The computer is working normally.
ComboFix 12-09-05.02 - LaVi 09/05/2012 21:28:09.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.545 [GMT -4:00]
Running from: c:\documents and settings\LaVi\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\LaVi\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\documents and settings\LaVi\Application Data\Adobe\rxsupply.sys"
"c:\documents and settings\LaVi\Local Settings\Application Data\ApplicationHistory\Adobe\xitdbv.dll"
"c:\documents and settings\LaVi\Local Settings\temp\2B.tmp"
"c:\documents and settings\LaVi\Local Settings\temp\2C.tmp"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users.WINDOWS\Application Data\3002.abs
c:\documents and settings\All Users.WINDOWS\Application Data\3002.xml
c:\documents and settings\LaVi\Application Data\Adobe\rxsupply.sys
c:\documents and settings\LaVi\Local Settings\Application Data\ApplicationHistory\Adobe\xitdbv.dll
c:\documents and settings\LaVi\Local Settings\temp\2B.tmp
c:\documents and settings\LaVi\Local Settings\temp\2C.tmp
c:\program files\Internet Explorer\SETE7.tmp
c:\program files\Internet Explorer\SETE9.tmp
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000014_.tmp.dll
c:\windows\system32\SET12E.tmp
c:\windows\system32\SET12F.tmp
c:\windows\system32\SET130.tmp
c:\windows\system32\SET2A6.tmp
c:\windows\system32\SET2AD.tmp
c:\windows\system32\SET2D6.tmp
c:\windows\system32\SET354.tmp
c:\windows\system32\SET36C.tmp
c:\windows\system32\SETCF.tmp
c:\windows\system32\SETD0.tmp
c:\windows\system32\SETD6.tmp
c:\windows\system32\SETD7.tmp
c:\windows\system32\SETD8.tmp
c:\windows\system32\SETDC.tmp
c:\windows\system32\SETDD.tmp
c:\windows\system32\SETDE.tmp
c:\windows\system32\SETE2.tmp
c:\windows\system32\SETE3.tmp
c:\windows\system32\SETE4.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_FsFilter
-------\Service_FsFilter
.
.
((((((((((((((((((((((((( Files Created from 2012-08-06 to 2012-09-06 )))))))))))))))))))))))))))))))
.
.
2012-09-05 20:16 . 2012-07-02 17:49 521728 -c----w- c:\windows\system32\dllcache\jsdbgui.dll
2012-09-05 18:51 . 2012-01-11 19:06 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2012-09-05 18:51 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\iacenc.dll
2012-09-02 06:47 . 2012-09-02 06:47 56200 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DFB8036E-2B86-4921-B9CF-174BDDACB600}\offreg.dll
2012-09-02 06:47 . 2012-09-02 06:47 29904 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DFB8036E-2B86-4921-B9CF-174BDDACB600}\MpKsla31eb478.sys
2012-09-02 06:31 . 2012-08-23 04:15 7022536 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DFB8036E-2B86-4921-B9CF-174BDDACB600}\mpengine.dll
2012-09-01 17:18 . 2012-08-23 04:15 7022536 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-31 16:40 . 2012-08-31 16:41 -------- d-----w- c:\program files\Microsoft Security Client
2012-08-26 18:55 . 2012-08-26 18:55 177496 ----a-w- c:\windows\system32\drivers\70228952.sys
2012-08-25 03:58 . 2012-08-25 03:58 -------- d-----w- c:\program files\ESET
2012-08-25 01:13 . 2012-08-26 18:55 -------- d-----w- C:\TDSSKiller_Quarantine
2012-08-11 21:40 . 2012-08-11 21:40 -------- d-----w- c:\windows\system32\wbem\Repository
2012-08-10 20:43 . 2012-08-10 20:43 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\PC Tools
2012-08-10 20:42 . 2012-08-10 20:42 -------- d-----w- c:\documents and settings\LaVi\Application Data\TestApp
2012-08-10 12:55 . 2012-08-10 12:55 -------- d-----w- c:\documents and settings\NetworkService.NT AUTHORITY.002\IECompatCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-06 02:14 . 2008-04-29 09:15 17408 ----a-w- c:\windows\system32\rpcnetp.exe
2012-09-06 02:14 . 2008-04-29 18:17 58288 ----a-w- c:\windows\system32\rpcnet.dll
2012-08-28 17:01 . 2008-04-29 19:44 17408 -c--a-w- c:\windows\system32\rpcnetp.dll
2012-08-25 01:15 . 2004-08-04 10:00 52480 ----a-w- c:\windows\system32\drivers\i8042prt.sys
2012-08-16 01:54 . 2012-08-04 12:14 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-16 01:54 . 2011-06-07 03:31 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-04 02:42 . 2012-08-04 02:42 260 ----a-w- c:\windows\system32\cmdVBS.vbs
2012-08-04 02:42 . 2012-08-04 02:42 256 ----a-w- c:\windows\system32\MSIevent.bat
2012-07-04 14:05 . 2008-04-29 19:29 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-02 17:49 . 2004-08-04 10:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-07-02 17:49 . 2004-08-04 10:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2004-08-04 10:00 385024 ----a-w- c:\windows\system32\html.iec
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2011-01-21 . 3F061815A6754C0A1C9BF3D78A14BB54 . 507904 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2011-01-21 . 3F061815A6754C0A1C9BF3D78A14BB54 . 507904 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\winlogon.exe
[7] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe
[7] 2004-08-04 . 01C3346C241652F43AED8E2149881BFE . 502272 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe
.
[-] 2011-01-21 . EAF851A4387DA45E9AC48C89FAE16A6C . 1033728 . . [6.00.2900.5512] . . c:\windows\system32\dllcache\explorer.exe
[-] 2011-01-21 . EAF851A4387DA45E9AC48C89FAE16A6C . 1033728 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2007-06-13 . 7712DF0CDDE3A5AC89843E61CD5B3658 . 1033216 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[7] 2004-08-04 . A0732187050030AE399B241436565E64 . 1032192 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe
.
((((((((((((((((((((((((((((( SnapShot@2012-08-31_04.26.36 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-14 00:17 . 2011-05-14 00:17 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_452bf920\vcomp.dll
+ 2011-05-13 23:45 . 2011-05-13 23:45 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80KOR.dll
+ 2011-05-13 23:45 . 2011-05-13 23:45 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80JPN.dll
+ 2011-05-13 23:45 . 2011-05-13 23:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ITA.dll
+ 2011-05-13 23:45 . 2011-05-13 23:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80FRA.dll
+ 2011-05-13 23:45 . 2011-05-13 23:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ESP.dll
+ 2011-05-13 23:45 . 2011-05-13 23:45 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ENU.dll
+ 2011-05-13 23:45 . 2011-05-13 23:45 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80DEU.dll
+ 2011-05-13 23:45 . 2011-05-13 23:45 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80CHT.dll
+ 2011-05-13 23:45 . 2011-05-13 23:45 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80CHS.dll
+ 2011-05-14 05:06 . 2011-05-14 05:06 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80u.dll
+ 2011-05-14 05:23 . 2011-05-14 05:23 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80.dll
+ 2011-05-13 22:37 . 2011-05-13 22:37 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_a4c618fa\ATL80.dll
+ 2012-09-06 02:14 . 2012-09-06 02:14 16384 c:\windows\Temp\Perflib_Perfdata_70.dat
- 2007-11-13 11:31 . 2010-11-03 13:12 46080 c:\windows\system32\tzchange.exe
+ 2007-11-13 11:31 . 2011-11-08 13:46 46080 c:\windows\system32\tzchange.exe
+ 2004-08-04 10:00 . 2009-10-21 05:38 75776 c:\windows\system32\strmfilt.dll
- 2004-08-04 10:00 . 2008-04-14 00:12 75776 c:\windows\system32\strmfilt.dll
+ 2004-08-04 10:00 . 2010-08-27 05:57 99840 c:\windows\system32\srvsvc.dll
+ 2004-08-04 10:00 . 2012-09-05 16:29 81198 c:\windows\system32\perfh009.dat
- 2004-08-04 10:00 . 2012-08-29 02:21 81198 c:\windows\system32\perfh009.dat
+ 2004-08-04 10:00 . 2012-09-05 16:29 76072 c:\windows\system32\perfc009.dat
- 2004-08-04 10:00 . 2012-08-29 02:21 76072 c:\windows\system32\perfc009.dat
+ 2004-08-04 10:00 . 2011-11-18 12:35 60416 c:\windows\system32\packager.exe
+ 2006-03-04 03:33 . 2012-07-02 17:49 67072 c:\windows\system32\mshtmled.dll
+ 2004-08-04 10:00 . 2012-07-02 17:49 25600 c:\windows\system32\jsproxy.dll
- 2004-08-04 10:00 . 2010-11-06 00:26 25600 c:\windows\system32\jsproxy.dll
+ 2004-08-04 10:00 . 2010-06-17 14:03 80384 c:\windows\system32\iccvid.dll
- 2004-08-04 10:00 . 2008-04-14 00:11 80384 c:\windows\system32\iccvid.dll
+ 2004-08-04 10:00 . 2009-10-21 05:38 25088 c:\windows\system32\httpapi.dll
+ 2004-08-04 10:00 . 2011-07-08 14:02 10496 c:\windows\system32\drivers\ndistapi.sys
- 2009-06-13 04:44 . 2010-11-06 00:26 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2009-06-13 04:44 . 2012-07-02 17:49 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2004-08-04 10:00 . 2009-10-21 05:38 75776 c:\windows\system32\dllcache\strmfilt.dll
- 2004-08-04 10:00 . 2008-04-14 00:12 75776 c:\windows\system32\dllcache\strmfilt.dll
+ 2010-08-27 05:57 . 2010-08-27 05:57 99840 c:\windows\system32\dllcache\srvsvc.dll
+ 2004-08-04 10:00 . 2011-11-18 12:35 60416 c:\windows\system32\dllcache\packager.exe
+ 2012-09-05 18:52 . 2011-07-08 14:02 10496 c:\windows\system32\dllcache\ndistapi.sys
+ 2006-03-04 03:33 . 2012-07-02 17:49 67072 c:\windows\system32\dllcache\mshtmled.dll
+ 2008-04-29 23:25 . 2012-07-02 17:49 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-04-29 23:25 . 2010-11-06 00:26 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2004-08-04 10:00 . 2012-07-02 17:49 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2004-08-04 10:00 . 2010-11-06 00:26 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2004-08-04 10:00 . 2010-11-06 00:26 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-04 10:00 . 2012-07-02 17:49 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-04 10:00 . 2009-10-21 05:38 25088 c:\windows\system32\dllcache\httpapi.dll
+ 2009-04-20 17:17 . 2009-04-20 17:17 45568 c:\windows\system32\dllcache\dnsrslvr.dll
- 2009-12-14 07:08 . 2009-12-14 07:08 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2009-12-14 07:08 . 2011-10-28 05:31 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2009-07-17 19:01 . 2009-07-17 19:01 58880 c:\windows\system32\dllcache\atl.dll
- 2004-08-04 10:00 . 2009-12-14 07:08 33280 c:\windows\system32\csrsrv.dll
+ 2004-08-04 10:00 . 2011-10-28 05:31 33280 c:\windows\system32\csrsrv.dll
+ 2004-08-04 10:00 . 2009-07-17 19:01 58880 c:\windows\system32\atl.dll
- 2004-08-04 10:00 . 2008-04-14 00:11 58880 c:\windows\system32\atl.dll
- 2009-01-16 23:36 . 2010-12-25 19:58 90112 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
+ 2009-01-16 23:36 . 2012-09-05 23:08 90112 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
- 2009-01-16 23:36 . 2010-12-25 19:58 45056 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2009-01-16 23:36 . 2012-09-05 23:08 45056 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
- 2009-01-16 23:36 . 2010-12-25 19:58 22528 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2009-01-16 23:36 . 2012-09-05 23:08 22528 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
- 2009-01-16 23:36 . 2010-12-25 19:58 30720 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\pptico.exe
+ 2009-01-16 23:36 . 2012-09-05 23:08 30720 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\pptico.exe
+ 2009-01-16 23:36 . 2012-09-05 23:08 16384 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
- 2009-01-16 23:36 . 2010-12-25 19:58 16384 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2009-01-16 23:36 . 2012-09-05 23:08 34304 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2009-01-16 23:36 . 2010-12-25 19:58 34304 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2009-01-16 23:36 . 2010-12-25 19:58 81920 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\fpicon.exe
+ 2009-01-16 23:36 . 2012-09-05 23:08 81920 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\fpicon.exe
+ 2009-01-31 00:18 . 2012-09-05 23:43 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2009-01-31 00:18 . 2010-12-25 19:58 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2011-10-16 18:55 . 2011-10-16 18:55 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2011-10-16 18:55 . 2012-09-05 22:39 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2009-02-26 22:43 . 2009-02-26 22:43 71520 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6612\XL12CNVP.DLL
+ 2009-02-26 21:45 . 2009-02-26 21:45 20808 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6612\WRD12EXE.EXE
+ 2009-02-26 17:06 . 2009-02-26 17:06 16712 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6612\PXBPROXY.DLL
+ 2009-02-26 17:06 . 2009-02-26 17:06 68488 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6612\PXBCOM.EXE
+ 2012-09-05 22:43 . 2010-11-06 00:26 12800 c:\windows\ie8updates\KB2722913-IE8\xpshims.dll
+ 2012-09-05 22:43 . 2010-11-06 00:26 66560 c:\windows\ie8updates\KB2722913-IE8\mshtmled.dll
+ 2012-09-05 22:43 . 2010-11-06 00:26 55296 c:\windows\ie8updates\KB2722913-IE8\msfeedsbs.dll
+ 2012-09-05 22:43 . 2010-11-06 00:26 43520 c:\windows\ie8updates\KB2722913-IE8\licmgr10.dll
+ 2012-09-05 22:43 . 2010-11-06 00:26 25600 c:\windows\ie8updates\KB2722913-IE8\jsproxy.dll
+ 2012-09-05 23:52 . 2012-09-05 23:52 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\3672938c0b0be4c6467c3992845cc7e8\UIAutomationProvider.ni.dll
+ 2012-09-05 23:43 . 2012-09-05 23:43 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\e90e8f631640971401f17ac1463bc85a\PresentationFontCache.ni.exe
+ 2012-09-05 23:39 . 2012-09-05 23:39 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\614a736dc39ce496b3c649122d3affa1\PresentationCFFRasterizer.ni.dll
+ 2012-09-04 23:48 . 2010-02-22 14:23 26488 c:\windows\$hf_mig$\KB982665\update\spcustom.dll
+ 2012-09-04 23:48 . 2010-02-22 14:23 17272 c:\windows\$hf_mig$\KB982665\spmsg.dll
+ 2010-06-17 14:02 . 2010-06-17 14:02 80384 c:\windows\$hf_mig$\KB982665\SP3QFE\iccvid.dll
+ 2012-09-05 00:12 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB981322\update\spcustom.dll
+ 2012-09-05 00:12 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB981322\spmsg.dll
+ 2012-09-05 00:10 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB974392\update\spcustom.dll
+ 2012-09-05 00:10 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB974392\spmsg.dll
+ 2012-09-05 00:12 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB973507\update\spcustom.dll
+ 2012-09-05 00:12 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB973507\spmsg.dll
+ 2009-07-17 19:25 . 2009-07-17 19:25 58880 c:\windows\$hf_mig$\KB973507\SP3QFE\atl.dll
+ 2012-09-05 00:08 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB971029\update\spcustom.dll
+ 2012-09-05 00:08 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB971029\spmsg.dll
+ 2012-09-05 00:22 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB970430\update\spcustom.dll
+ 2012-09-05 00:22 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB970430\spmsg.dll
+ 2009-10-21 05:40 . 2009-10-21 05:40 75776 c:\windows\$hf_mig$\KB970430\SP3QFE\strmfilt.dll
+ 2009-10-21 05:40 . 2009-10-21 05:40 25088 c:\windows\$hf_mig$\KB970430\SP3QFE\httpapi.dll
+ 2012-09-05 00:15 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2483185\update\spcustom.dll
+ 2012-09-05 00:15 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2483185\spmsg.dll
+ 2012-09-05 00:17 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2481109\update\spcustom.dll
+ 2012-09-05 00:17 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2481109\spmsg.dll
+ 2011-02-02 07:57 . 2011-02-02 07:57 53248 c:\windows\$hf_mig$\KB2481109\SP3QFE\tsgqec.dll
+ 2012-09-05 00:25 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2479943\update\spcustom.dll
+ 2012-09-05 00:25 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2479943\spmsg.dll
+ 2012-09-05 00:24 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2478971\update\spcustom.dll
+ 2012-09-05 00:24 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2478971\spmsg.dll
+ 2012-09-04 23:47 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2478960\update\spcustom.dll
+ 2012-09-04 23:47 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2478960\spmsg.dll
+ 2012-09-05 00:10 . 2010-02-22 14:23 26488 c:\windows\$hf_mig$\KB2419632\update\spcustom.dll
+ 2012-09-05 00:10 . 2010-02-22 14:23 17272 c:\windows\$hf_mig$\KB2419632\spmsg.dll
+ 2012-09-05 00:23 . 2010-02-22 14:23 26488 c:\windows\$hf_mig$\KB2345886\update\spcustom.dll
+ 2012-09-05 00:23 . 2010-02-22 14:23 17272 c:\windows\$hf_mig$\KB2345886\spmsg.dll
+ 2010-08-27 06:05 . 2010-08-27 06:05 99840 c:\windows\$hf_mig$\KB2345886\SP3QFE\srvsvc.dll
- 2009-04-15 14:41 . 2010-08-13 12:53 5120 c:\windows\system32\xpsp4res.dll
+ 2009-04-15 14:41 . 2010-08-26 12:52 5120 c:\windows\system32\xpsp4res.dll
- 2009-01-16 23:36 . 2010-12-25 19:58 3584 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
+ 2009-01-16 23:36 . 2012-09-05 23:08 3584 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2009-01-16 23:36 . 2010-12-25 19:58 8192 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2009-01-16 23:36 . 2012-09-05 23:08 8192 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2009-01-16 23:36 . 2012-09-05 23:08 2560 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
- 2009-01-16 23:36 . 2010-12-25 19:58 2560 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
+ 2010-08-26 12:52 . 2010-08-26 12:52 5120 c:\windows\$hf_mig$\KB2345886\SP3QFE\xpsp4res.dll
+ 2011-05-14 05:17 . 2011-05-14 05:17 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll
+ 2011-05-14 05:12 . 2011-05-14 05:12 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcp80.dll
+ 2011-05-14 05:11 . 2011-05-14 05:11 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcm80.dll
+ 2004-08-04 10:00 . 2010-04-16 15:36 406016 c:\windows\system32\usp10.dll
- 2004-08-04 10:00 . 2008-04-14 00:12 406016 c:\windows\system32\usp10.dll
- 2004-08-04 10:00 . 2008-04-14 00:12 135168 c:\windows\system32\shsvcs.dll
+ 2004-08-04 10:00 . 2009-07-27 23:17 135168 c:\windows\system32\shsvcs.dll
+ 2004-08-04 10:00 . 2011-01-21 14:44 439296 c:\windows\system32\shimgvw.dll
+ 2004-08-04 10:00 . 2011-02-09 13:53 270848 c:\windows\system32\sbe.dll
- 2004-08-04 10:00 . 2008-04-14 00:12 270848 c:\windows\system32\sbe.dll
+ 2004-08-04 10:00 . 2010-11-09 14:52 249856 c:\windows\system32\odbc32.dll
- 2004-08-04 10:00 . 2008-04-14 00:12 249856 c:\windows\system32\odbc32.dll
- 2004-08-04 10:00 . 2010-11-06 00:26 206848 c:\windows\system32\occache.dll
+ 2004-08-04 10:00 . 2012-07-02 17:49 206848 c:\windows\system32\occache.dll
- 2004-08-04 10:00 . 2008-04-14 00:12 270336 c:\windows\system32\oakley.dll
+ 2004-08-04 10:00 . 2009-10-13 10:30 270336 c:\windows\system32\oakley.dll
+ 2004-08-04 10:00 . 2010-12-09 15:15 718336 c:\windows\system32\ntdll.dll
+ 2008-04-29 19:29 . 2011-01-27 11:57 677888 c:\windows\system32\mstsc.exe
- 2008-04-29 19:29 . 2008-04-14 00:12 677888 c:\windows\system32\mstsc.exe
- 2006-03-04 03:33 . 2010-11-06 00:26 611840 c:\windows\system32\mstime.dll
+ 2006-03-04 03:33 . 2012-07-02 17:49 611840 c:\windows\system32\mstime.dll
+ 2012-08-31 16:44 . 2012-01-31 12:44 237072 c:\windows\system32\MpSigStub.exe
+ 2004-08-04 10:00 . 2011-02-08 13:33 974848 c:\windows\system32\mfc42u.dll
- 2004-08-04 10:00 . 2010-09-18 17:23 974848 c:\windows\system32\mfc42u.dll
+ 2004-08-04 10:00 . 2011-02-08 13:33 978944 c:\windows\system32\mfc42.dll
- 2004-08-04 10:00 . 2009-06-25 08:25 730112 c:\windows\system32\lsasrv.dll
+ 2004-08-04 10:00 . 2010-12-20 17:26 730112 c:\windows\system32\lsasrv.dll
+ 2004-08-04 10:00 . 2010-12-22 12:34 301568 c:\windows\system32\kerberos.dll
- 2004-08-04 10:00 . 2009-06-25 08:25 301568 c:\windows\system32\kerberos.dll
+ 2004-08-04 10:00 . 2012-02-29 14:10 148480 c:\windows\system32\imagehlp.dll
+ 2004-08-04 10:00 . 2012-07-02 17:49 387584 c:\windows\system32\iedkcs32.dll
- 2004-08-04 10:00 . 2010-11-06 00:26 387584 c:\windows\system32\iedkcs32.dll
+ 2004-08-04 10:00 . 2012-07-02 12:05 174080 c:\windows\system32\ie4uinit.exe
+ 2008-04-29 09:15 . 2012-09-06 02:11 268600 c:\windows\system32\FNTCACHE.DAT
- 2008-04-29 09:15 . 2010-12-26 02:28 268600 c:\windows\system32\FNTCACHE.DAT
+ 2004-08-04 10:00 . 2011-10-18 11:13 186880 c:\windows\system32\encdec.dll
- 2004-08-04 10:00 . 2008-04-14 00:11 186880 c:\windows\system32\encdec.dll
+ 2004-08-04 10:00 . 2011-02-17 13:18 357888 c:\windows\system32\drivers\srv.sys
+ 2004-08-04 10:00 . 2011-04-21 13:37 105472 c:\windows\system32\drivers\mup.sys
+ 2012-03-21 00:44 . 2012-03-21 00:44 171064 c:\windows\system32\drivers\MpFilter.sys
+ 2004-08-04 10:00 . 2009-10-20 16:20 265728 c:\windows\system32\drivers\http.sys
- 2004-08-04 10:00 . 2008-08-14 10:04 138496 c:\windows\system32\drivers\afd.sys
+ 2004-08-04 10:00 . 2011-08-17 13:49 138496 c:\windows\system32\drivers\afd.sys
- 2009-12-24 06:59 . 2009-12-24 06:59 177664 c:\windows\system32\dllcache\wintrust.dll
+ 2009-12-24 06:59 . 2012-02-29 14:10 177664 c:\windows\system32\dllcache\wintrust.dll
+ 2006-03-04 03:33 . 2012-07-02 17:49 916992 c:\windows\system32\dllcache\wininet.dll
+ 2004-12-05 21:52 . 2011-04-30 03:01 758784 c:\windows\system32\dllcache\vgx.dll
+ 2008-05-09 10:53 . 2011-03-04 06:37 420864 c:\windows\system32\dllcache\vbscript.dll
+ 2010-04-16 15:36 . 2010-04-16 15:36 406016 c:\windows\system32\dllcache\usp10.dll
+ 2004-08-04 10:00 . 2012-07-02 17:49 105984 c:\windows\system32\dllcache\url.dll
- 2004-08-04 10:00 . 2009-03-08 08:34 105984 c:\windows\system32\dllcache\url.dll
+ 2009-01-15 02:44 . 2011-02-17 13:18 357888 c:\windows\system32\dllcache\srv.sys
+ 2009-07-27 23:17 . 2009-07-27 23:17 135168 c:\windows\system32\dllcache\shsvcs.dll
+ 2011-01-21 14:44 . 2011-01-21 14:44 439296 c:\windows\system32\dllcache\shimgvw.dll
- 2004-08-04 10:00 . 2008-04-14 00:12 270848 c:\windows\system32\dllcache\sbe.dll
+ 2004-08-04 10:00 . 2011-02-09 13:53 270848 c:\windows\system32\dllcache\sbe.dll
+ 2008-04-29 19:29 . 2012-07-04 14:05 139784 c:\windows\system32\dllcache\rdpwd.sys
+ 2010-11-09 14:52 . 2010-11-09 14:52 249856 c:\windows\system32\dllcache\odbc32.dll
+ 2004-08-04 10:00 . 2012-07-02 17:49 206848 c:\windows\system32\dllcache\occache.dll
- 2004-08-04 10:00 . 2010-11-06 00:26 206848 c:\windows\system32\dllcache\occache.dll
+ 2009-10-13 10:30 . 2009-10-13 10:30 270336 c:\windows\system32\dllcache\oakley.dll
+ 2009-04-15 14:43 . 2010-12-09 15:15 718336 c:\windows\system32\dllcache\ntdll.dll
+ 2004-08-04 10:00 . 2011-04-21 13:37 105472 c:\windows\system32\dllcache\mup.sys
- 2008-06-20 17:46 . 2008-06-20 17:46 245248 c:\windows\system32\dllcache\mswsock.dll
+ 2008-06-20 17:46 . 2008-06-20 16:02 245248 c:\windows\system32\dllcache\mswsock.dll
+ 2006-03-04 03:33 . 2012-07-02 17:49 611840 c:\windows\system32\dllcache\mstime.dll
- 2006-03-04 03:33 . 2010-11-06 00:26 611840 c:\windows\system32\dllcache\mstime.dll
- 2004-12-05 21:52 . 2008-04-14 00:12 102400 c:\windows\system32\dllcache\msjro.dll
+ 2004-12-05 21:52 . 2010-11-09 14:52 102400 c:\windows\system32\dllcache\msjro.dll
+ 2008-04-29 23:25 . 2012-07-02 17:49 629760 c:\windows\system32\dllcache\msfeeds.dll
+ 2004-12-05 21:52 . 2010-11-09 14:52 200704 c:\windows\system32\dllcache\msadox.dll
- 2004-12-05 21:52 . 2008-04-14 00:11 200704 c:\windows\system32\dllcache\msadox.dll
+ 2004-12-05 21:52 . 2010-11-09 14:52 180224 c:\windows\system32\dllcache\msadomd.dll
- 2004-12-05 21:52 . 2008-04-14 00:11 180224 c:\windows\system32\dllcache\msadomd.dll
- 2004-12-05 21:52 . 2008-04-14 00:11 536576 c:\windows\system32\dllcache\msado15.dll
+ 2004-12-05 21:52 . 2012-05-28 18:16 536576 c:\windows\system32\dllcache\msado15.dll
+ 2004-12-05 21:52 . 2010-11-09 14:52 143360 c:\windows\system32\dllcache\msadco.dll
- 2004-12-05 21:52 . 2008-04-14 00:11 143360 c:\windows\system32\dllcache\msadco.dll
+ 2004-08-04 10:00 . 2011-02-08 13:33 974848 c:\windows\system32\dllcache\mfc42u.dll
- 2004-08-04 10:00 . 2010-09-18 17:23 974848 c:\windows\system32\dllcache\mfc42u.dll
+ 2004-08-04 10:00 . 2011-02-08 13:33 978944 c:\windows\system32\dllcache\mfc42.dll
- 2009-04-15 14:43 . 2009-06-25 08:25 730112 c:\windows\system32\dllcache\lsasrv.dll
+ 2009-04-15 14:43 . 2010-12-20 17:26 730112 c:\windows\system32\dllcache\lsasrv.dll
- 2008-04-29 19:29 . 2008-04-14 00:12 677888 c:\windows\system32\dllcache\lhmstsc.exe
+ 2008-04-29 19:29 . 2011-01-27 11:57 677888 c:\windows\system32\dllcache\lhmstsc.exe
- 2009-06-25 08:25 . 2009-06-25 08:25 301568 c:\windows\system32\dllcache\kerberos.dll
+ 2009-06-25 08:25 . 2010-12-22 12:34 301568 c:\windows\system32\dllcache\kerberos.dll
+ 2008-05-09 10:53 . 2011-03-04 06:37 726528 c:\windows\system32\dllcache\jscript.dll
- 2008-05-09 10:53 . 2009-12-09 05:53 726528 c:\windows\system32\dllcache\jscript.dll
+ 2012-02-29 14:10 . 2012-02-29 14:10 148480 c:\windows\system32\dllcache\imagehlp.dll
- 2009-06-13 04:44 . 2010-11-06 00:26 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2009-06-13 04:44 . 2012-07-02 17:49 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2006-03-04 03:33 . 2010-11-06 00:26 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2006-03-04 03:33 . 2012-07-02 17:49 184320 c:\windows\system32\dllcache\iepeers.dll
- 2010-12-25 02:00 . 2010-11-06 00:26 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2010-12-25 02:00 . 2012-07-02 17:49 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2004-08-04 10:00 . 2012-07-02 17:49 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2004-08-04 10:00 . 2010-11-06 00:26 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2004-08-04 10:00 . 2012-07-02 12:05 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2009-10-20 16:20 . 2009-10-20 16:20 265728 c:\windows\system32\dllcache\http.sys
- 2004-08-04 10:00 . 2008-04-14 00:11 186880 c:\windows\system32\dllcache\encdec.dll
+ 2004-08-04 10:00 . 2011-10-18 11:13 186880 c:\windows\system32\dllcache\encdec.dll
+ 2008-06-20 17:46 . 2011-03-03 06:55 149504 c:\windows\system32\dllcache\dnsapi.dll
+ 2012-05-31 13:22 . 2012-05-31 13:22 599040 c:\windows\system32\dllcache\crypt32.dll
+ 2010-10-28 13:13 . 2011-02-15 12:56 290432 c:\windows\system32\dllcache\atmfd.dll
- 2008-06-20 11:40 . 2008-08-14 10:04 138496 c:\windows\system32\dllcache\afd.sys
+ 2008-06-20 11:40 . 2011-08-17 13:49 138496 c:\windows\system32\dllcache\afd.sys
+ 2012-04-06 03:52 . 2012-04-06 03:52 131168 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
+ 2012-09-05 22:58 . 2012-09-05 22:58 467456 c:\windows\Installer\3e9b0bf.msi
+ 2012-08-31 16:40 . 2012-08-31 16:40 301056 c:\windows\Installer\2d322e2.msi
+ 2009-01-16 23:36 . 2012-09-05 23:08 114688 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\outicon.exe
- 2009-01-16 23:36 . 2010-12-25 19:58 114688 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\outicon.exe
- 2009-01-16 23:36 . 2010-12-25 19:58 167936 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2009-01-16 23:36 . 2012-09-05 23:08 167936 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2012-08-30 23:00 . 2012-08-31 16:41 109563 c:\windows\Installer\{0F842B77-56EA-4AAF-8295-81A022350B5E}\SCEP.exe
- 2012-08-30 23:00 . 2012-08-30 23:00 109563 c:\windows\Installer\{0F842B77-56EA-4AAF-8295-81A022350B5E}\SCEP.exe
+ 2012-08-31 16:41 . 2012-08-31 16:41 123352 c:\windows\Installer\{0F842B77-56EA-4AAF-8295-81A022350B5E}\MSE.exe
- 2012-08-30 23:00 . 2012-08-30 23:00 109563 c:\windows\Installer\{0F842B77-56EA-4AAF-8295-81A022350B5E}\INTUNE.exe
+ 2012-08-30 23:00 . 2012-08-31 16:41 109563 c:\windows\Installer\{0F842B77-56EA-4AAF-8295-81A022350B5E}\INTUNE.exe
+ 2012-08-30 23:00 . 2012-08-31 16:41 109563 c:\windows\Installer\{0F842B77-56EA-4AAF-8295-81A022350B5E}\FEP.exe
- 2012-08-30 23:00 . 2012-08-30 23:00 109563 c:\windows\Installer\{0F842B77-56EA-4AAF-8295-81A022350B5E}\FEP.exe
+ 2012-08-30 23:00 . 2012-08-31 16:41 109563 c:\windows\Installer\{0F842B77-56EA-4AAF-8295-81A022350B5E}\EPP.exe
- 2012-08-30 23:00 . 2012-08-30 23:00 109563 c:\windows\Installer\{0F842B77-56EA-4AAF-8295-81A022350B5E}\EPP.exe
+ 2010-03-31 05:16 . 2010-03-31 05:16 130408 c:\windows\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\PresentationHostDLL_X86.dll
+ 2012-09-05 22:43 . 2010-11-06 00:26 916480 c:\windows\ie8updates\KB2722913-IE8\wininet.dll
+ 2012-09-05 22:43 . 2009-03-08 08:34 105984 c:\windows\ie8updates\KB2722913-IE8\url.dll
+ 2012-09-05 22:44 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2722913-IE8\spuninst\updspapi.dll
+ 2012-09-05 22:44 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2722913-IE8\spuninst\spuninst.exe
+ 2012-09-05 22:43 . 2010-11-06 00:26 206848 c:\windows\ie8updates\KB2722913-IE8\occache.dll
+ 2012-09-05 22:43 . 2010-11-06 00:26 611840 c:\windows\ie8updates\KB2722913-IE8\mstime.dll
+ 2012-09-05 22:43 . 2010-11-06 00:26 602112 c:\windows\ie8updates\KB2722913-IE8\msfeeds.dll
+ 2012-09-05 22:43 . 2009-03-08 08:35 521216 c:\windows\ie8updates\KB2722913-IE8\jsdbgui.dll
+ 2012-09-05 22:43 . 2010-11-06 00:26 247808 c:\windows\ie8updates\KB2722913-IE8\ieproxy.dll
+ 2012-09-05 22:43 . 2010-11-06 00:26 184320 c:\windows\ie8updates\KB2722913-IE8\iepeers.dll
+ 2012-09-05 22:43 . 2010-11-06 00:26 743424 c:\windows\ie8updates\KB2722913-IE8\iedvtool.dll
+ 2012-09-05 22:43 . 2010-11-06 00:26 387584 c:\windows\ie8updates\KB2722913-IE8\iedkcs32.dll
+ 2012-09-05 22:43 . 2010-11-03 12:26 173568 c:\windows\ie8updates\KB2722913-IE8\ie4uinit.exe
+ 2012-09-05 22:32 . 2009-03-08 08:33 759296 c:\windows\ie8updates\KB2544521-IE8\vgx.dll
+ 2012-09-05 22:32 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2544521-IE8\spuninst\updspapi.dll
+ 2012-09-05 22:32 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2544521-IE8\spuninst\spuninst.exe
+ 2012-09-05 22:41 . 2010-03-10 06:15 420352 c:\windows\ie8updates\KB2510531-IE8\vbscript.dll
+ 2012-09-05 22:41 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2510531-IE8\spuninst\updspapi.dll
+ 2012-09-05 22:41 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2510531-IE8\spuninst\spuninst.exe
+ 2012-09-05 22:41 . 2009-12-09 05:53 726528 c:\windows\ie8updates\KB2510531-IE8\jscript.dll
+ 2009-10-20 16:20 . 2009-10-20 16:20 265728 c:\windows\Driver Cache\i386\http.sys
+ 2012-09-05 23:52 . 2012-09-05 23:52 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\6decc4730bac161b4cae7c8e59b59742\WindowsFormsIntegration.ni.dll
+ 2012-09-05 23:52 . 2012-09-05 23:52 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\a5003fc8367ca40672b3b425377d29c9\UIAutomationClient.ni.dll
+ 2012-09-05 23:48 . 2012-09-05 23:48 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c065edb2da7bf21a3cb5f73ab1070a10\PresentationFramework.Classic.ni.dll
+ 2012-09-05 23:48 . 2012-09-05 23:48 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\bcfc0267b35e80b21e83f29c90fc49e5\PresentationFramework.Luna.ni.dll
+ 2012-09-05 23:48 . 2012-09-05 23:48 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a5aa59449237ce28be79613522a64a52\PresentationFramework.Royale.ni.dll
+ 2012-09-05 23:46 . 2012-09-05 23:46 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\3fda6027c2d080a0bb40f3a216b32eb2\PresentationFramework.Aero.ni.dll
+ 2012-09-05 23:37 . 2012-09-05 23:37 532480 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
- 2009-02-27 00:12 . 2009-02-27 00:12 368640 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-09-05 23:37 . 2012-09-05 23:37 368640 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-09-04 23:48 . 2010-02-22 14:23 382840 c:\windows\$hf_mig$\KB982665\update\updspapi.dll
+ 2012-09-04 23:48 . 2010-02-22 14:23 755576 c:\windows\$hf_mig$\KB982665\update\update.exe
+ 2012-09-04 23:48 . 2010-02-22 14:23 231288 c:\windows\$hf_mig$\KB982665\spuninst.exe
+ 2012-09-05 00:12 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB981322\update\updspapi.dll
+ 2012-09-05 00:12 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB981322\update\update.exe
+ 2012-09-05 00:12 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB981322\spuninst.exe
+ 2010-04-16 15:29 . 2010-04-16 15:29 406016 c:\windows\$hf_mig$\KB981322\SP3QFE\usp10.dll
+ 2012-09-05 00:10 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB974392\update\updspapi.dll
+ 2012-09-05 00:10 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB974392\update\update.exe
+ 2012-09-05 00:10 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB974392\spuninst.exe
+ 2009-10-13 10:38 . 2009-10-13 10:38 270336 c:\windows\$hf_mig$\KB974392\SP3QFE\oakley.dll
+ 2012-09-05 00:12 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB973507\update\updspapi.dll
+ 2012-09-05 00:12 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB973507\update\update.exe
+ 2012-09-05 00:12 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB973507\spuninst.exe
+ 2012-09-05 00:08 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB971029\update\updspapi.dll
+ 2012-09-05 00:08 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB971029\update\update.exe
+ 2012-09-05 00:08 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB971029\spuninst.exe
+ 2009-07-27 22:13 . 2009-07-27 22:13 135168 c:\windows\$hf_mig$\KB971029\SP3QFE\shsvcs.dll
+ 2012-09-05 00:22 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB970430\update\updspapi.dll
+ 2012-09-05 00:22 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB970430\update\update.exe
+ 2012-09-05 00:22 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB970430\spuninst.exe
+ 2009-10-20 15:21 . 2009-10-20 15:21 265728 c:\windows\$hf_mig$\KB970430\SP3QFE\http.sys
+ 2012-09-05 00:15 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2483185\update\updspapi.dll
+ 2012-09-05 00:15 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2483185\update\update.exe
+ 2012-09-05 00:15 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2483185\spuninst.exe
+ 2011-01-21 14:42 . 2011-01-21 14:42 439808 c:\windows\$hf_mig$\KB2483185\SP3QFE\shimgvw.dll
+ 2012-09-05 00:17 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2481109\update\updspapi.dll
+ 2012-09-05 00:17 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2481109\update\update.exe
+ 2012-09-05 00:17 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2481109\spuninst.exe
+ 2011-01-27 11:41 . 2011-01-27 11:41 677888 c:\windows\$hf_mig$\KB2481109\SP3QFE\lhmstsc.exe
+ 2011-02-02 07:57 . 2011-02-02 07:57 136192 c:\windows\$hf_mig$\KB2481109\SP3QFE\aaclient.dll
+ 2012-09-05 00:25 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2479943\update\updspapi.dll
+ 2012-09-05 00:25 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2479943\update\update.exe
+ 2012-09-05 00:25 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2479943\spuninst.exe
+ 2011-02-09 13:52 . 2011-02-09 13:52 270848 c:\windows\$hf_mig$\KB2479943\SP3QFE\sbe.dll
+ 2011-02-09 13:52 . 2011-02-09 13:52 186880 c:\windows\$hf_mig$\KB2479943\SP3QFE\encdec.dll
+ 2012-09-05 00:24 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2478971\update\updspapi.dll
+ 2012-09-05 00:24 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2478971\update\update.exe
+ 2012-09-05 00:24 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2478971\spuninst.exe
+ 2010-12-22 12:32 . 2010-12-22 12:32 301568 c:\windows\$hf_mig$\KB2478971\SP3QFE\kerberos.dll
+ 2012-09-04 23:47 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2478960\update\updspapi.dll
+ 2012-09-04 23:47 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2478960\update\update.exe
+ 2012-09-04 23:47 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2478960\spuninst.exe
+ 2010-12-20 17:24 . 2010-12-20 17:24 730112 c:\windows\$hf_mig$\KB2478960\SP3QFE\lsasrv.dll
+ 2012-09-05 00:10 . 2010-02-22 14:23 382840 c:\windows\$hf_mig$\KB2419632\update\updspapi.dll
+ 2012-09-05 00:10 . 2010-02-22 14:23 755576 c:\windows\$hf_mig$\KB2419632\update\update.exe
+ 2012-09-05 00:10 . 2010-02-22 14:23 231288 c:\windows\$hf_mig$\KB2419632\spuninst.exe
+ 2010-11-09 14:50 . 2010-11-09 14:50 253952 c:\windows\$hf_mig$\KB2419632\SP3QFE\odbc32.dll
+ 2010-11-09 14:50 . 2010-11-09 14:50 102400 c:\windows\$hf_mig$\KB2419632\SP3QFE\msjro.dll
+ 2010-11-09 14:50 . 2010-11-09 14:50 200704 c:\windows\$hf_mig$\KB2419632\SP3QFE\msadox.dll
+ 2010-11-09 14:50 . 2010-11-09 14:50 180224 c:\windows\$hf_mig$\KB2419632\SP3QFE\msadomd.dll
+ 2010-11-09 14:50 . 2010-11-09 14:50 565248 c:\windows\$hf_mig$\KB2419632\SP3QFE\msado15.dll
+ 2010-11-09 14:50 . 2010-11-09 14:50 143360 c:\windows\$hf_mig$\KB2419632\SP3QFE\msadco.dll
+ 2012-09-05 00:23 . 2010-02-22 14:23 382840 c:\windows\$hf_mig$\KB2345886\update\updspapi.dll
+ 2012-09-05 00:23 . 2010-02-22 14:23 755576 c:\windows\$hf_mig$\KB2345886\update\update.exe
+ 2012-09-05 00:23 . 2010-02-22 14:23 231288 c:\windows\$hf_mig$\KB2345886\spuninst.exe
+ 2010-08-26 13:37 . 2010-08-26 13:37 357248 c:\windows\$hf_mig$\KB2345886\SP3QFE\srv.sys
+ 2011-05-14 00:04 . 2011-05-14 00:04 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfc80u.dll
+ 2011-05-14 00:04 . 2011-05-14 00:04 1101824 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfc80.dll
+ 2004-08-04 10:00 . 2012-04-11 13:12 1862272 c:\windows\system32\win32k.sys
+ 2004-08-04 10:00 . 2011-01-21 14:44 8462336 c:\windows\system32\shell32.dll
+ 2005-03-30 01:21 . 2012-04-11 13:14 2148352 c:\windows\system32\ntoskrnl.exe
+ 2005-03-30 01:01 . 2012-04-11 12:35 2026496 c:\windows\system32\ntkrnlpa.exe
- 2009-01-16 04:53 . 2009-07-31 15:05 1372672 c:\windows\system32\msxml6.dll
+ 2009-01-16 04:53 . 2012-06-05 15:50 1372672 c:\windows\system32\msxml6.dll
+ 2008-04-29 19:29 . 2011-02-02 07:58 2067456 c:\windows\system32\mstscax.dll
+ 2009-01-15 02:45 . 2012-04-11 13:12 1862272 c:\windows\system32\dllcache\win32k.sys
+ 2006-03-18 11:09 . 2012-07-02 17:49 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2008-06-17 19:02 . 2011-01-21 14:44 8462336 c:\windows\system32\dllcache\shell32.dll
+ 2009-01-15 02:45 . 2012-04-11 13:10 2192640 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2009-01-15 02:45 . 2012-04-11 12:35 2026496 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-01-15 02:45 . 2012-04-11 12:35 2069120 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2009-01-15 02:45 . 2012-04-11 13:14 2148352 c:\windows\system32\dllcache\ntkrnlmp.exe
- 2009-01-16 04:53 . 2009-07-31 15:05 1372672 c:\windows\system32\dllcache\msxml6.dll
+ 2009-01-16 04:53 . 2012-06-05 15:50 1372672 c:\windows\system32\dllcache\msxml6.dll
+ 2004-08-04 10:00 . 2012-06-05 15:50 1172480 c:\windows\system32\dllcache\msxml3.dll
- 2004-08-04 10:00 . 2010-06-14 07:41 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2006-03-23 17:32 . 2012-07-02 17:49 6008320 c:\windows\system32\dllcache\mshtml.dll
+ 2008-04-29 19:29 . 2011-02-02 07:58 2067456 c:\windows\system32\dllcache\lhmstscx.dll
+ 2008-04-29 23:25 . 2012-07-02 17:49 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2011-12-26 13:59 . 2011-12-26 13:59 4368896 c:\windows\Installer\3e9b175.msp
+ 2012-04-05 02:38 . 2012-04-05 02:38 3620864 c:\windows\Installer\3e9b168.msp
+ 2011-11-01 17:34 . 2011-11-01 17:34 2531840 c:\windows\Installer\3e9b11d.msp
+ 2012-04-29 01:43 . 2012-04-29 01:43 8459264 c:\windows\Installer\3e9b112.msp
+ 2011-04-28 16:23 . 2011-04-28 16:23 9607680 c:\windows\Installer\3e9b0f5.msp
+ 2011-02-25 18:25 . 2011-02-25 18:25 7968256 c:\windows\Installer\3e9b0df.msp
+ 2012-03-21 03:57 . 2012-03-21 03:57 6188544 c:\windows\Installer\3d75117.msp
+ 2012-08-31 16:41 . 2012-08-31 16:41 1826304 c:\windows\Installer\2d322e7.msi
+ 2010-03-31 05:16 . 2010-03-31 05:16 1249280 c:\windows\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\WindowsBase_x86.dll
+ 2010-12-25 19:50 . 2010-12-25 19:50 1249280 c:\windows\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\WindowsBase_GAC_x86.dll
+ 2010-03-31 05:16 . 2010-03-31 05:16 4210688 c:\windows\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\PresentationCore_x86.dll
+ 2010-12-25 19:50 . 2010-12-25 19:50 4210688 c:\windows\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\PresentationCore_GAC_x86.dll
+ 2011-07-07 06:58 . 2011-07-07 06:58 1616240 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6612\OGL.DLL
+ 2012-09-05 22:43 . 2010-11-06 00:26 1210880 c:\windows\ie8updates\KB2722913-IE8\urlmon.dll
+ 2012-09-05 22:43 . 2010-11-06 00:26 5959168 c:\windows\ie8updates\KB2722913-IE8\mshtml.dll
+ 2012-09-05 22:43 . 2010-11-06 00:26 1991680 c:\windows\ie8updates\KB2722913-IE8\iertutil.dll
+ 2009-01-15 02:45 . 2012-04-11 13:10 2192640 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2009-01-15 02:45 . 2012-04-11 12:35 2026496 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-01-15 02:45 . 2012-04-11 12:35 2069120 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-01-15 02:45 . 2012-04-11 13:14 2148352 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2012-09-05 23:40 . 2012-09-05 23:40 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\4f07a2a0c3bca965ec451174632d45e6\WindowsBase.ni.dll
+ 2012-09-05 23:52 . 2012-09-05 23:52 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\53acf4c61a887e1b998da4489af697cc\UIAutomationClientsideProviders.ni.dll
+ 2012-09-05 23:51 . 2012-09-05 23:51 1035264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\7392ea1ead49e964463c7a4ec0a685a2\System.Printing.ni.dll
+ 2012-09-05 23:49 . 2012-09-05 23:49 2146304 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\aa29cb1699a7dc73b7d006e9b5bfa823\ReachFramework.ni.dll
+ 2012-09-05 23:49 . 2012-09-05 23:49 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\92b6c02fa702d943f15732210013ee65\PresentationUI.ni.dll
- 2010-12-25 19:50 . 2010-12-25 19:50 1249280 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2012-09-05 23:37 . 2012-09-05 23:37 1249280 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2012-09-05 23:37 . 2012-09-05 23:37 5283840 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2012-09-05 23:37 . 2012-09-05 23:37 4214784 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2009-07-27 22:13 . 2009-07-27 22:13 8462848 c:\windows\$hf_mig$\KB971029\SP3QFE\shell32.dll
+ 2011-01-21 14:42 . 2011-01-21 14:42 8463360 c:\windows\$hf_mig$\KB2483185\SP3QFE\shell32.dll
+ 2011-02-02 07:57 . 2011-02-02 07:57 2069504 c:\windows\$hf_mig$\KB2481109\SP3QFE\lhmstscx.dll
+ 2008-04-29 23:25 . 2012-07-03 03:19 11111424 c:\windows\system32\dllcache\ieframe.dll
+ 2012-04-06 07:13 . 2012-04-06 07:13 16527872 c:\windows\Installer\3e9b15d.msp
+ 2011-09-15 22:37 . 2011-09-15 22:37 38176256 c:\windows\Installer\3e9b14e.msp
+ 2012-07-18 19:53 . 2012-07-18 19:53 10937344 c:\windows\Installer\3e9b0cb.msp
+ 2012-09-05 22:36 . 2012-09-05 22:36 20343808 c:\windows\Installer\3d75122.msp
+ 2012-09-05 22:43 . 2010-11-06 00:26 11080704 c:\windows\ie8updates\KB2722913-IE8\ieframe.dll
+ 2012-09-05 23:45 . 2012-09-05 23:45 14329856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\61341b67c15f121a333c7878c6f6c3be\PresentationFramework.ni.dll
+ 2012-09-05 23:42 . 2012-09-05 23:42 12218368 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\f9c1bbfa5b6a45643ed775dc68704f09\PresentationCore.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol System Monitor"="c:\program files\BillP Studios\WinPatrol\WinPatrol.exe" [2011-02-13 325000]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-14 39408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-05-16 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-05-16 162584]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2010-10-29 2498560]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-01-26 159744]
"VERIZONDM"="c:\program files\VERIZONDM\bin\sprtcmd.exe" [2012-06-02 206120]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2008-02-22 1245184]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /r \??\C:\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Ares\\chatServer.exe"=
"c:\\Documents and Settings\\LaVi\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"50000:UDP"= 50000:UDP:IHA_MessageCenter
.
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [12/19/2006 3:21 PM 79432]
R2 sprtsvc_verizondm;SupportSoft Sprocket Service (verizondm);c:\program files\VERIZONDM\bin\sprtsvc.exe [6/2/2012 6:34 AM 206120]
R2 tgsrvc_verizondm;SupportSoft Repair Service (verizondm);c:\program files\VERIZONDM\bin\tgsrvc.exe [6/2/2012 6:35 AM 185640]
S1 MpKsl80942173;MpKsl80942173;\??\c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DFB8036E-2B86-4921-B9CF-174BDDACB600}\MpKsl80942173.sys --> c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DFB8036E-2B86-4921-B9CF-174BDDACB600}\MpKsl80942173.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/25/2011 4:51 PM 135664]
S2 IHA_MessageCenter;IHA_MessageCenter;c:\program files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe [8/3/2012 4:22 PM 352248]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [8/4/2012 8:15 AM 250056]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [7/24/2009 4:06 PM 112640]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [8/25/2011 4:51 PM 135664]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [7/24/2009 4:06 PM 100480]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [9/24/2011 4:45 PM 18432]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ZSMC211
nmservice
MXOPSWD
cmuda3
tbhsd
Uim_IM
s7oppitx
akshhl
whoisd32
vmnetuserif
JGOGO
slimsvc
cdmservice
CSDriver
symantecantibotwatcher
pshost
.
Contents of the 'Scheduled Tasks' folder
.
2012-09-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-04 01:54]
.
2012-08-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2012-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-25 20:51]
.
2012-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-25 20:51]
.
2012-09-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1606980848-602609370-1417001333-1003Core.job
- c:\documents and settings\LaVi\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-09 16:42]
.
2012-09-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1606980848-602609370-1417001333-1003UA.job
- c:\documents and settings\LaVi\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-09 16:42]
.
2012-09-02 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 21:03]
.
2012-09-05 c:\windows\Tasks\User_Feed_Synchronization-{E5DE94E7-9A75-4BF0-9936-3EEE8C9D2555}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 08:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Adobe - c:\documents and settings\LaVi\Local Settings\Application Data\ApplicationHistory\Adobe\xitdbv.dll
HKU-Default-Run-Adobe - c:\documents and settings\LaVi\Local Settings\Application Data\ApplicationHistory\Adobe\xitdbv.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-09-05 22:19
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\DbgagD\1*]
"value"="?\07\01\0b\0e4\05y"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2572)
c:\windows\system32\WININET.dll
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\windows\system32\ieframe.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\mmfinfo.dll
c:\windows\system32\mkunicode.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\System32\SCardSvr.exe
c:\windows\system32\msdtc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\windows\system32\rpcnet.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\SigmaTel\C-Major Audio\WDM\StacSV.exe
c:\windows\system32\mqsvc.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Apoint\ApMsgFwd.exe
c:\program files\Apoint\HidFind.exe
c:\program files\Apoint\Apntex.exe
c:\program files\Digital Line Detect\DLG.exe
c:\progra~1\COMMON~1\MICROS~1\DW\DW20.EXE
.
**************************************************************************
.
Completion time: 2012-09-05 23:42:01 - machine was rebooted
ComboFix-quarantined-files.txt 2012-09-06 03:41
ComboFix2.txt 2012-08-31 04:39
ComboFix3.txt 2011-01-30 04:40
.
Pre-Run: 26,573,402,112 bytes free
Post-Run: 26,822,836,224 bytes free
.
- - End Of File - - 53E1031B5EDE44DDF4A78885751B6DDF