Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Bad, Very bad case of google redirect virus


  • This topic is locked This topic is locked
42 replies to this topic

#1 emudryj

emudryj

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:11:37 AM

Posted 02 September 2011 - 10:08 PM

Hi everybody and thanks in advance for your attention...
straight to the symptoms..
I was confident that I was protected aginst any virus by my updated and running McAfee Internet Security software...

1- I started getting random blue screens, some would not tell anything regarding the cause, other would mention "memory page file in non-paged area" or something like that.
Most of the times the blue screen would make mention of different files that all appear to be drivers.

2- In IE after a opening a few tabs, let say 6, the 7th one would open but would not go anywhere. I couldn't go to the home page or any other page for that matter, just a white, blank page...

3- sudden pop-ups coming from who knows where...

4- At this point I did not thought much about it until, I would google anything, get my search results, but when I click on those hyperlinks it would take me anywhere else...
It was not constant. but would do that 90% of the time.

I went to my work computer and search for these symptoms and didn't take long to know I was infected with the infamous, and wrongfully named, google re-direct virus...
At this point the symptoms were present 100% of the time.

I search for different options and I tried everything I could
Malwarebytes Anti-malware was the most mentioned recommendation on the web... on my computer would come completely clean, but I still had the problem.
Kapersky TDDSkiller would not find a single infection, completely clean...
SUPERantispyware, found 49 subject files and I direct it to delete those files.
Unhackme
Reanimator
Trojan remover
CCleaner (only thing I achieve was to wipe out my browsing history and cookies)
I've search for some registry keys, following advice on articles over the met but I would not have the keys they would tell me to look for.

At some point, the symptoms would get better for very short periods of time making me think that I solved the problem, but shrtly after they would re-erupt...The good thing now is that Malwarebytes Anty-malware active protection would block a LOT of the attempts of iexplorer.exe y firefox to redirect me to not requested pages, but sometimes he could not keep up and I would get the redirection or the pop-up. I also get my McAfee virus scan turned off, all the sudden and for no reason.
So I'm positive that I'm Still infected even though the most common antymalware software say I'm clean.

My last option is to start my windows install from scratch and cut the weed from the roots... the only thing stopping me to do that is that since I do not know how I got the virus, I do not know where is allocated, and if it's still on any of my backup files, I may go through all the hazard of re-formating and re-installing and still get the virus back 2 days or 2 hours later.

When I went back to my work computer I installed the Malwarebytes anty-malware, because even though I have not suffer the re-directions yet, I was starting to see the symptom that would let you open a new tab but you could not anywhere.
As soon as I got the antymalware installed I started getting the messages blocking IE to go to unknown ip addresses on the web.

So please, help me out!!! I tried as much as I could to avoid the nuisance but I'm out of options.

I'm a newbie and finally decided to let somebody guide with more experience to guide me thru the right order and precised steps.

My win 7 is 64bits so I assumed Gmer was of not use. If that is nor correct please let me know and I will run it.
My DDS.txt

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_25
Run by emudryj at 22:20:00 on 2011-09-02
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.6135.3800 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\WUDFHost.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
D:\Programs\Superantispiware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
D:\Programs\LogMeIn\x64\LMIGuardianSvc.exe
D:\Programs\LogMeIn\x64\RaMaint.exe
D:\Programs\LogMeIn\x64\LogMeIn.exe
D:\Programs\IBM\Lotus\Notes\nsd.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Windows\system32\mfevtps.exe
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
D:\Programs\IBM\Lotus\Notes\ntmulti.exe
C:\Windows\SysWOW64\PnkBstrA.exe
D:\Programs\Assistant\UsbClientService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\alg.exe
C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
D:\Programs\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\McAfee Online Backup\MOBK755backup.exe
C:\Program Files (x86)\McAfee Online Backup\MOBK755backup.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\McAfee Online Backup\MOBK755backup.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Media Player\WMPSideShowGadget.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
D:\Programs\LogMeIn\x64\LogMeInSystray.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
D:\Programs\Impulse\Now\ImpulseNow.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
D:\Programs\iTunes\iTunesHelper.exe
C:\Program Files (x86)\ASUS\ASUS Sync\asusUPCTLoader.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe
D:\Programs\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\SetPointG\SetPointII.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSService.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Programs\Mozilla Firefox\firefox.exe
D:\Programs\Mozilla Firefox\plugin-container.exe
D:\Programs\Microsoft Office\Office14\OUTLOOK.EXE
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Users\emudryj\Downloads\Defogger.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~2\mcafee\sitead~1\mcieplg.dll
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110526213057.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~2\mcafee\sitead~1\mcieplg.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - D:\Programs\Java\Jre6\bin\jp2ssv.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~2\mcafee\sitead~1\mcieplg.dll
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
uRun: [UnHackMe Monitor] D:\Programs\UnHackMe\hackmon.exe
uRun: [SUPERAntiSpyware] D:\Programs\Superantispiware\SUPERAntiSpyware.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [BCWipeTM Startup] "C:\Program Files (x86)\Jetico\BCWipe\BCWipeTM.exe" startup
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "D:\Programs\iTunes\iTunesHelper.exe"
mRun: [ASUS Sync Loader] "C:\Program Files (x86)\ASUS\ASUS Sync\asusUPCTLoader.exe" -startup
mRun: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S
mRun: [TrojanScanner] D:\Programs\Trojan Remover\Trjscan.exe /boot
mRun: [Malwarebytes' Anti-Malware] "D:\Programs\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\Users\emudryj\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\IMPULS~1.LNK - D:\Programs\Impulse\Now\ImpulseNow.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\LOGITE~1.LNK - C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - D:\Programs\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - D:\Programs\MICROS~1\Office14\ONBttnIE.dll/105
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/RACtrl.cab
TCP: DhcpNameServer = 205.152.144.23 205.152.132.23
TCP: Interfaces\{981DC840-1403-43B8-BB74-EBDF6C951E97} : DhcpNameServer = 205.152.144.23 205.152.132.23
TCP: Interfaces\{CAB1B010-6ED5-4505-8DB6-724B5510BD2F} : DhcpNameServer = 205.152.144.23 205.152.132.23
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: McAfee Phishing Filter: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO-X64: McAfee Phishing Filter - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110526213057.dll
BHO-X64: scriptproxy - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\progra~2\mcafee\sitead~1\mcieplg.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Programs\Java\Jre6\bin\jp2ssv.dll
TB-X64: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~2\mcafee\sitead~1\mcieplg.dll
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [BCWipeTM Startup] "C:\Program Files (x86)\Jetico\BCWipe\BCWipeTM.exe" startup
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "D:\Programs\iTunes\iTunesHelper.exe"
mRun-x64: [ASUS Sync Loader] "C:\Program Files (x86)\ASUS\ASUS Sync\asusUPCTLoader.exe" -startup
mRun-x64: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S
mRun-x64: [TrojanScanner] D:\Programs\Trojan Remover\Trjscan.exe /boot
mRun-x64: [Malwarebytes' Anti-Malware] "D:\Programs\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q=
FF - plugin: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nppl3260.dll
FF - plugin: C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nprpjplug.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - plugin: D:\Programs\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: D:\Programs\Java\Jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: D:\Programs\Java\Jre6\bin\new_plugin\npjp2.dll
.
============= SERVICES / DRIVERS ===============
.
R0 hotcore3;hc3ServiceName;C:\Windows\system32\DRIVERS\hotcore3.sys --> C:\Windows\system32\DRIVERS\hotcore3.sys [?]
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\system32\drivers\mfehidk.sys --> C:\Windows\system32\drivers\mfehidk.sys [?]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\system32\drivers\mfewfpk.sys --> C:\Windows\system32\drivers\mfewfpk.sys [?]
R1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\system32\DRIVERS\mfenlfk.sys --> C:\Windows\system32\DRIVERS\mfenlfk.sys [?]
R1 MOBK755Filter;MOBK755Filter;C:\Windows\system32\DRIVERS\MOBK755.sys --> C:\Windows\system32\DRIVERS\MOBK755.sys [?]
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 SASDIFSV;SASDIFSV;D:\Programs\Superantispiware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;D:\Programs\Superantispiware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;D:\Programs\Superantispiware\SASCore64.exe [2011-8-11 140672]
R2 LMIGuardianSvc;LMIGuardianSvc;D:\Programs\LogMeIn\x64\LMIGuardianSvc.exe [2011-3-1 375176]
R2 LMIInfo;LogMeIn Kernel Information Provider;D:\Programs\LogMeIn\x64\rainfo.sys [2010-9-17 15928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\C:\Windows\system32\drivers\LMIRfsDriver.sys --> C:\Windows\system32\drivers\LMIRfsDriver.sys [?]
R2 Lotus Notes Diagnostics;Lotus Notes Diagnostics;D:\Programs\IBM\Lotus\Notes\nsd.exe -svcinvoke -ini "C:\ProgramData\Lotus\Notes\Data\notes.ini" --> D:\Programs\IBM\Lotus\Notes\nsd.exe -svcinvoke -ini C:\ProgramData\Lotus\Notes\Data\notes.ini [?]
R2 MBAMService;MBAMService;D:\Programs\Malwarebytes' Anti-Malware\mbamservice.exe [2011-8-28 366640]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-5-26 355440]
R2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-5-26 355440]
R2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-5-26 355440]
R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-5-26 355440]
R2 McShield;McShield;C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe [2011-5-26 200056]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [2011-5-26 245352]
R2 mfevtp;McAfee Validation Trust Protection Service;"C:\Windows\system32\mfevtps.exe" --> C:\Windows\system32\mfevtps.exe [?]
R2 MOBK755backup;McAfee Online Backup Service;C:\Program Files (x86)\McAfee Online Backup\MOBK755backup.exe [2010-9-20 207672]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-7-4 2214504]
R2 UMVPFSrv;UMVPFSrv;C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2011-4-1 428640]
R2 UsbClientService;UsbClientService;D:\Programs\Assistant\UsbClientService.exe [2011-2-18 245760]
R3 busenum;Synology Virtual USB Hub;C:\Windows\system32\DRIVERS\busenum.sys --> C:\Windows\system32\DRIVERS\busenum.sys [?]
R3 cfwids;McAfee Inc. cfwids;C:\Windows\system32\drivers\cfwids.sys --> C:\Windows\system32\drivers\cfwids.sys [?]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;C:\Windows\system32\drivers\LGBusEnum.sys --> C:\Windows\system32\drivers\LGBusEnum.sys [?]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;C:\Windows\system32\drivers\LGVirHid.sys --> C:\Windows\system32\drivers\LGVirHid.sys [?]
R3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\system32\DRIVERS\lvrs64.sys --> C:\Windows\system32\DRIVERS\lvrs64.sys [?]
R3 LVUVC64;Logitech Webcam Pro 9000(UVC);C:\Windows\system32\DRIVERS\lvuvc64.sys --> C:\Windows\system32\DRIVERS\lvuvc64.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\system32\drivers\mfeavfk.sys --> C:\Windows\system32\drivers\mfeavfk.sys [?]
R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\system32\drivers\mfefirek.sys --> C:\Windows\system32\drivers\mfefirek.sys [?]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-6-7 136176]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;C:\Windows\system32\Drivers\ssadadb.sys --> C:\Windows\system32\Drivers\ssadadb.sys [?]
S3 DrvSnSht;DrvSnSht;C:\Program Files (x86)\R-Drive Image\DrvSnSht64.sys [2010-6-1 132432]
S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-6-7 136176]
S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\system32\drivers\mferkdet.sys --> C:\Windows\system32\drivers\mferkdet.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;D:\Programs\Microsoft Office\Office14\GROOVE.EXE [2010-1-21 51445112]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 R-ImageDisk;R-ImageDisk;C:\Program Files (x86)\R-Drive Image\R-ImageDisk64.sys [2010-10-16 187600]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 RemoteControl-USBLAN;RemoteControl-USBLAN;C:\Windows\system32\DRIVERS\rcblan.sys --> C:\Windows\system32\DRIVERS\rcblan.sys [?]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\system32\DRIVERS\ssadbus.sys --> C:\Windows\system32\DRIVERS\ssadbus.sys [?]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);C:\Windows\system32\DRIVERS\ssadmdfl.sys --> C:\Windows\system32\DRIVERS\ssadmdfl.sys [?]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;C:\Windows\system32\DRIVERS\ssadmdm.sys --> C:\Windows\system32\DRIVERS\ssadmdm.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 BCSWAP;BCSWAP;C:\Windows\system32\drivers\BCSWAP.sys --> C:\Windows\system32\drivers\BCSWAP.sys [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-09-02 22:45:06 -------- d-----w- C:\Users\emudryj\AppData\Local\{5D420F79-65F7-497C-92C7-85C067FAD907}
2011-09-02 22:44:56 -------- d-----w- C:\Users\emudryj\AppData\Local\{378986B6-0A63-4A35-8AC5-58670D00B5A4}
2011-09-02 01:00:52 -------- d-----w- C:\Users\emudryj\AppData\Local\{4C0D01BC-6237-45B2-928D-04BD39AB6415}
2011-09-02 01:00:42 -------- d-----w- C:\Users\emudryj\AppData\Local\{B9B49647-DA0A-4033-A5C1-BB3C40E4D588}
2011-09-02 00:54:20 8862544 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{DB9BFDEC-576B-40FF-A460-CF8EB3DDA8C7}\mpengine.dll
2011-08-31 23:49:13 -------- d-----w- C:\Users\emudryj\AppData\Local\{59F04404-93E6-437D-9615-F5541A046006}
2011-08-31 23:49:03 -------- d-----w- C:\Users\emudryj\AppData\Local\{A8F13873-1F4B-49D8-B1DC-15487AC86E7F}
2011-08-31 11:48:38 -------- d-----w- C:\Users\emudryj\AppData\Local\{E55A29EC-2BB2-4B23-BCC3-148B0DBBA141}
2011-08-31 11:48:29 -------- d-----w- C:\Users\emudryj\AppData\Local\{86BB2B69-3DC5-40D7-8E91-B058AD4A4586}
2011-08-30 23:39:58 -------- d-----w- C:\Users\emudryj\AppData\Local\{833A504C-3BDB-40E1-AF95-CF093D8D467A}
2011-08-30 23:39:48 -------- d-----w- C:\Users\emudryj\AppData\Local\{CE03C475-0CF9-421F-BF4C-FB132DA98457}
2011-08-29 23:26:42 -------- d-----w- C:\Users\emudryj\AppData\Local\{138CA9CB-66A6-422D-BBBE-D3B9367A39C0}
2011-08-29 23:26:30 -------- d-----w- C:\Users\emudryj\AppData\Local\{AA5C035F-E2AA-4980-87DB-C34AE7583807}
2011-08-29 01:33:52 -------- d-----w- C:\Users\emudryj\AppData\Local\{B3FCE715-40E5-4951-A376-511534EED9EB}
2011-08-29 01:33:41 -------- d-----w- C:\Users\emudryj\AppData\Local\{EA4C729C-E394-4E5B-933A-7C85C2B71AB9}
2011-08-28 15:41:51 -------- d-----w- C:\Users\emudryj\AppData\Roaming\Malwarebytes
2011-08-28 15:41:43 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-28 15:41:42 -------- d-----w- C:\ProgramData\Malwarebytes
2011-08-28 15:41:38 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-08-28 14:51:47 8862544 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-28 13:33:15 -------- d-----w- C:\Users\emudryj\AppData\Local\{D51F80AA-9F2A-4EAC-B587-F26979257B86}
2011-08-28 13:33:03 -------- d-----w- C:\Users\emudryj\AppData\Local\{B7D353E0-C9B1-4F58-B359-312DF7690B84}
2011-08-28 00:32:36 -------- d-----w- C:\Users\emudryj\AppData\Local\{671E52E2-D048-47D4-883C-08EE80BF6EEA}
2011-08-28 00:32:26 -------- d-----w- C:\Users\emudryj\AppData\Local\{3DDD0D53-7303-462A-82B0-0D581D9E04C4}
2011-08-27 23:22:10 -------- d-----w- C:\Users\emudryj\AppData\Roaming\SUPERAntiSpyware.com
2011-08-27 23:21:40 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2011-08-27 23:03:10 -------- d-sh--w- C:\$RECYCLE.BIN
2011-08-27 23:02:07 -------- d-----w- C:\Program Files\CCleaner
2011-08-27 21:53:54 -------- d-----w- C:\combofix
2011-08-27 20:37:53 77312 ----a-w- C:\Windows\SysWow64\ztvunace26.dll
2011-08-27 20:37:53 75264 ----a-w- C:\Windows\SysWow64\unacev2.dll
2011-08-27 20:37:53 69632 ----a-w- C:\Windows\SysWow64\ztvcabinet.dll
2011-08-27 20:37:53 162304 ----a-w- C:\Windows\SysWow64\ztvunrar36.dll
2011-08-27 20:37:53 153088 ----a-w- C:\Windows\SysWow64\UNRAR3.dll
2011-08-27 20:37:49 -------- d-----w- C:\Users\emudryj\AppData\Roaming\Simply Super Software
2011-08-27 20:37:49 -------- d-----w- C:\ProgramData\Simply Super Software
2011-08-27 20:32:00 601424 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{600DB068-0B6D-457E-9A2D-4FF95D9CBFD8}\gapaengine.dll
2011-08-27 20:28:18 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2011-08-27 20:28:14 -------- d-----w- C:\Program Files\Microsoft Security Client
2011-08-27 18:10:05 208896 ----a-w- C:\Windows\MBR.exe
2011-08-27 18:10:03 98816 ----a-w- C:\Windows\sed.exe
2011-08-27 18:10:03 518144 ----a-w- C:\Windows\SWREG.exe
2011-08-27 18:10:03 256000 ----a-w- C:\Windows\PEV.exe
2011-08-27 14:06:32 -------- d-----w- C:\ProgramData\PC Tools
2011-08-27 12:31:57 -------- d-----w- C:\Users\emudryj\AppData\Local\{1C1855F5-B7E5-4074-B1DD-03BDB227EC66}
2011-08-27 12:31:46 -------- d-----w- C:\Users\emudryj\AppData\Local\{56FB54D7-8B24-4635-9354-0D24A39A0A0D}
2011-08-27 00:19:39 24416 ----a-w- C:\Windows\SysWow64\drivers\regguard.sys
2011-08-27 00:16:03 39192 ----a-w- C:\Windows\System32\Partizan.exe
2011-08-27 00:12:30 39192 ----a-w- C:\Windows\SysWow64\Partizan.exe
2011-08-27 00:12:30 35816 ----a-w- C:\Windows\SysWow64\drivers\Partizan.sys
2011-08-27 00:12:15 2 --shatr- C:\Windows\winstart.bat
2011-08-27 00:12:12 12808 ----a-w- C:\Windows\SysWow64\drivers\UnHackMeDrv.sys
2011-08-26 23:59:39 -------- d-----w- C:\Users\emudryj\AppData\Local\{1A676F33-EA47-4FA7-A75F-6BC44BD66C73}
2011-08-26 23:59:29 -------- d-----w- C:\Users\emudryj\AppData\Local\{5970D767-FC4A-4DDA-9754-CDA2CC3A8981}
2011-08-25 23:33:44 -------- d-----w- C:\Users\emudryj\AppData\Local\{89FFD2D4-7D66-499A-9EEC-7AE3E2EBCCB5}
2011-08-25 23:33:33 -------- d-----w- C:\Users\emudryj\AppData\Local\{05A24F1F-9E10-4C71-8309-BCC4E5013ED8}
2011-08-24 22:36:42 -------- d-----w- C:\temp
2011-08-24 22:35:19 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-08-24 22:35:19 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-08-24 22:35:02 -------- d-----w- C:\Users\emudryj\AppData\Local\{93156864-4CC9-430E-95D3-E728C9E82443}
2011-08-24 22:34:22 -------- d-----w- C:\Users\emudryj\AppData\Local\{12861F1F-7AD4-4D74-84DF-D8A196981274}
2011-08-24 22:34:12 -------- d-----w- C:\Users\emudryj\AppData\Local\{78BA2C21-6301-4667-BFF8-F2213FD9A916}
2011-08-23 21:55:59 -------- d-----w- C:\Users\emudryj\AppData\Local\{816CC18E-DE44-428B-8B8E-CAD19C9706E4}
2011-08-23 21:55:49 -------- d-----w- C:\Users\emudryj\AppData\Local\{D569C2C6-EC46-430C-948C-47FF10D909D1}
2011-08-23 01:12:03 -------- d-----w- C:\Users\emudryj\AppData\Local\{722139F9-8402-45E5-B6B3-2CF8BC5EDAC4}
2011-08-23 01:11:52 -------- d-----w- C:\Users\emudryj\AppData\Local\{D1FC845F-A83A-404A-9448-B3E93F44D921}
2011-08-22 13:11:27 -------- d-----w- C:\Users\emudryj\AppData\Local\{43618183-8B30-4593-8611-804E0835F6B7}
2011-08-22 13:11:17 -------- d-----w- C:\Users\emudryj\AppData\Local\{E2E3CC70-8825-442D-9B99-CB09A25B008A}
2011-08-22 01:10:44 -------- d-----w- C:\Users\emudryj\AppData\Local\{19BBC1DA-D43F-4A15-8A58-4D5D1C13D9D8}
2011-08-22 01:10:34 -------- d-----w- C:\Users\emudryj\AppData\Local\{F21D0F4C-3CC2-4236-8C3E-7BD5AD04C2A5}
2011-08-21 13:10:09 -------- d-----w- C:\Users\emudryj\AppData\Local\{AB5D0240-0DD1-4247-9522-581419D0543E}
2011-08-21 13:09:59 -------- d-----w- C:\Users\emudryj\AppData\Local\{EB3247BB-3BA2-4E2C-95F0-EB82CB46B89C}
2011-08-21 00:26:42 -------- d-----w- C:\Users\emudryj\AppData\Local\{4534A216-1C9E-4D29-B8B8-8479829689D1}
2011-08-21 00:26:33 -------- d-----w- C:\Users\emudryj\AppData\Local\{8D89AF09-1B0B-4BEE-807C-8EBCDD5D2C0A}
2011-08-20 12:26:20 -------- d-----w- C:\Users\emudryj\AppData\Local\{4A9B7B7A-F9B1-44DD-8AE0-5FCEAD374320}
2011-08-20 12:26:11 -------- d-----w- C:\Users\emudryj\AppData\Local\{07FB85D1-222A-4B82-BDDD-340F1311D072}
2011-08-19 21:21:37 -------- d-----w- C:\Users\emudryj\AppData\Local\{CC336946-30CA-42DD-8EA3-CF9EB175C7C3}
2011-08-19 21:21:27 -------- d-----w- C:\Users\emudryj\AppData\Local\{E93D4164-F7ED-48D5-BD5D-BDE0C28EE04E}
2011-08-19 01:03:16 -------- d-----w- C:\Users\emudryj\AppData\Local\{13E3C684-CA53-47D0-81CF-6DA3A99FDE18}
2011-08-19 01:03:07 -------- d-----w- C:\Users\emudryj\AppData\Local\{296CE4B0-8C43-4DE7-9000-3ABAAD5DBED7}
2011-08-18 00:05:42 -------- d-----w- C:\Users\emudryj\AppData\Local\{703D44F2-5719-437B-9DDC-A95426E1E912}
2011-08-18 00:05:33 -------- d-----w- C:\Users\emudryj\AppData\Local\{3F6E0CB2-C38F-4B38-9DD7-FB68B7F4B8EA}
2011-08-17 00:55:52 -------- d-----w- C:\Users\emudryj\AppData\Local\{8BCC0D2D-DECB-4194-B6A1-0ED2B23AAB72}
2011-08-17 00:55:43 -------- d-----w- C:\Users\emudryj\AppData\Local\{58873267-F4AA-4635-AAA5-2624C5D5587C}
2011-08-16 12:36:12 -------- d-----w- C:\Users\emudryj\AppData\Local\{CD1DA322-D402-4F08-AD84-407AA93B03F3}
2011-08-16 12:36:02 -------- d-----w- C:\Users\emudryj\AppData\Local\{978C120A-8020-4D03-9CF0-01377FB25292}
2011-08-15 23:28:22 -------- d-----w- C:\Users\emudryj\AppData\Local\{11FAFA4D-262C-4C62-81CF-90FEAF96EC30}
2011-08-15 23:28:12 -------- d-----w- C:\Users\emudryj\AppData\Local\{FB617148-1A4E-423B-A422-9EE898F5983D}
2011-08-15 01:23:16 -------- d-----w- C:\Users\emudryj\AppData\Local\{F8AFFF45-B015-42B7-ADEF-30CC69955144}
2011-08-15 01:23:06 -------- d-----w- C:\Users\emudryj\AppData\Local\{300FDB03-0D51-4FE1-A10C-40392D98724A}
2011-08-14 17:02:12 271200 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-08-14 13:22:41 -------- d-----w- C:\Users\emudryj\AppData\Local\{2D8453F1-CFD1-4741-8263-204B1E1F00FA}
2011-08-14 13:22:30 -------- d-----w- C:\Users\emudryj\AppData\Local\{3FC2C278-66BA-43CC-8BF9-D523ED3B765F}
2011-08-14 01:22:06 -------- d-----w- C:\Users\emudryj\AppData\Local\{3C1D5EA0-F12C-4AAB-8B81-3D92905492AD}
2011-08-14 01:21:56 -------- d-----w- C:\Users\emudryj\AppData\Local\{69A39909-71F5-4F17-8F5F-31FB6757203C}
2011-08-13 13:21:31 -------- d-----w- C:\Users\emudryj\AppData\Local\{9471C865-8E17-4126-B7B2-86A9996E093A}
2011-08-13 13:21:21 -------- d-----w- C:\Users\emudryj\AppData\Local\{15B1B5CA-FA05-4D2D-89A4-93D9834E6540}
2011-08-13 01:20:56 -------- d-----w- C:\Users\emudryj\AppData\Local\{6AF20D7F-E605-4C81-A927-7A9FA91817B3}
2011-08-13 01:20:47 -------- d-----w- C:\Users\emudryj\AppData\Local\{EF4C1539-ED27-439C-B302-1F105B964FD0}
2011-08-12 00:10:02 -------- d-----w- C:\Users\emudryj\AppData\Local\{CB5CA58F-7AAF-420E-A309-0D638D0641A2}
2011-08-12 00:09:51 -------- d-----w- C:\Users\emudryj\AppData\Local\{8511E3B9-58C4-4F66-8A81-12C568E22A78}
2011-08-11 12:09:27 -------- d-----w- C:\Users\emudryj\AppData\Local\{E2DD06A1-D482-4394-9AD2-15D2BB81AD20}
2011-08-11 12:09:17 -------- d-----w- C:\Users\emudryj\AppData\Local\{F549E533-29AC-4102-943D-ED0876D50F2E}
2011-08-10 19:53:55 421888 ----a-w- C:\Windows\System32\KernelBase.dll
2011-08-10 19:51:17 -------- d-----w- C:\Users\emudryj\AppData\Local\{A5C7AC12-4376-4AC0-9A7A-6D65E910463C}
2011-08-10 19:51:07 -------- d-----w- C:\Users\emudryj\AppData\Local\{8840D864-E69B-414C-A963-3C7C87E7D03A}
2011-08-10 01:10:04 -------- d-----w- C:\Users\emudryj\AppData\Local\{82CC22D7-A14C-4FCC-8099-9E7B6F6C71DF}
2011-08-10 01:09:54 -------- d-----w- C:\Users\emudryj\AppData\Local\{8CD282E1-CAE3-4F12-9A1A-77B9A2B09FFA}
2011-08-09 13:09:42 -------- d-----w- C:\Users\emudryj\AppData\Local\{E2B75514-6F97-4448-A8FF-EF1B9E979760}
2011-08-09 13:09:32 -------- d-----w- C:\Users\emudryj\AppData\Local\{2AB93BBA-2177-40E6-86F3-B2AE5DBA4185}
2011-08-08 23:17:12 -------- d-----w- C:\Users\emudryj\AppData\Local\{50E87774-1190-40B5-8F14-9C397247887D}
2011-08-08 23:17:02 -------- d-----w- C:\Users\emudryj\AppData\Local\{6A194DC0-F131-45BD-B715-7159699ACE68}
2011-08-08 04:24:26 -------- d-----w- C:\Users\emudryj\AppData\Local\{44E6B8D4-22CD-418F-85A7-F8DB1725644C}
2011-08-08 04:24:16 -------- d-----w- C:\Users\emudryj\AppData\Local\{C79CCD31-C08F-4DA4-8533-1859DF532927}
2011-08-07 16:23:50 -------- d-----w- C:\Users\emudryj\AppData\Local\{1E2060F7-CF7A-4B31-85EC-A52A396C6F7D}
2011-08-07 16:23:40 -------- d-----w- C:\Users\emudryj\AppData\Local\{EDB99DEA-E23B-4074-BE43-A213F092F4D8}
2011-08-07 03:58:37 -------- d-----w- C:\Users\emudryj\AppData\Local\{174B67DB-B973-40E4-A261-C3DF223DA543}
2011-08-07 03:58:27 -------- d-----w- C:\Users\emudryj\AppData\Local\{A1047251-1F7B-4C4E-A313-A1B95D92A1A8}
2011-08-06 15:57:53 -------- d-----w- C:\Users\emudryj\AppData\Local\{11D119DD-DD7C-4261-849D-515BCF11F3D8}
2011-08-06 15:57:43 -------- d-----w- C:\Users\emudryj\AppData\Local\{E5859E1E-620A-47EB-A590-F4AC000EBBD1}
2011-08-06 01:56:36 -------- d-----w- C:\Users\emudryj\AppData\Local\{62D886A8-FE39-4E49-A01C-B51AB07B664C}
2011-08-06 01:56:26 -------- d-----w- C:\Users\emudryj\AppData\Local\{EB316BC4-BEB7-4B23-A33B-BB2EFD69EB10}
2011-08-05 12:52:50 -------- d-----w- C:\Users\emudryj\AppData\Local\{FB952384-9028-4D91-BE43-FAF9B333E484}
2011-08-05 12:52:40 -------- d-----w- C:\Users\emudryj\AppData\Local\{9CFFE45E-49E8-414B-91A5-F38BD0639AC2}
2011-08-05 03:53:26 -------- d-----w- C:\Windows\en
2011-08-05 03:52:51 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2011-08-05 03:52:07 18328 ----a-w- C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-08-05 03:51:02 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\e4d8b6b91cc532201\MeshBetaRemover.exe
2011-08-05 03:47:02 -------- d-----w- C:\Users\emudryj\AppData\Local\{2C11EB28-2BFD-4765-A854-A940F0A48352}
2011-08-04 12:24:02 -------- d-----w- C:\Users\emudryj\AppData\Local\{E1DCBF0A-4B1A-4C8F-9878-2F50DEDB4449}
.
==================== Find3M ====================
.
2011-09-02 01:44:37 271200 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2011-09-02 01:12:46 271200 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2011-08-31 00:06:22 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-22 05:42:23 2303488 ----a-w- C:\Windows\System32\jscript9.dll
2011-07-22 05:36:16 1389056 ----a-w- C:\Windows\System32\wininet.dll
2011-07-22 05:32:40 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-07-22 02:54:43 1797632 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-07-22 02:48:26 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-07-22 02:44:36 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-07-21 23:57:37 75136 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2011-07-19 21:08:14 87456 ----a-w- C:\Windows\System32\LMIRfsClientNP.dll.000.bak
2011-07-19 21:08:14 87456 ----a-w- C:\Windows\System32\LMIRfsClientNP.dll
2011-07-19 21:08:14 80768 ----a-w- C:\Windows\System32\LMIinit.dll
2011-07-19 21:08:14 33152 ----a-w- C:\Windows\System32\LMIport.dll
2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-07-16 04:29:19 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-07-16 04:26:00 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-07-16 04:25:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-07-16 04:24:23 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-07-16 04:24:22 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2011-07-16 02:21:44 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2011-07-16 02:21:41 2048 ----a-w- C:\Windows\SysWow64\user.exe
2011-07-16 02:17:19 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:17:19 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:17:19 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:17:19 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-07-14 04:52:28 127034 ------r- C:\Windows\bwUnin-8.1.1.50-8876480SL.exe
2011-07-14 03:26:14 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2011-07-09 02:46:28 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-06-24 05:34:53 214528 ----a-w- C:\Windows\System32\winsrv.dll
2011-06-24 05:25:49 338432 ----a-w- C:\Windows\System32\conhost.exe
2011-06-23 05:43:12 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-06-23 04:33:57 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-06-23 04:33:57 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-06-21 06:34:00 1923968 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-06-15 10:02:23 212992 ----a-w- C:\Windows\System32\odbctrac.dll
2011-06-15 10:02:23 163840 ----a-w- C:\Windows\System32\odbccp32.dll
2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccu32.dll
2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccr32.dll
2011-06-15 08:55:19 86016 ----a-w- C:\Windows\SysWow64\odbccu32.dll
2011-06-15 08:55:19 81920 ----a-w- C:\Windows\SysWow64\odbccr32.dll
2011-06-15 08:55:19 319488 ----a-w- C:\Windows\SysWow64\odbcjt32.dll
2011-06-15 08:55:19 163840 ----a-w- C:\Windows\SysWow64\odbctrac.dll
2011-06-15 08:55:19 122880 ----a-w- C:\Windows\SysWow64\odbccp32.dll
2011-06-11 03:07:25 3137536 ----a-w- C:\Windows\System32\win32k.sys
.
============= FINISH: 22:28:38.36 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:37 AM

Posted 03 September 2011 - 02:32 AM

Hello and Welcome to the forums!

My name is Gringo and I'll be glad to help you with your computer problems.

Somethings to remember while we are working together.

  • Do not run any other tool untill instructed to do so!
  • please Do not Attach logs or put in code boxes.
  • Tell me about any problems that have occurred during the fix.
  • Tell me of any other symptoms you may be having as these can help also.
  • Do not run anything while running a fix.
  • Do not run any other tool untill instructed to do so!


Click on the Watch Topic Button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 emudryj

emudryj
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:11:37 AM

Posted 03 September 2011 - 03:32 PM

Had multiple AV. choose one and uninstalled the other ones(superantispywere, ccleaner, etc..). I kept McAfee as the AV and Malwarebytes for malware.
I rebooted the computer right after removing the unneeded AV mentioned before.
Both, McAfee and Malwarebytes were disabled before running combofix.
It took a while but there was no problem whatsoever.
After reaching stage 50 computer rebooted itself and after coming back up the combofix log file showed up.
Here it is.

ComboFix 11-09-03.01 - emudryj 09/03/2011 15:18:33.3.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.6135.4098 [GMT -4:00]
Running from: c:\users\emudryj\Downloads\arreglacombo.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\bwUnin-8.1.1.50-8876480SL.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-08-03 to 2011-09-03 )))))))))))))))))))))))))))))))
.
.
2011-09-03 19:49 . 2011-09-03 19:49 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2011-09-03 19:49 . 2011-09-03 19:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-09-03 18:55 . 2011-09-03 18:55 -------- d-----w- c:\users\TEMP
2011-09-03 18:51 . 2011-09-03 18:51 -------- d-----w- c:\users\emudryj\AppData\Local\wj32
2011-08-31 00:04 . 2011-08-31 00:04 -------- d-----w- c:\windows\system32\Macromed
2011-08-28 15:41 . 2011-08-28 15:41 -------- d-----w- c:\users\emudryj\AppData\Roaming\Malwarebytes
2011-08-28 15:41 . 2011-07-06 23:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-28 15:41 . 2011-08-28 15:41 -------- d-----w- c:\programdata\Malwarebytes
2011-08-28 15:41 . 2011-07-06 23:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-27 23:21 . 2011-08-27 23:21 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-08-27 21:53 . 2011-09-03 19:10 -------- d-----w- C:\combofix
2011-08-27 14:06 . 2011-08-27 14:19 -------- d-----w- c:\programdata\PC Tools
2011-08-27 00:16 . 2011-08-27 00:16 39192 ----a-w- c:\windows\system32\Partizan.exe
2011-08-27 00:12 . 2011-08-27 00:12 2 --shatr- c:\windows\winstart.bat
2011-08-24 22:36 . 2011-08-24 22:36 -------- d-----w- C:\temp
2011-08-24 22:35 . 2011-07-09 05:26 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-24 22:35 . 2011-07-09 04:29 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-08-24 22:35 . 2011-08-24 22:35 -------- d-----w- c:\users\emudryj\AppData\Local\{93156864-4CC9-430E-95D3-E728C9E82443}
2011-08-14 17:02 . 2011-09-03 03:43 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-08-10 19:53 . 2011-07-16 05:41 243200 ----a-w- c:\windows\system32\wow64.dll
2011-08-05 03:53 . 2011-08-05 03:53 -------- d-----w- c:\windows\en
2011-08-05 03:52 . 2011-08-05 03:52 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2011-08-05 03:52 . 2011-08-05 03:52 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-08-05 03:51 . 2011-08-05 03:51 15712 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\e4d8b6b91cc532201\MeshBetaRemover.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-03 03:43 . 2011-07-22 00:02 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-09-02 01:44 . 2011-07-17 18:34 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2011-08-31 00:06 . 2011-06-27 17:53 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-21 23:57 . 2011-07-17 18:34 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-07-19 21:08 . 2011-05-26 02:20 87456 ----a-w- c:\windows\system32\LMIRfsClientNP.dll.000.bak
2011-07-19 21:08 . 2011-05-26 02:20 87456 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-07-19 21:08 . 2011-05-26 02:20 33152 ----a-w- c:\windows\system32\LMIport.dll
2011-07-19 21:08 . 2011-05-26 02:20 80768 ----a-w- c:\windows\system32\LMIinit.dll
2011-07-16 04:26 . 2011-08-10 19:53 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-07-14 03:26 . 2011-07-14 03:26 53248 ----a-r- c:\users\emudryj\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-07-14 03:26 . 2011-07-14 03:26 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-06-11 03:07 . 2011-07-12 23:53 3137536 ----a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((( SnapShot_2011-08-27_22.37.30 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-24 15:28 . 2011-09-03 18:55 57906 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-09-03 18:55 34880 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2011-05-24 09:21 . 2011-08-27 22:35 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-05-24 09:21 . 2011-09-03 19:53 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-05-24 09:21 . 2011-08-27 22:35 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-05-24 09:21 . 2011-09-03 19:53 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-08-27 22:35 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-09-03 19:53 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-01-11 22:05 . 2011-01-11 22:05 77128 c:\windows\Downloaded Program Files\CONFLICT.1\LMIProxyHelper.exe
+ 2011-08-27 23:55 . 2011-08-27 23:55 10240 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Serializ#\ed59e15a2a29d02c59dc383215cc85fc\System.Xml.Serialization.ni.dll
+ 2011-08-27 23:55 . 2011-08-27 23:55 43520 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Pres#\1a9bcef8abe20b3c0d53c535d680350f\System.Windows.Presentation.ni.dll
+ 2011-08-27 23:55 . 2011-08-27 23:55 86016 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Applicat#\0ee56d53077b281408cbf186e80ab175\System.Web.ApplicationServices.ni.dll
+ 2011-08-27 23:53 . 2011-08-27 23:53 97792 c:\windows\assembly\NativeImages_v4.0.30319_64\System.AddIn.Contra#\d53f3bf7a26f69ae3ad77f6732ebf9cf\System.AddIn.Contract.ni.dll
+ 2011-08-27 23:51 . 2011-08-27 23:51 14336 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualC\fbc331d848cf65928cc84de68eba079f\Microsoft.VisualC.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 10752 c:\windows\assembly\NativeImages_v4.0.30319_64\dfsvc\c551f53c6da4e594269e79636aef9f62\dfsvc.ni.exe
+ 2011-08-27 23:50 . 2011-08-27 23:50 58368 c:\windows\assembly\NativeImages_v4.0.30319_64\Accessibility\28f42eb8dddc9fd54d468171a8d2461d\Accessibility.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 96768 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\5e66ba90ab2f24317ca76582f3ea3948\UIAutomationProvider.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 35328 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Pres#\c42639bd8c7c7855c4d11be1f0ccdf97\System.Windows.Presentation.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 71680 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Applicat#\3be20b4f9e9df41aaea426041f4f410a\System.Web.ApplicationServices.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 82432 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\3bea7a34d24b4dc1e3925b0b9bc9d45b\System.ServiceModel.Channels.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 78848 c:\windows\assembly\NativeImages_v4.0.30319_32\System.AddIn.Contra#\882adb9ad5e9b434ef926193f595e757\System.AddIn.Contract.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 11776 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualC\7ee890ba3e1869ab04930948df453d3f\Microsoft.VisualC.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 44544 c:\windows\assembly\NativeImages_v4.0.30319_32\Accessibility\950b5b880e8d8af1709f06b6a1a854a0\Accessibility.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 60416 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Pres#\f4b0a65a0cad6d091bb903fb5f7f490d\System.Windows.Presentation.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 60416 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Pres#\f4b0a65a0cad6d091bb903fb5f7f490d\System.Windows.Presentation.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 54784 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\055b996b602a243bd4fcbdde8accc09c\System.Web.DynamicData.Design.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 54784 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\055b996b602a243bd4fcbdde8accc09c\System.Web.DynamicData.Design.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 90624 c:\windows\assembly\NativeImages_v2.0.50727_64\stdole\b33d58d0716cc4abc0183d5167bcdc2e\stdole.ni.dll
- 2011-08-10 20:18 . 2011-08-10 20:18 90624 c:\windows\assembly\NativeImages_v2.0.50727_64\stdole\b33d58d0716cc4abc0183d5167bcdc2e\stdole.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 72192 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFontCac#\fe5b12605f26ab36c26f0a3b3c475dd5\PresentationFontCache.ni.exe
+ 2011-08-27 23:49 . 2011-08-27 23:49 72192 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFontCac#\fe5b12605f26ab36c26f0a3b3c475dd5\PresentationFontCache.ni.exe
- 2011-08-11 19:04 . 2011-08-11 19:04 61952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCFFRast#\a2a31e05462d32f9f49febd89f515738\PresentationCFFRasterizer.ni.dll
+ 2011-08-27 23:41 . 2011-08-27 23:41 61952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCFFRast#\a2a31e05462d32f9f49febd89f515738\PresentationCFFRasterizer.ni.dll
+ 2011-08-27 23:48 . 2011-08-27 23:48 33792 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Run#\66019b987c020943413851e959ca80c2\Microsoft.WSMan.Runtime.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 33792 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Run#\66019b987c020943413851e959ca80c2\Microsoft.WSMan.Runtime.ni.dll
- 2011-08-10 20:21 . 2011-08-10 20:21 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\f2ee738d8439bf9025e1234c6afbd7e8\Microsoft.Windows.Diagnosis.SDHost.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\f2ee738d8439bf9025e1234c6afbd7e8\Microsoft.Windows.Diagnosis.SDHost.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 45056 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\e29ed5ad26446d196b4a5ea7e69c74e9\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 45056 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\e29ed5ad26446d196b4a5ea7e69c74e9\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 43520 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\b1c9507f23021701932fca6306d0df0f\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 43520 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\b1c9507f23021701932fca6306d0df0f\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 36864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\a4d48547af11390249b96fd1526ea514\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 36864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\a4d48547af11390249b96fd1526ea514\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
- 2011-08-10 20:21 . 2011-08-10 20:21 70144 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\636902d124bb3ee04ded9773d46f1d5d\Microsoft.Windows.Diagnosis.SDEngine.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 70144 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\636902d124bb3ee04ded9773d46f1d5d\Microsoft.Windows.Diagnosis.SDEngine.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 40448 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\6096a2f20727ede39049c5f3628b9a60\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 40448 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\6096a2f20727ede39049c5f3628b9a60\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 93696 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\f08621c868979befad8763fe0d125331\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 93696 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\f08621c868979befad8763fe0d125331\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\e64111bd10d5f438c9583b792b3607e1\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\e64111bd10d5f438c9583b792b3607e1\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 84480 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\e0ac06be22a8faf7637a87c3d2990f38\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 84480 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\e0ac06be22a8faf7637a87c3d2990f38\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 87040 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\aa2d67a0cadfb018e5325282d8c595de\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 87040 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\aa2d67a0cadfb018e5325282d8c595de\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.ni.dll
- 2011-08-10 20:16 . 2011-08-10 20:16 44544 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\99b4aa2629c9352abad71b63ccc0952b\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 44544 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\99b4aa2629c9352abad71b63ccc0952b\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 89088 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\9192fec4837545ae41f959c6a4f21265\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 89088 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\9192fec4837545ae41f959c6a4f21265\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.ni.dll
- 2011-08-10 20:16 . 2011-08-10 20:16 71680 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\861fcede19bd5fb41989b3cc06e936fb\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 71680 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\861fcede19bd5fb41989b3cc06e936fb\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\65ced0afa728e411a0c76ea34e923a47\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\65ced0afa728e411a0c76ea34e923a47\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 44544 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\3b44b6522f441ebf0ac8799d9ecaf2c9\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.ni.dll
- 2011-08-10 20:16 . 2011-08-10 20:16 44544 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\3b44b6522f441ebf0ac8799d9ecaf2c9\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 32256 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualC\ae0e01377a99fd22dde3dbea057fadb1\Microsoft.VisualC.ni.dll
- 2011-08-10 20:15 . 2011-08-10 20:15 32256 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualC\ae0e01377a99fd22dde3dbea057fadb1\Microsoft.VisualC.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 64000 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\dad98b9c968ce9a0b150753090c0d0aa\Microsoft.Security.ApplicationId.PolicyManagement.PolicyEngineApi.Interop.ni.dll
- 2011-08-10 20:19 . 2011-08-10 20:19 64000 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\dad98b9c968ce9a0b150753090c0d0aa\Microsoft.Security.ApplicationId.PolicyManagement.PolicyEngineApi.Interop.ni.dll
- 2011-08-10 20:19 . 2011-08-10 20:19 66048 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\cbba8254a8034f08e8b158ffd90e03e8\Microsoft.Security.ApplicationId.PolicyManagement.XmlHelper.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 66048 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\cbba8254a8034f08e8b158ffd90e03e8\Microsoft.Security.ApplicationId.PolicyManagement.XmlHelper.ni.dll
- 2011-08-10 20:19 . 2011-08-10 20:19 35840 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\4e3627453ac8a9f7770e3f64d3fc2879\Microsoft.Office.InfoPath.Permission.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 35840 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\4e3627453ac8a9f7770e3f64d3fc2879\Microsoft.Office.InfoPath.Permission.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 65536 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\b1a1a072eba978666cefe4f99fc6401c\Microsoft.MediaCenter.iTv.Hosting.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 65536 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\b1a1a072eba978666cefe4f99fc6401c\Microsoft.MediaCenter.iTv.Hosting.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 40960 c:\windows\assembly\NativeImages_v2.0.50727_64\LoadMxf\cdbee55e7f6c60f5cb56d6ec9f083951\LoadMxf.ni.exe
+ 2011-08-27 23:31 . 2011-08-27 23:31 40960 c:\windows\assembly\NativeImages_v2.0.50727_64\LoadMxf\cdbee55e7f6c60f5cb56d6ec9f083951\LoadMxf.ni.exe
+ 2011-08-27 23:31 . 2011-08-27 23:31 64000 c:\windows\assembly\NativeImages_v2.0.50727_64\ipdmctrl\c41af10612bb0639e717727bc22840a8\ipdmctrl.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 64000 c:\windows\assembly\NativeImages_v2.0.50727_64\ipdmctrl\c41af10612bb0639e717727bc22840a8\ipdmctrl.ni.dll
- 2011-08-10 20:18 . 2011-08-10 20:18 49664 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUPnP\16951451968fea951a2294c0ff4bd49e\ehiUPnP.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 49664 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUPnP\16951451968fea951a2294c0ff4bd49e\ehiUPnP.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 93184 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiTVMSMusic\867a57af137c4a524067cdbbf09766e0\ehiTVMSMusic.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 93184 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiTVMSMusic\867a57af137c4a524067cdbbf09766e0\ehiTVMSMusic.ni.dll
+ 2011-08-27 23:29 . 2011-08-27 23:29 28672 c:\windows\assembly\NativeImages_v2.0.50727_64\dfsvc\0c6cb1fd7a82938112cbea2c22e433df\dfsvc.ni.exe
- 2011-08-10 20:18 . 2011-08-10 20:18 28672 c:\windows\assembly\NativeImages_v2.0.50727_64\dfsvc\0c6cb1fd7a82938112cbea2c22e433df\dfsvc.ni.exe
+ 2011-08-27 22:55 . 2011-08-27 22:55 33280 c:\windows\assembly\NativeImages_v2.0.50727_64\AuditPolicyGPManage#\730d81fc0aa8d50175dcce63e8b68ef9\AuditPolicyGPManagedStubs.Interop.ni.dll
- 2011-08-10 20:15 . 2011-08-10 20:15 33280 c:\windows\assembly\NativeImages_v2.0.50727_64\AuditPolicyGPManage#\730d81fc0aa8d50175dcce63e8b68ef9\AuditPolicyGPManagedStubs.Interop.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 78848 c:\windows\assembly\NativeImages_v2.0.50727_64\Accessibility\23ea8465ac746c69a6ed7fdf628d3e9c\Accessibility.ni.dll
- 2011-08-10 20:15 . 2011-08-10 20:15 78848 c:\windows\assembly\NativeImages_v2.0.50727_64\Accessibility\23ea8465ac746c69a6ed7fdf628d3e9c\Accessibility.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 61440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\a7c9407e400a468846a53c7fc74a61b9\WindowsLiveWriter.ni.exe
- 2011-08-11 19:39 . 2011-08-11 19:39 61440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\a7c9407e400a468846a53c7fc74a61b9\WindowsLiveWriter.ni.exe
- 2011-08-11 19:39 . 2011-08-11 19:39 80896 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\becd6178ef5cb3df72825e83fcec5195\WindowsLive.Writer.Passport.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 80896 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\becd6178ef5cb3df72825e83fcec5195\WindowsLive.Writer.Passport.ni.dll
- 2011-08-10 20:33 . 2011-08-10 20:33 36352 c:\windows\assembly\NativeImages_v2.0.50727_32\WBOCXLib\d72de6cde3199642841199f8ac204ebd\WBOCXLib.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 36352 c:\windows\assembly\NativeImages_v2.0.50727_32\WBOCXLib\d72de6cde3199642841199f8ac204ebd\WBOCXLib.ni.dll
- 2011-08-10 20:33 . 2011-08-10 20:33 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\4a63fb97b3c648a28b8047697869ee7d\UIAutomationProvider.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\4a63fb97b3c648a28b8047697869ee7d\UIAutomationProvider.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\3ef94ae15e7d80bb818934265bb90c10\System.Windows.Presentation.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\3ef94ae15e7d80bb818934265bb90c10\System.Windows.Presentation.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\dd2bb107a0bbac08a0ccaf93c8bb7490\System.Web.DynamicData.Design.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\dd2bb107a0bbac08a0ccaf93c8bb7490\System.Web.DynamicData.Design.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\54d33aa6cf3af2d6e28c7d46c0ce363f\System.ComponentModel.DataAnnotations.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\54d33aa6cf3af2d6e28c7d46c0ce363f\System.ComponentModel.DataAnnotations.ni.dll
- 2011-08-10 20:34 . 2011-08-10 20:34 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\e88e6ace53ab318210c1657483321e40\System.AddIn.Contract.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\e88e6ace53ab318210c1657483321e40\System.AddIn.Contract.ni.dll
- 2011-08-10 20:33 . 2011-08-10 20:33 44032 c:\windows\assembly\NativeImages_v2.0.50727_32\stdole\cd32e850b908317981c109dd20a0d5b2\stdole.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 44032 c:\windows\assembly\NativeImages_v2.0.50727_32\stdole\cd32e850b908317981c109dd20a0d5b2\stdole.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 50688 c:\windows\assembly\NativeImages_v2.0.50727_32\StardockCentralDSkin\3f7040ae2f00439dc682f4a93a5b3cc1\StardockCentralDSkin.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 50688 c:\windows\assembly\NativeImages_v2.0.50727_32\StardockCentralDSkin\3f7040ae2f00439dc682f4a93a5b3cc1\StardockCentralDSkin.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 56320 c:\windows\assembly\NativeImages_v2.0.50727_32\Stardock.Central.Se#\412d8c1517c439908eaf64ce735706d9\Stardock.Central.Security.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 56320 c:\windows\assembly\NativeImages_v2.0.50727_32\Stardock.Central.Se#\412d8c1517c439908eaf64ce735706d9\Stardock.Central.Security.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 98816 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Uninstall\314fbe351cad73019b4f90f8c3fcb7d4\Sd.Uninstall.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 98816 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Uninstall\314fbe351cad73019b4f90f8c3fcb7d4\Sd.Uninstall.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\fe7afc935e0c66172577a1ded815993b\PresentationFontCache.ni.exe
+ 2011-08-27 22:52 . 2011-08-27 22:52 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\fe7afc935e0c66172577a1ded815993b\PresentationFontCache.ni.exe
- 2011-08-11 19:06 . 2011-08-11 19:06 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\e5c56e2a79ebb350e0aa6805f4d5e649\PresentationCFFRasterizer.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\e5c56e2a79ebb350e0aa6805f4d5e649\PresentationCFFRasterizer.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 79872 c:\windows\assembly\NativeImages_v2.0.50727_32\napcrypt\69b036f1479a9aa93430f2d1676032b2\napcrypt.ni.dll
- 2011-08-10 20:34 . 2011-08-10 20:34 79872 c:\windows\assembly\NativeImages_v2.0.50727_32\napcrypt\69b036f1479a9aa93430f2d1676032b2\napcrypt.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 17920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Run#\ab2d4de59dee683a2f77123f671839ba\Microsoft.WSMan.Runtime.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 17920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Run#\ab2d4de59dee683a2f77123f671839ba\Microsoft.WSMan.Runtime.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 25088 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\8a102c44ccfe60d131d7e350d149bf85\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 25088 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\8a102c44ccfe60d131d7e350d149bf85\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 19968 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\7ce6ebef5427853ecb5bd68da29f1fdd\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 19968 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\7ce6ebef5427853ecb5bd68da29f1fdd\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 21504 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\405aa271df15b8ce1b0b970f37687152\Microsoft.Windows.Diagnosis.SDEngine.ni.dll
- 2011-08-10 20:34 . 2011-08-10 20:34 21504 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\405aa271df15b8ce1b0b970f37687152\Microsoft.Windows.Diagnosis.SDEngine.ni.dll
- 2011-08-10 20:34 . 2011-08-10 20:34 32256 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\3442a002e4e5d93ca3895a29ba7adb74\Microsoft.Windows.Diagnosis.SDHost.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 32256 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\3442a002e4e5d93ca3895a29ba7adb74\Microsoft.Windows.Diagnosis.SDHost.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 23040 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\20c20811d44ba8c9513f2f2ba96d7047\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 23040 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\20c20811d44ba8c9513f2f2ba96d7047\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 27136 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\09a9791efe9f32a50bd01346f0b05666\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 27136 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\09a9791efe9f32a50bd01346f0b05666\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 86528 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\034ab6a3d60fdfba641443f16efdf309\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 86528 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\034ab6a3d60fdfba641443f16efdf309\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\2ac41c859d5e5e84993a555e3eeaea90\Microsoft.Vsa.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\2ac41c859d5e5e84993a555e3eeaea90\Microsoft.Vsa.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\fa0ab046907e7ed154ce2ba749eebb52\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\fa0ab046907e7ed154ce2ba749eebb52\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.ni.dll
- 2011-08-10 20:31 . 2011-08-10 20:31 35328 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\f356c4455ca50bd2b3d1707214229ad8\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 35328 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\f356c4455ca50bd2b3d1707214229ad8\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 43008 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\c5a915e87a37fdedf41ac24ee5f97bb1\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 43008 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\c5a915e87a37fdedf41ac24ee5f97bb1\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 42496 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\b282b2b3144437e0322d3c6c29e734d6\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 42496 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\b282b2b3144437e0322d3c6c29e734d6\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 84992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\9207940676e6fd95032e2f46f90bc862\Microsoft.VisualStudio.Tools.Office.Outlook.HostAdapter.v10.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 58368 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\8d721ab82f8d49ed7d3fcc4f547cee5d\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 58368 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\8d721ab82f8d49ed7d3fcc4f547cee5d\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.ni.dll
- 2011-08-10 20:31 . 2011-08-10 20:31 28160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\51705dba55e430dd088a76e7c07f8d3e\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 28160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\51705dba55e430dd088a76e7c07f8d3e\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 54784 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\3534f931f053ffd10f687f48170cd9c0\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 54784 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\3534f931f053ffd10f687f48170cd9c0\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 66560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\1bae59136b7143a0a5dd3d927d9ed4bd\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 66560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\1bae59136b7143a0a5dd3d927d9ed4bd\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 28672 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\0c0a573d4a6aba73f2916a1d9e56bfb3\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.ni.dll
- 2011-08-10 20:31 . 2011-08-10 20:31 28672 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\0c0a573d4a6aba73f2916a1d9e56bfb3\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\f7ce61c1a288adc4c39512d9f6767daf\Microsoft.VisualC.ni.dll
- 2011-08-10 20:31 . 2011-08-10 20:31 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\f7ce61c1a288adc4c39512d9f6767daf\Microsoft.VisualC.ni.dll
- 2011-08-10 20:34 . 2011-08-10 20:34 21504 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\d0a9152ccf7fdbbff625ca972783ece8\Microsoft.Security.ApplicationId.PolicyManagement.PolicyEngineApi.Interop.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 21504 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\d0a9152ccf7fdbbff625ca972783ece8\Microsoft.Security.ApplicationId.PolicyManagement.PolicyEngineApi.Interop.ni.dll
- 2011-08-10 20:34 . 2011-08-10 20:34 39936 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\261ccf76aae6ac8c396b7e40370f9430\Microsoft.Security.ApplicationId.PolicyManagement.XmlHelper.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 39936 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\261ccf76aae6ac8c396b7e40370f9430\Microsoft.Security.ApplicationId.PolicyManagement.XmlHelper.ni.dll
- 2011-08-10 20:34 . 2011-08-10 20:34 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\9152d7f0adafac97d853647ca783b8e4\Microsoft.Build.Framework.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\9152d7f0adafac97d853647ca783b8e4\Microsoft.Build.Framework.ni.dll
- 2011-08-10 20:34 . 2011-08-10 20:34 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\5c219cc49d452997a91d916309511e68\Microsoft.Build.Framework.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\5c219cc49d452997a91d916309511e68\Microsoft.Build.Framework.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.ShockwaveFl#\fb726243261251c4bfd0e6c1f65c6fce\Interop.ShockwaveFlashObjects.ni.dll
- 2011-08-10 20:33 . 2011-08-10 20:33 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.ShockwaveFl#\fb726243261251c4bfd0e6c1f65c6fce\Interop.ShockwaveFlashObjects.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 60416 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\ac010bace23545b3a5b1825e5c7b046e\ehiUserXp.ni.dll
- 2011-08-10 20:33 . 2011-08-10 20:33 60416 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\ac010bace23545b3a5b1825e5c7b046e\ehiUserXp.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\027211443c6da8187fe92e682c048cd5\dfsvc.ni.exe
- 2011-08-10 20:33 . 2011-08-10 20:33 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\027211443c6da8187fe92e682c048cd5\dfsvc.ni.exe
+ 2011-08-27 22:50 . 2011-08-27 22:50 57344 c:\windows\assembly\NativeImages_v2.0.50727_32\AxInterop.Shockwave#\1dbae557d869ed385b7deaf547884360\AxInterop.ShockwaveFlashObjects.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 57344 c:\windows\assembly\NativeImages_v2.0.50727_32\AxInterop.Shockwave#\1dbae557d869ed385b7deaf547884360\AxInterop.ShockwaveFlashObjects.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\AuditPolicyGPManage#\8286e5ea12f08f351f0d00280de1beba\AuditPolicyGPManagedStubs.Interop.ni.dll
- 2011-08-10 20:31 . 2011-08-10 20:31 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\AuditPolicyGPManage#\8286e5ea12f08f351f0d00280de1beba\AuditPolicyGPManagedStubs.Interop.ni.dll
- 2011-08-10 20:31 . 2011-08-10 20:31 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\b614f2d2f13857c09c98b02944fc1c41\Accessibility.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\b614f2d2f13857c09c98b02944fc1c41\Accessibility.ni.dll
+ 2011-05-26 07:17 . 2011-09-02 02:49 4356 c:\windows\system32\wdi\ERCQueuedResolutions.dat
- 2011-05-26 07:17 . 2011-08-26 04:00 4356 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2011-05-24 14:31 . 2011-09-03 18:55 8306 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3999918964-3837148993-3667228684-1000_UserData.bin
+ 2011-01-11 22:05 . 2011-01-11 22:05 8592 c:\windows\system32\ractrlkeyhook.dll
- 2011-08-27 22:35 . 2011-08-27 22:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-09-03 19:53 . 2011-09-03 19:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-08-27 22:35 . 2011-08-27 22:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-09-03 19:53 . 2011-09-03 19:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-08-27 22:55 . 2011-08-27 22:55 9216 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Serializ#\1a890e72269abe36365d861bca8fca70\System.Xml.Serialization.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 9728 c:\windows\assembly\NativeImages_v4.0.30319_32\dfsvc\e335cdfdb3e46fb0f75cb2ce83dabf48\dfsvc.ni.exe
+ 2011-08-31 00:06 . 2011-08-31 00:06 247456 c:\windows\SysWOW64\Macromed\Flash\FlashUtil11a_Plugin.exe
+ 2011-08-31 00:04 . 2011-08-31 00:04 247456 c:\windows\SysWOW64\Macromed\Flash\FlashUtil11a_ActiveX.exe
+ 2011-08-31 00:04 . 2011-08-31 00:04 335520 c:\windows\SysWOW64\Macromed\Flash\FlashUtil11a_ActiveX.dll
+ 2011-05-24 15:26 . 2011-09-03 18:57 706104 c:\windows\system32\perfh00A.dat
+ 2009-07-14 02:36 . 2011-09-03 18:57 628658 c:\windows\system32\perfh009.dat
+ 2011-05-24 15:26 . 2011-09-03 18:57 138638 c:\windows\system32\perfc00A.dat
+ 2009-07-14 02:36 . 2011-09-03 18:57 107964 c:\windows\system32\perfc009.dat
+ 2011-05-24 14:32 . 2010-10-19 20:51 270720 c:\windows\system32\MpSigStub.exe
- 2011-05-24 14:32 . 2010-10-19 15:33 270720 c:\windows\system32\MpSigStub.exe
+ 2011-08-31 00:06 . 2011-08-31 00:06 460448 c:\windows\system32\Macromed\Flash\FlashUtil64_11_0_1_Plugin.exe
+ 2011-08-31 00:04 . 2011-08-31 00:04 460448 c:\windows\system32\Macromed\Flash\FlashUtil64_11_0_1_ActiveX.exe
+ 2011-08-31 00:04 . 2011-08-31 00:04 376480 c:\windows\system32\Macromed\Flash\FlashUtil64_11_0_1_ActiveX.dll
- 2009-07-14 04:45 . 2011-07-14 01:17 418216 c:\windows\system32\FNTCACHE.DAT
+ 2011-08-29 02:26 . 2011-08-29 02:26 418216 c:\windows\system32\FNTCACHE.DAT
- 2009-07-14 05:01 . 2011-08-27 21:43 389820 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-09-03 19:52 389820 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-03-21 18:48 . 2011-03-21 18:48 310144 c:\windows\Downloaded Program Files\CONFLICT.1\LMIGuardianEvt.dll
+ 2011-03-21 18:51 . 2011-03-21 18:51 375184 c:\windows\Downloaded Program Files\CONFLICT.1\LMIGuardian.exe
+ 2011-08-30 01:16 . 2011-08-30 01:16 144272 c:\windows\Downloaded Program Files\CONFLICT.1\LMIBroker.exe
+ 2011-08-27 23:55 . 2011-08-27 23:55 336896 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsFormsIntegra#\d3536aadcda3bf1628fd5cb912f0d4df\WindowsFormsIntegration.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 231424 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationTypes\0bbce3d1912c29cdb65f7c7bfdfd8a01\UIAutomationTypes.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 122368 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationProvider\65616f4785226d28371ccf809e213fa6\UIAutomationProvider.ni.dll
+ 2011-08-27 23:55 . 2011-08-27 23:55 645120 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClient\cd62d82bb2e0ebe93c68c701a281d204\UIAutomationClient.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 528896 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Linq\70a6db2664fa1f7e996c58f81f63754d\System.Xml.Linq.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 256000 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Inpu#\321d4a33b1363649a45f47f8fbc107c9\System.Windows.Input.Manipulations.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 903168 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Transactions\fbffd4e050d2e397f5b51bcbede33326\System.Transactions.ni.dll
+ 2011-08-27 23:55 . 2011-08-27 23:55 281088 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceProce#\41a328f3f1e01dd6d6c45ec27dfb8d12\System.ServiceProcess.ni.dll
+ 2011-08-27 23:55 . 2011-08-27 23:55 517120 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\8a3044d7b76d748396c01aec083a1b01\System.ServiceModel.Routing.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 108032 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\4288f4e2ad790e4510344567c092ca68\System.ServiceModel.Channels.ni.dll
+ 2011-08-27 23:51 . 2011-08-27 23:51 946688 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Security\481e4462ee5dbf73d7f92d14505eabca\System.Security.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 376832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\93ea6aa98aa92eb1c27130599616cd48\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 987648 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Remo#\e01521d8c282ad1e79f9c8334cd4baef\System.Runtime.Remoting.ni.dll
+ 2011-08-27 23:51 . 2011-08-27 23:51 176640 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Numerics\0615b26e34fbb01ff661b827e8d80c97\System.Numerics.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 933376 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Net\836b59a54e74d2a9350d9dbcbee44e7d\System.Net.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 781824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Messaging\e530f9f49dcc8196f1333f65d9e17a51\System.Messaging.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 521728 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Management.I#\ca30070d69a7575b9b3637fde765b533\System.Management.Instrumentation.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 531456 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IO.Log\1af1dc859f12d724d15c2f8ac01b7d84\System.IO.Log.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 290816 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IdentityMode#\a236c6b9a7fa2dd99f840ffedb685464\System.IdentityModel.Selectors.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 348672 c:\windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\a8ac353249c61750e03ace04cce91d12\System.EnterpriseServices.Wrapper.dll
+ 2011-08-27 23:51 . 2011-08-27 23:51 512000 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Dynamic\d0cb2f5412272538eead0de22ee232c1\System.Dynamic.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 632832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\87240375600b6608957d4877632deacd\System.DirectoryServices.Protocols.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 141824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Device\22c569ca3bf7de3f386881fdaaefcf5c\System.Device.ni.dll
+ 2011-08-27 23:53 . 2011-08-27 23:53 176128 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.DataSet#\848a93911e91183c5833abac3c19b8c7\System.Data.DataSetExtensions.ni.dll
+ 2011-08-27 23:53 . 2011-08-27 23:53 181760 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuratio#\9ef51cbff9a0a281683413ff85bdc67e\System.Configuration.Install.ni.dll
+ 2011-08-27 23:53 . 2011-08-27 23:53 255488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\e5886d887164c57e7bbcff9eace93aff\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-08-27 23:53 . 2011-08-27 23:53 865792 c:\windows\assembly\NativeImages_v4.0.30319_64\System.AddIn\a618c2c8cd6669a1f562d583de816049\System.AddIn.ni.dll
+ 2011-08-27 23:53 . 2011-08-27 23:53 560640 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.D#\c06a32f20b3a8c40bb9ee4caaa7f791f\System.Activities.DurableInstancing.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 432128 c:\windows\assembly\NativeImages_v4.0.30319_64\SMSvcHost\898051ff62d86ecbb43c730672a5ce01\SMSvcHost.ni.exe
+ 2011-08-27 23:52 . 2011-08-27 23:52 185344 c:\windows\assembly\NativeImages_v4.0.30319_64\SMDiagnostics\2b6fb4f3fe65c3384cd588c84d5f426a\SMDiagnostics.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 802304 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\e7d3ae8b894e645f195435b0d0cca3d5\PresentationFramework.Luna.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 349184 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\9faf962dcc325fbdecde08f2b4b4de12\PresentationFramework.Classic.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 622592 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\89a56671c51182608a36ddabf7f11579\PresentationFramework.Aero.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 428032 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\1144c8dd74e20a85a56ea12af48cc763\PresentationFramework.Royale.ni.dll
+ 2011-08-27 23:51 . 2011-08-27 23:51 422400 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\78dbb63ddb830c7b67915373a26a64cb\Microsoft.VisualBasic.Compatibility.Data.ni.dll
+ 2011-08-27 23:51 . 2011-08-27 23:51 600064 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\2c6b57b8d66eb686e39af125a7b9cd3f\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 279552 c:\windows\assembly\NativeImages_v4.0.30319_64\CustomMarshalers\4b8193e798a848470e64c71f71a230a4\CustomMarshalers.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 253952 c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsFormsIntegra#\1b8d986036465b9f0db4fbaf8876ad72\WindowsFormsIntegration.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 196096 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\7b9037ad1952bc81a382b2fcddd8320a\UIAutomationTypes.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 484352 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClient\08b935a4ef1b64faec4e9739db313298\UIAutomationClient.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 393216 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\0f5813c19bc6dc46e87c6beafb97d525\System.Xml.Linq.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 189440 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Inpu#\8681ad3f75515a261e7980d01ac5fa2e\System.Windows.Input.Manipulations.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 649728 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\5314989a2066877016eaac44f927092c\System.Transactions.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 221696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\b784695a620842be9b660769dd43c898\System.ServiceProcess.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 369664 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\8671670b07fb8597048ef4aae0a5ede4\System.ServiceModel.Routing.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 311296 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\e8452df7471e5ba24ca642b4c4e1ef37\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 762880 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\bbc34aac73481fc04fe9b7aff9927437\System.Runtime.Remoting.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 657408 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Net\0db265c571d2baf9c46511b9955fa7c4\System.Net.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 626176 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Messaging\5539ada158b0520c68ab8cbaa6dab8b2\System.Messaging.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 395264 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management.I#\89a46fc2fa698580fd2fa81df5cd020a\System.Management.Instrumentation.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 413696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IO.Log\e022b746f10ca855a632ff405f7f1259\System.IO.Log.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 229888 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityMode#\a6518b3baf1d987d831c5fc1b295306d\System.IdentityModel.Selectors.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 236032 c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\3c81550255199caad42b6927e52cbe20\System.EnterpriseServices.Wrapper.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 787456 c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\3c81550255199caad42b6927e52cbe20\System.EnterpriseServices.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 913920 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\8227f92f9e71e619b541050995617717\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 470528 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\6ec8651192262a0732c9c187486e9fb9\System.DirectoryServices.Protocols.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 112640 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Device\1652ce31226964496c1d5b5b4f69277e\System.Device.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 134656 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.DataSet#\5b1934fc32b50e5a42a64999d0b27112\System.Data.DataSetExtensions.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 148480 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuratio#\7a2a83b1625f100331691f44b6e9c3ab\System.Configuration.Install.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 194048 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\a3084fbf0204cd93a9d1e8722774f0b7\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 617984 c:\windows\assembly\NativeImages_v4.0.30319_32\System.AddIn\6254a35e295c52224f7bdc9e5ac9c81f\System.AddIn.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 411136 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.D#\2b905c99ccccb248a7653fabe4b55b09\System.Activities.DurableInstancing.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 317952 c:\windows\assembly\NativeImages_v4.0.30319_32\SMSvcHost\51bdfe23e8b22bbed5fabfed9371b5b0\SMSvcHost.ni.exe
+ 2011-08-27 22:53 . 2011-08-27 22:53 143360 c:\windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\ef32e2d63c908a8e4b21b30b2debcd03\SMDiagnostics.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 303104 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\43eb12b6198092efc2b8a030ace2e3f2\Microsoft.VisualBasic.Compatibility.Data.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 418816 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\da0ae911ee95f4e67660e8e584ca8e7b\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 194048 c:\windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\8bd0bb7822eb2d50cb4c1a82a7f934e8\CustomMarshalers.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 468992 c:\windows\assembly\NativeImages_v2.0.50727_64\WsatConfig\bfb29034e69046d05e1ff758c0fcda27\WsatConfig.ni.exe
- 2011-08-11 19:46 . 2011-08-11 19:46 468992 c:\windows\assembly\NativeImages_v2.0.50727_64\WsatConfig\bfb29034e69046d05e1ff758c0fcda27\WsatConfig.ni.exe
+ 2011-08-27 23:50 . 2011-08-27 23:50 329216 c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsFormsIntegra#\1c573262c14ba755ac6ccab0945711cb\WindowsFormsIntegration.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 329216 c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsFormsIntegra#\1c573262c14ba755ac6ccab0945711cb\WindowsFormsIntegration.ni.dll
- 2011-08-10 20:21 . 2011-08-10 20:21 253952 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationTypes\d4f8fb1bc01621e0b7a19ee0954917d5\UIAutomationTypes.ni.dll
+ 2011-08-27 23:41 . 2011-08-27 23:41 253952 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationTypes\d4f8fb1bc01621e0b7a19ee0954917d5\UIAutomationTypes.ni.dll
- 2011-08-10 20:21 . 2011-08-10 20:21 120832 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationProvider\427b7ac4bbe49410e494979928d9b560\UIAutomationProvider.ni.dll
+ 2011-08-27 23:41 . 2011-08-27 23:41 120832 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationProvider\427b7ac4bbe49410e494979928d9b560\UIAutomationProvider.ni.dll
+ 2011-08-27 23:41 . 2011-08-27 23:41 653312 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClient\ad5c1e837ea97e2e6401fd4fac9d99d4\UIAutomationClient.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 653312 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClient\ad5c1e837ea97e2e6401fd4fac9d99d4\UIAutomationClient.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 304128 c:\windows\assembly\NativeImages_v2.0.50727_64\TaskScheduler\50621c88a5345fd8fcb959a9fc25f084\TaskScheduler.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 304128 c:\windows\assembly\NativeImages_v2.0.50727_64\TaskScheduler\50621c88a5345fd8fcb959a9fc25f084\TaskScheduler.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 529920 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml.Linq\ebd55d35d25cf10e6e24453238d3c5eb\System.Xml.Linq.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 529920 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml.Linq\ebd55d35d25cf10e6e24453238d3c5eb\System.Xml.Linq.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 187392 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Routing\0bf594db7ec4fd4754f7535f24b254aa\System.Web.Routing.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 187392 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Routing\0bf594db7ec4fd4754f7535f24b254aa\System.Web.Routing.ni.dll
+ 2011-08-27 23:28 . 2011-08-27 23:28 261120 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.RegularE#\f46bab10a21dd08219f69cf58c6e5766\System.Web.RegularExpressions.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 261120 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.RegularE#\f46bab10a21dd08219f69cf58c6e5766\System.Web.RegularExpressions.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 449024 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity\09199f147cafe8a357cbcf68f6098a77\System.Web.Entity.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 449024 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity\09199f147cafe8a357cbcf68f6098a77\System.Web.Entity.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 398848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity.D#\b21a0f26bff3d30480050c41f4f786f6\System.Web.Entity.Design.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 398848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity.D#\b21a0f26bff3d30480050c41f4f786f6\System.Web.Entity.Design.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 753664 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\adfea0205de0aeb42c9bd80be40d7c47\System.Web.DynamicData.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 753664 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\adfea0205de0aeb42c9bd80be40d7c47\System.Web.DynamicData.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 204800 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Abstract#\b6cc0ab04339d7cf16e83487e921fb71\System.Web.Abstractions.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 204800 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Abstract#\b6cc0ab04339d7cf16e83487e921fb71\System.Web.Abstractions.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 921600 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\5fbe4fcbb4259d38e57006802c957e23\System.Transactions.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 921600 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\5fbe4fcbb4259d38e57006802c957e23\System.Transactions.ni.dll
+ 2011-08-27 23:29 . 2011-08-27 23:29 295424 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\d69463a51d3536074bff664c0a097b1f\System.ServiceProcess.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 295424 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\d69463a51d3536074bff664c0a097b1f\System.ServiceProcess.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 928768 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Security\f330ec3533f2f0cb4c6dacd3a3e48044\System.Security.ni.dll
- 2011-08-11 19:03 . 2011-08-11 19:03 928768 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Security\f330ec3533f2f0cb4c6dacd3a3e48044\System.Security.ni.dll
+ 2011-08-27 23:28 . 2011-08-27 23:28 396288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\ddd7749c4f3e68ca556795b7cd2a7a00\System.Runtime.Serialization.Formatters.Soap.ni.dll
- 2011-08-11 19:04 . 2011-08-11 19:04 396288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\ddd7749c4f3e68ca556795b7cd2a7a00\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 916480 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Net\0646a91d680e840b201eb7a96876f053\System.Net.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 916480 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Net\0646a91d680e840b201eb7a96876f053\System.Net.ni.dll
+ 2011-08-27 23:29 . 2011-08-27 23:29 783360 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Messaging\f53e6c7d027431c87b5839036a2f977d\System.Messaging.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 783360 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Messaging\f53e6c7d027431c87b5839036a2f977d\System.Messaging.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 534016 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.I#\b9e961f0a21c8afe6213218fdbc8f8a2\System.Management.Instrumentation.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 534016 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.I#\b9e961f0a21c8afe6213218fdbc8f8a2\System.Management.Instrumentation.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 569856 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IO.Log\49a6af02ac362d95ccf98068492053e5\System.IO.Log.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 569856 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IO.Log\49a6af02ac362d95ccf98068492053e5\System.IO.Log.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 294400 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityMode#\4b21a062e82d08cf0ce61e7f1c8d1f2a\System.IdentityModel.Selectors.ni.dll
+ 2011-08-27 23:29 . 2011-08-27 23:29 294400 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityMode#\4b21a062e82d08cf0ce61e7f1c8d1f2a\System.IdentityModel.Selectors.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 446464 c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\1f84610e9a8c80e23e82f82cc4a894a3\System.EnterpriseServices.Wrapper.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 446464 c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\1f84610e9a8c80e23e82f82cc4a894a3\System.EnterpriseServices.Wrapper.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 288768 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing.Desi#\2327e346f00d0f89825a86e691d84dcc\System.Drawing.Design.ni.dll
+ 2011-08-27 23:28 . 2011-08-27 23:28 288768 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing.Desi#\2327e346f00d0f89825a86e691d84dcc\System.Drawing.Design.ni.dll
+ 2011-08-27 23:29 . 2011-08-27 23:29 649728 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\28d1d4c0f794a46ecdf34df502c3e20a\System.DirectoryServices.Protocols.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 649728 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\28d1d4c0f794a46ecdf34df502c3e20a\System.DirectoryServices.Protocols.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 629760 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\5e0b2a3713da55d99450c9cad93c4d2f\System.Data.Services.Design.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 629760 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\5e0b2a3713da55d99450c9cad93c4d2f\System.Data.Services.Design.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 194560 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.DataSet#\486d44582be2000df84c46e187a88e70\System.Data.DataSetExtensions.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 194560 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.DataSet#\486d44582be2000df84c46e187a88e70\System.Data.DataSetExtensions.ni.dll
+ 2011-08-27 23:29 . 2011-08-27 23:29 192000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\89adf5c48e4551ba19f324ee12780b89\System.Configuration.Install.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 192000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\89adf5c48e4551ba19f324ee12780b89\System.Configuration.Install.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 132096 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ComponentMod#\1bcd63abfac2072c18ab799a37dd89cf\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 132096 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ComponentMod#\1bcd63abfac2072c18ab799a37dd89cf\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 889344 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn\268f6f10ba5e94d24677a1a68f97ac15\System.AddIn.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 889344 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn\268f6f10ba5e94d24677a1a68f97ac15\System.AddIn.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 156672 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn.Contra#\fc738e6c257a4851a220b9660688c25f\System.AddIn.Contract.ni.dll
- 2011-08-10 20:21 . 2011-08-10 20:21 156672 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn.Contra#\fc738e6c257a4851a220b9660688c25f\System.AddIn.Contract.ni.dll
- 2011-08-10 20:22 . 2011-08-10 20:22 297984 c:\windows\assembly\NativeImages_v2.0.50727_64\sysglobl\7706a4ac4bf3f09a2d0b655e363fa401\sysglobl.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 297984 c:\windows\assembly\NativeImages_v2.0.50727_64\sysglobl\7706a4ac4bf3f09a2d0b655e363fa401\sysglobl.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 525824 c:\windows\assembly\NativeImages_v2.0.50727_64\SMSvcHost\8103d9a6fe544e521f89b92d24ac298a\SMSvcHost.ni.exe
+ 2011-08-27 23:49 . 2011-08-27 23:49 525824 c:\windows\assembly\NativeImages_v2.0.50727_64\SMSvcHost\8103d9a6fe544e521f89b92d24ac298a\SMSvcHost.ni.exe
- 2011-08-11 19:43 . 2011-08-11 19:43 349184 c:\windows\assembly\NativeImages_v2.0.50727_64\SMDiagnostics\c268879bbddc814fadfe497300c03752\SMDiagnostics.ni.dll
+ 2011-08-27 23:29 . 2011-08-27 23:29 349184 c:\windows\assembly\NativeImages_v2.0.50727_64\SMDiagnostics\c268879bbddc814fadfe497300c03752\SMDiagnostics.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 376832 c:\windows\assembly\NativeImages_v2.0.50727_64\SecurityAuditPolici#\a1f13955ca1028875a75a96ca614f949\SecurityAuditPoliciesSnapIn.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 376832 c:\windows\assembly\NativeImages_v2.0.50727_64\SecurityAuditPolici#\a1f13955ca1028875a75a96ca614f949\SecurityAuditPoliciesSnapIn.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 317440 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\f89aa0bd7259a8fbe122539c26ccdd24\PresentationFramework.Royale.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 317440 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\f89aa0bd7259a8fbe122539c26ccdd24\PresentationFramework.Royale.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 620544 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\ed1fe56e5b41607f2b31091a11662f12\PresentationFramework.Luna.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 620544 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\ed1fe56e5b41607f2b31091a11662f12\PresentationFramework.Luna.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 463360 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\e197484e00ac02ef81220d0c8b6491e1\PresentationFramework.Aero.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 463360 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\e197484e00ac02ef81220d0c8b6491e1\PresentationFramework.Aero.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 282624 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\0c098556b5184fe66c987547b512f00a\PresentationFramework.Classic.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 282624 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\0c098556b5184fe66c987547b512f00a\PresentationFramework.Classic.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 855040 c:\windows\assembly\NativeImages_v2.0.50727_64\napsnap\a04a8437f757b8da7a707e31702169d6\napsnap.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 855040 c:\windows\assembly\NativeImages_v2.0.50727_64\napsnap\a04a8437f757b8da7a707e31702169d6\napsnap.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 162816 c:\windows\assembly\NativeImages_v2.0.50727_64\napinit\711d1c8357619b22e5caffd9cab59736\napinit.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 162816 c:\windows\assembly\NativeImages_v2.0.50727_64\napinit\711d1c8357619b22e5caffd9cab59736\napinit.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 175104 c:\windows\assembly\NativeImages_v2.0.50727_64\naphlpr\644fd981e996dd2ba072cc6265a0b74b\naphlpr.ni.dll
- 2011-08-10 20:21 . 2011-08-10 20:21 175104 c:\windows\assembly\NativeImages_v2.0.50727_64\naphlpr\644fd981e996dd2ba072cc6265a0b74b\naphlpr.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 127488 c:\windows\assembly\NativeImages_v2.0.50727_64\napcrypt\fe39885123be43ee8b6f4c1ca669d49b\napcrypt.ni.dll
- 2011-08-10 20:21 . 2011-08-10 20:21 127488 c:\windows\assembly\NativeImages_v2.0.50727_64\napcrypt\fe39885123be43ee8b6f4c1ca669d49b\napcrypt.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 184320 c:\windows\assembly\NativeImages_v2.0.50727_64\MSBuild\b75df85509061d9729506b8af64513f7\MSBuild.ni.exe
+ 2011-08-27 23:48 . 2011-08-27 23:48 184320 c:\windows\assembly\NativeImages_v2.0.50727_64\MSBuild\b75df85509061d9729506b8af64513f7\MSBuild.ni.exe
+ 2011-08-27 23:31 . 2011-08-27 23:31 417792 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCFxCommon\c42d34f67692030a55a9bc64004e9041\MMCFxCommon.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 417792 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCFxCommon\c42d34f67692030a55a9bc64004e9041\MMCFxCommon.ni.dll
+ 2011-08-27 23:48 . 2011-08-27 23:48 681984 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Man#\5db5412b8b9fdbe83b43a79b76cb39c6\Microsoft.WSMan.Management.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 681984 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Man#\5db5412b8b9fdbe83b43a79b76cb39c6\Microsoft.WSMan.Management.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 122368 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\de2193a90cfc32eed4ad1c78a99b8363\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 122368 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\de2193a90cfc32eed4ad1c78a99b8363\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 105984 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Vsa\0836bcb90046e51c8bd055c0755bd57d\Microsoft.Vsa.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 105984 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Vsa\0836bcb90046e51c8bd055c0755bd57d\Microsoft.Vsa.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 277504 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\ea3e8ec6fdc66f937bb865e8347f0609\Microsoft.VisualStudio.Tools.Office.Excel.HostAdapter.v10.0.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 226816 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\d85ce31b31976d3b28963e20cb241daa\Microsoft.VisualStudio.Tools.Office.HostAdapter.v10.0.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 390656 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\d056d0cb42bbccc1021e51868972bbcc\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 390656 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\d056d0cb42bbccc1021e51868972bbcc\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 499200 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\c65916749cde39fbe973df6d7d276932\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 499200 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\c65916749cde39fbe973df6d7d276932\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.ni.dll
- 2011-08-10 20:16 . 2011-08-10 20:16 209920 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\c14218583ce38161507507b8cf727c7e\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 209920 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\c14218583ce38161507507b8cf727c7e\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 777728 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\c13be527cd76c3425be317056d9fa356\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 777728 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\c13be527cd76c3425be317056d9fa356\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 225280 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\a73a3884385c5c6e0de5f47cfad387b9\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 225280 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\a73a3884385c5c6e0de5f47cfad387b9\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 202752 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\9139f5736be52a098a86121a23bdf60a\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 202752 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\9139f5736be52a098a86121a23bdf60a\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 494592 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\8a54ca40b958fe8dd5be510fccd05a71\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 494592 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\8a54ca40b958fe8dd5be510fccd05a71\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 232448 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\731d5c8c894ceddd78db1605958dea1f\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 232448 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\731d5c8c894ceddd78db1605958dea1f\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 312320 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\6b21945e268902b3abab6b8c1be373a9\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 446464 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\679336a10a3630cc6ac56b5c01f1fe9c\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 446464 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\679336a10a3630cc6ac56b5c01f1fe9c\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 125440 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\48f288f06847fbf8a88e304273fce34f\Microsoft.VisualStudio.Tools.Office.Outlook.HostAdapter.v10.0.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 305664 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\48862d9e40531be0552f7dc7f90e2c7d\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 305664 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\48862d9e40531be0552f7dc7f90e2c7d\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 970240 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\3ca45519cf4f0fb31199f11ccf775be8\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 970240 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\3ca45519cf4f0fb31199f11ccf775be8\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 226816 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\017253ab1cff2e08a521ee4724a81717\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 226816 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\017253ab1cff2e08a521ee4724a81717\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 584192 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\b3361f5be5cde787e5e6c67b1bf55684\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-08-27 23:41 . 2011-08-27 23:41 584192 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\b3361f5be5cde787e5e6c67b1bf55684\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 235008 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\d9690cae12595eadba0605f021f48d5f\Microsoft.Security.ApplicationId.PolicyManagement.PolicyModel.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 235008 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\d9690cae12595eadba0605f021f48d5f\Microsoft.Security.ApplicationId.PolicyManagement.PolicyModel.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 937472 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\2f74ed7bc1850b7db2e4d2a804a6df52\Microsoft.Security.ApplicationId.Wizards.AutomaticRuleGenerationWizard.ni.dll
+ 2011-08-27 23:41 . 2011-08-27 23:41 937472 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\2f74ed7bc1850b7db2e4d2a804a6df52\Microsoft.Security.ApplicationId.Wizards.AutomaticRuleGenerationWizard.ni.dll
+ 2011-08-27 23:41 . 2011-08-27 23:41 318976 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\283fa4c05c71071fd97d028a0ee48ec6\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 318976 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\283fa4c05c71071fd97d028a0ee48ec6\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 275456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\2330fedf74b1566e7607445d0664745a\Microsoft.Security.ApplicationId.PolicyManagement.PolicyManager.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 275456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\2330fedf74b1566e7607445d0664745a\Microsoft.Security.ApplicationId.PolicyManagement.PolicyManager.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 237056 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\d99d7734ec2e39696ac5ce7e7b2d76bd\Microsoft.PowerShell.Security.ni.dll
+ 2011-08-27 23:41 . 2011-08-27 23:41 237056 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\d99d7734ec2e39696ac5ce7e7b2d76bd\Microsoft.PowerShell.Security.ni.dll
+ 2011-08-27 23:41 . 2011-08-27 23:41 999936 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\77160cddd8417526c586e13b529f68bf\Microsoft.PowerShell.GraphicalHost.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 999936 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\77160cddd8417526c586e13b529f68bf\Microsoft.PowerShell.GraphicalHost.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 416768 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\6a1869785554446d202d6f718d036a3e\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
+ 2011-08-27 23:33 . 2011-08-27 23:33 416768 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\6a1869785554446d202d6f718d036a3e\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 713216 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\5c7ffe4abea4b5a400f768cad060835d\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2011-08-27 23:33 . 2011-08-27 23:33 713216 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\5c7ffe4abea4b5a400f768cad060835d\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 253952 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\c4b939d55984f85d37fc5e8cc5790621\Microsoft.Office.Tools.v9.0.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 253952 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\c4b939d55984f85d37fc5e8cc5790621\Microsoft.Office.Tools.v9.0.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 244224 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\add064508f156447e77e2fb5b0f2e89f\Microsoft.Office.Tools.Outlook.v9.0.ni.dll
+ 2011-08-27 23:33 . 2011-08-27 23:33 244224 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\add064508f156447e77e2fb5b0f2e89f\Microsoft.Office.Tools.Outlook.v9.0.ni.dll
- 2011-08-10 20:19 . 2011-08-10 20:19 315392 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\a219719bfd4361d5c928afd9c77e475e\Microsoft.Office.InfoPath.Client.Internal.Host.Interop.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 315392 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\a219719bfd4361d5c928afd9c77e475e\Microsoft.Office.InfoPath.Client.Internal.Host.Interop.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 169472 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\0efdd2dd777badf013c9949cc5544284\Microsoft.Office.InfoPath.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 169472 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\0efdd2dd777badf013c9949cc5544284\Microsoft.Office.InfoPath.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 380416 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.Bu#\d9c887941d5406d5748aa0627d336a91\Microsoft.Office.BusinessApplications.Diagnostics.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 380416 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.Bu#\d9c887941d5406d5748aa0627d336a91\Microsoft.Office.BusinessApplications.Diagnostics.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 164864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\f0cb734b7acfb102c57ed39f8918ce3d\Microsoft.MediaCenter.Mheg.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 164864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\f0cb734b7acfb102c57ed39f8918ce3d\Microsoft.MediaCenter.Mheg.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 522240 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\e4313e989939114d32f9254a74eee676\Microsoft.MediaCenter.Interop.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 522240 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\e4313e989939114d32f9254a74eee676\Microsoft.MediaCenter.Interop.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 370176 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\87d3f8fed35fa164d0e5dabbcee46df8\Microsoft.MediaCenter.Playback.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 370176 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\87d3f8fed35fa164d0e5dabbcee46df8\Microsoft.MediaCenter.Playback.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 312320 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\5ec49bda571c34526ad7db5ec7a201c4\Microsoft.MediaCenter.iTv.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 312320 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\5ec49bda571c34526ad7db5ec7a201c4\Microsoft.MediaCenter.iTv.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 965632 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\3ea7a7a15d59a1185b74f340f05c0b33\Microsoft.MediaCenter.Sports.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 965632 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\3ea7a7a15d59a1185b74f340f05c0b33\Microsoft.MediaCenter.Sports.ni.dll
- 2011-08-10 20:18 . 2011-08-10 20:18 152576 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\1cbb6b9711bed2da17ae866cf2f58c31\Microsoft.MediaCenter.ITVVM.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 152576 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\1cbb6b9711bed2da17ae866cf2f58c31\Microsoft.MediaCenter.ITVVM.ni.dll
- 2011-08-10 20:18 . 2011-08-10 20:18 219648 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\04b81e74cc96402e59800be2c13358f9\Microsoft.MediaCenter.iTv.Media.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 219648 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\04b81e74cc96402e59800be2c13358f9\Microsoft.MediaCenter.iTv.Media.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 798720 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Managemen#\503235feed6b59fff53b29c9def81a5d\Microsoft.ManagementConsole.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 798720 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Managemen#\503235feed6b59fff53b29c9def81a5d\Microsoft.ManagementConsole.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 399360 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.GroupPoli#\8957ee8531a07a14713becab927220c6\Microsoft.GroupPolicy.Interop.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 399360 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.GroupPoli#\8957ee8531a07a14713becab927220c6\Microsoft.GroupPolicy.Interop.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 618496 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.GroupPoli#\1d50fe27db4c4144efe6d2d445b1c121\Microsoft.GroupPolicy.AdmTmplEditor.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 618496 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.GroupPoli#\1d50fe27db4c4144efe6d2d445b1c121\Microsoft.GroupPolicy.AdmTmplEditor.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 674304 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.BusinessD#\a6619260f978d02a8422386f916d625c\Microsoft.BusinessData.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 674304 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.BusinessD#\a6619260f978d02a8422386f916d625c\Microsoft.BusinessData.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 198656 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\6c999c27e6724dd1d0a10202f3e52e57\Microsoft.Build.Utilities.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 198656 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\6c999c27e6724dd1d0a10202f3e52e57\Microsoft.Build.Utilities.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 244736 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\137428fc7e8ae3a1b733ffc45a3f3076\Microsoft.Build.Utilities.v3.5.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 244736 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\137428fc7e8ae3a1b733ffc45a3f3076\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 142336 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\748b8b1f294666450436cc174c0b0684\Microsoft.Build.Framework.ni.dll
- 2011-08-10 20:19 . 2011-08-10 20:19 142336 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\748b8b1f294666450436cc174c0b0684\Microsoft.Build.Framework.ni.dll
- 2011-08-10 20:19 . 2011-08-10 20:19 121344 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\4196ba1264bd52f324e01016716cbbe9\Microsoft.Build.Framework.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 121344 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\4196ba1264bd52f324e01016716cbbe9\Microsoft.Build.Framework.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 294912 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Con#\8be3ef8d90c0f3e97437887dac5a8d78\Microsoft.Build.Conversion.v3.5.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 294912 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Con#\8be3ef8d90c0f3e97437887dac5a8d78\Microsoft.Build.Conversion.v3.5.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 423424 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Applicati#\3f6fda39fc730d02ffcc315ba0c2b9c0\Microsoft.ApplicationId.Framework.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 423424 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Applicati#\3f6fda39fc730d02ffcc315ba0c2b9c0\Microsoft.ApplicationId.Framework.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 727040 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Applicati#\11fdc05858c96e128780105a572921e5\Microsoft.ApplicationId.RuleWizard.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 727040 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Applicati#\11fdc05858c96e128780105a572921e5\Microsoft.ApplicationId.RuleWizard.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 107520 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft-Windows-H#\736323a581cc019ae2027f71dc496668\Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop.ni.dll
- 2011-08-10 20:19 . 2011-08-10 20:19 107520 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft-Windows-H#\736323a581cc019ae2027f71dc496668\Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 380928 c:\windows\assembly\NativeImages_v2.0.50727_64\Mcx2Dvcs\39e1e694a468028f2ca73994f76322d4\Mcx2Dvcs.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 380928 c:\windows\assembly\NativeImages_v2.0.50727_64\Mcx2Dvcs\39e1e694a468028f2ca73994f76322d4\Mcx2Dvcs.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 547328 c:\windows\assembly\NativeImages_v2.0.50727_64\mcupdate\d820c1a490dfb31933fd53f96514bbce\mcupdate.ni.exe
- 2011-08-11 19:44 . 2011-08-11 19:44 547328 c:\windows\assembly\NativeImages_v2.0.50727_64\mcupdate\d820c1a490dfb31933fd53f96514bbce\mcupdate.ni.exe
+ 2011-08-27 23:30 . 2011-08-27 23:30 533504 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstoredb\428aa9c2151b0f385227c513c9497673\mcstoredb.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 533504 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstoredb\428aa9c2151b0f385227c513c9497673\mcstoredb.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 549376 c:\windows\assembly\NativeImages_v2.0.50727_64\mcplayerinterop\614f7b9e9c362ac6d4175638ea2237d9\mcplayerinterop.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 549376 c:\windows\assembly\NativeImages_v2.0.50727_64\mcplayerinterop\614f7b9e9c362ac6d4175638ea2237d9\mcplayerinterop.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 696320 c:\windows\assembly\NativeImages_v2.0.50727_64\mcGlidHostObj\7f8a262f2b6807a47517c1ea6e6b2a7b\mcGlidHostObj.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 696320 c:\windows\assembly\NativeImages_v2.0.50727_64\mcGlidHostObj\7f8a262f2b6807a47517c1ea6e6b2a7b\mcGlidHostObj.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 156672 c:\windows\assembly\NativeImages_v2.0.50727_64\MCESidebarCtrl\0801a977b58776ed017238d4aaa7995e\MCESidebarCtrl.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 156672 c:\windows\assembly\NativeImages_v2.0.50727_64\MCESidebarCtrl\0801a977b58776ed017238d4aaa7995e\MCESidebarCtrl.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 659456 c:\windows\assembly\NativeImages_v2.0.50727_64\EventViewer\136009b4f22e65e77a916747429e599b\EventViewer.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 659456 c:\windows\assembly\NativeImages_v2.0.50727_64\EventViewer\136009b4f22e65e77a916747429e599b\EventViewer.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 969216 c:\windows\assembly\NativeImages_v2.0.50727_64\ehRecObj\d313ec20c40b0fd3125b8e710f74556d\ehRecObj.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 969216 c:\windows\assembly\NativeImages_v2.0.50727_64\ehRecObj\d313ec20c40b0fd3125b8e710f74556d\ehRecObj.ni.dll
- 2011-08-10 20:18 . 2011-08-10 20:18 661504 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiWUapi\fb85aad5c54840d8c5a17ac30a2fdfd7\ehiWUapi.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 661504 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiWUapi\fb85aad5c54840d8c5a17ac30a2fdfd7\ehiWUapi.ni.dll
- 2011-08-10 20:18 . 2011-08-10 20:18 933888 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiwmp\af6c550e9382dba858ca65bb220799ea\ehiwmp.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 933888 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiwmp\af6c550e9382dba858ca65bb220799ea\ehiwmp.ni.dll
- 2011-08-10 20:18 . 2011-08-10 20:18 145408 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUserXp\244edb2f64f825975b8c70f34162e6a6\ehiUserXp.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 145408 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUserXp\244edb2f64f825975b8c70f34162e6a6\ehiUserXp.ni.dll
- 2011-08-10 20:18 . 2011-08-10 20:18 196096 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiiTv\b37be197d70d359e864bfffcca28fdb9\ehiiTv.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 196096 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiiTv\b37be197d70d359e864bfffcca28fdb9\ehiiTv.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 397824 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiExtens\b538d9ee6bfc71d120550427ccbe9e9e\ehiExtens.ni.dll
- 2011-08-10 20:18 . 2011-08-10 20:18 397824 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiExtens\b538d9ee6bfc71d120550427ccbe9e9e\ehiExtens.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 110080 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiBmlDataCarousel\ce8305e1973d5a65569d9757f5b59c29\ehiBmlDataCarousel.ni.dll
- 2011-08-10 20:18 . 2011-08-10 20:18 110080 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiBmlDataCarousel\ce8305e1973d5a65569d9757f5b59c29\ehiBmlDataCarousel.ni.dll
- 2011-08-10 20:18 . 2011-08-10 20:18 126976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiActivScp\440bebddd70e03b2548635373ad2b666\ehiActivScp.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 126976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiActivScp\440bebddd70e03b2548635373ad2b666\ehiActivScp.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 389120 c:\windows\assembly\NativeImages_v2.0.50727_64\ehExtHost\a267870c9fce983dca1c454fbde4cc7e\ehExtHost.ni.exe
+ 2011-08-27 23:29 . 2011-08-27 23:29 389120 c:\windows\assembly\NativeImages_v2.0.50727_64\ehExtHost\a267870c9fce983dca1c454fbde4cc7e\ehExtHost.ni.exe
+ 2011-08-27 23:29 . 2011-08-27 23:29 313856 c:\windows\assembly\NativeImages_v2.0.50727_64\ehCIR\3a7ccf1084f8a546e8f7e7eecf33045c\ehCIR.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 313856 c:\windows\assembly\NativeImages_v2.0.50727_64\ehCIR\3a7ccf1084f8a546e8f7e7eecf33045c\ehCIR.ni.dll
- 2011-08-10 20:18 . 2011-08-10 20:18 348672 c:\windows\assembly\NativeImages_v2.0.50727_64\CustomMarshalers\436b0b38f271b905950f054c548a5722\CustomMarshalers.ni.dll
+ 2011-08-27 23:29 . 2011-08-27 23:29 348672 c:\windows\assembly\NativeImages_v2.0.50727_64\CustomMarshalers\436b0b38f271b905950f054c548a5722\CustomMarshalers.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 640000 c:\windows\assembly\NativeImages_v2.0.50727_64\ComSvcConfig\1af89517b158d3a94c051dfbc4ae9769\ComSvcConfig.ni.exe
- 2011-08-11 19:42 . 2011-08-11 19:42 640000 c:\windows\assembly\NativeImages_v2.0.50727_64\ComSvcConfig\1af89517b158d3a94c051dfbc4ae9769\ComSvcConfig.ni.exe
- 2011-08-11 19:42 . 2011-08-11 19:42 971264 c:\windows\assembly\NativeImages_v2.0.50727_64\BDATunePIA\61dd29a580f09716118ef51868ad9edd\BDATunePIA.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 971264 c:\windows\assembly\NativeImages_v2.0.50727_64\BDATunePIA\61dd29a580f09716118ef51868ad9edd\BDATunePIA.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 321024 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\41ccc24e8cc5f2474ce1105f0b8ebb78\WsatConfig.ni.exe
- 2011-08-11 19:42 . 2011-08-11 19:42 321024 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\41ccc24e8cc5f2474ce1105f0b8ebb78\WsatConfig.ni.exe
- 2011-08-11 19:40 . 2011-08-11 19:40 634368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\3d5351ce86e095303fba275133137193\WindowsLiveLocal.WriterPlugin.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 634368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\3d5351ce86e095303fba275133137193\WindowsLiveLocal.WriterPlugin.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 146432 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\fde572524923af2430d9525392a8bbea\WindowsLive.Writer.Instrumentation.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 146432 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\fde572524923af2430d9525392a8bbea\WindowsLive.Writer.Instrumentation.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 891392 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\e61916c2a95a661b4f283880056c3042\WindowsLive.Writer.HtmlEditor.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 891392 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\e61916c2a95a661b4f283880056c3042\WindowsLive.Writer.HtmlEditor.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 101376 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\e58c1973b837702923fc07d2a5e27707\WindowsLive.Writer.Api.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 101376 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\e58c1973b837702923fc07d2a5e27707\WindowsLive.Writer.Api.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\d7ea7bdb6dd006399d7b74471a9b2f6f\WindowsLive.Writer.Mshtml.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\d7ea7bdb6dd006399d7b74471a9b2f6f\WindowsLive.Writer.Mshtml.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 871424 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\afed845d8b8baca6804ac35b162872bd\WindowsLive.Writer.BlogClient.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 871424 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\afed845d8b8baca6804ac35b162872bd\WindowsLive.Writer.BlogClient.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\abc9bcdf52d164d4424395ac98c43f80\WindowsLive.Writer.FileDestinations.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\abc9bcdf52d164d4424395ac98c43f80\WindowsLive.Writer.FileDestinations.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 780800 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\9b7e17a219e407c817df48ee0e103324\WindowsLive.Writer.Controls.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 780800 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\9b7e17a219e407c817df48ee0e103324\WindowsLive.Writer.Controls.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 313856 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\9461d16c415bef24d73aa628181765ea\WindowsLive.Writer.Interop.SHDocVw.ni.dll
- 2011-08-10 20:32 . 2011-08-10 20:32 313856 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\9461d16c415bef24d73aa628181765ea\WindowsLive.Writer.Interop.SHDocVw.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 326144 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\8361b2421d717fc05f9de4dc31e27d30\WindowsLive.Writer.SpellChecker.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 326144 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\8361b2421d717fc05f9de4dc31e27d30\WindowsLive.Writer.SpellChecker.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 122368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\457b24f87e34b9d3d6e8cc53080ad041\WindowsLive.Writer.Extensibility.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 122368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\457b24f87e34b9d3d6e8cc53080ad041\WindowsLive.Writer.Extensibility.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 156672 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\3e7ecad8ced9f475964f30c8d52809f0\WindowsLive.Writer.HtmlParser.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 156672 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\3e7ecad8ced9f475964f30c8d52809f0\WindowsLive.Writer.HtmlParser.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 174080 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\12d8d77ff3c35b2aeb085fbb4b737dfd\WindowsLive.Writer.BrowserControl.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 174080 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\12d8d77ff3c35b2aeb085fbb4b737dfd\WindowsLive.Writer.BrowserControl.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 665600 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\0a3e6799a6081a5cf0d2167fea406056\WindowsLive.Writer.Interop.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 665600 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\0a3e6799a6081a5cf0d2167fea406056\WindowsLive.Writer.Interop.ni.dll
- 2011-08-10 20:32 . 2011-08-10 20:32 374272 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\0403af327e2ce5bab0bb0cf8464f7b60\WindowsLive.Writer.Interop.Mshtml.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 374272 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\0403af327e2ce5bab0bb0cf8464f7b60\WindowsLive.Writer.Interop.Mshtml.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\53fe01ef07d887e57a42138e67f7040c\WindowsLive.Client.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\53fe01ef07d887e57a42138e67f7040c\WindowsLive.Client.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\bb04320c07e3c71ac2d18cb382d97f41\WindowsFormsIntegration.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\bb04320c07e3c71ac2d18cb382d97f41\WindowsFormsIntegration.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 284160 c:\windows\assembly\NativeImages_v2.0.50727_32\VistaBridgeLibrary\2681dc7c69162a934818e1fee3502127\VistaBridgeLibrary.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 284160 c:\windows\assembly\NativeImages_v2.0.50727_32\VistaBridgeLibrary\2681dc7c69162a934818e1fee3502127\VistaBridgeLibrary.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 485888 c:\windows\assembly\NativeImages_v2.0.50727_32\VDialog\294f967a2f981dbf481d71088e7b6b2a\VDialog.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 485888 c:\windows\assembly\NativeImages_v2.0.50727_32\VDialog\294f967a2f981dbf481d71088e7b6b2a\VDialog.ni.dll
- 2011-08-10 20:33 . 2011-08-10 20:33 185344 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\8b3b6ed74cb3d94695b0eaf94a362d42\UIAutomationTypes.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 185344 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\8b3b6ed74cb3d94695b0eaf94a362d42\UIAutomationTypes.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 452096 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\d63e6fb41aa502bf6724043e6ac1367f\UIAutomationClient.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 452096 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\d63e6fb41aa502bf6724043e6ac1367f\UIAutomationClient.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 245248 c:\windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\1c1f731e8684204f56f37cc66b5bc60d\TaskScheduler.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 245248 c:\windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\1c1f731e8684204f56f37cc66b5bc60d\TaskScheduler.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 401408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\b096bd83a66a8d1dcd761747730cc64c\System.Xml.Linq.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 401408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\b096bd83a66a8d1dcd761747730cc64c\System.Xml.Linq.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\2622bc26ad7295b08252b3ccdedb46b2\System.Web.Routing.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\66126f1309396535f2ba93f752016902\System.Web.RegularExpressions.ni.dll
- 2011-08-11 19:07 . 2011-08-11 19:07 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\66126f1309396535f2ba93f752016902\System.Web.RegularExpressions.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 860160 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\6c551bf6f7716b0f527f4274fb04cc2e\System.Web.Extensions.Design.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 860160 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\6c551bf6f7716b0f527f4274fb04cc2e\System.Web.Extensions.Design.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\03eda303152940cb2e78a0030cf572b5\System.Web.Entity.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\03eda303152940cb2e78a0030cf572b5\System.Web.Entity.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 301568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\7b93fe55a51f2a6010365a17546170bc\System.Web.Entity.Design.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 301568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\7b93fe55a51f2a6010365a17546170bc\System.Web.Entity.Design.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\da66258812fce6e3d1613fbc435b4f03\System.Web.DynamicData.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\5cedfb8c4ef047d871467ee661bb36da\System.Web.Abstractions.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\4e03de263f1fec29c4a7fa18986d0868\System.Transactions.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\4e03de263f1fec29c4a7fa18986d0868\System.Transactions.ni.dll
- 2011-08-11 19:07 . 2011-08-11 19:07 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\86a2ec5efbcfcd1105475364d7975b15\System.ServiceProcess.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\86a2ec5efbcfcd1105475364d7975b15\System.ServiceProcess.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 680448 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\c0d90fae726bca4f272ac9a2906b3741\System.Security.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 680448 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\c0d90fae726bca4f272ac9a2906b3741\System.Security.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 310784 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\e47bab16c150f9697594d8fd65532578\System.Runtime.Serialization.Formatters.Soap.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 310784 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\e47bab16c150f9697594d8fd65532578\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\e3e3b399b69c569ab1ed3b0ace2c8c20\System.Runtime.Remoting.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\e3e3b399b69c569ab1ed3b0ace2c8c20\System.Runtime.Remoting.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 624128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\e16f381a978103ac92bf64b99716c857\System.Net.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 624128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\e16f381a978103ac92bf64b99716c857\System.Net.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\ac9fe083b4cf11aab834d6654cdeb429\System.Messaging.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\ac9fe083b4cf11aab834d6654cdeb429\System.Messaging.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 330240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\b95b509ac74958a1d8568293c3dc43ba\System.Management.Instrumentation.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 330240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\b95b509ac74958a1d8568293c3dc43ba\System.Management.Instrumentation.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\e083fdbcc88f5850290f2cf65ae1efae\System.IO.Log.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\e083fdbcc88f5850290f2cf65ae1efae\System.IO.Log.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\736226563a7f564e4629e34d52b3d6c6\System.IdentityModel.Selectors.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\736226563a7f564e4629e34d52b3d6c6\System.IdentityModel.Selectors.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\3a17291e4caa1a23f652129fc88e3dda\System.EnterpriseServices.Wrapper.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\3a17291e4caa1a23f652129fc88e3dda\System.EnterpriseServices.Wrapper.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 628224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\3a17291e4caa1a23f652129fc88e3dda\System.EnterpriseServices.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 628224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\3a17291e4caa1a23f652129fc88e3dda\System.EnterpriseServices.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\41d65038625368f089fc66b8a544f934\System.Drawing.Design.ni.dll
- 2011-08-11 19:07 . 2011-08-11 19:07 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\41d65038625368f089fc66b8a544f934\System.Drawing.Design.ni.dll
- 2011-08-11 19:07 . 2011-08-11 19:07 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\3c443dc0b8879bfe286a07f15060787f\System.DirectoryServices.Protocols.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\3c443dc0b8879bfe286a07f15060787f\System.DirectoryServices.Protocols.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 888320 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\1f6d55f401cfe7041f9fd3b4aebffa9b\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 888320 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\1f6d55f401cfe7041f9fd3b4aebffa9b\System.DirectoryServices.AccountManagement.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 462336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\0896f955eb175a4e0bfff73b94f57619\System.Data.Services.Design.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 462336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\0896f955eb175a4e0bfff73b94f57619\System.Data.Services.Design.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 763392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\8f130b77f8f47e23cd748679173bdf33\System.Data.Entity.Design.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 763392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\8f130b77f8f47e23cd748679173bdf33\System.Data.Entity.Design.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\ad3f6eae36ce486187311de6836b4904\System.Data.DataSetExtensions.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\ad3f6eae36ce486187311de6836b4904\System.Data.DataSetExtensions.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\36d0ed3f2a65b9d67933ed46dfcd2ccb\System.Configuration.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\36d0ed3f2a65b9d67933ed46dfcd2ccb\System.Configuration.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\81423a8207177ffcfac843f9d7b662d2\System.Configuration.Install.ni.dll
- 2011-08-11 19:07 . 2011-08-11 19:07 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\81423a8207177ffcfac843f9d7b662d2\System.Configuration.Install.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 633344 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\fc5edc97ac59d0d0d45bb9b623b9927b\System.AddIn.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 633344 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\fc5edc97ac59d0d0d45bb9b623b9927b\System.AddIn.ni.dll
- 2011-08-10 20:35 . 2011-08-10 20:35 232448 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\88f0efe11487b846342fdee227f3da52\sysglobl.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 232448 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\88f0efe11487b846342fdee227f3da52\sysglobl.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\4a33aa8911167af5fcba60f1b02ad45b\SMSvcHost.ni.exe
- 2011-08-11 19:41 . 2011-08-11 19:41 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\4a33aa8911167af5fcba60f1b02ad45b\SMSvcHost.ni.exe
+ 2011-08-27 22:50 . 2011-08-27 22:50 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\b907dd027bbe99c5035b1d6355f83998\SMDiagnostics.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\b907dd027bbe99c5035b1d6355f83998\SMDiagnostics.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 294912 c:\windows\assembly\NativeImages_v2.0.50727_32\SecurityAuditPolici#\8672e2155460b6fb8b1cf09095d149d9\SecurityAuditPoliciesSnapIn.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 294912 c:\windows\assembly\NativeImages_v2.0.50727_32\SecurityAuditPolici#\8672e2155460b6fb8b1cf09095d149d9\SecurityAuditPoliciesSnapIn.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd\0cd03ac0d4f56a3cab885e708c97b246\Sd.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd\0cd03ac0d4f56a3cab885e708c97b246\Sd.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 459776 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Zip\866f8806467d45135e6923b4ec102f55\Sd.Zip.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 459776 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Zip\866f8806467d45135e6923b4ec102f55\Sd.Zip.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 524288 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Web\ec6bb35d116c53bc527ec5aaa33a51b8\Sd.Web.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 524288 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Web\ec6bb35d116c53bc527ec5aaa33a51b8\Sd.Web.ni.dll

+ 2011-08-27 22:51 . 2011-08-27 22:51 155648 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.UI\21944290fc02e4717e7cd891bd7426b1\Sd.UI.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 155648 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.UI\21944290fc02e4717e7cd891bd7426b1\Sd.UI.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 804352 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Irc\4379d1640d9661eba3664070bc457536\Sd.Irc.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 804352 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Irc\4379d1640d9661eba3664070bc457536\Sd.Irc.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 352768 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.InstallManager\1e4051fd1e09ca17559ec489ce2dce30\Sd.InstallManager.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 352768 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.InstallManager\1e4051fd1e09ca17559ec489ce2dce30\Sd.InstallManager.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 899584 c:\windows\assembly\NativeImages_v2.0.50727_32\sd.central.cvp.serv#\9db067a23ba08f9dfd2a1a5252864cc9\sd.central.cvp.server.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 899584 c:\windows\assembly\NativeImages_v2.0.50727_32\sd.central.cvp.serv#\9db067a23ba08f9dfd2a1a5252864cc9\sd.central.cvp.server.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 129024 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Central.Archive\a6674a7fd98def5553429522bf82a82b\Sd.Central.Archive.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 129024 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Central.Archive\a6674a7fd98def5553429522bf82a82b\Sd.Central.Archive.ni.dll
- 2011-08-10 20:33 . 2011-08-10 20:33 374272 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Central.Archive.#\e67036dad8afb041fc70d845daee9685\Sd.Central.Archive.XmlSerializers.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 374272 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Central.Archive.#\e67036dad8afb041fc70d845daee9685\Sd.Central.Archive.XmlSerializers.ni.dll
- 2011-08-11 19:07 . 2011-08-11 19:07 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\9997cb70ba2c05761f6196f65dae7588\PresentationFramework.Royale.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\9997cb70ba2c05761f6196f65dae7588\PresentationFramework.Royale.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7f94f6b13f92f1e093716d3e15bf86d1\PresentationFramework.Aero.ni.dll
- 2011-08-11 19:07 . 2011-08-11 19:07 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7f94f6b13f92f1e093716d3e15bf86d1\PresentationFramework.Aero.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\4c9a05d7eea9a270d51ffe6f9466d8f8\PresentationFramework.Luna.ni.dll
- 2011-08-11 19:07 . 2011-08-11 19:07 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\4c9a05d7eea9a270d51ffe6f9466d8f8\PresentationFramework.Luna.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 226816 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\16c2dcb95bda37843824b6b0d82d8ef6\PresentationFramework.Classic.ni.dll
- 2011-08-11 19:07 . 2011-08-11 19:07 226816 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\16c2dcb95bda37843824b6b0d82d8ef6\PresentationFramework.Classic.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 723456 c:\windows\assembly\NativeImages_v2.0.50727_32\napsnap\96f4e4b87e625a1c36e4de2efb6f7dcc\napsnap.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 723456 c:\windows\assembly\NativeImages_v2.0.50727_32\napsnap\96f4e4b87e625a1c36e4de2efb6f7dcc\napsnap.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 117760 c:\windows\assembly\NativeImages_v2.0.50727_32\napinit\a4e2648f8b4962f4c9660b2085290b06\napinit.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 117760 c:\windows\assembly\NativeImages_v2.0.50727_32\napinit\a4e2648f8b4962f4c9660b2085290b06\napinit.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 114176 c:\windows\assembly\NativeImages_v2.0.50727_32\naphlpr\8fcb3f856afb930c5add8498cadb4d13\naphlpr.ni.dll
- 2011-08-10 20:34 . 2011-08-10 20:34 114176 c:\windows\assembly\NativeImages_v2.0.50727_32\naphlpr\8fcb3f856afb930c5add8498cadb4d13\naphlpr.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 326144 c:\windows\assembly\NativeImages_v2.0.50727_32\MyDock.Util\08e05b6a79b48a32edd1f001ba96d020\MyDock.Util.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 326144 c:\windows\assembly\NativeImages_v2.0.50727_32\MyDock.Util\08e05b6a79b48a32edd1f001ba96d020\MyDock.Util.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\46d3794a4a440f22cff17197648f6887\MSBuild.ni.exe
- 2011-08-11 19:41 . 2011-08-11 19:41 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\46d3794a4a440f22cff17197648f6887\MSBuild.ni.exe
+ 2011-08-27 22:51 . 2011-08-27 22:51 287232 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon\71b549afed40761f8be9075ca9ad8dd7\MMCFxCommon.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 287232 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon\71b549afed40761f8be9075ca9ad8dd7\MMCFxCommon.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 531968 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Man#\fd457e872296300765fa1a6d96a6683c\Microsoft.WSMan.Management.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 531968 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Man#\fd457e872296300765fa1a6d96a6683c\Microsoft.WSMan.Management.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 290304 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WindowsAP#\2fe389f1df49f26f233b873994814432\Microsoft.WindowsAPICodePack.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 290304 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WindowsAP#\2fe389f1df49f26f233b873994814432\Microsoft.WindowsAPICodePack.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 337408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\d3507fe27d8923dd419bfd835581752d\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 337408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\d3507fe27d8923dd419bfd835581752d\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 285184 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\c35af2e781284aaa8950788a83537d49\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 285184 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\c35af2e781284aaa8950788a83537d49\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 184320 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\b808aeafab1d64b51e838788b01bb44a\Microsoft.VisualStudio.Tools.Office.Excel.HostAdapter.v10.0.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\b7d6360dcead019981eefacfa72416e6\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\b7d6360dcead019981eefacfa72416e6\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 365056 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\b42639fb347902bc5b1469968cd04d7b\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 365056 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\b42639fb347902bc5b1469968cd04d7b\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 621568 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\ae8fe0125b35fc268b9b2f9e3c1b3578\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 621568 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\ae8fe0125b35fc268b9b2f9e3c1b3578\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 663552 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\9c748be94847db6c1e5301a99ba507b4\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 663552 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\9c748be94847db6c1e5301a99ba507b4\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 161792 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\97c705b0f2bd8e91dbc8d7d9e33585e9\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 161792 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\97c705b0f2bd8e91dbc8d7d9e33585e9\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 303104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\9415b026c58ef2fc5927a383162e9e54\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 303104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\9415b026c58ef2fc5927a383162e9e54\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 215040 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\76ee89a9fc6963c5243918faf33baca8\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 215040 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\76ee89a9fc6963c5243918faf33baca8\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 161280 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\7341b232170813c91843c804216e6277\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 161280 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\7341b232170813c91843c804216e6277\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0.ni.dll
- 2011-08-10 20:31 . 2011-08-10 20:31 112128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\6b120f8db932a314de97c4cd216f8784\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 112128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\6b120f8db932a314de97c4cd216f8784\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 133120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\4a8e5945ad34fa301703ba1a919726ff\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 133120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\4a8e5945ad34fa301703ba1a919726ff\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 146432 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\357ee59bdfd1a6401467728163ebb4b6\Microsoft.VisualStudio.Tools.Office.HostAdapter.v10.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 191488 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\03b33221e1a3f2a2bd63a67aa4b8b16f\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\b96b80f166196dc0e148c73dc8452d25\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\b96b80f166196dc0e148c73dc8452d25\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 187392 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\fbb7d30f2de697e4f77a02a2aeaf70f4\Microsoft.Security.ApplicationId.PolicyManagement.PolicyManager.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 187392 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\fbb7d30f2de697e4f77a02a2aeaf70f4\Microsoft.Security.ApplicationId.PolicyManagement.PolicyManager.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\d5db2f08b957beaa1fe59ecd8c830c37\Microsoft.Security.ApplicationId.Wizards.AutomaticRuleGenerationWizard.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\d5db2f08b957beaa1fe59ecd8c830c37\Microsoft.Security.ApplicationId.Wizards.AutomaticRuleGenerationWizard.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 210944 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\bbf387226939a9d1b23f8c240cff9964\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 210944 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\bbf387226939a9d1b23f8c240cff9964\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 157184 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\5732689d52aa336fce2ae58b0d2cef27\Microsoft.Security.ApplicationId.PolicyManagement.PolicyModel.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 157184 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\5732689d52aa336fce2ae58b0d2cef27\Microsoft.Security.ApplicationId.PolicyManagement.PolicyModel.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 786432 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\f5b347719df9fa791416713aa0fd342f\Microsoft.PowerShell.Commands.Management.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 786432 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\f5b347719df9fa791416713aa0fd342f\Microsoft.PowerShell.Commands.Management.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 729088 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\bebf12cadd8b4fbd9c8135405c64794b\Microsoft.PowerShell.GraphicalHost.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 729088 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\bebf12cadd8b4fbd9c8135405c64794b\Microsoft.PowerShell.GraphicalHost.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 291328 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\b3b22c86860de1de178e294bc4bd534d\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 291328 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\b3b22c86860de1de178e294bc4bd534d\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 167424 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\512a72ebad1bd44687d8134cd46e1a5c\Microsoft.PowerShell.Security.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 167424 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\512a72ebad1bd44687d8134cd46e1a5c\Microsoft.PowerShell.Security.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 515584 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\1e510aa4de5a90cd44ee2443ae45e097\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 515584 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\1e510aa4de5a90cd44ee2443ae45e097\Microsoft.PowerShell.ConsoleHost.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 854528 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\fa189812ef4d7af56b10c1a506078b97\Microsoft.Office.Tools.Word.v9.0.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 854528 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\fa189812ef4d7af56b10c1a506078b97\Microsoft.Office.Tools.Word.v9.0.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 816128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\e8496d36126597a0a8428b40d0c71a4e\Microsoft.Office.Tools.Common.v9.0.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 816128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\e8496d36126597a0a8428b40d0c71a4e\Microsoft.Office.Tools.Common.v9.0.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 167424 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\a72fa4478a5e320f5aa90eefee398fe7\Microsoft.Office.Tools.Outlook.v9.0.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 167424 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\a72fa4478a5e320f5aa90eefee398fe7\Microsoft.Office.Tools.Outlook.v9.0.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 152064 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\58a8452f9bf9f47e742eeed9d951d4cd\Microsoft.Office.Tools.v9.0.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 152064 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\58a8452f9bf9f47e742eeed9d951d4cd\Microsoft.Office.Tools.v9.0.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 561664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen#\9658825555dc2c9af1a8ce12e6da2cd7\Microsoft.ManagementConsole.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 561664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen#\9658825555dc2c9af1a8ce12e6da2cd7\Microsoft.ManagementConsole.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 286208 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.GroupPoli#\ca4fc1503283c934c8000cd0ebe9b90a\Microsoft.GroupPolicy.Interop.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 286208 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.GroupPoli#\ca4fc1503283c934c8000cd0ebe9b90a\Microsoft.GroupPolicy.Interop.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 455168 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.GroupPoli#\02b2dc0d65a44379fa11870638cf894e\Microsoft.GroupPolicy.AdmTmplEditor.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 455168 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.GroupPoli#\02b2dc0d65a44379fa11870638cf894e\Microsoft.GroupPolicy.AdmTmplEditor.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\c52f2b0958be337e88f37a141e18be78\Microsoft.Build.Utilities.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\c52f2b0958be337e88f37a141e18be78\Microsoft.Build.Utilities.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\3f194ebe9a0c1e0903b32f663cb53556\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\3f194ebe9a0c1e0903b32f663cb53556\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\e62aa0d898b65d0d831c11b4f56c0785\Microsoft.Build.Engine.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\e62aa0d898b65d0d831c11b4f56c0785\Microsoft.Build.Engine.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\78fb000aaaba73f34dfa9028b7caef8c\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\78fb000aaaba73f34dfa9028b7caef8c\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 587776 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\d6cddb8db9dbcc8c9e38cb2d56d2122d\Microsoft.ApplicationId.RuleWizard.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 587776 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\d6cddb8db9dbcc8c9e38cb2d56d2122d\Microsoft.ApplicationId.RuleWizard.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 316928 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\7cf4b92ac03e856eb30772c80ffd31f3\Microsoft.ApplicationId.Framework.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 316928 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\7cf4b92ac03e856eb30772c80ffd31f3\Microsoft.ApplicationId.Framework.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 364032 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstoredb\fe969316614223634cba1c5544f4e3dd\mcstoredb.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 364032 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstoredb\fe969316614223634cba1c5544f4e3dd\mcstoredb.ni.dll
- 2011-08-10 20:33 . 2011-08-10 20:33 100864 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.IWshRuntime#\21b21a8788a7005281a4fce27318c0c3\Interop.IWshRuntimeLibrary.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 100864 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.IWshRuntime#\21b21a8788a7005281a4fce27318c0c3\Interop.IWshRuntimeLibrary.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 726016 c:\windows\assembly\NativeImages_v2.0.50727_32\ICSharpCode.SharpZi#\ee611592b4cc5cf7f74eef8921683cb7\ICSharpCode.SharpZipLib.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 726016 c:\windows\assembly\NativeImages_v2.0.50727_32\ICSharpCode.SharpZi#\ee611592b4cc5cf7f74eef8921683cb7\ICSharpCode.SharpZipLib.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 553472 c:\windows\assembly\NativeImages_v2.0.50727_32\EventViewer\31231127c783eddf25c3d21761e1a15c\EventViewer.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 553472 c:\windows\assembly\NativeImages_v2.0.50727_32\EventViewer\31231127c783eddf25c3d21761e1a15c\EventViewer.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 693248 c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\aceba77dc2230519296726c4a1ce9518\ehRecObj.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 693248 c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\aceba77dc2230519296726c4a1ce9518\ehRecObj.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 875520 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiVidCtl\85464949c28a523e3b6cf24679a9776c\ehiVidCtl.ni.dll
- 2011-08-10 20:34 . 2011-08-10 20:34 875520 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiVidCtl\85464949c28a523e3b6cf24679a9776c\ehiVidCtl.ni.dll
- 2011-08-10 20:33 . 2011-08-10 20:33 442880 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiProxy\2ddabd185f08f72237aaa70edaffa6cc\ehiProxy.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 442880 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiProxy\2ddabd185f08f72237aaa70edaffa6cc\ehiProxy.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 161280 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtens\536082f3ff1f0f6fcd7bd58878098071\ehiExtens.ni.dll
- 2011-08-10 20:34 . 2011-08-10 20:34 161280 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtens\536082f3ff1f0f6fcd7bd58878098071\ehiExtens.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 254464 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtHost32\42621a148e3691a5a992816cb49bee0a\ehExtHost32.ni.exe
- 2011-08-11 19:40 . 2011-08-11 19:40 254464 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtHost32\42621a148e3691a5a992816cb49bee0a\ehExtHost32.ni.exe
- 2011-08-10 20:32 . 2011-08-10 20:32 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\d17a5e7b3e9c6ea0f5c66093771b35eb\CustomMarshalers.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\d17a5e7b3e9c6ea0f5c66093771b35eb\CustomMarshalers.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\a28cd0923e6ff03f952950eb713f03b3\ComSvcConfig.ni.exe
+ 2011-08-27 22:50 . 2011-08-27 22:50 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\a28cd0923e6ff03f952950eb713f03b3\ComSvcConfig.ni.exe
- 2011-08-11 19:39 . 2011-08-11 19:39 621568 c:\windows\assembly\NativeImages_v2.0.50727_32\BDATunePIA\482f9bd79c20ab87b6fa0fa2737d6aa3\BDATunePIA.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 621568 c:\windows\assembly\NativeImages_v2.0.50727_32\BDATunePIA\482f9bd79c20ab87b6fa0fa2737d6aa3\BDATunePIA.ni.dll
+ 2009-07-18 03:21 . 2011-08-31 00:06 8530592 c:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
+ 2011-03-21 18:57 . 2011-03-21 18:57 5353360 c:\windows\Downloaded Program Files\CONFLICT.1\RACtrl.dll
+ 2011-03-21 18:48 . 2011-03-21 18:48 1311616 c:\windows\Downloaded Program Files\CONFLICT.1\LMIGuardianDll.dll
+ 2011-08-27 23:51 . 2011-08-27 23:51 5237248 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsBase\2b21f937d40320cabc3c85c031db88d8\WindowsBase.ni.dll
+ 2011-08-27 23:55 . 2011-08-27 23:55 1430016 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClients#\d14a6bf514550fdc219f580348599c58\UIAutomationClientsideProviders.ni.dll
+ 2011-08-27 23:51 . 2011-08-27 23:51 7037952 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml\8e4323f5bfb90be4621456033d8b404b\System.Xml.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 2449408 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xaml\2a3c95561c3de429c3c0e7a53a920c45\System.Xaml.ni.dll
+ 2011-08-27 23:55 . 2011-08-27 23:55 5627904 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\b346685f479e27aadce1793789333bfb\System.Windows.Forms.DataVisualization.ni.dll
+ 2011-08-27 23:55 . 2011-08-27 23:55 2236416 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services\4ee71342f3eadce770c5b227e0e72015\System.Web.Services.ni.dll
+ 2011-08-27 23:55 . 2011-08-27 23:55 2735616 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Speech\7211feffc35222c34e5d6b9e97f1c009\System.Speech.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 1918976 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\e449cb587c51f7bec5fcff8964844151\System.ServiceModel.Activities.ni.dll
+ 2011-08-27 23:55 . 2011-08-27 23:55 1579008 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\5af78d8b92c4a0b7f90dd99a8742c565\System.ServiceModel.Discovery.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 3412992 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\2c3f2f005761a596bf9e7262b76735a3\System.Runtime.Serialization.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 1348096 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Dura#\d850328fdb0d5b403f2b4a7752ec43da\System.Runtime.DurableInstancing.ni.dll
+ 2011-08-27 23:53 . 2011-08-27 23:53 1467392 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Printing\35bb0262c48890be46a1861b63bed32d\System.Printing.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 1470464 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Management\73c6deea16d8ee87e65156bb9ef90e0b\System.Management.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 1416192 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IdentityModel\6d8ec822ecf54529d04b1342aef58dd3\System.IdentityModel.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 1098752 c:\windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\a8ac353249c61750e03ace04cce91d12\System.EnterpriseServices.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 2290688 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\0237eaa2a9c71060227e6d310a887c07\System.Drawing.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 1217536 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\8440779374dcb4d650179a61139684b0\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 1622528 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\1b6321bae09adccce41aedcd91fcea9b\System.DirectoryServices.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 2402816 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Deployment\f0cadc34a72bbfb06158ee14e3f3b97d\System.Deployment.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 8601600 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data\20d5aeb1486af05bd5885e431e8cf531\System.Data.ni.dll
+ 2011-08-27 23:51 . 2011-08-27 23:51 3390976 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.SqlXml\84e0e94c07d03148371aad1c9212daba\System.Data.SqlXml.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 1798656 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\c66f4672f3f96cac1796475fc53084f7\System.Data.Services.Client.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 3386368 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Linq\f985d985539603a521e6051cbef283d7\System.Data.Linq.ni.dll
+ 2011-08-27 23:51 . 2011-08-27 23:51 1257472 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\d17a133036827281e02df99161f83199\System.Configuration.ni.dll
+ 2011-08-27 23:53 . 2011-08-27 23:53 1007616 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\87cacc996ae318f4bd1e126f8271b8c1\System.ComponentModel.Composition.ni.dll
+ 2011-08-27 23:53 . 2011-08-27 23:53 5695488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities\6f46271408743437680ef855e26ba561\System.Activities.ni.dll
+ 2011-08-27 23:53 . 2011-08-27 23:53 5048832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.P#\b5dc8079f2701e3cf6a139deca5c0982\System.Activities.Presentation.ni.dll
+ 2011-08-27 23:53 . 2011-08-27 23:53 2064896 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.C#\bb930355f9bcc3bc388397471ae88492\System.Activities.Core.Presentation.ni.dll
+ 2011-08-27 23:53 . 2011-08-27 23:53 4232704 c:\windows\assembly\NativeImages_v4.0.30319_64\ReachFramework\8df1ec785fb8923566f2ce612f108cee\ReachFramework.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 2056192 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationUI\944136b49e38259ce517a6fe3e71fa4d\PresentationUI.ni.dll
+ 2011-08-27 23:51 . 2011-08-27 23:51 2317312 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\f35f1a86bb6cdfc3547ff815dddfa629\Microsoft.VisualBasic.ni.dll
+ 2011-08-27 23:51 . 2011-08-27 23:51 1623040 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\b915c536f129912ec5b50a187d663103\Microsoft.VisualBasic.Activities.Compiler.ni.dll
+ 2011-08-27 23:51 . 2011-08-27 23:51 1843200 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\7caaf5543210b5383267ef450c2173f7\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2011-08-27 23:51 . 2011-08-27 23:51 1526784 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\41248e69f60429253a19267620bd5dcd\Microsoft.Transactions.Bridge.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 3313664 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.JScript\a266703ae4763423c8e41fd9e375bf76\Microsoft.JScript.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 2009600 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.CSharp\db2aa89dbd68dddefe47c70b35c045cf\Microsoft.CSharp.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 1063424 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClients#\e6474cae2445440fccb0e62e689e6c22\UIAutomationClientsideProviders.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 1782272 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\cadbfd56dbffb78f67b92027bd56862e\System.Xaml.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 4545024 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form#\a216205660fa7dabec6af4a7c52956ee\System.Windows.Forms.DataVisualization.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 1885696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\40c543317017c549c3d17d714c3cf1fc\System.Web.Services.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 2012160 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Speech\86d3010efe01e554be5b8cd680fcfe2a\System.Speech.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 1140736 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\f37365c0acb4b409a486f3aa4512a03e\System.ServiceModel.Discovery.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 1392640 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\a53b7bb4838c656363b29f79f708a0f0\System.ServiceModel.Activities.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 2647040 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\33b886ae33f78b046f90bda3dde2688e\System.Runtime.Serialization.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 1021952 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\5c659e2195f712d6638b8536da384cda\System.Runtime.DurableInstancing.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 1060864 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Printing\0751e44f42a603bfe153a4bbd124f62f\System.Printing.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 1218560 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management\307dea1fa71faaa1c2dc0175487d9639\System.Management.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 1072640 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\e1acefba94c07ca77d751b68bc3e33d3\System.IdentityModel.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 1172992 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\be3d47a08a8e4118e75e31a402259409\System.DirectoryServices.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 1879040 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Deployment\864c2fd53f879fcd5f9b335cf49a66b4\System.Deployment.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 1343488 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\04f451f2d493483696f852bdce8c36e0\System.Data.Services.Client.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 4129792 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities\c527fa8c447a9edfeb14eeaf4af0a742\System.Activities.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 3757568 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.P#\5be7a4e9c92dff127c74c0d744b3f523\System.Activities.Presentation.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 1547264 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.C#\1871f74f0a94ec1d26071dcc872d4189\System.Activities.Core.Presentation.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 2907136 c:\windows\assembly\NativeImages_v4.0.30319_32\ReachFramework\5d8782e167084ab1fced20b86cfb26e2\ReachFramework.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 1640448 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationUI\de59faecd59acbc6caabecbd8efbbb50\PresentationUI.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 1838080 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\ce05202cabbee87cda0b3df2e56a6b20\Microsoft.VisualBasic.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 1172480 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\899c60052ad7e741dc444017cc907ca8\Microsoft.VisualBasic.Activities.Compiler.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 1139200 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\0adf14e7c198b3e2a634e53a23ddad7b\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 1085952 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\4376863f8deba766befd5d8e41316a91\Microsoft.Transactions.Bridge.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 2452480 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.JScript\2ceaa7403e2bdea36367a0a67d972f03\Microsoft.JScript.ni.dll
+ 2011-08-27 23:33 . 2011-08-27 23:33 4962816 c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsBase\64fc9675d94bda9f45731097f140c4f6\WindowsBase.ni.dll
- 2011-08-11 19:04 . 2011-08-11 19:04 4962816 c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsBase\64fc9675d94bda9f45731097f140c4f6\WindowsBase.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 1459712 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClients#\b8bf364f0522a662055f670bf4e86c8f\UIAutomationClientsideProviders.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 1459712 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClients#\b8bf364f0522a662055f670bf4e86c8f\UIAutomationClientsideProviders.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 6948864 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml\318b11a6b944c9ef2998d374c9d5bda8\System.Xml.ni.dll
- 2011-08-11 19:03 . 2011-08-11 19:03 6948864 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml\318b11a6b944c9ef2998d374c9d5bda8\System.Xml.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 1818112 c:\windows\assembly\NativeImages_v2.0.50727_64\System.WorkflowServ#\394711b95ef17f6a7314eca2aba756e7\System.WorkflowServices.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 1818112 c:\windows\assembly\NativeImages_v2.0.50727_64\System.WorkflowServ#\394711b95ef17f6a7314eca2aba756e7\System.WorkflowServices.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 2711040 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Run#\eafeb90e353fd552565511cdeb26bebf\System.Workflow.Runtime.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 2711040 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Run#\eafeb90e353fd552565511cdeb26bebf\System.Workflow.Runtime.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 5957632 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Com#\ec790f92424cdcec713fff09d475bf2b\System.Workflow.ComponentModel.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 5957632 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Com#\ec790f92424cdcec713fff09d475bf2b\System.Workflow.ComponentModel.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 3895296 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Act#\906d5186dd5dbb570648cd1e3dfed22e\System.Workflow.Activities.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 3895296 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Act#\906d5186dd5dbb570648cd1e3dfed22e\System.Workflow.Activities.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 2292224 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Services\29bf4a2b9e4edd846f35872642dd0f36\System.Web.Services.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 2292224 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Services\29bf4a2b9e4edd846f35872642dd0f36\System.Web.Services.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 3336704 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Mobile\fe69339f03e5b94b558c688512246a5e\System.Web.Mobile.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 3336704 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Mobile\fe69339f03e5b94b558c688512246a5e\System.Web.Mobile.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 1155072 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\b513632337cadf6b2a8f8b6975c7d96f\System.Web.Extensions.Design.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 1155072 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\b513632337cadf6b2a8f8b6975c7d96f\System.Web.Extensions.Design.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 3042304 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\9c1f2e29f7b5f1d398405640ef4b1c7c\System.Web.Extensions.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 3042304 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\9c1f2e29f7b5f1d398405640ef4b1c7c\System.Web.Extensions.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 2727936 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Speech\31bbf607c61e3b9aeced14cb984ea9f6\System.Speech.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 2727936 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Speech\31bbf607c61e3b9aeced14cb984ea9f6\System.Speech.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 2312704 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel#\667a561422e2ccf10daef0a5dc6c8043\System.ServiceModel.Web.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 2312704 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel#\667a561422e2ccf10daef0a5dc6c8043\System.ServiceModel.Web.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 3073536 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\50faf7f472bfc6d562696341df45b3c9\System.Runtime.Serialization.ni.dll
+ 2011-08-27 23:29 . 2011-08-27 23:29 3073536 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\50faf7f472bfc6d562696341df45b3c9\System.Runtime.Serialization.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 1022976 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Remo#\caddda432d02308c325519a8e2f09dc4\System.Runtime.Remoting.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 1022976 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Remo#\caddda432d02308c325519a8e2f09dc4\System.Runtime.Remoting.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 1463808 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Printing\3bc065deeefef52f1ff59628ec665ea7\System.Printing.ni.dll
+ 2011-08-27 23:41 . 2011-08-27 23:41 1463808 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Printing\3bc065deeefef52f1ff59628ec665ea7\System.Printing.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 1472000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management\36723de72c78b2791de226253580f107\System.Management.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 1472000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management\36723de72c78b2791de226253580f107\System.Management.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 1444352 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityModel\df0cb96e6d087500c9210b33be2c91c9\System.IdentityModel.ni.dll
+ 2011-08-27 23:29 . 2011-08-27 23:29 1444352 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityModel\df0cb96e6d087500c9210b33be2c91c9\System.IdentityModel.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 1081344 c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\1f84610e9a8c80e23e82f82cc4a894a3\System.EnterpriseServices.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 1081344 c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\1f84610e9a8c80e23e82f82cc4a894a3\System.EnterpriseServices.ni.dll
- 2011-08-11 19:04 . 2011-08-11 19:04 2311168 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\ad884485b63f08acfaf791d2dfaadd32\System.Drawing.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 2311168 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\ad884485b63f08acfaf791d2dfaadd32\System.Drawing.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 1640448 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\8255d3cb1b25eaa6e645322daa1f680c\System.DirectoryServices.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 1640448 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\8255d3cb1b25eaa6e645322daa1f680c\System.DirectoryServices.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 1230848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\11a932eb07432edfc6f9de22753337ba\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 1230848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\11a932eb07432edfc6f9de22753337ba\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-08-27 23:28 . 2011-08-27 23:28 2444288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Deployment\e2a96543efb1769b60dc0ff9e292c4bb\System.Deployment.ni.dll
- 2011-08-11 19:04 . 2011-08-11 19:04 2444288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Deployment\e2a96543efb1769b60dc0ff9e292c4bb\System.Deployment.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 8681472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data\d71dfde5e15e6b4271c9ce4c514775b2\System.Data.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 8681472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data\d71dfde5e15e6b4271c9ce4c514775b2\System.Data.ni.dll
- 2011-08-11 19:03 . 2011-08-11 19:03 3463680 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.SqlXml\ab0d4419e1826292c56e565405151290\System.Data.SqlXml.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 3463680 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.SqlXml\ab0d4419e1826292c56e565405151290\System.Data.SqlXml.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 2805760 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Services\f7483e84119e0be9074377e731ffbe0c\System.Data.Services.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 2805760 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Services\f7483e84119e0be9074377e731ffbe0c\System.Data.Services.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 1868288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\16932309d9a552f362c85ac0adfe1607\System.Data.Services.Client.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 1868288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\16932309d9a552f362c85ac0adfe1607\System.Data.Services.Client.ni.dll
+ 2011-08-27 23:28 . 2011-08-27 23:28 1506816 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.OracleC#\33f6d511288b5a1aaa011e52ba3821fd\System.Data.OracleClient.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 1506816 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.OracleC#\33f6d511288b5a1aaa011e52ba3821fd\System.Data.OracleClient.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 3480576 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Linq\82b491f0b4a55a29d4de0e7648a43707\System.Data.Linq.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 3480576 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Linq\82b491f0b4a55a29d4de0e7648a43707\System.Data.Linq.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 1080320 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity.#\22600cdf0f670e44b03b243af68cd76d\System.Data.Entity.Design.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 1080320 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity.#\22600cdf0f670e44b03b243af68cd76d\System.Data.Entity.Design.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 3315200 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Core\5f7c48b31971fee1af48dd20c7dd7033\System.Core.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 3315200 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Core\5f7c48b31971fee1af48dd20c7dd7033\System.Core.ni.dll
- 2011-08-11 19:03 . 2011-08-11 19:03 1308160 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\df2bfb30ffdbfbb49d2c5ef6fc763578\System.Configuration.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 1308160 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\df2bfb30ffdbfbb49d2c5ef6fc763578\System.Configuration.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 1530368 c:\windows\assembly\NativeImages_v2.0.50727_64\SrpUxSnapIn\bed44cd7a336e0d8cf98e84b3d0fef60\SrpUxSnapIn.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 1530368 c:\windows\assembly\NativeImages_v2.0.50727_64\SrpUxSnapIn\bed44cd7a336e0d8cf98e84b3d0fef60\SrpUxSnapIn.ni.dll
+ 2011-08-27 23:41 . 2011-08-27 23:41 3116032 c:\windows\assembly\NativeImages_v2.0.50727_64\ReachFramework\b2c3d06da323643af4ab68768cfe8880\ReachFramework.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 3116032 c:\windows\assembly\NativeImages_v2.0.50727_64\ReachFramework\b2c3d06da323643af4ab68768cfe8880\ReachFramework.ni.dll
+ 2011-08-27 23:41 . 2011-08-27 23:41 2109952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationUI\0f3e15bd55e4f4171604e889eac1c819\PresentationUI.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 2109952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationUI\0f3e15bd55e4f4171604e889eac1c819\PresentationUI.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 1884160 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationBuildTa#\ff71ee8681938634786fac49359c8b15\PresentationBuildTasks.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 1884160 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationBuildTa#\ff71ee8681938634786fac49359c8b15\PresentationBuildTasks.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 3601920 c:\windows\assembly\NativeImages_v2.0.50727_64\Narrator\2f9ac667c184e068523d6047153f2d91\Narrator.ni.exe
+ 2011-08-27 23:49 . 2011-08-27 23:49 3601920 c:\windows\assembly\NativeImages_v2.0.50727_64\Narrator\2f9ac667c184e068523d6047153f2d91\Narrator.ni.exe
- 2011-08-11 19:45 . 2011-08-11 19:45 2327552 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCEx\92414dfe464e98f09057245b6dd04d05\MMCEx.ni.dll
+ 2011-08-27 23:48 . 2011-08-27 23:48 2327552 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCEx\92414dfe464e98f09057245b6dd04d05\MMCEx.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 7970304 c:\windows\assembly\NativeImages_v2.0.50727_64\MIGUIControls\c66470a9076fc188a35ec7643aa1ee2e\MIGUIControls.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 7970304 c:\windows\assembly\NativeImages_v2.0.50727_64\MIGUIControls\c66470a9076fc188a35ec7643aa1ee2e\MIGUIControls.ni.dll
+ 2011-08-27 23:42 . 2011-08-27 23:42 1877504 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\5f7d20769d7707bf07110afe96a3289a\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 1877504 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\5f7d20769d7707bf07110afe96a3289a\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.ni.dll
+ 2011-08-27 23:41 . 2011-08-27 23:41 2131968 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\4b85c3384fdda12490074283615d4723\Microsoft.VisualBasic.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 2131968 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\4b85c3384fdda12490074283615d4723\Microsoft.VisualBasic.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 1598976 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\deae3fdab784ca275290c02a3288a33d\Microsoft.Transactions.Bridge.ni.dll
+ 2011-08-27 23:29 . 2011-08-27 23:29 1598976 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\deae3fdab784ca275290c02a3288a33d\Microsoft.Transactions.Bridge.ni.dll
+ 2011-08-27 23:33 . 2011-08-27 23:33 2176512 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\f1cc6b5a2520e6b946198cd51498dff9\Microsoft.PowerShell.Commands.Utility.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 2176512 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\f1cc6b5a2520e6b946198cd51498dff9\Microsoft.PowerShell.Commands.Utility.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 5350912 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\b1d791e971f5c23b5ab0bf61bcfe60a0\Microsoft.PowerShell.Editor.ni.dll
+ 2011-08-27 23:33 . 2011-08-27 23:33 5350912 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\b1d791e971f5c23b5ab0bf61bcfe60a0\Microsoft.PowerShell.Editor.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 2105344 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\42c4e6bd35af9d592663de61cb8c8108\Microsoft.PowerShell.GPowerShell.ni.dll
+ 2011-08-27 23:41 . 2011-08-27 23:41 2105344 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\42c4e6bd35af9d592663de61cb8c8108\Microsoft.PowerShell.GPowerShell.ni.dll
+ 2011-08-27 23:33 . 2011-08-27 23:33 1131008 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\332067cce1149bb2008d5af79ef8024d\Microsoft.PowerShell.Commands.Management.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 1131008 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\332067cce1149bb2008d5af79ef8024d\Microsoft.PowerShell.Commands.Management.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 1093632 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\f1434fe248d4bb3a225b0018682daf52\Microsoft.Office.Tools.Common.v9.0.ni.dll
+ 2011-08-27 23:33 . 2011-08-27 23:33 1093632 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\f1434fe248d4bb3a225b0018682daf52\Microsoft.Office.Tools.Common.v9.0.ni.dll
+ 2011-08-27 23:33 . 2011-08-27 23:33 1875456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\c435f47c13f3cfa266e8c8166a37ea88\Microsoft.Office.Tools.Excel.v9.0.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 1875456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\c435f47c13f3cfa266e8c8166a37ea88\Microsoft.Office.Tools.Excel.v9.0.ni.dll
+ 2011-08-27 23:33 . 2011-08-27 23:33 1186304 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\60a97c1e323bc55b51a8d2ab139ac462\Microsoft.Office.Tools.Word.v9.0.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 1186304 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\60a97c1e323bc55b51a8d2ab139ac462\Microsoft.Office.Tools.Word.v9.0.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 2780672 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\8bbcf5309314e020d7bdf987cdfb7b23\Microsoft.Office.InfoPath.Client.Internal.Host.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 2780672 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\8bbcf5309314e020d7bdf987cdfb7b23\Microsoft.Office.InfoPath.Client.Internal.Host.ni.dll
+ 2011-08-27 23:33 . 2011-08-27 23:33 1793536 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\67bf648f6cf227923d38710e38cc739f\Microsoft.Office.Interop.InfoPath.SemiTrust.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 1793536 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\67bf648f6cf227923d38710e38cc739f\Microsoft.Office.Interop.InfoPath.SemiTrust.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 1217024 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\0a4b6d46d2c5fdcf38c38a5511d7f1e7\Microsoft.Office.Interop.InfoPath.ni.dll
- 2011-08-10 20:19 . 2011-08-10 20:19 1217024 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\0a4b6d46d2c5fdcf38c38a5511d7f1e7\Microsoft.Office.Interop.InfoPath.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 2180608 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.Bu#\b330b629527ff0ed03d1ec87baeba78f\Microsoft.Office.BusinessApplications.Runtime.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 2180608 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.Bu#\b330b629527ff0ed03d1ec87baeba78f\Microsoft.Office.BusinessApplications.Runtime.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 2956288 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.Bu#\99032481c4ed92478e7535ed2f49f3fe\Microsoft.Office.BusinessApplications.RuntimeUi.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 2956288 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.Bu#\99032481c4ed92478e7535ed2f49f3fe\Microsoft.Office.BusinessApplications.RuntimeUi.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 6552576 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.Bu#\6ef7df69ee7342823c805279d3ae1d08\Microsoft.Office.BusinessApplications.SyncServices.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 6552576 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.Bu#\6ef7df69ee7342823c805279d3ae1d08\Microsoft.Office.BusinessApplications.SyncServices.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 4426752 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.Bu#\19b749e8fffe3326180481a54937ec6a\Microsoft.Office.BusinessData.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 4426752 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.Bu#\19b749e8fffe3326180481a54937ec6a\Microsoft.Office.BusinessData.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 8979456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\fc417f7e196b7d7d5e717cb892f16144\Microsoft.MediaCenter.UI.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 8979456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\fc417f7e196b7d7d5e717cb892f16144\Microsoft.MediaCenter.UI.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 1170432 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\ce834b9729a66c3ef9ec5c4350e6ab59\Microsoft.MediaCenter.TV.Tuners.Interop.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 1170432 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\ce834b9729a66c3ef9ec5c4350e6ab59\Microsoft.MediaCenter.TV.Tuners.Interop.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 1516544 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\cc0f76a8214ddc88b56c6c14146c2555\Microsoft.MediaCenter.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 1516544 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\cc0f76a8214ddc88b56c6c14146c2555\Microsoft.MediaCenter.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 1142784 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\8f1d674c4309a0c29fb708ba7a5e54c4\Microsoft.MediaCenter.Shell.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 1142784 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\8f1d674c4309a0c29fb708ba7a5e54c4\Microsoft.MediaCenter.Shell.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 1508864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\52e7f067d8a3358baeb77ac8cd988c0e\Microsoft.MediaCenter.Bml.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 1508864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\52e7f067d8a3358baeb77ac8cd988c0e\Microsoft.MediaCenter.Bml.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 3213312 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.JScript\95184c861c38e940aeadc4276a8596e6\Microsoft.JScript.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 3213312 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.JScript\95184c861c38e940aeadc4276a8596e6\Microsoft.JScript.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 2365952 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Ink\0e8c24abc2dbbafc9519f64571a39433\Microsoft.Ink.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 2365952 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Ink\0e8c24abc2dbbafc9519f64571a39433\Microsoft.Ink.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 5054976 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.GroupPoli#\e10acf1afed34b2048e526c94537392c\Microsoft.GroupPolicy.Reporting.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 5054976 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.GroupPoli#\e10acf1afed34b2048e526c94537392c\Microsoft.GroupPolicy.Reporting.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 2218496 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\638f3afd3c310ed7d048e60cc1daf57e\Microsoft.Build.Tasks.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 2218496 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\638f3afd3c310ed7d048e60cc1daf57e\Microsoft.Build.Tasks.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 2682880 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\58e96fd5359c0f3d6ed8f350ff721f87\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2011-08-27 23:32 . 2011-08-27 23:32 2682880 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\58e96fd5359c0f3d6ed8f350ff721f87\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 1137152 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\f2ae54183322e3710c0344c44fd512d8\Microsoft.Build.Engine.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 1137152 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\f2ae54183322e3710c0344c44fd512d8\Microsoft.Build.Engine.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 2544640 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\37c906e0ea6325e55c1f222aa4a5462b\Microsoft.Build.Engine.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 2544640 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\37c906e0ea6325e55c1f222aa4a5462b\Microsoft.Build.Engine.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 2801664 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstore\c0018e4aaaa7eebb4fadaf5220854fe8\mcstore.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 2801664 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstore\c0018e4aaaa7eebb4fadaf5220854fe8\mcstore.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 4088320 c:\windows\assembly\NativeImages_v2.0.50727_64\mcepg\0d18e8a503ef9e5bc676d89c7d508d7f\mcepg.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 4088320 c:\windows\assembly\NativeImages_v2.0.50727_64\mcepg\0d18e8a503ef9e5bc676d89c7d508d7f\mcepg.ni.dll
- 2011-08-10 20:18 . 2011-08-10 20:18 2184192 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiVidCtl\864ef3de707640f5a889efc4425e5c40\ehiVidCtl.ni.dll
+ 2011-08-27 23:30 . 2011-08-27 23:30 2184192 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiVidCtl\864ef3de707640f5a889efc4425e5c40\ehiVidCtl.ni.dll
- 2011-08-10 20:18 . 2011-08-10 20:18 1201664 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiProxy\60b7bccb6de4c8d42f2eaf1d0e7a9216\ehiProxy.ni.dll
+ 2011-08-27 23:29 . 2011-08-27 23:29 1201664 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiProxy\60b7bccb6de4c8d42f2eaf1d0e7a9216\ehiProxy.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 2193408 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\d4afec0a5e4cfbfde58a3891ab59dec8\WindowsLive.Writer.CoreServices.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 2193408 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\d4afec0a5e4cfbfde58a3891ab59dec8\WindowsLive.Writer.CoreServices.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 1346560 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\96c75f3d7d7a0a53260332bf8654e232\WindowsLive.Writer.Localization.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 1346560 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\96c75f3d7d7a0a53260332bf8654e232\WindowsLive.Writer.Localization.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 7025152 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\8fcbc148c8a680ddc574f8ff3745b52d\WindowsLive.Writer.PostEditor.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 7025152 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\8fcbc148c8a680ddc574f8ff3745b52d\WindowsLive.Writer.PostEditor.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 1285632 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\7978d94f1ae7929f854e0c2595e3a3b8\WindowsLive.Writer.ApplicationFramework.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 1285632 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\7978d94f1ae7929f854e0c2595e3a3b8\WindowsLive.Writer.ApplicationFramework.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 3347968 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\6124dbbfd45927c4a6226d6e6bca6253\WindowsBase.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 3347968 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\6124dbbfd45927c4a6226d6e6bca6253\WindowsBase.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 1047552 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\92104881c09380b6b86ec656e8c502f6\UIAutomationClientsideProviders.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 1047552 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\92104881c09380b6b86ec656e8c502f6\UIAutomationClientsideProviders.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 7963648 c:\windows\assembly\NativeImages_v2.0.50727_32\System\3da7c6c1a0f26ae91883fd8b03ec192d\System.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 7963648 c:\windows\assembly\NativeImages_v2.0.50727_32\System\3da7c6c1a0f26ae91883fd8b03ec192d\System.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 5453312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\16d2854bf69d59d94e64a918365705f1\System.Xml.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 5453312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\16d2854bf69d59d94e64a918365705f1\System.Xml.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 1358336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\a6409b4be5018e5cbad7ef197d4237e1\System.WorkflowServices.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 1358336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\a6409b4be5018e5cbad7ef197d4237e1\System.WorkflowServices.ni.dll
- 2011-08-11 19:07 . 2011-08-11 19:07 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\9af55d8d4cb44eabe53e940244864daa\System.Workflow.Runtime.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\9af55d8d4cb44eabe53e940244864daa\System.Workflow.Runtime.ni.dll
- 2011-08-11 19:07 . 2011-08-11 19:07 4515840 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\f40e6a02c815ee66b49d4f48802d9d9c\System.Workflow.ComponentModel.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 4515840 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\f40e6a02c815ee66b49d4f48802d9d9c\System.Workflow.ComponentModel.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 2995200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\82e83c3d87d72cafffc60c55585daaaa\System.Workflow.Activities.ni.dll
- 2011-08-11 19:07 . 2011-08-11 19:07 2995200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\82e83c3d87d72cafffc60c55585daaaa\System.Workflow.Activities.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\ac875791282999d72dc87fa8b7441ae5\System.Web.Services.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 2209792 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\4de6ad3bad2dc4fbbbd33b16b1a7b219\System.Web.Mobile.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 2209792 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\4de6ad3bad2dc4fbbbd33b16b1a7b219\System.Web.Mobile.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 2403328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\ba966c30a7714bb3f5ba968e03053b80\System.Web.Extensions.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\2c7c32228442440e4c23f772fd64b24b\System.Speech.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\2c7c32228442440e4c23f772fd64b24b\System.Speech.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 1707008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\0139ae05cabaf2ac25cc85279e187e0a\System.ServiceModel.Web.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 1707008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\0139ae05cabaf2ac25cc85279e187e0a\System.ServiceModel.Web.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 2347008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\e285e2af5e0e8ac7d91936b2cb18542f\System.Runtime.Serialization.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 2347008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\e285e2af5e0e8ac7d91936b2cb18542f\System.Runtime.Serialization.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 1044480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\b2834d89c14922370db32e5e4564e03a\System.Printing.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 1044480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\b2834d89c14922370db32e5e4564e03a\System.Printing.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 1051136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\6e9a08576157b4aeb91a3aaa452fcb00\System.Management.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 1051136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\6e9a08576157b4aeb91a3aaa452fcb00\System.Management.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 8872960 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\f2b1857a7db371f0417a84e8ca25f450\System.Management.Automation.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 8872960 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\f2b1857a7db371f0417a84e8ca25f450\System.Management.Automation.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 1083392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\5ab23d203c8bfade7160ea915719c730\System.IdentityModel.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 1083392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\5ab23d203c8bfade7160ea915719c730\System.IdentityModel.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\9e87dd8fe5d0f925d80a6a6eaf74fdb9\System.Drawing.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\9e87dd8fe5d0f925d80a6a6eaf74fdb9\System.Drawing.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 1117184 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\ac4d095d0371999fa879f8167e9a82fa\System.DirectoryServices.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 1117184 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\ac4d095d0371999fa879f8167e9a82fa\System.DirectoryServices.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 1806848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\364993b444187c2dd988cab2fb0f98c6\System.Deployment.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 1806848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\364993b444187c2dd988cab2fb0f98c6\System.Deployment.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 6610944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\bcfecd5581d0636b1710d78aff95627a\System.Data.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 2508288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\6c9eef4471f39022ab9418637c7ee9e1\System.Data.SqlXml.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 2508288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\6c9eef4471f39022ab9418637c7ee9e1\System.Data.SqlXml.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 2029568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\702efea190a39de2bacb81cbaf32de99\System.Data.Services.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 2029568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\702efea190a39de2bacb81cbaf32de99\System.Data.Services.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 1378816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\3da17a7980d13fae329f2c3a77797b08\System.Data.Services.Client.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 1378816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\3da17a7980d13fae329f2c3a77797b08\System.Data.Services.Client.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\fb1d7702c4b7ff4327a79a4bd42fdcfa\System.Data.OracleClient.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 2516992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\1992ecfb8eb3318820e3d28df55bee6a\System.Data.Linq.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 2516992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\1992ecfb8eb3318820e3d28df55bee6a\System.Data.Linq.ni.dll
- 2011-08-11 19:42 . 2011-08-11 19:42 9921536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\301160f0d81368efb2f79e9b714ec505\System.Data.Entity.ni.dll
+ 2011-08-27 22:53 . 2011-08-27 22:53 9921536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\301160f0d81368efb2f79e9b714ec505\System.Data.Entity.ni.dll
- 2011-08-11 19:39 . 2011-08-11 19:39 2297856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\ebdaeeb5ef1a6209d67a2f70fcaf5cd5\System.Core.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 2297856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\ebdaeeb5ef1a6209d67a2f70fcaf5cd5\System.Core.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 1351168 c:\windows\assembly\NativeImages_v2.0.50727_32\SrpUxSnapIn\ae885d628f85ede263e593688ef1caaf\SrpUxSnapIn.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 1351168 c:\windows\assembly\NativeImages_v2.0.50727_32\SrpUxSnapIn\ae885d628f85ede263e593688ef1caaf\SrpUxSnapIn.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 1759744 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Common\95e7f8bb2555890f8c08e2dd6f58b5a2\Sd.Common.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 1759744 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Common\95e7f8bb2555890f8c08e2dd6f58b5a2\Sd.Common.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 1139712 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Common.XmlSerial#\c1b8166db4c305fc1c11c0b28a0c5d66\Sd.Common.XmlSerializers.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 1139712 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Common.XmlSerial#\c1b8166db4c305fc1c11c0b28a0c5d66\Sd.Common.XmlSerializers.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 2157056 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\a09206d231b222c74183c7255bcacb35\ReachFramework.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 2157056 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\a09206d231b222c74183c7255bcacb35\ReachFramework.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 6773248 c:\windows\assembly\NativeImages_v2.0.50727_32\ProcessHacker\77cfae74e5b0f09017b441e8a629d559\ProcessHacker.ni.exe
+ 2011-08-27 22:50 . 2011-08-27 22:50 6773248 c:\windows\assembly\NativeImages_v2.0.50727_32\ProcessHacker\77cfae74e5b0f09017b441e8a629d559\ProcessHacker.ni.exe
+ 2011-08-27 22:51 . 2011-08-27 22:51 1658368 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\7f0d64056a690c2fe26071b7368b4c56\PresentationUI.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 1658368 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\7f0d64056a690c2fe26071b7368b4c56\PresentationUI.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 1451520 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\c16377318357fb4fcda87c1015815a76\PresentationBuildTasks.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 1451520 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\c16377318357fb4fcda87c1015815a76\PresentationBuildTasks.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 2623488 c:\windows\assembly\NativeImages_v2.0.50727_32\Narrator\ca760a3cb6cabbdf11c1aa42e5b79ee9\Narrator.ni.exe
+ 2011-08-27 22:52 . 2011-08-27 22:52 2623488 c:\windows\assembly\NativeImages_v2.0.50727_32\Narrator\ca760a3cb6cabbdf11c1aa42e5b79ee9\Narrator.ni.exe
- 2011-08-11 19:41 . 2011-08-11 19:41 1545216 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCEx\97051ca60f5e2ea7927adebcb2af9097\MMCEx.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 1545216 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCEx\97051ca60f5e2ea7927adebcb2af9097\MMCEx.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 6438912 c:\windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls\40f947b2a4ecb8ba656104c3f77bb79b\MIGUIControls.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 6438912 c:\windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls\40f947b2a4ecb8ba656104c3f77bb79b\MIGUIControls.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 1746944 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WindowsAP#\af003c8717b4c83eba937c1e72abd6d4\Microsoft.WindowsAPICodePack.Shell.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 1746944 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WindowsAP#\af003c8717b4c83eba937c1e72abd6d4\Microsoft.WindowsAPICodePack.Shell.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 1300992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\0e8e6ead7f4a6b149f12335a81660a83\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 1300992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\0e8e6ead7f4a6b149f12335a81660a83\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 1670144 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\47a4b624c147aae197214d4ee5f0661b\Microsoft.VisualBasic.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 1670144 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\47a4b624c147aae197214d4ee5f0661b\Microsoft.VisualBasic.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\0d7a48003dd32151b3518b3ee7f13350\Microsoft.Transactions.Bridge.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\0d7a48003dd32151b3518b3ee7f13350\Microsoft.Transactions.Bridge.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 3724288 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\79af41ccc6bdc25ede7b249ae32f0101\Microsoft.PowerShell.Editor.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 3724288 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\79af41ccc6bdc25ede7b249ae32f0101\Microsoft.PowerShell.Editor.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 1704960 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\348ff55789cc23b72b19036f01903b63\Microsoft.PowerShell.GPowerShell.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 1704960 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\348ff55789cc23b72b19036f01903b63\Microsoft.PowerShell.GPowerShell.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 1681920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\21f675cbc3d058e68f7f6371644da25f\Microsoft.PowerShell.Commands.Utility.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 1681920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\21f675cbc3d058e68f7f6371644da25f\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 1354752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\1df956de566bc4e34bc72f051a8acd5e\Microsoft.Office.Tools.Excel.v9.0.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 1354752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\1df956de566bc4e34bc72f051a8acd5e\Microsoft.Office.Tools.Excel.v9.0.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 6499840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\ffec5408d56ba9fb311518d6ec521691\Microsoft.MediaCenter.UI.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 6499840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\ffec5408d56ba9fb311518d6ec521691\Microsoft.MediaCenter.UI.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 1009664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\81359c52225ae557ddf7dbdf3c0bf048\Microsoft.MediaCenter.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 1009664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\81359c52225ae557ddf7dbdf3c0bf048\Microsoft.MediaCenter.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 2335744 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\35138a36b7d07f4d37adf96745ef80cb\Microsoft.JScript.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 2335744 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\35138a36b7d07f4d37adf96745ef80cb\Microsoft.JScript.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 1361408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Ink\9c17eb4bfbca7719a4f10bbd3473d07d\Microsoft.Ink.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 1361408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Ink\9c17eb4bfbca7719a4f10bbd3473d07d\Microsoft.Ink.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 4071424 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.GroupPoli#\5b6b82df7c502cf24eeab34e034de5a3\Microsoft.GroupPolicy.Reporting.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\4b45a3a1f24d0d773f9f8fb2d8ce8164\Microsoft.Build.Tasks.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\4b45a3a1f24d0d773f9f8fb2d8ce8164\Microsoft.Build.Tasks.ni.dll
+ 2011-08-27 22:52 . 2011-08-27 22:52 1970176 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\01de5c2808a0c30578614dae24c5d591\Microsoft.Build.Tasks.v3.5.ni.dll
- 2011-08-11 19:41 . 2011-08-11 19:41 1970176 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\01de5c2808a0c30578614dae24c5d591\Microsoft.Build.Tasks.v3.5.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\db9750e8aae34d7bd25b76564f2cebd5\Microsoft.Build.Engine.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\db9750e8aae34d7bd25b76564f2cebd5\Microsoft.Build.Engine.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 2035712 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstore\9004890e93911c7612aa5f218c474618\mcstore.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 2035712 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstore\9004890e93911c7612aa5f218c474618\mcstore.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 3025920 c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\e0683c0b9e68c44011a1f4b70b85239f\mcepg.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 3025920 c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\e0683c0b9e68c44011a1f4b70b85239f\mcepg.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 7060992 c:\windows\assembly\NativeImages_v2.0.50727_32\Impulse\2b01a4df593868f71a3a5a07dd1dd3c4\Impulse.ni.exe
+ 2011-08-27 22:51 . 2011-08-27 22:51 7060992 c:\windows\assembly\NativeImages_v2.0.50727_32\Impulse\2b01a4df593868f71a3a5a07dd1dd3c4\Impulse.ni.exe
+ 2011-08-31 00:06 . 2011-08-31 00:06 10937504 c:\windows\system32\Macromed\Flash\NPSWF64_11_0_1.dll
+ 2011-05-25 23:57 . 2011-09-03 19:52 26792056 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3999918964-3837148993-3667228684-1000-12288.dat
+ 2011-08-27 23:53 . 2011-08-27 23:53 17290752 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\65c3e4d26ac857162658b81b1efffb19\System.Windows.Forms.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 24551936 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel\48ed28e415c976c7adfb2c5ceeaeedb2\System.ServiceModel.ni.dll
+ 2011-08-27 23:54 . 2011-08-27 23:54 18480128 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Entity\529f1a1a0f3e9e994eb3356b55924f3c\System.Data.Entity.ni.dll
+ 2011-08-27 23:50 . 2011-08-27 23:50 10439168 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Core\3c24931e3b4e97b6b49c4d459ba8c552\System.Core.ni.dll
+ 2011-08-27 23:52 . 2011-08-27 23:52 24406528 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\d0abeeb299ca73f7afc5312a00e0bf22\PresentationFramework.ni.dll
+ 2011-08-27 23:51 . 2011-08-27 23:51 15907328 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationCore\de5aaef4bd369972fea5ba6ff7d3e264\PresentationCore.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 18058752 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\56df5c322f32e926eb46047f65d0a357\System.ServiceModel.ni.dll
+ 2011-08-27 22:54 . 2011-08-27 22:54 13346816 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity\093195c829c13c7ad35cb3ad43b52b6a\System.Data.Entity.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 10618880 c:\windows\assembly\NativeImages_v2.0.50727_64\System\3e6eefab37b44e147db80a3c34f0ac05\System.ni.dll
- 2011-08-11 19:03 . 2011-08-11 19:03 10618880 c:\windows\assembly\NativeImages_v2.0.50727_64\System\3e6eefab37b44e147db80a3c34f0ac05\System.ni.dll
+ 2011-08-27 23:28 . 2011-08-27 23:28 17379840 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\0737590c91350bf9ce7416cbbf789bc7\System.Windows.Forms.ni.dll
- 2011-08-11 19:04 . 2011-08-11 19:04 17379840 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\0737590c91350bf9ce7416cbbf789bc7\System.Windows.Forms.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 15249408 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web\01e1dddd3684f57d19699eeb1fad3892\System.Web.ni.dll
+ 2011-08-27 22:56 . 2011-08-27 22:56 15249408 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web\01e1dddd3684f57d19699eeb1fad3892\System.Web.ni.dll
- 2011-08-11 19:43 . 2011-08-11 19:43 23913984 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel\962330ba0685ac1176b611bc052d0ca7\System.ServiceModel.ni.dll
+ 2011-08-27 23:29 . 2011-08-27 23:29 23913984 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel\962330ba0685ac1176b611bc052d0ca7\System.ServiceModel.ni.dll
+ 2011-08-27 23:33 . 2011-08-27 23:33 11900928 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.A#\34d1eab899a35bb7a0075c0b0b3d5938\System.Management.Automation.ni.dll
- 2011-08-11 19:45 . 2011-08-11 19:45 11900928 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.A#\34d1eab899a35bb7a0075c0b0b3d5938\System.Management.Automation.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 13609472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Design\9f162ee8ce0ec6b2a539b68041421911\System.Design.ni.dll
+ 2011-08-27 22:57 . 2011-08-27 22:57 13609472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Design\9f162ee8ce0ec6b2a539b68041421911\System.Design.ni.dll
- 2011-08-11 19:46 . 2011-08-11 19:46 13760000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity\7bf5c7476d8c8255a30a4cda0c9f43be\System.Data.Entity.ni.dll
+ 2011-08-27 23:49 . 2011-08-27 23:49 13760000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity\7bf5c7476d8c8255a30a4cda0c9f43be\System.Data.Entity.ni.dll
+ 2011-08-27 23:41 . 2011-08-27 23:41 19195392 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\90e096ee99f6b0760c47016f862cf5a8\PresentationFramework.ni.dll
- 2011-08-11 19:05 . 2011-08-11 19:05 19195392 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\90e096ee99f6b0760c47016f862cf5a8\PresentationFramework.ni.dll
+ 2011-08-27 23:34 . 2011-08-27 23:34 16540160 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCore\72ea2b7db0ac2d9407d8ab2ed257c62a\PresentationCore.ni.dll
- 2011-08-11 19:04 . 2011-08-11 19:04 16540160 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCore\72ea2b7db0ac2d9407d8ab2ed257c62a\PresentationCore.ni.dll
+ 2011-08-27 22:55 . 2011-08-27 22:55 15568384 c:\windows\assembly\NativeImages_v2.0.50727_64\mscorlib\8f7abb6f7384aad8fc43659820726eab\mscorlib.ni.dll
- 2011-08-10 20:15 . 2011-08-10 20:15 15568384 c:\windows\assembly\NativeImages_v2.0.50727_64\mscorlib\8f7abb6f7384aad8fc43659820726eab\mscorlib.ni.dll
+ 2011-08-27 23:31 . 2011-08-27 23:31 25470976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehshell\857d393b4e25062d5ba400f3422b74e6\ehshell.ni.dll
- 2011-08-11 19:44 . 2011-08-11 19:44 25470976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehshell\857d393b4e25062d5ba400f3422b74e6\ehshell.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 12433408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\0d43c5e77ee7b8466700b16d7e7d4bb7\System.Windows.Forms.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 12433408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\0d43c5e77ee7b8466700b16d7e7d4bb7\System.Windows.Forms.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 11819520 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\72a8d3b35831f77ee9609d43cfd5de35\System.Web.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 17478656 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\052fc9c848a7f4630980ae0fd7a282e0\System.ServiceModel.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 17478656 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\052fc9c848a7f4630980ae0fd7a282e0\System.ServiceModel.ni.dll
- 2011-08-11 19:07 . 2011-08-11 19:07 10580480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\cbd362859e818467b75aaf0287af0fe2\System.Design.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 10580480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\cbd362859e818467b75aaf0287af0fe2\System.Design.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 14339072 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c60906a715473ceccf93f0559527e84d\PresentationFramework.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 14339072 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c60906a715473ceccf93f0559527e84d\PresentationFramework.ni.dll
+ 2011-08-27 22:51 . 2011-08-27 22:51 12234752 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\5566b57732d9edea236f54d06149835a\PresentationCore.ni.dll
- 2011-08-11 19:06 . 2011-08-11 19:06 12234752 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\5566b57732d9edea236f54d06149835a\PresentationCore.ni.dll
+ 2011-08-27 22:49 . 2011-08-27 22:49 11490304 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\16b68fcaff063835ae0ee348a1201f2a\mscorlib.ni.dll
- 2011-08-10 20:31 . 2011-08-10 20:31 11490304 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\16b68fcaff063835ae0ee348a1201f2a\mscorlib.ni.dll
+ 2011-08-27 22:50 . 2011-08-27 22:50 10530304 c:\windows\assembly\NativeImages_v2.0.50727_32\Gibraltar.Agent\ecc562f8f5edd71e6c213da5de3ec18a\Gibraltar.Agent.ni.dll
- 2011-08-11 19:40 . 2011-08-11 19:40 10530304 c:\windows\assembly\NativeImages_v2.0.50727_32\Gibraltar.Agent\ecc562f8f5edd71e6c213da5de3ec18a\Gibraltar.Agent.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-07-29 17361032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"BCWipeTM Startup"="c:\program files (x86)\Jetico\BCWipe\BCWipeTM.exe" [2008-09-04 545520]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"ASUS Sync Loader"="c:\program files (x86)\ASUS\ASUS Sync\asusUPCTLoader.exe" [2011-05-11 638976]
"ASUSWebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe" [2011-08-17 737104]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2011-7-14 66864]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-08 136176]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [x]
R3 DrvSnSht;DrvSnSht;c:\program files (x86)\R-Drive Image\DrvSnSht64.sys [2010-06-01 132432]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-08 136176]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;d:\programs\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 51445112]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-10 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 R-ImageDisk;R-ImageDisk;c:\program files (x86)\R-Drive Image\R-ImageDisk64.sys [2010-10-16 187600]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 RemoteControl-USBLAN;RemoteControl-USBLAN;c:\windows\system32\DRIVERS\rcblan.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x]
R3 Synth3dVsc;Synth3dVsc; [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub; [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 VGPU;VGPU; [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 BCSWAP;BCSWAP; [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [x]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x]
S1 MOBK755Filter;MOBK755Filter;c:\windows\system32\DRIVERS\MOBK755.sys [x]
S2 LMIGuardianSvc;LMIGuardianSvc;d:\programs\LogMeIn\x64\LMIGuardianSvc.exe [2011-07-19 375176]
S2 LMIInfo;LogMeIn Kernel Information Provider;d:\programs\LogMeIn\x64\RaInfo.sys [2010-09-17 15928]
S2 Lotus Notes Diagnostics;Lotus Notes Diagnostics;d:\programs\IBM\Lotus\Notes\nsd.exe [2010-08-11 3417480]
S2 MBAMService;MBAMService;d:\programs\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-04-14 245352]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x]
S2 MOBK755backup;McAfee Online Backup Service;c:\program files (x86)\McAfee Online Backup\MOBK755backup.exe [2010-09-20 207672]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504]
S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2011-04-01 428640]
S2 UsbClientService;UsbClientService;d:\programs\Assistant\UsbClientService.exe [2011-02-18 245760]
S3 busenum;Synology Virtual USB Hub;c:\windows\system32\DRIVERS\busenum.sys [x]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [x]
S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x]
S3 LVUVC64;Logitech Webcam Pro 9000(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-08 02:33]
.
2011-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-08 02:33]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2011-05-25 07:09 227840 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2011-05-25 07:09 227840 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK755]
@="{f378ff85-8d0a-cbe6-4735-3a67760db6bb}"
[HKEY_CLASSES_ROOT\CLSID\{f378ff85-8d0a-cbe6-4735-3a67760db6bb}]
2010-09-20 07:27 4718392 ----a-w- c:\program files (x86)\McAfee Online Backup\MOBK755shell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK7552]
@="{8406002f-3c7e-565d-de02-414c2856a50b}"
[HKEY_CLASSES_ROOT\CLSID\{8406002f-3c7e-565d-de02-414c2856a50b}]
2010-09-20 07:27 4718392 ----a-w- c:\program files (x86)\McAfee Online Backup\MOBK755shell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK7553]
@="{cb5494dd-88ee-383e-88d7-bbd79c7c52d4}"
[HKEY_CLASSES_ROOT\CLSID\{cb5494dd-88ee-383e-88d7-bbd79c7c52d4}]
2010-09-20 07:27 4718392 ----a-w- c:\program files (x86)\McAfee Online Backup\MOBK755shell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-09-11 8114720]
"LogMeIn GUI"="d:\programs\LogMeIn\x64\LogMeInSystray.exe" [2010-09-17 57928]
"BCSSync"="d:\programs\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 112512]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-06-23 1744152]
"Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2010-08-03 415816]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2010-08-03 2412616]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2010-08-03 4725320]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - d:\programs\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - d:\programs\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 205.152.144.23 205.152.132.23
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files (x86)\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q=
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11a_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11a_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11a.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11a.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11a.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11a.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
d:\programs\IBM\Lotus\Notes\ntmulti.exe
c:\windows\SysWOW64\rundll32.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Windows Live\Contacts\wlcomm.exe
.
**************************************************************************
.
Completion time: 2011-09-03 16:13:26 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-03 20:13
ComboFix2.txt 2011-08-27 22:57
ComboFix3.txt 2011-08-27 19:14
.
Pre-Run: 62,664,134,656 bytes free
Post-Run: 62,628,347,904 bytes free
.
- - End Of File - - 66CE0DF19741CFC9666481B809E0F2DD

#4 emudryj

emudryj
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:11:37 AM

Posted 03 September 2011 - 06:59 PM

I thought for a moment that the problem was fixed... but I just tried and Iexplorer.exe is still trying to redirect me.
Malwarebytes Antimalware would block the content of the re-direction but not the redirection itself... I do not know if I'm being clear...I'm really frustrated.

To google for the word "wiki" seems to be the one that never missed the attempt for re-direction...

#5 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:37 AM

Posted 03 September 2011 - 09:07 PM

Hello

I want you to run this tool for me next.

tdsskiller:

Please read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#6 emudryj

emudryj
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:11:37 AM

Posted 03 September 2011 - 10:13 PM

2011/09/03 23:11:30.0547 5584 TDSS rootkit removing tool 2.5.17.0 Aug 22 2011 15:46:57
2011/09/03 23:11:30.0970 5584 ================================================================================
2011/09/03 23:11:30.0970 5584 SystemInfo:
2011/09/03 23:11:30.0970 5584
2011/09/03 23:11:30.0971 5584 OS Version: 6.1.7601 ServicePack: 1.0
2011/09/03 23:11:30.0971 5584 Product type: Workstation
2011/09/03 23:11:30.0971 5584 ComputerName: TA-HOME
2011/09/03 23:11:30.0971 5584 UserName: emudryj
2011/09/03 23:11:30.0971 5584 Windows directory: C:\Windows
2011/09/03 23:11:30.0971 5584 System windows directory: C:\Windows
2011/09/03 23:11:30.0971 5584 Running under WOW64
2011/09/03 23:11:30.0971 5584 Processor architecture: Intel x64
2011/09/03 23:11:30.0971 5584 Number of processors: 8
2011/09/03 23:11:30.0971 5584 Page size: 0x1000
2011/09/03 23:11:30.0971 5584 Boot type: Normal boot
2011/09/03 23:11:30.0971 5584 ================================================================================
2011/09/03 23:11:46.0418 5584 Initialize success
2011/09/03 23:11:52.0439 11164 ================================================================================
2011/09/03 23:11:52.0439 11164 Scan started
2011/09/03 23:11:52.0439 11164 Mode: Manual;
2011/09/03 23:11:52.0439 11164 ================================================================================
2011/09/03 23:11:52.0613 11164 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
2011/09/03 23:11:52.0630 11164 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
2011/09/03 23:11:52.0645 11164 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
2011/09/03 23:11:52.0664 11164 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/09/03 23:11:52.0684 11164 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
2011/09/03 23:11:52.0701 11164 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
2011/09/03 23:11:52.0725 11164 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
2011/09/03 23:11:52.0741 11164 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
2011/09/03 23:11:52.0759 11164 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
2011/09/03 23:11:52.0773 11164 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
2011/09/03 23:11:52.0788 11164 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
2011/09/03 23:11:52.0803 11164 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
2011/09/03 23:11:52.0818 11164 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
2011/09/03 23:11:52.0833 11164 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/09/03 23:11:52.0847 11164 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
2011/09/03 23:11:52.0862 11164 androidusb (4de0d5d747a73797c95a97dcce5018b5) C:\Windows\system32\Drivers\ssadadb.sys
2011/09/03 23:11:52.0877 11164 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
2011/09/03 23:11:52.0903 11164 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
2011/09/03 23:11:52.0918 11164 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
2011/09/03 23:11:52.0932 11164 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/09/03 23:11:52.0946 11164 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
2011/09/03 23:11:52.0974 11164 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
2011/09/03 23:11:52.0993 11164 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
2011/09/03 23:11:53.0011 11164 BCSWAP (e33fb106d6968e3903a92fde120ea935) C:\Windows\system32\drivers\BCSWAP.sys
2011/09/03 23:11:53.0028 11164 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
2011/09/03 23:11:53.0050 11164 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/09/03 23:11:53.0068 11164 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
2011/09/03 23:11:53.0083 11164 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/09/03 23:11:53.0098 11164 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/09/03 23:11:53.0119 11164 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
2011/09/03 23:11:53.0134 11164 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/09/03 23:11:53.0149 11164 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/09/03 23:11:53.0165 11164 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/09/03 23:11:53.0180 11164 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/09/03 23:11:53.0201 11164 busenum (fc278504bfa3ac7e9ed92359d0ee7282) C:\Windows\system32\DRIVERS\busenum.sys
2011/09/03 23:11:53.0228 11164 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/09/03 23:11:53.0243 11164 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
2011/09/03 23:11:53.0261 11164 cfwids (676535b3156fecf7133cf80b4d2f6cf7) C:\Windows\system32\drivers\cfwids.sys
2011/09/03 23:11:53.0276 11164 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
2011/09/03 23:11:53.0293 11164 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
2011/09/03 23:11:53.0320 11164 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/09/03 23:11:53.0334 11164 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
2011/09/03 23:11:53.0354 11164 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys
2011/09/03 23:11:53.0370 11164 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
2011/09/03 23:11:53.0385 11164 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
2011/09/03 23:11:53.0403 11164 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/09/03 23:11:53.0429 11164 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys
2011/09/03 23:11:53.0458 11164 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
2011/09/03 23:11:53.0475 11164 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
2011/09/03 23:11:53.0491 11164 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
2011/09/03 23:11:53.0515 11164 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
2011/09/03 23:11:53.0526 11164 DrvSnSht (4e375548e71ce02f65d50dff35d6b5b8) C:\Program Files (x86)\R-Drive Image\DrvSnSht64.sys
2011/09/03 23:11:53.0549 11164 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
2011/09/03 23:11:53.0600 11164 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
2011/09/03 23:11:53.0654 11164 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
2011/09/03 23:11:53.0671 11164 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
2011/09/03 23:11:53.0697 11164 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
2011/09/03 23:11:53.0713 11164 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
2011/09/03 23:11:53.0731 11164 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
2011/09/03 23:11:53.0753 11164 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
2011/09/03 23:11:53.0768 11164 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
2011/09/03 23:11:53.0783 11164 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/09/03 23:11:53.0801 11164 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
2011/09/03 23:11:53.0822 11164 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
2011/09/03 23:11:53.0837 11164 fssfltr (6c06701bf1db05405804d7eb610991ce) C:\Windows\system32\DRIVERS\fssfltr.sys
2011/09/03 23:11:53.0855 11164 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
2011/09/03 23:11:53.0873 11164 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
2011/09/03 23:11:53.0888 11164 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/09/03 23:11:53.0902 11164 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/09/03 23:11:53.0926 11164 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
2011/09/03 23:11:53.0946 11164 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
2011/09/03 23:11:53.0961 11164 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/09/03 23:11:53.0977 11164 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
2011/09/03 23:11:53.0993 11164 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
2011/09/03 23:11:54.0010 11164 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
2011/09/03 23:11:54.0035 11164 hotcore3 (5e626ea93c77825c56e6fbc2fd5e5de5) C:\Windows\system32\DRIVERS\hotcore3.sys
2011/09/03 23:11:54.0051 11164 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
2011/09/03 23:11:54.0072 11164 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
2011/09/03 23:11:54.0091 11164 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
2011/09/03 23:11:54.0107 11164 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
2011/09/03 23:11:54.0125 11164 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
2011/09/03 23:11:54.0143 11164 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
2011/09/03 23:11:54.0185 11164 IntcAzAudAddService (5ba1779e2c84fde2a5e201fff9c42c9c) C:\Windows\system32\drivers\RTKVHD64.sys
2011/09/03 23:11:54.0215 11164 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
2011/09/03 23:11:54.0232 11164 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
2011/09/03 23:11:54.0250 11164 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/09/03 23:11:54.0269 11164 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
2011/09/03 23:11:54.0285 11164 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
2011/09/03 23:11:54.0303 11164 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
2011/09/03 23:11:54.0319 11164 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
2011/09/03 23:11:54.0337 11164 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
2011/09/03 23:11:54.0348 11164 ISODrive (88bb5280137dc9a7e9989c475763cd08) C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys
2011/09/03 23:11:54.0363 11164 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/09/03 23:11:54.0378 11164 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/09/03 23:11:54.0397 11164 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys
2011/09/03 23:11:54.0413 11164 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys
2011/09/03 23:11:54.0428 11164 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
2011/09/03 23:11:54.0461 11164 LGBusEnum (fa529fb35694c24bf98a9ef67c1cd9d0) C:\Windows\system32\drivers\LGBusEnum.sys
2011/09/03 23:11:54.0478 11164 LGVirHid (94b29ce153765e768f004fb3440be2b0) C:\Windows\system32\drivers\LGVirHid.sys
2011/09/03 23:11:54.0494 11164 LHidFilt (1074c77a47835e03c15bf92452f9a750) C:\Windows\system32\DRIVERS\LHidFilt.Sys
2011/09/03 23:11:54.0510 11164 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
2011/09/03 23:11:54.0557 11164 LMIInfo (0317335b15ff3bda8e10197e3434cfc0) D:\Programs\LogMeIn\x64\RaInfo.sys
2011/09/03 23:11:54.0575 11164 lmimirr (413ecdcfad9a82804d3674c8d7eec24e) C:\Windows\system32\DRIVERS\lmimirr.sys
2011/09/03 23:11:54.0609 11164 LMIRfsDriver (c57d3faa50e6f395759ffb7c709bd944) C:\Windows\system32\drivers\LMIRfsDriver.sys
2011/09/03 23:11:54.0624 11164 LMouFilt (96999c364c649e2866a268f7420a304a) C:\Windows\system32\DRIVERS\LMouFilt.Sys
2011/09/03 23:11:54.0649 11164 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/09/03 23:11:54.0665 11164 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/09/03 23:11:54.0681 11164 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/09/03 23:11:54.0698 11164 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/09/03 23:11:54.0714 11164 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
2011/09/03 23:11:54.0729 11164 LUsbFilt (11ddb1d900078fbe3691df7b878aec28) C:\Windows\system32\Drivers\LUsbFilt.Sys
2011/09/03 23:11:54.0748 11164 LVRS64 (ef586b959f747e74c76603ff16ae417b) C:\Windows\system32\DRIVERS\lvrs64.sys
2011/09/03 23:11:54.0801 11164 LVUVC64 (edf73bfa1bd24d74d1d64dc0ed28a7cd) C:\Windows\system32\DRIVERS\lvuvc64.sys
2011/09/03 23:11:54.0852 11164 MBAMProtector (9c4fb231b6e02f84580de2f00f3c5293) C:\Windows\system32\drivers\mbam.sys
2011/09/03 23:11:54.0897 11164 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
2011/09/03 23:11:54.0916 11164 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/09/03 23:11:54.0933 11164 mfeapfk (fb752feb1ed4e660ff51712892905c04) C:\Windows\system32\drivers\mfeapfk.sys
2011/09/03 23:11:54.0953 11164 mfeavfk (5822e70233218bcf22a65fcea74d012d) C:\Windows\system32\drivers\mfeavfk.sys
2011/09/03 23:11:54.0993 11164 mfefirek (5a24e7c834576313d8c5eaf0825da844) C:\Windows\system32\drivers\mfefirek.sys
2011/09/03 23:11:55.0016 11164 mfehidk (39030c98198f02a2f3a1c3166bf56253) C:\Windows\system32\drivers\mfehidk.sys
2011/09/03 23:11:55.0036 11164 mfenlfk (50c3a9d7465d385061c0601deefb5a8e) C:\Windows\system32\DRIVERS\mfenlfk.sys
2011/09/03 23:11:55.0054 11164 mferkdet (edf5ee799a0b3ed6dce8bb16a51f3d1f) C:\Windows\system32\drivers\mferkdet.sys
2011/09/03 23:11:55.0075 11164 mfewfpk (9182faf9addd5ea6308d155ceb502c6f) C:\Windows\system32\drivers\mfewfpk.sys
2011/09/03 23:11:55.0103 11164 MOBK755Filter (3c69aa906ee867ade4437acd8460b43d) C:\Windows\system32\DRIVERS\MOBK755.sys
2011/09/03 23:11:55.0119 11164 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
2011/09/03 23:11:55.0135 11164 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
2011/09/03 23:11:55.0150 11164 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
2011/09/03 23:11:55.0166 11164 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
2011/09/03 23:11:55.0182 11164 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
2011/09/03 23:11:55.0199 11164 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
2011/09/03 23:11:55.0215 11164 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
2011/09/03 23:11:55.0234 11164 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
2011/09/03 23:11:55.0251 11164 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/09/03 23:11:55.0268 11164 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/09/03 23:11:55.0285 11164 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/09/03 23:11:55.0301 11164 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
2011/09/03 23:11:55.0319 11164 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
2011/09/03 23:11:55.0342 11164 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
2011/09/03 23:11:55.0358 11164 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
2011/09/03 23:11:55.0374 11164 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
2011/09/03 23:11:55.0399 11164 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
2011/09/03 23:11:55.0415 11164 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/09/03 23:11:55.0431 11164 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
2011/09/03 23:11:55.0451 11164 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
2011/09/03 23:11:55.0470 11164 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
2011/09/03 23:11:55.0486 11164 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
2011/09/03 23:11:55.0502 11164 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/09/03 23:11:55.0522 11164 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
2011/09/03 23:11:55.0543 11164 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
2011/09/03 23:11:55.0568 11164 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
2011/09/03 23:11:55.0589 11164 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/09/03 23:11:55.0605 11164 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/09/03 23:11:55.0621 11164 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/09/03 23:11:55.0638 11164 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/09/03 23:11:55.0654 11164 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
2011/09/03 23:11:55.0670 11164 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
2011/09/03 23:11:55.0688 11164 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
2011/09/03 23:11:55.0716 11164 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/09/03 23:11:55.0734 11164 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
2011/09/03 23:11:55.0753 11164 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
2011/09/03 23:11:55.0786 11164 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
2011/09/03 23:11:55.0814 11164 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
2011/09/03 23:11:55.0948 11164 nvlddmkm (b34e9bfbd9c61048ef6281c3e7ec210a) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/09/03 23:11:56.0075 11164 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
2011/09/03 23:11:56.0093 11164 nvrd64 (5266d03c0628fae9c35f40eec078fc88) C:\Windows\system32\DRIVERS\nvrd64.sys
2011/09/03 23:11:56.0108 11164 nvsmu (e58d81fb8616d0cb55c1e36aa0b213c9) C:\Windows\system32\DRIVERS\nvsmu.sys
2011/09/03 23:11:56.0126 11164 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
2011/09/03 23:11:56.0145 11164 nvstor64 (2a718473ede7032a508a8f44c633657f) C:\Windows\system32\DRIVERS\nvstor64.sys
2011/09/03 23:11:56.0168 11164 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
2011/09/03 23:11:56.0184 11164 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
2011/09/03 23:11:56.0215 11164 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
2011/09/03 23:11:56.0231 11164 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
2011/09/03 23:11:56.0251 11164 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
2011/09/03 23:11:56.0266 11164 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
2011/09/03 23:11:56.0285 11164 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/09/03 23:11:56.0301 11164 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
2011/09/03 23:11:56.0324 11164 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
2011/09/03 23:11:56.0385 11164 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
2011/09/03 23:11:56.0401 11164 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
2011/09/03 23:11:56.0424 11164 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
2011/09/03 23:11:56.0452 11164 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
2011/09/03 23:11:56.0480 11164 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/09/03 23:11:56.0499 11164 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
2011/09/03 23:11:56.0511 11164 R-ImageDisk (05b931c48d60b7b96c38047f251cfa65) C:\Program Files (x86)\R-Drive Image\R-ImageDisk64.sys
2011/09/03 23:11:56.0527 11164 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
2011/09/03 23:11:56.0544 11164 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/09/03 23:11:56.0564 11164 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/09/03 23:11:56.0583 11164 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/09/03 23:11:56.0599 11164 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
2011/09/03 23:11:56.0618 11164 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
2011/09/03 23:11:56.0634 11164 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/09/03 23:11:56.0650 11164 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/09/03 23:11:56.0671 11164 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys
2011/09/03 23:11:56.0687 11164 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
2011/09/03 23:11:56.0706 11164 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
2011/09/03 23:11:56.0727 11164 RdpVideoMiniport (70cba1a0c98600a2aa1863479b35cb90) C:\Windows\system32\drivers\rdpvideominiport.sys
2011/09/03 23:11:56.0745 11164 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
2011/09/03 23:11:56.0763 11164 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
2011/09/03 23:11:56.0783 11164 RemoteControl-USBLAN (bfa4873cd96d7144dc0059a70e1e358f) C:\Windows\system32\DRIVERS\rcblan.sys
2011/09/03 23:11:56.0802 11164 RimUsb (7b04c9843921ab1f695fb395422c5360) C:\Windows\system32\Drivers\RimUsb_AMD64.sys
2011/09/03 23:11:56.0828 11164 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
2011/09/03 23:11:56.0848 11164 RTL8167 (16d4e350420baa7e63e16e3fc033e1f5) C:\Windows\system32\DRIVERS\Rt64win7.sys
2011/09/03 23:11:56.0866 11164 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys
2011/09/03 23:11:56.0886 11164 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
2011/09/03 23:11:56.0905 11164 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
2011/09/03 23:11:56.0930 11164 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
2011/09/03 23:11:56.0959 11164 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
2011/09/03 23:11:56.0977 11164 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
2011/09/03 23:11:56.0993 11164 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
2011/09/03 23:11:57.0020 11164 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
2011/09/03 23:11:57.0037 11164 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
2011/09/03 23:11:57.0054 11164 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
2011/09/03 23:11:57.0070 11164 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/09/03 23:11:57.0093 11164 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/09/03 23:11:57.0110 11164 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/09/03 23:11:57.0127 11164 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
2011/09/03 23:11:57.0151 11164 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
2011/09/03 23:11:57.0181 11164 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
2011/09/03 23:11:57.0204 11164 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
2011/09/03 23:11:57.0225 11164 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
2011/09/03 23:11:57.0249 11164 ssadbus (866f8212ef7e75bac8bca03331e30cb4) C:\Windows\system32\DRIVERS\ssadbus.sys
2011/09/03 23:11:57.0269 11164 ssadmdfl (73e2ba39e7eb024dc686412e2e924a74) C:\Windows\system32\DRIVERS\ssadmdfl.sys
2011/09/03 23:11:57.0287 11164 ssadmdm (74b032d6c1e36ae2f790752fde8ce055) C:\Windows\system32\DRIVERS\ssadmdm.sys
2011/09/03 23:11:57.0309 11164 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
2011/09/03 23:11:57.0329 11164 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys
2011/09/03 23:11:57.0345 11164 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys
2011/09/03 23:11:57.0362 11164 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
2011/09/03 23:11:57.0425 11164 Tcpip (f0e98c00a09fdf791525829a1d14240f) C:\Windows\system32\drivers\tcpip.sys
2011/09/03 23:11:57.0474 11164 TCPIP6 (f0e98c00a09fdf791525829a1d14240f) C:\Windows\system32\DRIVERS\tcpip.sys
2011/09/03 23:11:57.0499 11164 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
2011/09/03 23:11:57.0518 11164 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
2011/09/03 23:11:57.0535 11164 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
2011/09/03 23:11:57.0553 11164 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
2011/09/03 23:11:57.0569 11164 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
2011/09/03 23:11:57.0603 11164 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/09/03 23:11:57.0620 11164 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
2011/09/03 23:11:57.0653 11164 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
2011/09/03 23:11:57.0670 11164 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
2011/09/03 23:11:57.0690 11164 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
2011/09/03 23:11:57.0716 11164 UimBus (70771e2b8eb3cde389906463bcd5e675) C:\Windows\system32\DRIVERS\uimx64.sys
2011/09/03 23:11:57.0738 11164 Uim_IM (5d5988d94378c92f0365bf505e7c5475) C:\Windows\system32\Drivers\Uim_IMx64.sys
2011/09/03 23:11:57.0757 11164 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
2011/09/03 23:11:57.0774 11164 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
2011/09/03 23:11:57.0791 11164 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
2011/09/03 23:11:57.0819 11164 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys
2011/09/03 23:11:57.0836 11164 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys
2011/09/03 23:11:57.0853 11164 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/09/03 23:11:57.0870 11164 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
2011/09/03 23:11:57.0890 11164 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
2011/09/03 23:11:57.0909 11164 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
2011/09/03 23:11:57.0927 11164 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
2011/09/03 23:11:57.0944 11164 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
2011/09/03 23:11:57.0962 11164 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\drivers\USBSTOR.SYS
2011/09/03 23:11:57.0978 11164 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
2011/09/03 23:11:57.0997 11164 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
2011/09/03 23:11:58.0020 11164 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
2011/09/03 23:11:58.0039 11164 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/09/03 23:11:58.0056 11164 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
2011/09/03 23:11:58.0091 11164 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
2011/09/03 23:11:58.0108 11164 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
2011/09/03 23:11:58.0127 11164 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys
2011/09/03 23:11:58.0144 11164 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys
2011/09/03 23:11:58.0162 11164 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
2011/09/03 23:11:58.0182 11164 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
2011/09/03 23:11:58.0205 11164 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
2011/09/03 23:11:58.0225 11164 vpcbus (7254b4f4a59f9d18b49caf8aa0428631) C:\Windows\system32\DRIVERS\vpchbus.sys
2011/09/03 23:11:58.0242 11164 vpcnfltr (ed501cebf6f571fcce55887bdf4888ea) C:\Windows\system32\DRIVERS\vpcnfltr.sys
2011/09/03 23:11:58.0261 11164 vpcusb (2ce21ffd391fe21763ddc32b1caaba7d) C:\Windows\system32\DRIVERS\vpcusb.sys
2011/09/03 23:11:58.0281 11164 vpcvmm (c3f658cd063ea677fccbb620167b44c8) C:\Windows\system32\drivers\vpcvmm.sys
2011/09/03 23:11:58.0300 11164 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/09/03 23:11:58.0319 11164 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
2011/09/03 23:11:58.0346 11164 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
2011/09/03 23:11:58.0363 11164 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
2011/09/03 23:11:58.0372 11164 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
2011/09/03 23:11:58.0404 11164 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
2011/09/03 23:11:58.0427 11164 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
2011/09/03 23:11:58.0468 11164 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/09/03 23:11:58.0486 11164 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
2011/09/03 23:11:58.0525 11164 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
2011/09/03 23:11:58.0553 11164 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
2011/09/03 23:11:58.0586 11164 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
2011/09/03 23:11:58.0617 11164 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
2011/09/03 23:11:58.0636 11164 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/09/03 23:11:58.0663 11164 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
2011/09/03 23:11:58.0678 11164 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
2011/09/03 23:11:58.0685 11164 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk2\DR2
2011/09/03 23:11:58.0693 11164 Boot (0x1200) (5d5b996c3c3b48f1c022d8ebf3eee6df) \Device\Harddisk0\DR0\Partition0
2011/09/03 23:11:58.0702 11164 Boot (0x1200) (f3a1d70f0ee7a5a2f00867a63046e0eb) \Device\Harddisk0\DR0\Partition1
2011/09/03 23:11:58.0711 11164 Boot (0x1200) (9fc6694c85a17d87b36e2ab1613012e1) \Device\Harddisk1\DR1\Partition0
2011/09/03 23:11:58.0719 11164 Boot (0x1200) (ce31ab36b35c5f6d59ac22a61287bb5c) \Device\Harddisk2\DR2\Partition0
2011/09/03 23:11:58.0725 11164 ================================================================================
2011/09/03 23:11:58.0725 11164 Scan finished
2011/09/03 23:11:58.0725 11164 ================================================================================
2011/09/03 23:11:58.0731 9320 Detected object count: 0
2011/09/03 23:11:58.0731 9320 Actual detected object count: 0

#7 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:37 AM

Posted 03 September 2011 - 10:42 PM

Hello

Lets get a deeper look into the system and see if something shows up.

Download and run OTL

Download OTL by Old Timer and save it to your Desktop.
  • Double click on OTL.exe to run it.
  • Under Output, ensure that Minimal Output is selected.
  • Under Extra Registry section, select Use SafeList.
  • Click the Scan All Users checkbox.
  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open.
    • OTL.txt <-- Will be opened and the that I need posted back here
    • Extra.txt <-- Will be minimized - save this one on your desktop in case I ask for it later
  • Please post the contents of OTListIt.txt in your next reply.

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#8 emudryj

emudryj
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:11:37 AM

Posted 04 September 2011 - 10:00 AM

OTL logfile created on: 9/4/2011 10:54:21 AM - Run 1
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Users\emudryj\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.99 Gb Total Physical Memory | 3.95 Gb Available Physical Memory | 65.86% Memory free
11.98 Gb Paging File | 9.08 Gb Available in Paging File | 75.79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119.14 Gb Total Space | 57.79 Gb Free Space | 48.51% Space Free | Partition Type: NTFS
Drive D: | 1397.26 Gb Total Space | 1366.99 Gb Free Space | 97.83% Space Free | Partition Type: NTFS
Drive E: | 135.00 Mb Total Space | 43.74 Mb Free Space | 32.40% Space Free | Partition Type: NTFS
Drive G: | 5.40 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 1370.91 Gb Total Space | 627.95 Gb Free Space | 45.81% Space Free | Partition Type: NTFS
Drive I: | 1370.91 Gb Total Space | 627.95 Gb Free Space | 45.81% Space Free | Partition Type: NTFS
Drive W: | 1370.91 Gb Total Space | 627.95 Gb Free Space | 45.81% Space Free | Partition Type: NTFS
Drive X: | 1370.91 Gb Total Space | 627.95 Gb Free Space | 45.81% Space Free | Partition Type: NTFS
Drive Y: | 1370.91 Gb Total Space | 627.95 Gb Free Space | 45.81% Space Free | Partition Type: NTFS
Drive Z: | 1370.91 Gb Total Space | 627.95 Gb Free Space | 45.81% Space Free | Partition Type: NTFS

Computer Name: TA-HOME | User Name: emudryj | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\emudryj\Desktop\OTL.exe (OldTimer Tools)
PRC - D:\Programs\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe (ecareme)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
PRC - D:\Programs\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - D:\Programs\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\ASUS\ASUS Sync\asusUPCTLoader.exe (Futuredial Inc.)
PRC - C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - D:\Programs\Assistant\UsbClientService.exe ()
PRC - C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation)
PRC - D:\Programs\IBM\Lotus\Notes\ntmulti.exe (IBM Corp)
PRC - D:\Programs\IBM\Lotus\Notes\nsd.exe (IBM)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6e9a08576157b4aeb91a3aaa452fcb00\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\72a8d3b35831f77ee9609d43cfd5de35\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\0d43c5e77ee7b8466700b16d7e7d4bb7\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\9e87dd8fe5d0f925d80a6a6eaf74fdb9\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\16d2854bf69d59d94e64a918365705f1\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\36d0ed3f2a65b9d67933ed46dfcd2ccb\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\3da7c6c1a0f26ae91883fd8b03ec192d\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\b614f2d2f13857c09c98b02944fc1c41\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\16b68fcaff063835ae0ee348a1201f2a\mscorlib.ni.dll ()
MOD - D:\Programs\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\8.1.1.50-8876480SL\Program\clntutil.dll ()
MOD - C:\Program Files (x86)\ASUS\ASUS Sync\sqlite3.7.dll ()
MOD - C:\Program Files (x86)\ASUS\ASUS Sync\sqlite3.dll ()
MOD - C:\Program Files (x86)\ASUS\ASUS Sync\asusDetect.dll ()
MOD - C:\Program Files (x86)\ASUS\ASUS Sync\fdHttpd.dll ()
MOD - C:\Program Files (x86)\ASUS\ASUS Sync\asusDisk.dll ()
MOD - C:\Program Files (x86)\ASUS\ASUS Sync\asusDetectLegend.dll ()
MOD - C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AxInterop.ShockwaveFlashObjects.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (LBTServ) -- C:\Program Files\Common Files\logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (mfefire) -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV:64bit: - (McShield) -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (mfevtp) -- C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (McODS) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (MSK80Service) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McProxy) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNASvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcmscsvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McAfee SiteAdvisor Service) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (LMIMaint) -- D:\Programs\LogMeIn\x64\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) -- D:\Programs\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (MBAMService) -- D:\Programs\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (UMVPFSrv) -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (UsbClientService) -- D:\Programs\Assistant\UsbClientService.exe ()
SRV - (LogMeIn) -- D:\Programs\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (MOBK755backup) -- C:\Program Files (x86)\McAfee Online Backup\MOBK755backup.exe (McAfee, Inc.)
SRV - (Multi-user Cleanup Service) -- D:\Programs\IBM\Lotus\Notes\ntmulti.exe (IBM Corp)
SRV - (Lotus Notes Diagnostics) -- D:\Programs\IBM\Lotus\Notes\nsd.exe (IBM)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) -- D:\Programs\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (LMIRfsClientNP) -- C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (LUsbFilt) -- C:\Windows\SysNative\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) -- C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LMouFilt) -- C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (mfefirek) -- C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) -- C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) -- C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) -- C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfenlfk) -- C:\Windows\SysNative\drivers\mfenlfk.sys (McAfee, Inc.)
DRV:64bit: - (cfwids) -- C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (Uim_IM) -- C:\Windows\SysNative\drivers\Uim_IMx64.sys (Paragon)
DRV:64bit: - (UimBus) -- C:\Windows\SysNative\drivers\uimx64.sys (Windows ® 2000 DDK provider)
DRV:64bit: - (hotcore3) -- C:\Windows\SysNative\drivers\hotcore3.sys (Paragon Software Group)
DRV:64bit: - (LVUVC64) Logitech Webcam Pro 9000(UVC) -- C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) -- C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (mfehidk) -- C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) -- C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (busenum) -- C:\Windows\SysNative\drivers\busenum.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (MOBK755Filter) -- C:\Windows\SysNative\drivers\MOBK755.sys (Mozy, Inc.)
DRV:64bit: - (LMIRfsDriver) -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) -- C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV:64bit: - (ssadmdm) -- C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) -- C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (androidusb) -- C:\Windows\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (ssadmdfl) SAMSUNG Android USB Modem (Filter) -- C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (LGVirHid) -- C:\Windows\SysNative\drivers\LGVirHid.sys (Logitech Inc.)
DRV:64bit: - (LGBusEnum) -- C:\Windows\SysNative\drivers\LGBusEnum.sys (Logitech Inc.)
DRV:64bit: - (vpcvmm) -- C:\Windows\SysNative\drivers\vpcvmm.sys (Microsoft Corporation)
DRV:64bit: - (vpcbus) -- C:\Windows\SysNative\drivers\vpchbus.sys (Microsoft Corporation)
DRV:64bit: - (vpcusb) -- C:\Windows\SysNative\drivers\vpcusb.sys (Microsoft Corporation)
DRV:64bit: - (vpcnfltr) -- C:\Windows\SysNative\drivers\vpcnfltr.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (BCSWAP) -- C:\Windows\SysNative\drivers\bcswap.sys (Jetico, Inc.)
DRV:64bit: - (RimUsb) -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (RemoteControl-USBLAN) -- C:\Windows\SysNative\drivers\rcblan.sys (Belcarra Technologies)
DRV - (R-ImageDisk) -- C:\Program Files (x86)\R-Drive Image\R-ImageDisk64.sys (R-TT Inc.)
DRV - (LMIInfo) -- D:\Programs\LogMeIn\x64\rainfo.sys (LogMeIn, Inc.)
DRV - (DrvSnSht) -- C:\Program Files (x86)\R-Drive Image\DrvSnSht64.sys (R-TT Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (ISODrive) -- C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys (EZB Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3999918964-3837148993-3667228684-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-3999918964-3837148993-3667228684-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKU\S-1-5-21-3999918964-3837148993-3667228684-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A2 C8 DE A8 82 1A CC 01 [binary data]
IE - HKU\S-1-5-21-3999918964-3837148993-3667228684-1000\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-3999918964-3837148993-3667228684-1000\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-3999918964-3837148993-3667228684-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3999918964-3837148993-3667228684-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: " "
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: " "
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q="

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_0_1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: D:\Programs\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Programs\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: D:\Programs\Java\Jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files (x86)\McAfee\SiteAdvisor [2011/08/29 19:26:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\remotemode@splashtop.com: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\FFExtensions
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0\extensions\\Components: D:\Programs\Mozilla Firefox\components [2011/08/27 02:32:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0\extensions\\Plugins: D:\Programs\Mozilla Firefox\plugins

[2011/05/25 19:49:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\emudryj\AppData\Roaming\Mozilla\Extensions
[2011/08/08 08:15:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions
[2011/05/26 21:22:02 | 000,000,000 | ---D | M] (Freecorder Toolbar) -- C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}
[2011/08/08 08:15:26 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/05/29 15:59:48 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\engine@conduit.com
[2011/06/20 14:07:48 | 000,000,863 | ---- | M] () -- C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\searchplugins\conduit.xml
() (No name found) -- C:\USERS\EMUDRYJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JHV7MM9Q.DEFAULT\EXTENSIONS\TESTPILOT@LABS.MOZILLA.COM.XPI

O1 HOSTS File: ([2011/09/03 15:53:46 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho64.dll ()
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Programs\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110526213057.dll (McAfee, Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Programs\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110526213057.dll (McAfee, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4:64bit: - HKLM..\Run: [BCSSync] D:\Programs\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] D:\Programs\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [ASUS Sync Loader] C:\Program Files (x86)\ASUS\ASUS Sync\asusUPCTLoader.exe (Futuredial Inc.)
O4 - HKLM..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe (ecareme)
O4 - HKLM..\Run: [BCWipeTM Startup] C:\Program Files (x86)\Jetico\BCWipe\BCWipeTM.exe (Jetico, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] D:\Programs\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKU\S-1-5-21-3999918964-3837148993-3667228684-1003..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3999918964-3837148993-3667228684-1003..\RunOnce: [mctadmin] File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-3999918964-3837148993-3667228684-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3999918964-3837148993-3667228684-1000\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-3999918964-3837148993-3667228684-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3999918964-3837148993-3667228684-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3999918964-3837148993-3667228684-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3999918964-3837148993-3667228684-1003\Software\Policies\Microsoft\Internet Explorer\Recovery present
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - D:\Programs\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Se&nd to OneNote - D:\Programs\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - D:\Programs\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - D:\Programs\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Programs\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Programs\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - D:\Programs\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - D:\Programs\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/x64/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} http://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab (Device Detection)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/RACtrl.cab (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 205.152.144.23 205.152.132.23
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{981DC840-1403-43B8-BB74-EBDF6C951E97}: DhcpNameServer = 205.152.144.23 205.152.132.23
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CAB1B010-6ED5-4505-8DB6-724B5510BD2F}: DhcpNameServer = 205.152.144.23 205.152.132.23
O18:64bit: - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - Reg Error: Key error. - c:\Program Files\Common Files\logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D:\Programs\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/02/09 21:55:59 | 000,423,304 | R--- | M] (Electronic Arts) - G:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2010/02/10 02:21:09 | 000,000,000 | ---D | M] - G:\Autorun -- [ CDFS ]
O32 - AutoRun File - [2010/01/31 04:21:13 | 000,367,686 | R--- | M] () - G:\Autorun.ico -- [ CDFS ]
O32 - AutoRun File - [2010/02/09 22:55:03 | 009,965,568 | R--- | M] () - G:\autorun.dat -- [ CDFS ]
O32 - AutoRun File - [2010/02/09 22:54:55 | 000,000,155 | R--- | M] () - G:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/09/04 10:53:03 | 000,581,120 | ---- | C] (OldTimer Tools) -- C:\Users\emudryj\Desktop\OTL.exe
[2011/09/04 10:52:23 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{DF8F7F82-CD8E-49BE-B763-F40732FEAD24}
[2011/09/04 10:52:13 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{D5A98FCF-66AC-46D4-9435-CF5697DA31DC}
[2011/09/04 09:33:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2011/09/03 23:11:10 | 001,406,768 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\emudryj\Desktop\tdsskiller(1).exe
[2011/09/03 21:44:27 | 000,000,000 | ---D | C] -- C:\Users\emudryj\Documents\BFBC2
[2011/09/03 21:18:56 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{4D81980B-FCCE-4BDE-B582-1FA34F8FA7B0}
[2011/09/03 21:18:46 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{5AD95971-EF3D-4989-B59B-75D09D25D7C2}
[2011/09/03 18:14:09 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/09/03 15:12:39 | 000,000,000 | ---D | C] -- C:\arreglacombo
[2011/09/03 15:06:11 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2011/09/03 14:51:23 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\wj32
[2011/09/03 09:18:21 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{F99644DD-C5EA-4466-9E61-4012C4FBE963}
[2011/09/03 09:18:11 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{DF66D3DE-ED29-41BB-B877-3B7BADB1FBEE}
[2011/09/02 18:45:06 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{5D420F79-65F7-497C-92C7-85C067FAD907}
[2011/09/02 18:44:56 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{378986B6-0A63-4A35-8AC5-58670D00B5A4}
[2011/09/01 21:00:52 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{4C0D01BC-6237-45B2-928D-04BD39AB6415}
[2011/09/01 21:00:42 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{B9B49647-DA0A-4033-A5C1-BB3C40E4D588}
[2011/08/31 19:49:13 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{59F04404-93E6-437D-9615-F5541A046006}
[2011/08/31 19:49:03 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{A8F13873-1F4B-49D8-B1DC-15487AC86E7F}
[2011/08/31 07:48:38 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{E55A29EC-2BB2-4B23-BCC3-148B0DBBA141}
[2011/08/31 07:48:29 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{86BB2B69-3DC5-40D7-8E91-B058AD4A4586}
[2011/08/30 20:04:43 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2011/08/30 19:39:58 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{833A504C-3BDB-40E1-AF95-CF093D8D467A}
[2011/08/30 19:39:48 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{CE03C475-0CF9-421F-BF4C-FB132DA98457}
[2011/08/29 19:26:42 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{138CA9CB-66A6-422D-BBBE-D3B9367A39C0}
[2011/08/29 19:26:30 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{AA5C035F-E2AA-4980-87DB-C34AE7583807}
[2011/08/28 21:33:52 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{B3FCE715-40E5-4951-A376-511534EED9EB}
[2011/08/28 21:33:41 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{EA4C729C-E394-4E5B-933A-7C85C2B71AB9}
[2011/08/28 11:41:51 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Roaming\Malwarebytes
[2011/08/28 11:41:43 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/08/28 11:41:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/08/28 11:41:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/08/28 11:41:38 | 000,025,912 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/08/28 09:33:15 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{D51F80AA-9F2A-4EAC-B587-F26979257B86}
[2011/08/28 09:33:03 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{B7D353E0-C9B1-4F58-B359-312DF7690B84}
[2011/08/27 20:32:36 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{671E52E2-D048-47D4-883C-08EE80BF6EEA}
[2011/08/27 20:32:26 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{3DDD0D53-7303-462A-82B0-0D581D9E04C4}
[2011/08/27 19:21:40 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011/08/27 18:33:29 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/08/27 17:53:54 | 000,000,000 | ---D | C] -- C:\combofix
[2011/08/27 16:38:01 | 000,000,000 | ---D | C] -- C:\Users\emudryj\Documents\Simply Super Software
[2011/08/27 14:10:05 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/08/27 14:10:03 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/08/27 14:10:03 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/08/27 14:08:59 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/08/27 14:06:07 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/08/27 10:08:08 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2011/08/27 10:06:32 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2011/08/27 08:31:57 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{1C1855F5-B7E5-4074-B1DD-03BDB227EC66}
[2011/08/27 08:31:46 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{56FB54D7-8B24-4635-9354-0D24A39A0A0D}
[2011/08/26 20:16:03 | 000,039,192 | ---- | C] (Greatis Software) -- C:\Windows\SysNative\Partizan.exe
[2011/08/26 20:12:14 | 000,000,000 | ---D | C] -- C:\Users\emudryj\Documents\RegRun2
[2011/08/26 19:59:39 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{1A676F33-EA47-4FA7-A75F-6BC44BD66C73}
[2011/08/26 19:59:29 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{5970D767-FC4A-4DDA-9754-CDA2CC3A8981}
[2011/08/25 19:33:44 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{89FFD2D4-7D66-499A-9EEC-7AE3E2EBCCB5}
[2011/08/25 19:33:33 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{05A24F1F-9E10-4C71-8309-BCC4E5013ED8}
[2011/08/24 18:36:42 | 000,000,000 | ---D | C] -- C:\temp
[2011/08/24 18:35:02 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{93156864-4CC9-430E-95D3-E728C9E82443}
[2011/08/24 18:34:22 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{12861F1F-7AD4-4D74-84DF-D8A196981274}
[2011/08/24 18:34:12 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{78BA2C21-6301-4667-BFF8-F2213FD9A916}
[2011/08/23 17:55:59 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{816CC18E-DE44-428B-8B8E-CAD19C9706E4}
[2011/08/23 17:55:49 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{D569C2C6-EC46-430C-948C-47FF10D909D1}
[2011/08/22 21:12:03 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{722139F9-8402-45E5-B6B3-2CF8BC5EDAC4}
[2011/08/22 21:11:52 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{D1FC845F-A83A-404A-9448-B3E93F44D921}
[2011/08/22 09:11:27 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{43618183-8B30-4593-8611-804E0835F6B7}
[2011/08/22 09:11:17 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{E2E3CC70-8825-442D-9B99-CB09A25B008A}
[2011/08/21 21:10:44 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{19BBC1DA-D43F-4A15-8A58-4D5D1C13D9D8}
[2011/08/21 21:10:34 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{F21D0F4C-3CC2-4236-8C3E-7BD5AD04C2A5}
[2011/08/21 09:10:09 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{AB5D0240-0DD1-4247-9522-581419D0543E}
[2011/08/21 09:09:59 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{EB3247BB-3BA2-4E2C-95F0-EB82CB46B89C}
[2011/08/20 20:26:42 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{4534A216-1C9E-4D29-B8B8-8479829689D1}
[2011/08/20 20:26:33 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{8D89AF09-1B0B-4BEE-807C-8EBCDD5D2C0A}
[2011/08/20 18:05:05 | 000,000,000 | ---D | C] -- C:\Users\emudryj\Desktop\ser web site
[2011/08/20 08:26:20 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{4A9B7B7A-F9B1-44DD-8AE0-5FCEAD374320}
[2011/08/20 08:26:11 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{07FB85D1-222A-4B82-BDDD-340F1311D072}
[2011/08/19 17:21:37 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{CC336946-30CA-42DD-8EA3-CF9EB175C7C3}
[2011/08/19 17:21:27 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{E93D4164-F7ED-48D5-BD5D-BDE0C28EE04E}
[2011/08/18 21:03:16 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{13E3C684-CA53-47D0-81CF-6DA3A99FDE18}
[2011/08/18 21:03:07 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{296CE4B0-8C43-4DE7-9000-3ABAAD5DBED7}
[2011/08/18 21:03:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/08/17 20:05:42 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{703D44F2-5719-437B-9DDC-A95426E1E912}
[2011/08/17 20:05:33 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{3F6E0CB2-C38F-4B38-9DD7-FB68B7F4B8EA}
[2011/08/16 20:55:52 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{8BCC0D2D-DECB-4194-B6A1-0ED2B23AAB72}
[2011/08/16 20:55:43 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{58873267-F4AA-4635-AAA5-2624C5D5587C}
[2011/08/16 08:36:12 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{CD1DA322-D402-4F08-AD84-407AA93B03F3}
[2011/08/16 08:36:02 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{978C120A-8020-4D03-9CF0-01377FB25292}
[2011/08/15 19:28:22 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{11FAFA4D-262C-4C62-81CF-90FEAF96EC30}
[2011/08/15 19:28:12 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{FB617148-1A4E-423B-A422-9EE898F5983D}
[2011/08/14 21:23:16 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{F8AFFF45-B015-42B7-ADEF-30CC69955144}
[2011/08/14 21:23:06 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{300FDB03-0D51-4FE1-A10C-40392D98724A}
[2011/08/14 09:22:41 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{2D8453F1-CFD1-4741-8263-204B1E1F00FA}
[2011/08/14 09:22:30 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{3FC2C278-66BA-43CC-8BF9-D523ED3B765F}
[2011/08/13 21:22:06 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{3C1D5EA0-F12C-4AAB-8B81-3D92905492AD}
[2011/08/13 21:21:56 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{69A39909-71F5-4F17-8F5F-31FB6757203C}
[2011/08/13 09:21:31 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{9471C865-8E17-4126-B7B2-86A9996E093A}
[2011/08/13 09:21:21 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{15B1B5CA-FA05-4D2D-89A4-93D9834E6540}
[2011/08/12 21:20:56 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{6AF20D7F-E605-4C81-A927-7A9FA91817B3}
[2011/08/12 21:20:47 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{EF4C1539-ED27-439C-B302-1F105B964FD0}
[2011/08/11 20:10:02 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{CB5CA58F-7AAF-420E-A309-0D638D0641A2}
[2011/08/11 20:09:51 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{8511E3B9-58C4-4F66-8A81-12C568E22A78}
[2011/08/11 08:10:14 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011/08/11 08:10:14 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011/08/11 08:10:13 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011/08/11 08:10:13 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011/08/11 08:10:12 | 002,303,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2011/08/11 08:10:12 | 000,818,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011/08/11 08:10:12 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011/08/11 08:10:12 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2011/08/11 08:10:12 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2011/08/11 08:09:27 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{E2DD06A1-D482-4394-9AD2-15D2BB81AD20}
[2011/08/11 08:09:17 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{F549E533-29AC-4102-943D-ED0876D50F2E}
[2011/08/10 15:54:19 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xmllite.dll
[2011/08/10 15:54:16 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbcjt32.dll
[2011/08/10 15:54:16 | 000,212,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbctrac.dll
[2011/08/10 15:54:16 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbctrac.dll
[2011/08/10 15:54:16 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccp32.dll
[2011/08/10 15:54:16 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccp32.dll
[2011/08/10 15:54:16 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccu32.dll
[2011/08/10 15:54:16 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccr32.dll
[2011/08/10 15:54:16 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccu32.dll
[2011/08/10 15:54:16 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccr32.dll
[2011/08/10 15:53:55 | 001,162,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2011/08/10 15:53:55 | 000,421,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2011/08/10 15:53:55 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
[2011/08/10 15:53:55 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2011/08/10 15:53:55 | 000,214,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2011/08/10 15:53:54 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2011/08/10 15:53:54 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2011/08/10 15:53:54 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2011/08/10 15:53:54 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2011/08/10 15:53:54 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2011/08/10 15:53:54 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2011/08/10 15:53:54 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2011/08/10 15:53:54 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2011/08/10 15:53:54 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2011/08/10 15:53:54 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2011/08/10 15:53:54 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2011/08/10 15:53:54 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2011/08/10 15:53:54 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/08/10 15:53:54 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/08/10 15:53:54 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2011/08/10 15:53:54 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2011/08/10 15:53:54 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2011/08/10 15:53:54 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2011/08/10 15:53:54 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2011/08/10 15:53:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/08/10 15:53:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/08/10 15:53:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2011/08/10 15:53:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2011/08/10 15:53:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2011/08/10 15:53:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2011/08/10 15:53:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2011/08/10 15:53:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/08/10 15:53:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2011/08/10 15:53:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2011/08/10 15:53:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/08/10 15:53:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2011/08/10 15:53:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2011/08/10 15:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2011/08/10 15:53:52 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2011/08/10 15:53:52 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2011/08/10 15:53:52 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2011/08/10 15:53:52 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2011/08/10 15:53:52 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2011/08/10 15:53:52 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2011/08/10 15:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2011/08/10 15:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2011/08/10 15:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2011/08/10 15:53:52 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2011/08/10 15:53:44 | 003,912,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2011/08/10 15:53:43 | 005,561,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2011/08/10 15:53:43 | 003,967,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2011/08/10 15:51:17 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{A5C7AC12-4376-4AC0-9A7A-6D65E910463C}
[2011/08/10 15:51:07 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{8840D864-E69B-414C-A963-3C7C87E7D03A}
[2011/08/09 21:10:04 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{82CC22D7-A14C-4FCC-8099-9E7B6F6C71DF}
[2011/08/09 21:09:54 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{8CD282E1-CAE3-4F12-9A1A-77B9A2B09FFA}
[2011/08/09 09:09:42 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{E2B75514-6F97-4448-A8FF-EF1B9E979760}
[2011/08/09 09:09:32 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{2AB93BBA-2177-40E6-86F3-B2AE5DBA4185}
[2011/08/08 19:17:12 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{50E87774-1190-40B5-8F14-9C397247887D}
[2011/08/08 19:17:02 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{6A194DC0-F131-45BD-B715-7159699ACE68}
[2011/08/08 00:24:26 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{44E6B8D4-22CD-418F-85A7-F8DB1725644C}
[2011/08/08 00:24:16 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{C79CCD31-C08F-4DA4-8533-1859DF532927}
[2011/08/07 12:23:50 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{1E2060F7-CF7A-4B31-85EC-A52A396C6F7D}
[2011/08/07 12:23:40 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{EDB99DEA-E23B-4074-BE43-A213F092F4D8}
[2011/08/06 23:58:37 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{174B67DB-B973-40E4-A261-C3DF223DA543}
[2011/08/06 23:58:27 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{A1047251-1F7B-4C4E-A313-A1B95D92A1A8}
[2011/08/06 11:57:53 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{11D119DD-DD7C-4261-849D-515BCF11F3D8}
[2011/08/06 11:57:43 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{E5859E1E-620A-47EB-A590-F4AC000EBBD1}
[2011/08/05 21:56:36 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{62D886A8-FE39-4E49-A01C-B51AB07B664C}
[2011/08/05 21:56:26 | 000,000,000 | ---D | C] -- C:\Users\emudryj\AppData\Local\{EB316BC4-BEB7-4B23-A33B-BB2EFD69EB10}

========== Files - Modified Within 30 Days ==========

[2011/09/04 10:53:04 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\emudryj\Desktop\OTL.exe
[2011/09/04 10:52:04 | 000,001,739 | ---- | M] () -- C:\Users\emudryj\Desktop\MySyncFolder.lnk
[2011/09/04 10:51:53 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/09/04 10:48:01 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/04 09:36:52 | 000,010,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/04 09:36:52 | 000,010,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/04 09:35:48 | 001,563,690 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/09/04 09:35:48 | 000,706,104 | ---- | M] () -- C:\Windows\SysNative\perfh00A.dat
[2011/09/04 09:35:48 | 000,628,658 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/09/04 09:35:48 | 000,138,638 | ---- | M] () -- C:\Windows\SysNative\perfc00A.dat
[2011/09/04 09:35:48 | 000,107,964 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/09/04 09:33:43 | 000,001,828 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Internet Security.lnk
[2011/09/04 09:31:41 | 000,000,374 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.ics
[2011/09/04 09:31:34 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/09/04 09:31:33 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\drivers\lvuvc.hs
[2011/09/04 09:31:30 | 529,903,615 | -HS- | M] () -- C:\hiberfil.sys
[2011/09/03 23:26:09 | 000,271,200 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2011/09/03 23:26:09 | 000,271,200 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/09/03 23:19:06 | 000,271,200 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2011/09/03 23:11:15 | 001,406,768 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\emudryj\Desktop\tdsskiller(1).exe
[2011/09/03 23:09:26 | 000,001,088 | ---- | M] () -- C:\Users\emudryj\Desktop\BFBC2Game.exe - Shortcut.lnk
[2011/09/03 20:33:53 | 002,434,856 | ---- | M] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
[2011/09/03 19:53:15 | 530,414,235 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/09/03 15:53:46 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011/09/03 14:49:47 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011/09/03 13:48:40 | 000,002,344 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2011/09/02 22:16:13 | 000,000,000 | ---- | M] () -- C:\Users\emudryj\defogger_reenable
[2011/08/30 20:06:22 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/08/29 21:36:28 | 000,001,447 | ---- | M] () -- C:\Users\emudryj\Desktop\Internet Explorer.lnk
[2011/08/28 22:26:22 | 000,418,216 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/08/28 11:41:43 | 000,000,745 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/08/27 16:28:20 | 001,601,284 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/08/27 10:08:31 | 002,062,158 | ---- | M] () -- C:\Windows\SysNative\drivers\Cat.DB
[2011/08/27 02:32:05 | 000,000,750 | ---- | M] () -- C:\Users\emudryj\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/08/26 20:16:03 | 000,039,192 | ---- | M] (Greatis Software) -- C:\Windows\SysNative\Partizan.exe
[2011/08/26 20:12:15 | 000,000,002 | RHS- | M] () -- C:\Windows\winstart.bat
[2011/08/26 20:12:15 | 000,000,002 | RHS- | M] () -- C:\Windows\SysWow64\CONFIG.NT
[2011/08/26 20:12:15 | 000,000,002 | RHS- | M] () -- C:\Windows\SysWow64\AUTOEXEC.NT
[2011/08/24 20:27:11 | 000,047,694 | ---- | M] () -- C:\Users\emudryj\Desktop\2011_IM_Factura_28.jpg
[2011/08/24 19:31:07 | 000,062,133 | ---- | M] () -- C:\Users\emudryj\Desktop\Autorizaciones.jpg
[2011/08/19 08:29:49 | 000,001,238 | ---- | M] () -- C:\Users\Public\Desktop\ASUS WebStorage.lnk
[2011/08/18 21:03:06 | 000,002,515 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk

========== Files Created - No Company Name ==========

[2011/09/03 23:09:29 | 000,001,088 | ---- | C] () -- C:\Users\emudryj\Desktop\BFBC2Game.exe - Shortcut.lnk
[2011/09/03 20:33:53 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
[2011/09/03 09:15:51 | 530,414,235 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/09/02 22:16:13 | 000,000,000 | ---- | C] () -- C:\Users\emudryj\defogger_reenable
[2011/08/29 21:36:28 | 000,001,447 | ---- | C] () -- C:\Users\emudryj\Desktop\Internet Explorer.lnk
[2011/08/28 22:26:11 | 000,418,216 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/08/28 11:41:43 | 000,000,745 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/08/27 17:04:27 | 000,302,592 | ---- | C] () -- C:\Users\emudryj\Desktop\gmer.exe
[2011/08/27 16:29:35 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
[2011/08/27 14:10:05 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/08/27 14:10:03 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/08/27 14:10:03 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/08/27 14:10:03 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/08/27 14:10:03 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/08/27 10:08:20 | 002,062,158 | ---- | C] () -- C:\Windows\SysNative\drivers\Cat.DB
[2011/08/26 20:12:15 | 000,000,002 | RHS- | C] () -- C:\Windows\winstart.bat
[2011/08/26 20:12:15 | 000,000,002 | RHS- | C] () -- C:\Windows\SysWow64\CONFIG.NT
[2011/08/26 20:12:15 | 000,000,002 | RHS- | C] () -- C:\Windows\SysWow64\AUTOEXEC.NT
[2011/08/24 20:27:04 | 000,047,694 | ---- | C] () -- C:\Users\emudryj\Desktop\2011_IM_Factura_28.jpg
[2011/08/24 19:30:54 | 000,062,133 | ---- | C] () -- C:\Users\emudryj\Desktop\Autorizaciones.jpg
[2011/08/18 21:03:06 | 000,002,515 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2011/08/14 13:02:12 | 000,271,200 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/07/17 14:34:43 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/05/25 22:09:51 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011/05/25 19:54:14 | 001,601,284 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/25 19:49:45 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/05/25 18:54:25 | 000,000,028 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/05/24 10:30:17 | 000,000,990 | ---- | C] () -- C:\Users\emudryj\AppData\Local\7F68A003.il
[2011/05/24 10:30:17 | 000,000,832 | ---- | C] () -- C:\Users\emudryj\AppData\Local\IndexIE_7F68A003.il
[2011/04/01 05:07:02 | 010,877,272 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2011/04/01 05:07:02 | 000,102,744 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2011/04/01 05:06:56 | 000,331,608 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2011/01/11 18:05:18 | 000,008,592 | ---- | C] () -- C:\Windows\SysWow64\ractrlkeyhook.dll
[2009/09/09 21:48:52 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/05/29 16:52:26 | 000,204,800 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2009/05/29 16:47:06 | 000,881,664 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2009/02/26 02:50:32 | 000,000,176 | ---- | C] () -- C:\Windows\explorer.exe.config
[2007/09/04 12:56:10 | 000,164,352 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2007/02/05 20:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI

========== Alternate Data Streams ==========

@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:CB0AACC9
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >

#9 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:37 AM

Posted 04 September 2011 - 12:28 PM

Hello

I want you to run this custem OTL script for me and then let me know how things are after you finish.

Run OTL Script

  • Double-click OTL.exe to start the program.
  • Copy and Paste the following code into the Posted Image textbox. Do not include the word Code
    :otl
    IE - HKU\S-1-5-21-3999918964-3837148993-3667228684-1000\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - Reg Error: Key error. File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_0_1.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
    O4 - HKU\S-1-5-21-3999918964-3837148993-3667228684-1003..\RunOnce: [mctadmin] File not found
    O18:64bit: - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
    O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - Reg Error: Key error. - c:\Program Files\Common Files\logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
    @Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:CB0AACC9
    @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:DFC5A2B2
    FF - prefs.js..browser.search.defaultthis.engineName: " "
    FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}"
    FF - prefs.js..browser.search.selectedEngine: " "
    FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q="
    [2011/05/26 21:22:02 | 000,000,000 | ---D | M] (Freecorder Toolbar) -- C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}
    [2011/08/08 08:15:26 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
    [2011/05/29 15:59:48 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\engine@conduit.com
    [2011/06/20 14:07:48 | 000,000,863 | ---- | M] () -- C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\searchplugins\conduit.xml
    :Files
    ipconfig /flushdns /c
    :Commands
    [PURITY] 
    [EMPTYTEMP]
    [EMPTYFLASH]
    [RESETHOSTS] 
    
  • Then click the Run Fix button at the top.
  • Click Posted Image.
  • OTL may ask to reboot the machine. Please do so if asked.
  • The report should appear in Notepad after the reboot.Copy and Paste that report in your next reply.

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#10 emudryj

emudryj
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:11:37 AM

Posted 04 September 2011 - 01:46 PM

All processes killed
========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-3999918964-3837148993-3667228684-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{472734EA-242A-422b-ADF8-83D1E48CC825} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422b-ADF8-83D1E48CC825}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-3999918964-3837148993-3667228684-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\bwfile-8876480\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9462A756-7B47-47BC-8C80-C34B9B80B32B}\ not found.
File {9462A756-7B47-47BC-8C80-C34B9B80B32B} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ not found.
File {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ not found.
File {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype-ie-addon-data\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91774881-D725-4E58-B298-07617B9B86A8}\ not found.
File {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03C514A3-1EFB-4856-9F99-10D7BE1653C0}\ not found.
File {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324}\ not found.
File {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{314111c7-a502-11d2-bbca-00c04f8ec294}\ not found.
File {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn\ deleted successfully.
c:\Program Files\Common Files\logishrd\Bluetooth\LBTWLgn.dll moved successfully.
ADS C:\ProgramData\TEMP:CB0AACC9 deleted successfully.
ADS C:\ProgramData\TEMP:DFC5A2B2 deleted successfully.
Prefs.js: " " removed from browser.search.defaultthis.engineName
Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl
Prefs.js: " " removed from browser.search.selectedEngine
Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q=" removed from keyword.URL
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\components folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\searchbar folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\options folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib\weatherbutton\panels\images folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib\weatherbutton\panels folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib\weatherbutton\icons folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib\weatherbutton folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib\uwa folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib\radio\images folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib\radio\css folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib\radio folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib\panels\images folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib\panels\default\scripts folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib\panels\default\images folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib\panels\default\css folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib\panels\default folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib\panels\css folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib\panels folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib\debugbar folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin\lib folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\skin folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\data\weather folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\data\search folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\data\rss folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\data\dynamicElements folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\data folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\content\widgets\net.vmn.www.WebTV\skin\scripts folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\content\widgets\net.vmn.www.WebTV\skin\images folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\content\widgets\net.vmn.www.WebTV\skin\css folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\content\widgets\net.vmn.www.WebTV\skin folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\content\widgets\net.vmn.www.WebTV\js folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\content\widgets\net.vmn.www.WebTV\images folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\content\widgets\net.vmn.www.WebTV\css folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\content\widgets\net.vmn.www.WebTV folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\content\widgets folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\content\newtab\images folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\content\newtab folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\content\modules folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\content\lib folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome\content folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c}\chrome folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{70dd86e8-b5bc-4e4a-9d5c-b6234c24323c} folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\META-INF folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\chrome folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\engine@conduit.com\searchplugin folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\engine@conduit.com\META-INF folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\engine@conduit.com\lib folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\engine@conduit.com\DualPackage folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\engine@conduit.com\defaults folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\engine@conduit.com\components folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\engine@conduit.com\chrome folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\extensions\engine@conduit.com folder moved successfully.
C:\Users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\searchplugins\conduit.xml moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\emudryj\Desktop\cmd.bat deleted successfully.
C:\Users\emudryj\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56466 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: emudryj
->Temp folder emptied: 317914 bytes
->Temporary Internet Files folder emptied: 168213280 bytes
->Java cache emptied: 184018 bytes
->FireFox cache emptied: 42813506 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 67235 bytes

User: Public
->Temp folder emptied: 0 bytes

User: TEMP

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56466 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 33687 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 202.00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: emudryj
->Flash cache emptied: 0 bytes

User: Public

User: TEMP

User: UpdatusUser
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.27.0 log created on 09042011_144122

Files\Folders moved on Reboot...
C:\Users\emudryj\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat scheduled to be moved on reboot.
File\Folder C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VRBIBUZJ\54477947514535694b5634414477432f[1].htm not found!
File\Folder C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VRBIBUZJ\ddc[2].htm not found!
File\Folder C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VRBIBUZJ\fw-nonplayer-banner[7].htm not found!
File\Folder C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VRBIBUZJ\fw-nonplayer-banner[8].htm not found!
File\Folder C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VRBIBUZJ\fw-nonplayer-banner[9].htm not found!
File\Folder C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6XZZ0WXC\cory-lamb-it-s-a-good-day[1].htm not found!
File\Folder C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6XZZ0WXC\ddc[2].htm not found!
C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6XZZ0WXC\emily[3].htm moved successfully.
File\Folder C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5L7XJXWN\data_sync[1].htm not found!
File\Folder C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1VEB24M2\01[1].htm not found!
File\Folder C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1VEB24M2\adholder[1].htm not found!
File\Folder C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1VEB24M2\adholder[2].htm not found!
C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1VEB24M2\fw-nonplayer-banner[2].htm moved successfully.
File\Folder C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1VEB24M2\if[1].htm not found!
File\Folder C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1VEB24M2\x1743[1].htm not found!
C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1VEB24M2\x3-steve-jobs-resigns[1].htm moved successfully.
File\Folder C:\Users\emudryj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1VEB24M2\xd_receiver[2].htm not found!
File\Folder C:\Windows\temp\nsd_tmp_2296.tmp not found!

Registry entries deleted on Reboot...

#11 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:37 AM

Posted 04 September 2011 - 02:19 PM

How are things doing now?



gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#12 emudryj

emudryj
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:11:37 AM

Posted 04 September 2011 - 09:37 PM

not good.... I was ready to claim "mission accomplished" but all the sudden the Malwarebytes started blocking the re-directs for iexplorer AGAIN!!!!
tried a couple of common searches and I got the redirect at the second tried...


It's driving me nuts...

Is it possible that I may have it somewhere on my machine and is RE-infecting me every time that we clean it???

#13 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:37 AM

Posted 04 September 2011 - 09:55 PM

Hello

I would like you to download an updated version of combofix.

update combofix

Delete the version of combofix you have now on your desktop and download a new one from here

Link 1
Link 2
Link 3
**Note: It is important that it is saved directly to your desktop**

1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note:Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer
[/list]
"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#14 emudryj

emudryj
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:11:37 AM

Posted 05 September 2011 - 09:29 AM

OK. First tried running the new combofix did not fished extracting all the files.
I tried a second time and It went thru extracting, but the little blue administrator windows never came up... It usually takes a little of time but I wait for 2 and a half hs and did not showed up.
shutdown computer, went to sleep, tried again this morning.
It went fine.
The only thing worth to mention is that when the Combofix re-booted and the computer came back up, I started getting all this ads coming on my speakers.... nothing was running but I was getting like 10 advertisements going on at the same time on the speaker.
I looked in the volume mixer and it seem to be coming from iexporer.exe... but there was no IE window running at all. I brought up Malwarebytes and it seems to have stooped it.
Anyway here is the combofix log.

ComboFix 11-09-05.02 - emudryj 09/05/2011 9:19.4.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.6135.4044 [GMT -4:00]
Running from: c:\users\emudryj\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-08-05 to 2011-09-05 )))))))))))))))))))))))))))))))
.
.
2011-09-05 13:50 . 2011-09-05 13:50 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2011-09-05 13:50 . 2011-09-05 13:50 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-09-04 18:41 . 2011-09-04 18:41 -------- d-----w- C:\_OTL
2011-09-04 13:33 . 2011-09-04 18:41 -------- d-----w- c:\users\TEMP
2011-09-04 00:33 . 2011-09-04 00:33 2434856 ----a-w- c:\windows\SysWow64\pbsvc_bc2.exe
2011-09-03 20:13 . 2011-08-16 12:48 8862544 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2BBEE387-51BB-43F9-8A96-3B70033E3FAE}\mpengine.dll
2011-09-03 19:12 . 2011-09-03 20:14 -------- d-----w- C:\arreglacombo
2011-09-03 18:51 . 2011-09-03 18:51 -------- d-----w- c:\users\emudryj\AppData\Local\wj32
2011-08-31 00:04 . 2011-08-31 00:04 -------- d-----w- c:\windows\system32\Macromed
2011-08-28 15:41 . 2011-08-28 15:41 -------- d-----w- c:\users\emudryj\AppData\Roaming\Malwarebytes
2011-08-28 15:41 . 2011-07-06 23:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-28 15:41 . 2011-08-28 15:41 -------- d-----w- c:\programdata\Malwarebytes
2011-08-28 15:41 . 2011-07-06 23:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-27 23:21 . 2011-08-27 23:21 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-08-27 14:06 . 2011-08-27 14:19 -------- d-----w- c:\programdata\PC Tools
2011-08-27 00:16 . 2011-08-27 00:16 39192 ----a-w- c:\windows\system32\Partizan.exe
2011-08-27 00:12 . 2011-08-27 00:12 2 --shatr- c:\windows\winstart.bat
2011-08-24 22:36 . 2011-08-24 22:36 -------- d-----w- C:\temp
2011-08-24 22:35 . 2011-07-09 05:26 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-24 22:35 . 2011-07-09 04:29 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-08-24 22:35 . 2011-08-24 22:35 -------- d-----w- c:\users\emudryj\AppData\Local\{93156864-4CC9-430E-95D3-E728C9E82443}
2011-08-14 17:02 . 2011-09-05 02:46 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-08-10 19:53 . 2011-07-16 05:41 243200 ----a-w- c:\windows\system32\wow64.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-05 02:46 . 2011-07-22 00:02 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-09-05 02:39 . 2011-07-17 18:34 271200 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2011-08-31 00:06 . 2011-06-27 17:53 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-05 03:52 . 2011-08-05 03:52 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-07-21 23:57 . 2011-07-17 18:34 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-07-19 21:08 . 2011-05-26 02:20 87456 ----a-w- c:\windows\system32\LMIRfsClientNP.dll.000.bak
2011-07-19 21:08 . 2011-05-26 02:20 87456 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-07-19 21:08 . 2011-05-26 02:20 33152 ----a-w- c:\windows\system32\LMIport.dll
2011-07-19 21:08 . 2011-05-26 02:20 80768 ----a-w- c:\windows\system32\LMIinit.dll
2011-07-16 04:26 . 2011-08-10 19:53 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-07-14 03:26 . 2011-07-14 03:26 53248 ----a-r- c:\users\emudryj\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-07-14 03:26 . 2011-07-14 03:26 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-06-11 03:07 . 2011-07-12 23:53 3137536 ----a-w- c:\windows\system32\win32k.sys
2011-06-10 10:34 . 2011-06-10 10:34 74272 ----a-w- c:\windows\system32\RtNicProp64.dll
2011-06-10 10:34 . 2011-06-10 10:34 539240 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
.
.
((((((((((((((((((((((((((((( SnapShot_2011-09-03_19.54.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-24 15:28 . 2011-09-05 13:56 58398 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-09-05 13:56 34896 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:30 . 2011-07-14 04:56 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2009-07-14 05:30 . 2011-09-04 16:26 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2011-06-10 10:34 . 2011-06-10 10:34 74272 c:\windows\system32\DriverStore\FileRepository\cf64win7.inf_amd64_neutral_91cc4efffd053e93\RtNicProp64.dll
- 2011-05-24 09:21 . 2011-09-03 19:53 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-05-24 09:21 . 2011-09-05 13:53 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-05-24 09:21 . 2011-09-03 19:53 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-05-24 09:21 . 2011-09-05 13:53 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-09-03 19:53 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-09-05 13:53 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:46 . 2011-09-04 18:49 88528 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2011-09-04 00:09 . 2011-09-04 00:09 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2011-07-17 18:32 . 2011-07-17 18:32 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2011-07-17 18:32 . 2011-07-17 18:32 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2011-05-26 07:17 . 2011-09-02 02:49 4356 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2011-05-26 07:17 . 2011-09-05 03:02 4356 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2011-05-24 14:31 . 2011-09-05 13:08 8314 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3999918964-3837148993-3667228684-1000_UserData.bin
- 2011-09-03 19:53 . 2011-09-03 19:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-09-05 13:53 . 2011-09-05 13:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-09-05 13:53 . 2011-09-05 13:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-09-03 19:53 . 2011-09-03 19:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-05-24 15:26 . 2011-09-03 18:57 706104 c:\windows\system32\perfh00A.dat
+ 2011-05-24 15:26 . 2011-09-05 13:12 706104 c:\windows\system32\perfh00A.dat
+ 2009-07-14 02:36 . 2011-09-05 13:12 628658 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2011-09-03 18:57 628658 c:\windows\system32\perfh009.dat
- 2011-05-24 15:26 . 2011-09-03 18:57 138638 c:\windows\system32\perfc00A.dat
+ 2011-05-24 15:26 . 2011-09-05 13:12 138638 c:\windows\system32\perfc00A.dat
+ 2009-07-14 02:36 . 2011-09-05 13:12 107964 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2011-09-03 18:57 107964 c:\windows\system32\perfc009.dat
+ 2011-05-24 14:32 . 2011-05-24 23:14 270720 c:\windows\system32\MpSigStub.exe
- 2011-05-24 14:32 . 2010-10-19 20:51 270720 c:\windows\system32\MpSigStub.exe
- 2009-07-14 05:30 . 2011-07-14 04:56 239616 c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 05:30 . 2011-09-04 16:26 239616 c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 05:30 . 2011-09-04 16:26 143360 c:\windows\system32\DriverStore\infstor.dat
- 2009-07-14 05:30 . 2011-07-14 04:53 143360 c:\windows\system32\DriverStore\infstor.dat
+ 2011-06-10 10:34 . 2011-06-10 10:34 539240 c:\windows\system32\DriverStore\FileRepository\cf64win7.inf_amd64_neutral_91cc4efffd053e93\Rt64win7.sys
- 2009-07-14 05:01 . 2011-09-03 19:52 389820 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-09-05 13:52 389820 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2011-07-17 18:32 . 2011-07-17 18:32 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2011-07-17 18:32 . 2011-07-17 18:32 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2011-07-17 18:32 . 2011-07-17 18:32 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2011-07-17 18:32 . 2011-07-17 18:32 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2011-07-17 18:32 . 2011-07-17 18:32 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-17 18:32 . 2011-07-17 18:32 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-17 18:32 . 2011-07-17 18:32 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-17 18:32 . 2011-07-17 18:32 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-17 18:32 . 2011-07-17 18:32 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-17 18:32 . 2011-07-17 18:32 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-17 18:32 . 2011-07-17 18:32 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-17 18:32 . 2011-07-17 18:32 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-17 18:32 . 2011-07-17 18:32 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2011-07-17 18:32 . 2011-07-17 18:32 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2009-07-14 04:45 . 2011-09-04 18:39 5981465 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
- 2009-07-14 04:45 . 2011-08-25 22:57 5981465 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2010-02-10 02:55 . 2010-02-10 02:55 9965568 c:\windows\Installer\d2af1.msi
+ 2011-04-16 12:44 . 2011-04-16 12:44 2770944 c:\windows\Installer\9fdc2a.msi
+ 2011-09-04 00:20 . 2011-09-04 00:20 1693048 c:\windows\Installer\{3AC8457C-0385-4BEA-A959-E095F05D6D67}\BFBC2Updater.exe
- 2011-07-17 18:32 . 2011-07-17 18:32 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-17 18:32 . 2011-07-17 18:32 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-04 00:09 . 2011-09-04 00:09 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-05-25 23:57 . 2011-09-05 13:52 28327756 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3999918964-3837148993-3667228684-1000-12288.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"BCWipeTM Startup"="c:\program files (x86)\Jetico\BCWipe\BCWipeTM.exe" [2008-09-04 545520]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"ASUS Sync Loader"="c:\program files (x86)\ASUS\ASUS Sync\asusUPCTLoader.exe" [2011-05-11 638976]
"ASUSWebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe" [2011-08-17 737104]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-06-28 1486392]
"Malwarebytes' Anti-Malware"="d:\programs\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2011-7-14 66864]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-08 136176]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [x]
R3 DrvSnSht;DrvSnSht;c:\program files (x86)\R-Drive Image\DrvSnSht64.sys [2010-06-01 132432]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-08 136176]
R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x]
R3 LVUVC64;Logitech Webcam Pro 9000(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;d:\programs\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 51445112]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-10 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 R-ImageDisk;R-ImageDisk;c:\program files (x86)\R-Drive Image\R-ImageDisk64.sys [2010-10-16 187600]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 RemoteControl-USBLAN;RemoteControl-USBLAN;c:\windows\system32\DRIVERS\rcblan.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x]
R3 Synth3dVsc;Synth3dVsc; [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub; [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 VGPU;VGPU; [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 BCSWAP;BCSWAP; [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [x]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x]
S1 MOBK755Filter;MOBK755Filter;c:\windows\system32\DRIVERS\MOBK755.sys [x]
S2 LMIGuardianSvc;LMIGuardianSvc;d:\programs\LogMeIn\x64\LMIGuardianSvc.exe [2011-07-19 375176]
S2 LMIInfo;LogMeIn Kernel Information Provider;d:\programs\LogMeIn\x64\RaInfo.sys [2010-09-17 15928]
S2 Lotus Notes Diagnostics;Lotus Notes Diagnostics;d:\programs\IBM\Lotus\Notes\nsd.exe [2010-08-11 3417480]
S2 MBAMService;MBAMService;d:\programs\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-04-14 245352]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x]
S2 MOBK755backup;McAfee Online Backup Service;c:\program files (x86)\McAfee Online Backup\MOBK755backup.exe [2010-09-20 207672]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504]
S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2011-04-01 428640]
S2 UsbClientService;UsbClientService;d:\programs\Assistant\UsbClientService.exe [2011-02-18 245760]
S3 busenum;Synology Virtual USB Hub;c:\windows\system32\DRIVERS\busenum.sys [x]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-08 02:33]
.
2011-09-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-08 02:33]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2011-05-25 07:09 227840 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2011-05-25 07:09 227840 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK755]
@="{f378ff85-8d0a-cbe6-4735-3a67760db6bb}"
[HKEY_CLASSES_ROOT\CLSID\{f378ff85-8d0a-cbe6-4735-3a67760db6bb}]
2010-09-20 07:27 4718392 ----a-w- c:\program files (x86)\McAfee Online Backup\MOBK755shell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK7552]
@="{8406002f-3c7e-565d-de02-414c2856a50b}"
[HKEY_CLASSES_ROOT\CLSID\{8406002f-3c7e-565d-de02-414c2856a50b}]
2010-09-20 07:27 4718392 ----a-w- c:\program files (x86)\McAfee Online Backup\MOBK755shell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK7553]
@="{cb5494dd-88ee-383e-88d7-bbd79c7c52d4}"
[HKEY_CLASSES_ROOT\CLSID\{cb5494dd-88ee-383e-88d7-bbd79c7c52d4}]
2010-09-20 07:27 4718392 ----a-w- c:\program files (x86)\McAfee Online Backup\MOBK755shell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-09-11 8114720]
"LogMeIn GUI"="d:\programs\LogMeIn\x64\LogMeInSystray.exe" [2010-09-17 57928]
"BCSSync"="d:\programs\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 112512]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-06-23 1744152]
"Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2010-08-03 415816]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2010-08-03 2412616]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2010-08-03 4725320]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - d:\programs\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - d:\programs\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 205.152.144.23 205.152.132.23
FF - ProfilePath - c:\users\emudryj\AppData\Roaming\Mozilla\Firefox\Profiles\jhv7mm9q.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine -
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_bc2.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11a_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11a_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11a.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11a.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11a.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11a.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
d:\programs\IBM\Lotus\Notes\ntmulti.exe
c:\windows\SysWOW64\rundll32.exe
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Completion time: 2011-09-05 10:14:49 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-05 14:14
ComboFix2.txt 2011-09-03 20:13
ComboFix3.txt 2011-08-27 22:57
ComboFix4.txt 2011-08-27 19:14
.
Pre-Run: 62,041,841,664 bytes free
Post-Run: 61,711,839,232 bytes free
.
- - End Of File - - EDCCE2E8B96B6D8F533D1931C26FF1FE

#15 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:37 AM

Posted 06 September 2011 - 02:27 PM

Hello

:P2P Warning!:

IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

Please note that as long as you are using any form of Peer-to-Peer networking and downloading files from non-documented sources, you can expect infestations of malware to occur
Once upon a time, P2P file sharing was fairly safe. That is no longer true. P2P programs form a direct conduit on to your computer, their security measures are easily circumvented and malware writers are increasingly exploiting them to spread their wares on to your computer. Further to that, if your P2P program is not configured correctly, your computer may be sharing more files than you realise. There have been cases where people's passwords, address books and other personal, private, and financial details have been exposed to a file sharing network by a badly configured program.

Please read these short reports on the dangers of peer-2-peer programs and file sharing.

FBI Cyber Education Letter
File sharing infects 500,000 computers
USAToday
infoworld


These logs are looking alot better. But we still have some work to do.

Please print out these instructions, or copy them to a Notepad file. It will make it easier for you to follow the instructions and complete all of the necessary steps..

uninstall some programs

1. click on start
2. then go to settings
3. after that you need control panel
4. look for the icon add/remove programs
click on the following programs

Adobe Reader 9.1

and click on remove

Update Adobe Reader

Recently there have been vunerabilities detected in older versions of Adobe Reader. It is strongly suggested that you update to the current version.

You can download it from http://www.adobe.com/products/acrobat/readstep2.html
After installing the latest Adobe Reader, uninstall all previous versions.
If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

If you don't like Adobe Reader (53 MB), you can download Foxit PDF Reader(7 MB) from here. It's a much smaller file to download and uses a lot less resources than Adobe Reader.

Note: When installing FoxitReader, be carefull not to install anything to do with AskBar.
[/list]
Your Java is out of date.

It can be updated by the Java control panel
  • click on Start-> Control Panel (Classic View)-> Java (looks like a coffee cup) -> Update Tab -> Update Now.
  • An update should begin;
  • follow the prompts

Clear your Java Cache

  • click on Start-> Control Panel (Classic View)-> Java (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH Checked
      Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.

TFC(Temp File Cleaner):

  • Please download TFC to your desktop,
  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program.
  • If prompted, click "Yes" to reboot.
Note: Save your work. TFC will automatically close any open programs, let it run uninterrupted. It shouldn't take longer take a couple of minutes, and may only take a few seconds. Only if needed will you be prompted to reboot.

: Malwarebytes' Anti-Malware :

  • I would like you to rerun MBAM
  • Double-click mbam icon
  • go to the update tab at the top
  • click on check for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is Checked (ticked) except items in the C:\System Volume Information folder and click on Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply
  • If you accidently close it, the log file is saved here and will be named like this:
  • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


Download HijackThis

  • Go Here to download HijackThis Installer
  • Save HijackThis Installer to your desktop.
  • Double-click on the HijackThis Installer icon on your desktop. (Vista and Win 7 right click and run as admin)
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.
  • Once installed it will launch Hijackthis.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on Edit > Select All then click on Edit > Copy to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT use the AnalyseThis button its findings are dangerous if misinterpreted.
  • DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

If you have problems running Hijackthis.

sometimes we have to run it like this To run HijackThis as an administrator,
rightclick HijackThis.exe (located: C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe)
and select to run as administrator

"information and logs"

  • In your next post I need the following

  • Log From MBAM
  • report from Hijackthis
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users