dllcache\ks.sys
+ 2008-04-14 11:41 . 2010-12-22 12:34 301568 c:\winnt\system32\dllcache\kerberos.dll
- 2008-04-14 11:41 . 2009-06-25 08:25 301568 c:\winnt\system32\dllcache\kerberos.dll
+ 2008-04-14 11:41 . 2011-10-28 16:07 726528 c:\winnt\system32\dllcache\jscript.dll
- 2008-04-14 11:41 . 2009-12-09 05:53 726528 c:\winnt\system32\dllcache\jscript.dll
+ 2010-05-16 01:21 . 2010-07-27 06:35 257024 c:\winnt\system32\dllcache\infocomm.dll
- 2010-05-16 01:21 . 2008-04-14 11:41 257024 c:\winnt\system32\dllcache\infocomm.dll
+ 2004-10-14 17:19 . 2011-10-10 14:22 692736 c:\winnt\system32\dllcache\inetcomm.dll
- 2010-05-16 02:04 . 2010-02-25 06:24 247808 c:\winnt\system32\dllcache\ieproxy.dll
+ 2010-05-16 02:04 . 2011-11-04 19:20 247808 c:\winnt\system32\dllcache\ieproxy.dll
+ 2008-04-14 11:41 . 2011-11-04 19:20 184320 c:\winnt\system32\dllcache\iepeers.dll
- 2008-04-14 11:41 . 2010-02-25 06:24 184320 c:\winnt\system32\dllcache\iepeers.dll
+ 2011-03-01 02:13 . 2011-11-04 19:20 743424 c:\winnt\system32\dllcache\iedvtool.dll
+ 2008-04-14 11:41 . 2011-11-04 19:20 387584 c:\winnt\system32\dllcache\iedkcs32.dll
- 2008-04-14 11:41 . 2010-02-25 06:24 387584 c:\winnt\system32\dllcache\iedkcs32.dll
+ 2008-04-14 11:42 . 2011-11-04 11:24 174080 c:\winnt\system32\dllcache\ie4uinit.exe
+ 2010-05-16 01:30 . 2010-06-14 14:31 744448 c:\winnt\system32\dllcache\helpsvc.exe
- 2010-05-16 01:30 . 2008-04-14 11:42 744448 c:\winnt\system32\dllcache\helpsvc.exe
+ 2010-05-16 01:21 . 2011-02-11 13:25 229888 c:\winnt\system32\dllcache\fxscover.exe
- 2008-04-14 11:41 . 2008-04-14 11:41 186880 c:\winnt\system32\dllcache\encdec.dll
+ 2008-04-14 11:41 . 2011-10-18 11:13 186880 c:\winnt\system32\dllcache\encdec.dll
+ 2008-04-14 11:41 . 2011-03-03 06:55 149504 c:\winnt\system32\dllcache\dnsapi.dll
+ 2008-04-14 11:41 . 2011-09-28 07:06 599040 c:\winnt\system32\dllcache\crypt32.dll
- 2008-04-14 11:41 . 2008-04-14 11:41 599040 c:\winnt\system32\dllcache\crypt32.dll
+ 2008-04-14 11:41 . 2010-08-23 16:12 617472 c:\winnt\system32\dllcache\comctl32.dll
- 2008-04-14 11:41 . 2008-04-14 11:41 617472 c:\winnt\system32\dllcache\comctl32.dll
+ 2008-04-14 11:39 . 2011-02-15 12:56 290432 c:\winnt\system32\dllcache\atmfd.dll
+ 2011-02-24 03:54 . 2010-11-10 16:55 301056 c:\winnt\system32\dllcache\ati2dvag.dll
+ 2011-02-24 03:54 . 2010-11-10 16:20 704512 c:\winnt\system32\dllcache\ati2cqag.dll
- 2006-04-11 05:35 . 2008-04-14 11:41 369664 c:\winnt\system32\dllcache\asp51.dll
+ 2006-04-11 05:35 . 2010-06-30 20:38 369664 c:\winnt\system32\dllcache\asp51.dll
+ 2008-04-14 06:49 . 2011-08-17 13:49 138496 c:\winnt\system32\dllcache\afd.sys
- 2008-04-14 06:49 . 2008-08-14 10:04 138496 c:\winnt\system32\dllcache\afd.sys
+ 2008-04-13 22:09 . 2008-04-14 11:51 142592 c:\winnt\system32\dllcache\aec.sys
+ 2011-04-14 03:48 . 2001-08-17 19:07 101888 c:\winnt\system32\dllcache\adpu160m.sys
+ 2011-04-14 03:48 . 2001-08-17 17:19 747392 c:\winnt\system32\dllcache\adm8830.sys
+ 2011-04-14 03:48 . 2001-08-17 17:19 553984 c:\winnt\system32\dllcache\adm8820.sys
+ 2011-04-14 03:48 . 2001-08-17 17:19 584448 c:\winnt\system32\dllcache\adm8810.sys
+ 2008-04-14 06:06 . 2008-04-14 06:06 187776 c:\winnt\system32\dllcache\acpi.sys
- 2008-04-14 11:41 . 2009-11-21 15:51 471552 c:\winnt\system32\dllcache\aclayers.dll
+ 2008-04-14 11:41 . 2011-03-11 14:10 471552 c:\winnt\system32\dllcache\aclayers.dll
+ 2011-04-14 03:48 . 2001-08-17 17:20 297728 c:\winnt\system32\dllcache\ac97sis.sys
+ 2011-04-14 03:48 . 2008-04-14 03:06 231552 c:\winnt\system32\dllcache\ac97ali.sys
+ 2011-04-14 03:48 . 2001-08-18 03:36 462848 c:\winnt\system32\dllcache\a3dapi.dll
+ 2011-02-24 04:02 . 2004-11-17 15:29 254000 c:\winnt\system32\dllcache\a3d.dll
+ 2011-04-14 03:48 . 2001-08-17 17:48 148352 c:\winnt\system32\dllcache\3dfxvsm.sys
+ 2011-04-14 03:48 . 2001-08-17 19:55 689216 c:\winnt\system32\dllcache\3dfxvs.dll
+ 2011-04-14 03:48 . 2001-08-17 18:28 762780 c:\winnt\system32\dllcache\3cwmcru.sys
+ 2011-02-24 04:01 . 2007-04-11 21:35 331184 c:\winnt\system32\difxapi.dll
- 2008-04-14 11:41 . 2008-04-14 11:41 599040 c:\winnt\system32\crypt32.dll
+ 2008-04-14 11:41 . 2011-09-28 07:06 599040 c:\winnt\system32\crypt32.dll
+ 2008-04-14 11:41 . 2010-08-23 16:12 617472 c:\winnt\system32\comctl32.dll
- 2008-04-14 11:41 . 2008-04-14 11:41 617472 c:\winnt\system32\comctl32.dll
+ 2011-02-24 04:02 . 2004-11-17 15:29 254000 c:\winnt\system32\Audio3D.dll
+ 2008-04-14 11:39 . 2011-02-15 12:56 290432 c:\winnt\system32\atmfd.dll
+ 2011-02-20 04:03 . 2011-02-20 04:03 138056 c:\winnt\system32\atl100.dll
+ 2011-02-24 03:54 . 2011-01-27 04:26 887724 c:\winnt\system32\ativva6x.dat
+ 2011-02-24 03:54 . 2011-01-27 04:32 212992 c:\winnt\system32\atipdlxx.dll
+ 2011-02-24 03:54 . 2011-01-27 04:21 483328 c:\winnt\system32\atiok3x2.dll
+ 2011-02-24 03:54 . 2010-08-28 01:32 294912 c:\winnt\system32\ATIODE.exe
+ 2011-02-24 03:54 . 2011-01-27 04:23 651264 c:\winnt\system32\atikvmag.dll
+ 2011-02-24 03:54 . 2011-01-27 04:41 311296 c:\winnt\system32\atiiiexx.dll
+ 2011-02-24 03:54 . 2010-12-17 22:00 227587 c:\winnt\system32\atiicdxx.dat
+ 2011-02-24 03:54 . 2011-01-27 04:52 462848 c:\winnt\system32\ATIDEMGX.dll
+ 2011-02-24 03:54 . 2009-05-12 04:35 118784 c:\winnt\system32\atibtmon.exe
+ 2011-02-24 03:54 . 2011-01-27 04:27 143360 c:\winnt\system32\atiapfxx.exe
+ 2011-02-24 03:54 . 2011-01-27 04:21 196608 c:\winnt\system32\atiadlxx.dll
+ 2011-02-24 03:54 . 2011-01-27 04:30 638976 c:\winnt\system32\ati2evxx.exe
+ 2011-02-24 03:54 . 2011-01-27 04:31 188416 c:\winnt\system32\ati2evxx.dll
+ 2011-02-24 03:54 . 2011-01-27 04:51 302080 c:\winnt\system32\ati2dvag.dll
+ 2011-02-24 03:54 . 2011-01-27 04:15 847872 c:\winnt\system32\ati2cqag.dll
+ 2012-04-26 12:50 . 2012-04-26 12:50 284088 c:\winnt\system32\Adobe\Shockwave 11\SymCCIS.dll
+ 2012-04-26 13:05 . 2012-04-26 13:05 114176 c:\winnt\system32\Adobe\Shockwave 11\SwInit.exe
+ 2012-04-26 13:06 . 2012-04-26 13:06 434176 c:\winnt\system32\Adobe\Shockwave 11\Proj.dll
+ 2012-04-26 13:06 . 2012-04-26 13:06 366592 c:\winnt\system32\Adobe\Shockwave 11\Plugin.dll
+ 2012-04-26 12:54 . 2012-04-26 12:54 990208 c:\winnt\system32\Adobe\Shockwave 11\iml32.dll
+ 2012-04-26 13:05 . 2012-04-26 13:05 544256 c:\winnt\system32\Adobe\Shockwave 11\Control.dll
+ 2012-04-26 13:12 . 2012-04-26 13:12 113592 c:\winnt\system32\Adobe\Director\SWDNLD.EXE
+ 2012-04-26 13:12 . 2012-04-26 13:12 281016 c:\winnt\system32\Adobe\Director\SwDir.dll
+ 2012-04-26 13:06 . 2012-04-26 13:06 145920 c:\winnt\system32\Adobe\Director\np32dsw.dll
+ 2011-02-24 04:02 . 2004-11-17 15:29 254000 c:\winnt\system32\A3D.dll
+ 2011-02-11 13:25 . 2011-02-11 13:25 229888 c:\winnt\ServicePackFiles\ServicePackCache\i386\fxscover.exe
+ 2011-10-27 06:03 . 2011-09-14 03:44 169396 c:\winnt\PCHEALTH\helpctr\Config\Cache\Professional_32_1033.dat
+ 2010-05-16 01:30 . 2010-06-14 14:31 744448 c:\winnt\PCHEALTH\helpctr\binaries\helpsvc.exe
- 2010-05-16 01:30 . 2008-04-14 11:42 744448 c:\winnt\PCHEALTH\helpctr\binaries\HelpSvc.exe
+ 2010-03-31 06:16 . 2010-03-31 06:16 130408 c:\winnt\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
- 2009-10-27 05:45 . 2009-10-27 05:45 970752 c:\winnt\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
+ 2010-04-08 05:48 . 2010-04-08 05:48 970752 c:\winnt\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
- 2008-07-30 00:16 . 2008-07-30 00:16 110592 c:\winnt\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
+ 2010-04-08 05:48 . 2010-04-08 05:48 110592 c:\winnt\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
+ 2011-12-25 09:49 . 2011-12-25 09:49 436496 c:\winnt\Microsoft.NET\Framework\v2.0.50727\webengine.dll
+ 2010-02-09 18:22 . 2010-02-09 18:22 258048 c:\winnt\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
- 2008-07-25 16:17 . 2008-07-25 16:17 258048 c:\winnt\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
+ 2011-07-07 10:18 . 2011-07-07 10:18 388936 c:\winnt\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2011-03-25 11:15 . 2011-03-25 11:15 363856 c:\winnt\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2011-07-07 10:18 . 2011-07-07 10:18 989016 c:\winnt\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2011-12-25 04:55 . 2011-12-25 04:55 102400 c:\winnt\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2008-05-28 05:49 . 2008-05-28 05:49 102400 c:\winnt\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2011-12-25 04:53 . 2011-12-25 04:53 315392 c:\winnt\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2008-05-28 05:48 . 2008-05-28 05:48 315392 c:\winnt\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2011-12-25 05:49 . 2011-12-25 05:49 258048 c:\winnt\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
- 2008-05-28 06:30 . 2008-05-28 06:30 258048 c:\winnt\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-02-24 03:53 . 2011-02-24 03:53 429056 c:\winnt\Installer\dfdee.msi
+ 2012-05-09 14:06 . 2012-05-09 14:06 203776 c:\winnt\Installer\c75db34c.msi
+ 2012-05-09 14:05 . 2012-05-09 14:05 900096 c:\winnt\Installer\c75db338.msi
+ 2010-09-24 03:02 . 2010-09-24 03:02 798208 c:\winnt\Installer\c5e54.msp
+ 2010-02-25 06:14 . 2010-02-25 06:14 543232 c:\winnt\Installer\c5e09.msp
+ 2012-06-16 00:43 . 2012-06-16 00:43 160768 c:\winnt\Installer\b5f69.msi
+ 2011-07-23 03:37 . 2011-07-23 03:37 189440 c:\winnt\Installer\9e4fb33.msi
+ 2011-03-31 02:41 . 2011-03-31 02:41 228352 c:\winnt\Installer\6cba3344.msi
+ 2012-06-03 15:48 . 2012-06-03 15:48 430592 c:\winnt\Installer\461cc.msi
+ 2011-12-25 11:40 . 2011-12-25 11:40 819200 c:\winnt\Installer\1f3028.msp
- 2005-10-14 00:34 . 2010-12-18 19:32 409600 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2005-10-14 00:34 . 2011-09-22 18:26 409600 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2005-10-14 00:34 . 2011-09-22 18:26 286720 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2005-10-14 00:34 . 2010-12-18 19:32 286720 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2005-10-14 00:34 . 2011-09-22 18:26 249856 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2005-10-14 00:34 . 2010-12-18 19:32 249856 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2005-10-14 00:34 . 2011-09-22 18:26 794624 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2005-10-14 00:34 . 2010-12-18 19:32 794624 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2005-10-14 00:34 . 2010-12-18 19:32 135168 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2005-10-14 00:34 . 2011-09-22 18:26 135168 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2005-10-14 00:34 . 2010-12-18 19:32 593920 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2005-10-14 00:34 . 2011-09-22 18:26 593920 c:\winnt\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 249232 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\sqlite.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 394136 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\pdfshell.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 103848 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\PDFPrevHndlrShim.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 183696 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\nppdf32.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 104344 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AiodLite.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 102808 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRdIF.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 755088 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroPDF.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 296344 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acrobroker.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 205720 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\a3dutils.dll
+ 2012-01-21 09:13 . 2010-07-05 13:16 382840 c:\winnt\ie8updates\KB2632503-IE8\spuninst\updspapi.dll
+ 2012-01-21 09:13 . 2010-07-05 13:15 231288 c:\winnt\ie8updates\KB2632503-IE8\spuninst\spuninst.exe
+ 2012-01-21 09:13 . 2011-03-04 06:37 726528 c:\winnt\ie8updates\KB2632503-IE8\jscript.dll
+ 2012-01-21 09:07 . 2011-08-22 23:48 916480 c:\winnt\ie8updates\KB2618444-IE8\wininet.dll
+ 2012-01-21 09:07 . 2011-08-22 23:48 105984 c:\winnt\ie8updates\KB2618444-IE8\url.dll
+ 2012-01-21 09:07 . 2010-07-05 13:16 382840 c:\winnt\ie8updates\KB2618444-IE8\spuninst\updspapi.dll
+ 2012-01-21 09:07 . 2010-07-05 13:15 231288 c:\winnt\ie8updates\KB2618444-IE8\spuninst\spuninst.exe
+ 2012-01-21 09:07 . 2011-08-22 23:48 206848 c:\winnt\ie8updates\KB2618444-IE8\occache.dll
+ 2012-01-21 09:07 . 2011-08-22 23:48 611840 c:\winnt\ie8updates\KB2618444-IE8\mstime.dll
+ 2012-01-21 09:07 . 2011-08-22 23:48 602112 c:\winnt\ie8updates\KB2618444-IE8\msfeeds.dll
+ 2012-01-21 09:07 . 2011-08-22 23:48 247808 c:\winnt\ie8updates\KB2618444-IE8\ieproxy.dll
+ 2012-01-21 09:07 . 2011-08-22 23:48 184320 c:\winnt\ie8updates\KB2618444-IE8\iepeers.dll
+ 2012-01-21 09:07 . 2011-08-22 23:48 743424 c:\winnt\ie8updates\KB2618444-IE8\iedvtool.dll
+ 2012-01-21 09:07 . 2011-08-22 23:48 387584 c:\winnt\ie8updates\KB2618444-IE8\iedkcs32.dll
+ 2012-01-21 09:07 . 2011-08-22 11:56 174080 c:\winnt\ie8updates\KB2618444-IE8\ie4uinit.exe
+ 2011-10-27 06:16 . 2010-07-05 13:16 382840 c:\winnt\ie8updates\KB2598845-IE8\spuninst\updspapi.dll
+ 2011-10-27 06:16 . 2010-07-05 13:15 231288 c:\winnt\ie8updates\KB2598845-IE8\spuninst\spuninst.exe
+ 2011-10-27 06:16 . 2011-06-23 18:36 916480 c:\winnt\ie8updates\KB2586448-IE8\wininet.dll
+ 2011-10-27 06:16 . 2011-06-23 18:36 105984 c:\winnt\ie8updates\KB2586448-IE8\url.dll
+ 2011-10-27 06:16 . 2010-07-05 13:16 382840 c:\winnt\ie8updates\KB2586448-IE8\spuninst\updspapi.dll
+ 2011-10-27 06:16 . 2010-07-05 13:15 231288 c:\winnt\ie8updates\KB2586448-IE8\spuninst\spuninst.exe
+ 2011-10-27 06:16 . 2011-06-23 18:36 206848 c:\winnt\ie8updates\KB2586448-IE8\occache.dll
+ 2011-10-27 06:16 . 2011-06-23 18:36 611840 c:\winnt\ie8updates\KB2586448-IE8\mstime.dll
+ 2011-10-27 06:16 . 2011-06-23 18:36 602112 c:\winnt\ie8updates\KB2586448-IE8\msfeeds.dll
+ 2011-10-27 06:16 . 2011-06-23 18:36 247808 c:\winnt\ie8updates\KB2586448-IE8\ieproxy.dll
+ 2011-10-27 06:16 . 2011-06-23 18:36 184320 c:\winnt\ie8updates\KB2586448-IE8\iepeers.dll
+ 2011-10-27 06:16 . 2011-06-23 18:36 743424 c:\winnt\ie8updates\KB2586448-IE8\iedvtool.dll
+ 2011-10-27 06:16 . 2011-06-23 18:36 387584 c:\winnt\ie8updates\KB2586448-IE8\iedkcs32.dll
+ 2011-10-27 06:16 . 2011-06-23 12:05 173568 c:\winnt\ie8updates\KB2586448-IE8\ie4uinit.exe
+ 2011-09-08 03:20 . 2010-12-20 23:59 916480 c:\winnt\ie8updates\KB2559049-IE8\wininet.dll
+ 2011-09-08 03:20 . 2009-03-08 09:34 105984 c:\winnt\ie8updates\KB2559049-IE8\url.dll
+ 2011-09-08 03:20 . 2010-07-05 13:16 382840 c:\winnt\ie8updates\KB2559049-IE8\spuninst\updspapi.dll
+ 2011-09-08 03:20 . 2010-07-05 13:15 231288 c:\winnt\ie8updates\KB2559049-IE8\spuninst\spuninst.exe
+ 2011-09-08 03:20 . 2010-12-20 23:59 206848 c:\winnt\ie8updates\KB2559049-IE8\occache.dll
+ 2011-09-08 03:20 . 2010-12-20 23:59 611840 c:\winnt\ie8updates\KB2559049-IE8\mstime.dll
+ 2011-09-08 03:20 . 2010-12-20 23:59 602112 c:\winnt\ie8updates\KB2559049-IE8\msfeeds.dll
+ 2011-09-08 03:20 . 2010-12-20 23:59 247808 c:\winnt\ie8updates\KB2559049-IE8\ieproxy.dll
+ 2011-09-08 03:20 . 2010-12-20 23:59 184320 c:\winnt\ie8updates\KB2559049-IE8\iepeers.dll
+ 2011-09-08 03:20 . 2010-12-20 23:59 743424 c:\winnt\ie8updates\KB2559049-IE8\iedvtool.dll
+ 2011-09-08 03:20 . 2010-12-20 23:59 387584 c:\winnt\ie8updates\KB2559049-IE8\iedkcs32.dll
+ 2011-09-08 03:20 . 2010-12-20 12:55 173568 c:\winnt\ie8updates\KB2559049-IE8\ie4uinit.exe
+ 2011-09-08 03:20 . 2009-03-08 09:33 759296 c:\winnt\ie8updates\KB2544521-IE8\vgx.dll
+ 2011-09-08 03:20 . 2010-07-05 13:16 382840 c:\winnt\ie8updates\KB2544521-IE8\spuninst\updspapi.dll
+ 2011-09-08 03:20 . 2010-07-05 13:15 231288 c:\winnt\ie8updates\KB2544521-IE8\spuninst\spuninst.exe
+ 2011-09-08 03:16 . 2010-03-10 06:15 420352 c:\winnt\ie8updates\KB2510531-IE8\vbscript.dll
+ 2011-09-08 03:16 . 2010-07-05 13:16 382840 c:\winnt\ie8updates\KB2510531-IE8\spuninst\updspapi.dll
+ 2011-09-08 03:16 . 2010-07-05 13:15 231288 c:\winnt\ie8updates\KB2510531-IE8\spuninst\spuninst.exe
+ 2011-09-08 03:16 . 2009-12-09 05:53 726528 c:\winnt\ie8updates\KB2510531-IE8\jscript.dll
+ 2011-03-01 02:32 . 2010-02-25 06:24 916480 c:\winnt\ie8updates\KB2482017-IE8\wininet.dll
+ 2011-03-01 02:33 . 2010-07-05 13:16 382840 c:\winnt\ie8updates\KB2482017-IE8\spuninst\updspapi.dll
+ 2011-03-01 02:33 . 2010-07-05 13:15 231288 c:\winnt\ie8updates\KB2482017-IE8\spuninst\spuninst.exe
+ 2011-03-01 02:32 . 2010-02-25 06:24 206848 c:\winnt\ie8updates\KB2482017-IE8\occache.dll
+ 2011-03-01 02:32 . 2010-02-25 06:24 611840 c:\winnt\ie8updates\KB2482017-IE8\mstime.dll
+ 2011-03-01 02:32 . 2010-02-25 06:24 594432 c:\winnt\ie8updates\KB2482017-IE8\msfeeds.dll
+ 2011-03-01 02:32 . 2010-02-25 06:24 247808 c:\winnt\ie8updates\KB2482017-IE8\ieproxy.dll
+ 2011-03-01 02:32 . 2010-02-25 06:24 184320 c:\winnt\ie8updates\KB2482017-IE8\iepeers.dll
+ 2011-03-01 02:32 . 2009-03-08 09:35 742912 c:\winnt\ie8updates\KB2482017-IE8\iedvtool.dll
+ 2011-03-01 02:32 . 2010-02-25 06:24 387584 c:\winnt\ie8updates\KB2482017-IE8\iedkcs32.dll
+ 2011-03-01 02:32 . 2010-02-24 09:54 173056 c:\winnt\ie8updates\KB2482017-IE8\ie4uinit.exe
+ 2011-09-08 03:15 . 2010-02-22 14:23 382840 c:\winnt\ie8updates\KB2447568-IE8\spuninst\updspapi.dll
+ 2011-09-08 03:15 . 2010-02-22 14:23 231288 c:\winnt\ie8updates\KB2447568-IE8\spuninst\spuninst.exe
+ 2010-12-20 23:50 . 2010-12-20 23:50 204800 c:\winnt\ERDNT\12-20-2010\Users\00000002\UsrClass.dat
- 2010-12-20 12:41 . 2010-12-20 12:41 204800 c:\winnt\ERDNT\12-20-2010\Users\00000002\UsrClass.dat
+ 2010-05-16 02:32 . 2011-07-15 13:29 456320 c:\winnt\Driver Cache\i386\mrxsmb.sys
+ 2012-01-21 09:09 . 2012-01-21 09:09 835584 c:\winnt\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_31507923\System.Drawing.dll
+ 2012-01-21 09:09 . 2012-01-21 09:09 192512 c:\winnt\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_4a7aab1e\System.Drawing.Design.dll
+ 2012-01-21 09:09 . 2012-01-21 09:09 118784 c:\winnt\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_fd5344d6\CustomMarshalers.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 321536 c:\winnt\assembly\NativeImages_v2.0.50727_32\WsatConfig\c8627df7adb416722d8e0f05c57fef6b\WsatConfig.ni.exe
+ 2011-10-27 06:16 . 2011-10-27 06:16 240128 c:\winnt\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\a2c1bb3c5b1447b398e72c56091ca571\WindowsFormsIntegration.ni.dll
+ 2011-10-27 06:16 . 2011-10-27 06:16 187904 c:\winnt\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\f102afdffdbe2565bcedb7fa0626b865\UIAutomationTypes.ni.dll
+ 2011-10-27 06:15 . 2011-10-27 06:15 447488 c:\winnt\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\ba55240b7753047f8d1b03ef473bf74e\UIAutomationClient.ni.dll
+ 2011-10-27 06:59 . 2011-10-27 06:59 400896 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\566b2e11e7f3f6d973b17b86cf42f9bc\System.Xml.Linq.ni.dll
+ 2012-01-21 09:19 . 2012-01-21 09:19 129536 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\0bda7bdfaf440d5dd4bc6a1dea7ffa39\System.Web.Routing.ni.dll
+ 2011-10-27 06:59 . 2011-10-27 06:59 202240 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\018b6e48c32d5b5d78086998e3505f1c\System.Web.RegularExpressions.ni.dll
+ 2012-01-21 09:19 . 2012-01-21 09:19 859648 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\6e29f9faa74a48b83a13a3413b826295\System.Web.Extensions.Design.ni.dll
+ 2012-01-21 09:19 . 2012-01-21 09:19 328704 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\be8965fe859bc53dff61579bf626858b\System.Web.Entity.ni.dll
+ 2012-01-21 09:19 . 2012-01-21 09:19 301056 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\8441b3eb247e0344fede848337ee911c\System.Web.Entity.Design.ni.dll
+ 2012-01-21 09:19 . 2012-01-21 09:19 547328 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\09c6a41f187ba483486cdb92dad714a1\System.Web.DynamicData.ni.dll
+ 2012-01-21 09:19 . 2012-01-21 09:19 141312 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\5efb726d424b9712632eff749411fa89\System.Web.Abstractions.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 627200 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Transactions\8efcd633af87989355382b5039f1b7df\System.Transactions.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 212992 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 679936 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Security\36c12de583ee81e9c99acb72b09d77ac\System.Security.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 311296 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\81096bfe85eb0da5f05e8a127ffa43b2\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 621056 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Net\b2a84980f206431821d85d5155d5916f\System.Net.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 998400 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Management\90b90e700e59d73d6d692cf74e1ba16e\System.Management.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 330752 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Management.I#\f36eded354122da9555a6c7cdbdb5431\System.Management.Instrumentation.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 250368 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Management.A#\fff9ba9f177c193d8c5ac9bc74d1ff6e\System.Management.Automation.resources.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 188928 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Management.A#\fa74b590b28dbf434dc2f3f237ea16cd\System.Management.Automation.resources.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 221184 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Management.A#\eb8f630a81f6274df2574683bbf9c375\System.Management.Automation.resources.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 172544 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Management.A#\d800b92c93d2d6703f000d60180ad6c2\System.Management.Automation.resources.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 154112 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Management.A#\6f10327646e704c5f1278d1d84cf37ed\System.Management.Automation.resources.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 154624 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Management.A#\68cfbfed9e99fb7a21cf6f7303b5dc66\System.Management.Automation.resources.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 181248 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Management.A#\61d86c61f85f5f527794359569579916\System.Management.Automation.resources.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 177664 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Management.A#\4f5df2a653d5e29bf01d9e357d456561\System.Management.Automation.resources.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 169472 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Management.A#\4988c34bafc6dc76bbbb51f17612b7e7\System.Management.Automation.resources.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 169984 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Management.A#\32bf3a315d3f5a1fd259b95d78e4d660\System.Management.Automation.resources.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 175104 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Management.A#\1222f3f74fcdfdac51965b6c9c39cac9\System.Management.Automation.resources.ni.dll
+ 2011-10-27 06:17 . 2011-10-27 06:17 381440 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.IO.Log\20a77c41ee12362d303fb2574fcd5a24\System.IO.Log.ni.dll
+ 2011-10-27 06:17 . 2011-10-27 06:17 212992 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\41c3a2fcffc58b20023c7d54e57ea956\System.IdentityModel.Selectors.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 280064 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.Wrapper.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 627712 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.ni.dll
+ 2011-10-27 06:15 . 2011-10-27 06:15 208384 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\896eca06e2d9377b2dc4fad56ce49b07\System.Drawing.Design.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 455680 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\33e9b0c368c31ef37a2ec7b5a181044b\System.DirectoryServices.Protocols.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 881152 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\11cdd1c0d65428cd3505d3813d36638c\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 939008 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\e5ada332a9bc3c982e6aede6ba354196\System.Data.Services.Client.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 354816 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\3f179f373f31817a914b639a56cc0497\System.Data.Services.Design.ni.dll
+ 2012-01-21 09:19 . 2012-01-21 09:19 756736 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\f374e8e7849a72d1470b4a6a0771a137\System.Data.Entity.Design.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 135680 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\b9d9ff5d03e90ede1116794f2c7dd6da\System.Data.DataSetExtensions.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 971264 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll
+ 2011-10-27 06:58 . 2011-10-27 06:58 141312 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\29d7091f6eab0ec61c4eb625ed221b73\System.Configuration.Install.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 633856 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.AddIn\3048737e9e3bf5173121a084337256bc\System.AddIn.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 366080 c:\winnt\assembly\NativeImages_v2.0.50727_32\SMSvcHost\6e45cf503f025c5fe814ea7e52f62a78\SMSvcHost.ni.exe
+ 2011-10-27 06:51 . 2011-10-27 06:51 256000 c:\winnt\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\474a341340f687bcbd7777f2820a8c7a\SMDiagnostics.ni.dll
+ 2012-01-21 09:18 . 2012-01-21 09:18 320512 c:\winnt\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\439732479756e0f6df88d29e50a402bf\ServiceModelReg.ni.exe
+ 2011-10-27 06:15 . 2011-10-27 06:15 539648 c:\winnt\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c2ebcc8d60422f224b4088f3d7a2ac1f\PresentationFramework.Luna.ni.dll
+ 2011-10-27 06:15 . 2011-10-27 06:15 368128 c:\winnt\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\94cfc00ad448575bfb0e67c53b514cd5\PresentationFramework.Aero.ni.dll
+ 2011-10-27 06:15 . 2011-10-27 06:15 224768 c:\winnt\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\478d57d96f3d8d5fc15c7ac635a4a6a1\PresentationFramework.Classic.ni.dll
+ 2011-10-27 06:15 . 2011-10-27 06:15 258048 c:\winnt\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\23c5852ff8ed973ff9b63ce9ba7f91f0\PresentationFramework.Royale.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 133632 c:\winnt\assembly\NativeImages_v2.0.50727_32\MSBuild\04595f414c49cf2a65b349648ba23e62\MSBuild.ni.exe
+ 2011-10-27 06:52 . 2011-10-27 06:52 508928 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Man#\a976a4b51c81150402b0abee38f41ab1\Microsoft.WSMan.Management.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 386560 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\4cbd7ed9fbf9f1b3cbdf23906cc0f5a3\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 156160 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\df4a7b6bc850621fa2d38fb08f910ef7\Microsoft.PowerShell.Security.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 515584 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\b3d3d76cfc8350587616860fb0f64ccc\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2011-10-27 06:52 . 2011-10-27 06:52 729600 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\6f6b54b6cebab6867dafeb6db1b98ab1\Microsoft.PowerShell.GraphicalHost.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 737792 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\592e4b99037ec91cd4201d1ee28895b7\Microsoft.PowerShell.Commands.Management.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 291328 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\3a03ec48148fa16aa65fd9ba5df49cb8\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 144384 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\ff6d4892775fd1f9b137f7c92ea453f2\Microsoft.Build.Utilities.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 175104 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\47ff0720cb80a0fc0bbd15ddc3d12adc\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 839680 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\da112c5757e3c68d6369b6aa46cc9682\Microsoft.Build.Engine.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 222720 c:\winnt\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\dc278e1123086ae32fec8f7e9751db14\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 220672 c:\winnt\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\3e6deccf191ab943d3a0812a38ab5c97\CustomMarshalers.ni.dll
+ 2011-10-27 06:51 . 2011-10-27 06:51 410112 c:\winnt\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\4e68d5df30b197ff72c75f1c3c24b949\ComSvcConfig.ni.exe
+ 2012-01-21 09:18 . 2012-01-21 09:18 842240 c:\winnt\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\bfcea15c95909860c4f4ac19bd7a2d6c\AspNetMMCExt.ni.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 839680 c:\winnt\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 839680 c:\winnt\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 835584 c:\winnt\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 835584 c:\winnt\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 114688 c:\winnt\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 114688 c:\winnt\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 258048 c:\winnt\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 258048 c:\winnt\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-03-01 02:18 . 2011-03-01 02:18 970752 c:\winnt\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- 2010-05-16 04:08 . 2010-05-16 04:08 970752 c:\winnt\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 131072 c:\winnt\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 131072 c:\winnt\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 303104 c:\winnt\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 303104 c:\winnt\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 258048 c:\winnt\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 258048 c:\winnt\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 372736 c:\winnt\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 372736 c:\winnt\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 253952 c:\winnt\assembly\GAC_MSIL\System.Management.Automation.resources\1.0.0.0_en_31bf3856ad364e35\System.Management.Automation.resources.dll
+ 2011-03-01 02:18 . 2011-03-01 02:18 438272 c:\winnt\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 626688 c:\winnt\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 626688 c:\winnt\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 401408 c:\winnt\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 401408 c:\winnt\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 188416 c:\winnt\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 188416 c:\winnt\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 970752 c:\winnt\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 970752 c:\winnt\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 745472 c:\winnt\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 745472 c:\winnt\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 425984 c:\winnt\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 425984 c:\winnt\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 110592 c:\winnt\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 110592 c:\winnt\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2010-05-16 03:18 . 2010-05-16 03:18 110592 c:\winnt\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
+ 2011-03-01 02:18 . 2011-03-01 02:18 110592 c:\winnt\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 274432 c:\winnt\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 659456 c:\winnt\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 659456 c:\winnt\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 372736 c:\winnt\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 372736 c:\winnt\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 110592 c:\winnt\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 110592 c:\winnt\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 278528 c:\winnt\assembly\GAC_MSIL\Microsoft.PowerShell.GraphicalHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.GraphicalHost.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 651264 c:\winnt\assembly\GAC_MSIL\Microsoft.PowerShell.GPowerShell\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.GPowerShell.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 991232 c:\winnt\assembly\GAC_MSIL\Microsoft.PowerShell.Editor\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Editor.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 200704 c:\winnt\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll
- 2010-05-16 02:41 . 2010-05-16 02:41 200704 c:\winnt\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 618496 c:\winnt\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 262144 c:\winnt\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll
+ 2011-10-27 06:08 . 2011-10-27 06:08 102400 c:\winnt\assembly\GAC_MSIL\Microsoft.
Back to top
View user's profile Send private message
HerbCumbie
Junior Member


Joined: 13 Jan 2005
Last Visit: 14 Nov 2013
Posts: 49

PostPosted: Fri Aug 03, 2012 2:27 pm    Post subject: Reply with quote

And hopefully here's the last of it:

+ 2011-10-27 06:08 . 2011-10-27 06:08 2682880 c:\winnt\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 5062656 c:\winnt\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 5062656 c:\winnt\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2011-03-01 02:23 . 2011-03-01 02:23 5279744 c:\winnt\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 5246976 c:\winnt\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 2933248 c:\winnt\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 2933248 c:\winnt\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-03-01 02:23 . 2011-03-01 02:23 4210688 c:\winnt\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2010-05-16 03:18 . 2010-05-16 03:18 4210688 c:\winnt\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2012-01-21 09:11 . 2012-01-21 09:11 4550656 c:\winnt\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2010-05-16 04:06 . 2010-05-16 04:06 4550656 c:\winnt\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-01-21 09:09 . 2012-01-21 09:09 1232896 c:\winnt\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2009-10-15 04:40 . 2009-10-15 04:40 1232896 c:\winnt\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2012-01-21 09:09 . 2012-01-21 09:09 2064384 c:\winnt\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2012-01-21 09:09 . 2012-01-21 09:09 1269760 c:\winnt\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2008-04-14 11:42 . 2010-08-26 05:36 10841088 c:\winnt\system32\wmp.dll
- 2008-04-14 11:42 . 2009-07-14 04:43 10841088 c:\winnt\system32\wmp.dll
+ 2011-03-01 02:35 . 2010-11-10 17:04 16330752 c:\winnt\system32\ReinstallBackups\0010\DriverFiles\B108299\atioglxx.dll
+ 2005-10-13 10:58 . 2012-01-04 23:15 52128560 c:\winnt\system32\MRT.exe
+ 2009-03-08 09:39 . 2011-11-04 19:20 11081728 c:\winnt\system32\ieframe.dll
+ 2008-04-14 11:42 . 2010-08-26 05:36 10841088 c:\winnt\system32\dllcache\wmp.dll
- 2008-04-14 11:42 . 2009-07-14 04:43 10841088 c:\winnt\system32\dllcache\wmp.dll
+ 2010-05-16 02:04 . 2011-11-04 19:20 11081728 c:\winnt\system32\dllcache\ieframe.dll
+ 2011-02-24 03:54 . 2011-01-27 05:05 17252352 c:\winnt\system32\atioglxx.dll
+ 2011-12-26 23:02 . 2011-12-26 23:02 12482048 c:\winnt\Microsoft.NET\Framework\v1.1.4322\Updates\M2656353\M2656353Uninstall.msp
+ 2010-09-24 13:08 . 2010-09-24 13:08 17518080 c:\winnt\Installer\c5e6f.msp
+ 2010-05-19 19:08 . 2010-05-19 19:08 11408896 c:\winnt\Installer\c5e3f.msp
+ 2010-03-31 07:23 . 2010-03-31 07:23 15638528 c:\winnt\Installer\c5e33.msp
+ 2010-04-12 04:17 . 2010-04-12 04:17 14599680 c:\winnt\Installer\c5e00.msp
+ 2011-07-12 01:43 . 2011-07-12 01:43 11641344 c:\winnt\Installer\c52fc379.msp
+ 2011-07-12 20:50 . 2011-07-12 20:50 17555968 c:\winnt\Installer\c52fc36e.msp
+ 2011-03-28 08:27 . 2011-03-28 08:27 15456256 c:\winnt\Installer\8bdc8571.msp
+ 2012-07-21 23:40 . 2012-07-21 23:40 16799744 c:\winnt\Installer\678e16f.msi
+ 2011-09-05 22:01 . 2011-09-05 22:01 13135872 c:\winnt\Installer\37957794.msp
+ 2011-12-26 15:02 . 2011-12-26 15:02 19677184 c:\winnt\Installer\1f3043.msp
+ 2011-06-06 17:55 . 2011-06-06 17:55 24731544 c:\winnt\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32.dll
+ 2012-01-21 09:07 . 2011-08-23 22:48 11081728 c:\winnt\ie8updates\KB2618444-IE8\ieframe.dll
+ 2011-10-27 06:16 . 2011-06-23 18:36 11081728 c:\winnt\ie8updates\KB2586448-IE8\ieframe.dll
+ 2011-09-08 03:20 . 2010-12-21 11:29 11080704 c:\winnt\ie8updates\KB2559049-IE8\ieframe.dll
+ 2011-03-01 02:32 . 2010-02-25 16:54 11070976 c:\winnt\ie8updates\KB2482017-IE8\ieframe.dll
+ 2011-10-27 06:15 . 2011-10-27 06:15 12430848 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll
+ 2012-01-21 09:19 . 2012-01-21 09:19 11817472 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Web\62e34cfb5a8b233667c7c5a47a32ad93\System.Web.ni.dll
+ 2012-01-21 09:18 . 2012-01-21 09:18 17403904 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\2dac4fc006596760cd4988d0bfd52ff0\System.ServiceModel.ni.dll
+ 2012-01-21 09:12 . 2012-01-21 09:12 10683392 c:\winnt\assembly\NativeImages_v2.0.50727_32\System.Design\9e15d80ffb037e9171fa4bd2e0233497\System.Design.ni.dll
+ 2011-10-27 06:15 . 2011-10-27 06:15 14328320 c:\winnt\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\054488924fcc579cce9fa0209dafe28b\PresentationFramework.ni.dll
+ 2011-10-27 06:14 . 2011-10-27 06:14 12215808 c:\winnt\assembly\NativeImages_v2.0.50727_32\PresentationCore\b2f0318713eca304eaa9d86fc17edb96\PresentationCore.ni.dll
+ 2011-10-27 06:14 . 2011-10-27 06:14 11490816 c:\winnt\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-01 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [2008-04-14 143360]
"NVMixerTray"="c:\program files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 131072]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"Sunkist2k"="c:\program files\GE\USB 2.0 Card Reader\shwicon2k.exe" [2005-09-07 139264]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2006-07-07 576320]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2006-07-07 600896]
"NvCplDaemon"="c:\winnt\system32\NvCpl.dll" [2006-10-22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 1622016]
"NvMediaCenter"="c:\winnt\system32\NvMcTray.dll" [2006-10-22 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"VMware hqtray"="c:\program files\VMware\VMware Player\hqtray.exe" [2010-11-11 64112]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2010-05-05 33741424]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-05-02 348624]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [2008-04-14 214528]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-6-24 113664]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-6-24 113664]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-11-6 815104]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\VMware\\VMware Player\\vmware-authd.exe"=
"c:\\WINNT\\system32\\WUAUCLT.EXE"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7639:TCP"= 7639:TCP:Remote Assistance Local
"7841:TCP"= 7841:TCP:Remote Assistance Remote
.
R0 SI3112r;Silicon Image SiI 3112 SATARaid Controller;c:\winnt\system32\drivers\SI3112r.sys [11/10/2005 6:00 PM 116264]
R3 usbfilter;AMD USB Filter Driver;c:\winnt\system32\drivers\usbfilter.sys [2/23/2011 10:55 PM 30464]
S1 avkmgr;avkmgr;c:\winnt\system32\drivers\avkmgr.sys [6/15/2012 7:50 PM 36000]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/15/2012 7:50 PM 86224]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/16/2010 11:18 AM 135664]
S2 vmci;VMware vmci;c:\winnt\system32\drivers\vmci.sys [11/11/2010 2:32 PM 70768]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files\Common Files\VMware\USB\vmware-usbarbitrator.exe [11/11/2010 1:31 PM 539248]
S3 01484335;01484335; [x]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\winnt\system32\Macromed\Flash\FlashPlayerUpdateService.exe [3/31/2012 2:10 PM 250056]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\winnt\system32\drivers\AtihdXP3.sys [2/23/2011 10:54 PM 101904]
S3 dkab_device;dkab_device;c:\winnt\system32\DKabcoms.exe -service --> c:\winnt\system32\DKabcoms.exe -service [?]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\winnt\system32\DNINDIS5.sys [5/15/2007 6:05 PM 17149]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [5/16/2010 11:18 AM 135664]
S3 sunkfilt62;USB 6/1 Driver;c:\winnt\system32\drivers\sunkfilt62.sys [12/26/2003 11:25 AM 15460]
S3 usbhub20;USB Hub Support;c:\winnt\system32\drivers\usbhub20.sys [10/13/2005 2:00 AM 49776]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\winnt\system32\drivers\viahduaa.sys [2/27/2011 10:39 AM 2134256]
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\winnt\system32\DRIVERS\WPN111.sys --> c:\winnt\system32\DRIVERS\WPN111.sys [?]
S4 Utilsiostna;Utilsiostna; [x]
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-02 c:\winnt\Tasks\Adobe Flash Player Updater.job
- c:\winnt\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 21:29]
.
2012-08-03 c:\winnt\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-16 16:18]
.
2012-08-02 c:\winnt\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-16 16:18]
.
2012-08-03 c:\winnt\Tasks\User_Feed_Synchronization-{10501041-5131-4800-9729-A31139A8BAA0}.job
- c:\winnt\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\VMware\VMware Player\vsocklib.dll
TCP: Interfaces\{4DC6E9D5-4B66-4074-951C-479C3B15BDB9}: NameServer = 192.168.1.254
TCP: Interfaces\{528C1846-201D-40FA-9412-458CD0864393}: NameServer = 192.168.1.254
DPF: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
.
Supplementary scan did not complete!
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-IEEhbDnrDIeqnkP.exe - c:\documents and settings\All Users\Application Data\IEEhbDnrDIeqnkP.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-03 17:27
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(592)
c:\winnt\system32\Ati2evxx.dll
c:\winnt\system32\atiadlxx.dll
.
Completion time: 2012-08-03 17:29:05
ComboFix-quarantined-files.txt 2010-12-20 13:30
ComboFix2.txt 2010-12-20 13:30
.
Pre-Run: 15,349,968,896 bytes free
Post-Run: 16,392,261,632 bytes free
.
- - End Of File - - 1D0C1285789786B205CB186A89CFA572
Back to top
View user's profile Send private message
Cypher
Moderator


Joined: 05 Jul 2009
Last Visit: 22 Apr 2014
Posts: 4560
Location: Land Of The Leprechauns

PostPosted: Sat Aug 04, 2012 2:03 am    Post subject: Reply with quote

Hi,
Quote:
Thanks for helping me solve this problem.

You're welcome.
Quote:
I tried to use normal mode to download and run ComboFix.exe but it was so tied up by the malware I couldn't do anything there.
I rebooted into Safe Mode with Networking. Downloaded ComboFix.exe to Desktop. Ran ComboFix.exe.

Well done, that's exactly what i would have asked you to try next Wink
Quote:
The malwarebytes installer runs, then there's an error dialog saying not authorized and it backs out of the install.

Try running MBAM now, if successful post the resulting log please.
_________________
Admin/Teacher at Malware Removal University
Member of...

Back to top
View user's profile Send private message
HerbCumbie
Junior Member


Joined: 13 Jan 2005
Last Visit: 14 Nov 2013
Posts: 49

PostPosted: Sat Aug 04, 2012 6:40 am    Post subject: Reply with quote

Cypher,

Booted into Safe Mode with Networking.

Attempted to run MBAM-SETUP.EXE from desktop. Setup started, then got two error dialogs, first said Access Denied and second said Setup not completed. Please correct problem and run setup again. The setup then rolled back and exited.

I renamed the setup file to test.exe and ran it again. When prompted for install location changed default to same location on D: drive instead of C: drive. Setup completed successfully. Ran update. Ran MBAM and ran full scan of all hard drives. Results are shown below.







Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.08.04.04

Windows XP Service Pack 3 x86 NTFS (Safe Mode/Networking)
Internet Explorer 8.0.6001.18702
Herb :: PRO1 [administrator]

8/4/2012 9:08:11 AM
mbam-log-2012-08-04 (09-47-33).txt

Scan type: Full scan (C:\|D:\|F:\|Z:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 385980
Time elapsed: 37 minute(s), 36 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\IEEhbDnrDIeqnkP.exe.vir (Trojan.FakeAlert.3CH) -> No action taken.

(end)
Back to top
View user's profile Send private message
Cypher
Moderator


Joined: 05 Jul 2009
Last Visit: 22 Apr 2014
Posts: 4560
Location: Land Of The Leprechauns

PostPosted: Sat Aug 04, 2012 7:04 am    Post subject: Reply with quote

Hi HerbCumbie,

Please go to Virustotal or jotti.org

Copy/paste this file and path into the white box at the top:
Quote:
c:\winnt\is-MOL6L.exe

Press Submit - this will submit the file for testing.
Please wait for all the scanners to finish then copy and paste the permalink (web address) in your next response.
Example of web address :


Repeat the process for this file.
Quote:
c:\winnt\is-MOL6L.exe

Please post the results in your next reply.
_________________
Admin/Teacher at Malware Removal University
Member of...

Back to top
View user's profile Send private message
HerbCumbie
Junior Member


Joined: 13 Jan 2005
Last Visit: 14 Nov 2013
Posts: 49

PostPosted: Sat Aug 04, 2012 8:33 am    Post subject: Reply with quote

Cypher,

I submitted the file to FirusTotal for analysis.

The permalink for the result of the scan is https://www.virustotal.com/file/4e17155691148fc8e84aacaca79e1c62975ffcd64e37c6f6486bf17c5454bcc9/confirmation/?ajax=false&detection-ratio=0/42&blob=AMIfv95o3pA8h0dJ6I9BsnfnQOWGeGqcoEd5T6lZQozaK868InCl6yUA-SWLUQKpe5Sr0MpzQsjRfR7xwFGNfFE4knX8fpFjfG2lLAVVeBrjTFgKDlXz-tIMpv98TsKGjnyokjAdRgmk1qxEJqHZTICTXwQqeWGuzA&last-analysis=1342486888&filename=C:%5CWINNT%5Cis-MOL6L.exe

I only sumbitted the file once. The second file you listed was the same as filename and path as the first one.

Thanks again for all your help.

Herb
Back to top
View user's profile Send private message
HerbCumbie
Junior Member


Joined: 13 Jan 2005
Last Visit: 14 Nov 2013
Posts: 49

PostPosted: Sat Aug 04, 2012 8:38 am    Post subject: Reply with quote

Cypher,

After submitting the file to VirusTotal, I decided to also submit it to Jotti. That got a bit different result:

http://virusscan.jotti.org/en/scanresult/9a37c330a88720b75c244264523bf7f61725406f
Back to top
View user's profile Send private message
Cypher
Moderator


Joined: 05 Jul 2009
Last Visit: 22 Apr 2014
Posts: 4560
Location: Land Of The Leprechauns

PostPosted: Sat Aug 04, 2012 8:45 am    Post subject: Reply with quote

Hi,
Quote:
The second file you listed was the same as filename and path as the first one.

Sorry about that, cut/paste error.
Please upload this file for testing, and post the results in your next reply.
Quote:
c:\winnt\is-FJS35.exe

Also could you let me know how your computer runs in normal mode now.
_________________
Admin/Teacher at Malware Removal University
Member of...

Back to top
View user's profile Send private message
HerbCumbie
Junior Member


Joined: 13 Jan 2005
Last Visit: 14 Nov 2013
Posts: 49

PostPosted: Sat Aug 04, 2012 9:33 am    Post subject: Reply with quote

Submitted file to VirusTotal. Results: https://www.virustotal.com/file/4e17155691148fc8e84aacaca79e1c62975ffcd64e37c6f6486bf17c5454bcc9/confirmation/?ajax=false&detection-ratio=0/41&blob=AMIfv97Oo2Vw5bN8d5UXDlAtkd1Pha1M7qnscQskM8D2u5BXAqsR4Elqglz8rtaE9DvxXI4_b_ENBvQgEX0c1VS6u1qFgIgc5pYOUUs5S1jo-qydKQ8D5EYOCNSLAaX0lZZC-h0S3P_BVIy6f6aM3G9kgT6TH5ETNA&last-analysis=1344098411&filename=C:%5CWINNT%5Cis-FJS35.exe

Also submitted to Jotti, results: http://virusscan.jotti.org/en/scanresult/9a37c330a88720b75c244264523bf7f61725406f/31eaf206d5969075af3f779c28f74953d3c52d92

Currently operating in normal mode. No sign of the effects of the malware, ie there's no popup error messages about failing hard drive, etc. Anti-virus (Avira Free) started normally and just finished updating.

Thanks again for all the help.

Herb
Back to top
View user's profile Send private message
Cypher
Moderator


Joined: 05 Jul 2009
Last Visit: 22 Apr 2014
Posts: 4560
Location: Land Of The Leprechauns

PostPosted: Sat Aug 04, 2012 9:38 am    Post subject: Reply with quote

Hi,
Quote:
Thanks again for all the help.

No problem it's my pleasure.
Quote:
Currently operating in normal mode. No sign of the effects of the malware

Excellent.
Lets run one more scan to check for any leftovers.

ESET online scannner

Note: You can use either Internet Explorer or Mozilla FireFox for this scan.

Note: If you are using Windows Vista or Windows 7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
  • First please Disable any Antivirus you have active, as shown in This topic.
  • Note: Don't forget to re-enable it after the scan.
  • Next hold down Control then click on the following link to open a new window to ESET online scannner
  • Select the option YES, I accept the Terms of Use then click on Start.
    Quote:
    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on Start.
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on Finish.
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

_________________
Admin/Teacher at Malware Removal University
Member of...

Back to top
View user's profile Send private message
HerbCumbie
Junior Member


Joined: 13 Jan 2005
Last Visit: 14 Nov 2013
Posts: 49

PostPosted: Sat Aug 04, 2012 12:08 pm    Post subject: Reply with quote

Cypher,

I tried to run the ESET scan several times from normal mode. Each time it hung up on the prompt about installing the active-x control (I had disabled the local AntiVirus).

I restarted in Safe Mode with Networking and had no problem running the scan. Here's the log file text:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=caa75ef58820654fb707497020e39523
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2012-08-04 08:14:10
# local_time=2012-08-04 03:14:10 (-0600, Central Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 51136126 51136126 0 0
# compatibility_mode=1792 16777215 100 0 3379287 3379287 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=171567
# found=1
# cleaned=0
# scan_time=2553
C:\temp\temp\kl\first stage\kazaa_lite_202_english.exe multiple threats (unable to clean) 00000000000000000000000000000000 I


Thanks again,

Herb
Back to top
View user's profile Send private message
Cypher
Moderator


Joined: 05 Jul 2009
Last Visit: 22 Apr 2014
Posts: 4560
Location: Land Of The Leprechauns

PostPosted: Sun Aug 05, 2012 1:45 am    Post subject: Reply with quote

Hi,
Do the following then give me one more update on how your computer is performing.
  • Please navigate to Start >> All Programs >> ERUNT, then double-click ERUNT from the menu.
  • Click on OK within the pop-up menu.
  • In the next menu under C:\WINDOWS\ERDNT\DD-MM-YYYY under Backup options make sure both the following are selected:
    • System registry.
    • Current user registry.
  • Next click on "OK"... at the prompt... reply "Yes".
    After a short duration the Registry backup is complete! pop-up message will appear.
  • Now click on "OK". A registry backup has now been created.

Next.

Download OTM.exe by Old Timer and save it to your Desktop.
  • Double-click OTM.exe to run it.
  • Right-click then copy the following code, Do not include the word Code.

Code:

:Reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]

:Files
C:\temp\temp\kl\first stage\kazaa_lite_202_english.exe
c:\winnt\system32\PerfStringBackup.TMP
ipconfig /flushdns /c

:Commands
[emptytemp]
[Reboot]

  • Return to OTM, right-click then paste the code into the blank box below
  • Next click on the large button.
  • OTM may ask to reboot the machine. Please do so if asked.
  • Copy everything in the Results window (under the green bar), and paste it in your next reply.


Logs/Information to Post in your Next Reply
  • OTM log.
  • Please give me an update on your computers performance.

_________________
Admin/Teacher at Malware Removal University
Member of...

Back to top
View user's profile Send private message
HerbCumbie
Junior Member


Joined: 13 Jan 2005
Last Visit: 14 Nov 2013
Posts: 49

PostPosted: Sun Aug 05, 2012 5:37 am    Post subject: Reply with quote

Cipher,

Ran ERUNT successfully. Created backup of current registry.

Downloaded OTM.ext to Desktop.

Ran OTM.ext.

Pasted in the code listed in the text box.

Clicked the MoveIt button.

OTM processed the instructions. It then prompted me to reboot.

The contents of the OTM log file are shown below:

All processes killed
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
========== FILES ==========
C:\temp\temp\kl\first stage\kazaa_lite_202_english.exe moved successfully.
c:\winnt\system32\PerfStringBackup.TMP moved successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Herb\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Herb\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Herb
->Temp folder emptied: 10649487 bytes
->Temporary Internet Files folder emptied: 49694079 bytes
->Java cache emptied: 121196 bytes
->Flash cache emptied: 110110 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: SYSTEM

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 20092 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 1195730 bytes

Total Files Cleaned = 59.00 mb


OTM by OldTimer - Version 3.1.21.0 log created on 08052012_081555


The system seems to be running close to normal. The only thing I've noticed that's out of the ordinary is that when I go to some normal websites (such as http://lumberjocks.com/) I get a dialog popup that say's "Security Alert" in the title bar and the text in the dialog says "You are about to view pages over a secure connection. Any information you exchange with this site cannot be viewed by anyone else on the web." Then there's an unchecked check box and the text "In the future, do not show this warning." and finally there's two buttons, one is "OK" and the other is "More Info"

I can cancel the dialog and continue to the site or I can OK the dialog and continue to the site. The site does NOT have a https andress. Not really sure what's going on there.

Thanks again for all your help.

Herb
Back to top
View user's profile Send private message
Cypher
Moderator


Joined: 05 Jul 2009
Last Visit: 22 Apr 2014
Posts: 4560
Location: Land Of The Leprechauns

PostPosted: Sun Aug 05, 2012 6:45 am    Post subject: Reply with quote

Hi,
Quote:
The only thing I've noticed that's out of the ordinary is that when I go to some normal websites (such as http://lumberjocks.com/) I get a dialog popup that say's "Security Alert"

Nothing to worry about there they're standard warnings, if you are having no other problems you're good to go.

Your latest set of logs appear to be clean!
This is my general post for when your logs show no more signs of malware.

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Time for some housekeeping
  • Click on Start >> Run...
  • Now type in ComboFix /Uninstall into the box and click OK.
  • Note the space between the X and the /Uninstall, it needs to be there.

The above procedure will reset your System Restore and clear out the backups and quarantines created during the course of this fix.

You can now delete any tools/logs we used if they remain on your Desktop.

Protection Programs
Don't forget to re-enable any protection programs we disabled during your fix.

Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.
You can use one of these sites to check if any updates are needed for your pc.
Secunia Software Inspector
F-secure Health Check

Visit Microsoft often to get the latest updates for your computer
You can do that HERE

Read some information HERE On how to prevent Malware

I would be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can be closed.

Safe surfing!
_________________
Admin/Teacher at Malware Removal University
Member of...

Back to top
View user's profile Send private message
HerbCumbie
Junior Member


Joined: 13 Jan 2005
Last Visit: 14 Nov 2013
Posts: 49

PostPosted: Sun Aug 05, 2012 7:53 am    Post subject: Reply with quote

Cypher,

Thank you for all the help.

Is there any place I can submit a small donation to help keep the Spyware Warrior site running? You have been helpful on several occassions over the last five to ten years and I'd like to kick in a little to help with the on going expenses.

Again, thanks for everything.

Herb Cumbie
Back to top
View user's profile Send private message
Cypher
Moderator


Joined: 05 Jul 2009
Last Visit: 22 Apr 2014
Posts: 4560
Location: Land Of The Leprechauns

PostPosted: Sun Aug 05, 2012 8:16 am    Post subject: Reply with quote

Hi,
Quote:
Thank you for all the help.

You're most welcome, glad we could help.
Quote:
Is there any place I can submit a small donation to help keep the Spyware Warrior site running? You have been helpful on several occassions over the last five to ten years and I'd like to kick in a little to help with the on going expenses.
Thank you, any and all donations are greatly appreciated.
If you have been helped and wish to donate to help with the costs of this volunteer site, please read Spyware Warrior Donations

Any questions before i close this topic?
_________________
Admin/Teacher at Malware Removal University
Member of...

Back to top
View user's profile Send private message
HerbCumbie
Junior Member


Joined: 13 Jan 2005
Last Visit: 14 Nov 2013
Posts: 49

PostPosted: Sun Aug 05, 2012 9:20 am    Post subject: Reply with quote

Cipher,

No, you've been extremely helpful and compentent. This case can be closed at your convenience.

Thanks again.

Herb
Back to top
View user's profile Send private message
Cypher
Moderator


Joined: 05 Jul 2009
Last Visit: 22 Apr 2014
Posts: 4560
Location: Land Of The Leprechauns

PostPosted: Sun Aug 05, 2012 9:32 am    Post subject: Reply with quote

Hi,
Quote:
you've been extremely helpful and compentent. This case can be closed at your convenience.

As you have no further questions i will close this topic.
Good luck and stay safe.
Quote:
As your issues appear to be resolved, this topic is now closed.

_________________
Admin/Teacher at Malware Removal University
Member of...

Back to top
View user's profile Send private message
Display posts from previous:   
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Spyware Warrior Forum Index -> Archived Spyware Removal Help Topics All times are GMT - 8 Hours
Page 1 of 1

 
Jump to:  
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



smartBlue Style © 2002 Smartor
Powered by phpBB © 2001, 2002 phpBB Group