Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

The instruction at "0x8b76aa7f3" referenced memory at "0x8b76aa7f3". The memory could not be "read".


  • This topic is locked This topic is locked
19 replies to this topic

#1 Haerith

Haerith

  • Members
  • 50 posts
  • OFFLINE
  •  
  • Local time:07:12 PM

Posted 25 June 2009 - 08:41 PM

Okay so I was browsing around the internet and somehow when I tried to run firefox after I restarted it once I got this following error:

The instruction at "0x8b76aa7f3" referenced memory at "0x8b76aa7f3". The memory could not be "read".

Click ok to terminate program.

Furthermore, I have no access to the internet. I've tried to find updates for my firewall with no success.
Thank you for your help.

And so here's my log:

Attached Files



BC AdBot (Login to Remove)

 


#2 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,766 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:01:12 AM

Posted 30 June 2009 - 06:16 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE

regards _temp_

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

 

Follow BleepingComputer on: Facebook | Twitter | Google+


#3 Haerith

Haerith
  • Topic Starter

  • Members
  • 50 posts
  • OFFLINE
  •  
  • Local time:07:12 PM

Posted 30 June 2009 - 04:51 PM

Hey, thanks for the help.

I tried to run the DDS file but I couldn't. I turned off all my firewalls/antivirus but I ended up getting the following error:


The instruction at "0x8c26a7f3" referenced memory at "0x8c26a7f3". The memory could not be "written".

Click on OK to terminate the program.


I also forgot to mention that when I started up my computer a few days ago my COMODO Firewall spammed messages at the bottom right, usually saying that the file SKYNETnvobrrvk.dll was modifying files. I'm not sure if this file is the problem but it could be possible.

Thanks for the help again.

#4 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:02:12 AM

Posted 02 July 2009 - 04:43 PM

Hi,

Please rename dds to whatever.scr and try running it again. Let me know how it goes.

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.


#5 Haerith

Haerith
  • Topic Starter

  • Members
  • 50 posts
  • OFFLINE
  •  
  • Local time:07:12 PM

Posted 02 July 2009 - 07:52 PM

It worked! Here are the results. There is an attachment as well.


DDS (Ver_09-06-26.01) - NTFSx86
Run by User at 20:37:34.79 on Thu 07/02/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [COMODO Firewall Pro] "c:\program files\comodo\firewall\cfp.exe" -h
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
mRun: [COMODO Internet Security] "c:\program files\comodo\firewall\cfp.exe" -h
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\user\start menu\programs\imvu\Run IMVU.lnk
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scan8/oscan8.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1198356628938
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C9A2CBF3-B7F9-463E-A690-82CC077DCFC6} - hxxp://www.4story.com/Active_X/ZemiDetectHardware.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://www.driveragent.com/files/driveragent.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\6d36xtix.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\documents and settings\user\application data\mozilla\plugins\npoctoshape.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npracplug.dll
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2009-06-25 20:01 <DIR> --d----- C:\ComboFix
2009-06-25 20:01 389,120 a------- c:\windows\system32\CF25298.exe
2009-06-23 08:50 0 a----r-- C:\logwmemory.bin
2009-06-23 08:49 <DIR> --d----- c:\docume~1\user\applic~1\Soldat
2009-06-13 16:34 <DIR> --d----- c:\program files\Zemi Interactive
2009-06-13 16:29 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Estsoft
2009-06-13 16:28 <DIR> --d----- c:\program files\ESTsoft
2009-06-13 16:28 <DIR> --d----- c:\docume~1\user\applic~1\ESTsoft
2009-06-11 20:20 15,688 a------- c:\windows\system32\lsdelete.exe
2009-06-08 22:08 <DIR> --d----- c:\docume~1\user\applic~1\Toribash
2009-06-08 22:07 <DIR> --d----- C:\Games
2009-06-08 15:17 <DIR> --d----- C:\nDoors
2009-06-08 11:42 <DIR> --d----- c:\program files\DNA
2009-06-08 11:42 <DIR> --d----- c:\docume~1\user\applic~1\DNA

==================== Find3M ====================

2009-05-22 22:09 168,208 a------- c:\windows\system32\guard32.dll
2009-05-22 22:09 24,096 a------- c:\windows\system32\drivers\cmdhlp.sys
2009-05-22 22:09 132,640 a------- c:\windows\system32\drivers\cmdguard.sys
2009-05-21 11:33 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-15 15:27 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-05-15 15:27 325,896 a------- c:\windows\system32\drivers\avgldx86.sys
2009-05-07 11:32 345,600 a------- c:\windows\system32\localspl.dll
2009-04-29 00:56 827,392 a------- c:\windows\system32\wininet.dll
2009-04-29 00:55 78,336 a------- c:\windows\system32\ieencode.dll
2009-04-17 08:26 1,847,168 a------- c:\windows\system32\win32k.sys
2009-04-15 10:51 585,216 a------- c:\windows\system32\rpcrt4.dll
2009-01-03 09:21 15,706 a------- c:\program files\changes.txt
2009-01-01 08:58 1,852 a------- c:\program files\README.HTM
2008-11-11 12:10 1,927,850,032 a------- c:\program files\data2.cab
2008-11-11 12:10 751,167 a------- c:\program files\data1.hdr
2008-11-11 12:10 435 a------- c:\program files\layout.bin
2008-11-11 12:08 6,114,737 a------- c:\program files\data1.cab
2008-11-11 12:05 94 a------- c:\program files\Setup.ini
2008-11-11 12:05 169,305 a------- c:\program files\Setup.inx
2008-03-08 11:20 774,144 a------- c:\program files\RngInterstitial.dll
2007-07-30 19:30 470,240 a------- c:\program files\setup.bmp
2007-03-14 15:16 346,602 a------- c:\program files\ikernel.ex_
2008-10-05 17:00 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100520081006\index.dat

============= FINISH: 20:41:43.21 ===============

Attached Files



#6 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:02:12 AM

Posted 03 July 2009 - 02:17 AM

Hi,

It seems that ComboFix has been run in the system (not recommended unless supervised!). Please post back contents of ComboFix.txt log from that earlier run. You'll find it probably in c: root (c:\).

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.


#7 Haerith

Haerith
  • Topic Starter

  • Members
  • 50 posts
  • OFFLINE
  •  
  • Local time:07:12 PM

Posted 05 July 2009 - 05:42 PM

I was unable to find the ComboFix.txt log file on my computer. I am unsure if my brother has used the ComboFix log by himself or with help from a HJT Team assistant in the past. I also was unable to search my computer as the same error as read in the topic title shows. What do you think?

#8 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:02:12 AM

Posted 06 July 2009 - 03:33 AM

Hi,

Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
    Remember to re-enable them afterwards.

  • Click Yes to allow ComboFix to continue scanning for malware.
When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds.txt log.


A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.


#9 Haerith

Haerith
  • Topic Starter

  • Members
  • 50 posts
  • OFFLINE
  •  
  • Local time:07:12 PM

Posted 06 July 2009 - 08:58 PM

ComboFix 09-07-06.02 - User 07/06/2009 19:43.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.533 [GMT -4:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
.
/wow section - STAGE 1
'PV' is not recognized as an internal or external command


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Installer\165a689.msp
c:\windows\Installer\165a68a.msp
c:\windows\Installer\165a68b.msp
c:\windows\Installer\165a68c.msp
c:\windows\Installer\165a68d.msp
c:\windows\Installer\165a68e.msp
c:\windows\Installer\165a68f.msp
c:\windows\Installer\165a690.msp
c:\windows\Installer\165a691.msp
c:\windows\Installer\16e11d9.msp
c:\windows\Installer\16e11da.msp
c:\windows\Installer\16e11db.msp
c:\windows\Installer\16e11dc.msp
c:\windows\Installer\16e11dd.msp
c:\windows\Installer\16e11de.msp
c:\windows\Installer\16e11df.msp
c:\windows\Installer\16e11e0.msp
c:\windows\Installer\16e11e1.msp
c:\windows\Installer\16e11e2.msp
c:\windows\Installer\17cc3.msi
c:\windows\Installer\1edd6e8.msi
c:\windows\Installer\1f3ecd9.msp
c:\windows\Installer\1f3ecee.msp
c:\windows\Installer\6d117aa.msp
c:\windows\system32\drivers\SKYNETppqlxrrm.sys
c:\windows\system32\SKYNETbgikhllr.dat
c:\windows\system32\SKYNETmtkdbvcv.dat
c:\windows\system32\SKYNETnvobrrvk.dll
c:\windows\system32\SKYNETqsallhsb.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_SKYNETiqaomyqb


((((((((((((((((((((((((( Files Created from 2009-06-06 to 2009-07-06 )))))))))))))))))))))))))))))))
.

2009-07-06 23:25 . 2009-07-06 23:26 -------- d-----w- C:\32788R22FWJFW
2009-06-27 21:13 . 2009-06-27 21:13 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Help
2009-06-23 12:50 . 2009-03-28 23:52 94208 ----a-w- c:\documents and settings\User\Application Data\Soldat\Battleye\BEServer.dll
2009-06-23 12:50 . 2009-03-28 23:52 102400 ----a-w- c:\documents and settings\User\Application Data\Soldat\Battleye\BEClient.dll
2009-06-23 12:50 . 2009-06-23 12:50 0 ----a-r- C:\logwmemory.bin
2009-06-23 12:49 . 2009-06-23 12:49 -------- d-----w- c:\documents and settings\User\Application Data\Soldat
2009-06-15 17:23 . 2009-06-15 17:23 541696 ----a-w- c:\documents and settings\User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv304-0905011-0-main.dll
2009-06-13 20:34 . 2009-06-13 20:34 -------- d-----w- c:\program files\Zemi Interactive
2009-06-13 20:29 . 2009-06-13 20:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Estsoft
2009-06-13 20:28 . 2009-06-13 23:53 -------- d-----w- c:\program files\ESTsoft
2009-06-13 20:28 . 2009-06-13 20:29 -------- d-----w- c:\documents and settings\User\Application Data\ESTsoft
2009-06-12 00:20 . 2009-05-28 22:52 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-09 20:13 . 2009-06-09 20:13 152576 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-09 02:08 . 2009-06-09 02:08 -------- d-----w- c:\documents and settings\User\Application Data\Toribash
2009-06-09 02:07 . 2009-06-09 02:07 -------- d-----w- C:\Games
2009-06-08 19:17 . 2009-06-08 19:17 -------- d-----w- C:\nDoors
2009-06-08 15:42 . 2009-06-08 15:42 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\DNA
2009-06-08 15:42 . 2009-06-27 21:14 -------- d-----w- c:\documents and settings\User\Application Data\DNA
2009-06-08 15:42 . 2009-06-27 18:18 -------- d-----w- c:\program files\DNA

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-06 23:42 . 2008-04-17 19:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-26 01:14 . 2009-01-08 23:49 -------- d-----w- c:\program files\Steam
2009-06-25 04:08 . 2009-01-12 04:19 -------- d-----w- c:\documents and settings\User\Application Data\mIRC
2009-06-25 04:01 . 2009-01-12 04:19 -------- d-----w- c:\program files\mIRC
2009-06-25 02:38 . 2007-12-22 22:19 694464 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-25 01:48 . 2009-05-13 02:08 -------- d-----w- c:\program files\compLexity Demo Player
2009-06-17 00:09 . 2008-11-06 01:49 -------- d-----w- c:\program files\Diablo II
2009-06-15 16:26 . 2008-10-01 00:19 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-13 20:52 . 2007-12-22 19:35 73088 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-09 20:15 . 2009-04-26 17:56 -------- d-----w- c:\program files\Java
2009-06-08 21:52 . 2007-12-22 20:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-05 19:24 . 2008-05-31 22:47 -------- d-----w- c:\program files\StarCraft
2009-06-03 19:38 . 2008-05-24 17:32 -------- d-----w- c:\program files\StealthBot
2009-05-28 22:52 . 2009-05-28 22:52 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lsdelete.exe
2009-05-28 22:52 . 2009-05-28 22:52 83808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\ShellExt.dll
2009-05-28 22:52 . 2009-05-28 22:52 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\RPAPI.dll
2009-05-28 22:52 . 2009-05-28 22:52 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\PrivacyClean.dll
2009-05-27 20:16 . 2009-04-11 18:45 120088 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Plugins\npoctoshape.dll
2009-05-27 20:08 . 2009-05-27 20:08 -------- d-----w- c:\program files\RivaTuner v2.24
2009-05-25 10:50 . 2009-05-27 19:13 401920 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\sua-0905250-0-libOctoshapeClient.dll
2009-05-25 10:50 . 2009-05-27 19:13 120088 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\sua-0905250-0-npoctoshape.dll
2009-05-25 10:50 . 2009-05-27 19:13 124184 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\sua-0905250-0-apoctoshape.dll
2009-05-23 02:09 . 2008-10-01 00:12 168208 ----a-w- c:\windows\system32\guard32.dll
2009-05-23 02:09 . 2008-10-01 00:12 82080 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-05-23 02:09 . 2008-10-01 00:12 24096 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-05-23 02:09 . 2008-10-01 00:12 132640 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-05-22 19:41 . 2008-08-17 19:25 -------- d-----w- c:\documents and settings\User\Application Data\Ventrilo
2009-05-21 15:33 . 2009-04-26 17:57 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-15 19:27 . 2008-10-01 00:19 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-05-15 19:27 . 2008-10-01 00:19 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-15 19:27 . 2008-10-01 00:19 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-10 04:46 . 2009-05-10 04:46 -------- d-----w- c:\documents and settings\User\Application Data\Auslogics
2009-05-10 04:38 . 2009-05-10 04:38 -------- d-----w- c:\program files\Auslogics
2009-05-07 15:32 . 2004-08-03 13:56 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-02 04:37 . 2009-05-02 04:37 10134 ----a-r- c:\documents and settings\User\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2009-05-02 04:33 . 2009-05-02 04:33 10134 ----a-r- c:\documents and settings\User\Application Data\Microsoft\Installer\{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}\ARPPRODUCTICON.exe
2009-05-02 04:29 . 2009-05-02 04:29 10134 ----a-r- c:\documents and settings\User\Application Data\Microsoft\Installer\{56918C0C-0D87-4CA6-92BF-4975A43AC719}\ARPPRODUCTICON.exe
2009-04-30 22:52 . 2009-04-30 22:53 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-04-30 22:52 . 2009-04-30 22:52 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Drivers\32\lbd.sys
2009-04-29 04:56 . 2004-08-03 13:56 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-03 13:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-25 13:20 . 2009-04-25 13:20 576512 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\pmv302-0810271-0-libOctoshapeClient.dll
2009-04-17 12:26 . 2004-08-03 12:17 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-03 13:56 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-11 18:48 . 2009-04-11 18:48 585728 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\pmv302a-0902180-0-libOctoshapeClient.dll
2009-01-03 13:21 . 2009-01-03 13:21 15706 ----a-w- c:\program files\changes.txt
2009-01-01 12:58 . 2009-01-01 12:58 1852 ----a-w- c:\program files\README.HTM
2008-11-11 16:10 . 2008-11-23 03:51 751167 ----a-w- c:\program files\data1.hdr
2008-11-11 16:10 . 2008-11-23 03:51 435 ----a-w- c:\program files\layout.bin
2008-11-11 16:10 . 2008-11-23 03:48 1927850032 ----a-w- c:\program files\data2.cab
2008-11-11 16:08 . 2008-11-23 03:51 6114737 ----a-w- c:\program files\data1.cab
2008-11-11 16:05 . 2008-11-23 03:51 94 ----a-w- c:\program files\Setup.ini
2008-11-11 16:05 . 2008-11-23 03:51 169305 ----a-w- c:\program files\Setup.inx
2008-03-08 15:20 . 2008-03-08 15:21 774144 ----a-w- c:\program files\RngInterstitial.dll
2007-07-30 23:30 . 2008-11-23 03:51 470240 ----a-w- c:\program files\setup.bmp
2007-03-14 19:16 . 2008-11-23 03:51 346602 ----a-w- c:\program files\ikernel.ex_
.

((((((((((((((((((((((((((((( SnapShot@2009-05-10_04.33.30 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-06 23:42 . 2009-07-06 23:42 16384 c:\windows\temp\Perflib_Perfdata_39c.dat
+ 2009-06-13 20:41 . 2009-03-16 18:18 69448 c:\windows\system32\XAPOFX1_3.dll
+ 2009-06-13 20:41 . 2008-10-27 14:04 70992 c:\windows\system32\XAPOFX1_2.dll
+ 2009-06-13 20:41 . 2009-03-16 18:18 22360 c:\windows\system32\X3DAudio1_6.dll
+ 2009-06-13 20:41 . 2008-10-27 14:04 23376 c:\windows\system32\X3DAudio1_5.dll
+ 2008-07-30 01:10 . 2008-07-30 01:10 26112 c:\windows\system32\TsWpfWrp.exe
+ 2007-12-22 20:55 . 2007-11-30 11:18 26488 c:\windows\system32\spupdsvc.exe
- 2007-12-22 20:55 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe
+ 2007-12-22 22:14 . 2008-07-06 12:06 89088 c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
+ 2007-12-22 22:10 . 2008-07-09 07:38 17272 c:\windows\system32\spmsg.dll
- 2007-12-22 22:10 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
+ 2008-07-29 23:59 . 2008-07-29 23:59 43544 c:\windows\system32\PresentationHostProxy.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 44544 c:\windows\system32\pngfilt.dll
+ 2004-08-03 13:56 . 2009-04-29 04:56 44544 c:\windows\system32\pngfilt.dll
+ 2002-09-03 04:51 . 2009-05-13 02:16 85028 c:\windows\system32\perfc009.dat
- 2008-07-25 16:17 . 2007-10-24 05:47 15360 c:\windows\system32\mui\0409\mscorees.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 15360 c:\windows\system32\mui\0409\mscorees.dll
+ 2007-08-13 23:54 . 2009-04-29 04:55 52224 c:\windows\system32\msfeedsbs.dll
- 2007-08-13 23:54 . 2009-02-20 18:09 52224 c:\windows\system32\msfeedsbs.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 83968 c:\windows\system32\mscories.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 27648 c:\windows\system32\jsproxy.dll
+ 2004-08-03 13:56 . 2009-04-29 04:55 27648 c:\windows\system32\jsproxy.dll
+ 2008-07-29 23:24 . 2008-07-29 23:24 97800 c:\windows\system32\infocardapi.dll
- 2007-08-13 23:39 . 2009-02-20 10:20 13824 c:\windows\system32\ieudinit.exe
+ 2007-08-13 23:39 . 2009-04-28 09:05 13824 c:\windows\system32\ieudinit.exe
- 2004-08-03 13:56 . 2009-02-20 18:09 44544 c:\windows\system32\iernonce.dll
+ 2004-08-03 13:56 . 2009-04-29 04:55 44544 c:\windows\system32\iernonce.dll
- 2004-08-03 13:56 . 2009-02-20 10:20 70656 c:\windows\system32\ie4uinit.exe
+ 2004-08-03 13:56 . 2009-04-28 09:05 70656 c:\windows\system32\ie4uinit.exe
+ 2008-07-29 23:24 . 2008-07-29 23:24 11264 c:\windows\system32\icardres.dll
+ 2007-08-13 23:36 . 2009-04-29 04:55 63488 c:\windows\system32\icardie.dll
- 2007-08-13 23:36 . 2009-02-20 18:09 63488 c:\windows\system32\icardie.dll
+ 2008-07-30 01:10 . 2008-07-30 01:10 73720 c:\windows\system32\dxva2.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2004-08-03 13:56 . 2009-04-29 04:56 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2007-12-24 14:26 . 2009-04-29 04:55 52224 c:\windows\system32\dllcache\msfeedsbs.dll
- 2007-12-24 14:26 . 2009-02-20 18:09 52224 c:\windows\system32\dllcache\msfeedsbs.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-03 13:56 . 2009-04-29 04:55 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2007-12-24 14:26 . 2009-02-20 10:20 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2007-12-24 14:26 . 2009-04-28 09:05 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2004-08-03 13:56 . 2009-04-29 04:55 44544 c:\windows\system32\dllcache\iernonce.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\iernonce.dll
- 2009-02-20 18:09 . 2009-02-20 18:09 78336 c:\windows\system32\dllcache\ieencode.dll
+ 2009-02-20 18:09 . 2009-04-29 04:55 78336 c:\windows\system32\dllcache\ieencode.dll
+ 2004-08-03 13:56 . 2009-04-28 09:05 70656 c:\windows\system32\dllcache\ie4uinit.exe
- 2004-08-03 13:56 . 2009-02-20 10:20 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-12-24 14:26 . 2009-04-29 04:55 63488 c:\windows\system32\dllcache\icardie.dll
- 2007-12-24 14:26 . 2009-02-20 18:09 63488 c:\windows\system32\dllcache\icardie.dll
+ 2006-10-14 21:43 . 2008-07-06 12:06 89088 c:\windows\system32\dllcache\filterpipelineprintproc.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 96760 c:\windows\system32\dfshim.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 96760 c:\windows\system32\dfshim.dll
- 2007-12-22 19:18 . 2008-10-05 21:01 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-22 19:18 . 2009-07-06 23:18 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-22 19:18 . 2008-10-05 21:01 49152 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-22 19:18 . 2009-07-06 23:18 49152 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-12-22 19:18 . 2008-10-05 21:01 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2007-12-22 19:18 . 2009-07-06 23:18 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-07-30 03:40 . 2008-07-30 03:40 70648 c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
+ 2008-07-30 03:40 . 2008-07-30 03:40 91136 c:\windows\Microsoft.NET\Framework\v3.5\MSBuild.exe
+ 2008-07-30 03:40 . 2008-07-30 03:40 41984 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft.VisualC.STLCLR.dll
+ 2008-07-30 03:40 . 2008-07-30 03:40 40960 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft.Data.Entity.Build.Tasks.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 89080 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.2052.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 92664 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1042.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 95224 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1041.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 89592 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1028.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 84480 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.2052.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 94720 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1042.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 97792 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1041.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 84992 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1028.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 97280 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\DeleteTemp.exe
+ 2008-07-30 03:40 . 2008-07-30 03:40 95224 c:\windows\Microsoft.NET\Framework\v3.5\EdmGen.exe
+ 2008-07-30 03:40 . 2008-07-30 03:40 78856 c:\windows\Microsoft.NET\Framework\v3.5\DataSvcUtil.exe
+ 2008-07-30 03:40 . 2008-07-30 03:40 41984 c:\windows\Microsoft.NET\Framework\v3.5\AddInUtil.exe
+ 2008-07-30 03:40 . 2008-07-30 03:40 41992 c:\windows\Microsoft.NET\Framework\v3.5\AddInProcess32.exe
+ 2008-07-30 03:40 . 2008-07-30 03:40 41992 c:\windows\Microsoft.NET\Framework\v3.5\AddInProcess.exe
+ 2008-07-30 01:10 . 2008-07-30 01:10 46104 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
+ 2008-07-29 23:59 . 2008-07-29 23:59 32768 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationCFFRasterizer.dll
- 2008-07-30 00:59 . 2006-10-21 02:21 32768 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationCFFRasterizer.dll
+ 2008-07-30 01:10 . 2008-07-30 01:10 71160 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PenIMC.dll
+ 2008-07-29 23:32 . 2008-07-29 23:32 17448 c:\windows\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\PerformanceCounterInstaller.exe
+ 2008-07-29 23:16 . 2008-07-29 23:16 32768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
+ 2008-07-29 23:16 . 2008-07-29 23:16 73728 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.Install.dll
+ 2008-07-29 23:16 . 2008-07-29 23:16 20504 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceMonikerSupport.dll
+ 2008-07-29 23:16 . 2008-07-29 23:16 11280 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 37896 c:\windows\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 37896 c:\windows\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 81400 c:\windows\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL
- 2008-07-25 16:17 . 2007-10-24 05:47 81400 c:\windows\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL
+ 2008-07-25 15:17 . 2008-07-25 15:17 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 57392 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 57392 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 95232 c:\windows\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 95232 c:\windows\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 16896 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 16896 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 61952 c:\windows\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe
+ 2008-07-25 15:17 . 2008-07-25 15:17 61952 c:\windows\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe
- 2008-07-25 16:17 . 2007-10-24 05:47 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
+ 2008-07-25 15:17 . 2008-07-25 15:17 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- 2008-07-25 16:17 . 2007-10-24 05:47 53248 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
+ 2008-07-25 15:17 . 2008-07-25 15:17 53248 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
+ 2008-07-25 15:17 . 2008-07-25 15:17 88584 c:\windows\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 24584 c:\windows\Microsoft.NET\Framework\v2.0.50727\normalization.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 24584 c:\windows\Microsoft.NET\Framework\v2.0.50727\normalization.dll
- 2007-10-24 05:47 . 2007-10-24 05:47 31744 c:\windows\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 31744 c:\windows\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 19456 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscortim.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 19456 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscortim.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
- 2008-07-25 16:16 . 2007-10-24 05:47 18944 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 18944 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 77312 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 77312 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 94208 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorld.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 94208 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorld.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 46592 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorie.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 83456 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 83456 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
+ 2008-07-25 15:16 . 2008-07-25 15:16 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
- 2008-07-25 16:16 . 2007-10-24 05:47 97792 c:\windows\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 97792 c:\windows\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 12800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 12800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 40960 c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
+ 2008-07-25 15:16 . 2008-07-25 15:16 40960 c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
- 2008-07-25 16:17 . 2007-10-24 05:47 72192 c:\windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 72192 c:\windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 65032 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 65032 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
+ 2008-07-25 15:17 . 2008-07-25 15:17 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
- 2008-07-25 16:17 . 2007-10-24 05:47 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEHost.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEHost.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 18936 c:\windows\Microsoft.NET\Framework\v2.0.50727\fusion.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 18936 c:\windows\Microsoft.NET\Framework\v2.0.50727\fusion.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 62968 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfdll.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 35320 c:\windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe
+ 2008-07-25 15:16 . 2008-07-25 15:16 35320 c:\windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe
- 2008-07-25 16:17 . 2007-10-24 05:47 69120 c:\windows\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 69120 c:\windows\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 27136 c:\windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 27136 c:\windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 13312 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 13312 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 80376 c:\windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
+ 2008-07-25 15:16 . 2008-07-25 15:16 80376 c:\windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
+ 2008-07-25 15:17 . 2008-07-25 15:17 89608 c:\windows\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 33792 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2008-07-25 15:16 . 2008-07-25 15:16 34312 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
+ 2008-07-25 15:16 . 2008-07-25 15:16 33288 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe
+ 2008-07-25 15:16 . 2008-07-25 15:16 24576 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
- 2008-07-25 16:16 . 2007-10-24 05:47 24576 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
- 2008-07-25 16:16 . 2007-10-24 05:47 84480 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 84480 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 33800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 17416 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 22024 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 22024 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
+ 2008-07-25 15:16 . 2008-07-25 15:16 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
+ 2008-07-25 15:17 . 2008-07-25 15:17 58880 c:\windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
+ 2008-07-25 15:16 . 2008-07-25 15:16 98808 c:\windows\Microsoft.NET\Framework\v2.0.50727\alink.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 10752 c:\windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 10752 c:\windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 13824 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 13824 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 96768 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 16896 c:\windows\Microsoft.NET\Framework\SharedReg12.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 16896 c:\windows\Microsoft.NET\Framework\SharedReg12.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 16896 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 16896 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 16896 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 16896 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 16896 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 16896 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 82944 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
+ 2008-07-25 15:16 . 2008-07-25 15:16 82944 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
+ 2008-07-30 04:07 . 2008-07-30 04:07 23040 c:\windows\Installer\7dd9d9.msp
+ 2009-05-13 02:16 . 2009-05-13 02:16 88576 c:\windows\Installer\78b209.msi
+ 2009-03-31 21:49 . 2009-03-31 21:49 51712 c:\windows\Installer\483677.msi
+ 2007-12-22 21:38 . 2009-06-11 03:49 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2007-12-22 21:38 . 2009-04-30 23:43 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2007-12-22 21:38 . 2009-06-11 03:49 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2007-12-22 21:38 . 2009-04-30 23:43 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2007-12-22 21:38 . 2009-06-11 03:49 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2007-12-22 21:38 . 2009-04-30 23:43 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2007-12-22 21:38 . 2009-06-11 03:49 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2007-12-22 21:38 . 2009-04-30 23:43 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2007-12-22 21:38 . 2009-06-11 03:49 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2007-12-22 21:38 . 2009-04-30 23:43 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2007-12-22 21:38 . 2009-06-11 03:49 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2007-12-22 21:38 . 2009-04-30 23:43 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2007-03-22 23:05 . 2007-03-22 23:05 97632 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\PP7X32.DLL
+ 2009-06-11 03:42 . 2009-02-20 18:09 44544 c:\windows\ie7updates\KB969897-IE7\pngfilt.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 52224 c:\windows\ie7updates\KB969897-IE7\msfeedsbs.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 27648 c:\windows\ie7updates\KB969897-IE7\jsproxy.dll
+ 2009-06-11 03:42 . 2009-02-20 10:20 13824 c:\windows\ie7updates\KB969897-IE7\ieudinit.exe
+ 2009-06-11 03:42 . 2009-02-20 18:09 44544 c:\windows\ie7updates\KB969897-IE7\iernonce.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 78336 c:\windows\ie7updates\KB969897-IE7\ieencode.dll
+ 2009-06-11 03:42 . 2009-02-20 10:20 70656 c:\windows\ie7updates\KB969897-IE7\ie4uinit.exe
+ 2009-06-11 03:42 . 2009-02-20 18:09 63488 c:\windows\ie7updates\KB969897-IE7\icardie.dll
+ 2009-05-13 02:17 . 2008-07-06 12:06 89088 c:\windows\Driver Cache\i386\filterpipelineprintproc.dll
+ 2009-05-13 02:23 . 2009-05-13 02:23 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\8f5c0e1b77c840d99a68897898317b79\UIAutomationProvider.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\b5a285233229bb4f9d9831ebf27fe9ac\System.Windows.Presentation.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\17e2a7113434da494a846a8f4e4ac5e9\System.Web.DynamicData.Design.ni.dll
+ 2009-05-13 12:02 . 2009-05-13 12:02 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\a8e047504bdad9ec14efd483574b0dd5\System.ComponentModel.DataAnnotations.ni.dll
+ 2009-05-13 12:02 . 2009-05-13 12:02 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\f2b48eab657b4ef1d19dac11bdf0c913\System.AddIn.Contract.ni.dll
+ 2009-05-13 02:26 . 2009-05-13 02:26 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\9469981a17c01dd154c540127e678b35\PresentationFontCache.ni.exe
+ 2009-05-13 02:22 . 2009-05-13 02:22 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\487c1bc20f6e73e8e79503898d17d102\PresentationCFFRasterizer.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\28ea74096df47800fe2c78bb2b9a4f2a\Microsoft.Vsa.ni.dll
+ 2009-05-13 02:23 . 2009-05-13 02:23 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\f0e9a97ade4529d4caeccd467aa8e7db\Microsoft.VisualC.ni.dll
+ 2009-05-13 12:01 . 2009-05-13 12:01 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\66359457e427c0d547750a79f754f9ba\Microsoft.Build.Framework.ni.dll
+ 2009-05-13 02:22 . 2009-05-13 02:22 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\36dbc4689f7c51e393504230004c9dec\Microsoft.Build.Framework.ni.dll
+ 2009-05-13 12:01 . 2009-05-13 12:01 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\a2865dcec9c5d3cc9c55f026cbad6fcc\dfsvc.ni.exe
+ 2009-05-13 02:23 . 2009-05-13 02:23 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\c2af7cfbb47c077029a2645930b4eeac\Accessibility.ni.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 94208 c:\windows\assembly\GAC_MSIL\WindowsFormsIntegration\3.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 98304 c:\windows\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 40960 c:\windows\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 12288 c:\windows\assembly\GAC_MSIL\System.Windows.Presentation\3.5.0.0__b77a5c561934e089\System.Windows.Presentation.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 61440 c:\windows\assembly\GAC_MSIL\System.Web.Routing\3.5.0.0__31bf3856ad364e35\System.Web.Routing.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 32768 c:\windows\assembly\GAC_MSIL\System.Web.DynamicData.Design\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.Design.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 77824 c:\windows\assembly\GAC_MSIL\System.Web.Abstractions\3.5.0.0__31bf3856ad364e35\System.Web.Abstractions.dll
+ 2009-05-13 02:18 . 2009-05-13 02:18 32768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
+ 2009-05-13 02:18 . 2009-05-13 02:18 73728 c:\windows\assembly\GAC_MSIL\System.ServiceModel.Install\3.0.0.0__b77a5c561934e089\System.ServiceModel.Install.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 53248 c:\windows\assembly\GAC_MSIL\System.Data.DataSetExtensions\3.5.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
+ 2009-05-13 02:16 . 2009-05-13 02:16 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 57344 c:\windows\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\3.5.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 45056 c:\windows\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 46104 c:\windows\assembly\GAC_MSIL\PresentationFontCache\3.0.0.0__31bf3856ad364e35\PresentationFontCache.exe
+ 2009-05-13 02:18 . 2009-05-13 02:18 32768 c:\windows\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll
- 2007-12-22 22:15 . 2007-12-22 22:15 32768 c:\windows\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2008-04-11 21:04 . 2008-04-11 21:04 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2009-05-13 02:20 . 2009-05-13 02:20 41984 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR\1.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.STLCLR.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2009-05-13 02:20 . 2009-05-13 02:20 94208 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.v3.5.dll
+ 2009-05-13 02:20 . 2009-05-13 02:20 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2008-04-11 21:04 . 2008-04-11 21:04 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2008-04-11 21:04 . 2008-04-11 21:04 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2008-04-11 21:04 . 2008-04-11 21:04 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2008-07-30 03:40 . 2008-07-30 03:40 5632 c:\windows\Microsoft.NET\Framework\v3.5\Sentinel.v3.5Client.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 7168 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 7168 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 5632 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
- 2008-07-25 16:17 . 2007-10-24 05:47 5632 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 6656 c:\windows\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 6656 c:\windows\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 8192 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 8192 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 9728 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
+ 2008-07-25 15:17 . 2008-07-25 15:17 9728 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
+ 2008-07-25 15:16 . 2008-07-25 15:16 5120 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
- 2008-07-25 16:16 . 2007-10-24 05:47 5120 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
- 2007-12-22 21:38 . 2009-04-30 23:43 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2007-12-22 21:38 . 2009-06-11 03:49 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-05-13 02:21 . 2009-05-13 02:21 5632 c:\windows\assembly\GAC_MSIL\Sentinel.v3.5Client\3.5.0.0__b03f5f7f11d50a3a\Sentinel.v3.5Client.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2008-04-11 21:04 . 2008-04-11 21:04 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2008-04-11 21:04 . 2008-04-11 21:04 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2009-05-13 02:16 . 2009-05-13 02:16 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 635904 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 558080 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcp80.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcm80.dll
+ 2008-07-30 01:26 . 2008-07-30 01:26 301568 c:\windows\system32\XPSViewer\XPSViewer.exe
+ 2006-10-15 01:21 . 2008-07-06 12:06 575488 c:\windows\system32\xpsshhdr.dll
+ 2009-06-13 20:41 . 2009-03-16 18:18 517448 c:\windows\system32\XAudio2_4.dll
+ 2009-06-13 20:41 . 2008-10-27 14:04 514384 c:\windows\system32\XAudio2_3.dll
+ 2009-06-13 20:41 . 2009-03-16 18:18 235352 c:\windows\system32\xactengine3_4.dll
+ 2009-06-13 20:41 . 2008-10-27 14:04 235856 c:\windows\system32\xactengine3_3.dll
+ 2008-09-06 04:29 . 2009-03-11 02:18 934792 c:\windows\system32\WgaTray.exe
+ 2008-09-06 04:30 . 2009-03-11 02:18 239496 c:\windows\system32\WgaLogon.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 233472 c:\windows\system32\webcheck.dll
+ 2004-08-03 13:56 . 2009-04-29 04:56 233472 c:\windows\system32\webcheck.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 105984 c:\windows\system32\url.dll
+ 2004-08-03 13:56 . 2009-04-29 04:56 105984 c:\windows\system32\url.dll
+ 2008-07-29 23:59 . 2008-07-29 23:59 161296 c:\windows\system32\UIAutomationCore.dll
+ 2007-12-22 22:14 . 2008-07-06 12:06 765440 c:\windows\system32\spool\XPSEP\i386\mxdwdrv.dll
+ 2007-12-22 22:14 . 2008-07-06 12:06 765440 c:\windows\system32\spool\XPSEP\i386\i386\mxdwdrv.dll
+ 2007-12-22 22:14 . 2008-07-06 12:06 748032 c:\windows\system32\spool\XPSEP\amd64\mxdwdrv.dll
+ 2007-12-22 22:14 . 2008-07-06 12:06 748032 c:\windows\system32\spool\XPSEP\amd64\amd64\mxdwdrv.dll
+ 2007-12-22 22:14 . 2008-07-06 12:06 147456 c:\windows\system32\spool\prtprocs\x64\filterpipelineprintproc.dll
+ 2006-10-14 21:44 . 2008-07-06 10:50 597504 c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
- 2006-10-14 21:40 . 2007-05-15 08:08 761344 c:\windows\system32\spool\drivers\w32x86\3\unires.dll
+ 2006-10-14 21:40 . 2008-03-13 04:52 761344 c:\windows\system32\spool\drivers\w32x86\3\unires.dll
+ 2006-10-14 21:42 . 2008-07-06 12:06 744960 c:\windows\system32\spool\drivers\w32x86\3\unidrvui.dll
+ 2006-10-14 21:42 . 2008-07-06 12:06 373248 c:\windows\system32\spool\drivers\w32x86\3\unidrv.dll
- 2006-10-14 21:42 . 2008-04-14 00:12 373248 c:\windows\system32\spool\drivers\w32x86\3\unidrv.dll
+ 2006-10-14 21:42 . 2008-07-06 12:06 198656 c:\windows\system32\spool\drivers\w32x86\3\mxdwdui.dll
+ 2006-10-14 21:43 . 2008-07-06 12:06 765440 c:\windows\system32\spool\drivers\w32x86\3\mxdwdrv.dll
+ 2006-10-14 21:43 . 2008-07-06 12:06 117760 c:\windows\system32\prntvpt.dll
+ 2008-07-29 23:59 . 2008-07-29 23:59 781344 c:\windows\system32\PresentationNative_v0300.dll
+ 2008-07-30 00:35 . 2008-07-30 00:35 326160 c:\windows\system32\PresentationHost.exe
+ 2008-07-29 23:59 . 2008-07-29 23:59 105016 c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
+ 2002-09-03 04:51 . 2009-05-13 02:16 475548 c:\windows\system32\perfh009.dat
- 2004-08-03 13:56 . 2009-02-20 18:09 102912 c:\windows\system32\occache.dll
+ 2004-08-03 13:56 . 2009-04-29 04:56 102912 c:\windows\system32\occache.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 671232 c:\windows\system32\mstime.dll
+ 2004-08-03 13:56 . 2009-04-29 04:56 671232 c:\windows\system32\mstime.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 193024 c:\windows\system32\msrating.dll
+ 2004-08-03 13:56 . 2009-04-29 04:56 193024 c:\windows\system32\msrating.dll
+ 2004-08-03 13:56 . 2009-04-29 04:56 477696 c:\windows\system32\mshtmled.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 477696 c:\windows\system32\mshtmled.dll
- 2007-08-13 23:54 . 2009-02-20 18:09 459264 c:\windows\system32\msfeeds.dll
+ 2007-08-13 23:54 . 2009-04-29 04:55 459264 c:\windows\system32\msfeeds.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 158720 c:\windows\system32\mscorier.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 158720 c:\windows\system32\mscorier.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 282112 c:\windows\system32\mscoree.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 282112 c:\windows\system32\mscoree.dll
+ 2009-06-09 20:15 . 2009-05-21 15:34 148888 c:\windows\system32\javaws.exe
- 2009-04-26 17:57 . 2009-04-26 17:56 148888 c:\windows\system32\javaws.exe
+ 2009-06-09 20:15 . 2009-05-21 15:34 144792 c:\windows\system32\javaw.exe
- 2009-04-26 17:57 . 2009-04-26 17:56 144792 c:\windows\system32\javaw.exe
+ 2009-06-09 20:15 . 2009-05-21 15:34 144792 c:\windows\system32\java.exe
- 2009-04-26 17:57 . 2009-04-26 17:56 144792 c:\windows\system32\java.exe
- 2007-08-13 23:34 . 2009-02-20 18:09 268288 c:\windows\system32\iertutil.dll
+ 2007-08-13 23:34 . 2009-04-29 04:55 268288 c:\windows\system32\iertutil.dll
+ 2004-08-03 13:56 . 2009-04-29 04:55 385024 c:\windows\system32\iedkcs32.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 385024 c:\windows\system32\iedkcs32.dll
+ 2007-07-11 17:27 . 2009-04-29 04:55 383488 c:\windows\system32\ieapfltr.dll
- 2007-07-11 17:27 . 2009-02-20 18:09 383488 c:\windows\system32\ieapfltr.dll
+ 2002-09-03 04:40 . 2009-04-25 05:26 161792 c:\windows\system32\ieakui.dll
- 2002-09-03 04:40 . 2009-02-20 05:14 161792 c:\windows\system32\ieakui.dll
+ 2004-08-03 13:56 . 2009-04-29 04:55 230400 c:\windows\system32\ieaksie.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 230400 c:\windows\system32\ieaksie.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 153088 c:\windows\system32\ieakeng.dll
+ 2004-08-03 13:56 . 2009-04-29 04:55 153088 c:\windows\system32\ieakeng.dll
+ 2008-07-29 23:24 . 2008-07-29 23:24 622080 c:\windows\system32\icardagt.exe
+ 2007-12-22 13:47 . 2009-06-14 17:23 267008 c:\windows\system32\FNTCACHE.DAT
+ 2004-08-03 13:56 . 2009-04-29 04:55 133120 c:\windows\system32\extmgr.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 133120 c:\windows\system32\extmgr.dll
+ 2008-07-30 01:10 . 2008-07-30 01:10 493048 c:\windows\system32\evr.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 214528 c:\windows\system32\dxtrans.dll
+ 2004-08-03 13:56 . 2009-04-29 04:55 214528 c:\windows\system32\dxtrans.dll
+ 2004-08-03 13:56 . 2009-04-29 04:55 347136 c:\windows\system32\dxtmsft.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 347136 c:\windows\system32\dxtmsft.dll
+ 2006-10-15 01:21 . 2008-07-06 12:06 575488 c:\windows\system32\dllcache\xpsshhdr.dll
+ 2004-08-03 13:56 . 2009-04-29 04:56 827392 c:\windows\system32\dllcache\wininet.dll
+ 2008-09-06 04:29 . 2009-03-11 02:18 934792 c:\windows\system32\dllcache\WgaTray.exe
+ 2008-09-06 04:30 . 2009-03-11 02:18 239496 c:\windows\system32\dllcache\wgaLogon.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2004-08-03 13:56 . 2009-04-29 04:56 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2004-08-03 13:56 . 2009-04-29 04:56 105984 c:\windows\system32\dllcache\url.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 105984 c:\windows\system32\dllcache\url.dll
+ 2009-04-15 14:51 . 2009-04-15 14:51 585216 c:\windows\system32\dllcache\rpcrt4.dll
+ 2006-10-14 21:44 . 2008-07-06 10:50 597504 c:\windows\system32\dllcache\printfilterpipelinesvc.exe
+ 2004-08-03 13:56 . 2009-04-29 04:56 102912 c:\windows\system32\dllcache\occache.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 102912 c:\windows\system32\dllcache\occache.dll
+ 2004-08-03 13:56 . 2009-04-29 04:56 671232 c:\windows\system32\dllcache\mstime.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 671232 c:\windows\system32\dllcache\mstime.dll
+ 2004-08-03 13:56 . 2009-04-29 04:56 193024 c:\windows\system32\dllcache\msrating.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 193024 c:\windows\system32\dllcache\msrating.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2004-08-03 13:56 . 2009-04-29 04:56 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-12-24 14:26 . 2009-04-29 04:55 459264 c:\windows\system32\dllcache\msfeeds.dll
- 2007-12-24 14:26 . 2009-02-20 18:09 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2009-05-07 15:32 . 2009-05-07 15:32 345600 c:\windows\system32\dllcache\localspl.dll
+ 2007-12-22 18:54 . 2009-04-25 05:27 636088 c:\windows\system32\dllcache\iexplore.exe
- 2007-12-24 14:26 . 2009-02-20 18:09 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2007-12-24 14:26 . 2009-04-29 04:55 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2004-08-03 13:56 . 2009-04-29 04:55 385024 c:\windows\system32\dllcache\iedkcs32.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 385024 c:\windows\system32\dllcache\iedkcs32.dll
+ 2007-12-24 14:26 . 2009-04-29 04:55 383488 c:\windows\system32\dllcache\ieapfltr.dll
- 2007-12-24 14:26 . 2009-02-20 18:09 383488 c:\windows\system32\dllcache\ieapfltr.dll
- 2002-09-03 04:40 . 2009-02-20 05:14 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2002-09-03 04:40 . 2009-04-25 05:26 161792 c:\windows\system32\dllcache\ieakui.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2004-08-03 13:56 . 2009-04-29 04:55 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2004-08-03 13:56 . 2009-04-29 04:55 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2004-08-03 13:56 . 2009-04-29 04:55 133120 c:\windows\system32\dllcache\extmgr.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 133120 c:\windows\system32\dllcache\extmgr.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2004-08-03 13:56 . 2009-04-29 04:55 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2004-08-03 13:56 . 2009-04-29 04:55 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-03 13:56 . 2009-04-29 04:55 124928 c:\windows\system32\dllcache\advpack.dll
+ 2009-06-13 20:41 . 2009-03-09 19:27 453456 c:\windows\system32\d3dx10_41.dll
+ 2009-06-13 20:41 . 2008-10-10 08:52 452440 c:\windows\system32\d3dx10_40.dll
- 2004-08-03 13:56 . 2009-02-20 18:09 124928 c:\windows\system32\advpack.dll
+ 2004-08-03 13:56 . 2009-04-29 04:55 124928 c:\windows\system32\advpack.dll
+ 2008-09-04 22:58 . 2004-07-17 00:41 366080 c:\windows\ServicePackFiles\i386\digreqex.msi
+ 2008-09-04 22:58 . 2004-07-17 00:41 863232 c:\windows\ServicePackFiles\i386\digopt.msi
+ 2008-07-30 03:40 . 2008-07-30 03:40 196104 c:\windows\Microsoft.NET\Framework\v3.5\WFServicesReg.exe
+ 2008-07-30 03:40 . 2008-07-30 03:40 802816 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft.Build.Tasks.v3.5.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 984056 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapUI.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 107512 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 111096 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.3082.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 110072 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.2070.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 106488 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1055.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 105976 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1053.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 107000 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1049.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 107512 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1046.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 109048 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1045.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 106488 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1044.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 108536 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1043.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 110072 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1040.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 111096 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1038.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 101368 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1037.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 112120 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1036.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 106488 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1035.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 113656 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1032.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 111608 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1031.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 108536 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1030.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 108536 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1029.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 102904 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1025.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 689152 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vsscenario.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 413184 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vsbasereqs.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 632320 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vs70uimgr.dll
+ 2009-05-13 02:20 . 2009-05-13 02:20 652800 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vs_setup.msi
+ 2008-07-29 22:47 . 2008-07-29 22:47 110080 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 131584 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.3082.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 131072 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.2070.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 121344 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1055.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 121344 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1053.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 123904 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1049.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 122880 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1046.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 128512 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1045.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 121856 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1044.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 129024 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1043.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 128512 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1040.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 132096 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1038.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 111104 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1037.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 133120 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1036.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 122368 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1035.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 137728 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1032.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 130048 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1031.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 126464 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1030.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 125440 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1029.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 113152 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1025.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 269304 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
+ 2008-07-29 22:47 . 2008-07-29 22:47 177152 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\HtmlLite.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 276984 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\dlmgr.dll
+ 2008-07-30 03:40 . 2008-07-30 03:40 233976 c:\windows\Microsoft.NET\Framework\v3.5\1033\vbc7ui.dll
+ 2008-07-30 03:40 . 2008-07-30 03:40 168448 c:\windows\Microsoft.NET\Framework\v3.5\1033\cscompui.dll
+ 2008-07-30 00:35 . 2008-07-30 00:35 864256 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationUI.dll
+ 2008-07-29 23:59 . 2008-07-29 23:59 132120 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
+ 2008-07-29 23:16 . 2008-07-29 23:16 152576 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\WsatConfig.exe
+ 2008-07-29 23:16 . 2008-07-29 23:16 966656 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
+ 2008-07-29 23:16 . 2008-07-29 23:16 132096 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
+ 2008-07-29 23:16 . 2008-07-29 23:16 110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
+ 2008-07-29 23:16 . 2008-07-29 23:16 156688 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelReg.exe
+ 2008-07-29 23:16 . 2008-07-29 23:16 163840 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.Dtc.dll
+ 2008-07-29 23:16 . 2008-07-29 23:16 397312 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.dll
+ 2008-07-29 23:24 . 2008-07-29 23:24 881664 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
+ 2008-07-29 23:16 . 2008-07-29 23:16 168968 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ComSvcConfig.exe
+ 2008-07-25 15:16 . 2008-07-25 15:16 438272 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 839680 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 839680 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 835584 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 261632 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 114688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 114688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 131072 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 131072 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 303104 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 372736 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Management.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 372736 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Management.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 113664 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 113664 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 626688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 188416 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 188416 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 401408 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 401408 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 970752 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 745472 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 486400 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 425984 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 425984 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 392184 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 118784 c:\windows\Microsoft.NET\Framework\v2.0.50727\shfusion.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 143360 c:\windows\Microsoft.NET\Framework\v2.0.50727\peverify.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 100856 c:\windows\Microsoft.NET\Framework\v2.0.50727\ngen.exe
+ 2008-07-25 15:17 . 2008-07-25 15:17 230912 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 345600 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 114176 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 367104 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 308224 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 308224 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 998408 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 659456 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 372736 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 372736 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 749568 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 749568 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 655360 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 655360 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 348160 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 348160 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 230904 c:\windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe
+ 2008-07-25 15:17 . 2008-07-25 15:17 230904 c:\windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe
+ 2008-07-25 15:17 . 2008-07-25 15:17 798224 c:\windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 798224 c:\windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 575496 c:\windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
- 2008-07-25 16:17 . 2007-10-24 05:47 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
- 2008-07-25 16:16 . 2007-10-24 05:47 507904 c:\windows\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 507904 c:\windows\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
- 2008-07-25 16:16 . 2007-10-24 05:47 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
- 2008-07-25 16:17 . 2007-10-24 05:47 147968 c:\windows\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 147968 c:\windows\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 218112 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 218112 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll
- 2008-07-25 16:17 . 2007-10-24 05:47 193016 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 193016 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 145408 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 145408 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll
+ 2007-12-25 15:37 . 2007-12-25 15:37 871424 c:\windows\Installer\d5326.msi
+ 2009-04-30 22:47 . 2009-04-30 22:47 236032 c:\windows\Installer\d0db0.msi
+ 2008-10-08 21:32 . 2008-10-08 21:32 804352 c:\windows\Installer\a6d6b.msi
+ 2008-03-10 21:50 . 2008-03-10 21:50 467456 c:\windows\Installer\926fbf.msi
+ 2008-11-30 04:29 . 2008-11-30 04:29 228352 c:\windows\Installer\8441f7e.msi
+ 2009-05-13 02:21 . 2009-05-13 02:21 648192 c:\windows\Installer\80099c.msi
+ 2008-07-30 04:23 . 2008-07-30 04:23 250880 c:\windows\Installer\7dd9e2.msp
+ 2008-07-30 04:28 . 2008-07-30 04:28 278016 c:\windows\Installer\7dd9e0.msp
+ 2008-07-30 02:40 . 2008-07-30 02:40 291840 c:\windows\Installer\7dd9de.msp
+ 2009-05-13 02:19 . 2009-05-13 02:19 137728 c:\windows\Installer\7dd9d8.msi
+ 2008-07-30 00:35 . 2008-07-30 00:35 553472 c:\windows\Installer\78b20e.msp
+ 2008-07-30 00:33 . 2008-07-30 00:33 506368 c:\windows\Installer\78b20c.msp
+ 2008-07-30 00:37 . 2008-07-30 00:37 911360 c:\windows\Installer\78b20b.msp
+ 2006-06-13 18:12 . 2006-06-13 18:12 509440 c:\windows\Installer\6845c0c.msp
+ 2008-07-28 14:28 . 2008-07-28 14:28 532992 c:\windows\Installer\43882a.msi
+ 2007-12-22 21:01 . 2007-12-22 21:01 331264 c:\windows\Installer\3617bf.msi
+ 2008-08-13 04:57 . 2008-08-13 04:57 474624 c:\windows\Installer\2cccd0d.msi
+ 2009-01-01 03:34 . 2009-01-01 03:34 683008 c:\windows\Installer\2bb9100.msi
+ 2008-12-14 03:10 . 2008-12-14 03:10 390656 c:\windows\Installer\2a9e4b.msi
+ 2009-04-30 23:47 . 2009-04-30 23:47 140288 c:\windows\Installer\2a434e.msi
+ 2009-05-02 04:37 . 2009-05-02 04:37 176128 c:\windows\Installer\1ebce3c.msi
+ 2009-05-02 04:34 . 2009-05-02 04:34 213504 c:\windows\Installer\1ebce37.msi
+ 2008-06-11 18:02 . 2008-06-11 18:02 830464 c:\windows\Installer\1c0268e.msp
+ 2008-07-28 18:59 . 2008-07-28 18:59 180736 c:\windows\Installer\1c02679.msp
+ 2008-05-28 22:27 . 2008-05-28 22:27 537600 c:\windows\Installer\174b900.msi
+ 2008-12-14 21:20 . 2008-12-14 21:20 432640 c:\windows\Installer\1414551.msi
+ 2007-12-22 19:20 . 2007-12-22 19:20 264704 c:\windows\Installer\11f7a0.msi
+ 2007-12-22 21:38 . 2009-06-11 03:49 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2007-12-22 21:38 . 2009-04-30 23:43 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2007-12-22 21:38 . 2009-06-11 03:49 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2007-12-22 21:38 . 2009-04-30 23:43 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2007-12-22 21:38 . 2009-04-30 23:43 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2007-12-22 21:38 . 2009-06-11 03:49 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2007-12-22 21:38 . 2009-06-11 03:49 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2007-12-22 21:38 . 2009-04-30 23:43 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2007-12-22 21:38 . 2009-06-11 03:49 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2007-12-22 21:38 . 2009-04-30 23:43 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2007-12-22 21:38 . 2009-06-11 03:49 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2007-12-22 21:38 . 2009-04-30 23:43 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2009-06-11 03:42 . 2009-03-03 00:18 826368 c:\windows\ie7updates\KB969897-IE7\wininet.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 233472 c:\windows\ie7updates\KB969897-IE7\webcheck.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 105984 c:\windows\ie7updates\KB969897-IE7\url.dll
+ 2009-06-11 03:42 . 2008-07-09 07:38 382840 c:\windows\ie7updates\KB969897-IE7\spuninst\updspapi.dll
+ 2009-06-11 03:42 . 2008-07-09 07:38 231288 c:\windows\ie7updates\KB969897-IE7\spuninst\spuninst.exe
+ 2009-06-11 03:42 . 2009-02-20 18:09 102912 c:\windows\ie7updates\KB969897-IE7\occache.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 671232 c:\windows\ie7updates\KB969897-IE7\mstime.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 193024 c:\windows\ie7updates\KB969897-IE7\msrating.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 477696 c:\windows\ie7updates\KB969897-IE7\mshtmled.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 459264 c:\windows\ie7updates\KB969897-IE7\msfeeds.dll
+ 2009-06-11 03:42 . 2009-02-28 04:54 636072 c:\windows\ie7updates\KB969897-IE7\iexplore.exe
+ 2009-06-11 03:42 . 2009-02-20 18:09 268288 c:\windows\ie7updates\KB969897-IE7\iertutil.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 385024 c:\windows\ie7updates\KB969897-IE7\iedkcs32.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 383488 c:\windows\ie7updates\KB969897-IE7\ieapfltr.dll
+ 2009-06-11 03:42 . 2009-02-20 05:14 161792 c:\windows\ie7updates\KB969897-IE7\ieakui.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 230400 c:\windows\ie7updates\KB969897-IE7\ieaksie.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 153088 c:\windows\ie7updates\KB969897-IE7\ieakeng.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 133120 c:\windows\ie7updates\KB969897-IE7\extmgr.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 214528 c:\windows\ie7updates\KB969897-IE7\dxtrans.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 347136 c:\windows\ie7updates\KB969897-IE7\dxtmsft.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 124928 c:\windows\ie7updates\KB969897-IE7\advpack.dll
+ 2009-05-13 02:17 . 2008-03-13 04:52 761344 c:\windows\Driver Cache\i386\unires.dll
+ 2009-05-13 02:17 . 2008-07-06 12:06 744960 c:\windows\Driver Cache\i386\unidrvui.dll
+ 2009-05-13 02:17 . 2008-07-06 12:06 373248 c:\windows\Driver Cache\i386\unidrv.dll
+ 2009-05-13 02:17 . 2008-07-06 12:06 198656 c:\windows\Driver Cache\i386\mxdwdui.dll
+ 2009-05-13 02:17 . 2008-07-06 12:06 765440 c:\windows\Driver Cache\i386\mxdwdrv.dll
+ 2009-05-13 12:01 . 2009-05-13 12:01 321024 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\7d2a3adbdcb675f872eb2dbf21f73596\WsatConfig.ni.exe
+ 2009-05-13 02:30 . 2009-05-13 02:30 239616 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\a18dff8832712a0f6cccaaefbcc45861\WindowsFormsIntegration.ni.dll
+ 2009-05-13 02:23 . 2009-05-13 02:23 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\dbb2fcd246efaf3df823410597cd1677\UIAutomationTypes.ni.dll
+ 2009-05-13 02:30 . 2009-05-13 02:30 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\d255ab525d10d8fefe5df9ba092b2df8\UIAutomationClient.ni.dll
+ 2009-05-13 12:04 . 2009-05-13 12:04 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\8c0d96269480bdd3de8a825f0215308d\System.Xml.Linq.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\18e1acd6761195389db42bab83169fd2\System.Web.Routing.ni.dll
+ 2009-05-13 02:29 . 2009-05-13 02:29 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\70764208219715962d310336b5959dfa\System.Web.RegularExpressions.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 858112 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\f288f2cb75465c0f45154079365af9e8\System.Web.Extensions.Design.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\bbdc5cb2f2f92fd610de7331d748193a\System.Web.Entity.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\ca1ce755bb49324c7d275c426188a28f\System.Web.Entity.Design.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 542720 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\aff5e0fa23e49ee75e458408c1f66da2\System.Web.DynamicData.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\fbe60d84b9f1ab74e396fb1507f69615\System.Web.Abstractions.ni.dll
+ 2009-05-13 02:28 . 2009-05-13 02:28 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\12903c3843fe923d1977801ffa3cf26c\System.Transactions.ni.dll
+ 2009-05-13 02:29 . 2009-05-13 02:29 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\a9e71dda6389403be4db7b567592e3b8\System.ServiceProcess.ni.dll
+ 2009-05-13 02:22 . 2009-05-13 02:22 676352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\0418eb6dbffe9b46aa4c989153d6a3b5\System.Security.ni.dll
+ 2009-05-13 02:25 . 2009-05-13 02:25 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\01dc643b54310ebc5ab7e4696df426bc\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2009-05-13 02:28 . 2009-05-13 02:28 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\3736ba3ecac186f9c5d85f01bda2be98\System.Runtime.Remoting.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 620032 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\eabe1915c13467e1e66e2b073bcb842f\System.Net.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\643e95098a9ce99a598d3419b5ce157f\System.Messaging.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 997888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\894d87c08a9a5b5923e7104055a616d2\System.Management.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\1db9deebde7c96b2874b4ffccac2f48e\System.Management.Instrumentation.ni.dll
+ 2009-05-13 12:00 . 2009-05-13 12:00 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\bcfccfa22245d2223a764611c61a7cb9\System.IO.Log.ni.dll
+ 2009-05-13 12:00 . 2009-05-13 12:00 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\be8c7482f1e78a3b4984af9082d455a7\System.IdentityModel.Selectors.ni.dll
+ 2009-05-13 02:28 . 2009-05-13 02:28 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\5f9cd5bfebcb94175d440ebab3aa412f\System.EnterpriseServices.Wrapper.dll
+ 2009-05-13 02:28 . 2009-05-13 02:28 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\5f9cd5bfebcb94175d440ebab3aa412f\System.EnterpriseServices.ni.dll
+ 2009-05-13 02:29 . 2009-05-13 02:29 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\5f5d64dd0e7991aaaad2d98ee52afe42\System.Drawing.Design.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 880640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\c205bbbb88bfa4bd5e274f43ea0013cb\System.DirectoryServices.AccountManagement.ni.dll
+ 2009-05-13 02:29 . 2009-05-13 02:29 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\44de75caba2b9711b3d9030a30767f8b\System.DirectoryServices.Protocols.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 939520 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\d3aed340a6562196ca40978556fb29d1\System.Data.Services.Client.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\3cb9c5203e50cb6af99b163522e9357c\System.Data.Services.Design.ni.dll
+ 2009-05-13 12:02 . 2009-05-13 12:02 755200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\9867484f25281882e61f61066fa651a3\System.Data.Entity.Design.ni.dll
+ 2009-05-13 12:02 . 2009-05-13 12:02 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\4f4ddae492a4a4ce4a2961f3d72d9399\System.Data.DataSetExtensions.ni.dll
+ 2009-05-13 02:22 . 2009-05-13 02:22 970752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cb4cb21d14767292e079366a5d3d76cd\System.Configuration.ni.dll
+ 2009-05-13 02:29 . 2009-05-13 02:29 140800 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\22a1629a4dcdd493bbd8be40cc122e94\System.Configuration.Install.ni.dll
+ 2009-05-13 12:02 . 2009-05-13 12:02 632832 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\b01721205312c6c18df033cc47b60e5c\System.AddIn.ni.dll
+ 2009-05-13 02:30 . 2009-05-13 02:30 232448 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\6e07cc846884a853b910775fcec87ced\sysglobl.ni.dll
+ 2009-05-13 12:01 . 2009-05-13 12:01 365056 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\b9c1a29e684bc02e49226ff1e9eec253\SMSvcHost.ni.exe
+ 2009-05-13 12:01 . 2009-05-13 12:01 255488 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\2e19ccefc30d7b827bab3f7d8dcc0ab9\SMDiagnostics.ni.dll
+ 2009-05-13 12:01 . 2009-05-13 12:01 319488 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\6781b87c8d3b55e6120b1e86bea6e040\ServiceModelReg.ni.exe
+ 2009-05-13 02:29 . 2009-05-13 02:29 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ef1a93d10c3a91b728745dbfcc79c2c7\PresentationFramework.Classic.ni.dll
+ 2009-05-13 02:29 . 2009-05-13 02:29 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\b4dc4bd8534d90fbb7430926ad990cd9\PresentationFramework.Luna.ni.dll
+ 2009-05-13 02:29 . 2009-05-13 02:29 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\9e71fd0d299c5668c96a54e4a63479fa\PresentationFramework.Aero.ni.dll
+ 2009-05-13 02:29 . 2009-05-13 02:29 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\79c2fd29b1e46c943960278051b4e1b9\PresentationFramework.Royale.ni.dll
+ 2009-05-13 12:01 . 2009-05-13 12:01 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\87c84ffaaad81d8d106a9aa9d68b5926\MSBuild.ni.exe
+ 2009-05-13 12:01 . 2009-05-13 12:01 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\539e297cc9bc67fbf2fbdc9dc5fcd0f1\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2009-05-13 02:22 . 2009-05-13 02:22 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\43dceeb2d0601d79af40752fb20283c2\Microsoft.Build.Utilities.ni.dll
+ 2009-05-13 12:01 . 2009-05-13 12:01 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\28eede53267524df58362a75a668cf86\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2009-05-13 12:01 . 2009-05-13 12:01 838656 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\daf5ff5e06c80eefa80c6fcc79aec963\Microsoft.Build.Engine.ni.dll
+ 2009-05-13 12:01 . 2009-05-13 12:01 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\c5c4db4f9bc7a454e9cfc2548a9d45a5\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2009-05-13 12:01 . 2009-05-13 12:01 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\e148983beeb0f30918b0564849a16456\CustomMarshalers.ni.dll
+ 2009-05-13 12:01 . 2009-05-13 12:01 409600 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\19b50dd470540911fc5cc65331a769e4\ComSvcConfig.ni.exe
+ 2009-05-13 12:01 . 2009-05-13 12:01 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\c7ffd8c23e8de4018a88185b3b60631e\AspNetMMCExt.ni.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 385024 c:\windows\assembly\GAC_MSIL\UIAutomationClientsideProviders\3.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 167936 c:\windows\assembly\GAC_MSIL\UIAutomationClient\3.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 139264 c:\windows\assembly\GAC_MSIL\System.Xml.Linq\3.5.0.0__b77a5c561934e089\System.Xml.Linq.dll
+ 2009-05-13 02:20 . 2009-05-13 02:20 507904 c:\windows\assembly\GAC_MSIL\System.WorkflowServices\3.5.0.0__31bf3856ad364e35\System.WorkflowServices.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 540672 c:\windows\assembly\GAC_MSIL\System.Workflow.Runtime\3.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2008-04-11 21:04 . 2008-04-11 21:04 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 335872 c:\windows\assembly\GAC_MSIL\System.Web.Extensions.Design\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.Design.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 139264 c:\windows\assembly\GAC_MSIL\System.Web.Entity\3.5.0.0__b77a5c561934e089\System.Web.Entity.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 131072 c:\windows\assembly\GAC_MSIL\System.Web.Entity.Design\3.5.0.0__b77a5c561934e089\System.Web.Entity.Design.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 225280 c:\windows\assembly\GAC_MSIL\System.Web.DynamicData\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 688128 c:\windows\assembly\GAC_MSIL\System.Speech\3.0.0.0__31bf3856ad364e35\System.Speech.dll
- 2007-12-22 22:15 . 2007-12-22 22:15 688128 c:\windows\assembly\GAC_MSIL\System.Speech\3.0.0.0__31bf3856ad364e35\System.Speech.dll
+ 2009-05-13 02:16 . 2009-05-13 02:16 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2008-04-11 21:04 . 2008-04-11 21:04 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2009-05-13 02:20 . 2009-05-13 02:20 569344 c:\windows\assembly\GAC_MSIL\System.ServiceModel.Web\3.5.0.0__31bf3856ad364e35\System.ServiceModel.Web.dll
+ 2009-05-13 02:16 . 2009-05-13 02:16 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2008-04-11 21:04 . 2008-04-11 21:04 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2009-05-13 02:18 . 2009-05-13 02:18 966656 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 233472 c:\windows\assembly\GAC_MSIL\System.Net\3.5.0.0__b03f5f7f11d50a3a\System.Net.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 143360 c:\windows\assembly\GAC_MSIL\System.Management.Instrumentation\3.5.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
- 2007-12-22 22:15 . 2007-12-22 22:15 131072 c:\windows\assembly\GAC_MSIL\System.IO.Log\3.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
+ 2009-05-13 02:18 . 2009-05-13 02:18 131072 c:\windows\assembly\GAC_MSIL\System.IO.Log\3.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
+ 2009-05-13 02:18 . 2009-05-13 02:18 430080 c:\windows\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
- 2007-12-22 22:15 . 2007-12-22 22:15 126976 c:\windows\assembly\GAC_MSIL\System.IdentityModel.Selectors\3.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 126976 c:\windows\assembly\GAC_MSIL\System.IdentityModel.Selectors\3.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
+ 2009-05-13 02:16 . 2009-05-13 02:16 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2008-04-11 21:04 . 2008-04-11 21:04 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2009-05-13 02:20 . 2009-05-13 02:20 286720 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\3.5.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2009-05-13 02:20 . 2009-05-13 02:20 442368 c:\windows\assembly\GAC_MSIL\System.Data.Services\3.5.0.0__b77a5c561934e089\System.Data.Services.dll
+ 2009-05-13 02:20 . 2009-05-13 02:20 114688 c:\windows\assembly\GAC_MSIL\System.Data.Services.Design\3.5.0.0__b77a5c561934e089\System.Data.Services.Design.dll
+ 2009-05-13 02:20 . 2009-05-13 02:20 294912 c:\windows\assembly\GAC_MSIL\System.Data.Services.Client\3.5.0.0__b77a5c561934e089\System.Data.Services.Client.dll
+ 2009-05-13 02:20 . 2009-05-13 02:20 684032 c:\windows\assembly\GAC_MSIL\System.Data.Linq\3.5.0.0__b77a5c561934e089\System.Data.Linq.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 229376 c:\windows\assembly\GAC_MSIL\System.Data.Entity.Design\3.5.0.0__b77a5c561934e089\System.Data.Entity.Design.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 667648 c:\windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll
+ 2009-05-13 02:16 . 2009-05-13 02:16 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2008-04-11 21:04 . 2008-04-11 21:04 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2009-05-13 02:18 . 2009-05-13 02:18 110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
+ 2009-05-13 02:18 . 2009-05-13 02:18 528384 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
- 2007-12-22 22:15 . 2007-12-22 22:15 528384 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 864256 c:\windows\assembly\GAC_MSIL\PresentationUI\3.0.0.0__31bf3856ad364e35\PresentationUI.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 163840 c:\windows\assembly\GAC_MSIL\PresentationFramework.Royale\3.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 397312 c:\windows\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 139264 c:\windows\assembly\GAC_MSIL\PresentationFramework.Classic\3.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 196608 c:\windows\assembly\GAC_MSIL\PresentationFramework.Aero\3.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 598016 c:\windows\assembly\GAC_MSIL\PresentationBuildTasks\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2009-05-13 02:18 . 2009-05-13 02:18 397312 c:\windows\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2009-05-13 02:20 . 2009-05-13 02:20 802816 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.v3.5.dll
+ 2009-05-13 02:20 . 2009-05-13 02:20 733184 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2008-04-11 21:05 . 2008-04-11 21:05 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2009-05-13 02:20 . 2009-05-13 02:20 106496 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Conversion.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Conversion.v3.5.dll
- 2008-04-11 21:04 . 2008-04-11 21:04 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2009-05-13 02:18 . 2009-05-13 02:18 368640 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2009-05-13 02:16 . 2009-05-13 02:16 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2009-05-13 02:18 . 2009-05-13 02:18 163840 c:\windows\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2006-10-15 01:22 . 2008-07-06 12:06 1676288 c:\windows\system32\xpssvcs.dll
+ 2004-07-17 00:35 . 2004-07-17 00:35 1326080 c:\windows\system32\webfldrs.msi
+ 2004-08-03 13:56 . 2009-04-29 04:56 1159680 c:\windows\system32\urlmon.dll
+ 2007-12-22 22:14 . 2008-07-06 12:06 1676288 c:\windows\system32\spool\XPSEP\i386\xpssvcs.dll
+ 2007-12-22 22:14 . 2008-07-06 12:06 1676288 c:\windows\system32\spool\XPSEP\i386\i386\xpssvcs.dll
+ 2007-12-22 22:14 . 2008-07-06 21:36 2936832 c:\windows\system32\spool\XPSEP\amd64\xpssvcs.dll
+ 2007-12-22 22:14 . 2008-07-06 21:36 2936832 c:\windows\system32\spool\XPSEP\amd64\amd64\xpssvcs.dll
+ 2006-10-15 01:22 . 2008-07-06 12:06 1676288 c:\windows\system32\spool\drivers\w32x86\3\XpsSvcs.dll
+ 2004-08-03 13:56 . 2009-04-29 04:56 3596288 c:\windows\system32\mshtml.dll
+ 2007-10-11 19:12 . 2009-03-11 02:18 1482112 c:\windows\system32\LegitCheckControl.dll
+ 2007-08-13 23:54 . 2009-04-29 04:55 6066176 c:\windows\system32\ieframe.dll
- 2007-08-13 23:54 . 2009-02-20 18:09 6066176 c:\windows\system32\ieframe.dll
+ 2006-10-15 01:22 . 2008-07-06 12:06 1676288 c:\windows\system32\dllcache\xpssvcs.dll
+ 2008-10-15 22:24 . 2009-04-17 12:26 1847168 c:\windows\system32\dllcache\win32k.sys
+ 2004-08-03 13:56 . 2009-04-29 04:56 1159680 c:\windows\system32\dllcache\urlmon.dll
+ 2004-08-03 13:56 . 2009-04-29 04:56 3596288 c:\windows\system32\dllcache\mshtml.dll
- 2007-12-24 14:26 . 2009-02-20 18:09 6066176 c:\windows\system32\dllcache\ieframe.dll
+ 2007-12-24 14:26 . 2009-04-29 04:55 6066176 c:\windows\system32\dllcache\ieframe.dll
+ 2009-06-13 20:41 . 2009-03-09 19:27 4178264 c:\windows\system32\D3DX9_41.dll
+ 2009-06-13 20:41 . 2008-10-10 08:52 4379984 c:\windows\system32\D3DX9_40.dll
+ 2009-06-13 20:41 . 2009-03-09 19:27 1846632 c:\windows\system32\D3DCompiler_41.dll
+ 2009-06-13 20:41 . 2008-10-10 08:52 2036576 c:\windows\system32\D3DCompiler_40.dll
+ 2008-09-04 23:00 . 2004-07-17 00:35 1326080 c:\windows\ServicePackFiles\i386\webfldrs.msi
+ 2008-09-04 22:59 . 2004-07-17 00:41 5080576 c:\windows\ServicePackFiles\i386\msnmsgs.msi
+ 2008-07-30 03:40 . 2008-07-30 03:40 1720824 c:\windows\Microsoft.NET\Framework\v3.5\vbc.exe
+ 2008-07-29 22:47 . 2008-07-29 22:47 1054208 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vs_setup.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 1364992 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\SITSetup.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 1064448 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\gencomp.dll
+ 2008-07-30 03:40 . 2008-07-30 03:40 1548280 c:\windows\Microsoft.NET\Framework\v3.5\csc.exe
+ 2008-07-29 23:59 . 2008-07-29 23:59 1738760 c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll
+ 2008-07-29 23:16 . 2008-07-29 23:16 5931008 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll
- 2008-07-25 16:16 . 2007-10-24 05:47 1344000 c:\windows\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 1344000 c:\windows\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 1172472 c:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
- 2008-07-25 16:17 . 2007-10-24 05:47 1172472 c:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
+ 2008-07-25 15:17 . 2008-07-25 15:17 2048000 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 5238784 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 3149824 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 5062656 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 2933248 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 5815296 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2008-07-25 15:17 . 2008-07-25 15:17 4546560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2008-07-25 15:16 . 2008-07-25 15:16 1163768 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscomp.dll
+ 2007-05-25 17:08 . 2007-05-25 17:08 9609728 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp
+ 2009-04-30 22:47 . 2009-04-30 22:47 1802240 c:\windows\Installer\d0db5.msi
+ 2008-07-30 02:26 . 2008-07-30 02:26 1043456 c:\windows\Installer\7dd9e1.msp
+ 2008-07-30 03:37 . 2008-07-30 03:37 2679808 c:\windows\Installer\7dd9df.msp
+ 2008-07-30 04:15 . 2008-07-30 04:15 3697664 c:\windows\Installer\7dd9dd.msp
+ 2008-07-30 02:34 . 2008-07-30 02:34 1448448 c:\windows\Installer\7dd9dc.msp
+ 2008-07-30 03:22 . 2008-07-30 03:22 4137984 c:\windows\Installer\7dd9db.msp
+ 2008-07-30 02:18 . 2008-07-30 02:18 3376640 c:\windows\Installer\7dd9da.msp
+ 2008-07-30 00:45 . 2008-07-30 00:45 2543616 c:\windows\Installer\78b212.msp
+ 2008-07-30 00:29 . 2008-07-30 00:29 2926080 c:\windows\Installer\78b211.msp
+ 2008-07-30 00:41 . 2008-07-30 00:41 6487040 c:\windows\Installer\78b210.msp
+ 2008-07-30 00:39 . 2008-07-30 00:39 3403264 c:\windows\Installer\78b20f.msp
+ 2008-07-30 00:43 . 2008-07-30 00:43 1013248 c:\windows\Installer\78b20d.msp
+ 2008-07-30 00:31 . 2008-07-30 00:31 6083072 c:\windows\Installer\78b20a.msp
+ 2005-10-26 18:59 . 2005-10-26 18:59 2883072 c:\windows\Installer\68d820.msp
+ 2008-02-15 18:57 . 2008-02-15 18:57 5517312 c:\windows\Installer\68d80b.msp
+ 2006-10-12 14:50 . 2006-10-12 14:50 1091584 c:\windows\Installer\6845c4b.msp
+ 2007-05-22 13:46 . 2007-05-22 13:46 6108672 c:\windows\Installer\6845c36.msp
+ 2008-04-01 18:33 . 2008-04-01 18:33 5479936 c:\windows\Installer\6845bf6.msp
+ 2008-01-31 14:30 . 2008-01-31 14:30 9947648 c:\windows\Installer\6845bc8.msp
+ 2008-01-14 20:53 . 2008-01-14 20:53 5213696 c:\windows\Installer\6845b88.msp
+ 2006-07-17 21:11 . 2006-07-17 21:11 4578816 c:\windows\Installer\6845b73.msp
+ 2007-04-25 19:14 . 2007-04-25 19:14 9828864 c:\windows\Installer\6845b5d.msp
+ 2006-12-18 15:48 . 2006-12-18 15:48 5444096 c:\windows\Installer\6845b48.msp
+ 2006-09-11 16:19 . 2006-09-11 16:19 6253056 c:\windows\Installer\6845b1d.msp
+ 2006-08-16 02:36 . 2006-08-16 02:36 5206528 c:\windows\Installer\6845b08.msp
+ 2007-11-08 15:42 . 2007-11-08 15:42 4158464 c:\windows\Installer\6845af1.msp
+ 2007-04-25 19:10 . 2007-04-25 19:10 6835712 c:\windows\Installer\6845aca.msp
+ 2006-11-20 20:37 . 2006-11-20 20:37 6553088 c:\windows\Installer\6845ab5.msp
+ 2008-03-16 21:11 . 2008-03-16 21:11 5512704 c:\windows\Installer\6602e25.msp
+ 2008-10-23 03:43 . 2008-10-23 03:43 6820352 c:\windows\Installer\65571c.msp
+ 2008-10-23 03:48 . 2008-10-23 03:48 7672832 c:\windows\Installer\655707.msp
+ 2008-11-05 19:25 . 2008-11-05 19:25 5518336 c:\windows\Installer\6556f2.msp
+ 2008-06-10 13:49 . 2008-06-10 13:49 1635328 c:\windows\Installer\4f7deb5.msi
+ 2008-06-10 13:49 . 2008-06-10 13:49 8984576 c:\windows\Installer\4f7deb0.msi
+ 2009-05-01 19:49 . 2009-05-01 19:49 4328960 c:\windows\Installer\4c1abe.msp
+ 2009-01-15 07:35 . 2009-01-15 07:35 4830720 c:\windows\Installer\48367d.msp
+ 2008-03-07 14:31 . 2008-03-07 14:31 3620864 c:\windows\Installer\4390e.msi
+ 2007-12-22 21:01 . 2007-12-22 21:01 1124864 c:\windows\Installer\3617ba.msi
+ 2007-12-22 22:15 . 2007-12-22 22:15 1142784 c:\windows\Installer\2e792a.msi
+ 2007-12-22 20:51 . 2007-12-22 20:51 1105920 c:\windows\Installer\2d44c2.msi
+ 2009-04-06 21:00 . 2009-04-06 21:00 5518336 c:\windows\Installer\2a433f.msp
+ 2009-03-05 19:40 . 2009-03-05 19:40 6819840 c:\windows\Installer\2a432a.msp
+ 2008-09-05 17:08 . 2008-09-05 17:08 5515776 c:\windows\Installer\281ec1b.msp
+ 2008-09-07 19:21 . 2008-09-07 19:21 1405952 c:\windows\Installer\2453d2.msi
+ 2009-04-26 17:56 . 2009-04-26 17:56 1633792 c:\windows\Installer\1f105.msi
+ 2008-05-15 13:50 . 2008-05-15 13:50 5515776 c:\windows\Installer\1ef5f32.msp
+ 2009-01-14 20:43 . 2009-01-14 20:43 5520384 c:\windows\Installer\1eccb6.msp
+ 2009-05-02 04:33 . 2009-05-02 04:33 2863616 c:\windows\Installer\1ebce32.msi
+ 2009-05-02 04:29 . 2009-05-02 04:29 2628096 c:\windows\Installer\1ebce2d.msi
+ 2007-12-22 21:54 . 2007-12-22 21:54 3443712 c:\windows\Installer\1c7635.msi
+ 2008-10-25 14:15 . 2008-10-25 14:15 6227456 c:\windows\Installer\1c6b4b.msp
+ 2008-10-17 14:03 . 2008-10-17 14:03 5518336 c:\windows\Installer\1c6b37.msp
+ 2008-07-16 14:39 . 2008-07-16 14:39 5519360 c:\windows\Installer\1c026b8.msp
+ 2008-07-08 15:27 . 2008-07-08 15:27 8436736 c:\windows\Installer\1c026a3.msp
+ 2009-05-12 17:01 . 2009-05-12 17:01 6818816 c:\windows\Installer\1bdaf93.msp
+ 2009-05-28 16:32 . 2009-05-28 16:32 5518848 c:\windows\Installer\1bdaf7e.msp
+ 2009-04-23 21:57 . 2009-04-23 21:57 7672832 c:\windows\Installer\1bdaf69.msp
+ 2009-01-08 23:49 . 2009-01-08 23:49 1100288 c:\windows\Installer\1918dd6.msi
+ 2007-12-22 21:38 . 2007-12-22 21:38 5922816 c:\windows\Installer\17cd1.msi
+ 2008-05-28 22:39 . 2008-05-28 22:39 2130432 c:\windows\Installer\174ba85.msi
+ 2008-05-28 22:28 . 2008-05-28 22:28 1453568 c:\windows\Installer\174b90a.msi
+ 2008-05-28 22:27 . 2008-05-28 22:27 1868800 c:\windows\Installer\174b905.msi
+ 2008-05-28 22:07 . 2008-05-28 22:07 5091840 c:\windows\Installer\174b8f2.msi
+ 2008-06-11 19:05 . 2008-06-11 19:05 9994240 c:\windows\Installer\16c05de.msp
+ 2008-06-10 18:09 . 2008-06-10 18:09 5517312 c:\windows\Installer\16c05c5.msp
+ 2008-12-12 16:09 . 2008-12-12 16:09 5517824 c:\windows\Installer\13eab9a.msp
+ 2008-08-12 21:40 . 2008-08-12 21:40 1549312 c:\windows\Installer\13a4bbf.msi
+ 2008-08-12 21:40 . 2008-08-12 21:40 3379712 c:\windows\Installer\13a4b91.msi
+ 2008-08-12 21:38 . 2008-08-12 21:38 3174912 c:\windows\Installer\13a49f0.msi
+ 2008-04-18 18:26 . 2008-04-18 18:26 5518336 c:\windows\Installer\13725c2.msp
+ 2008-08-14 19:01 . 2008-08-14 19:01 5517312 c:\windows\Installer\135f0fb.msp
+ 2008-07-31 22:03 . 2008-07-31 22:03 1396224 c:\windows\Installer\13210c8.msi
+ 2009-06-11 03:42 . 2009-02-20 18:09 1160192 c:\windows\ie7updates\KB969897-IE7\urlmon.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 3595264 c:\windows\ie7updates\KB969897-IE7\mshtml.dll
+ 2009-06-11 03:42 . 2009-02-20 18:09 6066176 c:\windows\ie7updates\KB969897-IE7\ieframe.dll
+ 2009-06-11 03:42 . 2008-07-09 14:25 2455488 c:\windows\ie7updates\KB969897-IE7\ieapfltr.dat
+ 2009-05-13 02:23 . 2009-05-13 02:23 3311104 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\df20e56b59b1b1a595af305ddc0777ba\WindowsBase.ni.dll
+ 2009-05-13 02:30 . 2009-05-13 02:30 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\8698f073a59ef0db10a3258b1f1deaee\UIAutomationClientsideProviders.ni.dll
+ 2009-05-13 02:22 . 2009-05-13 02:22 7867392 c:\windows\assembly\NativeImages_v2.0.50727_32\System\aa7926460a336408c8041330ad90929d\System.ni.dll
+ 2009-05-13 02:22 . 2009-05-13 02:22 5449728 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\36f3953f24d4f0b767bf172331ad6f3e\System.Xml.ni.dll
+ 2009-05-13 12:04 . 2009-05-13 12:04 1355264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\43911ac4e29949c57560eee5cb7b76c2\System.WorkflowServices.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 1904128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\6d0966370023925610756f368140b947\System.Workflow.Runtime.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 4510720 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\9de33f5786cd15e220f47b916c5a15e9\System.Workflow.ComponentModel.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 2989568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\d6cc33db5d526553ffbbfd1d372a8493\System.Workflow.Activities.ni.dll
+ 2009-05-13 02:29 . 2009-05-13 02:29 1840128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\1dad08772eb89d48a8a0cfe9b0467eb0\System.Web.Services.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\e5995a34d44ad5af7d9f335075bded4d\System.Web.Mobile.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 2400256 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\6a20b64ad8e2aaa2f40d67ff01fcc708\System.Web.Extensions.ni.dll
+ 2009-05-13 02:30 . 2009-05-13 02:30 1912832 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\2e7a6c977ac9f8d46ebe2982697a0c8d\System.Speech.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 1705984 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\a3adabee8e63dc76f65710a9c32175fc\System.ServiceModel.Web.ni.dll
+ 2009-05-13 12:00 . 2009-05-13 12:00 2338304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\bb748f8ef8c98eb5c7f79b8faee95397\System.Runtime.Serialization.ni.dll
+ 2009-05-13 02:28 . 2009-05-13 02:28 1035264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\db428f231a2ccaf490ae219efd2edc69\System.Printing.ni.dll
+ 2009-05-13 12:00 . 2009-05-13 12:00 1056768 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\94b2ca600c860c76e387f8bd317bd4c3\System.IdentityModel.ni.dll
+ 2009-05-13 02:23 . 2009-05-13 02:23 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6978f2e90f13bc720d57fa6895c911e2\System.Drawing.ni.dll
+ 2009-05-13 02:28 . 2009-05-13 02:28 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\6bcc481030a56c24d5990d199812c594\System.DirectoryServices.ni.dll
+ 2009-05-13 02:23 . 2009-05-13 02:23 1800704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\df1efcbac5973454c608890f72eb994d\System.Deployment.ni.dll
+ 2009-05-13 02:28 . 2009-05-13 02:28 6614016 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\0b40341027c01716cec1dd97592698e0\System.Data.ni.dll
+ 2009-05-13 02:22 . 2009-05-13 02:22 2508800 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\0ec1b690c5ee057fa92ecff78de1457c\System.Data.SqlXml.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 1326080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\6f298259c87cc6c7318d931f52f053c5\System.Data.Services.ni.dll
+ 2009-05-13 02:29 . 2009-05-13 02:29 1115136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\57f7cf02ea17b36bc3d9c75c22d0f551\System.Data.OracleClient.ni.dll
+ 2009-05-13 02:29 . 2009-05-13 02:30 2510848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\fa206c73f39721cd2c55829b9853de44\System.Data.Linq.ni.dll
+ 2009-05-13 12:02 . 2009-05-13 12:02 9903104 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\8c050147d7031f912f6ca2b15550173f\System.Data.Entity.ni.dll
+ 2009-05-13 02:29 . 2009-05-13 02:29 2294784 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\6c69930d05c557da70144bcc0add7065\System.Core.ni.dll
+ 2009-05-13 02:28 . 2009-05-13 02:28 2125824 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\5c59991df60164cae10fd81b88a8e5b1\ReachFramework.ni.dll
+ 2009-05-13 02:28 . 2009-05-13 02:28 1656832 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\87fb973e4ab6a21fd00e45656fa7c115\PresentationUI.ni.dll
+ 2009-05-13 02:22 . 2009-05-13 02:22 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b6bfb51dec7f8cc42c21c5928470c773\PresentationBuildTasks.ni.dll
+ 2009-05-13 12:02 . 2009-05-13 12:02 1711104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\5b3d048d8c003d743ea5e72caf07773a\Microsoft.VisualBasic.ni.dll
+ 2009-05-13 12:01 . 2009-05-13 12:01 1092608 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\21bb6244c91b6207fbcb038884a641ef\Microsoft.Transactions.Bridge.ni.dll
+ 2009-05-13 12:03 . 2009-05-13 12:03 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\7d61e63dea85f4f77ea4c13df7651ec7\Microsoft.JScript.ni.dll
+ 2009-05-13 12:01 . 2009-05-13 12:01 1965568 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\cd6eeb3d7ea1f65c28a43e665db38644\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2009-05-13 12:01 . 2009-05-13 12:01 1620480 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\152cf75db013f0523933ac45177b4217\Microsoft.Build.Tasks.ni.dll
+ 2009-05-13 12:01 . 2009-05-13 12:01 1886208 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\ce984d7bbd9a6d5d3cca28c4e5038020\Microsoft.Build.Engine.ni.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 1245184 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 3149824 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2009-05-13 02:16 . 2009-05-13 02:16 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 1630208 c:\windows\assembly\GAC_MSIL\System.Workflow.ComponentModel\3.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 1138688 c:\windows\assembly\GAC_MSIL\System.Workflow.Activities\3.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
+ 2009-05-13 02:18 . 2009-05-13 02:18 5931008 c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2009-05-13 02:21 . 2009-05-13 02:21 2879488 c:\windows\assembly\GAC_MSIL\System.Data.Entity\3.5.0.0__b77a5c561934e089\System.Data.Entity.dll
+ 2009-05-13 02:19 . 2009-05-13 02:19 5283840 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2009-05-13 02:15 . 2009-05-13 02:15 5238784 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-05-13 02:16 . 2009-05-13 02:16 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2009-05-13 02:18 . 2009-05-13 02:18 4210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2009-05-13 02:16 . 2009-05-13 02:16 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2009-04-30 23:44 . 2009-06-01 16:51 23635392 c:\windows\system32\MRT.exe
+ 2006-10-30 09:05 . 2006-10-30 09:05 11390464 c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpf.msi
+ 2007-12-25 15:32 . 2007-12-25 15:32 19210240 c:\windows\Installer\d52da.msp
+ 2007-12-26 17:24 . 2007-12-26 17:24 15256576 c:\windows\Installer\6dccb.msp
+ 2008-03-17 16:48 . 2008-03-17 16:48 11813888 c:\windows\Installer\6845c21.msp
+ 2008-03-01 02:09 . 2008-03-01 02:09 16907776 c:\windows\Installer\6845bde.msp
+ 2008-04-14 18:26 . 2008-04-14 18:26 11888128 c:\windows\Installer\6845b9d.msp
+ 2008-01-14 19:24 . 2008-01-14 19:24 10721280 c:\windows\Installer\6845b32.msp
+ 2008-08-13 18:49 . 2008-08-13 18:49 11816960 c:\windows\Installer\281ec30.msp
+ 2008-07-08 14:09 . 2008-07-08 14:09 11887616 c:\windows\Installer\1c026cd.msp
+ 2008-07-01 13:25 . 2008-07-01 13:25 11814912 c:\windows\Installer\1c02664.msp
+ 2005-08-08 18:25 . 2005-08-08 18:25 97385984 c:\windows\Installer\15e4779.msp
+ 2008-07-30 12:50 . 2008-07-30 12:50 12506112 c:\windows\Installer\135f125.msp
+ 2008-06-04 17:29 . 2008-06-04 17:29 16905728 c:\windows\Installer\135f110.msp
+ 2009-05-13 02:23 . 2009-05-13 02:23 12428800 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\9a254c455892c02355ab0ab0f0727c5b\System.Windows.Forms.ni.dll
+ 2009-05-13 02:29 . 2009-05-13 02:29 11791360 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\50ea744ffc3cb7f09b027fd6c5c93b2b\System.Web.ni.dll
+ 2009-05-13 12:01 . 2009-05-13 12:01 17313792 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\d85d9535e91da842fded56869d57790a\System.ServiceModel.ni.dll
+ 2009-05-13 02:29 . 2009-05-13 02:29 10681344 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\204db7071fb26343b0fd3f3d140c0bf8\System.Design.ni.dll
+ 2009-05-13 02:27 . 2009-05-13 02:27 14320128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\9519494798a88867406b5755e1dbded6\PresentationFramework.ni.dll
+ 2009-05-13 02:23 . 2009-05-13 02:23 12213248 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\12dcb10b76012416357bdbb010fdaa97\PresentationCore.ni.dll
+ 2009-05-13 02:22 . 2009-05-13 02:22 11485184 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9adb89fa22fd5b4ce433b5aca7fb1b07\mscorlib.ni.dll
+ 2007-07-27 13:03 . 2007-07-27 13:03 119977472 c:\windows\Installer\150cf5f.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2009-05-23 1794320]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-15 1947928]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-15 13570048]
"COMODO Internet Security"="c:\program files\COMODO\Firewall\cfp.exe" [2009-05-23 1794320]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"NvMediaCenter"="NvMCTray.dll" - c:\windows\system32\nvmctray.dll [2008-08-15 86016]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-5-2 692224]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-15 19:27 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0pgdfgsvc C 1\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Steam\\steamapps\\koreathebest\\counter-strike\\hl.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Diablo II\\Diablo II.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgrsx.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:Diablo II Battle.Net

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4/30/2009 6:53 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/30/2008 8:19 PM 325896]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [9/30/2008 8:12 PM 132640]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [9/30/2008 8:12 PM 24096]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/30/2008 8:19 PM 298776]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1003344]
S3 DM9USB;DM9601 USB To Fast Ethernet Adapter;c:\windows\system32\drivers\dm9usb.sys [12/22/2007 3:43 PM 21376]
S3 XDva037;XDva037;\??\c:\windows\system32\XDva037.sys --> c:\windows\system32\XDva037.sys [?]
S3 XDva064;XDva064;\??\c:\windows\system32\XDva064.sys --> c:\windows\system32\XDva064.sys [?]
S3 XDva090;XDva090;\??\c:\windows\system32\XDva090.sys --> c:\windows\system32\XDva090.sys [?]
S3 XDva132;XDva132;\??\c:\windows\system32\XDva132.sys --> c:\windows\system32\XDva132.sys [?]
S3 XDva143;XDva143;\??\c:\windows\system32\XDva143.sys --> c:\windows\system32\XDva143.sys [?]
S3 XDva177;XDva177;\??\c:\windows\system32\XDva177.sys --> c:\windows\system32\XDva177.sys [?]
S3 XDva189;XDva189;\??\c:\windows\system32\XDva189.sys --> c:\windows\system32\XDva189.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2009-06-25 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 22:52]

2009-06-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-07-06 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-04-09 23:48]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\User\Start Menu\Programs\IMVU\Run IMVU.lnk
DPF: {C9A2CBF3-B7F9-463E-A690-82CC077DCFC6} - hxxp://www.4story.com/Active_X/ZemiDetectHardware.cab
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\6d36xtix.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\User\Application Data\Mozilla\plugins\npoctoshape.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-06 19:48
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose, ZwOpenFile

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************
.
Completion time: 2009-07-06 21:16
ComboFix-quarantined-files.txt 2009-07-07 01:16
ComboFix2.txt 2009-05-10 04:35

Pre-Run: 93,658,234,880 bytes free
Post-Run: 93,605,531,648 bytes free

1195 --- E O F --- 2009-06-11 03:49

#10 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:02:12 AM

Posted 07 July 2009 - 03:49 AM

Hi,

Some of your protection software seems to have interfered with ComboFix run.

Please disable antivirus protection and download & run ComboFix.exe again. Post back its results & fresh dds log.

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.


#11 Haerith

Haerith
  • Topic Starter

  • Members
  • 50 posts
  • OFFLINE
  •  
  • Local time:07:12 PM

Posted 08 July 2009 - 08:14 AM

Here is the ComboFix Log:

ComboFix 09-07-07.A2 - User 07/08/2009 1:30.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.462 [GMT -4:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.

((((((((((((((((((((((((( Files Created from 2009-06-08 to 2009-07-08 )))))))))))))))))))))))))))))))
.

2009-06-27 21:13 . 2009-06-27 21:13 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Help
2009-06-23 12:50 . 2009-03-28 23:52 94208 ----a-w- c:\documents and settings\User\Application Data\Soldat\Battleye\BEServer.dll
2009-06-23 12:50 . 2009-03-28 23:52 102400 ----a-w- c:\documents and settings\User\Application Data\Soldat\Battleye\BEClient.dll
2009-06-23 12:50 . 2009-06-23 12:50 0 ----a-r- C:\logwmemory.bin
2009-06-23 12:49 . 2009-06-23 12:49 -------- d-----w- c:\documents and settings\User\Application Data\Soldat
2009-06-15 17:23 . 2009-06-15 17:23 541696 ----a-w- c:\documents and settings\User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv304-0905011-0-main.dll
2009-06-13 20:34 . 2009-06-13 20:34 -------- d-----w- c:\program files\Zemi Interactive
2009-06-13 20:29 . 2009-06-13 20:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Estsoft
2009-06-13 20:28 . 2009-06-13 23:53 -------- d-----w- c:\program files\ESTsoft
2009-06-13 20:28 . 2009-06-13 20:29 -------- d-----w- c:\documents and settings\User\Application Data\ESTsoft
2009-06-12 00:20 . 2009-05-28 22:52 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-09 20:13 . 2009-06-09 20:13 152576 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-09 02:08 . 2009-06-09 02:08 -------- d-----w- c:\documents and settings\User\Application Data\Toribash
2009-06-09 02:07 . 2009-06-09 02:07 -------- d-----w- C:\Games
2009-06-08 19:17 . 2009-06-08 19:17 -------- d-----w- C:\nDoors
2009-06-08 15:42 . 2009-06-08 15:42 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\DNA
2009-06-08 15:42 . 2009-06-27 21:14 -------- d-----w- c:\documents and settings\User\Application Data\DNA
2009-06-08 15:42 . 2009-06-27 18:18 -------- d-----w- c:\program files\DNA

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-08 00:43 . 2008-04-17 19:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-07 13:42 . 2008-10-01 00:19 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-07 13:42 . 2008-10-01 00:19 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-07-07 13:42 . 2008-10-01 00:19 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-26 01:14 . 2009-01-08 23:49 -------- d-----w- c:\program files\Steam
2009-06-25 04:08 . 2009-01-12 04:19 -------- d-----w- c:\documents and settings\User\Application Data\mIRC
2009-06-25 04:01 . 2009-01-12 04:19 -------- d-----w- c:\program files\mIRC
2009-06-25 02:38 . 2007-12-22 22:19 694464 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-25 01:48 . 2009-05-13 02:08 -------- d-----w- c:\program files\compLexity Demo Player
2009-06-17 00:09 . 2008-11-06 01:49 -------- d-----w- c:\program files\Diablo II
2009-06-15 16:26 . 2008-10-01 00:19 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-13 20:52 . 2007-12-22 19:35 73088 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-09 20:15 . 2009-04-26 17:56 -------- d-----w- c:\program files\Java
2009-06-08 21:52 . 2007-12-22 20:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-05 19:24 . 2008-05-31 22:47 -------- d-----w- c:\program files\StarCraft
2009-06-03 19:38 . 2008-05-24 17:32 -------- d-----w- c:\program files\StealthBot
2009-05-28 22:52 . 2009-05-28 22:52 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lsdelete.exe
2009-05-28 22:52 . 2009-05-28 22:52 83808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\ShellExt.dll
2009-05-28 22:52 . 2009-05-28 22:52 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\RPAPI.dll
2009-05-28 22:52 . 2009-05-28 22:52 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\PrivacyClean.dll
2009-05-27 20:16 . 2009-04-11 18:45 120088 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Plugins\npoctoshape.dll
2009-05-27 20:08 . 2009-05-27 20:08 -------- d-----w- c:\program files\RivaTuner v2.24
2009-05-25 10:50 . 2009-05-27 19:13 401920 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\sua-0905250-0-libOctoshapeClient.dll
2009-05-25 10:50 . 2009-05-27 19:13 120088 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\sua-0905250-0-npoctoshape.dll
2009-05-25 10:50 . 2009-05-27 19:13 124184 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\sua-0905250-0-apoctoshape.dll
2009-05-23 02:09 . 2008-10-01 00:12 168208 ----a-w- c:\windows\system32\guard32.dll
2009-05-23 02:09 . 2008-10-01 00:12 82080 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-05-23 02:09 . 2008-10-01 00:12 24096 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-05-23 02:09 . 2008-10-01 00:12 132640 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-05-22 19:41 . 2008-08-17 19:25 -------- d-----w- c:\documents and settings\User\Application Data\Ventrilo
2009-05-21 15:33 . 2009-04-26 17:57 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-10 04:46 . 2009-05-10 04:46 -------- d-----w- c:\documents and settings\User\Application Data\Auslogics
2009-05-10 04:38 . 2009-05-10 04:38 -------- d-----w- c:\program files\Auslogics
2009-05-07 15:32 . 2004-08-03 13:56 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-02 04:37 . 2009-05-02 04:37 10134 ----a-r- c:\documents and settings\User\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2009-05-02 04:33 . 2009-05-02 04:33 10134 ----a-r- c:\documents and settings\User\Application Data\Microsoft\Installer\{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}\ARPPRODUCTICON.exe
2009-05-02 04:29 . 2009-05-02 04:29 10134 ----a-r- c:\documents and settings\User\Application Data\Microsoft\Installer\{56918C0C-0D87-4CA6-92BF-4975A43AC719}\ARPPRODUCTICON.exe
2009-04-30 22:52 . 2009-04-30 22:53 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-04-30 22:52 . 2009-04-30 22:52 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Drivers\32\lbd.sys
2009-04-29 04:56 . 2004-08-03 13:56 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-03 13:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-25 13:20 . 2009-04-25 13:20 576512 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\pmv302-0810271-0-libOctoshapeClient.dll
2009-04-17 12:26 . 2004-08-03 12:17 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-03 13:56 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-11 18:48 . 2009-04-11 18:48 585728 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\pmv302a-0902180-0-libOctoshapeClient.dll
2009-01-03 13:21 . 2009-01-03 13:21 15706 ----a-w- c:\program files\changes.txt
2009-01-01 12:58 . 2009-01-01 12:58 1852 ----a-w- c:\program files\README.HTM
2008-11-11 16:10 . 2008-11-23 03:51 751167 ----a-w- c:\program files\data1.hdr
2008-11-11 16:10 . 2008-11-23 03:51 435 ----a-w- c:\program files\layout.bin
2008-11-11 16:10 . 2008-11-23 03:48 1927850032 ----a-w- c:\program files\data2.cab
2008-11-11 16:08 . 2008-11-23 03:51 6114737 ----a-w- c:\program files\data1.cab
2008-11-11 16:05 . 2008-11-23 03:51 94 ----a-w- c:\program files\Setup.ini
2008-11-11 16:05 . 2008-11-23 03:51 169305 ----a-w- c:\program files\Setup.inx
2008-03-08 15:20 . 2008-03-08 15:21 774144 ----a-w- c:\program files\RngInterstitial.dll
2007-07-30 23:30 . 2008-11-23 03:51 470240 ----a-w- c:\program files\setup.bmp
2007-03-14 19:16 . 2008-11-23 03:51 346602 ----a-w- c:\program files\ikernel.ex_
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2009-05-23 1794320]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-07 1948440]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-15 13570048]
"COMODO Internet Security"="c:\program files\COMODO\Firewall\cfp.exe" [2009-05-23 1794320]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"NvMediaCenter"="NvMCTray.dll" - c:\windows\system32\nvmctray.dll [2008-08-15 86016]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-5-2 692224]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-07 13:42 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0pgdfgsvc C 1\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Steam\\steamapps\\koreathebest\\counter-strike\\hl.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Diablo II\\Diablo II.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgrsx.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:Diablo II Battle.Net

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4/30/2009 6:53 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/30/2008 8:19 PM 327688]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [9/30/2008 8:12 PM 132640]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [9/30/2008 8:12 PM 24096]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/30/2008 8:19 PM 298776]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1003344]
S3 DM9USB;DM9601 USB To Fast Ethernet Adapter;c:\windows\system32\drivers\dm9usb.sys [12/22/2007 3:43 PM 21376]
S3 XDva037;XDva037;\??\c:\windows\system32\XDva037.sys --> c:\windows\system32\XDva037.sys [?]
S3 XDva064;XDva064;\??\c:\windows\system32\XDva064.sys --> c:\windows\system32\XDva064.sys [?]
S3 XDva090;XDva090;\??\c:\windows\system32\XDva090.sys --> c:\windows\system32\XDva090.sys [?]
S3 XDva132;XDva132;\??\c:\windows\system32\XDva132.sys --> c:\windows\system32\XDva132.sys [?]
S3 XDva143;XDva143;\??\c:\windows\system32\XDva143.sys --> c:\windows\system32\XDva143.sys [?]
S3 XDva177;XDva177;\??\c:\windows\system32\XDva177.sys --> c:\windows\system32\XDva177.sys [?]
S3 XDva189;XDva189;\??\c:\windows\system32\XDva189.sys --> c:\windows\system32\XDva189.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2009-06-25 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 22:52]

2009-07-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-07-08 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-04-09 23:48]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\User\Start Menu\Programs\IMVU\Run IMVU.lnk
DPF: {C9A2CBF3-B7F9-463E-A690-82CC077DCFC6} - hxxp://www.4story.com/Active_X/ZemiDetectHardware.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\6d36xtix.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\User\Application Data\Mozilla\plugins\npoctoshape.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-08 01:37
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose, ZwOpenFile

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1000)
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'lsass.exe'(1056)
c:\windows\system32\guard32.dll

- - - - - - - > 'explorer.exe'(360)
c:\windows\system32\guard32.dll
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-07-08 1:40
ComboFix-quarantined-files.txt 2009-07-08 05:40
ComboFix2.txt 2009-07-07 01:16
ComboFix3.txt 2009-05-10 04:35

Pre-Run: 93,493,415,936 bytes free
Post-Run: 93,459,628,032 bytes free

214 --- E O F --- 2009-06-11 03:49




Here is the DDS Log:

ComboFix 09-07-07.A2 - User 07/08/2009 1:30.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.462 [GMT -4:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.

((((((((((((((((((((((((( Files Created from 2009-06-08 to 2009-07-08 )))))))))))))))))))))))))))))))
.

2009-06-27 21:13 . 2009-06-27 21:13 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Help
2009-06-23 12:50 . 2009-03-28 23:52 94208 ----a-w- c:\documents and settings\User\Application Data\Soldat\Battleye\BEServer.dll
2009-06-23 12:50 . 2009-03-28 23:52 102400 ----a-w- c:\documents and settings\User\Application Data\Soldat\Battleye\BEClient.dll
2009-06-23 12:50 . 2009-06-23 12:50 0 ----a-r- C:\logwmemory.bin
2009-06-23 12:49 . 2009-06-23 12:49 -------- d-----w- c:\documents and settings\User\Application Data\Soldat
2009-06-15 17:23 . 2009-06-15 17:23 541696 ----a-w- c:\documents and settings\User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv304-0905011-0-main.dll
2009-06-13 20:34 . 2009-06-13 20:34 -------- d-----w- c:\program files\Zemi Interactive
2009-06-13 20:29 . 2009-06-13 20:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Estsoft
2009-06-13 20:28 . 2009-06-13 23:53 -------- d-----w- c:\program files\ESTsoft
2009-06-13 20:28 . 2009-06-13 20:29 -------- d-----w- c:\documents and settings\User\Application Data\ESTsoft
2009-06-12 00:20 . 2009-05-28 22:52 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-09 20:13 . 2009-06-09 20:13 152576 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-09 02:08 . 2009-06-09 02:08 -------- d-----w- c:\documents and settings\User\Application Data\Toribash
2009-06-09 02:07 . 2009-06-09 02:07 -------- d-----w- C:\Games
2009-06-08 19:17 . 2009-06-08 19:17 -------- d-----w- C:\nDoors
2009-06-08 15:42 . 2009-06-08 15:42 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\DNA
2009-06-08 15:42 . 2009-06-27 21:14 -------- d-----w- c:\documents and settings\User\Application Data\DNA
2009-06-08 15:42 . 2009-06-27 18:18 -------- d-----w- c:\program files\DNA

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-08 00:43 . 2008-04-17 19:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-07 13:42 . 2008-10-01 00:19 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-07 13:42 . 2008-10-01 00:19 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-07-07 13:42 . 2008-10-01 00:19 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-26 01:14 . 2009-01-08 23:49 -------- d-----w- c:\program files\Steam
2009-06-25 04:08 . 2009-01-12 04:19 -------- d-----w- c:\documents and settings\User\Application Data\mIRC
2009-06-25 04:01 . 2009-01-12 04:19 -------- d-----w- c:\program files\mIRC
2009-06-25 02:38 . 2007-12-22 22:19 694464 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-25 01:48 . 2009-05-13 02:08 -------- d-----w- c:\program files\compLexity Demo Player
2009-06-17 00:09 . 2008-11-06 01:49 -------- d-----w- c:\program files\Diablo II
2009-06-15 16:26 . 2008-10-01 00:19 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-13 20:52 . 2007-12-22 19:35 73088 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-09 20:15 . 2009-04-26 17:56 -------- d-----w- c:\program files\Java
2009-06-08 21:52 . 2007-12-22 20:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-05 19:24 . 2008-05-31 22:47 -------- d-----w- c:\program files\StarCraft
2009-06-03 19:38 . 2008-05-24 17:32 -------- d-----w- c:\program files\StealthBot
2009-05-28 22:52 . 2009-05-28 22:52 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lsdelete.exe
2009-05-28 22:52 . 2009-05-28 22:52 83808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\ShellExt.dll
2009-05-28 22:52 . 2009-05-28 22:52 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\RPAPI.dll
2009-05-28 22:52 . 2009-05-28 22:52 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\PrivacyClean.dll
2009-05-27 20:16 . 2009-04-11 18:45 120088 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Plugins\npoctoshape.dll
2009-05-27 20:08 . 2009-05-27 20:08 -------- d-----w- c:\program files\RivaTuner v2.24
2009-05-25 10:50 . 2009-05-27 19:13 401920 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\sua-0905250-0-libOctoshapeClient.dll
2009-05-25 10:50 . 2009-05-27 19:13 120088 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\sua-0905250-0-npoctoshape.dll
2009-05-25 10:50 . 2009-05-27 19:13 124184 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\sua-0905250-0-apoctoshape.dll
2009-05-23 02:09 . 2008-10-01 00:12 168208 ----a-w- c:\windows\system32\guard32.dll
2009-05-23 02:09 . 2008-10-01 00:12 82080 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-05-23 02:09 . 2008-10-01 00:12 24096 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-05-23 02:09 . 2008-10-01 00:12 132640 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-05-22 19:41 . 2008-08-17 19:25 -------- d-----w- c:\documents and settings\User\Application Data\Ventrilo
2009-05-21 15:33 . 2009-04-26 17:57 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-10 04:46 . 2009-05-10 04:46 -------- d-----w- c:\documents and settings\User\Application Data\Auslogics
2009-05-10 04:38 . 2009-05-10 04:38 -------- d-----w- c:\program files\Auslogics
2009-05-07 15:32 . 2004-08-03 13:56 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-02 04:37 . 2009-05-02 04:37 10134 ----a-r- c:\documents and settings\User\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2009-05-02 04:33 . 2009-05-02 04:33 10134 ----a-r- c:\documents and settings\User\Application Data\Microsoft\Installer\{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}\ARPPRODUCTICON.exe
2009-05-02 04:29 . 2009-05-02 04:29 10134 ----a-r- c:\documents and settings\User\Application Data\Microsoft\Installer\{56918C0C-0D87-4CA6-92BF-4975A43AC719}\ARPPRODUCTICON.exe
2009-04-30 22:52 . 2009-04-30 22:53 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-04-30 22:52 . 2009-04-30 22:52 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Drivers\32\lbd.sys
2009-04-29 04:56 . 2004-08-03 13:56 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-03 13:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-25 13:20 . 2009-04-25 13:20 576512 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\pmv302-0810271-0-libOctoshapeClient.dll
2009-04-17 12:26 . 2004-08-03 12:17 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-03 13:56 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-11 18:48 . 2009-04-11 18:48 585728 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\pmv302a-0902180-0-libOctoshapeClient.dll
2009-01-03 13:21 . 2009-01-03 13:21 15706 ----a-w- c:\program files\changes.txt
2009-01-01 12:58 . 2009-01-01 12:58 1852 ----a-w- c:\program files\README.HTM
2008-11-11 16:10 . 2008-11-23 03:51 751167 ----a-w- c:\program files\data1.hdr
2008-11-11 16:10 . 2008-11-23 03:51 435 ----a-w- c:\program files\layout.bin
2008-11-11 16:10 . 2008-11-23 03:48 1927850032 ----a-w- c:\program files\data2.cab
2008-11-11 16:08 . 2008-11-23 03:51 6114737 ----a-w- c:\program files\data1.cab
2008-11-11 16:05 . 2008-11-23 03:51 94 ----a-w- c:\program files\Setup.ini
2008-11-11 16:05 . 2008-11-23 03:51 169305 ----a-w- c:\program files\Setup.inx
2008-03-08 15:20 . 2008-03-08 15:21 774144 ----a-w- c:\program files\RngInterstitial.dll
2007-07-30 23:30 . 2008-11-23 03:51 470240 ----a-w- c:\program files\setup.bmp
2007-03-14 19:16 . 2008-11-23 03:51 346602 ----a-w- c:\program files\ikernel.ex_
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2009-05-23 1794320]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-07 1948440]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-15 13570048]
"COMODO Internet Security"="c:\program files\COMODO\Firewall\cfp.exe" [2009-05-23 1794320]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"NvMediaCenter"="NvMCTray.dll" - c:\windows\system32\nvmctray.dll [2008-08-15 86016]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-5-2 692224]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-07 13:42 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0pgdfgsvc C 1\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Steam\\steamapps\\koreathebest\\counter-strike\\hl.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Diablo II\\Diablo II.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgrsx.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:Diablo II Battle.Net

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4/30/2009 6:53 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/30/2008 8:19 PM 327688]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [9/30/2008 8:12 PM 132640]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [9/30/2008 8:12 PM 24096]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/30/2008 8:19 PM 298776]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1003344]
S3 DM9USB;DM9601 USB To Fast Ethernet Adapter;c:\windows\system32\drivers\dm9usb.sys [12/22/2007 3:43 PM 21376]
S3 XDva037;XDva037;\??\c:\windows\system32\XDva037.sys --> c:\windows\system32\XDva037.sys [?]
S3 XDva064;XDva064;\??\c:\windows\system32\XDva064.sys --> c:\windows\system32\XDva064.sys [?]
S3 XDva090;XDva090;\??\c:\windows\system32\XDva090.sys --> c:\windows\system32\XDva090.sys [?]
S3 XDva132;XDva132;\??\c:\windows\system32\XDva132.sys --> c:\windows\system32\XDva132.sys [?]
S3 XDva143;XDva143;\??\c:\windows\system32\XDva143.sys --> c:\windows\system32\XDva143.sys [?]
S3 XDva177;XDva177;\??\c:\windows\system32\XDva177.sys --> c:\windows\system32\XDva177.sys [?]
S3 XDva189;XDva189;\??\c:\windows\system32\XDva189.sys --> c:\windows\system32\XDva189.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2009-06-25 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 22:52]

2009-07-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-07-08 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-04-09 23:48]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\User\Start Menu\Programs\IMVU\Run IMVU.lnk
DPF: {C9A2CBF3-B7F9-463E-A690-82CC077DCFC6} - hxxp://www.4story.com/Active_X/ZemiDetectHardware.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\6d36xtix.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\User\Application Data\Mozilla\plugins\npoctoshape.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-08 01:37
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose, ZwOpenFile

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1000)
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'lsass.exe'(1056)
c:\windows\system32\guard32.dll

- - - - - - - > 'explorer.exe'(360)
c:\windows\system32\guard32.dll
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-07-08 1:40
ComboFix-quarantined-files.txt 2009-07-08 05:40
ComboFix2.txt 2009-07-07 01:16
ComboFix3.txt 2009-05-10 04:35

Pre-Run: 93,493,415,936 bytes free
Post-Run: 93,459,628,032 bytes free

214 --- E O F --- 2009-06-11 03:49


And I attached the other one. I really appreciate all the help. Thanks alot.

Attached Files



#12 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:02:12 AM

Posted 08 July 2009 - 08:21 AM

Hi,

ComboFix log seems to have been included twice instead of posting dds.txt log. Please post missing log too :thumbup2:

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.


#13 Haerith

Haerith
  • Topic Starter

  • Members
  • 50 posts
  • OFFLINE
  •  
  • Local time:07:12 PM

Posted 08 July 2009 - 10:46 PM

Haha, I am so sorry....How is this:


DDS (Ver_09-06-26.01) - NTFSx86
Run by User at 9:10:14.14 on Wed 07/08/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.422 [GMT -4:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\User\Desktop\whatever.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [COMODO Firewall Pro] "c:\program files\comodo\firewall\cfp.exe" -h
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
mRun: [COMODO Internet Security] "c:\program files\comodo\firewall\cfp.exe" -h
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\user\start menu\programs\imvu\Run IMVU.lnk
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scan8/oscan8.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1198356628938
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C9A2CBF3-B7F9-463E-A690-82CC077DCFC6} - hxxp://www.4story.com/Active_X/ZemiDetectHardware.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://www.driveragent.com/files/driveragent.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\6d36xtix.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\documents and settings\user\application data\mozilla\plugins\npoctoshape.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npracplug.dll
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-30 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-9-30 327688]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-9-30 27784]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2008-9-30 132640]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2008-9-30 24096]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-9-30 298776]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\firewall\cmdagent.exe [2008-9-30 692496]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1003344]
S2 NAVAPEL;NAVAPEL;\??\c:\program files\symantec_client_security\symantec antivirus\navapel.sys --> c:\program files\symantec_client_security\symantec antivirus\NAVAPEL.SYS [?]
S3 DM9USB;DM9601 USB To Fast Ethernet Adapter;c:\windows\system32\drivers\dm9usb.sys [2007-12-22 21376]
S3 NAVAP;NAVAP;\??\c:\program files\symantec_client_security\symantec antivirus\navap.sys --> c:\program files\symantec_client_security\symantec antivirus\NAVAP.sys [?]
S3 XDva037;XDva037;\??\c:\windows\system32\xdva037.sys --> c:\windows\system32\XDva037.sys [?]
S3 XDva064;XDva064;\??\c:\windows\system32\xdva064.sys --> c:\windows\system32\XDva064.sys [?]
S3 XDva090;XDva090;\??\c:\windows\system32\xdva090.sys --> c:\windows\system32\XDva090.sys [?]
S3 XDva132;XDva132;\??\c:\windows\system32\xdva132.sys --> c:\windows\system32\XDva132.sys [?]
S3 XDva143;XDva143;\??\c:\windows\system32\xdva143.sys --> c:\windows\system32\XDva143.sys [?]
S3 XDva177;XDva177;\??\c:\windows\system32\xdva177.sys --> c:\windows\system32\XDva177.sys [?]
S3 XDva189;XDva189;\??\c:\windows\system32\xdva189.sys --> c:\windows\system32\XDva189.sys [?]

=============== Created Last 30 ================

2009-07-08 00:22 155,136 a------- c:\windows\PEV.exe
2009-07-06 21:14 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-06-23 08:50 0 a----r-- C:\logwmemory.bin
2009-06-23 08:49 <DIR> --d----- c:\docume~1\user\applic~1\Soldat
2009-06-13 16:34 <DIR> --d----- c:\program files\Zemi Interactive
2009-06-13 16:29 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Estsoft
2009-06-13 16:28 <DIR> --d----- c:\program files\ESTsoft
2009-06-13 16:28 <DIR> --d----- c:\docume~1\user\applic~1\ESTsoft
2009-06-11 20:20 15,688 a------- c:\windows\system32\lsdelete.exe
2009-06-08 22:08 <DIR> --d----- c:\docume~1\user\applic~1\Toribash
2009-06-08 22:07 <DIR> --d----- C:\Games
2009-06-08 15:17 <DIR> --d----- C:\nDoors
2009-06-08 11:42 <DIR> --d----- c:\program files\DNA
2009-06-08 11:42 <DIR> --d----- c:\docume~1\user\applic~1\DNA

==================== Find3M ====================

2009-07-07 09:42 327,688 a------- c:\windows\system32\drivers\avgldx86.sys
2009-07-07 09:42 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-05-22 22:09 168,208 a------- c:\windows\system32\guard32.dll
2009-05-22 22:09 24,096 a------- c:\windows\system32\drivers\cmdhlp.sys
2009-05-22 22:09 132,640 a------- c:\windows\system32\drivers\cmdguard.sys
2009-05-21 11:33 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-07 11:32 345,600 a------- c:\windows\system32\localspl.dll
2009-04-29 00:56 827,392 a------- c:\windows\system32\wininet.dll
2009-04-29 00:55 78,336 a------- c:\windows\system32\ieencode.dll
2009-04-17 08:26 1,847,168 a------- c:\windows\system32\win32k.sys
2009-04-15 10:51 585,216 a------- c:\windows\system32\rpcrt4.dll
2009-01-03 09:21 15,706 a------- c:\program files\changes.txt
2009-01-01 08:58 1,852 a------- c:\program files\README.HTM
2008-11-11 12:10 1,927,850,032 a------- c:\program files\data2.cab
2008-11-11 12:10 751,167 a------- c:\program files\data1.hdr
2008-11-11 12:10 435 a------- c:\program files\layout.bin
2008-11-11 12:08 6,114,737 a------- c:\program files\data1.cab
2008-11-11 12:05 94 a------- c:\program files\Setup.ini
2008-11-11 12:05 169,305 a------- c:\program files\Setup.inx
2008-03-08 11:20 774,144 a------- c:\program files\RngInterstitial.dll
2007-07-30 19:30 470,240 a------- c:\program files\setup.bmp
2007-03-14 15:16 346,602 a------- c:\program files\ikernel.ex_
2008-10-05 17:00 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100520081006\index.dat

============= FINISH: 9:10:37.73 ===============

#14 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:02:12 AM

Posted 09 July 2009 - 04:13 AM

Hi again,

Please do following having TeaTimer disabled:


Open notepad and copy/paste the text in the quotebox below into it:

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=-


Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

Posted Image

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.


Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.


Uninstall old Adobe Reader versions and get the latest one (9.1 + update 9.1.2 for it) here or get Foxit Reader here. Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here.


Download ATF (Atribune Temp File) Cleanerę by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Please run an online scan with Kaspersky Online Scanner as instructed in the screenshot here.


Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.


#15 Haerith

Haerith
  • Topic Starter

  • Members
  • 50 posts
  • OFFLINE
  •  
  • Local time:07:12 PM

Posted 09 July 2009 - 11:46 PM

I really appreciate all the help. Here are the reports:

ComboFix:

ComboFix 09-07-09.06 - User 07/09/2009 19:20.7.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.455 [GMT -4:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.

((((((((((((((((((((((((( Files Created from 2009-06-09 to 2009-07-09 )))))))))))))))))))))))))))))))
.

2009-07-09 23:01 . 2009-07-09 23:01 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-07-09 23:01 . 2009-07-09 23:01 -------- d-----w- c:\program files\NOS
2009-07-09 23:00 . 2009-07-08 18:22 32456 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\6d36xtix.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-07-09 23:00 . 2009-07-08 18:22 22848 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\6d36xtix.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-07-09 23:00 . 2009-07-08 18:22 18776 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\6d36xtix.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-06-27 21:13 . 2009-06-27 21:13 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Help
2009-06-23 12:50 . 2009-03-28 23:52 94208 ----a-w- c:\documents and settings\User\Application Data\Soldat\Battleye\BEServer.dll
2009-06-23 12:50 . 2009-03-28 23:52 102400 ----a-w- c:\documents and settings\User\Application Data\Soldat\Battleye\BEClient.dll
2009-06-23 12:50 . 2009-06-23 12:50 0 ----a-r- C:\logwmemory.bin
2009-06-23 12:49 . 2009-06-23 12:49 -------- d-----w- c:\documents and settings\User\Application Data\Soldat
2009-06-15 17:23 . 2009-06-15 17:23 541696 ----a-w- c:\documents and settings\User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv304-0905011-0-main.dll
2009-06-13 20:34 . 2009-06-13 20:34 -------- d-----w- c:\program files\Zemi Interactive
2009-06-13 20:29 . 2009-06-13 20:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Estsoft
2009-06-13 20:28 . 2009-06-13 23:53 -------- d-----w- c:\program files\ESTsoft
2009-06-13 20:28 . 2009-06-13 20:29 -------- d-----w- c:\documents and settings\User\Application Data\ESTsoft
2009-06-12 00:20 . 2009-05-28 22:52 15688 ----a-w- c:\windows\system32\lsdelete.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-09 23:07 . 2008-03-07 14:30 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-09 22:53 . 2009-06-18 22:52 314712 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\threatwork.exe
2009-07-09 22:53 . 2009-06-18 22:52 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\savapibridge.dll
2009-07-09 22:53 . 2009-06-18 22:52 169312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lavamessage.dll
2009-07-09 22:53 . 2009-06-18 22:52 348496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lavalicense.dll
2009-07-09 22:53 . 2009-06-18 22:52 298336 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\UpdateManager.dll
2009-07-09 22:53 . 2009-06-18 22:52 1630560 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Resources.dll
2009-07-09 22:53 . 2009-05-28 22:52 84832 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\ShellExt.dll
2009-07-09 22:53 . 2009-06-18 22:52 85352 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Drivers\32\AAWDriverTool.exe
2009-07-09 22:53 . 2009-06-18 22:52 664424 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\CEAPI.dll
2009-07-09 22:53 . 2009-05-28 22:52 246128 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\RPAPI.dll
2009-07-09 22:53 . 2009-05-28 22:52 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\PrivacyClean.dll
2009-07-09 22:52 . 2009-06-18 22:52 563064 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-AwareCommand.exe
2009-07-09 22:52 . 2009-06-18 22:52 566632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-AwareAdmin.exe
2009-07-09 22:52 . 2009-06-18 22:52 2353480 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-Aware.exe
2009-07-09 22:52 . 2009-06-18 22:52 629072 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AAWWSC.exe
2009-07-09 22:52 . 2009-06-18 22:52 520024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AAWTray.exe
2009-07-09 22:52 . 2009-06-18 22:52 1029456 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AAWService.exe
2009-07-09 01:44 . 2008-04-17 19:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-07 13:42 . 2008-10-01 00:19 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-07 13:42 . 2008-10-01 00:19 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-07-07 13:42 . 2008-10-01 00:19 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-27 21:14 . 2009-06-08 15:42 -------- d-----w- c:\documents and settings\User\Application Data\DNA
2009-06-27 18:18 . 2009-06-08 15:42 -------- d-----w- c:\program files\DNA
2009-06-26 01:14 . 2009-01-08 23:49 -------- d-----w- c:\program files\Steam
2009-06-25 04:08 . 2009-01-12 04:19 -------- d-----w- c:\documents and settings\User\Application Data\mIRC
2009-06-25 04:01 . 2009-01-12 04:19 -------- d-----w- c:\program files\mIRC
2009-06-25 02:38 . 2007-12-22 22:19 694464 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-25 01:48 . 2009-05-13 02:08 -------- d-----w- c:\program files\compLexity Demo Player
2009-06-17 00:09 . 2008-11-06 01:49 -------- d-----w- c:\program files\Diablo II
2009-06-15 16:26 . 2008-10-01 00:19 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-13 20:52 . 2007-12-22 19:35 73088 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-09 20:15 . 2009-04-26 17:56 -------- d-----w- c:\program files\Java
2009-06-09 20:13 . 2009-06-09 20:13 152576 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-09 02:08 . 2009-06-09 02:08 -------- d-----w- c:\documents and settings\User\Application Data\Toribash
2009-06-08 21:52 . 2007-12-22 20:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-05 19:24 . 2008-05-31 22:47 -------- d-----w- c:\program files\StarCraft
2009-06-03 19:38 . 2008-05-24 17:32 -------- d-----w- c:\program files\StealthBot
2009-05-28 22:52 . 2009-05-28 22:52 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lsdelete.exe
2009-05-27 20:16 . 2009-04-11 18:45 120088 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Plugins\npoctoshape.dll
2009-05-27 20:08 . 2009-05-27 20:08 -------- d-----w- c:\program files\RivaTuner v2.24
2009-05-25 10:50 . 2009-05-27 19:13 401920 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\sua-0905250-0-libOctoshapeClient.dll
2009-05-25 10:50 . 2009-05-27 19:13 120088 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\sua-0905250-0-npoctoshape.dll
2009-05-25 10:50 . 2009-05-27 19:13 124184 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\sua-0905250-0-apoctoshape.dll
2009-05-23 02:09 . 2008-10-01 00:12 168208 ----a-w- c:\windows\system32\guard32.dll
2009-05-23 02:09 . 2008-10-01 00:12 82080 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-05-23 02:09 . 2008-10-01 00:12 24096 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-05-23 02:09 . 2008-10-01 00:12 132640 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-05-22 19:41 . 2008-08-17 19:25 -------- d-----w- c:\documents and settings\User\Application Data\Ventrilo
2009-05-21 15:33 . 2009-04-26 17:57 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-07 15:32 . 2004-08-03 13:56 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-02 04:37 . 2009-05-02 04:37 10134 ----a-r- c:\documents and settings\User\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2009-05-02 04:33 . 2009-05-02 04:33 10134 ----a-r- c:\documents and settings\User\Application Data\Microsoft\Installer\{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}\ARPPRODUCTICON.exe
2009-05-02 04:29 . 2009-05-02 04:29 10134 ----a-r- c:\documents and settings\User\Application Data\Microsoft\Installer\{56918C0C-0D87-4CA6-92BF-4975A43AC719}\ARPPRODUCTICON.exe
2009-04-30 22:52 . 2009-04-30 22:53 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-04-30 22:52 . 2009-04-30 22:52 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Drivers\32\lbd.sys
2009-04-29 04:56 . 2004-08-03 13:56 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-03 13:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-25 13:20 . 2009-04-25 13:20 576512 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\pmv302-0810271-0-libOctoshapeClient.dll
2009-04-17 12:26 . 2004-08-03 12:17 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-03 13:56 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-11 18:48 . 2009-04-11 18:48 585728 ----a-w- c:\documents and settings\User\Application Data\Octoshape\Octoshape Streaming Services\pmv302a-0902180-0-libOctoshapeClient.dll
2009-01-03 13:21 . 2009-01-03 13:21 15706 ----a-w- c:\program files\changes.txt
2009-01-01 12:58 . 2009-01-01 12:58 1852 ----a-w- c:\program files\README.HTM
2008-11-11 16:10 . 2008-11-23 03:51 751167 ----a-w- c:\program files\data1.hdr
2008-11-11 16:10 . 2008-11-23 03:51 435 ----a-w- c:\program files\layout.bin
2008-11-11 16:10 . 2008-11-23 03:48 1927850032 ----a-w- c:\program files\data2.cab
2008-11-11 16:08 . 2008-11-23 03:51 6114737 ----a-w- c:\program files\data1.cab
2008-11-11 16:05 . 2008-11-23 03:51 94 ----a-w- c:\program files\Setup.ini
2008-11-11 16:05 . 2008-11-23 03:51 169305 ----a-w- c:\program files\Setup.inx
2008-03-08 15:20 . 2008-03-08 15:21 774144 ----a-w- c:\program files\RngInterstitial.dll
2007-07-30 23:30 . 2008-11-23 03:51 470240 ----a-w- c:\program files\setup.bmp
2007-03-14 19:16 . 2008-11-23 03:51 346602 ----a-w- c:\program files\ikernel.ex_
.

((((((((((((((((((((((((((((( SnapShot_2009-07-06_23.49.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-09 23:17 . 2009-07-09 23:17 802304 c:\windows\Installer\f4b4d83.msi
+ 2009-07-09 23:17 . 2009-07-09 23:17 295606 c:\windows\Installer\{AC76BA86-7AD7-5464-3428-900000000004}\ARPPRODUCTICON.exe
+ 2009-01-18 20:05 . 2009-01-18 20:05 675840 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\JP2KLib.dll
+ 2009-07-09 23:15 . 2009-07-09 23:15 6653952 c:\windows\Installer\f4b4d7e.msp
+ 2009-07-09 23:08 . 2009-07-09 23:08 3938816 c:\windows\Installer\f4b4d59.msi
+ 2008-12-18 20:48 . 2008-12-18 20:48 3645440 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\authplay.dll
+ 2009-02-27 20:37 . 2009-02-27 20:37 20403568 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\AcroRd32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2009-05-23 1794320]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-07 1948440]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-15 13570048]
"COMODO Internet Security"="c:\program files\COMODO\Firewall\cfp.exe" [2009-05-23 1794320]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"NvMediaCenter"="NvMCTray.dll" - c:\windows\system32\nvmctray.dll [2008-08-15 86016]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-5-2 692224]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-07 13:42 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0pgdfgsvc C 1\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Steam\\steamapps\\koreathebest\\counter-strike\\hl.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Diablo II\\Diablo II.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgrsx.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:Diablo II Battle.Net

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4/30/2009 6:53 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/30/2008 8:19 PM 327688]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [9/30/2008 8:12 PM 132640]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [9/30/2008 8:12 PM 24096]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/30/2008 8:19 PM 298776]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1029456]
S3 DM9USB;DM9601 USB To Fast Ethernet Adapter;c:\windows\system32\drivers\dm9usb.sys [12/22/2007 3:43 PM 21376]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [7/9/2009 7:01 PM 66056]
S3 XDva037;XDva037;\??\c:\windows\system32\XDva037.sys --> c:\windows\system32\XDva037.sys [?]
S3 XDva064;XDva064;\??\c:\windows\system32\XDva064.sys --> c:\windows\system32\XDva064.sys [?]
S3 XDva090;XDva090;\??\c:\windows\system32\XDva090.sys --> c:\windows\system32\XDva090.sys [?]
S3 XDva132;XDva132;\??\c:\windows\system32\XDva132.sys --> c:\windows\system32\XDva132.sys [?]
S3 XDva143;XDva143;\??\c:\windows\system32\XDva143.sys --> c:\windows\system32\XDva143.sys [?]
S3 XDva177;XDva177;\??\c:\windows\system32\XDva177.sys --> c:\windows\system32\XDva177.sys [?]
S3 XDva189;XDva189;\??\c:\windows\system32\XDva189.sys --> c:\windows\system32\XDva189.sys [?]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - GETPLUS®_HELPER
.
Contents of the 'Scheduled Tasks' folder

2009-07-09 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 22:52]

2009-07-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-07-09 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-04-09 23:48]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\User\Start Menu\Programs\IMVU\Run IMVU.lnk
DPF: {C9A2CBF3-B7F9-463E-A690-82CC077DCFC6} - hxxp://www.4story.com/Active_X/ZemiDetectHardware.cab
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\6d36xtix.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\6d36xtix.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\documents and settings\User\Application Data\Mozilla\plugins\npoctoshape.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-09 19:27
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose, ZwOpenFile

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1000)
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'lsass.exe'(1056)
c:\windows\system32\guard32.dll

- - - - - - - > 'explorer.exe'(216)
c:\windows\system32\guard32.dll
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-07-09 19:30
ComboFix-quarantined-files.txt 2009-07-09 23:30
ComboFix2.txt 2009-07-08 05:40
ComboFix3.txt 2009-07-07 01:16
ComboFix4.txt 2009-05-10 04:35

Pre-Run: 92,975,517,696 bytes free
Post-Run: 92,946,243,584 bytes free

242 --- E O F --- 2009-06-11 03:49



Kapersky:

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Friday, July 10, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Thursday, July 09, 2009 20:50:46
Records in database: 2451499
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\

Scan statistics:
Files scanned: 159909
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 02:34:27


File name / Threat name / Threats count
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1

The selected area was scanned.



DDS:



DDS (Ver_09-06-26.01) - NTFSx86
Run by User at 0:30:19.18 on Fri 07/10/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.596 [GMT -4:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\User\Desktop\whatever.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [COMODO Firewall Pro] "c:\program files\comodo\firewall\cfp.exe" -h
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
mRun: [COMODO Internet Security] "c:\program files\comodo\firewall\cfp.exe" -h
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\user\start menu\programs\imvu\Run IMVU.lnk
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scan8/oscan8.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1198356628938
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C9A2CBF3-B7F9-463E-A690-82CC077DCFC6} - hxxp://www.4story.com/Active_X/ZemiDetectHardware.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://www.driveragent.com/files/driveragent.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\6d36xtix.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\documents and settings\user\application data\mozilla\firefox\profiles\6d36xtix.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
FF - plugin: c:\documents and settings\user\application data\mozilla\plugins\npoctoshape.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npracplug.dll
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-30 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-9-30 327688]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-9-30 27784]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2008-9-30 132640]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2008-9-30 24096]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-9-30 298776]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\firewall\cmdagent.exe [2008-9-30 692496]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1029456]
S2 NAVAPEL;NAVAPEL;\??\c:\program files\symantec_client_security\symantec antivirus\navapel.sys --> c:\program files\symantec_client_security\symantec antivirus\NAVAPEL.SYS [?]
S3 DM9USB;DM9601 USB To Fast Ethernet Adapter;c:\windows\system32\drivers\dm9usb.sys [2007-12-22 21376]
S3 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-7-9 66056]
S3 NAVAP;NAVAP;\??\c:\program files\symantec_client_security\symantec antivirus\navap.sys --> c:\program files\symantec_client_security\symantec antivirus\NAVAP.sys [?]
S3 XDva037;XDva037;\??\c:\windows\system32\xdva037.sys --> c:\windows\system32\XDva037.sys [?]
S3 XDva064;XDva064;\??\c:\windows\system32\xdva064.sys --> c:\windows\system32\XDva064.sys [?]
S3 XDva090;XDva090;\??\c:\windows\system32\xdva090.sys --> c:\windows\system32\XDva090.sys [?]
S3 XDva132;XDva132;\??\c:\windows\system32\xdva132.sys --> c:\windows\system32\XDva132.sys [?]
S3 XDva143;XDva143;\??\c:\windows\system32\xdva143.sys --> c:\windows\system32\XDva143.sys [?]
S3 XDva177;XDva177;\??\c:\windows\system32\xdva177.sys --> c:\windows\system32\XDva177.sys [?]
S3 XDva189;XDva189;\??\c:\windows\system32\xdva189.sys --> c:\windows\system32\XDva189.sys [?]

=============== Created Last 30 ================

2009-07-08 00:22 155,136 a------- c:\windows\PEV.exe
2009-07-06 21:14 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-06-23 08:50 0 a----r-- C:\logwmemory.bin
2009-06-23 08:49 <DIR> --d----- c:\docume~1\user\applic~1\Soldat
2009-06-13 16:34 <DIR> --d----- c:\program files\Zemi Interactive
2009-06-13 16:29 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Estsoft
2009-06-13 16:28 <DIR> --d----- c:\program files\ESTsoft
2009-06-13 16:28 <DIR> --d----- c:\docume~1\user\applic~1\ESTsoft
2009-06-11 20:20 15,688 a------- c:\windows\system32\lsdelete.exe

==================== Find3M ====================

2009-07-07 09:42 327,688 a------- c:\windows\system32\drivers\avgldx86.sys
2009-07-07 09:42 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-05-22 22:09 168,208 a------- c:\windows\system32\guard32.dll
2009-05-22 22:09 24,096 a------- c:\windows\system32\drivers\cmdhlp.sys
2009-05-22 22:09 132,640 a------- c:\windows\system32\drivers\cmdguard.sys
2009-05-21 11:33 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-07 11:32 345,600 a------- c:\windows\system32\localspl.dll
2009-04-29 00:56 827,392 a------- c:\windows\system32\wininet.dll
2009-04-29 00:55 78,336 a------- c:\windows\system32\ieencode.dll
2009-04-17 08:26 1,847,168 a------- c:\windows\system32\win32k.sys
2009-04-15 10:51 585,216 a------- c:\windows\system32\rpcrt4.dll
2009-01-03 09:21 15,706 a------- c:\program files\changes.txt
2009-01-01 08:58 1,852 a------- c:\program files\README.HTM
2008-11-11 12:10 1,927,850,032 a------- c:\program files\data2.cab
2008-11-11 12:10 751,167 a------- c:\program files\data1.hdr
2008-11-11 12:10 435 a------- c:\program files\layout.bin
2008-11-11 12:08 6,114,737 a------- c:\program files\data1.cab
2008-11-11 12:05 94 a------- c:\program files\Setup.ini
2008-11-11 12:05 169,305 a------- c:\program files\Setup.inx
2008-03-08 11:20 774,144 a------- c:\program files\RngInterstitial.dll
2007-07-30 19:30 470,240 a------- c:\program files\setup.bmp
2007-03-14 15:16 346,602 a------- c:\program files\ikernel.ex_
2008-10-05 17:00 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100520081006\index.dat

============= FINISH: 0:31:03.76 ===============


Thanks!!!

Attached Files






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users