Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

redirect trouble, printer not working,


  • This topic is locked This topic is locked
38 replies to this topic

#1 surf

surf

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:38 PM

Posted 16 October 2010 - 04:03 PM

I downloaded a wmp file and played it. temporary insanity is all I can figure. it was bad. IE immediately started misdrecting google to host of multiple shopping links. google affected on all three web browsers google chrome, firefox and IE. have updated and run malware for two weeks. not found. My printer has also been rendered ineffective. jobs go into que and error, then block and stay deleting for a really long time. I'v had a 3 page job printing for 3 days now.

DDS (Ver_10-10-10.03) - NTFSx86
Run by Owner at 9:42:52.62 on Sat 10/16/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1406.690 [GMT -5:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Gateway\EzTune\dtsslsrv.exe
C:\Program Files\Gateway\EzTune\dtsrvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\CNYHKey.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\WinPortrait\wpctrl.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\WinPortrait\floater.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Owner.Kids\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Owner.Kids\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyServer = http=127.0.0.1:5577
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\windows\system32\BAE.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - No File
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [SansaDispatch] c:\documents and settings\owner.kids\application data\sandisk\sansa updater\SansaDispatch.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [CHotkey] mHotkey.exe
mRun: [ledpointer] CNYHKey.exe
mRun: [showwnd] showwnd.exe
mRun: [readericon] c:\program files\digital media reader\readericon45G.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Reminder] %WINDIR%\Creator\Remind_XP.exe
mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
mRun: [PivotSoftware] "c:\program files\winportrait\wpctrl.exe"
mRun: [P17Helper] Rundll32 P17.dll,P17Helper
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
dRun: [Power2GoExpress] NA
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
Trusted Zone: amaena.com
Trusted Zone: antispyexpert.com
Trusted Zone: avsystemcare.com
Trusted Zone: imageservr.com
Trusted Zone: imagesrvr.com
Trusted Zone: onerateld.com
Trusted Zone: safetydownload.com
Trusted Zone: spyguardpro.com
Trusted Zone: storageguardsoft.com
Trusted Zone: trustedantivirus.com
Trusted Zone: virusremover2008.com
Trusted Zone: virusschlacht.com
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} - hxxp://www.bebo.com/files/BeboUploader.5.1.4.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {297DE2B6-509A-4B36-93C5-A65276606900} - hxxp://www.in.honda.com/rraaapps/rraasec/codebase/RRAAINAX/RraainAX.CAB
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo2.walgreens.com/WalgreensActivia.cab
DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} - hxxp://www.servicehonda.com/TSWeb/msrdp.cab
DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://207.192.215.42/activex/AxisCamControl.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab
DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} - hxxp://www.shockwave.com/content/weddingdash/sis/WeddingDash.1.0.0.47.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
LSA: Notification Packages = scecli WMVSBPi.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\owner~1.kid\applic~1\mozilla\firefox\profiles\2wb7o8a2.default\
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\owner.kids\application data\mozilla\firefox\profiles\2wb7o8a2.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpClipBook.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpClipBookDB.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpNeoLogger.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSaturn.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSeymour.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSmartSelect.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSmartWebPrinting.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSWPOperation.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPLogging.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPMTC.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPMTL.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXREStub.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\owner.kids\application data\facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\owner.kids\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\plugins\nphpclipbook.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPcol305.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\spiralfrog\NPSFDMGR.dll
FF - plugin: c:\program files\spiralfrog\wmp\np-mswmp.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: XULRunner: {45182C5C-04E5-4C91-9C14-30001905AB2A} - c:\documents and settings\owner.kids\local settings\application data\{45182C5C-04E5-4C91-9C14-30001905AB2A}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

============= SERVICES / DRIVERS ===============

R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-5-9 24652]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-12-20 135664]

=============== Created Last 30 ================

2010-10-15 11:12:36 6084944 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\windows defender\definition updates\{bf01ef60-d790-47ef-a412-5d7fdfff732a}\mpengine.dll
2010-10-13 11:21:16 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-10-13 11:21:16 954368 -c----w- c:\windows\system32\dllcache\mfc40.dll
2010-10-13 11:21:16 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-13 11:21:09 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2010-09-25 03:20:14 -------- d-----w- c:\windows\pss

==================== Find3M ====================

2010-09-18 17:23:26 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53:25 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53:25 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53:25 953856 ------w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58:08 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58:06 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58:06 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:51:14 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02:29 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 12:52:45 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12:04 617472 ------w- c:\windows\system32\comctl32.dll
2010-08-17 13:17:06 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-20 00:56:23 53248 ----a-w- c:\windows\PalmDevC.dll
2010-04-20 02:47:07 818200 ----a-w- c:\program files\RealPlayerSPGold.exe
2010-01-27 02:40:40 18848592 ----a-w- c:\program files\LimeWireWin.exe
2009-11-05 23:14:38 25578557 ----a-w- c:\program files\Voobys.exe
2009-10-21 01:54:05 25740144 ----a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2009-10-15 11:36:16 1606064 ----a-w- c:\program files\googletalk-setup.exe
2009-09-04 22:19:12 27024112 ----a-w- c:\program files\PowerPointViewer.exe
2009-07-20 01:41:02 5877248 ----a-w- c:\program files\tistudycardscreator.exe
2009-05-23 05:18:30 4909440 ----a-w- c:\program files\Silverlight.2.0.exe
2009-03-22 03:21:19 16883056 ----a-w- c:\program files\IE8-WindowsXP-x86-ENU.exe
2008-12-27 13:14:02 5154304 ----a-w- c:\program files\WindowsDefender.msi
2008-09-03 21:44:19 486152 ----a-w- c:\program files\ChromeSetup.exe
2008-08-30 00:24:05 10509183 ----a-w- c:\program files\FreeMat-3.6_Setup.exe
2008-08-25 00:46:24 3252752 ----a-w- c:\program files\SansaUpdaterInstall.exe
2008-07-02 22:32:21 25813085 ----a-w- c:\program files\TWCSSSetup.exe
2008-05-29 20:11:30 136528 ----a-w- c:\program files\unagi_patch.exe
2008-05-29 19:17:51 13934776 ----a-w- c:\program files\Install_AIM.exe
2008-03-02 18:20:32 234592 ----a-w- c:\program files\SmileboxInstaller.exe
2008-01-03 02:21:49 2168976 ----a-w- c:\program files\mcsolitairesetup.exe
2007-10-31 22:31:17 1305088 ----a-w- c:\program files\Netflix_Movie_Viewer_Installer.msi
2007-05-06 19:46:47 2657486 ----a-w- c:\program files\Click2PosterSetup.exe
2007-04-13 11:25:35 14994152 ----a-w- c:\program files\GoogleEarthWin_EARV.exe
2007-03-01 02:19:09 288640 ----a-w- c:\program files\dxwebsetup.exe
2007-02-27 12:49:11 1568632 ----a-w- c:\program files\EZCD_Setup.exe
2007-02-27 12:23:29 14711997 ----a-w- c:\program files\mpeg-encoder-21713.exe
2007-02-13 01:05:46 19666504 ----a-w- c:\program files\QuickTimeInstaller.exe
2007-02-04 03:06:53 17357528 ----a-w- c:\program files\designer.exe
2007-02-02 02:58:41 14994392 ----a-w- c:\program files\GoogleEarthWin.exe
2006-09-01 16:27:08 90112 ----a-w- c:\program files\Unreal Anthology.exe
2006-08-21 18:32:17 643124 ----a-w- c:\program files\atomic.exe

============= FINISH: 9:43:49.68 ===============



BC AdBot (Login to Remove)

 


#2 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:06:38 PM

Posted 26 October 2010 - 06:22 PM

Hi,

Welcome to Bleeping Computer. My name is m0le and I will be helping you with your log.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Options box to the right of your topic title and selecting Track This Topic.

  • Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.

  • Please reply to this post so I know you are there.
The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then I will close the topic.

Once I receive a reply then I will return with your first instructions.

Thanks :thumbup2:
Posted Image
m0le is a proud member of UNITE

#3 surf

surf
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:38 PM

Posted 26 October 2010 - 08:36 PM

Thanks m0le !! I have done nothing since I posted. I await your command. I will be checking here at 2 pm Wed. cdt.

#4 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:06:38 PM

Posted 27 October 2010 - 04:38 PM

There's a number of things in the log that are malicious in nature.

Please run Combofix

Please download ComboFix from one of these locations:* IMPORTANT !!! Save ComboFix.exe to your Desktop making sure you rename it comfix.exe
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on Comfix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Posted Image
m0le is a proud member of UNITE

#5 surf

surf
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:38 PM

Posted 28 October 2010 - 09:48 AM

During this stage of ComboFix :

Rebooting Windows...Please Wait
Please allow ComboFix to reboot the machine.
Warning!! Do not manually reboot the machine yourself

This pop up happened:

ERUNT.cfxxe - Application Error
The istruction at "0x7c911689" referenced memory at "0x00000000".
The memory could not be "read". Click on OK to terminate the program

OK

I did not click OK, I only closed the box.


Here is the ComboFix log:

ComboFix 10-10-27.09 - Owner 10/28/2010 8:20.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1406.793 [GMT -5:00]
Running from: c:\documents and settings\Owner.Kids\Desktop\comfix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner.Kids\Local Settings\Application Data\{45182C5C-04E5-4C91-9C14-30001905AB2A}
c:\documents and settings\Owner.Kids\Local Settings\Application Data\{45182C5C-04E5-4C91-9C14-30001905AB2A}\chrome.manifest
c:\documents and settings\Owner.Kids\Local Settings\Application Data\{45182C5C-04E5-4C91-9C14-30001905AB2A}\chrome\content\_cfg.js
c:\documents and settings\Owner.Kids\Local Settings\Application Data\{45182C5C-04E5-4C91-9C14-30001905AB2A}\chrome\content\overlay.xul
c:\documents and settings\Owner.Kids\Local Settings\Application Data\{45182C5C-04E5-4C91-9C14-30001905AB2A}\install.rdf
c:\documents and settings\Owner.Kids\Recent\Thumbs.db
c:\program files\Shared
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.0.inf
c:\windows\settings.reg

Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\ERDNT\cache\winlogon.exe

Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\ERDNT\cache\explorer.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_usnjsvc


((((((((((((((((((((((((( Files Created from 2010-09-28 to 2010-10-28 )))))))))))))))))))))))))))))))
.

2010-10-15 11:12 . 2010-09-09 22:52 6084944 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{BF01EF60-D790-47EF-A412-5D7FDFFF732A}\mpengine.dll
2010-10-13 11:21 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-10-13 11:21 . 2010-09-18 06:53 954368 -c----w- c:\windows\system32\dllcache\mfc40.dll
2010-10-13 11:21 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-13 11:21 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 17:23 . 2005-01-09 23:48 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2005-01-09 23:48 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2005-01-09 23:48 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2005-01-09 23:48 953856 ------w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58 . 2005-01-09 23:48 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58 . 2005-01-09 23:48 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58 . 2005-01-09 23:48 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-09-09 22:52 . 2008-12-27 13:23 6084944 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2010-09-01 11:51 . 2005-01-09 23:47 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42 . 2005-01-09 23:48 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2005-01-09 23:48 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57 . 2005-01-09 23:48 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 13:39 . 2005-01-09 23:48 357248 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-26 12:52 . 2009-04-16 21:24 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12 . 2005-01-09 23:47 617472 ------w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2005-01-09 23:48 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2005-01-09 23:48 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-04-20 02:47 . 2010-03-13 21:06 818200 ----a-w- c:\program files\RealPlayerSPGold.exe
2010-01-27 02:40 . 2010-01-27 02:40 18848592 ----a-w- c:\program files\LimeWireWin.exe
2009-11-05 23:14 . 2009-11-05 23:14 25578557 ----a-w- c:\program files\Voobys.exe
2009-10-21 01:54 . 2008-06-05 19:07 25740144 ----a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2009-10-15 11:36 . 2006-11-15 21:25 1606064 ----a-w- c:\program files\googletalk-setup.exe
2009-09-04 22:19 . 2009-05-20 21:53 27024112 ----a-w- c:\program files\PowerPointViewer.exe
2009-07-20 01:41 . 2009-07-20 01:40 5877248 ----a-w- c:\program files\tistudycardscreator.exe
2009-05-23 05:18 . 2009-05-23 05:18 4909440 ----a-w- c:\program files\Silverlight.2.0.exe
2009-03-22 03:21 . 2009-03-22 03:21 16883056 ----a-w- c:\program files\IE8-WindowsXP-x86-ENU.exe
2008-12-27 13:14 . 2008-12-27 13:13 5154304 ----a-w- c:\program files\WindowsDefender.msi
2008-09-03 21:44 . 2008-09-03 21:44 486152 ----a-w- c:\program files\ChromeSetup.exe
2008-08-30 00:24 . 2008-08-30 00:23 10509183 ----a-w- c:\program files\FreeMat-3.6_Setup.exe
2008-08-25 00:46 . 2008-08-25 00:46 3252752 ----a-w- c:\program files\SansaUpdaterInstall.exe
2008-07-02 22:32 . 2008-07-02 22:32 25813085 ----a-w- c:\program files\TWCSSSetup.exe
2008-05-29 20:11 . 2008-05-29 20:11 136528 ----a-w- c:\program files\unagi_patch.exe
2008-05-29 19:17 . 2008-05-29 19:17 13934776 ----a-w- c:\program files\Install_AIM.exe
2008-03-02 18:20 . 2008-03-02 18:20 234592 ----a-w- c:\program files\SmileboxInstaller.exe
2008-01-03 02:21 . 2008-01-03 02:21 2168976 ----a-w- c:\program files\mcsolitairesetup.exe
2007-10-31 22:31 . 2007-10-31 22:28 1305088 ----a-w- c:\program files\Netflix_Movie_Viewer_Installer.msi
2007-05-06 19:46 . 2007-05-06 19:46 2657486 ----a-w- c:\program files\Click2PosterSetup.exe
2007-04-13 11:25 . 2007-04-13 11:25 14994152 ----a-w- c:\program files\GoogleEarthWin_EARV.exe
2007-03-01 02:19 . 2007-03-01 02:19 288640 ----a-w- c:\program files\dxwebsetup.exe
2007-02-27 12:49 . 2007-02-27 12:48 1568632 ----a-w- c:\program files\EZCD_Setup.exe
2007-02-27 12:23 . 2007-02-27 12:23 14711997 ----a-w- c:\program files\mpeg-encoder-21713.exe
2007-02-13 01:05 . 2007-02-13 01:05 19666504 ----a-w- c:\program files\QuickTimeInstaller.exe
2007-02-04 03:06 . 2007-02-04 03:06 17357528 ----a-w- c:\program files\designer.exe
2007-02-02 02:58 . 2007-02-02 02:58 14994392 ----a-w- c:\program files\GoogleEarthWin.exe
2006-09-01 16:27 . 2009-01-03 01:30 90112 ----a-w- c:\program files\Unreal Anthology.exe
2006-08-21 18:32 . 2006-08-21 18:32 643124 ----a-w- c:\program files\atomic.exe
2010-05-20 05:49 . 2010-05-20 05:49 58760 ----a-w- c:\program files\mozilla firefox\plugins\ateccli.dll
2010-05-20 05:49 . 2010-05-20 05:49 28472 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2010-05-20 05:49 . 2010-05-20 05:49 185224 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
2010-05-20 05:50 . 2010-05-20 05:49 99208 ----a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-27 68856]
"SansaDispatch"="c:\documents and settings\Owner.Kids\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe" [2009-05-22 79872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"CHotkey"="mHotkey.exe" [2004-12-09 550912]
"ledpointer"="CNYHKey.exe" [2004-03-03 5576704]
"showwnd"="showwnd.exe" [2003-09-19 36864]
"readericon"="c:\program files\Digital Media Reader\readericon45G.exe" [2005-12-10 139264]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-18 7204864]
"nwiz"="nwiz.exe" [2005-09-18 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-09-18 86016]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-02-26 966656]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"PivotSoftware"="c:\program files\WinPortrait\wpctrl.exe" [2005-01-26 698104]
"P17Helper"="P17.dll" [2005-05-03 64512]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-09-24 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-08-06 202256]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ WinCinema Manager.lnk
backup=c:\windows\pss\ WinCinema Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EzTune.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\EzTune.lnk
backup=c:\windows\pss\EzTune.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk
backup=c:\windows\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2010-03-18 16:19 207360 ----a-w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2006-12-06 03:55 54832 ----a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
2003-05-08 16:00 49152 ----a-w- c:\program files\ScanSoft\OmniPageSE2.0\opwareSE2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-01-05 22:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2006-11-23 20:10 56928 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpiralFrog]
2009-02-11 17:06 535864 ----a-w- c:\program files\SpiralFrog\Spiralfrog.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
2010-01-07 20:38 158448 ----a-w- c:\program files\Zune\ZuneLauncher.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"=

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [5/9/2008 6:08 PM 24652]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/20/2009 11:32 PM 135664]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-08-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]

2009-08-14 c:\windows\Tasks\At1.job
- c:\program files\norton pc checkup\pc_checkup.exe [2008-06-29 21:50]

2010-10-28 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-31 19:27]

2010-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb7011d8578d44.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-21 04:32]

2009-12-04 c:\windows\Tasks\Norton Security Scan for Owner.job
- c:\program files\Norton Security Scan\Norton Security Scan\Engine\2.3.0.44\Nss.exe [2009-07-17 20:01]

2010-10-28 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-351961390-340104498-4275350937-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 08:02]

2010-10-28 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-351961390-340104498-4275350937-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 08:02]

2010-07-03 c:\windows\Tasks\User_Feed_Synchronization-{6914C367-B0EA-45B8-9849-D9FFEBE6817F}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyServer = http=127.0.0.1:5577
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
Trusted Zone: amaena.com
Trusted Zone: antispyexpert.com
Trusted Zone: avsystemcare.com
Trusted Zone: imageservr.com
Trusted Zone: imagesrvr.com
Trusted Zone: onerateld.com
Trusted Zone: safetydownload.com
Trusted Zone: spyguardpro.com
Trusted Zone: storageguardsoft.com
Trusted Zone: trustedantivirus.com
Trusted Zone: virusremover2008.com
Trusted Zone: virusschlacht.com
DPF: {297DE2B6-509A-4B36-93C5-A65276606900} - hxxp://www.in.honda.com/rraaapps/rraasec/codebase/RRAAINAX/RraainAX.CAB
FF - ProfilePath - c:\documents and settings\Owner.Kids\Application Data\Mozilla\Firefox\Profiles\2wb7o8a2.default\
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\Owner.Kids\Application Data\Mozilla\Firefox\Profiles\2wb7o8a2.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSeymour.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\Owner.Kids\Application Data\Facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\Owner.Kids\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPcol305.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\SpiralFrog\NPSFDMGR.dll
FF - plugin: c:\program files\spiralfrog\wmp\np-mswmp.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-28 08:43
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
PivotSoftware = "c:\program files\WinPortrait\wpctrl.exe"??????????????w?????#??????X ??????????\ ?|???????|????????,E???????!??????????????????????????( ??????Service Pack 2?????????????????????????????????????????????????????????????????????????????????????????????????????
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
SansaDispatch = c:\documents and settings\Owner.Kids\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe?.lnk??VDDRZU[N~SRYC^CN?ARED^XY ?????????:=?????GEXTRDDXEvET_^CRTCBER ?o???:=?????YVZR ?dVYDVs^

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(724)
c:\windows\system32\WININET.dll
c:\program files\WinPortrait\WinpHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Gateway\EzTune\dtsslsrv.exe
c:\program files\Gateway\EzTune\dtsrvc.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\CNYHKey.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\Rundll32.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\WinPortrait\floater.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\ZuneBusEnum.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Zune\ZuneNss.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\dllhost.exe
c:\windows\eHome\ehmsas.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2010-10-28 08:52:20 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-28 13:52
ComboFix2.txt 2010-01-01 22:44

Pre-Run: 236,825,821,184 bytes free
Post-Run: 237,059,256,320 bytes free

- - End Of File - - 3FA760C2234642CB686DE3BB4E2E562E

#6 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:06:38 PM

Posted 28 October 2010 - 07:03 PM

One more run of Combofix please

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the box below into it:

File::
c:\windows\Tasks\At1.job

DDS::
uInternet Settings,ProxyServer = http=127.0.0.1:5577
Trusted Zone: amaena.com
Trusted Zone: antispyexpert.com
Trusted Zone: avsystemcare.com
Trusted Zone: imageservr.com
Trusted Zone: imagesrvr.com
Trusted Zone: onerateld.com
Trusted Zone: safetydownload.com
Trusted Zone: spyguardpro.com
Trusted Zone: storageguardsoft.com
Trusted Zone: trustedantivirus.com
Trusted Zone: virusremover2008.com
Trusted Zone: virusschlacht.com


Save this as CFScript.txt, in the same location as Comfix.exe (called ComboFix.exe in the below graphic)


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

If the program requests for you to update Combofix then click Yes.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Posted Image
m0le is a proud member of UNITE

#7 surf

surf
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:38 PM

Posted 31 October 2010 - 10:34 AM

I ran ComboFix with CFScript added. There were no incidents. I do not have AV and I think MalwareBytes Antimalware only runs on command. Have you seen anything different?
Here is ONE HALF OF THE log from the latest run. THE SECOND HALF WILL BE IN THE NEXT POST. I GOT A MESSAGE THAT THE POST WAS TOO LONG.
ComboFix 10-10-27.09 - Owner 10/30/2010 2:18.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1406.775 [GMT -5:00]
Running from: c:\documents and settings\Owner.Kids\Desktop\bleeping computer\comfix.exe
.

((((((((((((((((((((((((( Files Created from 2010-09-28 to 2010-10-30 )))))))))))))))))))))))))))))))
.

2010-10-15 11:12 . 2010-09-09 22:52 6084944 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{BF01EF60-D790-47EF-A412-5D7FDFFF732A}\mpengine.dll
2010-10-13 11:21 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-10-13 11:21 . 2010-09-18 06:53 954368 -c----w- c:\windows\system32\dllcache\mfc40.dll
2010-10-13 11:21 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-13 11:21 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 17:23 . 2005-01-09 23:48 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2005-01-09 23:48 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2005-01-09 23:48 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2005-01-09 23:48 953856 ------w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58 . 2005-01-09 23:48 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58 . 2005-01-09 23:48 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58 . 2005-01-09 23:48 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-09-09 22:52 . 2008-12-27 13:23 6084944 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2010-09-01 11:51 . 2005-01-09 23:47 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42 . 2005-01-09 23:48 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2005-01-09 23:48 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57 . 2005-01-09 23:48 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 13:39 . 2005-01-09 23:48 357248 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-26 12:52 . 2009-04-16 21:24 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12 . 2005-01-09 23:47 617472 ------w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2005-01-09 23:48 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2005-01-09 23:48 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-04-20 02:47 . 2010-03-13 21:06 818200 ----a-w- c:\program files\RealPlayerSPGold.exe
2010-01-27 02:40 . 2010-01-27 02:40 18848592 ----a-w- c:\program files\LimeWireWin.exe
2009-11-05 23:14 . 2009-11-05 23:14 25578557 ----a-w- c:\program files\Voobys.exe
2009-10-21 01:54 . 2008-06-05 19:07 25740144 ----a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2009-10-15 11:36 . 2006-11-15 21:25 1606064 ----a-w- c:\program files\googletalk-setup.exe
2009-09-04 22:19 . 2009-05-20 21:53 27024112 ----a-w- c:\program files\PowerPointViewer.exe
2009-07-20 01:41 . 2009-07-20 01:40 5877248 ----a-w- c:\program files\tistudycardscreator.exe
2009-05-23 05:18 . 2009-05-23 05:18 4909440 ----a-w- c:\program files\Silverlight.2.0.exe
2009-03-22 03:21 . 2009-03-22 03:21 16883056 ----a-w- c:\program files\IE8-WindowsXP-x86-ENU.exe
2008-12-27 13:14 . 2008-12-27 13:13 5154304 ----a-w- c:\program files\WindowsDefender.msi
2008-09-03 21:44 . 2008-09-03 21:44 486152 ----a-w- c:\program files\ChromeSetup.exe
2008-08-30 00:24 . 2008-08-30 00:23 10509183 ----a-w- c:\program files\FreeMat-3.6_Setup.exe
2008-08-25 00:46 . 2008-08-25 00:46 3252752 ----a-w- c:\program files\SansaUpdaterInstall.exe
2008-07-02 22:32 . 2008-07-02 22:32 25813085 ----a-w- c:\program files\TWCSSSetup.exe
2008-05-29 20:11 . 2008-05-29 20:11 136528 ----a-w- c:\program files\unagi_patch.exe
2008-05-29 19:17 . 2008-05-29 19:17 13934776 ----a-w- c:\program files\Install_AIM.exe
2008-03-02 18:20 . 2008-03-02 18:20 234592 ----a-w- c:\program files\SmileboxInstaller.exe
2008-01-03 02:21 . 2008-01-03 02:21 2168976 ----a-w- c:\program files\mcsolitairesetup.exe
2007-10-31 22:31 . 2007-10-31 22:28 1305088 ----a-w- c:\program files\Netflix_Movie_Viewer_Installer.msi
2007-05-06 19:46 . 2007-05-06 19:46 2657486 ----a-w- c:\program files\Click2PosterSetup.exe
2007-04-13 11:25 . 2007-04-13 11:25 14994152 ----a-w- c:\program files\GoogleEarthWin_EARV.exe
2007-03-01 02:19 . 2007-03-01 02:19 288640 ----a-w- c:\program files\dxwebsetup.exe
2007-02-27 12:49 . 2007-02-27 12:48 1568632 ----a-w- c:\program files\EZCD_Setup.exe
2007-02-27 12:23 . 2007-02-27 12:23 14711997 ----a-w- c:\program files\mpeg-encoder-21713.exe
2007-02-13 01:05 . 2007-02-13 01:05 19666504 ----a-w- c:\program files\QuickTimeInstaller.exe
2007-02-04 03:06 . 2007-02-04 03:06 17357528 ----a-w- c:\program files\designer.exe
2007-02-02 02:58 . 2007-02-02 02:58 14994392 ----a-w- c:\program files\GoogleEarthWin.exe
2006-09-01 16:27 . 2009-01-03 01:30 90112 ----a-w- c:\program files\Unreal Anthology.exe
2006-08-21 18:32 . 2006-08-21 18:32 643124 ----a-w- c:\program files\atomic.exe
2010-05-20 05:49 . 2010-05-20 05:49 58760 ----a-w- c:\program files\mozilla firefox\plugins\ateccli.dll
2010-05-20 05:49 . 2010-05-20 05:49 28472 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2010-05-20 05:49 . 2010-05-20 05:49 185224 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
2010-05-20 05:50 . 2010-05-20 05:49 99208 ----a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-01-01_22.39.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-22 02:46 . 2009-05-22 02:46 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2009-05-22 02:46 . 2009-05-22 02:46 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2009-05-22 02:46 . 2009-05-22 02:46 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2009-05-22 02:46 . 2009-05-22 02:46 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2009-05-22 02:46 . 2009-05-22 02:46 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2009-05-22 02:46 . 2009-05-22 02:46 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2009-05-22 02:46 . 2009-05-22 02:46 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2009-05-22 02:46 . 2009-05-22 02:46 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2009-05-22 02:46 . 2009-05-22 02:46 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2009-05-22 02:46 . 2009-05-22 02:46 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2009-05-22 02:46 . 2009-05-22 02:46 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2010-10-30 01:32 . 2010-10-30 01:32 16384 c:\windows\Temp\Perflib_Perfdata_618.dat
+ 2009-09-02 06:29 . 2010-01-07 20:22 74240 c:\windows\system32\ZuneUsbTransport.dll
- 2009-09-02 06:29 . 2009-09-02 06:29 74240 c:\windows\system32\ZuneUsbTransport.dll
+ 2009-09-02 06:29 . 2010-01-07 20:22 18944 c:\windows\system32\ZuneTcp2Udp.dll
- 2009-09-02 06:29 . 2009-09-02 06:29 18944 c:\windows\system32\ZuneTcp2Udp.dll
+ 2009-09-02 06:29 . 2010-01-07 20:22 57344 c:\windows\system32\ZuneRegUtil.dll
- 2009-09-02 06:29 . 2009-09-02 06:29 57344 c:\windows\system32\ZuneRegUtil.dll
- 2009-09-02 06:29 . 2009-09-02 06:29 12800 c:\windows\system32\ZunePTDNS.dll
+ 2009-09-02 06:29 . 2010-01-07 20:22 12800 c:\windows\system32\ZunePTDNS.dll
- 2009-09-04 19:16 . 2009-09-04 19:16 58592 c:\windows\system32\ZuneBusEnum.exe
+ 2010-01-07 20:38 . 2010-01-07 20:38 58592 c:\windows\system32\ZuneBusEnum.exe
+ 2004-06-09 19:27 . 2004-06-09 19:27 53248 c:\windows\system32\USBPort.dll
+ 2007-01-29 08:58 . 2010-06-21 14:46 46080 c:\windows\system32\tzchange.exe
- 2007-01-29 08:58 . 2009-10-28 15:07 46080 c:\windows\system32\tzchange.exe
- 2005-01-10 01:27 . 2009-01-08 00:21 26144 c:\windows\system32\spupdsvc.exe
+ 2005-01-10 01:27 . 2009-01-07 23:21 26144 c:\windows\system32\spupdsvc.exe
+ 2009-10-21 01:56 . 2009-01-07 23:20 16928 c:\windows\system32\spmsg.dll
- 2009-10-21 01:56 . 2009-01-08 00:20 16928 c:\windows\system32\spmsg.dll
+ 2010-03-10 05:08 . 2009-09-02 06:28 40832 c:\windows\system32\ReinstallBackups\0013\DriverFiles\zumbus.sys
+ 2010-03-31 05:16 . 2010-03-31 05:16 99176 c:\windows\system32\PresentationHostProxy.dll
+ 2005-01-09 23:48 . 2009-03-08 09:31 46592 c:\windows\system32\pngfilt.dll
+ 2005-01-09 23:48 . 2010-10-05 12:33 72530 c:\windows\system32\perfc009.dat
+ 2004-06-09 19:27 . 2004-06-09 19:27 53248 c:\windows\system32\PalmDevC.dll
- 2006-06-29 14:05 . 2009-01-08 00:20 23552 c:\windows\system32\normaliz.dll
+ 2006-06-29 14:05 . 2009-01-07 23:20 23552 c:\windows\system32\normaliz.dll
+ 2006-06-28 23:59 . 2009-01-07 23:20 24576 c:\windows\system32\nlsdl.dll
- 2006-06-28 23:59 . 2009-01-08 00:20 24576 c:\windows\system32\nlsdl.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 49488 c:\windows\system32\netfxperf.dll
+ 2009-11-06 03:17 . 2009-11-06 03:17 11600 c:\windows\system32\mui\0409\mscorees.dll
+ 2004-08-04 07:56 . 2009-11-27 17:11 17920 c:\windows\system32\msyuv.dll
+ 2007-02-04 01:00 . 2001-08-18 04:43 24576 c:\windows\system32\msxml3a.dll
+ 2005-01-09 23:48 . 2009-11-27 16:07 28672 c:\windows\system32\msvidc32.dll
+ 2005-01-09 23:48 . 2009-11-27 16:07 11264 c:\windows\system32\msrle32.dll
- 2005-01-09 23:48 . 2008-04-14 00:12 11264 c:\windows\system32\msrle32.dll
+ 2005-01-09 23:48 . 2009-03-08 09:31 48128 c:\windows\system32\mshtmler.dll
- 2005-01-09 23:48 . 2006-10-17 17:28 48128 c:\windows\system32\mshtmler.dll
+ 2005-01-09 23:48 . 2010-09-10 05:58 66560 c:\windows\system32\mshtmled.dll
- 2005-01-09 23:48 . 2006-10-17 17:56 45568 c:\windows\system32\mshta.exe
+ 2005-01-09 23:48 . 2009-03-08 09:31 45568 c:\windows\system32\mshta.exe
+ 2006-10-17 17:58 . 2009-03-08 09:31 13312 c:\windows\system32\msfeedssync.exe
+ 2006-11-08 03:03 . 2010-09-10 05:58 55296 c:\windows\system32\msfeedsbs.dll
+ 2005-01-09 23:48 . 2010-09-10 05:58 25600 c:\windows\system32\jsproxy.dll
+ 2004-08-04 07:56 . 2009-11-27 16:07 48128 c:\windows\system32\iyuv_32.dll
+ 2005-01-09 23:48 . 2009-03-08 09:32 94720 c:\windows\system32\inseng.dll
+ 2005-01-09 23:48 . 2009-03-08 09:31 34816 c:\windows\system32\imgutil.dll
- 2006-11-07 09:26 . 2009-03-08 10:32 36864 c:\windows\system32\ieudinit.exe
+ 2006-11-07 09:26 . 2009-03-08 09:32 36864 c:\windows\system32\ieudinit.exe
+ 2005-01-09 23:48 . 2009-03-08 09:32 71680 c:\windows\system32\iesetup.dll
+ 2005-01-09 23:48 . 2009-03-08 09:32 55808 c:\windows\system32\iernonce.dll
+ 2006-06-29 14:05 . 2009-01-07 23:20 26112 c:\windows\system32\idndl.dll
- 2006-06-29 14:05 . 2009-01-08 00:20 26112 c:\windows\system32\idndl.dll
+ 2005-01-09 23:48 . 2010-06-17 14:03 80384 c:\windows\system32\iccvid.dll
- 2005-01-09 23:48 . 2008-04-14 00:11 80384 c:\windows\system32\iccvid.dll
+ 2006-10-17 17:58 . 2009-03-08 09:31 59904 c:\windows\system32\icardie.dll
+ 2008-12-04 01:05 . 2008-12-04 01:05 20480 c:\windows\system32\hpzisn12.dll
+ 2008-12-04 01:05 . 2008-12-04 01:05 29696 c:\windows\system32\hpzipt12.dll
+ 2008-12-04 01:05 . 2008-12-04 01:05 33792 c:\windows\system32\HPZipr12.dll
+ 2008-12-04 01:05 . 2008-12-04 01:05 53760 c:\windows\system32\HPZipm12.dll
+ 2008-12-04 01:05 . 2008-12-04 01:05 44544 c:\windows\system32\HPZinw12.dll
+ 2008-12-04 01:05 . 2008-12-04 01:05 49152 c:\windows\system32\HPZidr12.dll
+ 2008-03-05 02:44 . 2008-03-05 02:44 39936 c:\windows\system32\hpbpro.dll
+ 2008-03-05 02:45 . 2008-03-05 02:45 25600 c:\windows\system32\hpboid.dll
+ 2008-03-05 02:44 . 2008-03-05 02:44 24576 c:\windows\system32\hpbmiapi.dll
+ 2005-01-09 23:48 . 2009-10-15 16:28 81920 c:\windows\system32\fontsub.dll
- 2005-01-09 23:48 . 2009-06-16 14:36 81920 c:\windows\system32\fontsub.dll
+ 2010-08-17 01:57 . 2008-10-28 10:27 16800 c:\windows\system32\DRVSTORE\hpzius13_D627171118186196E509949900C5F44341391758\drivers\dot4\WinxP\Hppaufd0.sys
+ 2010-08-17 01:57 . 2008-10-28 10:27 21568 c:\windows\system32\DRVSTORE\hpzius13_D627171118186196E509949900C5F44341391758\drivers\dot4\Win2000\HPZius12.sys
+ 2010-08-17 01:57 . 2008-10-28 10:27 16496 c:\windows\system32\DRVSTORE\hpzius13_D627171118186196E509949900C5F44341391758\drivers\dot4\Win2000\hpzipr12.sys
+ 2010-08-17 01:57 . 2008-10-28 10:27 49920 c:\windows\system32\DRVSTORE\hpzius13_D627171118186196E509949900C5F44341391758\drivers\dot4\Win2000\hpzid412.sys
+ 2010-08-17 01:57 . 2008-10-28 10:27 16496 c:\windows\system32\DRVSTORE\hpzipr13_D715F6098FA1E1AAA844100179F2F11B7BC72ABF\drivers\dot4\Win2000\HPZipr12.sys
+ 2010-08-17 01:57 . 2008-10-28 10:27 21568 c:\windows\system32\DRVSTORE\hpzipa13_C7C260442B1351522D77732EB0D2429A413CE56A\drivers\dot4\Win2000\HPZius12.sys
+ 2010-08-17 01:57 . 2008-10-28 10:27 16496 c:\windows\system32\DRVSTORE\hpzipa13_C7C260442B1351522D77732EB0D2429A413CE56A\drivers\dot4\Win2000\HPzipr12.sys
+ 2010-08-17 01:57 . 2008-10-28 10:27 49920 c:\windows\system32\DRVSTORE\hpzipa13_C7C260442B1351522D77732EB0D2429A413CE56A\drivers\dot4\Win2000\HPZid412.sys
+ 2010-08-17 01:57 . 2008-10-28 10:27 49920 c:\windows\system32\DRVSTORE\hpzid413_C0168545C52E0D1050765D2C107AF090EAEC0A96\drivers\dot4\Win2000\HPZid412.sys
- 2009-09-02 06:28 . 2009-09-02 06:28 40832 c:\windows\system32\drivers\zumbus.sys
+ 2009-09-02 06:28 . 2010-01-07 20:22 40832 c:\windows\system32\drivers\zumbus.sys
+ 2004-06-09 19:27 . 2010-07-20 00:56 16694 c:\windows\system32\drivers\PalmUSBD.sys
+ 2008-12-25 16:02 . 2010-04-29 20:39 38224 c:\windows\system32\drivers\mbamswissarmy.sys
- 2008-12-25 16:02 . 2009-12-03 22:14 38224 c:\windows\system32\drivers\mbamswissarmy.sys
+ 2008-12-25 16:02 . 2010-04-29 20:39 20952 c:\windows\system32\drivers\mbam.sys
+ 2010-08-17 02:06 . 2008-10-28 10:27 21568 c:\windows\system32\drivers\HPZius12.sys
+ 2010-08-17 02:06 . 2008-10-28 10:27 16496 c:\windows\system32\drivers\HPZipr12.sys
+ 2010-08-17 02:06 . 2008-10-28 10:27 49920 c:\windows\system32\drivers\HPZid412.sys
- 2009-06-11 12:21 . 2009-10-29 07:45 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2009-06-11 12:21 . 2010-09-10 05:58 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2010-08-27 05:57 . 2010-08-27 05:57 99840 c:\windows\system32\dllcache\srvsvc.dll
+ 2010-08-17 13:17 . 2010-08-17 13:17 58880 c:\windows\system32\dllcache\spoolsv.exe
+ 2006-06-23 11:25 . 2009-03-08 09:31 46592 c:\windows\system32\dllcache\pngfilt.dll
+ 2009-11-27 17:11 . 2009-11-27 17:11 17920 c:\windows\system32\dllcache\msyuv.dll
+ 2009-11-27 16:07 . 2009-11-27 16:07 28672 c:\windows\system32\dllcache\msvidc32.dll
+ 2009-11-27 16:07 . 2009-11-27 16:07 11264 c:\windows\system32\dllcache\msrle32.dll
+ 2006-10-17 17:28 . 2009-03-08 09:31 48128 c:\windows\system32\dllcache\mshtmler.dll
- 2006-10-17 17:28 . 2006-10-17 17:28 48128 c:\windows\system32\dllcache\mshtmler.dll
+ 2006-06-23 11:25 . 2010-09-10 05:58 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2006-10-17 17:56 . 2006-10-17 17:56 45568 c:\windows\system32\dllcache\mshta.exe
+ 2006-10-17 17:56 . 2009-03-08 09:31 45568 c:\windows\system32\dllcache\mshta.exe
+ 2007-05-09 10:29 . 2010-09-10 05:58 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2006-10-17 18:05 . 2010-09-10 05:58 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2006-06-23 11:25 . 2010-09-10 05:58 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-11-27 16:07 . 2009-11-27 16:07 48128 c:\windows\system32\dllcache\iyuv_32.dll
+ 2006-06-23 11:25 . 2009-03-08 09:32 94720 c:\windows\system32\dllcache\inseng.dll
+ 2006-10-17 17:57 . 2009-03-08 09:31 34816 c:\windows\system32\dllcache\imgutil.dll
+ 2006-11-07 09:26 . 2009-03-08 09:32 71680 c:\windows\system32\dllcache\iesetup.dll
+ 2006-11-07 09:26 . 2009-03-08 09:32 55808 c:\windows\system32\dllcache\iernonce.dll
+ 2007-08-20 10:04 . 2009-03-08 09:31 59904 c:\windows\system32\dllcache\icardie.dll
+ 2006-10-17 17:44 . 2009-03-08 09:24 68608 c:\windows\system32\dllcache\hmmapi.dll
- 2009-06-16 14:36 . 2009-06-16 14:36 81920 c:\windows\system32\dllcache\fontsub.dll
+ 2009-06-16 14:36 . 2009-10-15 16:28 81920 c:\windows\system32\dllcache\fontsub.dll
+ 2009-12-14 07:08 . 2009-12-14 07:08 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2009-03-08 09:33 . 2009-03-08 09:33 18944 c:\windows\system32\dllcache\corpol.dll
- 2009-03-08 10:33 . 2009-03-08 10:33 18944 c:\windows\system32\dllcache\corpol.dll
+ 2010-01-13 14:01 . 2010-01-13 14:01 86016 c:\windows\system32\dllcache\cabview.dll
- 2009-06-10 14:13 . 2009-06-10 14:13 84992 c:\windows\system32\dllcache\avifil32.dll
+ 2009-06-10 14:13 . 2009-11-27 16:07 84992 c:\windows\system32\dllcache\avifil32.dll
+ 2010-03-05 14:37 . 2010-03-05 14:37 65536 c:\windows\system32\dllcache\asycfilt.dll
+ 2006-11-07 09:26 . 2009-03-08 09:32 72704 c:\windows\system32\dllcache\admparse.dll
+ 2005-01-09 23:47 . 2009-12-14 07:08 33280 c:\windows\system32\csrsrv.dll
+ 2005-01-09 23:47 . 2009-03-08 09:33 18944 c:\windows\system32\corpol.dll
+ 2005-01-09 23:47 . 2010-01-13 14:01 86016 c:\windows\system32\cabview.dll
- 2005-01-09 23:47 . 2009-06-10 14:13 84992 c:\windows\system32\avifil32.dll
+ 2005-01-09 23:47 . 2009-11-27 16:07 84992 c:\windows\system32\avifil32.dll
+ 2005-01-09 23:47 . 2010-03-05 14:37 65536 c:\windows\system32\asycfilt.dll
+ 2010-10-28 12:22 . 2010-10-28 12:22 87717 c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
+ 2010-09-23 13:13 . 2010-09-23 13:13 94208 c:\windows\system32\Adobe\Shockwave 11\SwMenu.dll
- 2008-08-24 02:13 . 2008-12-06 04:51 94208 c:\windows\system32\Adobe\Shockwave 11\SwMenu.dll
+ 2010-09-20 12:56 . 2010-09-20 12:56 79488 c:\windows\system32\Adobe\Shockwave 11\gtapi.dll
+ 2010-09-23 13:21 . 2010-09-23 13:21 65816 c:\windows\system32\Adobe\Director\SwDnld.exe
+ 2005-01-09 23:47 . 2009-03-08 09:32 72704 c:\windows\system32\admparse.dll
+ 2010-07-20 00:59 . 2010-07-20 00:56 53248 c:\windows\PalmDevC.dll
- 2008-07-30 00:16 . 2008-07-30 00:16 32768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
+ 2010-04-08 04:48 . 2010-04-08 04:48 32768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 13648 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
+ 2010-09-22 14:43 . 2010-09-22 14:43 30544 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2010-09-23 20:55 . 2010-09-23 20:55 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
- 2008-05-28 05:49 . 2008-05-28 05:49 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2010-09-23 07:26 . 2010-09-23 07:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2010-09-23 07:26 . 2010-09-23 07:26 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2008-05-28 05:49 . 2008-05-28 05:49 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2010-09-23 07:26 . 2010-09-23 07:26 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2008-05-28 05:49 . 2008-05-28 05:49 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2008-05-28 06:30 . 2008-05-28 06:30 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2010-09-23 08:17 . 2010-09-23 08:17 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2003-02-21 10:19 . 2003-02-21 10:19 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2010-09-23 08:17 . 2010-09-23 08:17 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2005-01-10 01:06 . 2010-02-09 23:22 81920 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Security.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 13648 c:\windows\Microsoft.NET\Framework\SharedReg12.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 13648 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 13648 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 13648 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 13664 c:\windows\Microsoft.NET\Framework\sbs_wminet_utils.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 13688 c:\windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 13664 c:\windows\Microsoft.NET\Framework\sbs_system.data.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 13696 c:\windows\Microsoft.NET\Framework\sbs_system.configuration.install.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 13656 c:\windows\Microsoft.NET\Framework\sbs_mscorsec.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 13656 c:\windows\Microsoft.NET\Framework\sbs_mscorrc.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 13656 c:\windows\Microsoft.NET\Framework\sbs_mscordbi.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 13672 c:\windows\Microsoft.NET\Framework\sbs_microsoft.jscript.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 13664 c:\windows\Microsoft.NET\Framework\sbs_diasymreader.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 86864 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
+ 2010-10-20 04:47 . 2010-10-20 04:47 21504 c:\windows\Installer\bf4df.msi
+ 2010-08-17 01:58 . 2010-08-17 01:58 65536 c:\windows\Installer\60cfc5.msi
+ 2010-03-10 05:09 . 2010-03-10 05:09 28160 c:\windows\Installer\1aa7a44.msi
+ 2010-03-10 05:09 . 2010-03-10 05:09 28160 c:\windows\Installer\1aa7a3e.msi
+ 2010-03-10 05:09 . 2010-03-10 05:09 28160 c:\windows\Installer\1aa7a38.msi
+ 2010-03-10 05:09 . 2010-03-10 05:09 28160 c:\windows\Installer\1aa7a24.msi
+ 2010-08-06 17:26 . 2010-08-06 17:26 20480 c:\windows\Installer\15ac044.msi
+ 2010-05-15 20:20 . 2010-05-15 20:20 25214 c:\windows\Installer\{F7B0939E-58DF-11DF-B3A6-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 65536 c:\windows\Installer\{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}\NewShortcut1.A6CC6977_F7B4_4C0B_9510_BCD847D4BDB2.exe
- 2009-10-19 02:19 . 2009-10-19 02:19 49936 c:\windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe
+ 2010-06-10 05:59 . 2010-06-10 05:59 49936 c:\windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe
+ 2009-08-20 23:50 . 2010-10-13 12:54 40960 c:\windows\Installer\{90850409-6000-11D3-8CFE-0150048383C9}\wrdvicon.exe
- 2009-08-20 23:50 . 2009-12-19 07:13 40960 c:\windows\Installer\{90850409-6000-11D3-8CFE-0150048383C9}\wrdvicon.exe
+ 2010-06-04 06:12 . 2010-09-30 05:32 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2010-01-04 15:29 . 2010-01-04 15:29 29926 c:\windows\Installer\{571700F0-DB9D-4B3A-B03D-35A14BB5939F}\MsblIco.Exe
- 2007-04-01 18:01 . 2007-04-01 18:01 29926 c:\windows\Installer\{571700F0-DB9D-4B3A-B03D-35A14BB5939F}\MsblIco.Exe
+ 2010-09-30 11:15 . 2010-09-30 11:15 25214 c:\windows\Installer\{4286E640-B5FB-11DF-AC4B-005056C00008}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
+ 2010-09-30 11:15 . 2010-09-30 11:15 25214 c:\windows\Installer\{4286E640-B5FB-11DF-AC4B-005056C00008}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2010-09-30 11:15 . 2010-09-30 11:15 25214 c:\windows\Installer\{4286E640-B5FB-11DF-AC4B-005056C00008}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2010-09-30 11:15 . 2010-09-30 11:15 25214 c:\windows\Installer\{4286E640-B5FB-11DF-AC4B-005056C00008}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2010-09-30 11:15 . 2010-09-30 11:15 25214 c:\windows\Installer\{4286E640-B5FB-11DF-AC4B-005056C00008}\googleearth.exe1_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2010-09-30 11:15 . 2010-09-30 11:15 25214 c:\windows\Installer\{4286E640-B5FB-11DF-AC4B-005056C00008}\googleearth.exe_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2010-09-30 11:15 . 2010-09-30 11:15 25214 c:\windows\Installer\{4286E640-B5FB-11DF-AC4B-005056C00008}\ARPPRODUCTICON.exe
+ 2010-02-06 20:41 . 2010-02-06 20:41 25214 c:\windows\Installer\{2EAF7E61-068E-11DF-953C-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
+ 2010-04-10 21:51 . 2010-04-10 21:51 25214 c:\windows\Installer\{08C0729E-3E50-11DF-9D81-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut9.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut8.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut7.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut6.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut5.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut4.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut3.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut23.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut22.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut21.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut20.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut2.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut19.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut18.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut17.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut16.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut15.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut14.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut13.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut12.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut11.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut10.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2010-08-17 01:59 . 2010-08-17 01:59 91707 c:\windows\Installer\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}\NewShortcut1.8A4F6A3E_5FDC_4E68_953F_2A8D5A684B79.exe
+ 2009-12-18 10:05 . 2009-12-18 10:05 16832 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\ViewerPS.dll
+ 2009-12-18 13:58 . 2009-12-18 13:58 40368 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\reader_sl.exe
+ 2009-12-18 10:05 . 2009-12-18 10:05 67016 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\PDFPrevHndlrShim.exe
+ 2009-12-18 10:04 . 2009-12-18 10:04 83376 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\PDFPrevHndlr.dll
+ 2009-12-18 07:43 . 2009-12-18 07:43 95672 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\nppdf32.dll
+ 2009-12-18 07:57 . 2009-12-18 07:57 13752 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\AcroRd32Info.exe
+ 2009-12-18 07:16 . 2009-12-18 07:16 65536 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\Acrofx32.dll
+ 2010-06-10 05:59 . 2010-02-25 06:24 12800 c:\windows\ie8updates\KB982381-IE8\xpshims.dll
+ 2010-06-10 05:59 . 2010-02-25 06:24 55296 c:\windows\ie8updates\KB982381-IE8\msfeedsbs.dll
+ 2010-06-10 05:59 . 2010-02-25 06:24 25600 c:\windows\ie8updates\KB982381-IE8\jsproxy.dll
+ 2010-05-18 18:46 . 2009-05-26 11:40 17272 c:\windows\ie8updates\KB981332-IE8\spmsg.dll
+ 2010-05-18 18:46 . 2009-05-26 11:40 26488 c:\windows\ie8updates\KB981332-IE8\spcustom.dll
+ 2010-05-18 18:46 . 2009-03-08 09:33 12288 c:\windows\ie8updates\KB980182-IE8\xpshims.dll
+ 2010-05-18 18:46 . 2009-05-26 11:40 17272 c:\windows\ie8updates\KB980182-IE8\spmsg.dll
+ 2010-05-18 18:46 . 2009-05-26 11:40 26488 c:\windows\ie8updates\KB980182-IE8\spcustom.dll
+ 2010-05-18 18:46 . 2009-03-08 09:31 55296 c:\windows\ie8updates\KB980182-IE8\msfeedsbs.dll
+ 2010-05-18 18:46 . 2009-03-08 09:33 25600 c:\windows\ie8updates\KB980182-IE8\jsproxy.dll
+ 2010-05-18 18:46 . 2008-07-08 13:02 17272 c:\windows\ie8updates\KB976662-IE8\spmsg.dll
+ 2010-05-18 18:46 . 2008-07-08 13:02 26488 c:\windows\ie8updates\KB976662-IE8\spcustom.dll
+ 2010-05-18 18:45 . 2008-07-08 13:02 17272 c:\windows\ie8updates\KB971961-IE8\spmsg.dll
+ 2010-05-18 18:45 . 2008-07-08 13:02 26488 c:\windows\ie8updates\KB971961-IE8\spcustom.dll
+ 2010-10-13 12:54 . 2010-06-24 12:22 12800 c:\windows\ie8updates\KB2360131-IE8\xpshims.dll
+ 2010-10-13 12:54 . 2009-03-08 09:31 66560 c:\windows\ie8updates\KB2360131-IE8\mshtmled.dll
+ 2010-10-13 12:54 . 2010-06-24 12:21 55296 c:\windows\ie8updates\KB2360131-IE8\msfeedsbs.dll
+ 2010-10-13 12:54 . 2009-03-08 09:34 43008 c:\windows\ie8updates\KB2360131-IE8\licmgr10.dll
+ 2010-10-13 12:54 . 2010-06-24 12:21 25600 c:\windows\ie8updates\KB2360131-IE8\jsproxy.dll
+ 2010-08-12 06:09 . 2010-05-06 10:41 12800 c:\windows\ie8updates\KB2183461-IE8\xpshims.dll
+ 2010-08-12 06:09 . 2010-05-06 10:41 55296 c:\windows\ie8updates\KB2183461-IE8\msfeedsbs.dll
+ 2010-08-12 06:09 . 2010-05-06 10:41 25600 c:\windows\ie8updates\KB2183461-IE8\jsproxy.dll
+ 2010-05-18 11:54 . 2009-03-08 19:23 58464 c:\windows\ie8\spuninst\iecustom.dll
- 2010-01-01 22:15 . 2009-03-08 20:23 58464 c:\windows\ie8\spuninst\iecustom.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 44544 c:\windows\ie8\pngfilt.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 44544 c:\windows\ie8\pngfilt.dll
+ 2010-05-18 11:53 . 2006-10-17 17:28 48128 c:\windows\ie8\mshtmler.dll
- 2010-01-01 22:14 . 2006-10-17 17:28 48128 c:\windows\ie8\mshtmler.dll
+ 2010-05-18 11:53 . 2006-10-17 17:56 45568 c:\windows\ie8\mshta.exe
- 2010-01-01 22:14 . 2006-10-17 17:56 45568 c:\windows\ie8\mshta.exe
+ 2010-05-18 11:53 . 2006-10-17 17:58 12288 c:\windows\ie8\msfeedssync.exe
- 2010-01-01 22:14 . 2006-10-17 17:58 12288 c:\windows\ie8\msfeedssync.exe
+ 2010-05-18 11:53 . 2009-02-20 18:09 52224 c:\windows\ie8\msfeedsbs.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 52224 c:\windows\ie8\msfeedsbs.dll
- 2010-01-01 22:14 . 2006-10-17 18:05 40960 c:\windows\ie8\licmgr10.dll
+ 2010-05-18 11:53 . 2006-10-17 18:05 40960 c:\windows\ie8\licmgr10.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 27648 c:\windows\ie8\jsproxy.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 27648 c:\windows\ie8\jsproxy.dll
+ 2010-05-18 11:53 . 2006-11-07 09:26 92672 c:\windows\ie8\inseng.dll
- 2010-01-01 22:14 . 2006-11-07 09:26 92672 c:\windows\ie8\inseng.dll
- 2010-01-01 22:14 . 2006-10-17 17:57 36352 c:\windows\ie8\imgutil.dll
+ 2010-05-18 11:53 . 2006-10-17 17:57 36352 c:\windows\ie8\imgutil.dll
- 2010-01-01 22:14 . 2006-11-07 09:26 55296 c:\windows\ie8\iesetup.dll
+ 2010-05-18 11:53 . 2006-11-07 09:26 55296 c:\windows\ie8\iesetup.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 44544 c:\windows\ie8\iernonce.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 44544 c:\windows\ie8\iernonce.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 78336 c:\windows\ie8\ieencode.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 78336 c:\windows\ie8\ieencode.dll
+ 2010-05-18 11:53 . 2009-02-20 10:20 70656 c:\windows\ie8\ie4uinit.exe
- 2010-01-01 22:14 . 2009-02-20 10:20 70656 c:\windows\ie8\ie4uinit.exe
- 2010-01-01 22:14 . 2009-02-20 18:09 63488 c:\windows\ie8\icardie.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 63488 c:\windows\ie8\icardie.dll
- 2010-01-01 22:14 . 2006-10-17 17:44 60416 c:\windows\ie8\hmmapi.dll
+ 2010-05-18 11:53 . 2006-10-17 17:44 60416 c:\windows\ie8\hmmapi.dll
+ 2010-05-18 11:53 . 2008-04-14 00:11 35328 c:\windows\ie8\corpol.dll
- 2010-01-01 22:14 . 2008-04-14 00:11 35328 c:\windows\ie8\corpol.dll
+ 2010-05-18 11:53 . 2006-11-07 09:26 71680 c:\windows\ie8\admparse.dll
- 2010-01-01 22:14 . 2006-11-07 09:26 71680 c:\windows\ie8\admparse.dll
+ 2009-01-03 01:30 . 2009-11-27 17:11 17920 c:\windows\Driver Cache\i386\msyuv.dll
+ 2009-11-27 16:07 . 2009-11-27 16:07 48128 c:\windows\Driver Cache\i386\iyuv_32.dll
+ 2010-10-05 12:30 . 2010-10-05 12:30 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_ee13397b\System.Drawing.Design.dll
+ 2010-10-05 12:30 . 2010-10-05 12:30 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_e80a5fde\CustomMarshalers.dll
+ 2010-08-12 11:18 . 2010-08-12 11:18 45056 c:\windows\assembly\NativeImages_v2.0.50727_32\UIXControls\3ea519b3a3209ad007996d0106fd5677\UIXControls.ni.dll
+ 2010-08-12 10:43 . 2010-08-12 10:43 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\5ec9dec678303ebff0ef018edb5ec595\UIAutomationProvider.ni.dll
+ 2010-08-12 11:18 . 2010-08-12 11:18 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\46ef15b88ef577de4882c519329fc5d2\System.Windows.Presentation.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\70ee6267f7bad40e8707d402277770c3\System.Web.DynamicData.Design.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\2b5ff2c6358c483eb1439b99badb54fd\System.ComponentModel.DataAnnotations.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\6125ff5a4fcd93d70a246cbff3005d42\System.AddIn.Contract.ni.dll
+ 2010-08-12 06:13 . 2010-08-12 06:13 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\de26af01222270c121788161496fcfe7\PresentationFontCache.ni.exe
+ 2010-08-12 06:13 . 2010-08-12 06:13 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\3c5adeedb70e6e052a6556c6ab9b6918\PresentationCFFRasterizer.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\5e5176efbfeb803b7f217525beec6844\Microsoft.Vsa.ni.dll
+ 2010-08-12 11:18 . 2010-08-12 11:18 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\272d51526813ea113970b8e890c92ee2\Microsoft.VisualC.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e1d4e0b1f112000ab33bbaf88bd9ed99\Microsoft.Build.Framework.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\4200cf5b7f247ec1b997808c6d1ba7d1\Microsoft.Build.Framework.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\50b7fc7f36c76313cbb434b10923e4e9\dfsvc.ni.exe
+ 2010-08-12 11:15 . 2010-08-12 11:15 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\5ffa548547613dbc5a92f2c5b7cad196\Accessibility.ni.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2010-06-10 05:54 . 2010-06-10 05:54 32768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
- 2009-05-10 00:51 . 2009-05-10 00:51 32768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2010-10-05 12:30 . 2010-10-05 12:30 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2010-06-10 06:02 . 2010-06-10 06:02 81920 c:\windows\assembly\GAC\System.Security\1.0.3300.0__b03f5f7f11d50a3a\System.Security.dll
- 2009-09-20 19:13 . 2009-12-05 00:37 49152 c:\windows\.jagex_cache_32\runescape\jagmisc.dll
+ 2009-09-20 19:13 . 2010-04-01 21:43 49152 c:\windows\.jagex_cache_32\runescape\jagmisc.dll
+ 2009-09-20 19:12 . 2010-04-01 21:43 94208 c:\windows\.jagex_cache_32\runescape\jaggl.dll
+ 2010-08-12 06:07 . 2008-04-14 00:11 80384 c:\windows\$NtUninstallKB982665$\iccvid.dll
+ 2010-05-26 17:21 . 2010-01-23 08:11 46080 c:\windows\$NtUninstallKB981793$\tzchange.exe
+ 2010-05-26 17:21 . 2010-04-22 22:21 16896 c:\windows\$NtUninstallKB981793$\spuninst\tzchange.dll
+ 2010-06-10 06:02 . 2004-07-20 09:54 77824 c:\windows\$NtUninstallKB979904$\system.security.dll
+ 2010-06-10 05:55 . 2008-04-14 00:11 65024 c:\windows\$NtUninstallKB979482$\asycfilt.dll
+ 2010-04-13 18:46 . 2008-04-14 00:11 84480 c:\windows\$NtUninstallKB979309$\cabview.dll
+ 2010-02-24 09:00 . 2009-10-28 15:07 46080 c:\windows\$NtUninstallKB979306$\tzchange.exe
+ 2010-02-24 09:00 . 2010-01-23 10:40 16896 c:\windows\$NtUninstallKB979306$\spuninst\tzchange.dll
+ 2010-02-10 09:01 . 2008-04-14 00:11 32256 c:\windows\$NtUninstallKB978037$\csrsrv.dll
+ 2010-02-10 09:01 . 2004-08-10 19:00 25600 c:\windows\$NtUninstallKB977914$\msvidc32.dll
+ 2010-02-10 09:01 . 2008-04-14 00:12 11264 c:\windows\$NtUninstallKB977914$\msrle32.dll
+ 2010-02-10 09:01 . 2008-04-14 00:11 47616 c:\windows\$NtUninstallKB977914$\iyuv_32.dll
+ 2010-02-10 09:01 . 2009-06-10 14:13 84992 c:\windows\$NtUninstallKB977914$\avifil32.dll
+ 2010-02-10 09:01 . 2008-04-14 00:12 16896 c:\windows\$NtUninstallKB975560$\msyuv.dll
+ 2010-01-13 19:47 . 2009-06-16 14:36 81920 c:\windows\$NtUninstallKB972270$\fontsub.dll
+ 2010-09-15 03:59 . 2008-04-14 00:12 57856 c:\windows\$NtUninstallKB2347290$\spoolsv.exe
+ 2010-09-30 05:31 . 2010-04-21 13:28 46080 c:\windows\$NtUninstallKB2158563$\tzchange.exe
+ 2010-09-30 05:31 . 2010-06-23 00:54 16896 c:\windows\$NtUninstallKB2158563$\spuninst\tzchange.dll
+ 2010-09-15 03:59 . 2010-02-22 14:23 26488 c:\windows\$hf_mig$\KB982802\update\spcustom.dll
+ 2010-09-15 03:59 . 2010-02-22 14:23 17272 c:\windows\$hf_mig$\KB982802\spmsg.dll
+ 2010-08-12 06:07 . 2010-02-22 14:23 26488 c:\windows\$hf_mig$\KB982665\update\spcustom.dll
+ 2010-08-12 06:07 . 2010-02-22 14:23 17272 c:\windows\$hf_mig$\KB982665\spmsg.dll
+ 2010-06-17 14:02 . 2010-06-17 14:02 80384 c:\windows\$hf_mig$\KB982665\SP3QFE\iccvid.dll
+ 2010-06-10 05:59 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB982381-IE8\update\spcustom.dll
+ 2010-06-10 05:59 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB982381-IE8\spmsg.dll
+ 2010-06-09 11:18 . 2010-05-06 10:36 12800 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\xpshims.dll
+ 2010-06-09 11:18 . 2010-05-06 10:36 55296 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\msfeedsbs.dll
+ 2010-06-09 11:18 . 2010-05-06 10:36 25600 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\jsproxy.dll
+ 2010-08-12 06:13 . 2010-02-22 14:23 26488 c:\windows\$hf_mig$\KB982214\update\spcustom.dll
+ 2010-08-12 06:13 . 2010-02-22 14:23 17272 c:\windows\$hf_mig$\KB982214\spmsg.dll
+ 2010-08-12 06:07 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB981997\update\spcustom.dll
+ 2010-08-12 06:07 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB981997\spmsg.dll
+ 2010-08-12 06:12 . 2010-02-22 14:23 26488 c:\windows\$hf_mig$\KB981852\update\spcustom.dll
+ 2010-08-12 00:22 . 2010-06-18 06:28 16896 c:\windows\$hf_mig$\KB981852\update\mpsyschk.dll
+ 2010-08-12 06:12 . 2010-02-22 14:23 17272 c:\windows\$hf_mig$\KB981852\spmsg.dll
+ 2010-04-14 02:23 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB981332-IE8\update\spcustom.dll
+ 2010-04-14 02:23 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB981332-IE8\spmsg.dll
+ 2010-09-15 03:58 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB981322\update\spcustom.dll
+ 2010-09-15 03:58 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB981322\spmsg.dll
+ 2010-08-12 06:09 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB980436\update\spcustom.dll
+ 2010-08-12 06:09 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB980436\spmsg.dll
+ 2010-04-14 02:25 . 2009-05-26 09:01 26488 c:\windows\$hf_mig$\KB980232\update\spcustom.dll
+ 2010-04-14 02:25 . 2009-05-26 09:01 17272 c:\windows\$hf_mig$\KB980232\spmsg.dll
+ 2010-06-10 06:02 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB980218\update\spcustom.dll
+ 2010-06-10 06:02 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB980218\spmsg.dll
+ 2010-06-10 06:00 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB980195\update\spcustom.dll
+ 2010-06-10 06:00 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB980195\spmsg.dll
+ 2010-03-31 03:07 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB980182-IE8\update\spcustom.dll
+ 2010-03-31 03:07 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB980182-IE8\spmsg.dll
+ 2010-03-30 20:02 . 2010-02-25 06:19 12800 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\xpshims.dll
+ 2010-03-30 20:02 . 2010-02-25 06:19 55296 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\msfeedsbs.dll
+ 2010-03-30 20:02 . 2010-02-25 06:19 25600 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\jsproxy.dll
+ 2010-04-14 02:26 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB979683\update\spcustom.dll
+ 2010-04-14 00:49 . 2010-03-05 14:54 16896 c:\windows\$hf_mig$\KB979683\update\mpsyschk.dll
+ 2010-04-14 02:26 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB979683\spmsg.dll
+ 2010-06-10 05:59 . 2009-05-26 09:01 26488 c:\windows\$hf_mig$\KB979559\update\spcustom.dll
+ 2010-06-10 05:59 . 2009-05-26 09:01 17272 c:\windows\$hf_mig$\KB979559\spmsg.dll
+ 2010-06-10 05:55 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB979482\update\spcustom.dll
+ 2010-06-10 05:55 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB979482\spmsg.dll
+ 2010-03-05 14:52 . 2010-03-05 14:52 65536 c:\windows\$hf_mig$\KB979482\SP3QFE\asycfilt.dll
+ 2010-04-13 18:46 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB979309\update\spcustom.dll
+ 2010-04-13 18:46 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB979309\spmsg.dll
+ 2010-01-13 13:48 . 2010-01-13 13:48 86016 c:\windows\$hf_mig$\KB979309\SP3QFE\cabview.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB978706\update\spcustom.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB978706\spmsg.dll
+ 2010-04-13 18:46 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB978601\update\spcustom.dll
+ 2010-04-13 18:46 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB978601\spmsg.dll
+ 2010-05-12 08:01 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB978542\update\spcustom.dll
+ 2010-05-12 08:01 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB978542\spmsg.dll
+ 2010-04-14 02:23 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB978338\update\spcustom.dll
+ 2010-04-14 02:23 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB978338\spmsg.dll
+ 2010-02-10 09:04 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB978262\update\spcustom.dll
+ 2010-02-10 09:04 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB978262\spmsg.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB978251\update\spcustom.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB978251\spmsg.dll
+ 2010-01-22 03:10 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB978207-IE8\update\spcustom.dll
+ 2010-01-22 03:10 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB978207-IE8\spmsg.dll
+ 2010-01-22 01:45 . 2009-12-21 19:09 12800 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\xpshims.dll
+ 2010-01-22 01:45 . 2009-12-21 19:09 55296 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\msfeedsbs.dll
+ 2010-01-22 01:45 . 2009-12-21 19:09 25600 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\jsproxy.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB978037\update\spcustom.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB978037\spmsg.dll
+ 2009-12-14 07:10 . 2009-12-14 07:10 33280 c:\windows\$hf_mig$\KB978037\SP3QFE\csrsrv.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB977914\update\spcustom.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB977914\spmsg.dll
+ 2009-11-27 16:28 . 2009-11-27 16:28 28672 c:\windows\$hf_mig$\KB977914\SP3QFE\msvidc32.dll
+ 2009-11-27 16:28 . 2009-11-27 16:28 11264 c:\windows\$hf_mig$\KB977914\SP3QFE\msrle32.dll
+ 2009-11-27 16:28 . 2009-11-27 16:28 48128 c:\windows\$hf_mig$\KB977914\SP3QFE\iyuv_32.dll
+ 2009-11-27 16:28 . 2009-11-27 16:28 84992 c:\windows\$hf_mig$\KB977914\SP3QFE\avifil32.dll
+ 2010-04-14 02:23 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB977816\update\spcustom.dll
+ 2010-04-14 02:23 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB977816\spmsg.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB977165\update\spcustom.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB977165\spmsg.dll
+ 2010-02-24 09:01 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB976662-IE8\update\spcustom.dll
+ 2010-02-24 09:01 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB976662-IE8\spmsg.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB975713\update\spcustom.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB975713\spmsg.dll
+ 2010-06-10 05:55 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB975562\update\spcustom.dll
+ 2010-06-10 05:55 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB975562\spmsg.dll
+ 2010-03-11 04:33 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB975561\update\spcustom.dll
+ 2010-03-11 04:33 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB975561\spmsg.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB975560\update\spcustom.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB975560\spmsg.dll
+ 2009-11-27 17:23 . 2009-11-27 17:23 17920 c:\windows\$hf_mig$\KB975560\SP3QFE\msyuv.dll
+ 2010-01-13 19:47 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB972270\update\spcustom.dll
+ 2010-01-13 19:47 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB972270\spmsg.dll
+ 2010-01-13 12:13 . 2009-10-15 16:39 81920 c:\windows\$hf_mig$\KB972270\SP3QFE\fontsub.dll
+ 2010-02-10 09:04 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB971468\update\spcustom.dll
+ 2010-02-10 09:04 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB971468\spmsg.dll
+ 2010-01-13 19:48 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB955759\update\spcustom.dll
+ 2010-01-13 19:48 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB955759\spmsg.dll
+ 2010-09-15 03:59 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB2347290\update\spcustom.dll
+ 2010-09-15 03:59 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB2347290\spmsg.dll
+ 2010-08-17 13:19 . 2010-08-17 13:19 58880 c:\windows\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
+ 2010-08-03 12:27 . 2010-02-22 14:23 26488 c:\windows\$hf_mig$\KB2286198\update\spcustom.dll
+ 2010-08-03 12:27 . 2010-02-22 14:23 17272 c:\windows\$hf_mig$\KB2286198\spmsg.dll
+ 2010-09-15 03:59 . 2009-05-26 09:01 26488 c:\windows\$hf_mig$\KB2259922\update\spcustom.dll
+ 2010-09-15 03:59 . 2009-05-26 09:01 17272 c:\windows\$hf_mig$\KB2259922\spmsg.dll
+ 2010-07-14 11:58 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB2229593\update\spcustom.dll
+ 2010-07-14 11:58 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB2229593\spmsg.dll
+ 2010-08-12 06:09 . 2009-05-26 09:01 26488 c:\windows\$hf_mig$\KB2183461-IE8\update\spcustom.dll
+ 2010-08-12 06:09 . 2009-05-26 09:01 17272 c:\windows\$hf_mig$\KB2183461-IE8\spmsg.dll
+ 2010-08-12 00:21 . 2010-06-24 12:24 12800 c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\xpshims.dll
+ 2010-08-12 00:21 . 2010-06-24 12:24 55296 c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\msfeedsbs.dll
+ 2010-08-12 00:21 . 2010-06-24 12:24 25600 c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\jsproxy.dll
+ 2010-08-12 06:09 . 2010-02-22 14:23 26488 c:\windows\$hf_mig$\KB2160329\update\spcustom.dll
+ 2010-08-12 06:09 . 2010-02-22 14:23 17272 c:\windows\$hf_mig$\KB2160329\spmsg.dll
+ 2010-09-15 03:55 . 2010-02-22 14:23 26488 c:\windows\$hf_mig$\KB2141007\update\spcustom.dll
+ 2010-09-15 03:55 . 2010-02-22 14:23 17272 c:\windows\$hf_mig$\KB2141007\spmsg.dll
+ 2010-09-15 03:59 . 2010-02-22 14:23 26488 c:\windows\$hf_mig$\KB2121546\update\spcustom.dll
+ 2010-09-15 03:59 . 2010-02-22 14:23 17272 c:\windows\$hf_mig$\KB2121546\spmsg.dll
+ 2010-08-12 06:13 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB2115168\update\spcustom.dll
+ 2010-08-12 06:13 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB2115168\spmsg.dll
+ 2010-08-12 06:12 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB2079403\update\spcustom.dll
+ 2010-08-12 06:12 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB2079403\spmsg.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2001-08-18 05:36 . 2009-11-27 16:07 8704 c:\windows\system32\tsbyuv.dll
- 2009-11-17 22:57 . 2009-11-17 22:57 5632 c:\windows\system32\pndx5032.dll
+ 2009-11-17 22:57 . 2010-08-06 17:26 5632 c:\windows\system32\pndx5032.dll
- 2009-11-17 22:57 . 2009-11-17 22:57 6656 c:\windows\system32\pndx5016.dll
+ 2009-11-17 22:57 . 2010-08-06 17:26 6656 c:\windows\system32\pndx5016.dll
+ 2008-03-05 02:44 . 2008-03-05 02:44 7680 c:\windows\system32\hpbprops.dll
+ 2008-03-05 02:45 . 2008-03-05 02:45 7680 c:\windows\system32\hpboidps.dll
+ 2001-08-18 05:36 . 2009-11-27 16:07 8704 c:\windows\system32\dllcache\tsbyuv.dll
+ 2010-09-23 13:14 . 2010-09-23 13:14 9216 c:\windows\system32\Adobe\Shockwave 11\DynaPlayer.dll
- 2008-08-24 02:13 . 2008-12-06 04:53 9216 c:\windows\system32\Adobe\Shockwave 11\DynaPlayer.dll
+ 2009-11-27 16:07 . 2009-11-27 16:07 8704 c:\windows\Driver Cache\i386\tsbyuv.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2009-10-17 03:14 . 2009-10-17 03:14 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2010-09-15 03:59 . 2008-05-03 11:55 2560 c:\windows\$NtUninstallKB982802$\xpsp4res.dll
+ 2010-02-10 09:01 . 2001-08-18 04:36 8192 c:\windows\$NtUninstallKB977914$\tsbyuv.dll
+ 2010-07-22 05:57 . 2010-07-22 05:57 5120 c:\windows\$hf_mig$\KB982802\SP3QFE\xpsp4res.dll
+ 2009-11-27 16:28 . 2009-11-27 16:28 8704 c:\windows\$hf_mig$\KB977914\SP3QFE\tsbyuv.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll

#8 surf

surf
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:38 PM

Posted 31 October 2010 - 10:36 AM

SECOND HALF OF LOG

+ 2009-05-22 02:26 . 2009-05-22 02:26 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_312cf0e9\atl90.dll
- 2009-09-04 19:17 . 2009-09-04 19:17 447216 c:\windows\system32\ZuneWlanCfgSvc.exe
+ 2010-01-07 20:38 . 2010-01-07 20:38 447216 c:\windows\system32\ZuneWlanCfgSvc.exe
+ 2009-09-02 06:29 . 2010-01-07 20:22 310784 c:\windows\system32\ZuneNetProxy.dll
- 2009-09-02 06:29 . 2009-09-02 06:29 310784 c:\windows\system32\ZuneNetProxy.dll
- 2009-09-02 06:29 . 2009-09-02 06:29 147456 c:\windows\system32\ZuneMTPZ.dll
+ 2009-09-02 06:29 . 2010-01-07 20:22 147456 c:\windows\system32\ZuneMTPZ.dll
- 2007-01-19 11:43 . 2009-01-08 00:21 121856 c:\windows\system32\xmllite.dll
+ 2007-01-19 11:43 . 2009-01-07 23:21 121856 c:\windows\system32\xmllite.dll
+ 2005-01-09 23:48 . 2009-12-24 06:59 177664 c:\windows\system32\wintrust.dll
- 2005-01-09 23:48 . 2008-04-14 00:12 293376 c:\windows\system32\winsrv.dll
+ 2005-01-09 23:48 . 2010-06-18 17:45 293376 c:\windows\system32\winsrv.dll
+ 2006-10-17 18:05 . 2009-03-08 09:34 208384 c:\windows\system32\WinFXDocObj.exe
+ 2005-01-09 23:48 . 2009-03-08 09:34 236544 c:\windows\system32\webcheck.dll
+ 2005-01-09 23:48 . 2010-03-10 06:15 420352 c:\windows\system32\vbscript.dll
- 2005-01-09 23:48 . 2008-04-14 00:12 406016 c:\windows\system32\usp10.dll
+ 2005-01-09 23:48 . 2010-04-16 15:36 406016 c:\windows\system32\usp10.dll
+ 2005-01-09 23:48 . 2009-03-08 09:34 105984 c:\windows\system32\url.dll
- 2005-01-09 23:48 . 2009-02-20 18:09 105984 c:\windows\system32\url.dll
+ 2010-08-17 02:06 . 2009-04-16 19:08 312832 c:\windows\system32\spool\prtprocs\w32x86\hpfpp70v.dll
+ 2010-08-17 02:06 . 2009-01-06 00:40 761344 c:\windows\system32\spool\drivers\w32x86\hpdeskjet_d1600_seriaaf2\UNIRES.DLL
+ 2010-08-17 02:06 . 2009-01-06 00:40 740864 c:\windows\system32\spool\drivers\w32x86\hpdeskjet_d1600_seriaaf2\UNIDRVUI.DLL
+ 2010-08-17 02:06 . 2009-01-06 00:40 372736 c:\windows\system32\spool\drivers\w32x86\hpdeskjet_d1600_seriaaf2\UNIDRV.DLL
+ 2010-08-17 02:06 . 2009-04-16 19:07 206848 c:\windows\system32\spool\drivers\w32x86\hpdeskjet_d1600_seriaaf2\hpfvu70v.dll
+ 2010-08-17 02:06 . 2009-01-06 01:40 113664 c:\windows\system32\spool\drivers\w32x86\hpdeskjet_d1600_seriaaf2\hpfrs70v.dll
+ 2010-08-17 02:06 . 2009-04-16 19:08 306176 c:\windows\system32\spool\drivers\w32x86\hpdeskjet_d1600_seriaaf2\hpfpr70v.dll
+ 2010-08-17 02:06 . 2009-04-16 19:08 470016 c:\windows\system32\spool\drivers\w32x86\hpdeskjet_d1600_seriaaf2\hpfpa70v.dll
+ 2010-08-17 02:06 . 2009-04-10 16:29 403456 c:\windows\system32\spool\drivers\w32x86\hpdeskjet_d1600_seriaaf2\hpfig70v.dll
+ 2010-08-17 02:06 . 2009-01-23 22:18 252416 c:\windows\system32\spool\drivers\w32x86\hpdeskjet_d1600_seriaaf2\hpfie70v.dll
+ 2010-08-17 02:06 . 2009-04-16 19:08 531456 c:\windows\system32\spool\drivers\w32x86\hpdeskjet_d1600_seriaaf2\hpfev70v.dll
+ 2010-08-17 02:06 . 2009-04-16 19:08 634880 c:\windows\system32\spool\drivers\w32x86\hpdeskjet_d1600_seriaaf2\hpdj1603.dll
+ 2010-08-17 02:06 . 2009-04-16 19:07 206848 c:\windows\system32\spool\drivers\w32x86\3\hpfvu70v.dll
+ 2010-08-17 02:06 . 2009-01-06 01:40 113664 c:\windows\system32\spool\drivers\w32x86\3\hpfrs70v.dll
+ 2010-08-17 02:06 . 2009-04-16 19:08 306176 c:\windows\system32\spool\drivers\w32x86\3\hpfpr70v.dll
+ 2010-08-17 02:06 . 2009-04-16 19:08 470016 c:\windows\system32\spool\drivers\w32x86\3\hpfpa70v.dll
+ 2010-08-17 02:06 . 2009-04-10 16:29 403456 c:\windows\system32\spool\drivers\w32x86\3\hpfig70v.dll
+ 2010-08-17 02:06 . 2009-01-23 22:18 252416 c:\windows\system32\spool\drivers\w32x86\3\hpfie70v.dll
+ 2010-08-17 02:06 . 2009-04-16 19:08 531456 c:\windows\system32\spool\drivers\w32x86\3\hpfev70v.dll
+ 2010-08-17 02:06 . 2009-04-16 19:08 634880 c:\windows\system32\spool\drivers\w32x86\3\hpdj1603.dll
- 2005-01-09 23:48 . 2008-04-14 00:12 474112 c:\windows\system32\shlwapi.dll
+ 2005-01-09 23:48 . 2009-12-08 09:23 474112 c:\windows\system32\shlwapi.dll
+ 2005-01-09 23:48 . 2010-06-30 12:31 149504 c:\windows\system32\schannel.dll
- 2009-11-17 22:57 . 2009-11-17 22:57 185920 c:\windows\system32\rmoc3260.dll
+ 2009-11-17 22:57 . 2010-08-06 17:27 185920 c:\windows\system32\rmoc3260.dll
+ 2010-03-31 05:10 . 2010-03-31 05:10 295264 c:\windows\system32\PresentationHost.exe
- 2006-06-17 22:10 . 2009-11-17 22:56 278528 c:\windows\system32\pncrt.dll
+ 2006-06-17 22:10 . 2010-08-06 17:26 278528 c:\windows\system32\pncrt.dll
+ 2005-01-09 23:48 . 2010-10-05 12:33 444780 c:\windows\system32\perfh009.dat
+ 2005-01-09 23:48 . 2010-09-10 05:58 206848 c:\windows\system32\occache.dll
+ 2005-01-09 23:48 . 2010-09-10 05:58 611840 c:\windows\system32\mstime.dll
+ 2005-01-09 23:48 . 2009-03-08 09:34 193536 c:\windows\system32\msrating.dll
- 2008-08-26 03:56 . 2008-04-14 00:12 343040 c:\windows\system32\mspaint.exe
+ 2008-08-26 03:56 . 2009-12-16 18:43 343040 c:\windows\system32\mspaint.exe
- 2005-01-09 23:48 . 2006-11-08 03:03 156160 c:\windows\system32\msls31.dll
+ 2005-01-09 23:48 . 2009-03-08 09:22 156160 c:\windows\system32\msls31.dll
+ 2006-11-08 03:03 . 2010-09-10 05:58 602112 c:\windows\system32\msfeeds.dll
- 2009-01-07 23:20 . 2009-01-08 00:20 265720 c:\windows\system32\msdbg2.dll
+ 2009-01-07 23:20 . 2009-01-07 23:20 265720 c:\windows\system32\msdbg2.dll
+ 2009-11-07 06:07 . 2009-11-07 06:07 297808 c:\windows\system32\mscoree.dll
+ 2009-10-03 17:12 . 2010-05-21 19:14 221568 c:\windows\system32\MpSigStub.exe
- 2006-10-19 03:47 . 2006-10-19 03:47 317440 c:\windows\system32\MP4SDECD.dll
+ 2006-10-19 03:47 . 2010-03-30 17:24 317440 c:\windows\system32\mp4sdecd.dll
+ 2010-07-24 17:51 . 2010-07-24 17:51 231888 c:\windows\system32\Macromed\Flash\FlashUtil10h_Plugin.exe
+ 2005-01-09 23:48 . 2009-12-09 05:53 726528 c:\windows\system32\jscript.dll
+ 2005-01-10 01:09 . 2010-06-09 07:43 692736 c:\windows\system32\inetcomm.dll
+ 2006-11-08 03:03 . 2009-03-08 09:22 164352 c:\windows\system32\ieui.dll
+ 2005-01-09 23:48 . 2010-09-10 05:58 184320 c:\windows\system32\iepeers.dll
+ 2005-01-09 23:48 . 2010-09-10 05:58 387584 c:\windows\system32\iedkcs32.dll
+ 2006-10-17 17:27 . 2009-03-08 09:11 445952 c:\windows\system32\ieapfltr.dll
+ 2005-01-09 23:48 . 2009-03-08 09:32 163840 c:\windows\system32\ieakui.dll
+ 2005-01-09 23:48 . 2009-03-08 09:33 229376 c:\windows\system32\ieaksie.dll
+ 2005-01-09 23:48 . 2009-03-08 09:33 125952 c:\windows\system32\ieakeng.dll
+ 2005-01-09 23:48 . 2010-08-26 12:22 173056 c:\windows\system32\ie4uinit.exe
+ 2010-08-17 02:06 . 2009-04-15 21:53 452408 c:\windows\system32\hpzids01.dll
+ 2010-08-17 02:06 . 2008-10-28 10:27 372736 c:\windows\system32\hppldcoi.dll
+ 2007-04-24 15:33 . 2007-04-24 15:33 114688 c:\windows\system32\hplbdchn.dll
+ 2010-08-17 02:06 . 2009-04-16 19:08 126976 c:\windows\system32\hpfll70v.dll
+ 2005-01-09 16:59 . 2010-10-13 23:20 265416 c:\windows\system32\FNTCACHE.DAT
+ 2005-01-09 23:48 . 2009-03-08 09:31 216064 c:\windows\system32\dxtrans.dll
+ 2005-01-09 23:48 . 2009-03-08 09:31 348160 c:\windows\system32\dxtmsft.dll
+ 2010-08-17 01:57 . 2008-10-17 07:01 282624 c:\windows\system32\DRVSTORE\hpzius13_D627171118186196E509949900C5F44341391758\HPZc3212.dll
+ 2010-08-17 01:57 . 2008-10-28 10:27 372736 c:\windows\system32\DRVSTORE\hpzius13_D627171118186196E509949900C5F44341391758\drivers\dot4\Win2000\hppldcoi.dll
+ 2010-08-17 01:57 . 2008-10-28 10:27 309760 c:\windows\system32\DRVSTORE\hpzius13_D627171118186196E509949900C5F44341391758\drivers\dot4\Win2000\difxapi.dll
+ 2010-08-17 01:57 . 2008-10-17 07:01 282624 c:\windows\system32\DRVSTORE\hpzipa13_C7C260442B1351522D77732EB0D2429A413CE56A\HPZc3212.dll
+ 2010-08-17 01:57 . 2008-10-28 10:27 372736 c:\windows\system32\DRVSTORE\hpzipa13_C7C260442B1351522D77732EB0D2429A413CE56A\drivers\dot4\Win2000\hppldcoi.dll
+ 2010-08-17 01:57 . 2008-10-28 10:27 309760 c:\windows\system32\DRVSTORE\hpzipa13_C7C260442B1351522D77732EB0D2429A413CE56A\drivers\dot4\Win2000\difxapi.dll
+ 2010-08-17 01:57 . 2009-04-15 21:53 452408 c:\windows\system32\DRVSTORE\hpd1600_4E7CFE3336A68F34E9785C6DA27DF93FC6CEE2F3\hpzids01.dll
+ 2009-09-02 06:28 . 2010-01-07 20:22 708608 c:\windows\system32\drivers\UMDF\ZuneDriver.dll
+ 2005-01-09 23:48 . 2010-02-11 12:02 226880 c:\windows\system32\drivers\tcpip6.sys
+ 2005-01-09 23:48 . 2010-02-24 13:11 455680 c:\windows\system32\drivers\mrxsmb.sys
+ 2008-08-26 03:57 . 2010-07-12 12:55 218112 c:\windows\system32\dllcache\wordpad.exe
+ 2009-12-24 06:59 . 2009-12-24 06:59 177664 c:\windows\system32\dllcache\wintrust.dll
+ 2010-06-18 17:45 . 2010-06-18 17:45 293376 c:\windows\system32\dllcache\winsrv.dll
+ 2006-06-23 11:25 . 2010-09-10 05:58 916480 c:\windows\system32\dllcache\wininet.dll
+ 2006-11-08 03:03 . 2009-03-08 09:34 236544 c:\windows\system32\dllcache\webcheck.dll
+ 2006-09-18 14:15 . 2009-03-08 09:33 759296 c:\windows\system32\dllcache\VGX.dll
+ 2008-05-09 10:53 . 2010-03-10 06:15 420352 c:\windows\system32\dllcache\vbscript.dll
+ 2010-04-16 15:36 . 2010-04-16 15:36 406016 c:\windows\system32\dllcache\usp10.dll
+ 2006-10-17 18:05 . 2009-03-08 09:34 105984 c:\windows\system32\dllcache\url.dll
- 2006-10-17 18:05 . 2009-02-20 18:09 105984 c:\windows\system32\dllcache\url.dll
+ 2008-06-20 11:08 . 2010-02-11 12:02 226880 c:\windows\system32\dllcache\tcpip6.sys
+ 2009-06-16 14:36 . 2010-08-27 08:02 119808 c:\windows\system32\dllcache\t2embed.dll
- 2009-06-16 14:36 . 2009-06-16 14:36 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2008-10-16 04:04 . 2010-08-26 13:39 357248 c:\windows\system32\dllcache\srv.sys
+ 2009-01-07 23:20 . 2009-01-07 23:20 134144 c:\windows\system32\dllcache\sqmapi.dll
- 2009-01-08 00:20 . 2009-01-08 00:20 134144 c:\windows\system32\dllcache\sqmapi.dll
- 2009-01-08 00:20 . 2009-01-08 00:20 474112 c:\windows\system32\dllcache\shlwapi.dll
+ 2009-01-07 23:20 . 2009-01-07 23:20 474112 c:\windows\system32\dllcache\shlwapi.dll
+ 2008-12-05 06:54 . 2010-06-30 12:31 149504 c:\windows\system32\dllcache\schannel.dll
+ 2009-04-15 14:51 . 2010-08-16 08:45 590848 c:\windows\system32\dllcache\rpcrt4.dll
+ 2006-10-17 18:04 . 2010-09-10 05:58 206848 c:\windows\system32\dllcache\occache.dll
+ 2006-06-23 11:25 . 2010-09-10 05:58 611840 c:\windows\system32\dllcache\mstime.dll
+ 2006-06-23 11:25 . 2009-03-08 09:34 193536 c:\windows\system32\dllcache\msrating.dll
- 2008-08-26 03:56 . 2008-04-14 00:12 343040 c:\windows\system32\dllcache\mspaint.exe
+ 2008-08-26 03:56 . 2009-12-16 18:43 343040 c:\windows\system32\dllcache\mspaint.exe
+ 2006-11-08 03:03 . 2009-03-08 09:22 156160 c:\windows\system32\dllcache\msls31.dll
- 2006-11-08 03:03 . 2006-11-08 03:03 156160 c:\windows\system32\dllcache\msls31.dll
+ 2007-05-09 10:29 . 2010-09-10 05:58 602112 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-11-11 18:57 . 2010-02-24 13:11 455680 c:\windows\system32\dllcache\mrxsmb.sys
+ 2010-03-30 17:24 . 2010-03-30 17:24 317440 c:\windows\system32\dllcache\mp4sdecd.dll
+ 2006-10-14 08:13 . 2010-09-18 17:23 974848 c:\windows\system32\dllcache\mfc42u.dll
+ 2008-05-09 10:53 . 2009-12-09 05:53 726528 c:\windows\system32\dllcache\jscript.dll
+ 2008-08-13 13:50 . 2010-06-09 07:43 692736 c:\windows\system32\dllcache\inetcomm.dll
+ 2005-01-10 01:09 . 2009-03-08 19:09 638816 c:\windows\system32\dllcache\iexplore.exe
+ 2009-06-11 12:21 . 2010-09-10 05:58 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2006-06-23 11:25 . 2010-09-10 05:58 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2010-06-09 11:17 . 2010-09-10 05:58 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2006-11-07 09:27 . 2010-09-10 05:58 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2007-05-09 10:29 . 2009-03-08 09:11 445952 c:\windows\system32\dllcache\ieapfltr.dll
+ 2006-11-07 09:25 . 2009-03-08 09:32 163840 c:\windows\system32\dllcache\ieakui.dll
+ 2006-11-07 09:27 . 2009-03-08 09:33 229376 c:\windows\system32\dllcache\ieaksie.dll
+ 2006-11-07 09:26 . 2009-03-08 09:33 125952 c:\windows\system32\dllcache\ieakeng.dll
+ 2006-11-07 09:26 . 2010-08-26 12:22 173056 c:\windows\system32\dllcache\ie4uinit.exe
+ 2010-07-14 11:47 . 2010-06-14 14:31 744448 c:\windows\system32\dllcache\helpsvc.exe
+ 2006-06-23 11:25 . 2009-03-08 09:31 216064 c:\windows\system32\dllcache\dxtrans.dll
+ 2006-06-23 11:25 . 2009-03-08 09:31 348160 c:\windows\system32\dllcache\dxtmsft.dll
+ 2010-04-20 05:30 . 2010-09-01 11:51 285824 c:\windows\system32\dllcache\atmfd.dll
+ 2006-11-07 09:26 . 2009-03-08 09:32 128512 c:\windows\system32\dllcache\advpack.dll
+ 2010-01-13 12:13 . 2009-11-21 15:51 471552 c:\windows\system32\dllcache\aclayers.dll
+ 2010-02-12 04:33 . 2010-02-12 04:33 100864 c:\windows\system32\dllcache\6to4svc.dll
+ 2010-08-17 02:06 . 2008-10-28 10:27 309760 c:\windows\system32\difxapi.dll
+ 2005-01-09 23:47 . 2009-03-08 09:32 128512 c:\windows\system32\advpack.dll
- 2008-08-24 02:13 . 2008-12-06 04:51 114688 c:\windows\system32\Adobe\Shockwave 11\SwInit.exe
+ 2010-09-23 13:13 . 2010-09-23 13:13 114688 c:\windows\system32\Adobe\Shockwave 11\SwInit.exe
+ 2010-09-23 13:21 . 2010-09-23 13:21 467224 c:\windows\system32\Adobe\Shockwave 11\SwHelper_1158612.exe
+ 2010-09-20 12:56 . 2010-09-20 12:56 136568 c:\windows\system32\Adobe\Shockwave 11\SCC.dll
- 2008-08-24 02:13 . 2008-12-06 04:53 446464 c:\windows\system32\Adobe\Shockwave 11\Proj.dll
+ 2010-09-23 13:14 . 2010-09-23 13:14 446464 c:\windows\system32\Adobe\Shockwave 11\Proj.dll
+ 2010-09-23 13:13 . 2010-09-23 13:13 372736 c:\windows\system32\Adobe\Shockwave 11\Plugin.dll
+ 2010-09-23 12:52 . 2010-09-23 12:52 810496 c:\windows\system32\Adobe\Shockwave 11\gi.dll
+ 2010-09-23 13:13 . 2010-09-23 13:13 503808 c:\windows\system32\Adobe\Shockwave 11\Control.dll
+ 2010-09-23 13:21 . 2010-09-23 13:21 213272 c:\windows\system32\Adobe\Director\swdir.dll
+ 2010-09-23 13:14 . 2010-09-23 13:14 131072 c:\windows\system32\Adobe\Director\np32dsw.dll
+ 2009-05-22 00:58 . 2009-05-22 00:58 287256 c:\windows\system32\AbaleZip.dll
+ 2005-01-09 23:47 . 2010-02-12 04:33 100864 c:\windows\system32\6to4svc.dll
+ 2005-01-10 01:09 . 2010-06-14 14:31 744448 c:\windows\pchealth\helpctr\binaries\helpsvc.exe
- 2005-01-10 01:09 . 2008-04-14 00:12 744448 c:\windows\pchealth\helpctr\binaries\helpsvc.exe
+ 2010-03-31 05:16 . 2010-03-31 05:16 130408 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
+ 2010-04-08 04:48 . 2010-04-08 04:48 970752 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
- 2008-07-30 00:16 . 2008-07-30 00:16 110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
+ 2010-04-08 04:48 . 2010-04-08 04:48 110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
+ 2010-09-22 14:43 . 2010-09-22 14:43 435024 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
+ 2010-02-09 17:22 . 2010-02-09 17:22 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
- 2008-07-25 16:17 . 2008-07-25 16:17 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
+ 2010-05-11 11:40 . 2010-05-11 11:40 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
- 2009-08-08 04:51 . 2009-08-08 04:51 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2010-05-11 11:40 . 2010-05-11 11:40 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2010-09-23 07:26 . 2010-09-23 07:26 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2008-05-28 05:49 . 2008-05-28 05:49 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2010-09-23 07:25 . 2010-09-23 07:25 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2008-05-28 05:48 . 2008-05-28 05:48 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2008-05-28 06:30 . 2008-05-28 06:30 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2010-09-23 08:17 . 2010-09-23 08:17 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2010-01-04 15:29 . 2010-01-04 15:29 697856 c:\windows\Installer\bd0777.msi
+ 2010-08-17 02:02 . 2010-08-17 02:02 857600 c:\windows\Installer\60d033.msi
+ 2010-08-17 02:00 . 2010-08-17 02:00 577024 c:\windows\Installer\60d01e.msi
+ 2010-08-17 02:00 . 2010-08-17 02:00 279040 c:\windows\Installer\60d018.msi
+ 2010-08-17 02:00 . 2010-08-17 02:00 821760 c:\windows\Installer\60d012.msi
+ 2010-08-17 02:00 . 2010-08-17 02:00 477184 c:\windows\Installer\60d009.msi
+ 2010-08-17 02:00 . 2010-08-17 02:00 585216 c:\windows\Installer\60d003.msi
+ 2010-08-17 01:59 . 2010-08-17 01:59 678400 c:\windows\Installer\60cffd.msi
+ 2010-08-17 01:59 . 2010-08-17 01:59 692224 c:\windows\Installer\60cff7.msi
+ 2010-08-17 01:59 . 2010-08-17 01:59 307712 c:\windows\Installer\60cfea.msi
+ 2010-08-17 01:59 . 2010-08-17 01:59 935424 c:\windows\Installer\60cfe0.msi
+ 2010-08-17 01:59 . 2010-08-17 01:59 390144 c:\windows\Installer\60cfda.msi
+ 2010-08-17 01:59 . 2010-08-17 01:59 382464 c:\windows\Installer\60cfd4.msi
+ 2010-06-10 06:00 . 2010-06-10 06:00 200192 c:\windows\Installer\3fdf9d1.msi
+ 2010-02-25 05:14 . 2010-02-25 05:14 543232 c:\windows\Installer\3fdf997.msp
+ 2010-06-12 00:07 . 2010-06-12 00:07 168960 c:\windows\Installer\3bd1bcb.msp
+ 2010-09-24 02:02 . 2010-09-24 02:02 798208 c:\windows\Installer\28c98f9.msp
+ 2010-03-10 05:08 . 2010-03-10 05:08 635904 c:\windows\Installer\1aa7a10.msi
+ 2010-05-07 12:04 . 2010-10-28 12:34 295606 c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A82000000003}\SC_Reader.exe
- 2009-08-20 23:50 . 2009-12-19 07:13 135168 c:\windows\Installer\{90850409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-08-20 23:50 . 2010-10-13 12:54 135168 c:\windows\Installer\{90850409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2010-08-17 02:01 . 2010-08-17 02:01 689456 c:\windows\Installer\{7059BDA7-E1DB-442C-B7A1-6144596720A4}\HPSUShortcut_BB85ED9CAFC943BDB8DC258C3C7DF72E.exe
+ 2009-12-18 07:51 . 2009-12-18 07:51 372736 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\pdfshell.dll
+ 2009-11-10 03:34 . 2009-11-10 03:34 448512 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\JP2KLib.dll
+ 2009-12-18 07:14 . 2009-12-18 07:14 140728 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\AdobeUpdateCheck.exe
+ 2009-12-18 09:55 . 2009-12-18 09:55 738776 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\AdobeCollabSync.exe
+ 2009-12-18 08:21 . 2009-12-18 08:21 112048 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\AcroRdIF.dll
+ 2009-12-18 13:58 . 2009-12-18 13:58 345520 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\AcroRd32.exe
+ 2009-12-18 07:17 . 2009-12-18 07:17 632240 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\AcroPDF.dll
+ 2010-06-10 05:59 . 2010-02-25 06:24 916480 c:\windows\ie8updates\KB982381-IE8\wininet.dll
+ 2010-06-10 05:59 . 2010-02-22 14:23 382840 c:\windows\ie8updates\KB982381-IE8\spuninst\updspapi.dll
+ 2010-06-10 05:59 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB982381-IE8\spuninst\spuninst.exe
+ 2010-06-10 05:59 . 2010-02-25 06:24 206848 c:\windows\ie8updates\KB982381-IE8\occache.dll
+ 2010-06-10 05:59 . 2010-02-25 06:24 611840 c:\windows\ie8updates\KB982381-IE8\mstime.dll
+ 2010-06-10 05:59 . 2010-02-25 06:24 594432 c:\windows\ie8updates\KB982381-IE8\msfeeds.dll
+ 2010-06-10 05:59 . 2010-02-25 06:24 247808 c:\windows\ie8updates\KB982381-IE8\ieproxy.dll
+ 2010-06-10 05:59 . 2010-02-25 06:24 184320 c:\windows\ie8updates\KB982381-IE8\iepeers.dll
+ 2010-06-10 05:59 . 2009-03-08 09:35 742912 c:\windows\ie8updates\KB982381-IE8\iedvtool.dll
+ 2010-06-10 05:59 . 2010-02-25 06:24 387584 c:\windows\ie8updates\KB982381-IE8\iedkcs32.dll
+ 2010-06-10 05:59 . 2010-02-24 09:54 173056 c:\windows\ie8updates\KB982381-IE8\ie4uinit.exe
+ 2010-05-18 18:46 . 2009-03-08 09:33 420352 c:\windows\ie8updates\KB981332-IE8\vbscript.dll
+ 2010-05-18 18:46 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB981332-IE8\updspapi.dll
+ 2010-05-18 18:46 . 2009-05-26 11:40 755576 c:\windows\ie8updates\KB981332-IE8\update.exe
+ 2010-05-18 18:46 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB981332-IE8\spuninst\updspapi.dll
+ 2010-05-18 18:46 . 2009-05-26 11:40 231288 c:\windows\ie8updates\KB981332-IE8\spuninst\spuninst.exe
+ 2010-05-18 18:46 . 2009-05-26 11:40 231288 c:\windows\ie8updates\KB981332-IE8\spuninst.exe
+ 2010-05-18 18:46 . 2009-03-08 09:34 914944 c:\windows\ie8updates\KB980182-IE8\wininet.dll
+ 2010-05-18 18:46 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB980182-IE8\updspapi.dll
+ 2010-05-18 18:46 . 2009-05-26 11:40 755576 c:\windows\ie8updates\KB980182-IE8\update.exe
+ 2010-05-18 18:46 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB980182-IE8\spuninst\updspapi.dll
+ 2010-05-18 18:46 . 2009-05-26 11:40 231288 c:\windows\ie8updates\KB980182-IE8\spuninst\spuninst.exe
+ 2010-05-18 18:46 . 2009-05-26 11:40 231288 c:\windows\ie8updates\KB980182-IE8\spuninst.exe
+ 2010-05-18 18:46 . 2009-03-08 09:34 109568 c:\windows\ie8updates\KB980182-IE8\occache.dll
+ 2010-05-18 18:46 . 2009-03-08 09:32 611840 c:\windows\ie8updates\KB980182-IE8\mstime.dll
+ 2010-05-18 18:46 . 2009-03-08 09:32 594432 c:\windows\ie8updates\KB980182-IE8\msfeeds.dll
+ 2010-05-18 18:46 . 2009-03-08 09:33 246784 c:\windows\ie8updates\KB980182-IE8\ieproxy.dll
+ 2010-05-18 18:46 . 2009-03-08 09:31 183808 c:\windows\ie8updates\KB980182-IE8\iepeers.dll
+ 2010-05-18 18:46 . 2009-03-08 19:09 391536 c:\windows\ie8updates\KB980182-IE8\iedkcs32.dll
+ 2010-05-18 18:46 . 2009-03-08 09:32 173056 c:\windows\ie8updates\KB980182-IE8\ie4uinit.exe
+ 2010-05-18 18:46 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB976662-IE8\updspapi.dll
+ 2010-05-18 18:46 . 2008-07-08 13:02 755576 c:\windows\ie8updates\KB976662-IE8\update.exe
+ 2010-05-18 18:46 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB976662-IE8\spuninst\updspapi.dll
+ 2010-05-18 18:46 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB976662-IE8\spuninst\spuninst.exe
+ 2010-05-18 18:46 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB976662-IE8\spuninst.exe
+ 2010-05-18 18:46 . 2009-06-22 06:44 726528 c:\windows\ie8updates\KB976662-IE8\jscript.dll
+ 2010-05-18 18:45 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB971961-IE8\updspapi.dll
+ 2010-05-18 18:45 . 2008-07-08 13:02 755576 c:\windows\ie8updates\KB971961-IE8\update.exe
+ 2010-05-18 18:45 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB971961-IE8\spuninst\updspapi.dll
+ 2010-05-18 18:45 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB971961-IE8\spuninst\spuninst.exe
+ 2010-05-18 18:45 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB971961-IE8\spuninst.exe
+ 2010-05-18 18:45 . 2009-03-08 09:33 726528 c:\windows\ie8updates\KB971961-IE8\jscript.dll
+ 2010-10-13 12:54 . 2010-06-24 12:22 916480 c:\windows\ie8updates\KB2360131-IE8\wininet.dll
+ 2010-10-13 12:54 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2360131-IE8\spuninst\updspapi.dll
+ 2010-10-13 12:54 . 2009-05-26 09:01 231288 c:\windows\ie8updates\KB2360131-IE8\spuninst\spuninst.exe
+ 2010-10-13 12:54 . 2010-06-24 12:22 206848 c:\windows\ie8updates\KB2360131-IE8\occache.dll
+ 2010-10-13 12:54 . 2010-06-24 12:22 611840 c:\windows\ie8updates\KB2360131-IE8\mstime.dll
+ 2010-10-13 12:54 . 2010-06-24 12:21 599040 c:\windows\ie8updates\KB2360131-IE8\msfeeds.dll
+ 2010-10-13 12:54 . 2010-06-24 12:21 247808 c:\windows\ie8updates\KB2360131-IE8\ieproxy.dll
+ 2010-10-13 12:54 . 2010-06-24 12:21 184320 c:\windows\ie8updates\KB2360131-IE8\iepeers.dll
+ 2010-10-13 12:54 . 2010-06-24 12:21 743424 c:\windows\ie8updates\KB2360131-IE8\iedvtool.dll
+ 2010-10-13 12:54 . 2010-06-24 12:21 387584 c:\windows\ie8updates\KB2360131-IE8\iedkcs32.dll
+ 2010-10-13 12:54 . 2010-06-23 12:08 173056 c:\windows\ie8updates\KB2360131-IE8\ie4uinit.exe
+ 2010-08-12 06:09 . 2010-05-06 10:41 916480 c:\windows\ie8updates\KB2183461-IE8\wininet.dll
+ 2010-08-12 06:09 . 2010-02-22 14:23 382840 c:\windows\ie8updates\KB2183461-IE8\spuninst\updspapi.dll
+ 2010-08-12 06:09 . 2009-05-26 09:01 231288 c:\windows\ie8updates\KB2183461-IE8\spuninst\spuninst.exe
+ 2010-08-12 06:09 . 2010-05-06 10:41 206848 c:\windows\ie8updates\KB2183461-IE8\occache.dll
+ 2010-08-12 06:09 . 2010-05-06 10:41 611840 c:\windows\ie8updates\KB2183461-IE8\mstime.dll
+ 2010-08-12 06:09 . 2010-05-06 10:41 599040 c:\windows\ie8updates\KB2183461-IE8\msfeeds.dll
+ 2010-08-12 06:09 . 2010-05-06 10:41 247808 c:\windows\ie8updates\KB2183461-IE8\ieproxy.dll
+ 2010-08-12 06:09 . 2010-05-06 10:41 184320 c:\windows\ie8updates\KB2183461-IE8\iepeers.dll
+ 2010-08-12 06:09 . 2010-05-06 10:41 743424 c:\windows\ie8updates\KB2183461-IE8\iedvtool.dll
+ 2010-08-12 06:09 . 2010-05-06 10:41 387584 c:\windows\ie8updates\KB2183461-IE8\iedkcs32.dll
+ 2010-08-12 06:09 . 2010-05-05 13:30 173056 c:\windows\ie8updates\KB2183461-IE8\ie4uinit.exe
- 2010-01-01 22:14 . 2009-03-03 00:18 826368 c:\windows\ie8\wininet.dll
+ 2010-05-18 11:53 . 2009-03-03 00:18 826368 c:\windows\ie8\wininet.dll
+ 2010-05-18 11:53 . 2006-10-17 18:05 206336 c:\windows\ie8\winfxdocobj.exe
- 2010-01-01 22:14 . 2006-10-17 18:05 206336 c:\windows\ie8\winfxdocobj.exe
+ 2010-05-18 11:53 . 2009-02-20 18:09 233472 c:\windows\ie8\webcheck.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 233472 c:\windows\ie8\webcheck.dll
+ 2010-05-18 11:53 . 2007-07-12 23:31 765952 c:\windows\ie8\vgx.dll
- 2010-01-01 22:14 . 2007-07-12 23:31 765952 c:\windows\ie8\vgx.dll
+ 2010-05-18 11:53 . 2008-05-09 10:53 430080 c:\windows\ie8\vbscript.dll
- 2010-01-01 22:14 . 2008-05-09 10:53 430080 c:\windows\ie8\vbscript.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 105984 c:\windows\ie8\url.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 105984 c:\windows\ie8\url.dll
- 2010-01-01 22:15 . 2009-01-08 00:21 382496 c:\windows\ie8\spuninst\updspapi.dll
+ 2010-05-18 11:54 . 2009-01-07 23:21 382496 c:\windows\ie8\spuninst\updspapi.dll
- 2010-01-01 22:15 . 2009-01-08 00:20 231456 c:\windows\ie8\spuninst\spuninst.exe
+ 2010-05-18 11:54 . 2009-01-07 23:20 231456 c:\windows\ie8\spuninst\spuninst.exe
- 2010-01-01 22:14 . 2006-09-06 22:43 213216 c:\windows\ie8\spuninst.exe
+ 2010-05-18 11:53 . 2006-09-06 22:43 213216 c:\windows\ie8\spuninst.exe
+ 2010-05-18 11:53 . 2009-02-20 18:09 102912 c:\windows\ie8\occache.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 102912 c:\windows\ie8\occache.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 671232 c:\windows\ie8\mstime.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 671232 c:\windows\ie8\mstime.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 193024 c:\windows\ie8\msrating.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 193024 c:\windows\ie8\msrating.dll
+ 2010-05-18 11:53 . 2006-11-08 03:03 156160 c:\windows\ie8\msls31.dll
- 2010-01-01 22:14 . 2006-11-08 03:03 156160 c:\windows\ie8\msls31.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 477696 c:\windows\ie8\mshtmled.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 477696 c:\windows\ie8\mshtmled.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 459264 c:\windows\ie8\msfeeds.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 459264 c:\windows\ie8\msfeeds.dll
- 2010-01-01 22:14 . 2008-05-09 10:53 512000 c:\windows\ie8\jscript.dll
+ 2010-05-18 11:53 . 2008-05-09 10:53 512000 c:\windows\ie8\jscript.dll
- 2010-01-01 22:14 . 2009-02-28 04:54 636072 c:\windows\ie8\iexplore.exe
+ 2010-05-18 11:53 . 2009-02-28 04:54 636072 c:\windows\ie8\iexplore.exe
- 2010-01-01 22:14 . 2006-11-08 03:03 180736 c:\windows\ie8\ieui.dll
+ 2010-05-18 11:53 . 2006-11-08 03:03 180736 c:\windows\ie8\ieui.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 268288 c:\windows\ie8\iertutil.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 268288 c:\windows\ie8\iertutil.dll
+ 2010-05-18 11:53 . 2006-11-08 03:03 287744 c:\windows\ie8\ieproxy.dll
- 2010-01-01 22:14 . 2006-11-08 03:03 287744 c:\windows\ie8\ieproxy.dll
+ 2010-05-18 11:53 . 2006-11-08 03:03 191488 c:\windows\ie8\iepeers.dll
- 2010-01-01 22:14 . 2006-11-08 03:03 191488 c:\windows\ie8\iepeers.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 385024 c:\windows\ie8\iedkcs32.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 385024 c:\windows\ie8\iedkcs32.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 383488 c:\windows\ie8\ieapfltr.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 383488 c:\windows\ie8\ieapfltr.dll
- 2010-01-01 22:14 . 2009-02-20 05:14 161792 c:\windows\ie8\ieakui.dll
+ 2010-05-18 11:53 . 2009-02-20 05:14 161792 c:\windows\ie8\ieakui.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 230400 c:\windows\ie8\ieaksie.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 230400 c:\windows\ie8\ieaksie.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 153088 c:\windows\ie8\ieakeng.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 153088 c:\windows\ie8\ieakeng.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 214528 c:\windows\ie8\dxtrans.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 214528 c:\windows\ie8\dxtrans.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 347136 c:\windows\ie8\dxtmsft.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 347136 c:\windows\ie8\dxtmsft.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 124928 c:\windows\ie8\advpack.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 124928 c:\windows\ie8\advpack.dll
+ 2010-08-17 01:52 . 2010-08-17 02:07 158640 c:\windows\hphins33.dat
+ 2005-10-13 15:44 . 2005-10-13 15:44 434176 c:\windows\ehome\CreateDisc\pxdrv.dll
+ 2008-11-11 18:57 . 2010-02-24 13:11 455680 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2010-10-05 12:31 . 2010-10-05 12:31 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_f49cf361\System.Drawing.dll
+ 2010-10-05 12:31 . 2010-10-05 12:31 192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_f9006832\System.Drawing.Design.dll
+ 2010-10-05 12:31 . 2010-10-05 12:31 118784 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_fd1c825e\CustomMarshalers.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\a16b8bcca59515281688ec856c034698\WsatConfig.ni.exe
+ 2010-08-12 10:43 . 2010-08-12 10:43 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\672c4d8e3c33e309c1ed90fa4cb85aba\WindowsFormsIntegration.ni.dll
+ 2010-08-12 10:43 . 2010-08-12 10:43 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\cd91a32f4e36ccb2981c72c0d333e928\UIAutomationTypes.ni.dll
+ 2010-08-12 10:43 . 2010-08-12 10:43 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\9df760fdf8071c7b0de78f39de365e6a\UIAutomationClient.ni.dll
+ 2010-08-12 11:18 . 2010-08-12 11:18 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\ff53d5b5249a2841ee196294429f51cf\System.Xml.Linq.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\7f9a1ae146571025fd49914b5c71a39b\System.Web.Routing.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\d0ae809162b55e2fa958739177476af8\System.Web.RegularExpressions.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\b1646e54b708b9824f4193f87eb00c0e\System.Web.Extensions.Design.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\504a93e73da77c502ecf98bfdfc1485e\System.Web.Entity.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\f22334fbd9497d79448fffef515ae0cc\System.Web.Entity.Design.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\af5452305588da228a74e30324681d20\System.Web.DynamicData.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\9d9bca1a8993c427984aa1bc9c165a33\System.Web.Abstractions.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\26d5bf1f7e700c2c19aa9b1da5519b24\System.Transactions.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b000cc703c9d95593b516bf2c2ec316\System.ServiceProcess.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\75e331a5d731d8e207be07adc06dec23\System.Security.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\dd7497aa089340600c8c5af8ab421ff7\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\2a080994f308f347b0497bb8804861cf\System.Net.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\bc1cf48ba7dc00f45d0e949c49ab677a\System.Management.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\904fda53006680a67f917ab638be0305\System.Management.Instrumentation.ni.dll
+ 2010-08-12 11:15 . 2010-08-12 11:15 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\4490976887e2e5a3b594041edbdf5064\System.IO.Log.ni.dll
+ 2010-08-12 11:15 . 2010-08-12 11:15 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\77b9f6f6671aaaeb84c6907d467e792c\System.IdentityModel.Selectors.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\15724a7517f939c9b300f341fb5620b8\System.EnterpriseServices.Wrapper.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\15724a7517f939c9b300f341fb5620b8\System.EnterpriseServices.ni.dll
+ 2010-08-12 10:42 . 2010-08-12 10:42 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\90199b4aa63b1b9c8ed0c3de16eec824\System.Drawing.Design.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\849e98c9f428a12cb581320a23f69dbd\System.DirectoryServices.AccountManagement.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\7a823a4f61cf8c86aad02559f8fed07b\System.DirectoryServices.Protocols.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\ad95820d2e29e8d55c0d8a838214c6e5\System.Data.Services.Design.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\617acb0d900bdde947ec79f7b5ccc183\System.Data.Services.Client.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\165bd290e518b9397ca55192985fdee3\System.Data.Entity.Design.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\41345e34f26854fc1878eae3e4d5d4a5\System.Data.DataSetExtensions.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\ab688d0f9f333ba117832726bfb589c1\System.Configuration.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\b48677ab9aa7a6830785f67b8478b4da\System.Configuration.Install.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\93a0958d5557e2b380647af0171ad354\System.AddIn.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\d0758f84e927e3f0a15a6cde1b96d835\SMSvcHost.ni.exe
+ 2010-08-12 11:16 . 2010-08-12 11:16 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\8043a108e3bb2d3dcc84b547b8085e99\SMDiagnostics.ni.dll
+ 2010-10-05 21:01 . 2010-10-05 21:01 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\72d3aacfca2e1ce835c210f5a1decb36\ServiceModelReg.ni.exe
+ 2010-08-12 10:41 . 2010-08-12 10:41 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e7e7321956e6822b1bf3691c35c842f6\PresentationFramework.Aero.ni.dll
+ 2010-08-12 10:41 . 2010-08-12 10:41 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a14488afff027f0f2985e659449097f5\PresentationFramework.Royale.ni.dll
+ 2010-08-12 10:41 . 2010-08-12 10:41 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\787e60c5dd562cb45887080095d2a3b7\PresentationFramework.Classic.ni.dll
+ 2010-08-12 10:41 . 2010-08-12 10:41 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2313ccc125dcb6a9800048ec1c51ec12\PresentationFramework.Luna.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\5db9c32d9f352162e6da220ca463db0d\MSBuild.ni.exe
+ 2010-08-12 11:16 . 2010-08-12 11:16 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\fcf975f74bd134d8e0fa8f37c5bc6a8c\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\d6b9038136600fbfbbbd7460dc19da19\Microsoft.Build.Utilities.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\585cc7218599e7806521d0e737ba5ffb\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\3057ec53731286e69e389d103c32fa41\Microsoft.Build.Engine.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\914e338ac6e92714f3e32ae5d89bf03b\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\12ae6f3635448471fc9f7d8bfe39c67d\CustomMarshalers.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\daca3c9ad6d867d3fec70d14b4f20cf3\ComSvcConfig.ni.exe
+ 2010-10-05 21:01 . 2010-10-05 21:01 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\af4a3ae6d5c1cafa57002beb487b8d7a\AspNetMMCExt.ni.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2010-06-10 05:54 . 2010-06-10 05:54 970752 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2010-06-10 05:54 . 2010-06-10 05:54 438272 c:\windows\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2009-05-10 00:51 . 2009-05-10 00:51 110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
+ 2010-06-10 05:54 . 2010-06-10 05:54 110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2009-09-10 11:15 . 2009-09-10 11:15 204800 c:\windows\assembly\GAC\ehiPlay\6.0.3000.0__31bf3856ad364e35\ehiPlay.dll
+ 2010-02-07 04:45 . 2010-02-07 04:45 204800 c:\windows\assembly\GAC\ehiPlay\6.0.3000.0__31bf3856ad364e35\ehiplay.dll
- 2009-09-10 11:15 . 2009-09-10 11:15 868352 c:\windows\assembly\GAC\ehepg\6.0.3000.0__31bf3856ad364e35\ehepg.dll
+ 2010-02-07 04:45 . 2010-02-07 04:45 868352 c:\windows\assembly\GAC\ehepg\6.0.3000.0__31bf3856ad364e35\ehepg.dll
+ 2005-01-09 23:47 . 2009-11-21 15:51 471552 c:\windows\AppPatch\aclayers.dll
+ 2010-02-13 19:38 . 2010-04-01 21:43 826368 c:\windows\.jagex_cache_32\runescape\sw3d.dll
+ 2010-09-15 03:59 . 2010-02-22 14:23 382840 c:\windows\$NtUninstallKB982802$\spuninst\updspapi.dll
+ 2010-09-15 03:59 . 2010-02-22 14:23 231288 c:\windows\$NtUninstallKB982802$\spuninst\spuninst.exe
+ 2010-09-15 03:59 . 2009-04-15 14:51 585216 c:\windows\$NtUninstallKB982802$\rpcrt4.dll
+ 2010-08-12 06:07 . 2010-02-22 14:23 382840 c:\windows\$NtUninstallKB982665$\spuninst\updspapi.dll
+ 2010-08-12 06:07 . 2010-02-22 14:23 231288 c:\windows\$NtUninstallKB982665$\spuninst\spuninst.exe
+ 2010-08-12 06:13 . 2009-12-31 16:50 353792 c:\windows\$NtUninstallKB982214$\srv.sys
+ 2010-08-12 06:13 . 2010-02-22 14:23 382840 c:\windows\$NtUninstallKB982214$\spuninst\updspapi.dll
+ 2010-08-12 06:13 . 2010-02-22 14:23 231288 c:\windows\$NtUninstallKB982214$\spuninst\spuninst.exe
+ 2010-08-12 06:07 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB981997$\spuninst\updspapi.dll
+ 2010-08-12 06:07 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB981997$\spuninst\spuninst.exe
+ 2010-08-12 06:12 . 2010-02-22 14:23 382840 c:\windows\$NtUninstallKB981852$\spuninst\updspapi.dll
+ 2010-08-12 06:12 . 2010-02-22 14:23 231288 c:\windows\$NtUninstallKB981852$\spuninst\spuninst.exe
+ 2010-05-26 17:21 . 2009-05-26 09:01 382840 c:\windows\$NtUninstallKB981793$\spuninst\updspapi.dll
+ 2010-05-26 17:21 . 2009-05-26 09:01 231288 c:\windows\$NtUninstallKB981793$\spuninst\spuninst.exe
+ 2010-09-15 03:58 . 2008-04-14 00:12 406016 c:\windows\$NtUninstallKB981322$\usp10.dll
+ 2010-09-15 03:58 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB981322$\spuninst\updspapi.dll
+ 2010-09-15 03:58 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB981322$\spuninst\spuninst.exe
+ 2010-08-12 06:09 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB980436$\spuninst\updspapi.dll
+ 2010-08-12 06:09 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB980436$\spuninst\spuninst.exe
+ 2010-08-12 06:09 . 2009-06-25 08:25 147456 c:\windows\$NtUninstallKB980436$\schannel.dll
+ 2010-04-14 02:25 . 2009-05-26 09:01 382840 c:\windows\$NtUninstallKB980232$\spuninst\updspapi.dll
+ 2010-04-14 02:25 . 2009-05-26 09:01 231288 c:\windows\$NtUninstallKB980232$\spuninst\spuninst.exe
+ 2010-04-14 02:25 . 2009-12-04 18:22 455424 c:\windows\$NtUninstallKB980232$\mrxsmb.sys
+ 2010-06-10 06:02 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB980218$\spuninst\updspapi.dll
+ 2010-06-10 06:02 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB980218$\spuninst\spuninst.exe
+ 2010-06-10 06:02 . 2008-04-14 00:09 285696 c:\windows\$NtUninstallKB980218$\atmfd.dll
+ 2010-06-10 06:00 . 2008-07-08 13:02 382840 c:\windows\$NtUninstallKB980195$\spuninst\updspapi.dll
+ 2010-06-10 06:00 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB980195$\spuninst\spuninst.exe
+ 2010-06-10 06:02 . 2009-04-13 17:42 371424 c:\windows\$NtUninstallKB979904$\spuninst\updspapi.dll
+ 2010-06-10 06:02 . 2009-04-13 17:42 213216 c:\windows\$NtUninstallKB979904$\spuninst\spuninst.exe
+ 2010-04-14 02:26 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB979683$\spuninst\updspapi.dll
+ 2010-04-14 02:26 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB979683$\spuninst\spuninst.exe
+ 2010-06-10 05:59 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB979559$\spuninst\updspapi.dll
+ 2010-06-10 05:59 . 2009-05-26 09:01 231288 c:\windows\$NtUninstallKB979559$\spuninst\spuninst.exe
+ 2010-06-10 05:55 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB979482$\spuninst\updspapi.dll
+ 2010-06-10 05:55 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB979482$\spuninst\spuninst.exe
+ 2010-04-13 18:46 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB979309$\spuninst\updspapi.dll
+ 2010-04-13 18:46 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB979309$\spuninst\spuninst.exe
+ 2010-02-24 09:00 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB979306$\spuninst\updspapi.dll
+ 2010-02-24 09:00 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB979306$\spuninst\spuninst.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB978706$\spuninst\updspapi.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB978706$\spuninst\spuninst.exe
+ 2010-02-10 09:01 . 2008-04-14 00:12 343040 c:\windows\$NtUninstallKB978706$\mspaint.exe
+ 2010-06-10 05:55 . 2007-07-28 04:11 382840 c:\windows\$NtUninstallKB978695_WM9$\spuninst\updspapi.dll
+ 2010-06-10 05:55 . 2007-07-28 04:11 231288 c:\windows\$NtUninstallKB978695_WM9$\spuninst\spuninst.exe
+ 2010-04-13 18:46 . 2008-04-14 00:12 176640 c:\windows\$NtUninstallKB978601$\wintrust.dll
+ 2010-04-13 18:46 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB978601$\spuninst\updspapi.dll
+ 2010-04-13 18:46 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB978601$\spuninst\spuninst.exe
+ 2010-05-12 08:01 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB978542$\spuninst\updspapi.dll
+ 2010-05-12 08:01 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB978542$\spuninst\spuninst.exe
+ 2010-05-12 08:01 . 2008-04-11 19:04 691712 c:\windows\$NtUninstallKB978542$\inetcomm.dll
+ 2010-04-14 02:23 . 2008-06-20 11:08 225856 c:\windows\$NtUninstallKB978338$\tcpip6.sys
+ 2010-04-14 02:23 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB978338$\spuninst\updspapi.dll
+ 2010-04-14 02:23 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB978338$\spuninst\spuninst.exe
+ 2010-04-14 02:23 . 2008-04-14 00:11 100352 c:\windows\$NtUninstallKB978338$\6to4svc.dll
+ 2010-02-10 09:04 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB978262$\spuninst\updspapi.dll
+ 2010-02-10 09:04 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB978262$\spuninst\spuninst.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB978251$\spuninst\updspapi.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB978251$\spuninst\spuninst.exe
+ 2010-02-10 09:01 . 2008-10-24 11:21 455296 c:\windows\$NtUninstallKB978251$\mrxsmb.sys
+ 2010-02-10 09:01 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB978037$\spuninst\updspapi.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB978037$\spuninst\spuninst.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB977914$\spuninst\updspapi.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB977914$\spuninst\spuninst.exe
+ 2010-04-14 02:23 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB977816$\spuninst\updspapi.dll
+ 2010-04-14 02:23 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB977816$\spuninst\spuninst.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB977165$\spuninst\updspapi.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB977165$\spuninst\spuninst.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB975713$\spuninst\updspapi.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB975713$\spuninst\spuninst.exe
+ 2010-02-10 09:01 . 2008-04-14 00:12 474112 c:\windows\$NtUninstallKB975713$\shlwapi.dll
+ 2010-06-10 05:55 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB975562$\spuninst\updspapi.dll
+ 2010-06-10 05:55 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB975562$\spuninst\spuninst.exe
+ 2010-03-11 04:33 . 2009-05-26 23:10 382840 c:\windows\$NtUninstallKB975561$\spuninst\updspapi.dll
+ 2010-03-11 04:33 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB975561$\spuninst\spuninst.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB975560$\spuninst\updspapi.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB975560$\spuninst\spuninst.exe
+ 2010-09-15 03:59 . 2007-07-28 04:11 382840 c:\windows\$NtUninstallKB975558_WM8$\spuninst\updspapi.dll
+ 2010-09-15 03:59 . 2007-07-28 04:11 231288 c:\windows\$NtUninstallKB975558_WM8$\spuninst\spuninst.exe
+ 2010-09-15 03:59 . 2006-10-19 03:47 317440 c:\windows\$NtUninstallKB975558_WM8$\mp4sdecd.dll
+ 2010-01-13 19:47 . 2009-06-16 14:36 119808 c:\windows\$NtUninstallKB972270$\t2embed.dll
+ 2010-01-13 19:47 . 2008-07-08 13:02 382840 c:\windows\$NtUninstallKB972270$\spuninst\updspapi.dll
+ 2010-01-13 19:47 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB972270$\spuninst\spuninst.exe
+ 2010-02-10 09:04 . 2008-12-11 10:57 333952 c:\windows\$NtUninstallKB971468$\srv.sys
+ 2010-02-10 09:04 . 2008-07-08 13:02 382840 c:\windows\$NtUninstallKB971468$\spuninst\updspapi.dll
+ 2010-02-10 09:04 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB971468$\spuninst\spuninst.exe
+ 2010-01-13 19:48 . 2009-05-26 23:10 382840 c:\windows\$NtUninstallKB955759$\spuninst\updspapi.dll
+ 2010-01-13 19:48 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB955759$\spuninst\spuninst.exe
+ 2010-01-13 19:48 . 2008-04-14 00:11 451072 c:\windows\$NtUninstallKB955759$\aclayers.dll
+ 2010-02-07 01:37 . 2005-10-13 18:22 371424 c:\windows\$NtUninstallKB925766$\spuninst\updspapi.dll
+ 2010-02-07 01:37 . 2005-10-13 18:22 213216 c:\windows\$NtUninstallKB925766$\spuninst\spuninst.exe
+ 2010-09-15 03:59 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB2347290$\spuninst\updspapi.dll
+ 2010-09-15 03:59 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB2347290$\spuninst\spuninst.exe
+ 2010-08-03 12:27 . 2010-02-22 14:23 382840 c:\windows\$NtUninstallKB2286198$\spuninst\updspapi.dll
+ 2010-08-03 12:27 . 2010-02-22 14:23 231288 c:\windows\$NtUninstallKB2286198$\spuninst\spuninst.exe
+ 2010-09-15 03:59 . 2009-05-26 09:01 382840 c:\windows\$NtUninstallKB2259922$\spuninst\updspapi.dll
+ 2010-09-15 03:59 . 2009-05-26 09:01 231288 c:\windows\$NtUninstallKB2259922$\spuninst\spuninst.exe
+ 2010-07-14 11:58 . 2010-02-23 00:53 382840 c:\windows\$NtUninstallKB2229593$\spuninst\updspapi.dll
+ 2010-07-14 11:58 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB2229593$\spuninst\spuninst.exe
+ 2010-07-14 11:58 . 2008-04-14 00:12 744448 c:\windows\$NtUninstallKB2229593$\helpsvc.exe
+ 2010-08-12 06:09 . 2010-02-22 14:23 382840 c:\windows\$NtUninstallKB2160329$\spuninst\updspapi.dll
+ 2010-08-12 06:09 . 2010-02-22 14:23 231288 c:\windows\$NtUninstallKB2160329$\spuninst\spuninst.exe
+ 2010-09-30 05:31 . 2010-02-22 14:23 382840 c:\windows\$NtUninstallKB2158563$\spuninst\updspapi.dll
+ 2010-09-30 05:31 . 2010-02-22 14:23 231288 c:\windows\$NtUninstallKB2158563$\spuninst\spuninst.exe
+ 2010-09-15 03:55 . 2010-02-22 14:23 382840 c:\windows\$NtUninstallKB2141007$\spuninst\updspapi.dll
+ 2010-09-15 03:55 . 2010-02-22 14:23 231288 c:\windows\$NtUninstallKB2141007$\spuninst\spuninst.exe
+ 2010-09-15 03:55 . 2010-01-29 15:01 691712 c:\windows\$NtUninstallKB2141007$\inetcomm.dll
+ 2010-09-15 03:59 . 2008-04-14 00:12 293376 c:\windows\$NtUninstallKB2121546$\winsrv.dll
+ 2010-09-15 03:59 . 2010-02-22 14:23 382840 c:\windows\$NtUninstallKB2121546$\spuninst\updspapi.dll
+ 2010-09-15 03:59 . 2010-02-22 14:23 231288 c:\windows\$NtUninstallKB2121546$\spuninst\spuninst.exe
+ 2010-08-12 06:13 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB2115168$\spuninst\updspapi.dll
+ 2010-08-12 06:13 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB2115168$\spuninst\spuninst.exe
+ 2010-08-12 06:12 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB2079403$\spuninst\updspapi.dll
+ 2010-08-12 06:12 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB2079403$\spuninst\spuninst.exe
+ 2010-09-15 03:59 . 2010-02-22 14:23 382840 c:\windows\$hf_mig$\KB982802\update\updspapi.dll
+ 2010-09-15 03:59 . 2010-02-22 14:23 755576 c:\windows\$hf_mig$\KB982802\update\update.exe
+ 2010-09-15 03:59 . 2010-02-22 14:23 231288 c:\windows\$hf_mig$\KB982802\spuninst.exe
+ 2010-07-23 06:13 . 2010-07-23 06:13 590848 c:\windows\$hf_mig$\KB982802\SP3QFE\rpcrt4.dll
+ 2010-08-12 06:07 . 2010-02-22 14:23 382840 c:\windows\$hf_mig$\KB982665\update\updspapi.dll
+ 2010-08-12 06:07 . 2010-02-22 14:23 755576 c:\windows\$hf_mig$\KB982665\update\update.exe
+ 2010-08-12 06:07 . 2010-02-22 14:23 231288 c:\windows\$hf_mig$\KB982665\spuninst.exe
+ 2010-06-10 05:59 . 2010-02-22 14:23 382840 c:\windows\$hf_mig$\KB982381-IE8\update\updspapi.dll
+ 2010-06-10 05:59 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB982381-IE8\update\update.exe
+ 2010-06-10 05:59 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB982381-IE8\spuninst.exe
+ 2010-06-09 11:18 . 2010-05-06 10:36 919040 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\wininet.dll
+ 2010-06-09 11:18 . 2010-05-06 10:36 206848 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\occache.dll
+ 2010-06-09 11:18 . 2010-05-06 10:36 611840 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\mstime.dll
+ 2010-06-09 11:18 . 2010-05-06 10:36 599040 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\msfeeds.dll
+ 2010-06-09 11:17 . 2010-05-06 10:36 247808 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\ieproxy.dll
+ 2010-06-09 11:17 . 2010-05-06 10:36 184320 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\iepeers.dll
+ 2010-06-09 11:17 . 2010-05-06 10:36 743424 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\iedvtool.dll
+ 2010-06-09 11:17 . 2010-05-06 10:36 387584 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\iedkcs32.dll
+ 2010-06-09 11:17 . 2010-05-05 13:55 173056 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\ie4uinit.exe
+ 2010-08-12 06:13 . 2010-02-22 14:23 382840 c:\windows\$hf_mig$\KB982214\update\updspapi.dll
+ 2010-08-12 06:13 . 2010-02-22 14:23 755576 c:\windows\$hf_mig$\KB982214\update\update.exe
+ 2010-08-12 06:13 . 2010-02-22 14:23 231288 c:\windows\$hf_mig$\KB982214\spuninst.exe
+ 2010-08-12 00:22 . 2010-06-21 14:18 354304 c:\windows\$hf_mig$\KB982214\SP3QFE\srv.sys
+ 2010-08-12 06:07 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB981997\update\updspapi.dll
+ 2010-08-12 06:07 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB981997\update\update.exe
+ 2010-08-12 06:07 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB981997\spuninst.exe
+ 2010-08-12 06:12 . 2010-02-22 14:23 382840 c:\windows\$hf_mig$\KB981852\update\updspapi.dll
+ 2010-08-12 06:12 . 2010-02-22 14:23 755576 c:\windows\$hf_mig$\KB981852\update\update.exe
+ 2010-08-12 06:12 . 2010-02-22 14:23 231288 c:\windows\$hf_mig$\KB981852\spuninst.exe
+ 2010-04-14 02:23 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB981332-IE8\update\updspapi.dll
+ 2010-04-14 02:23 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB981332-IE8\update\update.exe
+ 2010-04-14 02:23 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB981332-IE8\spuninst.exe
+ 2010-04-14 00:49 . 2010-03-10 06:18 420352 c:\windows\$hf_mig$\KB981332-IE8\SP3QFE\vbscript.dll
+ 2010-09-15 03:58 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB981322\update\updspapi.dll
+ 2010-09-15 03:58 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB981322\update\update.exe
+ 2010-09-15 03:58 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB981322\spuninst.exe
+ 2010-04-16 15:29 . 2010-04-16 15:29 406016 c:\windows\$hf_mig$\KB981322\SP3QFE\usp10.dll
+ 2010-08-12 06:09 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB980436\update\updspapi.dll
+ 2010-08-12 06:09 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB980436\update\update.exe
+ 2010-08-12 06:09 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB980436\spuninst.exe
+ 2010-06-30 12:23 . 2010-06-30 12:23 149504 c:\windows\$hf_mig$\KB980436\SP3QFE\schannel.dll
+ 2010-04-14 02:25 . 2009-05-26 09:01 382840 c:\windows\$hf_mig$\KB980232\update\updspapi.dll
+ 2010-04-14 02:25 . 2009-05-26 09:01 755576 c:\windows\$hf_mig$\KB980232\update\update.exe
+ 2010-04-14 02:25 . 2009-05-26 09:01 231288 c:\windows\$hf_mig$\KB980232\spuninst.exe
+ 2010-04-14 00:49 . 2010-02-24 11:57 457216 c:\windows\$hf_mig$\KB980232\SP3QFE\mrxsmb.sys
+ 2010-06-10 06:02 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB980218\update\updspapi.dll
+ 2010-06-10 06:02 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB980218\update\update.exe
+ 2010-06-10 06:02 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB980218\spuninst.exe
+ 2010-04-20 05:37 . 2010-04-20 05:37 285824 c:\windows\$hf_mig$\KB980218\SP3QFE\atmfd.dll
+ 2010-06-10 06:00 . 2008-07-08 13:02 382840 c:\windows\$hf_mig$\KB980195\update\updspapi.dll
+ 2010-06-10 06:00 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB980195\update\update.exe
+ 2010-06-10 06:00 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB980195\spuninst.exe
+ 2010-03-31 03:07 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB980182-IE8\update\updspapi.dll
+ 2010-03-31 03:07 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB980182-IE8\update\update.exe
+ 2010-03-31 03:07 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB980182-IE8\spuninst.exe
+ 2010-03-30 20:02 . 2010-02-25 06:19 919040 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\wininet.dll
+ 2010-03-30 20:02 . 2010-02-25 06:19 206848 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\occache.dll
+ 2010-03-30 20:02 . 2010-02-25 06:19 611840 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\mstime.dll
+ 2010-03-30 20:02 . 2010-02-25 06:19 594432 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\msfeeds.dll
+ 2010-03-30 20:02 . 2010-02-25 06:19 247808 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\ieproxy.dll
+ 2010-03-30 20:02 . 2010-02-25 06:19 184320 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\iepeers.dll
+ 2010-03-30 20:02 . 2010-02-25 06:19 387584 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\iedkcs32.dll
+ 2010-03-30 20:02 . 2010-02-24 09:34 173056 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\ie4uinit.exe
+ 2010-04-14 02:26 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB979683\update\updspapi.dll
+ 2010-04-14 02:26 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB979683\update\update.exe
+ 2010-04-14 02:26 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB979683\spuninst.exe
+ 2010-06-10 05:59 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB979559\update\updspapi.dll
+ 2010-06-10 05:59 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB979559\update\update.exe
+ 2010-06-10 05:59 . 2009-05-26 09:01 231288 c:\windows\$hf_mig$\KB979559\spuninst.exe
+ 2010-06-10 05:55 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB979482\update\updspapi.dll
+ 2010-06-10 05:55 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB979482\update\update.exe
+ 2010-06-10 05:55 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB979482\spuninst.exe
+ 2010-04-13 18:46 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB979309\update\updspapi.dll
+ 2010-04-13 18:46 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB979309\update\update.exe
+ 2010-04-13 18:46 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB979309\spuninst.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB978706\update\updspapi.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB978706\update\update.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB978706\spuninst.exe
+ 2009-12-16 18:27 . 2009-12-16 18:27 343040 c:\windows\$hf_mig$\KB978706\SP3QFE\mspaint.exe
+ 2010-04-13 18:46 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB978601\update\updspapi.dll
+ 2010-04-13 18:46 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB978601\update\update.exe
+ 2010-04-13 18:46 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB978601\spuninst.exe
+ 2009-12-24 06:42 . 2009-12-24 06:42 178176 c:\windows\$hf_mig$\KB978601\SP3QFE\wintrust.dll
+ 2010-05-12 08:01 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB978542\update\updspapi.dll
+ 2010-05-12 08:01 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB978542\update\update.exe
+ 2010-05-12 08:01 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB978542\spuninst.exe
+ 2010-01-29 14:53 . 2010-01-29 14:53 691712 c:\windows\$hf_mig$\KB978542\SP3QFE\inetcomm.dll
+ 2010-04-14 02:23 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB978338\update\updspapi.dll
+ 2010-04-14 02:23 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB978338\update\update.exe
+ 2010-04-14 02:23 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB978338\spuninst.exe
+ 2010-02-11 11:36 . 2010-02-11 11:36 226880 c:\windows\$hf_mig$\KB978338\SP3QFE\tcpip6.sys
+ 2010-02-12 04:27 . 2010-02-12 04:27 100864 c:\windows\$hf_mig$\KB978338\SP3QFE\6to4svc.dll
+ 2010-02-10 09:04 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB978262\update\updspapi.dll
+ 2010-02-10 09:04 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB978262\update\update.exe
+ 2010-02-10 09:04 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB978262\spuninst.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB978251\update\updspapi.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB978251\update\update.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB978251\spuninst.exe
+ 2010-02-10 08:58 . 2009-12-04 17:25 456832 c:\windows\$hf_mig$\KB978251\SP3QFE\mrxsmb.sys
+ 2010-01-22 03:10 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB978207-IE8\update\updspapi.dll
+ 2010-01-22 03:10 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB978207-IE8\update\update.exe
+ 2010-01-22 03:10 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB978207-IE8\spuninst.exe
+ 2010-01-22 01:45 . 2009-12-21 19:09 916480 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\wininet.dll
+ 2010-01-22 01:45 . 2009-12-21 19:09 206848 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\occache.dll
+ 2010-01-22 01:45 . 2009-12-21 19:09 594432 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\msfeeds.dll
+ 2010-01-22 01:45 . 2009-12-21 19:09 246272 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\ieproxy.dll
+ 2010-01-22 01:45 . 2009-12-21 19:09 184320 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\iepeers.dll
+ 2010-01-22 01:45 . 2009-12-21 19:09 387584 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\iedkcs32.dll
+ 2010-01-22 01:45 . 2009-12-21 13:22 173056 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\ie4uinit.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB978037\update\updspapi.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB978037\update\update.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB978037\spuninst.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB977914\update\updspapi.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB977914\update\update.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB977914\spuninst.exe
+ 2010-04-14 02:23 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB977816\update\updspapi.dll
+ 2010-04-14 02:23 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB977816\update\update.exe
+ 2010-04-14 02:23 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB977816\spuninst.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB977165\update\updspapi.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB977165\update\update.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB977165\spuninst.exe
+ 2010-02-24 09:01 . 2008-07-08 13:02 382840 c:\windows\$hf_mig$\KB976662-IE8\update\updspapi.dll
+ 2010-02-24 09:01 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB976662-IE8\update\update.exe
+ 2010-02-24 09:01 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB976662-IE8\spuninst.exe
+ 2010-02-24 08:43 . 2009-12-09 05:51 726528 c:\windows\$hf_mig$\KB976662-IE8\SP3QFE\jscript.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB975713\update\updspapi.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB975713\update\update.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB975713\spuninst.exe
+ 2009-12-08 09:01 . 2009-12-08 09:01 474112 c:\windows\$hf_mig$\KB975713\SP3QFE\shlwapi.dll
+ 2010-06-10 05:55 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB975562\update\updspapi.dll
+ 2010-06-10 05:55 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB975562\update\update.exe
+ 2010-06-10 05:55 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB975562\spuninst.exe
+ 2010-03-11 04:33 . 2009-05-26 23:10 382840 c:\windows\$hf_mig$\KB975561\update\updspapi.dll
+ 2010-03-11 04:33 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB975561\update\update.exe
+ 2010-03-11 04:33 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB975561\spuninst.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB975560\update\updspapi.dll
+ 2010-02-10 09:01 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB975560\update\update.exe
+ 2010-02-10 09:01 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB975560\spuninst.exe
+ 2010-01-13 19:47 . 2008-07-08 13:02 382840 c:\windows\$hf_mig$\KB972270\update\updspapi.dll
+ 2010-01-13 19:47 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB972270\update\update.exe
+ 2010-01-13 19:47 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB972270\spuninst.exe
+ 2010-01-13 12:13 . 2009-10-15 16:39 119808 c:\windows\$hf_mig$\KB972270\SP3QFE\t2embed.dll
+ 2010-02-10 09:04 . 2008-07-08 13:02 382840 c:\windows\$hf_mig$\KB971468\update\updspapi.dll
+ 2010-02-10 09:04 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB971468\update\update.exe
+ 2010-02-10 09:04 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB971468\spuninst.exe
+ 2010-02-10 08:58 . 2010-01-01 07:58 353792 c:\windows\$hf_mig$\KB971468\SP3QFE\srv.sys
+ 2010-01-13 19:48 . 2009-05-26 23:10 382840 c:\windows\$hf_mig$\KB955759\update\updspapi.dll
+ 2010-01-13 19:48 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB955759\update\update.exe
+ 2010-01-13 19:48 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB955759\spuninst.exe
+ 2010-01-13 12:13 . 2009-11-21 15:40 471552 c:\windows\$hf_mig$\KB955759\SP3QFE\aclayers.dll
+ 2010-09-15 03:59 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB2347290\update\updspapi.dll
+ 2010-09-15 03:59 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB2347290\update\update.exe
+ 2010-09-15 03:59 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB2347290\spuninst.exe
+ 2010-08-03 12:27 . 2010-02-22 14:23 382840 c:\windows\$hf_mig$\KB2286198\update\updspapi.dll
+ 2010-08-03 12:27 . 2010-02-22 14:23 755576 c:\windows\$hf_mig$\KB2286198\update\update.exe
+ 2010-08-03 12:27 . 2010-02-22 14:23 231288 c:\windows\$hf_mig$\KB2286198\spuninst.exe
+ 2010-09-15 03:59 . 2009-05-26 09:01 382840 c:\windows\$hf_mig$\KB2259922\update\updspapi.dll
+ 2010-09-15 03:59 . 2009-05-26 09:01 755576 c:\windows\$hf_mig$\KB2259922\update\update.exe
+ 2010-09-15 03:59 . 2009-05-26 09:01 231288 c:\windows\$hf_mig$\KB2259922\spuninst.exe
+ 2010-07-14 11:58 . 2010-02-23 00:53 382840 c:\windows\$hf_mig$\KB2229593\update\updspapi.dll
+ 2010-07-14 11:58 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB2229593\update\update.exe
+ 2010-07-14 11:58 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB2229593\spuninst.exe
+ 2010-07-14 11:47 . 2010-06-14 14:38 744448 c:\windows\$hf_mig$\KB2229593\SP3QFE\helpsvc.exe
+ 2010-08-12 06:09 . 2010-02-22 14:23 382840 c:\windows\$hf_mig$\KB2183461-IE8\update\updspapi.dll
+ 2010-08-12 06:09 . 2009-05-26 09:01 755576 c:\windows\$hf_mig$\KB2183461-IE8\update\update.exe
+ 2010-08-12 06:09 . 2009-05-26 09:01 231288 c:\windows\$hf_mig$\KB2183461-IE8\spuninst.exe
+ 2010-08-12 00:21 . 2010-06-24 12:24 919040 c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\wininet.dll
+ 2010-08-12 00:21 . 2010-06-24 12:24 206848 c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\occache.dll
+ 2010-08-12 00:21 . 2010-06-24 12:24 611840 c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\mstime.dll
+ 2010-08-12 00:21 . 2010-06-24 12:24 599040 c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\msfeeds.dll
+ 2010-08-12 00:21 . 2010-06-24 12:24 247808 c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\ieproxy.dll
+ 2010-08-12 00:21 . 2010-06-24 12:24 184320 c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\iepeers.dll
+ 2010-08-12 00:21 . 2010-06-24 12:24 743424 c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\iedvtool.dll
+ 2010-08-12 00:21 . 2010-06-24 12:24 387584 c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\iedkcs32.dll
+ 2010-08-12 00:21 . 2010-06-23 11:30 173056 c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\ie4uinit.exe
+ 2010-08-12 06:09 . 2010-02-22 14:23 382840 c:\windows\$hf_mig$\KB2160329\update\updspapi.dll
+ 2010-08-12 06:09 . 2010-02-22 14:23 755576 c:\windows\$hf_mig$\KB2160329\update\update.exe
+ 2010-08-12 06:09 . 2010-02-22 14:23 231288 c:\windows\$hf_mig$\KB2160329\spuninst.exe
+ 2010-09-15 03:55 . 2010-02-22 14:23 382840 c:\windows\$hf_mig$\KB2141007\update\updspapi.dll
+ 2010-09-15 03:55 . 2010-02-22 14:23 755576 c:\windows\$hf_mig$\KB2141007\update\update.exe
+ 2010-09-15 03:55 . 2010-02-22 14:23 231288 c:\windows\$hf_mig$\KB2141007\spuninst.exe
+ 2010-06-09 07:41 . 2010-06-09 07:41 692736 c:\windows\$hf_mig$\KB2141007\SP3QFE\inetcomm.dll
+ 2010-09-15 03:59 . 2010-02-22 14:23 382840 c:\windows\$hf_mig$\KB2121546\update\updspapi.dll
+ 2010-09-15 03:59 . 2010-02-22 14:23 755576 c:\windows\$hf_mig$\KB2121546\update\update.exe
+ 2010-09-15 03:59 . 2010-02-22 14:23 231288 c:\windows\$hf_mig$\KB2121546\spuninst.exe
+ 2010-06-18 17:43 . 2010-06-18 17:43 293376 c:\windows\$hf_mig$\KB2121546\SP3QFE\winsrv.dll
+ 2010-08-12 06:13 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB2115168\update\updspapi.dll
+ 2010-08-12 06:13 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB2115168\update\update.exe
+ 2010-08-12 06:13 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB2115168\spuninst.exe
+ 2010-08-12 06:12 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB2079403\update\updspapi.dll
+ 2010-08-12 06:12 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB2079403\update\update.exe
+ 2010-08-12 06:12 . 2009-05-26 11:40 231288 c:\windows\$hf_mig$\KB2079403\spuninst.exe
+ 2010-10-13 11:21 . 2010-08-23 16:12 1054208 c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
+ 2005-01-09 23:49 . 2010-04-06 09:52 2462720 c:\windows\system32\WMVCore.dll
+ 2005-01-09 23:48 . 2010-09-10 05:58 1210880 c:\windows\system32\urlmon.dll
+ 2010-08-17 02:06 . 2009-04-16 19:08 1150464 c:\windows\system32\spool\drivers\w32x86\hpdeskjet_d1600_seriaaf2\hpfve70v.dll
+ 2010-08-17 02:06 . 2009-04-16 19:07 1779712 c:\windows\system32\spool\drivers\w32x86\hpdeskjet_d1600_seriaaf2\hpfui70v.dll
+ 2010-08-17 02:06 . 2009-04-16 18:58 1103360 c:\windows\system32\spool\drivers\w32x86\hpdeskjet_d1600_seriaaf2\hpfst70v.dll
+ 2010-08-17 02:06 . 2009-04-16 19:08 1490944 c:\windows\system32\spool\drivers\w32x86\hpdeskjet_d1600_seriaaf2\hpf3r70v.dll
+ 2010-08-17 02:06 . 2009-04-16 19:08 1150464 c:\windows\system32\spool\drivers\w32x86\3\hpfve70v.dll
+ 2010-08-17 02:06 . 2009-04-16 19:07 1779712 c:\windows\system32\spool\drivers\w32x86\3\hpfui70v.dll
+ 2010-08-17 02:06 . 2009-04-16 18:58 1103360 c:\windows\system32\spool\drivers\w32x86\3\hpfst70v.dll
+ 2010-08-17 02:06 . 2009-04-16 19:08 1490944 c:\windows\system32\spool\drivers\w32x86\3\hpf3r70v.dll
+ 2005-01-09 23:48 . 2010-07-27 06:30 8462336 c:\windows\system32\shell32.dll
+ 2010-03-10 05:08 . 2009-08-17 18:37 1461992 c:\windows\system32\ReinstallBackups\0013\DriverFiles\WdfCoInstaller01009.dll
+ 2005-01-09 23:48 . 2010-02-05 18:27 1291776 c:\windows\system32\quartz.dll
+ 2005-01-09 23:48 . 2010-07-16 12:05 1288192 c:\windows\system32\ole32.dll
+ 2005-01-09 23:48 . 2010-04-27 13:59 2146304 c:\windows\system32\ntoskrnl.exe
+ 2004-08-04 05:59 . 2010-04-27 13:05 2024448 c:\windows\system32\ntkrnlpa.exe
- 2005-01-09 23:48 . 2009-07-31 04:35 1172480 c:\windows\system32\msxml3.dll
+ 2005-01-09 23:48 . 2010-06-14 07:41 1172480 c:\windows\system32\msxml3.dll
+ 2005-01-09 23:48 . 2010-09-10 05:58 5957120 c:\windows\system32\mshtml.dll
+ 2009-10-28 03:40 . 2010-07-24 17:51 5612496 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2006-10-17 17:57 . 2010-09-10 05:58 1986560 c:\windows\system32\iertutil.dll
+ 2006-09-06 05:01 . 2009-02-07 02:07 3698584 c:\windows\system32\ieapfltr.dat
+ 2009-05-22 02:46 . 2009-05-22 02:46 1645320 c:\windows\system32\gdiplus.dll
+ 2005-01-09 23:49 . 2010-04-06 09:52 2462720 c:\windows\system32\dllcache\WMVCore.dll
+ 2008-10-16 04:03 . 2010-08-31 13:42 1852800 c:\windows\system32\dllcache\win32k.sys
+ 2006-07-25 20:42 . 2010-09-10 05:58 1210880 c:\windows\system32\dllcache\urlmon.dll
+ 2008-06-17 19:02 . 2010-07-27 06:30 8462336 c:\windows\system32\dllcache\shell32.dll
- 2009-01-08 00:20 . 2009-01-08 00:20 1497088 c:\windows\system32\dllcache\shdocvw.dll
+ 2009-01-07 23:20 . 2009-01-07 23:20 1497088 c:\windows\system32\dllcache\shdocvw.dll
+ 2008-05-07 05:12 . 2010-02-05 18:27 1291776 c:\windows\system32\dllcache\quartz.dll
+ 2010-07-16 12:05 . 2010-07-16 12:05 1288192 c:\windows\system32\dllcache\ole32.dll
+ 2008-10-16 04:03 . 2010-04-28 02:25 2189952 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2008-10-16 04:03 . 2010-04-27 13:05 2024448 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-10-16 04:03 . 2010-04-27 13:05 2066816 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2008-10-16 04:03 . 2010-04-27 13:59 2146304 c:\windows\system32\dllcache\ntkrnlmp.exe
- 2008-11-11 18:57 . 2009-07-31 04:35 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2008-11-11 18:57 . 2010-06-14 07:41 1172480 c:\windows\system32\dllcache\msxml3.dll
- 2009-08-12 10:15 . 2009-07-10 13:27 1315328 c:\windows\system32\dllcache\msoe.dll
+ 2009-08-12 10:15 . 2010-01-29 15:01 1315328 c:\windows\system32\dllcache\msoe.dll
+ 2006-07-28 11:30 . 2010-09-10 05:58 5957120 c:\windows\system32\dllcache\mshtml.dll
+ 2010-03-11 02:20 . 2010-06-18 13:36 3558912 c:\windows\system32\dllcache\moviemk.exe
+ 2007-05-09 10:29 . 2010-09-10 05:58 1986560 c:\windows\system32\dllcache\iertutil.dll
+ 2007-05-09 10:29 . 2009-02-07 02:07 3698584 c:\windows\system32\dllcache\ieapfltr.dat
- 2009-01-08 00:20 . 2009-01-08 00:20 1022976 c:\windows\system32\dllcache\browseui.dll
+ 2009-01-07 23:20 . 2009-01-07 23:20 1022976 c:\windows\system32\dllcache\browseui.dll
+ 2009-11-07 06:06 . 2009-11-07 06:06 1130824 c:\windows\system32\dfshim.dll
+ 2010-09-23 13:06 . 2010-09-23 13:06 1011712 c:\windows\system32\Adobe\Shockwave 11\iml32.dll
+ 2010-09-20 12:56 . 2010-09-20 12:56 2224816 c:\windows\system32\Adobe\Shockwave 11\gt.exe
+ 2010-09-23 13:08 . 2010-09-23 13:08 1802240 c:\windows\system32\Adobe\Shockwave 11\dirapi.dll
+ 2010-04-08 04:48 . 2010-04-08 04:48 5967872 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll
+ 2010-09-22 14:44 . 2010-09-22 14:44 5242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
- 2008-11-25 09:59 . 2008-11-25 09:59 5242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2010-03-23 10:32 . 2010-03-23 10:32 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2010-05-11 11:40 . 2010-05-11 11:40 5812560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
- 2009-08-08 04:51 . 2009-08-08 04:51 5812560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2010-05-11 11:40 . 2010-05-11 11:40 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
- 2008-05-28 06:35 . 2008-05-28 06:35 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2010-09-23 20:55 . 2010-09-23 20:55 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2008-05-28 06:35 . 2008-05-28 06:35 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2010-09-23 20:55 . 2010-09-23 20:55 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2010-09-23 07:26 . 2010-09-23 07:26 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
- 2008-05-28 05:48 . 2008-05-28 05:48 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2010-09-23 07:25 . 2010-09-23 07:25 2523136 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
- 2008-05-28 05:48 . 2008-05-28 05:48 2523136 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
- 2008-05-28 05:43 . 2008-05-28 05:43 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2010-09-23 20:55 . 2010-09-23 20:55 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2010-06-17 08:25 . 2010-06-17 08:25 3906560 c:\windows\Installer\f80d6c.msp
+ 2010-08-13 21:22 . 2010-08-13 21:22 5811200 c:\windows\Installer\78638.msp
+ 2010-08-17 02:01 . 2010-08-17 02:01 1097216 c:\windows\Installer\60d02d.msi
+ 2010-08-17 02:01 . 2010-08-17 02:01 1888768 c:\windows\Installer\60d025.msi
+ 2010-08-17 01:59 . 2010-08-17 01:59 2974720 c:\windows\Installer\60cff0.msi
+ 2010-08-17 01:58 . 2010-08-17 01:58 1221120 c:\windows\Installer\60cfce.msi
+ 2010-07-20 16:41 . 2010-07-20 16:41 3750912 c:\windows\Installer\5858c6.msp
+ 2010-05-07 12:04 . 2010-05-07 12:04 4272128 c:\windows\Installer\50c52c.msi
+ 2009-11-09 05:25 . 2009-11-09 05:25 1935360 c:\windows\Installer\445dbbe.msp
+ 2010-09-30 11:15 . 2010-09-30 11:15 1223680 c:\windows\Installer\42a47.msi
+ 2010-08-13 21:22 . 2010-08-13 21:22 5811200 c:\windows\Installer\41ac9e.msp
+ 2010-04-12 03:17 . 2010-04-12 03:17 2607104 c:\windows\Installer\3fdf9a4.msp
+ 2010-04-12 03:17 . 2010-04-12 03:17 4210688 c:\windows\Installer\3fdf9a3.msp
+ 2010-09-23 12:39 . 2010-09-23 12:39 4265472 c:\windows\Installer\28c98f1.msp
+ 2010-09-02 17:28 . 2010-09-02 17:28 3749376 c:\windows\Installer\20222a.msp
+ 2010-09-24 10:26 . 2010-09-24 10:26 8233984 c:\windows\Installer\1fbe4.msp
+ 2010-08-25 22:06 . 2010-08-25 22:06 6479360 c:\windows\Installer\16cff9b.msp
+ 2010-04-02 18:53 . 2010-04-02 18:53 7220736 c:\windows\Installer\150dc76.msp
+ 2009-12-18 07:16 . 2009-12-18 07:16 1949696 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\rt3d.dll
+ 2010-06-10 05:59 . 2010-02-25 06:24 1209344 c:\windows\ie8updates\KB982381-IE8\urlmon.dll
+ 2010-06-10 05:59 . 2010-02-25 06:24 5944832 c:\windows\ie8updates\KB982381-IE8\mshtml.dll
+ 2010-06-10 05:59 . 2010-02-25 06:24 1985536 c:\windows\ie8updates\KB982381-IE8\iertutil.dll
+ 2010-05-18 18:46 . 2009-03-08 09:34 1206784 c:\windows\ie8updates\KB980182-IE8\urlmon.dll
+ 2010-05-18 18:46 . 2009-03-08 09:41 5937152 c:\windows\ie8updates\KB980182-IE8\mshtml.dll
+ 2010-05-18 18:46 . 2009-03-08 09:32 1985024 c:\windows\ie8updates\KB980182-IE8\iertutil.dll
+ 2010-10-13 12:54 . 2010-06-24 12:22 1210368 c:\windows\ie8updates\KB2360131-IE8\urlmon.dll
+ 2010-10-13 12:54 . 2010-06-24 12:22 5951488 c:\windows\ie8updates\KB2360131-IE8\mshtml.dll
+ 2010-10-13 12:54 . 2010-06-24 12:21 1986560 c:\windows\ie8updates\KB2360131-IE8\iertutil.dll
+ 2010-08-12 06:09 . 2010-05-06 10:41 1209344 c:\windows\ie8updates\KB2183461-IE8\urlmon.dll
+ 2010-08-12 06:09 . 2010-05-06 10:41 5950976 c:\windows\ie8updates\KB2183461-IE8\mshtml.dll
+ 2010-08-12 06:09 . 2010-05-06 10:41 1985536 c:\windows\ie8updates\KB2183461-IE8\iertutil.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 1160192 c:\windows\ie8\urlmon.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 1160192 c:\windows\ie8\urlmon.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 3595264 c:\windows\ie8\mshtml.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 3595264 c:\windows\ie8\mshtml.dll
+ 2010-05-18 11:53 . 2009-02-20 18:09 6066176 c:\windows\ie8\ieframe.dll
- 2010-01-01 22:14 . 2009-02-20 18:09 6066176 c:\windows\ie8\ieframe.dll
+ 2010-05-18 11:53 . 2008-07-09 14:25 2455488 c:\windows\ie8\ieapfltr.dat
- 2010-01-01 22:14 . 2008-07-09 14:25 2455488 c:\windows\ie8\ieapfltr.dat
+ 2008-10-16 04:03 . 2010-04-28 02:25 2189952 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-10-16 04:03 . 2010-04-27 13:05 2024448 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-10-16 04:03 . 2010-04-27 13:05 2066816 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-16 04:03 . 2010-04-27 13:59 2146304 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2010-10-05 12:31 . 2010-10-05 12:31 4792320 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_7b825b0c\System.dll
+ 2010-10-05 12:30 . 2010-10-05 12:30 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_70b679fa\System.dll
+ 2010-10-05 12:31 . 2010-10-05 12:31 5513216 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_df96a4b7\System.Xml.dll
+ 2010-10-05 12:30 . 2010-10-05 12:30 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_60f31e48\System.Xml.dll
+ 2010-10-05 12:30 . 2010-10-05 12:30 3018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_e64cc06b\System.Windows.Forms.dll
+ 2010-10-05 12:31 . 2010-10-05 12:31 7884800 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_ac5c5678\System.Windows.Forms.dll
+ 2010-10-05 12:31 . 2010-10-05 12:31 2244608 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_4f203f87\System.Drawing.dll
+ 2010-10-05 12:31 . 2010-10-05 12:31 3395584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_ac2e3726\System.Design.dll
+ 2010-10-05 12:31 . 2010-10-05 12:31 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_29c4c49a\System.Design.dll
+ 2010-10-05 12:31 . 2010-10-05 12:31 8908800 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_9b31f685\mscorlib.dll
+ 2010-10-05 12:31 . 2010-10-05 12:31 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_59352fad\mscorlib.dll
+ 2010-08-12 11:18 . 2010-08-12 11:18 3671040 c:\windows\assembly\NativeImages_v2.0.50727_32\ZuneShell\f1455bf4c0cbb526c24e81b13dc86a9e\ZuneShell.ni.dll
+ 2010-08-12 11:18 . 2010-08-12 11:18 2179584 c:\windows\assembly\NativeImages_v2.0.50727_32\ZuneDBApi\e4df923ad1368f580a9b94a392676cbe\ZuneDBApi.ni.dll
+ 2010-08-12 06:13 . 2010-08-12 06:13 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cec7ecb8eac09dd630d180ce87d23b80\WindowsBase.ni.dll
+ 2010-08-12 11:18 . 2010-08-12 11:18 4542976 c:\windows\assembly\NativeImages_v2.0.50727_32\UIX\89c9cf99b4c6a99fea85fe0ba5a26162\UIX.ni.dll
+ 2010-08-12 11:18 . 2010-08-12 11:18 1831936 c:\windows\assembly\NativeImages_v2.0.50727_32\UIX.RenderApi\4cd3b3f7855925060537064e6c40137e\UIX.RenderApi.ni.dll
+ 2010-08-12 10:43 . 2010-08-12 10:43 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\b7f6e7b265f9aae807ddc4284563e550\UIAutomationClientsideProviders.ni.dll
+ 2010-08-12 06:13 . 2010-08-12 06:13 7949824 c:\windows\assembly\NativeImages_v2.0.50727_32\System\08ffa4d388d5f007869aa7651c458e7c\System.ni.dll
+ 2010-08-12 10:43 . 2010-08-12 10:43 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\a6dbe24cbfe3ab6b318ed3095cc572d8\System.Xml.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\bec60fe2e934a6284224ab45b0e981e2\System.WorkflowServices.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\09da139c48e2f5e76994a5c0f2e5b19e\System.Workflow.Runtime.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\6809417da74ff937e18b3034f1eac2f2\System.Workflow.ComponentModel.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\6c91ee82035d30efa8893e7b0396bbb0\System.Workflow.Activities.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\181254ba0cb690decedb950fd26d7bea\System.Web.Services.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\4200f716e9a41cb91d17516ba864e586\System.Web.Mobile.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 2405376 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\da367bc2ecf2c9c5b4f858b6dba9e2ea\System.Web.Extensions.ni.dll
+ 2010-08-12 10:42 . 2010-08-12 10:42 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\5eb08849d17b272ed2a393420cb0305b\System.Speech.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\8e34e273d036b7468fc4e951a1fde437\System.ServiceModel.Web.ni.dll
+ 2010-08-12 11:15 . 2010-08-12 11:15 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\8061a0f5c1c2ee0549e19224352f67fa\System.Runtime.Serialization.ni.dll
+ 2010-08-12 10:42 . 2010-08-12 10:42 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\99767d4df92b83fdfb06012512722ec1\System.Printing.ni.dll
+ 2010-10-05 21:01 . 2010-10-05 21:01 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\095bb4f033374647b6d66c51f16bb886\System.IdentityModel.ni.dll
+ 2010-08-12 10:42 . 2010-08-12 10:42 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dcc0244092fe52e6885b50be25ef3b31\System.Drawing.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\d20b7e58607ddb1ded9b687627ae8c21\System.DirectoryServices.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\daa33674d4250e38a24b70180d209ac8\System.Deployment.ni.dll
+ 2010-08-12 10:41 . 2010-08-12 10:41 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\f04ef00e652a8655a717639e8aeb7b63\System.Data.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\f0470c2be4e6bb1dadbeed43e4e8af5c\System.Data.SqlXml.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\b8c9267d87b7358e1a5f00bf1572c313\System.Data.Services.ni.dll
+ 2010-08-12 10:41 . 2010-08-12 10:41 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\c18c236a09e715138daec2e25be205bb\System.Data.Linq.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\6ce886492d9b6a34555be3f328682ec2\System.Data.Entity.ni.dll
+ 2010-08-12 10:41 . 2010-08-12 10:41 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\faeda674832135a080bc73eda51813ff\System.Core.ni.dll
+ 2010-08-12 10:41 . 2010-08-12 10:41 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\3e85c3d63ce3c3f37061aa626feb2a52\ReachFramework.ni.dll
+ 2010-08-12 10:41 . 2010-08-12 10:41 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\bf67db30179ff6e8cb1bdbaa290d122e\PresentationUI.ni.dll
+ 2010-08-12 06:13 . 2010-08-12 06:13 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\835786d8a0caabae09ad440f6e3abfc6\PresentationBuildTasks.ni.dll
+ 2010-10-05 21:01 . 2010-10-05 21:01 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\a27783547338dbebf84101a685ba641b\Microsoft.VisualBasic.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\773d7bf69a9a0c0556aa41f53e75ab05\Microsoft.Transactions.Bridge.ni.dll
+ 2010-08-12 11:17 . 2010-08-12 11:17 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\16ff33f07efdb9da2a18e27585c604be\Microsoft.JScript.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\d0fb91b296616a1a844bf265947018ee\Microsoft.Build.Tasks.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\892e993c8df1c75081113131dc429c15\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2010-08-12 11:16 . 2010-08-12 11:16 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\d0beebd2c9045158cdcd4bd5987b717b\Microsoft.Build.Engine.ni.dll
+ 2010-06-24 11:27 . 2010-06-24 11:27 1249280 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2010-10-05 12:33 . 2010-10-05 12:33 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
- 2009-05-10 00:57 . 2009-05-10 00:57 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
+ 2010-06-10 05:54 . 2010-06-10 05:54 5967872 c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2010-06-24 11:27 . 2010-06-24 11:27 5279744 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2009-10-17 03:14 . 2009-10-17 03:14 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2009-10-17 03:15 . 2009-10-17 03:15 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2009-05-10 00:51 . 2009-05-10 00:51 4210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2010-06-24 11:27 . 2010-06-24 11:27 4210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2010-10-05 12:32 . 2010-10-05 12:32 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2010-10-05 12:30 . 2010-10-05 12:30 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2009-10-17 03:09 . 2009-10-17 03:09 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2009-10-17 03:09 . 2009-10-17 03:09 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2010-10-05 12:30 . 2010-10-05 12:30 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2010-02-07 04:45 . 2010-02-07 04:45 1863680 c:\windows\assembly\GAC\EhCM\6.0.3000.0__31bf3856ad364e35\ehcm.dll
- 2009-09-10 11:15 . 2009-09-10 11:15 1863680 c:\windows\assembly\GAC\EhCM\6.0.3000.0__31bf3856ad364e35\EhCM.dll
+ 2010-08-12 06:07 . 2009-10-23 15:28 3558912 c:\windows\$NtUninstallKB981997$\moviemk.exe
+ 2010-08-12 06:12 . 2010-02-16 14:08 2146304 c:\windows\$NtUninstallKB981852$\ntoskrnl.exe
+ 2010-08-12 06:12 . 2010-02-16 13:25 2024448 c:\windows\$NtUninstallKB981852$\ntkrpamp.exe
+ 2010-08-12 06:12 . 2010-02-16 13:25 2024448 c:\windows\$NtUninstallKB981852$\ntkrnlpa.exe
+ 2010-08-12 06:12 . 2010-02-16 14:08 2146304 c:\windows\$NtUninstallKB981852$\ntkrnlmp.exe
+ 2010-04-14 02:26 . 2009-12-08 19:26 2145280 c:\windows\$NtUninstallKB979683$\ntoskrnl.exe
+ 2010-04-14 02:26 . 2009-12-08 18:43 2023936 c:\windows\$NtUninstallKB979683$\ntkrpamp.exe
+ 2010-04-14 02:26 . 2009-12-08 18:43 2023936 c:\windows\$NtUninstallKB979683$\ntkrnlpa.exe
+ 2010-04-14 02:26 . 2009-12-08 19:26 2145280 c:\windows\$NtUninstallKB979683$\ntkrnlmp.exe
+ 2010-06-10 05:59 . 2009-08-14 13:21 1850624 c:\windows\$NtUninstallKB979559$\win32k.sys
+ 2010-06-10 05:55 . 2009-05-20 09:56 2458112 c:\windows\$NtUninstallKB978695_WM9$\wmvcore.dll
+ 2010-05-12 08:01 . 2009-07-10 13:27 1315328 c:\windows\$NtUninstallKB978542$\msoe.dll
+ 2010-02-10 09:01 . 2009-08-04 15:13 2145280 c:\windows\$NtUninstallKB977165$\ntoskrnl.exe
+ 2010-02-10 09:01 . 2009-08-04 14:20 2023936 c:\windows\$NtUninstallKB977165$\ntkrpamp.exe
+ 2010-02-10 09:01 . 2009-08-04 14:20 2023936 c:\windows\$NtUninstallKB977165$\ntkrnlpa.exe
+ 2010-02-10 09:01 . 2009-08-04 15:13 2145280 c:\windows\$NtUninstallKB977165$\ntkrnlmp.exe
+ 2010-06-10 05:55 . 2009-11-27 17:11 1291776 c:\windows\$NtUninstallKB975562$\quartz.dll
+ 2010-03-11 04:33 . 2008-04-14 00:12 3558912 c:\windows\$NtUninstallKB975561$\moviemk.exe
+ 2010-02-10 09:01 . 2009-06-03 19:09 1291264 c:\windows\$NtUninstallKB975560$\quartz.dll
+ 2010-08-03 12:27 . 2008-06-17 19:02 8461312 c:\windows\$NtUninstallKB2286198$\shell32.dll
+ 2010-08-12 06:09 . 2010-05-02 05:22 1851264 c:\windows\$NtUninstallKB2160329$\win32k.sys
+ 2010-08-12 06:12 . 2009-07-31 04:35 1172480 c:\windows\$NtUninstallKB2079403$\msxml3.dll
+ 2010-06-09 11:17 . 2010-05-06 10:36 1209856 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\urlmon.dll
+ 2010-06-09 11:17 . 2010-05-06 10:36 5953024 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\mshtml.dll
+ 2010-06-09 11:17 . 2010-05-06 10:36 1986048 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\iertutil.dll
+ 2010-08-12 00:21 . 2010-06-18 13:43 3558912 c:\windows\$hf_mig$\KB981997\SP3QFE\moviemk.exe
+ 2010-08-12 00:22 . 2010-04-27 13:50 2190080 c:\windows\$hf_mig$\KB981852\SP3QFE\ntoskrnl.exe
+ 2010-08-12 00:22 . 2010-04-27 13:14 2024448 c:\windows\$hf_mig$\KB981852\SP3QFE\ntkrpamp.exe
+ 2010-04-28 12:14 . 2010-04-28 12:14 2066944 c:\windows\$hf_mig$\KB981852\SP3QFE\ntkrnlpa.exe
+ 2010-08-12 00:22 . 2010-04-27 13:54 2146304 c:\windows\$hf_mig$\KB981852\SP3QFE\ntkrnlmp.exe
+ 2010-03-30 20:02 . 2010-02-25 06:19 1209856 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\urlmon.dll
+ 2010-03-30 20:02 . 2010-02-25 06:19 5946880 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\mshtml.dll
+ 2010-03-30 20:02 . 2010-02-25 06:19 1986048 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\iertutil.dll
+ 2010-04-14 00:49 . 2010-02-16 12:52 2190080 c:\windows\$hf_mig$\KB979683\SP3QFE\ntoskrnl.exe
+ 2010-04-14 00:49 . 2010-02-16 12:12 2024448 c:\windows\$hf_mig$\KB979683\SP3QFE\ntkrpamp.exe
+ 2010-04-14 00:49 . 2010-02-16 12:12 2066944 c:\windows\$hf_mig$\KB979683\SP3QFE\ntkrnlpa.exe
+ 2010-04-14 00:49 . 2010-02-16 12:50 2146304 c:\windows\$hf_mig$\KB979683\SP3QFE\ntkrnlmp.exe
+ 2010-05-02 06:34 . 2010-05-02 06:34 1860352 c:\windows\$hf_mig$\KB979559\SP3QFE\win32k.sys
+ 2010-01-29 14:53 . 2010-01-29 14:53 1315328 c:\windows\$hf_mig$\KB978542\SP3QFE\msoe.dll
+ 2010-01-22 01:45 . 2009-12-21 19:09 1209344 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\urlmon.dll
+ 2010-01-22 01:45 . 2009-12-21 19:09 5945856 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\mshtml.dll
+ 2010-01-22 01:45 . 2009-12-21 19:09 1986048 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\iertutil.dll
+ 2009-12-09 05:52 . 2009-12-09 05:52 2189312 c:\windows\$hf_mig$\KB977165\SP3QFE\ntoskrnl.exe
+ 2010-02-10 08:57 . 2009-12-08 17:40 2023936 c:\windows\$hf_mig$\KB977165\SP3QFE\ntkrpamp.exe
+ 2009-12-09 05:10 . 2009-12-09 05:10 2066176 c:\windows\$hf_mig$\KB977165\SP3QFE\ntkrnlpa.exe
+ 2010-02-10 08:57 . 2009-12-08 18:20 2145280 c:\windows\$hf_mig$\KB977165\SP3QFE\ntkrnlmp.exe
+ 2010-02-05 18:29 . 2010-02-05 18:29 1291776 c:\windows\$hf_mig$\KB975562\SP3QFE\quartz.dll
+ 2010-03-11 02:20 . 2009-10-23 14:53 3558912 c:\windows\$hf_mig$\KB975561\SP3QFE\moviemk.exe
+ 2009-11-27 17:23 . 2009-11-27 17:23 1291776 c:\windows\$hf_mig$\KB975560\SP3QFE\quartz.dll
+ 2010-07-27 06:28 . 2010-07-27 06:28 8463360 c:\windows\$hf_mig$\KB2286198\SP3QFE\shell32.dll
+ 2010-08-12 00:21 . 2010-06-24 12:24 1211904 c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\urlmon.dll
+ 2010-08-12 00:21 . 2010-06-24 12:24 5954560 c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\mshtml.dll
+ 2010-08-12 00:21 . 2010-06-24 12:24 1987072 c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\iertutil.dll
+ 2010-06-24 02:14 . 2010-06-24 02:14 1861120 c:\windows\$hf_mig$\KB2160329\SP3QFE\win32k.sys
+ 2010-06-14 07:39 . 2010-06-14 07:39 1172480 c:\windows\$hf_mig$\KB2079403\SP3QFE\msxml3.dll
+ 2005-01-09 23:49 . 2010-08-26 04:36 10841088 c:\windows\system32\wmp.dll
- 2005-01-09 23:49 . 2009-07-14 04:43 10841088 c:\windows\system32\wmp.dll
+ 2009-03-17 02:27 . 2010-10-13 12:51 35385288 c:\windows\system32\MRT.exe
+ 2006-11-08 03:03 . 2010-09-10 05:58 11080192 c:\windows\system32\ieframe.dll
- 2009-07-14 04:43 . 2009-07-14 04:43 10841088 c:\windows\system32\dllcache\wmp.dll
+ 2009-07-14 04:43 . 2010-08-26 04:36 10841088 c:\windows\system32\dllcache\wmp.dll
+ 2007-05-09 10:29 . 2010-09-10 05:58 11080192 c:\windows\system32\dllcache\ieframe.dll
+ 2010-04-03 00:29 . 2010-04-03 00:29 11413504 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M979906\M979906Uninstall.msp
+ 2010-09-24 19:08 . 2010-09-24 19:08 11430400 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2416447\M2416447Uninstall.msp
+ 2010-01-20 09:00 . 2010-01-20 09:00 15710720 c:\windows\Installer\ef1d58.msp
+ 2010-06-04 06:12 . 2010-06-04 06:12 20242432 c:\windows\Installer\5bfe061.msp
+ 2010-09-02 12:52 . 2010-09-02 12:52 20303872 c:\windows\Installer\5a7e3c.msp
+ 2010-05-19 18:08 . 2010-05-19 18:08 11408896 c:\windows\Installer\5858bc.msp
+ 2010-03-31 06:23 . 2010-03-31 06:23 15638528 c:\windows\Installer\445dbcb.msp
+ 2010-05-11 16:30 . 2010-05-11 16:30 11194880 c:\windows\Installer\3fdf9f8.msp
+ 2010-04-02 17:30 . 2010-04-02 17:30 17456640 c:\windows\Installer\3fdf9ef.msp
+ 2010-04-24 22:09 . 2010-04-24 22:09 11750912 c:\windows\Installer\3fdf9bc.msp
+ 2010-04-12 03:17 . 2010-04-12 03:17 14599680 c:\windows\Installer\3fdf9b3.msp
+ 2010-09-30 05:32 . 2010-09-30 05:32 20303872 c:\windows\Installer\3f39167.msp
+ 2010-09-24 12:08 . 2010-09-24 12:08 17518080 c:\windows\Installer\28c98e7.msp
+ 2010-03-22 21:03 . 2010-03-22 21:03 11732992 c:\windows\Installer\1894834.msp
+ 2010-07-20 00:57 . 2010-07-20 00:57 11484672 c:\windows\Installer\163ebe7.msi
+ 2009-12-18 13:30 . 2009-12-18 13:30 13313464 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\AcroRd32.dll
+ 2009-04-03 23:46 . 2009-04-03 23:46 17314688 c:\windows\Installer\$PatchCache$\Managed\00002159FA0090400000000000F01FEC\12.0.6425\MSO.DLL
+ 2010-06-10 05:59 . 2010-02-25 16:54 11070976 c:\windows\ie8updates\KB982381-IE8\ieframe.dll
+ 2010-05-18 18:46 . 2009-03-08 09:39 11063808 c:\windows\ie8updates\KB980182-IE8\ieframe.dll
+ 2010-10-13 12:54 . 2010-06-24 22:51 11077120 c:\windows\ie8updates\KB2360131-IE8\ieframe.dll
+ 2010-08-12 06:09 . 2010-05-06 10:41 11076096 c:\windows\ie8updates\KB2183461-IE8\ieframe.dll
+ 2010-07-20 00:56 . 2010-07-20 00:56 53667100 c:\windows\Downloaded Installations\{69CC78F2-D6EE-4702-A0C8-1913BB2D9F01}\Palm.msi
+ 2010-08-12 10:42 . 2010-08-12 10:42 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\439c466b60614915587c5273eaf0ca7f\System.Windows.Forms.ni.dll
+ 2010-10-05 21:02 . 2010-10-05 21:02 11800576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\41f436dae3c8146752d06130f7331527\System.Web.ni.dll
+ 2010-10-05 21:01 . 2010-10-05 21:01 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\75aeb590008d6e166f7be18f935c52d2\System.ServiceModel.ni.dll
+ 2010-10-05 20:32 . 2010-10-05 20:32 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\fdc42078fd10e4dc8b05087900c63977\System.Design.ni.dll
+ 2010-08-12 10:39 . 2010-08-12 10:39 14328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a632f3ef85ffd35341b383eed577cb93\PresentationFramework.ni.dll
+ 2010-08-12 06:13 . 2010-08-12 06:13 12215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\f00db8db51f5707c7fe52c0683dc6136\PresentationCore.ni.dll
+ 2010-08-12 06:12 . 2010-08-12 06:12 11490816 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7bffd7ff2009f421fe5d229927588496\mscorlib.ni.dll
+ 2010-05-06 21:06 . 2010-05-06 21:06 11078144 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\ieframe.dll
+ 2010-03-30 20:02 . 2010-02-25 06:19 11073024 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\ieframe.dll
+ 2009-12-22 20:09 . 2009-12-22 20:09 11070976 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\ieframe.dll
+ 2010-08-12 00:21 . 2010-06-24 12:24 11079168 c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-27 68856]
"SansaDispatch"="c:\documents and settings\Owner.Kids\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe" [2009-05-22 79872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"CHotkey"="mHotkey.exe" [2004-12-09 550912]
"ledpointer"="CNYHKey.exe" [2004-03-03 5576704]
"showwnd"="showwnd.exe" [2003-09-19 36864]
"readericon"="c:\program files\Digital Media Reader\readericon45G.exe" [2005-12-10 139264]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-18 7204864]
"nwiz"="nwiz.exe" [2005-09-18 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-09-18 86016]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-02-26 966656]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"PivotSoftware"="c:\program files\WinPortrait\wpctrl.exe" [2005-01-26 698104]
"P17Helper"="P17.dll" [2005-05-03 64512]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-09-24 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-08-06 202256]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ WinCinema Manager.lnk
backup=c:\windows\pss\ WinCinema Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EzTune.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\EzTune.lnk
backup=c:\windows\pss\EzTune.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk
backup=c:\windows\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2010-03-18 16:19 207360 ----a-w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2006-12-06 03:55 54832 ----a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
2003-05-08 16:00 49152 ----a-w- c:\program files\ScanSoft\OmniPageSE2.0\opwareSE2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-01-05 22:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2006-11-23 20:10 56928 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpiralFrog]
2009-02-11 17:06 535864 ----a-w- c:\program files\SpiralFrog\Spiralfrog.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
2010-01-07 20:38 158448 ----a-w- c:\program files\Zune\ZuneLauncher.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"=

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [5/9/2008 6:08 PM 24652]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/20/2009 11:32 PM 135664]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-08-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]

2010-10-30 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-31 19:27]

2010-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb7011d8578d44.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-21 04:32]

2010-10-30 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-351961390-340104498-4275350937-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 08:02]

2010-10-30 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-351961390-340104498-4275350937-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 08:02]

2010-07-03 c:\windows\Tasks\User_Feed_Synchronization-{6914C367-B0EA-45B8-9849-D9FFEBE6817F}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyServer = http=127.0.0.1:5577
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
Trusted Zone: amaena.com
Trusted Zone: antispyexpert.com
Trusted Zone: avsystemcare.com
Trusted Zone: imageservr.com
Trusted Zone: imagesrvr.com
Trusted Zone: onerateld.com
Trusted Zone: safetydownload.com
Trusted Zone: spyguardpro.com
Trusted Zone: storageguardsoft.com
Trusted Zone: trustedantivirus.com
Trusted Zone: virusremover2008.com
Trusted Zone: virusschlacht.com
DPF: {297DE2B6-509A-4B36-93C5-A65276606900} - hxxp://www.in.honda.com/rraaapps/rraasec/codebase/RRAAINAX/RraainAX.CAB
FF - ProfilePath - c:\documents and settings\Owner.Kids\Application Data\Mozilla\Firefox\Profiles\2wb7o8a2.default\
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\Owner.Kids\Application Data\Mozilla\Firefox\Profiles\2wb7o8a2.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSeymour.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\Owner.Kids\Application Data\Facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\Owner.Kids\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPcol305.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\SpiralFrog\NPSFDMGR.dll
FF - plugin: c:\program files\spiralfrog\wmp\np-mswmp.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-30 02:27
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
PivotSoftware = "c:\program files\WinPortrait\wpctrl.exe"??????????????w?????#??????X ??????????\ ?|???????|????????,E???????!??????????????????????????( ??????Service Pack 2?????????????????????????????????????????????????????????????????????????????????????????????????????
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
SansaDispatch = c:\documents and settings\Owner.Kids\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe?.lnk??VDDRZU[N~SRYC^CN?ARED^XY ?????????:=?????GEXTRDDXEvET_^CRTCBER ?o???:=?????YVZR ?dVYDVs^

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(11444)
c:\windows\system32\WININET.dll
c:\program files\WinPortrait\WinpHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-10-30 02:30:27
ComboFix-quarantined-files.txt 2010-10-30 07:30
ComboFix2.txt 2010-01-01 22:44

Pre-Run: 237,134,630,912 bytes free
Post-Run: 237,146,030,080 bytes free

- - End Of File - - ACF9658085DCCD101FB7343D1543827A

#9 surf

surf
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:38 PM

Posted 31 October 2010 - 11:07 AM

Also more trouble, Internet being blocked all browsers now. My husband ran malware and found these and quarantined them. no web access now. network is fine. here is the log from MalwareBytes
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 5005

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

10/31/2010 9:34:15 AM
mbam-log-2010-10-31 (09-34-15).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 304188
Time elapsed: 1 hour(s), 54 minute(s), 21 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (explorer.exe,C:\Documents and Settings\Owner.Kids\Application Data\Microsoft\Windows\shell.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Owner.Kids\Application Data\Microsoft\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner.Kids\Local Settings\temp\6fb37beb.exe (Trojan.FakeAV) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner.Kids\Local Settings\temp\8b2cf326.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner.Kids\Application Data\hotfix.exe (Trojan.FakeAV) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner.Kids\Desktop\mstsc.exe (Trojan.FakeAV) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner.Kids\Application Data\Microsoft\Windows\shell.exe (Trojan.Shell) -> Quarantined and deleted successfully.

#10 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:06:38 PM

Posted 31 October 2010 - 05:13 PM

Combofix appears to have not run the script and left in everything that needed to go. MBAM has then been run (without my permission) and removed things that I would expect Combofix to have removed. Something isn't right so we'll run a different scanner and use that to remove the problems. Please do not run other tools because that makes things way too complicated.


Please download OTL

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.

Posted Image
m0le is a proud member of UNITE

#11 surf

surf
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:38 PM

Posted 31 October 2010 - 07:48 PM

Here are the two logs. My husband said "Sorry" for running RKILL then MBAM this morning. He said he didn't think about me receiving expert help on this computer. I don't believe that either of those two scans found the hidden stuff. I think what was found was something newly acquired from Saturday night anyway.

OTL logfile created on: 10/31/2010 7:29:00 PM - Run 1
OTL by OldTimer - Version 3.2.17.2
Folder = C:\Documents and Settings\Owner.Kids\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 58.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 293.75 Gb Total Space | 220.50 Gb Free Space | 75.06% Space Free | Partition Type: NTFS
Drive D: | 4.33 Gb Total Space | 2.38 Gb Free Space | 55.06% Space Free | Partition Type: FAT32

Computer Name: KIDS | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner.Kids\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
PRC - C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Owner.Kids\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
PRC - C:\Program Files\Digital Media Reader\readericon45G.exe (Alcor Micro, Corp.)
PRC - C:\Program Files\Gateway\EzTune\dtsslsrv.exe ()
PRC - C:\Program Files\Gateway\EzTune\DTSRVC.exe ()
PRC - C:\Program Files\WinPortrait\floater.exe ()
PRC - C:\Program Files\WinPortrait\wpctrl.exe ()
PRC - C:\WINDOWS\CNYHKey.exe (Chicony)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner.Kids\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll (RealPlayer)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll (Microsoft Corporation)
MOD - C:\Program Files\WinPortrait\winphook.dll ()


========== Win32 Services (SafeList) ==========

SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (ACDaemon) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (ZuneWlanCfgSvc) -- C:\WINDOWS\system32\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (ZuneBusEnum) -- C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) -- C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (PrismXL) -- C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
SRV - (Asset Management Daemon) -- C:\Program Files\Gateway\EzTune\dtsslsrv.exe ()
SRV - (DTSRVC) -- C:\Program Files\Gateway\EzTune\DTSRVC.exe ()


========== Driver Services (SafeList) ==========

DRV - (catchme) -- C:\DOCUME~1\OWNER~1.KID\LOCALS~1\Temp\catchme.sys File not found
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- C:\WINDOWS\System32\drivers\ALCXWDM.SYS File not found
DRV - (PalmUSBD) -- C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (MPE) -- C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (61883) -- C:\WINDOWS\system32\drivers\61883.sys (Microsoft Corporation)
DRV - (Avc) -- C:\WINDOWS\system32\drivers\avc.sys (Microsoft Corporation)
DRV - (MSDV) -- C:\WINDOWS\system32\drivers\msdv.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (ATIAVPCI) -- C:\WINDOWS\system32\drivers\atinavrr.sys (ATI Technologies Inc.)
DRV - (WinUSB) -- C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (Cdralw2k) -- C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) -- C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (Iviaspi) -- C:\WINDOWS\system32\drivers\iviaspi.sys (InterVideo, Inc.)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (pdiddcci) -- C:\WINDOWS\system32\drivers\pdiddcci.sys (Portrait Displays, Inc.)
DRV - (PdiPorts) -- C:\WINDOWS\system32\drivers\PdiPorts.sys (Portrait Displays, Inc.)
DRV - (nvnetbus) -- C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) -- C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (P17) -- C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (HSF_DPV) -- C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWBS2) -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (AmdK8) -- C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (pivotmou) -- C:\WINDOWS\system32\drivers\pivotmou.sys (Windows ® 2000 DDK provider)
DRV - (pivot) -- C:\WINDOWS\system32\drivers\pivot.sys (Windows ® 2000 DDK provider)
DRV - (ossrv) -- C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) -- C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (TIEHDUSB) -- C:\WINDOWS\system32\drivers\tiehdusb.sys (Texas Instruments Incorporated)
DRV - (wanatw) WAN Miniport (ATW) -- C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (Sparrow) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (mxnic) -- C:\WINDOWS\system32\drivers\mxnic.sys (Macronix International Co., Ltd. )


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50370

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:7.1.20100830W
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.5
FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.5
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.12
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50370
FF - prefs.js..network.proxy.type: 1


FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2008/11/11 14:01:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/02 01:00:17 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/04/22 13:57:24 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/08/06 12:27:17 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/08/16 21:02:09 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/28 07:18:01 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/28 07:34:25 | 000,000,000 | ---D | M]

[2009/04/05 20:46:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\Mozilla\Extensions
[2008/12/06 06:49:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Owner.Kids\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/05 20:46:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2010/10/30 21:48:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\Mozilla\Firefox\Profiles\2wb7o8a2.default\extensions
[2010/10/01 06:48:07 | 000,000,000 | ---D | M] (Flagfox) -- C:\Documents and Settings\Owner.Kids\Application Data\Mozilla\Firefox\Profiles\2wb7o8a2.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2010/07/07 06:57:34 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Owner.Kids\Application Data\Mozilla\Firefox\Profiles\2wb7o8a2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/03 10:28:02 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\Owner.Kids\Application Data\Mozilla\Firefox\Profiles\2wb7o8a2.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/10/30 20:19:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\Mozilla\Firefox\Profiles\2wb7o8a2.default\extensions\toolbar@ask.com
[2009/10/14 20:37:20 | 000,000,239 | ---- | M] () -- C:\Documents and Settings\Owner.Kids\Application Data\Mozilla\Firefox\Profiles\2wb7o8a2.default\searchplugins\Search.xml
[2010/10/30 21:48:50 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/10/28 07:17:56 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/12/31 23:16:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/04/11 20:53:59 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/08/04 03:27:33 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/04/22 13:57:42 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/09/03 19:20:43 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
[2010/10/28 07:17:56 | 000,025,048 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010/10/28 07:17:56 | 000,140,248 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2010/05/20 00:49:45 | 000,058,760 | ---- | M] (WebEx Comminucations, Inc) -- C:\Program Files\Mozilla Firefox\plugins\ateccli.dll
[2010/05/20 00:49:39 | 000,028,472 | ---- | M] (WebEx Communications, Inc) -- C:\Program Files\Mozilla Firefox\plugins\atgpcdec.dll
[2010/05/20 00:49:40 | 000,185,224 | ---- | M] (WebEx Communications, Inc) -- C:\Program Files\Mozilla Firefox\plugins\atgpcext.dll
[2010/05/20 00:50:02 | 000,099,208 | ---- | M] (WebEx Communications, Inc) -- C:\Program Files\Mozilla Firefox\plugins\ieatgpc.dll
[2010/05/20 00:49:39 | 000,061,832 | ---- | M] (WebEx Communications, Inc) -- C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2009/06/06 09:58:44 | 000,417,792 | ---- | M] (Invenda Corporation) -- C:\Program Files\Mozilla Firefox\plugins\NPcol305.dll
[2009/11/19 16:16:28 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/07/25 05:23:01 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
[2009/11/19 16:16:29 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2010/10/28 07:17:58 | 000,066,520 | ---- | M] (mozilla.org) -- C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2010/09/23 14:42:24 | 000,095,672 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
[2010/08/06 12:27:08 | 000,140,864 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
[2009/02/15 13:31:37 | 000,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
[2009/02/15 13:31:37 | 000,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
[2009/02/15 13:31:37 | 000,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
[2009/02/15 13:31:37 | 000,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
[2009/02/15 13:31:37 | 000,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
[2009/02/15 13:31:37 | 000,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
[2009/02/15 13:31:37 | 000,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
[2010/08/06 12:27:24 | 000,008,192 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
[2010/08/06 12:26:57 | 000,098,304 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
[2007/04/16 12:07:12 | 000,180,293 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
[2010/10/21 15:07:32 | 000,001,394 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml
[2010/10/21 15:07:32 | 000,002,193 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
[2010/10/21 15:07:32 | 000,001,534 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
[2010/10/21 15:07:32 | 000,002,344 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml
[2010/10/21 15:07:32 | 000,002,371 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2010/10/21 15:07:32 | 000,001,178 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
[2010/10/21 15:07:32 | 000,001,096 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml

O1 HOSTS File: ([2010/10/28 08:41:21 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\WINDOWS\system32\bae.dll (Gateway Inc.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Links) - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CHotkey] C:\WINDOWS\mHotkey.exe ()
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [ledpointer] C:\WINDOWS\CNYHKey.exe (Chicony)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [P17Helper] C:\WINDOWS\System32\P17.dll ()
O4 - HKLM..\Run: [PivotSoftware] C:\Program Files\WinPortrait\wpctrl.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\WINDOWS\creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [showwnd] C:\WINDOWS\ShowWnd.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SansaDispatch] C:\Documents and Settings\Owner.Kids\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: amaena.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: antispyexpert.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: avsystemcare.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: imageservr.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: imagesrvr.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: onerateld.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: safetydownload.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: spyguardpro.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: storageguardsoft.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: trustedantivirus.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: virusremover2008.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: virusschlacht.com ([]* in Trusted sites)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} http://www.bebo.com/files/BeboUploader.5.1.4.cab (Bebo Uploader Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {297DE2B6-509A-4B36-93C5-A65276606900} http://www.in.honda.com/rraaapps/rraasec/codebase/RRAAINAX/RraainAX.CAB (RRAAINAX_02.RRAAINAX)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo2.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/FacebookPhotoUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} http://www.servicehonda.com/TSWeb/msrdp.cab (Microsoft RDP Client Control (redist))
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://207.192.215.42/activex/AxisCamControl.cab (CamImage Class)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} http://www.shockwave.com/content/weddingdash/sis/WeddingDash.1.0.0.47.cab (CPlayFirstWeddingDashControl Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 207.192.213.44 207.192.213.54
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Owner.Kids\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner.Kids\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/01/09 20:13:09 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/10/31 10:21:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\bleeping computer
[2010/10/31 07:26:15 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/10/31 06:47:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner.Kids\Local Settings\Application Data\AskToolbar
[2010/10/30 20:19:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner.Kids\My Documents\FrostWire
[2010/10/30 20:19:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner.Kids\Application Data\FrostWire
[2010/10/30 20:19:24 | 000,000,000 | ---D | C] -- C:\Program Files\Ask.com
[2010/10/30 02:17:40 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/10/30 02:17:35 | 000,000,000 | ---D | C] -- C:\comfix
[2010/10/28 10:23:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner.Kids\Desktop\bleeping computer
[2010/10/28 08:07:18 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Owner.Kids\Desktop\ComboFix
[2010/10/26 20:51:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner.Kids\My Documents\ACDSeeBK_2010-10-26
[2010/10/15 20:22:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner.Kids\My Documents\Metropolitan
[2010/10/13 06:21:16 | 000,974,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc42.dll
[2010/10/13 06:21:16 | 000,954,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc40.dll
[2010/10/13 06:21:16 | 000,953,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc40u.dll
[2010/10/13 06:21:09 | 000,617,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comctl32.dll
[2010/10/04 21:48:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner.Kids\My Documents\sams pictures
[2010/10/04 13:11:22 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Documents\Server
[2010/03/13 16:06:45 | 000,818,200 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RealPlayerSPGold.exe
[2009/05/23 00:18:23 | 004,909,440 | ---- | C] (Microsoft Corporation) -- C:\Program Files\Silverlight.2.0.exe
[2009/05/20 16:53:45 | 027,024,112 | ---- | C] (Microsoft Corporation) -- C:\Program Files\PowerPointViewer.exe
[2009/03/21 22:21:09 | 016,883,056 | ---- | C] (Microsoft Corporation) -- C:\Program Files\IE8-WindowsXP-x86-ENU.exe
[2008/09/03 16:44:00 | 000,486,152 | ---- | C] (Google Inc.) -- C:\Program Files\ChromeSetup.exe
[2008/08/24 19:46:21 | 003,252,752 | ---- | C] (Macrovision Corporation) -- C:\Program Files\SansaUpdaterInstall.exe
[2008/06/05 14:07:52 | 025,740,144 | ---- | C] (Microsoft Corporation) -- C:\Program Files\wmp11-windowsxp-x86-enu.exe
[2008/05/29 15:11:30 | 000,136,528 | ---- | C] (AOL LLC.) -- C:\Program Files\unagi_patch.exe
[2008/05/29 14:17:42 | 013,934,776 | ---- | C] (AOL LLC.) -- C:\Program Files\Install_AIM.exe
[2008/01/02 21:21:02 | 002,168,976 | ---- | C] (Microsoft Corporation) -- C:\Program Files\mcsolitairesetup.exe
[2007/05/06 14:46:47 | 002,657,486 | ---- | C] (Blue Squirrel ) -- C:\Program Files\Click2PosterSetup.exe
[2007/04/13 06:25:25 | 014,994,152 | ---- | C] (Macrovision Corporation) -- C:\Program Files\GoogleEarthWin_EARV.exe
[2007/02/28 21:19:06 | 000,288,640 | ---- | C] (Microsoft Corporation) -- C:\Program Files\dxwebsetup.exe
[2007/02/12 20:05:46 | 019,666,504 | ---- | C] (Apple Computer, Inc.) -- C:\Program Files\QuickTimeInstaller.exe
[2007/02/03 22:06:53 | 017,357,528 | ---- | C] (The LEGO Group) -- C:\Program Files\designer.exe
[2007/02/01 21:58:37 | 014,994,392 | ---- | C] (Macrovision Corporation) -- C:\Program Files\GoogleEarthWin.exe
[2002/04/10 20:41:06 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\A3d.dll
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/10/31 19:21:42 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-351961390-340104498-4275350937-1006.job
[2010/10/31 19:21:42 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-351961390-340104498-4275350937-1006.job
[2010/10/31 17:10:51 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2010/10/31 12:07:20 | 000,194,560 | ---- | M] () -- C:\Documents and Settings\Owner.Kids\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/31 11:45:58 | 000,001,133 | ---- | M] () -- C:\Documents and Settings\Owner.Kids\Desktop\Shortcut to IMGP0336.lnk
[2010/10/31 09:54:59 | 000,001,170 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/10/31 09:53:59 | 000,030,277 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/10/31 09:53:50 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/10/31 09:53:48 | 1474,875,392 | -HS- | M] () -- C:\hiberfil.sys
[2010/10/31 07:26:30 | 000,364,032 | ---- | M] () -- C:\Documents and Settings\Owner.Kids\Desktop\rkill.com
[2010/10/30 21:07:36 | 000,000,960 | ---- | M] () -- C:\WINDOWS\cdplayer.ini
[2010/10/30 20:19:33 | 000,000,234 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/10/28 17:01:01 | 000,041,064 | ---- | M] () -- C:\Documents and Settings\Owner.Kids\Application Data\wklnhst.dat
[2010/10/28 08:41:21 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/10/28 07:34:25 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2010/10/27 19:47:42 | 000,173,399 | ---- | M] () -- C:\Documents and Settings\Owner.Kids\My Documents\dellsnitrogen.JPG
[2010/10/26 21:28:11 | 000,323,206 | ---- | M] () -- C:\Documents and Settings\Owner.Kids\My Documents\Grandpa and Grandma.jpg
[2010/10/26 21:04:06 | 002,482,192 | ---- | M] () -- C:\Documents and Settings\Owner.Kids\My Documents\Awww so sweet.jpg
[2010/10/26 21:02:58 | 002,141,389 | ---- | M] () -- C:\Documents and Settings\Owner.Kids\My Documents\Uncle Max Aunt Amanda.jpg
[2010/10/26 20:50:39 | 000,002,565 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\My Pictures.lnk
[2010/10/19 23:47:05 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cb7011d8578d44.job
[2010/10/16 09:40:30 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Owner.Kids\defogger_reenable
[2010/10/13 18:20:16 | 000,265,416 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/13 07:55:38 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/10/13 07:18:18 | 000,000,279 | RHS- | M] () -- C:\boot.ini
[2010/10/13 00:12:29 | 000,168,437 | ---- | M] () -- C:\Documents and Settings\Owner.Kids\Desktop\skillet tickets.pdf
[2010/10/10 12:59:02 | 000,132,584 | ---- | M] () -- C:\Documents and Settings\Owner.Kids\My Documents\FoundDogNotOursperHilary.jpg
[2010/10/06 23:19:26 | 000,095,281 | ---- | M] () -- C:\Documents and Settings\Owner.Kids\My Documents\print and give to mum.jpg
[2010/10/05 16:26:38 | 000,017,408 | ---- | M] () -- C:\Documents and Settings\Owner.Kids\My Documents\zac’s address and phone.wps
[2010/10/05 07:33:04 | 000,444,780 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/10/05 07:33:04 | 000,072,530 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/10/31 11:45:58 | 000,001,133 | ---- | C] () -- C:\Documents and Settings\Owner.Kids\Desktop\Shortcut to IMGP0336.lnk
[2010/10/31 07:25:40 | 000,364,032 | ---- | C] () -- C:\Documents and Settings\Owner.Kids\Desktop\rkill.com
[2010/10/30 20:19:33 | 000,000,234 | ---- | C] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/10/27 19:47:42 | 000,173,399 | ---- | C] () -- C:\Documents and Settings\Owner.Kids\My Documents\dellsnitrogen.JPG
[2010/10/26 21:28:11 | 000,323,206 | ---- | C] () -- C:\Documents and Settings\Owner.Kids\My Documents\Grandpa and Grandma.jpg
[2010/10/26 21:04:06 | 002,482,192 | ---- | C] () -- C:\Documents and Settings\Owner.Kids\My Documents\Awww so sweet.jpg
[2010/10/26 21:02:58 | 002,141,389 | ---- | C] () -- C:\Documents and Settings\Owner.Kids\My Documents\Uncle Max Aunt Amanda.jpg
[2010/10/19 23:47:05 | 000,000,882 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cb7011d8578d44.job
[2010/10/16 09:40:30 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner.Kids\defogger_reenable
[2010/10/13 07:18:15 | 000,001,808 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/10/13 00:12:29 | 000,168,437 | ---- | C] () -- C:\Documents and Settings\Owner.Kids\Desktop\skillet tickets.pdf
[2010/10/10 12:59:36 | 000,132,584 | ---- | C] () -- C:\Documents and Settings\Owner.Kids\My Documents\FoundDogNotOursperHilary.jpg
[2010/10/06 23:19:23 | 000,095,281 | ---- | C] () -- C:\Documents and Settings\Owner.Kids\My Documents\print and give to mum.jpg
[2010/08/16 20:52:19 | 000,000,731 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010/07/19 20:24:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2009/11/05 18:14:30 | 025,578,557 | ---- | C] () -- C:\Program Files\Voobys.exe
[2009/07/19 20:40:56 | 005,877,248 | ---- | C] () -- C:\Program Files\tistudycardscreator.exe
[2009/07/19 20:26:56 | 000,013,494 | ---- | C] () -- C:\Program Files\ACTWORD1.8xv
[2009/07/19 20:23:11 | 000,035,907 | ---- | C] () -- C:\Program Files\StudyCrd.8Xk
[2009/05/23 20:06:18 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2009/01/02 20:30:02 | 000,090,112 | ---- | C] () -- C:\Program Files\Unreal Anthology.exe
[2009/01/01 15:37:23 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2009/01/01 15:35:48 | 000,000,044 | ---- | C] () -- C:\WINDOWS\EPSNX400.ini
[2008/12/27 08:13:47 | 005,154,304 | ---- | C] () -- C:\Program Files\WindowsDefender.msi
[2008/12/25 13:30:28 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\Owner.Kids\Application Data\76DC24
[2008/12/25 13:30:27 | 000,870,128 | ---- | C] () -- C:\Documents and Settings\Owner.Kids\Application Data\mcs.rma
[2008/08/29 19:23:58 | 010,509,183 | ---- | C] () -- C:\Program Files\FreeMat-3.6_Setup.exe
[2008/07/02 17:32:06 | 025,813,085 | ---- | C] () -- C:\Program Files\TWCSSSetup.exe
[2008/05/29 14:26:14 | 000,000,021 | ---- | C] () -- C:\WINDOWS\atid.ini
[2008/04/14 13:33:11 | 000,142,375 | ---- | C] () -- C:\Program Files\soapmaker calculator for lye.zip
[2008/03/02 13:20:30 | 000,234,592 | ---- | C] () -- C:\Program Files\SmileboxInstaller.exe
[2007/12/26 18:27:49 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\CNMVS58.DLL
[2007/11/16 22:40:41 | 040,372,423 | ---- | C] () -- C:\Program Files\NP2k8Win.zip
[2007/10/31 17:28:01 | 001,305,088 | ---- | C] () -- C:\Program Files\Netflix_Movie_Viewer_Installer.msi
[2007/10/07 12:32:57 | 000,019,576 | ---- | C] () -- C:\Program Files\fe_out.txt
[2007/06/13 19:14:12 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/06/13 19:13:34 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/05/06 14:47:13 | 000,000,731 | ---- | C] () -- C:\WINDOWS\clik2pos.ini
[2007/04/21 19:08:31 | 000,000,084 | ---- | C] () -- C:\WINDOWS\WSST_Screen_Saver.ini
[2007/04/03 17:22:43 | 000,000,175 | ---- | C] () -- C:\WINDOWS\btw.ini
[2007/02/27 07:48:53 | 001,568,632 | ---- | C] () -- C:\Program Files\EZCD_Setup.exe
[2007/02/27 07:23:28 | 014,711,997 | ---- | C] () -- C:\Program Files\mpeg-encoder-21713.exe
[2007/02/01 21:58:36 | 005,709,889 | ---- | C] () -- C:\Program Files\BMNG-12months.kmz
[2006/12/25 12:34:05 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\WINKRNME.DLL
[2006/11/15 16:25:26 | 001,606,064 | ---- | C] () -- C:\Program Files\googletalk-setup.exe
[2006/11/01 16:26:46 | 000,000,144 | ---- | C] () -- C:\WINDOWS\VDECK.INI
[2006/10/16 20:21:20 | 000,000,047 | ---- | C] () -- C:\WINDOWS\3D Text Factory.INI
[2006/10/15 11:42:11 | 000,000,057 | ---- | C] () -- C:\WINDOWS\viewer.ini
[2006/10/15 11:42:10 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\CPUINF32.DLL
[2006/10/15 11:42:03 | 000,023,076 | ---- | C] () -- C:\WINDOWS\System32\LANDDLL2.DLL
[2006/09/21 19:19:16 | 000,000,960 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2006/09/16 14:52:18 | 000,000,044 | ---- | C] () -- C:\WINDOWS\liveup.ini
[2006/09/13 17:30:07 | 000,044,544 | ---- | C] () -- C:\WINDOWS\System32\gif89.dll
[2006/09/13 17:29:35 | 000,000,584 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2006/08/21 13:32:11 | 000,643,124 | ---- | C] () -- C:\Program Files\atomic.exe
[2006/08/21 09:44:55 | 000,000,898 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/08/19 20:57:49 | 000,029,618 | ---- | C] () -- C:\Program Files\NANSTD6.SAV
[2006/08/19 20:57:49 | 000,029,618 | ---- | C] () -- C:\Program Files\NANSTD5.SAV
[2006/08/19 20:57:49 | 000,029,618 | ---- | C] () -- C:\Program Files\NANSTD4.SAV
[2006/08/19 20:57:49 | 000,029,618 | ---- | C] () -- C:\Program Files\NANSTD3.SAV
[2006/08/19 20:57:49 | 000,029,618 | ---- | C] () -- C:\Program Files\NANSTD2.SAV
[2006/08/19 20:57:49 | 000,029,618 | ---- | C] () -- C:\Program Files\NANSTD1.SAV
[2006/08/19 20:57:49 | 000,029,618 | ---- | C] () -- C:\Program Files\NANSTD0.SAV
[2006/08/19 20:57:49 | 000,029,618 | ---- | C] () -- C:\Program Files\CONSTD.SAV
[2006/08/17 22:39:47 | 000,000,133 | ---- | C] () -- C:\Documents and Settings\Owner.Kids\Local Settings\Application Data\fusioncache.dat
[2006/08/17 21:09:00 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\CNMVS7I.DLL
[2006/08/17 21:07:59 | 000,000,532 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2006/08/17 08:42:17 | 000,000,000 | ---- | C] () -- C:\Program Files\game.ini
[2006/08/17 08:33:58 | 000,041,064 | ---- | C] () -- C:\Documents and Settings\Owner.Kids\Application Data\wklnhst.dat
[2006/08/17 07:46:19 | 000,194,560 | ---- | C] () -- C:\Documents and Settings\Owner.Kids\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/06/17 17:13:13 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\jesterss.dll
[2006/06/17 17:02:51 | 000,532,544 | ---- | C] () -- C:\WINDOWS\PIC.dll
[2006/06/17 17:02:51 | 000,049,152 | ---- | C] () -- C:\WINDOWS\CNYUSB.dll
[2006/06/17 17:02:51 | 000,024,576 | ---- | C] () -- C:\WINDOWS\HKNTDLL.dll
[2006/06/17 17:02:51 | 000,011,776 | ---- | C] () -- C:\WINDOWS\HIDMNT.dll
[2006/06/17 17:02:51 | 000,005,120 | ---- | C] () -- C:\WINDOWS\HKCYDLL.dll
[2006/06/17 17:02:51 | 000,000,360 | ---- | C] () -- C:\WINDOWS\CNYHKey.ini
[2006/06/17 17:01:11 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/06/17 15:38:26 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006/06/17 15:38:26 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006/06/17 15:38:25 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006/06/17 15:38:24 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006/06/17 15:38:23 | 001,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006/06/17 15:38:23 | 000,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006/06/17 15:38:21 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2005/08/06 00:01:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll
[2005/07/07 04:26:56 | 000,005,627 | ---- | C] () -- C:\WINDOWS\System32\Ludap17.ini
[2005/05/03 06:38:42 | 000,064,512 | ---- | C] () -- C:\WINDOWS\System32\P17.dll
[2005/03/08 01:17:08 | 000,000,054 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2005/01/12 12:38:00 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/01/09 18:49:16 | 000,001,252 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2005/01/09 18:49:16 | 000,000,494 | ---- | C] () -- C:\WINDOWS\System32\emver.ini
[2005/01/09 12:00:34 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2003/10/02 05:48:18 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\P17CPI.dll
[2002/03/21 16:39:02 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\UNACEV2.DLL

========== LOP Check ==========

[2008/12/25 13:18:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
[2006/08/17 21:09:02 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/01/01 16:24:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2010/07/19 19:59:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HotSync
[2009/08/03 19:58:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster
[2006/11/09 19:48:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap
[2007/02/03 22:28:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\QubeSoft
[2008/08/05 20:37:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ROBLOX
[2007/09/06 05:43:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2006/12/22 18:37:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Softdisk LLC
[2009/05/17 16:35:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2006/08/17 21:08:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2008/12/06 09:38:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/05/29 14:25:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/18 08:16:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{5B85955C-92A8-4C87-8577-917CF53455BC}
[2009/09/01 20:14:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\.minecraft
[2008/12/25 13:19:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\ACD Systems
[2010/03/02 19:25:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\Audacity
[2008/07/29 10:33:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\Canon
[2006/12/25 12:36:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\DisplayTune
[2009/04/09 16:31:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\EPSON
[2010/03/28 12:06:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\Facebook
[2010/10/30 20:48:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\FrostWire
[2009/12/04 07:02:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\GetRightToGo
[2010/07/19 19:56:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\HotSync
[2009/12/15 23:24:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\ImTOO Software Studio
[2009/01/01 15:59:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\Leadertech
[2010/01/26 21:49:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\LimeWire
[2007/11/11 15:35:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\PowerChallenge
[2008/08/07 15:38:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\ROBLOX
[2006/06/17 17:13:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\SampleView
[2009/01/25 16:17:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\SanDisk
[2006/08/17 21:08:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\ScanSoft
[2009/08/26 23:12:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\Smilebox
[2009/02/15 16:27:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\Snapfish
[2006/08/17 08:33:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\Template
[2008/06/01 23:57:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\Uniblue
[2007/02/25 22:57:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\Viewpoint
[2009/11/09 22:56:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\WebRenderer
[2007/09/17 19:31:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner.Kids\Application Data\yoclient
[2010/10/30 20:19:33 | 000,000,234 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2010/07/03 09:00:25 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{6914C367-B0EA-45B8-9849-D9FFEBE6817F}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52562F72
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >

OTL Extras logfile created on: 10/31/2010 7:29:00 PM - Run 1
OTL by OldTimer - Version 3.2.17.2
[/size] Folder = C:\Documents and Settings\Owner.Kids\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 58.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 293.75 Gb Total Space | 220.50 Gb Free Space | 75.06% Space Free | Partition Type: NTFS
Drive D: | 4.33 Gb Total Space | 2.38 Gb Free Space | 55.06% Space Free | Partition Type: FAT32

Computer Name: KIDS | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDSee 9.0.Browse] -- "C:\Program Files\ACD Systems\ACDSee\9.0\ACDSeeQV.exe" "%1" (ACD Systems Ltd.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10244:TCP" = 10244:TCP:LocalSubNet:Enabled:Zune Network Sharing Service
"10285:UDP" = 10285:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10286:UDP" = 10286:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10287:UDP" = 10287:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10288:UDP" = 10288:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10289:UDP" = 10289:UDP:LocalSubNet:Enabled:Zune Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10244:TCP" = 10244:TCP:LocalSubNet:Enabled:Zune Network Sharing Service
"10285:UDP" = 10285:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10286:UDP" = 10286:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10287:UDP" = 10287:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10288:UDP" = 10288:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10289:UDP" = 10289:UDP:LocalSubNet:Enabled:Zune Network Sharing Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 -- (Microsoft Corporation)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe -- (Hewlett-Packard)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe -- (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe -- (Hewlett-Packard Co.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 -- (Microsoft Corporation)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe -- (Hewlett-Packard)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe -- (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe -- (Hewlett-Packard Co.)
"C:\WINDOWS\network diagnostic\xpnetdiag.exe" = C:\WINDOWS\network diagnostic\xpnetdiag.exe:*:Disabled:Network Diagnostic for Windows XP -- (Microsoft Corporation)
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire -- File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0030188A-533E-42EE-9837-E044F10E4369}" = Palm
"{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}" = Zune Language Pack (FR)
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{01A1A019-E1D8-482A-BE17-5E118D17C0A0}" = ArcSoft Print Creations - Brochures & Flyers
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{14AA72DA-DB40-4A34-93A6-401A81D7AF9E}" = Unreal Anthology
"{15377C3E-9655-400F-B441-E69F0A6BEAFE}" = Recovery Software Suite Gateway
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{2301D80B-7E1F-4A12-83D5-1BEFF758F592}" = SpiralFrog Download Manager 2.1.12
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 15
"{272C2E66-6D29-4FB3-835B-05A4ED8E63FD}" = ROBLOX
"{2CD0168D-FBBC-4667-8810-105CB6EC6348}" = HP Deskjet D1600 Printer Driver Software 13.0 Rel .6
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{370BCBBA-67D7-4535-ADCD-58CD1C8DEC99}" = Zune Language Pack (DE)
"{3CE47E6B-AE27-4E40-AC54-329EED96B933}" = ArcSoft Print Creations - Funhouse II
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = Browser Address Error Redirector
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 4.0
"{40EC6323-497B-44DA-8A88-74578622D9B3}" = Zune Language Pack (IT)
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4AC55A61-BA20-4DF5-ABFF-8F4819E0C875}" = Digital Media Reader
"{4AFA5BCB-E113-4FD6-8C28-D8F3FD0100D3}" = Nancy Drew: Secret of the Scarlet Hand
"{5023B3E9-6B73-471E-8BD9-DA4442AE357C}" = ArcSoft Print Creations - Quick Photo Book
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5727583F-3530-45FD-B09E-7E1CB6C135AD}" = DJ_SF_06_D1600_SW_Min
"{5D1C82E7-7EC0-4404-A8AD-36C3B444BC34}" = ArcSoft Print Creations - Poster Creator
"{5D95AD35-368F-47D5-B63A-A082DDF00111}" = Microsoft Digital Image Starter Edition 2006 Editor
"{6054F774-FEF0-46C6-9311-EC97FC576FC5}" = USB Wireless Keyboard Driver
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{691F4068-81BF-49E3-B32E-FE3E16400111}" = Microsoft Digital Image Starter Edition 2006 Library
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78B55A60-5E51-11D4-A766-00C00C02EDEF}" = Nancy Drew: Message in a Haunted Mansion
"{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}" = OmniPage SE 2.0
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7D9B77E1-0078-0001-4447-ADD4C0A93D1D}" = Sansa Media Converter
"{84288B51-B162-47FB-A74E-25C6D67E44BB}" = EzTune
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{888FFC82-688D-46AB-A776-B417885432B6}" = Zune
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{92022F8E-2E55-4A16-88EB-B4778B35E942}" = ACDSee for PENTAX 3.0
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{95F875CC-1B85-43E6-B3E0-13EA04F3D995}" = ArcSoft Print Creations - Photo Prints
"{98177940-C048-4831-A279-F3888B1E2C7F}" = InstallMgr
"{98736A65-3C79-49EC-B7E9-A3C77774B0E6}" = Google SketchUp 6
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A8AC89BA-D8CB-4372-9743-1C54D23286B0}" = MSN Toolbar
"{A8B94669-8654-4126-BD28-D0D2412CDED6}" = TI Connect 1.6
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A96D3ED0-E7B3-41F6-8BB5-F3C63D80901D}" = SplashPhoto
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.5
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B3B2CC77-13A5-43E3-ABB3-73E6B64EC700}" = TI StudyCards Creator
"{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}" = Google SketchUp 6
"{B406605B-45FE-4D8F-8250-1E77479583AE}" = Zoo Tycoon 2 - Marine Mania
"{B6EF6DCE-078E-4952-A7FA-352A9C349EB0}" = MSN Toolbar
"{B7148D71-0A8F-4501-96B4-4E1CC67F874E}" = Microsoft Default Manager
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{B7B3E9B3-FB14-4927-894B-E9124509AF5A}" = Adobe Flash Player 10 ActiveX
"{BEAD39CD-901D-4267-8B8B-EAA83CB4B70D}" = Pivot Stickfigure Animator
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = Athlon 64 Processor Driver
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF23AFD7-3078-4134-8823-EBF6D1FE6FAD}" = Canon MP450
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{EAE8CF06-28CA-4213-839C-A32817A47E00}" = D1600
"{EE4ACABF-531E-419A-9225-B8E0FA4955AF}" = Zune Language Pack (ES)
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F227D8E5-2FD9-4652-B5D3-14003028F235}" = ArcSoft Print Creations
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{FC053571-8507-44E4-8B6D-AACEAB8CA57C}" = Sansa Media Converter
"3D Deck" = Sierra 3D Deck
"ActiveTouchMeetingClient" = WebEx
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"All ATI Software" = ATI - Software Uninstall Utility
"Amazing Slow Downer EE" = Amazing Slow Downer (remove only)
"American Greetings CreataCard 4.0" = American Greetings® CreataCard® 4
"Atomic Clock Sync" = Atomic Clock Sync
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.11 (Unicode)
"AudibleManager" = AudibleManager
"Awesome Deep Space Screen Saver Lite" = Awesome Deep Space Screen Saver Lite
"Best Buy Digital Music Store" = Best Buy Digital Music Store
"Click2Poster_is1" = Blue Squirrel Click2Poster
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200014F1" = Soft Data Fax Modem with SmartCP
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Custom 3D Home" = Custom 3D Home (remove only)
"DECCHECK" = Microsoft Windows XP Video Decoder Checkup Utility
"Easy CD and DVD Cover Creator" = Easy CD and DVD Cover Creator 4.12
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-WebPrint" = Easy-WebPrint
"Electronic Arts Game Updater" = Electronic Arts Game Updater
"EPSON Stylus NX400 Series" = EPSON Stylus NX400 Series Printer Uninstall
"Finale NotePad 2008" = Finale NotePad 2008
"Google Chrome" = Google Chrome
"Google Updater" = Google Updater
"gtw_logo" = gtw_logo
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"ImTOO Zune Video Converter" = ImTOO Zune Video Converter
"InstallShield_{4AC55A61-BA20-4DF5-ABFF-8F4819E0C875}" = Digital Media Reader
"InstallShield_{B406605B-45FE-4D8F-8250-1E77479583AE}" = Zoo Tycoon 2 - Marine Mania
"LEGO Digital Designer" = LEGO Digital Designer
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Media Center Solitaire" = Media Center Solitaire
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Money2006b" = Microsoft Money 2006
"Mozilla Firefox (3.6.12)" = Mozilla Firefox (3.6.12)
"MP Navigator 2.0" = Canon MP Navigator 2.0
"MPEG Encoder 3" = MPEG Encoder 3
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"Need For Speed - Porsche Unleashed" = Need For Speed - Porsche Unleashed
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PictureItSuiteTrial_v11" = Microsoft Digital Image Starter Edition 2006
"PolarClock3" = PolarClock3 Screen Saver
"RealPlayer 12.0" = RealPlayer
"RegistryBooster 2_is1" = Uniblue RegistryBooster 2
"ShapeCollage" = Shape Collage
"Shop for HP Supplies" = Shop for HP Supplies
"Sierra Home Architect" = Sierra Home Architect
"ST6UNST #2" = Myopoly5 (C:\Program Files\Myopoly5\)
"ST6UNST #3" = Myopoly5 (C:\Program Files\Myopoly5\) #3
"VideoEgg" = VideoEgg Publisher
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WebPost" = Microsoft Web Publishing Wizard 1.52
"WGA" = Windows Genuine Advantage Validation Tool
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"winusb0100" = Microsoft WinUsb 1.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01009" = Microsoft User-Mode Driver Framework Feature Pack 1.9
"Yahoo! Companion" = Yahoo! Toolbar for Internet Explorer
"Yahoo! Photos Easy Upload Tool" = Yahoo! Photos Easy Upload Tool
"Yahoo! Toolbar" = Yahoo! Toolbar
"Zune" = Zune

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"Sansa Updater" = Sansa Updater
"Smilebox" = Hallmark Smilebox

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/17/2010 3:13:16 PM | Computer Name = KIDS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/17/2010 3:14:33 PM | Computer Name = KIDS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/17/2010 3:31:09 PM | Computer Name = KIDS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/22/2010 2:10:36 PM | Computer Name = KIDS | Source = Application Hang | ID = 1002
Description = Hanging application mspaint.exe, version 5.1.2600.5918, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/25/2010 6:56:10 AM | Computer Name = KIDS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/28/2010 7:54:31 AM | Computer Name = KIDS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/30/2010 4:07:34 AM | Computer Name = KIDS | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 10/30/2010 10:59:13 AM | Computer Name = KIDS | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.2.3951, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/30/2010 8:28:34 PM | Computer Name = KIDS | Source = ZuneDriver | ID = 80837
Description =

Error - 10/31/2010 10:35:26 AM | Computer Name = KIDS | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

[ System Events ]
Error - 10/30/2010 4:09:35 AM | Computer Name = KIDS | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 10/30/2010 7:30:42 AM | Computer Name = KIDS | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 10/30/2010 11:19:56 AM | Computer Name = KIDS | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 10/30/2010 11:40:55 AM | Computer Name = KIDS | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 00155848C818 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 10/30/2010 4:31:41 PM | Computer Name = KIDS | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.101 for the Network Card with network
address 00155848C818 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 10/31/2010 7:44:46 AM | Computer Name = KIDS | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 10/31/2010 8:20:45 AM | Computer Name = KIDS | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 10/31/2010 10:37:20 AM | Computer Name = KIDS | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 10/31/2010 10:54:31 AM | Computer Name = KIDS | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 10/31/2010 10:54:33 AM | Computer Name = KIDS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
abp480n5 adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint asc asc3350p
asc3550
cbidf
cd20xrnt
CmdIde
Cpqarray
dac2w2k
dac960nt
dpti2o
hpn
i2omp
ini910u
IntelIde
mraid35x
perc2
perc2hib
ql1080
Ql10wnt
ql12160
ql1240
ql1280
sisagp
Sparrow
symc810
symc8xx
sym_hi
sym_u3
TosIde
ultra
viaagp
ViaIde


< End of report >

#12 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:06:38 PM

Posted 31 October 2010 - 08:15 PM

The Ask toolbar is not recommended. This toolbar enhances internet browsing and provides a direct link to the "ask.com" search engine. This program is not known to be bundled with spyware - The company strongly denies the toolbar as being malware.

Please read why it might be good to remove it here.

If you choose to remove it then follow the instructions below.

Click "start" on the taskbar and then click on the "Control Panel" icon.
Please doubleclick (or right-click, if you are using Vista) the "Add or Remove Programs" icon
A list of programs installed will be "populated" this may take a bit of time.
If they exist, uninstall the following by clicking on the following entries and selecting "remove":



Ask.com



Additional instructions can be found here if needed.


Now open OTL

Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50370
O15 - HKCU\..Trusted Domains: amaena.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: antispyexpert.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: avsystemcare.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: imageservr.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: imagesrvr.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: onerateld.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: safetydownload.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: spyguardpro.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: storageguardsoft.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: trustedantivirus.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: virusremover2008.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: virusschlacht.com ([]* in Trusted sites)
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52562F72
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"


Then click the Run Fix button at the top

Let the program run unhindered.

When done it will say "Fix Complete press ok to open the log"
Please post that log in your next reply. Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Posted Image
m0le is a proud member of UNITE

#13 surf

surf
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:38 PM

Posted 02 November 2010 - 10:51 PM

:OTL
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50370
O15 - HKCU\..Trusted Domains: amaena.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: antispyexpert.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: avsystemcare.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: imageservr.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: imagesrvr.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: onerateld.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: safetydownload.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: spyguardpro.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: storageguardsoft.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: trustedantivirus.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: virusremover2008.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: virusschlacht.com ([]* in Trusted sites)
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52562F72
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"

#14 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:06:38 PM

Posted 03 November 2010 - 04:30 PM

Can you follow the instructions again. You need to paste the code above into OTL's the custom fix field and then click Run Fix

Then post the log that it produces.
Posted Image
m0le is a proud member of UNITE

#15 surf

surf
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:38 PM

Posted 03 November 2010 - 07:13 PM

========== OTL ==========
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\amaena.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\antispyexpert.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avsystemcare.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\imageservr.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\imagesrvr.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\onerateld.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\safetydownload.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyguardpro.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\storageguardsoft.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\trustedantivirus.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\virusremover2008.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\virusschlacht.com\ not found.
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:52562F72 .
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 .
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\\""|""%1" %*" /E : value set successfully!

OTL by OldTimer - Version 3.2.17.2 log created on 11032010_191011




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users