Hello,
I ran combofix. The first time it wanted to restart it told me not to restart my computer itself and to let combofix restart it...but then it never restarted to I had to restart it myself.
ComboFix 11-09-02.04 - Loralee 09/02/2011 16:20:14.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1700 [GMT -4:00]
Running from: c:\documents and settings\Loralee\Desktop\ComboFix.exe
AV: Sophos Anti-Virus *Disabled/Updated* {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\$NtUninstallKB13835$
c:\windows\$NtUninstallKB13835$\1068889665\{1B372133-BFFA-4dba-9CCF-5474BED6A9F6}
c:\windows\$NtUninstallKB13835$\1068889665\click.tlb
c:\windows\$NtUninstallKB13835$\1068889665\L\bietimfh
c:\windows\$NtUninstallKB13835$\1068889665\loader.tlb
c:\windows\$NtUninstallKB13835$\1068889665\U\@00000001
c:\windows\$NtUninstallKB13835$\1068889665\U\@000000c0
c:\windows\$NtUninstallKB13835$\1068889665\U\@000000cb
c:\windows\$NtUninstallKB13835$\1068889665\U\@000000cf
c:\windows\$NtUninstallKB13835$\1068889665\U\@80000000
c:\windows\$NtUninstallKB13835$\1068889665\U\@800000c0
c:\windows\$NtUninstallKB13835$\1068889665\U\@800000cb
c:\windows\$NtUninstallKB13835$\1068889665\U\@800000cf
c:\windows\$NtUninstallKB13835$\1190037264
c:\windows\system32\c_22035.nls
c:\windows\system32\mfc100deu.dll
c:\windows\system32\sdccoinstaller.dll.stf00
.
Infected copy of c:\windows\system32\drivers\i8042prt.sys was found and disinfected
Restored copy from - The cat found it
Infected copy of c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024379.exe
.
Infected copy of c:\program files\Bonjour\mDNSResponder.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024378.exe
.
Infected copy of c:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024369.exe
.
Infected copy of c:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024377.exe
.
Infected copy of c:\program files\iPod\bin\iPodService.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024368.exe
.
Infected copy of c:\program files\Java\jre6\bin\jqs.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024376.exe
.
Infected copy of c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024375.EXE
.
Infected copy of c:\windows\system32\nvsvc32.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024382.exe
.
Infected copy of c:\program files\O2Micro Flash Memory Card Driver\o2flash.exe was found and disinfected
Restored copy from - c:\windows\system32\DRVSTORE\o2media_8ECA1613F5F621521A4B7367D36D43A53F39A779\o2flash.exe
.
Infected copy of c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024373.exe
.
Infected copy of c:\program files\Sophos\Remote Management System\ManagementAgentNT.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024372.exe
.
Infected copy of c:\program files\Sophos\AutoUpdate\ALsvc.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024371.exe
.
Infected copy of c:\program files\Sophos\Remote Management System\RouterNT.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024370.exe
.
Infected copy of c:\windows\System32\WLTRYSVC.EXE was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024381.EXE
.
Infected copy of c:\windows\system32\nvsvc32.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024382.exe
Infected copy of c:\program files\Sophos\Remote Management System\ManagementAgentNT.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024372.exe
Infected copy of c:\program files\Sophos\Remote Management System\RouterNT.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024370.exe
Infected copy of c:\windows\System32\WLTRYSVC.EXE was found and disinfected
Restored copy from - c:\system volume information\_restore{DC982EDD-C6E9-473F-8D87-4DB87B8309C0}\RP30\A0024381.EXE
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_3fb5f641
.
.
((((((((((((((((((((((((( Files Created from 2011-08-02 to 2011-09-02 )))))))))))))))))))))))))))))))
.
.
2011-09-02 20:36 . 2011-09-02 20:36 1893 ----a-w- c:\windows\bcmwltrytmp.reg
2011-09-02 20:11 . 2008-04-14 04:48 52480 -c--a-w- c:\windows\system32\dllcache\i8042prt.sys
2011-09-02 20:11 . 2008-04-14 04:48 52480 ----a-w- c:\windows\system32\drivers\i8042prt.sys
2011-08-27 01:20 . 2011-08-27 12:23 45328 --sha-w- c:\windows\system32\c_22035.nl_
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-27 12:22 . 2008-04-14 04:49 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-08-27 02:28 . 2010-01-25 10:31 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-08-27 01:31 . 2008-04-14 04:10 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2011-08-27 00:26 . 2008-04-14 04:47 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-03 22:24 . 2011-07-03 22:47 447752 ----a-w- c:\windows\system32\vp6vfw.dll
2011-08-12 05:57 . 2011-05-11 05:47 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
<pre>
c:\program files\Common Files\Java\Java Update\jusched .exe
c:\program files\Sophos\AutoUpdate\almon .exe
c:\windows\system32\rundll32 .exe
</pre>
.
((((((((((((((((((((((((((((( SnapShot_2011-05-05_21.28.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-12-02 04:46 . 2006-12-02 04:46 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2006-12-02 04:08 . 2006-12-02 04:08 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2006-12-02 04:26 . 2006-12-02 04:26 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
+ 2006-12-02 04:25 . 2006-12-02 04:25 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
+ 2011-09-02 20:36 . 2011-09-02 20:36 16384 c:\windows\Temp\Perflib_Perfdata_920.dat
+ 2011-09-02 20:35 . 2011-09-02 20:35 16384 c:\windows\Temp\Perflib_Perfdata_704.dat
+ 2011-02-20 03:03 . 2011-02-20 03:03 51024 c:\windows\system32\vcomp100.dll
+ 2011-05-09 20:45 . 2011-05-09 20:43 28912 c:\windows\system32\SophosBootTasks.exe
- 2011-03-24 20:43 . 2010-07-23 17:31 28912 c:\windows\system32\SophosBootTasks.exe
+ 2004-08-04 10:00 . 2011-08-27 04:31 59400 c:\windows\system32\perfc009.dat
+ 2010-01-25 19:36 . 2011-07-14 04:54 94513 c:\windows\system32\nvModes.dat
+ 2005-09-23 11:28 . 2005-09-23 11:28 32768 c:\windows\system32\netfxperf.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 74240 c:\windows\system32\mscories.dll
+ 2011-02-20 03:03 . 2011-02-20 03:03 81744 c:\windows\system32\mfcm100u.dll
+ 2011-02-20 03:03 . 2011-02-20 03:03 81744 c:\windows\system32\mfcm100.dll
+ 2011-02-20 03:03 . 2011-02-20 03:03 60752 c:\windows\system32\mfc100rus.dll
+ 2011-02-20 03:03 . 2011-02-20 03:03 43344 c:\windows\system32\mfc100kor.dll
+ 2011-02-20 03:03 . 2011-02-20 03:03 43856 c:\windows\system32\mfc100jpn.dll
+ 2011-02-20 03:03 . 2011-02-20 03:03 62288 c:\windows\system32\mfc100ita.dll
+ 2011-02-20 03:03 . 2011-02-20 03:03 64336 c:\windows\system32\mfc100fra.dll
+ 2011-02-20 03:03 . 2011-02-20 03:03 63824 c:\windows\system32\mfc100esn.dll
+ 2011-02-20 03:03 . 2011-02-20 03:03 55120 c:\windows\system32\mfc100enu.dll
+ 2011-02-20 03:03 . 2011-02-20 03:03 36176 c:\windows\system32\mfc100cht.dll
+ 2011-02-20 03:03 . 2011-02-20 03:03 36176 c:\windows\system32\mfc100chs.dll
+ 2011-04-26 06:07 . 2011-04-26 06:07 98304 c:\windows\system32\Macromed\Shockwave 10\SwOnce.dll
+ 2011-04-26 06:07 . 2011-04-26 06:07 86016 c:\windows\system32\Macromed\Shockwave 10\SwMenuX.dll
+ 2011-04-26 06:07 . 2011-04-26 06:07 77824 c:\windows\system32\Macromed\Shockwave 10\SwInit.exe
+ 2011-04-26 06:07 . 2011-04-26 06:07 64512 c:\windows\system32\Macromed\Shockwave 10\gcapi_dll.dll
+ 2011-04-26 06:07 . 2011-04-26 06:07 24576 c:\windows\system32\Macromed\Shockwave 10\DynaPlayer.dll
+ 2011-05-09 20:43 . 2011-05-09 20:43 14976 c:\windows\system32\drivers\SophosBootDriver.sys
- 2011-03-24 20:42 . 2008-05-23 07:38 14976 c:\windows\system32\drivers\SophosBootDriver.sys
+ 2011-05-09 20:43 . 2011-05-09 20:43 23928 c:\windows\system32\drivers\sdcfilter.sys
+ 2011-05-09 20:43 . 2011-05-09 20:43 24064 c:\windows\system32\drivers\savonaccessfilter.sys
- 2011-03-24 20:42 . 2010-10-08 14:14 24064 c:\windows\system32\drivers\savonaccessfilter.sys
+ 2005-09-23 11:28 . 2005-09-23 11:28 83456 c:\windows\system32\dfshim.dll
+ 2011-05-07 21:02 . 2011-05-07 21:02 64000 c:\windows\system32\config\systemprofile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
+ 2005-09-23 11:28 . 2005-09-23 11:28 28160 c:\windows\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 71680 c:\windows\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL
+ 2005-09-23 11:28 . 2005-09-23 11:28 86016 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 47616 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 85504 c:\windows\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 59072 c:\windows\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 53248 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 78336 c:\windows\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 14848 c:\windows\Microsoft.NET\Framework\v2.0.50727\normalization.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 96440 c:\windows\Microsoft.NET\Framework\v2.0.50727\ngen.exe
+ 2005-09-23 11:29 . 2005-09-23 11:29 22528 c:\windows\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 10240 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscortim.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 66240 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 67072 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 81408 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorld.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorie.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 73216 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 87552 c:\windows\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 12800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 73728 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
+ 2005-09-23 10:36 . 2005-09-23 10:36 85504 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.3082.dll
+ 2005-09-23 10:29 . 2005-09-23 10:29 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.3076.dll
+ 2005-09-23 10:47 . 2005-09-23 10:47 84480 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.2070.dll
+ 2005-09-23 10:30 . 2005-09-23 10:30 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.2052.dll
+ 2005-09-23 10:47 . 2005-09-23 10:47 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1055.dll
+ 2005-09-23 10:47 . 2005-09-23 10:47 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1053.dll
+ 2005-09-23 10:47 . 2005-09-23 10:47 82432 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1049.dll
+ 2005-09-23 10:47 . 2005-09-23 10:47 82432 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1046.dll
+ 2005-09-23 10:46 . 2005-09-23 10:46 83456 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1045.dll
+ 2005-09-23 10:46 . 2005-09-23 10:46 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1044.dll
+ 2005-09-23 10:46 . 2005-09-23 10:46 83456 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1043.dll
+ 2005-09-23 10:44 . 2005-09-23 10:44 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1042.dll
+ 2005-09-23 10:42 . 2005-09-23 10:42 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1041.dll
+ 2005-09-23 10:40 . 2005-09-23 10:40 84480 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1040.dll
+ 2005-09-23 10:40 . 2005-09-23 10:40 83968 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1038.dll
+ 2005-09-23 10:40 . 2005-09-23 10:40 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1037.dll
+ 2005-09-23 10:38 . 2005-09-23 10:38 86016 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1036.dll
+ 2005-09-23 10:38 . 2005-09-23 10:38 81408 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1035.dll
+ 2005-09-23 07:46 . 2005-09-23 07:46 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1033.dll
+ 2005-09-23 10:36 . 2005-09-23 10:36 87552 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1032.dll
+ 2005-09-23 10:34 . 2005-09-23 10:34 85504 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1031.dll
+ 2005-09-23 10:34 . 2005-09-23 10:34 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1030.dll
+ 2005-09-23 10:34 . 2005-09-23 10:34 82944 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1029.dll
+ 2005-09-23 10:32 . 2005-09-23 10:32 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1028.dll
+ 2005-09-23 10:29 . 2005-09-23 10:29 80896 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1025.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 40960 c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 72192 c:\windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 55296 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEHost.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 52736 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfdll.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 31936 c:\windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 68608 c:\windows\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 17920 c:\windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 13312 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 76984 c:\windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 88576 c:\windows\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 29888 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 29896 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 26824 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 13824 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 70656 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 23552 c:\windows\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 10752 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 55488 c:\windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 87552 c:\windows\Microsoft.NET\Framework\v2.0.50727\alink.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 10752 c:\windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 18944 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 86528 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 72704 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
+ 2011-05-09 20:44 . 2011-05-09 20:44 25214 c:\windows\Installer\{FED1005D-CBC8-45D5-A288-FFC7BB304121}\ARPPRODUCTICON.exe
+ 2011-05-09 20:46 . 2011-08-03 14:24 25214 c:\windows\Installer\{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}\MainGUIShortcut.exe
- 2011-03-24 20:44 . 2011-05-04 21:56 25214 c:\windows\Installer\{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}\MainGUIShortcut.exe
- 2011-03-24 20:44 . 2011-05-04 21:56 25214 c:\windows\Installer\{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}\ARPPRODUCTICON.exe
+ 2011-05-09 20:46 . 2011-08-03 14:24 25214 c:\windows\Installer\{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}\ARPPRODUCTICON.exe
+ 2011-05-12 00:00 . 2011-05-12 00:00 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2011-04-14 00:05 . 2011-04-14 00:05 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2010-01-25 18:33 . 2011-04-14 00:08 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2010-01-25 18:33 . 2011-05-12 00:01 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2010-01-25 18:33 . 2011-05-12 00:01 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2010-01-25 18:33 . 2011-04-14 00:08 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2010-01-25 18:33 . 2011-05-12 00:01 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2010-01-25 18:33 . 2011-04-14 00:08 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2010-01-25 18:33 . 2011-04-14 00:08 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2010-01-25 18:33 . 2011-05-12 00:01 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2010-01-25 18:33 . 2011-04-14 00:08 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2010-01-25 18:33 . 2011-05-12 00:01 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2010-01-25 18:33 . 2011-04-14 00:08 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2010-01-25 18:33 . 2011-05-12 00:01 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2011-05-09 20:42 . 2011-05-09 20:48 65536 c:\windows\Installer\{15C418EB-7675-42be-B2B3-281952DA014D}\ARPPRODUCTICON.exe
- 2011-03-15 13:13 . 2011-03-23 16:57 65536 c:\windows\Installer\{15C418EB-7675-42be-B2B3-281952DA014D}\ARPPRODUCTICON.exe
+ 2011-07-04 04:40 . 2011-07-04 04:40 81920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\0acf4c83a6b7cb429bf2028e12fb185e\Microsoft.Build.Framework.ni.dll
+ 2011-07-04 04:40 . 2011-07-04 04:40 15360 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\246888fafabd274a9f20ed801a61d266\dfsvc.ni.exe
+ 2011-07-04 04:39 . 2011-07-04 04:39 26624 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\3d61de94f004114b89b9cddb9b523be5\Accessibility.ni.dll
+ 2011-07-03 22:35 . 2011-07-03 22:35 86016 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-07-03 22:35 . 2011-07-03 22:35 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2011-07-03 22:35 . 2011-07-03 22:35 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-07-03 22:34 . 2011-07-03 22:34 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2011-07-03 22:34 . 2011-07-03 22:34 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2011-07-03 22:33 . 2011-07-03 22:33 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-07-03 22:35 . 2011-07-03 22:35 73728 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2011-07-03 22:34 . 2011-07-03 22:34 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-07-03 22:36 . 2011-07-03 22:36 36864 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2011-07-03 22:34 . 2011-07-03 22:34 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2011-07-03 22:35 . 2011-07-03 22:35 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2011-07-03 22:36 . 2011-07-03 22:36 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2011-07-03 22:35 . 2011-07-03 22:35 68608 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 6144 c:\windows\system32\mui\0409\mscorees.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 7680 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 9216 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 7168 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 5632 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 5632 c:\windows\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 8192 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 9728 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 9216 c:\windows\Microsoft.NET\Framework\v2.0.50727\fusion.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 4608 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 8192 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 4608 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 7680 c:\windows\Microsoft.NET\Framework\SharedReg12.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 7680 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 7680 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 7680 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 5120 c:\windows\Microsoft.NET\Framework\sbs_wminet_utils.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 5120 c:\windows\Microsoft.NET\Framework\sbs_VsaVb7rt.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 5120 c:\windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 5120 c:\windows\Microsoft.NET\Framework\sbs_system.data.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 5120 c:\windows\Microsoft.NET\Framework\sbs_system.configuration.install.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 5120 c:\windows\Microsoft.NET\Framework\sbs_mscorsec.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 5120 c:\windows\Microsoft.NET\Framework\sbs_mscorrc.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 5120 c:\windows\Microsoft.NET\Framework\sbs_mscordbi.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 5632 c:\windows\Microsoft.NET\Framework\sbs_microsoft.vsa.vb.codedomprocessor.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 5120 c:\windows\Microsoft.NET\Framework\sbs_microsoft.jscript.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 5120 c:\windows\Microsoft.NET\Framework\sbs_iehost.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 5120 c:\windows\Microsoft.NET\Framework\sbs_diasymreader.dll
- 2010-01-25 18:33 . 2011-04-14 00:08 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2010-01-25 18:33 . 2011-05-12 00:01 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2011-07-03 22:34 . 2011-07-03 22:34 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2011-07-03 22:37 . 2011-07-03 22:37 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-07-03 22:36 . 2011-07-03 22:36 5632 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2011-07-03 22:36 . 2011-07-03 22:36 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2011-07-03 22:34 . 2011-07-03 22:34 114176 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2011-07-03 22:34 . 2011-07-03 22:34 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2011-05-09 20:46 . 2011-05-09 20:43 131824 c:\windows\system32\sdccoinstaller.dll
+ 2004-08-04 10:00 . 2011-08-27 04:31 393432 c:\windows\system32\perfh009.dat
+ 2011-02-19 04:40 . 2011-02-19 04:40 773968 c:\windows\system32\msvcr100.dll
+ 2011-02-20 03:03 . 2011-02-20 03:03 421200 c:\windows\system32\msvcp100.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 150016 c:\windows\system32\mscorier.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 270848 c:\windows\system32\mscoree.dll
+ 2011-04-26 06:07 . 2011-04-26 06:07 136568 c:\windows\system32\Macromed\Shockwave 10\SCC.dll
+ 2011-04-26 06:07 . 2011-04-26 06:07 180224 c:\windows\system32\Macromed\Shockwave 10\Proj.dll
+ 2011-04-26 06:07 . 2011-04-26 06:07 475136 c:\windows\system32\Macromed\Shockwave 10\PluginPing.dll
+ 2011-04-26 06:07 . 2011-04-26 06:07 339968 c:\windows\system32\Macromed\Shockwave 10\Plugin.dll
+ 2011-04-26 06:07 . 2011-04-26 06:07 606208 c:\windows\system32\Macromed\Shockwave 10\iml32X.dll
+ 2011-04-26 06:53 . 2011-04-26 06:53 880640 c:\windows\system32\Macromed\Shockwave 10\gi.dll
+ 2011-04-26 06:07 . 2011-04-26 06:07 471040 c:\windows\system32\Macromed\Shockwave 10\Control.dll
+ 2011-05-09 20:43 . 2011-05-09 20:43 153344 c:\windows\system32\drivers\savonaccesscontrol.sys
- 2011-03-24 20:42 . 2010-10-08 14:14 153344 c:\windows\system32\drivers\savonaccesscontrol.sys
+ 2011-05-07 19:40 . 2011-05-07 19:40 115200 c:\windows\system32\c_10081Q.dll
+ 2011-02-20 03:03 . 2011-02-20 03:03 138056 c:\windows\system32\atl100.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 298496 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 823296 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 835584 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 260096 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 114688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 131072 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 299008 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 368640 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Management.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 114176 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 700416 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 188416 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 397312 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 884736 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 716800 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 482304 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 389120 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 377344 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 107520 c:\windows\Microsoft.NET\Framework\v2.0.50727\shfusion.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 136192 c:\windows\Microsoft.NET\Framework\v2.0.50727\peverify.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 226816 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 330752 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 102400 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 326144 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 288768 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 800768 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 667648 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 372736 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 745472 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 647168 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 413696 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll
+ 2005-09-23 11:57 . 2005-09-23 11:57 245408 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\unicows.dll
+ 2005-09-23 11:01 . 2005-09-23 11:01 609472 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 224952 c:\windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 788992 c:\windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 547840 c:\windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 503808 c:\windows\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 138240 c:\windows\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 208896 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 183808 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 136192 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll
+ 2011-05-09 20:44 . 2011-05-09 20:44 801792 c:\windows\Installer\bfa36.msi
+ 2011-07-03 22:47 . 2011-07-03 22:47 331264 c:\windows\Installer\6216ea71.msi
+ 2011-07-03 18:46 . 2011-07-03 18:46 160768 c:\windows\Installer\613c660f.msi
+ 2011-08-28 23:41 . 2011-08-28 23:41 332288 c:\windows\Installer\101227c.msi
- 2010-01-25 18:33 . 2011-04-14 00:08 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2010-01-25 18:33 . 2011-05-12 00:01 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2010-01-25 18:33 . 2011-04-14 00:08 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2010-01-25 18:33 . 2011-05-12 00:01 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2010-01-25 18:33 . 2011-04-14 00:08 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2010-01-25 18:33 . 2011-05-12 00:01 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2010-01-25 18:33 . 2011-05-12 00:01 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2010-01-25 18:33 . 2011-04-14 00:08 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2010-01-25 18:33 . 2011-04-14 00:08 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2010-01-25 18:33 . 2011-05-12 00:01 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2010-01-25 18:33 . 2011-04-14 00:08 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2010-01-25 18:33 . 2011-05-12 00:01 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2011-07-04 04:44 . 2011-07-04 04:44 237568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\72862b99e0e5cf4ea7ee46c93270b5de\System.Web.RegularExpressions.ni.dll
+ 2011-07-04 04:42 . 2011-07-04 04:42 684032 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\64b6bccf63924e458817b8c169f6d313\System.Transactions.ni.dll
+ 2011-07-04 04:41 . 2011-07-04 04:41 729088 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\ad4d8cc1649adb4290b88c1c9163f525\System.Security.ni.dll
+ 2011-07-04 04:41 . 2011-07-04 04:41 294912 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\5ebaa386fb994347a445e1401a4f9e12\System.EnterpriseServices.Wrapper.dll
+ 2011-07-04 04:41 . 2011-07-04 04:41 659456 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\5ebaa386fb994347a445e1401a4f9e12\System.EnterpriseServices.ni.dll
+ 2011-07-03 22:42 . 2011-07-03 22:42 229376 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\ae4fa2b492928d479d11354306b9ef3c\System.Drawing.Design.ni.dll
+ 2011-07-04 04:41 . 2011-07-04 04:41 512000 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\cb6561bc26fa094899834179e60574b5\System.DirectoryServices.Protocols.ni.dll
+ 2011-07-04 04:41 . 2011-07-04 04:41 962560 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\28a001aa39cd58468b0ada6760783f67\System.Configuration.ni.dll
+ 2011-07-04 04:40 . 2011-07-04 04:40 163840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\0d9d97fda12dc24d9ab569fa9faed2cb\Microsoft.Build.Utilities.ni.dll
+ 2011-07-04 04:40 . 2011-07-04 04:40 880640 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\acb51fa128e4924f8634b889d2f6d6ea\Microsoft.Build.Engine.ni.dll
+ 2011-07-04 04:40 . 2011-07-04 04:40 237568 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\311f40778973a84d81c63e6fa72d6d6f\CustomMarshalers.ni.dll
+ 2011-07-04 04:40 . 2011-07-04 04:40 860160 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\d05984abfe6c3d438d832f09d3b764d1\AspNetMMCExt.ni.dll
+ 2011-07-03 22:35 . 2011-07-03 22:35 823296 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2011-07-03 22:37 . 2011-07-03 22:37 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2011-07-03 22:35 . 2011-07-03 22:35 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2011-07-03 22:35 . 2011-07-03 22:35 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-07-03 22:36 . 2011-07-03 22:36 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2011-07-03 22:36 . 2011-07-03 22:36 299008 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2011-07-03 22:37 . 2011-07-03 22:37 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2011-07-03 22:36 . 2011-07-03 22:36 368640 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2011-07-03 22:37 . 2011-07-03 22:37 700416 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2011-07-03 22:35 . 2011-07-03 22:35 397312 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2011-07-03 22:35 . 2011-07-03 22:35 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2011-07-03 22:34 . 2011-07-03 22:34 884736 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2011-07-03 22:36 . 2011-07-03 22:36 716800 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2011-07-03 22:36 . 2011-07-03 22:36 389120 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2011-07-03 22:36 . 2011-07-03 22:36 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-07-03 22:47 . 2011-07-03 22:47 884736 c:\windows\assembly\GAC_MSIL\Microsoft.Web.Services3\3.0.0.0__31bf3856ad364e35\Microsoft.Web.Services3.dll
+ 2011-07-03 22:37 . 2011-07-03 22:37 667648 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2011-07-03 22:37 . 2011-07-03 22:37 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2011-07-03 22:37 . 2011-07-03 22:37 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2011-07-03 22:34 . 2011-07-03 22:34 745472 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2011-07-03 22:35 . 2011-07-03 22:35 647168 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2011-07-03 22:34 . 2011-07-03 22:34 413696 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2011-07-03 22:34 . 2011-07-03 22:34 503808 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2011-07-03 22:37 . 2011-07-03 22:37 260096 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2011-07-03 22:36 . 2011-07-03 22:36 482304 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2006-12-02 04:25 . 2006-12-02 04:25 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
+ 2006-12-02 04:25 . 2006-12-02 04:25 1101824 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
+ 2011-02-20 03:03 . 2011-02-20 03:03 4422992 c:\windows\system32\mfc100u.dll
+ 2011-02-20 03:03 . 2011-02-20 03:03 4397384 c:\windows\system32\mfc100.dll
+ 2011-04-27 09:55 . 2011-04-27 09:55 1495040 c:\windows\system32\Macromed\Shockwave 10\dirapiX.dll
+ 2010-01-25 16:13 . 2008-06-02 16:42 1966080 c:\windows\system32\BCMWLTRY.EXE
+ 2005-09-23 11:28 . 2005-09-23 11:28 1306624 c:\windows\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll
+ 2005-09-23 11:29 . 2005-09-23 11:29 1140920 c:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
+ 2005-09-23 11:28 . 2005-09-23 11:28 2035712 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 5316608 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 3018752 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 5050368 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 2878976 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 5615616 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 4308992 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2005-09-23 11:28 . 2005-09-23 11:28 1144832 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscomp.dll
+ 2011-05-09 20:48 . 2011-05-09 20:48 1554944 c:\windows\Installer\bfa9c.msi
+ 2011-04-27 15:14 . 2011-04-27 15:14 5520384 c:\windows\Installer\aa7fc64.msp
+ 2011-04-29 17:04 . 2011-04-29 17:04 5053440 c:\windows\Installer\aa7fc4f.msp
+ 2011-04-29 16:30 . 2011-04-29 16:30 1197056 c:\windows\Installer\aa7fc39.msp
+ 2011-07-03 22:47 . 2011-07-03 22:47 1013248 c:\windows\Installer\6216ea77.msi
+ 2011-07-03 22:38 . 2011-07-03 22:38 2109440 c:\windows\Installer\62089184.msi
+ 2011-08-03 14:24 . 2011-08-03 14:24 2959360 c:\windows\Installer\3da2b788.msi
+ 2011-07-03 22:41 . 2011-07-03 22:41 8093696 c:\windows\assembly\NativeImages_v2.0.50727_32\System\cfaba39313978d4ab2312c443d1a286d\System.ni.dll
+ 2011-07-03 22:43 . 2011-07-03 22:43 5640192 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\e8763c6a2dd53143a52d7b34324abace\System.Xml.ni.dll
+ 2011-07-04 04:44 . 2011-07-04 04:44 1945600 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\91ce60323969a442b2de44137086c688\System.Web.Services.ni.dll
+ 2011-07-04 04:44 . 2011-07-04 04:44 2310144 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\b5679ed0e953264cbe2c68b65ef3cbc0\System.Web.Mobile.ni.dll
+ 2011-07-03 22:42 . 2011-07-03 22:42 1626112 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3ad70b8a88c64c4d80f08054377445ea\System.Drawing.ni.dll
+ 2011-07-04 04:41 . 2011-07-04 04:41 1220608 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\6a9073a80e4a53478e4efb10bb390ddb\System.DirectoryServices.ni.dll
+ 2011-07-04 04:41 . 2011-07-04 04:41 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\f16df9a63e20b14d9b881abf6072105d\System.Deployment.ni.dll
+ 2011-07-03 22:43 . 2011-07-03 22:43 6688768 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\bfa81bc07aab4d4993f55ce03d1ce0dd\System.Data.ni.dll
+ 2011-07-04 04:41 . 2011-07-04 04:41 1724416 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\7cf7c38b94b88b45b8f42ce645f26f63\Microsoft.VisualBasic.ni.dll
+ 2011-07-04 04:40 . 2011-07-04 04:40 1691648 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\d005b57102137541a7251735f64880b8\Microsoft.Build.Tasks.ni.dll
+ 2011-07-03 22:36 . 2011-07-03 22:36 3018752 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2011-07-03 22:35 . 2011-07-03 22:35 2035712 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2011-07-03 22:35 . 2011-07-03 22:35 5316608 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2011-07-03 22:36 . 2011-07-03 22:36 5050368 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2011-07-03 22:35 . 2011-07-03 22:35 5025792 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-07-03 22:36 . 2011-07-03 22:36 2878976 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-07-03 22:36 . 2011-07-03 22:36 4308992 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2010-01-25 19:25 . 2011-05-12 00:01 42829768 c:\windows\system32\MRT.exe
+ 2005-09-23 11:48 . 2005-09-23 11:48 24863744 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\netfx.msi
+ 2011-07-03 22:42 . 2011-07-03 22:42 13107200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\132ffbaa949d9a43832c802afa8f558a\System.Windows.Forms.ni.dll
+ 2011-07-04 04:43 . 2011-07-04 04:43 11808768 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\947720806ca5da419d4ff473c8835350\System.Web.ni.dll
+ 2011-07-03 22:44 . 2011-07-03 22:44 10723328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\da7f79db04f7674aa5ec85d31a180855\System.Design.ni.dll
+ 2011-07-03 22:40 . 2011-07-03 22:40 11411456 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\dd044aec7e61e944a825e18879c94cfd\mscorlib.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-04-29 5248312]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-06-02 2220032]
"nwiz"="nwiz.exe" [2009-05-01 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-05-01 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-01 13750272]
"NVHotkey"="nvHotkey.dll" [2009-05-01 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"Sophos AutoUpdate Monitor"="c:\program files\Sophos\AutoUpdate\almon.exe" [2011-05-09 439536]
"Sgapepu"="c:\windows\umozitowayewecig.dll" [N/A]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]
"DLUPDR"="c:\program files\Dell Printers\Additional Color Laser Software\Updater\DLUPDR.EXE" [2007-02-22 140184]
"DLPSP"="c:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE" [2007-02-22 361368]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_2"="shell32" [X]
"_nltide_3"="advpack.dll" [2009-03-08 128512]
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2010-12-07 16:01 13672 ----a-w- c:\program files\Citrix\GoToAssist\615\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Loralee\\Desktop\\DCPlusPlus-0.750\\DCPlusPlus.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Documents and Settings\\Loralee\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Loralee\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [5/9/2011 4:43 PM 153344]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [5/9/2011 4:43 PM 24064]
R2 DLSDB;Dell Printer Status Database;c:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE [2/3/2010 10:20 AM 140184]
R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [5/9/2011 4:43 PM 163056]
R2 swi_service;Sophos Web Intelligence Service;c:\program files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [5/9/2011 4:43 PM 1541360]
S0 buep;buep;c:\windows\system32\drivers\iwjjfsii.sys --> c:\windows\system32\drivers\iwjjfsii.sys [?]
S2 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [5/9/2011 4:43 PM 97520]
S3 BlackBox;BlackBox SR2; [x]
S3 sdcfilter;sdcfilter;c:\windows\system32\drivers\sdcfilter.sys [5/9/2011 4:43 PM 23928]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [5/9/2011 4:43 PM 14976]
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-02 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-01-25 04:21]
.
2011-09-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1644491937-1417001333-1010Core.job
- c:\documents and settings\Loralee\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-30 14:37]
.
2011-09-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1644491937-1417001333-1010UA.job
- c:\documents and settings\Loralee\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-30 14:37]
.
2011-09-02 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\Loralee\Application Data\Mozilla\Firefox\Profiles\urg7gy8k.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/p/2.html
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-13494242.sys
SafeBoot-70117761.sys
SafeBoot-74810021.sys
SafeBoot-76055305.sys
SafeBoot-99107441.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-09-02 16:36
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\Sophos Message Router]
"ImagePath"="\"c:\program files\Sophos\Remote Management System\RouterNT.exe\" -service -name Router -ORBListenEndpoints iiop://:8193/ssl_port=8194"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-602162358-1644491937-1417001333-1010\Software\SecuROM\License information*]
"datasecu"=hex:87,84,f5,7d,8c,97,de,8f,89,1d,25,b6,a0,c0,9c,d7,c8,b0,8d,33,b3,
cc,de,5f,a0,fd,c3,ed,ef,1f,b5,f7,d8,07,8e,b5,22,48,84,a5,00,f0,14,33,bf,7a,\
"rkeysecu"=hex:d9,77,68,28,61,ba,57,76,68,15,33,5d,7e,ae,17,dd
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(916)
c:\program files\Citrix\GoToAssist\615\G2AWinLogon.dll
c:\windows\System32\BCMLogon.dll
.
- - - - - - - > 'explorer.exe'(1188)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\O2Micro Flash Memory Card Driver\o2flash.exe
c:\program files\Sophos\Remote Management System\ManagementAgentNT.exe
c:\program files\Sophos\AutoUpdate\ALsvc.exe
c:\program files\Sophos\Remote Management System\RouterNT.exe
c:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\Yahoo!\Messenger\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2011-09-02 16:41:00 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-02 20:40
ComboFix2.txt 2011-05-09 20:30
ComboFix3.txt 2011-05-05 21:34
ComboFix4.txt 2011-03-25 18:10
ComboFix5.txt 2011-09-02 20:09
.
Pre-Run: 6,993,510,400 bytes free
Post-Run: 8,427,802,624 bytes free
.
- - End Of File - - 01BD41F3767ADA15ECDA3FCC2BCD1E30