Here is the first log I ran.....second log follows.
ComboFix 12-02-05.02 - Administrator 02/05/2012 19:14:41.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1515 [GMT -6:00]
Running from: c:\documents and settings\Administrator\My Documents\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *Enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((( Files Created from 2012-01-06 to 2012-02-06 )))))))))))))))))))))))))))))))
.
.
2012-02-05 21:32 . 2012-02-05 21:33 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Deployment
2012-02-03 02:31 . 2011-08-16 10:45 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2012-02-03 01:21 . 2012-02-03 01:21 -------- d-----w- c:\program files\iPod
2012-02-03 01:21 . 2012-02-03 01:22 -------- d-----w- c:\program files\iTunes
2012-02-03 01:05 . 2012-02-03 01:19 -------- d-----w- c:\documents and settings\Administrator\Application Data\ElevatedDiagnostics
2012-02-03 01:03 . 2008-04-13 19:40 57600 -c--a-w- c:\windows\system32\dllcache\redbook.sys
2012-02-03 01:03 . 2008-04-13 19:40 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2012-02-03 00:23 . 2012-02-03 00:23 -------- d-----w- c:\program files\Common Files\Java
2012-02-03 00:22 . 2012-02-03 00:22 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-02-03 00:22 . 2012-02-03 00:22 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-02-03 00:22 . 2012-02-03 00:22 -------- d-----w- c:\program files\Java
2012-01-29 03:20 . 2012-01-29 03:20 -------- d-----w- C:\$AVG
2012-01-07 02:43 . 2012-01-07 02:43 -------- d-----w- c:\documents and settings\Administrator\Application Data\AVG2012
2012-01-07 02:41 . 2012-02-05 15:48 -------- d-----w- c:\windows\system32\drivers\AVG
2012-01-07 02:41 . 2012-01-31 03:53 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG2012
2012-01-07 02:41 . 2012-01-07 02:41 -------- d-----w- c:\program files\AVG
2012-01-07 02:17 . 2012-01-07 02:17 -------- d--h--w- c:\windows\system32\GroupPolicy
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-30 01:01 . 2011-10-16 00:56 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-25 21:57 . 2002-06-25 19:33 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-11-23 13:25 . 2002-06-25 19:32 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-18 12:35 . 2002-06-25 19:20 60416 ----a-w- c:\windows\system32\packager.exe
2011-11-16 14:21 . 2011-10-16 05:55 354816 ----a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:21 . 2002-06-25 19:24 152064 ----a-w- c:\windows\system32\schannel.dll
2011-11-12 17:18 . 2011-12-30 00:57 18560 ----a-w- c:\windows\system32\drivers\FlyUsb.sys
2011-10-16 08:04 . 2011-10-16 08:04 16409960 ----a-w- c:\program files\spybotsd162.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-29_11.24.15 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-04-19 04:51 . 2011-04-19 04:51 51024 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_4ddc769f\vcomp90.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 51008 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90rus.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90kor.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90jpn.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90ita.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90fra.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esp.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esn.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 53584 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90enu.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 63312 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90deu.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90cht.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 35664 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90chs.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 61760 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 53568 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 63296 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 35648 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90u.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90.dll
+ 2009-07-12 06:05 . 2009-07-12 06:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
+ 2009-07-12 06:05 . 2009-07-12 06:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
+ 2012-02-06 01:13 . 2012-02-06 01:13 16384 c:\windows\temp\Perflib_Perfdata_22c.dat
- 2011-10-16 07:43 . 2011-03-18 06:24 99328 c:\windows\system32\ZoneLabs\zlquarantine.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 99328 c:\windows\system32\ZoneLabs\zlquarantine.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 70656 c:\windows\system32\ZoneLabs\zatray.exe
+ 2012-01-07 02:19 . 2011-03-18 07:24 70656 c:\windows\system32\ZoneLabs\zatray.exe
- 2011-10-16 07:43 . 2011-03-18 06:25 21504 c:\windows\system32\ZoneLabs\lib\zsys.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 21504 c:\windows\system32\ZoneLabs\lib\zsys.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:25 14336 c:\windows\system32\ZoneLabs\lib\zmenu.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 14336 c:\windows\system32\ZoneLabs\lib\zmenu.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:25 48640 c:\windows\system32\ZoneLabs\lib\zfde.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 48640 c:\windows\system32\ZoneLabs\lib\zfde.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 85504 c:\windows\system32\ZoneLabs\lib\ZAlert.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:25 85504 c:\windows\system32\ZoneLabs\lib\ZAlert.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 37376 c:\windows\system32\ZoneLabs\lib\UpdateUI.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:25 37376 c:\windows\system32\ZoneLabs\lib\UpdateUI.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:25 12800 c:\windows\system32\ZoneLabs\lib\oem_1488.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 12800 c:\windows\system32\ZoneLabs\lib\oem_1488.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:25 12800 c:\windows\system32\ZoneLabs\lib\oem_1487.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 12800 c:\windows\system32\ZoneLabs\lib\oem_1487.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:25 12800 c:\windows\system32\ZoneLabs\lib\oem_1486.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 12800 c:\windows\system32\ZoneLabs\lib\oem_1486.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 20992 c:\windows\system32\ZoneLabs\lib\oem_1466.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:25 20992 c:\windows\system32\ZoneLabs\lib\oem_1466.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:25 12800 c:\windows\system32\ZoneLabs\lib\oem_1460.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 12800 c:\windows\system32\ZoneLabs\lib\oem_1460.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 10240 c:\windows\system32\ZoneLabs\lib\oem_1454.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:25 10240 c:\windows\system32\ZoneLabs\lib\oem_1454.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 11264 c:\windows\system32\ZoneLabs\lib\oem_1445.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:25 11264 c:\windows\system32\ZoneLabs\lib\oem_1445.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 14336 c:\windows\system32\ZoneLabs\lib\oem_1440.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:25 14336 c:\windows\system32\ZoneLabs\lib\oem_1440.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 12288 c:\windows\system32\ZoneLabs\lib\oem_1413.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:25 12288 c:\windows\system32\ZoneLabs\lib\oem_1413.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 11264 c:\windows\system32\ZoneLabs\lib\oem_1010.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 11264 c:\windows\system32\ZoneLabs\lib\oem_1010.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 29184 c:\windows\system32\ZoneLabs\lib\NavBar.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 29184 c:\windows\system32\ZoneLabs\lib\NavBar.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 13312 c:\windows\system32\ZoneLabs\lib\MainLoop.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 13312 c:\windows\system32\ZoneLabs\lib\MainLoop.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 35840 c:\windows\system32\ZoneLabs\lib\Alert.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 35840 c:\windows\system32\ZoneLabs\lib\Alert.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 38912 c:\windows\system32\ZoneLabs\featuremap.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 38912 c:\windows\system32\ZoneLabs\featuremap.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 75776 c:\windows\system32\ZoneLabs\camupd.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 75776 c:\windows\system32\ZoneLabs\camupd.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 69120 c:\windows\system32\zlcomm.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 69120 c:\windows\system32\zlcomm.dll
+ 2012-02-03 01:01 . 2007-11-01 04:48 20992 c:\windows\system32\windowspowershell\v1.0\pwrshsip.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 43008 c:\windows\system32\vswmi.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 43008 c:\windows\system32\vswmi.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 58368 c:\windows\system32\vsregexp.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 58368 c:\windows\system32\vsregexp.dll
- 2011-10-16 06:14 . 2011-07-08 13:49 46080 c:\windows\system32\tzchange.exe
+ 2011-10-16 06:14 . 2011-11-08 13:46 46080 c:\windows\system32\tzchange.exe
+ 2011-10-16 05:53 . 2009-01-08 00:21 26144 c:\windows\system32\spupdsvc.exe
- 2011-10-16 05:53 . 2009-01-07 23:21 26144 c:\windows\system32\spupdsvc.exe
+ 2011-10-16 07:53 . 2009-02-27 09:42 66440 c:\windows\system32\spool\drivers\w32x86\msonpui.dll
+ 2011-10-16 07:53 . 2009-02-27 09:42 66440 c:\windows\system32\spool\drivers\w32x86\3\msonpui.dll
+ 2011-11-21 00:28 . 2009-01-08 00:20 16928 c:\windows\system32\spmsg.dll
+ 2002-06-25 19:21 . 2012-01-11 22:57 68514 c:\windows\system32\perfc009.dat
- 2009-01-07 23:20 . 2009-01-07 23:20 23552 c:\windows\system32\normaliz.dll
+ 2009-01-07 23:20 . 2009-01-08 00:20 23552 c:\windows\system32\normaliz.dll
+ 2009-01-07 23:20 . 2009-01-08 00:20 24576 c:\windows\system32\nlsdl.dll
- 2009-01-07 23:20 . 2009-01-07 23:20 24576 c:\windows\system32\nlsdl.dll
+ 2011-10-16 07:53 . 2009-02-27 09:42 31640 c:\windows\system32\msonpmon.dll
+ 2002-06-25 19:15 . 2011-11-04 19:20 66560 c:\windows\system32\mshtmled.dll
- 2002-06-25 19:15 . 2011-08-22 23:48 66560 c:\windows\system32\mshtmled.dll
+ 2009-03-08 09:31 . 2011-11-04 19:20 55296 c:\windows\system32\msfeedsbs.dll
- 2009-03-08 09:31 . 2011-08-22 23:48 55296 c:\windows\system32\msfeedsbs.dll
+ 2002-06-25 19:12 . 2011-10-14 14:47 23040 c:\windows\system32\mciseq.dll
- 2002-06-25 19:12 . 2008-04-14 00:11 23040 c:\windows\system32\mciseq.dll
- 2002-06-25 19:11 . 2011-08-22 23:48 43520 c:\windows\system32\licmgr10.dll
+ 2002-06-25 19:11 . 2011-11-04 19:20 43520 c:\windows\system32\licmgr10.dll
- 2002-06-25 19:09 . 2011-08-22 23:48 25600 c:\windows\system32\jsproxy.dll
+ 2002-06-25 19:09 . 2011-11-04 19:20 25600 c:\windows\system32\jsproxy.dll
- 2009-03-08 09:32 . 2009-03-08 09:32 36864 c:\windows\system32\ieudinit.exe
+ 2009-03-08 09:32 . 2009-03-08 10:32 36864 c:\windows\system32\ieudinit.exe
- 2009-01-07 23:20 . 2009-01-07 23:20 26112 c:\windows\system32\idndl.dll
+ 2009-01-07 23:20 . 2009-01-08 00:20 26112 c:\windows\system32\idndl.dll
+ 2011-12-30 00:56 . 2011-11-12 17:18 33792 c:\windows\system32\DRVSTORE\leapfrog-0_B30D43972967E3C09B8E635B22BC13082452FEEA\i386\btblan.sys
+ 2011-12-30 00:57 . 2011-11-12 17:18 18560 c:\windows\system32\DRVSTORE\flyusb_E1B194E4380F1C20BBC476848F70DDC967C29749\i386\FlyUsb.sys
+ 2011-09-13 12:30 . 2011-09-13 12:30 32592 c:\windows\system32\drivers\avgrkx86.sys
+ 2011-08-08 12:08 . 2011-08-08 12:08 40016 c:\windows\system32\drivers\avgmfx86.sys
+ 2011-10-04 12:21 . 2011-10-04 12:21 16720 c:\windows\system32\drivers\AVGIDSShim.sys
+ 2011-07-11 07:14 . 2011-07-11 07:14 24272 c:\windows\system32\drivers\AVGIDSFilter.sys
+ 2011-07-11 07:14 . 2011-07-11 07:14 23120 c:\windows\system32\drivers\AVGIDSEH.sys
- 2011-10-16 06:22 . 2011-08-22 23:48 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2011-10-16 06:22 . 2011-11-04 19:20 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2011-11-18 12:35 . 2011-11-18 12:35 60416 c:\windows\system32\dllcache\packager.exe
- 2009-03-08 09:31 . 2011-08-22 23:48 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2009-03-08 09:31 . 2011-11-04 19:20 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2011-10-16 06:22 . 2011-08-22 23:48 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2011-10-16 06:22 . 2011-11-04 19:20 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2011-10-14 14:47 . 2011-10-14 14:47 23040 c:\windows\system32\dllcache\mciseq.dll
+ 2009-03-08 09:34 . 2011-11-04 19:20 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2009-03-08 09:34 . 2011-08-22 23:48 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2009-03-08 09:33 . 2011-11-04 19:20 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2009-03-08 09:33 . 2011-08-22 23:48 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2009-12-14 07:08 . 2011-04-26 11:07 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2009-12-14 07:08 . 2011-10-28 05:31 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2002-06-25 19:03 . 2011-10-28 05:31 33280 c:\windows\system32\csrsrv.dll
- 2002-06-25 19:03 . 2011-04-26 11:07 33280 c:\windows\system32\csrsrv.dll
+ 2011-12-25 09:49 . 2011-12-25 09:49 31504 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2011-12-01 04:17 . 2011-12-01 04:17 19968 c:\windows\Installer\e9ce24.msi
- 2011-10-16 07:53 . 2011-10-18 00:19 35088 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2011-10-16 07:53 . 2012-02-03 03:41 35088 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2011-10-16 07:53 . 2011-10-18 00:19 18704 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2011-10-16 07:53 . 2012-02-03 03:41 18704 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2011-10-16 07:53 . 2011-10-18 00:19 20240 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2011-10-16 07:53 . 2012-02-03 03:41 20240 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-02-26 22:45 . 2009-02-26 22:45 20808 c:\windows\Installer\$PatchCache$\Managed\00002119030000000000000000F01FEC\12.0.6612\WRD12EXE.EXE
+ 2006-07-24 15:50 . 2006-07-24 15:50 47920 c:\windows\Installer\$PatchCache$\Managed\00002119030000000000000000F01FEC\12.0.6612\VBAME.DLL
+ 2009-02-26 20:24 . 2009-02-26 20:24 71536 c:\windows\Installer\$PatchCache$\Managed\00002119030000000000000000F01FEC\12.0.6612\ONFILTER.DLL
+ 2009-02-26 20:24 . 2009-02-26 20:24 97680 c:\windows\Installer\$PatchCache$\Managed\00002119030000000000000000F01FEC\12.0.6612\ONENOTEM.EXE
+ 2006-07-24 15:50 . 2006-07-24 15:50 92976 c:\windows\Installer\$PatchCache$\Managed\00002119030000000000000000F01FEC\12.0.6612\MSADDNDR.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 56192 c:\windows\Installer\$PatchCache$\Managed\00002119030000000000000000F01FEC\12.0.4518\ACECNFLT.EXE
+ 2011-12-15 09:05 . 2011-08-22 23:48 12800 c:\windows\ie8updates\KB2618444-IE8\xpshims.dll
+ 2011-12-15 09:05 . 2011-08-22 23:48 66560 c:\windows\ie8updates\KB2618444-IE8\mshtmled.dll
+ 2011-12-15 09:05 . 2011-08-22 23:48 55296 c:\windows\ie8updates\KB2618444-IE8\msfeedsbs.dll
+ 2011-12-15 09:05 . 2011-08-22 23:48 43520 c:\windows\ie8updates\KB2618444-IE8\licmgr10.dll
+ 2011-12-15 09:05 . 2011-08-22 23:48 25600 c:\windows\ie8updates\KB2618444-IE8\jsproxy.dll
+ 2012-01-12 03:16 . 2012-01-12 03:16 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\750de53f30e516eb2c62de9bab7954e9\System.Web.DynamicData.Design.ni.dll
+ 2012-02-03 02:36 . 2012-02-03 02:36 30208 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\9855d3fb15e6c63a811b1f0b66d78428\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2012-02-03 02:36 . 2012-02-03 02:36 17408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\7618f444d33b1311e952ba9285e4a4b2\Microsoft.PowerShell.Security.resources.ni.dll
+ 2012-02-03 02:36 . 2012-02-03 02:36 19456 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\1b23e2c0707d81e7eb14f78552562635\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2012-02-03 02:36 . 2012-02-03 02:36 35328 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\05bbffbe100ede49139819641a41dfda\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2012-01-11 22:57 . 2012-01-11 22:57 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2012-02-03 01:01 . 2012-02-03 01:01 65536 c:\windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll
+ 2012-02-03 01:01 . 2012-02-03 01:01 36864 c:\windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.resources.dll
+ 2012-02-03 01:01 . 2012-02-03 01:01 32768 c:\windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.resources.dll
+ 2012-02-03 01:01 . 2012-02-03 01:01 11264 c:\windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.resources.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2011-12-30 00:57 . 2011-12-30 00:57 27003 c:\windows\2437DF07D3CB4D858397ED8AE9ED26D5.TMP\WiseCustomCall.dll
+ 2011-12-15 09:02 . 2011-07-08 13:49 46080 c:\windows\$NtUninstallKB2633952$\tzchange.exe
+ 2011-12-15 09:02 . 2011-11-08 14:58 16896 c:\windows\$NtUninstallKB2633952$\spuninst\tzchange.dll
+ 2011-12-15 09:00 . 2011-04-26 11:07 33280 c:\windows\$NtUninstallKB2620712$\csrsrv.dll
+ 2011-12-15 09:05 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2639417\update\spcustom.dll
+ 2011-12-15 09:05 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2639417\spmsg.dll
+ 2011-12-15 09:00 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2633171\update\spcustom.dll
+ 2011-12-14 23:09 . 2011-10-26 10:50 16896 c:\windows\$hf_mig$\KB2633171\update\mpsyschk.dll
+ 2011-12-15 09:00 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2633171\spmsg.dll
+ 2011-12-15 09:05 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2624667\update\spcustom.dll
+ 2011-12-15 09:05 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2624667\spmsg.dll
+ 2011-12-15 09:00 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2620712\update\spcustom.dll
+ 2011-12-15 09:00 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2620712\spmsg.dll
+ 2011-10-28 05:31 . 2011-10-28 05:31 33280 c:\windows\$hf_mig$\KB2620712\SP3QFE\csrsrv.dll
+ 2011-12-15 09:01 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2619339\update\spcustom.dll
+ 2011-12-15 09:01 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2619339\spmsg.dll
+ 2011-12-15 09:01 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2618451\update\spcustom.dll
+ 2011-12-15 09:01 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2618451\spmsg.dll
+ 2011-12-15 09:05 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2618444-IE8\update\spcustom.dll
+ 2011-12-15 09:05 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2618444-IE8\spmsg.dll
+ 2011-12-14 23:09 . 2011-11-04 19:19 12800 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\xpshims.dll
+ 2011-12-14 23:09 . 2011-11-04 19:19 66560 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\mshtmled.dll
+ 2011-12-14 23:09 . 2011-11-04 19:19 55296 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\msfeedsbs.dll
+ 2011-12-14 23:09 . 2011-11-04 19:19 43520 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\licmgr10.dll
+ 2011-12-14 23:09 . 2011-11-04 19:19 25600 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\jsproxy.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
- 2011-10-16 07:43 . 2011-10-16 07:43 4212 c:\windows\system32\zllictbl.dat
+ 2011-10-16 07:43 . 2012-01-07 02:19 4212 c:\windows\system32\zllictbl.dat
+ 2012-02-03 01:01 . 2007-06-30 18:49 4608 c:\windows\system32\windowspowershell\v1.0\pwrshmsg.dll
+ 2011-12-25 18:29 . 2001-08-18 04:36 5632 c:\windows\system32\ptpusb.dll
+ 2012-02-05 21:58 . 2012-02-05 22:29 1598 c:\windows\SoftwareDistribution\EventCache\{EF36D080-8C09-48B4-A986-49E8E0CD650B}.bin
+ 2012-02-03 02:38 . 2009-03-08 09:35 2048 c:\windows\ie8updates\KB2598845-IE8\iecompat.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2011-10-19 04:04 . 2011-10-19 04:04 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2012-02-03 01:01 . 2012-02-03 01:01 8704 c:\windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Security.resources.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 653136 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 569680 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcm90.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
+ 2009-07-12 06:05 . 2009-07-12 06:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 159048 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_92453bb7\atl90.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 141824 c:\windows\system32\ZoneLabs\zlupdate.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 141824 c:\windows\system32\ZoneLabs\zlupdate.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 173056 c:\windows\system32\ZoneLabs\vsvault.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 173056 c:\windows\system32\ZoneLabs\vsvault.dll
+ 2012-01-07 02:17 . 2011-03-18 07:24 211456 c:\windows\system32\ZoneLabs\vsdb.dll
- 2011-10-16 07:42 . 2011-03-18 06:24 211456 c:\windows\system32\ZoneLabs\vsdb.dll
- 2011-10-16 07:43 . 2007-10-11 21:51 832984 c:\windows\system32\ZoneLabs\updating.dll
+ 2012-01-07 02:19 . 2007-10-11 22:51 832984 c:\windows\system32\ZoneLabs\updating.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 434688 c:\windows\system32\ZoneLabs\ssleay32.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 434688 c:\windows\system32\ZoneLabs\ssleay32.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 135680 c:\windows\system32\ZoneLabs\scheduler.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 135680 c:\windows\system32\ZoneLabs\scheduler.dll
+ 2012-01-07 02:19 . 2009-07-14 05:58 722392 c:\windows\system32\ZoneLabs\qrbase.dll
- 2011-10-16 07:43 . 2009-07-14 04:58 722392 c:\windows\system32\ZoneLabs\qrbase.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 126976 c:\windows\system32\ZoneLabs\lib\zui.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:25 126976 c:\windows\system32\ZoneLabs\lib\zui.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 280064 c:\windows\system32\ZoneLabs\lib\TrayTest.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:25 280064 c:\windows\system32\ZoneLabs\lib\TrayTest.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:25 225792 c:\windows\system32\ZoneLabs\lib\Overview.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 225792 c:\windows\system32\ZoneLabs\lib\Overview.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 368640 c:\windows\system32\ZoneLabs\lib\LicenseUI.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 368640 c:\windows\system32\ZoneLabs\lib\LicenseUI.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 184832 c:\windows\system32\ZoneLabs\lib\DashBoard.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 184832 c:\windows\system32\ZoneLabs\lib\DashBoard.zip.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 375296 c:\windows\system32\ZoneLabs\lib\ConfigWizard.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 375296 c:\windows\system32\ZoneLabs\lib\ConfigWizard.zip.dll
+ 2012-01-07 02:17 . 2010-02-08 14:41 595432 c:\windows\system32\ZoneLabs\icslta.dll
- 2011-10-16 07:42 . 2010-02-08 13:41 595432 c:\windows\system32\ZoneLabs\icslta.dll
- 2011-10-16 07:44 . 2010-11-08 23:58 284136 c:\windows\system32\ZoneLabs\ffapi.dll
+ 2012-01-07 02:20 . 2010-11-09 00:58 284136 c:\windows\system32\ZoneLabs\ffapi.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 169984 c:\windows\system32\ZoneLabs\fbl.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 169984 c:\windows\system32\ZoneLabs\fbl.dll
- 2011-10-16 07:43 . 2008-03-17 21:52 813568 c:\windows\system32\ZoneLabs\dbghelp.dll
+ 2012-01-07 02:19 . 2008-03-17 22:52 813568 c:\windows\system32\ZoneLabs\dbghelp.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 104448 c:\windows\system32\zlcommdb.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 104448 c:\windows\system32\zlcommdb.dll
+ 2009-01-07 23:21 . 2009-01-08 00:21 121856 c:\windows\system32\xmllite.dll
- 2009-01-07 23:21 . 2008-04-14 00:12 121856 c:\windows\system32\xmllite.dll
+ 2002-06-25 19:33 . 2011-10-14 14:47 176128 c:\windows\system32\winmm.dll
- 2002-06-25 19:33 . 2008-04-14 00:12 176128 c:\windows\system32\winmm.dll
+ 2002-03-05 13:56 . 2011-11-04 19:20 916992 c:\windows\system32\wininet.dll
+ 2012-02-03 01:01 . 2007-10-30 09:15 330240 c:\windows\system32\windowspowershell\v1.0\powershell.exe
+ 2012-01-07 02:19 . 2011-03-18 07:24 110080 c:\windows\system32\vsxml.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 110080 c:\windows\system32\vsxml.dll
+ 2012-01-07 02:17 . 2011-03-18 07:24 715264 c:\windows\system32\vsutil.dll
- 2011-10-16 07:42 . 2011-03-18 06:24 715264 c:\windows\system32\vsutil.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 302592 c:\windows\system32\vspubapi.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 302592 c:\windows\system32\vspubapi.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 108032 c:\windows\system32\vsmonapi.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 108032 c:\windows\system32\vsmonapi.dll
- 2011-10-16 07:42 . 2011-03-18 06:24 228864 c:\windows\system32\vsinit.dll
+ 2012-01-07 02:17 . 2011-03-18 07:24 228864 c:\windows\system32\vsinit.dll
- 2011-10-16 07:43 . 2010-05-13 15:02 532224 c:\windows\system32\vsdatant.sys
+ 2012-01-07 02:19 . 2010-05-13 16:02 532224 c:\windows\system32\vsdatant.sys
+ 2012-01-07 02:17 . 2011-03-18 07:24 112128 c:\windows\system32\vsdata.dll
- 2011-10-16 07:42 . 2011-03-18 06:24 112128 c:\windows\system32\vsdata.dll
- 2002-03-05 23:15 . 2011-08-22 23:48 105984 c:\windows\system32\url.dll
+ 2002-03-05 23:15 . 2011-11-04 19:20 105984 c:\windows\system32\url.dll
+ 2011-10-16 07:53 . 2009-02-27 09:42 863128 c:\windows\system32\spool\drivers\w32x86\msonpdrv.dll
+ 2011-10-16 07:53 . 2009-02-27 09:42 863128 c:\windows\system32\spool\drivers\w32x86\3\msonpdrv.dll
+ 2002-06-25 19:22 . 2011-11-03 15:28 386048 c:\windows\system32\qdvd.dll
- 2002-06-25 19:22 . 2008-04-14 00:12 386048 c:\windows\system32\qdvd.dll
+ 2011-12-25 18:29 . 2008-04-14 01:12 159232 c:\windows\system32\ptpusd.dll
+ 2002-06-25 19:21 . 2012-01-11 22:57 435618 c:\windows\system32\perfh009.dat
+ 2002-06-25 19:20 . 2011-11-04 19:20 206848 c:\windows\system32\occache.dll
- 2002-06-25 19:20 . 2011-08-22 23:48 206848 c:\windows\system32\occache.dll
+ 2010-03-18 15:15 . 2010-03-18 15:15 770384 c:\windows\system32\msvcr100.dll
+ 2010-03-18 15:15 . 2010-03-18 15:15 421200 c:\windows\system32\msvcp100.dll
+ 2002-06-25 19:16 . 2011-11-04 19:20 611840 c:\windows\system32\mstime.dll
- 2002-06-25 19:16 . 2011-08-22 23:48 611840 c:\windows\system32\mstime.dll
+ 2009-03-08 09:32 . 2011-11-04 19:20 602112 c:\windows\system32\msfeeds.dll
- 2009-03-08 09:32 . 2011-08-22 23:48 602112 c:\windows\system32\msfeeds.dll
- 2009-01-07 23:20 . 2009-01-07 23:20 265720 c:\windows\system32\msdbg2.dll
+ 2009-01-07 23:20 . 2009-01-08 00:20 265720 c:\windows\system32\msdbg2.dll
+ 2011-11-30 04:04 . 2010-10-19 20:51 222080 c:\windows\system32\MpSigStub.exe
+ 2011-12-30 01:01 . 2011-12-30 01:01 247968 c:\windows\system32\Macromed\Flash\FlashUtil11e_Plugin.exe
- 2011-11-14 13:58 . 2011-11-14 13:58 247968 c:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
+ 2011-11-14 13:58 . 2011-12-02 22:23 247968 c:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
+ 2011-11-14 13:58 . 2011-12-02 22:23 335520 c:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.dll
- 2011-11-14 13:58 . 2011-11-14 13:58 335520 c:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.dll
+ 2012-02-03 00:22 . 2012-02-03 00:22 157472 c:\windows\system32\javaws.exe
+ 2012-02-03 00:22 . 2012-02-03 00:22 149280 c:\windows\system32\javaw.exe
+ 2012-02-03 00:22 . 2012-02-03 00:22 149280 c:\windows\system32\java.exe
+ 2002-06-25 19:08 . 2011-11-04 19:20 184320 c:\windows\system32\iepeers.dll
- 2002-06-25 19:08 . 2011-08-22 23:48 184320 c:\windows\system32\iepeers.dll
- 2002-06-25 19:08 . 2011-08-22 23:48 387584 c:\windows\system32\iedkcs32.dll
+ 2002-06-25 19:08 . 2011-11-04 19:20 387584 c:\windows\system32\iedkcs32.dll
+ 2002-06-25 19:08 . 2011-11-04 11:24 174080 c:\windows\system32\ie4uinit.exe
- 2002-06-25 19:08 . 2011-08-22 11:56 174080 c:\windows\system32\ie4uinit.exe
- 2011-10-12 19:02 . 2011-11-13 21:04 317952 c:\windows\system32\FNTCACHE.DAT
+ 2011-10-12 19:02 . 2011-12-15 09:22 317952 c:\windows\system32\FNTCACHE.DAT
- 2011-10-16 05:55 . 2011-02-09 13:53 186880 c:\windows\system32\encdec.dll
+ 2011-10-16 05:55 . 2011-10-18 11:13 186880 c:\windows\system32\encdec.dll
+ 2011-07-11 07:14 . 2011-07-11 07:14 295248 c:\windows\system32\drivers\avgtdix.sys
+ 2011-10-07 12:23 . 2011-10-07 12:23 230608 c:\windows\system32\drivers\avgldx86.sys
+ 2011-07-11 07:14 . 2011-07-11 07:14 134608 c:\windows\system32\drivers\AVGIDSDriver.sys
- 2011-04-26 11:07 . 2011-06-20 17:44 293376 c:\windows\system32\dllcache\winsrv.dll
+ 2011-04-26 11:07 . 2011-11-25 21:57 293376 c:\windows\system32\dllcache\winsrv.dll
+ 2011-10-14 14:47 . 2011-10-14 14:47 176128 c:\windows\system32\dllcache\winmm.dll
+ 2009-03-08 09:34 . 2011-11-04 19:20 916992 c:\windows\system32\dllcache\wininet.dll
+ 2008-12-16 12:30 . 2011-11-16 14:21 354816 c:\windows\system32\dllcache\winhttp.dll
- 2008-12-16 12:30 . 2009-08-25 09:17 354816 c:\windows\system32\dllcache\winhttp.dll
+ 2009-03-08 09:34 . 2011-11-04 19:20 105984 c:\windows\system32\dllcache\url.dll
- 2009-03-08 09:34 . 2011-08-22 23:48 105984 c:\windows\system32\dllcache\url.dll
+ 2008-12-05 06:54 . 2011-11-16 14:21 152064 c:\windows\system32\dllcache\schannel.dll
+ 2011-11-03 15:28 . 2011-11-03 15:28 386048 c:\windows\system32\dllcache\qdvd.dll
+ 2009-03-08 09:34 . 2011-11-04 19:20 206848 c:\windows\system32\dllcache\occache.dll
- 2009-03-08 09:34 . 2011-08-22 23:48 206848 c:\windows\system32\dllcache\occache.dll
+ 2009-03-08 09:32 . 2011-11-04 19:20 611840 c:\windows\system32\dllcache\mstime.dll
- 2009-03-08 09:32 . 2011-08-22 23:48 611840 c:\windows\system32\dllcache\mstime.dll
+ 2011-10-16 06:22 . 2011-11-04 19:20 602112 c:\windows\system32\dllcache\msfeeds.dll
- 2011-10-16 06:22 . 2011-08-22 23:48 602112 c:\windows\system32\dllcache\msfeeds.dll
- 2011-10-16 06:22 . 2011-08-22 23:48 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2011-10-16 06:22 . 2011-11-04 19:20 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2009-03-08 09:31 . 2011-08-22 23:48 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2009-03-08 09:31 . 2011-11-04 19:20 184320 c:\windows\system32\dllcache\iepeers.dll
- 2011-10-16 06:22 . 2011-08-22 23:48 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2011-10-16 06:22 . 2011-11-04 19:20 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2009-03-08 19:09 . 2011-08-22 23:48 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2009-03-08 19:09 . 2011-11-04 19:20 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2009-03-08 09:32 . 2011-11-04 11:24 174080 c:\windows\system32\dllcache\ie4uinit.exe
- 2009-03-08 09:32 . 2011-08-22 11:56 174080 c:\windows\system32\dllcache\ie4uinit.exe
- 2011-02-09 13:53 . 2011-02-09 13:53 186880 c:\windows\system32\dllcache\encdec.dll
+ 2011-02-09 13:53 . 2011-10-18 11:13 186880 c:\windows\system32\dllcache\encdec.dll
+ 2002-06-25 19:03 . 2008-04-14 00:11 640000 c:\windows\system32\dllcache\dbghelp.dll
+ 2010-03-18 15:15 . 2010-03-18 15:15 138056 c:\windows\system32\atl100.dll
+ 2011-12-25 09:49 . 2011-12-25 09:49 436496 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
+ 2011-12-25 11:40 . 2011-12-25 11:40 819200 c:\windows\Installer\74d54ca.msp
+ 2011-11-30 03:59 . 2011-11-30 03:59 301056 c:\windows\Installer\4b0e0.msi
+ 2012-01-08 09:00 . 2012-01-08 09:00 223744 c:\windows\Installer\2bc045d.msi
+ 2012-02-03 00:23 . 2012-02-03 00:23 203776 c:\windows\Installer\2b30db.msi
+ 2012-02-03 00:22 . 2012-02-03 00:22 901120 c:\windows\Installer\2b30d6.msi
+ 2012-01-07 02:40 . 2012-01-07 02:40 219648 c:\windows\Installer\11e0ad.msi
+ 2012-02-03 01:22 . 2012-02-03 01:22 380928 c:\windows\Installer\{F6D6B258-E3CA-4AAC-965A-68D3E3140A8C}\iTunesIco.exe
+ 2011-12-17 05:07 . 2011-12-17 05:07 897024 c:\windows\Installer\{F2AF3E5D-9697-485C-A5AC-E2B9468C446A}\SafariIco.exe
- 2011-10-16 07:53 . 2011-10-18 00:19 888080 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2011-10-16 07:53 . 2012-02-03 03:41 888080 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2011-10-16 07:53 . 2012-02-03 03:41 272648 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2011-10-16 07:53 . 2011-10-18 00:19 272648 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2011-10-16 07:53 . 2012-02-03 03:41 922384 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2011-10-16 07:53 . 2011-10-18 00:19 922384 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2011-10-16 07:53 . 2011-10-18 00:19 845584 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2011-10-16 07:53 . 2012-02-03 03:41 845584 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2011-10-16 07:53 . 2011-10-18 00:19 217864 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2011-10-16 07:53 . 2012-02-03 03:41 217864 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2011-10-16 07:53 . 2011-10-18 00:19 184080 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2011-10-16 07:53 . 2012-02-03 03:41 184080 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2011-10-16 07:53 . 2011-10-18 00:19 159504 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2011-10-16 07:53 . 2012-02-03 03:41 159504 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2012-02-03 03:36 . 2012-02-03 03:36 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
- 2011-10-17 02:43 . 2011-10-17 02:43 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2011-01-14 13:10 . 2011-01-14 13:10 155520 c:\windows\Installer\$PatchCache$\Managed\00004109500200000000000000F01FEC\14.0.5130\GKWORD6.DLL
+ 2011-01-14 13:10 . 2011-01-14 13:10 140160 c:\windows\Installer\$PatchCache$\Managed\00004109500200000000000000F01FEC\14.0.5130\GKEXCEL2.DLL
+ 2007-06-08 00:51 . 2007-06-08 00:51 125320 c:\windows\Installer\$PatchCache$\Managed\00002119030000000000000000F01FEC\12.0.6612\SSGEN.DLL
+ 2007-06-08 00:51 . 2007-06-08 00:51 465800 c:\windows\Installer\$PatchCache$\Managed\00002119030000000000000000F01FEC\12.0.6612\OUTLFLTR.DLL
+ 2008-03-19 11:27 . 2008-03-19 11:27 661536 c:\windows\Installer\$PatchCache$\Managed\00002119030000000000000000F01FEC\12.0.6612\OGALEGIT.DLL
+ 2006-07-24 15:50 . 2006-07-24 15:50 125744 c:\windows\Installer\$PatchCache$\Managed\00002119030000000000000000F01FEC\12.0.6612\MSSTDFMT.DLL
+ 2008-10-25 11:18 . 2008-10-25 11:18 172880 c:\windows\Installer\$PatchCache$\Managed\00002119030000000000000000F01FEC\12.0.6612\IEAWSDC.DLL
+ 2006-10-27 20:35 . 2006-10-27 20:35 436512 c:\windows\Installer\$PatchCache$\Managed\00002119030000000000000000F01FEC\12.0.4518\UMOUTLOOKADDIN.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 764800 c:\windows\Installer\$PatchCache$\Managed\00002119030000000000000000F01FEC\12.0.4518\ACECNF.DLL
+ 2011-12-15 09:05 . 2011-08-22 23:48 916480 c:\windows\ie8updates\KB2618444-IE8\wininet.dll
+ 2011-12-15 09:05 . 2011-08-22 23:48 105984 c:\windows\ie8updates\KB2618444-IE8\url.dll
+ 2011-12-15 09:05 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2618444-IE8\spuninst\updspapi.dll
+ 2011-12-15 09:05 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2618444-IE8\spuninst\spuninst.exe
+ 2011-12-15 09:05 . 2011-08-22 23:48 206848 c:\windows\ie8updates\KB2618444-IE8\occache.dll
+ 2011-12-15 09:05 . 2011-08-22 23:48 611840 c:\windows\ie8updates\KB2618444-IE8\mstime.dll
+ 2011-12-15 09:05 . 2011-08-22 23:48 602112 c:\windows\ie8updates\KB2618444-IE8\msfeeds.dll
+ 2011-12-15 09:05 . 2011-08-22 23:48 247808 c:\windows\ie8updates\KB2618444-IE8\ieproxy.dll
+ 2011-12-15 09:05 . 2011-08-22 23:48 184320 c:\windows\ie8updates\KB2618444-IE8\iepeers.dll
+ 2011-12-15 09:05 . 2011-08-22 23:48 743424 c:\windows\ie8updates\KB2618444-IE8\iedvtool.dll
+ 2011-12-15 09:05 . 2011-08-22 23:48 387584 c:\windows\ie8updates\KB2618444-IE8\iedkcs32.dll
+ 2011-12-15 09:05 . 2011-08-22 11:56 174080 c:\windows\ie8updates\KB2618444-IE8\ie4uinit.exe
+ 2012-02-03 02:38 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2598845-IE8\spuninst\updspapi.dll
+ 2012-02-03 02:38 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2598845-IE8\spuninst\spuninst.exe
+ 2010-02-10 13:24 . 2010-02-10 13:24 284048 c:\windows\Downloaded Program Files\rufsi.dll
+ 2012-01-12 03:16 . 2012-01-12 03:16 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\0bda7bdfaf440d5dd4bc6a1dea7ffa39\System.Web.Routing.ni.dll
+ 2012-01-12 03:16 . 2012-01-12 03:16 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\6e29f9faa74a48b83a13a3413b826295\System.Web.Extensions.Design.ni.dll
+ 2012-01-12 03:16 . 2012-01-12 03:16 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\be8965fe859bc53dff61579bf626858b\System.Web.Entity.ni.dll
+ 2012-01-12 03:16 . 2012-01-12 03:16 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\8441b3eb247e0344fede848337ee911c\System.Web.Entity.Design.ni.dll
+ 2012-01-12 03:16 . 2012-01-12 03:16 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\09c6a41f187ba483486cdb92dad714a1\System.Web.DynamicData.ni.dll
+ 2012-01-12 03:15 . 2012-01-12 03:15 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\5efb726d424b9712632eff749411fa89\System.Web.Abstractions.ni.dll
+ 2012-02-03 02:36 . 2012-02-03 02:36 160256 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\5d6a0e02b8e1cff94d07d2507667edc7\System.Management.Automation.resources.ni.dll
+ 2012-01-12 03:15 . 2012-01-12 03:15 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\f374e8e7849a72d1470b4a6a0771a137\System.Data.Entity.Design.ni.dll
+ 2012-01-12 03:15 . 2012-01-12 03:15 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\439732479756e0f6df88d29e50a402bf\ServiceModelReg.ni.exe
+ 2012-02-03 02:36 . 2012-02-03 02:36 492032 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\fb17fceaa5465d6eeb15034a4bea2687\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2012-02-03 02:36 . 2012-02-03 02:36 433664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\9963fdc4d47bf168d55ffca06288c0b6\Microsoft.PowerShell.Commands.Management.ni.dll
+ 2012-02-03 02:36 . 2012-02-03 02:36 148480 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\43b77700ad8d984224b12472318e02ec\Microsoft.PowerShell.Security.ni.dll
+ 2012-02-03 02:36 . 2012-02-03 02:36 968192 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\3062d06077a424dff6997145cad8e9e1\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2012-01-12 03:14 . 2012-01-12 03:14 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\bfcea15c95909860c4f4ac19bd7a2d6c\AspNetMMCExt.ni.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2012-02-03 01:01 . 2012-02-03 01:01 163840 c:\windows\assembly\GAC_MSIL\System.Management.Automation.resources\1.0.0.0_en_31bf3856ad364e35\System.Management.Automation.resources.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2012-01-11 22:57 . 2012-01-11 22:57 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2012-01-11 22:57 . 2012-01-11 22:57 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2012-01-11 22:57 . 2012-01-11 22:57 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2012-02-03 01:01 . 2012-02-03 01:01 200704 c:\windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll
+ 2012-02-03 01:01 . 2012-02-03 01:01 294912 c:\windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll
+ 2012-02-03 01:01 . 2012-02-03 01:01 139264 c:\windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2012-01-11 22:57 . 2012-01-11 22:57 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-12-30 00:57 . 2011-12-30 00:57 130323 c:\windows\2437DF07D3CB4D858397ED8AE9ED26D5.TMP\WiseCustomCalla2.exe
+ 2011-12-15 09:05 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2639417$\spuninst\updspapi.dll
+ 2011-12-15 09:05 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2639417$\spuninst\spuninst.exe
+ 2011-12-15 09:02 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2633952$\spuninst\updspapi.dll
+ 2011-12-15 09:02 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2633952$\spuninst\spuninst.exe
+ 2011-12-15 09:00 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2633171$\spuninst\updspapi.dll
+ 2011-12-15 09:00 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2633171$\spuninst\spuninst.exe
+ 2011-12-15 09:05 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2624667$\spuninst\updspapi.dll
+ 2011-12-15 09:05 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2624667$\spuninst\spuninst.exe
+ 2011-12-15 09:00 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2620712$\spuninst\updspapi.dll
+ 2011-12-15 09:00 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2620712$\spuninst\spuninst.exe
+ 2011-12-15 09:01 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2619339$\spuninst\updspapi.dll
+ 2011-12-15 09:01 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2619339$\spuninst\spuninst.exe
+ 2011-12-15 09:01 . 2011-02-09 13:53 186880 c:\windows\$NtUninstallKB2619339$\encdec.dll
+ 2011-12-15 09:01 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2618451$\spuninst\updspapi.dll
+ 2011-12-15 09:01 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2618451$\spuninst\spuninst.exe
+ 2011-12-15 09:05 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2639417\update\updspapi.dll
+ 2011-12-15 09:05 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2639417\update\update.exe
+ 2011-12-15 09:05 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2639417\spuninst.exe
+ 2011-12-15 09:00 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2633171\update\updspapi.dll
+ 2011-12-15 09:00 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2633171\update\update.exe
+ 2011-12-15 09:00 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2633171\spuninst.exe
+ 2011-12-15 09:05 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2624667\update\updspapi.dll
+ 2011-12-15 09:05 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2624667\update\update.exe
+ 2011-12-15 09:05 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2624667\spuninst.exe
+ 2011-12-15 09:00 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2620712\update\updspapi.dll
+ 2011-12-15 09:00 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2620712\update\update.exe
+ 2011-12-15 09:00 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2620712\spuninst.exe
+ 2011-12-15 09:01 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2619339\update\updspapi.dll
+ 2011-12-15 09:01 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2619339\update\update.exe
+ 2011-12-15 09:01 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2619339\spuninst.exe
+ 2011-10-18 11:12 . 2011-10-18 11:12 186880 c:\windows\$hf_mig$\KB2619339\SP3QFE\encdec.dll
+ 2011-12-15 09:01 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2618451\update\updspapi.dll
+ 2011-12-15 09:01 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2618451\update\update.exe
+ 2011-12-15 09:01 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2618451\spuninst.exe
+ 2011-12-15 09:05 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2618444-IE8\update\updspapi.dll
+ 2011-12-15 09:05 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2618444-IE8\update\update.exe
+ 2011-12-15 09:05 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2618444-IE8\spuninst.exe
+ 2011-12-14 23:09 . 2011-11-04 19:19 919552 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\wininet.dll
+ 2011-12-14 23:09 . 2011-11-04 19:19 105984 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\url.dll
+ 2011-12-14 23:09 . 2011-11-04 19:19 206848 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\occache.dll
+ 2011-12-14 23:09 . 2011-11-04 19:19 611840 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\mstime.dll
+ 2011-12-14 23:09 . 2011-11-04 19:19 602112 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\msfeeds.dll
+ 2011-12-14 23:09 . 2011-11-04 19:19 247808 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\ieproxy.dll
+ 2011-12-14 23:09 . 2011-11-04 19:19 184320 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\iepeers.dll
+ 2011-12-14 23:09 . 2011-11-04 19:19 743424 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\iedvtool.dll
+ 2011-12-14 23:09 . 2011-11-04 19:19 387584 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\iedkcs32.dll
+ 2011-12-14 23:09 . 2011-10-25 12:01 174080 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\ie4uinit.exe
+ 2011-04-19 04:51 . 2011-04-19 04:51 3781960 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90u.dll
+ 2011-04-19 04:51 . 2011-04-19 04:51 3766600 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 3780424 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
+ 2009-07-12 06:02 . 2009-07-12 06:02 3765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 1238528 c:\windows\system32\zpeng25.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 1238528 c:\windows\system32\zpeng25.dll
+ 2012-01-07 02:19 . 2011-03-18 07:24 1790464 c:\windows\system32\ZoneLabs\vsruledb.dll
- 2011-10-16 07:43 . 2011-03-18 06:24 1790464 c:\windows\system32\ZoneLabs\vsruledb.dll
+ 2012-01-07 02:19 . 2011-03-18 07:26 2435592 c:\windows\system32\ZoneLabs\vsmon.exe
- 2011-10-16 07:43 . 2011-03-18 06:26 2435592 c:\windows\system32\ZoneLabs\vsmon.exe
- 2011-10-16 07:43 . 2011-03-18 06:25 1536512 c:\windows\system32\ZoneLabs\lib\zpy.zip.dll
+ 2012-01-07 02:19 . 2011-03-18 07:25 1536512 c:\windows\system32\ZoneLabs\lib\zpy.zip.dll
- 2002-03-05 23:13 . 2011-08-22 23:48 1212416 c:\windows\system32\urlmon.dll
+ 2002-03-05 23:13 . 2011-11-04 19:20 1212416 c:\windows\system32\urlmon.dll
+ 2002-06-25 19:22 . 2011-11-03 15:28 1292288 c:\windows\system32\quartz.dll
+ 2002-06-25 19:20 . 2011-11-01 16:07 1288704 c:\windows\system32\ole32.dll
+ 2002-06-25 19:19 . 2011-10-25 13:37 2148864 c:\windows\system32\ntoskrnl.exe
- 2002-06-25 19:19 . 2010-12-09 13:42 2148864 c:\windows\system32\ntoskrnl.exe
- 2002-06-25 19:19 . 2010-12-09 13:07 2027008 c:\windows\system32\ntkrnlpa.exe
+ 2002-06-25 19:19 . 2011-10-25 12:52 2027008 c:\windows\system32\ntkrnlpa.exe
+ 2002-03-05 13:54 . 2011-11-04 19:20 5978112 c:\windows\system32\mshtml.dll
+ 2011-12-30 01:01 . 2011-12-30 01:01 8527008 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2009-03-08 09:32 . 2011-11-04 19:20 2000384 c:\windows\system32\iertutil.dll
- 2009-03-08 09:32 . 2011-08-22 23:48 2000384 c:\windows\system32\iertutil.dll
+ 2011-07-07 08:28 . 2011-07-07 08:28 1193320 c:\windows\system32\FM20.DLL
+ 2010-05-02 05:22 . 2011-11-23 13:25 1859584 c:\windows\system32\dllcache\win32k.sys
+ 2009-03-08 09:34 . 2011-11-04 19:20 1212416 c:\windows\system32\dllcache\urlmon.dll
- 2009-03-08 09:34 . 2011-08-22 23:48 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2009-01-08 00:20 . 2009-01-08 00:20 1497088 c:\windows\system32\dllcache\shdocvw.dll
+ 2009-11-27 17:11 . 2011-11-03 15:28 1292288 c:\windows\system32\dllcache\quartz.dll
+ 2010-07-16 12:05 . 2011-11-01 16:07 1288704 c:\windows\system32\dllcache\ole32.dll
+ 2011-10-16 06:08 . 2011-10-25 13:33 2192768 c:\windows\system32\dllcache\ntoskrnl.exe
- 2011-10-16 06:08 . 2010-12-09 13:38 2192768 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2011-10-16 06:08 . 2011-10-25 12:52 2027008 c:\windows\system32\dllcache\ntkrpamp.exe
- 2011-10-16 06:08 . 2010-12-09 13:07 2027008 c:\windows\system32\dllcache\ntkrpamp.exe
- 2009-02-08 00:02 . 2010-12-09 13:07 2069376 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2009-02-08 00:02 . 2011-10-25 12:52 2069376 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2011-10-16 06:08 . 2010-12-09 13:42 2148864 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2011-10-16 06:08 . 2011-10-25 13:37 2148864 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2009-03-08 09:41 . 2011-11-04 19:20 5978112 c:\windows\system32\dllcache\mshtml.dll
- 2011-10-16 06:22 . 2011-08-22 23:48 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2011-10-16 06:22 . 2011-11-04 19:20 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2009-01-08 00:20 . 2009-01-08 00:20 1022976 c:\windows\system32\dllcache\browseui.dll
+ 2011-12-25 09:50 . 2011-12-25 09:50 5246976 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2011-12-17 05:22 . 2011-12-17 05:22 1717248 c:\windows\Installer\9606b77.msi
+ 2011-12-17 05:12 . 2011-12-17 05:12 9474048 c:\windows\Installer\9606b61.msi
+ 2011-12-17 05:07 . 2011-12-17 05:07 3470848 c:\windows\Installer\9606b27.msi
+ 2011-12-17 05:03 . 2011-12-17 05:03 1709568 c:\windows\Installer\9606b22.msi
+ 2011-12-17 05:01 . 2011-12-17 05:01 1530368 c:\windows\Installer\9606b1a.msi
+ 2011-07-21 18:34 . 2011-07-21 18:34 3456000 c:\windows\Installer\7a80a1.msp
+ 2011-12-26 15:59 . 2011-12-26 15:59 4368896 c:\windows\Installer\74d54c3.msp
+ 2011-12-09 01:24 . 2011-12-09 01:24 4989952 c:\windows\Installer\74d54b9.msp
+ 2011-12-30 00:57 . 2011-12-30 00:57 2620928 c:\windows\Installer\520fff7.msi
+ 2011-12-30 00:56 . 2011-12-30 00:56 8100864 c:\windows\Installer\520fff2.msi
+ 2012-02-03 01:22 . 2012-02-03 01:22 5421056 c:\windows\Installer\4c4854.msi
+ 2012-02-02 19:58 . 2012-02-02 19:58 4698112 c:\windows\Installer\48f1b.msi
+ 2012-02-02 19:55 . 2012-02-02 19:55 2186240 c:\windows\Installer\48f04.msi
+ 2011-09-16 00:40 . 2011-09-16 00:40 7959552 c:\windows\Installer\2c8bed.msp
+ 2011-09-16 00:35 . 2011-09-16 00:35 1411072 c:\windows\Installer\2c89d4.msp
+ 2011-11-01 19:34 . 2011-11-01 19:34 4250112 c:\windows\Installer\221f833.msp
+ 2011-11-01 19:34 . 2011-11-01 19:34 2247168 c:\windows\Installer\221f81b.msp
+ 2011-11-11 22:14 . 2011-11-11 22:14 9096192 c:\windows\Installer\221f805.msp
+ 2011-11-01 19:34 . 2011-11-01 19:34 4225536 c:\windows\Installer\221f7ef.msp
+ 2011-11-01 19:34 . 2011-11-01 19:34 2531840 c:\windows\Installer\221f7d4.msp
+ 2011-11-11 22:15 . 2011-11-11 22:15 1795584 c:\windows\Installer\221f7be.msp
+ 2011-11-11 22:16 . 2011-11-11 22:16 8458240 c:\windows\Installer\221f7a8.msp
+ 2012-01-07 02:42 . 2012-01-07 02:42 4683264 c:\windows\Installer\11e0b5.msi
+ 2011-10-16 07:53 . 2012-02-03 03:41 1172240 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2011-10-16 07:53 . 2011-10-18 00:19 1172240 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2011-10-16 07:53 . 2012-02-03 03:41 1165584 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2011-10-16 07:53 . 2011-10-18 00:19 1165584 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2011-01-14 13:10 . 2011-01-14 13:10 2395008 c:\windows\Installer\$PatchCache$\Managed\00004109500200000000000000F01FEC\14.0.5130\GKWORD.DLL
+ 2011-01-14 13:10 . 2011-01-14 13:10 2180992 c:\windows\Installer\$PatchCache$\Managed\00004109500200000000000000F01FEC\14.0.5130\GKPOWERPOINT.DLL
+ 2011-01-14 13:10 . 2011-01-14 13:10 3443072 c:\windows\Installer\$PatchCache$\Managed\00004109500200000000000000F01FEC\14.0.5130\GKEXCEL.DLL
+ 2009-10-10 04:10 . 2009-10-10 04:10 2594632 c:\windows\Installer\$PatchCache$\Managed\00002119030000000000000000F01FEC\12.0.6612\VBE6.DLL
+ 2006-10-27 01:25 . 2006-10-27 01:25 2172688 c:\windows\Installer\$PatchCache$\Managed\00002119030000000000000000F01FEC\12.0.4518\PSRCHFEA.DLL
+ 2011-12-15 09:05 . 2011-08-22 23:48 1212416 c:\windows\ie8updates\KB2618444-IE8\urlmon.dll
+ 2011-12-15 09:05 . 2011-10-03 08:35 5971456 c:\windows\ie8updates\KB2618444-IE8\mshtml.dll
+ 2011-12-15 09:05 . 2011-08-22 23:48 2000384 c:\windows\ie8updates\KB2618444-IE8\iertutil.dll
- 2011-10-16 06:08 . 2010-12-09 13:38 2192768 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2011-10-16 06:08 . 2011-10-25 13:33 2192768 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2011-10-16 06:08 . 2011-10-25 12:52 2027008 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2011-10-16 06:08 . 2010-12-09 13:07 2027008 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2009-02-08 00:02 . 2010-12-09 13:07 2069376 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-02-08 00:02 . 2011-10-25 12:52 2069376 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2011-10-16 06:08 . 2010-12-09 13:42 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2011-10-16 06:08 . 2011-10-25 13:37 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2012-01-12 03:16 . 2012-01-12 03:16 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\05c29118462056cf810df0b6aa660d05\System.WorkflowServices.ni.dll
+ 2012-01-12 03:16 . 2012-01-12 03:16 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\26b3258c559dc0ab6bdce481ffd458b3\System.Workflow.Runtime.ni.dll
+ 2012-01-12 03:16 . 2012-01-12 03:16 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\1642d1b72cd84caf24cbe7c5e8fd8368\System.Workflow.ComponentModel.ni.dll
+ 2012-01-12 03:16 . 2012-01-12 03:16 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\32ce12c3c2049f2df94c44c94b052e16\System.Workflow.Activities.ni.dll
+ 2012-01-12 03:16 . 2012-01-12 03:16 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\f63ae1310e004777e880f28377bcddd2\System.Web.Services.ni.dll
+ 2012-01-12 03:16 . 2012-01-12 03:16 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\c99b02434e71ca9898bebbc08d63e885\System.Web.Mobile.ni.dll
+ 2012-01-12 03:16 . 2012-01-12 03:16 2405888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\c8f78b9e94857fdf6c2a378dd1629ee0\System.Web.Extensions.ni.dll
+ 2012-01-12 03:15 . 2012-01-12 03:15 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\ae749b024162e9ac79110c633b5ce6be\System.ServiceModel.Web.ni.dll
+ 2012-02-03 02:36 . 2012-02-03 02:36 4949504 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\1a32e7ce68fa086773b235fc8b525476\System.Management.Automation.ni.dll
+ 2012-01-12 03:14 . 2012-01-12 03:14 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\23eb4618c9d171be9fb551a13a475a32\System.IdentityModel.ni.dll
+ 2012-01-12 03:15 . 2012-01-12 03:15 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\f35064c125799df650c1a959d8fa450b\System.Data.Services.ni.dll
+ 2012-01-12 03:15 . 2012-01-12 03:15 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\a86c12788293105a0d9fda1bc90c90bc\Microsoft.VisualBasic.ni.dll
+ 2012-01-11 22:57 . 2012-01-11 22:57 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2011-10-19 03:53 . 2011-10-19 03:53 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
+ 2012-01-11 22:57 . 2012-01-11 22:57 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
+ 2012-02-03 01:01 . 2012-02-03 01:01 1564672 c:\windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 5246976 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-01-11 22:57 . 2012-01-11 22:57 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-01-11 22:56 . 2012-01-11 22:56 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2011-10-19 04:04 . 2011-10-19 04:04 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-12-30 00:57 . 2011-12-30 00:57 1077248 c:\windows\2437DF07D3CB4D858397ED8AE9ED26D5.TMP\WiseCustomCalla.dll
+ 2011-12-15 09:05 . 2011-09-06 13:20 1858944 c:\windows\$NtUninstallKB2639417$\win32k.sys
+ 2011-12-15 09:00 . 2010-12-09 13:42 2148864 c:\windows\$NtUninstallKB2633171$\ntoskrnl.exe
+ 2011-12-15 09:00 . 2010-12-09 13:07 2027008 c:\windows\$NtUninstallKB2633171$\ntkrpamp.exe
+ 2011-12-15 09:00 . 2010-12-09 13:07 2027008 c:\windows\$NtUninstallKB2633171$\ntkrnlpa.exe
+ 2011-12-15 09:00 . 2010-12-09 13:42 2148864 c:\windows\$NtUninstallKB2633171$\ntkrnlmp.exe
+ 2011-12-15 09:05 . 2010-07-16 12:05 1288192 c:\windows\$NtUninstallKB2624667$\ole32.dll
+ 2011-11-23 13:29 . 2011-11-23 13:29 1868544 c:\windows\$hf_mig$\KB2639417\SP3QFE\win32k.sys
+ 2011-10-25 13:34 . 2011-10-25 13:34 2192768 c:\windows\$hf_mig$\KB2633171\SP3QFE\ntoskrnl.exe
+ 2011-10-25 12:52 . 2011-10-25 12:52 2027008 c:\windows\$hf_mig$\KB2633171\SP3QFE\ntkrpamp.exe
+ 2011-10-25 12:52 . 2011-10-25 12:52 2069376 c:\windows\$hf_mig$\KB2633171\SP3QFE\ntkrnlpa.exe
+ 2011-10-25 13:38 . 2011-10-25 13:38 2148864 c:\windows\$hf_mig$\KB2633171\SP3QFE\ntkrnlmp.exe
+ 2011-11-01 16:05 . 2011-11-01 16:05 1289216 c:\windows\$hf_mig$\KB2624667\SP3QFE\ole32.dll
+ 2011-12-14 23:09 . 2011-11-04 19:19 1214464 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\urlmon.dll
+ 2011-12-14 23:09 . 2011-11-04 19:19 5978624 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\mshtml.dll
+ 2011-12-14 23:09 . 2011-11-04 19:19 2001408 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\iertutil.dll
+ 2011-10-16 06:20 . 2012-01-11 22:58 52128560 c:\windows\system32\MRT.exe
- 2009-03-08 09:39 . 2011-08-23 22:48 11081728 c:\windows\system32\ieframe.dll
+ 2009-03-08 09:39 . 2011-11-04 19:20 11081728 c:\windows\system32\ieframe.dll
- 2011-10-16 06:22 . 2011-08-23 22:48 11081728 c:\windows\system32\dllcache\ieframe.dll
+ 2011-10-16 06:22 . 2011-11-04 19:20 11081728 c:\windows\system32\dllcache\ieframe.dll
+ 2011-09-16 00:39 . 2011-09-16 00:39 11163136 c:\windows\Installer\2c8be4.msp
+ 2011-09-16 00:38 . 2011-09-16 00:38 10838528 c:\windows\Installer\2c8bd9.msp
+ 2011-09-16 00:37 . 2011-09-16 00:37 16691712 c:\windows\Installer\2c89ef.msp
+ 2011-09-16 00:37 . 2011-09-16 00:37 34428416 c:\windows\Installer\2c89d5.msp
+ 2011-12-15 09:05 . 2011-08-23 22:48 11081728 c:\windows\ie8updates\KB2618444-IE8\ieframe.dll
+ 2012-01-12 03:15 . 2012-01-12 03:15 11817472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\62e34cfb5a8b233667c7c5a47a32ad93\System.Web.ni.dll
+ 2012-01-12 03:15 . 2012-01-12 03:15 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\2dac4fc006596760cd4988d0bfd52ff0\System.ServiceModel.ni.dll
+ 2012-01-11 22:58 . 2012-01-11 22:58 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\9e15d80ffb037e9171fa4bd2e0233497\System.Design.ni.dll
+ 2011-11-05 20:19 . 2011-11-05 20:19 11083776 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\ieframe.dll
+ 2011-09-16 00:34 . 2011-09-16 00:34 428804608 c:\windows\Installer\2c8bcf.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\prxtbZon0.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{91DA5E8A-3318-4F8C-B67E-5964DE3AB546}"= "c:\program files\ZoneAlarm_Security\prxtbZon0.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-10-28 94208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-02-10 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-02-10 118784]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-27 30040]
"Lexmark 5200 series"="c:\program files\Lexmark 5200 series\lxbtbmgr.exe" [2004-06-04 57344]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-11-02 59240]
"Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2011-11-12 268640]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2011-03-18 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2011-02-15 738808]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-01-16 421736]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-22 734872]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-11-4 176128]
KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\LeapFrog\\LeapFrog Connect\\LeapFrogConnect.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [7/11/2011 1:14 AM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/13/2011 6:30 AM 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [10/7/2011 6:23 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/11/2011 1:14 AM 295248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 6:09 AM 192776]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [2/15/2011 9:25 AM 26872]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [2/15/2011 9:25 AM 488952]
S1 MpKsl8fe9bb30;MpKsl8fe9bb30;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{73FF3ED9-1D24-44E3-94B8-BF6F20F2422D}\MpKsl8fe9bb30.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{73FF3ED9-1D24-44E3-94B8-BF6F20F2422D}\MpKsl8fe9bb30.sys [?]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe --> c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [?]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 6:25 AM 4433248]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [7/11/2011 1:14 AM 134608]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [7/11/2011 1:14 AM 24272]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [10/4/2011 6:21 AM 16720]
S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [12/29/2011 6:57 PM 18560]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 6:49 AM 227232]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2012-02-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1965331169-682003330-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-02-05 21:33]
.
2012-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1965331169-682003330-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-02-05 21:33]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
TCP: DhcpNameServer = 192.168.1.254
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
Toolbar-Locked - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-02-05 19:22
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4f,23,96,d2,ff,80,5c,4c,bf,c4,aa,\
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4f,23,96,d2,ff,80,5c,4c,bf,c4,aa,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4f,23,96,d2,ff,80,5c,4c,bf,c4,aa,\
.
[HKEY_USERS\S-1-5-21-854245398-1965331169-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,28,34,c7,97,ca,5c,eb,4d,96,aa,02,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,28,34,c7,97,ca,5c,eb,4d,96,aa,02,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,28,34,c7,97,ca,5c,eb,4d,96,aa,02,\
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,28,34,c7,97,ca,5c,eb,4d,96,aa,02,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,28,34,c7,97,ca,5c,eb,4d,96,aa,02,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(940)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'lsass.exe'(1000)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Completion time: 2012-02-05 19:25:11
ComboFix-quarantined-files.txt 2012-02-06 01:25
ComboFix2.txt 2011-11-30 00:07
ComboFix3.txt 2011-11-29 12:01
.
Pre-Run: 96,396,500,992 bytes free
Post-Run: 96,657,125,376 bytes free
.
- - End Of File - - 0F52C850946F150DF22158654C9C5A3D
[b]
[b]This is the second log.
ComboFix 12-02-05.02 - Administrator 02/05/2012 19:44:46.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1521 [GMT -6:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *Enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((( Files Created from 2012-01-06 to 2012-02-06 )))))))))))))))))))))))))))))))
.
.
2012-02-05 21:32 . 2012-02-05 21:33 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Deployment
2012-02-03 02:31 . 2011-08-16 10:45 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2012-02-03 01:21 . 2012-02-03 01:21 -------- d-----w- c:\program files\iPod
2012-02-03 01:21 . 2012-02-03 01:22 -------- d-----w- c:\program files\iTunes
2012-02-03 01:05 . 2012-02-03 01:19 -------- d-----w- c:\documents and settings\Administrator\Application Data\ElevatedDiagnostics
2012-02-03 01:03 . 2008-04-13 19:40 57600 -c--a-w- c:\windows\system32\dllcache\redbook.sys
2012-02-03 01:03 . 2008-04-13 19:40 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2012-02-03 00:23 . 2012-02-03 00:23 -------- d-----w- c:\program files\Common Files\Java
2012-02-03 00:22 . 2012-02-03 00:22 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-02-03 00:22 . 2012-02-03 00:22 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-02-03 00:22 . 2012-02-03 00:22 -------- d-----w- c:\program files\Java
2012-01-29 03:20 . 2012-01-29 03:20 -------- d-----w- C:\$AVG
2012-01-07 02:43 . 2012-01-07 02:43 -------- d-----w- c:\documents and settings\Administrator\Application Data\AVG2012
2012-01-07 02:41 . 2012-02-05 15:48 -------- d-----w- c:\windows\system32\drivers\AVG
2012-01-07 02:41 . 2012-01-31 03:53 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG2012
2012-01-07 02:41 . 2012-01-07 02:41 -------- d-----w- c:\program files\AVG
2012-01-07 02:17 . 2012-01-07 02:17 -------- d--h--w- c:\windows\system32\GroupPolicy
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-30 01:01 . 2011-10-16 00:56 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-25 21:57 . 2002-06-25 19:33 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-11-23 13:25 . 2002-06-25 19:32 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-18 12:35 . 2002-06-25 19:20 60416 ----a-w- c:\windows\system32\packager.exe
2011-11-16 14:21 . 2011-10-16 05:55 354816 ----a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:21 . 2002-06-25 19:24 152064 ----a-w- c:\windows\system32\schannel.dll
2011-11-12 17:18 . 2011-12-30 00:57 18560 ----a-w- c:\windows\system32\drivers\FlyUsb.sys
2011-10-16 08:04 . 2011-10-16 08:04 16409960 ----a-w- c:\program files\spybotsd162.exe
.
.
((((((((((((((((((((((((((((( SnapShot_2012-02-06_01.22.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-02-06 01:44 . 2012-02-06 01:44 16384 c:\windows\temp\Perflib_Perfdata_77c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\prxtbZon0.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{91DA5E8A-3318-4F8C-B67E-5964DE3AB546}"= "c:\program files\ZoneAlarm_Security\prxtbZon0.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-10-28 94208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-02-10 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-02-10 118784]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-27 30040]
"Lexmark 5200 series"="c:\program files\Lexmark 5200 series\lxbtbmgr.exe" [2004-06-04 57344]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-11-02 59240]
"Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2011-11-12 268640]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2011-03-18 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2011-02-15 738808]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-01-16 421736]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-22 734872]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-11-4 176128]
KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\LeapFrog\\LeapFrog Connect\\LeapFrogConnect.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [7/11/2011 1:14 AM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/13/2011 6:30 AM 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [10/7/2011 6:23 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/11/2011 1:14 AM 295248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 6:09 AM 192776]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [2/15/2011 9:25 AM 26872]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [2/15/2011 9:25 AM 488952]
S1 MpKsl8fe9bb30;MpKsl8fe9bb30;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{73FF3ED9-1D24-44E3-94B8-BF6F20F2422D}\MpKsl8fe9bb30.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{73FF3ED9-1D24-44E3-94B8-BF6F20F2422D}\MpKsl8fe9bb30.sys [?]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe --> c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [?]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 6:25 AM 4433248]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [7/11/2011 1:14 AM 134608]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [7/11/2011 1:14 AM 24272]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [10/4/2011 6:21 AM 16720]
S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [12/29/2011 6:57 PM 18560]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 6:49 AM 227232]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2012-02-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1965331169-682003330-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-02-05 21:33]
.
2012-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1965331169-682003330-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-02-05 21:33]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
TCP: DhcpNameServer = 192.168.1.254
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-02-05 19:51
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4f,23,96,d2,ff,80,5c,4c,bf,c4,aa,\
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4f,23,96,d2,ff,80,5c,4c,bf,c4,aa,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4f,23,96,d2,ff,80,5c,4c,bf,c4,aa,\
.
[HKEY_USERS\S-1-5-21-854245398-1965331169-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,28,34,c7,97,ca,5c,eb,4d,96,aa,02,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,28,34,c7,97,ca,5c,eb,4d,96,aa,02,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,28,34,c7,97,ca,5c,eb,4d,96,aa,02,\
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,28,34,c7,97,ca,5c,eb,4d,96,aa,02,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,28,34,c7,97,ca,5c,eb,4d,96,aa,02,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(952)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'lsass.exe'(1012)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Completion time: 2012-02-05 19:53:20
ComboFix-quarantined-files.txt 2012-02-06 01:53
ComboFix2.txt 2012-02-06 01:25
ComboFix3.txt 2011-11-30 00:07
ComboFix4.txt 2011-11-29 12:01
.
Pre-Run: 96,582,819,840 bytes free
Post-Run: 96,583,524,352 bytes free
.
- - End Of File - - ABDB622BD86361EAEEE16F26E15D0D65