Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Something has infected every PC on my network, I'm at my whit's end


  • This topic is locked This topic is locked
18 replies to this topic

#1 3maz

3maz

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:04:03 PM

Posted 06 May 2012 - 05:14 PM

So, to start from the beginning... I believe it was in early March...

I tried to format a flash drive that I had been using and windows would not let me... started looking into possible causes and stumbled across some info about rootkits that spread over flash. Suddenly, it started to make sense to me why my computer couldn't download windows updates. Since then, I have learned quite a bit about rootkits, rogue DHCP servers, and bootkits. I've done just about everything... rkill, combofix, aswmbr, tdsskiller, gmer... something is always present.

Netstat is the most revealing way I have of knowing that a computer still has it. Everything is connected through a proxy, it seems , at 0.0.0.0 or 127.0.01. I see computers connecting to non-routable IPs, soliciting themselves as DHCP servers, or not able to connect to the network. I have a block of 100 IPs set for DHCP on my router (DD-WRT) and it seems like it runs out of IPs becuase a new PC can't acquire one.

It's gone on long enough and I need to get my computers bot free again, so I've come here for help. I'm pretty good with computers but you guys are the experts. I have a bunch of logs saved from Kaspersky, avast, avira, hijack this, dds... from the whole time and from each computer but I think the place to start is the current state of things, on my main computer. So, please find DDS log below.... and thank you so much in advance.

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Eric at 17:44:17 on 2012-05-06
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8191.6004 [GMT -4:00]
.
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Kaspersky Internet Security *Enabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}
SP: Kaspersky Internet Security *Enabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security *Enabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\HsMgr.exe
C:\Windows\system\HsMgr64.exe
C:\Program Files (x86)\Free Download Manager\fdm.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
C:\Users\Eric\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\AutoHotkey\AutoHotkey.exe
C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtblfs.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: LastPass Browser Helper Object: {95d9ecf5-2a4d-4550-be49-70d42f71296e} - C:\Program Files (x86)\LastPass\LPBar.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
BHO: Free Download Manager: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPBar.dll
uRun: [Free Download Manager] "C:\Program Files (x86)\Free Download Manager\fdm.exe" -autorun
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun: [avp] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe"
StartupFolder: C:\Users\Eric\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Eric\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\Eric\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MAINAH~1.LNK - S:\Dropbox\Dev\AutoHotKey\_Scripts\Main.ahk
StartupFolder: C:\Users\Eric\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Download all with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: LastPass - file://C:\Program Files (x86)\LastPass\context.html?cmd=lastpass
IE: LastPass Fill Forms - file://C:\Program Files (x86)\LastPass\context.html?cmd=fillforms
IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
TCP: Interfaces\{8F7A7258-3241-4800-B94E-2688E0B408E4} : NameServer = 208.67.222.222,208.67.220.220
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
BHO-X64: IEVkbdBHO - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: LastPass Browser Helper Object: {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar.dll
BHO-X64: LastPass Browser Helper Object - No File
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Free Download Manager: {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
BHO-X64: link filter bho - No File
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB-X64: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPBar.dll
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun-x64: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload
mRun-x64: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun-x64: [avp] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe"
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\c6l2d0b8.default\
.
============= SERVICES / DRIVERS ===============
.
R0 FixZeroAccess;Zero Access Fixtool driver;C:\Windows\system32\drivers\FixZeroAccess.sys --> C:\Windows\system32\drivers\FixZeroAccess.sys [?]
R1 avkmgr;avkmgr;C:\Windows\system32\DRIVERS\avkmgr.sys --> C:\Windows\system32\DRIVERS\avkmgr.sys [?]
R1 kl2;kl2;C:\Windows\system32\DRIVERS\kl2.sys --> C:\Windows\system32\DRIVERS\kl2.sys [?]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys --> C:\Windows\system32\DRIVERS\klim6.sys [?]
R1 nm3;Microsoft Network Monitor 3 Driver;C:\Windows\system32\DRIVERS\nm3.sys --> C:\Windows\system32\DRIVERS\nm3.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-4-4 63928]
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-4-28 86224]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-4-22 44768]
R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [2011-4-24 202296]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2012-5-3 1153368]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\system32\DRIVERS\klmouflt.sys --> C:\Windows\system32\DRIVERS\klmouflt.sys [?]
R3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver;C:\Windows\system32\DRIVERS\Rtnic64.sys --> C:\Windows\system32\DRIVERS\Rtnic64.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-4-22 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-27 257696]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-4-22 136176]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 51740536]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-2 129976]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\system32\drivers\synth3dvsc.sys --> C:\Windows\system32\drivers\synth3dvsc.sys [?]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\system32\drivers\terminpt.sys --> C:\Windows\system32\drivers\terminpt.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 tsusbhub;tsusbhub;C:\Windows\system32\drivers\tsusbhub.sys --> C:\Windows\system32\drivers\tsusbhub.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 AntiVirService;Avira Realtime Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-4-28 110032]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-05-05 04:18:20 -------- d-sh--w- C:\$RECYCLE.BIN
2012-05-05 01:56:44 8744608 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-05-04 21:15:13 8917360 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BB4A5419-DE9E-411E-9869-C60841C58E99}\mpengine.dll
2012-05-03 06:36:26 98816 ----a-w- C:\Windows\sed.exe
2012-05-03 06:36:26 518144 ----a-w- C:\Windows\SWREG.exe
2012-05-03 06:36:26 256000 ----a-w- C:\Windows\PEV.exe
2012-05-03 06:36:26 208896 ----a-w- C:\Windows\MBR.exe
2012-05-03 06:00:00 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2012-05-03 06:00:00 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2012-05-03 04:59:57 27256 ----a-w- C:\Windows\System32\drivers\FixZeroAccess.sys
2012-05-03 04:27:20 -------- d-----w- C:\Users\Eric\SecurityScans
2012-05-03 04:27:01 -------- d-----w- C:\Program Files\Microsoft Baseline Security Analyzer 2
2012-05-03 00:03:48 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service
2012-05-03 00:03:39 157352 ----a-w- C:\Program Files (x86)\Mozilla Firefox\maintenanceservice_installer.exe
2012-05-03 00:03:39 129976 ----a-w- C:\Program Files (x86)\Mozilla Firefox\maintenanceservice.exe
2012-04-30 14:11:46 -------- d-----w- C:\Users\Eric\AppData\Roaming\Wireshark
2012-04-30 11:44:37 -------- d-----w- C:\Program Files (x86)\WinPcap
2012-04-30 11:43:43 -------- d-----w- C:\Program Files\Wireshark
2012-04-30 10:48:35 -------- d-----r- C:\Users\Eric\AppData\Roaming\Brother
2012-04-28 13:59:23 -------- d-----w- C:\Downloads
2012-04-28 10:45:10 -------- d-----w- C:\Users\Eric\AppData\Roaming\Avira
2012-04-28 10:39:34 97312 ----a-w- C:\Windows\System32\drivers\avgntflt.sys
2012-04-28 10:39:34 27760 ----a-w- C:\Windows\System32\drivers\avkmgr.sys
2012-04-28 10:39:33 -------- d-----w- C:\ProgramData\Avira
2012-04-28 10:39:33 -------- d-----w- C:\Program Files (x86)\Avira
2012-04-28 09:30:01 -------- d-----w- C:\Users\Eric\AppData\Roaming\Free Download Manager
2012-04-28 09:29:59 -------- d-----w- C:\Program Files (x86)\Free Download Manager
2012-04-28 06:13:06 -------- d-----w- C:\ProgramData\Brother
2012-04-27 12:27:31 -------- d-----w- C:\Users\Eric\AppData\Roaming\PeerNetworking
2012-04-27 11:19:05 -------- d-----w- C:\Users\Eric\AppData\Roaming\KeePass
2012-04-27 11:17:01 -------- d-----w- C:\Program Files (x86)\AutoHotkey
2012-04-27 11:05:17 -------- d-----w- C:\Users\Eric\AppData\Roaming\pdfforge
2012-04-27 11:05:15 662288 ----a-w- C:\Windows\SysWow64\MSCOMCT2.OCX
2012-04-27 11:05:15 65024 ----a-w- C:\Windows\System32\pdfcmon.dll
2012-04-27 11:05:15 137000 ----a-w- C:\Windows\SysWow64\MSMAPI32.OCX
2012-04-27 11:05:15 1071088 ----a-w- C:\Windows\SysWow64\MSCOMCTL.OCX
2012-04-27 11:05:14 23552 ----a-w- C:\Windows\SysWow64\MSMPIDE.DLL
2012-04-27 11:05:14 -------- d-----w- C:\Program Files (x86)\PDFCreator
2012-04-27 10:58:39 -------- d-----w- C:\Users\Eric\AppData\Roaming\picpick
2012-04-27 10:57:32 -------- d-----w- C:\Program Files (x86)\PicPick
2012-04-27 07:29:42 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-27 07:29:42 419488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-04-27 05:59:52 -------- d-----w- C:\Users\Eric\dwhelper
2012-04-27 00:10:05 -------- d-----w- C:\Program Files (x86)\KeePass Password Safe 2
2012-04-27 00:04:46 -------- d-----w- C:\Program Files (x86)\MSECache
2012-04-27 00:02:31 14744 ----a-w- C:\Users\Eric\AppData\Roaming\Microsoft\IdentityCRL\Production\ppcrlconfig.dll
2012-04-26 23:17:25 -------- d-----w- C:\Program Files (x86)\LastPass
2012-04-25 21:41:26 -------- d-----w- C:\Users\Eric\AppData\Local\Thunderbird
2012-04-23 14:40:21 203264 ----a-w- C:\Windows\System32\unrar.dll
2012-04-23 14:40:20 92160 ----a-w- C:\Windows\System32\ff_vfw.dll
2012-04-23 14:40:19 -------- d-----w- C:\Program Files\K-Lite Codec Pack x64
2012-04-23 14:32:46 -------- d-----w- C:\Users\Eric\AppData\Roaming\XnView
2012-04-23 14:31:22 -------- d-----w- C:\Program Files (x86)\XnView
2012-04-23 14:28:17 -------- d-----w- C:\Users\Eric\AppData\Roaming\TrueCrypt
2012-04-23 14:28:01 230864 ----a-w- C:\Windows\System32\drivers\truecrypt.sys
2012-04-23 14:27:32 -------- d-----w- C:\Program Files\TrueCrypt
2012-04-23 01:14:24 -------- d-----w- C:\ProgramData\HitmanPro
2012-04-22 23:32:38 839680 ----a-w- C:\Windows\SysWow64\lameACM.acm
2012-04-22 23:32:38 650752 ----a-w- C:\Windows\SysWow64\xvidcore.dll
2012-04-22 23:32:38 243200 ----a-w- C:\Windows\SysWow64\xvidvfw.dll
2012-04-22 23:32:38 175616 ----a-w- C:\Windows\SysWow64\unrar.dll
2012-04-22 23:32:38 151552 ----a-w- C:\Windows\SysWow64\ac3acm.acm
2012-04-22 23:32:37 79360 ----a-w- C:\Windows\SysWow64\ff_vfw.dll
2012-04-22 23:32:36 -------- d-----w- C:\Program Files (x86)\K-Lite Codec Pack
2012-04-22 19:54:25 -------- d-----w- C:\Users\Eric\AppData\Local\Adobe
2012-04-22 19:36:44 -------- d-----w- C:\Program Files (x86)\MozBackup
2012-04-22 19:16:30 -------- d-----w- C:\Users\Eric\AppData\Roaming\Malwarebytes
2012-04-22 19:16:25 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-04-22 19:16:25 -------- d-----w- C:\ProgramData\Malwarebytes
2012-04-22 19:16:25 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-04-22 19:08:58 -------- d-----w- C:\Program Files\Microsoft Network Monitor 3
2012-04-22 18:35:00 -------- d-----w- C:\Program Files\HashTab Shell Extension
2012-04-22 18:29:03 -------- d-----w- C:\Program Files (x86)\VirusTotalUploader2
2012-04-22 17:25:20 -------- d-----w- C:\Users\Eric\AppData\Local\Google
2012-04-22 17:25:06 69976 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2012-04-22 17:24:47 41184 ----a-w- C:\Windows\avastSS.scr
2012-04-22 17:24:39 -------- d-----w- C:\ProgramData\AVAST Software
2012-04-22 17:24:39 -------- d-----w- C:\Program Files\AVAST Software
2012-04-22 16:01:31 525544 ----a-w- C:\Windows\System32\deployJava1.dll
2012-04-22 15:32:52 -------- d-----w- C:\Windows\SysWow64\ShellExt
2012-04-22 15:32:52 -------- d-----w- C:\Windows\System32\ShellExt
2012-04-22 15:30:51 -------- d-----w- C:\Users\Eric\AppData\Local\Anolis
2012-04-22 13:40:49 -------- d-----w- C:\Program Files (x86)\uTorrent
2012-04-22 13:40:19 -------- d-----w- C:\Users\Eric\AppData\Roaming\uTorrent
2012-04-22 11:06:02 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\e7493a0d1cd207705\MeshBetaRemover.exe
2012-04-22 11:05:14 -------- d-----w- C:\Users\Eric\AppData\Local\Windows Live
2012-04-22 11:05:13 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2012-04-22 09:38:49 -------- d-----w- C:\ProgramData\Kaspersky Lab
2012-04-22 09:38:49 -------- d-----w- C:\Program Files (x86)\Kaspersky Lab
2012-04-22 08:56:57 -------- d-----w- C:\Users\Eric\AppData\Local\Diagnostics
2012-04-22 05:18:04 419840 ----a-w- C:\Windows\System32\wrap_oal.dll
2012-04-22 05:18:04 413696 ----a-w- C:\Windows\SysWow64\wrap_oal.dll
2012-04-22 05:18:04 111616 ----a-w- C:\Windows\System32\OpenAL32.dll
2012-04-22 05:18:04 102400 ----a-w- C:\Windows\SysWow64\OpenAL32.dll
2012-04-22 05:18:04 -------- d-----w- C:\Program Files (x86)\OpenAL
2012-04-22 03:37:01 359424 ------w- C:\Windows\System32\CmiInstallResAll64.dll
2012-04-22 03:37:00 524768 ----a-w- C:\Windows\difxapi.dll
2012-04-21 03:46:26 97208 ----a-w- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
2012-04-21 03:46:26 588728 ----a-w- C:\Program Files (x86)\Mozilla Firefox\gkmedias.dll
2012-04-21 03:46:26 43960 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozglue.dll
2012-04-19 13:51:58 -------- d-----w- C:\Program Files\Microsoft Synchronization Services
2012-04-19 13:51:35 -------- d-----w- C:\Windows\PCHEALTH
2012-04-19 13:51:35 -------- d-----w- C:\Program Files\Microsoft SQL Server Compact Edition
2012-04-19 13:49:38 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 8
2012-04-19 13:48:51 -------- d-----w- C:\Program Files\Microsoft Analysis Services
2012-04-19 13:48:51 -------- d-----w- C:\Program Files (x86)\Microsoft Analysis Services
2012-04-19 13:48:24 -------- d-----w- C:\Users\Eric\AppData\Local\Microsoft Help
2012-04-19 10:47:49 -------- d-----w- C:\Users\Eric\AppData\Roaming\Dropbox
2012-04-19 10:41:58 -------- d-----w- C:\Windows\Panther
2012-04-19 10:41:43 -------- d-----w- C:\Boot
2012-04-19 09:25:12 -------- d-sh--w- C:\Windows\Installer
2012-04-19 09:18:17 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2012-04-19 09:18:12 -------- d-----w- C:\Program Files\NVIDIA Corporation
2012-04-19 09:16:05 -------- d-----w- C:\Windows\SysWow64\Wat
2012-04-19 09:16:04 -------- d-----w- C:\Windows\System32\Wat
2012-04-19 08:54:14 8917360 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-04-19 08:48:10 5559152 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-04-19 08:48:10 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-04-19 08:48:10 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-04-19 08:46:32 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-04-19 08:46:32 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-04-19 08:46:32 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-04-19 08:46:32 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-04-19 08:46:32 220672 ----a-w- C:\Windows\System32\wintrust.dll
2012-04-19 08:46:32 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-04-19 08:46:32 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-04-19 08:43:58 642944 ----a-w- C:\Windows\System32\winload.efi
2012-04-19 08:39:23 77312 ----a-w- C:\Windows\System32\packager.dll
2012-04-19 08:39:23 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2012-04-19 08:39:23 1731920 ----a-w- C:\Windows\System32\ntdll.dll
2012-04-19 08:39:23 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
2012-04-19 08:38:40 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2012-04-19 08:38:40 1112064 ----a-w- C:\Windows\System32\rdpcorets.dll
2012-04-19 08:38:40 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2012-04-19 08:38:39 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-04-19 08:38:39 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-04-19 08:29:56 74272 ----a-w- C:\Windows\System32\RtNicProp64.dll
2012-04-19 08:29:56 412776 ----a-w- C:\Windows\System32\drivers\Rt64win7.sys
2012-04-19 08:29:56 107552 ----a-w- C:\Windows\System32\RTNUninst64.dll
2012-04-19 08:29:53 -------- d-----w- C:\Program Files (x86)\Realtek
.
==================== Find3M ====================
.
2012-02-28 06:56:48 2311168 ----a-w- C:\Windows\System32\jscript9.dll
2012-02-28 06:49:56 1390080 ----a-w- C:\Windows\System32\wininet.dll
2012-02-28 06:48:57 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-02-28 06:42:55 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-02-28 01:18:55 1799168 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-02-28 01:11:21 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-02-28 01:11:07 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-02-28 01:03:16 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-02-23 14:18:36 279656 ------w- C:\Windows\System32\MpSigStub.exe
2012-02-10 06:36:07 1544192 ----a-w- C:\Windows\System32\DWrite.dll
2012-02-10 05:38:43 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
.
============= FINISH: 17:45:52.53 ===============

BC AdBot (Login to Remove)

 


#2 3maz

3maz
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:04:03 PM

Posted 09 May 2012 - 09:35 PM

bump

#3 nasdaq

nasdaq

  • Malware Response Team
  • 40,213 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:03 PM

Posted 10 May 2012 - 09:11 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.
===

Lets start from the beginning.

Please Download
TDSSKiller.zip

>>> Double-click on TDSSKiller.exe to run the application.
  • Click on the Start Scan button and wait for the scan and disinfection process to be over.
  • If an infected file is detected, the default action will be Cure, click on Continue
    Posted Image
  • If a suspicious file is detected, the default action will be Skip, click on Continue
    Posted Image
  • If you are asked to reboot the computer to complete the process, click on the Reboot Now button. A report will be automatically saved at the root of the System drive ((usually C:\) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt" (for example, C:\TDSSKiller.2.2.0_20.12.2009_15.31.43_log.txt). Please copy and paste the contents of that file here.
  • If no reboot is required, click on Report. A log file will appear. Please copy and paste the contents of that file in your next reply.

Download http://public.avast.com/~gmerek/aswMBR.exe (aswMBR.exe) to your desktop. Double click the aswMBR.exe to run it

  • Click the "Scan" button to start scan.
  • Upon completion of the scan, click Save log, and save it to your desktop. (Note - do not select any Fix at this time) <- IMPORTANT
  • Please post the contents of that log in your next reply.
There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

===

Please post the logs for my review.

#4 3maz

3maz
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:04:03 PM

Posted 10 May 2012 - 07:49 PM

Thanks, here they are!! As usual, nothing conclusive... I'm curious about those nt!IofCallDriver things though. They just seem suspicious..



20:36:57.0477 5060 TDSS rootkit removing tool 2.7.34.0 May 2 2012 09:59:18
20:36:57.0758 5060 ============================================================
20:36:57.0758 5060 Current date / time: 2012/05/10 20:36:57.0758
20:36:57.0758 5060 SystemInfo:
20:36:57.0758 5060
20:36:57.0758 5060 OS Version: 6.1.7601 ServicePack: 1.0
20:36:57.0758 5060 Product type: Workstation
20:36:57.0758 5060 ComputerName: DESKTOP
20:36:57.0758 5060 UserName: Eric
20:36:57.0758 5060 Windows directory: C:\Windows
20:36:57.0758 5060 System windows directory: C:\Windows
20:36:57.0758 5060 Running under WOW64
20:36:57.0758 5060 Processor architecture: Intel x64
20:36:57.0758 5060 Number of processors: 4
20:36:57.0758 5060 Page size: 0x1000
20:36:57.0758 5060 Boot type: Normal boot
20:36:57.0758 5060 ============================================================
20:36:58.0757 5060 Drive \Device\Harddisk0\DR0 - Size: 0x2658AE0000 (153.39 Gb), SectorSize: 0x200, Cylinders: 0x4E37, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:36:58.0766 5060 Drive \Device\Harddisk1\DR1 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:36:58.0793 5060 Drive \Device\Harddisk2\DR2 - Size: 0x3A70C70000 (233.76 Gb), SectorSize: 0x200, Cylinders: 0x7733, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:36:58.0805 5060 Drive \Device\Harddisk3\DR3 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
20:36:59.0267 5060 Drive \Device\Harddisk8\DR8 - Size: 0x15D50F65E00 (1397.27 Gb), SectorSize: 0x200, Cylinders: 0x2C881, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
20:37:04.0989 5060 ============================================================
20:37:04.0989 5060 \Device\Harddisk0\DR0:
20:37:05.0007 5060 MBR partitions:
20:37:05.0007 5060 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x132C4800
20:37:05.0007 5060 \Device\Harddisk1\DR1:
20:37:05.0007 5060 MBR partitions:
20:37:05.0007 5060 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x1D1C4800
20:37:05.0007 5060 \Device\Harddisk2\DR2:
20:37:05.0010 5060 MBR partitions:
20:37:05.0042 5060 \Device\Harddisk3\DR3:
20:37:05.0067 5060 MBR partitions:
20:37:05.0067 5060 \Device\Harddisk3\DR3\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x74705982
20:37:05.0067 5060 \Device\Harddisk8\DR8:
20:37:05.0069 5060 MBR partitions:
20:37:05.0069 5060 \Device\Harddisk8\DR8\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xAEA86741
20:37:05.0069 5060 ============================================================
20:37:05.0072 5060 C: <-> \Device\Harddisk0\DR0\Partition0
20:37:05.0091 5060 S: <-> \Device\Harddisk1\DR1\Partition0
20:37:05.0121 5060 Y: <-> \Device\Harddisk3\DR3\Partition0
20:37:05.0135 5060 Z: <-> \Device\Harddisk8\DR8\Partition0
20:37:05.0135 5060 ============================================================
20:37:05.0135 5060 Initialize success
20:37:05.0135 5060 ============================================================
20:37:23.0630 4476 ============================================================
20:37:23.0630 4476 Scan started
20:37:23.0630 4476 Mode: Manual;
20:37:23.0630 4476 ============================================================
20:37:25.0612 4476 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
20:37:25.0614 4476 1394ohci - ok
20:37:25.0644 4476 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
20:37:25.0645 4476 ACPI - ok
20:37:25.0661 4476 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
20:37:25.0662 4476 AcpiPmi - ok
20:37:25.0731 4476 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
20:37:25.0732 4476 AdobeARMservice - ok
20:37:25.0810 4476 AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
20:37:25.0811 4476 AdobeFlashPlayerUpdateSvc - ok
20:37:25.0852 4476 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys
20:37:25.0855 4476 adp94xx - ok
20:37:25.0875 4476 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys
20:37:25.0877 4476 adpahci - ok
20:37:25.0890 4476 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys
20:37:25.0891 4476 adpu320 - ok
20:37:25.0910 4476 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
20:37:25.0911 4476 AeLookupSvc - ok
20:37:25.0962 4476 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
20:37:25.0965 4476 AFD - ok
20:37:25.0987 4476 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
20:37:25.0989 4476 agp440 - ok
20:37:26.0001 4476 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
20:37:26.0001 4476 ALG - ok
20:37:26.0022 4476 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
20:37:26.0022 4476 aliide - ok
20:37:26.0031 4476 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
20:37:26.0031 4476 amdide - ok
20:37:26.0044 4476 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys
20:37:26.0045 4476 AmdK8 - ok
20:37:26.0065 4476 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
20:37:26.0065 4476 AmdPPM - ok
20:37:26.0086 4476 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
20:37:26.0086 4476 amdsata - ok
20:37:26.0102 4476 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys
20:37:26.0104 4476 amdsbs - ok
20:37:26.0121 4476 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
20:37:26.0122 4476 amdxata - ok
20:37:26.0147 4476 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
20:37:26.0147 4476 AppID - ok
20:37:26.0169 4476 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
20:37:26.0170 4476 AppIDSvc - ok
20:37:26.0197 4476 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
20:37:26.0199 4476 Appinfo - ok
20:37:26.0284 4476 Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
20:37:26.0285 4476 Apple Mobile Device - ok
20:37:26.0314 4476 AppMgmt (4aba3e75a76195a3e38ed2766c962899) C:\Windows\System32\appmgmts.dll
20:37:26.0315 4476 AppMgmt - ok
20:37:26.0344 4476 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys
20:37:26.0344 4476 arc - ok
20:37:26.0359 4476 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys
20:37:26.0360 4476 arcsas - ok
20:37:26.0397 4476 aswFsBlk (b9da213b5271db5fce962d827e6d620d) C:\Windows\system32\drivers\aswFsBlk.sys
20:37:26.0397 4476 aswFsBlk - ok
20:37:26.0439 4476 aswMonFlt (21c9835d0e5ad2ff0f16134bcb32cc71) C:\Windows\system32\drivers\aswMonFlt.sys
20:37:26.0440 4476 aswMonFlt - ok
20:37:26.0462 4476 aswRdr (1b96a5867abd4fa6135d8298fcccf9c6) C:\Windows\System32\Drivers\aswrdr2.sys
20:37:26.0464 4476 aswRdr - ok
20:37:26.0519 4476 aswSnx (6e98bb288696777a3a8a07a52b0eaee9) C:\Windows\system32\drivers\aswSnx.sys
20:37:26.0522 4476 aswSnx - ok
20:37:26.0555 4476 aswSP (d9fb49f16e4eb02efecae8cbfe4bcb4c) C:\Windows\system32\drivers\aswSP.sys
20:37:26.0556 4476 aswSP - ok
20:37:26.0577 4476 aswTdi (7352bb9a564b94bbd7c9cbf165f55006) C:\Windows\system32\drivers\aswTdi.sys
20:37:26.0577 4476 aswTdi - ok
20:37:26.0612 4476 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
20:37:26.0612 4476 AsyncMac - ok
20:37:26.0627 4476 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
20:37:26.0629 4476 atapi - ok
20:37:26.0686 4476 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
20:37:26.0695 4476 AudioEndpointBuilder - ok
20:37:26.0700 4476 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
20:37:26.0704 4476 AudioSrv - ok
20:37:26.0771 4476 avast! Antivirus (4041d31508a2a084dfb42c595854090f) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
20:37:26.0772 4476 avast! Antivirus - ok
20:37:26.0800 4476 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
20:37:26.0801 4476 AxInstSV - ok
20:37:26.0849 4476 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys
20:37:26.0851 4476 b06bdrv - ok
20:37:26.0905 4476 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
20:37:26.0906 4476 b57nd60a - ok
20:37:26.0970 4476 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
20:37:26.0970 4476 BDESVC - ok
20:37:26.0981 4476 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
20:37:26.0981 4476 Beep - ok
20:37:27.0021 4476 BFE (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll
20:37:27.0025 4476 BFE - ok
20:37:27.0062 4476 BITS (1ea7969e3271cbc59e1730697dc74682) C:\Windows\system32\qmgr.dll
20:37:27.0075 4476 BITS - ok
20:37:27.0105 4476 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
20:37:27.0105 4476 blbdrive - ok
20:37:27.0179 4476 Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe
20:37:27.0181 4476 Bonjour Service - ok
20:37:27.0211 4476 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
20:37:27.0211 4476 bowser - ok
20:37:27.0222 4476 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys
20:37:27.0222 4476 BrFiltLo - ok
20:37:27.0230 4476 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys
20:37:27.0230 4476 BrFiltUp - ok
20:37:27.0251 4476 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys
20:37:27.0251 4476 BridgeMP - ok
20:37:27.0276 4476 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
20:37:27.0277 4476 Browser - ok
20:37:27.0295 4476 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
20:37:27.0297 4476 Brserid - ok
20:37:27.0301 4476 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
20:37:27.0301 4476 BrSerWdm - ok
20:37:27.0304 4476 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
20:37:27.0304 4476 BrUsbMdm - ok
20:37:27.0321 4476 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
20:37:27.0322 4476 BrUsbSer - ok
20:37:27.0326 4476 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys
20:37:27.0326 4476 BTHMODEM - ok
20:37:27.0347 4476 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
20:37:27.0349 4476 bthserv - ok
20:37:27.0366 4476 catchme - ok
20:37:27.0392 4476 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
20:37:27.0394 4476 cdfs - ok
20:37:27.0419 4476 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
20:37:27.0420 4476 cdrom - ok
20:37:27.0447 4476 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
20:37:27.0449 4476 CertPropSvc - ok
20:37:27.0464 4476 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys
20:37:27.0465 4476 circlass - ok
20:37:27.0489 4476 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
20:37:27.0490 4476 CLFS - ok
20:37:27.0544 4476 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:37:27.0545 4476 clr_optimization_v2.0.50727_32 - ok
20:37:27.0587 4476 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
20:37:27.0589 4476 clr_optimization_v2.0.50727_64 - ok
20:37:27.0619 4476 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:37:27.0620 4476 clr_optimization_v4.0.30319_32 - ok
20:37:27.0672 4476 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
20:37:27.0674 4476 clr_optimization_v4.0.30319_64 - ok
20:37:27.0691 4476 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\drivers\CmBatt.sys
20:37:27.0692 4476 CmBatt - ok
20:37:27.0707 4476 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
20:37:27.0707 4476 cmdide - ok
20:37:27.0809 4476 cmuda3 (277d3ed6b6901a9c15b7828d40269509) C:\Windows\system32\drivers\cmudax3.sys
20:37:27.0821 4476 cmuda3 - ok
20:37:27.0931 4476 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
20:37:27.0932 4476 CNG - ok
20:37:27.0954 4476 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys
20:37:27.0954 4476 Compbatt - ok
20:37:27.0972 4476 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys
20:37:27.0974 4476 CompositeBus - ok
20:37:27.0986 4476 COMSysApp - ok
20:37:27.0995 4476 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys
20:37:27.0995 4476 crcdisk - ok
20:37:28.0039 4476 CryptSvc (15597883fbe9b056f276ada3ad87d9af) C:\Windows\system32\cryptsvc.dll
20:37:28.0041 4476 CryptSvc - ok
20:37:28.0074 4476 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys
20:37:28.0076 4476 CSC - ok
20:37:28.0097 4476 CscService (3ab183ab4d2c79dcf459cd2c1266b043) C:\Windows\System32\cscsvc.dll
20:37:28.0101 4476 CscService - ok
20:37:28.0134 4476 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
20:37:28.0141 4476 DcomLaunch - ok
20:37:28.0174 4476 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
20:37:28.0175 4476 defragsvc - ok
20:37:28.0215 4476 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
20:37:28.0216 4476 DfsC - ok
20:37:28.0251 4476 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
20:37:28.0254 4476 Dhcp - ok
20:37:28.0264 4476 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
20:37:28.0265 4476 discache - ok
20:37:28.0292 4476 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys
20:37:28.0292 4476 Disk - ok
20:37:28.0317 4476 dmvsc (5db085a8a6600be6401f2b24eecb5415) C:\Windows\system32\drivers\dmvsc.sys
20:37:28.0319 4476 dmvsc - ok
20:37:28.0345 4476 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
20:37:28.0346 4476 Dnscache - ok
20:37:28.0380 4476 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
20:37:28.0382 4476 dot3svc - ok
20:37:28.0400 4476 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
20:37:28.0402 4476 DPS - ok
20:37:28.0426 4476 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
20:37:28.0426 4476 drmkaud - ok
20:37:28.0475 4476 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
20:37:28.0480 4476 DXGKrnl - ok
20:37:28.0491 4476 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
20:37:28.0492 4476 EapHost - ok
20:37:28.0601 4476 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys
20:37:28.0632 4476 ebdrv - ok
20:37:28.0710 4476 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
20:37:28.0711 4476 EFS - ok
20:37:28.0759 4476 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
20:37:28.0761 4476 ehRecvr - ok
20:37:28.0779 4476 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
20:37:28.0779 4476 ehSched - ok
20:37:28.0832 4476 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys
20:37:28.0835 4476 elxstor - ok
20:37:28.0852 4476 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
20:37:28.0852 4476 ErrDev - ok
20:37:28.0891 4476 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
20:37:28.0897 4476 EventSystem - ok
20:37:28.0910 4476 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
20:37:28.0911 4476 exfat - ok
20:37:28.0930 4476 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
20:37:28.0931 4476 fastfat - ok
20:37:28.0976 4476 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
20:37:28.0986 4476 Fax - ok
20:37:29.0001 4476 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys
20:37:29.0001 4476 fdc - ok
20:37:29.0021 4476 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
20:37:29.0022 4476 fdPHost - ok
20:37:29.0031 4476 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
20:37:29.0032 4476 FDResPub - ok
20:37:29.0046 4476 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
20:37:29.0047 4476 FileInfo - ok
20:37:29.0055 4476 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
20:37:29.0056 4476 Filetrace - ok
20:37:29.0071 4476 FixZeroAccess (ac7e21145b9348bfc1b1dec7bc238b3f) C:\Windows\system32\drivers\FixZeroAccess.sys
20:37:29.0072 4476 FixZeroAccess - ok
20:37:29.0075 4476 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys
20:37:29.0075 4476 flpydisk - ok
20:37:29.0095 4476 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
20:37:29.0096 4476 FltMgr - ok
20:37:29.0155 4476 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
20:37:29.0170 4476 FontCache - ok
20:37:29.0230 4476 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
20:37:29.0230 4476 FontCache3.0.0.0 - ok
20:37:29.0265 4476 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
20:37:29.0266 4476 FsDepends - ok
20:37:29.0294 4476 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys
20:37:29.0294 4476 Fs_Rec - ok
20:37:29.0331 4476 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
20:37:29.0332 4476 fvevol - ok
20:37:29.0351 4476 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys
20:37:29.0352 4476 gagp30kx - ok
20:37:29.0376 4476 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
20:37:29.0376 4476 GEARAspiWDM - ok
20:37:29.0416 4476 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
20:37:29.0421 4476 gpsvc - ok
20:37:29.0491 4476 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:37:29.0492 4476 gupdate - ok
20:37:29.0506 4476 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:37:29.0507 4476 gupdatem - ok
20:37:29.0531 4476 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
20:37:29.0532 4476 hcw85cir - ok
20:37:29.0572 4476 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
20:37:29.0574 4476 HdAudAddService - ok
20:37:29.0594 4476 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys
20:37:29.0595 4476 HDAudBus - ok
20:37:29.0604 4476 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys
20:37:29.0604 4476 HidBatt - ok
20:37:29.0609 4476 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys
20:37:29.0610 4476 HidBth - ok
20:37:29.0621 4476 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys
20:37:29.0621 4476 HidIr - ok
20:37:29.0634 4476 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\System32\hidserv.dll
20:37:29.0635 4476 hidserv - ok
20:37:29.0676 4476 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
20:37:29.0677 4476 HidUsb - ok
20:37:29.0710 4476 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
20:37:29.0711 4476 hkmsvc - ok
20:37:29.0731 4476 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
20:37:29.0734 4476 HomeGroupListener - ok
20:37:29.0757 4476 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
20:37:29.0761 4476 HomeGroupProvider - ok
20:37:29.0775 4476 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
20:37:29.0776 4476 HpSAMD - ok
20:37:29.0809 4476 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
20:37:29.0812 4476 HTTP - ok
20:37:29.0819 4476 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
20:37:29.0819 4476 hwpolicy - ok
20:37:29.0850 4476 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
20:37:29.0850 4476 i8042prt - ok
20:37:29.0882 4476 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
20:37:29.0885 4476 iaStorV - ok
20:37:29.0969 4476 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
20:37:29.0972 4476 idsvc - ok
20:37:30.0001 4476 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys
20:37:30.0002 4476 iirsp - ok
20:37:30.0047 4476 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
20:37:30.0052 4476 IKEEXT - ok
20:37:30.0065 4476 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
20:37:30.0066 4476 intelide - ok
20:37:30.0090 4476 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\drivers\intelppm.sys
20:37:30.0090 4476 intelppm - ok
20:37:30.0111 4476 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
20:37:30.0112 4476 IPBusEnum - ok
20:37:30.0116 4476 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:37:30.0117 4476 IpFilterDriver - ok
20:37:30.0151 4476 iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll
20:37:30.0155 4476 iphlpsvc - ok
20:37:30.0167 4476 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
20:37:30.0167 4476 IPMIDRV - ok
20:37:30.0189 4476 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
20:37:30.0190 4476 IPNAT - ok
20:37:30.0247 4476 iPod Service (50d6ccc6ff5561f9f56946b3e6164fb8) C:\Program Files\iPod\bin\iPodService.exe
20:37:30.0259 4476 iPod Service - ok
20:37:30.0266 4476 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
20:37:30.0267 4476 IRENUM - ok
20:37:30.0277 4476 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
20:37:30.0277 4476 isapnp - ok
20:37:30.0294 4476 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
20:37:30.0296 4476 iScsiPrt - ok
20:37:30.0316 4476 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
20:37:30.0317 4476 kbdclass - ok
20:37:30.0342 4476 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
20:37:30.0344 4476 kbdhid - ok
20:37:30.0367 4476 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:37:30.0370 4476 KeyIso - ok
20:37:30.0382 4476 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys
20:37:30.0382 4476 KSecDD - ok
20:37:30.0395 4476 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys
20:37:30.0395 4476 KSecPkg - ok
20:37:30.0409 4476 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
20:37:30.0409 4476 ksthunk - ok
20:37:30.0437 4476 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
20:37:30.0441 4476 KtmRm - ok
20:37:30.0480 4476 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\System32\srvsvc.dll
20:37:30.0484 4476 LanmanServer - ok
20:37:30.0505 4476 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
20:37:30.0507 4476 LanmanWorkstation - ok
20:37:30.0539 4476 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
20:37:30.0540 4476 lltdio - ok
20:37:30.0572 4476 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
20:37:30.0575 4476 lltdsvc - ok
20:37:30.0591 4476 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
20:37:30.0592 4476 lmhosts - ok
20:37:30.0614 4476 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys
20:37:30.0615 4476 LSI_FC - ok
20:37:30.0819 4476 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys
20:37:30.0820 4476 LSI_SAS - ok
20:37:30.0986 4476 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys
20:37:30.0986 4476 LSI_SAS2 - ok
20:37:31.0110 4476 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys
20:37:31.0111 4476 LSI_SCSI - ok
20:37:31.0134 4476 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
20:37:31.0134 4476 luafv - ok
20:37:31.0150 4476 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll
20:37:31.0152 4476 Mcx2Svc - ok
20:37:31.0166 4476 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys
20:37:31.0166 4476 megasas - ok
20:37:31.0186 4476 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys
20:37:31.0187 4476 MegaSR - ok
20:37:31.0265 4476 Microsoft SharePoint Workspace Audit Service - ok
20:37:31.0306 4476 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
20:37:31.0307 4476 MMCSS - ok
20:37:31.0322 4476 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
20:37:31.0322 4476 Modem - ok
20:37:31.0349 4476 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
20:37:31.0350 4476 monitor - ok
20:37:31.0365 4476 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
20:37:31.0366 4476 mouclass - ok
20:37:31.0376 4476 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
20:37:31.0376 4476 mouhid - ok
20:37:31.0387 4476 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
20:37:31.0389 4476 mountmgr - ok
20:37:31.0454 4476 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
20:37:31.0454 4476 MozillaMaintenance - ok
20:37:31.0472 4476 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
20:37:31.0472 4476 mpio - ok
20:37:31.0485 4476 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
20:37:31.0486 4476 mpsdrv - ok
20:37:31.0526 4476 MpsSvc (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll
20:37:31.0531 4476 MpsSvc - ok
20:37:31.0549 4476 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
20:37:31.0550 4476 MRxDAV - ok
20:37:31.0579 4476 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
20:37:31.0580 4476 mrxsmb - ok
20:37:31.0596 4476 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:37:31.0597 4476 mrxsmb10 - ok
20:37:31.0607 4476 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:37:31.0607 4476 mrxsmb20 - ok
20:37:31.0622 4476 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
20:37:31.0622 4476 msahci - ok
20:37:31.0634 4476 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
20:37:31.0635 4476 msdsm - ok
20:37:31.0655 4476 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
20:37:31.0657 4476 MSDTC - ok
20:37:31.0674 4476 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
20:37:31.0674 4476 Msfs - ok
20:37:31.0699 4476 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
20:37:31.0700 4476 mshidkmdf - ok
20:37:31.0712 4476 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
20:37:31.0714 4476 msisadrv - ok
20:37:31.0741 4476 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
20:37:31.0742 4476 MSiSCSI - ok
20:37:31.0745 4476 msiserver - ok
20:37:31.0775 4476 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
20:37:31.0776 4476 MSKSSRV - ok
20:37:31.0777 4476 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
20:37:31.0779 4476 MSPCLOCK - ok
20:37:31.0781 4476 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
20:37:31.0782 4476 MSPQM - ok
20:37:31.0801 4476 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
20:37:31.0804 4476 MsRPC - ok
20:37:31.0816 4476 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
20:37:31.0817 4476 mssmbios - ok
20:37:31.0826 4476 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
20:37:31.0826 4476 MSTEE - ok
20:37:31.0839 4476 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys
20:37:31.0840 4476 MTConfig - ok
20:37:31.0850 4476 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
20:37:31.0851 4476 Mup - ok
20:37:31.0882 4476 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
20:37:31.0886 4476 napagent - ok
20:37:31.0924 4476 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
20:37:31.0925 4476 NativeWifiP - ok
20:37:31.0982 4476 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
20:37:31.0986 4476 NDIS - ok
20:37:31.0996 4476 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
20:37:31.0997 4476 NdisCap - ok
20:37:32.0010 4476 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
20:37:32.0011 4476 NdisTapi - ok
20:37:32.0032 4476 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
20:37:32.0034 4476 Ndisuio - ok
20:37:32.0040 4476 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
20:37:32.0041 4476 NdisWan - ok
20:37:32.0049 4476 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
20:37:32.0050 4476 NDProxy - ok
20:37:32.0081 4476 Netaapl (6f4607e2333fe21e9e3ff8133a88b35b) C:\Windows\system32\DRIVERS\netaapl64.sys
20:37:32.0081 4476 Netaapl - ok
20:37:32.0097 4476 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
20:37:32.0099 4476 NetBIOS - ok
20:37:32.0126 4476 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
20:37:32.0127 4476 NetBT - ok
20:37:32.0151 4476 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:37:32.0152 4476 Netlogon - ok
20:37:32.0190 4476 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
20:37:32.0196 4476 Netman - ok
20:37:32.0212 4476 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
20:37:32.0219 4476 netprofm - ok
20:37:32.0285 4476 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
20:37:32.0285 4476 NetTcpPortSharing - ok
20:37:32.0322 4476 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys
20:37:32.0324 4476 nfrd960 - ok
20:37:32.0359 4476 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
20:37:32.0361 4476 NlaSvc - ok
20:37:32.0417 4476 nm3 (f554c5fd7bd1efa4da5cfe2eed86391f) C:\Windows\system32\DRIVERS\nm3.sys
20:37:32.0419 4476 nm3 - ok
20:37:32.0455 4476 NPF (351533acc2a069b94e80bbfc177e8fdf) C:\Windows\system32\drivers\npf.sys
20:37:32.0455 4476 NPF - ok
20:37:32.0461 4476 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
20:37:32.0461 4476 Npfs - ok
20:37:32.0482 4476 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
20:37:32.0485 4476 nsi - ok
20:37:32.0502 4476 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
20:37:32.0502 4476 nsiproxy - ok
20:37:32.0580 4476 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
20:37:32.0587 4476 Ntfs - ok
20:37:32.0679 4476 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
20:37:32.0680 4476 Null - ok
20:37:33.0132 4476 nvlddmkm (9c1996dd3c0469bc8933321f15709f5a) C:\Windows\system32\DRIVERS\nvlddmkm.sys
20:37:33.0355 4476 nvlddmkm - ok
20:37:33.0451 4476 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
20:37:33.0451 4476 nvraid - ok
20:37:33.0480 4476 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
20:37:33.0481 4476 nvstor - ok
20:37:33.0507 4476 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
20:37:33.0509 4476 nv_agp - ok
20:37:33.0522 4476 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
20:37:33.0522 4476 ohci1394 - ok
20:37:33.0601 4476 ose64 (4965b005492cba7719e82b71e3245495) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:37:33.0602 4476 ose64 - ok
20:37:33.0800 4476 osppsvc (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
20:37:33.0854 4476 osppsvc - ok
20:37:33.0945 4476 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
20:37:33.0948 4476 p2pimsvc - ok
20:37:33.0971 4476 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
20:37:33.0975 4476 p2psvc - ok
20:37:34.0006 4476 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
20:37:34.0008 4476 Parport - ok
20:37:34.0033 4476 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys
20:37:34.0034 4476 partmgr - ok
20:37:34.0046 4476 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
20:37:34.0051 4476 PcaSvc - ok
20:37:34.0066 4476 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
20:37:34.0068 4476 pci - ok
20:37:34.0079 4476 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
20:37:34.0080 4476 pciide - ok
20:37:34.0101 4476 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys
20:37:34.0103 4476 pcmcia - ok
20:37:34.0114 4476 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
20:37:34.0114 4476 pcw - ok
20:37:34.0140 4476 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
20:37:34.0143 4476 PEAUTH - ok
20:37:34.0206 4476 PeerDistSvc (b9b0a4299dd2d76a4243f75fd54dc680) C:\Windows\system32\peerdistsvc.dll
20:37:34.0214 4476 PeerDistSvc - ok
20:37:34.0274 4476 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
20:37:34.0276 4476 PerfHost - ok
20:37:34.0384 4476 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
20:37:34.0391 4476 pla - ok
20:37:34.0454 4476 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
20:37:34.0458 4476 PlugPlay - ok
20:37:34.0466 4476 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
20:37:34.0469 4476 PNRPAutoReg - ok
20:37:34.0480 4476 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
20:37:34.0484 4476 PNRPsvc - ok
20:37:34.0516 4476 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
20:37:34.0520 4476 PolicyAgent - ok
20:37:34.0546 4476 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
20:37:34.0549 4476 Power - ok
20:37:34.0595 4476 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
20:37:34.0596 4476 PptpMiniport - ok
20:37:34.0610 4476 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys
20:37:34.0611 4476 Processor - ok
20:37:34.0633 4476 ProfSvc (5c78838b4d166d1a27db3a8a820c799a) C:\Windows\system32\profsvc.dll
20:37:34.0636 4476 ProfSvc - ok
20:37:34.0659 4476 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:37:34.0661 4476 ProtectedStorage - ok
20:37:34.0685 4476 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
20:37:34.0686 4476 Psched - ok
20:37:34.0746 4476 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys
20:37:34.0753 4476 ql2300 - ok
20:37:34.0880 4476 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys
20:37:34.0881 4476 ql40xx - ok
20:37:34.0919 4476 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
20:37:34.0923 4476 QWAVE - ok
20:37:34.0943 4476 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
20:37:34.0944 4476 QWAVEdrv - ok
20:37:34.0955 4476 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
20:37:34.0956 4476 RasAcd - ok
20:37:34.0985 4476 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
20:37:34.0985 4476 RasAgileVpn - ok
20:37:35.0009 4476 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
20:37:35.0011 4476 RasAuto - ok
20:37:35.0030 4476 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
20:37:35.0031 4476 Rasl2tp - ok
20:37:35.0049 4476 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
20:37:35.0053 4476 RasMan - ok
20:37:35.0078 4476 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
20:37:35.0079 4476 RasPppoe - ok
20:37:35.0093 4476 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
20:37:35.0094 4476 RasSstp - ok
20:37:35.0116 4476 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
20:37:35.0118 4476 rdbss - ok
20:37:35.0126 4476 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
20:37:35.0126 4476 rdpbus - ok
20:37:35.0144 4476 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
20:37:35.0145 4476 RDPCDD - ok
20:37:35.0166 4476 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys
20:37:35.0168 4476 RDPDR - ok
20:37:35.0184 4476 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
20:37:35.0185 4476 RDPENCDD - ok
20:37:35.0194 4476 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
20:37:35.0195 4476 RDPREFMP - ok
20:37:35.0223 4476 RdpVideoMiniport (70cba1a0c98600a2aa1863479b35cb90) C:\Windows\system32\drivers\rdpvideominiport.sys
20:37:35.0223 4476 RdpVideoMiniport - ok
20:37:35.0243 4476 RDPWD (6d76e6433574b058adcb0c50df834492) C:\Windows\system32\drivers\RDPWD.sys
20:37:35.0244 4476 RDPWD - ok
20:37:35.0278 4476 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
20:37:35.0280 4476 rdyboost - ok
20:37:35.0305 4476 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
20:37:35.0306 4476 RemoteAccess - ok
20:37:35.0346 4476 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
20:37:35.0349 4476 RemoteRegistry - ok
20:37:35.0410 4476 rpcapd (b60f58f175de20a6739194e85b035178) C:\Program Files (x86)\WinPcap\rpcapd.exe
20:37:35.0411 4476 rpcapd - ok
20:37:35.0425 4476 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
20:37:35.0428 4476 RpcEptMapper - ok
20:37:35.0446 4476 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
20:37:35.0449 4476 RpcLocator - ok
20:37:35.0474 4476 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\System32\rpcss.dll
20:37:35.0479 4476 RpcSs - ok
20:37:35.0503 4476 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
20:37:35.0504 4476 rspndr - ok
20:37:35.0533 4476 RTL8023x64 (04c2d5bd8d0776320230978a0aec3bd0) C:\Windows\system32\DRIVERS\Rtnic64.sys
20:37:35.0534 4476 RTL8023x64 - ok
20:37:35.0575 4476 RTL8167 (afc12dfa4c7b089673ad67402ca19edb) C:\Windows\system32\DRIVERS\Rt64win7.sys
20:37:35.0578 4476 RTL8167 - ok
20:37:35.0601 4476 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys
20:37:35.0603 4476 s3cap - ok
20:37:35.0626 4476 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:37:35.0628 4476 SamSs - ok
20:37:35.0653 4476 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
20:37:35.0654 4476 sbp2port - ok
20:37:35.0750 4476 SBSDWSCService (794d4b48dfb6e999537c7c3947863463) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
20:37:35.0755 4476 SBSDWSCService - ok
20:37:35.0775 4476 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
20:37:35.0778 4476 SCardSvr - ok
20:37:35.0814 4476 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
20:37:35.0814 4476 scfilter - ok
20:37:35.0856 4476 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
20:37:35.0873 4476 Schedule - ok
20:37:35.0889 4476 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
20:37:35.0890 4476 SCPolicySvc - ok
20:37:35.0903 4476 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
20:37:35.0905 4476 SDRSVC - ok
20:37:35.0919 4476 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
20:37:35.0920 4476 secdrv - ok
20:37:35.0934 4476 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
20:37:35.0936 4476 seclogon - ok
20:37:35.0950 4476 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\system32\sens.dll
20:37:35.0953 4476 SENS - ok
20:37:35.0959 4476 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
20:37:35.0961 4476 SensrSvc - ok
20:37:35.0989 4476 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
20:37:35.0989 4476 Serenum - ok
20:37:36.0015 4476 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
20:37:36.0016 4476 Serial - ok
20:37:36.0024 4476 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys
20:37:36.0025 4476 sermouse - ok
20:37:36.0044 4476 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
20:37:36.0046 4476 SessionEnv - ok
20:37:36.0063 4476 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
20:37:36.0063 4476 sffdisk - ok
20:37:36.0068 4476 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
20:37:36.0068 4476 sffp_mmc - ok
20:37:36.0070 4476 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
20:37:36.0071 4476 sffp_sd - ok
20:37:36.0074 4476 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys
20:37:36.0074 4476 sfloppy - ok
20:37:36.0110 4476 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
20:37:36.0113 4476 SharedAccess - ok
20:37:36.0143 4476 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
20:37:36.0146 4476 ShellHWDetection - ok
20:37:36.0169 4476 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys
20:37:36.0170 4476 SiSRaid2 - ok
20:37:36.0188 4476 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys
20:37:36.0189 4476 SiSRaid4 - ok
20:37:36.0209 4476 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
20:37:36.0210 4476 Smb - ok
20:37:36.0231 4476 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
20:37:36.0234 4476 SNMPTRAP - ok
20:37:36.0241 4476 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
20:37:36.0243 4476 spldr - ok
20:37:36.0276 4476 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
20:37:36.0280 4476 Spooler - ok
20:37:36.0395 4476 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
20:37:36.0440 4476 sppsvc - ok
20:37:36.0511 4476 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
20:37:36.0514 4476 sppuinotify - ok
20:37:36.0568 4476 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
20:37:36.0570 4476 srv - ok
20:37:36.0593 4476 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
20:37:36.0594 4476 srv2 - ok
20:37:36.0608 4476 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
20:37:36.0609 4476 srvnet - ok
20:37:36.0631 4476 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
20:37:36.0635 4476 SSDPSRV - ok
20:37:36.0648 4476 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
20:37:36.0650 4476 SstpSvc - ok
20:37:36.0673 4476 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys
20:37:36.0673 4476 stexstor - ok
20:37:36.0711 4476 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
20:37:36.0716 4476 stisvc - ok
20:37:36.0734 4476 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys
20:37:36.0735 4476 storflt - ok
20:37:36.0758 4476 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys
20:37:36.0759 4476 storvsc - ok
20:37:36.0763 4476 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
20:37:36.0764 4476 swenum - ok
20:37:36.0795 4476 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
20:37:36.0799 4476 swprv - ok
20:37:36.0845 4476 Synth3dVsc (c3a39c4079305480972d29c44b868c78) C:\Windows\system32\drivers\synth3dvsc.sys
20:37:36.0846 4476 Synth3dVsc - ok
20:37:36.0964 4476 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
20:37:36.0988 4476 SysMain - ok
20:37:37.0105 4476 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
20:37:37.0108 4476 TabletInputService - ok
20:37:37.0160 4476 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
20:37:37.0164 4476 TapiSrv - ok
20:37:37.0174 4476 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
20:37:37.0176 4476 TBS - ok
20:37:37.0266 4476 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys
20:37:37.0275 4476 Tcpip - ok
20:37:37.0441 4476 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys
20:37:37.0450 4476 TCPIP6 - ok
20:37:37.0491 4476 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
20:37:37.0491 4476 tcpipreg - ok
20:37:37.0509 4476 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
20:37:37.0510 4476 TDPIPE - ok
20:37:37.0525 4476 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
20:37:37.0525 4476 TDTCP - ok
20:37:37.0537 4476 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
20:37:37.0539 4476 tdx - ok
20:37:37.0547 4476 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\DRIVERS\termdd.sys
20:37:37.0549 4476 TermDD - ok
20:37:37.0565 4476 terminpt (2b5bdff688ec9871d7ec5837833374e9) C:\Windows\system32\drivers\terminpt.sys
20:37:37.0565 4476 terminpt - ok
20:37:37.0609 4476 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
20:37:37.0614 4476 TermService - ok
20:37:37.0622 4476 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
20:37:37.0625 4476 Themes - ok
20:37:37.0647 4476 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
20:37:37.0649 4476 THREADORDER - ok
20:37:37.0662 4476 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
20:37:37.0666 4476 TrkWks - ok
20:37:37.0707 4476 truecrypt (8de922cd4fea6f83b10805df965b9a08) C:\Windows\system32\drivers\truecrypt.sys
20:37:37.0710 4476 truecrypt - ok
20:37:37.0739 4476 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
20:37:37.0741 4476 TrustedInstaller - ok
20:37:37.0755 4476 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
20:37:37.0755 4476 tssecsrv - ok
20:37:37.0766 4476 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
20:37:37.0767 4476 TsUsbFlt - ok
20:37:37.0770 4476 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys
20:37:37.0771 4476 TsUsbGD - ok
20:37:37.0792 4476 tsusbhub (e1748d04ae40118b62bc18ac86032192) C:\Windows\system32\drivers\tsusbhub.sys
20:37:37.0794 4476 tsusbhub - ok
20:37:37.0821 4476 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
20:37:37.0822 4476 tunnel - ok
20:37:37.0832 4476 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys
20:37:37.0834 4476 uagp35 - ok
20:37:37.0854 4476 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
20:37:37.0856 4476 udfs - ok
20:37:37.0877 4476 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
20:37:37.0880 4476 UI0Detect - ok
20:37:37.0895 4476 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
20:37:37.0895 4476 uliagpkx - ok
20:37:37.0919 4476 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
20:37:37.0919 4476 umbus - ok
20:37:37.0921 4476 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys
20:37:37.0922 4476 UmPass - ok
20:37:37.0950 4476 UmRdpService (a293dcd756d04d8492a750d03b9a297c) C:\Windows\System32\umrdp.dll
20:37:37.0954 4476 UmRdpService - ok
20:37:37.0979 4476 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
20:37:37.0982 4476 upnphost - ok
20:37:38.0011 4476 USBAAPL64 (fb251567f41bc61988b26731dec19e4b) C:\Windows\system32\Drivers\usbaapl64.sys
20:37:38.0011 4476 USBAAPL64 - ok
20:37:38.0037 4476 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
20:37:38.0037 4476 usbccgp - ok
20:37:38.0071 4476 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
20:37:38.0072 4476 usbcir - ok
20:37:38.0089 4476 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
20:37:38.0089 4476 usbehci - ok
20:37:38.0120 4476 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
20:37:38.0122 4476 usbhub - ok
20:37:38.0132 4476 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\DRIVERS\usbohci.sys
20:37:38.0134 4476 usbohci - ok
20:37:38.0142 4476 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\drivers\usbprint.sys
20:37:38.0142 4476 usbprint - ok
20:37:38.0166 4476 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
20:37:38.0167 4476 USBSTOR - ok
20:37:38.0191 4476 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
20:37:38.0191 4476 usbuhci - ok
20:37:38.0207 4476 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
20:37:38.0211 4476 UxSms - ok
20:37:38.0234 4476 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:37:38.0236 4476 VaultSvc - ok
20:37:38.0267 4476 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
20:37:38.0269 4476 vdrvroot - ok
20:37:38.0296 4476 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
20:37:38.0301 4476 vds - ok
20:37:38.0317 4476 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
20:37:38.0317 4476 vga - ok
20:37:38.0327 4476 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
20:37:38.0327 4476 VgaSave - ok
20:37:38.0330 4476 VGPU - ok
20:37:38.0344 4476 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
20:37:38.0345 4476 vhdmp - ok
20:37:38.0359 4476 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
20:37:38.0359 4476 viaide - ok
20:37:38.0377 4476 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys
20:37:38.0379 4476 vmbus - ok
20:37:38.0391 4476 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys
20:37:38.0391 4476 VMBusHID - ok
20:37:38.0419 4476 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
20:37:38.0420 4476 volmgr - ok
20:37:38.0442 4476 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
20:37:38.0445 4476 volmgrx - ok
20:37:38.0456 4476 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
20:37:38.0459 4476 volsnap - ok
20:37:38.0470 4476 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys
20:37:38.0471 4476 vsmraid - ok
20:37:38.0532 4476 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
20:37:38.0542 4476 VSS - ok
20:37:38.0637 4476 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
20:37:38.0639 4476 vwifibus - ok
20:37:38.0675 4476 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
20:37:38.0679 4476 W32Time - ok
20:37:38.0694 4476 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys
20:37:38.0695 4476 WacomPen - ok
20:37:38.0721 4476 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
20:37:38.0722 4476 WANARP - ok
20:37:38.0724 4476 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
20:37:38.0725 4476 Wanarpv6 - ok
20:37:38.0795 4476 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
20:37:38.0801 4476 WatAdminSvc - ok
20:37:38.0939 4476 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
20:37:38.0947 4476 wbengine - ok
20:37:39.0037 4476 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
20:37:39.0042 4476 WbioSrvc - ok
20:37:39.0061 4476 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
20:37:39.0065 4476 wcncsvc - ok
20:37:39.0082 4476 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
20:37:39.0085 4476 WcsPlugInService - ok
20:37:39.0106 4476 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys
20:37:39.0106 4476 Wd - ok
20:37:39.0134 4476 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
20:37:39.0137 4476 Wdf01000 - ok
20:37:39.0147 4476 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
20:37:39.0151 4476 WdiServiceHost - ok
20:37:39.0154 4476 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
20:37:39.0156 4476 WdiSystemHost - ok
20:37:39.0177 4476 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
20:37:39.0180 4476 WebClient - ok
20:37:39.0191 4476 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
20:37:39.0195 4476 Wecsvc - ok
20:37:39.0199 4476 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
20:37:39.0202 4476 wercplsupport - ok
20:37:39.0220 4476 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
20:37:39.0224 4476 WerSvc - ok
20:37:39.0259 4476 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
20:37:39.0260 4476 WfpLwf - ok
20:37:39.0276 4476 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
20:37:39.0276 4476 WIMMount - ok
20:37:39.0301 4476 WinDefend - ok
20:37:39.0305 4476 WinHttpAutoProxySvc - ok
20:37:39.0341 4476 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
20:37:39.0342 4476 Winmgmt - ok
20:37:39.0417 4476 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
20:37:39.0432 4476 WinRM - ok
20:37:39.0561 4476 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
20:37:39.0562 4476 WinUsb - ok
20:37:39.0611 4476 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
20:37:39.0617 4476 Wlansvc - ok
20:37:39.0670 4476 wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
20:37:39.0670 4476 wlcrasvc - ok
20:37:39.0777 4476 wlidsvc (2bacd71123f42cea603f4e205e1ae337) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
20:37:39.0806 4476 wlidsvc - ok
20:37:39.0892 4476 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
20:37:39.0894 4476 WmiAcpi - ok
20:37:39.0937 4476 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
20:37:39.0940 4476 wmiApSrv - ok
20:37:39.0961 4476 WMPNetworkSvc - ok
20:37:39.0984 4476 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
20:37:39.0986 4476 WPCSvc - ok
20:37:40.0002 4476 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
20:37:40.0006 4476 WPDBusEnum - ok
20:37:40.0009 4476 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
20:37:40.0010 4476 ws2ifsl - ok
20:37:40.0022 4476 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\system32\wscsvc.dll
20:37:40.0025 4476 wscsvc - ok
20:37:40.0027 4476 WSearch - ok
20:37:40.0107 4476 wuauserv (9df12edbc698b0bc353b3ef84861e430) C:\Windows\system32\wuaueng.dll
20:37:40.0140 4476 wuauserv - ok
20:37:40.0231 4476 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
20:37:40.0232 4476 WudfPf - ok
20:37:40.0260 4476 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
20:37:40.0261 4476 WUDFRd - ok
20:37:40.0284 4476 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
20:37:40.0287 4476 wudfsvc - ok
20:37:40.0304 4476 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
20:37:40.0307 4476 WwanSvc - ok
20:37:40.0346 4476 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
20:37:40.0386 4476 \Device\Harddisk0\DR0 - ok
20:37:40.0389 4476 MBR (0x1B8) (0792f22bcc85cfd3b28324561fffcabb) \Device\Harddisk1\DR1
20:37:42.0159 4476 \Device\Harddisk1\DR1 - ok
20:37:42.0194 4476 MBR (0x1B8) (4004072431421eb6987f1a76377d26f0) \Device\Harddisk2\DR2
20:37:42.0262 4476 \Device\Harddisk2\DR2 - ok
20:37:42.0714 4476 MBR (0x1B8) (671b81004fdd1588fa9ed1331c9ceca9) \Device\Harddisk3\DR3
20:37:42.0717 4476 \Device\Harddisk3\DR3 - ok
20:37:42.0721 4476 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk8\DR8
20:37:42.0725 4476 \Device\Harddisk8\DR8 - ok
20:37:42.0726 4476 Boot (0x1200) (3743d1562c2b81674ef7e95ef66472fb) \Device\Harddisk0\DR0\Partition0
20:37:42.0727 4476 \Device\Harddisk0\DR0\Partition0 - ok
20:37:42.0730 4476 Boot (0x1200) (c6fa14444dd76649147081ccb7fff087) \Device\Harddisk1\DR1\Partition0
20:37:42.0730 4476 \Device\Harddisk1\DR1\Partition0 - ok
20:37:42.0732 4476 Boot (0x1200) (12e8f42b72f26157c42d90620875e37c) \Device\Harddisk3\DR3\Partition0
20:37:42.0735 4476 \Device\Harddisk3\DR3\Partition0 - ok
20:37:42.0737 4476 Boot (0x1200) (ea5a25182ff054c01c08fa93417cf5ac) \Device\Harddisk8\DR8\Partition0
20:37:42.0740 4476 \Device\Harddisk8\DR8\Partition0 - ok
20:37:42.0740 4476 ============================================================
20:37:42.0740 4476 Scan finished
20:37:42.0740 4476 ============================================================
20:37:42.0776 0536 Detected object count: 0
20:37:42.0776 0536 Actual detected object count: 0




aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-05-10 20:40:29
-----------------------------
20:40:29.850 OS Version: Windows x64 6.1.7601 Service Pack 1
20:40:29.850 Number of processors: 4 586 0x402
20:40:29.850 ComputerName: DESKTOP UserName: Eric
20:40:30.746 Initialize success
20:40:31.384 AVAST engine defs: 12051001
20:40:47.372 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
20:40:47.374 Disk 0 Vendor: HDT722516DLA380 V43OA80A Size: 157066MB BusType: 3
20:40:47.380 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-1
20:40:47.382 Disk 1 Vendor: SAMSUNG_SP2504C VT100-38 Size: 238475MB BusType: 3
20:40:47.385 Disk 2 \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP1T1L0-5
20:40:47.386 Disk 2 Vendor: Maxtor_7Y250M0 YAR51HW0 Size: 239372MB BusType: 3
20:40:47.412 Disk 0 MBR read successfully
20:40:47.414 Disk 0 MBR scan
20:40:47.416 Disk 0 Windows 7 default MBR code
20:40:47.427 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 157065 MB offset 2048
20:40:47.440 Disk 0 scanning C:\Windows\system32\drivers
20:40:51.966 Service scanning
20:41:09.735 Modules scanning
20:41:09.740 Disk 0 trace - called modules:
20:41:09.751 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
20:41:09.755 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007dd6060]
20:41:09.757 3 CLASSPNP.SYS[fffff880019c643f] -> nt!IofCallDriver -> [0xfffffa8006e11580]
20:41:09.761 5 ACPI.sys[fffff88000eed7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8006e0f060]
20:41:10.267 AVAST engine scan C:\Windows
20:41:11.542 AVAST engine scan C:\Windows\system32
20:42:42.609 AVAST engine scan C:\Windows\system32\drivers
20:42:48.050 AVAST engine scan C:\Users\Eric
20:46:22.913 AVAST engine scan C:\ProgramData
20:46:53.964 Scan finished successfully
20:47:27.718 Disk 0 MBR has been saved successfully to "S:\Dropbox\Log\Desktop\MBR.dat"
20:47:27.722 The log file has been saved successfully to "S:\Dropbox\Log\Desktop\20120510_aswMBR.txt"

Attached Files


Edited by 3maz, 10 May 2012 - 08:10 PM.


#5 nasdaq

nasdaq

  • Malware Response Team
  • 40,213 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:03 PM

Posted 11 May 2012 - 09:21 AM

I'm curious about those nt!IofCallDriver things though.

Your log looks clean to me.

If you want you can always scan your log for malware at Jotti.

>>> Run Jotti's malware scan: Please copy this line (in bold):
S:\Dropbox\Log\Desktop\MBR.dat
  • Go to Jotti's malware scan and click the Browse button,
  • A window will open, right-click in the File name field and choose Paste.
  • Click the Submit button and let the scan run uninterrupted.
  • At the end right-click the Permalink button and choose "Copy the link". Posted Image
  • Open Notepad (Start => All Programs => Accessories) and click "Edition" => "Paste".
Please copy and paste these Permalink in your next reply.
If Jotti is busy, please go to http://www.virustotal.com
===

Please download ComboFix from any of the links below, and save it to your desktop. For information regarding this download, please visit this web page: http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

IMPORTANT....

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Do not install any other programs until this if fixed.


How to : Disable Anti-virus and Firewall...
http://www.bleepingcomputer.com/forums/topic114351.html

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt
Note:
Do not mouse click ComboFix's window while it's running. That may cause it to stall


Note: If you have difficulty properly disabling your protective programs, refer to this link --> http://www.bleepingcomputer.com/forums/topic114351.html

#6 3maz

3maz
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:04:03 PM

Posted 12 May 2012 - 02:41 AM

Posted Image



Jotti's malware scan
Filename: MBR.dat Status: Scan finished. 0 out of 20 scanners reported malware. Scan taken on: Sat 12 May 2012 09:35:54 (CET) Permalink



Additional info
File size: 512 bytes
Filetype: x86 boot sector
MD5: b5ad5369b84072acf0756dfaeac78c09
SHA1: 4db44cc9317cdc13a87ba28e1dd931ab91cd74a1




Scanners
[ArcaVir]
2012-05-12 Found nothing
[Frisk F-Prot Antivirus]
2012-05-11 Found nothing
[Avast! antivirus]
2012-05-11 Found nothing
[F-Secure Anti-Virus]
2012-05-12 Found nothing
[Grisoft AVG Anti-Virus]
2012-05-11 Found nothing
[G DATA]
2012-05-12 Found nothing
[Avira AntiVir]
2012-05-11 Found nothing
[Ikarus]
2012-05-12 Found nothing
[Softwin BitDefender]
2012-05-12 Found nothing
[Kaspersky Anti-Virus]
2012-05-12 Found nothing
[ClamAV]
2012-05-12 Found nothing
[Panda Antivirus]
2012-05-11 Found nothing
[CPsecure]
2012-05-12 Found nothing
[Quick Heal]
2012-05-11 Found nothing
[Dr.Web]
2012-05-12 Found nothing
[Sophos]
2012-05-12 Found nothing
[Emsisoft Anti-Malware]
2012-05-12 Found nothing
[VirusBlokAda VBA32]
2012-05-11 Found nothing
[ESET]
2012-05-11 Found nothing
[VirusBuster]
2012-05-11 Found nothing


Scan a file - Hash search - Frequently Asked Questions - Privacy policy

© 2004-2012 Jotti <jotti@jotti.org>

#7 3maz

3maz
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:04:03 PM

Posted 12 May 2012 - 08:32 AM

OK, here is the combofix log....

ComboFix 12-05-12.01 - Eric 05/12/2012 8:52.4.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8191.6298 [GMT -4:00]
Running from: c:\users\Eric\Desktop\cfixmeup.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2012-04-12 to 2012-05-12 )))))))))))))))))))))))))))))))
.
.
2012-05-12 12:56 . 2012-05-12 12:56 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-05-12 12:44 . 2012-05-12 12:44 -------- d-----w- c:\program files\Microsoft Silverlight
2012-05-12 12:44 . 2012-05-12 12:44 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2012-05-11 22:43 . 2012-05-11 22:44 -------- d-----w- c:\program files (x86)\Nmap
2012-05-11 17:31 . 2012-04-13 08:46 8917360 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6864A3F8-65AE-4CEA-B646-289ADA52B4CF}\mpengine.dll
2012-05-11 04:20 . 2012-05-11 04:20 -------- d-----w- c:\program files (x86)\Secunia
2012-05-11 00:28 . 2012-05-11 00:27 955848 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-05-10 23:52 . 2012-03-06 23:01 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-05-10 23:52 . 2012-03-06 23:04 337240 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-05-10 23:52 . 2012-03-06 23:02 53080 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-05-10 23:52 . 2012-03-06 23:01 59224 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-05-10 23:52 . 2012-03-06 23:04 819032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-05-09 07:01 . 2012-05-09 07:01 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-05-09 07:00 . 2012-05-09 07:00 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
2012-05-09 04:56 . 2012-03-03 06:35 1544704 ----a-w- c:\windows\system32\DWrite.dll
2012-05-09 04:56 . 2012-03-03 05:31 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-05-09 04:56 . 2012-03-31 06:05 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-09 04:56 . 2012-03-31 04:39 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-05-09 04:56 . 2012-03-31 04:39 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-05-09 04:56 . 2012-03-31 03:10 3146240 ----a-w- c:\windows\system32\win32k.sys
2012-05-09 04:56 . 2012-03-17 07:58 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-05-09 04:55 . 2012-03-30 11:35 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-05-09 04:55 . 2012-03-31 05:42 1732096 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2012-05-09 04:55 . 2012-03-31 05:40 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2012-05-09 04:55 . 2012-03-31 05:40 1367552 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2012-05-09 04:55 . 2012-03-31 05:40 1393664 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2012-05-09 04:55 . 2012-03-31 04:29 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2012-05-08 04:36 . 2012-05-08 04:36 -------- d-----w- c:\program files (x86)\Box Edit
2012-05-07 21:37 . 2009-05-18 17:17 34152 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-05-07 21:35 . 2012-05-07 21:36 -------- d-----w- c:\programdata\Apple
2012-05-05 01:56 . 2012-05-05 01:56 8744608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-05-03 06:00 . 2012-05-03 06:20 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-05-03 06:00 . 2012-05-03 06:03 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2012-05-03 04:59 . 2012-05-03 04:59 27256 ----a-w- c:\windows\system32\drivers\FixZeroAccess.sys
2012-05-03 04:27 . 2012-05-03 04:27 -------- d-----w- c:\program files\Microsoft Baseline Security Analyzer 2
2012-05-03 00:03 . 2012-05-03 00:03 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-04-30 11:44 . 2012-04-30 11:44 -------- d-----w- c:\program files (x86)\WinPcap
2012-04-30 11:43 . 2012-04-30 11:44 -------- d-----w- c:\program files\Wireshark
2012-04-28 13:59 . 2012-05-05 11:16 -------- d-----w- C:\Downloads
2012-04-28 09:29 . 2012-04-28 09:30 -------- d-----w- c:\program files (x86)\Free Download Manager
2012-04-28 09:29 . 2012-04-28 09:29 -------- d-----w- c:\program files (x86)\FileZilla FTP Client
2012-04-28 06:13 . 2012-04-28 06:13 -------- d-----w- c:\programdata\Brother
2012-04-27 11:17 . 2012-04-27 11:18 -------- d-----w- c:\program files (x86)\AutoHotkey
2012-04-27 11:05 . 2012-03-14 22:23 65024 ----a-w- c:\windows\system32\pdfcmon.dll
2012-04-27 11:05 . 2005-04-16 00:58 1071088 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2012-04-27 11:05 . 2004-03-09 05:00 662288 ----a-w- c:\windows\SysWow64\MSCOMCT2.OCX
2012-04-27 11:05 . 1998-06-24 05:00 137000 ----a-w- c:\windows\SysWow64\MSMAPI32.OCX
2012-04-27 11:05 . 2012-04-27 11:05 -------- d-----w- c:\program files (x86)\PDFCreator
2012-04-27 11:05 . 1998-07-06 05:00 23552 ----a-w- c:\windows\SysWow64\MSMPIDE.DLL
2012-04-27 10:57 . 2012-04-27 10:57 -------- d-----w- c:\program files (x86)\PicPick
2012-04-27 07:29 . 2012-05-11 00:20 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-27 07:29 . 2012-05-11 00:20 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-04-27 07:29 . 2012-04-27 07:29 -------- d-----w- c:\windows\SysWow64\Macromed
2012-04-27 07:29 . 2012-04-27 07:29 -------- d-----w- c:\windows\system32\Macromed
2012-04-27 00:10 . 2012-04-27 00:10 -------- d-----w- c:\program files (x86)\KeePass Password Safe 2
2012-04-27 00:04 . 2012-04-27 00:04 -------- d-----w- c:\program files (x86)\MSECache
2012-04-26 23:17 . 2012-04-30 06:11 -------- d-----w- c:\program files (x86)\LastPass
2012-04-23 14:40 . 2011-03-02 11:43 203264 ----a-w- c:\windows\system32\unrar.dll
2012-04-23 14:40 . 2012-03-22 18:00 92160 ----a-w- c:\windows\system32\ff_vfw.dll
2012-04-23 14:40 . 2012-04-23 14:40 -------- d-----w- c:\program files\K-Lite Codec Pack x64
2012-04-23 14:31 . 2012-04-23 14:32 -------- d-----w- c:\program files (x86)\XnView
2012-04-23 14:28 . 2012-04-23 14:28 230864 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2012-04-23 14:27 . 2012-04-23 14:28 -------- d-----w- c:\program files\TrueCrypt
2012-04-23 01:14 . 2012-04-23 01:14 -------- d-----w- c:\programdata\HitmanPro
2012-04-22 23:32 . 2011-12-21 18:14 151552 ----a-w- c:\windows\SysWow64\ac3acm.acm
2012-04-22 23:32 . 2011-06-24 15:44 243200 ----a-w- c:\windows\SysWow64\xvidvfw.dll
2012-04-22 23:32 . 2011-06-24 15:28 650752 ----a-w- c:\windows\SysWow64\xvidcore.dll
2012-04-22 23:32 . 2011-03-02 11:43 175616 ----a-w- c:\windows\SysWow64\unrar.dll
2012-04-22 23:32 . 2008-09-24 19:41 839680 ----a-w- c:\windows\SysWow64\lameACM.acm
2012-04-22 23:32 . 2012-03-22 18:00 79360 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2012-04-22 23:32 . 2012-04-22 23:32 -------- d-----w- c:\program files (x86)\K-Lite Codec Pack
2012-04-22 22:23 . 2012-04-22 22:23 -------- d-----w- c:\program files (x86)\ImgBurn
2012-04-22 19:36 . 2012-04-22 19:36 -------- d-----w- c:\program files (x86)\MozBackup
2012-04-22 19:16 . 2012-04-28 09:42 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-04-22 19:16 . 2012-04-22 19:16 -------- d-----w- c:\programdata\Malwarebytes
2012-04-22 19:16 . 2012-04-04 19:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-22 19:08 . 2012-04-22 19:08 -------- d-----w- c:\program files\Microsoft Network Monitor 3
2012-04-22 18:35 . 2012-04-22 18:35 -------- d-----w- c:\program files\HashTab Shell Extension
2012-04-22 18:29 . 2012-04-22 18:29 -------- d-----w- c:\program files (x86)\VirusTotalUploader2
2012-04-22 17:25 . 2012-04-22 17:25 -------- d-----w- c:\program files (x86)\Google
2012-04-22 17:25 . 2012-03-06 23:15 258520 ----a-w- c:\windows\system32\aswBoot.exe
2012-04-22 17:25 . 2012-03-06 23:01 69976 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-04-22 17:24 . 2012-03-06 23:15 41184 ----a-w- c:\windows\avastSS.scr
2012-04-22 17:24 . 2012-03-06 23:15 201352 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-04-22 17:24 . 2012-04-22 17:24 -------- d-----w- c:\programdata\AVAST Software
2012-04-22 17:24 . 2012-04-22 17:24 -------- d-----w- c:\program files\AVAST Software
2012-04-22 16:01 . 2012-05-11 00:27 839112 ----a-w- c:\windows\system32\deployJava1.dll
2012-04-22 16:01 . 2012-05-11 00:27 -------- d-----w- c:\program files\Java
2012-04-22 15:41 . 2012-05-11 04:22 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird
2012-04-22 15:32 . 2012-04-22 15:32 -------- d-----w- c:\windows\SysWow64\ShellExt
2012-04-22 15:32 . 2012-04-22 15:32 -------- d-----w- c:\windows\system32\ShellExt
2012-04-22 13:40 . 2012-04-22 13:40 -------- d-----w- c:\program files (x86)\uTorrent
2012-04-22 11:07 . 2012-04-22 11:12 -------- d-----w- c:\program files (x86)\Windows Live
2012-04-22 11:06 . 2012-04-22 11:07 -------- d-----w- c:\program files\Windows Live
2012-04-22 11:05 . 2012-04-22 11:05 -------- d-----w- c:\program files (x86)\Common Files\Windows Live
2012-04-22 09:38 . 2012-05-07 08:55 -------- d-----w- c:\programdata\Kaspersky Lab
2012-04-22 08:21 . 2012-04-22 08:21 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2012-04-22 05:18 . 2012-04-22 05:18 419840 ----a-w- c:\windows\system32\wrap_oal.dll
2012-04-22 05:18 . 2012-04-22 05:18 413696 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-04-22 05:18 . 2012-04-22 05:18 111616 ----a-w- c:\windows\system32\OpenAL32.dll
2012-04-22 05:18 . 2012-04-22 05:18 102400 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2012-04-22 05:18 . 2012-04-22 05:18 -------- d-----w- c:\program files (x86)\OpenAL
2012-04-22 03:37 . 2009-08-19 20:00 359424 ------w- c:\windows\system32\CmiInstallResAll64.dll
2012-04-22 03:37 . 2006-10-06 09:45 524768 ----a-w- c:\windows\difxapi.dll
2012-04-20 08:43 . 2012-04-20 08:43 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2012-04-19 13:51 . 2012-04-19 13:51 -------- d-----w- c:\program files\Microsoft Synchronization Services
2012-04-19 13:51 . 2012-04-19 13:51 -------- d-----w- c:\windows\PCHEALTH
2012-04-19 13:51 . 2012-04-19 13:51 -------- d-----w- c:\program files\Microsoft Sync Framework
2012-04-19 13:51 . 2012-04-19 13:51 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2012-04-19 13:49 . 2012-04-19 13:49 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2012-04-19 13:48 . 2012-04-19 13:48 -------- d-----w- c:\program files\Microsoft Analysis Services
2012-04-19 13:48 . 2012-04-19 13:48 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2012-04-19 13:48 . 2012-05-09 07:08 -------- d-----w- c:\programdata\Microsoft Help
2012-04-19 13:48 . 2012-04-19 13:48 -------- d-----r- C:\MSOCache
2012-04-19 13:17 . 2012-04-19 13:17 -------- d-----w- c:\program files (x86)\Notepad++
2012-04-19 12:46 . 2012-04-22 05:17 -------- d-----w- c:\program files\7-Zip
2012-04-19 10:41 . 2012-04-19 07:28 -------- d-----w- c:\windows\Panther
2012-04-19 10:41 . 2012-04-19 10:41 -------- d-----w- C:\Boot
2012-04-19 09:25 . 2012-04-19 13:51 -------- d-----w- c:\program files (x86)\Microsoft.NET
2012-04-19 09:25 . 2012-05-12 12:45 -------- d-sh--w- c:\windows\Installer
2012-04-19 09:18 . 2012-04-19 09:18 -------- d-----w- c:\programdata\NVIDIA Corporation
2012-04-19 09:18 . 2012-04-19 09:18 -------- d-----w- c:\program files\NVIDIA Corporation
2012-04-19 09:16 . 2012-04-19 09:16 -------- d-----w- c:\windows\SysWow64\Wat
2012-04-19 09:16 . 2012-04-19 09:16 -------- d-----w- c:\windows\system32\Wat
2012-04-19 08:46 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-22 11:06 . 2011-03-28 22:36 19352 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-02-23 14:18 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-02-15 15:01 . 2012-02-15 15:01 52736 ----a-w- c:\windows\system32\drivers\usbaapl64.sys
2012-02-15 15:01 . 2012-02-15 15:01 4547944 ----a-w- c:\windows\system32\usbaaplrc.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-05-03_06.48.36 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-08-31 03:05 . 2011-08-31 03:05 50536 c:\windows\SysWOW64\jdns_sd.dll
+ 2011-08-31 03:05 . 2011-08-31 03:05 73064 c:\windows\SysWOW64\dnssd.dll
+ 2011-08-31 03:05 . 2011-08-31 03:05 83816 c:\windows\SysWOW64\dns-sd.exe
+ 2012-05-04 21:12 . 2012-05-12 12:57 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-07-14 04:54 . 2012-04-30 21:19 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-05-12 12:57 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-04-30 21:19 65536 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-05-12 12:57 65536 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-05-12 12:57 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-04-30 21:19 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-05-09 07:00 . 2012-05-12 12:44 16384 c:\windows\SysWOW64\%APPDATA%\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 00:21 . 2009-07-14 01:41 88064 c:\windows\system32\WpdMtpUS.dll
+ 2010-11-21 03:09 . 2012-05-12 12:39 31876 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-05-12 12:39 34110 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-08-31 03:05 . 2011-08-31 03:05 61288 c:\windows\system32\jdns_sd.dll
+ 2012-05-07 21:37 . 2009-05-18 17:17 34152 c:\windows\system32\DRVSTORE\GEARAspiWD_B60A2DA9F47E0A7F3329B57AA751F1789961A8BE\x64\GEARAspiWDM.sys
- 2009-07-14 05:30 . 2012-05-02 22:40 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2009-07-14 05:30 . 2012-05-07 23:46 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2012-02-15 15:01 . 2012-02-15 15:01 52736 c:\windows\system32\DriverStore\FileRepository\usbaapl64.inf_amd64_neutral_c111aaecb61e9a2b\usbaapl64.sys
+ 2011-08-02 20:38 . 2011-08-02 20:38 22528 c:\windows\system32\DriverStore\FileRepository\netaapl64.inf_amd64_neutral_dc2cbd989eec1514\netaapl64.sys
+ 2010-11-21 03:23 . 2010-11-21 03:23 41984 c:\windows\system32\drivers\winusb.sys
+ 2011-12-16 14:20 . 2011-12-16 14:20 17976 c:\windows\system32\drivers\psi_mf.sys
+ 2011-08-02 20:38 . 2011-08-02 20:38 22528 c:\windows\system32\drivers\netaapl64.sys
+ 2011-08-31 03:05 . 2011-08-31 03:05 85864 c:\windows\system32\dnssd.dll
+ 2011-08-31 03:05 . 2011-08-31 03:05 96104 c:\windows\system32\dns-sd.exe
- 2012-04-19 09:48 . 2012-05-01 11:09 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-04-19 09:48 . 2012-05-12 12:43 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-04-19 09:48 . 2012-05-12 12:43 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2012-04-19 09:48 . 2012-05-01 11:09 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-05-01 11:09 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-05-12 12:43 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-05-09 07:01 . 2012-05-12 12:44 16384 c:\windows\system32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 04:46 . 2012-05-10 23:53 97056 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2011-11-22 03:57 . 2011-11-22 03:57 68880 c:\windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll
+ 2011-12-15 18:01 . 2011-12-15 18:01 68880 c:\windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll
- 2011-11-22 02:31 . 2011-11-22 02:31 57616 c:\windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
+ 2011-12-15 17:08 . 2011-12-15 17:08 57616 c:\windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 87408 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 87408 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 93024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 93024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 35688 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 35688 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 11120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 11120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 17784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 17784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 58240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 58240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 44920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 44920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 37240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 37240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 64352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 64352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 51032 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 51032 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 50552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 50552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 81784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 81784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 81800 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 81800 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 39784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 39784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 68952 c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 68952 c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 62880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.ApplicationServer.Applications\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Windows.ApplicationServer.Applications.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 62880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.ApplicationServer.Applications\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Windows.ApplicationServer.Applications.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 12128 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2012-04-19 09:59 . 2012-04-19 09:59 12128 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 97680 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 97680 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 17240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 17240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 94552 c:\windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 94552 c:\windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 91488 c:\windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 91488 c:\windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-05-09 07:04 . 2012-05-09 07:04 78168 c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 78168 c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 81248 c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-05-09 07:04 . 2012-05-09 07:04 81248 c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-04-11 08:55 . 2012-04-11 08:55 41472 c:\windows\Installer\d6de5.msi
+ 2012-04-19 13:53 . 2012-05-09 07:08 34144 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\oisicon.exe
- 2012-04-19 13:53 . 2012-04-20 08:47 34144 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\oisicon.exe
- 2012-04-19 13:53 . 2012-04-20 08:47 42848 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\msouc.exe
+ 2012-04-19 13:53 . 2012-05-09 07:08 42848 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\msouc.exe
+ 2012-04-19 13:53 . 2012-05-09 07:08 19296 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\cagicon.exe
- 2012-04-19 13:53 . 2012-04-20 08:47 19296 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\cagicon.exe
+ 2012-05-07 21:36 . 2012-05-07 21:36 27136 c:\windows\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\AppleSoftwareUpdateIco.exe
+ 2012-05-09 07:12 . 2012-05-09 07:12 10240 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Serializ#\7fa267d10b2df6dbd00d00d130715f0a\System.Xml.Serialization.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 43520 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Pres#\054fce9466c6cef615b2f7cc9ff4e7f8\System.Windows.Presentation.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 86016 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Applicat#\ff78ec1b5bf38a8fb74c2d4f41bb308a\System.Web.ApplicationServices.ni.dll
+ 2012-05-09 07:10 . 2012-05-09 07:10 97792 c:\windows\assembly\NativeImages_v4.0.30319_64\System.AddIn.Contra#\e144d0028365c62178eb0662911ac910\System.AddIn.Contract.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 14336 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualC\93295f3771dc9e5be2d49d5f5d76a7a6\Microsoft.VisualC.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 55808 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\ae1aa0da6c3f69ae100effa75c1e2316\Microsoft.Office.Tools.v4.0.Framework.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 28160 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\3f51f3b0ffc904203234c8b32f98c31f\Microsoft.Office.Tools.ni.dll
+ 2012-05-09 07:07 . 2012-05-09 07:07 10752 c:\windows\assembly\NativeImages_v4.0.30319_64\dfsvc\5ea625ce2d6c08687f70cb81a003a28b\dfsvc.ni.exe
+ 2012-05-09 07:07 . 2012-05-09 07:07 58368 c:\windows\assembly\NativeImages_v4.0.30319_64\Accessibility\061cbee19075e086d675a9e1f65725d7\Accessibility.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 96768 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\05787d96761cf20b76b927ace10ef1d3\UIAutomationProvider.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 35328 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Pres#\f3a9c6e87bfa4bab3689ec1cdb56964f\System.Windows.Presentation.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 71680 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Applicat#\9b418f37f4594806e1f4b0ed6d083a95\System.Web.ApplicationServices.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 82432 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\d09c237ee72af3935f1a01388ef8e315\System.ServiceModel.Channels.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 78848 c:\windows\assembly\NativeImages_v4.0.30319_32\System.AddIn.Contra#\59be5fb54e018032511415f0b0523ee3\System.AddIn.Contract.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 11776 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualC\46f273930666397a8cb538ffe9190eef\Microsoft.VisualC.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 21504 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\d1863e1b75c767daef24a3b149faddac\Microsoft.Office.Tools.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 45056 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\31173593560b0b4db1a7b6025dabc5e5\Microsoft.Office.Tools.v4.0.Framework.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 44544 c:\windows\assembly\NativeImages_v4.0.30319_32\Accessibility\62c1a496dff99a6e5f5e4278d31ca4c1\Accessibility.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 60416 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Pres#\fb4bc14964a1d415bdbe55b62ce73a52\System.Windows.Presentation.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 54784 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\acd8bdefdcae0ce7c27b5ec016ef865c\System.Web.DynamicData.Design.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 90624 c:\windows\assembly\NativeImages_v2.0.50727_64\stdole\ee709a01b51c82626f4b2c1173f2db28\stdole.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 72192 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFontCac#\78f495970511b726a0ca7b8119360e25\PresentationFontCache.ni.exe
+ 2012-05-09 07:28 . 2012-05-09 07:28 61952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCFFRast#\1a359e9b908a2565c546a8ca04b241c2\PresentationCFFRasterizer.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 33792 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Run#\9d57c4bbbc0b3243046fc7839da71b00\Microsoft.WSMan.Runtime.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 43520 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\d6578432220dbabf2b15027681327bf8\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 40448 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\66deb65a87750efddf62d1e0c0655352\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 36864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\4b6402dc918e41b8de8c501f29833d91\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 45056 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\28545d2b6a0aaef4aa168f9808603bc5\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 70144 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\1d8a17a2c1416a8ad4d6ad2a28b4c5fd\Microsoft.Windows.Diagnosis.SDEngine.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\0abc7256549c204f39af7dcc52c9e5d5\Microsoft.Windows.Diagnosis.SDHost.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 45056 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\d84c14e69b88aeac74de3f6805b900e7\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 71680 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\abd9d2880ca61bf077d60419f5ec1114\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\90084df18546aa62b4341a272ea71d30\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 93696 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\75909fbd25e848d0425e03df4c06a00b\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 43520 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\7003996ae5bd140e50c6a12a7c419910\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 86016 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\397ef046a0d464801359654f6df589be\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\317ca97e8f47080ea7950654db36ece0\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 84992 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\2d07593d9552f036c38c9b15b6355390\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 87040 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\07f7dae1df42a6bce3126ce63ea0564e\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.ni.dll
+ 2012-05-09 07:27 . 2012-05-09 07:27 32256 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualC\3c3a6cce983114e7406e0a6e6116ecd8\Microsoft.VisualC.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 64000 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\da47c045fb26852f5f85c81daf7283ad\Microsoft.Security.ApplicationId.PolicyManagement.PolicyEngineApi.Interop.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 66048 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\470be8218256dec2c8a1a503b70feab1\Microsoft.Security.ApplicationId.PolicyManagement.XmlHelper.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 35840 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\44ff43026ea2bdd0956086fb761816a1\Microsoft.Office.InfoPath.Permission.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 65536 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\6ab0575bf49b60fd4b697d47e1754072\Microsoft.MediaCenter.iTv.Hosting.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 40960 c:\windows\assembly\NativeImages_v2.0.50727_64\LoadMxf\1569a004b1f41193818e3b3777f2c73d\LoadMxf.ni.exe
+ 2012-05-09 07:33 . 2012-05-09 07:33 64000 c:\windows\assembly\NativeImages_v2.0.50727_64\ipdmctrl\f368a0ed84f9474291c63e15bb7dc20f\ipdmctrl.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 49664 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUPnP\3ee98e8b2084e27d65953bbd7e362bf8\ehiUPnP.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 93184 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiTVMSMusic\1cd9f92749d29b9fd61fcb1c4ae84294\ehiTVMSMusic.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 28672 c:\windows\assembly\NativeImages_v2.0.50727_64\dfsvc\0811f67973c32efb2bfad62a4a2592b5\dfsvc.ni.exe
+ 2012-05-09 07:31 . 2012-05-09 07:31 33280 c:\windows\assembly\NativeImages_v2.0.50727_64\AuditPolicyGPManage#\e5caecdfb99f9de3031152786ee208d9\AuditPolicyGPManagedStubs.Interop.ni.dll
+ 2012-05-09 07:28 . 2012-05-09 07:28 78848 c:\windows\assembly\NativeImages_v2.0.50727_64\Accessibility\ae9311dcb0e713330a2a86b04cf361dc\Accessibility.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 61440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\46c90378e984963ce2acf8b3fd7703ed\WindowsLiveWriter.ni.exe
+ 2012-05-09 07:36 . 2012-05-09 07:36 80896 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b139a1cda26d066860aaa83ff1f0ff91\WindowsLive.Writer.Passport.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ca2eff60beb3ba00a529a2d42dceca22\UIAutomationProvider.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\66d750f3f8dde0cc865f921497ab3545\System.Windows.Presentation.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\c1ea7869d01b1b668de2181be6ebca56\System.Web.DynamicData.Design.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\543b0e12423bcec010bdd2ac27c5dc04\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\f34410ab8e82063735d876533db26c49\System.AddIn.Contract.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 44032 c:\windows\assembly\NativeImages_v2.0.50727_32\stdole\d246780b91fd9f6393e85fb13bde94a6\stdole.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\d24744f15243e28ea541a459ff7ff5d5\PresentationFontCache.ni.exe
+ 2012-05-09 07:26 . 2012-05-09 07:26 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5a9d0ff936810991cedd098fe006a9be\PresentationCFFRasterizer.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 79872 c:\windows\assembly\NativeImages_v2.0.50727_32\napcrypt\87a30ba337ed55d0905f19742e2985bc\napcrypt.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 17920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Run#\9f2e8e0df9ff39ad21088f1d66cfadb1\Microsoft.WSMan.Runtime.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 23040 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\d797123d55bb7b823120d0a7ffbbc2a7\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 32256 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\cb8ad29814d9e5589bd400d38e7a0b10\Microsoft.Windows.Diagnosis.SDHost.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 21504 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\cb42a0f25b7608b2675080081b03f6e5\Microsoft.Windows.Diagnosis.SDEngine.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 25088 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\c6e9143be5afb36345875d56b61c444f\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 19968 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\91767cf3facefe10e00734c815e925ad\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 27136 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\66cd99d2f576cde047074e98bd5e1848\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 86528 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\4308e1bdc640e1c3f1ea966e84e48900\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\06fcf2fbbe38d9425fc49d935498ec93\Microsoft.Vsa.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 51712 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\be59506a77d76e325dbb02a4ef651eff\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 86016 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\baca9a6ad57bf3a4e4fca51e11846f13\Microsoft.VisualStudio.Tools.Office.Outlook.HostAdapter.v10.0.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 66560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\a516cad7285e7506dc477e03c7468aac\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 35328 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\a3d7d37ccd26595b9858116ac8e78e42\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 58368 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\a306bdd890d9250b9cb4c03876f3b146\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\9e572d1a5f468ae4226d9c74a54dbf5a\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 43008 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\4d661ba2b6ac1a23427070f799fd540c\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 28160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\443eceb48c4c76162ef874395f612590\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 42496 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\11852ce9e3c8a47a9f194e2671a2597f\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 28160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\03f7e17a9422755c383ec2100e178a32\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.ni.dll
+ 2012-05-09 07:25 . 2012-05-09 07:25 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\55c57057dc81a5e8c5bde3a230f0bcb9\Microsoft.VisualC.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 21504 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\c8831ecadb3b99c04fdde12217e715cb\Microsoft.Security.ApplicationId.PolicyManagement.PolicyEngineApi.Interop.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 39936 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\54c9d51df5b739db67a270b421af5fde\Microsoft.Security.ApplicationId.PolicyManagement.XmlHelper.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e3ef400b1f37e4d3b79a42a8a602ea02\Microsoft.Build.Framework.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\2095344bf8c40f8baa94ba53a993fb4c\Microsoft.Build.Framework.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 60416 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\dc93539af5a961641a26ada75f730136\ehiUserXp.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\53d03b0e238c77cf7e5ac88e02aecd2c\dfsvc.ni.exe
+ 2012-05-09 07:36 . 2012-05-09 07:36 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\AuditPolicyGPManage#\2ebfc41cb0193cb129521d80ec206da7\AuditPolicyGPManagedStubs.Interop.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\2ec98ab0193d64e95b7d09d094deed97\Accessibility.ni.dll
+ 2012-04-19 14:24 . 2012-05-12 11:46 3108 c:\windows\system32\wdi\ERCQueuedResolutions.dat
- 2012-04-19 14:24 . 2012-05-02 09:46 3108 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2012-04-19 09:04 . 2012-05-12 12:39 8172 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2394762389-1655812683-3179763728-1000_UserData.bin
- 2012-05-03 06:40 . 2012-05-03 06:40 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-05-12 12:57 . 2012-05-12 12:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-05-12 12:57 . 2012-05-12 12:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-05-03 06:40 . 2012-05-03 06:40 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-05-09 07:14 . 2012-05-09 07:14 9216 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Serializ#\4b540b784465ca3f0742990e5af444e3\System.Xml.Serialization.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 9728 c:\windows\assembly\NativeImages_v4.0.30319_32\dfsvc\fd866b4158c3bd2a26c875f2896c5573\dfsvc.ni.exe
+ 2012-05-05 01:56 . 2012-05-11 00:20 351904 c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_Plugin.exe
+ 2012-04-27 07:29 . 2012-05-11 00:20 257696 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2012-05-07 21:37 . 2008-04-17 16:12 107368 c:\windows\SysWOW64\GEARAspi.dll
+ 2011-08-31 03:05 . 2011-08-31 03:05 178536 c:\windows\SysWOW64\dnssdX.dll
+ 2009-07-14 00:21 . 2009-07-14 01:41 297984 c:\windows\system32\WpdMtp.dll
+ 2012-04-19 10:24 . 2012-05-07 02:55 149108 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2009-07-14 02:36 . 2012-05-03 06:45 623940 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-05-12 12:34 623940 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2012-05-03 06:45 106316 c:\windows\system32\perfc009.dat
+ 2009-07-14 02:36 . 2012-05-12 12:34 106316 c:\windows\system32\perfc009.dat
+ 2012-05-05 01:56 . 2012-05-11 00:20 630944 c:\windows\system32\Macromed\Flash\FlashUtil64_11_2_202_235_Plugin.exe
+ 2012-05-11 00:28 . 2012-05-11 00:27 268744 c:\windows\system32\javaws.exe
+ 2012-05-11 00:27 . 2012-05-11 00:27 189384 c:\windows\system32\javaw.exe
+ 2012-05-11 00:27 . 2012-05-11 00:27 188872 c:\windows\system32\java.exe
+ 2012-05-07 21:37 . 2008-04-17 16:12 126312 c:\windows\system32\GEARAspi64.dll
- 2009-07-14 04:45 . 2012-04-19 14:25 414656 c:\windows\system32\FNTCACHE.DAT
+ 2009-07-14 04:45 . 2012-05-09 07:25 414656 c:\windows\system32\FNTCACHE.DAT
+ 2012-05-07 21:37 . 2008-04-17 16:12 126312 c:\windows\system32\DRVSTORE\GEARAspiWD_B60A2DA9F47E0A7F3329B57AA751F1789961A8BE\x64\GEARAspi64.dll
+ 2012-05-07 21:37 . 2008-04-17 16:12 107368 c:\windows\system32\DRVSTORE\GEARAspiWD_B60A2DA9F47E0A7F3329B57AA751F1789961A8BE\x64\GEARAspi.dll
+ 2009-07-14 05:30 . 2012-05-07 23:46 143360 c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2012-05-02 22:40 143360 c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2012-05-02 22:40 143360 c:\windows\system32\DriverStore\infstor.dat
+ 2009-07-14 05:30 . 2012-05-07 21:36 143360 c:\windows\system32\DriverStore\infstor.dat
+ 2011-08-31 03:05 . 2011-08-31 03:05 212840 c:\windows\system32\dnssdX.dll
+ 2009-07-14 05:12 . 2012-05-12 12:43 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-07-14 05:12 . 2012-04-19 09:06 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-07-14 05:01 . 2012-05-02 09:46 384992 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-05-12 12:56 384992 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-04-23 16:22 . 2012-05-12 00:50 888548 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2394762389-1655812683-3179763728-1000-12288.dat
+ 2011-12-15 18:01 . 2011-12-15 18:01 226600 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationHost_v0400.dll
+ 2011-12-15 17:08 . 2011-12-15 17:08 156440 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.AddIn.dll
- 2011-11-22 03:57 . 2011-11-22 03:57 598784 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SOS.dll
+ 2011-12-15 18:01 . 2011-12-15 18:01 598784 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SOS.dll
+ 2012-05-09 04:55 . 2012-02-10 23:29 172320 c:\windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationHostDLL.dll
+ 2012-05-09 04:56 . 2012-01-04 03:34 486144 c:\windows\Microsoft.NET\Framework64\v2.0.50727\SOS.dll
+ 2011-12-15 17:08 . 2011-12-15 17:08 182056 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationHost_v0400.dll
+ 2011-12-15 17:08 . 2011-12-15 17:08 156440 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.AddIn.dll
- 2011-11-22 02:31 . 2011-11-22 02:31 518400 c:\windows\Microsoft.NET\Framework\v4.0.30319\SOS.dll
+ 2011-12-15 17:08 . 2011-12-15 17:08 518400 c:\windows\Microsoft.NET\Framework\v4.0.30319\SOS.dll
+ 2011-12-15 17:08 . 2011-12-15 17:08 957200 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordbi.dll
- 2011-11-22 02:31 . 2011-11-22 02:31 957200 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordbi.dll
+ 2011-12-15 17:08 . 2011-12-15 17:08 386824 c:\windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
+ 2012-05-09 04:55 . 2012-02-10 23:31 131360 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
+ 2012-05-09 04:56 . 2012-01-04 02:51 389888 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2012-05-09 04:56 . 2012-01-04 02:50 364816 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2012-05-09 04:56 . 2012-01-04 02:50 996624 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 350592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 350592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 163168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 163168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 138592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 138592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 699224 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 699224 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 857960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 857960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 675672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 675672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 113512 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 113512 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 129912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 129912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 390008 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 390008 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 505208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 505208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 261472 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 261472 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 122264 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 122264 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 291184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 291184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 349568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 349568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 236880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 236880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 253280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 253280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 378720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 378720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 134528 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 134528 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 123736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 123736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 392552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 392552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 125816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 125816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 120152 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 120152 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 616216 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 616216 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 395120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 395120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 182144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 182144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 285072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 285072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 829280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 829280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 747360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 747360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 436600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 436600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 683872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 683872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 409448 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 409448 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 210816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 210816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 156440 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 122248 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 122248 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 525704 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 525704 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 112976 c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 112976 c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 581464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 581464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 832856 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 832856 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 194424 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 194424 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 478576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 478576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 167288 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 167288 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 232304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 232304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 661352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 661352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 349576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 349576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 387960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 387960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 746336 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 746336 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 505184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 505184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 288616 c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 288616 c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 335712 c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2012-04-19 10:00 . 2012-04-19 10:00 335712 c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 125440 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 125440 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 237424 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 237424 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 187776 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 187776 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 269672 c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 269672 c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 334688 c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 334688 c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 109568 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-05-09 07:04 . 2012-05-09 07:04 109568 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-05-09 07:04 . 2012-05-09 07:04 246128 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 246128 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 170368 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 170368 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2012-05-11 00:24 . 2012-05-11 00:24 891392 c:\windows\Installer\1e7b1e.msi
+ 2012-05-07 21:38 . 2012-05-07 21:38 380928 c:\windows\Installer\{CF8FFD12-602B-422D-AF1D-511B411E7632}\iTunesIco.exe
+ 2012-04-19 13:53 . 2012-05-09 07:08 415584 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\pubs.exe
- 2012-04-19 13:53 . 2012-04-20 08:47 415584 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\pubs.exe
+ 2012-04-19 13:53 . 2012-05-09 07:08 303456 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\outicon.exe
- 2012-04-19 13:53 . 2012-04-20 08:47 303456 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\outicon.exe
- 2012-04-19 13:53 . 2012-04-20 08:47 571232 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\misc.exe
+ 2012-04-19 13:53 . 2012-05-09 07:08 571232 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\misc.exe
- 2012-04-19 13:53 . 2012-04-20 08:47 326496 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\joticon.exe
+ 2012-04-19 13:53 . 2012-05-09 07:08 326496 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\joticon.exe
- 2012-04-19 13:53 . 2012-04-20 08:47 469856 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\inficon.exe
+ 2012-04-19 13:53 . 2012-05-09 07:08 469856 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\inficon.exe
+ 2012-04-19 13:53 . 2012-05-09 07:08 178528 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\grvicons.exe
- 2012-04-19 13:53 . 2012-04-20 08:47 178528 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\grvicons.exe
+ 2012-05-08 04:36 . 2012-05-08 04:36 367958 c:\windows\Installer\{15843DB2-2F72-4A26-8982-D7FB87AD6C32}\BoxEdit_1.exe
+ 2010-03-18 17:16 . 2010-03-18 17:16 181096 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\PresentationHostDLL_X86.dll
+ 2010-03-18 18:27 . 2010-03-18 18:27 225640 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\PresentationHostDLL_AMD64.dll
+

2012-05-09 07:12 . 2012-05-09 07:12 337408 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsFormsIntegra#\65f25960625d91ca79a40f9067adc021\WindowsFormsIntegration.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 231424 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationTypes\fb43d84bc59b21e8a7f3e36d616eea90\UIAutomationTypes.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 122368 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationProvider\26f12a0a3baed2a227cf30aaeae03913\UIAutomationProvider.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 645120 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClient\1c3c298326e9ac14796516ac1da09a16\UIAutomationClient.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 528896 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Linq\307eea660f877dc40ae90882ce554757\System.Xml.Linq.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 256000 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Inpu#\b4afa252d0f0e27b0b5e8fcb2cc5b3a7\System.Windows.Input.Manipulations.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 903168 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Transactions\8c0ee7b970cc4e8c2986c7898af71661\System.Transactions.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 281088 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceProce#\85810fe277a718273eb946a460ae8010\System.ServiceProcess.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 108032 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\eb4fb369926faaffede7aaf317fd6532\System.ServiceModel.Channels.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 517120 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\e5ab3c37897bb578bdbfe6b7e0558ad8\System.ServiceModel.Routing.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 946688 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Security\e48b6a8c491a96d1bc601795532af605\System.Security.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 376832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\7590828d50338d512b11a4d3f87d69a2\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 987648 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Remo#\21d5b44ef01ccfa69e79674a51707de0\System.Runtime.Remoting.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 176640 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Numerics\5f2bfb0585061dc256ee9587d430959f\System.Numerics.ni.dll
+ 2012-05-09 07:11 . 2012-05-09 07:11 933376 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Net\6996a415485a84fef2d2556b0462336f\System.Net.ni.dll
+ 2012-05-09 07:11 . 2012-05-09 07:11 781824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Messaging\a3849a373beeb3509d8c22d5751dfad3\System.Messaging.ni.dll
+ 2012-05-09 07:11 . 2012-05-09 07:11 521728 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Management.I#\92d266f677605e5475b7f39c063c4a9d\System.Management.Instrumentation.ni.dll
+ 2012-05-09 07:11 . 2012-05-09 07:11 531456 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IO.Log\07a0e1efc063042be3e8faf62b413a12\System.IO.Log.ni.dll
+ 2012-05-09 07:11 . 2012-05-09 07:11 290816 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IdentityMode#\7fd39b9a208214e6e5eba4e9396409f1\System.IdentityModel.Selectors.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 348672 c:\windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\8e10d4f2a408dc5a9740f8d0df5cebac\System.EnterpriseServices.Wrapper.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 512000 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Dynamic\521f5bccf74318a4777597b0c01fda1e\System.Dynamic.ni.dll
+ 2012-05-09 07:11 . 2012-05-09 07:11 632832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\6a8bd7d373c988a585e90bb61c5ec8cc\System.DirectoryServices.Protocols.ni.dll
+ 2012-05-09 07:11 . 2012-05-09 07:11 141824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Device\78dd02d104bb15bc3820c06bd2876239\System.Device.ni.dll
+ 2012-05-09 07:10 . 2012-05-09 07:10 176128 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.DataSet#\97d1aaf3733b107ecdbecb9d21050ff4\System.Data.DataSetExtensions.ni.dll
+ 2012-05-09 07:10 . 2012-05-09 07:10 181760 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuratio#\c3d7a7ff58ff502887d8f1b77e61adbc\System.Configuration.Install.ni.dll
+ 2012-05-09 07:10 . 2012-05-09 07:10 255488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\a4f91f2dfd1656ef2e42917963f6bf50\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-05-09 07:10 . 2012-05-09 07:10 871936 c:\windows\assembly\NativeImages_v4.0.30319_64\System.AddIn\b1c67ee2e0e6e78c31985069fbc82596\System.AddIn.ni.dll
+ 2012-05-09 07:10 . 2012-05-09 07:10 560640 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.D#\c69fb0f955adc7ca80cd5f2fd730edea\System.Activities.DurableInstancing.ni.dll
+ 2012-05-09 07:07 . 2012-05-09 07:07 432128 c:\windows\assembly\NativeImages_v4.0.30319_64\SMSvcHost\11fc863fa4f5092fca4f2ce25a9ac361\SMSvcHost.ni.exe
+ 2012-05-09 07:09 . 2012-05-09 07:09 185344 c:\windows\assembly\NativeImages_v4.0.30319_64\SMDiagnostics\50e8e826488639e549589ba34666933e\SMDiagnostics.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 428032 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\722c0236432dd5ccc047481d3ebbd49e\PresentationFramework.Royale.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 622592 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\6739c3715c9e38dbdfbfd57b424a3094\PresentationFramework.Aero.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 802304 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\3e7359f5f0fb68565314f88f6ec2d67a\PresentationFramework.Luna.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 349184 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\263748f3d18955b9e467710da1e8546f\PresentationFramework.Classic.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 864768 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualStu#\e4aa78e299b615e1fc92ba19a78071b8\Microsoft.VisualStudio.Tools.Office.Runtime.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 247808 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualStu#\e1725f0aad2d375efdcfeea0f428df59\Microsoft.VisualStudio.Tools.Office.Runtime.Internal.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 475136 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualStu#\ac6c6882341a572604fa25b32836a4c0\Microsoft.VisualStudio.Tools.Applications.Hosting.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 169984 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualStu#\45da98c4ff3a12f7438f2b7cd10752b9\Microsoft.VisualStudio.Tools.Applications.Runtime.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 235008 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualStu#\2a9c647ae603089dca838db23bdec62c\Microsoft.VisualStudio.Tools.Office.ContainerControl.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 992256 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualStu#\136e31ba5378e99c0439d13a53b6227f\Microsoft.VisualStudio.Tools.Applications.ServerDocument.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 422912 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\6493bbb60833072904ad141a5a4d08ac\Microsoft.VisualBasic.Compatibility.Data.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 600064 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\6480551111832c83ee88bcf756a72533\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 408576 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\f7b87cbf07144894a5e25831a259fbb2\Microsoft.Office.Tools.Outlook.Implementation.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 199680 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\73487c1ce2fd1b35d59ae1e54c76520d\Microsoft.Office.Tools.Outlook.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 432128 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\63be7108c18a21c22b8305b24c57473e\Microsoft.Office.Tools.Common.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 993280 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\40323c86511b6413f4192e4e589b723a\Microsoft.Office.Tools.Excel.ni.dll
+ 2012-05-09 07:07 . 2012-05-09 07:07 279552 c:\windows\assembly\NativeImages_v4.0.30319_64\CustomMarshalers\0e81a3996f7cbff23fc01bea4185a918\CustomMarshalers.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 253952 c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsFormsIntegra#\ede3b9144bc31da0eaaf86c7b6a9eaaa\WindowsFormsIntegration.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 196096 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\0a80fd3af7e48eb9cc9099fee5814dff\UIAutomationTypes.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 484352 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClient\7a9f70fa774076a7ec19bc03e7064d0d\UIAutomationClient.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 393216 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\4837a5c6204d53e7aa4f7dd94b98207c\System.Xml.Linq.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 189440 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Inpu#\c477bbff1e4662263255a1bf17bd9c2a\System.Windows.Input.Manipulations.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 649728 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\67a386434938003bceb0752e979dabb3\System.Transactions.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 221696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\35da2da22db8fde344d9e17b20a91816\System.ServiceProcess.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 369664 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\dc86fe1c7a6e3a7ce9e9c1f13d9b1e8e\System.ServiceModel.Routing.ni.dll
+ 2012-05-09 07:03 . 2012-05-09 07:03 736768 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Security\5a3beae8b211b91bfc620c029cf4c2d4\System.Security.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 311296 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\5a4d233916a69d48fa12a9f7f103d893\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 762880 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\65f0d70169a0e73b45307dddbd86f92b\System.Runtime.Remoting.ni.dll
+ 2012-05-09 07:03 . 2012-05-09 07:03 145408 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\7b7719d46a4da2e91e8c501347e48ab9\System.Numerics.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 657408 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Net\dd25ddcfa0417d40e3f1385e30abcd6f\System.Net.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 626176 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Messaging\87f2fdf92547c337644f4db30caa63e3\System.Messaging.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 395264 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management.I#\08397796343d5730a29f42e61c7f6ee7\System.Management.Instrumentation.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 413696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IO.Log\ff1250d2409bd16283c423650d6fd3f6\System.IO.Log.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 229888 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityMode#\e60675d3ba7fa94924489dc8466ebff5\System.IdentityModel.Selectors.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 236032 c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\bb40644f323a93fa9bc09be350918ef3\System.EnterpriseServices.Wrapper.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 787456 c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\bb40644f323a93fa9bc09be350918ef3\System.EnterpriseServices.ni.dll
+ 2012-05-09 07:03 . 2012-05-09 07:03 377856 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Dynamic\a9b1e597aaa263dea2cf8754440bd271\System.Dynamic.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 470528 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\e41e86da56bb60523251e0e08210a77b\System.DirectoryServices.Protocols.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 913920 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\94d45f7f28d81304d7fa83bcea849141\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 112640 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Device\4c50d8a951546d6dffdc8bcb23f47a7b\System.Device.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 134656 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.DataSet#\7803f4398a527a87d5cace8023e93e8b\System.Data.DataSetExtensions.ni.dll
+ 2012-05-09 07:03 . 2012-05-09 07:03 982528 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\623d2a0f11dd82bb9bc13d1cb981b239\System.Configuration.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 148480 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuratio#\977c7c2badf6a9059ba8371a0f645fc8\System.Configuration.Install.ni.dll
+ 2012-05-09 07:03 . 2012-05-09 07:03 693760 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\877ef74350e6d374ca8f80b489a8cc8e\System.ComponentModel.Composition.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 194048 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\4330e93f9d0ef85f1a972e11c2ac5156\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 624128 c:\windows\assembly\NativeImages_v4.0.30319_32\System.AddIn\0c67d9fc14856eb7d8b4e405aef79960\System.AddIn.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 411136 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.D#\2b046f2d5f056b906d7b25b75ca23575\System.Activities.DurableInstancing.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 317952 c:\windows\assembly\NativeImages_v4.0.30319_32\SMSvcHost\4847f66153121ec4ed532909f7c152be\SMSvcHost.ni.exe
+ 2012-05-09 07:13 . 2012-05-09 07:13 143360 c:\windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\bb97517e4ca64e02282fca24612ce8ad\SMDiagnostics.ni.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 309760 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\ef6e3eb351fe12a5766be7c956c35d95\PresentationFramework.Classic.ni.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 387072 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\e49a124fdad0f1db135f03a49f18fb48\PresentationFramework.Royale.ni.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 595968 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\a5fa2a1cfc6e9fdc39d9a8f2baa57bc9\PresentationFramework.Aero.ni.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 755712 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\141f0a8fbfb83604fa3dd43dbe8fa0f4\PresentationFramework.Luna.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 210432 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\e4446a8d82b4412494e2409af7a4b645\Microsoft.VisualStudio.Tools.Office.Runtime.Internal.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 364544 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\bdfc721f7e94acba00c2e92153307b70\Microsoft.VisualStudio.Tools.Applications.Hosting.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 135680 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\b2adaa453df6c958d3cf66ae051787de\Microsoft.VisualStudio.Tools.Applications.Runtime.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 738304 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\6e4e81d647b98053d4b580d5afcf682f\Microsoft.VisualStudio.Tools.Applications.ServerDocument.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 708608 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\53dc52854a22eb79069206f054f709e1\Microsoft.VisualStudio.Tools.Office.Runtime.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 178176 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualStu#\336cb6816013dcc3477597d532706c17\Microsoft.VisualStudio.Tools.Office.ContainerControl.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 303104 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\a604989c1d4b14505e020b7d015cacbd\Microsoft.VisualBasic.Compatibility.Data.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 418816 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\01c5ff7a1ea0463414736df5d449e0a9\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 730624 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\bc3bb3bef5a7fc42df95d68382c1a00a\Microsoft.Office.Tools.Excel.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 336384 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\b959c009fde768bc512f944f4423ba93\Microsoft.Office.Tools.Common.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 864768 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\731220afd1830875ef9c2449f0051abb\Microsoft.Office.Tools.Common.Implementation.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 676864 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\322118927d1ed7462e0f793a25c9ca54\Microsoft.Office.Tools.Word.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 152064 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\214046ba75547419c644e54ab309e90d\Microsoft.Office.Tools.Outlook.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 312320 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\013ef67531505afc6d64d771d08a10d8\Microsoft.Office.Tools.Outlook.Implementation.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 194048 c:\windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\f11d5fea7ded12068e8cdb8b2f1bdbd9\CustomMarshalers.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 468992 c:\windows\assembly\NativeImages_v2.0.50727_64\WsatConfig\ad7f43afb4f124acae4d503b40f591c1\WsatConfig.ni.exe
+ 2012-05-09 07:35 . 2012-05-09 07:35 329216 c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsFormsIntegra#\cefe28fde401a6a5718d1718c345fb37\WindowsFormsIntegration.ni.dll
+ 2012-05-09 07:28 . 2012-05-09 07:28 253952 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationTypes\bf634b0e2e28466c6ed6ae1eb602b09f\UIAutomationTypes.ni.dll
+ 2012-05-09 07:28 . 2012-05-09 07:28 120832 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationProvider\1ff8fb81d6f045f1dc6f50be95444292\UIAutomationProvider.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 653312 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClient\1f36e020c3563e0ff414f13138e238e1\UIAutomationClient.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 304128 c:\windows\assembly\NativeImages_v2.0.50727_64\TaskScheduler\769b7666d915de95db5b63ec22bf3e42\TaskScheduler.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 529920 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml.Linq\de45d043775d8c805f6feca40d7a9ed2\System.Xml.Linq.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 187392 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Routing\181702fb83901c085401957c6f731cf4\System.Web.Routing.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 261120 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.RegularE#\76662ce36d2141e45513e64386073cc2\System.Web.RegularExpressions.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 449024 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity\9b9d3e3e44dc7d03bb96033a5b829a6b\System.Web.Entity.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 398848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity.D#\ad2339c5f0fd9aa8a9989800825da487\System.Web.Entity.Design.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 753664 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\8309dc5dd39b93f3e105a4d455b74a00\System.Web.DynamicData.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 204800 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Abstract#\a79640760b61cc1c23ac3cfdfa6f0f3f\System.Web.Abstractions.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 921600 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\ec95ad2463c5588fc8ef552b3f375ee6\System.Transactions.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 295424 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\05acafa7eb44049849a5aafd39147ee5\System.ServiceProcess.ni.dll
+ 2012-05-09 07:27 . 2012-05-09 07:27 928768 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Security\1875b50d0228f29aef00bed38ab594d6\System.Security.ni.dll
+ 2012-05-09 07:28 . 2012-05-09 07:28 396288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\807759890a40e4047c35a24e64dc76d5\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 916480 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Net\3b3581851a728bef36f319e9d4c72499\System.Net.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 783360 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Messaging\b4297ef47e0839fce0145f665349dcc9\System.Messaging.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 534016 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.I#\599954438a668c94dd38e8e7e506ac2a\System.Management.Instrumentation.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 569856 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IO.Log\fd51741bfd973ad507bbd141e98932f8\System.IO.Log.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 294400 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityMode#\ef6abe121bb11bff2514bfdfb7e76b7a\System.IdentityModel.Selectors.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 446464 c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\d50cde53634ccbb5e0231738784ff4b8\System.EnterpriseServices.Wrapper.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 288768 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing.Desi#\e7abd70c16a5e638a7121fc5f68484cc\System.Drawing.Design.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 649728 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\4bb1134d9b166434327385ddf3c5dd54\System.DirectoryServices.Protocols.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 629760 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\7c4ce1b8a2f83ef29aa6d5f126ab5b71\System.Data.Services.Design.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 194560 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.DataSet#\19d1414f1ca718ce4d0c07e7305b3450\System.Data.DataSetExtensions.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 192000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\4aebed13b5309398cd809454cafe472f\System.Configuration.Install.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 132096 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ComponentMod#\9536bb262c4f1ea389d287ab669767d4\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 890880 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn\84262138e2e9f34c88fd282caa82baa5\System.AddIn.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 156672 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn.Contra#\176899be7b920fb20408ff49e636a776\System.AddIn.Contract.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 297984 c:\windows\assembly\NativeImages_v2.0.50727_64\sysglobl\ee0608cd62dfb37016016884fc39e425\sysglobl.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 525824 c:\windows\assembly\NativeImages_v2.0.50727_64\SMSvcHost\9fa1abf006689e262527ae50d452e97e\SMSvcHost.ni.exe
+ 2012-05-09 07:31 . 2012-05-09 07:31 349184 c:\windows\assembly\NativeImages_v2.0.50727_64\SMDiagnostics\2eac9c598de3341eba5c16787c74f220\SMDiagnostics.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 376832 c:\windows\assembly\NativeImages_v2.0.50727_64\SecurityAuditPolici#\16a3bcffca166e8c522eb1c3dfe90701\SecurityAuditPoliciesSnapIn.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 282624 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\89de197bdde5984658045ade41c2c9b9\PresentationFramework.Classic.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 620544 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\7ffb91db770d0b09921f623bc5d68b4f\PresentationFramework.Luna.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 463360 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\4f3567165e2a444fc9a62980c4d0ea82\PresentationFramework.Aero.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 317440 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\205bb33cef9ae6b906ceadd6f2861c86\PresentationFramework.Royale.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 855040 c:\windows\assembly\NativeImages_v2.0.50727_64\napsnap\bc8a2d99d8ebd29f94905072ccf4b3b8\napsnap.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 162816 c:\windows\assembly\NativeImages_v2.0.50727_64\napinit\b79da521cf602154b475ea740cc7fd3b\napinit.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 175104 c:\windows\assembly\NativeImages_v2.0.50727_64\naphlpr\5f0ae15f9d1cade37fbfaacff7e64bff\naphlpr.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 127488 c:\windows\assembly\NativeImages_v2.0.50727_64\napcrypt\5346ceca518baf5e5fa3fed9f900f792\napcrypt.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 184320 c:\windows\assembly\NativeImages_v2.0.50727_64\MSBuild\8f792883d0adad8c7beccf24aed65817\MSBuild.ni.exe
+ 2012-05-09 07:32 . 2012-05-09 07:32 417792 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCFxCommon\926d20041c179cebc6f4398155b1b2c4\MMCFxCommon.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 681984 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Man#\b78beede8a3c9720095dde4a4a162acc\Microsoft.WSMan.Management.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 122368 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\83222514e209f186ad3a1c3794168bfd\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 105984 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Vsa\a843956bb452503139683304de4cc8f6\Microsoft.Vsa.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 202752 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\f91011762717be2cbc01f328a806c37c\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 270336 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\ebaa756d3e61856714c9fbaecef0ecb8\Microsoft.VisualStudio.Tools.Office.Excel.HostAdapter.v10.0.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 209920 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\cfaa030ecf4e968aecd91ddca97d650e\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 232448 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\ce9a7eec17ddf23506e7e6795c6448bf\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 446464 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\c8c461dbe6ab47066c7890e6546a8907\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 773120 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\b6089ab817bb3f9ddbac924f7429ee2a\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 229888 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\a585108c8399c16bc551cb97caba4355\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 215040 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\a1a195375892f0fe555e71ec0755f5e7\Microsoft.VisualStudio.Tools.Office.HostAdapter.v10.0.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 956416 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\9522b90955f403c723b945cf1b201cf5\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 499200 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\902522b8368cc353596494d2e51bd34c\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 124928 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\78f7e019afde3c908d7e0818190449dd\Microsoft.VisualStudio.Tools.Office.Outlook.HostAdapter.v10.0.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 495616 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\7521a6224a26851550e2c903367e7a3b\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 305664 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\6e1bd44de0eb6c1a17c5953c6bb4c1d6\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 390656 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\639acfa01f065f3a0f8d41648ed5e1bc\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 225280 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\2e4e9ea1eea86e6915da6ae85abab822\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 311296 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\01ec6dd47728da0c62cd55c8142d6f99\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 584192 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\c56d6513e4b239b1b1dbe29b0588321a\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 937472 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\c3e6c7a45c97f1349d6273abbe1ffd07\Microsoft.Security.ApplicationId.Wizards.AutomaticRuleGenerationWizard.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 235008 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\92f7f1c771fc7c909cf0d4da4d558105\Microsoft.Security.ApplicationId.PolicyManagement.PolicyModel.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 318976 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\4ac43f1030faa080a78faf6867448fc7\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 275456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Security.#\168f2d23b2652dd1a4d6eb7c8c008d51\Microsoft.Security.ApplicationId.PolicyManagement.PolicyManager.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 713216 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\fb0d102ca78bd05fe7064b9e6be30fc7\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 237056 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\b21fa6ff448b99a97319e18c166c03e2\Microsoft.PowerShell.Security.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 999936 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\6c3fe42a14ac5b48ebd43be290973d24\Microsoft.PowerShell.GraphicalHost.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 416768 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\2572e94f9d0b412cdc529c8d74fdb689\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 244224 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\d0522e5e71b408ffde2e9dca680c1932\Microsoft.Office.Tools.Outlook.v9.0.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 253952 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\b3eec454fbf7152c2188d3eefbedfcfd\Microsoft.Office.Tools.v9.0.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 169472 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\d1bbd90fd1b074257c693a3618e8bff0\Microsoft.Office.InfoPath.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 315392 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\93aaae5b4c0c7f88fd8f5028ea20ae50\Microsoft.Office.InfoPath.Client.Internal.Host.Interop.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 380416 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.Bu#\47c4bfb36a399604469f84c6b363e93f\Microsoft.Office.BusinessApplications.Diagnostics.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 152576 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\f4faec8b6d3e2c327c68070963ec1750\Microsoft.MediaCenter.ITVVM.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 164864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\f04ccbbf5199d2b264f1b1175be44686\Microsoft.MediaCenter.Mheg.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 219648 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\f015188310f7613f819fcf032f98705a\Microsoft.MediaCenter.iTv.Media.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 312320 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\c5f4ab28f67d5bf0cc221ef81e7f6966\Microsoft.MediaCenter.iTv.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 370176 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\6dbd502a13b5e3caae0b1f2b4847612f\Microsoft.MediaCenter.Playback.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 522240 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\514667153fd74307d21e7f50b79858c9\Microsoft.MediaCenter.Interop.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 965632 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\18367b9a0b9e9261d1d9e371230af87c\Microsoft.MediaCenter.Sports.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 798720 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Managemen#\718cd5a598ed3e225a73b2aba7bcc1e1\Microsoft.ManagementConsole.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 399360 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.GroupPoli#\a92fbdf48c09de9c994cfea90f23af13\Microsoft.GroupPolicy.Interop.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 618496 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.GroupPoli#\3048f941ea295091c9caccb155c9e0ab\Microsoft.GroupPolicy.AdmTmplEditor.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 675840 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.BusinessD#\e6564d821cfb12ad515b88b59ccdb4ba\Microsoft.BusinessData.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 244736 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\d68a27daca73749e4438a47e61643c3c\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 198656 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\3151235c1c38db94fd44e3c6f290ff38\Microsoft.Build.Utilities.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 121344 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\cf5e9b5d10682467a9e03358a6d6258f\Microsoft.Build.Framework.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 142336 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\0f233d0eb396065719e83ab573a72cc5\Microsoft.Build.Framework.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 294912 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Con#\2416af06edb993f98a751acb69f67016\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 423424 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Applicati#\d79134097339d1d6ae563a5e1040f52d\Microsoft.ApplicationId.Framework.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 727040 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Applicati#\245e39437fa517c1f062d9c57fc911c5\Microsoft.ApplicationId.RuleWizard.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 107520 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft-Windows-H#\69286d5692277a166404cb897a8b2e7a\Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 380928 c:\windows\assembly\NativeImages_v2.0.50727_64\Mcx2Dvcs\74e4adc90675c3b1365825c7e78b5ce9\Mcx2Dvcs.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 547328 c:\windows\assembly\NativeImages_v2.0.50727_64\mcupdate\4a1f9a648a3928d42b77a91666d9aa8a\mcupdate.ni.exe
+ 2012-05-09 07:32 . 2012-05-09 07:32 533504 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstoredb\40d70417c04f9ccb5fdecb5b9be5a6a3\mcstoredb.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 549376 c:\windows\assembly\NativeImages_v2.0.50727_64\mcplayerinterop\927ada02b440d95fdf36a37ee96aaa54\mcplayerinterop.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 696320 c:\windows\assembly\NativeImages_v2.0.50727_64\mcGlidHostObj\35023ad5cb299ca2020bd660f5dba2fc\mcGlidHostObj.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 156672 c:\windows\assembly\NativeImages_v2.0.50727_64\MCESidebarCtrl\3fc113fe40d0145cd87afca2d107bf6d\MCESidebarCtrl.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 659456 c:\windows\assembly\NativeImages_v2.0.50727_64\EventViewer\0bd8d37bc6f648d092e1d8034609a107\EventViewer.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 969216 c:\windows\assembly\NativeImages_v2.0.50727_64\ehRecObj\584d419d4c837ea19f7f450a807b0273\ehRecObj.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 661504 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiWUapi\20c3505378a50f4859c9b2e7dcbb5fa2\ehiWUapi.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 933888 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiwmp\2f9f48ad6496c9103043db1c21a651fd\ehiwmp.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 145408 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUserXp\0955237aa3c1cb3a643248b8c58ec34c\ehiUserXp.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 196096 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiiTv\7998173654fa518876cc97e37b86d465\ehiiTv.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 397824 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiExtens\6c97aa6908f96ac9816ce74e4f6251ac\ehiExtens.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 110080 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiBmlDataCarousel\a501747a95523297a8a1f119df8b1642\ehiBmlDataCarousel.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 126976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiActivScp\414bbac4e1d7761a336bb9d74b9b243a\ehiActivScp.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 389120 c:\windows\assembly\NativeImages_v2.0.50727_64\ehExtHost\24d3859bba3ed02775f22c50ae5ab5a6\ehExtHost.ni.exe
+ 2012-05-09 07:31 . 2012-05-09 07:31 313856 c:\windows\assembly\NativeImages_v2.0.50727_64\ehCIR\ff7ef4caed03d6934669d1a39877a8ac\ehCIR.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 348672 c:\windows\assembly\NativeImages_v2.0.50727_64\CustomMarshalers\b7916689137fd0bc9ba1ba5a27e2a38a\CustomMarshalers.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 640000 c:\windows\assembly\NativeImages_v2.0.50727_64\ComSvcConfig\cc6e6febcd804604bf4d92d0eb8ec6ae\ComSvcConfig.ni.exe
+ 2012-05-09 07:31 . 2012-05-09 07:31 971264 c:\windows\assembly\NativeImages_v2.0.50727_64\BDATunePIA\d18719c2df1334364cac199bb9c86adf\BDATunePIA.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 321024 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\9d60139fdead64a892985181d663989f\WsatConfig.ni.exe
+ 2012-05-09 07:36 . 2012-05-09 07:36 634368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\7efc478aa653514837fa2d9f74abc242\WindowsLiveLocal.WriterPlugin.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 313856 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\dbbb5914ff727ce0f6793177c4da31ba\WindowsLive.Writer.Interop.SHDocVw.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 665600 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c38f725098b88c724d07b0a63f7d9a4d\WindowsLive.Writer.Interop.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 326144 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\befcde61587ee64fa3cbb00a2a49eb4c\WindowsLive.Writer.SpellChecker.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 871424 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\aba4c14578df5a2a2bdb905526071b80\WindowsLive.Writer.BlogClient.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\a9f7a39a31fa323327626c240f2bcebd\WindowsLive.Writer.FileDestinations.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\8d3d296f70fd964569a1981dfbf9ac8a\WindowsLive.Writer.Mshtml.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 146432 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\7868ce7aef400105ccd415151a24053e\WindowsLive.Writer.Instrumentation.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 156672 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\68e3097a2465cdbc3d61b919c309ce0a\WindowsLive.Writer.HtmlParser.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 122368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\608f6c85c4d0ef4e5d4f2e91a1e9fc5e\WindowsLive.Writer.Extensibility.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 374272 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\315bb426fe9c648562b1ead5e3cd989d\WindowsLive.Writer.Interop.Mshtml.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 101376 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\0eb76e19a15d656f3adde39c356e517a\WindowsLive.Writer.Api.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 780800 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\0a9d8902040b30058cf7c6b7f704742e\WindowsLive.Writer.Controls.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 174080 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\09da25dea37a498b6f3b894b20fe456c\WindowsLive.Writer.BrowserControl.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 891392 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\0252d2ef3f2e54b65ce297115c7a9adb\WindowsLive.Writer.HtmlEditor.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\4ae7969274514f9b8e90ae2e278f6048\WindowsLive.Client.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\9bfbf0613d3780e34d98333c7b381218\WindowsFormsIntegration.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 185344 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\d8af9a65cf0ed85d47360796e2645a06\UIAutomationTypes.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 452096 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\779b08c46960a1824503aa6f089673fa\UIAutomationClient.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 245248 c:\windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\c4edf782e69aa24453554f8b6cb40773\TaskScheduler.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 401408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\64de6810023adccdc56ddae13bdd6b03\System.Xml.Linq.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\d75f0b1e2ea688466552da04fd805949\System.Web.Routing.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\2b129372a27469195acbe3b6b81786ef\System.Web.RegularExpressions.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 860160 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\5d6fdd022660b8ca4be19ff06ddfee7a\System.Web.Extensions.Design.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\d084aa31b82c66eb83e40853ba961b48\System.Web.Entity.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 301568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\53ca1042189a64dcd1f8ff487922b749\System.Web.Entity.Design.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\0b8a9e120d8f557a9702229e3c64987c\System.Web.DynamicData.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\5d95b9a6cee5a9b1aac34b5d33c721ba\System.Web.Abstractions.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\80fae9f16f80075535e72458ef293f7a\System.Transactions.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\5abddd1112204bd1e3347be519eaa28f\System.ServiceProcess.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 680448 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\054fcff18035c210487b0888e6461192\System.Security.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 310784 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\2ff4e90c5842525f7a7456639de090d8\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 624128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\0b5f082230e3486412e0fa333290e85a\System.Net.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\f1241239a9b8229f91ce55d230fad38c\System.Messaging.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 330240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\8280490a2939075b726fd051d9010cc0\System.Management.Instrumentation.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\a03191ed937f6c1dc827b53d94ea0176\System.IO.Log.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\100d39c2f8985cb93e26feef86ba5212\System.IdentityModel.Selectors.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\168755d010e5a96ac940b0ddd27616a4\System.EnterpriseServices.Wrapper.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 628224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\168755d010e5a96ac940b0ddd27616a4\System.EnterpriseServices.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\6b16664ac4ab46643c4a7fdd960ef9fb\System.Drawing.Design.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\55545e89f96539ef93375524d1145a6f\System.DirectoryServices.Protocols.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 888320 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\4d73a7649876bb6e54a01ccbf235919b\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 462336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\e36e03067b12bc35fcc3787dc81022c8\System.Data.Services.Design.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 763392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\5a29fff52e2c3d13ec15e8701027ab17\System.Data.Entity.Design.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\940f62a5d077405e0b324422afb6ff2c\System.Data.DataSetExtensions.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\d3325c6bced333a67122db7414c1fd1e\System.Configuration.Install.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 634368 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\a90ec436f1d2c5cb0133a53c2e47d61a\System.AddIn.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 232448 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\1ed79278fe139272e868e3a53d736f22\sysglobl.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\1b0b19607668635281fa260707f4352f\SMSvcHost.ni.exe
+ 2012-05-09 07:36 . 2012-05-09 07:36 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\9e7bf69d97febe4ed1a288c787e5d9ca\SMDiagnostics.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 294912 c:\windows\assembly\NativeImages_v2.0.50727_32\SecurityAuditPolici#\f7d5b31f334ced015f8b58616f160163\SecurityAuditPoliciesSnapIn.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 226816 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ae55e761d480fe15781156d1311a1837\PresentationFramework.Classic.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramework.Aero.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7df1f379457aa5f39183903d115b5479\PresentationFramework.Royale.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\496bc57a53989bb83ec58865fa34be1d\PresentationFramework.Luna.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 723456 c:\windows\assembly\NativeImages_v2.0.50727_32\napsnap\9e0dafde490fbb06e0624ad4e5355b58\napsnap.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 117760 c:\windows\assembly\NativeImages_v2.0.50727_32\napinit\782ffccdf30881e1eb1236c3fd7e959b\napinit.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 114176 c:\windows\assembly\NativeImages_v2.0.50727_32\naphlpr\e0c40329b9cdd7f141a3702d79eb4bda\naphlpr.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\74a8b6419deb005337a1e43ec2502134\MSBuild.ni.exe
+ 2012-05-09 07:36 . 2012-05-09 07:36 287232 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon\9e8d56153e65d3cf74342c741126d396\MMCFxCommon.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 531968 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Man#\070505350ec9daa3343b3cd2bc8cf59e\Microsoft.WSMan.Management.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 161792 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\facec243ff2a723274709018d32e43cd\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 196608 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\e347818725714beed32bb4e44bf34cff\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 134144 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\d3d3ffda4ace48b6c4ed9a0faa84415f\Microsoft.VisualStudio.Tools.Office.HostAdapter.v10.0.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 337408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\cbaa2c3a4e91129440a784827d1d26bb\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 285184 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\a9f6c9b07b5450581322eada5a828b89\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 303104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\913fce36cb050a091d692e8d090ee3ae\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 161280 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\90947159599bba4aa64c55b6c6080bdf\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 148480 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\82a28951464c45b39b027d3d62fb4079\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 133120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\783a4e24531ee190eb826509f8cc2a45\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 112128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\6c7ccf3f7fa572b45a31097585b9be71\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 179200 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\4f8e0cc43e469f4178c31061f34fca62\Microsoft.VisualStudio.Tools.Office.Excel.HostAdapter.v10.0.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 650752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\4bc310439d3df869c82d0064c3e1180a\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 617472 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\4b76c8d476ab52a28bbfa154c6f5ef07\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 363008 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\3d016be961a0f7e1941e0ceca394ed9d\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 215040 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\1701cf92acbe16a9da38e2951929fd32\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\1e639225ba30d7f182b893ddacea506b\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 187392 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\8c10fabe7b25fbced5d8078481c9e9dc\Microsoft.Security.ApplicationId.PolicyManagement.PolicyManager.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 157184 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\637695a13f044c7fc5a8d8779e5a64ae\Microsoft.Security.ApplicationId.PolicyManagement.PolicyModel.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\498f876d5aef5febed9d62bf62e52e6a\Microsoft.Security.ApplicationId.Wizards.AutomaticRuleGenerationWizard.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 210944 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Security.#\1cea81520a22da5621733cad33e75ac4\Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 291328 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\d4c36b363fcd1ca494218e74ba606e99\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 786432 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\ba2ca86f5d270f493501848843d2f227\Microsoft.PowerShell.Commands.Management.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 729088 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\607324a312b1c6d7fbede8300e8cee91\Microsoft.PowerShell.GraphicalHost.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 167424 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\1f1185444c8a12ace85ba4c2d49f41f8\Microsoft.PowerShell.Security.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 515584 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\12715b7e3e89758161053520b57764b2\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 152064 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\ac10628d091eae96da114ea9b313bd6d\Microsoft.Office.Tools.v9.0.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 854528 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\9ff530df18dcbceb7e066bd61016da78\Microsoft.Office.Tools.Word.v9.0.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 816128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\40ef6717c89b12db31944bd98f01e9fa\Microsoft.Office.Tools.Common.v9.0.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 167424 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\157636189b85b95de6c5d6e6e9c28303\Microsoft.Office.Tools.Outlook.v9.0.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 561664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen#\f077b7199d773c7812c04bb146014257\Microsoft.ManagementConsole.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 286208 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.GroupPoli#\bfb3100618f589638a8a31ab52135ca4\Microsoft.GroupPolicy.Interop.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 455168 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.GroupPoli#\86ffe35a29d7705487510251cdd0bff3\Microsoft.GroupPolicy.AdmTmplEditor.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\7e59b3b84ca3c61adfc0dc74a65ea177\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\07e346ee0e3f7433f2de7a72fadd6713\Microsoft.Build.Utilities.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\432160eff3b1f9301c6a74c2e647e03d\Microsoft.Build.Engine.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\8297305de86377d0070a983d99a7f943\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 316928 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\c5fb23456e58073dd64cd1b8686565a4\Microsoft.ApplicationId.Framework.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 587776 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\39b197cc7e97cb5dfdb4047845fc1c8c\Microsoft.ApplicationId.RuleWizard.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 364032 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstoredb\541a5bb4d0f8490e506f885a4b435566\mcstoredb.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 553472 c:\windows\assembly\NativeImages_v2.0.50727_32\EventViewer\185067f9c70ccbccb4431063f9054b66\EventViewer.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 693248 c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\5ae5c6732ef8e7115baaeb66fd69cdd2\ehRecObj.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 875520 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiVidCtl\c4a5ce4f89c53b9601d13d22d01cf0bf\ehiVidCtl.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 442880 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiProxy\cbf3a07d3ab873b19f47d6a24f06c796\ehiProxy.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 161280 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtens\5cc4a5672758f4732ef430b3431f47fc\ehiExtens.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 254464 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtHost32\15b24807d7e7cae1db4f285f04cb82d7\ehExtHost32.ni.exe
+ 2012-05-09 07:36 . 2012-05-09 07:36 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\626d0ac2f4ada682d7ca6c4ebf821469\CustomMarshalers.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\3912b69593af13d0922279a063e5af66\ComSvcConfig.ni.exe
+ 2012-05-09 07:36 . 2012-05-09 07:36 621568 c:\windows\assembly\NativeImages_v2.0.50727_32\BDATunePIA\e1c3540ffb669448747187f76c6ebe82\BDATunePIA.ni.dll
- 2010-11-21 03:25 . 2010-11-21 03:25 163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
+ 2012-05-09 04:56 . 2012-01-04 02:50 163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
- 2010-11-21 03:24 . 2010-11-21 03:24 532480 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2012-05-09 04:55 . 2012-02-10 23:31 532480 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2012-05-09 04:55 . 2012-02-10 23:29 358912 c:\windows\assembly\GAC_64\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2010-11-21 03:24 . 2010-11-21 03:24 358912 c:\windows\assembly\GAC_64\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2010-11-21 03:24 . 2010-11-21 03:24 372736 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-05-09 04:55 . 2012-02-10 23:31 372736 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-05-05 01:56 . 2012-05-11 00:20 8797856 c:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
+ 2011-08-02 20:38 . 2011-08-02 20:38 1721576 c:\windows\system32\wdfcoinstaller01009.dll
- 2009-07-14 00:03 . 2009-07-14 01:41 1402880 c:\windows\system32\spool\drivers\x64\3\JNWDRV.dll
+ 2012-05-09 04:55 . 2012-03-31 05:40 1402880 c:\windows\system32\spool\drivers\x64\3\JNWDRV.dll
+ 2012-02-15 15:01 . 2012-02-15 15:01 4547944 c:\windows\system32\DriverStore\FileRepository\usbaapl64.inf_amd64_neutral_c111aaecb61e9a2b\usbaaplrc.dll
+ 2011-08-02 20:38 . 2011-08-02 20:38 1721576 c:\windows\system32\DriverStore\FileRepository\netaapl64.inf_amd64_neutral_dc2cbd989eec1514\wdfcoinstaller01009.dll
+ 2009-07-14 00:22 . 2009-07-14 01:41 1195008 c:\windows\system32\drivers\UMDF\WpdMtpDr.dll
- 2009-07-14 04:45 . 2012-05-02 22:38 7083571 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 04:45 . 2012-05-09 07:27 7083571 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2012-01-19 17:08 . 2012-01-19 17:08 1369872 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WindowsBase.dll
+ 2012-01-19 17:08 . 2012-01-19 17:08 6429992 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.dll
+ 2012-01-19 17:52 . 2012-01-19 17:52 3825952 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationCore.dll
+ 2011-12-15 17:08 . 2011-12-15 17:08 5029160 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Windows.Forms.dll
+ 2011-12-15 17:08 . 2011-12-15 17:08 3512072 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.dll
- 2011-11-22 02:31 . 2011-11-22 02:31 3512072 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.dll
- 2011-11-22 03:57 . 2011-11-22 03:57 4970768 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorlib.dll
+ 2011-12-15 18:01 . 2011-12-15 18:01 4970768 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorlib.dll
+ 2011-12-15 18:01 . 2011-12-15 18:01 1455376 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordbi.dll
- 2011-11-22 03:57 . 2011-11-22 03:57 1455376 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordbi.dll
- 2011-11-22 03:57 . 2011-11-22 03:57 1515792 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordacwks.dll
+ 2011-12-15 18:01 . 2011-12-15 18:01 1515792 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordacwks.dll
+ 2011-12-15 18:01 . 2011-12-15 18:01 1512712 c:\windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll
+ 2011-12-15 18:01 . 2011-12-15 18:01 9793280 c:\windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
- 2011-11-22 03:57 . 2011-11-22 03:57 9793280 c:\windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
+ 2012-05-09 04:55 . 2012-02-10 23:29 2256152 c:\windows\Microsoft.NET\Framework64\v3.0\WPF\wpfgfx_v0300.dll
- 2012-04-19 08:44 . 2011-03-29 22:32 5025792 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Windows.Forms.dll
+ 2012-05-09 04:56 . 2012-01-04 03:34 5025792 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Windows.Forms.dll
+ 2012-05-09 04:56 . 2012-01-04 03:34 3190784 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.dll
- 2012-04-19 08:44 . 2011-10-31 23:15 3190784 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.dll
+ 2012-05-09 04:56 . 2012-01-04 03:34 9992464 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
- 2012-04-19 08:44 . 2011-07-08 22:31 4567040 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll
+ 2012-05-09 04:56 . 2012-01-04 03:34 4567040 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll
+ 2012-05-09 04:56 . 2012-01-04 03:34 1577232 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
+ 2012-05-09 04:56 . 2012-01-04 03:34 1756432 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscordacwks.dll
+ 2012-01-19 17:08 . 2012-01-19 17:08 1369872 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsBase.dll
+ 2012-01-19 17:08 . 2012-01-19 17:08 6429992 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.dll
+ 2012-01-19 17:08 . 2012-01-19 17:08 3790112 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationCore.dll
+ 2011-12-15 17:08 . 2011-12-15 17:08 5029160 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Windows.Forms.dll
+ 2011-12-15 17:08 . 2011-12-15 17:08 3512072 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.dll
- 2011-11-22 02:31 . 2011-11-22 02:31 3512072 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.dll
- 2011-11-22 02:31 . 2011-11-22 02:31 5201168 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
+ 2011-12-15 17:08 . 2011-12-15 17:08 5201168 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
- 2011-11-22 02:31 . 2011-11-22 02:31 1143568 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordacwks.dll
+ 2011-12-15 17:08 . 2011-12-15 17:08 1143568 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordacwks.dll
- 2011-11-22 02:31 . 2011-11-22 02:31 6727424 c:\windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
+ 2011-12-15 17:08 . 2011-12-15 17:08 6727424 c:\windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
+ 2012-05-09 04:55 . 2012-02-10 23:31 1737496 c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll
- 2012-04-19 08:44 . 2011-03-29 22:33 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2012-05-09 04:56 . 2012-01-04 02:51 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
- 2012-04-19 08:44 . 2011-10-31 23:16 3190784 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2012-05-09 04:56 . 2012-01-04 02:51 3190784 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2012-05-09 04:56 . 2012-01-04 02:51 5925136 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2012-05-09 04:56 . 2012-01-04 02:50 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
- 2012-04-19 08:44 . 2011-07-08 22:33 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 1369872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 3512072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 3512072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 2207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 2207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 5029160 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 1711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 1711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 6097256 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 6097256 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 1026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 1026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 4464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 4464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 1354584 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 1354584 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 1199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 1199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 1462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 1462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 6429992 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 3116376 c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 3116376 c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 3825952 c:\windows\Microsoft.NET\assembly\GAC_64\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 4970768 c:\windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 4970768 c:\windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 3563408 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 3563408 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 2975064 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-05-09 07:04 . 2012-05-09 07:04 2975064 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 3790112 c:\windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 5201168 c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-05-09 07:04 . 2012-05-09 07:04 5201168 c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
- 2012-04-19 09:59 . 2012-04-19 09:59 2989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 2989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2012-03-15 17:15 . 2012-03-15 17:15 9949184 c:\windows\Installer\855868.msp
+ 2012-04-23 14:30 . 2012-04-23 14:30 3445760 c:\windows\Installer\855833.msp
+ 2012-03-15 17:12 . 2012-03-15 17:12 3172864 c:\windows\Installer\8557e6.msp
+ 2012-03-07 00:42 . 2012-03-07 00:42 2323456 c:\windows\Installer\4452b3.msi
+ 2012-03-07 00:39 . 2012-03-07 00:39 2682368 c:\windows\Installer\4452a3.msi
+ 2012-05-08 04:35 . 2012-05-08 04:35 1266688 c:\windows\Installer\1c55cea.msi
- 2012-04-19 13:53 . 2012-04-20 08:47 1479520 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\xlicons.exe
+ 2012-04-19 13:53 . 2012-05-09 07:08 1479520 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\xlicons.exe
- 2012-04-19 13:53 . 2012-04-20 08:47 1858400 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\wordicon.exe
+ 2012-04-19 13:53 . 2012-05-09 07:08 1858400 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\wordicon.exe
- 2012-04-19 13:53 . 2012-04-20 08:47 3792736 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\pptico.exe
+ 2012-04-19 13:53 . 2012-05-09 07:08 3792736 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\pptico.exe
- 2012-04-19 13:53 . 2012-04-20 08:47 1449312 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\accicons.exe
+ 2012-04-19 13:53 . 2012-05-09 07:08 1449312 c:\windows\Installer\{90140000-0011-0000-1000-0000000FF1CE}\accicons.exe
+ 2011-03-17 05:38 . 2011-03-17 05:38 6439808 c:\windows\Installer\$PatchCache$\Managed\00004109110000000100000000F01FEC\14.0.6029\GRAPH.EXE
+ 2012-05-09 07:08 . 2012-05-09 07:08 5237248 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsBase\e41f5739292f4771c64a55940369efd2\WindowsBase.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 1430016 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClients#\6ee9d76d9f1e618cd6fb94b13355bcc9\UIAutomationClientsideProviders.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 7037952 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml\28ca4f076264ab07f1d00a6c9623dc49\System.Xml.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 2449408 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xaml\df013cbfec0defc7e9997cdaa90b89bc\System.Xaml.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 5645824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\9e50e3bca6cb19f9acab815d46f5e7e5\System.Windows.Forms.DataVisualization.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 2236416 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services\bc6df78c506c89659ab7be738179b2ba\System.Web.Services.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 2735616 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Speech\cd7c3aed4408c3554c30a8f0236b90e1\System.Speech.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 1918976 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\94289b88c5b494f572cd7114fa995487\System.ServiceModel.Activities.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 1579008 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\2dbc7aabd92cc0d470acb455c498d919\System.ServiceModel.Discovery.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 3412992 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\affb28e2d9cc3c19de0758e7e8c68e8f\System.Runtime.Serialization.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 1348096 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Dura#\b37e6f4b1d742031f328504eb99d0f6c\System.Runtime.DurableInstancing.ni.dll
+ 2012-05-09 07:10 . 2012-05-09 07:10 1467392 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Printing\682ea473b36fc9043d982c4f5a667568\System.Printing.ni.dll
+ 2012-05-09 07:11 . 2012-05-09 07:11 1470464 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Management\b83f2453b4538b2e80fe09cfd94dce00\System.Management.ni.dll
+ 2012-05-09 07:11 . 2012-05-09 07:11 1416192 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IdentityModel\60bf6251873ef465abcebeb9a24b7932\System.IdentityModel.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 1098752 c:\windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\8e10d4f2a408dc5a9740f8d0df5cebac\System.EnterpriseServices.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 2303488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\dadeee26c90fecbf3196eba10dc077b4\System.Drawing.ni.dll
+ 2012-05-09 07:11 . 2012-05-09 07:11 1217024 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\a68116468a194678fd04167067134712\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 1622528 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\3a737af86a6a819af97a6d1a04c0e944\System.DirectoryServices.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 2403328 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Deployment\f20144fba069563333d0f6be2e0b6e06\System.Deployment.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 8601600 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data\0ec8effb7b9d03ae69d37922813bc880\System.Data.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 3390976 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.SqlXml\0eb72df497fad5c273ff16f88b0fb950\System.Data.SqlXml.ni.dll
+ 2012-05-09 07:11 . 2012-05-09 07:11 1799168 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\536e12016ad3adc78e0708b77e6b9219\System.Data.Services.Client.ni.dll
+ 2012-05-09 07:11 . 2012-05-09 07:11 3386368 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Linq\86553c1d7f3e66c17fc3e0274de7a2de\System.Data.Linq.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 1257472 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\6aea67f24827961ce1d48356715389d8\System.Configuration.ni.dll
+ 2012-05-09 07:10 . 2012-05-09 07:10 1007616 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\eac19ca5a18a6d08cd247e68b618ba68\System.ComponentModel.Composition.ni.dll
+ 2012-05-09 07:10 . 2012-05-09 07:10 5695488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities\3869077874ba987242c791b3a18b2f8b\System.Activities.ni.dll
+ 2012-05-09 07:10 . 2012-05-09 07:10 5048832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.P#\a7c19841c70fbce3b17ad3a46ee410d8\System.Activities.Presentation.ni.dll
+ 2012-05-09 07:10 . 2012-05-09 07:10 2064896 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.C#\96083298999a677341c98fc2bf01b248\System.Activities.Core.Presentation.ni.dll
+ 2012-05-09 07:10 . 2012-05-09 07:10 4233216 c:\windows\assembly\NativeImages_v4.0.30319_64\ReachFramework\fe1704ff12348776e6b70dd4a2c69163\ReachFramework.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 2056704 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationUI\b0b05b1ecbfb813474f685de13027585\PresentationUI.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 1843712 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\a36cd27bd492b55a5f443a4b4029f569\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 2317312 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\93536d93a44ce7d5a60faf1aeb55f49e\Microsoft.VisualBasic.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 1623040 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\16425c121db8083cbaa51f619c9e51e7\Microsoft.VisualBasic.Activities.Compiler.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 1526784 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\5284682fcf04815a86233bcaf696da66\Microsoft.Transactions.Bridge.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 2035200 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\d4fb64f2927e453f9b81c59f4aa51a66\Microsoft.Office.Tools.Excel.Implementation.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 1470464 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\a236dee1165c1350d3931ff349485278\Microsoft.Office.Tools.Word.Implementation.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 1070080 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\2addc9e043f4007adc64e3a617c780e0\Microsoft.Office.Tools.Word.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 1118208 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\22561d0ecf4728b6041f6ac509fa1e17\Microsoft.Office.Tools.Common.Implementation.ni.dll
+ 2012-05-09 07:11 . 2012-05-09 07:11 3313664 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.JScript\4b1d24a96b3882f9e77445e48a7c59ee\Microsoft.JScript.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 2009600 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.CSharp\1ff62486cdefbfc2dab41b686a9aa4e2\Microsoft.CSharp.ni.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 3858432 c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\4b7adff986a085bb562222d0c5fdf5aa\WindowsBase.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 1063424 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClients#\24ed0e1df6a605cdb2088f87ae2ab8ff\UIAutomationClientsideProviders.ni.dll
+ 2012-05-09 07:03 . 2012-05-09 07:03 9091584 c:\windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll
+ 2012-05-09 07:03 . 2012-05-09 07:03 5617664 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d1f299160424bad90fe9f658661389e2\System.Xml.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 1782272 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\d234eceae699d070b5a5712ce776c01f\System.Xaml.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 4587008 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form#\8ca12588b9ef54dbd02e607699fea6ae\System.Windows.Forms.DataVisualization.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 1885696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\b37cc0aa41e7feaba9f290da4da91d71\System.Web.Services.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 2012160 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Speech\f368c85283c4e6c9650dd1c8d369dcc5\System.Speech.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 1140736 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\ec057796972ce41b751eaa3a8306fbcb\System.ServiceModel.Discovery.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 1393152 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\5055b60e339143bbace5871f5fe4b114\System.ServiceModel.Activities.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 2647040 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\8a9fac9cb825b5d2db0bdb867fff940e\System.Runtime.Serialization.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 1021952 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\79ac99fe5274fb82ffcff2c15f71854c\System.Runtime.DurableInstancing.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 1060864 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Printing\bd371863e99082fa48cd630a73259448\System.Printing.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 1218560 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management\0c2b0d52156447592f33edf4116b7e7d\System.Management.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 1072640 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\bd28f26b18b8ffeee1a0fbaa98f5810e\System.IdentityModel.ni.dll
+ 2012-05-09 07:03 . 2012-05-09 07:03 1665536 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\03b5233f1511f5fdb39eb681b04e5506\System.Drawing.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 1172992 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\0fe1e56d17858b6156a3a46330f75f27\System.DirectoryServices.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 1880064 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Deployment\75b4d98f7c7a434aff4e18cb724deae4\System.Deployment.ni.dll
+ 2012-05-09 07:03 . 2012-05-09 07:03 6815232 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data\99d0f7ba920eea1117e45dcd9fec0eb5\System.Data.ni.dll
+ 2012-05-09 07:03 . 2012-05-09 07:03 2550272 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.SqlXml\fdb98c6d783fe167c1dc0022f27b7cd6\System.Data.SqlXml.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 1343488 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\b894a1df3e6d58ada8f1aa303465ca23\System.Data.Services.Client.ni.dll
+ 2012-05-09 07:03 . 2012-05-09 07:03 2517504 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\82c0c56ff8259e1440cfd0d5727a26d8\System.Data.Linq.ni.dll
+ 2012-05-09 07:03 . 2012-05-09 07:03 7069184 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Core\ed91b57205429a23bb91f4499059a459\System.Core.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 4129280 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities\51025a1c89f6fd752a5396a059d608b2\System.Activities.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 3757568 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.P#\ebdd265de5f0300069da5f64983eca82\System.Activities.Presentation.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 1546752 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.C#\66893548d2b2cad29cabf3b3578f356f\System.Activities.Core.Presentation.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 2906624 c:\windows\assembly\NativeImages_v4.0.30319_32\ReachFramework\4b6c6c090a1bcfe70c056f6c7116e8a9\ReachFramework.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 1641984 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationUI\ea5933189eb5f066028b6e7d27d1d797\PresentationUI.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 1139712 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\ebae0a4b7d3ae616b70417e6c778f48c\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 1838080 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\92694d06b9da1bff8e1722913a1d62bc\Microsoft.VisualBasic.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 1172480 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\42a7f127f3fda82fb12c6a6e144d08c1\Microsoft.VisualBasic.Activities.Compiler.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 1085952 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\9a37f4e64ce5b856ac3892fef064c7de\Microsoft.Transactions.Bridge.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 1551872 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\a7a818acc8fb850f2e7d7aa2a6df59e3\Microsoft.Office.Tools.Excel.Implementation.ni.dll
+ 2012-05-09 07:13 . 2012-05-09 07:13 1117696 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\11e6fd1012bb557cb4663926e6f87e1b\Microsoft.Office.Tools.Word.Implementation.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 2452480 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.JScript\cfcc92c125ddfaabad24abe61cfc0471\Microsoft.JScript.ni.dll
+ 2012-05-09 07:03 . 2012-05-09 07:03 1616896 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.CSharp\9912b6d76c1017b5af6ef24730f550ca\Microsoft.CSharp.ni.dll
+ 2012-05-09 07:12 . 2012-05-09 07:12 4930560 c:\windows\assembly\NativeImages_v4.0.30319_32\KeePass\84d12ac26d373416e27500e15033246e\KeePass.ni.exe
+ 2012-05-09 07:27 . 2012-05-09 07:27 4962816 c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsBase\4bcc5a6e9e9d25e068fc304bd7eda6af\WindowsBase.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 1459712 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClients#\783df1ee260d3df406fa80afa38502d4\UIAutomationClientsideProviders.ni.dll
+ 2012-05-09 07:27 . 2012-05-09 07:27 6948864 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml\24d1b7ccbedaa3602bae6a6acea9929e\System.Xml.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 1818112 c:\windows\assembly\NativeImages_v2.0.50727_64\System.WorkflowServ#\b7d8410b7226a2654823657f0a714441\System.WorkflowServices.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 2711040 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Run#\8ac687b7f43937c81f1c49d14975c740\System.Workflow.Runtime.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 5957632 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Com#\6fdec1a3278d87cbbc5211736d446d32\System.Workflow.ComponentModel.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 3895296 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Act#\052fd2c15eb37e00cecf33f6d13d9b09\System.Workflow.Activities.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 2292224 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Services\6a0b589c4c1467f6b783991842a0f961\System.Web.Services.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 3336704 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Mobile\395c96f5d2a876805d3846d396081c79\System.Web.Mobile.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 1155072 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\e4860ce9959b3593834516b4a6a75593\System.Web.Extensions.Design.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 3044352 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\baa7ed93207641c186f79f82ee22aea0\System.Web.Extensions.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 2727936 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Speech\ca51f026916139f886519fdf6d6c73e9\System.Speech.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 2312704 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel#\56ee9b5f220583c1c7374a61ad904044\System.ServiceModel.Web.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 3073536 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\265531568722647aab229a2cec195b3d\System.Runtime.Serialization.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 1022976 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Remo#\2a02b172fa4cf3d93ce7388b67b2a199\System.Runtime.Remoting.ni.dll
+ 2012-05-09 07:28 . 2012-05-09 07:28 1463808 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Printing\f0bcd188487600cb07ce08dfd7b471ba\System.Printing.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 1472000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management\fd4a8227569e64d657b80483da8ffe78\System.Management.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 1444352 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityModel\d1f21a29e79e73b5401fae156f339f67\System.IdentityModel.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 1081344 c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\d50cde53634ccbb5e0231738784ff4b8\System.EnterpriseServices.ni.dll
+ 2012-05-09 07:28 . 2012-05-09 07:28 2317312 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\92c038385ee5b9840e941f9c84b988df\System.Drawing.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 1230848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\39d16229a3d5c6e7c1594ef10758bf75\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-05-09 07:28 . 2012-05-09 07:28 1640448 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\152ef61928f1c300fdad8fa6d5905880\System.DirectoryServices.ni.dll
+ 2012-05-09 07:28 . 2012-05-09 07:28 2444288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Deployment\7c7024b309424dfaf8abae617f669fa0\System.Deployment.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 8681472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data\ea1848ec07c70f3d3c3445f4fbdae87a\System.Data.ni.dll
+ 2012-05-09 07:27 . 2012-05-09 07:27 3463680 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.SqlXml\7f6f74f1cc0ea6c40a2d6707b12af818\System.Data.SqlXml.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 2805760 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Services\0679fe5f3f9164f499e50cdade962ba3\System.Data.Services.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 1868288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\2e9de1acfb7974cad94b747442ca325f\System.Data.Services.Client.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 1506816 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.OracleC#\97429a1c70c94c49850be3f944a32a2e\System.Data.OracleClient.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 3480576 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Linq\2ec3d436b861d35c586b710a570e170d\System.Data.Linq.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 1080320 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity.#\b7b5364bc524988f7ca5b8c20a24119d\System.Data.Entity.Design.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 3315200 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Core\766ce7ee1a2e4f2a85fd90e7572f5d53\System.Core.ni.dll
+ 2012-05-09 07:27 . 2012-05-09 07:27 1308160 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\193d03ca60573c92f92d9b07fa5bc243\System.Configuration.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 1530368 c:\windows\assembly\NativeImages_v2.0.50727_64\SrpUxSnapIn\90deac07616d8b2ca995430d93928d62\SrpUxSnapIn.ni.dll
+ 2012-05-09 07:28 . 2012-05-09 07:28 3116032 c:\windows\assembly\NativeImages_v2.0.50727_64\ReachFramework\d6379f3503f00cf1c2bb4f6118efdbd9\ReachFramework.ni.dll
+ 2012-05-09 07:28 . 2012-05-09 07:28 2109952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationUI\5fa575ebe76aab9d9fd07ce601c0d2e1\PresentationUI.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 1884160 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationBuildTa#\4fbff79b8ebf082d08c0080923ff5036\PresentationBuildTasks.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 3601920 c:\windows\assembly\NativeImages_v2.0.50727_64\Narrator\d0c041e321cf4d752d5113a0cdbccbaa\Narrator.ni.exe
+ 2012-05-09 07:34 . 2012-05-09 07:34 2327552 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCEx\051b72a48f2c3f7ddd7353c7d5479b10\MMCEx.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 7970304 c:\windows\assembly\NativeImages_v2.0.50727_64\MIGUIControls\c79bf402b4840e3b0021f75cf467f82b\MIGUIControls.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 1877504 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\1dcc7a3940f5e4be8da3dd0b66bc38c0\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 2131968 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\70b3f55017e9ddb67ce0f3c983eb6f37\Microsoft.VisualBasic.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 1598976 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\28ba52bc122353647f1b547506e2df7c\Microsoft.Transactions.Bridge.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 1131008 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\f5790625975320b1ffad63b476da9132\Microsoft.PowerShell.Commands.Management.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 5350912 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\f29b31b09b826a27cced362030561d00\Microsoft.PowerShell.Editor.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 2176512 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\d0328b4733d1a99d342a84928e319d4f\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 2105344 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\99049fd20c2a5e2779e879c2d95c96a2\Microsoft.PowerShell.GPowerShell.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 1875456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\f188b5ba01ca7061aec81770298f3762\Microsoft.Office.Tools.Excel.v9.0.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 1093632 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\db955795f55bd1e47707d697801568e7\Microsoft.Office.Tools.Common.v9.0.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 1186304 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\c234c2d94a5ef875293f006ee4edcf33\Microsoft.Office.Tools.Word.v9.0.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 1793536 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\f6c7f3775c2abe74fb57d92e29fd94db\Microsoft.Office.Interop.InfoPath.SemiTrust.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 2780672 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\c7a5e8f606343adc2461e377b7aa5849\Microsoft.Office.InfoPath.Client.Internal.Host.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 1217024 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.In#\c2ec35e7fbf4979fca1d1c496d17f19e\Microsoft.Office.Interop.InfoPath.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 6566400 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.Bu#\e357482b7be4d5d2f3569e88059c355c\Microsoft.Office.BusinessApplications.SyncServices.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 2956800 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.Bu#\9ca92d1af4e4cb6f2116ac67949fc69b\Microsoft.Office.BusinessApplications.RuntimeUi.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 4488704 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.Bu#\3eea1145eb7eb83340de99847eea83bf\Microsoft.Office.BusinessData.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 2206208 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.Bu#\1c72da431e5a1674799d373c63cb3355\Microsoft.Office.BusinessApplications.Runtime.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 1516544 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\efdc3b97b3c9d01dd00959970d086937\Microsoft.MediaCenter.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 1170432 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\c057be8bb6614cce013af3721fe34983\Microsoft.MediaCenter.TV.Tuners.Interop.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 8979456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\5c50dfc78bd40be7ca0d850c781671e4\Microsoft.MediaCenter.UI.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 1508864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\31fb31c16a37080687f869db6b443adf\Microsoft.MediaCenter.Bml.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 1142784 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\260d83ee2128a3388051cf416d4450b0\Microsoft.MediaCenter.Shell.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 3213312 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.JScript\094f6a515ca31504f96b4bad5848d692\Microsoft.JScript.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 2365952 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Ink\a27890dd120635ba590a6fc9d9014197\Microsoft.Ink.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 5054976 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.GroupPoli#\dbfa4f1816f40f6e4603be9da9397679\Microsoft.GroupPolicy.Reporting.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 2218496 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\588a688a0b71a211247d8e18b05d61e4\Microsoft.Build.Tasks.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 2682880 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\4eeee4447f5045df9b4157d38d267de9\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 1137152 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\f1a0df6a86ceb708c5e50338f12b77ba\Microsoft.Build.Engine.ni.dll
+ 2012-05-09 07:33 . 2012-05-09 07:33 2544640 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\6b727c7aa69ae3e04a869908bfbae696\Microsoft.Build.Engine.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 2801664 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstore\208e6937e39f8f516536ba5f23e79687\mcstore.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 4088320 c:\windows\assembly\NativeImages_v2.0.50727_64\mcepg\596902addad034f4df2caf291b12d61d\mcepg.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 2184192 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiVidCtl\cdad46cd58389f53308b735e6f29ce1f\ehiVidCtl.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 1201664 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiProxy\0423915e377ec85d71ac216fafa77ab0\ehiProxy.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 7025152 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f719bb2b6393ad8db17a8ce6a00405a4\WindowsLive.Writer.PostEditor.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 1285632 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ef19d35486d93991481aea9dff55239c\WindowsLive.Writer.ApplicationFramework.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 1346560 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\bceb30d0438bc12bbae3b68083e0fb40\WindowsLive.Writer.Localization.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 2193408 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\1969e87f7777f3f03f75182ee5294c67\WindowsLive.Writer.CoreServices.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 3347968 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 1047552 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\3b452cde57280624e1085699fe8beb03\UIAutomationClientsideProviders.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 7967232 c:\windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 5452800 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 1358336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\439862b007b2dd84127ff35af476f5ad\System.WorkflowServices.ni.dll
+ 2012-05-09 07:27 . 2012-05-09 07:27 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\bfa1ffe928b4e3fd6701aabfee7df15e\System.Workflow.Runtime.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 4516352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\0a7d29e1614521f3a87cd5a13e57f9f1\System.Workflow.ComponentModel.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 2994688 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\edac556f009c25b62ef1a040152e9cda\System.Workflow.Activities.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\59a5af8e3ea07f7980e0476d2da234cd\System.Web.Services.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 2209792 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\0307caacafd3e157fc003ed4743c5e2e\System.Web.Mobile.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 2404352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\04442376410587c6de88f4b84cc69b1a\System.Web.Extensions.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\83053c3eeb3255672d84c1ddc0ce8ef3\System.Speech.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 1707008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\ed560b26f2f86b3f07b7f6d384f92275\System.ServiceModel.Web.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 2347008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\72a24b45e11d64eb2bc840aae9419ba5\System.Runtime.Serialization.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 1044480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\d900f9ec12af9070d7c8f061a2b2618c\System.Printing.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 1051136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\System.Management.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 8872960 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\a8495b797e6f7adddc5811a4e1f97db5\System.Management.Automation.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 1083392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\2ce8210219c7123610072357358df470\System.IdentityModel.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 1590784 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\69f6e582cb79f107c61308b468c1a215\System.Drawing.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 1117184 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\ef0d8a4790c24a3a091170958bc7b976\System.DirectoryServices.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 1806848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\bf659f9bb758ac14ed7a37bdfe965849\System.Deployment.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 6611456 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 2508288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\e9774272e9fc6ca49e6c616a31783040\System.Data.SqlXml.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 2029568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\3285887b33030a7ce453573d3bed4e95\System.Data.Services.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 1378816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\330d3ad45a00455b537047183e128def\System.Data.Services.Client.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\0f4e07fb8b1b7e7133a98f478856f70c\System.Data.OracleClient.ni.dll
+ 2012-05-09 07:38 . 2012-05-09 07:38 2516992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\2fe1658f05b0a96fe25c956a31d27b06\System.Data.Linq.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 9921536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\51a2589d5ee1c9c40fb6c56391570f9e\System.Data.Entity.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 2297856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 1351168 c:\windows\assembly\NativeImages_v2.0.50727_32\SrpUxSnapIn\b2640e99e610e58cc3797c921b09ffe1\SrpUxSnapIn.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 2157056 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\305c4315c192a2964a312051caa5259e\ReachFramework.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 1658368 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\b935f8a4e6115d3eeb7bb293bf4b2257\PresentationUI.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 1451520 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b3f13707cbd5d48aabaa9ef5264c8a30\PresentationBuildTasks.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 2623488 c:\windows\assembly\NativeImages_v2.0.50727_32\Narrator\a96e05eaed77a88a7a495091ed8296dc\Narrator.ni.exe
+ 2012-05-09 07:37 . 2012-05-09 07:37 1545216 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCEx\0310b6efd8cd8b1b90bb78303d014081\MMCEx.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 6438912 c:\windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls\6e602986ed39fd1f9e3801ee96b63f41\MIGUIControls.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 1300992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\0849dd848383994c63dc00278f64ddae\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 1670144 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\dab0ad2d0f5da372a4947d3a1c7c07a9\Microsoft.VisualBasic.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\cd9e47effec6549cdec61eb3aef99f7c\Microsoft.Transactions.Bridge.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 1681920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\d62bb06df2169fa249006539173d6b5f\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 3724288 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\870bb30c079ed5bc201057d71661601f\Microsoft.PowerShell.Editor.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 1704960 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\7ee29045f76b1e9577bfc1e0fab723d8\Microsoft.PowerShell.GPowerShell.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 1354752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\81d897ecd9572922097c05a58fa7bb51\Microsoft.Office.Tools.Excel.v9.0.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 6499840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\9ac798ce15e5c0336f43b624af7363ec\Microsoft.MediaCenter.UI.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 1009664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\0cb862d3708c15fe0f5c66d2a40cb074\Microsoft.MediaCenter.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 2335744 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\e3d2577e00aef6bc9b3e235eb83634f3\Microsoft.JScript.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 1361408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Ink\89ebef016091d09d58c8a1066def8bcd\Microsoft.Ink.ni.dll
+ 2012-05-09 07:37 . 2012-05-09 07:37 4071936 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.GroupPoli#\b3e1ec6f3acb6b118b643928e2e9eed8\Microsoft.GroupPolicy.Reporting.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 1970176 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\81b8987ca8661d6af40ead6311c45724\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\52e05f8fa4314803ceab2befae2e0a39\Microsoft.Build.Tasks.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\6b66f52dbd8f87e53c3c9a1de7ca5bba\Microsoft.Build.Engine.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 2035712 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstore\14defdf34097afaf302497a7d612aaaf\mcstore.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 3025920 c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\69b8de21b08c3412422c5918399ed702\mcepg.ni.dll
+ 2012-05-09 04:55 . 2012-02-10 23:31 1253376 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
- 2010-11-21 03:24 . 2010-11-21 03:24 1253376 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
- 2012-04-19 08:44 . 2011-10-31 23:16 3190784 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2012-05-09 04:56 . 2012-01-04 02:51 3190784 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2012-04-19 08:44 . 2011-03-29 22:33 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2012-05-09 04:56 . 2012-01-04 02:51 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2012-05-09 04:56 . 2012-02-10 23:31 5283840 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2012-05-09 04:55 . 2012-02-10 23:29 2256152 c:\windows\assembly\GAC_64\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll
+ 2012-05-09 04:56 . 2012-02-10 23:29 3998208 c:\windows\assembly\GAC_64\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2012-04-19 08:44 . 2011-07-08 22:31 4567040 c:\windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-05-09 04:56 . 2012-01-04 03:34 4567040 c:\windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-05-09 04:55 . 2012-02-10 23:31 1737496 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll
+ 2012-05-09 04:56 . 2012-02-10 23:31 4218880 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2010-11-21 03:24 . 2010-11-21 03:24 4218880 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2012-04-19 08:44 . 2011-07-08 22:33 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-05-09 04:56 . 2012-01-04 02:50 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2009-07-14 02:34 . 2012-04-19 10:01 10485760 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2012-05-09 07:23 10485760 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2012-04-19 08:46 . 2012-05-09 07:06 57848688 c:\windows\system32\MRT.exe
+ 2012-05-05 01:56 . 2012-05-11 00:20 11590304 c:\windows\system32\Macromed\Flash\NPSWF64_11_2_202_235.dll
+ 2012-04-19 09:00 . 2012-05-12 12:56 11552990 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2394762389-1655812683-3179763728-1000-8192.dat
+ 2012-05-12 12:44 . 2012-05-12 12:44 53217792 c:\windows\Installer\d6def.msp
+ 2012-03-15 17:14 . 2012-03-15 17:14 17090048 c:\windows\Installer\855889.msp
+ 2012-03-15 17:14 . 2012-03-15 17:14 65796096 c:\windows\Installer\85584d.msp
+ 2012-01-19 18:20 . 2012-01-19 18:20 11997696 c:\windows\Installer\85581b.msp
+ 2011-12-15 18:54 . 2011-12-15 18:54 39732736 c:\windows\Installer\85580c.msp
+ 2012-03-27 11:59 . 2012-03-27 11:59 49125888 c:\windows\Installer\4452b7.msi
+ 2012-03-07 00:33 . 2012-03-07 00:33 11105280 c:\windows\Installer\4452ab.msi
+ 2012-03-26 16:18 . 2012-03-26 16:18 20396032 c:\windows\Installer\44529a.msi
+ 2012-05-09 07:03 . 2012-05-09 07:03 11880448 c:\windows\assembly\NativeImages_v4.0.30319_64\System\935aea6e7eae16674abdd96a68ec97af\System.ni.dll
+ 2012-05-09 07:10 . 2012-05-09 07:10 17353728 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\401ebcc2dd54ce1e0d63a544f7ed7b8a\System.Windows.Forms.ni.dll
+ 2012-05-09 07:11 . 2012-05-09 07:11 24551936 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel\c4cc7eb7733c4221c32caccfd66ae320\System.ServiceModel.ni.dll
+ 2012-05-09 07:11 . 2012-05-09 07:11 18479616 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Entity\9df4e7ae75baa7bbb1af30c8061a6e9b\System.Data.Entity.ni.dll
+ 2012-05-09 07:07 . 2012-05-09 07:07 10440192 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Core\b64f213e823a591607c45fac4997801e\System.Core.ni.dll
+ 2012-05-09 07:09 . 2012-05-09 07:09 24407552 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\34c2013b5f730680bd610d6a98d2977f\PresentationFramework.ni.dll
+ 2012-05-09 07:08 . 2012-05-09 07:08 15908864 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationCore\4464e9df7184e3393b4cbb0f6dc286ba\PresentationCore.ni.dll
+ 2012-05-09 07:03 . 2012-05-09 07:03 19353600 c:\windows\assembly\NativeImages_v4.0.30319_64\mscorlib\6087fce8f76d9af69af496cb10b7d1ee\mscorlib.ni.dll
+ 2012-05-09 07:03 . 2012-05-09 07:03 13197312 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\9ee9841d9e33fe5dceba4cd7d90f2ae0\System.Windows.Forms.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 18058752 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\cfece6f67593b4d8bb58d23b7fdcc470\System.ServiceModel.ni.dll
+ 2012-05-09 07:14 . 2012-05-09 07:14 13345792 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity\7aa839fb16503243d6ae454ab334bcf4\System.Data.Entity.ni.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 18000896 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\041b1bcf6ae9ab58925791d8198c37e2\PresentationFramework.ni.dll
+ 2012-05-09 07:05 . 2012-05-09 07:05 11451904 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\a1de74c8d0dfd15e3246e5dd394013bf\PresentationCore.ni.dll
+ 2012-05-09 07:03 . 2012-05-09 07:03 14412800 c:\windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll
+ 2012-05-09 07:27 . 2012-05-09 07:27 10624512 c:\windows\assembly\NativeImages_v2.0.50727_64\System\c40ec0f4cd203c880298f94c0427dd54\System.ni.dll
+ 2012-05-09 07:28 . 2012-05-09 07:28 17379840 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\e2ca64137e0da231edc4d158b153e4b7\System.Windows.Forms.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 15270912 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web\1cb5a7cbd9cdf50f1d48cee830331c9f\System.Web.ni.dll
+ 2012-05-09 07:31 . 2012-05-09 07:31 23913984 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel\f74b2d1b8cf279ff6bfe479f79e70fe9\System.ServiceModel.ni.dll
+ 2012-05-09 07:34 . 2012-05-09 07:34 11900928 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.A#\00c4a761d0a5cafc00f34d763fe76ac4\System.Management.Automation.ni.dll
+ 2012-05-09 07:29 . 2012-05-09 07:29 13609472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Design\78c747493d14dd3db5134d26e623851c\System.Design.ni.dll
+ 2012-05-09 07:35 . 2012-05-09 07:35 13760000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity\daaff9fe9c85fc171d426a3cb6766dbb\System.Data.Entity.ni.dll
+ 2012-05-09 07:28 . 2012-05-09 07:28 19198464 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\9aa6320f06da2553fb04e78722c739c8\PresentationFramework.ni.dll
+ 2012-05-09 07:28 . 2012-05-09 07:28 16543232 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCore\4dc6e89ac37368291890ba27c374208b\PresentationCore.ni.dll
+ 2012-05-09 07:27 . 2012-05-09 07:27 15570944 c:\windows\assembly\NativeImages_v2.0.50727_64\mscorlib\f73f0a9c9a83dcd3ff428be509a7992f\mscorlib.ni.dll
+ 2012-05-09 07:32 . 2012-05-09 07:32 25470976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehshell\d19a72cf466c23b193009386b25049ba\ehshell.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 12433408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\90555968565afd59bce4b0974e9903bd\System.Windows.Forms.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 11833344 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\1a690902e9a6293de228c16fab21e2f7\System.Web.ni.dll
+ 2012-05-09 07:36 . 2012-05-09 07:36 17478656 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\8d735346f3a8a7123a1533637e980211\System.ServiceModel.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 10580480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\649766df70bab5885c1b74a1491d60cb\System.Design.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 14340608 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\07f019692c382d588d3c6cb2da2a9ec5\PresentationFramework.ni.dll
+ 2012-05-09 07:26 . 2012-05-09 07:26 12237824 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\2d1fd350e9bc62ce659e5cbcfd555796\PresentationCore.ni.dll
+ 2012-05-09 07:25 . 2012-05-09 07:25 11492864 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Free Download Manager"="c:\program files (x86)\Free Download Manager\fdm.exe" [2011-12-28 6148096]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"PicPick Start"="c:\program files (x86)\PicPick\picpick.exe" [2012-04-20 10811392]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2011-07-22 910208]
"GrooveMonitor"="c:\program files\Microsoft Office\Office14\GROOVEMN.EXE" [2011-02-05 1371528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-06 4241512]
"KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2012-01-05 1823744]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736]
.
c:\users\Eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Eric\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-2-14 24246216]
Main.ahk.lnk - s:\dropbox\Dev\AutoHotKey\_Scripts\Main.ahk [2012-4-7 8708]
Microsoft SharePoint Workspace.lnk - c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 51740536]
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 245120]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Box Edit.lnk - c:\program files (x86)\Box Edit\Box Edit.exe [2012-4-27 460864]
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2012-3-30 562232]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-22 136176]
R2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2012-03-30 681016]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-11 257696]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-22 136176]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-05-03 129976]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-10 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 FixZeroAccess;Zero Access Fixtool driver;c:\windows\system32\drivers\FixZeroAccess.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 nm3;Microsoft Network Monitor 3 Driver;c:\windows\system32\DRIVERS\nm3.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2012-03-30 1295416]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [x]
S3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver;c:\windows\system32\DRIVERS\Rtnic64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-05-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-27 00:20]
.
2012-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-22 17:25]
.
2012-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-22 17:25]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-06 23:15 135408 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"CmPCIaudio"="c:\windows\Syswow64\CMICNFG3.dll" [2011-04-01 8765440]
"Cmaudio8768GX"="c:\windows\syswow64\HsMgr.exe" [2008-07-11 200704]
"Cmaudio8768GX64"="c:\windows\system\HsMgr64.exe" [2008-07-11 282112]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Download all with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: LastPass - file://c:\program files (x86)\LastPass\context.html?cmd=lastpass
IE: LastPass Fill Forms - file://c:\program files (x86)\LastPass\context.html?cmd=fillforms
IE: Se&nd to OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
TCP: Interfaces\{8F7A7258-3241-4800-B94E-2688E0B408E4}: NameServer = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\c6l2d0b8.default\
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
.
**************************************************************************
.
Completion time: 2012-05-12 09:01:23 - machine was rebooted
ComboFix-quarantined-files.txt 2012-05-12 13:01
ComboFix2.txt 2012-05-07 09:28
ComboFix3.txt 2012-05-05 03:56
ComboFix4.txt 2012-05-03 06:50
.
Pre-Run: 114,403,741,696 bytes free
Post-Run: 114,284,179,456 bytes free
.
- - End Of File - - 9F7C6360D188ED031020A7694A955B0F

#8 nasdaq

nasdaq

  • Malware Response Team
  • 40,213 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:03 PM

Posted 12 May 2012 - 08:43 AM

The log is clean.

Third party programs if not up to date can be an open door for an infection

Please run this security check for my review.

Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===

Please let me know of any issues with this computer.

#9 3maz

3maz
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:04:03 PM

Posted 12 May 2012 - 08:44 AM

Hey, thanks so much for looking at these! I have some more info that might be useful....

Every time my computer boots (from shutdown or restart), Spybot S&D notifies me that there were three registry deletions. I'm pretty sure they are the same values every time also. I wanted to paste in here the ongoing log for TeaTimer, but I "archived" it instead of exporting. Now I don't see them or how to get them back. However, here is the current log, only showing a single boot since running combofix...

5/12/2012 9:10:09 AM Allowed (based on user decision) value "{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" (new data: "") deleted in Browser Helper Object!
5/12/2012 9:29:14 AM Allowed (based on user decision) value "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" (new data: "") deleted in Browser Helper Object!
5/12/2012 9:29:15 AM Allowed (based on user decision) value "{DBC80044-A445-435b-BC74-9C25C1C588A9}" (new data: "") deleted in Browser Helper Object!

Now, my PC reboot once after combofix, as expected and normal, but when it comes back up, every program or file I try to open says "Illegal operation attempted on a registry key that has been marked for deletion". There is nothing in the system tray except for the bare essentials, (sound, netcon....) The system must be restarted once more before anything is able to work.

Lastly, I cannot seem to access the network from some computers. On this PC, internet access is working via only static IP configuration in win7. Sometimes, I can see the router respond in Wireshark, and it says that it doesn't have any more addresses in the pool, or something...

I"m so CoNFuusED!!

#10 3maz

3maz
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:04:03 PM

Posted 12 May 2012 - 08:48 AM

Results of screen317's Security Check version 0.99.32
Windows 7 x64
Internet Explorer 9
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
avast! Free Antivirus
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:

Spybot - Search & Destroy
Secunia PSI (3.0.0.0006)
VirusTotal Uploader 2.0
Adobe Reader X (10.1.3)
Mozilla Firefox (12.0.)
Mozilla Thunderbird (x86 en-GB..)
````````````````````````````````
Process Check:
objlist.exe by Laurent

AVAST Software Avast AvastSvc.exe
AVAST Software Avast AvastUI.exe
``````````End of Log````````````



Whoops, I disabled my firewall to run combofix and I forgot to reenable it... geez. It is now running..

#11 nasdaq

nasdaq

  • Malware Response Team
  • 40,213 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:03 PM

Posted 12 May 2012 - 09:50 AM

Now, my PC reboot once after combofix, as expected and normal, but when it comes back up, every program or file I try to open says "Illegal operation attempted on a registry key that has been marked for deletion". There is nothing in the system tray except for the bare essentials, (sound, netcon....) The system must be restarted once more before anything is able to work.


Restart the computer normally and this should be fixed.
===

If Sypbot still report some false positive I suggest you remove it using the Add/Remove Programs list and reinstall the program.
===

Please download MiniToolBox to Desktop and run it.

Check mark the following boxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • List content of Hosts
  • List IP Configuration
  • List Last 10 Event Viewer Errors
  • List Users, Partitions and Memory Size
Click Go and copy/paste the log (Result.txt) into your next post.

#12 3maz

3maz
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:04:03 PM

Posted 12 May 2012 - 06:09 PM

:/ I wish I had more time right now. I want to show you my HijackThis log and the rest of MiniToolBox. One thing hijack this mentions is two winsock lsp(?) entries that it can't remove. It also shows many hidden processes, or more specifically, those with files missing and unknown owners. They seem to be removed but reappear with a restart.


MiniToolBox by Farbar Version: 18-01-2012
Ran by Eric (administrator) on 12-05-2012 at 18:56:01
Microsoft Windows 7 Ultimate Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================

127.0.0.1 localhost

========================= IP Configuration: ================================

Realtek PCIe GBE Family Controller = Local Area Connection (Connected)
D-Link DFE-530TX+ PCI Adapter = Local Area Connection 2 (Connected)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global
add route prefix=0.0.0.0/0 interface="Local Area Connection" nexthop=10.0.0.1 metric=1 publish=Yes
add address name="Local Area Connection" address=10.0.0.60 mask=255.255.0.0


popd
# End of IPv4 configuration



Windows IP Configuration

Host Name . . . . . . . . . . . . : Desktop
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
Physical Address. . . . . . . . . : 00-30-67-BF-AB-F9
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv4 Address. . . . . . . . . . . : 10.0.0.60(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.0.0
Default Gateway . . . . . . . . . : 10.0.0.1
DNS Servers . . . . . . . . . . . : 208.67.222.222
208.67.220.220
NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.{8F7A7258-3241-4800-B94E-2688E0B408E4}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Teredo Tunneling Pseudo-Interface:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2001:0:5ef5:79fd:c21:3964:f5ff:ffc3(Preferred)
Link-local IPv6 Address . . . . . : fe80::c21:3964:f5ff:ffc3%13(Preferred)
Default Gateway . . . . . . . . . : ::
NetBIOS over Tcpip. . . . . . . . : Disabled
Server: resolver1.opendns.com
Address: 208.67.222.222

Name: google.com
Addresses: 74.125.228.68
74.125.228.70
74.125.228.71
74.125.228.69
74.125.228.78
74.125.228.72
74.125.228.64
74.125.228.73
74.125.228.66
74.125.228.65
74.125.228.67


Pinging google.com [74.125.228.70] with 32 bytes of data:
Reply from 74.125.228.70: bytes=32 time=46ms TTL=51
Reply from 74.125.228.70: bytes=32 time=46ms TTL=51

Ping statistics for 74.125.228.70:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 46ms, Maximum = 46ms, Average = 46ms
Server: resolver1.opendns.com
Address: 208.67.222.222

Name: yahoo.com
Addresses: 209.191.122.70
98.139.183.24
72.30.38.140


Pinging yahoo.com [209.191.122.70] with 32 bytes of data:
Reply from 209.191.122.70: bytes=32 time=72ms TTL=51
Reply from 209.191.122.70: bytes=32 time=73ms TTL=51

Ping statistics for 209.191.122.70:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 72ms, Maximum = 73ms, Average = 72ms
Server: resolver1.opendns.com
Address: 208.67.222.222

Name: bleepingcomputer.com
Address: 208.43.87.2


Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
Reply from 208.43.87.2: Destination host unreachable.
Reply from 208.43.87.2: Destination host unreachable.

Ping statistics for 208.43.87.2:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
11...00 30 67 bf ab f9 ......Realtek PCIe GBE Family Controller
1...........................Software Loopback Interface 1
12...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
13...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 10.0.0.1 10.0.0.60 11
10.0.0.0 255.255.0.0 On-link 10.0.0.60 266
10.0.0.60 255.255.255.255 On-link 10.0.0.60 266
10.0.255.255 255.255.255.255 On-link 10.0.0.60 266
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 10.0.0.60 266
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 10.0.0.60 266
===========================================================================
Persistent Routes:
Network Address Netmask Gateway Address Metric
0.0.0.0 0.0.0.0 10.0.0.1 1
===========================================================================

IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
13 58 ::/0 On-link
1 306 ::1/128 On-link
13 58 2001::/32 On-link
13 306 2001:0:5ef5:79fd:c21:3964:f5ff:ffc3/128
On-link
13 306 fe80::/64 On-link
13 306 fe80::c21:3964:f5ff:ffc3/128
On-link
1 306 ff00::/8 On-link
13 306 ff00::/8 On-link
===========================================================================
Persistent Routes:
None

========================= Event log errors: ===============================

Application errors:
==================
Error: (05/12/2012 09:07:48 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/12/2012 08:57:38 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/12/2012 08:30:02 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/12/2012 01:18:03 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "*" of attribute "language" in element "assemblyIdentity" is invalid.

Error: (05/11/2012 08:52:34 PM) (Source: Application Error) (User: )
Description: Faulting application name: spoolsv.exe, version: 6.1.7601.17514, time stamp: 0x4ce7b4e7
Faulting module name: pdfcmon.dll, version: 0.1.1.0, time stamp: 0x4f60c5fb
Exception code: 0xc0000417
Fault offset: 0x0000000000003308
Faulting process id: 0x590
Faulting application start time: 0xspoolsv.exe0
Faulting application path: spoolsv.exe1
Faulting module path: spoolsv.exe2
Report Id: spoolsv.exe3

Error: (05/11/2012 08:52:31 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/11/2012 02:47:09 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "*" of attribute "language" in element "assemblyIdentity" is invalid.

Error: (05/10/2012 08:32:37 PM) (Source: Application Error) (User: )
Description: Faulting application name: spoolsv.exe, version: 6.1.7601.17514, time stamp: 0x4ce7b4e7
Faulting module name: pdfcmon.dll, version: 0.1.1.0, time stamp: 0x4f60c5fb
Exception code: 0xc0000417
Fault offset: 0x0000000000003308
Faulting process id: 0xf94
Faulting application start time: 0xspoolsv.exe0
Faulting application path: spoolsv.exe1
Faulting module path: spoolsv.exe2
Report Id: spoolsv.exe3

Error: (05/10/2012 08:27:08 PM) (Source: Application Error) (User: )
Description: Faulting application name: spoolsv.exe, version: 6.1.7601.17514, time stamp: 0x4ce7b4e7
Faulting module name: pdfcmon.dll, version: 0.1.1.0, time stamp: 0x4f60c5fb
Exception code: 0xc0000417
Fault offset: 0x0000000000003308
Faulting process id: 0x720
Faulting application start time: 0xspoolsv.exe0
Faulting application path: spoolsv.exe1
Faulting module path: spoolsv.exe2
Report Id: spoolsv.exe3

Error: (05/10/2012 08:25:54 PM) (Source: Application Error) (User: )
Description: Faulting application name: spoolsv.exe, version: 6.1.7601.17514, time stamp: 0x4ce7b4e7
Faulting module name: pdfcmon.dll, version: 0.1.1.0, time stamp: 0x4f60c5fb
Exception code: 0xc0000417
Fault offset: 0x0000000000003308
Faulting process id: 0x58c
Faulting application start time: 0xspoolsv.exe0
Faulting application path: spoolsv.exe1
Faulting module path: spoolsv.exe2
Report Id: spoolsv.exe3


System errors:
=============
Error: (05/12/2012 08:57:38 AM) (Source: Service Control Manager) (User: )
Description: The Windows Defender service terminated with the following error:
%%126

Error: (05/12/2012 08:56:08 AM) (Source: Service Control Manager) (User: )
Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

Error: (05/12/2012 08:54:18 AM) (Source: Service Control Manager) (User: )
Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

Error: (05/11/2012 08:52:36 PM) (Source: Service Control Manager) (User: )
Description: The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (05/11/2012 03:55:53 PM) (Source: Service Control Manager) (User: )
Description: The WinHTTP Web Proxy Auto-Discovery Service service depends on the DHCP Client service which failed to start because of the following error:
%%1058

Error: (05/11/2012 03:10:54 PM) (Source: Service Control Manager) (User: )
Description: The WinHTTP Web Proxy Auto-Discovery Service service depends on the DHCP Client service which failed to start because of the following error:
%%1058

Error: (05/11/2012 03:10:54 PM) (Source: Service Control Manager) (User: )
Description: The WinHTTP Web Proxy Auto-Discovery Service service depends on the DHCP Client service which failed to start because of the following error:
%%1058

Error: (05/11/2012 03:10:54 PM) (Source: Service Control Manager) (User: )
Description: The WinHTTP Web Proxy Auto-Discovery Service service depends on the DHCP Client service which failed to start because of the following error:
%%1058

Error: (05/11/2012 03:10:54 PM) (Source: Service Control Manager) (User: )
Description: The WinHTTP Web Proxy Auto-Discovery Service service depends on the DHCP Client service which failed to start because of the following error:
%%1058

Error: (05/11/2012 03:10:54 PM) (Source: Service Control Manager) (User: )
Description: The WinHTTP Web Proxy Auto-Discovery Service service depends on the DHCP Client service which failed to start because of the following error:
%%1058


Microsoft Office Sessions:
=========================
Error: (05/12/2012 09:07:48 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/12/2012 08:57:38 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/12/2012 08:30:02 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/12/2012 01:18:03 AM) (Source: SideBySide)(User: )
Description: assemblyIdentitylanguage*c:\program files (x86)\spybot - search & destroy\DelZip179.dllc:\program files (x86)\spybot - search & destroy\DelZip179.dll8

Error: (05/11/2012 08:52:34 PM) (Source: Application Error)(User: )
Description: spoolsv.exe6.1.7601.175144ce7b4e7pdfcmon.dll0.1.1.04f60c5fbc0000417000000000000330859001cd2fd98074f533C:\Windows\System32\spoolsv.exeC:\Windows\System32\pdfcmon.dllc2517fc4-9bcc-11e1-878c-003067bfabf9

Error: (05/11/2012 08:52:31 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/11/2012 02:47:09 AM) (Source: SideBySide)(User: )
Description: assemblyIdentitylanguage*c:\program files (x86)\spybot - search & destroy\DelZip179.dllc:\program files (x86)\spybot - search & destroy\DelZip179.dll8

Error: (05/10/2012 08:32:37 PM) (Source: Application Error)(User: )
Description: spoolsv.exe6.1.7601.175144ce7b4e7pdfcmon.dll0.1.1.04f60c5fbc00004170000000000003308f9401cd2f0cf0cb0cfeC:\Windows\System32\spoolsv.exeC:\Windows\System32\pdfcmon.dllcebb8685-9b00-11e1-bcfb-003067bfabf9

Error: (05/10/2012 08:27:08 PM) (Source: Application Error)(User: )
Description: spoolsv.exe6.1.7601.175144ce7b4e7pdfcmon.dll0.1.1.04f60c5fbc0000417000000000000330872001cd2f0cc680c748C:\Windows\System32\spoolsv.exeC:\Windows\System32\pdfcmon.dll0a7e24ad-9b00-11e1-bcfb-003067bfabf9

Error: (05/10/2012 08:25:54 PM) (Source: Application Error)(User: )
Description: spoolsv.exe6.1.7601.175144ce7b4e7pdfcmon.dll0.1.1.04f60c5fbc0000417000000000000330858c01cd2f083eae9fc7C:\Windows\System32\spoolsv.exeC:\Windows\System32\pdfcmon.dllde3680e2-9aff-11e1-bcfb-003067bfabf9


========================= Memory info: ===================================

Percentage of memory in use: 27%
Total physical RAM: 8191.3 MB
Available physical RAM: 5972.27 MB
Total Pagefile: 16380.8 MB
Available Pagefile: 14024.15 MB
Total Virtual: 4095.88 MB
Available Virtual: 3973.48 MB

========================= Partitions: =====================================

1 Drive c: (Win7) (Fixed) (Total:153.38 GB) (Free:106.53 GB) NTFS
7 Drive s: (Storage) (Fixed) (Total:232.88 GB) (Free:92.96 GB) NTFS
8 Drive y: (Terabyte) (Fixed) (Total:931.51 GB) (Free:6.46 GB) NTFS
9 Drive z: (Seagate) (Fixed) (Total:1397.26 GB) (Free:29.33 GB) NTFS

========================= Users: ========================================

User accounts for \\DESKTOP

Administrator Eric Guest


**** End of log ****

#13 nasdaq

nasdaq

  • Malware Response Team
  • 40,213 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:03 PM

Posted 13 May 2012 - 08:36 AM

I want to show you my HijackThis log and the rest of MiniToolBox. One thing hijack this mentions is two winsock lsp(?) entries that it can't remove.

Please post the HijackThis log for my review.

I do not see any winsock key in your ComboFix log. It may just be broken but I want to make sure first.

#14 3maz

3maz
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:04:03 PM

Posted 15 May 2012 - 05:03 PM

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:02:56 PM, on 5/15/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\HsMgr.exe
C:\Program Files (x86)\Free Download Manager\fdm.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\PicPick\picpick.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Box Edit\Box Edit.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
C:\Users\Eric\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\AutoHotkey\AutoHotkey.exe
C:\Program Files\TrueCrypt\TrueCrypt.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Eric\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: LastPass Browser Helper Object - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPBar.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files (x86)\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PicPick Start] C:\Program Files (x86)\PicPick\picpick.exe /startup
O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
O4 - HKCU\..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office14\GROOVEMN.EXE
O4 - Startup: Dropbox.lnk = C:\Users\Eric\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: Main.ahk.lnk = S:\Dropbox\Dev\AutoHotKey\_Scripts\Main.ahk
O4 - Startup: Microsoft SharePoint Workspace.lnk = C:\Program Files\Microsoft Office\Office14\GROOVE.EXE
O4 - Startup: OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
O4 - Global Startup: Box Edit.lnk = C:\Program Files (x86)\Box Edit\Box Edit.exe
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: LastPass - file://C:\Program Files (x86)\LastPass\context.html?cmd=lastpass
O8 - Extra context menu item: LastPass Fill Forms - file://C:\Program Files (x86)\LastPass\context.html?cmd=fillforms
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPBar.dll
O9 - Extra 'Tools' menuitem: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPBar.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{8F7A7258-3241-4800-B94E-2688E0B408E4}: NameServer = 208.67.222.222,208.67.220.220
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\sua.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11233 bytes

#15 nasdaq

nasdaq

  • Malware Response Team
  • 40,213 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:03 PM

Posted 16 May 2012 - 07:07 AM

:/ I wish I had more time right now. I want to show you my HijackThis log and the rest of MiniToolBox. One thing hijack this mentions is two winsock lsp(?) entries that it can't remove. It also shows many hidden processes, or more specifically, those with files missing and unknown owners. They seem to be removed but reappear with a restart.


You show two Winsock items. Both are for Windows Live.

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

Do not try to remove these items. They are required.
===

As for the missing files it's a false positive. HijackThis is not ready for the 64 bit operating system.

What are the remaining issues with this computer?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users